)]}'
{"id":"openvpn~1768","triplet_id":"openvpn~master~Ib2b6c2246f9d9c0a505292ee8d879f714901ffae","project":"openvpn","branch":"master","full_branch":"refs/heads/master","topic":"oob-server-probe","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-17 11:49:50.000000000","reason":"\u003cGERRIT_ACCOUNT_1000008\u003e replied on the change","reason_account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"}}},"removed_from_attention_set":{"1000008":{"account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-08-17 11:49:50.000000000","reason":"\u003cGERRIT_ACCOUNT_1000008\u003e replied on the change","reason_account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"}}},"hashtags":[],"change_id":"Ib2b6c2246f9d9c0a505292ee8d879f714901ffae","subject":"oob: advertise a connect_lifetime in the probe reply","status":"NEW","created":"2026-07-06 06:50:47.000000000","updated":"2026-09-18 08:31:39.000000000","submit_type":"CHERRY_PICK","total_comment_count":4,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"5d0eac55c3920ec3c090cde98ff4b1d65a60eb81","_number":1768,"virtual_id_number":1768,"owner":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}],"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-06 06:50:54.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-06 06:50:54.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"f8f21c1eef9c88de2818bf275892c44b52bc3a5d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 06:50:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"b59db3358946ccb8d082d997a72f84aa51551463","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:41.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":1},{"id":"820d3275c266d86920ded1b9ee1929f6cb4a93fb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 08:22:28.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"f774bbd766ecebc0221bda6f183438e635fdb5d7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"0ce2ec44b7d9feef2c8b71912cfbbc0a348899e5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 4: New patch set was added with same tree, parent tree, and commit message as Patch Set 3.","accounts_in_message":[],"_revision_number":4},{"id":"c6f637d90b09ce6ff8281dbf6b5371042db661d9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.","accounts_in_message":[],"_revision_number":5},{"id":"48d1962cb48d1c534a56ed314d5c5278ac10b550","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 07:54:14.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.","accounts_in_message":[],"_revision_number":6},{"id":"e841c6f48db2e82f7c8d8630dde2268573c865af","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7},{"id":"fb64be8646ff301079f98b0eab09f1c053546b68","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-21 12:35:24.000000000","message":"Uploaded patch set 8: Patch Set 7 was rebased.","accounts_in_message":[],"_revision_number":8},{"id":"6ed31c9dd0fac68fbe5b7f712506216d04f600ce","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 02:18:22.000000000","message":"Patch Set 8:\n\n(2 comments)","accounts_in_message":[],"_revision_number":8},{"id":"e90033473a49df3e45f747641e2295b1457db3bd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:03:23.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"8361c43f4ca4d4516ae921cde6f7d869bdf41a14","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-29 12:22:54.000000000","message":"Uploaded patch set 10: Patch Set 9 was rebased. Commit message was updated.","accounts_in_message":[],"_revision_number":10},{"id":"2c229ebc2074ebfb9a69ad686f0aa42d6accd392","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-04 08:10:28.000000000","message":"Uploaded patch set 11: Patch Set 10 was rebased.","accounts_in_message":[],"_revision_number":11},{"id":"ed8d1ffba3685048a0bc273aa135a1ec14ac021a","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-17 11:49:50.000000000","message":"Patch Set 11:\n\n(2 comments)","accounts_in_message":[],"_revision_number":11},{"id":"697c5ab048762e7beda7b11b3e1d4b4d4e189330","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-28 12:51:00.000000000","message":"Uploaded patch set 12: Patch Set 11 was rebased.","accounts_in_message":[],"_revision_number":12},{"id":"9f8b31699e280d00bd2c2af9fa6f0ba469fa12f7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:27:02.000000000","message":"Uploaded patch set 13.","accounts_in_message":[],"_revision_number":13},{"id":"33a35887391782bd844a3a0ee6e3802474146671","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 08:18:16.000000000","message":"Uploaded patch set 14: Patch Set 13 was rebased.","accounts_in_message":[],"_revision_number":14},{"id":"84cc337d172253e36ce3ee9413b319882bb026c1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 09:11:03.000000000","message":"Uploaded patch set 15.","accounts_in_message":[],"_revision_number":15},{"id":"2c17ae908755d860aca36dedd875098cc579e865","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 15:23:13.000000000","message":"Uploaded patch set 16: Patch Set 15 was rebased.","accounts_in_message":[],"_revision_number":16},{"id":"73089c100a165c43c542ff037ae67d35be54f501","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-12 07:08:46.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.","accounts_in_message":[],"_revision_number":17},{"id":"6a982a54919ecd28cdaea20ed2d9548138ec753e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-14 14:18:32.000000000","message":"Uploaded patch set 18.","accounts_in_message":[],"_revision_number":18},{"id":"248df715b9f84721b92d5b01ce91884da844bc0e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 06:23:31.000000000","message":"Uploaded patch set 19: Patch Set 18 was rebased.","accounts_in_message":[],"_revision_number":19},{"id":"33c8eb7cce7820e4665f0ac7d5693001da88dc35","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 12:59:19.000000000","message":"Uploaded patch set 20: Patch Set 19 was rebased.","accounts_in_message":[],"_revision_number":20},{"id":"4ebf7c07d4d055ab895613cdf6301d9dc5b1e4d2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:01:11.000000000","message":"Uploaded patch set 21.","accounts_in_message":[],"_revision_number":21},{"id":"a7dbc89fbdde9023df33e1aa4f63195d3929135f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:39:07.000000000","message":"Uploaded patch set 22: Patch Set 21 was rebased.","accounts_in_message":[],"_revision_number":22},{"id":"73d9b21339ecf55a474cd0bc94547c58bf444d7e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 11:30:36.000000000","message":"Uploaded patch set 23: Patch Set 22 was rebased.","accounts_in_message":[],"_revision_number":23},{"id":"7e410625fa0e3f123db08e83f7f92204017c2605","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 12:28:12.000000000","message":"Uploaded patch set 24: Patch Set 23 was rebased.","accounts_in_message":[],"_revision_number":24},{"id":"5d0eac55c3920ec3c090cde98ff4b1d65a60eb81","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 08:31:39.000000000","message":"Uploaded patch set 25.","accounts_in_message":[],"_revision_number":25}],"current_revision_number":25,"current_revision":"7b7c45c521bf9a21daec4b56a934967b6259ea6b","revisions":{"0d31896c89ab6af6d01adf0b3bc129befac23d7d":{"kind":"REWORK","_number":1,"created":"2026-07-06 06:50:47.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"b2be2dba3b616fac4dac010aa2df48273a389427","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a6a55ba6774a9ef192f1d5d2199f884054fb5d65":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-07-06 08:22:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"98c54b419aaa097b2202d807ae29a686d20792fa","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-06 08:20:50.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"43ceb2e492d54654a2b7b5f19ade691f4e013155":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"7e513b6bc4426f477718a824ca6085a8a96f249e","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:44.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5780c56d2a1649851153bbeec6d01fd84fd30e59":{"kind":"NO_CHANGE","_number":4,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9c1a29e6ae3bc934bf9e31e1b3572fb85f85775c","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:53.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8e7f1823d71d8c710e8abb62cd12dfc7d8f58464":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"612a1a2662619a5d7abf5dd08458bdc7d0f40778","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:22:23.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"83d11cf4cfe70ee315d8c66b4416e6a076fa511a":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-16 07:54:14.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9e77992ce4682ed00a1c4a2ceee2a531c1f88035","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 07:42:19.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"7bf1531091c139fdbb5a05319e08215941444d98":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"17496b0a6548cedeae83ecbf96ad36909e59300f","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:36.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a60e3ab7df6f11dd9574f976d8d0fea1e447aff3":{"kind":"TRIVIAL_REBASE","_number":8,"created":"2026-07-21 12:35:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/8","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/8","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"243d3c63615b01a49decb105afd1da33241557da","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-21 12:30:45.000000000","tz":180},"subject":"oob: advertise a connect_lifetime handshake shortcut","message":"oob: advertise a connect_lifetime handshake shortcut\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: the seconds the reply doubles as a\nhandshake shortcut, letting a probing client reuse it as the server\u0027s\nHARD_RESET and start the three-way handshake at the third packet.\n\nThe value is inferred, not configurable: the reply is only valid as a shortcut\nwhile its stateless SYN-cookie is, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6db4fe731e0fa3e226d94c3ac5b88062ba979919":{"kind":"REWORK","_number":9,"created":"2026-07-28 15:03:23.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/9","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/9","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"540aff5e0dadb70c55af4087b3724dda3deab55f","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-28 15:00:13.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A tls-crypt-v2 probe (unwrapped via its\nWKc) also sets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend\nthe WKc when completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement and its plumbing through oob_build_probe_reply()\nare added here; the client side that acts on it follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"52eb41d32656a1dbef8042a70463131500f6a77c":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":10,"created":"2026-07-29 12:22:54.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/10","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/10","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"bc96f8da5ebb9906aa1e6399d80e0b200ec2ab09","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-29 12:07:08.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A probe that arrived as\nP_CONTROL_OOB_WKC_V1 also gets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the\nclient to resend the WKc when completing the handshake, since the server keeps\nno state.\n\nOnly the wire advertisement is added here -- the server fills both values into\nthe probe_reply it hands to oob_build_probe_reply(). The client side that acts\non them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5cbfa5d1b07c85e67b6c53b8262fd1b63b352e82":{"kind":"TRIVIAL_REBASE","_number":11,"created":"2026-08-04 08:10:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/11","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/11","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4504db84b1cba2300bb2cc7f831dd2abf19e88fe","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-04 08:08:33.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A probe that arrived as\nP_CONTROL_OOB_WKC_V1 also gets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the\nclient to resend the WKc when completing the handshake, since the server keeps\nno state.\n\nOnly the wire advertisement is added here -- the server fills both values into\nthe probe_reply it hands to oob_build_probe_reply(). The client side that acts\non them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"c0c7af22be5b6a05a8f937d3afffe6c2683ad394":{"kind":"TRIVIAL_REBASE","_number":12,"created":"2026-08-28 12:51:00.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/12","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/12","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8f4288b1e06841684a06f9750d24b9ff1bf4cf84","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:56:54.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-28 12:33:23.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A probe that arrived as\nP_CONTROL_OOB_WKC_V1 also gets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the\nclient to resend the WKc when completing the handshake, since the server keeps\nno state.\n\nOnly the wire advertisement is added here -- the server fills both values into\nthe probe_reply it hands to oob_build_probe_reply(). The client side that acts\non them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"2c5406ba28ea35bcfd9a98dc94dcdb2887364ec0":{"kind":"REWORK","_number":13,"created":"2026-09-09 07:27:02.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/13","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/13","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"c91351a36a99bb33a9338727063dcc25481c54f0","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-09 06:53:51.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A probe that arrived as\nP_CONTROL_OOB_WKC_V1 also gets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the\nclient to resend the WKc when completing the handshake, since the server keeps\nno state.\n\nOnly the wire advertisement is added here -- the server puts both values into\nthe probe_reply it builds for an accepted probe. The client side that acts on\nthem follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"2e13038454158abce3a8215d227dc56107797ca4":{"kind":"TRIVIAL_REBASE","_number":14,"created":"2026-09-11 08:18:16.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/14","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/14","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"64693024367638f3bb40d39f0409e058dc4d02a4","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 08:10:23.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing client may\nuse the reply as the server\u0027s HARD_RESET when it starts a handshake.\n\nThe value is inferred, not configurable: the reply is only usable as that reset\nwhile its stateless SYN-cookie is valid, i.e. the guaranteed cookie window of\n~handshake_window (2 quantised buckets; see check_session_hmac_and_pkt_id), so\nthe server advertises exactly that. A probe that arrived as\nP_CONTROL_OOB_WKC_V1 also gets OOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the\nclient to resend the WKc when completing the handshake, since the server keeps\nno state.\n\nOnly the wire advertisement is added here -- the server puts both values into\nthe probe_reply it builds for an accepted probe. The client side that acts on\nthem follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"67b9effd64e7147c48159a846a03cee9682d758a":{"kind":"REWORK","_number":15,"created":"2026-09-11 09:11:03.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/15","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/15","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d9bd55db2ac03da4ece97aab53b207bfc2a349f1","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 09:04:01.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6fcc9968abf62b42a0dbe51ba81d7d35d5fff053":{"kind":"TRIVIAL_REBASE","_number":16,"created":"2026-09-11 15:23:13.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/16","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/16","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e999f45c962329ae86de2ff9171383846b1925dc","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 15:05:20.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"4dfa0965e1fef574f420437f19e501c389e3d529":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-09-12 07:08:46.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/17","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/17","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3da5662f22b566c4b907941ad93c60f1ea8b045c","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-12 07:06:50.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8c767f2e69eece06e7b353fee25870e3ea2f886f":{"kind":"REWORK","_number":18,"created":"2026-09-14 14:18:32.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/18","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/18","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"695fbbde00e7a7d7d9ac262d45d789b37800485f","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-14 13:44:49.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"2b2862275137a9ef7bdb9102f1f4830c23a09bc7":{"kind":"TRIVIAL_REBASE","_number":19,"created":"2026-09-15 06:23:31.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/19","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/19","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"96116236b4d2f8d1cbd1db2f5f10350837aa8b86","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 05:32:37.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"86ba2b1bba5d391e9aa144e45334c05966d6adfa":{"kind":"TRIVIAL_REBASE","_number":20,"created":"2026-09-15 12:59:19.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/20","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/20","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6c2b8603b91ce8465e49395c3953b0e9324e7cd3","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 12:49:01.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"57bf562e2a6e915636f6831659bce7da0b68dd1d":{"kind":"REWORK","_number":21,"created":"2026-09-17 07:01:11.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/21","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/21","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"a6ac814c0a4e992aa0ef0496e804032034f3680a","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 06:52:30.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"0c20013077938e6c8cbb462b3bfa6403eefd1f4b":{"kind":"TRIVIAL_REBASE","_number":22,"created":"2026-09-17 07:39:07.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/22","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/22","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/22 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2eb0e36989ec1797c53c9cd5849c239b1f1286da","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:31:46.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"15bec102ec8081042df2e9583ed43116ed4bb7d6":{"kind":"TRIVIAL_REBASE","_number":23,"created":"2026-09-17 11:30:36.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/23","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/23","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/23 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"240c548334815ba1cae7136b8049938df7ec2647","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:54:06.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"6017719072aebd0837dc62553416939b13168a88":{"kind":"TRIVIAL_REBASE","_number":24,"created":"2026-09-17 12:28:12.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/24","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/24","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/24 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"7226eadf8d989d5222390a7f572f2c39fef1bddc","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 11:45:25.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"7b7c45c521bf9a21daec4b56a934967b6259ea6b":{"kind":"REWORK","_number":25,"created":"2026-09-18 08:31:39.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/68/1768/25","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/68/1768/25","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25 \u0026\u0026 git checkout -b change-1768 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/68/1768/25 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2c7c0a581349f44304b7c9da44a1d80682022b77","subject":"oob: Send tls-crypt-v2 SERVER_PROBE from the client"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-08 13:02:30.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 08:26:43.000000000","tz":180},"subject":"oob: advertise a connect_lifetime in the probe reply","message":"oob: advertise a connect_lifetime in the probe reply\n\nA server answering an out-of-band SERVER_PROBE now also advertises a\nconnect_lifetime in the PROBE_REPLY: how long, in seconds, a probing\nclient may use the reply as the server\u0027s HARD_RESET when it starts a\nhandshake.\n\nThe value is inferred, not configurable: the reply is only usable as\nthat reset while its stateless SYN-cookie is valid, i.e. the guaranteed\ncookie window of ~handshake_window (2 quantised buckets; see\ncheck_session_hmac_and_pkt_id), so the server advertises exactly that. A\nprobe that arrived as P_CONTROL_OOB_WKC_V1 also gets\nOOB_PROBE_REPLY_FLAG_RESEND_WKC, telling the client to resend the WKc\nwhen completing the handshake, since the server keeps no state.\n\nOnly the wire advertisement is added here -- the server puts both values\ninto the probe_reply it builds for an accepted probe. The client side\nthat acts on them follows.\n\nChange-Id: Ib2b6c2246f9d9c0a505292ee8d879f714901ffae\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}]}
