From: Arne Schwabe Date: Mon, 10 Aug 2026 11:42:06 +0000 (+0200) Subject: Reenable xmit_hold when using p2p tcp-server and tls-server X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=603aa9698c140d15b7464af8fb83bd2aa71da680;p=thirdparty%2Fopenvpn.git Reenable xmit_hold when using p2p tcp-server and tls-server Commit 619c3e9 changed the logic to enable xmit_hold only when c->mode is CM_CHILD_TCP. This works for --mode server and was probably done to allow to properly work when the server is listening on multiple sockets and options->ce.proto cannot be used to determine if this socket is tcp or udp. Restore the logic for p2p to avoid both sides starting sending resets at the same time. Github: closes OpenVPN/openvpn#1089 Change-Id: I728067ef08481c87c7b6918c88ebcaeeec466534 Signed-off-by: Arne Schwabe Acked-by: MaxF Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1837 Message-Id: <20260810114212.28379-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38265.html Signed-off-by: Gert Doering --- diff --git a/src/openvpn/init.c b/src/openvpn/init.c index 69d226d3e..08278fc2e 100644 --- a/src/openvpn/init.c +++ b/src/openvpn/init.c @@ -3332,7 +3332,7 @@ do_init_crypto_tls(struct context *c, const unsigned int flags) /* should we not xmit any packets until we get an initial * response from client? */ - if (to.server && c->mode == CM_CHILD_TCP) + if (to.server && (c->mode == CM_CHILD_TCP || (c->mode == CM_P2P && options->ce.proto == PROTO_TCP_SERVER))) { to.xmit_hold = true; }