)]}'
{"id":"openvpn~1744","triplet_id":"openvpn~master~I930d3789e0313aa0c3bc51ee5fd1d108343d59f0","project":"openvpn","branch":"master","full_branch":"refs/heads/master","topic":"oob-server-probe","attention_set":{"1000041":{"account":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"last_update":"2026-09-29 13:16:31.000000000","reason":"Vote got outdated and was removed: Code-Review+1"},"1000008":{"account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-09-21 10:08:56.000000000","reason":"\u003cGERRIT_ACCOUNT_1000041\u003e replied on the change","reason_account":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}},"1000003":{"account":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-28 15:05:05.000000000","reason":"\u003cGERRIT_ACCOUNT_1000008\u003e replied on the change","reason_account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"}},"1000001":{"account":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-07-28 15:05:05.000000000","reason":"\u003cGERRIT_ACCOUNT_1000008\u003e replied on the change","reason_account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"}}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I930d3789e0313aa0c3bc51ee5fd1d108343d59f0","subject":"oob: Answer probe requests on the server (P_CONTROL_OOB_V1)","status":"NEW","created":"2026-06-29 07:58:31.000000000","updated":"2026-09-30 20:19:52.000000000","submit_type":"CHERRY_PICK","total_comment_count":12,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"52233b4ab902b2188b284004a3016c6b9dc3b330","_number":1744,"virtual_id_number":1744,"owner":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}],"CC":[{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-29 07:58:37.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-06-29 07:58:37.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-07-22 15:43:20.000000000","updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"real_updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"CC"},{"updated":"2026-09-08 08:54:18.000000000","updated_by":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"real_updated_by":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"reviewer":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"state":"REVIEWER"},{"updated":"2026-09-30 10:33:43.000000000","updated_by":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"real_updated_by":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"CC"}],"messages":[{"id":"46eacca47ad175060dfb4606d0bad7560dd49c56","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-06-29 07:58:31.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"903e86e51dcb8a6224bd13fa6b2029aaffdce452","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-06-29 12:37:47.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"a30e02097c429c4bab75d3a7d2dc2ff8c11fd11e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-02 12:30:33.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased. Commit message was updated.","accounts_in_message":[],"_revision_number":3},{"id":"9a6fd68b7820fb25c917fb2ca96340f0236f5450","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:37.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":3},{"id":"8c719daa1a1e3ed784cd7b8a182cf921a93b0bd3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 4: Patch Set 3 was rebased.","accounts_in_message":[],"_revision_number":4},{"id":"08dd146ea8418346c4771af9d887c31f3a798e42","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 5: New patch set was added with same tree, parent tree, and commit message as Patch Set 4.","accounts_in_message":[],"_revision_number":5},{"id":"d7838d27e1ca60a6e66f4f60d1cca3a7bf306e76","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.","accounts_in_message":[],"_revision_number":6},{"id":"9290f9fd3bad11e1b9340d489fdf6f7e9d934d2a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7},{"id":"920e4c74edad050aef719e5da79c741a2eb7050d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-21 12:35:24.000000000","message":"Uploaded patch set 8: Patch Set 7 was rebased.","accounts_in_message":[],"_revision_number":8},{"id":"073c089dabb067d89a6b6d02e5a89aade9e04d9e","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-22 15:43:20.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"8781c6c8d43bdf17bbd6271871b012bd36bb0e48","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 02:06:40.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"0f9669bdcccae874108a989d68654ff7bb42e460","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:03:23.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"b19baff41b9ee3fce184924a760c8ce1772ab57e","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:05:05.000000000","message":"Patch Set 9:\n\n(1 comment)","accounts_in_message":[],"_revision_number":9},{"id":"3917ff56f3f4efa22619faeedb608c0ddc7981f7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-29 12:22:54.000000000","message":"Uploaded patch set 10: Commit message was updated.","accounts_in_message":[],"_revision_number":10},{"id":"faa0b96e7ccf8792f45ba7edb8411ad5c20e0c3a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-04 08:10:28.000000000","message":"Uploaded patch set 11: Patch Set 10 was rebased.","accounts_in_message":[],"_revision_number":11},{"id":"afdaa0452b251eb8fe4eb937365a8dee6c510be2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-28 12:51:00.000000000","message":"Uploaded patch set 12.","accounts_in_message":[],"_revision_number":12},{"id":"f87dcdbd7db457ba45927a834d04ada9a4197018","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-08 08:54:18.000000000","message":"Patch Set 12: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":12},{"id":"6c9090d64d41c4b26770c96025b911eeb46456a9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:27:02.000000000","message":"Uploaded patch set 13.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":13},{"id":"e66a4823f3d14e641ead7eaac31ac1e0290014b1","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:28:14.000000000","message":"Patch Set 13:\n\n(2 comments)","accounts_in_message":[],"_revision_number":13},{"id":"3cbe7fc2f863e3b82147296e8c73565faa6469a5","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-09 11:43:52.000000000","message":"Patch Set 13: Code-Review+1","accounts_in_message":[],"_revision_number":13},{"id":"36c5e7cdb4995b854bdb9de25c346c4c53ab4671","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 09:11:03.000000000","message":"Uploaded patch set 14: Patch Set 13 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":14},{"id":"dfc19e7a7c75036215332524895b318ba012dd18","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-14 14:18:32.000000000","message":"Uploaded patch set 15: Patch Set 14 was rebased. Commit message was updated.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":15},{"id":"b326e07bd93a61b8082f087a83e52214d977be36","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:01:11.000000000","message":"Uploaded patch set 16.","accounts_in_message":[],"_revision_number":16},{"id":"821be8b789213c6f3f14f5d7db3959f347fcdbd4","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-17 13:12:43.000000000","message":"Patch Set 16: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":16},{"id":"5a23249b60032702e04f36d21cb3a849b2c11efb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 08:31:39.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.\n\nCopied Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":17},{"id":"306db9e16c7daa2bd396a33a4af45d2d71a81813","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 12:52:57.000000000","message":"Uploaded patch set 18.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":18},{"id":"a3514ef0a123133df83c80384b822c93880d8521","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 12:53:08.000000000","message":"Patch Set 17:\n\n(2 comments)","accounts_in_message":[],"_revision_number":17},{"id":"b72f4c341512ebdbdfc835d326467a1f5be7a4d9","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-21 10:08:56.000000000","message":"Patch Set 18: Code-Review+1","accounts_in_message":[],"_revision_number":18},{"id":"08615a129b9f5feb34afa5ac5383e1ce7273984f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-29 13:16:31.000000000","message":"Uploaded patch set 19.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":19},{"id":"d4531e612b1450060ed6b04b3b78ed6edfa42eb6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-30 08:25:29.000000000","message":"Uploaded patch set 20.","accounts_in_message":[],"_revision_number":20},{"id":"29c4536ad37e0077a22075e61a5fbe8e1615b876","author":{"_account_id":1000053,"name":"Răzvan Cojocaru","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-09-30 10:33:43.000000000","message":"Patch Set 20:\n\n(1 comment)","accounts_in_message":[],"_revision_number":20},{"id":"52233b4ab902b2188b284004a3016c6b9dc3b330","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-30 20:19:52.000000000","message":"Uploaded patch set 21: Patch Set 20 was rebased.","accounts_in_message":[],"_revision_number":21}],"current_revision_number":21,"current_revision":"52704745d4a760fe188a67157a650f7f40d73b9b","revisions":{"ba0990d5a06591518855e29695471871e113fbb5":{"kind":"REWORK","_number":1,"created":"2026-06-29 07:58:31.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4affc7258b2f3dffdf52640e3ba3705f405fae9e","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-29 07:58:02.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\noob.c is now wired into the openvpn build as it has a real caller.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"1982fb92635656a27559b8dde680921cb44f5e14":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-06-29 12:37:47.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f97b53396d0eedce335444a305505194107f6d13","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-29 12:32:06.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\noob.c is now wired into the openvpn build as it has a real caller.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"b1489c94ae9907d1f279ee9a9b1d9e4386eac51c":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":3,"created":"2026-07-02 12:30:33.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"7f5cd4fa48a346b91bbc1e7c52c1d6351e8cc61c","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-02 12:11:48.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d97d24573d0a99ec35bed9c4b70c0523af569894":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"a42fcc7cb35546e3b6e785928aa11e08365b68bc","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:43.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"b683e121d51a5cfa6f234373f89c19a49f9ce60c":{"kind":"NO_CHANGE","_number":5,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/5","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/5","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"18b9dcaa9e90f521ba97e58da6cdd733a0fa0534","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:52.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"fc2d2365dbc10b892639227518749bce7cc159fa":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/6","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/6","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"909e8c5f8911951ab767a6b7f1f9216cb9b91d38","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:14:32.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"335ff6a72e466bea1e50f2ee666bdf5e846ae1c1":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/7","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/7","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"c46db4fb2223a358944d3fe8c58a662778cd0ca7","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:35.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"c615b953bdde58c49ce0609f5f8ca62efdbe1460":{"kind":"TRIVIAL_REBASE","_number":8,"created":"2026-07-21 12:35:24.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/8","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/8","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"5999125a3c2d172cc9356b7bd76f4218c226d7b3","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-21 12:30:44.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime shortcut).\n\nP_LAST_OPCODE is intentionally not widened: the server path uses the\ntls_pre_decrypt_lite() allowlist and tls_wrap_control() directly, so opcode 12\nneed not pass the established-session opcode gate yet. That gate (and the\nmatching tls_pre_decrypt() handler) is widened together with the client\nreceive path.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"9565b10bbed5fd91897e7f84ade40811017c7d28":{"kind":"REWORK","_number":9,"created":"2026-07-28 15:03:23.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/9","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/9","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d66ee893ec450b110a39d65e67190f452065b9eb","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-28 15:00:12.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so probes cannot be used\n    to make the server answer faster than a reset flood could.\n\nThe reply\u0027s own session id is the stateless SYN-cookie used by the three-way\nhandshake, so the responder keeps no state and the reply can later serve as\nthe handshake reset (connect_lifetime advertisement).\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"e5a33e0ee7ca63abf1e975bbf4124eec6630a39c":{"kind":"NO_CODE_CHANGE","_number":10,"created":"2026-07-29 12:22:54.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/10","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/10","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"afe9726f7ebb810648544f6e78739cf1bc40cb9a","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-29 11:06:12.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"f21a8b51573cc6ee0979059dda77c0138eaf64c9":{"kind":"TRIVIAL_REBASE","_number":11,"created":"2026-08-04 08:10:28.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/11","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/11","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"154bfeb0b78d920dc16e5f426bd04e969894531c","subject":"mudp: extract send_standalone_reply() helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-04 08:08:32.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a5e4c6c7420d0a40fd560f4b51a5e3796d101fec":{"kind":"REWORK","_number":12,"created":"2026-08-28 12:51:00.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/12","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/12","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8a45bcacebf903eea3c03773a73159560a6ea3ee","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-28 11:20:58.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_build_probe_reply() whether to answer, and if so sends a PROBE_REPLY\n    via send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"67f1661f3e35af061ceec0138e4083e89321c541":{"kind":"REWORK","_number":13,"created":"2026-09-09 07:27:02.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/13","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/13","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8cf9b7955aa320f7fb32dd205689c8c577bf4b43","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-09 06:51:58.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_server_probe_accept() whether to answer, and if so builds the\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"f1342a4e5de8eff48e410d5206e6fa690111d066":{"kind":"TRIVIAL_REBASE","_number":14,"created":"2026-09-11 09:11:03.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/14","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/14","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"21a93d5823d18cf501738360450ae56c0574b5bd","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 09:03:49.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_server_probe_accept() whether to answer, and if so builds the\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8ebeaebde3b115cfe542eeed404c2ec0e810927f":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":15,"created":"2026-09-14 14:18:32.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/15","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/15","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"59a6b578f3df7a070b2b213db4f5a1e75a4dc416","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-14 08:10:54.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\r\n\r\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\r\ncreating a session, so probing costs the server no state:\r\n\r\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\r\n    VERDICT_VALID_OOB_V1 verdict.\r\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\r\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\r\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\r\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\r\n    header + probe_reply TLV).\r\n  - do_pre_decrypt_check() handles the new verdict: it asks\r\n    oob_server_probe_accept() whether to answer, and if so builds the\r\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\r\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\r\n    and returns false so no session is created. The verdict joins the reset\r\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\r\n    like a reset flood.\r\n\r\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\r\nhandshake uses, so the server keeps nothing per probe and a client can later\r\nreuse the reply as the server\u0027s reset.\r\n\r\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\r\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\r\n"},"branch":"refs/heads/master"},"010736ef7f721f4841eb67570de51563739399a5":{"kind":"REWORK","_number":16,"created":"2026-09-17 07:01:11.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/16","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/16","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ec37a5e65da7ada1e6e470eaa6af7c187a3da8bf","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 06:48:10.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_server_probe_accept() whether to answer, and if so builds the\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"46cad7fe12200e06128793f923efef3e05c98ab3":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-09-18 08:31:39.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/17","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/17","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"caff45b39c8172a2ae51c446d79e48effcc1ce7c","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 08:26:41.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_server_probe_accept() whether to answer, and if so builds the\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"ea6de1a0f171b515b904ea85a93a9b819798d8c0":{"kind":"REWORK","_number":18,"created":"2026-09-18 12:52:57.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/18","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/18","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"caff45b39c8172a2ae51c446d79e48effcc1ce7c","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 12:45:01.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE without\ncreating a session, so probing costs the server no state:\n\n  - tls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\n    VERDICT_VALID_OOB_V1 verdict.\n  - tls_wrap_oob_standalone() builds a session-less P_CONTROL_OOB_V1 packet:\n    opcode + session id + the usual tls-auth/tls-crypt wrapping around a bare\n    TLV payload (no reliability/ACK fields), mirroring tls_reset_standalone().\n  - oob_client_reply_write() writes the PROBE_REPLY message (message-type\n    header + probe_reply TLV).\n  - do_pre_decrypt_check() handles the new verdict: it asks\n    oob_server_probe_accept() whether to answer, and if so builds the\n    PROBE_REPLY, echoing the peer\u0027s session id, and sends it via\n    send_probe_reply() (synchronous, stateless, like the HMAC reset path)\n    and returns false so no session is created. The verdict joins the reset\n    verdicts in the reflect_filter rate-limit check, so a probe flood is capped\n    like a reset flood.\n\nThe reply carries, as its own session id, the stateless SYN-cookie the three-way\nhandshake uses, so the server keeps nothing per probe and a client can later\nreuse the reply as the server\u0027s reset.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"44bd8f0869c586469dcbc122453b2e96aa931631":{"kind":"REWORK","_number":19,"created":"2026-09-29 13:16:31.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/19","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/19","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ccc37cf08d2a5c5c96443e43deb35051a7cdb115","subject":"oob: Add SERVER_PROBE parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-29 13:05:04.000000000","tz":180},"subject":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)","message":"oob: Answer SERVER_PROBE on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band SERVER_PROBE\nwithout creating a session, so probing costs the server no state.\n\ntls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\nVERDICT_VALID_OOB_V1, and tls_wrap_oob_standalone() wraps a bare OOB\nmessage with the usual tls-auth/tls-crypt wrapping but no reliability\nfields, mirroring tls_reset_standalone(). do_pre_decrypt_check()\nclassifies the probe with oob_server_probe_check() and answers with a\nPROBE_REPLY that echoes the probe\u0027s request_id.\n\nA reply is charged against the same rate limit as the reset replies,\nonce one is going to be sent, so a probe flood is capped like a reset\nflood. A stale probe, one whose timestamp is outside --hand-window, is\nstill answered, but only within a separate budget of a twentieth of\n--connect-freq-initial per period (at least one): a client with a\nskewed clock can still probe, and a replayed probe gets no more than\nthat budget. The budget\u0027s limiter is quiet, as a replayed probe\nhitting it is not worth a warning.\n\nThe reply carries, as its own session id, the stateless SYN cookie the\nthree-way handshake uses, so the server keeps nothing per probe and a\nclient can later start the handshake from the reply.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"0160c1f0066118d78f9fcc46420134293de271b1":{"kind":"REWORK","_number":20,"created":"2026-09-30 08:25:29.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/20","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/20","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"970640f977539543ecd8fe58ab07cc900cc4669e","subject":"oob: Add probe request parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-30 08:13:01.000000000","tz":180},"subject":"oob: Answer probe requests on the server (P_CONTROL_OOB_V1)","message":"oob: Answer probe requests on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band probe request\nwithout creating a session, so probing costs the server no state.\n\ntls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\nVERDICT_VALID_OOB_V1, and tls_wrap_oob_standalone() wraps a bare OOB\nmessage with the usual tls-auth/tls-crypt wrapping but no reliability\nfields, mirroring tls_reset_standalone(). do_pre_decrypt_check()\nclassifies the probe with oob_probe_request_check() and answers with a\nprobe reply that echoes the probe\u0027s request_id.\n\nA reply is charged against the same rate limit as the reset replies,\nonce one is going to be sent, so a probe flood is capped like a reset\nflood. A stale probe, one whose timestamp is outside --hand-window, is\nstill answered, but only within a separate budget of a twentieth of\n--connect-freq-initial per period (at least one): a client with a\nskewed clock can still probe, and a replayed probe gets no more than\nthat budget. The budget\u0027s limiter is quiet, as a replayed probe\nhitting it is not worth a warning.\n\nThe reply carries, as its own session id, the stateless SYN cookie the\nthree-way handshake uses, so the server keeps nothing per probe and a\nclient can later start the handshake from the reply.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"52704745d4a760fe188a67157a650f7f40d73b9b":{"kind":"TRIVIAL_REBASE","_number":21,"created":"2026-09-30 20:19:52.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/44/1744/21","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/44/1744/21","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21 \u0026\u0026 git checkout -b change-1744 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/44/1744/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"653260954600e160459fcfe677583bcb99e55a98","subject":"oob: Add probe request parsing and the probe-reply decision"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-18 13:00:14.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-30 18:15:02.000000000","tz":180},"subject":"oob: Answer probe requests on the server (P_CONTROL_OOB_V1)","message":"oob: Answer probe requests on the server (P_CONTROL_OOB_V1)\n\nMake a --mode server UDP listener answer an out-of-band probe request\nwithout creating a session, so probing costs the server no state.\n\ntls_pre_decrypt_lite() accepts P_CONTROL_OOB_V1 and returns the new\nVERDICT_VALID_OOB_V1, and tls_wrap_oob_standalone() wraps a bare OOB\nmessage with the usual tls-auth/tls-crypt wrapping but no reliability\nfields, mirroring tls_reset_standalone(). do_pre_decrypt_check()\nclassifies the probe with oob_probe_request_check() and answers with a\nprobe reply that echoes the probe\u0027s request_id.\n\nA reply is charged against the same rate limit as the reset replies,\nonce one is going to be sent, so a probe flood is capped like a reset\nflood. A stale probe, one whose timestamp is outside --hand-window, is\nstill answered, but only within a separate budget of a twentieth of\n--connect-freq-initial per period (at least one): a client with a\nskewed clock can still probe, and a replayed probe gets no more than\nthat budget. The budget\u0027s limiter is quiet, as a replayed probe\nhitting it is not worth a warning.\n\nThe reply carries, as its own session id, the stateless SYN cookie the\nthree-way handshake uses, so the server keeps nothing per probe and a\nclient can later start the handshake from the reply.\n\nChange-Id: I930d3789e0313aa0c3bc51ee5fd1d108343d59f0\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}]}
