On Fri, 14 Aug 2026 12:00:25 +0200, Sabrina Dubroca <[email protected]>
wrote:
> 2026-07-29, 17:37:41 +0200, Ralf Lici wrote:
> > In MP mode, ovpn uses the peer VPN addresses to select the peer for
> > outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or
> > IPv6 attribute, but it only checks for the presence of the attribute and
> > not for a usable address value.
> >
> > This allows userspace to create an MP peer with only unspecified VPN
> > addresses, or to update an existing peer so that both VPN address
> > families become unspecified. Such a peer cannot be selected through the
> > VPN address hash tables.
> >
> > Reject MP peer creation or update when the resulting peer would not have
> > at least one VPN address configured.
>
> Same comment about "this has never worked".
>
ACK.
> > @@ -371,11 +373,19 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct
> > genl_info *info)
> > return -EINVAL;
> >
> > /* in MP mode VPN IPs are required for selecting the right peer */
> > - if (ovpn->mode == OVPN_MODE_MP && !attrs[OVPN_A_PEER_VPN_IPV4] &&
> > - !attrs[OVPN_A_PEER_VPN_IPV6]) {
> > - NL_SET_ERR_MSG_FMT_MOD(info->extack,
> > - "VPN IP must be provided in MP mode");
> > - return -EINVAL;
> > + if (ovpn->mode == OVPN_MODE_MP) {
> > + if (attrs[OVPN_A_PEER_VPN_IPV4])
> > + vpn_addr4.s_addr =
> > + nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]);
> > + if (attrs[OVPN_A_PEER_VPN_IPV6])
> > + vpn_addr6 =
> > + nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]);
> > +
> > + if (!vpn_addr4.s_addr && ipv6_addr_any(&vpn_addr6)) {
>
> minor nit, only if you end up resending this patch: the inconsistency
> between !s_addr and != htonl(INADDR_ANY) isn't great. (but I don't
> think it's confusing anyone)
>
Ah right, I missed this one. I'll resend the series anyway so I'll make
sure to use != htonl(INADDR_ANY) here as well.
--
Ralf Lici
Mandelbit Srl
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel