)]}'
{"id":"openvpn~1950","triplet_id":"openvpn~master~I440c4c73865fdbd80f2c607e83c50e345a0e2438","project":"openvpn","branch":"master","full_branch":"refs/heads/master","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-25 10:29:46.000000000","reason":"\u003cGERRIT_ACCOUNT_1000003\u003e replied on the change","reason_account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}}},"hashtags":[],"change_id":"I440c4c73865fdbd80f2c607e83c50e345a0e2438","subject":"Drop the OpenSSL errors a failed cipher/digest lookup leaves behind","status":"NEW","created":"2026-09-25 09:51:31.000000000","updated":"2026-09-25 10:29:46.000000000","submit_type":"CHERRY_PICK","total_comment_count":2,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"97dc6aa506a9d1a1a09eda4745dc7f7615efca7f","_number":1950,"virtual_id_number":1950,"owner":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"default_value":0}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-25 09:51:31.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"real_updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-09-25 10:17:21.000000000","updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"real_updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"CC"}],"messages":[{"id":"16e95ecefa9600ad6c8ff82f9cdbf2ae512f0075","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-09-25 09:51:31.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e537e5559f0f4b4bc0c36e2ec632c5e176e318b2","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-09-25 10:17:21.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"97dc6aa506a9d1a1a09eda4745dc7f7615efca7f","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-09-25 10:29:46.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"cf481197cd8c5e5270f11dbaa63c87265e2b13c8","revisions":{"cf481197cd8c5e5270f11dbaa63c87265e2b13c8":{"kind":"REWORK","_number":1,"created":"2026-09-25 09:51:31.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/50/1950/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/50/1950/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1 \u0026\u0026 git checkout -b change-1950 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/50/1950/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0cc99b10b4464bdeaa8c254f8388aeb241e8e8b6","subject":"GHA: Maintenance update September 2026"}],"author":{"name":"Drew Blokzyl","email":"drew@linuxkids.com","date":"2026-09-22 13:49:46.000000000","tz":0},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-09-25 09:51:19.000000000","tz":120},"subject":"Drop the OpenSSL errors a failed cipher/digest lookup leaves behind","message":"Drop the OpenSSL errors a failed cipher/digest lookup leaves behind\n\ncipher_get() looks a cipher up with EVP_CIPHER_fetch() and hands the\nresult, possibly NULL, to callers that only care whether it exists:\ncipher_valid_reason(), cipher_kt_mode_cbc/ofb_cfb/aead(),\ncipher_kt_block_size(), cipher_kt_insecure(). A failed fetch is a normal\noutcome for them, but under OpenSSL 3 it also pushes an\nEVP_R_UNSUPPORTED error (\"digital envelope routines::unsupported,\nAlgorithm (none : 0)\") onto the thread\u0027s error queue, and nobody pops it.\n\nThe common way to get there is not exotic. A server that does not set\n--cipher gets the legacy default BF-CBC, which is not in --data-ciphers,\nso do_init_crypto_tls() initialises the pre-negotiation key_type with\ncipher \"none\". Every new client instance then runs init_instance() -\u003e\ndo_init_crypto_tls() -\u003e cipher_kt_mode_ofb_cfb(\"none\"), and the frame\nand OCC calculations (calculate_crypto_overhead(), frame_calculate_*())\nwalk the same key_type, each fetching \"none\" and failing.\ncipher_kt_block_size() adds a second case for AEAD ciphers whose CBC\nsibling does not exist (CHACHA20-POLY1305 -\u003e \"CHACHA20-CBC\").\nmd_valid() has the same shape for digests.\n\nThe stale entry then misleads code that classifies an unrelated failure\nwith ERR_peek_error(), which returns the OLDEST queued entry. The visible\nsymptom is backend_tls_ctx_reload_crl() logging \"CRL: cannot read CRL\nfrom file\" on the first handshake after the CRL file changes although\nthe CRL loaded fine (GitHub #1103). Traced with gdb on OpenVPN 2.7.0 and\nmaster with OpenSSL 3.5.5: the single entry on the queue at reload entry\nis the cipher_kt_mode_ofb_cfb(\"none\") fetch from do_init_crypto_tls()\nof that same client instance.\n\nBracket the probing fetches with ERR_set_mark()/ERR_pop_to_mark() so a\nfailed lookup leaves the queue as it found it; the return value already\ncarries the answer these callers want. wolfSSL\u0027s compatibility layer has\nno error marks, so openssl_compat.h maps them to ERR_clear_error() there.\n\nWith this change the error queue is empty at multi_create_instance() and\nat backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305\nclients, and the spurious warning is gone: three CRL replacements, three\nhandshakes, zero warnings (unpatched: three of three).\n\nChange-Id: I440c4c73865fdbd80f2c607e83c50e345a0e2438\nSigned-off-by: Drew Blokzyl \u003cdrew@linuxkids.com\u003e\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"OK"}]}
