From patchwork Tue Sep 22 14:05:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 47 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp13354804mag; Tue, 22 Sep 2026 07:35:55 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwaePC3alYlIvO8W/nYgPn8AiJ38s2VqU3v81wy2hZxVZv1lfmHWDqjd2+mOWWdbuhmwbEospybtt0=@openvpn.net X-Received: by 2002:a05:6820:4b90:b0:6b1:d09d:6d73 with SMTP id 006d021491bc7-6ca9a13380dmr13079434eaf.8.1790087755629; Tue, 22 Sep 2026 07:35:55 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790087755; cv=none; d=google.com; s=arc-20260327; b=fcQcaKS/D/CVQCyoaeWF9eoudCsQAXiSTY41KnITGOIIIcIykvr34HqNVc0e8ZuFUB VBFdtQUPtg2M2ce+/lmhMjAiwhNpLOEe/By4e6FD4s3Oc25PNcURr1O9HJjpow21oTZt GOoL6z6xFd6BF+N44JlYpJsYTmQd5Xk2OwWs/WB5PwB/EtzgqvGsPM+rVQUwdCdCI4NU nD4QtMzHIvOxGM+CXSSycQiSFApe1RnoatBmLrxrp+HEkJtum9zty6iVO5nlz36tW3St 5TN66sMWyiiO8p9norkBDuxdxxG8/GMtl5FAYd1n7hDSAqqWl2k8I6IM9D1ycy2gKKk6 PJXQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=hGcOPOVCM3tNKMvWZ16NCkn/u71RvA4jhZASXMPboMo=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=iMuphEa+bG1NdJcHCzl5U0Ocl+bw2MgBKB050I+OScJC1H6mROOX8J0SJi372ZCOZS 42nYqHmtulT+n4D5xjLZJsx2P8YVSrRz0C3SSDUAfdDAj7wNG32qFH+LYaxwk8GyUVCb x51caWvRHbfx6mwsnveVYhUkeYlP2qPkI4ZY4UBFpZcagn6X1J54Mttbun2UgJ6VOnQj lAtWtjEaowkRrQFqndqAH/WmLrd0DSvV8Vg74U6mMJe1JxsV+40O6BhqsX318I3ovNe8 Dv+hRLXEReiBiCrXjP9ktjNJH0Y4+oFFJhUcOiShFAnVvMrhZ1oXwnZfd9NS0j+rllNt EE0Q==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="bpa3/UCG"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=hDqO973h; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CP1dkycx; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=CAQMrtCv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-48fbfbe7194si1863395fac.279.2026.09.22.07.35.55 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Sep 2026 07:35:55 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="bpa3/UCG"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=hDqO973h; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=CP1dkycx; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=CAQMrtCv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Cc:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=hGcOPOVCM3tNKMvWZ16NCkn/u71RvA4jhZASXMPboMo=; b=bpa3/UCGd027juzh4NJ/fI7LEN ib7WhCZ+M9efCHet0C8x+vW7RZFTSN4UsEoWqPC7wJ0QgmCMEZweASDuILbtqWLmnWRiiTkw8i6wf T7jONvdjU5nsjZJSCUr3x0+ILQ/1wKhZY8KVWf7E0OeFxLSNjRXyZbK9xTFteDJh+Z1M=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x91b4-0003EW-69; Tue, 22 Sep 2026 14:35:50 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x91b3-0003EQ-1K for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:35:49 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=dB6hDmBP9l82kh/wQzVt5rVQ0/2bOHurqMSi6r2/P94=; b=hDqO973hIQfKBThIlEQweeQEcf Ygm8PAntAcI8FpTFbSzVauaRyaCJLnUTynvkS8Lmk3sQ1HB7AjPgItjGYG84XG5BalqxBULh5br/f rU8XOSR9IzFpZ6wo36TM0yD2AkhcEXoyiNvIBf2wXq7yiZxDzhfk+fYOdc8p1pjPAcwY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=dB6hDmBP9l82kh/wQzVt5rVQ0/2bOHurqMSi6r2/P94=; b=C P1dkycxvX1Q0U2cN4lf9OhJfm4G7qxTsdbduGDaQSfYz7xte5duxtyTYyRS9mXi4rT6oQx31waZtk KcK+H1Rshly3i7DTCPB6MOlC4Owc/yb2Y+CzgH2DVwcTSnaAUy25XNtkC8n1nRtpNlGx0YYr3mQ/4 dw0iwYW1ecIhWouI=; Received: from mail-qk2-f13.google.com ([74.125.230.205]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1x91b2-0005mW-2m for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:35:49 +0000 Received: by mail-qk2-f13.google.com with SMTP id d75a77b69052e-530e28a62abso10401751cf.1 for ; Tue, 22 Sep 2026 07:35:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790087742; x=1790692542; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=dB6hDmBP9l82kh/wQzVt5rVQ0/2bOHurqMSi6r2/P94=; b=CAQMrtCv71Zhfxk52zfHXkh03WZ+vKkcRKiAodcfQrbq9ldNnELcFjkiJHDmO+KrJC +w68GThuYiTj6CVHdnTjUU8MJwyTPR2p3MqtFgUB89nA+HNcbLpy+CkXkFcULl4Ipe+1 7gmV7qn2icX5GR9Ehnpm4CizxsCM7lCmetueSJqQ9NhPn6EM/VhpkecfMvb/O9ol7Pya zqR8Y3RjjP7RT5u3LGmSM/AC2LmlensOuQUnakCmpR9GSB9WzKX7AlKG3JD2TdT+cqYw mceqfdV/YlOxJ241OFe11kbEasb+IS15lN79MerISfT1ee4YkbbXJnEY9wcRBdfWuxin HJzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790087742; x=1790692542; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dB6hDmBP9l82kh/wQzVt5rVQ0/2bOHurqMSi6r2/P94=; b=eUUlNSoQAwydCJssnQA0E1b9pf2d3ODCdfBUIpvd8kngGnQIWkpD6YTEExKOFFnshB YVoXaxRjcWRkLv9DGApNxa/kfXvJRE6JH+zn0ynxolM19hjeh5fiv8slPCcZz+61Q8q/ gSmNzW+pfJ5alnDLCSOA442OQexFDqZhF9OiwjVhaspGJRdYKskrD+uvdUwjMdf4IlNy XOYKnnBQySu6BliGnHWVUJG9kNLPXgDlV0vayxz+u7fHAaUml3nvNjeXklawmteO7Dit njPkD2KFuPSkZ7YLsbRIJHKbiYkofFry/LO+di1flTlZSahAfxyuRdHRmvaRjxr1Kxd1 +eFA== X-Gm-Message-State: AFuF++mDVHF8JiE5hryYBDPhWlVJUfFJ6OqAuL8ilrsrBL7xJUrnqxL6 dbUOp2PfqTAVAeEmbrNHfZySoGfeScRkICLWIjWbOkkgW2n53D0eRaCX2mDxjKzGrZaewrDNELR 30v2PpR+R X-Gm-Gg: AYBFou2iW3dHA3SIXUQ6SSnT6EjxOnt03d51FDgiIXOUamHsrn5jZrOSf+n06JTYagd ZNiaHXniRjKXWltD1c9wo+WnJXfwdwV+kYjdYLSqXHelVGAJpnRBfGkPN/WN5rrkKteLZvwc6zH me6FxU81sdEGwiNdYYiLWCbPCJ267gLLi4iZjAGPJrXvOOsqy+HWnm6sSKKaTXebHiEFWkSq9kp A8xbTQCLHYfWkZ30sT0ikUz21qSrPBTa2hhAdQw4mXlL1DIFT9nX08D/QqmUPwulGlsixey698T SzpH+JcjfQzXbXIgg76MEVzN78KlWYHEx08XLNCODnGw1+kpppCNNORBH1fEuc84icDAg5C9HQs ZI5qN9ZXTGhW+e1utPPs9URHQTCMQo971iXr56UGJuvZBLOgws2u3LIfRN7gAkUfjF3eweL+Ko/ TukL6fa+mk6IsYyCAjJGa0XqyXiZKiqgIhbLzCWv9ZPv+aGlMCj5EeLx02vR6jhxe00IWeeyXIY evCyiwe/REUJOlWSILBQ/m3GoasqyQ2CqWT16SaAy8d5Ch3HGZFlsiQKsr3grE= X-Received: by 2002:a05:690e:4553:20b0:66e:5f04:f755 with SMTP id 956f58d0204a3-6717fcb2c71mr3095711d50.22.1790085923373; Tue, 22 Sep 2026 07:05:23 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-672d166300asm230404d50.3.2026.09.22.07.05.21 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 22 Sep 2026 07:05:22 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Tue, 22 Sep 2026 10:05:18 -0400 Message-ID: <20260922140520.71500-1-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: This is the root-cause follow-up to the "CRL: cannot read CRL from file" report (GitHub #1103, PR #1104, which Arne rightly called a symptom fix). Traced with gdb on OpenVPN 2.7.0 and master against OpenSSL 3.5.5: the entry that misleads the CRL reload is left by cipher_get() being asked for the cipher "none". That is the pre-negotiation key_typ [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.230.205 listed in wl.mailspike.net] X-Headers-End: 1x91b2-0005mW-2m Subject: [Openvpn-devel] [PATCH 0/2] Stop failed cipher/digest lookups from polluting the OpenSSL error queue X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877043058232214284 X-GMAIL-MSGID: 1877043058232214284 This is the root-cause follow-up to the "CRL: cannot read CRL from file" report (GitHub #1103, PR #1104, which Arne rightly called a symptom fix). Traced with gdb on OpenVPN 2.7.0 and master against OpenSSL 3.5.5: the entry that misleads the CRL reload is left by cipher_get() being asked for the cipher "none". That is the pre-negotiation key_type every server without --cipher gets (BF-CBC default, not in --data-ciphers), and every new client instance walks it in do_init_crypto_tls() and the frame/OCC calculations. cipher_kt_block_size()'s CBC-sibling probe and md_valid() have the same shape. Patch 1 makes those probing lookups leave the queue as they found it (ERR_set_mark/ERR_pop_to_mark, with a wolfSSL fallback in openssl_compat.h). Patch 2 is the earlier CRL-side change, kept as hardening: the EOF test now looks at the error PEM_read just raised rather than the oldest queued one, so no other leftover can produce the warning either. Validated on an aarch64 Ubuntu 26.04 server (DCO) with UDP, TCP and CHACHA20-POLY1305 clients: the queue is empty at multi_create_instance() and at backend_tls_ctx_reload_crl() entry, three CRL replacements give three clean reloads (unpatched: three warnings), and a garbage CRL still fails with "loaded 0 CRLs" / "VERIFY ERROR: CRL not loaded". Not compile-tested against wolfSSL; the shim is two static inlines. Drew Blokzyl (2): Drop the OpenSSL errors a failed cipher/digest lookup leaves behind Make CRL reload EOF detection independent of stale error queue entries src/openvpn/crypto_openssl.c | 16 +++++++++++++++- src/openvpn/openssl_compat.h | 18 ++++++++++++++++++ src/openvpn/ssl_openssl.c | 13 +++++++++++-- 3 files changed, 44 insertions(+), 3 deletions(-)