)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":17,"context_line":"wait for retries. So this is more a one-shot notify but that is"},{"line_number":18,"context_line":"acceptable in this situation."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"ce9fb57d_f01b1b19","line":20,"updated":"2023-11-20 11:55:56.000000000","message":"superfluous space","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":17,"context_line":"wait for retries. So this is more a one-shot notify but that is"},{"line_number":18,"context_line":"acceptable in this situation."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"e66f6133_04b1cc5d","line":20,"in_reply_to":"ce9fb57d_f01b1b19","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"},{"line_number":24,"context_line":"information by alerts and since the user experience is much better with"},{"line_number":25,"context_line":"alerts, this compromise is worth it."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"8bf6026e_889913be","line":22,"updated":"2023-11-20 11:55:56.000000000","message":"\"consumer TLS implementations\"","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"},{"line_number":24,"context_line":"information by alerts and since the user experience is much better with"},{"line_number":25,"context_line":"alerts, this compromise is worth it."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"d04c679a_cc1ae3ed","line":22,"in_reply_to":"8bf6026e_889913be","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"},{"line_number":24,"context_line":"information by alerts and since the user experience is much better with"},{"line_number":25,"context_line":"alerts, this compromise is worth it."},{"line_number":26,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"a80886c0_b6d5627c","line":23,"updated":"2023-11-20 11:55:56.000000000","message":"\"implementations\"","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":20,"context_line":"Sending out alerts  is a slight compromise in security as alerts give"},{"line_number":21,"context_line":"out a bit of information that otherwise is not given"},{"line_number":22,"context_line":"out. But since all other consumers TLS implementation are already doing this"},{"line_number":23,"context_line":"and TLS implementation (nowadays) are very careful not to leak (sensitive)"},{"line_number":24,"context_line":"information by alerts and since the user experience is much better with"},{"line_number":25,"context_line":"alerts, this compromise is worth it."},{"line_number":26,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"8660b029_d3b05646","line":23,"in_reply_to":"a80886c0_b6d5627c","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"41c1639d_efd1a36a","updated":"2023-11-20 11:55:56.000000000","message":"Can\u0027t judge the state machine patch really. But the doubts about the shutdown function makes this a NAK either way.","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"e9fd2c0bc161a809cd40b1a0fa3662b4cabdc169","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"1c291abc_9459f39b","updated":"2023-11-20 13:08:11.000000000","message":"My concerns have been addressed, but state machine needs further review.","commit_id":"ed72e2c8fc699aa0833ac5394a1b322de794afc3"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"36be05aaa82845f93b7fe4a4ea64b23160cd5d43","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"1b175df4_8e1e1d31","updated":"2023-11-28 13:35:35.000000000","message":"Note: currently not reviewing due to the open build failure","commit_id":"5bccaaca12c6d1786b5e1a73e58eb7820c1d7814"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"1b288677817dd4b2204e977f61ffc13373b7e9f2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"6d746ea1_b941a588","updated":"2024-03-18 16:30:01.000000000","message":"Looks good to me, but did not test it.","commit_id":"e2a9651d8beb73f99905d422176b5fc66458803f"}],"Changes.rst":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":3,"context_line":"New features"},{"line_number":4,"context_line":"------------"},{"line_number":5,"context_line":"TLS alerts"},{"line_number":6,"context_line":"    OpenVPN 2.7 will send out TLS alerts to peer informing them if the TLS"},{"line_number":7,"context_line":"    session shuts down or when the TLS implementation informs the peer about"},{"line_number":8,"context_line":"    an error in the TLS session (e.g. mismatching TLS versions). This improves"},{"line_number":9,"context_line":"    the user experience as the client shows an error instead of running into"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9c3faa2e_d4fd7ba3","line":6,"updated":"2023-11-20 11:55:56.000000000","message":"\"peers\"","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":3,"context_line":"New features"},{"line_number":4,"context_line":"------------"},{"line_number":5,"context_line":"TLS alerts"},{"line_number":6,"context_line":"    OpenVPN 2.7 will send out TLS alerts to peer informing them if the TLS"},{"line_number":7,"context_line":"    session shuts down or when the TLS implementation informs the peer about"},{"line_number":8,"context_line":"    an error in the TLS session (e.g. mismatching TLS versions). This improves"},{"line_number":9,"context_line":"    the user experience as the client shows an error instead of running into"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f072ad8_eab0e86f","line":6,"in_reply_to":"9c3faa2e_d4fd7ba3","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":7,"context_line":"    session shuts down or when the TLS implementation informs the peer about"},{"line_number":8,"context_line":"    an error in the TLS session (e.g. mismatching TLS versions). This improves"},{"line_number":9,"context_line":"    the user experience as the client shows an error instead of running into"},{"line_number":10,"context_line":"    a timeout when the server just stop responding completely."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Deprecated features"},{"line_number":13,"context_line":"-------------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"fd295cc6_2def6a9b","line":10,"updated":"2023-11-20 11:55:56.000000000","message":"\"stops\"","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":7,"context_line":"    session shuts down or when the TLS implementation informs the peer about"},{"line_number":8,"context_line":"    an error in the TLS session (e.g. mismatching TLS versions). This improves"},{"line_number":9,"context_line":"    the user experience as the client shows an error instead of running into"},{"line_number":10,"context_line":"    a timeout when the server just stop responding completely."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"Deprecated features"},{"line_number":13,"context_line":"-------------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"568b8456_4669a9a3","line":10,"in_reply_to":"fd295cc6_2def6a9b","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"}],"src/openvpn/ssl.c":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":2843,"context_line":"}"},{"line_number":2844,"context_line":""},{"line_number":2845,"context_line":"/**"},{"line_number":2846,"context_line":" * Shut down an SSL session, so an SSL close notify is sent if there no other"},{"line_number":2847,"context_line":" * SSL notify."},{"line_number":2848,"context_line":" * @param ks"},{"line_number":2849,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"38284760_a524bebe","line":2846,"updated":"2023-11-20 11:55:56.000000000","message":"\"there is\"","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":2843,"context_line":"}"},{"line_number":2844,"context_line":""},{"line_number":2845,"context_line":"/**"},{"line_number":2846,"context_line":" * Shut down an SSL session, so an SSL close notify is sent if there no other"},{"line_number":2847,"context_line":" * SSL notify."},{"line_number":2848,"context_line":" * @param ks"},{"line_number":2849,"context_line":" */"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"a39b7fdf_e1dbd71f","line":2846,"in_reply_to":"38284760_a524bebe","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":2848,"context_line":" * @param ks"},{"line_number":2849,"context_line":" */"},{"line_number":2850,"context_line":"void"},{"line_number":2851,"context_line":"do_ssl_shutdown(struct key_state *ks)"},{"line_number":2852,"context_line":"{"},{"line_number":2853,"context_line":"}"},{"line_number":2854,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":1,"id":"8e4b3e48_338f6a18","line":2851,"updated":"2023-11-20 11:55:56.000000000","message":"Why do we need an empty function? Was this supposed to call key_state_ssl_shutdown?","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":2848,"context_line":" * @param ks"},{"line_number":2849,"context_line":" */"},{"line_number":2850,"context_line":"void"},{"line_number":2851,"context_line":"do_ssl_shutdown(struct key_state *ks)"},{"line_number":2852,"context_line":"{"},{"line_number":2853,"context_line":"}"},{"line_number":2854,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":1,"id":"8e57006f_630e475d","line":2851,"in_reply_to":"8e4b3e48_338f6a18","updated":"2023-11-20 13:02:18.000000000","message":"Yes. That is accidentally leftover code from an earlier version. I decided on the key_state_ssl_shutdown name as that aligns more with similar functions in existing code","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"1b288677817dd4b2204e977f61ffc13373b7e9f2","unresolved":true,"context_lines":[{"line_number":3233,"context_line":"            * from S_ACTIVE to S_GENERATED_KEYS */"},{"line_number":3234,"context_line":"            if (!tls_session_generate_data_channel_keys(multi, session))"},{"line_number":3235,"context_line":"            {"},{"line_number":3236,"context_line":"                msg(D_TLS_ERRORS, \"TLS Error: generate_key_expansion failed\");"},{"line_number":3237,"context_line":"                ks-\u003eauthenticated \u003d KS_AUTH_FALSE;"},{"line_number":3238,"context_line":"                key_state_ssl_shutdown(\u0026ks-\u003eks_ssl);"},{"line_number":3239,"context_line":"                ks-\u003estate \u003d S_ERROR_PRE;"}],"source_content_type":"text/x-csrc","patch_set":6,"id":"46b395cc_6e433008","line":3236,"updated":"2024-03-18 16:30:01.000000000","message":"While here, can we fix the error message, please?","commit_id":"e2a9651d8beb73f99905d422176b5fc66458803f"}],"src/openvpn/ssl_backend.h":[{"author":{"_account_id":1000001,"name":"Frank Lichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"change_message_id":"8f5e47aa3d3ce87a5567f7f965ad46ea16601d05","unresolved":true,"context_lines":[{"line_number":373,"context_line":""},{"line_number":374,"context_line":"/**"},{"line_number":375,"context_line":" * Sets a TLS session to be shutdown state, so the TLS library will generate"},{"line_number":376,"context_line":" * a shutdown altert."},{"line_number":377,"context_line":" */"},{"line_number":378,"context_line":"void"},{"line_number":379,"context_line":"key_state_ssl_shutdown(struct key_state_ssl *ks_ssl);"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"fa6d4de4_e2eda72e","line":376,"updated":"2023-11-20 11:55:56.000000000","message":"alert","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"},{"author":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"cfcb63acedfe6625ab9db44bf4cb3ba6c38e4360","unresolved":false,"context_lines":[{"line_number":373,"context_line":""},{"line_number":374,"context_line":"/**"},{"line_number":375,"context_line":" * Sets a TLS session to be shutdown state, so the TLS library will generate"},{"line_number":376,"context_line":" * a shutdown altert."},{"line_number":377,"context_line":" */"},{"line_number":378,"context_line":"void"},{"line_number":379,"context_line":"key_state_ssl_shutdown(struct key_state_ssl *ks_ssl);"}],"source_content_type":"text/x-csrc","patch_set":1,"id":"6cfd1f28_022bf406","line":376,"in_reply_to":"fa6d4de4_e2eda72e","updated":"2023-11-20 13:02:18.000000000","message":"Done","commit_id":"1c17880327486961b54c13500cd5e2c0778ad427"}]}
