Age | Commit message (Collapse) | Author | |
---|---|---|---|
2014-05-30 | More KNF. | Joel Sing | |
2014-05-30 | remove some #if 0 code. we don't need any more reminders that we're using | Ted Unangst | |
a not quite appropriate data structure. ok jsing | |||
2014-05-30 | Make use of SSL_IS_DTLS, SSL_USE_EXPLICIT_IV, SSL_USE_SIGALGS and | Joel Sing | |
SSL_USE_TLS1_2_CIPHERS. Largely based on OpenSSL head. | |||
2014-05-30 | SBus glue for qlw(4) for sparc. Untested. | Mark Kettenis | |
2014-05-30 | SBus glue for qlw(4) for sparc. Untested. | Mark Kettenis | |
2014-05-30 | Eliminate some duplicated "mfctl cr29, rN" instructions. | Mark Kettenis | |
ok jsing@ | |||
2014-05-30 | Set cold to 1 before executing the DVACT_POWERDOWN handlers when halting or | Martin Pieuchot | |
rebooting a machine, like it is done in the hibernate case. At least some USB host controller drivers rely on this to busy way instead of sleeping. Avoid a panic on macppc with an uhci(4) cardbus plugged in. ok deraadt@, uebayashi@ | |||
2014-05-30 | Remove unused fields from the pipes. | Martin Pieuchot | |
2014-05-30 | Fix some more nasty stringyness in here by using asprintf instead of cruft. | Bob Beck | |
gets rid of the second last use of the awful DECIMAL_SIZE. | |||
2008-09-06 | import of OpenSSL 0.9.8h | Damien Miller | |
2014-05-30 | Appletalk support was removed a while ago. So was natm and hylink (if ever). | Philip Guenther | |
Let's mention MPLS instead. Noted by Remi Locherer (remi.locherer (at) relo.ch) | |||
2014-05-30 | AF_NATM support was removed before 5.5 | Philip Guenther | |
2014-05-30 | more: no need to null check before free; ok guenther | Theo de Raadt | |
2014-05-30 | more: no need for null check before free | Theo de Raadt | |
ok tedu guenther | |||
2014-05-30 | While working on another diff I ended up looking to see why on earth the | Joel Sing | |
DTLS code had a chunk that checked to see if the SSL version was *not* DTLS. Turns out that this is inside a big #if 0 block with a comment explaining why DTLS will never need this code... The DTLS code was clearly written by wholesale copying the SSLv3 code. Any code not applicable to DTLS was seemingly #if 0'd or commented out and left for others to find. d1_pkt.c is copied from s3_pkt.c and it has a do_dtls1_write() function that has the same function signature as do_ssl3_write(), except that the create_empty_fragement (yes, that is the spelling in ssl_locl.h) argument is unused for DTLS (although there is code that pretends to use it) since it uses explicit IV (as the comment notes). Instead of leaving this turd lying around, nuke the #if 0'd code (along with the check for *not* DTLS) and remove the pointless create_empty_fragment argument given the only two do_dtls1_write() calls specify zero. This kind of thing also makes you wonder how much actual peer review occurred before the code was initially committed... ok beck@ | |||
2014-05-30 | Use calloc instead of malloc and memset. | YASUOKA Masahiko | |
from Benjamin Baier | |||
2014-05-30 | Rework parse_name() so that variable declaration is separate from function | Joel Sing | |
based initialisation, use more readable variable names and use a goto rather than duplicating the frees for the error and non-error paths... ok beck@ | |||
2014-05-30 | Add definitions for Process and (finally!) Thread | Philip Guenther | |
Tweak some error descriptions based on that Completely reword ETXTBSY description based on a suggestion from millert@ tweaks and oks jmc@ millert@ sobrado@ | |||
2014-05-30 | A program is the thing you run; a process is an instance of something | Philip Guenther | |
running ok millert@ sobrado@ | |||
2014-05-30 | remove CONST_STRICT. ok beck deraadt | Ted Unangst | |
2014-05-30 | no need for null check before free. from Brendan MacDonell | Ted Unangst | |
2014-05-30 | Don't write out more than we have allocated in obj_txt, as the glory | Bob Beck | |
that is OBJ_obj2txt() can return a larger value.. ok tedu@ | |||
2014-05-30 | remove some of the bigger lies, as applicable to libressl. | Ted Unangst | |
2014-05-30 | explicit_bzero for clearing stack variables. | Ted Unangst | |
2014-05-29 | I do not have time to describe how bad the realloc() uses in here, now | Theo de Raadt | |
being relaced by reallocarray(). you will have to look at the diff. there can be no explanations for the extra casts. as beck says, "Don't go towards the light theo!" ok beck tedu | |||
2014-05-29 | trivial realloc -> reallocarray | Theo de Raadt | |
2014-05-29 | the comment says RAND_pseudo_bytes should be RAND_bytes. make it so. | Ted Unangst | |
ok deraadt | |||
2014-05-29 | we no longer care that these aren't used for ssl2 | Ted Unangst | |
2014-05-29 | ok, next pass after review: when possible, put the reallocarray arguments | Theo de Raadt | |
in the "size_t nmemb, size_t size" | |||
2014-05-29 | convert 53 malloc(a*b) to reallocarray(NULL, a, b). that is 53 | Theo de Raadt | |
potential integer overflows easily changed into an allocation return of NULL, with errno nicely set if need be. checks for an allocations returning NULL are commonplace, or if the object is dereferenced (quite normal) will result in a nice fault which can be detected & repaired properly. ok tedu | |||
2014-05-29 | Use the same convention for mixer control names as azalia. | Alexandre Ratchov | |
2014-05-29 | sync | Theo de Raadt | |
2014-05-29 | Everything sane has stdio, and FILE *. we don't need ifdefs for this. | Bob Beck | |
ok to firebomb from tedu@ | |||
2014-05-29 | remove back compat that was already disabled back in 1998. | Ted Unangst | |
from Alexander Schrijver | |||
2014-05-29 | Make make includes work again without kssl.h | Bob Beck | |
2014-05-29 | Any sane platform has stdio. Stop pretending we will ever use a platform | Bob Beck | |
that does not. "fire bomb" tedu@ | |||
2014-05-29 | kssl is dead. | Ted Unangst | |
2014-05-29 | no space before label | Ted Unangst | |
2014-05-29 | line up else better | Ted Unangst | |
2014-05-29 | define -DLIBRESSL_INTERNAL in here so we don't use nasties | Bob Beck | |
ok deraadt@ | |||
2014-05-29 | consistent braces | Ted Unangst | |
2014-05-29 | unidef DH, ECDH, and ECDSA. there's no purpose to a libssl without them. | Ted Unangst | |
ok deraadt jsing | |||
2014-05-29 | repair KNF indent | Theo de Raadt | |
2010-10-01 | import OpenSSL-1.0.0a | Damien Miller | |
2014-05-29 | use calloc, from Benjamin Baier | Ted Unangst | |
2014-05-29 | use calloc, from Benjamin Baier | Ted Unangst | |
2014-05-29 | use calloc, from Benjamin Baier | Ted Unangst | |
2014-05-29 | use calloc, from Benjamin Baier | Ted Unangst | |
2014-05-29 | Make it substantially easier to identify protocol version requirements | Joel Sing | |
by adding an enc_flags field to the ssl3_enc_method, specifying four flags that are used with this field and providing macros for evaluating these conditions. Currently the version requirements are identified by continually checking the version number and other criteria. This change also adds separate SSL3_ENC_METHOD data for TLS v1.1 and v1.2, since they have different enc_flags from TLS v1. Based on changes in OpenSSL head. No objection from miod@ | |||
2014-05-29 | When you have functions that perform specific functions, use them. | Joel Sing | |
EVP_CIPHER_CTX_free() does a NULL check, then calls EVP_CIPHER_CTX_cleanup() and frees the memory. COMP_CTX_free() also had its own NULL check, so there is no point in duplicating that here. ok beck@ |