From patchwork Wed Jul 29 15:38:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marco Baffo X-Patchwork-Id: 5177 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp2127850mac; Wed, 29 Jul 2026 08:39:08 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpjM5qzf2z5kNowei6c4Nwtdo4ZlttLAzKY+dcd+fr7/V3zkpv/W8ZmbG/dDICXr08lBsy7yeOAoac=@openvpn.net X-Received: by 2002:a05:6870:ac13:b0:43e:e5bf:1ab4 with SMTP id 586e51a60fabf-4586cd1cec4mr4096567fac.21.1785339548300; Wed, 29 Jul 2026 08:39:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785339548; cv=none; d=google.com; s=arc-20260327; b=kFi+52Y6TwVPGYXpyuMnsGzucMzBoq10sXDpyAnTd+UBx31vgOSiJruuSTRCVJ70g5 dWK2D9VAJHuNPEPZxa6jWmPwkeQ1fQeN3d1siX2hqhKvmsL8jUKsqLFrPO0e1DTuS4mM nj6wceIBmUF1ZZJ7AYGjj9qeUCaiU1yQuWbtjOlxYtUvztsNeCB5r0T+PiyFeYrh8m8D VftwbVa70UgNAswPiahdzVLr7hEPQ1Pp+zZ/r9YFYfV1WhxIFzqU8HqWwH1QAEG2kyYp BzbrHiYF9Heo++zxXhPm5isjBTpLHX+SAKESOrurts2GwekIGQmPIWcZGk8v94zWgcE3 ooxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=vZy8/s1/M3pW3MqUAPtGervPmvq3KSBM+HQm5wXq11Y=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=sdo1EQO8DRQTJp9KvpKVnTmsLSTuuzJn+az4PHYPYAt9H53l37JDavpTmRgcrW9aqV 9B6jNPpbSxozMc45F4BAPFC2NaeHc+budAaOemkw0wTYXJ4kjdv1wmE4WJnllfUZ0VEl ZVfDiE65UloyWTLCCL5nL1WrYJmfxw0BA4tCNKEYftGZxbz5cQIqZl55K4loVUNo7YVX gVkc4nqiUc9t05spCd29b7SWTAhtask8ZOmUtTmywGZ7lw4RH0weYSNjZ6JD0bVu1s82 KjKQmYRjul2HYru50oFQqoIes9YI1rT2P2IPTxezC82RunEhz7SIZ6iVe8lIoMhcsRki o9NQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=DUrLCZpg; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Wts+6xUQ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=c5KsnzHP; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=SrSKeWdb; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886b510c2si2789984fac.229.2026.07.29.08.39.07 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 08:39:08 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=DUrLCZpg; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Wts+6xUQ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=c5KsnzHP; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=SrSKeWdb; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=vZy8/s1/M3pW3MqUAPtGervPmvq3KSBM+HQm5wXq11Y=; b=DUrLCZpg8vZskzN3JdKPjq/DIF GpP3EVyIdnbkEySlmwcYj3MIw1MNkW9qA7MT3G6fs7vv12FeiV6jRz0s8Zj9VwyvfKsXPMFiGXEvZ TVcA5Ft5T+14pIgHgNfN+CCGWqEy190YFsRz1TxNo9EvwtABTtuk3h4CyP5nyyBmaI9E=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp6N7-0002Ms-6x; Wed, 29 Jul 2026 15:39:05 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp6N5-0002Mk-KU for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:39:03 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=g2NhgoJnpn0gnAXzqvlVQGlVg8JdU49jbycZsnpmd8g=; b=Wts+6xUQ1L67jke7Oenwu0DsWr 2oQSjtJ6s86MKOBbxAWWULgyL5ZKnZlVu5ybOa7A95TnCgTGikSrqox69zM6w0k6E330kO6tgI4Yy Ll5XTdfoPLNWQuIOAK/4JaC3gehOvHKZdXiPqrZgfIJySTDoywAKJ8ZkjMUNuW4QDz+A=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=g2NhgoJnpn0gnAXzqvlVQGlVg8JdU49jbycZsnpmd8g=; b=c5KsnzHPY+oq4Wd/pj0TI26xi3 +qG5gZPVv68DaFNuD87zBmbnWV1jIcmuMLdDEchT9QX3HvRYy61MShwS/Yg92pvyXqIOso6N6VXcp Zc8xKuef6S8vmdOkOYmAOxzVtF+T0By9i4EhMJUwIgxtXd/hy6FXOY6hXnDTCh/iuGsU=; Received: from mout-b-201.mailbox.org ([195.10.208.61]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp6N1-0002oq-Ik for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:39:03 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-201.mailbox.org (Postfix) with ESMTPS id 4h9GhX1kSbzLm5m; Wed, 29 Jul 2026 17:38:52 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785339532; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=g2NhgoJnpn0gnAXzqvlVQGlVg8JdU49jbycZsnpmd8g=; b=SrSKeWdbwjzNqSA/H8Kbp9bn9oY2NOPAoKKgQgi/sw08caI+fXMEEo19zFbEnhkBAVDBWi UIlzeqmkocGntTwKVop2QbtV2SXsbAJTt53slP2a54IV0Kkb/+GWEzI/+HsBh6maQZcfHX DdrqgLGRhSqAWKFoLwcXtLElJvMDCUQ6Etq7+YmUh19ZbSAt0CTjNMvN2qbKoL34Q4ggYK 8WUuUtZxm1ZR/xWORsnSez2lovumrlvw3YK/ie65+K4KRpdl6SCydKC7Sk1DA1FTLEAjbA wZBfij4vk8N5L7d+5HuUJH0p2XdTjpx41UBodEy833/T8zC1cyViBTjokUf2iQ== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of marco@mandelbit.com designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=marco@mandelbit.com From: Marco Baffo To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 17:38:13 +0200 Message-ID: <20260729153815.2637139-2-marco@mandelbit.com> In-Reply-To: <20260729153815.2637139-1-marco@mandelbit.com> References: <20260729153815.2637139-1-marco@mandelbit.com> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h9GhX1kSbzLm5m X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex from the ovpn device namespace. If these namespaces differ, the ifindex alone is ambiguous [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URI: mandelbit.com] -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wp6N1-0002oq-Ik Subject: [Openvpn-devel] [PATCH ovpn net-next v3 2/4] ovpn: include target netns ID in notifications X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872064202238064756 X-GMAIL-MSGID: 1872064202238064756 ovpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex from the ovpn device namespace. If these namespaces differ, the ifindex alone is ambiguous to listeners. Include the device namespace ID relative to the receiving namespace when the two namespaces differ. Notifications may be generated from softirq context, so use peernet2id() without allocating a namespace ID. When the Netlink control and transport sockets share a namespace, the mapping normally already exists because it was needed to address the foreign interface. Otherwise, report NETNSA_NSID_NOT_ASSIGNED unless userspace established the mapping beforehand. Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion") Fixes: a215d253c17a ("ovpn: notify userspace when a peer is deleted") Fixes: c841b676da98 ("ovpn: notify userspace on client float event") Signed-off-by: Marco Baffo --- Changes in v3: - Removed changes in the ovpn.yaml . - Changed peernet2id_alloc() to peernet2id() to avoid potential deadlock when the notication is send from softirq context (peer-float, key-swap). Changes in v2: - This is a new patch. drivers/net/ovpn/netlink.c | 90 +++++++++++++++++++++----------------- 1 file changed, 50 insertions(+), 40 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index b70ecfaf46c8..81953467e6fb 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -1167,6 +1167,47 @@ int ovpn_nl_key_del_doit(struct sk_buff *skb, struct genl_info *info) return 0; } +static int ovpn_nl_send_notify(struct ovpn_peer *peer, struct sk_buff *msg, + void *hdr) +{ + struct ovpn_socket *sock; + struct net *net_sock, *net_dev; + int netnsid, ret = 0; + + rcu_read_lock(); + sock = rcu_dereference(peer->sock); + if (!sock) { + ret = -EINVAL; + goto unlock; + } + + net_sock = sock_net(sock->sk); + net_dev = dev_net(peer->ovpn->dev); + + /* The notification is delivered in the transport socket's netns. If the + * ovpn device is elsewhere, report its netns ID relative to that netns. + */ + if (!net_eq(net_sock, net_dev)) { + /* Peer-float and key-swap notifications may be generated from + * softirq context, so do not allocate an NSID here. If none + * exists, peernet2id() returns NETNSA_NSID_NOT_ASSIGNED. + */ + netnsid = peernet2id(net_sock, net_dev); + if (nla_put_s32(msg, OVPN_A_TARGET_NETNSID, netnsid)) { + ret = -EMSGSIZE; + goto unlock; + } + } + + genlmsg_end(msg, hdr); + genlmsg_multicast_netns(&ovpn_nl_family, net_sock, msg, 0, + OVPN_NLGRP_PEERS, GFP_ATOMIC); +unlock: + rcu_read_unlock(); + + return ret; +} + /** * ovpn_nl_peer_del_notify - notify userspace about peer being deleted * @peer: the peer being deleted @@ -1175,7 +1216,6 @@ int ovpn_nl_key_del_doit(struct sk_buff *skb, struct genl_info *info) */ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) { - struct ovpn_socket *sock; struct sk_buff *msg; struct nlattr *attr; int ret = -EMSGSIZE; @@ -1209,22 +1249,12 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) nla_nest_end(msg, attr); - genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + ret = ovpn_nl_send_notify(peer, msg, hdr); + if (ret < 0) + goto err_cancel_msg; return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1242,7 +1272,6 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, const struct sockaddr_storage *ss) { - struct ovpn_socket *sock; struct sockaddr_in6 *sa6; struct sockaddr_in *sa; struct sk_buff *msg; @@ -1291,22 +1320,13 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, } nla_nest_end(msg, attr); - genlmsg_end(msg, hdr); - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, - 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + ret = ovpn_nl_send_notify(peer, msg, hdr); + if (ret < 0) + goto err_cancel_msg; return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1323,7 +1343,6 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, */ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) { - struct ovpn_socket *sock; struct nlattr *k_attr; struct sk_buff *msg; int ret = -EMSGSIZE; @@ -1356,21 +1375,12 @@ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) goto err_cancel_msg; nla_nest_end(msg, k_attr); - genlmsg_end(msg, hdr); - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + ret = ovpn_nl_send_notify(peer, msg, hdr); + if (ret < 0) + goto err_cancel_msg; return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: