)]}'
{"src/openvpn/ssl.c":[{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"18bd0902b9ba1f175ac4b2408f2c326e021958e8","unresolved":true,"context_lines":[{"line_number":2622,"context_line":"                    /* Only a tls-crypt-v2 client has a wrapped client key to"},{"line_number":2623,"context_line":"                     * resend. The flag comes from the peer, so a peer that asks"},{"line_number":2624,"context_line":"                     * anyone else is broken or hostile; ignore it rather than"},{"line_number":2625,"context_line":"                     * promising a key we do not have. */"},{"line_number":2626,"context_line":"                    if (session-\u003etls_wrap.tls_crypt_v2_wkc)"},{"line_number":2627,"context_line":"                    {"},{"line_number":2628,"context_line":"                        ks-\u003ecrypto_options.flags |\u003d CO_RESEND_WKC;"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"28bbd6d6_fa5ad272","line":2625,"updated":"2026-09-15 09:59:31.000000000","message":"This is quite strangely written and talks about the client itself in a weird 3rd person and does not follow our style of comments\n\n```suggestion\n                     * Only accept the EARLY_NEG_FLAG_RESEND_WKC flag \n                     * from the server if we are configured with tls-crypt-v2\n```","commit_id":"65262c0afd5095fa68f320d23fdacd1b8c8a8e92"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"8d5b1c192ad679c6dd2db3c6e0ca24ccf84408b7","unresolved":false,"context_lines":[{"line_number":2622,"context_line":"                    /* Only a tls-crypt-v2 client has a wrapped client key to"},{"line_number":2623,"context_line":"                     * resend. The flag comes from the peer, so a peer that asks"},{"line_number":2624,"context_line":"                     * anyone else is broken or hostile; ignore it rather than"},{"line_number":2625,"context_line":"                     * promising a key we do not have. */"},{"line_number":2626,"context_line":"                    if (session-\u003etls_wrap.tls_crypt_v2_wkc)"},{"line_number":2627,"context_line":"                    {"},{"line_number":2628,"context_line":"                        ks-\u003ecrypto_options.flags |\u003d CO_RESEND_WKC;"}],"source_content_type":"text/x-csrc","patch_set":2,"id":"a53010cb_09d451a0","line":2625,"in_reply_to":"28bbd6d6_fa5ad272","updated":"2026-09-15 11:11:55.000000000","message":"Agreed, will simplify the comment.","commit_id":"65262c0afd5095fa68f320d23fdacd1b8c8a8e92"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"18bd0902b9ba1f175ac4b2408f2c326e021958e8","unresolved":true,"context_lines":[{"line_number":2682,"context_line":"control_packet_needs_wkc(const struct tls_session *session, const struct key_state *ks)"},{"line_number":2683,"context_line":"{"},{"line_number":2684,"context_line":"    return (ks-\u003ecrypto_options.flags \u0026 CO_RESEND_WKC) \u0026\u0026 (ks-\u003esend_reliable-\u003epacket_id \u003d\u003d 1)"},{"line_number":2685,"context_line":"           \u0026\u0026 session-\u003etls_wrap.tls_crypt_v2_wkc;"},{"line_number":2686,"context_line":"}"},{"line_number":2687,"context_line":""},{"line_number":2688,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":2,"id":"2649fc5a_7c021f6d","line":2685,"updated":"2026-09-15 09:59:31.000000000","message":"I don\u0027t particulary like mixing in this condition into this condition as it now does not really match its name anymore. Either rename the function to something better like control_packet_should_append_wkc or move the check if we can actually append the wkc to the caller and keep the function name.\n\nAlso it seems that we are actually checking for if we can really send it with the \"                msg(D_TLS_ERRORS, \"Could not append tls-crypt-v2 client key\");\" key that then also properly reports an error in the log instead of silently not sending the WKc key.\n\nIt feels like this change is better to be just dropped.","commit_id":"65262c0afd5095fa68f320d23fdacd1b8c8a8e92"},{"author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"change_message_id":"8d5b1c192ad679c6dd2db3c6e0ca24ccf84408b7","unresolved":false,"context_lines":[{"line_number":2682,"context_line":"control_packet_needs_wkc(const struct tls_session *session, const struct key_state *ks)"},{"line_number":2683,"context_line":"{"},{"line_number":2684,"context_line":"    return (ks-\u003ecrypto_options.flags \u0026 CO_RESEND_WKC) \u0026\u0026 (ks-\u003esend_reliable-\u003epacket_id \u003d\u003d 1)"},{"line_number":2685,"context_line":"           \u0026\u0026 session-\u003etls_wrap.tls_crypt_v2_wkc;"},{"line_number":2686,"context_line":"}"},{"line_number":2687,"context_line":""},{"line_number":2688,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":2,"id":"b82cac22_b1a27396","line":2685,"in_reply_to":"2649fc5a_7c021f6d","updated":"2026-09-15 11:11:55.000000000","message":"Dropped, along with the parameter and the three call sites.\n\nNote that tls_wrap_control(), which prints this message, doesn\u0027t cover the two call sites in write_outgoing_tls_ciphertext(). They read the key with buf_len() before anything is wrapped, and buf_len() is not NULL-safe. The check in parse_early_negotiation_tlvs() is what keeps those safe, so I kept it.","commit_id":"65262c0afd5095fa68f320d23fdacd1b8c8a8e92"}]}
