From patchwork Wed Jul 29 10:21:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5171 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746444mac; Wed, 29 Jul 2026 03:22:26 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RoARfQER9LV9FgUoMmOuI9aYwAOcCv/gyol9JUd3NNP6CLbUiFYt+GsN0UanpNNdNwV89P4t1iFuos=@openvpn.net X-Received: by 2002:a05:6830:4102:b0:7dc:df37:844b with SMTP id 46e09a7af769-7efff074021mr3930551a34.4.1785320545835; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=ZXC9uFs+PKRaFudWdSBXbdTQHvjjiQldBRgldCfhp7kS5YWRGX3c8QT8v2wPXhnT6K hCIc+eRhBRB4VP/AualQjSpsJJH2ZE8+H8wAAd8fEO0aJMwK1b/+A+MZgw0GiYXdNYCI 0tR0PIR2ghwOIwXd7ZtT+WSZOx9bnawKqtiMDQXAsjbK9FQvFz6mPIy/0ed1pRjkHM4R i5UqoQbiO9xRxWczDglbzTGXNM/N1aQyaP/L/jzltiBBt8fIzhVn8BJHtJ+XqzOuc/Cp Df7QHHwaPjWCkXZxYHQJYTiYrAMvzKYrJ2rN8jXCozh9gmZ3/bIQFTOENd0KYaOAcBOD o+KA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=61ipKnQQAYvhUMxo2PFCwGxoR6f2W5CnPQsPuEvkTuM=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=I9vyNqno4/x3Q9NWQ6t98tS2OdB55tQyHA3QUvV5gw4x9QP3nhl4fw1GpQyDsJ650x yU+wZbp1JaBOA/bPudAiFZqtY31/aRUpvc/AMybxrhdAJex4XgG1OuFyv7+kbA2a1ARb uWuDKYmQiJpGi63mI4CwkOyrYGnvLaF4t2yOvcXvxLKO33jvTvRoQL64NR9Wa2cbQOtr UMspim9hX7ssbXLL+LFqr7K9Y3uRSaoxebHSKGfxAHPi2ikv78iSNlf61rLKYbZUBq6J DinCbshsfJYASU9RT2nNVSCfkCP2ElyM2z0gOoecMg2HasstlfkdMJQ86Lq/gwLiI1b0 ZkYw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ed3rLNMq; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=J5BTP+XP; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=lD+2Aauw; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=wrIirvsr; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f00d5df5b1si1932983a34.1.2026.07.29.03.22.25 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ed3rLNMq; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=J5BTP+XP; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=lD+2Aauw; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=wrIirvsr; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=61ipKnQQAYvhUMxo2PFCwGxoR6f2W5CnPQsPuEvkTuM=; b=ed3rLNMqa1DSct9BZ+i7G6GAck PeqGm2fMZwypoYvQpFupo1rmU4tBknKVl/1TjeKXRXW0nHJe4GEcxpz0G7lFwvt3mO5W94zfqH1N0 fSxgq4MRZwuEz3iH4k7bZqoRd4p0Ofg1AHy1WcN4xRrWQajbPfJw8kuSkGsAKUgo5nfA=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qc-0004Aj-2W; Wed, 29 Jul 2026 10:22:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QM-0004AM-3b for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:06 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=9epp/RTDoFQYD1vdJo85EGEdQLGumxZFFX94OPVbfCw=; b=J5BTP+XP/dYoCTgOEChpGecm8Z 0m7Oue5cKABthdpFPzIvlmIOi/6yKi4ChGrYqskSfAE/f+yCktW931BUFO5mAJavm3j+SAsYvBInm dBa7u6tWqpjLLH0QhLzMM6fzeMWk11wmTqgM52hxrf9pFujkx/UZxWYmvJfXj3zGH6v4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=9epp/RTDoFQYD1vdJo85EGEdQLGumxZFFX94OPVbfCw=; b=lD+2Aauwg6Klr13cIGewfpIvfK dRrMac3cV8KmOliO3wGP9CgxWz9psOe2NZnBWj3pOAr+g1TUCgJms3OJZ/O8zBn8WPMY/DuJrCcyM ObcatqaHE/4p5xyzTm5saa/aWsQsiNOLmBT4UrIJ68enfQr8bzkTS80z9u+HJ9aGGaq4=; Received: from mout-b-106.mailbox.org ([195.10.208.46]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QK-0003UW-EI for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:06 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-106.mailbox.org (Postfix) with ESMTPS id 4h97fr07bdzNljs; Wed, 29 Jul 2026 12:21:56 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320516; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9epp/RTDoFQYD1vdJo85EGEdQLGumxZFFX94OPVbfCw=; b=wrIirvsrmPzJDe/0NfmjDj5LegbhkmUXeoPqwmwPMPuB/YFFYlvhqBttsyKoba7ZcLBlxt jGzHaLqPVgS78oh7d9l689aJ0hxJMq7TGuC3Jf7Ic6mXlQIdxCXDZ7VSuSqw9u3l7TXtf2 P3F8OJn4w1VzK9nTka8XmGXs0VYuClOvBa4S4SLk5reWKBCI0txJATZgv3/+ztUmHq6O00 3ZIIqzWytaXC4NpYxCiAGZDyUjZrSd/T1uieFzMuFFEA4eudlKFWyGj8n8AByvn7pwodHq oX+VmYvMDrETJiGVPRiHyksjTdNfXKwmDo4ACK7WedyGS9nOT4OASRp92drvZQ== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:41 +0200 Message-ID: In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fr07bdzNljs X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn_crypto_kill_key assumes both crypto slots are populated and dereferences each slot before checking it. That is not guaranteed: a peer can have only one installed key, and the kill path may be ask [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wp1QK-0003UW-EI Subject: [Openvpn-devel] [PATCH ovpn net v6 1/6] ovpn: fix NULL dereference when killing missing key X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044276744128096 X-GMAIL-MSGID: 1872044276744128096 ovpn_crypto_kill_key assumes both crypto slots are populated and dereferences each slot before checking it. That is not guaranteed: a peer can have only one installed key, and the kill path may be asked to remove a key that is not present. Read each slot once while holding the crypto state lock, check for NULL before looking at key_id, and only replace the slot that actually matches. Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/b2f5120a3efa20c62a83397d96e949eac6a983df.1783336121.git.ralf@mandelbit.com/ - Rework using the slot-based shape (Sabrina). Changes since v4 of this series https://lore.kernel.org/openvpn-devel/981d2ea51cca45138210aa52c6e5a0e55c0da7a0.1783099626.git.ralf@mandelbit.com/ - Add this previously posted standalone fix to the series so the whole set can be picked in order. - No changes since v2 of the original single patch https://lore.kernel.org/openvpn-devel/19318904cf077d067cd4ec628a22bab03ed7dd29.1782993857.git.ralf@mandelbit.com/ Changes since v1 of the original single patch https://lore.kernel.org/openvpn-devel/9fc33e6f9fae10b9e372a3e06934d697edf5b024.1782829171.git.ralf@mandelbit.com/ - Remove unnecessary braces around single-statement if/else branches. drivers/net/ovpn/crypto.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/drivers/net/ovpn/crypto.c b/drivers/net/ovpn/crypto.c index 90580e32052f..2e95f29514fc 100644 --- a/drivers/net/ovpn/crypto.c +++ b/drivers/net/ovpn/crypto.c @@ -58,15 +58,19 @@ void ovpn_crypto_state_release(struct ovpn_crypto_state *cs) bool ovpn_crypto_kill_key(struct ovpn_crypto_state *cs, u8 key_id) { struct ovpn_crypto_key_slot *ks = NULL; + struct ovpn_crypto_key_slot *tmp; + int slot = 0; spin_lock_bh(&cs->lock); - if (rcu_access_pointer(cs->slots[0])->key_id == key_id) { - ks = rcu_replace_pointer(cs->slots[0], NULL, - lockdep_is_held(&cs->lock)); - } else if (rcu_access_pointer(cs->slots[1])->key_id == key_id) { - ks = rcu_replace_pointer(cs->slots[1], NULL, - lockdep_is_held(&cs->lock)); + tmp = rcu_access_pointer(cs->slots[slot]); + if (!tmp || tmp->key_id != key_id) { + slot = 1; + tmp = rcu_access_pointer(cs->slots[slot]); } + + if (tmp && tmp->key_id == key_id) + ks = rcu_replace_pointer(cs->slots[slot], NULL, + lockdep_is_held(&cs->lock)); spin_unlock_bh(&cs->lock); if (ks) From patchwork Wed Jul 29 10:21:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5167 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746428mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqcbVCvaSw9DuKkAeDiRQPRDUPTnmtXDM87YJj8psmDn26KG4PiSj0PFVa94F4mkYNgXUWmaKQBdug=@openvpn.net X-Received: by 2002:a05:6870:1414:b0:430:b7d:f248 with SMTP id 586e51a60fabf-4586cd28564mr3628971fac.24.1785320545144; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=aRKbRitT7PY4Ko9Gs4enZm8XozMjNSzuGvB3RTqN+f37ur2q1ZSr0tgAXrCPwpghEG CgG6mKprrffxdHZeW7oKGgaLBLQNy9G6qUFXe3G1R5FlgJJvnnwjQVZBsQvTm71ZBpJ4 qSx5GJN2oOEoGeqOTtolurcvDS6iRif8gGzPU9Q45gMysX2m30F7crJ1eLwWwZphfLB3 J9Ooegu7o2j5uKtUi+xtqSNbQouRVIp/+Qc/xY2w1Y0FpHDeIWLDkNIfPGQnw5/+9ilI zeS7Vf/8N2zxeyirvRKSRM1TD6/RGPGPvMOiwubb56gT9AArO995EoiFO5M4BFy+EPCU I3dA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=kMNkgUjNrDHWjhafr/m2PoOCq5FcztEQ3XSBKmeFVzk=; fh=bDmbXayvKcQuWZaaz4JM7kgnS3MJBk3QUq2ehqNuBVc=; b=sKdPew3648nkqi5GUH+yG0mJ+RXgT4RrdP2RdZ7TImRbF/qO+n2sdIowCJ9A5c0ibC J1OJoO8cfGPlMDkxTXYYqaO91FYP0SK+/jo8eOSF8upeTgK+w+o/PepSCWj2xc/Tl7+n zl7rZ8LKamjdOE9xbccGd7gcHAbTGEnBxG8ftXFUduNniXqIWlJtJeHbxtGO7n1NZXd1 s5plx6kLzpfxJOMRWil8Hg/2+W93X7vaYlXD6LgOc46G0iFdSy98rU7niucDkFz9Omwj 36vFHAFrddGZ+fXxCGWmZwvv7Z8JKLJwB9QyYJL6RoZ6Fqt1v17/otSkXvzTzvqCkB/n 4/LQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=AGVKeG4y; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=ZpZkhczZ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=bnjGu8J6; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=OuckQJ77; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-4588696519fsi2310648fac.140.2026.07.29.03.22.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:24 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=AGVKeG4y; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=ZpZkhczZ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=bnjGu8J6; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=OuckQJ77; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=kMNkgUjNrDHWjhafr/m2PoOCq5FcztEQ3XSBKmeFVzk=; b=AGVKeG4yM0+P3kB4PguHMr3Osl QYs+f0fvknZuttvmMlpJ2B0CeIgrH6hC/4wsQwfVE9wIy4oUwzqxX9B9M/111vccZlPKMkuOBVnY2 xXq5q1SDLZWzXf/PUaxxfUoClaB/cA1eEIC9cvi6mvRVzdIV5JQiVJqO79X7yaAwmeOg=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qe-0002o7-9C; Wed, 29 Jul 2026 10:22:21 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QP-0002nc-WF for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=s7mKFePLkVlKhOpo7ibGf89xR4bksuWw337+41qyzQA=; b=ZpZkhczZJnGm/hVneSf9J9FTD9 NiUG3fWIhKIK2zf3DBbmOTS7B8aV7SUS/IYXZvmm5XF6dzeDTI37Rb5KKSbrDwgfqQxAP3vifYrNs dvuwW9VYxWk/s3B/gVgCk/Vnx+vPTRndS+/dhkMwJW1IV8NxQUYu5TmRQEeRg5saoas0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=s7mKFePLkVlKhOpo7ibGf89xR4bksuWw337+41qyzQA=; b=bnjGu8J6GR36wys6XvYp6G/HHA +NUv5FmoE1wPxqKehnQWl9cFnsm4MHWHALwabW/rx5Ge6bfjJvlW7I14Xb6kNKlKkWOpLc4dks7i/ QhMcbnbFTzreTZzXXTfrgo3DO+Nb1qt++eBrzO1MksHWhk+EA1yFFw7vP79QCClVxyGw=; Received: from mout-b-106.mailbox.org ([195.10.208.46]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QO-0002fC-Ru for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:07 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-106.mailbox.org (Postfix) with ESMTPS id 4h97fs0SLHzNkMP; Wed, 29 Jul 2026 12:21:57 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320517; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=s7mKFePLkVlKhOpo7ibGf89xR4bksuWw337+41qyzQA=; b=OuckQJ77/xY1Ohkm5e9wVza5iH7JcnwFEVUISPpIojZ+rGkeH9Qy32kSnOAzlbkwiy83q2 5dGwJtGyqRd/uJyylqi/3tVf2hUulSdDlb8HBQ82iYTKfF4UeTvMS816riWDdrxJRmiggP 9Bt1Hdo19zRo9HZ8sQX+b1JKd0fYBHk/16K9VKWSgKvlstMXKPoHYjWW0ig6KKNjt6M9tz oA9QjAx2ahsrUskyJ1QNXEEZxpkz4Tomycb4e11fQfWAQhsUrdkIvFQDG81SlAtaZWtR97 AvSMbrvbtjE0gooT0tQCg9Y4UdOfQeBDteO380YhmXpwLBxtjCYOTw6h+0MD4w== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:42 +0200 Message-ID: In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fs0SLHzNkMP X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Currently, in ovpn_nl_key_swap_notify, the OVPN_A_KEYCONF_KEY_ID attribute is packed as a 16-bit value despite being defined as a 32-bit u32 attribute in the YAML policy. Fix this inconsistency by using nla_put_u32. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wp1QO-0002fC-Ru Subject: [Openvpn-devel] [PATCH ovpn net v6 2/6] ovpn: use nla_put_u32 for the key ID attribute in ovpn_nl_key_swap_notify X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Sabrina Dubroca Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044275932889438 X-GMAIL-MSGID: 1872044275932889438 Currently, in ovpn_nl_key_swap_notify, the OVPN_A_KEYCONF_KEY_ID attribute is packed as a 16-bit value despite being defined as a 32-bit u32 attribute in the YAML policy. Fix this inconsistency by using nla_put_u32. Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion") Reviewed-by: Sabrina Dubroca Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/6e44855f0fcd704da43dd83b42a1236cb804c76e.1783336121.git.ralf@mandelbit.com/ - Add Sabrina's Reviewed-by tag. Changes since v4 of this series https://lore.kernel.org/openvpn-devel/981d2ea51cca45138210aa52c6e5a0e55c0da7a0.1783099626.git.ralf@mandelbit.com/ - Add this previously posted standalone fix to the series so the whole set can be picked in order. - No changes since v1 of the original single patch https://lore.kernel.org/openvpn-devel/8577555cc95646d0bd58a5b78e59c7e6a9b1a0c6.1783058844.git.ralf@mandelbit.com/ drivers/net/ovpn/netlink.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 4c66c1ec497e..abf038206a62 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -1335,7 +1335,7 @@ int ovpn_nl_key_swap_notify(struct ovpn_peer *peer, u8 key_id) if (nla_put_u32(msg, OVPN_A_KEYCONF_PEER_ID, peer->id)) goto err_cancel_msg; - if (nla_put_u16(msg, OVPN_A_KEYCONF_KEY_ID, key_id)) + if (nla_put_u32(msg, OVPN_A_KEYCONF_KEY_ID, key_id)) goto err_cancel_msg; nla_nest_end(msg, k_attr); From patchwork Wed Jul 29 10:21:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5166 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746425mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Roemtjl2j54ldrBeHg+eeHrbhTWxVYYneHpLufRjfiZHdBH3G5n3mcupu4rQfz6VglXsEzzJOvWSTI=@openvpn.net X-Received: by 2002:a05:6808:19a2:b0:4a3:5294:43d3 with SMTP id 5614622812f47-4ad5b966694mr3894069b6e.3.1785320545177; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=lGsuvH6yYqpEAGYiFiYIEq1iBPvr0c14ykUx2qghx0mZKcBcY2ZO6LckU/Y03m+s/r 0JPDaD/eplVR1dBHgt+atWWyfu8OrR2n0JfsvmKrZYsyaXMonyWpqbDHN8gQh7JzjPUG IriRrjGBdEsI28vbH+dWhfY4TORSjO7h67vIyy8CFMwDVlkNQ0QW8fg6nTVFsWyj/JUw nlrWBeHkxWP/jzYUzaCtCkX3XDjdU+EIfJOAFRH8yByhzyYaj/GB8luhyHgX7NLWShwn vD0Uh+cnhVTLiri7nyl9u3kK6DlGElSoAh3dLLycU6Jb6y0at/Ch1rbHHEBDYw/07mr5 mrWg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=e89kIFnmwRNssbGxBGgtnZI1ArLKDVAoiXXXoiSuFq4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=Y2oL9+Kah8VYHTf1Ta+ImTrgWX4Y8EMegCPnmxSwEgTU7Y2moCoEii3gkkjhjHnD/Z RUtQapP/9KqNarPqz87dDYf+rLqPhB9d7T+6JDGQDPuBX6t8Ukh1dmVuoNAmv8LVWnoM 98flpL3LE4ZPJH0T3iU01GV3ZginE9sNn6xKpbqY/1QhElU6ALdZ6Fc1E3ozLXU/YGrB UEmPYkaQrkVInJvR79H4w6aJgDjnS3xau5BSuQJpF8uL/ZSgu4jYONg/tfCxN/qxOUMD /DylsYoE6EIcL5Stp0mIzxRtyLPC9d+LHon+8ouR41L3BfZCJEVdhoERxdgXB2KjRBB8 3DtA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=WiqyKvS0; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Xq4sKBC8; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="emncrh/N"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=G9cWrdJg; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4ad6ecab2a4si1321616b6e.26.2026.07.29.03.22.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=WiqyKvS0; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Xq4sKBC8; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="emncrh/N"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=G9cWrdJg; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=e89kIFnmwRNssbGxBGgtnZI1ArLKDVAoiXXXoiSuFq4=; b=WiqyKvS0otuwRGPlgRirUX+kje PUI0k/dAq+mapnu6nkTOrrLr8F+7mF0qPlmLwOnVCT9VH19hEfG0KVBagNJTxgqHS0GJ/Q5pKMEy4 WuKFY1/f+vViS5QSU3Dw3cZfE6cL9MoXWzpjutbsekYR6HbpHk3BhIwSD8rxzKYiyaBA=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qa-0000Pn-09; Wed, 29 Jul 2026 10:22:20 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QN-0000PC-6E for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=cVEdZ3i3t9wUqjfdfrCLPyF3EcQBf+QdLVZrCqcZubg=; b=Xq4sKBC8OERBnxWA68nn0XuGQ5 zsFyTmCAQOHBHC3y/M6EFhQ//C3LREbc9CzOUU84j2uco0Xy0VbhbwqN8URyi120krda8t1yZKTUz K9AnNixLyeH/cvWTLyyNlqbNovj9m2W/nwZOyP6kO2yBqjG/AKc28ASaZpJkBGzZW2wE=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=cVEdZ3i3t9wUqjfdfrCLPyF3EcQBf+QdLVZrCqcZubg=; b=emncrh/NuDge0AV7hLSytyVGQx P2TByKyAq0FQMlkC5V2e+knhJa2w35FxN/QB6cqQWRwl1zFcpY7F1TYeekOMS+i3F4k+njMJ12hQZ hdw62Jb9vi3n4ViB8/ZYdMt0cA40W4rUGENdGPLQbpjCvP3003C9FQO5jDmwHgPsaFxQ=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QM-0003Uc-4v for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:07 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h97fs5Yc4z9smZ; Wed, 29 Jul 2026 12:21:57 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320517; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cVEdZ3i3t9wUqjfdfrCLPyF3EcQBf+QdLVZrCqcZubg=; b=G9cWrdJg84cU6ROy0emz2fUmeZbkRmkkzWPIOe462T4X3zOZhlPQ3UEgrYFxA1A1uVPZS+ PIsWBPNr+I5oNmYOe6R8jocIwy/C2dTdc2GUaANHDPpRKbipij36h7C43S/gRuALCamAr3 wCM9hAk4FjNp5pjQJubM2pGakNjerer5smVWYGHa64O8p9EOsqkdhmkJM4sk3j7mGGvdWI Y2XQ1wd8HErwMepRVsBRKVB7vIOqXNWxfiF/jiZpjtP/ZjZk/wdhD4b2qYEjRiq6TjAa7b oPSVqXWqJUzvtFRM67sSGu3DS8if4bvyCcDWOWUn/d+5PyHEMeNdqMpjRSazXA== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:43 +0200 Message-ID: In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fs5Yc4z9smZ X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn_tcp_init initializes the TCP proto and proto_ops templates used when a TCP socket is attached to an ovpn peer, but ovpn_init registers the generic netlink family before initializing those templat [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] X-Headers-End: 1wp1QM-0003Uc-4v Subject: [Openvpn-devel] [PATCH ovpn net v6 3/6] ovpn: initialize TCP state before registering UAPI X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044275660955051 X-GMAIL-MSGID: 1872044275660955051 ovpn_tcp_init initializes the TCP proto and proto_ops templates used when a TCP socket is attached to an ovpn peer, but ovpn_init registers the generic netlink family before initializing those templates. Once the family is visible, userspace can create an ovpn device and configure a TCP socket while the TCP templates are still zero-initialized. Initialize the TCP templates before publishing the netlink interfaces, so externally reachable setup paths can only observe initialized TCP state. Fixes: 11851cbd60ea ("ovpn: implement TCP transport") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/8f7261c5719fd67b8f0da4d0e89f2c4517fa8168.1783336121.git.ralf@mandelbit.com/ - Reword the message and drop the extra comment in the code (Sabrina). New patch added in v5. drivers/net/ovpn/main.