From patchwork Mon Sep 28 14:37:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5415 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5189:b0:8b3:6e77:b38b with SMTP id g9csp3403717mae; Mon, 28 Sep 2026 08:03:45 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvByzLcJKPwKRmcsvWCeYi9H/QUQ/Wr+Z2TbEgVuOFZlWNQHSLrh9JNabsOmmIv8+m/z+oZXNEdTnxiE=@openvpn.net X-Received: by 2002:a05:6808:50a3:b0:4c5:cd9d:c6de with SMTP id 5614622812f47-4d72c635ff8mr13645457b6e.7.1790607824895; Mon, 28 Sep 2026 08:03:44 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790607824; cv=none; d=google.com; s=arc-20260327; b=XJaYrTNkU+UM41lOOb3gfmKOw9v2Dal02XzdB+3752h/NJba46OLVfvZh7t4nV+8kL xmvdtQPnD1DmVGj7WPjBSEcA9Ve2l1tqAkQ3YV/bU/bexbX2ZT/bje5+LpTXniEAX7uY qDQhS3ZNek3EcEi9ZHD/dCfQenC6+U2UTkrN+A6CU+Twq1oBZ3grcE35Tjj/rSH16mU2 69jSnblDCBNgHKkLjWyAIc2dGkRSYWL1m3Dc/SLcScVFkDjqyvEoozjXeUWh3MLEjxk6 3xDefOnh4xU637oyb/dNZiYZWsqKA/wdLf4aUWajaw0pDUO5bh5g4Fh/h/riZW/ND4UN b0Dg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=swCyViZzfGCpFm6saAlWpenf2cdBQpyY+tkbjyGhIruoSQB/FuNtAITMCU3uHOf/Z9 57BZn0acHdTOqtrohfduTFf76T0xjW6z6mQvHAltk4f7bLhJyPcIq9FiCWIHLpnjv4Fq r8Kacg1ru2q9R+WFVr9vZOlSs5jn8xEMw5rSNl/fmTXlGyGrH/LbiqLH+qg2zC+oOe5q R4Y9SUOlw4pH6S3Lh3QpWKFguhVvKRT6Z0BAFECVj5enRtbfNOgN2vkluOAxhf8VZ2Nv I/nf9Ob0GM2HpT6UmDHhs8UbI2Axy0KNnbBhK/+c/T/O3+Mp64/nE2kuJGmpYUUXgrH3 FdXA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=knpujXwC; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dvs2euDp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Z17HBAvy; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n3p7+KI9; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4ebbc3d99b0si2834374b6e.64.2026.09.28.08.03.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 28 Sep 2026 08:03:44 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=knpujXwC; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dvs2euDp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Z17HBAvy; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n3p7+KI9; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; b=knpujXwCvhwg+Td2hx3l8vMe51 tIN6nnfzqGhe9WboswD4rnDOE7b4Isdv+/kQrDCGvjH9cTt07ml24nefIAfylstUhCGQ1OkYoEfaL K7SZaGGvjUJeylGsIjSRDm/Dd5t8Ku9P2sQotml0A4m3iZd0MZCrbSD7QFCCjLe6kKno=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBCt8-0002nJ-LA; Mon, 28 Sep 2026 15:03:28 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBCt6-0002nD-LK for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 15:03:26 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=dvs2euDpUXjJa0HrkmKVlW4+zY 9i5qSC7IpZv1CBPmI4XO0in2VOG9ctpwZTtXMW4f66+QrsVWNiYuCSHCVU1yK5F4v1Rc/n57CSTS2 6HhcnbjvMDzoz6OdVbdKP3adVEgddHrkjWw6+aryvUxewNOuLeFtwwDQ2az9+JJmUen4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=Z17HBAvya1TdGDJW7h9s+4ii1A UfGJZaNWUPwjxr5ZAjuli+RJlrrOW+idOzutImGhdFHMdtQRNknYKp6yLQXpBH//b6c/Au+UC4bVh 2xWrK828WiEyFBbNKmtZzX67ufNC6E/sAx4BqgehavOyz3gRJlPacAausBNV2tz7KeeA=; Received: from mail-vs2-f15.google.com ([74.125.227.15]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBCt2-00050e-Ld for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 15:03:26 +0000 Received: by mail-vs2-f15.google.com with SMTP id 71dfb90a1353d-5c981b0d59cso2196453e0c.3 for ; Mon, 28 Sep 2026 08:03:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790607799; x=1791212599; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=n3p7+KI9SMeihwGiq9l7ovOIgCJyfvwOkNufywriwGehCg2/jOao1im1u1Tmyrqnsy pCE4hy7aAhx5gwEaNS7Zn9A/WjIuNyEapbKgoYxhfIy81AqXc/OeDHXX5Yv+GB6TH+8j Eh48G2HIuUVVtBhbZTsBKrAU3xttKqwaXYU2fsxLTtRtpeqq+YHLj/nrlwG56c4fixWx /s8SDNLzGYbrJ+DDWg8EnBdTOzanGCHvfcMdDKFYeaU3YuiGubmjqli13m1JlTLWrfMS Bz2JjCSfA+SBxu2t8ibOdvmdq4ttMHHSd50oMErGQVzRp+WuGc2cmZK0EvEi6O8K0fIi eH4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790607799; x=1791212599; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=C723HzOrnR3Ts5qAOqA7GK7CNBPwVS6MI/bPyV7SDwlMRK4Uo6CTaR2jNStc+p40O7 p6EtUC7LLwWwojayF78hIJXkmYEehhF2enEwLfFju7ncqxCjiwzQu9sfngyGnqkANEnR DmSKfUenJ6ZfPnnJys5qnCRI+OkC/tLJ8Ya3nXSc8MJ9TkE9yh+UBfkCGVUSJ0Tr9cWH fHcIfS8KaABJCZFKlhcjEMFKOSIPQsq+V4VHLwJj6EtJDWmoYV/mgzDBpkrK0dtQ1nhR TLDzd5yYdgFPhiRBBcDp3lEAp80wxsiX4qRNVWUPHbownOfzDdK4qo3veSBtefY2pCzz 0EUQ== X-Gm-Message-State: AFq9FYKvQNTA0k00dcAFluuS4K7+4MKDw7dLj5+FfO/D3wj1ageMFtWI d4OWPjLgT/USL2N+IDAuWkja1adoV0wWJpz8PjjXL0xHjrQ+u4tBmDhKHABfzs78p2XIsevP5JG 6HJYfcMYx X-Gm-Gg: AYBFou0ChjDJ14mB7Igwp9ht+s6h4atVhol96J2rirrHqLC2XXkm7nqHZPtpQfy1jB0 eS7/pBB3IEwPCqV6dqIkk6AJ3EOCP/o494qDPcEBU4NCpYm+6gdGD+9bRV7NGiiEZDrElLJQgVE cHS5xgPIgEv87cv3b3aAFIMUaBiAUxs7N0WkjLlWZwhFF+oD1qqReavMgjYR8hVnco9iYa5prGf A89htpKx54P5NRLMap4/az6X8K/Y/eSektT0+gJMewmDYsyMc5VuvAUwdH01B8amZJfSANzlhXW 9B3L3OGitkewYPTEm+cHmI5iBl3NbKQj6umz3J76WclmW/SYu+jJWcDFSeXQkhXo91eW6nBuxo7 PDnE7TNhxXoflD77B+65Mb4d4vmOZCVMBYfz2NpGIdeNVdgXQ5L5c8+Bi2fRGj8FUI3rmGb92hc JPnk0qJE2ymyQ3cwjThXxaNsFQwxqH7zaOUQa3pEcO5HDjyMspRVSc+oZewjusbqH14D0Li1wD+ CmA03uoLwBuziW0GXRHD7HjfswwVDwOog0y+HHyOvFHeLxCTIXxuHUk+2PYT9w= X-Received: by 2002:a05:690c:dc5:b0:882:1d1e:d73a with SMTP id 00721157ae682-8a64bb00575mr56471247b3.4.1790606255711; Mon, 28 Sep 2026 07:37:35 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8a860e5e9besm45668487b3.11.2026.09.28.07.37.34 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 28 Sep 2026 07:37:34 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Mon, 28 Sep 2026 10:37:30 -0400 Message-ID: <20260928143730.47047-3-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260928143730.47047-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260928143730.47047-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behi [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.227.15 listed in wl.mailspike.net] X-Headers-End: 1xBCt2-00050e-Ld Subject: [Openvpn-devel] [PATCH v2 2/2] Make CRL reload EOF detection independent of stale error queue entries X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042728496797502 X-GMAIL-MSGID: 1877588390234179220 backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behind earlier in the thread turns a clean EOF into a "CRL: cannot read CRL from file" warning, prints the unrelated errors as if they came from the CRL file, and still installs the CRLs already parsed. The previous commit removes the leftover that triggered this in practice; this one stops the loop from depending on the queue being clean at all. Start the loop from an empty queue so only errors raised by PEM_read_bio_X509_CRL() are visible, test the error it raised last rather than the oldest one, and clear the queue on the EOF path instead of popping a single entry. Signed-off-by: Drew Blokzyl --- src/openvpn/ssl_openssl.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 7cfe9f4a..da3e07fe 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -1360,6 +1360,13 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b } int num_crls_loaded = 0; + /* + * Start from an empty error queue so the EOF test below only sees errors + * raised by PEM_read_bio_X509_CRL(). A stale error left by an earlier + * operation in this thread would otherwise be what ERR_peek_error() + * returns, and a clean EOF gets reported as "cannot read CRL". + */ + ERR_clear_error(); while (true) { X509_CRL *crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL); @@ -1367,13 +1374,15 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b { /* * PEM_R_NO_START_LINE can be considered equivalent to EOF. + * ERR_peek_last_error() is the error PEM_read_bio_X509_CRL() + * raised last; ERR_peek_error() would be the oldest queued one. */ - bool eof = ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE; + bool eof = ERR_GET_REASON(ERR_peek_last_error()) == PEM_R_NO_START_LINE; /* but warn if no CRLs have been loaded */ if (num_crls_loaded > 0 && eof) { /* remove that error from error stack */ - (void)ERR_get_error(); + ERR_clear_error(); break; }