From: Antonio Quartulli <antonio@openvpn.net>
To: netdev@vger.kernel.org
Cc: Antonio Quartulli <antonio@openvpn.net>,
Sabrina Dubroca <sd@queasysnail.net>,
Ralf Lici <ralf@mandelbit.com>, Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>
Subject: [PATCH net-next 5/7] selftests: ovpn: wait for the TCP server key setup before traffic
Date: Thu, 1 Oct 2026 00:25:39 +0200 [thread overview]
Message-ID: <20260930222542.3839327-6-antonio@openvpn.net> (raw)
In-Reply-To: <20260930222542.3839327-1-antonio@openvpn.net>
In TCP mode ovpn_add_peer() starts the server side from a background
subshell that first listens for the incoming connections and then
installs the data key of every peer. The subshell PID is discarded, so
nothing synchronizes the test against the key installation.
The sleep 5 that follows does not cover it: it elapses while "listen" is
still waiting for connections, and the peers only connect in the
subsequent ovpn_add_peer() iterations, so the key loop starts well after
that sleep has expired. Until now the test happened to work because of
the unrelated delays that ran in between.
Record the PID of the background subshell and wait for it once all the
peers have been registered, which is the earliest point at which
"listen" can have returned. A peer that was not given a key yet would
otherwise drop the server-to-client packets and make the first ping
fail.
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
---
tools/testing/selftests/net/ovpn/common.sh | 13 +++++++++++++
.../testing/selftests/net/ovpn/test-close-socket.sh | 2 ++
tools/testing/selftests/net/ovpn/test.sh | 2 ++
3 files changed, 17 insertions(+)
diff --git a/tools/testing/selftests/net/ovpn/common.sh b/tools/testing/selftests/net/ovpn/common.sh
index 2f7851b82343..96b40742eddf 100644
--- a/tools/testing/selftests/net/ovpn/common.sh
+++ b/tools/testing/selftests/net/ovpn/common.sh
@@ -264,6 +264,7 @@ ovpn_add_peer() {
1 0 ${OVPN_ALG} 0 data64.key
done
}) &
+ OVPN_TCP_KEYS_PID=$!
sleep 5
else
peer_ns="ovpn_peer${1}"
@@ -281,6 +282,18 @@ ovpn_add_peer() {
fi
}
+# In TCP mode the server accepts the peers and installs their data keys from a
+# background subshell. "listen" only returns once every peer has connected, so
+# the key installation necessarily runs after ovpn_add_peer() has been called
+# for the last peer. Wait for that subshell to finish before generating any
+# traffic, otherwise the first packets may race the key installation and get
+# dropped for lack of a key.
+ovpn_wait_tcp_keys() {
+ [ -n "${OVPN_TCP_KEYS_PID:-}" ] || return 0
+
+ wait "${OVPN_TCP_KEYS_PID}"
+}
+
ovpn_compare_ntfs() {
local diff_rc=0
local diff_file
diff --git a/tools/testing/selftests/net/ovpn/test-close-socket.sh b/tools/testing/selftests/net/ovpn/test-close-socket.sh
index ec9a51bbf3c9..142dc14e2606 100755
--- a/tools/testing/selftests/net/ovpn/test-close-socket.sh
+++ b/tools/testing/selftests/net/ovpn/test-close-socket.sh
@@ -37,6 +37,8 @@ ovpn_prepare_network() {
ovpn_cmd_ok "register peer${p} in overlay" ovpn_add_peer "${p}"
done
+ ovpn_cmd_ok "wait for server-side key setup" ovpn_wait_tcp_keys
+
for p in $(seq 1 ${OVPN_NUM_PEERS}); do
peer_ns="ovpn_peer${p}"
ovpn_cmd_ok "set peer0 timeout for peer ${p}" \
diff --git a/tools/testing/selftests/net/ovpn/test.sh b/tools/testing/selftests/net/ovpn/test.sh
index e2e6ffdd29bb..0762fa83e4b5 100755
--- a/tools/testing/selftests/net/ovpn/test.sh
+++ b/tools/testing/selftests/net/ovpn/test.sh
@@ -45,6 +45,8 @@ ovpn_prepare_network() {
ovpn_cmd_ok "register peer${p} in overlay" ovpn_add_peer "${p}"
done
+ ovpn_cmd_ok "wait for server-side key setup" ovpn_wait_tcp_keys
+
for p in $(seq 1 ${OVPN_NUM_PEERS}); do
peer_ns="ovpn_peer${p}"
ovpn_cmd_ok "set peer0 timeout for peer ${p}" \
--
2.55.0
next prev parent reply other threads:[~2026-09-30 22:26 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 22:25 [PATCH net-next 0/7] pull request: ovpn 2026-09-30 Antonio Quartulli
2026-09-30 22:25 ` [PATCH net-next 1/7] ovpn: Fix the return value in ovpn_bind_from_sockaddr() kernel-doc Antonio Quartulli
2026-09-30 22:25 ` [PATCH net-next 2/7] ovpn: remove unused work field from struct ovpn_socket Antonio Quartulli
2026-09-30 22:25 ` [PATCH net-next 3/7] ovpn: remove redundant peer NULL checks in crypto post functions Antonio Quartulli
2026-09-30 22:25 ` [PATCH net-next 4/7] selftests: ovpn: enable TCP_NODELAY on TCP sockets Antonio Quartulli
2026-09-30 22:25 ` Antonio Quartulli [this message]
2026-10-01 22:27 ` [PATCH net-next 5/7] selftests: ovpn: wait for the TCP server key setup before traffic netdev-bot+sashiko
2026-10-02 9:16 ` Antonio Quartulli
2026-09-30 22:25 ` [PATCH net-next 6/7] ovpn: send peer object along with PEER_DEL_NTF Antonio Quartulli
2026-10-01 22:27 ` netdev-bot+sashiko
2026-09-30 22:25 ` [PATCH net-next 7/7] MAINTAINERS: ovpn: add Ralf Lici as reviewer Antonio Quartulli
-- strict thread matches above, loose matches on Subject: below --
2026-10-07 13:30 [PATCH net-next 0/7] pull request: ovpn 2026-10-07 Antonio Quartulli
2026-10-07 13:30 ` [PATCH net-next 5/7] selftests: ovpn: wait for the TCP server key setup before traffic Antonio Quartulli
2026-10-08 13:32 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930222542.3839327-6-antonio@openvpn.net \
--to=antonio@openvpn.net \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=ralf@mandelbit.com \
--cc=sd@queasysnail.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox