]>
git.ipfire.org Git - thirdparty/gnutls.git/log
Daiki Ueno [Tue, 11 Jan 2022 06:34:59 +0000 (07:34 +0100)]
global: add API to retrieve library configuration at run time
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 16 Jan 2022 11:17:39 +0000 (12:17 +0100)]
configure.ac: emit feature summary as C macro
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 16 Jan 2022 16:48:14 +0000 (16:48 +0000)]
Merge branch 'wip/dueno/build-fixes3' into 'master'
Minor build fixes for 3.7.3 release (part 2)
See merge request gnutls/gnutls!1516
Daiki Ueno [Sun, 16 Jan 2022 15:19:53 +0000 (16:19 +0100)]
tests: suppress GCC -fanalyzer warnings
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 16 Jan 2022 15:00:10 +0000 (16:00 +0100)]
.gitignore: ignore more files
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 16 Jan 2022 14:59:01 +0000 (15:59 +0100)]
src: avoid overriding noinst_PROGRAMS
In src, we now have two helper programs: systemkey and dumpcfg.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Thu, 13 Jan 2022 13:30:02 +0000 (14:30 +0100)]
build: hide maintainer tool invocation behind AM_V_GEN
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sat, 15 Jan 2022 14:33:53 +0000 (14:33 +0000)]
Merge branch 'wip/dueno/remove-autogen' into 'master'
remove autogen dependency
Closes #775, #774, and #773
See merge request gnutls/gnutls!1506
Alexander Sosedkin [Thu, 13 Jan 2022 13:35:07 +0000 (14:35 +0100)]
tests: use more aliases in tests for better alias testing coverage
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Fri, 7 Jan 2022 09:02:32 +0000 (10:02 +0100)]
.gitlab-ci.yml: run static analyzers on Python files
This runs a couple of code analysis on the Python scripts added to
remove AutoGen dependency.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Fri, 7 Jan 2022 08:58:11 +0000 (09:58 +0100)]
.gitlab-ci.yml: bump cache key for python3 detection
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 5 Jan 2022 07:09:36 +0000 (08:09 +0100)]
README.md: mention Python as requirement instead of AutoGen
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 5 Jan 2022 06:39:10 +0000 (07:39 +0100)]
src: remove AutoGen .def files
As neither the tools nor documentation depends on AutoGen, we don't
need to include the AutoGen definition files.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 5 Jan 2022 06:24:03 +0000 (07:24 +0100)]
doc: generate man-pages from JSON
This replaces man-pages generation previously provided by the autogen
-Tagman.tpl command with a Python script (gen-cmd-man.py).
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 4 Jan 2022 08:06:21 +0000 (09:06 +0100)]
doc: generate texinfo files from JSON
This replaces texinfo generation previously provided by the autogen
-Tagtexi.tpl command with a Python script (gen-cmd-texi.py).
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 3 Jan 2022 10:02:43 +0000 (11:02 +0100)]
src: remove included copy of libopts
As no tools link with libopts anymore, we don't need to include it in
the distribution.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 3 Jan 2022 09:30:34 +0000 (10:30 +0100)]
src: replace autoopts/libopts with minimal config parser
This replaces configuration file parsing code previously provided by
<autoopts/options.h>, with a minimal compatible implementation.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Fri, 31 Dec 2021 17:13:58 +0000 (18:13 +0100)]
src: generate option handling code from JSON
This replaces AutoGen based command-line parser with a Python
script (gen-getopt.py), which takes JSON description as the input.
The included JSON files were converted one-off using the parse-autogen
program: https://gitlab.com/dueno/parse-autogen.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 4 Jan 2022 14:18:26 +0000 (15:18 +0100)]
python: add library for handling JSON-based option description
This adds the jsonopts Python module used by the command-line parser
generator and documentation generators in the following commits. This
also bumps the required Python interpreter version to 3.6.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Co-authored-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Fri, 14 Jan 2022 10:08:48 +0000 (10:08 +0000)]
Merge branch 'wip/dueno/gost-pkcs12' into 'master'
pkcs12: use the correct MAC algorithm for GOST key generation
Closes #1225
See merge request gnutls/gnutls!1514
Daiki Ueno [Thu, 13 Jan 2022 08:36:52 +0000 (09:36 +0100)]
pkcs12: use the correct MAC algorithm for GOST key generation
According to the latest TC-26 requirements, the MAC algorithm used for
PBKDF2 should always be HMAC_GOSTR3411_2012_512.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 12 Jan 2022 10:22:21 +0000 (10:22 +0000)]
Merge branch 'wip/dueno/build-fixes2' into 'master'
Minor build fixes before the 3.7.3 release
See merge request gnutls/gnutls!1511
Daiki Ueno [Wed, 12 Jan 2022 07:38:42 +0000 (07:38 +0000)]
Merge branch 'wip/dueno/cpuid' into 'master'
accelerated: fix CPU feature detection for Intel CPUs
See merge request gnutls/gnutls!1487
Daiki Ueno [Wed, 12 Jan 2022 07:20:28 +0000 (07:20 +0000)]
Merge branch 'curve-keygen-allowlist-test' into 'master'
Extend system-override-curves-allowlist test with key generation
See merge request gnutls/gnutls!1500
Daiki Ueno [Wed, 12 Jan 2022 07:15:24 +0000 (08:15 +0100)]
tests: simple: check if the digest algorithm is compiled in
When the library is built with --disable-gost, gnutls_digest_get_id
returns GNUTLS_DIG_UNKNOWN for GOST algorithms.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 11 Jan 2022 13:07:56 +0000 (14:07 +0100)]
x509: fix potential wrong usage of memcpy
Spotted by GCC analyzer:
common.c:552:17: warning: use of NULL 'out.data' where non-null expected [CWE-476] [-Wanalyzer-null-argument]
552 | memcpy(output_data, out.data, (size_t) out.size);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 9 Jan 2022 07:34:52 +0000 (08:34 +0100)]
cert-auth: suppress false-positive warnings with GCC analyzer
When compiled with gcc -fanalyzer, it reports:
cert.c: In function '_gnutls_pcert_to_auth_info':
cert.c:85:17: error: dereference of NULL 'info' [CWE-476] [-Werror=analyzer-null-dereference]
85 | if (info->raw_certificate_list != NULL) {
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 12 Jan 2022 06:54:10 +0000 (06:54 +0000)]
Merge branch 'wip/dueno/pkcs12' into 'master'
certtool: --to-p12: use modern algorithms by default
See merge request gnutls/gnutls!1499
Daiki Ueno [Fri, 7 Jan 2022 16:48:22 +0000 (17:48 +0100)]
gnutls_pkcs12_generate_mac: use SHA256 by default
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 20 Dec 2021 15:16:23 +0000 (16:16 +0100)]
.gitlab-ci.yml: reduce PKCS#12 iteration count while testing
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 21 Dec 2021 14:02:45 +0000 (15:02 +0100)]
tests: check algorithms for generating PKCS#12 file
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sat, 8 Jan 2022 10:04:40 +0000 (10:04 +0000)]
Merge branch 'wip/dueno/fipscontext' into 'master'
fips: add functions to inspect thread-local FIPS operation state
See merge request gnutls/gnutls!1465
Daiki Ueno [Sun, 26 Dec 2021 16:40:42 +0000 (17:40 +0100)]
cipher-api-test: mention why it is written using fork
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 23 Nov 2021 14:23:34 +0000 (15:23 +0100)]
fips: plumb service indicator to symmetric key crypto operations
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Co-authored-by: Pedro Monreal <pmonrealgonzalez@suse.de>
Daiki Ueno [Tue, 31 Aug 2021 11:29:45 +0000 (13:29 +0200)]
fips: plumb service indicator to public key crypto operations
This installs service indicator state transitions in certain public
key operations in gnutls_crypto_pk_st, namely:
* fallible operations
- encrypt
- sign
- generate_keys
- derive
* infallible operations
- decrypt, decrypt2
- verify
other operations, such as generate_params, are not considered as
crypto operation. Note that fallible operations above mean that those
return value could indicate error, while infallible operations do not
have distinction between errors and failures: decrypt/verify failures
are treated as a successful completion of the operation.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Co-authored-by: Pedro Monreal <pmonrealgonzalez@suse.de>
Daiki Ueno [Tue, 21 Dec 2021 14:17:55 +0000 (15:17 +0100)]
_gnutls_pkcs_generate_key: use HMAC-SHA256 for PBKDF2
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 20 Dec 2021 15:34:30 +0000 (16:34 +0100)]
pkcs12: determine iteration count for MAC at build time
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 20 Dec 2021 15:13:06 +0000 (16:13 +0100)]
pkcs7: determine iteration count for PBKDF2 at build time
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 20 Dec 2021 14:56:24 +0000 (15:56 +0100)]
certtool: --to-p12: use modern algorithms by default
Currently certtool uses PKCS12-3DES-SHA1 for encrypting keys in
PKCS#12, while it is suggested to migrate to more modern algorithms,
namely AES-128-CBC with PBKDF2 and SHA-256:
https://bugzilla.redhat.com/show_bug.cgi?id=
1759982
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Fri, 23 Jul 2021 08:31:08 +0000 (10:31 +0200)]
fips: add functions to inspect thread-local FIPS operation state
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Thu, 6 Jan 2022 13:01:49 +0000 (13:01 +0000)]
Merge branch 'tmp-2022-gtkdoc' into 'master'
Fix gtk-doc build, Debian bug #
1003075
See merge request gnutls/gnutls!1507
Andreas Metzler [Thu, 6 Jan 2022 06:17:01 +0000 (07:17 +0100)]
Drop unquoted angle brackets in gtk-doc comment.
Signed-off-by: Andreas Metzler <ametzler@bebt.de>
Andreas Metzler [Thu, 6 Jan 2022 06:15:31 +0000 (07:15 +0100)]
Fix gtk-doc build, use http URI in sgml master.
Signed-off-by: Andreas Metzler <ametzler@bebt.de>
Daiki Ueno [Wed, 5 Jan 2022 07:26:01 +0000 (07:26 +0000)]
Merge branch 'p11tool-always-auth' into 'master'
p11tool: add --mark-always-authenticate option
See merge request gnutls/gnutls!1504
Alon Bar-Lev [Sat, 1 Jan 2022 19:12:51 +0000 (21:12 +0200)]
p11tool: add --mark-always-authenticate option
Signed-off-by: Alon Bar-Lev <alon.barlev@gmail.com>
Daiki Ueno [Mon, 3 Jan 2022 06:53:34 +0000 (06:53 +0000)]
Merge branch 'copyright' into 'master'
doc: updated copyrights for 2022
See merge request gnutls/gnutls!1505
Alon Bar-Lev [Sun, 2 Jan 2022 17:31:33 +0000 (19:31 +0200)]
doc: updated copyrights for 2022
Signed-off-by: Alon Bar-Lev <alon.barlev@gmail.com>
Daiki Ueno [Thu, 18 Nov 2021 18:02:03 +0000 (19:02 +0100)]
accelerated: fix CPU feature detection for Intel CPUs
This fixes read_cpuid_vals to correctly read the CPUID quadruple, as
well as to set the bit the ustream CRYPTOGAMS uses to identify Intel
CPUs.
Suggested by Rafael Gieschke in:
https://gitlab.com/gnutls/gnutls/-/issues/1282
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 22 Dec 2021 16:00:03 +0000 (17:00 +0100)]
padlock: reset _gnutls_x86_cpuid_s only after padlock check succeeds
Otherwise it clears _gnutls_x86_cpuid_s which may already hold valid
CPUID detected for Intel and AMD CPUs.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 22 Dec 2021 15:16:02 +0000 (15:16 +0000)]
Merge branch 'wip/dueno/nettle-hash' into 'master'
wrap_nettle_hash_fast: avoid calling _update with zero-length input
See merge request gnutls/gnutls!1503
Daiki Ueno [Wed, 22 Dec 2021 09:37:01 +0000 (09:37 +0000)]
Merge branch 'wip/dueno/hash-copy-doc' into 'master'
gnutls_{hash,hmac}_copy: mention the functions do not always work
See merge request gnutls/gnutls!1502
Daiki Ueno [Wed, 22 Dec 2021 08:12:25 +0000 (09:12 +0100)]
wrap_nettle_hash_fast: avoid calling _update with zero-length input
As Nettle's hash update functions internally call memcpy, providing
zero-length input may cause undefined behavior.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 22 Dec 2021 07:22:04 +0000 (08:22 +0100)]
gnutls_{hash,hmac}_copy: mention the functions do not always work
It is known that some built-in accelerated implementation, such as
AF_ALG, does not support copying hash/hmac contexts. This expands the
documentation to suggest checking the return value of those functions.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Alexander Sosedkin [Mon, 20 Dec 2021 16:47:36 +0000 (17:47 +0100)]
tests: extend system-override-curves-allowlist with key generation
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Alexander Sosedkin [Mon, 20 Dec 2021 15:50:59 +0000 (16:50 +0100)]
tests: tweak system-override-curves-allowlist insignificantly
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Sat, 18 Dec 2021 16:37:58 +0000 (16:37 +0000)]
Merge branch 'tpm2-dep-correction' into 'master'
README: document tpm2-tss-engine test dependency
See merge request gnutls/gnutls!1498
Alexander Sosedkin [Fri, 17 Dec 2021 17:49:27 +0000 (18:49 +0100)]
README: document tpm2-tss-engine test dependency
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Fri, 17 Dec 2021 16:14:19 +0000 (16:14 +0000)]
Merge branch 'ktls_api' into 'master'
ktls: API
See merge request gnutls/gnutls!1477
Daiki Ueno [Fri, 17 Dec 2021 16:13:55 +0000 (16:13 +0000)]
Merge branch 'aarch64-sha384' into 'master'
use sha384_digest in lib/accelerated/aarch64/sha-aarch64.c sha384
See merge request gnutls/gnutls!1497
Alexander Sosedkin [Thu, 16 Dec 2021 11:46:38 +0000 (12:46 +0100)]
use sha384_digest in lib/accelerated/aarch64/sha-aarch64.c sha384
Mirrors https://gitlab.com/gnutls/gnutls/-/merge_requests/1466
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Frantisek Krenzelok [Thu, 2 Dec 2021 15:35:31 +0000 (16:35 +0100)]
ktls: flags
ktls enum flags API
Signed-off-by: Frantisek Krenzelok <krenzelok.frantisek@gmail.com>
Frantisek Krenzelok [Fri, 15 Oct 2021 13:00:17 +0000 (15:00 +0200)]
KTLS: API
ktls is enabled by default, we can check if inicialization was
succesfull with gnutls_transport_is_ktls_enabled
Signed-off-by: Frantisek Krenzelok <krenzelok.frantisek@gmail.com>
Daiki Ueno [Wed, 15 Dec 2021 12:06:15 +0000 (12:06 +0000)]
Merge branch 'fix-asan-out-of-tree' into 'master'
tests: fix out of tree builds with ASAN
See merge request gnutls/gnutls!1496
Daiki Ueno [Tue, 14 Dec 2021 11:27:42 +0000 (11:27 +0000)]
Merge branch 'wip/dueno/sct' into 'master'
Minor cleanup on the new X509 CT code
See merge request gnutls/gnutls!1495
Daiki Ueno [Thu, 9 Dec 2021 10:22:14 +0000 (11:22 +0100)]
.gitignore: ignore tests/x509cert-ct
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Thu, 9 Dec 2021 10:03:50 +0000 (11:03 +0100)]
X509 CT: defer filling in the length field
This eliminates the need of precalculating the payload size, to make
it easier to adapt to new format.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Alexander Sosedkin [Fri, 10 Dec 2021 12:47:21 +0000 (13:47 +0100)]
tests: fix out of tree builds with ASAN
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Alexander Sosedkin [Fri, 10 Dec 2021 13:44:31 +0000 (13:44 +0000)]
Merge branch 'test-allowlisting-proto-tcp' into 'master'
test for gnutls_protocol_set_enabled, TCP
See merge request gnutls/gnutls!1494
Alexander Sosedkin [Thu, 11 Nov 2021 13:05:40 +0000 (14:05 +0100)]
tests: add protocol-set-allowlist
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Alexander Sosedkin [Thu, 11 Nov 2021 13:04:54 +0000 (14:04 +0100)]
tests: add tcp_connect to utils
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Thu, 9 Dec 2021 09:48:58 +0000 (10:48 +0100)]
X509 CT: use size_t for array index instead of unsigned
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Ander Juaristi [Sat, 4 Dec 2021 19:58:02 +0000 (19:58 +0000)]
Merge branch 'aja-certificate-transparency' into 'master'
Read Certificate Transparency (RFC 6962) SCT extension
Closes #232
See merge request gnutls/gnutls!1367
Ander Juaristi [Fri, 26 Nov 2021 17:20:44 +0000 (18:20 +0100)]
Update symbols
Signed-off-by: Ander Juaristi <a@juaristi.eus>
Ander Juaristi [Wed, 17 Nov 2021 18:28:50 +0000 (19:28 +0100)]
devel: Suppress new API functions
Signed-off-by: Ander Juaristi <a@juaristi.eus>
Ander Juaristi [Sat, 28 Nov 2020 18:04:35 +0000 (19:04 +0100)]
x509 CT: Add tests
Signed-off-by: Ander Juaristi <a@juaristi.eus>
Ander Juaristi [Mon, 15 Nov 2021 19:03:12 +0000 (20:03 +0100)]
x509 CT: implement new public API
This commit implements import and export functions for the X.509
Certificate Transparency Signed Certificate Timestamp (SCT) extension
(RFC 6962).
