From patchwork Wed Sep 30 13:27:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5419 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6ac1:b0:8b3:6e77:b38b with SMTP id v1csp687130maw; Wed, 30 Sep 2026 06:35:52 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBxLqKbCTLVvQIcTf3p+B8Kiyn/Ha80AkE4PJISO1P19Qe2+yGg86vRXlaaT6TNrAnkvev8aPcROjkA=@openvpn.net X-Received: by 2002:a05:6820:4d01:b0:6cd:3fec:de7e with SMTP id 006d021491bc7-6dcf6816cdcmr1197582eaf.84.1790775352164; Wed, 30 Sep 2026 06:35:52 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790775352; cv=none; d=google.com; s=arc-20260327; b=p8TjMyBQQ298LsBlmbd1saBKrWYhqHjI7oKp7bwp8ARlRgGFJbEhXsWveghHxv8lBm Q1shlNeK6D7VRKJzMyJZPir4+W2W5lWd+urkjH6MWPpmNi8Xg2KX02mCQNvA+1fttSLN Fa5pBvPUSankDRQ3Msxjxi/2jO/Utj7arw8+e6rb2NHJ66q8yn3nlJXLNU72vb8gHopr vGX5SnwnW+5Laqftop8WIEbNHBNtSW3Y/EBJ2FVYDLiS+poltFrkzc94lZS+dq3dqzhl Y8CSxGGUxErqnTpMX6Mt20m62QBQY55O5CfIncbfVsfAfG6jpP0k7ldNPej50mzD0YMY jw/Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=pU+ywKL0zEQ+cYEuu/1lnLe5YVERWU+ZOm0wB4MhvIuLviW+2DtQu/rFy29B+X1nv4 7rm7oYsI8EJyvQzD0XUwS9YWz5TK9jzEQuD470YZ7+dybGj9f3t1rp/6TVhPjJwoh9kv jdXJZ/uQelbLixsaSQmwmIf4CcW4q8Xmefxo2eBhN59etWmNf8GzF7NHfCmhxF0etRop vHJyEl7xctELWBGvWuIMuvBSFtOMkKS/L+OALrOwWeWBOfZHO3mTMGYJHeYQwTmzdZoi qSExVvzuj8PijdWrrpMHqJFYkQxM8JD+IQWwj4unb+Z8ohpeR5Mpa3mBPV+7W3mLgsz2 r2Fw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=GJ7ESK3M; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="ao4/iDMP"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=cG2yNuvk; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=gMAToRef; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-49decf239b9si140286fac.36.2026.09.30.06.35.52 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 30 Sep 2026 06:35:52 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=GJ7ESK3M; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="ao4/iDMP"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=cG2yNuvk; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=gMAToRef; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=; b=GJ7ESK3MB2L8v1d19Woql77Hgq qpSFQiSmVWXxrwv4Tpl8NsPmpG3oAz9rI6W8YVpx7h1+sS9zE0fTihYwwPJ8PAQwK1S1s86kSYesh N7jdIJAVoUBn2pX75QhH90qubAi2HT+WUs0s2u9eFzKy7f5TI/GRnKP1BoCIRYddROpY=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBuTM-0008S7-05; Wed, 30 Sep 2026 13:35:48 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBuTD-0008Rw-3j for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:35:39 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=ao4/iDMPueykFrCxxSqAL9m74V vx6rRr+rAKzmN7clafNldxVeQngtPe3+38XQq+tveWoAWuKWZBTxVFCN6fzGDtt2WnyEuYsQUe8a6 fy3Wk8UfeOheunK5dokln/XZCLLEpTy25rYlc5qXdC5bgm8ZBMaNqe1sBTZEVjpFpbc0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=cG2yNuvkE1LE0CHoAK4bB7mcis behZcyvj29Kjw9JWsqztAldEXbMdcvYFJWv7mRiWMkL4NVQUxAZGJ2VXC7aj8OraHTx6XIm3uxXyD 30rMS8qIHayM2XPPclZS4Fv/KVXFAtCLFcGEP7CbJcxkc2AvTe5StlBN7ctstAi9wnNo=; Received: from mail-vs2-f41.google.com ([74.125.227.41]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBuTC-0005u4-I2 for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:35:39 +0000 Received: by mail-vs2-f41.google.com with SMTP id 71dfb90a1353d-5c981b0d59cso3719083e0c.3 for ; Wed, 30 Sep 2026 06:35:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790775332; x=1791380132; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=gMAToRefn3vMPuUnOXNnTLKiIq6dmtzcq1dH1BItUBoJIiNtgsXQCnSkKrtTBabvyL 43XOau3MMlpnhg7ZN/cyAP6GSGft704Xuyj+j1rjekm+u2lwisV9vco1NsX/Dyon6TSc 9jPraTSrtlo8ZcCzZs/amKXD99aKNvYhuRfgYfFb5olnLo8n/pzRg//6yyFs/I0G0/JV HKztKX0mcczwwL2Ldm4O0dMc4qwU8JGQm+nOchC597rLIRQX1ir4xOlyjszjAcHZQPzR deiYvBy/eSuduu6LXF4KG22+qAzTOBxy0McbaWCP3j1yJ8lu0LoF0ZXrPKkynxc2RUD9 Ar7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790775332; x=1791380132; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=tprBI/Jxt3dL8M7zj8a1Peonz7vU0M61jTUM3TUeEXiWNLl+CELtKEFH5RNSpqHj6m +6W/x8MLtSWQEh0sIEvIT/cOyUKXwIBwqUw/MoQ2ogA7CUYStU7GrmdaN3a3LOOK3ftP Vu+KUpAH4xdR8raR6lf6Lj64e2fubsq6oODQtB0obWM9Z/9b4ig4Kl5NdhYsq5/BcG7m 4BrtWf8tPY9KGAtPoWwr3Ogjlgn5dcYPa1ifOBqxINPznVJBIc0Y+zvXa0iedYiZ4jyP VKhz9DOnjXzSubktBB3vHfY6xKSc/lUHhxvPF7ib5bbIkc5ZmTevZXYYfCdIQFiw8E4a FHgQ== X-Gm-Message-State: AFq9FYKbE68/0muf1Ispq0ZuBVKbPT8mpSpyUkJef/qIFL8Be/BfbEph QAWvWu1M2f7TkHC+F8mcS5awICCVIgQ4FnZAvBNFLvKHtJPj42V8zO1Ax0ix1XChiZ1XiDtaaJV j8ZcmgA== X-Gm-Gg: AYBFou1UPTHn6gZj2XG1gGXah5bgtYn1P4Xq6bQnMeWLxEmt7MWRw9xoTmG89isapvd lUMPPivFy4GNL5WwHc4DIfLM4zR+6XwYLcqvXIqnEzsN+YolOozsduYagSdF3M912h2UgECFwDB 6luOotH0FyBL1UGyJ3ny8rfUEv7lfA0x6y06qKsoefT1FuQve+OllhRgR6itFEc2iWW+M9OY4Wr eI/atu9Fj3DgRWpiY0Gi92ZhdbMI0VQzoLAOJBwuvrd3vm9efwtIGUE40N78tzPnCzqW6kZDy1k WMrq9QmlaCvAPrpjTb0UoX6WepBN11ZPM7e27QcyQi68vHJnAG/RMM9zjXfVy914p1vQFZ7aIs1 9vm2QJ/DDkHQ2zy7KDR/sKoQW7A2yWEkr1RRpJsY/L0UGXYowNsBZM/dQnOUnMwv0mQjCUO/tqV xEkD012WcXJfHg4Y90E6gPNg13ls1TV6rAV005GytNV21IFIjNo0eMcIlWO6J3N2ZqTbpHZtF3i wYyRcxPEWAUPiAPpgEseYhpqoeVZSjlDMeUywJb/uqGL4lAi9EadjiCMxluYqo= X-Received: by 2002:a05:690e:1382:b0:66e:57d8:6a52 with SMTP id 956f58d0204a3-676833245d0mr564266d50.7.1790774831771; Wed, 30 Sep 2026 06:27:11 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-67680ac3521sm704189d50.1.2026.09.30.06.27.10 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 30 Sep 2026 06:27:10 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Wed, 30 Sep 2026 09:27:06 -0400 Message-ID: <20260930132707.51452-2-drew@linuxkids.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260930132707.51452-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260930132707.51452-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.227.41 listed in wl.mailspike.net] X-Headers-End: 1xBuTC-0005u4-I2 Subject: [Openvpn-devel] [PATCH v3 1/2] Do not look up the "none" cipher or digest in OpenSSL X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877764055532193951 X-GMAIL-MSGID: 1877764055532193951 cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), cipher_kt_insecure()) treat NULL as "not that". For the "none" cipher that is the expected answer, but under OpenSSL 3 the failed fetch also pushes EVP_R_UNSUPPORTED ("digital envelope routines::unsupported, Algorithm (none : 0)") onto the thread's error queue, and nothing pops it. "none" is what every server without --cipher carries in its pre-negotiation key_type: the legacy BF-CBC default is not in --data-ciphers, so do_init_crypto_tls() initialises the key_type with cipher "none". Each new client instance walks it in init_instance() -> do_init_crypto_tls() -> cipher_kt_mode_ofb_cfb("none") and in the frame and OCC calculations, and tls_ctx_reload_crl() runs right after. Its EOF test reads ERR_peek_error(), the OLDEST queued entry, so on the first handshake after the CRL file changed it finds the stale "unsupported" error and logs "CRL: cannot read CRL from file" for a CRL it loaded fine (GitHub #1103). Traced with gdb on 2.7.0 and master against OpenSSL 3.5.5. Return NULL for "none" before touching OpenSSL, as cipher_kt_name() already does. Real cipher names behave as before, and cipher_valid_reason() still finds the OpenSSL reason on the queue when it reports an unknown cipher. md_get() gets the same guard: no caller passes "none" today (md_kt_name(), md_kt_size() and md_defined() check first), but it has the same shape and would leave the same entry. Left alone on purpose: cipher_kt_block_size()'s probe for the CBC sibling of an AEAD cipher (CHACHA20-POLY1305 -> "CHACHA20-CBC") and md_valid() leave the same kind of entry, but neither runs between client instance creation and the CRL reload. The next commit makes that reload robust against any leftover and reports one when it sees it. With this change the queue is empty at multi_create_instance() and at backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305 clients; CRL replacements give clean reloads (unpatched: a warning every time). Signed-off-by: Drew Blokzyl --- src/openvpn/crypto_openssl.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 29c5fa68..b44d0797 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -568,6 +568,15 @@ cipher_get(const char *ciphername) { ASSERT(ciphername); + /* "none" is a valid OpenVPN cipher name that OpenSSL does not know. + * Return NULL without asking OpenSSL: a failed EVP_CIPHER_fetch() would + * leave an "unsupported" entry on the error queue that the cipher_kt_*() + * callers never clear. */ + if (strcmp("none", ciphername) == 0) + { + return NULL; + } + ciphername = translate_cipher_name_from_openvpn(ciphername); return EVP_CIPHER_fetch(NULL, ciphername, NULL); } @@ -981,6 +990,14 @@ md_get(const char *digest) { evp_md_type *md = NULL; ASSERT(digest); + + /* "none" is a valid OpenVPN digest name that OpenSSL does not know. + * Return NULL without asking OpenSSL, see cipher_get(). */ + if (strcmp("none", digest) == 0) + { + return NULL; + } + md = EVP_MD_fetch(NULL, digest, NULL); if (!md) {