From 21926d584a5b118cbff81a9fb4329059011f87c6 Mon Sep 17 00:00:00 2001 From: Haibo Huang Date: Tue, 8 Jan 2019 14:27:10 -0800 Subject: Upgrade curl from 7.62.0 to 7.63.0 Test: build, boots, `vendor/google/tools/fake-ota on streaming` works Change-Id: Iecd6120501e7a6d2c8b83c2891de62163a30f08a --- Android.bp | 193 +- CHANGES | 10184 ++++++++++--------- CMake/FindGSS.cmake | 4 +- CMakeLists.txt | 6 +- METADATA | 10 +- RELEASE-NOTES | 430 +- androidconfigure | 10 +- configure | 145 +- configure.ac | 88 +- docs/CHECKSRC.md | 42 +- docs/DEPRECATE.md | 26 - docs/FAQ | 2 +- docs/FEATURES | 6 +- docs/HISTORY.md | 51 + docs/HTTP2.md | 4 +- docs/INSTALL.md | 3 +- docs/INTERNALS.md | 1 - docs/KNOWN_BUGS | 27 +- docs/LICENSE-MIXING.md | 4 - docs/SECURITY-PROCESS.md | 22 +- docs/THANKS | 21 + docs/TODO | 33 +- docs/cmdline-opts/gen.pl | 2 +- docs/cmdline-opts/netrc-file.d | 2 +- docs/cmdline-opts/write-out.d | 12 + docs/curl-config.1 | 2 +- docs/curl.1 | 16 +- docs/examples/Makefile.am | 2 +- docs/examples/Makefile.inc | 3 +- docs/examples/Makefile.netware | 19 - docs/examples/ephiperfifo.c | 12 +- docs/examples/urlapi.c | 72 + docs/libcurl/curl_easy_cleanup.3 | 2 +- docs/libcurl/curl_easy_duphandle.3 | 2 +- docs/libcurl/curl_easy_escape.3 | 2 +- docs/libcurl/curl_easy_getinfo.3 | 2 +- docs/libcurl/curl_easy_init.3 | 2 +- docs/libcurl/curl_easy_pause.3 | 2 +- docs/libcurl/curl_easy_perform.3 | 2 +- docs/libcurl/curl_easy_recv.3 | 2 +- docs/libcurl/curl_easy_reset.3 | 2 +- docs/libcurl/curl_easy_send.3 | 2 +- docs/libcurl/curl_easy_setopt.3 | 4 +- docs/libcurl/curl_easy_strerror.3 | 2 +- docs/libcurl/curl_easy_unescape.3 | 2 +- docs/libcurl/curl_escape.3 | 2 +- docs/libcurl/curl_formadd.3 | 5 +- docs/libcurl/curl_formfree.3 | 2 +- docs/libcurl/curl_formget.3 | 2 +- docs/libcurl/curl_free.3 | 2 +- docs/libcurl/curl_getdate.3 | 2 +- docs/libcurl/curl_getenv.3 | 2 +- docs/libcurl/curl_global_cleanup.3 | 2 +- docs/libcurl/curl_global_init.3 | 2 +- docs/libcurl/curl_global_init_mem.3 | 2 +- docs/libcurl/curl_global_sslset.3 | 4 +- docs/libcurl/curl_mime_addpart.3 | 2 +- docs/libcurl/curl_mime_data.3 | 2 +- docs/libcurl/curl_mime_data_cb.3 | 2 +- docs/libcurl/curl_mime_encoder.3 | 2 +- docs/libcurl/curl_mime_filedata.3 | 2 +- docs/libcurl/curl_mime_filename.3 | 2 +- docs/libcurl/curl_mime_free.3 | 2 +- docs/libcurl/curl_mime_headers.3 | 2 +- docs/libcurl/curl_mime_init.3 | 2 +- docs/libcurl/curl_mime_name.3 | 2 +- docs/libcurl/curl_mime_subparts.3 | 2 +- docs/libcurl/curl_mime_type.3 | 2 +- docs/libcurl/curl_mprintf.3 | 2 +- docs/libcurl/curl_multi_add_handle.3 | 2 +- docs/libcurl/curl_multi_assign.3 | 2 +- docs/libcurl/curl_multi_cleanup.3 | 2 +- docs/libcurl/curl_multi_fdset.3 | 2 +- docs/libcurl/curl_multi_info_read.3 | 2 +- docs/libcurl/curl_multi_init.3 | 2 +- docs/libcurl/curl_multi_perform.3 | 2 +- docs/libcurl/curl_multi_remove_handle.3 | 2 +- docs/libcurl/curl_multi_setopt.3 | 2 +- docs/libcurl/curl_multi_socket.3 | 2 +- docs/libcurl/curl_multi_socket_action.3 | 2 +- docs/libcurl/curl_multi_strerror.3 | 2 +- docs/libcurl/curl_multi_timeout.3 | 2 +- docs/libcurl/curl_multi_wait.3 | 2 +- docs/libcurl/curl_share_cleanup.3 | 2 +- docs/libcurl/curl_share_init.3 | 2 +- docs/libcurl/curl_share_setopt.3 | 2 +- docs/libcurl/curl_share_strerror.3 | 2 +- docs/libcurl/curl_slist_append.3 | 2 +- docs/libcurl/curl_slist_free_all.3 | 2 +- docs/libcurl/curl_strequal.3 | 2 +- docs/libcurl/curl_unescape.3 | 2 +- docs/libcurl/curl_url.3 | 2 +- docs/libcurl/curl_url_cleanup.3 | 2 +- docs/libcurl/curl_url_dup.3 | 2 +- docs/libcurl/curl_url_get.3 | 2 +- docs/libcurl/curl_url_set.3 | 13 +- docs/libcurl/curl_version.3 | 2 +- docs/libcurl/curl_version_info.3 | 2 +- docs/libcurl/libcurl-easy.3 | 2 +- docs/libcurl/libcurl-env.3 | 2 +- docs/libcurl/libcurl-errors.3 | 10 +- docs/libcurl/libcurl-multi.3 | 2 +- docs/libcurl/libcurl-security.3 | 2 +- docs/libcurl/libcurl-share.3 | 2 +- docs/libcurl/libcurl-symbols.3 | 69 +- docs/libcurl/libcurl-thread.3 | 4 +- docs/libcurl/libcurl-tutorial.3 | 2 +- docs/libcurl/libcurl-url.3 | 2 +- docs/libcurl/libcurl.3 | 2 +- docs/libcurl/opts/CURLINFO_ACTIVESOCKET.3 | 2 +- docs/libcurl/opts/CURLINFO_APPCONNECT_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_APPCONNECT_TIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_CERTINFO.3 | 6 +- docs/libcurl/opts/CURLINFO_CONDITION_UNMET.3 | 2 +- docs/libcurl/opts/CURLINFO_CONNECT_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_CONNECT_TIME_T.3 | 2 +- .../opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD.3 | 2 +- .../opts/CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_CONTENT_LENGTH_UPLOAD.3 | 2 +- .../opts/CURLINFO_CONTENT_LENGTH_UPLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_CONTENT_TYPE.3 | 2 +- docs/libcurl/opts/CURLINFO_COOKIELIST.3 | 2 +- docs/libcurl/opts/CURLINFO_EFFECTIVE_URL.3 | 2 +- docs/libcurl/opts/CURLINFO_FILETIME.3 | 2 +- docs/libcurl/opts/CURLINFO_FILETIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_FTP_ENTRY_PATH.3 | 2 +- docs/libcurl/opts/CURLINFO_HEADER_SIZE.3 | 2 +- docs/libcurl/opts/CURLINFO_HTTPAUTH_AVAIL.3 | 2 +- docs/libcurl/opts/CURLINFO_HTTP_CONNECTCODE.3 | 2 +- docs/libcurl/opts/CURLINFO_HTTP_VERSION.3 | 2 +- docs/libcurl/opts/CURLINFO_LASTSOCKET.3 | 2 +- docs/libcurl/opts/CURLINFO_LOCAL_IP.3 | 2 +- docs/libcurl/opts/CURLINFO_LOCAL_PORT.3 | 2 +- docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_NAMELOOKUP_TIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_NUM_CONNECTS.3 | 2 +- docs/libcurl/opts/CURLINFO_OS_ERRNO.3 | 4 +- docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_PRETRANSFER_TIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_PRIMARY_IP.3 | 2 +- docs/libcurl/opts/CURLINFO_PRIMARY_PORT.3 | 2 +- docs/libcurl/opts/CURLINFO_PRIVATE.3 | 2 +- docs/libcurl/opts/CURLINFO_PROTOCOL.3 | 2 +- docs/libcurl/opts/CURLINFO_PROXYAUTH_AVAIL.3 | 2 +- .../libcurl/opts/CURLINFO_PROXY_SSL_VERIFYRESULT.3 | 2 +- docs/libcurl/opts/CURLINFO_REDIRECT_COUNT.3 | 2 +- docs/libcurl/opts/CURLINFO_REDIRECT_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_REDIRECT_TIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_REDIRECT_URL.3 | 2 +- docs/libcurl/opts/CURLINFO_REQUEST_SIZE.3 | 2 +- docs/libcurl/opts/CURLINFO_RESPONSE_CODE.3 | 2 +- docs/libcurl/opts/CURLINFO_RTSP_CLIENT_CSEQ.3 | 2 +- docs/libcurl/opts/CURLINFO_RTSP_CSEQ_RECV.3 | 2 +- docs/libcurl/opts/CURLINFO_RTSP_SERVER_CSEQ.3 | 2 +- docs/libcurl/opts/CURLINFO_RTSP_SESSION_ID.3 | 2 +- docs/libcurl/opts/CURLINFO_SCHEME.3 | 2 +- docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD.3 | 2 +- docs/libcurl/opts/CURLINFO_SIZE_DOWNLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_SIZE_UPLOAD.3 | 2 +- docs/libcurl/opts/CURLINFO_SIZE_UPLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD.3 | 2 +- docs/libcurl/opts/CURLINFO_SPEED_DOWNLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_SPEED_UPLOAD.3 | 2 +- docs/libcurl/opts/CURLINFO_SPEED_UPLOAD_T.3 | 2 +- docs/libcurl/opts/CURLINFO_SSL_ENGINES.3 | 2 +- docs/libcurl/opts/CURLINFO_SSL_VERIFYRESULT.3 | 2 +- docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_STARTTRANSFER_TIME_T.3 | 2 +- docs/libcurl/opts/CURLINFO_TLS_SESSION.3 | 2 +- docs/libcurl/opts/CURLINFO_TLS_SSL_PTR.3 | 6 +- docs/libcurl/opts/CURLINFO_TOTAL_TIME.3 | 2 +- docs/libcurl/opts/CURLINFO_TOTAL_TIME_T.3 | 2 +- .../opts/CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.3 | 2 +- .../opts/CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.3 | 2 +- docs/libcurl/opts/CURLMOPT_MAXCONNECTS.3 | 2 +- docs/libcurl/opts/CURLMOPT_MAX_HOST_CONNECTIONS.3 | 2 +- docs/libcurl/opts/CURLMOPT_MAX_PIPELINE_LENGTH.3 | 2 +- docs/libcurl/opts/CURLMOPT_MAX_TOTAL_CONNECTIONS.3 | 2 +- docs/libcurl/opts/CURLMOPT_PIPELINING.3 | 2 +- docs/libcurl/opts/CURLMOPT_PIPELINING_SERVER_BL.3 | 2 +- docs/libcurl/opts/CURLMOPT_PIPELINING_SITE_BL.3 | 2 +- docs/libcurl/opts/CURLMOPT_PUSHDATA.3 | 2 +- docs/libcurl/opts/CURLMOPT_PUSHFUNCTION.3 | 2 +- docs/libcurl/opts/CURLMOPT_SOCKETDATA.3 | 2 +- docs/libcurl/opts/CURLMOPT_SOCKETFUNCTION.3 | 2 +- docs/libcurl/opts/CURLMOPT_TIMERDATA.3 | 2 +- docs/libcurl/opts/CURLMOPT_TIMERFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_ABSTRACT_UNIX_SOCKET.3 | 2 +- docs/libcurl/opts/CURLOPT_ACCEPTTIMEOUT_MS.3 | 2 +- docs/libcurl/opts/CURLOPT_ACCEPT_ENCODING.3 | 2 +- docs/libcurl/opts/CURLOPT_ADDRESS_SCOPE.3 | 2 +- docs/libcurl/opts/CURLOPT_APPEND.3 | 2 +- docs/libcurl/opts/CURLOPT_AUTOREFERER.3 | 2 +- docs/libcurl/opts/CURLOPT_BUFFERSIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_CAINFO.3 | 2 +- docs/libcurl/opts/CURLOPT_CAPATH.3 | 2 +- docs/libcurl/opts/CURLOPT_CERTINFO.3 | 4 +- docs/libcurl/opts/CURLOPT_CHUNK_BGN_FUNCTION.3 | 8 +- docs/libcurl/opts/CURLOPT_CHUNK_DATA.3 | 8 +- docs/libcurl/opts/CURLOPT_CHUNK_END_FUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_CLOSESOCKETDATA.3 | 4 +- docs/libcurl/opts/CURLOPT_CLOSESOCKETFUNCTION.3 | 4 +- docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT.3 | 2 +- docs/libcurl/opts/CURLOPT_CONNECTTIMEOUT_MS.3 | 2 +- docs/libcurl/opts/CURLOPT_CONNECT_ONLY.3 | 2 +- docs/libcurl/opts/CURLOPT_CONNECT_TO.3 | 2 +- .../opts/CURLOPT_CONV_FROM_NETWORK_FUNCTION.3 | 2 +- .../libcurl/opts/CURLOPT_CONV_FROM_UTF8_FUNCTION.3 | 2 +- .../opts/CURLOPT_CONV_TO_NETWORK_FUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_COOKIE.3 | 2 +- docs/libcurl/opts/CURLOPT_COOKIEFILE.3 | 2 +- docs/libcurl/opts/CURLOPT_COOKIEJAR.3 | 2 +- docs/libcurl/opts/CURLOPT_COOKIELIST.3 | 2 +- docs/libcurl/opts/CURLOPT_COOKIESESSION.3 | 2 +- docs/libcurl/opts/CURLOPT_COPYPOSTFIELDS.3 | 2 +- docs/libcurl/opts/CURLOPT_CRLF.3 | 2 +- docs/libcurl/opts/CURLOPT_CRLFILE.3 | 2 +- docs/libcurl/opts/CURLOPT_CURLU.3 | 70 + docs/libcurl/opts/CURLOPT_CUSTOMREQUEST.3 | 2 +- docs/libcurl/opts/CURLOPT_DEBUGDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_DEBUGFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_DEFAULT_PROTOCOL.3 | 2 +- docs/libcurl/opts/CURLOPT_DIRLISTONLY.3 | 2 +- .../opts/CURLOPT_DISALLOW_USERNAME_IN_URL.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_CACHE_TIMEOUT.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_INTERFACE.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP4.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_LOCAL_IP6.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_SERVERS.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_SHUFFLE_ADDRESSES.3 | 2 +- docs/libcurl/opts/CURLOPT_DNS_USE_GLOBAL_CACHE.3 | 2 +- docs/libcurl/opts/CURLOPT_DOH_URL.3 | 2 +- docs/libcurl/opts/CURLOPT_EGDSOCKET.3 | 2 +- docs/libcurl/opts/CURLOPT_ERRORBUFFER.3 | 2 +- docs/libcurl/opts/CURLOPT_EXPECT_100_TIMEOUT_MS.3 | 2 +- docs/libcurl/opts/CURLOPT_FAILONERROR.3 | 2 +- docs/libcurl/opts/CURLOPT_FILETIME.3 | 2 +- docs/libcurl/opts/CURLOPT_FNMATCH_DATA.3 | 2 +- docs/libcurl/opts/CURLOPT_FNMATCH_FUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_FOLLOWLOCATION.3 | 2 +- docs/libcurl/opts/CURLOPT_FORBID_REUSE.3 | 2 +- docs/libcurl/opts/CURLOPT_FRESH_CONNECT.3 | 2 +- docs/libcurl/opts/CURLOPT_FTPPORT.3 | 2 +- docs/libcurl/opts/CURLOPT_FTPSSLAUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_ACCOUNT.3 | 2 +- .../libcurl/opts/CURLOPT_FTP_ALTERNATIVE_TO_USER.3 | 2 +- .../libcurl/opts/CURLOPT_FTP_CREATE_MISSING_DIRS.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_FILEMETHOD.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_RESPONSE_TIMEOUT.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_SKIP_PASV_IP.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_SSL_CCC.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_USE_EPRT.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_USE_EPSV.3 | 2 +- docs/libcurl/opts/CURLOPT_FTP_USE_PRET.3 | 2 +- docs/libcurl/opts/CURLOPT_GSSAPI_DELEGATION.3 | 2 +- .../opts/CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.3 | 2 +- docs/libcurl/opts/CURLOPT_HAPROXYPROTOCOL.3 | 2 +- docs/libcurl/opts/CURLOPT_HEADER.3 | 2 +- docs/libcurl/opts/CURLOPT_HEADERDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_HEADERFUNCTION.3 | 4 +- docs/libcurl/opts/CURLOPT_HEADEROPT.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTP200ALIASES.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTPAUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTPGET.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTPHEADER.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTPPOST.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTPPROXYTUNNEL.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTP_CONTENT_DECODING.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTP_TRANSFER_DECODING.3 | 2 +- docs/libcurl/opts/CURLOPT_HTTP_VERSION.3 | 2 +- docs/libcurl/opts/CURLOPT_IGNORE_CONTENT_LENGTH.3 | 2 +- docs/libcurl/opts/CURLOPT_INFILESIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_INFILESIZE_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_INTERFACE.3 | 2 +- docs/libcurl/opts/CURLOPT_INTERLEAVEDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_INTERLEAVEFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_IOCTLDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_IOCTLFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_IPRESOLVE.3 | 2 +- docs/libcurl/opts/CURLOPT_ISSUERCERT.3 | 2 +- docs/libcurl/opts/CURLOPT_KEEP_SENDING_ON_ERROR.3 | 2 +- docs/libcurl/opts/CURLOPT_KEYPASSWD.3 | 2 +- docs/libcurl/opts/CURLOPT_KRBLEVEL.3 | 2 +- docs/libcurl/opts/CURLOPT_LOCALPORT.3 | 2 +- docs/libcurl/opts/CURLOPT_LOCALPORTRANGE.3 | 2 +- docs/libcurl/opts/CURLOPT_LOGIN_OPTIONS.3 | 2 +- docs/libcurl/opts/CURLOPT_LOW_SPEED_LIMIT.3 | 2 +- docs/libcurl/opts/CURLOPT_LOW_SPEED_TIME.3 | 2 +- docs/libcurl/opts/CURLOPT_MAIL_AUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_MAIL_FROM.3 | 2 +- docs/libcurl/opts/CURLOPT_MAIL_RCPT.3 | 2 +- docs/libcurl/opts/CURLOPT_MAXCONNECTS.3 | 2 +- docs/libcurl/opts/CURLOPT_MAXFILESIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_MAXFILESIZE_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_MAXREDIRS.3 | 2 +- docs/libcurl/opts/CURLOPT_MAX_RECV_SPEED_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_MAX_SEND_SPEED_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_MIMEPOST.3 | 2 +- docs/libcurl/opts/CURLOPT_NETRC.3 | 19 +- docs/libcurl/opts/CURLOPT_NETRC_FILE.3 | 2 +- docs/libcurl/opts/CURLOPT_NEW_DIRECTORY_PERMS.3 | 2 +- docs/libcurl/opts/CURLOPT_NEW_FILE_PERMS.3 | 2 +- docs/libcurl/opts/CURLOPT_NOBODY.3 | 2 +- docs/libcurl/opts/CURLOPT_NOPROGRESS.3 | 2 +- docs/libcurl/opts/CURLOPT_NOPROXY.3 | 2 +- docs/libcurl/opts/CURLOPT_NOSIGNAL.3 | 2 +- docs/libcurl/opts/CURLOPT_OPENSOCKETDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_OPENSOCKETFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_PASSWORD.3 | 2 +- docs/libcurl/opts/CURLOPT_PATH_AS_IS.3 | 2 +- docs/libcurl/opts/CURLOPT_PINNEDPUBLICKEY.3 | 2 +- docs/libcurl/opts/CURLOPT_PIPEWAIT.3 | 2 +- docs/libcurl/opts/CURLOPT_PORT.3 | 2 +- docs/libcurl/opts/CURLOPT_POST.3 | 2 +- docs/libcurl/opts/CURLOPT_POSTFIELDS.3 | 2 +- docs/libcurl/opts/CURLOPT_POSTFIELDSIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_POSTFIELDSIZE_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_POSTQUOTE.3 | 2 +- docs/libcurl/opts/CURLOPT_POSTREDIR.3 | 2 +- docs/libcurl/opts/CURLOPT_PREQUOTE.3 | 2 +- docs/libcurl/opts/CURLOPT_PRE_PROXY.3 | 2 +- docs/libcurl/opts/CURLOPT_PRIVATE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROGRESSDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_PROGRESSFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_PROTOCOLS.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYAUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYHEADER.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYPASSWORD.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYPORT.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYTYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYUSERNAME.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXYUSERPWD.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_CAINFO.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_CAPATH.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_CRLFILE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_KEYPASSWD.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_PINNEDPUBLICKEY.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SERVICE_NAME.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSLCERT.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSLCERTTYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSLKEY.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSLKEYTYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSLVERSION.3 | 6 +- docs/libcurl/opts/CURLOPT_PROXY_SSL_CIPHER_LIST.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSL_OPTIONS.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYHOST.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_SSL_VERIFYPEER.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_TLS13_CIPHERS.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_PASSWORD.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_TYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_TLSAUTH_USERNAME.3 | 2 +- docs/libcurl/opts/CURLOPT_PROXY_TRANSFER_MODE.3 | 2 +- docs/libcurl/opts/CURLOPT_PUT.3 | 2 +- docs/libcurl/opts/CURLOPT_QUOTE.3 | 2 +- docs/libcurl/opts/CURLOPT_RANDOM_FILE.3 | 2 +- docs/libcurl/opts/CURLOPT_RANGE.3 | 2 +- docs/libcurl/opts/CURLOPT_READDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_READFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_REDIR_PROTOCOLS.3 | 2 +- docs/libcurl/opts/CURLOPT_REFERER.3 | 2 +- docs/libcurl/opts/CURLOPT_REQUEST_TARGET.3 | 2 +- docs/libcurl/opts/CURLOPT_RESOLVE.3 | 2 +- docs/libcurl/opts/CURLOPT_RESOLVER_START_DATA.3 | 2 +- .../libcurl/opts/CURLOPT_RESOLVER_START_FUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_RESUME_FROM.3 | 2 +- docs/libcurl/opts/CURLOPT_RESUME_FROM_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_CLIENT_CSEQ.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_REQUEST.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_SERVER_CSEQ.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_SESSION_ID.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_STREAM_URI.3 | 2 +- docs/libcurl/opts/CURLOPT_RTSP_TRANSPORT.3 | 2 +- docs/libcurl/opts/CURLOPT_SASL_IR.3 | 2 +- docs/libcurl/opts/CURLOPT_SEEKDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_SEEKFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_SERVICE_NAME.3 | 2 +- docs/libcurl/opts/CURLOPT_SHARE.3 | 2 +- docs/libcurl/opts/CURLOPT_SOCKOPTDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_SOCKOPTFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_SOCKS5_AUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_NEC.3 | 2 +- docs/libcurl/opts/CURLOPT_SOCKS5_GSSAPI_SERVICE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_AUTH_TYPES.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_COMPRESSION.3 | 2 +- .../libcurl/opts/CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_KEYDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_KEYFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_KNOWNHOSTS.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_PRIVATE_KEYFILE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSH_PUBLIC_KEYFILE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLCERT.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLCERTTYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLENGINE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLENGINE_DEFAULT.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLKEY.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLKEYTYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSLVERSION.3 | 4 +- docs/libcurl/opts/CURLOPT_SSL_CIPHER_LIST.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_CTX_DATA.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_CTX_FUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_ENABLE_ALPN.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_ENABLE_NPN.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_FALSESTART.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_OPTIONS.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_SESSIONID_CACHE.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_VERIFYHOST.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 | 2 +- docs/libcurl/opts/CURLOPT_SSL_VERIFYSTATUS.3 | 2 +- docs/libcurl/opts/CURLOPT_STDERR.3 | 2 +- docs/libcurl/opts/CURLOPT_STREAM_DEPENDS.3 | 2 +- docs/libcurl/opts/CURLOPT_STREAM_DEPENDS_E.3 | 2 +- docs/libcurl/opts/CURLOPT_STREAM_WEIGHT.3 | 2 +- .../opts/CURLOPT_SUPPRESS_CONNECT_HEADERS.3 | 2 +- docs/libcurl/opts/CURLOPT_TCP_FASTOPEN.3 | 2 +- docs/libcurl/opts/CURLOPT_TCP_KEEPALIVE.3 | 2 +- docs/libcurl/opts/CURLOPT_TCP_KEEPIDLE.3 | 2 +- docs/libcurl/opts/CURLOPT_TCP_KEEPINTVL.3 | 2 +- docs/libcurl/opts/CURLOPT_TCP_NODELAY.3 | 2 +- docs/libcurl/opts/CURLOPT_TELNETOPTIONS.3 | 2 +- docs/libcurl/opts/CURLOPT_TFTP_BLKSIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_TFTP_NO_OPTIONS.3 | 2 +- docs/libcurl/opts/CURLOPT_TIMECONDITION.3 | 2 +- docs/libcurl/opts/CURLOPT_TIMEOUT.3 | 2 +- docs/libcurl/opts/CURLOPT_TIMEOUT_MS.3 | 2 +- docs/libcurl/opts/CURLOPT_TIMEVALUE.3 | 2 +- docs/libcurl/opts/CURLOPT_TIMEVALUE_LARGE.3 | 2 +- docs/libcurl/opts/CURLOPT_TLS13_CIPHERS.3 | 2 +- docs/libcurl/opts/CURLOPT_TLSAUTH_PASSWORD.3 | 2 +- docs/libcurl/opts/CURLOPT_TLSAUTH_TYPE.3 | 2 +- docs/libcurl/opts/CURLOPT_TLSAUTH_USERNAME.3 | 2 +- docs/libcurl/opts/CURLOPT_TRANSFERTEXT.3 | 2 +- docs/libcurl/opts/CURLOPT_TRANSFER_ENCODING.3 | 2 +- docs/libcurl/opts/CURLOPT_UNIX_SOCKET_PATH.3 | 2 +- docs/libcurl/opts/CURLOPT_UNRESTRICTED_AUTH.3 | 2 +- docs/libcurl/opts/CURLOPT_UPLOAD.3 | 2 +- docs/libcurl/opts/CURLOPT_UPLOAD_BUFFERSIZE.3 | 2 +- docs/libcurl/opts/CURLOPT_URL.3 | 9 +- docs/libcurl/opts/CURLOPT_USERAGENT.3 | 2 +- docs/libcurl/opts/CURLOPT_USERNAME.3 | 2 +- docs/libcurl/opts/CURLOPT_USERPWD.3 | 2 +- docs/libcurl/opts/CURLOPT_USE_SSL.3 | 2 +- docs/libcurl/opts/CURLOPT_VERBOSE.3 | 2 +- docs/libcurl/opts/CURLOPT_WILDCARDMATCH.3 | 2 +- docs/libcurl/opts/CURLOPT_WRITEDATA.3 | 2 +- docs/libcurl/opts/CURLOPT_WRITEFUNCTION.3 | 10 +- docs/libcurl/opts/CURLOPT_XFERINFODATA.3 | 2 +- docs/libcurl/opts/CURLOPT_XFERINFOFUNCTION.3 | 2 +- docs/libcurl/opts/CURLOPT_XOAUTH2_BEARER.3 | 2 +- docs/libcurl/opts/Makefile.inc | 1 + docs/libcurl/symbols-in-versions | 35 +- include/curl/curl.h | 11 +- include/curl/curlver.h | 8 +- include/curl/typecheck-gcc.h | 1 + lib/Makefile.Watcom | 2 +- lib/Makefile.inc | 4 +- lib/Makefile.netware | 27 +- lib/asyn-ares.c | 33 +- lib/asyn-thread.c | 11 +- lib/asyn.h | 9 +- lib/base64.c | 26 +- lib/checksrc.pl | 118 +- lib/conncache.c | 2 +- lib/connect.c | 8 +- lib/cookie.c | 67 +- lib/curl_config.h | 6 - lib/curl_config.h.in | 6 - lib/curl_gssapi.c | 6 +- lib/curl_multibyte.c | 12 +- lib/curl_ntlm_core.c | 34 +- lib/curl_printf.h | 16 +- lib/curl_setup.h | 2 +- lib/curlx.h | 11 +- lib/doh.c | 43 +- lib/easy.c | 10 +- lib/escape.c | 2 +- lib/file.c | 25 +- lib/ftp.c | 30 +- lib/ftplistparser.c | 2 +- lib/hostcheck.c | 5 +- lib/hostip4.c | 4 +- lib/hostip6.c | 2 +- lib/http.c | 78 +- lib/http2.c | 10 +- lib/http2.h | 4 + lib/http_negotiate.c | 8 + lib/if2ip.c | 6 +- lib/imap.c | 4 +- lib/inet_ntop.c | 12 +- lib/ldap.c | 15 +- lib/libcurl.plist | 6 +- lib/libcurl.rc | 12 +- lib/md4.c | 1 + lib/md5.c | 7 - lib/memdebug.c | 4 +- lib/mprintf.c | 2 +- lib/multi.c | 66 +- lib/multiif.h | 10 +- lib/netrc.c | 11 +- lib/netrc.h | 2 + lib/openldap.c | 4 +- lib/pop3.c | 14 +- lib/progress.c | 36 +- lib/security.c | 4 +- lib/sendf.c | 15 +- lib/setopt.c | 6 + lib/socks_gssapi.c | 6 +- lib/socks_sspi.c | 8 +- lib/ssh-libssh.c | 24 +- lib/ssh.c | 26 +- lib/strerror.c | 26 +- lib/telnet.c | 30 +- lib/tftp.c | 14 +- lib/transfer.c | 47 +- lib/url.c | 160 +- lib/urlapi-int.h | 5 + lib/urlapi.c | 61 +- lib/urldata.h | 2 + lib/vauth/digest.c | 10 +- lib/vauth/ntlm.c | 222 +- lib/version.c | 36 +- lib/vtls/axtls.c | 741 -- lib/vtls/axtls.h | 33 - lib/vtls/cyassl.c | 8 +- lib/vtls/darwinssl.c | 26 +- lib/vtls/gskit.c | 2 +- lib/vtls/gtls.c | 26 +- lib/vtls/mbedtls.c | 6 +- lib/vtls/mesalink.c | 6 +- lib/vtls/nss.c | 72 +- lib/vtls/openssl.c | 252 +- lib/vtls/polarssl.c | 8 +- lib/vtls/schannel.c | 83 +- lib/vtls/schannel.h | 4 +- lib/vtls/schannel_verify.c | 4 +- lib/vtls/vtls.c | 16 +- lib/vtls/vtls.h | 1 - lib/x509asn1.c | 2 +- local-configure.patch | 67 +- m4/curl-confopts.m4 | 2 +- packages/AIX/Makefile.am | 3 - packages/AIX/RPM/Makefile.am | 1 - packages/AIX/RPM/README | 32 - packages/AIX/RPM/curl.spec.in | 134 - packages/DOS/common.dj | 2 +- packages/Linux/Makefile.am | 1 - packages/Linux/RPM/Makefile.am | 1 - packages/Linux/RPM/README | 4 - packages/Linux/RPM/curl-ssl.spec.in | 85 - packages/Linux/RPM/curl.spec.in | 83 - packages/Linux/RPM/make_curl_rpm | 62 - packages/Makefile.am | 4 +- packages/NetWare/get_exp.awk | 71 - packages/NetWare/get_ver.awk | 43 - packages/OS400/README.OS400 | 1 + packages/OS400/ccsidcurl.c | 46 +- packages/OS400/ccsidcurl.h | 6 + packages/OS400/curl.inc.in | 147 +- packages/Solaris/Makefile.am | 38 - packages/Symbian/group/libcurl.mmp | 2 +- packages/Win32/Makefile.am | 3 - packages/Win32/README | 53 - packages/Win32/cygwin/Makefile.am | 62 - packages/Win32/cygwin/README | 114 - packages/vms/generate_config_vms_h_curl.com | 6 - packages/vms/gnv_link_curl.com | 2 +- packages/vms/setup_gnv_curl_build.com | 2 +- post_update.sh | 3 +- projects/README | 2 +- projects/Windows/VC10/lib/libcurl.vcxproj | 2 - projects/Windows/VC11/lib/libcurl.vcxproj | 2 - projects/Windows/VC12/lib/libcurl.vcxproj | 2 - projects/Windows/VC14/lib/libcurl.vcxproj | 2 - projects/Windows/VC15/lib/libcurl.vcxproj | 2 - projects/Windows/VC6/lib/libcurl.dsp | 8 - projects/Windows/VC7.1/lib/libcurl.vcproj | 6 - projects/Windows/VC7/lib/libcurl.vcproj | 6 - projects/Windows/VC8/lib/libcurl.vcproj | 8 - projects/Windows/VC9/lib/libcurl.vcproj | 8 - src/Makefile.netware | 22 +- src/curl.rc | 10 +- src/tool_cb_dbg.c | 6 +- src/tool_cb_hdr.c | 2 +- src/tool_cb_prg.c | 4 +- src/tool_cb_wrt.c | 38 +- src/tool_cfgable.h | 4 +- src/tool_dirhie.c | 4 +- src/tool_doswin.c | 55 + src/tool_doswin.h | 1 + src/tool_getparam.c | 56 +- src/tool_hugehelp.c | 9941 +++++++++--------- src/tool_main.c | 27 +- src/tool_operate.c | 9 +- src/tool_operhlp.c | 4 +- src/tool_parsecfg.c | 14 +- src/tool_setopt.c | 22 +- src/tool_urlglob.c | 22 +- src/tool_version.h | 2 +- src/tool_writeout.c | 12 +- tests/FILEFORMAT | 3 +- tests/Makefile.am | 2 +- tests/data/Makefile.inc | 16 +- tests/data/test1159 | 58 + tests/data/test1160 | 6 +- tests/data/test1322 | 2 +- tests/data/test1457 | 62 + tests/data/test1518 | 62 + tests/data/test1519 | 62 + tests/data/test1652 | 23 + tests/data/test1653 | 23 + tests/data/test20 | 2 +- tests/data/test203 | 6 +- tests/data/test2070 | 41 - tests/data/test2076 | 75 + tests/data/test327 | 73 + tests/data/test328 | 55 + tests/data/test329 | 70 + tests/data/test658 | 50 + tests/http_pipe.py | 441 - tests/libtest/Makefile.inc | 11 +- tests/libtest/chkdecimalpoint.c | 2 +- tests/libtest/first.c | 4 +- tests/libtest/lib1156.c | 2 +- tests/libtest/lib1502.c | 4 +- tests/libtest/lib1506.c | 12 +- tests/libtest/lib1510.c | 12 +- tests/libtest/lib1512.c | 12 +- tests/libtest/lib1515.c | 10 +- tests/libtest/lib1518.c | 74 + tests/libtest/lib1529.c | 5 +- tests/libtest/lib1560.c | 29 +- tests/libtest/lib1900.c | 4 +- tests/libtest/lib518.c | 64 +- tests/libtest/lib530.c | 4 +- tests/libtest/lib537.c | 66 +- tests/libtest/lib540.c | 4 +- tests/libtest/lib553.c | 4 +- tests/libtest/lib658.c | 76 + tests/libtest/libauthretry.c | 4 +- tests/libtest/libntlmconnect.c | 4 +- tests/libtest/stub_gssapi.c | 9 +- tests/libtest/testtrace.c | 6 +- tests/runtests.1 | 2 +- tests/runtests.pl | 27 +- tests/secureserver.pl | 5 + tests/server/fake_ntlm.c | 8 +- tests/server/rtspd.c | 32 +- tests/server/sockfilt.c | 16 +- tests/server/sws.c | 46 +- tests/server/tftpd.c | 10 +- tests/server/util.c | 15 +- tests/symbol-scan.pl | 4 +- tests/testcurl.1 | 2 +- tests/unit/Makefile.inc | 8 +- tests/unit/unit1304.c | 51 +- tests/unit/unit1397.c | 4 +- tests/unit/unit1398.c | 4 +- tests/unit/unit1399.c | 4 +- tests/unit/unit1604.c | 28 +- tests/unit/unit1650.c | 12 +- tests/unit/unit1652.c | 133 + tests/unit/unit1653.c | 129 + 662 files changed, 14442 insertions(+), 14437 deletions(-) create mode 100644 docs/examples/urlapi.c create mode 100644 docs/libcurl/opts/CURLOPT_CURLU.3 delete mode 100644 lib/vtls/axtls.c delete mode 100644 lib/vtls/axtls.h delete mode 100644 packages/AIX/Makefile.am delete mode 100644 packages/AIX/RPM/Makefile.am delete mode 100644 packages/AIX/RPM/README delete mode 100644 packages/AIX/RPM/curl.spec.in delete mode 100644 packages/Linux/Makefile.am delete mode 100644 packages/Linux/RPM/Makefile.am delete mode 100644 packages/Linux/RPM/README delete mode 100644 packages/Linux/RPM/curl-ssl.spec.in delete mode 100644 packages/Linux/RPM/curl.spec.in delete mode 100644 packages/Linux/RPM/make_curl_rpm delete mode 100644 packages/NetWare/get_exp.awk delete mode 100644 packages/NetWare/get_ver.awk delete mode 100644 packages/Solaris/Makefile.am delete mode 100644 packages/Win32/Makefile.am delete mode 100644 packages/Win32/README delete mode 100644 packages/Win32/cygwin/Makefile.am delete mode 100644 packages/Win32/cygwin/README create mode 100644 tests/data/test1159 create mode 100644 tests/data/test1457 create mode 100644 tests/data/test1518 create mode 100644 tests/data/test1519 create mode 100644 tests/data/test1652 create mode 100644 tests/data/test1653 delete mode 100644 tests/data/test2070 create mode 100644 tests/data/test2076 create mode 100644 tests/data/test327 create mode 100644 tests/data/test328 create mode 100644 tests/data/test329 create mode 100644 tests/data/test658 delete mode 100755 tests/http_pipe.py create mode 100644 tests/libtest/lib1518.c create mode 100644 tests/libtest/lib658.c create mode 100644 tests/unit/unit1652.c create mode 100644 tests/unit/unit1653.c diff --git a/Android.bp b/Android.bp index a36c1a65..01d14635 100644 --- a/Android.bp +++ b/Android.bp @@ -60,115 +60,110 @@ cc_library { "-DBUILDING_LIBCURL", ], srcs:[ + "lib/amigaos.c", + "lib/asyn-ares.c", + "lib/asyn-thread.c", + "lib/base64.c", + "lib/conncache.c", + "lib/connect.c", + "lib/content_encoding.c", + "lib/cookie.c", + "lib/curl_addrinfo.c", "lib/curl_ctype.c", + "lib/curl_des.c", + "lib/curl_endian.c", + "lib/curl_fnmatch.c", + "lib/curl_gethostname.c", + "lib/curl_gssapi.c", + "lib/curl_memrchr.c", + "lib/curl_multibyte.c", + "lib/curl_ntlm_core.c", + "lib/curl_ntlm_wb.c", "lib/curl_range.c", + "lib/curl_rtmp.c", + "lib/curl_sasl.c", + "lib/curl_sspi.c", + "lib/curl_threads.c", + "lib/dict.c", "lib/doh.c", - "lib/rand.c", + "lib/dotdot.c", + "lib/easy.c", + "lib/escape.c", "lib/file.c", - "lib/timeval.c", - "lib/base64.c", - "lib/hostip.c", - "lib/progress.c", + "lib/fileinfo.c", "lib/formdata.c", - "lib/cookie.c", - "lib/http.c", - "lib/sendf.c", "lib/ftp.c", - "lib/url.c", - "lib/urlapi.c", - "lib/dict.c", - "lib/if2ip.c", - "lib/speedcheck.c", - "lib/ldap.c", - "lib/version.c", + "lib/ftplistparser.c", "lib/getenv.c", - "lib/escape.c", - "lib/mprintf.c", - "lib/telnet.c", - "lib/netrc.c", "lib/getinfo.c", - "lib/transfer.c", - "lib/easy.c", - "lib/security.c", - "lib/curl_fnmatch.c", - "lib/fileinfo.c", - "lib/ftplistparser.c", - "lib/wildcard.c", - "lib/krb5.c", - "lib/memdebug.c", - "lib/http_chunks.c", - "lib/strtok.c", - "lib/connect.c", - "lib/llist.c", + "lib/gopher.c", "lib/hash.c", - "lib/multi.c", - "lib/content_encoding.c", - "lib/share.c", - "lib/http_digest.c", - "lib/md4.c", - "lib/md5.c", - "lib/http_negotiate.c", - "lib/inet_pton.c", - "lib/strtoofft.c", - "lib/strerror.c", - "lib/amigaos.c", + "lib/hmac.c", "lib/hostasyn.c", + "lib/hostcheck.c", + "lib/hostip.c", "lib/hostip4.c", "lib/hostip6.c", "lib/hostsyn.c", + "lib/http.c", + "lib/http2.c", + "lib/http_chunks.c", + "lib/http_digest.c", + "lib/http_negotiate.c", + "lib/http_ntlm.c", + "lib/http_proxy.c", + "lib/idn_win32.c", + "lib/if2ip.c", + "lib/imap.c", "lib/inet_ntop.c", + "lib/inet_pton.c", + "lib/krb5.c", + "lib/ldap.c", + "lib/llist.c", + "lib/md4.c", + "lib/md5.c", + "lib/memdebug.c", + "lib/mime.c", + "lib/mprintf.c", + "lib/multi.c", + "lib/netrc.c", + "lib/non-ascii.c", + "lib/nonblock.c", + "lib/openldap.c", "lib/parsedate.c", + "lib/pingpong.c", + "lib/pipeline.c", + "lib/pop3.c", + "lib/progress.c", + "lib/rand.c", + "lib/rtsp.c", + "lib/security.c", "lib/select.c", - "lib/tftp.c", - "lib/splay.c", - "lib/strcase.c", - "lib/strdup.c", + "lib/sendf.c", + "lib/setopt.c", + "lib/sha256.c", + "lib/share.c", + "lib/slist.c", + "lib/smb.c", + "lib/smtp.c", "lib/socks.c", - "lib/ssh.c", - "lib/curl_addrinfo.c", "lib/socks_gssapi.c", "lib/socks_sspi.c", - "lib/curl_sspi.c", - "lib/slist.c", - "lib/nonblock.c", - "lib/curl_memrchr.c", - "lib/imap.c", - "lib/pop3.c", - "lib/smtp.c", - "lib/pingpong.c", - "lib/rtsp.c", - "lib/curl_threads.c", - "lib/warnless.c", - "lib/hmac.c", - "lib/curl_rtmp.c", - "lib/openldap.c", - "lib/curl_gethostname.c", - "lib/gopher.c", - "lib/idn_win32.c", - "lib/http_proxy.c", - "lib/non-ascii.c", - "lib/asyn-ares.c", - "lib/asyn-thread.c", - "lib/curl_gssapi.c", - "lib/http_ntlm.c", - "lib/curl_ntlm_wb.c", - "lib/curl_ntlm_core.c", - "lib/curl_sasl.c", - "lib/curl_multibyte.c", - "lib/hostcheck.c", - "lib/conncache.c", - "lib/pipeline.c", - "lib/dotdot.c", - "lib/x509asn1.c", - "lib/http2.c", - "lib/smb.c", - "lib/curl_endian.c", - "lib/curl_des.c", + "lib/speedcheck.c", + "lib/splay.c", + "lib/ssh.c", + "lib/strcase.c", + "lib/strdup.c", + "lib/strerror.c", + "lib/strtok.c", + "lib/strtoofft.c", "lib/system_win32.c", - "lib/mime.c", - "lib/sha256.c", - "lib/setopt.c", - "lib/vauth/vauth.c", + "lib/telnet.c", + "lib/tftp.c", + "lib/timeval.c", + "lib/transfer.c", + "lib/url.c", + "lib/urlapi.c", "lib/vauth/cleartext.c", "lib/vauth/cram.c", "lib/vauth/digest.c", @@ -180,17 +175,21 @@ cc_library { "lib/vauth/oauth2.c", "lib/vauth/spnego_gssapi.c", "lib/vauth/spnego_sspi.c", - "lib/vtls/openssl.c", + "lib/vauth/vauth.c", + "lib/version.c", + "lib/vtls/cyassl.c", + "lib/vtls/gskit.c", "lib/vtls/gtls.c", - "lib/vtls/vtls.c", + "lib/vtls/mbedtls.c", "lib/vtls/nss.c", + "lib/vtls/openssl.c", "lib/vtls/polarssl.c", "lib/vtls/polarssl_threadlock.c", - "lib/vtls/axtls.c", - "lib/vtls/cyassl.c", "lib/vtls/schannel.c", - "lib/vtls/gskit.c", - "lib/vtls/mbedtls.c", + "lib/vtls/vtls.c", + "lib/warnless.c", + "lib/wildcard.c", + "lib/x509asn1.c", ], shared_libs: [ "libcrypto", @@ -226,8 +225,8 @@ cc_binary { "src/tool_dirhie.c", "src/tool_doswin.c", "src/tool_easysrc.c", - "src/tool_formparse.c", "src/tool_filetime.c", + "src/tool_formparse.c", "src/tool_getparam.c", "src/tool_getpass.c", "src/tool_help.c", @@ -243,9 +242,9 @@ cc_binary { "src/tool_panykey.c", "src/tool_paramhlp.c", "src/tool_parsecfg.c", - "src/tool_strdup.c", "src/tool_setopt.c", "src/tool_sleep.c", + "src/tool_strdup.c", "src/tool_urlglob.c", "src/tool_util.c", "src/tool_vms.c", diff --git a/CHANGES b/CHANGES index 221e90cd..8c497b99 100644 --- a/CHANGES +++ b/CHANGES @@ -6,7287 +6,7537 @@ Changelog -Version 7.62.0 (30 Oct 2018) +Version 7.63.0 (12 Dec 2018) -Daniel Stenberg (30 Oct 2018) -- RELEASE-NOTES: 7.62.0 +Daniel Stenberg (12 Dec 2018) +- RELEASE-NOTES: 7.63.0 -- THANKS: 7.62.0 status +- THANKS: from the curl 7.62.0 cycle -Daniel Gustafsson (30 Oct 2018) -- vtls: add MesaLink to curl_sslbackend enum +- test1519: use lib1518 and test CURLINFO_REDIRECT_URL more + +- Curl_follow: extract the Location: header field unvalidated - MesaLink support was added in commit 57348eb97d1b8fc3742e02c but the - backend was never added to the curl_sslbackend enum in curl/curl.h. - This adds the new backend to the enum and updates the relevant docs. + ... when not actually following the redirect. Otherwise we return error + for this and an application can't extract the value. - Closes #3195 - Reviewed-by: Daniel Stenberg - -Daniel Stenberg (30 Oct 2018) -- [Ruslan Baratov brought this change] + Test 1518 added to verify. + + Reported-by: Pavel Pavlov + Fixes #3340 + Closes #3364 - cmake: Remove unused CURL_CONFIG_HAS_BEEN_RUN_BEFORE variable +- multi: convert two timeout variables to timediff_t - Closes #3191 + The time_t type is unsigned on some systems and these variables are used + to hold return values from functions that return timediff_t + already. timediff_t is always a signed type. + + Closes #3363 -- test2080: verify the fix for CVE-2018-16842 +- delta: use --diff-filter on the git diff-tree invokes + + Suggested-by: Dave Reisner -- voutf: fix bad arethmetic when outputting warnings to stderr +Patrick Monnerat (11 Dec 2018) +- documentation: curl_formadd field and file names are now escaped - CVE-2018-16842 - Reported-by: Brian Carpenter - Bug: https://curl.haxx.se/docs/CVE-2018-16842.html + Prior to 7.56.0, fieldnames and filenames were set in Content-Disposition + header without special processing: this may lead to invalid RFC 822 + quoted-strings. + 7.56.0 introduces escaping of backslashes and double quotes in these names: + mention it in the documentation. + + Reported-by: daboul on github + Closes #3361 -- [Tuomo Rinne brought this change] +Daniel Stenberg (11 Dec 2018) +- scripts/delta: show repo delta info from last release + + ... where "last release" should be the git tag in the repo. - cmake: uniform ZLIB to use USE_ variable and clean curl-config.cmake.in +Daniel Gustafsson (11 Dec 2018) +- tests: add urlapi unittest - Closes #3123 + This adds a new unittest intended to cover the internal functions in + the urlapi code, starting with parse_port(). In order to avoid name + collisions in debug builds, parse_port() is renamed Curl_parse_port() + since it will be exported. + + Reviewed-by: Daniel Stenberg + Reviewed-by: Marcel Raad -- [Tuomo Rinne brought this change] +- urlapi: fix portnumber parsing for ipv6 zone index + + An IPv6 URL which contains a zone index includes a '%%25' + string before the ending ']' bracket. The parsing logic wasn't set + up to cope with the zone index however, resulting in a malformed url + error being returned. Fix by breaking the parsing into two stages + to correctly handle the zone index. + + Closes #3355 + Closes #3319 + Reported-by: tonystz on Github + Reviewed-by: Daniel Stenberg + Reviewed-by: Marcel Raad - cmake: add find_dependency call for ZLIB to CMake config file +Daniel Stenberg (11 Dec 2018) +- [Jay Satiro brought this change] -- [Tuomo Rinne brought this change] + http: fix HTTP auth to include query in URI + + - Include query in the path passed to generate HTTP auth. + + Recent changes to use the URL API internally (46e1640, 7.62.0) + inadvertently broke authentication URIs by omitting the query. + + Fixes https://github.com/curl/curl/issues/3353 + Closes #3356 - cmake: add support for transitive ZLIB target +- [Michael Kaufmann brought this change] -- unit1650: fix "null pointer passed as argument 1 to memcmp" + http: don't set CURLINFO_CONDITION_UNMET for http status code 204 - Detected by UndefinedBehaviorSanitizer + The http status code 204 (No Content) should not change the "condition + unmet" flag. Only the http status code 304 (Not Modified) should do + this. - Closes #3187 + Closes #359 -- travis: add a "make tidy" build that runs clang-tidy +- [Samuel Surtees brought this change] + + ldap: fix LDAP URL parsing regressions - Closes #3182 + - Match URL scheme with LDAP and LDAPS + - Retrieve attributes, scope and filter from URL query instead + + Regression brought in 46e164069d1a5230 (7.62.0) + + Closes #3362 -- unit1300: fix stack-use-after-scope AddressSanitizer warning +- RELEASE-NOTES: synced + +- [Stefan Kanthak brought this change] + + (lib)curl.rc: fixup for minor bugs - Closes #3186 + All resources defined in lib/libcurl.rc and curl.rc are language + neutral. + + winbuild/MakefileBuild.vc ALWAYS defines the macro DEBUGBUILD, so the + ifdef's in line 33 of lib/libcurl.rc and src/curl.rc are wrong. + + Replace the hard-coded constants in both *.rc files with #define'd + values. + + Thumbs-uped-by: Rod Widdowson, Johannes Schindelin + URL: https://curl.haxx.se/mail/lib-2018-11/0000.html + Closes #3348 -- Curl_auth_create_plain_message: fix too-large-input-check +- test329: verify cookie max-age=0 immediate expiry + +- cookies: expire "Max-Age=0" immediately - CVE-2018-16839 - Reported-by: Harry Sintonen - Bug: https://curl.haxx.se/docs/CVE-2018-16839.html + Reported-by: Jeroen Ooms + Fixes #3351 + Closes #3352 -- Curl_close: clear data->multi_easy on free to avoid use-after-free +- [Johannes Schindelin brought this change] + + Upon HTTP_1_1_REQUIRED, retry the request with HTTP/1.1 - Regression from b46cfbc068 (7.59.0) - CVE-2018-16840 - Reported-by: Brian Carpenter (Geeknik Labs) + This is a companion patch to cbea2fd2c (NTLM: force the connection to + HTTP/1.1, 2018-12-06): with NTLM, we can switch to HTTP/1.1 + preemptively. However, with other (Negotiate) authentication it is not + clear to this developer whether there is a way to make it work with + HTTP/2, so let's try HTTP/2 first and fall back in case we encounter the + error HTTP_1_1_REQUIRED. - Bug: https://curl.haxx.se/docs/CVE-2018-16840.html + Note: we will still keep the NTLM workaround, as it avoids an extra + round trip. + + Daniel Stenberg helped a lot with this patch, in particular by + suggesting to introduce the Curl_h2_http_1_1_error() function. + + Closes #3349 + + Signed-off-by: Johannes Schindelin -- [randomswdev brought this change] +- [Ben Greear brought this change] - system.h: use proper setting with Sun C++ as well + openssl: fix unused variable compiler warning with old openssl - system.h selects the proper Sun settings when __SUNPRO_C is defined. The - Sun compiler does not define it when compiling C++ files. I'm adding a - check also on __SUNPRO_CC to allow curl to work properly also when used - in a C++ project on Sun Solaris. + URL: https://curl.haxx.se/mail/lib-2018-11/0055.html - Closes #3181 + Closes #3347 -- rand: add comment to skip a clang-tidy false positive +- [Johannes Schindelin brought this change] -- test1651: unit test Curl_extract_certinfo() + NTLM: force the connection to HTTP/1.1 - The version used for Gskit, NSS, GnuTLS, WolfSSL and schannel. + Since v7.62.0, cURL tries to use HTTP/2 whenever the server announces + the capability. However, NTLM authentication only works with HTTP/1.1, + and will likely remain in that boat (for details, see + https://docs.microsoft.com/en-us/iis/get-started/whats-new-in-iis-10/http2-on-iis#when-is-http2-not-supported). + + When we just found out that we want to use NTLM, and when the current + connection runs in HTTP/2 mode, let's force the connection to be closed + and to be re-opened using HTTP/1.1. + + Fixes https://github.com/curl/curl/issues/3341. + Closes #3345 + + Signed-off-by: Johannes Schindelin -- x509asn1: always check return code from getASN1Element() +- [Johannes Schindelin brought this change] -- Makefile: add 'tidy' target that runs clang-tidy + curl_global_sslset(): id == -1 is not necessarily an error - Available in the root, src and lib dirs. + It is allowed to call that function with id set to -1, specifying the + backend by the name instead. We should imitate what is done further down + in that function to allow for that. - Closes #3163 + Signed-off-by: Johannes Schindelin + + Closes #3346 -- RELEASE-PROCEDURE: adjust the release dates +Johannes Schindelin (6 Dec 2018) +- .gitattributes: make tabs in indentation a visible error - See: https://curl.haxx.se/mail/lib-2018-10/0107.html + Signed-off-by: Johannes Schindelin -Patrick Monnerat (27 Oct 2018) -- x509asn1: suppress left shift on signed value +Daniel Stenberg (6 Dec 2018) +- RELEASE-NOTES: synced + +- doh: fix memory leak in OOM situation - Use an unsigned variable: as the signed operation behavior is undefined, - this change silents clang-tidy about it. + Reviewed-by: Daniel Gustafsson + Closes #3342 + +- doh: make it work for h2-disabled builds too - Ref: https://github.com/curl/curl/pull/3163 - Reported-By: Daniel Stenberg + Reported-by: dtmsecurity at github + Fixes #3325 + Closes #3336 -Michael Kaufmann (27 Oct 2018) -- multi: Fix error handling in the SENDPROTOCONNECT state +- packages: remove old leftover files and dirs - If Curl_protocol_connect() returns an error code, - handle the error instead of switching to the next state. + This subdir has mostly become an attic of never-used cruft from the + past. - Closes #3170 + Closes #3331 -Daniel Stenberg (27 Oct 2018) -- RELEASE-NOTES: synced +- [Gergely Nagy brought this change] -- openssl: output the correct cipher list on TLS 1.3 error + openssl: do not use file BIOs if not requested - When failing to set the 1.3 cipher suite, the wrong string pointer would - be used in the error message. Most often saying "(nil)". + Moves the file handling BIO calls to the branch of the code where they + are actually used. - Reported-by: Ricky-Tigg on github - Fixes #3178 - Closes #3180 + Closes #3339 -- docs/CIPHERS: fix the TLS 1.3 cipher names - - ... picked straight from the OpenSSL man page: - https://www.openssl.org/docs/manmaster/man3/SSL_CTX_set_ciphersuites.html +- [Paul Howarth brought this change] + + nss: Fix compatibility with nss versions 3.14 to 3.15 + +- [Paul Howarth brought this change] + + nss: Improve info message when falling back SSL protocol - Reported-by: Ricky-Tigg on github - Bug: #3178 + Use descriptive text strings rather than decimal numbers. -Marcel Raad (27 Oct 2018) -- travis: install gnutls-bin package +- [Paul Howarth brought this change] + + nss: Fall back to latest supported SSL version - This is required for gnutls-serv, which enables a few more tests. + NSS may be built without support for the latest SSL/TLS versions, + leading to "SSL version range is not valid" errors when the library + code supports a recent version (e.g. TLS v1.3) but it has explicitly + been disabled. - Closes https://github.com/curl/curl/pull/2958 + This change adjusts the maximum SSL version requested by libcurl to + be the maximum supported version at runtime, as long as that version + is at least as high as the minimum version required by libcurl. + + Fixes #3261 -Daniel Gustafsson (26 Oct 2018) -- ssh: free the session on init failures +Daniel Gustafsson (3 Dec 2018) +- travis: enable COPYRIGHTYEAR extended warning - Ensure to clear the session object in case the libssh2 initialization - fails. + The extended warning for checking incorrect COPYRIGHTYEAR is quite + expensive to run, so rather than expecting every developer to do it + we ensure it's turned on locally for Travis. + +- checksrc: add COPYRIGHTYEAR check - It could be argued that the libssh2 error function should be called to - get a proper error message in this case. But since the only error path - in libssh2_knownhost_init() is memory a allocation failure it's safest - to avoid since the libssh2 error handling allocates memory. + Forgetting to bump the year in the copyright clause when hacking has + been quite common among curl developers, but a traditional checksrc + check isn't a good fit as it would penalize anyone hacking on January + 1st (among other things). This adds a more selective COPYRIGHTYEAR + check which intends to only cover the currently hacked on changeset. - Closes #3179 + The check for updated copyright year is currently not enforced on all + files but only on files edited and/or committed locally. This is due to + the amount of files which aren't updated with their correct copyright + year at the time of their respective commit. + + To further avoid running this expensive check for every developer, it + adds a new local override mode for checksrc where a .checksrc file can + be used to turn on extended warnings locally. + + Closes #3303 Reviewed-by: Daniel Stenberg -Daniel Stenberg (26 Oct 2018) -- docs/RELEASE-PROCEDURE: remove old entries, modify the Dec 2018 date +Daniel Stenberg (3 Dec 2018) +- CHECKSRC.md: document more warnings - ... I'm moving it up one week due to travels. The rest stays. + Closes #3335 + [ci skip] -- [Daniel Gustafsson brought this change] +- RELEASE-NOTES: synced - openssl: make 'done' a proper boolean +- SECURITY-PROCESS: bountygraph shuts down - Closes #3176 + This backpedals back the documents to the state before bountygraph. + + Closes #3311 -- gtls: Values stored to but never read +- curl: fix memory leak reading --writeout from file - Detected by clang-tidy + If another string had been set first, the writout function for reading + the syntax from file would leak the previously allocated memory. - Closes #3176 - -- [Alexey Eremikhin brought this change] + Reported-by: Brian Carpenter + Fixes #3322 + Closes #3330 - curl.1: --ipv6 mutexes ipv4 (fixed typo) +- tool_main: rename function to make it unique and better - Fixes #3171 - Closes #3172 + ... there's already another function in the curl tool named + free_config_fields! -- tool_main: make TerminalSettings static +Daniel Gustafsson (29 Nov 2018) +- TODO: remove CURLOPT_DNS_USE_GLOBAL_CACHE entry - Reported-by: Gisle Vanem - Bug: https://github.com/curl/curl/commit/becfe1233ff2b6b0c3e1b6a10048b55b68c2539f#commitcomment-31008819 - Closes #3161 + Commit 7c5837e79280e6abb3ae143dfc49bca5e74cdd11 deprecated the option + making it a manual code-edit operation to turn it back on. The removal + process has thus started and is now documented in docs/DEPRECATE.md so + remove from the TODO to avoid anyone looking for something to pick up + spend cycles on an already in-progress entry. + + Reviewed-by: Daniel Stenberg -- curl-config.in: remove dependency on bc +Jay Satiro (29 Nov 2018) +- [Sevan Janiyan brought this change] + + connect: fix building for recent versions of Minix - Reported-by: Dima Pasechnik - Fixes #3143 - Closes #3174 + EBADIOCTL doesn't exist on more recent Minix. + There have also been substantial changes to the network stack. + Fixes build on Minix 3.4rc + + Closes https://github.com/curl/curl/pull/3323 -- [Gisle Vanem brought this change] +- [Konstantin Kushnir brought this change] - rtmp: fix for compiling with lwIP + CMake: fix MIT/Heimdal Kerberos detection - Compiling on _WIN32 and with USE_LWIPSOCK, causes this error: - curl_rtmp.c(223,3): error: use of undeclared identifier 'setsockopt' - setsockopt(r->m_sb.sb_socket, SOL_SOCKET, SO_RCVTIMEO, - ^ - curl_rtmp.c(41,32): note: expanded from macro 'setsockopt' - #define setsockopt(a,b,c,d,e) (setsockopt)(a,b,c,(const char *)d,(int)e) - ^ - Closes #3155 + - fix syntax error in FindGSS.cmake + - correct krb5 include directory. FindGSS exports + "GSS_INCLUDE_DIR" variable. + + Closes https://github.com/curl/curl/pull/3316 -- configure: remove CURL_CONFIGURE_CURL_SOCKLEN_T +Daniel Stenberg (28 Nov 2018) +- test328: verify Content-Encoding: none - Follow-up to #3166 which did the cmake part of this. This type/define is - not used. + Because of issue #3315 - Closes #3168 + Closes #3317 -- [Ruslan Baratov brought this change] +- [James Knight brought this change] - cmake: remove unused variables + configure: include all libraries in ssl-libs fetch - Remove variables: - * HAVE_SOCKLEN_T - * CURL_SIZEOF_CURL_SOCKLEN_T - * CURL_TYPEOF_CURL_SOCKLEN_T + When compiling a collection of SSL libraries to link against (SSL_LIBS), + ensure all libraries are included. The call `--libs-only-l` can produce + only a subset of found in a `--libs` call (e.x. pthread may be excluded). + Adding `--libs-only-other` ensures other libraries are also included in + the list. This corrects select build environments compiling against a + static version of OpenSSL. Before the change, the following could be + observed: - Closes #3166 + checking for openssl options with pkg-config... found + configure: pkg-config: SSL_LIBS: "-lssl -lz -ldl -lcrypto -lz -ldl " + configure: pkg-config: SSL_LDFLAGS: "-L/home/jdknight//staging/usr/lib -L/home/jdknight//staging/usr/lib " + configure: pkg-config: SSL_CPPFLAGS: "-I/home/jdknight//staging/usr/include " + checking for HMAC_Update in -lcrypto... no + checking for HMAC_Init_ex in -lcrypto... no + checking OpenSSL linking with -ldl... no + checking OpenSSL linking with -ldl and -lpthread... no + configure: WARNING: SSL disabled, you will not be able to use HTTPS, FTPS, NTLM and more. + configure: WARNING: Use --with-ssl, --with-gnutls, --with-polarssl, --with-cyassl, --with-nss, --with-axtls, --with-winssl, or --with-darwinssl to address this. + ... + SSL support: no (--with-{ssl,gnutls,nss,polarssl,mbedtls,cyassl,axtls,winssl,darwinssl} ) + ... + + And include the other libraries when compiling SSL_LIBS succeeds with: + + checking for openssl options with pkg-config... found + configure: pkg-config: SSL_LIBS: "-lssl -lz -ldl -pthread -lcrypto -lz -ldl -pthread " + configure: pkg-config: SSL_LDFLAGS: "-L/home/jdknight//staging/usr/lib -L/home/jdknight//staging/usr/lib " + configure: pkg-config: SSL_CPPFLAGS: "-I/home/jdknight//staging/usr/include " + checking for HMAC_Update in -lcrypto... yes + checking for SSL_connect in -lssl... yes + ... + SSL support: enabled (OpenSSL) + ... + + Signed-off-by: James Knight + Closes #3193 -Michael Kaufmann (25 Oct 2018) -- urldata: Fix comment in header +Daniel Gustafsson (26 Nov 2018) +- doh: fix typo in infof call - The "connecting" function is used by multiple protocols, not only FTP + Reviewed-by: Daniel Stenberg -- netrc: free temporary strings if memory allocation fails +- cmdline-opts/gen.pl: define the correct varname - - Change the inout parameters after all needed memory has been - allocated. Do not change them if something goes wrong. - - Free the allocated temporary strings if strdup() fails. + The variable definition had a small typo making it declare another + variable then the intended. - Closes #3122 + Closes #3304 + Reviewed-by: Daniel Stenberg -Daniel Stenberg (24 Oct 2018) -- [Ruslan Baratov brought this change] +Daniel Stenberg (25 Nov 2018) +- RELEASE-NOTES: synced - config: Remove unused SIZEOF_VOIDP +- curl_easy_perform: fix timeout handling - Closes #3162 + curl_multi_wait() was erroneously used from within + curl_easy_perform(). It could lead to it believing there was no socket + to wait for and then instead sleep for a while instead of monitoring the + socket and then miss acting on that activity as swiftly as it should + (causing an up to 1000 ms delay). + + Reported-by: Antoni Villalonga + Fixes #3305 + Closes #3306 + Closes #3308 -- RELEASE-NOTES: synced +- CURLOPT_WRITEFUNCTION.3: spell out that it gets called many times -GitHub (23 Oct 2018) -- [Gisle Vanem brought this change] +- cookies: create the cookiejar even if no cookies to save + + Important for when the file is going to be read again and thus must not + contain old contents! + + Adds test 327 to verify. + + Reported-by: daboul on github + Fixes #3299 + Closes #3300 - Fix for compiling with lwIP (3) +- checksrc: ban snprintf use, add command line flag to override warns + +- snprintf: renamed and we now only use msnprintf() - lwIP on Windows does not have a WSAIoctl() function. - But it do have a SO_SNDBUF option to lwip_setsockopt(). But it currently does nothing. + The function does not return the same value as snprintf() normally does, + so readers may be mislead into thinking the code works differently than + it actually does. A different function name makes this easier to detect. + + Reported-by: Tomas Hoger + Assisted-by: Daniel Gustafsson + Fixes #3296 + Closes #3297 -Daniel Stenberg (23 Oct 2018) -- Curl_follow: return better errors on URL problems +- [Tobias Hintze brought this change] + + test: update test20/1322 for eglibc bug workaround - ... by making the converter function global and accessible. + The tests 20 and 1322 are using getaddrinfo of libc for resolving. In + eglibc-2.19 there is a memory leakage and invalid free bug which + surfaces in some special circumstances (PF_UNSPEC hint with invalid or + non-existent names). The valgrind runs in testing fail in these + situations. - Closes #3153 + As the tests 20/1322 are not specific on either protocol (IPv4/IPv6) + this commit changes the hints to IPv4 protocol by passing `--ipv4` flag + on the tests' command line. This prevents the valgrind failures. -- Curl_follow: remove remaining free(newurl) +- [Tobias Hintze brought this change] + + host names: allow trailing dot in name resolve, then strip it - Follow-up to 05564e750e8f0c. This function no longer frees the passed-in - URL. + Delays stripping of trailing dots to after resolving the hostname. - Reported-by: Michael Kaufmann - Bug: https://github.com/curl/curl/commit/05564e750e8f0c79016c680f301ce251e6e86155#commitcomm - ent-30985666 + Fixes #3022 + Closes #3222 -Daniel Gustafsson (23 Oct 2018) -- headers: end all headers with guard comment +- [UnknownShadow200 brought this change] + + CURLOPT_HEADERFUNCTION.3: match 'nitems' name in synopsis and description - Most headerfiles end with a /* */ comment, but it was - missing from some. The comment isn't the most important part of our - code documentation but consistency has an intrinsic value in itself. - This adds header guard comments to the files that were lacking it. + Closes #3295 + +Daniel Gustafsson (21 Nov 2018) +- configure: Fix typo in comment + +Michael Kaufmann (21 Nov 2018) +- openssl: support session resume with TLS 1.3 + + Session resumption information is not available immediately after a TLS 1.3 + handshake. The client must wait until the server has sent a session ticket. + + Use OpenSSL's "new session" callback to get the session information and put it + into curl's session cache. For TLS 1.3 sessions, this callback will be invoked + after the server has sent a session ticket. + + The "new session" callback is invoked only if OpenSSL's session cache is + enabled, so enable it and use the "external storage" mode which lets curl manage + the contents of the session cache. + + A pointer to the connection data and the sockindex are now saved as "SSL extra + data" to make them available to the callback. + + This approach also works for old SSL/TLS versions and old OpenSSL versions. - Closes #3158 - Reviewed-by: Jay Satiro Reviewed-by: Daniel Stenberg - -Jay Satiro (23 Oct 2018) -- CIPHERS.md: Mention the options used to set TLS 1.3 ciphers - Closes https://github.com/curl/curl/pull/3159 + Fixes #3202 + Closes #3271 -Daniel Stenberg (20 Oct 2018) -- docs/BUG-BOUNTY: the sponsors actually decide the amount +- ssl: fix compilation with OpenSSL 0.9.7 - Retract the previous approach as the sponsors will be the ones to set the - final amounts. + - ENGINE_cleanup() was used without including "openssl/engine.h" + - enable engine support for OpenSSL 0.9.7 - Closes #3152 - [ci skip] + Closes #3266 -- multi: avoid double-free +Daniel Stenberg (21 Nov 2018) +- openssl: disable TLS renegotiation with BoringSSL - Curl_follow() no longer frees the string. Make sure it happens in the - caller function, like we normally handle allocations. + Since we're close to feature freeze, this change disables this feature + with an #ifdef. Define ALLOW_RENEG at build-time to enable. - This bug was introduced with the use of the URL API internally, it has - never been in a release version + This could be converted to a bit for CURLOPT_SSL_OPTIONS to let + applications opt-in this. - Reported-by: Dario Weißer - Closes #3149 + Concern-raised-by: David Benjamin + Fixes #3283 + Closes #3293 -- multi: make the closure handle "inherit" CURLOPT_NOSIGNAL +- [Romain Fliedel brought this change] + + ares: remove fd from multi fd set when ares is about to close the fd - Otherwise, closing that handle can still cause surprises! + When using c-ares for asyn dns, the dns socket fd was silently closed + by c-ares without curl being aware. curl would then 'realize' the fd + has been removed at next call of Curl_resolver_getsock, and only then + notify the CURLMOPT_SOCKETFUNCTION to remove fd from its poll set with + CURL_POLL_REMOVE. At this point the fd is already closed. - Reported-by: Martin Ankerl - Fixes #3138 - Closes #3147 - -Marcel Raad (19 Oct 2018) -- VS projects: add USE_IPV6 + By using ares socket state callback (ARES_OPT_SOCK_STATE_CB), this + patch allows curl to be notified that the fd is not longer needed + for neither for write nor read. At this point by calling + Curl_multi_closed we are able to notify multi with CURL_POLL_REMOVE + before the fd is actually closed by ares. - The Visual Studio builds didn't use IPv6. Add it to all projects since - Visual Studio 2008, which is verified to build via AppVeyor. + In asyn-ares.c Curl_resolver_duphandle we can't use ares_dup anymore + since it does not allow passing a different sock_state_cb_data - Closes https://github.com/curl/curl/pull/3137 + Closes #3238 -- config_win32: enable LDAPS +- [Romain Fliedel brought this change] + + examples/ephiperfifo: report error when epoll_ctl fails + +Daniel Gustafsson (20 Nov 2018) +- [pkubaj brought this change] + + ntlm: Remove redundant ifdef USE_OPENSSL - As done in the autotools and CMake builds by default. + lib/curl_ntlm.c had code that read as follows: - Closes https://github.com/curl/curl/pull/3137 - -Daniel Stenberg (18 Oct 2018) -- travis: add build for "configure --disable-verbose" + #ifdef USE_OPENSSL + # ifdef USE_OPENSSL + # else + # .. + # endif + #endif - Closes #3144 - -Kamil Dudka (17 Oct 2018) -- tool_cb_hdr: handle failure of rename() + Remove the redundant USE_OPENSSL along with #else (it's not possible to + reach it anyway). The removed construction is a leftover from when the + SSLeay support was removed. - Detected by Coverity. + Closes #3269 + Reviewed-by: Daniel Gustafsson + Reviewed-by: Daniel Stenberg + +Daniel Stenberg (20 Nov 2018) +- [Han Han brought this change] + + ssl: replace all internal uses of CURLE_SSL_CACERT - Closes #3140 - Reviewed-by: Jay Satiro + Closes #3291 -Daniel Stenberg (17 Oct 2018) +Han Han (19 Nov 2018) +- docs: add more description to unified ssl error codes + +- curle: move deprecated error code to ifndef block + +Patrick Monnerat (19 Nov 2018) +- os400: add CURLOPT_CURLU to ILE/RPG binding. + +- os400: Add curl_easy_conn_upkeep() to ILE/RPG binding. + +- os400: fix return type of curl_easy_pause() in ILE/RPG binding. + +Daniel Stenberg (19 Nov 2018) - RELEASE-NOTES: synced -- docs/SECURITY-PROCESS: the hackerone IBB program drops curl +- impacket: add LICENSE - ... now there's only BountyGraph. - -Jay Satiro (16 Oct 2018) -- [Matthew Whitehead brought this change] + The license for the impacket package was not in our tree. + + Imported now from upstream's + https://github.com/SecureAuthCorp/impacket/blob/master/LICENSE + + Reported-by: infinnovation-dev on github + Fixes #3276 + Closes #3277 - x509asn1: Fix SAN IP address verification +Daniel Gustafsson (18 Nov 2018) +- tool_doswin: Fix uninitialized field warning - For IP addresses in the subject alternative name field, the length - of the IP address (and hence the number of bytes to perform a - memcmp on) is incorrectly calculated to be zero. The code previously - subtracted q from name.end. where in a successful case q = name.end - and therefore addrlen equalled 0. The change modifies the code to - subtract name.beg from name.end to calculate the length correctly. + The partial struct initialization in 397664a065abffb7c3445ca9 caused + a warning on uninitialized MODULEENTRY32 struct members: - The issue only affects libcurl with GSKit SSL, not other SSL backends. - The issue is not a security issue as IP verification would always fail. + /src/tool_doswin.c:681:3: warning: missing initializer for field + 'th32ModuleID' of 'MODULEENTRY32 {aka struct tagMODULEENTRY32}' + [-Wmissing-field-initializers] - Fixes #3102 - Closes #3141 + This is sort of a bogus warning as the remaining members will be set + to zero by the compiler, as all omitted members are. Nevertheless, + remove the warning by omitting all members and setting the dwSize + members explicitly. + + Closes #3254 + Reviewed-by: Marcel Raad + Reviewed-by: Jay Satiro -Daniel Gustafsson (15 Oct 2018) -- INSTALL: mention mesalink in TLS section +- openssl: Remove SSLEAY leftovers - Commit 57348eb97d1b8fc3742e02c6587d2d02ff592da5 added support for the - MesaLink vtls backend, but missed updating the TLS section containing - supported backends in the docs. + Commit 709cf76f6bb7dbac deprecated USE_SSLEAY, as curl since long isn't + compatible with the SSLeay library. This removes the few leftovers that + were omitted in the less frequently used platform targets. - Closes #3134 + Closes #3270 Reviewed-by: Daniel Stenberg -Marcel Raad (14 Oct 2018) -- nonblock: fix unused parameter warning - - If USE_BLOCKING_SOCKETS is defined, curlx_nonblock's arguments are not - used. +Daniel Stenberg (16 Nov 2018) +- [Elia Tufarolo brought this change] -Michael Kaufmann (13 Oct 2018) -- Curl_follow: Always free the passed new URL + http_negotiate: do not close connection until negotiation is completed - Closes #3124 - -Viktor Szakats (12 Oct 2018) -- replace rawgit links [ci skip] + Fix HTTP POST using CURLAUTH_NEGOTIATE. - Ref: https://rawgit.com/ "RawGit has reached the end of its useful life" - Ref: https://news.ycombinator.com/item?id=18202481 - Closes https://github.com/curl/curl/pull/3131 + Closes #3275 -Daniel Stenberg (12 Oct 2018) -- docs/BUG-BOUNTY.md: for vulns published since Aug 1st 2018 +- pop3: only do APOP with a valid timestamp - [ci skip] + Brought-by: bobmitchell1956 on github + Fixes #3278 + Closes #3279 -- travis: make distcheck scan for BOM markers +Jay Satiro (16 Nov 2018) +- [Peter Wu brought this change] + + openssl: do not log excess "TLS app data" lines for TLS 1.3 - and remove BOM from projects/wolfssl_override.props + The SSL_CTX_set_msg_callback callback is not just called for the + Handshake or Alert protocols, but also for the raw record header + (SSL3_RT_HEADER) and the decrypted inner record type + (SSL3_RT_INNER_CONTENT_TYPE). Be sure to ignore the latter to avoid + excess debug spam when using `curl -v` against a TLSv1.3-enabled server: - Closes #3126 + * TLSv1.3 (IN), TLS app data, [no content] (0): + + (Following this message, another callback for the decrypted + handshake/alert messages will be be present anyway.) + + Closes https://github.com/curl/curl/pull/3281 -Marcel Raad (11 Oct 2018) -- CMake: remove BOM +Marc Hoersken (15 Nov 2018) +- tests: disable SO_EXCLUSIVEADDRUSE for stunnel on Windows - Accidentally aded in commit 1bb86057ff07083deeb0b00f8ad35879ec4d03ea. + SO_EXCLUSIVEADDRUSE is on by default on Vista or newer, + but does not work together with SO_REUSEADDR being on. - Reported-by: Viktor Szakats - Ref: https://github.com/curl/curl/pull/3120#issuecomment-428673136 + The default changes were made with stunnel 5.34 and 5.35. -Daniel Gustafsson (10 Oct 2018) -- transfer: fix typo in comment +Daniel Stenberg (13 Nov 2018) +- [Kamil Dudka brought this change] -Michael Kaufmann (10 Oct 2018) -- docs: add "see also" links for SSL options - - - link TLS 1.2 and TLS 1.3 options - - link proxy and non-proxy options + nss: remove version selecting dead code - Closes #3121 + Closes #3262 -Marcel Raad (10 Oct 2018) -- AppVeyor: remove BDIR variable that sneaked in again +- nss: set default max-tls to 1.3/1.2 - Removed in ae762e1abebe3a5fe75658583c85059a0957ef6e, accidentally added - again in 9f3be5672dc4dda30ab43e0152e13d714a84d762. + Fixes #3261 -- CMake: disable -Wpedantic-ms-format +Daniel Gustafsson (13 Nov 2018) +- tool_cb_wrt: Silence function cast compiler warning - As done in the autotools build. This is required for MinGW, which - supports only %I64 for printing 64-bit values, but warns about it. + Commit 5bfaa86ceb3c2a9ac474a928e748c4a86a703b33 introduced a new + compiler warning on Windows cross compilation with GCC. See below + for an example of the warning from the autobuild logs (whitespace + edited to fit): - Closes https://github.com/curl/curl/pull/3120 - -Viktor Szakats (9 Oct 2018) -- ldap: show precise LDAP call in error message on Windows + /src/tool_cb_wrt.c:175:9: warning: cast from function call of type + 'intptr_t {aka long long int}' to non-matching type 'void *' + [-Wbad-function-cast] + (HANDLE) _get_osfhandle(fileno(outs->stream)), + ^ - Also add a unique but common text ('bind via') to make it - easy to grep this specific failure regardless of platform. + Store the return value from _get_osfhandle() in an intermediate + variable and cast the variable in WriteConsoleW() rather than the + function call directly to avoid a compiler warning. - Ref: https://github.com/curl/curl/pull/878/files#diff-7a636f08047c4edb53a240f540b4ecf6R468 - Closes https://github.com/curl/curl/pull/3118 - Reviewed-by: Daniel Stenberg + In passing, also add inspection of the MultiByteToWideChar() return + value and return failure in case an error is reported. + + Closes #3263 Reviewed-by: Marcel Raad + Reviewed-by: Viktor Szakats -Daniel Stenberg (9 Oct 2018) -- docs/DEPRECATE: minor reformat to render nicer on web +Daniel Stenberg (12 Nov 2018) +- nss: fix fallthrough comment to fix picky compiler warning -Daniel Gustafsson (9 Oct 2018) -- CURLOPT_SSL_VERIFYSTATUS: Fix typo - - Changes s/OSCP/OCSP/ and bumps the copyright year due to the change. +- docs: expanded on some CURLU details -Marcel Raad (9 Oct 2018) -- curl_setup: define NOGDI on Windows +- [Tim Rühsen brought this change] + + ftp: avoid two unsigned int overflows in FTP listing parser - This avoids an ERROR macro clash between and - on MinGW. + Curl_ftp_parselist: avoid unsigned integer overflows - Closes https://github.com/curl/curl/pull/3113 + The overflow has no real world impact, just avoid it for "best + practice". + + Closes #3225 -- Windows: fixes for MinGW targeting Windows Vista +- curl: --local-port range was not "including" - Classic MinGW has neither InitializeCriticalSectionEx nor - GetTickCount64, independent of the target Windows version. + The end port number in a given range was not included in the range used, + as it is documented to be. - Closes https://github.com/curl/curl/pull/3113 + Reported-by: infinnovation-dev on github + Fixes #3251 + Closes #3255 -Daniel Stenberg (8 Oct 2018) -- TODO: fixed 'API for URL parsing/splitting' +- [Jérémy Rocher brought this change] -Daniel Gustafsson (8 Oct 2018) -- KNOWN_BUGS: Fix various typos + openssl: support BoringSSL TLS renegotiation - Closes #3112 - Reviewed-by: Daniel Stenberg - -Viktor Szakats (8 Oct 2018) -- spelling fixes [ci skip] + As per BoringSSL porting documentation [1], BoringSSL rejects peer + renegotiations by default. - as detected by codespell 1.14.0 + curl fails when trying to authenticate to server through client + certificate if it is requested by server after the initial TLS + handshake. - Closes https://github.com/curl/curl/pull/3114 - Reviewed-by: Marcel Raad + Enable renegotiation by default with BoringSSL to get same behavior as + with OpenSSL. This is done by calling SSL_set_renegotiate_mode [2] + which was introduced in commit 1d5ef3bb1eb9 [3]. + + 1 - https://boringssl.googlesource.com/boringssl/+/HEAD/PORTING.md#tls-renegotiation + 2 - https://boringssl.googlesource.com/boringssl/+/master/include/openssl/ssl.h#3482 + 3 - https://boringssl.googlesource.com/boringssl/+/1d5ef3bb1eb97848617db5e7d633d735a401df86 + + Signed-off-by: Jérémy Rocher + Fixes #3258 + Closes #3259 -Daniel Stenberg (8 Oct 2018) -- RELEASE-NOTES: synced +- HISTORY: add some milestones + + Added a few of the more notable milestones in curl history that were + missing. Primarily more recent ones but I also noted some older that + could be worth mentioning. + + [ci skip] + Closes #3257 -- curl_ntlm_wb: check aprintf() return codes +Daniel Gustafsson (9 Nov 2018) +- KNOWN_BUGS: add --proxy-any connection issue - ... when they return NULL we're out of memory and MUST return failure. + Add the identified issue with --proxy-any and proxy servers which + advertise authentication schemes other than the supported one. - closes #3111 + Closes #876 + Closes #3250 + Reported-by: NTMan on Github + Reviewed-by: Daniel Stenberg -- docs/BUG-BOUNTY: proposed additional docs +Daniel Stenberg (9 Nov 2018) +- [Jim Fuller brought this change] + + setopt: add CURLOPT_CURLU - Bug bounty explainer. See https://bountygraph.com/programs/curl + Allows an application to pass in a pre-parsed URL via a URL handle. - Closes #3067 + Closes #3227 -- [Rick Deist brought this change] +- [Gisle Vanem brought this change] - hostip: fix check on Curl_shuffle_addr return value + docs: ESCape "\n" codes - Closes #3110 + Groff / Troff will display a: + printaf("Errno: %ld\n", error); + as: + printf("Errno: %ld0, error); + + when a "\n" is not escaped. Use "\\n" instead. + + Closes #3246 -- FILE: fix CURLOPT_NOBODY and CURLOPT_HEADER output +- curl: --local-port fix followup - Now FILE transfers send headers to the header callback like HTTP and - other protocols. Also made curl_easy_getinfo(...CURLINFO_PROTOCOL...) - work for FILE in the callbacks. + Regression by 52db54869e6. - Makes "curl -i file://.." and "curl -I file://.." work like before - again. Applied the bold header logic to them too. + Reported-by: infinnovation-dev on github + Fixes #3248 + Closes #3249 + +GitHub (7 Nov 2018) +- [Gisle Vanem brought this change] + + More "\n" ESCaping + +Daniel Stenberg (7 Nov 2018) +- RELEASE-NOTES: synced + +- curl: fix --local-port integer overflow - Regression from c1c2762 (7.61.0) + The tool's local port command line range parser didn't check for integer + overflows and could pass "weird" data to libcurl for this option. + libcurl however, has a strict range check for the values so it rejects + anything outside of the accepted range. - Reported-by: Shaun Jackman - Fixes #3083 - Closes #3101 + Reported-by: Brian Carpenter + Closes #3242 -Daniel Gustafsson (7 Oct 2018) -- gskit: make sure to terminate version string +- curl: correct the switch() logic in ourWriteOut - In case a very small buffer was passed to the version function, it could - result in the buffer not being NULL-terminated since strncpy() doesn't - guarantee a terminator on an overflowed buffer. Rather than adding code - to terminate (and handle zero-sized buffers), move to using snprintf() - instead like all the other vtls backends. + Follow-up to e431daf013, as I did the wrong correction for a compiler + warning. It should be a break and not a fall-through. - Closes #3105 - Reviewed-by: Daniel Stenberg - Reviewed-by: Viktor Szakats + Pointed-out-by: Frank Gevaerts -- TODO: add LD_PRELOAD support on macOS +- [Frank Gevaerts brought this change] + + curl: add %{stderr} and %{stdout} for --write-out - Add DYLD_INSERT_LIBRARIES support to the TODO list. Reported in #2394. + Closes #3115 -- runtests: skip ld_preload tests on macOS +Daniel Gustafsson (7 Nov 2018) +- winssl: be consistent in Schannel capitalization - The LD_PRELOAD functionality doesn't exist on macOS, so skip any tests - requiring it. + The productname from Microsoft is "Schannel", but in infof/failf + reporting we use "schannel". This removes different versions. - Fixes #2394 - Closes #3106 - Reported-by: Github user @jakirkham + Closes #3243 Reviewed-by: Daniel Stenberg -Marcel Raad (7 Oct 2018) -- AppVeyor: use Debug builds to run tests +Daniel Stenberg (7 Nov 2018) +- TODO: Have the URL API offer IDN decoding - This enables more tests. + Similar to how URL decoding/encoding is done, we could have URL + functions to convert IDN host names to punycode. - Closes https://github.com/curl/curl/pull/3104 + Suggested-by: Alexey Melnichuk + Closes #3232 -- AppVeyor: add HTTP_ONLY build +- urlapi: only skip encoding the first '=' with APPENDQUERY set - Closes https://github.com/curl/curl/pull/3104 + APPENDQUERY + URLENCODE would skip all equals signs but now it only skip + encoding the first to better allow "name=content" for any content. + + Reported-by: Alexey Melnichuk + Fixes #3231 + Closes #3231 -- AppVeyor: add WinSSL builds +- url: a short host name + port is not a scheme - Use the oldest and latest Windows SDKs for them. - Also, remove all but one OpenSSL build. + The function identifying a leading "scheme" part of the URL considered a + few letters ending with a colon to be a scheme, making something like + "short:80" to become an unknown scheme instead of a short host name and + a port number. - Closes https://github.com/curl/curl/pull/3104 + Extended test 1560 to verify. + + Also fixed test203 to use file_pwd to make it get the correct path on + windows. Removed test 2070 since it was a duplicate of 203. + + Assisted-by: Marcel Raad + Reported-by: Hagai Auro + Fixes #3220 + Fixes #3233 + Closes #3223 + Closes #3235 -- AppVeyor: add remaining Visual Studio versions +- [Sangamkar brought this change] + + libcurl: stop reading from paused transfers - This adds Visual Studio 9 and 10 builds. - There's no 64-bit VC9 compiler on AppVeyor, so use it as the Win32 - build. Also, VC9 cannot be used for running the test suite. + In the transfer loop it would previously not acknwledge the pause bit + and continue until drained or loop ended. - Closes https://github.com/curl/curl/pull/3104 + Closes #3240 -- AppVeyor: break long line +Jay Satiro (6 Nov 2018) +- tool: add undocumented option --dump-module-paths for win32 - Closes https://github.com/curl/curl/pull/3104 - -- AppVeyor: remove unused BDIR variable + - Add an undocumented diagnostic option for Windows to show the full + paths of all loaded modules regardless of whether or not libcurl + initialization succeeds. - Closes https://github.com/curl/curl/pull/3104 + This is needed so that in the CI we can get a list of all DLL + dependencies after initialization (when they're most likely to have + finished loading) and then package them as artifacts so that a + functioning build can be downloaded. Also I imagine it may have some use + as a diagnostic for help requests. + + Ref: https://github.com/curl/curl/pull/3103 + + Closes https://github.com/curl/curl/pull/3208 -Daniel Stenberg (6 Oct 2018) -- test2100: test DoH using IPv4-only +- curl_multibyte: fix a malloc overcalculation - To make it only send one DoH request and avoid the race condition that - could lead to the requests getting sent in reversed order and thus - making it hard to compare in the test case. + Prior to this change twice as many bytes as necessary were malloc'd when + converting wchar to UTF8. To allay confusion in the future I also + changed the variable name for the amount of bytes from len to bytes. - Fixes #3107 - Closes #3108 + Closes https://github.com/curl/curl/pull/3209 -- tests/FILEFORMAT: mention how to use and too +Michael Kaufmann (5 Nov 2018) +- netrc: don't ignore the login name specified with "--user" - [ci skip] + - for "--netrc", don't ignore the login/password specified with "--user", + only ignore the login/password in the URL. + This restores the netrc behaviour of curl 7.61.1 and earlier. + - fix the documentation of CURL_NETRC_REQUIRED + - improve the detection of login/password changes when reading .netrc + - don't read .netrc if both login and password are already set + + Fixes #3213 + Closes #3224 -- RELEASE-NOTES: synced +Patrick Monnerat (5 Nov 2018) +- OS400: add URL API ccsid wrappers and sync ILE/RPG bindings -- [Dmitry Kostjuchenko brought this change] +Daniel Stenberg (5 Nov 2018) +- [Yasuhiro Matsumoto brought this change] - timeval: fix use of weak symbol clock_gettime() on Apple platforms + curl: fixed UTF-8 in current console code page (Windows) - Closes #3048 + Fixes #3211 + Fixes #3175 + Closes #3212 -- doh: keep the IPv4 address in (original) network byte order - - Ideally this will fix the reversed order shown in SPARC tests: - - resp 8: Expected 127.0.0.1 got 1.0.0.127 +- TODO: 2.6 multi upkeep - Closes #3091 - -Jay Satiro (5 Oct 2018) -- INTERNALS.md: wrap lines longer than 79 + Closes #3199 -Daniel Gustafsson (5 Oct 2018) -- INTERNALS: escape reference to parameter +Daniel Gustafsson (5 Nov 2018) +- unittest: make 1652 stable across collations - The parameter reference was causing rendering issues in the - generated HTML page, as isn't a valid HTML tag. Fix by back- - tick escaping it. + The previous coding used a format string whose output depended on the + current locale of the environment running the test. Since the gist of + the test is to have a format string, with the actual formatting being + less important, switch to a more stable formatstring with decimals. - Closes #3099 - Reviewed-by: Jay Satiro + Reported-by: Marcel Raad + Closes #3234 Reviewed-by: Daniel Stenberg + Reviewed-by: Marcel Raad -- checksrc: handle zero scoped ignore commands +Daniel Stenberg (5 Nov 2018) +- Revert "url: a short host name + port is not a scheme" - If a !checksrc! disable command specified to ignore zero errors, it was - still added to the ignore block even though nothing was ignored. While - there were no blocks ignored that shouldn't be ignored, the processing - ended with with a warning: + This reverts commit 226cfa8264cd979eff3fd52c0f3585ef095e7cf2. - ::: warning: Unused ignore: LONGLINE (UNUSEDIGNORE) - /* !checksrc! disable LONGLINE 0 */ - ^ - Fix by instead treating a zero ignore as a a badcommand and throw a - warning for that one. + This commit caused test failures on appveyor/windows. Work on fixing them is + in #3235. + +- symbols-in-versions: add missing CURLU_ symbols - Closes #3096 - Reviewed-by: Daniel Stenberg + ...and fix symbol-scan.pl to also scan urlapi.h + + Reported-by: Alexey Melnichuk + Fixes #3226 + Closes #3230 -- checksrc: enable strict mode and warnings +Daniel Gustafsson (3 Nov 2018) +- infof: clearly indicate truncation - Enable strict and warnings mode for checksrc to ensure we aren't missing - anything due to bugs in the checking code. This uncovered a few things - which are all fixed in this commit: + The internal buffer in infof() is limited to 2048 bytes of payload plus + an additional byte for NULL termination. Servers with very long error + messages can however cause truncation of the string, which currently + isn't very clear, and leads to badly formatted output. - * several variables were used uninitialized - * several variables were not defined in the correct scope - * the whitelist filehandle was read even if the file didn't exist - * the enable_warn() call when a disable counter had expired was passing - incorrect variables, but since the checkwarn() call is unlikely to hit - (the counter is only decremented to zero on actual ignores) it didn't - manifest a problem. + This appends a "...\n" (or just "..." in case the format didn't with a + newline char) marker to the end of the string to clearly show + that it has been truncated. - Closes #3090 + Also include a unittest covering infof() to try and catch any bugs + introduced in this quite important function. + + Closes #3216 Reviewed-by: Daniel Stenberg Reviewed-by: Marcel Raad -Marcel Raad (5 Oct 2018) -- CMake: suppress MSVC warning C4127 for libtest - - It's issued by older Windows SDKs (prior to version 8.0). - -Sergei Nikulov (5 Oct 2018) -- Merge branch 'dmitrykos-fix_missing_CMake_defines' - -- [Dmitry Kostjuchenko brought this change] +Michael Kaufmann (3 Nov 2018) +- tool_getparam: fix some comments - cmake: test and set missed defines during configuration +Daniel Stenberg (3 Nov 2018) +- url: a short host name + port is not a scheme - Added configuration checks for HAVE_BUILTIN_AVAILABLE and HAVE_CLOCK_GETTIME_MONOTONIC. + The function identifying a leading "scheme" part of the URL considered a few + letters ending with a colon to be a scheme, making something like "short:80" + to become an unknown scheme instead of a short host name and a port number. - Closes #3097 + Extended test 1560 to verify. + + Reported-by: Hagai Auro + Fixes #3220 + Closes #3223 -Marcel Raad (5 Oct 2018) -- AppVeyor: disable test 500 +- URL: fix IPv6 numeral address parser - It almost always results in - "starttransfer vs total: 0.000001 0.000000". - I cannot reproduce this locally, so disable it for now. + Regression from 46e164069d1a52. Extended test 1560 to verify. - Closes https://github.com/curl/curl/pull/3100 + Reported-by: tpaukrt on github + Fixes #3218 + Closes #3219 -- AppVeyor: set custom install prefix +- travis: remove curl before a normal build - CMake's default has spaces and in 32-bit mode parentheses, which result - in syntax errors in curl-config. + on Linux. To make sure the test suite runs with its newly build tool and + doesn't require an external one present. - Closes https://github.com/curl/curl/pull/3100 + Bug: #3198 + Closes #3200 -- AppVeyor: Remove non-SSL non-test builds +- [Tim Rühsen brought this change] + + mprintf: avoid unsigned integer overflow warning - They don't add much value. + The overflow has no real world impact. + Just avoid it for "best practice". - Closes https://github.com/curl/curl/pull/3100 + Code change suggested by "The Infinnovation Team" and Daniel Stenberg. + Closes #3184 -- AppVeyor: run test suite +- Curl_follow: accept non-supported schemes for "fake" redirects - Use the preinstalled MSYS2 bash for that. - Disable test 1139 as the CMake build doesn't generate curl.1. + When not actually following the redirect and the target URL is only + stored for later retrieval, curl always accepted "non-supported" + schemes. This was a regression from 46e164069d1a5230. - Ref: https://github.com/curl/curl/issues/3070#issuecomment-425922224 - Closes https://github.com/curl/curl/pull/3100 + Reported-by: Brad King + Fixes #3210 + Closes #3215 -- AppVeyor: use in-tree build +Daniel Gustafsson (2 Nov 2018) +- openvms: fix example name - Required to run the tests. + Commit efc696a2e09225bfeab4 renamed persistant.c to persistent.c to + fix the typo in the name, but missed to update the OpenVMS package + files which still looked for the old name. - Closes https://github.com/curl/curl/pull/3100 + Closes #3217 + Reviewed-by: Daniel Stenberg + Reviewed-by: Viktor Szakats -Daniel Stenberg (4 Oct 2018) -- doh: make sure TTL isn't re-inited by second (discarded?) response +Daniel Stenberg (1 Nov 2018) +- configure: show CFLAGS, LDFLAGS etc in summary - Closes #3092 + To make it easier to understand other people's and remote builds etc. + + Closes #3207 -- test320: strip out more HTML when comparing +- version: bump for next cycle + +- axtls: removed - To make the test case work with different gnutls-serv versions better. + As has been outlined in the DEPRECATE.md document, the axTLS code has + been disabled for 6 months and is hereby removed. - Reported-by: Kamil Dudka - Fixes #3093 - Closes #3094 - -Marcel Raad (4 Oct 2018) -- runtests: use Windows paths for Windows curl + Use a better supported TLS library! - curl generated by CMake's Visual Studio generator has "Windows" in the - version number. + Assisted-by: Daniel Gustafsson + Closes #3194 -Daniel Stenberg (4 Oct 2018) -- [Colin Hogben brought this change] +- [marcosdiazr brought this change] - tests/negtelnetserver.py: fix Python2-ism in neg TELNET server - - Fix problems caused by differences in treatment of bytes objects between - python2 and python3. + schannel: make CURLOPT_CERTINFO support using Issuer chain - Fixes #2929 - Closes #3080 + Closes #3197 -Daniel Gustafsson (3 Oct 2018) -- memory: ensure to check allocation results +- travis: build with sanitize=address,undefined,signed-integer-overflow - The result of a memory allocation should always be checked, as we may - run under memory pressure where even a small allocation can fail. This - adds checking and error handling to a few cases where the allocation - wasn't checked for success. In the ftp case, the freeing of the path - variable is moved ahead of the allocation since there is little point - in keeping it around across the strdup, and the separation makes for - more readable code. In nwlib, the lock is aslo freed in the error path. - - Also bumps the copyright years on affected files. + ... using clang - Closes #3084 - Reviewed-by: Jay Satiro - Reviewed-by: Daniel Stenberg + Closes #3190 -- comment: Fix multiple typos in function parameters +- schannel: use Curl_ prefix for global private symbols - Ensure that the parameters in the comment match the actual names in the - prototype. + Curl_verify_certificate() must use the Curl_ prefix since it is globally + available in the lib and otherwise steps outside of our namespace! - Closes #3079 - Reviewed-by: Daniel Stenberg + Closes #3201 -- CURLOPT_SSLVERSION.3: fix typos and consistent spelling +Kamil Dudka (1 Nov 2018) +- tests: drop http_pipe.py script no longer used - Use TLS vX.Y throughout the document, instead of TLS X.Y, as that was - already done in all but a few cases. Also fix a few typos. + It is unused since commit f7208df7d9d5cd5e15e2d89237e828f32b63f135. - Closes #3076 - Reviewed-by: Marcel Raad - Reviewed-by: Daniel Stenberg + Closes #3204 -- SECURITY-PROCESS: make links into hyperlinks +Daniel Stenberg (31 Oct 2018) +- runtests: use the local curl for verifying - Use proper Markdown hyperlink format for the Bountygraph links in order - for the generated website page to be more user friendly. Also link to - the sponsors to give them a little extra credit. + ... revert the mistaken change brought in commit 8440616f53. - Closes #3082 - Reviewed-by: Daniel Stenberg + Reported-by: Alessandro Ghedini + Bug: https://curl.haxx.se/mail/lib-2018-10/0118.html + + Closes #3198 -Jay Satiro (3 Oct 2018) -- CURLOPT_HEADER.3: fix typo +Version 7.62.0 (30 Oct 2018) -- nss: fix nssckbi module loading on Windows +Daniel Stenberg (30 Oct 2018) +- RELEASE-NOTES: 7.62.0 + +- THANKS: 7.62.0 status + +Daniel Gustafsson (30 Oct 2018) +- vtls: add MesaLink to curl_sslbackend enum - - Use .DLL extension instead of .so to load modules on Windows. + MesaLink support was added in commit 57348eb97d1b8fc3742e02c but the + backend was never added to the curl_sslbackend enum in curl/curl.h. + This adds the new backend to the enum and updates the relevant docs. - Bug: https://curl.haxx.se/mail/lib-2018-09/0077.html - Reported-by: Maxime Legros + Closes #3195 + Reviewed-by: Daniel Stenberg + +Daniel Stenberg (30 Oct 2018) +- [Ruslan Baratov brought this change] + + cmake: Remove unused CURL_CONFIG_HAS_BEEN_RUN_BEFORE variable - Ref: https://github.com/curl/curl/pull/3016/#issuecomment-423069442 + Closes #3191 + +- test2080: verify the fix for CVE-2018-16842 + +- voutf: fix bad arethmetic when outputting warnings to stderr - Closes https://github.com/curl/curl/pull/3086 + CVE-2018-16842 + Reported-by: Brian Carpenter + Bug: https://curl.haxx.se/docs/CVE-2018-16842.html -- data-binary.d: clarify default content-type is x-www-form-urlencoded +- [Tuomo Rinne brought this change] + + cmake: uniform ZLIB to use USE_ variable and clean curl-config.cmake.in - - Advise user that --data-binary sends a default content type of - x-www-form-urlencoded, and to have the data treated as arbitrary - binary data by the server set the content-type header to octet-stream. + Closes #3123 + +- [Tuomo Rinne brought this change] + + cmake: add find_dependency call for ZLIB to CMake config file + +- [Tuomo Rinne brought this change] + + cmake: add support for transitive ZLIB target + +- unit1650: fix "null pointer passed as argument 1 to memcmp" - Ref: https://github.com/curl/curl/pull/2852#issuecomment-426465094 + Detected by UndefinedBehaviorSanitizer - Closes https://github.com/curl/curl/pull/3085 + Closes #3187 -Marcel Raad (2 Oct 2018) -- test1299: use single quotes around asterisk +- travis: add a "make tidy" build that runs clang-tidy - Ref: https://github.com/curl/curl/issues/1751#issuecomment-321522580 + Closes #3182 -Daniel Stenberg (2 Oct 2018) -- docs/CIPHERS: mention the colon separation for OpenSSL +- unit1300: fix stack-use-after-scope AddressSanitizer warning - Bug: #3077 + Closes #3186 -- runtests: ignore disabled even when ranges are given +- Curl_auth_create_plain_message: fix too-large-input-check - runtests.pl support running a range of tests, like "44 to 127". Starting - now, the code makes sure that even such given ranges will ignore tests - that are marked as disabled. + CVE-2018-16839 + Reported-by: Harry Sintonen + Bug: https://curl.haxx.se/docs/CVE-2018-16839.html + +- Curl_close: clear data->multi_easy on free to avoid use-after-free - Disabled tests can still be run by explictly specifying that test - number. + Regression from b46cfbc068 (7.59.0) + CVE-2018-16840 + Reported-by: Brian Carpenter (Geeknik Labs) - Closes #3075 + Bug: https://curl.haxx.se/docs/CVE-2018-16840.html -- urlapi: starting with a drive letter on win32 is not an abs url - - ... and libcurl doesn't support any single-letter URL schemes (if there - even exist any) so it should be fairly risk-free. +- [randomswdev brought this change] + + system.h: use proper setting with Sun C++ as well - Reported-by: Marcel Raad + system.h selects the proper Sun settings when __SUNPRO_C is defined. The + Sun compiler does not define it when compiling C++ files. I'm adding a + check also on __SUNPRO_CC to allow curl to work properly also when used + in a C++ project on Sun Solaris. - Fixes #3070 - Closes #3071 + Closes #3181 -Marcel Raad (2 Oct 2018) -- doh: fix curl_easy_setopt argument type - - CURLOPT_POSTFIELDSIZE is long. Fixes a compiler warning on 64-bit - MinGW. +- rand: add comment to skip a clang-tidy false positive -Daniel Stenberg (2 Oct 2018) -- RELEASE-NOTES: synced +- test1651: unit test Curl_extract_certinfo() + + The version used for Gskit, NSS, GnuTLS, WolfSSL and schannel. -Jay Satiro (1 Oct 2018) -- [Ruslan Baratov brought this change] +- x509asn1: always check return code from getASN1Element() - CMake: Improve config installation +- Makefile: add 'tidy' target that runs clang-tidy - Use 'GNUInstallDirs' standard module to set destinations of installed - files. + Available in the root, src and lib dirs. - Use uppercase "CURL" names instead of lowercase "curl" to match standard - 'FindCURL.cmake' CMake module: - * https://cmake.org/cmake/help/latest/module/FindCURL.html + Closes #3163 + +- RELEASE-PROCEDURE: adjust the release dates - Meaning: - * Install 'CURLConfig.cmake' instead of 'curl-config.cmake' - * User should call 'find_package(CURL)' instead of 'find_package(curl)' + See: https://curl.haxx.se/mail/lib-2018-10/0107.html + +Patrick Monnerat (27 Oct 2018) +- x509asn1: suppress left shift on signed value - Use 'configure_package_config_file' function to generate - 'CURLConfig.cmake' file. This will make 'curl-config.cmake.in' template - file smaller and handle components better. E.g. current configuration - report no error if user specified unknown components (note: new - configuration expects no components, report error if user will try to - specify any). + Use an unsigned variable: as the signed operation behavior is undefined, + this change silents clang-tidy about it. - Closes https://github.com/curl/curl/pull/2849 + Ref: https://github.com/curl/curl/pull/3163 + Reported-By: Daniel Stenberg -Daniel Stenberg (1 Oct 2018) -- test1650: make it depend on http/2 +Michael Kaufmann (27 Oct 2018) +- multi: Fix error handling in the SENDPROTOCONNECT state - Follow-up to 570008c99da0ccbb as it gets link errors. + If Curl_protocol_connect() returns an error code, + handle the error instead of switching to the next state. - Reported-by: Michael Kaufmann - Closes #3068 + Closes #3170 -- [Nate Prewitt brought this change] +Daniel Stenberg (27 Oct 2018) +- RELEASE-NOTES: synced - MANUAL: minor grammar fix +- openssl: output the correct cipher list on TLS 1.3 error - Noticed a typo reading through the docs. + When failing to set the 1.3 cipher suite, the wrong string pointer would + be used in the error message. Most often saying "(nil)". - Closes #3069 + Reported-by: Ricky-Tigg on github + Fixes #3178 + Closes #3180 -- doh: only build if h2 enabled +- docs/CIPHERS: fix the TLS 1.3 cipher names - The DoH spec says "HTTP/2 [RFC7540] is the minimum RECOMMENDED version - of HTTP for use with DoH". + ... picked straight from the OpenSSL man page: + https://www.openssl.org/docs/manmaster/man3/SSL_CTX_set_ciphersuites.html - Reported-by: Marcel Raad - Closes #3066 + Reported-by: Ricky-Tigg on github + Bug: #3178 -- test2100: require http2 to run +Marcel Raad (27 Oct 2018) +- travis: install gnutls-bin package - Reported-by: Marcel Raad - Fixes #3064 - Closes #3065 + This is required for gnutls-serv, which enables a few more tests. + + Closes https://github.com/curl/curl/pull/2958 -- multi: fix memory leak in content encoding related error path +Daniel Gustafsson (26 Oct 2018) +- ssh: free the session on init failures - ... a missing multi_done() call. + Ensure to clear the session object in case the libssh2 initialization + fails. - Credit to OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10728 - Closes #3063 + It could be argued that the libssh2 error function should be called to + get a proper error message in this case. But since the only error path + in libssh2_knownhost_init() is memory a allocation failure it's safest + to avoid since the libssh2 error handling allocates memory. + + Closes #3179 + Reviewed-by: Daniel Stenberg -- travis: bump the Secure Transport build to use xcode 10 +Daniel Stenberg (26 Oct 2018) +- docs/RELEASE-PROCEDURE: remove old entries, modify the Dec 2018 date - Due to an issue with travis - (https://github.com/travis-ci/travis-ci/issues/9956) we've been using - Xcode 9.2 for darwinssl builds for a while. Now xcode 10 is offered as - an alternative and as it builds curl+darwinssl fine that seems like a - better choice. + ... I'm moving it up one week due to travels. The rest stays. + +- [Daniel Gustafsson brought this change] + + openssl: make 'done' a proper boolean - Closes #3062 + Closes #3176 -- [Rich Turner brought this change] +- gtls: Values stored to but never read + + Detected by clang-tidy + + Closes #3176 - curl: enabled Windows VT Support and UTF-8 output +- [Alexey Eremikhin brought this change] + + curl.1: --ipv6 mutexes ipv4 (fixed typo) - Enabled Console VT support (if running OS supports VT) in tool_main.c. + Fixes #3171 + Closes #3172 + +- tool_main: make TerminalSettings static - Fixes #3008 - Closes #3011 + Reported-by: Gisle Vanem + Bug: https://github.com/curl/curl/commit/becfe1233ff2b6b0c3e1b6a10048b55b68c2539f#commitcomment-31008819 + Closes #3161 -- multi: fix location URL memleak in error path +- curl-config.in: remove dependency on bc - Follow-up to #3044 - fix a leak OSS-Fuzz detected - Closes #3057 + Reported-by: Dima Pasechnik + Fixes #3143 + Closes #3174 -Sergei Nikulov (28 Sep 2018) -- cmake: fixed path used in generation of docs/tests during curl build through add_subdicectory(...) +- [Gisle Vanem brought this change] -- [Brad King brought this change] + rtmp: fix for compiling with lwIP + + Compiling on _WIN32 and with USE_LWIPSOCK, causes this error: + curl_rtmp.c(223,3): error: use of undeclared identifier 'setsockopt' + setsockopt(r->m_sb.sb_socket, SOL_SOCKET, SO_RCVTIMEO, + ^ + curl_rtmp.c(41,32): note: expanded from macro 'setsockopt' + #define setsockopt(a,b,c,d,e) (setsockopt)(a,b,c,(const char *)d,(int)e) + ^ + Closes #3155 - cmake: Backport to work with CMake 3.0 again +- configure: remove CURL_CONFIGURE_CURL_SOCKLEN_T - Changes in commit 7867aaa9a0 (cmake: link curl to the OpenSSL targets - instead of lib absolute paths, 2018-07-17) and commit f826b4ce98 (cmake: - bumped minimum version to 3.4, 2018-07-19) required CMake 3.4 to fix - issue #2746. This broke support for users on older versions of CMake - even if they just want to build curl and do not care whether transitive - dependencies work. + Follow-up to #3166 which did the cmake part of this. This type/define is + not used. - Backport the logic to work with CMake 3.0 again by implementing the - fix only when the version of CMake is at least 3.4. + Closes #3168 -Marcel Raad (27 Sep 2018) -- curl_threads: fix classic MinGW compile break +- [Ruslan Baratov brought this change] + + cmake: remove unused variables - Classic MinGW still has _beginthreadex's return type as unsigned long - instead of uintptr_t [0]. uintptr_t is not even defined because of [1]. + Remove variables: + * HAVE_SOCKLEN_T + * CURL_SIZEOF_CURL_SOCKLEN_T + * CURL_TYPEOF_CURL_SOCKLEN_T - [0] https://sourceforge.net/p/mingw/mingw-org-wsl/ci/wsl-5.1-release/tree/mingwrt/include/process.h#l167 - [1] https://sourceforge.net/p/mingw/mingw-org-wsl/ci/wsl-5.1-release/tree/mingwrt/include/process.h#l90 + Closes #3166 + +Michael Kaufmann (25 Oct 2018) +- urldata: Fix comment in header - Bug: https://github.com/curl/curl/issues/2924#issuecomment-424334807 - Closes https://github.com/curl/curl/pull/3051 + The "connecting" function is used by multiple protocols, not only FTP -Daniel Stenberg (26 Sep 2018) -- configure: s/AC_RUN_IFELSE/CURL_RUN_IFELSE +- netrc: free temporary strings if memory allocation fails - fix a few leftovers + - Change the inout parameters after all needed memory has been + allocated. Do not change them if something goes wrong. + - Free the allocated temporary strings if strdup() fails. - Fixes #3006 - Closes #3049 + Closes #3122 -- [Doron Behar brought this change] +Daniel Stenberg (24 Oct 2018) +- [Ruslan Baratov brought this change] - example/htmltidy: fix include paths of tidy libraries + config: Remove unused SIZEOF_VOIDP - Closes #3050 + Closes #3162 - RELEASE-NOTES: synced -- Curl_http2_done: fix memleak in error path - - Free 'header_recvbuf' unconditionally even if 'h2' isn't (yet) set, for - early failures. - - Detected by OSS-Fuzz - - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10669 - Closes #3046 +GitHub (23 Oct 2018) +- [Gisle Vanem brought this change] -- http: fix memleak in rewind error path - - If the rewind would fail, a strdup() would not get freed. - - Detected by OSS-Fuzz + Fix for compiling with lwIP (3) - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10665 - Closes #3044 + lwIP on Windows does not have a WSAIoctl() function. + But it do have a SO_SNDBUF option to lwip_setsockopt(). But it currently does nothing. -Viktor Szakats (24 Sep 2018) -- test320: fix regression in [ci skip] +Daniel Stenberg (23 Oct 2018) +- Curl_follow: return better errors on URL problems - The value in question is coming directly from `gnutls-serv`, so it cannot - be modified freely. + ... by making the converter function global and accessible. - Reported-by: Marcel Raad - Ref: https://github.com/curl/curl/commit/6ae6b2a533e8630afbb21f570305bd4ceece6348#commitcomment-30621004 + Closes #3153 -Daniel Stenberg (24 Sep 2018) -- Curl_retry_request: fix memory leak +- Curl_follow: remove remaining free(newurl) - Detected by OSS-Fuzz + Follow-up to 05564e750e8f0c. This function no longer frees the passed-in + URL. - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10648 - Closes #3042 + Reported-by: Michael Kaufmann + Bug: https://github.com/curl/curl/commit/05564e750e8f0c79016c680f301ce251e6e86155#commitcomm + ent-30985666 -- openssl: load built-in engines too +Daniel Gustafsson (23 Oct 2018) +- headers: end all headers with guard comment - Regression since 38203f1 + Most headerfiles end with a /* */ comment, but it was + missing from some. The comment isn't the most important part of our + code documentation but consistency has an intrinsic value in itself. + This adds header guard comments to the files that were lacking it. - Reported-by: Jean Fabrice - Fixes #3023 - Closes #3040 - -- [Christian Heimes brought this change] + Closes #3158 + Reviewed-by: Jay Satiro + Reviewed-by: Daniel Stenberg - OpenSSL: enable TLS 1.3 post-handshake auth +Jay Satiro (23 Oct 2018) +- CIPHERS.md: Mention the options used to set TLS 1.3 ciphers - OpenSSL 1.1.1 requires clients to opt-in for post-handshake - authentication. + Closes https://github.com/curl/curl/pull/3159 + +Daniel Stenberg (20 Oct 2018) +- docs/BUG-BOUNTY: the sponsors actually decide the amount - Fixes: https://github.com/curl/curl/issues/3026 - Signed-off-by: Christian Heimes + Retract the previous approach as the sponsors will be the ones to set the + final amounts. - Closes https://github.com/curl/curl/pull/3027 - -- [Even Rouault brought this change] + Closes #3152 + [ci skip] - Curl_dedotdotify(): always nul terminate returned string. - - This fixes potential out-of-buffer access on "file:./" URL +- multi: avoid double-free - $ valgrind curl "file:./" - ==24516== Memcheck, a memory error detector - ==24516== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al. - ==24516== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info - ==24516== Command: /home/even/install-curl-git/bin/curl file:./ - ==24516== - ==24516== Conditional jump or move depends on uninitialised value(s) - ==24516== at 0x4C31F9C: strcmp (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) - ==24516== by 0x4EBB315: seturl (urlapi.c:801) - ==24516== by 0x4EBB568: parseurl (urlapi.c:861) - ==24516== by 0x4EBC509: curl_url_set (urlapi.c:1199) - ==24516== by 0x4E644C6: parseurlandfillconn (url.c:2044) - ==24516== by 0x4E67AEF: create_conn (url.c:3613) - ==24516== by 0x4E68A4F: Curl_connect (url.c:4119) - ==24516== by 0x4E7F0A4: multi_runsingle (multi.c:1440) - ==24516== by 0x4E808E5: curl_multi_perform (multi.c:2173) - ==24516== by 0x4E7558C: easy_transfer (easy.c:686) - ==24516== by 0x4E75801: easy_perform (easy.c:779) - ==24516== by 0x4E75868: curl_easy_perform (easy.c:798) + Curl_follow() no longer frees the string. Make sure it happens in the + caller function, like we normally handle allocations. - Was originally spotted by - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10637 - Credit to OSS-Fuzz + This bug was introduced with the use of the URL API internally, it has + never been in a release version - Closes #3039 + Reported-by: Dario Weißer + Closes #3149 -Viktor Szakats (23 Sep 2018) -- update URLs in tests +- multi: make the closure handle "inherit" CURLOPT_NOSIGNAL - - and one in docs/MANUAL as well + Otherwise, closing that handle can still cause surprises! - Closes https://github.com/curl/curl/pull/3038 + Reported-by: Martin Ankerl + Fixes #3138 + Closes #3147 -- whitespace fixes +Marcel Raad (19 Oct 2018) +- VS projects: add USE_IPV6 - - replace tabs with spaces where possible - - remove line ending spaces - - remove double/triple newlines at EOF - - fix a non-UTF-8 character - - cleanup a few indentations/line continuations - in manual examples + The Visual Studio builds didn't use IPv6. Add it to all projects since + Visual Studio 2008, which is verified to build via AppVeyor. - Closes https://github.com/curl/curl/pull/3037 + Closes https://github.com/curl/curl/pull/3137 -Daniel Stenberg (23 Sep 2018) -- http: add missing return code check +- config_win32: enable LDAPS - Detected by Coverity. CID 1439610. + As done in the autotools and CMake builds by default. - Follow-up from 46e164069d1a523 + Closes https://github.com/curl/curl/pull/3137 + +Daniel Stenberg (18 Oct 2018) +- travis: add build for "configure --disable-verbose" - Closes #3034 + Closes #3144 -- ftp: don't access pointer before NULL check +Kamil Dudka (17 Oct 2018) +- tool_cb_hdr: handle failure of rename() - Detected by Coverity. CID 1439611. + Detected by Coverity. - Follow-up from 46e164069d1a523 + Closes #3140 + Reviewed-by: Jay Satiro -- unit1650: fix out of boundary access +Daniel Stenberg (17 Oct 2018) +- RELEASE-NOTES: synced + +- docs/SECURITY-PROCESS: the hackerone IBB program drops curl - Fixes #2987 - Closes #3035 + ... now there's only BountyGraph. -Viktor Szakats (23 Sep 2018) -- docs/examples: URL updates +Jay Satiro (16 Oct 2018) +- [Matthew Whitehead brought this change] + + x509asn1: Fix SAN IP address verification - - also update two URLs outside of docs/examples - - fix spelling of filename persistant.c - - fix three long lines that started failing checksrc.pl + For IP addresses in the subject alternative name field, the length + of the IP address (and hence the number of bytes to perform a + memcmp on) is incorrectly calculated to be zero. The code previously + subtracted q from name.end. where in a successful case q = name.end + and therefore addrlen equalled 0. The change modifies the code to + subtract name.beg from name.end to calculate the length correctly. - Closes https://github.com/curl/curl/pull/3036 + The issue only affects libcurl with GSKit SSL, not other SSL backends. + The issue is not a security issue as IP verification would always fail. + + Fixes #3102 + Closes #3141 -- examples/Makefile.m32: sync with core [ci skip] +Daniel Gustafsson (15 Oct 2018) +- INSTALL: mention mesalink in TLS section - also: - - fix two warnings in synctime.c (one of them Windows-specific) - - upgrade URLs in synctime.c and remove a broken one + Commit 57348eb97d1b8fc3742e02c6587d2d02ff592da5 added support for the + MesaLink vtls backend, but missed updating the TLS section containing + supported backends in the docs. - Closes https://github.com/curl/curl/pull/3033 + Closes #3134 + Reviewed-by: Daniel Stenberg -Daniel Stenberg (22 Sep 2018) -- examples/parseurl.c: show off the URL API a bit +Marcel Raad (14 Oct 2018) +- nonblock: fix unused parameter warning - Closes #3030 + If USE_BLOCKING_SOCKETS is defined, curlx_nonblock's arguments are not + used. -- SECURITY-PROCESS: mention the bountygraph program [ci skip] +Michael Kaufmann (13 Oct 2018) +- Curl_follow: Always free the passed new URL - Closes #3032 + Closes #3124 -- url: use the URL API internally as well - - ... to make it a truly unified URL parser. +Viktor Szakats (12 Oct 2018) +- replace rawgit links [ci skip] - Closes #3017 + Ref: https://rawgit.com/ "RawGit has reached the end of its useful life" + Ref: https://news.ycombinator.com/item?id=18202481 + Closes https://github.com/curl/curl/pull/3131 -Viktor Szakats (22 Sep 2018) -- URL and mailmap updates, remove an obsolete directory [ci skip] +Daniel Stenberg (12 Oct 2018) +- docs/BUG-BOUNTY.md: for vulns published since Aug 1st 2018 - Closes https://github.com/curl/curl/pull/3031 + [ci skip] -Daniel Stenberg (22 Sep 2018) -- RELEASE-NOTES: synced +- travis: make distcheck scan for BOM markers + + and remove BOM from projects/wolfssl_override.props + + Closes #3126 -- configure: force-use -lpthreads on HPUX +Marcel Raad (11 Oct 2018) +- CMake: remove BOM - When trying to detect pthreads use on HPUX the checks will succeed - without the correct -l option but then end up failing at run-time. + Accidentally aded in commit 1bb86057ff07083deeb0b00f8ad35879ec4d03ea. - Reported-by: Eason-Yu on github - Fixes #2697 - Closes #3025 + Reported-by: Viktor Szakats + Ref: https://github.com/curl/curl/pull/3120#issuecomment-428673136 -- [Erik Minekus brought this change] +Daniel Gustafsson (10 Oct 2018) +- transfer: fix typo in comment - Curl_saferealloc: Fixed typo in docblock +Michael Kaufmann (10 Oct 2018) +- docs: add "see also" links for SSL options - Closes #3029 - -- urlapi: fix support for address scope in IPv6 numerical addresses + - link TLS 1.2 and TLS 1.3 options + - link proxy and non-proxy options - Closes #3024 - -- [Loganaden Velvindron brought this change] + Closes #3121 - GnutTLS: TLS 1.3 support +Marcel Raad (10 Oct 2018) +- AppVeyor: remove BDIR variable that sneaked in again - Closes #2971 + Removed in ae762e1abebe3a5fe75658583c85059a0957ef6e, accidentally added + again in 9f3be5672dc4dda30ab43e0152e13d714a84d762. -- TODO: c-ares and CURLOPT_OPENSOCKETFUNCTION +- CMake: disable -Wpedantic-ms-format - Removed DoH. + As done in the autotools build. This is required for MinGW, which + supports only %I64 for printing 64-bit values, but warns about it. - Closes #2734 + Closes https://github.com/curl/curl/pull/3120 -Jay Satiro (20 Sep 2018) -- vtls: fix ssl version "or later" behavior change for many backends - - - Treat CURL_SSLVERSION_MAX_NONE the same as - CURL_SSLVERSION_MAX_DEFAULT. Prior to this change NONE would mean use - the minimum version also as the maximum. +Viktor Szakats (9 Oct 2018) +- ldap: show precise LDAP call in error message on Windows - This is a follow-up to 6015cef which changed the behavior of setting - the SSL version so that the requested version would only be the minimum - and not the maximum. It appears it was (mostly) implemented in OpenSSL - but not other backends. In other words CURL_SSLVERSION_TLSv1_0 used to - mean use just TLS v1.0 and now it means use TLS v1.0 *or later*. + Also add a unique but common text ('bind via') to make it + easy to grep this specific failure regardless of platform. - - Fix CURL_SSLVERSION_MAX_DEFAULT for OpenSSL. + Ref: https://github.com/curl/curl/pull/878/files#diff-7a636f08047c4edb53a240f540b4ecf6R468 + Closes https://github.com/curl/curl/pull/3118 + Reviewed-by: Daniel Stenberg + Reviewed-by: Marcel Raad + +Daniel Stenberg (9 Oct 2018) +- docs/DEPRECATE: minor reformat to render nicer on web + +Daniel Gustafsson (9 Oct 2018) +- CURLOPT_SSL_VERIFYSTATUS: Fix typo - Prior to this change CURL_SSLVERSION_MAX_DEFAULT with OpenSSL was - erroneously treated as always TLS 1.3, and would cause an error if - OpenSSL was built without TLS 1.3 support. + Changes s/OSCP/OCSP/ and bumps the copyright year due to the change. + +Marcel Raad (9 Oct 2018) +- curl_setup: define NOGDI on Windows - Co-authored-by: Daniel Gustafsson + This avoids an ERROR macro clash between and + on MinGW. - Fixes https://github.com/curl/curl/issues/2969 - Closes https://github.com/curl/curl/pull/3012 + Closes https://github.com/curl/curl/pull/3113 -Daniel Stenberg (20 Sep 2018) -- certs: generate tests certs with sha256 digest algorithm - - As OpenSSL 1.1.1 starts to complain and fail on sha1 CAs: +- Windows: fixes for MinGW targeting Windows Vista - "SSL certificate problem: CA signature digest algorithm too weak" + Classic MinGW has neither InitializeCriticalSectionEx nor + GetTickCount64, independent of the target Windows version. - Closes #3014 + Closes https://github.com/curl/curl/pull/3113 -- urlapi: document the error codes, remove two unused ones - - Assisted-by: Daniel Gustafsson - Closes #3019 +Daniel Stenberg (8 Oct 2018) +- TODO: fixed 'API for URL parsing/splitting' -- urlapi: add CURLU_GUESS_SCHEME and fix hostname acceptance - - In order for this API to fully work for libcurl itself, it now offers a - CURLU_GUESS_SCHEME flag that makes it "guess" scheme based on the host - name prefix just like libcurl always did. If there's no known prefix, it - will guess "http://". - - Separately, it relaxes the check of the host name so that IDN host names - can be passed in as well. - - Both these changes are necessary for libcurl itself to use this API. +Daniel Gustafsson (8 Oct 2018) +- KNOWN_BUGS: Fix various typos - Assisted-by: Daniel Gustafsson - Closes #3018 + Closes #3112 + Reviewed-by: Daniel Stenberg -Kamil Dudka (19 Sep 2018) -- nss: try to connect even if libnssckbi.so fails to load - - One can still use CA certificates stored in NSS database. +Viktor Szakats (8 Oct 2018) +- spelling fixes [ci skip] - Reported-by: Maxime Legros - Bug: https://curl.haxx.se/mail/lib-2018-09/0077.html + as detected by codespell 1.14.0 - Closes #3016 + Closes https://github.com/curl/curl/pull/3114 + Reviewed-by: Marcel Raad -Daniel Gustafsson (19 Sep 2018) -- urlapi: don't set value which is never read +Daniel Stenberg (8 Oct 2018) +- RELEASE-NOTES: synced + +- curl_ntlm_wb: check aprintf() return codes - In the CURLUPART_URL case, there is no codepath which invokes url - decoding so remove the assignment of the urldecode variable. This - fixes the deadstore bug-report from clang static analysis. + ... when they return NULL we're out of memory and MUST return failure. - Closes #3015 - Reviewed-by: Daniel Stenberg + closes #3111 -- todo: Update reference to already done item +- docs/BUG-BOUNTY: proposed additional docs - TODO item 1.1 was implemented in commit 946ce5b61f, update reference - to it with instead referencing the implemented option. + Bug bounty explainer. See https://bountygraph.com/programs/curl - Closes #3013 - Reviewed-by: Daniel Stenberg - -Daniel Stenberg (18 Sep 2018) -- RELEASE-NOTES: synced + Closes #3067 -- [slodki brought this change] +- [Rick Deist brought this change] - cmake: don't require OpenSSL if USE_OPENSSL=OFF - - User must have OpenSSL installed even if not used by libcurl at all - since 7.61.1 release. Broken at - 7867aaa9a01decf93711428462335be8cef70212 + hostip: fix check on Curl_shuffle_addr return value - Reviewed-by: Sergei Nikulov - Closes #3001 + Closes #3110 -- curl_multi_wait: call getsock before figuring out timeout +- FILE: fix CURLOPT_NOBODY and CURLOPT_HEADER output - .... since getsock may update the expiry timer. + Now FILE transfers send headers to the header callback like HTTP and + other protocols. Also made curl_easy_getinfo(...CURLINFO_PROTOCOL...) + work for FILE in the callbacks. - Fixes #2996 - Closes #3000 - -- examples/http2-pushinmemory: receive HTTP/2 pushed files in memory + Makes "curl -i file://.." and "curl -I file://.." work like before + again. Applied the bold header logic to them too. - Closes #3004 + Regression from c1c2762 (7.61.0) + + Reported-by: Shaun Jackman + Fixes #3083 + Closes #3101 -Daniel Gustafsson (18 Sep 2018) -- darwinssl: Fix realloc memleak +Daniel Gustafsson (7 Oct 2018) +- gskit: make sure to terminate version string - The reallocation was using the input pointer for the return value, which - leads to a memory leak on reallication failure. Fix by instead use the - safe internal API call Curl_saferealloc(). + In case a very small buffer was passed to the version function, it could + result in the buffer not being NULL-terminated since strncpy() doesn't + guarantee a terminator on an overflowed buffer. Rather than adding code + to terminate (and handle zero-sized buffers), move to using snprintf() + instead like all the other vtls backends. - Closes #3005 + Closes #3105 Reviewed-by: Daniel Stenberg - Reviewed-by: Nick Zitzmann - -- [Kruzya brought this change] + Reviewed-by: Viktor Szakats - examples: Fix memory leaks from realloc errors +- TODO: add LD_PRELOAD support on macOS - Make sure to not overwrite the reallocated pointer in realloc() calls - to avoid a memleak on memory errors. + Add DYLD_INSERT_LIBRARIES support to the TODO list. Reported in #2394. -- memory: add missing curl_printf header +- runtests: skip ld_preload tests on macOS - ftp_send_command() was using vsnprintf() without including the libcurl - *rintf() replacement header. Fix by including curl_printf.h and also - add curl_memory.h while at it since memdebug.h depends on it. + The LD_PRELOAD functionality doesn't exist on macOS, so skip any tests + requiring it. - Closes #2999 + Fixes #2394 + Closes #3106 + Reported-by: Github user @jakirkham Reviewed-by: Daniel Stenberg -Daniel Stenberg (16 Sep 2018) -- [Si brought this change] +Marcel Raad (7 Oct 2018) +- AppVeyor: use Debug builds to run tests + + This enables more tests. + + Closes https://github.com/curl/curl/pull/3104 - curl: update --tlsv* descriptions in --help output +- AppVeyor: add HTTP_ONLY build - Closes #2994 + Closes https://github.com/curl/curl/pull/3104 -- http: made Curl_add_buffer functions take a pointer-pointer +- AppVeyor: add WinSSL builds - ... so that they can clear the original pointer on failure, which makes - the error-paths and their cleanups easier. + Use the oldest and latest Windows SDKs for them. + Also, remove all but one OpenSSL build. - Closes #2992 + Closes https://github.com/curl/curl/pull/3104 -- http2: fix memory leaks on error-path +- AppVeyor: add remaining Visual Studio versions + + This adds Visual Studio 9 and 10 builds. + There's no 64-bit VC9 compiler on AppVeyor, so use it as the Win32 + build. Also, VC9 cannot be used for running the test suite. + + Closes https://github.com/curl/curl/pull/3104 -- [Rikard Falkeborn brought this change] +- AppVeyor: break long line + + Closes https://github.com/curl/curl/pull/3104 - libtest: Add chkdecimalpoint to .gitignore +- AppVeyor: remove unused BDIR variable - Closes #2998 + Closes https://github.com/curl/curl/pull/3104 -Viktor Szakats (14 Sep 2018) -- secure Openwall URLs +Daniel Stenberg (6 Oct 2018) +- test2100: test DoH using IPv4-only + + To make it only send one DoH request and avoid the race condition that + could lead to the requests getting sent in reversed order and thus + making it hard to compare in the test case. + + Fixes #3107 + Closes #3108 -Daniel Stenberg (14 Sep 2018) -- openssl: show "proper" version number for libressl builds +- tests/FILEFORMAT: mention how to use and too - Closes #2989 + [ci skip] -- [Rainer Jung brought this change] +- RELEASE-NOTES: synced - openssl: assume engine support in 0.9.8 or later +- [Dmitry Kostjuchenko brought this change] + + timeval: fix use of weak symbol clock_gettime() on Apple platforms - Fixes #2983 - Closes #2988 + Closes #3048 -Daniel Gustafsson (13 Sep 2018) -- sendf: use failf() rather than Curl_failf() +- doh: keep the IPv4 address in (original) network byte order - The failf() macro is the name used for invoking Curl_failf(). While - there isn't a way to turn off failf like there is for infof, but it's - still a good idea to use the macro. + Ideally this will fix the reversed order shown in SPARC tests: - Reviewed-by: Daniel Stenberg + resp 8: Expected 127.0.0.1 got 1.0.0.127 + + Closes #3091 -- sendf: Fix whitespace in infof/failf concatenation +Jay Satiro (5 Oct 2018) +- INTERNALS.md: wrap lines longer than 79 + +Daniel Gustafsson (5 Oct 2018) +- INTERNALS: escape reference to parameter - Strings broken on multiple rows in the .c file need to have appropriate - whitespace padding on either side of the concatenation point to render - a correct amalgamated string. Fix by adding a space at the occurrences - found. + The parameter reference was causing rendering issues in the + generated HTML page, as isn't a valid HTML tag. Fix by back- + tick escaping it. - Closes #2986 + Closes #3099 + Reviewed-by: Jay Satiro Reviewed-by: Daniel Stenberg -- krb5: fix memory leak in krb_auth +- checksrc: handle zero scoped ignore commands - The FTP command allocated by aprintf() must be freed after usage. + If a !checksrc! disable command specified to ignore zero errors, it was + still added to the ignore block even though nothing was ignored. While + there were no blocks ignored that shouldn't be ignored, the processing + ended with with a warning: + + ::: warning: Unused ignore: LONGLINE (UNUSEDIGNORE) + /* !checksrc! disable LONGLINE 0 */ + ^ + Fix by instead treating a zero ignore as a a badcommand and throw a + warning for that one. + Closes #3096 Reviewed-by: Daniel Stenberg -- ftp: include command in Curl_ftpsend sendbuffer +- checksrc: enable strict mode and warnings - Commit 8238ba9c5f10414a88f502bf3f5d5a42d632984c inadvertently removed - the actual command to be sent from the send buffer in a refactoring. - Add back copying the command into the buffer. Also add more guards - against malformed input while at it. + Enable strict and warnings mode for checksrc to ensure we aren't missing + anything due to bugs in the checking code. This uncovered a few things + which are all fixed in this commit: - Closes #2985 + * several variables were used uninitialized + * several variables were not defined in the correct scope + * the whitelist filehandle was read even if the file didn't exist + * the enable_warn() call when a disable counter had expired was passing + incorrect variables, but since the checkwarn() call is unlikely to hit + (the counter is only decremented to zero on actual ignores) it didn't + manifest a problem. + + Closes #3090 Reviewed-by: Daniel Stenberg + Reviewed-by: Marcel Raad -- ntlm_wb: Fix memory leaks in ntlm_wb_response +Marcel Raad (5 Oct 2018) +- CMake: suppress MSVC warning C4127 for libtest - When erroring out on a request being too large, the existing buffer was - leaked. Fix by explicitly freeing on the way out. - - Closes #2966 - Reviewed-by: Daniel Stenberg - -Daniel Stenberg (13 Sep 2018) -- [Yiming Jing brought this change] - - travis: build the MesaLink vtls backend with MesaLink 0.7.1 - -- [Yiming Jing brought this change] + It's issued by older Windows SDKs (prior to version 8.0). - runtests.pl: run tests against the MesaLink vtls backend +Sergei Nikulov (5 Oct 2018) +- Merge branch 'dmitrykos-fix_missing_CMake_defines' -- [Yiming Jing brought this change] +- [Dmitry Kostjuchenko brought this change] - vtls: add a MesaLink vtls backend + cmake: test and set missed defines during configuration - Closes #2984 - -- [Yiming Jing brought this change] - - configure.ac: add a MesaLink vtls backend + Added configuration checks for HAVE_BUILTIN_AVAILABLE and HAVE_CLOCK_GETTIME_MONOTONIC. + + Closes #3097 -- [Dave Reisner brought this change] +Marcel Raad (5 Oct 2018) +- AppVeyor: disable test 500 + + It almost always results in + "starttransfer vs total: 0.000001 0.000000". + I cannot reproduce this locally, so disable it for now. + + Closes https://github.com/curl/curl/pull/3100 - curl_url_set.3: properly escape \n in example code +- AppVeyor: set custom install prefix - This yields + CMake's default has spaces and in 32-bit mode parentheses, which result + in syntax errors in curl-config. - "the scheme is %s\n" + Closes https://github.com/curl/curl/pull/3100 + +- AppVeyor: Remove non-SSL non-test builds - instead of + They don't add much value. - "the scheme is %s0 + Closes https://github.com/curl/curl/pull/3100 + +- AppVeyor: run test suite - Closes #2970 + Use the preinstalled MSYS2 bash for that. + Disable test 1139 as the CMake build doesn't generate curl.1. + + Ref: https://github.com/curl/curl/issues/3070#issuecomment-425922224 + Closes https://github.com/curl/curl/pull/3100 -- [Dave Reisner brought this change] +- AppVeyor: use in-tree build + + Required to run the tests. + + Closes https://github.com/curl/curl/pull/3100 - curl_url_set.3: fix typo in reference to CURLU_APPENDQUERY +Daniel Stenberg (4 Oct 2018) +- doh: make sure TTL isn't re-inited by second (discarded?) response + + Closes #3092 -- urlglob: improve error message +- test320: strip out more HTML when comparing - to help user understand what the problem is + To make the test case work with different gnutls-serv versions better. - Reported-by: Daniel Shahaf + Reported-by: Kamil Dudka + Fixes #3093 + Closes #3094 + +Marcel Raad (4 Oct 2018) +- runtests: use Windows paths for Windows curl - Fixes #2763 - Closes #2977 + curl generated by CMake's Visual Studio generator has "Windows" in the + version number. -- [Yiming Jing brought this change] +Daniel Stenberg (4 Oct 2018) +- [Colin Hogben brought this change] - tests/certs: rebuild certs with 2048-bit RSA keys - - The previous test certificates contained RSA keys of only 1024 bits. - However, RSA claims that 1024-bit RSA keys are likely to become - crackable some time before 2010. The NIST recommends at least 2048-bit - keys for RSA for now. + tests/negtelnetserver.py: fix Python2-ism in neg TELNET server - Better use full 2048 also for testing. + Fix problems caused by differences in treatment of bytes objects between + python2 and python3. - Closes #2973 + Fixes #2929 + Closes #3080 -Daniel Gustafsson (12 Sep 2018) -- TODO: fix typo in item +Daniel Gustafsson (3 Oct 2018) +- memory: ensure to check allocation results - Closes #2968 + The result of a memory allocation should always be checked, as we may + run under memory pressure where even a small allocation can fail. This + adds checking and error handling to a few cases where the allocation + wasn't checked for success. In the ftp case, the freeing of the path + variable is moved ahead of the allocation since there is little point + in keeping it around across the strdup, and the separation makes for + more readable code. In nwlib, the lock is aslo freed in the error path. + + Also bumps the copyright years on affected files. + + Closes #3084 + Reviewed-by: Jay Satiro Reviewed-by: Daniel Stenberg -Marcel Raad (12 Sep 2018) -- anyauthput: fix compiler warning on 64-bit Windows +- comment: Fix multiple typos in function parameters - On Windows, the read function from is used, which has its byte - count parameter as unsigned int instead of size_t. + Ensure that the parameters in the comment match the actual names in the + prototype. - Closes https://github.com/curl/curl/pull/2972 + Closes #3079 + Reviewed-by: Daniel Stenberg -Viktor Szakats (12 Sep 2018) -- lib: fix gcc8 warning on Windows +- CURLOPT_SSLVERSION.3: fix typos and consistent spelling - Closes https://github.com/curl/curl/pull/2979 - -Jay Satiro (12 Sep 2018) -- openssl: fix gcc8 warning + Use TLS vX.Y throughout the document, instead of TLS X.Y, as that was + already done in all but a few cases. Also fix a few typos. - - Use memcpy instead of strncpy to copy a string without termination, - since gcc8 warns about using strncpy to copy as many bytes from a - string as its length. + Closes #3076 + Reviewed-by: Marcel Raad + Reviewed-by: Daniel Stenberg + +- SECURITY-PROCESS: make links into hyperlinks - Suggested-by: Viktor Szakats + Use proper Markdown hyperlink format for the Bountygraph links in order + for the generated website page to be more user friendly. Also link to + the sponsors to give them a little extra credit. - Closes https://github.com/curl/curl/issues/2980 + Closes #3082 + Reviewed-by: Daniel Stenberg -Daniel Stenberg (10 Sep 2018) -- libcurl-url.3: overview man page for the URL API - - Closes #2967 +Jay Satiro (3 Oct 2018) +- CURLOPT_HEADER.3: fix typo -- example/asiohiper: insert warning comment about its status +- nss: fix nssckbi module loading on Windows - This example is simply not working correctly but there's nobody around - with the skills and energy to fix it. + - Use .DLL extension instead of .so to load modules on Windows. - Closes #2407 - -Kamil Dudka (10 Sep 2018) -- docs/cmdline-opts: update the documentation of --tlsv1.0 + Bug: https://curl.haxx.se/mail/lib-2018-09/0077.html + Reported-by: Maxime Legros - ... to reflect the changes in 6015cefb1b2cfde4b4850121c42405275e5e77d9 + Ref: https://github.com/curl/curl/pull/3016/#issuecomment-423069442 - Closes #2955 + Closes https://github.com/curl/curl/pull/3086 -- docs/examples: do not wait when no transfers are running +- data-binary.d: clarify default content-type is x-www-form-urlencoded - Closes #2948 - -Daniel Stenberg (10 Sep 2018) -- [Daniel Gustafsson brought this change] - - cookies: Move failure case label to end of function + - Advise user that --data-binary sends a default content type of + x-www-form-urlencoded, and to have the data treated as arbitrary + binary data by the server set the content-type header to octet-stream. - Rather than jumping backwards to where failure cleanup happens - to be performed, move the failure case to end of the function - where it is expected per existing coding convention. + Ref: https://github.com/curl/curl/pull/2852#issuecomment-426465094 - Closes #2965 - -- [Daniel Gustafsson brought this change] + Closes https://github.com/curl/curl/pull/3085 - misc: fix typos in comments +Marcel Raad (2 Oct 2018) +- test1299: use single quotes around asterisk - Closes #2963 - -- [Daniel Gustafsson brought this change] + Ref: https://github.com/curl/curl/issues/1751#issuecomment-321522580 - cookies: fix leak when writing cookies to file - - If the formatting fails, we error out on a fatal error and - clean up on the way out. The array was however freed within - the wrong scope and was thus never freed in case the cookies - were written to a file instead of STDOUT. +Daniel Stenberg (2 Oct 2018) +- docs/CIPHERS: mention the colon separation for OpenSSL - Closes #2957 - -- [Daniel Gustafsson brought this change] + Bug: #3077 - cookies: Remove redundant expired check +- runtests: ignore disabled even when ranges are given - Expired cookies have already been purged at a later expiration time - before this check, so remove the redundant check. + runtests.pl support running a range of tests, like "44 to 127". Starting + now, the code makes sure that even such given ranges will ignore tests + that are marked as disabled. - closes #2962 + Disabled tests can still be run by explictly specifying that test + number. + + Closes #3075 -- ntlm_wb: bail out if the response gets overly large +- urlapi: starting with a drive letter on win32 is not an abs url - Exit the realloc() loop if the response turns out ridiculously large to - avoid worse problems. + ... and libcurl doesn't support any single-letter URL schemes (if there + even exist any) so it should be fairly risk-free. - Reported-by: Harry Sintonen - Closes #2959 - -- [Daniel Gustafsson brought this change] - - url.c: fix comment typo and indentation + Reported-by: Marcel Raad - Closes #2960 + Fixes #3070 + Closes #3071 -- urlapi: avoid derefencing a possible NULL pointer +Marcel Raad (2 Oct 2018) +- doh: fix curl_easy_setopt argument type - Coverity CID 1439134 + CURLOPT_POSTFIELDSIZE is long. Fixes a compiler warning on 64-bit + MinGW. +Daniel Stenberg (2 Oct 2018) - RELEASE-NOTES: synced -Marcel Raad (8 Sep 2018) -- test324: fix after 3f3b26d6feb0667714902e836af608094235fca2 - - The expected error code is now 60. 51 is dead. - -Daniel Stenberg (8 Sep 2018) -- curl_url_set.3: correct description - -- curl_url-docs: fix AVAILABILITY as Added in curl 7.62.0 +Jay Satiro (1 Oct 2018) +- [Ruslan Baratov brought this change] -- URL-API + CMake: Improve config installation - See header file and man pages for API. All documented API details work - and are tested in the 1560 test case. + Use 'GNUInstallDirs' standard module to set destinations of installed + files. - Closes #2842 + Use uppercase "CURL" names instead of lowercase "curl" to match standard + 'FindCURL.cmake' CMake module: + * https://cmake.org/cmake/help/latest/module/FindCURL.html + + Meaning: + * Install 'CURLConfig.cmake' instead of 'curl-config.cmake' + * User should call 'find_package(CURL)' instead of 'find_package(curl)' + + Use 'configure_package_config_file' function to generate + 'CURLConfig.cmake' file. This will make 'curl-config.cmake.in' template + file smaller and handle components better. E.g. current configuration + report no error if user specified unknown components (note: new + configuration expects no components, report error if user will try to + specify any). + + Closes https://github.com/curl/curl/pull/2849 -- curl_easy_upkeep: removed 'conn' from the name +Daniel Stenberg (1 Oct 2018) +- test1650: make it depend on http/2 - ... including the associated option. + Follow-up to 570008c99da0ccbb as it gets link errors. - Fixes #2951 - Closes #2952 + Reported-by: Michael Kaufmann + Closes #3068 -- [Max Dymond brought this change] +- [Nate Prewitt brought this change] - upkeep: add a connection upkeep API: curl_easy_conn_upkeep() - - Add functionality so that protocols can do custom keepalive on their - connections, when an external API function is called. + MANUAL: minor grammar fix - Add docs for the new options in 7.62.0 + Noticed a typo reading through the docs. - Closes #1641 - -- [Philipp Waehnert brought this change] + Closes #3069 - configure: add option to disable automatic OpenSSL config loading +- doh: only build if h2 enabled - Sometimes it may be considered a security risk to load an external - OpenSSL configuration automatically inside curl_global_init(). The - configuration option --disable-ssl-auto-load-config disables this - automatism. The Windows build scripts winbuild/Makefile.vs provide a - corresponding option ENABLE_SSL_AUTO_LOAD_CONFIG accepting a boolean - value. + The DoH spec says "HTTP/2 [RFC7540] is the minimum RECOMMENDED version + of HTTP for use with DoH". - Setting neither of these options corresponds to the previous behavior - loading the external OpenSSL configuration automatically. + Reported-by: Marcel Raad + Closes #3066 + +- test2100: require http2 to run - Fixes #2724 - Closes #2791 + Reported-by: Marcel Raad + Fixes #3064 + Closes #3065 -- doh: minor edits to please Coverity +- multi: fix memory leak in content encoding related error path - The gcc typecheck macros and coverity combined made it warn on the 2nd - argument for ERROR_CHECK_SETOPT(). Here's minor rearrange to please it. + ... a missing multi_done() call. - Coverity CID 1439115 and CID 1439114. + Credit to OSS-Fuzz + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10728 + Closes #3063 -- schannel: avoid switch-cases that go to default anyway +- travis: bump the Secure Transport build to use xcode 10 - SEC_E_APPLICATION_PROTOCOL_MISMATCH isn't defined in some versions of - mingw and would require an ifdef otherwise. + Due to an issue with travis + (https://github.com/travis-ci/travis-ci/issues/9956) we've been using + Xcode 9.2 for darwinssl builds for a while. Now xcode 10 is offered as + an alternative and as it builds curl+darwinssl fine that seems like a + better choice. - Reported-by: Thomas Glanzmann - Approved-by: Marc Hörsken - Bug: https://curl.haxx.se/mail/lib-2018-09/0020.html - Closes #2950 + Closes #3062 -- [Nicklas Avén brought this change] +- [Rich Turner brought this change] - imap: change from "FETCH" to "UID FETCH" - - ... and add "MAILINDEX". + curl: enabled Windows VT Support and UTF-8 output - As described in #2789, this is a suggested solution. Changing UID=xx to - actually get mail with UID xx and add "MAILINDEX" to get a mail with a - special index in the mail box (old behavior). So MAILINDEX=1 gives the - first non deleted mail in the mail box. + Enabled Console VT support (if running OS supports VT) in tool_main.c. - Fixes #2789 - Closes #2815 + Fixes #3008 + Closes #3011 -- CURLOPT_UPLOAD_BUFFERSIZE: set upload buffer size - - This is step 3 of #2888. +- multi: fix location URL memleak in error path - Fixes #2888 - Closes #2896 - -- travis: add the DOH tests to the torture testing + Follow-up to #3044 - fix a leak OSS-Fuzz detected + Closes #3057 -- DOH: add test case 1650 and 2100 +Sergei Nikulov (28 Sep 2018) +- cmake: fixed path used in generation of docs/tests during curl build through add_subdicectory(...) -- curl: --doh-url added +- [Brad King brought this change] -- setopt: add CURLOPT_DOH_URL + cmake: Backport to work with CMake 3.0 again - Closes #2668 - -- [Han Han brought this change] - - ssl: deprecate CURLE_SSL_CACERT in favour of a unified error code + Changes in commit 7867aaa9a0 (cmake: link curl to the OpenSSL targets + instead of lib absolute paths, 2018-07-17) and commit f826b4ce98 (cmake: + bumped minimum version to 3.4, 2018-07-19) required CMake 3.4 to fix + issue #2746. This broke support for users on older versions of CMake + even if they just want to build curl and do not care whether transitive + dependencies work. - Long live CURLE_PEER_FAILED_VERIFICATION - -- [Han Han brought this change] + Backport the logic to work with CMake 3.0 again by implementing the + fix only when the version of CMake is at least 3.4. - x509asn1: return CURLE_PEER_FAILED_VERIFICATION on failure to parse cert +Marcel Raad (27 Sep 2018) +- curl_threads: fix classic MinGW compile break - CURLE_PEER_FAILED_VERIFICATION makes more sense because Curl_parseX509 - does not allocate memory internally as its first argument is a pointer - to the certificate structure. The same error code is also returned by - Curl_verifyhost when its call to Curl_parseX509 fails so the change - makes error handling more consistent. - -- [Han Han brought this change] + Classic MinGW still has _beginthreadex's return type as unsigned long + instead of uintptr_t [0]. uintptr_t is not even defined because of [1]. + + [0] https://sourceforge.net/p/mingw/mingw-org-wsl/ci/wsl-5.1-release/tree/mingwrt/include/process.h#l167 + [1] https://sourceforge.net/p/mingw/mingw-org-wsl/ci/wsl-5.1-release/tree/mingwrt/include/process.h#l90 + + Bug: https://github.com/curl/curl/issues/2924#issuecomment-424334807 + Closes https://github.com/curl/curl/pull/3051 - openssl: return CURLE_PEER_FAILED_VERIFICATION on failure to parse issuer +Daniel Stenberg (26 Sep 2018) +- configure: s/AC_RUN_IFELSE/CURL_RUN_IFELSE - Failure to extract the issuer name from the server certificate should - return a more specific error code like on other TLS backends. + fix a few leftovers + + Fixes #3006 + Closes #3049 -- [Han Han brought this change] +- [Doron Behar brought this change] - schannel: unified error code handling + example/htmltidy: fix include paths of tidy libraries - Closes #2901 + Closes #3050 -- [Han Han brought this change] +- RELEASE-NOTES: synced - darwinssl: more specific and unified error codes +- Curl_http2_done: fix memleak in error path - Closes #2901 - -- CURLOPT_DNS_USE_GLOBAL_CACHE: deprecated + Free 'header_recvbuf' unconditionally even if 'h2' isn't (yet) set, for + early failures. - Disable the CURLOPT_DNS_USE_GLOBAL_CACHE option and mark it for - deprecation and complete removal in six months. + Detected by OSS-Fuzz - Bug: https://curl.haxx.se/mail/lib-2018-09/0010.html - Closes #2942 + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10669 + Closes #3046 -- url: default to CURL_HTTP_VERSION_2TLS if built h2-enabled +- http: fix memleak in rewind error path - Closes #2709 - -- multiplex: enable by default + If the rewind would fail, a strdup() would not get freed. - Starting 7.62.0, multiplexing is enabled by default in multi handles. - -- [Jim Fuller brought this change] - - tests: add unit tests for url.c + Detected by OSS-Fuzz - Approved-by: Daniel Gustafsson - Closes #2937 + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10665 + Closes #3044 -- test1452: mark as flaky +Viktor Szakats (24 Sep 2018) +- test320: fix regression in [ci skip] - makes it not run in the CI builds + The value in question is coming directly from `gnutls-serv`, so it cannot + be modified freely. - Closes #2941 + Reported-by: Marcel Raad + Ref: https://github.com/curl/curl/commit/6ae6b2a533e8630afbb21f570305bd4ceece6348#commitcomment-30621004 -- pipelining: deprecated +Daniel Stenberg (24 Sep 2018) +- Curl_retry_request: fix memory leak - Transparently. The related curl_multi_setopt() options all still returns - OK when pipelining is selected. + Detected by OSS-Fuzz - To re-enable the support, the single line change in lib/multi.c needs to - be reverted. + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10648 + Closes #3042 + +- openssl: load built-in engines too - See docs/DEPRECATE.md + Regression since 38203f1 - Closes #2705 - -- RELEASE-NOTES: start working on 7.62.0 - -Version 7.61.1 (4 Sep 2018) - -Daniel Stenberg (4 Sep 2018) -- THANKS: 7.61.1 status + Reported-by: Jean Fabrice + Fixes #3023 + Closes #3040 -- RELEASE-NOTES: 7.61.1 +- [Christian Heimes brought this change] -- Curl_getoff_all_pipelines: ignore unused return values + OpenSSL: enable TLS 1.3 post-handshake auth - Since scan-build would warn on the dead "Dead store/Dead increment" - -Viktor Szakats (4 Sep 2018) -- sftp: fix indentation + OpenSSL 1.1.1 requires clients to opt-in for post-handshake + authentication. + + Fixes: https://github.com/curl/curl/issues/3026 + Signed-off-by: Christian Heimes + + Closes https://github.com/curl/curl/pull/3027 -Daniel Stenberg (4 Sep 2018) -- [Przemysław Tomaszewski brought this change] +- [Even Rouault brought this change] - sftp: don't send post-qoute sequence when retrying a connection + Curl_dedotdotify(): always nul terminate returned string. - Fixes #2939 - Closes #2940 - -Kamil Dudka (3 Sep 2018) -- url, vtls: make CURLOPT{,_PROXY}_TLS13_CIPHERS work + This fixes potential out-of-buffer access on "file:./" URL - This is a follow-up to PR #2607 and PR #2926. + $ valgrind curl "file:./" + ==24516== Memcheck, a memory error detector + ==24516== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al. + ==24516== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info + ==24516== Command: /home/even/install-curl-git/bin/curl file:./ + ==24516== + ==24516== Conditional jump or move depends on uninitialised value(s) + ==24516== at 0x4C31F9C: strcmp (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) + ==24516== by 0x4EBB315: seturl (urlapi.c:801) + ==24516== by 0x4EBB568: parseurl (urlapi.c:861) + ==24516== by 0x4EBC509: curl_url_set (urlapi.c:1199) + ==24516== by 0x4E644C6: parseurlandfillconn (url.c:2044) + ==24516== by 0x4E67AEF: create_conn (url.c:3613) + ==24516== by 0x4E68A4F: Curl_connect (url.c:4119) + ==24516== by 0x4E7F0A4: multi_runsingle (multi.c:1440) + ==24516== by 0x4E808E5: curl_multi_perform (multi.c:2173) + ==24516== by 0x4E7558C: easy_transfer (easy.c:686) + ==24516== by 0x4E75801: easy_perform (easy.c:779) + ==24516== by 0x4E75868: curl_easy_perform (easy.c:798) - Closes #2936 - -Daniel Stenberg (3 Sep 2018) -- [Jay Satiro brought this change] + Was originally spotted by + https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10637 + Credit to OSS-Fuzz + + Closes #3039 - tool_operate: Add http code 408 to transient list for --retry +Viktor Szakats (23 Sep 2018) +- update URLs in tests - - Treat 408 request timeout as transient so that curl will retry the - request if --retry was used. + - and one in docs/MANUAL as well - Closes #2925 - -- [Jay Satiro brought this change] + Closes https://github.com/curl/curl/pull/3038 - openssl: Fix setting TLS 1.3 cipher suites - - The flag indicating TLS 1.3 cipher support in the OpenSSL backend was - missing. +- whitespace fixes - Bug: https://github.com/curl/curl/pull/2607#issuecomment-417283187 - Reported-by: Kamil Dudka + - replace tabs with spaces where possible + - remove line ending spaces + - remove double/triple newlines at EOF + - fix a non-UTF-8 character + - cleanup a few indentations/line continuations + in manual examples - Closes #2926 + Closes https://github.com/curl/curl/pull/3037 -- Curl_ntlm_core_mk_nt_hash: return error on too long password +Daniel Stenberg (23 Sep 2018) +- http: add missing return code check - ... since it would cause an integer overflow if longer than (max size_t - / 2). + Detected by Coverity. CID 1439610. - This is CVE-2018-14618 + Follow-up from 46e164069d1a523 - Bug: https://curl.haxx.se/docs/CVE-2018-14618.html - Closes #2756 - Reported-by: Zhaoyang Wu - -- [Rikard Falkeborn brought this change] + Closes #3034 - http2: Use correct format identifier for stream_id +- ftp: don't access pointer before NULL check - Closes #2928 + Detected by Coverity. CID 1439611. + + Follow-up from 46e164069d1a523 -Marcel Raad (2 Sep 2018) -- test1148: fix precheck output +- unit1650: fix out of boundary access - "precheck command error" is not very helpful. + Fixes #2987 + Closes #3035 -Daniel Stenberg (1 Sep 2018) -- all: s/int/size_t cleanup +Viktor Szakats (23 Sep 2018) +- docs/examples: URL updates - Assisted-by: Rikard Falkeborn + - also update two URLs outside of docs/examples + - fix spelling of filename persistant.c + - fix three long lines that started failing checksrc.pl - Closes #2922 - -- ssh-libssh: use FALLTHROUGH to silence gcc8 - -Jay Satiro (31 Aug 2018) -- tool_operate: Fix setting proxy TLS 1.3 ciphers - -Daniel Stenberg (31 Aug 2018) -- [Daniel Gustafsson brought this change] + Closes https://github.com/curl/curl/pull/3036 - cookies: support creation-time attribute for cookies +- examples/Makefile.m32: sync with core [ci skip] - According to RFC6265 section 5.4, cookies with equal path lengths - SHOULD be sorted by creation-time (earlier first). This adds a - creation-time record to the cookie struct in order to make cookie - sorting more deterministic. The creation-time is defined as the - order of the cookies in the jar, the first cookie read fro the - jar being the oldest. The creation-time is thus not serialized - into the jar. Also remove the strcmp() matching in the sorting as - there is no lexicographic ordering in RFC6265. Existing tests are - updated to match. + also: + - fix two warnings in synctime.c (one of them Windows-specific) + - upgrade URLs in synctime.c and remove a broken one - Closes #2524 + Closes https://github.com/curl/curl/pull/3033 -Marcel Raad (31 Aug 2018) -- Don't use Windows path %PWD for SSH tests - - All these tests failed on Windows because something like - sftp://%HOSTIP:%SSHPORT%PWD/ - expanded to - sftp://127.0.0.1:1234c:/msys64/home/bla/curl - and then curl complained about the port number ending with a letter. +Daniel Stenberg (22 Sep 2018) +- examples/parseurl.c: show off the URL API a bit - Use the original POSIX path instead of the Windows path created in - checksystem to fix this. + Closes #3030 + +- SECURITY-PROCESS: mention the bountygraph program [ci skip] - Closes https://github.com/curl/curl/pull/2920 + Closes #3032 -Jay Satiro (29 Aug 2018) -- CURLOPT_SSL_CTX_FUNCTION.3: clarify connection reuse warning +- url: use the URL API internally as well - Reported-by: Daniel Stenberg + ... to make it a truly unified URL parser. - Closes https://github.com/curl/curl/issues/2916 + Closes #3017 -Daniel Stenberg (28 Aug 2018) -- THANKS-filter: dedup Daniel Jeliński +Viktor Szakats (22 Sep 2018) +- URL and mailmap updates, remove an obsolete directory [ci skip] + + Closes https://github.com/curl/curl/pull/3031 +Daniel Stenberg (22 Sep 2018) - RELEASE-NOTES: synced -- CURLOPT_ACCEPT_ENCODING.3: list them comma-separated [ci skip] - -- CURLOPT_SSL_CTX_FUNCTION.3: might cause unintended connection reuse [ci skip] +- configure: force-use -lpthreads on HPUX - Added a warning! + When trying to detect pthreads use on HPUX the checks will succeed + without the correct -l option but then end up failing at run-time. - Closes #2915 + Reported-by: Eason-Yu on github + Fixes #2697 + Closes #3025 -- curl: fix time-of-check, time-of-use race in dir creation - - Patch-by: Jay Satiro - Detected by Coverity - Fixes #2739 - Closes #2912 +- [Erik Minekus brought this change] -- cmdline-opts/page-footer: fix edit mistake - - There was a missing newline. + Curl_saferealloc: Fixed typo in docblock - follow-up to a7ba60bb7250 + Closes #3029 -- docs: clarify NO_PROXY env variable functionality +- urlapi: fix support for address scope in IPv6 numerical addresses - Reported-by: Kirill Marchuk - Fixes #2773 - Closes #2911 + Closes #3024 -Marcel Raad (24 Aug 2018) -- lib1522: fix curl_easy_setopt argument type +- [Loganaden Velvindron brought this change] + + GnutTLS: TLS 1.3 support - CURLOPT_POSTFIELDSIZE is a long option. + Closes #2971 -- curl_threads: silence bad-function-cast warning +- TODO: c-ares and CURLOPT_OPENSOCKETFUNCTION - As uintptr_t and HANDLE are always the same size, this warning is - harmless. Just silence it using an intermediate uintptr_t variable. + Removed DoH. - Closes https://github.com/curl/curl/pull/2908 + Closes #2734 -Daniel Stenberg (24 Aug 2018) -- README: add appveyor build badge [ci skip] +Jay Satiro (20 Sep 2018) +- vtls: fix ssl version "or later" behavior change for many backends - Closes #2913 - -- [Ihor Karpenko brought this change] - - schannel: client certificate store opening fix + - Treat CURL_SSLVERSION_MAX_NONE the same as + CURL_SSLVERSION_MAX_DEFAULT. Prior to this change NONE would mean use + the minimum version also as the maximum. - 1) Using CERT_STORE_OPEN_EXISTING_FLAG ( or CERT_STORE_READONLY_FLAG ) - while opening certificate store would be sufficient in this scenario and - less-demanding in sense of required user credentials ( for example, - IIS_IUSRS will get "Access Denied" 0x05 error for existing CertOpenStore - call without any of flags mentioned above ), + This is a follow-up to 6015cef which changed the behavior of setting + the SSL version so that the requested version would only be the minimum + and not the maximum. It appears it was (mostly) implemented in OpenSSL + but not other backends. In other words CURL_SSLVERSION_TLSv1_0 used to + mean use just TLS v1.0 and now it means use TLS v1.0 *or later*. - 2) as 'cert_store_name' is a DWORD, attempt to format its value like a - string ( in "Failed to open cert store" error message ) will throw null - pointer exception + - Fix CURL_SSLVERSION_MAX_DEFAULT for OpenSSL. - 3) adding GetLastError(), in my opinion, will make error message more - useful. + Prior to this change CURL_SSLVERSION_MAX_DEFAULT with OpenSSL was + erroneously treated as always TLS 1.3, and would cause an error if + OpenSSL was built without TLS 1.3 support. - Bug: https://curl.haxx.se/mail/lib-2018-08/0198.html + Co-authored-by: Daniel Gustafsson - Closes #2909 - -- [Leonardo Taccari brought this change] + Fixes https://github.com/curl/curl/issues/2969 + Closes https://github.com/curl/curl/pull/3012 - gopher: Do not translate `?' to `%09' +Daniel Stenberg (20 Sep 2018) +- certs: generate tests certs with sha256 digest algorithm - Since GOPHER support was added in curl `?' character was automatically - translated to `%09' (`\t'). + As OpenSSL 1.1.1 starts to complain and fail on sha1 CAs: - However, this behaviour does not seems documented in RFC 4266 and for - search selectors it is documented to directly use `%09' in the URL. - Apart that several gopher servers in the current gopherspace have CGI - support where `?' is used as part of the selector and translating it to - `%09' often leads to surprising results. + "SSL certificate problem: CA signature digest algorithm too weak" - Closes #2910 + Closes #3014 -Marcel Raad (23 Aug 2018) -- cookie tests: treat files as text +- urlapi: document the error codes, remove two unused ones - Fixes test failures because of wrong line endings on Windows. + Assisted-by: Daniel Gustafsson + Closes #3019 -Daniel Stenberg (23 Aug 2018) -- libcurl-thread.3: expand somewhat on the NO_SIGNAL motivation +- urlapi: add CURLU_GUESS_SCHEME and fix hostname acceptance - Multi-threaded applictions basically MUST set CURLOPT_NO_SIGNAL to 1L to - avoid the risk of getting a SIGPIPE. + In order for this API to fully work for libcurl itself, it now offers a + CURLU_GUESS_SCHEME flag that makes it "guess" scheme based on the host + name prefix just like libcurl always did. If there's no known prefix, it + will guess "http://". - Either way, a multi-threaded application that uses libcurl/openssl needs - to have a signhandler for or ignore SIGPIPE on its own. + Separately, it relaxes the check of the host name so that IDN host names + can be passed in as well. - Based on discussions in #2800 - Closes #2904 - -- RELEASE-NOTES: synced - -Marcel Raad (22 Aug 2018) -- Tests: fixes for Windows + Both these changes are necessary for libcurl itself to use this API. - - test 1268 requires unix sockets - - test 2072 must be disabled also for MSYS/MinGW + Assisted-by: Daniel Gustafsson + Closes #3018 -Daniel Stenberg (22 Aug 2018) -- http2: abort the send_callback if not setup yet - - When Curl_http2_done() gets called before the http2 data is setup all - the way, we cannot send anything and this should just return an error. +Kamil Dudka (19 Sep 2018) +- nss: try to connect even if libnssckbi.so fails to load - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10012 - -- http2: remove four unused nghttp2 callbacks + One can still use CA certificates stored in NSS database. - Closes #2903 - -- x509asn1: use FALLTHROUGH + Reported-by: Maxime Legros + Bug: https://curl.haxx.se/mail/lib-2018-09/0077.html - ... as no other comments are accepted since 014ed7c22f51463 + Closes #3016 -Marcel Raad (21 Aug 2018) -- test1148: disable if decimal separator is not point +Daniel Gustafsson (19 Sep 2018) +- urlapi: don't set value which is never read - Modifying the locale with environment variables doesn't work for native - Windows applications. Just disable the test in this case if the decimal - separator is something different than a point. Use a precheck with a - small C program to achieve that. + In the CURLUPART_URL case, there is no codepath which invokes url + decoding so remove the assignment of the urldecode variable. This + fixes the deadstore bug-report from clang static analysis. - Closes https://github.com/curl/curl/pull/2786 + Closes #3015 + Reviewed-by: Daniel Stenberg -- Enable more GCC warnings +- todo: Update reference to already done item - This enables the following additional warnings: - -Wold-style-definition - -Warray-bounds=2 instead of the default 1 - -Wformat=2, but only for GCC 4.8+ as Wno-format-nonliteral is not - respected for older versions - -Wunused-const-variable, which enables level 2 instead of the default 1 - -Warray-bounds also in debug mode through -ftree-vrp - -Wnull-dereference also in debug mode through - -fdelete-null-pointer-checks + TODO item 1.1 was implemented in commit 946ce5b61f, update reference + to it with instead referencing the implemented option. - Closes https://github.com/curl/curl/pull/2747 + Closes #3013 + Reviewed-by: Daniel Stenberg -- curl-compilers: enable -Wimplicit-fallthrough=4 for GCC +Daniel Stenberg (18 Sep 2018) +- RELEASE-NOTES: synced + +- [slodki brought this change] + + cmake: don't require OpenSSL if USE_OPENSSL=OFF - This enables level 4 instead of the default level 3, which of the - currently used comments only allows /* FALLTHROUGH */ to silence the - warning. + User must have OpenSSL installed even if not used by libcurl at all + since 7.61.1 release. Broken at + 7867aaa9a01decf93711428462335be8cef70212 - Closes https://github.com/curl/curl/pull/2747 + Reviewed-by: Sergei Nikulov + Closes #3001 -- curl-compilers: enable -Wbad-function-cast on GCC +- curl_multi_wait: call getsock before figuring out timeout - This warning used to be enabled only for clang as it's a bit stricter - on GCC. Silence the remaining occurrences and enable it on GCC too. + .... since getsock may update the expiry timer. - Closes https://github.com/curl/curl/pull/2747 + Fixes #2996 + Closes #3000 -- configure: conditionally enable pedantic-errors - - Enable pedantic-errors for GCC >= 5 with --enable-werror. Before GCC 5, - pedantic-errors was synonymous to -Werror=pedantic [0], which is still - the case for clang [1]. With GCC 5, it became complementary [2]. +- examples/http2-pushinmemory: receive HTTP/2 pushed files in memory - Also fix a resulting error in acinclude.m4 as main's return type was - missing, which is illegal in C99. + Closes #3004 + +Daniel Gustafsson (18 Sep 2018) +- darwinssl: Fix realloc memleak - [0] https://gcc.gnu.org/onlinedocs/gcc-4.9.0/gcc/Warning-Options.html - [1] https://clang.llvm.org/docs/UsersManual.html#options-to-control-error-and-warning-messages - [2] https://gcc.gnu.org/onlinedocs/gcc-5.1.0/gcc/Warning-Options.html + The reallocation was using the input pointer for the return value, which + leads to a memory leak on reallication failure. Fix by instead use the + safe internal API call Curl_saferealloc(). - Closes https://github.com/curl/curl/pull/2747 + Closes #3005 + Reviewed-by: Daniel Stenberg + Reviewed-by: Nick Zitzmann -- Remove unused definitions - - Closes https://github.com/curl/curl/pull/2747 +- [Kruzya brought this change] -Daniel Stenberg (21 Aug 2018) -- x509asn1: make several functions static - - and remove the private SIZE_T_MAX define and use the generic one. + examples: Fix memory leaks from realloc errors - Closes #2902 + Make sure to not overwrite the reallocated pointer in realloc() calls + to avoid a memleak on memory errors. -- INTERNALS: require GnuTLS >= 2.11.3 +- memory: add missing curl_printf header - Since the public pinning support was brought in e644866caf4. GnuTLS - 2.11.3 was released in October 2010. + ftp_send_command() was using vsnprintf() without including the libcurl + *rintf() replacement header. Fix by including curl_printf.h and also + add curl_memory.h while at it since memdebug.h depends on it. - Figured out in #2890 + Closes #2999 + Reviewed-by: Daniel Stenberg -- http2: avoid set_stream_user_data() before stream is assigned - - ... before the stream is started, we have it set to -1. +Daniel Stenberg (16 Sep 2018) +- [Si brought this change] + + curl: update --tlsv* descriptions in --help output - Fixes #2894 - Closes #2898 + Closes #2994 -- SSLCERTS: improve the openssl command line +- http: made Curl_add_buffer functions take a pointer-pointer - ... for extracting certs from a live HTTPS server to make a cacerts.pem - from them. + ... so that they can clear the original pointer on failure, which makes + the error-paths and their cleanups easier. + + Closes #2992 -- docs/SECURITY-PROCESS: now we name the files after the CVE id +- http2: fix memory leaks on error-path -- RELEASE-NOTES: synced +- [Rikard Falkeborn brought this change] -- upload: change default UPLOAD_BUFSIZE to 64KB - - To make uploads significantly faster in some circumstances. + libtest: Add chkdecimalpoint to .gitignore - Part 2 of #2888 - Closes #2892 + Closes #2998 -- upload: allocate upload buffer on-demand - - Saves 16KB on the easy handle for operations that don't need that - buffer. +Viktor Szakats (14 Sep 2018) +- secure Openwall URLs + +Daniel Stenberg (14 Sep 2018) +- openssl: show "proper" version number for libressl builds - Part 1 of #2888 + Closes #2989 -- [Laurent Bonnans brought this change] +- [Rainer Jung brought this change] - vtls: reinstantiate engine on duplicated handles - - Handles created with curl_easy_duphandle do not use the SSL engine set - up in the original handle. This fixes the issue by storing the engine - name in the internal url state and setting the engine from its name - inside curl_easy_duphandle. + openssl: assume engine support in 0.9.8 or later - Reported-by: Anton Gerasimov - Signed-of-by: Laurent Bonnans - Fixes #2829 - Closes #2833 + Fixes #2983 + Closes #2988 -- http2: make sure to send after RST_STREAM +Daniel Gustafsson (13 Sep 2018) +- sendf: use failf() rather than Curl_failf() - If this is the last stream on this connection, the RST_STREAM might not - get pushed to the wire otherwise. + The failf() macro is the name used for invoking Curl_failf(). While + there isn't a way to turn off failf like there is for infof, but it's + still a good idea to use the macro. - Fixes #2882 - Closes #2887 - Researched-by: Michael Kaufmann + Reviewed-by: Daniel Stenberg -- test1268: check the stderr output as "text" +- sendf: Fix whitespace in infof/failf concatenation - Follow-up to 099f37e9c57 + Strings broken on multiple rows in the .c file need to have appropriate + whitespace padding on either side of the concatenation point to render + a correct amalgamated string. Fix by adding a space at the occurrences + found. - Pointed-out-by: Marcel Raad + Closes #2986 + Reviewed-by: Daniel Stenberg -- urldata: remove unused pipe_broke struct field +- krb5: fix memory leak in krb_auth - This struct field is never set TRUE in any existing code path. This - change removes the field completely. + The FTP command allocated by aprintf() must be freed after usage. - Closes #2871 + Reviewed-by: Daniel Stenberg -- curl: warn the user if a given file name looks like an option - - ... simply because this is usually a sign of the user having omitted the - file name and the next option is instead "eaten" by the parser as a file - name. +- ftp: include command in Curl_ftpsend sendbuffer - Add test1268 to verify + Commit 8238ba9c5f10414a88f502bf3f5d5a42d632984c inadvertently removed + the actual command to be sent from the send buffer in a refactoring. + Add back copying the command into the buffer. Also add more guards + against malformed input while at it. - Closes #2885 + Closes #2985 + Reviewed-by: Daniel Stenberg -- http2: check nghttp2_session_set_stream_user_data return code +- ntlm_wb: Fix memory leaks in ntlm_wb_response - Might help bug #2688 debugging + When erroring out on a request being too large, the existing buffer was + leaked. Fix by explicitly freeing on the way out. - Closes #2880 + Closes #2966 + Reviewed-by: Daniel Stenberg -- travis: revert back to gcc-7 for coverage builds - - ... since the gcc-8 ones seem to fail frequently. - - Follow-up from b85207199544ca - - Closes #2886 +Daniel Stenberg (13 Sep 2018) +- [Yiming Jing brought this change] -- RELEASE-NOTES: synced - - ... and now listed in alphabetical order! + travis: build the MesaLink vtls backend with MesaLink 0.7.1 -- [Adrien brought this change] +- [Yiming Jing brought this change] - CMake: CMake config files are defining CURL_STATICLIB for static builds - - This change allows to use the CMake config files generated by Curl's - CMake scripts for static builds of the library. - The symbol CURL_STATIC lib must be defined to compile downstream, - thus the config package is the perfect place to do so. - - Fixes #2817 - Closes #2823 - Reported-by: adnn on github - Reviewed-by: Sergei Nikulov + runtests.pl: run tests against the MesaLink vtls backend -- TODO: host name sections in config files +- [Yiming Jing brought this change] -Kamil Dudka (14 Aug 2018) -- ssh-libssh: fix infinite connect loop on invalid private key - - Added test 656 (based on test 604) to verify the fix. - - Bug: https://bugzilla.redhat.com/1595135 + vtls: add a MesaLink vtls backend - Closes #2879 + Closes #2984 -- ssh-libssh: reduce excessive verbose output about pubkey auth - - The verbose message "Authentication using SSH public key file" was - printed each time the ssh_userauth_publickey_auto() was called, which - meant each time a packet was transferred over network because the API - operates in non-blocking mode. - - This patch makes sure that the verbose message is printed just once - (when the authentication state is entered by the SSH state machine). +- [Yiming Jing brought this change] -Daniel Stenberg (14 Aug 2018) -- travis: disable h2 torture tests for "coverage" - - Since they started to fail almost 100% since a few days. - - Closes #2876 + configure.ac: add a MesaLink vtls backend -Marcel Raad (14 Aug 2018) -- travis: update to GCC 8 - - Closes https://github.com/curl/curl/pull/2869 +- [Dave Reisner brought this change] -Daniel Stenberg (13 Aug 2018) -- http: fix for tiny "HTTP/0.9" response + curl_url_set.3: properly escape \n in example code - Deal with tiny "HTTP/0.9" (header-less) responses by checking the - status-line early, even before a full "HTTP/" is received to allow - detecting 0.9 properly. + This yields - Test 1266 and 1267 added to verify. + "the scheme is %s\n" - Fixes #2420 - Closes #2872 - -Kamil Dudka (13 Aug 2018) -- docs: add disallow-username-in-url.d and haproxy-protocol.d on the list + instead of - ... to make make the files appear in distribution tarballs + "the scheme is %s0 - Closes #2856 + Closes #2970 -- .travis.yml: verify that man pages can be regenerated - - ... when curl is built from distribution tarball - - Closes #2856 +- [Dave Reisner brought this change] -Marcel Raad (11 Aug 2018) -- Split non-portable part off test 1133 - - Split off testing file names with double quotes into new test 1158. - Disable it for MSYS using a precheck as it doesn't support file names - with double quotes (but Cygwin does, for example). - - Fixes https://github.com/curl/curl/issues/2796 - Closes https://github.com/curl/curl/pull/2854 + curl_url_set.3: fix typo in reference to CURLU_APPENDQUERY -Jay Satiro (11 Aug 2018) -- projects: Improve Windows perl detection in batch scripts +- urlglob: improve error message - - Determine if perl is in the user's PATH by running perl.exe. + to help user understand what the problem is - Prior to this change detection was done by checking the PATH for perl/ - but that did not work in all cases (eg git install includes perl but - not in perl/ path). + Reported-by: Daniel Shahaf - Bug: https://github.com/curl/curl/pull/2865 - Reported-by: Daniel Jeliński + Fixes #2763 + Closes #2977 -- [Michael Kaufmann brought this change] +- [Yiming Jing brought this change] - docs: Improve the manual pages of some callbacks + tests/certs: rebuild certs with 2048-bit RSA keys - - CURLOPT_HEADERFUNCTION: add newlines - - CURLOPT_INTERLEAVEFUNCTION: fix the description of 'userdata' - - CURLOPT_READDATA: mention crashes, same as in CURLOPT_WRITEDATA - - CURLOPT_READFUNCTION: rename 'instream' to 'userdata' and explain - how to set it + The previous test certificates contained RSA keys of only 1024 bits. + However, RSA claims that 1024-bit RSA keys are likely to become + crackable some time before 2010. The NIST recommends at least 2048-bit + keys for RSA for now. - Closes https://github.com/curl/curl/pull/2868 + Better use full 2048 also for testing. + + Closes #2973 -Marcel Raad (11 Aug 2018) -- GCC: silence -Wcast-function-type uniformly +Daniel Gustafsson (12 Sep 2018) +- TODO: fix typo in item - Pointed-out-by: Rikard Falkeborn - Closes https://github.com/curl/curl/pull/2860 + Closes #2968 + Reviewed-by: Daniel Stenberg -- Silence GCC 8 cast-function-type warnings +Marcel Raad (12 Sep 2018) +- anyauthput: fix compiler warning on 64-bit Windows - On Windows, casting between unrelated function types is fine and - sometimes even necessary, so just use an intermediate cast to - (void (*) (void)) to silence the warning as described in [0]. + On Windows, the read function from is used, which has its byte + count parameter as unsigned int instead of size_t. - [0] https://gcc.gnu.org/onlinedocs/gcc-8.1.0/gcc/Warning-Options.html + Closes https://github.com/curl/curl/pull/2972 + +Viktor Szakats (12 Sep 2018) +- lib: fix gcc8 warning on Windows - Closes https://github.com/curl/curl/pull/2860 + Closes https://github.com/curl/curl/pull/2979 -Daniel Stenberg (11 Aug 2018) -- CURLINFO_SIZE_UPLOAD: fix missing counter update +Jay Satiro (12 Sep 2018) +- openssl: fix gcc8 warning - Adds test 1522 for verification. + - Use memcpy instead of strncpy to copy a string without termination, + since gcc8 warns about using strncpy to copy as many bytes from a + string as its length. - Reported-by: cjmsoregan - Fixes #2847 - Closes #2864 - -- [Daniel Jelinski brought this change] - - Documentation: fix CURLOPT_SSH_COMPRESSION copy/paste bug + Suggested-by: Viktor Szakats - Closes #2867 - -- RELEASE-NOTES: synced + Closes https://github.com/curl/curl/issues/2980 -- openssl: fix potential NULL pointer deref in is_pkcs11_uri +Daniel Stenberg (10 Sep 2018) +- libcurl-url.3: overview man page for the URL API - Follow-up to 298d2565e - Coverity CID 1438387 + Closes #2967 -Marcel Raad (10 Aug 2018) -- travis: execute "set -eo pipefail" for coverage build +- example/asiohiper: insert warning comment about its status - Follow-up to 2de63ab179eb78630ee039ad94fb2a5423df522d and - 0b87c963252d3504552ee0c8cf4402bd65a80af5. + This example is simply not working correctly but there's nobody around + with the skills and energy to fix it. - Closes https://github.com/curl/curl/pull/2862 + Closes #2407 -Daniel Stenberg (10 Aug 2018) -- lib1502: fix memory leak in torture test +Kamil Dudka (10 Sep 2018) +- docs/cmdline-opts: update the documentation of --tlsv1.0 - Reported-by: Marcel Raad - Fixes #2861 - Closes #2863 - -- docs: mention NULL is fine input to several functions + ... to reflect the changes in 6015cefb1b2cfde4b4850121c42405275e5e77d9 - Fixes #2837 - Closes #2858 - Reported-by: Markus Elfring - -- [Bas van Schaik brought this change] + Closes #2955 - README.md: add LGTM.com code quality grade for C/C++ +- docs/examples: do not wait when no transfers are running - Closes #2857 + Closes #2948 -- [Rikard Falkeborn brought this change] +Daniel Stenberg (10 Sep 2018) +- [Daniel Gustafsson brought this change] - test1531: Add timeout + cookies: Move failure case label to end of function - Previously, the macro TEST_HANG_TIMEOUT was unused, but since there is - looping going on, we might as well add timing instead of removing it. + Rather than jumping backwards to where failure cleanup happens + to be performed, move the failure case to end of the function + where it is expected per existing coding convention. - Closes #2853 + Closes #2965 -- [Rikard Falkeborn brought this change] +- [Daniel Gustafsson brought this change] - test1540: Remove unused macro TEST_HANG_TIMEOUT - - The macro has never been used, and it there is not really any place - where it would make sense to add timing checks. + misc: fix typos in comments - Closes #2852 + Closes #2963 -- [Rikard Falkeborn brought this change] +- [Daniel Gustafsson brought this change] - asyn-thread: Remove unused macro + cookies: fix leak when writing cookies to file - The macro seems to never have been used. + If the formatting fails, we error out on a fatal error and + clean up on the way out. The array was however freed within + the wrong scope and was thus never freed in case the cookies + were written to a file instead of STDOUT. - Closes #2852 + Closes #2957 -- [Rikard Falkeborn brought this change] +- [Daniel Gustafsson brought this change] - http_proxy: Remove unused macro SELECT_TIMEOUT + cookies: Remove redundant expired check - Usage was removed in 5113ad0424044458ac497fa1458ebe0101356b22. + Expired cookies have already been purged at a later expiration time + before this check, so remove the redundant check. - Closes #2852 - -- [Rikard Falkeborn brought this change] + closes #2962 - formdata: Remove unused macro HTTPPOST_CONTENTTYPE_DEFAULT +- ntlm_wb: bail out if the response gets overly large - Its usage was removed in - 84ad1fd3047815f9c6e78728bb351b828eac10b1. + Exit the realloc() loop if the response turns out ridiculously large to + avoid worse problems. - Closes #2852 + Reported-by: Harry Sintonen + Closes #2959 -- [Rikard Falkeborn brought this change] +- [Daniel Gustafsson brought this change] - telnet: Remove unused macros TELOPTS and TELCMDS + url.c: fix comment typo and indentation - Their usage was removed in 3a145180cc754a5959ca971ef3cd243c5c83fc51. + Closes #2960 + +- urlapi: avoid derefencing a possible NULL pointer - Closes #2852 + Coverity CID 1439134 -- [Daniel Jelinski brought this change] +- RELEASE-NOTES: synced - openssl: fix debug messages +Marcel Raad (8 Sep 2018) +- test324: fix after 3f3b26d6feb0667714902e836af608094235fca2 - Fixes #2806 - Closes #2843 + The expected error code is now 60. 51 is dead. -- configure: fix for -lpthread detection with OpenSSL and pkg-config - - ... by making sure it uses the -I provided by pkg-config! - - Reported-by: pszemus on github - Fixes #2848 - Closes #2850 +Daniel Stenberg (8 Sep 2018) +- curl_url_set.3: correct description -- RELEASE-NOTES: synced +- curl_url-docs: fix AVAILABILITY as Added in curl 7.62.0 -- windows: follow up to the buffer-tuning 1ba1dba7 +- URL-API - Somehow I didn't include the amended version of the previous fix. This - is the missing piece. + See header file and man pages for API. All documented API details work + and are tested in the 1560 test case. - Pointed-out-by: Viktor Szakats - -- [Daniel Jelinski brought this change] + Closes #2842 - windows: implement send buffer tuning +- curl_easy_upkeep: removed 'conn' from the name - Significantly enhances upload performance on modern Windows versions. + ... including the associated option. - Bug: https://curl.haxx.se/mail/lib-2018-07/0080.html - Closes #2762 - Fixes #2224 + Fixes #2951 + Closes #2952 -- [Anderson Toshiyuki Sasaki brought this change] +- [Max Dymond brought this change] - ssl: set engine implicitly when a PKCS#11 URI is provided + upkeep: add a connection upkeep API: curl_easy_conn_upkeep() - This allows the use of PKCS#11 URI for certificates and keys without - setting the corresponding type as "ENG" and the engine as "pkcs11" - explicitly. If a PKCS#11 URI is provided for certificate, key, - proxy_certificate or proxy_key, the corresponding type is set as "ENG" - if not provided and the engine is set to "pkcs11" if not provided. + Add functionality so that protocols can do custom keepalive on their + connections, when an external API function is called. - Acked-by: Nikos Mavrogiannopoulos - Closes #2333 + Add docs for the new options in 7.62.0 + + Closes #1641 -- [Ruslan Baratov brought this change] +- [Philipp Waehnert brought this change] - CMake: Respect BUILD_SHARED_LIBS + configure: add option to disable automatic OpenSSL config loading - Use standard CMake variable BUILD_SHARED_LIBS instead of introducing - custom option CURL_STATICLIB. + Sometimes it may be considered a security risk to load an external + OpenSSL configuration automatically inside curl_global_init(). The + configuration option --disable-ssl-auto-load-config disables this + automatism. The Windows build scripts winbuild/Makefile.vs provide a + corresponding option ENABLE_SSL_AUTO_LOAD_CONFIG accepting a boolean + value. - Use '-DBUILD_SHARED_LIBS=%SHARED%' in appveyor.yml. + Setting neither of these options corresponds to the previous behavior + loading the external OpenSSL configuration automatically. - Reviewed-by: Sergei Nikulov - Closes #2755 - -- [John Butterfield brought this change] + Fixes #2724 + Closes #2791 - cmake: bumped minimum version to 3.4 +- doh: minor edits to please Coverity - Closes #2753 - -- [John Butterfield brought this change] - - cmake: link curl to the OpenSSL targets instead of lib absolute paths + The gcc typecheck macros and coverity combined made it warn on the 2nd + argument for ERROR_CHECK_SETOPT(). Here's minor rearrange to please it. - Reviewed-by: Jakub Zakrzewski - Reviewed-by: Sergei Nikulov - Closes #2753 + Coverity CID 1439115 and CID 1439114. -- travis: build darwinssl on macos 10.12 +- schannel: avoid switch-cases that go to default anyway - ... as building on 10.13.x before 10.13.4 leads to link errors. + SEC_E_APPLICATION_PROTOCOL_MISMATCH isn't defined in some versions of + mingw and would require an ifdef otherwise. - Assisted-by: Nick Zitzmann - Fixes #2835 - Closes #2845 + Reported-by: Thomas Glanzmann + Approved-by: Marc Hörsken + Bug: https://curl.haxx.se/mail/lib-2018-09/0020.html + Closes #2950 -- DEPRECATE: remove release date from 7.62.0 - - Since it will slip and the version is the important part there, not the - date. +- [Nicklas Avén brought this change] -- lib/Makefile: only do symbol hiding if told to + imap: change from "FETCH" to "UID FETCH" - This restores the ability to build a static lib with - --disable-symbol-hiding to keep non-curl_ symbols. + ... and add "MAILINDEX". - Researched-by: Dan Fandrich - Reported-by: Ran Mozes - Fixes #2830 - Closes #2831 - -Marcel Raad (2 Aug 2018) -- hostip: fix unused variable warning + As described in #2789, this is a suggested solution. Changing UID=xx to + actually get mail with UID xx and add "MAILINDEX" to get a mail with a + special index in the mail box (old behavior). So MAILINDEX=1 gives the + first non deleted mail in the mail box. - addresses is only used in an infof call, which is a macro expanding to - nothing if CURL_DISABLE_VERBOSE_STRINGS is set. + Fixes #2789 + Closes #2815 -Daniel Stenberg (2 Aug 2018) -- test1307: disabled +- CURLOPT_UPLOAD_BUFFERSIZE: set upload buffer size - Turns out that since we're using the native fnmatch function now when - available, and they simply disagree on a huge number of test patterns - that make it hard to test this function like this... + This is step 3 of #2888. - Fixes #2825 + Fixes #2888 + Closes #2896 -- smb: don't mark it done in smb_do - - Follow-up to 09e401e01bf9. The SMB protocol handler needs to use its - doing function too, which requires smb_do() to not mark itself as - done... - - Closes #2822 +- travis: add the DOH tests to the torture testing -- [Rikard Falkeborn brought this change] +- DOH: add test case 1650 and 2100 - general: fix printf specifiers +- curl: --doh-url added + +- setopt: add CURLOPT_DOH_URL - Closes #2818 + Closes #2668 -- RELEASE-NOTES: synced +- [Han Han brought this change] -- mailmap: Daniel Jelinski + ssl: deprecate CURLE_SSL_CACERT in favour of a unified error code + + Long live CURLE_PEER_FAILED_VERIFICATION -- [Harry Sintonen brought this change] +- [Han Han brought this change] - HTTP: Don't attempt to needlessly decompress redirect body - - This change fixes a regression where redirect body would needlessly be - decompressed even though it was to be ignored anyway. As it happens this - causes secondary issues since there appears to be a bug in apache2 that - it in certain conditions generates a corrupt zlib response. The - regression was created by commit: - dbcced8e32b50c068ac297106f0502ee200a1ebd + x509asn1: return CURLE_PEER_FAILED_VERIFICATION on failure to parse cert - Discovered-by: Harry Sintonen - Closes #2798 + CURLE_PEER_FAILED_VERIFICATION makes more sense because Curl_parseX509 + does not allocate memory internally as its first argument is a pointer + to the certificate structure. The same error code is also returned by + Curl_verifyhost when its call to Curl_parseX509 fails so the change + makes error handling more consistent. -- curl: use Content-Disposition before the "URL end" for -OJ - - Regression introduced in 7.61.0 +- [Han Han brought this change] + + openssl: return CURLE_PEER_FAILED_VERIFICATION on failure to parse issuer - Reported-by: Thomas Klausner - Fixes #2783 - Closes #2813 + Failure to extract the issuer name from the server certificate should + return a more specific error code like on other TLS backends. -- [Daniel Jelinski brought this change] +- [Han Han brought this change] - retry: return error if rewind was necessary but didn't happen + schannel: unified error code handling - Fixes #2801 - Closes #2812 + Closes #2901 -- http2: clear the drain counter in Curl_http2_done - - Reported-by: Andrei Virtosu - Fixes #2800 - Closes #2809 +- [Han Han brought this change] -- smb: fix memory leak on early failure - - ... by making sure connection related data (->share) is stored in the - connection and not in the easy handle. + darwinssl: more specific and unified error codes - Detected by OSS-fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9369 - Fixes #2769 - Closes #2810 + Closes #2901 -- travis: run a 'make checksrc' too +- CURLOPT_DNS_USE_GLOBAL_CACHE: deprecated - ... to make sure the examples are all checked. + Disable the CURLOPT_DNS_USE_GLOBAL_CACHE option and mark it for + deprecation and complete removal in six months. - Closes #2811 - -Jay Satiro (29 Jul 2018) -- examples/ephiperfifo: checksrc compliance - -- [Michael Kaufmann brought this change] + Bug: https://curl.haxx.se/mail/lib-2018-09/0010.html + Closes #2942 - sws: handle EINTR when calling select() +- url: default to CURL_HTTP_VERSION_2TLS if built h2-enabled - Closes https://github.com/curl/curl/pull/2808 + Closes #2709 -Daniel Stenberg (29 Jul 2018) -- test1157: follow-up to 35ecffb9 +- multiplex: enable by default - Ignore the user-agent line. - Pointed-out-by: Marcel Raad + Starting 7.62.0, multiplexing is enabled by default in multi handles. -Michael Kaufmann (29 Jul 2018) -- tests/http_pipe.py: Use /usr/bin/env to find python +- [Jim Fuller brought this change] -Daniel Stenberg (28 Jul 2018) -- TODO: Support Authority Information Access certificate extension (AIA) + tests: add unit tests for url.c - Closes #2793 + Approved-by: Daniel Gustafsson + Closes #2937 -- conn_free: updated comment to clarify +- test1452: mark as flaky - Let's call it disassociate instead of disconnect since the latter term - is used so much for (TCP) connections already. - -- test1157: test -H from empty file + makes it not run in the CI builds - Verifies bugfix #2797 - -- [Tobias Blomberg brought this change] + Closes #2941 - curl: Fix segfault when -H @headerfile is empty +- pipelining: deprecated - The curl binary would crash if the -H command line option was given a - filename to read using the @filename syntax but that file was empty. + Transparently. The related curl_multi_setopt() options all still returns + OK when pipelining is selected. - Closes #2797 - -- mime: check Curl_rand_hex's return code + To re-enable the support, the single line change in lib/multi.c needs to + be reverted. - Bug: https://curl.haxx.se/mail/archive-2018-07/0015.html - Reported-by: Jeffrey Walton - Closes #2795 + See docs/DEPRECATE.md + + Closes #2705 -- [Josh Bialkowski brought this change] +- RELEASE-NOTES: start working on 7.62.0 - docs/examples: add hiperfifo example using linux epoll/timerfd - - Closes #2804 +Version 7.61.1 (4 Sep 2018) -- [Darío Hereñú brought this change] +Daniel Stenberg (4 Sep 2018) +- THANKS: 7.61.1 status - docs/INSTALL.md: minor formatting fixes +- RELEASE-NOTES: 7.61.1 + +- Curl_getoff_all_pipelines: ignore unused return values - Closes #2794 + Since scan-build would warn on the dead "Dead store/Dead increment" -- [Christopher Head brought this change] +Viktor Szakats (4 Sep 2018) +- sftp: fix indentation - docs/CURLOPT_URL: fix indentation - - The statement, “The application does not have to keep the string around - after setting this option,†appears to be indented under the RTMP - paragraph. It actually applies to all protocols, not just RTMP. - Eliminate the extra indentation. - - Closes #2788 +Daniel Stenberg (4 Sep 2018) +- [Przemysław Tomaszewski brought this change] -- [Christopher Head brought this change] + sftp: don't send post-qoute sequence when retrying a connection + + Fixes #2939 + Closes #2940 - docs/CURLOPT_WRITEFUNCTION: size is always 1 +Kamil Dudka (3 Sep 2018) +- url, vtls: make CURLOPT{,_PROXY}_TLS13_CIPHERS work - For compatibility with `fwrite`, the `CURLOPT_WRITEFUNCTION` callback is - passed two `size_t` parameters which, when multiplied, designate the - number of bytes of data passed in. In practice, CURL always sets the - first parameter (`size`) to 1. + This is a follow-up to PR #2607 and PR #2926. - This practice is also enshrined in documentation and cannot be changed - in future. The documentation states that the default callback is - `fwrite`, which means `fwrite` must be a suitable function for this - purpose. However, the documentation also states that the callback must - return the number of *bytes* it successfully handled, whereas ISO C - `fwrite` returns the number of items (each of size `size`) which it - wrote. The only way these numbers can be equal is if `size` is 1. + Closes #2936 + +Daniel Stenberg (3 Sep 2018) +- [Jay Satiro brought this change] + + tool_operate: Add http code 408 to transient list for --retry - Since `size` is 1 and can never be changed in future anyway, document - that fact explicitly and let users rely on it. + - Treat 408 request timeout as transient so that curl will retry the + request if --retry was used. - Closes #2787 + Closes #2925 -- [Carie Pointer brought this change] +- [Jay Satiro brought this change] - wolfSSL/CyaSSL: Fix memory leak in Curl_cyassl_random + openssl: Fix setting TLS 1.3 cipher suites - RNG structure must be freed by call to FreeRng after its use in - Curl_cyassl_random. This call fixes Valgrind failures when running the - test suite with wolfSSL. + The flag indicating TLS 1.3 cipher support in the OpenSSL backend was + missing. - Closes #2784 - -- [Even Rouault brought this change] + Bug: https://github.com/curl/curl/pull/2607#issuecomment-417283187 + Reported-by: Kamil Dudka + + Closes #2926 - reuse_conn(): free old_conn->options +- Curl_ntlm_core_mk_nt_hash: return error on too long password - This fixes a memory leak when CURLOPT_LOGIN_OPTIONS is used, together with - connection reuse. + ... since it would cause an integer overflow if longer than (max size_t + / 2). - I found this with oss-fuzz on GDAL and curl master: - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9582 - I couldn't reproduce with the oss-fuzz original test case, but looking - at curl source code pointed to this well reproducable leak. + This is CVE-2018-14618 - Closes #2790 + Bug: https://curl.haxx.se/docs/CVE-2018-14618.html + Closes #2756 + Reported-by: Zhaoyang Wu -Marcel Raad (25 Jul 2018) -- [Daniel Jelinski brought this change] +- [Rikard Falkeborn brought this change] - system_win32: fix version checking - - In the current version, VERSION_GREATER_THAN_EQUAL 6.3 will return false - when run on windows 10.0. This patch addresses that error. + http2: Use correct format identifier for stream_id - Closes https://github.com/curl/curl/pull/2792 + Closes #2928 -Daniel Stenberg (24 Jul 2018) -- [Johannes Schindelin brought this change] +Marcel Raad (2 Sep 2018) +- test1148: fix precheck output + + "precheck command error" is not very helpful. - auth: pick Bearer authentication whenever a token is available +Daniel Stenberg (1 Sep 2018) +- all: s/int/size_t cleanup - So far, the code tries to pick an authentication method only if - user/password credentials are available, which is not the case for - Bearer authentictation... + Assisted-by: Rikard Falkeborn - Signed-off-by: Johannes Schindelin - Closes #2754 + Closes #2922 -- [Johannes Schindelin brought this change] +- ssh-libssh: use FALLTHROUGH to silence gcc8 - auth: only ever pick CURLAUTH_BEARER if we *have* a Bearer token +Jay Satiro (31 Aug 2018) +- tool_operate: Fix setting proxy TLS 1.3 ciphers + +Daniel Stenberg (31 Aug 2018) +- [Daniel Gustafsson brought this change] + + cookies: support creation-time attribute for cookies - The Bearer authentication was added to cURL 7.61.0, but there is a - problem: if CURLAUTH_ANY is selected, and the server supports multiple - authentication methods including the Bearer method, we strongly prefer - that latter method (only CURLAUTH_NEGOTIATE beats it), and if the Bearer - authentication fails, we will never even try to attempt any other - method. + According to RFC6265 section 5.4, cookies with equal path lengths + SHOULD be sorted by creation-time (earlier first). This adds a + creation-time record to the cookie struct in order to make cookie + sorting more deterministic. The creation-time is defined as the + order of the cookies in the jar, the first cookie read fro the + jar being the oldest. The creation-time is thus not serialized + into the jar. Also remove the strcmp() matching in the sorting as + there is no lexicographic ordering in RFC6265. Existing tests are + updated to match. - This is particularly unfortunate when we already know that we do not - have any Bearer token to work with. + Closes #2524 + +Marcel Raad (31 Aug 2018) +- Don't use Windows path %PWD for SSH tests - Such a scenario happens e.g. when using Git to push to Visual Studio - Team Services (which supports Basic and Bearer authentication among - other methods) and specifying the Personal Access Token directly in the - URL (this aproach is frequently taken by automated builds). + All these tests failed on Windows because something like + sftp://%HOSTIP:%SSHPORT%PWD/ + expanded to + sftp://127.0.0.1:1234c:/msys64/home/bla/curl + and then curl complained about the port number ending with a letter. - Let's make sure that we have a Bearer token to work with before we - select the Bearer authentication among the available authentication - methods. + Use the original POSIX path instead of the Windows path created in + checksystem to fix this. - Signed-off-by: Johannes Schindelin - Closes #2754 + Closes https://github.com/curl/curl/pull/2920 -Marcel Raad (22 Jul 2018) -- test320: treat curl320.out file as binary +Jay Satiro (29 Aug 2018) +- CURLOPT_SSL_CTX_FUNCTION.3: clarify connection reuse warning - Otherwise, LF line endings are converted to CRLF on Windows, - but no conversion is done for the reply, so the test case fails. + Reported-by: Daniel Stenberg - Closes https://github.com/curl/curl/pull/2776 + Closes https://github.com/curl/curl/issues/2916 -Daniel Stenberg (22 Jul 2018) -- vtls: set conn->data when closing TLS - - Follow-up to 1b76c38904f0. The VTLS backends that close down the TLS - layer for a connection still needs a Curl_easy handle for the session_id - cache etc. - - Fixes #2764 - Closes #2771 +Daniel Stenberg (28 Aug 2018) +- THANKS-filter: dedup Daniel Jeliński -Marcel Raad (21 Jul 2018) -- tests: fixes for Windows line endlings +- RELEASE-NOTES: synced + +- CURLOPT_ACCEPT_ENCODING.3: list them comma-separated [ci skip] + +- CURLOPT_SSL_CTX_FUNCTION.3: might cause unintended connection reuse [ci skip] - Set mode="text" when line endings depend on the system representation. + Added a warning! - Closes https://github.com/curl/curl/pull/2772 + Closes #2915 -- test214: disable MSYS2's POSIX path conversion for URL - - By default, the MSYS2 bash converts all backslashes to forward slashes - in URLs. Disable this with MSYS2_ARG_CONV_EXCL for the test to pass. +- curl: fix time-of-check, time-of-use race in dir creation - Ref https://github.com/msys2/msys2/wiki/Porting#filesystem-namespaces + Patch-by: Jay Satiro + Detected by Coverity + Fixes #2739 + Closes #2912 -Daniel Stenberg (20 Jul 2018) -- http2: several cleanups +- cmdline-opts/page-footer: fix edit mistake - - separate easy handle from connections better - - added asserts on a number of places - - added sanity check of pipelines for debug builds + There was a missing newline. - Closes #2751 + follow-up to a7ba60bb7250 -- smb_getsock: always wait for write socket too - - ... the protocol is doing read/write a lot, so it needs to write often - even when downloading. A more proper fix could check for eactly when it - wants to write and only ask for it then. +- docs: clarify NO_PROXY env variable functionality - Without this fix, an SMB download could easily get stuck when the event-driven - API was used. + Reported-by: Kirill Marchuk + Fixes #2773 + Closes #2911 + +Marcel Raad (24 Aug 2018) +- lib1522: fix curl_easy_setopt argument type - Closes #2768 + CURLOPT_POSTFIELDSIZE is a long option. -Marcel Raad (20 Jul 2018) -- test1143: disable MSYS2's POSIX path conversion +- curl_threads: silence bad-function-cast warning - By default, the MSYS2 bash interprets http:/%HOSTIP:%HTTPPORT/want/1143 - as a POSIX file list and converts it to a Windows file list. - Disable this with MSYS2_ARG_CONV_EXCL for the test to pass. + As uintptr_t and HANDLE are always the same size, this warning is + harmless. Just silence it using an intermediate uintptr_t variable. - Ref https://github.com/msys2/msys2/wiki/Porting#filesystem-namespaces - Closes https://github.com/curl/curl/pull/2765 + Closes https://github.com/curl/curl/pull/2908 -Daniel Stenberg (18 Jul 2018) -- RELEASE-NOTES: sync +Daniel Stenberg (24 Aug 2018) +- README: add appveyor build badge [ci skip] - ... and work toward 7.61.1 - -- [Ruslan Baratov brought this change] + Closes #2913 - CMake: Update scripts to use consistent style - - Closes #2727 - Reviewed-by: Sergei Nikulov +- [Ihor Karpenko brought this change] -- header output: switch off all styles, not just unbold + schannel: client certificate store opening fix - ... the "unbold" sequence doesn't work on the mac Terminal. + 1) Using CERT_STORE_OPEN_EXISTING_FLAG ( or CERT_STORE_READONLY_FLAG ) + while opening certificate store would be sufficient in this scenario and + less-demanding in sense of required user credentials ( for example, + IIS_IUSRS will get "Access Denied" 0x05 error for existing CertOpenStore + call without any of flags mentioned above ), - Reported-by: Zero King - Fixes #2736 - Closes #2738 - -Nick Zitzmann (14 Jul 2018) -- [Rodger Combs brought this change] - - darwinssl: add support for ALPN negotiation - -Marcel Raad (14 Jul 2018) -- test1422: add required file feature + 2) as 'cert_store_name' is a DWORD, attempt to format its value like a + string ( in "Failed to open cert store" error message ) will throw null + pointer exception - curl configured with --enable-debug --disable-file currently complains - on test1422: - Info: Protocol "file" not supported or disabled in libcurl + 3) adding GetLastError(), in my opinion, will make error message more + useful. - Make test1422 dependend on enabled FILE protocol to fix this. + Bug: https://curl.haxx.se/mail/lib-2018-08/0198.html - Fixes https://github.com/curl/curl/issues/2741 - Closes https://github.com/curl/curl/pull/2742 + Closes #2909 -Patrick Monnerat (12 Jul 2018) -- content_encoding: accept up to 4 unknown trailer bytes after raw deflate data +- [Leonardo Taccari brought this change] + + gopher: Do not translate `?' to `%09' - Some servers issue raw deflate data that may be followed by an undocumented - trailer. This commit makes curl tolerate such a trailer of up to 4 bytes - before considering the data is in error. + Since GOPHER support was added in curl `?' character was automatically + translated to `%09' (`\t'). - Reported-by: clbr on github - Fixes #2719 - -Daniel Stenberg (12 Jul 2018) -- smb: fix memory-leak in URL parse error path + However, this behaviour does not seems documented in RFC 4266 and for + search selectors it is documented to directly use `%09' in the URL. + Apart that several gopher servers in the current gopherspace have CGI + support where `?' is used as part of the selector and translating it to + `%09' often leads to surprising results. - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9369 - Closes #2740 + Closes #2910 -Marcel Raad (12 Jul 2018) -- schannel: enable CALG_TLS1PRF for w32api >= 5.1 +Marcel Raad (23 Aug 2018) +- cookie tests: treat files as text - The definition of CALG_TLS1PRF has been fixed in the 5.1 branch: - https://osdn.net/projects/mingw/scm/git/mingw-org-wsl/commits/73aedcc0f2e6ba370de0d86ab878ad76a0dda7b5 + Fixes test failures because of wrong line endings on Windows. -Daniel Stenberg (12 Jul 2018) -- docs/SECURITY-PROCESS: mention bounty, drop pre-notify +Daniel Stenberg (23 Aug 2018) +- libcurl-thread.3: expand somewhat on the NO_SIGNAL motivation - + The hackerone bounty and its process + Multi-threaded applictions basically MUST set CURLOPT_NO_SIGNAL to 1L to + avoid the risk of getting a SIGPIPE. - - We don't and can't handle pre-notification + Either way, a multi-threaded application that uses libcurl/openssl needs + to have a signhandler for or ignore SIGPIPE on its own. + + Based on discussions in #2800 + Closes #2904 -- multi: always do the COMPLETED procedure/state +- RELEASE-NOTES: synced + +Marcel Raad (22 Aug 2018) +- Tests: fixes for Windows - It was previously erroneously skipped in some situations. + - test 1268 requires unix sockets + - test 2072 must be disabled also for MSYS/MinGW + +Daniel Stenberg (22 Aug 2018) +- http2: abort the send_callback if not setup yet - libtest/libntlmconnect.c wrongly depended on wrong behavior (that it - would get a zero timeout) when no handles are "running" in a multi - handle. That behavior is no longer present with this fix. Now libcurl - will always return a -1 timeout when all handles are completed. + When Curl_http2_done() gets called before the http2 data is setup all + the way, we cannot send anything and this should just return an error. - Closes #2733 + Detected by OSS-Fuzz + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=10012 -- Curl_getoff_all_pipelines: improved for multiplexed +- http2: remove four unused nghttp2 callbacks - On multiplexed connections, transfers can be removed from anywhere not - just at the head as for pipelines. - -- ares: check for NULL in completed-callback + Closes #2903 -- conn: remove the boolean 'inuse' field +- x509asn1: use FALLTHROUGH - ... as the usage needs to be counted. - -- [Paul Howarth brought this change] + ... as no other comments are accepted since 014ed7c22f51463 - openssl: assume engine support in 1.0.0 or later +Marcel Raad (21 Aug 2018) +- test1148: disable if decimal separator is not point - Commit 38203f1585da changed engine detection to be version-based, - with a baseline of openssl 1.0.1. This does in fact break builds - with openssl 1.0.0, which has engine support - the configure script - detects that ENGINE_cleanup() is available - but - doesn't get included to declare it. + Modifying the locale with environment variables doesn't work for native + Windows applications. Just disable the test in this case if the decimal + separator is something different than a point. Use a precheck with a + small C program to achieve that. - According to upstream documentation, engine support was added to - mainstream openssl builds as of version 0.9.7: - https://github.com/openssl/openssl/blob/master/README.ENGINE + Closes https://github.com/curl/curl/pull/2786 + +- Enable more GCC warnings - This commit drops the version test down to 1.0.0 as version 1.0.0d - is the oldest version I have to test with. + This enables the following additional warnings: + -Wold-style-definition + -Warray-bounds=2 instead of the default 1 + -Wformat=2, but only for GCC 4.8+ as Wno-format-nonliteral is not + respected for older versions + -Wunused-const-variable, which enables level 2 instead of the default 1 + -Warray-bounds also in debug mode through -ftree-vrp + -Wnull-dereference also in debug mode through + -fdelete-null-pointer-checks - Closes #2732 + Closes https://github.com/curl/curl/pull/2747 -Marcel Raad (11 Jul 2018) -- schannel: fix MinGW compile break - - Original MinGW's w32api has a sytax error in its definition of - CALG_TLS1PRF [0]. Don't use original MinGW w32api's CALG_TLS1PRF - until this bug [1] is fixed. +- curl-compilers: enable -Wimplicit-fallthrough=4 for GCC - [0] https://osdn.net/projects/mingw/scm/git/mingw-org-wsl/blobs/d1d4a17e51a2b78e252ef0147d483267d56c90cc/w32api/include/wincrypt.h - [1] https://osdn.net/projects/mingw/ticket/38391 + This enables level 4 instead of the default level 3, which of the + currently used comments only allows /* FALLTHROUGH */ to silence the + warning. - Fixes https://github.com/curl/curl/pull/2721#issuecomment-403636043 - Closes https://github.com/curl/curl/pull/2728 + Closes https://github.com/curl/curl/pull/2747 -Daniel Stenberg (11 Jul 2018) -- examples/crawler.c: move #ifdef to column 0 +- curl-compilers: enable -Wbad-function-cast on GCC - Apparently the C => HTML converter on the web site doesn't quite like it - otherwise. + This warning used to be enabled only for clang as it's a bit stricter + on GCC. Silence the remaining occurrences and enable it on GCC too. - Reported-by: Jeroen Ooms - -Version 7.61.0 (11 Jul 2018) - -Daniel Stenberg (11 Jul 2018) -- release: 7.61.0 + Closes https://github.com/curl/curl/pull/2747 -- TODO: Configurable loading of OpenSSL configuration file +- configure: conditionally enable pedantic-errors - Closes #2724 - -- post303.d: clarify that this is an RFC violation + Enable pedantic-errors for GCC >= 5 with --enable-werror. Before GCC 5, + pedantic-errors was synonymous to -Werror=pedantic [0], which is still + the case for clang [1]. With GCC 5, it became complementary [2]. - ... and not the other way around, which this previously said. + Also fix a resulting error in acinclude.m4 as main's return type was + missing, which is illegal in C99. - Reported-by: Vasiliy Faronov - Fixes #2723 - Closes #2726 - -- [Ruslan Baratov brought this change] + [0] https://gcc.gnu.org/onlinedocs/gcc-4.9.0/gcc/Warning-Options.html + [1] https://clang.llvm.org/docs/UsersManual.html#options-to-control-error-and-warning-messages + [2] https://gcc.gnu.org/onlinedocs/gcc-5.1.0/gcc/Warning-Options.html + + Closes https://github.com/curl/curl/pull/2747 - CMake: remove redundant and old end-of-block syntax +- Remove unused definitions - Reviewed-by: Jakub Zakrzewski - Closes #2715 + Closes https://github.com/curl/curl/pull/2747 -Jay Satiro (9 Jul 2018) -- lib/curl_setup.h: remove unicode character +Daniel Stenberg (21 Aug 2018) +- x509asn1: make several functions static - Follow-up to 82ce416. + and remove the private SIZE_T_MAX define and use the generic one. - Ref: https://github.com/curl/curl/commit/8272ec5#commitcomment-29646818 - -Daniel Stenberg (9 Jul 2018) -- lib/curl_setup.h: remove unicode bom from 8272ec50f02 + Closes #2902 -Marcel Raad (9 Jul 2018) -- schannel: fix -Wsign-compare warning - - MinGW warns: - /lib/vtls/schannel.c:219:64: warning: signed and unsigned type in - conditional expression [-Wsign-compare] +- INTERNALS: require GnuTLS >= 2.11.3 - Fix this by casting the ptrdiff_t to size_t as we know it's positive. + Since the public pinning support was brought in e644866caf4. GnuTLS + 2.11.3 was released in October 2010. - Closes https://github.com/curl/curl/pull/2721 + Figured out in #2890 -- schannel: workaround for wrong function signature in w32api +- http2: avoid set_stream_user_data() before stream is assigned - Original MinGW's w32api has CryptHashData's second parameter as BYTE * - instead of const BYTE *. + ... before the stream is started, we have it set to -1. - Closes https://github.com/curl/curl/pull/2721 + Fixes #2894 + Closes #2898 -- schannel: make more cipher options conditional - - They are not defined in the original MinGW's . +- SSLCERTS: improve the openssl command line - Closes https://github.com/curl/curl/pull/2721 + ... for extracting certs from a live HTTPS server to make a cacerts.pem + from them. -- curl_setup: include before +- docs/SECURITY-PROCESS: now we name the files after the CVE id + +- RELEASE-NOTES: synced + +- upload: change default UPLOAD_BUFSIZE to 64KB - Otherwise, only part of it gets pulled in through on - original MinGW. + To make uploads significantly faster in some circumstances. - Fixes https://github.com/curl/curl/issues/2361 - Closes https://github.com/curl/curl/pull/2721 + Part 2 of #2888 + Closes #2892 -- examples: fix -Wformat warnings +- upload: allocate upload buffer on-demand - When size_t is not a typedef for unsigned long (as usually the case on - Windows), GCC emits -Wformat warnings when using lu and lx format - specifiers with size_t. Silence them with explicit casts to - unsigned long. + Saves 16KB on the easy handle for operations that don't need that + buffer. - Closes https://github.com/curl/curl/pull/2721 + Part 1 of #2888 -Daniel Stenberg (9 Jul 2018) -- smtp: use the upload buffer size for scratch buffer malloc +- [Laurent Bonnans brought this change] + + vtls: reinstantiate engine on duplicated handles - ... not the read buffer size, as that can be set smaller and thus cause - a buffer overflow! CVE-2018-0500 + Handles created with curl_easy_duphandle do not use the SSL engine set + up in the original handle. This fixes the issue by storing the engine + name in the internal url state and setting the engine from its name + inside curl_easy_duphandle. - Reported-by: Peter Wu - Bug: https://curl.haxx.se/docs/adv_2018-70a2.html - -- [Dave Reisner brought this change] + Reported-by: Anton Gerasimov + Signed-of-by: Laurent Bonnans + Fixes #2829 + Closes #2833 - scripts: include _curl as part of CLEANFILES +- http2: make sure to send after RST_STREAM - Closes #2718 - -- [Nick Zitzmann brought this change] + If this is the last stream on this connection, the RST_STREAM might not + get pushed to the wire otherwise. + + Fixes #2882 + Closes #2887 + Researched-by: Michael Kaufmann - darwinssl: allow High Sierra users to build the code using GCC +- test1268: check the stderr output as "text" - ...but GCC users lose out on TLS 1.3 support, since we can't weak-link - enumeration constants. + Follow-up to 099f37e9c57 - Fixes #2656 - Closes #2703 - -- [Ruslan Baratov brought this change] + Pointed-out-by: Marcel Raad - CMake: Remove unused 'output_var' from 'collect_true' +- urldata: remove unused pipe_broke struct field - Variable 'output_var' is not used and can be removed. - Function 'collect_true' renamed to 'count_true'. - -- [Ruslan Baratov brought this change] - - CMake: Remove unused functions + This struct field is never set TRUE in any existing code path. This + change removes the field completely. - Closes #2711 - -- KNOWN_BUGS: Stick to same family over SOCKS proxy + Closes #2871 -- libssh: goto DISCONNECT state on error, not SSH_SESSION_FREE +- curl: warn the user if a given file name looks like an option - ... because otherwise not everything get closed down correctly. + ... simply because this is usually a sign of the user having omitted the + file name and the next option is instead "eaten" by the parser as a file + name. - Fixes #2708 - Closes #2712 - -- libssh: include line number in state change debug messages + Add test1268 to verify - Closes #2713 - -- KNOWN_BUGS: Borland support is dropped, AIX problem is too old + Closes #2885 -- [Jeroen Ooms brought this change] +- http2: check nghttp2_session_set_stream_user_data return code + + Might help bug #2688 debugging + + Closes #2880 - example/crawler.c: simple crawler based on libxml2 +- travis: revert back to gcc-7 for coverage builds - Closes #2706 + ... since the gcc-8 ones seem to fail frequently. + + Follow-up from b85207199544ca + + Closes #2886 - RELEASE-NOTES: synced - -- DEPRECATE: include year when specifying date - -- DEPRECATE: linkified - -- DEPRECATE: mention the PR that disabled axTLS - -- docs/DEPRECATE.md: spelling and minor formatting - -- DEPRECATE: new doc describing planned item removals - Closes #2704 + ... and now listed in alphabetical order! -- [Gisle Vanem brought this change] +- [Adrien brought this change] - telnet: fix clang warnings + CMake: CMake config files are defining CURL_STATICLIB for static builds - telnet.c(1401,28): warning: cast from function call of type 'int' to - non-matching type 'HANDLE' (aka 'void *') [-Wbad-function-cast] + This change allows to use the CMake config files generated by Curl's + CMake scripts for static builds of the library. + The symbol CURL_STATIC lib must be defined to compile downstream, + thus the config package is the perfect place to do so. - Fixes #2696 - Closes #2700 - -- docs: fix missed option name markups + Fixes #2817 + Closes #2823 + Reported-by: adnn on github + Reviewed-by: Sergei Nikulov -- [Gaurav Malhotra brought this change] +- TODO: host name sections in config files - openssl: Remove some dead code +Kamil Dudka (14 Aug 2018) +- ssh-libssh: fix infinite connect loop on invalid private key - Closes #2698 - -- openssl: make the requested TLS version the *minimum* wanted + Added test 656 (based on test 604) to verify the fix. - The code treated the set version as the *exact* version to require in - the TLS handshake, which is not what other TLS backends do and probably - not what most people expect either. + Bug: https://bugzilla.redhat.com/1595135 - Reported-by: Andreas Olsson - Assisted-by: Gaurav Malhotra - Fixes #2691 - Closes #2694 - -- RELEASE-NOTES: synced + Closes #2879 -- openssl: allow TLS 1.3 by default +- ssh-libssh: reduce excessive verbose output about pubkey auth - Reported-by: Andreas Olsson - Fixes #2692 - Closes #2693 - -- [Adrian Peniak brought this change] + The verbose message "Authentication using SSH public key file" was + printed each time the ssh_userauth_publickey_auto() was called, which + meant each time a packet was transferred over network because the API + operates in non-blocking mode. + + This patch makes sure that the verbose message is printed just once + (when the authentication state is entered by the SSH state machine). - CURLINFO_TLS_SSL_PTR.3: improve the example +Daniel Stenberg (14 Aug 2018) +- travis: disable h2 torture tests for "coverage" - The previous example was a little bit confusing, because SSL* structure - (or other "in use" SSL connection pointer) is not accessible after the - transfer is completed, therefore working with the raw TLS library - specific pointer needs to be done during transfer. + Since they started to fail almost 100% since a few days. - Closes #2690 + Closes #2876 -- travis: add a build using the synchronous name resolver - - ... since default uses the threaded one and we test the c-ares build - already. +Marcel Raad (14 Aug 2018) +- travis: update to GCC 8 - Closes #2689 + Closes https://github.com/curl/curl/pull/2869 -- configure: remove CURL_CHECK_NI_WITHSCOPEID too +Daniel Stenberg (13 Aug 2018) +- http: fix for tiny "HTTP/0.9" response - Since it isn't used either and requires the getnameinfo check + Deal with tiny "HTTP/0.9" (header-less) responses by checking the + status-line early, even before a full "HTTP/" is received to allow + detecting 0.9 properly. - Follow-up to 0aeca41702d2 - -- getnameinfo: not used + Test 1266 and 1267 added to verify. - Closes #2687 + Fixes #2420 + Closes #2872 -- easy_perform: use *multi_timeout() to get wait times +Kamil Dudka (13 Aug 2018) +- docs: add disallow-username-in-url.d and haproxy-protocol.d on the list - ... and trim the threaded Curl_resolver_getsock() to return zero - millisecond wait times during the first three milliseconds so that - localhost or names in the OS resolver cache gets detected and used - faster. + ... to make make the files appear in distribution tarballs - Closes #2685 + Closes #2856 -Max Dymond (27 Jun 2018) -- configure: Add dependent libraries after crypto +- .travis.yml: verify that man pages can be regenerated - The linker is pretty dumb and processes things left to right, keeping a - tally of symbols it hasn't resolved yet. So, we need -ldl to appear - after -lcrypto otherwise the linker won't find the dl functions. + ... when curl is built from distribution tarball - Closes #2684 - -Daniel Stenberg (27 Jun 2018) -- GOVERNANCE: linkify, changed some titles - -- GOVERNANCE: add maintainer details/duties + Closes #2856 -- url: check Curl_conncache_add_conn return code +Marcel Raad (11 Aug 2018) +- Split non-portable part off test 1133 - ... it was previously unchecked in two places and thus errors could - remain undetected and cause trouble. + Split off testing file names with double quotes into new test 1158. + Disable it for MSYS using a precheck as it doesn't support file names + with double quotes (but Cygwin does, for example). - Closes #2681 - -- include/README: remove "hacking" advice, not the right place - -- RELEASE-NOTES: synced + Fixes https://github.com/curl/curl/issues/2796 + Closes https://github.com/curl/curl/pull/2854 -- CURLOPT_SSL_VERIFYPEER.3: fix syntax mistake +Jay Satiro (11 Aug 2018) +- projects: Improve Windows perl detection in batch scripts - Follow-up to b6a16afa0aa5 - -- netrc: use a larger buffer + - Determine if perl is in the user's PATH by running perl.exe. - ... to work with longer passwords etc. Grow it from a 256 to a 4096 - bytes buffer. + Prior to this change detection was done by checking the PATH for perl/ + but that did not work in all cases (eg git install includes perl but + not in perl/ path). - Reported-by: Dario Nieuwenhuis - Fixes #2676 - Closes #2680 + Bug: https://github.com/curl/curl/pull/2865 + Reported-by: Daniel Jeliński -- [Patrick Schlangen brought this change] +- [Michael Kaufmann brought this change] - CURLOPT_SSL_VERIFYPEER.3: Add performance note + docs: Improve the manual pages of some callbacks - Closes #2673 + - CURLOPT_HEADERFUNCTION: add newlines + - CURLOPT_INTERLEAVEFUNCTION: fix the description of 'userdata' + - CURLOPT_READDATA: mention crashes, same as in CURLOPT_WRITEDATA + - CURLOPT_READFUNCTION: rename 'instream' to 'userdata' and explain + how to set it + + Closes https://github.com/curl/curl/pull/2868 -- [Javier Blazquez brought this change] +Marcel Raad (11 Aug 2018) +- GCC: silence -Wcast-function-type uniformly + + Pointed-out-by: Rikard Falkeborn + Closes https://github.com/curl/curl/pull/2860 - multi: fix crash due to dangling entry in connect-pending list +- Silence GCC 8 cast-function-type warnings - Fixes #2677 - Closes #2679 + On Windows, casting between unrelated function types is fine and + sometimes even necessary, so just use an intermediate cast to + (void (*) (void)) to silence the warning as described in [0]. + + [0] https://gcc.gnu.org/onlinedocs/gcc-8.1.0/gcc/Warning-Options.html + + Closes https://github.com/curl/curl/pull/2860 -- ConnectionExists: make sure conn->data is set when "taking" a connection +Daniel Stenberg (11 Aug 2018) +- CURLINFO_SIZE_UPLOAD: fix missing counter update - Follow-up to 2c15693. + Adds test 1522 for verification. - Bug #2674 - Closes #2675 + Reported-by: cjmsoregan + Fixes #2847 + Closes #2864 -- [Kevin R. Bulgrien brought this change] +- [Daniel Jelinski brought this change] - system.h: fix for gcc on 32 bit OpenServer + Documentation: fix CURLOPT_SSH_COMPRESSION copy/paste bug - Bug: https://curl.haxx.se/mail/lib-2018-06/0100.html + Closes #2867 -- [Raphael Gozzo brought this change] +- RELEASE-NOTES: synced - cmake: allow multiple SSL backends - - This will make possible to select the SSL backend (using - curl_global_sslset()) even when the libcurl is built using CMake +- openssl: fix potential NULL pointer deref in is_pkcs11_uri - Closes #2665 + Follow-up to 298d2565e + Coverity CID 1438387 -- url: fix dangling conn->data pointer +Marcel Raad (10 Aug 2018) +- travis: execute "set -eo pipefail" for coverage build - By masking sure to use the *current* easy handle with extracted - connections from the cache, and make sure to NULLify the ->data pointer - when the connection is put into the cache to make this mistake easier to - detect in the future. + Follow-up to 2de63ab179eb78630ee039ad94fb2a5423df522d and + 0b87c963252d3504552ee0c8cf4402bd65a80af5. - Reported-by: Will Dietz - Fixes #2669 - Closes #2672 - -- CURLOPT_INTERFACE.3: interface names not supported on Windows + Closes https://github.com/curl/curl/pull/2862 -- travis: run more tests for coverage check +Daniel Stenberg (10 Aug 2018) +- lib1502: fix memory leak in torture test - ... run a few more tortured based and run all tests event-based. + Reported-by: Marcel Raad + Fixes #2861 + Closes #2863 + +- docs: mention NULL is fine input to several functions - Closes #2664 + Fixes #2837 + Closes #2858 + Reported-by: Markus Elfring -- multi: fix memory leak when stopped during name resolve +- [Bas van Schaik brought this change] + + README.md: add LGTM.com code quality grade for C/C++ - When the application just started the transfer and then stops it while - the name resolve in the background thread hasn't completed, we need to - wait for the resolve to complete and then cleanup data accordingly. + Closes #2857 + +- [Rikard Falkeborn brought this change] + + test1531: Add timeout - Enabled test 1553 again and added test 1590 to also check when the host - name resolves successfully. + Previously, the macro TEST_HANG_TIMEOUT was unused, but since there is + looping going on, we might as well add timing instead of removing it. - Detected by OSS-fuzz. - Closes #1968 + Closes #2853 -Viktor Szakats (15 Jun 2018) -- maketgz: delete .bak files, fix indentation +- [Rikard Falkeborn brought this change] + + test1540: Remove unused macro TEST_HANG_TIMEOUT - Ref: https://github.com/curl/curl/pull/2660 + The macro has never been used, and it there is not really any place + where it would make sense to add timing checks. - Closes https://github.com/curl/curl/pull/2662 + Closes #2852 -Daniel Stenberg (15 Jun 2018) -- runtests.pl: remove debug leftover from bb9a340c73f3 +- [Rikard Falkeborn brought this change] -- curl-confopts.m4: fix typo from ed224f23d5beb + asyn-thread: Remove unused macro - Fixes my local configure to detect a custom installed c-ares without - pkgconfig. - -- docs/RELEASE-PROCEDURE.md: renamed to use .md extension + The macro seems to never have been used. - Closes #2663 - -- RELEASE-PROCEDURE: gpg sign the tags + Closes #2852 -- RELEASE-NOTES: synced +- [Rikard Falkeborn brought this change] -- CURLOPT_HTTPAUTH.3: CURLAUTH_BEARER was added in 7.61.0 + http_proxy: Remove unused macro SELECT_TIMEOUT + + Usage was removed in 5113ad0424044458ac497fa1458ebe0101356b22. + + Closes #2852 -- [Mamta Upadhyay brought this change] +- [Rikard Falkeborn brought this change] - maketgz: fix sed issues on OSX - - maketgz creates release tarballs and removes the -DEV string in curl - version (e.g. 7.58.0-DEV), else -DEV shows up on command line when curl - is run. maketgz works fine on linux but fails on OSX. Problem is with - the sed commands that use option -i without an extension. Maketgz - expects GNU sed instead of BSD and this simply won't work on OSX. Adding - a backup extension .bak after -i fixes this issue + formdata: Remove unused macro HTTPPOST_CONTENTTYPE_DEFAULT - Running the script as if on OSX gives this error: + Its usage was removed in + 84ad1fd3047815f9c6e78728bb351b828eac10b1. - sed: -e: No such file or directory + Closes #2852 + +- [Rikard Falkeborn brought this change] + + telnet: Remove unused macros TELOPTS and TELCMDS - Adding a .bak extension resolves it + Their usage was removed in 3a145180cc754a5959ca971ef3cd243c5c83fc51. - Closes #2660 + Closes #2852 -- configure: enhance ability to detect/build with static openssl - - Fix the -ldl and -ldl + -lpthread checks for OpenSSL, necessary for - building with static libs without pkg-config. +- [Daniel Jelinski brought this change] + + openssl: fix debug messages - Reported-by: Marcel Raad - Fixes #2199 - Closes #2659 + Fixes #2806 + Closes #2843 -- configure: use pkg-config for c-ares detection +- configure: fix for -lpthread detection with OpenSSL and pkg-config - First check if there's c-ares information given as pkg-config info and use - that as first preference. + ... by making sure it uses the -I provided by pkg-config! Reported-by: pszemus on github - Fixes #2203 - Closes #2658 + Fixes #2848 + Closes #2850 -- GOVERNANCE.md: explains how this project is run +- RELEASE-NOTES: synced + +- windows: follow up to the buffer-tuning 1ba1dba7 - Closes #2657 + Somehow I didn't include the amended version of the previous fix. This + is the missing piece. + + Pointed-out-by: Viktor Szakats -- KNOWN_BUGS: NTLM doen't support password with § character +- [Daniel Jelinski brought this change] + + windows: implement send buffer tuning - Closes #2120 + Significantly enhances upload performance on modern Windows versions. + + Bug: https://curl.haxx.se/mail/lib-2018-07/0080.html + Closes #2762 + Fixes #2224 -- KNOWN_BUGS: slow connect to localhost on Windows +- [Anderson Toshiyuki Sasaki brought this change] + + ssl: set engine implicitly when a PKCS#11 URI is provided - Closes #2281 + This allows the use of PKCS#11 URI for certificates and keys without + setting the corresponding type as "ENG" and the engine as "pkcs11" + explicitly. If a PKCS#11 URI is provided for certificate, key, + proxy_certificate or proxy_key, the corresponding type is set as "ENG" + if not provided and the engine is set to "pkcs11" if not provided. + + Acked-by: Nikos Mavrogiannopoulos + Closes #2333 -- [Matteo Bignotti brought this change] +- [Ruslan Baratov brought this change] - mk-ca-bundle.pl: make -u delete certdata.txt if found not changed + CMake: Respect BUILD_SHARED_LIBS - certdata.txt should be deleted also when the process is interrupted by - "same certificate downloaded, exiting" + Use standard CMake variable BUILD_SHARED_LIBS instead of introducing + custom option CURL_STATICLIB. - The certdata.txt is currently kept on disk even if you give the -u - option + Use '-DBUILD_SHARED_LIBS=%SHARED%' in appveyor.yml. - Closes #2655 + Reviewed-by: Sergei Nikulov + Closes #2755 -- progress: remove a set of unused defines - - Reported-by: Peter Wu - Closes #2654 +- [John Butterfield brought this change] -- TODO: "Option to refuse usernames in URLs" done + cmake: bumped minimum version to 3.4 - Implemented by Björn in 946ce5b61f + Closes #2753 -- [Lyman Epp brought this change] +- [John Butterfield brought this change] - Curl_init_do: handle NULL connection pointer passed in + cmake: link curl to the OpenSSL targets instead of lib absolute paths - Closes #2653 + Reviewed-by: Jakub Zakrzewski + Reviewed-by: Sergei Nikulov + Closes #2753 -- runtests: support variables in +- travis: build darwinssl on macos 10.12 - ... and make use of that to make 1455 work better without using a fixed - local port number. + ... as building on 10.13.x before 10.13.4 leads to link errors. - Fixes #2649 - Closes #2650 + Assisted-by: Nick Zitzmann + Fixes #2835 + Closes #2845 -- Curl_debug: remove dead printhost code - - The struct field is never set (since 5e0d9aea3) so remove the use of it - and remove the connectdata pointer from the prototype. +- DEPRECATE: remove release date from 7.62.0 - Reported-by: Tejas - Bug: https://curl.haxx.se/mail/lib-2018-06/0054.html - Closes #2647 + Since it will slip and the version is the important part there, not the + date. -Viktor Szakats (12 Jun 2018) -- schannel: avoid incompatible pointer warning +- lib/Makefile: only do symbol hiding if told to - with clang-6.0: - ``` - vtls/schannel_verify.c: In function 'add_certs_to_store': - vtls/schannel_verify.c:212:30: warning: passing argument 11 of 'CryptQueryObject' from incompatible pointer type [-Wincompatible-pointer-types] - &cert_context)) { - ^ - In file included from /usr/share/mingw-w64/include/schannel.h:10:0, - from /usr/share/mingw-w64/include/schnlsp.h:9, - from vtls/schannel.h:29, - from vtls/schannel_verify.c:40: - /usr/share/mingw-w64/include/wincrypt.h:4437:26: note: expected 'const void **' but argument is of type 'CERT_CONTEXT ** {aka struct _CERT_CONTEXT **}' - WINIMPM WINBOOL WINAPI CryptQueryObject (DWORD dwObjectType, const void *pvObject, DWORD dwExpectedContentTypeFlags, DWORD dwExpectedFormatTypeFlags, DWORD dwFlags, - ^~~~~~~~~~~~~~~~ - ``` - Ref: https://msdn.microsoft.com/library/windows/desktop/aa380264 + This restores the ability to build a static lib with + --disable-symbol-hiding to keep non-curl_ symbols. - Closes https://github.com/curl/curl/pull/2648 - -Daniel Stenberg (12 Jun 2018) -- [Robert Prag brought this change] + Researched-by: Dan Fandrich + Reported-by: Ran Mozes + Fixes #2830 + Closes #2831 - schannel: support selecting ciphers - - Given the contstraints of SChannel, I'm exposing these as the algorithms - themselves instead; while replicating the ciphersuite as specified by - OpenSSL would have been preferable, I found no way in the SChannel API - to do so. - - To use this from the commandline, you need to pass the names of contants - defining the desired algorithms. For example, curl --ciphers - "CALG_SHA1:CALG_RSA_SIGN:CALG_RSA_KEYX:CALG_AES_128:CALG_DH_EPHEM" - https://github.com The specific names come from wincrypt.h +Marcel Raad (2 Aug 2018) +- hostip: fix unused variable warning - Closes #2630 - -- [Bernhard M. Wiedemann brought this change] + addresses is only used in an infof call, which is a macro expanding to + nothing if CURL_DISABLE_VERBOSE_STRINGS is set. - test 46: make test pass after 2025 - - shifting the expiry date to 2037 for now - to be before the possibly problematic year 2038 +Daniel Stenberg (2 Aug 2018) +- test1307: disabled - similar in spirit to commit e6293cf8764e9eecb + Turns out that since we're using the native fnmatch function now when + available, and they simply disagree on a huge number of test patterns + that make it hard to test this function like this... - Closes #2646 - -- [Marian Klymov brought this change] + Fixes #2825 - cppcheck: fix warnings - - - Get rid of variable that was generating false positive warning - (unitialized) - - - Fix issues in tests - - - Reduce scope of several variables all over +- smb: don't mark it done in smb_do - etc + Follow-up to 09e401e01bf9. The SMB protocol handler needs to use its + doing function too, which requires smb_do() to not mark itself as + done... - Closes #2631 + Closes #2822 -- openssl: assume engine support in 1.0.1 or later - - Previously it was checked for in configure/cmake, but that would then - leave other build systems built without engine support. - - While engine support probably existed prior to 1.0.1, I decided to play - safe. If someone experience a problem with this, we can widen the - version check. +- [Rikard Falkeborn brought this change] + + general: fix printf specifiers - Fixes #2641 - Closes #2644 + Closes #2818 - RELEASE-NOTES: synced -- RELEASE-PROCEDURE: update the release calendar for 2019 +- mailmap: Daniel Jelinski -- [Gisle Vanem brought this change] +- [Harry Sintonen brought this change] - boringssl + schannel: undef X509_NAME in lib/schannel.h - - Fixes the build problem when both boringssl and schannel are enabled. + HTTP: Don't attempt to needlessly decompress redirect body - Fixes #2634 - Closes #2643 - -- [Vladimir Kotal brought this change] - - mk-ca-bundle.pl: leave certificate name untouched in decode() + This change fixes a regression where redirect body would needlessly be + decompressed even though it was to be ignored anyway. As it happens this + causes secondary issues since there appears to be a bug in apache2 that + it in certain conditions generates a corrupt zlib response. The + regression was created by commit: + dbcced8e32b50c068ac297106f0502ee200a1ebd - Closes #2640 - -- [Rikard Falkeborn brought this change] + Discovered-by: Harry Sintonen + Closes #2798 - tests/libtests/Makefile.am: Add lib1521.c to CLEANFILES +- curl: use Content-Disposition before the "URL end" for -OJ - This removes the generated lib1521.c when running make clean. + Regression introduced in 7.61.0 - Closes #2633 + Reported-by: Thomas Klausner + Fixes #2783 + Closes #2813 -- [Rikard Falkeborn brought this change] +- [Daniel Jelinski brought this change] - tests/libtest: Add lib1521 to nodist_SOURCES - - Since 467da3af0, lib1521.c is generated instead of checked in. According - to the commit message, the intention was to remove it from the tarball - as well. However, it is still present when running make dist. To remove - it, add it to nodist_lib1521_SOURCES. This also means there is no need - for the manually added dist-rule in the Makefile. + retry: return error if rewind was necessary but didn't happen - Also update CMakelists.txt to handle the fact that we now may have - nodist_SOURCES. + Fixes #2801 + Closes #2812 -- [Stephan Mühlstrasser brought this change] +- http2: clear the drain counter in Curl_http2_done + + Reported-by: Andrei Virtosu + Fixes #2800 + Closes #2809 - system.h: add support for IBM xlc C compiler +- smb: fix memory leak on early failure - Added a section to system.h guarded with __xlc__ for the IBM xml C - compiler. Before this change the section titled 'generic "safe guess" on - old 32 bit style' was used, which resulted in a wrong definition of - CURL_TYPEOF_CURL_SOCKLEN_T, and for 64-bit also CURL_TYPEOF_CURL_OFF_T - was wrong. + ... by making sure connection related data (->share) is stored in the + connection and not in the easy handle. - Compilation warnings fixed with this change: + Detected by OSS-fuzz + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9369 + Fixes #2769 + Closes #2810 + +- travis: run a 'make checksrc' too - CC libcurl_la-ftp.lo - "ftp.c", line 290.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "ftp.c", line 293.48: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "ftp.c", line 1070.49: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "ftp.c", line 1154.53: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "ftp.c", line 1187.51: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - CC libcurl_la-connect.lo - "connect.c", line 448.56: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "connect.c", line 516.66: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "connect.c", line 687.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - "connect.c", line 696.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - CC libcurl_la-tftp.lo - "tftp.c", line 1115.33: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + ... to make sure the examples are all checked. - Closes #2637 + Closes #2811 -- cmdline-opts/cert-type.d: mention "p12" as a recognized type as well +Jay Satiro (29 Jul 2018) +- examples/ephiperfifo: checksrc compliance -Viktor Szakats (3 Jun 2018) -- spelling fixes +- [Michael Kaufmann brought this change] + + sws: handle EINTR when calling select() - Detected using the `codespell` tool (version 1.13.0). + Closes https://github.com/curl/curl/pull/2808 + +Daniel Stenberg (29 Jul 2018) +- test1157: follow-up to 35ecffb9 - Also secure and fix an URL. + Ignore the user-agent line. + Pointed-out-by: Marcel Raad -Daniel Stenberg (2 Jun 2018) -- axtls: follow-up spell fix of comment +Michael Kaufmann (29 Jul 2018) +- tests/http_pipe.py: Use /usr/bin/env to find python -- axTLS: not considered fit for use +Daniel Stenberg (28 Jul 2018) +- TODO: Support Authority Information Access certificate extension (AIA) - URL: https://curl.haxx.se/mail/lib-2018-06/0000.html + Closes #2793 + +- conn_free: updated comment to clarify - This is step one. It adds #error statements that require source edits to - make curl build again if asked to use axTLS. At a later stage we might - remove the axTLS specific code completely. + Let's call it disassociate instead of disconnect since the latter term + is used so much for (TCP) connections already. + +- test1157: test -H from empty file - Closes #2628 + Verifies bugfix #2797 -- build: remove the Borland specific makefiles +- [Tobias Blomberg brought this change] + + curl: Fix segfault when -H @headerfile is empty - According to the user survey 2018, not even one out of 670 users use - them. Nobody on the mailing list spoke up for them either. + The curl binary would crash if the -H command line option was given a + filename to read using the @filename syntax but that file was empty. - Closes #2629 + Closes #2797 -- curl_addrinfo: use same #ifdef conditions in source as header +- mime: check Curl_rand_hex's return code - ... for curl_dofreeaddrinfo + Bug: https://curl.haxx.se/mail/archive-2018-07/0015.html + Reported-by: Jeffrey Walton + Closes #2795 -- multi: remove a DEBUGF() - - ... it might call infof() with a NULL first argument that isn't harmful - but makes it not do anything. The infof() line is not very useful - anymore, it has served it purpose. Good riddance! +- [Josh Bialkowski brought this change] + + docs/examples: add hiperfifo example using linux epoll/timerfd - Fixes #2627 + Closes #2804 -- [Alibek.Jorajev brought this change] +- [Darío Hereñú brought this change] - CURLOPT_RESOLVE: always purge old entry first - - If there's an existing entry using the selected name. + docs/INSTALL.md: minor formatting fixes - Closes #2622 + Closes #2794 -- fnmatch: use the system one if available - - If configure detects fnmatch to be available, use that instead of our - custom one for FTP wildcard pattern matching. For standard compliance, - to reduce our footprint and to use already well tested and well - exercised code. +- [Christopher Head brought this change] + + docs/CURLOPT_URL: fix indentation - A POSIX fnmatch behaves slightly different than the internal function - for a few test patterns currently and the macOS one yet slightly - different. Test case 1307 is adjusted for these differences. + The statement, “The application does not have to keep the string around + after setting this option,†appears to be indented under the RTMP + paragraph. It actually applies to all protocols, not just RTMP. + Eliminate the extra indentation. - Closes #2626 + Closes #2788 -Patrick Monnerat (31 May 2018) -- os400: add new option in ILE/RPG binding +- [Christopher Head brought this change] + + docs/CURLOPT_WRITEFUNCTION: size is always 1 - Follow-up to commit 946ce5b + For compatibility with `fwrite`, the `CURLOPT_WRITEFUNCTION` callback is + passed two `size_t` parameters which, when multiplied, designate the + number of bytes of data passed in. In practice, CURL always sets the + first parameter (`size`) to 1. + + This practice is also enshrined in documentation and cannot be changed + in future. The documentation states that the default callback is + `fwrite`, which means `fwrite` must be a suitable function for this + purpose. However, the documentation also states that the callback must + return the number of *bytes* it successfully handled, whereas ISO C + `fwrite` returns the number of items (each of size `size`) which it + wrote. The only way these numbers can be equal is if `size` is 1. + + Since `size` is 1 and can never be changed in future anyway, document + that fact explicitly and let users rely on it. + + Closes #2787 -Daniel Stenberg (31 May 2018) -- tests/libtest/.gitignore: follow-up fix to ignore lib5* too +- [Carie Pointer brought this change] -- KNOWN_BUGS: CURL_GLOBAL_SSL + wolfSSL/CyaSSL: Fix memory leak in Curl_cyassl_random - Closes #2276 + RNG structure must be freed by call to FreeRng after its use in + Curl_cyassl_random. This call fixes Valgrind failures when running the + test suite with wolfSSL. + + Closes #2784 -- [Bernhard Walle brought this change] +- [Even Rouault brought this change] - configure: check for declaration of getpwuid_r - - On our x86 Android toolchain, getpwuid_r is implemented but the header - is missing: + reuse_conn(): free old_conn->options - netrc.c:81:7: error: implicit declaration of function 'getpwuid_r' [-Werror=implicit-function-declaration] + This fixes a memory leak when CURLOPT_LOGIN_OPTIONS is used, together with + connection reuse. - Unfortunately, the function is used in curl_ntlm_wb.c, too, so I moved - the prototype to curl_setup.h. + I found this with oss-fuzz on GDAL and curl master: + https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9582 + I couldn't reproduce with the oss-fuzz original test case, but looking + at curl source code pointed to this well reproducable leak. - Signed-off-by: Bernhard Walle - Closes #2609 + Closes #2790 -- [Rikard Falkeborn brought this change] +Marcel Raad (25 Jul 2018) +- [Daniel Jelinski brought this change] - tests: update .gitignore for libtests + system_win32: fix version checking - Closes #2624 - -- [Rikard Falkeborn brought this change] - - strictness: correct {infof, failf} format specifiers + In the current version, VERSION_GREATER_THAN_EQUAL 6.3 will return false + when run on windows 10.0. This patch addresses that error. - Closes #2623 + Closes https://github.com/curl/curl/pull/2792 -- [Björn Stenberg brought this change] +Daniel Stenberg (24 Jul 2018) +- [Johannes Schindelin brought this change] - option: disallow username in URL + auth: pick Bearer authentication whenever a token is available - Adds CURLOPT_DISALLOW_USERNAME_IN_URL and --disallow-username-in-url. Makes - libcurl reject URLs with a username in them. + So far, the code tries to pick an authentication method only if + user/password credentials are available, which is not the case for + Bearer authentictation... - Closes #2340 - -- libcurl-security.3: improved layout for two rememdy lists + Signed-off-by: Johannes Schindelin + Closes #2754 -- libcurl-security.3: refer to URL instead of in-source markdown file +- [Johannes Schindelin brought this change] -Viktor Szakats (30 May 2018) -- curl.rc: embed manifest for correct Windows version detection + auth: only ever pick CURLAUTH_BEARER if we *have* a Bearer token - * enable it in `src/Makefile.m32` - * enable it in `winbuild/MakefileBuild.vc` if a custom manifest is - _not_ enabled via the existing `EMBED_MANIFEST` option - * enable it for all Windows CMake builds (also disable the built-in - minimal manifest, added by CMake by default.) + The Bearer authentication was added to cURL 7.61.0, but there is a + problem: if CURLAUTH_ANY is selected, and the server supports multiple + authentication methods including the Bearer method, we strongly prefer + that latter method (only CURLAUTH_NEGOTIATE beats it), and if the Bearer + authentication fails, we will never even try to attempt any other + method. - For other build systems, add the `-DCURL_EMBED_MANIFEST` option to - the list of RC (Resource Compiler) flags to enable the manifest - included in `src/curl.rc`. This may require to disable whatever - automatic or other means in which way another manifest is added to - `curl.exe`. + This is particularly unfortunate when we already know that we do not + have any Bearer token to work with. - Notice that Borland C doesn't support this method due to a - long-pending resource compiler bug. Watcom C may also not handle - it correctly when the `-zm` `wrc` option is used (this option may - be unnecessary though) and regardless of options in certain earlier - revisions of the 2.0 beta version. + Such a scenario happens e.g. when using Git to push to Visual Studio + Team Services (which supports Basic and Bearer authentication among + other methods) and specifying the Personal Access Token directly in the + URL (this aproach is frequently taken by automated builds). - Closes https://github.com/curl/curl/pull/1221 - Fixes https://github.com/curl/curl/issues/2591 - -Patrick Monnerat (30 May 2018) -- os400: sync EBCDIC wrappers and ILE/RPG binding with latest options - -- os400: implement mime api EBCDIC wrappers + Let's make sure that we have a Bearer token to work with before we + select the Bearer authentication among the available authentication + methods. - Also sync ILE/RPG binding to define the new functions. + Signed-off-by: Johannes Schindelin + Closes #2754 -Daniel Stenberg (29 May 2018) -- setopt: add TLS 1.3 ciphersuites - - Adds CURLOPT_TLS13_CIPHERS and CURLOPT_PROXY_TLS13_CIPHERS. +Marcel Raad (22 Jul 2018) +- test320: treat curl320.out file as binary - curl: added --tls13-ciphers and --proxy-tls13-ciphers + Otherwise, LF line endings are converted to CRLF on Windows, + but no conversion is done for the reply, so the test case fails. - Fixes #2435 - Reported-by: zzq1015 on github - Closes #2607 + Closes https://github.com/curl/curl/pull/2776 -- configure: override AR_FLAGS to silence warning +Daniel Stenberg (22 Jul 2018) +- vtls: set conn->data when closing TLS - The automake default ar flags are 'cru', but the 'u' flag in there - causes warnings on many modern Linux distros. Removing 'u' may have a - minor performance impact on older distros but should not cause harm. + Follow-up to 1b76c38904f0. The VTLS backends that close down the TLS + layer for a connection still needs a Curl_easy handle for the session_id + cache etc. - Explained on the automake mailing list already back in April 2015: + Fixes #2764 + Closes #2771 + +Marcel Raad (21 Jul 2018) +- tests: fixes for Windows line endlings - https://www.mail-archive.com/automake-patches@gnu.org/msg07705.html + Set mode="text" when line endings depend on the system representation. - Reported-by: elephoenix on github - Fixes #2617 - Closes #2619 - -Sergei Nikulov (29 May 2018) -- cmake: fixed comments in compile checks code + Closes https://github.com/curl/curl/pull/2772 -Daniel Stenberg (29 May 2018) -- INSTALL: LDFLAGS=-Wl,-R/usr/local/ssl/lib +- test214: disable MSYS2's POSIX path conversion for URL - ... the older description doesn't work + By default, the MSYS2 bash converts all backslashes to forward slashes + in URLs. Disable this with MSYS2_ARG_CONV_EXCL for the test to pass. - Reported-by: Peter Varga - Fixes #2615 - Closes #2616 - -- [Will Dietz brought this change] + Ref https://github.com/msys2/msys2/wiki/Porting#filesystem-namespaces - KNOWN_BUGS: restore text regarding #2101. - - This was added earlier but appears to have been removed accidentally. +Daniel Stenberg (20 Jul 2018) +- http2: several cleanups - AFAICT this is very much still an issue. + - separate easy handle from connections better + - added asserts on a number of places + - added sanity check of pipelines for debug builds - ----- + Closes #2751 + +- smb_getsock: always wait for write socket too - I say "accidentally" because the text seems to have harmlessly snuck - into [1] (which makes no mention of it). [1] was later reverted for - unspecified reasons in [2], presumably because the mentioned issue was - fixed or invalid. + ... the protocol is doing read/write a lot, so it needs to write often + even when downloading. A more proper fix could check for eactly when it + wants to write and only ask for it then. - [1] de9fac00c40db321d44fa6fbab6eb62ec4c83998 - [2] 16d1f369403cbb04bd7b085eabbeebf159473fc2 + Without this fix, an SMB download could easily get stuck when the event-driven + API was used. - Closes #2618 + Closes #2768 -- fnmatch: insist on escaped bracket to match - - A non-escaped bracket ([) is for a character group - as documented. It - will *not* match an individual bracket anymore. Test case 1307 updated - accordingly to match. +Marcel Raad (20 Jul 2018) +- test1143: disable MSYS2's POSIX path conversion - Problem detected by OSS-Fuzz, although this fix is probably not a final - fix for the notorious timeout issues. + By default, the MSYS2 bash interprets http:/%HOSTIP:%HTTPPORT/want/1143 + as a POSIX file list and converts it to a Windows file list. + Disable this with MSYS2_ARG_CONV_EXCL for the test to pass. - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8525 - Closes #2614 + Ref https://github.com/msys2/msys2/wiki/Porting#filesystem-namespaces + Closes https://github.com/curl/curl/pull/2765 -Patrick Monnerat (28 May 2018) -- psl: use latest psl and refresh it periodically - - The latest psl is cached in the multi or share handle. It is refreshed - before use after 72 hours. - New share lock CURL_LOCK_DATA_PSL controls the psl cache sharing. - If the latest psl is not available, the builtin psl is used. +Daniel Stenberg (18 Jul 2018) +- RELEASE-NOTES: sync - Reported-by: Yaakov Selkowitz - Fixes #2553 - Closes #2601 + ... and work toward 7.61.1 -Daniel Stenberg (28 May 2018) -- [Fabrice Fontaine brought this change] +- [Ruslan Baratov brought this change] - configure: fix ssh2 linking when built with a static mbedtls - - The ssh2 pkg-config file could contain the following lines when build - with a static version of mbedtls: - Libs: -L${libdir} -lssh2 /xxx/libmbedcrypto.a - Libs.private: /xxx/libmbedcrypto.a + CMake: Update scripts to use consistent style - This static mbedtls library must be used to correctly detect ssh2 - support and this library must be copied in libcurl.pc otherwise - compilation of any application (such as upmpdcli) with libcurl will fail - when trying to found mbedtls functions included in libssh2. So, replace - pkg-config --libs-only-l by pkg-config --libs. + Closes #2727 + Reviewed-by: Sergei Nikulov + +- header output: switch off all styles, not just unbold - Fixes: - - http://autobuild.buildroot.net/results/43e24b22a77f616d6198c10435dcc23cc3b9088a + ... the "unbold" sequence doesn't work on the mac Terminal. - Signed-off-by: Fabrice Fontaine - Closes #2613 - -- RELEASE-NOTES: synced + Reported-by: Zero King + Fixes #2736 + Closes #2738 -- [Bernhard Walle brought this change] +Nick Zitzmann (14 Jul 2018) +- [Rodger Combs brought this change] - cmake: check for getpwuid_r + darwinssl: add support for ALPN negotiation + +Marcel Raad (14 Jul 2018) +- test1422: add required file feature - The autotools-based build system does it, so we do it also in CMake. + curl configured with --enable-debug --disable-file currently complains + on test1422: + Info: Protocol "file" not supported or disabled in libcurl - Bug: #2609 - Signed-off-by: Bernhard Walle - -- cmdline-opts/gen.pl: warn if mutexes: or see-also: list non-existing options - -- [Frank Gevaerts brought this change] + Make test1422 dependend on enabled FILE protocol to fix this. + + Fixes https://github.com/curl/curl/issues/2741 + Closes https://github.com/curl/curl/pull/2742 - curl.1: Fix cmdline-opts reference errors. +Patrick Monnerat (12 Jul 2018) +- content_encoding: accept up to 4 unknown trailer bytes after raw deflate data - --data, --form, and --ntlm were declared to be mutually exclusive with - non-existing options. --data and --form referred to --upload (which is - short for --upload-file and therefore did work, so this one was merely - a bit confusing), --ntlm referred to --negotiated instead of --negotiate. + Some servers issue raw deflate data that may be followed by an undocumented + trailer. This commit makes curl tolerate such a trailer of up to 4 bytes + before considering the data is in error. - Closes #2612 - -- [Frank Gevaerts brought this change] + Reported-by: clbr on github + Fixes #2719 - docs: fix cmdline-opts metadata headers case consistency. +Daniel Stenberg (12 Jul 2018) +- smb: fix memory-leak in URL parse error path - Almost all headers start with an uppercase letter, but some didn't. + Detected by OSS-Fuzz + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9369 + Closes #2740 -- mailmap: Max Savenkov +Marcel Raad (12 Jul 2018) +- schannel: enable CALG_TLS1PRF for w32api >= 5.1 + + The definition of CALG_TLS1PRF has been fixed in the 5.1 branch: + https://osdn.net/projects/mingw/scm/git/mingw-org-wsl/commits/73aedcc0f2e6ba370de0d86ab878ad76a0dda7b5 -Sergei Nikulov (28 May 2018) -- [Max Savenkov brought this change] +Daniel Stenberg (12 Jul 2018) +- docs/SECURITY-PROCESS: mention bounty, drop pre-notify + + + The hackerone bounty and its process + + - We don't and can't handle pre-notification - Fix the test for fsetxattr and strerror_r tests in CMake to work without compiling +- multi: always do the COMPLETED procedure/state + + It was previously erroneously skipped in some situations. + + libtest/libntlmconnect.c wrongly depended on wrong behavior (that it + would get a zero timeout) when no handles are "running" in a multi + handle. That behavior is no longer present with this fix. Now libcurl + will always return a -1 timeout when all handles are completed. + + Closes #2733 -Daniel Stenberg (27 May 2018) -- mailmap: a Richard Alcock fixup +- Curl_getoff_all_pipelines: improved for multiplexed + + On multiplexed connections, transfers can be removed from anywhere not + just at the head as for pipelines. -- [Richard Alcock brought this change] +- ares: check for NULL in completed-callback - schannel: add failf calls for client certificate failures +- conn: remove the boolean 'inuse' field - Closes #2604 + ... as the usage needs to be counted. -- [Richard Alcock brought this change] +- [Paul Howarth brought this change] - winbuild: In MakefileBuild.vc fix typo DISTDIR->DIRDIST + openssl: assume engine support in 1.0.0 or later - Change requirement from $(DISTDIR) to $(DIRDIST) + Commit 38203f1585da changed engine detection to be version-based, + with a baseline of openssl 1.0.1. This does in fact break builds + with openssl 1.0.0, which has engine support - the configure script + detects that ENGINE_cleanup() is available - but + doesn't get included to declare it. - closes #2603 - -- [Richard Alcock brought this change] - - winbuild: only delete OUTFILE if it exists + According to upstream documentation, engine support was added to + mainstream openssl builds as of version 0.9.7: + https://github.com/openssl/openssl/blob/master/README.ENGINE - This removes the slightly annoying "Could not file LIBCURL_OBJS.inc" and - "Could not find CURL_OBJS.inc.inc" message when building into a clean - folder. + This commit drops the version test down to 1.0.0 as version 1.0.0d + is the oldest version I have to test with. - closes #2602 - -- [Alejandro R. Sedeño brought this change] + Closes #2732 - content_encoding: handle zlib versions too old for Z_BLOCK +Marcel Raad (11 Jul 2018) +- schannel: fix MinGW compile break - Fallback on Z_SYNC_FLUSH when Z_BLOCK is not available. + Original MinGW's w32api has a sytax error in its definition of + CALG_TLS1PRF [0]. Don't use original MinGW w32api's CALG_TLS1PRF + until this bug [1] is fixed. - Fixes #2606 - Closes #2608 + [0] https://osdn.net/projects/mingw/scm/git/mingw-org-wsl/blobs/d1d4a17e51a2b78e252ef0147d483267d56c90cc/w32api/include/wincrypt.h + [1] https://osdn.net/projects/mingw/ticket/38391 + + Fixes https://github.com/curl/curl/pull/2721#issuecomment-403636043 + Closes https://github.com/curl/curl/pull/2728 -- multi: provide a socket to wait for in Curl_protocol_getsock +Daniel Stenberg (11 Jul 2018) +- examples/crawler.c: move #ifdef to column 0 - ... even when there's no protocol specific handler setup. + Apparently the C => HTML converter on the web site doesn't quite like it + otherwise. - Bug: https://curl.haxx.se/mail/lib-2018-05/0062.html - Reported-by: Sean Miller - Closes #2600 + Reported-by: Jeroen Ooms -- [Linus Lewandowski brought this change] +Version 7.61.0 (11 Jul 2018) - httpauth: add support for Bearer tokens +Daniel Stenberg (11 Jul 2018) +- release: 7.61.0 + +- TODO: Configurable loading of OpenSSL configuration file - Closes #2102 + Closes #2724 -- TODO: CURLINFO_PAUSE_STATE +- post303.d: clarify that this is an RFC violation - Closes #2588 + ... and not the other way around, which this previously said. + + Reported-by: Vasiliy Faronov + Fixes #2723 + Closes #2726 -Sergei Nikulov (24 May 2018) -- cmake: set -d postfix for debug builds if not specified - using -DCMAKE_DEBUG_POSTFIX explicitly +- [Ruslan Baratov brought this change] + + CMake: remove redundant and old end-of-block syntax - fixes #2121, obsoletes #2384 + Reviewed-by: Jakub Zakrzewski + Closes #2715 -Daniel Stenberg (23 May 2018) -- configure: add basic test of --with-ssl prefix +Jay Satiro (9 Jul 2018) +- lib/curl_setup.h: remove unicode character - When given a prefix, the $PREFIX_OPENSSL/lib/openssl.pc or - $PREFIX_OPENSSL/include/openssl/ssl.h files must be present or cause an - error. Helps users detect when giving configure the wrong path. + Follow-up to 82ce416. - Reported-by: Oleg Pudeyev - Assisted-by: Per Malmberg - Fixes #2580 + Ref: https://github.com/curl/curl/commit/8272ec5#commitcomment-29646818 -Patrick Monnerat (22 May 2018) -- http resume: skip body if http code 416 (range error) is ignored. +Daniel Stenberg (9 Jul 2018) +- lib/curl_setup.h: remove unicode bom from 8272ec50f02 + +Marcel Raad (9 Jul 2018) +- schannel: fix -Wsign-compare warning - This avoids appending error data to already existing good data. + MinGW warns: + /lib/vtls/schannel.c:219:64: warning: signed and unsigned type in + conditional expression [-Wsign-compare] - Test 92 is updated to match this change. - New test 1156 checks all combinations of --range/--resume, --fail, - Content-Range header and http status code 200/416. + Fix this by casting the ptrdiff_t to size_t as we know it's positive. - Fixes #1163 - Reported-By: Ithubg on github - Closes #2578 - -Daniel Stenberg (22 May 2018) -- tftp: make sure error is zero terminated before printfing it + Closes https://github.com/curl/curl/pull/2721 -- configure: add missing m4/ax_compile_check_sizeof.m4 +- schannel: workaround for wrong function signature in w32api - follow-up to mistake in 6876ccf90b4 - -Jay Satiro (22 May 2018) -- [Johannes Schindelin brought this change] + Original MinGW's w32api has CryptHashData's second parameter as BYTE * + instead of const BYTE *. + + Closes https://github.com/curl/curl/pull/2721 - schannel: make CAinfo parsing resilient to CR/LF +- schannel: make more cipher options conditional - OpenSSL has supported --cacert for ages, always accepting LF-only line - endings ("Unix line endings") as well as CR/LF line endings ("Windows - line endings"). + They are not defined in the original MinGW's . - When we introduced support for --cacert also with Secure Channel (or in - cURL speak: "WinSSL"), we did not take care to support CR/LF line - endings, too, even if we are much more likely to receive input in that - form when using Windows. + Closes https://github.com/curl/curl/pull/2721 + +- curl_setup: include before - Let's fix that. + Otherwise, only part of it gets pulled in through on + original MinGW. - Happily, CryptQueryObject(), the function we use to parse the ca-bundle, - accepts CR/LF input already, and the trailing LF before the END - CERTIFICATE marker catches naturally any CR/LF line ending, too. So all - we need to care about is the BEGIN CERTIFICATE marker. We do not - actually need to verify here that the line ending is CR/LF. Just - checking for a CR or an LF is really plenty enough. + Fixes https://github.com/curl/curl/issues/2361 + Closes https://github.com/curl/curl/pull/2721 + +- examples: fix -Wformat warnings - Signed-off-by: Johannes Schindelin + When size_t is not a typedef for unsigned long (as usually the case on + Windows), GCC emits -Wformat warnings when using lu and lx format + specifiers with size_t. Silence them with explicit casts to + unsigned long. - Closes https://github.com/curl/curl/pull/2592 + Closes https://github.com/curl/curl/pull/2721 -Daniel Stenberg (22 May 2018) -- CURLOPT_ACCEPT_ENCODING.3: add brotli and clarify a bit +Daniel Stenberg (9 Jul 2018) +- smtp: use the upload buffer size for scratch buffer malloc + + ... not the read buffer size, as that can be set smaller and thus cause + a buffer overflow! CVE-2018-0500 + + Reported-by: Peter Wu + Bug: https://curl.haxx.se/docs/adv_2018-70a2.html -- RELEASE-NOTES: synced +- [Dave Reisner brought this change] -- KNOWN_BUGS: mention the -O with %-encoded file names + scripts: include _curl as part of CLEANFILES - Closes #2573 + Closes #2718 -- checksrc: make sure sizeof() is used *with* parentheses - - ... and unify the source code to adhere. - - Closes #2563 +- [Nick Zitzmann brought this change] -- curl: added --styled-output + darwinssl: allow High Sierra users to build the code using GCC - It is enabled by default, so --no-styled-output will switch off the - detection/use of bold headers. + ...but GCC users lose out on TLS 1.3 support, since we can't weak-link + enumeration constants. - Closes #2538 + Fixes #2656 + Closes #2703 -- curl: show headers in bold +- [Ruslan Baratov brought this change] + + CMake: Remove unused 'output_var' from 'collect_true' - The feature is only enabled if the output is believed to be a tty. + Variable 'output_var' is not used and can be removed. + Function 'collect_true' renamed to 'count_true'. + +- [Ruslan Baratov brought this change] + + CMake: Remove unused functions - -J: There's some minor differences and improvements in -J handling, as - now J should work with -i and it actually creates a file first using the - initial name and then *renames* that to the one found in - Content-Disposition (if any). + Closes #2711 + +- KNOWN_BUGS: Stick to same family over SOCKS proxy + +- libssh: goto DISCONNECT state on error, not SSH_SESSION_FREE - -i: only shows headers for HTTP transfers now (as documented). - Previously it would also show for pieces of the transfer that were HTTP - (for example when doing FTP over a HTTP proxy). + ... because otherwise not everything get closed down correctly. - -i: now shows trailers as well. Previously they were not shown at all. + Fixes #2708 + Closes #2712 + +- libssh: include line number in state change debug messages - --libcurl: the CURLOPT_HEADER is no longer set, as the header output is - now done in the header callback. + Closes #2713 -- configure: compile-time SIZEOF checks +- KNOWN_BUGS: Borland support is dropped, AIX problem is too old + +- [Jeroen Ooms brought this change] + + example/crawler.c: simple crawler based on libxml2 - ... instead of exeucting code to get the size. Removes the use of - LD_LIBRARY_PATH for this. + Closes #2706 + +- RELEASE-NOTES: synced + +- DEPRECATE: include year when specifying date + +- DEPRECATE: linkified + +- DEPRECATE: mention the PR that disabled axTLS + +- docs/DEPRECATE.md: spelling and minor formatting + +- DEPRECATE: new doc describing planned item removals - Fixes #2586 - Closes #2589 - Reported-by: Bernhard Walle + Closes #2704 -- configure: replace AC_TRY_RUN with CURL_RUN_IFELSE +- [Gisle Vanem brought this change] + + telnet: fix clang warnings - ... and export LD_LIBRARY_PATH properly. This is a follow-up from - 2d4c215. + telnet.c(1401,28): warning: cast from function call of type 'int' to + non-matching type 'HANDLE' (aka 'void *') [-Wbad-function-cast] - Fixes #2586 - Reported-by: Bernhard Walle + Fixes #2696 + Closes #2700 -- docs: clarify CURLOPT_HTTPGET somewhat - - Reported-by: bsammon on github - Fixes #2590 +- docs: fix missed option name markups -- curl_fnmatch: only allow two asterisks for matching - - The previous limit of 5 can still end up in situation that takes a very - long time and consumes a lot of CPU. +- [Gaurav Malhotra brought this change] + + openssl: Remove some dead code - If there is still a rare use case for this, a user can provide their own - fnmatch callback for a version that allows a larger set of wildcards. + Closes #2698 + +- openssl: make the requested TLS version the *minimum* wanted - This commit was triggered by yet another OSS-Fuzz timeout due to this. - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8369 + The code treated the set version as the *exact* version to require in + the TLS handshake, which is not what other TLS backends do and probably + not what most people expect either. - Closes #2587 + Reported-by: Andreas Olsson + Assisted-by: Gaurav Malhotra + Fixes #2691 + Closes #2694 -- checksrc: fix too long line +- RELEASE-NOTES: synced + +- openssl: allow TLS 1.3 by default - follow-up to e05ad5d + Reported-by: Andreas Olsson + Fixes #2692 + Closes #2693 -- [Aleks brought this change] +- [Adrian Peniak brought this change] - docs: mention HAproxy protocol "version 1" + CURLINFO_TLS_SSL_PTR.3: improve the example - ...as there's also a version 2. + The previous example was a little bit confusing, because SSL* structure + (or other "in use" SSL connection pointer) is not accessible after the + transfer is completed, therefore working with the raw TLS library + specific pointer needs to be done during transfer. - Closes #2579 + Closes #2690 -- examples/progressfunc: make it build on older libcurls +- travis: add a build using the synchronous name resolver - This example was changed in ce2140a8c1 to use the new microsecond based - getinfo option. This change makes it conditionally keep using the older - option so that the example still builds with older libcurl versions. + ... since default uses the threaded one and we test the c-ares build + already. - Closes #2584 + Closes #2689 -- stub_gssapi: fix numerous 'unused parameter' warnings +- configure: remove CURL_CHECK_NI_WITHSCOPEID too - follow-up to d9e92fd9fd1d - -- [Philip Prindeville brought this change] - - getinfo: add microsecond precise timers for various intervals + Since it isn't used either and requires the getnameinfo check - Provide a set of new timers that return the time intervals using integer - number of microseconds instead of floats. + Follow-up to 0aeca41702d2 + +- getnameinfo: not used - The new info names are as following: + Closes #2687 + +- easy_perform: use *multi_timeout() to get wait times - CURLINFO_APPCONNECT_TIME_T - CURLINFO_CONNECT_TIME_T - CURLINFO_NAMELOOKUP_TIME_T - CURLINFO_PRETRANSFER_TIME_T - CURLINFO_REDIRECT_TIME_T - CURLINFO_STARTTRANSFER_TIME_T - CURLINFO_TOTAL_TIME_T + ... and trim the threaded Curl_resolver_getsock() to return zero + millisecond wait times during the first three milliseconds so that + localhost or names in the OS resolver cache gets detected and used + faster. - Closes #2495 + Closes #2685 -- openssl: acknowledge --tls-max for default version too +Max Dymond (27 Jun 2018) +- configure: Add dependent libraries after crypto - ... previously it only used the max setting if a TLS version was also - explicitly asked for. + The linker is pretty dumb and processes things left to right, keeping a + tally of symbols it hasn't resolved yet. So, we need -ldl to appear + after -lcrypto otherwise the linker won't find the dl functions. - Reported-by: byte_bucket - Fixes #2571 - Closes #2572 + Closes #2684 -- bump: start working on the pending 7.61.0 +Daniel Stenberg (27 Jun 2018) +- GOVERNANCE: linkify, changed some titles -- [Dagobert Michelsen brought this change] +- GOVERNANCE: add maintainer details/duties - tests/libtest/Makefile: Do not unconditionally add gcc-specific flags +- url: check Curl_conncache_add_conn return code - The warning flag leads e.g. Sun Studio compiler to bail out. + ... it was previously unchecked in two places and thus errors could + remain undetected and cause trouble. - Closes #2576 + Closes #2681 -- schannel_verify: fix build for non-schannel +- include/README: remove "hacking" advice, not the right place -Jay Satiro (16 May 2018) -- rand: fix typo +- RELEASE-NOTES: synced -- schannel: disable manual verify if APIs not available +- CURLOPT_SSL_VERIFYPEER.3: fix syntax mistake - .. because original MinGW and old compilers do not have the Windows API - definitions needed to support manual verification. - -- [Archangel_SDY brought this change] + Follow-up to b6a16afa0aa5 - schannel: disable client cert option if APIs not available +- netrc: use a larger buffer - Original MinGW targets Windows 2000 by default, which lacks some APIs and - definitions for this feature. Disable it if these APIs are not available. + ... to work with longer passwords etc. Grow it from a 256 to a 4096 + bytes buffer. - Closes https://github.com/curl/curl/pull/2522 + Reported-by: Dario Nieuwenhuis + Fixes #2676 + Closes #2680 -Version 7.60.0 (15 May 2018) +- [Patrick Schlangen brought this change] -Daniel Stenberg (15 May 2018) -- RELEASE-NOTES: 7.60.0 release + CURLOPT_SSL_VERIFYPEER.3: Add performance note + + Closes #2673 -- THANKS: added people from the curl 7.60.0 release +- [Javier Blazquez brought this change] -- docs/libcurl/index.html: removed + multi: fix crash due to dangling entry in connect-pending list - The HTML files are long gone from the dist, now remove the last HTML - file pointing to those missing files. + Fixes #2677 + Closes #2679 + +- ConnectionExists: make sure conn->data is set when "taking" a connection - d + Follow-up to 2c15693. + + Bug #2674 + Closes #2675 -- [steini2000 brought this change] +- [Kevin R. Bulgrien brought this change] - http2: remove unused variable + system.h: fix for gcc on 32 bit OpenServer - Closes #2570 - -- [steini2000 brought this change] + Bug: https://curl.haxx.se/mail/lib-2018-06/0100.html - http2: use easy handle of stream for logging +- [Raphael Gozzo brought this change] -- gcc: disable picky gcc-8 function pointer warnings in two places + cmake: allow multiple SSL backends - Reported-by: Rikard Falkeborn - Bug: #2560 - Closes #2569 - -- http2: use the correct function pointer typedef + This will make possible to select the SSL backend (using + curl_global_sslset()) even when the libcurl is built using CMake - Fixes gcc-8 picky compiler warnings - Reported-by: Rikard Falkeborn - Bug: #2560 - Closes #2568 + Closes #2665 -- CODE_STYLE: mention return w/o parens, but sizeof with +- url: fix dangling conn->data pointer - ... and remove the github markdown syntax so that it renders better on - the web site. Also, don't use back-ticks inlined to allow the CSS to - highlight source code better. + By masking sure to use the *current* easy handle with extracted + connections from the cache, and make sure to NULLify the ->data pointer + when the connection is put into the cache to make this mistake easier to + detect in the future. + + Reported-by: Will Dietz + Fixes #2669 + Closes #2672 -- [Rikard Falkeborn brought this change] +- CURLOPT_INTERFACE.3: interface names not supported on Windows - examples: Fix format specifiers +- travis: run more tests for coverage check - Closes #2561 + ... run a few more tortured based and run all tests event-based. + + Closes #2664 -- [Rikard Falkeborn brought this change] +- multi: fix memory leak when stopped during name resolve + + When the application just started the transfer and then stops it while + the name resolve in the background thread hasn't completed, we need to + wait for the resolve to complete and then cleanup data accordingly. + + Enabled test 1553 again and added test 1590 to also check when the host + name resolves successfully. + + Detected by OSS-fuzz. + Closes #1968 - tool: Fix format specifiers +Viktor Szakats (15 Jun 2018) +- maketgz: delete .bak files, fix indentation + + Ref: https://github.com/curl/curl/pull/2660 + + Closes https://github.com/curl/curl/pull/2662 -- [Rikard Falkeborn brought this change] +Daniel Stenberg (15 Jun 2018) +- runtests.pl: remove debug leftover from bb9a340c73f3 - ntlm: Fix format specifiers +- curl-confopts.m4: fix typo from ed224f23d5beb + + Fixes my local configure to detect a custom installed c-ares without + pkgconfig. -- [Rikard Falkeborn brought this change] +- docs/RELEASE-PROCEDURE.md: renamed to use .md extension + + Closes #2663 - tests: Fix format specifiers +- RELEASE-PROCEDURE: gpg sign the tags -- [Rikard Falkeborn brought this change] +- RELEASE-NOTES: synced - lib: Fix format specifiers +- CURLOPT_HTTPAUTH.3: CURLAUTH_BEARER was added in 7.61.0 -- contributors.sh: use "on github", not at +- [Mamta Upadhyay brought this change] -- http2: getsock fix for uploads + maketgz: fix sed issues on OSX - When there's an upload in progress, make sure to wait for the socket to - become writable. + maketgz creates release tarballs and removes the -DEV string in curl + version (e.g. 7.58.0-DEV), else -DEV shows up on command line when curl + is run. maketgz works fine on linux but fails on OSX. Problem is with + the sed commands that use option -i without an extension. Maketgz + expects GNU sed instead of BSD and this simply won't work on OSX. Adding + a backup extension .bak after -i fixes this issue - Detected-by: steini2000 on github - Bug: #2520 - Closes #2567 - -- pingpong: fix response cache memcpy overflow + Running the script as if on OSX gives this error: - Response data for a handle with a large buffer might be cached and then - used with the "closure" handle when it has a smaller buffer and then the - larger cache will be copied and overflow the new smaller heap based - buffer. + sed: -e: No such file or directory - Reported-by: Dario Weisser - CVE: CVE-2018-1000300 - Bug: https://curl.haxx.se/docs/adv_2018-82c2.html - -- http: restore buffer pointer when bad response-line is parsed + Adding a .bak extension resolves it - ... leaving the k->str could lead to buffer over-reads later on. + Closes #2660 + +- configure: enhance ability to detect/build with static openssl - CVE: CVE-2018-1000301 - Assisted-by: Max Dymond + Fix the -ldl and -ldl + -lpthread checks for OpenSSL, necessary for + building with static libs without pkg-config. - Detected by OSS-Fuzz. - Bug: https://curl.haxx.se/docs/adv_2018-b138.html - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7105 + Reported-by: Marcel Raad + Fixes #2199 + Closes #2659 -Patrick Monnerat (13 May 2018) -- cookies: do not take cookie name as a parameter - - RFC 6265 section 4.2.1 does not set restrictions on cookie names. - This is a follow-up to commit 7f7fcd0. - Also explicitly check proper syntax of cookie name/value pair. +- configure: use pkg-config for c-ares detection - New test 1155 checks that cookie names are not reserved words. + First check if there's c-ares information given as pkg-config info and use + that as first preference. - Reported-By: anshnd at github - Fixes #2564 - Closes #2566 + Reported-by: pszemus on github + Fixes #2203 + Closes #2658 -Daniel Stenberg (12 May 2018) -- smb: reject negative file sizes - - Assisted-by: Max Dymond +- GOVERNANCE.md: explains how this project is run - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8245 + Closes #2657 -- setup_transfer: deal with both sockets being -1 +- KNOWN_BUGS: NTLM doen't support password with § character - Detected by Coverity; CID 1435559. Follow-up to f8d608f38d00. It would - index the array with -1 if neither index was a socket. + Closes #2120 -- travis: add build using NSS +- KNOWN_BUGS: slow connect to localhost on Windows - Closes #2558 + Closes #2281 -- [Sunny Purushe brought this change] +- [Matteo Bignotti brought this change] - openssl: change FILE ops to BIO ops - - To make builds with VS2015 work. Recent changes in VS2015 _IOB_ENTRIES - handling is causing problems. This fix changes the OpenSSL backend code - to use BIO functions instead of FILE I/O functions to circumvent those - problems. + mk-ca-bundle.pl: make -u delete certdata.txt if found not changed - Closes #2512 - -- travis: add a build using WolfSSL + certdata.txt should be deleted also when the process is interrupted by + "same certificate downloaded, exiting" - Assisted-by: Dan Fandrich + The certdata.txt is currently kept on disk even if you give the -u + option - Closes #2528 + Closes #2655 -- RELEASE-NOTES: typo +- progress: remove a set of unused defines + + Reported-by: Peter Wu + Closes #2654 -- RELEASE-NOTES: synced +- TODO: "Option to refuse usernames in URLs" done + + Implemented by Björn in 946ce5b61f -- [Daniel Gustafsson brought this change] +- [Lyman Epp brought this change] - URLs: fix one more http url - - This file wasn't included in commit 4af40b3646d3b09 which updated all - haxx.se http urls to https. The file was committed prior to that update, - but may have been merged after it and hence didn't get updated. + Curl_init_do: handle NULL connection pointer passed in - Closes #2550 - -- github/lock: auto-lock closed issues after 90 days of inactivity + Closes #2653 -- vtls: fix missing commas +- runtests: support variables in - follow-up to e66cca046cef + ... and make use of that to make 1455 work better without using a fixed + local port number. + + Fixes #2649 + Closes #2650 -- vtls: use unified "supports" bitfield member in backends +- Curl_debug: remove dead printhost code - ... instead of previous separate struct fields, to make it easier to - extend and change individual backends without having to modify them all. + The struct field is never set (since 5e0d9aea3) so remove the use of it + and remove the connectdata pointer from the prototype. - closes #2547 + Reported-by: Tejas + Bug: https://curl.haxx.se/mail/lib-2018-06/0054.html + Closes #2647 -- transfer: don't unset writesockfd on setup of multiplexed conns +Viktor Szakats (12 Jun 2018) +- schannel: avoid incompatible pointer warning - Curl_setup_transfer() can be called to setup a new individual transfer - over a multiplexed connection so it shouldn't unset writesockfd. + with clang-6.0: + ``` + vtls/schannel_verify.c: In function 'add_certs_to_store': + vtls/schannel_verify.c:212:30: warning: passing argument 11 of 'CryptQueryObject' from incompatible pointer type [-Wincompatible-pointer-types] + &cert_context)) { + ^ + In file included from /usr/share/mingw-w64/include/schannel.h:10:0, + from /usr/share/mingw-w64/include/schnlsp.h:9, + from vtls/schannel.h:29, + from vtls/schannel_verify.c:40: + /usr/share/mingw-w64/include/wincrypt.h:4437:26: note: expected 'const void **' but argument is of type 'CERT_CONTEXT ** {aka struct _CERT_CONTEXT **}' + WINIMPM WINBOOL WINAPI CryptQueryObject (DWORD dwObjectType, const void *pvObject, DWORD dwExpectedContentTypeFlags, DWORD dwExpectedFormatTypeFlags, DWORD dwFlags, + ^~~~~~~~~~~~~~~~ + ``` + Ref: https://msdn.microsoft.com/library/windows/desktop/aa380264 - Bug: #2520 - Closes #2549 + Closes https://github.com/curl/curl/pull/2648 -- [Frank Gevaerts brought this change] +Daniel Stenberg (12 Jun 2018) +- [Robert Prag brought this change] - configure: put CURLDEBUG and DEBUGBUILD in lib/curl_config.h + schannel: support selecting ciphers - They are removed from the compiler flags. + Given the contstraints of SChannel, I'm exposing these as the algorithms + themselves instead; while replicating the ciphersuite as specified by + OpenSSL would have been preferable, I found no way in the SChannel API + to do so. - This ensures that make dependency tracking will force a rebuild whenever - configure --enable-debug or --enable-curldebug changes. + To use this from the commandline, you need to pass the names of contants + defining the desired algorithms. For example, curl --ciphers + "CALG_SHA1:CALG_RSA_SIGN:CALG_RSA_KEYX:CALG_AES_128:CALG_DH_EPHEM" + https://github.com The specific names come from wincrypt.h - Closes #2548 + Closes #2630 -- http: don't set the "rewind" flag when not uploading anything +- [Bernhard M. Wiedemann brought this change] + + test 46: make test pass after 2025 - It triggers an assert. + shifting the expiry date to 2037 for now + to be before the possibly problematic year 2038 - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8144 - Closes #2546 - -- travis: add an mbedtls build + similar in spirit to commit e6293cf8764e9eecb - Closes #2531 + Closes #2646 -- configure: only check for CA bundle for file-using SSL backends +- [Marian Klymov brought this change] + + cppcheck: fix warnings - When only building with SSL backends that don't use the CA bundle file - (by default), skip the check. + - Get rid of variable that was generating false positive warning + (unitialized) - Fixes #2543 - Fixes #2180 - Closes #2545 - -- ssh-libssh.c: fix left shift compiler warning + - Fix issues in tests - ssh-libssh.c:2429:21: warning: result of '1 << 31' requires 33 bits to - represent, but 'int' only has 32 bits [-Wshift-overflow=] + - Reduce scope of several variables all over - 'len' will never be that big anyway so I converted the run-time check to - a regular assert. - -- [Stephan Mühlstrasser brought this change] + etc + + Closes #2631 - URL: fix ASCII dependency in strcpy_url and strlen_url +- openssl: assume engine support in 1.0.1 or later - Commit 3c630f9b0af097663a64e5c875c580aa9808a92b partially reverted the - changes from commit dd7521bcc1b7a6fcb53c31f9bd1192fcc884bd56 because of - the problem that strcpy_url() was modified unilaterally without also - modifying strlen_url(). As a consequence strcpy_url() was again - depending on ASCII encoding. + Previously it was checked for in configure/cmake, but that would then + leave other build systems built without engine support. - This change fixes strlen_url() and strcpy_url() in parallel to use a - common host-encoding independent criterion for deciding whether an URL - character must be %-escaped. + While engine support probably existed prior to 1.0.1, I decided to play + safe. If someone experience a problem with this, we can widen the + version check. - Closes #2535 + Fixes #2641 + Closes #2644 -- [Denis Ollier brought this change] +- RELEASE-NOTES: synced - docs: remove extraneous commas in man pages - - Closes #2544 +- RELEASE-PROCEDURE: update the release calendar for 2019 -- RELEASE-NOTES: synced +- [Gisle Vanem brought this change] -- Revert "TODO: remove configure --disable-pthreads" + boringssl + schannel: undef X509_NAME in lib/schannel.h - This reverts commit d5d683a97f9765bddfd964fe32e137aa6e703ed3. + Fixes the build problem when both boringssl and schannel are enabled. - --disable-pthreads can be used to disable pthreads and get the threaded - resolver to use the windows threading when building with mingw. + Fixes #2634 + Closes #2643 -- vtls: don't define MD5_DIGEST_LENGTH for wolfssl - - ... as it defines it (too) +- [Vladimir Kotal brought this change] -- TODO: remove configure --disable-pthreads + mk-ca-bundle.pl: leave certificate name untouched in decode() + + Closes #2640 -Jay Satiro (2 May 2018) -- [David Garske brought this change] +- [Rikard Falkeborn brought this change] - wolfssl: Fix non-blocking connect + tests/libtests/Makefile.am: Add lib1521.c to CLEANFILES - Closes https://github.com/curl/curl/pull/2542 - -Daniel Stenberg (30 Apr 2018) -- CURLOPT_URL.3: add ENCODING section [ci skip] + This removes the generated lib1521.c when running make clean. - Feedback-by: Michael Kilburn + Closes #2633 -- KNOWN_BUGS: Client cert with Issuer DN differs between backends - - Closes #1411 +- [Rikard Falkeborn brought this change] -- KNOWN_BUGS: Passive transfer tries only one IP address + tests/libtest: Add lib1521 to nodist_SOURCES - Closes #1508 - -- KNOWN_BUGS: --upload-file . hang if delay in STDIN + Since 467da3af0, lib1521.c is generated instead of checked in. According + to the commit message, the intention was to remove it from the tarball + as well. However, it is still present when running make dist. To remove + it, add it to nodist_lib1521_SOURCES. This also means there is no need + for the manually added dist-rule in the Makefile. - Closes #2051 + Also update CMakelists.txt to handle the fact that we now may have + nodist_SOURCES. -- KNOWN_BUGS: Connection information when using TCP Fast Open - - Closes #1332 +- [Stephan Mühlstrasser brought this change] -- travis: enable libssh2 on both macos and Linux + system.h: add support for IBM xlc C compiler - It seems to not be detected by default anymore (which is a bug I - believe) + Added a section to system.h guarded with __xlc__ for the IBM xml C + compiler. Before this change the section titled 'generic "safe guess" on + old 32 bit style' was used, which resulted in a wrong definition of + CURL_TYPEOF_CURL_SOCKLEN_T, and for 64-bit also CURL_TYPEOF_CURL_OFF_T + was wrong. - Closes #2541 - -- TODO: Support the clienthello extension + Compilation warnings fixed with this change: - Closes #2299 - -- TODO: CLOEXEC + CC libcurl_la-ftp.lo + "ftp.c", line 290.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "ftp.c", line 293.48: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "ftp.c", line 1070.49: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "ftp.c", line 1154.53: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "ftp.c", line 1187.51: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + CC libcurl_la-connect.lo + "connect.c", line 448.56: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "connect.c", line 516.66: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "connect.c", line 687.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + "connect.c", line 696.55: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. + CC libcurl_la-tftp.lo + "tftp.c", line 1115.33: 1506-280 (W) Function argument assignment between types "unsigned long* restrict" and "int*" is not allowed. - Closes #2252 + Closes #2637 -- tests: provide 'manual' as a feature to optionally require +- cmdline-opts/cert-type.d: mention "p12" as a recognized type as well + +Viktor Szakats (3 Jun 2018) +- spelling fixes - ... and make test 1026 rely on that feature so that --disable-manual - builds don't cause test failures. + Detected using the `codespell` tool (version 1.13.0). - Reported-by: Max Dymond and Anders Roxell - Fixes #2533 - Closes #2540 - -- CURLINFO_PROTOCOL.3: mention the existing defined names + Also secure and fix an URL. -Jay Satiro (27 Apr 2018) -- [Daniel Gustafsson brought this change] +Daniel Stenberg (2 Jun 2018) +- axtls: follow-up spell fix of comment - cookies: remove unused macro +- axTLS: not considered fit for use - Commit 2bc230de63 made the macro MAX_COOKIE_LINE_TXT become unused, - so remove as it's not part of the published API. + URL: https://curl.haxx.se/mail/lib-2018-06/0000.html - Closes https://github.com/curl/curl/pull/2537 - -Daniel Stenberg (27 Apr 2018) -- [Daniel Gustafsson brought this change] + This is step one. It adds #error statements that require source edits to + make curl build again if asked to use axTLS. At a later stage we might + remove the axTLS specific code completely. + + Closes #2628 - checksrc: force indentation of lines after an else +- build: remove the Borland specific makefiles - This extends the INDENTATION case to also handle 'else' statements - and require proper indentation on the following line. Also fixes the - offending cases found in the codebase. + According to the user survey 2018, not even one out of 670 users use + them. Nobody on the mailing list spoke up for them either. - Closes #2532 + Closes #2629 -- http2: fix null pointer dereference in http2_connisdead +- curl_addrinfo: use same #ifdef conditions in source as header - This function can get called on a connection that isn't setup enough to - have the 'recv_underlying' function pointer initialized so it would try - to call the NULL pointer. + ... for curl_dofreeaddrinfo + +- multi: remove a DEBUGF() - Reported-by: Dario Weisser + ... it might call infof() with a NULL first argument that isn't harmful + but makes it not do anything. The infof() line is not very useful + anymore, it has served it purpose. Good riddance! - Follow-up to db1b2c7fe9b093f8 (never shipped in a release) - Closes #2536 + Fixes #2627 -- http2: get rid of another strstr() +- [Alibek.Jorajev brought this change] + + CURLOPT_RESOLVE: always purge old entry first - Follow-up to 1514c44655e12e: replace another strstr() call done on a - buffer that might not be zero terminated - with a memchr() call, even if - we know the substring will be found. + If there's an existing entry using the selected name. - Assisted-by: Max Dymond + Closes #2622 + +- fnmatch: use the system one if available - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8021 + If configure detects fnmatch to be available, use that instead of our + custom one for FTP wildcard pattern matching. For standard compliance, + to reduce our footprint and to use already well tested and well + exercised code. - Closes #2534 + A POSIX fnmatch behaves slightly different than the internal function + for a few test patterns currently and the macOS one yet slightly + different. Test case 1307 is adjusted for these differences. + + Closes #2626 -- cyassl: adapt to libraries without TLS 1.0 support built-in +Patrick Monnerat (31 May 2018) +- os400: add new option in ILE/RPG binding - WolfSSL doesn't enable it by default anymore + Follow-up to commit 946ce5b -- configure: provide --with-wolfssl as an alias for --with-cyassl +Daniel Stenberg (31 May 2018) +- tests/libtest/.gitignore: follow-up fix to ignore lib5* too -- RELEASE-NOTES: synced +- KNOWN_BUGS: CURL_GLOBAL_SSL + + Closes #2276 -- [Daniel Gustafsson brought this change] +- [Bernhard Walle brought this change] - os400.c: fix ASSIGNWITHINCONDITION checksrc warnings + configure: check for declaration of getpwuid_r - All occurrences of assignment within conditional expression in - os400sys.c rewritten into two steps: first assignment and then the check - on the success of the assignment. Also adjust related incorrect brace - positions to match project indentation style. + On our x86 Android toolchain, getpwuid_r is implemented but the header + is missing: - This was spurred by seeing "if((inp = input_token))", but while in there - all warnings were fixed. + netrc.c:81:7: error: implicit declaration of function 'getpwuid_r' [-Werror=implicit-function-declaration] - There should be no functional change from these changes. + Unfortunately, the function is used in curl_ntlm_wb.c, too, so I moved + the prototype to curl_setup.h. - Closes #2525 + Signed-off-by: Bernhard Walle + Closes #2609 -- [Daniel Gustafsson brought this change] +- [Rikard Falkeborn brought this change] - cookies: ensure that we have cookies before writing jar - - The jar should be written iff there are cookies, so ensure that we still - have cookies after expiration to avoid creating an empty file. + tests: update .gitignore for libtests - Closes #2529 + Closes #2624 -- strcpy_url: only %-encode values >= 0x80 - - OSS-Fuzz detected - - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8000 - - Broke in dd7521bcc1b7 +- [Rikard Falkeborn brought this change] -- mime: avoid NULL pointer dereference risk + strictness: correct {infof, failf} format specifiers - Coverity detected, CID 1435120 - - Closes #2527 + Closes #2623 -- [Stephan Mühlstrasser brought this change] +- [Björn Stenberg brought this change] - ctype: restore character classification for non-ASCII platforms + option: disallow username in URL - With commit 4272a0b0fc49a1ac0ceab5c4a365c9f6ab8bf8e2 curl-speficic - character classification macros and functions were introduced in - curl_ctype.[ch] to avoid dependencies on the locale. This broke curl on - non-ASCII, e.g. EBCDIC platforms. This change restores the previous set - of character classification macros when CURL_DOES_CONVERSIONS is - defined. + Adds CURLOPT_DISALLOW_USERNAME_IN_URL and --disallow-username-in-url. Makes + libcurl reject URLs with a username in them. - Closes #2494 + Closes #2340 -- ftplistparser: keep state between invokes +- libcurl-security.3: improved layout for two rememdy lists + +- libcurl-security.3: refer to URL instead of in-source markdown file + +Viktor Szakats (30 May 2018) +- curl.rc: embed manifest for correct Windows version detection - Fixes FTP wildcard parsing when done over a number of read buffers. + * enable it in `src/Makefile.m32` + * enable it in `winbuild/MakefileBuild.vc` if a custom manifest is + _not_ enabled via the existing `EMBED_MANIFEST` option + * enable it for all Windows CMake builds (also disable the built-in + minimal manifest, added by CMake by default.) - Regression from f786d1f14 + For other build systems, add the `-DCURL_EMBED_MANIFEST` option to + the list of RC (Resource Compiler) flags to enable the manifest + included in `src/curl.rc`. This may require to disable whatever + automatic or other means in which way another manifest is added to + `curl.exe`. - Reported-by: wncboy on github - Fixes #2445 - Closes #2526 - -- examples/http2-upload: expand buffer to avoid silly warning + Notice that Borland C doesn't support this method due to a + long-pending resource compiler bug. Watcom C may also not handle + it correctly when the `-zm` `wrc` option is used (this option may + be unnecessary though) and regardless of options in certain earlier + revisions of the 2.0 beta version. - http2-upload.c:135:44: error: ‘%02d’ directive output may be truncated - writing between 2 and 11 bytes into a region of size between 8 and 17 + Closes https://github.com/curl/curl/pull/1221 + Fixes https://github.com/curl/curl/issues/2591 -- examples/sftpuploadresume: typecast fseek argument to long - - /docs/examples/sftpuploadresume.c:102:12: warning: conversion to 'long - int' from 'curl_off_t {aka long long int}' may alter its value +Patrick Monnerat (30 May 2018) +- os400: sync EBCDIC wrappers and ILE/RPG binding with latest options -- Revert "ftplistparser: keep state between invokes" - - This reverts commit abbc8457d85aca74b7cfda1d394b0844932b2934. +- os400: implement mime api EBCDIC wrappers - Caused fuzzer problems on travis not seen when this was a PR! + Also sync ILE/RPG binding to define the new functions. -- Curl_memchr: zero length input can't match +Daniel Stenberg (29 May 2018) +- setopt: add TLS 1.3 ciphersuites - Avoids undefined behavior. + Adds CURLOPT_TLS13_CIPHERS and CURLOPT_PROXY_TLS13_CIPHERS. - Reported-by: Geeknik Labs + curl: added --tls13-ciphers and --proxy-tls13-ciphers + + Fixes #2435 + Reported-by: zzq1015 on github + Closes #2607 -- ftplistparser: keep state between invokes +- configure: override AR_FLAGS to silence warning - Fixes FTP wildcard parsing when doing over a number of read buffers. + The automake default ar flags are 'cru', but the 'u' flag in there + causes warnings on many modern Linux distros. Removing 'u' may have a + minor performance impact on older distros but should not cause harm. - Regression from f786d1f14 + Explained on the automake mailing list already back in April 2015: - Reported-by: wncboy on github - Fixes #2445 - Closes #2519 - -- ftplistparser: renamed some members and variables + https://www.mail-archive.com/automake-patches@gnu.org/msg07705.html - ... to make them better spell out what they're for. - -- RELEASE-NOTES: synced + Reported-by: elephoenix on github + Fixes #2617 + Closes #2619 -- [Christian Schmitz brought this change] +Sergei Nikulov (29 May 2018) +- cmake: fixed comments in compile checks code - curl_global_sslset: always provide available backends +Daniel Stenberg (29 May 2018) +- INSTALL: LDFLAGS=-Wl,-R/usr/local/ssl/lib - Closes #2499 + ... the older description doesn't work + + Reported-by: Peter Varga + Fixes #2615 + Closes #2616 -- http2: convert an assert to run-time check +- [Will Dietz brought this change] + + KNOWN_BUGS: restore text regarding #2101. - Fuzzing has proven we can reach code in on_frame_recv with status_code - not having been set, so let's detect that in run-time (instead of with - assert) and error error accordingly. + This was added earlier but appears to have been removed accidentally. - (This should no longer happen with the latest nghttp2) + AFAICT this is very much still an issue. - Detected by OSS-Fuzz - Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7903 - Closes #2514 - -- curl.1: clarify that options and URLs can be mixed + ----- - Fixes #2515 - Closes #2517 - -Jay Satiro (23 Apr 2018) -- [Archangel_SDY brought this change] - - CURLOPT_SSLCERT.3: improve WinSSL-specific usage info + I say "accidentally" because the text seems to have harmlessly snuck + into [1] (which makes no mention of it). [1] was later reverted for + unspecified reasons in [2], presumably because the mentioned issue was + fixed or invalid. - Ref: https://github.com/curl/curl/pull/2376#issuecomment-381858780 + [1] de9fac00c40db321d44fa6fbab6eb62ec4c83998 + [2] 16d1f369403cbb04bd7b085eabbeebf159473fc2 - Closes https://github.com/curl/curl/pull/2504 - -- [Archangel_SDY brought this change] + Closes #2618 - schannel: fix build error on targets <= XP +- fnmatch: insist on escaped bracket to match - - Use CRYPT_STRING_HEX instead of CRYPT_STRING_HEXRAW since XP doesn't - support the latter. + A non-escaped bracket ([) is for a character group - as documented. It + will *not* match an individual bracket anymore. Test case 1307 updated + accordingly to match. - Ref: https://github.com/curl/curl/pull/2376#issuecomment-382153668 + Problem detected by OSS-Fuzz, although this fix is probably not a final + fix for the notorious timeout issues. - Closes https://github.com/curl/curl/pull/2504 + Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8525 + Closes #2614 -Daniel Stenberg (23 Apr 2018) -- Revert "ftplistparser: keep state between invokes" +Patrick Monnerat (28 May 2018) +- psl: use latest psl and refresh it periodically - This reverts commit 8fb78f9ddc6d858d630600059b8ad84a80892fd9. + The latest psl is cached in the multi or share handle. It is refreshed + before use after 72 hours. + New share lock CURL_LOCK_DATA_PSL controls the psl cache sharing. + If the latest psl is not available, the builtin psl is used. - Unfortunately this fix introduces memory leaks I've not been able to fix - in several days. Reverting this for now to get the leaks fixed. + Reported-by: Yaakov Selkowitz + Fixes #2553 + Closes #2601 -Jay Satiro (21 Apr 2018) -- tool_help: clarify --max-time unit of time is seconds - - Before: - -m, --max-time