)]}'
{"id":"openvpn~1768","triplet_id":"openvpn~master~Ib2b6c2246f9d9c0a505292ee8d879f714901ffae","project":"openvpn","branch":"master","topic":"oob-server-probe","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-06 06:50:54.000000000","reason":"Reviewer was added"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"Ib2b6c2246f9d9c0a505292ee8d879f714901ffae","subject":"oob: advertise a connect_lifetime handshake shortcut","status":"NEW","created":"2026-07-06 06:50:47.000000000","updated":"2026-07-16 08:09:01.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"e841c6f48db2e82f7c8d8630dde2268573c865af","_number":1768,"virtual_id_number":1768,"owner":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-06 06:50:54.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-06 06:50:54.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"f8f21c1eef9c88de2818bf275892c44b52bc3a5d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 06:50:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"b59db3358946ccb8d082d997a72f84aa51551463","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:41.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":1},{"id":"820d3275c266d86920ded1b9ee1929f6cb4a93fb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 08:22:28.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"f774bbd766ecebc0221bda6f183438e635fdb5d7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"0ce2ec44b7d9feef2c8b71912cfbbc0a348899e5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 4: New patch set was added with same tree, parent tree, and commit message as Patch Set 3.","accounts_in_message":[],"_revision_number":4},{"id":"c6f637d90b09ce6ff8281dbf6b5371042db661d9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.","accounts_in_message":[],"_revision_number":5},{"id":"48d1962cb48d1c534a56ed314d5c5278ac10b550","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 07:54:14.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.","accounts_in_message":[],"_revision_number":6},{"id":"e841c6f48db2e82f7c8d8630dde2268573c865af","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"7bf1531091c139fdbb5a05319e08215941444d98","revisions":{"0d31896c89ab6af6d01adf0b3bc129befac23d7d":{"kind":"REWORK","_number":1,"created":"2026-07-06 06:50:47.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"b2be2dba3b616fac4dac010aa2df48273a389427","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a6a55ba6774a9ef192f1d5d2199f884054fb5d65":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-07-06 08:22:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"98c54b419aaa097b2202d807ae29a686d20792fa","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-06 08:20:50.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"43ceb2e492d54654a2b7b5f19ade691f4e013155":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"7e513b6bc4426f477718a824ca6085a8a96f249e","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:44.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5780c56d2a1649851153bbeec6d01fd84fd30e59":{"kind":"NO_CHANGE","_number":4,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9c1a29e6ae3bc934bf9e31e1b3572fb85f85775c","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:53.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8e7f1823d71d8c710e8abb62cd12dfc7d8f58464":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"612a1a2662619a5d7abf5dd08458bdc7d0f40778","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:22:23.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"83d11cf4cfe70ee315d8c66b4416e6a076fa511a":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-16 07:54:14.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9e77992ce4682ed00a1c4a2ceee2a531c1f88035","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 07:42:19.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"7bf1531091c139fdbb5a05319e08215941444d98":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"17496b0a6548cedeae83ecbf96ad36909e59300f","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:36.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
