platform/upstream/curl.git
10 years agoRELEASE-NOTES: Synced with 0ff0a994ada62a
Steve Holme [Wed, 25 Dec 2013 00:08:16 +0000 (00:08 +0000)]
RELEASE-NOTES: Synced with 0ff0a994ada62a

10 years agoCurl_thread_create: use Curl_safefree to allow NULL better
Daniel Stenberg [Tue, 24 Dec 2013 23:53:15 +0000 (00:53 +0100)]
Curl_thread_create: use Curl_safefree to allow NULL better

free() itself allows a NULL input but our memory debug system requires
Curl_safefree() to be used instead when a "legitimate" NULL may be freed. Like
in the code here.

Pointed-out-by: Steve Holme
10 years agothreaded resolver: Use pthread_t * for curl_thread_t
Luke Dashjr [Tue, 24 Dec 2013 23:10:42 +0000 (23:10 +0000)]
threaded resolver: Use pthread_t * for curl_thread_t

... since pthread_t may be non-scalar and/or may represent a real thread
with scalar 0.

Bug: http://curl.haxx.se/bug/view.cgi?id=1314

10 years agoimap: Fixed auth preference not being honored when CAPABILITY not supported
Steve Holme [Tue, 24 Dec 2013 22:45:25 +0000 (22:45 +0000)]
imap: Fixed auth preference not being honored when CAPABILITY not supported

If a user indicated they preferred to authenticate using a SASL
mechanism, but SASL authentication wasn't supported by the server, curl
would always fall back to clear text when CAPABILITY wasn't supported,
even though the user didn't want to use this.

10 years agopop3: Fixed auth preference not being honored when CAPA not supported
Steve Holme [Tue, 24 Dec 2013 22:35:55 +0000 (22:35 +0000)]
pop3: Fixed auth preference not being honored when CAPA not supported

If a user indicated they preferred to authenticate using APOP or a SASL
mechanism, but neither were supported by the server, curl would always
fall back to clear text when CAPA wasn't supported, even though the
user didn't want to use this.

This also fixes the auto build failure caused by commit 6f2d5f0562f64a.

10 years agoTheArtOfHttpScripting: major update, converted layout and more
Daniel Stenberg [Wed, 18 Dec 2013 21:21:17 +0000 (22:21 +0100)]
TheArtOfHttpScripting: major update, converted layout and more

10 years agoCurl_pp_readresp: use memmove not memcpy, possibly overlapping areas
Daniel Stenberg [Tue, 24 Dec 2013 20:29:18 +0000 (21:29 +0100)]
Curl_pp_readresp: use memmove not memcpy, possibly overlapping areas

Fixes commit 1deac31eba7

10 years agoRELEASE-NOTES: Corrected copy/paste typo
Steve Holme [Tue, 24 Dec 2013 16:48:48 +0000 (16:48 +0000)]
RELEASE-NOTES: Corrected copy/paste typo

10 years agopop3: Fixed APOP being determined by CAPA response rather than by timestamp
Steve Holme [Tue, 24 Dec 2013 16:32:48 +0000 (16:32 +0000)]
pop3: Fixed APOP being determined by CAPA response rather than by timestamp

This commit replaces that of 9f260b5d6610f3 because according to RFC-2449,
section 6, there is no APOP capability "...even though APOP is an
optional command in [POP3].  Clients discover server support of APOP by
the presence in the greeting banner of an initial challenge enclosed in
angle brackets."

10 years agotests: Removed APOP timestamp from default server greeting
Steve Holme [Tue, 24 Dec 2013 06:52:18 +0000 (06:52 +0000)]
tests: Removed APOP timestamp from default server greeting

10 years agotest936: Corrected login details from commit 7246255416617a
Steve Holme [Mon, 23 Dec 2013 12:25:33 +0000 (12:25 +0000)]
test936: Corrected login details from commit 7246255416617a

10 years agoftpserver.pl: Updated custom full text REPLY regex
Steve Holme [Mon, 23 Dec 2013 12:20:32 +0000 (12:20 +0000)]
ftpserver.pl: Updated custom full text REPLY regex

SASL downgrade tests: 833, 835, 879, 881, 935 and 937 would fail as
they contained a minus sign in their authentication mechanism and this
would be missed by the custom reply parser.

10 years agotests: Corrected syntax error from commit 7246255416617a
Steve Holme [Mon, 23 Dec 2013 08:10:55 +0000 (08:10 +0000)]
tests: Corrected syntax error from commit 7246255416617a

10 years agotests: Added SMTP SASL downgrade tests
Steve Holme [Sun, 22 Dec 2013 22:30:50 +0000 (22:30 +0000)]
tests: Added SMTP SASL downgrade tests

10 years agotests: Added POP3 SASL downgrade tests
Steve Holme [Sun, 22 Dec 2013 22:20:50 +0000 (22:20 +0000)]
tests: Added POP3 SASL downgrade tests

10 years agotests: Added IMAP SASL downgrade tests
Steve Holme [Sun, 22 Dec 2013 22:10:50 +0000 (22:10 +0000)]
tests: Added IMAP SASL downgrade tests

10 years agodocs: mention CURLOPT_MAX_RECV/SEND_SPEED_LARGE don't work for FILE://
Daniel Stenberg [Sun, 22 Dec 2013 22:45:10 +0000 (23:45 +0100)]
docs: mention CURLOPT_MAX_RECV/SEND_SPEED_LARGE don't work for FILE://

10 years agoFILE: don't wait due to CURLOPT_MAX_RECV_SPEED_LARGE
Daniel Stenberg [Sun, 22 Dec 2013 22:36:11 +0000 (23:36 +0100)]
FILE: don't wait due to CURLOPT_MAX_RECV_SPEED_LARGE

The FILE:// code doesn't support this option - and it doesn't make sense
to support it as long as it works as it does since then it'd only block
even longer.

But: setting CURLOPT_MAX_RECV_SPEED_LARGE would make the transfer first
get done and then libcurl would wait until the average speed would get
low enough. This happened because the transfer happens completely in the
DO state for FILE:// but then it would still unconditionally continue in
to the PERFORM state where the speed check is made.

Starting now, the code will skip from DO_DONE to DONE immediately if no
socket is set to be recv()ed or send()ed to.

Bug: http://curl.haxx.se/bug/view.cgi?id=1312
Reported-by: Mohammad AlSaleh
10 years agoftpserver.pl: Fixed runtime warning from commit 7da9c95bcf1fe6
Steve Holme [Sun, 22 Dec 2013 21:40:50 +0000 (21:40 +0000)]
ftpserver.pl: Fixed runtime warning from commit 7da9c95bcf1fe6

Use of uninitialized value $FTPARG in concatenation (.) or string at
line 3255.

10 years agoftpserver.pl: Added the ability to send custom full text replies
Steve Holme [Sun, 22 Dec 2013 19:10:43 +0000 (19:10 +0000)]
ftpserver.pl: Added the ability to send custom full text replies

10 years agoftpserver.pl: Added the ability to specify custom full text replies
Steve Holme [Sun, 22 Dec 2013 17:10:43 +0000 (17:10 +0000)]
ftpserver.pl: Added the ability to specify custom full text replies

10 years agoftpserver.pl: Renamed commandreply variable from customreply
Steve Holme [Sun, 22 Dec 2013 15:10:43 +0000 (15:10 +0000)]
ftpserver.pl: Renamed commandreply variable from customreply

10 years agotests: Added SASL cancellation keywords
Steve Holme [Sun, 22 Dec 2013 13:10:43 +0000 (13:10 +0000)]
tests: Added SASL cancellation keywords

Added SASL CANCELLATION keywords to differentiate these tests from the
upcoming SASL downgrade tests.

10 years agoemail: Fixed segfault introduced in commit 195b63f99c2fe3
Steve Holme [Sun, 22 Dec 2013 00:16:52 +0000 (00:16 +0000)]
email: Fixed segfault introduced in commit 195b63f99c2fe3

10 years agocode police: fix indent level to silence checksrc complaints
Daniel Stenberg [Sun, 22 Dec 2013 00:01:19 +0000 (01:01 +0100)]
code police: fix indent level to silence checksrc complaints

10 years agoemail: Extended the login options to support multiple auth mechanisms
Steve Holme [Sat, 21 Dec 2013 23:34:45 +0000 (23:34 +0000)]
email: Extended the login options to support multiple auth mechanisms

10 years agoCurl_pp_readresp: replace stupid loop with memcpy
Daniel Stenberg [Sat, 21 Dec 2013 23:29:43 +0000 (00:29 +0100)]
Curl_pp_readresp: replace stupid loop with memcpy

