| Message ID | 5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789558856.git.ralf@mandelbit.com |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp6082449mag;
Wed, 16 Sep 2026 04:47:09 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AKwUvBztewEsBRstpbe+s/MdLyvMZdFovm6KBmNt2x52DMXnELVUzttJ+BcuP1tddpUQzEODjYGBSYEpjO0=@openvpn.net
X-Received: by 2002:a05:6830:2684:b0:7eb:3af8:8c09 with SMTP id
46e09a7af769-80b2be8262fmr2912772a34.3.1789559228923;
Wed, 16 Sep 2026 04:47:08 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789559228; cv=none;
d=google.com; s=arc-20260327;
b=hWE+hFf6xTVDo44n3kwkg8Gtirze6SWaK+grgG6ddcR92n2lNdEwr2TzZUvQiFixLQ
5lqpRydZ/6zSL0fF8eciwm69xQwMI4BBz2WwKnz9bjYrZtAeBIFe8SurJ2ehUXjqwCYh
FhTi8Zuok3JJC0zv11OVWJFbFKYFTNL5XzYioo2l+QmC9woVul7I3aeSECYfUrqDIIdu
fzkLH3rNsG0mKO3A954km7ceWcvzwMQGX38Pecg/HXVkqFukGeci4kCg3GydyB/zOJE4
9zjGlaThLmp9QG6r3E6iS5op5yiZzYCyHjx9gLnCP7lPTMFp6FNxIR9dBW7m+tfgC/d2
WXTw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=NrT5bfNUdQJlGBtcLpJ9yg6gPy1nTO9utIlO8zH8n24=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=O+hc6gUJIJCaLAPCWf6Al/8t/X0tsYJ3gJGBbIe1MfuuBTvFk8xC7WYymE1IgMuyyR
67IXTHe1vgIhRH2C92zuapHHQRrHL7vAbEtfnf51zvxsTBIgkZ1sQaPaTEABqVi1I4Hg
VPkgUUcalPFFBlwwAmuvSGn4p/IqK8w5XmuulxONY6VEofJbf93Qq3jV6EUmddr8PpHA
F42q+//gI5n3P9SPKVQGWBY8y7HYTKm6hjN+QinJPOzKi0L802niqa4iWhke7ps9djXt
kjnv+nZg5S40bf+Wc7Xtg4o9omJQfOHvQQChqxt1vp780Y69xHUCEWnk+ejc5WyMFKNt
ELyg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=d1RIQ5Kb;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=mFUeMZdz;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=QtmJZxHA;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=ElVXXbXC;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-80b04bf447esi3743076a34.20.2026.09.16.04.47.08
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 16 Sep 2026 04:47:08 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=d1RIQ5Kb;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=mFUeMZdz;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=QtmJZxHA;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=ElVXXbXC;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=NrT5bfNUdQJlGBtcLpJ9yg6gPy1nTO9utIlO8zH8n24=; b=d1RIQ5Kb/Bzr25jqyXyuQvfCBF
Cxp/+/mRcHDFSYOEZLMIKkkCP44TthPSWVDWZAOO4PJQJHKQPxw8Rxt7X8wdSML2wCqic6eDsdmzV
ZvK7rY/OJLuLc5tzYmGSmz9BHet7+OgWTu+nYanxidb1Z47YZNbD2CfAuGfZnlydbutg=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1x6o6O-0006eu-Ux;
Wed, 16 Sep 2026 11:47:00 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1x6o6M-0006el-Nd
for openvpn-devel@lists.sourceforge.net;
Wed, 16 Sep 2026 11:46:59 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=tWYKNcc1OFIeVJrh/5V++4+gbS7idj2SJXZM7bNQgBE=; b=mFUeMZdzGOKnZz3b78Fx9Fp+29
3r6g9WwmV10O1bkj/mHPFWFLAkNtKSFAnKtdMed4UUmZ6FYd9wHZmgS1r4uRj2J8kp56JD9jZwRrG
PWKkc8RbAavRoN8KohFDlilpN44lqBr8SAwvQ0xzusyczN7sVgq6I4GPWzJoj0hwFsE4=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=tWYKNcc1OFIeVJrh/5V++4+gbS7idj2SJXZM7bNQgBE=; b=QtmJZxHAgERdUhReOEbseDIY0N
/Lk5QUy+BkE/TLidovVFpEE+Fv6UbT/y5lWyz7covhjgbiT+ovRNZ5vYB7eViUcBHsX5kQxq+Fnzu
DNk7CMChqXuWdjzRAkjU926sjxxH/EXh6LH9TEZMapM0bPnNOHoFun7MxevtfVPyHmA0=;
Received: from mout-b-202.mailbox.org ([195.10.208.62])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1x6o6L-0001Vx-4o for openvpn-devel@lists.sourceforge.net;
Wed, 16 Sep 2026 11:46:58 +0000
Received: from smtp1.mailbox.org (smtp1.mailbox.org
[IPv6:2001:67c:2050:b231:465::1])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-202.mailbox.org (Postfix) with ESMTPS id 4hlHCp0B21zKmBJ
for <openvpn-devel@lists.sourceforge.net>;
Wed, 16 Sep 2026 13:46:30 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1789559190;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=tWYKNcc1OFIeVJrh/5V++4+gbS7idj2SJXZM7bNQgBE=;
b=ElVXXbXCcDl9q/0BYnA8Ek3G1BYyQuXGhlCyBdfydWuYQ4sT9ow2H1yMxPCG5tBvEKC7mR
a8Gu5giEsexmeyan/dbUHIOdb99YvOhRiE6bk6F6JeYwEIkq2S8beZgQD/vq1Rjyt8aDI+
wwDpwDz/irrDPUXC6gDWg56pmoWQZBtt3QsPaEmsgmio75Lfi3IZCDy4Qo6vMqUtOOjS+E
nQ0YhRN3LPSJVH5weIeHd3MkExvyG+rP+cTTzbASZh5RefBc9LjCxBS6G7f/ItyKQehxg+
