)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"change_message_id":"0946f258b227a1a1d079ea415c60d073df96b685","unresolved":true,"context_lines":[{"line_number":7,"context_line":"Make required action returned from pre_decrypt_verdict more explicit"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"The current code relies on the condition if state.server_session_id"},{"line_number":10,"context_line":"is defined to decided if session_skip_to_pre_start should be used."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Instead explicitly return the intent and use that to decide if"},{"line_number":13,"context_line":"session_skip_to_pre_start should be called."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"790ac71f_74691884","line":10,"updated":"2026-08-17 10:34:49.000000000","message":"Typo: \"to decide\".","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"4fd200fd49f2096a8383307105a94c6c874e90b2","unresolved":false,"context_lines":[{"line_number":7,"context_line":"Make required action returned from pre_decrypt_verdict more explicit"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"The current code relies on the condition if state.server_session_id"},{"line_number":10,"context_line":"is defined to decided if session_skip_to_pre_start should be used."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Instead explicitly return the intent and use that to decide if"},{"line_number":13,"context_line":"session_skip_to_pre_start should be called."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"e3697b68_91d649b0","line":10,"in_reply_to":"790ac71f_74691884","updated":"2026-08-17 11:39:39.000000000","message":"Done","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"ab074131852d1d76082ad78ec6cd9534620dcc00","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"67fbf3ec_b03bfee4","updated":"2026-08-05 14:04:01.000000000","message":"Needs more explanation, best added as in-code documentation.","commit_id":"e4c4e2fff1272a6a949b347d4bfe38d3d4278f6d"},{"author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"change_message_id":"0946f258b227a1a1d079ea415c60d073df96b685","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"2f9b8ef7_1ef4b5d4","updated":"2026-08-17 10:34:49.000000000","message":"Just a few minor-ish comments. 😊","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"}],"src/openvpn/mudp.c":[{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"ab074131852d1d76082ad78ec6cd9534620dcc00","unresolved":true,"context_lines":[{"line_number":80,"context_line":"    PRE_DECRYPT_CREATE_SESSION_SKIP"},{"line_number":81,"context_line":"};"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"/* Returns true if this packet should create a new session */"},{"line_number":84,"context_line":"static enum pre_decrypt_verdict"},{"line_number":85,"context_line":"do_pre_decrypt_check(struct multi_context *m, struct tls_pre_decrypt_state *state,"},{"line_number":86,"context_line":"                     struct mroute_addr addr, struct link_socket *sock)"}],"source_content_type":"text/x-csrc","patch_set":4,"id":"2bb3363f_a8fbd3eb","line":83,"updated":"2026-08-05 14:04:01.000000000","message":"Obsolete comment. Please add some explanation here about the different states.","commit_id":"e4c4e2fff1272a6a949b347d4bfe38d3d4278f6d"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"f94600ac9925a1f64e2f4dfe8dd7ea303ecb3172","unresolved":true,"context_lines":[{"line_number":80,"context_line":"    PRE_DECRYPT_CREATE_SESSION_SKIP"},{"line_number":81,"context_line":"};"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"/* Returns true if this packet should create a new session */"},{"line_number":84,"context_line":"static enum pre_decrypt_verdict"},{"line_number":85,"context_line":"do_pre_decrypt_check(struct multi_context *m, struct tls_pre_decrypt_state *state,"},{"line_number":86,"context_line":"                     struct mroute_addr addr, struct link_socket *sock)"}],"source_content_type":"text/x-csrc","patch_set":4,"id":"e7731825_d660ca9a","line":83,"in_reply_to":"2bb3363f_a8fbd3eb","updated":"2026-08-05 19:20:44.000000000","message":"I added the different states as doxygen comments in the enum itself. Is that the right direction?","commit_id":"e4c4e2fff1272a6a949b347d4bfe38d3d4278f6d"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"68016bca3aba1a452ab4326ac786595419e47d9f","unresolved":false,"context_lines":[{"line_number":80,"context_line":"    PRE_DECRYPT_CREATE_SESSION_SKIP"},{"line_number":81,"context_line":"};"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"/* Returns true if this packet should create a new session */"},{"line_number":84,"context_line":"static enum pre_decrypt_verdict"},{"line_number":85,"context_line":"do_pre_decrypt_check(struct multi_context *m, struct tls_pre_decrypt_state *state,"},{"line_number":86,"context_line":"                     struct mroute_addr addr, struct link_socket *sock)"}],"source_content_type":"text/x-csrc","patch_set":4,"id":"07cd59a4_a731903c","line":83,"in_reply_to":"e7731825_d660ca9a","updated":"2026-08-27 11:17:24.000000000","message":"Done","commit_id":"e4c4e2fff1272a6a949b347d4bfe38d3d4278f6d"},{"author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"952ed3baa7fc6e5e6bb5a3ed82a773a365e6b2ad","unresolved":true,"context_lines":[{"line_number":216,"context_line":"        }"},{"line_number":217,"context_line":"        gc_free(\u0026gc);"},{"line_number":218,"context_line":""},{"line_number":219,"context_line":"        return PRE_DECRYPT_CREATE_SESSION_SKIP;"},{"line_number":220,"context_line":"    }"},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"    /* VERDICT_INVALID */"}],"source_content_type":"text/x-csrc","patch_set":6,"id":"37634b9b_6d626d52","line":219,"updated":"2026-08-13 12:48:28.000000000","message":"If I got this right, before we returned FALSE for invalid/missing SID or wrong pid, and the calling code did nothing. Now we only log \"ret\" and return PRE_DECRYPT_CREATE_SESSION_SKIP, which makes calling code create multi_instance and call session_skip_to_pre_start() with attacker-supplied session-id. \n\nWhat about\n\nreturn ret ? PRE_DECRYPT_CREATE_SESSION_SKIP : PRE_DECRYPT_NO_ACTION;","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8e1608edc753a0040292f2b11619412890da7529","unresolved":false,"context_lines":[{"line_number":216,"context_line":"        }"},{"line_number":217,"context_line":"        gc_free(\u0026gc);"},{"line_number":218,"context_line":""},{"line_number":219,"context_line":"        return PRE_DECRYPT_CREATE_SESSION_SKIP;"},{"line_number":220,"context_line":"    }"},{"line_number":221,"context_line":""},{"line_number":222,"context_line":"    /* VERDICT_INVALID */"}],"source_content_type":"text/x-csrc","patch_set":6,"id":"0e5c043b_23a1402b","line":219,"in_reply_to":"37634b9b_6d626d52","updated":"2026-08-14 11:56:37.000000000","message":"Done","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"952ed3baa7fc6e5e6bb5a3ed82a773a365e6b2ad","unresolved":true,"context_lines":[{"line_number":246,"context_line":"            \"MULTI: Connection attempt from %s ignored while server is \""},{"line_number":247,"context_line":"            \"shutting down\","},{"line_number":248,"context_line":"            mroute_addr_print(real, \u0026gc));"},{"line_number":249,"context_line":"        return NULL;"},{"line_number":250,"context_line":"    }"},{"line_number":251,"context_line":"    enum pre_decrypt_verdict verdict \u003d do_pre_decrypt_check(m, \u0026state, *real, sock);"},{"line_number":252,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":6,"id":"903eb032_918042cd","line":249,"updated":"2026-08-13 12:48:28.000000000","message":"here we leak gc","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8e1608edc753a0040292f2b11619412890da7529","unresolved":false,"context_lines":[{"line_number":246,"context_line":"            \"MULTI: Connection attempt from %s ignored while server is \""},{"line_number":247,"context_line":"            \"shutting down\","},{"line_number":248,"context_line":"            mroute_addr_print(real, \u0026gc));"},{"line_number":249,"context_line":"        return NULL;"},{"line_number":250,"context_line":"    }"},{"line_number":251,"context_line":"    enum pre_decrypt_verdict verdict \u003d do_pre_decrypt_check(m, \u0026state, *real, sock);"},{"line_number":252,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":6,"id":"88ece37c_ae307f74","line":249,"in_reply_to":"903eb032_918042cd","updated":"2026-08-14 11:56:37.000000000","message":"Done","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000008,"name":"stipa","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"952ed3baa7fc6e5e6bb5a3ed82a773a365e6b2ad","unresolved":true,"context_lines":[{"line_number":277,"context_line":"                 * state is using the same */"},{"line_number":278,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":279,"context_line":"                {"},{"line_number":280,"context_line":"                    mi-\u003econtext.c2.tls_multi-\u003en_sessions++;"},{"line_number":281,"context_line":"                    struct tls_session *session \u003d"},{"line_number":282,"context_line":"                        \u0026mi-\u003econtext.c2.tls_multi-\u003esession[TM_INITIAL];"},{"line_number":283,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":6,"id":"234941b8_caa0d072","line":280,"updated":"2026-08-13 12:48:28.000000000","message":"previously we only incremented sessions when we skipped to pre_start and now we do it for CREATE_SESSION as well, is this intended?","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"8e1608edc753a0040292f2b11619412890da7529","unresolved":false,"context_lines":[{"line_number":277,"context_line":"                 * state is using the same */"},{"line_number":278,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":279,"context_line":"                {"},{"line_number":280,"context_line":"                    mi-\u003econtext.c2.tls_multi-\u003en_sessions++;"},{"line_number":281,"context_line":"                    struct tls_session *session \u003d"},{"line_number":282,"context_line":"                        \u0026mi-\u003econtext.c2.tls_multi-\u003esession[TM_INITIAL];"},{"line_number":283,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":6,"id":"0994f11a_6c2811e3","line":280,"in_reply_to":"234941b8_caa0d072","updated":"2026-08-14 11:56:37.000000000","message":"No. That would count it double. Moved to the if clause below.","commit_id":"217af18cbca9c5fe2aa6794c9f4f6633f150205a"},{"author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"change_message_id":"0946f258b227a1a1d079ea415c60d073df96b685","unresolved":true,"context_lines":[{"line_number":279,"context_line":"                multi_assign_peer_id(m, mi);"},{"line_number":280,"context_line":""},{"line_number":281,"context_line":"                /* If we have a session id already, ensure that the"},{"line_number":282,"context_line":"                 * state is using the same */"},{"line_number":283,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":284,"context_line":"                {"},{"line_number":285,"context_line":"                    struct tls_session *session \u003d"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"7b4c0a0a_8072e62c","line":282,"updated":"2026-08-17 10:34:49.000000000","message":"This comment now appears to be stale.","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"4fd200fd49f2096a8383307105a94c6c874e90b2","unresolved":false,"context_lines":[{"line_number":279,"context_line":"                multi_assign_peer_id(m, mi);"},{"line_number":280,"context_line":""},{"line_number":281,"context_line":"                /* If we have a session id already, ensure that the"},{"line_number":282,"context_line":"                 * state is using the same */"},{"line_number":283,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":284,"context_line":"                {"},{"line_number":285,"context_line":"                    struct tls_session *session \u003d"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"b376acc1_2bdb8e9f","line":282,"in_reply_to":"7b4c0a0a_8072e62c","updated":"2026-08-17 11:39:39.000000000","message":"Done","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"},{"author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"change_message_id":"0946f258b227a1a1d079ea415c60d073df96b685","unresolved":true,"context_lines":[{"line_number":280,"context_line":""},{"line_number":281,"context_line":"                /* If we have a session id already, ensure that the"},{"line_number":282,"context_line":"                 * state is using the same */"},{"line_number":283,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":284,"context_line":"                {"},{"line_number":285,"context_line":"                    struct tls_session *session \u003d"},{"line_number":286,"context_line":"                        \u0026mi-\u003econtext.c2.tls_multi-\u003esession[TM_INITIAL];"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"cd87a5b4_c13c3108","line":283,"updated":"2026-08-17 10:34:49.000000000","message":"Is it possible for this check to be false here?\n\nIt\u0027s possible that I\u0027m missing something, but I _think_ tls_pre_decrypt_lite() is supposed to have run before we\u0027re here, and it rejects packets with no defined peer id.\n\nIf true, we can just remove this test and do something like:\n\n    if (verdict \u003d\u003d PRE_DECRYPT_CREATE_SESSION_SKIP)\n    {\n        ASSERT(session_id_defined(\u0026state.peer_session_id));\n    \n        mi-\u003econtext.c2.tls_multi-\u003en_sessions++;\n        struct tls_session *session \u003d \u0026mi-\u003econtext.c2.tls_multi-\u003esession[TM_INITIAL];\n        session_skip_to_pre_start(session, \u0026state, \u0026m-\u003etop.c2.from);\n    }","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"4fd200fd49f2096a8383307105a94c6c874e90b2","unresolved":false,"context_lines":[{"line_number":280,"context_line":""},{"line_number":281,"context_line":"                /* If we have a session id already, ensure that the"},{"line_number":282,"context_line":"                 * state is using the same */"},{"line_number":283,"context_line":"                if (session_id_defined((\u0026state.peer_session_id)))"},{"line_number":284,"context_line":"                {"},{"line_number":285,"context_line":"                    struct tls_session *session \u003d"},{"line_number":286,"context_line":"                        \u0026mi-\u003econtext.c2.tls_multi-\u003esession[TM_INITIAL];"}],"source_content_type":"text/x-csrc","patch_set":8,"id":"0a45728d_36e85f12","line":283,"in_reply_to":"cd87a5b4_c13c3108","updated":"2026-08-17 11:39:39.000000000","message":"yepp, good idea","commit_id":"0ed03b5aa12f834249b9ecd2e8edb20d5e4d6fef"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"68016bca3aba1a452ab4326ac786595419e47d9f","unresolved":true,"context_lines":[{"line_number":96,"context_line":"{"},{"line_number":97,"context_line":"    /** This packet should not create a new session */"},{"line_number":98,"context_line":"    PRE_DECRYPT_NO_ACTION,"},{"line_number":99,"context_line":"    /** This packet creates a new session normally */"},{"line_number":100,"context_line":"    PRE_DECRYPT_CREATE_SESSION,"},{"line_number":101,"context_line":"    /** Create a new session but skip the first two packets of"},{"line_number":102,"context_line":"     * the three way handshake */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"9fd8d5e8_9886e72b","line":99,"updated":"2026-08-27 11:17:24.000000000","message":"\"normally\" is not very useful here I think. How about: \"This packet creates a new session to store the Wkc while we wait for completion of the challenge.\"","commit_id":"793301a47dcc96dfdd667c31e923d1c416f069e0"},{"author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"68016bca3aba1a452ab4326ac786595419e47d9f","unresolved":true,"context_lines":[{"line_number":99,"context_line":"    /** This packet creates a new session normally */"},{"line_number":100,"context_line":"    PRE_DECRYPT_CREATE_SESSION,"},{"line_number":101,"context_line":"    /** Create a new session but skip the first two packets of"},{"line_number":102,"context_line":"     * the three way handshake */"},{"line_number":103,"context_line":"    PRE_DECRYPT_CREATE_SESSION_SKIP"},{"line_number":104,"context_line":"};"},{"line_number":105,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"3edeef13_ff72c925","line":102,"updated":"2026-08-27 11:17:24.000000000","message":"\"This packet creates a new session. The challenge has already been completed.\"","commit_id":"793301a47dcc96dfdd667c31e923d1c416f069e0"}]}
