summaryrefslogtreecommitdiff
path: root/src/lib/libc/stdlib/hcreate.c (unfollow)
Commit message (Collapse)AuthorFilesLines
2021-07-19document X509_CRL_print(3) and X509_CRL_print_fp(3)schwarze5-7/+124
2021-07-19Mop up dtls1_get_ccs_header() and struct ccs_header_st.jsing3-21/+3
All this code does is read one byte from memory with an unknown length, potentially being a one byte overread... and then nothing is actually done with the value. ok tb@
2021-07-19Inline DTLS1_CCS_HEADER_LENGTH rather than having a single use variable.jsing1-3/+2
ok tb@
2021-07-15Wrap over 80 long lines in ca.cinoguchi1-83/+154
2021-07-15Explicitly check pointer variable if it is NULL or not in ca.cinoguchi1-58/+58
2021-07-15Remove space between '*' and pointer variable in ca.cinoguchi1-56/+56
2021-07-15Use 'serial' rather than 'ser' in ca.cinoguchi1-19/+19
input from jsing@
2021-07-15Convert openssl(1) ca option handlinginoguchi1-456/+643
New option handling for openssl(1) ca. This diff is just replacing with new option handling, no functional change. I'm using the word DN or RDN in description as manual uses them, rather than replacing with "Distinguished Name" or "Relative Distinguished Name". I would like to add another fixes below by follow-up diffs. - remove space between '*' and pointer variable - wrap 80+ long lines - explicitly check pointer variable if it is NULL or not comments and ok from jsing@
2021-07-14Remove unneeded calls to tls_init(3)kn1-6/+1
As per the manual and lib/libtls/tls.c revision 1.79 from 2018 "Automatically handle library initialisation for libtls." initialisation is handled automatically by other tls_*(3) functions. Remove explicit tls_init() calls from base to not give the impression of it being needed. Feedback tb OK Tests mestre
2021-07-12new manual page X509_print_ex(3)schwarze4-5/+287
2021-07-12Use the x509_verify_cert_cache_extensions fuction instead of manuallybeck1-9/+4
calling the OpenSSL legacy cache extensions goo. Requested by tb@ ok tb@
2021-07-12Change the error reporting pattern throughout the tree when unveilbeck2-13/+13
fails to report the path that the failure occured on. Suggested by deraadt@ after some tech discussion. Work done and verified by Ashton Fagg <ashton@fagg.id.au> ok deraadt@ semarie@ claudio@
2021-07-12document X509V3_extensions_print(3)schwarze6-7/+112
2021-07-12document X509V3_EXT_print(3)schwarze5-8/+167
2021-07-11While the traditional OpenSSL return value and behaviour of BIO_dump(3)beck2-31/+17
is pure comedy gold, and now documented as such, sadly this bit of pure Muppet genius can't really in good consience stay in the tree as is. Change BIO_dump to always return the number of bytes printed on success and to stop printing and return -1 on failure if a writing function fails. ok tb@, jsing@
2021-07-11new manual page ASN1_parse_dump(3)schwarze5-7/+222
2021-07-11document ASN1_get_object(3)schwarze4-5/+207
2021-07-10Fix a read buffer overrun in X509_CERT_AUX_print(3),schwarze1-3/+3
which by implication also affects X509_print(3). The ASN1_STRING_get0_data(3) manual explitely cautions the reader that the data is not necessarily NUL-terminated, and the function X509_alias_set1(3) does not sanitize the data passed into it in any way either, so we must assume the alias->data field is merely a byte array and not necessarily a string in the sense of the C language. I found this bug while writing manual pages for these functions. OK tb@ As an aside, note that the function still produces incomplete and misleading results when the data contains a NUL byte in the middle and that error handling is consistently absent throughout, even though the function provides an "int" return value obviously intended to be 1 for success and 0 for failure, and even though this function is called by another function that also wants to return 1 for success and 0 for failure and even does so in many of its code paths, though not in others. But let's stay focussed. Many things would be nice to have in the wide wild world, but a buffer overflow must not be allowed to remain in our backyard.
2021-07-10new manual page BIO_dump(3)schwarze3-3/+149
2021-07-10Add a bunch of workarond in the verifier to support partial chains andbeck2-16/+135
the saving of the first error case so that the "autochain" craziness from openssl will work with the new verifier. This should allow the new verification code to work with a bunch of the autochain using cases in some software. (and should allow us to stop using the legacy verifier with autochain) ok tb@
2021-07-09Fix mixup between localKeyID and friendlyName.tb1-3/+3
"please commit" schwarze
2021-07-09KNF: remove whitespace between functions and parenthesestb6-28/+28
2021-07-09new manual page for X509_keyid_set1(3), X509_keyid_get0(3),schwarze5-9/+184
X509_alias_set1(3), X509_alias_get0(3)
2021-07-08document X509_add1_reject_object(3) and X509_reject_clear(3)schwarze1-7/+24
2021-07-08add new manual page for X509_add1_trust_object(3) and X509_trust_clear(3)schwarze3-3/+87
2021-07-06document X509_signature_dump(3) and X509_signature_print(3)schwarze5-9/+97
2021-07-06alarm(3) cannot fail, remove error handling.bluhm1-3/+2
suggested by millert@
2021-07-06Fix a bug in X509_print_ex(3).schwarze1-3/+3
If the user set nmflags == X509_FLAG_COMPAT and X509_NAME_print_ex(3) failed, the error return value of 0 was misinterpreted as an indicator of success, causing X509_print_ex(3) to ignore the error, continue printing, and potentially return successfully even though not all the content of the certificate was printed. The X509_NAME_print_ex(3) manual page explains that this function indicates failure by returning 0 if nmflags == X509_FLAG_COMPAT and by returning -1 if nmflags != X509_FLAG_COMPAT. That's definitely atrocious API design (witnessed by the complexity of the code needed for correct error checking), but changing the API contract and becoming incompatible with OpenSSL would make matters even worse. Note that just checking for <= 0 in all cases would not be correct either because X509_NAME_print_ex(3) returns 0 to indicate that it successfully printed zero bytes in some cases, for example when all three of the following conditions hold: 1. nmflags != X509_FLAG_COMPAT 2. indent == 0 (which X509_print_ex(3) does use in some cases) 3. the name object is NULL or empty I found the bug by code inspection and proposed an incomplete patch, then jsing@ proposed this improved version of the patch. OK jsing@.
2021-07-05document i2a_ASN1_OBJECT(3)schwarze1-8/+61
2021-07-04document X509_find_by_subject(3) and X509_find_by_issuer_and_serial(3)schwarze3-3/+74
2021-07-04Bugfix: when X509_NAME_dup(3) failed, X509_NAME_set(3) indicated successschwarze1-14/+8
even though it did not actually set the name. Instead, indicate failure in this case. This commit sneaks in a small, unrelated change in behaviour. If the first argument of X509_NAME_set(3) was NULL, the function used to return failure. Now it crashes the program by accessing the NULL pointer, for compatibility with the same change in OpenSSL. This merges the following two commits from the OpenSSL-1.1.1 branch, which is still available under a free license: 1. 180794c5 Rich Salz Sep 3 11:33:34 2017 -0400 2. c1c1783d Richard Levitte May 17 09:53:14 2018 +0200 OK tb@
2021-07-03Document X509_NAME_set(3).schwarze1-3/+41
It is not particularly well-designed and sets a number of traps for the unwary, but it is a public API function in both OpenSSL and LibreSSL and used at various places.
2021-07-03Do a first pass clean up of SSL_METHOD.jsing4-103/+14
The num_ciphers, get_cipher_by_char and put_cipher_by_char function pointers use the same function for all methods - call ssl3_num_ciphers() directly, absorb ssl3_get_cipher_by_char() into SSL_CIPHER_find() and remove the unused ssl3_put_cipher_by_char() code. ok inoguchi@ tb@
2021-07-03Garbage collect do_test_cipherlist().jsing1-45/+0
This code no longer compiles and the equivalent test coverage has been added to regress/lib/libssl/ciphers (and is actually run).
2021-07-03Add test that ensures ssl3_ciphers[] is sorted by cipher id.jsing1-0/+37
2021-07-03Rewrite get_put_test() as cipher_find_test().jsing1-54/+25
The get_cipher_by_char() and put_cipher_by_char() pointers are no longer accessible on the SSL_METHOD (and soon will not even exist). Rewrite the test to use SSL_CIPHER_find() instead.
2021-07-03fix a bug that resulted in incomplete testing:schwarze1-4/+4
end statements with ';' because ',' isn't enough
2021-07-02Document the read-only (sic!) accessor function X509_NAME_ENTRY_set(3).schwarze1-9/+77
While here, stress that X509_NAME objects cannot share X509_NAME_ENTRY objects, and polish a few misleading wordings.
2021-07-02Add a roff comment saying that X509_certificate_type(3) is intentionallyschwarze1-2/+5
undocumented. It is archaic and practically unused and unusable. tb@ and jsing@ agree with marking it as undocumented. Put the comment here because EVP_PKEY_base_id(3) is a viable alternative.
2021-07-02call the API function X509_NAME_cmp(3) instead of the obsolete,schwarze1-2/+2
undocumented macro alias X509_name_cmp(3); no change to the assembler code generated by the compiler; OK tb@
2021-07-02Add a roff comment saying that X509_name_cmp(3) is intentionallyschwarze1-2/+4
undocumented because it is almost unused in real-world code. OK tb@
2021-07-01Merge SSL_METHOD_INTERNAL into SSL_METHOD.jsing15-195/+126
Now that SSL_METHOD is opaque and in internal headers, we can remove SSL_METHOD_INTERNAL by merging it back into SSL_METHOD. ok tb@
2021-06-30Disable some code that reaches into libssl internals.jsing1-0/+7
This should be moved to a dedicated regress test.
2021-06-30Disable some tests that probably no longer make sense.jsing1-0/+5
We'll either fix these or remove them in the near future.
2021-06-30Pull in ssl_locl.h to allow for move of struct ssl_session_st.jsing2-2/+5
2021-06-30Prepare to provide SSL_get_signature_nid() and friends.jsing2-2/+81
This adds functionality for SSL_get_signature_nid(), SSL_get_peer_signature_nid(), SSL_get_signature_type_nid() and SSL_get_peer_signature_type_nid(). This is not currently publicly visible and will be exposed at a later date. ok inoguchi@ tb@
2021-06-30Move some structs from public to private headers.jsing3-125/+108
Move struct ssl_cipher_st, struct ssl_method_st, struct ssl_session_st and struct ssl3_state_st from public to private headers. These are already under #ifdef LIBRESSL_INTERNAL and are no longer publicly visible. ok inoguchi@ tb@
2021-06-30document and deprecate the macros X509_extract_key(3)schwarze1-6/+35
and X509_REQ_extract_key(3), using feedback from tb@ and jsing@
2021-06-30Correct sigalg hash usage when signing content for client verify.jsing1-3/+2
This was inadvertently broken during sigalgs refactoring.
2021-06-29Pull sigalg selection up into ssl3_send_client_verify().jsing1-14/+11
This means that we do sigalg selection for all cases, including those where are are not sending sigalgs. This is needed in order to track our signature type in legacy cases. ok tb@