Netdev List
 help / color / mirror / Atom feed
From: Antonio Quartulli <antonio@openvpn.net>
To: netdev@vger.kernel.org
Cc: Antonio Quartulli <antonio@openvpn.net>,
	Sabrina Dubroca <sd@queasysnail.net>,
	Ralf Lici <ralf@mandelbit.com>, Jakub Kicinski <kuba@kernel.org>,
	Paolo Abeni <pabeni@redhat.com>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>
Subject: [PATCH net 00/11] pull request: fixes for ovpn 2026-09-21
Date: Mon, 21 Sep 2026 12:22:01 +0200	[thread overview]
Message-ID: <20260921102215.3599702-1-antonio@openvpn.net> (raw)

Hi all!

Here is a batch of eleven ovpn fixes for net, all from Ralf. They come
from two series that went through a few rounds of sashiko pre-review on
openvpn-devel....

There is also a patch for our selftest, which is just a companion change
for a fix introduced here, hence I attached it to this PR.

The first group hardens the UDP transmit path. struct ovpn_bind is
published with RCU and read locklessly on TX, but the local endpoint was
still being updated in place, which can result in torn IPv6 address
reads. The peer dst cache was also not invalidated when the socket mark
or UDP source port changed, and a route resolved from an already
replaced bind could end up being cached. On top of that,
netlink-configured IPv6 link-local remotes lost their scope id, which
breaks route lookup.

The second group tightens peer VPN address validation. In MP mode these
addresses are the lookup keys used to select the peer for an outgoing
tunnel packet, but duplicates, peers left with no usable address, and
addresses that can never identify a peer (multicast, broadcast,
loopback) were all accepted. Such configurations have never worked
reliably, so they are now rejected at configuration time rather than
misbehaving later.

NOTE: Sashiko points out that ovpn_route_key does not include sk_bound_dev_if:
that is a known gap, addressed by the bound-device work already in my
queue for net-next.

There are still larger fixes in our queue, so please ignore any
"previous issue" Sashiko may report on these (is it still reporting
pre-existing issues?).


Please pull or let me know of any issue!

Thanks a lot,
	Antonio

The following changes since commit 1e24c4f2ee44be0eee94092b5d13cbdb4bdf0d60:

  selftests: tc-testing: add a lateral-drift hfsc classify-walk test (2026-09-19 16:42:11 -0700)

are available in the Git repository at:

  https://github.com/OpenVPN/ovpn-net-next.git ovpn-net-20260921

for you to fetch changes up to 006208026819d5e9e5ec07b3e73d95960a059327:

  selftests: ovpn: validate peer VPN addresses (2026-09-21 11:39:13 +0200)

----------------------------------------------------------------
Included fixes:
* add selftest coverage for peer VPN address validation
* reject multicast, broadcast and loopback peer VPN addresses, which
  can never identify a peer
* reject MP peers left with no usable VPN address, as they can never
  be selected for TX
* reject duplicate peer VPN addresses, which made peer lookup return
  an arbitrary peer
* fix stale entry left in the VPN address hashtable when an address
  is cleared
* fix torn IPv6 address read on lockless TX when the unusable local
  source is cleared in place
* fix torn IPv6 address read on lockless TX when a new local endpoint
  is learned in place
* fix dst cache being populated with a route resolved from an already
  replaced bind
* fix stale route being reused after the socket mark or UDP source
  port changed
* fix bogus validation of an unspecified local source address, which
  must instead be left to route source autoselection
* fix IPv6 link-local peer endpoints losing their scope id when
  configured via netlink, breaking route lookup

----------------------------------------------------------------
Ralf Lici (11):
      ovpn: preserve IPv6 scope id for netlink peer endpoints
      ovpn: skip UDP source validation for unspecified addresses
      ovpn: track UDP socket route key for peer dst cache
      ovpn: validate peer state before caching UDP dst
      ovpn: replace bind when learning local endpoint
      ovpn: replace bind when clearing stale local source
      ovpn: always unhash old VPN addresses before rehashing
      ovpn: reject duplicate peer VPN addresses
      ovpn: reject multipeer peers without VPN addresses
      ovpn: reject invalid peer VPN addresses
      selftests: ovpn: validate peer VPN addresses

 drivers/net/ovpn/netlink.c                  | 108 ++++++++++++++--
 drivers/net/ovpn/peer.c                     | 121 +++++++++++++----
 drivers/net/ovpn/peer.h                     |  25 +++-
 drivers/net/ovpn/udp.c                      | 193 +++++++++++++++++++++++-----
 tools/testing/selftests/net/ovpn/common.sh  |  13 ++
 tools/testing/selftests/net/ovpn/ovpn-cli.c |  54 +++++---
 tools/testing/selftests/net/ovpn/test.sh    |  75 ++++++++++-
 7 files changed, 493 insertions(+), 96 deletions(-)

             reply	other threads:[~2026-09-21 10:22 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 10:22 Antonio Quartulli [this message]
2026-09-21 10:22 ` [PATCH net 01/11] ovpn: preserve IPv6 scope id for netlink peer endpoints Antonio Quartulli
2026-09-24 17:00   ` patchwork-bot+netdevbpf
2026-09-21 10:22 ` [PATCH net 02/11] ovpn: skip UDP source validation for unspecified addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 03/11] ovpn: track UDP socket route key for peer dst cache Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 04/11] ovpn: validate peer state before caching UDP dst Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 05/11] ovpn: replace bind when learning local endpoint Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 06/11] ovpn: replace bind when clearing stale local source Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 07/11] ovpn: always unhash old VPN addresses before rehashing Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 08/11] ovpn: reject duplicate peer VPN addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 09/11] ovpn: reject multipeer peers without " Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 10/11] ovpn: reject invalid peer " Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 11/11] selftests: ovpn: validate " Antonio Quartulli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921102215.3599702-1-antonio@openvpn.net \
    --to=antonio@openvpn.net \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=ralf@mandelbit.com \
    --cc=sd@queasysnail.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox