List of issues:
1: The certificate time check is not considered an error if there is no callback return value of 0 at the lower level.
2: Some comment issues.
3: The provider initialization is not protected by a lock.
4: Some functions lack parameter checks.
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1471
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Add timestamp entropy startup auto-tests and related SDV coverage, preserve seed DRBG lock and rand fallback across provider/libctx teardown, and fix detached CMS streaming verification without signedAttrs while aligning key checks and build dependencies.
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1451
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
1. The IdentityHint parsed from ParseServerIdentityHint does not have a \0 terminator
2. ConsumeHandshakeMessage` does not perform length verification when reading the message after the header
3. There is a problem with the implementation of HITLS_SESS_Decode. The first parameter passed is an output parameter
4. When retransmitting the ccs voyage message in REC_RetransmitListFlush, if the call to REC_DeActiveOutdatedWriteState(ctx) to switch states fails before ccs
5. Descriptions of store ownership need to be added for HITLS_SetCertStore, HITLS_SetChainStore, and HITLS_SetVerifyStore
6. The header file HITLS_CFG_SetSessionCacheSize lacks a description of the behavior when cachesize is set to 0
7. When there is only a cookie and no keyshare in the hrr, the generation of keyshare fails when sending the second clienthello
Signed-off-by: balabala-123 <guozhang4@huawei.com>
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1448
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
add node-based BSL list helpers and migrate shared-list readers off curr-mutating macros
precompute DN UTF-8 during parse and reuse cached values in X.509 compare/verify
clean up app UIO ownership handling and expand PKI/TLS regression coverage
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: hanzhiyang<hanzhiyang4@h-partners.com>
# message auto-generated for no-merge-commit merge:
!961 merge main into main
fix:Code optimization and refactoring
Created-by: hanzhiyang
Commit-by: hanzhiyang
Merged-by: liwei3013
Description: <!-- Thanks for sending a pull request! Here are some tips for you:
1) If this is your first time, please read our contributor guidelines: https://gitcode.com/openHiTLS/openhitls/wiki/FAQ-社区需求贡献流程.md
-->
**What does this PR do / why do we need it**:
**Self-checklist**:(**请自检,在[ ]内打上x**)
+ - [ ] **测试**:PR中的代码是否已有UT/ST测试用例进行充分的覆盖,新增测试用例是否随本PR一并上库或已经上库
+ - [ ] **接口**:是否涉及对外接口变更,相应变更已得到接口评审组织的通过,API对应的注释信息已经刷新正确
+ - [ ] **文档**:是否涉及官网文档修改,如果涉及请及时提交资料到Doc仓
<!-- **Special notes for your reviewers**: -->
<!-- + - [ ] 是否导致无法前向兼容 -->
<!-- + - [ ] 是否涉及依赖的三方库变更 -->
See merge request: openHiTLS/openhitls!961
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: Tom<yanxu52@huawei.com>
# message auto-generated for no-merge-commit merge:
!886 merge feature/support-frodoKEM into main
feat: support Mceliece and Frodokem algorithms
Created-by: m0_69551548
Commit-by: Tom
Merged-by: liwei3013
Description: feat: support Mceliece and Frodokem PQC algorithms
See merge request: openHiTLS/openhitls!886
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: xuzhengyi<xuzhengyi1@h-partners.com>
# message auto-generated for no-merge-commit merge:
!877 merge FIX_BUG into main
Random number interface call specification check
Created-by: libiaoliang
Commit-by: xuzhengyi
Merged-by: liwei3013
Description: Random number interface call specification check
See merge request: openHiTLS/openhitls!877
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
**Core Platform Support:**
- Add Darwin/macOS platform detection and conditional compilation
- Implement platform-specific library extensions (.dylib for macOS, .so for Linux)
- Enhanced dynamic library loading with cross-platform error handling
- Platform-optimized time functions (clock_gettime_nsec_np for macOS)
- Add App module support for Darwin/macOS
**Threading & Synchronization:**
- BSL: Migrate from simple integer flags to proper pthread_once_t implementation
- Add BSL_SAL_OnceControl type with platform-specific implementations
- Implement thread-safe one-time initialization across platforms
- Fix memory initialization patterns for thread-once controls
**Build System Improvements:**
- Remove GNU ld-specific flags for test-framework use c function pointer replace or `stub_utils.h` to hook target function
- Boundcheck components will linked as static library for tests, reduce tests dynamic library deps
- Update CMake configurations for Darwin support
**Test Framework Enhancements:**
- Replace jmp_buf with sigjmp_buf for better signal handling
- Update time handling to avoid platform-specific gmtime issues
- Improve entropy test stability across platforms
- Add proper RAND initialization/deinitialization
**Entropy & Cryptographic Updates:**
- Temporarily disable CPU jitter entropy on macOS (pending validation)
- Add cross-platform entropy source management
- Update DRBG configuration for improved compatibility
- Enhance hardware entropy detection and handling
**Network & I/O:**
- Extend POSIX network functions to support both Linux and Darwin
- Add file accessibility checks before dynamic loading
- Improve error handling for symbol resolution across platforms
- Update socket and I/O operations for cross-platform compatibility
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/677
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
- Implement the generic HCTR block cipher mode of operation.
- Utilize universal hashing based on GF(128) multiplication for data integrity.
- Employ a CTR-like mechanism for confidentiality using the underlying block cipher (ECB mode).
- Support key splitting (K1, K2) and tweak (TW) as required by HCTR.
- Provide a specific implementation wrapper for SM4-HCTR.
- Include internal buffering to handle data streams via Update/Final.
Related to #41
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/395
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Major Features:
- Multi-compiler/linker configuration system with toolchain support
- Auto-manage Secure C (libboundscheck) dependency
- Dynamic provider library names for CMVP modes (ISO19790, SM)
- macOS/Darwin platform support with unified POSIX abstractions
- Cross-platform build improvements and optimizations
Build System:
- Add toolchain management for cross-compilation
- Support nested 'common' format in compile config
- with _EXTRA/_REMOVE/_OVERRIDE in common flags, we can add remove by
per compiler
- Unify toolchain naming convention (arch-vendor-os-abi-compiler)
Platform Support:
- Unify Linux and Darwin sources under POSIX
- Add Darwin support for SAL and build flags
- Add Darwin support for REC wrapper functions (WIP)
- Cross-platform ops count macros for benchmarking
- Platform-specific library extension detection (.dylib vs .so)
Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/652
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: balabala-123<guozhang4@huawei.com>
# message auto-generated for no-merge-commit merge:
merge fixbug into main
fix:Fix client not disabling tlcp version in tls_all
Created-by: balabala-123
Commit-by: balabala-123
Merged-by: liwei3013
Description: fix:Fix client not disabling tlcp version in tls_all
See merge request: openHiTLS/openhitls!594
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: baoyi84930<zhangcheng170@huawei.com>
# message auto-generated for no-merge-commit merge:
merge dev into main
fix: fix some issue
Created-by: baoyi84930
Commit-by: baoyi84930
Merged-by: liwei3013
Description: fix: fix some issue
See merge request: openHiTLS/openhitls!457
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: Ooohui<zhanghui160@huawei.com>
# message auto-generated for no-merge-commit merge:
!960 merge openhitls-0.2 into openhitls-0.2
feat: Support curve nistp192 and setting/getting generic extension
Created-by: Ooohui
Commit-by: Ooohui
Merged-by: liwei3013
Description: <!-- Thanks for sending a pull request! Here are some tips for you:
1) If this is your first time, please read our contributor guidelines: https://gitcode.com/openHiTLS/openhitls/wiki/FAQ-社区需求贡献流程.md
-->
**What does this PR do / why do we need it**:
**Self-checklist**:(**请自检,在[ ]内打上x**)
+ - [ ] **测试**:PR中的代码是否已有UT/ST测试用例进行充分的覆盖,新增测试用例是否随本PR一并上库或已经上库
+ - [ ] **接口**:是否涉及对外接口变更,相应变更已得到接口评审组织的通过,API对应的注释信息已经刷新正确
+ - [ ] **文档**:是否涉及官网文档修改,如果涉及请及时提交资料到Doc仓
<!-- **Special notes for your reviewers**: -->
<!-- + - [ ] 是否导致无法前向兼容 -->
<!-- + - [ ] 是否涉及依赖的三方库变更 -->
See merge request: openHiTLS/openhitls!960
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: pi_ixeL<xuzhewei2@huawei.com>
# message auto-generated for no-merge-commit merge:
!793 merge 0.2_fix into openhitls-0.2
fix: Correct argument order in SAL_NET_SockAddrCopy function
Created-by: pi_ixeL
Commit-by: pi_ixeL
Merged-by: liwei3013
Description: fix: Correct argument order in SAL_NET_SockAddrCopy function
See merge request: openHiTLS/openhitls!793
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: balabala-123<guozhang4@huawei.com>
# message auto-generated for no-merge-commit merge:
merge openhitls-0.2 into openhitls-0.2
fix:Change the function parameter type to bool*
Created-by: balabala-123
Commit-by: balabala-123
Merged-by: liwei3013
Description: fix:Change the function parameter type to bool*
See merge request: openHiTLS/openhitls!609
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>
Co-authored-by: hanzhiyang<hanzhiyang4@h-partners.com>
# message auto-generated for no-merge-commit merge:
merge openhitls-0.2 into openhitls-0.2
fix:Get the result of the pthread_join function
Created-by: hanzhiyang
Commit-by: hanzhiyang
Merged-by: liwei3013
Description: fix:Get the result of the pthread_join function
See merge request: openHiTLS/openhitls!610
Signed-off-by: Dongjianwei001 <dongjianwei1@huawei.com>