[Openvpn-devel,v1] Show version and double check we use the right TLS library in Github Actions
| Message ID | 20260311164053.21530-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:1e24:b0:83c:d90d:321 with SMTP id
ht36csp2741951mab;
Wed, 11 Mar 2026 09:41:07 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AJvYcCUE0aO2zAWj7mZz9mYZz1Xvyljq+ngQjd1GA+Zgz1LcqkfyLXWjruXjjj6UGjGfbP8nEVEA3HCUBuM=@openvpn.net
X-Received: by 2002:a05:600c:1f0e:b0:471:700:f281 with SMTP id
5b1f17b1804b1-4854b123bafmr57185935e9.25.1773247267650;
Wed, 11 Mar 2026 09:41:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1773247267; cv=none;
d=google.com; s=arc-20240605;
b=LI0v+N1mj5HA42WdDzSAs7z+S+FcVbNcJTvnOs+bmU2MxA2Q3xXe4IzLh92amSDPjc
9e1HLdydpIz3XK4cOhYpyEPNgNc9X4K//B6CE3injvSUgvwB4GRblc/VxfzBkx7s2t7F
wB4py34Notkw2mEtBK5pvgSj3arV5YQtM/ERfpc/q3ZtaCOxSRtXPH4oFPT5OjwXhfnl
9YlQmRPns7Z2W8yTkXp9276ObGCEe/Yzi8IMYDjCZeTp5g5aFgwHxpEnl7c7OHIxErf3
aZkdqrxNmK1zOdztJm3sR9OMyO/O/yterXcyMDL5jAVwSye1gtFi444SnoVkLOSeqYcH
eQ+g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=NYLx8ivRCluauV9PG+6RN/JGt9J97Mrj2G/Oa5QpULI=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=kE65VjaQWHKHws/sxlc+wercFlaWTucB7usrQKqhIIkPyk7EGa6s33wLsZk6sFkvHz
8DxJ8r/yGehKoATtFjyDpDkrAE1lJY4eyD22jlv2IEABQ3zGOO4RwiHcwRaoW3xvqP9J
QSzC4Q9cqiE+Y4gZxapOjVABDiS1bsFBaD9TR2We9AIUcBVldLB4CI3cTkJmlURH1i+9
lL5ls485BJUw2LFGZLZlHxXlSOfBnyiZE25JBeKF0v2J4yaxRGEovN3yglfHlbaRI5Ck
kJPWEzVPBzsnbrByk5YcFA2qW4Fw+lAFyxsq5DnHca97KkWiQRnJe0/UK3UsQBetB7du
4U+g==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=Fj906OEf;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=Swnpm6r+;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=kb2gYAvs;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
ffacd0b85a97d-439fe2239b1si320871f8f.152.2026.03.11.09.41.07
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 11 Mar 2026 09:41:07 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=Fj906OEf;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=Swnpm6r+;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=kb2gYAvs;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=NYLx8ivRCluauV9PG+6RN/JGt9J97Mrj2G/Oa5QpULI=; b=Fj906OEfVqm1ahkLtmkXmYMSdq
sLjDrOgv4NO4fmHd7wZsr+MxGaFm1MSvmIEaXXgCQr+1UBsgrAXWAzQvquDCQSRJh857hri3QhMA5
e6dDSpHt2Z26rF358HEGO2ikNn5YDXp6+vDzLhvQAVLxtXhmzr5b9waJRMz4gFQAIGTE=;
Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com)
by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1w0McJ-0005BX-UV;
Wed, 11 Mar 2026 16:41:03 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1w0McH-0005BO-Js
for openvpn-devel@lists.sourceforge.net;
Wed, 11 Mar 2026 16:41:01 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=8nHtd5niWeF77rOpfSrcL/fSRdQUhY3uDl7ATP4VXXc=; b=Swnpm6r+cyJ84Bg3CRjmNs0l/S
EIZadc9JLwBdjzK0GuWfwAvWv19wLTgw54J0uQOxhRBNMnguSn/VGtEt/l8xjRHcUO2Ze4iJTDClc
tF2GtOm98UkuT0X+fpioI8XiaDKVE7ChUZLZFUdjY3TGZDXgJ5L3YafxZzT2BN3I8d9k=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=8nHtd5niWeF77rOpfSrcL/fSRdQUhY3uDl7ATP4VXXc=; b=kb2gYAvslVYgLPIC2LAbR9kuse
76Yg2bgQ4tyOGc2FD6aPnHuRAdBdYuRn0EMQJ30ufRT4yX4hPrs+8qQinda1i3rnwtoe5tYzqC/5G
zHga8GSrHgXjzatGRzU4AADEBGsQj7B8ntNT4LsbrYqNEPHX9FqDu9V94yp7epKY9NeM=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1w0McG-0001Fx-Oh for openvpn-devel@lists.sourceforge.net;
Wed, 11 Mar 2026 16:41:01 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 62BGesef021549
for <openvpn-devel@lists.sourceforge.net>; Wed, 11 Mar 2026 17:40:54 +0100
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.1/8.18.1/Submit) id 62BGest5021548
for openvpn-devel@lists.sourceforge.net; Wed, 11 Mar 2026 17:40:54 +0100
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 11 Mar 2026 17:40:47 +0100
Message-ID: <20260311164053.21530-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.52.0
In-Reply-To:
<gerrit.1773243451000.Ia929c949cceaabe21a2937ad3217052aec4b2b4c@gerrit.openvpn.net>
References:
<gerrit.1773243451000.Ia929c949cceaabe21a2937ad3217052aec4b2b4c@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Arne Schwabe <arne@rfc2549.org> We recently discovered
that the AWS-LC builds in Github Actions were actually using OpenSSL. This
will now cause an error if something like this happens in the future again.
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1w0McG-0001Fx-Oh
Subject: [Openvpn-devel] [PATCH v1] Show version and double check we use the
right TLS library in Github Actions
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1859384526653428259?=
X-GMAIL-MSGID: =?utf-8?q?1859384526653428259?=
|
| Series |
[Openvpn-devel,v1] Show version and double check we use the right TLS library in Github Actions
|
|
Commit Message
Gert Doering
March 11, 2026, 4:40 p.m. UTC
From: Arne Schwabe <arne@rfc2549.org> We recently discovered that the AWS-LC builds in Github Actions were actually using OpenSSL. This will now cause an error if something like this happens in the future again. Change-Id: Ia929c949cceaabe21a2937ad3217052aec4b2b4c Signed-off-by: Arne Schwabe <arne-openvpn@rfc2549.org> Acked-by: Frank Lichtenheld <frank@lichtenheld.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1566 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1566 This mail reflects revision 1 of this Change. Signed-off-by line for the author was added as per our policy. Acked-by according to Gerrit (reflected above): Frank Lichtenheld <frank@lichtenheld.com>
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 2e9b62a..4207606 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -363,6 +363,10 @@ run: ./configure --with-crypto-library=openssl ${{matrix.configureflags}} --enable-werror - name: make all run: make -j3 + - name: Ensure the build uses LibreSSL + run: | + ./src/openvpn/openvpn --version + ./src/openvpn/openvpn --version | grep -q "library versions: LibreSSL" - name: configure checks run: echo 'RUN_SUDO="sudo -E"' >tests/t_server_null.rc - name: make check @@ -497,6 +501,10 @@ ./configure --with-crypto-library=openssl - name: make all run: make -j3 + - name: Ensure the build uses AWS-LC + run: | + ./src/openvpn/openvpn --version + ./src/openvpn/openvpn --version | grep -q "library versions: AWS-LC" - name: configure checks run: echo 'RUN_SUDO="sudo -E"' >tests/t_server_null.rc - name: make check