Commit graph

37789 commits

Author SHA1 Message Date
Daniel Stenberg
434e5312f4
tool_operate: split post_per_transfer into sub functions
To make it easier to read and manage. Reduce complexity.

Closes #20560
2026-02-11 09:41:48 +01:00
renovate[bot]
69f67f5e1a
GHA/linux: update pizlonator/fil-c to v0.678
Closes #20558
2026-02-11 06:12:04 +01:00
Viktor Szakats
e269e3daf1
pytest: bump pip cryptography to 46.0.5
For CVE-2026-26007 (curl not affected)
2026-02-11 06:10:21 +01:00
renovate[bot]
64ea225589
GHA: update awslabs/aws-lc to v1.67.0
Closes #20553
2026-02-10 07:54:12 +01:00
Daniel Stenberg
ee3a4dff1a
http_aws_sigv4: fix query normalization of %2b
Reported-by: Nuno Goncalves
Fixes #20543
Closes #20550
2026-02-10 07:52:18 +01:00
Viktor Szakats
5c250e2421
gss: exclude verbose error logic from non-verbose builds
Closes #20551
2026-02-10 02:34:33 +01:00
Jay Satiro
b844c1a075 vtls: use ALPN http/1.0 & http/1.1 for HTTP/1.0 requests
- For compatibility reasons send both ALPN ids http/1.0 and http/1.1 for
  HTTP/1.0 requests.

Prior to this change for compatibility reasons curl would send ALPN
http/1.1 for HTTP/1.0 requests, since some servers do not recognize
ALPN http/1.0. However some servers may recognize only ALPN http/1.0 for
HTTP/1.0 requests. Therefore curl now sends both.

Reported-by: programmerlexi@users.noreply.github.com

Fixes https://github.com/curl/curl/issues/20487
Closes https://github.com/curl/curl/pull/20533
2026-02-09 12:15:35 -05:00
Daniel Stenberg
0291f751cb
RELEASE-NOTES: synced 2026-02-09 16:28:57 +01:00
Daniel Stenberg
22010e4185
test1980: verify sigv4 normalization query with + and spaces
Ref: #20543
Closes #20548
2026-02-09 13:41:42 +01:00
Daniel Stenberg
15a8a777b8
VULN-DISCLOSURE-POLICY.md: mention GitHub quirks
Closes #20541
2026-02-09 12:42:36 +01:00
Daniel Stenberg
950c7bb174
digest: escape double quotes and backslashes in realm and nonce
change test 907 to use quote in realm to verify

Fixes #20482
Reported-by: cooldadpresident on github
Closes #20545
2026-02-09 08:50:32 +01:00
Daniel Stenberg
afe9fdd1eb
tests: convert base64 data to %b64[]
To make it easier to read, understand and edit tests - and grep them.

Closes #20547
2026-02-09 08:42:49 +01:00
Viktor Szakats
cdfc8dc7ad
build: tidy up and simplify setmode() detection and use
- move macro to `curl_setup.h` (from curlx), and rename.
  It's required by src, test servers, libtests. Also used by unit/tunit,
  (which is fixable but this patch doesn't touch it.)
- special-case it for Windows/Cygwin/MS-DOS.
- build: drop `setmode()`/`_setmode()` detection.
  This also avoids detecting the different `setmode()` on BSDs,
  and a lot of complexity and overhead.
- use `CURL_O_BINARY`.

Follow-up to 250d613763 #15787
Follow-up to 5e70566094 #15169

Closes #20539
2026-02-08 15:47:47 +01:00
Viktor Szakats
2c0019b085
curl_setup.h: drop extra header guard for internal include
The included local header starts with this same guard. The original
commit added it for fixing VMS builds along with many other changes, but
without mention of this specific one in the commit message.

`curl_setup.h` is included once, which includes `curl_setup_once.h`
once, even if the latter wouldn't have it's own guard.

