]> git.ipfire.org Git - thirdparty/curl.git/log
thirdparty/curl.git
3 hours agoservers: fix to reverse `SA_RESTART` option for `sigaction()` on modern codepath master
Viktor Szakats [Tue, 16 Jun 2026 01:07:58 +0000 (03:07 +0200)] 
servers: fix to reverse `SA_RESTART` option for `sigaction()` on modern codepath

Historically servers used the deprecated `siginterrupt()` function to
configure restart behavior on specific signals. It accepts a flag, where
1 means to remove the `SA_RESTART` option, and 0 means to enable it.

In year 2021 3fb6e5a01001b8c7dfdc33a89041178aac381a27 introduced the
modern alternative to the codebase, replacing `siginterrupt()` with
`sigaction()`. After this patch, supporting, modern, systems reacted on
the same flag, but, by accident, set the `SA_RESTART` bit when flag is
1, and did not set it when 0. This reversed the previous behavior, and
the one still used on the `siginterrupt()` legacy codepath.

Fix it by revesring the `SA_RESTART` logic for the `sigaction()`
codepath, syncing it with the pre-existing behavior.

I find it odd this did not cause any perceivable issue for 5 years, even
though it's the active one in most Unix envs.

Spotted by GitHub Code Quality, though suggesting to fix
`siginterrupt()` calls. But looking into the history, those were correct
all along.

Refs:
https://pubs.opengroup.org/onlinepubs/9699919799/functions/siginterrupt.html
https://pubs.opengroup.org/onlinepubs/9699919799/functions/sigaction.html
https://www.man7.org/linux/man-pages/man3/siginterrupt.3.html
https://www.man7.org/linux/man-pages/man2/sigaction.2.html

Follow-up to 3fb6e5a01001b8c7dfdc33a89041178aac381a27 #6529

Closes #22037

8 hours agoTODO: do not consider APPDATA for netrc
Daniel Stenberg [Tue, 4 Aug 2026 08:17:03 +0000 (10:17 +0200)] 
TODO: do not consider APPDATA for netrc

See #22462
Closes #22480

9 hours agodnscache: use Curl_peer in resolve and dnscache operations
Stefan Eissing [Thu, 30 Jul 2026 11:49:58 +0000 (13:49 +0200)] 
dnscache: use Curl_peer in resolve and dnscache operations

Removes unused/duplicate members in async/ares/doh structs.

Closes #22446

11 hours agourl: rename Curl_init_do => Curl_init_transfer
Daniel Stenberg [Mon, 3 Aug 2026 14:49:40 +0000 (16:49 +0200)] 
url: rename Curl_init_do => Curl_init_transfer

And correct some comments

Closes #22474

27 hours agocurl_ed25519: add GnuTLS support (via nettle, hogweed)
Viktor Szakats [Fri, 31 Jul 2026 22:45:57 +0000 (00:45 +0200)] 
curl_ed25519: add GnuTLS support (via nettle, hogweed)

The necessary cryptography API is provided by nettle 3.1+, via its
'hogweed' library. The minimum GnuTLS version required by curl is 3.6.5,
which requires nettle 3.4.1+, so the API is always available.

Also:
- autotools: detect and use nettle's hogweed library.
- cmake/FindNettle: add support for the hogweed library.
- GHA/http3-linux: enable in the autotools/cmake GnuTLS jobs.

Ref: https://github.com/gnutls/gnutls/commit/4353ea025ae032887f3e8cf5aadace25662c6b35

Closes #22456

28 hours agotest557: test curl_mv*printf() functions
Daniel Stenberg [Mon, 3 Aug 2026 12:38:38 +0000 (14:38 +0200)] 
test557: test curl_mv*printf() functions

These functions were previously untested in the test suite. This is just
a set of basic invokes to make sure they work. The core of these
functions is identical and is tested already.

  - curl_mvfprintf
  - curl_mvprintf
  - curl_mvsnprintf
  - curl_mvsprintf
  - curl_mvaprintf

Closes #22472

30 hours agolib1560: add CURLU_NO_GUESS_SCHEME tests 22469/head
Daniel Stenberg [Mon, 3 Aug 2026 10:51:02 +0000 (12:51 +0200)] 
lib1560: add CURLU_NO_GUESS_SCHEME tests

Closes #22469

30 hours agotests: convert unit test 1396 and 1398 into libtests
Daniel Stenberg [Mon, 3 Aug 2026 11:31:33 +0000 (13:31 +0200)] 
tests: convert unit test 1396 and 1398 into libtests

They were previously unit tests but used only public library functions.

Closes #22471

31 hours agocurl_trc: remove unused expire timers
Stefan Eissing [Mon, 3 Aug 2026 10:14:17 +0000 (12:14 +0200)] 
curl_trc: remove unused expire timers

The expire timers
-  DNS_PER_NAME
-  DNS_PER_NAME2
-  HAPPY_EYEBALLS_DNS

are unused since we changed our happy eyeballing and handling of partial
resolve results.

Closes #22468

33 hours agomulti: remove #if 0'ed code that uses old struct
Daniel Stenberg [Mon, 3 Aug 2026 08:37:28 +0000 (10:37 +0200)] 
multi: remove #if 0'ed code that uses old struct

Closes #22467

35 hours agoGHA: Update pizlonator/fil-c to v0.682
renovate[bot] [Mon, 3 Aug 2026 04:52:17 +0000 (04:52 +0000)] 
GHA: Update pizlonator/fil-c to v0.682

Closes #22464

35 hours agolib: update mentions of the legacy "sessionhandle"
Daniel Stenberg [Sun, 2 Aug 2026 22:53:00 +0000 (00:53 +0200)] 
lib: update mentions of the legacy "sessionhandle"

It is now "Curl_easy"

Follow-up to 434f8d0389 (June 2016)

Closes #22463

2 days agosshserver.pl: bump an sshd config to use its modern name
Viktor Szakats [Sun, 2 Aug 2026 09:09:40 +0000 (11:09 +0200)] 
sshserver.pl: bump an sshd config to use its modern name

Ref: https://github.com/openssh/openssh-portable/commit/ee9c0da8035b3168e8e57c1dedc2d1b0daf00eec

Closes #22460

2 days agoDEPENDENCIES.md: document minimum nettle version: 3.4.1 (2018-12-04)
Viktor Szakats [Sat, 1 Aug 2026 11:08:30 +0000 (13:08 +0200)] 
DEPENDENCIES.md: document minimum nettle version: 3.4.1 (2018-12-04)

It comes as a transitive requirement by the minimum GnuTLS version.
Because libcurl uses nettle directly (in GnuTLS builds), I figure it is
useful to document explicitly.

Refs:
https://github.com/gnutls/gnutls/commit/4353ea025ae032887f3e8cf5aadace25662c6b35
https://github.com/curl/curl/pull/22456#discussion_r3695417678
https://github.com/gnutls/nettle/releases/tag/nettle_3.4.1_release_20181204

Closes #22457

2 days agoGHA: bump GitHub Actions and pips
dependabot[bot] [Sat, 1 Aug 2026 14:56:08 +0000 (14:56 +0000)] 
GHA: bump GitHub Actions and pips

- update `actions/checkout` from 7.0.0 to 7.0.1
- update `actions/labeler` from 6.1.0 to 7.0.0
- update `github/codeql-action/analyze` from 4.36.2 to 4.37.3
- update `github/codeql-action/init` from 4.36.2 to 4.37.3

- update `cryptography` from 48.0.1 to 49.0.0
- update `filelock` from 3.29.0 to 3.32.0
- update `impacket` from 0.13.0 to 0.13.1
- update `pytest` from 9.0.3 to 9.1.1
- update `websockets` from 16.0 to 16.1.1

Closes #22458
Closes #22459

4 days agoGHA/http3-linux: enable HTTPSIG in jobs running tests
Viktor Szakats [Fri, 31 Jul 2026 10:51:25 +0000 (12:51 +0200)] 
GHA/http3-linux: enable HTTPSIG in jobs running tests

To test HTTPSIG with all supported OpenSSL forks.

Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239

Closes #22453

4 days agocurl_ed25519: drop unused wolfSSL random generator
Viktor Szakats [Thu, 30 Jul 2026 23:35:56 +0000 (01:35 +0200)] 
curl_ed25519: drop unused wolfSSL random generator

Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239

Closes #22451

4 days agocurl_ed25519: tidy-up backend fallback
Viktor Szakats [Thu, 30 Jul 2026 22:26:37 +0000 (00:26 +0200)] 
curl_ed25519: tidy-up backend fallback

Sync fallback logic with other crypto algos to:

- allow falling back to the next backend candidate when wolfSSL does not
  have ed25519 built in.

- de-duplicate fallback code.

Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239

Closes #22450

4 days agobuild: assume POSIX `select()` is available
Viktor Szakats [Thu, 30 Jul 2026 12:20:59 +0000 (14:20 +0200)] 
build: assume POSIX `select()` is available

This change effectively replaces an explicit compile-time #error with
a missing prototype error in environments not offering `select()`, and
saves curl-compatible systems from performing an explicit feature check.

Refs:
https://pubs.opengroup.org/onlinepubs/009695399/functions/pselect.html
https://linux.die.net/man/2/select

Closes #22448

4 days agoh3-proxy: fix NULL deref when non-:status header arrives before :status
Ramesh Adhikari [Thu, 30 Jul 2026 16:29:16 +0000 (21:59 +0530)] 
h3-proxy: fix NULL deref when non-:status header arrives before :status

Closes #22449

4 days agoapple-fast-udp: fix sendmsg_x partial results
Stefan Eissing [Wed, 29 Jul 2026 11:11:20 +0000 (13:11 +0200)] 
apple-fast-udp: fix sendmsg_x partial results

When sending with sendmsg_x(), fix handling of last gso chunk being
smaller. Handle partial results correctly. Ignore SOCKEMSGSIZE by
reporting success which drops PMTUD probes into the void.

Closes #22429

5 days agocurl: help category cleanups
Daniel Stenberg [Thu, 30 Jul 2026 11:47:03 +0000 (13:47 +0200)] 
curl: help category cleanups

- add 'mqtt' as a category
- add more protocol categories to several options
- make --data worded better to also cover MQTT

Closes #22447

5 days agogitignore: maintenance updates
Viktor Szakats [Sat, 25 Jul 2026 14:50:51 +0000 (16:50 +0200)] 
gitignore: maintenance updates

- docs/cmdline-opts/.gitignore: also ignore `manpage.tmp.*`.
  Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239

- ./.gitignore: drop obsolete entries.
  Follow-up to 4f38db1d28a971f938400f558e968fdffb9233a0 #1923

Closes #22445

5 days agotidy-up: minor code fixes and improvements
Viktor Szakats [Fri, 24 Jul 2026 22:11:21 +0000 (00:11 +0200)] 
tidy-up: minor code fixes and improvements

- schannel: drop redundant parentheses.
- os400sys: drop redundant includes.
  Follow-up to ebc5212dacd3db8f5315b5a2d676415848e936d5 #22374
- pytest: replace `()` with `[]` to match rest of tests.
- libtests: constify some local pointers.
- libtests: drop redundant `(long)` casts.
- lib650: use `CURL_CSTRLEN()`.
  Follow-up to 59dc2bbe07c3b5889e0b380e5fa384d338d9d24e #22424

Closes #22444

5 days agotidy-up: comments, messages, formatting
Viktor Szakats [Fri, 24 Jul 2026 00:44:11 +0000 (02:44 +0200)] 
tidy-up: comments, messages, formatting

- 'null-terminate', sync casing.
- add an `#endif` comment.
- avoid a few instances of 'will'.
- configure: 'aws' -> 'aws-sigv4', where missing.
- unfold/fold lines.
- update memzero/strzero comments.
- uppercase 'CRLF'.

Closes #22443

5 days agoGHA: update dependency google/boringssl to v0.20260730.0
renovate[bot] [Thu, 30 Jul 2026 08:37:30 +0000 (08:37 +0000)] 
GHA: update dependency google/boringssl to v0.20260730.0

Closes #22442

5 days agolib5004: fix memleak on OOM, check all slist append results (httpsig)
Viktor Szakats [Wed, 29 Jul 2026 21:30:51 +0000 (23:30 +0200)] 
lib5004: fix memleak on OOM, check all slist append results (httpsig)

Detected by torture tests:
```
test 5004...[HTTP RFC 9421 B.2.6: Ed25519 POST with headers (RFC test vector)]
 105 functions found, but only fail 25 (23.81%)
** MEMORY FAILURE
Leak detected: memory still allocated: 99 bytes
At 6000022c9408, there is 36 bytes.
 allocated by /Users/runner/work/curl/curl/lib/slist.c:87
At 6000039c8e78, there is 31 bytes.
 allocated by /Users/runner/work/curl/curl/lib/slist.c:87
At 6000037dd688, there is 16 bytes.
 allocated by /Users/runner/work/curl/curl/lib/slist.c:62
At 6000037dd628, there is 16 bytes.
 allocated by /Users/runner/work/curl/curl/lib/slist.c:62
LIMIT /Users/runner/work/curl/curl/lib/slist.c:62 malloc reached memlimit
 5004: torture FAILED: function number 10 in test.
```
Ref: https://github.com/curl/curl/actions/runs/30497660391/job/90730128599?pr=22437#step:16:2331

Also:
- enable HTTPSIG in torture tests.
- NULL check all `curl_slist_append()` results.
- apply a NULL check to sibling test 5000 also.

Co-authored-by: Daniel Stenberg
Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239

Closes #22437

5 days agoGHA: set `HOMEBREW_NO_INSTALL_CLEANUP=1` where brew is used
Viktor Szakats [Wed, 29 Jul 2026 22:52:10 +0000 (00:52 +0200)] 
GHA: set `HOMEBREW_NO_INSTALL_CLEANUP=1` where brew is used

To save work unnecessary in CI context, and to reduce log noise.

Cherry-picked from #22437

Closes #22440

5 days agoRELEASE-NOTES: synced
Daniel Stenberg [Thu, 30 Jul 2026 07:12:28 +0000 (09:12 +0200)] 
RELEASE-NOTES: synced

5 days agobuild: fix HTTPSIG option for unsupported TLS backends
Viktor Szakats [Thu, 30 Jul 2026 00:24:58 +0000 (02:24 +0200)] 
build: fix HTTPSIG option for unsupported TLS backends

Show a warning and force-disable HTTPSIG when the TLS backend is not
OpenSSL or wolfSSL. Before this patch this resulted in a mismatched
feature list in configure and `curl -V`.

Also enable HTTPSIG in more CI jobs to cover unsupported ones, Windows
compilers, clang-tidy, cmake.

Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386 #21239
Cherry-picked from #22437

Closes #22439

5 days agoGHA: work around Homebrew `ca-certificates` install error
Viktor Szakats [Wed, 29 Jul 2026 23:46:15 +0000 (01:46 +0200)] 
GHA: work around Homebrew `ca-certificates` install error

Working around:
```
==> Installing libngtcp2 dependency: ca-certificates
==> Pouring ca-certificates--2026-07-16.all.bottle.1.tar.gz
Warning: The post-install step did not complete successfully
[...]
Error: Process completed with exit code 1.
```

Refs:
https://github.com/Homebrew/homebrew-core/pull/295934
https://github.com/Homebrew/brew/pull/23357

Bug: https://github.com/curl/curl/pull/22437#issuecomment-5124151490

Closes #22438

5 days agosws: log the exact closing reason better, to help debugging tests
Daniel Stenberg [Wed, 29 Jul 2026 14:32:40 +0000 (16:32 +0200)] 
sws: log the exact closing reason better, to help debugging tests

Closes #22431

5 days agotool: remove duplicate setopts
Stefan Eissing [Wed, 29 Jul 2026 15:58:08 +0000 (17:58 +0200)] 
tool: remove duplicate setopts

CURLOPT_RESOLVE and CURLOPT_CONNECT_TO were set twice.
A happy little accident?

Closes #22433

5 days agotests: fix cert comparison with old cryptography
Dan Fandrich [Tue, 28 Jul 2026 23:27:38 +0000 (16:27 -0700)] 
tests: fix cert comparison with old cryptography

The fallback path for cryptography < 42 was broken by commit e13362c2
that caused a comparison between offset-naive and offset-aware
datetimes. Use the positional form of tz in datetime.now() everywhere.

Ref: #22396

Pointed out by Codex Security
Closes #22426

6 days agoldap: support empty username and password
Jay Satiro [Fri, 26 Jun 2026 18:12:43 +0000 (14:12 -0400)] 
ldap: support empty username and password

Prior to this change an empty username or password was passed to the
LDAP bind function as NULL instead of an empty string.

Regression since 8f71d0fd.

Reported-by: Yoshiro Yoneya
Fixes https://github.com/curl/curl/issues/22162
Closes https://github.com/curl/curl/pull/22196

6 days agoGHA: update dependency nghttp2/nghttp2 to v1.70.0
renovate[bot] [Wed, 29 Jul 2026 17:14:11 +0000 (17:14 +0000)] 
GHA: update dependency nghttp2/nghttp2 to v1.70.0

Closes #22434

6 days agourlapi: clear password buffer on error path
Viktor Szakats [Wed, 29 Jul 2026 15:09:06 +0000 (17:09 +0200)] 
urlapi: clear password buffer on error path

Reported by Copilot
Bug: https://github.com/curl/curl/pull/21637#pullrequestreview-4809702512
Follow-up to 112a8b5adf36c17e7816a8db701b3e7a22958e52 #21637
Follow-up to 7c34365ccea19949317878c7fcd5f7376e2e09f1 #21879

Closes #22432

6 days agosrc: safely clear certain buffers
Viktor Szakats [Wed, 13 May 2026 23:36:22 +0000 (01:36 +0200)] 
src: safely clear certain buffers

That may hold credentials or other sensitive data, or where we want to
ensure the zeroing is not optimized out by the compiler.

Credits-to: Daniel Gustafsson
Ref: #13589 (original attempt)
Ref: #21588

Follow-up to #21645
Follow-up to 066478f6346a2d987a9ecc3bd3bf45764d69c1c4 #21598

Closes #21637

6 days agodocs/INTERNALS.md -> docs/DEPENDENCIES.md
Daniel Stenberg [Wed, 29 Jul 2026 11:59:31 +0000 (13:59 +0200)] 
docs/INTERNALS.md -> docs/DEPENDENCIES.md

With some minor cleanups

Closes #22430

6 days agosrc: improve `curlx_memzero()` internal APIs
Viktor Szakats [Sat, 16 May 2026 10:08:00 +0000 (12:08 +0200)] 
src: improve `curlx_memzero()` internal APIs

- delete zero-and-free wrapper macros. (not yet used)
  To keep it simple.
- do NULL-check in `curlx_memzero()`.
  To avoid noise at call sites.
- add `curlx_strzero()` for null-terminated strings, also with
  NULL-check.

Ref: #21637
Follow-upt o 066478f6346a2d987a9ecc3bd3bf45764d69c1c4 #21598

Closes #21645

6 days agoh2: bootstrap max streams from multi handle if in use
CatboxParadox [Tue, 28 Jul 2026 12:12:09 +0000 (14:12 +0200)] 
h2: bootstrap max streams from multi handle if in use

Closes #22418

6 days agoEXPERIMENTAL: cleanups, unify on titles, merge quiche into a single segment
Daniel Stenberg [Wed, 29 Jul 2026 11:21:52 +0000 (13:21 +0200)] 
EXPERIMENTAL: cleanups, unify on titles, merge quiche into a single segment

Closes #22428

6 days agoEXPERIMENTAL: Apple fast UDP
Daniel Stenberg [Wed, 29 Jul 2026 11:12:46 +0000 (13:12 +0200)] 
EXPERIMENTAL: Apple fast UDP

Follow-up to 079a11bcba5858ffab2cf6e810e9d980

Closes #22428

6 days agowebsocket: pause writing and meta data fix
Stefan Eissing [Tue, 28 Jul 2026 12:27:13 +0000 (14:27 +0200)] 
websocket: pause writing and meta data fix

When writing a decoded chunk of websocket data, always flush the writer
chain so that buffered data gets delivered before the ws meta data gets
updated.

Add client writer flags CURL_CW_FLAG_BLOWUP for writer types that may
significantly enlarge write sizes. This flag causes the pause writer to
be added and shrinks the write chunk sizes. We do not want that for
content decoders like WS that do not change the size.

Add test_20_13 to check that large frames are paused/unpaused correctly
with the matching meta data.

Fixes #22413
Reported-by: Hendrik Hübner
Closes #22416

6 days agoconncache: connection healthiness fix
Stefan Eissing [Tue, 28 Jul 2026 08:43:30 +0000 (10:43 +0200)] 
conncache: connection healthiness fix

Update the `lastchecked` timestamp on connection health checks when
successful to prevent repeated recalcs for a second.

Rename `seems_dead` to `seems_healthy` because the world is already
depressing enough.

Consider pending input on connection only unhealthy when the connection
has no transfers and is not multiplexed.

Closes #22412

6 days agovquic: add option to use Apple fast UDP
Viktor Szakats [Tue, 28 Jul 2026 12:22:43 +0000 (14:22 +0200)] 
vquic: add option to use Apple fast UDP

Using Apple's secret `SYS_recvmsg_x` and `SYS_sendmsg_x` syscalls for
receiving/sending batches of UDP packets.

Since it uses undocumented calls, it's experimental and disabled by
default.

To enable:
- autotools: `--enable-apple-fast-udp`
- cmake: `-DCURL_ENABLE_APPLE_FAST_UDP=ON`

Also:
- enable in two H3 CI jobs with both build tools, pytest and clang-tidy.

Refs:
https://max-inden.de/post/fast-udp-io-in-firefox/
https://www.macsyscalls.com/en/syscall/480-recvmsg-x
https://www.macsyscalls.com/en/syscall/481-sendmsg-x

C-code-authored-by: Stefan Eissing
Build-code-authored-by: Viktor Szakats
Closes #22341
Closes #22417

6 days agoGHA/configure-vs-cmake: dump `./configure --help`
Viktor Szakats [Wed, 29 Jul 2026 09:25:07 +0000 (11:25 +0200)] 
GHA/configure-vs-cmake: dump `./configure --help`

For visual review when necessary. For the three major platforms for
symmetry and good measure.

Closes #22427

6 days agoGHA: update dependency google/boringssl to v0.20260728.0
renovate[bot] [Tue, 28 Jul 2026 22:21:01 +0000 (22:21 +0000)] 
GHA: update dependency google/boringssl to v0.20260728.0

Closes #22425

6 days agoHISTORY: add when c-ares support was introduced (2004)
Daniel Stenberg [Wed, 29 Jul 2026 07:04:46 +0000 (09:04 +0200)] 
HISTORY: add when c-ares support was introduced (2004)

6 days agotidy-up: use `CURL_CSTRLEN()` macro on more static strings
Viktor Szakats [Tue, 28 Jul 2026 20:36:11 +0000 (22:36 +0200)] 
tidy-up: use `CURL_CSTRLEN()` macro on more static strings

Follow-up to e1450d8fdaf05f27ec75eb15df303fe931755a59 #22406

Closes #22424

6 days agoscripts/badwords.txt: do not recommend using 'will' in rewrites
Daniel Stenberg [Tue, 28 Jul 2026 20:44:50 +0000 (22:44 +0200)] 
scripts/badwords.txt: do not recommend using 'will' in rewrites

Instead suggest "avoid contraction and rewrite to present tense"

Reported-by: claudex on github
Fixes #22422
Closes #22423

6 days agodocs/INTERNALS.md: move a column one byte
Daniel Stenberg [Tue, 28 Jul 2026 12:47:44 +0000 (14:47 +0200)] 
docs/INTERNALS.md: move a column one byte

To make the minimum gap two spaces, so that we can separate the columns
programmatically

6 days agoscorecard: fix `max_upload` init value in `ul_parallel()`
Viktor Szakats [Wed, 15 Jul 2026 00:18:30 +0000 (02:18 +0200)] 
scorecard: fix `max_upload` init value in `ul_parallel()`

"In `ul_parallel`, `max_parallel` is computed using
`self._download_parallel` instead of `self._upload_parallel`. This
causes the upload parallelism to incorrectly follow the download
parallel setting. It should use `self._upload_parallel` to be consistent
with how `uploads()` computes `max_parallel`."

Reported by GitHub Code Quality

Follow-up to 30ef79ed937ca0fc7592ff73d162398773c6a5aa #17295

Closes #22421

6 days agodnsd: fix bounds check in `read_https_alpn_part()`
Viktor Szakats [Wed, 15 Jul 2026 00:28:09 +0000 (02:28 +0200)] 
dnsd: fix bounds check in `read_https_alpn_part()`

"The check `i > 256` permits `i == 256` to pass through. When `i` is
then cast to `uint8_t` in `blob_add(b, (uint8_t)i)`, the value wraps to
0, silently encoding a zero-length ALPN entry instead of rejecting it.
The condition should be `i > 255` (or equivalently `i >= 256`) to
correctly reject any length that does not fit in a single byte."

Reported by GitHub Code Quality

Follow-up to 86f1e5b3f6c90e453368fdf23c366c1d4a8c953b #21299

Closes #22420

6 days agoCI: improve labeler matches
Dan Fandrich [Tue, 28 Jul 2026 20:19:40 +0000 (13:19 -0700)] 
CI: improve labeler matches

7 days agoschannel: fix error check logic in `get_client_cert()` file reader
Viktor Szakats [Wed, 15 Jul 2026 16:04:59 +0000 (18:04 +0200)] 
schannel: fix error check logic in `get_client_cert()` file reader

Reported by GitHub Code Quality
Follow-up to 0fdf96512613574591f501d63fe49495ba40e1d5 #5193

Closes #22415

7 days agocurl_gssapi: document/update feature availability
Viktor Szakats [Tue, 28 Jul 2026 15:08:02 +0000 (17:08 +0200)] 
curl_gssapi: document/update feature availability

- update `GSS_C_DELEG_POLICY_FLAG` comment to include Apple GSS, add
  date, and amend MIT Kerberos version to 1.7+ (was: 1.8+)
  Ref: https://github.com/krb5/krb5/commit/45875a4d7bbd6bb8a943572d84fef5ca2bb18291
  Ref: https://github.com/apple-oss-distributions/Heimdal/commit/1635de38a813f6e1dd3f8fd270683187ad4f02be

- document `HAVE_GSS_SET_NEG_MECHS`/`gss_set_neg_mechs()`.
  Ref: https://github.com/krb5/krb5/commit/079eed2cf749702f75ddc385cf943fbab931f9d8
  It's also committed to Heimdal, but not present in a release
  as of 7.8.0 (current latest).
  Ref: https://github.com/heimdal/heimdal/commit/735039dbdc3aa58d06afdefd214efe3f5e421244

Follow-up to a8881e5e1d2e22d4b085d45ab6c8ce1df251d602 #21315 #22410
Follow-up to d169ad68faa5ed5ba2375e7502307a6262466d88 #22052

Closes #22419

7 days agotests: bump ruff version to 0.60.0
Dan Fandrich [Sat, 25 Jul 2026 23:41:05 +0000 (16:41 -0700)] 
tests: bump ruff version to 0.60.0

This version enables many more warnings by default.

Closes #22396

7 days agotests: target Python 3.8 as the minimum Python version
Dan Fandrich [Sat, 25 Jul 2026 20:34:38 +0000 (13:34 -0700)] 
tests: target Python 3.8 as the minimum Python version

This version is already two releases out of support, but is "only" 7
years old so is probably still being used in the real world. Document
this version along with some other testing dependencies.  Remove code
support for earlier versions. Disable ruff checks that need a newer
version.

7 days agotests: address mutable class vars and naive datetime in Python code
Dan Fandrich [Sat, 25 Jul 2026 20:23:21 +0000 (13:23 -0700)] 
tests: address mutable class vars and naive datetime in Python code

Mark Python mutable class variables with ClassVar, to denote that the
danger this can cause has been considered.  Since any change made to
these in any object affects all other objects, this can cause locality
errors. However, as used in the test suite, they are are never modified
and so they are annotated as being intended.

Always set a timezone in datetime objects, as mixing naive and
timezone-aware object can cause errors.

These fix ruff rules DTZ005, RUF012.

7 days agotests: use simpler constructions in Python code
Dan Fandrich [Sat, 25 Jul 2026 21:05:01 +0000 (14:05 -0700)] 
tests: use simpler constructions in Python code

* call super() without arguments
* mark an unused variable as such
* simplify by using dict getter for default values
* use writelines() when possible
* use dedent to simplify some text formatting
* avoid items() on dict in a loop when unnecessary
* replace most Python format() calls with f-strings
* use capture_output in subprocess.run

This fixes ruff rules FLY002, FURB122, PERF102, RUF059, SIM401, UP008,
UP022, UP030.

7 days agotests: simplify by removing unneeded Python code
Dan Fandrich [Sat, 25 Jul 2026 20:49:29 +0000 (13:49 -0700)] 
tests: simplify by removing unneeded Python code

* combine separate if statements
* remove an unneeded encode() call
* remove unneeded returns
* simplify code when returning early

This fixes ruff rules SIM102, SIM114, UP012, PLR1711.

7 days agotests: change whitespace and comments in Python test code
Dan Fandrich [Sat, 25 Jul 2026 20:35:51 +0000 (13:35 -0700)] 
tests: change whitespace and comments in Python test code

* remove an unneeded ruff warning disable
* remove coding: utf-8 from Python code; PEP 3120 makes UTF-8 the
  default encoding
* remove unusable shebang lines from Python code
* remove empty print strings
* disable warnings when file objects are stored; these instances can't
  be handled with context managers
* use more consistent whitespace in Python code, fixing flake8 warnings
* set the executable bit on scorecard.py, making it easier to run

These fix ruff rules EXE001, FURB105, UP009, SIM115.

7 days agotests: improve exception handling in Python test code
Dan Fandrich [Sat, 25 Jul 2026 20:06:38 +0000 (13:06 -0700)] 
tests: improve exception handling in Python test code

* Explicitly set "check" in subprocess.run() to raise an exception
  automatically, where it was done manually before
* Use contextlib.suppress to ignore exceptions
* Use custom exceptions for test errors for clarity and flexibility.
* Replace IOError with OSError

This fixes ruff rules BLE001, PLW1510, S110, TRY201, TRY203, TRY002,
UP024.

7 days agotidy-up: use more `static`, `sizeof()`, `char[]`, double-const
Viktor Szakats [Wed, 22 Jul 2026 23:50:06 +0000 (01:50 +0200)] 
tidy-up: use more `static`, `sizeof()`, `char[]`, double-const

- make `const` data `static`, where missing and possible.
- replace `strlen()` on literal or const strings with `sizeof()`.
  While the latter is optimized by popular C compiler, e.g. MSVC only
  does it with `/O2`.
- replace magic numbers with `sizeof()`, where missing.
- introduce `CURL_CSTRLEN()` macro for `sizeof(char[]) - 1`.
- use `CURL_CSTRLEN()` macro.
- move `const` before integer types, where missing.
- replace `char *var` with `var[]`, where missing and possible.
- use double const, where missing.
  `static const char *` -> `static const char * const`.
- lib1514: constify pointers.
- unit3205: drop redundant cast, avoid another one.
- unit1666: map `OID()` macro to identical `STRCONST()`.

Closes #22406

7 days agourlapi: improved return codes
Daniel Stenberg [Mon, 27 Jul 2026 14:05:38 +0000 (16:05 +0200)] 
urlapi: improved return codes

- add CURLUE_BACKSLASH that can be returned when a backslash was used
  where a forward one probably was intended.

- make CURLUE_NO_HOST higher priority than port number errors for URLs
  without hostname. Like in "http://::1"

- shortened some URL parser error strings

Extend test 1560 to verify.

Reported-by: kit-ty-kate on github
Fixes #22337
Closes #22408

7 days agolib2405: adjust for non-threaded builds
Daniel Stenberg [Tue, 28 Jul 2026 09:53:42 +0000 (11:53 +0200)] 
lib2405: adjust for non-threaded builds

- Attempt to fix the flakiness set in 9726fc8259ad7ebf1682
- Reduce macro use

Closes #22414

7 days agoEXPERIMENTAL.md: We do not accept vuln reports for experimental features
Daniel Stenberg [Mon, 27 Jul 2026 21:56:44 +0000 (23:56 +0200)] 
EXPERIMENTAL.md: We do not accept vuln reports for experimental features

Closes #22411

7 days agospnego: block NTLM fallback in SPNEGO negotiation
Matthew John Cheetham [Mon, 13 Apr 2026 11:58:52 +0000 (12:58 +0100)] 
spnego: block NTLM fallback in SPNEGO negotiation

- Switch the Windows SSPI identity struct to SEC_WINNT_AUTH_IDENTITY_EX
  to use !ntlm in PackageList to prevent NTLM from being offered.

- For GSS filter out NTLMSSP OID, and restrict via gss_set_neg_mechs()
  to prevent NTLM from being offered.

- Extend the GSS-API debug stub layer to support the NTLM blocking logic
  without a real Kerberos environment.

- Update test 2057 to check that negotiate auth is silently skipped with
  no Authorization header when only NTLM stub credentials are available.

- Add SPNEGO NTLM blocking test 2093 which verifies that Kerberos
  credentials still succeed when NTLM is blocked within SPNEGO.

- Suppress tests valgrind leak for MIT krb5 gss_display_status, since
  the leak is in the library and not in curl.

To suppress the tests valgrind leak, the wildcard '...' bridges over an
anonymous frame inside libgssapi_krb5.so that valgrind reports as '???'.

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
Aided-by: Johannes Schindelin
Closes https://github.com/curl/curl/pull/21315
Closes https://github.com/curl/curl/pull/22410

7 days agoconncache: conn upkeep/alive: move and enhance
Stefan Eissing [Mon, 27 Jul 2026 07:49:33 +0000 (09:49 +0200)] 
conncache: conn upkeep/alive: move and enhance

- move `Curl_conn_seems_dead()` into conncache.c
- move `Curl_conn_upkeep()` into conncache.c
- when upkeep gives an error on a connection not in use,
  terminate it

Closes #21806

8 days agotypecheck-gcc: allow passing `char[]` as callback data
Viktor Szakats [Mon, 27 Jul 2026 11:17:56 +0000 (13:17 +0200)] 
typecheck-gcc: allow passing `char[]` as callback data

E.g. `TEST_DATA_STRING` in test 655.

Cherry-picked from #22406

Closes #22409

8 days agovquic: use ngtcp2 v1.25.0 new close2 callback
Stefan Eissing [Mon, 20 Jul 2026 12:37:13 +0000 (14:37 +0200)] 
vquic: use ngtcp2 v1.25.0 new close2 callback

Forward only the app error code from the receiving side to the h3 layer.

This only takes effect when building against ngtcp2 v1.25.0 or higher.

Fixes #22270

Closes #22356

8 days agoGHA: update dependency ngtcp2/ngtcp2 to v1.25.0
renovate[bot] [Mon, 27 Jul 2026 08:20:01 +0000 (08:20 +0000)] 
GHA: update dependency ngtcp2/ngtcp2 to v1.25.0

Closes #22398

8 days agocf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code
Viktor Szakats [Sun, 26 Jul 2026 18:48:02 +0000 (20:48 +0200)] 
cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code

Closes #22401

8 days agocmake: verify if options are listed in `INSTALL-CMAKE.md`
Viktor Szakats [Mon, 27 Jul 2026 00:42:09 +0000 (02:42 +0200)] 
cmake: verify if options are listed in `INSTALL-CMAKE.md`

Also:
- add one debug option to pass the test.

Ref: https://github.com/curl/curl/discussions/14885#discussioncomment-10632311

Closes #22404

8 days agopytest: update two H3 tests for nghttp3 1.18.0+
Viktor Szakats [Sun, 26 Jul 2026 19:15:33 +0000 (21:15 +0200)] 
pytest: update two H3 tests for nghttp3 1.18.0+

Fixing:
```
FAILED ../../tests/http/test_02_download.py::TestDownload::test_02_36_looong_urls[65536-h3] -
  AssertionError: expected exit code 0, got 56
FAILED ../../tests/http/test_14_auth.py::TestAuth::test_14_05_basic_large_pw[h3] -
  AssertionError: expected exit code 0, got 56
```
Ref: https://github.com/curl/curl/actions/runs/30207198835/job/89807247058?pr=22400

Refs:
https://github.com/ngtcp2/nghttp3/pull/539
https://github.com/ngtcp2/nghttp3/commit/a5872645446cdc07e897fea33b61a3c665563da9

Bug: https://github.com/curl/curl/pull/22397#issuecomment-5084927935

Closes #22402

8 days agovquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables
Viktor Szakats [Sun, 26 Jul 2026 14:57:51 +0000 (16:57 +0200)] 
vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables

To avoid a breakage in CI and curl-for-win builds on upstream updates
extending the callback lists. Each such breakage needed patching curl,
rolling these patches into curl-for-win, and doing it in near real-time,
to keep CI and builds working (and still causing some red CI jobs).

Bring calmness here by suppressing the warnings and allowing time to
extend the callback tables as/if needed and at a convenient moment.

Closes #22400

8 days agoRELEASE-NOTES: synced
Daniel Stenberg [Mon, 27 Jul 2026 07:40:05 +0000 (09:40 +0200)] 
RELEASE-NOTES: synced

8 days agoGHA/windows: bump stunnel to 5.79
Viktor Szakats [Sun, 26 Jul 2026 23:41:07 +0000 (01:41 +0200)] 
GHA/windows: bump stunnel to 5.79

Closes #22403

8 days agoruntests: fix `mode="warn"` tests passing unconditionally, fix test 1752
Viktor Szakats [Sat, 25 Jul 2026 11:43:33 +0000 (13:43 +0200)] 
runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752

Fix test 1712 to pass curl C by setting `COLUMNS` to the highest
accepted value, and adjust expected results. To avoid envs with varying
lengths of `LOGDIR` affect the outcome.

Apply the same fix to test 459, though it wasn't affected in curl CI.

Also sync up test 433 `COLUMNS` value with these two tests for
consistency.

Ref: #22381
Follow-up to 8e3a2a64d103a46508e17cde76595993de96ea6c #20666

Closes #22388

8 days agohttp: fix httpsig with auth-redir
Daniel Stenberg [Sat, 25 Jul 2026 21:48:07 +0000 (23:48 +0200)] 
http: fix httpsig with auth-redir

Do not let unrelated credentials from a redirected URL bypass the
cross-host auth boundary

Verified by test 5023 to 5025

Follow-up to a55731050e8c3dbea0

Closes #22395

9 days agoGHA/http3-linux: update dependency ngtcp2/nghttp3 to v1.18.0
renovate[bot] [Sun, 26 Jul 2026 10:13:55 +0000 (10:13 +0000)] 
GHA/http3-linux: update dependency ngtcp2/nghttp3 to v1.18.0

Closes #22397

9 days agovquic: initialize new callback slot for nghttp3 v1.18.0+
Viktor Szakats [Sun, 26 Jul 2026 14:27:34 +0000 (16:27 +0200)] 
vquic: initialize new callback slot for nghttp3 v1.18.0+

Closes #22399

9 days agoruntests: allow comments in `setenv` section, merge sections in test433
Viktor Szakats [Sat, 25 Jul 2026 12:18:07 +0000 (14:18 +0200)] 
runtests: allow comments in `setenv` section, merge sections in test433

Closes #22389

9 days agobuild: tidy up httpsig options
Viktor Szakats [Sat, 25 Jul 2026 14:58:54 +0000 (16:58 +0200)] 
build: tidy up httpsig options

- say 'experimental'.
- cmake: add to documentation.
- cmake: alpha-sort.

Follow-up to a55731050e8c3dbea0b96205cf916443118f6acb #22386

Closes #22391

9 days agotool_getparam: clear the --httpsig-key argument
Daniel Stenberg [Sat, 25 Jul 2026 21:06:29 +0000 (23:06 +0200)] 
tool_getparam: clear the --httpsig-key argument

To hide it somewhat from process listings.

Closes #22394

9 days agocd2nroff: fix backslashes for 4-space indent lines
Daniel Stenberg [Sat, 25 Jul 2026 20:22:21 +0000 (22:22 +0200)] 
cd2nroff: fix backslashes for 4-space indent lines

They were previously only properly escaped for ~~~ quotes. Spotted for
the CURLOPT_HTTPSIG_KEY man page.

Closes #22393

9 days agocurl: make --httpsig-key take a key OR a file name for key
Daniel Stenberg [Sat, 25 Jul 2026 15:03:22 +0000 (17:03 +0200)] 
curl: make --httpsig-key take a key OR a file name for key

Verified by test 5022

Closes #22392

10 days agohttpsig: add RFC 9421 HTTP Message Signatures support
Sameeh Jubran [Fri, 24 Jul 2026 20:49:52 +0000 (22:49 +0200)] 
httpsig: add RFC 9421 HTTP Message Signatures support

Add support for signing outgoing HTTP requests per RFC 9421 using
Ed25519 or HMAC-SHA256 algorithms.

New libcurl options:
 - CURLOPT_HTTPSIG: signing algorithm ("ed25519" or "hmac-sha256")
 - CURLOPT_HTTPSIG_KEY: path to hex-encoded key file
 - CURLOPT_HTTPSIG_KEYID: key identifier for Signature-Input
 - CURLOPT_HTTPSIG_HEADERS: space-separated components to sign

New CLI flags: --httpsig, --httpsig-key, --httpsig-keyid,
--httpsig-headers

The crypto layer follows the sha256.c multi-backend pattern with
implementations for OpenSSL (EVP_DigestSign) and wolfSSL
(wc_ed25519_sign_msg). HMAC-SHA256 uses the existing Curl_hmacit()
infrastructure which works on all backends.

Verified by test 5000 to 5021

Assisted-by: Daniel Stenberg
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
Closes #22386
Closes #21239

10 days agotidy-up: drop redundant includes
Viktor Szakats [Sun, 28 Jun 2026 11:10:38 +0000 (13:10 +0200)] 
tidy-up: drop redundant includes

`sys/types.h` and `sys/socket.h` (non-Win32). They are included via
`curl/curl.h` and `curl_setup.h`.

This drops `HAVE_SYS_TYPES_H` guards from the codebase. It's safe
because `sys/types.h` (POSIX) is already required unconditionally by
`curl/curl.h`. It remains used in feature checks by both autotools and
cmake; to be reviewed in a future step.

Closes #22374

10 days agospacecheck: cap number of lines per file
Viktor Szakats [Fri, 24 Jul 2026 18:26:01 +0000 (20:26 +0200)] 
spacecheck: cap number of lines per file

To prevent merging large text files by accident.

Set the cap at 10k lines. The current line number top list is:
```
    5577 configure.ac
    5561 lib/vtls/openssl.c
    5077 lib/http.c
    4517 lib/ftp.c
    4284 lib/multi.c
```

Closes #22387

10 days agoconnect: connection close tweaks
Stefan Eissing [Thu, 23 Jul 2026 12:17:13 +0000 (14:17 +0200)] 
connect: connection close tweaks

- connclose/streamclose/connkeep() remove description string that was
  never used anywhere. Add trace statements where reasons for closing
  were not already traced and maybe not obvious.
- multi_remove_handle: only lookup former connection in pool when
  transfer is set to connect only
- test1554: adapt expectations now that pool is less often locked

Closes #22379

10 days agohttpsrr: DoH with HTTPS, fix response handling
Stefan Eissing [Thu, 23 Jul 2026 09:20:19 +0000 (11:20 +0200)] 
httpsrr: DoH with HTTPS, fix response handling

Fix handling of DoH response that only asks for HTTPS records.

Add test 2117 for checking that a HTTPS-RR resolve is processed,
even though the actual answer is invalid.

Closes #22372

10 days agoapi-guard: check lock on session cache
Stefan Eissing [Wed, 22 Jul 2026 09:06:39 +0000 (11:06 +0200)] 
api-guard: check lock on session cache

Add a property to easy/multi API calls that prohibit calling
the function when the involved SSL session cache is under lock
by the current thread.

Checks are only in effect when pthreads/Windows threads are
available.

Closes #22367

11 days agoterminal: Enhance terminal size detection for multiple outputs 22276/head
AlanKingPL [Wed, 8 Jul 2026 11:13:40 +0000 (13:13 +0200)] 
terminal: Enhance terminal size detection for multiple outputs

- Get the terminal size from STDOUT or STDERR when the terminal size of
  STDIN is not available.

Closes https://github.com/curl/curl/pull/22276

11 days agohttp: fix non-tunneling proxy hostname use
Stefan Eissing [Fri, 24 Jul 2026 12:20:58 +0000 (14:20 +0200)] 
http: fix non-tunneling proxy hostname use

Make sure hostname used in URL to proxy is IDN decoded form, but keep
the original hostname in case it was ipv6.

Fixes #22382
Reported-by: RMMoreton on github
Closes #22385

11 days agotests: fix the FTP check for unexpected RST
Graham Campbell [Sun, 12 Jul 2026 17:47:32 +0000 (18:47 +0100)] 
tests: fix the FTP check for unexpected RST

- In vsftpd ignore unrelated RST by matching tcpdump RSTs to the data
  connection port pair.

Prior to this change an unrelated RST on a recycled ephemeral port
could cause test failure.

Closes https://github.com/curl/curl/pull/22305

11 days agoasyn-thrdd: retry link-local ipv6 if missing scope id
Stefan Eissing [Tue, 21 Jul 2026 11:28:59 +0000 (13:28 +0200)] 
asyn-thrdd: retry link-local ipv6 if missing scope id

When the threaded resolver gets AAAA results that carry a link-local
address without scope-id, it now re-queues a query with AF_UNSPEC and
strips ipv4 addresses from that result. Whatever the resulting addresses
and scope-ids are, this becomes the result of the resolve.

Fixes #22330
Reported-by: Bartel Sielski
Closes #22368

11 days agoctype: exclude control bytes from ISPRINT and ISGRAPH
Alhuda Khan [Thu, 23 Jul 2026 06:39:04 +0000 (12:09 +0530)] 
ctype: exclude control bytes from ISPRINT and ISGRAPH

Closes #22371

11 days agoconfigure: only check in the watt library if WATT_ROOT is set
Ross Burton [Thu, 23 Jul 2026 12:09:13 +0000 (13:09 +0100)] 
configure: only check in the watt library if WATT_ROOT is set

Only look for gethostbyname in libwatt in $WATT_ROOT/lib if WATT_ROOT
has actually been set. This avoids configure trying to search in /lib,
which won't every succeed and can cause problems in cross builds which
check that host paths are not being searched.

Closes #22380