1. aef0e2d Reference-count CRYPTO_BUFFER_POOLs by David Benjamin · 9 hours ago upstream/main
  2. 7a441c6 rust: bssl-tls: Sessions for TLS 1.3 by Xiangfei Ding · 9 hours ago
  3. 8aab304 rust: bssl-tls: Carve out tokio support into its own crate by Xiangfei Ding · 9 hours ago
  4. b771573 rust: bssl-tls: I/O mocking infrastructure by Xiangfei Ding · 10 hours ago
  5. 6935e82 rust: bssl-tls: General functional tests by Xiangfei Ding · 11 hours ago
  6. a1c1467 rust: bssl-tls: Formatting and feature gate fix by Xiangfei Ding · 2 days ago
  7. 57b745e audit_symbols: Allowlist stdext:: weak symbols on Windows by Lily Chen · 2 days ago
  8. aedc995 Modernize crypto/x509/policy.cc a bit by David Benjamin · 2 days ago
  9. bb9fc5f Add helpers to match characters in CBS by Lily Chen · 2 days ago
  10. 7b20b3c Various IWYU fixes by David Benjamin · 2 days ago
  11. 271b64a Check for negative bit indices in ASN1_BIT_STRING_set_bit by David Benjamin · 2 days ago
  12. 75a048d Hook up X-wing to EVP_KEM by Lily Chen · 3 days ago
  13. 04aa32f Fix the legacy AES-GCM API's IV resizing logic by David Benjamin · 3 days ago
  14. ac5067e Move some code around in v3_ncons.cc by Lily Chen · 3 days ago
  15. 61e81eb Fix up v2i_NAME_CONSTRAINTS by David Benjamin · 3 days ago
  16. 929f91f Add tests for nameConstraints' ad-hoc config parser by David Benjamin · 3 days ago
  17. 1f6e731 Clear the sorted bit after sk_FOO_set by David Benjamin · 4 days ago
  18. f50cce8 rust: bssl-tls: Add MLDSA into list of signature algorithms by Xiangfei Ding · 4 days ago
  19. 0b5b5ff Tidy up ownership a bit in X509_get1_email and friends by David Benjamin · 4 days ago
  20. 102f5c5 Defer dedup in X509_get1_email and friends to the end by David Benjamin · 4 days ago
  21. 8415495 Unwind EC_FELEM hooks on EC_METHOD by David Benjamin · 4 days ago
  22. 06212ed Add an EVP adapter for KEM encap/decap by Lily Chen · 4 days ago
  23. b9696cb Add sk_FOO_sort_and_dedup by David Benjamin · 4 days ago
  24. 4d124cf Update documentation for ML-KEM by Lily Chen · 4 days ago
  25. 0d88d52 pregenerate: Compile public headers entirely as C. by Rudolf Polzer · 5 days ago
  26. 1cd0994 Reject trailing data in ClientHello and EncryptedExtensions trust_anchors by David Benjamin · 5 days ago
  27. cb507bd Test trailing data in OCSP staple parsing by David Benjamin · 5 days ago
  28. e93c8fd Test trailing data for SNI parsing by David Benjamin · 5 days ago
  29. c70aca7 Remove the OPENSSL_NO_ASM gate in OPENSSL_cleanse by David Benjamin · 5 days ago
  30. 151cf73 Add tests for X509_get1_email and friends by David Benjamin · 5 days ago
  31. 0d160a8 pregenerate: Collect symbols with -DBORINGSSL_NO_CXX by David Benjamin · 5 days ago
  32. b82b0af pregenerate: Don't process libpki headers for symbols by David Benjamin · 5 days ago
  33. 0f0884b EVP_PKEY: Treat pss_params as params for RSA-PSS keys by Lily Chen · 5 days ago
  34. 7ab7be8 Allow no-op EVP_CTRL_AEAD_SET_IVLEN calls to keep the IV set by David Benjamin · 6 days ago
  35. 0b42382 slhdsa: Reorder a BSSL_CHECK with its shift by David Benjamin · 7 days ago
  36. b9f2f76 Fix some unreachable code in curve25519_64_adx.h's fiat_addcarryx_u64 by David Benjamin · 7 days ago
  37. 75c449c rust: bssl-tls: Introduce basic session controls on context level by Xiangfei Ding · 7 days ago
  38. 6afcf8d rust: bssl-tls: More advanced controls over certificate verification by xfding · 7 days ago
  39. 837e6ce rust: bssl-tls: More advanced control over IO transport by xfding · 7 days ago
  40. c67abbf rust: bssl-tls: Introduce TLS alerts by xfding · 7 days ago
  41. 3d5cafd Don't skip calling the cleanup hook in EVP_PKEY_CTX when the copy hook fails by David Benjamin · 7 days ago
  42. 40e356a Check for invalid certificate_authorities extensions by David Benjamin · 7 days ago
  43. bf307da Remove p224-64.cc.inc by David Benjamin · 7 days ago
  44. c3ffc33 pki: Check for unused bits when verifying MTC proofs by David Benjamin · 7 days ago
  45. 92fc136 rust: bssl-tls: Reinstate preshared key tests by Xiangfei Ding · 7 days ago
  46. f02f0ee rust: bssl-x509: Stop reporting partially constructed cert chain by Xiangfei Ding · 7 days ago
  47. 09e53b2 rust: bssl-x509: proper serialisation of X.509 certificate serial number by Xiangfei Ding · 7 days ago
  48. ef5a1cc Test 0 * P + 0 * G in ec_point_mul_scalar_public by David Benjamin · 7 days ago
  49. 21fa3fc Cut down on test-only OPENSSL_EXPORTs by David Benjamin · 7 days ago
  50. d944558 rust: bssl-rustls-adapters: Mask the content type and protocol by Xiangfei Ding · 7 days ago
  51. 439e537 rust: bssl-tls: std and tokio transport integration by Xiangfei Ding · 8 days ago
  52. f3229af rust: bssl-tls: Drop Sync on BIO objects by Xiangfei Ding · 8 days ago
  53. acd9b96 rust: bssl-tls: Application facing I/O by Xiangfei Ding · 8 days ago
  54. a73b26b rust: bssl-tls: Make certificate store more ergonomic by Xiangfei Ding · 8 days ago
  55. ca56661 Add missing CONSTTIME_SECRET markers to ML-DSA implementation by David Benjamin · 8 days ago
  56. 880f5db Configure .clangd and .clang-format so that header insertion works by David Benjamin · 8 days ago
  57. 1cc9482 Reset IV state in legacy AES-GCM API on EVP_CTRL_AEAD_SET_IVLEN by David Benjamin · 8 days ago
  58. 4a3cda4 Support ML-DSA in libssl by Nick Harper · 8 days ago
  59. e9449d4 Require internal and external ML-KEM public key structs to match in size by Lily Chen · 8 days ago
  60. 2d55409 rust: bssl-tls: Cap the input length reported by the abstract socket by Xiangfei Ding · 8 days ago
  61. 75bc5f6 Update documented default scrypt memory limits by David Benjamin · 8 days ago
  62. e42d18b EVP_PKEY_copy_parameters: Allocate new receiving key if not present by Lily Chen · 9 days ago
  63. 90a06ca Handle short-name-less NIDs in X509_NAME_print_ex by David Benjamin · 9 days ago
  64. 11bc8cd Remove SSL_R_PAKE_AND_KEY_SHARE_NOT_ALLOWED by David Benjamin · 9 days ago
  65. 54b9d73 EVP_PKEY: null-check EVP_PKEY_ASN1_METHOD before using by Lily Chen · 9 days ago
  66. 0e22042 Fix beeu_mod_inverse_vartime on aarch64 by David Benjamin · 9 days ago
  67. 6814079 More gracefully handle invalid ASN1_STRING objects in ASN1_STRING_print_ex by David Benjamin · 9 days ago
  68. 070839a Allow zero-length inputs in SHA256_TransformBlocks by David Benjamin · 9 days ago
  69. 8743baf Fix ERR_add_error_data call in SSL_add_dir_cert_subjects_to_stack by David Benjamin · 9 days ago
  70. fe80243 More consistently make the ASN1_TYPE-level type take precedence over the ASN1_STRING one by David Benjamin · 9 days ago
  71. b3a767e rust: bssl-tls: Take a borrowed credentials by Xiangfei Ding · 9 days ago
  72. 6143ebd rust: bssl-tls: Drop unused functions by Xiangfei Ding · 9 days ago
  73. c87bfdc rust: bssl-tls: Bubble up EOF during shutdown by Xiangfei Ding · 9 days ago
  74. 580f428 Fix output bounds checking in EVP_AEAD_CTX_seal_scatter by David Benjamin · 9 days ago
  75. f5a4dc4 Fix return value on impossible error condition by David Benjamin · 9 days ago
  76. 6b2753a pki: Set a default iteration limit of 20 by David Benjamin · 9 days ago
  77. 7954718 Check for PMULL in gcm_sha3_capable by David Benjamin · 9 days ago
  78. 3509b0a Document some historical mistakes in HandshakeHints tagging by David Benjamin · 9 days ago
  79. c8eb36b Check hashes when parsing test-only, semi-expand ML-KEM private keys by David Benjamin · 9 days ago
  80. 257bd24 Update style guide to reflect C++ usage by David Benjamin · 9 days ago
  81. 8c67f91 rust: bssl-tls: Cope with upstream type inference regression by Xiangfei Ding · 9 days ago
  82. 4ccbe2a Split MLKEM's scalar_*code functions into compile-time alternatives by bit size. by Rudolf Polzer · 10 days ago
  83. 6226a46 rust: bssl-tls: Safe abstraction of a partially filled buffer by Xiangfei Ding · 10 days ago
  84. 12883de Clarify that the old PSK API is just about TLS 1.2 PSKs by David Benjamin · 10 days ago
  85. 23510b3 rust: bssl-tls: Keep CertificateCache live by Xiangfei Ding · 10 days ago
  86. 5cdb378 Remove check_imported_libraries.go script by David Benjamin · 10 days ago
  87. b271161 Update reference for X-Wing to a more recent draft by Lily Chen · 10 days ago
  88. 456ed35 Unroll the ML-KEM NTT outer loops. by Rudolf Polzer · 10 days ago
  89. 2382739 Disable check_imported_libraries check on CI by David Benjamin · 10 days ago
  90. d6b7595 Link to CMVP certificate for 20240805 by Dimitri John Ledkov · 11 days ago
  91. 7e8ee38 ML-KEM benchmarks: add per-operation microbenchmarks. by Rudolf Polzer · 11 days ago
  92. 9bd9c49 Add a value barrier to EVP_sha256_final_with_secret_suffix too by David Benjamin · 11 days ago
  93. 8bfbe4b Add unit tests for EVP_aead_aes_128_cbc_sha256_tls by David Benjamin · 11 days ago
  94. 6bf9398 docs/references: Use the newer RFC for ChaCha20-Poly1305 by David Benjamin · 11 days ago
  95. 81fa30a Add some missing #includes by Lily Chen · 11 days ago
  96. 458f307 Remove an unused label and dead code from chacha20_poly1305_armv8.pl by David Benjamin · 11 days ago
  97. d889399 Rust: fix a missing import by Lily Chen · 12 days ago
  98. 4380f65 anyExtendeKeyUsage -> anyExtendedKeyUsage by Amir Sarabadani · 12 days ago
  99. 93b2c78 Fix typos by Amir Sarabadani · 12 days ago
  100. 63159df rust: bssl-macros: Add Apache-2.0 license by Raul E Rangel · 12 days ago