cron2 has uploaded a new patch set (#2) to the change originally created by stipa. ( http://gerrit.openvpn.net/c/openvpn/+/1920?usp=email )
The following approvals got outdated and were removed: Code-Review+2 by cron2 Change subject: dco_win: report per-peer ioctl failures instead of exiting ...................................................................... dco_win: report per-peer ioctl failures instead of exiting Three per-peer operations end the process when their ioctl fails: MP_NEW_PEER, NEW_KEY and SWAP_KEYS all report with M_ERR, which is M_FATAL. On a server that means one client's failure disconnects every other client. The shared code above them already recovers per instance: a failed MP_NEW_PEER drops that client in multi.c, a failed SWAP_KEYS raises SIGUSR1 for that instance in forward.c, and change 1835 restarts the instance on a failed NEW_KEY. None of it runs on Windows, because the process is gone before the error can be returned. Report and return, which is what DEL_PEER, MP_SET_PEER and the iroute calls in this same file already do. The remaining M_ERR uses here are interface-wide setup, where failing hard is still right. NEW_KEY failing is not hypothetical: the driver owns the keepalive timer and expires peers itself, so a key install can arrive for a peer it has just removed. Measured on a Windows DCO server under peer churn: 15 refused installs across four runs, no process exit. Signed-off-by: Lev Stipakov <[email protected]> Acked-by: Gert Doering <[email protected]> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1920 Change-Id: Ie46934c0a8f04908cc277114ae491c100d368cb2 Message-Id: <[email protected]> URL: https://www.mail-archive.com/[email protected]/msg39349.html Signed-off-by: Gert Doering <[email protected]> --- M src/openvpn/dco_win.c 1 file changed, 4 insertions(+), 3 deletions(-) git pull ssh://gerrit.openvpn.net:29418/openvpn refs/changes/20/1920/2 diff --git a/src/openvpn/dco_win.c b/src/openvpn/dco_win.c index b3268bc..90cff8c 100644 --- a/src/openvpn/dco_win.c +++ b/src/openvpn/dco_win.c @@ -460,7 +460,8 @@ if (!DeviceIoControl(dco->tt->hand, OVPN_IOCTL_MP_NEW_PEER, &newPeer, sizeof(newPeer), NULL, 0, &bytesReturned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_MP_NEW_PEER) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_MP_NEW_PEER) failed"); + return -1; } return 0; @@ -575,7 +576,7 @@ if (!DeviceIoControl(dco->tt->hand, ioctl, buf, bufSize, NULL, 0, &bytes_returned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_NEW_KEY) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_NEW_KEY) failed"); return -1; } return 0; @@ -609,7 +610,7 @@ DWORD bytes_returned = 0; if (!DeviceIoControl(dco->tt->hand, ioctl, buf, len, NULL, 0, &bytes_returned, NULL)) { - msg(M_ERR, "DeviceIoControl(OVPN_IOCTL_SWAP_KEYS) failed"); + msg(M_WARN | M_ERRNO, "DeviceIoControl(OVPN_IOCTL_SWAP_KEYS) failed"); return -1; } return 0; -- To view, visit http://gerrit.openvpn.net/c/openvpn/+/1920?usp=email To unsubscribe, or for help writing mail filters, visit http://gerrit.openvpn.net/settings?usp=email Gerrit-MessageType: newpatchset Gerrit-Project: openvpn Gerrit-Branch: master Gerrit-Change-Id: Ie46934c0a8f04908cc277114ae491c100d368cb2 Gerrit-Change-Number: 1920 Gerrit-PatchSet: 2 Gerrit-Owner: stipa <[email protected]> Gerrit-Reviewer: cron2 <[email protected]> Gerrit-Reviewer: plaisthos <[email protected]> Gerrit-CC: openvpn-devel <[email protected]>
_______________________________________________ Openvpn-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-devel
