[openssl-commits] Coverity Scan: Analysis completed for openssl/openssl

2017-09-04 Thread scan-admin

Your request for analysis of openssl/openssl has been completed 
successfully.
The results are available at 
https://u2389337.ct.sendgrid.net/wf/click?upn=08onrYu34A-2BWcWUl-2F-2BfV0V05UPxvVjWch-2Bd2MGckcRakUl6QyjujEohY7rPpoYUEcf-2B75FkFkxwwFKGZV8c1xA-3D-3D_19DGMz38yO7VfzGQuXkecdlEmzBoDG4v8Dvyanv-2F1I2N7bq7wRoLn-2Bvutzi1vsk5P-2Fj2RSGdlol4eFkvK2Sb7BEOjlNRkbxksEOJq8sa9LPP-2BeWBdzxLxOUK3CyrFUdpeQ88hQpYUGei2L-2BJLrOJQtACTiOFyKi62GeV10mxQsR0pp7ez3KdIA1Ru8gupzoWsgJFlb7uVTJ-2BXUwocmc-2BzSt5-2B5Z2oKYA-2B95WxP1tJ-2BU-3D

Analysis Summary:
   New defects found: 0
   Defects eliminated: 0

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] FAILED build of OpenSSL branch OpenSSL_1_1_0-stable with options -d --strict-warnings enable-weak-ssl-ciphers

2017-09-04 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.4.0-77-generic #98-Ubuntu SMP Wed Apr 26 08:34:02 UTC 2017 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings enable-weak-ssl-ciphers

Commit log since last time:

90507fb Fix OpenSSL::Test::Utils::config to actualy load the config data

Build log ended with (last 100 lines):

../../openssl/test/recipes/05-test_hmac.t . ok
../../openssl/test/recipes/05-test_idea.t . ok
../../openssl/test/recipes/05-test_md2.t .. skipped: md2 is not 
supported by this OpenSSL build
../../openssl/test/recipes/05-test_md4.t .. ok
../../openssl/test/recipes/05-test_md5.t .. ok
../../openssl/test/recipes/05-test_mdc2.t . ok
../../openssl/test/recipes/05-test_rand.t . ok
../../openssl/test/recipes/05-test_rc2.t .. ok
../../openssl/test/recipes/05-test_rc4.t .. ok
../../openssl/test/recipes/05-test_rc5.t .. skipped: rc5 is not 
supported by this OpenSSL build
../../openssl/test/recipes/05-test_rmd.t .. ok
../../openssl/test/recipes/05-test_sha1.t . ok
../../openssl/test/recipes/05-test_sha256.t ... ok
../../openssl/test/recipes/05-test_sha512.t ... ok
../../openssl/test/recipes/05-test_wp.t ... ok
../../openssl/test/recipes/10-test_bn.t ... ok
../../openssl/test/recipes/10-test_exp.t .. ok
../../openssl/test/recipes/15-test_dh.t ... ok
../../openssl/test/recipes/15-test_dsa.t .. ok
../../openssl/test/recipes/15-test_ec.t ... ok
../../openssl/test/recipes/15-test_ecdsa.t  ok
../../openssl/test/recipes/15-test_genrsa.t ... ok
../../openssl/test/recipes/15-test_rsa.t .. ok
../../openssl/test/recipes/15-test_rsapss.t ... ok
../../openssl/test/recipes/20-test_enc.t .. ok
../../openssl/test/recipes/20-test_passwd.t ... ok
../../openssl/test/recipes/25-test_crl.t .. ok
../../openssl/test/recipes/25-test_d2i.t .. ok
../../openssl/test/recipes/25-test_pkcs7.t  ok
../../openssl/test/recipes/25-test_req.t .. ok
../../openssl/test/recipes/25-test_sid.t .. ok
../../openssl/test/recipes/25-test_verify.t ... ok
../../openssl/test/recipes/25-test_x509.t . ok
../../openssl/test/recipes/30-test_afalg.t  ok
../../openssl/test/recipes/30-test_engine.t ... ok
../../openssl/test/recipes/30-test_evp.t .. ok
../../openssl/test/recipes/30-test_evp_extra.t  ok
../../openssl/test/recipes/30-test_pbelu.t  ok
../../openssl/test/recipes/40-test_rehash.t ... ok
../../openssl/test/recipes/60-test_x509_store.t ... ok
../../openssl/test/recipes/70-test_asyncio.t .. ok
../../openssl/test/recipes/70-test_bad_dtls.t . ok
../../openssl/test/recipes/70-test_clienthello.t .. ok
../../openssl/test/recipes/70-test_packet.t ... ok
../../openssl/test/recipes/70-test_sslcbcpadding.t  skipped: Unable to 
start up Proxy for tests
../../openssl/test/recipes/70-test_sslcertstatus.t  skipped: Unable to 
start up Proxy for tests
../../openssl/test/recipes/70-test_sslextension.t . skipped: Unable to 
start up Proxy for tests
../../openssl/test/recipes/70-test_sslmessages.t .. skipped: Unable to 
start up Proxy for tests
../../openssl/test/recipes/70-test_sslrecords.t ... 
Dubious, test returned 1 (wstat 256, 0x100)
Failed 1/11 subtests 
../../openssl/test/recipes/70-test_sslsessiontick.t ... ok
../../openssl/test/recipes/70-test_sslskewith0p.t . ok
../../openssl/test/recipes/70-test_sslvertol.t  ok
../../openssl/test/recipes/70-test_tlsextms.t . ok
../../openssl/test/recipes/70-test_verify_extra.t . ok
../../openssl/test/recipes/80-test_ca.t ... ok
../../openssl/test/recipes/80-test_cipherlist.t ... ok
../../openssl/test/recipes/80-test_cms.t .. ok
../../openssl/test/recipes/80-test_ct.t ... ok
../../openssl/test/recipes/80-test_dane.t . ok
../../openssl/test/recipes/80-test_dtls.t . ok
../../openssl/test/recipes/80-test_dtlsv1listen.t . ok
../../openssl/test/recipes/80-test_ocsp.t . ok
../../openssl/test/recipes/80-test_pkcs12.t ... ok
../../openssl/test/recipes/80-test_ssl_new.t .. ok
../../openssl/test/recipes/80-test_ssl_old.t .. ok
../../openssl/test/recipes/80-test_ssl_test_ctx.t . ok
../../openssl/test/recipes/80-test_sslcorrupt.t ... ok
../../openssl/test/recipes/80-test_tsa.t .. ok
../../openssl/test/recipes/80-test_x509aux.t .. ok
../../openssl/test/recipes/90-test_async.t  ok
../../openssl/test/recipes/90-test_bio_enc.t .. ok
../../openssl/test/recipes/90-test_bioprint.t . ok

