From patchwork Wed Jul 29 07:20:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5160 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1591225mac; Wed, 29 Jul 2026 00:21:03 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqoOWbn4myXZv0uyf6ugNHYnB7OCrmxcfCzrT8piDSHjrPRs6gVz8TO467FgEzT9sIEG349//FJ8kw=@openvpn.net X-Received: by 2002:a05:6870:ac28:b0:456:5873:3b56 with SMTP id 586e51a60fabf-4586c9ea3e1mr3461488fac.27.1785309662909; Wed, 29 Jul 2026 00:21:02 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785309662; cv=none; d=google.com; s=arc-20260327; b=ZO2LWUTTNjpOxZU4NTSlj3QI5vXg2x98tCyEcvaVPGt0gwEd9wrcMcSsDTdPo+Llum g7Qo1ZzPLrQbptXDBcYLwwNJTqFk6oYqcZYKvOk63TffoVF+aSCZSExa2VSjQIxsFhpT t+37eBmZdImmSotzB5946CSJP3sNOi95J8/Kei5L1kUSl2Y2f6M+7LZnSLQ/XRr7GSos UUDbPIy86gauY3fUs3UolSnxmpLidipgVhjnPhy3mF7n7+KmiWa/iK/bA5q0bq7mDHYk cURFH8FhMxXibRGTMYntoVxC0Xs+wmihb2jievrRVlbSHzl3EYg5TD3iDMa95aC7HnK5 VwbQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=WV1gq7Pzen/8u1HLK2NQnE+/KJUg4zbN32LEfgyU/kg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=dYe66gKSojf89IXgVAVWTRG1Kxm6W4MLjYMxdYKEZLIE/KbOqhxbkVeBOUnjZN3Rv5 Rh6lL/62FVJXXMCrI6Al7KafA4tweJVGWAPHIPu/d0iXux7bWfBRhJQ8kmP1PP4+hNDw s73ZKGnfsbE7VhshZtzh/ywqUo+NCU2JZ1KzJrE6LCOned9rNkrGOD49nUolwE/tJFRw ShOCAKmH+55IRKgEF0Z/XsMAXS3Nmx7M0VG2SvVV2JMmO1TWSTOAeKBeK7GJwZNu/z8Y NlrWnt/I4QdDm4NtWK/IVsMM8dYP1uOd8NXeOByuipQfBheqOCf/VysDiNIPyAiMRGsI gviw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=UWyvMnOr; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=hXgLovVd; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=QoIkjPMM; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=Ebf5OQ+w; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886b4feadsi1988074fac.247.2026.07.29.00.21.02 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 00:21:02 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=UWyvMnOr; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=hXgLovVd; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=QoIkjPMM; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=Ebf5OQ+w; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=WV1gq7Pzen/8u1HLK2NQnE+/KJUg4zbN32LEfgyU/kg=; b=UWyvMnOrcNBT3VJGYXbJlx0f31 mghjcXCiAljME36JlpEHhU7sdf8+TNVUsltkeRzyOdVHidDw2bSS8KhISwPa+VoCdoS/+1pONTpGJ grRxeZDZc2V+L27pZZzaUJPR19FX/ycXai6DRuzdBDcsMS5jMz30jcGVbA0/O+NU2iaU=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1woyb5-0000Bu-C6; Wed, 29 Jul 2026 07:20:59 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1woyb4-0000Bn-57 for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 07:20:58 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ipEaZg7tfzbAlF4Sgl6jeb1UbMREFHEpCQfumpuH4O4=; b=hXgLovVdz5tsbGMxhK4+WqBl0e GvKkmghEr4m6P+5MNdJPqx9n1fyiU9kuV7S1tTkYkOeP9+V2dMhGaY1iaQnerw/MnuH5Or4BG7V7X lq97NdQcIxblbjj+wJhV1GHFULDxGbS8EPBxNG5WtPnxe54CXN0mUgA/wBHt5N46b3tM=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=ipEaZg7tfzbAlF4Sgl6jeb1UbMREFHEpCQfumpuH4O4=; b=QoIkjPMM69NnvFrlmAB2dyHuYi 5X46jrvrdJG6y/cQy928WIkZKkdzfe88NmbgucppvRYEH3ZHgWyweA7DzDeborqJAAMQVCjYBgDKo RJ3XkByUKIAo1X6URoBHz+yaddHhXP7yd9cDU/taqBP9e1CSbMsALH19cjRtGABepvDM=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1woyb5-0004eQ-0i for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 07:20:58 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h93dq4d1zz9tLy; Wed, 29 Jul 2026 09:20:47 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785309647; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ipEaZg7tfzbAlF4Sgl6jeb1UbMREFHEpCQfumpuH4O4=; b=Ebf5OQ+wegkxNvLyjqXi4hEULx3ZoqkHeQTIdS5qzkIBDa1uckZd6GXf9Xe7j1DP1prOwP Wd3Qu/98Vf4ooVvwHtehWOOY6CjQRvijMUyWn+wSDpgYQzjWjZb2UA5Ojm5n0TidS0Rzbt tBaDBVWDZ8wiSCeIow1W01VeRRsynJl3tGGd9GuIE/AZpPClmi976g/QUlKM0JT5msS0ut aAVk0e31pxQfRMhBjKF3v18fta2IVHUGMBTQMHEHlf1uHq5qbKwwq5qWIFfgbrBWpKmK0J afk0kp+yi1eEcs258+xszbjAEjjHHzklf0P5d4icnGkriTSy/WVBbuUXDIItjw== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 09:20:32 +0200 Message-ID: <87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785308184.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h93dq4d1zz9tLy X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] X-Headers-End: 1woyb5-0004eQ-0i Subject: [Openvpn-devel] [PATCH ovpn net v2 1/5] ovpn: preserve IPv6 scope id for netlink peer endpoints X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872032865184295881 X-GMAIL-MSGID: 1872032865184295881 ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint parser never copied the attribute into the sockaddr_in6 used to create or update the peer bind. As a result, an IPv6 link-local remote endpoint configured through netlink loses its interface scope, unlike on the peer float path where ipv6_iface_scope_id populates the field. The UDPv6 output path then builds a flow with flowi6_oif set to zero and route lookup can fail or select the wrong interface. Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The existing precheck already rejects the scope-id attribute for IPv4 and v4-mapped IPv6 remotes. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- No changes since v1 https://lore.kernel.org/openvpn-devel/87f7c1a6eea0005a067889e9b6f73fc6bd4f40e1.1785253480.git.ralf@mandelbit.com/ drivers/net/ovpn/netlink.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 291e2e5bb450..883a28d69d8e 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, struct sockaddr_in6 *sin6; struct sockaddr_in *sin; struct in6_addr *in6; + struct nlattr *scope; + u32 scope_id = 0; __be16 port = 0; __be32 *in; @@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, } else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) { ss->ss_family = AF_INET6; in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]); + scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID]; + if (scope) + scope_id = nla_get_u32(scope); } else { return false; } @@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs, if (!ipv6_addr_v4mapped(in6)) { sin6 = (struct sockaddr_in6 *)ss; sin6->sin6_port = port; + sin6->sin6_scope_id = scope_id; memcpy(&sin6->sin6_addr, in6, sizeof(*in6)); break; }