A new constant GNUTLS_X509EXT_OID_CT_SCT is introduced
with the value "1.3.6.1.4.1.11129.2.4.2".
The following new public API functions are introduced:
- gnutls_x509_ext_ct_scts_init
- gnutls_x509_ext_ct_scts_deinit
- gnutls_x509_ext_ct_import_scts
- gnutls_x509_ext_ct_export_scts
- gnutls_x509_ct_sct_get_version
- gnutls_x509_ct_sct_get
Signed-off-by: Ander Juaristi <a@juaristi.eus>
František Krenželok [Thu, 2 Dec 2021 11:14:40 +0000 (11:14 +0000)]
Merge branch 'wip/dueno/abi-check-latest' into 'master'
build: stop running abi-dump-latest at "make files-update"
See merge request gnutls/gnutls!1491
Daiki Ueno [Tue, 30 Nov 2021 13:33:33 +0000 (14:33 +0100)]
devel/libgnutls.abignore: ignore drbg_aes_* functions
These functions are only defined when compiled with
--enable-fips140-mode.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 29 Nov 2021 14:20:48 +0000 (14:20 +0000)]
Merge branch 'wip/dueno/config-allowlisting' into 'master'
priority: support allowlisting in configuration file
Closes #1172
See merge request gnutls/gnutls!1427
Daiki Ueno [Thu, 6 May 2021 10:41:40 +0000 (12:41 +0200)]
priority: support allowlisting in configuration file
This adds a new mode of interpreting the [overrides] section. If
"override-mode" is set to "allowlisting" in the [global] section, all
the algorithms (hashes, signature algorithms, curves, and versions)
are initially marked as insecure/disabled. Then the user can enable
them by specifying allowlisting keywords such as "secure-hash" in the
[overrides] section.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Co-authored-by: Alexander Sosedkin <asosedkin@redhat.com>
Daiki Ueno [Sat, 27 Nov 2021 16:57:42 +0000 (16:57 +0000)]
Merge branch 'wip/dueno/valgrind-tests' into 'master'
build: update to use the latest valgrind-tests module from Gnulib
Closes #1253
See merge request gnutls/gnutls!1488
Daiki Ueno [Sat, 27 Nov 2021 15:48:51 +0000 (16:48 +0100)]
CONTRIBUTING.md: clarify how to introduce new API
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sat, 27 Nov 2021 15:39:41 +0000 (16:39 +0100)]
release-steps: "make abi-dump-latest" at release time
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sat, 27 Nov 2021 15:36:17 +0000 (16:36 +0100)]
build: stop running abi-dump-latest at "make files-update"
The procedure of registering ABI updates has changed in
bd3c78b9d10937adb1855b85bca1864972a1c986 .
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Wed, 24 Nov 2021 17:44:13 +0000 (18:44 +0100)]
build: update to use the latest valgrind-tests module from Gnulib
This adjust the existing valgrind invocations in the test suite with:
https://www.gnu.org/software/gnulib/manual/html_node/Valgrind-options.html
- make --suppressions option to per directory, using AM_VALGRINDFLAGS
- use LOG_VALGRIND for LOG_COMPILER
- quote '$(LOG_VALGRIND)' in TESTS_ENVIRONMENT
- move gl_VALGRIND_TESTS_DEFAULT_NO call before gl_INIT
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Fri, 26 Nov 2021 17:11:45 +0000 (17:11 +0000)]
Merge branch 'fix_non_vla_02' into 'master'
sockets: fixed building for Windows with compilers without VLA support (alternative version)
See merge request gnutls/gnutls!1490
Evgeny Grin [Fri, 26 Nov 2021 11:08:22 +0000 (14:08 +0300)]
sockets: fixed compiler warning on Windows x32
Signed-off-by: Evgeny Grin <k2k@narod.ru>
Evgeny Grin [Fri, 26 Nov 2021 10:50:52 +0000 (13:50 +0300)]
sockets: fixed building for Windows with compilers without VLA support
Signed-off-by: Evgeny Grin <k2k@narod.ru>
Daiki Ueno [Wed, 5 May 2021 14:27:55 +0000 (16:27 +0200)]
priority: refactor config file parsing
This adds the following refactoring:
- avoid side-effects during parsing the config file, by separating
application phase; the parsed configuration can be applied globally
with cfg_apply, after validation
- make _gnutls_*_mark_{disabled,insecure} take an ID instead of the
name
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Mon, 22 Nov 2021 10:59:38 +0000 (10:59 +0000)]
Merge branch 'wip/dueno/thr' into 'master'
locks: couple of improvements using Gnulib glthread
See merge request gnutls/gnutls!1485
Daiki Ueno [Tue, 16 Nov 2021 17:46:41 +0000 (18:46 +0100)]
locks: deprecate gnutls_global_set_mutex
As the library now uses static mutexes, rwlocks, and onces, it doesn't
make much sense to only replace dynamic mutex usage.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 14 Nov 2021 13:57:15 +0000 (14:57 +0100)]
locks: use once execution for on-demand initialization of globals
This makes sure that the global variables are initialized only once.
Most of those variables are initialized at ELF constructor, though a
couple of occasions they are initialized on-demand: the global keylog
file pointer and TPM2 TCTI context. To properly protect the
initialization this patch uses gl_once provided by Gnulib.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 14 Nov 2021 15:39:29 +0000 (16:39 +0100)]
locks: rework rwlock primitives
Remove GNUTLS_STATIC_RWLOCK_*LOCK macros and respect return values of
rwlock primitives.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 16 Nov 2021 17:20:24 +0000 (18:20 +0100)]
pkcs11: switch to using static mutex
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Tue, 16 Nov 2021 17:00:12 +0000 (18:00 +0100)]
verify-tofu: switch to using static mutex for locking
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 14 Nov 2021 13:04:59 +0000 (14:04 +0100)]
locks: replace custom mutex wrappers with "glthread/lock.h"
As Gnulib provides portability wrappers of mutex implementations, we
don't need to provide similar wrappers by ourselves.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Sun, 14 Nov 2021 07:12:38 +0000 (07:12 +0000)]
Merge branch 'wip/dueno/tpm2' into 'master'
Port openconnect TPM2 code
Closes #594
See merge request gnutls/gnutls!1460
Nikos Mavrogiannopoulos [Fri, 22 Mar 2019 13:52:10 +0000 (14:52 +0100)]
Port openconnect TPM2 code
This introduces transparent loading of TPM2 keys which are in PEM
form by gnutls_privkey_import_x509_raw() and higher level functions
which wrap it.
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
Co-authored-by: David Woodhouse <dwmw2@infradead.org>
Co-authored-by: Daiki Ueno <ueno@gnu.org>
Daiki Ueno [Thu, 11 Nov 2021 06:22:34 +0000 (06:22 +0000)]
Merge branch 'abs-top-builddir-fix' into 'master'
tests: pass $abs_top_builddir more consistently
See merge request gnutls/gnutls!1484
Alexander Sosedkin [Mon, 8 Nov 2021 18:07:28 +0000 (19:07 +0100)]
tests: set $abs_top_builddir in more places
`$abs_top_builddir` has been used all across tests' subdirectories
(through tests/scripts/common.sh)
but has only been defined for tests/suite/ ones.
Defining it in other Makefiles where `top_builddir` is being passed.
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>