)]}'
{"id":"openvpn~1836","triplet_id":"openvpn~master~Icc0721fd4a910110507d06b4e941e9e6dbb11e9f","project":"openvpn","branch":"master","attention_set":{"1000007":{"account":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"last_update":"2026-08-05 09:23:41.000000000","reason":"Someone else replied on the change"}},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-05 16:06:50.000000000","reason":"removed on reply"}},"hashtags":[],"change_id":"Icc0721fd4a910110507d06b4e941e9e6dbb11e9f","subject":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher","status":"NEW","created":"2026-08-05 01:27:22.000000000","updated":"2026-08-06 11:24:39.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"ddadee8191ce1fa4e03d91d4b108816dbfe2e752","_number":1836,"virtual_id_number":1836,"owner":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"actions":{},"labels":{"Code-Review":{"approved":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"all":[{"value":2,"date":"2026-08-06 11:24:39.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-05 01:27:23.000000000","updated_by":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-08-05 01:27:23.000000000","updated_by":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"e1f3de35319b75e195c315f1b91610f7e1507cb3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 01:27:22.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"db35c9f0c67b3351fbdaca53ff45bdb4952afbd5","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-05 09:23:41.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"c932dbd61a9cf4886ff8c76f96c966394f508bdb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-05 11:05:42.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"69ed0b5e1531c66a84bad7bf1e58da11750bd1d5","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-05 16:06:50.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"ddadee8191ce1fa4e03d91d4b108816dbfe2e752","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"date":"2026-08-06 11:24:39.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.\n\nCopied Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"84e155246221f2d6e4cdb939634c5a80c6398d3a","revisions":{"9c799a5e6b94f273ffc6c70a84ef21a89a53df60":{"kind":"REWORK","_number":1,"created":"2026-08-05 01:27:22.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/36/1836/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/36/1836/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1 \u0026\u0026 git checkout -b change-1836 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9f0e71a3741abae86ab67bd74d7530db76e1d604","subject":"dco: do not exit the process when installing a DCO key fails"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 00:25:45.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 00:25:45.000000000","tz":120},"subject":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher","message":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher\n\nThe epoch data key format is defined for AEAD ciphers only. Both places\nthat enable it locally verify this - multi.c when picking the cipher to\npush and ssl_ncp.c for p2p NCP - but the pulling side imports the\n\"aead-epoch\" protocol flag without validating it against the cipher that\nwas actually negotiated.\n\nA peer pushing \"protocol-flags aead-epoch\" together with a non-AEAD\ncipher therefore makes us reach the M_FATAL in init_key_contexts() and\nterminate the process. This can be triggered whenever a non-AEAD cipher\nis part of our own --data-ciphers, which is not unusual in\nconfigurations kept compatible with old peers, e.g.\n\n  data-ciphers AES-256-GCM:AES-256-CBC\n\nValidate the combination in do_deferred_options(), next to the existing\ndata v2 check, so that the mismatch is reported as an OPTIONS ERROR and\nthe connection is restarted. Turn the now unreachable M_FATAL in\ninit_key_contexts() into a session error as well, so that no future code\npath can promote this to a process exit.\n\nChange-Id: Icc0721fd4a910110507d06b4e941e9e6dbb11e9f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"e7ba43c8495f1a1d969e81514e690de485360e89":{"kind":"REWORK","_number":2,"created":"2026-08-05 11:05:42.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/36/1836/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/36/1836/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2 \u0026\u0026 git checkout -b change-1836 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"673e321220a104f42914bd04adb1968a7b2d9112","subject":"dco: do not exit the process when installing a DCO key fails"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:10:35.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:24:00.000000000","tz":120},"subject":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher","message":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher\n\nThe epoch data key format is defined for AEAD ciphers only. Both places\nthat enable it locally verify this - multi.c when picking the cipher to\npush and ssl_ncp.c for p2p NCP - but the pulling side imports the\n\"aead-epoch\" protocol flag without validating it against the cipher that\nwas actually negotiated.\n\nA peer pushing \"protocol-flags aead-epoch\" together with a non-AEAD\ncipher therefore makes us reach the M_FATAL in init_key_contexts() and\nterminate the process. This can be triggered whenever a non-AEAD cipher\nis part of our own --data-ciphers, which is not unusual in\nconfigurations kept compatible with old peers, e.g.\n\n  data-ciphers AES-256-GCM:AES-256-CBC\n\nValidate the combination in do_deferred_options(), next to the existing\ndata v2 check, so that the mismatch is reported as an OPTIONS ERROR and\nthe connection is restarted. Turn the now unreachable M_FATAL in\ninit_key_contexts() into a session error as well, so that no future code\npath can promote this to a process exit.\n\nChange-Id: Icc0721fd4a910110507d06b4e941e9e6dbb11e9f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"},"84e155246221f2d6e4cdb939634c5a80c6398d3a":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-08-06 11:24:39.000000000","uploader":{"_account_id":1000007,"name":"ordex","display_name":"Antonio Quartulli","email":"antonio@mandelbit.com","username":"ordex"},"ref":"refs/changes/36/1836/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/36/1836/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3 \u0026\u0026 git checkout -b change-1836 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/36/1836/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"031918103f2e8e2063368d0e347a72ae8b95ea1c","subject":"dco: do not exit the process when installing a DCO key fails"}],"author":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-05 09:10:35.000000000","tz":120},"committer":{"name":"Antonio Quartulli","email":"antonio@mandelbit.com","date":"2026-08-06 11:24:02.000000000","tz":120},"subject":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher","message":"ssl: reject a pushed epoch data format tag with a non-AEAD cipher\n\nThe epoch data key format is defined for AEAD ciphers only. Both places\nthat enable it locally verify this - multi.c when picking the cipher to\npush and ssl_ncp.c for p2p NCP - but the pulling side imports the\n\"aead-epoch\" protocol flag without validating it against the cipher that\nwas actually negotiated.\n\nA peer pushing \"protocol-flags aead-epoch\" together with a non-AEAD\ncipher therefore makes us reach the M_FATAL in init_key_contexts() and\nterminate the process. This can be triggered whenever a non-AEAD cipher\nis part of our own --data-ciphers, which is not unusual in\nconfigurations kept compatible with old peers, e.g.\n\n  data-ciphers AES-256-GCM:AES-256-CBC\n\nValidate the combination in do_deferred_options(), next to the existing\ndata v2 check, so that the mismatch is reported as an OPTIONS ERROR and\nthe connection is restarted. Turn the now unreachable M_FATAL in\ninit_key_contexts() into a session error as well, so that no future code\npath can promote this to a process exit.\n\nChange-Id: Icc0721fd4a910110507d06b4e941e9e6dbb11e9f\nSigned-off-by: Antonio Quartulli \u003cantonio@mandelbit.com\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Code-Review","status":"OK","applied_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"],"failing_atoms":[]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
