)]}'
{"id":"openvpn~1835","triplet_id":"openvpn~master~I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd","project":"openvpn","branch":"master","attention_set":{"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-08-05 15:48:17.000000000","reason":"\u003cGERRIT_ACCOUNT_1000007\u003e replied on the change","reason_account":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"}},"1000007":{"account":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"last_update":"2026-08-06 11:40:53.000000000","reason":"Someone else replied on the change"}},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-06 11:40:53.000000000","reason":"removed on reply"},"1000041":{"account":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"last_update":"2026-08-06 13:16:30.000000000","reason":"\u003cGERRIT_ACCOUNT_1000041\u003e replied on the change","reason_account":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}}},"hashtags":[],"change_id":"I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd","subject":"dco: do not exit the process when installing a DCO key fails","status":"NEW","created":"2026-08-05 01:27:22.000000000","updated":"2026-08-06 13:16:30.000000000","submit_type":"CHERRY_PICK","submittable":true,"total_comment_count":12,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"71b8cbc7dce51d6de59258059b3ef3d395dd78a4","_number":1835,"virtual_id_number":1835,"owner":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"actions":{},"labels":{"Code-Review":{"approved":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"all":[{"value":2,"date":"2026-08-06 11:40:53.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":2,"date":"2026-08-06 13:16:30.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}],"CC":[{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-05 01:27:23.000000000","updated_by":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-08-05 01:27:23.000000000","updated_by":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-08-05 07:10:22.000000000","updated_by":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"reviewer":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"state":"CC"},{"updated":"2026-08-05 13:27:24.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"CC"},{"updated":"2026-08-05 16:04:40.000000000","updated_by":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"reviewer":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"state":"REVIEWER"}],"messages":[{"id":"4a528da1d7ac50617d8519e4b60d57c47207b40a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 01:27:22.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"58b8e59132fac3ff4d29048de88856a8028ad6c1","author":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-08-05 07:10:22.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"fe4e02df0c2d1316cf98ec775f089bbc9cb5539f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 11:05:42.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"3e24d378c0c8a3d608dbc60ed819d50740c5ead6","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 11:07:11.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"e13ff0a5435d6556a1dbf0e6b9a9db0f9d195efc","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-08-05 13:27:24.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"a5e2bebb8e788d732b979883f16590625e65a4e0","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-05 14:09:33.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"d8a2cf7cb8cd9c3ee08c2ef84f26de7056742348","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 15:48:17.000000000","message":"Patch Set 2:\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"4c1b80e94921bc7d0b5912c0c4d2fe348a581a8b","author":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-08-05 16:04:40.000000000","message":"Patch Set 2: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"f220343cdf9ca1bfb628cea356c66ac5d2024186","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-06 11:24:28.000000000","message":"Patch Set 2:\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"0c7c8d1efb0ff2c498ff13d531b013b5e174e002","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-06 11:24:39.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"2cfb12a1200c7ed3ea74cd70eb9229fe3ab4dc97","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-06 11:40:53.000000000","message":"Patch Set 3: Code-Review+2","accounts_in_message":[],"_revision_number":3},{"id":"71b8cbc7dce51d6de59258059b3ef3d395dd78a4","author":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"},"date":"2026-08-06 13:16:30.000000000","message":"Patch Set 3: Code-Review+2","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"031918103f2e8e2063368d0e347a72ae8b95ea1c","revisions":{"9f0e71a3741abae86ab67bd74d7530db76e1d604":{"kind":"REWORK","_number":1,"created":"2026-08-05 01:27:22.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/35/1835/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/35/1835/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1 \u0026\u0026 git checkout -b change-1835 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d1e67f419f1ea9121d44fa4b91c59e7209785e57","subject":"ssl: Ignore hard reset packets with a non-zero packet id"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 00:25:24.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 00:25:24.000000000","tz":120},"subject":"dco: do not exit the process when installing a DCO key fails","message":"dco: do not exit the process when installing a DCO key fails\n\nWhen the DCO peer is gone from the kernel while userspace still believes\nit exists, dco_new_key() fails with ENOENT and init_key_contexts() calls\nmsg(M_FATAL, ...). On a server this terminates the whole daemon and\ndisconnects every other client, even though only a single peer is\naffected.\n\nMake init_key_contexts() return a bool and propagate the failure through\ngenerate_key_expansion(), which already has an error path that wipes the\ngenerated key material. Record the condition in tls_multi so that\ndco_update_keys() reports the mismatch and the existing\ncheck_dco_key_status() caller restarts only the affected connection,\nwhich re-creates the DCO peer from scratch.\n\nNote that commit ea3bb67e2b1e (\"dco: make key state desync recoverable\")\ndoes not cover this case, as both of its hunks are conditional on the\nkey installation having succeeded.\n\nGithub: fixes OpenVPN/openvpn#542\nChange-Id: I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"673e321220a104f42914bd04adb1968a7b2d9112":{"kind":"REWORK","_number":2,"created":"2026-08-05 11:05:42.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/35/1835/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/35/1835/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2 \u0026\u0026 git checkout -b change-1835 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d1e67f419f1ea9121d44fa4b91c59e7209785e57","subject":"ssl: Ignore hard reset packets with a non-zero packet id"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:09:49.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:23:43.000000000","tz":120},"subject":"dco: do not exit the process when installing a DCO key fails","message":"dco: do not exit the process when installing a DCO key fails\n\nWhen the DCO peer is gone from the kernel while userspace still believes\nit exists, dco_new_key() fails with ENOENT and init_key_contexts() calls\nmsg(M_FATAL, ...). On a server this terminates the whole daemon and\ndisconnects every other client, even though only a single peer is\naffected.\n\nPropagate the failure instead. Since a DCO desync needs a different\nrecovery than any other key generation error - the kernel peer has to be\nre-created, which only a reconnect can do - report it as a distinct\nkey_gen_status through generate_key_expansion() and\ntls_session_generate_data_channel_keys(), and let tls_multi_process()\nturn it into a new TLSMP_RESTART result that check_tls() dispatches as a\nSIGUSR1. On a server this restarts only the affected client instance.\n\nThe restart request is tracked separately from \u0027active\u0027 because it must\nnot be overwritten by a later TLSMP_ACTIVE or TLSMP_RECONNECT\nassignment, and the return value now applies an explicit precedence:\nkilling the session supersedes restarting it, which supersedes \u0027active\u0027.\n\ntls_session_update_crypto_params_do_work() collapses the desync back to\na plain failure, as all of its callers already turn a failure into a\nSIGUSR1.\n\nNote that commit ea3bb67e2b1e (\"dco: make key state desync recoverable\")\ndoes not cover this case, as both of its hunks are conditional on the\nkey installation having succeeded.\n\nGithub: fixes OpenVPN/openvpn#542\nChange-Id: I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"031918103f2e8e2063368d0e347a72ae8b95ea1c":{"kind":"REWORK","_number":3,"created":"2026-08-06 11:24:39.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/35/1835/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/35/1835/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3 \u0026\u0026 git checkout -b change-1835 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/35/1835/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d1e67f419f1ea9121d44fa4b91c59e7209785e57","subject":"ssl: Ignore hard reset packets with a non-zero packet id"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:09:49.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-06 11:24:01.000000000","tz":120},"subject":"dco: do not exit the process when installing a DCO key fails","message":"dco: do not exit the process when installing a DCO key fails\n\nWhen the DCO peer is gone from the kernel while userspace still believes\nit exists, dco_new_key() fails with ENOENT and init_key_contexts() calls\nmsg(M_FATAL, ...). On a server this terminates the whole daemon and\ndisconnects every other client, even though only a single peer is\naffected.\n\nPropagate the failure instead. Since a DCO desync needs a different\nrecovery than any other key generation error - the kernel peer has to be\nre-created, which only a reconnect can do - report it as a distinct\nkey_gen_status through generate_key_expansion() and\ntls_session_generate_data_channel_keys(), and let tls_multi_process()\nturn it into a new TLSMP_RESTART result that check_tls() dispatches as a\nSIGUSR1. On a server this restarts only the affected client instance.\n\nThe restart request is tracked separately from \u0027active\u0027 because it must\nnot be overwritten by a later TLSMP_ACTIVE or TLSMP_RECONNECT\nassignment, and the return value now applies an explicit precedence:\nkilling the session supersedes restarting it, which supersedes \u0027active\u0027.\n\ntls_session_update_crypto_params_do_work() collapses the desync back to\na plain failure, as all of its callers already turn a failure into a\nSIGUSR1.\n\nNote that commit ea3bb67e2b1e (\"dco: make key state desync recoverable\")\ndoes not cover this case, as both of its hunks are conditional on the\nkey installation having succeeded.\n\nGithub: fixes OpenVPN/openvpn#542\nChange-Id: I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Code-Review","status":"OK","applied_by":{"_account_id":1000041,"name":"ralf_lici","display_name":"Ralf Lici","email":"ralf@mandelbit.com","username":"ralf_lici"}}]},{"rule_name":"checks~ChecksSubmitRule","status":"OK"}],"submit_requirements":[{"name":"Code-Review","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"],"failing_atoms":[]}},{"name":"checks~ChecksSubmitRule","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":true,"status":"PASS","passing_atoms":["checks~ChecksSubmitRule"],"failing_atoms":[]}}]}
