summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto/objects (unfollow)
Commit message (Collapse)AuthorFilesLines
2026-05-25Remove unused prototype.jsing1-2/+1
2026-05-22rfc3779 test: various minor tweakstb1-15/+32
- include length in hexdump output - show hexdumps also if lengths don't match - more comments and consistency
2026-05-22rfc3779 regress: tweak order of variable declarationstb1-2/+2
2026-05-21rfc3779 test: exercise IPAddressFamily_cmp a bit moretb1-1/+168
This populates an IPAddrBlocks object with not all that sensible data and tests behavior of serialization and deserialization of this thing. Prior to x509_addr.c rev 1.96 this would call memcmp() on NULL.
2026-05-19remove '#undef _' added for Windows CEjsg1-5/+1
ok jsing@ tb@
2026-05-19libcrypto/ui: mechanically rename the union _ into utb1-29/+29
While mainstream OS use compilers that understand anonymous unions, which would be cleaner here, some special snowflakes rely on LibreSSL in their stacks and they sometimes use very old and special compilers. There is no need to impose a burden on them. There is far more impactful and important cleanup that could be done in the ui pit. This obviates jsg's upcoming removal of a windows-ce workaround. discussed with jsing
2026-05-19libcrypto/ui: move ui_string_st to ui_lib.c. It's only used there.tb2-35/+35
2026-05-18x509_addr: do not call memcmp() on NULLtb1-5/+5
If the minimum length is 0, either a->data or b->data could be NULL, so do not call memcmp() and let the length comparison decide. Doing it this way preserves the RFC 3779, section 2.2.3.3 semantics and avoids the UB. A valid IPAddressFamily has an addressFamily element of 2 or 3 octets: 2 octets for the AFI and 1 octet for the optional SAFI. The check as it is written compares the AFIs and, if they're equal, lets absent SAFI be smaller than any other SAFI. So IPv4 (0x0001) sorts before IPv4 unicast (0x000101) and that in turn sorts before IPv6 (0x0002). Found by beck while breaking OpenSSL ok kenjiro
2026-05-16Introduce and use dtls12_handshake_msg.jsing6-77/+363
Add struct dtls12_handshake_msg and various related functions, which allow for the construction of DTLS handshake messages and associated fragments. Use this on the DTLS write path for sending handshake message fragments. This means that we no longer modify the init buffer, which also fixes a bug where the message callback is called with a corrupted handshake message when multiple fragments have been sent. We also now correctly track fragment offsets when sending a handshake message that results in multiple calls to dtls1_do_write_handshake_message(). This is the first step towards further untangling of the write path in the legacy TLS stack. ok kenjiro@ tb@
2026-05-16x509_prn: zap more than useless commentstb1-8/+1
2026-05-16x509_prn: hoist unknown_ext_print() above its only caller; drop prototypetb1-29/+25
2026-05-16asn1_print_obstring_ctx: cast to const char * rather than char *tb1-2/+2
Another call to BIO_dump_indent() that cast away const for no good reason.
2026-05-16unknown_ext_print: avoid casting away consttb1-2/+2
The BIO_dump_indent() API masterpiece expects a const char pointer as input. Don't cast away const when suppressing pointer sign warnings. Prompted by a report by N. Dossche ok kenjiro
2026-05-16Ensure X509V3_EXT_print() only returns 0 and 1tb1-3/+3
In a rare mistake by schwarze, X509V3_EXT_print() is documented to return 0 and 1. This is also what most internal callers expect. However, if either X509V3_EXT_DUMP_UNKNOWN or X509V3_EXT_PARSE_UNKNOWN is set, the extension has an unknown NID or on failure to deserialize the extension value, the return values of BIO_dump_indent() (which is number of bytes written or -1 on error) and ASN1_parse_dump() (which is 0, 1, or 2 on EOC) are propagated. Follow what OpenSSL did and translate to Boolean returns. Error indicators are rather useless here since most errors are ignored anyway. Most callers do if (!X509V3_EXT_print(...)) but they also pass a zero flag. Reported by N. Dossche ok kenjiro
2026-05-16remove unused ssleay.cnf file; ok tb@jsg1-78/+0
2026-05-16ASN1{,_parse}_dump: document return value 2 on EOCtb1-3/+7
Prompted by a report by N. Dossche ok kenjiro
2026-05-16BIO_dump: Xr BIO_printf rather than BIO_write/fwritetb1-6/+4
Prompted by a report by N. Dossche ok kenjiro
2026-05-14Sync cert.pem with mozilla roots; quite a few CA certificates weresthen1-1146/+1
either removed or distrusted for web so are removed here. ok tb@ Common policies (moz, google, ca/b) are now to distrust roots with key material created before a certain time (currently 2008, this rolls forwards by 2 years each April until 2029 when it moves to '15 years from creation'), and also roots used for TLS are not permitted to be shared with other purposes (Secure Email, Code Signing, or others). This removes all root certificates from the following CA operators: -AffirmTrust - /C=US/O=AffirmTrust/CN=AffirmTrust Commercial - /C=US/O=AffirmTrust/CN=AffirmTrust Networking - /C=US/O=AffirmTrust/CN=AffirmTrust Premium - /C=US/O=AffirmTrust/CN=AffirmTrust Premium ECC -Firmaprofesional SA - /C=ES/O=Firmaprofesional SA/2.5.4.97=VATES-A62634068/CN=FIRMAPROFESIONAL CA ROOT-A WEB -SecureTrust Corporation - /C=US/O=SecureTrust Corporation/CN=Secure Global CA - /C=US/O=SecureTrust Corporation/CN=SecureTrust CA -TeliaSonera - /O=TeliaSonera/CN=TeliaSonera Root CA v1 -Trustwave Holdings, Inc. - /C=US/ST=Illinois/L=Chicago/O=Trustwave Holdings, Inc./CN=Trustwave Global Certification Authority - /C=US/ST=Illinois/L=Chicago/O=Trustwave Holdings, Inc./CN=Trustwave Global ECC P256 Certification Authority - /C=US/ST=Illinois/L=Chicago/O=Trustwave Holdings, Inc./CN=Trustwave Global ECC P384 Certification Authority -certSIGN - /C=RO/O=certSIGN/OU=certSIGN ROOT CA -e-commerce monitoring GmbH - /C=AT/O=e-commerce monitoring GmbH/CN=GLOBALTRUST 2020 ...and some but not all root certificates from these (the ones without - are still remaining): COMODO CA Limited - /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO Certification Authority /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO ECC Certification Authority /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority Dhimyotis - /C=FR/O=Dhimyotis/CN=Certigna /C=FR/O=Dhimyotis/OU=0002 48146308100036/CN=Certigna Root CA DigiCert Inc - /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Assured ID Root CA /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Assured ID Root G2 /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Assured ID Root G3 - /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root CA /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root G2 /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Global Root G3 - /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert Trusted Root G4 Entrust, Inc. - /C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2009 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - G2 - /C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2012 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - EC1 /C=US/O=Entrust, Inc./OU=www.entrust.net/CPS is incorporated by reference/OU=(c) 2006 Entrust, Inc./CN=Entrust Root Certification Authority Google Trust Services LLC /C=US/O=Google Trust Services LLC/CN=GTS Root R1 - /C=US/O=Google Trust Services LLC/CN=GTS Root R2 /C=US/O=Google Trust Services LLC/CN=GTS Root R3 /C=US/O=Google Trust Services LLC/CN=GTS Root R4 QuoVadis Limited /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 1 G3 - /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 2 /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 2 G3 - /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 3 /C=BM/O=QuoVadis Limited/CN=QuoVadis Root CA 3 G3 SwissSign AG - /C=CH/O=SwissSign AG/CN=SwissSign Gold CA - G2 /C=CH/O=SwissSign AG/CN=SwissSign RSA TLS Root CA 2022 - 1 This is based on changes hitting the Mozilla release branch https://raw.githubusercontent.com/mozilla-firefox/firefox/refs/heads/release/security/nss/lib/ckfw/builtins/certdata.txt but the individual commits are easier to see here: https://hg-edge.mozilla.org/projects/nss/log/tip/lib/ckfw/builtins/certdata.txt
2026-05-12Add a guarded .note.GNU-stack section to crypto assembly files.jsing9-9/+45
Add a .note.GNU-stack section to avoid ending up with an executable stack on toolchains that believe we should have an executable stack by default. Reported by ruuda on Github. Discussed with tb@
2026-05-10rsa_padding_test: %i -> %dtb1-3/+3
2026-05-10Slightly adjust BUGS section for X509_addr_add_range()tb1-2/+3
Since x509_addr.c r1.95 X509_addr_add_range() clears the unused bits in the maximum, so this is is only true in some implementations.
2026-05-10openssl s_socket: do not fail accept on reverse DNS lookup failurekenjiro1-9/+2
Found by Frank Denis
2026-05-09openssl crl: make verify failure result in "app" failuretb1-4/+5
Found by Frank Denis
2026-05-09openssl ecparam: make EC_GROUP_check() failure result in "app" failuretb1-3/+4
Found by Frank Denis
2026-05-09openssl s_client: avoid two out of bounds writestb1-2/+4
A NUL termination after an unchecked BIO_read() call in XMSS mode could lead to a write one byte before the start of sbuf or one past its end. Add an error check to avoid the former and read one byte less to avoid the latter. Found by Frank Denis
2026-05-09libssl: record extension lengths in ClientHello hashingtb1-1/+4
The ClientHello hash is intended to ensure that the second CH after an HRR only makes the allowed changes to the TLS extensiosn by recording message type followed by the raw extension data if it must remain unchanged. This makes it possible (in principle) that part of free form extension data is confused with type (and length) information of a subsequent extension. Recording the length after the type prevents such a confusion and fixes the framing of the extensions. Found by Frank Denis ok jsing
2026-05-09ssl_lib: trade two extra empty lines for a missing onetb1-4/+2
2026-05-09PKCS#12: fix erroneous error check in PKCS12_newpass()tb1-3/+3
This is an error I introduced in a refactoring two years ago in r1.20. This means that nothing uses this... From Frank Denis via logan
2026-05-09Use uint32_t instead of SHA_LONG in the SHA-256 code.jsing1-22/+22
This is more readable and we already have a compile time assert that they are the same size. ok tb@
2026-05-09Use W rather than X for the SHA-256 message schedule.jsing1-83/+83
This more closely matches the SHA-256 specification in FIPS 180-4. ok tb@
2026-05-09Use consistent variable names in the sha256 code.jsing1-67/+67
Use 'ctx' rather than 'c' for the SHA256_CTX and use data/len rather than d/n. ok kenjiro@ tb@
2026-05-09Use crypto_add_u32dw_u64() to increment SHA-256 message bit counter.jsing1-9/+3
ok kenjiro@ tb@
2026-05-09Correct argument type for SHA context.jsing1-4/+4
These are SHA_CTX not SHA256_CTX.
2026-05-09Correct argument type in comments.jsing2-4/+4
2026-05-08Add wide version of open_memstream regress.millert3-2/+196
2026-05-08remove bogus ifdefs; ok tb@jsg1-8/+1
2026-05-08x509_purp: fix doc comment for check_ca()tb1-3/+7
This comment has gotten out of sync with reality. The "I don't know..." fallback was removed and a special case for netscape CAs was added. Sync from the manual and add some more details. Pointed out by Maximilian Radoy in https://github.com/libressl/portable/issues/1274 ok kenjiro
2026-05-08asr regress: workaround due to removal of . from the pathtb1-2/+2
Since . is no longer part of the default path, . regress.subr no longer works. Use ${PWD}. With this, the regress appears to mostly work except for what looks like ordering issues and of course it isn't using bsd.regress.mk. I leave the former to the DNS experts and the latter to the regress experts if they're interested.
2026-05-08asr regress: /etc/networks was removed in 2018tb1-2/+1
2026-05-08asr regress: set -Wno-unused-but-set-variables in CFLAGStb1-1/+2
This allows building without modifying some debugging code.
2026-05-08asr regress: extern three variables to fix build with -fcommontb1-4/+4
2026-05-07Use macros for global functions and objects within SHA assembly.jsing9-53/+53
This lets us remove some of the repetitive statements and allows for them to be adjusted for various platforms. ok kenjiro@ tb@
2026-05-07Use defines for symbol offsets in aarch64 assembly.jsing3-7/+12
These also very between platforms. ok kenjiro@ tb@
2026-05-07Use defines for text and rodata section names in SHA assembly.jsing8-21/+31
These vary between platforms. ok kenjiro@ tb@
2026-05-07Use a define based instruction separator in SHA assembly.jsing9-191/+219
Unfortunately, not all assemblers use the same instruction separator. In particular, LLVM on macOS uses %% as an instruction separator, while most other assemblers use a semi-colon. ok kenjiro@ tb@
2026-05-06Get rid of struct dtls1_retransmit_state.jsing2-26/+10
In order to retransmit DTLS messages we potentially need to use the record protection from a previous epoch. However, DTLS currently also saves and restores the session, which is unnecessary - all of the record protection and keys are handled in the TLS record layer. Remove the rather useless dtls1_retransmit_state struct and just keep the epoch - keeping pointers hanging around to sessions is pretty nasty and unnecessary. ok kenjiro@ tb@
2026-05-06Avoid use of uninitialised decode_error variable.jsing1-10/+14
Pull initialisation of decode_error and invalid_key up to tls_key_share_{client,server}_peer_public(), which are the entry points for the key share code. The entry point was previously tls_key_share_peer_public(), however with the introduction of MLKEM this was split into separate client and server functions, without the initialisation being included. Also initialise decode_error and invalid_params on entry to tls_key_share_peer_params(). Code that reaches tls_key_share_client_peer_public_mlkem768x25519() could previously result in code branching based on decode_error, which is uninitialised stack based memory. Thanks to Guido Vranken of Aisle Research for reporting this issue. With and ok tb@
2026-05-05wycheproof: add regress target to ensure proper go formattingtb1-2/+5
2026-05-05openssl: centralize speed benchmark timer handlingkenjiro1-124/+135
The speed benchmark currently arms alarm() from print_message() and pkey_print_message(), making the output helpers also control benchmark lifetime. This hidden coupling makes the code harder to maintain and led to missing alarm cleanup on Windows, as reported in #1245. Move alarm setup and run-state initialization into speed-specific timer helpers so benchmark timing is controlled explicitly at the start and stop points. ok tb joshua
2026-05-04mlkem: also zero the failure_keytb1-1/+2
from logan https://github.com/libressl/openbsd/pull/154