[Openvpn-devel,v3,0/2] Stop failed cipher/digest lookups from polluting the OpenSSL error queue
| Message ID | 20260930132707.51452-1-drew@linuxkids.com |
|---|---|
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:6ac1:b0:8b3:6e77:b38b with SMTP id v1csp683767maw;
Wed, 30 Sep 2026 06:33:32 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AKwUvBxUIF1kjlxkd0XkAtA2FShQxvqucE7REbxkvPtmbRz/lsnRmrnos3wWiigU614kyV54UC2Gn36qfKY=@openvpn.net
X-Received: by 2002:a05:6830:6289:b0:804:ec69:3979 with SMTP id
46e09a7af769-8204b5c0229mr1444763a34.21.1790775211823;
Wed, 30 Sep 2026 06:33:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790775211; cv=none;
d=google.com; s=arc-20260327;
b=MZGWmF5uiushPmLZAJvXME6wFEy39vG8Al/KRRQmXgcYMsgjiturFd7w6RKB4qUjw5
+yIaGo9+17vVuZNz1Q6mtu/iGu3sAHgY4sWBya9QCsTclC/vYMQWuO8CkBzck7kOKI7p
mRJbWuNrLGGbE+5EgcpA9pWduP34NMt4Xvxu/UjQMqWQV5yi5aAytcJ882sGrdzmQmhU
4Pa6rast1MrMD6IQHTCRonK7vq4OkhsyXxO/fyiLhSbZ08h+apizIuGAzAlzRW2fBVfn
U7ev5bOdjyjBcrmpW33Iun6kVrPs1R4QWdBI2bF+LhXcuBerny10UHlbOQyjXBZay9gp
ckkw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=2tj5r+SxxhGc/s/sRwMzaN+uFT1rH+ZUoMdYPXXIvrE=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=p/l4+VwqZuFs/lmACe/BE4DqDA5YtvbV4/t1KsTtkxVnjQPE66adgyz6/rlshLH7c2
M+/Rh1WuWccduL9tYz8Qy2ZpVJJ1A6csbmfDxRjPE8gh/PWHzvvIRU0joY34lvSGKJAi
d7kCpMIy8SAcvFjKhbwBgBOmcQxdJAtRD9akQ823WiYjqD+ly/1elOLjPXXgDees1gwK
yBICNQ4HYZzUbBTwsj15VbasvbSEciPfbpGcUMD+BTdsrzt2OzbjjLcRR4KIwrSboxfc
O4zHX82UYZM+0kHNeTuW+x/Ut1UyO1lrGELRR8nixt0Qc0hmxx3HCMUUGjmjTlvSKtr2
BK9g==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=ZqUENr+K;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=VzkhPO8t;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=E7ujyN3b;
dkim=neutral (body hash did not verify)
header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104
header.b=WX1W24+8;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dara=neutral header.i=@openvpn.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-82063be359fsi2130708a34.49.2026.09.30.06.33.31
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 30 Sep 2026 06:33:31 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=ZqUENr+K;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=VzkhPO8t;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=E7ujyN3b;
dkim=neutral (body hash did not verify)
header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104
header.b=WX1W24+8;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dara=neutral header.i=@openvpn.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=2tj5r+SxxhGc/s/sRwMzaN+uFT1rH+ZUoMdYPXXIvrE=; b=ZqUENr+KnS4dI2z+HtvcH7aZhc
EfaZBeftIQSCtUxe78VfxfHMl3UcgU8QYwPqJarzYFKUwZKepaE6Jy+VURryFvyHOmFTbEjUn9i+B
+q1lUHLahT7tmQt4HQ1a8uxPCvje2cBI97sllQJRnOscBy6+iShOstHac3BEwSso2Zqw=;
Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com)
by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1xBuR6-00028M-72;
Wed, 30 Sep 2026 13:33:28 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <drew@linuxkids.com>) id 1xBuR4-00028F-Kb
for openvpn-devel@lists.sourceforge.net;
Wed, 30 Sep 2026 13:33:27 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=evh1pR5G38EdV/dDo1EytuMs32JZynyib+71Qvcipqc=; b=VzkhPO8t/zrFb/8HjPrdUTQJgS
UdQVbNesKgSeMACRRxz/OBssCDXYXiIs8HefrLw9p+GAOfaLAHPLq5zpvrlUZBYUeYsV7BBxlS9Wo
Ft14geH7JYPII8ZZJkUtLrQsm/V0MyCb8Ob7DkSOW6OSB5xFe152YGuUkVGq9M2zHNcw=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=evh1pR5G38EdV/dDo1EytuMs32JZynyib+71Qvcipqc=; b=E7ujyN3bi2kDkgXYJoR7Ac/ltT
X3luEozXHkmuoQA4YiarPQo6z2ajIurdIQD/x4mRqTdUr129B6o3e1tcSvWuKuv3HkJftY9BjUIC0
NYGs58OgD8iVQBskNTbPd1yMvu6hZQ7NbB5r0AQ2cmnw5KkCtpHI6brOIzbFcVUKxMB8=;
Received: from mail-vs2-f36.google.com ([74.125.227.36])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95)
id 1xBuR4-0005Gf-Oi for openvpn-devel@lists.sourceforge.net;
Wed, 30 Sep 2026 13:33:27 +0000
Received: by mail-vs2-f36.google.com with SMTP id
71dfb90a1353d-5d4ea61c057so841876e0c.0
for <openvpn-devel@lists.sourceforge.net>;
Wed, 30 Sep 2026 06:33:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790775201;
x=1791380001;
darn=lists.sourceforge.net;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:from:to:cc:subject:date
:message-id:reply-to:content-type;
bh=evh1pR5G38EdV/dDo1EytuMs32JZynyib+71Qvcipqc=;
b=WX1W24+84x7eK4HzcgHd9+gt/9hWJa1g4ix5jy+aji+sT+zXhsbBgsrzfgJ2eEdgEu
aJn987ZR58YYiMq+b1tQNcZbY28qWFBHQRy/Kj6wFKySxwjWQrzCo1vjEH0FTDzvs0C9
khJ82RaEJSEJvSVicKjyERCnujdjzwufHr/stCharUM4A6FbWVBsXpd83qTzun8pJw9y
0GZ35DbWpoH3GBB1HQDyhRFM4ZUBY2JIZBDxZNDBMO//IoIxH9XAO4S6II9MkFE697P7
Yti2NTH7CuSrjImKwgyq8jfA7KS+VorihKIFmylJqm1Cu4hkKnu5I4giGXx0RbV4lO5f
VuyA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20260707; t=1790775201; x=1791380001;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from
:to:cc:subject:date:message-id:reply-to:content-type;
bh=evh1pR5G38EdV/dDo1EytuMs32JZynyib+71Qvcipqc=;
b=oQUhkaYZcUbuXWBq0JH3QRqnpJXoQuRTC4HS3MR9+42pQuKIciCm1j45AvW6Tb/HCK
8tYYoXmQexlzIUcAxOUcj4HkFYaSsuwrx1ckcZJJV0Tuz0LFnQdNQlGX/f8gcHS/+yTG
341IVOV+Mft8kAV7jooy62fnJvvzofWXIrVwc/7YHCr/pL3UUv89VkI6it3ki+GcVRAb
9pKfTJQr8qE+SPqqnrDWBAu8QhcWF708TRBnOLK/wCQh0NCdi5rojk6hEEv0L1/EYyqF
UF4R8deau+f6YU5jjQlE1Ae7RmGvcQNuUJt/A/BQDoojL/mkIyYo/E2zHotl6TLxinXd
ehIA==
X-Gm-Message-State: AFq9FYLGmguLZlxCH2T44D6JQV2pjfAiULnzXIhUHaN3CnqvfAXTHXa4
FcVBi6Z4DOMjMGlxMGjFgGsd5XNIwwWo3bXtxiLerK8H57hkKbNum2OotQR3jaO2OGA9KJNAy/x
qsn4cyg==
X-Gm-Gg: AYBFou2QvEODiLB2u7j7HEiip3bDoTxw6gMSZgFHSLSUN2U52WPZxx83YXbxKaXQYt4
csr/zPXWm4ZgRSOoQFldr+5lX1pedRYkbg2SJeLx50/bTMbIqBFev/LOiKCJo8Trjqd6brOyFLx
oh+xzXsTfs7oS/TVJdxFgYzcy7EWhA8acXykbzr7Yehh+U5STL75ffGdwwrFU3tbKFyzvYUtCxn
YgoZcUtVhvhozDoQKRILhp8kNvEv6tsJ+HaZEMKunL68wftVdHDZ4vdKUectM2qFrkNdb+NQ6IG
dJfx8fA4QaS4Ian0tny0P7XbK00kGA/0EWby9ZrYOkWdi0iKs7Eqimu6POtF38VevGJ3APrjFFo
2rj+VZGk5Y8R6pkjbfzwqoRZunAqpoN8HjlbJ/ij3QpyWzJBs2AryD27TBFl7bVoPsflhxRZqNH
vIlaFrDO6hPM5bZkbKwjCRBnQq1UdzxqxFAmOfdVnjdc1lrbFTmmkx8qV2jGan/stNJWB0GLmlL
oackWP/tR306dlCzgOJmb0rYKMS0G/Gm3ZTsFAX6XuXDqsFw9B8EhXM5VbMwj4=
X-Received: by 2002:a05:690e:4885:10b0:673:4a02:a126 with SMTP id
956f58d0204a3-676834802c4mr521959d50.33.1790774830078;
Wed, 30 Sep 2026 06:27:10 -0700 (PDT)
Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net.
[71.208.239.209]) by smtp.gmail.com with ESMTPSA id
956f58d0204a3-67680ac3521sm704189d50.1.2026.09.30.06.27.08
(version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256);
Wed, 30 Sep 2026 06:27:08 -0700 (PDT)
From: Drew Blokzyl <drew@linuxkids.com>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 30 Sep 2026 09:27:05 -0400
Message-ID: <20260930132707.51452-1-drew@linuxkids.com>
X-Mailer: git-send-email 2.54.0
In-Reply-To: <20260922140520.71500-1-drew@linuxkids.com>
References: <20260922140520.71500-1-drew@linuxkids.com>
MIME-Version: 1.0
X-Spam-Score: 0.0 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-2.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Root-cause follow-up to the "CRL: cannot read CRL from file"
report (GitHub #1103, PR #1104,
Gerrit change 1950 for v1 of patch 1). Changes
in v3, both from Arne's review on the PR: Patch 1: md_get() gets the same
"none" guard as cipher_get(). Note this changes md_get("none") from a fatal
"Message hash algorithm 'none' not found" to a NULL return; no caller passes
"none" today (m [...]
Content analysis details: (0.0 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[74.125.227.36 listed in wl.mailspike.net]
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
X-Headers-End: 1xBuR4-0005Gf-Oi
Subject: [Openvpn-devel] [PATCH v3 0/2] Stop failed cipher/digest lookups
from polluting the OpenSSL error queue
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1877043058232214284
X-GMAIL-MSGID: 1877763908390493070
|
| Series |
Stop failed cipher/digest lookups from polluting the OpenSSL error queue
|
|
Message
Drew Blokzyl
Sept. 30, 2026, 1:27 p.m. UTC
Root-cause follow-up to the "CRL: cannot read CRL from file" report
(GitHub #1103, PR #1104, Gerrit change 1950 for v1 of patch 1).
Changes in v3, both from Arne's review on the PR:
Patch 1: md_get() gets the same "none" guard as cipher_get(). Note this
changes md_get("none") from a fatal "Message hash algorithm 'none' not
found" to a NULL return; no caller passes "none" today (md_kt_name(),
md_kt_size() and md_defined() check first), so behaviour is unchanged,
but a future caller would hit the NULL rather than the fatal. Say if
you would rather have an ASSERT there.
Patch 2: instead of clearing the queue silently before the CRL read
loop, report a non-empty queue at D_LOW with the queued errors, then
clear. crypto_msg() only drains the queue when the level is enabled, so
the explicit ERR_clear_error() after it is what empties the queue at
normal verbosity.
Changes in v2: patch 1 returns NULL for "none" before touching OpenSSL,
no error marks and no wolfSSL shim, so cipher_valid_reason() keeps the
OpenSSL reason for unknown names (Razvan's point on Gerrit 1950).
Validation on the aarch64 Ubuntu 26.04 server (OpenSSL 3.5.5, DCO) with
gdb watching the queue:
- v3, both patches: UDP, TCP, CHACHA20-POLY1305 and a plain client
after it enter multi_create_instance() and backend_tls_ctx_reload_crl()
with an empty queue; four CRL replacements give four clean reloads; a
garbage CRL still fails with "loaded 0 CRLs" / "VERIFY ERROR: CRL not
loaded".
- patch 2 alone on master, i.e. with the "none" polluter still live:
the new D_LOW line fires with the stale "unsupported" entry printed
above it, followed by "loaded 1 CRLs" and no false warning, on both
a UDP and a TCP handshake after a CRL replacement.
Drew Blokzyl (2):
Do not look up the "none" cipher or digest in OpenSSL
Make CRL reload EOF detection independent of stale error queue entries
src/openvpn/crypto_openssl.c | 17 +++++++++++++++++
src/openvpn/ssl_openssl.c | 19 +++++++++++++++++--
2 files changed, 34 insertions(+), 2 deletions(-)