opnsense-src/ssl/record
Pierre Pronchery b84c4564ef openssl: Vendor import of OpenSSL-3.0.9
Summary:

Release notes can be found at
https://www.openssl.org/news/openssl-3.0-notes.html .

Obtained from:  https://www.openssl.org/source/openssl-3.0.9.tar.gz

Test Plan:
```
$ git status
On branch vendor/openssl-3.0
Your branch is up to date with 'origin/vendor/openssl-3.0'.

nothing to commit, working tree clean
$ (cd ..; fetch http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz.asc)
openssl-3.0.9.tar.gz                                    14 MB   74 MBps    01s
openssl-3.0.9.tar.gz.asc                               833  B   10 MBps    00s
$ set | egrep '(XLIST|OSSLVER)='
OSSLVER=3.0.9
XLIST=FREEBSD-Xlist
$ gpg --list-keys
/home/khorben/.gnupg/pubring.kbx
--------------------------------
pub   rsa4096 2021-07-16 [SC] [expires: 2031-07-14]
      A21FAB74B0088AA361152586B8EF1A6BA9DA2D5C
uid           [ unknown] Tomáš Mráz <tm@t8m.info>
uid           [ unknown] Tomáš Mráz <tomas@arleto.cz>
uid           [ unknown] Tomáš Mráz <tomas@openssl.org>
sub   rsa4096 2021-07-16 [S] [expires: 2027-07-15]
sub   rsa4096 2021-07-16 [E] [expires: 2031-07-14]

$ gpg --verify ../openssl-${OSSLVER}.tar.gz.asc ../openssl-${OSSLVER}.tar.gz
gpg: Signature made Tue May 30 14:32:24 2023 CEST
gpg:                using RSA key DC7032662AF885E2F47F243F527466A21CA79E6D
gpg: Good signature from "Tomáš Mráz <tm@t8m.info>" [unknown]
gpg:                 aka "Tomáš Mráz <tomas@arleto.cz>" [unknown]
gpg:                 aka "Tomáš Mráz <tomas@openssl.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: A21F AB74 B008 8AA3 6115  2586 B8EF 1A6B A9DA 2D5C
     Subkey fingerprint: DC70 3266 2AF8 85E2 F47F  243F 5274 66A2 1CA7 9E6D

$ tar -x -X $XLIST -f ../openssl-${OSSLVER}.tar.gz -C ..
$ rsync --exclude FREEBSD.* --delete -avzz ../openssl-${OSSLVER}/* .
[...]
$ diff -arq ../openssl-${OSSLVER}  .
Only in .: .git
Only in .: FREEBSD-Xlist
Only in .: FREEBSD-upgrade
$ git status FREEBSD*
On branch vendor/openssl-3.0
Your branch is up to date with 'origin/vendor/openssl-3.0'.

nothing to commit, working tree clean
```
2023-06-23 09:13:27 -04:00
..
dtls1_bitmap.c openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00
README.md openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00
rec_layer_d1.c openssl: Vendor import of OpenSSL-3.0.9 2023-06-23 09:13:27 -04:00
rec_layer_s3.c openssl: Vendor import of OpenSSL-3.0.9 2023-06-23 09:13:27 -04:00
record.h openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00
record_local.h openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00
ssl3_buffer.c openssl: Vendor import of OpenSSL-3.0.9 2023-06-23 09:13:27 -04:00
ssl3_record.c openssl: Vendor import of OpenSSL-3.0.9 2023-06-23 09:13:27 -04:00
ssl3_record_tls13.c openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00
tls_pad.c openssl: Vendor import of OpenSSL-3.0.8 2023-03-06 12:41:29 -08:00

Record Layer Design

This file provides some guidance on the thinking behind the design of the record layer code to aid future maintenance.

The record layer is divided into a number of components. At the time of writing there are four: SSL3_RECORD, SSL3_BUFFER, DLTS1_BITMAP and RECORD_LAYER. Each of these components is defined by:

  1. A struct definition of the same name as the component
  2. A set of source files that define the functions for that component
  3. A set of accessor macros

All struct definitions are in record.h. The functions and macros are either defined in record.h or record_local.h dependent on whether they are intended to be private to the record layer, or whether they form part of the API to the rest of libssl.

The source files map to components as follows:

dtls1_bitmap.c                 -> DTLS1_BITMAP component
ssl3_buffer.c                  -> SSL3_BUFFER component
ssl3_record.c                  -> SSL3_RECORD component
rec_layer_s3.c, rec_layer_d1.c -> RECORD_LAYER component

The RECORD_LAYER component is a facade pattern, i.e. it provides a simplified interface to the record layer for the rest of libssl. The other 3 components are entirely private to the record layer and therefore should never be accessed directly by libssl.

Any component can directly access its own members - they are private to that component, e.g. ssl3_buffer.c can access members of the SSL3_BUFFER struct without using a macro. No component can directly access the members of another component, e.g. ssl3_buffer cannot reach inside the RECORD_LAYER component to directly access its members. Instead components use accessor macros, so if code in ssl3_buffer.c wants to access the members of the RECORD_LAYER it uses the RECORD_LAYER_* macros.

Conceptually it looks like this:

                      libssl
                         |
-------------------------|-----record.h------------------------------------
                         |
                  _______V______________
                 |                      |
                 |    RECORD_LAYER      |
                 |                      |
                 |    rec_layer_s3.c    |
                 |          ^           |
                 | _________|__________ |
                 ||                    ||
                 || DTLS1_RECORD_LAYER ||
                 ||                    ||
                 || rec_layer_d1.c     ||
                 ||____________________||
                 |______________________|
      record_local.h     ^   ^   ^
       _________________|   |   |_________________
      |                     |                     |
 _____V_________      ______V________      _______V________
|               |    |               |    |                |
| SSL3_BUFFER   |    | SSL3_RECORD   |    | DTLS1_BITMAP   |
|               |--->|               |    |                |
| ssl3_buffer.c |    | ssl3_record.c |    | dtls1_bitmap.c |
|_______________|    |_______________|    |________________|

The two RECORD_LAYER source files build on each other, i.e. the main one is rec_layer_s3.c which provides the core SSL/TLS layer. The second one is rec_layer_d1.c which builds off of the SSL/TLS code to provide DTLS specific capabilities. It uses some DTLS specific RECORD_LAYER component members which should only be accessed from rec_layer_d1.c. These are held in the DTLS1_RECORD_LAYER struct.