[Openvpn-devel] [S] Change in openvpn[master]: Change default of "topology" to "subnet"

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: flichtenheld, plaisthos. Hello plaisthos, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/421?usp=email to look at the new patch set (#2). The following approvals got outdated and were removed: Code-Review-1 by

[Openvpn-devel] [S] Change in openvpn[master]: GHA: clean up libressl builds with newer libressl

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. Hello plaisthos, I'd like you to do a code review. Please visit http://gerrit.openvpn.net/c/openvpn/+/461?usp=email to review the following change. Change subject: GHA: clean up libressl builds with newer libressl

[Openvpn-devel] [S] Change in openvpn[master]: Cache mbed TLS dependency and build latest 2.x mbed TLS as well

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: plaisthos. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/455?usp=email to look at the new patch set (#2). Change subject: Cache mbed TLS dependency and build latest 2.x mbed TLS as well

[Openvpn-devel] [M] Change in openvpn[master]: Print SSL peer signature information in handshake debug details

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/365?usp=email ) Change subject: Print SSL peer signature information in handshake debug details

[Openvpn-devel] [XS] Change in openvpn[master]: Document tls-exit option mainly as test option

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/447?usp=email ) Change subject: Document tls-exit option mainly as test option .. Patch

[Openvpn-devel] [XS] Change in openvpn[master]: Document tls-exit option mainly as test option

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld, plaisthos. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/447?usp=email to look at the new patch set (#2). The following approvals got outdated and were removed: Code-Review-1

[Openvpn-devel] [XS] Change in openvpn[master]: Document tls-exit option mainly as test option

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/447?usp=email ) Change subject: Document tls-exit option mainly as test option .. Patch

[Openvpn-devel] [M] Change in openvpn[master]: Implement generating TLS 1.0 PRF using new OpenSSL 3.0 APIs

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/457?usp=email ) Change subject: Implement generating TLS 1.0 PRF using new OpenSSL 3.0 APIs

[Openvpn-devel] [S] Change in openvpn[master]: Change default of "topology" to "subnet"

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/421?usp=email ) Change subject: Change default of "topology" to "subnet" .. Patch Set

[Openvpn-devel] [M] Change in openvpn[master]: Check PRF availability on initialisation and add --force-tls-key-mate...

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/460?usp=email to look at the new patch set (#2). Change subject: Check PRF availability on initialisation and add

[Openvpn-devel] [XS] Change in openvpn[master]: Extend the error message when TLS 1.0 PRF fails

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. Hello flichtenheld, I'd like you to reexamine a change. Please visit http://gerrit.openvpn.net/c/openvpn/+/456?usp=email to look at the new patch set (#5). The following approvals got outdated and were removed: Code-Review-1 by

[Openvpn-devel] [M] Change in openvpn[master]: Check PRF availability on initialisation and add --force-tls-key-mate...

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/460?usp=email ) Change subject: Check PRF availability on initialisation and add --force-tls-key-material-export

[Openvpn-devel] [XS] Change in openvpn[master]: Extend the error message when TLS 1.0 PRF fails

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/456?usp=email ) Change subject: Extend the error message when TLS 1.0 PRF fails ..

[Openvpn-devel] [M] Change in openvpn[master]: Allow the TLS session to send out TLS alerts

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/449?usp=email ) Change subject: Allow the TLS session to send out TLS alerts .. Patch

[Openvpn-devel] [S] Change in openvpn[master]: Allow specifying custom mbed TLS directories with CMake

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: MaxF, plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/377?usp=email ) Change subject: Allow specifying custom mbed TLS directories with CMake

[Openvpn-devel] [S] Change in openvpn[master]: Allow specifying custom mbed TLS directories with CMake

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/377?usp=email ) Change subject: Allow specifying custom mbed TLS directories with CMake

[Openvpn-devel] [M] Change in openvpn[master]: Print SSL peer signature information in handshake debug details

2023-11-28 Thread plaisthos (Code Review)
Attention is currently required from: flichtenheld. plaisthos has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/365?usp=email ) Change subject: Print SSL peer signature information in handshake debug details

[Openvpn-devel] [S] Change in openvpn[master]: Remove unused/uneeded defines from configure and cmake config

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/443?usp=email ) Change subject: Remove unused/uneeded defines from configure and cmake config

[Openvpn-devel] [M] Change in openvpn[master]: Print SSL peer signature information in handshake debug details

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/365?usp=email ) Change subject: Print SSL peer signature information in handshake debug details

[Openvpn-devel] [M] Change in openvpn[master]: Check PRF availability on initialisation and add --force-tls-key-mate...

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/460?usp=email ) Change subject: Check PRF availability on initialisation and add --force-tls-key-material-export

[Openvpn-devel] [PATCH v1] Minimal Solaris/OpenIndiana support to Cmake and clean up -Werror

2023-11-28 Thread Frank Lichtenheld
From: Arne Schwabe Change-Id: I66e3dd7b7166459526824fe5ae81a449b375b8db Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL:

[Openvpn-devel] [S] Change in openvpn[master]: Minimal Solaris/OpenIndiana support to Cmake and clean up -Werror

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/458?usp=email ) Change subject: Minimal Solaris/OpenIndiana support to Cmake and clean up -Werror

[Openvpn-devel] [XS] Change in openvpn[master]: Extend the error message when TLS 1.0 PRF fails

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/456?usp=email ) Change subject: Extend the error message when TLS 1.0 PRF fails ..

[Openvpn-devel] [S] Change in openvpn[master]: Cache mbed TLS dependency and build latest 2.x mbed TLS as well

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/455?usp=email ) The change is no longer submittable: Code-Review is unsatisfied now. Change subject: Cache mbed TLS dependency and build latest 2.x mbed TLS

[Openvpn-devel] [S] Change in openvpn[master]: Cache mbed TLS dependency and build latest 2.x mbed TLS as well

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/455?usp=email ) Change subject: Cache mbed TLS dependency and build latest 2.x mbed TLS as well

[Openvpn-devel] [PATCH v1] Fix check_session_buf_not_used using wrong index

2023-11-28 Thread Frank Lichtenheld
From: Arne Schwabe The inner loop used i instead of j when iterating through the buffers. Since i is always between 0 and 2 and ks->send_reliable->size is (when it is defined) always 6 (TLS_RELIABLE_N_SEND_BUFFERS) this does not cause an index of out bounds. So while the check is not doing

[Openvpn-devel] [XS] Change in openvpn[master]: Fix check_session_buf_not_used using wrong index

2023-11-28 Thread flichtenheld (Code Review)
Attention is currently required from: plaisthos. flichtenheld has posted comments on this change. ( http://gerrit.openvpn.net/c/openvpn/+/459?usp=email ) Change subject: Fix check_session_buf_not_used using wrong index ..

[Openvpn-devel] [PATCH v3] Add check for nice in cmake config

2023-11-28 Thread Frank Lichtenheld
From: Arne Schwabe Change-Id: I2cc8f9b82079acca250db5871ffd9fad2997d1a8 Acked-by: Frank Lichtenheld Signed-off-by: Arne Schwabe --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL:

[Openvpn-devel] [PATCH v2] Remove compat versionhelpers.h and remove cmake/configure check for it

2023-11-28 Thread Frank Lichtenheld
From: Arne Schwabe The cmake file defined that file to be never present in contrast to the old msvc-config.h that always had it present. Remove also the compat implementation taken from mingw. All our current build environments already have that header in place. Change-Id:

[Openvpn-devel] [PATCH v1] configure.ac: Remove unused AC_TYPE_SIGNAL macro

2023-11-28 Thread Frank Lichtenheld
Recent autoconf warns: configure.ac:448: warning: The macro `AC_TYPE_SIGNAL' is obsolete. And it turns out that we do not actually use RETSIGTYPE. Additionally, there is no reason to do so since as the autoconf documentation says: "These days, it is portable to assume C89, and that signal

[Openvpn-devel] [PATCH v3] Rename state_change to continue_tls_process

2023-11-28 Thread Frank Lichtenheld
From: Arne Schwabe The name state_change is more confusing than helpful as it not really indicates if there was a state change but rather if processing should be continued. There even some states that are definitively state changes (setting to_link buffer) that require continue_tls_process to be