Attention is currently required from: cron2, plaisthos.

selvanair has posted comments on this change by selvanair. ( 
http://gerrit.openvpn.net/c/openvpn/+/1415?usp=email )

Change subject: pull-filter: improve documentation
......................................................................


Patch Set 2:

(1 comment)

Patchset:

PS2:
> ewww... who permitted such ugliness to pass the parser... […]
I had an inkling that there could be more ways than just spaces to defeat this 
-- and you challenged me to find one 😊

Anyway, such "unknown unknowns" is what prompted me to write this in a nuanced 
and hedged fashion... Now we know at least one concrete way to break it, we 
could just say:

  *Warning:* ``pull-filter`` cannot be relied upon as a security measure to
  protect against offending options pushed by a server. For example, the
  filter could be defeated by pushing options with extra spaces between
  tokens or other formatting variations.

I thought about improving the matching algorithm, but it doesn't look trivial. 
For now it has to remain a convenience option.



--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1415?usp=email
To unsubscribe, or for help writing mail filters, visit 
http://gerrit.openvpn.net/settings?usp=email

Gerrit-MessageType: comment
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: I2c8d40038e52fbdff1c56f93db1e6a2f9255c59a
Gerrit-Change-Number: 1415
Gerrit-PatchSet: 2
Gerrit-Owner: selvanair <[email protected]>
Gerrit-Reviewer: cron2 <[email protected]>
Gerrit-Reviewer: plaisthos <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-Attention: plaisthos <[email protected]>
Gerrit-Attention: cron2 <[email protected]>
Gerrit-Comment-Date: Mon, 08 Dec 2025 21:50:59 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: cron2 <[email protected]>
Comment-In-Reply-To: selvanair <[email protected]>
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to