From patchwork Wed Sep 16 06:52:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5355 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp5853283mag; Tue, 15 Sep 2026 23:53:20 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwb7jifxRG3cmVmdA0g/xh+/Vy4IEh+DM2l52/e5qif+N0Q0XvN9OrArhrxRaKuFfcaVq8ILAHmCMA=@openvpn.net X-Received: by 2002:a05:6820:c3d2:10b0:6b9:7d9e:5708 with SMTP id 006d021491bc7-6c7d15cebe7mr2822900eaf.3.1789541600281; Tue, 15 Sep 2026 23:53:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789541600; cv=none; d=google.com; s=arc-20260327; b=PW3ZPux3TgEYVgq3nmPkgsEEQ0Ep7zJbOluto2zkKIlWFcAuQo+wTyeHeIKKjHszQz BKXDVF13wzrOYFHlvMbxEnNe9tV6bV32Dao53iwLZCRONqj2mmO2Q2u+yJBxsLAdJ0q1 WRW3humfWzVfw/y+k9ipoS6nnejI0U0nheHuqNChujUiUKnwpN5L/JV/wLPaK5p7CGL4 Krw09rzYVK+zr1/CXElnJ3jFrtOzMoQNHGgCa4PlYxCQcINfr31VsC0rPEcqXBzlvbkW KDo+YbS1IJnBwlSGtMPH+zFUy2Trpj4Wh0mgO6L6xWKexXxKI/1eGccbFw7UICvkRhqu pNNQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=mxm8eVdBoVBQHbQC+vqCA0pgfKSu4owbZEC3wgxENsc=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=IH6XiGNON1GW3VmaLu7lQjUyZ9fjhq5gT5YH7pgka5sUD+ZCW5uQkbQAYp1MP9W2WN 0THlNQKSfWW452iNp4L2xVFQq7EHoqyRWdlnU20EvZexWlhLv6T+rcfRo4bEVhFj4sPN cz7PM0xQegs/XDVMqL0vGkQ2YDuE31EI7TW3mdd6zPUkuTk1K22AnAM02LJTwKWW7iPu W6Zx4/qDe9i6oNpAEX+2ouefEhmpfvaPV8SgJiPD6T8s66T/DBXzFE8HoNVtLKm06vk7 qJbvmU5fymTePzrb31b7cRNKq4L4iqrVn9CSQ57mzFHNxlIS9bvygy32Pnk91iP7uPTf /BbQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Brj+QsjX; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=e8GRi46b; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=SyCGqdUO; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=dok8doYm; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-80b081ed126si2451919a34.76.2026.09.15.23.53.20 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 15 Sep 2026 23:53:20 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Brj+QsjX; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=e8GRi46b; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=SyCGqdUO; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=dok8doYm; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=mxm8eVdBoVBQHbQC+vqCA0pgfKSu4owbZEC3wgxENsc=; b=Brj+QsjXkAfImItG8eGpvxBvUr o2lGcIQtiNUKXdWItg8GWclvVD2C1Jgvn8MUko1v2ULoz07S0sTyLJrtgmkE2sGtFXD5Z/55dhEU5 MpZ4PttKgErebvDMZ6OxwVJFlCf4M2HAEdnIAS4Nheoqg6udKKPlfZVj39Ggsybuomd4=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x6jW1-00042N-WF; Wed, 16 Sep 2026 06:53:10 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x6jW0-000425-0G for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 06:53:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=MZVjiga8pyIY9u8NzfX8XEMiodR9+oFFncj7fLYshsA=; b=e8GRi46bmUK5YEN5GQ+LK5gmfo yc3lZ0442ghPbKh0qMZ/3KT+J6ygWarOWpAP1oZjZSut3K30klJECB1ZfrBXrav5sz0fWSmoCbPpw VutnJEMf+W4wr9Q0r88UKNxcNEE9tF+4Ty7XisvFQp+baJLqullr5LgBlJa/UTFgZdw0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=MZVjiga8pyIY9u8NzfX8XEMiodR9+oFFncj7fLYshsA=; b=SyCGqdUOGp2U3JpzHFGtaIMk/t dqMsKSADty7CL+r17pYmgHg6YqQSeoEFaXbaw02a7s8JLi+u1uCM6wc3j2wC9RdWzLs4qI2uw/WuN YRtKZysTb0Dcp6NZ8zQ6Gler9QU/DJCVlhUQ8k08YlrijYlP6og0tHqQBdcOu3Dgwsh8=; Received: from mout-b-112.mailbox.org ([195.10.208.42]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x6jVz-0001sb-70 for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 06:53:08 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-112.mailbox.org (Postfix) with ESMTPS id 4hl8j66Zhsz5wh1 for ; Wed, 16 Sep 2026 