mirror of
https://github.com/curl/curl.git
synced 2026-08-25 22:53:38 +03:00
parent
1ea3060a25
commit
032ea65ff2
5 changed files with 119 additions and 123 deletions
104
docs/VERIFY.md
104
docs/VERIFY.md
|
|
@ -57,75 +57,75 @@ How do you then verify that what is in git is fine to build a product from?
|
||||||
In the curl project we verify the source code in multiple ways, and one way to
|
In the curl project we verify the source code in multiple ways, and one way to
|
||||||
gain trust is to verify and review our testing procedures.
|
gain trust is to verify and review our testing procedures.
|
||||||
|
|
||||||
- we have a consistent code style (invalid style causes errors)
|
- we have a consistent code style (invalid style causes errors)
|
||||||
|
|
||||||
- we ban and avoid a number of "sensitive" and "hard-to-use" C functions (use
|
- we ban and avoid a number of "sensitive" and "hard-to-use" C functions (use
|
||||||
of such functions causes errors)
|
of such functions causes errors)
|
||||||
|
|
||||||
- we have a ceiling for complexity in functions to keep them easy to follow,
|
- we have a ceiling for complexity in functions to keep them easy to follow,
|
||||||
read and understand (failing to do so causes errors)
|
read and understand (failing to do so causes errors)
|
||||||
|
|
||||||
- we review all pull requests before merging, both with humans and with bots. We
|
- we review all pull requests before merging, both with humans and with bots. We
|
||||||
link back commits to their origin pull requests in commit messages.
|
link back commits to their origin pull requests in commit messages.
|
||||||
|
|
||||||
- we ban use of "binary blobs" in git to not provide means for malicious
|
- we ban use of "binary blobs" in git to not provide means for malicious
|
||||||
actors to bundle encrypted payloads (trying to include a blob causes errors)
|
actors to bundle encrypted payloads (trying to include a blob causes errors)
|
||||||
|
|
||||||
- we actively avoid base64 encoded chunks as they too could function as ways
|
- we actively avoid base64 encoded chunks as they too could function as ways
|
||||||
to obfuscate malicious contents
|
to obfuscate malicious contents
|
||||||
|
|
||||||
- we ban most uses of UTF-8 in code and documentation to avoid easily mixed
|
- we ban most uses of UTF-8 in code and documentation to avoid easily mixed
|
||||||
up Unicode characters that look like other characters. (adding Unicode
|
up Unicode characters that look like other characters. (adding Unicode
|
||||||
characters causes errors)
|
characters causes errors)
|
||||||
|
|
||||||
- we document everything to make it clear how things are supposed to work. No
|
- we document everything to make it clear how things are supposed to work. No
|
||||||
surprises. Lots of documentation is tested and verified in addition to
|
surprises. Lots of documentation is tested and verified in addition to
|
||||||
spellchecks and consistent wording.
|
spellchecks and consistent wording.
|
||||||
|
|
||||||
- we have thousands of tests and we add test cases for (ideally) every
|
- we have thousands of tests and we add test cases for (ideally) every
|
||||||
functionality. Finding "white spots" and adding coverage is a top priority.
|
functionality. Finding "white spots" and adding coverage is a top priority.
|
||||||
curl runs on countless operating systems, CPU architectures and you can
|
curl runs on countless operating systems, CPU architectures and you can
|
||||||
build curl in billions of different configuration setups: not every
|
build curl in billions of different configuration setups: not every
|
||||||
combination is practically possible to test
|
combination is practically possible to test
|
||||||
|
|
||||||
- we build curl and run tests in over two hundred CI jobs that are run for
|
- we build curl and run tests in over two hundred CI jobs that are run for
|
||||||
every commit and every PR. We do not merge commits that have unexplained
|
every commit and every PR. We do not merge commits that have unexplained
|
||||||
test failures.
|
test failures.
|
||||||
|
|
||||||
- we build curl in CI with the most picky compiler options enabled and we
|
- we build curl in CI with the most picky compiler options enabled and we
|
||||||
never allow compiler warnings to linger. We always use `-Werror` that
|
never allow compiler warnings to linger. We always use `-Werror` that
|
||||||
converts warnings to errors and fail the builds.
|
converts warnings to errors and fail the builds.
|
||||||
|
|
||||||
- we run all tests using valgrind and several combinations of sanitizers to
|
- we run all tests using valgrind and several combinations of sanitizers to
|
||||||
find and reduce the risk for memory problems, undefined behavior and
|
find and reduce the risk for memory problems, undefined behavior and
|
||||||
similar
|
similar
|
||||||
|
|
||||||
- we run all tests as "torture tests", where each test case is rerun to have
|
- we run all tests as "torture tests", where each test case is rerun to have
|
||||||
every invoked fallible function call fail once each, to make sure curl
|
every invoked fallible function call fail once each, to make sure curl
|
||||||
never leaks memory or crashes due to this.
|
never leaks memory or crashes due to this.
|
||||||
|
|
||||||
- we run fuzzing on curl: non-stop as part of Google's OSS-Fuzz project, but
|
- we run fuzzing on curl: non-stop as part of Google's OSS-Fuzz project, but
|
||||||
also briefly as part of the CI setup for every commit and PR
|
also briefly as part of the CI setup for every commit and PR
|
||||||
|
|
||||||
- we make sure that the CI jobs we have for curl never "write back" to curl.
|
- we make sure that the CI jobs we have for curl never "write back" to curl.
|
||||||
They access the source repository read-only and even if they would be
|
They access the source repository read-only and even if they would be
|
||||||
breached, they cannot infect or taint source code.
|
breached, they cannot infect or taint source code.
|
||||||
|
|
||||||
- we run `zizmor` and other code analyzer tools on the CI job config scripts
|
- we run `zizmor` and other code analyzer tools on the CI job config scripts
|
||||||
to reduce the risk of us running or using insecure CI jobs.
|
to reduce the risk of us running or using insecure CI jobs.
|
||||||
|
|
||||||
- we are committed to always fix reported vulnerabilities in the following
|
- we are committed to always fix reported vulnerabilities in the following
|
||||||
release. Security problems never linger around once they have been
|
release. Security problems never linger around once they have been
|
||||||
reported.
|
reported.
|
||||||
|
|
||||||
- we document everything and every detail about all curl vulnerabilities ever
|
- we document everything and every detail about all curl vulnerabilities ever
|
||||||
reported
|
reported
|
||||||
|
|
||||||
- our commitment to never breaking ABI or API allows all users to easily
|
- our commitment to never breaking ABI or API allows all users to easily
|
||||||
upgrade to new releases. This enables users to run recent security-fixed
|
upgrade to new releases. This enables users to run recent security-fixed
|
||||||
versions instead of legacy insecure versions.
|
versions instead of legacy insecure versions.
|
||||||
|
|
||||||
- our code has been audited several times by external security experts, and
|
- our code has been audited several times by external security experts, and
|
||||||
the few issues that have been detected in those were immediately addressed
|
the few issues that have been detected in those were immediately addressed
|
||||||
|
|
||||||
- Two-factor authentication on GitHub is mandatory for all committers
|
- Two-factor authentication on GitHub is mandatory for all committers
|
||||||
|
|
|
||||||
|
|
@ -1102,7 +1102,6 @@ void Curl_resolv_destroy_all(struct Curl_easy *data)
|
||||||
|
|
||||||
#endif /* USE_CURL_ASYNC */
|
#endif /* USE_CURL_ASYNC */
|
||||||
|
|
||||||
|
|
||||||
#ifdef USE_UNIX_SOCKETS
|
#ifdef USE_UNIX_SOCKETS
|
||||||
CURLcode Curl_resolv_unix(struct Curl_easy *data,
|
CURLcode Curl_resolv_unix(struct Curl_easy *data,
|
||||||
const char *unix_path,
|
const char *unix_path,
|
||||||
|
|
|
||||||
|
|
@ -72,7 +72,6 @@ void Curl_httpsrr_cleanup(struct Curl_https_rrinfo *rrinfo);
|
||||||
bool Curl_httpsrr_applicable(struct Curl_easy *data,
|
bool Curl_httpsrr_applicable(struct Curl_easy *data,
|
||||||
const struct Curl_https_rrinfo *rr);
|
const struct Curl_https_rrinfo *rr);
|
||||||
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Code points for DNS wire format SvcParams as per RFC 9460
|
* Code points for DNS wire format SvcParams as per RFC 9460
|
||||||
*/
|
*/
|
||||||
|
|
@ -90,7 +89,6 @@ CURLcode Curl_httpsrr_from_ares(const ares_dns_record_t *dnsrec,
|
||||||
#endif /* USE_ARES */
|
#endif /* USE_ARES */
|
||||||
|
|
||||||
#ifdef CURLVERBOSE
|
#ifdef CURLVERBOSE
|
||||||
|
|
||||||
CURLcode Curl_httpsrr_print(struct dynbuf *tmp,
|
CURLcode Curl_httpsrr_print(struct dynbuf *tmp,
|
||||||
struct Curl_https_rrinfo *rr);
|
struct Curl_https_rrinfo *rr);
|
||||||
void Curl_httpsrr_trace(struct Curl_easy *data,
|
void Curl_httpsrr_trace(struct Curl_easy *data,
|
||||||
|
|
|
||||||
|
|
@ -1623,7 +1623,6 @@ static CURLcode cookiefile(struct Curl_easy *data, const char *ptr)
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifndef CURL_DISABLE_PROXY
|
#ifndef CURL_DISABLE_PROXY
|
||||||
|
|
||||||
static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
|
static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
|
||||||
{
|
{
|
||||||
if((data->set.str[STRING_PROXY] && proxy) &&
|
if((data->set.str[STRING_PROXY] && proxy) &&
|
||||||
|
|
@ -1636,7 +1635,6 @@ static CURLcode setproxy(struct Curl_easy *data, const char *proxy)
|
||||||
return Curl_setstropt(&data->set.str[STRING_PROXY], proxy);
|
return Curl_setstropt(&data->set.str[STRING_PROXY], proxy);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
static CURLcode setopt_cptr_proxy(struct Curl_easy *data, CURLoption option,
|
static CURLcode setopt_cptr_proxy(struct Curl_easy *data, CURLoption option,
|
||||||
const char *ptr)
|
const char *ptr)
|
||||||
{
|
{
|
||||||
|
|
|
||||||
|
|
@ -73,7 +73,7 @@ static int checkparts(CURLU *u, const char *in, const char *wanted,
|
||||||
/* an IPv6 numerical address host, get the zone */
|
/* an IPv6 numerical address host, get the zone */
|
||||||
(void)curl_url_get(u, CURLUPART_ZONEID, &z, getflags);
|
(void)curl_url_get(u, CURLUPART_ZONEID, &z, getflags);
|
||||||
curl_msnprintf(bufp, len, "%s%s%s%s", buf[0] ? " | " : "", p,
|
curl_msnprintf(bufp, len, "%s%s%s%s", buf[0] ? " | " : "", p,
|
||||||
z ? " ": "", z ? z : "");
|
z ? " " : "", z ? z : "");
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
curl_msnprintf(bufp, len, "%s[%d]", buf[0] ? " | " : "", rc);
|
curl_msnprintf(bufp, len, "%s[%d]", buf[0] ? " | " : "", rc);
|
||||||
|
|
@ -217,56 +217,57 @@ static const struct testcase get_parts_list[] = {
|
||||||
"http://[fe80::1%25eth0]/",
|
"http://[fe80::1%25eth0]/",
|
||||||
"http | [11] | [12] | [13] | [fe80::1] eth0 | [15] | / | [16] | [17]",
|
"http | [11] | [12] | [13] | [fe80::1] eth0 | [15] | / | [16] | [17]",
|
||||||
0, 0, CURLUE_OK },
|
0, 0, CURLUE_OK },
|
||||||
{"curl.se",
|
{ "curl.se",
|
||||||
"[10] | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
"[10] | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
||||||
CURLU_GUESS_SCHEME, CURLU_NO_GUESS_SCHEME, CURLUE_OK},
|
CURLU_GUESS_SCHEME, CURLU_NO_GUESS_SCHEME, CURLUE_OK },
|
||||||
{"https://curl.se:0/#",
|
