From patchwork Wed Jul 29 10:21:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5168 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746427mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Ro881rUlfeYmjZR/T22Eh4UXYd5tauzoJlJSozweSc5XPjyzs8wKtkwsTMtQQWqgFqTfRSpKzkCCJo=@openvpn.net X-Received: by 2002:a4a:edcc:0:b0:6aa:ec6a:21a5 with SMTP id 006d021491bc7-6ac96c284b5mr3412561eaf.31.1785320545156; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=jEkqe01yikBhJm8KExa8VSRh0UavOOb3zXas/7kzhGV1yB6HbFeWuC1zoCeOn3sGDg p+PlmRusOlM+WaqGZ4axr9rbECPHflbchtbQ6+QHu0dUYvDqKf7rwqtjTo6rp8IboRxV ANd0DoDOxX+GxzH3FSBhy1PoraurZZV6W7ixktgYXgFwdpx+qxglnbBtdN73CvORLFCy FIjpQNFperlLxt1CvReKxM5jiCMtgHsVu2cfCDqgNb7Z6LVLxsH4xYy04bqKyMJvSpQo 5siiaTtbUXBmXE89OjH4ngaS07qY8bspsVrfO8w7p/2HyBczaUj6/4silViSOfi/wjGx sx1Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=T5OtqUONyaKJsw/ZeyjIuO7djlmvLmzh4KZuWu2ilFY=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=PlSQW7UvPs0KW9cQoD9TOZBqXkvn8hTcnb7HL7oLT30mnVBAhiTQcRJ0wbuPcbQ7lr vAtkXtU0a5ezzscG46hZPMLKoWZxCY+Qtn9tmsKFS4Aev2s2O9vfIQ/qHvK29eSDRJFd gIQAJbpenhx10+PJSwIUoS4DZAmO+bJ/UWz3eZvd17ukCUQ++K+ppOfeDLI5cxKIUy4M aKQacTCB4xWDU/2eBjQDjIVc3bZDJJyFI/6/38mGJG9QQ9q5KHHaA51tF0vPJESJmvMs v90U7o30WKZq8N++ooPAI+NJKhcmUfPydStHUh7B2Cgou0jA4JSrubhmDlSuuen6MqVK 7sHw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=d5h2nelV; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=CGPG4LEM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CWa1+tua; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="DqN/JyP8"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886cbe650si2189881fac.368.2026.07.29.03.22.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=d5h2nelV; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=CGPG4LEM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CWa1+tua; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="DqN/JyP8"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=T5OtqUONyaKJsw/ZeyjIuO7djlmvLmzh4KZuWu2ilFY=; b=d5h2nelVQoMag0wZy7qUIssk2k 0n8O0TN4ds2hnGpB7nSxQtIDVs7EBloLNRsZOLf9oAZCapV8j4B6D9qN8XDw9sQsKUSO2ApiP02AY jrOVALy0a5eTvRE533ybFPjZu6iKUXEUyAT5azLKhj4NKmLWSLzBXzOEVOBX82PubMxI=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1QY-00083W-PV; Wed, 29 Jul 2026 10:22:19 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QO-00083C-EW for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=CGPG4LEM3nXFMtEAn641rYbnsP rjDL/F12OJ+Ada/0qx/jxwNrKj1MBHTajYabOPiK0BEdC0UQhDL4G1Q+RNfm2M4DQWTsnkHK57YLs yyLh7Gh+ZewwU9y8Rt6w6+nT1diKH1tnCk0h1LzLlkuVU5fGjaBvDWiQvf6/JPEK6NlY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=CWa1+tuaFYp9aqqr2HrVOdWzas lTTi1OTSELJXnuR3J/02DppQx+vR5n1R0MSW2+/tSf7hKjljSMLfAJ20u8gS3xOtJIu6jPOQPD3al 0FfoOyU1Kv9QYiSHbltdP/DcnmRljjcLcVNfi5M93nRpNU2N2ZwRpqTLmX2hYAHCY8GU=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QR-0002fE-6Z for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:09 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h97fv5LXJz9tbx; Wed, 29 Jul 2026 12:21:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320519; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=DqN/JyP8NKGywg33IjW+6PciPl+I/nKNAoTDSrFR8tiVlr2vC6qHM/syZlSpf+x4BuFzD1 KORLcX96thnZirOro4CpgrYOxdjSs6Td02u1mmTkQmP3FyQ3sMdbcPze7fw/RoYefK1Ez+ KST8sz328wjG3vnE5pOb8SH9qIP1FzyD/dvCcbjjVua0IPleaMvv1yMKWyYTqi2ITJo8HE iVM+YomssC5VHWG01SslOWEoOWIcBYea9zaibB/n6MedA9lh2tKKT6TTgjHyWHymL9Pcb3 Ux642MK+pOFDAreiLnNfe+NXQ5gzqEO4l71zSTUjafUATWiFILvvluM3GIti5Q== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:46 +0200 Message-ID: <99bd088e56302f9bd7cd565eb4208912e6fd26e7.1785318038.