From patchwork Tue Sep 22 14:05:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5403 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp13347803mag; Tue, 22 Sep 2026 07:30:53 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvByK8FxjaF0JLUpGwggWwqr+mODu7Yvha8dLPKvylbjtUiM+0UnZA7OM5q0P4oydq4sZcjwcl0RQcUQ=@openvpn.net X-Received: by 2002:a05:6870:f09b:20b0:48f:e25e:e202 with SMTP id 586e51a60fabf-48fe25f137emr786033fac.61.1790087452907; Tue, 22 Sep 2026 07:30:52 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790087452; cv=none; d=google.com; s=arc-20260327; b=nbBHmI1Q/JwH+zOjZzUWmJf4CwRpGNEsi2MrwvWL9d75CjWHGmolVMmr7rlns6Qn4X 5qwxY5CxWFZRVW4loDU70VkhXcm3JXrJhoPK/Ffs0NwW92gNoXN/U9L3vLlEGtASjFZ+ CcwO51pWHTgDzEcZGbJ94fR/ekIUxfbECvcAFvz0Jp8Cfmtvh3Y9MdG/bfjlfwFctY+E 92MJg4stE/sqMH7DvXViaMAN8ajChFT7SoRXsMTs7QbM8kDvGbzuH+KTol9WNp3mDHY4 FmbJ2LmHFg17e0pWII+9eUTL/2Z2EtZD45X2tJ0e6IB48y7e5V5X4N0g+or4Xwu+kZJn e7pA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=UjJLGpEFvi4gdiBD0qFmd4Y+CurZLRNFPn/A8ci86Wg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=j5x8vrvy0oo76KqZ4UZw56Wpt5vY67P40B31eNf5PNp9orz+9RAtvKr+c/6DgP6YLW Ye/bxThoNywOiIJoGYUd0+/etAt5QXRjViEK6tcpheITtrE8h3OW2FWrY+9fIyVAf7WC as+/oQlsIeJxERgoNUR4W0sliHpeCwErKQmWpsiFXUF5r9duPv5v6wsZWcc7t4jbg/Dj KAR9lxmkHHtrUxmCLtKsD/YJvUQ+I63UnzrdAVpzGiBkztu0qg9pJWQDGyvH50xKSIek BfNDQEt5fGZYacZHw09yMjqViAsTDTxUe5n4FZhjv7t65RCfDxAYewRtbBCWndo4ktep U+rg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SdqZPXgB; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=X5YPEJw2; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=FGv+65HK; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n9N4zEng; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-48fbf35a64bsi1903658fac.183.2026.09.22.07.30.52 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Sep 2026 07:30:52 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SdqZPXgB; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=X5YPEJw2; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=FGv+65HK; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n9N4zEng; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=UjJLGpEFvi4gdiBD0qFmd4Y+CurZLRNFPn/A8ci86Wg=; b=SdqZPXgBr7yElByq0xZJ8uq6to Nxm7bXfZvYWdzSnJzPoOy0NIpKiFbb61KSdHQQ419azIIMagvXwaIATRbinm253kpMAkf+8z+sRKc H0dvZcV0l3GawHBuxtdDQAEVC4GsEET6PXvLWM7BX/Q/uYxHTndaCgnSj3bQ9/Mcl1t8=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x91WC-000323-4Q; Tue, 22 Sep 2026 14:30:48 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x91WA-00031v-Gw for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:30:47 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=octz7T5lr/Zu8b8f/b46E9fy3nyXMxkGosRd7FG4Osk=; b=X5YPEJw2qbBkaxgiBoy4spDIm/ /dli5SgExbDo+1T2opOCKYe0oJEP7fRUOPgQ1A6Ogzkwe8KOgyZh9akgno189vWYGmfGxZorljzQf jIHX3V1hGh1gQer6Uky5Fi5SyJQtw/Az6VFjIckH7t6BoMXH0Lgm+31RcN9hEtkOnpFU=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=octz7T5lr/Zu8b8f/b46E9fy3nyXMxkGosRd7FG4Osk=; b=FGv+65HKlUhAWPdnr8rrZ67h5t 6Rw7MYLb8osQURZBzwzgHhTSD/KvwaGTWjWg+Yuupak0BR+A2VHEff4HSfH6/ClcHkGmMLUhmvI8u nF01+ld0sptS0JLsPtabt6nmpWr+VcrrPGhkb3hw+Xewcp/mSOUtMhvtPFaxghJZpKRY=; Received: from mail-qk2-f12.google.com ([74.125.230.204]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1x91W9-0002cc-FG for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:30:47 +0000 Received: by mail-qk2-f12.google.com with SMTP id d75a77b69052e-52fb76bcb1eso8091941cf.3 for ; Tue, 22 Sep 2026 07:30:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790087439; x=1790692239; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=octz7T5lr/Zu8b8f/b46E9fy3nyXMxkGosRd7FG4Osk=; b=n9N4zEngm4A1HZx9+6YctMVAYJGhcKAE40a7KuD4zEN6gWNUE718wrJY5SWU2UJFPq ywwHX/cXsrukW36RCgixduifnnimSo8oKUawROPDlG9LvdVoWZqeirItL2amlDumwIlP ELGVS7dPW/Z9w6VXnA1gSZjXaxsbhxH9ViTyqwkNVsavANwVwiofRL58u3CVE4YMMgIx Y9WD1Rvkez+yxI4PqNxAzNNdEuv9PyzoXdA28ZG4R2TVT685RuAT0DASBSvp5QiH2GqM WqbjUUoO4AV9Wnip/mSx6vq7piVDnu30s1PRIE1idP9XP7Er1e1u4ACFY8Y4KtHW8RQW F3mQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790087439; x=1790692239; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=octz7T5lr/Zu8b8f/b46E9fy3nyXMxkGosRd7FG4Osk=; b=wAgQrm9uUSfzszPAixFkcEjRjKUNmXi3kmZdbiUsnLr/Oaok3G2kdMGmzG/H9pw1dG T7Jn87Ail7DJXBS6Kgg8ZP5+V35dcVwPhIDn5b0S+5asY/lxJ9pLEyODuHrnesMVqwH+ UP3mB3MX6mSXcIW8QRlRutQITClsJQOHMZCDX4E+z2iqC9VUCE0CtXSO0zp598ZUSwfS 3qFC+ph14lMYX2Ft334RsFTnUJjQu40Gh6mkKANh0phcAnIumPZbT7DneFxYe0BLfGAE 6WOAspj+kgHsxgvpQm4CdK180dg1jdmHbfkjDVM6Y+oYjYlxLNMkJ3BASGALF9C9hRcB KOvA== X-Gm-Message-State: AFuF++lRACFBhlE868KY41ePdMPOU5iIS2vg2jAKpsZUrkCsU8E8tMA3 O+wMbLIWT9JQdrMtMCTJNfUw3qXbliv9HGSgOmkvSNSZavcCK/frEG+Y0DPV8f5Wy0e9yrBMCZ/ 8ObkBKHs8 X-Gm-Gg: AYBFou2ELtuUe0XnUM03shyBgTTy7aaGNXlYM3ZlSuyebNfotl3ELVt+p6eIyUwF8XI Onr7KQL3zq930OLLO4VG41MlrGkcM5Y3nY4qO6JzAFeDkCSYqGgfNbijhqIUhW9vZQz/b4xZj73 r9X/oB41j9oa/2aHdyaTejfnK20eHQsYPeDy1UmWEXTUQCzB8MlPQOai49o9kezoz4aPUwfKbG6 ya1Srm9NLzlzh/Zm1WE4aYPj1xtLorDyb968VzWhUOo40a/iPtV1nZeE2GjU8y3GhkDjP7DFwvs iDyFOkcfq+zRFh+ZfPRtsyrFFPRUGGKH5/P3ZaM1VAM8DOQ2scgHSLWfYtNIFDU9s/zdbBp3CKT 4xs2SvkB+lgJ83n0R998kKathAS7Q4zlx38q5v8uND7Q5PzJ0FBW1WpzxNa9CnqniJ5JyuVb3Bo WMAK8bmA46qLGQBPci6ig24iLV56teDtXYJT/HfijqrmnTBnmwpmGD4McjKIp5SFT/KM9inc0uO /Iuq6H5xFn9q+E21rHAEQ1SqqkJQTpU9vJh+xLcUNqpjI21vXkg073vK5YwfRgzR3XN4Nxtfw== X-Received: by 2002:a53:ac9b:0:b0:672:99e0:ebce with SMTP id 956f58d0204a3-67299e0ee21mr3124476d50.102.1790085924719; Tue, 22 Sep 2026 07:05:24 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-672d166300asm230404d50.3.2026.09.22.07.05.23 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 22 Sep 2026 07:05:23 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Tue, 22 Sep 2026 10:05:19 -0400 Message-ID: <20260922140520.71500-2-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260922140520.71500-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: cipher_get() looks a cipher up with EVP_CIPHER_fetch() and hands the result, possibly NULL, to callers that only care whether it exists: cipher_valid_reason(), cipher_kt_mode_cbc/ofb_cfb/aead(), ciphe [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.230.204 listed in wl.mailspike.net] 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1x91W9-0002cc-FG Subject: [Openvpn-devel] [PATCH 1/2] Drop the OpenSSL errors a failed cipher/digest lookup leaves behind X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042741064284915 X-GMAIL-MSGID: 1877042741064284915 cipher_get() looks a cipher up with EVP_CIPHER_fetch() and hands the result, possibly NULL, to callers that only care whether it exists: cipher_valid_reason(), cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), cipher_kt_insecure(). A failed fetch is a normal outcome for them, but under OpenSSL 3 it also pushes an EVP_R_UNSUPPORTED error ("digital envelope routines::unsupported, Algorithm (none : 0)") onto the thread's error queue, and nobody pops it. The common way to get there is not exotic. A server that does not set --cipher gets the legacy default BF-CBC, which is not in --data-ciphers, so do_init_crypto_tls() initialises the pre-negotiation key_type with cipher "none". Every new client instance then runs init_instance() -> do_init_crypto_tls() -> cipher_kt_mode_ofb_cfb("none"), and the frame and OCC calculations (calculate_crypto_overhead(), frame_calculate_*()) walk the same key_type, each fetching "none" and failing. cipher_kt_block_size() adds a second case for AEAD ciphers whose CBC sibling does not exist (CHACHA20-POLY1305 -> "CHACHA20-CBC"). md_valid() has the same shape for digests. The stale entry then misleads code that classifies an unrelated failure with ERR_peek_error(), which returns the OLDEST queued entry. The visible symptom is backend_tls_ctx_reload_crl() logging "CRL: cannot read CRL from file" on the first handshake after the CRL file changes although the CRL loaded fine (GitHub #1103). Traced with gdb on OpenVPN 2.7.0 and master with OpenSSL 3.5.5: the single entry on the queue at reload entry is the cipher_kt_mode_ofb_cfb("none") fetch from do_init_crypto_tls() of that same client instance. Bracket the probing fetches with ERR_set_mark()/ERR_pop_to_mark() so a failed lookup leaves the queue as it found it; the return value already carries the answer these callers want. wolfSSL's compatibility layer has no error marks, so openssl_compat.h maps them to ERR_clear_error() there. With this change the error queue is empty at multi_create_instance() and at backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305 clients, and the spurious warning is gone: three CRL replacements, three handshakes, zero warnings (unpatched: three of three). Signed-off-by: Drew Blokzyl --- src/openvpn/crypto_openssl.c | 16 +++++++++++++++- src/openvpn/openssl_compat.h | 18 ++++++++++++++++++ 2 files changed, 33 insertions(+), 1 deletion(-) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 29c5fa68..575db985 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -569,7 +569,17 @@ cipher_get(const char *ciphername) ASSERT(ciphername); ciphername = translate_cipher_name_from_openvpn(ciphername); - return EVP_CIPHER_fetch(NULL, ciphername, NULL); + + /* A failed fetch leaves an EVP "unsupported" error on the thread's + * error queue. Callers legitimately probe names OpenSSL does not know + * ("none" for the not-yet-negotiated key_type, the CBC sibling of an + * AEAD cipher, user supplied names) and only look at the return value, + * so drop whatever the fetch raised instead of leaving it for an + * unrelated ERR_peek_error() to misinterpret later. */ + ERR_set_mark(); + evp_cipher_type *cipher = EVP_CIPHER_fetch(NULL, ciphername, NULL); + ERR_pop_to_mark(); + return cipher; } bool @@ -692,7 +702,9 @@ cipher_kt_block_size(const char *ciphername) strcpy(mode_str, "-CBC"); + ERR_set_mark(); cbc_cipher = EVP_CIPHER_fetch(NULL, translate_cipher_name_from_openvpn(name), NULL); + ERR_pop_to_mark(); if (cbc_cipher) { block_size = EVP_CIPHER_block_size(cbc_cipher); @@ -1001,7 +1013,9 @@ md_get(const char *digest) bool md_valid(const char *digest) { + ERR_set_mark(); evp_md_type *md = EVP_MD_fetch(NULL, digest, NULL); + ERR_pop_to_mark(); bool valid = (md != NULL); EVP_MD_free(md); return valid; diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h index 098bdd56..3029f7ac 100644 --- a/src/openvpn/openssl_compat.h +++ b/src/openvpn/openssl_compat.h @@ -47,6 +47,24 @@ /* Define the type of error. This is something that is less * intrusive than casts everywhere */ +#if defined(ENABLE_CRYPTO_WOLFSSL) +/* wolfSSL's OpenSSL compatibility layer has no error queue marks. The + * callers use them to drop what a failed lookup raised, so fall back to + * clearing the queue. */ +static inline int +ERR_set_mark(void) +{ + return 1; +} + +static inline int +ERR_pop_to_mark(void) +{ + ERR_clear_error(); + return 1; +} +#endif /* defined(ENABLE_CRYPTO_WOLFSSL) */ + #if defined(OPENSSL_IS_AWSLC) typedef uint32_t openssl_err_t; typedef size_t openssl_stack_size_t; From patchwork Tue Sep 22 14:05:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5402 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp13347533mag; Tue, 22 Sep 2026 07:30:41 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwxR9ZT6rnsBCLhBR2+yECyodYMSfCem5U7/UN9n2eaTk4QknslGVNqMSC9egXn34wCJHPOybXlbXY=@openvpn.net X-Received: by 2002:a05:6820:16aa:b0:6cd:3fdc:a92d with SMTP id 006d021491bc7-6cd3fecc3ccmr9230124eaf.74.1790087441378; Tue, 22 Sep 2026 07:30:41 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790087441; cv=none; d=google.com; s=arc-20260327; b=HbKh7XrR/Odb/vFLdExR9HzHEd+zXlC7iPKLryXJN2lWmZ03H7B+38a65YC6P90PFa xUx4PLd1U/WeguZL8aw+zJUUdZHxgjClr1rfGgFae1F7PLsTu44l0yJHRdLclEFpom7l ZAfhTicifpZxfMHsKNwuEUPnKwwX+Fhl45tG6vJenGR1uhmMTPWE6fB9q9FiH4mOn+yg D1MO/I2HskqOjmQSQ/gpe44MdHWIcTYwnps9sMXIY9E0dCRUKXG/SSy/JaqsmoBpoez/ mLSZQKQGH7afvjxshp52LwjGEd5GHz8UCvKI2mv4W09IIotrn0y5Iw31HXEK7/exv8D2 +0qg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=POQa8PrH3aMxD1PUqNuXqUk/I8HkeXxhfyAA61Ab9yR/0A9D9VtGeglbYl5eLtJhCr 0AxQJ0Y/uI628lMajgUM8pr6ubYzrWjAWnoxbREwzdVq/jVcD21+ZTXuMLFCwqT5lT+E 5v41jcFgU61mcG5fqFnAjleufTjmV5tl46lKv6ktB+HAdQGPeW3b713V0hC/Nj1rtgzY 1+QNtsxDloLGD85nuaZKsRn8vN7sbmpAXGVICF9ArDq8YUUOF45MlG5Ed0vi92DMksUf fg2rPKCsa+/cZ5jXjzJoAd9SidBrVLihAP8LOadENIN48BYLnn6HRHF1SiKf8v038X1P zcHg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SXZwoI5z; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MCsbQxVN; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=YveeAS3z; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b="U0M8qZ/l"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6d1de001041si2121854eaf.29.2026.09.22.07.30.41 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 22 Sep 2026 07:30:41 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=SXZwoI5z; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MCsbQxVN; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=YveeAS3z; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b="U0M8qZ/l"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; b=SXZwoI5zMA/nKMjJ4oRgcjLn3B wK8e5oQRVz6mj710n7QR0ZEdecXhJJBYWUhqadjF+nGXsnWgi+Gumgn/HZNeD7MgEsUFB0XMuxZ9a ziU8M8H10ZQ95YL3sqECpYek5kNoP+H9DQmmvqfHJJtfkxup65ycm5vY4/rmpVUcDAng=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x91W2-0006BJ-BD; Tue, 22 Sep 2026 14:30:35 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x91W0-0006BD-Qs for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:30:34 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=MCsbQxVNLrOJG+Dzp30logm4P0 f/Z8kwZ450jmQJ5v8ZLv+ekEeP2P5mvw6RqSGauxRE3WWiBZct0YlsjjKIso6lMO+ih2vyAlx1WGS gQWtHdDWNTiEdiRSXL9lKKZ40Y55GZEwvCZ+ILtfAMwId824jFumZ3vj6KfoBj/yAlLk=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=YveeAS3zJn0hexRtLekYxDWDFH dn7YqGHwkRmaplNDg3h2PZWO4jcdUlktcAL+lsuvqfmN7X6tQMYFzOp8ofcohCff8uITLyaU9RO8V Gvr+Z2ZEu5WMm4sUg/W8dc/qoeZZsXvUROCuQLY7rzj8i3hwuVKq+db+5NB4sI33S+9Q=; Received: from mail-oo2-f41.google.com ([74.125.231.169]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1x91Vw-0005h9-Vy for openvpn-devel@lists.sourceforge.net; Tue, 22 Sep 2026 14:30:34 +0000 Received: by mail-oo2-f41.google.com with SMTP id 006d021491bc7-6bc475ffcbfso1395606eaf.2 for ; Tue, 22 Sep 2026 07:30:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790087427; x=1790692227; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=U0M8qZ/lIcgUQWC20Cf4nRLsCWHVDlHkHH61GX7KLHIFKAyXFKuwvB1qfBvPopbvRB eAH3NT9zlq01/UxK+AicrBFBsHYJDfKXTur446W0wlCOdSTZslGFSs5CKyNBef6V5ryj hVK+W5aAiAXn8vdnGtX8X2SkyxT7l6xnW0haYOSJXPacSRGmkN1cY8JtBhDIGKL4/DJe aq4mbLknlsjYYdzayTe0l7fojjJ8p8oZ4ekR8+nkZw6VZJDGdeSc5A5MjAV5Z7W1DpBW dbH91PmFl1lmmKEY7r/VV62YljgJDVqRGdBqU28H95OvY3jzn3XQ1UiaKmZ4CrgvhIlO b2tA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790087427; x=1790692227; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=gIRiBQnDqG/jtphsBAOonir01KXHhWx7ZubbvihhHZhYysYPGPMHjTWXk57ouY7g6l JN1yZWznTiE/SKuYDuWRwq1LR0wFLzr5rLMc/j0GeiwXQzCWAX6Bnr5miGpqkYL52D/D 00PAN6eAlTVIKj2VeNPm+xvURcLX0yIw13vdGJyg2NQayTyPr/y+z6m+JCBs8o+YGyiA TE809iWP3TuqpwFf4Lt6BDKgeIfYmanM9rFRgHZotliRqPSFvHnUoB8NtGvbIuJSbXSv gw9SW8keGlUIS6eJUGITetw5sVGHCeXvljYB8LqEprNqXRsfcVbz9+M89crbxCAHCdcV u0oA== X-Gm-Message-State: AFuF++lBwAoVqgqW0f0fMstFIfM+RSN1qp/Ao7YJOEvFgDuPBhDlU9RX Z5YbwhSOk6WF0C8Q/ARm3u8v7CZANTvGCqlwhms8QcJ/4az+Lf0Dxw0bjDk0ND2Vb70fmN+4b8y h7XEL3F19 X-Gm-Gg: AYBFou1s4GtCAuT1zEDfnvwn9vqJ4h26V/pG5WHi0r6KKW5W9qYnMvdT2knJuyL+c6Z YxLwDyKTPuDBmkxpJ7whCpiNDwliS2+Cb+ekjVjVfRv8WNr+MTqWCR3U982yXROPA6A5AOlXPNL vzDe4nYE/wCAM0KLD628nUkvrhjyAJlQV7mXIWCXsqHm8NyZMyr8O6i5gk2cGdFAdx1la/Df5M9 Jl04g04yE/6Vhh8a77ElEmJPYY20TeMay0xr5tNSMSJngZYj7Cm5DexeBapO8ZBbf96PocEnbM0 97t/+R3+UoLZPsszUD6//dFQnKGQCcddlBevH7KQEYQda6p/wrOcQJU9Z0I7BOkuvpLiT5nj8/N 8G5lvBfg4ErpsvSr+lkMR9pSLYCk/XlAN3J0DksajwtTNWNMKIsslm33MNyWsnrl+QjNq03wNl4 9hnVTursJosuiUGWAyH9Qd5OEGZDzmIhxPS0q2qI09lLTDpxmTFoNLqfmpcR4SaFWqRdQgN/n2X YAuG5JQF0pZpqW9lkk5PJ9q5/ygsmG1lPRqZgT06R/eMsfYTAWe1tOAgf4cYB0= X-Received: by 2002:a05:690e:1511:b0:66c:ea12:95d9 with SMTP id 956f58d0204a3-6717fcaa502mr4295285d50.22.1790085925678; Tue, 22 Sep 2026 07:05:25 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-672d166300asm230404d50.3.2026.09.22.07.05.24 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 22 Sep 2026 07:05:25 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Tue, 22 Sep 2026 10:05:20 -0400 Message-ID: <20260922140520.71500-3-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260922140520.71500-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behi [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.231.169 listed in wl.mailspike.net] X-Headers-End: 1x91Vw-0005h9-Vy Subject: [Openvpn-devel] [PATCH 2/2] Make CRL reload EOF detection independent of stale error queue entries X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042728496797502 X-GMAIL-MSGID: 1877042728496797502 backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behind earlier in the thread turns a clean EOF into a "CRL: cannot read CRL from file" warning, prints the unrelated errors as if they came from the CRL file, and still installs the CRLs already parsed. The previous commit removes the leftover that triggered this in practice; this one stops the loop from depending on the queue being clean at all. Start the loop from an empty queue so only errors raised by PEM_read_bio_X509_CRL() are visible, test the error it raised last rather than the oldest one, and clear the queue on the EOF path instead of popping a single entry. Signed-off-by: Drew Blokzyl --- src/openvpn/ssl_openssl.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 7cfe9f4a..da3e07fe 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -1360,6 +1360,13 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b } int num_crls_loaded = 0; + /* + * Start from an empty error queue so the EOF test below only sees errors + * raised by PEM_read_bio_X509_CRL(). A stale error left by an earlier + * operation in this thread would otherwise be what ERR_peek_error() + * returns, and a clean EOF gets reported as "cannot read CRL". + */ + ERR_clear_error(); while (true) { X509_CRL *crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL); @@ -1367,13 +1374,15 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b { /* * PEM_R_NO_START_LINE can be considered equivalent to EOF. + * ERR_peek_last_error() is the error PEM_read_bio_X509_CRL() + * raised last; ERR_peek_error() would be the oldest queued one. */ - bool eof = ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE; + bool eof = ERR_GET_REASON(ERR_peek_last_error()) == PEM_R_NO_START_LINE; /* but warn if no CRLs have been loaded */ if (num_crls_loaded > 0 && eof) { /* remove that error from error stack */ - (void)ERR_get_error(); + ERR_clear_error(); break; }