[XS] Change in openvpn[master]: Correctly calculate packet id size when epoch packet format is in use
"plaisthos \(Code Review\) via Openvpn-devel" <[email protected]> Tue, 28 Jul 2026 22:25:08 +0000
| Newsgroups | gmane.network.openvpn.devel |
|---|---|
| Message-ID | <d24dcfa14e95d75aa7e7c9a1182461fc0af0859d-EmailReplacePatchSet-HTML@gerrit.openvpn.net> |
Attention is currently required from: ordex, plaisthos.
Hello ordex,
I'd like you to reexamine a change. Please visit
http://gerrit.openvpn.net/c/openvpn/+/1829?usp=email
to look at the new patch set (#2).
The following approvals got outdated and were removed:
Code-Review-1 by ordex
Change subject: Correctly calculate packet id size when epoch packet format is in use
......................................................................
Correctly calculate packet id size when epoch packet format is in use
The code assumed that always when tls mode (without CFB/OFB) is in use
that the packet size is 4 bytes. With epoch packet format is incorrect
as that uses 64 bit.
Even thought packet_id_long_form has a the same size (8 byte) it is not
the same header format (32 bit time + 32 bit IV) as the epoch
format (16 bit epoch + 48 IV). Use a simple sizeof(uint64_t) to
avoid suggesting that it might be the same.
Closes: Github #1074
Change-Id: I5b862eabe032eb4d2229ff5b2f4f6af7406f6f4e
Signed-off-by: Arne Schwabe <[email protected]>
---
M src/openvpn/mtu.c
1 file changed, 8 insertions(+), 0 deletions(-)
git pull ssh://gerrit.openvpn.net:29418/openvpn refs/changes/29/1829/2
diff --git a/src/openvpn/mtu.c b/src/openvpn/mtu.c
index e5db8ab..1f64a8a 100644
--- a/src/openvpn/mtu.c
+++ b/src/openvpn/mtu.c
@@ -35,6 +35,7 @@
#include "crypto.h"
#include "memdbg.h"
+#include "ssl_common.h"
/* allocate a buffer for socket or tun layer */
void
@@ -51,6 +52,13 @@
calc_packet_id_size_dc(const struct options *options, const struct key_type *kt)
{
bool tlsmode = options->tls_server || options->tls_client;
+ bool epoch = options->imported_protocol_flags & CO_EPOCH_DATA_KEY_FORMAT;
+
+ /* epoch uses a 64-bit packet ID consisting of 64 bit (24 bit epoch + 48 bit IV) */
+ if (epoch)
+ {
+ return sizeof(uint64_t);
+ }
bool packet_id_long_form = !tlsmode || cipher_kt_mode_ofb_cfb(kt->cipher);
--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1829?usp=email
To unsubscribe, or for help writing mail filters, visit http://gerrit.openvpn.net/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: I5b862eabe032eb4d2229ff5b2f4f6af7406f6f4e
Gerrit-Change-Number: 1829
Gerrit-PatchSet: 2
Gerrit-Owner: plaisthos <[email protected]>
Gerrit-Reviewer: ordex <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-Attention: plaisthos <[email protected]>
Gerrit-Attention: ordex <[email protected]>
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel