401de51885384e2d612ca7cc32ffc0936bc5969b: Bug 1421572 - Correct early exporter secret derivation, r=ekr
Martin Thomson <martin.thomson@gmail.com> - Wed, 29 Nov 2017 06:23:19 -0800 - rev 14175
Push 2923 by ekr@mozilla.com at Wed, 29 Nov 2017 14:47:26 +0000
Bug 1421572 - Correct early exporter secret derivation, r=ekr Summary: This was pretty obviously wrong before, which was made obvious when I moved a few things around. Reviewers: ekr, Lekensteyn Reviewed By: Lekensteyn Subscribers: mt, Lekensteyn Bug #: 1421572 Differential Revision: https://phabricator.services.mozilla.com/D297
7c9e5bd3d8fe33be7bc0ebfe74ee3934e2fc64f4: Bug 1417331 - Early exporters for TLS 1.3, r=lekensteyn
Martin Thomson <martin.thomson@gmail.com> - Wed, 29 Nov 2017 21:20:44 +1100 - rev 14174
Push 2922 by martin.thomson@gmail.com at Wed, 29 Nov 2017 10:23:39 +0000
Bug 1417331 - Early exporters for TLS 1.3, r=lekensteyn Reviewers: Lekensteyn Reviewed By: Lekensteyn Bug #: 1317331 Differential Revision: https://phabricator.services.mozilla.com/D287
79f689370b96037c38d2268673d5c1f8e1037467: Bug 1212199 - Fix signed/unsigned warning for V2Hello handler, r=ttaubert
Martin Thomson <martin.thomson@gmail.com> - Fri, 24 Nov 2017 10:47:00 +1100 - rev 14173
Push 2921 by martin.thomson@gmail.com at Wed, 29 Nov 2017 10:03:36 +0000
Bug 1212199 - Fix signed/unsigned warning for V2Hello handler, r=ttaubert
96e6dbbd080f07b325a31e67fea8ed858c6b21cf: Bug 1419278 - make lg_CopyAttribute handle optionsDate and smimeOptions properly, r=ttaubert,jseward
Franziskus Kiefer <franziskuskiefer@gmail.com> - Wed, 29 Nov 2017 09:24:43 +0100 - rev 14172
Push 2920 by franziskuskiefer@gmail.com at Wed, 29 Nov 2017 08:28:29 +0000
Bug 1419278 - make lg_CopyAttribute handle optionsDate and smimeOptions properly, r=ttaubert,jseward Reviewers: ttaubert Reviewed By: ttaubert Subscribers: ttaubert, franziskus, jseward Bug #: 1419278 Differential Revision: https://phabricator.services.mozilla.com/D267
2e84661d39faf3b224384180d9ca81314b9f127c: NSS_TLS13_DRAFT19_BRANCH merge follow-up, remove ssl3encode, r=mt,ttaubert
Franziskus Kiefer <franziskuskiefer@gmail.com> - Wed, 29 Nov 2017 09:24:33 +0100 - rev 14171
Push 2920 by franziskuskiefer@gmail.com at Wed, 29 Nov 2017 08:28:29 +0000
NSS_TLS13_DRAFT19_BRANCH merge follow-up, remove ssl3encode, r=mt,ttaubert Reviewers: mt, ttaubert Reviewed By: mt, ttaubert Differential Revision: https://phabricator.services.mozilla.com/D283
c71d2fa1a53c6039f40878bf66be90a6bbc927c9: Bug 1265127 - fixed race condition in ssl_PushIOLayer, r=franziskus
Jonas Allmann <jallmann@mozilla.com> - Wed, 29 Nov 2017 09:20:58 +0100 - rev 14170
Push 2919 by franziskuskiefer@gmail.com at Wed, 29 Nov 2017 08:23:30 +0000
Bug 1265127 - fixed race condition in ssl_PushIOLayer, r=franziskus Reviewers: franziskus Reviewed By: franziskus Bug #: 1265127 Differential Revision: https://phabricator.services.mozilla.com/D293
36dc2b60c1f61f2c3bed38eced382333e966f90b: Bug 1417331 - fix key log unit tests, r=mt
Peter Wu <peter@lekensteyn.nl> - Wed, 15 Nov 2017 07:48:54 +0000 - rev 14169
Push 2918 by martin.thomson@gmail.com at Mon, 27 Nov 2017 05:40:20 +0000
Bug 1417331 - fix key log unit tests, r=mt The key log unit tests were never activated because the SSLKEYLOGFILE environment variable was not properly set (putenv claims the pointer and requires it to be valid after invocation) after changing to PR_SetEnv. The test failures did not show up because gtest somehow swallows errors for the child process. Set "throw_on_failure" in the child to fix this. And finally fix the invalid tests (client random size 1? nope) and ensure 0-RTT is triggered such that CLIENT_EARLY_TRAFFIC_SECRET can be tested.
2b6dc5a87babdfbc15fefe0ef561bf6cc9b83562: Bug 1429776 - Various coverity issues on TLS 1.3 branch, r=ekr
Martin Thomson <martin.thomson@gmail.com> - Mon, 27 Nov 2017 10:08:54 +1100 - rev 14168
Push 2917 by martin.thomson@gmail.com at Mon, 27 Nov 2017 00:04:16 +0000
Bug 1429776 - Various coverity issues on TLS 1.3 branch, r=ekr
b0658ed367633e505d38c0c0f63b801ddbbb21a4: Bug 1377940, Change NSS default storage file format (currently DBM), when no prefix is given, to SQL, r=rrelyea, r=fkiefer
Kai Engert <kaie@kuix.de> - Fri, 24 Nov 2017 19:43:14 +0100 - rev 14167
Push 2916 by kaie@kuix.de at Fri, 24 Nov 2017 18:43:01 +0000
Bug 1377940, Change NSS default storage file format (currently DBM), when no prefix is given, to SQL, r=rrelyea, r=fkiefer
807662e6ba57db5be05036511ac8634466ed473f: Bug 1383369 - update HACL* dockerfile and ChaCha20, r=ttaubert
Franziskus Kiefer <franziskuskiefer@gmail.com> - Fri, 24 Nov 2017 15:46:03 +0100 - rev 14166
Push 2915 by franziskuskiefer@gmail.com at Fri, 24 Nov 2017 16:32:27 +0000
Bug 1383369 - update HACL* dockerfile and ChaCha20, r=ttaubert Reviewers: ttaubert Reviewed By: ttaubert Differential Revision: https://phabricator.services.mozilla.com/D277
d514c4480dbc95ff7991efff0bb2a5ddfea59e1a: record that NSS 3.35 will require NSPR 4.18, no bug, r=me
Kai Engert <kaie@kuix.de> - Fri, 24 Nov 2017 14:02:21 +0100 - rev 14165
Push 2914 by kaie@kuix.de at Fri, 24 Nov 2017 13:01:57 +0000
record that NSS 3.35 will require NSPR 4.18, no bug, r=me DONTBUILD
206300edf2a9b5025828f284d39f573897a38db5: Dummy change to trigger a build to test latest NSPR commits
Kai Engert <kaie@kuix.de> - Fri, 24 Nov 2017 13:44:39 +0100 - rev 14164
Push 2913 by kaie@kuix.de at Fri, 24 Nov 2017 12:44:14 +0000
Dummy change to trigger a build to test latest NSPR commits
2b531ba79bdc927adc54bf6e5a6732bdc35a3b95: Dummy change to trigger a build to test latest NSPR commits NSS_3_34_BRANCH
Kai Engert <kaie@kuix.de> - Fri, 24 Nov 2017 13:41:46 +0100 - rev 14163
Push 2912 by kaie@kuix.de at Fri, 24 Nov 2017 12:41:22 +0000
Dummy change to trigger a build to test latest NSPR commits
ceb8b9290b35ced16c5e7799888d2b5d735232db: Merge TLS 1.3 branch into trunk
Martin Thomson <martin.thomson@gmail.com> - Fri, 24 Nov 2017 16:30:09 +1100 - rev 14162
Push 2911 by martin.thomson@gmail.com at Fri, 24 Nov 2017 05:31:28 +0000
Merge TLS 1.3 branch into trunk
88c3f3fa581bb58f0cbfbe5aa170a9a4105d223c: Merge NSS trunk to NSS_TLS13_DRAFT19_BRANCH NSS_TLS13_DRAFT19_BRANCH
Martin Thomson <martin.thomson@gmail.com> - Fri, 24 Nov 2017 14:26:57 +1100 - rev 14161
Push 2911 by martin.thomson@gmail.com at Fri, 24 Nov 2017 05:31:28 +0000
Merge NSS trunk to NSS_TLS13_DRAFT19_BRANCH
90fa0804c6238a22e9f6804c260fe51364f1c525: Bug 1385203 - Ensure wrBuf is empty when not in use, r=ekr NSS_TLS13_DRAFT19_BRANCH
Martin Thomson <martin.thomson@gmail.com> - Fri, 24 Nov 2017 10:48:17 +1100 - rev 14160
Push 2911 by martin.thomson@gmail.com at Fri, 24 Nov 2017 05:31:28 +0000
Bug 1385203 - Ensure wrBuf is empty when not in use, r=ekr
d7d3102fd75cb699400556bb7f00bd64b5656ade: Merge NSS trunk to NSS_TLS13_DRAFT19_BRANCH NSS_TLS13_DRAFT19_BRANCH
Martin Thomson <martin.thomson@gmail.com> - Thu, 23 Nov 2017 12:05:35 +1100 - rev 14159
Push 2911 by martin.thomson@gmail.com at Fri, 24 Nov 2017 05:31:28 +0000
Merge NSS trunk to NSS_TLS13_DRAFT19_BRANCH
5bd4fdfaaac3d10b7f839835ade5a644d4782aa1: Bug 1418862 - Make HelloRetryRequest look like ServerHello, r=ekr NSS_TLS13_DRAFT19_BRANCH
Martin Thomson <martin.thomson@gmail.com> - Wed, 22 Nov 2017 20:33:29 +1100 - rev 14158
Push 2911 by martin.thomson@gmail.com at Fri, 24 Nov 2017 05:31:28 +0000
Bug 1418862 - Make HelloRetryRequest look like ServerHello, r=ekr Update TLS 1.3 implementation for draft-22. This makes the changes from Bug 1411475 the default mode of operation. A new option, SSL_ENABLE_TLS13_COMPAT_MODE, is added to control whether a client attempts to force the server into compatibility mode. When enabled, clients will send a fake session_id in the ClientHello and send a ChangeCipherSpec message before sending any encrypted records. This patch also includes changes to make a HelloRetryRequest look like a ServerHello. This includes the version number change to draft-22.
f83e6fee069d5a7962ee18e1223bdf1c574671b4: Bug 1414811 - ssl3_config_match_init() shouldn't return a signed int r=ttaubert
Jean-Luc Bonnafoux <jeanluc.bonnafoux@wanadoo.fr> - Thu, 23 Nov 2017 16:56:42 +0100 - rev 14157
Push 2910 by ttaubert@mozilla.com at Thu, 23 Nov 2017 16:23:35 +0000
Bug 1414811 - ssl3_config_match_init() shouldn't return a signed int r=ttaubert Summary: ssl3_config_match_init() shouldn't return a signed int Reviewers: ttaubert Bug #: 1414811 Differential Revision: https://phabricator.services.mozilla.com/D197
c05ba18909a5e5fd5f49fad18043071ce668f45d: Added tag NSS_3_34_1_RTM for changeset e61c0f657100 NSS_3_34_BRANCH
Kai Engert <kaie@kuix.de> - Thu, 23 Nov 2017 16:08:55 +0100 - rev 14156
Push 2909 by kaie@kuix.de at Thu, 23 Nov 2017 15:11:17 +0000
Added tag NSS_3_34_1_RTM for changeset e61c0f657100
(0) -10000 -3000 -1000 -300 -100 -50 -20 +20 +50 +100 +300 +1000 tip