[Openvpn-devel] [PATCH] Adding AWS-LC to the OpenVPN CI

2025-01-29 Thread Shubham Mittal via Openvpn-devel
URL: https://github.com/OpenVPN/openvpn/pull/673 Acked-by: Arne Schwabe Signed-off-by: Shubham Mittal --- .github/workflows/build.yaml | 62 1 file changed, 62 insertions(+) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 90d52

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .. options: add IPv4 support to '--show-gateway ' This is an old debug opti

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
Hello flichtenheld, plaisthos, stipa, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/881?usp=email to look at the new patch set (#4). The following approvals got outdated and were removed: Code-Review+2 by stipa Change subject: options: add IPv4 sup

[Openvpn-devel] [PATCH applied] Re: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread Gert Doering
As the commit message states, there is not much meat behind this option yet - it's there to help testing the coming implementations. Lev tested this against his windows implementations, and we spent quite some time argueing host byte order, network byte order, and overall confusion on things memor

[Openvpn-devel] [XS] Change in openvpn[master]: Fix doxygen warnings in crypto_epoch.h

2025-01-29 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#2) to the change originally created by flichtenheld. ( http://gerrit.openvpn.net/c/openvpn/+/877?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by plaisthos Change subject: Fix doxygen warnings in crypto_epoch.h

[Openvpn-devel] [XS] Change in openvpn[master]: Fix doxygen warnings in crypto_epoch.h

2025-01-29 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/877?usp=email ) Change subject: Fix doxygen warnings in crypto_epoch.h .. Fix doxygen warnings in crypto_epoch.h Introduced by commit 92adbc88b1b37095cebd

[Openvpn-devel] [PATCH applied] Re: Fix doxygen warnings in crypto_epoch.h

2025-01-29 Thread Gert Doering
Well spotted ;-) Your patch has been applied to the master branch. commit b6a2533a3fb29eafe78a2432eaf9adaa0e707420 Author: Frank Lichtenheld Date: Wed Jan 29 19:28:18 2025 +0100 Fix doxygen warnings in crypto_epoch.h Signed-off-by: Frank Lichtenheld Acked-by: Arne Schwabe

[Openvpn-devel] [PATCH v1] Fix doxygen warnings in crypto_epoch.h

2025-01-29 Thread Gert Doering
From: Frank Lichtenheld Introduced by commit 92adbc88b1b37095cebde2a1c5b6ae242f382678. Change-Id: I0133085ac68f7b0db574b88276f6d5e1d3ad62d5 Signed-off-by: Frank Lichtenheld Acked-by: Arne Schwabe --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge

[Openvpn-devel] [XS] Change in openvpn[master]: Fix doxygen warnings in crypto_epoch.h

2025-01-29 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/877?usp=email ) Change subject: Fix doxygen warnings in crypto_epoch.h .. Patch Set 1: C

[Openvpn-devel] [M] Change in openvpn[master]: Extend the unit test for data channel packets with aead limit tests

2025-01-29 Thread MaxF (Code Review)
Attention is currently required from: flichtenheld, plaisthos. MaxF has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/868?usp=email ) Change subject: Extend the unit test for data channel packets with aead limit tests ...

[Openvpn-devel] [PATCH v3] options: add IPv4 support to '--show-gateway '

2025-01-29 Thread Gert Doering
This is an old debug option, which used to print "the default routes found" for IPv4 and IPv6, and optionally "a route to a particular IPv6 target" if passed an argument. With the work started in commit 0fcfc8381f60d we want this to handle IPv4 as well, mostly to be able to easily test per-platfor

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread stipa (Code Review)
Attention is currently required from: cron2, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .. Patch

[Openvpn-devel] [M] Change in openvpn[master]: route.c: improve get_default_gateway() logic on Windows

2025-01-29 Thread stipa (Code Review)
Attention is currently required from: flichtenheld, plaisthos. Hello flichtenheld, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/879?usp=email to look at the new patch set (#2). Change subject: route.c: improve get_default_gateway() logi

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: cron2, plaisthos, stipa. Hello flichtenheld, plaisthos, stipa, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/881?usp=email to look at the new patch set (#3). Change subject: options: add IPv4 support to '--show

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread flichtenheld (Code Review)
Attention is currently required from: cron2, plaisthos, stipa. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .

[Openvpn-devel] [XS] Change in openvpn[master]: man: extend --persist-tun section

2025-01-29 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/819?usp=email ) Change subject: man: extend --persist-tun section .. man: extend --persist-tun section The current persist-tun section has no mention of r

[Openvpn-devel] [XS] Change in openvpn[master]: man: extend --persist-tun section

2025-01-29 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#3) to the change originally created by ordex. ( http://gerrit.openvpn.net/c/openvpn/+/819?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by flichtenheld Change subject: man: extend --persist-tun section .

[Openvpn-devel] [PATCH applied] Re: man: extend --persist-tun section

2025-01-29 Thread Gert Doering
Documentation enhancements are always welcome :-) Your patch has been applied to the master branch. commit 519209da6902e107eec9d43aa2479635b64541cd Author: Antonio Quartulli Date: Wed Jan 29 10:41:25 2025 +0100 man: extend --persist-tun section Signed-off-by: Antonio Quartulli

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#7) to the change originally created by its_Giaan. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by cron2 Change subject: mroute/management: repair mgmt client-kill for mroute with

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: repair mgmt client-kill for mroute with proto .. mroute/management: repair mgmt client-kill for mroute w

[Openvpn-devel] [PATCH applied] Re: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread Gert Doering
This is somewhat of a cleanup-repair-broken-API patch, and it took us a few rounds to get this in a nice shape. commit dda93f304 adds a "proto" field to the mroute hashing & comparison to disambiguate udp and tcp connects, and that promptly broke the "kill $ip:$port" management command (not matc

[Openvpn-devel] [PATCH applied] Re: Add compatibility to build OpenVPN with AWS-LC.

2025-01-29 Thread Gert Doering
I have not tested this with AWS LC, just tested basic client side tests with OpenSSL (work). Arne is the master of "mostly compatible SSL libraries" so if he says this is fine, I'm happy to follow. Your patch has been applied to the master branch. commit aab1f862f42f300d4ee7fe9a971fd2ae474c53db

[Openvpn-devel] [PATCH v6] mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread Gert Doering
From: Gianmarco De Gregori Fix issue reported by Coverity: CID 1641564: Uninitialized variables (UNINIT) Using unitialized value "maddr.proto" when calling "mroute_addr_equal()". Due to changes at the mroute structure which now includes the protocol, the mgmt iface client-kill-by-addr feature ha

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: repair mgmt client-kill for mroute with proto

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, its_Giaan, ordex, plaisthos. Hello cron2, flichtenheld, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/880?usp=email to look at the new patch set (#6). The following approvals got

[Openvpn-devel] [L] Change in openvpn[master]: Add support for simultaneous use of UDP and TCP sockets

2025-01-29 Thread ordex (Code Review)
Attention is currently required from: cron2, its_Giaan, plaisthos. ordex has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/764?usp=email ) Change subject: Add support for simultaneous use of UDP and TCP sockets ...

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos, stipa. Hello flichtenheld, plaisthos, stipa, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/881?usp=email to look at the new patch set (#2). The following approvals got outdated an

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
cron2 has abandoned this change. ( http://gerrit.openvpn.net/c/openvpn/+/882?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .. Abandoned gerrit mishap, this is 881 v2 really -- To view, visit http:/

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, plaisthos. Hello plaisthos, flichtenheld, I'd like you to do a code review. Please visit http://gerrit.openvpn.net/c/openvpn/+/882?usp=email to review the following change. Change subject: options: add IPv4 support to '--show-gateway ' .

[Openvpn-devel] IRC community meeting summary

2025-01-29 Thread Johan Draaisma
Meeting summary for 29 January 2025: * *Updated: Release 2.7* /We want to get our release done before the next major Debian release./ /This means tentatively getting stuff for 2.7 done before March 1 or so, and release early April./ * *Updated: DCO Linux upstreaming* /Upstreaming D

[Openvpn-devel] [M] Change in openvpn[master]: Add lwip support to t_server_null

2025-01-29 Thread mattock (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos. mattock has removed a vote from this change. ( http://gerrit.openvpn.net/c/openvpn/+/811?usp=email ) Change subject: Add lwip support to t_server_null .. R

[Openvpn-devel] [M] Change in openvpn[master]: Add lwip support to t_server_null

2025-01-29 Thread mattock (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos. mattock has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/811?usp=email ) Change subject: Add lwip support to t_server_null .. Pat

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread stipa (Code Review)
Attention is currently required from: cron2, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .. Patch

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread flichtenheld (Code Review)
Attention is currently required from: cron2, plaisthos, stipa. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread flichtenheld (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' ..

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread stipa (Code Review)
Attention is currently required from: cron2, flichtenheld, plaisthos. stipa has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' .

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread flichtenheld (Code Review)
Attention is currently required from: cron2, plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/881?usp=email ) Change subject: options: add IPv4 support to '--show-gateway ' ..

