)]}'
{"id":"openvpn~1832","triplet_id":"openvpn~master~I3c7d1f9e5b2a4c6d8e1f3a5b7c9d2e4f6a8b1c3d","project":"openvpn","branch":"master","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-31 11:44:41.000000000","reason":"\u003cGERRIT_ACCOUNT_1000003\u003e replied on the change","reason_account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}},"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-07-31 20:09:36.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I3c7d1f9e5b2a4c6d8e1f3a5b7c9d2e4f6a8b1c3d","subject":"ssl: Ignore hard reset packets with a non-zero packet id","status":"MERGED","created":"2026-07-30 09:03:40.000000000","updated":"2026-07-31 20:09:36.000000000","submitted":"2026-07-31 20:09:36.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1832","meta_rev_id":"8e1f4b21296e2804cb96d470ac48bc8fa7293ea6","_number":1832,"virtual_id_number":1832,"owner":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-30 09:03:41.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-30 09:03:41.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"20bd2367e30d2b0ee6dae06bc3d05260d51ce464","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-30 09:03:40.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"a34bffc798c646c1385acde5abf78d267a41c89d","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-31 11:44:41.000000000","message":"Patch Set 1: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"8e1f4b21296e2804cb96d470ac48bc8fa7293ea6","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-07-31 20:09:36.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"d1e67f419f1ea9121d44fa4b91c59e7209785e57","revisions":{"2962c4e1c61699905dba0ce2d6efc6799f984b13":{"kind":"REWORK","_number":1,"created":"2026-07-30 09:03:40.000000000","uploader":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"ref":"refs/changes/32/1832/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/32/1832/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1 \u0026\u0026 git checkout -b change-1832 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"1e8bc06b45f792230e2bea4643053a50fade344c","subject":"ssl: Do not queue control ciphertext while a packet is still queued"}],"author":{"name":"Frank Lichtenheld","email":"frank@lichtenheld.com","date":"2026-07-28 15:53:30.000000000","tz":120},"committer":{"name":"Frank Lichtenheld","email":"frank@lichtenheld.com","date":"2026-07-30 09:03:06.000000000","tz":120},"subject":"ssl: Ignore hard reset packets with a non-zero packet id","message":"ssl: Ignore hard reset packets with a non-zero packet id\n\nA hard reset is always the first packet of a session, so it always\ncarries reliable packet id 0. tls_process_state() relies on that when it\ntreats a received reset as the early negotiation packet only for packet\nid 0, and the stateless three-way handshake relies on it as well (see\nthe comment in session_skip_to_pre_start()).\n\nA reset claiming a different id is therefore bogus.\n\nWe had a bug that could cause hard reset replays with packet id 1 in\nspecific scenarios (P2P TCP). In that case we accepted the packet id\nat face value and then ignored the control packet that actually had\nid 1 as an replay. This caused a difficult to diagnose dead connection\nthat was stuck just before TLS negotiation. The check added handles\nthis specific scenario well in that we just ignore the bogus reset\nbut do not abort the connection attempt. Starting fresh might retrigger\nthe bug. If there would be a separate bug where the client only sends\nhard resets with packet id 1 we will still get logging on the server\nside now.\n\nChange-Id: I3c7d1f9e5b2a4c6d8e1f3a5b7c9d2e4f6a8b1c3d\nSigned-off-by: Frank Lichtenheld \u003cfrank@lichtenheld.com\u003e\n"},"branch":"refs/heads/master"},"d1e67f419f1ea9121d44fa4b91c59e7209785e57":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":2,"created":"2026-07-31 20:09:36.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/32/1832/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/32/1832/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2 \u0026\u0026 git checkout -b change-1832 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/32/1832/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d9ae1f0fa43f8ac2551f048f90f37a110a9ecaa4","subject":"t_server_null: run server processes with \u0027ulimit -t 300\u0027"}],"author":{"name":"Frank Lichtenheld","email":"frank@lichtenheld.com","date":"2026-07-31 11:45:54.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-07-31 12:49:58.000000000","tz":120},"subject":"ssl: Ignore hard reset packets with a non-zero packet id","message":"ssl: Ignore hard reset packets with a non-zero packet id\n\nA hard reset is always the first packet of a session, so it always\ncarries reliable packet id 0. tls_process_state() relies on that when it\ntreats a received reset as the early negotiation packet only for packet\nid 0, and the stateless three-way handshake relies on it as well (see\nthe comment in session_skip_to_pre_start()).\n\nA reset claiming a different id is therefore bogus.\n\nWe had a bug that could cause hard reset replays with packet id 1 in\nspecific scenarios (P2P TCP). In that case we accepted the packet id\nat face value and then ignored the control packet that actually had\nid 1 as an replay. This caused a difficult to diagnose dead connection\nthat was stuck just before TLS negotiation. The check added handles\nthis specific scenario well in that we just ignore the bogus reset\nbut do not abort the connection attempt. Starting fresh might retrigger\nthe bug. If there would be a separate bug where the client only sends\nhard resets with packet id 1 we will still get logging on the server\nside now.\n\nChange-Id: I3c7d1f9e5b2a4c6d8e1f3a5b7c9d2e4f6a8b1c3d\nSigned-off-by: Frank Lichtenheld \u003cfrank@lichtenheld.com\u003e\nAcked-by: Arne Schwabe \u003carne-openvpn@rfc2549.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1832\nMessage-Id: \u003c20260731114605.11596-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38098.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
