From patchwork Mon Sep 28 14:37:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5414 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5189:b0:8b3:6e77:b38b with SMTP id g9csp3382909mae; Mon, 28 Sep 2026 07:46:09 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBx4JVdaOiCLTBcQkOD32HgXP0NOws3R7A+BpnvdIEbMBbgMKMbglATlXau2jrrVJkzUFOeCvdLkqJw=@openvpn.net X-Received: by 2002:a05:6820:4df0:b0:6b1:bbc0:b69d with SMTP id 006d021491bc7-6d43e31f93amr13584770eaf.15.1790606768933; Mon, 28 Sep 2026 07:46:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790606768; cv=none; d=google.com; s=arc-20260327; b=nDjXgaH3TlmXuAjs1EOTgKwEzJOJYrajkJJz8SvEmHoqL1iZHFRD4pq1NVaMdWFV4t RmuKIYDCGMGXtTRPRhSDAiTwlwb8Uv+YpBVbXKSbB7yuskeKEZIDiFL5G7nqgw5/LEhe xdyGcesC9eEArQw2/vHU45SEzSkath510HxRh84LYdI3iXUN/MbQTmHcGUX34OJrxVRy KfOJOm1/UqI5f14wNlCYk24qyoelUZWH0+83wIhsiitvskC/T7bPxY80z1MaVjDzowBn FLZHNiJCJWI0vWhroTA0L9ZNyG3KbJLJmbczlsATEXxxpCnKsdmy01oW1+2klyyPwiDC dWsg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=ubwv8sQCBtUxlVe6TEIWvSv/wo6vepSkvl6b2/OQGGw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=fonUHBDNc1h8HmXU9iSeirWpR+hhx+wJHYphMbAXzCBmU0bnYkWO8Fu9u/UkLGyxJ+ qUjZ4R9mSPbvVrwnprJoQ2A7xWVc+SyXT7j1uDQimMBH65KKhzvAP+59+gI8KvYCpxa6 Y69OdsMZUT8rdCXi6ynHjymtKJhQYLg8Nkt3gMuzCyGElzLxv1OTAaxjZPWzdAIVpRCd zXQuMTVcv/I7JdFKQY1t4DcMkq7HNt62QmcPaObF1xwfEe3PYoxPOwICSCpvnqPG8VJG tvFjKQDJwpaMeam5auo2JUXz348BQWD9PidIo+/pGN5blld6/G0eXb88LL9bBum+HY8n P9ug==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=BrQT+sRm; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=BfqxoDsy; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=A3C6YBmD; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=Aa35q63l; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-81d58c0a46csi3134903a34.78.2026.09.28.07.46.08 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 28 Sep 2026 07:46:08 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=BrQT+sRm; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=BfqxoDsy; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=A3C6YBmD; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=Aa35q63l; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=ubwv8sQCBtUxlVe6TEIWvSv/wo6vepSkvl6b2/OQGGw=; b=BrQT+sRmKANTVghK1RBpUTak3g CJb8V4lhEkjEKUrn7H9V2R2nl2asgO09SrKyz8+TGzuxYNgYWZcfe6DA1mL3hG6C5lgUBOBY2Yfew M79EsaKim46Qt1i5xnpT4VNjKCsjokXCs/yEoOPUr7WbWZBdEq4T3PKMdHw8dcmiC2R0=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBCcF-00045H-Qp; Mon, 28 Sep 2026 14:46:04 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBCcE-00045A-Py for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 14:46:03 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=dszHu+a80WD1wZlGP3DaK3girbMHUPD0OAOLqbjzBSs=; b=BfqxoDsy/pT0ZmXJrnONXvxsT5 MnJKmq26H2+i5eCDT7Q+YwyKeVY8O/iINtHvmjLefQZI4zgt6CR8DUU++OKutbChNvb616qmSFoD+ m+/tcB77bHEmRypH9vG6Mht2OduaynJfm6qS+DLarkVWAwBZJdhUUev2m5WKvryI429Q=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=dszHu+a80WD1wZlGP3DaK3girbMHUPD0OAOLqbjzBSs=; b=A3C6YBmDb+tY+WEfL9hMXqrmFD YfE2YRSSCb+1eoOYqtLZIzi6IIXznq2Ypwhh2HUvlLladjJfhIPukzy3uAWc8rLTnI38TQESY9fMN gwfG1B/iP4w8lm5nbJEyry5BCMi86uMYKKfghLgQzSw9UdxOA+muY13CX//PgXJA87TU=; Received: from mail-oo2-f38.google.com ([74.125.231.166]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBCcE-00079o-Q4 for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 14:46:03 +0000 Received: by mail-oo2-f38.google.com with SMTP id 46e09a7af769-81bea216172so813397a34.0 for ; Mon, 28 Sep 2026 07:46:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790606757; x=1791211557; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dszHu+a80WD1wZlGP3DaK3girbMHUPD0OAOLqbjzBSs=; b=Aa35q63lKQqKi3G0UO//hHDjZPqGLag3OQpWwc8M0/uXQFaKbLvfOGWivJvnWtryEz uUikaNVTsl6ub7dOpMcaBb6On4NX48DxZS+bdWCG/P95IqKEyco4KiMY8tEsZxXUeM6n jIw6v2r23kPg453a+KI1MavoEJYBnvD7lHX9qzIr1wXffzrsszLx8Y196+jPOHKGqmcp dMOgOoIbmVBELaLlOPxaakDg2qhLgaF2sWclgLGtEuU2/nZARC3RjftnLiKX837n/cQ3 HwQEdkyDirf57eKtVZepkE9Zss/Q2udYlExGuZ2jr8qkE4CAhxE9DIqN1Ta5rzyapGDC Ou8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790606757; x=1791211557; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dszHu+a80WD1wZlGP3DaK3girbMHUPD0OAOLqbjzBSs=; b=WL1U/AQVdoM2hS0/46zm+TlTnDmMX3NOFGOy4jjmJ/BD/0nvaxx4eol7HqayB1pIoI fm1ozTgj+GCVV8QznrLb28JIaSTvn4vpePd80EDRdwprRJ5Yp/PuzjnK+wE+UxB8E6tw t3qmDWbz7Jz9hVdud5ox2mcA4CojAesavgi9ZrqfDEkrgH+bWDwVkyYwa0sSKZQOT2tX jGto3lbUrhzyqSNT30Ta6oXptIoTdUWKgcYWqIMuAtL33HyI8VrmC8mumjEcIY6FIQIi xMqomWccB/nG9ZzirB947nbIzndR8Iez7lx3trEJKJ/LTIa/SCGxrgMmcK37xH1MkTz9 +twQ== X-Gm-Message-State: AFuF++nrCfxFx1sBsDsitNrl/hLoN9uXP9HodLI4BD18D9bFdL5G6BOw +SnKBF+8aJZgBtcmMSUZZ5wvBS/p2b9bgK3soObqFODdvFxHn3xsNvHTf2rriV8bvMlZSHTwcJT QAPI/uheJ X-Gm-Gg: AYBFou2OIzRQXiEd3INy2bxy/CWNBecun9/QMcnoOtkxqMD0eBM/vymaOwpAVEQha+K eFSDKPCwDOXT9OTdxV+TeiBtHtyBMd75Jdz2OYNL7VLDTau7261apjML+N+o8MlU05VmUJKvGyK g3QZGPpRtwdU5cgXkbfg1bP+usRyTkEt3l4UDaxuHaJT9sWlaox8rRHPiHioquX7pN6fW5237RC TG5TvLV2xVyfa5jbFlVRlDw3ECcCEIr1KwfkgHdhO3RlVwpgxfmIrDMnauQZlFdqaYin9p74lSH BfJTPnIVMV1jK7IeYkwWUF59ZlilIKPKd+eYamvak2j0/d+xVjdTQ2i+31epb8GvSSHiDbnD9W3 3x/afikDWsDDUWYJ6nlC8XMYjsbsly8DJbAylyjwI+eCrswo+UyT82LmYNBBJAB2tyZNg64AmdN nU+zIUa0DqVlprPITg6yayK0n3GzathpYP1DYLYTkrDp52Y3qjwDX9bp+T/5wd9tXPQKFNmgF29 GcFxVx2VrAxOR6ozha6AHX7J+WtzdvzWiu/3A+k8PysQ2sb9U9HIubxR9UCXKw= X-Received: by 2002:a05:690c:a6db:b0:8a8:6c5f:5b32 with SMTP id 00721157ae682-8a86c5f6ee6mr25425217b3.52.1790606254436; Mon, 28 Sep 2026 07:37:34 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8a860e5e9besm45668487b3.11.2026.09.28.07.37.32 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 28 Sep 2026 07:37:33 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Mon, 28 Sep 2026 10:37:29 -0400 Message-ID: <20260928143730.47047-2-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260928143730.47047-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260928143730.47047-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.231.166 listed in wl.mailspike.net] X-Headers-End: 1xBCcE-00079o-Q4 Subject: [Openvpn-devel] [PATCH v2 1/2] Do not look up the "none" cipher in OpenSSL X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877587283301169619 X-GMAIL-MSGID: 1877587283301169619 cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), cipher_kt_insecure()) treat NULL as "not that". For the "none" cipher that is the expected answer, but under OpenSSL 3 the failed fetch also pushes EVP_R_UNSUPPORTED ("digital envelope routines::unsupported, Algorithm (none : 0)") onto the thread's error queue, and nothing pops it. "none" is what every server without --cipher carries in its pre-negotiation key_type: the legacy BF-CBC default is not in --data-ciphers, so do_init_crypto_tls() initialises the key_type with cipher "none". Each new client instance walks it in init_instance() -> do_init_crypto_tls() -> cipher_kt_mode_ofb_cfb("none") and in the frame and OCC calculations, and tls_ctx_reload_crl() runs right after. Its EOF test reads ERR_peek_error(), the OLDEST queued entry, so on the first handshake after the CRL file changed it finds the stale "unsupported" error and logs "CRL: cannot read CRL from file" for a CRL it loaded fine (GitHub #1103). Traced with gdb on 2.7.0 and master against OpenSSL 3.5.5. Return NULL for "none" before touching OpenSSL, as cipher_kt_name() already does. Real cipher names behave as before, and cipher_valid_reason() still finds the OpenSSL reason on the queue when it reports an unknown cipher. Left alone on purpose: cipher_kt_block_size()'s probe for the CBC sibling of an AEAD cipher (CHACHA20-POLY1305 -> "CHACHA20-CBC") and md_valid() leave the same kind of entry, but neither runs between client instance creation and the CRL reload. The next commit makes that reload robust against any leftover. With this change the queue is empty at multi_create_instance() and at backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305 clients; three CRL replacements give three clean reloads (unpatched: three warnings). Signed-off-by: Drew Blokzyl --- src/openvpn/crypto_openssl.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 29c5fa68..367a68a9 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -568,6 +568,15 @@ cipher_get(const char *ciphername) { ASSERT(ciphername); + /* "none" is a valid OpenVPN cipher name that OpenSSL does not know. + * Return NULL without asking OpenSSL: a failed EVP_CIPHER_fetch() would + * leave an "unsupported" entry on the error queue that the cipher_kt_*() + * callers never clear. */ + if (strcmp("none", ciphername) == 0) + { + return NULL; + } + ciphername = translate_cipher_name_from_openvpn(ciphername); return EVP_CIPHER_fetch(NULL, ciphername, NULL); } From patchwork Mon Sep 28 14:37:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5415 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5189:b0:8b3:6e77:b38b with SMTP id g9csp3403717mae; Mon, 28 Sep 2026 08:03:45 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvByzLcJKPwKRmcsvWCeYi9H/QUQ/Wr+Z2TbEgVuOFZlWNQHSLrh9JNabsOmmIv8+m/z+oZXNEdTnxiE=@openvpn.net X-Received: by 2002:a05:6808:50a3:b0:4c5:cd9d:c6de with SMTP id 5614622812f47-4d72c635ff8mr13645457b6e.7.1790607824895; Mon, 28 Sep 2026 08:03:44 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790607824; cv=none; d=google.com; s=arc-20260327; b=XJaYrTNkU+UM41lOOb3gfmKOw9v2Dal02XzdB+3752h/NJba46OLVfvZh7t4nV+8kL xmvdtQPnD1DmVGj7WPjBSEcA9Ve2l1tqAkQ3YV/bU/bexbX2ZT/bje5+LpTXniEAX7uY qDQhS3ZNek3EcEi9ZHD/dCfQenC6+U2UTkrN+A6CU+Twq1oBZ3grcE35Tjj/rSH16mU2 69jSnblDCBNgHKkLjWyAIc2dGkRSYWL1m3Dc/SLcScVFkDjqyvEoozjXeUWh3MLEjxk6 3xDefOnh4xU637oyb/dNZiYZWsqKA/wdLf4aUWajaw0pDUO5bh5g4Fh/h/riZW/ND4UN b0Dg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=swCyViZzfGCpFm6saAlWpenf2cdBQpyY+tkbjyGhIruoSQB/FuNtAITMCU3uHOf/Z9 57BZn0acHdTOqtrohfduTFf76T0xjW6z6mQvHAltk4f7bLhJyPcIq9FiCWIHLpnjv4Fq r8Kacg1ru2q9R+WFVr9vZOlSs5jn8xEMw5rSNl/fmTXlGyGrH/LbiqLH+qg2zC+oOe5q R4Y9SUOlw4pH6S3Lh3QpWKFguhVvKRT6Z0BAFECVj5enRtbfNOgN2vkluOAxhf8VZ2Nv I/nf9Ob0GM2HpT6UmDHhs8UbI2Axy0KNnbBhK/+c/T/O3+Mp64/nE2kuJGmpYUUXgrH3 FdXA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=knpujXwC; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dvs2euDp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Z17HBAvy; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n3p7+KI9; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4ebbc3d99b0si2834374b6e.64.2026.09.28.08.03.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 28 Sep 2026 08:03:44 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=knpujXwC; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dvs2euDp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Z17HBAvy; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=n3p7+KI9; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=MOHCnENBi5b/0/AQX4kO6q1+P/Z/cb8sXyoPAd4Y4rw=; b=knpujXwCvhwg+Td2hx3l8vMe51 tIN6nnfzqGhe9WboswD4rnDOE7b4Isdv+/kQrDCGvjH9cTt07ml24nefIAfylstUhCGQ1OkYoEfaL K7SZaGGvjUJeylGsIjSRDm/Dd5t8Ku9P2sQotml0A4m3iZd0MZCrbSD7QFCCjLe6kKno=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBCt8-0002nJ-LA; Mon, 28 Sep 2026 15:03:28 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBCt6-0002nD-LK for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 15:03:26 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=dvs2euDpUXjJa0HrkmKVlW4+zY 9i5qSC7IpZv1CBPmI4XO0in2VOG9ctpwZTtXMW4f66+QrsVWNiYuCSHCVU1yK5F4v1Rc/n57CSTS2 6HhcnbjvMDzoz6OdVbdKP3adVEgddHrkjWw6+aryvUxewNOuLeFtwwDQ2az9+JJmUen4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=Z17HBAvya1TdGDJW7h9s+4ii1A UfGJZaNWUPwjxr5ZAjuli+RJlrrOW+idOzutImGhdFHMdtQRNknYKp6yLQXpBH//b6c/Au+UC4bVh 2xWrK828WiEyFBbNKmtZzX67ufNC6E/sAx4BqgehavOyz3gRJlPacAausBNV2tz7KeeA=; Received: from mail-vs2-f15.google.com ([74.125.227.15]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBCt2-00050e-Ld for openvpn-devel@lists.sourceforge.net; Mon, 28 Sep 2026 15:03:26 +0000 Received: by mail-vs2-f15.google.com with SMTP id 71dfb90a1353d-5c981b0d59cso2196453e0c.3 for ; Mon, 28 Sep 2026 08:03:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790607799; x=1791212599; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=n3p7+KI9SMeihwGiq9l7ovOIgCJyfvwOkNufywriwGehCg2/jOao1im1u1Tmyrqnsy pCE4hy7aAhx5gwEaNS7Zn9A/WjIuNyEapbKgoYxhfIy81AqXc/OeDHXX5Yv+GB6TH+8j Eh48G2HIuUVVtBhbZTsBKrAU3xttKqwaXYU2fsxLTtRtpeqq+YHLj/nrlwG56c4fixWx /s8SDNLzGYbrJ+DDWg8EnBdTOzanGCHvfcMdDKFYeaU3YuiGubmjqli13m1JlTLWrfMS Bz2JjCSfA+SBxu2t8ibOdvmdq4ttMHHSd50oMErGQVzRp+WuGc2cmZK0EvEi6O8K0fIi eH4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790607799; x=1791212599; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=R2YE17U0FQKslV0yZr3KOBZEq6PvSGhL9OXcvkwoygo=; b=C723HzOrnR3Ts5qAOqA7GK7CNBPwVS6MI/bPyV7SDwlMRK4Uo6CTaR2jNStc+p40O7 p6EtUC7LLwWwojayF78hIJXkmYEehhF2enEwLfFju7ncqxCjiwzQu9sfngyGnqkANEnR DmSKfUenJ6ZfPnnJys5qnCRI+OkC/tLJ8Ya3nXSc8MJ9TkE9yh+UBfkCGVUSJ0Tr9cWH fHcIfS8KaABJCZFKlhcjEMFKOSIPQsq+V4VHLwJj6EtJDWmoYV/mgzDBpkrK0dtQ1nhR TLDzd5yYdgFPhiRBBcDp3lEAp80wxsiX4qRNVWUPHbownOfzDdK4qo3veSBtefY2pCzz 0EUQ== X-Gm-Message-State: AFq9FYKvQNTA0k00dcAFluuS4K7+4MKDw7dLj5+FfO/D3wj1ageMFtWI d4OWPjLgT/USL2N+IDAuWkja1adoV0wWJpz8PjjXL0xHjrQ+u4tBmDhKHABfzs78p2XIsevP5JG 6HJYfcMYx X-Gm-Gg: AYBFou0ChjDJ14mB7Igwp9ht+s6h4atVhol96J2rirrHqLC2XXkm7nqHZPtpQfy1jB0 eS7/pBB3IEwPCqV6dqIkk6AJ3EOCP/o494qDPcEBU4NCpYm+6gdGD+9bRV7NGiiEZDrElLJQgVE cHS5xgPIgEv87cv3b3aAFIMUaBiAUxs7N0WkjLlWZwhFF+oD1qqReavMgjYR8hVnco9iYa5prGf A89htpKx54P5NRLMap4/az6X8K/Y/eSektT0+gJMewmDYsyMc5VuvAUwdH01B8amZJfSANzlhXW 9B3L3OGitkewYPTEm+cHmI5iBl3NbKQj6umz3J76WclmW/SYu+jJWcDFSeXQkhXo91eW6nBuxo7 PDnE7TNhxXoflD77B+65Mb4d4vmOZCVMBYfz2NpGIdeNVdgXQ5L5c8+Bi2fRGj8FUI3rmGb92hc JPnk0qJE2ymyQ3cwjThXxaNsFQwxqH7zaOUQa3pEcO5HDjyMspRVSc+oZewjusbqH14D0Li1wD+ CmA03uoLwBuziW0GXRHD7HjfswwVDwOog0y+HHyOvFHeLxCTIXxuHUk+2PYT9w= X-Received: by 2002:a05:690c:dc5:b0:882:1d1e:d73a with SMTP id 00721157ae682-8a64bb00575mr56471247b3.4.1790606255711; Mon, 28 Sep 2026 07:37:35 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 00721157ae682-8a860e5e9besm45668487b3.11.2026.09.28.07.37.34 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 28 Sep 2026 07:37:34 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Mon, 28 Sep 2026 10:37:30 -0400 Message-ID: <20260928143730.47047-3-drew@linuxkids.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260928143730.47047-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260928143730.47047-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behi [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.227.15 listed in wl.mailspike.net] X-Headers-End: 1xBCt2-00050e-Ld Subject: [Openvpn-devel] [PATCH v2 2/2] Make CRL reload EOF detection independent of stale error queue entries X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042728496797502 X-GMAIL-MSGID: 1877588390234179220 backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behind earlier in the thread turns a clean EOF into a "CRL: cannot read CRL from file" warning, prints the unrelated errors as if they came from the CRL file, and still installs the CRLs already parsed. The previous commit removes the leftover that triggered this in practice; this one stops the loop from depending on the queue being clean at all. Start the loop from an empty queue so only errors raised by PEM_read_bio_X509_CRL() are visible, test the error it raised last rather than the oldest one, and clear the queue on the EOF path instead of popping a single entry. Signed-off-by: Drew Blokzyl --- src/openvpn/ssl_openssl.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 7cfe9f4a..da3e07fe 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -1360,6 +1360,13 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b } int num_crls_loaded = 0; + /* + * Start from an empty error queue so the EOF test below only sees errors + * raised by PEM_read_bio_X509_CRL(). A stale error left by an earlier + * operation in this thread would otherwise be what ERR_peek_error() + * returns, and a clean EOF gets reported as "cannot read CRL". + */ + ERR_clear_error(); while (true) { X509_CRL *crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL); @@ -1367,13 +1374,15 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b { /* * PEM_R_NO_START_LINE can be considered equivalent to EOF. + * ERR_peek_last_error() is the error PEM_read_bio_X509_CRL() + * raised last; ERR_peek_error() would be the oldest queued one. */ - bool eof = ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE; + bool eof = ERR_GET_REASON(ERR_peek_last_error()) == PEM_R_NO_START_LINE; /* but warn if no CRLs have been loaded */ if (num_crls_loaded > 0 && eof) { /* remove that error from error stack */ - (void)ERR_get_error(); + ERR_clear_error(); break; }