{ "https://curl.se:0/#",
|
||||||
"https | [11] | [12] | [13] | curl.se | 0 | / | [16] | ",
|
"https | [11] | [12] | [13] | curl.se | 0 | / | [16] | ",
|
||||||
0, CURLU_GET_EMPTY, CURLUE_OK},
|
0, CURLU_GET_EMPTY, CURLUE_OK },
|
||||||
{"https://curl.se/#",
|
{ "https://curl.se/#",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | ",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | ",
|
||||||
0, CURLU_GET_EMPTY, CURLUE_OK},
|
0, CURLU_GET_EMPTY, CURLUE_OK },
|
||||||
{"https://curl.se/?#",
|
{ "https://curl.se/?#",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | | ",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | | ",
|
||||||
0, CURLU_GET_EMPTY, CURLUE_OK},
|
0, CURLU_GET_EMPTY, CURLUE_OK },
|
||||||
{"https://curl.se/?",
|
{ "https://curl.se/?",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | | [17]",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | | [17]",
|
||||||
0, CURLU_GET_EMPTY, CURLUE_OK},
|
0, CURLU_GET_EMPTY, CURLUE_OK },
|
||||||
{"https://curl.se/?",
|
{ "https://curl.se/?",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
||||||
0, 0, CURLUE_OK},
|
0, 0, CURLUE_OK },
|
||||||
{"https://curl.se/?#",
|
{ "https://curl.se/?#",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | [17]",
|
||||||
0, 0, CURLUE_OK},
|
0, 0, CURLUE_OK },
|
||||||
{"https://curl.se/# ",
|
{ "https://curl.se/# ",
|
||||||
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | %20%20",
|
"https | [11] | [12] | [13] | curl.se | [15] | / | [16] | %20%20",
|
||||||
CURLU_URLENCODE | CURLU_ALLOW_SPACE, 0, CURLUE_OK},
|
CURLU_URLENCODE | CURLU_ALLOW_SPACE, 0, CURLUE_OK },
|
||||||
{"", "", 0, 0, CURLUE_MALFORMED_INPUT},
|
{ "", "", 0, 0, CURLUE_MALFORMED_INPUT },
|
||||||
{" ", "", 0, 0, CURLUE_MALFORMED_INPUT},
|
{ " ", "", 0, 0, CURLUE_MALFORMED_INPUT },
|
||||||
{"1h://example.net", "", 0, 0, CURLUE_BAD_SCHEME},
|
{ "1h://example.net", "", 0, 0, CURLUE_BAD_SCHEME },
|
||||||
{"..://example.net", "", 0, 0, CURLUE_BAD_SCHEME},
|
{ "..://example.net", "", 0, 0, CURLUE_BAD_SCHEME },
|
||||||
{"-ht://example.net", "", 0, 0, CURLUE_BAD_SCHEME},
|
{ "-ht://example.net", "", 0, 0, CURLUE_BAD_SCHEME },
|
||||||
{"+ftp://example.net", "", 0, 0, CURLUE_BAD_SCHEME},
|
{ "+ftp://example.net", "", 0, 0, CURLUE_BAD_SCHEME },
|
||||||
{"hej.hej://example.net",
|
{ "hej.hej://example.net",
|
||||||
"hej.hej | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
"hej.hej | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
||||||
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK},
|
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK },
|
||||||
{"ht-tp://example.net",
|
{ "ht-tp://example.net",
|
||||||
"ht-tp | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
"ht-tp | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
||||||
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK},
|
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK },
|
||||||
{"ftp+more://example.net",
|
{ "ftp+more://example.net",
|
||||||
"ftp+more | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
"ftp+more | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
||||||
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK},
|
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK },
|
||||||
{"f1337://example.net",
|
{ "f1337://example.net",
|
||||||
"f1337 | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
"f1337 | [11] | [12] | [13] | example.net | [15] | / | [16] | [17]",
|
||||||
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK},
|
CURLU_NON_SUPPORT_SCHEME, 0, CURLUE_OK },
|
||||||
{"https://user@example.net?hello# space ",
|
{ "https://user@example.net?hello# space ",
|
||||||
"https | user | [12] | [13] | example.net | [15] | / | hello | %20space%20",
|
"https | user | [12] | [13] | example.net | [15] | / | hello | "
|
||||||
CURLU_ALLOW_SPACE | CURLU_URLENCODE, 0, CURLUE_OK},
|
"%20space%20",
|
||||||
{"https://test%test", "", 0, 0, CURLUE_BAD_HOSTNAME},
|
CURLU_ALLOW_SPACE | CURLU_URLENCODE, 0, CURLUE_OK },
|
||||||
{"https://example.com%252f%40@example.net",
|
{ "https://test%test", "", 0, 0, CURLUE_BAD_HOSTNAME },
|
||||||
"https | example.com%2f@ | [12] | [13] | example.net | [15] | / "
|
{ "https://example.com%252f%40@example.net",
|
||||||
"| [16] | [17]",
|
"https | example.com%2f@ | [12] | [13] | example.net | [15] | / "
|
||||||
0, CURLU_URLDECODE, CURLUE_OK },
|
"| [16] | [17]",
|
||||||
|
0, CURLU_URLDECODE, CURLUE_OK },
|
||||||
#ifdef USE_IDN
|
#ifdef USE_IDN
|
||||||
/*
|
/*
|
||||||
https://sv.wikipedia.org/wiki/R%c3%a4ksm%c3%b6rg%c3%a5s
|
https://sv.wikipedia.org/wiki/R%c3%a4ksm%c3%b6rg%c3%a5s
|
||||||
|
|
@ -274,22 +275,22 @@ static const struct testcase get_parts_list[] = {
|
||||||
https://codepoints.net/U+00F6 Latin Small Letter O with Diaeresis
|
https://codepoints.net/U+00F6 Latin Small Letter O with Diaeresis
|
||||||
https://codepoints.net/U+00E5 Latin Small Letter A with Ring Above
|
https://codepoints.net/U+00E5 Latin Small Letter A with Ring Above
|
||||||
*/
|
*/
|
||||||
{"https://r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
{ "https://r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
||||||
"https | [11] | [12] | [13] | xn--rksmrgs-5wao1o.se | "
|
"https | [11] | [12] | [13] | xn--rksmrgs-5wao1o.se | "
|
||||||
"[15] | / | [16] | [17]", 0, CURLU_PUNYCODE, CURLUE_OK},
|
"[15] | / | [16] | [17]", 0, CURLU_PUNYCODE, CURLUE_OK },
|
||||||
{"https://xn--rksmrgs-5wao1o.se",
|
{ "https://xn--rksmrgs-5wao1o.se",
|
||||||
"https | [11] | [12] | [13] | r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
"https | [11] | [12] | [13] | r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
||||||
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK},
|
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK },
|
||||||
{"https://www.xn--rksmrgs-5wao1o.se",
|
{ "https://www.xn--rksmrgs-5wao1o.se",
|
||||||
"https | [11] | [12] | [13] | www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
"https | [11] | [12] | [13] | www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
||||||
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK},
|
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK },
|
||||||
{"https://www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
{ "https://www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
||||||
"https | [11] | [12] | [13] | www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
"https | [11] | [12] | [13] | www.r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se | "
|
||||||
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK},
|
"[15] | / | [16] | [17]", 0, CURLU_PUNY2IDN, CURLUE_OK },
|
||||||
#else
|
#else
|
||||||
{"https://r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
{ "https://r\xc3\xa4ksm\xc3\xb6rg\xc3\xa5s.se",
|
||||||
"https | [11] | [12] | [13] | [30] | [15] | / | [16] | [17]",
|
"https | [11] | [12] | [13] | [30] | [15] | / | [16] | [17]",
|
||||||
0, CURLU_PUNYCODE, CURLUE_OK},
|
0, CURLU_PUNYCODE, CURLUE_OK },
|
||||||
#endif
|
#endif
|
||||||
/*
|
/*
|
||||||
https://codepoints.net/U+2102 Double-Struck Capital C
|
https://codepoints.net/U+2102 Double-Struck Capital C
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue