From patchwork Fri Aug 28 13:00:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5291 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2a5c:b0:87d:ab56:3700 with SMTP id l28csp1142125maz; Fri, 28 Aug 2026 06:01:17 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rrvt8to2nqTFHawLCnUteVkaTo/4pzcpzsbE4GU21MGFmI+1Kkp+FHZ/cyjh7pAipSfvA8A/VQnbkU=@openvpn.net X-Received: by 2002:a05:6870:8254:b0:455:c1d1:9cc0 with SMTP id 586e51a60fabf-46837f1f5a3mr7611615fac.19.1787922077254; Fri, 28 Aug 2026 06:01:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787922077; cv=none; d=google.com; s=arc-20260327; b=CnEXGl8g0FJxzbQ4tBfmfoKdAZ4vdTb61dkD8jD+5RKWltRf7kGwrZO1Bj+9a1xvpC ts8rax61l9lt0ddl8wWmfKJkBBOYtcRF/PvkzxMB7gLHl5RY4Vkrj5J8XNtv+yBA+5YR kqPvWl2smNVCOo1e4F735wQ02hRtjeHaDrQj7h69bo8DlIa5zBpbpC96YXlw1QsHUSuE 08uemjwo/Z7ikDkVb0BNIMQcCP8Hb2Xo9/PSOwB0jTQqPc2jcJdZD+EYnQeS64eguB2K 5xNaS9yq5SqJz9zs2RFlHzFJkC68Zv9EadAswhHJFujm0uCXq31iM7Ze51tBSgAjSroh QFyw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=mAAcVpxSwxMD+4/hmKw2PJp7VFrEyA/6Q54mH2jqwjw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=cZRmlvPcjsSQViJyKGe110naWSxnrg85mU8jF3z+v91QhOhV57iEIk2QR7sO3PCxvn B6PeKs9fwJhEkkTDlZTs3CilL74pSWAbGZchTZC1sHnWBsvn6kWaaXMbai6VSGzf/JjJ PxYwni30kWIWa+WXM8o+cmAW7Iayy8bichCu7NrY07tFBzNcEX4Ss3KZYs1p2aPzHmrW cgE5QPHifVt2vaBjOrfcqNIaIY4Y4CMG+34LcFU5NEGRbzteI8ZGMh12eo59s9yQ6RE3 2Ct8Xsww0GHzoHnq943KJGzYLxNCMhE0CwhGCuSF0qZw1HxzDv4Veso1HsiJ/yMNpZqT Kuxw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SZwKEbvA; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=PeNtzGIC; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Ryg92vpH; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=uJIDZg2H; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-468a61612a3si1728406fac.269.2026.08.28.06.01.16 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 06:01:16 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SZwKEbvA; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=PeNtzGIC; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Ryg92vpH; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=uJIDZg2H; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=mAAcVpxSwxMD+4/hmKw2PJp7VFrEyA/6Q54mH2jqwjw=; b=SZwKEbvAZJBmvyQojujbH4j4vb ljKWiXG5BPE1tZJyhY22eL1uvYVj2+c0/yVyjLHMKM9pE8LL0aK10QBh3AJY5w5Hz2zFksACaJAa0 aL2Y+EemYwkXnwGzCtjwcSdsTylgKTRUdxq/hlRJ0ZycKwdVk87tkjna5z3BTlt5dZxQ=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzwCm-00017a-9t; Fri, 28 Aug 2026 13:01:12 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzwCN-00016r-AU for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:48 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=PKHz1IxdpECY3W1lGOkcRp7xmXjrQnWLzGIFgQJBM5k=; b=PeNtzGIC5kHLSzhwkeqWzYiSdk bJ+eBC3J1En/thMamOS8Vn58RnMMpGgDhuMnA4Eoks7+oWjf3RbneJW0jz6Dogt9kOOVxjktF0H4n ZrVHU9713Vv1A4sHJcCTUg9eE0n4rOBbMjGuzLA+mlloQDWLg2vJQL+gyntkZucGJ5A8=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=PKHz1IxdpECY3W1lGOkcRp7xmXjrQnWLzGIFgQJBM5k=; b=Ryg92vpHsWN8fGhJZnx2sAIxvv bjdP6lmMCwn82R2rfmF/rXbrsJK5F2MbYkdQ941PP+iMgeVLBv2oNxJjjfG3TyUSGbWyEff/Vitc5 NnkdHhEABGne5NGM5yF7UzSdJrM/Xb7V4WKcVd4Ymd4xLL8PVrjFnjsmn3fjnCQvmBSM=; Received: from mout-b-203.mailbox.org ([195.10.208.52]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzwCA-0005bC-79 for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:38 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-203.mailbox.org (Postfix) with ESMTPS id 4hWdls3pwJzLlqM; Fri, 28 Aug 2026 15:00:25 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787922025; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=PKHz1IxdpECY3W1lGOkcRp7xmXjrQnWLzGIFgQJBM5k=; b=uJIDZg2HlM/YPVF3+cCDPiI0Ig5r5+0T0TNyIchkHNVH3MmqOTNeElTFZIjxx7PFuBYjQI +mbh81ajsLdBmIpobAog8D46/5wU1VOmTsGuxplP9Qy/o1micTCN4ogTmXNjeO1ZFNdNS7 AcZ2ulwq5YtKAw/zHpNLpdI372WW2573x/IBzsUV+vBsJqIvn8Rf1tb3vmw97x2Gy2zg/Q 2ooiMFYxw+HP24pVeWtPWMFG7QSmBtqXFXKVopW4WQh9lX5XpbxylI/Xmb5s/sHNVjx40R 7yxW8wIBCo0IqJXLpaJGa9d+r69p2SVb1dEJkk2QhFhdRaOflIG+bzHf8rCuUg== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 15:00:06 +0200 Message-ID: <8eca0229a26d5e6db8e095b2f1693b6fc03fcfb1.1787919082.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries after userspace changes a peer VPN address. The current code removes an old hash entry only when the new address for that family is [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzwCA-0005bC-79 Subject: [Openvpn-devel] [PATCH ovpn net v2 1/5] ovpn: always unhash old VPN addresses before rehashing X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874772179659412179 X-GMAIL-MSGID: 1874772179659412179 ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries after userspace changes a peer VPN address. The current code removes an old hash entry only when the new address for that family is not the unspecified address. When an address is cleared to 0.0.0.0 or ::, its hash node therefore remains linked in the bucket selected by the old address. The address comparison performed during lookup prevents the old address from matching, but the table retains a stale entry until the peer is removed or another address is configured for that family. Always remove both old VPN address hash entries before conditionally adding the currently configured addresses back. This ensures that a cleared address leaves its hash node unhashed. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- No changes since v1 https://lore.kernel.org/openvpn-devel/e15d597b1c6d0e98727f482113b51f86a8510c50.1785338921.git.ralf@mandelbit.com/ drivers/net/ovpn/peer.c | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index c95656ca7c35..68a2b05689ef 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -990,10 +990,11 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) if (hlist_unhashed(&peer->hash_entry_id)) return; - if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + /* remove potential old hashing */ + hlist_nulls_del_init_rcu(&peer->hash_entry_addr4); + hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); + if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) { nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr4, &peer->vpn_addrs.ipv4, sizeof(peer->vpn_addrs.ipv4)); @@ -1001,9 +1002,6 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer) } if (!ipv6_addr_any(&peer->vpn_addrs.ipv6)) { - /* remove potential old hashing */ - hlist_nulls_del_init_rcu(&peer->hash_entry_addr6); - nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr6, &peer->vpn_addrs.ipv6, sizeof(peer->vpn_addrs.ipv6)); From patchwork Fri Aug 28 13:00:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5290 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2a5c:b0:87d:ab56:3700 with SMTP id l28csp1142040maz; Fri, 28 Aug 2026 06:01:15 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RrbLK5lxwXd9pbe3uLYTdAMRdxAUuoCSechf0CkQ6IZVH0IfPeJOt9GEVZdHrSVtVj02qZjMxEoqQk=@openvpn.net X-Received: by 2002:a05:6870:c1d0:b0:455:9a0a:f40f with SMTP id 586e51a60fabf-46836af1e30mr7034365fac.12.1787922074791; Fri, 28 Aug 2026 06:01:14 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787922074; cv=none; d=google.com; s=arc-20260327; b=JGZu4tY1arP0kVCAJsKc1QwGvrsSaCRcuuprXgbGVM4xUfBwFy9cApKTiof/d+c78Z p5PMe/3lg0nAszj7wtHUbwwnKITqLASGIBgmwj+n5so4mX+4lP9tx1fqfOY7Vsstoj4m ZxgZSPavoZYOzXFLS6VPmmTECT35YoxzSW45g2l9gGs5p3HqFIHqDDLFm83hZICTp7KF kbB8Q6Uhhn5nzVVV2ro2mzwRDaAU2Tv+LFggodFawB4k+KIIQ8O9/lGFjKUf5OC/m0ff VR+QY2PHb2EUP3yndUgkd3G4aoKhuhpwuJwV+BkxAhfrjawm9+NmRUSHKqoY5QU94UDs a6Qw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=yvMTJ++0LDskAUkMKnffCKtqHDawJMKC1+FPfB30cUk=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=XMCZoDNDOFQguVVN1X5QYgksJTvAQgf7Uh/9nrEjq0GdEJVqjCcMM00mhA4mFC6l/y 1pGL/wu16p0CAd1tHcJB/RfKnFQDWu5g/816CRMSAdTIuIWyE7oKAbvWA38RgWP7Zeva Qs6R4vsXaPO5YB57uNqc3wx3ynbPDubK9Y+pdq77Nx4i2YejaMLtzf9yF8Mu96NZ6xfi JijYGvw7aI0zJZG1PZ/b/T4SRHKdAp2IFjLzASult+j6AjxOhTBtwwz64ItRfPzY+PVX pS/nMozw04KlFZnDNcHa3ri9OMeGcUmmNA4FxNZ931JieicTHHmD8XGmbU4PjL2zD80Y Pn7Q==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Vg0aEMed; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=HGYU3rs8; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mxjlTvj5; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=HSz0i8XL; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-468a69c78c4si1761037fac.361.2026.08.28.06.01.14 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 06:01:14 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=Vg0aEMed; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=HGYU3rs8; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mxjlTvj5; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=HSz0i8XL; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=yvMTJ++0LDskAUkMKnffCKtqHDawJMKC1+FPfB30cUk=; b=Vg0aEMednGFIUPhFaNOfiRVP97 mBF8bRjEQ5TfQI1mn/XGqsG27XgQhPNr5bGTAh9ixDPuUh+bW9XZTyqGz9R/7mZM7fn615mIJQ4Q4 qqhFv+3EzCe+qn6H43gio4jXMlQwFiSgG5rcLa99arnSq9SMyMFOfyafLl7jAiXDq9ro=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzwCj-0001bD-He; Fri, 28 Aug 2026 13:01:10 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzwCM-0001aG-JE for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:48 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=KtdulZmEFhCpglK28MwKNKSoL519haptelaHqlRGy7M=; b=HGYU3rs8OhusgMINLQ2uTkZuxF 3OPaICQ8Hz7sR2GOOKU8uPgkPCfXaYmu/gemRBCD80QRL6ACCXwyikwOglQ4HnUlU2YC9VYhrXaSD p5I1akLJg6Jgs5ulsJbVLAayXlZfRPBChvLYxPRV8yvRSzT1V+4NMPtuXzyguRhjF8F4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=KtdulZmEFhCpglK28MwKNKSoL519haptelaHqlRGy7M=; b=mxjlTvj5dYU92mxo8NXffo5+DY GQF/xej3zd9RFR50Ypl+SQc5MH2Cm2b0gSUDVQ5vd4EP5PEXTTvfWMV4G/ogps91WQj3cC2170ze2 SFdNzfiY+lE+RBSFjuxM4feXV97K/BJdvvfhycse+RKcjARuYjW5l1Xn+fAk3x4nQIGM=; Received: from mout-b-206.mailbox.org ([195.10.208.51]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzwCB-0005bL-Ge for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:37 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-206.mailbox.org (Postfix) with ESMTPS id 4hWdlv0YtyzHj; Fri, 28 Aug 2026 15:00:27 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787922027; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=KtdulZmEFhCpglK28MwKNKSoL519haptelaHqlRGy7M=; b=HSz0i8XLNuFCq+zt0BXSfyjLANxfcLsOZUmlco5F8EPUGx/cvXDNha+LNX3HalivW2mMym ec5JhDh45inv42rcd4WHPoFnq9YxUqJETq9cPoBFeI+gEm5ch4VF9+MdNeWmZhh8XJMvDE Na37oH9Oaydbpj+9idSjq0/+St/k6EkaybQVAuniM7Um/gf9rfPnzO/hlXkfW83DsG8+Jq fmXqDuUHft12i26Pc6mNK07yW619j3fatSUgG2/SeIqUNiGai8JNTcrhtsGLGir3soBM4X P1KeIqqOHNdklf5Hxa4KwojwYRUZZgB6llxjCgI3wiVmkE1zsrcKbMYw77W/PQ== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 15:00:07 +0200 Message-ID: <3da9a7b4d938b88f7c5cad9127bdffa5c79fcfbb.1787919082.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hWdlv0YtyzHj X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: In MP mode, ovpn uses the peer VPN addresses as lookup keys for selecting the peer that should receive an outgoing tunnel packet. However, the netlink peer configuration path does not currently reject [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.51 listed in wl.mailspike.net] -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzwCB-0005bL-Ge Subject: [Openvpn-devel] [PATCH ovpn net v2 2/5] ovpn: reject duplicate peer VPN addresses X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874772177512789791 X-GMAIL-MSGID: 1874772177512789791 In MP mode, ovpn uses the peer VPN addresses as lookup keys for selecting the peer that should receive an outgoing tunnel packet. However, the netlink peer configuration path does not currently reject duplicate VPN addresses. If two peers are configured with the same VPN address, both can be inserted in the VPN address hash table and lookups return whichever peer is found first. This makes peer selection ambiguous and dependent on hash insertion order. Reject peer creation or update when the resulting VPN address is already assigned to another peer. Ignore unspecified addresses because those are not inserted in the VPN address hash tables. This changes such configurations from being accepted to being rejected, but they have never worked reliably because peer selection is ambiguous. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- Changes since v1 https://lore.kernel.org/openvpn-devel/872f401e31dae10388fe65b45463c5c55b96ac86.1785338921.git.ralf@mandelbit.com/ - Explicitly stated that the policy introduced by this commit is not breaking userspace. (Sabrina) - Split ovpn_peer_vpn_addr_conflict into two helpers, one for v4 and one for v6. (Sabrina) drivers/net/ovpn/netlink.c | 37 ++++++++++++++++----- drivers/net/ovpn/peer.c | 67 +++++++++++++++++++++++++++++++++++++- drivers/net/ovpn/peer.h | 6 ++++ 3 files changed, 101 insertions(+), 9 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 4dad85294198..a444930234b6 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -474,8 +474,10 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) { - struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; struct ovpn_priv *ovpn = info->user_ptr[0]; + struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; + struct in6_addr vpn_addr6; + struct in_addr vpn_addr4; struct ovpn_socket *sock; struct ovpn_peer *peer; u32 peer_id; @@ -522,28 +524,47 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) rcu_read_unlock(); spin_lock_bh(&ovpn->lock); - ret = ovpn_nl_peer_modify(peer, info, attrs); - if (ret < 0) { - spin_unlock_bh(&ovpn->lock); - ovpn_peer_put(peer); - return ret; + + /* reject peer with conflicting VPN address */ + if (attrs[OVPN_A_PEER_VPN_IPV4]) { + vpn_addr4.s_addr = nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]); + if (ovpn_peer_vpn_addr_conflict4(ovpn, peer, &vpn_addr4)) + goto addr_conflict; } + if (attrs[OVPN_A_PEER_VPN_IPV6]) { + vpn_addr6 = nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]); + if (ovpn_peer_vpn_addr_conflict6(ovpn, peer, &vpn_addr6)) + goto addr_conflict; + } + + ret = ovpn_nl_peer_modify(peer, info, attrs); + if (ret < 0) + goto unlock; /* ret == 1 means that VPN IPv4/6 has been modified and rehashing * is required */ - if (ret > 0) + if (ret > 0) { ovpn_peer_hash_vpn_ip(peer); + ret = 0; + } /* if the remote endpoint was updated, the by_transp_addr hash bucket * also needs to be refreshed, otherwise incoming packets from the new * remote address would fail the lockless lookup */ if (attrs[OVPN_A_PEER_REMOTE_IPV4] || attrs[OVPN_A_PEER_REMOTE_IPV6]) ovpn_peer_hash_transp_addr(peer); + +unlock: spin_unlock_bh(&ovpn->lock); ovpn_peer_put(peer); - return 0; + return ret; +addr_conflict: + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "VPN IP is already assigned to another peer"); + ret = -EADDRINUSE; + goto unlock; } static int ovpn_nl_send_peer(struct sk_buff *skb, const struct genl_info *info, diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index 68a2b05689ef..da456981bc67 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -484,7 +484,7 @@ static struct ovpn_peer *ovpn_peer_get_by_vpn_addr4(struct ovpn_priv *ovpn, * Return: the peer if found or NULL otherwise */ static struct ovpn_peer *ovpn_peer_get_by_vpn_addr6(struct ovpn_priv *ovpn, - struct in6_addr *addr) + const struct in6_addr *addr) { struct hlist_nulls_head *nhead; struct hlist_nulls_node *ntmp; @@ -509,6 +509,64 @@ static struct ovpn_peer *ovpn_peer_get_by_vpn_addr6(struct ovpn_priv *ovpn, return NULL; } +/** + * ovpn_peer_vpn_addr_conflict4 - check if the VPN v4 address is already in use + * @ovpn: the openvpn instance to search + * @peer: peer being added or updated, or NULL + * @addr: VPN IPv4 address to check + * + * Check whether @addr is already assigned to another peer. @peer is ignored + * when found, allowing peer updates that keep an existing address. + * Unspecified addresses are ignored. + * + * Note: the caller must hold @ovpn->lock. + * + * Return: true on conflict, false otherwise. + */ +bool ovpn_peer_vpn_addr_conflict4(struct ovpn_priv *ovpn, + const struct ovpn_peer *peer, + const struct in_addr *addr) +{ + struct ovpn_peer *tmp = NULL; + + lockdep_assert_held(&ovpn->lock); + + /* we don't hash INADDR_ANY, no conflict in that case */ + if (addr->s_addr != htonl(INADDR_ANY)) + tmp = ovpn_peer_get_by_vpn_addr4(ovpn, addr->s_addr); + + return tmp && tmp != peer; +} + +/** + * ovpn_peer_vpn_addr_conflict6 - check if the VPN v6 address is already in use + * @ovpn: the openvpn instance to search + * @peer: peer being added or updated, or NULL + * @addr: VPN IPv6 address to check + * + * Check whether @addr is already assigned to another peer. @peer is ignored + * when found, allowing peer updates that keep an existing address. + * Unspecified addresses are ignored. + * + * Note: the caller must hold @ovpn->lock. + * + * Return: true on conflict, false otherwise. + */ +bool ovpn_peer_vpn_addr_conflict6(struct ovpn_priv *ovpn, + const struct ovpn_peer *peer, + const struct in6_addr *addr) +{ + struct ovpn_peer *tmp = NULL; + + lockdep_assert_held(&ovpn->lock); + + /* we don't hash ::, no conflict in that case */ + if (!ipv6_addr_any(addr)) + tmp = ovpn_peer_get_by_vpn_addr6(ovpn, addr); + + return tmp && tmp != peer; +} + /** * ovpn_peer_transp_match - check if sockaddr and peer binding match * @peer: the peer to get the binding from @@ -1036,6 +1094,13 @@ static int ovpn_peer_add_mp(struct ovpn_priv *ovpn, struct ovpn_peer *peer) goto out; } + /* reject peer with conflicting VPN address */ + if (ovpn_peer_vpn_addr_conflict4(ovpn, NULL, &peer->vpn_addrs.ipv4) || + ovpn_peer_vpn_addr_conflict6(ovpn, NULL, &peer->vpn_addrs.ipv6)) { + ret = -EADDRINUSE; + goto out; + } + bind = rcu_dereference_protected(peer->bind, true); /* peers connected via TCP have bind == NULL */ if (bind) { diff --git a/drivers/net/ovpn/peer.h b/drivers/net/ovpn/peer.h index dfa5c0037e02..a1cbd4013349 100644 --- a/drivers/net/ovpn/peer.h +++ b/drivers/net/ovpn/peer.h @@ -149,6 +149,12 @@ struct ovpn_peer *ovpn_peer_get_by_transp_addr(struct ovpn_priv *ovpn, struct ovpn_peer *ovpn_peer_get_by_id(struct ovpn_priv *ovpn, u32 peer_id); struct ovpn_peer *ovpn_peer_get_by_dst(struct ovpn_priv *ovpn, struct sk_buff *skb); +bool ovpn_peer_vpn_addr_conflict4(struct ovpn_priv *ovpn, + const struct ovpn_peer *peer, + const struct in_addr *addr); +bool ovpn_peer_vpn_addr_conflict6(struct ovpn_priv *ovpn, + const struct ovpn_peer *peer, + const struct in6_addr *addr); void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer); void ovpn_peer_hash_transp_addr(struct ovpn_peer *peer); bool ovpn_peer_check_by_src(struct ovpn_priv *ovpn, struct sk_buff *skb, From patchwork Fri Aug 28 13:00:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5288 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2a5c:b0:87d:ab56:3700 with SMTP id l28csp1141939maz; Fri, 28 Aug 2026 06:01:12 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RrKqXMtdfsrdEJ6hPN9hAlMlJwEu/XpScfatFDjoDa+5uO0x/ZswDtc7cwF9t7rX3wI2J+n1Y1xcVw=@openvpn.net X-Received: by 2002:a05:6870:b0f3:b0:456:4c3f:7e03 with SMTP id 586e51a60fabf-4683789c517mr7535322fac.18.1787922072506; Fri, 28 Aug 2026 06:01:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787922072; cv=none; d=google.com; s=arc-20260327; b=q7bMbQate//Wx7e1plqBO6xUEEyACmiwZFSMRwwracg7He1PA5oZWUoA/dBCp2r/Ai lLaazYuNLlBGkSZC602jGRbDI7wualiClCTeUapFTXRWByknchmVrmd6wJ1DZPTJCpV+ 1zqzvkeKdZtkEKmIKBanJo6OZhmFLkbxHaS8+YNgmibsQwCetvHVbCm+7oSz9gASQkO/ 6ANk49uJleSy15/xWJy7N3PU4PkxtllP6VUd/jyUKpf8s3nNnNWBe3hCl8zCr8ySQXGZ K/jKMuy0fHdwxiMX7f17SAvCVa4Dlddh2lyqM/+OZv/zEMnEH51VPi3eueXouCpZObtt QHTQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=lWPkrGgvVjN58GRu/eOguuiC+yrB49p3loCJxkTKbOk=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=TiU/oc/+K9ToCyV1U+zg8o+jkH/nos5EElqQ1V5n+HkR/jEhf2HvPjerX1ypW7Zh6W lgTkpy1yQ6GElEazptujUXdJAU5XJ2Nx21ocUhktY6o2UBvuE+hObabQpqiEzFkVyrsl 2PbG/5+3p/QhQg6IIuEH0RaQdhEqqj0KbK4fxSbv7qd+fDliJ3gBI7+dTWwZx0fV8fkU RRIZqyZG6HgRvDwtlj5pt//6LbfUdogps2FdzA8iEVJpk/PGxFTk7lkTFMZsvRTG+rjZ 0GQrjaEfBZSmjN7e0DK6nKvJCdcjFn/Mr25ef/mbRkfN4GRnwuebCEcb8B2er3YEMvN8 L6vQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=cH9vmQ6B; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=HQIZWT1F; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=fPjTW4Gp; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=PTfvCBDB; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-468a341ad49si1801175fac.104.2026.08.28.06.01.12 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 06:01:12 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=cH9vmQ6B; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=HQIZWT1F; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=fPjTW4Gp; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=PTfvCBDB; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=lWPkrGgvVjN58GRu/eOguuiC+yrB49p3loCJxkTKbOk=; b=cH9vmQ6Boof3BamFWt12R820qJ n5p6NiRLSvlakAf1ayPJE3hSKXj0sDt2pfQ1mLh0x5Nl1xsoac+g6O3NK9XsghC5NTbcR8zBBeOpm srnF0xmNzWz44PJGI/RZoDIe6SqekZOk9MhHpv5g/soO2xIjq28Jsx5nDMcmrxjGYIk4=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzwCl-0003Hr-22; Fri, 28 Aug 2026 13:01:08 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzwCP-0003H4-UN for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:48 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=eA/0FjXZziVVh1UlSjwtBwDjZ/Se2eCwuRS93nmojG0=; b=HQIZWT1FGabrgmYMbzSdq8r4s0 p5SGp9iFVROoQCB8P4Sp2FYZw7uKGJSLOdBK6tTzlfWo8EaoBuy+OWt/QRW/UvzVPXpPFJ/QkxRB2 cChHKXI7P3G3Uq3LdgNO7Rp/sN+6nDE8eMI43xrcseQM+mtFqGae2SMABEP2ug5V1pj0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=eA/0FjXZziVVh1UlSjwtBwDjZ/Se2eCwuRS93nmojG0=; b=fPjTW4Gpn6N4XxHIAGmAcrsLZ2 Qgj0EvIJbs6C/QA8RywJQCHmQD3hm/J5bxq08ZUOD18/7LTY4jPZy15jXuOyXLePiwN/AIGo1Hzs+ /EunsKNH7qjZLuKiLXfHLaNDSRffbiuTcPgiPhqaIPu5HuzpYa7KxjGZgnXXx8S6CMIQ=; Received: from mout-b-112.mailbox.org ([195.10.208.42]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzwCC-0005bO-KM for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:38 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-112.mailbox.org (Postfix) with ESMTPS id 4hWdlw25pwz5wlm; Fri, 28 Aug 2026 15:00:28 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787922028; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=eA/0FjXZziVVh1UlSjwtBwDjZ/Se2eCwuRS93nmojG0=; b=PTfvCBDBqf+Pt0dA7AiFyP4GhQnrdKdDKejlsMrgZELzsfC0hNim95V5oFEDAF5itJQSc4 nM0GmfoEuqPgEYWP3EA5MSBff1/Az7tihQThtde4flQyK9BhKS0F33FoRp+gfVymI97EYv Xob41TsD/gf+ws2MPb93+AGbrxDHa8aldviNekoirPCMJKhO4PK8iyrh5ri9wS1hjy/IQO y78fZYctBMQYSbbCjTSjQIdLpVhkyONkZjoSsLMqa/+a6yCsixt35Pg0Uue+4Pypo5hcpK cmco4LDnhkORlKmDqIKFSS5fvPpIxLQWuYtx97EHa7ULhJoYfvVpkZr69ldfsQ== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 15:00:08 +0200 Message-ID: <21af0a98270dc43e5720734834bdd836b8384b52.1787919082.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: In MP mode, ovpn uses the peer VPN addresses to select the peer for outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or IPv6 attribute, but it only checks for the presence of the a [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzwCC-0005bO-KM Subject: [Openvpn-devel] [PATCH ovpn net v2 3/5] ovpn: reject multipeer peers without VPN addresses X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874772174739951855 X-GMAIL-MSGID: 1874772174739951855 In MP mode, ovpn uses the peer VPN addresses to select the peer for outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or IPv6 attribute, but it only checks for the presence of the attribute and not for a usable address value. This allows userspace to create an MP peer with only unspecified VPN addresses, or to update an existing peer so that both VPN address families become unspecified. Such a peer cannot be selected through the VPN address hash tables. Reject MP peer creation or update when the resulting peer would not have at least one VPN address configured. This changes such configurations from being accepted to being rejected, but they have never been usable because the peer cannot be selected through the VPN address hash tables. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- Changes since v1 https://lore.kernel.org/openvpn-devel/17ced9a7caee691e602e3c02f5e399aa9a35067c.1785338921.git.ralf@mandelbit.com/ - Explicitly stated that the policy introduced by this commit is not breaking userspace. (Sabrina) - Used htonl(INADDR_ANY) instead of directly comparing s_addr. (Sabrina) drivers/net/ovpn/netlink.c | 36 ++++++++++++++++++++++++++++++------ 1 file changed, 30 insertions(+), 6 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index a444930234b6..a0ed09278a6b 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -346,8 +346,10 @@ static int ovpn_nl_peer_modify(struct ovpn_peer *peer, struct genl_info *info, int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) { - struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; + struct in_addr vpn_addr4 = { .s_addr = htonl(INADDR_ANY) }; + struct in6_addr vpn_addr6 = IN6ADDR_ANY_INIT; struct ovpn_priv *ovpn = info->user_ptr[0]; + struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; struct ovpn_socket *ovpn_sock; struct socket *sock = NULL; struct ovpn_peer *peer; @@ -371,11 +373,20 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) return -EINVAL; /* in MP mode VPN IPs are required for selecting the right peer */ - if (ovpn->mode == OVPN_MODE_MP && !attrs[OVPN_A_PEER_VPN_IPV4] && - !attrs[OVPN_A_PEER_VPN_IPV6]) { - NL_SET_ERR_MSG_FMT_MOD(info->extack, - "VPN IP must be provided in MP mode"); - return -EINVAL; + if (ovpn->mode == OVPN_MODE_MP) { + if (attrs[OVPN_A_PEER_VPN_IPV4]) + vpn_addr4.s_addr = + nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]); + if (attrs[OVPN_A_PEER_VPN_IPV6]) + vpn_addr6 = + nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]); + + if (vpn_addr4.s_addr == htonl(INADDR_ANY) && + ipv6_addr_any(&vpn_addr6)) { + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "at least one VPN IP must be configured in MP mode"); + return -EINVAL; + } } peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]); @@ -525,6 +536,9 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) spin_lock_bh(&ovpn->lock); + vpn_addr4 = peer->vpn_addrs.ipv4; + vpn_addr6 = peer->vpn_addrs.ipv6; + /* reject peer with conflicting VPN address */ if (attrs[OVPN_A_PEER_VPN_IPV4]) { vpn_addr4.s_addr = nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]); @@ -537,6 +551,16 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) goto addr_conflict; } + /* in MP mode VPN IPs are required for selecting the right peer */ + if (ovpn->mode == OVPN_MODE_MP && + vpn_addr4.s_addr == htonl(INADDR_ANY) && + ipv6_addr_any(&vpn_addr6)) { + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "at least one VPN IP must be configured in MP mode"); + ret = -EINVAL; + goto unlock; + } + ret = ovpn_nl_peer_modify(peer, info, attrs); if (ret < 0) goto unlock; From patchwork Fri Aug 28 13:00:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5289 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2a5c:b0:87d:ab56:3700 with SMTP id l28csp1142028maz; Fri, 28 Aug 2026 06:01:15 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpjjjXJSJozu23J6+/Q4J/1Z+AuiR7nONTUY1JANvblM6CBkKt+5pnZGjQeiS/pUNgAkkrfX87jmLk=@openvpn.net X-Received: by 2002:a05:6808:c173:b0:492:c9a4:2104 with SMTP id 5614622812f47-4b37c999474mr11817180b6e.10.1787922074713; Fri, 28 Aug 2026 06:01:14 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787922074; cv=none; d=google.com; s=arc-20260327; b=jG9USipZQjQvMnoW5pX/iq2tZiutbYkEidpx5+cuu8eXCBq6kqklKmoJUVL8gzjHVE bkP3rUxpJdm3hbY8T2gKJ87HeO4p9s2GUl+el4KEEkS5qUMEekyc/H9OXuEZVDAOd01W feTtYRhrad4wyC4/4cuSk/MNHyx6J47TQ8ZglhZA3BqSNFJJURNviVVcs6jD8Q0lDXjC NxceA8jnNXE4/V0WR15aHsJbMoh0pmy0NL8scgnCAGBxGJnueRl9NoS0bhUImupQ/6Rp Dw2nbxdT4pEb1uW3zJZ5VH3L9Hd9+oExmpIg7nUAqwWPVlCLx9Uyvk/F3bfi5Ov2i5Ha +ZKA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=1l+znuyS9Iq2X8+ZUk55dxxrAhapFh0acSpaa5HkgLw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=l9FDPy5YNZyoup2SBbW7iofm4mo70GwTWi87Z6qj0a//SqvJSeRWf60K3LOl1C2+0k WCpNB3w3ZNXF4c9gSopSRue3DrlgrectqghO7n4UBAFxX9f+kXSZI9zfELgpBaV4cA2Y KGHTRNQURSSJsSP3eqyNHso/xCCaQW2hKRGzvJvBk5HTeuKiauRRRPiojhn7bTzaWTn0 VBO+S/BHrXglzR+AssoDrrZ8Clw2AoNDqww1fmzLOLK+3nSgNdMQeDOfK1BVs1Byqj3a d3tv3mmkvBcheIfO7mIp4iysoCgfQbOw8f67gsndegRyW0+W5OzWbjsjBKmfriUJBzv6 ZGKg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=A8ZERpLe; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Zwb1iDyM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=WQtq3vEi; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=Swe3vX+2; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4b3a1bc832asi2029383b6e.130.2026.08.28.06.01.14 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 06:01:14 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=A8ZERpLe; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Zwb1iDyM; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=WQtq3vEi; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=Swe3vX+2; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=1l+znuyS9Iq2X8+ZUk55dxxrAhapFh0acSpaa5HkgLw=; b=A8ZERpLeuxx4j3jXSCnUHzQbVj CFyCVj6UjVLSc2s7vVvnXmqI/83WwtLMUL9dfNRWeDujEaRB892dcYdnbkB5vS84LjKk5DX6m2Tsx vq6H7hA1W6PbSLpE+grwuOUs+8PwOrI/TR8ghTpljzz3/AjpMfsnFAdpa8giFUSAAnkU=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzwCj-0001b4-7H; Fri, 28 Aug 2026 13:01:09 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzwCM-0001aM-JL for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:48 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=l3kKVzpsCJJNFGYtCfLWekadyfB69gwfvzgBALJzdSw=; b=Zwb1iDyMXgw6n0g4VcrPDEGztn lM3WSjscl/9bpEPq6zhtPTdSdJ0NxtYU9Uo8JioVN+LTC39SsCRX8/eHzBohHZHpwI6NpcnOLHZ9a aJwfQgrIkfEp+Rpoe/AniJwcs8MxrsQqn5kdp5dj6TBmk8szxmC8OsnhYepMNyUt9sDA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=l3kKVzpsCJJNFGYtCfLWekadyfB69gwfvzgBALJzdSw=; b=WQtq3vEiUUYP0HunglGQBnnYBD 42gmcMnMoSrcYvt3wpkzcJ3JxTcVLKj42EF6wW2tlZExIC5ivB0876chvTLTVGpNdaYsW3tEcP7cD 9rUxTjsI1vVuy+twFz3e1+eTJ/FgHaJ3bS4hy1FfK2Fcf3nrNMBL8MoMjB/OUa3DIRPM=; Received: from mout-b-112.mailbox.org ([195.10.208.42]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzwCH-0003Ww-7C for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:45 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-112.mailbox.org (Postfix) with ESMTPS id 4hWdlx2S8Pz5wPq; Fri, 28 Aug 2026 15:00:29 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787922029; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l3kKVzpsCJJNFGYtCfLWekadyfB69gwfvzgBALJzdSw=; b=Swe3vX+2qqRES9i5QHz1w9BqUrRwOXIYf9fhPByes6If/YazAoUf3wyVpdCsE+aH5GNyGP skjx6x3lXo3KxoCFfL75aNovUEcS0FgkhgLtqxOnekxDTe806um638UrS4XzYvWRyXrwaB t+O599tP9nsCQsfLJ25hPZG1ZwNuZnf14pPn7dHHdnHcEK5gdbKPNNIJ/v60mfR0nO8tFy 19/OH3DNFSDpEw9abLKnubM4JyTPUA+lQCAMqiIKrKqUzTQaa+XKSn40aVXmh8CSX7TvzT s7XEUnCWeKpXqzyZLknpkcP0ekrJFZN/oZ23fvO1LSYg1+M+No7jdVoRoatvbA== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 15:00:09 +0200 Message-ID: <1bddf9d3f19e8d74d831526e9ce80182bcfcab73.1787919082.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: In MP mode, ovpn uses peer VPN addresses as lookup keys for selecting the peer that should receive outgoing tunnel packets. The netlink configuration path currently accepts address values that cannot [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzwCH-0003Ww-7C Subject: [Openvpn-devel] [PATCH ovpn net v2 4/5] ovpn: reject invalid peer VPN addresses X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874772177544476880 X-GMAIL-MSGID: 1874772177544476880 In MP mode, ovpn uses peer VPN addresses as lookup keys for selecting the peer that should receive outgoing tunnel packets. The netlink configuration path currently accepts address values that cannot sensibly identify a VPN peer, such as multicast, broadcast or loopback addresses. Reject invalid peer VPN addresses when creating or updating an MP peer. Keep accepting the unspecified address as the internal unset value, provided that at least one VPN address family remains configured. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- Changes since v1 https://lore.kernel.org/openvpn-devel/934f840c132e350415369712806b3d9d77957ca5.1785338921.git.ralf@mandelbit.com/ - Adapted to changes in 2/5 and 3/5; no behavioral changes. drivers/net/ovpn/netlink.c | 55 +++++++++++++++++++++++++++++--------- 1 file changed, 42 insertions(+), 13 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index a0ed09278a6b..e9fef784dfc1 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -179,6 +179,39 @@ static sa_family_t ovpn_nl_family_get(struct nlattr *addr4, return AF_UNSPEC; } +static int ovpn_nl_peer_check_vpn_addrs(const struct in_addr *addr4, + const struct in6_addr *addr6, + struct genl_info *info) +{ + int addr6_type; + + if (addr4->s_addr == htonl(INADDR_ANY) && ipv6_addr_any(addr6)) { + NL_SET_ERR_MSG_MOD(info->extack, + "at least one VPN IP must be configured in MP mode"); + return -EINVAL; + } + + if (ipv4_is_multicast(addr4->s_addr) || ipv4_is_lbcast(addr4->s_addr) || + ipv4_is_loopback(addr4->s_addr)) { + NL_SET_ERR_MSG_MOD(info->extack, + "VPN IPv4 address must be valid unicast or any"); + return -EADDRNOTAVAIL; + } + + if (!ipv6_addr_any(addr6)) { + addr6_type = ipv6_addr_type(addr6); + + if (!(addr6_type & IPV6_ADDR_UNICAST) || + (addr6_type & (IPV6_ADDR_LOOPBACK | IPV6_ADDR_COMPATv4))) { + NL_SET_ERR_MSG_MOD(info->extack, + "VPN IPv6 address must be valid unicast or any"); + return -EADDRNOTAVAIL; + } + } + + return 0; +} + static int ovpn_nl_peer_precheck(struct ovpn_priv *ovpn, struct genl_info *info, struct nlattr **attrs) @@ -381,12 +414,10 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) vpn_addr6 = nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]); - if (vpn_addr4.s_addr == htonl(INADDR_ANY) && - ipv6_addr_any(&vpn_addr6)) { - NL_SET_ERR_MSG_FMT_MOD(info->extack, - "at least one VPN IP must be configured in MP mode"); - return -EINVAL; - } + ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6, + info); + if (ret < 0) + return ret; } peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]); @@ -552,13 +583,11 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) } /* in MP mode VPN IPs are required for selecting the right peer */ - if (ovpn->mode == OVPN_MODE_MP && - vpn_addr4.s_addr == htonl(INADDR_ANY) && - ipv6_addr_any(&vpn_addr6)) { - NL_SET_ERR_MSG_FMT_MOD(info->extack, - "at least one VPN IP must be configured in MP mode"); - ret = -EINVAL; - goto unlock; + if (ovpn->mode == OVPN_MODE_MP) { + ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6, + info); + if (ret < 0) + goto unlock; } ret = ovpn_nl_peer_modify(peer, info, attrs); From patchwork Fri Aug 28 13:00:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5292 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2a5c:b0:87d:ab56:3700 with SMTP id l28csp1143293maz; Fri, 28 Aug 2026 06:01:50 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rp4OSBm18/Azw9r9KzMOv5PAsCV1Ay7SeduGcnSxb+CQqVBtl8JZTvhc/jH+LPUOkdlUfQdMSs9r70=@openvpn.net X-Received: by 2002:a05:6830:6f48:b0:7eb:3af8:8c09 with SMTP id 46e09a7af769-7f4f223b98bmr8669506a34.3.1787922073476; Fri, 28 Aug 2026 06:01:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787922073; cv=none; d=google.com; s=arc-20260327; b=gwCU0GvQTB7rVrODNSVrbAz7Xqq4E2Vs3XBg8UOzegr8SJIK4Iu/HpsG5NPtjqPBW/ whemA9j2tDboTtttFqz4PmP+28cqbSVaMnRICqddl2ISI1sRyq2vBlB6lULCKJP2Wl3s qnUqXoAb5LI4CMHpUB1eAVP549BYS40QrbpsZ648uDrFG6109RqJSaadpsxjyt8vaKlh /126/sbWgd67pAY1xSqSJYZJNMKP0KR3DBwGm7IKvNf5o83YfYYJDad0YkghK7pzJGhi vVb+7fWZKwHu972aXTxrDFoLdzCIiXPJ0DHXMK6JZzReEobinAmHSnAzOCe51uSedTdI a9Tw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=EPG89q/UKjh6SOVGDivsC2Sy2ANHEvKeWmt7plWEFGA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=H8yAHGk0ViISUSCdgbmdexyyFOBHE3+FUBh4fA2qCqeK45UuDE1Pfo13W0Y2omTlmC rU1dpH2hjRqZanH6lhIirv5HGZ93UwXUMXgBErg2L9rBFY4g/cDaAQYVLMOylZ5kig16 Tm90vlwEFsPMTolfh9C40F9l1ciAHVcQnC0KR0c2Yr1VhBUHy0dfTO4vz5jMOpF/gILG vFZJdHqKI869dsfx2jnFW9VhLG2ou9iSL5zsCkoWMQXmsV4uEoHu+nYRmB+J1251fT2s elWk/q0yMPnOz8AC4yk2zVZaRS5gyR3umCrSq2lyHuwsX6fV6xkpYwpxowZZgF5r8Wvk Wxfg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e69BfvM9; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=G+p1ootX; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=M+o4e9MU; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=TvKUXUVY; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f4fa7c44b7si2285236a34.24.2026.08.28.06.01.11 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 06:01:12 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e69BfvM9; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=G+p1ootX; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=M+o4e9MU; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=TvKUXUVY; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=EPG89q/UKjh6SOVGDivsC2Sy2ANHEvKeWmt7plWEFGA=; b=e69BfvM99xSAkhrfZ75FQhGDzm VeyNeNy3Fkiw1BJi/PEEmBi+AdXUaCE4EP5VgK87YpCGk2G8tGRWDl4DmgYlb6AzuJswtGuDEZLip 1YFapxG64m+yC+RqUnianoWjIZ4rN+kCRtJicvbGvrXsACnt+Qb6qJeUFoXHOrI02nAM=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wzwCg-0002kL-S6; Fri, 28 Aug 2026 13:01:07 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wzwCM-0002jg-H9 for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:48 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=64FT6M4h95fUIBYhCf5pIcrEkfMFR0b/9CKVXRTYQuc=; b=G+p1ootX8t/JWQ2mt/ShWNSZkE f8sC1cmLV3SnYjStAPR1y+qyRQGeqXc5hD5aeMe921zp+p4QZgQMsssvkPIKF49o98XO6E9ON72ME 8OI59wxhQ01VE9z0ruQJxtoWnlFcPCU6TUpK2/Ex5xZgM1fmnC0XEVrCq71TOl7uucG0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=64FT6M4h95fUIBYhCf5pIcrEkfMFR0b/9CKVXRTYQuc=; b=M+o4e9MUUbxZSnISUosDDefiqk vNm/Wb1wEekXB+fm/CJx2EKi4KV5el69y/XJwpCY0VZQWvt6BpXVWRsdnhpRFsW7i6HnbSx9LAfP3 T1U2w+MQMrpqretDWt4Rj6hyi7hSAp7naRgNzXFG5ShvXJK2XjIhXxgSfZSZrlcKXpGQ=; Received: from mout-b-106.mailbox.org ([195.10.208.46]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wzwCG-0003Wv-1R for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 13:00:43 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-106.mailbox.org (Postfix) with ESMTPS id 4hWdlz38nbzNlZq; Fri, 28 Aug 2026 15:00:31 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1787922031; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=64FT6M4h95fUIBYhCf5pIcrEkfMFR0b/9CKVXRTYQuc=; b=TvKUXUVYkQKyOcWx1k+SANJOPTJAPr/ZOxfwBGx1EIKi9IqbHHt9zSt/8ppSI4hrE+9qqZ 59gjcKagedyvbu7+QUoyTfjyTgfYsl4CvL5aVOxnuci1Emv8ucoMFzLx/29PElbTpcbLCU naITfM6/RrYVJFQmuMydMninuyVEWoZ3tT3+9ya6+73Na0gYRzjXxM3wZTa2DxPiVDictV WYjPs/HYHVM6cXMpGu+rC6Ihx+rtdXBWUdT1Yi94lkL59KdxP3KtgPwSA6n6y4CC4IJF2K AuVtkk3CWPmTZkxXqOCZ1Ndb+jFm+fKavkLqDIVRgivid/AxcSXzv77JVk2G7w== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 15:00:10 +0200 Message-ID: <035e544caefc976ba9649eda9ca541a6fe4c56b2.1787919082.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Exercise peer VPN address validation through both peer creation and update. Check missing, unspecified, duplicate, multicast, broadcast, loopback, IPv4-compatible and IPv4-mapped addresses. Temporarily configure a peer with both address families to verify that either family can be cleared while the other remains configured, then restore the original addresses before running the existing [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wzwCG-0003Wv-1R Subject: [Openvpn-devel] [PATCH ovpn net v2 5/5] selftests: ovpn: validate peer VPN addresses X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874772174955874780 X-GMAIL-MSGID: 1874772174955874780 Exercise peer VPN address validation through both peer creation and update. Check missing, unspecified, duplicate, multicast, broadcast, loopback, IPv4-compatible and IPv4-mapped addresses. Temporarily configure a peer with both address families to verify that either family can be cleared while the other remains configured, then restore the original addresses before running the existing traffic tests. Extend ovpn-cli peer updates with an optional VPN address and preserve peer creation errors so the negative tests can observe rejected netlink requests. Signed-off-by: Ralf Lici --- No changes since v1 https://lore.kernel.org/openvpn-devel/7b19fd9eb8d2c2a4afc4a8d102bdfeeeec8024bf.1785338921.git.ralf@mandelbit.com/ tools/testing/selftests/net/ovpn/common.sh | 13 ++++ tools/testing/selftests/net/ovpn/ovpn-cli.c | 54 ++++++++++----- tools/testing/selftests/net/ovpn/test.sh | 75 ++++++++++++++++++++- 3 files changed, 123 insertions(+), 19 deletions(-) diff --git a/tools/testing/selftests/net/ovpn/common.sh b/tools/testing/selftests/net/ovpn/common.sh index 2d844eb3aa6e..5e9c81e885e6 100644 --- a/tools/testing/selftests/net/ovpn/common.sh +++ b/tools/testing/selftests/net/ovpn/common.sh @@ -136,6 +136,19 @@ ovpn_create_ns() { ip netns add "ovpn_peer${1}" } +ovpn_peer_vpn_addr() { + local peer="$1" + local file + + if [ "${OVPN_PROTO}" == "UDP" ]; then + file="${OVPN_UDP_PEERS_FILE}" + else + file="${OVPN_TCP_PEERS_FILE}" + fi + + awk -v peer="${peer}" '$1 == peer {print $NF; exit}' "${file}" +} + ovpn_setup_ns() { local peer="ovpn_peer${1}" local server_ns="ovpn_peer0" diff --git a/tools/testing/selftests/net/ovpn/ovpn-cli.c b/tools/testing/selftests/net/ovpn/ovpn-cli.c index f4effa7580c0..3b612a8a18fe 100644 --- a/tools/testing/selftests/net/ovpn/ovpn-cli.c +++ b/tools/testing/selftests/net/ovpn/ovpn-cli.c @@ -650,6 +650,26 @@ static int ovpn_connect(struct ovpn_ctx *ovpn) return ret; } +static int ovpn_nl_put_vpn_addr(struct nl_msg *msg, + const struct ovpn_ctx *ovpn) +{ + if (!ovpn->peer_ip_set) + return 0; + + switch (ovpn->peer_ip.in4.sin_family) { + case AF_INET: + return nla_put_u32(msg, OVPN_A_PEER_VPN_IPV4, + ovpn->peer_ip.in4.sin_addr.s_addr); + case AF_INET6: + return nla_put(msg, OVPN_A_PEER_VPN_IPV6, + sizeof(struct in6_addr), + &ovpn->peer_ip.in6.sin6_addr); + default: + fprintf(stderr, "Invalid family for peer address\n"); + return -EAFNOSUPPORT; + } +} + static int ovpn_new_peer(struct ovpn_ctx *ovpn, bool is_tcp) { struct nlattr *attr; @@ -691,22 +711,9 @@ static int ovpn_new_peer(struct ovpn_ctx *ovpn, bool is_tcp) } } - if (ovpn->peer_ip_set) { - switch (ovpn->peer_ip.in4.sin_family) { - case AF_INET: - NLA_PUT_U32(ctx->nl_msg, OVPN_A_PEER_VPN_IPV4, - ovpn->peer_ip.in4.sin_addr.s_addr); - break; - case AF_INET6: - NLA_PUT(ctx->nl_msg, OVPN_A_PEER_VPN_IPV6, - sizeof(struct in6_addr), - &ovpn->peer_ip.in6.sin6_addr); - break; - default: - fprintf(stderr, "Invalid family for peer address\n"); - goto nla_put_failure; - } - } + ret = ovpn_nl_put_vpn_addr(ctx->nl_msg, ovpn); + if (ret) + goto nla_put_failure; nla_nest_end(ctx->nl_msg, attr); @@ -732,6 +739,10 @@ static int ovpn_set_peer(struct ovpn_ctx *ovpn) ovpn->keepalive_interval); NLA_PUT_U32(ctx->nl_msg, OVPN_A_PEER_KEEPALIVE_TIMEOUT, ovpn->keepalive_timeout); + + ret = ovpn_nl_put_vpn_addr(ctx->nl_msg, ovpn); + if (ret) + goto nla_put_failure; nla_nest_end(ctx->nl_msg, attr); ret = ovpn_nl_msg_send(ctx, NULL); @@ -1730,13 +1741,14 @@ static void usage(const char *cmd) fprintf(stderr, "\tmark: socket FW mark value\n"); fprintf(stderr, - "* set_peer : set peer attributes\n"); + "* set_peer [vpnaddr]: set peer attributes\n"); fprintf(stderr, "\tiface: ovpn interface name\n"); fprintf(stderr, "\tpeer_id: peer ID of the peer to modify\n"); fprintf(stderr, "\tkeepalive_interval: interval for sending ping messages\n"); fprintf(stderr, "\tkeepalive_timeout: time after which a peer is timed out\n"); + fprintf(stderr, "\tvpnaddr: peer VPN IP\n"); fprintf(stderr, "* del_peer : delete peer\n"); fprintf(stderr, "\tiface: ovpn interface name\n"); @@ -2090,6 +2102,8 @@ static int ovpn_run_cmd(struct ovpn_ctx *ovpn) return ret; ret = ovpn_new_peer(ovpn, false); + if (ret < 0) + return ret; ovpn_waitbg(); break; case CMD_NEW_MULTI_PEER: @@ -2331,6 +2345,12 @@ static int ovpn_parse_cmd_args(struct ovpn_ctx *ovpn, int argc, char *argv[]) "keepalive interval value out of range\n"); return -1; } + + if (argc > 6) { + ret = ovpn_parse_remote(ovpn, NULL, NULL, argv[6]); + if (ret < 0) + return -1; + } break; case CMD_DEL_PEER: if (argc < 4) diff --git a/tools/testing/selftests/net/ovpn/test.sh b/tools/testing/selftests/net/ovpn/test.sh index 9b5610837032..392109d5e14e 100755 --- a/tools/testing/selftests/net/ovpn/test.sh +++ b/tools/testing/selftests/net/ovpn/test.sh @@ -56,6 +56,76 @@ ovpn_prepare_network() { done } +ovpn_new_test_peer() { + local peer_id="$1" + + shift + ip netns exec ovpn_peer0 "${OVPN_CLI}" new_peer tun0 \ + "${peer_id}" none 65000 10.10.1.2 1 "$@" +} + +ovpn_set_peer_vpn_addr() { + ip netns exec ovpn_peer0 "${OVPN_CLI}" set_peer tun0 \ + "$1" 60 120 "$2" +} + +ovpn_run_vpn_addr_validation() { + local addr + local peer1_addr4 + local test_peer_id=$((OVPN_NUM_PEERS + 1)) + local test_peer_addr6="2001:db8::2" + # Do not include 0.0.0.0 or :: here. They are invalid on creation, but + # clear one address family on update and are valid if the other remains. + local -a invalid_addrs=( + "127.0.0.1" + "224.0.0.1" + "255.255.255.255" + "::1" + "::192.0.2.1" + "::ffff:192.0.2.1" + "ff02::1" + ) + + peer1_addr4=$(ovpn_peer_vpn_addr 1) + + ovpn_cmd_fail "reject peer without VPN address" \ + ovpn_new_test_peer "${test_peer_id}" + + for addr in "0.0.0.0" "::" "${invalid_addrs[@]}"; do + ovpn_cmd_fail "reject new peer VPN address ${addr}" \ + ovpn_new_test_peer "${test_peer_id}" "${addr}" + done + + ovpn_cmd_fail "reject duplicate IPv4 address on peer creation" \ + ovpn_new_test_peer "${test_peer_id}" "${peer1_addr4}" + ovpn_cmd_fail "reject clearing the last peer VPN address" \ + ovpn_set_peer_vpn_addr 1 0.0.0.0 + + for addr in "${invalid_addrs[@]}"; do + ovpn_cmd_fail "reject updated peer VPN address ${addr}" \ + ovpn_set_peer_vpn_addr 1 "${addr}" + done + + ovpn_cmd_fail "reject duplicate IPv4 address on peer update" \ + ovpn_set_peer_vpn_addr 2 "${peer1_addr4}" + + ovpn_cmd_ok "add peer IPv6 address" \ + ovpn_set_peer_vpn_addr 1 "${test_peer_addr6}" + ovpn_cmd_fail "reject duplicate IPv6 address on peer creation" \ + ovpn_new_test_peer "${test_peer_id}" "${test_peer_addr6}" + ovpn_cmd_fail "reject duplicate IPv6 address on peer update" \ + ovpn_set_peer_vpn_addr 2 "${test_peer_addr6}" + + ovpn_cmd_ok "clear peer IPv4 address" \ + ovpn_set_peer_vpn_addr 1 0.0.0.0 + ovpn_cmd_fail "reject clearing the remaining peer IPv6 address" \ + ovpn_set_peer_vpn_addr 1 :: + ovpn_cmd_ok "restore peer IPv4 address" \ + ovpn_set_peer_vpn_addr 1 "${peer1_addr4}" + ovpn_cmd_ok "clear peer IPv6 address" \ + ovpn_set_peer_vpn_addr 1 :: +} + ovpn_run_basic_traffic() { local p local header1 @@ -293,15 +363,16 @@ trap ovpn_stage_err ERR ktap_print_header if [ "${OVPN_FLOAT}" == "1" ]; then - ktap_set_plan 13 + ktap_set_plan 14 else - ktap_set_plan 12 + ktap_set_plan 13 fi ovpn_cleanup modprobe -q ovpn || true ovpn_run_stage "setup network topology" ovpn_prepare_network +ovpn_run_stage "validate peer VPN addresses" ovpn_run_vpn_addr_validation ovpn_run_stage "run baseline data traffic" ovpn_run_basic_traffic ovpn_run_stage "run LAN traffic behind peer1" ovpn_run_lan_traffic [ "${OVPN_FLOAT}" == "1" ] && ovpn_run_stage "run floating peer checks" \