Update OpenSSL-1.1.1-pre8-dev
This commit is contained in:
+30
-33
@@ -1209,6 +1209,7 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
|
||||
SSL3_RECORD *rr;
|
||||
SSL3_BUFFER *rbuf;
|
||||
void (*cb) (const SSL *ssl, int type2, int val) = NULL;
|
||||
int is_tls13 = SSL_IS_TLS13(s);
|
||||
|
||||
rbuf = &s->rlayer.rbuf;
|
||||
|
||||
@@ -1340,7 +1341,7 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
|
||||
if (type == SSL3_RECORD_get_type(rr)
|
||||
|| (SSL3_RECORD_get_type(rr) == SSL3_RT_CHANGE_CIPHER_SPEC
|
||||
&& type == SSL3_RT_HANDSHAKE && recvd_type != NULL
|
||||
&& !SSL_IS_TLS13(s))) {
|
||||
&& !is_tls13)) {
|
||||
/*
|
||||
* SSL3_RT_APPLICATION_DATA or
|
||||
* SSL3_RT_HANDSHAKE or
|
||||
@@ -1524,7 +1525,8 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
|
||||
cb(s, SSL_CB_READ_ALERT, j);
|
||||
}
|
||||
|
||||
if (alert_level == SSL3_AL_WARNING) {
|
||||
if (alert_level == SSL3_AL_WARNING
|
||||
|| (is_tls13 && alert_descr == SSL_AD_USER_CANCELLED)) {
|
||||
s->s3->warn_alert = alert_descr;
|
||||
SSL3_RECORD_set_read(rr);
|
||||
|
||||
@@ -1534,34 +1536,19 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
|
||||
SSL_R_TOO_MANY_WARN_ALERTS);
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
|
||||
if (alert_descr == SSL_AD_CLOSE_NOTIFY) {
|
||||
s->shutdown |= SSL_RECEIVED_SHUTDOWN;
|
||||
return 0;
|
||||
}
|
||||
/*
|
||||
* Apart from close_notify the only other warning alert in TLSv1.3
|
||||
* is user_cancelled - which we just ignore.
|
||||
*/
|
||||
if (SSL_IS_TLS13(s) && alert_descr != SSL_AD_USER_CANCELLED) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_F_SSL3_READ_BYTES,
|
||||
SSL_R_UNKNOWN_ALERT_TYPE);
|
||||
return -1;
|
||||
}
|
||||
/*
|
||||
* This is a warning but we receive it if we requested
|
||||
* renegotiation and the peer denied it. Terminate with a fatal
|
||||
* alert because if application tried to renegotiate it
|
||||
* presumably had a good reason and expects it to succeed. In
|
||||
* future we might have a renegotiation where we don't care if
|
||||
* the peer refused it where we carry on.
|
||||
*/
|
||||
if (alert_descr == SSL_AD_NO_RENEGOTIATION) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_F_SSL3_READ_BYTES,
|
||||
SSL_R_NO_RENEGOTIATION);
|
||||
return -1;
|
||||
}
|
||||
} else if (alert_level == SSL3_AL_FATAL) {
|
||||
/*
|
||||
* Apart from close_notify the only other warning alert in TLSv1.3
|
||||
* is user_cancelled - which we just ignore.
|
||||
*/
|
||||
if (is_tls13 && alert_descr == SSL_AD_USER_CANCELLED) {
|
||||
goto start;
|
||||
} else if (alert_descr == SSL_AD_CLOSE_NOTIFY
|
||||
&& (is_tls13 || alert_level == SSL3_AL_WARNING)) {
|
||||
s->shutdown |= SSL_RECEIVED_SHUTDOWN;
|
||||
return 0;
|
||||
} else if (alert_level == SSL3_AL_FATAL || is_tls13) {
|
||||
char tmp[16];
|
||||
|
||||
s->rwstate = SSL_NOTHING;
|
||||
@@ -1574,13 +1561,23 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
|
||||
SSL3_RECORD_set_read(rr);
|
||||
SSL_CTX_remove_session(s->session_ctx, s->session);
|
||||
return 0;
|
||||
} else {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_F_SSL3_READ_BYTES,
|
||||
SSL_R_UNKNOWN_ALERT_TYPE);
|
||||
} else if (alert_descr == SSL_AD_NO_RENEGOTIATION) {
|
||||
/*
|
||||
* This is a warning but we receive it if we requested
|
||||
* renegotiation and the peer denied it. Terminate with a fatal
|
||||
* alert because if application tried to renegotiate it
|
||||
* presumably had a good reason and expects it to succeed. In
|
||||
* future we might have a renegotiation where we don't care if
|
||||
* the peer refused it where we carry on.
|
||||
*/
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_F_SSL3_READ_BYTES,
|
||||
SSL_R_NO_RENEGOTIATION);
|
||||
return -1;
|
||||
}
|
||||
|
||||
goto start;
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_F_SSL3_READ_BYTES,
|
||||
SSL_R_UNKNOWN_ALERT_TYPE);
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (s->shutdown & SSL_SENT_SHUTDOWN) { /* but we have not received a
|
||||
|
||||
+3
-3
@@ -769,11 +769,11 @@ static int remove_session_lock(SSL_CTX *ctx, SSL_SESSION *c, int lck)
|
||||
if (lck)
|
||||
CRYPTO_THREAD_unlock(ctx->lock);
|
||||
|
||||
if (ret)
|
||||
SSL_SESSION_free(r);
|
||||
|
||||
if (ctx->remove_session_cb != NULL)
|
||||
ctx->remove_session_cb(ctx, c);
|
||||
|
||||
if (ret)
|
||||
SSL_SESSION_free(r);
|
||||
} else
|
||||
ret = 0;
|
||||
return ret;
|
||||
|
||||
@@ -984,7 +984,9 @@ static int final_server_name(SSL *s, unsigned int context, int sent)
|
||||
return 0;
|
||||
|
||||
case SSL_TLSEXT_ERR_ALERT_WARNING:
|
||||
ssl3_send_alert(s, SSL3_AL_WARNING, altmp);
|
||||
/* TLSv1.3 doesn't have warning alerts so we suppress this */
|
||||
if (!SSL_IS_TLS13(s))
|
||||
ssl3_send_alert(s, SSL3_AL_WARNING, altmp);
|
||||
return 1;
|
||||
|
||||
case SSL_TLSEXT_ERR_NOACK:
|
||||
|
||||
Reference in New Issue
Block a user