From patchwork Tue Sep 22 08:24:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marco Baffo X-Patchwork-Id: 5396 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp12954872mag; Tue, 22 Sep 2026 01:24:33 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBx2YCaHCo4sX9S8M3RxKq89P2M5CaKD5HBmLgb8z/V+1p/GaKalUug9hwiw7ChxCU6nvO8rZDyjeKY=@openvpn.net X-Received: by 2002:a4a:edcd:0:b0:6b1:404f:6eb4 with SMTP id 006d021491bc7-6ca9a0270f0mr11223483eaf.9.1790065473682; Tue, 22 Sep 2026 01:24:33 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790065473; cv=none; d=google.com; s=arc-20260327; b=KWbAlM2iZhHHV4UWIsVOx65ybB4MN77AArMtqW9TeIGIZ5PmRlNKPwesS78zLHPQ/f 41A1387OQzGiplcRoZQQB97GdFftjyyMUDsuKdVWvh5/U4Dd5yPK2lnn35AIg0MvlUx7 DisHKUCIELb+lE/y/u2Py5pX5Pq6W0rOrvx8b1hxvetanJEpYDt5m2hpzdk5YD4go4b8 r1cXhq3jBm+8wxgdONriJeOxCIvbAit0vUHq4HdZWpEgNqjl+MsKDcdIidMQhtT4EhIx Kp5UuTBsYzRtxQ8tHHuEL5boXMBHMA2Xx/OhxNXTuHwSyYJCzIMbstKTgfZ2wXfxfH1a N4Jw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=yGqUSdPLH/TNO9CRzAxW+VsKsNSUQdRRqd4i4FFP5Og=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=eaHcpsu0+OPpcgN6zKJ1pYk2n+fC5jA0sZs3PtjskEblcoA+tC8BYsFxDCke90tMD3 n7CE9bfeS8W1jZZDPUFlfSFNpsZCtfq0DMKVg8qwdtWf6LDNrzgUPAWtTaDgogbzt+Z3 2HcLwHqLmFSaNQ46zhW1unLFYiHXNh6jT8ziiKGNwWCAbLXTMKhgpgZxv48j9y6zdthm qKKP3AxXbJjN+QPNtC5eybHfOYabQhZ7RUSQyN3S4T9ms5y29W7wy+mC9+7t3tyHWiqv pBsLEkZlZpB+3ciD3IJt/F4MFawggNAkap08onyOTND2g9oavpHm1us08OE83VH//mVa 80kw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=aCS7QwUj; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lTFbbbC9; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="hE11g/L6"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="M/97voqQ"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-48fbf4b289dsi944321fac.194.2026.09.22.01.24.33 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Sep 2026 01:24:33 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=aCS7QwUj; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lTFbbbC9; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="hE11g/L6"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="M/97voqQ"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=yGqUSdPLH/TNO9CRzAxW+VsKsNSUQdRRqd4i4FFP5Og=; b=aCS7QwUjlui1482McBR9hkmN3i xmMVuo9EmsN6WoAzElxQplKxOpFzsMpTt2ZELjNrFuWqJZgKEivEgvDEaQoIAABB3mu3Y3WuW3krl MSD5LSrBECpy0v1oQo0qUXXonRxvKUQqDg6Cpbij2mPQcpuK+KEMCd9IOKgo4tuVwFjo=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x8vnl-0002Ul-Cn; Tue, 22 Sep 2026 08:24:30 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x8vne-0002T2-53 for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 08:24:23 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=QBpPCXVbZfbngu0Y7PsZ0werro+77CozEA8OSF+q+Yw=; b=lTFbbbC9X8OpxPeYoPAEolMZUi mr+sDDe/NbWKlGw4kSpbbXn18soebqsUDkZYp6uNtGLhdzcNNN8VZIsKI7xmmV/TwsEQ11EEH04nW 30cO7LsFJhfooJasG5EPYi3N/Xrn9syZ+4PJxlFcTjmnK+PcjiNhPxu26FXhGZDNaZjg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=QBpPCXVbZfbngu0Y7PsZ0werro+77CozEA8OSF+q+Yw=; b=hE11g/L6knMZNckE9BMmqfe0di E+bUsCDBfrU0ApH+ttA03v8u91b/dnqbZxxocWp0q7r3aDix38jfKpywd9huvA4eFN5mpSPp+WJzp nARuDSY5VbWrBW3xxUB/7sPvJXB16DBMDQ+uIJvj5Iv77xGaFq3qIA0kyUEmTSPvduz0=; Received: from mout-b-203.mailbox.org ([195.10.208.52]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x8vnb-0005Sp-0k for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 08:24:23 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-203.mailbox.org (Postfix) with ESMTPS id 4hptRg4wrJzLmJm; Tue, 22 Sep 2026 10:24:15 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1790065455; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QBpPCXVbZfbngu0Y7PsZ0werro+77CozEA8OSF+q+Yw=; b=M/97voqQmC0llxPLTl7k5Wvzw1lLWDBukHLZSqLFFyFB6VJummWKuvdPwAArhhmUMsrLAN vKact8P7ui2XXzK3uvCZDuQurIr2r+CQL2DfbC4gFGgo8gSEda0SmwM0vjkSnfFGTPulBd CaGg5FHCjMinfg9Ee1/Nmgt80h5wLQtjNWALFceuBsvHuqXYVj+u/aqO/Fo8X20gEGvwBb 0uUjYykQ9d8XrzBbmZWEgNE7iHcb4v38i5uvuKDYArxNWy8Qm2qZ7wzBcVWU+P4l2YHOQH hzeHIPiQzZ98c05rYnj8jicS+7S6SlcTA8qjTuie3U2Fmp7WH3cf62fJ8gW7qg== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of marco@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=marco@mandelbit.com From: Marco Baffo To: openvpn-devel@lists.sourceforge.net Date: Tue, 22 Sep 2026 10:24:07 +0200 Message-ID: <20260922082408.2930734-2-marco@mandelbit.com> In-Reply-To: <20260922082408.2930734-1-marco@mandelbit.com> References: <20260922082408.2930734-1-marco@mandelbit.com> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hptRg4wrJzLmJm X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: vpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex that is only meaningful in the ovpn device namespace. If the two namespaces differ, listener [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1x8vnb-0005Sp-0k Subject: [Openvpn-devel] [RFC ovpn net-next v5 2/3] ovpn: send notifications in the device netns X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877019694062351523 X-GMAIL-MSGID: 1877019694062351523 vpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex that is only meaningful in the ovpn device namespace. If the two namespaces differ, listeners resolve it to an unrelated interface, as ifindexes are numbered per netns. Multicast notifications in the device namespace instead. This also avoids depending on the transport socket when sending a notification. Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion") Fixes: a215d253c17a ("ovpn: notify userspace when a peer is deleted") Fixes: c841b676da98 ("ovpn: notify userspace on client float event") Signed-off-by: Marco Baffo --- Changes in v5: - None Changes in v4: - Instead of adding the netns id in the noify message we just send the message in the ovpn netns. Changes in v3: - Removed changes in the ovpn.yaml . - Changed peernet2id_alloc() to peernet2id() to avoid potential deadlock when the notication is send from softirq context (peer-float, key-swap). Changes in v2: - This is a new patch. drivers/net/ovpn/netlink.c | 44 +++++--------------------------------- 1 file changed, 5 insertions(+), 39 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 7a13c056131de..f6758b16b26ae 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -1182,7 +1182,6 @@ int ovpn_nl_key_del_doit(struct sk_buff *skb, struct genl_info *info) */ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) { - struct ovpn_socket *sock; struct sk_buff *msg; struct nlattr *attr; int ret = -EMSGSIZE; @@ -1215,23 +1214,12 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) goto err_cancel_msg; nla_nest_end(msg, attr); - genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, + 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1249,7 +1237,6 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, const struct sockaddr_storage *ss) { - struct ovpn_socket *sock; struct sockaddr_in6 *sa6; struct sockaddr_in *sa; struct sk_buff *msg; @@ -1299,21 +1286,11 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, nla_nest_end(msg, attr); genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1330,7 +1307,6 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, */ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) { - struct ovpn_socket *sock; struct nlattr *k_attr; struct sk_buff *msg; int ret = -EMSGSIZE; @@ -1364,20 +1340,10 @@ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) nla_nest_end(msg, k_attr); genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, + 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: