From patchwork Wed Jul 29 15:37:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5183 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp2131964mac; Wed, 29 Jul 2026 08:42:37 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RouKFXUw3GbeBesicC9hBXF2xbOuwpLL0faQqSPhWdgGfGM2FguVxnwih+DR17G2DgnaEGq39xptXo=@openvpn.net X-Received: by 2002:a05:6870:3c07:b0:44d:133f:dd78 with SMTP id 586e51a60fabf-4586d1d67cbmr3959886fac.43.1785339757599; Wed, 29 Jul 2026 08:42:37 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785339757; cv=none; d=google.com; s=arc-20260327; b=C4Sp9cYYdmtWCyz+1FCxeAPcxlhBw5M15ExsGZ8g0GHQUQZ9KhhoBTvSCOoG9uW6jm 7WgKuEOtQjWcCr17G/7IZLuMKX9/T5C/Bm7nxOjEsg//V5Db7tjjXJAg2b/iyb0rbZR2 x22lEIyl+HZ7HN08lArsC8NnnYt6wDNH3eclqcW+K/Xrpp1PKtrSVGKVh8KODTVlJOJa OaEG5pG+JvoX6/SdqLE+8CtcZYSBbKoEhIsJdrYyP2X4v5oa5iGrFyng2pSIJSm9lQGV I5IGfjNeEV0RdebVXTdhlpuS0BJFnIZ07E1T2zcR0BE3/2iMLk8hsDOYtNiKgV24lihj fYmQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=8cGRYLl9DNQAa1p+DdGbUHxB2O8lL7fkPJrSV01Cyzc=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=SBR2tf7IJ1/ZH5zNorMGz/a68D/6ybnjua8FJ5Fu9CUJs5YwyctcBqWoZ371ImnBq9 cAVtCJETuNMWQl+wb7KSJma1mDg9+1tY4fW095MkrCr/YjEcmvHURZW/QcuVCICnI7CD Xfnuly94gVjUbKGciQStu2es8FLWltx4g1XOSZagi+JR4y6pB7EIzzMp7isL0NAkMJa7 NIi8M+89cEm9y6+hwfgvUwA/pNdKev9l1rOSFBc+fg27Wr8FdUklfgnqWXpRbo8Jh1oK S7y1jiDDIY7DLRXvdSE/LeRXwIRVFciCZqcGwfMZJBOymUvk9UbDdNJaHe10YcVlYgW4 8dNg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=k1Ni4IjL; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=YhMRyRIj; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=NKVRWm9A; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=hHKkNcIj; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886498708si2925863fac.102.2026.07.29.08.42.37 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 08:42:37 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=k1Ni4IjL; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=YhMRyRIj; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=NKVRWm9A; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=hHKkNcIj; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=8cGRYLl9DNQAa1p+DdGbUHxB2O8lL7fkPJrSV01Cyzc=; b=k1Ni4IjLo3Ha4z+mfK2nUOkG5G EdIWUF7fO7sAoprwty0sHU2T+GS7J11wCpnkuSH6lhFq6okrXmaVKGzH1bYSBiQeMv5wBLlGYYfWH n+utaUF4zmCQ7fxSnTRrKeFtTfhEwivyWegGTk33nuqixXJSFOPQ8Q+aFG9ZAuLtxegg=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp6QU-0002WH-Tp; Wed, 29 Jul 2026 15:42:34 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp6QE-0002Vh-Nn for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:42:18 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=; b=YhMRyRIjji5J4Z1nsPdKmpYgYR a2aEo7bz9TFotPm0IxNwlLeBClx0MQmPd/bG/URgSI/ub2Ihm8pvH/8TdNkgqhRwwrxi+PJyzRy2O tXNg3giXRbOoMKospp259bv90AQIaEH7M9Mm62J904ttFcRUnbucjKII8/ltQqWnZm5U=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=; b=NKVRWm9AcRUq/x6d6ZHlb93toV yemxanD++ZrfPnWHskXFigNL5PzZHFGdRBVRjOBHMW28ZxRZW0AjxZKUVNJyNdJkx5CEp3Ey7JjwQ JpM9Ju5TbIUZ52hIaa7dJ7YA0kX4e6EisuGMcjDd14iUQMfD9S0u9uw/ZBBrfxyZD7gw=; Received: from mout-b-110.mailbox.org ([195.10.208.55]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp6QD-0002tz-9O for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:42:18 +0000 Received: from smtp2.mailbox.org (smtp2.mailbox.org [IPv6:2001:67c:2050:b231:465::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4h9GmK3b83zNlmH; Wed, 29 Jul 2026 17:42:09 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785339729; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2vjgLsDKJbs5n1mVWaNjla9Xm1S5OTNt2up56irwDqk=; b=hHKkNcIjxRopzPbYfiYVcBqXYrAssZ/Sejv0hAt6qhZVlX2KKBJB4moyPTPPv07dIkVEPB BifP4R1/CI4P3s+/i6tUQSezQUmsODyVig0yyd99sZcWXLdfQxAW93fSo4dznbpd9vK+ef yUQXnnEY9i1uEq3JCGH6sRIRgqx1+clmqjDMo3ZSI+Vzr/a1IP005Advw/Kv9xjOheSUDV 5dj0qBmCf6gFMRtNB+k5JV5o5ek6yeQj6gCoPEv+qlJ0XpU9UDBqhRIkSckoS1tF8cwNct KE1NUSlvuVvJl2XxSFmEy2VRICtXGcHpu2AbPfL37XWDcldcirk2TLmD6QH2zA== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::2 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 17:37:39 +0200 Message-ID: In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h9GmK3b83zNlmH X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries after userspace changes a peer VPN address. The current code removes an old hash entry only when the new address for that family is [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wp6QD-0002tz-9O Subject: [Openvpn-devel] [PATCH ovpn net 1/5] ovpn: always unhash old VPN addresses before rehashing X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872064422020742006 X-GMAIL-MSGID: 1872064422020742006 ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries after userspace changes a peer VPN address. The current code removes an old hash entry only when the new address for that family is not the unspecified address. When an address is cleared to 0.0.0.0 or ::, its hash node therefore remains linked in the bucket selected by the old address. The address comparison performed during lookup prevents the old address from matching, but the table retains a stale entry until the peer is removed or another address is configured for that family. Always remove both old VPN address hash entries before conditionally adding the currently configured addresses back. This ensures that a cleared address leaves its hash node unhashed. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- drivers/net/ovpn/peer.c | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index a21d02ac715e..6b1f176433d9 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -906,10 +906,11 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) if (peer->ovpn->mode != OVPN_MODE_MP) return; - if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + /* remove potential old hashing */ + hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); + if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr4, &peer->vpn_addrs.ipv4, sizeof(peer->vpn_addrs.ipv4)); @@ -917,9 +918,6 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) } if (!ipv6_addr_any(&peer->vpn_addrs.ipv6)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); - nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr6, &peer->vpn_addrs.ipv6, sizeof(peer->vpn_addrs.ipv6));