Krzysztof Stachowiak
28485d0a01
Improve comments style
2018-04-10 13:36:43 +02:00
Krzysztof Stachowiak
99fb6e9461
Remove a redundant test
2018-04-10 13:36:00 +02:00
Krzysztof Stachowiak
57e1a9fdfc
Add buffer size check before cert_type_len read
2018-04-10 13:35:09 +02:00
Krzysztof Stachowiak
8fc134fcb1
Update change log
2018-04-05 08:51:35 +02:00
Krzysztof Stachowiak
0ac812f5ce
Adjust 2.1 specific code to match the buffer verification tests
2018-04-05 08:50:20 +02:00
Krzysztof Stachowiak
444678ea8b
Add a missing buffer size check
2018-04-04 15:41:07 +02:00
Krzysztof Stachowiak
f8ba5cf8e9
Correct buffer size check
...
Further in the code the next field from the binary buffer is read. The
check contained an off by one error.
2018-04-04 14:36:20 +02:00
Gilles Peskine
225684015d
Merge remote-tracking branch 'upstream-public/pr/1501' into mbedtls-2.1-proposed
2018-04-01 12:41:33 +02:00
Gilles Peskine
8b1cddcf26
Merge remote-tracking branch 'upstream-public/pr/1542' into mbedtls-2.1-proposed
2018-04-01 12:41:00 +02:00
Gilles Peskine
dea12c25cb
Merge branch 'pr_1544' into mbedtls-2.1-proposed
2018-04-01 12:36:10 +02:00
Gilles Peskine
419e670702
Minor changelog improvement
2018-04-01 12:33:35 +02:00
Andrzej Kurek
a1149a70ae
Add tests for "return plaintext data faster on unpadded decryption"
2018-03-30 05:00:19 -04:00
Andrzej Kurek
944adb9f4f
return plaintext data faster on unpadded decryption
2018-03-30 04:58:13 -04:00
Darryl Green
093c170377
Improve documentation of mbedtls_ssl_write()
2018-03-29 16:56:09 +01:00
Jaeden Amero
cbe731c653
Merge remote-tracking branch 'upstream-public/pr/1532' into mbedtls-2.1-proposed
2018-03-29 11:03:17 +01:00
Jaeden Amero
82e288adb6
Merge remote-tracking branch 'upstream-public/pr/1494' into mbedtls-2.1-proposed
2018-03-29 10:59:43 +01:00
Jaeden Amero
d58f697472
Merge remote-tracking branch 'upstream-public/pr/1493' into mbedtls-2.1-proposed
...
Fixes #504 and fixes #1057 for the 2.1 branch
2018-03-29 10:54:08 +01:00
Jaeden Amero
616485854e
Merge remote-tracking branch 'upstream-public/pr/1469' into mbedtls-2.1-proposed
2018-03-28 15:36:01 +01:00
Jaeden Amero
478baecc06
Merge remote-tracking branch 'upstream-public/pr/1525' into mbedtls-2.1-proposed
2018-03-28 15:34:25 +01:00
Ivan Krylov
1110a6fa63
Add ChangeLog entry
2018-03-28 17:25:12 +03:00
Ivan Krylov
c501f9cbb9
mbedtls_net_bind: ip_len can be NULL if client_ip is null
2018-03-28 17:21:54 +03:00
Jaeden Amero
8b4cd26eaf
Merge remote-tracking branch 'upstream-public/pr/1481' into mbedtls-2.1-proposed
2018-03-28 13:44:28 +01:00
Jaeden Amero
7eaea0b12b
Merge remote-tracking branch 'upstream-public/pr/1527' into mbedtls-2.1-proposed
...
Fixes #1299 , fixes #1475 for the 2.1 branch
2018-03-28 12:51:23 +01:00
Gilles Peskine
f362b97415
Add ChangeLog entry
...
Fixes #1299 . Fixes #1475 .
2018-03-27 23:22:37 +02:00
Deomid Ryabkov
e42510305f
Fix some test deps
...
* Cert revocation tests require `MBEDTLS_HAVE_TIME_DATE`.
* Verison features tests require... well, `MBEDTLS_VERSION_FEATURES`, actually.
Fixes https://github.com/ARMmbed/mbedtls/issues/1475
2018-03-27 23:22:34 +02:00
Andres Amaya Garcia
47569d7384
Add ChangeLog entry for PBES2 when ASN1 disabled
2018-03-27 21:34:15 +01:00
Andres Amaya Garcia
748ddda494
Fix test dependencies of pkcs5 pbs2 on asn1 parse
2018-03-27 21:33:07 +01:00
Andres Amaya Garcia
624b557e56
Fix coding style in pkcs5.c preprocessor directives
2018-03-27 21:33:05 +01:00
Marcos Del Sol Vives
a3ee13d199
Compile PBES2 in PKCS5 only if ASN1 is enabled
2018-03-27 21:33:02 +01:00
Andres Amaya Garcia
aa3ff98b1d
Fix shared library lookup on Mac OS X when running tests
2018-03-27 20:08:04 +01:00
Andres Amaya Garcia
9b2c5b7202
Make DLEXT var configurable in programs and tests makefiles
2018-03-27 20:08:03 +01:00
Andres Amaya Garcia
bc00667a90
Improve ChangeLog for DLEXT and AR_DASH changes
2018-03-27 20:07:52 +01:00
Andres Amaya Garcia
83bffd353e
Add ChangeLog entry for library/makefile changes
2018-03-26 00:15:21 +01:00
Andres Amaya Garcia
b3ac0ff722
Allow overriding ar param prefix in library/Makefile
2018-03-26 00:12:55 +01:00
Andres Amaya Garcia
23e520143d
Make DLEXT var configurable in library/Makefile
2018-03-26 00:12:53 +01:00
Jaeden Amero
f8270e30d9
Merge remote-tracking branch 'upstream-restricted/pr/457' into mbedtls-2.1
2018-03-23 11:16:30 +00:00
Gilles Peskine
d888bd2c65
Add changelog entries for improved testing
...
Fixes #1040
2018-03-23 02:29:49 +01:00
Gilles Peskine
9a05d1a765
Add missing dependencies in test_suite_x509parse
...
Found by depends-hashes.pl and depends-pkgalgs.pl.
2018-03-23 02:29:02 +01:00
Gilles Peskine
a19316965d
all.sh --keep-going: properly handle multiple-builds scripts
...
In keep-going mode, if a multiple-builds script fails, record its
status and keep going.
2018-03-23 02:29:00 +01:00
Gilles Peskine
2a74061198
Merge tag 'mbedtls-2.1.11' into iotssl-1381-x509-verify-refactor-2.1-restricted
...
Conflict resolution:
* ChangeLog
* tests/data_files/Makefile: concurrent additions, order irrelevant
* tests/data_files/test-ca.opensslconf: concurrent additions, order irrelevant
* tests/scripts/all.sh: one comment change conflicted with a code
addition. In addition some of the additions in the
iotssl-1381-x509-verify-refactor-restricted branch need support for
keep-going mode, this will be added in a subsequent commit.
2018-03-23 02:28:33 +01:00
Jethro Beekman
1a886ff45f
Fix parsing of PKCS#8 encoded Elliptic Curve keys.
...
The relevant ASN.1 definitions for a PKCS#8 encoded Elliptic Curve key are:
PrivateKeyInfo ::= SEQUENCE {
version Version,
privateKeyAlgorithm PrivateKeyAlgorithmIdentifier,
privateKey PrivateKey,
attributes [0] IMPLICIT Attributes OPTIONAL
}
AlgorithmIdentifier ::= SEQUENCE {
algorithm OBJECT IDENTIFIER,
parameters ANY DEFINED BY algorithm OPTIONAL
}
ECParameters ::= CHOICE {
namedCurve OBJECT IDENTIFIER
-- implicitCurve NULL
-- specifiedCurve SpecifiedECDomain
}
ECPrivateKey ::= SEQUENCE {
version INTEGER { ecPrivkeyVer1(1) } (ecPrivkeyVer1),
privateKey OCTET STRING,
parameters [0] ECParameters {{ NamedCurve }} OPTIONAL,
publicKey [1] BIT STRING OPTIONAL
}
Because of the two optional fields, there are 4 possible variants that need to
be parsed: no optional fields, only parameters, only public key, and both
optional fields. Previously mbedTLS was unable to parse keys with "only
parameters". Also, only "only public key" was tested. There was a test for "no
optional fields", but it was labelled incorrectly as SEC.1 and not run because
of a great renaming mixup.
2018-03-22 18:03:30 -07:00
Andres Amaya Garcia
387ff07157
Make matching more robbust in generate_errors.pl
2018-03-22 15:46:22 +01:00
Andres Amaya Garcia
8936ffe66a
Ensure that only .h files are parsed in generate_errors.pl
2018-03-22 15:46:21 +01:00
Andres Amaya Garcia
4a91c1a0b5
Change generate_errors.pl to call perl grep
...
Change the script generate_errors.pl to call the grep function in Perl
instead of calling the external tool grep directly as this causes
problems when ANSI escape sequences are included in the grep output
string.
2018-03-22 15:46:16 +01:00
Andres Amaya Garcia
2a0aee3163
Add ChangeLog entry for redundant mutex initialization optimizations
2018-03-21 17:40:48 +00:00
Gergely Budai
0a91973e4b
Do not define and initialize global mutexes on configurations that do not use them.
2018-03-21 15:32:47 +00:00
Paul Bakker
3d72b5d688
Add end guard comment
2018-03-21 15:29:35 +00:00
Embedthis Software
d641260987
Fix single threaded builds
2018-03-21 15:29:01 +00:00
Andres Amaya Garcia
09d787f2fc
Add ChangeLog entry for dylib builds using Makefile
2018-03-21 11:24:32 +00:00
Mitsuhiro Nakamura
e00964d9a7
Fix dylib linking
2018-03-21 11:21:59 +00:00