git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 3/4] imap-send: remove two string length checks

From
Beat Bolli <dev+git@drbeat.li>
Date
Mar 11, 2026, 21:49 UTC
Message-ID
<a64f450b-1044-421f-86ca-aa523608911b@drbeat.li>
In-Reply-To
<abFw7FMAwHPPWOBT@ugly.lan>
Hi Oswald
On 11.03.2026 14:41, Oswald Buddenhagen wrote:
Show 9 quoted lines
> On Wed, Mar 11, 2026 at 01:11:06PM +0100, Beat Bolli wrote:
>> At this point, these two checks verify that the ASN1_STRINGs are
>> internally consistent. This may have been ok when the fields were
>> accessed directly, but now that the API is used, is unnecessary.
>>
> that argumentation makes no sense.
> the purpose of this check is to ensure that there are no embedded nulls, 
> which the matcher would be unable to deal with, which may be a security 
> hole.
Thanks for the clarification; this was the piece that I was missing.
I'll send a v2 shortly that removes this change.
Cheers, Beat
Previous: Oswald BuddenhagenNext: Junio C Hamano
Message 4 of 14 in “imap-send: modernize the OpenSSL API”
  1. 0/4 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  2. 3/4 imap-send: remove two string length checksBeat Bolli, Mar 11, 2026
  3. Oswald BuddenhagenMar 11, 2026
  4. Beat BolliMar 11, 2026
  5. Junio C HamanoMar 11, 2026
  6. Beat BolliMar 11, 2026
  7. 4/4 imap-send: refactor function host_matches()Beat Bolli, Mar 11, 2026
  8. 2/4 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026
  9. 1/4 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  10. 1/3 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  11. 0/3 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  12. Junio C HamanoMar 12, 2026
  13. 3/3 imap-send: move common code into function host_matches()Beat Bolli, Mar 11, 2026
  14. 2/3 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.