8WSrbS4G8vNtj93ZWhL2Au96lgHNlJrvTXNeaAeIclVHnjNODoWh6EsT9OW8kw==
Authentication-Results: outgoing_mbo_mout; dkim=none;
spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates
2001:67c:2050:b231:465::1 as permitted sender)
smtp.mailfrom=ralf@mandelbit.com
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 16 Sep 2026 13:46:10 +0200
Message-ID:
<5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789558856.git.ralf@mandelbit.com>
In-Reply-To: <cover.1789558856.git.ralf@mandelbit.com>
References: <cover.1789558856.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Rspamd-Queue-Id: 4hlHCp0B21zKmBJ
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST
when the receiving host has no local TCP socket for the flow. Although ovpn
segments every GSO input itself, it does not advertise NETIF_F_ [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[195.10.208.62 listed in wl.mailspike.net]
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1x6o6L-0001Vx-4o
Subject: [Openvpn-devel] [RFC ovpn net-next v4 2/9] ovpn: accept frag-list
GSO input
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1876488857940299054
X-GMAIL-MSGID: 1876488857940299054
|
| Series |
ovpn: preserve GSO and GRO batching
|
|
Commit Message
Ralf Lici
Sept. 16, 2026, 11:46 a.m. UTC
Forwarded TCP traffic can be coalesced into SKB_GSO_FRAGLIST when the
receiving host has no local TCP socket for the flow. Although ovpn
segments every GSO input itself, it does not advertise NETIF_F_FRAGLIST,
so generic transmit validation segments these aggregates before calling
ovpn_net_xmit. That segmentation is functionally correct, but causes
ovpn_net_xmit to be invoked separately for every resulting packet.
Advertise frag-list storage so ovpn receives the aggregate intact and
performs protocol validation and destination-to-peer lookup once before
segmenting it. Frag-list GSO segmentation recovers the complete child
skbs, which can then be encrypted in place and transmitted
independently. Rebuilding those children into a replacement UDP GSO
aggregate was found to add cost rather than improve throughput.
The feature also admits non-GSO frag lists, which describe one packet
split across several skbs. Let skb_cow_data preserve small lists
directly. If a list exceeds the AEAD scatterlist limit, linearize it and
continue rather than rejecting an otherwise valid packet.
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
---
No changes since v3 https://lore.kernel.org/openvpn-devel/5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789546917.git.ralf@mandelbit.com/
No changes since v2 https://lore.kernel.org/openvpn-devel/5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789540779.git.ralf@mandelbit.com/
No changes since v1 https://lore.kernel.org/openvpn-devel/5baa1d94e29e7b109ffd412b4f1d5d113a319389.1789485693.git.ralf@mandelbit.com/
drivers/net/ovpn/crypto_aead.c | 8 ++++++--
drivers/net/ovpn/main.c | 3 ++-
2 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ovpn/crypto_aead.c b/drivers/net/ovpn/crypto_aead.c index 74eaf6fac2f5..2af493fd5735 100644 --- a/drivers/net/ovpn/crypto_aead.c +++ b/drivers/net/ovpn/crypto_aead.c @@ -168,8 +168,12 @@ int ovpn_aead_encrypt(struct ovpn_peer *peer, struct ovpn_crypto_key_slot *ks, if (unlikely(nfrags < 0)) return nfrags; - if (unlikely(nfrags + 2 > (MAX_SKB_FRAGS + 2))) - return -ENOSPC; + if (unlikely(nfrags > MAX_SKB_FRAGS)) { + ret = skb_linearize(skb); + if (unlikely(ret)) + return ret; + nfrags = 1; + } /* allocate temporary memory for iv, sg and req */ tmp = kmalloc(ovpn_aead_crypto_tmp_size(ks->encrypt, nfrags), diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 28e1eb06e127..ac4e0d85e215 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -158,7 +158,8 @@ static const struct ethtool_ops ovpn_ethtool_ops = { static void ovpn_setup(struct net_device *dev) { netdev_features_t feat = NETIF_F_HW_CSUM | NETIF_F_SG | NETIF_F_GSO | - NETIF_F_GSO_SOFTWARE | NETIF_F_HIGHDMA; + NETIF_F_GSO_SOFTWARE | NETIF_F_FRAGLIST | + NETIF_F_HIGHDMA; dev->needs_free_netdev = true;