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 9993c1dfe471..5093a3b5aba6 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -233,8 +233,11 @@ static struct rtnl_link_ops ovpn_link_ops = { static int __init ovpn_init(void) { - int err = rtnl_link_register(&ovpn_link_ops); + int err; + ovpn_tcp_init(); + + err = rtnl_link_register(&ovpn_link_ops); if (err) { pr_err("ovpn: can't register rtnl link ops: %d\n", err); return err; @@ -246,8 +249,6 @@ static int __init ovpn_init(void) goto unreg_rtnl; } - ovpn_tcp_init(); - return 0; unreg_rtnl: From patchwork Wed Jul 29 10:21:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5170 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746439mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rqg/QdxETtSD+CCBlcR0VtwB9Jm40ctmqNgniYkgujF4yCSXwtbkZNT0vjD2liIPIkQl55dhbdhL54=@openvpn.net X-Received: by 2002:a4a:ec42:0:b0:6a3:9215:3b75 with SMTP id 006d021491bc7-6ac96de04fbmr3046111eaf.66.1785320545703; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=Ncl9rBf90Zsc9VdVfvnvIXt72g0hsTo0YGjRmEy7njOGl5rfC+/KoKoSt1ex5nGAYu DoMxS9geEaMjcwbhSAiqE4noxMi14LwnoA7N9V4JWkUr06mlFM3l9GdT6LDATGXafTlc xmcw3Hgbj+kGPG2NlSMVqebINexMqk3MwP9rWemY7LbhirPBTvP6w9jm8qmFllcwsX23 HoYV2DUFOyBg+44gSOIEoDpXEcqy7aLyZZh6CxTZpZqnLsD2JPc54daV58lqCdSqkOiG HbH+3NFahcfqeejrqzlFWuGXRVKjQycZMaS6Rm+43qcK5HwqkklODRh/7JX2tV21al73 UuIA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=J0CIzUvtLzpBY0ADK34s1HiTczXhEdGD7rGTQIdW7fw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=M4Y62a1WFn28Su4Nb0Zh6+/fNpJs3u/U2SZ76xP8ksFve9Pc30BVK917fRRA7f+0kP imiXMh/0nzSTt5fHC0bzl6XofIGZ1Se7kb4dyS42UJmqRuJILJ2JOwXd6gpqw+xGa5hJ fWZJ1/ygHst7QjwFSms73mTQTqsfxQ8eN+e2F2s9lc43y1/G377UdfjHT0oYwcVBK7qm oisAfbTHNxHk3M9ug7UWaN31Secq1nR8F7NMXmtQInlZr7ORLqnWo2L4smQqkW9Xfk/V bv+71wD8hrzAZ9PIzbygiUqystYQFLbHP8klhywILruXFtlj9y/R2rs4ysPuukzTj4g3 Yqdg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Z7fqNAfy; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=GlLqb0Jl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mKYPPhFg; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=0wAAJex0; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-458869657b3si2350621fac.177.2026.07.29.03.22.25 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Z7fqNAfy; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=GlLqb0Jl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mKYPPhFg; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=0wAAJex0; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=J0CIzUvtLzpBY0ADK34s1HiTczXhEdGD7rGTQIdW7fw=; b=Z7fqNAfytaDoNb9uWgwO8peOt2 gmpoQz7ljnSSxAIVZFW9sem0zt8hfqd/WrW5EhDzmRn+JYTrU6y9UMZGOQOCV5A3GxpeuRQMudKKW 1OLNEodycS759k6r4t9/EIBsxZ6tiCox+Z1sOnqCdxhkfTuHKVhPQQaL0aSAjdZSo5pQ=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qc-0004At-Dw; Wed, 29 Jul 2026 10:22:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QQ-0004AW-SS for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:10 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=cTf/bhGf8rX5ITyQ0t3ft3oRbgdO+t9mKY6Liyetwdg=; b=GlLqb0JlT4gzFlU7q32e4UFQPI pp89zEStnYDPfDew4V0v5WowTtqz4ltEz6T3Gn18nvt83HUMRz1US+w/KVchmSvHgkvF+yFCMlJZ/ smSKQRdIG9a0PGI2vItA3wFM+zl/Vrj/uwJHEAt+2VG22/28+7PMv5MSq/u0gySUTSk4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=cTf/bhGf8rX5ITyQ0t3ft3oRbgdO+t9mKY6Liyetwdg=; b=mKYPPhFgVw2F4HViQWCCUWnpq1 GHvuTmgZooCNs/uCtjfhKNJYiIBIn0n7NFvuf1zNSYpjABsTZHlMvOp4RykE+oS8PS1aMX6oUPA26 aVQc9tSp7v8CwgVKsMtNOiq7yAR34+2Qr5CYyaf0EH+57juCKMm0Q0UL0NxgP71pdEdc=; Received: from mout-b-110.mailbox.org ([195.10.208.55]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QQ-0002fD-7o for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:10 +0000 Received: from smtp102.mailbox.org (unknown [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-110.mailbox.org (Postfix) with ESMTPS id 4h97ft2xp1zNlG7; Wed, 29 Jul 2026 12:21:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320518; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cTf/bhGf8rX5ITyQ0t3ft3oRbgdO+t9mKY6Liyetwdg=; b=0wAAJex0KgpIGbU3eVDkSAbWlcHZBhcPUs332d0hw3NYPTkuNlHhrT/cfBEMUYbcr8fSjk QV070kJLueYcYyfnorOjMIGTXoVLvRaOULE62S+fAbBfK1UKPyXe6HPXncj9Oj84Llisiv +JErXa05Qu7YsxIhBlGqiD6fEgZhQB7sXSr8xLOzCubuMhmUuw13rR8xUCb5rk07OeDxNX b0YDAU9Va5iDc39Sx8athhTFlPc3NsgE7GMTdFprmKPLWv984ADy072USTquEicuigqX3j gzhCxVoZNF8+139khBXHuZkXT7d/xqIANmNJsiXblsUFoDXWRT2F/kWdYkKIsg== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:44 +0200 Message-ID: <9f5ae15a10087fe7bb258594ebd745818401da4a.1785318038.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Crypto completion callbacks hold both key-slot and peer references. The peer reference pins the netdev, and dropping the last peer reference can let netdev unregistration and module removal make progr [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wp1QQ-0002fD-7o Subject: [Openvpn-devel] [PATCH ovpn net v6 4/6] ovpn: finish crypto callback cleanup before peer release X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044276379202347 X-GMAIL-MSGID: 1872044276379202347 Crypto completion callbacks hold both key-slot and peer references. The peer reference pins the netdev, and dropping the last peer reference can let netdev unregistration and module removal make progress. Do not release that peer reference before the callback has finished its own cleanup. If ovpn_crypto_key_slot_put runs after ovpn_peer_put, it can schedule an RCU callback backed by module text after ovpn_cleanup rcu_barrier has already run. The TX error path also freed the remaining skb after ovpn_peer_put, leaving callback cleanup outside the peer/netdev lifetime window. Release the key slot and free any remaining skb first, then drop the peer reference as the last callback action. Fixes: 8534731dbf2d ("ovpn: implement packet processing") Signed-off-by: Ralf Lici --- No changes since v5 https://lore.kernel.org/openvpn-devel/7336c4c945f4d8f816b57da2525c8f7b037cfa46.1783336121.git.ralf@mandelbit.com/ No changes since v4 https://lore.kernel.org/openvpn-devel/981d2ea51cca45138210aa52c6e5a0e55c0da7a0.1783099626.git.ralf@mandelbit.com/ No changes since v3 https://lore.kernel.org/openvpn-devel/f367b736f2597edb1677794173997d5a0f9f599c.1783080055.git.ralf@mandelbit.com/ Changes since v2 https://lore.kernel.org/openvpn-devel/567de7a9371ce72b0632158799dd11bb543cae08.1783068961.git.ralf@mandelbit.com/ - Also free the remaining TX skb before dropping the peer reference, so crypto callbacks do not continue cleanup after peer release. drivers/net/ovpn/io.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/net/ovpn/io.c b/drivers/net/ovpn/io.c index 9a66d693039a..9526f8096da6 100644 --- a/drivers/net/ovpn/io.c +++ b/drivers/net/ovpn/io.c @@ -204,10 +204,10 @@ void ovpn_decrypt_post(void *data, int ret) ovpn_dev_dstats_rx_dropped(peer->ovpn->dev); kfree_skb(skb); drop_nocount: - if (likely(peer)) - ovpn_peer_put(peer); if (likely(ks)) ovpn_crypto_key_slot_put(ks); + if (likely(peer)) + ovpn_peer_put(peer); } /* RX path entry point: decrypt packet and forward it to the device */ @@ -302,11 +302,11 @@ void ovpn_encrypt_post(void *data, int ret) err: if (unlikely(skb)) ovpn_dev_dstats_tx_dropped(peer->ovpn->dev); - if (likely(peer)) - ovpn_peer_put(peer); + kfree_skb(skb); if (likely(ks)) ovpn_crypto_key_slot_put(ks); - kfree_skb(skb); + if (likely(peer)) + ovpn_peer_put(peer); } static bool ovpn_encrypt_one(struct ovpn_peer *peer, struct sk_buff *skb) From patchwork Wed Jul 29 10:21:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5169 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746435mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rr9iBTyO3vQCTvUFzDANEk0+QPPyyBp2edkGxiPgF1+cAEUyp3GmOcnPIMIt6r7Nrd6wWSffwA9E+c=@openvpn.net X-Received: by 2002:a05:6871:680c:b0:456:b6b3:5b4f with SMTP id 586e51a60fabf-4586cc8aca5mr3510501fac.15.1785320545421; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=g+oHvik1zJkH205gKuhWKcRfKVUynF9iHF9fVAbHPnylVE5uJj+/Q1vGy/7jxLNJid ZR7yqxRycnlfKJ9YunOoNQbKptQ8WANEjzH6qMeQbHLEvh22HpuPBY46iyl2VL9dxKpu kTyRGZmixlVM6K+Hm1wYsWSOFYpr7nJmePAmURu3ukJq6sYTrWrmSQJLMrw9LwjJ2jAM J1urZ3SajKB774UnvT8XQRymqQ7QPyysz9nwlxvGWMiXYPEhcnlKZYLuMSGFsseGzkpG 9muAhBpMwUnzxKPK8/KfppRnvdICm/pT9NVFB16SKhz5c/ZplMJ4C/Zb2/FzIBMgDkQk QkCg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=VrxwItvEhFf40sVA8AsGqTMIdNR+EgsDh61u9lxhdZI=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=JtftEgwOQoyPBiah0W5jbd0P0pWB3E9Nj0d0eqhP/i93G+BE2fj0gRMkciBfVNqKVD RgSIhNoM8XBPHjQ+xUqbT/3xBYGWtvRcPzo6245/zODQ7U3muG7gqt4DEcPvZkKom/U7 9Jgkg7h/hEHrP56lUTV96nOeukoebETFtQ6NwmpVQsVBeYM29eRm0Hn2l0dc6fvt9z0L Mcn7WcJcPYad4yzq8yAJaGHxRW0ZulzMjYElOBNSmohLKw+aIAgQGHHGf5wU/gp/egGZ IDlxFROpY+VivsEQREdQYiGYBe8XF2UNJ+/o08eFdAcC349sYq3q7+Qyh0zpwEBblVWL Cs3w==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Yjl3HpIT; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EhA82whe; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Q7OizojZ; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=nkeWkOvO; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-458863b6efbsi2189299fac.62.2026.07.29.03.22.25 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Yjl3HpIT; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=EhA82whe; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Q7OizojZ; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=nkeWkOvO; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=VrxwItvEhFf40sVA8AsGqTMIdNR+EgsDh61u9lxhdZI=; b=Yjl3HpITb8bZSfem5+vCAgOySP ZZgu3+x9/iXZ0PjFR7smVq8xksWrLIhtoLY+eH2toQqBjGUJ/a/QxjDoYhfbfHed+xLYCy4sdZKZz rNwuCpJqXvyGIp4KRbdlkV5J7DNrpxx+Qd1lx28BFKc91RxMykbXh41gM4I/kg4DOmaY=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1Qe-0002oK-MB; Wed, 29 Jul 2026 10:22:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QT-0002nk-VE for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:11 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=EhA82wheEXIW2+CDym9fIJaAZH QgBWT9akhbLvzb6rgbpvXzCftRM3jUVfGaf9pARFJs2lgOl8yBNOBfswKvDV0mXvG/Nt6kVSUkAWd w3NJ/vJeMqwah8qPKxpMKE57t0VzYEtlkfmsy2EZ1jrHaqL+M0N3bt17xAsU+inhBDzA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=Q7OizojZY3TdT2u9r0D89/a2np eHqBcr4OwxxdNOUv++XYA7afDO97sRqd/TzVWw5EE1pRXKduRqeu6KfEaRhf8V3PMCiSMT2unTSlP sBjEJaXdI3sg/XkbRTflj+J88ySesosFcIiJPK5KwTo1Hiv8WHuoZpaSUzM4DAK2R/xI=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QN-0003Ug-66 for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:11 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h97fv0S8xz9tcs; Wed, 29 Jul 2026 12:21:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320519; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=MKJoF6j+aK8nKirKr2ZQCdrxwKMQUsp7A7+a8+GHQcY=; b=nkeWkOvO8aStAJh8nGbOl97YF+HTZ/9jYGGf5QgIF4AHk9OCS/bPZKxEISYKhaDW7TeIvD Ify1PWW6G2PXXLdrPcIcB1ADsCN+qiEGOUNUzGTykauyb7kL0OGvpswIwEcqA9gwHiLjW8 fE/CT8qMFiAUkn4YYLsWggx6lY3kbQ9u5xObLayxv7W+DbFrHJqgKEaeFknxCTZzrWzSWH cyc0PhhxZQfYKXe9KebGINPO4DdPqb+bFpI4KEfjtdRJdMksYpGWDt48nZqyfQNKvDeGJD kWV6E6jz/gS/TMVG+kHkr7O0f+MC87iw4omMr2cLIueiCNCVWrQPGybal9waig== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:45 +0200 Message-ID: <51a8febf0da1fe17e5fc0b857e8d0a8797002ea2.1785318038.