)]}'
{"id":"openvpn~1750","triplet_id":"openvpn~master~I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac","project":"openvpn","branch":"master","full_branch":"refs/heads/master","topic":"oob-server-probe","attention_set":{"1000041":{"account":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"last_update":"2026-09-29 13:16:31.000000000","reason":"Vote got outdated and was removed: Code-Review+1"},"1000008":{"account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-09-16 09:22:03.000000000","reason":"\u003cGERRIT_ACCOUNT_1000041\u003e replied on the change","reason_account":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}},"1000003":{"account":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-06-29 07:58:39.000000000","reason":"Reviewer was added"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac","subject":"oob: Wrap the client probe request with tls-auth/tls-crypt","status":"NEW","created":"2026-06-29 07:58:31.000000000","updated":"2026-09-30 20:19:52.000000000","submit_type":"CHERRY_PICK","total_comment_count":3,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"371cf87bfffb53ae98ea839dc47aa71218486a6f","_number":1750,"virtual_id_number":1750,"owner":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-29 07:58:39.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-06-29 07:58:39.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-09-14 14:35:25.000000000","updated_by":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"real_updated_by":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"reviewer":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"state":"REVIEWER"}],"messages":[{"id":"f0cbb925b82d77515db2a8dc4a0db6446b316f02","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-06-29 07:58:31.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"196d00bd9daa6ae329bf115eca7b351ecda18678","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-06-29 12:08:26.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"318055cd80c32475d5d1d3c7cf4a152086d3c5cd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-06-29 12:37:47.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"7b85766775d16e75af8e5df4f517dce9614463d2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-02 12:30:33.000000000","message":"Uploaded patch set 4: Patch Set 3 was rebased.","accounts_in_message":[],"_revision_number":4},{"id":"b0b093e30d1ad6b5f804ec99b37787ad9268fbcc","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 06:50:47.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"af1c02442933cffa3cd1a50add11468fc589efff","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:39.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":5},{"id":"e9693a49bbfa55286b10cd58344c2a4aaa65ffcb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 08:22:28.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.","accounts_in_message":[],"_revision_number":6},{"id":"16601d1ad479202612dfdaa9c2bd4cebfed10c7f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7},{"id":"2bccc893c0739ee079d1d3c629e8a4e4fe288209","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 8: New patch set was added with same tree, parent tree, and commit message as Patch Set 7.","accounts_in_message":[],"_revision_number":8},{"id":"d462cffbbd7e62b898ffae1d943529253c7b888c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"3cccbccf607606fa770e9250e566a90d63f04a23","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 07:54:14.000000000","message":"Uploaded patch set 10: Patch Set 9 was rebased.","accounts_in_message":[],"_revision_number":10},{"id":"f5ccde405b21b4b2011f5261ea81c7db87e8f660","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 11: Patch Set 10 was rebased.","accounts_in_message":[],"_revision_number":11},{"id":"36bc4c3ec063dbe5c1b1fd7056530b66ca5bbe6a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-21 12:35:24.000000000","message":"Uploaded patch set 12: Patch Set 11 was rebased.","accounts_in_message":[],"_revision_number":12},{"id":"4a7048cbde69474f25a6c5df1ef559ee4df83899","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:03:23.000000000","message":"Uploaded patch set 13: Patch Set 12 was rebased.","accounts_in_message":[],"_revision_number":13},{"id":"2c0b50a8ecffb6689c386e2081ed6742b47bc7fc","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-29 12:22:54.000000000","message":"Uploaded patch set 14.","accounts_in_message":[],"_revision_number":14},{"id":"29d72ba889744c69127e063687dbc31e3d89d0d8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-04 08:10:28.000000000","message":"Uploaded patch set 15: Patch Set 14 was rebased.","accounts_in_message":[],"_revision_number":15},{"id":"01c3d4712b0b02ad8a70c05fdce5ae27a7c095aa","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-28 12:51:00.000000000","message":"Uploaded patch set 16: Patch Set 15 was rebased.","accounts_in_message":[],"_revision_number":16},{"id":"fece0acd0a85fd7293c5e50a099044c4358652bf","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:27:02.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.","accounts_in_message":[],"_revision_number":17},{"id":"2bee49ead7c4aa8926592b3702758cc664ab31df","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 08:18:16.000000000","message":"Uploaded patch set 18.","accounts_in_message":[],"_revision_number":18},{"id":"a36cebc874a6bc3235f821fd09cf887ef01cc6c2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 09:11:03.000000000","message":"Uploaded patch set 19: Patch Set 18 was rebased.","accounts_in_message":[],"_revision_number":19},{"id":"73ee2e3ef6185c54e49943fd867a50c616ededc7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-14 14:18:32.000000000","message":"Uploaded patch set 20.","accounts_in_message":[],"_revision_number":20},{"id":"c20e8c90cb245ec818467ea51e5bde564aa5aee5","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-14 14:35:25.000000000","message":"Patch Set 20: Code-Review+1\n\n(2 comments)","accounts_in_message":[],"_revision_number":20},{"id":"5dead22d21dca4a8fbbf9e76c9797beb240b3d9e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 06:23:31.000000000","message":"Uploaded patch set 21.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":21},{"id":"46137913ccba04f834f6270fd057a0941381858a","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 06:24:11.000000000","message":"Patch Set 21:\n\n(1 comment)","accounts_in_message":[],"_revision_number":21},{"id":"493abf8ad3f9b514fe50a8c395ff177340091bbd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 12:59:19.000000000","message":"Uploaded patch set 22.","accounts_in_message":[],"_revision_number":22},{"id":"c4b56e0a47017e29de7e49ac6f80ce615dd65276","author":{"_account_id":1000041,"name":"Ralf Lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-09-16 09:22:03.000000000","message":"Patch Set 22: Code-Review+1","accounts_in_message":[],"_revision_number":22},{"id":"729a2b2c00988ffd72a926ad1b18a03392b9c957","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:01:11.000000000","message":"Uploaded patch set 23: Patch Set 22 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":23},{"id":"02fb671585de1df5f2a73545659bf69b554aed34","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 11:30:36.000000000","message":"Uploaded patch set 24: Patch Set 23 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":24},{"id":"bd925469018ebfb2088825ecbdf52c821fe804b8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 12:28:12.000000000","message":"Uploaded patch set 25: Patch Set 24 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":25},{"id":"1b4884e69a4d7873ce48a308a9abd74eff964cc6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 08:31:39.000000000","message":"Uploaded patch set 26: Patch Set 25 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":26},{"id":"b3961d0721fe31e41b0b14490f40e03e169bb819","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-22 13:11:05.000000000","message":"Uploaded patch set 27: Patch Set 26 was rebased.\n\nCopied Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":27},{"id":"ca11da08fadad6cd704556e10e39e00206685dfd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-29 13:16:31.000000000","message":"Uploaded patch set 28.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":28},{"id":"d5252b5f8fc651c33c4fc291a2d3b74b9e2bd477","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-30 08:25:29.000000000","message":"Uploaded patch set 29.","accounts_in_message":[],"_revision_number":29},{"id":"371cf87bfffb53ae98ea839dc47aa71218486a6f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-30 20:19:52.000000000","message":"Uploaded patch set 30: Patch Set 29 was rebased.","accounts_in_message":[],"_revision_number":30}],"current_revision_number":30,"current_revision":"384c4f418585ba5e69a14edef90387cb7071aa17","revisions":{"12f4da05d164693c6888eafa9b272cfdd329b77e":{"kind":"REWORK","_number":1,"created":"2026-06-29 07:58:31.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3c9d06f404680f612acaf7e9bc1f71b34fca7179","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-29 07:58:03.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6a3bf7c29972a35367a7d971181e56750a3d7b9d":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-06-29 12:08:26.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9760ca98da2c9413eab663f46ace226e6057b1ff","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-29 11:45:13.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6a79f04723e88b7018a6496c2fe83b87e498e3ed":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-06-29 12:37:47.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"637774cfce1046c89940e0cbab8cebe2c82af9f9","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-29 12:32:06.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"35d1eb7016e383b3926210b997e27bd4753eed21":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2026-07-02 12:30:33.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d98910685128fd6f92b5bd95e180082a92b4e84f","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-02 12:11:49.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5472f7c1a5d685cbe385e5bab59e156315b53b52":{"kind":"REWORK","_number":5,"created":"2026-07-06 06:50:47.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/5","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/5","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2cda9b9d7980c20f37548a4f9c62b67bb3bdeaed","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:44:00.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a1d7253ce5b83fae17ad307c828cf37a234f21d2":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-06 08:22:28.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/6","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/6","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ab578511a6cf46734339fd81182a0be1607b97b5","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-06 08:20:50.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"bc5e4a1f4f6e504a6ac9e9f7a461be79d104f3c8":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/7","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/7","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ac35e6514a9a9966adfbffe4e3b8f6e848ba5410","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:44.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"1b6bd4878c83e9aff167508cbe99f91dffdf6d07":{"kind":"NO_CHANGE","_number":8,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/8","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/8","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"74a838b58557ea0e0291e25dccda28d7e0e7f1bd","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:52.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"08c04cc3342a367667db6af214d9973b0cd7d15a":{"kind":"REWORK","_number":9,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/9","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/9","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"40b989fe798cd2553ea526d6304ec859cb80095a","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:22:23.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"023abcb1e9c2c6c2f80011aee8cafe3b7bdeec82":{"kind":"TRIVIAL_REBASE","_number":10,"created":"2026-07-16 07:54:14.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/10","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/10","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"64e68d8ee5edb8467cc92477036d990b2b3eb03c","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 07:41:38.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"3fcc29d999f1d94fb1546f2683d851c3d16f0e03":{"kind":"TRIVIAL_REBASE","_number":11,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/11","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/11","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e0d2bd1347f9e0dc2219cedd2ac91eec1d0e7e6d","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:36.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"2f43f370ca6e6433932bc1587112ce5e2f65d9eb":{"kind":"TRIVIAL_REBASE","_number":12,"created":"2026-07-21 12:35:24.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/12","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/12","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"984ed88395987dd32f243c2fd6b77886d7070e1b","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-21 12:30:45.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"0444fae6648408f69b55bdd11d64fdb9d96bbf16":{"kind":"TRIVIAL_REBASE","_number":13,"created":"2026-07-28 15:03:23.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/13","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/13","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"27d2ad2e2dd7a61cfc4ade257444ecbc77f3a0df","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-28 15:00:13.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does).\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"9f3567b3c8c3b33c9f2953861e313f1b20276557":{"kind":"REWORK","_number":14,"created":"2026-07-29 12:22:54.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/14","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/14","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"07337d595cf3d6fd11a4e40f7366effdb7b2e6a8","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-29 12:06:53.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d84ed89b69218a5331deaf3962dd036b0bcc6f03":{"kind":"TRIVIAL_REBASE","_number":15,"created":"2026-08-04 08:10:28.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/15","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/15","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"467a1bfa16db28f5373b938a65e036b608ff944d","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-04 08:08:33.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"fae033fb17cf13e8f7e9d4fcecf143d3130ddf5f":{"kind":"TRIVIAL_REBASE","_number":16,"created":"2026-08-28 12:51:00.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/16","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/16","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"87f2992be4b5eced7fa04e4daab592cd24b04bee","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-28 12:33:23.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"96503c52a57bb085acdaa0747b3503df45ee5f05":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-09-09 07:27:02.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/17","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/17","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"786b69e40760e509e94090549e1624ee7c82de02","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-09 06:52:00.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"9603e06393f7ec72519197dfa7ea61a30a8b758b":{"kind":"REWORK","_number":18,"created":"2026-09-11 08:18:16.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/18","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/18","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2df0fffe1554b26361e7c7727a3f5716a01d782b","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 08:10:23.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6253892b75073df45eb365d15f20fa3a3099993f":{"kind":"TRIVIAL_REBASE","_number":19,"created":"2026-09-11 09:11:03.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/19","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/19","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"826f7e6e998dd83d1b7caf2d089a6a595ba58ca2","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 09:03:51.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to before,\nso the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"7ae449254bdf2e78c59214b71fe4e36cf389e76d":{"kind":"REWORK","_number":20,"created":"2026-09-14 14:18:32.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/20","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/20","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"98f9ff2f77d8fa738a51db8473ea596415c94843","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-14 13:44:48.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the first remote\u0027s key, so probing is declined\nwhen another remote is keyed differently. The key material loaded for\nthe probe is released afterwards; init loads it again for the\nconnection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d0fffc509e1a69b7d24ec755451a4d8a8acb23e2":{"kind":"REWORK","_number":21,"created":"2026-09-15 06:23:31.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/21","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/21","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"98f9ff2f77d8fa738a51db8473ea596415c94843","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 05:32:37.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"fef050d631e4f3c467777a59a8f495251ceac0fa":{"kind":"REWORK","_number":22,"created":"2026-09-15 12:59:19.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/22","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/22","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/22 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6a955de5896427b8f9afe11d688e6413fe5ccfcf","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 12:49:01.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5a05d6d5c50389634b9c23bb93725acec31f0c2a":{"kind":"TRIVIAL_REBASE","_number":23,"created":"2026-09-17 07:01:11.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/23","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/23","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/23 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"339db8515e5cf80c66ad78d8a56361bee1ac76b5","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 06:52:30.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d6730d8df0654d9d2a16a548aa5e5ce69b2dbef5":{"kind":"TRIVIAL_REBASE","_number":24,"created":"2026-09-17 11:30:36.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/24","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/24","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/24 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"be9877c95e8c0f036ae1cb0157b0a710305b56d2","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:54:06.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d08be9944431210e97454289e93ded1cff023929":{"kind":"TRIVIAL_REBASE","_number":25,"created":"2026-09-17 12:28:12.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/25","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/25","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/25 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"a546fb4d13544e6fda8f7fd04249cddbe3925d54","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 11:45:25.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"dcf8b219f47bd48ae2329abe895904a09ba0dc84":{"kind":"TRIVIAL_REBASE","_number":26,"created":"2026-09-18 08:31:39.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/26","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/26","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/26 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"42d27471c1343394196474ede1d7b7f5b9ec378a","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 08:26:42.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"ab147aa1629539b52243fcb67a6e47a1728a0850":{"kind":"TRIVIAL_REBASE","_number":27,"created":"2026-09-22 13:11:05.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/27","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/27","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/27 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"1a55669c568b3eba671a1117806bbb0595bfb523","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 12:45:02.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe previously sent a plaintext SERVER_PROBE and\nparsed replies by hand, so it only worked against a server with no\ncontrol-channel wrapping. Build a standalone wrapping context for the\nprobe (mirroring the server\u0027s tls_auth_standalone) and route both the\noutgoing probe and the incoming replies through the same control-channel\npath the rest of the code uses:\n\n  - tls_wrap_oob_standalone() wraps the probe payload, applying the\n    tls-auth HMAC or tls-crypt encryption (or nothing, when neither is\n    configured).\n  - read_control_auth() unwraps each reply, verifying the HMAC /\n    decrypting and stripping the opcode + session id, on a per-packet\n    copy of the wrapping context (as tls_pre_decrypt_lite() does). It\n    decrypts in place, so oob_probe_handle_reply() now takes a mutable\n    buffer.\n\nWith neither tls-auth nor tls-crypt configured the context stays in\nTLS_WRAP_NONE and the on-wire probe is byte-for-byte identical to\nbefore, so the plaintext case is unchanged.\n\ntls-crypt-v2 is not supported yet: the server only learns the client key\nfrom the WKc carried in the TLS handshake, which an out-of-band probe\ncannot provide. Such configurations skip probing and keep the configured\nremote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"70f2a3018386bce458c1658391c3e556af95e067":{"kind":"REWORK","_number":28,"created":"2026-09-29 13:16:31.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/28","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/28","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/28 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8ae8b68ff2e316997d1ba6d832dbcfb9cdc159ee","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-29 13:05:06.000000000","tz":180},"subject":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt","message":"oob: Wrap the client SERVER_PROBE with tls-auth/tls-crypt\n\nThe client --server-probe sent a plaintext SERVER_PROBE and parsed\nreplies by hand, so it only worked against a server with no\ncontrol-channel wrapping.\n\nBuild a standalone wrapping context for the probe, mirroring the\nserver\u0027s tls_auth_standalone, and send probes and unwrap replies through\nthe regular control-channel path (tls_wrap_oob_standalone() and\nread_control_auth()). Replies are unwrapped on a per-packet copy of the\ncontext, as tls_pre_decrypt_lite() does. Each transmission is wrapped on\nits own, as each carries its own request_id; with tls-auth or tls-crypt\nthat also gives each its own replay packet id. Without either, the\nprobe goes out in plaintext as before.\n\ntls-crypt-v2 is not supported yet: the server only learns the client\nkey from the WKc carried in the TLS handshake, which an out-of-band\nprobe cannot provide. Such configurations skip probing and keep the\nconfigured remote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"eba94b5d13c734281738d6a01ded685b8186042d":{"kind":"REWORK","_number":29,"created":"2026-09-30 08:25:29.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/29","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/29","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/29 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"aad13f822a304c802df8f49c13896167a80203ce","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-30 08:13:01.000000000","tz":180},"subject":"oob: Wrap the client probe request with tls-auth/tls-crypt","message":"oob: Wrap the client probe request with tls-auth/tls-crypt\n\nThe client --server-probe sent a plaintext probe request and parsed\nreplies by hand, so it only worked against a server with no\ncontrol-channel wrapping.\n\nBuild a standalone wrapping context for the probe, mirroring the\nserver\u0027s tls_auth_standalone, and send probes and unwrap replies through\nthe regular control-channel path (tls_wrap_oob_standalone() and\nread_control_auth()). Replies are unwrapped on a per-packet copy of the\ncontext, as tls_pre_decrypt_lite() does. Each transmission is wrapped on\nits own, as each carries its own request_id; with tls-auth or tls-crypt\nthat also gives each its own replay packet id. Without either, the\nprobe goes out in plaintext as before.\n\ntls-crypt-v2 is not supported yet: the server only learns the client\nkey from the WKc carried in the TLS handshake, which an out-of-band\nprobe cannot provide. Such configurations skip probing and keep the\nconfigured remote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n\n"},"branch":"refs/heads/master"},"384c4f418585ba5e69a14edef90387cb7071aa17":{"kind":"TRIVIAL_REBASE","_number":30,"created":"2026-09-30 20:19:52.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/50/1750/30","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1750/30","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30 \u0026\u0026 git checkout -b change-1750 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/50/1750/30 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"81a8b4e613c339ca31cfc40884b91757011a2c6a","subject":"oob: Extract init_tls_wrap_ctx() control-channel wrap helper"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-06-23 07:16:15.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-30 18:15:02.000000000","tz":180},"subject":"oob: Wrap the client probe request with tls-auth/tls-crypt","message":"oob: Wrap the client probe request with tls-auth/tls-crypt\n\nThe client --server-probe sent a plaintext probe request and parsed\nreplies by hand, so it only worked against a server with no\ncontrol-channel wrapping.\n\nBuild a standalone wrapping context for the probe, mirroring the\nserver\u0027s tls_auth_standalone, and send probes and unwrap replies through\nthe regular control-channel path (tls_wrap_oob_standalone() and\nread_control_auth()). Replies are unwrapped on a per-packet copy of the\ncontext, as tls_pre_decrypt_lite() does. Each transmission is wrapped on\nits own, as each carries its own request_id; with tls-auth or tls-crypt\nthat also gives each its own replay packet id. Without either, the\nprobe goes out in plaintext as before.\n\ntls-crypt-v2 is not supported yet: the server only learns the client\nkey from the WKc carried in the TLS handshake, which an out-of-band\nprobe cannot provide. Such configurations skip probing and keep the\nconfigured remote order.\n\nThe probe is wrapped with the key of the first remote we can probe --\nthe same entry the other probed remotes are compared against -- so\nprobing is declined when another one of them is keyed differently. The\nkey material loaded for the probe is released afterwards; init loads it\nagain for the connection.\n\nChange-Id: I1f9d7b5a5ec19bf77c0c212795f583c5ba4c03ac\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}]}
