mirror of
https://github.com/torvalds/linux.git
synced 2026-10-04 18:29:02 +02:00
* add selftest coverage for peer VPN address validation * reject multicast, broadcast and loopback peer VPN addresses, which can never identify a peer * reject MP peers left with no usable VPN address, as they can never be selected for TX * reject duplicate peer VPN addresses, which made peer lookup return an arbitrary peer * fix stale entry left in the VPN address hashtable when an address is cleared * fix torn IPv6 address read on lockless TX when the unusable local source is cleared in place * fix torn IPv6 address read on lockless TX when a new local endpoint is learned in place * fix dst cache being populated with a route resolved from an already replaced bind * fix stale route being reused after the socket mark or UDP source port changed * fix bogus validation of an unspecified local source address, which must instead be left to route source autoselection * fix IPv6 link-local peer endpoints losing their scope id when configured via netlink, breaking route lookup -----BEGIN PGP SIGNATURE----- iJEEABYIADkWIQQr0db7q+Rc7Zog28Fc8QQzwdnOtwUCarECxxsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDIACgkQXPEEM8HZzrcvTAEA/r3oFnZ4EOtiOyA2OpZ/ Iya+WAJ7LShj7tLymzujMe8BAIH6J2RyrWXnfDFvtSG8HGDEe4EBzVpP56tX0ZVn xc0N =fg0G -----END PGP SIGNATURE----- Merge tag 'ovpn-net-20260921' of https://github.com/OpenVPN/ovpn-net-next Antonio Quartulli says: ==================== Included fixes: * add selftest coverage for peer VPN address validation * reject multicast, broadcast and loopback peer VPN addresses, which can never identify a peer * reject MP peers left with no usable VPN address, as they can never be selected for TX * reject duplicate peer VPN addresses, which made peer lookup return an arbitrary peer * fix stale entry left in the VPN address hashtable when an address is cleared * fix torn IPv6 address read on lockless TX when the unusable local source is cleared in place * fix torn IPv6 address read on lockless TX when a new local endpoint is learned in place * fix dst cache being populated with a route resolved from an already replaced bind * fix stale route being reused after the socket mark or UDP source port changed * fix bogus validation of an unspecified local source address, which must instead be left to route source autoselection * fix IPv6 link-local peer endpoints losing their scope id when configured via netlink, breaking route lookup * tag 'ovpn-net-20260921' of https://github.com/OpenVPN/ovpn-net-next: selftests: ovpn: validate peer VPN addresses ovpn: reject invalid peer VPN addresses ovpn: reject multipeer peers without VPN addresses ovpn: reject duplicate peer VPN addresses ovpn: always unhash old VPN addresses before rehashing ovpn: replace bind when clearing stale local source ovpn: replace bind when learning local endpoint ovpn: validate peer state before caching UDP dst ovpn: track UDP socket route key for peer dst cache ovpn: skip UDP source validation for unspecified addresses ovpn: preserve IPv6 scope id for netlink peer endpoints ==================== Link: https://patch.msgid.link/20260921102215.3599702-1-antonio@openvpn.net Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
||
|---|---|---|
| .. | ||
| crypto/chacha20-s390 | ||
| cxl | ||
| fault-injection | ||
| ktest | ||
| kunit | ||
| memblock | ||
| nvdimm | ||
| radix-tree | ||
| rbtree | ||
| scatterlist | ||
| selftests | ||
| shared | ||
| vma | ||
| vsock | ||