cosmopolitan/third_party/mbedtls
Justine Tunney ae5d06dc53 Unbloat build config
- 10.5% reduction of o//depend dependency graph
- 8.8% reduction in latency of make command
- Fix issue with temporary file cleanup

There's a new -w option in compile.com that turns off the recent
Landlock output path workaround for "good commands" which do not
unlink() the output file like GNU tooling does.

Our new GNU Make unveil sandboxing appears to have zero overhead
in the grand scheme of things. Full builds are pretty fast since
the only thing that's actually slowed us down is probably libcxx

    make -j16 MODE=rel
    RL: took 85,732,063µs wall time
    RL: ballooned to 323,612kb in size
    RL: needed 828,560,521µs cpu (11% kernel)
    RL: caused 39,080,670 page faults (99% memcpy)
    RL: 350,073 context switches (72% consensual)
    RL: performed 0 reads and 11,494,960 write i/o operations

pledge() and unveil() no longer consider ENOSYS to be an error.
These functions have also been added to Python's cosmo module.

This change also removes some WIN32 APIs and System Five magnums
which we're not using and it's doubtful anyone else would be too
2022-08-10 04:43:09 -07:00
..
test Unbloat build config 2022-08-10 04:43:09 -07:00
aes.c Unbloat build config 2022-08-10 04:43:09 -07:00
aes.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
aesni.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
aesni.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
asn1.h Unbloat build config 2022-08-10 04:43:09 -07:00
asn1parse.c Unbloat build config 2022-08-10 04:43:09 -07:00
asn1write.c Unbloat build config 2022-08-10 04:43:09 -07:00
asn1write.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
base64.c Unbloat build config 2022-08-10 04:43:09 -07:00
base64.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
bigmul.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
bigmul4.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bignum.c Unbloat build config 2022-08-10 04:43:09 -07:00
bignum.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
bignum_internal.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bigshift.c Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
blake2b256.c Decentralize Python native module linkage 2021-09-07 11:40:11 -07:00
ccm.c Unbloat build config 2022-08-10 04:43:09 -07:00
ccm.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
certs.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
certs.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
chacha20.c Unbloat build config 2022-08-10 04:43:09 -07:00
chacha20.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
chachapoly.c Unbloat build config 2022-08-10 04:43:09 -07:00
chachapoly.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
check.inc Refactor out some duplicated code 2021-08-14 06:17:56 -07:00
chk.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher.c Unbloat build config 2022-08-10 04:43:09 -07:00
cipher.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
cipher_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher_wrap.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
common.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
config.h Make numerous improvements 2021-09-28 01:52:34 -07:00
ctr_drbg.c Make numerous improvements 2021-09-28 01:52:34 -07:00
ctr_drbg.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
debug.c Unbloat build config 2022-08-10 04:43:09 -07:00
debug.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
des.c Add error checks to Python objectifier (#281) 2021-10-02 06:17:17 -07:00
des.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
dhm.c Unbloat build config 2022-08-10 04:43:09 -07:00
dhm.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ecdh.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecdh.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ecdh_everest.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecdh_everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdsa.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecdsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecp.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ecp256.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecp384.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecp_curves.c Unbloat build config 2022-08-10 04:43:09 -07:00
ecp_internal.h Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
ecpshl.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
endian.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy.c Unbloat build config 2022-08-10 04:43:09 -07:00
entropy.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
entropy_poll.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy_poll.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
error.c Unbloat build config 2022-08-10 04:43:09 -07:00
error.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
everest.c Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
fastdiv.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
formatclientciphers.c Import C++ Standard Template Library 2022-03-22 06:41:54 -07:00
gcm.c Make numerous improvements 2021-09-28 01:52:34 -07:00
gcm.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
getalertdescription.c Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
getciphersuite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getciphersuitename.c Make exciting improvements 2022-03-18 03:02:00 -07:00
getsslstatename.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hkdf.c Make numerous improvements 2021-09-28 01:52:34 -07:00
hkdf.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
hmac_drbg.c Make numerous improvements 2021-09-28 01:52:34 -07:00
hmac_drbg.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
iana.h Import C++ Standard Template Library 2022-03-22 06:41:54 -07:00
isciphersuitegood.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
karatsuba.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
LICENSE Import Mbed TLS v2.26.0 2021-06-24 11:12:45 -07:00
math.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
mbedtls.mk Add error checks to Python objectifier (#281) 2021-10-02 06:17:17 -07:00
md.c Unbloat build config 2022-08-10 04:43:09 -07:00
md.h Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
md5.c Unbloat build config 2022-08-10 04:43:09 -07:00
md5.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
mdtype.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
net_sockets.c Add more missing libc functionality 2022-08-06 10:50:51 -07:00
net_sockets.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
nist_kw.c Unbloat build config 2022-08-10 04:43:09 -07:00
nist_kw.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
oid.c Unbloat build config 2022-08-10 04:43:09 -07:00
oid.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
param.c Unbloat build config 2022-08-10 04:43:09 -07:00
pem.c Unbloat build config 2022-08-10 04:43:09 -07:00
pem.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
pk.c Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
pk.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
pk_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_wrap.c Unbloat build config 2022-08-10 04:43:09 -07:00
pkcs5.c Make numerous improvements 2021-09-28 01:52:34 -07:00
pkcs5.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
pkparse.c Make numerous improvements 2021-09-28 01:52:34 -07:00
pktype.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkwrite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
poly1305.c Make numerous improvements 2021-09-28 01:52:34 -07:00
poly1305.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
profile.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rando.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
README.cosmo Restore Referer-Policy and wrap up MbedTLS changes 2021-08-04 01:05:49 -07:00
rsa.c Improve redbean plus code size optimizations 2022-05-29 08:21:19 -07:00
rsa.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
rsa_internal.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rsa_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
secp256r1.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
secp384r1.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
select.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha1.c Make numerous improvements 2021-09-28 01:52:34 -07:00
sha1.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
sha256.c Make more libc improvements 2022-08-06 17:18:40 -07:00
sha256.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
sha512.c Make more libc improvements 2022-08-06 17:18:40 -07:00
sha512.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
shiftright-avx.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
shiftright.c Reduce build latency and fix old cpu bugs 2021-08-05 14:43:53 -07:00
sigalg.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
speed.sh Make numerous improvements 2021-09-28 01:52:34 -07:00
srtp.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl.h Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
ssl_cache.c Make numerous improvements 2021-09-28 01:52:34 -07:00
ssl_cache.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_ciphersuites.c Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
ssl_ciphersuites.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ssl_cli.c Add MODE=optlinux build mode (#141) 2021-10-14 19:36:49 -07:00
ssl_cookie.c Make numerous improvements 2021-09-28 01:52:34 -07:00
ssl_cookie.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ssl_internal.h Make numerous improvements 2021-09-28 01:52:34 -07:00
ssl_invasive.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_msg.c Make numerous improvements 2021-09-28 01:52:34 -07:00
ssl_srv.c Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
ssl_ticket.c Make numerous improvements 2021-09-28 01:52:34 -07:00
ssl_ticket.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
ssl_tls.c Fix stdio regression 2022-05-19 00:51:15 -07:00
ssl_tls13_keys.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls13_keys.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
version.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509.c Make numerous improvements 2021-09-28 01:52:34 -07:00
x509.h Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
x509_create.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crl.c Make numerous improvements 2021-09-28 01:52:34 -07:00
x509_crl.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
x509_crt.c Reduce makefile dependencies by 10% 2022-06-08 20:01:28 -07:00
x509_crt.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
x509_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_csr.h Make it possible to compile redbean with chibicc 2022-04-22 15:25:04 -07:00
x509write_crt.c Revert whitespace fixes to third_party (#501) 2022-07-21 21:46:07 -07:00
x509write_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
zeroize.c Improve redbean plus code size optimizations 2022-05-29 08:21:19 -07:00

DESCRIPTION

  Mbed TLS is a crypto library built by ARM that's been released
  under a more permissive license than alternatives like OpenSSL
  and is useful for interoperating with systems that require TLS

SOURCE

  https://github.com/ARMmbed/mbedtls/archive/refs/tags/v2.26.0.tar.gz

LICENSE

  Apache 2.o

LOCAL CHANGES

  - Strengthened server against DOS by removing expensive protections
    for old Internet Explorer against Lucky Thirteen timing attacks.

  - Reduce build+test latency from 15 seconds to 5 seconds.

  - Features have been added that enable this library to produce SSL
    certificates that can be used by Google Chrome. This required we
    add featurces for editing Subject Alternative Names and Extended
    Key Usage X.509 extension fields since upstream mbedtls can only
    do that currently for Netscape Navigator.

  - Local changes needed to be made to test_suite_ssl.datax due to it
    not taking into consideration disabled features like DTLS.

  - Local changes needed to be made to test_suite_x509parse.datax due
    to the features we added for subject alternative name parsing.

  - We've slimmed things down to meet our own specific local needs.
    For example, we don't need the PSA code since we don't target ARM
    hardware. We also don't need algorithms like camellia, blowfish,
    ripemd, arc4, ecjpake, etc. We want security code that's simple,
    readable, and easy to maintain. For example, the formally verified
    eliptic curve diffie-helman code was 38 files and most of it was
    dead code which could be consolidated into one < 1 kLOC file.

  - The only breaking API change that's been made is to redefine int
    arrays of things like long lists of ciphersuites to be uint8_t or
    uint16_t instead when appropriate.

  - Exported test code so it (a) doesn't have python as a build time
    dependency, (b) doesn't print to stdout on success, (c) bundles
    its dependencies inside a zip container so the tests are able to
    run hermetically if the binary is scp'd to some machine, and (d)
    doesn't have large amounts of duplicated generated code.

  - Fix mbedtls_mpi_sub_abs() to not call malloc/free/memcpy since
    it's called 11,124 times during as SSL handshake.

  - Make P-256 and P-384 modulus goes 5x faster.

  - Make chacha20 26% faster.

  - Make base64 100x faster.

  - Make gcm faster.