Blame

9ea8ff Samuli Seppänen 2025-01-29 07:28:13 1
# OpenVPN Hackathon 2018
2
3
This year's hackathon is organized by Andriy Revin and David Sommerseth
4
5
We will stick to the format of the previous years, which means attendance is in principle limited to "active developers that are also regularly contributing to #openvpn-devel or the mailing list". We should have enough space in the meeting room for 10-14 devs.
6
7
## Who is coming?
8
9
| Name | Topics | Arrival | Departure | Hotel |
10
|------|--------|---------|-----------|-------|
11
| Andriy Revin | - | - | - | @home |
12
| David Sommerseth | clean-ups, plug-ins, OpenVPN 3 client | Thu evening (LO482/LO763) | Tue (LO766/LO483) | Ibis |
13
| Antonio Quartulli | remaining IPv6-only work, VLAN patches, netlink, multi-socket/multi-protocol, transport API(?) | Fri | Tue | Ibis |
14
| Steffan Karger | Performance, clean ups, crypto stuff | Thu (OS381, ETA 15:20 @ airport) | Sun | Ibis |
15
| Gert Döring | VLAN Patches / Architecture, Challenge / Plugin stuff, Performance (Threading?) | Fri (LH2550, ETA 11:30 @airport) | Mon (LH2551) | Ibis |
16
| Samuli Seppänen | Packaging (MSI, DEB, RPM), !HackerOne tuning | Fri late evening | Mon early morning | Ibis |
17
| James Yonan | - | - | - | - |
18
| Arne Schwabe | random stuff | Thu (LO410/LO765) | Tue (LO766/LO407) | Ibis |
19
| Johan Draaisma | things | 3 oct | 8 oct | somewhere |
20
| Lev Stipakov | things | Fri evening (TK443) | Tue | Ibis |
21
22
## Where?
23
24
The meeting is held at the OpenVPN office in Lviv (Ukraine): [Shevchenka Ave 5](https://www.openstreetmap.org/search?query=49.83826%2C24.03129#map=19/49.83826/24.03129&layers=N).
25
26
Lviv Danylo Halytskyi International Airport is quite close to the city. Best way of public transport is via Uber.
27
28
If you have any questions - please contact Andriy Revin (andriy @ openvpn.net).
29
30
## When?
31
32
The hackathon will take place from Friday October 5th 2018 to Sunday October 7th.
33
34
## What?
35
36
1. What features do we want in 2.5? Set the timeline accordingly.
37
- tls-crypt v2, sitnl, vlan patches, ipv6-only, transport plug-in?
38
- MSI packaging?
39
- EasyRSA 3 for Windows (NSIS/MSI) installers?
40
- **conclusion:** [check here](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant)
41
42
2. Should OpenVPN be a "swiss army knife" or "secure vpn client for dummies"
43
- Could the split between OpenVPN 2.x and 3.x reflect these two roles?
44
- **conclusion:** making OpenVPN 2.x a simple client for dummies is not a priority, but devs will try to reduce complexity by removing as many ifdefs as possible and by reviewing options whenever it is possible.
45
46
3. Feature changes
47
- Do we need `--opt-verify`? Is this a feature strictly needed these days?
48
- **conclusion:** check last item in the [2.5 discussion section](https://community.openvpn.net/openvpn/wiki/LvivHackathon2018#featuresin2.5thatwewant)
49
50
4. MSI packaging
51
- Available for testing for tap-windows6, but not yet for OpenVPN 2
52
- **conclusion:** get MSI packaging working with 2.5 (NSIS will be dropped)
53
54
## Input
55
56
TBD
57
58
## Internet
59
60
Free wifi network is available at the office
61
62
## Accommodation
63
64
There are many options with hotels and Airbnb alternatives in walking distance from the office (5-10 minutes). Most reasonably priced hotels are fairly small and availability is varying a lot, but double check against hotels.com, booking.com, trivago.com or similar sites to ensure you get a good price.
65
66
Some hotels close by (4-8 minutes walk):
67
68
| Hotel | URL | Comments |
69
|-------|-----|----------|
70
| Ibis Styles Lviv Center | [Link](https://www.accorhotels.com/gb/hotel-9709-ibis-styles-lviv-center/index.shtml) | Most likely one of the bigger ones, small rooms but decent |
71
| Swiss Hotel | [Link](http://swiss-hotel.lviv.ua/en/) | Reasonable hotel when getting good price offers |
72
| ANTARES Apart hotel | [Link](https://antares-apart.com.ua/en/) | - |
73
| Danylo Inn | [Link](http://www.danyloinn.com/) | - |
74
75
## Results
76
77
(informal notes on some of the discussions that benefit from writing down)
78
79
### 2.4.7
80
81
- We need to do a 2.4.7 release "soonish", to fix the `--opt-verify` issue Lev and Johan have encountered with NCP (patch has been merged in master+release/2.4).
82
- We want the "asymmetric compression" change from Arne in there.
83
- The `--allow-compression` option will be added which forcefully allows the local side to send compressed data. The current patch will be updated to **not** allow this new option to be pushable. We will require this to be explicitly set in the configuration file on both sides to enable compression.
84
- 2.4.7 will be initially released with the old TAP6 driver, and then we can do a re-release with the new TAP6 driver after sufficient testing (when our new approach can get all testing/signing issues fixed, estimated ~4-6 weeks).
85
- TLS1.3 related patches are acceptable for 2.4.7 if they do not change existing behavior (unless you use `--tls-ciphersuite`).
86
87
### T-Shirts
88
89
- are buggy
90
- 30 day refund policy
91
92
### features in 2.5 that we want
93
94
The following is what was discussed in terms of "2.5 release" during the hackathon, but for a more schematic status report about 2.5, please check [this link](https://community.openvpn.net/openvpn/wiki/StatusOfOpenvpn25)
95
96
- we have a page in the wiki so people can read up on this
97
- MSI packaging (Simon, Samuli) //must have//
98
- tls-cryptv2 //must have//
99
- Antonio is reviewing, goal: this weekend
100
- IPv6-only //really nice to have//
101
- client side is already finished(!)
102
- server side needs brains to closely check disentanglement of ipv4/ipv6 server pools for unexpected side effects
103
- Gert needs to finish review and test bed
104
- netlink / sitnl refactoring of tun.c, route.c //must have/
105
- Arne volunteers to review, but is entangled in ipv6-only changes (so might need rebasing) -> Antonio to check
106
- code is there, but needs better coordination
107
- blocker
108
- transport plugin (obfuscation or others) //nice to have//
109
- operator foundation, founded by google
110
- coordinating with Antonio
111
- patches based on 2.4 - asked to rebase on master
112
- "nice to have"?
113
- "make VPN fast again" (Antonio) - //nice to have//
114
- split control/data channel -> separate threads
115
- "client connect" activity will no longer interfere with "forwarding packets for other clients"
116
- going from there to multiple workers for data channel
117
- "all the complicated event handling" -> control thread
118
- send/receive multi-messages
119
- use tun driver more efficiently
120
- tap6 on server 2016 - maybe slow because driver reports attributes wrongly?
121
- initial connect speed of 2.x clients compared to 3.x clients
122
- there is one "1 second" coarse timer left in the 2.x code base
123
- Gert and Steffan did not dare to remove this one yet
124
- OpenVPN3 offload API?
125
- ongoing activity...
126
- VLAN patchset //must have//
127
- Antonio volunteers to rebase + adjust the code to master
128
- Arne volunteers to review
129
- Gert to build test infrastructure
130
- David: suggest to checkout the code tree "right before the uncrustify changes", apply Fabian's v2 patch set, and proceed from there
131
- asynchronous client-connect (?) patchset from Fabian Kittel - //must have//
132
- Gert/Arne/Antonio
133
- multi-listen / multi-port / multi-ip patch set
134
- multi-port is done, with multi-ip (if same protocol) (first chunk) "in beta" //must have//
135
- multi-protocol (TCP+UDP) "not even alpha" //postpone to 2.6, too early code//
136
- Arne feels like he needs to review this
137
- dynamic-route (routes in CCD/)
138
- today: OpenVPN only adds route at startup
139
- adding routes at client-connect time needs to be done "outside"
140
- //nice to have(!!)// - it can be done with `--client-connect` or in plugin code - but easier debugged if "built in"
141
- enable `--enable-async-push` by default
142
- it is tested fairly well now
143
- get rid of extra #ifdef
144
- cross-platform - today this depends on inotify, which is not available on most platforms we support (Linux, maybe FreeBSD, nothing else)
145
- David pushed out a new build enabling this by default for [Fedora Rawhide](https://koji.fedoraproject.org/koji/buildinfo?buildID=1150556) (future Fedora 30) and [Fedora 29](https://bodhi.fedoraproject.org/updates/openvpn-2.4.6-3.fc29)
146
- OpenSolaris: fix fragment handling for IPv4 - ***done***
147
- IPv6 fragments over tun work, IPv4 fragments not
148
- not an OpenVPN problem, but combination of OpenSolaris, FreeBSD pf(4) and `scrub in all` without the `no-df` flag triggered this
149
- AIX: tunnel emulation //nice to have//
150
- AIX has no tun interface, only tap
151
- to talk to "have no tap interface, only tun" peers, one side needs to emulate
152
- AIX code nearly done, waiting for ICMPv6 generation code in OpenVPN 2.x code to show up (block-ipv6 v4)
153
- `--opt-verify` handling
154
- remove it from the AS config default ("it breaks clients")
155
- the way it is now is not really needed anymore - most option mismatches can be pushed from the server, except for the caveats...
156
- make all the `--*mtu*` things pushable (not easy: reallocation of buffers needed)
157
- include "more sane ciphers" in the default NCP cipherlist (Arne, Steffan)
158
- what else?
159
160
### features we want in 2.6
161
- asynchronous netlink (= do not block waiting for kernel ACK)
162
- performance enhancements on multi-CPU machines
163
- multithreading? Do we want to just go for 3.0 here?