From patchwork Tue Jul 28 15:50:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5150 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp806159mac; Tue, 28 Jul 2026 08:50:47 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqLzdGZV4FjOWgrN86dM3BtEoY12zLJOsVOx/IN3sZyauP72nhE7cYyUE0h5Ix7iuPrQy3jA8ewqyU=@openvpn.net X-Received: by 2002:a05:6830:67d8:b0:7e6:e1d2:3bd0 with SMTP id 46e09a7af769-7efff0df270mr1625081a34.10.1785253847556; Tue, 28 Jul 2026 08:50:47 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785253847; cv=none; d=google.com; s=arc-20260327; b=NNliB5T7DUonL9OboIEWB3HlFWI7qMzM//xSE4g4J9Cmw1RDlxkzaWXPb2/orcYRTT U516SPHjVN8XnQGZsKXBAC1kXgUePN2bUo86cS/QgjUkAv5cU5ubWeXUgOpPkikTwZ9o 9cGhjlGrBhGBaPT6VVU/CXzOh4pg3YwnDbq40Jvy9rI+Y05N2YZHXm7GP2mXoCPwnn7b o5TWCvo0jVG7+55lQGxZNXK/wgOJ2w08Y1rqgkIm8ClZyXmi0Lhnlz5nt5NmlGfHB9o0 Xio/eBM3IpCf6mo05ZbaQlqmcwpQAgHIjbKvU5/Rvce6VT3RQ1VBzXfJN0k3GJWIP2jD fd6w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=VzBUHeVkeT7BjJODdYr3iLIx+16OAfSSM60E7zIbo8s=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=YZZLgu59DFsVumG3kKXvP5gOgGlb22mP2jyEU3AYaarB2RHE9SDolG8lp1aYTCEZYF EH6ne6xPZWqJHfiToV1HgH1fJRUIAZ6t8xr2yqka/rm9XpXv9NAb8APQJdw78Iss0jkt FFPUp/zo7a5rx95kgHrcN+lXwbYeXPxJYvMWQEiLpszIfM/KCExZRw9eej8YNZK7mXdz 8u7CQnynSrkahtVtp9vH/ocNdAqDam8uAIoNfn0WHmeSUqRCh9p8die9MJUiDWmn9F69 nKcsjtuyHHUuB243Ipx5uN7fgJx1d9UyWb0P8cJA3JntiwCaUQ9VocSjJfPJ+crf1M0H Hidw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e9r+jDAE; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=ktitMwWX; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=f7PZNXJC; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=kDiJusjY; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f00da0c478si27073a34.72.2026.07.28.08.50.47 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 28 Jul 2026 08:50:47 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e9r+jDAE; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=ktitMwWX; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=f7PZNXJC; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=kDiJusjY; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=VzBUHeVkeT7BjJODdYr3iLIx+16OAfSSM60E7zIbo8s=; b=e9r+jDAEHN8cGmhA5XdGei9aRM rtIHtkLmK1Va2l5ePmtEhrw91iQikkyuAP700RM0SPanmJAseZ2FsuMkm2AUPRE9HkK8GgJVLWUZK 7ORRiBrYuVA+x0w6pNb3Rf0N2kBgUG7gLCQN7St+WkJuRFQJGTHvwVa8zhEKjkjnStB0=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wok4n-000316-Ju; Tue, 28 Jul 2026 15:50:42 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wok4k-00030w-Vl for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 15:50:40 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Ugkvjvevx4m9D1KSWtMsQVP4RsNSZmE4wESHbgcDJg0=; b=ktitMwWXQJl2gcOrXEOGw6f3V/ tmtu60uglYFFeuLYM4oAfI7aGp9YL6ebVWMXeWbPYXB4BNhvGCkbE7cTf8IfNSADx/6sOCEkHzWxK 8w4IjkI6/PkSBkL3Jiuo/WlguOqBQ8ZjOfyGRogZI7pZc4V1KrspsTBBn2MUNWhqIeZM=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Ugkvjvevx4m9D1KSWtMsQVP4RsNSZmE4wESHbgcDJg0=; b=f7PZNXJCalgJVK2apw04GC8Ont aArULoA3WI7soq4peXb2hCBXasqKkrgHidmqwpnUbgmtQY9wMLwPlxORD6kWQ8njZtSGNDYUt+D8a 3URrbLYMn3GTIw58Wq0hZHb6AEY/H609Ba1iskxgyxZBki9Gbat67Mo5XIRxvpPP6Uek=; Received: from mout-b-110.mailbox.org ([195.10.208.55]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wok4k-00027M-By for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 15:50:39 +0000 Received: from smtp202.mailbox.org (smtp202.mailbox.org [IPv6:2001:67c:2050:b231:465::202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4h8g0Q4G2BzNlfb; Tue, 28 Jul 2026 17:50:30 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785253830; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ugkvjvevx4m9D1KSWtMsQVP4RsNSZmE4wESHbgcDJg0=; b=kDiJusjYd0Jm4ggFTmwRf3z6c6sc0BxkVrKinmKWYuhmk7iafzKm5BgnWzb4dPBc+rVZNc 7GriZ8ftFXzKVhAVYaXQf8ZRusuB1AeLqu5KK/uubDaX8ZYUFhR+N267/q5yYitCnXODku NSS5/TymExPR3jTQt6JSoUuEauYOeBN1o25v1WtlKq4EBiJALDFhBr8ogUb3G8cPytoXbQ pwkfrZ+E6dyeDI6WgQpncohPeV6JrOyA6dgfmp/dx7zHJv22V32uNHwtRNTeM62ns+kZYc 3YvISMTp8q/MytzxYcCVwK4op+QxWg/S4aoqLHV2p/VQ/kxh8f0o1KtK1LtDfw== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::202 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Tue, 28 Jul 2026 17:50:11 +0200 Message-ID: <87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785253480.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h8g0Q4G2BzNlfb X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wok4k-00027M-By Subject: [Openvpn-devel] [PATCH ovpn net 1/5] ovpn: preserve IPv6 scope id for netlink peer endpoints X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871974337934050586 X-GMAIL-MSGID: 1871974337934050586 ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create or update the peer bind. As a result, an IPv6 link-local remote endpoint configured through netlink loses its interface scope, unlike on the peer float path where ipv6_iface_scope_id populates the field. The UDPv6 output path then builds a flow with flowi6_oif set to zero and route lookup can fail or select the wrong interface. Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The existing precheck already rejects the scope-id attribute for IPv4 and v4-mapped IPv6 remotes. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- drivers/net/ovpn/netlink.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 291e2e5bb450..883a28d69d8e 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, struct sockaddr_in6 *sin6; struct sockaddr_in *sin; struct in6_addr *in6; + struct nlattr *scope; + u32 scope_id = 0; __be16 port = 0; __be32 *in; @@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, } else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) { ss->ss_family = AF_INET6; in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]); + scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID]; + if (scope) + scope_id = nla_get_u32(scope); } else { return false; } @@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, if (!ipv6_addr_v4mapped(in6)) { sin6 = (struct sockaddr_in6 *)ss; sin6->sin6_port = port; + sin6->sin6_scope_id = scope_id; memcpy(&sin6->sin6_addr, in6, sizeof(*in6)); break; }