summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* gcc: disable picky gcc-8 function pointer warnings in two placesbagder/gcc8-cast-function-typeDaniel Stenberg2018-05-142-2/+12
| | | | | Reported-by: Rikard Falkeborn Bug: #2560
* http2: use the correct function pointer typedefDaniel Stenberg2018-05-143-22/+18
| | | | | | | Fixes gcc-8 picky compiler warnings Reported-by: Rikard Falkeborn Bug: #2560 Closes #2568
* CODE_STYLE: mention return w/o parens, but sizeof withDaniel Stenberg2018-05-141-38/+46
| | | | | | ... and remove the github markdown syntax so that it renders better on the web site. Also, don't use back-ticks inlined to allow the CSS to highlight source code better.
* examples: Fix format specifiersRikard Falkeborn2018-05-147-20/+20
| | | | Closes #2561
* tool: Fix format specifiersRikard Falkeborn2018-05-142-3/+3
|
* ntlm: Fix format specifiersRikard Falkeborn2018-05-141-3/+3
|
* tests: Fix format specifiersRikard Falkeborn2018-05-148-13/+13
|
* lib: Fix format specifiersRikard Falkeborn2018-05-145-8/+8
|
* contributors.sh: use "on github", not atDaniel Stenberg2018-05-141-1/+2
|
* http2: getsock fix for uploadsDaniel Stenberg2018-05-141-1/+4
| | | | | | | | | When there's an upload in progress, make sure to wait for the socket to become writable. Detected-by: steini2000 on github Bug: #2520 Closes #2567
* pingpong: fix response cache memcpy overflowDaniel Stenberg2018-05-141-1/+4
| | | | | | | | | | | Response data for a handle with a large buffer might be cached and then used with the "closure" handle when it has a smaller buffer and then the larger cache will be copied and overflow the new smaller heap based buffer. Reported-by: Dario Weisser CVE: CVE-2018-1000300 Bug: https://curl.haxx.se/docs/adv_2018-82c2.html
* http: restore buffer pointer when bad response-line is parsedDaniel Stenberg2018-05-141-1/+5
| | | | | | | | | | | ... leaving the k->str could lead to buffer over-reads later on. CVE: CVE-2018-1000301 Assisted-by: Max Dymond Detected by OSS-Fuzz. Bug: https://curl.haxx.se/docs/adv_2018-b138.html Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7105
* cookies: do not take cookie name as a parameterPatrick Monnerat2018-05-133-2/+62
| | | | | | | | | | | | RFC 6265 section 4.2.1 does not set restrictions on cookie names. This is a follow-up to commit 7f7fcd0. Also explicitly check proper syntax of cookie name/value pair. New test 1155 checks that cookie names are not reserved words. Reported-By: anshnd at github Fixes #2564 Closes #2566
* smb: reject negative file sizesDaniel Stenberg2018-05-121-4/+10
| | | | | | | Assisted-by: Max Dymond Detected by OSS-Fuzz Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8245
* setup_transfer: deal with both sockets being -1Daniel Stenberg2018-05-111-1/+2
| | | | | Detected by Coverity; CID 1435559. Follow-up to f8d608f38d00. It would index the array with -1 if neither index was a socket.
* travis: add build using NSSDaniel Stenberg2018-05-101-1/+8
| | | | Closes #2558
* openssl: change FILE ops to BIO opsSunny Purushe2018-05-101-15/+41
| | | | | | | | | To make builds with VS2015 work. Recent changes in VS2015 _IOB_ENTRIES handling is causing problems. This fix changes the OpenSSL backend code to use BIO functions instead of FILE I/O functions to circumvent those problems. Closes #2512
* travis: add a build using WolfSSLDaniel Stenberg2018-05-091-1/+27
| | | | | | Assisted-by: Dan Fandrich Closes #2528
* RELEASE-NOTES: typoDaniel Stenberg2018-05-071-1/+1
|
* RELEASE-NOTES: syncedDaniel Stenberg2018-05-071-5/+24
|
* URLs: fix one more http urlDaniel Gustafsson2018-05-051-1/+1
| | | | | | | | This file wasn't included in commit 4af40b3646d3b09 which updated all haxx.se http urls to https. The file was committed prior to that update, but may have been merged after it and hence didn't get updated. Closes #2550
* github/lock: auto-lock closed issues after 90 days of inactivityDaniel Stenberg2018-05-051-0/+8
|
* vtls: fix missing commasDaniel Stenberg2018-05-043-3/+3
| | | | follow-up to e66cca046cef
* vtls: use unified "supports" bitfield member in backendsDaniel Stenberg2018-05-0415-89/+53
| | | | | | | ... instead of previous separate struct fields, to make it easier to extend and change individual backends without having to modify them all. closes #2547
* transfer: don't unset writesockfd on setup of multiplexed connsDaniel Stenberg2018-05-041-6/+13
| | | | | | | | Curl_setup_transfer() can be called to setup a new individual transfer over a multiplexed connection so it shouldn't unset writesockfd. Bug: #2520 Closes #2549
* configure: put CURLDEBUG and DEBUGBUILD in lib/curl_config.hFrank Gevaerts2018-05-042-10/+4
| | | | | | | | | They are removed from the compiler flags. This ensures that make dependency tracking will force a rebuild whenever configure --enable-debug or --enable-curldebug changes. Closes #2548
* http: don't set the "rewind" flag when not uploading anythingDaniel Stenberg2018-05-041-1/+1
| | | | | | | | It triggers an assert. Detected by OSS-Fuzz Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=8144 Closes #2546
* travis: add an mbedtls buildbagder/travis-mbedtlsDaniel Stenberg2018-05-041-0/+17
| | | | Closes #2531
* configure: only check for CA bundle for file-using SSL backendsDaniel Stenberg2018-05-031-3/+9
| | | | | | | | | When only building with SSL backends that don't use the CA bundle file (by default), skip the check. Fixes #2543 Fixes #2180 Closes #2545
* ssh-libssh.c: fix left shift compiler warningDaniel Stenberg2018-05-031-2/+1
| | | | | | | | ssh-libssh.c:2429:21: warning: result of '1 << 31' requires 33 bits to represent, but 'int' only has 32 bits [-Wshift-overflow=] 'len' will never be that big anyway so I converted the run-time check to a regular assert.
* URL: fix ASCII dependency in strcpy_url and strlen_urlStephan Mühlstrasser2018-05-033-2/+22
| | | | | | | | | | | | | | Commit 3c630f9b0af097663a64e5c875c580aa9808a92b partially reverted the changes from commit dd7521bcc1b7a6fcb53c31f9bd1192fcc884bd56 because of the problem that strcpy_url() was modified unilaterally without also modifying strlen_url(). As a consequence strcpy_url() was again depending on ASCII encoding. This change fixes strlen_url() and strcpy_url() in parallel to use a common host-encoding independent criterion for deciding whether an URL character must be %-escaped. Closes #2535
* docs: remove extraneous commas in man pagesDenis Ollier2018-05-033-4/+4
| | | | Closes #2544
* RELEASE-NOTES: syncedDaniel Stenberg2018-05-031-13/+31
|
* Revert "TODO: remove configure --disable-pthreads"Daniel Stenberg2018-05-031-11/+6
| | | | | | | This reverts commit d5d683a97f9765bddfd964fe32e137aa6e703ed3. --disable-pthreads can be used to disable pthreads and get the threaded resolver to use the windows threading when building with mingw.
* vtls: don't define MD5_DIGEST_LENGTH for wolfsslDaniel Stenberg2018-05-021-1/+3
| | | | ... as it defines it (too)
* TODO: remove configure --disable-pthreadsDaniel Stenberg2018-05-021-6/+11
|
* wolfssl: Fix non-blocking connectDavid Garske2018-05-021-1/+1
| | | | Closes https://github.com/curl/curl/pull/2542
* CURLOPT_URL.3: add ENCODING section [ci skip]Daniel Stenberg2018-04-301-1/+11
| | | | Feedback-by: Michael Kilburn
* KNOWN_BUGS: Client cert with Issuer DN differs between backendsDaniel Stenberg2018-04-301-0/+8
| | | | Closes #1411
* KNOWN_BUGS: Passive transfer tries only one IP addressDaniel Stenberg2018-04-301-0/+13
| | | | Closes #1508
* KNOWN_BUGS: --upload-file . hang if delay in STDINDaniel Stenberg2018-04-301-0/+8
| | | | Closes #2051
* KNOWN_BUGS: Connection information when using TCP Fast OpenDaniel Stenberg2018-04-301-0/+8
| | | | Closes #1332
* travis: enable libssh2 on both macos and LinuxDaniel Stenberg2018-04-301-2/+2
| | | | | | | It seems to not be detected by default anymore (which is a bug I believe) Closes #2541
* TODO: Support the clienthello extensionDaniel Stenberg2018-04-301-0/+11
| | | | Closes #2299
* TODO: CLOEXECDaniel Stenberg2018-04-301-0/+9
| | | | Closes #2252
* tests: provide 'manual' as a feature to optionally requireDaniel Stenberg2018-04-293-0/+21
| | | | | | | | | ... and make test 1026 rely on that feature so that --disable-manual builds don't cause test failures. Reported-by: Max Dymond and Anders Roxell Fixes #2533 Closes #2540
* CURLINFO_PROTOCOL.3: mention the existing defined namesDaniel Stenberg2018-04-271-3/+12
|
* cookies: remove unused macroDaniel Gustafsson2018-04-271-1/+0
| | | | | | | Commit 2bc230de63 made the macro MAX_COOKIE_LINE_TXT become unused, so remove as it's not part of the published API. Closes https://github.com/curl/curl/pull/2537
* checksrc: force indentation of lines after an elseDaniel Gustafsson2018-04-277-17/+11
| | | | | | | | This extends the INDENTATION case to also handle 'else' statements and require proper indentation on the following line. Also fixes the offending cases found in the codebase. Closes #2532
* http2: fix null pointer dereference in http2_connisdeadDaniel Stenberg2018-04-261-2/+5
| | | | | | | | | | | This function can get called on a connection that isn't setup enough to have the 'recv_underlying' function pointer initialized so it would try to call the NULL pointer. Reported-by: Dario Weisser Follow-up to db1b2c7fe9b093f8 (never shipped in a release) Closes #2536