)]}'
{"id":"openvpn~1766","triplet_id":"openvpn~release%2F2.5~I16187153e5b107eb08ccb7c9c9ed4acd6377af0c","project":"openvpn","branch":"release/2.5","hashtags":[],"change_id":"I16187153e5b107eb08ccb7c9c9ed4acd6377af0c","subject":"Backport stricter check for valid tokens","status":"NEW","created":"2026-07-02 11:41:18.000000000","updated":"2026-07-02 11:41:18.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"f42b220232f79fb2641049ca034808fb99c76e72","_number":1766,"virtual_id_number":1766,"owner":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-02 11:41:18.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"}],"messages":[{"id":"04b2dd9e6fff031555e16ba0e3974102c724ddbf","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-02 11:41:18.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"abf505b43e81379893327db19314920f5271556e","revisions":{"abf505b43e81379893327db19314920f5271556e":{"kind":"REWORK","_number":1,"created":"2026-07-02 11:41:18.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/66/1766/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/66/1766/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1 \u0026\u0026 git checkout -b change-1766 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/66/1766/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"37160ee8408150990787eef4a76e0299230ed8d8","subject":"Update Changes.rst"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-05-20 23:07:34.000000000","tz":0},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-02 11:41:07.000000000","tz":120},"subject":"Backport stricter check for valid tokens","message":"Backport stricter check for valid tokens\n\nThis also improves is_auth_token to check for the correct length and\nadds a few unit tests.\n\nOpenVPN 2.5 does not have the logic to keep a session id for the auth\ntoken. So it does not suffer the same problem that 2.6 and 2.7 did\n(CVE 2026-13122).\n\nHowever the improvement that we are a lot stricter to check what might\nbe an auth token is a good thing to backport as well to avoid any other\npotential issues that might be there.\n\nPartial cherry pick from ee119b24b3.\n\nChange-Id: I16187153e5b107eb08ccb7c9c9ed4acd6377af0c\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/release/2.5"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
