| Message ID | 20260930132707.51452-2-drew@linuxkids.com |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:6ac1:b0:8b3:6e77:b38b with SMTP id v1csp687130maw;
Wed, 30 Sep 2026 06:35:52 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AKwUvBxLqKbCTLVvQIcTf3p+B8Kiyn/Ha80AkE4PJISO1P19Qe2+yGg86vRXlaaT6TNrAnkvev8aPcROjkA=@openvpn.net
X-Received: by 2002:a05:6820:4d01:b0:6cd:3fec:de7e with SMTP id
006d021491bc7-6dcf6816cdcmr1197582eaf.84.1790775352164;
Wed, 30 Sep 2026 06:35:52 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790775352; cv=none;
d=google.com; s=arc-20260327;
b=p8TjMyBQQ298LsBlmbd1saBKrWYhqHjI7oKp7bwp8ARlRgGFJbEhXsWveghHxv8lBm
Q1shlNeK6D7VRKJzMyJZPir4+W2W5lWd+urkjH6MWPpmNi8Xg2KX02mCQNvA+1fttSLN
Fa5pBvPUSankDRQ3Msxjxi/2jO/Utj7arw8+e6rb2NHJ66q8yn3nlJXLNU72vb8gHopr
vGX5SnwnW+5Laqftop8WIEbNHBNtSW3Y/EBJ2FVYDLiS+poltFrkzc94lZS+dq3dqzhl
Y8CSxGGUxErqnTpMX6Mt20m62QBQY55O5CfIncbfVsfAfG6jpP0k7ldNPej50mzD0YMY
jw/Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature:dkim-signature;
bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=pU+ywKL0zEQ+cYEuu/1lnLe5YVERWU+ZOm0wB4MhvIuLviW+2DtQu/rFy29B+X1nv4
7rm7oYsI8EJyvQzD0XUwS9YWz5TK9jzEQuD470YZ7+dybGj9f3t1rp/6TVhPjJwoh9kv
jdXJZ/uQelbLixsaSQmwmIf4CcW4q8Xmefxo2eBhN59etWmNf8GzF7NHfCmhxF0etRop
vHJyEl7xctELWBGvWuIMuvBSFtOMkKS/L+OALrOwWeWBOfZHO3mTMGYJHeYQwTmzdZoi
qSExVvzuj8PijdWrrpMHqJFYkQxM8JD+IQWwj4unb+Z8ohpeR5Mpa3mBPV+7W3mLgsz2
r2Fw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=GJ7ESK3M;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="ao4/iDMP";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=cG2yNuvk;
dkim=neutral (body hash did not verify)
header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104
header.b=gMAToRef;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dara=neutral header.i=@openvpn.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
586e51a60fabf-49decf239b9si140286fac.36.2026.09.30.06.35.52
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 30 Sep 2026 06:35:52 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=GJ7ESK3M;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="ao4/iDMP";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=cG2yNuvk;
dkim=neutral (body hash did not verify)
header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104
header.b=gMAToRef;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dara=neutral header.i=@openvpn.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=; b=GJ7ESK3MB2L8v1d19Woql77Hgq
qpSFQiSmVWXxrwv4Tpl8NsPmpG3oAz9rI6W8YVpx7h1+sS9zE0fTihYwwPJ8PAQwK1S1s86kSYesh
N7jdIJAVoUBn2pX75QhH90qubAi2HT+WUs0s2u9eFzKy7f5TI/GRnKP1BoCIRYddROpY=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1xBuTM-0008S7-05;
Wed, 30 Sep 2026 13:35:48 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <drew@linuxkids.com>) id 1xBuTD-0008Rw-3j
for openvpn-devel@lists.sourceforge.net;
Wed, 30 Sep 2026 13:35:39 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=ao4/iDMPueykFrCxxSqAL9m74V
vx6rRr+rAKzmN7clafNldxVeQngtPe3+38XQq+tveWoAWuKWZBTxVFCN6fzGDtt2WnyEuYsQUe8a6
fy3Wk8UfeOheunK5dokln/XZCLLEpTy25rYlc5qXdC5bgm8ZBMaNqe1sBTZEVjpFpbc0=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=cG2yNuvkE1LE0CHoAK4bB7mcis
behZcyvj29Kjw9JWsqztAldEXbMdcvYFJWv7mRiWMkL4NVQUxAZGJ2VXC7aj8OraHTx6XIm3uxXyD
30rMS8qIHayM2XPPclZS4Fv/KVXFAtCLFcGEP7CbJcxkc2AvTe5StlBN7ctstAi9wnNo=;
Received: from mail-vs2-f41.google.com ([74.125.227.41])
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95)
id 1xBuTC-0005u4-I2 for openvpn-devel@lists.sourceforge.net;
Wed, 30 Sep 2026 13:35:39 +0000
Received: by mail-vs2-f41.google.com with SMTP id
71dfb90a1353d-5c981b0d59cso3719083e0c.3
for <openvpn-devel@lists.sourceforge.net>;
Wed, 30 Sep 2026 06:35:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790775332;
x=1791380132;
darn=lists.sourceforge.net;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:from:to:cc:subject:date
:message-id:reply-to:content-type;
bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=;
b=gMAToRefn3vMPuUnOXNnTLKiIq6dmtzcq1dH1BItUBoJIiNtgsXQCnSkKrtTBabvyL
43XOau3MMlpnhg7ZN/cyAP6GSGft704Xuyj+j1rjekm+u2lwisV9vco1NsX/Dyon6TSc
9jPraTSrtlo8ZcCzZs/amKXD99aKNvYhuRfgYfFb5olnLo8n/pzRg//6yyFs/I0G0/JV
HKztKX0mcczwwL2Ldm4O0dMc4qwU8JGQm+nOchC597rLIRQX1ir4xOlyjszjAcHZQPzR
deiYvBy/eSuduu6LXF4KG22+qAzTOBxy0McbaWCP3j1yJ8lu0LoF0ZXrPKkynxc2RUD9
Ar7w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20260707; t=1790775332; x=1791380132;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from
:to:cc:subject:date:message-id:reply-to:content-type;
bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=;
b=tprBI/Jxt3dL8M7zj8a1Peonz7vU0M61jTUM3TUeEXiWNLl+CELtKEFH5RNSpqHj6m
+6W/x8MLtSWQEh0sIEvIT/cOyUKXwIBwqUw/MoQ2ogA7CUYStU7GrmdaN3a3LOOK3ftP
Vu+KUpAH4xdR8raR6lf6Lj64e2fubsq6oODQtB0obWM9Z/9b4ig4Kl5NdhYsq5/BcG7m
4BrtWf8tPY9KGAtPoWwr3Ogjlgn5dcYPa1ifOBqxINPznVJBIc0Y+zvXa0iedYiZ4jyP
VKhz9DOnjXzSubktBB3vHfY6xKSc/lUHhxvPF7ib5bbIkc5ZmTevZXYYfCdIQFiw8E4a
FHgQ==
X-Gm-Message-State: AFq9FYKbE68/0muf1Ispq0ZuBVKbPT8mpSpyUkJef/qIFL8Be/BfbEph
QAWvWu1M2f7TkHC+F8mcS5awICCVIgQ4FnZAvBNFLvKHtJPj42V8zO1Ax0ix1XChiZ1XiDtaaJV
j8ZcmgA==
X-Gm-Gg: AYBFou1UPTHn6gZj2XG1gGXah5bgtYn1P4Xq6bQnMeWLxEmt7MWRw9xoTmG89isapvd
lUMPPivFy4GNL5WwHc4DIfLM4zR+6XwYLcqvXIqnEzsN+YolOozsduYagSdF3M912h2UgECFwDB
6luOotH0FyBL1UGyJ3ny8rfUEv7lfA0x6y06qKsoefT1FuQve+OllhRgR6itFEc2iWW+M9OY4Wr
eI/atu9Fj3DgRWpiY0Gi92ZhdbMI0VQzoLAOJBwuvrd3vm9efwtIGUE40N78tzPnCzqW6kZDy1k
WMrq9QmlaCvAPrpjTb0UoX6WepBN11ZPM7e27QcyQi68vHJnAG/RMM9zjXfVy914p1vQFZ7aIs1
9vm2QJ/DDkHQ2zy7KDR/sKoQW7A2yWEkr1RRpJsY/L0UGXYowNsBZM/dQnOUnMwv0mQjCUO/tqV
xEkD012WcXJfHg4Y90E6gPNg13ls1TV6rAV005GytNV21IFIjNo0eMcIlWO6J3N2ZqTbpHZtF3i
wYyRcxPEWAUPiAPpgEseYhpqoeVZSjlDMeUywJb/uqGL4lAi9EadjiCMxluYqo=
X-Received: by 2002:a05:690e:1382:b0:66e:57d8:6a52 with SMTP id
956f58d0204a3-676833245d0mr564266d50.7.1790774831771;
Wed, 30 Sep 2026 06:27:11 -0700 (PDT)
Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net.
[71.208.239.209]) by smtp.gmail.com with ESMTPSA id
956f58d0204a3-67680ac3521sm704189d50.1.2026.09.30.06.27.10
(version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256);
Wed, 30 Sep 2026 06:27:10 -0700 (PDT)
From: Drew Blokzyl <drew@linuxkids.com>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 30 Sep 2026 09:27:06 -0400
Message-ID: <20260930132707.51452-2-drew@linuxkids.com>
X-Mailer: git-send-email 2.54.0
In-Reply-To: <20260930132707.51452-1-drew@linuxkids.com>
References: <20260922140520.71500-1-drew@linuxkids.com>
<20260930132707.51452-1-drew@linuxkids.com>
MIME-Version: 1.0
X-Spam-Score: 0.0 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: cipher_get() hands EVP_CIPHER_fetch() whatever name it is
given, and the callers that only ask whether a cipher exists or which mode
it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), [...]
Content analysis details: (0.0 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[74.125.227.41 listed in wl.mailspike.net]
X-Headers-End: 1xBuTC-0005u4-I2
Subject: [Openvpn-devel] [PATCH v3 1/2] Do not look up the "none" cipher or
digest in OpenSSL
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1877764055532193951
X-GMAIL-MSGID: 1877764055532193951
|
| Series |
Stop failed cipher/digest lookups from polluting the OpenSSL error queue
|
|
Commit Message
Drew Blokzyl
Sept. 30, 2026, 1:27 p.m. UTC
cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the
callers that only ask whether a cipher exists or which mode it has
(cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(),
cipher_kt_insecure()) treat NULL as "not that". For the "none" cipher
that is the expected answer, but under OpenSSL 3 the failed fetch also
pushes EVP_R_UNSUPPORTED ("digital envelope routines::unsupported,
Algorithm (none : 0)") onto the thread's error queue, and nothing pops
it.
"none" is what every server without --cipher carries in its
pre-negotiation key_type: the legacy BF-CBC default is not in
--data-ciphers, so do_init_crypto_tls() initialises the key_type with
cipher "none". Each new client instance walks it in init_instance() ->
do_init_crypto_tls() -> cipher_kt_mode_ofb_cfb("none") and in the frame
and OCC calculations, and tls_ctx_reload_crl() runs right after. Its
EOF test reads ERR_peek_error(), the OLDEST queued entry, so on the
first handshake after the CRL file changed it finds the stale
"unsupported" error and logs "CRL: cannot read CRL from file" for a CRL
it loaded fine (GitHub #1103). Traced with gdb on 2.7.0 and master
against OpenSSL 3.5.5.
Return NULL for "none" before touching OpenSSL, as cipher_kt_name()
already does. Real cipher names behave as before, and
cipher_valid_reason() still finds the OpenSSL reason on the queue when
it reports an unknown cipher. md_get() gets the same guard: no caller
passes "none" today (md_kt_name(), md_kt_size() and md_defined() check
first), but it has the same shape and would leave the same entry.
Left alone on purpose: cipher_kt_block_size()'s probe for the CBC
sibling of an AEAD cipher (CHACHA20-POLY1305 -> "CHACHA20-CBC") and
md_valid() leave the same kind of entry, but neither runs between
client instance creation and the CRL reload. The next commit makes that
reload robust against any leftover and reports one when it sees it.
With this change the queue is empty at multi_create_instance() and at
backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305
clients; CRL replacements give clean reloads (unpatched: a warning
every time).
Signed-off-by: Drew Blokzyl <drew@linuxkids.com>
---
src/openvpn/crypto_openssl.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 29c5fa68..b44d0797 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -568,6 +568,15 @@ cipher_get(const char *ciphername) { ASSERT(ciphername); + /* "none" is a valid OpenVPN cipher name that OpenSSL does not know. + * Return NULL without asking OpenSSL: a failed EVP_CIPHER_fetch() would + * leave an "unsupported" entry on the error queue that the cipher_kt_*() + * callers never clear. */ + if (strcmp("none", ciphername) == 0) + { + return NULL; + } + ciphername = translate_cipher_name_from_openvpn(ciphername); return EVP_CIPHER_fetch(NULL, ciphername, NULL); } @@ -981,6 +990,14 @@ md_get(const char *digest) { evp_md_type *md = NULL; ASSERT(digest); + + /* "none" is a valid OpenVPN digest name that OpenSSL does not know. + * Return NULL without asking OpenSSL, see cipher_get(). */ + if (strcmp("none", digest) == 0) + { + return NULL; + } + md = EVP_MD_fetch(NULL, digest, NULL); if (!md) {