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fv5LXJz9tbx X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Key slots are released through a kref and the existing release path frees the AEAD transforms from an RCU callback. That is not safe for all crypto implementations: crypto_free_aead can sleep, for exa [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wp1QR-0002fE-6Z Subject: [Openvpn-devel] [PATCH ovpn net v6 6/6] ovpn: defer key slot crypto freeing to workqueue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044275624340208 X-GMAIL-MSGID: 1872044275624340208 Key slots are released through a kref and the existing release path frees the AEAD transforms from an RCU callback. That is not safe for all crypto implementations: crypto_free_aead can sleep, for example when an async or hardware implementation has teardown work to complete. Use queue_rcu_work for key-slot release. This keeps the RCU grace period needed by lockless key-slot readers, but runs the actual crypto teardown from workqueue context where sleeping is allowed. Once the rcu_work callback runs, pre-existing RCU readers are gone, and the final kref put already proves that no transform user remains, so the worker can release the AEAD transforms and free the slot directly. The previous patch drains ovpn_wq during module exit, so queued key-slot teardown work cannot outlive module text. Fixes: 8534731dbf2d ("ovpn: implement packet processing") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/5e4de5963ea48d7e7431e55192f0d6a5784c2a47.1783336121.git.ralf@mandelbit.com/ - Use queue_rcu_work for key-slot release so RCU readers are preserved without adding a key-slot reference in ovpn_crypto_config_get (Sabrina). No changes since v4 https://lore.kernel.org/openvpn-devel/b53ae1a9714bae7081c71bdab7b30623ce3cb77b.1783099626.git.ralf@mandelbit.com/ Changes since v3 https://lore.kernel.org/openvpn-devel/ac2842c8e759849c51447126343376dcc793c7ae.1783080055.git.ralf@mandelbit.com/ - Reuse the module-owned ovpn workqueue instead of allocating a crypto-specific workqueue for key-slot teardown. Changes since v2 https://lore.kernel.org/openvpn-devel/b5dfebec718f230783ff47aa354c3b3fa1aa2ed7.1783068961.git.ralf@mandelbit.com/ - Reword the message to note the dependency on patch 1. Changes since v1 https://lore.kernel.org/openvpn-devel/350f6b48c363dde5a8d0bdf7a1b9fd2abb8b1034.1783057762.git.ralf@mandelbit.com/ - Fix a potential AEAD transform UAF in ovpn_crypto_config_get by holding a slot kref while reading the cipher algorithm. drivers/net/ovpn/crypto.c | 10 +--------- drivers/net/ovpn/crypto.h | 4 +++- drivers/net/ovpn/crypto_aead.c | 19 ++++++++++++++----- drivers/net/ovpn/crypto_aead.h | 1 - 4 files changed, 18 insertions(+), 16 deletions(-) diff --git a/drivers/net/ovpn/crypto.c b/drivers/net/ovpn/crypto.c index 2e95f29514fc..7e545428900a 100644 --- a/drivers/net/ovpn/crypto.c +++ b/drivers/net/ovpn/crypto.c @@ -18,20 +18,12 @@ #include "crypto_aead.h" #include "crypto.h" -static void ovpn_ks_destroy_rcu(struct rcu_head *head) -{ - struct ovpn_crypto_key_slot *ks; - - ks = container_of(head, struct ovpn_crypto_key_slot, rcu); - ovpn_aead_crypto_key_slot_destroy(ks); -} - void ovpn_crypto_key_slot_release(struct kref *kref) { struct ovpn_crypto_key_slot *ks; ks = container_of(kref, struct ovpn_crypto_key_slot, refcount); - call_rcu(&ks->rcu, ovpn_ks_destroy_rcu); + queue_rcu_work(ovpn_wq, &ks->free_work); } /* can only be invoked when all peer references have been dropped (i.e. RCU diff --git a/drivers/net/ovpn/crypto.h b/drivers/net/ovpn/crypto.h index 0e284fec3a75..e3feb16d5498 100644 --- a/drivers/net/ovpn/crypto.h +++ b/drivers/net/ovpn/crypto.h @@ -10,6 +10,8 @@ #ifndef _NET_OVPN_OVPNCRYPTO_H_ #define _NET_OVPN_OVPNCRYPTO_H_ +#include + #include "pktid.h" #include "proto.h" @@ -45,8 +47,8 @@ struct ovpn_crypto_key_slot { struct ovpn_pktid_recv pid_recv ____cacheline_aligned_in_smp; struct ovpn_pktid_xmit pid_xmit ____cacheline_aligned_in_smp; + struct rcu_work free_work; struct kref refcount; - struct rcu_head rcu; }; struct ovpn_crypto_state { diff --git a/drivers/net/ovpn/crypto_aead.c b/drivers/net/ovpn/crypto_aead.c index 8f07c418622b..74eaf6fac2f5 100644 --- a/drivers/net/ovpn/crypto_aead.c +++ b/drivers/net/ovpn/crypto_aead.c @@ -9,6 +9,7 @@ #include #include +#include #include #include #include @@ -380,13 +381,19 @@ static struct crypto_aead *ovpn_aead_init(const char *title, return ERR_PTR(ret); } -void ovpn_aead_crypto_key_slot_destroy(struct ovpn_crypto_key_slot *ks) +static void ovpn_aead_crypto_key_slot_free(struct ovpn_crypto_key_slot *ks) { - if (!ks) - return; - crypto_free_aead(ks->encrypt); crypto_free_aead(ks->decrypt); +} + +static void ovpn_aead_crypto_key_slot_free_work(struct work_struct *work) +{ + struct ovpn_crypto_key_slot *ks; + + ks = container_of(to_rcu_work(work), struct ovpn_crypto_key_slot, + free_work); + ovpn_aead_crypto_key_slot_free(ks); kfree(ks); } @@ -420,6 +427,7 @@ ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc) ks->encrypt = NULL; ks->decrypt = NULL; + INIT_RCU_WORK(&ks->free_work, ovpn_aead_crypto_key_slot_free_work); kref_init(&ks->refcount); ks->key_id = kc->key_id; @@ -453,7 +461,8 @@ ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc) return ks; destroy_ks: - ovpn_aead_crypto_key_slot_destroy(ks); + ovpn_aead_crypto_key_slot_free(ks); + kfree(ks); return ERR_PTR(ret); } diff --git a/drivers/net/ovpn/crypto_aead.h b/drivers/net/ovpn/crypto_aead.h index 65a2ff307898..fae3b585a43b 100644 --- a/drivers/net/ovpn/crypto_aead.h +++ b/drivers/net/ovpn/crypto_aead.h @@ -22,7 +22,6 @@ int ovpn_aead_decrypt(struct ovpn_peer *peer, struct ovpn_crypto_key_slot *ks, struct ovpn_crypto_key_slot * ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc); -void ovpn_aead_crypto_key_slot_destroy(struct ovpn_crypto_key_slot *ks); enum ovpn_cipher_alg ovpn_aead_crypto_alg(struct ovpn_crypto_key_slot *ks);