From patchwork Tue Sep 22 14:25:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marco Baffo X-Patchwork-Id: 5399 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp13340732mag; Tue, 22 Sep 2026 07:25:34 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBw/QSDnccmicLEgBWABTQU2DYki6L8PqIkMcaFRml8ImE8d4Sq7ldWUTVnQ2pGw/albqC+RIJRsRLI=@openvpn.net X-Received: by 2002:a05:6871:3747:b0:48f:e0f6:bd4a with SMTP id 586e51a60fabf-48fe0f6ccf9mr909819fac.31.1790087134179; Tue, 22 Sep 2026 07:25:34 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790087134; cv=none; d=google.com; s=arc-20260327; b=hJKRevfZLVhrYX552MDmG7krlDMP97wip1PrHJm8BaHYSs49PgRlxRzzxqklIMhh3p m1PJNrUVSOmf/v7pDBO3JtbOGbyS3v7Awfc4csZjCcJu7M2lqTeFaGujdJsFAv/7FNYL j6l0Fdm83tV7smj/KsUL0oAC5PlkU/ASUxhVTvPyc6c8kCOhF2+cgInakxdbhiF1rK15 oHZ5UEVDCCMEfc3kwYwq93TJHqvLW1tws+x3Q57dPgRVFbhJkIU+1SENUuG/QGnbmpH8 v/QgfhW4sL9Tl39Vp5VBcfEOQeMrW39PpTxkWYiRi1QRo6Y7mGB0YswI1h9xmvAaj9gd Ygvw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=8ILjLKVOxzKN8ExA+i9DN4hsiC2nUv+iAYshu6FS43A=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=sKW9ySRwb6iBfRV+aOhw/kUZhrlKcwJAzxc8e+IIhFHD4SfJzhP1NWrXShs6kIDFgy 8GnT3OGkJzhyJdkPDmP10PjvHraIuW9j6mGkNW1QoZFjQGKBzcPHCwo+B8VQXg52gQmJ G70132VSz+9IvtXKFBFqTc3jum1kiyuJZtrzGZfYa81YP4ow1Vup8E7g8Tt7Lmr4sXY3 dE/u1vzVIjaVQOfFjFemz7c57lecYk9Ikw7oKx9fQHzdI/pmOp99+l/81bKtSP1C28bD y/UPki6cgqFMwrgeeAAKwJ+CEydEOwkjB1za7Uq6AKiWBOnwoLT7UhJ5c5BLeIyKG1gr lqEg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NQWtsNPH; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Pgq9+Lix; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=IkEMrRid; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=BfvoBd0h; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-48fbf4b7723si1914243fac.215.2026.09.22.07.25.33 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Sep 2026 07:25:34 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NQWtsNPH; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Pgq9+Lix; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=IkEMrRid; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=BfvoBd0h; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=8ILjLKVOxzKN8ExA+i9DN4hsiC2nUv+iAYshu6FS43A=; b=NQWtsNPHLheMvKjm2lk61JUQU5 tnM+drlYgdAttEmteghYhCl6cdKpJWl16/ZUK7K4tqq0QzMlfJLO3Y+8DgElTC/znq6Dan6vcbeK5 WRGZhhmT5U/bo/WcDqKJc2nrN4WZrO9amyf6eKfyneb5k2ygdLDsnM04XfhIlbPfphHQ=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x91R6-000640-Kt; Tue, 22 Sep 2026 14:25:30 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x91Qw-00063l-Un for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:25:21 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=OFB80b2B5lThtSDxDFyJA6YeBrOiQJawIQIHrzvUi5Y=; b=Pgq9+Lix8ENZZiEG1+gjtmLVqy 3NB2GUp9spHJhDN4u4EMlp3WT/NjJtzoiVzsCyA3vfhNzD81B9cafhk1SKjTsdnvzpxV40o6hDNGZ uDnrFGsDeFQH08GlvbfTA6RVoaHrHGk2mLRXOZuvqL41rj0PafE5wbkO31OWDcIvbZMk=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=OFB80b2B5lThtSDxDFyJA6YeBrOiQJawIQIHrzvUi5Y=; b=IkEMrRid5xJW3NyqKFmW4nsdK8 BdaEzQHix1e60qJfra7jBz5/x6Q1HJoKCv8AShhVgBAiOKK16HRyLHBVJSMubeBECj9oq17qIHdWf 0FHFucLLfdtukJ5QjA0Lk0dF6OYfeRXJ8x0VI++7hmLGe2Bf38vaRTuCsc8R+WJupLLE=; Received: from mout-b-110.mailbox.org ([195.10.208.55]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x91Qs-0005bU-KP for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:25:20 +0000 Received: from smtp2.mailbox.org (smtp2.mailbox.org [IPv6:2001:67c:2050:b231:465::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4hq2S65tstzNlxK; Tue, 22 Sep 2026 16:25:10 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1790087110; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OFB80b2B5lThtSDxDFyJA6YeBrOiQJawIQIHrzvUi5Y=; b=BfvoBd0ha3Ed8wdWf4Uplj1I/EMylKfJQPT1zXZwu6wS+ySw7zqHpiOuj6aJw6EyzknjoI