From: Antonio Quartulli <antonio@openvpn.net>
To: netdev@vger.kernel.org
Cc: Ralf Lici <ralf@mandelbit.com>,
Sabrina Dubroca <sd@queasysnail.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Antonio Quartulli <antonio@openvpn.net>
Subject: [PATCH net 01/11] ovpn: preserve IPv6 scope id for netlink peer endpoints
Date: Mon, 21 Sep 2026 12:22:02 +0200 [thread overview]
Message-ID: <20260921102215.3599702-2-antonio@openvpn.net> (raw)
In-Reply-To: <20260921102215.3599702-1-antonio@openvpn.net>
From: Ralf Lici <ralf@mandelbit.com>
ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports
bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint
parser never copied the attribute into the sockaddr_in6 used to create or
update the peer bind.
As a result, an IPv6 link-local remote endpoint configured through
netlink loses its interface scope, unlike on the peer float path where
ipv6_iface_scope_id populates the field. The UDPv6 output path then
builds a flow with flowi6_oif set to zero and route lookup can fail or
select the wrong interface.
Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The
existing precheck already rejects the scope-id attribute for IPv4 and
v4-mapped IPv6 remotes.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
---
drivers/net/ovpn/netlink.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index 4dad85294198..2ba762082acc 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
struct sockaddr_in6 *sin6;
struct sockaddr_in *sin;
struct in6_addr *in6;
+ struct nlattr *scope;
+ u32 scope_id = 0;
__be16 port = 0;
__be32 *in;
@@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
} else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) {
ss->ss_family = AF_INET6;
in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]);
+ scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID];
+ if (scope)
+ scope_id = nla_get_u32(scope);
} else {
return false;
}
@@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
if (!ipv6_addr_v4mapped(in6)) {
sin6 = (struct sockaddr_in6 *)ss;
sin6->sin6_port = port;
+ sin6->sin6_scope_id = scope_id;
memcpy(&sin6->sin6_addr, in6, sizeof(*in6));
break;
}
--
2.55.0
next prev parent reply other threads:[~2026-09-21 10:22 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 10:22 [PATCH net 00/11] pull request: fixes for ovpn 2026-09-21 Antonio Quartulli
2026-09-21 10:22 ` Antonio Quartulli [this message]
2026-09-24 17:00 ` [PATCH net 01/11] ovpn: preserve IPv6 scope id for netlink peer endpoints patchwork-bot+netdevbpf
2026-09-21 10:22 ` [PATCH net 02/11] ovpn: skip UDP source validation for unspecified addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 03/11] ovpn: track UDP socket route key for peer dst cache Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 04/11] ovpn: validate peer state before caching UDP dst Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 05/11] ovpn: replace bind when learning local endpoint Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 06/11] ovpn: replace bind when clearing stale local source Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 07/11] ovpn: always unhash old VPN addresses before rehashing Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 08/11] ovpn: reject duplicate peer VPN addresses Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 09/11] ovpn: reject multipeer peers without " Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 10/11] ovpn: reject invalid peer " Antonio Quartulli
2026-09-21 10:22 ` [PATCH net 11/11] selftests: ovpn: validate " Antonio Quartulli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921102215.3599702-2-antonio@openvpn.net \
--to=antonio@openvpn.net \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=ralf@mandelbit.com \
--cc=sd@queasysnail.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox