]> git.ipfire.org Git - thirdparty/curl.git/log
thirdparty/curl.git
3 months agotool_formparse: polish error message + make two functions static
Daniel Stenberg [Wed, 6 May 2026 06:50:44 +0000 (08:50 +0200)] 
tool_formparse: polish error message + make two functions static

Closes #21510

3 months agoprotocol: introduce typedef for the do_more() function 21509/head
Daniel Stenberg [Tue, 5 May 2026 16:39:12 +0000 (18:39 +0200)] 
protocol: introduce typedef for the do_more() function

Instead of using magic values -1, 0 and -1 using enum.

Closes #21509

3 months agomulti: make multi_runsingle use sub functions for states
Daniel Stenberg [Tue, 5 May 2026 13:02:32 +0000 (15:02 +0200)] 
multi: make multi_runsingle use sub functions for states

The state machine now calls dedicated sub functions for each state, to
reduce the size and complexity.

Closes #21506

3 months agohostip: convert Curl_resolv_unix to static resolv_unix
Daniel Stenberg [Tue, 5 May 2026 15:09:36 +0000 (17:09 +0200)] 
hostip: convert Curl_resolv_unix to static resolv_unix

It was only used within this file

Closes #21508

3 months agohsts: rename Curl_hsts() to hsts_check() and make it static
Daniel Stenberg [Tue, 5 May 2026 15:01:41 +0000 (17:01 +0200)] 
hsts: rename Curl_hsts() to hsts_check() and make it static

It is no longer used outside of hsts.c

Closes #21507

3 months agoGHA: verify function-lengths
Daniel Stenberg [Mon, 4 May 2026 12:25:47 +0000 (14:25 +0200)] 
GHA: verify function-lengths

No production code function is allowed to be longer than 500 lines.

The lib/setopt.c:setopt_cptr function is currently exempt, as a single
exception until we make it smaller.

Closes #21492

3 months agosocks_gssapi: simplify Curl_SOCKS5_gssapi_negotiate
Daniel Stenberg [Tue, 5 May 2026 09:13:07 +0000 (11:13 +0200)] 
socks_gssapi: simplify Curl_SOCKS5_gssapi_negotiate

Also: pass in NULL when 'conf_state' is not wanted for gss_wrap() and
gss_unwrap()

Closes #21502

3 months agolib: introduce Curl_peer
Stefan Eissing [Tue, 5 May 2026 10:58:22 +0000 (12:58 +0200)] 
lib: introduce Curl_peer

`struct Curl_peer` keeps information about a communication endpoint
together. It will replace `conn->host` and `conn->conn_to_host` and
proxyinfo host. It will also become part of `struct ssl_peer`.

It has a reference counter, so an instance can be shared between
connections and filters.

Elminiates `conn->host` and `conn->connect_to_host`, used in the
proxyinfo structures. Passed to DNS resolution and socks filters, etc.

Pass peer to http proxy and socks tunnel filters. Use peer in dns filter
and resolving. Make `Curl_peer` a member in the `struct ssl_peer`.

Add `docs/internals/PEERS.md` for documentation.

Closes #21472

3 months agothrdqueue.h: minor language polish in comments
Daniel Stenberg [Tue, 5 May 2026 12:34:27 +0000 (14:34 +0200)] 
thrdqueue.h: minor language polish in comments

3 months agothrdqueue.h: forward declare curl_thrdq unconditionally
Daniel Stenberg [Tue, 5 May 2026 09:37:03 +0000 (11:37 +0200)] 
thrdqueue.h: forward declare curl_thrdq unconditionally

This allows the unit tests to have a prototype involving such a struct
pointer - even when the build is done without threaded resolver.

Follow-up to 117d50b4bf48ca04908f87dd665ba

Closes #21503

3 months agotool_formparse.c: use define instead of magic number
Daniel Stenberg [Tue, 5 May 2026 07:20:47 +0000 (09:20 +0200)] 
tool_formparse.c: use define instead of magic number

The longest header lines accepted for the -F option is now a define
instead of a magic number. I also bumped it to be an even 8K.

When fixing, I noticed that for some OOM errors curl would display two
error messages. Also fixed here.

Closes #21501

3 months agothrdqueue: make thrdq_await_done only for unit tests
Daniel Stenberg [Mon, 4 May 2026 21:44:25 +0000 (23:44 +0200)] 
thrdqueue: make thrdq_await_done only for unit tests

It is not used for anything else, so drop Curl_ and make it conditional
accordingly.

Closes #21499

3 months agogtls: fix some typos
Daniel Stenberg [Mon, 4 May 2026 21:33:49 +0000 (23:33 +0200)] 
gtls: fix some typos

Also make gtls_get_ietf_proto() static

Found by Copilot

Closes #21498

3 months agolib: two minor typos
Daniel Stenberg [Mon, 4 May 2026 14:17:11 +0000 (16:17 +0200)] 
lib: two minor typos

Spotted by Copilot

Closes #21496

3 months agoshow-headers.md: mention bold headers and --no-styled-output
Daniel Stenberg [Mon, 4 May 2026 15:19:04 +0000 (17:19 +0200)] 
show-headers.md: mention bold headers and --no-styled-output

Mentioned-by: Sollace on github
Fixes #21495
Closes #21497

3 months agosocks_gssapi: tiny Curl_SOCKS5_gssapi_negotiate cleanups
Daniel Stenberg [Mon, 4 May 2026 10:47:12 +0000 (12:47 +0200)] 
socks_gssapi: tiny Curl_SOCKS5_gssapi_negotiate cleanups

- use 'result' instead of 'code' for CURLcode variable
- use aprintf() instead of malloc + snprintf

Closes #21493

3 months agolibcurl-easy.md: minor clarifications
Daniel Stenberg [Mon, 4 May 2026 09:13:19 +0000 (11:13 +0200)] 
libcurl-easy.md: minor clarifications

Closes #21491

3 months agomime: simplify Curl_mime_prepare_headers
Daniel Stenberg [Mon, 4 May 2026 08:50:50 +0000 (10:50 +0200)] 
mime: simplify Curl_mime_prepare_headers

Make add_content_disposition() a sub function for that single purpose.

Closes #21490

3 months agotool_formparse: cleanups
Daniel Stenberg [Mon, 4 May 2026 08:28:10 +0000 (10:28 +0200)] 
tool_formparse: cleanups

- explain the get_param_part() function
- make it parse only blanks like the rest of this code
- check for commas explicitly when scanning multiple files (to help code
  understanding)

Closes #21489

3 months agogtls: simplify Curl_gtls_verifyserver
Daniel Stenberg [Mon, 4 May 2026 07:55:26 +0000 (09:55 +0200)] 
gtls: simplify Curl_gtls_verifyserver

Move peer certificate verification logic into gtls_verify_cert()

Closes #21488

3 months agosetopt: changing the proxy port is also a proxy change
Daniel Stenberg [Sat, 2 May 2026 15:18:00 +0000 (17:18 +0200)] 
setopt: changing the proxy port is also a proxy change

Test 1589 verifies.

Closes #21485

3 months agoGHA: bump actions and pips
dependabot[bot] [Fri, 1 May 2026 17:50:42 +0000 (17:50 +0000)] 
GHA: bump actions and pips

- update action `actions/cache` from 5.0.4 to 5.0.5
- update action `actions/upload-artifact` from 7.0.0 to 7.0.1
- update action `github/codeql-action` from 4.32.4 to 4.35.2
- update action `msys2/setup-msys2` from 2.31.0 to 2.31.1

- update pip `filelock` from 3.25.2 to 3.29.0
- update pip `impacket` to 0.13.0
- update pip `ruff` from 0.15.10 to 0.15.12

Closes #21483
Closes #21482

3 months agotool_formparse.c: fix two minor comment typos
Daniel Stenberg [Fri, 1 May 2026 09:28:30 +0000 (11:28 +0200)] 
tool_formparse.c: fix two minor comment typos

Pointed out by Copilot

Closes #21480

3 months agourl: simplify parseurlandfillconn
Daniel Stenberg [Fri, 1 May 2026 09:13:27 +0000 (11:13 +0200)] 
url: simplify parseurlandfillconn

Introduce two helper functions:

- hsts_upgrade()
- setup_hostname()

Closes #21479

3 months agoRELEASE-NOTES: synced
Daniel Stenberg [Fri, 1 May 2026 09:34:15 +0000 (11:34 +0200)] 
RELEASE-NOTES: synced

Also bump the curlver to tenative 8.20.1

3 months agoasyn-thrdd: fix result processing without wakeup socketpair
Stefan Eissing [Thu, 30 Apr 2026 14:53:02 +0000 (16:53 +0200)] 
asyn-thrdd: fix result processing without wakeup socketpair

When building curl 8.20.0 with socketpair disabled, there is no
wakeup socket and the resolve results are not processed.

This fix performs result processing in the absence of a wakeup
socket before checking the resolve result.

Closes #21476

3 months agouser-agent.md: mention double quotes too
Daniel Stenberg [Thu, 30 Apr 2026 20:50:27 +0000 (22:50 +0200)] 
user-agent.md: mention double quotes too

Reported-by: Jeremy Nicoll
Bug: https://curl.se/mail/archive-2026-04/0029.html
Closes #21477

3 months agotool_formparse: simplify get_param_part
Daniel Stenberg [Thu, 30 Apr 2026 12:51:47 +0000 (14:51 +0200)] 
tool_formparse: simplify get_param_part

Introduce a few sub functions to reduce complexity

Closes #21478

3 months agotidy-up: miscellaneous
Viktor Szakats [Wed, 29 Apr 2026 13:27:37 +0000 (15:27 +0200)] 
tidy-up: miscellaneous

- sha256: fix backend priority in comment.
- URLs: link to IETF URLs to the HTML document, to match others.
- VERSIONS.md: use unified date format for recent entries too.
  Ref: https://github.com/curl/curl-www/commit/ce5d32032f8d3d8601f3ef022bbca485020d1bb9
- GHA/labeler.yml: alpha-sort file masks in a label block.
- tests/server/mqttd: fix call arg list in a disabled function.
- tests/server/mqttd: fix comment.

Closes #21473

3 months agoGHA/curl-for-win: switch riscv job to debian:stable (testing broke)
Viktor Szakats [Thu, 30 Apr 2026 14:06:35 +0000 (16:06 +0200)] 
GHA/curl-for-win: switch riscv job to debian:stable (testing broke)

```
The following packages have unmet dependencies:
[...]
E: Unable to satisfy dependencies. Reached two conflicting assignments:
   1. musl-dev:amd64=1.2.5-3+b1 is selected for install
   2. musl-dev:amd64 is not selected for install because:
      1. musl-dev:riscv64=1.2.5-3 is selected for install
      2. musl-dev:amd64 Breaks musl-dev:riscv64 (!= 1.2.5-3+b1)
```
Ref: https://github.com/curl/curl/actions/runs/25168601672/job/73785600341#step:3:154

Closes #21475

3 months agomqtt: validate PINGRESP and DISCONNECT have remaining_length == 0
Raymond Steen [Wed, 29 Apr 2026 07:27:39 +0000 (10:27 +0300)] 
mqtt: validate PINGRESP and DISCONNECT have remaining_length == 0

Per MQTT 3.1.1 sections 3.13.1 and 3.14.1, PINGRESP and DISCONNECT fixed
headers must have remaining_length set to zero. The previous code
dispatched to mqtt->nextstate based on the queued state alone without
validating remaining_length for these no-payload packet types, allowing
a malicious broker to send a PINGRESP with non-zero remaining_length
whose trailing bytes would be interpreted as the payload of whatever
message type was queued (CONNACK, SUBACK, etc.).

The exploitation path turned out to be narrow — curl sends data to the
server the user chose to talk to — but the spec violation and the
resulting protocol-state error are real. Reject the malformed packets
with CURLE_WEIRD_SERVER_REPLY before state dispatch.

Reported-by: Raymond Steen <raymond@vortiqxconsilium.com>
Found by VORTIQ-X VXF Framework
Bug: https://hackerone.com/reports/3702718

Signed-off-by: Raymond Steen <raymond@vortiqxconsilium.com>
Closes #21465

3 months agoGHA/linux: work around Linuxbrew install failure
Viktor Szakats [Wed, 29 Apr 2026 19:51:43 +0000 (21:51 +0200)] 
GHA/linux: work around Linuxbrew install failure

Root cause unknown, it appeared today without any local change:
```
==> Installing dependencies for libssh2: openssl@3 and zlib-ng-compat
==> Installing libssh2 dependency: openssl@3
==> Pouring openssl@3--3.6.2.x86_64_linux.bottle.tar.gz
Error: A `brew install openssl@4 libssh2 libngtcp2 libnghttp3 c-ares` process has already locked /home/linuxbrew/.linuxbrew/Cellar/openssl@4.
Please wait for it to finish or terminate it to continue.
Error: Process completed with exit code 1.
```
Ref: https://github.com/curl/curl/actions/runs/25129061781/job/73650161844?pr=21468#step:2:407

Last known good run: https://github.com/curl/curl/actions/runs/25038989485/job/73337289504

Ref: 1fbffe7f08f0d551038520b569b817f58084f77b #21379

Closes #21469

3 months agoRELEASE-NOTES: synced curl-8_20_0
Daniel Stenberg [Wed, 29 Apr 2026 05:45:21 +0000 (07:45 +0200)] 
RELEASE-NOTES: synced

curl 8.20.0 release

plus VERSIONS.md update

3 months agoTHANKS: names from the 8.20.0 release
Daniel Stenberg [Wed, 29 Apr 2026 05:45:21 +0000 (07:45 +0200)] 
THANKS: names from the 8.20.0 release

3 months agotidy-up: a cmake warning message and a variable name
Viktor Szakats [Mon, 27 Apr 2026 20:21:27 +0000 (22:21 +0200)] 
tidy-up: a cmake warning message and a variable name

Spotted by GitHub Code Quality

Closes #21462

3 months agobuild: stop building and installing `runtests.1` and `testcurl.1`
Viktor Szakats [Mon, 27 Apr 2026 15:51:16 +0000 (17:51 +0200)] 
build: stop building and installing `runtests.1` and `testcurl.1`

The corresponding tools are never installed, and both are dev tools.
Refer to their `.md` originals instead.

Also markdownify text in lines nearby.

Ref: https://github.com/curl/curl/pull/21460#issuecomment-4328258450

Closes #21461

3 months agocmake: do not install shell completions when `BUILD_CURL_EXE=OFF`
Viktor Szakats [Mon, 27 Apr 2026 15:12:42 +0000 (17:12 +0200)] 
cmake: do not install shell completions when `BUILD_CURL_EXE=OFF`

Follow-up to 74542c1f4bfea75f92562075370fd839891cc440 #21459

Closes #21460

3 months agocmake: do not install `wcurl` when `BUILD_CURL_EXE=OFF`
Viktor Szakats [Mon, 27 Apr 2026 15:00:41 +0000 (17:00 +0200)] 
cmake: do not install `wcurl` when `BUILD_CURL_EXE=OFF`

Skip installing `wcurl.1` also.

Reported-by: Daniel Schulte
Fixes #21458
Follow-up to 23bed347b38922779382599f8b72c4d762add7bd #17035

Closes #21459

3 months agoGHA/checksrc: switch to zizmor `--persona` option
Viktor Szakats [Mon, 27 Apr 2026 12:55:40 +0000 (14:55 +0200)] 
GHA/checksrc: switch to zizmor `--persona` option

Closes #21457

3 months agotidy-up: whitespace
Viktor Szakats [Wed, 15 Apr 2026 21:57:35 +0000 (23:57 +0200)] 
tidy-up: whitespace

Closes #21456

3 months agowrite-out.md: minor language fix
Daniel Stenberg [Mon, 27 Apr 2026 09:41:34 +0000 (11:41 +0200)] 
write-out.md: minor language fix

Pointed out by Copilot

Closes #21455

3 months agotool_dirhie: fix to create drive-relative directory
Viktor Szakats [Sun, 26 Apr 2026 11:38:47 +0000 (13:38 +0200)] 
tool_dirhie: fix to create drive-relative directory

Fix to create the top directory `foo` when specified as
`X:foo\bar\filename`, on Windows and MS-DOS. Add test to verify.

Caught by Codex Security

Follow-up to 787ee935acd5867bdac836b2043b6095eed2c29e #16566

Closes #21449

3 months agotunits: initialize global `tool_stderr`
Viktor Szakats [Mon, 27 Apr 2026 08:49:45 +0000 (10:49 +0200)] 
tunits: initialize global `tool_stderr`

To avoid difficult to track down crashes when a tested function ends up
outputing a message via `errorf()`, `warnf()` or siblings.

Cherry-picked from #21449

Closes #21454

3 months agoruntests: fix linefeeds in log messages
Viktor Szakats [Sun, 26 Apr 2026 23:25:37 +0000 (01:25 +0200)] 
runtests: fix linefeeds in log messages

Cherry-picked from #21449

Closes #21452

3 months agounits: tidy up dynbuf init
Viktor Szakats [Sun, 26 Apr 2026 20:06:59 +0000 (22:06 +0200)] 
units: tidy up dynbuf init

Init dynbuf after global init to bring closer to use, improve
readability and sync test sources.

Closes #21451

3 months agosetopt: clear proxy auth properties when switching
Daniel Stenberg [Mon, 27 Apr 2026 07:14:51 +0000 (09:14 +0200)] 
setopt: clear proxy auth properties when switching

Verify with test 1588

Closes #21453

3 months agodocs/cmdline-opts/write-out.md: minor language edit
Daniel Stenberg [Sun, 26 Apr 2026 14:42:31 +0000 (16:42 +0200)] 
docs/cmdline-opts/write-out.md: minor language edit

3 months agodocs/cmdline-opts/write-out.md: tls_earlydata was adeded in 8.13.0
Daniel Stenberg [Sun, 26 Apr 2026 14:35:33 +0000 (16:35 +0200)] 
docs/cmdline-opts/write-out.md: tls_earlydata was adeded in 8.13.0

3 months agowrite-out.md: fix minor language mistake
Daniel Stenberg [Sun, 26 Apr 2026 14:18:12 +0000 (16:18 +0200)] 
write-out.md: fix minor language mistake

Closes #21450

3 months agoKNOWN_BUGS.md: Windows stdin relay accepts unauthenticated local connections
Daniel Stenberg [Fri, 24 Apr 2026 06:49:03 +0000 (08:49 +0200)] 
KNOWN_BUGS.md: Windows stdin relay accepts unauthenticated local connections

A windows developer could have a look at this.

Closes #21433

3 months agosectrust: fail on missing OCSP stapling
Stefan Eissing [Sat, 25 Apr 2026 08:34:06 +0000 (10:34 +0200)] 
sectrust: fail on missing OCSP stapling

When using Apple SecTrust, requiring the server to send
an OCSP response and does not, fail correctly.

Reported-by: Carlos Carrillo
Closes #21444

3 months agotest_22_httpsrr: avoid class name clash with `test_21_resolve`
Viktor Szakats [Sat, 25 Apr 2026 12:08:12 +0000 (14:08 +0200)] 
test_22_httpsrr: avoid class name clash with `test_21_resolve`

Spotted by GitHub Code Quality

Closes #21448

3 months agotidy-up: git options, ECH, HTTP/3 documentation
Viktor Szakats [Sat, 25 Apr 2026 10:59:55 +0000 (12:59 +0200)] 
tidy-up: git options, ECH, HTTP/3 documentation

- prefer `--branch` over `-b`, where missing.
- add `--depth 1` where missing.
- sync option order between docs and GHA.
- bump quiche and rustls-ffi versions in documentation.
- ECH.md: update for OpenSSL 4.

Closes #21447

3 months agotest_22_httpsrr: drop duplicate skipif conditions
Viktor Szakats [Sat, 25 Apr 2026 10:42:56 +0000 (12:42 +0200)] 
test_22_httpsrr: drop duplicate skipif conditions

Already set at class-level.

Spotted by GitHub Code Quality

Closes #21446

3 months agopytest: drop unused imports
Viktor Szakats [Sat, 25 Apr 2026 10:05:32 +0000 (12:05 +0200)] 
pytest: drop unused imports

Spotted by GitHub Code Quality

Closes #21445

3 months agoRELEASE-NOTES: synced
Daniel Stenberg [Sat, 25 Apr 2026 09:37:19 +0000 (11:37 +0200)] 
RELEASE-NOTES: synced

3 months agoRELEASE-NOTES: add missing contributors
Daniel Stenberg [Sat, 25 Apr 2026 09:28:08 +0000 (11:28 +0200)] 
RELEASE-NOTES: add missing contributors

From security reports etc

3 months agosshserver.pl: tidy up around `AllowUsers` setup
Viktor Szakats [Fri, 24 Apr 2026 20:49:10 +0000 (22:49 +0200)] 
sshserver.pl: tidy up around `AllowUsers` setup

- drop redundant space-to-`?` replacement.
- add parentheses to silence code checker.
- tidy up comments.

Follow-up to e53523fef07894991c69d907a7c7794c7ada4ff4 #14859

Closes #21442

3 months agoGHA/windows: bump stunnel to 5.78
Viktor Szakats [Fri, 24 Apr 2026 22:18:54 +0000 (00:18 +0200)] 
GHA/windows: bump stunnel to 5.78

Closes #21443

3 months agoconnect: fix typo on error message [ci skip]
Viktor Szakats [Fri, 24 Apr 2026 20:25:07 +0000 (22:25 +0200)] 
connect: fix typo on error message [ci skip]

Pointed out by GitHub Code Quality

3 months agosetup connection filter: mark as setup
Stefan Eissing [Fri, 24 Apr 2026 09:34:13 +0000 (11:34 +0200)] 
setup connection filter: mark as setup

Add CF_TYPE_SETUP to the setup connection filter so that it is
removed and destroyed after the connection has been established.

Closes #21437

3 months agosocks filter: pass operation parameters
Stefan Eissing [Fri, 24 Apr 2026 08:38:22 +0000 (10:38 +0200)] 
socks filter: pass operation parameters

Pass all operations parameters to a SOCKS filter at creation
time, not relying on "global" connectdata values.

Eliminate modifications to `conn->ip_version` when local resolving
for SOCKS4.

Do not retrieve the socket for GSSAPI blocking calls from connectdata,
but from the filters "below" the SOCKS one.

Closes #21436

3 months agombedtls: remove failf() call with first argument as NULL
Daniel Stenberg [Fri, 24 Apr 2026 15:23:05 +0000 (17:23 +0200)] 
mbedtls: remove failf() call with first argument as NULL

failf() needs an easy handle to work. This change removes the call since
there is normnally nowhere to show the output if init fails.

Bonus: improve language in an infof() call

Spotted by Copilot

Closes #21441

3 months agosshserver.pl: add option to enable KEX algorithms in sshd
Viktor Szakats [Fri, 24 Apr 2026 11:31:53 +0000 (13:31 +0200)] 
sshserver.pl: add option to enable KEX algorithms in sshd

Necessary when the libssh2/libssh client library does not support KEX
algos offered by default by the OpenSSH server. E.g. libssh2 with WinCNG
combined with OpenSSH 10+.

Also: use this option in GHA/windows.

Follow-up to 3b8bb1a86afbaf967163bf6709b1825e11655bf5 #21219
Follow-up to c98d0a2e9aa7ec87d16af8b056e6e7c0d614feec #21220

Closes #21438

3 months agombedtls: cleanup more without care for 'initialized'
Daniel Stenberg [Fri, 24 Apr 2026 14:27:34 +0000 (16:27 +0200)] 
mbedtls: cleanup more without care for 'initialized'

Several mbedTLS resources (entropy/CTR-DRBG, CA/client certs, keys, CRL)
are initialized and may allocate memory before initialized is set, and
must still be cleaned up.

Follow-up to 1c4813c769ea65c128c067004

Caught by Codex Security
Closes #21440

3 months agoGHA/windows: disable ssh-ed25519 hostkey in libssh2-wincng jobs
Viktor Szakats [Fri, 24 Apr 2026 12:38:50 +0000 (14:38 +0200)] 
GHA/windows: disable ssh-ed25519 hostkey in libssh2-wincng jobs

libssh2 built with the WinCNG crypto backend does not support ed25519
hostkeys.

Ref: #21438
Follow-up to acda4eae5eeb24a7b0ab9ec7b1783d74eb43687c #21223

Closes #21439

3 months agoresolve: pass bool for proxy resolves
Stefan Eissing [Thu, 23 Apr 2026 14:26:13 +0000 (16:26 +0200)] 
resolve: pass bool for proxy resolves

So that CURLcode failure is correct and not figured out later via
`conn->bits.proxy`. Add the flag to the async struct.

`for_proxy` is figured out by the caller of Curl_resolv() when it
figures out which host/proxy name it wants the addresses for.

Remove CONN_IS_PROXIED macro as no longer needed.

Closes #21423

3 months agochecksrc: add missing semicolon, fix `IFDEFSINGLE` capture group
Viktor Szakats [Fri, 24 Apr 2026 08:07:40 +0000 (10:07 +0200)] 
checksrc: add missing semicolon, fix `IFDEFSINGLE` capture group

Pointed out by GitHub Code Quality

Closes #21435

3 months agotests: drop support for the hex="yes" option in getpart
Daniel Stenberg [Thu, 23 Apr 2026 20:54:01 +0000 (22:54 +0200)] 
tests: drop support for the hex="yes" option in getpart

The remaining datacheck sections using this for MQTT tests were not
actually used anyway!

Closes #21428

3 months agochecksrc: add missing items to warnings hash, alpha-sort
Viktor Szakats [Fri, 24 Apr 2026 07:53:21 +0000 (09:53 +0200)] 
checksrc: add missing items to warnings hash, alpha-sort

Closes #21434

3 months agochecksrc: fix code quality findings
Viktor Szakats [Thu, 23 Apr 2026 23:24:32 +0000 (01:24 +0200)] 
checksrc: fix code quality findings

- fix counting errors. Update test1185 results accordingly.
- fix an error message.
- tidy up regexp syntax.

Pointed out by GitHub Code Quality

Closes #21429

3 months agodoh: fix #ifdef name
Daniel Stenberg [Fri, 24 Apr 2026 05:57:14 +0000 (07:57 +0200)] 
doh: fix #ifdef name

Spotted by Copilot

Closes #21431

3 months agohostip: init the curl_jmpenv_lock appropriately
Daniel Stenberg [Fri, 24 Apr 2026 06:11:10 +0000 (08:11 +0200)] 
hostip: init the curl_jmpenv_lock appropriately

A zero-initialized static value is not guaranteed to be a valid mutex on
all POSIX implementations

Spotted by Codex Security

Closes #21432

3 months agourldata.h: fix typo and lingering backtick
Daniel Stenberg [Fri, 24 Apr 2026 05:55:00 +0000 (07:55 +0200)] 
urldata.h: fix typo and lingering backtick

Spotted by Copilot

Closes #21430

3 months agorustls: fix memory leak on repeated SSLKEYLOGFILE fails
Daniel Stenberg [Thu, 23 Apr 2026 19:49:50 +0000 (21:49 +0200)] 
rustls: fix memory leak on repeated SSLKEYLOGFILE fails

Before this fix, Curl_tls_keylog_open() assigned the environment
variable result to a global keylog_file_name without freeing any prior
allocation. If the file cannot be opened (e.g., permission error)
keylog_file_fp stays NULL, so subsequent calls to Curl_tls_keylog_open
will overwrite keylog_file_name and leak the previous allocation.

Spotted by Codex Security

Closes #21427

3 months agochecksrc.pl: delete stray commas
Viktor Szakats [Thu, 23 Apr 2026 18:57:44 +0000 (20:57 +0200)] 
checksrc.pl: delete stray commas

Closes #21426

3 months agoci: update RUSTLS_VERSION 0.15.2 -> 0.15.3
Daniel McCarney [Thu, 23 Apr 2026 15:20:42 +0000 (11:20 -0400)] 
ci: update RUSTLS_VERSION 0.15.2 -> 0.15.3

Closes #21424

3 months agodoh: remove conn->bits.doh
Stefan Eissing [Thu, 23 Apr 2026 12:43:11 +0000 (14:43 +0200)] 
doh: remove conn->bits.doh

Since we have a new struct instance for each async operation now and
async operation may happen in parallel, remove the connection bit
indicating doh is in progress.

Closes #21422

3 months agomulti: enhance pending handles fairness
Stefan Eissing [Wed, 22 Apr 2026 13:00:14 +0000 (15:00 +0200)] 
multi: enhance pending handles fairness

When trying to connect a pending transfer, remember the `mid` that was
last reactivated and start looking for future pending handles from the
last one forward through the pending bitset.

Background: when many pending handles exist, iterating the bitset always
from the start may become unfair to transfers that were assigned higher
`mid` values.

Fixes #21396
Reported-by: Juan Belón
Closes #21412

3 months agovtls: fix comment typos and tidy up a type
Viktor Szakats [Thu, 23 Apr 2026 09:55:59 +0000 (11:55 +0200)] 
vtls: fix comment typos and tidy up a type

Pointed out by GitHub Code Quality

Closes #21421

3 months agoCI: set `DO_NOT_TRACK=1`
Viktor Szakats [Thu, 23 Apr 2026 08:17:13 +0000 (10:17 +0200)] 
CI: set `DO_NOT_TRACK=1`

Closes #21420

3 months agoGHA/appveyor-status: disable `gh` tool telemetry
Viktor Szakats [Thu, 23 Apr 2026 08:11:16 +0000 (10:11 +0200)] 
GHA/appveyor-status: disable `gh` tool telemetry

Ref: https://cli.github.com/telemetry

Closes #21418

3 months agovtls: log when key logging is enabled.
Yedaya Katsman [Tue, 2 Dec 2025 16:15:47 +0000 (18:15 +0200)] 
vtls: log when key logging is enabled.

If built with LibreSSL, also warn that it only works for TLS <= 1.2

Inspired-by: Viktor Szakats
Closes #19814

3 months agourlapi: simplify urlget_url
Daniel Stenberg [Wed, 22 Apr 2026 21:37:57 +0000 (23:37 +0200)] 
urlapi: simplify urlget_url

- unify the query and fragment separator logic
- read the bitflags directly instead of via a temp variable
- narrow the scope of a few variables

Closes #21417

3 months agoGHA: deprioritize Azure Ubuntu mirror
Viktor Szakats [Wed, 22 Apr 2026 16:43:23 +0000 (18:43 +0200)] 
GHA: deprioritize Azure Ubuntu mirror

Due to year-long unreliability.

The default Ubuntu mirror works as fast as the Azure one when it's
working at its normal speed. And has HTTPS.

Also:
- replac the retry hack that turn out to not solve the problem.
- add timeouts to each download step to catch slowness early.

Follow-up to a5838847c4395cdf043d9a833f38d5ba0a704ca1 #21181
Follow-up to 5172ba5475cffc525c2338dfa63f818e11e80a42 #21107

Closes #21414

3 months agoasyn-thrdd: drop redundant `result` check
Viktor Szakats [Wed, 22 Apr 2026 15:34:57 +0000 (17:34 +0200)] 
asyn-thrdd: drop redundant `result` check

Pointed out by GitHub Code Quality

Closes #21415

3 months agoGHA: delete all apt sources except `ubuntu.sources`
Viktor Szakats [Wed, 22 Apr 2026 16:03:32 +0000 (18:03 +0200)] 
GHA: delete all apt sources except `ubuntu.sources`

GitHub runners are getting new 3rd-party sources frequntly now, last
week `docker.list`, this week: `google-chrome.sources`. To avoid
playing catch up, allowlist the only one we use: `ubuntu.sources`. If
this is renamed, CI would break. Let's hope this happens much less
often than new sources.

Bug: https://github.com/curl/curl/pull/21414#issuecomment-4297788640

Follow-up to 3e0e2cc1ab6f3f44c7d35e84256858edc2ef73f5 #21344

Closes #21416

3 months agoasyn-thrdd: minor without-IPv6 fixes
Daniel Stenberg [Wed, 22 Apr 2026 13:05:57 +0000 (15:05 +0200)] 
asyn-thrdd: minor without-IPv6 fixes

Pointed out by Copilot

Closes #21413

3 months agodocs: clarify retry-max-time timing
Dio Putra [Wed, 22 Apr 2026 10:36:36 +0000 (17:36 +0700)] 
docs: clarify retry-max-time timing

Closes #21411

3 months agoDockerfile: update debian:bookworm-slim Docker digest to f9c6a2f
renovate[bot] [Wed, 22 Apr 2026 02:54:52 +0000 (02:54 +0000)] 
Dockerfile: update debian:bookworm-slim Docker digest to f9c6a2f

Closes #21406

3 months agoappveyor: bump to OpenSSL 3.6
Viktor Szakats [Tue, 21 Apr 2026 22:24:55 +0000 (00:24 +0200)] 
appveyor: bump to OpenSSL 3.6

Closes #21405

3 months agoRELEASE-NOTES: synced
Daniel Stenberg [Wed, 22 Apr 2026 05:53:54 +0000 (07:53 +0200)] 
RELEASE-NOTES: synced

3 months agotool_operate: reset the upload glob counter for next URL
Daniel Stenberg [Tue, 21 Apr 2026 15:51:26 +0000 (17:51 +0200)] 
tool_operate: reset the upload glob counter for next URL

Fixes #21402

Adjust test 2012 and 2013 accordingly

Closes #21403

3 months agotool_operate: keep the filename for upload globbing
Daniel Stenberg [Tue, 21 Apr 2026 15:14:51 +0000 (17:14 +0200)] 
tool_operate: keep the filename for upload globbing

Follow-up to 19695e815c51f8830fc54255

Verify with test 2012 and 2013

Closes #21401

3 months agoruntests: allow %EMPTY in <stdout> to verify no output
Daniel Stenberg [Tue, 21 Apr 2026 15:15:05 +0000 (17:15 +0200)] 
runtests: allow %EMPTY in <stdout> to verify no output

3 months agoasync-ares: fix query counter handling
Stefan Eissing [Tue, 21 Apr 2026 13:06:46 +0000 (15:06 +0200)] 
async-ares: fix query counter handling

When starting an c-ares query, the provided callback may be invoked
right away, leading to a decrement of `queries_ongoing`. Increment
the counter *before* call c-ares. Otherwise, the `async->done` bit
is not properly set.

Closes #21399

3 months agolib557: add tests with flags AND conversion specifier
Daniel Stenberg [Tue, 21 Apr 2026 12:49:32 +0000 (14:49 +0200)] 
lib557: add tests with flags AND conversion specifier

Remove superfluous and never-built test code for systems with 16-bit and
64-bit ints and 16-bit longs, as we don't know any such.

3 months agomprintf: OR the flags
Daniel Stenberg [Tue, 21 Apr 2026 12:33:27 +0000 (14:33 +0200)] 
mprintf: OR the flags

As 'flags' may already have been set to something when
parse_conversion() is called, make sure to only OR the new flags.

Follow-up to 4e0bfd8cf73603697ddad5d25e94

Closes #21398

3 months agomisc: fix code quality findings
Viktor Szakats [Tue, 21 Apr 2026 08:14:16 +0000 (10:14 +0200)] 
misc: fix code quality findings

- httpsrr: drop redundant checks.
  Follow-up to 809dda3a37363160d4bf5ea2dafa0bcb8188a3f0 #21354
- httpsrr.h: drop obsolete comment.
  Follow-up to 2b3dfb4ad47ec05efad9af930c47968a49916999 #21175
- ws: drop redundant check in `curl_ws_start_frame()`.
  Follow-up to 37cecfc7b91118f116cf16af8f50a18b15d00d51 #17683
- ws: fix typo in comment.
- tool_operate: fix VMS build. (broken since 2019-07-20, v7.66.0)
  Follow-up to b88940850002a3f1c25bc6488b95ad30eb80d696 #3804

Pointed out by Copilot Code Quality

Closes #21393

3 months agoparsedate: refactor
Daniel Stenberg [Tue, 21 Apr 2026 07:19:53 +0000 (09:19 +0200)] 
parsedate: refactor

- introduce 'struct when' to hold the parser result
- initwhen() initializes a 'struct when'
- datestring() parses strings
- datenum() parses numbers
- datecheck() does some final checks
- tzadjust() adds the time zone offset
- convert math to 64 bit, squeeze into time_t only in the last step,
  mktimet() does the time_t storing

Closes #21394