| Message ID | e15d597b1c6d0e98727f482113b51f86a8510c50.1785338921.git.ralf@mandelbit.com |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id
cw11csp2131964mac;
Wed, 29 Jul 2026 08:42:37 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RouKFXUw3GbeBesicC9hBXF2xbOuwpLL0faQqSPhWdgGfGM2FguVxnwih+DR17G2DgnaEGq39xptXo=@openvpn.net
X-Received: by 2002:a05:6870:3c07:b0:44d:133f:dd78 with SMTP id
586e51a60fabf-4586d1d67cbmr3959886fac.43.1785339757599;
Wed, 29 Jul 2026 08:42:37 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785339757; cv=none;
d=google.com; s=arc-20260327;
b=C4Sp9cYYdmtWCyz+1FCxeAPcxlhBw5M15ExsGZ8g0GHQUQZ9KhhoBTvSCOoG9uW6jm
7WgKuEOtQjWcCr17G/7IZLuMKX9/T5C/Bm7nxOjEsg//V5Db7tjjXJAg2b/iyb0rbZR2
x22lEIyl+HZ7HN08lArsC8NnnYt6wDNH3eclqcW+K/Xrpp1PKtrSVGKVh8KODTVlJOJa
OaEG5pG+JvoX6/SdqLE+8CtcZYSBbKoEhIsJdrYyP2X4v5oa5iGrFyng2pSIJSm9lQGV
I5IGfjNeEV0RdebVXTdhlpuS0BJFnIZ07E1T2zcR0BE3/2iMLk8hsDOYtNiKgV24lihj
fYmQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=8cGRYLl9DNQAa1p+DdGbUHxB2O8lL7fkPJrSV01Cyzc=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=SBR2tf7IJ1/ZH5zNorMGz/a68D/6ybnjua8FJ5Fu9CUJs5YwyctcBqWoZ371ImnBq9
cAVtCJETuNMWQl+wb7KSJma1mDg9+1tY4fW095MkrCr/YjEcmvHURZW/QcuVCICnI7CD
Xfnuly94gVjUbKGciQStu2es8FLWltx4g1XOSZagi+JR4y6pB7EIzzMp7isL0NAkMJa7
NIi8M+89cEm9y6+hwfgvUwA/pNdKev9l1rOSFBc+fg27Wr8FdUklfgnqWXpRbo8Jh1oK
S7y1jiDDIY7DLRXvdSE/LeRXwIRVFciCZqcGwfMZJBOymUvk9UbDdNJaHe10YcVlYgW4
8dNg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=k1Ni4IjL;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=YhMRyRIj;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=NKVRWm9A;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=hHKkNcIj;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
586e51a60fabf-45886498708si2925863fac.102.2026.07.29.08.42.37
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 29 Jul 2026 08:42:37 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=k1Ni4IjL;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=YhMRyRIj;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=NKVRWm9A;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=hHKkNcIj;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=8cGRYLl9DNQAa1p+DdGbUHxB2O8lL7fkPJrSV01Cyzc=; b=k1Ni4IjLo3Ha4z+mfK2nUOkG5G
EdIWUF7fO7sAoprwty0sHU2T+GS7J11wCpnkuSH6lhFq6okrXmaVKGzH1bYSBiQeMv5wBLlGYYfWH
n+utaUF4zmCQ7fxSnTRrKeFtTfhEwivyWegGTk33nuqixXJSFOPQ8Q+aFG9ZAuLtxegg=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wp6QU-0002WH-Tp;
Wed, 29 Jul 2026 15:42:34 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1wp6QE-0002Vh-Nn
for openvpn-devel@lists.sourceforge.net;
Wed, 29 Jul 2026 15:42:18 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=; b=YhMRyRIjji5J4Z1nsPdKmpYgYR
a2aEo7bz9TFotPm0IxNwlLeBClx0MQmPd/bG/URgSI/ub2Ihm8pvH/8TdNkgqhRwwrxi+PJyzRy2O
tXNg3giXRbOoMKospp259bv90AQIaEH7M9Mm62J904ttFcRUnbucjKII8/ltQqWnZm5U=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=; b=NKVRWm9AcRUq/x6d6ZHlb93toV
yemxanD++ZrfPnWHskXFigNL5PzZHFGdRBVRjOBHMW28ZxRZW0AjxZKUVNJyNdJkx5CEp3Ey7JjwQ
JpM9Ju5TbIUZ52hIaa7dJ7YA0kX4e6EisuGMcjDd14iUQMfD9S0u9uw/ZBBrfxyZD7gw=;
Received: from mout-b-110.mailbox.org ([195.10.208.55])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wp6QD-0002tz-9O for openvpn-devel@lists.sourceforge.net;
Wed, 29 Jul 2026 15:42:18 +0000
Received: from smtp2.mailbox.org (smtp2.mailbox.org
[IPv6:2001:67c:2050:b231:465::2])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4h9GmK3b83zNlmH;
Wed, 29 Jul 2026 17:42:09 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1785339729;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=;
b=hHKkNcIjxRopzPbYfiYVcBqXYrAssZ/Sejv0hAt6qhZVlX2KKBJB4moyPTPPv07dIkVEPB
BifP4R1/CI4P3s+/i6tUQSezQUmsODyVig0yyd99sZcWXLdfQxAW93fSo4dznbpd9vK+ef
yUQXnnEY9i1uEq3JCGH6sRIRgqx1+clmqjDMo3ZSI+Vzr/a1IP005Advw/Kv9xjOheSUDV
5dj0qBmCf6gFMRtNB+k5JV5o5ek6yeQj6gCoPEv+qlJ0XpU9UDBqhRIkSckoS1tF8cwNct
KE1NUSlvuVvJl2XxSFmEy2VRICtXGcHpu2AbPfL37XWDcldcirk2TLmD6QH2zA==
Authentication-Results: outgoing_mbo_mout; dkim=none;
spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates
2001:67c:2050:b231:465::2 as permitted sender)
smtp.mailfrom=ralf@mandelbit.com
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 29 Jul 2026 17:37:39 +0200
Message-ID:
<e15d597b1c6d0e98727f482113b51f86a8510c50.1785338921.git.ralf@mandelbit.com>
In-Reply-To: <cover.1785338921.git.ralf@mandelbit.com>
References: <cover.1785338921.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Rspamd-Queue-Id: 4h9GmK3b83zNlmH
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash
entries after userspace changes a peer VPN address. The current code removes
an old hash entry only when the new address for that family is [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1wp6QD-0002tz-9O
Subject: [Openvpn-devel] [PATCH ovpn net 1/5] ovpn: always unhash old VPN
addresses before rehashing
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1872064422020742006
X-GMAIL-MSGID: 1872064422020742006
|
| Series |
ovpn: validate peer VPN addresses
|
|
Commit Message
Ralf Lici
July 29, 2026, 3:37 p.m. UTC
ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries
after userspace changes a peer VPN address. The current code removes an
old hash entry only when the new address for that family is not the
unspecified address.
When an address is cleared to 0.0.0.0 or ::, its hash node therefore
remains linked in the bucket selected by the old address. The address
comparison performed during lookup prevents the old address from
matching, but the table retains a stale entry until the peer is removed
or another address is configured for that family.
Always remove both old VPN address hash entries before conditionally
adding the currently configured addresses back. This ensures that a
cleared address leaves its hash node unhashed.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
---
drivers/net/ovpn/peer.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index a21d02ac715e..6b1f176433d9 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -906,10 +906,11 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) if (peer->ovpn->mode != OVPN_MODE_MP) return; - if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + /* remove potential old hashing */ + hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); + if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr4, &peer->vpn_addrs.ipv4, sizeof(peer->vpn_addrs.ipv4)); @@ -917,9 +918,6 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) } if (!ipv6_addr_any(&peer->vpn_addrs.ipv6)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); - nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr6, &peer->vpn_addrs.ipv6, sizeof(peer->vpn_addrs.ipv6));