From patchwork Tue Jul 21 20:38:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5117 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:508:b0:87c:c0c2:48b6 with SMTP id y8csp2500689mae; Tue, 21 Jul 2026 13:38:27 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpT8uwqmseGH1Dkfme2dKkeyRmnb6Oy6hFcCon8oLBsdUJ89RaQzysjZ7Dy6SowuHeVmqRmMuQnvdM=@openvpn.net X-Received: by 2002:a05:6820:2d03:b0:6a3:955b:8474 with SMTP id 006d021491bc7-6a5366c863emr10233821eaf.4.1784666307636; Tue, 21 Jul 2026 13:38:27 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1784666307; cv=none; d=google.com; s=arc-20260327; b=dzxtHZi3NvyrkDHGwvmDc8fLifson6xNLD9wW9YnaMTYv9woM64BeyN4leU5+nGcOZ 8aindLpvWUHtLfvK2ETkycmG25S02ixILFy5nKKIaNGP1tPrIDXP2txoOxfGBZuLEPP6 +tSZ4S2h56jtToJbin7YT4gY0S0HxvkKuQsCXmjKnxlhZBmfN7NH1KtuLHlS8L5AnwJc aaN1PYlmZvOQ6Wnwwn6M5GK88/ZPSIxySG6khKZ95dUA55oaEJ5cG5urThJ/ANPzeyp1 4VagU9riPXLipvhNfJzrLi6/ZEiuSCuKBTCj+eK4z31UHUuUNGKfCikLXoT3ikgZrAzQ qiLQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=Hq0RWL3AeLrLTRzvofYXRfgnNQUqZDv8DTO564Sn8uA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=kIqmsCOMJgo33OQJy9yPMPD21iGi+zf/kugTHFGEWJUgLUe95I37BhUqxP1stNjMtf a7Fmp5wKN12GaPHhl2KNcWwJKDbGS1YUL+oZ/UVs8kp5o4Wa4n8Jq5dwMQgDVfsdxj3Y m0IhdbYTptEbBFibhNtUXZ0myftbBbRA8Y8Fc4ZO85x9XG5sSPGh7jT8+MmDLR6y/8by Q5/ZhVTFz62Y2ZxVJdiA8Nkwiya+LYOYtEbtyQjMPJ/EuujYSyhedervVtHvwml8RH1W sbY697/5yvo+jas2IagKTRcWZRc60m5H108v2N6XJYpJoQYtBr+zSDHIB9McBjiDLMvy 3TZw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=nSGoD4tU; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Mj+YyHfp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=adC2RZht; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6aa7d07105dsi208597eaf.79.2026.07.21.13.38.26 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Jul 2026 13:38:27 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=nSGoD4tU; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Mj+YyHfp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=adC2RZht; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Hq0RWL3AeLrLTRzvofYXRfgnNQUqZDv8DTO564Sn8uA=; b=nSGoD4tU+A5MO6drC8EBoVW2ci JWaUlt7iSO1rHY1USNfmdfVDp72bgDZ2PiqX/ZMshbFIU5uu2/eINS8vGyWrET4NyhqIpuOPt8t4B /kQo8ClVZW3+csH1BLiYK1KD0iLa+CqMAM+5DdhPuljoJ6b7Q3X1YFEpFszeFyYNLeHs=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wmHEJ-0004qx-AD; Tue, 21 Jul 2026 20:38:19 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wmHEH-0004qq-NZ for openvpn-devel@lists.sourceforge.net; Tue, 21 Jul 2026 20:38:17 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ueA6b/cRvIPwWCLCy+FVzX82xpJYGd0SNRL49Epf/1w=; b=Mj+YyHfpdB/F3uQ/zyJyt/AN2Y +wQA8TSUbYWgTLdmjHatQ/L4Rjl7zrL3sFhH6JJyWBf2Gcvd16fjOIBUmP8+Toni8DkEeEnv/OBzq i43hQZ6rnPRB8vGU/FkIyPKSjjcQ8JUtd1kTafF8YQm1YMNZ91PlEO/G2y+nWQpjeLsU=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=ueA6b/cRvIPwWCLCy+FVzX82xpJYGd0SNRL49Epf/1w=; b=adC2RZhtJu0vP1HB9pELB5Gz2c s76FHpzylZlzHxv4kaddvflK4VjpdFup9/W/J1w+jmvQjrtX4/EAnCYzKBcasjV7ov4Ru/cOVJygH VTgdWEvFtFpm9IOU3yWD2aseDf1x0pw1EMztUSUJraDehVqOwwy3hfkPB0T9Aytdqn0U=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wmHEF-0007cD-ID for openvpn-devel@lists.sourceforge.net; Tue, 21 Jul 2026 20:38:17 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 66LKc8QK005857 for ; Tue, 21 Jul 2026 22:38:08 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 66LKc8Tp005856 for openvpn-devel@lists.sourceforge.net; Tue, 21 Jul 2026 22:38:08 