From patchwork Fri Aug 28 14:50:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5297 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp51124mab; Fri, 28 Aug 2026 07:50:59 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RrrVRVFxZS7Yha679+pcZz7x551DK8YoRzX/KmlLNBjZfNYJyt2Kcf/JFFuRw2sSlx2qWH22zwy8II=@openvpn.net X-Received: by 2002:a05:6830:680f:b0:7f4:c88c:7b10 with SMTP id 46e09a7af769-7f4f24de4efmr8575413a34.12.1787928659236; Fri, 28 Aug 2026 07:50:59 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787928659; cv=none; d=google.com; s=arc-20260327; b=WJIv3nSs2CoCMpyVgizBoTFBDg2NF7eKoAbtdYt/7pgFgzV00GUt8ChVZ2SKqG/3GM P7MRtW5kM/f4jX/oW55tG748Z9ksGrVEHF7SijQa2A3BjAQ64vTEVY3DqF3pDXgkgNPm N8gm/OjQAFkytO3tEwrbIPrtD2ukz41il4iLZjcDBfHw16zNhHxM1onulTFPwJpD9Dzi DO0bX5U1pqdiVVw2EnfwlfRKhS5A5PhlK+pOSrFt7PCuZ4J0u89SbN1t+2d9Kg+Xb7dr HNv2K+TGb+4CjfaOUseWTM1d4pJy747Xyni1ZVvAPRFRugsEeXYFuw9dbn9gC3yHZ8Gt XUbw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=BpStNCLB/icquu9vAztURt9kx1UAANcphcF4V2xD0b4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=CxSq5Xzp/JDHpPN+bbFTyL+4RtAdAKGCoOJb1H4tdu8HLCujvnbmIOdznUwSMonBuP tjiN+15BpSIrqwQ788p1vJ6glAWDg7fPwXSKhPpTaK0A41CQf28J97Azda9Cer+6UzYv wUYShqpe3tRwWpSLl18pKJmRdl0x18pfD7uDN93msdP3S51MaWVyJd5bFRnvnACWkz3K hJC4EV84SV0TVLRLeo8hCjDMnot20pYTzQ4iby584TGCNwz8+hU2JzE/zAd8mZ3C7bye vY8sFetv3PIOCWhrurp0JuKDhIl6jn6m5eMgcdpayEoYu9moLsVYcMirExZUc97ZQUIF 1iDw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=OaTJ5bGS; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Q52bIxvx; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=DfSdMQEh; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="d/hrcb7f"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f4fa7c9a9asi2808481a34.26.2026.08.28.07.50.57 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 07:50:58 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=OaTJ5bGS; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Q52bIxvx; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=DfSdMQEh; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="d/hrcb7f"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=BpStNCLB/icquu9vAztURt9kx1UAANcphcF4V2xD0b4=; b=OaTJ5bGSAdypXqfPhKlkffB+iU 6150ZleDt+2CxsdGjQmT6/fP+eA1XLXg7Ec/moq32zcRcuTE8Ls92ljPOBeb9T8xotXUhzkvDBxY7 5g8SMN+qwGi3hjB0aVNeSTQWOYWBWNyY5wHLN6KKonUNpxu2rVnMsKC9sGMDAS6v+J5M=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzxuw-0003lB-Fn; Fri, 28 Aug 2026 14:50:54 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzxuu-0003l4-N4 for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 14:50:52 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=; b=Q52bIxvxLRn+GlPGmbV84zQtDx 87oky0AJiH+Qs9WpN/xobQJBuGhA/ZKBxkXzaUJDQucDATW7Ec3TYq5PhvoF6RUeUHeZPbP7ID6OF Uk8koQF8IFrIYzrO0+L4yVe7Cy95YRztk065SnkxTUuNJVpAeBOZwBQD+ACmu9bH9pYk=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=; b=DfSdMQEhIj7riUTG+nJdzoTQca KxqDBUd6EUd4SS5qgE3GH2TDVHqQX3tQasXHGWU/EivAF0FijPqBaAj/O0GU3/HmRchFUGeQGNgf+ zREORtzq7HX52HzthkmNy/qBslBZORjozyK1uLPaUuGDT+7WH9eMboIo+IwIkITH/8qk=; Received: from mout-b-110.mailbox.org ([195.10.208.55]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzxuq-0005qV-AU for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 14:50:52 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4hWhC35fcxzNlf3 for ; Fri, 28 Aug 2026 16:50:39 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787928639; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Qm2WApMEB3Msc9WYkr9RkT7HPiUkRIZqD8uAotX4ZkY=; b=d/hrcb7f9wFxV8g0RxyefADHIRw4TfGzb+fsHAEy3w6CkdzI3TCLexeTdYj08cwsRQF7xh 8Fgz5JULPRBUlrE9DjTRx1ikngn4BHRr9uvSTJdqr78hbgkYDuFK3JrhWVoCE/CjlmxpTu JSvRX0ESOCpGsdrs1c68sdWuMqDj505SrQeySLCOz1jUXfMJfMtCq38lBfhH5Jjid5dHEf z7l58ixzDQPfCee6XwfoYB3LzjSx3PRWaKB9yjoRS7UpfnKXiVrZ8amD7rCGXz3DK8i6Hp OnNqhyFDfQoxHLC17nWsiBAPFd2hJSd57vo4yB9gyE1V92WiM6knHUI/aWrclA== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 16:50:22 +0200 Message-ID: <87624efbd20845abc23ebde353e82d5a90e0325c.1787925761.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzxuq-0005qV-AU Subject: [Openvpn-devel] [PATCH ovpn net v3 1/6] ovpn: preserve IPv6 scope id for netlink peer endpoints X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874779080549191326 X-GMAIL-MSGID: 1874779080549191326 ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create or update the peer bind. As a result, an IPv6 link-local remote endpoint configured through netlink loses its interface scope, unlike on the peer float path where ipv6_iface_scope_id populates the field. The UDPv6 output path then builds a flow with flowi6_oif set to zero and route lookup can fail or select the wrong interface. Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The existing precheck already rejects the scope-id attribute for IPv4 and v4-mapped IPv6 remotes. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- No changes since v2 https://lore.kernel.org/openvpn-devel/87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785308184.git.ralf@mandelbit.com/ No changes since v1 https://lore.kernel.org/openvpn-devel/87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785253480.git.ralf@mandelbit.com/ drivers/net/ovpn/netlink.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 4dad85294198..2ba762082acc 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, struct sockaddr_in6 *sin6; struct sockaddr_in *sin; struct in6_addr *in6; + struct nlattr *scope; + u32 scope_id = 0; __be16 port = 0; __be32 *in; @@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, } else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) { ss->ss_family = AF_INET6; in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]); + scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID]; + if (scope) + scope_id = nla_get_u32(scope); } else { return false; } @@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, if (!ipv6_addr_v4mapped(in6)) { sin6 = (struct sockaddr_in6 *)ss; sin6->sin6_port = port; + sin6->sin6_scope_id = scope_id; memcpy(&sin6->sin6_addr, in6, sizeof(*in6)); break; }