FAILED build of OpenSSL branch master with options -d --strict-warnings no-cms

2020-08-05 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.15.0-106-generic #107-Ubuntu SMP Thu Jun 4 11:27:52 UTC 2020 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings no-cms

Commit log since last time:

914f97eecc Fix provider cipher reinit after init/update with a partial update 
block.
c5b356d5d6 Mark an argument of an inline function as unused
ebc1e8fc4e openssl-cmp.pod.in: Update and extend example using Insta Demo CA
4c525cb5b6 DESERIALIZER: Fix EVP_PKEY construction by export
aff8c0a411 Fix error message on setting cert validity period in apps/cmp.c
57c05c57c3 apps: Correct and extend diagnostics of parse_name()
02ae130e3d Add 'section=...' info in error output of X509V3_EXT_nconf() as far 
as appropriate
1ac658ac9d Rename misleading X509V3_R_INVALID_NULL_NAME to 
X509V3_R_INVALID_EMPTY_NAME
c90c469376 Correct confusing X509V3 conf error output by removing needless 
'section:' etc.
b516a4b139 Correct misleading diagnostics of OBJ_txt2obj on unknown object name
8f7e897995 apps/cmp.c: Defer diagnostic output on server+proxy to be contacted
b5b6669fb6 PROV: Make the DER to KEY deserializer decode parameters too
19b4e6f8fe Coverity Fixes for issue #12531
e5b2cd5899 Change the provider implementation of X942kdf to use wpacket to do 
der encoding of sharedInfo
37d898df34 Add CHANGES.md entry for SSL_set1_host()/SSL_add1_host() taking IP 
literals
892a9e4c99 Disallow setting more than one IP address with SSL_add1_host()
396e720965 Fix certificate validation for IPv6 literals in sconnect demo
c832840e89 Make SSL_set1_host() and SSL_add1_host() take IP addresses
a677190779 81-test_cmp_cli.t: Skip tests with mock server if server cannot be 
started

Build log ended with (last 100 lines):

clang  -I. -Iinclude -Iapps/include -I../openssl -I../openssl/include 
-I../openssl/apps/include  -pthread -m64 -Wa,--noexecstack -Qunused-arguments 
-Wall -O0 -g -DDEBUG_UNUSED -DPEDANTIC -pedantic -Wno-long-long -Wall -Wextra 
-Wno-unused-parameter -Wno-missing-field-initializers -Wswitch -Wsign-compare 
-Wshadow -Wformat -Wtype-limits -Wundef -Werror -Wmissing-prototypes 
-Wstrict-prototypes -Wno-unknown-warning-option -Wswitch-default 
-Wno-parentheses-equality -Wno-language-extension-token -Wno-extended-offsetof 
-Wconditional-uninitialized -Wincompatible-pointer-types-discards-qualifiers 
-Wmissing-variable-declarations -DOPENSSL_BUILDING_OPENSSL  -MMD -MF 
test/ssl_cert_table_internal_test-bin-ssl_cert_table_internal_test.d.tmp -MT 
test/ssl_cert_table_internal_test-bin-ssl_cert_table_internal_test.o -c -o 
test/ssl_cert_table_internal_test-bin-ssl_cert_table_internal_test.o 
../openssl/test/ssl_cert_table_internal_test.c
clang  -Iinclude -Iapps/include -I../openssl/include -I../openssl/apps/include  
-pthread -m64 -Wa,--noexecstack -Qunused-arguments -Wall -O0 -g -DDEBUG_UNUSED 
-DPEDANTIC -pedantic -Wno-long-long -Wall -Wextra -Wno-unused-parameter 
-Wno-missing-field-initializers -Wswitch -Wsign-compare -Wshadow -Wformat 
-Wtype-limits -Wundef -Werror -Wmissing-prototypes -Wstrict-prototypes 
-Wno-unknown-warning-option -Wswitch-default -Wno-parentheses-equality 
-Wno-language-extension-token -Wno-extended-offsetof 
-Wconditional-uninitialized -Wincompatible-pointer-types-discards-qualifiers 
-Wmissing-variable-declarations -DOPENSSL_BUILDING_OPENSSL  -MMD -MF 
test/ssl_ctx_test-bin-ssl_ctx_test.d.tmp -MT 
test/ssl_ctx_test-bin-ssl_ctx_test.o -c -o test/ssl_ctx_test-bin-ssl_ctx_test.o 
../openssl/test/ssl_ctx_test.c
clang  -I. -Iinclude -I../openssl -I../openssl/include -Iinclude -Iapps/include 
-I../openssl/include -I../openssl/apps/include  -pthread -m64 -Wa,--noexecstack 
-Qunused-arguments -Wall -O0 -g -DDEBUG_UNUSED -DPEDANTIC -pedantic 
-Wno-long-long -Wall -Wextra -Wno-unused-parameter 
-Wno-missing-field-initializers -Wswitch -Wsign-compare -Wshadow -Wformat 
-Wtype-limits -Wundef -Werror -Wmissing-prototypes -Wstrict-prototypes 
-Wno-unknown-warning-option -Wswitch-default -Wno-parentheses-equality 
-Wno-language-extension-token -Wno-extended-offsetof 
-Wconditional-uninitialized -Wincompatible-pointer-types-discards-qualifiers 
-Wmissing-variable-declarations -DOPENSSL_BUILDING_OPENSSL  -MMD -MF 
test/ssl_test-bin-handshake_helper.d.tmp -MT 
test/ssl_test-bin-handshake_helper.o -c -o test/ssl_test-bin-handshake_helper.o 
../openssl/test/handshake_helper.c
clang  -Iinclude -Iapps/include -I../openssl/include -I../openssl/apps/include  
-pthread -m64 -Wa,--noexecstack -Qunused-arguments -Wall -O0 -g -DDEBUG_UNUSED 
-DPEDANTIC -pedantic -Wno-long-long -Wall -Wextra -Wno-unused-parameter 
-Wno-missing-field-initializers -Wswitch -Wsign-compare -Wshadow -Wformat 
-Wtype-limits -Wundef -Werror -Wmissing-prototypes -Wstrict-prototypes 
-Wno-unknown-warning-option -Wswitch-default -Wno-parentheses-equality 
-Wno-language-extension-token -Wno-extended-offsetof 
-Wconditional-uninitialized -Wincompatible-pointer-types-discards-qualifiers 
-Wmissing-variable-declarations 

Canceled: openssl/openssl#36492 (master - 914f97e)

2020-08-05 Thread Travis CI
Build Update for openssl/openssl
-

Build: #36492
Status: Canceled

Duration: 11 hrs, 52 mins, and 43 secs
Commit: 914f97e (master)
Author: Shane Lontis
Message: Fix provider cipher reinit after init/update with a partial update 
block.

The test added previously used a 16 byte block during the update which does not 
cause internal buffering in the provider.
Some internal variables related to the buffering were not being cleared in the 
init, which meant that the second
update would use the buffered data from the first update.
Added test for this scenario with exclusions for ciphers that do not support 
partial block updates.

Found by guidovranken.

Reviewed-by: Matt Caswell 
(Merged from https://github.com/openssl/openssl/pull/12523)

View the changeset: 
https://github.com/openssl/openssl/compare/c5b356d5d6cf...914f97eecc91

View the full build log and details: 
https://travis-ci.com/github/openssl/openssl/builds/178477933?utm_medium=notification_source=email

  Restart your build: 
https://travis-ci.com/github/openssl/openssl/builds/178477933?utm_medium=notification_source=email

--

You can unsubscribe from build emails from the openssl/openssl repository going 
to 
https://travis-ci.com/account/preferences/unsubscribe?repository=13885459_medium=notification_source=email.
Or unsubscribe from *all* email updating your settings at 
https://travis-ci.com/account/preferences/unsubscribe?utm_medium=notification_source=email.
Or configure specific recipients for build notifications in your .travis.yml 
file. See https://docs.travis-ci.com/user/notifications.



Still FAILED build of OpenSSL branch master with options -d --strict-warnings no-autoerrinit

2020-08-05 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.15.0-106-generic #107-Ubuntu SMP Thu Jun 4 11:27:52 UTC 2020 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings no-autoerrinit

Commit log since last time:

914f97eecc Fix provider cipher reinit after init/update with a partial update 
block.
c5b356d5d6 Mark an argument of an inline function as unused
ebc1e8fc4e openssl-cmp.pod.in: Update and extend example using Insta Demo CA
4c525cb5b6 DESERIALIZER: Fix EVP_PKEY construction by export
aff8c0a411 Fix error message on setting cert validity period in apps/cmp.c
57c05c57c3 apps: Correct and extend diagnostics of parse_name()
02ae130e3d Add 'section=...' info in error output of X509V3_EXT_nconf() as far 
as appropriate
1ac658ac9d Rename misleading X509V3_R_INVALID_NULL_NAME to 
X509V3_R_INVALID_EMPTY_NAME
c90c469376 Correct confusing X509V3 conf error output by removing needless 
'section:' etc.
b516a4b139 Correct misleading diagnostics of OBJ_txt2obj on unknown object name
8f7e897995 apps/cmp.c: Defer diagnostic output on server+proxy to be contacted
b5b6669fb6 PROV: Make the DER to KEY deserializer decode parameters too
19b4e6f8fe Coverity Fixes for issue #12531
e5b2cd5899 Change the provider implementation of X942kdf to use wpacket to do 
der encoding of sharedInfo
37d898df34 Add CHANGES.md entry for SSL_set1_host()/SSL_add1_host() taking IP 
literals
892a9e4c99 Disallow setting more than one IP address with SSL_add1_host()
396e720965 Fix certificate validation for IPv6 literals in sconnect demo
c832840e89 Make SSL_set1_host() and SSL_add1_host() take IP addresses
a677190779 81-test_cmp_cli.t: Skip tests with mock server if server cannot be 
started

Build log ended with (last 100 lines):

65-test_cmp_status.t ... ok
65-test_cmp_vfy.t .. ok
70-test_asyncio.t .. ok
70-test_bad_dtls.t . ok
70-test_clienthello.t .. ok
70-test_comp.t . ok
70-test_key_share.t  ok
70-test_packet.t ... ok
70-test_recordlen.t  ok
70-test_renegotiation.t  ok
70-test_servername.t ... ok
70-test_sslcbcpadding.t  ok
70-test_sslcertstatus.t  ok
70-test_sslextension.t . ok
70-test_sslmessages.t .. ok
70-test_sslrecords.t ... ok
70-test_sslsessiontick.t ... ok
70-test_sslsigalgs.t ... ok
70-test_sslsignature.t . ok
70-test_sslskewith0p.t . ok
70-test_sslversions.t .. ok
70-test_sslvertol.t  ok
70-test_tls13alerts.t .. ok
70-test_tls13cookie.t .. ok
70-test_tls13downgrade.t ... ok
70-test_tls13hrr.t . ok
70-test_tls13kexmodes.t  ok
70-test_tls13messages.t  ok
70-test_tls13psk.t . ok
70-test_tlsextms.t . ok
70-test_verify_extra.t . ok
70-test_wpacket.t .. ok
71-test_ssl_ctx.t .. ok
80-test_ca.t ... ok
80-test_cipherbytes.t .. ok
80-test_cipherlist.t ... ok
80-test_ciphername.t ... ok

# 80-test_cms.t .. ok
80-test_cmsapi.t ... ok
80-test_ct.t ... ok
80-test_dane.t . ok
80-test_dtls.t . ok
80-test_dtls_mtu.t . ok
80-test_dtlsv1listen.t . ok
80-test_http.t . ok
80-test_ocsp.t . ok
80-test_pkcs12.t ... ok
80-test_ssl_new.t .. ok
80-test_ssl_old.t .. ok
80-test_ssl_test_ctx.t . ok
80-test_sslcorrupt.t ... ok
80-test_tsa.t .. ok
80-test_x509aux.t .. ok

# 81-test_cmp_cli.t .. ok
90-test_asn1_time.t  ok
90-test_async.t  ok
90-test_bio_enc.t .. ok
90-test_bio_memleak.t .. ok
90-test_constant_time.t  ok
90-test_fatalerr.t . ok
90-test_gmdiff.t ... ok
90-test_gost.t . ok
90-test_ige.t .. ok
90-test_includes.t . ok
90-test_memleak.t .. ok
90-test_overhead.t . ok
90-test_secmem.t ... ok
90-test_shlibload.t  ok
90-test_srp.t .. ok
90-test_sslapi.t ... ok
90-test_sslbuffers.t ... ok
90-test_store.t  ok
90-test_sysdefault.t ... ok
90-test_threads.t .. ok
90-test_time_offset.t .. ok
90-test_tls13ccs.t . ok
90-test_tls13encryption.t .. ok
90-test_tls13secrets.t . ok
90-test_v3name.t ... ok
95-test_external_boringssl.t ... skipped: No external tests in this 

Still FAILED build of OpenSSL branch master with options -d --strict-warnings enable-asan no-shared -DOPENSSL_SMALL_FOOTPRINT

2020-08-05 Thread OpenSSL run-checker
Platform and configuration command:

$ uname -a
Linux run 4.15.0-106-generic #107-Ubuntu SMP Thu Jun 4 11:27:52 UTC 2020 x86_64 
x86_64 x86_64 GNU/Linux
$ CC=clang ../openssl/config -d --strict-warnings enable-asan no-shared 
-DOPENSSL_SMALL_FOOTPRINT

Commit log since last time:

914f97eecc Fix provider cipher reinit after init/update with a partial update 
block.
c5b356d5d6 Mark an argument of an inline function as unused
ebc1e8fc4e openssl-cmp.pod.in: Update and extend example using Insta Demo CA
4c525cb5b6 DESERIALIZER: Fix EVP_PKEY construction by export
aff8c0a411 Fix error message on setting cert validity period in apps/cmp.c
57c05c57c3 apps: Correct and extend diagnostics of parse_name()
02ae130e3d Add 'section=...' info in error output of X509V3_EXT_nconf() as far 
as appropriate
1ac658ac9d Rename misleading X509V3_R_INVALID_NULL_NAME to 
X509V3_R_INVALID_EMPTY_NAME
c90c469376 Correct confusing X509V3 conf error output by removing needless 
'section:' etc.
b516a4b139 Correct misleading diagnostics of OBJ_txt2obj on unknown object name
8f7e897995 apps/cmp.c: Defer diagnostic output on server+proxy to be contacted
b5b6669fb6 PROV: Make the DER to KEY deserializer decode parameters too
19b4e6f8fe Coverity Fixes for issue #12531
e5b2cd5899 Change the provider implementation of X942kdf to use wpacket to do 
der encoding of sharedInfo
37d898df34 Add CHANGES.md entry for SSL_set1_host()/SSL_add1_host() taking IP 
literals
892a9e4c99 Disallow setting more than one IP address with SSL_add1_host()
396e720965 Fix certificate validation for IPv6 literals in sconnect demo
c832840e89 Make SSL_set1_host() and SSL_add1_host() take IP addresses
a677190779 81-test_cmp_cli.t: Skip tests with mock server if server cannot be 
started

Build log ended with (last 100 lines):

# Server sent alert unexpected_message but client received no alert.
# 8097B653B97F:error::SSL routines::unexpected 
message:../openssl/ssl/statem/statem_srvr.c:318:
not ok 9 - iteration 9
# --
not ok 1 - test_handshake
# --
../../util/wrap.pl ../../test/ssl_test 25-cipher.cnf.default default => 1
not ok 6 - running ssl_test 25-cipher.cnf
# --
# Looks like you failed 2 tests of 9.
not ok 26 - Test configuration 25-cipher.cnf
# --
# Looks like you failed 1 test of 31.80-test_ssl_new.t .. 
Dubious, test returned 1 (wstat 256, 0x100)
Failed 1/31 subtests 
80-test_ssl_old.t .. ok
80-test_ssl_test_ctx.t . ok

# INFO:  @ ../openssl/test/sslcorrupttest.c:199
# Starting #2, ECDHE-RSA-CHACHA20-POLY1305
# ERROR: (int) 'SSL_get_error(clientssl, 0) == SSL_ERROR_WANT_READ' 
failed @ ../openssl/test/ssltestlib.c:1032
# [1] compared to [2]
# ERROR: (bool) 'create_ssl_connection(server, client, SSL_ERROR_NONE) 
== true' failed @ ../openssl/test/sslcorrupttest.c:229
# false
# 80575E42407F:error::SSL routines::unexpected 
message:../openssl/ssl/statem/statem_clnt.c:403:
not ok 3 - iteration 3
# --
# INFO:  @ ../openssl/test/sslcorrupttest.c:199
# Starting #3, DHE-RSA-CHACHA20-POLY1305
# ERROR: (int) 'SSL_get_error(clientssl, 0) == SSL_ERROR_WANT_READ' 
failed @ ../openssl/test/ssltestlib.c:1032
# [1] compared to [2]
# ERROR: (bool) 'create_ssl_connection(server, client, SSL_ERROR_NONE) 
== true' failed @ ../openssl/test/sslcorrupttest.c:229
# false
# 80575E42407F:error::SSL routines::unexpected 
message:../openssl/ssl/statem/statem_clnt.c:403:
not ok 4 - iteration 4
# --
not ok 1 - test_ssl_corrupt
# --
../../util/wrap.pl ../../test/sslcorrupttest ../../../openssl/apps/server.pem 
../../../openssl/apps/server.pem => 1
not ok 1 - running sslcorrupttest
# --
#   Failed test 'running sslcorrupttest'
#   at ../openssl/test/recipes/80-test_sslcorrupt.t line 19.
# Looks like you failed 1 test of 1.80-test_sslcorrupt.t ... 
Dubious, test returned 1 (wstat 256, 0x100)
Failed 1/1 subtests 
80-test_tsa.t .. ok
80-test_x509aux.t .. ok

# 81-test_cmp_cli.t .. ok
90-test_asn1_time.t  ok
90-test_async.t  ok
90-test_bio_enc.t .. ok
90-test_bio_memleak.t .. ok
90-test_constant_time.t  ok
90-test_fatalerr.t 

Build failed: openssl master.35965

2020-08-05 Thread AppVeyor



Build openssl master.35965 failed


Commit 6346875f9a by Richard Levitte on 8/5/2020 8:28 AM:

"Downgrade" provider-native keys to legacy where needed


Configure your notification preferences



Errored: openssl/openssl#36492 (master - 914f97e)

2020-08-05 Thread Travis CI
Build Update for openssl/openssl
-

Build: #36492
Status: Errored

Duration: 11 hrs, 52 mins, and 43 secs
Commit: 914f97e (master)
Author: Shane Lontis
Message: Fix provider cipher reinit after init/update with a partial update 
block.

The test added previously used a 16 byte block during the update which does not 
cause internal buffering in the provider.
Some internal variables related to the buffering were not being cleared in the 
init, which meant that the second
update would use the buffered data from the first update.
Added test for this scenario with exclusions for ciphers that do not support 
partial block updates.

Found by guidovranken.

Reviewed-by: Matt Caswell 
(Merged from https://github.com/openssl/openssl/pull/12523)

View the changeset: 
https://github.com/openssl/openssl/compare/c5b356d5d6cf...914f97eecc91

View the full build log and details: 
https://travis-ci.com/github/openssl/openssl/builds/178477933?utm_medium=notification_source=email


--

You can unsubscribe from build emails from the openssl/openssl repository going 
to 
https://travis-ci.com/account/preferences/unsubscribe?repository=13885459_medium=notification_source=email.
Or unsubscribe from *all* email updating your settings at 
https://travis-ci.com/account/preferences/unsubscribe?utm_medium=notification_source=email.
Or configure specific recipients for build notifications in your .travis.yml 
file. See https://docs.travis-ci.com/user/notifications.