summaryrefslogtreecommitdiffstats
path: root/lib/libcrypto/ts
AgeCommit message (Collapse)AuthorFilesLines
2019-07-03snprintf/vsnprintf return < 0 on error, rather than -1.deraadt1-2/+2
2018-05-13Add const to the ASN1_OBJECT argument of TS_TST_INFO_get_ext_by_OBJ(3).tb2-4/+5
Should have been part of the previous commit. Omission noted by schwarze. tested in bulk build by sthen ok jsing
2018-05-13Add const qualifier to the ASN1_OBJ * argument oftb3-11/+11
TS_REQ_get_ext_by_OBJ(3), TS_REQ_set_policy_id(3), TS_RESP_CTX_add_policy(3), TS_RESP_CTX_set_def_policy(3), and TS_TST_INFO_get_ext_by_OBJ(3) tested in a bulk by sthen ok jsing
2018-04-14Make ENGINE_free() succeed on NULL. Matches OpenSSL's behavior andtb1-3/+2
simplifies the caller side. tested by & ok inoguchi; discussed with schwarze
2017-01-29Send the function codes from the error functions to the bit bucket,beck8-139/+81
as was done earlier in libssl. Thanks inoguchi@ for noticing libssl had more reacharounds into this. ok jsing@ inoguchi@
2016-12-27Remove all DECLARE_ASN1_SET_OF macro usage - since 2000 these have beenjsing1-4/+1
nothing but markers for utils/mkstack.pl... and we removed the code that generated more macros from these markers in 2014.
2016-11-05More X509_STORE_CTX_set_*() return value checks.miod1-2/+4
ok beck@ jsing@
2016-11-04Kill a bunch of OLD_ASN1 usage by replacing ASN1_{d2i,i2d}_* withjsing1-21/+17
ASN1_item_{d2i,i2d}_* equivalents. ok guenther@ miod@
2016-03-11X509_free(3) is NULL-safe, so remove NULL checks before its calls.mmcc1-3/+2
ok doug@
2015-09-30Replace M_ASN1_GENERALIZEDTIME_(new|free) withjsing1-2/+2
ASN1_GENERALIZEDTIME_(new|free).
2015-09-10Replace remaining M_ASN1_STRING_* macros with calls to ASN1_STRING_*.jsing1-4/+4
This is not the same as the macro expansion, however the ASN1_STRING_* functions do match the macro expansions. ok doug@ miod@
2015-07-29Expand obsolete M_ASN1.*(cmp|dup|print|set) macros - no change in generatedjsing2-4/+4
assembly. ok bcook@
2015-07-24Expand ASN.1 template macros - the generated assembly only differs byjsing1-51/+341
changes to line numbers.
2015-07-19Verify ASN1 objects types before attempting to access them as a particularmiod1-1/+3
type. ok guenther@ doug@
2015-07-19Now that it is safe to invoke X509_STORE_CTX_cleanup() if X509_STORE_CTX_init()miod1-5/+11
fails, check its return value and correctly mop up after ourselves. ok beck@ doug@
2015-07-19Put explicit braces around assignment used in a conditional.miod1-2/+2
ok bcook@ doug@
2015-07-15Do not allow TS_check_signer_name() with signer == NULL frommiod1-1/+4
int_TS_RESP_verify_token(). Coverity CID 21710. Looking further, int_TS_RESP_verify_token() will only initialize signer to something non-NULL if TS_VFY_SIGNATURE is set in ctx->flags. But guess what? TS_REQ_to_TS_VERIFY_CTX() in ts/ts_verify_ctx.c, which is the TS_VERIFY_CTX constructor, explicitely clears this bit, with: ret->flags = TS_VFY_ALL_IMPRINT & ~(TS_VFY_TSA_NAME | TS_VFY_SIGNATURE); followed by more conditional flag clears. Of course, nothing prevents the user to fiddle with ctx->flags afterwards. This is exactly what ts.c in usr.bin/openssl does. This is gross, mistakes will happen. ok beck@
2015-02-11Enable building with -DOPENSSL_NO_DEPRECATED.doug1-1/+2
If you didn't enable deprecated code, there were missing err.h and bn.h includes. This commit allows building with or without deprecated code. This was not derived from an OpenSSL commit. However, they recently enabled OPENSSL_NO_DEPRECATED in git and fixed these header problems in a different way. Verified with clang that this only changes line numbers in the generated asm. ok miod@
2015-02-10Remove assert() or OPENSSL_assert() of pointers being non-NULL. The policymiod1-3/+1
for libraries in OpenBSD is to deliberately let NULL pointers cause a SIGSEGV. ok doug@ jsing@
2015-02-10Manually expand ASN1_ITEM_rptr macros that should have been expanded withjsing1-10/+10
the IMPLEMENT_ASN1_DUP_FUNCTION macro.
2015-02-10Expand the IMPLEMENT_ASN1_DUP_FUNCTION macro so that the code is visiblejsing1-10/+55
and functions can be readily located. Change has been scripted and the generated assembly only differs by changes to line numbers. Discussed with beck@ miod@ tedu@
2015-02-10Expand the IMPLEMENT_ASN1_FUNCTIONS_{const,fname,name} macros so that thejsing1-10/+226
code is visible and functions can be readily located. Change has been scripted and the generated assembly only differs by changes to line numbers. Discussed with beck@ miod@ tedu@
2014-10-28Check the result of sk_*_push() operations for failure.miod1-3/+8
ok doug@ jsing@
2014-07-12if (x) FOO_free(x) -> FOO_free(x).miod1-3/+2
Improves readability, keeps the code smaller so that it is warmer in your cache. review & ok deraadt@
2014-07-11Only import cryptlib.h in the four source files that actually need it.jsing9-30/+30
Remove the openssl public includes from cryptlib.h and add a small number of includes into the source files that actually need them. While here, also sort/group/tidy the includes. ok beck@ miod@
2014-07-10Explicitly include <openssl/opensslconf.h> in every file that referencesjsing4-4/+12
an OPENSSL_NO_* define. This avoids relying on something else pulling it in for us, plus it fixes several cases where the #ifndef OPENSSL_NO_XYZ is never going to do anything, since OPENSSL_NO_XYZ will never defined, due to the fact that opensslconf.h has not been included. This also includes some miscellaneous sorting/tidying of headers.
2014-07-10Stop including standard headers via cryptlib.h - pull in the headers thatjsing4-6/+14
are needed in the source files that actually require them. ok beck@ miod@
2014-07-09cast ASN1_STRING (unsigned char *) to match strlcat's argument (char *)bcook1-2/+2
ok beck@
2014-06-12tags as requested by miod and teduderaadt12-12/+12
2014-06-07malloc() result does not need a cast.deraadt1-1/+1
ok miod
2014-05-31Get the public headers from the official place with <openssl/ >deraadt2-2/+2
from Brent Cook
2014-05-30Don't write out more than we have allocated in obj_txt, as the glorybeck1-1/+2
that is OBJ_obj2txt() can return a larger value.. ok tedu@
2014-05-29Everything sane has stdio, and FILE *. we don't need ifdefs for this.beck1-8/+0
ok to firebomb from tedu@
2014-05-27Fix a Y2038 problem, by conversion of long to time_t.deraadt2-18/+8
The TS_RESP_CTX_set_time_cb() API gets removed. Nothing in the greater ecosystem ever calls it. This API needs to be removed, because if anyone ever calls on a BE 32 system assuming long rather than time_t, it will be dangerously incompatible. ok miod guenther
2014-05-25calloc instead of malloc/memset. from Benjamin Baiertedu2-6/+4
2014-05-22Hello? Yes, you're speaking with OPENSSL_SYS_UNIX.jsing1-28/+0
ok beck@ miod@
2014-04-28Remove WIN32, WIN64 and MINGW32 tentacles.miod1-5/+0
Also check for _LP64 rather than __arch64__ (the former being more reliable than __LP64__ or __arch64__) to tell 64-bit int platforms apart from 32-bit int platforms. Loosely based upon a diff from Martijn van Duren on tech@
2014-04-27Put explicit (void) in function declarations and shuffle keywords in somemiod1-1/+1
declaration to pass -Wextra, should we want to add it to CFLAGS. No binary change.
2014-04-26Replace all use of ERR_add_error_data with ERR_asprintf_error_data.beck2-7/+7
This avoids a lot of ugly gymnastics to do snprintfs before sending the bag of strings to ERR, and eliminates at least one place in dso_dlfctn.c where it was being called with the incorrect number of arguments and using random things off the stack as addresses of strings. ok krw@, jsing@
2014-04-21KNF.jsing12-1456/+1607
2014-04-20Restore tedu's rev 1.4: snprintf() was reviewed.guenther1-1/+1
2014-04-20reset imprint to NULL to avoid double free. from mancha1 at zohotedu1-0/+1
2014-04-19We'll interpret a (void) cast on snprintf() to mean it's been verified thatguenther1-1/+1
truncation is either desirable, not an issue, or is detected and handled later ok deraadt@
2014-04-17Change library to use intrinsic memory allocation functions instead ofbeck4-15/+15
OPENSSL_foo wrappers. This changes: OPENSSL_malloc->malloc OPENSSL_free->free OPENSSL_relloc->realloc OPENSSL_freeFunc->free
2014-04-16Clean up dangerous strncpy use. This included a use where the resultingbeck1-9/+5
string was potentially not nul terminated and a place where malloc return was unchecked. while we're at it remove dummytest.c ok miod@
2014-04-16Zero-pad usec format to handle values less than 100,000 correctlyguenther1-1/+1
ok matthew@ tedu@
2014-04-16Mandatory Surgeon Guenther's Warning: This code could not possibly betedu1-24/+24
correct because it doesn't zerofill the front of usecs, but that's the way I found it. a more thorough emulation of the old code, but with fewer whacky snprintf pointer arithmetic antics. ok beck guenther
2014-04-16revert. the full horror has only now revealed itself.tedu1-26/+21
2014-04-16replace some bio_snprintf crazy with regular snprintf.tedu1-21/+26
beck had a diff to convert to strftime, but it's easier to verify this is functionally the same. ok beck.
2014-04-15we don't use these files for buildingtedu1-86/+0