)]}'
{"id":"openvpn~1683","triplet_id":"openvpn~master~I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f","project":"openvpn","branch":"master","full_branch":"refs/heads/master","attention_set":{},"removed_from_attention_set":{"1000007":{"account":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"last_update":"2026-09-28 14:28:26.000000000","reason":"Change was submitted"},"1000053":{"account":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"last_update":"2026-09-28 11:35:10.000000000","reason":"removed on reply"},"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-28 14:28:26.000000000","reason":"Change was submitted"},"1000001":{"account":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-09-28 14:28:26.000000000","reason":"Change was submitted"}},"hashtags":["mailsubmitted"],"change_id":"I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f","subject":"dco: remove iroute at client exit time instead of delayed exit","status":"MERGED","created":"2026-05-20 08:23:36.000000000","updated":"2026-09-28 14:28:26.000000000","submitted":"2026-09-28 14:28:26.000000000","submitter":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":7,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1683","meta_rev_id":"3e007cef37a5d02f8949fa7e2244ff895610f07b","_number":1683,"virtual_id_number":1683,"owner":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},{"value":0,"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-20 08:23:37.000000000","updated_by":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"real_updated_by":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-05-20 08:23:37.000000000","updated_by":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"real_updated_by":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-05-21 11:23:49.000000000","updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"real_updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"},{"updated":"2026-09-10 09:01:21.000000000","updated_by":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"real_updated_by":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"REVIEWER"}],"messages":[{"id":"4fcbf646169df32da4c670ddd44a206499df01e5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-20 08:23:36.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"0de1e4cfee17a48239272895b0db8c8f5b256205","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-20 08:54:27.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"6b20487e1b3fd8113b9e6bd56bef8f9c58a9480e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-20 20:21:53.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"c5b335ce0ea483f424cd4661b428f3dd07c00fda","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-21 10:06:43.000000000","message":"Uploaded patch set 4: Commit message was updated.","accounts_in_message":[],"_revision_number":4},{"id":"9c1cdf5de9ed4f7562c53afd1f28cb2dabba67cf","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-05-21 11:23:49.000000000","message":"Patch Set 4: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"e473e9d6331733e07772e9459fad9b772b7dff46","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-21 12:15:32.000000000","message":"Patch Set 4:\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"bfa0bb629e05904dabe8c4542d92e3f75382e653","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-21 13:52:50.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":5},{"id":"b184619179cb0400f7508b19a4b84ac4f5c11100","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-05-21 13:53:30.000000000","message":"Patch Set 4:\n\n(3 comments)","accounts_in_message":[],"_revision_number":4},{"id":"e5101505b0198c5a70cc00c5021d4439d8833820","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-08 20:25:42.000000000","message":"Patch Set 5: Code-Review+2","accounts_in_message":[],"_revision_number":5},{"id":"0bfa51b7c896fa610bf2795255d1f2a027d2f8a8","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-08 15:27:04.000000000","message":"Hashtag added: mailsubmitted","accounts_in_message":[],"_revision_number":5},{"id":"c07f6cde7f13718f87a1ae1c8c28589895fcd2a3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-09-10 08:22:43.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":6},{"id":"12197f387abb37a609fdc46152f2093133111dde","author":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-09-10 09:01:21.000000000","message":"Patch Set 6: Code-Review+2","accounts_in_message":[],"_revision_number":6},{"id":"d49de48194e9a99cf88fbebe0653c4a54ed88118","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-09-28 11:28:23.000000000","message":"Uploaded patch set 7.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":7},{"id":"acd5229477e1b0afeb1e5d1ba348d3f7af22dd34","author":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-09-28 11:35:10.000000000","message":"Patch Set 7: Code-Review+2","accounts_in_message":[],"_revision_number":7},{"id":"3e007cef37a5d02f8949fa7e2244ff895610f07b","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-28 14:28:26.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":8}],"current_revision_number":8,"current_revision":"2f76d3aac55a5347273013d60eb86aa17c8b8941","revisions":{"63dad7001bf173d7068cbb215f9a596ab2a75ea8":{"kind":"REWORK","_number":1,"created":"2026-05-20 08:23:36.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f5af8cfaeaee954ba4a81d3dd3e571e030bf2d00","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:23:17.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a exits (because it sent an EEN or because it\u0027s connection\ntimed out) OpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects and a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) OpenVPN\nwill:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"690581f8d5e83e8cc92f2bd06b43f8785d30ce50":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-05-20 08:54:27.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"c5f02a68b6036a8c30e5e81704b1ffa417b26d83","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:54:20.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a exits (because it sent an EEN or because it\u0027s connection\ntimed out) OpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects and a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) OpenVPN\nwill:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"d7ce722dd34d46f2408819ead24e0e5c6490fde5":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-05-20 20:21:53.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"913767cf436841f1e605089e1b7c2ba5021a335c","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 20:21:35.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a exits (because it sent an EEN or because it\u0027s connection\ntimed out) OpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects and a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) OpenVPN\nwill:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"6ba94fe192fc58331f740bae631c15ab08827439":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2026-05-21 10:06:43.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"913767cf436841f1e605089e1b7c2ba5021a335c","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-21 09:57:06.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a exits (because it sent an EEN or because it\u0027s connection\ntimed out) OpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects and a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) OpenVPN\nwill:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nGitHub: closes openvpn/OpenVPN#1040\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"a6f3f92a7bd0ef1c026f5ebe7684f9494cf2deb1":{"kind":"REWORK","_number":5,"created":"2026-05-21 13:52:50.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/5","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/5","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"913767cf436841f1e605089e1b7c2ba5021a335c","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-21 13:48:51.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a client exits due to one of the following reasons:\n* EEN received\n* AUTH_FAILED sent\n* RESTART sent\nOpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects, a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) and the\nsame IP is assigned, then OpenVPN will:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nNote that this issue is DCO specific, because without DCO OpenVPN\ncreates virtual routes (no system routing table involved) and makes\nthe last connecting client own them.\nThis means that the delayed exit routine won\u0027t have any iroute to\ndelete.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nGitHub: closes openvpn/OpenVPN#1040\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"162d13467d7eb9df027f1d6b3bd8b21257f8bc71":{"kind":"REWORK","_number":6,"created":"2026-09-10 08:22:43.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/6","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/6","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8559184d4d69311300b093095358ddbf4346b90a","subject":"multi/dco: simplify dco_delete_iroutes call chain"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-09-10 08:14:59.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a client exits due to one of the following reasons:\n* EEN received\n* AUTH_FAILED sent\n* RESTART sent\nOpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects, a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) and the\nsame IP is assigned, then OpenVPN will:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nNote that this issue is DCO specific, because without DCO OpenVPN\ncreates virtual routes (no system routing table involved) and makes\nthe last connecting client own them.\nThis means that the delayed exit routine won\u0027t have any iroute to\ndelete.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nGitHub: closes openvpn/OpenVPN#1040\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"569eaffaf9d78054eb750d1f32982ae90fd2a75d":{"kind":"REWORK","_number":7,"created":"2026-09-28 11:28:23.000000000","uploader":{"_account_id":1000007,"name":"Antonio Quartulli","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/83/1683/7","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/7","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0702ff8e2945f8615f67c0dfc03e5a013567b3f8","subject":"buffer: make buf_valid() and buf_defined() NULL-safe"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-20 08:10:56.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-09-28 11:09:22.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a client exits due to one of the following reasons:\n* EEN received\n* AUTH_FAILED sent\n* RESTART sent\nOpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects, a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) and the\nsame IP is assigned, then OpenVPN will:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nNote that this issue is DCO specific, because without DCO OpenVPN\ncreates virtual routes (no system routing table involved) and makes\nthe last connecting client own them.\nThis means that the delayed exit routine won\u0027t have any iroute to\ndelete.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nGitHub: closes openvpn/OpenVPN#1040\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"2f76d3aac55a5347273013d60eb86aa17c8b8941":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":8,"created":"2026-09-28 14:28:26.000000000","uploader":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/83/1683/8","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/83/1683/8","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8 \u0026\u0026 git checkout -b change-1683 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/83/1683/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"459fcbb252b9c9781d2807f4d44dbfd758a26afa","subject":"dco: stop fetching peer stats during client disconnect"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-09-28 11:37:18.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-09-28 13:29:43.000000000","tz":120},"subject":"dco: remove iroute at client exit time instead of delayed exit","message":"dco: remove iroute at client exit time instead of delayed exit\n\nWhen a client exits due to one of the following reasons:\n* EEN received\n* AUTH_FAILED sent\n* RESTART sent\nOpenVPN will perform some minimal cleanup and will\nthen postpone the actual instance purge by 5 seconds.\n\nIf iroutes are configured for the exiting client, the actual DCO\niroutes removal is also postponed.\n\nIf during this time window the same client reconnects, a new\ninstance is created (for example because --duplicate-cn is set or\nbecause the same username is provided upon authentication) and the\nsame IP is assigned, then OpenVPN will:\n\n* create the new client instance;\n* attempt adding the related DCO iroutes (which will fail because\n  EEXIST);\n* 5 seconds timeout fires -\u003e execute the delayed exit routine and\n  delete the DCO iroutes;\n* no iroutes exists anymore on the server despite the client being\n  fully connected.\n\nNote that this issue is DCO specific, because without DCO OpenVPN\ncreates virtual routes (no system routing table involved) and makes\nthe last connecting client own them.\nThis means that the delayed exit routine won\u0027t have any iroute to\ndelete.\n\nWith this patch we move the DCO iroutes deletion to the actual\nclient exit time in order to avoid racing with a possible addition\nbeing executed when the client reconnects. The new flow will be:\n\n* client exits (due to EEN or timeout)\n* DCO iroutes are immediately deleted\n* client re-connects -\u003e new instance created\n* DCO iroutes are added -\u003e SUCCESS\n* 5 seconds timeout fires -\u003e old instance client is fully purged\n* client is connected and iroutes are in place as expected\n\nThis issue was reported by OpenVPN Access Server developers after\nobserving erratic iroutes disappearance with DCO in place.\n\nChange-Id: I0ba723d12d433e6e020588b7b0c3ba10bcf8c44f\nGitHub: closes openvpn/OpenVPN#1040\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\nAcked-by: Razvan Cojocaru \u003crazvanc@mailbox.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1683\nMessage-Id: \u003c20260928113726.32340-1-gert@greenie.muc.de\u003e\nURL: https://lore.kernel.org/openvpn-devel/20260928113726.32340-1-gert@greenie.muc.de/T/#u\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[]}
