)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"07f32c56_ff9eb8f2","updated":"2024-12-29 00:42:46.000000000","message":"Needs uncrustification.\n\nCode looks good to me, I just have some comments about comments and naming.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"23bf4e37_85f0044a","updated":"2024-12-28 17:34:37.000000000","message":"Reviewed until crypto_epoch.h, will continue later","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"08cd8ccaa218f78bddaadccf7929eea5f035f6c6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"28b2b569_d03927b3","updated":"2025-01-09 16:33:05.000000000","message":"Looks good!\n\nSome typos, but those can be resolved during check-in I think.","commit_id":"c6102d8f41dac23bacbd449710feb38a40e1653d"}],"src/openvpn/crypto.h":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":172,"context_line":"    /** Number of bytes set in the HMac key material */"},{"line_number":173,"context_line":"    int hmac_size;"},{"line_number":174,"context_line":""},{"line_number":175,"context_line":"    /** the epoch of the key is if it was generated as epoch data key material */"},{"line_number":176,"context_line":"    uint16_t epoch;"},{"line_number":177,"context_line":"};"},{"line_number":178,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"a432af93_97a33d7a","line":175,"range":{"start_line":175,"start_character":4,"end_line":175,"end_character":81},"updated":"2024-12-28 17:34:37.000000000","message":"I think you mean: The epoch of the key, if it was generated as epoch data key material.\n\n(Implying, it\u0027s undefined if this is a different kind of key?)","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":172,"context_line":"    /** Number of bytes set in the HMac key material */"},{"line_number":173,"context_line":"    int hmac_size;"},{"line_number":174,"context_line":""},{"line_number":175,"context_line":"    /** the epoch of the key is if it was generated as epoch data key material */"},{"line_number":176,"context_line":"    uint16_t epoch;"},{"line_number":177,"context_line":"};"},{"line_number":178,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"4cf4ae43_56da8da9","line":175,"range":{"start_line":175,"start_character":4,"end_line":175,"end_character":81},"in_reply_to":"a432af93_97a33d7a","updated":"2024-12-29 03:09:05.000000000","message":"I will clarify that this only meaningful if key parameters are used in epoch data and it is not meaningful otherwise.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":220,"context_line":"    /** number of failed verification using this cipher */"},{"line_number":221,"context_line":"    uint64_t failed_verifications;"},{"line_number":222,"context_line":"    /** OpenVPN data channel epoch, this variable holds the"},{"line_number":223,"context_line":"     *  epoch number that is key belongs to. Note that epoch 0 is not used"},{"line_number":224,"context_line":"     *  and epoch is always non-zero for epoch key contexts */"},{"line_number":225,"context_line":"    uint16_t epoch;"},{"line_number":226,"context_line":"};"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"735a8e52_5784bd7e","line":223,"range":{"start_line":223,"start_character":26,"end_line":223,"end_character":28},"updated":"2024-12-28 17:34:37.000000000","message":"this?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":220,"context_line":"    /** number of failed verification using this cipher */"},{"line_number":221,"context_line":"    uint64_t failed_verifications;"},{"line_number":222,"context_line":"    /** OpenVPN data channel epoch, this variable holds the"},{"line_number":223,"context_line":"     *  epoch number that is key belongs to. Note that epoch 0 is not used"},{"line_number":224,"context_line":"     *  and epoch is always non-zero for epoch key contexts */"},{"line_number":225,"context_line":"    uint16_t epoch;"},{"line_number":226,"context_line":"};"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"788a09ea_7023fafa","line":223,"range":{"start_line":223,"start_character":26,"end_line":223,"end_character":28},"in_reply_to":"735a8e52_5784bd7e","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":304,"context_line":"    /** the key_type that is used to generate the epoch keys */"},{"line_number":305,"context_line":"    struct key_type epoch_key_type;"},{"line_number":306,"context_line":""},{"line_number":307,"context_line":"    /** This limit for AEAD cipher, this is the sum of packets + blocks"},{"line_number":308,"context_line":"     * that are allowed to be used. Will switch to a new epoch if this"},{"line_number":309,"context_line":"     * limit is reached*/"},{"line_number":310,"context_line":"    uint64_t aead_usage_limit;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"71ce8066_a53680c4","line":307,"range":{"start_line":307,"start_character":8,"end_line":307,"end_character":34},"updated":"2024-12-29 00:42:46.000000000","message":"The limit for AEAD ciphers?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":304,"context_line":"    /** the key_type that is used to generate the epoch keys */"},{"line_number":305,"context_line":"    struct key_type epoch_key_type;"},{"line_number":306,"context_line":""},{"line_number":307,"context_line":"    /** This limit for AEAD cipher, this is the sum of packets + blocks"},{"line_number":308,"context_line":"     * that are allowed to be used. Will switch to a new epoch if this"},{"line_number":309,"context_line":"     * limit is reached*/"},{"line_number":310,"context_line":"    uint64_t aead_usage_limit;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"3d1e7540_b7a53f6a","line":307,"range":{"start_line":307,"start_character":8,"end_line":307,"end_character":34},"in_reply_to":"71ce8066_a53680c4","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":312,"context_line":"    /** Keeps the future epoch data keys for decryption. The current one"},{"line_number":313,"context_line":"     * that is expected to be used is stored in key_ctx_bi."},{"line_number":314,"context_line":"     *"},{"line_number":315,"context_line":"     * We keep both decrypt and encrypt key here in the future keys"},{"line_number":316,"context_line":"     * as we want to be able to switch also sending key if the peer"},{"line_number":317,"context_line":"     * switching to a newer key epoch"},{"line_number":318,"context_line":"     * */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"a6671a3f_87bca2ec","line":315,"range":{"start_line":315,"start_character":40,"end_line":315,"end_character":43},"updated":"2024-12-28 17:34:37.000000000","message":"keys","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":312,"context_line":"    /** Keeps the future epoch data keys for decryption. The current one"},{"line_number":313,"context_line":"     * that is expected to be used is stored in key_ctx_bi."},{"line_number":314,"context_line":"     *"},{"line_number":315,"context_line":"     * We keep both decrypt and encrypt key here in the future keys"},{"line_number":316,"context_line":"     * as we want to be able to switch also sending key if the peer"},{"line_number":317,"context_line":"     * switching to a newer key epoch"},{"line_number":318,"context_line":"     * */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"1dead943_a6393dd1","line":315,"range":{"start_line":315,"start_character":40,"end_line":315,"end_character":43},"in_reply_to":"a6671a3f_87bca2ec","updated":"2024-12-29 03:09:05.000000000","message":"yes but also the comment is wrong as epoch_data_keys_future only stores receive keys.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":313,"context_line":"     * that is expected to be used is stored in key_ctx_bi."},{"line_number":314,"context_line":"     *"},{"line_number":315,"context_line":"     * We keep both decrypt and encrypt key here in the future keys"},{"line_number":316,"context_line":"     * as we want to be able to switch also sending key if the peer"},{"line_number":317,"context_line":"     * switching to a newer key epoch"},{"line_number":318,"context_line":"     * */"},{"line_number":319,"context_line":"    struct key_ctx *epoch_data_keys_future;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"5f52e18e_e35d296c","line":316,"range":{"start_line":316,"start_character":29,"end_line":316,"end_character":55},"updated":"2024-12-28 17:34:37.000000000","message":"to also switch the sending key?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":313,"context_line":"     * that is expected to be used is stored in key_ctx_bi."},{"line_number":314,"context_line":"     *"},{"line_number":315,"context_line":"     * We keep both decrypt and encrypt key here in the future keys"},{"line_number":316,"context_line":"     * as we want to be able to switch also sending key if the peer"},{"line_number":317,"context_line":"     * switching to a newer key epoch"},{"line_number":318,"context_line":"     * */"},{"line_number":319,"context_line":"    struct key_ctx *epoch_data_keys_future;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"78aa125b_37d2d67c","line":316,"range":{"start_line":316,"start_character":29,"end_line":316,"end_character":55},"in_reply_to":"5f52e18e_e35d296c","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":321,"context_line":"    /** number of keys stored in \\c epoch_data_keys_future */"},{"line_number":322,"context_line":"    uint16_t epoch_data_keys_future_count;"},{"line_number":323,"context_line":""},{"line_number":324,"context_line":"    /** The old key bevor the sender switch to a new epoch data key */"},{"line_number":325,"context_line":"    struct key_ctx epoch_retiring_data_receive_key;"},{"line_number":326,"context_line":"    struct packet_id_rec epoch_retiring_key_pid_recv;"},{"line_number":327,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"68672759_37e827d3","line":324,"range":{"start_line":324,"start_character":37,"end_line":324,"end_character":43},"updated":"2024-12-28 17:34:37.000000000","message":"switched?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":321,"context_line":"    /** number of keys stored in \\c epoch_data_keys_future */"},{"line_number":322,"context_line":"    uint16_t epoch_data_keys_future_count;"},{"line_number":323,"context_line":""},{"line_number":324,"context_line":"    /** The old key bevor the sender switch to a new epoch data key */"},{"line_number":325,"context_line":"    struct key_ctx epoch_retiring_data_receive_key;"},{"line_number":326,"context_line":"    struct packet_id_rec epoch_retiring_key_pid_recv;"},{"line_number":327,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"f57d4cd6_30ec7906","line":324,"range":{"start_line":324,"start_character":37,"end_line":324,"end_character":43},"in_reply_to":"68672759_37e827d3","updated":"2024-12-29 03:09:05.000000000","message":"yes, and also before instead of bevor.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":521,"context_line":" *"},{"line_number":522,"context_line":" * @param opt   Crypto options for this packet, contains replay state."},{"line_number":523,"context_line":" * @param pin   Packet ID read from packet."},{"line_number":524,"context_line":" * @param epoch Epoch read from packet or 0 when epoch is not used."},{"line_number":525,"context_line":" * @param error_prefix  Prefix to use when printing error messages."},{"line_number":526,"context_line":" * @param gc    Garbage collector to use."},{"line_number":527,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"7c80d6b3_104e8e59","line":524,"range":{"start_line":524,"start_character":3,"end_line":524,"end_character":67},"updated":"2024-12-28 17:34:37.000000000","message":"That\u0027s not an argument of the function.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":521,"context_line":" *"},{"line_number":522,"context_line":" * @param opt   Crypto options for this packet, contains replay state."},{"line_number":523,"context_line":" * @param pin   Packet ID read from packet."},{"line_number":524,"context_line":" * @param epoch Epoch read from packet or 0 when epoch is not used."},{"line_number":525,"context_line":" * @param error_prefix  Prefix to use when printing error messages."},{"line_number":526,"context_line":" * @param gc    Garbage collector to use."},{"line_number":527,"context_line":" *"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"be5e1ecc_1af62691","line":524,"range":{"start_line":524,"start_character":3,"end_line":524,"end_character":67},"in_reply_to":"7c80d6b3_104e8e59","updated":"2024-12-29 03:09:05.000000000","message":"yes that got into a commit too early. I moved it to the commit that actually adds the epoch parameter.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"}],"src/openvpn/crypto_epoch.c":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":133,"context_line":""},{"line_number":134,"context_line":"    /* E_N+1 \u003d OVPN-Expand-Label(E_N, \"datakey upd\", \"\", 32) */"},{"line_number":135,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":136,"context_line":"                      epoch_update_label, 11,"},{"line_number":137,"context_line":"                      NULL, 0,"},{"line_number":138,"context_line":"                      new_epoch_key.epoch_key, sizeof(new_epoch_key.epoch_key));"},{"line_number":139,"context_line":"    *epoch_key \u003d new_epoch_key;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"4fc082c6_eb80eb11","line":136,"range":{"start_line":136,"start_character":42,"end_line":136,"end_character":44},"updated":"2024-12-29 00:42:46.000000000","message":"We could use strlen() here.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":133,"context_line":""},{"line_number":134,"context_line":"    /* E_N+1 \u003d OVPN-Expand-Label(E_N, \"datakey upd\", \"\", 32) */"},{"line_number":135,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":136,"context_line":"                      epoch_update_label, 11,"},{"line_number":137,"context_line":"                      NULL, 0,"},{"line_number":138,"context_line":"                      new_epoch_key.epoch_key, sizeof(new_epoch_key.epoch_key));"},{"line_number":139,"context_line":"    *epoch_key \u003d new_epoch_key;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"37c7c0ca_5ba66eff","line":136,"range":{"start_line":136,"start_character":42,"end_line":136,"end_character":44},"in_reply_to":"4fc082c6_eb80eb11","updated":"2024-12-29 03:09:05.000000000","message":"I will be using sizeof(array) - 1 as strlen doesn\u0027t really like operating on a uint8_t array.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":154,"context_line":""},{"line_number":155,"context_line":"    const uint8_t epoch_data_key_label[] \u003d \"data_key\";"},{"line_number":156,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":157,"context_line":"                      epoch_data_key_label, 8,"},{"line_number":158,"context_line":"                      NULL, 0,"},{"line_number":159,"context_line":"                      (uint8_t *)(\u0026key-\u003ecipher), key-\u003ecipher_size);"},{"line_number":160,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"8fdb0547_fcd70ff2","line":157,"range":{"start_line":157,"start_character":44,"end_line":157,"end_character":45},"updated":"2024-12-29 00:42:46.000000000","message":"strlen?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":154,"context_line":""},{"line_number":155,"context_line":"    const uint8_t epoch_data_key_label[] \u003d \"data_key\";"},{"line_number":156,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":157,"context_line":"                      epoch_data_key_label, 8,"},{"line_number":158,"context_line":"                      NULL, 0,"},{"line_number":159,"context_line":"                      (uint8_t *)(\u0026key-\u003ecipher), key-\u003ecipher_size);"},{"line_number":160,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"b83b22ac_c3dd00bb","line":157,"range":{"start_line":157,"start_character":44,"end_line":157,"end_character":45},"in_reply_to":"8fdb0547_fcd70ff2","updated":"2024-12-29 03:09:05.000000000","message":"same as above","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":160,"context_line":""},{"line_number":161,"context_line":"    const uint8_t epoch_data_iv_label[] \u003d \"data_iv\";"},{"line_number":162,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":163,"context_line":"                      epoch_data_iv_label, 7,"},{"line_number":164,"context_line":"                      NULL, 0,"},{"line_number":165,"context_line":"                      (uint8_t *)(\u0026key-\u003ehmac), key-\u003ehmac_size);"},{"line_number":166,"context_line":"    key-\u003eepoch \u003d epoch_key-\u003eepoch;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"403bd9f7_0bc3e36d","line":163,"range":{"start_line":163,"start_character":43,"end_line":163,"end_character":44},"updated":"2024-12-29 00:42:46.000000000","message":"strlen?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":160,"context_line":""},{"line_number":161,"context_line":"    const uint8_t epoch_data_iv_label[] \u003d \"data_iv\";"},{"line_number":162,"context_line":"    ovpn_expand_label(epoch_key-\u003eepoch_key, sizeof(epoch_key-\u003eepoch_key),"},{"line_number":163,"context_line":"                      epoch_data_iv_label, 7,"},{"line_number":164,"context_line":"                      NULL, 0,"},{"line_number":165,"context_line":"                      (uint8_t *)(\u0026key-\u003ehmac), key-\u003ehmac_size);"},{"line_number":166,"context_line":"    key-\u003eepoch \u003d epoch_key-\u003eepoch;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"ae88362e_fa765dab","line":163,"range":{"start_line":163,"start_character":43,"end_line":163,"end_character":44},"in_reply_to":"403bd9f7_0bc3e36d","updated":"2024-12-29 03:09:05.000000000","message":"same as above","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":207,"context_line":"    /* We want the number of receive keys starting with the currently used"},{"line_number":208,"context_line":"     * keys. */"},{"line_number":209,"context_line":"    ASSERT(co-\u003ekey_ctx_bi.initialized);"},{"line_number":210,"context_line":"    uint16_t current_epoch_recv \u003d co-\u003ekey_ctx_bi.decrypt.epoch;"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"    /* Either we have not generated any future keys yet or the last"},{"line_number":213,"context_line":"     * index is the same as our current epoch key */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"769c056a_676d4fc5","line":210,"range":{"start_line":210,"start_character":4,"end_line":210,"end_character":63},"updated":"2024-12-29 00:42:46.000000000","message":"The variable name makes this look like it should be co-\u003eepoch_key_recv.epoch.\n\nAfter reading the function, I think the code is correct, but together with the ASSERT below, this caused me a lot of confusion. I thought that the assert was saying that you can only generate new future keys if you used them all up.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":207,"context_line":"    /* We want the number of receive keys starting with the currently used"},{"line_number":208,"context_line":"     * keys. */"},{"line_number":209,"context_line":"    ASSERT(co-\u003ekey_ctx_bi.initialized);"},{"line_number":210,"context_line":"    uint16_t current_epoch_recv \u003d co-\u003ekey_ctx_bi.decrypt.epoch;"},{"line_number":211,"context_line":""},{"line_number":212,"context_line":"    /* Either we have not generated any future keys yet or the last"},{"line_number":213,"context_line":"     * index is the same as our current epoch key */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"4b15f462_6189d29b","line":210,"range":{"start_line":210,"start_character":4,"end_line":210,"end_character":63},"in_reply_to":"769c056a_676d4fc5","updated":"2024-12-29 03:09:05.000000000","message":"I reworked the comment and the function doxygen to hopefully make it a bit better to understand.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":420,"context_line":"        /* draft 8 of the aead usage limit still had but draft 9 complete"},{"line_number":421,"context_line":"         * dropped this statement:"},{"line_number":422,"context_line":"         *"},{"line_number":423,"context_line":"         *    In particular, is two-party communication, one participant cannot"},{"line_number":424,"context_line":"         *    regard apparent overuse of a key by other participants as"},{"line_number":425,"context_line":"         *    being in error, when it could be that the other participant has"},{"line_number":426,"context_line":"         *    better information about bounds."}],"source_content_type":"text/x-csrc","patch_set":9,"id":"dcaea617_c7f7124b","line":423,"range":{"start_line":423,"start_character":29,"end_line":423,"end_character":31},"updated":"2024-12-29 00:42:46.000000000","message":"in?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":420,"context_line":"        /* draft 8 of the aead usage limit still had but draft 9 complete"},{"line_number":421,"context_line":"         * dropped this statement:"},{"line_number":422,"context_line":"         *"},{"line_number":423,"context_line":"         *    In particular, is two-party communication, one participant cannot"},{"line_number":424,"context_line":"         *    regard apparent overuse of a key by other participants as"},{"line_number":425,"context_line":"         *    being in error, when it could be that the other participant has"},{"line_number":426,"context_line":"         *    better information about bounds."}],"source_content_type":"text/x-csrc","patch_set":9,"id":"85168ea8_12a0a758","line":423,"range":{"start_line":423,"start_character":29,"end_line":423,"end_character":31},"in_reply_to":"dcaea617_c7f7124b","updated":"2024-12-29 03:09:05.000000000","message":"not sure how I managed to mangle this when I copy\u0026pasted it.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"08cd8ccaa218f78bddaadccf7929eea5f035f6c6","unresolved":true,"context_lines":[{"line_number":212,"context_line":"void"},{"line_number":213,"context_line":"epoch_generate_future_receive_keys(struct crypto_options *co)"},{"line_number":214,"context_line":"{"},{"line_number":215,"context_line":"    /* We want the future receive keys to start just after the epoch of the"},{"line_number":216,"context_line":"     * the currently used decryption key. */"},{"line_number":217,"context_line":"    ASSERT(co-\u003ekey_ctx_bi.initialized);"},{"line_number":218,"context_line":"    uint16_t current_decrypt_epoch \u003d co-\u003ekey_ctx_bi.decrypt.epoch;"},{"line_number":219,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":12,"id":"b2171fc7_9bf1eb9e","line":216,"range":{"start_line":215,"start_character":0,"end_line":216,"end_character":44},"updated":"2025-01-09 16:33:05.000000000","message":"\"the the\"\n\n(can be fixed during commit I think)","commit_id":"c6102d8f41dac23bacbd449710feb38a40e1653d"}],"src/openvpn/crypto_epoch.h":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"/**"},{"line_number":71,"context_line":" * Generate a data channel key pair from the epoch key"},{"line_number":72,"context_line":" * @param epoch_key     Epoch key to be used"},{"line_number":73,"context_line":" * @param key          Destination for the generated data key"},{"line_number":74,"context_line":" * @parm kt             Cipher information to generate the data channel key for"},{"line_number":75,"context_line":" */"},{"line_number":76,"context_line":"void"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"ced0bc22_010e9c3f","line":73,"range":{"start_line":72,"start_character":1,"end_line":73,"end_character":61},"updated":"2024-12-28 17:34:37.000000000","message":"wrong order compared to the function.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"/**"},{"line_number":71,"context_line":" * Generate a data channel key pair from the epoch key"},{"line_number":72,"context_line":" * @param epoch_key     Epoch key to be used"},{"line_number":73,"context_line":" * @param key          Destination for the generated data key"},{"line_number":74,"context_line":" * @parm kt             Cipher information to generate the data channel key for"},{"line_number":75,"context_line":" */"},{"line_number":76,"context_line":"void"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"87827b4b_e2c66cc6","line":73,"range":{"start_line":72,"start_character":1,"end_line":73,"end_character":61},"in_reply_to":"ced0bc22_010e9c3f","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":88,"context_line":"epoch_generate_future_receive_keys(struct crypto_options *co);"},{"line_number":89,"context_line":""},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"/** This is called when the peer using a new send key that is not the default"},{"line_number":92,"context_line":" * key. This function ensures the following:"},{"line_number":93,"context_line":" * - recv key matches the epoch index provided"},{"line_number":94,"context_line":" * - send key epoch is equal or higher than recv_key epoch"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"cb952e40_38a4c3a6","line":91,"range":{"start_line":91,"start_character":33,"end_line":91,"end_character":38},"updated":"2024-12-28 17:34:37.000000000","message":"uses","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":88,"context_line":"epoch_generate_future_receive_keys(struct crypto_options *co);"},{"line_number":89,"context_line":""},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"/** This is called when the peer using a new send key that is not the default"},{"line_number":92,"context_line":" * key. This function ensures the following:"},{"line_number":93,"context_line":" * - recv key matches the epoch index provided"},{"line_number":94,"context_line":" * - send key epoch is equal or higher than recv_key epoch"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"3e654f8c_e8b2f61e","line":91,"range":{"start_line":91,"start_character":33,"end_line":91,"end_character":38},"in_reply_to":"cb952e40_38a4c3a6","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":93,"context_line":" * - recv key matches the epoch index provided"},{"line_number":94,"context_line":" * - send key epoch is equal or higher than recv_key epoch"},{"line_number":95,"context_line":" *"},{"line_number":96,"context_line":" * @param new_epoch the new epoch to use a the receive key"},{"line_number":97,"context_line":" */"},{"line_number":98,"context_line":"void"},{"line_number":99,"context_line":"epoch_replace_update_recv_key(struct crypto_options *co,"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"480f9270_6b023e63","line":96,"range":{"start_line":96,"start_character":41,"end_line":96,"end_character":42},"updated":"2024-12-28 17:34:37.000000000","message":"for the receive key?