| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
| |
Assisted-by: Jay Satiro
Closes #5607
|
|
|
|
| |
It needs a 'with:' in front of it.
|
|
|
| |
enables code security scanning with github actions
|
|
|
|
|
|
| |
test 1296 is a simply command line test
test 1910 is a libcurl test including a redirect
|
|
|
|
|
|
| |
Reported-by: Jon Johnson Jr
Fixes #5582
Closes #5592
|
|
|
|
|
|
| |
... or all "control codes" or nothing.
Assisted-by: Nicolas Sterchele
|
|
|
|
|
|
|
|
|
| |
...previously CURLINFO_EFFECTIVE_URL would report the URL of the
original "mother transfer", not the actually pushed resource.
Reported-by: Jonathan Cardoso Machado
Fixes #5589
Closes #5591
|
|
|
|
|
|
|
| |
- Include wincrypt before OpenSSL includes so that the latter can
properly handle any conflicts between the two.
Closes https://github.com/curl/curl/pull/5606
|
|
|
|
| |
As was reported in #5601
|
|
|
|
|
|
|
|
| |
Regression added in 7.71.0.
Fixes #5601
Reported-by: Kristoffer Gleditsch
Closes #5602
|
|
|
|
|
|
| |
Reported-by: Siva Sivaraman
Fixes #5412
Closes #5597
|
|
|
|
|
|
|
|
|
| |
Replace "Failed writing body (X != Y)" with
"Failure writing output to destination". Possibly slightly less cryptic.
Reported-by: coinhubs on github
Fixes #5594
Closes #5596
|
| |
|
| |
|
|
|
|
| |
Closes #5599
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
Follow-up to c4e6968127e876b0
When a new transfer is created, as a resuly of an acknowledged push,
that transfer needs a download buffer allocated.
Closes #5590
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit changes the behavior of CURLSSLOPT_NATIVE_CA so that it does
not override CURLOPT_CAINFO / CURLOPT_CAPATH, or the hardcoded default
locations. Instead the CA store can now be used at the same time.
The change is due to the impending release. The issue is still being
discussed. The behavior of CURLSSLOPT_NATIVE_CA is subject to change and
is now documented as experimental.
Ref: bc052cc (parent commit)
Ref: https://github.com/curl/curl/issues/5585
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Background:
148534d added CURLSSLOPT_NATIVE_CA to use the Windows OS certificate
store in libcurl w/ OpenSSL on Windows. CURLSSLOPT_NATIVE_CA overrides
CURLOPT_CAINFO if both are set. The curl tool will fall back to
CURLSSLOPT_NATIVE_CA if it could not find a certificate bundle to set
via CURLOPT_CAINFO.
Problem:
libcurl may be built with hardcoded paths to a certificate bundle or
directory, and if CURLSSLOPT_NATIVE_CA is used then those paths are
ignored.
Solution:
A solution is still being discussed but since there's an impending
release this commit removes using CURLSSLOPT_NATIVE_CA in the curl tool.
Ref: https://github.com/curl/curl/issues/5585
|
|
|
|
|
|
|
| |
Prior to this change I assume a build error would occur when
CURL_CA_FALLBACK was used.
Closes https://github.com/curl/curl/pull/5587
|
| |
|
| |
|
|
|
|
|
| |
Reported-by: sn on hackerone
Bug: https://curl.haxx.se/docs/CVE-2020-8177.html
|
|
|
|
|
|
| |
Reviewed-by: Marcel Raad
Fixes #5512
Closes #5517
|
|
|
|
|
| |
Reviewed-by: Marcel Raad
Closes #5580
|
|
|
|
| |
Closes #5584
|
|
|
|
|
|
|
|
|
|
| |
... and not as a "glob". Now done by passing the supposed host to the
URL parser which supposedly will do a better job at identifying "real"
numerical IPv6 addresses.
Reported-by: puckipedia on github
Fixes #5576
Closes #5579
|
| |
|
|
|
|
|
|
|
| |
Follow-up to 9e5669f3880674
Detected by Coverity CID 1464582 ("Logically dead code")
Closes #5577
|
| |
|
|
|
|
|
|
|
|
| |
For QUIC but also for regular TCP when the second family runs out of IPs
with a failure while the first family is still trying to connect.
Separated the timeout handling for IPv4 and IPv6 connections when they
both have a number of addresses to iterate over.
|
| |
|
|
|
|
|
|
| |
Reported-by: Peter Wu
Fixes #5565
Closes #5568
|
|
|
|
| |
Closes #5573
|
|
|
|
|
|
|
|
|
|
|
|
| |
This avoids using a pair of TCP ports to provide wakeup functionality
for every multi instance on Windows, where socketpair() is emulated
using a TCP socket on loopback which could in turn lead to socket
resource exhaustion.
Reviewed-by: Gergely Nagy
Reviewed-by: Marc Hörsken
Closes #5397
|
|
|
|
|
|
| |
CURL_SSL_BACKEND, QLOGDIR and SSLKEYLOGFILE
Closes #5571
|
| |
|
|
|
|
| |
Also adds pkg-config support for the wolfSSL detection.
|
|
|
|
|
|
|
|
|
| |
When wolfSSL is built with its OpenSSL API layer, it fetures the same DES*
functions that OpenSSL has. This change take advantage of that.
Co-authored-by: Daniel Stenberg
Closes #5556
Fixes #5548
|
|
|
|
|
|
|
|
|
|
|
|
| |
Since the connection can be used by many independent requests (using
HTTP/2 or HTTP/3), things like user-agent and other transfer-specific
data MUST NOT be kept connection oriented as it could lead to requests
getting the wrong string for their requests. This struct data was
lingering like this due to old HTTP1 legacy thinking where it didn't
mattered..
Fixes #5566
Closes #5567
|
|
|
|
|
|
|
|
|
|
|
| |
Assisted-by: Daniel Gustafsson
Assisted-by: Rich Salz
Assisted-by: Hugo van Kemenade
Assisted-by: James Fuller
Assisted-by: Marc Hörsken
Assisted-by: Jay Satiro
Closes #5555
|
|
|
|
|
|
|
|
| |
It was superfluous since we have the list.size alredy
Reported-by: Jay Satiro
Fixes #5553
Closes #5563
|
|
|
|
|
|
|
| |
Added a few missing features not previously mentioned. Ordered them
alphabetically.
Closes #5558
|
|
|
|
| |
Closes #5562
|
|
|
|
|
|
|
|
|
|
| |
The point of this section is to meet the CII Best Practices gold level
critera:
"The project MUST clearly identify small tasks that can be performed by
new or casual contributors"
Closes #5560
|
|
|
|
| |
Closes #5462
|
| |
|
|
|
|
|
|
|
| |
Follow-up to ad6416986755e417c66e2c6, which caused wrong formatting on
curl documentation website
Closes #5561
|
|
|
|
| |
Closes #5549
|