OpenVPN 3 Linux v27.1 (Stable release)

The v27.1 release is purely a bug fix release

* FEATURE DEPRECATION: openvpn3-autoload

  ** THIS IS THE LAST RELEASE SHIPPING THIS UTILITY - MIGRATE NOW **

  The openvpn3-autoload feature was deprecated already in the
  v20 release.  This feature will be removed in the next major
  release.

  The replacement is the [email protected] systemd unit.
  Please see the openvpn3-systemd man page [1] for more details.

  If you depend on openvpn3-autoload today, please migrate ASAP
  to the systemd approach.

  [1] 
<https://codeberg.org/OpenVPN/openvpn3-linux/src/branch/master/docs/man/openvpn3-systemd.8.rst>


* Regression: File descriptor leaks with reconnects

  The v27 release attempted to fix a file descriptor leak which
  happens when the VPN session is triggered to do a full reconnect
  to the server.   It turned out that this change caused a lot more
  issues and resulted in a large regression when the server-side
  sent a PUSH_UPDATE event to update routing tables.

  This file descriptor leak fix has been reverted in the v27.1
  release, as the investigation revealed that this requires a more
  careful change inside the OpenVPN 3 Core Library in addition.

  The file descriptor leak can be an issue for users on unstable
  Internet connections, where the client is triggered to do a full
  in-session restart.

  The only workaround is to stop the session completely before
  starting it again.  Using the [email protected] unit file,
  this is done with a single

      # systemctl restart openvpn3-session@CONFIG_NAME.service

  command.  This is planned to be fixed in the next major release,
  where it will upgrade to OpenVPN 3 Core Library v3.12.


* Bugfix: VPN sessions using DCO interfaces misbehave with PUSH_UPDATE

  When the server pushed a PUSH_UPDATE event to the client with updates
  to the network configuration, this would cause the DCO-based VPN tunnel
  to freeze and become dysfunctional.  This has been resolved and the
  DCO interface is fully capable of reconfiguring the network when
  requested by the server.


* Bugfix: Retrieve tunnel statistics for DCO interfaces

  It has been a long outstanding bug where the session traffic details
  were not updated when DCO interfaces were used.  This is now fixed and
  the openvpn3 session-stats command will now report up-to-date
  statistics.


* Build: Fixed issues building with GCC-16.1

  Several new compiler warnings appeared, especially in environments
  enabling hardened builds, when the GCC compiler was upgraded to
  version 16.1.  This should be resolved.

  Fixing these issues was a requirement to make Fedora 44 builds
  available.


* OpenVPN 3 Core Library update

  The OpenVPN 3 Core Library has been updated to version 3.11.7. This
  resolves several bugs related to the ovpn-dco-v2 kernel module
  integration, fixes issues with large wire packets when the
  --tls-crypt-v2 feature is used and provides additional fixes for
  GCC-16.1 related compiler warnings.


Known issues:

  - The openvpn3-service-netcfg service does not differentiate between
    --dns server X resolve-domains and --dns search-domains when using
    the --resolv-conf mode, which is not the intended behaviour.  This
    was discovered in the v24 release and is scheduled to be
    fixed in the next releases.  When this gets fixed, only
    --dns search-domains will be considered as search domains and
    --dns server X resolve-domains will enable split-DNS when using
    --systemd-resolved and otherwise ignored when using
    --resolv-conf with openvpn3-service-netcfg.


Supported Linux distributions
-----------------------------

  - Debian: 12, 13
  - Fedora: 43, 44
  - Red Hat Enterprise Linux 8, 9, 10[*]
  - Ubuntu: 22.04, 24.04, 26.04

Installation and getting started instructions can be found here:

  <https://community.openvpn.net/openvpn/wiki/OpenVPN3Linux>

The OpenVPN Inc. provided repositories will be updated in the coming
days.  The community provided repositories on Fedora Copr and
openSUSE Build Service are already published.

There are in addition other Linux distributions now providing
OpenVPN 3 Linux packages.  These distributions are primarily
supported by their respective distribution communities.  We will
naturally review and apply fixes deemed needed for any
distributions as they occur.

NOTE: Red Hat Enterprise Linux 10
  It is necessary to use the 'rhel+epel-10-x86_64' chroot when running
  the 'dnf copr enable' command on RHEL-10.

      # dnf copr enable dsommers/openvpn3 rhel+epel-10-x86_64

  The stable repositories provided by OpenVPN Inc should not
  have this issue.


Experimental Builds
-------------------

With this release we have enabled building packages via the
openSUSE Build Service for the following SUSE/openSUSE
distributions

 - openSUSE Factory (x86_64, aarch64)
 - openSUSE Leap 16.0 (x86_64, aarch64)
 - openSUSE Tumbleweed (x86_64, aarch64)


Source forge hosting
--------------------

OpenVPN 3 Linux and GDBus++ are being pushed to several forge hosting
services: Codeberg (main), GitLab (mirror) and GitHub (mirror).  In
addition from v27, the Radicle Network was added.

Codeberg will for now be the main repository for bug/issue tracking.
For patch ("pull request") submissions, it is preferred to use the
[email protected] mailing list.  In addition the
Radicle Network can now be used.

The Radicle Network is a fully distributed network for hosting
projects.  This satisfies one big reason why the mailing list approach
has been the preferred way for submitting patches - it is decentralised
and it does not require a single hosting service to be available at
all times.  In addition to Radicle being fully decentralised, it also
provides a pretty solid integrity check to any changes in a project,
which also includes changes to the patch submission tracking as well
as the git repository changes (and issue tracking, which we will not
make use of at the moment).

For more information on Radicle, visit <https://radicle.dev/>

For a quick-start guide to use Radicle, see 
<https://radicle.dev/guides/quick-start>


--
kind regards,

David Sommerseth
OpenVPN Inc


---- Source tarballs ---------------------------------------------------
* OpenVPN 3 Linux v27.1

  <https://swupdate.openvpn.net/community/releases/openvpn3-linux-27.1.tar.xz>
  
<https://swupdate.openvpn.net/community/releases/openvpn3-linux-27.1.tar.xz.asc>

* GDBus++ v3

  <https://swupdate.openvpn.net/community/releases/gdbuspp-3.tar.xz>
  <https://swupdate.openvpn.net/community/releases/gdbuspp-3.tar.xz.asc>

---- SHA256 Checksums --------------------------------------------------

842162e48f7fc756a517b9f5807fb993152e210e996df4a267c3ff2ab40142d6  
openvpn3-linux-27.1.tar.xz
960bd3d315a07953b354e9c398c9c97ebaf3cab70f5a4c6442e259800e675b42  
openvpn3-linux-27.1.tar.xz.asc
c7a053a13c4eb5811a542b747d5fcdb3a8e58a4a42c7237cc5e2e2ca72e0c94e  
gdbuspp-3.tar.xz
b9cf732d7a347f324d6a5532dc48f80c2815dbf6704c169b4ee97a411506a99b  
gdbuspp-3.tar.xz.asc

---- git references ----------------------------------------------------

git repositories:

 - OpenVPN 3 Linux

   git tag: v27.1
   git commit: 4aff60fe2bfd2fd41b0d373228f746905fbe76d4

   Radicle (PRIMARY, code + patches): rad:zN58oopqzrAkTregNZaRQpgg7x3c
   
<https://radicle.network/nodes/bndcrepos.radicle.garden/rad:zN58oopqzrAkTregNZaRQpgg7x3c>

   Codeberg (PRIMARY, code + issue/bugs reports)
   <https://codeberg.org/OpenVPN/openvpn3-linux>

   Code mirrors:
   <https://gitlab.com/openvpn/openvpn3-linux>
   <https://github.com/OpenVPN/openvpn3-linux>

 - GDBus++

   git tag: v3
   git commit: 96f7fb688ed2dea3f192c63c5fe283dbe4900f16

   Radicle (PRIMARY, code + patches): rad:z2Tpg8xVSDgTpoU4Q5FN1aPGqf6mG
   
<https://radicle.network/nodes/bndcrepos.radicle.garden/rad:z2Tpg8xVSDgTpoU4Q5FN1aPGqf6mG>

   Codeberg (PRIMARY, code + issue/bugs reports)
   <https://codeberg.org/OpenVPN/gdbuspp/>

   Code mirrors:
   <https://gitlab.com/openvpn/gdbuspp/>
   <https://github.com/openvpn/gdbuspp/>


---- Changes from v27 to v27.1 -------------------------------------

Antonio Quartulli (2):
      dco: retrieve peer stats from kernel module
      netcfg: Make tun_builder_new() DCO-aware for PUSH_UPDATE reconfiguration

David Sommerseth (11):
      common: Fix dhcp-option and dns handling of multiple occurrences
      Revert "client: Plug a file descriptor leak with virtual tun interfaces"
      ovpn3cli/init-config: Show the compiled-in username for the openvpn user
      build/selinux: Refactor the building setup for SELinux policies
      common: Fix missing static declarations in ExclusiveOptionError and 
ConfigFileException
      policy: Add needed D-Bus policy to access net.openvpn.v3.netcfg.GetPeer
      docs: Remove the "tech-preview" label from DCO functionality
      scripts: Fix get-version extracting wrong git commit for openvpn3-core
      vendor: Upgrade to ASIO 1.38.0
      build: Fix the systemd requirement dependecy again
      core: Update to OpenVPN 3 Core Library v3.11.7

--------------------------------------------------------------------

-- 
  Frank Lichtenheld


_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to