)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"change_message_id":"6d621c45eb9a089a73f225e8c4dbcec60b78ce60","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"363f7b65_da0012a9","updated":"2026-09-07 12:40:25.000000000","message":"One question based on stare-at-code. Didn\u0027t test yet.","commit_id":"efb1f77d28be164260bf4235949ee81f9aff5124"},{"author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"55e410778b03caad09ec25b5c9800ba083e71050","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"e80b5a76_1c79fa86","updated":"2026-09-17 09:49:30.000000000","message":"doing explicit `for()` loops to \"find a number in a buffer\" feels clumsy... but this is just in case you want to do another round anyway, I\u0027ll commit it either way if Steffan +2\u0027s it","commit_id":"124c4ffe53af78ba007ffe23de2f952fadfc30ae"}],"src/openvpn/ssl_verify_openssl.c":[{"author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"change_message_id":"6d621c45eb9a089a73f225e8c4dbcec60b78ce60","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"c50e1cc5_1b545483","side":"PARENT","line":389,"updated":"2026-09-07 12:40:25.000000000","message":"Why remove the ESC_CTRL?","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"d8d585486911b1768bc9804b83cb61a72ff97938","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"3fffd9fc_ccfa4019","side":"PARENT","line":389,"in_reply_to":"210ac99e_88f02f74","updated":"2026-09-10 23:06:45.000000000","message":"Alternatively, we could check for \"\\\\0\" substrings. Seems cleaner to me than parsing the subject twice.\n\nSince you misunderstood the change in master, would you like me to make the same change there?","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"b8a932c40e357654eb9bda0d73472a70868f8f85","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"9fedb878_47595476","side":"PARENT","line":389,"in_reply_to":"3fffd9fc_ccfa4019","updated":"2026-09-16 21:43:59.000000000","message":"I changed the code to escape control characters again. I went with the approach of calling the print function twice after all because that way is less error-prone.","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"change_message_id":"9f4a484eeb52f6c1a6b819316cd91a94eb12aa7b","unresolved":false,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"9ac2163d_204c3cfd","side":"PARENT","line":389,"in_reply_to":"9fedb878_47595476","updated":"2026-09-17 12:33:32.000000000","message":"Acknowledged","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"c1ae08a821712faa72373048af254765d7653b39","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"ff834928_84e03501","side":"PARENT","line":389,"in_reply_to":"c50e1cc5_1b545483","updated":"2026-09-07 12:54:20.000000000","message":"I did the same thing in the master branch. This flag was escaping null bytes to \u0027\\\\0\u0027, so the check after it wouldn\u0027t work.","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"change_message_id":"538bc928d290f4a73690ca7bab65b9aee22c7b31","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"210ac99e_88f02f74","side":"PARENT","line":389,"in_reply_to":"f93e7c60_473c2dec","updated":"2026-09-07 13:47:38.000000000","message":"(Where that last remark about using RFC2253 is about master, not release/2.7)","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"change_message_id":"157e0920bf6675214eb50a1d651503a2d15c6a73","unresolved":true,"context_lines":[{"line_number":386,"context_line":""},{"line_number":387,"context_line":"    X509_NAME_print_ex(subject_bio, X509_get_subject_name(cert), 0,"},{"line_number":388,"context_line":"                       XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN | ASN1_STRFLGS_UTF8_CONVERT"},{"line_number":389,"context_line":"                           | ASN1_STRFLGS_ESC_CTRL);"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"    if (BIO_eof(subject_bio))"},{"line_number":392,"context_line":"    {"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"f93e7c60_473c2dec","side":"PARENT","line":389,"in_reply_to":"ff834928_84e03501","updated":"2026-09-07 13:46:17.000000000","message":"Hmm, but that still changes user-visible behavior, since we now no longer escape all the other control characters. Maybe we need two print_ex calls: one to check for null-bytes and one for actually printing the subject.\n\nFor master I seem to have missed there are two closely related escape names: ASN1_STRFLGS_RFC2253 and ASN1_STRFLGS_ESC_2253. I thought you used the RFC2253 one, which also includes ESC_CTRL... Which makes me wonder, shouldn\u0027t we use the RFC2253 one for the actual printing (and also have one extra just for checking for nul-bytes)?","commit_id":"acd9702b6cdf94b173e78a6e310e408ffe33aec2"},{"author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"change_message_id":"55e410778b03caad09ec25b5c9800ba083e71050","unresolved":true,"context_lines":[{"line_number":405,"context_line":"            msg(M_WARN, \"ERROR: Certificate subject contains a \u0027\\\\0\u0027 byte.\");"},{"line_number":406,"context_line":"            goto err;"},{"line_number":407,"context_line":"        }"},{"line_number":408,"context_line":"    }"},{"line_number":409,"context_line":""},{"line_number":410,"context_line":"    /* Now output the subject with escaped control characters. */"},{"line_number":411,"context_line":"    if (!BIO_reset(subject_bio))"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"2d301fa2_cd509a6b","line":408,"updated":"2026-09-17 09:49:30.000000000","message":"```\nif (memchr(subject_mem-\u003edata, 0, subject_mem-\u003elength) !\u003d NULL)\n```\n?","commit_id":"124c4ffe53af78ba007ffe23de2f952fadfc30ae"},{"author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"3a0b8ba0db90be79c731ddb3742a1b2fb9b1e79a","unresolved":false,"context_lines":[{"line_number":405,"context_line":"            msg(M_WARN, \"ERROR: Certificate subject contains a \u0027\\\\0\u0027 byte.\");"},{"line_number":406,"context_line":"            goto err;"},{"line_number":407,"context_line":"        }"},{"line_number":408,"context_line":"    }"},{"line_number":409,"context_line":""},{"line_number":410,"context_line":"    /* Now output the subject with escaped control characters. */"},{"line_number":411,"context_line":"    if (!BIO_reset(subject_bio))"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"1da26cc9_aea5d429","line":408,"in_reply_to":"2d301fa2_cd509a6b","updated":"2026-09-17 11:34:25.000000000","message":"I had to push another version because I didn\u0027t check the return value of BIO_reset correctly, so I also replaced the for-loop. I wasn\u0027t aware that memchr exists, so thanks for pointing it out!","commit_id":"124c4ffe53af78ba007ffe23de2f952fadfc30ae"}]}
