Remove ext_dat.h

This was a manually-built sorted table that relied on a runtime check to
get the order right. Instead, we can just write a plain switch/case and
let the compiler decide how it would like to implement this dispatch.

Change-Id: If1623d1b1d1d6a38f66df36c50bdd73eb901b0e9
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/79108
Commit-Queue: Adam Langley <agl@google.com>
Auto-Submit: David Benjamin <davidben@google.com>
Reviewed-by: Adam Langley <agl@google.com>
diff --git a/build.json b/build.json
index 6ca837e..f870d2f 100644
--- a/build.json
+++ b/build.json
@@ -556,7 +556,6 @@
             "crypto/rsa/internal.h",
             "crypto/spake2plus/internal.h",
             "crypto/trust_token/internal.h",
-            "crypto/x509/ext_dat.h",
             "crypto/x509/internal.h",
             "third_party/fiat/curve25519_32.h",
             "third_party/fiat/curve25519_64.h",
@@ -878,7 +877,6 @@
             "crypto/test/gtest_main.cc",
             "crypto/thread_test.cc",
             "crypto/trust_token/trust_token_test.cc",
-            "crypto/x509/tab_test.cc",
             "crypto/x509/x509_test.cc",
             "crypto/x509/x509_time_test.cc"
         ],
diff --git a/crypto/x509/ext_dat.h b/crypto/x509/ext_dat.h
deleted file mode 100644
index 0411fad..0000000
--- a/crypto/x509/ext_dat.h
+++ /dev/null
@@ -1,77 +0,0 @@
-// Copyright 1999-2016 The OpenSSL Project Authors. All Rights Reserved.
-//
-// Licensed under the Apache License, Version 2.0 (the "License");
-// you may not use this file except in compliance with the License.
-// You may obtain a copy of the License at
-//
-//     https://www.apache.org/licenses/LICENSE-2.0
-//
-// Unless required by applicable law or agreed to in writing, software
-// distributed under the License is distributed on an "AS IS" BASIS,
-// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
-// See the License for the specific language governing permissions and
-// limitations under the License.
-
-// This file contains a table of "standard" extensions
-
-#if defined(__cplusplus)
-extern "C" {
-#endif
-
-extern const X509V3_EXT_METHOD v3_bcons, v3_nscert, v3_key_usage, v3_ext_ku;
-extern const X509V3_EXT_METHOD v3_info, v3_sinfo;
-extern const X509V3_EXT_METHOD v3_ns_ia5_list[], v3_alt[], v3_skey_id,
-    v3_akey_id;
-extern const X509V3_EXT_METHOD v3_crl_num, v3_crl_reason, v3_crl_invdate;
-extern const X509V3_EXT_METHOD v3_delta_crl, v3_cpols, v3_crld, v3_freshest_crl;
-extern const X509V3_EXT_METHOD v3_ocsp_nocheck;
-extern const X509V3_EXT_METHOD v3_crl_hold;
-extern const X509V3_EXT_METHOD v3_policy_mappings, v3_policy_constraints;
-extern const X509V3_EXT_METHOD v3_name_constraints, v3_inhibit_anyp, v3_idp;
-extern const X509V3_EXT_METHOD v3_addr, v3_asid;
-
-// This table will be searched using OBJ_bsearch so it *must* kept in order
-// of the ext_nid values.
-
-static const X509V3_EXT_METHOD *const standard_exts[] = {
-    &v3_nscert,
-    &v3_ns_ia5_list[0],
-    &v3_ns_ia5_list[1],
-    &v3_ns_ia5_list[2],
-    &v3_ns_ia5_list[3],
-    &v3_ns_ia5_list[4],
-    &v3_ns_ia5_list[5],
-    &v3_ns_ia5_list[6],
-    &v3_skey_id,
-    &v3_key_usage,
-    &v3_alt[0],
-    &v3_alt[1],
-    &v3_bcons,
-    &v3_crl_num,
-    &v3_cpols,
-    &v3_akey_id,
-    &v3_crld,
-    &v3_ext_ku,
-    &v3_delta_crl,
-    &v3_crl_reason,
-    &v3_crl_invdate,
-    &v3_info,
-    &v3_ocsp_nocheck,
-    &v3_sinfo,
-    &v3_policy_constraints,
-    &v3_name_constraints,
-    &v3_policy_mappings,
-    &v3_inhibit_anyp,
-    &v3_idp,
-    &v3_alt[2],
-    &v3_freshest_crl,
-};
-
-// Number of standard extensions
-
-#define STANDARD_EXTENSION_COUNT \
-  (sizeof(standard_exts) / sizeof(X509V3_EXT_METHOD *))
-
-#if defined(__cplusplus)
-}  // extern C
-#endif
diff --git a/crypto/x509/internal.h b/crypto/x509/internal.h
index 1fab446..345b44c 100644
--- a/crypto/x509/internal.h
+++ b/crypto/x509/internal.h
@@ -560,6 +560,25 @@
 int x509_marshal_algorithm(CBB *out, const X509_ALGOR *in);
 
 
+// Standard extensions.
+
+extern const X509V3_EXT_METHOD v3_bcons, v3_nscert, v3_key_usage, v3_ext_ku;
+extern const X509V3_EXT_METHOD v3_info, v3_sinfo;
+extern const X509V3_EXT_METHOD v3_skey_id, v3_akey_id;
+extern const X509V3_EXT_METHOD v3_subject_alt_name, v3_issuer_alt_name,
+    v3_certificate_issuer;
+extern const X509V3_EXT_METHOD v3_netscape_base_url, v3_netscape_revocation_url,
+    v3_netscape_ca_revocation_url, v3_netscape_renewal_url,
+    v3_netscape_ca_policy_url, v3_netscape_ssl_server_name, v3_netscape_comment;
+extern const X509V3_EXT_METHOD v3_crl_num, v3_crl_reason, v3_crl_invdate;
+extern const X509V3_EXT_METHOD v3_delta_crl, v3_cpols, v3_crld, v3_freshest_crl;
+extern const X509V3_EXT_METHOD v3_ocsp_nocheck;
+extern const X509V3_EXT_METHOD v3_crl_hold;
+extern const X509V3_EXT_METHOD v3_policy_mappings, v3_policy_constraints;
+extern const X509V3_EXT_METHOD v3_name_constraints, v3_inhibit_anyp, v3_idp;
+extern const X509V3_EXT_METHOD v3_addr, v3_asid;
+
+
 #if defined(__cplusplus)
 }  // extern C
 #endif
diff --git a/crypto/x509/tab_test.cc b/crypto/x509/tab_test.cc
deleted file mode 100644
index d8433bd..0000000
--- a/crypto/x509/tab_test.cc
+++ /dev/null
@@ -1,33 +0,0 @@
-// Copyright 1999-2016 The OpenSSL Project Authors. All Rights Reserved.
-//
-// Licensed under the Apache License, Version 2.0 (the "License");
-// you may not use this file except in compliance with the License.
-// You may obtain a copy of the License at
-//
-//     https://www.apache.org/licenses/LICENSE-2.0
-//
-// Unless required by applicable law or agreed to in writing, software
-// distributed under the License is distributed on an "AS IS" BASIS,
-// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
-// See the License for the specific language governing permissions and
-// limitations under the License.
-
-#if !defined(BORINGSSL_SHARED_LIBRARY)
-
-#include <gtest/gtest.h>
-
-#include <openssl/x509.h>
-
-#include "../internal.h"
-#include "ext_dat.h"
-
-// Check ext_data.h is correct.
-TEST(X509V3Test, TabTest) {
-  EXPECT_EQ(OPENSSL_ARRAY_SIZE(standard_exts), STANDARD_EXTENSION_COUNT);
-  for (size_t i = 1; i < OPENSSL_ARRAY_SIZE(standard_exts); i++) {
-    SCOPED_TRACE(i);
-    EXPECT_LT(standard_exts[i-1]->ext_nid, standard_exts[i]->ext_nid);
-  }
-}
-
-#endif  // !BORINGSSL_SHARED_LIBRARY
diff --git a/crypto/x509/v3_akey.cc b/crypto/x509/v3_akey.cc
index e92775f..6c3c6a9 100644
--- a/crypto/x509/v3_akey.cc
+++ b/crypto/x509/v3_akey.cc
@@ -23,7 +23,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_alt.cc b/crypto/x509/v3_alt.cc
index 7cb7ae6..d89498c 100644
--- a/crypto/x509/v3_alt.cc
+++ b/crypto/x509/v3_alt.cc
@@ -21,7 +21,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
@@ -43,15 +42,55 @@
   return i2v_GENERAL_NAMES(method, reinterpret_cast<GENERAL_NAMES *>(ext), ret);
 }
 
-const X509V3_EXT_METHOD v3_alt[] = {
-    {NID_subject_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES), 0, 0, 0, 0, 0, 0,
-     i2v_GENERAL_NAMES_cb, v2i_subject_alt, NULL, NULL, NULL},
+const X509V3_EXT_METHOD v3_subject_alt_name = {
+    NID_subject_alt_name,
+    0,
+    ASN1_ITEM_ref(GENERAL_NAMES),
+    0,
+    0,
+    0,
+    0,
+    0,
+    0,
+    i2v_GENERAL_NAMES_cb,
+    v2i_subject_alt,
+    nullptr,
+    nullptr,
+    nullptr,
+};
 
-    {NID_issuer_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES), 0, 0, 0, 0, 0, 0,
-     i2v_GENERAL_NAMES_cb, v2i_issuer_alt, NULL, NULL, NULL},
+const X509V3_EXT_METHOD v3_issuer_alt_name = {
+    NID_issuer_alt_name,
+    0,
+    ASN1_ITEM_ref(GENERAL_NAMES),
+    0,
+    0,
+    0,
+    0,
+    0,
+    0,
+    i2v_GENERAL_NAMES_cb,
+    v2i_issuer_alt,
+    nullptr,
+    nullptr,
+    nullptr,
+};
 
-    {NID_certificate_issuer, 0, ASN1_ITEM_ref(GENERAL_NAMES), 0, 0, 0, 0, 0, 0,
-     i2v_GENERAL_NAMES_cb, NULL, NULL, NULL, NULL},
+const X509V3_EXT_METHOD v3_certificate_issuer = {
+    NID_certificate_issuer,
+    0,
+    ASN1_ITEM_ref(GENERAL_NAMES),
+    0,
+    0,
+    0,
+    0,
+    0,
+    0,
+    i2v_GENERAL_NAMES_cb,
+    NULL,
+    NULL,
+    NULL,
+    NULL,
 };
 
 STACK_OF(CONF_VALUE) *i2v_GENERAL_NAMES(const X509V3_EXT_METHOD *method,
diff --git a/crypto/x509/v3_bcons.cc b/crypto/x509/v3_bcons.cc
index 1156f4a..0399557 100644
--- a/crypto/x509/v3_bcons.cc
+++ b/crypto/x509/v3_bcons.cc
@@ -22,7 +22,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_bitst.cc b/crypto/x509/v3_bitst.cc
index 6d1a450..eb7d0e1 100644
--- a/crypto/x509/v3_bitst.cc
+++ b/crypto/x509/v3_bitst.cc
@@ -20,7 +20,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_cpols.cc b/crypto/x509/v3_cpols.cc
index 46b7118..7664de2 100644
--- a/crypto/x509/v3_cpols.cc
+++ b/crypto/x509/v3_cpols.cc
@@ -24,7 +24,6 @@
 #include <openssl/stack.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 // Certificate policies extension support: this one is a bit complex...
diff --git a/crypto/x509/v3_crld.cc b/crypto/x509/v3_crld.cc
index df9652a..5ba89d1 100644
--- a/crypto/x509/v3_crld.cc
+++ b/crypto/x509/v3_crld.cc
@@ -23,7 +23,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_enum.cc b/crypto/x509/v3_enum.cc
index e1d1f34..95ee398 100644
--- a/crypto/x509/v3_enum.cc
+++ b/crypto/x509/v3_enum.cc
@@ -19,7 +19,6 @@
 #include <openssl/x509.h>
 #include <openssl/x509v3.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_extku.cc b/crypto/x509/v3_extku.cc
index ea1ed20..15bcc51 100644
--- a/crypto/x509/v3_extku.cc
+++ b/crypto/x509/v3_extku.cc
@@ -20,7 +20,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_ia5.cc b/crypto/x509/v3_ia5.cc
index 0c37808..36f9e65 100644
--- a/crypto/x509/v3_ia5.cc
+++ b/crypto/x509/v3_ia5.cc
@@ -23,7 +23,7 @@
 #include <openssl/x509.h>
 
 #include "../internal.h"
-#include "ext_dat.h"
+#include "internal.h"
 
 
 static char *i2s_ASN1_IA5STRING(const X509V3_EXT_METHOD *method, void *ext) {
@@ -65,15 +65,17 @@
         s2i_ASN1_IA5STRING, 0, 0, 0, 0, NULL                               \
   }
 
-#define EXT_END \
-  { -1, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 }
-
-const X509V3_EXT_METHOD v3_ns_ia5_list[] = {
-    EXT_IA5STRING(NID_netscape_base_url),
-    EXT_IA5STRING(NID_netscape_revocation_url),
-    EXT_IA5STRING(NID_netscape_ca_revocation_url),
-    EXT_IA5STRING(NID_netscape_renewal_url),
-    EXT_IA5STRING(NID_netscape_ca_policy_url),
-    EXT_IA5STRING(NID_netscape_ssl_server_name),
-    EXT_IA5STRING(NID_netscape_comment),
-    EXT_END};
+const X509V3_EXT_METHOD v3_netscape_base_url =
+    EXT_IA5STRING(NID_netscape_base_url);
+const X509V3_EXT_METHOD v3_netscape_revocation_url =
+    EXT_IA5STRING(NID_netscape_revocation_url);
+const X509V3_EXT_METHOD v3_netscape_ca_revocation_url =
+    EXT_IA5STRING(NID_netscape_ca_revocation_url);
+const X509V3_EXT_METHOD v3_netscape_renewal_url =
+    EXT_IA5STRING(NID_netscape_renewal_url);
+const X509V3_EXT_METHOD v3_netscape_ca_policy_url =
+    EXT_IA5STRING(NID_netscape_ca_policy_url);
+const X509V3_EXT_METHOD v3_netscape_ssl_server_name =
+    EXT_IA5STRING(NID_netscape_ssl_server_name);
+const X509V3_EXT_METHOD v3_netscape_comment =
+    EXT_IA5STRING(NID_netscape_comment);
diff --git a/crypto/x509/v3_info.cc b/crypto/x509/v3_info.cc
index 4f6c69d..00b4744 100644
--- a/crypto/x509/v3_info.cc
+++ b/crypto/x509/v3_info.cc
@@ -23,7 +23,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_int.cc b/crypto/x509/v3_int.cc
index f97337d..8f4942f 100644
--- a/crypto/x509/v3_int.cc
+++ b/crypto/x509/v3_int.cc
@@ -17,7 +17,7 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
+#include "internal.h"
 
 
 static char *i2s_ASN1_INTEGER_cb(const X509V3_EXT_METHOD *method, void *ext) {
diff --git a/crypto/x509/v3_lib.cc b/crypto/x509/v3_lib.cc
index d5a308c..dadc978 100644
--- a/crypto/x509/v3_lib.cc
+++ b/crypto/x509/v3_lib.cc
@@ -25,8 +25,6 @@
 
 #include "internal.h"
 
-#include "ext_dat.h"
-
 DEFINE_STACK_OF(X509V3_EXT_METHOD)
 
 static STACK_OF(X509V3_EXT_METHOD) *ext_list = NULL;
@@ -51,33 +49,81 @@
   return 1;
 }
 
-static int ext_cmp(const void *void_a, const void *void_b) {
-  const X509V3_EXT_METHOD **a = (const X509V3_EXT_METHOD **)void_a;
-  const X509V3_EXT_METHOD **b = (const X509V3_EXT_METHOD **)void_b;
-  return ext_stack_cmp(a, b);
-}
-
 const X509V3_EXT_METHOD *X509V3_EXT_get_nid(int nid) {
-  X509V3_EXT_METHOD tmp;
-  const X509V3_EXT_METHOD *t = &tmp, *const * ret;
-  size_t idx;
-
   if (nid < 0) {
-    return NULL;
-  }
-  tmp.ext_nid = nid;
-  ret = reinterpret_cast<X509V3_EXT_METHOD **>(
-      bsearch(&t, standard_exts, STANDARD_EXTENSION_COUNT,
-              sizeof(X509V3_EXT_METHOD *), ext_cmp));
-  if (ret) {
-    return *ret;
-  }
-  if (!ext_list) {
-    return NULL;
+    return nullptr;
   }
 
-  if (!sk_X509V3_EXT_METHOD_find(ext_list, &idx, &tmp)) {
-    return NULL;
+  switch (nid) {
+    case NID_netscape_cert_type:
+      return &v3_nscert;
+    case NID_netscape_base_url:
+      return &v3_netscape_base_url;
+    case NID_netscape_revocation_url:
+      return &v3_netscape_revocation_url;
+    case NID_netscape_ca_revocation_url:
+      return &v3_netscape_ca_revocation_url;
+    case NID_netscape_renewal_url:
+      return &v3_netscape_renewal_url;
+    case NID_netscape_ca_policy_url:
+      return &v3_netscape_ca_policy_url;
+    case NID_netscape_ssl_server_name:
+      return &v3_netscape_ssl_server_name;
+    case NID_netscape_comment:
+      return &v3_netscape_comment;
+    case NID_subject_key_identifier:
+      return &v3_skey_id;
+    case NID_key_usage:
+      return &v3_key_usage;
+    case NID_subject_alt_name:
+      return &v3_subject_alt_name;
+    case NID_issuer_alt_name:
+      return &v3_issuer_alt_name;
+    case NID_certificate_issuer:
+      return &v3_certificate_issuer;
+    case NID_basic_constraints:
+      return &v3_bcons;
+    case NID_crl_number:
+      return &v3_crl_num;
+    case NID_certificate_policies:
+      return &v3_cpols;
+    case NID_authority_key_identifier:
+      return &v3_akey_id;
+    case NID_crl_distribution_points:
+      return &v3_crld;
+    case NID_ext_key_usage:
+      return &v3_ext_ku;
+    case NID_delta_crl:
+      return &v3_delta_crl;
+    case NID_crl_reason:
+      return &v3_crl_reason;
+    case NID_invalidity_date:
+      return &v3_crl_invdate;
+    case NID_info_access:
+      return &v3_info;
+    case NID_id_pkix_OCSP_noCheck:
+      return &v3_ocsp_nocheck;
+    case NID_sinfo_access:
+      return &v3_sinfo;
+    case NID_policy_constraints:
+      return &v3_policy_constraints;
+    case NID_name_constraints:
+      return &v3_name_constraints;
+    case NID_policy_mappings:
+      return &v3_policy_mappings;
+    case NID_inhibit_any_policy:
+      return &v3_inhibit_anyp;
+    case NID_issuing_distribution_point:
+      return &v3_idp;
+    case NID_freshest_crl:
+      return &v3_freshest_crl;
+  }
+
+  X509V3_EXT_METHOD tmp;
+  tmp.ext_nid = nid;
+  size_t idx;
+  if (ext_list == nullptr || !sk_X509V3_EXT_METHOD_find(ext_list, &idx, &tmp)) {
+    return nullptr;
   }
   return sk_X509V3_EXT_METHOD_value(ext_list, idx);
 }
@@ -125,9 +171,6 @@
   OPENSSL_END_ALLOW_DEPRECATED
 }
 
-// Legacy function: we don't need to add standard extensions any more because
-// they are now kept in ext_dat.h.
-
 int X509V3_add_standard_extensions(void) { return 1; }
 
 // Return an extension internal structure
diff --git a/crypto/x509/v3_ncons.cc b/crypto/x509/v3_ncons.cc
index a79f47d..7661ea8 100644
--- a/crypto/x509/v3_ncons.cc
+++ b/crypto/x509/v3_ncons.cc
@@ -23,7 +23,6 @@
 #include <openssl/x509.h>
 
 #include "../internal.h"
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_ocsp.cc b/crypto/x509/v3_ocsp.cc
index ab929d1..d0a5d67 100644
--- a/crypto/x509/v3_ocsp.cc
+++ b/crypto/x509/v3_ocsp.cc
@@ -18,7 +18,7 @@
 #include <openssl/bio.h>
 #include <openssl/nid.h>
 
-#include "ext_dat.h"
+#include "internal.h"
 
 // OCSP extensions and a couple of CRL entry extensions
 
diff --git a/crypto/x509/v3_pcons.cc b/crypto/x509/v3_pcons.cc
index cb13137..417f1ad 100644
--- a/crypto/x509/v3_pcons.cc
+++ b/crypto/x509/v3_pcons.cc
@@ -22,7 +22,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_pmaps.cc b/crypto/x509/v3_pmaps.cc
index a182f21..62ccb1b 100644
--- a/crypto/x509/v3_pmaps.cc
+++ b/crypto/x509/v3_pmaps.cc
@@ -20,7 +20,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/crypto/x509/v3_skey.cc b/crypto/x509/v3_skey.cc
index 60bf261..fd86d93 100644
--- a/crypto/x509/v3_skey.cc
+++ b/crypto/x509/v3_skey.cc
@@ -22,7 +22,6 @@
 #include <openssl/obj.h>
 #include <openssl/x509.h>
 
-#include "ext_dat.h"
 #include "internal.h"
 
 
diff --git a/gen/sources.bzl b/gen/sources.bzl
index eb11797..c0f52c6 100644
--- a/gen/sources.bzl
+++ b/gen/sources.bzl
@@ -658,7 +658,6 @@
     "crypto/rsa/internal.h",
     "crypto/spake2plus/internal.h",
     "crypto/trust_token/internal.h",
-    "crypto/x509/ext_dat.h",
     "crypto/x509/internal.h",
     "third_party/fiat/curve25519_32.h",
     "third_party/fiat/curve25519_64.h",
@@ -778,7 +777,6 @@
     "crypto/test/gtest_main.cc",
     "crypto/thread_test.cc",
     "crypto/trust_token/trust_token_test.cc",
-    "crypto/x509/tab_test.cc",
     "crypto/x509/x509_test.cc",
     "crypto/x509/x509_time_test.cc",
 ]
diff --git a/gen/sources.cmake b/gen/sources.cmake
index 6e347f5..39cd4e4 100644
--- a/gen/sources.cmake
+++ b/gen/sources.cmake
@@ -676,7 +676,6 @@
   crypto/rsa/internal.h
   crypto/spake2plus/internal.h
   crypto/trust_token/internal.h
-  crypto/x509/ext_dat.h
   crypto/x509/internal.h
   third_party/fiat/curve25519_32.h
   third_party/fiat/curve25519_64.h
@@ -802,7 +801,6 @@
   crypto/test/gtest_main.cc
   crypto/thread_test.cc
   crypto/trust_token/trust_token_test.cc
-  crypto/x509/tab_test.cc
   crypto/x509/x509_test.cc
   crypto/x509/x509_time_test.cc
 )
diff --git a/gen/sources.gni b/gen/sources.gni
index 1dfd70f..f4158f9 100644
--- a/gen/sources.gni
+++ b/gen/sources.gni
@@ -658,7 +658,6 @@
   "crypto/rsa/internal.h",
   "crypto/spake2plus/internal.h",
   "crypto/trust_token/internal.h",
-  "crypto/x509/ext_dat.h",
   "crypto/x509/internal.h",
   "third_party/fiat/curve25519_32.h",
   "third_party/fiat/curve25519_64.h",
@@ -778,7 +777,6 @@
   "crypto/test/gtest_main.cc",
   "crypto/thread_test.cc",
   "crypto/trust_token/trust_token_test.cc",
-  "crypto/x509/tab_test.cc",
   "crypto/x509/x509_test.cc",
   "crypto/x509/x509_time_test.cc",
 ]
diff --git a/gen/sources.json b/gen/sources.json
index 9602d9d..80e6199 100644
--- a/gen/sources.json
+++ b/gen/sources.json
@@ -640,7 +640,6 @@
       "crypto/rsa/internal.h",
       "crypto/spake2plus/internal.h",
       "crypto/trust_token/internal.h",
-      "crypto/x509/ext_dat.h",
       "crypto/x509/internal.h",
       "third_party/fiat/curve25519_32.h",
       "third_party/fiat/curve25519_64.h",
@@ -759,7 +758,6 @@
       "crypto/test/gtest_main.cc",
       "crypto/thread_test.cc",
       "crypto/trust_token/trust_token_test.cc",
-      "crypto/x509/tab_test.cc",
       "crypto/x509/x509_test.cc",
       "crypto/x509/x509_time_test.cc"
     ],
diff --git a/gen/sources.mk b/gen/sources.mk
index d46e05b..b6664dc 100644
--- a/gen/sources.mk
+++ b/gen/sources.mk
@@ -650,7 +650,6 @@
   crypto/rsa/internal.h \
   crypto/spake2plus/internal.h \
   crypto/trust_token/internal.h \
-  crypto/x509/ext_dat.h \
   crypto/x509/internal.h \
   third_party/fiat/curve25519_32.h \
   third_party/fiat/curve25519_64.h \
@@ -767,7 +766,6 @@
   crypto/test/gtest_main.cc \
   crypto/thread_test.cc \
   crypto/trust_token/trust_token_test.cc \
-  crypto/x509/tab_test.cc \
   crypto/x509/x509_test.cc \
   crypto/x509/x509_time_test.cc