From patchwork Fri Sep 25 13:18:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5409 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2145:b0:8b5:356c:6cee with SMTP id g5csp161458mac; Fri, 25 Sep 2026 06:18:44 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBxNUUHlAlkekAM9bGNz+hoVWcp5/YboAX75dkrcBnastZMfTuQmFQcV6kt7xVvA8k8Ts/Bxwzx0KDw=@openvpn.net X-Received: by 2002:a05:6808:c0cf:10b0:4c2:c0c0:5056 with SMTP id 5614622812f47-4d72e465425mr4320775b6e.32.1790342323791; Fri, 25 Sep 2026 06:18:43 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790342323; cv=none; d=google.com; s=arc-20260327; b=sO3IZIvTMnCP4xINioBywjkMquTDTZRsRqB510vDnyi5PjCIZSveJ//ELbk6Q5sdCv TASsLNuxnatgdlDETl3/YaIc/2L8zaBWRNJUfgqkZRQpmRvMmSeGOwQ1b7drtBL08Yb6 KEakNAoNWflSoYGQXITwd9XVr/cDoYyMSTrvrVHj/gVnFSBmS9Z3r7bZSsSXuSx/9X+G SaRBvHqfGL6IKaRFc+FmvaXhoIZeWYel7sULVdGeZkye//MNTi10BFtpXFgNCwW02dB4 k210U08DtHGD1UlAg7wFx9BdP8uVp9LLKSdGtShqKfGNBqQc7vBK4FIirsJA4qOX3ckw +uVg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=qhVbFjwc9kV4TCK/1l2Faxk5ywtSBqe7zppA6pqYnlg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=W9h+JN4dJi8Sk3QoEr94MIJTJRUo9KTqGmUvQK9h+BWFSUpXM7evVNlkT26n7TMGol CBfD58WIBJQ3cE6ElHRuRLoefF02U2GaW2BF38mYUfLdXahORNpCzAQU3yeh4YSQZnc8 xXrHzqXo9QdMQZS5CHUlxV2fnW681lN9G/g90tpKSMkVjJdPtD07HwEdVMnGaB8qI7/H oMd4YN9JyjldhZihYRX3eZ4ZSp+jMrfB809GIjluRzHkrtInPOFBD6bBVe230KRFXj7U SEuN3sU6s0hKZWBO0TCCEdIi+tzOQWUlTu6aUV0CKtCSohI7/fyZbZ9N/vIK+dBLnI6b ZvCA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=CVnS4y2F; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=NUKQ9uxu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=KFoPdktB; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4dcd5bf292dsi2947405b6e.87.2026.09.25.06.18.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 25 Sep 2026 06:18:43 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=CVnS4y2F; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=NUKQ9uxu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=KFoPdktB; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=qhVbFjwc9kV4TCK/1l2Faxk5ywtSBqe7zppA6pqYnlg=; b=CVnS4y2FXCoyXVtu16UbMX8knJ tO+IiXIQ0f3bZXrUmZwpamoc1Zb6OumpBbVoOY/KM73d5OsFuFWV8IScJBGCTp7eANZEf5TFAkZfo mFe6kus5HdltA0ZcLQZNGW6IsAVZs0bMfuuF0jH9ov7MH+/MeY7MYxZnuj5OnSFnHChQ=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xA5p1-0007bv-97; Fri, 25 Sep 2026 13:18:40 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xA5p0-0007bo-1d for openvpn-devel@lists.sourceforge.net; Fri, 25 Sep 2026 13:18:38 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=HrVRkpzfUqlROVmBwQk6rqfQ3h+yLnc9kI3NZg3U4Dk=; b=NUKQ9uxuVrteXmx4Jw1xBehlZH vv1EceT16jqv2Ja3CB3wdhl/NmGSZOYmjdHuSjIF0YaV8B+Br50X0n8Rt5wsALnyURW5UHii8Y3bR jaRHRhaWMAi6S9Lme/40cjrjq880lnWSGVwla4YWfRrbY5ZDxROrHoBb/A3QOhjoKY8Y=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=HrVRkpzfUqlROVmBwQk6rqfQ3h+yLnc9kI3NZg3U4Dk=; b=KFoPdktBVkRbP90brfH+wTF2p2 zT3bwlWbStTsu98NA3Esa+B/P22UT1sicvkAOrE9y4itGD+uNzt5nLshJYpu+rHmmZVnqeCIsJkNd GmD7jmqX05SGW4MEp3mf2JsP/Xx5DAeXy0CrCfIM5K6NcV0Dwy1m+9oL+bMainD+NFD4=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1xA5oz-00064h-3P for openvpn-devel@lists.sourceforge.net; Fri, 25 Sep 2026 13:18:38 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68PDIUOn010914 for ; Fri, 25 Sep 2026 15:18:30 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68PDIUQZ010913 for openvpn-devel@lists.sourceforge.net; Fri, 25 Sep 2026 15:18:30 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 25 Sep 2026 15:18:24 +0200 Message-ID: <20260925131830.10902-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli __is_locked existed only to stop setenv_stats() from issuing a GET_PEER request/reply while the shared socket was still being drained for a batch of notifications, which could fail with NLE_BUSY/NLE_N [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1xA5oz-00064h-3P Subject: [Openvpn-devel] [PATCH v3] dco_linux: drop the now-redundant __is_locked re-entrancy guard X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877309992790404129 X-GMAIL-MSGID: 1877309992790404129 From: Antonio Quartulli __is_locked existed only to stop setenv_stats() from issuing a GET_PEER request/reply while the shared socket was still being drained for a batch of notifications, which could fail with NLE_BUSY/NLE_NOMEM or re-enter nl_recvmsgs() on the busy socket. Now that notifications are read on a dedicated socket and GET_PEER goes to the request/reply socket, the two never share an nl_recvmsgs() call: the request/reply socket no longer dispatches notifications, so multi_process_incoming_dco() (the only path that reaches dco_get_peer() during message parsing) never runs while that socket is in flight, and the flag is always false at its check. Remove the flag, its set/clear and the early return. Change-Id: I46a9ef71359f42395d69cf899c948014fb72f65a Signed-off-by: Antonio Quartulli Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1738 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1738 This mail reflects revision 3 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/dco_linux.c b/src/openvpn/dco_linux.c index 27f4f99..e583696 100644 --- a/src/openvpn/dco_linux.c +++ b/src/openvpn/dco_linux.c @@ -49,16 +49,6 @@ #include #include -/* When parsing multiple DEL_PEER notifications, openvpn tries to request stats - * for each DEL_PEER message (see setenv_stats). This triggers a GET_PEER - * request-reply while we are still parsing the rest of the initial - * notifications, which can lead to NLE_BUSY or even NLE_NOMEM. - * - * This basic lock ensures we don't bite our own tail by issuing a dco_get_peer - * while still busy receiving and parsing other messages. - */ -static bool __is_locked = false; - /* libnl < 3.5.0 does not set the NLA_F_NESTED on its own, therefore we * have to explicitly do it to prevent the kernel from failing upon * parsing of the message @@ -170,12 +160,16 @@ return ret; } +/** + * Drain the request/reply socket. Used to read command/stats replies. This + * socket is never subscribed to the multicast group, so it cannot deliver an + * asynchronous notification: a reply being parsed here can therefore never + * trigger an instance close or a re-entrant request on the same socket. + */ static int ovpn_nl_recvmsgs(dco_context_t *dco, const char *prefix) { - __is_locked = true; int ret = nl_recvmsgs(dco->nl_sock, dco->nl_cb); - __is_locked = false; return ovpn_nl_recvmsgs_report(ret, prefix); } @@ -1223,12 +1217,6 @@ { ASSERT(dco); - if (__is_locked) - { - msg(D_DCO_DEBUG, "%s: cannot request peer stats while parsing other messages", __func__); - return 0; - } - /* peer_id == -1 means "dump all peers", but this is allowed in MP mode only. * If it happens in P2P mode it means that the DCO peer was deleted and we * can simply bail out