Commit message (Collapse) | Author | Files | Lines | ||
---|---|---|---|---|---|
2022-06-08 | KNF, mostly whitespace - no binary change on amd64 | tb | 1 | -22/+19 | |
2022-06-07 | Fix format strings: change %i, %li, %lli to %d, %ld, %lld and switch to | tb | 1 | -18/+18 | |
%zu for master_key_length, session_id_length and sid_ctx_length, which are now size_t. | |||||
2022-06-07 | Change the loop index from an unsigned int to size_t now that all | tb | 1 | -2/+2 | |
upper bounds are known to be size_t. ok jsing | |||||
2022-06-07 | Simplify another CBS_write_bytes() call in d2i_SSL_SESSION() | tb | 1 | -5/+2 | |
ok jsing | |||||
2022-06-07 | Switch sid_ctx_length in SSL, SSL_CTX and SSL_SESSION to a size_t | tb | 1 | -4/+4 | |
ok jsing | |||||
2022-06-07 | Use CBS_write_bytes() instead of manual unpacking of a CBS and assigning | tb | 1 | -3/+5 | |
length and using memcpy(). This also provides a missing overflow check (which is done by the only caller, however). ok jsing | |||||
2022-06-07 | Simplify various CBS_write_bytes() calls | tb | 3 | -13/+7 | |
Now that session_id_length is a size_t, we can pass it directly to CBS_write_bytes() instead of using a temporary variable. ok jsing | |||||
2022-06-07 | Switch SSL_SESSION's session_id_length to a size_t | tb | 1 | -2/+2 | |
ok jsing | |||||
2022-06-07 | Add missing error check call in ssl3_get_new_session_ticket() | tb | 1 | -4/+9 | |
EVP_Digest() can fail, so handle failure appropriately and prepare switch of session_id_length to a size_t. ok jsing | |||||
2022-06-07 | Another small readability tweak: compare explicitly against 0 and NULL, | tb | 1 | -4/+3 | |
respectively ok jsing | |||||
2022-06-07 | Tweak readability of a test: compare tmp explicitly against 0 and drop | tb | 1 | -2/+2 | |
redundant parentheses. ok jsing | |||||
2022-06-07 | Add a cast to SSL_SESSION_get_id() to indicate that session_id_length | tb | 1 | -2/+2 | |
is deliberately reduced to an unsigned int. Since the session_id is at most 32 bytes, this is not a concern. ok jsing | |||||
2022-06-07 | fix indent | tb | 1 | -2/+2 | |
2022-06-07 | Unindent and simplify remove_session_lock() | tb | 1 | -21/+22 | |
ok jsing (who informs me he had the same diff in his jungle) | |||||
2022-06-07 | Drop an unnecessary cast | tb | 1 | -2/+2 | |
ok jsing | |||||
2022-06-07 | Simplify CBS_write_bytes() invocation | tb | 1 | -5/+2 | |
Now that master_key_length is a size_t, we no longer have to fiddle with data_len. We can rather pass a pointer to it to CBS_write_bytes(). ok jsing | |||||
2022-06-07 | The master_key_length can no longer be < 0 | tb | 1 | -2/+2 | |
ok jsing | |||||
2022-06-07 | Switch the SSL_SESSION's master_key_length to a size_t | tb | 1 | -2/+2 | |
ok jsing | |||||
2022-06-07 | Add error checking to tls_session_secret_cb() calls | tb | 2 | -32/+49 | |
Failure of this undocumented callback was previously silently ignored. Follow OpenSSL's behavior and throw an internal error (for lack of a better choice) if the callback failed or if it set the master_key_length to a negative number. Unindent the success path and clean up some strange idioms. ok jsing | |||||
2022-06-06 | Use SSL3_CK_VALUE_MASK instead of hardcoded 0xffff and remove some | tb | 2 | -12/+6 | |
SSLv2 remnants. ok jsing | |||||
2022-06-06 | Tweak comment describing the SSL_SESSION ASN.1 | tb | 1 | -4/+5 | |
ok jsing | |||||
2022-06-06 | Minor style cleanup in ssl_txt.c | tb | 1 | -23/+41 | |
Wrap long lines and fix a bug where the wrong struct member was checked for NULL. ok jsing | |||||
2022-06-06 | Fix comment + spacing. | tb | 1 | -2/+2 | |
Apparently 60 * 5 + 4 seconds is 5 minutes. Presumably this is the case with sufficiently potent crack, which would explain a few things in here. | |||||
2022-06-06 | Remove incorrect and ungrammattical comment | tb | 1 | -3/+2 | |
The fallback to SHA-1 if SHA-256 is disabled fell victim to tedu many moons ago when this file was still called s3_clnt.c and had no RCS ID. | |||||
2022-06-06 | Fix spaces before tabs | tb | 1 | -12/+12 | |
2022-06-06 | Minor tweaks to psk modes regress | tb | 1 | -3/+3 | |
2022-06-05 | move the calls to psk kex modes tests down to match order in ssl_tlsext.c | tb | 1 | -4/+4 | |
2022-06-05 | Add regress coverage for PSK kex modes tlsext handlers. | tb | 1 | -2/+210 | |
2022-06-04 | The parse stubs need to skip over the extension data. | tb | 1 | -3/+3 | |
Found by anton with tlsfuzzer ok anton | |||||
2022-06-04 | Tweak a comment using review feedback from jsing | tb | 1 | -4/+4 | |
2022-06-03 | Add stubbed out handlers for the pre_shared_key extension | tb | 2 | -2/+65 | |
ok jsing | |||||
2022-06-03 | Implement handlers for the psk_key_exchange_modes extensions. | tb | 2 | -3/+96 | |
ok jsing | |||||
2022-06-03 | Add a use_psk_dhe_ke flag to the TLSv1.3 handshake struct | tb | 1 | -1/+4 | |
This will be used to indicate client side support for DHE key establishment. ok jsing | |||||
2022-06-03 | Ensure that a client who sent a PSK extension has also sent a PSK | tb | 1 | -4/+9 | |
key exchange mode extension, as required by RFC 8446, 4.2.9. ok jsing | |||||
2022-06-03 | Provide #defines for the two currently registered PskKeyExchangeModes. | tb | 1 | -1/+12 | |
ok jsing | |||||
2022-06-02 | Use consistent spacing around assignments | tb | 1 | -4/+4 | |
2022-06-02 | Only constraints and verify need static linking in here. | tb | 2 | -5/+9 | |
2022-05-28 | *** empty log message *** | mbuhl | 4 | -11/+11 | |
2022-05-25 | Remove an unnecessary XXX comment. The suggested check is part of | tb | 1 | -5/+1 | |
extract_min_max(). | |||||
2022-05-24 | Clean up ASN1_item_sign_ctx() a little | tb | 1 | -25/+38 | |
Instead of inl, outl, and outll, use in_len, out_len, and buf_out_len. Use the appropriate types for them. Check return values properly, check for overflow. Remove some unnecessary casts and add some for readability. Use asn1_abs_set_unused_bits() instead of inlining it. This removes the last direct consumer of ASN1_STRING_FLAG_BITS_LEFT outside of asn1/a_bitstr.c. The flag is still mentioned in x509/x509_addr.c but that will hopefully go away soon. tweaks/ok jsing | |||||
2022-05-24 | Simplify ec_asn1_group2curve() | tb | 1 | -18/+21 | |
Don't try to reuse curve->seed to avoid an allocation. Free it unconditionally and copy over the group->seed if it's available. Use asn1_abs_set_unused_bits() instead of inlining it. ok jsing | |||||
2022-05-24 | Straightforward conversion of ecdh_cms_encrypt() to | tb | 1 | -3/+3 | |
asn1_abs_set_unused_bits() ok jsing | |||||
2022-05-24 | Rewrite X509_PUBKEY_set0_param() to use asn1_abs_set_unused_bits() | tb | 1 | -10/+8 | |
This streamlines the logic and uses ASN1_STRING_set0() and asn1_abs_set_unused_bits() instead of inlining them. ok jsing | |||||
2022-05-24 | Use asn1_abs_set_unused_bits() in asn1_str2type() | tb | 1 | -5/+6 | |
ok jsing | |||||
2022-05-24 | Recent changes to truncate(2) swapped the ordering of some validations | anton | 1 | -2/+2 | |
causing EACCESS as opposed of ESDIR to be returned while trying to truncate a directory as a user lacking write permissions to the same directory. As this behavior is reasonable, change the truncate directory from /etc/ to /tmp which makes the test pass both as root and non-root. | |||||
2022-05-21 | Remove some unhelpful comments and spell NULL correctly. | jsing | 1 | -10/+4 | |
2022-05-21 | Factor out ASN1_ITYPE_EXTERN handling. | jsing | 1 | -15/+32 | |
Factor out the ef->asn1_ex_d2i() callback handling - this allows us to pull out all of the related variables into a self-contained function. ok tb@ | |||||
2022-05-21 | Use 'at' for ASN1_TEMPLATE variable names rather than 'tt'. | jsing | 1 | -52/+58 | |
Also use array indexes for it->templates, rather than trying to be extra clever in for loops (suggested by tb@ during a review). No functional change. ok tb@ | |||||
2022-05-21 | Remove _ex_ from all of the internal function names. | jsing | 1 | -35/+35 | |
It no longer makes sense to have "extended" versions of functions internally. No functional change. ok tb@ | |||||
2022-05-21 | system(3) should ignore SIGINT and SIGQUIT until the shell exits. | millert | 1 | -4/+17 | |
This got broken when system.c was converted from signal(3) to sigaction(2). Also add SIGINT and SIGQUIT to the set of blocked signals and unblock them in the parent after the signal handlers are installed. Based on a diff from Leon Fischer. OK deraadt@ |