)]}'
{"id":"openvpn~1702","triplet_id":"openvpn~master~I2df0fec786184b9fcf9b7c56c74816325cdb6942","project":"openvpn","branch":"master","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-06-10 16:48:45.000000000","reason":"Change was submitted"},"1000034":{"account":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"last_update":"2026-06-10 16:48:45.000000000","reason":"Change was submitted"},"1000002":{"account":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"last_update":"2026-06-09 07:53:59.000000000","reason":"removed on reply"},"1000007":{"account":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"last_update":"2026-06-09 07:42:34.000000000","reason":"Reviewer/Cc was removed"}},"hashtags":[],"change_id":"I2df0fec786184b9fcf9b7c56c74816325cdb6942","subject":"mudp: send HMAC reset reply synchronously","status":"MERGED","created":"2026-05-22 13:18:00.000000000","updated":"2026-06-10 16:48:45.000000000","submitted":"2026-06-10 16:48:45.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":4,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1702","meta_rev_id":"0bb1c694ee1756f12d447cbda2a18e17528e796d","_number":1702,"virtual_id_number":1702,"owner":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-22 13:18:00.000000000","updated_by":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"reviewer":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"state":"REVIEWER"},{"updated":"2026-05-22 13:18:01.000000000","updated_by":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-05-22 13:18:01.000000000","updated_by":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-06-09 07:26:43.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"state":"REVIEWER"},{"updated":"2026-06-09 07:42:34.000000000","updated_by":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"reviewer":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"state":"CC"},{"updated":"2026-06-09 08:52:44.000000000","updated_by":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"state":"REVIEWER"},{"updated":"2026-06-10 16:48:45.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"state":"CC"}],"messages":[{"id":"3109b3e627541b2ef8e3d34255cc41eab7d5e8a5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"date":"2026-05-22 13:18:00.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5eb4c44cdde78d5c64fbfb429f9cce2b4f68a467","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-07 21:17:33.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"9123f489f7e44a1b3b282ae0062f9e0802d3c1c6","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-09 07:26:43.000000000","message":"Patch Set 1: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"f6e0d541295f3d1b9b82cab03ed5f5687f05a2c7","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-09 07:30:57.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"b646c3cf056be032df9ea68f161a986f03890f1c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"date":"2026-06-09 07:42:34.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review+2, Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"34fca11bb5bd474b9f65a3b305e32065b014d57c","author":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"date":"2026-06-09 07:43:33.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"2479b81e679e26a8a745dd44a9bf14bd643fa9dd","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-09 07:53:59.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"43ebe2e93ac422c16854f172764d23dc9becadad","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-06-09 08:52:44.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"0bb1c694ee1756f12d447cbda2a18e17528e796d","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-10 16:48:45.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"9bad30f6d9884d48db57106ce078bfd7b2a73df9","revisions":{"813856dba54347167bcd041b67ed831479cf37b7":{"kind":"REWORK","_number":1,"created":"2026-05-22 13:18:00.000000000","uploader":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"ref":"refs/changes/02/1702/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1702/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1 \u0026\u0026 git checkout -b change-1702 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2b8afc6c685f4e451fd0fa5aa37f18147520dfc1","subject":"openvpnserv: always use W variant of RpcStringFree()"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-22 09:25:47.000000000","tz":120},"committer":{"name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","date":"2026-05-22 11:01:18.000000000","tz":120},"subject":"mudp: send HMAC reset reply synchronously","message":"mudp: send HMAC reset reply synchronously\n\nBuilding a HARD_RESET reply was queueing the result into three\nmulti_context fields and deferring the send to the next event-loop\niteration, where multi_process_outgoing_link() flushed it:\n\n  struct buffer hmac_reply;\n  struct link_socket_actual *hmac_reply_dest;  /* aliased \u0026m-\u003etop.c2.from */\n  struct link_socket *hmac_reply_ls;\n\nThe mechanism had three latent issues:\n\n1. hmac_reply_dest \u003d \u0026m-\u003etop.c2.from stored a pointer alias into\n   shared mutable state.  Any subsequent read into m-\u003etop.c2.from\n   silently retargeted the pending reply to a different peer.\n2. m-\u003ehmac_reply_ls \u003d sock; at the top of multi_get_create_instance_udp()\n   was executed unconditionally for every UDP packet, including packets\n   that did not queue a reply.  A stale queued reply could thus be sent\n   on the wrong listening socket.\n3. hmac_reply.data pointed into m-\u003etop.c2.buffers-\u003eaux_buf (the only\n   slot).  A second send_hmac_reset_packet() before the first flush\n   would overwrite the first reply\u0027s bytes.\n\nThese were latent on master because m-\u003emulti_io-\u003eudp_flags was consumed\nand zeroed by the first event in each multi_io_process_io() loop, so at\nmost one UDP read ran per outer iteration.\n\nSend the reply synchronously from within send_hmac_reset_packet() using\nthe sock that the read fired on (threaded through do_pre_decrypt_check).\nThe reply is small, stateless, and rate-limited by the existing\nreflect_filter_rate_limit_check(); dropping on EAGAIN is acceptable\nbecause the client retransmits its HARD_RESET.  The three multi_context\nfields and the deferred-flush block in multi_process_outgoing_link() are\ngone; p2mp_iow_flags() no longer needs an IOW_TO_LINK branch for hmac\nstate.\n\nChange-Id: I2df0fec786184b9fcf9b7c56c74816325cdb6942\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"9bb6c3cf8378bba2bd4c7ae2495f6882de92cd95":{"kind":"REWORK","_number":2,"created":"2026-06-09 07:42:34.000000000","uploader":{"_account_id":1000034,"name":"its_Giaan","display_name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","username":"its_Giaan"},"ref":"refs/changes/02/1702/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1702/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2 \u0026\u0026 git checkout -b change-1702 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"a71e8508f93f6ea19841779e42b9d60561613195","subject":"dev-tools: Fix run-cppcheck to cover more code"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-05-22 09:25:47.000000000","tz":120},"committer":{"name":"Gianmarco De Gregori","email":"gianmarco@mandelbit.com","date":"2026-06-09 07:39:36.000000000","tz":120},"subject":"mudp: send HMAC reset reply synchronously","message":"mudp: send HMAC reset reply synchronously\n\nBuilding a HARD_RESET reply was queueing the result into three\nmulti_context fields and deferring the send to the next event-loop\niteration, where multi_process_outgoing_link() flushed it:\n\n  struct buffer hmac_reply;\n  struct link_socket_actual *hmac_reply_dest;  /* aliased \u0026m-\u003etop.c2.from */\n  struct link_socket *hmac_reply_ls;\n\nThe mechanism had three latent issues:\n\n1. hmac_reply_dest \u003d \u0026m-\u003etop.c2.from stored a pointer alias into\n   shared mutable state.  Any subsequent read into m-\u003etop.c2.from\n   silently retargeted the pending reply to a different peer.\n2. m-\u003ehmac_reply_ls \u003d sock; at the top of multi_get_create_instance_udp()\n   was executed unconditionally for every UDP packet, including packets\n   that did not queue a reply.  A stale queued reply could thus be sent\n   on the wrong listening socket.\n3. hmac_reply.data pointed into m-\u003etop.c2.buffers-\u003eaux_buf (the only\n   slot).  A second send_hmac_reset_packet() before the first flush\n   would overwrite the first reply\u0027s bytes.\n\nThese were latent on master because m-\u003emulti_io-\u003eudp_flags was consumed\nand zeroed by the first event in each multi_io_process_io() loop, so at\nmost one UDP read ran per outer iteration.\n\nSend the reply synchronously from within send_hmac_reset_packet() using\nthe sock that the read fired on (threaded through do_pre_decrypt_check).\nThe reply is small, stateless, and rate-limited by the existing\nreflect_filter_rate_limit_check(); dropping on EAGAIN is acceptable\nbecause the client retransmits its HARD_RESET.  The three multi_context\nfields and the deferred-flush block in multi_process_outgoing_link() are\ngone; p2mp_iow_flags() no longer needs an IOW_TO_LINK branch for hmac\nstate.\n\nChange-Id: I2df0fec786184b9fcf9b7c56c74816325cdb6942\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"9bad30f6d9884d48db57106ce078bfd7b2a73df9":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":3,"created":"2026-06-10 16:48:45.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/02/1702/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1702/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3 \u0026\u0026 git checkout -b change-1702 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/02/1702/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0d7ea983e4c92d4c2caf5077ed8e868744c72512","subject":"Fix: port-share and multi-socket interaction"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-06-09 07:54:07.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-10 16:25:49.000000000","tz":120},"subject":"mudp: send HMAC reset reply synchronously","message":"mudp: send HMAC reset reply synchronously\n\nBuilding a HARD_RESET reply was queueing the result into three\nmulti_context fields and deferring the send to the next event-loop\niteration, where multi_process_outgoing_link() flushed it:\n\n  struct buffer hmac_reply;\n  struct link_socket_actual *hmac_reply_dest;  /* aliased \u0026m-\u003etop.c2.from */\n  struct link_socket *hmac_reply_ls;\n\nThe mechanism had three latent issues:\n\n1. hmac_reply_dest \u003d \u0026m-\u003etop.c2.from stored a pointer alias into\n   shared mutable state.  Any subsequent read into m-\u003etop.c2.from\n   silently retargeted the pending reply to a different peer.\n2. m-\u003ehmac_reply_ls \u003d sock; at the top of multi_get_create_instance_udp()\n   was executed unconditionally for every UDP packet, including packets\n   that did not queue a reply.  A stale queued reply could thus be sent\n   on the wrong listening socket.\n3. hmac_reply.data pointed into m-\u003etop.c2.buffers-\u003eaux_buf (the only\n   slot).  A second send_hmac_reset_packet() before the first flush\n   would overwrite the first reply\u0027s bytes.\n\nThese were latent on master because m-\u003emulti_io-\u003eudp_flags was consumed\nand zeroed by the first event in each multi_io_process_io() loop, so at\nmost one UDP read ran per outer iteration.\n\nSend the reply synchronously from within send_hmac_reset_packet() using\nthe sock that the read fired on (threaded through do_pre_decrypt_check).\nThe reply is small, stateless, and rate-limited by the existing\nreflect_filter_rate_limit_check(); dropping on EAGAIN is acceptable\nbecause the client retransmits its HARD_RESET.  The three multi_context\nfields and the deferred-flush block in multi_process_outgoing_link() are\ngone; p2mp_iow_flags() no longer needs an IOW_TO_LINK branch for hmac\nstate.\n\nChange-Id: I2df0fec786184b9fcf9b7c56c74816325cdb6942\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\nAcked-by: Gert Doering \u003cgert@greenie.muc.de\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1702\nMessage-Id: \u003c20260609075413.17380-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg37117.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
