From: Antonio Quartulli <antonio@openvpn.net>
To: netdev@vger.kernel.org
Cc: Ralf Lici <ralf@mandelbit.com>,
Sabrina Dubroca <sd@queasysnail.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Antonio Quartulli <antonio@openvpn.net>
Subject: [PATCH net 10/11] ovpn: reject invalid peer VPN addresses
Date: Mon, 21 Sep 2026 12:22:11 +0200 [thread overview]
Message-ID: <20260921102215.3599702-11-antonio@openvpn.net> (raw)
In-Reply-To: <20260921102215.3599702-1-antonio@openvpn.net>
From: Ralf Lici <ralf@mandelbit.com>
In MP mode, ovpn uses peer VPN addresses as lookup keys for selecting
the peer that should receive outgoing tunnel packets. The netlink
configuration path currently accepts address values that cannot sensibly
identify a VPN peer, such as multicast, broadcast or loopback addresses.
Reject invalid peer VPN addresses when creating or updating an MP peer.
Keep accepting the unspecified address as the internal unset value,
provided that at least one VPN address family remains configured.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
---
drivers/net/ovpn/netlink.c | 55 +++++++++++++++++++++++++++++---------
1 file changed, 42 insertions(+), 13 deletions(-)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index e9e0f75e0443..5432bc2eb8e8 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -185,6 +185,39 @@ static sa_family_t ovpn_nl_family_get(struct nlattr *addr4,
return AF_UNSPEC;
}
+static int ovpn_nl_peer_check_vpn_addrs(const struct in_addr *addr4,
+ const struct in6_addr *addr6,
+ struct genl_info *info)
+{
+ int addr6_type;
+
+ if (addr4->s_addr == htonl(INADDR_ANY) && ipv6_addr_any(addr6)) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "at least one VPN IP must be configured in MP mode");
+ return -EINVAL;
+ }
+
+ if (ipv4_is_multicast(addr4->s_addr) || ipv4_is_lbcast(addr4->s_addr) ||
+ ipv4_is_loopback(addr4->s_addr)) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "VPN IPv4 address must be valid unicast or any");
+ return -EADDRNOTAVAIL;
+ }
+
+ if (!ipv6_addr_any(addr6)) {
+ addr6_type = ipv6_addr_type(addr6);
+
+ if (!(addr6_type & IPV6_ADDR_UNICAST) ||
+ (addr6_type & (IPV6_ADDR_LOOPBACK | IPV6_ADDR_COMPATv4))) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "VPN IPv6 address must be valid unicast or any");
+ return -EADDRNOTAVAIL;
+ }
+ }
+
+ return 0;
+}
+
static int ovpn_nl_peer_precheck(struct ovpn_priv *ovpn,
struct genl_info *info,
struct nlattr **attrs)
@@ -387,12 +420,10 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info)
vpn_addr6 =
nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]);
- if (vpn_addr4.s_addr == htonl(INADDR_ANY) &&
- ipv6_addr_any(&vpn_addr6)) {
- NL_SET_ERR_MSG_FMT_MOD(info->extack,
- "at least one VPN IP must be configured in MP mode");
- return -EINVAL;
- }
+ ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6,
+ info);
+ if (ret < 0)
+ return ret;
}
peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]);
@@ -558,13 +589,11 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
}
/* in MP mode VPN IPs are required for selecting the right peer */
- if (ovpn->mode == OVPN_MODE_MP &&
- vpn_addr4.s_addr == htonl(INADDR_ANY) &&
- ipv6_addr_any(&vpn_addr6)) {
- NL_SET_ERR_MSG_FMT_MOD(info->extack,
- "at least one VPN IP must be configured in MP mode");
- ret = -EINVAL;
- goto unlock;
+ if (ovpn->mode == OVPN_MODE_MP) {
+ ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6,
+ info);
+ if (ret < 0)
+ goto unlock;
}
ret = ovpn_nl_peer_modify(peer, info, attrs);
--
2.55.0
next prev parent reply other threads:[~2026-09-21 10:22 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 10:22 [PATCH net 00/11] pull request: fixes for ovpn 2026-09-21 Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 01/11] ovpn: preserve IPv6 scope id for netlink peer endpoints Antonio Quartulli
2026-09-24 17:00 ` patchwork-bot+netdevbpf
2026-09-21 10:22 ` [PATCH net 02/11] ovpn: skip UDP source validation for unspecified addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 03/11] ovpn: track UDP socket route key for peer dst cache Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 04/11] ovpn: validate peer state before caching UDP dst Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 05/11] ovpn: replace bind when learning local endpoint Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 06/11] ovpn: replace bind when clearing stale local source Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 07/11] ovpn: always unhash old VPN addresses before rehashing Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 08/11] ovpn: reject duplicate peer VPN addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 09/11] ovpn: reject multipeer peers without " Antonio Quartulli
2026-09-21 10:22 ` Antonio Quartulli [this message]
2026-09-21 10:22 ` [PATCH net 11/11] selftests: ovpn: validate peer " Antonio Quartulli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921102215.3599702-11-antonio@openvpn.net \
--to=antonio@openvpn.net \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=ralf@mandelbit.com \
--cc=sd@queasysnail.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox