Blame

6f02e7 Samuli Seppänen 2025-01-29 06:40:08 1
# IrcMeetings
2
3
## Basic Info
4
5
- **Time**: Wednesday 17 April 2024 at 13:00 CEST (11:00 UTC)
6
- **Place**: #openvpn-meeting channel on LiberaChat IRC network
7
8
## Topics
9
10
### Current Topics
11
12
- **New: updated 2.6.10 with new MSI installers**
13
- _There is a new Windows DCO driver that should handle coming back from hibernation better/faster, as it doesn't wait for keepalive timeout after hibernation._
14
15
- **New: --topology directive**
16
- _We changed the default for this to be 'subnet' as this is the most commonly used setup and has been for ages (used to be net30)._
17
- _This is however breaking things by default for peer to peer setups. We could limit the change to just --server mode._
18
- _djpig will propose a patch and it can be discussed further there._
19
20
- **Closed: live route update feature**
21
- _In short, the ability to update routes, DNS, ifconfig options, live, without having to do a full reconnect._
22
- _After discussing last week seems like a path forward is clear._
23
24
- **Updated: Security mailing list procedure can stand improvement**
25
- _company will improve process on picking up tasks from security mailing list in the next week or so._
26
- _The idea being that community guys will continue doing their thing as usual, and company guys monitor the list for company related items and follow up on those._
27
- _The idea of an NDA is also revived. But it was made clear internally that we need like a one-page simple NDA for community members, not the unnecessarily restrictive one originally suggested by legal guys._
28
29
- **Updated: DCO and Linux upstreaming, API change**
30
- _Upstreaming DCO to Linux is proceeding, it is in review stage at the moment._
31
- _ordex will send a patchset v3 based on feedback received today._
32
- _There will be an API change that makes it incompatible with the current implementation._
33
- _A graceful solution to that was already discussed and in motion. giaan will be working on this._
34
35
- **Updated: donation collection**
36
- _From earlier exploration it is clear that setting up a legal entity is not worth the expense at this point. We're just starting out with donations._
37
- _What we can do is start out with an existing company that can collect the money and puts it to good community use. ordex volunteers to take this on._
38
- _There are some options to consider. There may be existing solutions that we want to consider._
39
- _PayPal seems overly expensive with all their fees._
40
- _Stripe could be worth considering for credit card processing._
41
- _GitHub Sponsors was mentioned as a possible solution, this is worth investigating._
42
- _Open Collective was also mentioned, that needs some investigating how that exactly would work for us._
43
44
- **Updated: forums topics**
45
- _ecrist still working on forums. waiting on ecrist to move things around._
46
- _Plan is to soon switch URLs so new forum is on forums.openvpn.net and old forums is on archive address._
47
- _email confirmation on registration was suggested._
48
- _mod guide, hard or soft delete (chuck board?), what to do with GDPR, etc. (write it down and actually make it available to mods, maybe a hidden topic)_
49
- _access for mods to logs so one can see what others did_
50
51
- **Updated: mattock topics**
52
- _Managed to make tests run reliably now, the occassional failures seem resolved now._
53
- _Documentation here: [https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst)_
54
- _Will submit a patch soon._
55
56
- **OpenVPN community meetup 2024**
57
- _Naming: We decided to rename from 'Hackathon' to 'OpenVPN community meetup'. This has a more open spirit to it._
58
- _Where: Karlsruhe, Germany. Meeting room location to be determined._
59
- _When: At the moment tentatively set to 20-22 September 2024._
60
- _Who: We'll do an open invitation to openvpn-devel mailing list, but also CC: specifically past attendees and people of interest._
61
- _Shirts: There is plenty of time still to prepare a shirt design._
62
- _There's a wiki page up now where we can coordinate: [https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024](https://community.openvpn.net/openvpn/wiki/CommunityMeetup2024)_
63
64
- **Website release process**
65
- _Waiting for faster way to update community downloads and security advisories on main site._
66
- _Again postponed due to issues. Now planned for this week. We'll see._
67
68
- **Status of SBOM**
69
- _There was a discussion between MaxF and djpig and others._
70
- _For OpenVPN2 / OpenVPN-NL, there is not much overlap, as OpenVPN2 doesn't ship much in terms of libraries, but OpenVPN-NL does._
71
- _The interesting use-case for an SBOM is really the OpenVPN Windows GUI client._
72
73
- **Status of trac/wiki**
74
- _No progress since last meeting._
75
- _This will probably have to wait until "--dev null" is done_
76
- _Should have access controls so only approved members can edit._
77
78
- **Tunnelcrack progress [TunnelCrack community wiki article](https://community.openvpn.net/openvpn/wiki/TunnelCrack)**
79
- _Current status: when mitigations start appearing we will mention them in meeting notes._
80
81
- **Static-key mini how-to is outdated.**
82
- _This page is outdated badly: [https://openvpn.net/community-resources/static-key-mini-howto/](https://openvpn.net/community-resources/static-key-mini-howto/)_
83
- _company will send this to tech writer to redo based on [https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst](https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst) info and also retain a link to that github doc._
84
- _having a simple guide online will help adoption_
85
86
- **OpenVPN 2.6 performance results.**
87
- _tests should cover: gre, ipsec, userland, dco_
88
- _linux, freebsd, windows_
89
- _requires time to be dedicated to doing this, when time available will do it_
90
91
- **What's going on with new taskbar icons?**
92
- _matt provided icons in [https://github.com/OpenVPN/openvpn-gui/issues/595](https://github.com/OpenVPN/openvpn-gui/issues/595)_
93
- _last update: will be picked up by selva when he has time_
94
95
- **Software code signing topic**
96
- _company switched EV code signing to cloudhsm, this is same cert type we use for driver signing, is also suitable for binary signing._
97
- _in future we could possibly switch community to that same key. saves having to maintain 2 different keys._
98
- _depends on how hard/easy it is to access company key signing thingee from community infrastructure._
99
- _also no high priority at the moment, we have a working solution now._
100
101
- **Management interface documentation on main website will be updated with info from doc/management-notes.txt**
102
- _novaflash will pick this up at some point_
103
104
## Mattock Topics
105
106
### --dev null server testing
107
108
Latest status in [ServerSideTestingImprovementPlan](https://github.com/mattock/openvpn/blob/dev_null/doc/server-side-testing-improvement-plan.rst). Additional details in [https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst](https://github.com/mattock/openvpn/blob/dev_null/doc/dev-null-test-suite.rst). Current PoC code is available in mattock's "dev_null" branch. A good starting point is [t_server_null.sh](https://github.com/mattock/openvpn/blob/dev_null/tests/t_server_null.sh).
109
110
Potential next steps:
111
112
- Expand the test suite
113
- Integrate into Buildbot (i.e. get to production)
114
- Support multiple client versions (depends on Buildbot integration)
115
116
Git commit history needs to be cleaned up and there may be other small fixes / improvements here and there to be done:
117
118
- Enable disabling the test suite (requires root so we can't run it by default)
119
120
### Debian/Ubuntu snapshot publishing
121
122
- In the last meeting we agreed to publish snapshot Debian/Ubuntu packages on *build.openvpn.net*
123
- The tool to use to publish is [aptly](https://www.aptly.info/)
124
- Aptly does not have direct support for running commands (e.g. rsync, scp) after publishing packages, e.g. to a local filesystem on the buildmaster
125
- **Option 1 (hacky)**: use **inotifywait** with **rsync** or **scp** to copy the published repo to build.openvpn.net
126
- **Option 2 (less hacky)**: use **NFS** to publish "directly" to build.openvpn.net
127
- Both options require a fair amount of tinkering
128
- Mattock moved this forward a bit at the buildbot end (get the files out from workers)