diff --git a/BUILD b/BUILD index c3143894a..a855aa5a9 100644 --- a/BUILD +++ b/BUILD @@ -18,14 +18,7 @@ load( "crypto_headers", "crypto_internal_headers", "crypto_sources", - "crypto_sources_apple_aarch64", - "crypto_sources_apple_arm", - "crypto_sources_apple_x86", - "crypto_sources_apple_x86_64", - "crypto_sources_linux_aarch64", - "crypto_sources_linux_arm", - "crypto_sources_linux_x86", - "crypto_sources_linux_x86_64", + "crypto_sources_asm", "fips_fragments", "ssl_headers", "ssl_internal_headers", @@ -38,33 +31,47 @@ licenses(["notice"]) exports_files(["LICENSE"]) -[ - ( - config_setting( - name = os + "_" + arch, - constraint_values = [ - "@platforms//os:" + os, - "@platforms//cpu:" + arch, - ], - ), - ) - for os in [ - "linux", - "android", - "macos", - "ios", - "tvos", - "watchos", - ] - for arch in [ - "arm64", - "armv7", - "x86_64", - "x86_32", - ] -] +# By default, the C files will expect assembly files, if any, to be linked in +# with the build. This default can be flipped with -DOPENSSL_NO_ASM. If building +# in a configuration where we have no assembly optimizations, -DOPENSSL_NO_ASM +# has no effect, and either value is fine. +# +# Like C files, assembly files are wrapped in #ifdef (or NASM equivalent), so it +# is safe to include a file for the wrong platform in the build. It will just +# output an empty object file. However, we need some platform selectors to +# distinguish between gas or NASM syntax. +# +# For all non-Windows platforms, we use gas assembly syntax and can assume any +# GCC-compatible toolchain includes a gas-compatible assembler. +# +# For Windows, we use NASM on x86 and x86_64 and gas, specifically +# clang-assembler, on aarch64. We have not yet added NASM support to this build, +# and would need to detect MSVC vs clang-cl for aarch64 so, for now, we just +# disable assembly on Windows across the board. +# +# These two selects for asm_sources and asm_copts must be kept in sync. If we +# specify assembly, we don't want OPENSSL_NO_ASM. If we don't specify assembly, +# we want OPENSSL_NO_ASM, in case the C files expect them in some format (e.g. +# NASM) this build file doesn't yet support. +# +# TODO(https://crbug.com/boringssl/531): Enable assembly for Windows. +asm_sources = select({ + "@platforms//os:windows": [], + "//conditions:default": crypto_sources_asm, +}) +asm_copts = select({ + "@platforms//os:windows": ["-DOPENSSL_NO_ASM"], + "//conditions:default": [], +}) -posix_copts = [ +# Configure C, C++, and common flags for GCC-compatible toolchains. +# +# TODO(davidben): Can we remove some of these? In Bazel, are warnings the +# toolchain or project's responsibility? -Wa,--noexecstack should be unnecessary +# now, though https://crbug.com/boringssl/292 tracks testing this in CI. +# -fno-common did not become default until +# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85678. +gcc_copts = [ # Assembler option --noexecstack adds .note.GNU-stack to each object to # ensure that binaries can be built with non-executable stack. "-Wa,--noexecstack", @@ -79,119 +86,51 @@ posix_copts = [ "-Wshadow", "-fno-common", ] - -glibc_copts = posix_copts + [ - # This is needed on glibc systems (at least) to get rwlock in pthread, but - # it should not be set on Apple platforms or FreeBSD, where it instead - # disables APIs we use. - # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 - "-D_XOPEN_SOURCE=700", -] - -boringssl_copts = select({ - "@platforms//os:linux": glibc_copts, - "@platforms//os:android": posix_copts, - "@platforms//os:macos": posix_copts, - "@platforms//os:ios": posix_copts, - "@platforms//os:tvos": posix_copts, - "@platforms//os:watchos": posix_copts, - "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], - "//conditions:default": [], -}) - -# These selects must be kept in sync. -crypto_sources_asm = select({ - ":linux_armv7": crypto_sources_linux_arm, - ":linux_arm64": crypto_sources_linux_aarch64, - ":linux_x86_32": crypto_sources_linux_x86, - ":linux_x86_64": crypto_sources_linux_x86_64, - ":android_armv7": crypto_sources_linux_arm, - ":android_arm64": crypto_sources_linux_aarch64, - ":android_x86_32": crypto_sources_linux_x86, - ":android_x86_64": crypto_sources_linux_x86_64, - ":macos_armv7": crypto_sources_apple_arm, - ":macos_arm64": crypto_sources_apple_aarch64, - ":macos_x86_32": crypto_sources_apple_x86, - ":macos_x86_64": crypto_sources_apple_x86_64, - ":ios_armv7": crypto_sources_apple_arm, - ":ios_arm64": crypto_sources_apple_aarch64, - ":ios_x86_32": crypto_sources_apple_x86, - ":ios_x86_64": crypto_sources_apple_x86_64, - ":tvos_armv7": crypto_sources_apple_arm, - ":tvos_arm64": crypto_sources_apple_aarch64, - ":tvos_x86_32": crypto_sources_apple_x86, - ":tvos_x86_64": crypto_sources_apple_x86_64, - ":watchos_armv7": crypto_sources_apple_arm, - ":watchos_arm64": crypto_sources_apple_aarch64, - ":watchos_x86_32": crypto_sources_apple_x86, - ":watchos_x86_64": crypto_sources_apple_x86_64, - "//conditions:default": [], -}) -boringssl_copts += select({ - ":linux_armv7": [], - ":linux_arm64": [], - ":linux_x86_32": [], - ":linux_x86_64": [], - ":android_armv7": [], - ":android_arm64": [], - ":android_x86_32": [], - ":android_x86_64": [], - ":macos_armv7": [], - ":macos_arm64": [], - ":macos_x86_32": [], - ":macos_x86_64": [], - ":ios_armv7": [], - ":ios_arm64": [], - ":ios_x86_32": [], - ":ios_x86_64": [], - ":tvos_armv7": [], - ":tvos_arm64": [], - ":tvos_x86_32": [], - ":tvos_x86_64": [], - ":watchos_armv7": [], - ":watchos_arm64": [], - ":watchos_x86_32": [], - ":watchos_x86_64": [], - "//conditions:default": ["-DOPENSSL_NO_ASM"], -}) - -# For C targets only (not C++), compile with C11 support. -posix_copts_c11 = [ +gcc_copts_c11 = [ "-std=c11", "-Wmissing-prototypes", "-Wold-style-definition", "-Wstrict-prototypes", ] - -boringssl_copts_c11 = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_c11, - "@platforms//os:android": posix_copts_c11, - "@platforms//os:macos": posix_copts_c11, - "@platforms//os:ios": posix_copts_c11, - "@platforms//os:tvos": posix_copts_c11, - "@platforms//os:watchos": posix_copts_c11, - "//conditions:default": [], -}) - -# For C++ targets only (not C), compile with C++14 support. -posix_copts_cxx = [ +gcc_copts_cxx = [ "-std=c++14", "-Wmissing-declarations", ] -boringssl_copts_cxx = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_cxx, - "@platforms//os:android": posix_copts_cxx, - "@platforms//os:macos": posix_copts_cxx, - "@platforms//os:ios": posix_copts_cxx, - "@platforms//os:tvos": posix_copts_cxx, - "@platforms//os:watchos": posix_copts_cxx, +boringssl_copts = select({ + # We assume that non-Windows builds use a GCC-compatible toolchain and that + # Windows builds do not. + # + # TODO(davidben): Should these be querying something in @bazel_tools? + # Unfortunately, @bazel_tools is undocumented. See + # https://github.com/bazelbuild/bazel/issues/14914 + "@platforms//os:windows": [], + "//conditions:default": gcc_copts, +}) + select({ + # This is needed on glibc systems to get rwlock in pthreads, but it should + # not be set on Apple platforms or FreeBSD, where it instead disables APIs + # we use. + # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 + "@platforms//os:linux": ["-D_XOPEN_SOURCE=700"], + # Without WIN32_LEAN_AND_MEAN, pulls in wincrypt.h, which + # conflicts with our . + "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], "//conditions:default": [], +}) + asm_copts + +boringssl_copts_c11 = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_c11, +}) + +boringssl_copts_cxx = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_cxx, }) cc_library( name = "crypto", - srcs = crypto_sources + crypto_internal_headers + crypto_sources_asm, + srcs = crypto_sources + crypto_internal_headers + asm_sources, hdrs = crypto_headers + fips_fragments, copts = boringssl_copts_c11, includes = ["src/include"], diff --git a/BUILD.generated.bzl b/BUILD.generated.bzl index 138cd8a3b..e26538445 100644 --- a/BUILD.generated.bzl +++ b/BUILD.generated.bzl @@ -713,3 +713,18 @@ crypto_sources_win_x86_64 = [ "win-x86_64/crypto/fipsmodule/x86_64-mont5-win.asm", "win-x86_64/crypto/test/trampoline-x86_64-win.asm", ] + +crypto_sources_asm = [] +crypto_sources_asm.extend(crypto_sources_apple_arm) +crypto_sources_asm.extend(crypto_sources_apple_aarch64) +crypto_sources_asm.extend(crypto_sources_apple_x86) +crypto_sources_asm.extend(crypto_sources_apple_x86_64) +crypto_sources_asm.extend(crypto_sources_linux_arm) +crypto_sources_asm.extend(crypto_sources_linux_aarch64) +crypto_sources_asm.extend(crypto_sources_linux_x86) +crypto_sources_asm.extend(crypto_sources_linux_x86_64) +crypto_sources_asm.extend(crypto_sources_win_aarch64) + +crypto_sources_nasm = [] +crypto_sources_nasm.extend(crypto_sources_win_x86) +crypto_sources_nasm.extend(crypto_sources_win_x86_64) diff --git a/CMakeLists.txt b/CMakeLists.txt index 0000cc4a7..b9401eecf 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -14,21 +14,21 @@ # This file is created by generate_build_files.py. Do not edit manually. -cmake_minimum_required(VERSION 3.5) +cmake_minimum_required(VERSION 3.10) project(BoringSSL LANGUAGES C CXX) -if(CMAKE_CXX_COMPILER_ID MATCHES "Clang") - set(CLANG 1) +set(CMAKE_CXX_STANDARD 14) +set(CMAKE_CXX_STANDARD_REQUIRED ON) +set(CMAKE_C_STANDARD 11) +set(CMAKE_C_STANDARD_REQUIRED ON) +if(CMAKE_COMPILER_IS_GNUCXX OR CMAKE_CXX_COMPILER_ID MATCHES "Clang") + set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") + set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common") endif() -if(CMAKE_COMPILER_IS_GNUCXX OR CLANG) - set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -std=c++14 -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common -std=c11") -endif() - -# pthread_rwlock_t requires a feature flag. -if(NOT WIN32) +# pthread_rwlock_t requires a feature flag on glibc. +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -D_XOPEN_SOURCE=700") endif() @@ -38,73 +38,19 @@ if(WIN32) add_definitions(-DNOMINMAX) # Allow use of fopen. add_definitions(-D_CRT_SECURE_NO_WARNINGS) - # VS 2017 and higher supports STL-only warning suppressions. - # A bug in CMake < 3.13.0 may cause the space in this value to - # cause issues when building with NASM. In that case, update CMake. - add_definitions("-D_STL_EXTRA_DISABLED_WARNINGS=4774 4987") endif() add_definitions(-DBORINGSSL_IMPLEMENTATION) -# CMake's iOS support uses Apple's multiple-architecture toolchain. It takes an -# architecture list from CMAKE_OSX_ARCHITECTURES, leaves CMAKE_SYSTEM_PROCESSOR -# alone, and expects all architecture-specific logic to be conditioned within -# the source files rather than the build. This does not work for our assembly -# files, so we fix CMAKE_SYSTEM_PROCESSOR and only support single-architecture -# builds. -if(NOT OPENSSL_NO_ASM AND CMAKE_OSX_ARCHITECTURES) - list(LENGTH CMAKE_OSX_ARCHITECTURES NUM_ARCHES) - if(NOT NUM_ARCHES EQUAL 1) - message(FATAL_ERROR "Universal binaries not supported.") - endif() - list(GET CMAKE_OSX_ARCHITECTURES 0 CMAKE_SYSTEM_PROCESSOR) -endif() - -if(OPENSSL_NO_ASM) - add_definitions(-DOPENSSL_NO_ASM) - set(ARCH "generic") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86_64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "amd64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "AMD64") - # cmake reports AMD64 on Windows, but we might be building for 32-bit. - if(CMAKE_SIZEOF_VOID_P EQUAL 8) - set(ARCH "x86_64") - else() - set(ARCH "x86") - endif() -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i386") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i686") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "aarch64") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64") - set(ARCH "aarch64") -# Apple A12 Bionic chipset which is added in iPhone XS/XS Max/XR uses arm64e architecture. -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64e") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "^arm*") - set(ARCH "arm") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "mips") - # Just to avoid the “unknown processor” error. - set(ARCH "generic") -else() - message(FATAL_ERROR "Unknown processor:" ${CMAKE_SYSTEM_PROCESSOR}) -endif() - if(NOT OPENSSL_NO_ASM) - if(UNIX) + # On x86 and x86_64 Windows, we use the NASM output. + if(WIN32 AND CMAKE_SYSTEM_PROCESSOR MATCHES "AMD64|x86_64|amd64|x86|i[3-6]86") + enable_language(ASM_NASM) + set(OPENSSL_NASM TRUE) + set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") + else() enable_language(ASM) - - # Clang's integerated assembler does not support debug symbols. - if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") - set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") - endif() - + set(OPENSSL_ASM TRUE) # CMake does not add -isysroot and -arch flags to assembly. if(APPLE) if(CMAKE_OSX_SYSROOT) @@ -114,9 +60,13 @@ if(NOT OPENSSL_NO_ASM) set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -arch ${arch}") endforeach() endif() - else() - set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") - enable_language(ASM_NASM) + if(NOT WIN32) + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,--noexecstack") + endif() + # Clang's integerated assembler does not support debug symbols. + if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") + endif() endif() endif() @@ -130,7 +80,7 @@ endif() include_directories(src/include) set( - CRYPTO_apple_aarch64_SOURCES + CRYPTO_SOURCES_ASM apple-aarch64/crypto/chacha/chacha-armv8-apple.S apple-aarch64/crypto/cipher_extra/chacha20_poly1305_armv8-apple.S @@ -146,11 +96,6 @@ set( apple-aarch64/crypto/fipsmodule/sha512-armv8-apple.S apple-aarch64/crypto/fipsmodule/vpaes-armv8-apple.S apple-aarch64/crypto/test/trampoline-armv8-apple.S -) - -set( - CRYPTO_apple_arm_SOURCES - apple-arm/crypto/chacha/chacha-armv4-apple.S apple-arm/crypto/fipsmodule/aesv8-armv7-apple.S apple-arm/crypto/fipsmodule/armv4-mont-apple.S @@ -162,11 +107,6 @@ set( apple-arm/crypto/fipsmodule/sha512-armv4-apple.S apple-arm/crypto/fipsmodule/vpaes-armv7-apple.S apple-arm/crypto/test/trampoline-armv4-apple.S -) - -set( - CRYPTO_apple_x86_SOURCES - apple-x86/crypto/chacha/chacha-x86-apple.S apple-x86/crypto/fipsmodule/aesni-x86-apple.S apple-x86/crypto/fipsmodule/bn-586-apple.S @@ -180,11 +120,6 @@ set( apple-x86/crypto/fipsmodule/vpaes-x86-apple.S apple-x86/crypto/fipsmodule/x86-mont-apple.S apple-x86/crypto/test/trampoline-x86-apple.S -) - -set( - CRYPTO_apple_x86_64_SOURCES - apple-x86_64/crypto/chacha/chacha-x86_64-apple.S apple-x86_64/crypto/cipher_extra/aes128gcmsiv-x86_64-apple.S apple-x86_64/crypto/cipher_extra/chacha20_poly1305_x86_64-apple.S @@ -204,11 +139,6 @@ set( apple-x86_64/crypto/fipsmodule/x86_64-mont-apple.S apple-x86_64/crypto/fipsmodule/x86_64-mont5-apple.S apple-x86_64/crypto/test/trampoline-x86_64-apple.S -) - -set( - CRYPTO_linux_aarch64_SOURCES - linux-aarch64/crypto/chacha/chacha-armv8-linux.S linux-aarch64/crypto/cipher_extra/chacha20_poly1305_armv8-linux.S linux-aarch64/crypto/fipsmodule/aesv8-armv8-linux.S @@ -223,11 +153,6 @@ set( linux-aarch64/crypto/fipsmodule/sha512-armv8-linux.S linux-aarch64/crypto/fipsmodule/vpaes-armv8-linux.S linux-aarch64/crypto/test/trampoline-armv8-linux.S -) - -set( - CRYPTO_linux_arm_SOURCES - linux-arm/crypto/chacha/chacha-armv4-linux.S linux-arm/crypto/fipsmodule/aesv8-armv7-linux.S linux-arm/crypto/fipsmodule/armv4-mont-linux.S @@ -239,13 +164,6 @@ set( linux-arm/crypto/fipsmodule/sha512-armv4-linux.S linux-arm/crypto/fipsmodule/vpaes-armv7-linux.S linux-arm/crypto/test/trampoline-armv4-linux.S - src/crypto/curve25519/asm/x25519-asm-arm.S - src/crypto/poly1305/poly1305_arm_asm.S -) - -set( - CRYPTO_linux_x86_SOURCES - linux-x86/crypto/chacha/chacha-x86-linux.S linux-x86/crypto/fipsmodule/aesni-x86-linux.S linux-x86/crypto/fipsmodule/bn-586-linux.S @@ -259,11 +177,6 @@ set( linux-x86/crypto/fipsmodule/vpaes-x86-linux.S linux-x86/crypto/fipsmodule/x86-mont-linux.S linux-x86/crypto/test/trampoline-x86-linux.S -) - -set( - CRYPTO_linux_x86_64_SOURCES - linux-x86_64/crypto/chacha/chacha-x86_64-linux.S linux-x86_64/crypto/cipher_extra/aes128gcmsiv-x86_64-linux.S linux-x86_64/crypto/cipher_extra/chacha20_poly1305_x86_64-linux.S @@ -283,11 +196,8 @@ set( linux-x86_64/crypto/fipsmodule/x86_64-mont-linux.S linux-x86_64/crypto/fipsmodule/x86_64-mont5-linux.S linux-x86_64/crypto/test/trampoline-x86_64-linux.S -) - -set( - CRYPTO_win_aarch64_SOURCES - + src/crypto/curve25519/asm/x25519-asm-arm.S + src/crypto/poly1305/poly1305_arm_asm.S win-aarch64/crypto/chacha/chacha-armv8-win.S win-aarch64/crypto/cipher_extra/chacha20_poly1305_armv8-win.S win-aarch64/crypto/fipsmodule/aesv8-armv8-win.S @@ -305,7 +215,7 @@ set( ) set( - CRYPTO_win_x86_SOURCES + CRYPTO_SOURCES_NASM win-x86/crypto/chacha/chacha-x86-win.asm win-x86/crypto/fipsmodule/aesni-x86-win.asm @@ -320,11 +230,6 @@ set( win-x86/crypto/fipsmodule/vpaes-x86-win.asm win-x86/crypto/fipsmodule/x86-mont-win.asm win-x86/crypto/test/trampoline-x86-win.asm -) - -set( - CRYPTO_win_x86_64_SOURCES - win-x86_64/crypto/chacha/chacha-x86_64-win.asm win-x86_64/crypto/cipher_extra/aes128gcmsiv-x86_64-win.asm win-x86_64/crypto/cipher_extra/chacha20_poly1305_x86_64-win.asm @@ -346,18 +251,17 @@ set( win-x86_64/crypto/test/trampoline-x86_64-win.asm ) -if(APPLE) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_apple_${ARCH}_SOURCES}) -elseif(UNIX) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_linux_${ARCH}_SOURCES}) -elseif(WIN32) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_win_${ARCH}_SOURCES}) +if(OPENSSL_ASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_ASM}) +endif() +if(OPENSSL_NASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_NASM}) endif() add_library( crypto - ${CRYPTO_ARCH_SOURCES} + ${CRYPTO_SOURCES_ASM_USED} err_data.c src/crypto/asn1/a_bitstr.c src/crypto/asn1/a_bool.c @@ -650,8 +554,9 @@ add_executable( target_link_libraries(bssl ssl crypto) -if(NOT WIN32 AND NOT ANDROID) - target_link_libraries(crypto pthread) +if(NOT ANDROID) + find_package(Threads REQUIRED) + target_link_libraries(crypto Threads::Threads) endif() if(WIN32) diff --git a/src/crypto/err/err_data_generate.go b/src/crypto/err/err_data_generate.go index 963964c66..3e06f00bd 100644 --- a/src/crypto/err/err_data_generate.go +++ b/src/crypto/err/err_data_generate.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2015, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2015, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/crypto/fipsmodule/bn/bn_test_to_fuzzer.go b/src/crypto/fipsmodule/bn/bn_test_to_fuzzer.go index 13cff26a0..2915db5f9 100644 --- a/src/crypto/fipsmodule/bn/bn_test_to_fuzzer.go +++ b/src/crypto/fipsmodule/bn/bn_test_to_fuzzer.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( @@ -138,7 +140,7 @@ func checkKeys(t test, keys ...string) bool { } } - for k, _ := range t.Values { + for k := range t.Values { var found bool for _, k2 := range keys { if k == k2 { diff --git a/src/crypto/fipsmodule/bn/check_bn_tests.go b/src/crypto/fipsmodule/bn/check_bn_tests.go index 26443b93d..032b9e328 100644 --- a/src/crypto/fipsmodule/bn/check_bn_tests.go +++ b/src/crypto/fipsmodule/bn/check_bn_tests.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( @@ -135,7 +137,7 @@ func checkKeys(t test, keys ...string) bool { } } - for k, _ := range t.Values { + for k := range t.Values { var found bool for _, k2 := range keys { if k == k2 { diff --git a/src/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go b/src/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go index 716da55b7..1d3896aa9 100644 --- a/src/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go +++ b/src/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/crypto/fipsmodule/ec/make_p256-nistz-tests.go b/src/crypto/fipsmodule/ec/make_p256-nistz-tests.go index 36194e61b..e10990b30 100644 --- a/src/crypto/fipsmodule/ec/make_p256-nistz-tests.go +++ b/src/crypto/fipsmodule/ec/make_p256-nistz-tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/crypto/fipsmodule/ec/make_tables.go b/src/crypto/fipsmodule/ec/make_tables.go index dbcaab06f..ef7ac64f3 100644 --- a/src/crypto/fipsmodule/ec/make_tables.go +++ b/src/crypto/fipsmodule/ec/make_tables.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/crypto/obj/objects.go b/src/crypto/obj/objects.go index 1b9ded347..716adf948 100644 --- a/src/crypto/obj/objects.go +++ b/src/crypto/obj/objects.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/src/crypto/x509/test/make_basic_constraints.go b/src/crypto/x509/test/make_basic_constraints.go index 652479968..ea502b4c8 100644 --- a/src/crypto/x509/test/make_basic_constraints.go +++ b/src/crypto/x509/test/make_basic_constraints.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_basic_constraints.go generates self-signed certificates with the basic // constraints extension. diff --git a/src/crypto/x509/test/make_invalid_extensions.go b/src/crypto/x509/test/make_invalid_extensions.go index aba2d7197..8287bf8d3 100644 --- a/src/crypto/x509/test/make_invalid_extensions.go +++ b/src/crypto/x509/test/make_invalid_extensions.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_invalid_extensions.go generates a number of certificate chains with // invalid extension encodings. diff --git a/src/crypto/x509/test/make_many_constraints.go b/src/crypto/x509/test/make_many_constraints.go index 578618dfb..24a5c4071 100644 --- a/src/crypto/x509/test/make_many_constraints.go +++ b/src/crypto/x509/test/make_many_constraints.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2017, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2017, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_many_constraints.go generates test certificates many_constraints.pem, // many_names*.pem, and some_names*.pem for x509_test.cc @@ -107,10 +109,10 @@ func main() { NotBefore: notBefore, NotAfter: notAfter, BasicConstraintsValid: true, - IsCA: true, - ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, - KeyUsage: x509.KeyUsageCertSign, - SignatureAlgorithm: x509.SHA256WithRSA, + IsCA: true, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + KeyUsage: x509.KeyUsageCertSign, + SignatureAlgorithm: x509.SHA256WithRSA, } for i := 0; i < 513; i++ { caTemplate.ExcludedDNSDomains = append(caTemplate.ExcludedDNSDomains, fmt.Sprintf("x%d.test", i)) @@ -149,10 +151,10 @@ func main() { NotBefore: notBefore, NotAfter: notAfter, BasicConstraintsValid: true, - IsCA: false, - ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, - KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment, - SignatureAlgorithm: x509.SHA256WithRSA, + IsCA: false, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment, + SignatureAlgorithm: x509.SHA256WithRSA, } for i := 0; i < leaf.names; i++ { leafTemplate.DNSNames = append(leafTemplate.DNSNames, fmt.Sprintf("t%d.test", i)) diff --git a/src/crypto/x509/test/make_policy_certs.go b/src/crypto/x509/test/make_policy_certs.go index c57d97310..bc944f2de 100644 --- a/src/crypto/x509/test/make_policy_certs.go +++ b/src/crypto/x509/test/make_policy_certs.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_policy_certs.go generates certificates for testing policy handling. package main diff --git a/src/crypto/x509/x509_test.cc b/src/crypto/x509/x509_test.cc index fea26e7bc..63ce092a3 100644 --- a/src/crypto/x509/x509_test.cc +++ b/src/crypto/x509/x509_test.cc @@ -5716,6 +5716,10 @@ TEST(X509Test, ExtensionFromConf) { // If no config is provided, this should fail. {"basicConstraints", "critical,@section", nullptr, {}}, + // issuingDistributionPoint takes a list of name:value pairs. Omitting the + // value is not allowed. + {"issuingDistributionPoint", "fullname", nullptr, {}}, + // The "DER:" prefix just specifies an arbitrary byte string. Colons // separators are ignored. {kTestOID, "DER:0001020304", nullptr, {0x30, 0x15, 0x06, 0x0c, 0x2a, 0x86, @@ -6205,3 +6209,14 @@ key = FORMAT:HEX,OCTWRAP,OCT:9d61b19deffd5a60ba844af492ec2cc44449c5697b326919703 } } } + +TEST(X509Test, AddUnserializableExtension) { + bssl::UniquePtr key = PrivateKeyFromPEM(kP256Key); + ASSERT_TRUE(key); + bssl::UniquePtr x509 = + MakeTestCert("Issuer", "Subject", key.get(), /*is_ca=*/true); + ASSERT_TRUE(x509); + bssl::UniquePtr ext(X509_EXTENSION_new()); + ASSERT_TRUE(X509_EXTENSION_set_object(ext.get(), OBJ_nid2obj(NID_undef))); + EXPECT_FALSE(X509_add_ext(x509.get(), ext.get(), /*loc=*/-1)); +} diff --git a/src/crypto/x509/x509_v3.c b/src/crypto/x509/x509_v3.c index 9153dce19..dd8435243 100644 --- a/src/crypto/x509/x509_v3.c +++ b/src/crypto/x509/x509_v3.c @@ -148,6 +148,7 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, X509_EXTENSION *new_ex = NULL; int n; STACK_OF(X509_EXTENSION) *sk = NULL; + int free_sk = 0; if (x == NULL) { OPENSSL_PUT_ERROR(X509, ERR_R_PASSED_NULL_PARAMETER); @@ -158,6 +159,7 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, if ((sk = sk_X509_EXTENSION_new_null()) == NULL) { goto err; } + free_sk = 1; } else { sk = *x; } @@ -183,7 +185,9 @@ err: OPENSSL_PUT_ERROR(X509, ERR_R_MALLOC_FAILURE); err2: X509_EXTENSION_free(new_ex); - sk_X509_EXTENSION_free(sk); + if (free_sk) { + sk_X509_EXTENSION_free(sk); + } return NULL; } diff --git a/src/crypto/x509v3/v3_conf.c b/src/crypto/x509v3/v3_conf.c index 480bb3b79..a4f172d3f 100644 --- a/src/crypto/x509v3/v3_conf.c +++ b/src/crypto/x509v3/v3_conf.c @@ -357,13 +357,12 @@ int X509V3_EXT_add_nconf_sk(const CONF *conf, const X509V3_CTX *ctx, for (size_t i = 0; i < sk_CONF_VALUE_num(nval); i++) { const CONF_VALUE *val = sk_CONF_VALUE_value(nval, i); X509_EXTENSION *ext = X509V3_EXT_nconf(conf, ctx, val->name, val->value); - if (ext == NULL) { + int ok = ext != NULL && // + (sk == NULL || X509v3_add_ext(sk, ext, -1) != NULL); + X509_EXTENSION_free(ext); + if (!ok) { return 0; } - if (sk) { - X509v3_add_ext(sk, ext, -1); - } - X509_EXTENSION_free(ext); } return 1; } diff --git a/src/crypto/x509v3/v3_crld.c b/src/crypto/x509v3/v3_crld.c index 4b5a36df8..0b6899a6f 100644 --- a/src/crypto/x509v3/v3_crld.c +++ b/src/crypto/x509v3/v3_crld.c @@ -129,6 +129,13 @@ static STACK_OF(GENERAL_NAME) *gnames_from_sectname(const X509V3_CTX *ctx, static int set_dist_point_name(DIST_POINT_NAME **pdp, const X509V3_CTX *ctx, const CONF_VALUE *cnf) { + // If |cnf| comes from |X509V3_parse_list|, which is possible for a v2i + // function, |cnf->value| may be NULL. + if (cnf->value == NULL) { + OPENSSL_PUT_ERROR(X509V3, X509V3_R_MISSING_VALUE); + return 0; + } + STACK_OF(GENERAL_NAME) *fnm = NULL; STACK_OF(X509_NAME_ENTRY) *rnm = NULL; if (!strncmp(cnf->name, "fullname", 9)) { diff --git a/src/decrepit/cfb/cfb.c b/src/decrepit/cfb/cfb.c index d23115357..c15292cf0 100644 --- a/src/decrepit/cfb/cfb.c +++ b/src/decrepit/cfb/cfb.c @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/src/decrepit/cfb/cfb_test.cc b/src/decrepit/cfb/cfb_test.cc index 2510a88a6..da9681eca 100644 --- a/src/decrepit/cfb/cfb_test.cc +++ b/src/decrepit/cfb/cfb_test.cc @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/src/decrepit/xts/xts_test.cc b/src/decrepit/xts/xts_test.cc index 22e80facd..346ca556c 100644 --- a/src/decrepit/xts/xts_test.cc +++ b/src/decrepit/xts/xts_test.cc @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/src/util/BUILD.toplevel b/src/util/BUILD.toplevel index c3143894a..a855aa5a9 100644 --- a/src/util/BUILD.toplevel +++ b/src/util/BUILD.toplevel @@ -18,14 +18,7 @@ load( "crypto_headers", "crypto_internal_headers", "crypto_sources", - "crypto_sources_apple_aarch64", - "crypto_sources_apple_arm", - "crypto_sources_apple_x86", - "crypto_sources_apple_x86_64", - "crypto_sources_linux_aarch64", - "crypto_sources_linux_arm", - "crypto_sources_linux_x86", - "crypto_sources_linux_x86_64", + "crypto_sources_asm", "fips_fragments", "ssl_headers", "ssl_internal_headers", @@ -38,33 +31,47 @@ licenses(["notice"]) exports_files(["LICENSE"]) -[ - ( - config_setting( - name = os + "_" + arch, - constraint_values = [ - "@platforms//os:" + os, - "@platforms//cpu:" + arch, - ], - ), - ) - for os in [ - "linux", - "android", - "macos", - "ios", - "tvos", - "watchos", - ] - for arch in [ - "arm64", - "armv7", - "x86_64", - "x86_32", - ] -] +# By default, the C files will expect assembly files, if any, to be linked in +# with the build. This default can be flipped with -DOPENSSL_NO_ASM. If building +# in a configuration where we have no assembly optimizations, -DOPENSSL_NO_ASM +# has no effect, and either value is fine. +# +# Like C files, assembly files are wrapped in #ifdef (or NASM equivalent), so it +# is safe to include a file for the wrong platform in the build. It will just +# output an empty object file. However, we need some platform selectors to +# distinguish between gas or NASM syntax. +# +# For all non-Windows platforms, we use gas assembly syntax and can assume any +# GCC-compatible toolchain includes a gas-compatible assembler. +# +# For Windows, we use NASM on x86 and x86_64 and gas, specifically +# clang-assembler, on aarch64. We have not yet added NASM support to this build, +# and would need to detect MSVC vs clang-cl for aarch64 so, for now, we just +# disable assembly on Windows across the board. +# +# These two selects for asm_sources and asm_copts must be kept in sync. If we +# specify assembly, we don't want OPENSSL_NO_ASM. If we don't specify assembly, +# we want OPENSSL_NO_ASM, in case the C files expect them in some format (e.g. +# NASM) this build file doesn't yet support. +# +# TODO(https://crbug.com/boringssl/531): Enable assembly for Windows. +asm_sources = select({ + "@platforms//os:windows": [], + "//conditions:default": crypto_sources_asm, +}) +asm_copts = select({ + "@platforms//os:windows": ["-DOPENSSL_NO_ASM"], + "//conditions:default": [], +}) -posix_copts = [ +# Configure C, C++, and common flags for GCC-compatible toolchains. +# +# TODO(davidben): Can we remove some of these? In Bazel, are warnings the +# toolchain or project's responsibility? -Wa,--noexecstack should be unnecessary +# now, though https://crbug.com/boringssl/292 tracks testing this in CI. +# -fno-common did not become default until +# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85678. +gcc_copts = [ # Assembler option --noexecstack adds .note.GNU-stack to each object to # ensure that binaries can be built with non-executable stack. "-Wa,--noexecstack", @@ -79,119 +86,51 @@ posix_copts = [ "-Wshadow", "-fno-common", ] - -glibc_copts = posix_copts + [ - # This is needed on glibc systems (at least) to get rwlock in pthread, but - # it should not be set on Apple platforms or FreeBSD, where it instead - # disables APIs we use. - # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 - "-D_XOPEN_SOURCE=700", -] - -boringssl_copts = select({ - "@platforms//os:linux": glibc_copts, - "@platforms//os:android": posix_copts, - "@platforms//os:macos": posix_copts, - "@platforms//os:ios": posix_copts, - "@platforms//os:tvos": posix_copts, - "@platforms//os:watchos": posix_copts, - "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], - "//conditions:default": [], -}) - -# These selects must be kept in sync. -crypto_sources_asm = select({ - ":linux_armv7": crypto_sources_linux_arm, - ":linux_arm64": crypto_sources_linux_aarch64, - ":linux_x86_32": crypto_sources_linux_x86, - ":linux_x86_64": crypto_sources_linux_x86_64, - ":android_armv7": crypto_sources_linux_arm, - ":android_arm64": crypto_sources_linux_aarch64, - ":android_x86_32": crypto_sources_linux_x86, - ":android_x86_64": crypto_sources_linux_x86_64, - ":macos_armv7": crypto_sources_apple_arm, - ":macos_arm64": crypto_sources_apple_aarch64, - ":macos_x86_32": crypto_sources_apple_x86, - ":macos_x86_64": crypto_sources_apple_x86_64, - ":ios_armv7": crypto_sources_apple_arm, - ":ios_arm64": crypto_sources_apple_aarch64, - ":ios_x86_32": crypto_sources_apple_x86, - ":ios_x86_64": crypto_sources_apple_x86_64, - ":tvos_armv7": crypto_sources_apple_arm, - ":tvos_arm64": crypto_sources_apple_aarch64, - ":tvos_x86_32": crypto_sources_apple_x86, - ":tvos_x86_64": crypto_sources_apple_x86_64, - ":watchos_armv7": crypto_sources_apple_arm, - ":watchos_arm64": crypto_sources_apple_aarch64, - ":watchos_x86_32": crypto_sources_apple_x86, - ":watchos_x86_64": crypto_sources_apple_x86_64, - "//conditions:default": [], -}) -boringssl_copts += select({ - ":linux_armv7": [], - ":linux_arm64": [], - ":linux_x86_32": [], - ":linux_x86_64": [], - ":android_armv7": [], - ":android_arm64": [], - ":android_x86_32": [], - ":android_x86_64": [], - ":macos_armv7": [], - ":macos_arm64": [], - ":macos_x86_32": [], - ":macos_x86_64": [], - ":ios_armv7": [], - ":ios_arm64": [], - ":ios_x86_32": [], - ":ios_x86_64": [], - ":tvos_armv7": [], - ":tvos_arm64": [], - ":tvos_x86_32": [], - ":tvos_x86_64": [], - ":watchos_armv7": [], - ":watchos_arm64": [], - ":watchos_x86_32": [], - ":watchos_x86_64": [], - "//conditions:default": ["-DOPENSSL_NO_ASM"], -}) - -# For C targets only (not C++), compile with C11 support. -posix_copts_c11 = [ +gcc_copts_c11 = [ "-std=c11", "-Wmissing-prototypes", "-Wold-style-definition", "-Wstrict-prototypes", ] - -boringssl_copts_c11 = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_c11, - "@platforms//os:android": posix_copts_c11, - "@platforms//os:macos": posix_copts_c11, - "@platforms//os:ios": posix_copts_c11, - "@platforms//os:tvos": posix_copts_c11, - "@platforms//os:watchos": posix_copts_c11, - "//conditions:default": [], -}) - -# For C++ targets only (not C), compile with C++14 support. -posix_copts_cxx = [ +gcc_copts_cxx = [ "-std=c++14", "-Wmissing-declarations", ] -boringssl_copts_cxx = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_cxx, - "@platforms//os:android": posix_copts_cxx, - "@platforms//os:macos": posix_copts_cxx, - "@platforms//os:ios": posix_copts_cxx, - "@platforms//os:tvos": posix_copts_cxx, - "@platforms//os:watchos": posix_copts_cxx, +boringssl_copts = select({ + # We assume that non-Windows builds use a GCC-compatible toolchain and that + # Windows builds do not. + # + # TODO(davidben): Should these be querying something in @bazel_tools? + # Unfortunately, @bazel_tools is undocumented. See + # https://github.com/bazelbuild/bazel/issues/14914 + "@platforms//os:windows": [], + "//conditions:default": gcc_copts, +}) + select({ + # This is needed on glibc systems to get rwlock in pthreads, but it should + # not be set on Apple platforms or FreeBSD, where it instead disables APIs + # we use. + # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 + "@platforms//os:linux": ["-D_XOPEN_SOURCE=700"], + # Without WIN32_LEAN_AND_MEAN, pulls in wincrypt.h, which + # conflicts with our . + "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], "//conditions:default": [], +}) + asm_copts + +boringssl_copts_c11 = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_c11, +}) + +boringssl_copts_cxx = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_cxx, }) cc_library( name = "crypto", - srcs = crypto_sources + crypto_internal_headers + crypto_sources_asm, + srcs = crypto_sources + crypto_internal_headers + asm_sources, hdrs = crypto_headers + fips_fragments, copts = boringssl_copts_c11, includes = ["src/include"], diff --git a/src/util/all_tests.go b/src/util/all_tests.go index 4f484f353..c0dceba55 100644 --- a/src/util/all_tests.go +++ b/src/util/all_tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2015, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2015, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/util/ar/ar.go b/src/util/ar/ar.go index 756caf53d..fdc2dd2b1 100644 --- a/src/util/ar/ar.go +++ b/src/util/ar/ar.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // ar.go contains functions for parsing .a archive files. diff --git a/src/util/ar/ar_test.go b/src/util/ar/ar_test.go index fac0e266a..31baaf162 100644 --- a/src/util/ar/ar_test.go +++ b/src/util/ar/ar_test.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package ar diff --git a/src/util/check_filenames.go b/src/util/check_filenames.go index 886c3f609..384c19f51 100644 --- a/src/util/check_filenames.go +++ b/src/util/check_filenames.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_filenames.go checks that filenames are unique. Some of our consumers do // not support multiple files with the same name in the same build target, even // if they are in different directories. diff --git a/src/util/check_imported_libraries.go b/src/util/check_imported_libraries.go index 187e51441..f3803f1c1 100644 --- a/src/util/check_imported_libraries.go +++ b/src/util/check_imported_libraries.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_imported_libraries.go checks that each of its arguments only imports // allowed libraries. This is used to avoid accidental dependencies on // libstdc++.so. diff --git a/src/util/check_stack.go b/src/util/check_stack.go index b718ea4ac..ad763e652 100644 --- a/src/util/check_stack.go +++ b/src/util/check_stack.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_stack.go checks that each of its arguments has a non-executable stack. // See https://www.airs.com/blog/archives/518 for details. package main diff --git a/src/util/compare_benchmarks.go b/src/util/compare_benchmarks.go index 0c79d638e..05e1b5db0 100644 --- a/src/util/compare_benchmarks.go +++ b/src/util/compare_benchmarks.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020 Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020 Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // compare_benchmarks takes the JSON-formatted output of bssl speed and // compares it against a baseline output. diff --git a/src/util/convert_comments.go b/src/util/convert_comments.go index 917f29c86..df9e3d3ae 100644 --- a/src/util/convert_comments.go +++ b/src/util/convert_comments.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/src/util/convert_wycheproof.go b/src/util/convert_wycheproof.go index f81771e4b..809da6f51 100644 --- a/src/util/convert_wycheproof.go +++ b/src/util/convert_wycheproof.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // convert_wycheproof.go converts Wycheproof test vectors into a format more // easily consumed by BoringSSL. diff --git a/src/util/diff_asm.go b/src/util/diff_asm.go index 710a42cb6..5ac1c04bb 100644 --- a/src/util/diff_asm.go +++ b/src/util/diff_asm.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2016, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2016, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/src/util/doc.go b/src/util/doc.go index 45caa15ea..4fb73ca0d 100644 --- a/src/util/doc.go +++ b/src/util/doc.go @@ -1,10 +1,11 @@ +//go:build ignore + // doc generates HTML files from the comments in header files. // // doc expects to be given the path to a JSON file via the --config option. // From that JSON (which is defined by the Config struct) it reads a list of // header file locations and generates HTML files for each in the current // directory. - package main import ( @@ -411,7 +412,7 @@ func (config *Config) parseHeader(path string) (*HeaderFile, error) { lines = lines[1:] lineNo++ break - } + } if line == cppGuard { return nil, fmt.Errorf("hit ending C++ guard while in section on line %d (possibly missing two empty lines ahead of guard?)", lineNo) } diff --git a/src/util/embed_test_data.go b/src/util/embed_test_data.go index 266f2969a..ae7135fae 100644 --- a/src/util/embed_test_data.go +++ b/src/util/embed_test_data.go @@ -10,7 +10,9 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // embed_test_data generates a C++ source file which exports a function, // GetTestData, which looks up the specified data files. diff --git a/src/util/fetch_ech_config_list.go b/src/util/fetch_ech_config_list.go index 8f09e66b1..732d0d3b8 100644 --- a/src/util/fetch_ech_config_list.go +++ b/src/util/fetch_ech_config_list.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/src/util/fipstools/acvp/acvptool/test/check_expected.go b/src/util/fipstools/acvp/acvptool/test/check_expected.go index ccc803850..588b8038b 100644 --- a/src/util/fipstools/acvp/acvptool/test/check_expected.go +++ b/src/util/fipstools/acvp/acvptool/test/check_expected.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/src/util/fipstools/acvp/acvptool/test/trim_vectors.go b/src/util/fipstools/acvp/acvptool/test/trim_vectors.go index 53e970e02..703f75fd2 100644 --- a/src/util/fipstools/acvp/acvptool/test/trim_vectors.go +++ b/src/util/fipstools/acvp/acvptool/test/trim_vectors.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // trimvectors takes an ACVP vector set file and discards all but a single test // from each test group. This hope is that this achieves good coverage without // having to check in megabytes worth of JSON files. diff --git a/src/util/fipstools/break-hash.go b/src/util/fipstools/break-hash.go index 9893716b9..a4ab8083d 100644 --- a/src/util/fipstools/break-hash.go +++ b/src/util/fipstools/break-hash.go @@ -10,7 +10,9 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // break-hash parses an ELF binary containing the FIPS module and corrupts the // first byte of the module. This should cause the integrity check to fail. diff --git a/src/util/fipstools/break-kat.go b/src/util/fipstools/break-kat.go index 6eace5b46..ebf5dd703 100644 --- a/src/util/fipstools/break-kat.go +++ b/src/util/fipstools/break-kat.go @@ -1,3 +1,5 @@ +//go:build + // break-kat corrupts a known-answer-test input in a binary and writes the // corrupted binary to stdout. This is used to demonstrate that the KATs in the // binary notice the error. diff --git a/src/util/fipstools/delocate/delocate.go b/src/util/fipstools/delocate/delocate.go index c9daff931..c28be558c 100644 --- a/src/util/fipstools/delocate/delocate.go +++ b/src/util/fipstools/delocate/delocate.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // delocate performs several transformations of textual assembly code. See // crypto/fipsmodule/FIPS.md for an overview. diff --git a/src/util/fipstools/delocate/delocate_test.go b/src/util/fipstools/delocate/delocate_test.go index e3dff546e..e341a3815 100644 --- a/src/util/fipstools/delocate/delocate_test.go +++ b/src/util/fipstools/delocate/delocate_test.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package main diff --git a/src/util/fipstools/fipscommon/const.go b/src/util/fipstools/fipscommon/const.go index f4c0b75d4..c709961e1 100644 --- a/src/util/fipstools/fipscommon/const.go +++ b/src/util/fipstools/fipscommon/const.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package fipscommon diff --git a/src/util/fipstools/inject_hash/inject_hash.go b/src/util/fipstools/inject_hash/inject_hash.go index 3680cfdf8..9c3083663 100644 --- a/src/util/fipstools/inject_hash/inject_hash.go +++ b/src/util/fipstools/inject_hash/inject_hash.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // inject_hash parses an archive containing a file object file. It finds a FIPS // module inside that object, calculates its hash and replaces the default hash diff --git a/src/util/generate_build_files.py b/src/util/generate_build_files.py index c319a5529..0cabe9c2b 100644 --- a/src/util/generate_build_files.py +++ b/src/util/generate_build_files.py @@ -255,6 +255,23 @@ class Bazel(object): self.PrintVariableSection( out, 'crypto_sources_%s_%s' % (osname, arch), asm_files) + # Generate combined source lists for gas and nasm. Consumers have a choice + # of using the per-platform ones or the combined ones. In the combined + # mode, Windows x86 and Windows x86_64 must still be special-cased, but + # otherwise all assembly files can be linked together. + out.write('\n') + out.write('crypto_sources_asm = []\n') + for (osname, arch, _, _, asm_ext) in OS_ARCH_COMBOS: + if asm_ext == 'S': + out.write('crypto_sources_asm.extend(crypto_sources_%s_%s)\n' % + (osname, arch)) + out.write('\n') + out.write('crypto_sources_nasm = []\n') + for (osname, arch, _, _, asm_ext) in OS_ARCH_COMBOS: + if asm_ext == 'asm': + out.write('crypto_sources_nasm.extend(crypto_sources_%s_%s)\n' % + (osname, arch)) + with open('BUILD.generated_tests.bzl', 'w+') as out: out.write(self.header) @@ -401,21 +418,21 @@ class CMake(object): self.header = LicenseHeader("#") + R''' # This file is created by generate_build_files.py. Do not edit manually. -cmake_minimum_required(VERSION 3.5) +cmake_minimum_required(VERSION 3.10) project(BoringSSL LANGUAGES C CXX) -if(CMAKE_CXX_COMPILER_ID MATCHES "Clang") - set(CLANG 1) +set(CMAKE_CXX_STANDARD 14) +set(CMAKE_CXX_STANDARD_REQUIRED ON) +set(CMAKE_C_STANDARD 11) +set(CMAKE_C_STANDARD_REQUIRED ON) +if(CMAKE_COMPILER_IS_GNUCXX OR CMAKE_CXX_COMPILER_ID MATCHES "Clang") + set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") + set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common") endif() -if(CMAKE_COMPILER_IS_GNUCXX OR CLANG) - set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -std=c++14 -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common -std=c11") -endif() - -# pthread_rwlock_t requires a feature flag. -if(NOT WIN32) +# pthread_rwlock_t requires a feature flag on glibc. +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -D_XOPEN_SOURCE=700") endif() @@ -425,73 +442,19 @@ if(WIN32) add_definitions(-DNOMINMAX) # Allow use of fopen. add_definitions(-D_CRT_SECURE_NO_WARNINGS) - # VS 2017 and higher supports STL-only warning suppressions. - # A bug in CMake < 3.13.0 may cause the space in this value to - # cause issues when building with NASM. In that case, update CMake. - add_definitions("-D_STL_EXTRA_DISABLED_WARNINGS=4774 4987") endif() add_definitions(-DBORINGSSL_IMPLEMENTATION) -# CMake's iOS support uses Apple's multiple-architecture toolchain. It takes an -# architecture list from CMAKE_OSX_ARCHITECTURES, leaves CMAKE_SYSTEM_PROCESSOR -# alone, and expects all architecture-specific logic to be conditioned within -# the source files rather than the build. This does not work for our assembly -# files, so we fix CMAKE_SYSTEM_PROCESSOR and only support single-architecture -# builds. -if(NOT OPENSSL_NO_ASM AND CMAKE_OSX_ARCHITECTURES) - list(LENGTH CMAKE_OSX_ARCHITECTURES NUM_ARCHES) - if(NOT NUM_ARCHES EQUAL 1) - message(FATAL_ERROR "Universal binaries not supported.") - endif() - list(GET CMAKE_OSX_ARCHITECTURES 0 CMAKE_SYSTEM_PROCESSOR) -endif() - -if(OPENSSL_NO_ASM) - add_definitions(-DOPENSSL_NO_ASM) - set(ARCH "generic") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86_64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "amd64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "AMD64") - # cmake reports AMD64 on Windows, but we might be building for 32-bit. - if(CMAKE_SIZEOF_VOID_P EQUAL 8) - set(ARCH "x86_64") - else() - set(ARCH "x86") - endif() -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i386") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i686") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "aarch64") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64") - set(ARCH "aarch64") -# Apple A12 Bionic chipset which is added in iPhone XS/XS Max/XR uses arm64e architecture. -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64e") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "^arm*") - set(ARCH "arm") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "mips") - # Just to avoid the “unknown processor” error. - set(ARCH "generic") -else() - message(FATAL_ERROR "Unknown processor:" ${CMAKE_SYSTEM_PROCESSOR}) -endif() - if(NOT OPENSSL_NO_ASM) - if(UNIX) + # On x86 and x86_64 Windows, we use the NASM output. + if(WIN32 AND CMAKE_SYSTEM_PROCESSOR MATCHES "AMD64|x86_64|amd64|x86|i[3-6]86") + enable_language(ASM_NASM) + set(OPENSSL_NASM TRUE) + set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") + else() enable_language(ASM) - - # Clang's integerated assembler does not support debug symbols. - if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") - set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") - endif() - + set(OPENSSL_ASM TRUE) # CMake does not add -isysroot and -arch flags to assembly. if(APPLE) if(CMAKE_OSX_SYSROOT) @@ -501,9 +464,13 @@ if(NOT OPENSSL_NO_ASM) set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -arch ${arch}") endforeach() endif() - else() - set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") - enable_language(ASM_NASM) + if(NOT WIN32) + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,--noexecstack") + endif() + # Clang's integerated assembler does not support debug symbols. + if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") + endif() endif() endif() @@ -537,7 +504,7 @@ include_directories(src/include) out.write(')\n\n') out.write('target_link_libraries(%s %s)\n\n' % (name, ' '.join(libs))) - def PrintSection(self, out, name, files): + def PrintVariable(self, out, name, files): out.write('set(\n') out.write(' %s\n\n' % name) for f in sorted(files): @@ -548,29 +515,35 @@ include_directories(src/include) with open('CMakeLists.txt', 'w+') as cmake: cmake.write(self.header) + asm_sources = [] + nasm_sources = [] for ((osname, arch), asm_files) in asm_outputs: - self.PrintSection(cmake, 'CRYPTO_%s_%s_SOURCES' % (osname, arch), - asm_files) + if (osname, arch) in (('win', 'x86'), ('win', 'x86_64')): + nasm_sources.extend(asm_files) + else: + asm_sources.extend(asm_files) + self.PrintVariable(cmake, 'CRYPTO_SOURCES_ASM', sorted(asm_sources)) + self.PrintVariable(cmake, 'CRYPTO_SOURCES_NASM', sorted(nasm_sources)) cmake.write( -R'''if(APPLE) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_apple_${ARCH}_SOURCES}) -elseif(UNIX) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_linux_${ARCH}_SOURCES}) -elseif(WIN32) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_win_${ARCH}_SOURCES}) +R'''if(OPENSSL_ASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_ASM}) +endif() +if(OPENSSL_NASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_NASM}) endif() ''') self.PrintLibrary(cmake, 'crypto', - files['crypto'] + ['${CRYPTO_ARCH_SOURCES}']) + files['crypto'] + ['${CRYPTO_SOURCES_ASM_USED}']) self.PrintLibrary(cmake, 'ssl', files['ssl']) self.PrintExe(cmake, 'bssl', files['tool'], ['ssl', 'crypto']) cmake.write( -R'''if(NOT WIN32 AND NOT ANDROID) - target_link_libraries(crypto pthread) +R'''if(NOT ANDROID) + find_package(Threads REQUIRED) + target_link_libraries(crypto Threads::Threads) endif() if(WIN32) diff --git a/src/util/godeps.go b/src/util/godeps.go index 960faa46b..56be55944 100644 --- a/src/util/godeps.go +++ b/src/util/godeps.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // godeps prints out dependencies of a package in either CMake or Make depfile // format, for incremental rebuilds. // diff --git a/src/util/make_errors.go b/src/util/make_errors.go index 4e2718b8d..018845258 100644 --- a/src/util/make_errors.go +++ b/src/util/make_errors.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/src/util/make_prefix_headers.go b/src/util/make_prefix_headers.go index b536f14ce..8787654b5 100644 --- a/src/util/make_prefix_headers.go +++ b/src/util/make_prefix_headers.go @@ -12,12 +12,15 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // This program takes a file containing newline-separated symbols, and generates // boringssl_prefix_symbols.h, boringssl_prefix_symbols_asm.h, and // boringssl_prefix_symbols_nasm.inc. These header files can be used to build // BoringSSL with a prefix for all symbols in order to avoid symbol name // conflicts when linking a project with multiple copies of BoringSSL; see // BUILDING.md for more details. +package main // TODO(joshlf): For platforms which support it, use '#pragma redefine_extname' // instead of a custom macro. This avoids the need for a custom macro, but also @@ -26,8 +29,6 @@ // IllumOS' fork of OpenSSL: // https://github.com/joyent/illumos-extra/blob/master/openssl1x/sunw_prefix.h -package main - import ( "bufio" "flag" diff --git a/src/util/read_symbols.go b/src/util/read_symbols.go index 96c148ab5..69d000282 100644 --- a/src/util/read_symbols.go +++ b/src/util/read_symbols.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // read_symbols scans one or more .a files and, for each object contained in // the .a files, reads the list of symbols in that object file. package main diff --git a/src/util/run_android_tests.go b/src/util/run_android_tests.go index 51b20172a..59ddbe75a 100644 --- a/src/util/run_android_tests.go +++ b/src/util/run_android_tests.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import (