From patchwork Fri Aug 28 20:17:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5299 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp442845mab; Fri, 28 Aug 2026 13:18:19 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpT8qkfIf3rmazWmAgKT+FxOhF40/hZT57C+exJWrLgWIX3vRYRI+GrRpDcS1l3fs6uWSMnqTIhUBs=@openvpn.net X-Received: by 2002:a4a:e7c8:0:b0:6ac:8e23:3078 with SMTP id 006d021491bc7-6b1c6422a9bmr6935636eaf.5.1787948299082; Fri, 28 Aug 2026 13:18:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787948299; cv=none; d=google.com; s=arc-20260327; b=FIxZQWwM12ko/U0V4nO9o70ySC02f1CNXs3ZdhejfDJTV+zNGe5B3p1mQVP8jkam5C 9BrEnnCJ0pxu7xqYtUxAu2YqUkkn8McQMLriTFiMfSwl1lkegYUqrPfjcPjI2SOCSVKz Llm1abDdICdfryzbh0cwzdCyG5YOuBGujkuItskSbPVZPbjOsW58ejMcvTd9SipjpR4S tzNt4RaYUltD1GHi/uqVtQaOOFe3k7eBfuOfgHKbueUj7zsH5FnObI3c04ZHNqqCrwy6 jzQuyP6xscCd1xsWPB/a/M/rPwdNl+A9GjfbPmTqBSaE70IFaVL9VQ+KiaN2u3F3QzFv QNWg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=zprAGpHSA0QDbu2HMdcgUKyO/LAzQiMD5bN/MAK+wxY=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=lcfErTwfhu6MrwCtlw7R+tcO8XWUS52lTSw1CSo9184zb2VGEgY8dVmAT7+lpoLsHA MqJuLFrM/iOAb+0hpq49nfdqDr/afkdd7gKC/4p54KqmMac469TFQ/vF+AHHblnZNyCv E999+4ZDFmv6TLvQQtYgGG3KnwePYAOHtLl4RYwqo/8lxVUuToGhSN8iy2YvPtdpVPbt Ao6FMFUcUZ9Il2G3gpiO2afgb2sBt5TCJ1UdVXjXuTHrCH9yu6dyYekQF2/83AiO0p5+ WACU/+Om2D3k5QS4kUqUg7S1ERR6owoCZ6XpHISiQYoXDV8OeJpsgA6raVDbCDxm+sdg tHfQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=krjaQHnX; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dU0znS9t; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Y+2nm1Cv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6b1ce3545c4si4015546eaf.60.2026.08.28.13.18.18 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 28 Aug 2026 13:18:19 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=krjaQHnX; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dU0znS9t; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Y+2nm1Cv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=zprAGpHSA0QDbu2HMdcgUKyO/LAzQiMD5bN/MAK+wxY=; b=krjaQHnXg9iB4QH3KKZidd0OJF i3j+ZqI4ITVRVzxoGTjRnK9d2kHxDP+Xl/WAJGKVYYtf+noeqHK6fJc1b2fQpuHCVLUplnhOf4AZM 57kieSGuG581xpUtdpOmPLr1ol2t58tPC01TWqXYpSki8XX6qRCWenmumR2AZTKUyeJM=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x031e-0006Lb-6U; Fri, 28 Aug 2026 20:18:07 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x031c-0006LS-Ob for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 20:18:06 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=teqr5lNlbjVaUjNWk+FXzKVk0sobbSbRToJ5c76Q2xo=; b=dU0znS9tGsQJ5/qF6GPioNz11T su2FCVFcFfiBhQdhSN1pavEGeQC4tMUn14b5gc0GtoxakEWM1NLBZ6B+pyBZRfKMPDBgoZJpzgEYA RvAyzpieS2L1WWLJ8PtW6cZfhmhq420edWK8tTiYh43nPmoZaL+24PQamd4YvM61y3xE=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=teqr5lNlbjVaUjNWk+FXzKVk0sobbSbRToJ5c76Q2xo=; b=Y+2nm1Cv4d8VXvN7Te+hdBm64R qstJ2QVtjcYvqciSQKEfVNlF47L1aWk3oISWh3W6Q6Z9fn96Qs8SCWAaxHKDyYfOVcN2ff1wBjxxM 2KNMlxL6Y7r/ykt8E3rkn/FRNnGrFMb8iKjPi6AA2TB+w6eZ6moodzT7vSvqCQZAc9fo=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x031Y-00052i-Rw for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 20:18:06 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67SKHvFW000764 for ; Fri, 28 Aug 2026 22:17:57 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67SKHvSL000763 for openvpn-devel@lists.sourceforge.net; Fri, 28 Aug 2026 22:17:57 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 28 Aug 2026 22:17:50 +0200 Message-ID: <20260828201757.744-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Frank Lichtenheld Since the first distros have started to pick up these versions before a fix is released, let's make our tests pass on these versions. A fix is merged, so it might be fixed in 4.3.0. But I didn't want to add that to the version check until we have verified that. Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to DNSWL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#DnsBlocklists-dnsbl-block for more information. [193.149.48.129 listed in list.dnswl.org] 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x031Y-00052i-Rw Subject: [Openvpn-devel] [PATCH v2] mbedtls: Work-around bug in mbedtls 4.1.0 and 4.2.0 X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874799675511245943 X-GMAIL-MSGID: 1874799675511245943 From: Frank Lichtenheld Since the first distros have started to pick up these versions before a fix is released, let's make our tests pass on these versions. A fix is merged, so it might be fixed in 4.3.0. But I didn't want to add that to the version check until we have verified that. Change-Id: I694410615958afbb422d9ead71f04c1a60edc640 Signed-off-by: Frank Lichtenheld Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1849 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1849 This mail reflects revision 2 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 29e8be2a..56dd3ed 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -365,7 +365,7 @@ ovpnlibdesc: mbed TLS 4. # versioning=semver-coerced ghrepo: Mbed-TLS/mbedtls - gitref: v4.0.0 + gitref: v4.2.0 libconfigure: cmake -B build -DCMAKE_INSTALL_PREFIX=$LIBPREFIX libmake: cmake --build build libinstall: sudo cmake --install build diff --git a/src/openvpn/mbedtls_compat.h b/src/openvpn/mbedtls_compat.h index 50739b6..ec45a0f 100644 --- a/src/openvpn/mbedtls_compat.h +++ b/src/openvpn/mbedtls_compat.h @@ -43,6 +43,7 @@ #include "crypto_mbedtls_legacy.h" #else #include +#include "crypto_mbedtls.h" #endif /* MBEDTLS_VERSION_NUMBER < 0x04000000 */ #ifdef HAVE_PSA_CRYPTO_H @@ -228,6 +229,18 @@ mbedtls_compat_pk_check_pair(const mbedtls_pk_context *pub, const mbedtls_pk_context *prv) { #if MBEDTLS_VERSION_NUMBER >= 0x04000000 + /* work around bug in mbedtls 4.1.0 by adding missing public key information in prv + * cf. https://github.com/Mbed-TLS/TF-PSA-Crypto/issues/807 */ +#if MBEDTLS_VERSION_NUMBER >= 0x04010000 + if (prv->MBEDTLS_PRIVATE(pub_raw_len) == 0) + { + mbedtls_pk_context *mut_prv = (mbedtls_pk_context *)prv; /* remove const */ + ASSERT(mbed_ok(psa_export_public_key(mut_prv->MBEDTLS_PRIVATE(priv_id), + mut_prv->MBEDTLS_PRIVATE(pub_raw), + sizeof(mut_prv->MBEDTLS_PRIVATE(pub_raw)), + &mut_prv->MBEDTLS_PRIVATE(pub_raw_len)))); + } +#endif return mbedtls_pk_check_pair(pub, prv); #else return mbedtls_pk_check_pair(pub, prv, mbedtls_ctr_drbg_random, rand_ctx_get());