Skip to content

Commit 7ac5f89

Browse files
itsGiaancron2
authored andcommitted
socket: restore per-connection lport override over global default
OpenVPN 2.7.x introduced a regression where --lport specified inside a <connection> block did not override a globally defined local port. As a result, the socket was bound to the global default port instead of the per-connection value. Adjust the socket local_port selection logic to honour local_port_defined when set for the active connection profile. This change restores the documented and previously working behaviour from 2.6.x, where connection-level lport takes precedence over global defaults. Github: closes #995 Change-Id: I7cf5d5ef7e2531f397ad97baf4663e3763072f6b Signed-off-by: Gianmarco De Gregori <gianmarco@mandelbit.com> Acked-by: Antonio Quartulli <antonio@mandelbit.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1555 Message-Id: <20260316134841.28362-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg36164.html Signed-off-by: Gert Doering <gert@greenie.muc.de>
1 parent 690aace commit 7ac5f89

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

src/openvpn/socket.c

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1357,6 +1357,13 @@ link_socket_init_phase1(struct context *c, int sock_index, int mode)
13571357
proto = o->ce.proto;
13581358
}
13591359

1360+
/* If --lport is specified in a client connection block,
1361+
* it takes precedence over the global setting. */
1362+
if (o->mode == MODE_POINT_TO_POINT && o->ce.local_port_defined)
1363+
{
1364+
port = o->ce.local_port;
1365+
}
1366+
13601367
if (c->mode == CM_CHILD_TCP || c->mode == CM_CHILD_UDP)
13611368
{
13621369
struct link_socket *tmp_sock = NULL;

0 commit comments

Comments
 (0)