| Message ID | 87624efbd20845abc23ebde353e82d5a90e0325c.1787925761.git.ralf@mandelbit.com |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp51124mab;
Fri, 28 Aug 2026 07:50:59 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RrrVRVFxZS7Yha679+pcZz7x551DK8YoRzX/KmlLNBjZfNYJyt2Kcf/JFFuRw2sSlx2qWH22zwy8II=@openvpn.net
X-Received: by 2002:a05:6830:680f:b0:7f4:c88c:7b10 with SMTP id
46e09a7af769-7f4f24de4efmr8575413a34.12.1787928659236;
Fri, 28 Aug 2026 07:50:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787928659; cv=none;
d=google.com; s=arc-20260327;
b=WJIv3nSs2CoCMpyVgizBoTFBDg2NF7eKoAbtdYt/7pgFgzV00GUt8ChVZ2SKqG/3GM
P7MRtW5kM/f4jX/oW55tG748Z9ksGrVEHF7SijQa2A3BjAQ64vTEVY3DqF3pDXgkgNPm
N8gm/OjQAFkytO3tEwrbIPrtD2ukz41il4iLZjcDBfHw16zNhHxM1onulTFPwJpD9Dzi
DO0bX5U1pqdiVVw2EnfwlfRKhS5A5PhlK+pOSrFt7PCuZ4J0u89SbN1t+2d9Kg+Xb7dr
HNv2K+TGb+4CjfaOUseWTM1d4pJy747Xyni1ZVvAPRFRugsEeXYFuw9dbn9gC3yHZ8Gt
XUbw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=BpStNCLB/icquu9vAztURt9kx1UAANcphcF4V2xD0b4=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=CxSq5Xzp/JDHpPN+bbFTyL+4RtAdAKGCoOJb1H4tdu8HLCujvnbmIOdznUwSMonBuP
tjiN+15BpSIrqwQ788p1vJ6glAWDg7fPwXSKhPpTaK0A41CQf28J97Azda9Cer+6UzYv
wUYShqpe3tRwWpSLl18pKJmRdl0x18pfD7uDN93msdP3S51MaWVyJd5bFRnvnACWkz3K
hJC4EV84SV0TVLRLeo8hCjDMnot20pYTzQ4iby584TGCNwz8+hU2JzE/zAd8mZ3C7bye
vY8sFetv3PIOCWhrurp0JuKDhIl6jn6m5eMgcdpayEoYu9moLsVYcMirExZUc97ZQUIF
1iDw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=OaTJ5bGS;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=Q52bIxvx;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=DfSdMQEh;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b="d/hrcb7f";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-7f4fa7c9a9asi2808481a34.26.2026.08.28.07.50.57
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 28 Aug 2026 07:50:58 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=OaTJ5bGS;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=Q52bIxvx;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=DfSdMQEh;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b="d/hrcb7f";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=BpStNCLB/icquu9vAztURt9kx1UAANcphcF4V2xD0b4=; b=OaTJ5bGSAdypXqfPhKlkffB+iU
6150ZleDt+2CxsdGjQmT6/fP+eA1XLXg7Ec/moq32zcRcuTE8Ls92ljPOBeb9T8xotXUhzkvDBxY7
5g8SMN+qwGi3hjB0aVNeSTQWOYWBWNyY5wHLN6KKonUNpxu2rVnMsKC9sGMDAS6v+J5M=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wzxuw-0003lB-Fn;
Fri, 28 Aug 2026 14:50:54 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1wzxuu-0003l4-N4
for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:52 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=; b=Q52bIxvxLRn+GlPGmbV84zQtDx
87oky0AJiH+Qs9WpN/xobQJBuGhA/ZKBxkXzaUJDQucDATW7Ec3TYq5PhvoF6RUeUHeZPbP7ID6OF
Uk8koQF8IFrIYzrO0+L4yVe7Cy95YRztk065SnkxTUuNJVpAeBOZwBQD+ACmu9bH9pYk=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=; b=DfSdMQEhIj7riUTG+nJdzoTQca
KxqDBUd6EUd4SS5qgE3GH2TDVHqQX3tQasXHGWU/EivAF0FijPqBaAj/O0GU3/HmRchFUGeQGNgf+
zREORtzq7HX52HzthkmNy/qBslBZORjozyK1uLPaUuGDT+7WH9eMboIo+IwIkITH/8qk=;
Received: from mout-b-110.mailbox.org ([195.10.208.55])
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wzxuq-0005qV-AU for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:52 +0000
Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4hWhC35fcxzNlf3
for <openvpn-devel@lists.sourceforge.net>;
Fri, 28 Aug 2026 16:50:39 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1787928639;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=;
b=d/hrcb7f9wFxV8g0RxyefADHIRw4TfGzb+fsHAEy3w6CkdzI3TCLexeTdYj08cwsRQF7xh
8Fgz5JULPRBUlrE9DjTRx1ikngn4BHRr9uvSTJdqr78hbgkYDuFK3JrhWVoCE/CjlmxpTu
JSvRX0ESOCpGsdrs1c68sdWuMqDj505SrQeySLCOz1jUXfMJfMtCq38lBfhH5Jjid5dHEf
z7l58ixzDQPfCee6XwfoYB3LzjSx3PRWaKB9yjoRS7UpfnKXiVrZ8amD7rCGXz3DK8i6Hp
OnNqhyFDfQoxHLC17nWsiBAPFd2hJSd57vo4yB9gyE1V92WiM6knHUI/aWrclA==
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 28 Aug 2026 16:50:22 +0200
Message-ID:
<87624efbd20845abc23ebde353e82d5a90e0325c.1787925761.git.ralf@mandelbit.com>
In-Reply-To: <cover.1787925761.git.ralf@mandelbit.com>
References: <cover.1787925761.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports
bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser
never copied the attribute into the sockaddr_in6 used to create [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1wzxuq-0005qV-AU
Subject: [Openvpn-devel] [PATCH ovpn net v3 1/6] ovpn: preserve IPv6 scope
id for netlink peer endpoints
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1874779080549191326
X-GMAIL-MSGID: 1874779080549191326
|
| Series |
ovpn: fix UDP route cache and endpoint handling
|
|
Commit Message
Ralf Lici
Aug. 28, 2026, 2:50 p.m. UTC
ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports
bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint
parser never copied the attribute into the sockaddr_in6 used to create or
update the peer bind.
As a result, an IPv6 link-local remote endpoint configured through
netlink loses its interface scope, unlike on the peer float path where
ipv6_iface_scope_id populates the field. The UDPv6 output path then
builds a flow with flowi6_oif set to zero and route lookup can fail or
select the wrong interface.
Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The
existing precheck already rejects the scope-id attribute for IPv4 and
v4-mapped IPv6 remotes.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
---
No changes since v2 https://lore.kernel.org/openvpn-devel/87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785308184.git.ralf@mandelbit.com/
No changes since v1 https://lore.kernel.org/openvpn-devel/87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785253480.git.ralf@mandelbit.com/
drivers/net/ovpn/netlink.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 4dad85294198..2ba762082acc 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, struct sockaddr_in6 *sin6; struct sockaddr_in *sin; struct in6_addr *in6; + struct nlattr *scope; + u32 scope_id = 0; __be16 port = 0; __be32 *in; @@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, } else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) { ss->ss_family = AF_INET6; in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]); + scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID]; + if (scope) + scope_id = nla_get_u32(scope); } else { return false; } @@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, if (!ipv6_addr_v4mapped(in6)) { sin6 = (struct sockaddr_in6 *)ss; sin6->sin6_port = port; + sin6->sin6_scope_id = scope_id; memcpy(&sin6->sin6_addr, in6, sizeof(*in6)); break; }