diff options
Diffstat (limited to 'ssl/record/rec_layer_d1.c')
| -rw-r--r-- | ssl/record/rec_layer_d1.c | 83 |
1 files changed, 38 insertions, 45 deletions
diff --git a/ssl/record/rec_layer_d1.c b/ssl/record/rec_layer_d1.c index 111fbaf7d3a4..a6ddbbffe460 100644 --- a/ssl/record/rec_layer_d1.c +++ b/ssl/record/rec_layer_d1.c @@ -118,11 +118,9 @@ static int dtls_buffer_record(SSL_CONNECTION *s, TLS_RECORD *rec) #ifndef OPENSSL_NO_SCTP /* Store bio_dgram_sctp_rcvinfo struct */ - if (BIO_dgram_is_sctp(s->rbio) && - (ossl_statem_get_state(s) == TLS_ST_SR_FINISHED - || ossl_statem_get_state(s) == TLS_ST_CR_FINISHED)) { + if (BIO_dgram_is_sctp(s->rbio) && (ossl_statem_get_state(s) == TLS_ST_SR_FINISHED || ossl_statem_get_state(s) == TLS_ST_CR_FINISHED)) { BIO_ctrl(s->rbio, BIO_CTRL_DGRAM_SCTP_GET_RCVINFO, - sizeof(rdata->recordinfo), &rdata->recordinfo); + sizeof(rdata->recordinfo), &rdata->recordinfo); } #endif @@ -158,7 +156,7 @@ static void dtls_unbuffer_record(SSL_CONNECTION *s) /* Restore bio_dgram_sctp_rcvinfo struct */ if (BIO_dgram_is_sctp(s->rbio)) { BIO_ctrl(s->rbio, BIO_CTRL_DGRAM_SCTP_SET_RCVINFO, - sizeof(rdata->recordinfo), &rdata->recordinfo); + sizeof(rdata->recordinfo), &rdata->recordinfo); } #endif @@ -197,21 +195,19 @@ static void dtls_unbuffer_record(SSL_CONNECTION *s) * none of our business */ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, - unsigned char *buf, size_t len, - int peek, size_t *readbytes) + unsigned char *buf, size_t len, + int peek, size_t *readbytes) { int i, j, ret; size_t n; TLS_RECORD *rr; - void (*cb) (const SSL *ssl, int type2, int val) = NULL; + void (*cb)(const SSL *ssl, int type2, int val) = NULL; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (sc == NULL) return -1; - if ((type && (type != SSL3_RT_APPLICATION_DATA) && - (type != SSL3_RT_HANDSHAKE)) || - (peek && (type != SSL3_RT_APPLICATION_DATA))) { + if ((type && (type != SSL3_RT_APPLICATION_DATA) && (type != SSL3_RT_HANDSHAKE)) || (peek && (type != SSL3_RT_APPLICATION_DATA))) { SSLfatal(sc, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return -1; } @@ -226,7 +222,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, return -1; } - start: +start: sc->rwstate = SSL_NOTHING; /* @@ -251,17 +247,17 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, rr = &sc->rlayer.tlsrecs[sc->rlayer.num_recs]; ret = HANDLE_RLAYER_READ_RETURN(sc, - sc->rlayer.rrlmethod->read_record(sc->rlayer.rrl, - &rr->rechandle, - &rr->version, &rr->type, - &rr->data, &rr->length, - &rr->epoch, rr->seq_num)); + sc->rlayer.rrlmethod->read_record(sc->rlayer.rrl, + &rr->rechandle, + &rr->version, &rr->type, + &rr->data, &rr->length, + &rr->epoch, rr->seq_num)); if (ret <= 0) { ret = dtls1_read_failed(sc, ret); /* - * Anything other than a timeout is an error. SSLfatal() already - * called if appropriate. - */ + * Anything other than a timeout is an error. SSLfatal() already + * called if appropriate. + */ if (ret <= 0) return ret; else @@ -270,7 +266,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, rr->off = 0; sc->rlayer.num_recs++; } while (sc->rlayer.rrlmethod->processed_read_pending(sc->rlayer.rrl) - && sc->rlayer.num_recs < SSL_MAX_PIPELINES); + && sc->rlayer.num_recs < SSL_MAX_PIPELINES); } rr = &sc->rlayer.tlsrecs[sc->rlayer.curr_rec]; @@ -284,7 +280,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, /* we now have a packet which can be read and processed */ if (sc->s3.change_cipher_spec /* set when we receive ChangeCipherSpec, - * reset by ssl3_get_finished */ + * reset by ssl3_get_finished */ && (rr->type != SSL3_RT_HANDSHAKE)) { /* * We now have application data between CCS and Finished. Most likely @@ -324,9 +320,9 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * doing a handshake for the first time */ if (SSL_in_init(s) && (type == SSL3_RT_APPLICATION_DATA) - && (SSL_IS_FIRST_HANDSHAKE(sc))) { + && (SSL_IS_FIRST_HANDSHAKE(sc))) { SSLfatal(sc, SSL_AD_UNEXPECTED_MESSAGE, - SSL_R_APP_DATA_IN_HANDSHAKE); + SSL_R_APP_DATA_IN_HANDSHAKE); return -1; } @@ -363,8 +359,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * app data. If there was an alert and there is no message to read * anymore, finally set shutdown. */ - if (BIO_dgram_is_sctp(SSL_get_rbio(s)) && - sc->d1->shutdown_received + if (BIO_dgram_is_sctp(SSL_get_rbio(s)) && sc->d1->shutdown_received && BIO_dgram_sctp_msg_waiting(SSL_get_rbio(s)) <= 0) { sc->shutdown |= SSL_RECEIVED_SHUTDOWN; return 0; @@ -385,16 +380,16 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, PACKET alert; if (!PACKET_buf_init(&alert, alert_bytes, rr->length) - || !PACKET_get_1(&alert, &alert_level) - || !PACKET_get_1(&alert, &alert_descr) - || PACKET_remaining(&alert) != 0) { + || !PACKET_get_1(&alert, &alert_level) + || !PACKET_get_1(&alert, &alert_descr) + || PACKET_remaining(&alert) != 0) { SSLfatal(sc, SSL_AD_UNEXPECTED_MESSAGE, SSL_R_INVALID_ALERT); return -1; } if (sc->msg_callback) sc->msg_callback(0, sc->version, SSL3_RT_ALERT, alert_bytes, 2, s, - sc->msg_callback_arg); + sc->msg_callback_arg); if (sc->info_callback != NULL) cb = sc->info_callback; @@ -414,7 +409,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, sc->rlayer.alert_count++; if (sc->rlayer.alert_count == MAX_WARN_ALERT_COUNT) { SSLfatal(sc, SSL_AD_UNEXPECTED_MESSAGE, - SSL_R_TOO_MANY_WARN_ALERTS); + SSL_R_TOO_MANY_WARN_ALERTS); return -1; } @@ -425,8 +420,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * after a close_notify alert. We have to check this first so * that nothing gets discarded. */ - if (BIO_dgram_is_sctp(SSL_get_rbio(s)) && - BIO_dgram_sctp_msg_waiting(SSL_get_rbio(s)) > 0) { + if (BIO_dgram_is_sctp(SSL_get_rbio(s)) && BIO_dgram_sctp_msg_waiting(SSL_get_rbio(s)) > 0) { sc->d1->shutdown_received = 1; sc->rwstate = SSL_READING; BIO_clear_retry_flags(SSL_get_rbio(s)); @@ -452,8 +446,8 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, sc->rwstate = SSL_NOTHING; sc->s3.fatal_alert = alert_descr; SSLfatal_data(sc, SSL_AD_NO_ALERT, - SSL_AD_REASON_OFFSET + alert_descr, - "SSL alert number %d", alert_descr); + SSL_AD_REASON_OFFSET + alert_descr, + "SSL alert number %d", alert_descr); sc->shutdown |= SSL_RECEIVED_SHUTDOWN; if (!ssl_release_record(sc, rr, 0)) return -1; @@ -468,7 +462,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, } if (sc->shutdown & SSL_SENT_SHUTDOWN) { /* but we have not received a - * shutdown */ + * shutdown */ sc->rwstate = SSL_NOTHING; if (!ssl_release_record(sc, rr, 0)) return -1; @@ -496,7 +490,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * at least enough record bytes for a message header */ if (rr->epoch != sc->rlayer.d->r_epoch - || rr->length < DTLS1_HM_HEADER_LENGTH) { + || rr->length < DTLS1_HM_HEADER_LENGTH) { if (!ssl_release_record(sc, rr, 0)) return -1; goto start; @@ -599,9 +593,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * application data at this point (session renegotiation not yet * started), we will indulge it. */ - if (sc->s3.in_read_app_data && - (sc->s3.total_renegotiations != 0) && - ossl_statem_app_data_allowed(sc)) { + if (sc->s3.in_read_app_data && (sc->s3.total_renegotiations != 0) && ossl_statem_app_data_allowed(sc)) { sc->s3.in_read_app_data = 2; return -1; } else { @@ -617,7 +609,7 @@ int dtls1_read_bytes(SSL *s, uint8_t type, uint8_t *recvd_type, * not all data has been sent or non-blocking IO. */ int dtls1_write_bytes(SSL_CONNECTION *s, uint8_t type, const void *buf, - size_t len, size_t *written) + size_t len, size_t *written) { int i; @@ -631,7 +623,7 @@ int dtls1_write_bytes(SSL_CONNECTION *s, uint8_t type, const void *buf, } int do_dtls1_write(SSL_CONNECTION *sc, uint8_t type, const unsigned char *buf, - size_t len, size_t *written) + size_t len, size_t *written) { int i; OSSL_RECORD_TEMPLATE tmpl; @@ -661,7 +653,7 @@ int do_dtls1_write(SSL_CONNECTION *sc, uint8_t type, const unsigned char *buf, * header: otherwise some clients will ignore it. */ if (s->method->version == DTLS_ANY_VERSION - && sc->max_proto_version != DTLS1_BAD_VER) + && sc->max_proto_version != DTLS1_BAD_VER) tmpl.version = DTLS1_VERSION; else tmpl.version = sc->version; @@ -669,7 +661,7 @@ int do_dtls1_write(SSL_CONNECTION *sc, uint8_t type, const unsigned char *buf, tmpl.buflen = len; ret = HANDLE_RLAYER_WRITE_RETURN(sc, - sc->rlayer.wrlmethod->write_records(sc->rlayer.wrl, &tmpl, 1)); + sc->rlayer.wrlmethod->write_records(sc->rlayer.wrl, &tmpl, 1)); if (ret > 0) *written = (int)len; @@ -692,7 +684,8 @@ void dtls1_increment_epoch(SSL_CONNECTION *s, int rw) } } -uint16_t dtls1_get_epoch(SSL_CONNECTION *s, int rw) { +uint16_t dtls1_get_epoch(SSL_CONNECTION *s, int rw) +{ uint16_t epoch; if (rw & SSL3_CC_READ) |
