)]}'
{"id":"openvpn~1771","triplet_id":"openvpn~master~Icec4696ff263ab39ebab06e8d478395a5ddfaab9","project":"openvpn","branch":"master","full_branch":"refs/heads/master","topic":"oob-server-probe","attention_set":{"1000008":{"account":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-07-26 02:08:53.000000000","reason":"\u003cGERRIT_ACCOUNT_1000003\u003e replied on the change","reason_account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}}},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-26 02:08:53.000000000","reason":"\u003cGERRIT_ACCOUNT_1000003\u003e replied on the change","reason_account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}}},"hashtags":[],"change_id":"Icec4696ff263ab39ebab06e8d478395a5ddfaab9","subject":"oob: fall back quickly when a probe-started handshake is ignored","status":"NEW","created":"2026-07-06 06:50:47.000000000","updated":"2026-09-18 08:31:39.000000000","submit_type":"CHERRY_PICK","total_comment_count":2,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"1f2f91c530cfb33c424defe9a0dcedff5a250d78","_number":1771,"virtual_id_number":1771,"owner":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"rejected":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"all":[{"value":-2,"date":"2026-09-18 08:31:39.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0,"blocking":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}],"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-06 06:50:55.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-06 06:50:55.000000000","updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"8ad021d73ec21bb157986acd087f23374378f792","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 06:50:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"a4c01e1999165517171249527c1305504ab99ccc","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 07:11:41.000000000","message":"Topic set to oob-server-probe","accounts_in_message":[],"_revision_number":1},{"id":"f281cfda93a245564ef34221dd187dc29936e473","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-06 08:22:28.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"098fcf6c963b655799dddb0763badcd04566214f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-09 13:47:21.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"70b4da3cb72f1cbfef7df8b2beaddca5f05ff856","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 08:14:41.000000000","message":"Uploaded patch set 4: New patch set was added with same tree, parent tree, and commit message as Patch Set 3.","accounts_in_message":[],"_revision_number":4},{"id":"82205d9426055cf18b7172c4f000c2317e4ba1ec","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-14 12:32:24.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.","accounts_in_message":[],"_revision_number":5},{"id":"066a87f73a85c6a296ad31a7bfebad3e47544b04","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 07:54:14.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.","accounts_in_message":[],"_revision_number":6},{"id":"81e851f00568e31308287e991506320811e77c26","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-16 08:09:01.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.","accounts_in_message":[],"_revision_number":7},{"id":"89f93c90bde26323dd26184d7e974297c9edf97c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-21 12:35:24.000000000","message":"Uploaded patch set 8: Patch Set 7 was rebased.","accounts_in_message":[],"_revision_number":8},{"id":"aa26bea56293e2e3938ee4574e7c90b2f028b0ac","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 02:08:53.000000000","message":"Patch Set 8:\n\n(2 comments)","accounts_in_message":[],"_revision_number":8},{"id":"fc7803cbbdb1c7f375fdc6b3971dd5a438f70da4","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 02:09:02.000000000","message":"Patch Set 8: Code-Review-2","accounts_in_message":[],"_revision_number":8},{"id":"51f65b3717e94e3ab6e4349655e3d6059dd0c768","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-28 15:03:23.000000000","message":"Uploaded patch set 9.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":9},{"id":"1643b42abf1861f6b667e95abaf49592ce2acb43","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-07-29 12:22:54.000000000","message":"Uploaded patch set 10: Patch Set 9 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":10},{"id":"bb125e263e8a23a0989c3a4c52e3b61f06ced80c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-04 08:10:28.000000000","message":"Uploaded patch set 11: Patch Set 10 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":11},{"id":"053c0c6e7faa89ab7baf4a18de327bfa0277bcb3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-08-28 12:51:00.000000000","message":"Uploaded patch set 12: Patch Set 11 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":12},{"id":"bad124a0b4db24551970342e60ed3bb14e0c7b25","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-09 07:27:02.000000000","message":"Uploaded patch set 13: Patch Set 12 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":13},{"id":"b60f64680d7fc274d093dff6792ef3d3339859f4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 08:18:16.000000000","message":"Uploaded patch set 14: Patch Set 13 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":14},{"id":"eaacdbc4ca6f5d2a7e59d7cbe1757ba1814e348a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 09:11:03.000000000","message":"Uploaded patch set 15: Patch Set 14 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":15},{"id":"365916d961e7e554643b9bd6cbb7345b3715f6fd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-11 15:23:13.000000000","message":"Uploaded patch set 16: Patch Set 15 was rebased. Commit message was updated.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":16},{"id":"97df4964fdeceb18edf7db63436f5904d59abb37","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-12 07:08:46.000000000","message":"Uploaded patch set 17: Patch Set 16 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":17},{"id":"0ced96e916f6a4f3184aa7c68342949d05013d2c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-14 14:18:32.000000000","message":"Uploaded patch set 18.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":18},{"id":"71c205975b6266fb3a904c0a5d13a126abef007c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 06:23:31.000000000","message":"Uploaded patch set 19: Patch Set 18 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":19},{"id":"aa25c3e076f4451624611f665f52d3e7973e4bd4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 12:59:19.000000000","message":"Uploaded patch set 20: Patch Set 19 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":20},{"id":"fb48cde3efe7b2119f2f8d1d3131c34ca6b8ff98","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:01:11.000000000","message":"Uploaded patch set 21: Patch Set 20 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":21},{"id":"84f6800bcd921ceff65f0ecd14c7e126eded595d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 07:39:07.000000000","message":"Uploaded patch set 22: Patch Set 21 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":22},{"id":"02a706693e231061b14c17b5892535d2e64114e0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 11:30:36.000000000","message":"Uploaded patch set 23: Patch Set 22 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":23},{"id":"a99d5f8fb1a356295a10a466fc134965b70de97a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-17 12:28:12.000000000","message":"Uploaded patch set 24: Patch Set 23 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":24},{"id":"1f2f91c530cfb33c424defe9a0dcedff5a250d78","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 08:31:39.000000000","message":"Uploaded patch set 25: Patch Set 24 was rebased.\n\nCopied Votes:\n* Code-Review-2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR **is:MIN**\")\n","accounts_in_message":[],"_revision_number":25}],"current_revision_number":25,"current_revision":"30b49af81a4cfdccf0ff143a1d1ac2b64a666756","revisions":{"369bfc7631690d4d13c9bd9c501677fa966183d0":{"kind":"REWORK","_number":1,"created":"2026-07-06 06:50:47.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"fbd8bd63102fd7461907218a0a0224e40e3475ab","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 12:24:46.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"e04f62c5472f749d4351e715f6357e18390a6902":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-07-06 08:22:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"58f36111634204ed3d7c30357daacc1eae388e36","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-06 08:20:50.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"65d178ba4debd2725749be9889abfe32fbd3cbe7":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-07-09 13:47:21.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"fbc9dbbe6d7ecb8f527c604cce1529f4f8c21fc4","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-09 13:39:44.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"142034e8a64131d32a180b8576ccb18aa1bbde44":{"kind":"NO_CHANGE","_number":4,"created":"2026-07-14 08:14:41.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4c0a450da919e565a12bba0149c3c8f2492d0dfd","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 08:13:53.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"ce0cee706d136eafcc96e264d6f51938148c17cf":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-14 12:32:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"69348b80747574cdc64b3b8323957f50c22bdbc8","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-14 12:22:23.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8cd6d237a59f2f5c449a245822225604f3506b92":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-16 07:54:14.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"8c83de24372c690a1dc968ab24133511d794258a","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 07:42:37.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"e1edddfeb55fe1375b860a96356c9ee7d49c61c0":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-16 08:09:01.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"b513ee5fb0834a2586a3e6b52ca5c12f37acf54b","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-16 08:08:36.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"060ee6a4015f002fe2c9e7029a22834c596bd667":{"kind":"TRIVIAL_REBASE","_number":8,"created":"2026-07-21 12:35:24.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/8","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/8","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ad957fa52d9cd851d8e9f52beb2171a656c43db0","subject":"oob: client handshake shortcut via a server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-21 12:30:45.000000000","tz":180},"subject":"oob: fall back quickly when a handshake shortcut is ignored","message":"oob: fall back quickly when a handshake shortcut is ignored\n\nIf the server does not accept the shortcut third packet (e.g. a middlebox\ndrops the larger P_CONTROL_WKC_V1, or a version/bug mismatch), the client\npreviously stalled for the full handshake_window (~60s) before recovering.\n\nGive the shortcut session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected shortcut costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"13f2ecd12d67d13d841ab9140da2f55a373e79d6":{"kind":"REWORK","_number":9,"created":"2026-07-28 15:03:23.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/9","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/9","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"417762280a87265ae3e372375d8587e3d3d4e45f","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-28 15:00:13.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d36747500afa9bc8c91d2c26eaa00d96f61ed2bc":{"kind":"TRIVIAL_REBASE","_number":10,"created":"2026-07-29 12:22:54.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/10","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/10","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"e737cb18671990dcc6dfe38f0702df123f17d50d","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-29 12:07:08.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"a3ceca602bfdbd04365742c6b03c9f0503561c1b":{"kind":"TRIVIAL_REBASE","_number":11,"created":"2026-08-04 08:10:28.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/11","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/11","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/11 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d09f16ef82fd521e10961cc54a932b3da67a1f5c","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-04 08:08:33.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"ec164e8e4245fbc9caf431e52f1ea9c347e4c541":{"kind":"TRIVIAL_REBASE","_number":12,"created":"2026-08-28 12:51:00.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/12","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/12","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/12 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"45f6716e7f2dbe02989c0be4769d86252b16a7b6","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-08-28 12:33:23.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"8ec46cbcbe7d66a3fad75e70b8e153ab5aefb7e4":{"kind":"TRIVIAL_REBASE","_number":13,"created":"2026-09-09 07:27:02.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/13","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/13","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/13 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3d2e539367af5dbd58159dcacf615fa00bdb8c28","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-09 06:53:51.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"7b4a53267a141ac6cf6ee6163f585941f225b82d":{"kind":"TRIVIAL_REBASE","_number":14,"created":"2026-09-11 08:18:16.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/14","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/14","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/14 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"dcec71008791f76c404e0d0d19fa233b549ecd5f","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 08:10:23.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"19fdb9c8c3db86fba7cf63cfcaffc21e810f2f1c":{"kind":"TRIVIAL_REBASE","_number":15,"created":"2026-09-11 09:11:03.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/15","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/15","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/15 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"46303ec4c076da3e8a2e9f7ca03125e932e769ff","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 09:04:05.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started from a\nprobe reply, the client previously stalled for the full handshake_window (~60s)\nbefore recovering.\n\nIn a normal handshake, no answer could mean the server is down, so waiting is\nright. Here we know it is up, since it answered a probe a moment ago -- so no\nanswer means it did not accept the reply as a reset, and waiting 60s is pointless.\nThat happens when a load balancer sends the probe and the handshake to different\ninstances, when NAT changes the source port the cookie is bound to, or when the\nserver restarted and rotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off. If no\nresponse arrives, the session times out quickly and the normal handshake\nrecovery kicks in, so a rejected reply costs a few seconds instead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"fbf4fdab96d9c306dccbcdfc80457ada2086e5c7":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":16,"created":"2026-09-11 15:23:13.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/16","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/16","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/16 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"54150d727f9a1391e12f7f28682c823dd5d9d5da","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-11 15:22:31.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives, the session times out quickly and the normal\nhandshake recovery kicks in, so a rejected reply costs a few seconds\ninstead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"4f4acc4a6ef33883fb8f4e25a80754bb58db5cdc":{"kind":"TRIVIAL_REBASE","_number":17,"created":"2026-09-12 07:08:46.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/17","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/17","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/17 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"cea07119c54d788d9ecfd44325d7baf008e7c352","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-12 07:06:50.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives, the session times out quickly and the normal\nhandshake recovery kicks in, so a rejected reply costs a few seconds\ninstead of ~60.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"833da91dd69e33d63e609a6fa583a2f55cf2b563":{"kind":"REWORK","_number":18,"created":"2026-09-14 14:18:32.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/18","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/18","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/18 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"43645c205354c85bad18af559df53e73568a2070","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-14 13:44:49.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"2ef9e6274c59fefdb1662dd11ec8fa5871d5c92e":{"kind":"TRIVIAL_REBASE","_number":19,"created":"2026-09-15 06:23:31.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/19","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/19","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/19 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"f77a18399ec4033e733de8652aea86c8b92d4833","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 05:32:37.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"0661430fc9758228cef5f525aa28b9f5393530e6":{"kind":"TRIVIAL_REBASE","_number":20,"created":"2026-09-15 12:59:19.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/20","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/20","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/20 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"5f5b350380cc4daff7b8cbd43c7741b2a93f9158","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 12:49:02.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"de126fdcfba0237586ddd9123c9232ac3d55febb":{"kind":"TRIVIAL_REBASE","_number":21,"created":"2026-09-17 07:01:11.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/21","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/21","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/21 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"bc61cb4fa00c62cb4f6054a2c8e5ca1c6a944491","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 06:52:30.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"39332fc8b659b874d61117960d066e52cdc4b8a8":{"kind":"TRIVIAL_REBASE","_number":22,"created":"2026-09-17 07:39:07.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/22","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/22","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/22 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"5575bac348571b786f4be058c4d6eff8eba87828","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:31:46.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"bc0d0328876a38fd178b087a9703ae4953d3fbe3":{"kind":"TRIVIAL_REBASE","_number":23,"created":"2026-09-17 11:30:36.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/23","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/23","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/23 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"10d8bc0068c3867f7a830ddbc1d307437383a008","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 07:54:06.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"0eba0109874155cfa24a753d81a52f7ccb988f8a":{"kind":"TRIVIAL_REBASE","_number":24,"created":"2026-09-17 12:28:12.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/24","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/24","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/24 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"5b52cecbc2399bb06b4871e5ec2c21cc8aa4da48","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 11:45:25.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"30b49af81a4cfdccf0ff143a1d1ac2b64a666756":{"kind":"TRIVIAL_REBASE","_number":25,"created":"2026-09-18 08:31:39.000000000","uploader":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/71/1771/25","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/71/1771/25","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25 \u0026\u0026 git checkout -b change-1771 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/71/1771/25 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3e2e57191c4f70d01cb4a35822cb825337a60acb","subject":"oob: start the client handshake from the server probe"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-07-03 09:58:51.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 08:26:43.000000000","tz":180},"subject":"oob: fall back quickly when a probe-started handshake is ignored","message":"oob: fall back quickly when a probe-started handshake is ignored\n\nIf the server does not accept the third packet of a handshake started\nfrom a probe reply, the client previously stalled for the full\nhandshake_window (~60s) before recovering.\n\nIn a normal handshake, no answer could mean the server is down, so\nwaiting is right. Here we know it is up, since it answered a probe a\nmoment ago -- so no answer means it did not accept the reply as a reset,\nand waiting 60s is pointless. That happens when a load balancer sends\nthe probe and the handshake to different instances, when NAT changes the\nsource port the cookie is bound to, or when the server restarted and\nrotated its session-id HMAC key.\n\nGive such a session a short first-response deadline\n(min(handshake_window, 5s)); once the server answers, tls_pre_decrypt()\nrestores the full window so a slow-but-working handshake is not cut off.\nIf no response arrives the session times out quickly and the client\nrestarts the attempt rather than retrying in place: the restart moves on\nto the next resolved address or connection entry, so the server that\nanswered the probe is not tried again this cycle. A rejected reply\ntherefore costs a few seconds instead of ~60, at the price of giving up\non that server.\n\nChange-Id: Icec4696ff263ab39ebab06e8d478395a5ddfaab9\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"REJECT","applied_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}]}
