[Openvpn-devel,net,v3,2/6] ovpn: skip UDP source validation for unspecified addresses
| Message ID | 204af84e2b14079780e06d32ad24c88f1b2d1999.1787925761.git.ralf@mandelbit.com |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp51120mab;
Fri, 28 Aug 2026 07:50:59 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RoHNlHH4Of23DJB8d04+crrFQPnV5xSECsp2r8BZY1Vu+9sP1LiAuTb/BzMK2PiWlnj/gTgtgGk5FU=@openvpn.net
X-Received: by 2002:a05:6820:4cc8:b0:6b1:42ab:d040 with SMTP id
006d021491bc7-6b1c6744b43mr5863924eaf.28.1787928659117;
Fri, 28 Aug 2026 07:50:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787928659; cv=none;
d=google.com; s=arc-20260327;
b=bfY1PhlvKjGi/hHIVh1vxchj00bsCBUGxWMa17hWvDlzjcg1Ye2yz2Hrw7iKVAP6LM
bE23BHqmeJGRqcAAtlYvPo7kTtNHBSAG8yKGMHAXgloNRcpaMF/Lx+b+WbZVa03qly6q
icjCao4umgeGvSF1uZm1hmINb0BRETCQ7aQccDE+nNsan6IqDkMy0673KYPAWSyyYLwV
LgT6x1XQ/icWak3+ylrBhJu3N+lQEbxJUhjTAAS8lXdaYTBSp9Cf6kAOmCVZZuJu/gNs
sZwmYuke5C2DnVdyBVtSuStmFM1lnUzqhrWf7yLG8VpJxsSDTUJMTekUbJ4FIiIgIAP8
WfAQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=qYzwudV+NzBLNRJEmob+rXxGadxGGgQK8RELb0n1irM=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=mnUwwwZHhXBFt1z4xjDaSax6BQdaSP3oKS8CYjd408hf1c9T5jkguWx0QkVNQnHgaM
OvVJuV+fB2Z6FJlU0B93sDa2h0BW8j5s064q5aYudVzpIPq7Kp4GREJ85FCyTfjgxnDx
3OKey74sBag4aLSw+ptomlQn+RrNsLTNwCCSTA/kouZphg3orf8ZPgr5qh3X6ZjzQ32A
MCwsutoHqJF5QEoXVyexR7/MTQbGjm1ZL7Pru/s9glLeNnnnX9MdaBQnFVlRKKtfSM1a
6zGjlAoOXoM3tFci4zVm2NcNXDryEuWBZkX+nTREIiKGaupl5/Dc4OrW5EcYf4EqF90D
c5Eg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=GUgnJjKR;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=AUz7ic8F;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=K+0GPBGu;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=crTjqrp4;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
006d021491bc7-6b1ce3eb96bsi2494505eaf.84.2026.08.28.07.50.58
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 28 Aug 2026 07:50:59 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=GUgnJjKR;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=AUz7ic8F;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=K+0GPBGu;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=crTjqrp4;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=qYzwudV+NzBLNRJEmob+rXxGadxGGgQK8RELb0n1irM=; b=GUgnJjKRLCF/1iFD7OidIlmeHT
oWBalfpoWTViBoYUlv3pIYoAmX50dVXlvcLq/dzhWghnRgdm6e7QbTNza89AThhGZzvWqkepqKmEZ
z5FyZ1FnbZf8vtMoIZGzyY0NxTn7BiQC3TnjM0bv4SjeIa2PIElsZeurB6cOtGYpQfak=;
Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com)
by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wzxv0-00048C-P0;
Fri, 28 Aug 2026 14:50:56 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1wzxux-000484-Aq
for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:52 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=mGXWEtESJmpRf+hvG7ryt7oZfowt9ZJ+xoPXROLSSX0=; b=AUz7ic8FgU2QraKkRzD48lEznJ
WTWO4H2Dc1JAlok+92GfwxKvIkcwkN43gR+OuCMutWaBF1hlTJxC9vrRxzb4dsZc5DxQX4b+iL9T+
TVts33oMt6jabxAP7iPxiyNGpk504c1+nhUASlifB2EGEEEEdEr4DQY8Oudlnncf3HPs=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=mGXWEtESJmpRf+hvG7ryt7oZfowt9ZJ+xoPXROLSSX0=; b=K+0GPBGucahgmXfski1KEcZ9vA
AQ2N2IHMH6NmhIWdEP74jDM5rJt69TOIB1GcTccM1ZMkYenlcTRfITvlQhyj1de3PD9phwT2+sPbt
dEMmNbQn+eBbAbBUP2ZoqBr6IMzMWjXM9/ogArSMxBBJyZAJGL1jg8JAAmQaPJlHpbyA=;
Received: from mout-b-110.mailbox.org ([195.10.208.55])
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wzxuq-0005qW-Mm for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:52 +0000
Received: from smtp102.mailbox.org (smtp102.mailbox.org
[IPv6:2001:67c:2050:b231:465::102])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4hWhC43lkzzNlfQ
for <openvpn-devel@lists.sourceforge.net>;
Fri, 28 Aug 2026 16:50:40 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1787928640;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=mGXWEtESJmpRf+hvG7ryt7oZfowt9ZJ+xoPXROLSSX0=;
b=crTjqrp4dosbNRoMW125l7hCu+h5pPouZNYToUaWv74IJrwSZ0B/N9LocP6MeFnBDdjqXm
Bx+prHmUKaw6IYR8O3x6T//BTX+4vSitxvlf6eqksaqU39zLdUsjnzQz1G5Prvu0qi/ZnK
FIgYZnnhoJnPOHDW9tDiGSJBUmHuuOXsJZnehYZBpu4Y2jIZv1VnZ4Xdx15aPp4RLyAVNc
quLKoAQVRz2B831ClUCDPAsiaJxLu6a1sBgaEc7nkzEzZI9iMIgvVQ046J8gNtNFtIsxCN
LZ1ufB7MHa+kSM/ZPjQgKppdQP/tRC0gnODuj9tcJZ74F18M24UaH4N3JX1xxA==
Authentication-Results: outgoing_mbo_mout; dkim=none;
spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates
2001:67c:2050:b231:465::102 as permitted sender)
smtp.mailfrom=ralf@mandelbit.com
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 28 Aug 2026 16:50:23 +0200
Message-ID:
<204af84e2b14079780e06d32ad24c88f1b2d1999.1787925761.git.ralf@mandelbit.com>
In-Reply-To: <cover.1787925761.git.ralf@mandelbit.com>
References: <cover.1787925761.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Rspamd-Queue-Id: 4hWhC43lkzzNlfQ
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: ovpn validates the cached local UDP source address before
reusing or refreshing a peer dst cache. This is only meaningful when a
concrete
source address is selected. For IPv6, calling ipv6_chk_addr with :: checks
whether the unspecified address itself is configured on the host. A peer
may legitimately have bind->local.ipv6 set to :: when no local endpoint was
conf [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1wzxuq-0005qW-Mm
Subject: [Openvpn-devel] [PATCH ovpn net v3 2/6] ovpn: skip UDP source
validation for unspecified addresses
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1874779081564273996
X-GMAIL-MSGID: 1874779081564273996
|
| Series |
ovpn: fix UDP route cache and endpoint handling
|
|
Commit Message
Ralf Lici
Aug. 28, 2026, 2:50 p.m. UTC
ovpn validates the cached local UDP source address before reusing or
refreshing a peer dst cache. This is only meaningful when a concrete
source address is selected.
For IPv6, calling ipv6_chk_addr with :: checks whether the unspecified
address itself is configured on the host. A peer may legitimately have
bind->local.ipv6 set to :: when no local endpoint was configured or
after a stale learned address was cleared. In that case the source
should be left unspecified and selected by ip6_dst_lookup_flow().
For IPv4, inet_confirm_addr(..., local = 0, ...) asks for local address
autoselection rather than validating a chosen source. Skip the precheck
there as well and let ip_route_output_flow select or reject the source.
Only validate non-zero/non-any source addresses.
Fixes: 08857b5ec5d9 ("ovpn: implement basic TX path (UDP)")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
---
No changes since v2 https://lore.kernel.org/openvpn-devel/cb51001bfdaeba899b6ca9b22186ea2ebb49c23c.1785308184.git.ralf@mandelbit.com/
No changes since v1 https://lore.kernel.org/openvpn-devel/cb51001bfdaeba899b6ca9b22186ea2ebb49c23c.1785253480.git.ralf@mandelbit.com/
drivers/net/ovpn/udp.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c index 7f69e8890b5b..df4750dabd1e 100644 --- a/drivers/net/ovpn/udp.c +++ b/drivers/net/ovpn/udp.c @@ -161,8 +161,8 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind, if (rt) goto transmit; - if (unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0, fl.saddr, - RT_SCOPE_HOST))) { + if (fl.saddr && unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0, + fl.saddr, RT_SCOPE_HOST))) { /* we may end up here when the cached address is not usable * anymore. In this case we reset address/cache and perform a * new look up @@ -238,7 +238,8 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind, if (dst) goto transmit; - if (unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) { + if (!ipv6_addr_any(&fl.saddr) && + unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) { /* we may end up here when the cached address is not usable * anymore. In this case we reset address/cache and perform a * new look up