Blame

a75bb0 Samuli Seppänen 2025-01-29 07:33:21 1
# OpenVPN Hackathon 2017
2
3
## who
4
This year's hackathon is organized by Heiko Hund (d12fk).
5
6
We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 16 devs.
7
8
## who is coming?
9
10
| Name | Topics | Arrival | Departure | Hotel |
11
|-----------------|------------------------------------------|-----------------------|-------------------|-------------------|
12
| Heiko Hund | - | Fri. 10am | Sun. 20pm | @home |
13
| Antonio Quartulli | traffic manipulation API | Thu noon | Sun afternoon | Der Blaue Reiter |
14
| Samuli Seppänen | OpenVPN 3 development | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
15
| Steffan Karger | Post-quantum key exchange, performance | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon | Blaue Reiter |
16
| Gert Döring | branch maintenance - what goes where, and why? | Fri noon-ish | Sun late afternoon| Blauer Reiter |
17
| Arne Schwabe | - | Fri 12 am at HBF | Sun late afternoon| Blauer Reiter |
18
| David Sommerseth| clean-ups, plug-ins, OpenVPN 3 client | Thursday evening | Sun afternoon | Blaue Reiter |
19
| Lev Stipakov | ovpn3 | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
20
| Jan Just Keijser| performance, EduVPN | Friday early afternoon| Sun late-afternoon| Der Blaue Reiter |
21
| Gert van Dijk | Post-quantum key exchange, documentation | Fri 13:16 (Bhf Durlach)| Sun mid-afternoon| Blaue Reiter |
22
| Johan Draaisma | Moral support | Thu noon-ish | Sun at noon | Der Blaue Reiter |
23
| James Yonan | | Thursday | - | - |
24
| Simon Rozman | eduVPN, MSI packaging | Thu late evening | Sun mid-afternoon | Der Blaue Reiter |
25
| François Kooman | eduVPN, OAuth | Thu afternoon | Mon | Der Blaue Reiter |
26
27
## where?
28
29
The meeting is held at the Sophos office in Karlsruhe (Germany): [Sophos Office](https://osm.org/go/0DlEda7Ld?m=&node=2127345937).
30
31
Karlsruhe is an one hour ICE train ride away from Frankfurt Airport.
32
33
If you have any questions or got lost - please contact Heiko at +49 172 74 911 92.
34
35
## when?
36
37
The hackathon will take place from Friday November 10th 2017 to Sunday November 12th.
38
39
## what?
40
41
So what is the goal of the Hackathon?
42
43
- Should we get rid of LZ4 as bundled library and always rely on what the system has installed?
44
- Plan clean up route.c and tun.c - which approach should we use? Improve OS/distro modularization? Settle on an improved API?
45
- Add more topics here!
46
47
We're all open for additions here - I think the meetings in Brussels (2011+2012), Munich (2013+2014), Delft (2015) and Helsinki (2016) have shown that "just being able to sit together and hack" is a useful exercise.
48
49
## input
50
51
There will be drinks and snacks to get us through the day. We have a kitchen, so you can also [make sandwiches](https://xkcd.com/149/) or a bowl of cereals. Chance of BBQ if there's demand in November.
52
53
## internet
54
55
Free Wifi and wired network is available
56
57
## accommodation
58
59
The closest Hotel is the "Der Blaue Reiter" just across the street.\
60
Cheapest accommodation is [IBIS budget](http://www.ibis.com/gb/hotel-3179-ibis-budget-karlsruhe/index.shtml) a good 10 minute walk away.
61
62
## results
63
64
(informal notes on some of the discussions that benefit from writing down)
65
66
### MSI
67
- TAP-Windows driver:
68
- MSI (and MSM) packages are to be built on Windows using WiX Toolset.
69
- Test certificates are injected prior driver installation on all supported Windows versions.
70
- Possible later improvements:
71
- tapinstall.exe is to be eventually replaced with vanilla GPL-licenced utility.
72
- Add metadata to the driver .inf file to allow it to be installed from the file's context menu in explorer.
73
- OpenVPN:
74
- MSI package creation is integrated into openvpn-build using either msitools (preferred) or by running WiX toolset with Mono.
75
- The initial installer will be a silent one and aimed for enterprises and advanced users.
76
- It will not include any GUI, so normal users may/will get confused.
77
- Simon prepares the initial sample, we discuss options when we have something to work on.
78
- UI while installing is not required or kept to the minimum.
79
- MSI packages are also to be packed into an EXE installer for end-users.
80
81
### route.c / tun.c rehaul
82
- Linux support for ifconfig/route is dropped.
83
- We keep iproute2 support.
84
- We add direct netlink support.
85
- Netlink support needs to come along with strong unit tests.
86
- We split route.c to route.c and route-platform.c.
87
- We look into splitting tun.c into tun-unix.c and tun-win32.c.
88
- Tun.c needs to see all those nearly-identical tun_read()/tun_write() functions merged into one place.
89
90
### Vagrant
91
- We have a few use-cases for Vagrant.
92
- Mattock has a rudimentary Vagrant setup [here](https://github.com/mattock/openvpn-vagrant).
93
- Next steps include adding basic provisioning scripts and setting up a t_client style server setup.
94
95
### block-ipv6 patch
96
- Considered a good idea, Arne will cleanup patch and resend patch.
97
98
### `--tls-cert-profile`
99
- The OpenSSL 'custom security callbacks' are undocumented.
100
- We'll accept slightly different behavior between openssl and mbed TLS, at least for now.
101
- Steffan will send David his patches that attempt to reimplement tls-cert-profile for openssl, so he can give it a try too if he wants to.
102
- Steffan will send a v2 of the mbed patch that will print a warning for openssl build, instead of refusing to start, if `--tls-cert-profile` is used.
103
- Steffan will later send a patch to implement the seclevel approach for openssl.
104
105
### argv processing clean-up (David, Heiko)
106
- Heiko has some patches on the ML which have been awaiting some updates since last Hackathon; approximately half of the patch-set have been applied but the rest have been lingering since that time.
107
- David and Heiko reviewed these last outstanding patches and agreed to clean them up and rebase on master to complete these patches.
108
- One bug is discovered and will be fixed before being sent to the ML.
109
- Considered if callers of the `argv_*()` functions should be enforced to provide a `gc_arena`. Decided such a change would be quite intrusive and not providing any clear gains.
110
- The `argv_*()` functions already have an internal `gc_arena` which is used for the argv arrays of string pointers and is handled properly there.
111
- Where memory is allocated by `argv_*()` functions to be returned to the calling function, a `gc_arena` pointer is already provided in that call; that allocation happens in the `gc_arena` owned by the caller.
112
- Will also try to add a bit more code comments to ensure the code is easier to understand in the future.
113
114
### Version life cycle
115
- Agreed that our current approach is quite good, but poorly documented and communicated.
116
- David and Steffan wrote a draft that should help change that, comments and contributions very welcome: [Supported Versions](https://community.openvpn.net/openvpn/wiki/SupportedVersions)
117
- We will aim for having all 2.5 features in for the 2018 hackathon, and go into 'produce a release mode' afterwards.
118
- tls-crypt-v2
119
- transport plugin (primary use case: obfuscation)
120
- netlink support (includes route.c / tun.c refactoring)
121
- 'make VPN fast again!'
122
- remove ENABLE_CRYPTO
123
- purge NSIS installers (migrate to MSI installers)
124
- VLAN patch set
125
- support for multiple sockets (UDP/TCP/multi-port/multi-IP)
126
- dynamic routes ('route in ccd-file'), depends on netlink support
127
- improve control channel performance
128
- update the PRF to ditch MD5/SHA1 (not because broken crypto (it is not!), but for simplicity and marketing)
129
- maybe: add PRF plugin interface
130
- maybe: add key exchange plugin interface (allows easily doing .e.g post quantum kex)
131
- maybe: add data channel separation (or, move to ovpn3, which already has this?)
132
- maybe: fix radius-plugin - plugin is useful but not maintained very well
133
134
### Control channel optimization
135
- Gert van Dijk and Steffan will be looking into optimizing the control channel in the coming weeks.
136
- Discussed with Arne that we probably would need some dynamic window size to increase performance.
137
- We want to keep the OpenVPN implementation simple, and have a very strong preference to not change the wire format (i.e., must be backward compatible).
138
- Arne will look into good candidate window size algorithms, and make a suggestion about which to use.