Conversation
feventura
commented
Jun 12, 2026
Re-document that ASN1_STRINGs are not NUL byte terminated, and have been documented as such for over 20 years. ASN1_STRING data has never been guaranteed to be NUL byte terminated. ASN1_STRING_set() added one anyway; its replacements do not, so code relying on UB, and treating it as a C string is more likely to break. Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Fri Sep 4 17:35:40 2026 Merged-from: openssl#32233
The write macros in include/openssl/pem.h take const TYPE *x, but PEM_read_bio_PrivateKey.pod still documented several write functions without const. Match the public headers. Fixes: openssl#31169 Assisted-by: Hermes Agent:gpt-5.6-sol Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com> Merge-date: Fri Sep 4 17:37:17 2026 Merged-from: openssl#32422
Decrypt with a wrong tag for each AEAD and inspect the error reason left on the queue. Repeat for ciphertext only, AAD only, and ciphertext + AAD. The tag rejection must fail at EVP_DecryptFinal_ex(), and leave error PROV_R_BAD_DECRYPT on the queue. Assisted-by: Claude:claude-opus-4-8 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Fri Sep 4 17:39:21 2026 Merged-from: openssl#32587
In the DTLS variant of the TLS 1.3 HRR tests a large key share can split the server's flight across two datagrams, leaving the proxy with an incomplete message fragment when the client rejects the ServerHello and its alert arrives first. The proxy treated any peer change with pending fragment data as fatal and died, aborting the whole test recipe. This made the no-ec run-checker build fail intermittently, since only the ffdhe key shares are large enough to force the fragmentation. A DTLS peer may legitimately abort mid-flight, so discard the stale fragment data and carry on instead. TLS keeps the strict behaviour. Assisted-by: Claude:claude-fable-5 Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Fri Sep 4 17:40:52 2026 Merged-from: openssl#32630
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Sat Sep 5 17:06:55 2026 (Merged from openssl#32644)
DTLSv1_listen() copied the ClientHello record sequence into the HelloVerifyRequest, but after a valid cookie it advanced the write sequence by one. If the client retransmitted ClientHello, the following ServerHello could be sent with the wrong record sequence. Seed the DTLS write record sequence from the valid-cookie ClientHello before continuing the handshake. Also make DTLS 1.2 write sequence increments fail at the 48-bit wire sequence boundary instead of carrying into the unused high bytes. Add tests for the ServerHello record sequence and DTLS 1.2 sequence wrap handling. Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Merge-date: Mon Sep 7 08:15:23 2026 Merged-from: openssl#32064
Call tls_construct_client_key_exchange() directly for each key exchange the dispatcher can select, priming the connection with the state the real state machine would have set up: a minimal session, the negotiated cipher and the server key material. The kRSA test decrypts the emitted premaster secret and checks it against the saved one, kECDHE/kDHE check the encoded public key and the derived secret, and kPSK checks the emitted identity plus the PSK stashed for the secret derivation. Add deterministic tests for the error branches: a missing server certificate or ephemeral key, the PSK callback failures, a WPACKET overflow and a cipher matching no key exchange. Out-of-memory branches are exercised with the mfail tests. Assisted-by: Claude:claude-fable-5 Reviewed-by: Ryan Hooper <ryanh@openssl.foundation> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 13:26:41 2026 Merged-from: openssl#32299
Add a new test recipe covering the enc app skey handling: an opaque key imported via -skeymgmt/-skeyopt raw bytes produces the same AES ciphertext as the equivalent raw -K key and decrypts back, the raw key and skeyopt options are mutually exclusive, and unknown skeymgmt names or malformed skeyopt values are rejected. With module support, the fake-cipher provider covers a full encrypt/decrypt roundtrip through a provider-implemented cipher, including defaulting the skeymgmt name to the cipher name when -skeymgmt is not given. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 13:28:07 2026 Merged-from: openssl#32570
Add a subtest covering -kfile: a passphrase read from a file with a trailing CRLF encrypts data that decrypts with the same passphrase given via -k, an empty passphrase file is rejected and so is a file containing only a newline. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Paul Dale <paul.dale@oracle.com> Merge-date: Mon Sep 7 13:29:19 2026 Merged-from: openssl#32574
With -multi, a later certificate failure could return success after an earlier certificate succeeded because ret retained the earlier result on reaching err:. Set ret = 1 at err: so every path reaching it reports failure. Paths bypassing err: remain unchanged, including the pre-existing X509_VERIFY_PARAM_new() failure under -checkend, which will be addressed separately. Add a regression test using -multi -checkhost with a two-certificate chain whose second certificate fails. Fixes openssl#32189 Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Todd Short <todd.short@me.com> Merge-date: Mon Sep 7 14:01:00 2026 Merged-from: openssl#32190
Add an MFAIL regression test for X509V3_EXT_add_nconf(). Targeting bug : (openssl#32206) In asn1_gen.c asn1_multi() function variable allocated as ASN1_TYPE *typ = generate_v3() is not freed if if (!sk_ASN1_TYPE_push(sk, typ)) branch fails. The issue was found by the x509v3 fuzzer MFAIL test. Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Merge-date: Mon Sep 7 14:08:11 2026 Merged-from: openssl#32330
Free the partially constructed ASN1_TYPE and return NULL when ASN1_STRING_type_new() fails. Previously asn1_multi() returned an incomplete object. Found by x509v3 mfail regression test. Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Merge-date: Mon Sep 7 14:08:12 2026 Merged-from: openssl#32330
Fix a minor style violation in ssl/statem/statem_srvr.c. The violation arrived with the DTLS 1.3 series and was never caught locally, because git rebase does not run the pre-commit hooks over the commits it replays. CI did not catch it either: the check-style job enumerates a pull request's changed files with `gh pr view --json files`, which returns at most 100 entries, and the DTLS 1.3 pull request changed 186 files -- ssl/statem/statem_srvr.c fell outside the checked set. The following commit fixes that workflow bug. Assisted-by: Claude:claude-opus-5 Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Paul Dale <paul.dale@oracle.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:09:39 2026 Merged-from: openssl#32516
The check-style job built its file list with `gh pr view --json files`. That returns only the first 100 entries - gh's GraphQL query asks for 100 and does not follow further pages - so any pull request touching more than 100 files had the remainder silently skipped, and the job reported a pass having never examined them. This was not hypothetical. The DTLS 1.3 pull request changed 186 files, so 86 were dropped - 41 of them .c/.h files clang-format would have examined - and the job passed while ssl/statem/statem_srvr.c carried a real formatting violation. Use the REST files endpoint with --paginate instead, which follows every page. Two details worth noting: this endpoint names the field `filename` rather than the `path` exposed by gh's GraphQL mapping, and per_page is set only to reduce the request count, since the REST default of 30 would fetch the same 186 files over seven requests rather than two. Checked against that same pull request: the old command yields 100 paths, the new one yields all 186, matching `git diff --name-only` exactly. Running pre-commit over each list against the unfixed tree confirms the difference - the 100-file list passes, the full list fails on ssl/statem/statem_srvr.c. Assisted-by: Claude:claude-opus-5 Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Paul Dale <paul.dale@oracle.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:09:40 2026 Merged-from: openssl#32516
Add a test deriving a key with -binary -out and comparing the raw bytes against the expected value, also covering -out to a file. Use diag() instead of print for TAP failure diagnostics. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Paul Dale <paul.dale@oracle.com> Merge-date: Mon Sep 7 14:11:18 2026 Merged-from: openssl#32578
Add tests generating a prime in decimal and hex output, verifying the result is reported prime by feeding it back for primality checking, checking the -safe option produces p with (p-1)/2 also prime, and covering the error cases of a missing -bits and a trailing number argument. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Paul Dale <paul.dale@oracle.com> Merge-date: Mon Sep 7 14:12:35 2026 Merged-from: openssl#32580
Reading DSA parameters from a file with -dsaparam and converting them to X9.42 DH parameters was not covered, nor were the error paths when the input file key type does not match the -dsaparam expectation. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Paul Dale <paul.dale@oracle.com> Merge-date: Mon Sep 7 14:14:08 2026 Merged-from: openssl#32588
Several test recipes duplicate a helper that runs an openssl application expecting a failure exit status and checks that the stderr output matches a regular expression. Add a shared app_fails function so new recipes do not need to repeat it, together with a slurp_file function for reading back a captured output file. Assisted-by: Claude:claude-fable-5 Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:15:49 2026 Merged-from: openssl#32592
Previously a negative or zero numbits argument made genrsa exit with a failure status without printing any error message. Assisted-by: Claude:claude-fable-5 Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:15:50 2026 Merged-from: openssl#32592
Cover the bad option failures (unknown cipher, invalid primes, bits and password arguments) as well as the key generation failure with an invalid number of primes, verifying the error messages printed to stderr. Also cover the -verbose progress output and check that -quiet suppresses it. Assisted-by: Claude:claude-fable-5 Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:15:50 2026 Merged-from: openssl#32592
Cover the bad option failures (missing and extra arguments, unknown cipher and invalid password argument) as well as the failures when loading a nonexistent, invalid or non-DSA parameters file, verifying the error messages printed to stderr. Also extend the -verbose test to check the reported progress output and cover the -quiet option. Assisted-by: Claude:claude-fable-5 Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:15:51 2026 Merged-from: openssl#32592
Cover the bad option failures (missing algorithm, extra arguments, invalid output format, unknown algorithm, key option, cipher and password arguments) as well as the failures when loading a nonexistent or invalid parameters file, verifying the error messages printed to stderr. Also cover the -verbose progress output and the -quiet option. Assisted-by: Claude:claude-fable-5 Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Sep 7 14:15:52 2026 Merged-from: openssl#32592
Write the testec-p256.pem private key in DER form with and without -no_public and check that the stripped encoding is smaller and matches a new checked-in reference file. Also check that the public key is recomputed from the private scalar when loading such a key, by comparing -pubout output against the existing ec-conv-unc.der reference. Assisted-by: Claude:claude-fable-5 Reviewed-by: Daniel Kubec <kubec@openssl.foundation> Reviewed-by: Paul Dale <paul.dale@oracle.com> Merge-date: Mon Sep 7 14:16:44 2026 Merged-from: openssl#32596
The DTLS 1.3 unified header carries only the low 8 or 16 bits of the record sequence number. Passing the full uint64_t value to WPACKET_put_bytes_u16() made SSL_write() fail when the counter reached 65536. Mask only the value encoded on the wire and in the corresponding AEAD additional data, leaving the full counter intact for the nonce. On receipt, reconstruct the full value relative to the right edge of the current epoch's replay window, as recommended by RFC 9147 section 4.2.2. Add boundary vectors for both wire widths and an end-to-end test across the 16-bit wrap. Fixes openssl#32584 Assisted-by: pi:Hy4-preview Assisted-by: Codex:gpt-5.6-sol Reviewed-by: Ryan Hooper <ryanh@openssl.foundation> Reviewed-by: Andrew Dinh <andrewd@openssl.org> Merge-date: Mon Sep 7 14:20:03 2026 Merged-from: openssl#32601
dtls1_increment_epoch() capped the read/write epoch at UINT16_MAX for DTLS 1.2, but skipped that check entirely for DTLS 1.3, relying only on the full 64-bit wrap as a backstop. RFC 9147 Section 8 requires a much tighter bound for senders: "sending implementations MUST NOT allow the epoch to exceed 2^48-1", motivated by AES-128's 128-bit key giving a non-negligible key-reuse probability at anything near 2^64 rekeys. Receivers are held to the looser Section 6.1 ceiling instead, so this is intentionally a write-side-only, DTLS-1.3-only check. Add DTLS1_3_MAX_EPOCH (2^48-1) and enforce it in the write branch of dtls1_increment_epoch() before the increment, mirroring the existing UINT16_MAX guard's pre-increment style. With both the DTLS 1.2 and DTLS 1.3 write-side ceilings now always intercepting w_conn_epoch well below UINT64_MAX, the post-increment wrap-to-zero check on that path can no longer be reached, so it is removed. Add test_dtls13_increment_epoch_max() to test/dtls13_internal_test.c, which negotiates a real DTLS 1.3 connection (SSL_CONNECTION_IS_DTLS13() depends on the negotiated method and can't be forced directly), then writes w_conn_epoch to one below the limit and calls the real increment function at and past the boundary. Fixes: openssl#32511 Assisted-by: Claude:claude-sonnet-5 Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com> Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Merge-date: Mon Sep 7 14:28:46 2026 Merged-from: openssl#32617
DTLS 1.3 accepted forged DTLSPlaintext records after traffic keys were installed. Injected alerts could terminate or desynchronise an association, while plaintext handshake and ACK records could invoke WPACKET_cleanup() on an uninitialised WPACKET. Silently discard DTLSPlaintext in nonzero epochs, as required by RFC 9147, after consuming the complete fragment. Harden tls13_cipher() by honouring allow_plain_alerts, rejecting non-unified DTLS headers, and ensuring WPACKET is initialised before cleanup. Keep validate_record_header unset because invalid DTLS records must be silently discarded rather than converted into fatal alerts. Assisted-by: pi:kimi-k3 Reviewed-by: Ryan Hooper <ryanh@openssl.foundation> Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com> Merge-date: Mon Sep 7 14:41:16 2026 Merged-from: openssl#32622
Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Matt Caswell <matt@openssl.foundation> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> MergeDate: Wed Sep 23 14:46:50 2026 (Merged from openssl#32681)
The following commit openssl@b2f2f7f exposes a side effect that causes a segfault in sslapitest. sslapittest is a static, and loads the DASYNC engine as a shared library. The callstack on failure is: dasync_destroy() ERR_unload_strings() CRYPTO_THREAD_write_lock() ← SIGSEGV This happens because the cleanup order is such that the err_cleanp() is called first which frees the lock and sets err_string_lock = NULL Then it later calls ERR_unload_string() which will crash on the write_lock() The above commit does a call early to ERR_set_mark() which changes the cleanup order. Assisted-by: OpenAI Codex:gpt-5.6-sol Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Norbert Pocs <norbertp@openssl.org> Merge-date: Wed Sep 23 18:37:17 2026 Merged-from: openssl#32943
Callers of CRYPTO_atomic_cmp_exch_ptr() that fail the exchange adopt the winning pointer delivered through *expect and access the object it points to: the publish-after-init pattern, where the winner publishes a built object with the compare-exchange and the loser adopts it. With a relaxed failure memory order there is no happens-before edge from the winner's initialization writes to the loser's subsequent reads of the object contents — a genuine data race, latent on weakly-ordered architectures (ARM, POWER), and visible to ThreadSanitizer for any caller that adopts the published object this way. Unlike the report that motivated 8f9f0d2 ("Fix persniketyness in tsan"), such a report here is a true positive: there, publication went through locks, so relaxed loads were sufficient; here, publication goes through the compare-exchange itself, so the failure path must carry acquire semantics. The relaxed production memory orders of CRYPTO_atomic_load_ptr() and CRYPTO_atomic_store_ptr() (the TSAN_LOAD_MEM_ORDER / TSAN_STORE_MEM_ORDER dance) are untouched; whether they should be strengthened outside TSan builds is a separate question. Assisted-by: Pi:moonshotai/kimi-k3 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Merge-date: Tue Sep 22 09:29:50 2026 Merged-from: openssl#32868
Describes an alternative API design using PKCS12_PARSE_CTX opaque context and public PKCS12_SAFEBAG_get1_skey() for Java keytool PKCS#12 files. Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:20 2026 (Merged from openssl#30937)
This is the base AES OID used by Java keytool when storing generic AES symmetric keys in PKCS#12 files. Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:21 2026 (Merged from openssl#30937)
Introduce PKCS12_PARSE_CTX opaque context for PKCS12_parse_ex(), replacing the growing parameter list pattern. Add PKCS12_decrypt_secretbag() for decrypting secret bags and PKCS12_SAFEBAG_get1_skey() for converting decrypted PKCS8 data to EVP_SKEY, following the existing private key pattern (PKCS12_decrypt_skey_ex + EVP_PKCS82PKEY_ex). Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:22 2026 (Merged from openssl#30937)
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:24 2026 (Merged from openssl#30937)
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:25 2026 (Merged from openssl#30937)
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com> Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:26 2026 (Merged from openssl#30937)
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr> Reviewed-by: Simo Sorce <simo@redhat.com> MergeDate: Thu Sep 24 07:34:27 2026 (Merged from openssl#30937)
In the extended cross-compile workflows for aarch64 and RISC-V, the "make all tests" and "make some tests" steps now also run when the marker appears in the pull request body, and the "make evp tests" step is skipped in that case. A pull request matching only on its title still gets the EVP tier, and legs setting `tests: none` stay build-only. Assisted-by: Claude:claude-opus-5 Reviewed-by: Richard Levitte <levitte@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Merge-date: Thu Sep 24 07:44:32 2026 Merged-from: openssl#32879
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Milan Broz <mbroz@openssl.org> Merge-date: Thu Sep 24 08:51:59 2026 Merged-from: openssl#32972
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Milan Broz <mbroz@openssl.org> Merge-date: Thu Sep 24 08:52:43 2026 Merged-from: openssl#32970
see openssl#29934 Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com> Reviewed-by: Paul Yang <paulyang.inf@gmail.com> Merge-date: Thu Sep 24 08:58:11 2026 Merged-from: openssl#32862
…enameMacros These were omitted in 232b328 "Add a WebKit clang-format file" for some reason, and clang-format is apparently unable to figure out that a macro resolves in a type name, in all its geniousness, leading to incorrect and misleading formating of the code that uses these type macros. Rescind that omission. Fixes: 232b328 "Add a WebKit clang-format file" Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Merge-date: Thu Sep 24 09:01:04 2026 Merged-from: openssl#32304
For some reason, these macros haven't been included in clang-format config in commit 232b328 "Add a WebKit clang-format file", which led to incorrect (and at times misleading) formatting of the code that uses them. Rescind that omission. Fixes: 232b328 "Add a WebKit clang-format file" Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Merge-date: Thu Sep 24 09:01:05 2026 Merged-from: openssl#32304
Re-formatting was done using the following command:
for i in `git grep -l 'OSSL_LIST\|PRIORITY_QUEUE_OF\|SPARSE_ARRAY_OF' \
-- '*.c' '*.h' '*.c.in' '*.h.in'`; do \
clang-format-21 --style=file:.clang-format -i "$i"; \
done
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:01:06 2026
Merged-from: openssl#32304
Fixes: openssl#31672 Signed-off-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Norbert Pocs <norbertp@openssl.org> Merge-date: Thu Sep 24 09:13:10 2026 Merged-from: openssl#32899
The RCU code calls CRYPTO_atomic_load_int() and CRYPTO_atomic_add64() for their side effect and ignores the return value, in get_hold_current_qp() and in ossl_rcu_read_unlock(). Those functions leave the output untouched when they fail, so qp_idx, tmp and ret are only guaranteed to be written when the call succeeds. In practice they cannot fail here, because ossl_rcu_lock_new() does not return a lock unless rw_lock was created. The compiler cannot see that, though, and reports the reads as potentially uninitialised as soon as the atomics gain a visible early return - which the next commit adds. Give the three variables initialisers. Zero is a safe choice in each case: qp_idx indexes qp_group, which always holds at least two entries, so both the subscript and the returned pointer stay in bounds; tmp then matches qp_idx, so the equality test succeeds and the loop exits on its first pass instead of running again on an indeterminate index; and ret satisfies the assertion that follows it. Assisted-by: Claude:claude-opus-5 Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Merge-date: Thu Sep 24 09:18:02 2026 Merged-from: openssl#32633
crypto/threads_win.c provides two implementations of the CRYPTO_atomic_*
family: a lock-free one built on the Interlocked* intrinsics, and a
fallback that takes a CRYPTO_RWLOCK. The fallback is compiled when
OSSL_USE_INTERLOCKEDOR64 is not defined, which per
include/internal/threads_common.h means MSVC 2010 and earlier on x86, or
a MinGW build that is not __MINGW64__ - that is, 32-bit MinGW. The
comment on the rw_lock field in this file names those same two cases.
Eight functions in that fallback path assert that the caller supplied a
lock. That assumption does not hold: OPENSSL_init_crypto() in
crypto/init.c calls
CRYPTO_atomic_load(&optsdone, &tmp, NULL)
deliberately, and the comment above the call explains why. It is an
optimisation that runs before optsdone_lock has been created, so there
is no lock to pass, and it is documented as expected to fail on
platforms without lockless atomic loads, with the failure ignored.
Because OPENSSL_init_crypto() runs on essentially the first use of the
library in any process, the assertion fires immediately on the affected
targets and every binary aborts before doing any work:
$ openssl version
crypto/threads_win.c:694: OpenSSL internal error: \
assertion failed: lock != NULL
The equivalent function in crypto/threads_pthread.c returns 0 for a NULL
lock rather than asserting, which is what the caller in init.c expects,
so this was a difference between the two backends rather than an
invariant of the API.
Return 0 for a NULL lock in all eight functions, matching the pthread
backend. Behaviour when a lock is supplied is unchanged.
This restores the check that commit 1e1ea71 replaced with an
assertion. That commit also relied on the assertion to suppress three
-Wmaybe-uninitialized reports in the RCU code; the preceding commit
addresses those directly, so a --strict-warnings build stays clean.
Assisted-by: Claude:claude-opus-5
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Thu Sep 24 09:18:03 2026
Merged-from: openssl#32633
Because that is known to cause problems when a different libcrypto version is used in the calling application. Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Merge-date: Thu Sep 24 11:11:30 2026 Merged-from: openssl#32896
Reviewed-by: Matt Caswell <matt@openssl.foundation> Reviewed-by: Kurt Roeckx <kurt@roeckx.be> Merge-date: Thu Sep 24 13:42:08 2026 Merged-from: openssl#32895
Cover the bad option failures (unknown option, invalid input and output formats, unparseable bit sizes and extra arguments) as well as the failure when loading an invalid parameters file, verifying the error messages printed to stderr with the shared app_fails helper. Reviewed-by: Richard Levitte <levitte@openssl.org> Reviewed-by: Ryan Hooper <ryanh@openssl.foundation> Merge-date: Thu Sep 24 14:35:00 2026 Merged-from: openssl#32589
When decoding a datagram in qrx_process_pkt, we reserve some space in the rxe and copy the token out of the packet to the rxe header. However, if we do a second decode in this function (which is possible), we reset that pointer to point into the datagram buffer. While this is generally not catastrophic as there is no non-debug code that references this pointer after the URXE is freed, its an issue waiting to happen, so if we do a second decode, restore the token pointer again to point to our reserved space. Fixes openssl/srt#298 Reviewed-by: Saša Nedvědický <sashan@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Fri Sep 25 10:58:42 2026 Merged-from: openssl#32933
Commit 3a69b19 changed b64_write from chunked ctx->buf output to a dynamic encoded_buf. The new buffer was scratch-only, so retryable downstream failures or positive short writes could drop encoded output while still reporting the input bytes as consumed. Track encoded_buf as pending output with offset and length, include it in BIO_wpending, and write any pending output before accepting more input. Add tests for retry via -1, retry via 0, positive short writes, and short writes followed by retry, with and without BIO_FLAGS_BASE64_NO_NL, across both aligned input and final-tail input. Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Viktor Dukhovni <viktor@openssl.org> Merge-date: Fri Sep 25 11:02:43 2026 Merged-from: openssl#31000
The signing-only option validation runs before load_key(), so privkey is always NULL when determining newout. Consequently, -key or -signkey alone does not identify re-signing an input certificate or signing an -x509toreq output. Signing options are rejected, and the default extensions section is not loaded. Check privkeyfile at this stage, which records that the option was supplied. Keep the later privkey check unchanged because the key has been loaded by then. Add tests for the validation guard, re-signing options, and certificate and request extensions. Fixes openssl#32150 Assisted-by: pi:kimi-k3 Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Merge-date: Fri Sep 25 11:07:32 2026 Merged-from: openssl#32151
Signed-off-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Fri Sep 25 11:33:23 2026 Merged-from: openssl#32990
Check X509_NAME_add_entry_by_txt() result (wrapped in X509_NAME_ADD() macro), as it may fail. Reported by Coverity as unchecked return value, CID 1701601, 1701602, and 170604. Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701601 Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701602 Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701604 Complements: 4dde554 "chunk 5 of CMP contribution to OpenSSL" Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Norbert Pocs <norbertp@openssl.org> Merge-date: Fri Sep 25 11:43:52 2026 Merged-from: openssl#32901
This test is explicitly written to fail. Suppress. Signed-off-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Richard Levitte <levitte@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Merge-date: Fri Sep 25 13:37:15 2026 Merged-from: openssl#32992
Signed-off-by: feventura <felipe.ventura@entrust.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was created to facilitate the identification of the changes made to implement composite signatures and certificates.
This branch contains all 18 combinations: