From gnutls-devel at lists.gnutls.org Mon Aug 3 09:32:16 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 07:32:16 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 Project:Branches: dueno/gnutls:wip/dueno/buffer-pop-uint to gnutls/gnutls:master Author: Daiki Ueno * str: use more elaborate types for _gnutls_buffer_pop_prefix* * str: remove check argument of _gnutls_buffer_pop_prefix* * str: switch to using _gnutls_buffer_pop_uint* where possible As _gnutls_buffer_pop_prefix*(..., 0) is equivalent to _gnutls_buffer_pop_uint*(...), use the latter instead. * str: split _gnutls_buffer_pop_prefix* to _gnutls_buffer_pop_uint* ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4texchdnk51hg5l25qizbky30-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:30:23 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:30:23 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was approved by Zolt?n Fridrich Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:30:44 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:30:44 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Zolt?n Fridrich commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593933 Minor nitpicks that I would do differently. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593933 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-04sesqol387z975epjzx7rdjc-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:33:38 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:33:38 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request !2121 was approved by Zolt?n Fridrich Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 Project:Branches: dueno/gnutls:wip/dueno/buffer-pop-uint to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:35:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:35:59 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615428 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615428 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-83jqdfszkeu9lfcp5tyd476ul-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:35:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:35:59 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was approved by Sahana Prasad Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno Assignees: Reviewers: -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:15 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:15 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Zolt?n Fridrich -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593790 > + c <= GROUP_CLASS_MAX; c++) { > + if (cpos_by_class[c] < cpos) { > + cpos = cpos_by_class[c]; could be ``` cpos = session->internals.priorities->server_precedence ? NOT_FOUND : cpos_by_class[c]; ``` and the duplicated for loop could be removed. -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593858 > + * TLS 1.3 as an encrypted extension. */ > + return 0; > + } else { I would just remove `else` when the `if` just returns. It would be nicer to read. The same pattern is seen elsewhere. -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593868 > - } > + return client_send_params(session, extdata); > + } else { remove `else` -- Zolt?n Fridrich started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635593881 > + if (group->pk == GNUTLS_PK_DH) { > + return GROUP_CLASS_DH; > + } else if (IS_EC(group->pk)) { I would remove `else`. They all return anyway. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3osb0z9svo799bgzb7je6bdyw-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:17 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:17 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Sahana Prasad -- Sahana Prasad started a new discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3635615392 > - /* we figure what is the minimum DH allowed for this session, if any */ > - min_dh = get_min_dh(session); > + if (len != data_size) Here we are forcing a strict check for length which seem correct, as opposed to the old code where padded bytes/trailing bytes were ignored, I hope that we were not tolerating such supported_groups extension previously. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-alev8ti15gva04994hobwo786-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:44:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:44:18 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Zolt?n Fridrich -- Zolt?n Fridrich started a new discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3635606863 > +{ > + if (buf->length < 1) { > + gnutls_assert(); I would use return `gnutls_assert_val(...)` whenever possible. The would look nicer. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2nrzpx95q3wlrvrmonfezhl8n-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 10:58:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 08:58:18 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Sahana Prasad -- Sahana Prasad started a new discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3635702557 > - > - if (check && *data > buf->length - 1) { > + if (buf->length < 1 || *data > buf->length - 1) { isn't buf->length already decremented before returning in _gnutls_buffer_pop_uint8()? Do we need to have the -1 check here again? I think same thing happens in other prefix functions as well. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-32vyoanl3i6vzy20xs6auo6zd-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:32:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:32:51 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636348416 > return _gnutls_buffer_append_data(buf, ss, pfx_size); > } > > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check) > +int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data) > { > - if (buf->length < 1) { > - gnutls_assert(); > + if (_gnutls_buffer_pop_uint8(buf, data)) { > return GNUTLS_E_PARSING_ERROR; > } > > - *data = buf->data[0]; > - > - if (check && *data > buf->length - 1) { > + if (buf->length < 1 || *data > buf->length - 1) { That's a very good point (and AI didn't notice that). Thanks :-) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636348416 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-bpff8r5iiv0k3uwi6lp25c02q-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:44:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:44:11 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 was reviewed by Daiki Ueno -- Daiki Ueno commented on a discussion on lib/str.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636390858 > +{ > + if (buf->length < 1) { > + gnutls_assert(); I removed `gnutls_assert()` as it's too primitive to log the error. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-ae24o2i5tvlaowai680xjk483-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 13:44:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 11:44:11 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: All discussions on merge request !2121 were resolved by Daiki Ueno https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0jmvhxe74qfbgxiox631nt3vs-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 3 15:25:37 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 03 Aug 2026 13:25:37 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636902331 I also added `_gnutls_buffer_append_uint*` and changed the relevant code. @sahprasa @ZoltanFridrich I'd appreciate if you could check the latest 2 commits. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3636902331 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2uiabh5kmozyqfc28m5hq59e8-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 04:26:25 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 02:26:25 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 was reviewed by Daiki Ueno -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406826 > + c <= GROUP_CLASS_MAX; c++) { > + if (cpos_by_class[c] < cpos) { > + cpos = cpos_by_class[c]; Not really, as the `if` conditions are also different depending on server_precedence. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406883 > + if (group->pk == GNUTLS_PK_DH) { > + return GROUP_CLASS_DH; > + } else if (IS_EC(group->pk)) { Not my style, sorry. `else` makes it clear that the above condition doesn't meet. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406889 > - /* we figure what is the minimum DH allowed for this session, if any */ > - min_dh = get_min_dh(session); > + if (len != data_size) Overlong (or padded) extension should be rejected, while the previous was too tolerate and ignored it. RFC 8446 defines Extension so that it shouldn't happen and tlsfuzzer has tests for that in some extensions. -- Daiki Ueno commented on a discussion on lib/ext/supported_groups.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120#note_3639406896 > + * TLS 1.3 as an encrypted extension. */ > + return 0; > + } else { I think this is written so that client/server code paths are treated equally (not the way either of it is a special case), so I'm not a fan of omitting `else` here. However, using a `switch` might be better in that case. Let me change that. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-9u91mio3yx0cj3n793dr3aa5v-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 06:01:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 04:01:24 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: All discussions on merge request !2120 were resolved by Daiki Ueno https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5zh9oh1o8flgai6zku47qb0lp-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 06:01:34 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 04:01:34 +0000 Subject: [gnutls-devel] GnuTLS | supported_groups: rewrite group negotiation without nested loop (!2120) In-Reply-To: References: Message-ID: Merge request !2120 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 Project:Branches: dueno/gnutls:wip/dueno/stupid-loop to gnutls/gnutls:master Author: Daiki Ueno -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2120 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-buxgbv58kkwbulxzfthoc36mv-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 10:09:03 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 08:09:03 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3640254645 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3640254645 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-6tkfw26e4b64cacdjgtbi6gby-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 4 21:55:14 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 04 Aug 2026 19:55:14 +0000 Subject: [gnutls-devel] GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122) References: Message-ID: David Dudas created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122 Project:Branches: d-Dudas/gnutls:dev/ddudas/max-depth-for-cert-chain-verification to gnutls/gnutls:master Author: David Dudas * [#1893] Align max cert verify depth with OpenSSL Max certificate verification depth changed from 16 to 101 (leaf + 100). Issue: #1893 ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [x] Test suite updated with functionality tests * [x] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4lis9eacw62nso9idiyqu8f2o-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 5 17:28:22 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 05 Aug 2026 15:28:22 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Alexander Sosedkin started a new discussion on lib/hello_ext.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648422333 > > _gnutls_buffer_clear(buf); > > - if ((ret = _gnutls_buffer_append_prefix(buf, 8, recv_buf->htype)) < 0) > + if ((ret = _gnutls_buffer_append_uint8(buf, recv_buf->htype)) < 0) > return gnutls_assert_val(ret); > - if ((ret = _gnutls_buffer_append_prefix(buf, 24, > - recv_buf->data.length)) < 0) > + if ((ret = _gnutls_buffer_append_uint24(buf, recv_buf->data.length)) < > + 0) > return gnutls_assert_val(ret); > if ((ret = _gnutls_buffer_append_data(buf, recv_buf->data.data, > recv_buf->data.length)) < 0) > return gnutls_assert_val(ret); More of a strategic style direction question: what's preferred, `_gnutls_buffer_append_uint24` + `_gnutls_buffer_append_data` or a `_gnutls_buffer_append_data_prefix` (dispatching to `_gnutls_buffer_append_prefix`, of which it's the only remaining caller)? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648422333 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8p45b8w12o03vhlybq20wb9rn-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 5 17:38:50 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 05 Aug 2026 15:38:50 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Alexander Sosedkin started a new discussion on lib/str.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648480705 > - int check); > - > -/* 24-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix24(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 16-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix16(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 8-bit prefix, if check is true ensure, there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check); > +/* 32-bit prefix, ensure there are no remaining bytes in buf */ the "ensure there are no remaining bytes in buf" part doesn't feel intended (and doesn't match the `*data_size > buf->length` error condition) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3648480705 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1a1461ehfqlrzbcc8ez1awa80-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 11:15:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 09:15:51 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno * build: fix comment indentation after applying clang-format When applying clang-format back in 2023 in commit aa5950aba, the tool for some reason indented the first line of multi-line comment block but not the rest. This fixes it by applying the following Elisp function with: ``` cat >indent-comments.el < From gnutls-devel at lists.gnutls.org Thu Aug 6 11:38:04 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 09:38:04 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Tim R?hsen commented: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3652013907 Just ran into the same issue when adding (GnuTLS) DANE support for Wget2. The Debian `libgnutls-dane0` library depends on `libunbound8`, which depends on `libssl`. The resulting deps are ``` wget2 ??? libgnutls-dane.so.0 ??? libunbound.so.8 ??? libssl.so.3 / libcrypto.so.3 ``` I believe it's not something that Debian can solve by using other configure/build options for unbound. It requires some structural changes in the unbound build system (libunbound8 alone can in theory be built with nettle deps instead of libssl/libcrypto). I'd love to see a libc only solution. As an alternative, [this patch](https://github.com/c-ares/c-ares/pull/20) could possibly be revived. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3652013907 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-excm1q7jisab7ch3wtdzw8pmu-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:16:00 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:16:00 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Merge request !2123 was approved by Sahana Prasad Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:16:09 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:16:09 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Sahana Prasad commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123#note_3652182769 LGTM -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123#note_3652182769 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5njxm3it7tq1jr8vzmb6kui9y-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:36:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:36:18 +0000 Subject: [gnutls-devel] GnuTLS | build: fix comment indentation after applying clang-format (!2123) In-Reply-To: References: Message-ID: Merge request !2123 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 Project:Branches: dueno/gnutls:wip/dueno/comments to gnutls/gnutls:master Author: Daiki Ueno -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2123 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-264ggjqxll680k1prvy8eift5-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:51:22 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:51:22 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/hello_ext.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652326297 > > _gnutls_buffer_clear(buf); > > - if ((ret = _gnutls_buffer_append_prefix(buf, 8, recv_buf->htype)) < 0) > + if ((ret = _gnutls_buffer_append_uint8(buf, recv_buf->htype)) < 0) > return gnutls_assert_val(ret); > - if ((ret = _gnutls_buffer_append_prefix(buf, 24, > - recv_buf->data.length)) < 0) > + if ((ret = _gnutls_buffer_append_uint24(buf, recv_buf->data.length)) < > + 0) > return gnutls_assert_val(ret); > if ((ret = _gnutls_buffer_append_data(buf, recv_buf->data.data, > recv_buf->data.length)) < 0) > return gnutls_assert_val(ret); That's tricky. For the "pop" functions, `_gnutls_buffer_pop_uint*` are preferred over the previous `_gnutls_buffer_pop_prefix` (with the `size_t *` argument) for type-safety, because GCC will warn if the value read does not fit in the given `uint*_t *` parameter. On the other hand, for the "append" functions, it is legitimate to pass a `uint32_t` as a `uint8_t` argument, so even if we eliminate the `_gnutls_buffer_append_prefix` function, there are still issues with truncation. I guess a reasonable middle ground is to make `_gnutls_buffer_append_uint*` to take `size_t`, but with a run-time check whether it fits in the expected type. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652326297 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4yj4gx5qrrsv63e7ai2g1vb9a-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 12:54:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 10:54:24 +0000 Subject: [gnutls-devel] GnuTLS | Refactor `_gnutls_buffer_pop_prefix*` (!2121) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/str.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652338218 > - int check); > - > -/* 24-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix24(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 16-bit prefix, if check is true, ensure there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix16(gnutls_buffer_st *buf, size_t *data_size, > - int check); > - > -/* 8-bit prefix, if check is true ensure, there are enough bytes > - * remaining in buf */ > -int _gnutls_buffer_pop_prefix8(gnutls_buffer_st *buf, uint8_t *data, int check); > +/* 32-bit prefix, ensure there are no remaining bytes in buf */ Yeah, the previous comment (without the mention of `check` argument) was correct; just a mess up with rebase. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652338218 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1lg5nvpnrpubssq6n51udctho-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 14:54:04 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 12:54:04 +0000 Subject: [gnutls-devel] GnuTLS | bootstrap: propagate ENABLE_TESTS to src/gl/ after gnulib import (!2118) In-Reply-To: References: Message-ID: Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118#note_3652820472 A hesitant approve, since that if would better be generated and supported by gnulib. But it turns out `src/gl/Makefile.am` is no longer checked in, and we at least won't end up with a dirty tree, so, OK. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118#note_3652820472 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8xbrs4wgllipy8d8xurmymi3g-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 15:19:47 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 13:19:47 +0000 Subject: [gnutls-devel] GnuTLS | bootstrap: propagate ENABLE_TESTS to src/gl/ after gnulib import (!2118) In-Reply-To: References: Message-ID: Merge request !2118 was approved by Alexander Sosedkin Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118 Project:Branches: dueno/gnutls:wip/dueno/disable-tests to gnutls/gnutls:master Author: Daiki Ueno -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 6 19:15:46 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 06 Aug 2026 17:15:46 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Andreas Metzler commented: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3654178142 At the time libgnuts-dane was added to Debian libunbound **was** using nettle. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3654178142 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1sbvjnbidad4kd97x05syggbb-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 7 10:07:58 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 07 Aug 2026 08:07:58 +0000 Subject: [gnutls-devel] GnuTLS | Modularize `gnutls_int.h` (#1926) References: Message-ID: Issue created by Daiki Ueno: https://gitlab.com/gnutls/gnutls/-/work_items/1926 Over the time, `lib/gnutls_int.h` has evolved like a kitchen sink; it includes 30 header files and defines 7 inline functions and 145 macros. We should review them and make *.c files pull in only necessary definitions. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1926 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-7vtfe6nmm6g2va6vcz33ahsme-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 7 10:23:15 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 07 Aug 2026 08:23:15 +0000 Subject: [gnutls-devel] GnuTLS | bootstrap: propagate ENABLE_TESTS to src/gl/ after gnulib import (!2118) In-Reply-To: References: Message-ID: Merge request !2118 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118 Project:Branches: dueno/gnutls:wip/dueno/disable-tests to gnutls/gnutls:master Author: Daiki Ueno -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2118 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-eb809budsf2d2osvhn9glydbl-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 7 23:21:00 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 07 Aug 2026 21:21:00 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Tim R?hsen commented: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3660292396 @ametzler Do you think the libssl dep is a regression and worth a (Debian) bug report? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3660292396 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-39n87odpzurm25vgl5yocg7ab-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sat Aug 8 22:39:09 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sat, 08 Aug 2026 20:39:09 +0000 Subject: [gnutls-devel] GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122) In-Reply-To: References: Message-ID: Tim R?hsen started a new discussion on lib/gnutls_int.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662766930 > * update many_icas in tests/test-chains.h when increasing > * DEFAULT_MAX_VERIFY_DEPTH. > */ > -#define DEFAULT_MAX_VERIFY_DEPTH 16 > #define DEFAULT_MAX_VERIFY_BITS (MAX_PK_PARAM_SIZE * 8) > #define MAX_VERIFY_DEPTH 4096 > > +/* The depth includes the peer certificate, unlike OpenSSL's limit. */ Confusing: The title says "align with OpenSSL", but here the comment says "unlike OpenSSL's limit". -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662766930 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a8cjw105exrzmbxmdmyud5tpz-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sat Aug 8 22:40:42 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sat, 08 Aug 2026 20:40:42 +0000 Subject: [gnutls-devel] GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122) In-Reply-To: References: Message-ID: Tim R?hsen started a new discussion on tests/verify-limits.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662786375 > +#endif > + > +#include > +#include > +#include > +#include > + > +#include > +#include > +#include > + > +#include "cert-common.h" > +#include "eagain-common.h" > +#include "utils.h" > + > +#define DEFAULT_CHAIN_SIZE 101 Instead of duplicating 101 here, maybe it's better to use `DEFAULT_MAX_VERIFY_DEPTH`? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662786375 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0pqxcerqav9fhfrv3j2e66kbr-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sat Aug 8 22:48:08 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sat, 08 Aug 2026 20:48:08 +0000 Subject: [gnutls-devel] GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122) In-Reply-To: References: Message-ID: Tim R?hsen started a new discussion on tests/verify-limits.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662821681 > + gnutls_deinit(server); > + gnutls_certificate_free_credentials(client_cred); > + gnutls_certificate_free_credentials(server_cred); > +} > + > +void doit(void) > +{ > + gnutls_x509_crt_t certs[CERTIFICATE_COUNT]; > + gnutls_x509_privkey_t key; > + unsigned int i; > + > + CHECK_RET(global_init()); > + CHECK_RET(gnutls_x509_privkey_init(&key)); > + CHECK_RET(gnutls_x509_privkey_import(key, &server_ecc_key, > + GNUTLS_X509_FMT_PEM)); > + create_chain(certs, key); Pass the countof certs as `chain_size` -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662821681 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5181k09ehzhd8potbo0ku2fm5-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 04:14:52 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 02:14:52 +0000 Subject: [gnutls-devel] GnuTLS | Fix compiler warnings (!2124) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124 Project:Branches: dueno/gnutls:wip/dueno/warning-fixes to gnutls/gnutls:master Author: Daiki Ueno * eagain-cli: suppress -Wunused-but-set-variable warning * build: suppress -Wdiscarded-qualifiers warnings The string search functions, such as strstr, etc., now checks the return type matches the first argument. * cert: suppress -Wunused-but-set-parameter warning This makes get_issuers validate the input data size to properly "use" the argument. * supported_groups: suppress -Wreturn-type warnings For historical reasons, an entity (GNUTLS_CLIENT or GNUTLS_SERVER) is defined as part of gnutls_init_flags_t enum which has more members and prevents using a switch to cover all branches. ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0x18anpfyji1jebni0tet16yu-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 9 21:00:38 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 09 Aug 2026 19:00:38 +0000 Subject: [gnutls-devel] GnuTLS | Drop the unbound dependency in libdane (#21) In-Reply-To: References: Message-ID: Andreas Metzler commented on a discussion: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3664370499 I looked it up, is was an intentional change on the unbound side, I guess it happened after the switch to OpenSSL 3. ``` unbound (1.18.0-2) unstable; urgency=medium * d/control, d/rules: switch from libnettle back to libssl once it is GPL-compatible (#828699 is of no concern anymore). This fixes libunbound init failure. Also Closes: #1007260 ``` -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/21#note_3664370499 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-dv9yxq8vehzddq6q7yfc2e3xj-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 12 02:46:55 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 12 Aug 2026 00:46:55 +0000 Subject: [gnutls-devel] GnuTLS | Mismerge of fix of CVE-2025-13151 (#1932) In-Reply-To: References: Message-ID: Issue was closed by Daiki Ueno Issue #1932: https://gitlab.com/gnutls/gnutls/-/work_items/1932 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1932 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3r9fbil7q0jpeacdg20duk99b-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 15:48:56 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 13:48:56 +0000 Subject: [gnutls-devel] GnuTLS | Building from master: ` error: 'rsa_oaep_sha256_encrypt' undeclared` (#1930) In-Reply-To: References: Message-ID: Tim Rühsen commented: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667097244 [config.log](/uploads/550c88266bbaaccf5c1d4519edcd76dd/config.log) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667097244 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-e1w9vr6nsqs70mhifh2h0c9ds-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 12 18:03:16 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 12 Aug 2026 16:03:16 +0000 Subject: [gnutls-devel] GnuTLS | Fix DECR_LEN usage after commit e0fe31f1f (!2126) In-Reply-To: References: Message-ID: Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2126#note_3678453952 4507ed39 addresses all my concerns, LGTM. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2126#note_3678453952 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-7uer23mp1yd1pfwg2ozevlnj9-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 15:52:13 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 13:52:13 +0000 Subject: [gnutls-devel] GnuTLS | Building from master: ` error: 'rsa_oaep_sha256_encrypt' undeclared` (#1930) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667114746 No, we shouldn't add any directories under devel/ to the include path. They are purely for maintenance purposes. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667114746 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-573mfzqto6ls33q2pwf4vrvb2-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 11 21:04:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 11 Aug 2026 19:04:11 +0000 Subject: [gnutls-devel] GnuTLS | Mismerge of fix of CVE-2025-13151 (#1932) References: Message-ID: Issue created by bastien roucaries: https://gitlab.com/gnutls/gnutls/-/work_items/1932 CVE-2025-13151 (libtasn1 - off-by-one in asn1_expand_octet_string, fixed in 4.20.0) The fix changes: char name[2 * ASN1_MAX_NAME_SIZE + 1] to: char name[2 * ASN1_MAX_NAME_SIZE + 2] This applies to two functions: asn1_expand_any_defined_by and asn1_expand_octet_string. gnutls28 vendor libtasn1 internally and show a partial fix - asn1_expand_any_defined_by has been updated (+ 2 present) but asn1_expand_octet_string still carries the vulnerable version (+ 1): - gnutls28 (lib/minitasn1/decoding.c) asn1_expand_any_defined_by: patched asn1_expand_octet_string: VULNERABLE Thanks Gajendra Nath Soren rouca link: [[https://bugs.debian.org/1144080]] -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1932 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-cojk2mdhhzk0g2r8r4cmr5j2g-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 12 12:17:01 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 12 Aug 2026 10:17:01 +0000 Subject: [gnutls-devel] GnuTLS | Fix compiler warnings (!2124) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on src/cli.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124#note_3676727946 > #endif > > /* returns the host part of a URL */ > -static const char *host_from_url(const char *url, unsigned int *port, Ah, I somehow missed that `p` is reused for both const and non-const storage. Sorry for the confusion. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124#note_3676727946 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a27gdc76aesckc0plo7uyfh0x-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 15:57:49 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 13:57:49 +0000 Subject: [gnutls-devel] GnuTLS | Building from master: ` error: 'rsa_oaep_sha256_encrypt' undeclared` (#1930) In-Reply-To: References: Message-ID: Tim Rühsen commented: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667143258 Maybe my misunderstanding. Then this boils down to "Debian's nettle 3.10.2" doesn work out. Here it is ``` ii libnettle8t64:amd64 3.10.2-1+b1 amd64 low level cryptographic library (symmetric and one-way crypto> ii libnettle8t64:i386 3.10.2-1+b1 i386 low level cryptographic library (symmetric and one-way crypto> ii nettle-dev:amd64 3.10.2-1+b1 amd64 low level cryptographic library (development files) ``` ``` $ grep -Rin rsa_oaep_sha256_encrypt /usr/include/nettle/ /usr/include/nettle/rsa.h:91:#define rsa_oaep_sha256_encrypt nettle_rsa_oaep_sha256_encrypt /usr/include/nettle/rsa.h:438:rsa_oaep_sha256_encrypt (const struct rsa_public_key *key, ``` ``` $ make -j1 V=1 depbase=`echo pk.lo | sed 's|[^/]*$|.deps/&|;s|\.lo$||'`;\ /bin/bash ../../libtool --tag=CC --mode=compile gcc -DHAVE_CONFIG_H -I. -I../.. -DGNUTLS_BUILDING_LIB=1 -I./int -I./backport -I./../../gl -I./../../gl -I./../includes -I./../includes -I./../../gl -I./.. -Wtype-limits -fanalyzer -fstrict-flex-arrays -Wall -Wbad-function-cast -Wcast-align=strict -Wdate-time -Wdouble-promotion -Wduplicated-branches -Wduplicated-cond -Wextra -Wflex-array-member-not-at-end -Winit-self -Winvalid-pch -Wlogical-op -Wmissing-declarations -Wmissing-include-dirs -Wmissing-prototypes -Wnested-externs -Wnull-dereference -Wold-style-definition -Wopenmp-simd -Wpacked -Wpointer-arith -Wshadow -Wstrict-flex-arrays -Wstrict-prototypes -Wsuggest-attribute=cold -Wsuggest-attribute=format -Wsuggest-attribute=malloc -Wsync-nand -Wtrampolines -Wuninitialized -Wunknown-pragmas -Wunused-macros -Wvariadic-macros -Wvector-operation-performance -Wwrite-strings -Warray-bounds=2 -Wattribute-alias=2 -Wbidi-chars=any,ucn -Wformat-overflow=2 -Wformat=2 -Wformat-truncation=2 -Wimplicit-fallthrough=5 -Wshift-overflow=2 -Wuse-after-free=3 -Wunused-const-variable=2 -Wvla-larger-than=4031 -Wzero-as-null-pointer-constant -Wno-analyzer-malloc-leak -Wno-missing-field-initializers -Wno-unused-parameter -Wno-format-truncation -Wimplicit-fallthrough=2 -Wabi=11 -fdiagnostics-show-option -fno-builtin-strcmp -I/usr/include/p11-kit-1 -g -ggdb3 -Og -Wall -Wextra -MT pk.lo -MD -MP -MF $depbase.Tpo -c -o pk.lo pk.c &&\ mv -f $depbase.Tpo $depbase.Plo libtool: compile: gcc -DHAVE_CONFIG_H -I. -I../.. -DGNUTLS_BUILDING_LIB=1 -I./int -I./backport -I./../../gl -I./../../gl -I./../includes -I./../includes -I./../../gl -I./.. -Wtype-limits -fanalyzer -fstrict-flex-arrays -Wall -Wbad-function-cast -Wcast-align=strict -Wdate-time -Wdouble-promotion -Wduplicated-branches -Wduplicated-cond -Wextra -Wflex-array-member-not-at-end -Winit-self -Winvalid-pch -Wlogical-op -Wmissing-declarations -Wmissing-include-dirs -Wmissing-prototypes -Wnested-externs -Wnull-dereference -Wold-style-definition -Wopenmp-simd -Wpacked -Wpointer-arith -Wshadow -Wstrict-flex-arrays -Wstrict-prototypes -Wsuggest-attribute=cold -Wsuggest-attribute=format -Wsuggest-attribute=malloc -Wsync-nand -Wtrampolines -Wuninitialized -Wunknown-pragmas -Wunused-macros -Wvariadic-macros -Wvector-operation-performance -Wwrite-strings -Warray-bounds=2 -Wattribute-alias=2 -Wbidi-chars=any,ucn -Wformat-overflow=2 -Wformat=2 -Wformat-truncation=2 -Wimplicit-fallthrough=5 -Wshift-overflow=2 -Wuse-after-free=3 -Wunused-const-variable=2 -Wvla-larger-than=4031 -Wzero-as-null-pointer-constant -Wno-analyzer-malloc-leak -Wno-missing-field-initializers -Wno-unused-parameter -Wno-format-truncation -Wimplicit-fallthrough=2 -Wabi=11 -fdiagnostics-show-option -fno-builtin-strcmp -I/usr/include/p11-kit-1 -g -ggdb3 -Og -Wall -Wextra -MT pk.lo -MD -MP -MF .deps/pk.Tpo -c pk.c -fPIC -DPIC -o .libs/pk.o pk.c: In function ‘_rsa_oaep_encrypt’: pk.c:1043:32: error: ‘rsa_oaep_sha256_encrypt’ undeclared (first use in this function); did you mean ‘_rsa_oaep_encrypt’? 1043 | encrypt_func = rsa_oaep_sha256_encrypt; | ^~~~~~~~~~~~~~~~~~~~~~~ | _rsa_oaep_encrypt ``` -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1930#note_3667143258 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-biwvyxlhl4i4l7l9s0wk8qoeu-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 15:20:26 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 13:20:26 +0000 Subject: [gnutls-devel] GnuTLS | Build instructions (bootstrap+configure+make) run configure twice (#1929) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/work_items/1929#note_3666951332 I suspect your system has a clock skew? It works perfectly fine. Closing. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1929#note_3666951332 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1weguqu2eigrkfuoct61r3esv-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 12 12:21:52 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 12 Aug 2026 10:21:52 +0000 Subject: [gnutls-devel] GnuTLS | Fix compiler warnings (!2124) In-Reply-To: References: Message-ID: Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124#note_3676749492 @dueno the fresh push with variable separation looks good, but there's two of them `host_from_url`s -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2124#note_3676749492 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-dodwd9dbtvr3brfccc3yenxyd-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 10 12:32:33 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 10 Aug 2026 10:32:33 +0000 Subject: [gnutls-devel] GnuTLS | Solaris (OpenIndiana) parameter handling problem in certtool (#1916) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/work_items/1916#note_3666208151 @dreibh Thank you for the report and sorry for the delay. I don't have an environment to test this, but maybe the issue could be resolved by just importing the getopt module from Gnulib, by adding `getopt-gnu` to `src_modules` in `bootstrap.conf`. Could you try that? If that works, we can pick it in the next release. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1916#note_3666208151 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8olxotdyzuhvld5hk61ik90g2-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 13 18:06:06 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 13 Aug 2026 16:06:06 +0000 Subject: [gnutls-devel] GnuTLS | Remove unused verify_bits (!2129) References: Message-ID: David Dudas created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129 Project:Branches: d-Dudas/gnutls:dev/ddudas/remove-unused-verify-bits to gnutls/gnutls:master Author: David Dudas Remove unused verify_bits Cleaned up unused verify_bits and updated the documentation. ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [x] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-13cv25r8dr2g8z0fh632rkpqi-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 13 18:42:38 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 13 Aug 2026 16:42:38 +0000 Subject: [gnutls-devel] GnuTLS | libdane: Use includes from libtasn proper instead of minitasn. (!2127) In-Reply-To: References: Message-ID: All discussions on merge request !2127 were resolved by Andreas Metzler https://gitlab.com/gnutls/gnutls/-/merge_requests/2127 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-anvfboyebdn6mlduh03ttfogf-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 13 18:42:44 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 13 Aug 2026 16:42:44 +0000 Subject: [gnutls-devel] GnuTLS | libdane: Use includes from libtasn proper instead of minitasn. (!2127) In-Reply-To: References: Message-ID: Andreas Metzler commented on a discussion on libdane/Makefile.am: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127#note_3683685477 > -I$(srcdir)/../lib/includes \ > -I$(srcdir)/includes \ > -I$(builddir)/includes \ > - -I$(srcdir)/../lib/minitasn1 \ > -I$(srcdir)/../lib > > +if ENABLE_MINITASN1 > +AM_CPPFLAGS += -I$(srcdir)/minitasn1 > +else > +AM_CPPFLAGS += $(LIBTASN1_CFLAGS) > +endif Sure, force-pushed with this change. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127#note_3683685477 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2x3tm3djzwfqrqv4nsppn5g4n-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Thu Aug 13 19:00:49 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Thu, 13 Aug 2026 17:00:49 +0000 Subject: [gnutls-devel] GnuTLS | Mismerge of fix of CVE-2025-13151 (#1932) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/work_items/1932#note_3683765165 Is the internal copy of libtasn1 still useful in GnuTLS? Maybe we should just remove it. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1932#note_3683765165 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-01qm4hrg03f4g8pwm5dfb4iug-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:26:46 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:26:46 +0000 Subject: [gnutls-devel] GnuTLS | libdane: Use includes from libtasn proper instead of minitasn. (!2127) In-Reply-To: References: Message-ID: Merge request !2127 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127 Project:Branches: ametzler/gnutls:tmp-2026-dane-minitasn-include to gnutls/gnutls:master Author: Andreas Metzler -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:26:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:26:59 +0000 Subject: [gnutls-devel] GnuTLS | libdane: Use includes from libtasn proper instead of minitasn. (!2127) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127#note_3685537246 Thank you! -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127#note_3685537246 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a2gspz39lcwt11ynzq6qsf118-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:27:06 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:27:06 +0000 Subject: [gnutls-devel] GnuTLS | libdane: Use includes from libtasn proper instead of minitasn. (!2127) In-Reply-To: References: Message-ID: Merge request !2127 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127 Project:Branches: ametzler/gnutls:tmp-2026-dane-minitasn-include to gnutls/gnutls:master Author: Andreas Metzler -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2127 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-72cnybxtlksrkfcnah22kjbqb-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:27:06 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:27:06 +0000 Subject: [gnutls-devel] GnuTLS | libgnutls-dane always uses tasn header file from lib/mintasn1 (#1931) In-Reply-To: References: Message-ID: Issue was closed by Daiki Ueno with merge request !2127 (https://gitlab.com/gnutls/gnutls/-/merge_requests/2127) Issue #1931: https://gitlab.com/gnutls/gnutls/-/work_items/1931 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1931 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2mq94e61hsnll9ew2eavxwtd7-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:27:06 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:27:06 +0000 Subject: [gnutls-devel] GnuTLS | libgnutls-dane always uses tasn header file from lib/mintasn1 (#1931) In-Reply-To: References: Message-ID: Issue was closed by Daiki Ueno with commit 776779bb617e63c3cd6fa50c5c9569e2742f9c35 Issue #1931: https://gitlab.com/gnutls/gnutls/-/work_items/1931 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1931 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-cugnylwi3oqih5i9r07brv41f-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:28:23 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:28:23 +0000 Subject: [gnutls-devel] GnuTLS | Remove unused verify_bits (!2129) In-Reply-To: References: Message-ID: Merge request !2129 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129 Project:Branches: d-Dudas/gnutls:dev/ddudas/remove-unused-verify-bits to gnutls/gnutls:master Author: David Dudas -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:28:30 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:28:30 +0000 Subject: [gnutls-devel] GnuTLS | Remove unused verify_bits (!2129) In-Reply-To: References: Message-ID: Merge request !2129 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129 Project:Branches: d-Dudas/gnutls:dev/ddudas/remove-unused-verify-bits to gnutls/gnutls:master Author: David Dudas -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3b6d8vk3grqc0ckheq9vx8e1l-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 06:28:26 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 04:28:26 +0000 Subject: [gnutls-devel] GnuTLS | Remove unused verify_bits (!2129) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129#note_3685539561 LGTM, thank you! -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2129#note_3685539561 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-bgko5990u2mrunak31srpu6ny-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 17:52:20 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 15:52:20 +0000 Subject: [gnutls-devel] GnuTLS | meson: add an alternative Meson build system (!2130) References: Message-ID: Tal Regev created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130 Project:Branches: tal.regev/gnutls:TalR/meson_ci to gnutls/gnutls:master Author: Tal Regev meson: add an alternative Meson build system ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [x] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [x] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-c1wpplz79mj89p8laa8eb6e02-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 18:25:09 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 16:25:09 +0000 Subject: [gnutls-devel] GnuTLS | meson: add an alternative Meson build system (!2130) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130#note_3688151136 Please -- no. Maintaining one build system (autoconf) is enough work, let alone supporting both autoconf and meson, and the added complexity of different behaviour depending on build system. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130#note_3688151136 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4te2w23zu6ekjc1jj3c8kn0ni-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Fri Aug 14 20:23:39 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Fri, 14 Aug 2026 18:23:39 +0000 Subject: [gnutls-devel] GnuTLS | meson: add an alternative Meson build system (!2130) In-Reply-To: References: Message-ID: Tal Regev commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130#note_3688525883 ok. I solve this issue. Please close it, that other will not try. https://gitlab.com/gnutls/gnutls/-/work_items/320 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130#note_3688525883 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2jjd4xfab1lctm0awjm3exrdz-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sat Aug 15 11:20:48 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sat, 15 Aug 2026 09:20:48 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) References: Message-ID: Issue created by Daiki Ueno: https://gitlab.com/gnutls/gnutls/-/work_items/1938 Given that the library interface of libtasn1 is considered stable and no significant ABI changes are expected, we probably could remove the bundled one (minitasn1) to reduce the maintenance burden. The users who want to statically link to libtasn1 can do that by compiling it with `--disable-shared` just like what Fedora does with leancrypto. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a9s2dwyrktvwoe3pw5lklqplj-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sat Aug 15 11:21:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sat, 15 Aug 2026 09:21:24 +0000 Subject: [gnutls-devel] GnuTLS | Mismerge of fix of CVE-2025-13151 (#1932) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/work_items/1932#note_3690008468 I don't think it's useful anymore. Filed https://gitlab.com/gnutls/gnutls/-/work_items/1938 to remove it. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1932#note_3690008468 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-2n9stj51fkpt9qdeu5k9h2s6c-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 16 11:14:59 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 16 Aug 2026 09:14:59 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691197466 Are you going to work on this? I could look into preparing a merge request with this. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691197466 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0clr0z03dwvv99vxxrej4im5u-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 16 11:17:21 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 16 Aug 2026 09:17:21 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691200770 I realized that a better way to implement the minitasn1 approach would be with a git submodule. I think we should first remove the current minitasn1 approach, and then if we find a strong use-case for it, re-implement the concept using a git submodule of libtasn1 instead. I normally dislike git submodules, and I think most users are much better of building libtasn1 separately before GnuTLS. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691200770 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5mma5kg318qd9pf4s7b7780y7-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 16 11:29:29 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 16 Aug 2026 09:29:29 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) In-Reply-To: References: Message-ID: Simon Josefsson commented on a discussion: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691213382 Never mind: I realized we already had a git submodule for libtasn1, only that it wasn't updated to v4.21.0. I think removing minitasn1 is a good idea, rather than to just bump the git libtasn1 submodule which would probably have resolved #1932 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3691213382 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-9pf0g22t3pmsuut8mzh7g384r-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 16 12:10:58 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 16 Aug 2026 10:10:58 +0000 Subject: [gnutls-devel] GnuTLS | Draft: doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) References: Message-ID: C H created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 Project:Branches: kalvdans/gnutls:doc/gnutls-pin-env-var to gnutls/gnutls:master Author: C H * doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables Document that gnutls-cli and similar tools can accept PIN via GNUTLS_PIN (user PIN) and GNUTLS_SO_PIN (security officer PIN) environment variables. This is implemented by the default PIN callback in the command-line tools. ## Checklist * [ ] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-6ch74ihuoivar5e4dyg4efn76-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Sun Aug 16 18:40:46 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Sun, 16 Aug 2026 16:40:46 +0000 Subject: [gnutls-devel] GnuTLS | doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) In-Reply-To: References: Message-ID: C H marked merge request !2131 as ready -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0p7q6isjgab3ujgm7yndlpqew-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 17 07:53:54 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 17 Aug 2026 05:53:54 +0000 Subject: [gnutls-devel] GnuTLS | doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131#note_3692637364 Thank you. I'm ok with this, though I wonder if those should be primarily mentioned in tools' documentation such as in the "Invoking gnutls-cli" section (which should be generated from src/gnutls-cli-options.json). -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131#note_3692637364 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-55f6vtbnrua5vpz4vkht7cn1h-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Mon Aug 17 07:54:05 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Mon, 17 Aug 2026 05:54:05 +0000 Subject: [gnutls-devel] GnuTLS | doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) In-Reply-To: References: Message-ID: Milestone changed to Release of GnuTLS 3.8.14 (Apr 30, 2026–Aug 31, 2026) ( https://gitlab.com/gnutls/gnutls/-/milestones/52 ) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5fmsugzlsl5bfop2zo4qy3t5r-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 10:38:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 08:38:51 +0000 Subject: [gnutls-devel] GnuTLS | ext: use gnutls_buffer_st to parse extension data instead of DECR_LEN (!2132) References: Message-ID: Daiki Ueno created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132 Project:Branches: dueno/gnutls:wip/dueno/ext-buffer to gnutls/gnutls:master Author: Daiki Ueno * ext: use gnutls_buffer_st to parse extension data * alert: map GNUTLS_E_PARSING_ERROR to "decode_error" alert As _gnutls_buffer_pop_* functions return GNUTLS_E_PARSING_ERROR upon error, map the error to the same alert generated from GNUTLS_E_UNEXPECTED_EXTENSIONS_LENGTH, so _gnutls_buffer_pop_* can be used in the extension handling code. Partially fixes: #1928 ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-7r2jduippo26dsmz0wiv91xwp-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 10:55:09 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 08:55:09 +0000 Subject: [gnutls-devel] GnuTLS | session_ticket: Use gnutls_free instead of free (!2133) References: Message-ID: Tim Rühsen created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2133 Branches: rockdaboot/gnutls_free-in-session-ticket to master Author: Tim Rühsen Tiny random finding. * session_ticket: Use gnutls_free instead of free Signed-off-by: Tim Rühsen ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2133 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-7s0hc1d2iuobvwd4o6hqzxbgj-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 11:18:52 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 09:18:52 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) References: Message-ID: Tim Rühsen created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 Branches: rockdaboot/fix-repeat-on-invalid-handle to master Author: Tim Rühsen * pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE The macro REPEAT_ON_INVALID_HANDLE contained a return, which did not do cleanups like freeing memory or unlocking mutexes. This leads to memory leaks and even deadlocks under certain error conditions. Signed-off-by: Tim Rühsen ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-es4k966wh2ueq0h0byl0lut0t-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 11:28:14 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 09:28:14 +0000 Subject: [gnutls-devel] GnuTLS | x509_privkey_verify_seed: Fix memory leak (!2135) References: Message-ID: Tim Rühsen created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 Branches: rockdaboot/fix-privkey-memleak to master Author: Tim Rühsen * x509_privkey_verify_seed: Fix memory leak The cleanup was missing for the case where seed is NULL or has 0 length. Signed-off-by: Tim Rühsen ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5njhk85auylpndr0m37cr0nwv-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 12:05:32 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 10:05:32 +0000 Subject: [gnutls-devel] GnuTLS | ext: use gnutls_buffer_st to parse extension data instead of DECR_LEN (!2132) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2132 was reviewed by Alexander Sosedkin -- Alexander Sosedkin started a new discussion on lib/ext/max_record.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132#note_3698952222 > - gnutls_assert(); > - return GNUTLS_E_UNEXPECTED_PACKET_LENGTH; > - } Is this relaxation intentional? -- Alexander Sosedkin started a new discussion on lib/ext/session_ticket.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132#note_3698952262 > + priv->session_ticket, ticket_len); > if (!priv->session_ticket) { > - gnutls_free(priv); why drop this? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8bmxq9jrl5bha6csttjij9tzy-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 12:05:31 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 10:05:31 +0000 Subject: [gnutls-devel] GnuTLS | ext: use gnutls_buffer_st to parse extension data instead of DECR_LEN (!2132) In-Reply-To: References: Message-ID: Alexander Sosedkin commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132#note_3698952288 Looks aligned with https://gitlab.com/gnutls/gnutls/-/merge_requests/2121#note_3652326297 =) Should alert changes / increased strictness on processing trailing data be reflected in NEWS? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2132#note_3698952288 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8rsay3dubcp63usybsl6ys5rc-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 12:22:37 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 10:22:37 +0000 Subject: [gnutls-devel] GnuTLS | session_ticket: Use gnutls_free instead of free (!2133) In-Reply-To: References: Message-ID: Merge request !2133 was approved by Alexander Sosedkin Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2133 Branches: rockdaboot/gnutls_free-in-session-ticket to master Author: Tim Rühsen -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 12:30:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 10:30:18 +0000 Subject: [gnutls-devel] GnuTLS | x509_privkey_verify_seed: Fix memory leak (!2135) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 was reviewed by Alexander Sosedkin -- Alexander Sosedkin started a new discussion on lib/x509/privkey.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135#note_3699062786 > - return gnutls_assert_val(GNUTLS_E_PK_NO_VALIDATION_PARAMS); > + if (seed == NULL || seed_size == 0) { > + gnutls_assert_val(GNUTLS_E_PK_NO_VALIDATION_PARAMS); ret = ..., so that it doesn't return 0? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3qn4st6buv9ata1vluebrf0xq-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 12:32:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 10:32:24 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Merge request !2134 was approved by Alexander Sosedkin Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 Branches: rockdaboot/fix-repeat-on-invalid-handle to master Author: Tim Rühsen -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 13:02:24 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 11:02:24 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3699209056 This kind of macro usage always confuses me and it's actually [discouraged](https://www.kernel.org/doc/html/v4.10/process/coding-style.html#macros-enums-and-rtl) in the Linux kernel coding style. Can we simply expand this macro at the call sites? I checked all places and only the third one `_gnutls_pkcs11_privkey_decrypt_data` requires cleanup. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3699209056 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3j8zsnm0qd7bkxvviikxa0pm9-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 13:09:17 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 11:09:17 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 was reviewed by Daiki Ueno -- Daiki Ueno started a new discussion on lib/pkcs11_privkey.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3699208923 > + ret = reopen_privkey_session(key); \ > + if (ret < 0) { \ > + gnutls_assert_val(ret); \ ```suggestion:-0+0 gnutls_assert(); \ ``` -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-6pqh8bc3ay5ybnv6wz0x2xnz6-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 14:06:13 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 12:06:13 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3699518355 Thanks; a merge request for this would be appreciated. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3699518355 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-e2mzki1ca4kxzfnj4nngs202b-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 14:29:31 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 12:29:31 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: All discussions on merge request !2134 were resolved by Tim Rühsen https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-eujqtpgehdn5tkm1vgy7gdma6-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 14:32:00 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 12:32:00 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Tim Rühsen commented on a discussion: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3699662114 I kinda agree about the confusion. But let's make a list of these macros and open an issue to discuss how to deal with each one. I am not inclined to add this as a fly-by change in this MR. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3699662114 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-ey0jmyplbhq8dp1z64co5mni0-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 14:32:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 12:32:11 +0000 Subject: [gnutls-devel] GnuTLS | x509_privkey_verify_seed: Fix memory leak (!2135) In-Reply-To: References: Message-ID: All discussions on merge request !2135 were resolved by Tim Rühsen https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-40irtldpatawcnmzq8nruqo3k-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 14:32:36 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 12:32:36 +0000 Subject: [gnutls-devel] GnuTLS | session_ticket: Use gnutls_free instead of free (!2133) In-Reply-To: References: Message-ID: Merge request !2133 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2133 Branches: rockdaboot/gnutls_free-in-session-ticket to master Author: Tim Rühsen -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2133 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8lcz3umcy1n3g89azodal4jix-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 15:12:26 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 13:12:26 +0000 Subject: [gnutls-devel] GnuTLS | Review changes between RFC 9846 and RFC 8846 (#1939) References: Message-ID: Issue created by Daiki Ueno: https://gitlab.com/gnutls/gnutls/-/work_items/1939 [RFC 9846](https://www.rfc-editor.org/rfc/rfc9846.html) has been published to update RFC 8446. It's good to go through the [changes](https://www.rfc-editor.org/rfc/rfc9846.html#name-major-differences-from-tls-) and apply tightening as necessary. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1939 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3s0n5syv1lp4kk6s20ri1gnht-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 16:15:51 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 14:15:51 +0000 Subject: [gnutls-devel] GnuTLS | x509_privkey_verify_seed: Fix memory leak (!2135) In-Reply-To: References: Message-ID: Merge request !2135 was approved by Alexander Sosedkin Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 Branches: rockdaboot/fix-privkey-memleak to master Author: Tim Rühsen -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 16:18:04 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 14:18:04 +0000 Subject: [gnutls-devel] GnuTLS | x509_privkey_verify_seed: Fix memory leak (!2135) In-Reply-To: References: Message-ID: Merge request !2135 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 Branches: rockdaboot/fix-privkey-memleak to master Author: Tim Rühsen -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2135 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-8vj6geypfftmdzvfikwsbnriy-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 18:05:16 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 16:05:16 +0000 Subject: [gnutls-devel] GnuTLS | gnutls_certificate_set_x509_crl: Use gnutls_free instead of free (!2136) References: Message-ID: Tim Rühsen created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2136 Branches: rockdaboot/cert-cred-free to master Author: Tim Rühsen * gnutls_certificate_set_x509_crl: Use gnutls_free instead of free Signed-off-by: Tim Rühsen ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2136 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3t2lb6fs0rdv809jubpum82ei-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 18:24:28 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 16:24:28 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (#1938) In-Reply-To: References: Message-ID: Simon Josefsson commented on a discussion: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3701019812 There is now !2137 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1938#note_3701019812 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-0o5omh14p43aiy6kpa8f5ns9f-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 19:16:02 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 17:16:02 +0000 Subject: [gnutls-devel] GnuTLS | Undefined behavior in _gnutls_resolve_priorities() (#1940) References: Message-ID: Issue created by Tim Rühsen: https://gitlab.com/gnutls/gnutls/-/work_items/1940 At https://gitlab.com/gnutls/gnutls/-/blob/master/lib/priority.c?ref_type=heads#L2560, we subtract a potential NULL pointer (`additional`) and a non-NULL pointer (`ss_next`), which is UB. This is a finding of `scan-build` 22. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1940 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-cuwdyeec4wkycty7gc7ja0vvu-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Tue Aug 18 19:30:11 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Tue, 18 Aug 2026 17:30:11 +0000 Subject: [gnutls-devel] GnuTLS | _gnutls_alt_name_assign_virt_type: Fix memory leak (!2138) References: Message-ID: Tim Rühsen created a merge request: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138 Branches: rockdaboot/memleak-gnutls_alt_name_assign_virt_type to master Author: Tim Rühsen * _gnutls_alt_name_assign_virt_type: Fix memory leak Signed-off-by: Tim Rühsen ## Short explanation `_gnutls_alt_name_assign_virt_type()` takes ownership of `othername_oid` in case of success. The callers free `othername_oid` in case of error. But this isn't true for cases where `type > GNUTLS_SAN_MAX` - `othername_oid` isn't consumed nor freed. This MR frees `othername_oid` in the success case and when `type > GNUTLS_SAN_MAX`. ## Checklist * [x] Commits have `Signed-off-by:` with name/author being identical to the commit author * [ ] Code modified for feature * [ ] Test suite updated with functionality tests * [ ] Test suite updated with negative tests * [ ] Documentation updated / NEWS entry present (for non-trivial changes) ## Reviewer's checklist: * [ ] Any issues marked for closing are addressed * [ ] There is a test suite reasonably covering new functionality or modifications * [ ] Function naming, parameters, return values, types, etc., are consistent and according to `CONTRIBUTION.md` * [ ] This feature/change has adequate documentation added * [ ] No obvious mistakes in the code -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-1fakpjlrv6y6haqg0qs5p0zfc-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:05:55 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:05:55 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Merge request !2137 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137 Branches: jas/remove-minitasn1 to master Author: Simon Josefsson -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:06:03 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:06:03 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3702910486 LGTM, thank you. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3702910486 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-djst8075o5ohc6s2jdz490dyk-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:29:33 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:29:33 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Merge request !2134 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 Branches: rockdaboot/fix-repeat-on-invalid-handle to master Author: Tim Rühsen -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:30:05 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:30:05 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: All discussions on merge request !2134 were resolved by Daiki Ueno https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-d9cy8m6ne4gdmfhy4s8ccya5w-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:30:07 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:30:07 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3702952852 OK, let's do that in a separate MR. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134#note_3702952852 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-3vuqkjqrvp3z8i83ttft0pxb9-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:32:57 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:32:57 +0000 Subject: [gnutls-devel] GnuTLS | _gnutls_alt_name_assign_virt_type: Fix memory leak (!2138) In-Reply-To: References: Message-ID: Daiki Ueno started a new discussion on lib/x509/virt-san.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3702957672 > name->type = GNUTLS_SAN_OTHERNAME; > > gnutls_free(san->data); > + gnutls_free(othername_oid); Are you calling `gnutls_free` on a function argument with `const char *othername_oid`? That doesn't sound correct; I guess we should do that in the caller instead. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3702957672 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-amybef9fxuc9qtmmubku6lp81-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:36:39 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:36:39 +0000 Subject: [gnutls-devel] GnuTLS | gnutls_certificate_set_x509_crl: Use gnutls_free instead of free (!2136) In-Reply-To: References: Message-ID: Merge request !2136 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2136 Branches: rockdaboot/cert-cred-free to master Author: Tim Rühsen -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:37:18 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:37:18 +0000 Subject: [gnutls-devel] GnuTLS | doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) In-Reply-To: References: Message-ID: Merge request !2131 was approved by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 Project:Branches: kalvdans/gnutls:doc/gnutls-pin-env-var to gnutls/gnutls:master Author: C H -- You're receiving this email because of your account on gitlab.com. -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:37:28 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:37:28 +0000 Subject: [gnutls-devel] GnuTLS | doc: document GNUTLS_PIN and GNUTLS_SO_PIN environment variables (!2131) In-Reply-To: References: Message-ID: Merge request !2131 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 Project:Branches: kalvdans/gnutls:doc/gnutls-pin-env-var to gnutls/gnutls:master Author: C H -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2131 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-9wc116060v0xfopf7h1t5hd09-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 04:38:28 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 02:38:28 +0000 Subject: [gnutls-devel] GnuTLS | meson: add an alternative Meson build system (!2130) In-Reply-To: References: Message-ID: Merge request !2130 was closed by Daiki Ueno Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130 Project:Branches: tal.regev/gnutls:TalR/meson_ci to gnutls/gnutls:master Author: Tal Regev -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2130 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-6ezjoi3q9skresvqeb1d360sz-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 05:28:29 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 03:28:29 +0000 Subject: [gnutls-devel] GnuTLS | _gnutls_alt_name_assign_virt_type: Fix memory leak (!2138) In-Reply-To: References: Message-ID: Merge request https://gitlab.com/gnutls/gnutls/-/merge_requests/2138 was reviewed by Daiki Ueno -- Daiki Ueno commented on a discussion on lib/x509/virt-san.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3703059049 > > gnutls_free(san->data); > + gnutls_free(othername_oid); Here is my attempt along these lines: [othername.patch](/uploads/1c29c1629f55dadaa57357d94fcbb1d2/othername.patch) -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-573881wyh14i08kd3yttewuzz-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 08:42:21 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 06:42:21 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703502960 Thanks for review! The only thing I feel uncertain about is the NEWS addition. Do you have some policy on when/how to add NEWS entries? I was a bit surprised to not see any modification in there compared to the last release. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703502960 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a2419dqlcuxvgy0agctuewrpb-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 09:43:42 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 07:43:42 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703720826 Apparently we forgot to add entries for the past couple of changes; let me file a new MR to update it once this gets merged. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703720826 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-7jdgv0pl6ceh3dip55ugdyh3m-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 10:14:44 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 08:14:44 +0000 Subject: [gnutls-devel] GnuTLS | _gnutls_alt_name_assign_virt_type: Fix memory leak (!2138) In-Reply-To: References: Message-ID: Tim Rühsen commented on a discussion on lib/x509/virt-san.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3703852075 > name->type = GNUTLS_SAN_OTHERNAME; > > gnutls_free(san->data); > + gnutls_free(othername_oid); > Are you calling gnutls_free on a function argument declared as const char *othername_oid? That doesn't sound correct; I guess we should do that in the caller instead. Yeah, it doesn't sound correct, but follows the logic of the existing `name->othername_oid.data = (uint8_t *)othername_oid;`. And it's a minimal change. But I also agree with your patch. Going through it in details (+ applying) later today. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3703852075 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-5xks7z64sk378222unqwz2ph7-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 10:31:50 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 08:31:50 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Simon Josefsson commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703922371 Anything more pending before mergin? Should I push a rebase to master? Rebasing using the web interface loses the git PGP signature on the commit, which isn't important but nice anyway... -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3703922371 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-4y0405svrps8h5ycs1dldbikf-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 10:49:21 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 08:49:21 +0000 Subject: [gnutls-devel] GnuTLS | pkcs11: Fix macro REPEAT_ON_INVALID_HANDLE (!2134) In-Reply-To: References: Message-ID: Merge request !2134 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 Branches: rockdaboot/fix-repeat-on-invalid-handle to master Author: Tim Rühsen -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2134 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-630zdht7vlx8xnobqik6tm5ku-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 10:49:42 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 08:49:42 +0000 Subject: [gnutls-devel] GnuTLS | gnutls_certificate_set_x509_crl: Use gnutls_free instead of free (!2136) In-Reply-To: References: Message-ID: Merge request !2136 was merged Merge request URL: https://gitlab.com/gnutls/gnutls/-/merge_requests/2136 Branches: rockdaboot/cert-cred-free to master Author: Tim Rühsen -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2136 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-csz5zm64rcynqjztvjuawy76n-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 11:24:20 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 09:24:20 +0000 Subject: [gnutls-devel] GnuTLS | _gnutls_alt_name_assign_virt_type: Fix memory leak (!2138) In-Reply-To: References: Message-ID: Daiki Ueno commented on a discussion on lib/x509/virt-san.c: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3704164348 > name->type = GNUTLS_SAN_OTHERNAME; > > gnutls_free(san->data); > + gnutls_free(othername_oid); Let's not aim for a minimal change nor follow any historic convention. We should remove code smells rather than adding more. -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2138#note_3704164348 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-abeoah7ou825o4kd0obbe76ir-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: From gnutls-devel at lists.gnutls.org Wed Aug 19 11:29:32 2026 From: gnutls-devel at lists.gnutls.org ((Deprecated) Read-only notification of GnuTLS library development activities) Date: Wed, 19 Aug 2026 09:29:32 +0000 Subject: [gnutls-devel] GnuTLS | Remove minitasn1 (!2137) In-Reply-To: References: Message-ID: Daiki Ueno commented: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3704187439 Sure, please push the merge button. I wasn't aware of the issue with the commit signatures; is it still the case if your branch is on par with the git master? -- Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2137#note_3704187439 You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-aphzidvrrpqffqqf7x5xichsq-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help -------------- next part -------------- An HTML attachment was scrubbed... URL: