git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 4/4] imap-send: refactor function host_matches()

From
Beat Bolli <dev+git@drbeat.li>
Date
Mar 11, 2026, 12:11 UTC
Message-ID
<20260311121107.1122387-5-dev+git@drbeat.li>
In-Reply-To
<20260311121107.1122387-1-dev+git@drbeat.li>

Move the ASN1_STRING access and the associated cast into host_matches() to simplify both callers.

Signed-off-by: Beat Bolli <dev+git@drbeat.li>
---
 imap-send.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/imap-send.c b/imap-send.c
index 2bb0003f08..789055d7fd 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -219,8 +219,9 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED,
 
 #else
 
-static int host_matches(const char *host, const char *pattern)
+static int host_matches(const char *host, const ASN1_STRING *asn1_str)
 {
+	const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str);
 	if (pattern[0] == '*' && pattern[1] == '.') {
 		pattern += 2;
 		if (!(host = strchr(host, '.')))
@@ -252,8 +253,7 @@ static int verify_hostname(X509 *cert, const char *hostname)
 			GENERAL_NAME *subj_alt_name = sk_GENERAL_NAME_value(subj_alt_names, i);
 			ASN1_STRING *subj_alt_str = GENERAL_NAME_get0_value(subj_alt_name, &ntype);
 
-			if (ntype == GEN_DNS &&
-			    host_matches(hostname, (const char *)ASN1_STRING_get0_data(subj_alt_str)))
+			if (ntype == GEN_DNS && host_matches(hostname, subj_alt_str))
 				found = 1;
 		}
 		sk_GENERAL_NAME_pop_free(subj_alt_names, GENERAL_NAME_free);
@@ -268,7 +268,7 @@ static int verify_hostname(X509 *cert, const char *hostname)
 	    (cname_entry = X509_NAME_get_entry(subj, i)) == NULL ||
 	    (cname = X509_NAME_ENTRY_get_data(cname_entry)) == NULL)
 		return error("cannot get certificate common name");
-	if (host_matches(hostname, (const char *)ASN1_STRING_get0_data(cname)))
+	if (host_matches(hostname, cname))
 		return 0;
 	return error("certificate owner '%s' does not match hostname '%s'",
 		     ASN1_STRING_get0_data(cname), hostname);
-- 
2.51.0
Previous: Beat BolliNext: Beat Bolli
Message 7 of 14 in “imap-send: modernize the OpenSSL API”
  1. 0/4 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  2. 3/4 imap-send: remove two string length checksBeat Bolli, Mar 11, 2026
  3. Oswald BuddenhagenMar 11, 2026
  4. Beat BolliMar 11, 2026
  5. Junio C HamanoMar 11, 2026
  6. Beat BolliMar 11, 2026
  7. 4/4 imap-send: refactor function host_matches()Beat Bolli, Mar 11, 2026
  8. 2/4 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026
  9. 1/4 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  10. 1/3 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  11. 0/3 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  12. Junio C HamanoMar 12, 2026
  13. 3/3 imap-send: move common code into function host_matches()Beat Bolli, Mar 11, 2026
  14. 2/3 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.