)]}'
{"id":"openvpn~1727","triplet_id":"openvpn~master~Idb59ecd119331b198792ad1379bec8600211651b","project":"openvpn","branch":"master","topic":"multipeer","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-10 14:20:05.000000000","reason":"\u003cGERRIT_ACCOUNT_1000001\u003e replied on the change","reason_account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}}},"removed_from_attention_set":{"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-08-10 14:20:05.000000000","reason":"\u003cGERRIT_ACCOUNT_1000001\u003e replied on the change","reason_account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}}},"hashtags":[],"change_id":"Idb59ecd119331b198792ad1379bec8600211651b","subject":"Add lookup of multi session by session id","status":"NEW","created":"2026-06-22 13:23:08.000000000","updated":"2026-08-17 11:39:08.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":37,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"b177d6bbec9f13d10f7173ce67e02fe01ea337c8","_number":1727,"virtual_id_number":1727,"owner":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-22 13:23:19.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-06-22 14:03:17.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"}],"messages":[{"id":"2ecf9ce964744ee446b1f6f88103c891ffb31af0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-22 13:23:08.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"92b8562acaa637bd0ec95e40359025d0eddc9dda","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-06-22 14:03:17.000000000","message":"Patch Set 1: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"eeb4e7911d1e4393d85318cba58fbdc0f5930a28","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-22 15:29:40.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"ad763b11d42f06e8a03c37d437b95c4a984ac681","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-22 15:31:08.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"fb3ecd0b1860ba1fab4d792f0a4c319cbade4e0e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-25 13:37:02.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"6b4618739f3cb09b1211ec06646c238950d46563","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-06 12:47:29.000000000","message":"Patch Set 3: Code-Review-2\n\n(10 comments)","accounts_in_message":[],"_revision_number":3},{"id":"3441e3d3513906e4366fa4905ac47f060ad15deb","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-14 13:01:00.000000000","message":"Patch Set 3:\n\n(10 comments)","accounts_in_message":[],"_revision_number":3},{"id":"91847198319338a62a8721a9edd24e9546350369","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-14 13:01:06.000000000","message":"Uploaded patch set 4.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":4},{"id":"f00efcb7a0f54b9c001b7f0e9c191de5337541e8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-17 14:32:28.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":5},{"id":"1ff58817f1678e7de450f556f75bbb02094b24a3","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-17 15:25:24.000000000","message":"Patch Set 5: Code-Review-2\n\n(2 comments)","accounts_in_message":[],"_revision_number":5},{"id":"93f4f02de467bc31a37f30c79b35794251df215f","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-20 10:55:13.000000000","message":"Patch Set 5:\n\n(2 comments)","accounts_in_message":[],"_revision_number":5},{"id":"ed5589f265783341a9cd7ec029f5230cba7cfd8c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-20 11:02:31.000000000","message":"Uploaded patch set 6: New patch set was added with same tree, parent tree, and commit message as Patch Set 5.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"**changekind:NO_CHANGE** OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":6},{"id":"9092922f2e3a20c8f3196c78cff74ec058ea1d55","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-20 12:16:21.000000000","message":"Uploaded patch set 7.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":7},{"id":"b6ad10d493de7f7bdd7638f5bf64827fba2f2ca1","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-22 10:11:58.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"d11953712f02fa69ea5727c6b8e80185f1138e91","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 11:57:38.000000000","message":"Uploaded patch set 8.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":8},{"id":"50a89340292e91e03a671ff4a268dee5c4dd0d29","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 12:38:58.000000000","message":"Uploaded patch set 9: New patch set was added with same tree, parent tree, and commit message as Patch Set 8.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"**changekind:NO_CHANGE** OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":9},{"id":"c075231f32ee24a1f6c92a1bd7ec358c46fac991","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 12:58:42.000000000","message":"Uploaded patch set 10.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":10},{"id":"4d55f9ddc77b03f47251fae6cdc8d187220e305b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 13:27:56.000000000","message":"Uploaded patch set 11.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":11},{"id":"d9054c5ac404dc725bdd21c1324143634d26ca41","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 15:54:26.000000000","message":"Uploaded patch set 12.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":12},{"id":"bdeffe964180be6db4d61634c7672453e983582e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 16:11:36.000000000","message":"Uploaded patch set 13: Patch Set 12 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":13},{"id":"30f9a413054e36626e6c5be05c9c4c35b0c6919c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 16:12:37.000000000","message":"Uploaded patch set 14: Patch Set 13 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":14},{"id":"11586e98024845a381717bb528064316092199e1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-24 16:00:47.000000000","message":"Uploaded patch set 15.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":15},{"id":"bffcef1cd71894e5f005ff0a0fafafe0bf23412a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-24 16:04:03.000000000","message":"Uploaded patch set 16.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":16},{"id":"59590aabf9ea197c45b2fa1ae85f710014674981","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-25 15:13:54.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":17},{"id":"61971e21400a93ea15be0b90f21513d03f27a546","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-25 18:07:35.000000000","message":"Uploaded patch set 18: Patch Set 17 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":18},{"id":"fd037b82098afa67cf10141a37eee4edc1013bac","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-25 18:10:07.000000000","message":"Uploaded patch set 19.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":19},{"id":"815d90f67ccf5aaaaaed0807dd94a690e79fd4ff","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-25 22:06:28.000000000","message":"Uploaded patch set 20: Patch Set 19 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":20},{"id":"40d7718e95125d93b123a11d17934569b1c630ac","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 00:06:29.000000000","message":"Uploaded patch set 21: Patch Set 20 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":21},{"id":"700c010f8aaf33adf9d3124e56adc944723c18ce","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 00:32:37.000000000","message":"Uploaded patch set 22: Patch Set 21 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":22},{"id":"cb0bfda4dea60ede6ad66ac62914c0fb0ab226f3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-27 12:39:42.000000000","message":"Uploaded patch set 23.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":23},{"id":"e7441bf825e9f5ae4dffd99ba9496a5a6790d33a","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-30 11:36:30.000000000","message":"Patch Set 23: -Code-Review","accounts_in_message":[],"_revision_number":23},{"id":"ab7330657fcf37eee3820fc8bc8d9c8e0bc6f015","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-30 12:03:44.000000000","message":"Uploaded patch set 24: Patch Set 23 was rebased.","accounts_in_message":[],"_revision_number":24},{"id":"4894f5a259baa58153249f13d24a065715754812","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-03 13:25:30.000000000","message":"Uploaded patch set 25.","accounts_in_message":[],"_revision_number":25},{"id":"4576ee826355a9407a10c5d6850b4eee82246aef","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-03 14:11:00.000000000","message":"Uploaded patch set 26.","accounts_in_message":[],"_revision_number":26},{"id":"f2ad96d3ed3e793728e30e9b78af4beed21585ab","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-08-07 15:57:10.000000000","message":"Patch Set 26: Code-Review-1\n\n(4 comments)","accounts_in_message":[],"_revision_number":26},{"id":"745126b44dc27fc8a92978e16775aa15322a1778","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-08 21:53:02.000000000","message":"Patch Set 26:\n\n(4 comments)","accounts_in_message":[],"_revision_number":26},{"id":"930733d8f6b5024c44c365e6809e1b2cc0cee9f8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-08 21:53:41.000000000","message":"Uploaded patch set 27.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":27},{"id":"b163739decb32ab68bf17bf1b85531d2ef310b5d","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-08-10 14:20:05.000000000","message":"Patch Set 27:\n\n(1 comment)","accounts_in_message":[],"_revision_number":27},{"id":"96cbc601220159979984832f5fe60de041c1d2f4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-14 11:56:29.000000000","message":"Uploaded patch set 28.","accounts_in_message":[],"_revision_number":28},{"id":"b177d6bbec9f13d10f7173ce67e02fe01ea337c8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-17 11:39:08.000000000","message":"Uploaded patch set 29.","accounts_in_message":[],"_revision_number":29}],"current_revision_number":29,"current_revision":"9849c75f6f4904505c27e85ccf04b1e159dad8d8","revisions":{"43b6031f882d58e4d5b9790c558b913926128399":{"kind":"REWORK","_number":1,"created":"2026-06-22 13:23:08.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"c6be58f905f2caf0c4f8049671b0cf1aad287c28","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-06-22 13:14:54.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"0fefdd1d70ac3f8183ca1d136e37071853a692c1":{"kind":"REWORK","_number":2,"created":"2026-06-22 15:31:08.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"74eff7b260954fa3a0a44e4ae9708104bbe05503","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-06-22 15:30:51.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"3d148280b63a069b8d6879a7d9be7e5175292aa9":{"kind":"REWORK","_number":3,"created":"2026-06-25 13:37:02.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"30112912578226bfe2e750920037a567b6ca5a16","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-06-25 13:36:34.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"8817d14501ae5c247a1e7f4555e3ec3b906c3e2b":{"kind":"REWORK","_number":4,"created":"2026-07-14 13:01:06.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4a81c72f784f0878124a097af3574c29ff185564","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-14 13:00:13.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"2c063aab2095cb86186f395d73a59626431ea289":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-17 14:32:28.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-15 12:17:21.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"cf3148052e5a11b68e1ec066d6e3a2b55a4d6bbe":{"kind":"NO_CHANGE","_number":6,"created":"2026-07-20 11:02:31.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-20 11:02:14.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"f53adb3c21b87136486bc9c926247d68403c9cf5":{"kind":"REWORK","_number":7,"created":"2026-07-20 12:16:21.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-20 12:16:10.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"9ec070a5ba0cb3f0e9d5d720c38bd3db87ba3b98":{"kind":"REWORK","_number":8,"created":"2026-07-23 11:57:38.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/8","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/8","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 11:57:26.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"50c1d2aaff2913f21d159d731aeb81599db5c945":{"kind":"NO_CHANGE","_number":9,"created":"2026-07-23 12:38:58.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/9","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/9","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 12:38:47.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"ac19d4729d3bec678125c6ea0ecc926148f3b23e":{"kind":"REWORK","_number":10,"created":"2026-07-23 12:58:42.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/10","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/10","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 12:58:10.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"fa465621a14140c1d1cffb65114be695d50831dc":{"kind":"REWORK","_number":11,"created":"2026-07-23 13:27:56.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/11","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/11","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 13:27:51.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"1900bdaf8c3648886bdd555461c7d072801d2569":{"kind":"REWORK","_number":12,"created":"2026-07-23 15:54:26.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/12","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/12","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d501861ad4ca12f7c402c999e914430ee48fc480","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 15:54:10.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"b8abb3e8a30147ce72f8195693f4aec738b0140f":{"kind":"TRIVIAL_REBASE","_number":13,"created":"2026-07-23 16:11:36.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/13","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/13","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"65b380fdcf4dd4fd5302ab4d10c276b5952e8244","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 16:11:20.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"f7758df953af7137e16bfca6638f5036000c2ca7":{"kind":"TRIVIAL_REBASE","_number":14,"created":"2026-07-23 16:12:37.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/14","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/14","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"020ad887d34077178ef9cbbbc6a76c002917be45","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 16:12:33.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"7396ad095d0877c856abc55fd06db2b6d477ff13":{"kind":"REWORK","_number":15,"created":"2026-07-24 16:00:47.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/15","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/15","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f2ad40cf8e34868e24609fd4d4016a77fecea015","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-24 16:00:43.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"fb8c590e8cf3bedd704dc4b47bb177a09f696dc6":{"kind":"REWORK","_number":16,"created":"2026-07-24 16:04:03.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/16","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/16","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6a4d86dc51bebf4f52ae01b0cec91f5fb0c37e01","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-24 16:03:34.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"4510ef61dc1a33c84da219ee638dc692be9cf5a2":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-07-25 15:13:54.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/17","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/17","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0d48b26515bf754c61f8aebbcfe19b5b11970e80","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-25 15:13:48.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"da8c2293ad20b76c4e8042781c2059be4b020bae":{"kind":"TRIVIAL_REBASE","_number":18,"created":"2026-07-25 18:07:35.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/18","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/18","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9f3537e0de29f10eed02d180fe5321d244d139f4","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-25 18:07:31.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"09f7d25470b139a2a8d139a7437ea0ec0335cb35":{"kind":"REWORK","_number":19,"created":"2026-07-25 18:10:07.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/19","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/19","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9f3537e0de29f10eed02d180fe5321d244d139f4","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-25 18:09:55.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"7a1758ae79098e5522e8276f50598b996fc29dcb":{"kind":"TRIVIAL_REBASE","_number":20,"created":"2026-07-25 22:06:28.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/20","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/20","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"62b2bbc8f6ef3994887d238776f547d94dfef185","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-25 22:06:21.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"ea023221040c4bb7ad766faef38f0a2ace1036ae":{"kind":"TRIVIAL_REBASE","_number":21,"created":"2026-07-26 00:06:29.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/21","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/21","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6ce1a19693662b44537a8e642701e16f645e9334","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-26 00:06:24.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"1db8052c88f34a694562ffade027c7a24aecb311":{"kind":"TRIVIAL_REBASE","_number":22,"created":"2026-07-26 00:32:37.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/22","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/22","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/22 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"93137a998fbc40f3fdd31de1b58ff91e92c1ec70","subject":"Split multi_get_create_instance_udp into data and control parts"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-26 00:32:20.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"c215d4d06117b113e30b234ca4e102e05ca28f8e":{"kind":"REWORK","_number":23,"created":"2026-07-27 12:39:42.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/23","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/23","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/23 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2a0be5eccb9a78b6bd73c28e4dc6b5d2b3f49fef","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-27 12:39:19.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"7d23c6943e58b02fdb2e107649c9069ba4fccc75":{"kind":"TRIVIAL_REBASE","_number":24,"created":"2026-07-30 12:03:44.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/24","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/24","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/24 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ee8b9c84bf2713432f5b36af7527753bf4652c9e","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-30 12:02:38.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"89e0a69040356390333432041997a4d3dfe2ea5d":{"kind":"REWORK","_number":25,"created":"2026-08-03 13:25:30.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/25","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/25","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/25 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8408bdb15b8c8a7fec1998ce7493ade0cc46f04b","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-03 13:22:35.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"40cfe5c6d64dcd4fb6cbe8dbd3268a21527e71a3":{"kind":"REWORK","_number":26,"created":"2026-08-03 14:11:00.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/26","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/26","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/26 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e4c4e2fff1272a6a949b347d4bfe38d3d4278f6d","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-03 14:10:33.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"4ac71e05cf29591662491cfc32df284217abc699":{"kind":"REWORK","_number":27,"created":"2026-08-08 21:53:41.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/27","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/27","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/27 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"217af18cbca9c5fe2aa6794c9f4f6633f150205a","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-08 21:53:31.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"7fb4963f5775ec258af08dbaeea4ce03e454ede2":{"kind":"REWORK","_number":28,"created":"2026-08-14 11:56:29.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/28","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/28","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/28 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"fde394d23dc191ee47c023fbf3ffeb230e1f2101","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-14 11:56:23.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"9849c75f6f4904505c27e85ccf04b1e159dad8d8":{"kind":"REWORK","_number":29,"created":"2026-08-17 11:39:08.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/27/1727/29","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/27/1727/29","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29 \u0026\u0026 git checkout -b change-1727 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/27/1727/29 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"793301a47dcc96dfdd667c31e923d1c416f069e0","subject":"Make required action returned from pre_decrypt_verdict more explicit"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-01-07 16:45:14.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-17 11:36:07.000000000","tz":120},"subject":"Add lookup of multi session by session id","message":"Add lookup of multi session by session id\n\nThis refactors the way that we lookup control channel packets for UDP\npackets from other peers. Instead of looking them up by their source\nIP address, we lookup the session ids instead.\n\nIt also has the consequence that we can have multiple ongoing\nsessions from the same source IP address and the new session will\ngo through all the connect steps like an initial session.\n\nThe check if the new session can take over the old session\u0027s IP\nis now also the same as for floating.\n\nThis eliminates a whole class of bugs that we currently have that\nbreak connection if the reconnecting client has different\ncapabilities as the setup and negotiation is inherited from the\nprevious client currently. Currently there is at least one bug\nregarding the dynamic tls-crypt in this situation.\n\nThis also changes the user visible behaviour for clients\nreconnecting from the same IP and port. They are now almost\nbehaving like clients that reconnect from a different IP\naddress. These now do the whole renegotiation and run\nconnect scripts/plugins and all the things are normally\nskipped when reconnecting from the same IP and port.\n\nThe only difference is that duplicate-cn does not\nallow both connection.\n\nThis will also eventually allow us to get rid of TM_INITIAL\nslot as we now do no longer need to keep an ongoing and a\nnew session anymore. Currently the p2p mode still needs\nthe extra session slot for the new session so we cannot\nremove it just yet.\n\nThis now allows a multiple pending session from the\nsame source IP and port. Previously a client would need\nto use a different ports to create multiple pending\nsession. This change does not make it really easier to\nexhaust all pending session than before.\n\nChange-Id: Idb59ecd119331b198792ad1379bec8600211651b\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
