platform/upstream/curl.git
13 years agonss: do not ignore value of CURLOPT_SSL_VERIFYPEER
Kamil Dudka [Tue, 15 Mar 2011 13:52:26 +0000 (14:52 +0100)]
nss: do not ignore value of CURLOPT_SSL_VERIFYPEER

When NSS-powered libcurl connected to a SSL server with
CURLOPT_SSL_VERIFYPEER equal to zero, NSS remembered that the peer
certificate was accepted by libcurl and did not ask the second time when
connecting to the same server with CURLOPT_SSL_VERIFYPEER equal to one.

This patch turns off the SSL session cache for the particular SSL socket
if peer verification is disabled.  In order to avoid any performance
impact, the peer verification is completely skipped in that case, which
makes it even faster than before.

Bug: https://bugzilla.redhat.com/678580

13 years agoRemoved unused var.
Guenter Knauf [Tue, 15 Mar 2011 11:21:58 +0000 (12:21 +0100)]
Removed unused var.

13 years agoconfigure: stop using the deprecated AM_INIT_AUTOMAKE syntax
Daniel Stenberg [Tue, 15 Mar 2011 10:27:44 +0000 (11:27 +0100)]
configure: stop using the deprecated AM_INIT_AUTOMAKE syntax

13 years agoprotocol handler cleanup: SSL awareness
Daniel Stenberg [Tue, 15 Mar 2011 09:02:05 +0000 (10:02 +0100)]
protocol handler cleanup: SSL awareness

As a follow-up to commit 8831000bc0: don't assume that the SSL powered
protocol alternatives are available.

13 years agoldap: use the new protocol handler setup
Daniel Stenberg [Tue, 15 Mar 2011 08:13:11 +0000 (09:13 +0100)]
ldap: use the new protocol handler setup

Use the new flags field and stop using the old protocol defines.

13 years agoTODO-RELEASE: add and remove issues
Daniel Stenberg [Tue, 15 Mar 2011 08:04:52 +0000 (09:04 +0100)]
TODO-RELEASE: add and remove issues

Removed a fixed issue, added five new existing ones and clarified one of
the previous ones.

13 years agoprotocols: use CURLPROTO_ internally
Daniel Stenberg [Mon, 14 Mar 2011 21:52:14 +0000 (22:52 +0100)]
protocols: use CURLPROTO_ internally

The PROT_* set of internal defines for the protocols is no longer
used. We now use the same bits internally as we have defined in the
public header using the CURLPROTO_ prefix. This is for simplicity and
because the PROT_* prefix was already used duplicated internally for a
set of KRB4 values.

The PROTOPT_* defines were moved up to just below the struct definition
within which they are used.

13 years agoprotocol handler: added flags field
Daniel Stenberg [Mon, 14 Mar 2011 21:22:22 +0000 (22:22 +0100)]
protocol handler: added flags field

The protocol handler struct got a 'flags' field for special information
and characteristics of the given protocol.

This now enables us to move away central protocol information such as
CLOSEACTION and DUALCHANNEL from single defines in a central place, out
to each protocol's definition. It also made us stop abusing the protocol
field for other info than the protocol, and we could start cleaning up
other protocol-specific things by adding flags bits to set in the
handler struct.

The "protocol" field connectdata struct was removed as well and the code
now refers directly to the conn->handler->protocol field instead. To
make things work properly, the code now always store a conn->given
pointer that points out the original handler struct so that the code can
learn details from the original protocol even if conn->handler is
modified along the way - for example when switching to go over a HTTP
proxy.

13 years ago- Take new char * options into account in OS400 curl_easy_setopt_ccsid().
Patrick Monnerat [Mon, 14 Mar 2011 16:54:57 +0000 (17:54 +0100)]
- Take new char * options into account in OS400 curl_easy_setopt_ccsid().
- Keep RPG binding, STRING_* table end check and OS400 README up to date.

13 years agoFAQ: indent tables
Daniel Stenberg [Mon, 14 Mar 2011 12:31:05 +0000 (13:31 +0100)]
FAQ: indent tables

Lines that are indented with at least 5 spaces get special treatment by
the script that converts it to HTML on the site.

