)]}'
{"id":"openvpn~1920","triplet_id":"openvpn~master~Ie46934c0a8f04908cc277114ae491c100d368cb2","project":"openvpn","branch":"master","full_branch":"refs/heads/master","attention_set":{},"removed_from_attention_set":{"1000008":{"account":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"last_update":"2026-09-19 19:13:26.000000000","reason":"Change was submitted"},"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-19 19:13:26.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Ie46934c0a8f04908cc277114ae491c100d368cb2","subject":"dco_win: report per-peer ioctl failures instead of exiting","status":"MERGED","created":"2026-09-18 07:15:44.000000000","updated":"2026-09-19 19:13:26.000000000","submitted":"2026-09-19 19:13:26.000000000","submitter":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1920","meta_rev_id":"ee29134f3b028d53502fc15dad8e1da27e350a67","_number":1920,"virtual_id_number":1920,"owner":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"reviewers":{"REVIEWER":[{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-18 07:15:45.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-09-18 07:15:45.000000000","updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"real_updated_by":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-09-18 18:04:51.000000000","updated_by":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"real_updated_by":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"state":"REVIEWER"}],"messages":[{"id":"dc259875a05650c148986463ab560fed23cf355f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"date":"2026-09-18 07:15:44.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"95b6ec4dadad8ae9c3b91a6f16d8db5b8cc444b4","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-18 18:04:51.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"ee29134f3b028d53502fc15dad8e1da27e350a67","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-19 19:13:26.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"11a37e7733ab8b98add5fe168ae25497f89b3873","revisions":{"0e031e39e423011f3b2912f2b5bba3833afb3974":{"kind":"REWORK","_number":1,"created":"2026-09-18 07:15:44.000000000","uploader":{"_account_id":1000008,"name":"Lev Stipakov","display_name":"Lev Stipakov","email":"lstipakov@gmail.com","username":"stipa"},"ref":"refs/changes/20/1920/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/20/1920/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1 \u0026\u0026 git checkout -b change-1920 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"bc7f77ea2b6a8e5d964f6cbb403e6bbf1fe77fa4","subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-17 10:59:29.000000000","tz":180},"committer":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 07:12:43.000000000","tz":180},"subject":"dco_win: report per-peer ioctl failures instead of exiting","message":"dco_win: report per-peer ioctl failures instead of exiting\n\nThree per-peer operations end the process when their ioctl fails: MP_NEW_PEER,\nNEW_KEY and SWAP_KEYS all report with M_ERR, which is M_FATAL. On a server that\nmeans one client\u0027s failure disconnects every other client.\n\nThe shared code above them already recovers per instance: a failed MP_NEW_PEER\ndrops that client in multi.c, a failed SWAP_KEYS raises SIGUSR1 for that\ninstance in forward.c, and change 1835 restarts the instance on a failed\nNEW_KEY. None of it runs on Windows, because the process is gone before the\nerror can be returned.\n\nReport and return, which is what DEL_PEER, MP_SET_PEER and the iroute calls in\nthis same file already do. The remaining M_ERR uses here are interface-wide\nsetup, where failing hard is still right.\n\nNEW_KEY failing is not hypothetical: the driver owns the keepalive timer and\nexpires peers itself, so a key install can arrive for a peer it has just\nremoved. Measured on a Windows DCO server under peer churn: 15 refused installs\nacross four runs, no process exit.\n\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\nChange-Id: Ie46934c0a8f04908cc277114ae491c100d368cb2\n"},"branch":"refs/heads/master"},"11a37e7733ab8b98add5fe168ae25497f89b3873":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":2,"created":"2026-09-19 19:13:26.000000000","uploader":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/20/1920/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/20/1920/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2 \u0026\u0026 git checkout -b change-1920 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/20/1920/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"6b5f8ff6763307e659b32a4bf47967abf8cb9311","subject":"dco: do not exit the process when installing a DCO key fails"}],"author":{"name":"Lev Stipakov","email":"lev@openvpn.net","date":"2026-09-18 18:05:01.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-09-19 19:08:37.000000000","tz":120},"subject":"dco_win: report per-peer ioctl failures instead of exiting","message":"dco_win: report per-peer ioctl failures instead of exiting\n\nThree per-peer operations end the process when their ioctl fails:\nMP_NEW_PEER, NEW_KEY and SWAP_KEYS all report with M_ERR, which is\nM_FATAL. On a server that means one client\u0027s failure disconnects\nevery other client.\n\nThe shared code above them already recovers per instance: a failed\nMP_NEW_PEER drops that client in multi.c, a failed SWAP_KEYS raises\nSIGUSR1 for that instance in forward.c, and change 1835 restarts\nthe instance on a failed NEW_KEY. None of it runs on Windows, because\nthe process is gone before the error can be returned.\n\nReport and return, which is what DEL_PEER, MP_SET_PEER and the\niroute calls in this same file already do. The remaining M_ERR uses\nhere are interface-wide setup, where failing hard is still right.\n\nNEW_KEY failing is not hypothetical: the driver owns the keepalive\ntimer and expires peers itself, so a key install can arrive for a\npeer it has just removed. Measured on a Windows DCO server under\npeer churn: 15 refused installs across four runs, no process exit.\n\nSigned-off-by: Lev Stipakov \u003clev@openvpn.net\u003e\nAcked-by: Gert Doering \u003cgert@greenie.muc.de\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1920\nChange-Id: Ie46934c0a8f04908cc277114ae491c100d368cb2\nMessage-Id: \u003c20260918180507.26425-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg39349.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[]}
