From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Cheng Zhao Date: Fri, 29 Mar 2019 16:50:56 +0900 Subject: fix: key gen APIs are not available in BoringSSL This will make Node's key pair generation APIs fail. diff --git a/src/node_crypto.cc b/src/node_crypto.cc index ed886abd749661a90e488b24152b2998fb38a4f8..3c9345fb46f65294b005102eafbaf60604a475f9 100644 --- a/src/node_crypto.cc +++ b/src/node_crypto.cc @@ -288,24 +288,14 @@ Maybe Decorate(Environment* env, Local obj, V(BIO) \ V(PKCS7) \ V(X509V3) \ - V(PKCS12) \ V(RAND) \ - V(DSO) \ V(ENGINE) \ V(OCSP) \ V(UI) \ V(COMP) \ V(ECDSA) \ V(ECDH) \ - V(OSSL_STORE) \ - V(FIPS) \ - V(CMS) \ - V(TS) \ V(HMAC) \ - V(CT) \ - V(ASYNC) \ - V(KDF) \ - V(SM2) \ V(USER) \ #define V(name) case ERR_LIB_##name: lib = #name "_"; break; @@ -6135,6 +6125,7 @@ class DSAKeyPairGenerationConfig : public KeyPairGenerationConfig { if (EVP_PKEY_paramgen_init(param_ctx.get()) <= 0) return nullptr; +#ifndef OPENSSL_IS_BORINGSSL if (EVP_PKEY_CTX_set_dsa_paramgen_bits(param_ctx.get(), modulus_bits_) <= 0) return nullptr; @@ -6145,6 +6136,7 @@ class DSAKeyPairGenerationConfig : public KeyPairGenerationConfig { return nullptr; } } +#endif EVP_PKEY* raw_params = nullptr; if (EVP_PKEY_paramgen(param_ctx.get(), &raw_params) <= 0) diff --git a/src/node_crypto_common.cc b/src/node_crypto_common.cc index 6473b652ac95609aff555d99be38b48a5aa513a5..caaaf19dc02101c2024b511780c94fc85476b7a2 100644 --- a/src/node_crypto_common.cc +++ b/src/node_crypto_common.cc @@ -240,10 +240,10 @@ int UseSNIContext(const SSLPointer& ssl, BaseObjectPtr context) { } const char* GetClientHelloALPN(const SSLPointer& ssl) { +#ifndef OPENSSL_IS_BORINGSSL const unsigned char* buf; size_t len; size_t rem; - if (!SSL_client_hello_get0_ext( ssl.get(), TLSEXT_TYPE_application_layer_protocol_negotiation, @@ -252,17 +252,18 @@ const char* GetClientHelloALPN(const SSLPointer& ssl) { rem < 2) { return nullptr; } - len = (buf[0] << 8) | buf[1]; if (len + 2 != rem) return nullptr; return reinterpret_cast(buf + 3); +#endif + return nullptr; } const char* GetClientHelloServerName(const SSLPointer& ssl) { +#ifndef OPENSSL_IS_BORINGSSL const unsigned char* buf; size_t len; size_t rem; - if (!SSL_client_hello_get0_ext( ssl.get(), TLSEXT_TYPE_server_name, @@ -284,6 +285,8 @@ const char* GetClientHelloServerName(const SSLPointer& ssl) { if (len + 2 > rem) return nullptr; return reinterpret_cast(buf + 5); +#endif + return nullptr; } const char* GetServerName(SSL* ssl) { @@ -291,7 +294,10 @@ const char* GetServerName(SSL* ssl) { } bool SetGroups(SecureContext* sc, const char* groups) { +#ifndef OPENSSL_IS_BORINGSSL return SSL_CTX_set1_groups_list(**sc, groups) == 1; +#endif + return false; } const char* X509ErrorCode(long err) { // NOLINT(runtime/int) @@ -768,13 +774,13 @@ MaybeLocal GetClientHelloCiphers( Environment* env, const SSLPointer& ssl) { EscapableHandleScope scope(env->isolate()); - const unsigned char* buf; - size_t len = SSL_client_hello_get0_ciphers(ssl.get(), &buf); + const unsigned char* buf = nullptr; + size_t len = 0; // SSL_client_hello_get0_ciphers(ssl.get(), &buf); size_t count = len / 2; MaybeStackBuffer, 16> ciphers(count); int j = 0; for (size_t n = 0; n < len; n += 2) { - const SSL_CIPHER* cipher = SSL_CIPHER_find(ssl.get(), buf); + const SSL_CIPHER* cipher = nullptr; // SSL_CIPHER_find(ssl.get(), buf); buf += 2; Local obj = Object::New(env->isolate()); if (!Set(env->context(),