From 507ac830036d7531489490831814cf03e0d7c4d6 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Tue, 31 Jan 2023 12:14:20 -0500 Subject: [PATCH 1/7] Fix error-handling in X509V3_EXT_add_nconf_sk and X509v3_add_ext. See also upstream's abcf241114c4dc33af95288ae7f7d10916c67db0. Fixed: oss-fuzz:55555, oss-fuzz:55556, oss-fuzz:55560 Change-Id: I3b015822806ced39a498017bd2329323ed8dfbf0 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56685 Auto-Submit: David Benjamin Reviewed-by: Bob Beck Commit-Queue: David Benjamin --- crypto/x509/x509_test.cc | 11 +++++++++++ crypto/x509/x509_v3.c | 6 +++++- crypto/x509v3/v3_conf.c | 9 ++++----- 3 files changed, 20 insertions(+), 6 deletions(-) diff --git a/crypto/x509/x509_test.cc b/crypto/x509/x509_test.cc index fea26e7bc..aebc76a92 100644 --- a/crypto/x509/x509_test.cc +++ b/crypto/x509/x509_test.cc @@ -6205,3 +6205,14 @@ key = FORMAT:HEX,OCTWRAP,OCT:9d61b19deffd5a60ba844af492ec2cc44449c5697b326919703 } } } + +TEST(X509, AddUnserializableExtension) { + bssl::UniquePtr key = PrivateKeyFromPEM(kP256Key); + ASSERT_TRUE(key); + bssl::UniquePtr x509 = + MakeTestCert("Issuer", "Subject", key.get(), /*is_ca=*/true); + ASSERT_TRUE(x509); + bssl::UniquePtr ext(X509_EXTENSION_new()); + ASSERT_TRUE(X509_EXTENSION_set_object(ext.get(), OBJ_nid2obj(NID_undef))); + EXPECT_FALSE(X509_add_ext(x509.get(), ext.get(), /*loc=*/-1)); +} diff --git a/crypto/x509/x509_v3.c b/crypto/x509/x509_v3.c index 9153dce19..dd8435243 100644 --- a/crypto/x509/x509_v3.c +++ b/crypto/x509/x509_v3.c @@ -148,6 +148,7 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, X509_EXTENSION *new_ex = NULL; int n; STACK_OF(X509_EXTENSION) *sk = NULL; + int free_sk = 0; if (x == NULL) { OPENSSL_PUT_ERROR(X509, ERR_R_PASSED_NULL_PARAMETER); @@ -158,6 +159,7 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, if ((sk = sk_X509_EXTENSION_new_null()) == NULL) { goto err; } + free_sk = 1; } else { sk = *x; } @@ -183,7 +185,9 @@ err: OPENSSL_PUT_ERROR(X509, ERR_R_MALLOC_FAILURE); err2: X509_EXTENSION_free(new_ex); - sk_X509_EXTENSION_free(sk); + if (free_sk) { + sk_X509_EXTENSION_free(sk); + } return NULL; } diff --git a/crypto/x509v3/v3_conf.c b/crypto/x509v3/v3_conf.c index 480bb3b79..a4f172d3f 100644 --- a/crypto/x509v3/v3_conf.c +++ b/crypto/x509v3/v3_conf.c @@ -357,13 +357,12 @@ int X509V3_EXT_add_nconf_sk(const CONF *conf, const X509V3_CTX *ctx, for (size_t i = 0; i < sk_CONF_VALUE_num(nval); i++) { const CONF_VALUE *val = sk_CONF_VALUE_value(nval, i); X509_EXTENSION *ext = X509V3_EXT_nconf(conf, ctx, val->name, val->value); - if (ext == NULL) { + int ok = ext != NULL && // + (sk == NULL || X509v3_add_ext(sk, ext, -1) != NULL); + X509_EXTENSION_free(ext); + if (!ok) { return 0; } - if (sk) { - X509v3_add_ext(sk, ext, -1); - } - X509_EXTENSION_free(ext); } return 1; } From 8a69c0d4f8f412432f80dd36ee5987fb1675bfbc Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Tue, 31 Jan 2023 13:14:54 -0500 Subject: [PATCH 2/7] Check for null value in set_dist_point_name. CONF_VALUEs are a mess. They show up in three forms: - When parsed from a config file (in a CONF), I believe name and value are never NULL. - Internally, CONF represents sections as funny CONF_VALUEs where name is NULL, and value is a STACK_OF(CONF_VALUE) of the wrong type. This is ridiculous and should be a separate type, though I don't believe it ever leaks outside the public API. - When created by X509V3_parse_list, it is possible for them to be value-less, with a NULL value. v2i functions can see the last case, and set_dist_point_name comes from a v2i function. Add a missing NULL check. This only impacts the unsafe, stringly-typed extensions-building APIs that no one should be using anyway. Also fix the name of the test I added in the previous CL. I didn't quite follow the existing convention. Fixed: oss-fuzz:55558 Change-Id: I1a2403312f3ce59007d23fe7e226f2e602653019 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56705 Commit-Queue: Bob Beck Reviewed-by: Bob Beck Commit-Queue: David Benjamin Auto-Submit: David Benjamin --- crypto/x509/x509_test.cc | 6 +++++- crypto/x509v3/v3_crld.c | 7 +++++++ 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/crypto/x509/x509_test.cc b/crypto/x509/x509_test.cc index aebc76a92..63ce092a3 100644 --- a/crypto/x509/x509_test.cc +++ b/crypto/x509/x509_test.cc @@ -5716,6 +5716,10 @@ TEST(X509Test, ExtensionFromConf) { // If no config is provided, this should fail. {"basicConstraints", "critical,@section", nullptr, {}}, + // issuingDistributionPoint takes a list of name:value pairs. Omitting the + // value is not allowed. + {"issuingDistributionPoint", "fullname", nullptr, {}}, + // The "DER:" prefix just specifies an arbitrary byte string. Colons // separators are ignored. {kTestOID, "DER:0001020304", nullptr, {0x30, 0x15, 0x06, 0x0c, 0x2a, 0x86, @@ -6206,7 +6210,7 @@ key = FORMAT:HEX,OCTWRAP,OCT:9d61b19deffd5a60ba844af492ec2cc44449c5697b326919703 } } -TEST(X509, AddUnserializableExtension) { +TEST(X509Test, AddUnserializableExtension) { bssl::UniquePtr key = PrivateKeyFromPEM(kP256Key); ASSERT_TRUE(key); bssl::UniquePtr x509 = diff --git a/crypto/x509v3/v3_crld.c b/crypto/x509v3/v3_crld.c index 4b5a36df8..0b6899a6f 100644 --- a/crypto/x509v3/v3_crld.c +++ b/crypto/x509v3/v3_crld.c @@ -129,6 +129,13 @@ static STACK_OF(GENERAL_NAME) *gnames_from_sectname(const X509V3_CTX *ctx, static int set_dist_point_name(DIST_POINT_NAME **pdp, const X509V3_CTX *ctx, const CONF_VALUE *cnf) { + // If |cnf| comes from |X509V3_parse_list|, which is possible for a v2i + // function, |cnf->value| may be NULL. + if (cnf->value == NULL) { + OPENSSL_PUT_ERROR(X509V3, X509V3_R_MISSING_VALUE); + return 0; + } + STACK_OF(GENERAL_NAME) *fnm = NULL; STACK_OF(X509_NAME_ENTRY) *rnm = NULL; if (!strncmp(cnf->name, "fullname", 9)) { From 741c153370f58dbf73c6680c8f37de656bc2cb3c Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Wed, 25 Jan 2023 17:37:16 -0500 Subject: [PATCH 3/7] Align the generated CMake build with the main one. Having two of these is tedious and I hope, eventually, we can align them. But for now, sync them manually: - Bump the minimum CMake versions to match - Align the C/C++ version directives - Simplify architecture detection - Trim some Windows defines that date to our overly aggressive warnings - Use the Threads package - Only use _XOPEN_SOURCE on Linux because it's a glibc-specific problem. I've tested this manually, but we don't particularly test this build right now (I forget if anyone is even using it), so this is mostly relying on finding out from others if it breaks something. In the long term, we should merge the two CMake builds. Bug: 542 Change-Id: Icccc466464306967275d29a6982c0e9859fc972c Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56445 Commit-Queue: Adam Langley Reviewed-by: Adam Langley Auto-Submit: David Benjamin --- util/generate_build_files.py | 128 ++++++++++++----------------------- 1 file changed, 42 insertions(+), 86 deletions(-) diff --git a/util/generate_build_files.py b/util/generate_build_files.py index c319a5529..383de02d2 100644 --- a/util/generate_build_files.py +++ b/util/generate_build_files.py @@ -401,21 +401,21 @@ class CMake(object): self.header = LicenseHeader("#") + R''' # This file is created by generate_build_files.py. Do not edit manually. -cmake_minimum_required(VERSION 3.5) +cmake_minimum_required(VERSION 3.10) project(BoringSSL LANGUAGES C CXX) -if(CMAKE_CXX_COMPILER_ID MATCHES "Clang") - set(CLANG 1) +set(CMAKE_CXX_STANDARD 14) +set(CMAKE_CXX_STANDARD_REQUIRED ON) +set(CMAKE_C_STANDARD 11) +set(CMAKE_C_STANDARD_REQUIRED ON) +if(CMAKE_COMPILER_IS_GNUCXX OR CMAKE_CXX_COMPILER_ID MATCHES "Clang") + set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") + set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common") endif() -if(CMAKE_COMPILER_IS_GNUCXX OR CLANG) - set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -std=c++14 -fvisibility=hidden -fno-common -fno-exceptions -fno-rtti") - set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fvisibility=hidden -fno-common -std=c11") -endif() - -# pthread_rwlock_t requires a feature flag. -if(NOT WIN32) +# pthread_rwlock_t requires a feature flag on glibc. +if(CMAKE_SYSTEM_NAME STREQUAL "Linux") set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -D_XOPEN_SOURCE=700") endif() @@ -425,73 +425,19 @@ if(WIN32) add_definitions(-DNOMINMAX) # Allow use of fopen. add_definitions(-D_CRT_SECURE_NO_WARNINGS) - # VS 2017 and higher supports STL-only warning suppressions. - # A bug in CMake < 3.13.0 may cause the space in this value to - # cause issues when building with NASM. In that case, update CMake. - add_definitions("-D_STL_EXTRA_DISABLED_WARNINGS=4774 4987") endif() add_definitions(-DBORINGSSL_IMPLEMENTATION) -# CMake's iOS support uses Apple's multiple-architecture toolchain. It takes an -# architecture list from CMAKE_OSX_ARCHITECTURES, leaves CMAKE_SYSTEM_PROCESSOR -# alone, and expects all architecture-specific logic to be conditioned within -# the source files rather than the build. This does not work for our assembly -# files, so we fix CMAKE_SYSTEM_PROCESSOR and only support single-architecture -# builds. -if(NOT OPENSSL_NO_ASM AND CMAKE_OSX_ARCHITECTURES) - list(LENGTH CMAKE_OSX_ARCHITECTURES NUM_ARCHES) - if(NOT NUM_ARCHES EQUAL 1) - message(FATAL_ERROR "Universal binaries not supported.") - endif() - list(GET CMAKE_OSX_ARCHITECTURES 0 CMAKE_SYSTEM_PROCESSOR) -endif() - -if(OPENSSL_NO_ASM) - add_definitions(-DOPENSSL_NO_ASM) - set(ARCH "generic") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86_64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "amd64") - set(ARCH "x86_64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "AMD64") - # cmake reports AMD64 on Windows, but we might be building for 32-bit. - if(CMAKE_SIZEOF_VOID_P EQUAL 8) - set(ARCH "x86_64") - else() - set(ARCH "x86") - endif() -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "x86") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i386") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "i686") - set(ARCH "x86") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "aarch64") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64") - set(ARCH "aarch64") -# Apple A12 Bionic chipset which is added in iPhone XS/XS Max/XR uses arm64e architecture. -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "arm64e") - set(ARCH "aarch64") -elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "^arm*") - set(ARCH "arm") -elseif(CMAKE_SYSTEM_PROCESSOR STREQUAL "mips") - # Just to avoid the “unknown processor” error. - set(ARCH "generic") -else() - message(FATAL_ERROR "Unknown processor:" ${CMAKE_SYSTEM_PROCESSOR}) -endif() - if(NOT OPENSSL_NO_ASM) - if(UNIX) + # On x86 and x86_64 Windows, we use the NASM output. + if(WIN32 AND CMAKE_SYSTEM_PROCESSOR MATCHES "AMD64|x86_64|amd64|x86|i[3-6]86") + enable_language(ASM_NASM) + set(OPENSSL_NASM TRUE) + set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") + else() enable_language(ASM) - - # Clang's integerated assembler does not support debug symbols. - if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") - set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") - endif() - + set(OPENSSL_ASM TRUE) # CMake does not add -isysroot and -arch flags to assembly. if(APPLE) if(CMAKE_OSX_SYSROOT) @@ -501,9 +447,13 @@ if(NOT OPENSSL_NO_ASM) set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -arch ${arch}") endforeach() endif() - else() - set(CMAKE_ASM_NASM_FLAGS "${CMAKE_ASM_NASM_FLAGS} -gcv8") - enable_language(ASM_NASM) + if(NOT WIN32) + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,--noexecstack") + endif() + # Clang's integerated assembler does not support debug symbols. + if(NOT CMAKE_ASM_COMPILER_ID MATCHES "Clang") + set(CMAKE_ASM_FLAGS "${CMAKE_ASM_FLAGS} -Wa,-g") + endif() endif() endif() @@ -537,7 +487,7 @@ include_directories(src/include) out.write(')\n\n') out.write('target_link_libraries(%s %s)\n\n' % (name, ' '.join(libs))) - def PrintSection(self, out, name, files): + def PrintVariable(self, out, name, files): out.write('set(\n') out.write(' %s\n\n' % name) for f in sorted(files): @@ -548,29 +498,35 @@ include_directories(src/include) with open('CMakeLists.txt', 'w+') as cmake: cmake.write(self.header) + asm_sources = [] + nasm_sources = [] for ((osname, arch), asm_files) in asm_outputs: - self.PrintSection(cmake, 'CRYPTO_%s_%s_SOURCES' % (osname, arch), - asm_files) + if (osname, arch) in (('win', 'x86'), ('win', 'x86_64')): + nasm_sources.extend(asm_files) + else: + asm_sources.extend(asm_files) + self.PrintVariable(cmake, 'CRYPTO_SOURCES_ASM', sorted(asm_sources)) + self.PrintVariable(cmake, 'CRYPTO_SOURCES_NASM', sorted(nasm_sources)) cmake.write( -R'''if(APPLE) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_apple_${ARCH}_SOURCES}) -elseif(UNIX) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_linux_${ARCH}_SOURCES}) -elseif(WIN32) - set(CRYPTO_ARCH_SOURCES ${CRYPTO_win_${ARCH}_SOURCES}) +R'''if(OPENSSL_ASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_ASM}) +endif() +if(OPENSSL_NASM) + list(APPEND CRYPTO_SOURCES_ASM_USED ${CRYPTO_SOURCES_NASM}) endif() ''') self.PrintLibrary(cmake, 'crypto', - files['crypto'] + ['${CRYPTO_ARCH_SOURCES}']) + files['crypto'] + ['${CRYPTO_SOURCES_ASM_USED}']) self.PrintLibrary(cmake, 'ssl', files['ssl']) self.PrintExe(cmake, 'bssl', files['tool'], ['ssl', 'crypto']) cmake.write( -R'''if(NOT WIN32 AND NOT ANDROID) - target_link_libraries(crypto pthread) +R'''if(NOT ANDROID) + find_package(Threads REQUIRED) + target_link_libraries(crypto Threads::Threads) endif() if(WIN32) From 54b04fdc21d540a6e24f9ddb7ddc3e583518e24f Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Sun, 29 Jan 2023 11:56:25 -0500 Subject: [PATCH 4/7] Mark standalone Go scripts with go:build ignore gopls currently litters our project with a sea of red, because it assumes Go files are part of a package, but we have a lot of standalone Go scripts. (If there are C files in the same directory as the script, it gets upset about cgo. If there are multiple standalone scripts in the same directory, it gets uspet about duplicate files.) Per https://github.com/golang/go/issues/49657 and https://github.com/golang/tools/blob/master/gopls/doc/settings.md#standalonetags-string, the convention seems to be a go:build ignore tag. Newer versions of gopls run in a "standalone" mode, so we still get all the nice LSP features. As part of this, I had to align the license header comments from /* block comments */ to // line comments. Go build constraints can only be preceded by blank lines and line comments. Block comments apparently aren't allowed. (See https://pkg.go.dev/cmd/go#hdr-Build_constraints.) If I leave the file unconverted, go fmt will immediately move the comment to above the license block. Change-Id: I47c69255522e9aae2bdb97a6e83fcc6ce0cf29d5 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56525 Commit-Queue: Adam Langley Reviewed-by: Adam Langley Auto-Submit: David Benjamin --- crypto/err/err_data_generate.go | 28 ++++++------ crypto/fipsmodule/bn/bn_test_to_fuzzer.go | 2 + crypto/fipsmodule/bn/check_bn_tests.go | 2 + .../ec/make_ec_scalar_base_mult_tests.go | 28 ++++++------ crypto/fipsmodule/ec/make_p256-nistz-tests.go | 28 ++++++------ crypto/fipsmodule/ec/make_tables.go | 28 ++++++------ crypto/obj/objects.go | 2 + crypto/x509/test/make_basic_constraints.go | 28 ++++++------ crypto/x509/test/make_invalid_extensions.go | 28 ++++++------ crypto/x509/test/make_many_constraints.go | 44 ++++++++++--------- crypto/x509/test/make_policy_certs.go | 28 ++++++------ util/all_tests.go | 28 ++++++------ util/check_filenames.go | 2 + util/check_imported_libraries.go | 2 + util/check_stack.go | 2 + util/compare_benchmarks.go | 28 ++++++------ util/convert_comments.go | 2 + util/convert_wycheproof.go | 28 ++++++------ util/diff_asm.go | 28 ++++++------ util/doc.go | 5 ++- util/embed_test_data.go | 4 +- util/fetch_ech_config_list.go | 2 + .../acvp/acvptool/test/check_expected.go | 2 + .../acvp/acvptool/test/trim_vectors.go | 2 + util/fipstools/break-hash.go | 2 + util/fipstools/break-kat.go | 2 + util/godeps.go | 2 + util/make_errors.go | 2 + util/make_prefix_headers.go | 5 ++- util/read_symbols.go | 2 + util/run_android_tests.go | 2 + 31 files changed, 229 insertions(+), 169 deletions(-) diff --git a/crypto/err/err_data_generate.go b/crypto/err/err_data_generate.go index 963964c66..3e06f00bd 100644 --- a/crypto/err/err_data_generate.go +++ b/crypto/err/err_data_generate.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2015, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2015, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/crypto/fipsmodule/bn/bn_test_to_fuzzer.go b/crypto/fipsmodule/bn/bn_test_to_fuzzer.go index 13cff26a0..afe7d61c8 100644 --- a/crypto/fipsmodule/bn/bn_test_to_fuzzer.go +++ b/crypto/fipsmodule/bn/bn_test_to_fuzzer.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/crypto/fipsmodule/bn/check_bn_tests.go b/crypto/fipsmodule/bn/check_bn_tests.go index 26443b93d..0c8493d06 100644 --- a/crypto/fipsmodule/bn/check_bn_tests.go +++ b/crypto/fipsmodule/bn/check_bn_tests.