From 235ee97b469ca6761e5096ea829f4da032c591fe Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Fri, 1 Sep 2023 10:39:44 -0400 Subject: [PATCH 1/2] Reland "Build with C11 on MSVC in the standalone Bazel build" This reverts 1e2f1696636088626cb223aa5a10f64e07b62ffd. Bazel 6.3 has since been released, which includes a fix for https://github.com/bazelbuild/bazel/issues/15073. Envoy and gRPC have both since updated to this Bazel version. The policies in https://opensource.google/documentation/policies/cplusplus-support#build_systems also imply a minimum Bazel version of 6.3.2. I'm thinking we let this bake for a little while, to catch any unexpected issues, and then, if it sticks, we try to go ahead and require C11 across the board. Update-Note: If using Bazel with MSVC, and the build fails with something like "Command line error D8016 : '/std:c++20' and '/std:c11' command-line options are incompatible", you are likely running into the above Bazel bug. Update to Bazel 6.3 or later. Bug: 623, 624 Change-Id: I8baa99392ca47bc7580bc2930e7f4b16beced91e Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/62905 Auto-Submit: David Benjamin Reviewed-by: Adam Langley Commit-Queue: Adam Langley --- util/BUILD.toplevel | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/util/BUILD.toplevel b/util/BUILD.toplevel index f5bbbdc51..48dc92068 100644 --- a/util/BUILD.toplevel +++ b/util/BUILD.toplevel @@ -121,10 +121,7 @@ boringssl_copts = [ }) + asm_copts boringssl_copts_c11 = boringssl_copts + select({ - # TODO(crbug.com/boringssl/624): This should pass /std:c11 on MSVC. It was - # reverted due to https://github.com/bazelbuild/bazel/issues/15073. When - # Bazel 6.3.0 is released, restore it and require C11 on MSVC. - "@platforms//os:windows": [], + "@platforms//os:windows": ["/std:c11"], "//conditions:default": gcc_copts_c11, }) From 9404a0b6c98e049094929db483634210560d31fb Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Fri, 1 Sep 2023 11:38:14 -0400 Subject: [PATCH 2/2] runner: Check that the shim HRRs echo the session ID We have a corresponding check on the ServerHello, but not HelloRetryRequest. See also https://github.com/rustls/rustls/pull/1374, where rustls forgot to apply the compatibility logic to HelloRetryRequest. (From the perspective of a TLS-1.2-expecting observer, HelloRetryRequest is the ServerHello, so encoding hacks need to apply to both.) Change-Id: I9b711ea45c54770a76ecfbca8bc992a4eaef6fcd Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/62906 Reviewed-by: Adam Langley Auto-Submit: David Benjamin Commit-Queue: Adam Langley --- ssl/test/runner/handshake_client.go | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/ssl/test/runner/handshake_client.go b/ssl/test/runner/handshake_client.go index 0ed0094e9..f198bb2b0 100644 --- a/ssl/test/runner/handshake_client.go +++ b/ssl/test/runner/handshake_client.go @@ -997,6 +997,10 @@ func (hs *clientHandshakeState) doTLS13Handshake(msg any) error { if haveHelloRetryRequest { hs.writeServerHash(helloRetryRequest.marshal()) + if !bytes.Equal(hs.hello.sessionID, helloRetryRequest.sessionID) { + return errors.New("tls: ClientHello and HelloRetryRequest session IDs did not match.") + } + if c.config.Bugs.FailIfHelloRetryRequested { return errors.New("tls: unexpected HelloRetryRequest") } @@ -1097,7 +1101,7 @@ func (hs *clientHandshakeState) doTLS13Handshake(msg any) error { } if !bytes.Equal(hs.hello.sessionID, hs.serverHello.sessionID) { - return errors.New("tls: session IDs did not match.") + return errors.New("tls: ClientHello and ServerHello session IDs did not match.") } // Resolve PSK and compute the early secret.