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":93,"context_line":" * - recv key matches the epoch index provided"},{"line_number":94,"context_line":" * - send key epoch is equal or higher than recv_key epoch"},{"line_number":95,"context_line":" *"},{"line_number":96,"context_line":" * @param new_epoch the new epoch to use a the receive key"},{"line_number":97,"context_line":" */"},{"line_number":98,"context_line":"void"},{"line_number":99,"context_line":"epoch_replace_update_recv_key(struct crypto_options *co,"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"0a1c083e_f7fbf9ba","line":96,"range":{"start_line":96,"start_character":41,"end_line":96,"end_character":42},"in_reply_to":"480f9270_6b023e63","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":100,"context_line":"                              uint16_t new_epoch);"},{"line_number":101,"context_line":""},{"line_number":102,"context_line":"/**"},{"line_number":103,"context_line":" * Updates the send key and send_epoch_keyt in cryptio_options-\u003ekey_ctx_bi to"},{"line_number":104,"context_line":" * use the next epoch */"},{"line_number":105,"context_line":"void"},{"line_number":106,"context_line":"epoch_iterate_send_key(struct crypto_options *co);"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"3dba7c21_2b0cdd56","line":103,"range":{"start_line":103,"start_character":28,"end_line":103,"end_character":43},"updated":"2024-12-28 17:34:37.000000000","message":"send_epoch_key","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":100,"context_line":"                              uint16_t new_epoch);"},{"line_number":101,"context_line":""},{"line_number":102,"context_line":"/**"},{"line_number":103,"context_line":" * Updates the send key and send_epoch_keyt in cryptio_options-\u003ekey_ctx_bi to"},{"line_number":104,"context_line":" * use the next epoch */"},{"line_number":105,"context_line":"void"},{"line_number":106,"context_line":"epoch_iterate_send_key(struct crypto_options *co);"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"f2c845b2_b82d132e","line":103,"range":{"start_line":103,"start_character":28,"end_line":103,"end_character":43},"in_reply_to":"3dba7c21_2b0cdd56","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"1e7b2126341ea0b79ab486dc15cf56792a7492a3","unresolved":true,"context_lines":[{"line_number":115,"context_line":" * Initialises data channel keys and internal structures for epoch data keys"},{"line_number":116,"context_line":" * using the provided E0 epoch key"},{"line_number":117,"context_line":" *"},{"line_number":118,"context_line":" * @param e1_send    The E1 send epoch key derived by TLS-EKM"},{"line_number":119,"context_line":" * @param e1_recv    The E1 receive epoch key derived by TLS-EKM"},{"line_number":120,"context_line":" */"},{"line_number":121,"context_line":"void"},{"line_number":122,"context_line":"epoch_init_key_ctx(struct crypto_options *co, const struct key_type *key_type,"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"44263987_947e608e","line":119,"range":{"start_line":118,"start_character":1,"end_line":119,"end_character":64},"updated":"2024-12-28 17:34:37.000000000","message":"incomplete parameters","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":115,"context_line":" * Initialises data channel keys and internal structures for epoch data keys"},{"line_number":116,"context_line":" * using the provided E0 epoch key"},{"line_number":117,"context_line":" *"},{"line_number":118,"context_line":" * @param e1_send    The E1 send epoch key derived by TLS-EKM"},{"line_number":119,"context_line":" * @param e1_recv    The E1 receive epoch key derived by TLS-EKM"},{"line_number":120,"context_line":" */"},{"line_number":121,"context_line":"void"},{"line_number":122,"context_line":"epoch_init_key_ctx(struct crypto_options *co, const struct key_type *key_type,"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"2ef5767a_589a85d0","line":119,"range":{"start_line":118,"start_character":1,"end_line":119,"end_character":64},"in_reply_to":"44263987_947e608e","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"}],"src/openvpn/packet_id.c":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":78,"context_line":"}"},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"void"},{"line_number":81,"context_line":"packet_id_init_recv(struct packet_id_rec *rec, int seq_backtrack, int time_backtrack, const char *name, int unit)"},{"line_number":82,"context_line":"{"},{"line_number":83,"context_line":"    rec-\u003ename \u003d name;"},{"line_number":84,"context_line":"    rec-\u003eunit \u003d unit;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"bf06e613_bc17423a","line":81,"updated":"2024-12-29 00:42:46.000000000","message":"You could make this a static function.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":78,"context_line":"}"},{"line_number":79,"context_line":""},{"line_number":80,"context_line":"void"},{"line_number":81,"context_line":"packet_id_init_recv(struct packet_id_rec *rec, int seq_backtrack, int time_backtrack, const char *name, int unit)"},{"line_number":82,"context_line":"{"},{"line_number":83,"context_line":"    rec-\u003ename \u003d name;"},{"line_number":84,"context_line":"    rec-\u003eunit \u003d unit;"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"129a630b_4118bf6c","line":81,"in_reply_to":"bf06e613_bc17423a","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"}],"src/openvpn/packet_id.h":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":211,"context_line":" * be reinitialised with"},{"line_number":212,"context_line":" * @param dest"},{"line_number":213,"context_line":" * @param src"},{"line_number":214,"context_line":" */"},{"line_number":215,"context_line":"void"},{"line_number":216,"context_line":"packet_id_move_recv(struct packet_id_rec *dest, struct packet_id_rec *src);"},{"line_number":217,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"7be792f3_fe78b9b2","line":214,"updated":"2024-12-29 00:42:46.000000000","message":"Incomplete","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":211,"context_line":" * be reinitialised with"},{"line_number":212,"context_line":" * @param dest"},{"line_number":213,"context_line":" * @param src"},{"line_number":214,"context_line":" */"},{"line_number":215,"context_line":"void"},{"line_number":216,"context_line":"packet_id_move_recv(struct packet_id_rec *dest, struct packet_id_rec *src);"},{"line_number":217,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"929b34fb_60e60e0a","line":214,"in_reply_to":"7be792f3_fe78b9b2","updated":"2024-12-29 03:09:05.000000000","message":"Acknowledged","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"08cd8ccaa218f78bddaadccf7929eea5f035f6c6","unresolved":true,"context_lines":[{"line_number":207,"context_line":"void packet_id_free(struct packet_id *p);"},{"line_number":208,"context_line":""},{"line_number":209,"context_line":"/**"},{"line_number":210,"context_line":" * Move the packet id recv structure from \\c src to \\c dest. \\c src will will"},{"line_number":211,"context_line":" * be reinitialised. \\c dest will be freed before the move."},{"line_number":212,"context_line":" */"},{"line_number":213,"context_line":"void"},{"line_number":214,"context_line":"packet_id_move_recv(struct packet_id_rec *dest, struct packet_id_rec *src);"}],"source_content_type":"text/x-csrc","patch_set":12,"id":"0548db58_7fc4e970","line":211,"range":{"start_line":210,"start_character":0,"end_line":211,"end_character":59},"updated":"2025-01-09 16:33:05.000000000","message":"\"will will\"","commit_id":"c6102d8f41dac23bacbd449710feb38a40e1653d"}],"tests/unit_tests/openvpn/test_crypto.c":[{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":725,"context_line":""},{"line_number":726,"context_line":"    init_key_type(\u0026data-\u003ekt, \"AES-128-GCM\", \"none\", true, false);"},{"line_number":727,"context_line":""},{"line_number":728,"context_line":"    /* have an epoch key that is uses 0x23 for the key for all bytes */"},{"line_number":729,"context_line":"    struct epoch_key epoch1send \u003d { .epoch \u003d 1, .epoch_key \u003d {0x23} };"},{"line_number":730,"context_line":"    struct epoch_key epoch1recv \u003d { .epoch \u003d 1, .epoch_key \u003d {0x27} };"},{"line_number":731,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"7799a129_e434234f","line":728,"range":{"start_line":728,"start_character":30,"end_line":728,"end_character":37},"updated":"2024-12-29 00:42:46.000000000","message":"uses","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":725,"context_line":""},{"line_number":726,"context_line":"    init_key_type(\u0026data-\u003ekt, \"AES-128-GCM\", \"none\", true, false);"},{"line_number":727,"context_line":""},{"line_number":728,"context_line":"    /* have an epoch key that is uses 0x23 for the key for all bytes */"},{"line_number":729,"context_line":"    struct epoch_key epoch1send \u003d { .epoch \u003d 1, .epoch_key \u003d {0x23} };"},{"line_number":730,"context_line":"    struct epoch_key epoch1recv \u003d { .epoch \u003d 1, .epoch_key \u003d {0x27} };"},{"line_number":731,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"b63adfb5_696e6519","line":728,"range":{"start_line":728,"start_character":30,"end_line":728,"end_character":37},"in_reply_to":"7799a129_e434234f","updated":"2024-12-29 03:09:05.000000000","message":"Done","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":827,"context_line":"    assert_int_equal(epoch_lookup_decrypt_key(co, 14)-\u003eepoch, 14);"},{"line_number":828,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 15));"},{"line_number":829,"context_line":""},{"line_number":830,"context_line":"    /* Should move 1 to retiring key but leave 1-5 undefined, 7 as"},{"line_number":831,"context_line":"     * active and 8-20 as future keys*/"},{"line_number":832,"context_line":"    epoch_replace_update_recv_key(co, 7);"},{"line_number":833,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"e365ffa5_5d07eb01","line":830,"range":{"start_line":830,"start_character":47,"end_line":830,"end_character":50},"updated":"2024-12-29 00:42:46.000000000","message":"2-6","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":827,"context_line":"    assert_int_equal(epoch_lookup_decrypt_key(co, 14)-\u003eepoch, 14);"},{"line_number":828,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 15));"},{"line_number":829,"context_line":""},{"line_number":830,"context_line":"    /* Should move 1 to retiring key but leave 1-5 undefined, 7 as"},{"line_number":831,"context_line":"     * active and 8-20 as future keys*/"},{"line_number":832,"context_line":"    epoch_replace_update_recv_key(co, 7);"},{"line_number":833,"context_line":""}],"source_content_type":"text/x-csrc","patch_set":9,"id":"aa4ca31d_556d7a6b","line":830,"range":{"start_line":830,"start_character":47,"end_line":830,"end_character":50},"in_reply_to":"e365ffa5_5d07eb01","updated":"2024-12-29 03:09:05.000000000","message":"Done","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":832,"context_line":"    epoch_replace_update_recv_key(co, 7);"},{"line_number":833,"context_line":""},{"line_number":834,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 0));"},{"line_number":835,"context_line":"    assert_int_equal(epoch_lookup_decrypt_key(co, 1)-\u003eepoch, 1);"},{"line_number":836,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 2));"},{"line_number":837,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 3));"},{"line_number":838,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 4));"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"c9e49297_c1a18bdd","line":835,"updated":"2024-12-29 00:42:46.000000000","message":"Could we make sure that it really is the retiring key by comparing it with \u0026co-\u003eepoch_retiring_data_receive_key?\n\nSimilar for epoch 7 and \u0026co-\u003ekey_ctx_bi.decrypt","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":832,"context_line":"    epoch_replace_update_recv_key(co, 7);"},{"line_number":833,"context_line":""},{"line_number":834,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 0));"},{"line_number":835,"context_line":"    assert_int_equal(epoch_lookup_decrypt_key(co, 1)-\u003eepoch, 1);"},{"line_number":836,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 2));"},{"line_number":837,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 3));"},{"line_number":838,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, 4));"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"cb188983_ad366b2c","line":835,"in_reply_to":"c9e49297_c1a18bdd","updated":"2024-12-29 03:09:05.000000000","message":"good idea.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"change_message_id":"e2a6b299528a6253460120651a7a04bd0fb07228","unresolved":true,"context_lines":[{"line_number":896,"context_line":""},{"line_number":897,"context_line":"    /* This key is no longer eligible for decrypting as the 32 future keys"},{"line_number":898,"context_line":"     * would be larger than uint16_t maximum */"},{"line_number":899,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, UINT16_MAX - 32));"},{"line_number":900,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, UINT16_MAX));"},{"line_number":901,"context_line":""},{"line_number":902,"context_line":"    /* Check that moving to the last possible epoch works */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"a1b07fcd_530357a4","line":899,"updated":"2024-12-29 00:42:46.000000000","message":"This hard-codes the assumption that this function is called with a state that has num_future_keys \u003d\u003d 32. Can\u0027t we get that number from co instead?","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"},{"author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"change_message_id":"87f72477ed56cf4de89e7324706e45990765a7a3","unresolved":false,"context_lines":[{"line_number":896,"context_line":""},{"line_number":897,"context_line":"    /* This key is no longer eligible for decrypting as the 32 future keys"},{"line_number":898,"context_line":"     * would be larger than uint16_t maximum */"},{"line_number":899,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, UINT16_MAX - 32));"},{"line_number":900,"context_line":"    assert_null(epoch_lookup_decrypt_key(co, UINT16_MAX));"},{"line_number":901,"context_line":""},{"line_number":902,"context_line":"    /* Check that moving to the last possible epoch works */"}],"source_content_type":"text/x-csrc","patch_set":9,"id":"eca5ecc7_126d252a","line":899,"in_reply_to":"a1b07fcd_530357a4","updated":"2024-12-29 03:09:05.000000000","message":"I think for a unit test hardcoding this is fine. I think we want to rather hardcode it here rather then to rely on the internal state of co being correct for the unit test.\n\nI will add an assert that the num_future_keys is 32 and then use num_future_keys as you suggested.","commit_id":"046bb827deaeefe001187b2bb1d2100135d6677e"}]}
