This is somewhat beyond my pay grade, but fortunately MaxF understands these parts and has reviewed & ACKed it, and also Walter Doekes has tested that it fixes his problem scenario.
I have tested that it does not break any of my scenarios (t_client, t_server). Code looks reasonable as well. I have changed the commit message to "... where these ids *are* 0 or 1...". Your patch has been applied to the master branch. commit 518e122b42739b0dbb54e7169a8a3aadb4773125 Author: Arne Schwabe Date: Tue Aug 19 23:22:09 2025 +0200 Check message id/acked ids too when doing sessionid cookie checks Signed-off-by: Arne Schwabe <a...@rfc2549.org> Acked-by: MaxF <m...@max-fillinger.net> Message-Id: <20250819212214.16218-1-g...@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg32626.html Signed-off-by: Gert Doering <g...@greenie.muc.de> -- kind regards, Gert Doering _______________________________________________ Openvpn-devel mailing list Openvpn-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-devel