)]}'
{"id":"openvpn~1916","triplet_id":"openvpn~master~Iac6d49d064215510bde9a4cd4600ab3a50a45cb4","project":"openvpn","branch":"master","full_branch":"refs/heads/master","attention_set":{},"removed_from_attention_set":{"1000008":{"account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-09-17 17:09:41.000000000","reason":"Change was submitted"},"1000003":{"account":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-16 12:08:42.000000000","reason":"removed on reply"}},"hashtags":[],"change_id":"Iac6d49d064215510bde9a4cd4600ab3a50a45cb4","subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key","status":"MERGED","created":"2026-09-15 07:18:08.000000000","updated":"2026-09-17 17:09:41.000000000","submitted":"2026-09-17 17:09:41.000000000","submitter":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":4,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1916","meta_rev_id":"ee855aa002fe6cc846706b45f638eaf02a196b31","_number":1916,"virtual_id_number":1916,"owner":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-15 07:18:09.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-09-15 07:18:09.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"ba5876719cda30ee71481d3486dbea291b59c0b1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 07:18:08.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"9d3a3fdfd8251060921750fcd87c6e144a95bda7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 07:57:14.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"18bd0902b9ba1f175ac4b2408f2c326e021958e8","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-09-15 09:59:31.000000000","message":"Patch Set 2: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"ed6d35867f7687bff23b53dcdfba7508e5420f2f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 11:11:48.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"8d5b1c192ad679c6dd2db3c6e0ca24ccf84408b7","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-15 11:11:55.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"aea7b37afbcb8832e409c745ebc00ec3a2cfdf78","author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-09-16 12:08:42.000000000","message":"Patch Set 3: Code-Review+2","accounts_in_message":[],"_revision_number":3},{"id":"ee855aa002fe6cc846706b45f638eaf02a196b31","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-17 17:09:41.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"bc7f77ea2b6a8e5d964f6cbb403e6bbf1fe77fa4","revisions":{"747130af870c9262b430a06f55483ef3a9b5427c":{"kind":"REWORK","_number":1,"created":"2026-09-15 07:18:08.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/16/1916/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/16/1916/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1 \u0026\u0026 git checkout -b change-1916 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"aa12dd64b74142bbbff9f37cec05959ba115c06d","subject":"options: fix unsigned underflow when clearing domain_search_list"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 06:44:24.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 07:11:55.000000000","tz":180},"subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key","message":"ssl: do not trust the peer\u0027s request to resend the wrapped client key\n\nparse_early_negotiation_tlvs() sets CO_RESEND_WKC just because the peer\nset EARLY_NEG_FLAG_RESEND_WKC in its reset packet, without checking that\nthis client has a wrapped client key at all. control_packet_needs_wkc()\nthen reports that our first control packet needs the key appended and\nwrite_outgoing_tls_ciphertext() sizes it with\n\n    maxlen -\u003d buf_len(session-\u003etls_wrap.tls_crypt_v2_wkc);\n\ntls_crypt_v2_wkc is only set with --tls-crypt-v2 and buf_len() is not\nNULL-safe, so a client without --tls-crypt-v2 dies with SIGSEGV while\nprocessing the server\u0027s first reset packet, before the peer has been\nauthenticated.\n\nOnly set the flag if we have a key to resend, check the same in\ncontrol_packet_needs_wkc(), and let tls_wrap_control() refuse to append a\nkey it does not have.\n\nGithub: OpenVPN/openvpn-private-issues#181\nChange-Id: Iac6d49d064215510bde9a4cd4600ab3a50a45cb4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"65262c0afd5095fa68f320d23fdacd1b8c8a8e92":{"kind":"REWORK","_number":2,"created":"2026-09-15 07:57:14.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/16/1916/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/16/1916/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2 \u0026\u0026 git checkout -b change-1916 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"aa12dd64b74142bbbff9f37cec05959ba115c06d","subject":"options: fix unsigned underflow when clearing domain_search_list"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 07:55:58.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 07:56:10.000000000","tz":180},"subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key","message":"ssl: do not trust the peer\u0027s request to resend the wrapped client key\n\nparse_early_negotiation_tlvs() sets CO_RESEND_WKC just because the peer\nset EARLY_NEG_FLAG_RESEND_WKC in its reset packet, without checking that\nthis client has a wrapped client key at all. control_packet_needs_wkc()\nthen reports that our first control packet needs the key appended and\nwrite_outgoing_tls_ciphertext() sizes it with\n\n    maxlen -\u003d buf_len(session-\u003etls_wrap.tls_crypt_v2_wkc);\n\ntls_crypt_v2_wkc is only set with --tls-crypt-v2 and buf_len() is not\nNULL-safe, so a client without --tls-crypt-v2 dies with SIGSEGV while\nprocessing the server\u0027s first reset packet, before the peer has been\nauthenticated.\n\nOnly set the flag if we have a key to resend, check the same in\ncontrol_packet_needs_wkc(), and let tls_wrap_control() refuse to append a\nkey it does not have.\n\ntls_reset_standalone() drives tls_wrap_control() directly, so the test\nuses it to build the two control packets that carry a wrapped client key\nwith tls_crypt_v2_wkc unset. Both segfault without the fix.\n\nGithub: OpenVPN/openvpn-private-issues#181\nChange-Id: Iac6d49d064215510bde9a4cd4600ab3a50a45cb4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"d6ce7238774423b5d4970d502c554cff1d2235b8":{"kind":"REWORK","_number":3,"created":"2026-09-15 11:11:48.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/16/1916/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/16/1916/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3 \u0026\u0026 git checkout -b change-1916 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"aa12dd64b74142bbbff9f37cec05959ba115c06d","subject":"options: fix unsigned underflow when clearing domain_search_list"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 07:55:58.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-15 10:37:10.000000000","tz":180},"subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key","message":"ssl: do not trust the peer\u0027s request to resend the wrapped client key\n\nparse_early_negotiation_tlvs() sets CO_RESEND_WKC just because the peer\nset EARLY_NEG_FLAG_RESEND_WKC in its reset packet, without checking that\nthis client has a wrapped client key at all. control_packet_needs_wkc()\nthen reports that our first control packet needs the key appended and\nwrite_outgoing_tls_ciphertext() sizes it with\n\n    maxlen -\u003d buf_len(session-\u003etls_wrap.tls_crypt_v2_wkc);\n\ntls_crypt_v2_wkc is only set with --tls-crypt-v2 and buf_len() is not\nNULL-safe, so a client without --tls-crypt-v2 dies with SIGSEGV while\nprocessing the server\u0027s first reset packet, before the peer has been\nauthenticated.\n\nOnly set the flag if we have a key to resend, and let tls_wrap_control()\nrefuse to append a key it does not have.\n\ntls_reset_standalone() drives tls_wrap_control() directly, so the test\nuses it to build the two control packets that carry a wrapped client key\nwith tls_crypt_v2_wkc unset. Both segfault without the fix.\n\nGithub: OpenVPN/openvpn-private-issues#181\nChange-Id: Iac6d49d064215510bde9a4cd4600ab3a50a45cb4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\n"},"branch":"refs/heads/master"},"bc7f77ea2b6a8e5d964f6cbb403e6bbf1fe77fa4":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":4,"created":"2026-09-17 17:09:41.000000000","uploader":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/16/1916/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/16/1916/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4 \u0026\u0026 git checkout -b change-1916 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/16/1916/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"17f6cec06fbced967cb64338c83e902e949ece95","subject":"Improve auth token related comments"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-16 20:32:06.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-09-17 10:58:58.000000000","tz":120},"subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key","message":"ssl: do not trust the peer\u0027s request to resend the wrapped client key\n\nparse_early_negotiation_tlvs() sets CO_RESEND_WKC just because the peer\nset EARLY_NEG_FLAG_RESEND_WKC in its reset packet, without checking that\nthis client has a wrapped client key at all. control_packet_needs_wkc()\nthen reports that our first control packet needs the key appended and\nwrite_outgoing_tls_ciphertext() sizes it with\n\n    maxlen -\u003d buf_len(session-\u003etls_wrap.tls_crypt_v2_wkc);\n\ntls_crypt_v2_wkc is only set with --tls-crypt-v2 and buf_len() is not\nNULL-safe, so a client without --tls-crypt-v2 dies with SIGSEGV while\nprocessing the server\u0027s first reset packet, before the peer has been\nauthenticated.\n\nOnly set the flag if we have a key to resend, and let tls_wrap_control()\nrefuse to append a key it does not have.\n\ntls_reset_standalone() drives tls_wrap_control() directly, so the test\nuses it to build the two control packets that carry a wrapped client key\nwith tls_crypt_v2_wkc unset. Both segfault without the fix.\n\nGithub: OpenVPN/openvpn-private-issues#181\nChange-Id: Iac6d49d064215510bde9a4cd4600ab3a50a45cb4\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\nAcked-by: Arne Schwabe \u003carne-openvpn@rfc2549.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1916\nMessage-Id: \u003c20260916203212.21285-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg39268.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[]}
