From patchwork Fri Aug 14 10:28:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5236 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5508:b0:87d:ab56:3700 with SMTP id e8csp2003213mah; Fri, 14 Aug 2026 03:30:39 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqnIHp/KDwJ7LRkUedakzccTNKckYbSCrwxdzININkmBXbG4whPcSO6gsIJF7B/TLtNMsFSVJpF3MI=@openvpn.net X-Received: by 2002:a05:6820:f021:b0:6b0:3b29:2301 with SMTP id 006d021491bc7-6b0d5dc9c2fmr3482973eaf.0.1786703438982; Fri, 14 Aug 2026 03:30:38 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1786703438; cv=none; d=google.com; s=arc-20260327; b=ZSXBIHMr/kdaB+RnghMgyh3afHfDGpuzCCThxNRSxTO1Z+8ZWPf9XKHuFy+osqhlNf CIhNY0Tikf+mcasBvCA3dyc8vzXUBOKvm8s+X8cT2paYRQZ/sxTqXrFRcxMNLewHVdT8 5SnBNb0eSLiHyw8R4Vj7NlGajle0wf+wUWBLiIkRGxMw5JO7XgTw2y6dlaGQ4HSvu6Tx s/yXRLFu0IEchm4WLDuZopCCpKTVwmwVrhcGRsV+5MkdHvmtNfJUODVXOlSTAg/uohNR rwNmP9fJKr6plWvJcgaq1AGH4/vipPyGhOUPKgfJem4N27Skn12yYdCAqrt5nuXXj8Uk 8GwA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=FkbvIc+g9o2o2d5Ng5f/tMP94LaKuwciQCZPDM/IDz4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=eILXr78L3yeRqwIS4G1X3egiqw3dEx88J1QGYlCNy7z+h1oBQKt0VUyG4bPRQ/HwiH 4mFug4DAP2FpeDdMgoPXuq6ih7jmegND8onRoDQ+/tXZuq37jmydW4+3ycgmndjKBLHS 3ynkL6pkWzGSwTYmyLMDR43rPhMDszM6+KML4uu5K4Onu/t2D/rwWKPOQcZeRGwfQyoN XF/741oFjSdt/07wC8Q78hBKhRJubsBg9r27OGHlbioFMjxny1V+nAIzPJLWQZJfiC3q RkdbMoWOPVvkgWPgSmkZII7xZQhj0qTfPXRoQO3LzM479iylo5aIAZ7nNozx83XOImZu xI4Q==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=FY44xAak; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=djkeVrCF; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=nPSVojlH; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6b0d920359fsi1925065eaf.34.2026.08.14.03.30.38 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 14 Aug 2026 03:30:38 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=FY44xAak; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=djkeVrCF; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=nPSVojlH; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=FkbvIc+g9o2o2d5Ng5f/tMP94LaKuwciQCZPDM/IDz4=; b=FY44xAakVpaL007Hp+2o9rFeF8 SARUkr4ZTf5InsznUsJEJSK9o7new62/xatH+9VUl1jv0LJzKJpDS4vW9dbZ80duOFc23E2f+dIsh 3qvku5KdSfqlxQ6wcRUuAQQ38KPYu3wDUa3UhmWVZYxi0G3h4jCHfY2pY3CweznuUqR0=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wupBN-0000Lm-M0; Fri, 14 Aug 2026 10:30:35 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wupBM-0000Lf-Fl for openvpn-devel@lists.sourceforge.net; Fri, 14 Aug 2026 10:30:34 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=2I7ZtaI5tr+3zCSTUj58JqseT81ZC7QnnVF3fPe0WyA=; b=djkeVrCFKqOtv/bbSXkro9FL2t jGIgoUo3EkTnyl23JF2EHPy0PHa/2Aoa16xMuo1Fxemr7dKZ3nU4H6N5HW0b33BSOBU/pI/1dkKqc MH4v2VJPyj3+VX6TZfSFm7eiiC9SsaPVwySvbxXKiV5pVENOyeR2oIFvWEnJNFWKckuU=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=2I7ZtaI5tr+3zCSTUj58JqseT81ZC7QnnVF3fPe0WyA=; b=nPSVojlHlPNWD5j2BfNSz9GxnD ybIHWGVRl7Q5/p9Vu/VijJqPt6esU0ZsR/OLOrBbhZ3MWASIcrwCvjEGGYhRTM38fPgxrp77JlSXj uLCBnrOiL8qfq/781dr2tZKX0qVJmZJWq23tnqHBqFC+ey49s8W0s2ceKTzXgr3heVcg=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wupBL-0002vP-Jr for openvpn-devel@lists.sourceforge.net; Fri, 14 Aug 2026 10:30:33 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67EAUO9F028500 for ; Fri, 14 Aug 2026 12:30:24 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67EAUOLw028499 for openvpn-devel@lists.sourceforge.net; Fri, 14 Aug 2026 12:30:24 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 14 Aug 2026 12:28:25 +0200 Message-ID: <20260814103024.28342-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Frank Lichtenheld This is intended to document in one place all the policies applicable to submitted changes. This serves multiple purposes: * Make it clearer to submitters what is required of them * Make it clearer what to consider automating when developing (be it by writing scripts or by instructing an AI agent) * Reduce the bus factor [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wupBL-0002vP-Jr Subject: [Openvpn-devel] [PATCH v1] Start a new document CODE_CHECKLIST X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1873494345165385537 X-GMAIL-MSGID: 1873494345165385537 From: Frank Lichtenheld This is intended to document in one place all the policies applicable to submitted changes. This serves multiple purposes: * Make it clearer to submitters what is required of them * Make it clearer what to consider automating when developing (be it by writing scripts or by instructing an AI agent) * Reduce the bus factor of the project by reducing the amount of things only stored in Gert's head Change-Id: Ib123b7bf58317a1be5af1a1d45decb8f31f2ec68 Signed-off-by: Frank Lichtenheld Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1776 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1776 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/CODE_CHECKLIST.md b/CODE_CHECKLIST.md new file mode 100644 index 0000000..3c61ee3 --- /dev/null +++ b/CODE_CHECKLIST.md @@ -0,0 +1,112 @@ +# Checklist for Contributions + +## Introduction + +This documents all policies applied to any change that should be applied +in this repository. It is separated in two parts. The first part describes +the parts of the checklist that any submitter should check. The seconds part +describes the parts that integrators need to check before actually merging the +change. + +In general the Integrator Checklist does imply that all checks from the +Submitter Checklist have been passed. They are not repeated. + +## Submitter Checklist + +### Commit message + +* Does the commit message acurately describe the change? +* Does it end with the line `Signed-off-by: My Name ` ? + +### Automated tests + +* Did the change pass a local `make` build? +* Did the change pass a local run of `make check`? +* Have you verified the code formatting with clang-format? +* Is the code covered by Unit Tests? If not, have you considered adding + a new Unit Test? + +### Change-specific checks + +* Does your change require adaptions on both server and client side + because it changes the wire-protocol? + * Did you propose a change to http://github.com/openvpn-rfc/ + to agree on the protocol format changes? +* Does your change add, remove, or change a config option? + * Have you adapted the usage text (`openvpn --help`)? + * Have you adapted the man page text (`man -l ./doc/openvpn.8`)? +* Have you reviewed all code comments around code you touched to + check whether they need to be adapted? + +## Integrator Checklist + +### General + +* Is the exact code change to be merged available as an email on openvpn-devel + mailing list (note: this does not apply to the commit message since that needs + to be massaged anyway)? +* If not, is the change to merge a trivial cherry-pick? + +### Commit message + +* Does it contain the pointer to the email on openvpn-devel? + This means a line `Message-Id: ` and a line + `URL: `. If mail-archive.com + is not working, alternatively an URL to SourceForge's mail archive + is also acceptable. +* Does it contain at least one `Acked-by` line from a known OpenVPN + core developer? Valid sources for `Acked-by` lines are mails on + the mailing list or +2 votes in Gerrit. +* If the change is a security fix, does it contain a `CVE:` line in + the format `CVE: -`? +* If the change fixes a Github issue, does it contain a line + `Github: OpenVPN/openvpn#`? (Other repositories might + also be referenced if applicable) +* Have you considered adding a `Reported-by:` line? This is usual + for attribution for security issues but might be added for any + report where the reporter added significant value by his report. +* If doing a cherry-pick, have you made sure to use `git cherry-pick -x` + to add a reference to the picked commit? + +#### Gerrit specific + +Additional checks if the change was reviewed and submitted via Gerrit. + +* Does it contain a correct `Gerrit URL:` line? (This is generally ensured + by using `gerrit-send-email.py`) +* Is the `Change-Id:` line present and located in the last paragraph of the + message? (If not in the last paragraph, Gerrit will ignore it) + +### Automated tests + +* Has the change passed a full build run in buildbot? (Usually ensured via + Gerrit). This ensures the following points (which otherwise might need to + be considered separately): + * Build passes on multiple platforms (Linux, FreeBSD, Windows, macOS, other BSDs) + * Build passes with multiple compilers (GCC, Clang, MSVC, GCC MinGW) + * Build passes with multiple configurations (--enable-small, --disable-management, + etc.) + * Build passes with multiple versions of multiple SSL libraries (OpenSSL, mbedTLS) + * Unit tests pass in all these settings + * t\_server\_null, t_client pass in all these settings + * t_server passes + * Verified clang-format code formatting +* If buildbot ignored the change that usually means that it did not match the + file match list (e.g. only changes in `.github/`). Consider whether that seems + correct. +* Has the change passed a GHA run? +* Do any of the tests actually excercise the code? If not, has someone other than the + submitter done any manual verification? + +### Backports + +* Is it clear to which branches the change should be applied? + * If it is a security fix, it should be applied to all branches that are + affected and that are not "unsupported" + (cf. https://community.openvpn.net/Pages/Supported%20versions) + * If it is a bugfix, it should be applied to all branches that are in + "Full stable support". Depending on the severity it might also be + applied to branches in "Old stable support". +* Have you checked for all branches whether a trivial cherry-pick is + possible or whether a backport is required? If a backport is required + have you communicated this to the submitter?