Attention is currently required from: ordex, plaisthos.
ralf_lici has posted comments on this change by ordex. (
http://gerrit.openvpn.net/c/openvpn/+/1835?usp=email )
Change subject: dco: do not exit the process when installing a DCO key fails
......................................................................
Patch Set 1:
(1 comment)
Patchset:
PS1:
The change looks good to me overall, but I wonder whether we could avoid adding
the persistent bool to `tls_multi`.
Basically, the error must ultimately propagate from `init_key_contexts` to
`check_tls`, where the recovery action can be dispatched. The call graph
branches at `tls_session_generate_data_channel_keys` whose callers are:
- `tls_session_update_crypto_params_do_work`, whose failure is already
propagated by its callers to paths that emit `SIGUSR1`, and
- `tls_multi_process` where the failed key is moved to `S_ERROR_PRE` but the
failure does not currently request a connection restart from `check_tls`.
So, one possible simplification would be to add a `TLSMP_RESTART` result and
return it from `tls_multi_process` when key generation fails with DCO enabled:
```
if (!tls_session_generate_data_channel_keys(multi, session))
{
msg(D_TLS_ERRORS, "TLS Error: generate_key_expansion failed");
ks->authenticated = KS_AUTH_FALSE;
key_state_ssl_shutdown(&ks->ks_ssl);
ks->state = S_ERROR_PRE;
if (session->opt->dco_enabled)
{
active = TLSMP_RESTART;
}
}
```
`check_tls` could then emit `SIGUSR1` when it receives `TLSMP_RESTART`.
This would avoid storing a persistent cross-layer error flag in `tls_multi` and
would propagate the recovery request directly through the existing
`tls_multi_process` result contract.
Would this approach make sense?
--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1835?usp=email
To unsubscribe, or for help writing mail filters, visit
http://gerrit.openvpn.net/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: I564edc6e0cc179c2b8b5ddef5e80838949fe9fcd
Gerrit-Change-Number: 1835
Gerrit-PatchSet: 1
Gerrit-Owner: ordex <[email protected]>
Gerrit-Reviewer: plaisthos <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-CC: ralf_lici <[email protected]>
Gerrit-Attention: plaisthos <[email protected]>
Gerrit-Attention: ordex <[email protected]>
Gerrit-Comment-Date: Wed, 05 Aug 2026 07:10:22 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel