update master-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2023-04-07 07:00:12 +00:00
4 changed files with 20 additions and 8 deletions
+9 -2
View File
@@ -833,11 +833,18 @@ static enum ssl_hs_wait_t do_read_server_hello(SSL_HANDSHAKE *hs) {
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_INTERNAL_ERROR);
return ssl_hs_error;
}
// Note: session_id could be empty.
hs->new_session->session_id_length = CBS_len(&server_hello.session_id);
// Save the session ID from the server. This may be empty if the session
// isn't resumable, or if we'll receive a session ticket later.
assert(CBS_len(&server_hello.session_id) <= SSL3_SESSION_ID_SIZE);
static_assert(SSL3_SESSION_ID_SIZE <= UINT8_MAX,
"max session ID is too large");
hs->new_session->session_id_length =
static_cast<uint8_t>(CBS_len(&server_hello.session_id));
OPENSSL_memcpy(hs->new_session->session_id,
CBS_data(&server_hello.session_id),
CBS_len(&server_hello.session_id));
hs->new_session->cipher = hs->new_cipher;
}
+2 -2
View File
@@ -3838,11 +3838,11 @@ struct ssl_session_st {
// session. In TLS 1.3 and up, it is the resumption PSK for sessions handed to
// the caller, but it stores the resumption secret when stored on |SSL|
// objects.
int secret_length = 0;
uint8_t secret_length = 0;
uint8_t secret[SSL_MAX_MASTER_KEY_LENGTH] = {0};
// session_id - valid?
unsigned session_id_length = 0;
uint8_t session_id_length = 0;
uint8_t session_id[SSL_MAX_SSL_SESSION_ID_LENGTH] = {0};
// this is used to determine whether the session is being reused in
// the appropriate context. It is up to the application to set this,
+7 -3
View File
@@ -486,7 +486,7 @@ static int SSL_SESSION_parse_bounded_octet_string(CBS *cbs, uint8_t *out,
return 0;
}
OPENSSL_memcpy(out, CBS_data(&value), CBS_len(&value));
*out_len = (uint8_t)CBS_len(&value);
*out_len = static_cast<uint8_t>(CBS_len(&value));
return 1;
}
@@ -578,9 +578,13 @@ UniquePtr<SSL_SESSION> SSL_SESSION_parse(CBS *cbs,
return nullptr;
}
OPENSSL_memcpy(ret->session_id, CBS_data(&session_id), CBS_len(&session_id));
ret->session_id_length = CBS_len(&session_id);
static_assert(SSL3_MAX_SSL_SESSION_ID_LENGTH <= UINT8_MAX,
"max session ID is too large");
ret->session_id_length = static_cast<uint8_t>(CBS_len(&session_id));
OPENSSL_memcpy(ret->secret, CBS_data(&secret), CBS_len(&secret));
ret->secret_length = CBS_len(&secret);
static_assert(SSL_MAX_MASTER_KEY_LENGTH <= UINT8_MAX,
"max secret is too large");
ret->secret_length = static_cast<uint8_t>(CBS_len(&secret));
CBS child;
uint64_t timeout;
+2 -1
View File
@@ -513,7 +513,8 @@ bool tls13_add_certificate(SSL_HANDSHAKE *hs) {
if (!ssl->method->init_message(ssl, cbb.get(), body,
SSL3_MT_COMPRESSED_CERTIFICATE) ||
!CBB_add_u16(body, hs->cert_compression_alg_id) ||
!CBB_add_u24(body, msg.size()) ||
msg.size() > (1u << 24) - 1 || //
!CBB_add_u24(body, static_cast<uint32_t>(msg.size())) ||
!CBB_add_u24_length_prefixed(body, &compressed)) {
OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
return false;