13 years agosslgen: define Curl_ssl_connect_nonblocking for non-SSL
Daniel Stenberg [Mon, 14 Mar 2011 10:13:12 +0000 (11:13 +0100)]
sslgen: define Curl_ssl_connect_nonblocking for non-SSL

The non-blocking connect improvement for IMAP showed that we didn't
properly define the Curl_ssl_connect_nonblocking function for non-SSL
builds.

Reported by: Tor Arntsen

13 years agoconfigure: removed wrongly claimed default paths
Daniel Stenberg [Mon, 14 Mar 2011 09:42:15 +0000 (10:42 +0100)]
configure: removed wrongly claimed default paths

Several --with-XXX options claimed the wrong default path in their help
outputs.

Reported by: Vincent Torri

13 years agomk-ca-bundle.pl: Only download if modified
Ask Bjørn Hansen [Mon, 14 Mar 2011 05:52:33 +0000 (06:52 +0100)]
mk-ca-bundle.pl: Only download if modified

Only download and convert the certdata to the ca-bundle.crt if Mozilla
changed the data

The Perl LWP module (which in a bit of a circular reference is used by
mk-ca-bundle.pl) is now indirectly using this script. I made this small
tweak to make it easier to automatically maintain the generated
ca-bundle.crt file in version control.

13 years agoSSH: add protocol lock direction
Daniel Stenberg [Sun, 13 Mar 2011 22:21:03 +0000 (23:21 +0100)]
SSH: add protocol lock direction

Some protocols have to call the underlying functions without regard to
what exact state the socket signals. For example even if the socket says
"readable", the send function might need to be called while uploading,
or vice versa. This is the case for libssh2 based protocols: SCP and
SFTP and we now introduce a define to set those protocols and we make
the multi interface code aware of this concept.

This is another fix to make test 582 run properly.

13 years agostate: add missing state to debug table
Daniel Stenberg [Sun, 13 Mar 2011 13:19:16 +0000 (14:19 +0100)]
state: add missing state to debug table

As a new state recently was added to the IMAP state machine it has to be
in the array of names as well as otherwise libcurl crashes when a debug
version runs...

13 years agotest 582: enabled again
Daniel Stenberg [Sun, 13 Mar 2011 13:11:48 +0000 (14:11 +0100)]
test 582: enabled again

Commit ca37692bf43b5ef should now hopefully make it run

13 years agossh_statemach_act: set cselect for sftp upload
Daniel Stenberg [Sun, 13 Mar 2011 13:10:27 +0000 (14:10 +0100)]
ssh_statemach_act: set cselect for sftp upload

For uploads we want to use the _sending_ function even when the socket
turns out readable as the underlying libssh2 sftp send function will
deal with both accordingly. This is what the cselect_bits magic is for.

Fixes test 582.

13 years agoRELEASE-NOTES: synced with e649a7baae2
Daniel Stenberg [Sun, 13 Mar 2011 00:06:23 +0000 (01:06 +0100)]
RELEASE-NOTES: synced with e649a7baae2

13 years agoRevert "test582: enabled"
Daniel Stenberg [Sat, 12 Mar 2011 23:55:27 +0000 (00:55 +0100)]
Revert "test582: enabled"

This reverts commit b8478187406cf625c9d0f10b45a082221130cc92.

13 years agoMerge branch 'imap' of https://github.com/bnoordhuis/curl into bnoordhuis-imap
Daniel Stenberg [Sat, 12 Mar 2011 23:36:38 +0000 (00:36 +0100)]
Merge branch 'imap' of https://github.com/bnoordhuis/curl into bnoordhuis-imap

13 years agoTODO-RELEASE: fixed four isues
Daniel Stenberg [Sat, 12 Mar 2011 23:28:31 +0000 (00:28 +0100)]
TODO-RELEASE: fixed four isues

These issues are now addressed:

276 - Karl M's vc makefile patch
277 - The "Stall when uploading to sftp using multi interface"  bug
279 - curl_multi_remove_handle() crashes
280 - Marcus Sundberg's gss patch

13 years agoVC: add missing file
Karl M [Sat, 12 Mar 2011 23:23:04 +0000 (00:23 +0100)]
VC: add missing file

http_negotiate_sspi.c was added to the source tree recently

13 years agoGSS: handle reuse fix
Marcus Sundberg [Sat, 12 Mar 2011 23:21:07 +0000 (00:21 +0100)]
GSS: handle reuse fix

Make GSS authentication work when a curl handle is reused for multiple
authenticated requests, by always setting negdata->state in
output_auth_headers().

Signed-off-by: Marcus Sundberg <marcus.sundberg@aptilo.com>
13 years agotest583: verify early SSH multi remove handle
Daniel Stenberg [Sat, 12 Mar 2011 23:18:04 +0000 (00:18 +0100)]
test583: verify early SSH multi remove handle

This test case is meant to verify that the logic in commit
60172a0446bbe3f8b actually works. This test failed for me before that
change and it works after it.

13 years agoSFTP: gracefully handle shutdown early
Daniel Stenberg [Sat, 12 Mar 2011 23:15:59 +0000 (00:15 +0100)]
SFTP: gracefully handle shutdown early

When using the multi interface and a handle using SFTP was removed very
early on, we would get a segfault due to the code assumed data was there
that hadn't yet been setup.

Bug: http://curl.haxx.se/mail/lib-2011-03/0066.html
Reported by: Saqib Ali

13 years agoCURL_CHECK_FUNC_RECVFROM: android/bionic fix
Manuel Massing [Sat, 12 Mar 2011 22:38:10 +0000 (23:38 +0100)]
CURL_CHECK_FUNC_RECVFROM: android/bionic fix

recvfrom in bionic (the android libc) deviates from POSIX and uses a
const in the 5th argument ("const struct sockaddr *") so the check now
tests for that as well.

13 years agotest582: enabled
Daniel Stenberg [Sat, 12 Mar 2011 22:10:58 +0000 (23:10 +0100)]
test582: enabled

13 years agoPROT_CLOSEACTION: added SFTP and SCP
Daniel Stenberg [Sat, 12 Mar 2011 22:08:10 +0000 (23:08 +0100)]
PROT_CLOSEACTION: added SFTP and SCP

Both SFTP and SCP are protocols that need to shut down stuff properly
when the connection is about to get torned down. The primary effect of
not doing this shows up as memory leaks (when using SCP or SFTP with the
multi interface).

This is one of the problems detected by test 582.

13 years agoreadwrite_upload: stop upload at file size
Daniel Stenberg [Sat, 12 Mar 2011 22:05:11 +0000 (23:05 +0100)]
readwrite_upload: stop upload at file size

As we know how much to send, we can and should stop once we've sent that
much data as it avoids having to rely on other mechanisms to detect the
end.

This is one of the problems detected by test 582.

Reported by: Henry Ludemann <misc@hl.id.au>

13 years agosftp upload: expire to advance state machine
Daniel Stenberg [Sat, 12 Mar 2011 22:02:04 +0000 (23:02 +0100)]
sftp upload: expire to advance state machine

When using the multi_socket API to do SFTP upload, it is important that
we set a quick expire when leaving the SSH_SFTP_UPLOAD_INIT state as
there's nothing happening on the socket so there's no read or write to
wait for, but the next libssh2 API function needs to be called to get
the ball rolling.

This is one of the problems detected by test 582.

Reported by: Henry Ludemann <misc@hl.id.au>

13 years agotest582: improved info messages
Daniel Stenberg [Sat, 12 Mar 2011 22:01:16 +0000 (23:01 +0100)]
test582: improved info messages

13 years agosource header: added to more files
Daniel Stenberg [Fri, 11 Mar 2011 23:14:32 +0000 (00:14 +0100)]
source header: added to more files

13 years agosources: update source headers
Daniel Stenberg [Thu, 10 Mar 2011 10:48:02 +0000 (11:48 +0100)]
sources: update source headers

All C and H files now (should) feature the proper project curl source
code header, which includes basic info, a copyright statement and some
basic disclaimers.

13 years agoTODO-RELEASE: add 10 pending issues
Daniel Stenberg [Thu, 10 Mar 2011 10:47:40 +0000 (11:47 +0100)]
TODO-RELEASE: add 10 pending issues

13 years agoTODO-RELEASE: fix the IPv6-working probing
Daniel Stenberg [Thu, 10 Mar 2011 10:41:59 +0000 (11:41 +0100)]
TODO-RELEASE: fix the IPv6-working probing

13 years agotests: phase out haxx.se
Daniel Stenberg [Wed, 9 Mar 2011 22:04:38 +0000 (23:04 +0100)]
tests: phase out haxx.se

Instead of using haxx.se as a fixed magic host name in lots of tests,
this is a first step to move toward the generic example.com host
instead.

13 years agotest523: avoid using haxx.se
Daniel Stenberg [Wed, 9 Mar 2011 13:10:44 +0000 (14:10 +0100)]
test523: avoid using haxx.se

... since search engines find what they think is a URL in this, they
hammer www.haxx.se on this port!

13 years agoconfigure: update the copyright year in the output
Daniel Stenberg [Wed, 9 Mar 2011 07:49:40 +0000 (08:49 +0100)]
configure: update the copyright year in the output

13 years agoForce setopt constants written by --libcurl to be long
Dan Fandrich [Wed, 9 Mar 2011 22:02:42 +0000 (14:02 -0800)]
Force setopt constants written by --libcurl to be long

13 years agocyassl: fix compiler warnings
Daniel Stenberg [Tue, 8 Mar 2011 13:09:20 +0000 (14:09 +0100)]
cyassl: fix compiler warnings

13 years agoSSL: (part 2) Added CyaSSL to SSL abstraction layer
Todd A Ouska [Tue, 8 Mar 2011 12:54:58 +0000 (13:54 +0100)]
SSL: (part 2) Added CyaSSL to SSL abstraction layer

This is the modified existing files commit.

13 years agoSSL: Added CyaSSL to SSL abstraction layer
Todd A Ouska [Tue, 1 Mar 2011 02:02:47 +0000 (18:02 -0800)]
SSL: Added CyaSSL to SSL abstraction layer

CyaSSL (available from git@github.com:cyassl/cyassl.git) has been
added to the SSL abstraction layer.

To test:
1) git CyaSSL sources
2) autoreconf -i
3) ./configure --disable-static
4) make
5) sudo make install
6) autoreconf -i
7) git curl sources (and this patch)
8) ./configure --disable-shared --with-cyassl --without-ssl --enable-debug
9) make
10) normal testing

Please send questions or comments to todd@yassl.com .

13 years agocurl.1: clarify -E
Daniel Stenberg [Tue, 8 Mar 2011 10:43:42 +0000 (11:43 +0100)]
curl.1: clarify -E

Stress that it is for client certificates and then mention that it also
works for all other SSL-based protocols apart from HTTPS and
FTPS. Namely POP3S, IMAPS and SMTPS for now.

13 years agoFAQ: Protocol xxx not supported or disabled in libcurl
Daniel Stenberg [Tue, 8 Mar 2011 10:15:59 +0000 (11:15 +0100)]
FAQ: Protocol xxx not supported or disabled in libcurl

13 years agolib582: used for test 582
Daniel Stenberg [Tue, 8 Mar 2011 07:21:03 +0000 (08:21 +0100)]
lib582: used for test 582

Accidentally not included in commit 0e74e1d8d83

13 years agoFixed libcurl to honour the --disable-ldaps configure option
Dan Fandrich [Tue, 8 Mar 2011 01:45:33 +0000 (17:45 -0800)]
Fixed libcurl to honour the --disable-ldaps configure option

13 years agosftp-multi: test 582 added
Henry Ludemann [Mon, 7 Mar 2011 23:19:49 +0000 (00:19 +0100)]
sftp-multi: test 582 added

Add test 582 for uploading a file using sftp and the multi interface.

(Patch and test slightly tweaked by Daniel Stenberg)

Initially marked as disabled until it is fixed in the source.

13 years agoFAQ: How to SFTP from my user's home directory?
Daniel Stenberg [Mon, 7 Mar 2011 21:27:26 +0000 (22:27 +0100)]
FAQ: How to SFTP from my user's home directory?

