update master-with-bazel from master branch
This commit is contained in:
@@ -5244,13 +5244,6 @@ OPENSSL_EXPORT int SSL_CTX_set_tlsext_status_arg(SSL_CTX *ctx, void *arg);
|
||||
SSL_R_TLSV1_ALERT_BAD_CERTIFICATE_HASH_VALUE
|
||||
#define SSL_R_TLSV1_CERTIFICATE_REQUIRED SSL_R_TLSV1_ALERT_CERTIFICATE_REQUIRED
|
||||
|
||||
// SSL_CIPHER_get_value calls |SSL_CIPHER_get_protocol_id|.
|
||||
//
|
||||
// TODO(davidben): |SSL_CIPHER_get_value| was our name for this function, but
|
||||
// upstream added it as |SSL_CIPHER_get_protocol_id|. Switch callers to the new
|
||||
// name and remove this one.
|
||||
OPENSSL_EXPORT uint16_t SSL_CIPHER_get_value(const SSL_CIPHER *cipher);
|
||||
|
||||
|
||||
// Compliance policy configurations
|
||||
//
|
||||
|
||||
@@ -1370,10 +1370,6 @@ uint16_t SSL_CIPHER_get_protocol_id(const SSL_CIPHER *cipher) {
|
||||
return static_cast<uint16_t>(cipher->id);
|
||||
}
|
||||
|
||||
uint16_t SSL_CIPHER_get_value(const SSL_CIPHER *cipher) {
|
||||
return SSL_CIPHER_get_protocol_id(cipher);
|
||||
}
|
||||
|
||||
int SSL_CIPHER_is_aead(const SSL_CIPHER *cipher) {
|
||||
return (cipher->algorithm_mac & SSL_AEAD) != 0;
|
||||
}
|
||||
|
||||
@@ -198,9 +198,8 @@ static enum ssl_hs_wait_t do_read_hello_retry_request(SSL_HANDSHAKE *hs) {
|
||||
if (cipher == nullptr ||
|
||||
SSL_CIPHER_get_min_version(cipher) > ssl_protocol_version(ssl) ||
|
||||
SSL_CIPHER_get_max_version(cipher) < ssl_protocol_version(ssl) ||
|
||||
!ssl_tls13_cipher_meets_policy(
|
||||
SSL_CIPHER_get_value(cipher),
|
||||
ssl->config->tls13_cipher_policy)) {
|
||||
!ssl_tls13_cipher_meets_policy(SSL_CIPHER_get_protocol_id(cipher),
|
||||
ssl->config->tls13_cipher_policy)) {
|
||||
OPENSSL_PUT_ERROR(SSL, SSL_R_WRONG_CIPHER_RETURNED);
|
||||
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_ILLEGAL_PARAMETER);
|
||||
return ssl_hs_error;
|
||||
|
||||
Reference in New Issue
Block a user