Re: [Openvpn-devel] [PATCH] Adding AWS-LC to the OpenVPN CI

2025-01-29 Thread Arne Schwabe
Am 28.01.25 um 00:54 schrieb Shubham Mittal: URL: https://github.com/OpenVPN/openvpn/pull/673 Acked-by: Arne Schwabe Signed-off-by: Shubham Mittal --- .github/workflows/build.yaml | 61 1 file changed, 61 insertions(+) This looks fine but should we also

[Openvpn-devel] [PATCH v5] mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread Gert Doering
From: Gianmarco De Gregori Fix issue reported by Coverity: CID 1641564: Uninitialized variables (UNINIT) Using unitialized value "maddr.proto" when calling "mroute_addr_equal()". Due to changes at the mroute structure which now includes the protocol, the mgmt iface client-kill-by-addr feature ha

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: repair mgmt client-kill for mroute with proto

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: repair mgmt client-kill for mroute with proto

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, its_Giaan, ordex, plaisthos. Hello cron2, flichtenheld, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/880?usp=email to look at the new patch set (#5). The following approvals got

[Openvpn-devel] [S] Change in openvpn[master]: options: add IPv4 support to '--show-gateway '

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, plaisthos. Hello plaisthos, flichtenheld, I'd like you to do a code review. Please visit http://gerrit.openvpn.net/c/openvpn/+/881?usp=email to review the following change. Change subject: options: add IPv4 support to '--show-gateway ' .

Re: [Openvpn-devel] [PATCH] Add compatibility to build OpenVPN with AWS-LC.

2025-01-29 Thread Arne Schwabe
The changes are quite small and the change that  affects other crypto libraries is well documented Acked-By: Arne Schwabe Am 28.01.2025 um 23:09 schrieb Shubham Mittal: Additional context from PR on Github about changes in ssl_openssl.c around line 1900: This change addresses a subtle behavi

[Openvpn-devel] [PATCH v4] mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread Gert Doering
From: Gianmarco De Gregori Fix issue reported by Coverity: CID 1641564: Uninitialized variables (UNINIT) Using unitialized value "maddr.proto" when calling "mroute_addr_equal()". Fix this by passing the proto along with IP:port. While at it, changed the mroute_addr_print_ex() format to display

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: fix uninitialized variable (UNINIT) ..

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, its_Giaan, ordex, plaisthos. Hello cron2, flichtenheld, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/880?usp=email to look at the new patch set (#4). The following approvals got

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, ordex, plaisthos. its_Giaan has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: fix uninitialized variable (UNINIT) ..

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: fix uninitialized variable (UNINIT) ..

[Openvpn-devel] [PATCH applied] Re: route.c: change the signature of get_default_gateway()

2025-01-29 Thread Gert Doering
As discusssed on IRC, this is the first patch of a series to improve the IPv4 gateway lookup, aka, "make it as good as the IPv6 implementation". The problem today is that the IPv4 code only looks for "the default route", which is not the right answer for "which route and interface is used to reach

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, ordex, plaisthos. its_Giaan has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: fix uninitialized variable (UNINIT) ..

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread its_Giaan (Code Review)
Attention is currently required from: cron2, flichtenheld, its_Giaan, ordex, plaisthos. Hello cron2, flichtenheld, plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/880?usp=email to look at the new patch set (#3). The following approvals got

[Openvpn-devel] [S] Change in openvpn[master]: route.c: change the signature of get_default_gateway()

2025-01-29 Thread cron2 (Code Review)
cron2 has submitted this change. ( http://gerrit.openvpn.net/c/openvpn/+/878?usp=email ) Change subject: route.c: change the signature of get_default_gateway() .. route.c: change the signature of get_default_gateway() As a prep

[Openvpn-devel] [S] Change in openvpn[master]: route.c: change the signature of get_default_gateway()

2025-01-29 Thread cron2 (Code Review)
cron2 has uploaded a new patch set (#2) to the change originally created by stipa. ( http://gerrit.openvpn.net/c/openvpn/+/878?usp=email ) The following approvals got outdated and were removed: Code-Review+2 by cron2 Change subject: route.c: change the signature of get_default_gateway() ...

[Openvpn-devel] [PATCH v1] route.c: change the signature of get_default_gateway()

2025-01-29 Thread Gert Doering
From: Lev Stipakov As a preparation of an upcoming refactoring of get_default_gateway(), add `dest` parameter to specify destination address to which we are looking the best route. Change-Id: I58735fb24bc4a94c803b7dfcd6de87af0f75522a Signed-off-by: Lev Stipakov Acked-by: Gert Doering --- This

[Openvpn-devel] [PATCH v2] man: extend --persist-tun section

2025-01-29 Thread Gert Doering
From: Antonio Quartulli The current persist-tun section has no mention of retaining IP/routes and its potential usage in traffic leaking protection. Spell this out to allow the user to better understand when this option can play an important role. Change-Id: I6816f61b308ca9f6d1f9f687a6dc8e0aa2d

[Openvpn-devel] [M] Change in openvpn[master]: mroute/management: fix uninitialized variable (UNINIT)

2025-01-29 Thread cron2 (Code Review)
Attention is currently required from: flichtenheld, its_Giaan, ordex, plaisthos. cron2 has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/880?usp=email ) Change subject: mroute/management: fix uninitialized variable (UNINIT) ..