<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/regress/lib/libcrypto, branch OPENBSD_7_9</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_7_9</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_7_9'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2026-04-13T17:04:23+00:00</updated>
<entry>
<title>Prior to this we substring matched and allowed a leading .</title>
<updated>2026-04-13T17:04:23+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2026-04-13T17:04:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=cf3eec32e7a6acbaecd14871fb75ad34fb76c3e7'/>
<id>urn:sha1:cf3eec32e7a6acbaecd14871fb75ad34fb76c3e7</id>
<content type='text'>
on a SAN DNSname constraint. This is not correct, as with
a DNSname constraint, it may exacly match or match zero or
more additional components on the front of the candidte to
match.

Spotted by Haruto Kimura &lt;hkimura2026@gmail.com&gt;

ok tb@ kenjiro@
</content>
</entry>
<entry>
<title>Adjust depth check to match change in verifier.</title>
<updated>2026-04-01T14:39:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-04-01T14:39:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=89eb797db1e499a83313d47457a8fa9fe9272e8c'/>
<id>urn:sha1:89eb797db1e499a83313d47457a8fa9fe9272e8c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add additional X.509 verifier test cases.</title>
<updated>2026-03-31T13:39:48+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-03-31T13:39:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=848a8ff0f8b9bd889cd059b6040b85d5cd2cc980'/>
<id>urn:sha1:848a8ff0f8b9bd889cd059b6040b85d5cd2cc980</id>
<content type='text'>
The second case (14b) currently triggers a bug in the new verifier.
</content>
</entry>
<entry>
<title>Run new test certificate bundles through Go's verifier.</title>
<updated>2026-03-31T13:37:45+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-03-31T13:37:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e2ae938d435d7b2dd9dbd93f4ee01af27ccd864d'/>
<id>urn:sha1:e2ae938d435d7b2dd9dbd93f4ee01af27ccd864d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add additional certificate test bundles.</title>
<updated>2026-03-31T13:37:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-03-31T13:37:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5dfea9a73c261844c01f9d5cb3f0972a24e2ba98'/>
<id>urn:sha1:5dfea9a73c261844c01f9d5cb3f0972a24e2ba98</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Generate two additional certificate test scenarios which have deep chains.</title>
<updated>2026-03-31T13:34:25+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-03-31T13:34:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=de6886498c915f9480c27735044fb65a6578e0c3'/>
<id>urn:sha1:de6886498c915f9480c27735044fb65a6578e0c3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add missing include path required to reach newly added crypto_assembly.h</title>
<updated>2026-03-29T06:19:12+00:00</updated>
<author>
<name>anton</name>
<email></email>
</author>
<published>2026-03-29T06:19:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=66d7751c9972254d6d0f07fca49cf3533f291b5c'/>
<id>urn:sha1:66d7751c9972254d6d0f07fca49cf3533f291b5c</id>
<content type='text'>
include.
</content>
</entry>
<entry>
<title>rfc3779 regress: explain where the range comes from</title>
<updated>2026-03-13T06:47:34+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-03-13T06:47:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7d892da013d87af304d51aa7b2f8d8e284b459ae'/>
<id>urn:sha1:7d892da013d87af304d51aa7b2f8d8e284b459ae</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rfc3779 regress: add an actual range</title>
<updated>2026-03-13T06:40:56+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-03-13T06:40:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f82cf34cdfda5cb110c15fef4f54ba94e1beb3a9'/>
<id>urn:sha1:f82cf34cdfda5cb110c15fef4f54ba94e1beb3a9</id>
<content type='text'>
This improves the test coverage of make_addressRange() where there is an
annoyance with unused bits in the RFC 3779 ASN.1 encoding versus trailing
ones in the network encoding that the X509v3_addr_add_range() API expects.
</content>
</entry>
<entry>
<title>assembly regress: use make's MACHINE_ARCH rather than handrolling it</title>
<updated>2026-01-25T14:57:43+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-01-25T14:57:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=efd505d49400b554c0256059d2e26357d2be6066'/>
<id>urn:sha1:efd505d49400b554c0256059d2e26357d2be6066</id>
<content type='text'>
discussed with jsing
</content>
</entry>
</feed>
