git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 0/3] imap-send: modernize the OpenSSL API

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 12, 2026, 00:25 UTC
Message-ID
<xmqqsea5lwqj.fsf@gitster.g>
In-Reply-To
<20260311221027.1404476-1-dev+git@drbeat.li>
Beat Bolli <dev+git@drbeat.li> writes:
> Changes vs v1:
> - keep the check for embedded NUL characters

... which amounts to this difference, which is a lot more explicit way to express what is going on. I like it.

Thanks.
diff --git a/imap-send.c b/imap-send.c
index 789055d7fd..af02c6a689 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -222,6 +222,11 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED,
 static int host_matches(const char *host, const ASN1_STRING *asn1_str)
 {
 	const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str);
+
+	/* embedded NUL characters may open a security hole */
+	if (memchr(pattern, '\0', ASN1_STRING_length(asn1_str)))
+	    return 0;
+
 	if (pattern[0] == '*' && pattern[1] == '.') {
 		pattern += 2;
 		if (!(host = strchr(host, '.')))
Previous: Beat BolliNext: Beat Bolli
Message 12 of 14 in “imap-send: modernize the OpenSSL API”
  1. 0/4 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  2. 3/4 imap-send: remove two string length checksBeat Bolli, Mar 11, 2026
  3. Oswald BuddenhagenMar 11, 2026
  4. Beat BolliMar 11, 2026
  5. Junio C HamanoMar 11, 2026
  6. Beat BolliMar 11, 2026
  7. 4/4 imap-send: refactor function host_matches()Beat Bolli, Mar 11, 2026
  8. 2/4 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026
  9. 1/4 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  10. 1/3 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  11. 0/3 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  12. Junio C HamanoMar 12, 2026
  13. 3/3 imap-send: move common code into function host_matches()Beat Bolli, Mar 11, 2026
  14. 2/3 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.