21 Commits

Author SHA1 Message Date
code4lala 78da00405e openssl-3.0.9.tar.gz
Signed-off-by: code4lala <fengziteng2@huawei.com>
2023-11-16 16:27:34 +08:00
code4lala f7de6b0b2f rm openssl 3.0.7
Signed-off-by: code4lala <fengziteng2@huawei.com>
2023-11-16 16:27:24 +08:00
code4lala 393e3604f5 tar -xf openssl-openssl-3.0.7.tar.gz
Signed-off-by: code4lala <fengziteng2@huawei.com>
2023-04-12 11:12:14 +08:00
code4lala 05d2ef44d1 rm all
Signed-off-by: code4lala <fengziteng2@huawei.com>
2023-04-12 11:12:06 +08:00
HJ 0b759159b9 huangjun42@huawei.com
Signed-off-by: HJ <huangjun42@huawei.com>
2021-08-10 16:32:34 +08:00
h00416433 ab6439910d Merge branch 'upstream/OpenSSL_1_1_1f' into hj20200529
Conflicts:
	CHANGES
	CONTRIBUTING
	Configurations/50-win-onecore.conf
	Configurations/90-team.norelease.conf
	Configurations/unix-Makefile.tmpl
	Configure
	NEWS
	NOTES.ANDROID
	README
	apps/rehash.c
	apps/s_cb.c
	apps/s_server.c
	apps/speed.c
	config
	crypto/aes/asm/aes-s390x.pl
	crypto/aes/asm/aesni-x86_64.pl
	crypto/aes/asm/aesp8-ppc.pl
	crypto/aes/asm/aesv8-armx.pl
	crypto/aes/asm/vpaes-armv8.pl
	crypto/aes/asm/vpaes-x86_64.pl
	crypto/asn1/charmap.h
	crypto/asn1/x_bignum.c
	crypto/bio/b_addr.c
	crypto/bio/bss_file.c
	crypto/bn/asm/armv8-mont.pl
	crypto/bn/asm/mips.pl
	crypto/bn/asm/ppc.pl
	crypto/bn/asm/rsaz-avx2.pl
	crypto/bn/asm/rsaz-x86_64.pl
	crypto/bn/asm/x86_64-mont5.pl
	crypto/bn/bn_local.h
	crypto/bn/bn_prime.c
	crypto/bn/bn_prime.h
	crypto/chacha/asm/chacha-armv8.pl
	crypto/cms/cms_att.c
	crypto/conf/conf_def.h
	crypto/conf/conf_lib.c
	crypto/dh/dh_gen.c
	crypto/dso/dso_dlfcn.c
	crypto/ec/asm/ecp_nistz256-armv8.pl
	crypto/ec/asm/ecp_nistz256-sparcv9.pl
	crypto/ec/asm/ecp_nistz256-x86_64.pl
	crypto/ec/asm/x25519-ppc64.pl
	crypto/ec/ec_asn1.c
	crypto/ec/ec_local.h
	crypto/ec/ecp_nistp224.c
	crypto/ec/ecp_nistp256.c
	crypto/ec/ecp_nistp521.c
	crypto/ec/ecp_nistz256.c
	crypto/ec/ecx_meth.c
	crypto/engine/eng_openssl.c
	crypto/err/err.c
	crypto/err/openssl.txt
	crypto/evp/e_aes.c
	crypto/evp/evp_err.c
	crypto/hmac/hmac.c
	crypto/modes/asm/ghash-x86_64.pl
	crypto/objects/obj_dat.h
	crypto/objects/obj_xref.h
	crypto/perlasm/x86_64-xlate.pl
	crypto/poly1305/asm/poly1305-armv8.pl
	crypto/ppccpuid.pl
	crypto/rand/drbg_lib.c
	crypto/rand/rand_err.c
	crypto/rand/rand_lib.c
	crypto/rand/rand_local.h
	crypto/rand/rand_unix.c
	crypto/rand/rand_vms.c
	crypto/rsa/rsa_ossl.c
	crypto/rsa/rsa_pk1.c
	crypto/rsa/rsa_pmeth.c
	crypto/rsa/rsa_ssl.c
	crypto/sha/asm/keccak1600-armv4.pl
	crypto/sha/asm/keccak1600-armv8.pl
	crypto/sha/asm/sha512-armv8.pl
	crypto/sha/asm/sha512-sparcv9.pl
	crypto/threads_none.c
	crypto/threads_win.c
	crypto/x509/x509_cmp.c
	crypto/x509/x509_vfy.c
	crypto/x509/x_crl.c
	crypto/x509v3/v3_purp.c
	doc/HOWTO/proxy_certificates.txt
	doc/man1/enc.pod
	doc/man1/s_client.pod
	doc/man1/x509.pod
	doc/man3/BN_generate_prime.pod
	doc/man3/CRYPTO_memcmp.pod
	doc/man3/EC_GROUP_copy.pod
	doc/man3/EVP_DigestSignInit.pod
	doc/man3/EVP_DigestVerifyInit.pod
	doc/man3/EVP_PKEY_new.pod
	doc/man3/EVP_SignInit.pod
	doc/man3/OPENSSL_malloc.pod
	doc/man3/RAND_bytes.pod
	doc/man3/RAND_set_rand_method.pod
	doc/man3/RSA_get0_key.pod
	doc/man3/SSL_SESSION_get0_hostname.pod
	doc/man3/SSL_get_error.pod
	doc/man3/X509_LOOKUP_meth_new.pod
	doc/man3/X509_STORE_add_cert.pod
	doc/man3/X509_cmp.pod
	doc/man3/X509_get_extension_flags.pod
	doc/man3/d2i_X509.pod
	doc/man5/config.pod
	doc/man7/Ed25519.pod
	doc/man7/X25519.pod
	e_os.h
	engines/e_afalg.c
	include/crypto/dso_conf.h.in
	include/internal/constant_time.h
	include/openssl/bio.h
	include/openssl/evperr.h
	include/openssl/lhash.h
	include/openssl/obj_mac.h
	include/openssl/opensslv.h
	include/openssl/randerr.h
	include/openssl/sslerr.h
	krb5
	ssl/record/rec_layer_s3.c
	ssl/s3_lib.c
	ssl/ssl_lib.c
	ssl/ssl_local.h
	ssl/statem/extensions.c
	ssl/statem/extensions_srvr.c
	ssl/statem/statem_lib.c
	ssl/statem/statem_srvr.c
	ssl/t1_lib.c
	ssl/tls13_enc.c
	test/bio_memleak_test.c
	test/bntest.c
	test/build.info
	test/certs/root-cert-rsa2.pem
	test/certs/server-pss-restrict-cert.pem
	test/certs/server-pss-restrict-key.pem
	test/certs/setup.sh
	test/dtlstest.c
	test/ec_internal_test.c
	test/ecdsatest.h
	test/ectest.c
	test/evp_extra_test.c
	test/recipes/02-test_errstr.t
	test/recipes/03-test_internal_ec.t
	test/recipes/30-test_evp_data/evpccmcavs.txt
	test/recipes/80-test_cms_data/bad_signtime_attr.cms
	test/recipes/80-test_cms_data/ct_multiple_attr.cms
	test/recipes/80-test_cms_data/no_ct_attr.cms
	test/recipes/80-test_cms_data/no_md_attr.cms
	test/recipes/90-test_bio_memleak.t
	test/recipes/90-test_includes_data/includes-eq-ws.cnf
	test/recipes/90-test_includes_data/includes-eq.cnf
	test/shlibloadtest.c
	test/ssl-tests/29-dtls-sctp-label-bug.conf
	test/ssl-tests/29-dtls-sctp-label-bug.conf.in
	test/sslapitest.c
	test/testutil.h
	test/testutil/random.c
	util/cavs-to-evptest.pl
	util/libcrypto.num
	util/perl/OpenSSL/Test.pm
	util/perl/TLSProxy/CertificateRequest.pm

Change-Id: I388e77b9fc937720aaf18841949f5f954ef2131b
2020-06-16 09:25:29 +08:00
h00416433 cf46376e29 TicketNo:AR000DI992
Description:openssl 1.1.1d used bu libhapverify
Team:OTHERS
Feature or Bugfix:Feature
Binary Source:Yes, it is
PrivateCode(Yes/No):No

Change-Id: I8968f9c0f146b587da17a3e603bd04fb7b4c505b
Reviewed-on: http://mgit-tm.rnd.huawei.com/7842784
Tested-by: public jenkins <public_jenkins@notesmail.huawei.com>
Reviewed-by: houyuezhou 00386575 <hou@huawei.com>
Reviewed-by: linyibin 00246405 <linyibin@huawei.com>
Reviewed-by: weiping 00548480 <ping.wei@huawei.com>
2020-02-27 13:52:11 +08:00
z00416851 68b4f9db72 TicketNo:AR000D76VD
Description:openssl开源社区安全补丁
Team:EMUI
Feature or Bugfix:Feature
Binary Source:NA
PrivateCode(Yes/No):No

Change-Id: Ia942e70461a3a5337de001ab0f40604776fe8f91
Reviewed-on: http://mgit-tm.rnd.huawei.com/6664137
Tested-by: public jenkins <public_jenkins@notesmail.huawei.com>
Reviewed-by: yanglijun 00294367 <yanglijun@huawei.com>
Reviewed-by: luomeiling 00216346 <luomeiling@huawei.com>
Reviewed-by: shenchunlong 00356424 <shenchunlong@huawei.com>
2019-11-08 15:44:13 +08:00
Dr. Matthias St. Pierre fbbfd128c9 Fix header file include guard names
Make the include guards consistent by renaming them systematically according
to the naming conventions below

The public header files (in the 'include/openssl' directory) are not changed
in 1.1.1, because it is a stable release.

For the private header files files, the guard names try to match the path
specified in the include directives, with all letters converted to upper case
and '/' and '.' replaced by '_'. An extra 'OSSL_' is added as prefix.

Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/9681)
2019-09-27 23:58:12 +02:00
Dr. Matthias St. Pierre 1b0fe00e27 drbg: ensure fork-safety without using a pthread_atfork handler
When the new OpenSSL CSPRNG was introduced in version 1.1.1,
it was announced in the release notes that it would be fork-safe,
which the old CSPRNG hadn't been.

The fork-safety was implemented using a fork count, which was
incremented by a pthread_atfork handler. Initially, this handler
was enabled by default. Unfortunately, the default behaviour
had to be changed for other reasons in commit b5319bdbd0, so
the new OpenSSL CSPRNG failed to keep its promise.

This commit restores the fork-safety using a different approach.
It replaces the fork count by a fork id, which coincides with
the process id on UNIX-like operating systems and is zero on other
operating systems. It is used to detect when an automatic reseed
after a fork is necessary.

To prevent a future regression, it also adds a test to verify that
the child reseeds after fork.

CVE-2019-1549

Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/9802)
2019-09-09 17:09:06 +01:00
Matt Caswell 72a7a7021f Update copyright year
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/8347)
2019-02-26 14:05:09 +00:00
Bernd Edlinger b6769a3865 PPC: Try out if mftb works before using it
If this fails try out if mfspr268 works.

Use OPENSSL_ppccap=0x20 for enabling mftb,
OPENSSL_ppccap=0x40 for enabling mfspr268,
and OPENSSL_ppccap=0 for enabling neither.

Fixes #8012

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/8043)

(cherry picked from commit c8f370485c43729db44b680e41e875ddd7f3108c)
2019-01-21 15:45:53 +01:00
Pauli 79c2c74130 Use secure_getenv(3) when available.
Change all calls to getenv() inside libcrypto to use a new wrapper function
that use secure_getenv() if available and an issetugid then getenv if not.

CPU processor override flags are unchanged.

Extra checks for OPENSSL_issetugid() have been removed in favour of the
safe getenv.

Reviewed-by: Bernd Edlinger <bernd.edlinger@hotmail.de>
(Merged from https://github.com/openssl/openssl/pull/7047)

(cherry picked from commit 5c39a55d04ea6e6f734b627a050b9e702788d50d)
2018-09-24 11:22:22 +10:00
Andy Polyakov ceb8e32cbc crypto/dllmain.c: remove unused OPENSSL_NONPIC_relocated variable.
Reviewed-by: Kurt Roeckx <kurt@roeckx.be>
(Merged from https://github.com/openssl/openssl/pull/6752)
2018-07-25 16:37:31 +02:00
Nicola Tuveri 34446a8524 Remove __cplusplus preamble from internal headers
These headers are internal and never exposed to a cpp compiler, hence no
need for the preamble.

Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Rich Salz <rsalz@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Matthias St. Pierre <Matthias.St.Pierre@ncp-e.com>
(Merged from https://github.com/openssl/openssl/pull/6554)
2018-06-22 12:24:59 +02:00
Pauli 360fc9f412 Make OPENSSL_rdtsc universally available.
If such a timer/counter register is not available, the return value is always
zero.  This matches the assembly implementations' behaviour.

Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Matthias St. Pierre <Matthias.St.Pierre@ncp-e.com>
(Merged from https://github.com/openssl/openssl/pull/5231)
2018-02-07 10:08:15 +10:00
Kurt Roeckx d807db26a4 Create a prototype for OPENSSL_rdtsc
Switch to make it return an uint32_t instead of the various different
types it returns now.

Fixes: #3125

Reviewed-by: Andy Polyakov <appro@openssl.org>
GH: #4757
2017-11-25 14:30:11 +01:00
Rich Salz 0e598a3d18 Add CRYPTO_get_alloc_counts.
Use atomic operations for the counters
Rename malloc_lock to memdbg_lock
Also fix some style errors in mem_dbg.c

Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/4359)
2017-10-12 22:04:12 -04:00
Pauli 198c42f5af Move OPENSSL_CONF from e_os.h to cryptlib.h
Reviewed-by: Andy Polyakov <appro@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4188)
2017-08-30 07:20:44 +10:00
Pauli 677963e5a4 e_os.h removal from other headers and source files.
Removed e_os.h from all bar three headers (apps/apps.h crypto/bio/bio_lcl.h and
ssl/ssl_locl.h).

Added e_os.h into the files that need it now.

Directly reference internal/nelem.h when required.

Reviewed-by: Andy Polyakov <appro@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4188)
2017-08-30 07:20:43 +10:00
Matt Caswell 67dc995eaf Move ossl_assert
Move the definition of ossl_assert() out of e_os.h which is intended for OS
specific things. Instead it is moved into internal/cryptlib.h.

This also changes the definition to remove the (int) cast.

Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4073)
2017-08-03 10:48:00 +01:00