From patchwork Wed Sep 30 13:27:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5419 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6ac1:b0:8b3:6e77:b38b with SMTP id v1csp687130maw; Wed, 30 Sep 2026 06:35:52 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBxLqKbCTLVvQIcTf3p+B8Kiyn/Ha80AkE4PJISO1P19Qe2+yGg86vRXlaaT6TNrAnkvev8aPcROjkA=@openvpn.net X-Received: by 2002:a05:6820:4d01:b0:6cd:3fec:de7e with SMTP id 006d021491bc7-6dcf6816cdcmr1197582eaf.84.1790775352164; Wed, 30 Sep 2026 06:35:52 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790775352; cv=none; d=google.com; s=arc-20260327; b=p8TjMyBQQ298LsBlmbd1saBKrWYhqHjI7oKp7bwp8ARlRgGFJbEhXsWveghHxv8lBm Q1shlNeK6D7VRKJzMyJZPir4+W2W5lWd+urkjH6MWPpmNi8Xg2KX02mCQNvA+1fttSLN Fa5pBvPUSankDRQ3Msxjxi/2jO/Utj7arw8+e6rb2NHJ66q8yn3nlJXLNU72vb8gHopr vGX5SnwnW+5Laqftop8WIEbNHBNtSW3Y/EBJ2FVYDLiS+poltFrkzc94lZS+dq3dqzhl Y8CSxGGUxErqnTpMX6Mt20m62QBQY55O5CfIncbfVsfAfG6jpP0k7ldNPej50mzD0YMY jw/Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=pU+ywKL0zEQ+cYEuu/1lnLe5YVERWU+ZOm0wB4MhvIuLviW+2DtQu/rFy29B+X1nv4 7rm7oYsI8EJyvQzD0XUwS9YWz5TK9jzEQuD470YZ7+dybGj9f3t1rp/6TVhPjJwoh9kv jdXJZ/uQelbLixsaSQmwmIf4CcW4q8Xmefxo2eBhN59etWmNf8GzF7NHfCmhxF0etRop vHJyEl7xctELWBGvWuIMuvBSFtOMkKS/L+OALrOwWeWBOfZHO3mTMGYJHeYQwTmzdZoi qSExVvzuj8PijdWrrpMHqJFYkQxM8JD+IQWwj4unb+Z8ohpeR5Mpa3mBPV+7W3mLgsz2 r2Fw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=GJ7ESK3M; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="ao4/iDMP"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=cG2yNuvk; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=gMAToRef; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-49decf239b9si140286fac.36.2026.09.30.06.35.52 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 30 Sep 2026 06:35:52 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=GJ7ESK3M; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="ao4/iDMP"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=cG2yNuvk; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=gMAToRef; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=R7wudGp5WGyOyhnwOR/5ZLBdLkt5q+0BFAfhfIpjqXg=; b=GJ7ESK3MB2L8v1d19Woql77Hgq qpSFQiSmVWXxrwv4Tpl8NsPmpG3oAz9rI6W8YVpx7h1+sS9zE0fTihYwwPJ8PAQwK1S1s86kSYesh N7jdIJAVoUBn2pX75QhH90qubAi2HT+WUs0s2u9eFzKy7f5TI/GRnKP1BoCIRYddROpY=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBuTM-0008S7-05; Wed, 30 Sep 2026 13:35:48 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBuTD-0008Rw-3j for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:35:39 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=ao4/iDMPueykFrCxxSqAL9m74V vx6rRr+rAKzmN7clafNldxVeQngtPe3+38XQq+tveWoAWuKWZBTxVFCN6fzGDtt2WnyEuYsQUe8a6 fy3Wk8UfeOheunK5dokln/XZCLLEpTy25rYlc5qXdC5bgm8ZBMaNqe1sBTZEVjpFpbc0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=cG2yNuvkE1LE0CHoAK4bB7mcis behZcyvj29Kjw9JWsqztAldEXbMdcvYFJWv7mRiWMkL4NVQUxAZGJ2VXC7aj8OraHTx6XIm3uxXyD 30rMS8qIHayM2XPPclZS4Fv/KVXFAtCLFcGEP7CbJcxkc2AvTe5StlBN7ctstAi9wnNo=; Received: from mail-vs2-f41.google.com ([74.125.227.41]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBuTC-0005u4-I2 for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:35:39 +0000 Received: by mail-vs2-f41.google.com with SMTP id 71dfb90a1353d-5c981b0d59cso3719083e0c.3 for ; Wed, 30 Sep 2026 06:35:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790775332; x=1791380132; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=gMAToRefn3vMPuUnOXNnTLKiIq6dmtzcq1dH1BItUBoJIiNtgsXQCnSkKrtTBabvyL 43XOau3MMlpnhg7ZN/cyAP6GSGft704Xuyj+j1rjekm+u2lwisV9vco1NsX/Dyon6TSc 9jPraTSrtlo8ZcCzZs/amKXD99aKNvYhuRfgYfFb5olnLo8n/pzRg//6yyFs/I0G0/JV HKztKX0mcczwwL2Ldm4O0dMc4qwU8JGQm+nOchC597rLIRQX1ir4xOlyjszjAcHZQPzR deiYvBy/eSuduu6LXF4KG22+qAzTOBxy0McbaWCP3j1yJ8lu0LoF0ZXrPKkynxc2RUD9 Ar7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790775332; x=1791380132; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QnqTcy2r76nsYbwmco1+y8FAUQ2KjXCh5RLVao63fY0=; b=tprBI/Jxt3dL8M7zj8a1Peonz7vU0M61jTUM3TUeEXiWNLl+CELtKEFH5RNSpqHj6m +6W/x8MLtSWQEh0sIEvIT/cOyUKXwIBwqUw/MoQ2ogA7CUYStU7GrmdaN3a3LOOK3ftP Vu+KUpAH4xdR8raR6lf6Lj64e2fubsq6oODQtB0obWM9Z/9b4ig4Kl5NdhYsq5/BcG7m 4BrtWf8tPY9KGAtPoWwr3Ogjlgn5dcYPa1ifOBqxINPznVJBIc0Y+zvXa0iedYiZ4jyP VKhz9DOnjXzSubktBB3vHfY6xKSc/lUHhxvPF7ib5bbIkc5ZmTevZXYYfCdIQFiw8E4a FHgQ== X-Gm-Message-State: AFq9FYKbE68/0muf1Ispq0ZuBVKbPT8mpSpyUkJef/qIFL8Be/BfbEph QAWvWu1M2f7TkHC+F8mcS5awICCVIgQ4FnZAvBNFLvKHtJPj42V8zO1Ax0ix1XChiZ1XiDtaaJV j8ZcmgA== X-Gm-Gg: AYBFou1UPTHn6gZj2XG1gGXah5bgtYn1P4Xq6bQnMeWLxEmt7MWRw9xoTmG89isapvd lUMPPivFy4GNL5WwHc4DIfLM4zR+6XwYLcqvXIqnEzsN+YolOozsduYagSdF3M912h2UgECFwDB 6luOotH0FyBL1UGyJ3ny8rfUEv7lfA0x6y06qKsoefT1FuQve+OllhRgR6itFEc2iWW+M9OY4Wr eI/atu9Fj3DgRWpiY0Gi92ZhdbMI0VQzoLAOJBwuvrd3vm9efwtIGUE40N78tzPnCzqW6kZDy1k WMrq9QmlaCvAPrpjTb0UoX6WepBN11ZPM7e27QcyQi68vHJnAG/RMM9zjXfVy914p1vQFZ7aIs1 9vm2QJ/DDkHQ2zy7KDR/sKoQW7A2yWEkr1RRpJsY/L0UGXYowNsBZM/dQnOUnMwv0mQjCUO/tqV xEkD012WcXJfHg4Y90E6gPNg13ls1TV6rAV005GytNV21IFIjNo0eMcIlWO6J3N2ZqTbpHZtF3i wYyRcxPEWAUPiAPpgEseYhpqoeVZSjlDMeUywJb/uqGL4lAi9EadjiCMxluYqo= X-Received: by 2002:a05:690e:1382:b0:66e:57d8:6a52 with SMTP id 956f58d0204a3-676833245d0mr564266d50.7.1790774831771; Wed, 30 Sep 2026 06:27:11 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-67680ac3521sm704189d50.1.2026.09.30.06.27.10 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 30 Sep 2026 06:27:10 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Wed, 30 Sep 2026 09:27:06 -0400 Message-ID: <20260930132707.51452-2-drew@linuxkids.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260930132707.51452-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260930132707.51452-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.227.41 listed in wl.mailspike.net] X-Headers-End: 1xBuTC-0005u4-I2 Subject: [Openvpn-devel] [PATCH v3 1/2] Do not look up the "none" cipher or digest in OpenSSL X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877764055532193951 X-GMAIL-MSGID: 1877764055532193951 cipher_get() hands EVP_CIPHER_fetch() whatever name it is given, and the callers that only ask whether a cipher exists or which mode it has (cipher_kt_mode_cbc/ofb_cfb/aead(), cipher_kt_block_size(), cipher_kt_insecure()) treat NULL as "not that". For the "none" cipher that is the expected answer, but under OpenSSL 3 the failed fetch also pushes EVP_R_UNSUPPORTED ("digital envelope routines::unsupported, Algorithm (none : 0)") onto the thread's error queue, and nothing pops it. "none" is what every server without --cipher carries in its pre-negotiation key_type: the legacy BF-CBC default is not in --data-ciphers, so do_init_crypto_tls() initialises the key_type with cipher "none". Each new client instance walks it in init_instance() -> do_init_crypto_tls() -> cipher_kt_mode_ofb_cfb("none") and in the frame and OCC calculations, and tls_ctx_reload_crl() runs right after. Its EOF test reads ERR_peek_error(), the OLDEST queued entry, so on the first handshake after the CRL file changed it finds the stale "unsupported" error and logs "CRL: cannot read CRL from file" for a CRL it loaded fine (GitHub #1103). Traced with gdb on 2.7.0 and master against OpenSSL 3.5.5. Return NULL for "none" before touching OpenSSL, as cipher_kt_name() already does. Real cipher names behave as before, and cipher_valid_reason() still finds the OpenSSL reason on the queue when it reports an unknown cipher. md_get() gets the same guard: no caller passes "none" today (md_kt_name(), md_kt_size() and md_defined() check first), but it has the same shape and would leave the same entry. Left alone on purpose: cipher_kt_block_size()'s probe for the CBC sibling of an AEAD cipher (CHACHA20-POLY1305 -> "CHACHA20-CBC") and md_valid() leave the same kind of entry, but neither runs between client instance creation and the CRL reload. The next commit makes that reload robust against any leftover and reports one when it sees it. With this change the queue is empty at multi_create_instance() and at backend_tls_ctx_reload_crl() entry for UDP, TCP and CHACHA20-POLY1305 clients; CRL replacements give clean reloads (unpatched: a warning every time). Signed-off-by: Drew Blokzyl --- src/openvpn/crypto_openssl.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 29c5fa68..b44d0797 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -568,6 +568,15 @@ cipher_get(const char *ciphername) { ASSERT(ciphername); + /* "none" is a valid OpenVPN cipher name that OpenSSL does not know. + * Return NULL without asking OpenSSL: a failed EVP_CIPHER_fetch() would + * leave an "unsupported" entry on the error queue that the cipher_kt_*() + * callers never clear. */ + if (strcmp("none", ciphername) == 0) + { + return NULL; + } + ciphername = translate_cipher_name_from_openvpn(ciphername); return EVP_CIPHER_fetch(NULL, ciphername, NULL); } @@ -981,6 +990,14 @@ md_get(const char *digest) { evp_md_type *md = NULL; ASSERT(digest); + + /* "none" is a valid OpenVPN digest name that OpenSSL does not know. + * Return NULL without asking OpenSSL, see cipher_get(). */ + if (strcmp("none", digest) == 0) + { + return NULL; + } + md = EVP_MD_fetch(NULL, digest, NULL); if (!md) { From patchwork Wed Sep 30 13:27:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Drew Blokzyl X-Patchwork-Id: 5418 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6ac1:b0:8b3:6e77:b38b with SMTP id v1csp682391maw; Wed, 30 Sep 2026 06:32:40 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBx09rI8xlYvWNFa/ue/2N9W52S3byiCFEB4bqQ968bOQuQYbd8fuWtKzX4skl30O+fPbzWGFvkbS9M=@openvpn.net X-Received: by 2002:a05:6820:1f03:b0:6d9:4131:503d with SMTP id 006d021491bc7-6dcf622d1cfmr1294926eaf.59.1790775160296; Wed, 30 Sep 2026 06:32:40 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790775160; cv=none; d=google.com; s=arc-20260327; b=H7hHH3dbIyx1SVTqL4jHZ+LjWPSnulqDWGDxnKV+fffMsEbx53y3mpImtOU1eGeZDY pociDmZU+E6aGUaY89zjp4c+05VqblgLMdSuIX6JRKeG4rIth1jV60oeTQeZBDiyQ1AM i7XOmc79V7PU7P+C43TVmwvbnPoTbzOGHtaFF8hdCtv2tb+pGNlpc9Vzpc4PlFXvcSIV 6FeuU22j6Ke9kGsNeinmAfzeBXRahyjjNDNR4apN9/9Vwl+e4xK6LA7cISv17OI/OtwR 9yh+nlFGf1zxwHZ3mZ9GhszctqtnDmZzP/pJqZygEujg5qDSy1d6UYB5GnghrmGdzhKI nYHA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=w3VRX4OEihG3lG/Gr76ZnvYyemIymwXPAWRIlYeZohE=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=g5EplGQ0UNMdFFWD83onS0lXPfBz5X93x6DRZlbuBPaqSuZwCHeEVkdQTRO5KNPy5d /LkBXq+RmK/pWAx8L7ya7z+I3wOZKsqVxLBeXkddqV/+Vy5k0N4+tQYvj8Lo+zV3FcO6 leCdvZkJU+sZl7iF5fJshoT8G+P6SWmS7baLULBwlHHOpMFS7cSEgICiL/C4jcDoZ0BA MIb1ohzDHv1W21Ax7nPwYnDQ48K1O1CTa83bIjHxfCsJ/7u6owc5dHYV5y7c7H/ajzUp 5F1dXClCQC0s51fuDODhAs7xnAdpejDMQgN/9m40vjaUkPr2cr6xPGjkvwNMS8EAFyXM Gd/A==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=eOJdPBi9; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=c5SOs1o9; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="P1t6+/5y"; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=zxLeL3iu; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 006d021491bc7-6dd99cdb2f7si24955eaf.78.2026.09.30.06.32.39 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 30 Sep 2026 06:32:40 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=eOJdPBi9; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=c5SOs1o9; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="P1t6+/5y"; dkim=neutral (body hash did not verify) header.i=@linuxkids-com.20251104.gappssmtp.com header.s=20251104 header.b=zxLeL3iu; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dara=neutral header.i=@openvpn.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=w3VRX4OEihG3lG/Gr76ZnvYyemIymwXPAWRIlYeZohE=; b=eOJdPBi9wtoSYlaNX02dc1r29v QvR884y9IUTWDEMou0Llj7mFQKRKl7V01zMG70crecXi+6U+m+pMe1e2eu3Z5iPTJXM1GqmQMai7Y v0NOt2uES+fzONw/umb3UR1iZSHIKX1Ptwribs12G2dpGQmPJDvo53dgzoCV8DYEQEHY=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1xBuQE-0006Zs-Eq; Wed, 30 Sep 2026 13:32:35 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1xBuQD-0006Zg-90 for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:32:34 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=4Sd0FXto2g683+AMPnossSXcHR+FbwoL2sqVKyn8brU=; b=c5SOs1o9NOe012OLR94tA00IAu 4HZQ3MJNXmdUL3wPfZVzRrJ48uxaT/djoBIbn7W+rbBQyxP1wpj3Xlxznw/U81rmShcr6NiYZKsPE ybhT/uQTff66dKu3sNMkV9Y4NB1p8S3rlFccPpsPCB9M2wSdRUrj/5bQlANpI7+6SoD8=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=4Sd0FXto2g683+AMPnossSXcHR+FbwoL2sqVKyn8brU=; b=P1t6+/5ycgmWBhX6kJPJlvz4Wj 6HIUfdsBeimy7PnBUIYQqUk5lIT3m4gA47kDS/71FwaUrjwhmUi+doJ75Pj6hcEr+6u0aJ3pnBdit h+TaMeHtsC2UltSQWnQJo1a4Bl7pERcYPFuXIdpGFVD0+RDAWy7myNxl7fvaWVQDR1Kw=; Received: from mail-pz2-f37.google.com ([74.125.228.37]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1xBuQB-0005qL-DF for openvpn-devel@lists.sourceforge.net; Wed, 30 Sep 2026 13:32:34 +0000 Received: by mail-pz2-f37.google.com with SMTP id 41be03b00d2f7-cc7c4c92477so1213536a12.0 for ; Wed, 30 Sep 2026 06:32:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxkids-com.20251104.gappssmtp.com; s=20251104; t=1790775146; x=1791379946; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4Sd0FXto2g683+AMPnossSXcHR+FbwoL2sqVKyn8brU=; b=zxLeL3iuik147VIl+Wi3j79TiXUd2PgSnzx/DD6pQHLjyGdlwjnyRhO6MyqL8WhhBE 7KaIwuF/9DE37Lrla3OXH+CnH1EivqbVC8x/VcTaHzX+jdAAmv0xdXTW9sDP9mJPbg0r UC6umvWSzAaowg5ax4AmOkTYi2+yQ4w7hLsw1MQgIdSP60Xu4fhrXYiFoH9d7YSamnKI tUuS54OGV8KjyBMNtpPxbSdC21rYggc8GDWnJ+mihrynt789Wg0sFuwAQtlma63u4pzh kgysI8gxaCkMJAxIXi7jLZVenEtC2nfK1ShMyR0oAzvvo4sAEexL9tAWcMS9kTZGcda1 Gz5w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790775146; x=1791379946; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4Sd0FXto2g683+AMPnossSXcHR+FbwoL2sqVKyn8brU=; b=h+bj5jCBUGkUfgH1xT30QCQcL1LjsqrayJD9sFnkuiz3FOyK7FEZV9mhrgW/9jJCou RPbqZcf3vZMPtOzJORs9W6++vF6ILE+wTGfEo87CLAP/XqvhYyFWv7cKwLkqyNt5WNOQ jfyUvxdUD9mSpeNjlp97tI4ZXJCTVB7eD6J+KpgPo3zDa1+6OXmdK5ZzH1pCPWmZAdhM iPg9+MwC6awo0IYt7y8G0Z7NVelCow3BOH/nPPz+4GqrtNA2HyQq5ZXK2qE/C3ahRi8H W1BB+QTRlIOoJ1/2DHqn6B+YsCEeC7HZNXgQ/yPrcAyZPIeK/HPSYoyydPdngQHNcojO jStQ== X-Gm-Message-State: AFuF++lOe0EGqYiIhGq9FHQyGWk1aU1Czul/JeID0/Ytm1puEbphHV0J 5v0hiZkywSms+VyRqPXvXfNByBaoQTrOk5vGzCO08HlZTeRJzh1IwFfI69UCGV650kqPhXbeDRU mCATG3w== X-Gm-Gg: AYBFou10aku5m8PDVqxa8ZY11CaeCaN8fm70p/9UeunhC0RdLgJbbxr55Zr3Fn+WuJY 9SKtB/n6AxknKnuYM5EicnQdpZaLXyxOF5wDzSV0/5v8Ao9ch7UQ1DrrEGAOXNYdP9jPbxG4azK n1AYlhzt9wp5G1BBkxV0D47n/Jt+HVdsaL6y7YRD21OhJQiSFlEi5yJzR+aU7MJJhpTQSQ4kCM/ mE8ntCJKEL7GZH/tuBubn5uj5iEU2n/GtXmrHT6cjzYhQ9q1uoHjPwgnKQI9fT6aGEsOjOF8QJe Fd7x5cj11UWzIOtsfETGW121Ch9VHF2HUyCkoebk2TDZZINlTf+Os+cwxNhOnzrG8G7QbCfuhO6 eYU4FRSn1Ok7m3AC3LqcfTrVYR2suttgTAG6Q0M4wFJq8FjKgGzzfNN4W5p87NDL+odCubtHJY2 JVQRdyaw/MN9u+s1Jo7guqT3ASuKv//CIEHXYbUnRT3qUYXEa327SMpbzNGNZliMTe/vNzhyoEC SP2110KRXWthQJVnKqJ0GdAxKmp+6DPhAFn2Puuuh2zZdvJLGAtrkXrHxCfpRnMg+LtUrLoqA== X-Received: by 2002:a05:690e:4505:20b0:672:f0b6:263d with SMTP id 956f58d0204a3-676834669c7mr362845d50.76.1790774832998; Wed, 30 Sep 2026 06:27:12 -0700 (PDT) Received: from MN-277C755CCA3B.localdomain (71-208-239-209.ftmy.qwest.net. [71.208.239.209]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-67680ac3521sm704189d50.1.2026.09.30.06.27.11 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 30 Sep 2026 06:27:12 -0700 (PDT) From: Drew Blokzyl To: openvpn-devel@lists.sourceforge.net Date: Wed, 30 Sep 2026 09:27:07 -0400 Message-ID: <20260930132707.51452-3-drew@linuxkids.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260930132707.51452-1-drew@linuxkids.com> References: <20260922140520.71500-1-drew@linuxkids.com> <20260930132707.51452-1-drew@linuxkids.com> MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behi [...] Content analysis details: (0.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [74.125.228.37 listed in wl.mailspike.net] X-Headers-End: 1xBuQB-0005qL-DF Subject: [Openvpn-devel] [PATCH v3 2/2] Make CRL reload EOF detection independent of stale error queue entries X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1877042728496797502 X-GMAIL-MSGID: 1877763854476022298 backend_tls_ctx_reload_crl() treats a NULL from PEM_read_bio_X509_CRL() as EOF when ERR_peek_error() shows PEM_R_NO_START_LINE. ERR_peek_error() returns the OLDEST queued error, so any entry left behind earlier in the thread turns a clean EOF into a "CRL: cannot read CRL from file" warning, prints the unrelated errors as if they came from the CRL file, and still installs the CRLs already parsed. The previous commit removes the leftover that triggered this in practice; this one stops the loop from depending on the queue being clean at all. If the queue is not empty when the CRL is loaded, say so at D_LOW with the queued errors, since that is a bug somewhere else worth seeing, then start the loop from an empty queue so only errors raised by PEM_read_bio_X509_CRL() are visible. Test the error it raised last rather than the oldest one, and clear the queue on the EOF path instead of popping a single entry. Signed-off-by: Drew Blokzyl --- src/openvpn/ssl_openssl.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 7cfe9f4a..b14cbbe9 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -1360,6 +1360,19 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b } int num_crls_loaded = 0; + /* + * The EOF test below must only see errors raised by + * PEM_read_bio_X509_CRL(). Anything already queued was left by an + * earlier operation in this thread and would otherwise be what + * ERR_peek_error() returns, turning a clean EOF into "cannot read CRL". + * Report it, since that is a bug elsewhere, then start from an empty + * queue (crypto_msg() drains the queue while printing it). + */ + if (ERR_peek_error() != 0) + { + crypto_msg(D_LOW, "CRL: OpenSSL error queue not empty on CRL load"); + } + ERR_clear_error(); while (true) { X509_CRL *crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL); @@ -1367,13 +1380,15 @@ backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, b { /* * PEM_R_NO_START_LINE can be considered equivalent to EOF. + * ERR_peek_last_error() is the error PEM_read_bio_X509_CRL() + * raised last; ERR_peek_error() would be the oldest queued one. */ - bool eof = ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE; + bool eof = ERR_GET_REASON(ERR_peek_last_error()) == PEM_R_NO_START_LINE; /* but warn if no CRLs have been loaded */ if (num_crls_loaded > 0 && eof) { /* remove that error from error stack */ - (void)ERR_get_error(); + ERR_clear_error(); break; }