Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
932 commits
Select commit Hold shift + click to select a range
4b581a4
Add a migration entry for ASN1_STRINGs
bob-beck Aug 6, 2026
4ddd100
doc: add missing const to PEM write SYNOPSIS
felirami Aug 18, 2026
f7d2d2a
AEADs: add an error to the queue on tag mismatch
bbbrumley Aug 29, 2026
82733d9
test: tolerate DTLS peer change with fragment data
bukka Sep 1, 2026
1935d21
Add metadata support to EVP_SKEY objects
beldmit Sep 2, 2026
ec444cb
dtls: fix DTLSv1_listen record sequence after cookie verify
baoyi84930 Jul 24, 2026
bfa50e1
statem: test tls_construct_client_key_exchange
bukka Aug 11, 2026
0e11020
apps: test enc app opaque symmetric key options
bukka Aug 28, 2026
19c76c2
apps: test enc -kfile option
bukka Aug 28, 2026
8da3880
apps/x509.c: failing exit status on every failure path reaching err:
idrassi Aug 4, 2026
db1b675
Add test for ASN1_TYPE memory leak in asn1_multi()
Greensi7 Aug 11, 2026
a58528d
Fix error handling in asn1_multi()
Greensi7 Aug 12, 2026
27f6123
Fix clang-format violation in tls_process_client_hello()
mattcaswell Aug 26, 2026
b4f5e49
Check every changed file in the coding style CI job
mattcaswell Aug 26, 2026
7144265
apps: cover the kdf -binary option in the test recipe
bukka Aug 28, 2026
518e7ed
apps: cover the prime -generate option in the test recipe
bukka Aug 28, 2026
83ba3cb
apps: cover the dhparam -dsaparam file input in the test recipe
bukka Aug 29, 2026
4d4b0d9
test framework: add app_fails and slurp_file to OpenSSL::Test
bukka Aug 29, 2026
d6d126c
apps: print an error for a non-positive genrsa bits argument
bukka Aug 29, 2026
da7d7a3
apps: cover the genrsa error cases and verbose mode in the test recipe
bukka Aug 29, 2026
5f972fb
apps: cover the gendsa error cases and verbose mode in the test recipe
bukka Aug 29, 2026
b2bd6a8
apps: cover the genpkey error cases and verbose mode in the test recipe
bukka Aug 29, 2026
39952ff
apps: cover the ec no_public option in the test recipe
bukka Aug 29, 2026
398553b
DTLS 1.3: truncate the unified header sequence number and reconstruct it
idrassi Aug 30, 2026
bf416ba
DTLS 1.3 Enforce the RFC 9147 Section 8 sending epoch limit
rsith71 Aug 31, 2026
689fb0a
Fix DTLS 1.3 accepting unauthenticated plaintext alerts
idrassi Aug 31, 2026
3d3a147
test: DTLS 1.3 forged DTLSPlaintext alert regression tests
idrassi Aug 31, 2026
4e78dbf
statem_clnt_construct_test.c: Use snprintf() instead of BIO_snprintf()
t8m Sep 7, 2026
01fa9c4
quic_multistream_test.c: Fix test failure in fuzzing build
t8m Sep 7, 2026
6317e5b
apps: cover request attributes in req test recipe
bukka Sep 1, 2026
5947136
apps: cover the -extfile option in the ca recipe
bukka Sep 1, 2026
f576890
apps: cover the -crlexts option in the ca recipe
bukka Sep 1, 2026
acfedc4
Provider compat CI: Force copy of fips.so and fipsmodule.cnf
t8m Sep 2, 2026
9d036bd
params: add directive for dealing with duplicated parameters
paulidale Sep 4, 2026
68b9085
ec: accept duplicate instances of the point format parameter
paulidale Sep 4, 2026
9e52bfd
Convert the paths for generator scripts on windows.
bob-beck Sep 2, 2026
5ff3020
copyright.pm: spell the null device the platform's way
bob-beck Sep 2, 2026
55d5f10
test/recipes/95-test_external_pyca_data/cryptography.sh: use python3 …
esyr Sep 3, 2026
c5c6f69
test/recipes/95-test_external_pyca_data/cryptography.sh: use BLDTOP, …
esyr Sep 3, 2026
ead81ea
test/recipes/95-test_external_pyca_data/cryptography.sh: update dep i…
esyr Sep 3, 2026
12060ef
Update pyca-cryptography and wycheproof submodules
esyr Sep 3, 2026
1802f56
Revert "Skip pyca cryptography tests for now"
esyr Sep 3, 2026
97fd919
Accept CRLs whose IDP names the issuer of a certificate without CDP
Aug 26, 2026
f289977
ktls_send_ctrl_message(): Fix parameter name from 'lengthi' to 'length'
Ohyunj Aug 28, 2026
8f6fd3f
Pass parameters to evp_keymgmt_newdata
simo5 Sep 2, 2026
223e04f
Fix AES-GCM tag length query and the test meant to cover it
bbbrumley Sep 2, 2026
5ce57ab
Fix Debian 11 build in OS Zoo CI
quarckster Sep 8, 2026
3dfdd6d
Update pyca-cryptography submodule to 51.0.0-dev1
bukka Sep 8, 2026
6a9238e
cryptography.sh: install vectors from the submodule
bukka Sep 8, 2026
1ea0898
test: derive dtls_listen_write_seq_test's expected sequence from the …
rsith71 Sep 8, 2026
9e97c88
CHANGES.md: wording changes, formatting fixes
esyr Sep 8, 2026
1d6938b
CHANGES.md: reorder existing entries
esyr Sep 9, 2026
3c63230
CHANGES.md, NEWS.md: update for 4.1.0-alpha1
esyr Sep 9, 2026
e074eab
Copyright year updates
openssl-machine Sep 9, 2026
27e8c37
make update
openssl-machine Sep 9, 2026
47b46ba
Prepare for 4.2
openssl-machine Sep 9, 2026
16c2d52
Addressed Mike's comments
feventura Sep 9, 2026
bd04401
Add adaptations from the cherry-pick of 035019
feventura Sep 9, 2026
6f67d15
added no ec/ecx block in composite test
feventura Sep 9, 2026
2cf976b
capabilities: fix some type errors in the TLS capabilities definitions
paulidale Sep 7, 2026
92b20ad
test: verify TLS group capability parameter type
paulidale Sep 8, 2026
71a4b55
test/certs/mkcert.sh: fix default DAYS to be really 100 years (not on…
DDvO Jun 19, 2026
12e823b
25-test_verify.t and test/certs/: add mixed 3-level RSA/ECC chain and…
DDvO Aug 26, 2026
7a1ae9e
65-test_cmp_vfy.t etc.: take 2-level and 3-level cert hierarchy from …
DDvO Jun 19, 2026
6cd6a9a
doc/man1: fix description of -{,chain,verify}CAstore option parameter…
DDvO Apr 26, 2025
33ed820
doc/man3: fix doc of uri parameters of X509_LOOKUP_add_store{,_ex}() …
DDvO Apr 26, 2025
0d5b305
90-test_store.t: fix outdated comment on relative file: path
DDvO Apr 26, 2025
5e53ea9
ossl_store_register_loader_int(): refactor by extracting the macro OS…
DDvO Apr 26, 2025
503162e
ossl_store_register_loader_int(): make sure to check that scheme is n…
DDvO Aug 31, 2026
a938e69
OSSL_parse_url(): refactor scheme parsing, using new OSSL_SKIP_SCHEME()
DDvO Apr 26, 2025
a9ebcbc
OSSL_STORE_open_ex(): fix scheme parsing, using new OSSL_SKIP_SCHEME()
DDvO May 1, 2025
b21a12d
test/fake_rsa: fix invalid scheme name to 'fake-rsa'
DDvO May 1, 2025
bf89ed9
OSSL_HTTP_parse_url.pod: fix doc of string return values for absent q…
DDvO Feb 20, 2025
f8cc083
Fix crash on programmatically added X509 extensions
beldmit Jun 22, 2026
1a4923a
Test that we don't crash on programmatically added X.509 extensions
beldmit Jul 4, 2026
2564382
Documentation for X509V3_EXT_nconf and X509V3_EXT_nconf_int
beldmit Aug 19, 2026
f08174e
Add public API for IPAddrBlocks (RFC 3779)
herbenderbler Mar 29, 2026
f2680a4
Added supporting tests for algor null pointer fix
mandreko Mar 16, 2026
e80aae7
fix: guard MD5-dependent X509_ALGOR test with OPENSSL_NO_MD5
mandreko Aug 3, 2026
0a7d45b
encode_key2any: free key params on error in key_to_p8info and key_to_…
rootvector2 Jul 3, 2026
b5f0da4
test: assert the specific alert in DTLS sslrecords tests
bukka Jul 17, 2026
4da7d54
CHANGES.md, NEWS.md: Add a new 4.2 section
t8m Sep 9, 2026
b233525
Add 4.1 branch to various CI jobs
t8m Sep 9, 2026
2238a94
Remove 3.0 branch from various CI jobs as it is EOL
t8m Sep 9, 2026
f6c146f
Add a watchdog timeout to the C tests built with testutil/main
bob-beck Aug 19, 2026
668dc66
Add core dumps and matching binary to CI artifacts on linux
bob-beck Aug 19, 2026
8b2632d
Revert "Free connections before listeners in the radix test cleanup"
nhorman Sep 2, 2026
f99bbcd
Dont have dgram_pairs track bios, track bio_dgram_pair_st instead
nhorman Sep 3, 2026
862853b
Add tests for bio_dgram_pair
bukka Sep 2, 2026
e66f91b
Augment docs for BIO_s_dgram_pair
nhorman Sep 4, 2026
e6c03cb
use BUF_MEM_free instead of OPENSSL_free to free BUF_MEM in str_copy
nhorman Sep 9, 2026
1caa35f
Fix set but unsued variable in lib/opt.c
nhorman Sep 10, 2026
f6eb87c
Remove --feeling-safe from interop_tests.yml
nhorman Sep 10, 2026
da1c478
coveralls.yml: Do not timeoout in tests
t8m Sep 14, 2026
a012e34
DTLS1.3: disallow TLS_AES_128_CCM_8_SHA256 under DTLS1.3
rsith71 Sep 8, 2026
4fc10a5
X509: keep names modified until canonicalization succeeds
carrerasdarren-cell Jul 22, 2026
5fd4eae
X509: complete ASN.1 stream failure handling
carrerasdarren-cell Sep 1, 2026
223fba0
Properly capture STDERR in pkcs12 tests
beldmit Sep 7, 2026
8b59e80
tdes: restore query parameters
paulidale Sep 3, 2026
dbf8765
Port script_50
andrewkdinh Aug 3, 2026
7b81755
Port script_51
andrewkdinh Aug 3, 2026
5bbf74f
Port script_52
andrewkdinh Aug 3, 2026
f8bb485
Port script_53
andrewkdinh Aug 3, 2026
af3173b
Port script_54
andrewkdinh Aug 3, 2026
84ad0cc
Fix tick race in radix fault-injection scripts
andrewkdinh Aug 23, 2026
1edb853
Migrate script_55 to script_59
andrewkdinh Aug 31, 2026
b9b1f48
add windows-arm64 job into OS Zoo workflow
quarckster Aug 21, 2026
eacf272
chore(bump): update cross-platform-actions/action to v1.5.0
ngie-eign Jul 2, 2026
e4653f5
chore(bump): update FreeBSD and OpenBSD images
ngie-eign Jul 2, 2026
b165e1b
CI: fix capability assignments in cross compile workflows
idrassi Sep 9, 2026
b223c2a
Port script_60
andrewkdinh Sep 5, 2026
6e2ec69
Port script_61
andrewkdinh Sep 5, 2026
cd3c863
Port script_62
andrewkdinh Sep 5, 2026
4a301dc
Port script_63
andrewkdinh Sep 5, 2026
b10b3ad
Port script_64
andrewkdinh Sep 5, 2026
75d20e6
Add a CI job to build once with Microsoft's nmake, not only jom
bob-beck Sep 2, 2026
e4aeafa
Free WPACKETs on error paths
jogme Sep 2, 2026
d6d07e7
Don't cleanup uninitialised variable hdr
jogme Sep 4, 2026
29c2859
CI: Add AArch64 GCS validation build job
gowthamsk-arm Aug 27, 2026
ec24702
Fix NULL dereference and memory leak in ASN1_item_dup()
Greensi7 Sep 3, 2026
0ab1125
Add X509_REQ_dup MFAIL test
Greensi7 Sep 4, 2026
b9c17d0
Add ASN1_item_dup() failure cleanup test
Greensi7 Sep 8, 2026
4a25fb9
Fix typo in INSTALL.md for enable-ec_explicit_curves
Rochish-Manda Sep 14, 2026
a857515
Fix bugs in OSSL_STORE_attach
Greensi7 Aug 16, 2026
f666172
Fix memory leak in ossl_decoder_instance_new_forprov()
Greensi7 Aug 13, 2026
4972eee
Fix NULL dereference in try_key_value()
Greensi7 Aug 13, 2026
53287d0
Add OSSL_STORE store regression tests
Greensi7 Aug 17, 2026
faaef82
Add cms_verify fuzzer
Greensi7 Aug 11, 2026
6ac66ab
Update corpora submodule
Greensi7 Aug 14, 2026
cdf6816
apps: test dgst -hex and -binary options
bukka Aug 28, 2026
fa1d46d
apps: test ciphers app output modes and cipher selection
bukka Aug 28, 2026
6caadd9
apps: cover the pkeyutl asn1parse and hexdump options in the test recipe
bukka Aug 29, 2026
4ea4a71
Regression test for PKCS12_parse
beldmit Sep 9, 2026
0a62876
Provide stricter test for cert order on parse
beldmit Sep 10, 2026
3bdd4a6
Fix a memory leak in apps/ocsp.c issuer
bernd-edlinger Sep 12, 2026
5f38725
add script (setup-mock.sh) to generate test credentials for CMP.
rajeev-0 Feb 20, 2026
aee3523
Fix double free in server client-certificate parse error path
idrassi Sep 1, 2026
37809a1
store: add a fake store provider for API tests
bukka Sep 1, 2026
ab566c7
apps: cover the rsa error cases in the test recipe
bukka Aug 29, 2026
e713336
apps: fix dsa app exit status on option parsing errors
bukka Aug 29, 2026
b9c5f2b
apps: cover the dsa error cases in the test recipe
bukka Aug 29, 2026
1cdca26
Make the extended tests CI jobs run on ready_for_review
t8m Sep 4, 2026
dd6c536
Check return code of BIO_ADDR_rawmake
jogme Sep 2, 2026
017d9aa
Dynamic compression: do not leave errors behind on success
t8m Aug 27, 2026
9e0cc5e
update active branches in deploy-docs-openssl-org.yml workflow
quarckster Sep 10, 2026
4d7195c
http: reject HTTPS downgrades after relative redirects
idrassi Sep 5, 2026
bcf6c88
statem: fail ClientHello construction on ECH GREASE failure
bukka Aug 5, 2026
d39b221
ECH: Fix keylog callback to use inner client hello random from ECH
n13l Aug 3, 2026
c3cb4f1
Fix memory leak on error on OSSL_PROVIDER_available()
ndossche Sep 9, 2026
0376ea6
quic-radix: inject the path challenge flood only into 1-RTT packets
bukka Sep 8, 2026
852480d
Removes unused args from ossl_rsa_multiprime_derive() declaration
fwh-dc Sep 13, 2026
aeeca5a
rand: prevent recursive seed source construction
Sep 5, 2026
28016ea
wrap.pl: exec the command so signals reach the right pid
mattcaswell Sep 10, 2026
ca09ef0
70-test_stime.t: SIGKILL the server instead of SIGHUP
mattcaswell Sep 10, 2026
0038f3e
Add ASCON-AEAD128 cipher implementation per NIST SP 800-232
evil-cry Nov 5, 2025
f218ddb
[test/recipes/30-test_evp_data] more ascon unit tests, both positive …
bbbrumley Mar 30, 2026
b3b5c27
Removes unused foreign member of evp_pkey_st
fwh-dc Sep 13, 2026
ce24e2c
test framework: add binary mode to slurp_file
bukka Sep 8, 2026
9138c69
cms: reject signature alg OID as digestAlgorithm
bukka Sep 5, 2026
35e3150
cms: correctly fail on invalid key length in CMS_decrypt
bukka Jul 25, 2026
0c307fb
RISC-V: GHASH: multi-block aggregation
HeliC829 May 11, 2026
ef4247f
RISC-V: GHASH: Zvbc multi-block aggregation
HeliC829 May 11, 2026
1eef7f6
RISC-V: GHASH: Zvkg multi-block aggregation
HeliC829 May 11, 2026
382ccef
Removes SSL and SSLv3 from SSL_state_string_long() return.
fwh-dc Apr 15, 2026
200b907
test: handle atomic load failure in hashtable cleanup
nikolapajkovsky Sep 16, 2026
b2162f9
doc: add reference to how to list EC curve names
kovan Jul 23, 2026
3a19032
crypto/asn1: add checks for possibly negative ASN1_STRING length
esyr Sep 14, 2026
b04d83b
Fix memory leak of der_buf on error in x942_encode_otherinfo()
ndossche Sep 8, 2026
abdc711
Remove unused static variables to suppress new clang warning
t8m Sep 14, 2026
57ff835
hashtable.c: Use previously unused variables to avoid warning
t8m Sep 14, 2026
c3e1d0c
fake_rsaprov.c: Use previously unused global variables
t8m Sep 14, 2026
f903c6b
quic_cfq_test.c: Use previously unused global variables
t8m Sep 14, 2026
fa5c8d1
apps/server.c: Do not declare use_sendfile and use_zc_sendfile withou…
t8m Sep 16, 2026
138bea8
aes: factor out shared VAES-512 primitives
madanm3 Aug 31, 2026
1734809
aes-ctr-avx512: add VAES-512 AES-CTR encryption
madanm3 Aug 31, 2026
c5bd80d
Mark the encoding stale in X509_set_serialNumber()
bob-beck Sep 5, 2026
57e38e5
Mark the encoding stale when adding a CRL extension
bob-beck Sep 5, 2026
8e7db02
Discard the cached encoding when it cannot be saved
bob-beck Sep 6, 2026
e3c1809
Cache the signed encoding when signing an ASN.1 item
bob-beck Sep 5, 2026
ad686dc
Compare the signature in X509_cmp()
bob-beck Sep 4, 2026
600251e
Fall back to comparing the encoding in X509_CRL_match()
bob-beck Sep 4, 2026
d0113f1
Treat a modified certificate or CRL as equal only to itself
bob-beck Sep 5, 2026
647a966
Make the cached SHA-1 fingerprint internal-only
bob-beck Sep 3, 2026
e12ed4e
Make the cached CRL fingerprint internal-only
bob-beck Sep 3, 2026
403dbe5
Compute X509_get_signature_info() on demand, not in the cache
bob-beck Sep 3, 2026
90c3f51
Use SipHash for the internal fingerprint
bob-beck Sep 3, 2026
98a76fa
Document when X509_cmp() and X509_CRL_match() order objects
bob-beck Sep 5, 2026
68f6d3a
Make system exec directly rather than calling /bin/sh
nhorman Sep 13, 2026
da1a85b
Fix Status badges to only show scheduled runs
nhorman Sep 15, 2026
9bd26a3
dtls: Add missing pqueue free
jogme Sep 3, 2026
36e1546
dtls: Don't check for NULL when it can't be
jogme Sep 3, 2026
7ff33de
Fix wrong condition evaluation order
jogme Sep 3, 2026
7c234e5
Fix potential DoS and undefined behavior in KRB5KDF due to zero-lengt…
AntonMoryakov Jan 23, 2026
5df7d33
NUL-terminate ASN1_STRING data built inside libcrypto
bob-beck Sep 14, 2026
90621b1
Poison the ASN1_STRING NUL terminator under ASan and MSan
bob-beck Sep 14, 2026
ecdb79e
DTLS: reject trailing bytes after the ACK record number vector
idrassi Sep 16, 2026
859aea4
Bound the DTLS 1.3 ACK body read by the record, not init_num
mattcaswell Sep 10, 2026
0dee42e
Poison the ASN1_STRING NUL terminator under Valgrind
bob-beck Sep 15, 2026
d501113
refcount: declare Windows CRYPTO_REF_COUNT as volatile long
nikolapajkovsky Sep 9, 2026
0e94c5b
Fix EXFLAG_SS set on self-issued rollover CA certificates
idrassi Sep 10, 2026
db3319e
TLSProxy: track message reassembly per sender, not globally
rsith71 Sep 14, 2026
edf18df
QUIC: initialize Retry WPACKET before error-path cleanup
nikolapajkovsky Sep 16, 2026
baaa403
.github/workflows: add Rolling OS Zoo CI workflow
esyr Sep 16, 2026
9765348
.github/workflows/os-zoo.yml: update Linux distro matrix
esyr Sep 16, 2026
a41c00d
DTLS: preserve outstanding flights after incomplete ACKs
idrassi Sep 16, 2026
92dcf84
Fix rx_max_udp_payload_length default for QUIC
nhorman Sep 16, 2026
d190c27
Fix lock_failed output in Windows cmp_exch_ptr
bukka Sep 17, 2026
99970d3
aes-ctr-avx512: disable the VAES-512 CTR path for MSVC
madanm3 Sep 18, 2026
e9344b0
Remove /Gs0 windows compiler flag
jogme Sep 17, 2026
63c7eba
os-zoo.ci: Enable md4 for win arm64
jogme Sep 17, 2026
071d697
dtls: read the rest of a DTLS 1.3 ACK body from the current record
idrassi Sep 17, 2026
411499a
test: cover DTLS 1.3 ACK reads across timeout expiry
idrassi Sep 17, 2026
6a13694
Add windows arm64 hybridcrt config
jogme Sep 17, 2026
cdd3960
CHANGES.md: massage ASN1_STRING_set1_*() entry
esyr Sep 23, 2026
a32ad40
CHANGES.md: update for 4.1.0-beta1
esyr Sep 23, 2026
f0fa375
CHANGES.md: cleanup CRL scope checking change log entry
esyr Sep 14, 2026
bced994
CHANGES.md: move IPAddrBlocks change log entry to a proper section
esyr Sep 14, 2026
108ced2
ML-KEM-512 hybrid TLS KEMs
Sep 3, 2026
04f8091
More accurate ssl_new curve tests
Sep 4, 2026
bb105c9
Suppress unusable PSK offers and 0-RTT client-side
Jul 22, 2026
15ed7c1
Add overlooked DTLS min/max version bounds for SM4
Sep 4, 2026
53c6289
Fix: CI Failure
slontis Sep 23, 2026
cd19b15
crypto/threads_pthread.c: acquire on cmp_exch failure
levitte Sep 17, 2026
255c87c
Add design doc for PKCS#12 symmetric key support (v2 approach)
beldmit Apr 21, 2026
377d369
Add id-aes OID to OpenSSL object database
beldmit Apr 15, 2026
89c6d4d
Add support for Java keytool PKCS#12 files with symmetric secret keys
beldmit Apr 21, 2026
b68e796
Add tests for Java PKCS#12 symmetric key support
beldmit Apr 21, 2026
c8af5fc
Add symmetric key support to OSSL_STORE PKCS#12 loader
beldmit Sep 10, 2026
49a9ba5
Add documentation for PKCS#12 symmetric key support
beldmit Apr 21, 2026
90bf314
Provide metadata for symmetric keys when parsing pkcs#12 files
beldmit Sep 21, 2026
0dcf166
CI: treat [aarch64 ci]/[riscv ci] in a PR body as a full-test opt-in
igus68 Sep 18, 2026
f52ce99
sslapitest.c: Fix build with no-chacha
t8m Sep 24, 2026
f6eed83
sslapitest.c: ML-KEM-512 hybrids are not supported by old fips providers
t8m Sep 24, 2026
82d6fa4
CHANGES.md entry for ASCON-AEAD128
bbbrumley Sep 16, 2026
0e6d3c8
.clang-format: add OSSL_LIST, {PRIORITY_QUEUE,SPARSE_ARRAY}_OF to Typ…
esyr Aug 13, 2026
52b6781
.clang-format: add OSSL_LIST_FOREACH* macros to ForEachMacros
esyr Aug 11, 2026
98089e8
Re-format code after TypenameMacros and ForEachMacros additions
esyr Aug 11, 2026
393e066
Disable AVX2 base64 codec for MinGW GCC builds
nikolapajkovsky Sep 21, 2026
8dd3089
threads_win: initialise RCU locals not written on every path
josealf Sep 1, 2026
5dfc09b
threads_win: don't abort CRYPTO_atomic_* on a NULL lock
josealf Sep 1, 2026
4f9c1f3
Use NO_ATEXIT in non-static legacy provider
bernd-edlinger Sep 20, 2026
d81b899
Fix a memory leak in quicapitest.c
bernd-edlinger Sep 19, 2026
d8f792f
apps: cover the dsaparam error cases in the test recipe
bukka Aug 29, 2026
4242c88
Restore QUIC token value after second urxe decode
nhorman Sep 22, 2026
34f8ce6
Fix base64 BIO write retry handling
idrassi Apr 27, 2026
7aa9f50
apps/x509: Fix new output detection for -key signing
idrassi Aug 3, 2026
fd0ddcc
Increment test counter when a test is added
jogme Sep 25, 2026
e067d98
test/cmp_hdr_test.c: check X509_NAME_add_entry_by_txt() result
esyr Sep 21, 2026
e13af7e
Suppress asn1 string nul byte poisoning test on valgrind
jogme Sep 25, 2026
1b75ab8
merge from upstream
feventura Sep 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
23 changes: 22 additions & 1 deletion .clang-format
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,19 @@ PointerAlignment: Right
# of a comment block to protect comments as
# per STYLE.md
CommentPragmas: '(^ IWYU pragma:|^\*$|^-$)'
ForEachMacros:
- "OSSL_LIST_FOREACH"
- "OSSL_LIST_FOREACH_FROM"
- "OSSL_LIST_FOREACH_REV"
- "OSSL_LIST_FOREACH_REV_FROM"
- "OSSL_LIST_FOREACH_DELSAFE"
- "OSSL_LIST_FOREACH_DELSAFE_FROM"
- "OSSL_LIST_FOREACH_REV_DELSAFE"
- "OSSL_LIST_FOREACH_REV_DELSAFE_FROM"
- "OSSL_RBT_FOREACH"
- "OSSL_RBT_FOREACH_SAFE"
- "OSSL_RBT_FOREACH_REVERSE"
- "OSSL_RBT_FOREACH_REVERSE_SAFE"
# OpenSSL uses typedefs extensively. Tell clang-format about them.
TypeNames:
- "ACCESS_DESCRIPTION"
Expand Down Expand Up @@ -1129,7 +1142,14 @@ TypeNames:
- "HASH_LONG"
- "MD32_REG_T"
# OpenSSL uses macros extensively. Tell clang-format about them.
TypenameMacros: ['LHASH_OF', 'STACK_OF']
TypenameMacros:
- "LHASH_OF"
- "OSSL_LIST"
- "OSSL_RBT_ENTRY"
- "OSSL_RBT_HEAD"
- "PRIORITY_QUEUE_OF"
- "SPARSE_ARRAY_OF"
- "STACK_OF"
StatementMacros:
- "BLOCK_CIPHER_aead"
- "BLOCK_CIPHER_generic"
Expand Down Expand Up @@ -1365,6 +1385,7 @@ StatementMacros:
- "ASN1_SEQUENCE_END_enc"
- "ASN1_SEQUENCE_END_name"
- "ASN1_SEQUENCE_END_ref"
- "k2d_NOCTX"
- "make_dh"
- "make_dh_bn"
- "static_ASN1_CHOICE_END"
Expand Down
1 change: 1 addition & 0 deletions .codespellrc
Original file line number Diff line number Diff line change
Expand Up @@ -258,6 +258,7 @@ ignore-words-list =
requestor,
Requestor,
requestors,
REQUIREDs,
rewinded,
roperties,
sav,
Expand Down
84 changes: 78 additions & 6 deletions .github/workflows/aarch64-more-cross-compiles.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,19 +14,54 @@ on:
schedule:
- cron: '05 03 * * *'
workflow_dispatch:
inputs:
pr:
description: 'Internal: openssl-ci-bot PR number. Leave empty for a normal manual run.'
required: false
type: string
head_sha:
description: 'Internal: openssl-ci-bot commit SHA. Leave empty for a normal manual run.'
required: false
type: string
check_run_id:
description: 'Internal: openssl-ci-bot check-run ID. Leave empty for a normal manual run.'
required: false
type: string

# Keep in sync with openssl-ci-bot's run-name parser, and with the Actions statistics
# collector that attributes CI load by parsing this same string. Both break silently.
run-name: >-
${{ github.event.inputs.pr && format('ci-dispatch pr={0} head={1} check_run_id={2}', github.event.inputs.pr, github.event.inputs.head_sha, github.event.inputs.check_run_id) || github.workflow }}

concurrency:
group: ${{ github.workflow }}-${{ github.event.inputs.pr || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
# Only a dispatch carries inputs, so this is skipped on every other trigger.
validate-dispatch-inputs:
if: inputs.pr != '' || inputs.head_sha != '' || inputs.check_run_id != ''
uses: ./.github/workflows/validate-dispatch-inputs.yml
with:
pr: ${{ inputs.pr }}
head_sha: ${{ inputs.head_sha }}
check_run_id: ${{ inputs.check_run_id }}

cross-compilation-aarch64:
# pull request title contains 'aarch64'
# pull request title contains 'arm64'
# pull request body contains '[aarch64 ci]'
# push event commit message contains '[aarch64 ci]'
# cron job
# manual dispatch
if: contains(github.event.pull_request.title, 'aarch64') || contains(github.event.pull_request.title, 'AArch64') || contains(github.event.pull_request.title, 'arm64') || contains(github.event.pull_request.body, '[aarch64 ci]') || contains(github.event.head_commit.message, '[aarch64 ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch'
needs: [validate-dispatch-inputs]
if: >-
(contains(github.event.pull_request.title, 'aarch64') || contains(github.event.pull_request.title, 'AArch64') || contains(github.event.pull_request.title, 'arm64') || contains(github.event.pull_request.body, '[aarch64 ci]') || contains(github.event.head_commit.message, '[aarch64 ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch') &&
!cancelled() &&
(needs.validate-dispatch-inputs.result == 'success' || needs.validate-dispatch-inputs.result == 'skipped')
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -134,6 +169,7 @@ jobs:
- uses: actions/checkout@v6
with:
persist-credentials: false
ref: ${{ github.event.inputs.head_sha || github.sha }}
- name: checkout fuzz/corpora submodule
run: git submodule update --init --depth 1 fuzz/corpora

Expand Down Expand Up @@ -165,8 +201,8 @@ jobs:

- name: Set OpenSSL caps environment
if: matrix.platform.opensslcapsname != ''
run: echo "OPENSSL_${{ matrix.platform.opensslcapsname }}=\
${{ matrix.platform.opensslcaps }}" >> $GITHUB_ENV
run: |
echo "OPENSSL_${{ matrix.platform.opensslcapsname }}=${{ matrix.platform.opensslcaps }}" >> "$GITHUB_ENV"

- name: get cpu info
run: cat /proc/cpuinfo
Expand All @@ -175,20 +211,24 @@ jobs:
if: matrix.platform.tests != 'none'
run: QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh info -cpusettings

# A dispatched run, and a pull request that opts in with `[aarch64 ci]` in its body, take the
# push tier: both exist to run pre-merge what otherwise only runs post-merge, and evp-only
# is the weaker signal. A pull request that only matches on its title keeps the evp tier.
# Legs setting `tests: none` stay build-only on every trigger, by design.
- name: make all tests
if: github.event_name == 'push' && matrix.platform.tests == ''
if: (github.event_name == 'push' || inputs.pr != '' || contains(github.event.pull_request.body, '[aarch64 ci]')) && matrix.platform.tests == ''
run: |
.github/workflows/make-test \
TESTS="-test_afalg" \
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
- name: make some tests
if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != ''
if: (github.event_name == 'push' || inputs.pr != '' || contains(github.event.pull_request.body, '[aarch64 ci]')) && matrix.platform.tests != 'none' && matrix.platform.tests != ''
run: |
.github/workflows/make-test \
TESTS="${{ matrix.platform.tests }} -test_afalg" \
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
- name: make evp tests
if: github.event_name == 'pull_request' && matrix.platform.tests != 'none'
if: github.event_name == 'pull_request' && !contains(github.event.pull_request.body, '[aarch64 ci]') && matrix.platform.tests != 'none'
run: |
.github/workflows/make-test \
TESTS="test_evp*" \
Expand All @@ -200,3 +240,35 @@ jobs:
name: "cross-compiles-aarch64@${{ matrix.platform.capslabel }}"
path: artifacts.tar.gz
if-no-files-found: ignore

gcs-validation-aarch64:
# pull request title contains 'aarch64'
# pull request title contains 'arm64'
# pull request body contains '[aarch64 ci]'
# push event commit message contains '[aarch64 ci]'
# cron job
# manual dispatch
needs: [validate-dispatch-inputs]
if: >-
(contains(github.event.pull_request.title, 'aarch64') || contains(github.event.pull_request.title, 'AArch64') || contains(github.event.pull_request.title, 'arm64') || contains(github.event.pull_request.body, '[aarch64 ci]') || contains(github.event.head_commit.message, '[aarch64 ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch') &&
!cancelled() &&
(needs.validate-dispatch-inputs.result == 'success' || needs.validate-dispatch-inputs.result == 'skipped')
runs-on: ubuntu-26.04-arm
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
ref: ${{ github.event.inputs.head_sha || github.sha }}
- name: print tool versions
run: |
gcc --version
ld --version
- name: config
run: |
CFLAGS='-mbranch-protection=standard' \
LDFLAGS='-Wl,-z,gcs=always -Wl,-z,gcs-report=error' \
./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace --banner=Configured
- name: config dump
run: ./configdata.pm --dump
- name: make
run: make -j4
49 changes: 49 additions & 0 deletions .github/workflows/avx512-sde.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,28 @@ on:
schedule:
- cron: '30 02 * * *'
workflow_dispatch:
inputs:
pr:
description: 'Internal: openssl-ci-bot PR number. Leave empty for a normal manual run.'
required: false
type: string
head_sha:
description: 'Internal: openssl-ci-bot commit SHA. Leave empty for a normal manual run.'
required: false
type: string
check_run_id:
description: 'Internal: openssl-ci-bot check-run ID. Leave empty for a normal manual run.'
required: false
type: string

# Keep in sync with openssl-ci-bot's run-name parser, and with the Actions statistics
# collector that attributes CI load by parsing this same string. Both break silently.
run-name: >-
${{ github.event.inputs.pr && format('ci-dispatch pr={0} head={1} check_run_id={2}', github.event.inputs.pr, github.event.inputs.head_sha, github.event.inputs.check_run_id) || github.workflow }}

concurrency:
group: ${{ github.workflow }}-${{ github.event.inputs.pr || github.run_id }}
cancel-in-progress: true

permissions:
contents: read
Expand All @@ -32,12 +54,26 @@ env:
SDE_MIRROR_ID: 915934

jobs:
# Only a dispatch carries inputs, so this is skipped on the nightly cron.
validate-dispatch-inputs:
if: inputs.pr != '' || inputs.head_sha != '' || inputs.check_run_id != ''
uses: ./.github/workflows/validate-dispatch-inputs.yml
with:
pr: ${{ inputs.pr }}
head_sha: ${{ inputs.head_sha }}
check_run_id: ${{ inputs.check_run_id }}

linux:
needs: [validate-dispatch-inputs]
if: |
!cancelled() &&
(needs.validate-dispatch-inputs.result == 'success' || needs.validate-dispatch-inputs.result == 'skipped')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
ref: ${{ github.event.inputs.head_sha || github.sha }}

- name: install NASM
run: sudo apt-get install -y nasm
Expand Down Expand Up @@ -71,17 +107,25 @@ jobs:
- name: sha3_x4_internal_test (AVX512 via SDE)
run: sde64 -icx -- ./test/sha3_x4_internal_test

- name: evp_extra_test (AVX512 via SDE)
run: sde64 -icx -- ./test/evp_extra_test

- name: fipsinstall (FIPS KAT via SDE)
run: sde64 -icx -- ./apps/openssl fipsinstall -module ./providers/fips.so -out /tmp/fipsmodule.cnf -provider_name fips

windows:
needs: [validate-dispatch-inputs]
if: |
!cancelled() &&
(needs.validate-dispatch-inputs.result == 'success' || needs.validate-dispatch-inputs.result == 'skipped')
runs-on: windows-2022
env:
VCVARS: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
ref: ${{ github.event.inputs.head_sha || github.sha }}

- name: install nasm
if: github.repository == 'openssl/openssl'
Expand Down Expand Up @@ -161,6 +205,11 @@ jobs:
shell: cmd
run: sde -icx -- test\sha3_x4_internal_test.exe

- name: evp_extra_test (AVX512 via SDE)
working-directory: _build
shell: cmd
run: sde -icx -- test\evp_extra_test.exe

- name: fipsinstall (FIPS KAT via SDE)
working-directory: _build
shell: cmd
Expand Down
14 changes: 10 additions & 4 deletions .github/workflows/backport.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,18 +7,27 @@

name: Backports CI

on: [pull_request]
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]

permissions:
contents: read

concurrency:
group: backports-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
check_backports:
strategy:
fail-fast: false
matrix:
release: [
{
branch: '4.1',
cppflags: ''
}, {
branch: '4.0',
cppflags: ''
}, {
Expand All @@ -30,9 +39,6 @@ jobs:
}, {
branch: '3.4',
cppflags: 'CPPFLAGS=-ansi'
}, {
branch: '3.0',
cppflags: 'CPPFLAGS=-ansi'
}
]
runs-on: ubuntu-latest
Expand Down
Loading
Loading