From patchwork Wed Sep 16 20:34:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5377 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp6597474mag; Wed, 16 Sep 2026 13:34:43 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwdCyePiMP6kGeEezRpWsMlmcj6uVBOVZIdcjvsUmVFSad1kpvYd02OigNfP7aacAeVbevSux7DwP4=@openvpn.net X-Received: by 2002:a05:6808:bc3:b0:495:feaa:9e3b with SMTP id 5614622812f47-4ca49dd32e3mr4992295b6e.7.1789590883673; Wed, 16 Sep 2026 13:34:43 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789590883; cv=none; d=google.com; s=arc-20260327; b=Nnqvbwrnxk94yvxf2sPmxVl1f9Q02FCBj0H/N7bej51Dki4pe/qQHfwthfBEmAcuUk tNHVVgCsaUc5XzwvHQV3KgHcjhCI/6nhwyl0G7B3N2HqM2eDurVFnjdCkOIq09h2YN+s SuPKdsyrc/8wk0JIkNICrKQszRPm6DMDT42lUNx8bf4kENgurM72yxGqhcbatYL3Qhhv +8qwZZq5t+O4cTXAlLJmnAHywSyqm+rg+c264rqusOy2TDQrh8tI/ntbTjn8xYX8G+jz WWjOdoWt2QDOzidqG77eOEY4/g/6Jq9MOFr3OMtIkIajIcqHUbSYNjds+EyRnn2Gfo2+ Z5lQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=SzP4EK6BBMrdN7pwMoPT5QIvaLPuDqRtacXN51gHfS4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=sX/x4xtTJ9j2fUZbLY5/83dFXbc7fRJOvYrWAUso2nUEzKVPtVj7bQTUzxP05lPasL 5169POrmc/fmS5JCC/OzdqPtjCGtaeVhmtX3vb2+kdQCY+0BxId1vk2BbSBZthzoN6CC wdU0wr/qev7WzBtQFliHwDesEsJF8TIazEpuoaLXBnrM5vdovtouI69/1tq2wRB7pGj5 g01/96F7tZHS8gIR6I11uNAliVN9I/EP0rUI6SpSvrCuoiH6L6qIfhKMjKZdZcUloV+A 3Dx23y9U/s1nsHpeHLQuQFh62+/6eHSIRrUGVi6Ls2j38O0Tgtt12o+ubnC809hcmtxR Jf/w==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="I/bwgyfK"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MxDUhr0l; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=I224P18P; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4cb6f9728bbsi1282904b6e.133.2026.09.16.13.34.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Sep 2026 13:34:43 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="I/bwgyfK"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MxDUhr0l; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=I224P18P; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=SzP4EK6BBMrdN7pwMoPT5QIvaLPuDqRtacXN51gHfS4=; b=I/bwgyfK6LnOKZVprpX3oWVW/7 VT7Uxh6LkksBz8CMaIozYWNVhLljK8i+p8EmJqklkFFnVvCFbgYZQRU9jcnmghrTcMFkSJM98Kn6q dM9nFe3cxyMAdXbl6WnQVdtgNd9TE66uIjy4sb2/+bvKKPj/cAEOBZqpnSkn829Dow9Q=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x6wL2-0000sX-GS; Wed, 16 Sep 2026 20:34:40 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x6wKx-0000sO-Hs for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 20:34:35 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Dz5zre3qoD+aq1tG23h/KVZTvBuyCOD7qgFrTOzJofk=; b=MxDUhr0l6n5chd/LpKKmGPFmwv /40vaVbaHUAqmUydPjLCXtbSRQ62C8WI4DIn6q4o9Bd7o6iG8KRHd/UEAGgPX+popZovoEWeb6fL6 A8xg7PlShf2PqUYMtSwIEToXgFmMhOIRlR/V54tmn9MupKm74L3Sv/oGKKC9s1tQyDIY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Dz5zre3qoD+aq1tG23h/KVZTvBuyCOD7qgFrTOzJofk=; b=I224P18PYVw7yv0bV0oAI5fjo3 BTG2HzJJ3/nCZmIfxMM6ObrqaFU626bdsxbLlOyFE0E9AjIfhE18onzT+qmOb/yIRpxYFDq7t4IUF Ugaok3RLJ9vqC5bGgTU4jWUzD/2jtxjl7tqRiM82RN1YZferQN3Via0ToxMeJKXW2sEY=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x6wKu-0007yV-BI for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 20:34:33 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68GKYPHY021463 for ; Wed, 16 Sep 2026 22:34:25 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68GKYPAf021462 for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 22:34:25 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Wed, 16 Sep 2026 22:34:19 +0200 Message-ID: <20260916203425.21448-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe Change-Id: Ibf7238bade2aed81ac7fe4fda2af58e091dc8cd0 Signed-off-by: Arne Schwabe Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/ope [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x6wKu-0007yV-BI Subject: [Openvpn-devel] [PATCH v1] Improve auth token related comments X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876522050123252644 X-GMAIL-MSGID: 1876522050123252644 From: Arne Schwabe Change-Id: Ibf7238bade2aed81ac7fe4fda2af58e091dc8cd0 Signed-off-by: Arne Schwabe Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1918 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1918 This mail reflects revision 1 of this Change. Signed-off-by line for the author was added as per our policy. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/auth_token.c b/src/openvpn/auth_token.c index f928a41..b457b6f 100644 --- a/src/openvpn/auth_token.c +++ b/src/openvpn/auth_token.c @@ -22,7 +22,7 @@ #define AUTH_TOKEN_SESSION_ID_BASE64_LEN (OPENVPN_BASE64_LENGTH(AUTH_TOKEN_SESSION_ID_LEN)) /* We want our token to be a multiple of 3 bytes to avoid the base64 padding */ -static_assert(AUTH_TOKEN_SESSION_ID_LEN % 3 == 0, "AUTH_TOKEN_SESSION_ID_LEN needs to be multiple a 3"); +static_assert(AUTH_TOKEN_SESSION_ID_LEN % 3 == 0, "AUTH_TOKEN_SESSION_ID_LEN must be multiple of 3"); #define AUTH_TOKEN_HMAC_LEN SHA256_DIGEST_LENGTH /* Size of the data of the token (not b64 encoded and without prefix) */ @@ -34,7 +34,7 @@ /* Ensure that TOKEN_DATA_LEN is a multiple of 3 so the we avoid the base64 * padding */ -static_assert(TOKEN_DATA_LEN % 3 == 0, "TOKEN_DATA_BASE64_LEN is not a multiple of 3"); +static_assert(TOKEN_DATA_LEN % 3 == 0, "TOKEN_DATA_LEN is not a multiple of 3"); bool is_auth_token(const char *password) diff --git a/src/openvpn/auth_token.h b/src/openvpn/auth_token.h index fd8317d..62ac012 100644 --- a/src/openvpn/auth_token.h +++ b/src/openvpn/auth_token.h @@ -109,16 +109,14 @@ #define SESSION_ID_PREFIX "SESS_ID_AT_" /** - * Return if the password string has the format of a password. + * Return if the password string has the format of an auth token. * - * This function will always read as many bytes as SESSION_ID_PREFIX is longer - * the caller needs ensure that password memory is at least that long (true for - * calling with struct user_pass) * @param password * @return whether the password string starts with the session token prefix */ bool is_auth_token(const char *password); + /** * Checks if a client should be sent a new auth token to update its * current auth-token