LlBrfEV16RHhA1JwVgO2CAUv+UOeySf8+LdUGGKrhI/MtwLCcdcn5Dmw67T2CcnA8eQop9 V9/k+lriScs0YaAw1O85UPJcTnmjsCQZUnsLtUN8BXc/pNydhRX7qabrPyT/FMKDddYb2D 9MU5iJMArFRQHsAb7fQjFgg0wqJFJjcarsmSHUAPeZGVQcCui5edA4Bdg2gr6EnmfLC74W BthajIqCpdwljqfkEuMJimEUZmAk4x6CutzkMPeFpLljyn87Ei+bSdYzt+jv7w== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of marco@mandelbit.com designates 2001:67c:2050:b231:465::2 as permitted sender) smtp.mailfrom=marco@mandelbit.com From: Marco Baffo To: openvpn-devel@lists.sourceforge.net Date: Tue, 22 Sep 2026 16:25:04 +0200 Message-ID: <20260922142505.3138388-2-marco@mandelbit.com> In-Reply-To: <20260922142505.3138388-1-marco@mandelbit.com> References: <20260922142505.3138388-1-marco@mandelbit.com> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hq2S65tstzNlxK X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: vpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex that is only meaningful in the ovpn device namespace. If the two namespaces differ, listener [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1x91Qs-0005bU-KP Subject: [Openvpn-devel] [PATCH ovpn net-next 2/3] ovpn: send notifications in the device netns X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042406647168295 X-GMAIL-MSGID: 1877042406647168295 vpn notifications are multicast in the network namespace of the peer transport socket, but carry an ifindex that is only meaningful in the ovpn device namespace. If the two namespaces differ, listeners resolve it to an unrelated interface, as ifindexes are numbered per netns. Multicast notifications in the device namespace instead. This also avoids depending on the transport socket when sending a notification. Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion") Fixes: a215d253c17a ("ovpn: notify userspace when a peer is deleted") Fixes: c841b676da98 ("ovpn: notify userspace on client float event") Signed-off-by: Marco Baffo --- drivers/net/ovpn/netlink.c | 44 +++++--------------------------------- 1 file changed, 5 insertions(+), 39 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 04df2c0288a5d..5c94d34219c73 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -1188,7 +1188,6 @@ int ovpn_nl_key_del_doit(struct sk_buff *skb, struct genl_info *info) */ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) { - struct ovpn_socket *sock; struct sk_buff *msg; struct nlattr *attr; int ret = -EMSGSIZE; @@ -1221,23 +1220,12 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) goto err_cancel_msg; nla_nest_end(msg, attr); - genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, + 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1255,7 +1243,6 @@ int ovpn_nl_peer_del_notify(struct ovpn_peer *peer) int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, const struct sockaddr_storage *ss) { - struct ovpn_socket *sock; struct sockaddr_in6 *sa6; struct sockaddr_in *sa; struct sk_buff *msg; @@ -1305,21 +1292,11 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, nla_nest_end(msg, attr); genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: @@ -1336,7 +1313,6 @@ int ovpn_nl_peer_float_notify(struct ovpn_peer *peer, */ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) { - struct ovpn_socket *sock; struct nlattr *k_attr; struct sk_buff *msg; int ret = -EMSGSIZE; @@ -1370,20 +1346,10 @@ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) nla_nest_end(msg, k_attr); genlmsg_end(msg, hdr); - - rcu_read_lock(); - sock = rcu_dereference(peer->sock); - if (!sock) { - ret = -EINVAL; - goto err_unlock; - } - genlmsg_multicast_netns(&ovpn_nl_family, sock_net(sock->sk), msg, 0, - OVPN_NLGRP_PEERS, GFP_ATOMIC); - rcu_read_unlock(); + genlmsg_multicast_netns(&ovpn_nl_family, dev_net(peer->ovpn->dev), msg, + 0, OVPN_NLGRP_PEERS, GFP_ATOMIC); return 0; -err_unlock: - rcu_read_unlock(); err_cancel_msg: genlmsg_cancel(msg, hdr); err_free_msg: