)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":"P_LAST_OPCODE becomes 12, and opcode_valid_in_session() replaces the"},{"line_number":25,"context_line":"plain range check because OOB opcodes are answered statelessly and are"},{"line_number":26,"context_line":"never legal on an established session."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"See the OOB control message section of the wire protocol specification"},{"line_number":29,"context_line":"(openvpn-rfc PR #30)."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":16,"id":"e49cd08f_c4d00e95","line":26,"updated":"2026-09-17 12:41:53.000000000","message":"Commit message not updated.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":23,"context_line":""},{"line_number":24,"context_line":"P_LAST_OPCODE becomes 12, and opcode_valid_in_session() replaces the"},{"line_number":25,"context_line":"plain range check because OOB opcodes are answered statelessly and are"},{"line_number":26,"context_line":"never legal on an established session."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"See the OOB control message section of the wire protocol specification"},{"line_number":29,"context_line":"(openvpn-rfc PR #30)."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":16,"id":"5dcde3e3_54c4a1a6","line":26,"in_reply_to":"e49cd08f_c4d00e95","updated":"2026-09-18 08:32:15.000000000","message":"oops, updated now. It describes the explicit rejection in tls_pte_decrypt() instead of removed helper.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":25,"context_line":"plain range check because OOB opcodes are answered statelessly and are"},{"line_number":26,"context_line":"never legal on an established session."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"See the OOB control message section of the wire protocol specification"},{"line_number":29,"context_line":"(openvpn-rfc PR #30)."},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"Change-Id: I1c8d302ac57c5603d622a7be14be369437388268"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":16,"id":"02f6b113_8081e410","line":28,"updated":"2026-09-17 12:41:53.000000000","message":"Better to reference a link in the spec and/or the header under which is this is defined rather than a PR that does get updated/receives documentation fixes.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":25,"context_line":"plain range check because OOB opcodes are answered statelessly and are"},{"line_number":26,"context_line":"never legal on an established session."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"See the OOB control message section of the wire protocol specification"},{"line_number":29,"context_line":"(openvpn-rfc PR #30)."},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"Change-Id: I1c8d302ac57c5603d622a7be14be369437388268"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":16,"id":"53b41016_5c610b6f","line":28,"in_reply_to":"02f6b113_8081e410","updated":"2026-09-18 08:32:15.000000000","message":"It now points at the spec sections.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"aaf9452cdd9a3c6ddb4cbd70092d6586b96c458e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"9ae888d6_b834e0de","updated":"2026-06-30 11:59:32.000000000","message":"This fails \"make distcheck\" (see the -package builds in buildbot). That is due to oob.h not being referenced anywhere in the Makefiles. Please fix.","commit_id":"e268a6167a01da9be34af5193ec5ba8a5c093e82"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"0e82b77663ad0c417c43619b7450c0dbe1efd6fb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"8ad02623_d0b1f7b8","updated":"2026-07-26 00:42:43.000000000","message":"The spec I wrote cover both out of band and also inband MTU check packets that have the same format. The naming of oob.c basically ignores that we have the other kind of messages even though they share a lot in common.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"5278f621_12b3eb59","in_reply_to":"8ad02623_d0b1f7b8","updated":"2026-07-28 15:04:11.000000000","message":"I will move the code which touches both OOB and future inband into control_msg.c/h and leave only OOB-specific code in oob.c/oob_client.c","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"be2b01d9d0282929e08edac701520b5c85bc5dc4","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":17,"id":"55a871dd_88da62af","updated":"2026-09-25 15:23:13.000000000","message":"We already have TLV parser/write that parses/write TLV with a compatible format for TLV_TYPE_EARLY_NEG_FLAGS. \n\nWhile I know this code is not as sophisticated as the one used for the new TLV, the old TLV is the same format and we should use only have one parser infrastructue instead of two.","commit_id":"ffa8097cbd669f623a93dd9b368ffb776ae60d2e"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"ee20a6709b2cf036ffb9b38ff5f0f921ce30dd2f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"2fe25bc0_e817a258","in_reply_to":"55a871dd_88da62af","updated":"2026-09-30 08:28:01.000000000","message":"Yeah makes sense. So I moved TLV parser into a separate commit, which also replaces TLV parsing in ssl.c. \n\nhttps://gerrit.openvpn.net/c/openvpn/+/1965\n\nThis makes https://gerrit.openvpn.net/c/openvpn/+/1741 much smaller.","commit_id":"ffa8097cbd669f623a93dd9b368ffb776ae60d2e"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"c3132c4a0d6a2b15db77b28193a43ed993eec9c8","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":18,"id":"30fdb1e9_d12942b5","updated":"2026-09-29 22:16:12.000000000","message":"This seems to be unfinished. IT still contains a lot of SERVER_PROBE/PROBE_REPLY references in commit and comments. I did not check after that but will wait until the patch set has been updated fully.","commit_id":"842942c1351f98633602bb39d6f0ad183ebcfe36"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"ee20a6709b2cf036ffb9b38ff5f0f921ce30dd2f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"612ee9be_2abcbf56","in_reply_to":"30fdb1e9_d12942b5","updated":"2026-09-30 08:28:01.000000000","message":"Yes, I changed the wire format only. Let me fix the naming and also look into (existing) TLV parser.","commit_id":"842942c1351f98633602bb39d6f0ad183ebcfe36"}],"CMakeLists.txt":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"a911e76917ec3681f0b8fc2b4d7a25e0fd52de26","unresolved":true,"context_lines":[{"line_number":865,"context_line":"        tests/unit_tests/openvpn/mock_get_random.c"},{"line_number":866,"context_line":"        src/openvpn/oob.c"},{"line_number":867,"context_line":"        src/openvpn/session_id.c"},{"line_number":868,"context_line":"        )"},{"line_number":869,"context_line":""},{"line_number":870,"context_line":"    target_sources(test_pkt PRIVATE"},{"line_number":871,"context_line":"        tests/unit_tests/openvpn/mock_win32_execve.c"}],"source_content_type":"text/x-cmake","patch_set":8,"id":"1bb061ef_38225867","line":868,"updated":"2026-07-26 01:10:34.000000000","message":"Do we really need an extra unit test for this? Can we instead just add this as extra compilation file to to test_pkt or similar?","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":865,"context_line":"        tests/unit_tests/openvpn/mock_get_random.c"},{"line_number":866,"context_line":"        src/openvpn/oob.c"},{"line_number":867,"context_line":"        src/openvpn/session_id.c"},{"line_number":868,"context_line":"        )"},{"line_number":869,"context_line":""},{"line_number":870,"context_line":"    target_sources(test_pkt PRIVATE"},{"line_number":871,"context_line":"        tests/unit_tests/openvpn/mock_win32_execve.c"}],"source_content_type":"text/x-cmake","patch_set":8,"id":"c99a69f9_76cadbc8","line":868,"in_reply_to":"1bb061ef_38225867","updated":"2026-07-28 15:04:11.000000000","message":"I would keep it separate. There are already 19 test drivers here, many for smaller modules, so per module seemed to be the pattern. Also test_pkt links the crypto backends, tls_crypt and reliable, while oob_testdriver only needs a few files, so I would not link crypto stack to it.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":886,"context_line":"        src/openvpn/session_id.c"},{"line_number":887,"context_line":"        )"},{"line_number":888,"context_line":""},{"line_number":889,"context_line":"    target_sources(test_oob PRIVATE"},{"line_number":890,"context_line":"        tests/unit_tests/openvpn/mock_get_random.c"},{"line_number":891,"context_line":"        src/openvpn/control_msg.c"},{"line_number":892,"context_line":"        src/openvpn/oob.c"}],"source_content_type":"text/x-cmake","patch_set":16,"id":"06bdba7f_c8c4e830","line":889,"updated":"2026-09-17 12:41:53.000000000","message":"Same comment as on the Automake file.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":886,"context_line":"        src/openvpn/session_id.c"},{"line_number":887,"context_line":"        )"},{"line_number":888,"context_line":""},{"line_number":889,"context_line":"    target_sources(test_oob PRIVATE"},{"line_number":890,"context_line":"        tests/unit_tests/openvpn/mock_get_random.c"},{"line_number":891,"context_line":"        src/openvpn/control_msg.c"},{"line_number":892,"context_line":"        src/openvpn/oob.c"}],"source_content_type":"text/x-cmake","patch_set":16,"id":"93b4a140_4a61df35","line":889,"in_reply_to":"06bdba7f_c8c4e830","updated":"2026-09-18 08:32:15.000000000","message":"Done, test_oob.c is built into test_pkt.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"src/openvpn/control_msg.c":[{"author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"change_message_id":"c8c9098a907844f312462d0e00c1b53082686549","unresolved":true,"context_lines":[{"line_number":70,"context_line":"{"},{"line_number":71,"context_line":"    struct ctrl_msg_tlv_header hdr;"},{"line_number":72,"context_line":"    bool found \u003d false;"},{"line_number":73,"context_line":"    while (ctrl_msg_tlv_read_header(payload, \u0026hdr))"},{"line_number":74,"context_line":"    {"},{"line_number":75,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"},{"line_number":76,"context_line":"         * length is really there and advances past it in one step, so the TLV"}],"source_content_type":"text/x-csrc","patch_set":12,"id":"7fe73b74_450fca1e","line":73,"updated":"2026-09-07 16:22:54.000000000","message":"Seems like a truncated TLV header after the wanted TLV is accepted here. Once `found` is true, `ctrl_msg_tlv_read_header` returning false for 1-3 trailing bytes ends the loop and the function returns true.\n\nI think we should distinguish clean EOF from a malformed header:\n\n```\nwhile (BLEN(payload) \u003e 0)\n{\n    if (!ctrl_msg_tlv_read_header(payload, \u0026hdr))\n    {\n        return false; /* bytes remain, so this is a truncated header */\n    }\n\n    /* process TLV */\n}\n\nreturn found;\n```\n\nProbably a test with one byte appended after a valid TLV would cover this.","commit_id":"b401b0989fda78f36449073f3b64df9900d21bc5"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"5691cdb9b87edfc2e2fe9800137fcc47ff0bcf49","unresolved":false,"context_lines":[{"line_number":70,"context_line":"{"},{"line_number":71,"context_line":"    struct ctrl_msg_tlv_header hdr;"},{"line_number":72,"context_line":"    bool found \u003d false;"},{"line_number":73,"context_line":"    while (ctrl_msg_tlv_read_header(payload, \u0026hdr))"},{"line_number":74,"context_line":"    {"},{"line_number":75,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"},{"line_number":76,"context_line":"         * length is really there and advances past it in one step, so the TLV"}],"source_content_type":"text/x-csrc","patch_set":12,"id":"d18d7f6c_303cd624","line":73,"in_reply_to":"7fe73b74_450fca1e","updated":"2026-09-09 07:27:24.000000000","message":"Done. Truncated header means rejection. Test added.","commit_id":"b401b0989fda78f36449073f3b64df9900d21bc5"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"e85b59c1d3e7bffe10c1781138cfc0160796c42e","unresolved":true,"context_lines":[{"line_number":74,"context_line":"    {"},{"line_number":75,"context_line":"        if (!ctrl_msg_tlv_read_header(payload, \u0026hdr))"},{"line_number":76,"context_line":"        {"},{"line_number":77,"context_line":"            /* bytes remain but too few for a header: truncated */"},{"line_number":78,"context_line":"            return false;"},{"line_number":79,"context_line":"        }"},{"line_number":80,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"}],"source_content_type":"text/x-csrc","patch_set":15,"id":"70013775_fb1d4853","line":77,"updated":"2026-09-16 23:39:24.000000000","message":"Which bytes remain here? Didn\u0027t ctrl_msg_tlv_read_header read all of the availabe ones?","commit_id":"3f8217314124701400cb9ce525071943a373e780"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"20a8915d222d5664290050550a37e3d1bd217e59","unresolved":false,"context_lines":[{"line_number":74,"context_line":"    {"},{"line_number":75,"context_line":"        if (!ctrl_msg_tlv_read_header(payload, \u0026hdr))"},{"line_number":76,"context_line":"        {"},{"line_number":77,"context_line":"            /* bytes remain but too few for a header: truncated */"},{"line_number":78,"context_line":"            return false;"},{"line_number":79,"context_line":"        }"},{"line_number":80,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"}],"source_content_type":"text/x-csrc","patch_set":15,"id":"6e0dd0ad_3afb4251","line":77,"in_reply_to":"70013775_fb1d4853","updated":"2026-09-17 07:42:23.000000000","message":"The header needs 4 bytes, if fewer are left the message is truncated. Comment amended.","commit_id":"3f8217314124701400cb9ce525071943a373e780"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"e85b59c1d3e7bffe10c1781138cfc0160796c42e","unresolved":true,"context_lines":[{"line_number":94,"context_line":"            }"},{"line_number":95,"context_line":"        }"},{"line_number":96,"context_line":"        else if (!hdr.optional)"},{"line_number":97,"context_line":"        {"},{"line_number":98,"context_line":"            /* A TLV we do not understand that the sender did not mark optional"},{"line_number":99,"context_line":"             * carries something it requires us to act on, so the message as a"},{"line_number":100,"context_line":"             * whole is not ours to interpret. This is why the scan continues"}],"source_content_type":"text/x-csrc","patch_set":15,"id":"9e684786_029ba13d","line":97,"updated":"2026-09-16 23:39:24.000000000","message":"So this API design forces us to rewrite the parsing once we have a message that has two TLV and one of them is mandatory as this function is only useful to parse messages that contain exactly one TLV.\n\nEither we should not pretend to support/implment multiple TLV with this method or update the doxygen to explain that this method/API currently only works for the scenario with one TLV of expected payload while ignoring optional ones.","commit_id":"3f8217314124701400cb9ce525071943a373e780"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"20a8915d222d5664290050550a37e3d1bd217e59","unresolved":false,"context_lines":[{"line_number":94,"context_line":"            }"},{"line_number":95,"context_line":"        }"},{"line_number":96,"context_line":"        else if (!hdr.optional)"},{"line_number":97,"context_line":"        {"},{"line_number":98,"context_line":"            /* A TLV we do not understand that the sender did not mark optional"},{"line_number":99,"context_line":"             * carries something it requires us to act on, so the message as a"},{"line_number":100,"context_line":"             * whole is not ours to interpret. This is why the scan continues"}],"source_content_type":"text/x-csrc","patch_set":15,"id":"1b53219a_6d3f5abe","line":97,"in_reply_to":"9e684786_029ba13d","updated":"2026-09-17 07:42:23.000000000","message":"Yep, the API only handles messages with one mandatory TLV, which is every OOB message so far. Fixed the doxygen to say it clearly. Extending the scan can wait until we add a message with more than one.","commit_id":"3f8217314124701400cb9ce525071943a373e780"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":78,"context_line":"        }"},{"line_number":79,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"},{"line_number":80,"context_line":"         * length is really there and advances past it in one step, so the TLV"},{"line_number":81,"context_line":"         * we are looking for and the ones we skip are bounds-checked alike. */"},{"line_number":82,"context_line":"        uint8_t *v \u003d buf_read_alloc(payload, hdr.value_len);"},{"line_number":83,"context_line":"        if (!v)"},{"line_number":84,"context_line":"        {"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"af589fdc_2762f9ec","line":81,"updated":"2026-09-17 12:41:53.000000000","message":"This sounds quite complicated. Is there anything more than trying to say \"Adavanced to the end of TLV and see if the data is complete\"?","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":78,"context_line":"        }"},{"line_number":79,"context_line":"        /* Take the value out of payload. This validates that the header\u0027s"},{"line_number":80,"context_line":"         * length is really there and advances past it in one step, so the TLV"},{"line_number":81,"context_line":"         * we are looking for and the ones we skip are bounds-checked alike. */"},{"line_number":82,"context_line":"        uint8_t *v \u003d buf_read_alloc(payload, hdr.value_len);"},{"line_number":83,"context_line":"        if (!v)"},{"line_number":84,"context_line":"        {"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"7e8b6f15_b43106bd","line":81,"in_reply_to":"af589fdc_2762f9ec","updated":"2026-09-18 08:32:15.000000000","message":"yes, that\u0027s all it does. Changed to \"advance past the value, fails if the payload is shorter than the header claims\"","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"src/openvpn/control_msg.h":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":85,"context_line":" * future) TLV type that is marked optional."},{"line_number":86,"context_line":" *"},{"line_number":87,"context_line":" * This is for messages that carry exactly one mandatory TLV, which is every"},{"line_number":88,"context_line":" * OOB message so far: any other TLV that is not marked optional invalidates"},{"line_number":89,"context_line":" * the message wherever it sits, so the whole sequence is walked. A message"},{"line_number":90,"context_line":" * with several mandatory TLVs would need a scan that knows all of them."},{"line_number":91,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"9195d45f_4d95ac70","line":88,"updated":"2026-09-17 12:41:53.000000000","message":"which matches the currently supported OOB messages.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":85,"context_line":" * future) TLV type that is marked optional."},{"line_number":86,"context_line":" *"},{"line_number":87,"context_line":" * This is for messages that carry exactly one mandatory TLV, which is every"},{"line_number":88,"context_line":" * OOB message so far: any other TLV that is not marked optional invalidates"},{"line_number":89,"context_line":" * the message wherever it sits, so the whole sequence is walked. A message"},{"line_number":90,"context_line":" * with several mandatory TLVs would need a scan that knows all of them."},{"line_number":91,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"f19b0faa_514665bb","line":88,"in_reply_to":"9195d45f_4d95ac70","updated":"2026-09-18 08:32:15.000000000","message":"fixed","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":86,"context_line":" *"},{"line_number":87,"context_line":" * This is for messages that carry exactly one mandatory TLV, which is every"},{"line_number":88,"context_line":" * OOB message so far: any other TLV that is not marked optional invalidates"},{"line_number":89,"context_line":" * the message wherever it sits, so the whole sequence is walked. A message"},{"line_number":90,"context_line":" * with several mandatory TLVs would need a scan that knows all of them."},{"line_number":91,"context_line":" *"},{"line_number":92,"context_line":" * On success value covers exactly the found TLV\u0027s value bytes. The length from"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"97e70ce2_3d0ef64a","line":89,"updated":"2026-09-17 12:41:53.000000000","message":"sits? \n\n\"it is present\" perhaps","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":86,"context_line":" *"},{"line_number":87,"context_line":" * This is for messages that carry exactly one mandatory TLV, which is every"},{"line_number":88,"context_line":" * OOB message so far: any other TLV that is not marked optional invalidates"},{"line_number":89,"context_line":" * the message wherever it sits, so the whole sequence is walked. A message"},{"line_number":90,"context_line":" * with several mandatory TLVs would need a scan that knows all of them."},{"line_number":91,"context_line":" *"},{"line_number":92,"context_line":" * On success value covers exactly the found TLV\u0027s value bytes. The length from"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"84a3578a_f518ba01","line":89,"in_reply_to":"97e70ce2_3d0ef64a","updated":"2026-09-18 08:32:15.000000000","message":"fixed","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":97,"context_line":" *"},{"line_number":98,"context_line":" * @param payload      buffer positioned at a TLV header"},{"line_number":99,"context_line":" * @param wanted_type  the TLV type to look for"},{"line_number":100,"context_line":" * @param value        set to a buffer covering the found TLV\u0027s value"},{"line_number":101,"context_line":" * @return true if the TLV was found, false if it is not present, a TLV header"},{"line_number":102,"context_line":" *         or value is malformed or truncated, or a TLV we do not understand is"},{"line_number":103,"context_line":" *         not marked optional."}],"source_content_type":"text/x-csrc","patch_set":16,"id":"a4d071d5_835ea037","line":100,"updated":"2026-09-17 12:41:53.000000000","message":"Point out that this buffer points at a portain of payload and does not have its own storage.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":97,"context_line":" *"},{"line_number":98,"context_line":" * @param payload      buffer positioned at a TLV header"},{"line_number":99,"context_line":" * @param wanted_type  the TLV type to look for"},{"line_number":100,"context_line":" * @param value        set to a buffer covering the found TLV\u0027s value"},{"line_number":101,"context_line":" * @return true if the TLV was found, false if it is not present, a TLV header"},{"line_number":102,"context_line":" *         or value is malformed or truncated, or a TLV we do not understand is"},{"line_number":103,"context_line":" *         not marked optional."}],"source_content_type":"text/x-csrc","patch_set":16,"id":"87a24226_7877b37a","line":100,"in_reply_to":"a4d071d5_835ea037","updated":"2026-09-18 08:32:15.000000000","message":"added - it points into payload and owns no storage","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"src/openvpn/oob.c":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"82b7c79358a277b90e32384368ddd7d14b040989","unresolved":true,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"#include \"oob.h\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"/* Consume @p value_len bytes of TLV value, of which @p consumed have already"},{"line_number":32,"context_line":" * been read, ignoring (skipping) any trailing bytes that this version does not"},{"line_number":33,"context_line":" * understand. Fails if fewer than @p consumed bytes were declared. */"},{"line_number":34,"context_line":"static bool"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"7bda6ca1_5d7760a6","line":31,"updated":"2026-07-08 16:13:11.000000000","message":"Doxygen syntax but not marked as Doxygen comment","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"bd876f201c986802639f74834919dad3747fb01d","unresolved":true,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"#include \"oob.h\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"/* Consume @p value_len bytes of TLV value, of which @p consumed have already"},{"line_number":32,"context_line":" * been read, ignoring (skipping) any trailing bytes that this version does not"},{"line_number":33,"context_line":" * understand. Fails if fewer than @p consumed bytes were declared. */"},{"line_number":34,"context_line":"static bool"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"c951b8b7_d2f6c9a8","line":31,"in_reply_to":"7bda6ca1_5d7760a6","updated":"2026-07-09 13:49:00.000000000","message":"Will change to real doxygen.","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"33752b140d06ce90c663b157cbfafe26e758c30c","unresolved":false,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"#include \"oob.h\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"/* Consume @p value_len bytes of TLV value, of which @p consumed have already"},{"line_number":32,"context_line":" * been read, ignoring (skipping) any trailing bytes that this version does not"},{"line_number":33,"context_line":" * understand. Fails if fewer than @p consumed bytes were declared. */"},{"line_number":34,"context_line":"static bool"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"65179444_a7cb9a36","line":31,"in_reply_to":"c951b8b7_d2f6c9a8","updated":"2026-07-20 13:23:11.000000000","message":"Done","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"82b7c79358a277b90e32384368ddd7d14b040989","unresolved":true,"context_lines":[{"line_number":102,"context_line":"    bool ok \u003d true;"},{"line_number":103,"context_line":"    p-\u003etimestamp \u003d buf_read_u64(buf, \u0026ok);"},{"line_number":104,"context_line":"    p-\u003eflags \u003d buf_read_u32(buf, \u0026ok);"},{"line_number":105,"context_line":"    if (!ok)"},{"line_number":106,"context_line":"    {"},{"line_number":107,"context_line":"        return false;"},{"line_number":108,"context_line":"    }"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"5d122562_14850b3c","line":105,"updated":"2026-07-08 16:13:11.000000000","message":"Is that safe? If the buffer has enough to read for u32 but not for u64 could we end up with ok being true?","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"33752b140d06ce90c663b157cbfafe26e758c30c","unresolved":false,"context_lines":[{"line_number":102,"context_line":"    bool ok \u003d true;"},{"line_number":103,"context_line":"    p-\u003etimestamp \u003d buf_read_u64(buf, \u0026ok);"},{"line_number":104,"context_line":"    p-\u003eflags \u003d buf_read_u32(buf, \u0026ok);"},{"line_number":105,"context_line":"    if (!ok)"},{"line_number":106,"context_line":"    {"},{"line_number":107,"context_line":"        return false;"},{"line_number":108,"context_line":"    }"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"456532e6_83b27529","line":105,"in_reply_to":"01cc794e_e144d4ad","updated":"2026-07-20 13:23:11.000000000","message":"Done","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"bd876f201c986802639f74834919dad3747fb01d","unresolved":true,"context_lines":[{"line_number":102,"context_line":"    bool ok \u003d true;"},{"line_number":103,"context_line":"    p-\u003etimestamp \u003d buf_read_u64(buf, \u0026ok);"},{"line_number":104,"context_line":"    p-\u003eflags \u003d buf_read_u32(buf, \u0026ok);"},{"line_number":105,"context_line":"    if (!ok)"},{"line_number":106,"context_line":"    {"},{"line_number":107,"context_line":"        return false;"},{"line_number":108,"context_line":"    }"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"01cc794e_e144d4ad","line":105,"in_reply_to":"5d122562_14850b3c","updated":"2026-07-09 13:49:00.000000000","message":"No, this is a bug. Will fix.","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":29,"context_line":"#include \"oob.h\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"/**"},{"line_number":32,"context_line":" * Consume @p value_len bytes of TLV value, of which @p consumed have already"},{"line_number":33,"context_line":" * been read, ignoring (skipping) any trailing bytes that this version does"},{"line_number":34,"context_line":" * not understand."},{"line_number":35,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"b45eab83_cea5e37e","line":32,"updated":"2026-07-26 00:58:29.000000000","message":"What is @p? That is not used anywhere else.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":29,"context_line":"#include \"oob.h\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"/**"},{"line_number":32,"context_line":" * Consume @p value_len bytes of TLV value, of which @p consumed have already"},{"line_number":33,"context_line":" * been read, ignoring (skipping) any trailing bytes that this version does"},{"line_number":34,"context_line":" * not understand."},{"line_number":35,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"e5bb0109_e5122bc3","line":32,"in_reply_to":"b45eab83_cea5e37e","updated":"2026-07-28 15:04:11.000000000","message":"We do use it together with param name in doxygen in other files (init.h for example), but somewhat inconsistently. Let me remove it and use only @param and bare parameter names.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":34,"context_line":" * not understand."},{"line_number":35,"context_line":" *"},{"line_number":36,"context_line":" * @param buf        buffer positioned after the @p consumed value bytes"},{"line_number":37,"context_line":" * @param value_len  the TLV\u0027s declared value length"},{"line_number":38,"context_line":" * @param consumed   number of value bytes already read from @p buf"},{"line_number":39,"context_line":" * @return true on success, false if fewer than @p consumed bytes were"},{"line_number":40,"context_line":" *         declared or @p buf does not hold the trailing bytes."}],"source_content_type":"text/x-csrc","patch_set":8,"id":"87eaa606_951f189c","line":37,"updated":"2026-07-26 00:58:29.000000000","message":"declared as in the length in the header or declared as in the spec or as in expected.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":34,"context_line":" * not understand."},{"line_number":35,"context_line":" *"},{"line_number":36,"context_line":" * @param buf        buffer positioned after the @p consumed value bytes"},{"line_number":37,"context_line":" * @param value_len  the TLV\u0027s declared value length"},{"line_number":38,"context_line":" * @param consumed   number of value bytes already read from @p buf"},{"line_number":39,"context_line":" * @return true on success, false if fewer than @p consumed bytes were"},{"line_number":40,"context_line":" *         declared or @p buf does not hold the trailing bytes."}],"source_content_type":"text/x-csrc","patch_set":8,"id":"b28e0c8b_70ef40c7","line":37,"in_reply_to":"87eaa606_951f189c","updated":"2026-07-28 15:04:11.000000000","message":"Will replace with \"the value length from the TLV header\"","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":35,"context_line":" *"},{"line_number":36,"context_line":" * @param buf        buffer positioned after the @p consumed value bytes"},{"line_number":37,"context_line":" * @param value_len  the TLV\u0027s declared value length"},{"line_number":38,"context_line":" * @param consumed   number of value bytes already read from @p buf"},{"line_number":39,"context_line":" * @return true on success, false if fewer than @p consumed bytes were"},{"line_number":40,"context_line":" *         declared or @p buf does not hold the trailing bytes."},{"line_number":41,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"c82b36ce_c84f3b09","line":38,"updated":"2026-07-26 00:58:29.000000000","message":"We normally do this by buf_advance instead of this way.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":35,"context_line":" *"},{"line_number":36,"context_line":" * @param buf        buffer positioned after the @p consumed value bytes"},{"line_number":37,"context_line":" * @param value_len  the TLV\u0027s declared value length"},{"line_number":38,"context_line":" * @param consumed   number of value bytes already read from @p buf"},{"line_number":39,"context_line":" * @return true on success, false if fewer than @p consumed bytes were"},{"line_number":40,"context_line":" *         declared or @p buf does not hold the trailing bytes."},{"line_number":41,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"6c0b4a64_7b69b0a2","line":38,"in_reply_to":"c82b36ce_c84f3b09","updated":"2026-07-28 15:04:11.000000000","message":"Yep, will call buf_advance() directly.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":49,"context_line":"    return buf_advance(buf, value_len - consumed);"},{"line_number":50,"context_line":"}"},{"line_number":51,"context_line":""},{"line_number":52,"context_line":"bool"},{"line_number":53,"context_line":"oob_msg_write_header(struct buffer *buf, uint16_t msg_type)"},{"line_number":54,"context_line":"{"},{"line_number":55,"context_line":"    return buf_write_u16(buf, msg_type);"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"d7e80cce_f9965cee","line":52,"updated":"2026-07-26 00:58:29.000000000","message":"Why just have a method that wraps buf_write_u16? That seems uncessary.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":49,"context_line":"    return buf_advance(buf, value_len - consumed);"},{"line_number":50,"context_line":"}"},{"line_number":51,"context_line":""},{"line_number":52,"context_line":"bool"},{"line_number":53,"context_line":"oob_msg_write_header(struct buffer *buf, uint16_t msg_type)"},{"line_number":54,"context_line":"{"},{"line_number":55,"context_line":"    return buf_write_u16(buf, msg_type);"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"b4561618_b5c30c7a","line":52,"in_reply_to":"d7e80cce_f9965cee","updated":"2026-07-28 15:04:11.000000000","message":"agreed, will remove the wrapper and call buf_write_u16 directly.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":88,"context_line":"    }"},{"line_number":89,"context_line":"    *type \u003d (uint16_t)(field \u0026 OOB_TLV_TYPE_MASK);"},{"line_number":90,"context_line":"    *optional \u003d (field \u0026 OOB_TLV_OPTIONAL_FLAG) !\u003d 0;"},{"line_number":91,"context_line":"    *value_len \u003d (uint16_t)len;"},{"line_number":92,"context_line":"    return true;"},{"line_number":93,"context_line":"}"},{"line_number":94,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":8,"id":"c74e3f34_d9a3d0be","line":91,"updated":"2026-07-26 00:58:29.000000000","message":"I feel instead of passing the same values with pointers again and again we should instead use proper structs","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":88,"context_line":"    }"},{"line_number":89,"context_line":"    *type \u003d (uint16_t)(field \u0026 OOB_TLV_TYPE_MASK);"},{"line_number":90,"context_line":"    *optional \u003d (field \u0026 OOB_TLV_OPTIONAL_FLAG) !\u003d 0;"},{"line_number":91,"context_line":"    *value_len \u003d (uint16_t)len;"},{"line_number":92,"context_line":"    return true;"},{"line_number":93,"context_line":"}"},{"line_number":94,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":8,"id":"1537b583_56bd7781","line":91,"in_reply_to":"c74e3f34_d9a3d0be","updated":"2026-07-28 15:04:11.000000000","message":"Yep, will add struct oob_tlv_header struct.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":165,"context_line":"    r-\u003econnect_lifetime \u003d (uint16_t)connect_lifetime;"},{"line_number":166,"context_line":"    r-\u003emax_latency_diff \u003d (uint16_t)max_latency_diff;"},{"line_number":167,"context_line":"    return oob_skip_trailing(buf, value_len, OOB_PROBE_REPLY_LEN);"},{"line_number":168,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"a5fbae94_48df0998","line":168,"updated":"2026-07-26 00:58:29.000000000","message":"The formatting of this method is not really great.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":165,"context_line":"    r-\u003econnect_lifetime \u003d (uint16_t)connect_lifetime;"},{"line_number":166,"context_line":"    r-\u003emax_latency_diff \u003d (uint16_t)max_latency_diff;"},{"line_number":167,"context_line":"    return oob_skip_trailing(buf, value_len, OOB_PROBE_REPLY_LEN);"},{"line_number":168,"context_line":"}"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"9db80515_ad07ed38","line":168,"in_reply_to":"a5fbae94_48df0998","updated":"2026-07-28 15:04:11.000000000","message":"yep agreed, will fix.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"}],"src/openvpn/oob.h":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8428b0ec3dc10add58fffb0f8eefe302f738a5b9","unresolved":true,"context_lines":[{"line_number":92,"context_line":"/**"},{"line_number":93,"context_line":" * Read and verify an OOB message-type header from @p buf, advancing past it."},{"line_number":94,"context_line":" *"},{"line_number":95,"context_line":" * @param expected_msg_type  the message type the payload must carry"},{"line_number":96,"context_line":" * @return true if a message type was read and equals @p expected_msg_type,"},{"line_number":97,"context_line":" *         false on a short buffer or a mismatching type."},{"line_number":98,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"d13a7f25_6ad9b312","line":95,"updated":"2026-06-30 12:02:11.000000000","message":"If you document one parameter you need to document all of them. See the doxygen buildbot failure for details.","commit_id":"e268a6167a01da9be34af5193ec5ba8a5c093e82"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"1e85739400d6f6d1a9e98dfb4004520cd126e2f0","unresolved":false,"context_lines":[{"line_number":92,"context_line":"/**"},{"line_number":93,"context_line":" * Read and verify an OOB message-type header from @p buf, advancing past it."},{"line_number":94,"context_line":" *"},{"line_number":95,"context_line":" * @param expected_msg_type  the message type the payload must carry"},{"line_number":96,"context_line":" * @return true if a message type was read and equals @p expected_msg_type,"},{"line_number":97,"context_line":" *         false on a short buffer or a mismatching type."},{"line_number":98,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"9ef9c417_ef3b982e","line":95,"in_reply_to":"d13a7f25_6ad9b312","updated":"2026-07-02 12:31:22.000000000","message":"Done","commit_id":"e268a6167a01da9be34af5193ec5ba8a5c093e82"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"82b7c79358a277b90e32384368ddd7d14b040989","unresolved":true,"context_lines":[{"line_number":32,"context_line":" * 0x2xx space), followed by a 16-bit length giving the size of the value that"},{"line_number":33,"context_line":" * follows the header."},{"line_number":34,"context_line":" *"},{"line_number":35,"context_line":" * This slice implements the SERVER_PROBE / PROBE_REPLY pair used for server"},{"line_number":36,"context_line":" * latency checks. Other message/TLV types are added as the feature grows."},{"line_number":37,"context_line":" */"},{"line_number":38,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":3,"id":"42e94415_5c8f2b50","line":35,"updated":"2026-07-08 16:13:11.000000000","message":"Not sure of the purpose of this sentence?","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"bd876f201c986802639f74834919dad3747fb01d","unresolved":true,"context_lines":[{"line_number":32,"context_line":" * 0x2xx space), followed by a 16-bit length giving the size of the value that"},{"line_number":33,"context_line":" * follows the header."},{"line_number":34,"context_line":" *"},{"line_number":35,"context_line":" * This slice implements the SERVER_PROBE / PROBE_REPLY pair used for server"},{"line_number":36,"context_line":" * latency checks. Other message/TLV types are added as the feature grows."},{"line_number":37,"context_line":" */"},{"line_number":38,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":3,"id":"615dc762_016d178a","line":35,"in_reply_to":"42e94415_5c8f2b50","updated":"2026-07-09 13:49:00.000000000","message":"This is about series of patches. I agree it might add confusion so I\u0027ll remote it.","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"33752b140d06ce90c663b157cbfafe26e758c30c","unresolved":false,"context_lines":[{"line_number":32,"context_line":" * 0x2xx space), followed by a 16-bit length giving the size of the value that"},{"line_number":33,"context_line":" * follows the header."},{"line_number":34,"context_line":" *"},{"line_number":35,"context_line":" * This slice implements the SERVER_PROBE / PROBE_REPLY pair used for server"},{"line_number":36,"context_line":" * latency checks. Other message/TLV types are added as the feature grows."},{"line_number":37,"context_line":" */"},{"line_number":38,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":3,"id":"8e8394ef_e1488568","line":35,"in_reply_to":"615dc762_016d178a","updated":"2026-07-20 13:23:11.000000000","message":"Acknowledged","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"82b7c79358a277b90e32384368ddd7d14b040989","unresolved":true,"context_lines":[{"line_number":59,"context_line":"/* Minimum on-wire value length (excluding the 4-byte TLV header) of each TLV."},{"line_number":60,"context_line":" * The value may be longer for forward compatibility; trailing bytes that are"},{"line_number":61,"context_line":" * not understood are ignored on read. */"},{"line_number":62,"context_line":"#define OOB_PROBE_PARAMETER_LEN 12"},{"line_number":63,"context_line":"#define OOB_PROBE_REPLY_LEN     20"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"/* probe parameter TLV (sent by the client in a SERVER_PROBE) */"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"0d55380a_a563bb77","line":62,"updated":"2026-07-08 16:13:11.000000000","message":"why do we hardcode those instead of defining them via sizeof() ?","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"bd876f201c986802639f74834919dad3747fb01d","unresolved":true,"context_lines":[{"line_number":59,"context_line":"/* Minimum on-wire value length (excluding the 4-byte TLV header) of each TLV."},{"line_number":60,"context_line":" * The value may be longer for forward compatibility; trailing bytes that are"},{"line_number":61,"context_line":" * not understood are ignored on read. */"},{"line_number":62,"context_line":"#define OOB_PROBE_PARAMETER_LEN 12"},{"line_number":63,"context_line":"#define OOB_PROBE_REPLY_LEN     20"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"/* probe parameter TLV (sent by the client in a SERVER_PROBE) */"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"298aabee_731ed6bc","line":62,"in_reply_to":"0d55380a_a563bb77","updated":"2026-07-09 13:49:00.000000000","message":"Those are on-wire lengths, so sizeof(struct) could be wrong due to padding. But let me derive from wire field types instead.","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"f538306fb4fff67e7bd031aeb8fc8e2286925808","unresolved":false,"context_lines":[{"line_number":59,"context_line":"/* Minimum on-wire value length (excluding the 4-byte TLV header) of each TLV."},{"line_number":60,"context_line":" * The value may be longer for forward compatibility; trailing bytes that are"},{"line_number":61,"context_line":" * not understood are ignored on read. */"},{"line_number":62,"context_line":"#define OOB_PROBE_PARAMETER_LEN 12"},{"line_number":63,"context_line":"#define OOB_PROBE_REPLY_LEN     20"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"/* probe parameter TLV (sent by the client in a SERVER_PROBE) */"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"ef87b237_5a6142ba","line":62,"in_reply_to":"298aabee_731ed6bc","updated":"2026-07-09 14:02:04.000000000","message":"\u003e Those are on-wire lengths, so sizeof(struct) could be wrong due to padding. But let me derive from wire field types instead.","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"change_message_id":"c8c9098a907844f312462d0e00c1b53082686549","unresolved":true,"context_lines":[{"line_number":75,"context_line":"    uint16_t priority;                 /**\u003c DNS-SRV style priority (lower is preferred) */"},{"line_number":76,"context_line":"    uint16_t weight;                   /**\u003c DNS-SRV style weight */"},{"line_number":77,"context_line":"    uint16_t max_latency_diff;         /**\u003c advertised candidate-band margin in ms;"},{"line_number":78,"context_line":"                                        *   0 means \"defer to the client\u0027s setting\" */"},{"line_number":79,"context_line":"    uint16_t connect_lifetime;         /**\u003c seconds the reply stays valid as the handshake reset */"},{"line_number":80,"context_line":"    uint32_t flags;                    /**\u003c server behaviour flags */"},{"line_number":81,"context_line":"};"}],"source_content_type":"text/x-csrc","patch_set":12,"id":"b9ac27b9_00f52354","line":78,"updated":"2026-09-07 16:22:54.000000000","message":"This comment wrongly describes 0 as a sentinel. If the client has no override, only the fastest server and RTT ties are candidates. Whether to use the client or server value is instead determined by `client_margin \u003e\u003d 0` and the later patch implements that correctly. So I\u0027d update this comment to reflect that.","commit_id":"b401b0989fda78f36449073f3b64df9900d21bc5"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"5691cdb9b87edfc2e2fe9800137fcc47ff0bcf49","unresolved":false,"context_lines":[{"line_number":75,"context_line":"    uint16_t priority;                 /**\u003c DNS-SRV style priority (lower is preferred) */"},{"line_number":76,"context_line":"    uint16_t weight;                   /**\u003c DNS-SRV style weight */"},{"line_number":77,"context_line":"    uint16_t max_latency_diff;         /**\u003c advertised candidate-band margin in ms;"},{"line_number":78,"context_line":"                                        *   0 means \"defer to the client\u0027s setting\" */"},{"line_number":79,"context_line":"    uint16_t connect_lifetime;         /**\u003c seconds the reply stays valid as the handshake reset */"},{"line_number":80,"context_line":"    uint32_t flags;                    /**\u003c server behaviour flags */"},{"line_number":81,"context_line":"};"}],"source_content_type":"text/x-csrc","patch_set":12,"id":"c8a0757f_b4229003","line":78,"in_reply_to":"b9ac27b9_00f52354","updated":"2026-09-09 07:27:24.000000000","message":"Right, comment is outdated - zero means 0ms band.","commit_id":"b401b0989fda78f36449073f3b64df9900d21bc5"}],"src/openvpn/ssl_pkt.c":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":168,"context_line":"{"},{"line_number":169,"context_line":"    ASSERT(ks-\u003ekey_id \u003e\u003d 0 \u0026\u0026 ks-\u003ekey_id \u003c\u003d P_KEY_ID_MASK);"},{"line_number":170,"context_line":"    ASSERT(opcode \u003e\u003d 0 \u0026\u0026 opcode \u003c\u003d P_LAST_OPCODE);"},{"line_number":171,"context_line":"    ASSERT(!opcode_is_oob(opcode)); /* those are built by tls_wrap_oob_standalone() */"},{"line_number":172,"context_line":"    uint8_t header \u003d (uint8_t)(ks-\u003ekey_id | (opcode \u003c\u003c P_OPCODE_SHIFT));"},{"line_number":173,"context_line":""},{"line_number":174,"context_line":"    /* Workaround for Softether servers. Softether has a bug that it only"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"48fd91f3_fae27106","line":171,"updated":"2026-09-17 12:41:53.000000000","message":"what does those reference here? I have a rough idea what you are trying to say but I think this comment is a bit cryptic.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":168,"context_line":"{"},{"line_number":169,"context_line":"    ASSERT(ks-\u003ekey_id \u003e\u003d 0 \u0026\u0026 ks-\u003ekey_id \u003c\u003d P_KEY_ID_MASK);"},{"line_number":170,"context_line":"    ASSERT(opcode \u003e\u003d 0 \u0026\u0026 opcode \u003c\u003d P_LAST_OPCODE);"},{"line_number":171,"context_line":"    ASSERT(!opcode_is_oob(opcode)); /* those are built by tls_wrap_oob_standalone() */"},{"line_number":172,"context_line":"    uint8_t header \u003d (uint8_t)(ks-\u003ekey_id | (opcode \u003c\u003c P_OPCODE_SHIFT));"},{"line_number":173,"context_line":""},{"line_number":174,"context_line":"    /* Workaround for Softether servers. Softether has a bug that it only"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"811fab47_a4c877a0","line":171,"in_reply_to":"48fd91f3_fae27106","updated":"2026-09-18 08:32:15.000000000","message":"changed to (hopefully) less cryptic \"OOB packets carry no message id or ACK array, tls_wrap_standalone() builds them\"","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"src/openvpn/ssl_pkt.h":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"fee29e6f337beabb28f2bb82b2b8f3ae988eb091","unresolved":true,"context_lines":[{"line_number":67,"context_line":" * widening it before an OOB receive handler exists would let OOB packets"},{"line_number":68,"context_line":" * be misparsed as established-session control packets. Bump P_LAST_OPCODE"},{"line_number":69,"context_line":" * to 12 in the same change that adds the handler. */"},{"line_number":70,"context_line":"#define P_CONTROL_OOB_V1 12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* define the range of legal opcodes"},{"line_number":73,"context_line":" * Since we do no longer support key-method 1 we consider"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"34640017_fe9a3866","line":70,"updated":"2026-07-26 00:58:29.000000000","message":"That feels like a very hacky way of doing this and also will already create problem with the spec that we written as CONTROL_DATA_V1 (\u003d14) as we then need to change LAST_OPCODE to 14 and then this falls apart.\n\nAlso the assumption here that P_CONTROL_OOB_V1 needs to treat specially should be explained here better. What is the harm we consider if we parsed and respond to such packet during a session? I don\u0027t see an obvious reason why that is bad.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"4a7a0d954c49eb1b90d7cf9dc9ce5ae7ae46c696","unresolved":true,"context_lines":[{"line_number":67,"context_line":" * widening it before an OOB receive handler exists would let OOB packets"},{"line_number":68,"context_line":" * be misparsed as established-session control packets. Bump P_LAST_OPCODE"},{"line_number":69,"context_line":" * to 12 in the same change that adds the handler. */"},{"line_number":70,"context_line":"#define P_CONTROL_OOB_V1 12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* define the range of legal opcodes"},{"line_number":73,"context_line":" * Since we do no longer support key-method 1 we consider"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"4a12bf6c_a19a4737","line":70,"in_reply_to":"23c27391_45a5ff38","updated":"2026-09-16 23:19:01.000000000","message":"You did not really address the comment. The code still has P_LAST_OPCODE as one define that is still 12. If anything the comments and the change made it even more confusing now.\n\nSomehow now an OOB opcode is not valid inside a session but a CLIENT_RESET_V2 opcode is valid inside a session but both have similar treatment in the reset of the code. Also you introduce the concept of \"inside a session\" without properly explaining what a session in this context actually is.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"c9cbf54fed4709bec4742be56b97b0e0a06f7d0c","unresolved":false,"context_lines":[{"line_number":67,"context_line":" * widening it before an OOB receive handler exists would let OOB packets"},{"line_number":68,"context_line":" * be misparsed as established-session control packets. Bump P_LAST_OPCODE"},{"line_number":69,"context_line":" * to 12 in the same change that adds the handler. */"},{"line_number":70,"context_line":"#define P_CONTROL_OOB_V1 12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* define the range of legal opcodes"},{"line_number":73,"context_line":" * Since we do no longer support key-method 1 we consider"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"23c27391_45a5ff38","line":70,"in_reply_to":"34640017_fe9a3866","updated":"2026-07-28 15:04:11.000000000","message":"The root cause is that P_LAST_OPCODE has 2 different meanings:\n\n - could this opcode appear on an established session\n - highest opcode that exists\n\nAt the moment the last opcode which could appear on a session is 11 and 12/13 are\nOOB. When 14 (inband) appears, this will indeed break.\n\nLet me change it in the following way:\n\n - P_LAST_OPCODE will be the highest opcode that exists (in/outband)\n - new static inlines to gate session-valid opcodes:\n\nstatic inline bool\nopcode_is_oob(int op)\n{\n    return op \u003d\u003d P_CONTROL_OOB_V1 || op \u003d\u003d P_CONTROL_OOB_WKC_V1;\n}\n\n/* true if op may occur on an established control-channel session */\nstatic inline bool\nopcode_valid_in_session(int op)\n{\n    return op \u003e\u003d P_FIRST_OPCODE \u0026\u0026 op \u003c\u003d P_LAST_OPCODE \u0026\u0026 !opcode_is_oob(op);\n}\n\nWhat harm in answering OOB packets inside the session?\n\nNo real harm today - a probe on a live session is dropped anyway, but\nincidentally: OOB carries no ACK fields, so the session path reads SERVER_PROBE\u0027s\n0x0100 as an ACK count of 1 and then TLV bytes as a packet-id and session id,\nwhich mismatches. The payload is attacker-chosen and session ids are plaintext,\nso it can be crafted into a valid ACK array - forged ACKs stall a handshake or\nrekey.\n\nAnswering in-session: yes, but as a follow-up. Today\u0027s behaviour is worse than\nrejected - the stateless path only runs when the address has no instance, so a\nconnected peer\u0027s probe is dropped, not answered (rare in practice: probe sockets\nare unbound, so reconnects arrive on a fresh port). It needs dispatch before\nreliable_ack_read(), a per-instance rate limit etc. I\u0027d do it with\nCONTROL_DATA_V1.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"20a8915d222d5664290050550a37e3d1bd217e59","unresolved":false,"context_lines":[{"line_number":67,"context_line":" * widening it before an OOB receive handler exists would let OOB packets"},{"line_number":68,"context_line":" * be misparsed as established-session control packets. Bump P_LAST_OPCODE"},{"line_number":69,"context_line":" * to 12 in the same change that adds the handler. */"},{"line_number":70,"context_line":"#define P_CONTROL_OOB_V1 12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* define the range of legal opcodes"},{"line_number":73,"context_line":" * Since we do no longer support key-method 1 we consider"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"382b0d88_c0e1ced9","line":70,"in_reply_to":"4a12bf6c_a19a4737","updated":"2026-09-17 07:42:23.000000000","message":"Dropped opcode_valid_in_session() and the \"session\" wording. P_LAST_OPCODE is the highest defined opcode again, and the OOB opcodes are excluded by name, || opcode_is_oob(op), not by position in the range. So when CONTROL_DATA_V1 arrives, P_LAST_OPCODE becomes 14 and nothing else has to change; 12 and 13 stay out of  tls_pre_decrypt().\n\nWhy they have to stay out: tls_pre_decrypt() starts by parsing the reliability header (ACK array, packet id), and an OOB packet has none, so its TLV bytes would be read as ACKs. CLIENT_RESET_V2 does carry that header, which is the difference between the two. Nothing on that path handles an OOB payload either, so there is nothing to gain by letting it in. Answering probes on an established connection would need its own dispatch before the ACK parsing plus a rate limit, so I would do that as a follow-up. write_control_auth(), which writes the header, gets the matching ASSERT.","commit_id":"4e332039301865b4061702bc2d6b622d0691ee60"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":69,"context_line":"#define P_FIRST_OPCODE 3"},{"line_number":70,"context_line":"#define P_LAST_OPCODE  12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* the out-of-band opcodes, which carry no reliability header */"},{"line_number":73,"context_line":"static inline bool"},{"line_number":74,"context_line":"opcode_is_oob(int op)"},{"line_number":75,"context_line":"{"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"b734bc70_7c5c92c6","line":72,"updated":"2026-09-17 12:41:53.000000000","message":"Other part of the code call this ACK array. I would be a bit more verbose here: \n\nOOB opcodes are part of the reliable control channel: ie no control message id and no ACK array.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":69,"context_line":"#define P_FIRST_OPCODE 3"},{"line_number":70,"context_line":"#define P_LAST_OPCODE  12"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"/* the out-of-band opcodes, which carry no reliability header */"},{"line_number":73,"context_line":"static inline bool"},{"line_number":74,"context_line":"opcode_is_oob(int op)"},{"line_number":75,"context_line":"{"}],"source_content_type":"text/x-csrc","patch_set":16,"id":"8e3f8bf7_3896c14c","line":72,"in_reply_to":"b734bc70_7c5c92c6","updated":"2026-09-18 08:32:15.000000000","message":"fixed (looks like you missed \"not\") - OOB opcodes are not part of the reliable control channel, no control message id and no ack array.","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"tests/unit_tests/openvpn/Makefile.am":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"5536f30e3e3d18737b8229d7f86e885c4936cb1a","unresolved":true,"context_lines":[{"line_number":154,"context_line":"\t$(top_srcdir)/src/openvpn/win32-util.c \\"},{"line_number":155,"context_line":"\t$(top_srcdir)/src/openvpn/session_id.c"},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"oob_testdriver_CFLAGS  \u003d \\"},{"line_number":158,"context_line":"\t-I$(top_srcdir)/include -I$(top_srcdir)/src/compat -I$(top_srcdir)/src/openvpn \\"},{"line_number":159,"context_line":"\t@TEST_CFLAGS@"},{"line_number":160,"context_line":"oob_testdriver_LDFLAGS \u003d @TEST_LDFLAGS@"}],"source_content_type":"application/octet-stream","patch_set":16,"id":"fc3a9237_5f6856aa","line":157,"updated":"2026-09-17 12:41:53.000000000","message":"Can we just add test_oob.c to pkt_testdriver_SOURCES and not add yet another test suite with a very low number tests?","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"a6d859e25cf6fbc403b77656b7a37a1a696691a6","unresolved":false,"context_lines":[{"line_number":154,"context_line":"\t$(top_srcdir)/src/openvpn/win32-util.c \\"},{"line_number":155,"context_line":"\t$(top_srcdir)/src/openvpn/session_id.c"},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"oob_testdriver_CFLAGS  \u003d \\"},{"line_number":158,"context_line":"\t-I$(top_srcdir)/include -I$(top_srcdir)/src/compat -I$(top_srcdir)/src/openvpn \\"},{"line_number":159,"context_line":"\t@TEST_CFLAGS@"},{"line_number":160,"context_line":"oob_testdriver_LDFLAGS \u003d @TEST_LDFLAGS@"}],"source_content_type":"application/octet-stream","patch_set":16,"id":"a984c08b_67f336c8","line":157,"in_reply_to":"fc3a9237_5f6856aa","updated":"2026-09-18 08:32:15.000000000","message":"done, oob_testdriver is gone, and test_oob.c is part of pkt_testdriver and its tests run as a second cmocka group from test_pkt\u0027s main(),","commit_id":"5b1e911f450ab09703cf02f50846d58bf66fbaeb"}],"tests/unit_tests/openvpn/test_oob.c":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"82b7c79358a277b90e32384368ddd7d14b040989","unresolved":true,"context_lines":[{"line_number":150,"context_line":"    gc_free(\u0026gc);"},{"line_number":151,"context_line":"}"},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"/* Reading a header from a buffer that is too small must fail rather than read"},{"line_number":154,"context_line":" * past the end. */"},{"line_number":155,"context_line":"static void"},{"line_number":156,"context_line":"test_tlv_header_truncated(void **state)"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"72e0985a_82f563a3","line":153,"updated":"2026-07-08 16:13:11.000000000","message":"This comment does not seem to correspond to the test. The buffer is big enough. This tests for malformed TLV headers, doesn\u0027t it?","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"33752b140d06ce90c663b157cbfafe26e758c30c","unresolved":false,"context_lines":[{"line_number":150,"context_line":"    gc_free(\u0026gc);"},{"line_number":151,"context_line":"}"},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"/* Reading a header from a buffer that is too small must fail rather than read"},{"line_number":154,"context_line":" * past the end. */"},{"line_number":155,"context_line":"static void"},{"line_number":156,"context_line":"test_tlv_header_truncated(void **state)"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"5f264f3c_60e1f85c","line":153,"in_reply_to":"5475378e_0edbd3c9","updated":"2026-07-20 13:23:11.000000000","message":"Done","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"bd876f201c986802639f74834919dad3747fb01d","unresolved":true,"context_lines":[{"line_number":150,"context_line":"    gc_free(\u0026gc);"},{"line_number":151,"context_line":"}"},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"/* Reading a header from a buffer that is too small must fail rather than read"},{"line_number":154,"context_line":" * past the end. */"},{"line_number":155,"context_line":"static void"},{"line_number":156,"context_line":"test_tlv_header_truncated(void **state)"}],"source_content_type":"text/x-csrc","patch_set":3,"id":"5475378e_0edbd3c9","line":153,"in_reply_to":"72e0985a_82f563a3","updated":"2026-07-09 13:49:00.000000000","message":"Will rephrase, thanks!","commit_id":"493aec58151150b86fbdc1665e116706b34dcfcf"}]}
