From patchwork Tue Sep 15 15:23:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5345 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp5064926mag; Tue, 15 Sep 2026 08:26:03 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwiTFbdSyuqY884FZvr21qbBaJyTaZ/x6jMPDcmosQds8hYrF8OfvHBsFuIA+wO5FKdqs1g8pcJF8s=@openvpn.net X-Received: by 2002:a05:6870:3c0d:b0:46a:e0c1:6b34 with SMTP id 586e51a60fabf-481f94edd6amr10661066fac.12.1789485861834; Tue, 15 Sep 2026 08:24:21 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789485861; cv=none; d=google.com; s=arc-20260327; b=nY3KDby0ru4Wk7ZiuEnqYWhkO4P2gMk8ujR07+hxBRKL+GG1uxcu23xdYFyEEqyqNu KejJh077gDER3PQ8nsU7BD1yErmhXIAppC752Pd6tdU4ASJRWa8YQpOCjgSJzZQp0Zx3 NjylyKSguq0EFIQnYqRNKXarhFFq+E0ZARHahCYhABKW0WQ8hOs9jvecPPyA5cZsybXw RWQw7jSo1AvcWYV8YnGBfjwiGnS/JC04z5B0ZuqKmMgwIeL0cOfFbseTqq7OE7wfMYL6 MuUKewlvTgTiiNVmY6M/7nVImzDRIM+CNevU4cQiIY2GxtUEoWz+YM2eJANCaRa8Pkqs p/4Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=PJFlxf6DvHbxep4kldQFnVa65oEFoZADIy767GjhKEA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=mMt9Kdm//A7mAP4SlQd8ifCTzLCxh1ykKkIhe2b5jUudTiWhzbEXB+GbJn2RdJCW4E LHQU2Q3VTHEcCwORYV7zRDJrwNU1Ye6UT7Qxevs0JqHf5X5vC/TyBSw0wwpTnpXVkp/k bNTV2GuAxI7CexU2qLaY3lBAiltBMeG9KAJcFOh8iD52EQlWy/dk3ipcx5DT7YA5ottK t7FnkGCFvFkRkkDjFmtlU7607SOG9uoJHrKBCeIe9jOz8f9nQSoaZWk4k4+7D1MVVJTk Ey/mVPoCROME2KsyP1SbKZlTRX3zduPhIgCIBMNB7f0410LgriINqj5ycNJx1dp+Zx5N /mbg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ONdBfeRo; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EuZouNdn; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=SFzPdMNA; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=O09c0CTs; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-47df961d79csi11323480fac.235.2026.09.15.08.24.21 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 15 Sep 2026 08:24:21 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ONdBfeRo; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EuZouNdn; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=SFzPdMNA; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=O09c0CTs; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=PJFlxf6DvHbxep4kldQFnVa65oEFoZADIy767GjhKEA=; b=ONdBfeRoovy0tajPo218JKdlDf ktNA5ASIW/JFU+W2HZ+tvHF4WSLMY4lo0ULB3C6n5mLSVWjniPuXfu9ktZLnO0T3dtjSBkwvlEfKv fVI6hCQwwwEIaKK5K2kSqIhG+VEhRMxnldN4Trg+CtvcksF3gLuF2HErrPy1pGJ+Yrpo=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x6V15-0005pi-2T; Tue, 15 Sep 2026 15:24:15 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x6V12-0005pT-FX for openvpn-devel@lists.sourceforge.net; Tue, 15 Sep 2026 15:24:13 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=GKJOL2XeKLv1y8rVhqwEbNqapdsR912FCXVnp63S2KI=; b=EuZouNdnCNkXVBaDjUiqjbQGh/ 07viJL2vfHv3hqmtAerc61++sDb/03SAoojnAAmic17ZBivlIwYFoivx0EDMVm3YoutnCLxuc1ArW 4z9t1mbWJwIX8WJ37gCzr4Ah6Wq1+4xASN67JwuLqVVot2RUUDldBeWH2sZ2xgHa3jtc=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=GKJOL2XeKLv1y8rVhqwEbNqapdsR912FCXVnp63S2KI=; b=SFzPdMNAiUg/m6A+mmkojulnLa 72id7ENpLtf6khDvUooMxA3UkRsOq3uIfP0O2GsMaSEctYDE006jsYHki8jZIZzvgp+nkp7KjgCIY wrXIX1pU4rfjRg8fAUgd9KmdPjYHxH3ZsolHczsBLvFfbWpfGRum6xqbCm/u+gIqYy8o=; Received: from mout-b-210.mailbox.org ([195.10.208.40]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x6V11-0003bO-GG for openvpn-devel@lists.sourceforge.net; Tue, 15 Sep 2026 15:24:12 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-210.mailbox.org (Postfix) with ESMTPS id 4hkm5G4KvKzFqwg for ; Tue, 15 Sep 2026 17:24:02 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1789485842; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=GKJOL2XeKLv1y8rVhqwEbNqapdsR912FCXVnp63S2KI=; b=O09c0CTsHAb9mdnk4nBD5O8upwTGGamA9Tnm1/fE15XxwGNIWTnNBc+NvYk+fHeEyK9c5z QeOsPzLenuHSD/lwj5CgCcY3tFVQpJrtQA1+FvyMte/O4tPDd+09BBjd5wHahCzsBE1XcQ PsWUKYKYOmUSGlEG4NmELtpPpBlnB6jCWTaakNBqvEBmrwXc6k/gBhnMenk6hIOZPduoBY lpE7or5Dd6nZ0nlf4BKoBK/N7EImRLYpa54+MGVOVkBeLp2rPuFsvPQU0W/hAjuXC4Yfug V0VBlArnATtUHRRKbpyy1vr4l2euukOPaHW4wuN00Kg8MI80EktjAqR+3Az3Yw== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Tue, 15 Sep 2026 17:23:50 +0200 Message-ID: <5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789485693.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST when the receiving host has no local TCP socket for the flow. Although ovpn segments every GSO input itself, it does not advertise NETIF_F_ [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1x6V11-0003bO-GG Subject: [Openvpn-devel] [RFC ovpn net-next 2/9] ovpn: accept frag-list GSO input X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876411927015035984 X-GMAIL-MSGID: 1876411927015035984 Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST when the receiving host has no local TCP socket for the flow. Although ovpn segments every GSO input itself, it does not advertise NETIF_F_FRAGLIST, so generic transmit validation segments these aggregates before calling ovpn_net_xmit. That segmentation is functionally correct, but causes ovpn_net_xmit to be invoked separately for every resulting packet. Advertise frag-list storage so ovpn receives the aggregate intact and performs protocol validation and destination-to-peer lookup once before segmenting it. Frag-list GSO segmentation recovers the complete child skbs, which can then be encrypted in place and transmitted independently. Rebuilding those children into a replacement UDP GSO aggregate was found to add cost rather than improve throughput. The feature also admits non-GSO frag lists, which describe one packet split across several skbs. Let skb_cow_data preserve small lists directly. If a list exceeds the AEAD scatterlist limit, linearize it and continue rather than rejecting an otherwise valid packet. Signed-off-by: Ralf Lici --- drivers/net/ovpn/crypto_aead.c | 8 ++++++-- drivers/net/ovpn/main.c | 3 ++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/drivers/net/ovpn/crypto_aead.c b/drivers/net/ovpn/crypto_aead.c index 74eaf6fac2f5..2af493fd5735 100644 --- a/drivers/net/ovpn/crypto_aead.c +++ b/drivers/net/ovpn/crypto_aead.c @@ -168,8 +168,12 @@ int ovpn_aead_encrypt(struct ovpn_peer *peer, struct ovpn_crypto_key_slot *ks, if (unlikely(nfrags < 0)) return nfrags; - if (unlikely(nfrags + 2 > (MAX_SKB_FRAGS + 2))) - return -ENOSPC; + if (unlikely(nfrags > MAX_SKB_FRAGS)) { + ret = skb_linearize(skb); + if (unlikely(ret)) + return ret; + nfrags = 1; + } /* allocate temporary memory for iv, sg and req */ tmp = kmalloc(ovpn_aead_crypto_tmp_size(ks->encrypt, nfrags), diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 28e1eb06e127..ac4e0d85e215 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -158,7 +158,8 @@ static const struct ethtool_ops ovpn_ethtool_ops = { static void ovpn_setup(struct net_device *dev) { netdev_features_t feat = NETIF_F_HW_CSUM | NETIF_F_SG | NETIF_F_GSO | - NETIF_F_GSO_SOFTWARE | NETIF_F_HIGHDMA; + NETIF_F_GSO_SOFTWARE | NETIF_F_FRAGLIST | + NETIF_F_HIGHDMA; dev->needs_free_netdev = true;