[PATCH v1] dco-linux: enforce ifindex only for DEL_PEER notifications
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.devel |
|---|---|
| Message-ID | <[email protected]> |
From: Ralf Lici <[email protected]> The unconditional ifindex check introduced by commit e78a8af2f5ce rejects legitimate kernel replies, specifically peer stats responses, because those messages do not carry OVPN_ATTR_IFINDEX. Move the check into ovpn_handle_del_peer() so it applies only to spontaneous DEL_PEER notifications from the kernel. This keeps response handling working while still filtering foreign-instance notifications. Fixes: e78a8af2f5ce ("dco: backport immediate notification processing on Linux and FreeBSD") Github: closes OpenVPN/openvpn#1020 Change-Id: I9b1f4fd06c8a02d3f51b6a3bdea2f92191669660 Signed-off-by: Ralf Lici <[email protected]> Acked-by: Gert Doering <[email protected]> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1636 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to release/2.6. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1636 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Gert Doering <[email protected]> diff --git a/src/openvpn/dco_linux.c b/src/openvpn/dco_linux.c index 8ce7026..1df56cf 100644 --- a/src/openvpn/dco_linux.c +++ b/src/openvpn/dco_linux.c @@ -857,6 +857,23 @@ static int ovpn_handle_del_peer(dco_context_t *dco, struct nlattr *attrs[]) { + /* we must know which interface this message is referring to in order to + * avoid mixing messages for other instances + */ + if (!attrs[OVPN_ATTR_IFINDEX]) + { + msg(D_DCO, "ovpn-dco: Received message without ifindex"); + return NL_STOP; + } + + uint32_t ifindex = nla_get_u32(attrs[OVPN_ATTR_IFINDEX]); + if (ifindex != dco->ifindex) + { + msg(D_DCO_DEBUG, "ovpn-dco: ignoring message for foreign ifindex %d", + ifindex); + return NL_SKIP; + } + if (!attrs[OVPN_ATTR_DEL_PEER]) { msg(D_DCO, "ovpn-dco: no attributes in OVPN_DEL_PEER message"); @@ -930,23 +947,6 @@ return NL_STOP; } - /* we must know which interface this message is referring to in order to - * avoid mixing messages for other instances - */ - if (!attrs[OVPN_ATTR_IFINDEX]) - { - msg(D_DCO, "ovpn-dco: Received message without ifindex"); - return NL_STOP; - } - - uint32_t ifindex = nla_get_u32(attrs[OVPN_ATTR_IFINDEX]); - if (ifindex != dco->ifindex) - { - msg(D_DCO_DEBUG, "ovpn-dco: ignoring message for foreign ifindex %d", - ifindex); - return NL_SKIP; - } - /* based on the message type, we parse the subobject contained in the * message, that stores the type-specific attributes. *