]> git.ipfire.org Git - thirdparty/curl.git/log
thirdparty/curl.git
18 months agoci: update nghttp2/nghttp2 to v1.62.0
renovate[bot] [Tue, 14 May 2024 22:25:54 +0000 (22:25 +0000)] 
ci: update nghttp2/nghttp2 to v1.62.0

Closes #13650

18 months agoci: update ngtcp2/nghttp3 to v1.3.0
renovate[bot] [Tue, 14 May 2024 22:26:02 +0000 (22:26 +0000)] 
ci: update ngtcp2/nghttp3 to v1.3.0

Closes #13651

18 months agoci: update ngtcp2/ngtcp2 to v1.5.0
renovate[bot] [Tue, 14 May 2024 22:26:08 +0000 (22:26 +0000)] 
ci: update ngtcp2/ngtcp2 to v1.5.0

Closes #13652

18 months agoci: handle git submodules for mbedTLS
Max Dymond [Tue, 14 May 2024 09:02:30 +0000 (10:02 +0100)] 
ci: handle git submodules for mbedTLS

18 months agoci: reconfigure renovate
Max Dymond [Tue, 14 May 2024 08:57:03 +0000 (09:57 +0100)] 
ci: reconfigure renovate

- set prefix for github actions updates to be gha:
- set prefix for other renovate actions to be ci:
- disable debian updates in linux-old.yml

18 months agotidy-up: whitespace [ci skip]
Viktor Szakats [Tue, 14 May 2024 14:49:47 +0000 (16:49 +0200)] 
tidy-up: whitespace [ci skip]

18 months agowarnless: delete orphan declarations
Viktor Szakats [Tue, 14 May 2024 12:39:11 +0000 (14:39 +0200)] 
warnless: delete orphan declarations

Follow-up to 358f7e757781857c4b498a68634726609fa3884a #11932
Closes #13639

18 months agoBUG-BOUNTY.md: clarify the third party situation
Daniel Stenberg [Wed, 8 May 2024 09:45:37 +0000 (11:45 +0200)] 
BUG-BOUNTY.md: clarify the third party situation

We do not pay bounties for problems in other libraries.

Closes #13560

18 months agohttp tests: in CI skip test_02_23* for quiche
Stefan Eissing [Tue, 14 May 2024 10:32:09 +0000 (12:32 +0200)] 
http tests: in CI skip test_02_23* for quiche

For unknown reasons, these tests fail in CI often, but run fine locally.
Skip them in CI to avoid unrelated PRs to have failures.

Closes #13638

18 months agohsts: explicitly skip blank lines
Daniel Gustafsson [Tue, 14 May 2024 08:19:41 +0000 (10:19 +0200)] 
hsts: explicitly skip blank lines

Keep blank lines or lines containing only whitespace to make it all
the way to the more expensive sscanf call in hsts_add.

Closes: #13603
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
18 months agoautotools: Only probe for SGI MIPS compilers on IRIX
Daniel Gustafsson [Tue, 14 May 2024 08:04:27 +0000 (10:04 +0200)] 
autotools: Only probe for SGI MIPS compilers on IRIX

MIPSPro and the predecessor compiler which was part of the IDO (IRIS
Development Option) were only ever shipped on the SGI IRIX operating
system (with MIPSPro on 6.0+ which was released in 1994).  Limit the
autoconf check to IRIX when probing for these compilers to save some
cycles on other platforms.

Closes: #13611
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
18 months agotests: fix test 1167 to skip digit-only symbols
Viktor Szakats [Mon, 13 May 2024 20:45:56 +0000 (22:45 +0200)] 
tests: fix test 1167 to skip digit-only symbols

This avoids mistaking symbols with their numeric value when using
certain C preprocessors which output these numeric values at the
beginning of the line as part of an expression.

Seen on OpenBSD 7.5 + clang.

Example `test1167.pl -v` output, before this patch:
```
Source: cpp /home/runner/work/curl/curl/tests/../include/curl/curl.h
Symbol: 20000
Line #3835:   20000 +  142,
[...]
Bad symbols in public header files:
   20000
   [...]
```
Ref: https://github.com/curl/curl/actions/runs/9069136530/job/24918015357#step:3:7513

Ref: #13583
Closes #13634

18 months agolib: call Curl_strntolower instead of doing crafted loops
Daniel Stenberg [Mon, 13 May 2024 21:11:46 +0000 (23:11 +0200)] 
lib: call Curl_strntolower instead of doing crafted loops

Closes #13627

18 months agosetopt: acknowledge errors proper for CURLOPT_COOKIEJAR
Daniel Stenberg [Mon, 13 May 2024 15:31:44 +0000 (17:31 +0200)] 
setopt: acknowledge errors proper for CURLOPT_COOKIEJAR

Error out on error, do not continue.

Closes #13624

18 months agovtls: remove duplicate assign
Daniel Stenberg [Mon, 13 May 2024 18:00:23 +0000 (20:00 +0200)] 
vtls: remove duplicate assign

Curl_ssl_peer_cleanup() already clears the ->sni field, no point in
assigning it again.

Spotted by CodeSonar

Closes #13626

18 months agoGroup all non-major updates together to reduce PR spam
Max Dymond [Mon, 13 May 2024 15:20:34 +0000 (16:20 +0100)] 
Group all non-major updates together to reduce PR spam

18 months agoAdd the remainder of the workflows
Max Dymond [Mon, 13 May 2024 15:15:18 +0000 (16:15 +0100)] 
Add the remainder of the workflows

18 months agoAdd some basic versioning for some workflows to check whether this is detected properly
Max Dymond [Mon, 13 May 2024 14:45:30 +0000 (15:45 +0100)] 
Add some basic versioning for some workflows to check whether this is detected properly

18 months agoAdd renovate.json
renovate[bot] [Mon, 13 May 2024 13:54:50 +0000 (13:54 +0000)] 
Add renovate.json

18 months agovauth: make two functions void that always just returned OK
Daniel Stenberg [Mon, 13 May 2024 15:21:54 +0000 (17:21 +0200)] 
vauth: make two functions void that always just returned OK

Removes the need to check return values when they can never fail.

Pointed out by CodeSonar

Closes #13621

18 months agosetopt: remove check for 'option' that is always true
Daniel Stenberg [Mon, 13 May 2024 14:25:12 +0000 (16:25 +0200)] 
setopt: remove check for 'option' that is always true

- make sure that passing in option set to NULL clears the fields
  correctly

- remove the weird second take if Curl_parse_login_details() returns
  error

Follow-up to 7333faf00bf25db7cd1e0012d6b140

Spotted by CodeSonar

Closes #13619

18 months agotests: tidy up types in server code
Viktor Szakats [Sun, 12 May 2024 19:14:06 +0000 (21:14 +0200)] 
tests: tidy up types in server code

Cherry-picked from #13489
Closes #13610

18 months agosetopt: make the setstropt_userpwd args compulsory
Daniel Stenberg [Sun, 12 May 2024 14:52:51 +0000 (16:52 +0200)] 
setopt: make the setstropt_userpwd args compulsory

They were always used so no point in allowing them to be optional.

follow-up to 0e37b42dc956bd8a

Closes #13608
Reviewed-by: Daniel Gustafsson
18 months agoRELEASE-NOTES: synced
Daniel Stenberg [Mon, 13 May 2024 07:48:25 +0000 (09:48 +0200)] 
RELEASE-NOTES: synced

18 months agowebsocket: Avoid memory leak in error path
Daniel Gustafsson [Mon, 13 May 2024 07:11:23 +0000 (09:11 +0200)] 
websocket: Avoid memory leak in error path

In the errorpath for randstr being too long to copy into the buffer
we leak the randstr when returning CURLE_FAILED_INIT.  Fix by using
an explicit free on randstr in the errorpath.

Closes: #13602
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
18 months agohsts: Remove single-use single-line function
Daniel Gustafsson [Mon, 13 May 2024 07:07:30 +0000 (09:07 +0200)] 
hsts: Remove single-use single-line function

The hsts_entry() function contains of a single line and is only
used in a single place in the code, so move the allocation into
hsts_create instead to improve code readability. C code usually
don't use the factory abstraction for object creation, and this
small example wasn't following our usual code style.

Closes: #13604
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
18 months agolib: bump hash sizes to `size_t`
Viktor Szakats [Sun, 5 May 2024 15:45:11 +0000 (17:45 +0200)] 
lib: bump hash sizes to `size_t`

Follow-up to cc907e80a2498c0599253271a6f657f614b52a4e #13502
Cherry-picked from #13489
Closes #13601

18 months agotests: make the unit test result type `CURLcode`
Viktor Szakats [Sat, 11 May 2024 19:36:05 +0000 (21:36 +0200)] 
tests: make the unit test result type `CURLcode`

Before this patch, the result code was a mixture of `int` and
`CURLcode`.

Also adjust casts and fix a couple of minor issues found along the way.

Cherry-picked from #13489
Closes #13600

18 months agoappveyor: tidy-ups
Viktor Szakats [Sat, 11 May 2024 13:34:12 +0000 (15:34 +0200)] 
appveyor: tidy-ups

- delete a duplicate line.
- simplify a `make` call.
- merge two `if` branches.
- reorder autotools options for clarity.
- add `--enable-warnings` where missing (it's also the default.)
- add empty lines to YAML for readability.
- use lowercase install prefix/directory.

Closes #13598

18 months agodocs/cmdline-opts: mention STARTTLS for --ssl and --ssl-reqd
Daniel Stenberg [Fri, 10 May 2024 21:30:06 +0000 (23:30 +0200)] 
docs/cmdline-opts: mention STARTTLS for --ssl and --ssl-reqd

... since users might look for those terms in the manpage.

Closes #13590

18 months agosetopt: warn on Curl_set*opt() uses not using the return value
Daniel Stenberg [Fri, 10 May 2024 21:50:58 +0000 (23:50 +0200)] 
setopt: warn on Curl_set*opt() uses not using the return value

And switch the invokes that would "set" NULL to instead just plainly
free the pointer, as those were otherwise the invokes that would ignore
the return code. And possibly confuse static code analyzers.

Closes #13591

18 months agoautotools: delete unused functions
Orgad Shaneh [Sun, 12 May 2024 05:45:11 +0000 (08:45 +0300)] 
autotools: delete unused functions

Closes #13605

18 months agoexamples: fix/silence `-Wsign-conversion`
Viktor Szakats [Sat, 27 Apr 2024 19:09:01 +0000 (21:09 +0200)] 
examples: fix/silence `-Wsign-conversion`

- extend `FD_SET()` hack to all platforms (was only Cygwin).
  Warnings may also happen in other envs, e.g. OmniOS.
  Ref: https://github.com/libssh2/libssh2/actions/runs/8854199687/job/24316762831#step:3:2021

- tidy-up `CURLcode` vs `int` use.

- cast an unsigned to `long` before passing to `curl_easy_setopt()`.

Cherry-picked from #13489
Follow-up to 3829759bd042c03225ae862062560f568ba1a231 #12489
Closes #13501

18 months agocmake: fix `HAVE_IOCTLSOCKET_FIONBIO` test with gcc 14
Orgad Shaneh [Fri, 10 May 2024 10:13:32 +0000 (13:13 +0300)] 
cmake: fix `HAVE_IOCTLSOCKET_FIONBIO` test with gcc 14

The function signature has had u_long flags since ever. This is how it
is defined in the documentation, and implemented in MinGW.

The code that uses ioctlsocket in nonblock.c also has unsigned long.

Error:
CurlTests.c:275:41: error: passing argument 3 of 'ioctlsocket' from incompatible pointer type [-Wincompatible-pointer-types]
  275 |         if(0 != ioctlsocket(0, FIONBIO, &flags))
      |                                         ^~~~~~
      |                                         |
      |                                         int *
In file included from CurlTests.c:266:
/opt/mxe/usr/i686-w64-mingw32.static/include/winsock2.h:1007:76: note: expected 'u_long *' {aka 'long unsigned int *'} but argument is of type 'int *'
 1007 |   WINSOCK_API_LINKAGE int WSAAPI ioctlsocket(SOCKET s,__LONG32 cmd,u_long *argp);
      |                                                                    ~~~~~~~~^~~~

Closes #13578

18 months agoftp: fix build for CURL_DISABLE_VERBOSE_STRINGS
Jay Satiro [Fri, 10 May 2024 23:14:29 +0000 (19:14 -0400)] 
ftp: fix build for CURL_DISABLE_VERBOSE_STRINGS

This is a follow-up to b7c7dffe which changed the FTP state change
verbose debug text (aka infof) to tracing debug text (aka trc).

Prior to this change if libcurl was without DEBUGBUILD and built with
CURL_DISABLE_VERBOSE_STRINGS (ie --disable-verbose) the build would
error.

Caught by Circle CI job openssl-no-verbose.

18 months agolib: clear the easy handle's saved errno before transfer
Jay Satiro [Fri, 10 May 2024 07:19:16 +0000 (03:19 -0400)] 
lib: clear the easy handle's saved errno before transfer

- Clear data->state.os_errno before transfer.

- Explain the change in behavior in the CURLINFO_OS_ERRNO doc.

- Add to the CURLINFO_OS_ERRNO doc the list of libcurl network-related
  errors that may cause the errno to be saved.

data->state.os_errno is saved before libcurl returns a network-related
failure such as connection failure. It is accessible to the user via
CURLINFO_OS_ERRNO so they can get more information about the failure.

Prior to this change it wasn't cleared before transfer, so if a user
retrieved the saved errno it could be from a previous transfer. That is
because an errno is not always saved for network-related errors.

Closes https://github.com/curl/curl/pull/13574

18 months agoftp: add tracing support
Stefan Eissing [Fri, 10 May 2024 10:59:12 +0000 (12:59 +0200)] 
ftp: add tracing support

- add `Curl_trc_feat_ftp` for tracing via trace config
- add macro CURL_TRC_FTP(data, fmt, ...)
- replace DEBUGF(infof()) statements in ftp.c by CURL_TRC_FTP()
- always trace FTP connection state

Closes #13580

18 months agohttp: remove redundant check
Daniel Stenberg [Fri, 10 May 2024 12:33:34 +0000 (14:33 +0200)] 
http: remove redundant check

Spotted by CodeSonar

Closes #13582

18 months agoldap: fix unused variables (seen on OmniOS)
Viktor Szakats [Fri, 10 May 2024 15:03:26 +0000 (17:03 +0200)] 
ldap: fix unused variables (seen on OmniOS)

```
../../lib/ldap.c: In function 'ldap_do':
  ../../lib/ldap.c:380:11: error: unused variable 'ldap_ca' [-Werror=unused-variable]
    380 |     char *ldap_ca = conn->ssl_config.CAfile;
        |           ^~~~~~~
  ../../lib/ldap.c:379:9: error: unused variable 'ldap_option' [-Werror=unused-variable]
    379 |     int ldap_option;
        |         ^~~~~~~~~~~
```
Ref: https://github.com/curl/curl/actions/runs/9033564377/job/24824192730#step:3:6059

Ref: #13583
Closes #13588

18 months agourl: make parse_login_details use memdup0
Daniel Stenberg [Fri, 10 May 2024 13:32:57 +0000 (15:32 +0200)] 
url: make parse_login_details use memdup0

Also make the user and password arguments mandatory, since all code
paths in libcurl used them anyway.