13 years agocpp: correct #endif placement
Daniel Stenberg [Sun, 6 Mar 2011 22:00:28 +0000 (23:00 +0100)]
cpp: correct #endif placement

The end-of-file #endif in rawstr.h was not correcly positioned after all
prototypes.

Reported by: Boris
Bug: http://curl.haxx.se/bug/view.cgi?id=3195205

13 years agoMoved test 577 into the unit test framework as test 1307
Dan Fandrich [Fri, 4 Mar 2011 23:56:40 +0000 (15:56 -0800)]
Moved test 577 into the unit test framework as test 1307

13 years agoAdded unit test 1306 so tests 558 & 559 are now fully replaced
Dan Fandrich [Fri, 4 Mar 2011 23:13:12 +0000 (15:13 -0800)]
Added unit test 1306 so tests 558 & 559 are now fully replaced

13 years agoThe unit test argument is allowed to be used
Dan Fandrich [Fri, 4 Mar 2011 23:11:21 +0000 (15:11 -0800)]
The unit test argument is allowed to be used

13 years agoConverted tests 558 & 559 to use the unit test framework as 1305
Dan Fandrich [Fri, 4 Mar 2011 22:32:58 +0000 (14:32 -0800)]
Converted tests 558 & 559 to use the unit test framework as 1305

Test 558 was just a subset of 559 which is something that can be
easily added later.

13 years agoFixed test 1300 to pass the torture test
Dan Fandrich [Fri, 4 Mar 2011 21:54:04 +0000 (13:54 -0800)]
Fixed test 1300 to pass the torture test

13 years agoAdded abort_* unit test macros
Dan Fandrich [Fri, 4 Mar 2011 21:53:15 +0000 (13:53 -0800)]
Added abort_* unit test macros

These are for when a test failure makes it impossible to continue
running further tests.

13 years agotransfer: avoid insane conversion of time_t
Stefan Krause [Wed, 23 Feb 2011 18:58:43 +0000 (19:58 +0100)]
transfer: avoid insane conversion of time_t

13 years agossh_connect: treat libssh2 return code better
Daniel Stenberg [Sat, 26 Feb 2011 09:59:03 +0000 (10:59 +0100)]
ssh_connect: treat libssh2 return code better

libssh2_knownhost_readfile() returns a negative value on error or
otherwise number of parsed known hosts - this was previously not
documented correctly in the libssh2 man page for the function.

Bug: http://curl.haxx.se/mail/lib-2011-02/0327.html
Reported by: murat

13 years agohttp: removed wrong unused comment.
Julien Chaffraix [Sat, 26 Feb 2011 04:37:54 +0000 (20:37 -0800)]
http: removed wrong unused comment.

|premature| is used in Curl_http_done.

13 years agohttp: removed code duplication for stubbed https_getsock function.
Julien Chaffraix [Sat, 26 Feb 2011 04:35:16 +0000 (20:35 -0800)]
http: removed code duplication for stubbed https_getsock function.

13 years agoRELEASE-NOTES: synced with 2345c1dd661c
Daniel Stenberg [Wed, 23 Feb 2011 11:59:06 +0000 (12:59 +0100)]
RELEASE-NOTES: synced with 2345c1dd661c

13 years agoruntests.pl/stopserver: space separate pids
Daniel Stenberg [Tue, 22 Feb 2011 12:28:27 +0000 (13:28 +0100)]
runtests.pl/stopserver: space separate pids

The stopserver function would append pids to kill and could append them
without separating them with space properly. The result would be a very
large number that by (some implementations of) kill would be interpreted
as a negative number and that process group would be wiped...

Bug: http://curl.haxx.se/bug/view.cgi?id=3188836
Reported by: Greg Pratt

13 years agonss: do not ignore failure of SSL handshake
Kamil Dudka [Tue, 22 Feb 2011 12:13:53 +0000 (13:13 +0100)]
nss: do not ignore failure of SSL handshake

Flaw introduced in fc77790 and present in curl-7.21.4.
Bug: https://bugzilla.redhat.com/669702#c16

13 years agoCURLOPT_SSH_KEYFUNCTION: requires *SSH_KNOWNHOSTS
Daniel Stenberg [Mon, 21 Feb 2011 12:51:26 +0000 (13:51 +0100)]
CURLOPT_SSH_KEYFUNCTION: requires *SSH_KNOWNHOSTS

Extend the docs to clarify that CURLOPT_SSH_KEYFUNCTION is only called
if the known hosts option is also correctly set!

13 years agocurl_easy_setopt.3: Removed wrong reference to CURLOPT_USERPASSWORD.
Julien Chaffraix [Mon, 21 Feb 2011 05:13:19 +0000 (21:13 -0800)]
curl_easy_setopt.3: Removed wrong reference to CURLOPT_USERPASSWORD.

CURLOPT_HTTPAUTH was mentioning CURLOPT_USERPASSWORD instead of
CURLOPT_PASSWORD.

Reported by: Mike Henshaw

13 years agonetrc: Removed _NETRC_DEBUG code.
Julien Chaffraix [Mon, 21 Feb 2011 05:10:45 +0000 (21:10 -0800)]
netrc: Removed _NETRC_DEBUG code.

This is not needed anymore as we have unit testing running on it.

13 years agotests: Cleaned up netrc testing.
Julien Chaffraix [Mon, 21 Feb 2011 05:10:36 +0000 (21:10 -0800)]
tests: Cleaned up netrc testing.

Removed the "netrc_debug" keyword replaced with --netrc-file additions.
Removed the debug code from Curl_parsenetrc as it is superseeded by
--netrc-file.

13 years agocurl: Added --netrc-file.
Julien Chaffraix [Mon, 21 Feb 2011 05:10:03 +0000 (21:10 -0800)]
curl: Added --netrc-file.

This enables people to specify a path to the netrc file to use.
The new option override --netrc if both are present. However it
does follow --netrc-optional if specified.

13 years agoIMAP in multi mode: use Curl_ssl_connect_nonblocking() when upgrading the connection...
Ben Noordhuis [Tue, 15 Feb 2011 23:56:46 +0000 (00:56 +0100)]
IMAP in multi mode: use Curl_ssl_connect_nonblocking() when upgrading the connection to TLS/SSL.

13 years agoIMAP in multi mode: use Curl_ssl_connect_nonblocking() when connecting.
Ben Noordhuis [Mon, 14 Feb 2011 18:41:42 +0000 (19:41 +0100)]
IMAP in multi mode: use Curl_ssl_connect_nonblocking() when connecting.

13 years agomulti: close connection on timeout
Mike Crowe [Fri, 18 Feb 2011 22:19:14 +0000 (23:19 +0100)]
multi: close connection on timeout

After a request times out, the connection wasn't properly closed and
prevented to get re-used, so subsequent transfers could still mistakenly
get to use the previously aborted connection.

13 years agomulti: better failed connect treatment
Daniel Stenberg [Thu, 17 Feb 2011 22:51:43 +0000 (23:51 +0100)]
multi: better failed connect treatment

When failing to connect the protocol during the CURLM_STATE_PROTOCONNECT
state, Curl_done() has to be called with the premature flag set TRUE as
for the pingpong protocols this can be important.

When Curl_done() is called with premature == TRUE, it needs to call
Curl_disconnect() with its 'dead_connection' argument set to TRUE as
well so that any protocol handler's disconnect function won't attempt to
use the (control) connection for anything.

This problem caused the pingpong protocols to fail to disconnect when
STARTTLS failed.

Reported by: Alona Rossen
Bug: http://curl.haxx.se/mail/lib-2011-02/0195.html

13 years agoPolarSSL: Return 0 on receiving TLS CLOSE_NOTIFY alert
Hoi-Ho Chan [Fri, 18 Feb 2011 05:46:59 +0000 (21:46 -0800)]
PolarSSL: Return 0 on receiving TLS CLOSE_NOTIFY alert

Signed-off-by: Hoi-Ho Chan <hoiho.chan@gmail.com>
13 years agosymbols-in-versions: sorted
Daniel Stenberg [Thu, 17 Feb 2011 22:22:11 +0000 (23:22 +0100)]
symbols-in-versions: sorted

I forgot to sort it when I added the CURL_SOCKOPT_* symbols

13 years agoTODO-RELEASE: refresh
Daniel Stenberg [Thu, 17 Feb 2011 22:03:34 +0000 (23:03 +0100)]
TODO-RELEASE: refresh

13 years agoSOCKOPTFUNCTION: documented new return codes
Daniel Stenberg [Thu, 17 Feb 2011 21:34:18 +0000 (22:34 +0100)]
SOCKOPTFUNCTION: documented new return codes

13 years agoSOCKOPTFUNCTION: callback can say already-connected
Daniel Stenberg [Wed, 9 Feb 2011 14:46:41 +0000 (15:46 +0100)]
SOCKOPTFUNCTION: callback can say already-connected

Introducing a few CURL_SOCKOPT* defines for conveniance. The new
CURL_SOCKOPT_ALREADY_CONNECTED signals to libcurl that the socket is to
be treated as already connected and thus it will skip the connect()
call.

13 years agonss: avoid memory leak on SSL connection failure
Kamil Dudka [Thu, 17 Feb 2011 16:37:24 +0000 (17:37 +0100)]
nss: avoid memory leak on SSL connection failure

13 years agoRELEASE-NOTES: fresh start towards 7.21.5
Daniel Stenberg [Thu, 17 Feb 2011 13:00:25 +0000 (14:00 +0100)]
RELEASE-NOTES: fresh start towards 7.21.5

13 years agocurlver.h: bump to 7.21.5
Daniel Stenberg [Thu, 17 Feb 2011 12:59:27 +0000 (13:59 +0100)]
curlver.h: bump to 7.21.5

13 years agoTHANKS: add contributors from 7.21.4
Daniel Stenberg [Thu, 17 Feb 2011 12:58:24 +0000 (13:58 +0100)]
THANKS: add contributors from 7.21.4

13 years agoSet -fpcc-struct-return only for gcc compiler.
Guenter Knauf [Thu, 17 Feb 2011 10:46:41 +0000 (11:46 +0100)]
Set -fpcc-struct-return only for gcc compiler.

13 years agoRELEASE-NOTES: credits since 7.21.3
Daniel Stenberg [Thu, 17 Feb 2011 08:40:53 +0000 (09:40 +0100)]
RELEASE-NOTES: credits since 7.21.3

I went through all the names mentioned as authors and in commit messages
since 7.21.3, and this list inserted now is sorted on first name.

13 years agonss_load_key: fix unused variable warning
Daniel Stenberg [Wed, 16 Feb 2011 18:33:22 +0000 (19:33 +0100)]
nss_load_key: fix unused variable warning

13 years agogmtime: remove define
Daniel Stenberg [Mon, 14 Feb 2011 12:42:01 +0000 (13:42 +0100)]
gmtime: remove define

It turns out some systems rely on the gmtime or gmtime_r to be defined
already in the system headers and thus my "precaution" redefining of
them only caused trouble. They are now removed.

13 years agoAdded -m32 to CFLAGS to compile with x86_64 gcc.
Guenter Knauf [Sun, 13 Feb 2011 13:31:22 +0000 (14:31 +0100)]
Added -m32 to CFLAGS to compile with x86_64 gcc.

13 years agoUpdated OpenSSL version, added links to docu.
Guenter Knauf [Sun, 13 Feb 2011 11:13:21 +0000 (12:13 +0100)]
Updated OpenSSL version, added links to docu.

13 years agoRELEASE-NOTES: synced with 3bb1291fbd4
Daniel Stenberg [Thu, 10 Feb 2011 21:33:12 +0000 (22:33 +0100)]
RELEASE-NOTES: synced with 3bb1291fbd4

13 years ago--keepalive-time: warn if not supported properly
Daniel Stenberg [Thu, 10 Feb 2011 21:21:57 +0000 (22:21 +0100)]
--keepalive-time: warn if not supported properly

Since the feature requires support for TCP_KEEPIDLE and TCP_KEEPINTVL to
function as documented, it now warns if that support is missing when the
option is used.

13 years agoCall ERR_peek_error instead of ERR_peek_last_error
Dan Fandrich [Thu, 10 Feb 2011 20:29:34 +0000 (12:29 -0800)]
Call ERR_peek_error instead of ERR_peek_last_error

The latter isn't available in older OpenSSL versions, and is
less useful since it returns the most recent error instead of
the first one encountered.

13 years agonetrc: Enable setting up the filename in unit tests.
Julien Chaffraix [Tue, 8 Feb 2011 16:39:44 +0000 (08:39 -0800)]
netrc: Enable setting up the filename in unit tests.

Unset the environment variable so that we can specify different
filenames in the unit test.

13 years agotest1304: Added some unit tests for Curl_parsenetrc.
Julien Chaffraix [Tue, 8 Feb 2011 06:12:37 +0000 (22:12 -0800)]
test1304: Added some unit tests for Curl_parsenetrc.

Moved some definitons into the header file so that we can reuse them.

13 years agoCURLE_TLSAUTH_FAILED: removed
Quinn Slack [Wed, 9 Feb 2011 22:34:30 +0000 (23:34 +0100)]
CURLE_TLSAUTH_FAILED: removed

On second thought, I think CURLE_TLSAUTH_FAILED should be eliminated. It
was only being raised when an internal error occurred while allocating
or setting the GnuTLS SRP client credentials struct. For TLS
authentication failures, the general CURLE_SSL_CONNECT_ERROR seems
appropriate; its error string already includes "passwords" as a possible
cause. Having a separate TLS auth error code might also cause people to
think that a TLS auth failure means the wrong username or password was
entered, when it could also be a sign of a man-in-the-middle attack.

13 years agoTLS-SRP: new options documented
Quinn Slack [Wed, 9 Feb 2011 22:33:06 +0000 (23:33 +0100)]
TLS-SRP: new options documented

13 years agoCURLOPT_SOCKOPTFUNCTION: return proper error code
Daniel Stenberg [Wed, 9 Feb 2011 14:36:36 +0000 (15:36 +0100)]
CURLOPT_SOCKOPTFUNCTION: return proper error code

When the callback returns an error, this function must make sure to return
CURLE_ABORTED_BY_CALLBACK properly and not CURLE_OK as before to allow the
callback to properly abort the operation.

13 years agocurl.1: typo in -v description
Daniel Stenberg [Tue, 8 Feb 2011 21:39:04 +0000 (22:39 +0100)]
curl.1: typo in -v description

Reported by: Ian D Allen
Bug: https://bugs.launchpad.net/ubuntu/+source/curl/+bug/714895

Forwarded to us by:

Reported by: Andreas Olsson
Bug: http://curl.haxx.se/bug/view.cgi?id=3175422

13 years agonetrc: Removed dead code.
Julien Chaffraix [Fri, 28 Jan 2011 16:34:17 +0000 (08:34 -0800)]
netrc: Removed dead code.

The main has not been updated from some time and is out of sync with
the code. The code is now tested by several test cases so no need for
a seperate code path.

13 years agonetrc: Tightened up the type checks.
Julien Chaffraix [Fri, 28 Jan 2011 16:20:37 +0000 (08:20 -0800)]
netrc: Tightened up the type checks.

The state should not be anonymous so that we can check if the values
are fine. Added 2 unreachables states to the switch as a result of this
change.

13 years agoimap: Fixed typo in a comment.
Julien Chaffraix [Thu, 27 Jan 2011 15:48:19 +0000 (07:48 -0800)]
imap: Fixed typo in a comment.

13 years agoCurl_gmtime: avoid future mistakes
Daniel Stenberg [Mon, 7 Feb 2011 14:09:24 +0000 (15:09 +0100)]
Curl_gmtime: avoid future mistakes

Document Curl_gmtime() and define away the old functions so that they
won't be used internally again by mistake.

13 years agoCurl_gmtime: added a portable gmtime
Daniel Stenberg [Mon, 7 Feb 2011 14:00:48 +0000 (15:00 +0100)]
Curl_gmtime: added a portable gmtime

Instead of polluting many places with #ifdefs, we create a single place
for this function, and also check return code properly so that a NULL
pointer returned won't cause problems.