| Message ID | 20250922204329.23460-1-gert@greenie.muc.de |
|---|---|
| State | Accepted |
| Headers | show |
| Series | [Openvpn-devel,v9] ssl_verify: Change backend_x509_* functions to size_t for lengths | expand |
Stared at code, very straightforward - matches callers and callees.
Not tested myself, relying on BB coverage.
Your patch has been applied to the master branch.
commit 38f2cedc60258d0dcb340873faa12e1de594e3c8
Author: Frank Lichtenheld
Date: Mon Sep 22 22:43:23 2025 +0200
ssl_verify: Change backend_x509_* functions to size_t for lengths
Signed-off-by: Frank Lichtenheld <frank@lichtenheld.com>
Acked-by: Gert Doering <gert@greenie.muc.de>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1138
Message-Id: <20250922204329.23460-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg33152.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/ssl_verify_backend.h b/src/openvpn/ssl_verify_backend.h index a0559c9..c6ab9dd 100644 --- a/src/openvpn/ssl_verify_backend.h +++ b/src/openvpn/ssl_verify_backend.h @@ -123,7 +123,7 @@ * * @return \c FAILURE, \c or SUCCESS */ -result_t backend_x509_get_username(char *common_name, int cn_len, char *x509_username_field, +result_t backend_x509_get_username(char *common_name, size_t cn_len, char *x509_username_field, openvpn_x509_cert_t *peer_cert); #ifdef ENABLE_X509ALTUSERNAME diff --git a/src/openvpn/ssl_verify_mbedtls.c b/src/openvpn/ssl_verify_mbedtls.c index cfcfb25..986c7da 100644 --- a/src/openvpn/ssl_verify_mbedtls.c +++ b/src/openvpn/ssl_verify_mbedtls.c @@ -128,7 +128,7 @@ #endif result_t -backend_x509_get_username(char *cn, int cn_len, char *x509_username_field, mbedtls_x509_crt *cert) +backend_x509_get_username(char *cn, size_t cn_len, char *x509_username_field, mbedtls_x509_crt *cert) { mbedtls_x509_name *name; diff --git a/src/openvpn/ssl_verify_openssl.c b/src/openvpn/ssl_verify_openssl.c index b79b09b..5bbd72c 100644 --- a/src/openvpn/ssl_verify_openssl.c +++ b/src/openvpn/ssl_verify_openssl.c @@ -120,7 +120,7 @@ } static bool -extract_x509_extension(X509 *cert, char *fieldname, char *out, int size) +extract_x509_extension(X509 *cert, char *fieldname, char *out, size_t size) { bool retval = false; char *buf = 0; @@ -195,7 +195,7 @@ * to contain result is grounds for error). */ static result_t -extract_x509_field_ssl(X509_NAME *x509, const char *field_name, char *out, int size) +extract_x509_field_ssl(X509_NAME *x509, const char *field_name, char *out, size_t size) { int lastpos = -1; int tmp = -1; @@ -252,7 +252,7 @@ } result_t -backend_x509_get_username(char *common_name, int cn_len, char *x509_username_field, X509 *peer_cert) +backend_x509_get_username(char *common_name, size_t cn_len, char *x509_username_field, X509 *peer_cert) { #ifdef ENABLE_X509ALTUSERNAME if (strncmp("ext:", x509_username_field, 4) == 0)