Blame
| 9ea8ff | Samuli Seppänen | 2025-01-29 07:28:13 | 1 | # OpenVPN Hackathon 2018 |
| 2 | ||||
| 3 | This year's hackathon is organized by Andriy Revin and David Sommerseth |
|||
| 4 | ||||
| 5 | We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 10-14 devs. |
|||
| 6 | ||||
| 7 | ## Who is coming? |
|||
| 8 | ||||
| 9 | | Name | Topics | Arrival | Departure | Hotel | |
|||
| 10 | |------|--------|---------|-----------|-------| |
|||
| 11 | | Andriy Revin | - | - | - | @home | |
|||
| 12 | | David Sommerseth | clean-ups, plug-ins, OpenVPN 3 client | Thu evening (LO482/LO763) | Tue (LO766/LO483) | Ibis | |
|||
| 13 | | Antonio Quartulli | remaining IPv6-only work, VLAN patches, netlink, multi-socket/multi-protocol, transport API(?) | Fri | Tue | Ibis | |
|||
| 14 | | Steffan Karger | Performance, clean ups, crypto stuff | Thu (OS381, ETA 15:20 @ airport) | Sun | Ibis | |
|||
| 15 | | Gert Döring | VLAN Patches / Architecture, Challenge / Plugin stuff, Performance (Threading?) | Fri (LH2550, ETA 11:30 @airport) | Mon (LH2551) | Ibis | |
|||
| 16 | | Samuli Seppänen | Packaging (MSI, DEB, RPM), !HackerOne tuning | Fri late evening | Mon early morning | Ibis | |
|||
| 17 | | James Yonan | - | - | - | - | |
|||
| 18 | | Arne Schwabe | random stuff | Thu (LO410/LO765) | Tue (LO766/LO407) | Ibis | |
|||
| 19 | | Johan Draaisma | things | 3 oct | 8 oct | somewhere | |
|||
| 20 | | Lev Stipakov | things | Fri evening (TK443) | Tue | Ibis | |
|||
| 21 | ||||
| 22 | ## Where? |
|||
| 23 | ||||
| 24 | The meeting is held at the OpenVPN office in Lviv (Ukraine): [Shevchenka Ave 5](https://www.openstreetmap.org/search?query=49.83826%2C24.03129#map=19/49.83826/24.03129&layers=N). |
|||
| 25 | ||||
| 26 | Lviv Danylo Halytskyi International Airport is quite close to the city. Best way of public transport is via Uber. |
|||
| 27 | ||||
| 28 | If you have any questions - please contact Andriy Revin (andriy @ openvpn.net). |
|||
| 29 | ||||
| 30 | ## When? |
|||
| 31 | ||||
| 32 | The hackathon will take place from Friday October 5th 2018 to Sunday October 7th. |
|||
| 33 | ||||
| 34 | ## What? |
|||
| 35 | ||||
| 36 | 1. What features do we want in 2.5? Set the timeline accordingly. |
|||
| 37 | - tls-crypt v2, sitnl, vlan patches, ipv6-only, transport plug-in? |
|||
| 38 | - MSI packaging? |
|||
| 39 | - EasyRSA 3 for Windows (NSIS/MSI) installers? |
|||
| 40 | - **conclusion:** [check here](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant) |
|||
| 41 | ||||
| 42 | 2. Should OpenVPN be a "swiss army knife" or "secure vpn client for dummies" |
|||
| 43 | - Could the split between OpenVPN 2.x and 3.x reflect these two roles? |
|||
| 44 | - **conclusion:** making OpenVPN 2.x a simple client for dummies is not a priority, but devs will try to reduce complexity by removing as many ifdefs as possible and by reviewing options whenever it is possible. |
|||
| 45 | ||||
| 46 | 3. Feature changes |
|||
| 47 | - Do we need `--opt-verify`? Is this a feature strictly needed these days? |
|||
| 48 | - **conclusion:** check last item in the [2.5 discussion section](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant) |
|||
| 49 | ||||
| 50 | 4. MSI packaging |
|||
| 51 | - Available for testing for tap-windows6, but not yet for OpenVPN 2 |
|||
| 52 | - **conclusion:** get MSI packaging working with 2.5 (NSIS will be dropped) |
|||
| 53 | ||||
| 54 | ## Input |
|||
| 55 | ||||
| 56 | TBD |
|||
| 57 | ||||
| 58 | ## Internet |
|||
| 59 | ||||
| 60 | Free wifi network is available at the office |
|||
| 61 | ||||
| 62 | ## Accommodation |
|||
| 63 | ||||
| 64 | There are many options with hotels and Airbnb alternatives in walking distance from the office (5-10 minutes). Most reasonably priced hotels are fairly small and availability is varying a lot, but double check against hotels.com, booking.com, trivago.com or similar sites to ensure you get a good price. |
|||
| 65 | ||||
| 66 | Some hotels close by (4-8 minutes walk): |
|||
| 67 | ||||
| 68 | | Hotel | URL | Comments | |
|||
| 69 | |-------|-----|----------| |
|||
| 70 | | Ibis Styles Lviv Center | [Link](https://www.accorhotels.com/gb/hotel-9709-ibis-styles-lviv-center/index.shtml) | Most likely one of the bigger ones, small rooms but decent | |
|||
| 71 | | Swiss Hotel | [Link](http://swiss-hotel.lviv.ua/en/) | Reasonable hotel when getting good price offers | |
|||
| 72 | | ANTARES Apart hotel | [Link](https://antares-apart.com.ua/en/) | - | |
|||
| 73 | | Danylo Inn | [Link](http://www.danyloinn.com/) | - | |
|||
| 74 | ||||
| 75 | ## Results |
|||
| 76 | ||||
| 77 | (informal notes on some of the discussions that benefit from writing down) |
|||
| 78 | ||||
| 79 | ### 2.4.7 |
|||
| 80 | ||||
| 81 | - We need to do a 2.4.7 release "soonish", to fix the `--opt-verify` issue Lev and Johan have encountered with NCP (patch has been merged in master+release/2.4). |
|||
| 82 | - We want the "asymmetric compression" change from Arne in there. |
|||
| 83 | - The `--allow-compression` option will be added which forcefully allows the local side to send compressed data. The current patch will be updated to **not** allow this new option to be pushable. We will require this to be explicitly set in the configuration file on both sides to enable compression. |
|||
| 84 | - 2.4.7 will be initially released with the old TAP6 driver, and then we can do a re-release with the new TAP6 driver after sufficient testing (when our new approach can get all testing/signing issues fixed, estimated ~4-6 weeks). |
|||
| 85 | - TLS1.3 related patches are acceptable for 2.4.7 if they do not change existing behavior (unless you use `--tls-ciphersuite`). |
|||
| 86 | ||||
| 87 | ### T-Shirts |
|||
| 88 | ||||
| 89 | - are buggy |
|||
| 90 | - 30 day refund policy |
|||
| 91 | ||||
| 92 | ### features in 2.5 that we want |
|||
| 93 | ||||
| 94 | The following is what was discussed in terms of "2.5 release" during the hackathon, but for a more schematic status report about 2.5, please check [this link](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn25) |
|||
| 95 | ||||
| 96 | - we have a page in the wiki so people can read up on this |
|||
| 97 | - MSI packaging (Simon, Samuli) //must have// |
|||
| 98 | - tls-cryptv2 //must have// |
|||
| 99 | - Antonio is reviewing, goal: this weekend |
|||
| 100 | - IPv6-only //really nice to have// |
|||
| 101 | - client side is already finished(!) |
|||
| 102 | - server side needs brains to closely check disentanglement of ipv4/ipv6 server pools for unexpected side effects |
|||
| 103 | - Gert needs to finish review and test bed |
|||
| 104 | - netlink / sitnl refactoring of tun.c, route.c //must have/ |
|||
| 105 | - Arne volunteers to review, but is entangled in ipv6-only changes (so might need rebasing) -> Antonio to check |
|||
| 106 | - code is there, but needs better coordination |
|||
| 107 | - blocker |
|||
| 108 | - transport plugin (obfuscation or others) //nice to have// |
|||
| 109 | - operator foundation, founded by google |
|||
| 110 | - coordinating with Antonio |
|||
| 111 | - patches based on 2.4 - asked to rebase on master |
|||
| 112 | - "nice to have"? |
|||
| 113 | - "make VPN fast again" (Antonio) - //nice to have// |
|||
| 114 | - split control/data channel -> separate threads |
|||
| 115 | - "client connect" activity will no longer interfere with "forwarding packets for other clients" |
|||
| 116 | - going from there to multiple workers for data channel |
|||
| 117 | - "all the complicated event handling" -> control thread |
|||
| 118 | - send/receive multi-messages |
|||
| 119 | - use tun driver more efficiently |
|||
| 120 | - tap6 on server 2016 - maybe slow because driver reports attributes wrongly? |
|||
| 121 | - initial connect speed of 2.x clients compared to 3.x clients |
|||
| 122 | - there is one "1 second" coarse timer left in the 2.x code base |
|||
| 123 | - Gert and Steffan did not dare to remove this one yet |
|||
| 124 | - OpenVPN3 offload API? |
|||
| 125 | - ongoing activity... |
|||
| 126 | - VLAN patchset //must have// |
|||
| 127 | - Antonio volunteers to rebase + adjust the code to master |
|||
| 128 | - Arne volunteers to review |
|||
| 129 | - Gert to build test infrastructure |
|||
| 130 | - David: suggest to checkout the code tree "right before the uncrustify changes", apply Fabian's v2 patch set, and proceed from there |
|||
| 131 | - asynchronous client-connect (?) patchset from Fabian Kittel - //must have// |
|||
| 132 | - Gert/Arne/Antonio |
|||
| 133 | - multi-listen / multi-port / multi-ip patch set |
|||
| 134 | - multi-port is done, with multi-ip (if same protocol) (first chunk) "in beta" //must have// |
|||
| 135 | - multi-protocol (TCP+UDP) "not even alpha" //postpone to 2.6, too early code// |
|||
| 136 | - Arne feels like he needs to review this |
|||
| 137 | - dynamic-route (routes in CCD/) |
|||
| 138 | - today: OpenVPN only adds route at startup |
|||
| 139 | - adding routes at client-connect time needs to be done "outside" |
|||
| 140 | - //nice to have(!!)// - it can be done with `--client-connect` or in plugin code - but easier debugged if "built in" |
|||
| 141 | - enable `--enable-async-push` by default |
|||
| 142 | - it is tested fairly well now |
|||
| 143 | - get rid of extra #ifdef |
|||
| 144 | - cross-platform - today this depends on inotify, which is not available on most platforms we support (Linux, maybe FreeBSD, nothing else) |
|||
| 145 | - David pushed out a new build enabling this by default for [Fedora Rawhide](https://koji.fedoraproject.org/koji/buildinfo?buildID=1150556) (future Fedora 30) and [Fedora 29](https://bodhi.fedoraproject.org/updates/openvpn-2.4.6-3.fc29) |
|||
| 146 | - OpenSolaris: fix fragment handling for IPv4 - ***done*** |
|||
| 147 | - IPv6 fragments over tun work, IPv4 fragments not |
|||
| 148 | - not an OpenVPN problem, but combination of OpenSolaris, FreeBSD pf(4) and `scrub in all` without the `no-df` flag triggered this |
|||
| 149 | - AIX: tunnel emulation //nice to have// |
|||
| 150 | - AIX has no tun interface, only tap |
|||
| 151 | - to talk to "have no tap interface, only tun" peers, one side needs to emulate |
|||
| 152 | - AIX code nearly done, waiting for ICMPv6 generation code in OpenVPN 2.x code to show up (block-ipv6 v4) |
|||
| 153 | - `--opt-verify` handling |
|||
| 154 | - remove it from the AS config default ("it breaks clients") |
|||
| 155 | - the way it is now is not really needed anymore - most option mismatches can be pushed from the server, except for the caveats... |
|||
| 156 | - make all the `--*mtu*` things pushable (not easy: reallocation of buffers needed) |
|||
| 157 | - include "more sane ciphers" in the default NCP cipherlist (Arne, Steffan) |
|||
| 158 | - what else? |
|||
| 159 | ||||
| 160 | ### features we want in 2.6 |
|||
| 161 | - asynchronous netlink (= do not block waiting for kernel ACK) |
|||
| 162 | - performance enhancements on multi-CPU machines |
|||
| 163 | - multithreading? Do we want to just go for 3.0 here? |
