)]}'
{"id":"openvpn~1881","triplet_id":"openvpn~master~Iacd56d245e9ab30cfb25b2b364ca661fa289dc55","project":"openvpn","branch":"master","attention_set":{"1000055":{"account":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"last_update":"2026-08-29 14:19:58.000000000","reason":"\u003cGERRIT_ACCOUNT_1000053\u003e replied on the change","reason_account":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}}},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-29 19:46:44.000000000","reason":"\u003cGERRIT_ACCOUNT_1000003\u003e replied on the change","reason_account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}},"1000053":{"account":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"last_update":"2026-08-29 14:19:58.000000000","reason":"\u003cGERRIT_ACCOUNT_1000053\u003e replied on the change","reason_account":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}}},"hashtags":[],"change_id":"Iacd56d245e9ab30cfb25b2b364ca661fa289dc55","subject":"compat: close all unrelated fds in forked helpers","status":"NEW","created":"2026-08-27 16:54:38.000000000","updated":"2026-08-30 20:48:53.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":15,"unresolved_comment_count":13,"has_review_started":true,"meta_rev_id":"a5afa4baa66ec48d949376e8daf79c73d1f2a454","_number":1881,"virtual_id_number":1881,"owner":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"CC":[{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-27 16:54:38.000000000","updated_by":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-08-27 16:54:38.000000000","updated_by":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-08-28 07:05:56.000000000","updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"REVIEWER"},{"updated":"2026-08-29 16:37:49.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"state":"CC"}],"messages":[{"id":"bc541dd49dc05f7e8f6e05deaec88a400c334b41","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"date":"2026-08-27 16:54:38.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"d8be5a6bd174e415f609f15358faa3aeeb3f9e16","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-08-28 07:05:56.000000000","message":"Patch Set 1: Code-Review-1\n\n(7 comments)","accounts_in_message":[],"_revision_number":1},{"id":"bb0fda2926cd3af7d1f15f9be5ae93f62551509a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"date":"2026-08-28 11:05:25.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"06ce56b2f8b59a1e35a235e6b4286e279be86c58","author":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"date":"2026-08-28 11:06:44.000000000","message":"Patch Set 2:\n\nPatch set 2 adds the missing CMake source and non-Windows test target, converts the driver to cmocka, verifies descriptors 0, 1, and 2 survive, restores the full license headers, and documents the helper. The CMake main and focused targets build, CTest passes, and the Clang native and GCC forced-fallback tests both pass.","accounts_in_message":[],"_revision_number":2},{"id":"a9818a68d9a9f67d041bc61bc096dc0687aaa2f0","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-08-29 14:19:58.000000000","message":"Patch Set 2:\n\n(5 comments)","accounts_in_message":[],"_revision_number":2},{"id":"d33cb8c17c852510e48e6a6cb83492f06716c0fb","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-29 16:37:49.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"9c2c5d6f40296d8c301ffb70c8d43d8b60b35446","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-29 19:46:44.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"a5afa4baa66ec48d949376e8daf79c73d1f2a454","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"date":"2026-08-30 20:48:53.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"db8854f550226474ea84c377fdbc5024620f05e4","revisions":{"af300510350e2496a17f0e3e07ae22107bb42d5a":{"kind":"REWORK","_number":1,"created":"2026-08-27 16:54:38.000000000","uploader":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"ref":"refs/changes/81/1881/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/81/1881/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1 \u0026\u0026 git checkout -b change-1881 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2508b2d749f3cd4d951867156700af30c0db7eae","subject":"init: Fix conversion warnings"}],"author":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-21 10:10:04.000000000","tz":-240},"committer":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-27 16:16:19.000000000","tz":-240},"subject":"compat: close all unrelated fds in forked helpers","message":"compat: close all unrelated fds in forked helpers\n\nThe forked auth-pam, down-root, and port-share helpers only closed\ndescriptor numbers 3 through 100. Descriptors above that range could\nremain open in long-lived helper processes, including helpers that\nintentionally retain privilege.\n\nAdd a shared compatibility helper that uses close_range() when available\nand falls back to the process descriptor limit. Preserve the helper\ncommand socket and add coverage for both low and high preserved\ndescriptors.\n\nChange-Id: Iacd56d245e9ab30cfb25b2b364ca661fa289dc55\nSigned-off-by: David Sarkisyan \u003cdavid@srkyn.com\u003e\n"},"branch":"refs/heads/master"},"af724b68aea7ad161492da8aad1cd8a5ff456bd5":{"kind":"REWORK","_number":2,"created":"2026-08-28 11:05:25.000000000","uploader":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"ref":"refs/changes/81/1881/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/81/1881/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2 \u0026\u0026 git checkout -b change-1881 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2508b2d749f3cd4d951867156700af30c0db7eae","subject":"init: Fix conversion warnings"}],"author":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-21 10:10:04.000000000","tz":-240},"committer":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-28 11:03:53.000000000","tz":-240},"subject":"compat: close all unrelated fds in forked helpers","message":"compat: close all unrelated fds in forked helpers\n\nThe forked auth-pam, down-root, and port-share helpers only closed\ndescriptor numbers 3 through 100. Descriptors above that range could\nremain open in long-lived helper processes, including helpers that\nintentionally retain privilege.\n\nAdd a shared compatibility helper that uses close_range() when available\nand falls back to the process descriptor limit. Preserve the helper\ncommand socket and add coverage for both low and high preserved\ndescriptors.\n\nChange-Id: Iacd56d245e9ab30cfb25b2b364ca661fa289dc55\nSigned-off-by: David Sarkisyan \u003cdavid@srkyn.com\u003e\n"},"branch":"refs/heads/master"},"db8854f550226474ea84c377fdbc5024620f05e4":{"kind":"REWORK","_number":3,"created":"2026-08-30 20:48:53.000000000","uploader":{"_account_id":1000055,"name":"srkyn","email":"david@srkyn.com","username":"srkyn"},"ref":"refs/changes/81/1881/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/81/1881/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3 \u0026\u0026 git checkout -b change-1881 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/81/1881/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2508b2d749f3cd4d951867156700af30c0db7eae","subject":"init: Fix conversion warnings"}],"author":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-21 10:10:04.000000000","tz":-240},"committer":{"name":"David Sarkisyan","email":"david@srkyn.com","date":"2026-08-30 20:47:59.000000000","tz":-240},"subject":"compat: close all unrelated fds in forked helpers","message":"compat: close all unrelated fds in forked helpers\n\nThe forked auth-pam, down-root, and port-share helpers only closed\ndescriptor numbers 3 through 100. Descriptors above that range could\nremain open in long-lived helper processes, including helpers that\nintentionally retain privilege.\n\nAdd a shared compatibility helper that uses close_range() when available\nand falls back to the process descriptor limit. Preserve the helper\ncommand socket and add coverage for both low and high preserved\ndescriptors.\n\nChange-Id: Iacd56d245e9ab30cfb25b2b364ca661fa289dc55\nSigned-off-by: David Sarkisyan \u003cdavid@srkyn.com\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