[openssl-commits] SUCCESSFUL build of OpenSSL branch OpenSSL_1_1_0-stable with options -d --strict-warnings no-aria

2017-09-04 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.4.0-77-generic #98-Ubuntu SMP Wed Apr 26 08:34:02 UTC 2017 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings no-aria

Commit log since last time:

90507fb Fix OpenSSL::Test::Utils::config to actualy load the config data
_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Build completed: openssl master.12945

2017-09-04 Thread AppVeyor


Build openssl master.12945 completed



Commit 1d2491e20e by Matt Caswell on 9/4/2017 2:15 PM:

Don't use ciphersuites for inflating the ClientHello in clienthellotest


Configure your notification preferences

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Still Failing: openssl/openssl#13665 (master - 1d2491e)

2017-09-04 Thread Travis CI
Build Update for openssl/openssl
-

Build: #13665
Status: Still Failing

Duration: 34 minutes and 37 seconds
Commit: 1d2491e (master)
Author: Matt Caswell
Message: Don't use ciphersuites for inflating the ClientHello in clienthellotest

clienthellotest tries to fill out the size of the ClientHello by adding
extra ciphersuites in order to test the padding extension. This is
unreliable because they are very dependent on configuration options. If we
add too much data the test will fail! We were already also adding some dummy
ALPN protocols to pad out the size, and it turns out that this is sufficient
just in itself, so drop the extra ciphersuites.

Reviewed-by: Paul Dale 
(Merged from https://github.com/openssl/openssl/pull/4331)

View the changeset: 
https://github.com/openssl/openssl/compare/45fd6a59faca...1d2491e20e14

View the full build log and details: 
https://travis-ci.org/openssl/openssl/builds/271710952?utm_source=email_medium=notification

--

You can configure recipients for build notifications in your .travis.yml file. 
See https://docs.travis-ci.com/user/notifications

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Build failed: openssl master.12944

2017-09-04 Thread AppVeyor



Build openssl master.12944 failed


Commit d3dd177a4c by Richard Levitte on 8/28/2017 2:08 PM:

Some of the team configs needed adapting


Configure your notification preferences

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Build completed: openssl master.12942

2017-09-04 Thread AppVeyor


Build openssl master.12942 completed



Commit 5262848d12 by Matt Caswell on 9/4/2017 10:20 AM:

Allow an endpoint to read the alert data before closing the socket


Configure your notification preferences

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] [openssl] master update

2017-09-04 Thread Matt Caswell
The branch master has been updated
   via  1d2491e20e1400def31eb1d1daea5583bfc7ea38 (commit)
   via  3d85c7f408e54e1a0b367901534139ba5f1cad07 (commit)
  from  45fd6a59facab8b8aa088f9f492f10aa5d2581c2 (commit)


- Log -
commit 1d2491e20e1400def31eb1d1daea5583bfc7ea38
Author: Matt Caswell 
Date:   Mon Sep 4 08:45:12 2017 +0100

Don't use ciphersuites for inflating the ClientHello in clienthellotest

clienthellotest tries to fill out the size of the ClientHello by adding
extra ciphersuites in order to test the padding extension. This is
unreliable because they are very dependent on configuration options. If we
add too much data the test will fail! We were already also adding some dummy
ALPN protocols to pad out the size, and it turns out that this is sufficient
just in itself, so drop the extra ciphersuites.

Reviewed-by: Paul Dale 
(Merged from https://github.com/openssl/openssl/pull/4331)

commit 3d85c7f408e54e1a0b367901534139ba5f1cad07
Author: Matt Caswell 
Date:   Mon Sep 4 08:44:02 2017 +0100

Don't attempt to add a zero length padding extension

The padding extension should always be at least 1 byte long

Reviewed-by: Paul Dale 
(Merged from https://github.com/openssl/openssl/pull/4331)

---

Summary of changes:
 ssl/statem/extensions_clnt.c |  2 +-
 test/clienthellotest.c   | 12 +---
 2 files changed, 6 insertions(+), 8 deletions(-)

diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c
index 2c72dea..bffe7ac 100644
--- a/ssl/statem/extensions_clnt.c
+++ b/ssl/statem/extensions_clnt.c
@@ -843,7 +843,7 @@ EXT_RETURN tls_construct_ctos_padding(SSL *s, WPACKET *pkt,
  * 1 byte long so as not to have an empty extension last (WebSphere 
7.x,
  * 8.x are intolerant of that condition)
  */
-if (hlen >= 4)
+if (hlen > 4)
 hlen -= 4;
 else
 hlen = 1;
diff --git a/test/clienthellotest.c b/test/clienthellotest.c
index fbac8ea..ee2d0ba 100644
--- a/test/clienthellotest.c
+++ b/test/clienthellotest.c
@@ -90,16 +90,14 @@ static int test_client_hello(int currtest)
 case TEST_PADDING_NOT_NEEDED:
 SSL_CTX_set_options(ctx, SSL_OP_TLSEXT_PADDING);
 /*
- * Add lots of ciphersuites so that the ClientHello is at least
+ * Add some dummy ALPN protocols so that the ClientHello is at least
  * F5_WORKAROUND_MIN_MSG_LEN bytes long - meaning padding will be
- * needed. Also add some dummy ALPN protocols in case we still don't
- * have enough.
+ * needed.
  */
 if (currtest == TEST_ADD_PADDING
-&& (!TEST_true(SSL_CTX_set_cipher_list(ctx, "ALL"))
-|| !TEST_false(SSL_CTX_set_alpn_protos(ctx,
-   (unsigned char *)alpn_prots,
-   sizeof(alpn_prots) - 1
+&& (!TEST_false(SSL_CTX_set_alpn_protos(ctx,
+(unsigned char *)alpn_prots,
+sizeof(alpn_prots) - 1
 goto end;
 
 break;
_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Build failed: openssl master.12941

2017-09-04 Thread AppVeyor



Build openssl master.12941 failed


Commit 3c5de4418d by Richard Levitte on 9/4/2017 1:42 PM:

Add a recursive option to 'openssl storeutl'


Configure your notification preferences

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] SUCCESSFUL build of OpenSSL branch master with options -d --strict-warnings no-ui

2017-09-04 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.4.0-77-generic #98-Ubuntu SMP Wed Apr 26 08:34:02 UTC 2017 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings no-ui

Commit log since last time:

79120f4 OSSL_STORE: Avoid testing with URIs on the mingw command line
02eca5c Fix doc-nits from previous commit
8a4460c config: get "stty technique" working again on MacOS X.
26810b5 test/run_tests.pl: don't use Module::Load::Conditional.
b3696a5 Less documentation for deprecated API
607f4d5 Fix OpenSSL::Test::Utils::config to actualy load the config data
c4604e9 Fix long SNI lengths in test/handshake_helper.c
de0dc00 Fixup include path in ossl_shim test after e_os.h work
e65dfa4 Tighten up SSL_get1_supported_ciphers() docs
4130016 Fix Proxy where a timeout occurs waiting for both client and server
6e5a853 crypto/cryptlib.c: mask more capability bits upon FXSR bit flip.
89bc9cf ssl/statem/extensions_clnt.c: fix return code buglet.
eb5fd03 ssl/statem/*.c: address "enum mixed with another type" warnings.
4cff10d struct timeval include guards
75551e0 Address feedback
ed6b2c7 Add CRYPTO_thread_glock_new
3907872 Fix potential null problem.
ccb7668 Avoid possible uninitialized variable.
_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Broken: openssl/openssl#13659 (master - 45fd6a5)

2017-09-04 Thread Travis CI
Build Update for openssl/openssl
-

Build: #13659
Status: Broken

Duration: 27 minutes and 20 seconds
Commit: 45fd6a5 (master)
Author: Richard Levitte
Message: Fix 90-test_store.t: using config() requires OpenSSL::Test::Utils

Reviewed-by: Matt Caswell 
(Merged from https://github.com/openssl/openssl/pull/4332)

View the changeset: 
https://github.com/openssl/openssl/compare/21c7942140ff...45fd6a59faca

View the full build log and details: 
https://travis-ci.org/openssl/openssl/builds/271638994?utm_source=email_medium=notification

--

You can configure recipients for build notifications in your .travis.yml file. 
See https://docs.travis-ci.com/user/notifications

_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] [openssl] master update

2017-09-04 Thread Richard Levitte
The branch master has been updated
   via  45fd6a59facab8b8aa088f9f492f10aa5d2581c2 (commit)
  from  21c7942140ff6e57cfcbf1afc9da8d8a8817ed2f (commit)


- Log -
commit 45fd6a59facab8b8aa088f9f492f10aa5d2581c2
Author: Richard Levitte 
Date:   Mon Sep 4 12:47:12 2017 +0200

Fix 90-test_store.t: using config() requires OpenSSL::Test::Utils

Reviewed-by: Matt Caswell 
(Merged from https://github.com/openssl/openssl/pull/4332)

---

Summary of changes:
 test/recipes/90-test_store.t | 1 +
 1 file changed, 1 insertion(+)

diff --git a/test/recipes/90-test_store.t b/test/recipes/90-test_store.t
index 9c240a0..7a5433b 100644
--- a/test/recipes/90-test_store.t
+++ b/test/recipes/90-test_store.t
@@ -10,6 +10,7 @@ use File::Spec;
 use File::Copy;
 use MIME::Base64;
 use OpenSSL::Test qw(:DEFAULT srctop_file srctop_dir bldtop_file data_file);
+use OpenSSL::Test::Utils;
 
 my $test_name = "test_store";
 setup($test_name);
_
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits


[openssl-commits] Build failed in Jenkins: master_aarch64 #138

2017-09-04 Thread osslsanity
See 


Changes:

[levitte] OSSL_STORE: Avoid testing with URIs on the mingw command line

[paul.dale] Fix an include location problem in the extrended tests. [extended 
tests]

--
Started by upstream project "1_0_2_basic" build number 143
originally caused by:
 Started by timer
Building in workspace 

 > git rev-parse --is-inside-work-tree # timeout=10
Fetching changes from the remote Git repository
 > git config remote.origin.url https://github.com/openssl/openssl.git # 
 > timeout=10
Fetching upstream changes from https://github.com/openssl/openssl.git
 > git --version # timeout=10
 > git fetch --tags --progress https://github.com/openssl/openssl.git 
 > +refs/heads/*:refs/remotes/origin/*
 > git rev-parse refs/remotes/origin/master^{commit} # timeout=10
 > git rev-parse refs/remotes/origin/origin/master^{commit} # timeout=10
Checking out Revision 21c7942140ff6e57cfcbf1afc9da8d8a8817ed2f 
(refs/remotes/origin/master)
 > git config core.sparsecheckout # timeout=10
 > git checkout -f 21c7942140ff6e57cfcbf1afc9da8d8a8817ed2f
 > git rev-list 02eca5c640ced75805ff576c4845b33b77e4753a # timeout=10
[master_aarch64] $ /bin/sh -xe /tmp/jenkins1182342636898242296.sh
+ export 
PATH=/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games:/usr/local/buildroot-2017.02/output/host/usr/bin/
+ export CROSS_COMPILE=aarch64-linux-
+ ./Configure linux-aarch64
Using implicit seed configuration
Configuring OpenSSL version 1.1.1-dev (0x10101000L)
for linux-aarch64
no-aria [default]  OPENSSL_NO_ARIA (skip dir)
no-asan [default]  OPENSSL_NO_ASAN
no-crypto-mdebug [default]  OPENSSL_NO_CRYPTO_MDEBUG
no-crypto-mdebug-backtrace [default]  OPENSSL_NO_CRYPTO_MDEBUG_BACKTRACE
no-devcryptoeng [default]  OPENSSL_NO_DEVCRYPTOENG
no-ec_nistp_64_gcc_128 [default]  OPENSSL_NO_EC_NISTP_64_GCC_128
no-egd  [default]  OPENSSL_NO_EGD
no-external-tests [default]  OPENSSL_NO_EXTERNAL_TESTS
no-fuzz-afl [default]  OPENSSL_NO_FUZZ_AFL
no-fuzz-libfuzzer [default]  OPENSSL_NO_FUZZ_LIBFUZZER
no-heartbeats   [default]  OPENSSL_NO_HEARTBEATS
no-md2  [default]  OPENSSL_NO_MD2 (skip dir)
no-msan [default]  OPENSSL_NO_MSAN
no-rc5  [default]  OPENSSL_NO_RC5 (skip dir)
no-sctp [default]  OPENSSL_NO_SCTP
no-ssl-trace[default]  OPENSSL_NO_SSL_TRACE
no-ssl3 [default]  OPENSSL_NO_SSL3
no-ssl3-method  [default]  OPENSSL_NO_SSL3_METHOD
no-tls13downgrade [default]  OPENSSL_NO_TLS13DOWNGRADE
no-tls1_3   [default]  OPENSSL_NO_TLS1_3
no-ubsan[default]  OPENSSL_NO_UBSAN
no-unit-test[default]  OPENSSL_NO_UNIT_TEST
no-weak-ssl-ciphers [default]  OPENSSL_NO_WEAK_SSL_CIPHERS
no-zlib [default] 
no-zlib-dynamic [default] 

PERL  =/usr/bin/perl
PERLVERSION   =5.18.2 for x86_64-linux-gnu-thread-multi
HASHBANGPERL  =/usr/bin/env perl
CC=aarch64-linux-gcc
CFLAG =-Wall -O3 -pthread 
CXX   =aarch64-linux-g++
CXXFLAG   =-Wall -O3 -pthread 
DEFINES   =DSO_DLFCN HAVE_DLFCN_H NDEBUG OPENSSL_THREADS 
OPENSSL_NO_STATIC_ENGINE OPENSSL_PIC OPENSSL_BN_ASM_MONT SHA1_ASM SHA256_ASM 
SHA512_ASM VPAES_ASM ECP_NISTZ256_ASM POLY1305_ASM
EX_LIBS   =-ldl 
+ make depend
+ make clean
rm -f libcrypto.so.1.1
rm -f libcrypto.so
rm -f libssl.so.1.1
rm -f libssl.so
rm -f
rm -f libcrypto.a libssl.a test/libtestutil.a
rm -f *.map
rm -f apps/openssl fuzz/asn1-test fuzz/asn1parse-test fuzz/bignum-test 
fuzz/bndiv-test fuzz/client-test fuzz/cms-test fuzz/conf-test fuzz/crl-test 
fuzz/ct-test fuzz/server-test fuzz/x509-test test/aborttest test/afalgtest 
test/asn1_encode_test test/asn1_internal_test test/asn1_string_table_test 
test/asn1_time_test test/asynciotest test/asynctest test/bad_dtls_test 
test/bftest test/bio_enc_test test/bioprinttest test/bntest test/buildtest_aes 
test/buildtest_asn1 test/buildtest_asn1err test/buildtest_asn1t 
test/buildtest_async test/buildtest_asyncerr test/buildtest_bio 
test/buildtest_bioerr test/buildtest_blowfish test/buildtest_bn 
test/buildtest_bnerr test/buildtest_buffer test/buildtest_buffererr 
test/buildtest_camellia test/buildtest_cast test/buildtest_cmac 
test/buildtest_cms test/buildtest_cmserr test/buildtest_comp 
test/buildtest_comperr test/buildtest_conf test/buildtest_conf_api 
test/buildtest_conferr test/buildtest_crypto test/buildtest_cryptoerr 
test/buildtest_ct test/buildte
 st_cterr test/buildtest_des test/buildtest_dh test/buildtest_dherr 
test/buildtest_dsa test/buildtest_dsaerr test/buildtest_dtls1 
test/buildtest_e_os2 test/buildtest_ebcdic test/buildtest_ec 
test/buildtest_ecdh test/buildtest_ecdsa test/buildtest_ecerr 
test/buildtest_engine test/buildtest_engineerr