summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto (follow)
Commit message (Collapse)AuthorAgeFilesLines
...
* Use of OPENSSL_SYS_xxx defines in public header files considered harmful.miod2014-04-174-28/+1
|
* Bob O.D.'ed on the o_dir code so high he forgot to rm the `test' aftermiod2014-04-171-66/+0
| | | | rewriting the code.
* sprintf: bad.miod2014-04-171-1/+1
| | | | | | snprintf: good. snprintf with a correct size: better! (harmless in this case)
* Remove utils that we don't useafresh12014-04-173-165/+0
| | | | | | | opensslwrap.sh and shlib_wrap.sh are used by tests that are getting replaced, x86asm.sh is obsoleted by our Makefile machinery ok miod
* Remove unused ssl utilsafresh12014-04-1730-5719/+0
| | | | | | This code is the reason perl has a name as a write only language. ok deraadt miod
* Remove oh-so-important-from-a-security-pov OpenSSL_rtdsc() function.miod2014-04-1712-251/+2
|
* fix some more leaks, mostly suggestions from miodjsg2014-04-176-2/+14
| | | | ok miod@
* Remove the benchmark part of the selftest. It uses the undocumentedmiod2014-04-171-43/+0
| | | | | | | OPENSSL_rdtsc() routine to get a high-precision timestamp, and (although this is the only user of this routine in libcrypto) forces every platform willing to provide fast assembly versions of some routines, to also provide OPENSSL_rdtsc().
* Ok, there was a need for OPENSSL_cleanse() instead of bzero() to preventmiod2014-04-1710-373/+2
| | | | | | | | | | | supposedly smart compilers from optimizing memory cleanups away. Understood. Ok, in case of an hypothetically super smart compiler, OPENSSL_cleanse() had to be convoluted enough for the compiler not to recognize that this was actually bzero() in disguise. Understood. But then why there had been optimized assembler versions of OPENSSL_cleanse() is beyond me. Did someone not trust the C obfuscation?
* Move the machine-specific parts of the libcrypto Makefile to per-arch makefilemiod2014-04-175-104/+242
| | | | | | fragments, to ease maintainance, and see through the fog of bugs. "looks good" deraadt@
* some KNF cleanup following the scriptderaadt2014-04-1722-169/+166
|
* fix some of the leaksjsg2014-04-174-7/+23
| | | | ok miod@ looks good deraadt@
* remove OPENSSL_realloc_clean usage here - replace with intrinsics to makebeck2014-04-171-4/+7
| | | | | it obvious what should happen. ok tedu@
* Fully kill FIPS API. Forcible certification conflicts with the goals of atedu2014-04-173-80/+2
| | | | | | free software project. ok beck deraadt Ports calling FIPS_mode_set(1): mongodb
* Initial KNF.jsing2014-04-174-508/+505
|
* I've replaced everything in this file. ISC liscense it with my copyrightbeck2014-04-171-54/+13
|
* KNF.jsing2014-04-171-3/+3
|
* Initial KNF.jsing2014-04-173-139/+122
|
* simply wrap around intrinsics, and knf cleanup.beck2014-04-171-57/+54
| | | | ok miod@ deraadt@
* Change library to use intrinsic memory allocation functions instead ofbeck2014-04-17200-1004/+1004
| | | | | | | | OPENSSL_foo wrappers. This changes: OPENSSL_malloc->malloc OPENSSL_free->free OPENSSL_relloc->realloc OPENSSL_freeFunc->free
* Revert unintended whitespace changes.jsing2014-04-172-6/+6
|
* OPENSSL_gmtime() is not a gmtime() wrapper. It is a gmtime_r().deraadt2014-04-171-18/+4
| | | | | Always trying to confuse people... ok guenther
* OPENSSL_DECLARE_EXIT serves no purpose.deraadt2014-04-179-9/+0
|
* 1. RAND_seed is now DEPRECATEDderaadt2014-04-172-2/+0
| | | | | | | | | | 2. Even passing a digest in as entropy is sloppy. But apparently the OpenSSL guys could find no objects of lesser value to pass to the pluggable random subsystem, and had to resort to private keys and digests. Classy. ok djm
* RAND_seed now does nothing, so skip the operationderaadt2014-04-171-6/+0
|
* Do not feed RSA private key information to the random subsystem asderaadt2014-04-173-11/+0
| | | | | | | | entropy. It might be fed to a pluggable random subsystem.... What were they thinking?! ok guenther
* remove duplicated tests in if statementsjsg2014-04-171-4/+4
| | | | ok krw@ sthen@ deraadt@
* unistd.h is always in the same place; no need to #include the result ofderaadt2014-04-1712-22/+11
| | | | a maze of conditional #define's
* OpenSSL PR#3309: when looking for an extension, set the last found positionsthen2014-04-171-3/+3
| | | | | | to -1 to properly search all extensions. ok tedu@ From http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=300b9f0b70
* move enginetest to regress as was done with the other testsjsg2014-04-171-283/+0
|
* call the correct decrypt function in aes_cbc_cipher()jsg2014-04-171-1/+1
| | | | | | | | | | | | | | | | From: commit e9c80e04c1a3b5a0de8e666155ab4ecb2697a77d Author: Andy Polyakov <appro@openssl.org> Date: Wed Dec 18 21:42:46 2013 +0100 evp/e_[aes|camellia].c: fix typo in CBC subroutine. It worked because it was never called. Our e_camellia.c does not have this problem. ok miod@ deraadt@
* tag some functions with bounded. idea and ok djmtedu2014-04-171-3/+6
|
* Clean up dangerous strncpy use. This included a use where the resultingbeck2014-04-168-27/+17
| | | | | | | string was potentially not nul terminated and a place where malloc return was unchecked. while we're at it remove dummytest.c ok miod@
* - Why do we hide from the OpenSSL police, dad?miod2014-04-166-114/+23
| | | | | | | | - Because they're not like us, son. They use macros to wrap stdio routines, for an undocumented (OPENSSL_USE_APPLINK) use case, which only serves to obfuscate the code. ok tedu@
* > As I walk through the valley of the shadow of deathtedu2014-04-1610-606/+4
| | | | | | | | | > I take a look at my life and realize there's nothin' left > Cause I've been blasting and laughing so long, > That even my mama thinks that my mind is gone Remove even more unspeakable evil being perpetuated in the name of VMS. (and lesser evils done in the name of others.) ok miod
* No need to define ANSI_SOURCE and NO_ERR. TERMIOS kept until ui/ui_openssl.cmiod2014-04-161-2/+2
| | | | gets a second trim.
* No need to build with -DOPENSSL_NO_CAPIENG and -DOPENSSL_NO_HW_xxx for allmiod2014-04-161-10/+1
| | | | now removed engines.
* delete a few leftoverstedu2014-04-161-5/+1
|
* fix a few bugs observed on http://www.viva64.com/en/b/0250/tedu2014-04-162-2/+2
| | | | ok krw miod
* whack the ifdef pinata:tedu2014-04-161-260/+5
| | | | | | | | | | | | | | | | | | OPENSSL_SYSNAME_VXWORKS OPENSSL_SYS_VMS OPENSSL_SYS_MSDOS OPENSSL_UNISTD OPENSSL_SYS_WIN16 WIN_CONSOLE_BUG OPENSSL_SYS_WINCE SGTTY OPENSSL_SYS_MACINTOSH_CLASSIC MAC_OS_GUSI_SOURCE OPENSSL_SYS_NETWARE OPENSSL_SYS_SUNOS __DJGPP__ OPENSSL_SYS_BEOS OPENSSL_SYS_WIN32
* Zero-pad usec format to handle values less than 100,000 correctlyguenther2014-04-161-1/+1
| | | | ok matthew@ tedu@
* Mandatory Surgeon Guenther's Warning: This code could not possibly betedu2014-04-161-24/+24
| | | | | | | correct because it doesn't zerofill the front of usecs, but that's the way I found it. a more thorough emulation of the old code, but with fewer whacky snprintf pointer arithmetic antics. ok beck guenther
* revert. the full horror has only now revealed itself.tedu2014-04-161-26/+21
|
* replace some bio_snprintf crazy with regular snprintf.tedu2014-04-161-21/+26
| | | | | beck had a diff to convert to strftime, but it's easier to verify this is functionally the same. ok beck.
* More KNF.jsing2014-04-1610-104/+109
|
* Make this byzantine horror a shell of it's former self by stubbing thebeck2014-04-161-660/+17
| | | | | | | functions. The ability to set the debug mem functions died with mem.c, but some of the rest of this is still exposed API so we can't delete it.. yet... ok tedu@
* Some software expects RAND_status() to return 1 for success, so alwaysreyk2014-04-161-2/+10
| | | | | | | return 1 in the arc4random backend because there is no possible error condition. Unbreaks lynx, git and friends. ok miod@ dcoppa@
* Clean up non-fatal error handling - we know which error numbers we havejsing2014-04-163-105/+0
| | | | | | defined. ok miod@ beck@
* unbreak install; /usr/share/man/man3/EVP_PKEY_print_private.3 should link tosthen2014-04-161-2/+2
| | | | /usr/share/man/man3/EVP_PKEY_print_public.3 not itself, from deraadt
* Sync the list of man pages for libcrypto, explicity rename conflictingmpi2014-04-1610-56/+1576
| | | | | | | pages instead of doing it in the Makefiles and move a libssl page where it belongs. ok miod@