Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ Add new entries under `Unreleased`; published release sections are history.

## Unreleased

- TLS rejects certificates with empty version, public-key or signature fields,
and correctly parses certificates containing unique identifiers.
- TLS rejects HelloRetryRequest cookies and ClientHello messages that do not
fit their buffers, and reports failed key-share construction.
- TLS 1.3 handshake builder failures preserve the original error and release
Expand Down
15 changes: 15 additions & 0 deletions tests/x509/CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -158,3 +158,18 @@ target_link_libraries(test_clienthello_lists PRIVATE
target_compile_options(test_clienthello_lists PRIVATE -Wall -Wextra -UAMINETXDUO_IPV6)

add_test(NAME tls_clienthello_lists COMMAND test_clienthello_lists)

# N-128, N-129, N-130, E-234: the X.509 certificate parser on re-encoded
# certificates (unique IDs inserted, an empty EC key, signature or version),
# the same guard-region contract, plus the exact consumed count.
add_executable(test_x509_field_bounds
test_x509_field_bounds.c
"${CMAKE_SOURCE_DIR}/tests/fuzz/fuzz_nxstub.c"
"${CMAKE_SOURCE_DIR}/tests/fuzz/fuzz_txstub.c")

target_link_libraries(test_x509_field_bounds PRIVATE
test_x509_nx_secure test_x509_nx_crypto)

target_compile_options(test_x509_field_bounds PRIVATE -Wall -Wextra -UAMINETXDUO_IPV6)

add_test(NAME tls_x509_field_bounds COMMAND test_x509_field_bounds)
Loading
Loading