From: Beat Bolli Date: Wed, 11 Mar 2026 12:11:07 GMT Subject: [PATCH 4/4] imap-send: refactor function host_matches() Message-ID: <20260311121107.1122387-5-dev+git@drbeat.li> In-Reply-To: <20260311121107.1122387-1-dev+git@drbeat.li> Move the ASN1_STRING access and the associated cast into host_matches() to simplify both callers. Signed-off-by: Beat Bolli --- imap-send.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/imap-send.c b/imap-send.c index 2bb0003f08..789055d7fd 100644 --- a/imap-send.c +++ b/imap-send.c @@ -219,8 +219,9 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED, #else -static int host_matches(const char *host, const char *pattern) +static int host_matches(const char *host, const ASN1_STRING *asn1_str) { + const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str); if (pattern[0] == '*' && pattern[1] == '.') { pattern += 2; if (!(host = strchr(host, '.'))) @@ -252,8 +253,7 @@ static int verify_hostname(X509 *cert, const char *hostname) GENERAL_NAME *subj_alt_name = sk_GENERAL_NAME_value(subj_alt_names, i); ASN1_STRING *subj_alt_str = GENERAL_NAME_get0_value(subj_alt_name, &ntype); - if (ntype == GEN_DNS && - host_matches(hostname, (const char *)ASN1_STRING_get0_data(subj_alt_str))) + if (ntype == GEN_DNS && host_matches(hostname, subj_alt_str)) found = 1; } sk_GENERAL_NAME_pop_free(subj_alt_names, GENERAL_NAME_free); @@ -268,7 +268,7 @@ static int verify_hostname(X509 *cert, const char *hostname) (cname_entry = X509_NAME_get_entry(subj, i)) == NULL || (cname = X509_NAME_ENTRY_get_data(cname_entry)) == NULL) return error("cannot get certificate common name"); - if (host_matches(hostname, (const char *)ASN1_STRING_get0_data(cname))) + if (host_matches(hostname, cname)) return 0; return error("certificate owner '%s' does not match hostname '%s'", ASN1_STRING_get0_data(cname), hostname); -- 2.51.0