<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en">
<head>
<meta content="text/html; charset=US-ASCII" http-equiv="Content-Type">
<title>
GitLab
</title>


<style>img {
max-width: 100%; height: auto;
}
</style>
</head>
<body>
<div class="content">

<p class="details" style="font-style: italic; color: #666;">
<a href="https://gitlab.com/dueno">Daiki Ueno</a> created a merge request:
</p>
<p>
</p>
<div class="branch">
Branches: tmp-backport-3.6 to gnutls_3_6_x
</div>
<div class="author">
Author: Daiki Ueno
</div>
<div class="assignee">
Assignees: 
</div>
<div class="approvers">

</div>

<div>
<p dir="auto">This backports the following MRs:
<a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1309" data-original="!1309" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67721187" data-project-path="gnutls/gnutls" data-iid="1309" data-mr-title="handshake: check TLS version against modified server priorities" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1309</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1308" data-original="!1308" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67585596" data-project-path="gnutls/gnutls" data-iid="1308" data-mr-title="cert-session: check OCSP error responses" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1308</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1312" data-original="!1312" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67754333" data-project-path="gnutls/gnutls" data-iid="1312" data-mr-title="gnutls_aead_cipher_decrypt: check output buffer size before writing" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1312</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1311" data-original="!1311" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67729527" data-project-path="gnutls/gnutls" data-iid="1311" data-mr-title="gnutls_x509_crt_export2: return 0 instead of the length" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1311</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1307" data-original="!1307" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67509564" data-project-path="gnutls/gnutls" data-iid="1307" data-mr-title="minitasn1: move WARN_CFLAGS setting to configure.ac" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1307</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1306" data-original="!1306" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67306719" data-project-path="gnutls/gnutls" data-iid="1306" data-mr-title="_gnutls_fips_mode_enabled: treat selftest failure as FIPS disabled" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1306</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1305" data-original="!1305" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67301017" data-project-path="gnutls/gnutls" data-iid="1305" data-mr-title="doc: assorted typo fixes" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1305</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1304" data-original="!1304" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="67299851" data-project-path="gnutls/gnutls" data-iid="1304" data-mr-title="cert-session: ensure that invalid flag is always set" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1304</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1268" data-original="!1268" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="59854696" data-project-path="gnutls/gnutls" data-iid="1268" data-mr-title="Fix two issues about certtool and passwords" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1268</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1300" data-original="!1300" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="64468983" data-project-path="gnutls/gnutls" data-iid="1300" data-mr-title="Mangle/hide GNUTLS-built ecc_scalar_random()" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1300</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1301" data-original="!1301" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="65231681" data-project-path="gnutls/gnutls" data-iid="1301" data-mr-title="pubkey: avoid spurious audit messages from _gnutls_pubkey_compatible_with_sig()" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1301</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1299" data-original="!1299" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="64059330" data-project-path="gnutls/gnutls" data-iid="1299" data-mr-title="nettle: check validity of (EC)DH shared secret before export" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1299</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1296" data-original="!1296" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="62875479" data-project-path="gnutls/gnutls" data-iid="1296" data-mr-title="build: use $(LIBPTHREAD) rather than non-existent $(LTLIBPTHREAD)" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1296</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1291" data-original="!1291" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61444944" data-project-path="gnutls/gnutls" data-iid="1291" data-mr-title=".gitlab-ci: disable config.cache for nettle-master builds" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1291</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1298" data-original="!1298" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="63459590" data-project-path="gnutls/gnutls" data-iid="1298" data-mr-title="tests: split up system-override-sig-hash.sh" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1298</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1294" data-original="!1294" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="62160686" data-project-path="gnutls/gnutls" data-iid="1294" data-mr-title="Detect the availability of connectx at runtime" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1294</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1297" data-original="!1297" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="62943336" data-project-path="gnutls/gnutls" data-iid="1297" data-mr-title="safe_memcmp: remove in favor of gnutls_memcmp" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1297</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1295" data-original="!1295" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="62782543" data-project-path="gnutls/gnutls" data-iid="1295" data-mr-title="fips: tighten check on DH parameters according to SP800-56A (rev 3)" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1295</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1289" data-original="!1289" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61436890" data-project-path="gnutls/gnutls" data-iid="1289" data-mr-title="Wipe session ticket keys before releasing the session structure" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1289</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1285" data-original="!1285" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="60886127" data-project-path="gnutls/gnutls" data-iid="1285" data-mr-title="issues #1018- Modied the license to GPLv2.1+ to keep with LICENSE file." data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1285</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1292" data-original="!1292" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61715971" data-project-path="gnutls/gnutls" data-iid="1292" data-mr-title='Detect Python interpreter for tests instead of assuming "python"' data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1292</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1287" data-original="!1287" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61372341" data-project-path="gnutls/gnutls" data-iid="1287" data-mr-title="build: minor fixes" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1287</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1251" data-original="!1251" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="58899736" data-project-path="gnutls/gnutls" data-iid="1251" data-mr-title="refine tests for ancient servers which support both SSL 3.0 and TLS 1.0, but both only with %NO_EXTENSIONS" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1251</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1288" data-original="!1288" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61372609" data-project-path="gnutls/gnutls" data-iid="1288" data-mr-title="tests: improve datefudge usage" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1288</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1284" data-original="!1284" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="60875037" data-project-path="gnutls/gnutls" data-iid="1284" data-mr-title="configure.ac: prefer the latest version of build infrastructure" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1284</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1286" data-original="!1286" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="61037624" data-project-path="gnutls/gnutls" data-iid="1286" data-mr-title="configure: improve nettle, gmp, and hogweed soname detection" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1286</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1276" data-original="!1276" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="60660764" data-project-path="gnutls/gnutls" data-iid="1276" data-mr-title="tests: updated tlsfuzzer tests to latest version" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1276</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1274" data-original="!1274" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="60314215" data-project-path="gnutls/gnutls" data-iid="1274" data-mr-title="gnutls_aead_cipher_init: fix potential memleak" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1274</a>, <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1273" data-original="!1273" data-link="false" data-link-reference="false" data-project="179611" data-merge-request="60258432" data-project-path="gnutls/gnutls" data-iid="1273" data-mr-title="serv: omit upper bound of --maxearlydata option definition" data-reference-type="merge_request" data-container="body" data-placement="top" title="" class="gfm gfm-merge_request">!1273</a></p>
<h2 dir="auto">
<a id="user-content-checklist" class="anchor" href="#checklist" aria-hidden="true"></a>Checklist</h2>
<ul class="task-list" dir="auto">
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" checked disabled> Commits have <code>Signed-off-by:</code> with name/author being identical to the commit author</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Code modified for feature</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Test suite updated with functionality tests</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Test suite updated with negative tests</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Documentation updated / NEWS entry present (for non-trivial changes)</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> CI timeout is 2h or higher (see Settings/CICD/General pipelines/Timeout)</li>
</ul>
<h2 dir="auto">
<a id="user-content-reviewers-checklist" class="anchor" href="#reviewers-checklist" aria-hidden="true"></a>Reviewer's checklist:</h2>
<ul class="task-list" dir="auto">
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Any issues marked for closing are addressed</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> There is a test suite reasonably covering new functionality or modifications</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> Function naming, parameters, return values, types, etc., are consistent and according to <code>CONTRIBUTION.md</code>
</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> This feature/change has adequate documentation added</li>
<li class="task-list-item">
<input type="checkbox" class="task-list-item-checkbox" disabled> No obvious mistakes in the code</li>
</ul>
</div>

</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #666;">

<br>
Reply to this email directly or <a href="https://gitlab.com/gnutls/gnutls/-/merge_requests/1317">view it on GitLab</a>.
<br>
You're receiving this email because of your account on gitlab.com.
If you'd like to receive fewer emails, you can
<a href="https://gitlab.com/-/sent_notifications/1cd5a9ddfd208905a8c39dabde2cadd1/unsubscribe">unsubscribe</a>
from this thread or
adjust your notification settings.
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Merge request","url":"https://gitlab.com/gnutls/gnutls/-/merge_requests/1317"}}</script>


</p>
</div>
</body>
</html>