10 years agoCurl_pp_readresp: zero terminate line
Daniel Stenberg [Sat, 21 Dec 2013 23:17:58 +0000 (00:17 +0100)]
Curl_pp_readresp: zero terminate line

The comment in the code mentions the zero terminating after having
copied data, but it mistakingly zero terminated the source data and not
the destination! This caused the test 864 problem discussed on the list:

http://curl.haxx.se/mail/lib-2013-12/0113.html
Signed-off-by: Daniel Stenberg <daniel@haxx.se>
10 years agoRevert "pop3: Added debug information to assist with test864 failure"
Steve Holme [Sat, 21 Dec 2013 12:50:30 +0000 (12:50 +0000)]
Revert "pop3: Added debug information to assist with test864 failure"

This reverts commit 727d798d680f29c8b3cb7d7f03d6b6a3eb4356da.

10 years agopop3: Added debug information to assist with test864 failure
Steve Holme [Sat, 21 Dec 2013 11:15:00 +0000 (11:15 +0000)]
pop3: Added debug information to assist with test864 failure

10 years agoRELEASE-NOTES: Synced with 812c5ace759d04
Steve Holme [Fri, 20 Dec 2013 20:27:21 +0000 (20:27 +0000)]
RELEASE-NOTES: Synced with 812c5ace759d04

10 years agopop3: Fixed APOP timestamp detection from commit 1cfb436a2f1795
Steve Holme [Fri, 20 Dec 2013 20:17:59 +0000 (20:17 +0000)]
pop3: Fixed APOP timestamp detection from commit 1cfb436a2f1795

10 years agoMakefile.inc: use standard source header
Daniel Stenberg [Wed, 18 Dec 2013 13:27:31 +0000 (14:27 +0100)]
Makefile.inc: use standard source header

10 years agoMakefile.inc: specify the vtls sources+headers separately
Daniel Stenberg [Wed, 18 Dec 2013 13:25:43 +0000 (14:25 +0100)]
Makefile.inc: specify the vtls sources+headers separately

10 years agovtls: renamed sslgen.[ch] to vtls.[ch]
Daniel Stenberg [Tue, 17 Dec 2013 22:32:47 +0000 (23:32 +0100)]
vtls: renamed sslgen.[ch] to vtls.[ch]

10 years agoopenssl: renamed backend files to openssl.[ch]
Daniel Stenberg [Tue, 17 Dec 2013 22:26:35 +0000 (23:26 +0100)]
openssl: renamed backend files to openssl.[ch]

10 years agovtls: moved all TLS/SSL source and header files into subdir
Daniel Stenberg [Tue, 17 Dec 2013 22:16:34 +0000 (23:16 +0100)]
vtls: moved all TLS/SSL source and header files into subdir

10 years agovtls: created subdir, moved sslgen.[ch] there, updated all include lines
Daniel Stenberg [Tue, 17 Dec 2013 22:05:37 +0000 (23:05 +0100)]
vtls: created subdir, moved sslgen.[ch] there, updated all include lines

10 years agopop3: Fixed selection of APOP when server replies with an invalid timestamp
Steve Holme [Fri, 20 Dec 2013 12:46:18 +0000 (12:46 +0000)]
pop3: Fixed selection of APOP when server replies with an invalid timestamp

Although highlighted by a bug in commit 1cfb436a2f1795, APOP
authentication could be chosen if the server was to reply with an empty
or missing timestamp in the server greeting and APOP was given in the
capability list by the server.

10 years agopop3: Fixed processing of more than one response when sent in same packet
Steve Holme [Fri, 20 Dec 2013 07:17:17 +0000 (07:17 +0000)]
pop3: Fixed processing of more than one response when sent in same packet

Added a loop to pop3_statemach_act() in which Curl_pp_readresp() is
called until the cache is drained. Without this multiple responses
received in a single packet could result in a hang or delay.

10 years agopop3: Moved CAPA response handling to pop3_state_capa_resp()
Steve Holme [Fri, 20 Dec 2013 07:12:12 +0000 (07:12 +0000)]
pop3: Moved CAPA response handling to pop3_state_capa_resp()

Similar to the processing of untagged CAPABILITY responses in IMAP and
multi-line EHLO responses in SMTP, moved the processing of multi-line
CAPA responses to pop3_state_capa_resp().

10 years agopop3: Moved APOP detection into pop3_state_servergreet_resp()
Steve Holme [Fri, 20 Dec 2013 07:07:07 +0000 (07:07 +0000)]
pop3: Moved APOP detection into pop3_state_servergreet_resp()

In an effort to reduce what pop3_endofresp() does and bring the POP3
source back inline with the IMAP and SMTP protocols, moved the APOP
detection into pop3_state_servergreet_resp().

10 years agocurl_easy_setopt: Fixed OAuth 2.0 Bearer option name
Steve Holme [Thu, 19 Dec 2013 22:40:56 +0000 (22:40 +0000)]
curl_easy_setopt: Fixed OAuth 2.0 Bearer option name

Bug: http://curl.haxx.se/bug/view.cgi?id=1313
Reported-by: Viktor Szakáts
10 years agocurl.1: remove URL encoding phrase from --data description
Daniel Stenberg [Wed, 18 Dec 2013 21:46:38 +0000 (22:46 +0100)]
curl.1: remove URL encoding phrase from --data description

... it could be misleading a reader into thinking it _has_ to be encoded.

10 years agoimap/pop3/smtp: Added support for SASL authentication downgrades
Steve Holme [Wed, 18 Dec 2013 20:44:20 +0000 (20:44 +0000)]
imap/pop3/smtp: Added support for SASL authentication downgrades

Added support for downgrading the SASL authentication mechanism when the
decoding of CRAM-MD5, DIGEST-MD5 and NTLM messages fails. This enhances
the previously added support for graceful cancellation by allowing the
client to retry a lesser SASL mechanism such as LOGIN or PLAIN, or even
APOP / clear text (in the case of POP3 and IMAP) when supported by the
server.

10 years agoRELEASE-PROCEDURE: new document
Daniel Stenberg [Wed, 18 Dec 2013 13:37:04 +0000 (14:37 +0100)]
RELEASE-PROCEDURE: new document

10 years agogitignore: ignore .dirstamp files
Daniel Stenberg [Wed, 18 Dec 2013 13:35:56 +0000 (14:35 +0100)]
gitignore: ignore .dirstamp files

10 years agosmtp: fix compiler warning
Daniel Stenberg [Wed, 18 Dec 2013 12:53:45 +0000 (13:53 +0100)]
smtp: fix compiler warning

smtp.c:478:21: error: unused variable 'smtpc' [-Werror=unused-variable]

10 years agosmtp: Moved the calculation of SASL login details into a separate function
Steve Holme [Wed, 18 Dec 2013 12:39:13 +0000 (12:39 +0000)]
smtp: Moved the calculation of SASL login details into a separate function

10 years agopop3: Moved the calculation of SASL login details into a separate function
Steve Holme [Wed, 18 Dec 2013 12:34:56 +0000 (12:34 +0000)]
pop3: Moved the calculation of SASL login details into a separate function

10 years agoimap: Moved the calculation of SASL login details into a separate function
Steve Holme [Wed, 18 Dec 2013 12:29:46 +0000 (12:29 +0000)]
imap: Moved the calculation of SASL login details into a separate function

10 years agosmtp: Moved the sending of the AUTH command into a separate function
Steve Holme [Wed, 18 Dec 2013 07:10:22 +0000 (07:10 +0000)]
smtp: Moved the sending of the AUTH command into a separate function

10 years agopop3: Moved the sending of the AUTH command into a separate function
Steve Holme [Wed, 18 Dec 2013 07:05:11 +0000 (07:05 +0000)]
pop3: Moved the sending of the AUTH command into a separate function

10 years agoimap: Moved the sending of the AUTHENICATE command into a separate function
Steve Holme [Wed, 18 Dec 2013 07:00:00 +0000 (07:00 +0000)]
imap: Moved the sending of the AUTHENICATE command into a separate function

10 years agoemail: Renamed *_perform_authenticate() functions
Steve Holme [Tue, 17 Dec 2013 22:48:09 +0000 (22:48 +0000)]
email: Renamed *_perform_authenticate() functions

In preparation for the upcoming SASL downgrade feature renamed the
imap__perform_authenticate(), pop3__perform_authenticate() and
smtp__perform_authenticate() functions.

10 years agobump: start working on the next release
Daniel Stenberg [Tue, 17 Dec 2013 15:38:51 +0000 (16:38 +0100)]
bump: start working on the next release

10 years agoRELEASE-NOTES: synced with c0ef05e67
Daniel Stenberg [Mon, 16 Dec 2013 21:46:22 +0000 (22:46 +0100)]
RELEASE-NOTES: synced with c0ef05e67

... for the pending 7.34.0 release

Upped the contributor count

10 years agoTHANKS: add contributors from 7.34.0 release
Daniel Stenberg [Mon, 16 Dec 2013 21:52:41 +0000 (22:52 +0100)]
THANKS: add contributors from 7.34.0 release

24 new great friends

10 years agogtls: respect *VERIFYHOST independently of *VERIFYPEER
Daniel Stenberg [Fri, 29 Nov 2013 21:46:05 +0000 (22:46 +0100)]
gtls: respect *VERIFYHOST independently of *VERIFYPEER

Security flaw CVE-2013-6422

This is conceptually the same problem and fix that 3c3622b6 brought to the
OpenSSL backend and that resulted in CVE-2013-4545.

This version of the problem was independently introduced to the GnuTLS
backend with commit 59cf93cc, present in the code since the libcurl
7.21.4 release.

Advisory: http://curl.haxx.se/docs/adv_20131217.html
Bug: http://curl.haxx.se/mail/lib-2013-11/0214.html
Reported-by: Marc Deslauriers
10 years agocurl.1 document -J doesn't %-decode
Daniel Stenberg [Sun, 15 Dec 2013 22:38:37 +0000 (23:38 +0100)]
curl.1 document -J doesn't %-decode

...also added as KNOWN_BUG #87 with reference to bug #1294

10 years agomulti: add timer inaccuracy margin to timeout/connecttimeout
Daniel Stenberg [Mon, 2 Dec 2013 14:33:32 +0000 (15:33 +0100)]
multi: add timer inaccuracy margin to timeout/connecttimeout

Since all systems have inaccuracy in the timeout handling it is
imperative that we add an inaccuracy margin to the general timeout and
connecttimeout handling with the multi interface. This way, when the
timeout fires we should be fairly sure that it has passed the timeout
value and will be suitably detected.

For cases where the timeout fire before the actual timeout, we would
otherwise consume the timeout action and still not run the timeout code
since the condition wasn't met.

Reported-by: He Qin
Bug: http://curl.haxx.se/bug/view.cgi?id=1298

10 years agoRELEASE-NOTES: synced with dd4d9ea542
Daniel Stenberg [Sat, 14 Dec 2013 22:22:52 +0000 (23:22 +0100)]
RELEASE-NOTES: synced with dd4d9ea542

10 years agocurl_easy_setopt: clarify some USERPWD and PROXYUSERPWD details
Daniel Stenberg [Sat, 14 Dec 2013 22:09:05 +0000 (23:09 +0100)]
curl_easy_setopt: clarify some USERPWD and PROXYUSERPWD details

10 years agologin options: remove the ;[options] support from CURLOPT_USERPWD
Daniel Stenberg [Sat, 14 Dec 2013 21:39:27 +0000 (22:39 +0100)]
login options: remove the ;[options] support from CURLOPT_USERPWD

To avoid the regression when users pass in passwords containing semi-
colons, we now drop the ability to set the login options with the same
options. Support for login options in CURLOPT_USERPWD was added in
7.31.0.

Test case 83 was modified to verify that colons and semi-colons can be
used as part of the password when using -u (CURLOPT_USERPWD).

Bug: http://curl.haxx.se/bug/view.cgi?id=1311
Reported-by: Petr Bahula
Assisted-by: Steve Holme
Signed-off-by: Daniel Stenberg <daniel@haxx.se>
10 years agoimap: Fixed exclude of clear text when using auth=* in commit 75cd7fd66762bb
Steve Holme [Sat, 14 Dec 2013 12:23:23 +0000 (12:23 +0000)]
imap: Fixed exclude of clear text when using auth=* in commit 75cd7fd66762bb

It is not 100% clear whether * should include clear text LOGIN or not
from RFC-5092, however, including it is then consistent with current
POP3 behaviour where clear text, APOP or SASL may be chosen.

10 years agoimap: Fixed incorrect fallback to clear text authentication
Steve Holme [Fri, 13 Dec 2013 22:57:13 +0000 (22:57 +0000)]
imap: Fixed incorrect fallback to clear text authentication

If a specific SASL authentication mechanism was requested by the user
as part of the login options but wasn't supported by the server then
curl would fallback to clear text, when it shouldn't, rather than
reporting "No known authentication mechanisms supported" as the POP3
and SMTP protocols do.

10 years agoparsedate: avoid integer overflow
Eric Lubin [Wed, 11 Dec 2013 04:01:07 +0000 (20:01 -0800)]
parsedate: avoid integer overflow

In C, signed integer overflow is undefined behavior. Thus, the compiler
is allowed to assume that it will not occur. In the check for an
overflow, the developer assumes that the signed integer of type time_t
will wrap around if it overflows. However, this behavior is undefined in
the C standard. Thus, when the compiler sees this, it simplifies t +
delta < t to delta < 0. Since delta > 0 and delta < 0 can't both be
true, the entire if statement is optimized out under certain
optimization levels. Thus, the parsedate function would return
PARSEDATE_OK with an undefined value in the time, instead of return -1 =
PARSEDATE_FAIL.

10 years agoparseconfig: warn if unquoted white spaces are detected
Daniel Stenberg [Mon, 9 Dec 2013 07:19:04 +0000 (08:19 +0100)]
parseconfig: warn if unquoted white spaces are detected

Commit 0db811b6 made some existing config files pass on unexpected
values to libcurl that made it somewhat hard to track down what was
really going on.

This code detects unquoted white spaces in the parameter when parsing a
config file as that would be one symptom and it is generally a bad
syntax anyway.

10 years agoRELEASE-NOTES: recount contributors and libcurl options
Daniel Stenberg [Mon, 9 Dec 2013 10:56:01 +0000 (11:56 +0100)]
RELEASE-NOTES: recount contributors and libcurl options

10 years agoRELEASE-NOTES: synced with c4f46e97ca6c
Daniel Stenberg [Sat, 7 Dec 2013 21:52:31 +0000 (22:52 +0100)]
RELEASE-NOTES: synced with c4f46e97ca6c

10 years agoTFTP: let tftp_multi_statemach()'s return codes through
James Dury [Sat, 7 Dec 2013 14:53:08 +0000 (15:53 +0100)]
TFTP: let tftp_multi_statemach()'s return codes through

It would otherwise always clobber the return code with new function
calls and it couldn't return timeout etc.

Bug: http://curl.haxx.se/bug/view.cgi?id=1310

10 years agodarwinssl: Fix #if 10.6.0 for SecKeychainSearch
Melissa Mears [Wed, 4 Dec 2013 00:07:32 +0000 (16:07 -0800)]
darwinssl: Fix #if 10.6.0 for SecKeychainSearch

The comment here says that SecKeychainSearch causes a deprecation
warning when used with a minimum Mac OS X SDK version of 10.7.0, which
is correct.  However, the #if guard did not match.  It was intended to
only use the code if 10.6.0 support was enabled, but it had 10.7.0
instead.  This caused a warning if the minimum was exactly 10.7.0.

10 years agocurl.h: <sys/select.h> for OpenBSD
Christian Weisgerber [Wed, 4 Dec 2013 15:45:50 +0000 (16:45 +0100)]
curl.h: <sys/select.h> for OpenBSD

curl.h should also include <sys/select.h> on OpenBSD to reliably
pull in select().  Typically, including <sys/time.h> will be enough,
but not if strict standards-compliance is requested (e.g. by defining
_XOPEN_SOURCE).

10 years agodigest: fix CURLAUTH_DIGEST_IE
Daniel Stenberg [Wed, 4 Dec 2013 22:08:17 +0000 (23:08 +0100)]
digest: fix CURLAUTH_DIGEST_IE

The URI that is passed in as part of the Authorization: header needs to
be cut off at '?' if CURLAUTH_DIGEST_IE is set. Previously the code only
did when calculating the MD5sum.

Bug: http://curl.haxx.se/bug/view.cgi?id=1308
Patched-by: Sergey Tatarincev
10 years agoCurl_is_connected: use proxy name in error message when proxy is used
Daniel Stenberg [Wed, 4 Dec 2013 21:46:49 +0000 (22:46 +0100)]
Curl_is_connected: use proxy name in error message when proxy is used

(bug introduced in 255826c4, never present in a release)

Reported-by: Dima Tisnek
Bug: http://curl.haxx.se/mail/lib-2013-12/0006.html

10 years agoimap/pop3: Post graceful cancellation consistency changes
Steve Holme [Wed, 4 Dec 2013 20:10:33 +0000 (20:10 +0000)]
imap/pop3: Post graceful cancellation consistency changes

10 years agopop3: Fix POP3_TYPE_ANY signed compilation warning
Melissa Mears [Tue, 3 Dec 2013 23:56:39 +0000 (15:56 -0800)]
pop3: Fix POP3_TYPE_ANY signed compilation warning

POP3_TYPE_ANY, or ~0, is written to pop3c->preftype in lib/pop3c.c, an
unsigned int variable.  The result of ~0 is -1, which caused a warning
due to writing a negative number to an unsigned variable.  To fix this,
make the expression ~0U so that its value is considered the unsigned
number UINT_MAX which is what SASL_AUTH_ANY does in curl_sasl.h.

10 years agotool_metalink: do not use HAVE_NSS_INITCONTEXT
Kamil Dudka [Mon, 2 Dec 2013 16:00:35 +0000 (17:00 +0100)]
tool_metalink: do not use HAVE_NSS_INITCONTEXT

... no longer provided by the configure script

10 years agonss: make sure that 'sslver' is always initialized
Kamil Dudka [Mon, 2 Dec 2013 15:09:12 +0000 (16:09 +0100)]
nss: make sure that 'sslver' is always initialized

10 years agonss: unconditionally require NSS_InitContext()
Kamil Dudka [Mon, 2 Dec 2013 13:25:07 +0000 (14:25 +0100)]
nss: unconditionally require NSS_InitContext()

... since we depend on NSS 3.14+ because of SSL_VersionRangeSet() anyway

10 years agonss: allow to use TLS > 1.0 if built against recent NSS
Kamil Dudka [Mon, 25 Nov 2013 15:25:15 +0000 (16:25 +0100)]
nss: allow to use TLS > 1.0 if built against recent NSS

Bug: http://curl.haxx.se/mail/lib-2013-11/0162.html

10 years agonss: put SSL version selection into separate fnc
Kamil Dudka [Mon, 25 Nov 2013 15:14:55 +0000 (16:14 +0100)]
nss: put SSL version selection into separate fnc

10 years agonss: use a better API for controlling SSL version
Kamil Dudka [Mon, 25 Nov 2013 15:03:52 +0000 (16:03 +0100)]
nss: use a better API for controlling SSL version

This change introduces a dependency on NSS 3.14+.

10 years agoOS400: sync wrappers and RPG binding.
Patrick Monnerat [Mon, 2 Dec 2013 13:33:51 +0000 (14:33 +0100)]
OS400: sync wrappers and RPG binding.

10 years agomulti.c: Fixed compilation warning
Steve Holme [Sun, 1 Dec 2013 20:22:44 +0000 (20:22 +0000)]
multi.c: Fixed compilation warning

warning: declaration of 'pipe' shadows a global declaration

10 years agoRELEASE-NOTES: Synced with ad3836448efbb7
Steve Holme [Sun, 1 Dec 2013 16:50:16 +0000 (16:50 +0000)]
RELEASE-NOTES: Synced with ad3836448efbb7

10 years agobase64: Corrected typo from commit f3ee587775c88a
Steve Holme [Sun, 1 Dec 2013 16:40:55 +0000 (16:40 +0000)]
base64: Corrected typo from commit f3ee587775c88a

10 years agobase64: Post extended extended validation tidy up
Steve Holme [Sun, 1 Dec 2013 13:47:11 +0000 (13:47 +0000)]
base64: Post extended extended validation tidy up

Reduced the separate processing of the last quantum to be performed in
the main decoding loop and renamed some variables for consistency.

10 years agobase64: Extended validation to look for invalid characters
Steve Holme [Sun, 1 Dec 2013 11:05:11 +0000 (11:05 +0000)]
base64: Extended validation to look for invalid characters

Extended the basic validation in commit e17c1b25bc33eb to return a
failure when invalid base64 characters are included.

10 years agobase64: Post basic validation tidy up
Steve Holme [Sat, 30 Nov 2013 19:09:09 +0000 (19:09 +0000)]
base64: Post basic validation tidy up

Due to the length checks introduced in commit e17c1b25bc33eb there is no
need to allow for extra space in the output buffer for a non-padded last
quantum.

10 years agocurl_easy_getinfo: Post CURLINFO_TLS_SESSION tidy up
Steve Holme [Sat, 30 Nov 2013 10:59:01 +0000 (10:59 +0000)]
curl_easy_getinfo: Post CURLINFO_TLS_SESSION tidy up

1) Renamed curl_tlsinfo to curl_tlssessioninfo as discussed on the
mailing list.
2) Renamed curl_ssl_backend to curl_sslbackend so it doesn't follow our
function naming convention.
3) Updated sessioninfo.c example accordingly.

10 years agoparseconfig: dash options can't specified with colon or equals
Daniel Stenberg [Wed, 6 Nov 2013 22:57:44 +0000 (23:57 +0100)]
parseconfig: dash options can't specified with colon or equals

Bug: http://curl.haxx.se/bug/view.cgi?id=1297
Reported-by: Michael Osipov
10 years agocurl.1: -G also takes --data-urlencode data
Daniel Stenberg [Fri, 29 Nov 2013 14:10:27 +0000 (15:10 +0100)]
curl.1: -G also takes --data-urlencode data

10 years agoglobbing: curl glob counter mismatch with {} list use
Daniel Stenberg [Thu, 28 Nov 2013 22:31:31 +0000 (23:31 +0100)]
globbing: curl glob counter mismatch with {} list use

The "fixed string" function wrongly bumped the "urlnum" counter which
made curl output the total number of URLs wrong when using
{one,two,three} lists in globs.

Reported-by: Michael-O
Bug: http://curl.haxx.se/bug/view.cgi?id=1305

10 years agosessioninfo.c: Added sample code for CURLINFO_TLS_SESSION
Christian Grothoff [Wed, 27 Nov 2013 22:37:09 +0000 (23:37 +0100)]
sessioninfo.c: Added sample code for CURLINFO_TLS_SESSION

Added a simple example to show how one can use CURLINFO_TLS_SESSION for
obtaining extensive TLS certificate information.

10 years agomulti.c: Fixed compilation error introduced in commit a900d45489fc14
Steve Holme [Wed, 27 Nov 2013 22:44:09 +0000 (22:44 +0000)]
multi.c: Fixed compilation error introduced in commit a900d45489fc14

Systems that define SIGPIPE_VARIABLE as a noop would not compile as
restore_pipe was defined afterwards.

10 years agocurl_easy_getopt: Handle API violation gracefully
Christian Grothoff [Wed, 27 Nov 2013 22:28:26 +0000 (23:28 +0100)]
curl_easy_getopt: Handle API violation gracefully

This fixes a NULL dereference in the case where the client asks for
CURLINFO_TLS_SESSION data after the (TLS) session has already been
destroyed (i.e. curl_easy_perform has already completed for this
handle). Instead of crashing, we now return a CURLSSLBACKEND_NONE
error.

10 years agoKNOWN_BUGS: #86: Disconnect commands may not be sent by IMAP, POP3 and SMTP
Steve Holme [Wed, 27 Nov 2013 22:33:22 +0000 (22:33 +0000)]
KNOWN_BUGS: #86: Disconnect commands may not be sent by IMAP, POP3 and SMTP

10 years agocurl_multi_cleanup: ignore SIGPIPE
Jeff King [Mon, 25 Nov 2013 14:43:21 +0000 (15:43 +0100)]
curl_multi_cleanup: ignore SIGPIPE

This is an extension to the fix in 7d80ed64e43515. We may
call Curl_disconnect() while cleaning up the multi handle,
which could lead to openssl sending packets, which could get
a SIGPIPE.

Signed-off-by: Jeff King <peff@peff.net>
10 years agosigpipe: factor out sigpipe_reset from easy.c
Jeff King [Mon, 25 Nov 2013 14:35:37 +0000 (15:35 +0100)]
sigpipe: factor out sigpipe_reset from easy.c

Commit 7d80ed64e43515 introduced some helpers to handle
sigpipe in easy.c. However, that fix was incomplete, and we
need to add more callers in other files. The first step is
making the helpers globally accessible.

Since the functions are small and should generally end up
inlined anyway, we simply define them in the header as
static functions.

Signed-off-by: Jeff King <peff@peff.net>