Adapted unit test case 1620 to the new rules.

Closes #13584

18 months agodigest: replace strcpy for empty string with simple assignment
Orgad Shaneh [Fri, 10 May 2024 15:08:25 +0000 (18:08 +0300)] 
digest: replace strcpy for empty string with simple assignment

Closes #13586

18 months agoautotools: fix `HAVE_IOCTLSOCKET_FIONBIO` test for gcc 14
Viktor Szakats [Fri, 10 May 2024 16:01:22 +0000 (18:01 +0200)] 
autotools: fix `HAVE_IOCTLSOCKET_FIONBIO` test for gcc 14

```
conftest.c:152:41: error: passing argument 3 of 'ioctlsocket' from incompatible pointer type [-Wincompatible-pointer-types]
  152 |         if(0 != ioctlsocket(0, FIONBIO, &flags))
      |                                         ^~~~~~
      |                                         |
      |                                         int *
```

Reported-by: LigH
Fixes #13579
Closes #13587

18 months agoCI: ignore test 286 on Appveyor gcc 7 build
Viktor Szakats [Fri, 10 May 2024 07:49:57 +0000 (09:49 +0200)] 
CI: ignore test 286 on Appveyor gcc 7 build

Disabled earlier for gcc 9 builds. gcc 7 uses the same runner and
prone to similar intermittent failures.

Follow-up to f1e05a6e6e7225fa09952abb2c935ae1abe44f45 #12106 #12040
Closes #13575

18 months agocf-socket: don't try getting local IP without socket
Daniel Stenberg [Fri, 10 May 2024 08:52:58 +0000 (10:52 +0200)] 
cf-socket: don't try getting local IP without socket

In cf_tcp_connect(), it might fail and not get a socket assigned to
ctx->sock but set_local_ip() is still called which would make
getsockname() get invoked with a negative file desriptor and fail.

By adding this check, set_local_ip() will now instead blank out the
fields correctly.

Spotted by CodeSonar

Closes #13577

18 months agotool_getparam: remove two redundant conditions
Daniel Stenberg [Fri, 10 May 2024 08:24:15 +0000 (10:24 +0200)] 
tool_getparam: remove two redundant conditions

When getstr() does not return error, it returns a valid pointer.

Spotted by CodeSonar

Closes #13576

18 months agoquiche: trust its timeout handling
Stefan Eissing [Fri, 10 May 2024 12:01:20 +0000 (14:01 +0200)] 
quiche: trust its timeout handling

- set the idle timeout transport parameter
  in milliseconds as documented by quiche
- do not calculate the idle timeout, rely on
  quiche handling it

Closes #13581

18 months agodmaketgz: accept a SOURCE_DATE_EPOCH as an second argument
Daniel Stenberg [Fri, 10 May 2024 06:50:47 +0000 (08:50 +0200)] 
dmaketgz: accept a SOURCE_DATE_EPOCH as an second argument

to make it easier to reproduce a tarball

Closes #13573

18 months agoRELEASE-NOTES: synced
Daniel Stenberg [Fri, 10 May 2024 07:33:26 +0000 (09:33 +0200)] 
RELEASE-NOTES: synced

18 months agoh3/ngtcp2: improve error handling
Stefan Eissing [Wed, 8 May 2024 11:44:35 +0000 (13:44 +0200)] 
h3/ngtcp2: improve error handling

- identify ngtcp2 and nghttp3 error codes that are fatal
- close quic connection on fatal errors
- refuse further filter operations once connection is closed
- confusion about the nghttp3 API. We should close the QUIC stream on
  cancel and not use the nghttp3 calls intended to be invoked when the
  QUIC stream was closed by the peer.

Closes #13562

18 months agodocs: fix some CURLINFO examples
Jay Satiro [Wed, 8 May 2024 07:37:12 +0000 (03:37 -0400)] 
docs: fix some CURLINFO examples

- improve getinfo result check for example sections:
  CURLINFO_ACTIVESOCKET, CURLINFO_LASTSOCKET, CURLINFO_SSL_VERIFYRESULT,
  CURLINFO_PROXY_SSL_VERIFYRESULT

- fix getinfo result check for example sections:
  CURLINFO_NUM_CONNECTS, CURLINFO_OS_ERRNO

- fix verify result check for example sections:
  CURLINFO_PROXY_SSL_VERIFYRESULT

Bug: https://github.com/curl/curl/discussions/13557#discussion-6625507
Reported-by: farazrbx@users.noreply.github.com
Closes https://github.com/curl/curl/pull/13559

18 months agoKNOWN_BUGS: gssapi library name + version is missing in curl_version_info()
Daniel Stenberg [Thu, 9 May 2024 09:24:07 +0000 (11:24 +0200)] 
KNOWN_BUGS: gssapi library name + version is missing in curl_version_info()

Closes #13492
Closes #13570

18 months agokrb5: use dynbuf
Daniel Stenberg [Wed, 8 May 2024 13:20:23 +0000 (15:20 +0200)] 
krb5: use dynbuf

Closes #13568

18 months agomanagen: fix the option sort order
Daniel Stenberg [Wed, 8 May 2024 21:50:55 +0000 (23:50 +0200)] 
managen: fix the option sort order

... it used to strip off the .d file extension to sort correctly but
ever since the extension changed to .md the operation failed and the
sort got wrong.

Follow-up to 2494b8dd5175cee7f2e

Closes #13567

18 months agoGHA: repair the linux-old job
Stefan Eissing [Wed, 8 May 2024 13:39:06 +0000 (15:39 +0200)] 
GHA: repair the linux-old job

package libc6_2.28-10+deb10u2_amd64.deb changed to
libc6_2.28-10+deb10u3_amd64.deb

Closes #13564

18 months agoappveyor: make gcc 6 mingw64 job build-only
Viktor Szakats [Wed, 8 May 2024 17:43:07 +0000 (19:43 +0200)] 
appveyor: make gcc 6 mingw64 job build-only

This job has proven to be the flakiest of all, and it's also the oldest
Windows runner we had tests running on: 'Visual Studio 2015', that is
running on Windows Server 2012 R2:
  https://www.appveyor.com/docs/windows-images-software/

Turn off tests on this job to help stabilizing CI runs.

This was also one of the slowest running job amongst the AppVeyor CI ones.

Flakiness data:
  https://testclutch.curl.se/static/reports/summary.html
Entries:
  Appveyor / CMake, mingw-w64, gcc 6, Debug, x86, Schannel, Static, no-unity (curl) [current]
  Appveyor / CMake, mingw-w64, gcc 6, Debug, x86, Schannel, Static (curl) [former]

Closes #13566

18 months agounit2604: use alloc instead of overlong string const
Stefan Eissing [Wed, 8 May 2024 13:32:28 +0000 (15:32 +0200)] 
unit2604: use alloc instead of overlong string const

Closes #13563

19 months agobufq: remove duplicate word in comment
Daniel Gustafsson [Wed, 8 May 2024 17:12:03 +0000 (19:12 +0200)] 
bufq: remove duplicate word in comment

Inspired by 13552.

Closes: #13554
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
19 months agolib/cf-h1-proxy: silence compiler warnings (gcc 14)
Viktor Szakats [Tue, 7 May 2024 15:50:42 +0000 (17:50 +0200)] 
lib/cf-h1-proxy: silence compiler warnings (gcc 14)

They came up ealier with gcc 12 (Windows), but apparently gcc 14 is
still reporting them, also under Linux.

```
/home/runner/work/curl-for-win/curl-for-win/curl/lib/cf-h1-proxy.c: In function 'cf_h1_proxy_close':
/home/runner/work/curl-for-win/curl-for-win/curl/lib/cf-h1-proxy.c:1060:17: warning: null pointer dereference [-Wnull-dereference]
 1060 |   cf->connected = FALSE;
/home/runner/work/curl-for-win/curl-for-win/curl/lib/cf-h1-proxy.c:1061:8: warning: null pointer dereference [-Wnull-dereference]
 1061 |   if(cf->ctx) {
      |      ~~^~~~~
In function 'tunnel_free',
    inlined from 'cf_h1_proxy_destroy' at /home/runner/work/curl-for-win/curl-for-win/curl/lib/cf-h1-proxy.c:1053:3:
/home/runner/work/curl-for-win/curl-for-win/curl/lib/cf-h1-proxy.c:198:27: warning: null pointer dereference [-Wnull-dereference]
  198 |   struct h1_tunnel_state *ts = cf->ctx;
      |                           ^~
```
Ref: https://github.com/curl/curl-for-win/actions/runs/8985369476/job/24679219528#step:3:6320

Fixes #13237
Closes #13555

19 months agombedtls: support TLS 1.3
MAntoniak [Thu, 8 Feb 2024 20:12:49 +0000 (21:12 +0100)] 
mbedtls: support TLS 1.3

Closes #13539

19 months agoversion: use msnprintf instead of strncpy
Daniel Stenberg [Wed, 8 May 2024 06:41:28 +0000 (08:41 +0200)] 
version: use msnprintf instead of strncpy

- to ensure a terminating null byte
- to avoid zero-padding the target

debug code only

Closes #13549

19 months agocurl_path: make Curl_get_pathname use dynbuf
Daniel Stenberg [Tue, 7 May 2024 12:28:29 +0000 (14:28 +0200)] 
curl_path: make Curl_get_pathname use dynbuf

... instead of malloc and memcpy

- unit test 2604 verifies Curl_get_pathname()

Closes #13550

19 months agolib: make protocol handlers store scheme name lowercase
Daniel Stenberg [Tue, 7 May 2024 14:55:23 +0000 (16:55 +0200)] 
lib: make protocol handlers store scheme name lowercase

- saves a lowercase operation when the "[scheme]_proxy" name is
  generated
- appears less "shouting"
- update test 970, 972, 1438 and 1536

Closes #13553

19 months agolib: remove two instances of "only only" messages
Daniel Stenberg [Tue, 7 May 2024 14:25:37 +0000 (16:25 +0200)] 
lib: remove two instances of "only only" messages

Fixes #13551
Reported-by: Lucas Nussbaum
Closes #13552

19 months agoasyn-thread: fix curl_global_cleanup crash in Windows
Pavel P [Thu, 2 May 2024 04:15:44 +0000 (06:15 +0200)] 
asyn-thread: fix curl_global_cleanup crash in Windows

- Make sure that asynchronous resolves handled by Winsock are stopped
  before WSACleanup is called.

This is implemented by ensuring that when Curl_resolver_kill is called
(eg via multi_done) it will cancel the Winsock asynchronous resolve and
wait for the cancellation to complete. Winsock runs the asynchronous
completion routine immediately when a resolve is canceled.

Prior to this change it was possible that during curl_global_cleanup
"a DNS resolver thread created by GetAddrInfoExW did not terminate yet,
however curl is already shutting down, deinitializing Winsock with
WSACleanup() leading to an access violation."

Background:

If libcurl is built with the asynchronous threaded resolver option for
Windows then it resolves in one of two ways. For Windows 8.1 and later,
libcurl resolves by using the Winsock asynchronous resolver which does
its own thread management. For older versions of Windows, libcurl
resolves by creating a separate thread that calls getaddrinfo. This
change only affects the former and it's already handled for the latter.

Reported-by: Ch40zz@users.noreply.github.com
Fixes https://github.com/curl/curl/issues/13509
Closes https://github.com/curl/curl/pull/13518

19 months agoasyn-thread: fix Curl_thread_create result check
Jay Satiro [Mon, 6 May 2024 18:49:43 +0000 (14:49 -0400)] 
asyn-thread: fix Curl_thread_create result check

- Compare to curl_thread_t_null instead of 0 for error.

Currently for both supported thread libraries (pthreads and Windows)
curl_thread_t_null is defined as 0. However, the pattern throughout the
code is to check against curl_thread_t_null and not 0 since for
posterity some thread library may not use 0 for error.

Closes https://github.com/curl/curl/pull/13542

19 months agocurl_multibyte: remove access() function wrapper for Windows
Jay Satiro [Fri, 3 May 2024 23:31:00 +0000 (19:31 -0400)] 
curl_multibyte: remove access() function wrapper for Windows

- Remove curlx_win32_access() which was a wrapper to use access() in
  Windows.

This is a follow-up to 602fc213, one of two commits which removed
access() calls from the codebase and banned use of the function.

Closes https://github.com/curl/curl/pull/13529

19 months agotls: Remove EXAMPLEs from deprecated options
Daniel Gustafsson [Mon, 6 May 2024 18:55:27 +0000 (20:55 +0200)] 
tls: Remove EXAMPLEs from deprecated options

CURLOPT_EGDSOCKET and CURLOPT_RANDOM_FILE are both completely dead
so remove their example sections since the code there is useless.
There is still a way to inject a random file for OpenSSL older than
1.1.0 but it's not what the example showed (and it's not even done
with this option) so we refrain from documenting it here.

Closes: #13540
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
19 months agotests: Only require EXAMPLE for non-deprecated options
Daniel Gustafsson [Mon, 6 May 2024 18:55:00 +0000 (20:55 +0200)] 
tests: Only require EXAMPLE for non-deprecated options

Manpages which document deprecated CURLOPT_ or CURLINFO_ are not
required to have an EXAMPLE section since they might effectively
be dead no-ops which we don't want to trick users into believing
they can use by copying example code.

Closes: #13540
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
19 months agoEXPERIMENTAL: add graduation requirements for each feature
Daniel Stenberg [Mon, 6 May 2024 12:02:31 +0000 (14:02 +0200)] 
EXPERIMENTAL: add graduation requirements for each feature

Starting now, experimental features should have a set of documentated
requirements of what is needed for the feature to graduate.

This adds requirements to all existing experiments.

Closes #13541

19 months agomisc: fix typos, quoting and spelling
Ivan [Mon, 6 May 2024 08:35:53 +0000 (10:35 +0200)] 
misc: fix typos, quoting and spelling

Fix wording of comments, and misquotings where `' is markdown parsed
where it shouldn't be, and remove a misspelled preprocessor comment
which really isn't needed (and removing it makes it match surrounding
code better).

Closes: #13538
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
19 months agotests: Mark tftpd timer function as noreturn
Daniel Gustafsson [Mon, 6 May 2024 07:51:16 +0000 (09:51 +0200)] 
tests: Mark tftpd timer function as noreturn

This avoids the below compiler warning:

tftpd.c:280:1: warning: function 'timer' could be declared with
    attribute 'noreturn' [-Wmissing-noreturn]

Closes: #13534
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
19 months agodoh: Remove unused function prototype
Daniel Gustafsson [Mon, 6 May 2024 07:50:37 +0000 (09:50 +0200)] 
doh: Remove unused function prototype

Closes: #13536
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
19 months agodoh: cleanups in ECH related functions
Daniel Stenberg [Fri, 3 May 2024 13:06:54 +0000 (15:06 +0200)] 
doh: cleanups in ECH related functions

- make local_decode_rdata_name use dynbuf instead of calloc + memcpy
- avoid extra memdup in local_decode_rdata_alpn
- no need to if() before free()
- use memdup instead of calloc + memcpy in Curl_doh_decode_httpsrr

Reviewed-by: Stephen Farrell
Closes #13526

19 months agolibssh2: delete redundant feature guard
Viktor Szakats [Sun, 5 May 2024 09:49:11 +0000 (11:49 +0200)] 
libssh2: delete redundant feature guard

Delete `HAVE_LIBSSH2_VERSION` (equivalent to
`LIBSSH2_VERSION_NUM` > 0x010100) guard surrounding
a `LIBSSH2_VERSION_NUM` > 0x010B00 one.

Reviewed-by: Daniel Gustafsson
Closes #13537

19 months agotool_cfgable: free {proxy_}cipher13_list on exit
Jan Venekamp [Sat, 4 May 2024 01:05:51 +0000 (03:05 +0200)] 
tool_cfgable: free {proxy_}cipher13_list on exit

Author: Jan Venekamp
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Closes: #13531
19 months agodoh: Fix typo in comment
RainRat [Sat, 4 May 2024 09:52:43 +0000 (11:52 +0200)] 
doh: Fix typo in comment

Closes: #13504
Author: RainRat on Github
Reviewed-by: Daniel Stenberg <daniel@haxx.se>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
19 months agodynbuf: Fix returncode on memory error
Christian Schmitz [Sat, 4 May 2024 09:44:02 +0000 (11:44 +0200)] 
dynbuf: Fix returncode on memory error

Curl_dyn_vaddf should return a proper error code in case allocating
memory failed.

Closes: #13533
Author: Christian Schmitz <support@monkeybreadsoftware.de>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
19 months agoRELEASE-NOTES: synced
Daniel Stenberg [Fri, 3 May 2024 12:39:39 +0000 (14:39 +0200)] 
RELEASE-NOTES: synced

19 months agobearssl: use common code for cipher suite lookup
Jan Venekamp [Wed, 24 Apr 2024 15:37:14 +0000 (17:37 +0200)] 
bearssl: use common code for cipher suite lookup

Take advantage of the Curl_cipher_suite_walk_str() and
Curl_cipher_suite_get_str() functions introduced in commit fba9afeb.

This also fixes CURLOPT_SSL_CIPHER_LIST not working at all for bearssl
due to commit ff74cef5.

Closes #13464

19 months agocurl.h: change CURL_SSLVERSION_* from enum to defines
Daniel Stenberg [Tue, 30 Apr 2024 21:11:59 +0000 (23:11 +0200)] 
curl.h: change CURL_SSLVERSION_* from enum to defines

C++20 and later compilers emit a deprecation warning if values from two
different enums are combined with a bitwise operation the way the
CURL_SSLVERSION_* values were previously created.

Reported-by: Michael Kaufmann
Fixes #13510
Closes #13511

19 months agoconfigure: error on missing perl if docs or manual is enabled
Daniel Stenberg [Wed, 1 May 2024 08:48:16 +0000 (10:48 +0200)] 
configure: error on missing perl if docs or manual is enabled

Fixes #13508
Reported-by: Harmen Stoppels
Closes #13514

19 months agotool_cb_rea: limit rate unpause for -T . uploads
Daniel Stenberg [Tue, 30 Apr 2024 09:07:28 +0000 (11:07 +0200)] 
tool_cb_rea: limit rate unpause for -T . uploads

To avoid getting stuck in a busy-loop when nothing is read from stdin,
this function now checks the call rate and might enforce a short sleep
when called repeatedly without uploading anything. It is a crude
work-around to avoid a 100% busy CPU.

Reported-by: magisterquis on hackerone
Fixes #13174
Closes #13506

19 months agoappveyor: enable websockets for VS2017 jobs
Viktor Szakats [Wed, 1 May 2024 08:20:58 +0000 (10:20 +0200)] 
appveyor: enable websockets for VS2017 jobs

Follow-up to eb4fe6c6340c3d5b0c347c6e30be004d4f9117d7 #13232
Closes #13513

19 months agoif2ip: make the buf_size arg a size_t
Daniel Stenberg [Tue, 30 Apr 2024 07:11:00 +0000 (09:11 +0200)] 
if2ip: make the buf_size arg a size_t

sizes should be size_t

Ref: #13489
Closes #13505

19 months agocf-https-connect: use timeouts as unsigned ints
Daniel Stenberg [Tue, 30 Apr 2024 06:56:53 +0000 (08:56 +0200)] 
cf-https-connect: use timeouts as unsigned ints

To match the type used in 'set.happy_eyeballs_timeout'.

Ref: #13489
Closes #13503

19 months agohash: change 'slots' to size_t from int
Daniel Stenberg [Tue, 30 Apr 2024 06:46:54 +0000 (08:46 +0200)] 
hash: change 'slots' to size_t from int

- an unsigned type makes more sense
- size_t seems suitable
- on 64 bit args, the struct alignment makes the new Curl_hash remain
  the same size

Closes #13502

19 months agolibssh2: replace `access()` with `stat()`
Viktor Szakats [Mon, 29 Apr 2024 11:49:03 +0000 (13:49 +0200)] 
libssh2: replace `access()` with `stat()`

Prefer `stat()` to verify the presence of key files.

This drops the last uses of `access()` in the codebase, which was
reported to cause issues in some cases.

Also add `access()` to the list of banned functions in checksrc.

Ref: https://github.com/curl/curl/pull/13412#issuecomment-2065505415
Ref: https://github.com/curl/curl/pull/13482#issuecomment-2078980522
Ref: #13497
Co-authored-by: Jay Satiro
Closes #13498

19 months agomulti: remove useless assignment
Daniel Stenberg [Mon, 29 Apr 2024 14:32:46 +0000 (16:32 +0200)] 
multi: remove useless assignment

Spotted by CodeSonar

Closes #13500

19 months agoRELEASE-NOTES: synced
Daniel Stenberg [Tue, 30 Apr 2024 07:08:57 +0000 (09:08 +0200)] 
RELEASE-NOTES: synced

19 months agocmake: FindNGHTTP2 add static lib name to find_library call
fuzzard [Mon, 29 Apr 2024 01:27:39 +0000 (11:27 +1000)] 
cmake: FindNGHTTP2 add static lib name to find_library call

Add the static library name, nghttp2_static as a name to search.

This provides cmake parity with the winbuild Makefile.vc allowing
the cmake build to find and allow the link to static nghttp2 library.

19 months agoDISTROS: add patch and issues link for curl-for-win
Viktor Szakats [Mon, 29 Apr 2024 12:08:38 +0000 (14:08 +0200)] 
DISTROS: add patch and issues link for curl-for-win

curl-for-win sometimes includes curl patches that were already merged in
master, but not yet part of a stable release.

Also include the Issues link. Build-specific issues are handled there.

Ref: #13493
Closes #13499

19 months agomime: avoid using access()
Daniel Stenberg [Mon, 29 Apr 2024 09:50:56 +0000 (11:50 +0200)] 
mime: avoid using access()

If stat() fails, there is no point in calling access()

Also: return error immediately if the stat() fails.

Ref: #13482
Closes #13497

19 months agotests: add SNI and peer name checks
Stefan Eissing [Fri, 26 Apr 2024 12:13:23 +0000 (14:13 +0200)] 
tests: add SNI and peer name checks

- connect to DNS names with trailing dot
- connect to DNS names with double trailing dot
- rustls, always give `peer->hostname` and let it
  figure out SNI itself
- add SNI tests for ip address and localhost
- document in code and TODO that QUIC with ngtcp2+wolfssl
  does not do proper peer verification of the certificate
- mbedtls, skip tests with ip address verification as not
  supported by the library

Closes #13486

19 months agocurl_getdate.md: document two-digit year handling
Daniel Stenberg [Sun, 28 Apr 2024 21:07:49 +0000 (23:07 +0200)] 
curl_getdate.md: document two-digit year handling

Mentioned-by: Paul Gilmartin
Ref: https://curl.se/mail/archive-2024-04/0014.html
Closes #13494

19 months agocmake: add `BUILD_EXAMPLES` option to build examples
Viktor Szakats [Sat, 27 Apr 2024 22:11:38 +0000 (00:11 +0200)] 
cmake: add `BUILD_EXAMPLES` option to build examples

You can enable it with `-DBUILD_EXAMPLES=ON`.

To match autotools' `make examples` feature.
Windows (static) builds not tested.

Also enable examples in a pair of CI jobs.

Apply related updates to the macOS CI workflow:
- drop unused `CXX` envs.
- drop no longer needed `-Wno-error=undef -Wno-error=conversion` flags.
- pass `-Wno-deprecated-declarations` to GCC too (for `BUILD_EXAMPLES`).
- document why `-Wno-deprecated-declarations` is necessary.

Closes #13491

19 months agohttp3: quiche+ngtcp2 improvements
Stefan Eissing [Thu, 25 Apr 2024 11:12:18 +0000 (13:12 +0200)] 
http3: quiche+ngtcp2 improvements

- quiche: error transfers that try to receive on a closed
  or draining connection
- ngtcp2: use callback for extending max bidi streams. This
  allows more precise calculation of MAX_CONCURRENT as we
  only can start a new stream when the server acknowledges
  the close - not when we locally have closed it.
- remove a fprintf() from h2-download client to avoid excess
  log files on tests timing out.

Closes #13475

19 months agovtls: TLS session storage overhaul
Stefan Eissing [Fri, 26 Apr 2024 08:11:51 +0000 (10:11 +0200)] 
vtls: TLS session storage overhaul

- add session with destructor callback
- remove vtls `session_free` method
- let `Curl_ssl_addsessionid()` take ownership
  of session object, freeing it also on failures
- change tls backend use
- test_17, add tests for SSL session resumption

Closes #13386

19 months agomulti: multi_wait improvements
Stefan Eissing [Wed, 20 Mar 2024 07:08:43 +0000 (08:08 +0100)] 
multi: multi_wait improvements

 - only call `multi_getsock()` once for all transfers
 - realloc pollset array on demand
 - fold repeated sockets

Closes #13150

19 months agoci: remove microsoft-prod.list
Philip H. [Thu, 25 Apr 2024 09:46:41 +0000 (09:46 +0000)] 
ci: remove microsoft-prod.list

This is added by default, and it is often broken, but we don't need
anything from it.

Closes #13473

19 months agocurl_setup.h: detect 'inline' support
Evgeny Grin [Thu, 11 Apr 2024 21:44:38 +0000 (23:44 +0200)] 
curl_setup.h: detect 'inline' support

Closes #13355