[Openvpn-devel] [S] Change in openvpn[master]: Do not attempt to decrypt packets anymore after 2**36 failed decryptions

2024-12-27 Thread MaxF (Code Review)
Attention is currently required from: flichtenheld, plaisthos. MaxF has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/843?usp=email ) Change subject: Do not attempt to decrypt packets anymore after 2**36 failed decryptions ..

[Openvpn-devel] [S] Change in openvpn[master]: Do not attempt to decrypt packets anymore after 2**36 failed decryptions

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: MaxF, flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/843?usp=email ) Change subject: Do not attempt to decrypt packets anymore after 2**36 failed decryptions ..

[Openvpn-devel] [S] Change in openvpn[master]: Do not attempt to decrypt packets anymore after 2**36 failed decryptions

2024-12-27 Thread MaxF (Code Review)
Attention is currently required from: flichtenheld, plaisthos. MaxF has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/843?usp=email ) Change subject: Do not attempt to decrypt packets anymore after 2**36 failed decryptions ..

[Openvpn-devel] [PATCH applied] Re: Regenerate doxygen config file with doxygen -u

2024-12-27 Thread Gert Doering
"whatever this does"... it doesn't come with code changes, so nothing for me to test. Your patch has been applied to the master branch. commit 115058d2d586ad19956d7ee119ca438b1c5a985a Author: Frank Lichtenheld Date: Fri Dec 27 19:22:42 2024 +0100 Regenerate doxygen config file with doxyge

[Openvpn-devel] [M] Change in openvpn[master]: Add methods to read/write packet ids for epoch data

2024-12-27 Thread MaxF (Code Review)
Attention is currently required from: flichtenheld, plaisthos, stipa. MaxF has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/803?usp=email ) Change subject: Add methods to read/write packet ids for epoch data .

[Openvpn-devel] [M] Change in openvpn[master]: Add methods to read/write packet ids for epoch data

2024-12-27 Thread MaxF (Code Review)
Attention is currently required from: flichtenheld, plaisthos, stipa. MaxF has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/803?usp=email ) Change subject: Add methods to read/write packet ids for epoch data .

[Openvpn-devel] [PATCH v2] Regenerate doxygen config file with doxygen -u

2024-12-27 Thread Gert Doering
From: Frank Lichtenheld We clearly do not maintain this file, so let's doxygen do it. Drops some obsolte parameters but otherwise shouldn't change anything. Change-Id: Ia6fa1fd8161126bd8e7fba00f28c55dc29bb0cef Signed-off-by: Frank Lichtenheld Acked-by: Arne Schwabe --- This change was reviewe

[Openvpn-devel] [XL] Change in openvpn[master]: Regenerate doxygen config file with doxygen -u

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/779?usp=email ) Change subject: Regenerate doxygen config file with doxygen -u .. Patch

[Openvpn-devel] [S] Change in openvpn[master]: Rename aead-tag-at-end to aead-epoch

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/805?usp=email to look at the new patch set (#9). The following approvals got outdated and were removed: Code-Review-1 by flichtenh

[Openvpn-devel] [M] Change in openvpn[master]: Add methods to read/write packet ids for epoch data

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld, stipa. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/803?usp=email to look at the new patch set (#9). The following approvals got outdated and were removed: Code-Review-1 by fli

[Openvpn-devel] [S] Change in openvpn[master]: Rename aead-tag-at-end to aead-epoch

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/805?usp=email ) Change subject: Rename aead-tag-at-end to aead-epoch .. Patch Set 8: (1

[Openvpn-devel] [M] Change in openvpn[master]: Add methods to read/write packet ids for epoch data

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld, stipa. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/803?usp=email ) Change subject: Add methods to read/write packet ids for epoch data ...

[Openvpn-devel] [S] Change in openvpn[master]: Rename aead-tag-at-end to aead-epoch

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/805?usp=email ) Change subject: Rename aead-tag-at-end to aead-epoch .. Patch Set 8: (1

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#10) to the change originally created by its_Giaan. ( http://gerrit.openvpn.net/c/openvpn/+/762?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by cron2 Change subject: override ai_family if 'local' numeric address was specifi

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/762?usp=email ) Change subject: override ai_family if 'local' numeric address was specified .. override ai_family if 'local' numeric address was specified

[Openvpn-devel] [PATCH applied] Re: override ai_family if 'local' numeric address was specified

2024-12-27 Thread Gert Doering
This does change semantics of "local " or "remote ", but in a useful way. The old code would just fail on proto udp4 remote 2001:db8::1 because it tried to force-resolve the v6 address as "proto v4" (and vice versa): 2024-12-24 13:24:18 RESOLVE: Cannot resolve host address: 2001:db8::1:5119

[Openvpn-devel] [PATCH applied] Re: Review doxygen warnings

2024-12-27 Thread Gert Doering
Only comment changes, so nothing to test for me :-) Your patch has been applied to the master branch. commit ccdffc08f3c9e672f68755876138e1f50468575f Author: Frank Lichtenheld Date: Fri Dec 27 17:16:48 2024 +0100 Review doxygen warnings Signed-off-by: Frank Lichtenheld Acked-b

[Openvpn-devel] [L] Change in openvpn[master]: Review doxygen warnings

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#3) to the change originally created by flichtenheld. ( http://gerrit.openvpn.net/c/openvpn/+/778?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by plaisthos Change subject: Review doxygen warnings ...

[Openvpn-devel] [L] Change in openvpn[master]: Review doxygen warnings

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/778?usp=email ) Change subject: Review doxygen warnings .. Review doxygen warnings We write doxygen comments but we do not verify them. So quite some erro

[Openvpn-devel] [M] Change in openvpn[master]: Change API of init_key_ctx to use struct key_parameters

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/801?usp=email ) Change subject: Change API of init_key_ctx to use struct key_parameters .. Change API of init_key_ctx to use struct key_parameters This in

[Openvpn-devel] [M] Change in openvpn[master]: Change API of init_key_ctx to use struct key_parameters

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#10) to the change originally created by plaisthos. ( http://gerrit.openvpn.net/c/openvpn/+/801?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by flichtenheld Change subject: Change API of init_key_ctx to use struct key_param

[Openvpn-devel] [PATCH applied] Re: Change API of init_key_ctx to use struct key_parameters

2024-12-27 Thread Gert Doering
I'm not sure I understand all the intricacies here (like, "cipher_size = MAX_CIPHER_KEY_LENGTH", what's that for?), but it passes all the client/server test, memory operations look safe, and it has a unit test and a +2 from Frank :-) Your patch has been applied to the master branch. commit 5bbf0a

[Openvpn-devel] [L] Change in openvpn[master]: dns: apply settings via script on unixoid systems

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: d12fk, plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/838?usp=email ) Change subject: dns: apply settings via script on unixoid systems .

[Openvpn-devel] [M] Change in openvpn[master]: dns: support running up/down script with privsep

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: d12fk, plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/839?usp=email ) Change subject: dns: support running up/down script with privsep ..

[Openvpn-devel] [M] Change in openvpn[master]: Add methods to read/write packet ids for epoch data

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos, stipa. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/803?usp=email ) Change subject: Add methods to read/write packet ids for epoch data ...

[Openvpn-devel] [L] Change in openvpn[master]: Review doxygen warnings

2024-12-27 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/778?usp=email ) Change subject: Review doxygen warnings .. Patch Set 2: Code-Review+2

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/762?usp=email ) Change subject: override ai_family if 'local' numeric address was specified .

[Openvpn-devel] [PATCH v9] override ai_family if 'local' numeric address was specified

2024-12-27 Thread Gert Doering
From: Antonio Quartulli This change ensures that when a numeric IP address is specified as argument to a 'local' directive, its ai_family overrides the one extracted from the 'proto' config option. Change-Id: Ie2471e6b2d6974e70423b09918ad1c2136253754 Signed-off-by: Antonio Quartulli Signed-off-

[Openvpn-devel] [PATCH v2] Review doxygen warnings

2024-12-27 Thread Gert Doering
From: Frank Lichtenheld We write doxygen comments but we do not verify them. So quite some errors have crept in. Trying to reduce them by reviewing the warnings output of doxygen and addressing most of them. Did generally ignore "The following parameter is not documented" warnings (except those

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#3) to the change originally created by flichtenheld. ( http://gerrit.openvpn.net/c/openvpn/+/789?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by stipa, Code-Review+2 by uddr Change subject: GHA: General update December 202

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/789?usp=email ) Change subject: GHA: General update December 2024 .. GHA: General update December 2024 Contains the following renovate updates: - Update

[Openvpn-devel] [PATCH applied] Re: GHA: General update December 2024

2024-12-27 Thread Gert Doering
Your patch has been applied to the master branch. commit 08fe4bb4b040f44450439b92788eac6144283494 Author: Frank Lichtenheld Date: Fri Dec 27 15:36:52 2024 +0100 GHA: General update December 2024 Signed-off-by: Frank Lichtenheld Acked-by: Yuriy Darnobyt Acked-by: Lev Stipa

[Openvpn-devel] [S] Change in openvpn[master]: Rename aead-tag-at-end to aead-epoch

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/805?usp=email ) Change subject: Rename aead-tag-at-end to aead-epoch .. Patch Set 8: Cod

[Openvpn-devel] [PATCH v2] GHA: General update December 2024

2024-12-27 Thread Frank Lichtenheld
Contains the following renovate updates: - Update dependency libressl/portable to v4 - Requires setting LIBRESSL_GIT_OPTIONS since the default is --depth=8 which is unusable for checking out tags. - Update dependency Mbed-TLS/mbedtls to v3.6.2 - Update mingw ubuntu runner to v24 - Do N

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread uddr (Code Review)
Attention is currently required from: flichtenheld, plaisthos. uddr has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/789?usp=email ) Change subject: GHA: General update December 2024 .. Patch Set 2:

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread stipa (Code Review)
Attention is currently required from: flichtenheld, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/789?usp=email ) Change subject: GHA: General update December 2024 .. Patch Set 2:

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/789?usp=email ) Change subject: GHA: General update December 2024 .. Patch Set 2: (1 co

[Openvpn-devel] [M] Change in openvpn[master]: GHA: General update December 2024

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. Hello plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/789?usp=email to look at the new patch set (#2). Change subject: GHA: General update December 2024 .

[Openvpn-devel] [L] Change in openvpn[master]: PUSH_UPDATE: Added remove_option() and do_update().

2024-12-27 Thread stipa (Code Review)
Attention is currently required from: flichtenheld, mrbff, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/809?usp=email ) Change subject: PUSH_UPDATE: Added remove_option() and do_update().

[Openvpn-devel] [PATCH v3] Allow DEFAULT in data-ciphers and report both expanded and user set option

2024-12-27 Thread Frank Lichtenheld
From: Arne Schwabe This adds support for parsing DEFAULT in data-ciphers, the idea is that people can modify the default without repeating the default ciphers. In the past we have seem that people will use data-ciphers BF-CBC or data-ciphers AES-128-CBC when getting the warning that the cipher i

[Openvpn-devel] [S] Change in openvpn[master]: t_server_null_default.rc: Add some tests with --data-ciphers

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. Hello plaisthos, I'd like you to do a code review. Please visit http://gerrit.openvpn.net/c/openvpn/+/847?usp=email to review the following change. Change subject: t_server_null_default.rc: Add some tests with --data-ciphers ...

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, ordex, plaisthos. its_Giaan has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/762?usp=email ) Change subject: override ai_family if 'local' numeric address was specified .

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread its_Giaan (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. Hello cron2, flichtenheld, ordex, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/762?usp=email to look at the new patch set (#9). Change subject: override ai

[Openvpn-devel] [XS] Change in openvpn[master]: Move cipher/data-ciphers warning to D_LOW (verb 4)

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/746?usp=email ) Change subject: Move cipher/data-ciphers warning to D_LOW (verb 4) .. Pa

[Openvpn-devel] [L] Change in openvpn[master]: Allow DEFAULT in data-ciphers and report both expanded and user set o...

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/828?usp=email ) Change subject: Allow DEFAULT in data-ciphers and report both expanded and user set option ..

[Openvpn-devel] [XS] Change in openvpn[master]: Ensure that Python3 is available

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/846?usp=email ) Change subject: Ensure that Python3 is available .. Ensure that Python3 is available Use the more standard cmake find_package to search fo

[Openvpn-devel] [XS] Change in openvpn[master]: Ensure that Python3 is available

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#3) to the change originally created by plaisthos. ( http://gerrit.openvpn.net/c/openvpn/+/846?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by stipa Change subject: Ensure that Python3 is available .

[Openvpn-devel] [PATCH applied] Re: Ensure that Python3 is available

2024-12-27 Thread Gert Doering
Whatever this python thingie is... but GHA tells me that it builds fine, and people that do care tell me the patch is +2'ed, so, here we go :-) Your patch has been applied to the master branch. commit e4c68b23e26efcfa301ae4aec4f4fc65384ab9eb Author: Arne Schwabe Date: Fri Dec 27 12:22:55 2024 +

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/762?usp=email ) Change subject: override ai_family if 'local' numeric address was specified

[Openvpn-devel] [M] Change in openvpn[master]: Add building/testing with msbuild and the clang compiler

2024-12-27 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/751?usp=email ) Change subject: Add building/testing with msbuild and the clang compiler .. Add building/testing with msbuild and the clang compiler The L

[Openvpn-devel] [M] Change in openvpn[master]: Add building/testing with msbuild and the clang compiler

2024-12-27 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#7) to the change originally created by plaisthos. ( http://gerrit.openvpn.net/c/openvpn/+/751?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by stipa Change subject: Add building/testing with msbuild and the clang compiler .

[Openvpn-devel] [PATCH applied] Re: Add building/testing with msbuild and the clang compiler

2024-12-27 Thread Gert Doering
Sanity tested on my GH account. Succeeds. Your patch has been applied to the master branch. commit c815217ab6f7f203f82e9d26771f4f461242bfd2 Author: Arne Schwabe Date: Fri Dec 27 12:22:07 2024 +0100 Add building/testing with msbuild and the clang compiler Signed-off-by: Arne Schwabe

[Openvpn-devel] [PATCH v2] Ensure that Python3 is available

2024-12-27 Thread Gert Doering
From: Arne Schwabe Use the more standard cmake find_package to search for Python3 and make it required. This also provides a better error message than "version.cmake" not found when python3 is missing. Change-Id: I350fd615ed8474d34392a057a5f8bded78173949 Signed-off-by: Arne Schwabe Acked-by: L

[Openvpn-devel] [PATCH v6] Add building/testing with msbuild and the clang compiler

2024-12-27 Thread Gert Doering
From: Arne Schwabe The LLVM/clang compiler warning and error message are easier too read than their MSVC cl counterparts. Also compiling/running tests on Windows with a different compiler has the benefit of a better coverage. This includes a few minor changes to allow clang-cl to compile the pro

[Openvpn-devel] [XS] Change in openvpn[master]: Ensure that Python3 is available

2024-12-27 Thread stipa (Code Review)
Attention is currently required from: flichtenheld, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/846?usp=email ) Change subject: Ensure that Python3 is available .. Patch Set 2:

[Openvpn-devel] [M] Change in openvpn[master]: Add building/testing with msbuild and the clang compiler

2024-12-27 Thread stipa (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/751?usp=email ) Change subject: Add building/testing with msbuild and the clang compiler ...

[Openvpn-devel] [PATCH v9] Change API of init_key_ctx to use struct key_parameters

2024-12-27 Thread Gert Doering
From: Arne Schwabe This introduces a new structure key_parameters. The reason is that the current struct serves both as an internal struct as well as an on-wire/in-file format. Separate these two different usages to allow extending the struct. Change-Id: I4a981c5a70717e2276d89bf83a06c7fdbe6712d7

[Openvpn-devel] [M] Change in openvpn[master]: Change API of init_key_ctx to use struct key_parameters

2024-12-27 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/801?usp=email ) Change subject: Change API of init_key_ctx to use struct key_parameters ..

[Openvpn-devel] [S] Change in openvpn[master]: override ai_family if 'local' numeric address was specified

2024-12-27 Thread its_Giaan (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, plaisthos. Hello cron2, flichtenheld, ordex, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/762?usp=email to look at the new patch set (#8). Change subject: override ai_family