Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | pem: Use chunk_map() instead of non-portable mmap() | Martin Willi | 2014-01-23 | 1 | -29/+6 | |
| | ||||||
* | integrity-checker: Use chunk_map() instead of non-portable mmap() | Martin Willi | 2014-01-23 | 1 | -31/+6 | |
| | ||||||
* | chunk: Externalize error reporting in chunk_write() | Martin Willi | 2014-01-23 | 3 | -13/+11 | |
| | | | | | This avoids passing that arbitrary label just for error messages, and gives greater flexibility in handling errors. | |||||
* | chunk: Provide a fallback chunk_map() if mmap is not available | Martin Willi | 2014-01-23 | 1 | -1/+46 | |
| | ||||||
* | chunk: Use dynamically allocated buffer in chunk_from_fd() | Martin Willi | 2014-01-23 | 3 | -14/+130 | |
| | | | | | | | | When acting on files, we can use fstat() to estimate the buffer size. On non-file FDs, we dynamically increase an allocated buffer. Additionally we slightly change the function signature to properly handle zero-length files and add appropriate unit tests. | |||||
* | chunk: Add functions to map file contents to a chunk | Martin Willi | 2014-01-23 | 3 | -1/+149 | |
| | ||||||
* | curl: Replace spaces in URIs with %20 | Tobias Brunner | 2014-01-23 | 1 | -3/+14 | |
| | | | | | | | cURL requires the URIs to be URL-encoded. Apparently, some CAs encode CRL URIs with spaces in them. Fixes #454. | |||||
* | utils: Add strreplace function | Tobias Brunner | 2014-01-23 | 3 | -2/+155 | |
| | ||||||
* | agent: Keep CAP_DAC_OVERRIDE to connect to ssh-agent socket | Tobias Brunner | 2014-01-23 | 3 | -2/+10 | |
| | | | | This is also required if charon-cmd is used with capability dropping. | |||||
* | unit-tests: Pass a test suite collection name to print during test execution | Martin Willi | 2014-01-22 | 3 | -8/+11 | |
| | | | | | As we except to get more and more test runners for the different components, we add a name to easily identify them on the test output. | |||||
* | array: Add an array_get() function | Martin Willi | 2014-01-22 | 3 | -3/+44 | |
| | ||||||
* | watcher: Don't complain if select() syscall got interrupted | Martin Willi | 2014-01-22 | 1 | -1/+1 | |
| | ||||||
* | stream: Make sure no watcher callback is active while changing stream callbacks | Martin Willi | 2014-01-22 | 1 | -14/+3 | |
| | | | | | | | | | | | When changing async callbacks on streams, we have to make sure the watcher callback is not currently active and has temporarily disabled callbacks. This could have been the case, as we didn't explicitly removed any pending watcher registration if both callbacks are NULL. By enforcing the watcher unregistration, we are sure the watcher callback is not active and currently is not mangling the callback hooks. This should make sure we avoid any races for the callback variables. | |||||
* | proposal: Add possibility to register custom proposal keyword parser | Thomas Egerer | 2014-01-20 | 2 | -2/+66 | |
| | | | | | | | | | If a proposal string cannot be matched to a token using strcmp (e.g. if you want to register a whole class of algorithms containing their ID, like my_alg_2342), you can use the provided function to register a parser that transforms the given string into a proposal token. Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | unit-tests: Add environment variable to reduce the number of generated keys | Tobias Brunner | 2014-01-20 | 2 | -2/+14 | |
| | | | | | | | If TESTS_REDUCED_KEYLENGTHS is set RSA and ECDSA keys are only generated for the lowest configured key length. Fixes #474. | |||||
* | unit-tests: Generate RSA key with 768 bits not 786 | Tobias Brunner | 2014-01-20 | 1 | -1/+1 | |
| | ||||||
* | printf-hook-builtin: Correctly calculate written bytes in print_in_hook() | Martin Willi | 2014-01-15 | 1 | -3/+7 | |
| | | | | | | | | | | The hook data counts remaining buffer bytes, not used ones. Counting them correctly fixes a crash for long hexdumps. Further, print_in_hook() must return the number of bytes that would have been written, not the actually written bytes. This is important, as we allocate a dynamic buffer in bus that relies on the exact byte count. Fixes long hexdumps that got truncated. | |||||
* | test-asn1: Fix skipping of >2038 tests on i386 | Tobias Brunner | 2014-01-06 | 1 | -35/+35 | |
| | | | | | | | | The two constants overflow time_t on i386 (they also produced a compiler warning without type suffix) so the comparison with TIME_32_BIT_SIGNED_MAX did not work as intended. Fixes #477. | |||||
* | chunk: Fix chunk_mac/hash tests on big-endian systems | Tobias Brunner | 2014-01-06 | 1 | -2/+27 | |
| | | | | | | | | Our SipHash-2-4 implementation returns the result in host order, while the test vectors are little-endian. Use a custom comparison function to account for this. Fixes #478. | |||||
* | utils: Fix %T printf hook on big-endian systems | Tobias Brunner | 2014-01-06 | 1 | -1/+1 | |
| | | | | | | | | The cast to a bool* cut of the actual value on big-endian systems if bool was shorter than int because the bool argument to printf gets promoted to an int. Fixes #479. | |||||
* | tun-device: Include system headers before our own | Tobias Brunner | 2013-12-20 | 2 | -3/+5 | |
| | | | | | | | | | | | | | On CentOS 6.5 the sys/capability.h header file defines _LINUX_TYPES_H without actually including that header, preventing its later inclusion here. As library.h (via which the capabilities headers are included) is not actually required in tun_device.[ch], moving the inclusion of tun_device.h would not strictly be necessary. But it's probably a good idea to include our own headers after system headers anyway, for if one of the recursively included files at a later point includes library.h we'd have the same problem again. | |||||
* | unit-tests: NTRU test to check a special branch | Andreas Steffen | 2013-12-08 | 1 | -0/+7 | |
| | ||||||
* | min_MGF_hash_calls parameter is not needed anymore | Andreas Steffen | 2013-12-07 | 2 | -18/+0 | |
| | ||||||
* | Optimized MGF1 implementation | Andreas Steffen | 2013-12-07 | 1 | -8/+13 | |
| | ||||||
* | Implemented ntru_trits class | Andreas Steffen | 2013-12-07 | 9 | -293/+383 | |
| | ||||||
* | Streamlined DRBG and MGF1 debug output | Andreas Steffen | 2013-12-07 | 3 | -14/+20 | |
| | ||||||
* | unit-tests: Added crypter tests | Andreas Steffen | 2013-12-06 | 4 | -3/+112 | |
| | ||||||
* | Added own MGF1 mask generating function | Andreas Steffen | 2013-12-05 | 11 | -436/+707 | |
| | ||||||
* | unit-tests: Added hasher tests | Andreas Steffen | 2013-12-04 | 3 | -0/+191 | |
| | ||||||
* | Moved test_rng to a test suite of its own | Andreas Steffen | 2013-12-04 | 4 | -26/+58 | |
| | ||||||
* | unit-tests: Don't use priority for destructor that unregisters testable ↵ | Tobias Brunner | 2013-12-04 | 1 | -1/+6 | |
| | | | | | | | | | functions This fixes coverage reports, at least if leak detective is disabled. If it is enabled the plugins are not unloaded so the destructor is not executed until the process is destroyed, which seems not to be covered by gcov. | |||||
* | unit-tests: Export ntru_drbg_create as testable function so no linking is ↵ | Tobias Brunner | 2013-12-04 | 3 | -6/+11 | |
| | | | | | | | | required This way the plugin does not have to be linked explicitly to the test runner, which otherwise would require that the plugin is either always enabled to build the tests or that ifdefs are added to the Makefile. | |||||
* | unit-tests: Add facility to register testable functions | Tobias Brunner | 2013-12-04 | 5 | -3/+169 | |
| | | | | | These can be defined in plugins, or other parts of the tested libraries. They can even be static. | |||||
* | unit-tests: Move ntru_test_rng_t to a utility class in libtest | Tobias Brunner | 2013-12-04 | 6 | -48/+37 | |
| | ||||||
* | unit-tests: Fix apidoc for libtest | Tobias Brunner | 2013-12-04 | 2 | -8/+23 | |
| | ||||||
* | ntru: Fix compiler warning caused by ++/-- on righthand side of an assignment | Tobias Brunner | 2013-12-04 | 1 | -4/+4 | |
| | | | | The behavior of stuff like x = --x; (or x++) is not defined. | |||||
* | Added DRBG automatic reseeding tests | Andreas Steffen | 2013-11-27 | 2 | -170/+216 | |
| | ||||||
* | Use strongSwan hash plugins for SHA-1 and SHA-256 | Andreas Steffen | 2013-11-27 | 20 | -2764/+178 | |
| | ||||||
* | Extended NIST SP 800-90A HMAC_DRBG test cases | Andreas Steffen | 2013-11-27 | 1 | -21/+103 | |
| | ||||||
* | Cleaned up ntru-crypto library | Andreas Steffen | 2013-11-27 | 11 | -474/+8 | |
| | ||||||
* | Implemented NIST SP 800-90A DRBG_HMAC with SHA-256 | Andreas Steffen | 2013-11-27 | 16 | -1541/+697 | |
| | ||||||
* | unit-tests: Added ntru wrong ciphertext test | Andreas Steffen | 2013-11-27 | 2 | -0/+37 | |
| | ||||||
* | unit-tests: Added ntru entropy, retransmission and ciphertext tests | Andreas Steffen | 2013-11-27 | 3 | -0/+69 | |
| | ||||||
* | Any of the four NTRU parameter sets can be selected | Andreas Steffen | 2013-11-27 | 3 | -55/+130 | |
| | ||||||
* | Make the NTRU parameter set configurable | Andreas Steffen | 2013-11-27 | 2 | -40/+110 | |
| | ||||||
* | unit-tests: first NTRU test case | Andreas Steffen | 2013-11-27 | 4 | -2/+95 | |
| | ||||||
* | Prototype implementation of IKE key exchange via NTRU encryption | Andreas Steffen | 2013-11-27 | 40 | -3/+9380 | |
| | ||||||
* | chunk: Fix signedness warnings caused by chunk_from_* macros | Tobias Brunner | 2013-11-27 | 1 | -3/+3 | |
| | | | | | | There are countless other such warnings because e.g. chunk_create() is called with char*, but at least we prevent users from causing such warnings inadvertently when using these macros. | |||||
* | tun-device: Include <linux/types.h> before <linux/if_tun.h> | Martin Willi | 2013-11-22 | 1 | -0/+1 | |
| | | | | Fixes a build error on CentOS 6.4. | |||||
* | printf-hook-builtin: Don't use %P to print uppercase hex pointers | Martin Willi | 2013-11-20 | 1 | -6/+0 | |
| | | | | We use %P as custom printf specifier for proposals. |