commit | 21a879a78a60c8667468a9eba994c8365eaf92ea | [log] [tgz] |
---|---|---|
author | David Benjamin <davidben@google.com> | Mon Feb 10 18:46:14 2020 -0500 |
committer | Adam Langley <agl@google.com> | Tue Feb 11 21:47:07 2020 +0000 |
tree | a01c03635bc7877608b726267531b42a602de070 | |
parent | 82a4b2234ece952a98c653cdcd207d1c02e92009 [diff] |
Delete unreachable DTLS check. It is impossible for us to have an unconsumed ChangeCipherSpec message in dtls_has_unprocessed_handshake_data. dtls_has_unprocessed_handshake_data is only called in dtls1_set_read_state and, in DTLS 1.2 and earlier, we only ever switch the cipher state immediately after consuming ChangeCipherSpec. Remove this because later commits will check has_unprocessed_handshake_data in more places and we have a test (StrayChangeCipherSpec) which asserts we do tolerate arbitrarily early ChangeCipherSpecs messages. There may be something to be said for rejecting this (the peer would have to be doing something weird and sending ChangeCipherSpec in the wrong flight), but ChangeCipherSpec in DTLS is predictable and informationless, so this is probably not worth worrying about. Change-Id: I1bc2952c0ba5231a7f962b9f7ca4c63271ec079f Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/39986 Reviewed-by: Adam Langley <agl@google.com>
BoringSSL is a fork of OpenSSL that is designed to meet Google's needs.
Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.
Programs ship their own copies of BoringSSL when they use it and we update everything as needed when deciding to make API changes. This allows us to mostly avoid compromises in the name of compatibility. It works for us, but it may not work for you.
BoringSSL arose because Google used OpenSSL for many years in various ways and, over time, built up a large number of patches that were maintained while tracking upstream OpenSSL. As Google's product portfolio became more complex, more copies of OpenSSL sprung up and the effort involved in maintaining all these patches in multiple places was growing steadily.
Currently BoringSSL is the SSL library in Chrome/Chromium, Android (but it's not part of the NDK) and a number of other apps/programs.
Project links:
There are other files in this directory which might be helpful: