)]}'
{"id":"openvpn~30","triplet_id":"openvpn~master~I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9","project":"openvpn","branch":"master","topic":"bloom","attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2024-09-21 14:26:47.000000000","reason":"\u003cGERRIT_ACCOUNT_1000030\u003e replied on the change","reason_account":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"}},"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2024-09-21 14:16:18.000000000","reason":"Reviewer was added"},"1000030":{"account":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"last_update":"2026-08-28 13:50:11.000000000","reason":"Vote got outdated and was removed: Code-Review-1"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9","subject":"Implement initial packet reflection protection using bloom filter","status":"NEW","created":"2023-02-23 18:07:42.000000000","updated":"2026-08-30 16:28:03.000000000","submit_type":"CHERRY_PICK","submittable":false,"total_comment_count":16,"unresolved_comment_count":15,"has_review_started":true,"meta_rev_id":"1e5d27a9962825bde72d15da684360136bffe74d","_number":30,"virtual_id_number":30,"owner":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2024-09-21 14:16:18.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2024-09-21 14:16:18.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"},{"updated":"2024-09-21 14:26:47.000000000","updated_by":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"reviewer":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"state":"REVIEWER"},{"updated":"2026-08-30 16:28:03.000000000","updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"CC"}],"messages":[{"id":"3cb97488292e816032b38cb1e4bcf26dc7beb473","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-23 18:07:42.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"b549e0a5c26457ac76fedbad18e171f0b0b03390","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-26 03:12:26.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"088bb56ccc147aa28b3d5db88f22330865e43637","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-27 01:07:37.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"c1f2e5f59171bf414de0b26af769b491b60838c1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-27 01:29:38.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"4c604dbfa660ed81da42914210e792f2dfca3894","tag":"autogenerated:gerrit:setWorkInProgress","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-27 01:34:13.000000000","message":"Set Work In Progress","accounts_in_message":[],"_revision_number":4},{"id":"9facbd975710b0cd07c9ff5229bef88035bef993","tag":"autogenerated:gerrit:setReadyForReview","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-27 01:34:35.000000000","message":"Set Ready For Review","accounts_in_message":[],"_revision_number":4},{"id":"523ccaf197e7850d6d3ea9ea73c1fd179d5809f0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-02-27 12:43:08.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"82f7b5f9734dca7af29015a1f565990d28e98eff","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-03-01 14:02:53.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"40f325df35158513654077b1621da170b5bf5571","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-03-02 12:01:23.000000000","message":"Topic set to bloom","accounts_in_message":[],"_revision_number":6},{"id":"5e59285b9e7c382ed1ba6bc5709527b6a7bb55ab","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-03-06 12:59:20.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"4bc384c4d35465b20309102762ff8c471020cc83","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2023-03-06 13:04:57.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"70bf9f589619683d8925a88acfb0434301ea9ce6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2024-09-21 14:16:16.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"a2ec20f5c9eef16ab062006f5ad13d2aac5a916d","author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"date":"2024-09-21 14:26:47.000000000","message":"Patch Set 9: Code-Review-1\n\n(10 comments)","accounts_in_message":[],"_revision_number":9},{"id":"83f2c0b8398e16eda9c97163c08e17a46eb2ebd1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-28 13:50:11.000000000","message":"Uploaded patch set 10.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":10},{"id":"1e5d27a9962825bde72d15da684360136bffe74d","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-08-30 16:28:03.000000000","message":"Patch Set 10:\n\n(6 comments)","accounts_in_message":[],"_revision_number":10}],"current_revision_number":10,"current_revision":"8f25090ead49b0c71eb783623d1309738e9a7b12","revisions":{"a4c591c3e2f347d5487cf2db428fd3c29264a4ff":{"kind":"REWORK","_number":1,"created":"2023-02-23 18:07:42.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/1 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"625ed77b96e13b822e17a43521d46552185afcf8","subject":"Add siphash reference impelmentation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-02-23 18:07:32.000000000","tz":60},"subject":"WIP Bloom filter","message":"WIP Bloom filter\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"af32ad616310c315b13708cf0b90f05ae0251818":{"kind":"REWORK","_number":2,"created":"2023-02-26 03:12:26.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/2 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"958368e970e2e5822b2d9bbf4ab35d9c01310b03","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-02-26 03:10:25.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"c3dc7d359342cc7e9f55fcf19e015ab319a83e89":{"kind":"REWORK","_number":3,"created":"2023-02-27 01:07:37.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/3 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"958368e970e2e5822b2d9bbf4ab35d9c01310b03","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-02-27 01:03:53.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"86d3e2d4007c733375a3cc2f20c43e79f8248070":{"kind":"REWORK","_number":4,"created":"2023-02-27 01:29:38.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/4 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"958368e970e2e5822b2d9bbf4ab35d9c01310b03","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-02-27 01:28:53.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"f4abb1fd176048982fbddea8f0987819477b342c":{"kind":"REWORK","_number":5,"created":"2023-02-27 12:43:08.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/5 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4521da516369a189059e7447c7e531be56a29dce","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-02-27 12:41:39.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"93f1ddc0ce8e0abbb5e7b7f628811578ac2735a4":{"kind":"REWORK","_number":6,"created":"2023-03-01 14:02:53.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/6 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"689088a56a10aeb4f2ceced5c752a8d958a2da0e","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-03-01 14:02:33.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"3f1dcada5633462e3dcba0460b1cfe80631618b1":{"kind":"REWORK","_number":7,"created":"2023-03-06 12:59:20.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/7 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4afcc352cc49202c03d4d4cbe9a3ed1af69f97f6","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-03-06 12:58:27.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"9ad1a4d4b8c54017f2a5fdb12c5697a85bde5d5b":{"kind":"REWORK","_number":8,"created":"2023-03-06 13:04:57.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/8","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/8","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/8 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/8","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/8 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4afcc352cc49202c03d4d4cbe9a3ed1af69f97f6","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2022-12-05 13:31:11.000000000","tz":60},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-03-06 13:04:02.000000000","tz":60},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\n"},"branch":"refs/heads/master"},"d43f1cc810efceedecd674b1351a189098d2355a":{"kind":"REWORK","_number":9,"created":"2024-09-21 14:16:16.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/9","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/9","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/9 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/9","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/9 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9a0182bba221d885c91fc510ec8678c061c608a0","subject":"Add siphash reference implementation"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-06-29 10:19:50.000000000","tz":180},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2024-09-21 14:15:59.000000000","tz":120},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"8f25090ead49b0c71eb783623d1309738e9a7b12":{"kind":"REWORK","_number":10,"created":"2026-08-28 13:50:11.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/30/30/10","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/30/30/10","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/10 \u0026\u0026 git checkout -b change-30 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/30/30/10","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/30/30/10 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"9849c75f6f4904505c27e85ccf04b1e159dad8d8","subject":"Add lookup of multi session by session id"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2023-06-29 10:19:50.000000000","tz":180},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-28 13:48:19.000000000","tz":120},"subject":"Implement initial packet reflection protection using bloom filter","message":"Implement initial packet reflection protection using bloom filter\n\nWhen an OpenVPN server is used/tried to be usedc in a reflection attack\nthe protection with the simple --connect-freq-initial also block legimitate\nclient from other networks that are not attacked by a reflection attack.\n\nTo allow a server to still reply to these clients, we need to make the counts\nrather more detailed and count per subnet or IP address. On the other hand\nwhen we keep all this state, we eliminate the advantage of having a stateless\ncookie based initial packet handshake.\n\nAs compromoise we use a bloom filter to store the information. This data\nstructure is probabilistic and can have false positive and more packets\nbeing dropped but since it is a constant size and the size of this map\nis small enough for non-embedded systems (tests were done with a 2MB\nbloom filter), it is a good compromise.\n\nThe code is split into the bloom filter implementation and the actual logic\nimplementing tracking the subnets, so the bloom filter should be relatively\neasily be exchangable by another data structure.\n\nAs hash funtion SIPHASH has been chosen since it was designed for this kind\nof application.\n\nChange-Id: I0a9274cab7fefce3b13c05052fb9a072e0bfa6b9\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"}},"requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"NOT_READY","labels":[{"label":"Code-Review","status":"NEED"}]},{"rule_name":"checks~ChecksSubmitRule","status":"NOT_READY","requirements":[{"status":"NOT_READY","fallback_text":"All required checks must pass","type":"checks_pass"}]}],"submit_requirements":[{"name":"Code-Review","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","-label:Code-Review\u003dMIN"]}},{"name":"checks~ChecksSubmitRule","status":"UNSATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"rule:checks~ChecksSubmitRule","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["checks~ChecksSubmitRule"]}}]}
