From patchwork Mon Sep 21 13:42:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Frank Lichtenheld X-Patchwork-Id: 5393 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp11966851mag; Mon, 21 Sep 2026 06:42:32 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBxRU/+Q8IK1MzmJIs8Pm3tejW3dd4gq2XuXIKW90QyWAQ8GaqTOQxUg3WZC5owHbG0VKMP/QJAodIU=@openvpn.net X-Received: by 2002:a05:6820:4b91:b0:6cd:3ffc:e32a with SMTP id 006d021491bc7-6cd3ffcea03mr6922445eaf.72.1789998152474; Mon, 21 Sep 2026 06:42:32 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789998152; cv=none; d=google.com; s=arc-20260327; b=Wz3mQzcb+7JSBJ6HRoj0Re0kcdagJAh0Jz5QwK1Amy5xq48wXBYEu5zmiQtNNUoImI /grswNZcBOv/08S2prTqzMaQcLhH5D313050u9BfBqOQBGj61+xFoPId48q2EOV2zQec qUDSBrCY15UkJIUNzYYqvkU4gb6D7WgW7isYLVRkf+lDAK10mtDNx+8XDDvt1I9gWK4c ugjL39QnUQmi/2NKxILWRE2zojZ+n45QL8uZtx3kOvdujbp4++1AmQNtjmOb+mavyAhx Jr5SRx8a16+8lubEKgVKQKUfcVUk1ADQ0Vue26ip8HmO3anfExLDtST0HILdKi1qkRC6 gNyw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=33+WKALIHey+9NTWQPfSM8gghAUMUZr2jToA99A+4Bg=; fh=MKmPM5ODifyhFxT1B+tttKj00bmm4fTLfUX2a0zL790=; b=qVl2pBgTg0oUrK0gY7IckZ0wWdon/y8iN09y1/5Ka1rI27Hhd4A8FK/iAf8JNQNI0W XWehHOZRslRPteE4TWOm+iaYzQDlZwfN9D+6H+gZNplKiIt45EH1K0bPQ6Ix5NAlI0CN mlfRSBaBHsFv2pBERxnzMChhjZpGPYBzvySAvV3GNTfJCZfvkyFDegFZZ0CUxdKzdgyM A33VG/OekJiBeMS7XSXxsY21xbQSfMetoaa4uLnVM3aBR6Sxj8XOVXZ+aLQEbw2W7F8K xn/4haWqYofVtW7LR6Afal0W4Qd2YMQuBpuDK/ZFImRPA4nLPJk4j6sJT6aF3xjqxBJA JyOg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=QaDk5176; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=BLH0wB2g; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=A8MyGzAp; dkim=neutral (body hash did not verify) header.i=@lichtenheld.com header.s=MBO0001 header.b=RDgDQxSJ; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6cd3631080esi11399412eaf.34.2026.09.21.06.42.31 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Sep 2026 06:42:32 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=QaDk5176; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=BLH0wB2g; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=A8MyGzAp; dkim=neutral (body hash did not verify) header.i=@lichtenheld.com header.s=MBO0001 header.b=RDgDQxSJ; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=33+WKALIHey+9NTWQPfSM8gghAUMUZr2jToA99A+4Bg=; b=QaDk5176gLvXPmETb0UTcW64zf nUKPA5gWSLDGzjJtrebD0hO18l7x2rPFlsiDa/vUXyUnjdcKNh58BKWePB8fQOmM1NcHq2sZ4VrNK gfQRJINSzjA53VNLkEW3CBK6XkSqFHT+NyHLz3XvODwa2pRsFJmcfNN16ytQkgYvktR0=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x8eHo-0005vE-Hy; Mon, 21 Sep 2026 13:42:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x8eHm-0005v6-5R for openvpn-devel@lists.sourceforge.net; Mon, 21 Sep 2026 13:42:20 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=x3vE5kky+PbQxIPpsKQjt1gkt/FmC4EOeMTm4GRVk4U=; b=BLH0wB2gwtsIIDAFxbW0W9eZoA 1M0NW8ZCqQq4E4ttBBTOxfa3j+thtaH+aXaQYnONAjmK4C3IiE+ucPlZ4LsJ5MT++14iItmMO39R5 zBnj4wRyBJ0yfcanP3m3FjeldK1GxNz5NQxEOtamleBr3ciV0ENa7163a4mxR5Q3XUj8=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=x3vE5kky+PbQxIPpsKQjt1gkt/FmC4EOeMTm4GRVk4U=; b=A 8MyGzApC4WsJHrJ4/VBFsgcWhkrXTYE2FdLm+PGseHwVwz9GxrJIm3zC6eDttQjHK/6Cr8ml1euYp bvgHiLfcE7+9ffaa0NQi2AVrt0ZY3YpIHJEwtOYGHcN0uG8sCSRcfV/xKX9oLMgwawqmUAjsXyQ1o cNQX3z93kR6kSjoY=; Received: from mout-p-102.mailbox.org ([80.241.56.152]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x8eHi-0007oy-9t for openvpn-devel@lists.sourceforge.net; Mon, 21 Sep 2026 13:42:19 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-102.mailbox.org (Postfix) with ESMTPS id 4hpPXy3lhrzKmRL; Mon, 21 Sep 2026 15:42:10 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lichtenheld.com; s=MBO0001; t=1789998130; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=x3vE5kky+PbQxIPpsKQjt1gkt/FmC4EOeMTm4GRVk4U=; b=RDgDQxSJ70n/IMEwCpy3nUuhduflPRNcFwG4fp9EtpoTL/qZ0PvdEseCXmcaDhNfmpYRsJ xJTqJex6+jDrp0fmgClnQVnETszBueyRNX0lRZENDjylc0IDvmKtWQGcCcaq3YSpjP47Hv 3I6Xcnt6lmeYZ2tA3hwfuE26YkRl0wcVJmih8IbjHxfzxRraczl3xd43MnFFLYYNdvVkgN UXMcmVSfLMQ/OAli6yfC19es4uJ1tH3iK/g6d9AuiBxoBBpjQ9lG6ZqEwwRbTAkiiX42LU YcGDc9VFtaHWm7eFJZtGQi8YKdfR0EdWgeQeU9QhKlfZCSFazYbgwKI9KCT98g== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of frank@lichtenheld.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=frank@lichtenheld.com From: Frank Lichtenheld To: openvpn-devel@lists.sourceforge.net Date: Mon, 21 Sep 2026 15:42:08 +0200 Message-ID: <20260921134208.54064-1-frank@lichtenheld.com> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hpPXy3lhrzKmRL X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Sarvagya Chaturvedi The client-kill command in the management interface accepts an optional message parameter (M), which is sent to the client as a control channel command before terminating the session on the server. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain X-Headers-End: 1x8eHi-0007oy-9t Subject: [Openvpn-devel] [PATCH] doc: document optional message parameter for management command client-kill X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Sarvagya Chaturvedi Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876949102763753116 X-GMAIL-MSGID: 1876949102763753116 From: Sarvagya Chaturvedi The client-kill command in the management interface accepts an optional message parameter (M), which is sent to the client as a control channel command before terminating the session on the server. Document the syntax of client-kill, the message format (RESTART or HALT with optional flags [P] and [N] and human-readable message), and the resulting notifications emitted on the client management interface. Github: OpenVPN/openvpn#1096 Acked-by: Frank Lichtenheld Change-Id: Ied848552f6e9618ca6541d74e20aa1d340027999 Signed-off-by: Sarvagya Chaturvedi --- doc/management-notes.txt | 27 ++++++++++++++++++++++++++- 1 file changed, 26 insertions(+), 1 deletion(-) diff --git a/doc/management-notes.txt b/doc/management-notes.txt index 11264684..412b79bc 100644 --- a/doc/management-notes.txt +++ b/doc/management-notes.txt @@ -828,11 +828,36 @@ COMMAND -- client-kill (OpenVPN 2.1 or higher) Immediately kill a client instance by CID. - client-kill {CID} + client-kill {CID} [M] CID -- client ID. See documentation for ">CLIENT:" notification for more info. +M -- optional message to send to the client before termination +(defaults to "RESTART"). The format of M is: + + RESTART|HALT[,[flags][human-readable-message]] + +RESTART instructs the client to perform a restart (SIGUSR1). +HALT instructs the client to exit (SIGTERM). + +Optional flags in brackets: +- [P] -- preserve cached passwords and credentials on client (avoids purging auth). +- [N] -- advance to the next remote server entry in client configuration. + +If a human-readable message string is included after the comma, it is +logged by the client and forwarded to the client's management interface +via a ">NOTIFY:" event: + + >NOTIFY:info,server-pushed-connection-reset, (for RESTART) + >NOTIFY:info,server-pushed-halt, (for HALT) + +If the message parameter contains spaces, it should be enclosed in double +quotes, for example: + + client-kill 1 "HALT,Server shutting down for maintenance" + client-kill 1 "RESTART,[P]Reconnecting to update configuration" + COMMAND -- remote-entry-count (OpenVPN 2.6+ management version > 3) -------------------------------------------------------------------