Blame
| c9d9c9 | Samuli Seppänen | 2025-01-29 12:06:32 | 1 | # Introduction |
| 2 | ||||
| 3 | This page shows the high-level status of the OpenVPN 2.4 release. For all the details, see the [Active Tickets by Milestone](report:3) report. |
|||
| 4 | ||||
| 5 | # Schedule |
|||
| 6 | ||||
| 7 | - **November 16** - 2.4_beta1 |
|||
| 8 | After this date, no new features are allowed; stabilizing starts for real. Some minor "nice to have" patches might be accepted after evaluation/discussion on IRC. |
|||
| 9 | ||||
| 10 | - **(optional) November 24th/25th** - 2.4_beta2 |
|||
| 11 | Only patches related to stabilizing and important bug-fixes are allowed after this point. No more "nice to have" patches after this point. This release can be skipped if there are no bug fixes or otherwise stabilizing code. |
|||
| 12 | ||||
| 13 | - **December 1st** - 2.4_rc1 |
|||
| 14 | Only really needed and critical bug fixes allowed. This is also the time where we change to a unified coding style across the whole source code. |
|||
| 15 | ||||
| 16 | - **December 15th** - 2.4_rc2 |
|||
| 17 | Branching out release/2.4 happens here. |
|||
| 18 | ||||
| 19 | - **December 28th** - 2.4.0 |
|||
| 20 | Final release. |
|||
| 21 | ||||
| 22 | ## Deadline: Debian 9 freeze |
|||
| 23 | ||||
| 24 | Mattock asked the Debian package maintainer about getting 2.4_something into Debian 9 before the freeze. Here's the response: *"I'll consider uploading 2.4_something in early December, so we have a month to fix possible issues. After December 29, it won't be doable."* |
|||
| 25 | ||||
| 26 | # Features/Fixes to Include |
|||
| 27 | ||||
| 28 | ## Must Have |
|||
| 29 | ||||
| 30 | All done. |
|||
| 31 | ||||
| 32 | ## Minor, but "We Should Try to Make It Happen" |
|||
| 33 | ||||
| 34 | | **Task Description** | **Assigned to** | **Status** | |
|||
| 35 | | --- | --- | --- | |
|||
| 36 | | [struct argv overhaul](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12818.html) | d12fk | Patch review completed (dazo), patches 1-4 applied, patches 5-7 need v2 | |
|||
| 37 | | [auth-gen-token: Inform client why auth-token was rejected](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12848.html) | dazo | Patch review in progress (syzzer) | |
|||
| 38 | | [tftp/wpad patch](http://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg10511.html) | jjk | Patch on list, needs review and merge | |
|||
| 39 | | Support TLS record splitting (like ovpn3) | syzzer | #554 (started, but no patches available yet) | |
|||
| 40 | | [Allow OpenVPN to communicate to peers via a Linux VRF](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12767.html) | - | [Updated patches](https://github.com/OpenVPN/openvpn/pull/65/commits/1baa7e6782b39ed664eedb9b006728d31e22c07e) need review + ML submission | |
|||
| 41 | | Test server that does --auth-user-pass and/or challenge stuff | cron2 (snair) | Not started | |
|||
| 42 | | Update auth-user-pass docs | mattock | Not started, discussion [here](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12835.html) | |
|||
| 43 | | Update OpenVPN PRF (move away from SHA1/MD5) | syzzer | Not started | |
|||
| 44 | ||||
| 45 | ## Work Needed |
|||
| 46 | ||||
| 47 | - Trac tickets (2.3.x, 2.4.x, unclassified) |
|||
| 48 | ||||
| 49 | ## (Major) Items Already Done |
|||
| 50 | ||||
| 51 | - Poor man's NCP (v6) |
|||
| 52 | - Make openvpnserv2 use exit-events |
|||
| 53 | - Combined 32/64-bit Windows installers |
|||
| 54 | - Semi-automated testing of OpenVPN/OpenVPN-GUI/openvpnserv2 on Windows using [openvpn-windows-test](https://github.com/OpenVPN/openvpn-windows-test) |
|||
| 55 | - dhcp-option DNS6 (stub, windows netsh+service, android) |
|||
| 56 | - Bundle OpenSSL 1.0.2 on Windows |
|||
| 57 | - [Refactor CRL handling](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12809.html) |
|||
| 58 | - [--tls-crypt control channel encryption](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg12974.html) #633 |
|||
| 59 | - ifconfig-before-open reversal patch for Windows fixed (argv_printf) and merged |
|||
| 60 | - openvpnserv2 integration |
|||
| 61 | - Pushable ciphers, and cipher negotiation |
|||
| 62 | - True dual-stack operation (2.3 has "dual single-stack") |
|||
| 63 | - Interactive service + openvpn-gui integration |
|||
| 64 | - IPv6 route-gateway redirection |
|||
| 65 | - AEAD cipher |
|||
| 66 | - Cipher negotiation (for all but a few corner cases) |
|||
| 67 | - Peer-id (server and client, 2.3 has only client) |
|||
| 68 | - Compression v2 = more efficient alignment |
|||
| 69 | - Unified TCP timeout handling (Arne v3) |
|||
| 70 | - New buildbots for FreeBSD 10.3, NetBSD 7.0.1, OpenBSD 6.0, MacOS X, various recent Linux versions |
|||
| 71 | - --multihome fixed on BSD/amd64 architectures, tested by buildbots |
|||
| 72 | - Recursive routing fixup (Lev v4) |
|||
| 73 | - Block-outside-dns on multiple tunnels (v2, Selva) |
|||
| 74 | - Re-indent formatting (dazo, syzzer). More details on CodeStyle |
