Skip to content

All combinations - #1

Open
feventura wants to merge 932 commits into
upstreamfrom
main
Open

feventura wants to merge 932 commits into
upstreamfrom
main

Conversation

@feventura

@feventura feventura commented Jun 9, 2026 •

Copy link
Copy Markdown
Collaborator

This PR was created to facilitate the identification of the changes made to implement composite signatures and certificates.

This branch contains all 18 combinations:

  • MLDSA44-RSA2048-PSS-SHA256
  • MLDSA44-RSA2048-PKCS15-SHA256
  • MLDSA44-Ed25519-SHA512
  • MLDSA44-ECDSA-P256-SHA256
  • MLDSA65-RSA3072-PSS-SHA512
  • MLDSA65-RSA3072-PKCS15-SHA512
  • MLDSA65-RSA4096-PSS-SHA512
  • MLDSA65-RSA4096-PKCS15-SHA512
  • MLDSA65-ECDSA-P256-SHA512
  • MLDSA65-ECDSA-P384-SHA512
  • MLDSA65-ECDSA-brainpoolP256r1-SHA512
  • MLDSA65-Ed25519-SHA512
  • MLDSA87-ECDSA-P384-SHA512
  • MLDSA87-ECDSA-brainpoolP384r1-SHA512
  • MLDSA87-Ed448-SHAKE256
  • MLDSA87-RSA3072-PSS-SHA512
  • MLDSA87-RSA4096-PSS-SHA512
  • MLDSA87-ECDSA-P521-SHA512

Comment thread providers/implementations/signature/composite_sig.c Outdated
@feventura feventura changed the title Composite Sigs and Cert All combinations Jul 20, 2026
bob-beck and others added 26 commits September 4, 2026 19:35
Re-document that ASN1_STRINGs are not NUL byte terminated, and
have been documented as such for over 20 years.

ASN1_STRING data has never been guaranteed to be NUL byte terminated.
ASN1_STRING_set() added one anyway; its replacements do not, so code
relying on UB, and treating it as a C string is more likely to break.

Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Fri Sep  4 17:35:40 2026
Merged-from: openssl#32233
The write macros in include/openssl/pem.h take const TYPE *x, but
PEM_read_bio_PrivateKey.pod still documented several write functions
without const. Match the public headers.

Fixes: openssl#31169

Assisted-by: Hermes Agent:gpt-5.6-sol
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Merge-date: Fri Sep  4 17:37:17 2026
Merged-from: openssl#32422
Decrypt with a wrong tag for each AEAD and inspect the error reason left
on the queue. Repeat for ciphertext only, AAD only, and ciphertext + AAD.
The tag rejection must fail at EVP_DecryptFinal_ex(), and leave error
PROV_R_BAD_DECRYPT on the queue.

Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Fri Sep  4 17:39:21 2026
Merged-from: openssl#32587
In the DTLS variant of the TLS 1.3 HRR tests a large key share can
split the server's flight across two datagrams, leaving the proxy
with an incomplete message fragment when the client rejects the
ServerHello and its alert arrives first.  The proxy treated any peer
change with pending fragment data as fatal and died, aborting the
whole test recipe.  This made the no-ec run-checker build fail
intermittently, since only the ffdhe key shares are large enough to
force the fragmentation.

A DTLS peer may legitimately abort mid-flight, so discard the stale
fragment data and carry on instead.  TLS keeps the strict behaviour.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Fri Sep  4 17:40:52 2026
Merged-from: openssl#32630
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Sat Sep  5 17:06:55 2026
(Merged from openssl#32644)
DTLSv1_listen() copied the ClientHello record sequence into the
HelloVerifyRequest, but after a valid cookie it advanced the write
sequence by one. If the client retransmitted ClientHello, the following
ServerHello could be sent with the wrong record sequence.

Seed the DTLS write record sequence from the valid-cookie ClientHello
before continuing the handshake. Also make DTLS 1.2 write sequence
increments fail at the 48-bit wire sequence boundary instead of carrying
into the unused high bytes.

Add tests for the ServerHello record sequence and DTLS 1.2 sequence wrap
handling.

Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Merge-date: Mon Sep  7 08:15:23 2026
Merged-from: openssl#32064
Call tls_construct_client_key_exchange() directly for each key exchange
the dispatcher can select, priming the connection with the state the
real state machine would have set up: a minimal session, the negotiated
cipher and the server key material.  The kRSA test decrypts the emitted
premaster secret and checks it against the saved one, kECDHE/kDHE check
the encoded public key and the derived secret, and kPSK checks the
emitted identity plus the PSK stashed for the secret derivation.  Add
deterministic tests for the error branches: a missing server
certificate or ephemeral key, the PSK callback failures, a WPACKET
overflow and a cipher matching no key exchange.  Out-of-memory branches
are exercised with the mfail tests.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Ryan Hooper <ryanh@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 13:26:41 2026
Merged-from: openssl#32299
Add a new test recipe covering the enc app skey handling: an opaque key
imported via -skeymgmt/-skeyopt raw bytes produces the same AES
ciphertext as the equivalent raw -K key and decrypts back, the raw key
and skeyopt options are mutually exclusive, and unknown skeymgmt names
or malformed skeyopt values are rejected.  With module support, the
fake-cipher provider covers a full encrypt/decrypt roundtrip through a
provider-implemented cipher, including defaulting the skeymgmt name to
the cipher name when -skeymgmt is not given.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 13:28:07 2026
Merged-from: openssl#32570
Add a subtest covering -kfile: a passphrase read from a file with a
trailing CRLF encrypts data that decrypts with the same passphrase
given via -k, an empty passphrase file is rejected and so is a file
containing only a newline.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Mon Sep  7 13:29:19 2026
Merged-from: openssl#32574
With -multi, a later certificate failure could return success after an
earlier certificate succeeded because ret retained the earlier result
on reaching err:.

Set ret = 1 at err: so every path reaching it reports failure. Paths
bypassing err: remain unchanged, including the pre-existing
X509_VERIFY_PARAM_new() failure under -checkend, which will be addressed
separately.

Add a regression test using -multi -checkhost with a two-certificate
chain whose second certificate fails.

Fixes openssl#32189

Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Todd Short <todd.short@me.com>
Merge-date: Mon Sep  7 14:01:00 2026
Merged-from: openssl#32190
Add an MFAIL regression test for X509V3_EXT_add_nconf().

Targeting bug : (openssl#32206)
In asn1_gen.c asn1_multi() function variable allocated as
ASN1_TYPE *typ = generate_v3() is not freed if
if (!sk_ASN1_TYPE_push(sk, typ)) branch fails.

The issue was found by the x509v3 fuzzer MFAIL test.

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Merge-date: Mon Sep  7 14:08:11 2026
Merged-from: openssl#32330
Free the partially constructed ASN1_TYPE and return NULL when
ASN1_STRING_type_new() fails. Previously asn1_multi() returned an
incomplete object.

Found by x509v3 mfail regression test.

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Merge-date: Mon Sep  7 14:08:12 2026
Merged-from: openssl#32330
Fix a minor style violation in ssl/statem/statem_srvr.c.

The violation arrived with the DTLS 1.3 series and was never caught
locally, because git rebase does not run the pre-commit hooks over the
commits it replays. CI did not catch it either: the check-style job
enumerates a pull request's changed files with `gh pr view --json
files`, which returns at most 100 entries, and the DTLS 1.3 pull
request changed 186 files -- ssl/statem/statem_srvr.c fell outside the
checked set. The following commit fixes that workflow bug.

Assisted-by: Claude:claude-opus-5
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:09:39 2026
Merged-from: openssl#32516
The check-style job built its file list with `gh pr view --json files`.
That returns only the first 100 entries - gh's GraphQL query asks for
100 and does not follow further pages - so any pull request touching
more than 100 files had the remainder silently skipped, and the job
reported a pass having never examined them.

This was not hypothetical. The DTLS 1.3 pull request changed 186 files,
so 86 were dropped - 41 of them .c/.h files clang-format would have
examined - and the job passed while ssl/statem/statem_srvr.c carried a
real formatting violation.

Use the REST files endpoint with --paginate instead, which follows every
page. Two details worth noting: this endpoint names the field
`filename` rather than the `path` exposed by gh's GraphQL mapping, and
per_page is set only to reduce the request count, since the REST
default of 30 would fetch the same 186 files over seven requests rather
than two.

Checked against that same pull request: the old command yields 100
paths, the new one yields all 186, matching `git diff --name-only`
exactly. Running pre-commit over each list against the unfixed tree
confirms the difference - the 100-file list passes, the full list fails
on ssl/statem/statem_srvr.c.

Assisted-by: Claude:claude-opus-5
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:09:40 2026
Merged-from: openssl#32516
Add a test deriving a key with -binary -out and comparing the raw
bytes against the expected value, also covering -out to a file.
Use diag() instead of print for TAP failure diagnostics.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Mon Sep  7 14:11:18 2026
Merged-from: openssl#32578
Add tests generating a prime in decimal and hex output, verifying the
result is reported prime by feeding it back for primality checking,
checking the -safe option produces p with (p-1)/2 also prime, and
covering the error cases of a missing -bits and a trailing number
argument.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Mon Sep  7 14:12:35 2026
Merged-from: openssl#32580
Reading DSA parameters from a file with -dsaparam and converting them
to X9.42 DH parameters was not covered, nor were the error paths when
the input file key type does not match the -dsaparam expectation.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Mon Sep  7 14:14:08 2026
Merged-from: openssl#32588
Several test recipes duplicate a helper that runs an openssl
application expecting a failure exit status and checks that the
stderr output matches a regular expression.  Add a shared app_fails
function so new recipes do not need to repeat it, together with a
slurp_file function for reading back a captured output file.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:15:49 2026
Merged-from: openssl#32592
Previously a negative or zero numbits argument made genrsa exit
with a failure status without printing any error message.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:15:50 2026
Merged-from: openssl#32592
Cover the bad option failures (unknown cipher, invalid primes,
bits and password arguments) as well as the key generation failure
with an invalid number of primes, verifying the error messages
printed to stderr.  Also cover the -verbose progress output and
check that -quiet suppresses it.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:15:50 2026
Merged-from: openssl#32592
Cover the bad option failures (missing and extra arguments, unknown
cipher and invalid password argument) as well as the failures when
loading a nonexistent, invalid or non-DSA parameters file, verifying
the error messages printed to stderr.  Also extend the -verbose test
to check the reported progress output and cover the -quiet option.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:15:51 2026
Merged-from: openssl#32592
Cover the bad option failures (missing algorithm, extra arguments,
invalid output format, unknown algorithm, key option, cipher and
password arguments) as well as the failures when loading a
nonexistent or invalid parameters file, verifying the error messages
printed to stderr.  Also cover the -verbose progress output and the
-quiet option.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Mon Sep  7 14:15:52 2026
Merged-from: openssl#32592
Write the testec-p256.pem private key in DER form with and without
-no_public and check that the stripped encoding is smaller and matches
a new checked-in reference file.  Also check that the public key is
recomputed from the private scalar when loading such a key, by
comparing -pubout output against the existing ec-conv-unc.der
reference.

Assisted-by: Claude:claude-fable-5
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Mon Sep  7 14:16:44 2026
Merged-from: openssl#32596
The DTLS 1.3 unified header carries only the low 8 or 16 bits of the
record sequence number. Passing the full uint64_t value to
WPACKET_put_bytes_u16() made SSL_write() fail when the counter reached
65536.

Mask only the value encoded on the wire and in the corresponding AEAD
additional data, leaving the full counter intact for the nonce. On
receipt, reconstruct the full value relative to the right edge of the
current epoch's replay window, as recommended by RFC 9147 section 4.2.2.

Add boundary vectors for both wire widths and an end-to-end test across
the 16-bit wrap.

Fixes openssl#32584

Assisted-by: pi:Hy4-preview
Assisted-by: Codex:gpt-5.6-sol
Reviewed-by: Ryan Hooper <ryanh@openssl.foundation>
Reviewed-by: Andrew Dinh <andrewd@openssl.org>
Merge-date: Mon Sep  7 14:20:03 2026
Merged-from: openssl#32601
dtls1_increment_epoch() capped the read/write epoch at UINT16_MAX for
DTLS 1.2, but skipped that check entirely for DTLS 1.3, relying only
on the full 64-bit wrap as a backstop. RFC 9147 Section 8 requires a
much tighter bound for senders: "sending implementations MUST NOT
allow the epoch to exceed 2^48-1", motivated by AES-128's 128-bit key
giving a non-negligible key-reuse probability at anything near 2^64
rekeys. Receivers are held to the looser Section 6.1 ceiling instead,
so this is intentionally a write-side-only, DTLS-1.3-only check.

Add DTLS1_3_MAX_EPOCH (2^48-1) and enforce it in the write branch of
dtls1_increment_epoch() before the increment, mirroring the existing
UINT16_MAX guard's pre-increment style. With both the DTLS 1.2 and
DTLS 1.3 write-side ceilings now always intercepting w_conn_epoch
well below UINT64_MAX, the post-increment wrap-to-zero check on that
path can no longer be reached, so it is removed.

Add test_dtls13_increment_epoch_max() to test/dtls13_internal_test.c,
which negotiates a real DTLS 1.3 connection (SSL_CONNECTION_IS_DTLS13()
depends on the negotiated method and can't be forced directly), then
writes w_conn_epoch to one below the limit and calls the real
increment function at and past the boundary.

Fixes: openssl#32511
Assisted-by: Claude:claude-sonnet-5
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Merge-date: Mon Sep  7 14:28:46 2026
Merged-from: openssl#32617
DTLS 1.3 accepted forged DTLSPlaintext records after traffic keys
were installed. Injected alerts could terminate or desynchronise an
association, while plaintext handshake and ACK records could invoke
WPACKET_cleanup() on an uninitialised WPACKET.

Silently discard DTLSPlaintext in nonzero epochs, as required by RFC
9147, after consuming the complete fragment. Harden tls13_cipher() by
honouring allow_plain_alerts, rejecting non-unified DTLS headers, and
ensuring WPACKET is initialised before cleanup.

Keep validate_record_header unset because invalid DTLS records must be
silently discarded rather than converted into fatal alerts.

Assisted-by: pi:kimi-k3
Reviewed-by: Ryan Hooper <ryanh@openssl.foundation>
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Merge-date: Mon Sep  7 14:41:16 2026
Merged-from: openssl#32622
Viktor Dukhovni and others added 30 commits September 24, 2026 00:46
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
MergeDate: Wed Sep 23 14:46:50 2026
(Merged from openssl#32681)
The following commit openssl@b2f2f7f
exposes a side effect that causes a segfault in sslapitest.

sslapittest is a static, and loads the DASYNC engine as a shared library.
The callstack on failure is:
dasync_destroy()
  ERR_unload_strings()
    CRYPTO_THREAD_write_lock()  ← SIGSEGV

This happens because the cleanup order is such that the err_cleanp() is called first
which frees the lock and sets err_string_lock = NULL
Then it later calls ERR_unload_string() which will crash on the write_lock()

The above commit does a call early to ERR_set_mark() which changes the cleanup order.

Assisted-by: OpenAI Codex:gpt-5.6-sol
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Merge-date: Wed Sep 23 18:37:17 2026
Merged-from: openssl#32943
Callers of CRYPTO_atomic_cmp_exch_ptr() that fail the exchange adopt
the winning pointer delivered through *expect and access the object
it points to: the publish-after-init pattern, where the winner
publishes a built object with the compare-exchange and the loser
adopts it.

With a relaxed failure memory order there is no happens-before edge
from the winner's initialization writes to the loser's subsequent
reads of the object contents — a genuine data race, latent on
weakly-ordered architectures (ARM, POWER), and visible to
ThreadSanitizer for any caller that adopts the published object this
way.

Unlike the report that motivated 8f9f0d2 ("Fix persniketyness in
tsan"), such a report here is a true positive: there, publication
went through locks, so relaxed loads were sufficient; here,
publication goes through the compare-exchange itself, so the failure
path must carry acquire semantics.

The relaxed production memory orders of CRYPTO_atomic_load_ptr() and
CRYPTO_atomic_store_ptr() (the TSAN_LOAD_MEM_ORDER /
TSAN_STORE_MEM_ORDER dance) are untouched; whether they should be
strengthened outside TSan builds is a separate question.

Assisted-by: Pi:moonshotai/kimi-k3
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Tue Sep 22 09:29:50 2026
Merged-from: openssl#32868
Describes an alternative API design using PKCS12_PARSE_CTX opaque context
and public PKCS12_SAFEBAG_get1_skey() for Java keytool PKCS#12 files.

Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:20 2026
(Merged from openssl#30937)
This is the base AES OID used by Java keytool when storing generic
AES symmetric keys in PKCS#12 files.

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:21 2026
(Merged from openssl#30937)
Introduce PKCS12_PARSE_CTX opaque context for PKCS12_parse_ex(), replacing
the growing parameter list pattern. Add PKCS12_decrypt_secretbag() for
decrypting secret bags and PKCS12_SAFEBAG_get1_skey() for converting
decrypted PKCS8 data to EVP_SKEY, following the existing private key
pattern (PKCS12_decrypt_skey_ex + EVP_PKCS82PKEY_ex).

Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:22 2026
(Merged from openssl#30937)
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:24 2026
(Merged from openssl#30937)
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:25 2026
(Merged from openssl#30937)
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>

Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:26 2026
(Merged from openssl#30937)
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Simo Sorce <simo@redhat.com>
MergeDate: Thu Sep 24 07:34:27 2026
(Merged from openssl#30937)
In the extended cross-compile workflows for aarch64 and RISC-V, the
"make all tests" and "make some tests" steps now also run when the
marker appears in the pull request body, and the "make evp tests" step
is skipped in that case.  A pull request matching only on its title
still gets the EVP tier, and legs setting `tests: none` stay
build-only.

Assisted-by: Claude:claude-opus-5
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 07:44:32 2026
Merged-from: openssl#32879
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Merge-date: Thu Sep 24 08:51:59 2026
Merged-from: openssl#32972
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Merge-date: Thu Sep 24 08:52:43 2026
Merged-from: openssl#32970
see openssl#29934

Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Paul Yang <paulyang.inf@gmail.com>
Merge-date: Thu Sep 24 08:58:11 2026
Merged-from: openssl#32862
…enameMacros

These were omitted in 232b328 "Add a WebKit clang-format file"
for some reason, and clang-format is apparently unable to figure out
that a macro resolves in a type name, in all its geniousness, leading
to incorrect and misleading formating of the code that uses these type
macros.  Rescind that omission.

Fixes: 232b328 "Add a WebKit clang-format file"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:01:04 2026
Merged-from: openssl#32304
For some reason, these macros haven't been included in clang-format
config in commit 232b328 "Add a WebKit clang-format file", which
led to incorrect (and at times misleading) formatting of the code
that uses them.  Rescind that omission.

Fixes: 232b328 "Add a WebKit clang-format file"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:01:05 2026
Merged-from: openssl#32304
Re-formatting was done using the following command:

    for i in `git grep -l 'OSSL_LIST\|PRIORITY_QUEUE_OF\|SPARSE_ARRAY_OF' \
                       -- '*.c' '*.h' '*.c.in' '*.h.in'`; do \
        clang-format-21 --style=file:.clang-format -i "$i"; \
    done

Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:01:06 2026
Merged-from: openssl#32304
Fixes: openssl#31672
Signed-off-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Merge-date: Thu Sep 24 09:13:10 2026
Merged-from: openssl#32899
The RCU code calls CRYPTO_atomic_load_int() and CRYPTO_atomic_add64()
for their side effect and ignores the return value, in
get_hold_current_qp() and in ossl_rcu_read_unlock(). Those functions
leave the output untouched when they fail, so qp_idx, tmp and ret are
only guaranteed to be written when the call succeeds.

In practice they cannot fail here, because ossl_rcu_lock_new() does not
return a lock unless rw_lock was created. The compiler cannot see that,
though, and reports the reads as potentially uninitialised as soon as
the atomics gain a visible early return - which the next commit adds.

Give the three variables initialisers. Zero is a safe choice in each
case: qp_idx indexes qp_group, which always holds at least two entries,
so both the subscript and the returned pointer stay in bounds; tmp then
matches qp_idx, so the equality test succeeds and the loop exits on its
first pass instead of running again on an indeterminate index; and ret
satisfies the assertion that follows it.

Assisted-by: Claude:claude-opus-5
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:18:02 2026
Merged-from: openssl#32633
crypto/threads_win.c provides two implementations of the CRYPTO_atomic_*
family: a lock-free one built on the Interlocked* intrinsics, and a
fallback that takes a CRYPTO_RWLOCK. The fallback is compiled when
OSSL_USE_INTERLOCKEDOR64 is not defined, which per
include/internal/threads_common.h means MSVC 2010 and earlier on x86, or
a MinGW build that is not __MINGW64__ - that is, 32-bit MinGW. The
comment on the rw_lock field in this file names those same two cases.

Eight functions in that fallback path assert that the caller supplied a
lock. That assumption does not hold: OPENSSL_init_crypto() in
crypto/init.c calls

    CRYPTO_atomic_load(&optsdone, &tmp, NULL)

deliberately, and the comment above the call explains why. It is an
optimisation that runs before optsdone_lock has been created, so there
is no lock to pass, and it is documented as expected to fail on
platforms without lockless atomic loads, with the failure ignored.

Because OPENSSL_init_crypto() runs on essentially the first use of the
library in any process, the assertion fires immediately on the affected
targets and every binary aborts before doing any work:

    $ openssl version
    crypto/threads_win.c:694: OpenSSL internal error: \
        assertion failed: lock != NULL

The equivalent function in crypto/threads_pthread.c returns 0 for a NULL
lock rather than asserting, which is what the caller in init.c expects,
so this was a difference between the two backends rather than an
invariant of the API.

Return 0 for a NULL lock in all eight functions, matching the pthread
backend. Behaviour when a lock is supplied is unchanged.

This restores the check that commit 1e1ea71 replaced with an
assertion. That commit also relied on the assertion to suppress three
-Wmaybe-uninitialized reports in the RCU code; the preceding commit
addresses those directly, so a --strict-warnings build stays clean.

Assisted-by: Claude:claude-opus-5
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:18:03 2026
Merged-from: openssl#32633
Because that is known to cause problems when a different
libcrypto version is used in the calling application.

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Merge-date: Thu Sep 24 11:11:30 2026
Merged-from: openssl#32896
Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Kurt Roeckx <kurt@roeckx.be>
Merge-date: Thu Sep 24 13:42:08 2026
Merged-from: openssl#32895
Cover the bad option failures (unknown option, invalid input and
output formats, unparseable bit sizes and extra arguments) as well
as the failure when loading an invalid parameters file, verifying
the error messages printed to stderr with the shared app_fails
helper.

Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Ryan Hooper <ryanh@openssl.foundation>
Merge-date: Thu Sep 24 14:35:00 2026
Merged-from: openssl#32589
When decoding a datagram in qrx_process_pkt, we reserve some space in
the rxe and copy the token out of the packet to the rxe header.
However, if we do a second decode in this function (which is possible),
we reset that pointer to point into the datagram buffer.  While this is
generally not catastrophic as there is no non-debug code that references
this pointer after the URXE is freed, its an issue waiting to happen, so
if we do a second decode, restore the token pointer again to point to
our reserved space.

Fixes openssl/srt#298

Reviewed-by: Saša Nedvědický <sashan@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Fri Sep 25 10:58:42 2026
Merged-from: openssl#32933
Commit 3a69b19 changed b64_write from chunked ctx->buf output
to a dynamic encoded_buf. The new buffer was scratch-only, so
retryable downstream failures or positive short writes could drop
encoded output while still reporting the input bytes as consumed.

Track encoded_buf as pending output with offset and length, include
it in BIO_wpending, and write any pending output before accepting
more input. Add tests for retry via -1, retry via 0, positive short
writes, and short writes followed by retry, with and without
BIO_FLAGS_BASE64_NO_NL, across both aligned input and final-tail
input.

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
Merge-date: Fri Sep 25 11:02:43 2026
Merged-from: openssl#31000
The signing-only option validation runs before load_key(), so
privkey is always NULL when determining newout. Consequently, -key
or -signkey alone does not identify re-signing an input certificate
or signing an -x509toreq output. Signing options are rejected, and
the default extensions section is not loaded.

Check privkeyfile at this stage, which records that the option was
supplied. Keep the later privkey check unchanged because the key has
been loaded by then. Add tests for the validation guard, re-signing
options, and certificate and request extensions.

Fixes openssl#32150

Assisted-by: pi:kimi-k3
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Merge-date: Fri Sep 25 11:07:32 2026
Merged-from: openssl#32151
Signed-off-by: Norbert Pocs <norbertp@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Fri Sep 25 11:33:23 2026
Merged-from: openssl#32990
Check X509_NAME_add_entry_by_txt() result (wrapped in X509_NAME_ADD()
macro), as it may fail.

Reported by Coverity as unchecked return value, CID 1701601, 1701602,
and 170604.

Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701601
Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701602
Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701604
Complements: 4dde554 "chunk 5 of CMP contribution to OpenSSL"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Merge-date: Fri Sep 25 11:43:52 2026
Merged-from: openssl#32901
This test is explicitly written to fail. Suppress.

Signed-off-by: Norbert Pocs <norbertp@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Merge-date: Fri Sep 25 13:37:15 2026
Merged-from: openssl#32992
Signed-off-by: feventura <felipe.ventura@entrust.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.