From gnutls-devel at lists.gnutls.org Mon Aug 3 09:32:16 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 07:32:16 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 Project:Branches: dueno/gnutls:wip/dueno/buffer-pop-uint to gnutls/gnutls:master Author: Daiki Ueno * str: use more elaborate types for _gnutls_buffer_pop_prefix* * str: remove check argument of _gnutls_buffer_pop_prefix* * str: switch to using _gnutls_buffer_pop_uint* where possible As _gnutls_buffer_pop_prefix*(..., 0) is equivalent to _gnutls_buffer_pop_uint*(...), use the latter instead. * str: split _gnutls_buffer_pop_prefix* to _gnutls_buffer_pop_uint* ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4texchdnk51hg5l25qizbky30-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:30:23 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:30:23 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was approved by Zolt?n Fridrich Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:30:44 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:30:44 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Zolt?n Fridrich commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593933 Minor nitpicks that I would do differently. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593933 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-04sesqol387z975epjzx7rdjc-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:33:38 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:33:38 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request !2121 was approved by Zolt?n Fridrich Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 Project:Branches: dueno/gnutls:wip/dueno/buffer-pop-uint to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:35:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:35:59 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615428 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615428 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-83jqdfszkeu9lfcp5tyd476ul-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:35:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:35:59 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was approved by Sahana Prasad Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:15 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:15 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Zolt?n Fridrich -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593790 > + c <= GROUP_CLASS_MAX; c++) { > + if (cpos_by_class[c] < cpos) { > + cpos = cpos_by_class[c]; could be ``` cpos = session->internals.priorities->server_precedence ? NOT_FOUND : cpos_by_class[c]; ``` and the duplicated for loop could be removed. -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593858 > + * TLS 1.3 as an encrypted extension. */ > + return 0; > + } else { I would just remove `else` when the `if` just returns. It would be nicer to read. The same pattern is seen elsewhere. -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593868 > - } > + return client_send_params(session, extdata); > + } else { remove `else` -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593881 > + if (group->pk == GNUTLS_PK_DH) { > + return GROUP_CLASS_DH; > + } else if (IS_EC(group->pk)) { I would remove `else`. They all return anyway. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3osb0z9svo799bgzb7je6bdyw-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:17 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:17 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Sahana Prasad -- Sahana Prasad started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615392 > - /* we figure what is the minimum DH allowed for this session, if any */ > - min_dh = get_min_dh(session); > + if (len != data_size) Here we are forcing a strict check for length which seem correct, as opposed to the old code where padded bytes/trailing bytes were ignored, I hope that we were not tolerating such supported_groups extension previously. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-alev8ti15gva04994hobwo786-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:18 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Zolt?n Fridrich -- Zolt?n Fridrich started a new discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3635606863 > +{ > + if (buf->length < 1) { > + gnutls_assert(); I would use return `gnutls_assert_val(...)` whenever possible. The would look nicer. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2nrzpx95q3wlrvrmonfezhl8n-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:58:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:58:18 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Sahana Prasad -- Sahana Prasad started a new discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3635702557 > - > - if (check && *data > buf->length - 1) { > + if (buf->length < 1 || *data > buf->length - 1) { isn't buf->length already decremented before returning in _gnutls_buffer_pop_uint8()? Do we need to have the -1 check here again? I think same thing happens in other prefix functions as well. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-32vyoanl3i6vzy20xs6auo6zd-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:32:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:32:51 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636348416 > return _gnutls_buffer_append_data(buf, ss, pfx_size); > } > > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check) > +int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data) > { > - if (buf->length < 1) { > - gnutls_assert(); > + if (_gnutls_buffer_pop_uint8(buf, data)) { > return GNUTLS_E_PARSING_ERROR; > } > > - *data = buf->data[0]; > - > - if (check && *data > buf->length - 1) { > + if (buf->length < 1 || *data > buf->length - 1) { That's a very good point (and AI didn't notice that). Thanks :-) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636348416 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-bpff8r5iiv0k3uwi6lp25c02q-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:44:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:44:11 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Daiki Ueno -- Daiki Ueno commented on a discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636390858 > +{ > + if (buf->length < 1) { > + gnutls_assert(); I removed `gnutls_assert()` as it's too primitive to log the error. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-ae24o2i5tvlaowai680xjk483-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:44:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:44:11 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: All discussions on merge request !2121 were resolved by Daiki Ueno https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0jmvhxe74qfbgxiox631nt3vs-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 15:25:37 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 13:25:37 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636902331 I also added `_gnutls_buffer_append_uint*` and changed the relevant code. @sahprasa @ZoltanFridrich I'd appreciate if you could check the latest 2 commits. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636902331 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2uiabh5kmozyqfc28m5hq59e8-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 04:26:25 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 02:26:25 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Daiki Ueno -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406826 > + c <= GROUP_CLASS_MAX; c++) { > + if (cpos_by_class[c] < cpos) { > + cpos = cpos_by_class[c]; Not really, as the `if` conditions are also different depending on server_precedence. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406883 > + if (group->pk == GNUTLS_PK_DH) { > + return GROUP_CLASS_DH; > + } else if (IS_EC(group->pk)) { Not my style, sorry. `else` makes it clear that the above condition doesn't meet. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406889 > - /* we figure what is the minimum DH allowed for this session, if any */ > - min_dh = get_min_dh(session); > + if (len != data_size) Overlong (or padded) extension should be rejected, while the previous was too tolerate and ignored it. RFC 8446 defines Extension so that it shouldn't happen and tlsfuzzer has tests for that in some extensions. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406896 > + * TLS 1.3 as an encrypted extension. */ > + return 0; > + } else { I think this is written so that client/server code paths are treated equally (not the way either of it is a special case), so I'm not a fan of omitting `else` here. However, using a `switch` might be better in that case. Let me change that. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-9u91mio3yx0cj3n793dr3aa5v-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 06:01:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 04:01:24 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: All discussions on merge request !2120 were resolved by Daiki Ueno https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5zh9oh1o8flgai6zku47qb0lp-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 06:01:34 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 04:01:34 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-buxgbv58kkwbulxzfthoc36mv-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 10:09:03 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 08:09:03 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3640254645 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3640254645 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-6tkfw26e4b64cacdjgtbi6gby-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 21:55:14 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 19:55:14 +0000 Subject: [gnutls-devel] GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122) References: Message-ID: David Dudas created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122 Project:Branches: d-Dudas/gnutls:dev/ddudas/max-depth-for-cert-chain-verification to gnutls/gnutls:master Author: David Dudas * [#1893] Align max cert verify depth with OpenSSL Max certificate verification depth changed from 16 to 101 (leaf + 100). Issue: #1893 ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [x] Test suite updated with functionality tests * [x] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4lis9eacw62nso9idiyqu8f2o-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 5 17:28:22 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 05 Aug 2026 15:28:22 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Alexander Sosedkin started a new discussion on lib/hello_ext.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648422333 > > _gnutls_buffer_clear(buf); > > - if ((ret = _gnutls_buffer_append_prefix(buf, 8, recv_buf->htype)) < 0) > + if ((ret = _gnutls_buffer_append_uint8(buf, recv_buf->htype)) < 0) > return gnutls_assert_val(ret); > - if ((ret = _gnutls_buffer_append_prefix(buf, 24, > - recv_buf->data.length)) < 0) > + if ((ret = _gnutls_buffer_append_uint24(buf, recv_buf->data.length)) < > + 0) > return gnutls_assert_val(ret); > if ((ret = _gnutls_buffer_append_data(buf, recv_buf->data.data, > recv_buf->data.length)) < 0) > return gnutls_assert_val(ret); More of a strategic style direction question: what's preferred, `_gnutls_buffer_append_uint24` + `_gnutls_buffer_append_data` or a `_gnutls_buffer_append_data_prefix` (dispatching to `_gnutls_buffer_append_prefix`, of which it's the only remaining caller)? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648422333 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8p45b8w12o03vhlybq20wb9rn-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 5 17:38:50 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 05 Aug 2026 15:38:50 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Alexander Sosedkin started a new discussion on lib/str.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648480705 > - int check); > - > -/* 24-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix24(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 16-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix16(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 8-bit prefix, if check is true ensure, there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check); > +/* 32-bit prefix, ensure there are no remaining bytes in buf */ the "ensure there are no remaining bytes in buf" part doesn't feel intended (and doesn't match the `*data_size > buf->length` error condition) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648480705 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1a1461ehfqlrzbcc8ez1awa80-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 11:15:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 09:15:51 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno * build: fix comment indentation after applying clang-format When applying clang-format back in 2023 in commit aa5950aba, the tool for some reason indented the first line of multi-line comment block but not the rest. This fixes it by applying the following Elisp function with: ``` cat >indent-comments.el < From gnutls-devel at lists.gnutls.org Thu Aug 6 11:38:04 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 09:38:04 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Tim R?hsen commented: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3652013907 Just ran into the same issue when adding (GnuTLS) DANE support for Wget2. The Debian `libgnutls-dane0` library depends on `libunbound8`, which depends on `libssl`. The resulting deps are ``` wget2 ??? libgnutls-dane.so.0 ??? libunbound.so.8 ??? libssl.so.3 / libcrypto.so.3 ``` I believe it's not something that Debian can solve by using other configure/build options for unbound. It requires some structural changes in the unbound build system (libunbound8 alone can in theory be built with nettle deps instead of libssl/libcrypto). I'd love to see a libc only solution. As an alternative, [this patch](https://github.com/c-ares/c-ares/pull/20) could possibly be revived. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3652013907 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-excm1q7jisab7ch3wtdzw8pmu-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:16:00 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:16:00 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Merge request !2123 was approved by Sahana Prasad Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:16:09 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:16:09 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123#note_3652182769 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123#note_3652182769 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5njxm3it7tq1jr8vzmb6kui9y-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:36:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:36:18 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Merge request !2123 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-264ggjqxll680k1prvy8eift5-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:51:22 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:51:22 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/hello_ext.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652326297 > > _gnutls_buffer_clear(buf); > > - if ((ret = _gnutls_buffer_append_prefix(buf, 8, recv_buf->htype)) < 0) > + if ((ret = _gnutls_buffer_append_uint8(buf, recv_buf->htype)) < 0) > return gnutls_assert_val(ret); > - if ((ret = _gnutls_buffer_append_prefix(buf, 24, > - recv_buf->data.length)) < 0) > + if ((ret = _gnutls_buffer_append_uint24(buf, recv_buf->data.length)) < > + 0) > return gnutls_assert_val(ret); > if ((ret = _gnutls_buffer_append_data(buf, recv_buf->data.data, > recv_buf->data.length)) < 0) > return gnutls_assert_val(ret); That's tricky. For the "pop" functions, `_gnutls_buffer_pop_uint*` are preferred over the previous `_gnutls_buffer_pop_prefix` (with the `size_t *` argument) for type-safety, because GCC will warn if the value read does not fit in the given `uint*_t *` parameter. On the other hand, for the "append" functions, it is legitimate to pass a `uint32_t` as a `uint8_t` argument, so even if we eliminate the `_gnutls_buffer_append_prefix` function, there are still issues with truncation. I guess a reasonable middle ground is to make `_gnutls_buffer_append_uint*` to take `size_t`, but with a run-time check whether it fits in the expected type. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652326297 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4yj4gx5qrrsv63e7ai2g1vb9a-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:54:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:54:24 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/str.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652338218 > - int check); > - > -/* 24-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix24(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 16-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix16(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 8-bit prefix, if check is true ensure, there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check); > +/* 32-bit prefix, ensure there are no remaining bytes in buf */ Yeah, the previous comment (without the mention of `check` argument) was correct; just a mess up with rebase. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652338218 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1lg5nvpnrpubssq6n51udctho-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 14:54:04 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 12:54:04 +0000 Subject: [gnutls-devel] GnuTLS | bootstrap: propagate ENABLE_TESTS to src/gl/ after gnulib import (!2118) In-Reply-To: References: Message-ID: Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118#note_3652820472 A hesitant approve, since that if would better be generated and supported by gnulib. But it turns out `src/gl/Makefile.am` is no longer checked in, and we at least won't end up with a dirty tree, so, OK. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118#note_3652820472 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8xbrs4wgllipy8d8xurmymi3g-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 15:19:47 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 13:19:47 +0000 Subject: [gnutls-devel] GnuTLS | bootstrap: propagate ENABLE_TESTS to src/gl/ after gnulib import (!2118) In-Reply-To: References: Message-ID: Merge request !2118 was approved by Alexander Sosedkin Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118 Project:Branches: dueno/gnutls:wip/dueno/disable-tests to gnutls/gnutls:master Author: Daiki Ueno -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 19:15:46 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 17:15:46 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Andreas Metzler commented: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3654178142 At the time libgnuts-dane was added to Debian libunbound **was** using nettle. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3654178142 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1sbvjnbidad4kd97x05syggbb-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: