From patchwork Fri Jul 31 10:07:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5192 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp261271mau; Fri, 31 Jul 2026 03:08:11 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rosqo9ShmmjChKlga7QotyDjaxPvy8j1IL28Q5ix3Imb5pNQzZLoQ3TL9cbyuMY8wm3j1eZwcVVeGw=@openvpn.net X-Received: by 2002:a05:6870:80d2:b0:451:25f2:da63 with SMTP id 586e51a60fabf-458f2e49966mr1423604fac.6.1785492491555; Fri, 31 Jul 2026 03:08:11 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785492491; cv=none; d=google.com; s=arc-20260327; b=Ss7+uEmdzUNS5R3iveQGR60ZOsWrT1ir14GSKiQPebc16AxPYO2cDiwhOtuMdGkYeJ zrfSZZ+mkpw/EAM+n6jZ74jJtuac7Ye/BV/FLwsq307vDCnFR9TcvKm3y0LtfoOT0OL2 Fw7/+gSsTACMO3PNwwMQC1EiRu3E1JABZ7K8qLqqFnxobAcmvfXoUuQomcVaBHNRd9/k 6Z6y/wDYJo4UoC08eCp+aenqjyBlyp8QQ1VUnqJUCN+MsX03r+IFSTtJQGM3q7T6zAbe CPwe+kPuRKAV3Us1LvCCCHiIPpT5+oY5jMmI8W1EADS4pIqgf4dezqGQ66Bg5cxI6BbM N27g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=g2CA0CjLBWgb/Du9kL6ZWpn62LPMUhyi0bgIp/+SM0Y=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=CI6Dy3MfXuZCrKVu3GZ7QUHAhh9ZSsNRETjrZmmk90XROG6GAq2f0w70mDN1w9AmDu Iqp5x6SE5guk4eICZwiQWaomzr5NPCcNRzZp8fbXGk1WV8OQXDUEqG5CLvKu7Ivochqp Fpd/NJOv/dgZvgRZzRD9aah2VcfbLeHzSX88rUUjsT0CdmeRz5dFTaaBZ44ujUE7J6rJ kVp7C6z3K0cy4zyY7FJx8esmj18YbY76+EC9/ggOuzHHig9Mk1+rg1Tu3OQhcOgYiDvx 4wFCjrE1nYKK6O8hAVm6R0YFtQnzZagvMXvguU0oxf94xsysHa/TB7X3lbyM/0BP60Be dJfA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=XWrrE08A; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lHnnNqkt; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CO4tCjs2; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-458f664dcc6si617844fac.255.2026.07.31.03.08.11 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 31 Jul 2026 03:08:11 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=XWrrE08A; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lHnnNqkt; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CO4tCjs2; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=g2CA0CjLBWgb/Du9kL6ZWpn62LPMUhyi0bgIp/+SM0Y=; b=XWrrE08ABwp9A2wsYxhWNg81NE GLVWxNEsUpjvTp/1c6BomC9m5esTvLXi7GWwTdWG1diNUpKoWiZVcUERINtcqZkh06ZFtaSeiSSbR 316f4M/Rad0jSYJKrlliKgxKa4TTABqN5acVTxz19yCoMyrqFy/8b0xghMZnTVqHpS58=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wpk9y-0005Yy-FO; Fri, 31 Jul 2026 10:08:08 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wpk9x-0005Ys-Oh for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 10:08:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=lvpkmAqt8fO7VAZmNqPSEQqLqgYlvVb7ch56qFwBRoU=; b=lHnnNqkttAPSsX5Bs+J2+/nSS4 vMqfiKsR+/qaTtuByrx15kDFseObOi6CCETRMS3m6wUreEJgKUvAMo0xSBTFYzswm5dzlxB3p+nRJ 9BOwT3dqqOb9dhZECXSJ9XUqiz9+Dy5J3hK+QoouvguHVWOOTttlMBDbCAVNPobq3yBY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=lvpkmAqt8fO7VAZmNqPSEQqLqgYlvVb7ch56qFwBRoU=; b=CO4tCjs2arMvkcyTVTS0hg7sLK l9Uav2bMYFDoyiVOl87QOFpbhFprXC98mp8odW8Je08kQuF1HP0hWh+VI7tyYx5XlYyeGXeK8yOsI YeoKLGOwtMiavgSGyANjjr/Wi9oKcXtQgNcYw2rRx9F7WaHDXKWcRvBQWwaT29IT58v4=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wpk9x-0000pt-0H for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 10:08:07 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 66VA7wWn003381 for ; Fri, 31 Jul 2026 12:07:58 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 66VA7wxh003380 for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 12:07:58 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 31 Jul 2026 12:07:52 +0200 Message-ID: <20260731100758.3368-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe Change-Id: I3d52c6d008502293c3ec57ad22d1c613dcd1a94e Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wpk9x-0000pt-0H Subject: [Openvpn-devel] [PATCH v15] Extract multi_check_dest_addr_allowed from multi_process_float X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1870971756801370358 X-GMAIL-MSGID: 1872224574948109266 From: Arne Schwabe Change-Id: I3d52c6d008502293c3ec57ad22d1c613dcd1a94e Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1723 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1723 This mail reflects revision 15 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index 72b0b53..9b64598 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -3069,6 +3069,76 @@ } /** + * This methods checks if a client instance is allowed to use an address + * + * Reasons for disallowing a specific address are that a client might be + * already using that address. In that case the method needs to decide + * if this instance can kick out the other instance. + * + * The method will then terminate the other instance if that check was + * positive. + */ +static bool +multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi, struct mroute_addr *real) +{ + struct hash *hash = m->hash; + const uint64_t hv = hash_value(hash, real); + struct hash_bucket *bucket = hash_bucket(hash, hv); + + /* make sure that we don't assign the client to an address taken by + * another client */ + struct hash_element *he = hash_lookup_fast(hash, bucket, real, hv); + if (!he) + { + /* Address is not taken, everything is fine. */ + return true; + } + + struct multi_instance *ex_mi = he->value; + + struct tls_multi *m1 = mi->context.c2.tls_multi; + struct tls_multi *m2 = ex_mi->context.c2.tls_multi; + + struct gc_arena gc = gc_new(); + int ret = false; + + /* do not allow if target address is taken by client with another cert */ + if (!cert_hash_compare(m1->locked_cert_hash_set, m2->locked_cert_hash_set)) + { + msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s", + multi_instance_string(ex_mi, false, &gc)); + + mi->context.c2.buf.len = 0; + goto done; + } + + /* It doesn't make sense to let a peer float to the address it already + * has, so we disallow it. This can happen if a DCO netlink notification + * gets lost and we miss a floating step. + */ + if (m1->rx_peer_id == m2->rx_peer_id) + { + msg(M_WARN, + "disallowing peer %" PRIu32 " (%s) from floating to " + "its own address (%s)", + m1->rx_peer_id, tls_common_name(mi->context.c2.tls_multi, false), + mroute_addr_print(&mi->real, &gc)); + goto done; + } + + msg(D_MULTI_LOW, + "closing instance %s due to float collision with %s " + "using the same certificate", + multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc)); + multi_close_instance(m, ex_mi, false); + ret = true; + +done: + gc_free(&gc); + return ret; +} + +/** * Handles peer floating. * * If peer is floated to a taken address, either drops packet @@ -3080,8 +3150,6 @@ multi_process_float(struct multi_context *m, struct multi_instance *mi, struct link_socket *sock) { struct mroute_addr real = { 0 }; - struct hash *hash = m->hash; - struct gc_arena gc = gc_new(); if (mi->real.type & MR_WITH_PROTO) { @@ -3091,53 +3159,16 @@ if (!mroute_extract_openvpn_sockaddr(&real, &m->top.c2.from.dest, true)) { - goto done; + return; } - const uint64_t hv = hash_value(hash, &real); - struct hash_bucket *bucket = hash_bucket(hash, hv); - - /* make sure that we don't float to an address taken by another client */ - struct hash_element *he = hash_lookup_fast(hash, bucket, &real, hv); - if (he) + if (!multi_check_dest_addr_allowed(m, mi, &real)) { - struct multi_instance *ex_mi = (struct multi_instance *)he->value; - - struct tls_multi *m1 = mi->context.c2.tls_multi; - struct tls_multi *m2 = ex_mi->context.c2.tls_multi; - - /* do not float if target address is taken by client with another cert */ - if (!cert_hash_compare(m1->locked_cert_hash_set, m2->locked_cert_hash_set)) - { - msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s", - multi_instance_string(ex_mi, false, &gc)); - - mi->context.c2.buf.len = 0; - - goto done; - } - - /* It doesn't make sense to let a peer float to the address it already - * has, so we disallow it. This can happen if a DCO netlink notification - * gets lost and we miss a floating step. - */ - if (m1->rx_peer_id == m2->rx_peer_id) - { - msg(M_WARN, - "disallowing peer %" PRIu32 " (%s) from floating to " - "its own address (%s)", - m1->rx_peer_id, tls_common_name(mi->context.c2.tls_multi, false), - mroute_addr_print(&mi->real, &gc)); - goto done; - } - - msg(D_MULTI_LOW, - "closing instance %s due to float collision with %s " - "using the same certificate", - multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc)); - multi_close_instance(m, ex_mi, false); + return; } + struct gc_arena gc = gc_new(); + msg(D_MULTI_MEDIUM, "peer %" PRIu32 " (%s) floated from %s to %s", mi->context.c2.tls_multi->rx_peer_id, tls_common_name(mi->context.c2.tls_multi, false), @@ -3166,7 +3197,6 @@ ASSERT(hash_add(m->cid_hash, &mi->context.c2.mda_context.cid, mi, true)); #endif -done: gc_free(&gc); }