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go b/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go index 716da55b7..1d3896aa9 100644 --- a/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go +++ b/crypto/fipsmodule/ec/make_ec_scalar_base_mult_tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/crypto/fipsmodule/ec/make_p256-nistz-tests.go b/crypto/fipsmodule/ec/make_p256-nistz-tests.go index 36194e61b..e10990b30 100644 --- a/crypto/fipsmodule/ec/make_p256-nistz-tests.go +++ b/crypto/fipsmodule/ec/make_p256-nistz-tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/crypto/fipsmodule/ec/make_tables.go b/crypto/fipsmodule/ec/make_tables.go index dbcaab06f..ef7ac64f3 100644 --- a/crypto/fipsmodule/ec/make_tables.go +++ b/crypto/fipsmodule/ec/make_tables.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/crypto/obj/objects.go b/crypto/obj/objects.go index 1b9ded347..716adf948 100644 --- a/crypto/obj/objects.go +++ b/crypto/obj/objects.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/crypto/x509/test/make_basic_constraints.go b/crypto/x509/test/make_basic_constraints.go index 652479968..ea502b4c8 100644 --- a/crypto/x509/test/make_basic_constraints.go +++ b/crypto/x509/test/make_basic_constraints.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_basic_constraints.go generates self-signed certificates with the basic // constraints extension. diff --git a/crypto/x509/test/make_invalid_extensions.go b/crypto/x509/test/make_invalid_extensions.go index aba2d7197..8287bf8d3 100644 --- a/crypto/x509/test/make_invalid_extensions.go +++ b/crypto/x509/test/make_invalid_extensions.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_invalid_extensions.go generates a number of certificate chains with // invalid extension encodings. diff --git a/crypto/x509/test/make_many_constraints.go b/crypto/x509/test/make_many_constraints.go index 578618dfb..24a5c4071 100644 --- a/crypto/x509/test/make_many_constraints.go +++ b/crypto/x509/test/make_many_constraints.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2017, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2017, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_many_constraints.go generates test certificates many_constraints.pem, // many_names*.pem, and some_names*.pem for x509_test.cc @@ -107,10 +109,10 @@ func main() { NotBefore: notBefore, NotAfter: notAfter, BasicConstraintsValid: true, - IsCA: true, - ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, - KeyUsage: x509.KeyUsageCertSign, - SignatureAlgorithm: x509.SHA256WithRSA, + IsCA: true, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + KeyUsage: x509.KeyUsageCertSign, + SignatureAlgorithm: x509.SHA256WithRSA, } for i := 0; i < 513; i++ { caTemplate.ExcludedDNSDomains = append(caTemplate.ExcludedDNSDomains, fmt.Sprintf("x%d.test", i)) @@ -149,10 +151,10 @@ func main() { NotBefore: notBefore, NotAfter: notAfter, BasicConstraintsValid: true, - IsCA: false, - ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, - KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment, - SignatureAlgorithm: x509.SHA256WithRSA, + IsCA: false, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment, + SignatureAlgorithm: x509.SHA256WithRSA, } for i := 0; i < leaf.names; i++ { leafTemplate.DNSNames = append(leafTemplate.DNSNames, fmt.Sprintf("t%d.test", i)) diff --git a/crypto/x509/test/make_policy_certs.go b/crypto/x509/test/make_policy_certs.go index c57d97310..bc944f2de 100644 --- a/crypto/x509/test/make_policy_certs.go +++ b/crypto/x509/test/make_policy_certs.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // make_policy_certs.go generates certificates for testing policy handling. package main diff --git a/util/all_tests.go b/util/all_tests.go index 4f484f353..c0dceba55 100644 --- a/util/all_tests.go +++ b/util/all_tests.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2015, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2015, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/util/check_filenames.go b/util/check_filenames.go index 886c3f609..384c19f51 100644 --- a/util/check_filenames.go +++ b/util/check_filenames.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_filenames.go checks that filenames are unique. Some of our consumers do // not support multiple files with the same name in the same build target, even // if they are in different directories. diff --git a/util/check_imported_libraries.go b/util/check_imported_libraries.go index 187e51441..f3803f1c1 100644 --- a/util/check_imported_libraries.go +++ b/util/check_imported_libraries.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_imported_libraries.go checks that each of its arguments only imports // allowed libraries. This is used to avoid accidental dependencies on // libstdc++.so. diff --git a/util/check_stack.go b/util/check_stack.go index b718ea4ac..ad763e652 100644 --- a/util/check_stack.go +++ b/util/check_stack.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // check_stack.go checks that each of its arguments has a non-executable stack. // See https://www.airs.com/blog/archives/518 for details. package main diff --git a/util/compare_benchmarks.go b/util/compare_benchmarks.go index 0c79d638e..05e1b5db0 100644 --- a/util/compare_benchmarks.go +++ b/util/compare_benchmarks.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2020 Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2020 Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // compare_benchmarks takes the JSON-formatted output of bssl speed and // compares it against a baseline output. diff --git a/util/convert_comments.go b/util/convert_comments.go index 917f29c86..df9e3d3ae 100644 --- a/util/convert_comments.go +++ b/util/convert_comments.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/util/convert_wycheproof.go b/util/convert_wycheproof.go index f81771e4b..809da6f51 100644 --- a/util/convert_wycheproof.go +++ b/util/convert_wycheproof.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2018, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2018, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // convert_wycheproof.go converts Wycheproof test vectors into a format more // easily consumed by BoringSSL. diff --git a/util/diff_asm.go b/util/diff_asm.go index 710a42cb6..5ac1c04bb 100644 --- a/util/diff_asm.go +++ b/util/diff_asm.go @@ -1,16 +1,18 @@ -/* Copyright (c) 2016, Google Inc. - * - * Permission to use, copy, modify, and/or distribute this software for any - * purpose with or without fee is hereby granted, provided that the above - * copyright notice and this permission notice appear in all copies. - * - * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES - * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF - * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY - * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES - * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION - * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN - * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// Copyright (c) 2016, Google Inc. +// +// Permission to use, copy, modify, and/or distribute this software for any +// purpose with or without fee is hereby granted, provided that the above +// copyright notice and this permission notice appear in all copies. +// +// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +// WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +// MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY +// SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +// WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION +// OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore package main diff --git a/util/doc.go b/util/doc.go index 45caa15ea..4fb73ca0d 100644 --- a/util/doc.go +++ b/util/doc.go @@ -1,10 +1,11 @@ +//go:build ignore + // doc generates HTML files from the comments in header files. // // doc expects to be given the path to a JSON file via the --config option. // From that JSON (which is defined by the Config struct) it reads a list of // header file locations and generates HTML files for each in the current // directory. - package main import ( @@ -411,7 +412,7 @@ func (config *Config) parseHeader(path string) (*HeaderFile, error) { lines = lines[1:] lineNo++ break - } + } if line == cppGuard { return nil, fmt.Errorf("hit ending C++ guard while in section on line %d (possibly missing two empty lines ahead of guard?)", lineNo) } diff --git a/util/embed_test_data.go b/util/embed_test_data.go index 266f2969a..ae7135fae 100644 --- a/util/embed_test_data.go +++ b/util/embed_test_data.go @@ -10,7 +10,9 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +//go:build ignore // embed_test_data generates a C++ source file which exports a function, // GetTestData, which looks up the specified data files. diff --git a/util/fetch_ech_config_list.go b/util/fetch_ech_config_list.go index 8f09e66b1..732d0d3b8 100644 --- a/util/fetch_ech_config_list.go +++ b/util/fetch_ech_config_list.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/util/fipstools/acvp/acvptool/test/check_expected.go b/util/fipstools/acvp/acvptool/test/check_expected.go index ccc803850..588b8038b 100644 --- a/util/fipstools/acvp/acvptool/test/check_expected.go +++ b/util/fipstools/acvp/acvptool/test/check_expected.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/util/fipstools/acvp/acvptool/test/trim_vectors.go b/util/fipstools/acvp/acvptool/test/trim_vectors.go index 53e970e02..703f75fd2 100644 --- a/util/fipstools/acvp/acvptool/test/trim_vectors.go +++ b/util/fipstools/acvp/acvptool/test/trim_vectors.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // trimvectors takes an ACVP vector set file and discards all but a single test // from each test group. This hope is that this achieves good coverage without // having to check in megabytes worth of JSON files. diff --git a/util/fipstools/break-hash.go b/util/fipstools/break-hash.go index 9893716b9..b0c59bc57 100644 --- a/util/fipstools/break-hash.go +++ b/util/fipstools/break-hash.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +//go:build ignore + // break-hash parses an ELF binary containing the FIPS module and corrupts the // first byte of the module. This should cause the integrity check to fail. package main diff --git a/util/fipstools/break-kat.go b/util/fipstools/break-kat.go index 6eace5b46..ebf5dd703 100644 --- a/util/fipstools/break-kat.go +++ b/util/fipstools/break-kat.go @@ -1,3 +1,5 @@ +//go:build + // break-kat corrupts a known-answer-test input in a binary and writes the // corrupted binary to stdout. This is used to demonstrate that the KATs in the // binary notice the error. diff --git a/util/godeps.go b/util/godeps.go index 960faa46b..56be55944 100644 --- a/util/godeps.go +++ b/util/godeps.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // godeps prints out dependencies of a package in either CMake or Make depfile // format, for incremental rebuilds. // diff --git a/util/make_errors.go b/util/make_errors.go index 4e2718b8d..018845258 100644 --- a/util/make_errors.go +++ b/util/make_errors.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( diff --git a/util/make_prefix_headers.go b/util/make_prefix_headers.go index b536f14ce..8787654b5 100644 --- a/util/make_prefix_headers.go +++ b/util/make_prefix_headers.go @@ -12,12 +12,15 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // This program takes a file containing newline-separated symbols, and generates // boringssl_prefix_symbols.h, boringssl_prefix_symbols_asm.h, and // boringssl_prefix_symbols_nasm.inc. These header files can be used to build // BoringSSL with a prefix for all symbols in order to avoid symbol name // conflicts when linking a project with multiple copies of BoringSSL; see // BUILDING.md for more details. +package main // TODO(joshlf): For platforms which support it, use '#pragma redefine_extname' // instead of a custom macro. This avoids the need for a custom macro, but also @@ -26,8 +29,6 @@ // IllumOS' fork of OpenSSL: // https://github.com/joyent/illumos-extra/blob/master/openssl1x/sunw_prefix.h -package main - import ( "bufio" "flag" diff --git a/util/read_symbols.go b/util/read_symbols.go index 96c148ab5..69d000282 100644 --- a/util/read_symbols.go +++ b/util/read_symbols.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + // read_symbols scans one or more .a files and, for each object contained in // the .a files, reads the list of symbols in that object file. package main diff --git a/util/run_android_tests.go b/util/run_android_tests.go index 51b20172a..59ddbe75a 100644 --- a/util/run_android_tests.go +++ b/util/run_android_tests.go @@ -12,6 +12,8 @@ // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +//go:build ignore + package main import ( From 4ed497f0c513dbc1c176dcad7806eea5caf6fbef Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Sun, 29 Jan 2023 12:03:03 -0500 Subject: [PATCH 5/7] Fix stray */s in // line comment license headers I assume this came from a bad conversion and then got copy-and-pasted everywhere. Change-Id: Id596623608266ce6350d70dff413f38e9fdf13b3 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56526 Commit-Queue: David Benjamin Reviewed-by: Adam Langley --- decrepit/cfb/cfb.c | 2 +- decrepit/cfb/cfb_test.cc | 2 +- decrepit/xts/xts_test.cc | 2 +- util/ar/ar.go | 2 +- util/ar/ar_test.go | 2 +- util/fipstools/break-hash.go | 2 +- util/fipstools/delocate/delocate.go | 2 +- util/fipstools/delocate/delocate_test.go | 2 +- util/fipstools/fipscommon/const.go | 2 +- util/fipstools/inject_hash/inject_hash.go | 2 +- 10 files changed, 10 insertions(+), 10 deletions(-) diff --git a/decrepit/cfb/cfb.c b/decrepit/cfb/cfb.c index d23115357..c15292cf0 100644 --- a/decrepit/cfb/cfb.c +++ b/decrepit/cfb/cfb.c @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/decrepit/cfb/cfb_test.cc b/decrepit/cfb/cfb_test.cc index 2510a88a6..da9681eca 100644 --- a/decrepit/cfb/cfb_test.cc +++ b/decrepit/cfb/cfb_test.cc @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/decrepit/xts/xts_test.cc b/decrepit/xts/xts_test.cc index 22e80facd..346ca556c 100644 --- a/decrepit/xts/xts_test.cc +++ b/decrepit/xts/xts_test.cc @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. #include diff --git a/util/ar/ar.go b/util/ar/ar.go index 756caf53d..fdc2dd2b1 100644 --- a/util/ar/ar.go +++ b/util/ar/ar.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // ar.go contains functions for parsing .a archive files. diff --git a/util/ar/ar_test.go b/util/ar/ar_test.go index fac0e266a..31baaf162 100644 --- a/util/ar/ar_test.go +++ b/util/ar/ar_test.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package ar diff --git a/util/fipstools/break-hash.go b/util/fipstools/break-hash.go index b0c59bc57..a4ab8083d 100644 --- a/util/fipstools/break-hash.go +++ b/util/fipstools/break-hash.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. //go:build ignore diff --git a/util/fipstools/delocate/delocate.go b/util/fipstools/delocate/delocate.go index c9daff931..c28be558c 100644 --- a/util/fipstools/delocate/delocate.go +++ b/util/fipstools/delocate/delocate.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // delocate performs several transformations of textual assembly code. See // crypto/fipsmodule/FIPS.md for an overview. diff --git a/util/fipstools/delocate/delocate_test.go b/util/fipstools/delocate/delocate_test.go index e3dff546e..e341a3815 100644 --- a/util/fipstools/delocate/delocate_test.go +++ b/util/fipstools/delocate/delocate_test.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package main diff --git a/util/fipstools/fipscommon/const.go b/util/fipstools/fipscommon/const.go index f4c0b75d4..c709961e1 100644 --- a/util/fipstools/fipscommon/const.go +++ b/util/fipstools/fipscommon/const.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. package fipscommon diff --git a/util/fipstools/inject_hash/inject_hash.go b/util/fipstools/inject_hash/inject_hash.go index 3680cfdf8..9c3083663 100644 --- a/util/fipstools/inject_hash/inject_hash.go +++ b/util/fipstools/inject_hash/inject_hash.go @@ -10,7 +10,7 @@ // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */ +// CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. // inject_hash parses an archive containing a file object file. It finds a FIPS // module inside that object, calculates its hash and replaces the default hash From f31654786c0e9c54c227b1e966faadc615780ef5 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Sun, 29 Jan 2023 12:06:01 -0500 Subject: [PATCH 6/7] Simplify a pair of Go range expressions gopls was warning about this. Change-Id: Ida8ff67bcb9ada253fb075a8a800cbefd432ca8f Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56545 Commit-Queue: David Benjamin Reviewed-by: Adam Langley --- crypto/fipsmodule/bn/bn_test_to_fuzzer.go | 2 +- crypto/fipsmodule/bn/check_bn_tests.go | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/crypto/fipsmodule/bn/bn_test_to_fuzzer.go b/crypto/fipsmodule/bn/bn_test_to_fuzzer.go index afe7d61c8..2915db5f9 100644 --- a/crypto/fipsmodule/bn/bn_test_to_fuzzer.go +++ b/crypto/fipsmodule/bn/bn_test_to_fuzzer.go @@ -140,7 +140,7 @@ func checkKeys(t test, keys ...string) bool { } } - for k, _ := range t.Values { + for k := range t.Values { var found bool for _, k2 := range keys { if k == k2 { diff --git a/crypto/fipsmodule/bn/check_bn_tests.go b/crypto/fipsmodule/bn/check_bn_tests.go index 0c8493d06..032b9e328 100644 --- a/crypto/fipsmodule/bn/check_bn_tests.go +++ b/crypto/fipsmodule/bn/check_bn_tests.go @@ -137,7 +137,7 @@ func checkKeys(t test, keys ...string) bool { } } - for k, _ := range t.Values { + for k := range t.Values { var found bool for _, k2 := range keys { if k == k2 { From 23776d03bdc8e5e15ac82b993d64fa24aae87db4 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Fri, 9 Dec 2022 11:33:17 -0500 Subject: [PATCH 7/7] Simplify the external Bazel build. Now that all assembly files are conditionalized, we no longer need to detect platforms at the build level. This is convenient because detecting platforms in Bazel is a bit of a mess. In particular, this reduces how much we depend on @platforms being correct. gRPC's build appears to still be using some legacy modes which seem cause it to, on cross-compiles, report the host's platforms rather than the target. See https://github.com/grpc/grpc/pull/31938 gRPC should eventually fix this, but it is apparently challenging due to complexities in migrating from Bazel's legacy system the new "platforms" mechanism. Instead, try to sidestep this problem by not relying on the build to do this. Now, we primarily rely on os:windows being accurate, and cross-compiling to/from Windows is uncommon. We do also need os:linux to be accurate when Linux is the target OS, but if Linux is the host and gRPC mislabels the target as os:linux, this is fine as long as the target is not FreeBSD, Apple, or another platform that cares about _XOPEN_SOURCE. (In particular, Android is ambivalent.) I've also renamed a few things based on what they were actually selecting. posix_copts was really copts for toolchains with GCC-style flags. Unfortunately, it's not clear how to condition on the compiler, rather than the platform in Bazel, so we'll do the wrong thing on non-MSVC Windows toolchains, but that was true before. Bug: 542 Change-Id: I7330d8961145ae5714d4cad01259044230d96bcd Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/56465 Reviewed-by: Adam Langley Commit-Queue: David Benjamin --- util/BUILD.toplevel | 205 ++++++++++++----------------------- util/generate_build_files.py | 17 +++ 2 files changed, 89 insertions(+), 133 deletions(-) diff --git a/util/BUILD.toplevel b/util/BUILD.toplevel index c3143894a..a855aa5a9 100644 --- a/util/BUILD.toplevel +++ b/util/BUILD.toplevel @@ -18,14 +18,7 @@ load( "crypto_headers", "crypto_internal_headers", "crypto_sources", - "crypto_sources_apple_aarch64", - "crypto_sources_apple_arm", - "crypto_sources_apple_x86", - "crypto_sources_apple_x86_64", - "crypto_sources_linux_aarch64", - "crypto_sources_linux_arm", - "crypto_sources_linux_x86", - "crypto_sources_linux_x86_64", + "crypto_sources_asm", "fips_fragments", "ssl_headers", "ssl_internal_headers", @@ -38,33 +31,47 @@ licenses(["notice"]) exports_files(["LICENSE"]) -[ - ( - config_setting( - name = os + "_" + arch, - constraint_values = [ - "@platforms//os:" + os, - "@platforms//cpu:" + arch, - ], - ), - ) - for os in [ - "linux", - "android", - "macos", - "ios", - "tvos", - "watchos", - ] - for arch in [ - "arm64", - "armv7", - "x86_64", - "x86_32", - ] -] +# By default, the C files will expect assembly files, if any, to be linked in +# with the build. This default can be flipped with -DOPENSSL_NO_ASM. If building +# in a configuration where we have no assembly optimizations, -DOPENSSL_NO_ASM +# has no effect, and either value is fine. +# +# Like C files, assembly files are wrapped in #ifdef (or NASM equivalent), so it +# is safe to include a file for the wrong platform in the build. It will just +# output an empty object file. However, we need some platform selectors to +# distinguish between gas or NASM syntax. +# +# For all non-Windows platforms, we use gas assembly syntax and can assume any +# GCC-compatible toolchain includes a gas-compatible assembler. +# +# For Windows, we use NASM on x86 and x86_64 and gas, specifically +# clang-assembler, on aarch64. We have not yet added NASM support to this build, +# and would need to detect MSVC vs clang-cl for aarch64 so, for now, we just +# disable assembly on Windows across the board. +# +# These two selects for asm_sources and asm_copts must be kept in sync. If we +# specify assembly, we don't want OPENSSL_NO_ASM. If we don't specify assembly, +# we want OPENSSL_NO_ASM, in case the C files expect them in some format (e.g. +# NASM) this build file doesn't yet support. +# +# TODO(https://crbug.com/boringssl/531): Enable assembly for Windows. +asm_sources = select({ + "@platforms//os:windows": [], + "//conditions:default": crypto_sources_asm, +}) +asm_copts = select({ + "@platforms//os:windows": ["-DOPENSSL_NO_ASM"], + "//conditions:default": [], +}) -posix_copts = [ +# Configure C, C++, and common flags for GCC-compatible toolchains. +# +# TODO(davidben): Can we remove some of these? In Bazel, are warnings the +# toolchain or project's responsibility? -Wa,--noexecstack should be unnecessary +# now, though https://crbug.com/boringssl/292 tracks testing this in CI. +# -fno-common did not become default until +# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85678. +gcc_copts = [ # Assembler option --noexecstack adds .note.GNU-stack to each object to # ensure that binaries can be built with non-executable stack. "-Wa,--noexecstack", @@ -79,119 +86,51 @@ posix_copts = [ "-Wshadow", "-fno-common", ] - -glibc_copts = posix_copts + [ - # This is needed on glibc systems (at least) to get rwlock in pthread, but - # it should not be set on Apple platforms or FreeBSD, where it instead - # disables APIs we use. - # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 - "-D_XOPEN_SOURCE=700", -] - -boringssl_copts = select({ - "@platforms//os:linux": glibc_copts, - "@platforms//os:android": posix_copts, - "@platforms//os:macos": posix_copts, - "@platforms//os:ios": posix_copts, - "@platforms//os:tvos": posix_copts, - "@platforms//os:watchos": posix_copts, - "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], - "//conditions:default": [], -}) - -# These selects must be kept in sync. -crypto_sources_asm = select({ - ":linux_armv7": crypto_sources_linux_arm, - ":linux_arm64": crypto_sources_linux_aarch64, - ":linux_x86_32": crypto_sources_linux_x86, - ":linux_x86_64": crypto_sources_linux_x86_64, - ":android_armv7": crypto_sources_linux_arm, - ":android_arm64": crypto_sources_linux_aarch64, - ":android_x86_32": crypto_sources_linux_x86, - ":android_x86_64": crypto_sources_linux_x86_64, - ":macos_armv7": crypto_sources_apple_arm, - ":macos_arm64": crypto_sources_apple_aarch64, - ":macos_x86_32": crypto_sources_apple_x86, - ":macos_x86_64": crypto_sources_apple_x86_64, - ":ios_armv7": crypto_sources_apple_arm, - ":ios_arm64": crypto_sources_apple_aarch64, - ":ios_x86_32": crypto_sources_apple_x86, - ":ios_x86_64": crypto_sources_apple_x86_64, - ":tvos_armv7": crypto_sources_apple_arm, - ":tvos_arm64": crypto_sources_apple_aarch64, - ":tvos_x86_32": crypto_sources_apple_x86, - ":tvos_x86_64": crypto_sources_apple_x86_64, - ":watchos_armv7": crypto_sources_apple_arm, - ":watchos_arm64": crypto_sources_apple_aarch64, - ":watchos_x86_32": crypto_sources_apple_x86, - ":watchos_x86_64": crypto_sources_apple_x86_64, - "//conditions:default": [], -}) -boringssl_copts += select({ - ":linux_armv7": [], - ":linux_arm64": [], - ":linux_x86_32": [], - ":linux_x86_64": [], - ":android_armv7": [], - ":android_arm64": [], - ":android_x86_32": [], - ":android_x86_64": [], - ":macos_armv7": [], - ":macos_arm64": [], - ":macos_x86_32": [], - ":macos_x86_64": [], - ":ios_armv7": [], - ":ios_arm64": [], - ":ios_x86_32": [], - ":ios_x86_64": [], - ":tvos_armv7": [], - ":tvos_arm64": [], - ":tvos_x86_32": [], - ":tvos_x86_64": [], - ":watchos_armv7": [], - ":watchos_arm64": [], - ":watchos_x86_32": [], - ":watchos_x86_64": [], - "//conditions:default": ["-DOPENSSL_NO_ASM"], -}) - -# For C targets only (not C++), compile with C11 support. -posix_copts_c11 = [ +gcc_copts_c11 = [ "-std=c11", "-Wmissing-prototypes", "-Wold-style-definition", "-Wstrict-prototypes", ] - -boringssl_copts_c11 = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_c11, - "@platforms//os:android": posix_copts_c11, - "@platforms//os:macos": posix_copts_c11, - "@platforms//os:ios": posix_copts_c11, - "@platforms//os:tvos": posix_copts_c11, - "@platforms//os:watchos": posix_copts_c11, - "//conditions:default": [], -}) - -# For C++ targets only (not C), compile with C++14 support. -posix_copts_cxx = [ +gcc_copts_cxx = [ "-std=c++14", "-Wmissing-declarations", ] -boringssl_copts_cxx = boringssl_copts + select({ - "@platforms//os:linux": posix_copts_cxx, - "@platforms//os:android": posix_copts_cxx, - "@platforms//os:macos": posix_copts_cxx, - "@platforms//os:ios": posix_copts_cxx, - "@platforms//os:tvos": posix_copts_cxx, - "@platforms//os:watchos": posix_copts_cxx, +boringssl_copts = select({ + # We assume that non-Windows builds use a GCC-compatible toolchain and that + # Windows builds do not. + # + # TODO(davidben): Should these be querying something in @bazel_tools? + # Unfortunately, @bazel_tools is undocumented. See + # https://github.com/bazelbuild/bazel/issues/14914 + "@platforms//os:windows": [], + "//conditions:default": gcc_copts, +}) + select({ + # This is needed on glibc systems to get rwlock in pthreads, but it should + # not be set on Apple platforms or FreeBSD, where it instead disables APIs + # we use. + # See compat(5), sys/cdefs.h, and https://crbug.com/boringssl/471 + "@platforms//os:linux": ["-D_XOPEN_SOURCE=700"], + # Without WIN32_LEAN_AND_MEAN, pulls in wincrypt.h, which + # conflicts with our . + "@platforms//os:windows": ["-DWIN32_LEAN_AND_MEAN"], "//conditions:default": [], +}) + asm_copts + +boringssl_copts_c11 = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_c11, +}) + +boringssl_copts_cxx = boringssl_copts + select({ + "@platforms//os:windows": [], + "//conditions:default": gcc_copts_cxx, }) cc_library( name = "crypto", - srcs = crypto_sources + crypto_internal_headers + crypto_sources_asm, + srcs = crypto_sources + crypto_internal_headers + asm_sources, hdrs = crypto_headers + fips_fragments, copts = boringssl_copts_c11, includes = ["src/include"], diff --git a/util/generate_build_files.py b/util/generate_build_files.py index 383de02d2..0cabe9c2b 100644 --- a/util/generate_build_files.py +++ b/util/generate_build_files.py @@ -255,6 +255,23 @@ class Bazel(object): self.PrintVariableSection( out, 'crypto_sources_%s_%s' % (osname, arch), asm_files) + # Generate combined source lists for gas and nasm. Consumers have a choice + # of using the per-platform ones or the combined ones. In the combined + # mode, Windows x86 and Windows x86_64 must still be special-cased, but + # otherwise all assembly files can be linked together. + out.write('\n') + out.write('crypto_sources_asm = []\n') + for (osname, arch, _, _, asm_ext) in OS_ARCH_COMBOS: + if asm_ext == 'S': + out.write('crypto_sources_asm.extend(crypto_sources_%s_%s)\n' % + (osname, arch)) + out.write('\n') + out.write('crypto_sources_nasm = []\n') + for (osname, arch, _, _, asm_ext) in OS_ARCH_COMBOS: + if asm_ext == 'asm': + out.write('crypto_sources_nasm.extend(crypto_sources_%s_%s)\n' % + (osname, arch)) + with open('BUILD.generated_tests.bzl', 'w+') as out: out.write(self.header)