[Openvpn-devel,v3,0/2] Stop failed cipher/digest lookups from polluting the OpenSSL error queue

Message ID 20260930132707.51452-1-drew@linuxkids.com
Headers
Series Stop failed cipher/digest lookups from polluting the OpenSSL error queue |

Message

Drew Blokzyl Sept. 30, 2026, 1:27 p.m. UTC
  Root-cause follow-up to the "CRL: cannot read CRL from file" report
(GitHub #1103, PR #1104, Gerrit change 1950 for v1 of patch 1).

Changes in v3, both from Arne's review on the PR:

Patch 1: md_get() gets the same "none" guard as cipher_get(). Note this
changes md_get("none") from a fatal "Message hash algorithm 'none' not
found" to a NULL return; no caller passes "none" today (md_kt_name(),
md_kt_size() and md_defined() check first), so behaviour is unchanged,
but a future caller would hit the NULL rather than the fatal. Say if
you would rather have an ASSERT there.

Patch 2: instead of clearing the queue silently before the CRL read
loop, report a non-empty queue at D_LOW with the queued errors, then
clear. crypto_msg() only drains the queue when the level is enabled, so
the explicit ERR_clear_error() after it is what empties the queue at
normal verbosity.

Changes in v2: patch 1 returns NULL for "none" before touching OpenSSL,
no error marks and no wolfSSL shim, so cipher_valid_reason() keeps the
OpenSSL reason for unknown names (Razvan's point on Gerrit 1950).

Validation on the aarch64 Ubuntu 26.04 server (OpenSSL 3.5.5, DCO) with
gdb watching the queue:

- v3, both patches: UDP, TCP, CHACHA20-POLY1305 and a plain client
  after it enter multi_create_instance() and backend_tls_ctx_reload_crl()
  with an empty queue; four CRL replacements give four clean reloads; a
  garbage CRL still fails with "loaded 0 CRLs" / "VERIFY ERROR: CRL not
  loaded".
- patch 2 alone on master, i.e. with the "none" polluter still live:
  the new D_LOW line fires with the stale "unsupported" entry printed
  above it, followed by "loaded 1 CRLs" and no false warning, on both
  a UDP and a TCP handshake after a CRL replacement.

Drew Blokzyl (2):
  Do not look up the "none" cipher or digest in OpenSSL
  Make CRL reload EOF detection independent of stale error queue entries

 src/openvpn/crypto_openssl.c | 17 +++++++++++++++++
 src/openvpn/ssl_openssl.c    | 19 +++++++++++++++++--
 2 files changed, 34 insertions(+), 2 deletions(-)