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Tue, 21 Jul 2026 22:38:01 +0200 Message-ID: <20260721203807.5813-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Ralf Lici If installing a DCO key succeeds, always record the slot in the corresponding key_state. The installed-key counter only tracks whether the number of kernel slots grew, but a successful KEY_NEW still m [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wmHEF-0007cD-ID Subject: [Openvpn-devel] [PATCH v3] dco: make key state desync recoverable X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871358258174795589 X-GMAIL-MSGID: 1871358258174795589 From: Ralf Lici If installing a DCO key succeeds, always record the slot in the corresponding key_state. The installed-key counter only tracks whether the number of kernel slots grew, but a successful KEY_NEW still means that this key_state is associated with the selected DCO slot. Also replace DCO key-state assertions in dco_update_keys() with error returns. This preserves the invariant checks but lets the existing caller restart the connection instead of aborting the process if userspace ever detects inconsistent DCO key state. Github: https://github.com/OpenVPN/openvpn-private-issues/issues/143 Change-Id: I4d0887839b4a13a92e92250d1b315dec949698f3 Signed-off-by: Ralf Lici Acked-by: Antonio Quartulli Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1795 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1795 This mail reflects revision 3 of this Change. Acked-by according to Gerrit (reflected above): Antonio Quartulli diff --git a/src/openvpn/dco.c b/src/openvpn/dco.c index e944547..2584368 100644 --- a/src/openvpn/dco.c +++ b/src/openvpn/dco.c @@ -73,9 +73,12 @@ int ret = dco_new_key(multi->dco, multi->dco_peer_id, ks->key_id, slot, encrypt_key, encrypt_iv, decrypt_key, decrypt_iv, ciphername, epoch); - if ((ret == 0) && (multi->dco_keys_installed < 2)) + if (ret == 0) { - multi->dco_keys_installed++; + if (multi->dco_keys_installed < 2) + { + multi->dco_keys_installed++; + } ks->dco_status = (slot == OVPN_KEY_SLOT_PRIMARY) ? DCO_INSTALLED_PRIMARY : DCO_INSTALLED_SECONDARY; } @@ -166,7 +169,13 @@ /* if we have a primary key, it must have been installed already (keys * are installed upon generation in the TLS code) */ - ASSERT(primary->dco_status != DCO_NOT_INSTALLED); + if (primary->dco_status == DCO_NOT_INSTALLED) + { + msg(D_DCO, "DCO key state mismatch: selected primary key is not installed " + "(peer_id=%d, key_id=%d, dco_keys_installed=%d)", + multi->dco_peer_id, primary->key_id, multi->dco_keys_installed); + return false; + } struct key_state *secondary = dco_get_secondary_key(multi, primary); /* if the current primary key was installed as secondary in DCO, @@ -190,6 +199,14 @@ primary->key_id); } + if (secondary && secondary->dco_status != DCO_INSTALLED_PRIMARY) + { + msg(D_DCO, "DCO key state mismatch: expected old primary key is not installed as DCO primary before swap " + "(peer_id=%d, new_primary_key_id=%d, old_primary_key_id=%d, old_primary_dco_status=%d, dco_keys_installed=%d)", + multi->dco_peer_id, primary->key_id, secondary->key_id, secondary->dco_status, multi->dco_keys_installed); + return false; + } + int ret = dco_swap_keys(dco, multi->dco_peer_id); if (ret < 0) { @@ -200,7 +217,6 @@ primary->dco_status = DCO_INSTALLED_PRIMARY; if (secondary) { - ASSERT(secondary->dco_status == DCO_INSTALLED_PRIMARY); secondary->dco_status = DCO_INSTALLED_SECONDARY; } }