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fv0S8xz9tcs X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callba [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wp1QN-0003Ug-66 Subject: [Openvpn-devel] [PATCH ovpn net v6 5/6] ovpn: run deferred work on a module-owned workqueue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044276575105185 X-GMAIL-MSGID: 1872044276575105185 ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed. Object references protect the objects used by the callbacks, but they do not prove that a workqueue function has returned. In particular, a worker can drop the final reference that unblocks device teardown while it is still executing ovpn code. Add a module-owned workqueue and queue all ovpn work items on it. During module exit, unregister rtnl and netlink first, flush the workqueue so ordinary ovpn workers finish, run the final RCU barrier, and destroy the workqueue last. This keeps the workqueue available for cleanup work queued from RCU callbacks, while ensuring no ovpn work item can outlive the module text. The per-device delayed keepalive work remains explicitly disabled during netdev teardown (disable_delayed_work_sync in ndo_uninit), since flush_workqueue does not flush delayed work that is still only pending on its timer. Fixes: 3ecfd9349f40 ("ovpn: implement keepalive mechanism") Fixes: 11851cbd60ea ("ovpn: implement TCP transport") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/d530ecfc3719845075fbddd0cd7c34752bc2ce16.1783336121.git.ralf@mandelbit.com/ - Update the module-exit ordering for the queue_rcu_work-based key-slot release: flush ordinary ovpn work before rcu_barrier, then destroy the workqueue after RCU callbacks have queued their cleanup work. Changes since v4 https://lore.kernel.org/openvpn-devel/6edfcc51e0855bfd34286b86d4e7f26bb3bcd3f7.1783099626.git.ralf@mandelbit.com/ - Rebase on the pending keepalive and TCP deferred-work refcount fixes, preserving their hold-before-queue and queue-failure put handling when converting schedule_work to queue_work. Changes since v3 https://lore.kernel.org/openvpn-devel/49f38f89340e18ed30543d3990a7a7e20595b6af.1783080055.git.ralf@mandelbit.com/ - Replace the RCU-deferred peer netdev reference release with a module-owned workqueue that drains all ovpn work callbacks before module text can be freed. drivers/net/ovpn/main.c | 19 ++++++++++++++++++- drivers/net/ovpn/ovpnpriv.h | 4 ++++ drivers/net/ovpn/peer.c | 8 ++++---- drivers/net/ovpn/tcp.c | 9 ++++----- 4 files changed, 30 insertions(+), 10 deletions(-) diff --git a/drivers/net/ovpn/main.c b/drivers/net/ovpn/main.c index 5093a3b5aba6..80d10f9ef7d8 100644 --- a/drivers/net/ovpn/main.c +++ b/drivers/net/ovpn/main.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include #include @@ -26,6 +27,9 @@ #include "tcp.h" #include "udp.h" +/* module-owned workqueue on which all ovpn-specific work is queued */ +struct workqueue_struct *ovpn_wq; + static void ovpn_priv_free(struct net_device *net) { struct ovpn_priv *ovpn = netdev_priv(net); @@ -237,10 +241,16 @@ static int __init ovpn_init(void) ovpn_tcp_init(); + ovpn_wq = alloc_workqueue("ovpn", 0, 0); + if (!ovpn_wq) { + pr_err("ovpn: cannot allocate workqueue\n"); + return -ENOMEM; + } + err = rtnl_link_register(&ovpn_link_ops); if (err) { pr_err("ovpn: can't register rtnl link ops: %d\n", err); - return err; + goto destroy_wq; } err = ovpn_nl_register(); @@ -253,6 +263,9 @@ static int __init ovpn_init(void) unreg_rtnl: rtnl_link_unregister(&ovpn_link_ops); +destroy_wq: + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; return err; } @@ -261,7 +274,11 @@ static __exit void ovpn_cleanup(void) ovpn_nl_unregister(); rtnl_link_unregister(&ovpn_link_ops); + flush_workqueue(ovpn_wq); rcu_barrier(); + + destroy_workqueue(ovpn_wq); + ovpn_wq = NULL; } module_init(ovpn_init); diff --git a/drivers/net/ovpn/ovpnpriv.h b/drivers/net/ovpn/ovpnpriv.h index 5898f6adada7..84499140e4bd 100644 --- a/drivers/net/ovpn/ovpnpriv.h +++ b/drivers/net/ovpn/ovpnpriv.h @@ -15,6 +15,10 @@ #include #include +struct workqueue_struct; + +extern struct workqueue_struct *ovpn_wq; + /** * struct ovpn_peer_collection - container of peers for MultiPeer mode * @by_id: table of peers index by ID diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index a21d02ac715e..a80e85a62af5 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -62,7 +62,7 @@ void ovpn_peer_keepalive_set(struct ovpn_peer *peer, u32 interval, u32 timeout) /* now that interval and timeout have been changed, kick * off the worker so that the next delay can be recomputed */ - mod_delayed_work(system_percpu_wq, &peer->ovpn->keepalive_work, 0); + mod_delayed_work(ovpn_wq, &peer->ovpn->keepalive_work, 0); } /** @@ -1287,7 +1287,7 @@ static time64_t ovpn_peer_keepalive_work_single(struct ovpn_peer *peer, peer->id); if (WARN_ON(!ovpn_peer_hold(peer))) return 0; - if (!schedule_work(&peer->keepalive_work)) + if (!queue_work(ovpn_wq, &peer->keepalive_work)) ovpn_peer_put(peer); } @@ -1379,8 +1379,8 @@ void ovpn_peer_keepalive_work(struct work_struct *work) netdev_dbg(ovpn->dev, "scheduling keepalive work: now=%llu next_run=%llu delta=%llu\n", next_run, now, next_run - now); - schedule_delayed_work(&ovpn->keepalive_work, - (next_run - now) * HZ); + queue_delayed_work(ovpn_wq, &ovpn->keepalive_work, + (next_run - now) * HZ); } unlock_ovpn(ovpn, &release_list); } diff --git a/drivers/net/ovpn/tcp.c b/drivers/net/ovpn/tcp.c index 0af14055c39a..8fe8a8e750a4 100644 --- a/drivers/net/ovpn/tcp.c +++ b/drivers/net/ovpn/tcp.c @@ -151,7 +151,7 @@ static void ovpn_tcp_rcv(struct strparser *strp, struct sk_buff *skb) /* take reference for deferred peer deletion. should never fail */ if (WARN_ON(!ovpn_peer_hold(peer))) goto err_nopeer; - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); ovpn_dev_dstats_rx_dropped(peer->ovpn->dev); err_nopeer: @@ -284,13 +284,12 @@ static void ovpn_tcp_send_sock(struct ovpn_peer *peer, struct sock *sk) * stream therefore we abort the connection */ ovpn_peer_hold(peer); - if (!schedule_work(&peer->tcp.defer_del_work)) + if (!queue_work(ovpn_wq, &peer->tcp.defer_del_work)) ovpn_peer_put(peer); /* we bail out immediately and keep tx_in_progress set * to true. This way we prevent more TX attempts - * which would lead to more invocations of - * schedule_work() + * which would lead to more invocations of queue_work() */ return; } @@ -487,7 +486,7 @@ static void ovpn_tcp_write_space(struct sock *sk) rcu_read_lock(); sock = rcu_dereference_sk_user_data(sk); if (likely(sock && sock->peer)) { - schedule_work(&sock->tcp_tx_work); + queue_work(ovpn_wq, &sock->tcp_tx_work); sock->peer->tcp.sk_cb.sk_write_space(sk); } rcu_read_unlock(); From patchwork Wed Jul 29 10:21:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5168 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1746427mac; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Ro881rUlfeYmjZR/T22Eh4UXYd5tauzoJlJSozweSc5XPjyzs8wKtkwsTMtQQWqgFqTfRSpKzkCCJo=@openvpn.net X-Received: by 2002:a4a:edcc:0:b0:6aa:ec6a:21a5 with SMTP id 006d021491bc7-6ac96c284b5mr3412561eaf.31.1785320545156; Wed, 29 Jul 2026 03:22:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785320545; cv=none; d=google.com; s=arc-20260327; b=jEkqe01yikBhJm8KExa8VSRh0UavOOb3zXas/7kzhGV1yB6HbFeWuC1zoCeOn3sGDg p+PlmRusOlM+WaqGZ4axr9rbECPHflbchtbQ6+QHu0dUYvDqKf7rwqtjTo6rp8IboRxV ANd0DoDOxX+GxzH3FSBhy1PoraurZZV6W7ixktgYXgFwdpx+qxglnbBtdN73CvORLFCy FIjpQNFperlLxt1CvReKxM5jiCMtgHsVu2cfCDqgNb7Z6LVLxsH4xYy04bqKyMJvSpQo 5siiaTtbUXBmXE89OjH4ngaS07qY8bspsVrfO8w7p/2HyBczaUj6/4silViSOfi/wjGx sx1Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=T5OtqUONyaKJsw/ZeyjIuO7djlmvLmzh4KZuWu2ilFY=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=PlSQW7UvPs0KW9cQoD9TOZBqXkvn8hTcnb7HL7oLT30mnVBAhiTQcRJ0wbuPcbQ7lr vAtkXtU0a5ezzscG46hZPMLKoWZxCY+Qtn9tmsKFS4Aev2s2O9vfIQ/qHvK29eSDRJFd gIQAJbpenhx10+PJSwIUoS4DZAmO+bJ/UWz3eZvd17ukCUQ++K+ppOfeDLI5cxKIUy4M aKQacTCB4xWDU/2eBjQDjIVc3bZDJJyFI/6/38mGJG9QQ9q5KHHaA51tF0vPJESJmvMs v90U7o30WKZq8N++ooPAI+NJKhcmUfPydStHUh7B2Cgou0jA4JSrubhmDlSuuen6MqVK 7sHw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=d5h2nelV; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=CGPG4LEM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CWa1+tua; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="DqN/JyP8"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886cbe650si2189881fac.368.2026.07.29.03.22.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 03:22:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=d5h2nelV; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=CGPG4LEM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CWa1+tua; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b="DqN/JyP8"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=T5OtqUONyaKJsw/ZeyjIuO7djlmvLmzh4KZuWu2ilFY=; b=d5h2nelVQoMag0wZy7qUIssk2k 0n8O0TN4ds2hnGpB7nSxQtIDVs7EBloLNRsZOLf9oAZCapV8j4B6D9qN8XDw9sQsKUSO2ApiP02AY jrOVALy0a5eTvRE533ybFPjZu6iKUXEUyAT5azLKhj4NKmLWSLzBXzOEVOBX82PubMxI=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp1QY-00083W-PV; Wed, 29 Jul 2026 10:22:19 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp1QO-00083C-EW for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=CGPG4LEM3nXFMtEAn641rYbnsP rjDL/F12OJ+Ada/0qx/jxwNrKj1MBHTajYabOPiK0BEdC0UQhDL4G1Q+RNfm2M4DQWTsnkHK57YLs yyLh7Gh+ZewwU9y8Rt6w6+nT1diKH1tnCk0h1LzLlkuVU5fGjaBvDWiQvf6/JPEK6NlY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=CWa1+tuaFYp9aqqr2HrVOdWzas lTTi1OTSELJXnuR3J/02DppQx+vR5n1R0MSW2+/tSf7hKjljSMLfAJ20u8gS3xOtJIu6jPOQPD3al 0FfoOyU1Kv9QYiSHbltdP/DcnmRljjcLcVNfi5M93nRpNU2N2ZwRpqTLmX2hYAHCY8GU=; Received: from mout-b-105.mailbox.org ([195.10.208.50]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp1QR-0002fE-6Z for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 10:22:09 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-105.mailbox.org (Postfix) with ESMTPS id 4h97fv5LXJz9tbx; Wed, 29 Jul 2026 12:21:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785320519; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=BSrmGFLfmj1vxpGXTQtMWYMXzpjTnVrd2FUwOb2GXB0=; b=DqN/JyP8NKGywg33IjW+6PciPl+I/nKNAoTDSrFR8tiVlr2vC6qHM/syZlSpf+x4BuFzD1 KORLcX96thnZirOro4CpgrYOxdjSs6Td02u1mmTkQmP3FyQ3sMdbcPze7fw/RoYefK1Ez+ KST8sz328wjG3vnE5pOb8SH9qIP1FzyD/dvCcbjjVua0IPleaMvv1yMKWyYTqi2ITJo8HE iVM+YomssC5VHWG01SslOWEoOWIcBYea9zaibB/n6MedA9lh2tKKT6TTgjHyWHymL9Pcb3 Ux642MK+pOFDAreiLnNfe+NXQ5gzqEO4l71zSTUjafUATWiFILvvluM3GIti5Q== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 12:21:46 +0200 Message-ID: <99bd088e56302f9bd7cd565eb4208912e6fd26e7.1785318038.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h97fv5LXJz9tbx X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Key slots are released through a kref and the existing release path frees the AEAD transforms from an RCU callback. That is not safe for all crypto implementations: crypto_free_aead can sleep, for exa [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.50 listed in wl.mailspike.net] 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wp1QR-0002fE-6Z Subject: [Openvpn-devel] [PATCH ovpn net v6 6/6] ovpn: defer key slot crypto freeing to workqueue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872044275624340208 X-GMAIL-MSGID: 1872044275624340208 Key slots are released through a kref and the existing release path frees the AEAD transforms from an RCU callback. That is not safe for all crypto implementations: crypto_free_aead can sleep, for example when an async or hardware implementation has teardown work to complete. Use queue_rcu_work for key-slot release. This keeps the RCU grace period needed by lockless key-slot readers, but runs the actual crypto teardown from workqueue context where sleeping is allowed. Once the rcu_work callback runs, pre-existing RCU readers are gone, and the final kref put already proves that no transform user remains, so the worker can release the AEAD transforms and free the slot directly. The previous patch drains ovpn_wq during module exit, so queued key-slot teardown work cannot outlive module text. Fixes: 8534731dbf2d ("ovpn: implement packet processing") Signed-off-by: Ralf Lici --- Changes since v5 https://lore.kernel.org/openvpn-devel/5e4de5963ea48d7e7431e55192f0d6a5784c2a47.1783336121.git.ralf@mandelbit.com/ - Use queue_rcu_work for key-slot release so RCU readers are preserved without adding a key-slot reference in ovpn_crypto_config_get (Sabrina). No changes since v4 https://lore.kernel.org/openvpn-devel/b53ae1a9714bae7081c71bdab7b30623ce3cb77b.1783099626.git.ralf@mandelbit.com/ Changes since v3 https://lore.kernel.org/openvpn-devel/ac2842c8e759849c51447126343376dcc793c7ae.1783080055.git.ralf@mandelbit.com/ - Reuse the module-owned ovpn workqueue instead of allocating a crypto-specific workqueue for key-slot teardown. Changes since v2 https://lore.kernel.org/openvpn-devel/b5dfebec718f230783ff47aa354c3b3fa1aa2ed7.1783068961.git.ralf@mandelbit.com/ - Reword the message to note the dependency on patch 1. Changes since v1 https://lore.kernel.org/openvpn-devel/350f6b48c363dde5a8d0bdf7a1b9fd2abb8b1034.1783057762.git.ralf@mandelbit.com/ - Fix a potential AEAD transform UAF in ovpn_crypto_config_get by holding a slot kref while reading the cipher algorithm. drivers/net/ovpn/crypto.c | 10 +--------- drivers/net/ovpn/crypto.h | 4 +++- drivers/net/ovpn/crypto_aead.c | 19 ++++++++++++++----- drivers/net/ovpn/crypto_aead.h | 1 - 4 files changed, 18 insertions(+), 16 deletions(-) diff --git a/drivers/net/ovpn/crypto.c b/drivers/net/ovpn/crypto.c index 2e95f29514fc..7e545428900a 100644 --- a/drivers/net/ovpn/crypto.c +++ b/drivers/net/ovpn/crypto.c @@ -18,20 +18,12 @@ #include "crypto_aead.h" #include "crypto.h" -static void ovpn_ks_destroy_rcu(struct rcu_head *head) -{ - struct ovpn_crypto_key_slot *ks; - - ks = container_of(head, struct ovpn_crypto_key_slot, rcu); - ovpn_aead_crypto_key_slot_destroy(ks); -} - void ovpn_crypto_key_slot_release(struct kref *kref) { struct ovpn_crypto_key_slot *ks; ks = container_of(kref, struct ovpn_crypto_key_slot, refcount); - call_rcu(&ks->rcu, ovpn_ks_destroy_rcu); + queue_rcu_work(ovpn_wq, &ks->free_work); } /* can only be invoked when all peer references have been dropped (i.e. RCU diff --git a/drivers/net/ovpn/crypto.h b/drivers/net/ovpn/crypto.h index 0e284fec3a75..e3feb16d5498 100644 --- a/drivers/net/ovpn/crypto.h +++ b/drivers/net/ovpn/crypto.h @@ -10,6 +10,8 @@ #ifndef _NET_OVPN_OVPNCRYPTO_H_ #define _NET_OVPN_OVPNCRYPTO_H_ +#include + #include "pktid.h" #include "proto.h" @@ -45,8 +47,8 @@ struct ovpn_crypto_key_slot { struct ovpn_pktid_recv pid_recv ____cacheline_aligned_in_smp; struct ovpn_pktid_xmit pid_xmit ____cacheline_aligned_in_smp; + struct rcu_work free_work; struct kref refcount; - struct rcu_head rcu; }; struct ovpn_crypto_state { diff --git a/drivers/net/ovpn/crypto_aead.c b/drivers/net/ovpn/crypto_aead.c index 8f07c418622b..74eaf6fac2f5 100644 --- a/drivers/net/ovpn/crypto_aead.c +++ b/drivers/net/ovpn/crypto_aead.c @@ -9,6 +9,7 @@ #include #include +#include #include #include #include @@ -380,13 +381,19 @@ static struct crypto_aead *ovpn_aead_init(const char *title, return ERR_PTR(ret); } -void ovpn_aead_crypto_key_slot_destroy(struct ovpn_crypto_key_slot *ks) +static void ovpn_aead_crypto_key_slot_free(struct ovpn_crypto_key_slot *ks) { - if (!ks) - return; - crypto_free_aead(ks->encrypt); crypto_free_aead(ks->decrypt); +} + +static void ovpn_aead_crypto_key_slot_free_work(struct work_struct *work) +{ + struct ovpn_crypto_key_slot *ks; + + ks = container_of(to_rcu_work(work), struct ovpn_crypto_key_slot, + free_work); + ovpn_aead_crypto_key_slot_free(ks); kfree(ks); } @@ -420,6 +427,7 @@ ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc) ks->encrypt = NULL; ks->decrypt = NULL; + INIT_RCU_WORK(&ks->free_work, ovpn_aead_crypto_key_slot_free_work); kref_init(&ks->refcount); ks->key_id = kc->key_id; @@ -453,7 +461,8 @@ ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc) return ks; destroy_ks: - ovpn_aead_crypto_key_slot_destroy(ks); + ovpn_aead_crypto_key_slot_free(ks); + kfree(ks); return ERR_PTR(ret); } diff --git a/drivers/net/ovpn/crypto_aead.h b/drivers/net/ovpn/crypto_aead.h index 65a2ff307898..fae3b585a43b 100644 --- a/drivers/net/ovpn/crypto_aead.h +++ b/drivers/net/ovpn/crypto_aead.h @@ -22,7 +22,6 @@ int ovpn_aead_decrypt(struct ovpn_peer *peer, struct ovpn_crypto_key_slot *ks, struct ovpn_crypto_key_slot * ovpn_aead_crypto_key_slot_new(const struct ovpn_key_config *kc); -void ovpn_aead_crypto_key_slot_destroy(struct ovpn_crypto_key_slot *ks); enum ovpn_cipher_alg ovpn_aead_crypto_alg(struct ovpn_crypto_key_slot *ks);