Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-21 Thread Илья Шипицин
sorry, it does not look like "2 new threads". also, I'm not sure patchwork will be able to pick 2 ack from 1 thread. I'm not motivated to run in circles from you to Gert and back. if you can find someone more motivated, I'll appreciate that. пн, 21 февр. 2022 г. в 17:02, Lev Stipakov : > Reply

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-21 Thread Lev Stipakov
Reply to both of them with the line (remove ">"): > Acked-by: Ilya Shipitsin if you think that you could ack both of those patches. ma 21. helmik. 2022 klo 13.17 Илья Шипицин (chipits...@gmail.com) kirjoitti: > > Lev, I see two new messages in this thread. Please clarify what do you want > me

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-21 Thread Илья Шипицин
Lev, I see two new messages in this thread. Please clarify what do you want me to do? пн, 21 февр. 2022 г. в 13:59, Lev Stipakov : > Let's start from the beginning. > > I'll start two new threads (master and 2.5) and Ilya could ack them. > > Ilya, to ack please reply on those threads with

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-21 Thread Lev Stipakov
Let's start from the beginning. I'll start two new threads (master and 2.5) and Ilya could ack them. Ilya, to ack please reply on those threads with following line: Acked-by: Firstname Lastname su 20. helmik. 2022 klo 19.31 Gert Doering (g...@greenie.muc.de) kirjoitti: > > Hi, > > On Sun, Feb

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Gert Doering
Hi, On Sun, Feb 20, 2022 at 07:53:56PM +0500, ?? wrote: > There is ack from me earlier in this thread. "ACK in this thread" is not really helpful, as it is not clear for which patch exactly this is. (You basically ACKed in response to v1 of the 2.5 patch, while we have v2

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Илья Шипицин
There is ack from me earlier in this thread. Lev, I did all things you asked me to do. Please follow up. I do not catch what else left On Sun, Feb 20, 2022, 7:38 PM Gert Doering wrote: > Hi, > > On Sun, Feb 20, 2022 at 07:29:24PM +0500, ?? wrote: > > Lev, I'm lost here.

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Gert Doering
Hi, On Sun, Feb 20, 2022 at 07:29:24PM +0500, ?? wrote: > Lev, I'm lost here. Can you please follow up? Please test and ACK *this* patch: https://patchwork.openvpn.net/patch/2296/ this is the "v2 for master" patch. When that is done, we can talk about release/2.5

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Илья Шипицин
Lev, I'm lost here. Can you please follow up? On Sun, Feb 20, 2022, 7:18 PM Gert Doering wrote: > Hi, > > On Sun, Feb 20, 2022 at 07:15:33PM +0500, ?? wrote: > > It is applied to master. > > The "adjust build options to harden binaries" has no ACK for master. > > This is

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Gert Doering
Hi, On Sun, Feb 20, 2022 at 07:15:33PM +0500, ?? wrote: > It is applied to master. The "adjust build options to harden binaries" has no ACK for master. This is needed so the 2.5 patch can go into 2.5 gert -- "If was one thing all people took for granted, was conviction

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Илья Шипицин
It is applied to master. git id: https://github.com/OpenVPN/openvpn/commit/9da733751ce80b2226ef19923365bd3102cfbd47 On Sun, Feb 20, 2022, 7:10 PM Gert Doering wrote: > Hi, > > On Sun, Feb 20, 2022 at 07:07:15PM +0500, ?? wrote: > > pdb patch > > Whatever that is... a

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Gert Doering
Hi, On Sun, Feb 20, 2022 at 07:07:15PM +0500, ?? wrote: > pdb patch Whatever that is... a commit ID in master would be much easier for me to cherrypick. (In any case, *this* patch can't go into 2.5 before the *master* patch has an ACK - for patches for "master + 2.5",

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Илья Шипицин
pdb patch On Sun, Feb 20, 2022, 7:04 PM Gert Doering wrote: > Hi, > > On Thu, Feb 17, 2022 at 01:55:35PM +0200, Lev Stipakov wrote: > > > can you please apply "pdb" patch to your branch ? > > > CI: github actions: keep "pdb" in artifacts · OpenVPN/openvpn@9da7337 > > > > Done!

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-20 Thread Gert Doering
Hi, On Thu, Feb 17, 2022 at 01:55:35PM +0200, Lev Stipakov wrote: > > can you please apply "pdb" patch to your branch ? > > CI: github actions: keep "pdb" in artifacts · OpenVPN/openvpn@9da7337 > > Done! https://github.com/lstipakov/openvpn/actions/runs/1858390624 > > > BinSkim uses pdb for

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-17 Thread Илья Шипицин
Ack from me. чт, 17 февр. 2022 г. в 16:55, Lev Stipakov : > Hi, > > > can you please apply "pdb" patch to your branch ? > > CI: github actions: keep "pdb" in artifacts · OpenVPN/openvpn@9da7337 > > Done! https://github.com/lstipakov/openvpn/actions/runs/1858390624 > > > BinSkim uses pdb for

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-17 Thread Lev Stipakov
Hi, > can you please apply "pdb" patch to your branch ? > CI: github actions: keep "pdb" in artifacts · OpenVPN/openvpn@9da7337 Done! https://github.com/lstipakov/openvpn/actions/runs/1858390624 > BinSkim uses pdb for analysis. > > probably, it makes sense to apply this patch to release/2.5

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-17 Thread Илья Шипицин
чт, 17 февр. 2022 г. в 13:53, Lev Stipakov : > Hi, > > Thanks for testing. > > > original patch does not apply > > Indeed it doesn't apply anymore since recent changes to vcxproj files. > I have rebased it. > > > minor build issues still there: test · chipitsine/openvpn@eeff765 ( > github.com) >

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-17 Thread Lev Stipakov
Hi, Thanks for testing. > original patch does not apply Indeed it doesn't apply anymore since recent changes to vcxproj files. I have rebased it. > minor build issues still there: test · chipitsine/openvpn@eeff765 (github.com) Those are likely because this was not applied

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-16 Thread Илья Шипицин
original patch does not apply C:\i\openvpn-chipitsine-2.5>"C:\Program Files\Git\usr\bin\patch.exe" -p1 < c:\users\ilia\Downloads\Openvpn-devel-2.5-msvc-adjust-build-options-to-harden-binaries.diff patching file src/openvpn/openvpn.vcxproj Hunk #1 FAILED at 147. Hunk #2 FAILED at 162. Hunk #3

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-09 Thread Илья Шипицин
Sorry, I did not catch that you have been waiting for me. I'll have a look in couple of days ср, 9 февр. 2022 г. в 15:07, Lev Stipakov : > Hi Ilja, > > Is there any chance you could have a look at this patch? > > > pe 7. tammik. 2022 klo 16.54 Lev Stipakov (lstipa...@gmail.com) kirjoitti: > > >

Re: [Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-02-09 Thread Lev Stipakov
Hi Ilja, Is there any chance you could have a look at this patch? pe 7. tammik. 2022 klo 16.54 Lev Stipakov (lstipa...@gmail.com) kirjoitti: > > From: Lev Stipakov > > - enable hardware-enforced stack protection on > compatible hardware/software (/CETCOMPAT linker option) > > - hash object

[Openvpn-devel] [PATCH 2.5] msvc: adjust build options to harden binaries

2022-01-07 Thread Lev Stipakov
From: Lev Stipakov - enable hardware-enforced stack protection on compatible hardware/software (/CETCOMPAT linker option) - hash object files with SHA256 (/ZH:SHA_256 compiler option) - enable SDL. The required to add _CRT_NONSTDC_NO_DEPRECATE _CRT_SECURE_NO_WARNINGS