Make the other dup_ref functions take nullptr

Matches https://boringssl-review.googlesource.com/c/boringssl/+/102507

Change-Id: I982e6b5476b1ad284d3e48d02b265df8df980f7b
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/103857
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: Lily Chen <chlily@google.com>
diff --git a/crypto/evp/evp.cc b/crypto/evp/evp.cc
index f99ee15..6348a1e 100644
--- a/crypto/evp/evp.cc
+++ b/crypto/evp/evp.cc
@@ -64,7 +64,6 @@
     return nullptr;
   }
   auto pkey_ref = const_cast<EVP_PKEY *>(pkey);
-  // We know that this call always returns one.
   EVP_PKEY_up_ref(pkey_ref);
   return pkey_ref;
 }
diff --git a/crypto/pool/pool.cc b/crypto/pool/pool.cc
index 4bc3a19..a308ab8 100644
--- a/crypto/pool/pool.cc
+++ b/crypto/pool/pool.cc
@@ -273,6 +273,9 @@
 }
 
 CRYPTO_BUFFER *CRYPTO_BUFFER_dup_ref(const CRYPTO_BUFFER *buf) {
+  if (buf == nullptr) {
+    return nullptr;
+  }
   auto *buf_ = const_cast<CRYPTO_BUFFER *>(buf);
   FromOpaque(buf_)->UpRefInternal();
   return buf_;
diff --git a/crypto/x509/x_x509.cc b/crypto/x509/x_x509.cc
index 413c40f..9a5493d 100644
--- a/crypto/x509/x_x509.cc
+++ b/crypto/x509/x_x509.cc
@@ -328,8 +328,10 @@
 }
 
 X509 *X509_dup_ref(const X509 *x) {
+  if (x == nullptr) {
+    return nullptr;
+  }
   auto *x_ref = const_cast<X509 *>(x);
-  // We know that this call always returns one.
   X509_up_ref(x_ref);
   return x_ref;
 }
diff --git a/ssl/ssl_credential.cc b/ssl/ssl_credential.cc
index 34f7ac2..9eff530 100644
--- a/ssl/ssl_credential.cc
+++ b/ssl/ssl_credential.cc
@@ -484,9 +484,10 @@
 }
 
 SSL_CREDENTIAL *SSL_CREDENTIAL_dup_ref(const SSL_CREDENTIAL *cred) {
-  // Safety: we do not mutate the internal state of `cred` other than the
-  // ref-count atomic variable.
-  auto *cred_impl = FromOpaque(const_cast<SSL_CREDENTIAL *>(cred));
+  if (cred == nullptr) {
+    return nullptr;
+  }
+  auto *cred_impl = FromOpaque(cred);
   cred_impl->UpRefInternal();
   return const_cast<SSL_CREDENTIAL *>(cred);
 }