Netdev List
 help / color / mirror / Atom feed
From: Ralf Lici <ralf@mandelbit.com>
To: netdev@vger.kernel.org
Cc: Antonio Quartulli <antonio@openvpn.net>,
	Sabrina Dubroca <sd@queasysnail.net>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>, David Ahern <dsahern@kernel.org>,
	Ido Schimmel <idosch@nvidia.com>
Subject: [PATCH net 0/1] ovpn: avoid caching stale IPv6 dst after FIB changes
Date: Thu, 17 Sep 2026 12:09:53 +0200	[thread overview]
Message-ID: <cover.1789639346.git.ralf@mandelbit.com> (raw)

Hi,

This patch was originally part of a wider ovpn series addressing UDP
route-cache correctness when mutable socket routing properties or peer
endpoint state change while packets are being transmitted [1]. The
ovpn-specific fixes were resubmitted separately after dropping this
patch, which addresses an independent IPv6 FIB race reproduced in ovpn.

During review, Sabrina suggested submitting the patch directly to netdev
rather than through the ovpn pull request because it touches generic
dst_cache code and the underlying late-cookie sampling pattern is not
specific to ovpn. I first sent an RFC describing the race and a possible
kernel-wide solution [2], but it has not received any feedback so far.

After discussing the submission path with Antonio, we decided to post
the concrete ovpn fix directly to netdev. It prevents ovpn from caching
a route if the IPv6 FIB generation changed during lookup, without
attempting the broader network-stack refactoring discussed in the RFC.

[1] https://lore.kernel.org/openvpn-devel/cover.1785308184.git.ralf@mandelbit.com/
[2] https://lore.kernel.org/netdev/20260901122501.482920-1-ralf@mandelbit.com/

Compared with the version previously posted as part of the ovpn series,
this patch has been rebased on current net/main and made independent of
the pending ovpn route-cache and endpoint changes.

Thanks,

Ralf Lici
Mandelbit Srl

---
Ralf Lici (1):
  ovpn: avoid caching stale IPv6 dst after FIB changes

 drivers/net/ovpn/udp.c  | 20 +++++++++++++++++---
 include/net/dst_cache.h | 13 +++++++++++++
 net/core/dst_cache.c    | 19 +++++++++++++++----
 3 files changed, 45 insertions(+), 7 deletions(-)

base-commit: c9151088f1674fd29ff26a20f5fc687acf53a2f0
-- 
2.55.0


             reply	other threads:[~2026-09-17 10:10 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 10:09 Ralf Lici [this message]
2026-09-17 10:09 ` [PATCH net 1/1] ovpn: avoid caching stale IPv6 dst after FIB changes Ralf Lici
2026-09-17 19:09   ` David Ahern
2026-09-18  6:51     ` Ralf Lici
2026-09-18 18:42       ` David Ahern
2026-09-18 20:27         ` Ralf Lici
2026-09-28  8:56           ` Ralf Lici
2026-09-29 14:09             ` David Ahern
2026-09-29 15:04               ` Ralf Lici
2026-10-09  0:33                 ` Antonio Quartulli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1789639346.git.ralf@mandelbit.com \
    --to=ralf@mandelbit.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=antonio@openvpn.net \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sd@queasysnail.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox