Blame
| a75bb0 | Samuli Seppänen | 2025-01-29 07:33:21 | 1 | # OpenVPN Hackathon 2017 |
| 2 | ||||
| 3 | ## who |
|||
| 4 | This year's hackathon is organized by Heiko Hund (d12fk). |
|||
| 5 | ||||
| 6 | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 16 devs. |
|||
| 7 | ||||
| 8 | ## who is coming? |
|||
| 9 | ||||
| 10 | | Name | Topics | Arrival | Departure | Hotel | |
|||
| 11 | |-----------------|------------------------------------------|-----------------------|-------------------|-------------------| |
|||
| 12 | | Heiko Hund | - | Fri. 10am | Sun. 20pm | @home | |
|||
| 13 | | Antonio Quartulli | traffic manipulation API | Thu noon | Sun afternoon | Der Blaue Reiter | |
|||
| 14 | | Samuli Seppänen | OpenVPN 3 development | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
|||
| 15 | | Steffan Karger | Post-quantum key exchange, performance | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon | Blaue Reiter | |
|||
| 16 | | Gert Döring | branch maintenance - what goes where, and why? | Fri noon-ish | Sun late afternoon| Blauer Reiter | |
|||
| 17 | | Arne Schwabe | - | Fri 12 am at HBF | Sun late afternoon| Blauer Reiter | |
|||
| 18 | | David Sommerseth| clean-ups, plug-ins, OpenVPN 3 client | Thursday evening | Sun afternoon | Blaue Reiter | |
|||
| 19 | | Lev Stipakov | ovpn3 | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
|||
| 20 | | Jan Just Keijser| performance, EduVPN | Friday early afternoon| Sun late-afternoon| Der Blaue Reiter | |
|||
| 21 | | Gert van Dijk | Post-quantum key exchange, documentation | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon| Blaue Reiter | |
|||
| 22 | | Johan Draaisma | Moral support | Thu noon-ish | Sun at noon | Der Blaue Reiter | |
|||
| 23 | | James Yonan | | Thursday | - | - | |
|||
| 24 | | Simon Rozman | eduVPN, MSI packaging | Thu late evening | Sun mid-afternoon | Der Blaue Reiter | |
|||
| 25 | | François Kooman | eduVPN, OAuth | Thu afternoon | Mon | Der Blaue Reiter | |
|||
| 26 | ||||
| 27 | ## where? |
|||
| 28 | ||||
| 29 | The meeting is held at the Sophos office in Karlsruhe (Germany): [Sophos Office](https://osm.org/go/0DlEda7Ld?m=&node=2127345937). |
|||
| 30 | ||||
| 31 | Karlsruhe is an one hour ICE train ride away from Frankfurt Airport. |
|||
| 32 | ||||
| 33 | If you have any questions or got lost - please contact Heiko at +49 172 74 911 92. |
|||
| 34 | ||||
| 35 | ## when? |
|||
| 36 | ||||
| 37 | The hackathon will take place from Friday November 10th 2017 to Sunday November 12th. |
|||
| 38 | ||||
| 39 | ## what? |
|||
| 40 | ||||
| 41 | So what is the goal of the Hackathon? |
|||
| 42 | ||||
| 43 | - Should we get rid of LZ4 as bundled library and always rely on what the system has installed? |
|||
| 44 | - Plan clean up route.c and tun.c - which approach should we use? Improve OS/distro modularization? Settle on an improved API? |
|||
| 45 | - Add more topics here! |
|||
| 46 | ||||
| 47 | We're all open for additions here - I think the meetings in Brussels (2011+2012), Munich (2013+2014), Delft (2015) and Helsinki (2016) have shown that "just being able to sit together and hack" is a useful exercise. |
|||
| 48 | ||||
| 49 | ## input |
|||
| 50 | ||||
| 51 | There will be drinks and snacks to get us through the day. We have a kitchen, so you can also [make sandwiches](https://xkcd.com/149/) or a bowl of cereals. Chance of BBQ if there's demand in November. |
|||
| 52 | ||||
| 53 | ## internet |
|||
| 54 | ||||
| 55 | Free Wifi and wired network is available |
|||
| 56 | ||||
| 57 | ## accommodation |
|||
| 58 | ||||
| 59 | The closest Hotel is the "Der Blaue Reiter" just across the street.\ |
|||
| 60 | Cheapest accommodation is [IBIS budget](http://www.ibis.com/gb/hotel-3179-ibis-budget-karlsruhe/index.shtml) a good 10 minute walk away. |
|||
| 61 | ||||
| 62 | ## results |
|||
| 63 | ||||
| 64 | (informal notes on some of the discussions that benefit from writing down) |
|||
| 65 | ||||
| 66 | ### MSI |
|||
| 67 | - TAP-Windows driver: |
|||
| 68 | - MSI (and MSM) packages are to be built on Windows using WiX Toolset. |
|||
| 69 | - Test certificates are injected prior driver installation on all supported Windows versions. |
|||
| 70 | - Possible later improvements: |
|||
| 71 | - tapinstall.exe is to be eventually replaced with vanilla GPL-licenced utility. |
|||
| 72 | - Add metadata to the driver .inf file to allow it to be installed from the file's context menu in explorer. |
|||
| 73 | - OpenVPN: |
|||
| 74 | - MSI package creation is integrated into openvpn-build using either msitools (preferred) or by running WiX toolset with Mono. |
|||
| 75 | - The initial installer will be a silent one and aimed for enterprises and advanced users. |
|||
| 76 | - It will not include any GUI, so normal users may/will get confused. |
|||
| 77 | - Simon prepares the initial sample, we discuss options when we have something to work on. |
|||
| 78 | - UI while installing is not required or kept to the minimum. |
|||
| 79 | - MSI packages are also to be packed into an EXE installer for end-users. |
|||
| 80 | ||||
| 81 | ### route.c / tun.c rehaul |
|||
| 82 | - Linux support for ifconfig/route is dropped. |
|||
| 83 | - We keep iproute2 support. |
|||
| 84 | - We add direct netlink support. |
|||
| 85 | - Netlink support needs to come along with strong unit tests. |
|||
| 86 | - We split route.c to route.c and route-platform.c. |
|||
| 87 | - We look into splitting tun.c into tun-unix.c and tun-win32.c. |
|||
| 88 | - Tun.c needs to see all those nearly-identical tun_read()/tun_write() functions merged into one place. |
|||
| 89 | ||||
| 90 | ### Vagrant |
|||
| 91 | - We have a few use-cases for Vagrant. |
|||
| 92 | - Mattock has a rudimentary Vagrant setup [here](https://github.com/mattock/openvpn-vagrant). |
|||
| 93 | - Next steps include adding basic provisioning scripts and setting up a t_client style server setup. |
|||
| 94 | ||||
| 95 | ### block-ipv6 patch |
|||
| 96 | - Considered a good idea, Arne will cleanup patch and resend patch. |
|||
| 97 | ||||
| 98 | ### `--tls-cert-profile` |
|||
| 99 | - The OpenSSL 'custom security callbacks' are undocumented. |
|||
| 100 | - We'll accept slightly different behavior between openssl and mbed TLS, at least for now. |
|||
| 101 | - Steffan will send David his patches that attempt to reimplement tls-cert-profile for openssl, so he can give it a try too if he wants to. |
|||
| 102 | - Steffan will send a v2 of the mbed patch that will print a warning for openssl build, instead of refusing to start, if `--tls-cert-profile` is used. |
|||
| 103 | - Steffan will later send a patch to implement the seclevel approach for openssl. |
|||
| 104 | ||||
| 105 | ### argv processing clean-up (David, Heiko) |
|||
| 106 | - Heiko has some patches on the ML which have been awaiting some updates since last Hackathon; approximately half of the patch-set have been applied but the rest have been lingering since that time. |
|||
| 107 | - David and Heiko reviewed these last outstanding patches and agreed to clean them up and rebase on master to complete these patches. |
|||
| 108 | - One bug is discovered and will be fixed before being sent to the ML. |
|||
| 109 | - Considered if callers of the `argv_*()` functions should be enforced to provide a `gc_arena`. Decided such a change would be quite intrusive and not providing any clear gains. |
|||
| 110 | - The `argv_*()` functions already have an internal `gc_arena` which is used for the argv arrays of string pointers and is handled properly there. |
|||
| 111 | - Where memory is allocated by `argv_*()` functions to be returned to the calling function, a `gc_arena` pointer is already provided in that call; that allocation happens in the `gc_arena` owned by the caller. |
|||
| 112 | - Will also try to add a bit more code comments to ensure the code is easier to understand in the future. |
|||
| 113 | ||||
| 114 | ### Version life cycle |
|||
| 115 | - Agreed that our current approach is quite good, but poorly documented and communicated. |
|||
| 116 | - David and Steffan wrote a draft that should help change that, comments and contributions very welcome: [Supported Versions](https://community.openvpn.net/openvpn/wiki/SupportedVersions) |
|||
| 117 | - We will aim for having all 2.5 features in for the 2018 hackathon, and go into 'produce a release mode' afterwards. |
|||
| 118 | - tls-crypt-v2 |
|||
| 119 | - transport plugin (primary use case: obfuscation) |
|||
| 120 | - netlink support (includes route.c / tun.c refactoring) |
|||
| 121 | - 'make VPN fast again!' |
|||
| 122 | - remove ENABLE_CRYPTO |
|||
| 123 | - purge NSIS installers (migrate to MSI installers) |
|||
| 124 | - VLAN patch set |
|||
| 125 | - support for multiple sockets (UDP/TCP/multi-port/multi-IP) |
|||
| 126 | - dynamic routes ('route in ccd-file'), depends on netlink support |
|||
| 127 | - improve control channel performance |
|||
| 128 | - update the PRF to ditch MD5/SHA1 (not because broken crypto (it is not!), but for simplicity and marketing) |
|||
| 129 | - maybe: add PRF plugin interface |
|||
| 130 | - maybe: add key exchange plugin interface (allows easily doing .e.g post quantum kex) |
|||
| 131 | - maybe: add data channel separation (or, move to ovpn3, which already has this?) |
|||
| 132 | - maybe: fix radius-plugin - plugin is useful but not maintained very well |
|||
| 133 | ||||
| 134 | ### Control channel optimization |
|||
| 135 | - Gert van Dijk and Steffan will be looking into optimizing the control channel in the coming weeks. |
|||
| 136 | - Discussed with Arne that we probably would need some dynamic window size to increase performance. |
|||
| 137 | - We want to keep the OpenVPN implementation simple, and have a very strong preference to not change the wire format (i.e., must be backward compatible). |
|||
| 138 | - Arne will look into good candidate window size algorithms, and make a suggestion about which to use. |
