You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f820453
Browse filesBrowse the repository at this point in the historyBrowse files
Four review findings on the TLS-gaps work:
1. use_pkcs12_file assigned its password with std::string(passphrase),
reintroducing the one-past-the-end pointer that trips ASan
detect_invalid_pointer_pairs on a non-null-terminated view (the same
bug just fixed in use_pkcs12). Use assign(ptr, len) to match.
2. CRL loading was PEM-only and dropped parse failures silently, so a
DER or malformed CRL vanished — and under soft_fail a peer the missing
CRL might have revoked was then accepted (fail-open), contradicting the
"PEM or DER" contract. Both backends now try PEM then DER, and a CRL
that parses as neither fails the handshake closed (OpenSSL in
do_handshake, WolfSSL in init_ssl_for_role). New generic test asserts a
malformed CRL under soft_fail fails rather than silently accepting.
3. wolfssl_stream comment claimed PKCS#12 CA/chain entries "are not
loaded"; the code loads and sends them (and testPkcs12Chain proves it).
Comment corrected.
4. Added the "Copyright (c) 2026 Michael Vandeberg" line to two files
substantially modified in this PR (test/unit/tls_context.cpp,
include/boost/corosio/tls_stream.hpp) per the repo convention.
Verified on system WolfSSL (HAVE_CRL off), a vcpkg-flag WolfSSL 5.8.2
build (HAVE_CRL on), and the asan+ubsan config with the CI ASAN_OPTIONS:
all TLS suites pass.
0 commit comments