cosmopolitan/third_party/mbedtls
Justine Tunney 00611e9b06 Improve ZIP filesystem and change its prefix
The ZIP filesystem has a breaking change. You now need to use /zip/ to
open() / opendir() / etc. assets within the ZIP structure of your APE
binary, instead of the previous convention of using zip: or zip! URIs.
This is needed because Python likes to use absolute paths, and having
ZIP paths encoded like URIs simply broke too many things.

Many more system calls have been updated to be able to operate on ZIP
files and file descriptors. In particular fcntl() and ioctl() since
Python would do things like ask if a ZIP file is a terminal and get
confused when the old implementation mistakenly said yes, because the
fastest way to guarantee native file descriptors is to dup(2). This
change also improves the async signal safety of zipos and ensures it
doesn't maintain any open file descriptors beyond that which the user
has opened.

This change makes a lot of progress towards adding magic numbers that
are specific to platforms other than Linux. The philosophy here is that,
if you use an operating system like FreeBSD, then you should be able to
take advantage of FreeBSD exclusive features, even if we don't polyfill
them on other platforms. For example, you can now open() a file with the
O_VERIFY flag. If your program runs on other platforms, then Cosmo will
automatically set O_VERIFY to zero. This lets you safely use it without
the need for #ifdef or ifstatements which detract from readability.

One of the blindspots of the ASAN memory hardening we use to offer Rust
like assurances has always been that memory passed to the kernel via
system calls (e.g. writev) can't be checked automatically since the
kernel wasn't built with MODE=asan. This change makes more progress
ensuring that each system call will verify the soundness of memory
before it's passed to the kernel. The code for doing these checks is
fast, particularly for buffers, where it can verify 64 bytes a cycle.

- Correct O_LOOP definition on NT
- Introduce program_executable_name
- Add ASAN guards to more system calls
- Improve termios compatibility with BSDs
- Fix bug in Windows auxiliary value encoding
- Add BSD and XNU specific errnos and open flags
- Add check to ensure build doesn't talk to internet
2021-08-22 01:11:53 -07:00
..
test Improve ZIP filesystem and change its prefix 2021-08-22 01:11:53 -07:00
aes.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
aes.h Undiamond Python headers 2021-08-12 14:07:40 -07:00
aesni.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
aesni.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
asn1.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1parse.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1write.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1write.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
base64.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
base64.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
bigmul.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
bigmul4.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bignum.c Undiamond Python headers 2021-08-12 14:07:40 -07:00
bignum.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bignum_internal.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bigshift.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
ccm.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ccm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
certs.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
certs.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
chacha20.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
chacha20.h Make chacha20 go faster 2021-07-05 14:03:50 -07:00
chachapoly.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
chachapoly.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
check.inc Refactor out some duplicated code 2021-08-14 06:17:56 -07:00
chk.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher_wrap.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
common.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
config.h Refactor out some duplicated code 2021-08-14 06:17:56 -07:00
ctr_drbg.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ctr_drbg.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
debug.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
debug.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
des.c Undiamond Python headers 2021-08-12 14:07:40 -07:00
des.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
dhm.c Secure the testing infrastructure 2021-08-07 13:22:35 -07:00
dhm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdh.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecdh.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdh_everest.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdh_everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdsa.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp.c Refactor out some duplicated code 2021-08-14 06:17:56 -07:00
ecp.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecp256.c Undiamond Python headers 2021-08-12 14:07:40 -07:00
ecp384.c Undiamond Python headers 2021-08-12 14:07:40 -07:00
ecp_curves.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecp_internal.h Fix bugs and make improvements to redbean 2021-08-06 14:18:34 -07:00
ecpshl.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
endian.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy_poll.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy_poll.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
error.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
error.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
everest.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
fastdiv.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
gcm.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
gcm.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getalertdescription.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getciphersuite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getciphersuitename.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getsslstatename.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hkdf.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hkdf.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
hmac_drbg.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hmac_drbg.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
iana.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
isciphersuitegood.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
karatsuba.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
LICENSE Import Mbed TLS v2.26.0 2021-06-24 11:12:45 -07:00
math.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
mbedtls.mk Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
md.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
md.h Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
md5.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
md5.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
mdtype.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
net_sockets.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
net_sockets.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
nist_kw.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
nist_kw.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
oid.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
oid.h Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
param.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pem.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pem.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pk.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_wrap.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pkcs5.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pkcs5.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkparse.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pktype.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkwrite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
poly1305.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
poly1305.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
profile.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rando.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
README.cosmo Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
rsa.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
rsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
rsa_internal.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rsa_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
secp256r1.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
secp384r1.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
select.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha1.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha1.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha256.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
sha256.h Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
sha512.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
sha512.h Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
shiftright-avx.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
shiftright.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
sigalg.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
speed.sh Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
srtp.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl.h Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
ssl_cache.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cache.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_ciphersuites.c Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
ssl_ciphersuites.h Implement RFC8442 2021-08-07 16:43:00 -07:00
ssl_cli.c Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
ssl_cookie.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cookie.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_internal.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_invasive.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_msg.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
ssl_srv.c Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
ssl_ticket.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_ticket.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls.c Make redbean SSL more tunable 2021-08-09 07:38:57 -07:00
ssl_tls13_keys.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls13_keys.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
version.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_create.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crl.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crl.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_crt.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crt.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_csr.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509write_crt.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509write_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
zeroize.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00

DESCRIPTION

  Mbed TLS is a crypto library built by ARM that's been released
  under a more permissive license than alternatives like OpenSSL
  and is useful for interoperating with systems that require TLS

SOURCE

  https://github.com/ARMmbed/mbedtls/archive/refs/tags/v2.26.0.tar.gz

LICENSE

  Apache 2.o

LOCAL CHANGES

  - Strengthened server against DOS by removing expensive protections
    for old Internet Explorer against Lucky Thirteen timing attacks.

  - Reduce build+test latency from 15 seconds to 5 seconds.

  - Features have been added that enable this library to produce SSL
    certificates that can be used by Google Chrome. This required we
    add featurces for editing Subject Alternative Names and Extended
    Key Usage X.509 extension fields since upstream mbedtls can only
    do that currently for Netscape Navigator.

  - Local changes needed to be made to test_suite_ssl.datax due to it
    not taking into consideration disabled features like DTLS.

  - Local changes needed to be made to test_suite_x509parse.datax due
    to the features we added for subject alternative name parsing.

  - We've slimmed things down to meet our own specific local needs.
    For example, we don't need the PSA code since we don't target ARM
    hardware. We also don't need algorithms like camellia, blowfish,
    ripemd, arc4, ecjpake, etc. We want security code that's simple,
    readable, and easy to maintain. For example, the formally verified
    eliptic curve diffie-helman code was 38 files and most of it was
    dead code which could be consolidated into one < 1 kLOC file.

  - The only breaking API change that's been made is to redefine int
    arrays of things like long lists of ciphersuites to be uint8_t or
    uint16_t instead when appropriate.

  - Exported test code so it (a) doesn't have python as a build time
    dependency, (b) doesn't print to stdout on success, (c) bundles
    its dependencies inside a zip container so the tests are able to
    run hermetically if the binary is scp'd to some machine, and (d)
    doesn't have large amounts of duplicated generated code.

  - Fix mbedtls_mpi_sub_abs() to not call malloc/free/memcpy since
    it's called 11,124 times during as SSL handshake.

  - Make P-256 and P-384 modulus goes 5x faster.

  - Make chacha20 26% faster.

  - Make base64 100x faster.

  - Make gcm faster.