)]}'
{"id":"openvpn~1770","triplet_id":"openvpn~master~I454d5040cbad4d373ee4f90b8d683200d2a4c0e4","project":"openvpn","branch":"master","topic":"oob-server-probe","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-28 15:03:23.000000000","reason":"Vote got outdated and was removed: Code-Review-1"}},"removed_from_attention_set":{"1000008":{"account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-07-28 15:06:10.000000000","reason":"\u003cGERRIT_ACCOUNT_1000008\u003e replied on the change","reason_account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"}}},"hashtags":[],"change_id":"I454d5040cbad4d373ee4f90b8d683200d2a4c0e4","subject":"oob: start the client handshake from the server probe","status":"NEW","created":"2026-07-06 06:50:47.000000000","updated":"2026-09-18 08:31:39.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":6,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"305230b439559f64df78fc0ce3a80e555fa28317","_number":1770,"virtual_id_number":1770,"owner":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-06 06:50:55.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-06 06:50:55.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"9a8627097130c3230fc0decc22ad7355c52a716f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 06:50:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"f2f9444a9412a346d3c169629105a6330206be46","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:41.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":1},{"id":"f934b73c4d2d3ad1cb54e5182aef55da254b11db","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 08:22:28.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"3a96aab768b8852192044d0ed2ed7475ac061cb3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"7c704c9132f23d82014e009326359d95da40c39e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 4: New patch set was added with same tree, parent tree, and commit message as Patch Set 3.","accounts_in_message":[],"_revision_number":4},{"id":"16734921c986adbe6a2ee74c30810e43638a82e3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.","accounts_in_message":[],"_revision_number":5},{"id":"a5e76681425a3d8f8ca8f43fb5cf4906bb69e622","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 07:54:14.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"ccb5b8c972b662037000097ced0d656e7dad5fca","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7},{"id":"0c03547abcac021b19cfcd6ba3e552a4617d96b0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-21 12:35:24.000000000","message":"Uploaded patch set 8: Patch Set 7 was rebased.","accounts_in_message":[],"_revision_number":8},{"id":"df55b457a6d551acc9223301c60c861f314fbf79","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 01:55:46.000000000","message":"Patch Set 8: Code-Review-1\n\n(3 comments)","accounts_in_message":[],"_revision_number":8},{"id":"2c737de915506770b0526eff89126e73641835a2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:03:23.000000000","message":"Uploaded patch set 9.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":9},{"id":"52f0114478facb9251c5191447d99e7a802e5d04","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:06:10.000000000","message":"Patch Set 9:\n\n(3 comments)","accounts_in_message":[],"_revision_number":9},{"id":"074e118cb1a5b1fbfee0c8eaaf14e5a2ccfda3a6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-29 12:22:54.000000000","message":"Uploaded patch set 10.","accounts_in_message":[],"_revision_number":10},{"id":"478fad7feb5908193a3592d86ff1d3b56dcf8c94","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-04 08:10:28.000000000","message":"Uploaded patch set 11: Patch Set 10 was rebased.","accounts_in_message":[],"_revision_number":11},{"id":"b200b5c637c70f8d78cfb36a357aacf826d3d1c2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-28 12:51:00.000000000","message":"Uploaded patch set 12: Patch Set 11 was rebased.","accounts_in_message":[],"_revision_number":12},{"id":"cecfe4c03440f436454b39b14730ecb696d823b6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:27:02.000000000","message":"Uploaded patch set 13: Patch Set 12 was rebased.","accounts_in_message":[],"_revision_number":13},{"id":"cd93945c03bab3170dae128ef785b4e6ccf43dc5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 08:18:16.000000000","message":"Uploaded patch set 14.","accounts_in_message":[],"_revision_number":14},{"id":"a99b4423e8b46e463ad982ae690452cafe6bd058","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 09:11:03.000000000","message":"Uploaded patch set 15.","accounts_in_message":[],"_revision_number":15},{"id":"7eb0fecf136405edd70adb677ae196b2b0037476","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 15:23:13.000000000","message":"Uploaded patch set 16.","accounts_in_message":[],"_revision_number":16},{"id":"30c57f389241937670cf645467a28a384a4a915d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-12 07:08:46.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.","accounts_in_message":[],"_revision_number":17},{"id":"66169fa6fb116e67fe797a59277df943c2fc41f6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-14 14:18:32.000000000","message":"Uploaded patch set 18.","accounts_in_message":[],"_revision_number":18},{"id":"fbf8550e8dee61c35fc4b332ccd38d5f2de18b97","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 06:23:31.000000000","message":"Uploaded patch set 19: Patch Set 18 was rebased.","accounts_in_message":[],"_revision_number":19},{"id":"f935003c6a09709de24b38a22017c853971188c7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 12:59:19.000000000","message":"Uploaded patch set 20: Patch Set 19 was rebased.","accounts_in_message":[],"_revision_number":20},{"id":"a2fb376b6ba08b52d7b797df232965a8c8872b03","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:01:11.000000000","message":"Uploaded patch set 21.","accounts_in_message":[],"_revision_number":21},{"id":"5a65959900a62a2ec188c0b7d64375abb807040b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:39:07.000000000","message":"Uploaded patch set 22: Patch Set 21 was rebased.","accounts_in_message":[],"_revision_number":22},{"id":"c39d7654248182d288339e81d17aadb79aa10313","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 11:30:36.000000000","message":"Uploaded patch set 23: Patch Set 22 was rebased.","accounts_in_message":[],"_revision_number":23},{"id":"b89fb151e9f4e55fa6946f296e7e71bfe5aa3f42","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 12:28:12.000000000","message":"Uploaded patch set 24: Patch Set 23 was rebased.","accounts_in_message":[],"_revision_number":24},{"id":"305230b439559f64df78fc0ce3a80e555fa28317","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 08:31:39.000000000","message":"Uploaded patch set 25: Patch Set 24 was rebased.","accounts_in_message":[],"_revision_number":25}],"current_revision_number":25,"current_revision":"3e2e57191c4f70d01cb4a35822cb825337a60acb","revisions":{"fbd8bd63102fd7461907218a0a0224e40e3475ab":{"kind":"REWORK","_number":1,"created":"2026-07-06 06:50:47.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e5bf3f752723bf8da1d79993651a64c5b3155ba3","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 12:18:40.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"58f36111634204ed3d7c30357daacc1eae388e36":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-07-06 08:22:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"5c10d382b85ff489fc008cf4ff4e8d9e509fd7ac","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-06 08:20:50.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"fbc9dbbe6d7ecb8f527c604cce1529f4f8c21fc4":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"fd0663c6295a147265d74560f143628ef4e848bb","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:44.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"4c0a450da919e565a12bba0149c3c8f2492d0dfd":{"kind":"NO_CHANGE","_number":4,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"91a672c825b06881ed8c5dc0c7e9f9a623c5922c","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:53.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"69348b80747574cdc64b3b8323957f50c22bdbc8":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2c5db3aeb9e63569cbc2badb3640d86098c2084d","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:22:23.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8c83de24372c690a1dc968ab24133511d794258a":{"kind":"REWORK","_number":6,"created":"2026-07-16 07:54:14.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4334b88d751d5b10c9817cb49530a1ef8a4030d5","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 07:42:37.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"b513ee5fb0834a2586a3e6b52ca5c12f37acf54b":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"54bd711c44c39351131753cc1f8ee4765c107fb1","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:36.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"ad957fa52d9cd851d8e9f52beb2171a656c43db0":{"kind":"TRIVIAL_REBASE","_number":8,"created":"2026-07-21 12:35:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/8","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/8","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f15ede77590c15f577f8942e5f43cf807bf8a226","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-21 12:30:45.000000000","tz":180},"subject":"oob: client handshake shortcut via a server probe","message":"oob: client handshake shortcut via a server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, the\nclient now skips its own three-way handshake and starts at the third packet,\nreusing the probe reply as the server\u0027s HARD_RESET (its session id is a valid\nstateless SYN-cookie). Saves one RTT on connect.\n\n  - oob_client.c: on a shortcut-capable winner, hand its probe socket, the\n    captured server session id (cookie), our probe session id, the pinned\n    responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has\n    no user-to-kernel socket handoff (probing still works, only the shortcut is\n    skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"417762280a87265ae3e372375d8587e3d3d4e45f":{"kind":"REWORK","_number":9,"created":"2026-07-28 15:03:23.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/9","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/9","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"26847361f54364b37eca7bb5ed7e43142c426016","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-28 15:00:13.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"e737cb18671990dcc6dfe38f0702df123f17d50d":{"kind":"REWORK","_number":10,"created":"2026-07-29 12:22:54.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/10","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/10","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2e8c69fc666ccea92e01d5bd79634d3deb734d2d","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-29 12:07:08.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d09f16ef82fd521e10961cc54a932b3da67a1f5c":{"kind":"TRIVIAL_REBASE","_number":11,"created":"2026-08-04 08:10:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/11","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/11","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"07f33a145c5d1c172151c3ae610eda962e4f1b4b","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-04 08:08:33.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"45f6716e7f2dbe02989c0be4769d86252b16a7b6":{"kind":"TRIVIAL_REBASE","_number":12,"created":"2026-08-28 12:51:00.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/12","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/12","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"99fb4362655e6c8316d7a239a91d00aa2905dc48","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-28 12:33:23.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"3d2e539367af5dbd58159dcacf615fa00bdb8c28":{"kind":"TRIVIAL_REBASE","_number":13,"created":"2026-09-09 07:27:02.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/13","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/13","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"27ce4fa6e43a752f15c71fb824d3037f2525d319","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-09 06:53:51.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"dcec71008791f76c404e0d0d19fa233b549ecd5f":{"kind":"REWORK","_number":14,"created":"2026-09-11 08:18:16.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/14","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/14","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"64a51e2de89a73a146e0c55f7c59c1ccb9e7ef31","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 08:10:23.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime, its\nreply also served as the server\u0027s HARD_RESET: its session id is a valid\nstateless SYN-cookie. The client therefore starts the handshake from that reply\ninstead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its reply take\nthe place of the two reset packets rather than removing them. The saving is one\nRTT compared with probing and then connecting; a client that does not probe is\nunaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand its probe\n    socket, the captured server session id (cookie), our probe session id, the\n    pinned responder address, and the resend-wkc flag to the connection via c2;\n    relinquish that socket (do not close it); gate off for dco-win, which has no\n    user-to-kernel socket handoff (probing still works, only starting from the\n    reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the probe\u0027s\n    (the cookie is an HMAC over it), the remote session id to the cookie, ack\n    the phantom server reset (id 0) so the third packet carries the cookie, set\n    CO_RESEND_WKC for tls-crypt-v2, and drop to S_PRE_START so tls_process()\n    promotes to S_START and sends the ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when adopting,\n    and count the probe reply as the initial packet received (n_sessions++, as\n    the server does before its own session_skip_to_pre_start) so\n    check_server_poll_timeout() does not restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"46303ec4c076da3e8a2e9f7ca03125e932e769ff":{"kind":"REWORK","_number":15,"created":"2026-09-11 09:11:03.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/15","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/15","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d21561bf2734066edcb5c1041d115b9fcebfebdf","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 09:04:05.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"54150d727f9a1391e12f7f28682c823dd5d9d5da":{"kind":"REWORK","_number":16,"created":"2026-09-11 15:23:13.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/16","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/16","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3de512b3e9153465ef84466ae1b773f902507d20","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 15:22:31.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"cea07119c54d788d9ecfd44325d7baf008e7c352":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-09-12 07:08:46.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/17","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/17","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"42b9daf062a6ae85a91b5cb1199c2de8c594f9b9","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-12 07:06:50.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"43645c205354c85bad18af559df53e73568a2070":{"kind":"REWORK","_number":18,"created":"2026-09-14 14:18:32.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/18","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/18","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"1c0b21741b805c45b4af76e2cf33c9e2a89fbe5c","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-14 13:44:49.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"f77a18399ec4033e733de8652aea86c8b92d4833":{"kind":"TRIVIAL_REBASE","_number":19,"created":"2026-09-15 06:23:31.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/19","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/19","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ae756e9b4199523c5a6e51bc8a64a64b6ea929ea","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 05:32:37.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5f5b350380cc4daff7b8cbd43c7741b2a93f9158":{"kind":"TRIVIAL_REBASE","_number":20,"created":"2026-09-15 12:59:19.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/20","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/20","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6051cefbaa08b45deff80a53711c699151ce54ed","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 12:49:02.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"bc61cb4fa00c62cb4f6054a2c8e5ca1c6a944491":{"kind":"REWORK","_number":21,"created":"2026-09-17 07:01:11.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/21","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/21","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ad0ed08c1cc4bee724bdbca7f4488cb0dcabbeb7","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 06:52:30.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5575bac348571b786f4be058c4d6eff8eba87828":{"kind":"TRIVIAL_REBASE","_number":22,"created":"2026-09-17 07:39:07.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/22","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/22","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/22 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"777c6b002a074c06b9b796b639d37566e30ed127","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:31:46.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"10d8bc0068c3867f7a830ddbc1d307437383a008":{"kind":"TRIVIAL_REBASE","_number":23,"created":"2026-09-17 11:30:36.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/23","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/23","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/23 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"38f6b32c9da59d387e45e2c2ea2f94504c1ec57f","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:54:06.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"5b52cecbc2399bb06b4871e5ec2c21cc8aa4da48":{"kind":"TRIVIAL_REBASE","_number":24,"created":"2026-09-17 12:28:12.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/24","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/24","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/24 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e906e24cb71866a89499d53a3cc9c89f3ccf53ee","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 11:45:25.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"3e2e57191c4f70d01cb4a35822cb825337a60acb":{"kind":"TRIVIAL_REBASE","_number":25,"created":"2026-09-18 08:31:39.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/70/1770/25","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/70/1770/25","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25 \u0026\u0026 git checkout -b change-1770 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/70/1770/25 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"153952333cf2562dce3068ee107369a9672f12b7","subject":"socket: adopt a pre-created UDP socket for a client connection"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:40.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 08:26:43.000000000","tz":180},"subject":"oob: start the client handshake from the server probe","message":"oob: start the client handshake from the server probe\n\nWhen the best remote answered a probe and advertised a connect_lifetime,\nits reply also served as the server\u0027s HARD_RESET: its session id is a\nvalid stateless SYN-cookie. The client therefore starts the handshake\nfrom that reply instead of running its own reset exchange.\n\nNote this does not shorten the handshake itself -- the probe and its\nreply take the place of the two reset packets rather than removing them.\nThe saving is one RTT compared with probing and then connecting; a\nclient that does not probe is unaffected.\n\n  - oob_client.c: when the winner advertised a connect_lifetime, hand\n    its probe socket, the captured server session id (cookie), our probe\n    session id, the pinned responder address, and the resend-wkc flag to\n    the connection via c2; relinquish that socket (do not close it);\n    gate off for dco-win, which has no user-to-kernel socket handoff\n    (probing still works, only starting from the reply is skipped).\n  - ssl.c session_skip_to_pre_start_client(): seed our session id to the\n    probe\u0027s (the cookie is an HMAC over it), the remote session id to\n    the cookie, ack the phantom server reset (id 0) so the third packet\n    carries the cookie, set CO_RESEND_WKC for tls-crypt-v2, and drop to\n    S_PRE_START so tls_process() promotes to S_START and sends the\n    ClientHello (no HARD_RESET sent).\n  - init.c: invoke the client skip after tls_multi_init_finalize when\n    adopting, and count the probe reply as the initial packet received\n    (n_sessions++, as the server does before its own\n    session_skip_to_pre_start) so check_server_poll_timeout() does not\n    restart the connected session.\n\nThree things guard the shortcut. The reply\u0027s session id is rejected\nunless it is defined: it becomes the remote session id, and the phantom\nACK means reliable_ack_write() would assert on an all-zero one, so a\nserver -- or, without tls-auth/tls-crypt, anyone who answers first --\ncould otherwise kill the client with a single packet.\n\nThe probe socket and the cookie belong to the remote that answered, so\nboth are given up unless next_connection_entry() selected that same\nremote. The entry is mapped by value and the management interface may\nrewrite the copy, so the check compares the resulting host, port and\nproxy settings rather than which entry was picked.\n\nFinally, the server honours its reply only for the advertised\nconnect_lifetime, which a passphrase or token prompt during init can\noutlast; the shortcut is dropped when it has elapsed. Steps after that\npoint fall to the short fallback deadline instead.\n\nChange-Id: I454d5040cbad4d373ee4f90b8d683200d2a4c0e4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
