e95d20dcb8
This CL removes the last of the EVP_CIPHER codepath in ssl/. The dead code is intentionally not pruned for ease of review, except in DTLS-only code where adding new logic to support both, only to remove half, would be cumbersome. Fixes made: - dtls1_retransmit_state is taught to retain aead_write_ctx rather than enc_write_ctx. - d1_pkt.c reserves space for the variable-length nonce when echoed into the packet. - dtls1_do_write sizes the MTU based on EVP_AEAD max overhead. - tls1_change_cipher_state_cipher should not free AEAD write contexts in DTLS. This matches the (rather confused) ownership for the EVP_CIPHER contexts. I've added a TODO to resolve this craziness. A follow-up CL will remove all the resultant dead code. Change-Id: I644557f4db53bbfb182950823ab96d5e4c908866 Reviewed-on: https://boringssl-review.googlesource.com/2699 Reviewed-by: Adam Langley <agl@google.com> |
||
---|---|---|
.. | ||
pqueue | ||
test | ||
CMakeLists.txt | ||
d1_both.c | ||
d1_clnt.c | ||
d1_lib.c | ||
d1_meth.c | ||
d1_pkt.c | ||
d1_srtp.c | ||
d1_srvr.c | ||
s3_both.c | ||
s3_cbc.c | ||
s3_clnt.c | ||
s3_enc.c | ||
s3_lib.c | ||
s3_meth.c | ||
s3_pkt.c | ||
s3_srvr.c | ||
ssl_algs.c | ||
ssl_asn1.c | ||
ssl_cert.c | ||
ssl_ciph.c | ||
ssl_error.c | ||
ssl_lib.c | ||
ssl_locl.h | ||
ssl_rsa.c | ||
ssl_sess.c | ||
ssl_stat.c | ||
ssl_test.c | ||
ssl_txt.c | ||
t1_enc.c | ||
t1_lib.c | ||
t1_reneg.c |