<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src, branch OPENBSD_7_6_BASE</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_7_6_BASE</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_7_6_BASE'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2024-09-22T14:59:48+00:00</updated>
<entry>
<title>Reinstate bounds check accidentally disabled when defining OPENSSL_NO_DTLS1</title>
<updated>2024-09-22T14:59:48+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-22T14:59:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e58cba35ab15d6597f0c9cd8d6fba1928ade3acf'/>
<id>urn:sha1:e58cba35ab15d6597f0c9cd8d6fba1928ade3acf</id>
<content type='text'>
From Kenjiro Nakayama
Closes https://github.com/libressl/portable/issues/1097
</content>
</entry>
<entry>
<title>remove unneeded semicolons; checked by millert@</title>
<updated>2024-09-20T02:00:46+00:00</updated>
<author>
<name>jsg</name>
<email></email>
</author>
<published>2024-09-20T02:00:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=bd425e27ad9c9e978ee7a877656733f4742e01cc'/>
<id>urn:sha1:bd425e27ad9c9e978ee7a877656733f4742e01cc</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Enable large number of extension tests and stop skippking QUIC transport</title>
<updated>2024-09-18T19:12:37+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-18T19:12:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=4eb33e8fd82392fb4a1bd0371751b715f59cb0fb'/>
<id>urn:sha1:4eb33e8fd82392fb4a1bd0371751b715f59cb0fb</id>
<content type='text'>
parameter extension which we now know about
</content>
</entry>
<entry>
<title>tlsfuzzer: add a start-server convenience target for interactive testing</title>
<updated>2024-09-17T08:47:37+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-17T08:47:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a3dfde83168aecbb6a98aa0743c0c69da4a7dcf0'/>
<id>urn:sha1:a3dfde83168aecbb6a98aa0743c0c69da4a7dcf0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Replace OpenSSL 3.1 (which no longer is in ports) with 3.3</title>
<updated>2024-09-17T06:12:06+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-17T06:12:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=6e34bd33930f39214ac1267b6475a5f09858ce17'/>
<id>urn:sha1:6e34bd33930f39214ac1267b6475a5f09858ce17</id>
<content type='text'>
</content>
</entry>
<entry>
<title>tlsfuzzer: grammar fix missed in previous</title>
<updated>2024-09-14T07:11:34+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-14T07:11:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=66b93829fa7df600a9678c3990da889f04aadbac'/>
<id>urn:sha1:66b93829fa7df600a9678c3990da889f04aadbac</id>
<content type='text'>
</content>
</entry>
<entry>
<title>typo: troups -&gt; groups</title>
<updated>2024-09-13T05:58:17+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-13T05:58:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=746015254469781a178d5e33a0389004f2e446f4'/>
<id>urn:sha1:746015254469781a178d5e33a0389004f2e446f4</id>
<content type='text'>
</content>
</entry>
<entry>
<title>parametes -&gt; parameters</title>
<updated>2024-09-11T15:04:16+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-11T15:04:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=09903e44fed5f689c935935b95c447ccb1465128'/>
<id>urn:sha1:09903e44fed5f689c935935b95c447ccb1465128</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Make error 235 resolve to "no application protocol"</title>
<updated>2024-09-09T07:40:03+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-09T07:40:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=ff309a8343aabbb4675e666bacf197d8838061b4'/>
<id>urn:sha1:ff309a8343aabbb4675e666bacf197d8838061b4</id>
<content type='text'>
We accidentally have two errors 235 since we didn't notice that OpenSSL
removed the unused SSL_R_TRIED_TO_USE_UNSUPPORTED_CIPHER and later that
becamse SSL_R_NO_APPLICATION_PROTOCOL. Getting an "unsupported cipher"
error when fiddling with ALPN is confusing, so fix that.

ok jsing
</content>
</entry>
<entry>
<title>Fix alert callback in the QUIC layer</title>
<updated>2024-09-09T03:55:55+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2024-09-09T03:55:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=47902b1741d383c06ea246859858115749b1c9b6'/>
<id>urn:sha1:47902b1741d383c06ea246859858115749b1c9b6</id>
<content type='text'>
Only close_notify and user_cancelled are warning alerts. All others
should be fatal. In order for the lower layers to behave correctly,
the return code for fatal alerts needs to be TLS13_IO_ALERT instead
of TLS13_IO_SUCCESS.

Failure to signal handshake failure in the public API led to a crash
in HAProxy when forcing the tls cipher to TLS_AES_128_CCM_SHA256 as
found by haproxyfred while investigating
https://github.com/haproxy/haproxy/issues/2569

Kenjiro Nakayama found misbehavior of ngtcp2-based servers, wrote a
similar patch and tested this version.

Fixes https://github.com/libressl/portable/issues/1093

ok jsing
</content>
</entry>
</feed>
