)]}'
{"id":"openvpn~1949","triplet_id":"openvpn~master~I2e8f1449fe54e7f628e2bdb042ee2a567f25e02d","project":"openvpn","branch":"master","full_branch":"refs/heads/master","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-25 03:25:20.000000000","reason":"Reviewer was added"},"1000001":{"account":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-09-28 07:37:25.000000000","reason":"Someone else replied on a comment you posted"}},"removed_from_attention_set":{"1000054":{"account":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"last_update":"2026-09-28 07:37:25.000000000","reason":"removed on reply"}},"hashtags":[],"change_id":"I2e8f1449fe54e7f628e2bdb042ee2a567f25e02d","subject":"tests: add an end-to-end test for --route gateway keywords","status":"NEW","created":"2026-09-25 03:25:19.000000000","updated":"2026-09-29 01:58:09.000000000","submit_type":"CHERRY_PICK","total_comment_count":12,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"7c9d62d1686e6d2ca68963501a40d0c2f5ee80ca","_number":1949,"virtual_id_number":1949,"owner":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-25 03:25:20.000000000","updated_by":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"real_updated_by":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-09-25 03:25:20.000000000","updated_by":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"real_updated_by":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-09-25 11:48:01.000000000","updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"real_updated_by":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"}],"messages":[{"id":"7fb1800c4cf9b88a436d963a0cca03bc52b49a8e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-25 03:25:19.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"fb8e8e15b8eab6c5033890055146a5a1598c197b","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-25 03:25:33.000000000","message":"Patch Set 1:\n\nThis is the harness I mentioned on IRC. Pushing it so the discussion has\nsomething concrete to look at rather than a description.\n\nTwo things worth deciding.\n\nFirst, this would be the first use of network namespaces in the tree. From\nwhat I was told most of the CI runners can do this and already do for DCO\nwork, but containers cannot, so it will skip there. If that is not\nacceptable I can drop the namespace and create the dummy interface on the\nhost the way t_net.sh does, at the cost of touching the host routing table\nwhile the test runs.\n\nSecond, it covers net_gateway for IPv4 only. The IPv6 side is the same code\npath and I would add it once I9e45c0e lands, which is what prompted writing\nthis in the first place.\n\nUnlike t_net.sh there is no HAVE_SITNL gate, because this needs no\nspecially built binary and skips at runtime instead. Happy to add one if\nconsistency is preferred.","accounts_in_message":[],"_revision_number":1},{"id":"8936254b5cb272200db00d929a5aa6761194b33b","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-09-25 11:48:01.000000000","message":"Patch Set 1: Code-Review-1\n\n(6 comments)","accounts_in_message":[],"_revision_number":1},{"id":"cc75682e81813b1747e3fd75fc5e1cd9281db4f2","author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-09-25 11:53:19.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"75dee0b6bd10bbc0f90bc494d59109e197163f94","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-28 07:26:09.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"9884a3993da26528d67b1ba1c39dd632e6d1d0c2","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-28 07:37:25.000000000","message":"Patch Set 2:\n\n(5 comments)\n\nThanks, all five are addressed in PS2.\n\nOn the *BSD question, I split the script. t_route_common.sh holds the parts that do not care how the environment is isolated: starting the openvpn pair, waiting for the route, and comparing the gateway. t_route.sh supplies three hooks, one to run a command inside the namespace and two to query the routing table. The assertion needed the real change. It used to match \"via $GW\" against ip route output, and it now compares against a gateway the platform hook extracts, since netstat -rn spells the entry differently.\n\nSo a BSD front end would define the three hooks and reuse the rest. I have not written one and have no way to test one, so I would rather not guess at it in this change.\n\nOne heads up: 1946 adds a case to test_networking.c and bumps LAST_TEST in t_net.sh, which is the same area 1586 touches. Whichever lands first will leave the other needing a rebase.","accounts_in_message":[],"_revision_number":2},{"id":"1424533e0966d115e3e293260868dc806a49a241","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-29 01:57:48.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"7c9d62d1686e6d2ca68963501a40d0c2f5ee80ca","author":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"date":"2026-09-29 01:58:09.000000000","message":"Patch Set 3:\n\nPS3 changes how the test decides it cannot run. The tunnel is now waited for separately from the route and /dev/net/tun is checked up front, so an environment that cannot open a tunnel skips. A tunnel that comes up without the route, or with the wrong gateway, is still a failure. Both paths now print the client and server logs along with the addresses and routes.\n\nThat is a guess at the cause though. PS2 failed arch-factory-default and debian-13-factory-default and I have not managed to reproduce either. It passes here as a normal user and as root, and in the full tests/ suite alongside t_cltsrv.sh. Every other builder is green, including debian-unstable, so it does not look like a toolchain issue.\n\nI also do not know how to read the buildbot logs. The links in the checks point at buildbot.community.aws.openvpn.in, which I cannot reach, so I have no way to see what actually failed. If someone can paste the relevant part of either log, or tell me how to get at them, I can fix the real cause instead of guessing.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"1d4de58aa6dd1e086e4bf715e30fbfc9feb5c723","revisions":{"57e9b919136ba4e1dac9ff6ca0de201f644c057b":{"kind":"REWORK","_number":1,"created":"2026-09-25 03:25:19.000000000","uploader":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"ref":"refs/changes/49/1949/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/1949/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1 \u0026\u0026 git checkout -b change-1949 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0cc99b10b4464bdeaa8c254f8388aeb241e8e8b6","subject":"GHA: Maintenance update September 2026"}],"author":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-25 02:59:31.000000000","tz":0},"committer":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-25 03:24:59.000000000","tz":0},"subject":"tests: add an end-to-end test for --route gateway keywords","message":"tests: add an end-to-end test for --route gateway keywords\n\nNothing self-contained checks that a route openvpn says it installed\nactually reached the kernel with the gateway it reported. t_client.sh does\ncompare routes, but it needs a t_client.rc and reachable servers, so it\nskips for contributors and in CI.\n\nRun a TLS loopback pair inside a throwaway network namespace, ask the\nclient for a route via net_gateway, and check where it lands. route.c\ntracks two gateways, the system default route and the route towards the\npeer, and net_gateway is the former. The peer here is on loopback, so the\ntwo differ and the assertion can tell them apart: resolving from the wrong\none leaves the route with no gateway and the install fails outright.\n\nThe namespace also means the fixed loopback ports cannot collide, so this\nneeds none of the retry-on-address-in-use handling t_cltsrv.sh has.\n\nSkips rather than fails when it cannot run: not Linux, no iproute2, or no\nway to get the privileges a namespace needs. Containers commonly disallow\nnamespace creation, so this will skip there and run on VMs and bare metal.\nRUN_SUDO is picked up from t_client.rc the same way t_net.sh does.\n\nChange-Id: I2e8f1449fe54e7f628e2bdb042ee2a567f25e02d\nSigned-off-by: Charlie Vigue \u003ccharlie.vigue@openvpn.com\u003e\n"},"branch":"refs/heads/master"},"5b7dd8356d402cce1f8a8b5005c43596a7ee4d12":{"kind":"REWORK","_number":2,"created":"2026-09-28 07:26:09.000000000","uploader":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"ref":"refs/changes/49/1949/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/1949/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2 \u0026\u0026 git checkout -b change-1949 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0cc99b10b4464bdeaa8c254f8388aeb241e8e8b6","subject":"GHA: Maintenance update September 2026"}],"author":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-25 02:59:31.000000000","tz":0},"committer":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-28 07:22:52.000000000","tz":0},"subject":"tests: add an end-to-end test for --route gateway keywords","message":"tests: add an end-to-end test for --route gateway keywords\n\nNothing self-contained checks that a route openvpn says it installed\nactually reached the kernel with the gateway it reported. t_client.sh does\ncompare routes, but it needs a t_client.rc and reachable servers, so it\nskips for contributors and in CI.\n\nRun a TLS loopback pair inside a throwaway network namespace, ask the\nclient for a route via net_gateway, and check where it lands. route.c\ntracks two gateways, the system default route and the route towards the\npeer, and net_gateway is the former. The peer here is on loopback, so the\ntwo differ and the assertion can tell them apart: resolving from the wrong\none leaves the route with no gateway and the install fails outright.\n\nThe namespace also means the fixed loopback ports cannot collide, so this\nneeds none of the retry-on-address-in-use handling t_cltsrv.sh has.\n\nThe part that does not depend on how the environment is isolated lives in\nt_route_common.sh: starting the openvpn pair, waiting for the route to\nappear, and comparing the gateway.  t_route.sh supplies the three hooks\nthat do depend on the platform, running a command inside the namespace and\nthe two routing table queries.  The comparison is against the gateway the\nplatform reports rather than the text of the routing table entry, because\nevery routing tool spells that entry differently.  A front end for a\nsystem without network namespaces can then reuse the whole driver.\n\nBoth files are POSIX sh.  Nothing here needed bash, and with a /bin/sh\nshebang the runtime skips below can do their job on a platform without\nbash rather than the script failing to start.\n\nSkips rather than fails when it cannot run: not Linux, no iproute2, or no\nway to get the privileges a namespace needs. Containers commonly disallow\nnamespace creation, so this will skip there and run on VMs and bare metal.\nRUN_SUDO is picked up from t_client.rc the same way t_net.sh does.\n\nChange-Id: I2e8f1449fe54e7f628e2bdb042ee2a567f25e02d\nSigned-off-by: Charlie Vigue \u003ccharlie.vigue@openvpn.com\u003e\n"},"branch":"refs/heads/master"},"1d4de58aa6dd1e086e4bf715e30fbfc9feb5c723":{"kind":"REWORK","_number":3,"created":"2026-09-29 01:57:48.000000000","uploader":{"_account_id":1000054,"name":"chugly","email":"charlie.vigue@openvpn.com","username":"chugly"},"ref":"refs/changes/49/1949/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/49/1949/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3 \u0026\u0026 git checkout -b change-1949 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/49/1949/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0cc99b10b4464bdeaa8c254f8388aeb241e8e8b6","subject":"GHA: Maintenance update September 2026"}],"author":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-25 02:59:31.000000000","tz":0},"committer":{"name":"Charlie Vigue","email":"charlie.vigue@openvpn.com","date":"2026-09-29 01:57:02.000000000","tz":0},"subject":"tests: add an end-to-end test for --route gateway keywords","message":"tests: add an end-to-end test for --route gateway keywords\n\nNothing self-contained checks that a route openvpn says it installed\nactually reached the kernel with the gateway it reported. t_client.sh does\ncompare routes, but it needs a t_client.rc and reachable servers, so it\nskips for contributors and in CI.\n\nRun a TLS loopback pair inside a throwaway network namespace, ask the\nclient for a route via net_gateway, and check where it lands. route.c\ntracks two gateways, the system default route and the route towards the\npeer, and net_gateway is the former. The peer here is on loopback, so the\ntwo differ and the assertion can tell them apart: resolving from the wrong\none leaves the route with no gateway and the install fails outright.\n\nThe namespace also means the fixed loopback ports cannot collide, so this\nneeds none of the retry-on-address-in-use handling t_cltsrv.sh has.\n\nThe part that does not depend on how the environment is isolated lives in\nt_route_common.sh: starting the openvpn pair, waiting for the tunnel and\nthen the route, and comparing the gateway.  t_route.sh supplies the hooks\nthat do depend on the platform, running a command inside the namespace and\nthe routing table queries.  The comparison is against the gateway the\nplatform reports rather than the text of the routing table entry, because\nevery routing tool spells that entry differently.  A front end for a\nsystem without network namespaces can then reuse the whole driver.\n\nNothing can be concluded about a route until the tunnel carrying it\nexists, so the tun device is waited for separately and /dev/net/tun is\nchecked up front.  An environment that cannot open a tunnel skips; only a\ntunnel that comes up without the route, or with the wrong gateway, is a\nfailure.  Both paths print the client and server logs together with the\naddresses and routes, so a failing run says why.\n\nBoth files are POSIX sh.  Nothing here needed bash, and with a /bin/sh\nshebang the runtime skips below can do their job on a platform without\nbash rather than the script failing to start.\n\nSkips rather than fails when it cannot run: not Linux, no iproute2, no\ntun device, or no way to get the privileges a namespace needs. Containers\ncommonly disallow namespace creation, so this will skip there and run on\nVMs and bare metal. RUN_SUDO is picked up from t_client.rc the same way\nt_net.sh does.\n\nChange-Id: I2e8f1449fe54e7f628e2bdb042ee2a567f25e02d\nSigned-off-by: Charlie Vigue \u003ccharlie.vigue@openvpn.com\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"OK"}]}