08:52:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1789541578; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=MZVjiga8pyIY9u8NzfX8XEMiodR9+oFFncj7fLYshsA=; b=dok8doYm5tI2lyVG9WktR9opJIIFQBLnkxwEBo+DOvc919OSRhyrG/ZcDSDQSJvD+De4cn hS4bskrc6eLTZ6+xMCmQHL7KMfsP8Uk605/0Gd8vB6sVpJvHx1l0tM2dLjmH3cwTY48QJV u1Wf7s9QmVYoZ1RWKTrdLAHulW/n66o6/RQ6Mr0ripni8Od6LsaGabTizqIIuCraTlJVno uF5nkjAjgA8Un76vBeOnPtzMEAwYzl4zUdKTHwVjc+nYPZESjxM28HABTpRfJ2tK9KoXPp zEJpCjIE96+nwqYw6i/ezXTVx3458ikjfjH1BOUVv2vokOP/LRgRUFbsL2zN3w== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 16 Sep 2026 08:52:43 +0200 Message-ID: <5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789540779.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hl8j66Zhsz5wh1 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST when the receiving host has no local TCP socket for the flow. Although ovpn segments every GSO input itself, it does not advertise NETIF_F_ [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1x6jVz-0001sb-70 Subject: [Openvpn-devel] [RFC ovpn net-next v2 2/9] ovpn: accept frag-list GSO input X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876470373092731855 X-GMAIL-MSGID: 1876470373092731855 Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST when the receiving host has no local TCP socket for the flow. Although ovpn segments every GSO input itself, it does not advertise NETIF_F_FRAGLIST, so generic transmit validation segments these aggregates before calling ovpn_net_xmit. That segmentation is functionally correct, but causes ovpn_net_xmit to be invoked separately for every resulting packet. Advertise frag-list storage so ovpn receives the aggregate intact and performs protocol validation and destination-to-peer lookup once before segmenting it. Frag-list GSO segmentation recovers the complete child skbs, which can then be encrypted in place and transmitted independently. Rebuilding those children into a replacement UDP GSO aggregate was found to add cost rather than improve throughput. The feature also admits non-GSO frag lists, which describe one packet split across several skbs. Let skb_cow_data preserve small lists directly. If a list exceeds the AEAD scatterlist limit, linearize it and continue rather than rejecting an otherwise valid packet. Signed-off-by: Ralf Lici --- No changes since v1 https://lore.kernel.org/openvpn-devel/5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789485693.git.ralf@mandelbit.com/ drivers/net/ovpn/crypto_aead.c | 8 ++++++-- drivers/net/ovpn/main.c | 3 ++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/drivers/net/ovpn/crypto_aead.c b/drivers/net/ovpn/crypto_aead.c index 74eaf6fac2f5..2af493fd5735 100644 --- a/drivers/net/ovpn/crypto_aead.c +++ b/drivers/net/ovpn/crypto_aead.c @@ -168,8 +168,12 @@ int ovpn_aead_encrypt(struct ovpn_peer *peer, struct ovpn_crypto_key_slot *ks, if (unlikely(nfrags < 0)) return nfrags; - if (unlikely(nfrags + 2 > (MAX_SKB_FRAGS + 2))) - return -ENOSPC; + if (unlikely(nfrags > MAX_SKB_FRAGS)) { + ret = skb_linearize(skb); + if (unlikely(ret)) + return ret; + nfrags = 1; + } /* allocate temporary memory for iv, sg and req */ tmp = kmalloc(ovpn_aead_crypto_tmp_size(ks->encrypt, nfrags), diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 28e1eb06e127..ac4e0d85e215 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -158,7 +158,8 @@ static const struct ethtool_ops ovpn_ethtool_ops = { static void ovpn_setup(struct net_device *dev) { netdev_features_t feat = NETIF_F_HW_CSUM | NETIF_F_SG | NETIF_F_GSO | - NETIF_F_GSO_SOFTWARE | NETIF_F_HIGHDMA; + NETIF_F_GSO_SOFTWARE | NETIF_F_FRAGLIST | + NETIF_F_HIGHDMA; dev->needs_free_netdev = true;