mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-08-30 03:08:38 +09:00
- Added HACL*Poly1305 32-bit (INRIA/Microsoft) - Updated to final TLS 1.3 draft version (28) - Removed TLS 1.3 prerelease draft limit check - Removed NPN code - Enabled dev/urandom-only RNG on Linux with NSS_SEED_ONLY_DEV_URANDOM for non-standard environments - Fixed several bugs with TLS 1.3 negotiation - Updated internal certificate store - Added support for the TLS Record Size Limit Extension. - Fixed CVE-2018-0495 - Various security fixes in the ASN.1 code.
40 lines
1.2 KiB
Bash
40 lines
1.2 KiB
Bash
#!/usr/bin/env bash
|
|
|
|
if [[ $(id -u) -eq 0 ]]; then
|
|
# Drop privileges by re-running this script.
|
|
# Note: this mangles arguments, better to avoid running scripts as root.
|
|
exec su worker -c "$0 $*"
|
|
fi
|
|
|
|
set -e -x -v
|
|
|
|
# The docker image this is running in has the HACL* and NSS sources.
|
|
# The extracted C code from HACL* is already generated and the HACL* tests were
|
|
# successfully executed.
|
|
|
|
# Verify HACL*. Taskcluster fails when we do this in the image build.
|
|
make -C hacl-star verify-nss -j$(nproc)
|
|
|
|
# Add license header to specs
|
|
spec_files=($(find ~/hacl-star/specs -type f -name '*.fst'))
|
|
for f in "${spec_files[@]}"; do
|
|
cat /tmp/license.txt "$f" > /tmp/tmpfile && mv /tmp/tmpfile "$f"
|
|
done
|
|
|
|
# Format the extracted C code.
|
|
cd ~/hacl-star/snapshots/nss
|
|
cp ~/nss/.clang-format .
|
|
find . -type f -name '*.[ch]' -exec clang-format -i {} \+
|
|
|
|
# These diff commands will return 1 if there are differences and stop the script.
|
|
files=($(find ~/nss/lib/freebl/verified/ -type f -name '*.[ch]'))
|
|
for f in "${files[@]}"; do
|
|
diff $f $(basename "$f")
|
|
done
|
|
|
|
# Check that the specs didn't change either.
|
|
cd ~/hacl-star/specs
|
|
files=($(find ~/nss/lib/freebl/verified/specs -type f))
|
|
for f in "${files[@]}"; do
|
|
diff $f $(basename "$f")
|
|
done
|