From patchwork Thu Aug 13 16:32:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5229 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5508:b0:87d:ab56:3700 with SMTP id e8csp1101023mah; Thu, 13 Aug 2026 09:33:24 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RrOwGwRGh8VcbiwGLcbQIAU0IIjLuP3hu6R/73gTFPlZFGEZf9jCpQhiKaelCDeOYOSir1byHVvZac=@openvpn.net X-Received: by 2002:a05:6808:a589:10b0:4b2:3e72:bab1 with SMTP id 5614622812f47-4b23e72bfd2mr159933b6e.6.1786638803996; Thu, 13 Aug 2026 09:33:23 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1786638803; cv=none; d=google.com; s=arc-20260327; b=HCLte8CEf3Hwi7MsJpz6DQWPK8heLWlabHF4ZY6bF59iLVYTunkvjkZhndy80qG3Nf qh4xtOYh/GLZQAm/83uidjJoGbWq5bnSuFSwq7jfp5WLmU0JE81Gdz83VHtT4Nb8fncA iKK1cl/WBNPJlVnUWZMkSu2xpWJLH1FZUZkYBYhkOtbvClOkcJ8f3my8Ln2vkILxrEpb biR9Iz5KDoRU1sr1iBxJ2c9VO5ISXFaoGM2zo4S6FlhM+SM1M1JR8ODrPZwPKjl/eS1O tlSJU5WW6vr72BgPyVZMErQ9DQKsLTn8/cn5xtWFNu8tE93j135iuIzdCu4segPyeM1f W5Jw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=vxnO9Kt1UKMHJ9ODVFvcTIZaFzPSJ47VHbxUShRwQiw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=a8BPC7Z36gxDFXa1lfP+bq6U6fZpfJqCfduxzotic5GgyguTzUZ5+NoUlA3a1E8q9F rxP7ODi8oOWTRKxTC6/Pgb5rx00ajRIyPVlVABrI16u/48AtS28EFu5HgrYss1cLQsEx nrQa4eq0SQDRrLAJifnuq4brCJdPY8nHD8NchD2wL+A677Cbk/AGv4PGRi/l7hDYJVkl pgRPMZErIp5/2fSjktPhVKhzH1IK45COplnX7IZiZuOSDPGCWGj2lowtLFV6atmSQDl1 bynv7dpJwZVRqIZrCC0dGjv9jZ3XxhjiIJpO3SdITbzM3myE8hMlrGzA6KegmecXdpJ5 JbVQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=kvcsRweQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=NUKW0Izh; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="KlouPXJ/"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4b22cca61b6si4612597b6e.13.2026.08.13.09.33.23 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 13 Aug 2026 09:33:23 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=kvcsRweQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=NUKW0Izh; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="KlouPXJ/"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=vxnO9Kt1UKMHJ9ODVFvcTIZaFzPSJ47VHbxUShRwQiw=; b=kvcsRweQezSM5+d6dc9rD5HOGo uBpmTp1eGrOkcC2mvlZFpUvQE31DVngX9/+4xM5atFvczb2/H9RFL19KR8Po9R2mAfmn9egYb2Udi DhwOWaexpaHmIdh4Jq1HTAt5lSlKf5Kt4XlN+SONNWMVcwAAXeXYMRp7vRI9iHNQFChQ=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wuYMp-0003FL-Qg; Thu, 13 Aug 2026 16:33:19 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wuYMT-0003Eg-KG for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 16:32:57 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=CB76UEGzndmMt+4F9gxhueQ2km3tsKsgx/MNWOKZEDM=; b=NUKW0IzhVVOQ266awxFZXKckNI B7/JL01SgdbGJ6AtR1kG6vz5AJhpMvK72XPt/6CmjHW4XcwH1OpXncIAbPWkOQXSyx2vEpTQSi9Q3 /Q7IaZjMG4CPF0CUFpV5+YkpKqMQ15hvEbtnSlrT8mwTPSrQYVt3XtiIPcJHxDcBse2E=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=CB76UEGzndmMt+4F9gxhueQ2km3tsKsgx/MNWOKZEDM=; b=KlouPXJ/UcFTJArgbtjoSgLgcO Wv1XED/4vEYOwEDSc1oo0jzotJ58qn1r8oxz5r/jzwWAsvnRY0/PeNDQEcbjdjhGLQKl6jrD5LL+T 0Manav1peTyAiLz4Zd5bvpbBg4nV0q8a0wJgUW0U06GmW9vBXyyaSpgOio+pXFLknBdo=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wuYMI-0004Cw-Oe for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 16:32:48 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67DGWd5u026579 for ; Thu, 13 Aug 2026 18:32:39 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67DGWdFD026578 for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 18:32:39 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Thu, 13 Aug 2026 18:32:33 +0200 Message-ID: <20260813163239.26557-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Gleb Pesin OpenSSL 3.0.3 and newer can reinitialize an EVP_MAC HMAC context with its existing key when EVP_MAC_init is called without parameters. Use that path instead of supplying the digest and key again on ev [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wuYMI-0004Cw-Oe Subject: [Openvpn-devel] [PATCH v1] OpenSSL: avoid resetting the HMAC key on every packet X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1873426570668414451 X-GMAIL-MSGID: 1873426570668414451 From: Gleb Pesin OpenSSL 3.0.3 and newer can reinitialize an EVP_MAC HMAC context with its existing key when EVP_MAC_init is called without parameters. Use that path instead of supplying the digest and key again on every OpenVPN HMAC reset. Retain the old parameter-based reset for OpenSSL 3.0.0 through 3.0.2, where parameterless EVP_MAC reinitialization did not reset the underlying HMAC implementation. Change-Id: I1913a6e64b7ce22b66d2034df2a2fac33f60ea9f Signed-off-by: Arne Schwabe Acked-by: Arne Schwabe Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1840 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1840 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Arne Schwabe Razvan Cojocaru diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 1191f20..2019280 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -1209,7 +1209,7 @@ HMAC_Final(ctx, dst, &in_hmac_len); } -#else /* if OPENSSL_VERSION_NUMBER < 0x30000000L */ +#else /* if OPENSSL_VERSION_NUMBER < 0x30000000L */ hmac_ctx_t * hmac_ctx_new(void) { @@ -1275,10 +1275,14 @@ void hmac_ctx_reset(hmac_ctx_t *ctx) { - /* The OpenSSL MAC API lacks a reset method and passing NULL as params - * does not reset it either, so use the params array to reinitialise it the - * same way as before */ - if (!EVP_MAC_init(ctx->ctx, NULL, 0, ctx->params)) + /* OpenSSL 3.0.3 fixed EVP_MAC reinitialization with an existing key. + * Older versions need the parameters, including the key, to reset. */ +#if OPENSSL_VERSION_NUMBER >= 0x30000030L + const OSSL_PARAM *params = NULL; +#else + const OSSL_PARAM *params = ctx->params; +#endif + if (!EVP_MAC_init(ctx->ctx, NULL, 0, params)) { crypto_msg(M_FATAL, "EVP_MAC_init failed"); }