From patchwork Mon Aug 3 13:21:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5197 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp3641304mau; Mon, 3 Aug 2026 06:21:34 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpwO+7HuzwM4D47lq519PtloStxgzfAyquWqcgPucmrqRd40aeIwFZoFdn3OUdaeLfay+Jui+izwlM=@openvpn.net X-Received: by 2002:a05:6820:c2c5:10b0:6a3:a335:1ccd with SMTP id 006d021491bc7-6ae431d7aebmr9896976eaf.8.1785763294620; Mon, 03 Aug 2026 06:21:34 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785763294; cv=none; d=google.com; s=arc-20260327; b=TVH9c7Y1TWbVNzoUxeTPb1BgSX20/7TavTquKfwcoMIumPOt92PG0CJtwYrCCBKswX 0Mk2S+FHmvdC4hjDwXv9Yg4kwyuV6owt9BTkQKObsPEkQFixps4qF8JfX4nhgydYAraI EoPQ1osviHEN998WU9LICkDrflHTx0qQSDIM+MMOsimL2jYGx/owNfINp5cqQwkDIqpJ g9WsQsAlU9SrFWMcWvJFfCsYT1BBHlDhcHNoVc1IDo6G2VyMhh7FyO0U4OHhESDDTABH mUgNuNAT74BCuijlzNxfT+uq6Km3eTKrRfBWccrpQWLvyyO+UzmcjvTYA9WdVAh6mMkO vFhg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=XI6aj/JNozMSuPOjOSYfirZsVqNdN88lDN/XYBsgTg0=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=FLBBY3tEHBIp+iRJFmM/eJOKECvs6hdPUlM/YSfdCC/hFiuBAqLlS8SoBok7ftIklM cy0ohpf7PyW0Q7W70NTRLBqKW+54yYxIq87exzBwo7cVcRyoI4OO6miNvV4wrDKOd9he JeJehPzlxabufWD3fDHgtZovcgdU4CCkP+qJsMfZ3GOj1fza1qecOs8HmCPZ1MFpnFtA EdDAr/D3pyFqlxrH4DZIML+F9Hx0roxvp2sHk/lvtxP27fkk7KtnUHXBacfazwoxsvg8 5uYYR7U3SJPlspL9Y2dvliketSGehU1MtjBNd6ppWBZPmPR5hIm2fhL9YLLmitOzBfg9 E7kQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=biIAcKWi; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=cCMGH5Ly; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="Kc/QghGq"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-458f65b1039si9061663fac.149.2026.08.03.06.21.34 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 03 Aug 2026 06:21:34 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=biIAcKWi; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=cCMGH5Ly; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="Kc/QghGq"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=XI6aj/JNozMSuPOjOSYfirZsVqNdN88lDN/XYBsgTg0=; b=biIAcKWiKX9pBh9lKI5fL11XWS P3BpMj7cjtjL4UfhjNLSH4cLftCOmM5JDaS+nWHiNjOWJrypB5g0gJiu2LehaXFSW+qukddYXnEXv aazVt9Cj+0ARQ8xDknyUagC6De34svq1yP4qhe2vdp+ctvbWf0JI2O4cEYPK/wlEdbis=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wqsbg-0007Xn-DU; Mon, 03 Aug 2026 13:21:29 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wqsbe-0007Xg-78 for openvpn-devel@lists.sourceforge.net; Mon, 03 Aug 2026 13:21:26 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=2PO2TRbgkXg19UfpH4jQO2BLMzpSA9SzBMSIF+7WMMQ=; b=cCMGH5LyH0oWRsmrMvp7qe1yF9 tpu7CaO4eHJFDrjjCzx6YiBj6tghSkqJOnevZ2DvmOrheC4Z6NyaBqdYpKKNVSsKw0QiBwSIAaMig hcSn4MFBp23Tp6U6dFW57lFtqM1aRZ+/YwnjiM/gqXkqbgkt8rK8jm7EN10D7eKAfAUk=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=2PO2TRbgkXg19UfpH4jQO2BLMzpSA9SzBMSIF+7WMMQ=; b=Kc/QghGqxQ3/uZuiHoBufyhHyN 2HksNcUkzDFxIBytOnYcrOJyvF4SyXUD5dksFi+fFMIakof5ptw4HOzozleCuHodl0b4N8qvTmkzh ycZeVsFzOJ5Uz7BVrSyj5z6XQvXMr2cPtjCyxgpgddpZ0f1VPhZBMd6GQEZ6E0YLEX/Q=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wqsbg-0003IM-On for openvpn-devel@lists.sourceforge.net; Mon, 03 Aug 2026 13:21:26 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 673DLHZt006367 for ; Mon, 3 Aug 2026 15:21:17 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 673DLHP0006366 for openvpn-devel@lists.sourceforge.net; Mon, 3 Aug 2026 15:21:17 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Mon, 3 Aug 2026 15:21:12 +0200 Message-ID: <20260803132117.6353-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe prng_bytes is already ASSERT(rand_bytes(...)), so this change is just a little cleanup that makes a code a little bit nicer. Change-Id: If458a3362e03630ce699bd122e957169601657a5 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wqsbg-0003IM-On Subject: [Openvpn-devel] [PATCH v1] Replace ASSERT(rand_bytes(...)) with prng_bytes X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872508532038919316 X-GMAIL-MSGID: 1872508532038919316 From: Arne Schwabe prng_bytes is already ASSERT(rand_bytes(...)), so this change is just a little cleanup that makes a code a little bit nicer. Change-Id: If458a3362e03630ce699bd122e957169601657a5 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1833 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1833 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld diff --git a/src/openvpn/crypto.c b/src/openvpn/crypto.c index ee43d65..8f59838 100644 --- a/src/openvpn/crypto.c +++ b/src/openvpn/crypto.c @@ -1219,7 +1219,7 @@ ASSERT(cipher_ctx_iv_length(cipher) >= OPENVPN_AEAD_MIN_IV_LEN); /* Generate dummy implicit IV */ - ASSERT(rand_bytes(co->key_ctx_bi.encrypt.implicit_iv, OPENVPN_MAX_IV_LENGTH)); + prng_bytes(co->key_ctx_bi.encrypt.implicit_iv, OPENVPN_MAX_IV_LENGTH); memcpy(co->key_ctx_bi.decrypt.implicit_iv, co->key_ctx_bi.encrypt.implicit_iv, OPENVPN_MAX_IV_LENGTH); @@ -1239,7 +1239,7 @@ ASSERT(buf_init(&src, 0)); ASSERT(i <= src.capacity); src.len = i; - ASSERT(rand_bytes(BPTR(&src), BLEN(&src))); + prng_bytes(BPTR(&src), BLEN(&src)); /* copy source to input buf */ buf = work; diff --git a/src/openvpn/proxy.c b/src/openvpn/proxy.c index 9f3ec93..9acb2fa 100644 --- a/src/openvpn/proxy.c +++ b/src/openvpn/proxy.c @@ -734,7 +734,7 @@ } /* generate a client nonce */ - ASSERT(rand_bytes(cnonce_raw, sizeof(cnonce_raw))); + prng_bytes(cnonce_raw, sizeof(cnonce_raw)); cnonce = make_base64_string2(cnonce_raw, sizeof(cnonce_raw), &gc); diff --git a/tests/unit_tests/openvpn/test_ssl.c b/tests/unit_tests/openvpn/test_ssl.c index d473d67..b86d57c 100644 --- a/tests/unit_tests/openvpn/test_ssl.c +++ b/tests/unit_tests/openvpn/test_ssl.c @@ -322,7 +322,7 @@ ASSERT(buf_init(&src, 0)); ASSERT(i <= src.capacity); src.len = i; - ASSERT(rand_bytes(BPTR(&src), BLEN(&src))); + prng_bytes(BPTR(&src), BLEN(&src)); /* copy source to input buf */ buf = work; @@ -368,7 +368,7 @@ ASSERT(buf_init(&src, 0)); ASSERT(len <= src.capacity); src.len = len; - ASSERT(rand_bytes(BPTR(&src), BLEN(&src))); + prng_bytes(BPTR(&src), BLEN(&src)); /* copy source to input buf */ buf = work; @@ -453,10 +453,10 @@ } else { - ASSERT(rand_bytes(key2.keys[0].cipher, sizeof(key2.keys[0].cipher))); - ASSERT(rand_bytes(key2.keys[0].hmac, sizeof(key2.keys[0].hmac))); - ASSERT(rand_bytes(key2.keys[1].cipher, sizeof(key2.keys[1].cipher))); - ASSERT(rand_bytes(key2.keys[1].hmac, sizeof(key2.keys)[1].hmac)); + prng_bytes(key2.keys[0].cipher, sizeof(key2.keys[0].cipher)); + prng_bytes(key2.keys[0].hmac, sizeof(key2.keys[0].hmac)); + prng_bytes(key2.keys[1].cipher, sizeof(key2.keys[1].cipher)); + prng_bytes(key2.keys[1].hmac, sizeof(key2.keys)[1].hmac); } struct crypto_options co = { 0 };