From patchwork Fri Sep 18 18:05:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5389 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp9110302mag; Fri, 18 Sep 2026 11:05:31 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBzlYAYEiMWfjTt5aHHvjFt7LWhEZCKWtfU6aNqa4d1HAyxXVX0pNypNpDk3uay40x4FPq6LN0f56cI=@openvpn.net X-Received: by 2002:a05:6808:c175:b0:49b:33c8:4b75 with SMTP id 5614622812f47-4ccf6a67699mr3586340b6e.5.1789754729287; Fri, 18 Sep 2026 11:05:29 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789754729; cv=none; d=google.com; s=arc-20260327; b=YWLQBMRvKpf6R80316pMZ7gYpWu2WK+/uOnygJLUrRab1228B5QNQv4X3zwCHYraiO xQKtJp1si1+82KrzZKty5/h6MCPqFArbunhvSfdmkbi0Rzb/dO+qoZpHmohec6cO/MwU 9itQCTEHDV4g0AB69hWYoMfYIFHpoa4T+ljzznnAtEUbYjfoHvtKzguQz7+rTDMFBvhm CKtdwhZFzWXlrErtKb6QsrGCagwuJ1wd6vj950gKn6EhEoct+WmJD7aAsIweTGTwCWu3 htk6Xu1WDlOhCkVt8Wwpbg0Fw9vmS7bG3ZQx04B2Cxzfyj9T9BG3MP2aE0vwR/INNtI8 z4KA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=Co9b1XE9tozpLRslQ+HyZHY1f+1IASrXZJLvwzr6GgA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=Vfuu3rCllU3EgRQf96DfApCljs04UTw6NsGh9j1l+E0NXFw1WYQLg98I1DKc1/a4e0 znO7eujqRYwNjcmkBbEwfRiQlFzCloVX+VJdXCDq+Kc1sGAfEARaEMYGeDFwrohtCEM2 53tXseCZg4ORikQMt/yDPbgn3NA6lASHmShVQL+YrBkdztN92cynJy16vXu91HzDhZ8b 4eEh0sOkLijCgog5MItMehfMu1Myj0nblQhv/yLmkSewG6yHNgJ1/93FIV29zrpq3TFD 7z9SDXQoZtRLzhcY0txxuc95jmlkTXHYhrWkktVcH717yyZKdA+Z074PlndqCmPNyes7 hD9A==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NosrvLEQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=frLeHCmg; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=a5au7a4m; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4cd6a870eebsi3712691b6e.97.2026.09.18.11.05.29 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 18 Sep 2026 11:05:29 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NosrvLEQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=frLeHCmg; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=a5au7a4m; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Co9b1XE9tozpLRslQ+HyZHY1f+1IASrXZJLvwzr6GgA=; b=NosrvLEQf3NFT3SNAFHlhigIEb LR5AF5tDfzkbuHGafphPnVAMx43E/wwaDQdXMIxrDtf3xuh20LyvJQlua+fGxsjNR546endWcTbgE wlZq7clpMuJ3cjVFjAH9VJd9Zb8Bq4UkhrAYsahkOJKutR9ZiRzF04kCjsQ+fWn2YVXk=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x7cxh-0002Wm-5x; Fri, 18 Sep 2026 18:05:25 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x7cxe-0002WV-OH for openvpn-devel@lists.sourceforge.net; Fri, 18 Sep 2026 18:05:23 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=rxTviZ8klLzRoeDwsZdSOz3qx7zUymfHZvjvcerhuig=; b=frLeHCmgELRQa+QJ5QKSN/GPs9 K8kztGJ8EEYU5QD82ika0VIkz1GxA679PHJ6ewmSHPzq0al/9tuQ6ETTrbLJ+NBIqzaM+osWOqX5Q O7DYBql5bn+k8JFfRrfLmzM51ldGHckcUR2we2SEyWHGl4nXiUsvTre3AVFN6oEDowwM=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=rxTviZ8klLzRoeDwsZdSOz3qx7zUymfHZvjvcerhuig=; b=a5au7a4myd/qUFzWG0r/Nt5ES5 CXK/a4yDSzt2mruVPLNiu46JPZUPljejCF3pXF2VrYRf4+REermpRRkAIdZwn92tAoZo+3N9fZBGS iJbeQzjmPyARFJBmj4MeZwWZHZt0eUrx00gmwJbcQZkeSS8/tNpCjpyaLeNaej5jzptk=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x7cxX-0000kG-4j for openvpn-devel@lists.sourceforge.net; Fri, 18 Sep 2026 18:05:16 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68II57id026467 for ; Fri, 18 Sep 2026 20:05:07 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68II57WZ026452 for openvpn-devel@lists.sourceforge.net; Fri, 18 Sep 2026 20:05:07 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 18 Sep 2026 20:05:01 +0200 Message-ID: <20260918180507.26425-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Lev Stipakov Three per-peer operations end the process when their ioctl fails: MP_NEW_PEER, NEW_KEY and SWAP_KEYS all report with M_ERR, which is M_FATAL. On a server that means one client's failure disconnects ev [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x7cxX-0000kG-4j Subject: [Openvpn-devel] [PATCH v1] dco_win: report per-peer ioctl failures instead of exiting X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876693854775330895 X-GMAIL-MSGID: 1876693854775330895 From: Lev Stipakov Three per-peer operations end the process when their ioctl fails: MP_NEW_PEER, NEW_KEY and SWAP_KEYS all report with M_ERR, which is M_FATAL. On a server that means one client's failure disconnects every other client. The shared code above them already recovers per instance: a failed MP_NEW_PEER drops that client in multi.c, a failed SWAP_KEYS raises SIGUSR1 for that instance in forward.c, and change 1835 restarts the instance on a failed NEW_KEY. None of it runs on Windows, because the process is gone before the error can be returned. Report and return, which is what DEL_PEER, MP_SET_PEER and the iroute calls in this same file already do. The remaining M_ERR uses here are interface-wide setup, where failing hard is still right. NEW_KEY failing is not hypothetical: the driver owns the keepalive timer and expires peers itself, so a key install can arrive for a peer it has just removed. Measured on a Windows DCO server under peer churn: 15 refused installs across four runs, no process exit. Signed-off-by: Lev Stipakov Acked-by: Gert Doering Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1920 Change-Id: Ie46934c0a8f04908cc277114ae491c100d368cb2 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1920 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Gert Doering diff --git a/src/openvpn/dco_win.c b/src/openvpn/dco_win.c index b3268bc..90cff8c 100644 --- a/src/openvpn/dco_win.c +++ b/src/openvpn/dco_win.c @@ -460,7 +460,8 @@ if (!DeviceIoControl(dco->tt->hand, OVPN_IOCTL_MP_NEW_PEER, &newPeer, sizeof(newPeer), NULL, 0, &bytesReturned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_MP_NEW_PEER) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_MP_NEW_PEER) failed"); + return -1; } return 0; @@ -575,7 +576,7 @@ if (!DeviceIoControl(dco->tt->hand, ioctl, buf, bufSize, NULL, 0, &bytes_returned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_NEW_KEY) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_NEW_KEY) failed"); return -1; } return 0; @@ -609,7 +610,7 @@ DWORD bytes_returned = 0; if (!DeviceIoControl(dco->tt->hand, ioctl, buf, len, NULL, 0, &bytes_returned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_SWAP_KEYS) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_SWAP_KEYS) failed"); return -1; } return 0;