From 70690f72f7f75891b9f3abd75d13e7fe3837af18 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Wed, 25 Jan 2023 09:56:43 -0500 Subject: [PATCH 1/2] Align headers in generate_build_files.py output. This generator script once lived in Chromium, so we put the Chromium copyright on the output. But we've long since moved it into BoringSSL, so use the BoringSSL license header consistently. This avoids an unnecessary mixed of licenses in the generated branch. Bug: 542 Change-Id: I813a088d97af9671c8a4d7c9c707ae9d835f0349 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56285 Auto-Submit: David Benjamin Reviewed-by: Adam Langley Commit-Queue: Adam Langley --- util/generate_build_files.py | 91 ++++++++++++------------------------ 1 file changed, 31 insertions(+), 60 deletions(-) diff --git a/util/generate_build_files.py b/util/generate_build_files.py index 6c589f793..f778a28b1 100644 --- a/util/generate_build_files.py +++ b/util/generate_build_files.py @@ -60,24 +60,35 @@ def PathOf(x): return x if not PREFIX else os.path.join(PREFIX, x) +LICENSE_TEMPLATE = """Copyright (c) 2015, Google Inc. + +Permission to use, copy, modify, and/or distribute this software for any +purpose with or without fee is hereby granted, provided that the above +copyright notice and this permission notice appear in all copies. + +THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.""".split("\n") + +def LicenseHeader(comment): + lines = [] + for line in LICENSE_TEMPLATE: + if not line: + lines.append(comment) + else: + lines.append("%s %s" % (comment, line)) + lines.append("") + return "\n".join(lines) + + class Android(object): def __init__(self): - self.header = \ -"""# Copyright (C) 2015 The Android Open Source Project -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - + self.header = LicenseHeader("#") + """ # This file is created by generate_build_files.py. Do not edit manually. """ @@ -163,21 +174,7 @@ class Android(object): class AndroidCMake(object): def __init__(self): - self.header = \ -"""# Copyright (C) 2019 The Android Open Source Project -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - + self.header = LicenseHeader("#") + """ # This file is created by generate_build_files.py. Do not edit manually. # To specify a custom path prefix, set BORINGSSL_ROOT before including this # file, or use list(TRANSFORM ... PREPEND) from CMake 3.12. @@ -282,21 +279,7 @@ class Bazel(object): class Eureka(object): def __init__(self): - self.header = \ -"""# Copyright (C) 2017 The Android Open Source Project -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - + self.header = LicenseHeader("#") + """ # This file is created by generate_build_files.py. Do not edit manually. """ @@ -327,11 +310,7 @@ class GN(object): def __init__(self): self.firstSection = True - self.header = \ -"""# Copyright 2016 The Chromium Authors -# Use of this source code is governed by a BSD-style license that can be -# found in the LICENSE file. - + self.header = LicenseHeader("#") + """ # This file is created by generate_build_files.py. Do not edit manually. """ @@ -386,11 +365,7 @@ class GN(object): class GYP(object): def __init__(self): - self.header = \ -"""# Copyright 2016 The Chromium Authors -# Use of this source code is governed by a BSD-style license that can be -# found in the LICENSE file. - + self.header = LicenseHeader("#") + """ # This file is created by generate_build_files.py. Do not edit manually. """ @@ -421,11 +396,7 @@ class GYP(object): class CMake(object): def __init__(self): - self.header = \ -R'''# Copyright (c) 2019 The Chromium Authors. All rights reserved. -# Use of this source code is governed by a BSD-style license that can be -# found in the LICENSE file. - + self.header = LicenseHeader("#") + R''' # This file is created by generate_build_files.py. Do not edit manually. cmake_minimum_required(VERSION 3.5) From eefe6cf27cad9f8303743208f3886cc3f128de53 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Tue, 24 Jan 2023 18:08:09 -0500 Subject: [PATCH 2/2] Unexport BN_MONT_CTX_set_locked. The only callers of this function were reaching into RSA internals. We cannot fix all the issues with RSA state management when callers do this. Those have since been fixed, so unexport this function. Update-Note: This removes a function that can only be used by accessing one of BoringSSL's private locks. Change-Id: I0f067b5650ead38d2dbb7302bad4ddd0b2512458 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56286 Reviewed-by: Bob Beck Auto-Submit: David Benjamin Commit-Queue: David Benjamin Commit-Queue: Bob Beck --- crypto/fipsmodule/bn/internal.h | 9 +++++++++ include/openssl/bn.h | 9 --------- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/crypto/fipsmodule/bn/internal.h b/crypto/fipsmodule/bn/internal.h index 85009a925..0bccf1eb1 100644 --- a/crypto/fipsmodule/bn/internal.h +++ b/crypto/fipsmodule/bn/internal.h @@ -652,6 +652,15 @@ int bn_mod_inverse_prime(BIGNUM *out, const BIGNUM *a, const BIGNUM *p, int bn_mod_inverse_secret_prime(BIGNUM *out, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx, const BN_MONT_CTX *mont_p); +// BN_MONT_CTX_set_locked takes |lock| and checks whether |*pmont| is NULL. If +// so, it creates a new |BN_MONT_CTX| and sets the modulus for it to |mod|. It +// then stores it as |*pmont|. It returns one on success and zero on error. Note +// this function assumes |mod| is public. +// +// If |*pmont| is already non-NULL then it does nothing and returns one. +int BN_MONT_CTX_set_locked(BN_MONT_CTX **pmont, CRYPTO_MUTEX *lock, + const BIGNUM *mod, BN_CTX *bn_ctx); + // Low-level operations for small numbers. // diff --git a/include/openssl/bn.h b/include/openssl/bn.h index ff8eb5efa..633bb9c11 100644 --- a/include/openssl/bn.h +++ b/include/openssl/bn.h @@ -861,15 +861,6 @@ OPENSSL_EXPORT void BN_MONT_CTX_free(BN_MONT_CTX *mont); OPENSSL_EXPORT BN_MONT_CTX *BN_MONT_CTX_copy(BN_MONT_CTX *to, const BN_MONT_CTX *from); -// BN_MONT_CTX_set_locked takes |lock| and checks whether |*pmont| is NULL. If -// so, it creates a new |BN_MONT_CTX| and sets the modulus for it to |mod|. It -// then stores it as |*pmont|. It returns one on success and zero on error. Note -// this function assumes |mod| is public. -// -// If |*pmont| is already non-NULL then it does nothing and returns one. -int BN_MONT_CTX_set_locked(BN_MONT_CTX **pmont, CRYPTO_MUTEX *lock, - const BIGNUM *mod, BN_CTX *bn_ctx); - // BN_to_montgomery sets |ret| equal to |a| in the Montgomery domain. |a| is // assumed to be in the range [0, n), where |n| is the Montgomery modulus. It // returns one on success or zero on error.