| Message ID | cb51001bfdaeba899b6ca9b22186ea2ebb49c23c.1785253480.git.ralf@mandelbit.com |
|---|---|
| State | Superseded |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id
cw11csp806165mac;
Tue, 28 Jul 2026 08:50:48 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RqfoxJlQa/bokv5uj+G9dgXInTXbRpd1/wPoNHpFpyqyOBDdbop7AVij57Xi/T+NygGYHEJOruhYeE=@openvpn.net
X-Received: by 2002:a05:6830:8389:b0:7e6:cfd0:42de with SMTP id
46e09a7af769-7efff247f64mr1589310a34.15.1785253847753;
Tue, 28 Jul 2026 08:50:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785253847; cv=none;
d=google.com; s=arc-20260327;
b=rtHZYcxlKVEcSAYxg5f8/W4rxl8UYhSVfHhUhHp3f7V84jTUp7d/3fmpH74bRA2+F1
46OirdPpyIYVYqhi0Q4dTLUFI6RleDSKxFPiyvrZ6DgoEbW62HOcdwUKZvl0jFwACib3
3RHTh+AyjT5R5CLQ09kkMd9PeED5FreYXuFKMHa4YbhWODJrbbLkYOWG2855Qk+6rC/T
7LOsbRS6pmW222N8992lWbUxQwCe83QQMhIRxTkH0grJU262hZtho2qK/H65BHjJnZSu
0X1mPNW4YqV8JpeKp3kmoz7emhuaxJsUI+FZl0AjO72AoftswWj7lhA8rnEFbqHxakL9
G3cQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=2lbSjbl2tjujzETWgMO75R0nGRuM614xzT3wzcX5CXQ=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=ABChGyCqP101zPVr8seV9WEWm+8KvX2WcEL4T2jVyVexuuwSMwxc3LdF2Tsd6ogmoH
Ba1/Tq8oVm6yzBwcWgbSTkzSTkcfj67bfQIH8I3oxkGVuEWCro2lm6LSE5IPB113Vfvw
td9Y5BhZ8dYhagQxu868vrD/TI9kErLQ0ACrXBklJLaCX9Oa4X1OLOMLpDv80zRAxQMH
EufrCb/taWhYQG0v7HewjlUpYt9LuzUyNAXFXnoM53erzUDt30bB8crXCMGiMl5qoV+Z
zBfj+m7bLseZsHNyxxd79oaF5c6OPbWulhO3VCPF06m0dmHv/xCK7wE+aN+8DquM9Eb6
OzIg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=JOuc0ZV8;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=lPeE36H1;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=PuKcrOXG;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=Yo2UgsXI;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-7f00d66b7casi48820a34.53.2026.07.28.08.50.47
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Tue, 28 Jul 2026 08:50:47 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=JOuc0ZV8;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=lPeE36H1;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=PuKcrOXG;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=Yo2UgsXI;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=2lbSjbl2tjujzETWgMO75R0nGRuM614xzT3wzcX5CXQ=; b=JOuc0ZV8r2uxoav5rZ3MYUOj2f
c7BdAhQJJdOLjnp6Jih5T+aDVDQlJdOaPdQUeGrtxzve4AgkEgu0OiotdEE8rV2IuR2G8kHCk+oMW
7OehZlEQJga9aBObtMQN2wPAZQkZOGyB6lCCL2cZzfUkm23J4pAiu4i3Phk2cT9R4rTE=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wok4o-0007yd-Sz;
Tue, 28 Jul 2026 15:50:42 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1wok4n-0007yV-0u
for openvpn-devel@lists.sourceforge.net;
Tue, 28 Jul 2026 15:50:41 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=/lAS7AeX2AF9eFFaDtOcSZRextZWWfNUwogcEusO2yM=; b=lPeE36H1NgwUs95vJGQ0clF7Gu
wLiWsiVo3yQ7qsdm4Bh+PhkUDIdXSjce077ni+572Lnj8uStT2so7FWKqXd6oYm14mMBsp2DgS2gb
eAS4aZstBRhToi6ubKQb+QGNNO6gz/MWSv7HOl8QfRXYUMxX7wbsLOj6ntjwrE9rw+J4=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=/lAS7AeX2AF9eFFaDtOcSZRextZWWfNUwogcEusO2yM=; b=PuKcrOXGlOD1VZf6IUY4RA2FH1
DyJX+HXTw0BhscrwyWghlwcl0WqyjcXmfi70YElM8QeR9qcqJ8w9oD3HGvvllirkqsLc9GaQ0aIrE
xoAL6ezz63R7101SYt2oIfRQJ4ZluRXL2Sz50E7saIIop0KPc3gkwDM28hksY082FFPc=;
Received: from mout-b-110.mailbox.org ([195.10.208.55])
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wok4o-00026e-PB for openvpn-devel@lists.sourceforge.net;
Tue, 28 Jul 2026 15:50:40 +0000
Received: from smtp202.mailbox.org (smtp202.mailbox.org
[IPv6:2001:67c:2050:b231:465::202])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4h8g0R21w9zNlj8;
Tue, 28 Jul 2026 17:50:31 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1785253831;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=/lAS7AeX2AF9eFFaDtOcSZRextZWWfNUwogcEusO2yM=;
b=Yo2UgsXILPEpgGcHbegN0iTVRLjD0mLhm33ArNvkvdru7vE8SDwLwnYW9oxDb1UjoRo/wz
EZoY5RNZI9jyq6rRGcwWX27NYWTLFFvquTUYyOlh5nVLcTqtBfBUOULjeIMMZKDoroN92e
u+5xnMS/L3fzIpl43BGjCc7ggDLOu4LgF6t98iLeLdLzZ3cxbmj+x8UhYzjKRvdEo1ZF2J
dFgAEtAfC53UudWM3Fs0QwC7tQ3dL6e9Q1YZAj/r6w8sGi2LFqNCrnoCDwk1S8S30qD0Sm
meVbSdW3VgUDqmf1W1lCsv9rxocP3LxsDuYxM5C5k/t7wj27CPvL0tY53xfB2g==
Authentication-Results: outgoing_mbo_mout; dkim=none;
spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates
2001:67c:2050:b231:465::202 as permitted sender)
smtp.mailfrom=ralf@mandelbit.com
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Tue, 28 Jul 2026 17:50:12 +0200
Message-ID:
<cb51001bfdaeba899b6ca9b22186ea2ebb49c23c.1785253480.git.ralf@mandelbit.com>
In-Reply-To: <cover.1785253480.git.ralf@mandelbit.com>
References: <cover.1785253480.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Rspamd-Queue-Id: 4h8g0R21w9zNlj8
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: ovpn validates the cached local UDP source address before
reusing or refreshing a peer dst cache. This is only meaningful when a
concrete
source address is selected. For IPv6, calling ipv6_chk_addr with :: checks
whether the unspecified address itself is configured on the host. A peer
may legitimately have bind->local.ipv6 set to :: when no local endpoint was
conf [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
X-Headers-End: 1wok4o-00026e-PB
Subject: [Openvpn-devel] [PATCH ovpn net 2/5] ovpn: skip UDP source
validation for unspecified addresses
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1871974338924995155
X-GMAIL-MSGID: 1871974338924995155
|
| Series |
ovpn: fix UDP route cache and endpoint handling
|
|
Commit Message
Ralf Lici
July 28, 2026, 3:50 p.m. UTC
ovpn validates the cached local UDP source address before reusing or
refreshing a peer dst cache. This is only meaningful when a concrete
source address is selected.
For IPv6, calling ipv6_chk_addr with :: checks whether the unspecified
address itself is configured on the host. A peer may legitimately have
bind->local.ipv6 set to :: when no local endpoint was configured or
after a stale learned address was cleared. In that case the source
should be left unspecified and selected by ip6_dst_lookup_flow().
For IPv4, inet_confirm_addr(..., local = 0, ...) asks for local address
autoselection rather than validating a chosen source. Skip the precheck
there as well and let ip_route_output_flow select or reject the source.
Only validate non-zero/non-any source addresses.
Fixes: 08857b5ec5d9 ("ovpn: implement basic TX path (UDP)")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
---
drivers/net/ovpn/udp.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c index 493a5a0744af..eb342c7eef29 100644 --- a/drivers/net/ovpn/udp.c +++ b/drivers/net/ovpn/udp.c @@ -161,8 +161,8 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind, if (rt) goto transmit; - if (unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0, fl.saddr, - RT_SCOPE_HOST))) { + if (fl.saddr && unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0, + fl.saddr, RT_SCOPE_HOST))) { /* we may end up here when the cached address is not usable * anymore. In this case we reset address/cache and perform a * new look up @@ -238,7 +238,8 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind, if (dst) goto transmit; - if (unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) { + if (!ipv6_addr_any(&fl.saddr) && + unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) { /* we may end up here when the cached address is not usable * anymore. In this case we reset address/cache and perform a * new look up