Ref: 25f351424b

Closes #20544
2026-02-08 15:47:47 +01:00
Viktor Szakats
bb56f325a4
curl_get_line: drop single-use macro
Follow-up to 769ccb4d42 #19140

Closes #20542
2026-02-08 15:47:47 +01:00
Daniel Stenberg
aa0be708b9
url.c: restore mistaken comment change
Follow-up to d7a9f1ab15

Closes #20540
2026-02-07 23:26:57 +01:00
Daniel Stenberg
510fdad64d
sws: prevent "connection monitor" to say disconnect twice 2026-02-07 22:16:53 +01:00
Daniel Stenberg
34fa034d9a
url: fix reuse of connections using HTTP Negotiate
Assume Negotiate means connection-based

Reported-by: Zhicheng Chen
Closes #20534
2026-02-07 22:16:53 +01:00
Viktor Szakats
2d8284e4e8
src/Makefile.inc: update CURLX_HFILES
Closes #20537
2026-02-07 19:40:45 +01:00
Viktor Szakats
02c37d269c
docs: compare result against literal CURLE_OK (where missing)
Also scope to result variables.

Closes #20536
2026-02-07 19:40:45 +01:00
Viktor Szakats
85de995208
tidy-up: move literals to right-side of if expressions (where missing)
Closes #20535
2026-02-07 16:41:51 +01:00
Viktor Szakats
c6ac2de5b3
tool_cb_prg: drop duplicate preprocessor logic
In favor of the copy in `curl_setup.h`.

Closes #20531
2026-02-05 23:46:49 +01:00
Viktor Szakats
0495425c69
lib518, 537: drop #error on unlikely/impossible build condition
`FD_SETSIZE` is used in core code and expected to be present.

Closes #20530
2026-02-05 23:46:49 +01:00
Daniel Stenberg
97cf032809
README: add MQTTS
Follow-up to 6c31df453b

Closes #20532
2026-02-05 22:55:01 +01:00
Juan Belon
12a1be509e
curl_setup_once: allow CURL_DEBUGASSERT for customization
Closes #19744
2026-02-05 17:40:46 +01:00
renovate[bot]
3417cb1562
Dockerfile: update debian:bookworm-slim Docker digest to 98f4b71
Closes #20501
2026-02-05 17:36:44 +01:00
Spenser Black
e674e84654
docs: fix grammar nitpicks
Closes #20518
2026-02-05 17:26:02 +01:00
Stefan Eissing
d7a9f1ab15
url.c: code/comment cleanup around conn creation
Several comments were outdated and parameters to create_conn() and
ConnectionExists() were not needed. Give functions better names and
consistently use terms `needle` and `conn`.

No functional change.

Closes #20464
2026-02-05 17:21:53 +01:00
jhauga
161be30854
curl: add -I and -i to -h important
Closes #20483
2026-02-05 17:20:29 +01:00
renovate[bot]
7fc12ecae8
GHA: update google/boringssl to v0.20260204.0
Closes #20519
2026-02-05 17:18:55 +01:00
Viktor Szakats
14144a4064
mk-ca-bundle.pl: drop support for obsolete/insecure fingerprint algos
MD5 and SHA1 fingerprints can no longer be included in the output when
using the `-t` option.

Closes #20527
2026-02-05 15:22:01 +01:00
Viktor Szakats
4b3af7fb67
lib: disable websockets early if no http
To prevent inconsistent `CURL_DISABLE_WEBSOCKETS` states between source
files.

Follow-up to 8edc0338f3 #20351

Closes #20526
2026-02-05 13:12:10 +01:00
Viktor Szakats
f659b82c2a
build: make HTTP_ONLY build options also disable websockets
Closes #20525
2026-02-05 13:12:10 +01:00
Viktor Szakats
4fb5c916fd
cmake: use list(APPEND ...) where missing
Cherry-picked from #20407

Closes #20522
2026-02-05 13:12:10 +01:00
Viktor Szakats
fa9318cabf
GHA/linux-old: use tilde where possible and consistent
Cherry-picked from #20407

Closes #20524
2026-02-05 13:12:10 +01:00
Viktor Szakats
86d8e2b94d
GHA/non-native: pin DJGPP toolchain to hash
This package is automatically bumped, but needs manual intervention
anyway, to update gcc version number in the filename.

Follow-up to 4ad0a022e1 #20517

Closes #20523
2026-02-05 13:12:10 +01:00
Viktor Szakats
4ad0a022e1
CI: log downloaded file hashes, pin manually bumped ones
To ensure downloaded binaries are the expected ones. Also to document
SHA-256 hashes of all binary packages and source tarballs.

Closes #20517
2026-02-05 03:20:46 +01:00
Viktor Szakats
462244447e
build: use native file open flags in Windows-specific code
To comply with official documentation. Also to make code compile with
`NO_OLDNAMES` (mingw-w64) or `_CRT_DECLARE_NONSTDC_NAMES=0` (MSVC) set.

Ref: #15652

Closes #20516
2026-02-04 15:59:35 +01:00
Daniel Stenberg
94349aa932
mqtt: verify Remaining Length for CONNACK and PUBACK
Verified in test 1132

Closes #20513
2026-02-04 15:43:13 +01:00
Daniel Stenberg
0ccaf6c835
VULN-DISCLOSURE-POLICY.md: push reports to the web form
Closes #20515
2026-02-04 12:45:51 +01:00
Viktor Szakats
0bfd2645ca
GHA/windows: set lookup-only in build-cache jobs
To save a few seconds by not actually restoring the cache, just checking
if there is cache hit.

Follow-up to fb44e44d92 #20456

Closes #20512
2026-02-04 03:07:29 +01:00
Viktor Szakats
443a539fcf
build: move curl stat struct type to the curlx namespace
To match surrounding curlx symbols and functions.

Follow-up to a84b041281 #20496

Closes #20508
2026-02-04 02:07:16 +01:00
Daniel Stenberg
fdca2e0fd3
imap: add a check for Curl_meta_get()
It should not return NULL, but if it does we need to bail out. Like we
do elsewhere.a

Found by CodeSonar.
Closes #20510
2026-02-03 23:24:06 +01:00
Stefan Eissing
2d4efbb9b3 multi: update timer unconditionally in multi_remove_handle
When removing an easy handle from a multi, there was an optimization
to update the timer only when the removed handle had any timers.

With the introduction of the "dirty" bitset, easy handles can now cause
a timeout of 0 to be set without having anything in their timer list.
Removing such a handle needs to update the timer now always, so that
it may get cleared when there is nothing more to wait for.

The previous "not clearing a 0 timer" should not have any effect on
application's logic. Without clearing, the timer will fire and then
adjust itself to the proper value. But it would cause one more timer
fire than necessary.

Reported-by: Jan Macku

Fixes https://github.com/curl/curl/issues/20498
Closes https://github.com/curl/curl/pull/20502
2026-02-03 16:24:39 -05:00
Viktor Szakats
0590753a3c
build: require POSIX strdup()
Stop detecting this function and drop the local fallback.

Let us know if this update is causing an issue.

Notes:
- on Windows `_strdup()` is required instead.
- `strdup()/_strdup()` were required before this patch to build one of
  the examples: `block_ip`.
- `strdup()/_strdup()` were required in 8.18.0 and earlier to build
  tests.

Closes #20505
2026-02-03 17:50:18 +01:00
Viktor Szakats
710d5a28fb
fopen.h: simplify curl memory macro mappings
Closes #20506
2026-02-03 15:13:37 +01:00
Viktor Szakats
5bdbad87c5
curlx: drop unused curlx_saferealloc()
Unused since 67ae101666 #19949

Closes #20504
2026-02-03 15:13:37 +01:00
Viktor Szakats
31a4f415af
build: tidy up and dedupe strdup functions
- de-dupe lib/src strdup/memdup functions into curlx.
- introduce `CURLX_STRDUP_LOW()` for mapping `strdup()`, and to do it at
  one place within the code, in `curl_setup.h`.
- tests/server: use `curlx_strdup()`. (Also to fix building without
  a system `strdup()`.)
- curlx/curlx.h: shorten and tidy up.
- adjust Windows build path to not need `HAVE_STRDUP`.
- build: stop detecting `HAVE_STRDUP` on Windows.

Closes #20497
2026-02-03 14:02:30 +01:00
Viktor Szakats
e39650c984
curl_setup.h: simplify curl memory macro mappings
Full argument listing is redundant for `curl`-prefixed internal macros.

Closes #20499
2026-02-03 10:54:42 +01:00
Viktor Szakats
d442be2ce3
typos: silence false positives found in C code
Closes #20500
2026-02-03 00:59:41 +01:00