Skip to Content.
Sympa Menu

sm-commit - [[SM-Commit] ] GIT changes to master grimoire by Treeve Jelbert (57f88b4e661bf959cd5d6e94dc1ed6d988fc010a)

sm-commit AT lists.ibiblio.org

Subject: Source Mage code commit list

List archive

Chronological Thread  
  • From: Treeve Jelbert <scm AT sourcemage.org>
  • To: sm-commit AT lists.ibiblio.org, sm-commit AT lists.sourcemage.org
  • Subject: [[SM-Commit] ] GIT changes to master grimoire by Treeve Jelbert (57f88b4e661bf959cd5d6e94dc1ed6d988fc010a)
  • Date: Wed, 26 Aug 2026 13:29:40 +0000

GIT changes to master grimoire by Treeve Jelbert <treeve AT sourcemage.org>:

crypto/botan/DETAILS | 2
crypto/botan/HISTORY | 3
crypto/xmlsec/DETAILS | 4
crypto/xmlsec/HISTORY | 3
devel/ccache/DETAILS | 4
devel/ccache/HISTORY | 3
http/nghttp2/DETAILS | 4
http/nghttp2/HISTORY | 3
libs/simdjson/DETAILS | 4
libs/simdjson/HISTORY | 3
python-pypi/m2crypto/DETAILS | 6
python-pypi/m2crypto/HISTORY | 3
qt-cmake/kddockwidgets/DETAILS | 2
qt-cmake/kddockwidgets/HISTORY | 3
qt-cmake/qca/BUILD | 5
qt-cmake/qca/HISTORY | 4
qt-cmake/qca/PRE_BUILD | 3
qt-cmake/qca/patches/ssl4.diff | 408
+++++++++++++++++++++++++++++++++++++++++
18 files changed, 452 insertions(+), 15 deletions(-)

New commits:
commit 57f88b4e661bf959cd5d6e94dc1ed6d988fc010a
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

simdjson: => 4.6.8

commit 5a88967b375963e616124e22140f45be6bd2e0d4
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

qca - fix build with ssl4. qt6

commit c732bb681480f96d6397e46119b5e29e42e6808c
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

botan: => 3.13.0

commit 945338f1205a01f76dc9ed21bad7910b677e4a3c
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

ccache: => 4.14

commit 73fcc829c37b508d814c50f813b2a592a5a140b5
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

nghttp2: => 1.70.0

commit 3555d6bc6edaeca13ce0bf46895a3a721f515c47
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

m2crypto: => 0.49.0

commit cd1e2d182156727fc34652fbbf758b432fcebc21
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

xmlsec: => 1.3.12

commit 665390cabbed1c3c2eda12de7400c4ce1619a61c
Author: Treeve Jelbert <treeve AT sourcemage.org>
Commit: Treeve Jelbert <treeve AT sourcemage.org>

kddockwidgets: => 2.4.1

diff --git a/crypto/botan/DETAILS b/crypto/botan/DETAILS
index 9a6d313..425f2fc 100755
--- a/crypto/botan/DETAILS
+++ b/crypto/botan/DETAILS
@@ -1,5 +1,5 @@
SPELL=botan
- VERSION=3.12.0
+ VERSION=3.13.0
SECURITY_PATCH=2
SOURCE=Botan-$VERSION.tar.xz
SOURCE_URL[0]=https://botan.randombit.net/releases/$SOURCE
diff --git a/crypto/botan/HISTORY b/crypto/botan/HISTORY
index a76180f..6ebd681 100644
--- a/crypto/botan/HISTORY
+++ b/crypto/botan/HISTORY
@@ -1,3 +1,6 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 3.13.0
+
2026-05-18 Treeve Jelbert <treeve AT sourcemage.org>
* DETAILS: version 3.12.0

diff --git a/crypto/xmlsec/DETAILS b/crypto/xmlsec/DETAILS
index 9bf621b..578b811 100755
--- a/crypto/xmlsec/DETAILS
+++ b/crypto/xmlsec/DETAILS
@@ -1,6 +1,6 @@
SPELL=xmlsec
- VERSION=1.3.8
-
SOURCE_HASH=sha512:b6dcd04c617b316d3c345634fc363e0400767ff1f8e52031fde097a9e89688efc97f30ea3d6c6350050233828cea318da60f9f2f6c7e783b19e8be62056e75ed
+ VERSION=1.3.12
+
SOURCE_HASH=sha512:dff897cbe3d0235f6f99505d699ab7998bfb80fe1d8239493ae6d0fd760b41d4d3993c4c2dc2c75d87198f797a9b98c91c76929d39056cc4c6db10237d256f38
SECURITY_PATCH=1
SOURCE=$SPELL${VERSION%%\.*}-$VERSION.tar.gz
SOURCE_DIRECTORY=$BUILD_DIRECTORY/$SPELL${VERSION%%\.*}-$VERSION
diff --git a/crypto/xmlsec/HISTORY b/crypto/xmlsec/HISTORY
index 093cc5c..6b10e78 100644
--- a/crypto/xmlsec/HISTORY
+++ b/crypto/xmlsec/HISTORY
@@ -1,3 +1,6 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 1.3.12
+
2025-10-20 Treeve Jelbert <treeve AT sourcemage.org>
* DETAILS: version 1.3.8

diff --git a/devel/ccache/DETAILS b/devel/ccache/DETAILS
index 60d9d11..30e9d83 100755
--- a/devel/ccache/DETAILS
+++ b/devel/ccache/DETAILS
@@ -1,7 +1,7 @@
source $GRIMOIRE/CMAKE_FUNCTIONS
SPELL=ccache
- VERSION=4.13.6
-
SOURCE_HASH=sha512:5b64221958435744ae1d81c8cf124a21955b2dc34420425749ce2983fed3ca62c0ac7a41e0c67101a05d24952f6ce5f6302927976b5ec1de959408fb47dcaf75
+ VERSION=4.14
+
SOURCE_HASH=sha512:df099fbfaf10b47afda642f50c8b3b0a4c213486b841ae0c8c4f17c27c9a7790ebf3443065c15759c5b4cadec0b0743a744ed98b63363c49d59ecec8546fcd3e
SOURCE=$SPELL-$VERSION.tar.xz
SOURCE_DIRECTORY=$BUILD_DIRECTORY/$SPELL-$VERSION

SOURCE_URL[0]=https://github.com/$SPELL/$SPELL/releases/download/v$VERSION/$SOURCE
diff --git a/devel/ccache/HISTORY b/devel/ccache/HISTORY
index 56d226d..3de1492 100755
--- a/devel/ccache/HISTORY
+++ b/devel/ccache/HISTORY
@@ -1,3 +1,6 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 4.14
+
2026-05-11 Treeve Jelbert <treeve AT sourcemage.org>
* DETAILS: version 4.13.6

diff --git a/http/nghttp2/DETAILS b/http/nghttp2/DETAILS
index 60814ed..11fd5b4 100755
--- a/http/nghttp2/DETAILS
+++ b/http/nghttp2/DETAILS
@@ -1,6 +1,6 @@
SPELL="nghttp2"
- VERSION="1.63.0"
-
SOURCE_HASH="sha512:ac5005f33664981e194730223881f4207c9570cb8d9bba51b5592a3e7eb59455ebe25bf190211811513c64497a1b42ec7a82cc7f810059f46c99a83dd2d6cef9"
+ VERSION=1.70.0
+
SOURCE_HASH=sha512:8d8a95dcd05dfe8a032b78d99b7d32a9f0ad2c952c4548de4c6b4af0d2f3c584b0a2854b31516eca20b0c9c30f20d0d040edfe9961a3084e96353012f711b9d1
SECURITY_PATCH="4"
SOURCE="${SPELL}-${VERSION}.tar.xz"

SOURCE_URL[0]="https://github.com/${SPELL}/${SPELL}/releases/download/v${VERSION}/${SOURCE}";
diff --git a/http/nghttp2/HISTORY b/http/nghttp2/HISTORY
index 61d1b99..2c36ba9 100644
--- a/http/nghttp2/HISTORY
+++ b/http/nghttp2/HISTORY
@@ -1,3 +1,6 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 1.70.0
+
2024-09-18 Pavel Vinogradov <public AT sourcemage.org>
* DETAILS: version 1.63.0, SECURITY_PATCH++, (CVE-2024-28182),
added Watch line
diff --git a/libs/simdjson/DETAILS b/libs/simdjson/DETAILS
index 268d970..313a7a4 100755
--- a/libs/simdjson/DETAILS
+++ b/libs/simdjson/DETAILS
@@ -1,7 +1,7 @@
source $GRIMOIRE/CMAKE_FUNCTIONS
SPELL=simdjson
- VERSION=4.6.6
-
SOURCE_HASH=sha512:47c99bca59b8d6ae31cba57b42d6260d5b314131b6e7b1d5d8c1585ec3753094706737f1905cf4c1368fba08f88d492a54f9d72f52ce39704a81f73efee6e921
+ VERSION=4.6.8
+
SOURCE_HASH=sha512:badc5828019e9a0531bd2ce92b66aa8273ea1a31b69ff47f009d1102132a5aad46b4bc3e50ab004d1ec2e63f58dbaf89c018dda6b156b9062cf8f800aad73aa2
SOURCE=$SPELL-$VERSION.tar.gz
SOURCE_DIRECTORY=$BUILD_DIRECTORY/$SPELL-$VERSION
WEB_SITE=https://github.com/simdjson/simdjson
diff --git a/libs/simdjson/HISTORY b/libs/simdjson/HISTORY
index 4db2cca..706c962 100644
--- a/libs/simdjson/HISTORY
+++ b/libs/simdjson/HISTORY
@@ -1,3 +1,6 @@
+2026-08-26 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 4.6.8
+
2026-08-18 Treeve Jelbert <treeve AT sourcemage.org>
* DETAILS: version 4.6.6

diff --git a/python-pypi/m2crypto/DETAILS b/python-pypi/m2crypto/DETAILS
index 502f253..ca88802 100755
--- a/python-pypi/m2crypto/DETAILS
+++ b/python-pypi/m2crypto/DETAILS
@@ -1,7 +1,7 @@
SPELL=m2crypto
- VERSION=0.45.1
-
VX=ad/69/33db804ea9c50175df3508d97bd3c33926913480bbd951008b92f678b138
-
SOURCE_HASH=sha512:7915bbb63625f645b6281dbdd2bb60691a6fa0d54ab505a1105d76efad5e0407ce68e38bebd5e0b0773bcbb99025ff7aa7d8df25fe32364d4a33471e6e9466ce
+ VERSION=0.49.0
+
VX=d6/42/b1b6d202f66335ed80f10eae23eb0f9a69f9dd77783aa248892f44c91e66
+
SOURCE_HASH=sha512:56a90a4445f9c0aa75661d9671aff0f277b72339c52715aafb54cdcde2fa5e35eb3f221c8545c5652ccfbd72643d60cf613f76741cccccc969efadfd6b1e6edf
SOURCE=$SPELL-$VERSION.tar.gz
SOURCE_DIRECTORY=$BUILD_DIRECTORY/$SPELL-$VERSION
SOURCE_URL[0]=https://files.pythonhosted.org/packages/$VX/$SOURCE
diff --git a/python-pypi/m2crypto/HISTORY b/python-pypi/m2crypto/HISTORY
index b0d1dd1..2c0a253 100644
--- a/python-pypi/m2crypto/HISTORY
+++ b/python-pypi/m2crypto/HISTORY
@@ -1,3 +1,6 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 0.49.0
+
2025-06-17 Ismael Luceno <ismael AT sourcemage.org>
updated spell to 0.45.1

diff --git a/qt-cmake/kddockwidgets/DETAILS b/qt-cmake/kddockwidgets/DETAILS
index e16088b..d7e192f 100755
--- a/qt-cmake/kddockwidgets/DETAILS
+++ b/qt-cmake/kddockwidgets/DETAILS
@@ -1,6 +1,6 @@
SPELL=kddockwidgets
SPELLX=KDDockWidgets
- VERSION=2.4.0
+ VERSION=2.4.1
SOURCE=$SPELL-$VERSION.tar.gz
SOURCE_DIRECTORY=$BUILD_DIRECTORY/$SPELLX-$VERSION
WEB_SITE=https://github.com/KDAB/KDDockWidgets
diff --git a/qt-cmake/kddockwidgets/HISTORY b/qt-cmake/kddockwidgets/HISTORY
index 062be68..648941a 100644
--- a/qt-cmake/kddockwidgets/HISTORY
+++ b/qt-cmake/kddockwidgets/HISTORY
@@ -1,3 +1,6 @@
+2026-08-25 Treeve Jelbert <treeve AT sourcemage.org>
+ * DETAILS: version 2.4.1
+
2025-11-15 Treeve Jelbert <treeve AT sourcemage.org>
* DETAILS: add gpg checking
* DETAILS: version 2.4.0
diff --git a/qt-cmake/qca/BUILD b/qt-cmake/qca/BUILD
index 458d10b..09557a5 100755
--- a/qt-cmake/qca/BUILD
+++ b/qt-cmake/qca/BUILD
@@ -1,3 +1,4 @@
-CXXFLAGS+=" -Wno-cpp -fpermissive"
-OPTS+=' -DBUILD_TESTS=0'
+CXXFLAGS+=" -Wno-cpp -fpermissive" &&
+OPTS+=' -DBUILD_TESTS=0' &&
+OPTS+=' -DBUILD_WITH_QT6=1' &&
default_build
diff --git a/qt-cmake/qca/HISTORY b/qt-cmake/qca/HISTORY
index bcb5df8..846084f 100644
--- a/qt-cmake/qca/HISTORY
+++ b/qt-cmake/qca/HISTORY
@@ -1,3 +1,7 @@
+2026-08-24 Treeve Jelbert <treeve AT sourcemage.org>
+ * PRE_BUILD ssl4.diff: added, fix build with openssl-4
+ * BUILD: force qt6
+
2026-07-25 Ismael Luceno <ismael AT sourcemage.org>
* DEPENDS: switched to Qt 6;
added flags for optional depedencies
diff --git a/qt-cmake/qca/PRE_BUILD b/qt-cmake/qca/PRE_BUILD
new file mode 100755
index 0000000..4604ffc
--- /dev/null
+++ b/qt-cmake/qca/PRE_BUILD
@@ -0,0 +1,3 @@
+default_pre_build &&
+cd $SOURCE_DIRECTORY &&
+apply_patch_dir patches
diff --git a/qt-cmake/qca/patches/ssl4.diff b/qt-cmake/qca/patches/ssl4.diff
new file mode 100644
index 0000000..2a49a6b
--- /dev/null
+++ b/qt-cmake/qca/patches/ssl4.diff
@@ -0,0 +1,408 @@
+diff --git a/plugins/qca-ossl/qca-ossl.cpp b/plugins/qca-ossl/qca-ossl.cpp
+index f41fcbb5..7ab1b47d 100644
+--- a/plugins/qca-ossl/qca-ossl.cpp
++++ b/plugins/qca-ossl/qca-ossl.cpp
+@@ -281,6 +281,30 @@ static Constraints ext_only(const Constraints &list)
+ return constraints;
+ }*/
+
++// We need this to support openssl3 (could be removed once we only support
>= 4 if that ever happens)
++template<typename T> static void *our_X509V3_EXT_d2i(T *ext)
++{
++ using NonConstType = std::remove_const_t<T>;
++
++ return X509V3_EXT_d2i(const_cast<NonConstType *>(ext));
++}
++
++// We need this to support openssl1 (could be removed once we only support
>= 3 if that ever happens)
++template<typename T> static int our_X509_NAME_get_index_by_NID(T *name, int
nid, int lastpos)
++{
++ using NonConstType = std::remove_const_t<T>;
++
++ return X509_NAME_get_index_by_NID(const_cast<NonConstType *>(name),
nid, lastpos);
++}
++
++// We need this to support openssl1 (could be removed once we only support
>= 3 if that ever happens)
++template<typename T> static int our_X509_NAME_get_index_by_OBJ(T *name,
const ASN1_OBJECT *obj, int lastpos)
++{
++ using NonConstType = std::remove_const_t<T>;
++
++ return X509_NAME_get_index_by_OBJ(const_cast<NonConstType *>(name),
obj, lastpos);
++}
++
+ static void try_add_name_item(X509_NAME **name, int nid, const QString &val)
+ {
+ if (val.isEmpty())
+@@ -304,20 +328,22 @@ static X509_NAME *new_cert_name(const CertificateInfo
&info)
+ return name;
+ }
+
+-static void try_get_name_item(X509_NAME *name, int nid, const
CertificateInfoType &t, CertificateInfo *info)
++static void try_get_name_item(const X509_NAME *name, int nid, const
CertificateInfoType &t, CertificateInfo *info)
+ {
+ int loc;
+ loc = -1;
+- while ((loc = X509_NAME_get_index_by_NID(name, nid, loc)) != -1) {
+- X509_NAME_ENTRY *ne = X509_NAME_get_entry(name, loc);
+- ASN1_STRING *data = X509_NAME_ENTRY_get_data(ne);
+- QByteArray cs((const char *)data->data, data->length);
++ while ((loc = our_X509_NAME_get_index_by_NID(name, nid, loc)) != -1) {
++ const X509_NAME_ENTRY *ne = X509_NAME_get_entry(name, loc);
++ const ASN1_STRING *data = X509_NAME_ENTRY_get_data(ne);
++ QByteArray cs((const char
*)ASN1_STRING_get0_data(data), ASN1_STRING_length(data));
+ info->insert(t, QString::fromLatin1(cs));
+ }
+ }
+
+-static void
+-try_get_name_item_by_oid(X509_NAME *name, const QString &oidText, const
CertificateInfoType &t, CertificateInfo *info)
++static void try_get_name_item_by_oid(const X509_NAME *name,
++ const QString &oidText,
++ const CertificateInfoType &t,
++ CertificateInfo *info)
+ {
+ ASN1_OBJECT *oid = OBJ_txt2obj(oidText.toLatin1().data(), 1); // 1 =
only accept dotted input
+ if (!oid)
+@@ -325,17 +351,17 @@ try_get_name_item_by_oid(X509_NAME *name, const
QString &oidText, const Certific
+
+ int loc;
+ loc = -1;
+- while ((loc = X509_NAME_get_index_by_OBJ(name, oid, loc)) != -1) {
+- X509_NAME_ENTRY *ne = X509_NAME_get_entry(name, loc);
+- ASN1_STRING *data = X509_NAME_ENTRY_get_data(ne);
+- QByteArray cs((const char *)data->data, data->length);
++ while ((loc = our_X509_NAME_get_index_by_OBJ(name, oid, loc)) != -1) {
++ const X509_NAME_ENTRY *ne = X509_NAME_get_entry(name, loc);
++ const ASN1_STRING *data = X509_NAME_ENTRY_get_data(ne);
++ QByteArray cs((const char
*)ASN1_STRING_get0_data(data), ASN1_STRING_length(data));
+ info->insert(t, QString::fromLatin1(cs));
+ qDebug() << "oid: " << oidText << ", result: " << cs;
+ }
+ ASN1_OBJECT_free(oid);
+ }
+
+-static CertificateInfo get_cert_name(X509_NAME *name)
++static CertificateInfo get_cert_name(const X509_NAME *name)
+ {
+ CertificateInfo info;
+ try_get_name_item(name, NID_commonName, CommonName, &info);
+@@ -389,9 +415,9 @@ static X509_EXTENSION *new_basic_constraints(bool ca,
int pathlen)
+ return ex;
+ }
+
+-static void get_basic_constraints(X509_EXTENSION *ex, bool *ca, int
*pathlen)
++static void get_basic_constraints(const X509_EXTENSION *ex, bool *ca, int
*pathlen)
+ {
+- BASIC_CONSTRAINTS *bs = (BASIC_CONSTRAINTS *)X509V3_EXT_d2i(ex);
++ BASIC_CONSTRAINTS *bs = (BASIC_CONSTRAINTS *)our_X509V3_EXT_d2i(ex);
+ *ca = (bs->ca ? true : false);
+ if (bs->pathlen)
+ *pathlen = ASN1_INTEGER_get(bs->pathlen);
+@@ -641,10 +667,10 @@ static void try_get_general_name(GENERAL_NAMES *names,
const CertificateInfoType
+ }
+ }
+
+-static CertificateInfo get_cert_alt_name(X509_EXTENSION *ex)
++static CertificateInfo get_cert_alt_name(const X509_EXTENSION *ex)
+ {
+ CertificateInfo info;
+- GENERAL_NAMES *gn = (GENERAL_NAMES *)X509V3_EXT_d2i(ex);
++ GENERAL_NAMES *gn = (GENERAL_NAMES *)our_X509V3_EXT_d2i(ex);
+ try_get_general_name(gn, Email, &info);
+ try_get_general_name(gn, URI, &info);
+ try_get_general_name(gn, DNS, &info);
+@@ -704,7 +730,7 @@ static X509_EXTENSION *new_cert_key_usage(const
Constraints &constraints)
+ return ex;
+ }
+
+-static Constraints get_cert_key_usage(X509_EXTENSION *ex)
++static Constraints get_cert_key_usage(const X509_EXTENSION *ex)
+ {
+ Constraints constraints;
+ int bit_table[9] = {DigitalSignature,
+@@ -717,7 +743,7 @@ static Constraints get_cert_key_usage(X509_EXTENSION *ex)
+ EncipherOnly,
+ DecipherOnly};
+
+- ASN1_BIT_STRING *keyusage = (ASN1_BIT_STRING *)X509V3_EXT_d2i(ex);
++ ASN1_BIT_STRING *keyusage = (ASN1_BIT_STRING *)our_X509V3_EXT_d2i(ex);
+ for (int n = 0; n < 9; ++n) {
+ if (ASN1_BIT_STRING_get_bit(keyusage, n))
+ constraints +=
ConstraintType((ConstraintTypeKnown)bit_table[n]);
+@@ -778,11 +804,11 @@ static X509_EXTENSION *new_cert_ext_key_usage(const
Constraints &constraints)
+ return ex;
+ }
+
+-static Constraints get_cert_ext_key_usage(X509_EXTENSION *ex)
++static Constraints get_cert_ext_key_usage(const X509_EXTENSION *ex)
+ {
+ Constraints constraints;
+
+- EXTENDED_KEY_USAGE *extkeyusage = (EXTENDED_KEY_USAGE
*)X509V3_EXT_d2i(ex);
++ EXTENDED_KEY_USAGE *extkeyusage = (EXTENDED_KEY_USAGE
*)our_X509V3_EXT_d2i(ex);
+ for (int n = 0; n < sk_ASN1_OBJECT_num(extkeyusage); ++n) {
+ ASN1_OBJECT *obj = sk_ASN1_OBJECT_value(extkeyusage, n);
+ int nid = OBJ_obj2nid(obj);
+@@ -852,10 +878,10 @@ static X509_EXTENSION *new_cert_policies(const
QStringList &policies)
+ return ex;
+ }
+
+-static QStringList get_cert_policies(X509_EXTENSION *ex)
++static QStringList get_cert_policies(const X509_EXTENSION *ex)
+ {
+ QStringList out;
+- STACK_OF(POLICYINFO) *pols = (STACK_OF(POLICYINFO) *)X509V3_EXT_d2i(ex);
++ STACK_OF(POLICYINFO) *pols = (STACK_OF(POLICYINFO)
*)our_X509V3_EXT_d2i(ex);
+ for (int n = 0; n < sk_POLICYINFO_num(pols); ++n) {
+ POLICYINFO *pol = sk_POLICYINFO_value(pols, n);
+ QByteArray buf(128, 0);
+@@ -867,9 +893,9 @@ static QStringList get_cert_policies(X509_EXTENSION *ex)
+ return out;
+ }
+
+-static QByteArray get_cert_subject_key_id(X509_EXTENSION *ex)
++static QByteArray get_cert_subject_key_id(const X509_EXTENSION *ex)
+ {
+- ASN1_OCTET_STRING *skid = (ASN1_OCTET_STRING *)X509V3_EXT_d2i(ex);
++ ASN1_OCTET_STRING *skid = (ASN1_OCTET_STRING *)our_X509V3_EXT_d2i(ex);
+ const QByteArray out = qca_ASN1_STRING_toByteArray(skid);
+ ASN1_OCTET_STRING_free(skid);
+ return out;
+@@ -877,9 +903,9 @@ static QByteArray get_cert_subject_key_id(X509_EXTENSION
*ex)
+
+ // If you get any more crashes in this code, please provide a copy
+ // of the cert to bradh AT frogmouth.net
+-static QByteArray get_cert_issuer_key_id(X509_EXTENSION *ex)
++static QByteArray get_cert_issuer_key_id(const X509_EXTENSION *ex)
+ {
+- AUTHORITY_KEYID *akid = (AUTHORITY_KEYID *)X509V3_EXT_d2i(ex);
++ AUTHORITY_KEYID *akid = (AUTHORITY_KEYID *)our_X509V3_EXT_d2i(ex);
+ QByteArray out;
+ if (akid->keyid)
+ out = qca_ASN1_STRING_toByteArray(akid->keyid);
+@@ -3334,16 +3360,16 @@ class X509Item
+ // by Eric Young
+ QDateTime ASN1_UTCTIME_QDateTime(const ASN1_UTCTIME *tm, int *isGmt)
+ {
+- QDateTime qdt;
+- char *v;
+- int gmt = 0;
+- int i;
+- int y = 0, M = 0, d = 0, h = 0, m = 0, s = 0;
+- QDate qdate;
+- QTime qtime;
++ QDateTime qdt;
++ const char *v;
++ int gmt = 0;
++ int i;
++ int y = 0, M = 0, d = 0, h = 0, m = 0, s = 0;
++ QDate qdate;
++ QTime qtime;
+
+- i = tm->length;
+- v = (char *)tm->data;
++ i = ASN1_STRING_length((const ASN1_STRING *)tm);
++ v = (const char *)ASN1_STRING_get0_data((const ASN1_STRING *)tm);
+
+ if (i < 10)
+ goto auq_err;
+@@ -3672,42 +3698,42 @@ class MyCertContext : public CertContext
+ p.pathLimit = 0;
+ int pos = X509_get_ext_by_NID(x, NID_basic_constraints, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ get_basic_constraints(ex, &p.isCA, &p.pathLimit);
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_subject_alt_name, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ subject.unite(get_cert_alt_name(ex));
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_issuer_alt_name, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ issuer.unite(get_cert_alt_name(ex));
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_key_usage, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ p.constraints = get_cert_key_usage(ex);
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_ext_key_usage, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ p.constraints += get_cert_ext_key_usage(ex);
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_certificate_policies, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ p.policies = get_cert_policies(ex);
+ }
+@@ -3716,9 +3742,10 @@ class MyCertContext : public CertContext
+
+ X509_get0_signature(&signature, nullptr, x);
+ if (signature) {
+- p.sig = QByteArray(signature->length, 0);
+- for (int i = 0; i < signature->length; i++)
+- p.sig[i] = signature->data[i];
++ const int byte_len = ASN1_STRING_length((const ASN1_STRING
*)signature);
++ p.sig = QByteArray(byte_len, 0);
++ for (int i = 0; i < byte_len; i++)
++ p.sig[i] = ASN1_BIT_STRING_get_bit(signature, i);
+ }
+
+ switch (X509_get_signature_nid(x)) {
+@@ -3758,14 +3785,14 @@ class MyCertContext : public CertContext
+
+ pos = X509_get_ext_by_NID(x, NID_subject_key_identifier, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ p.subjectId += get_cert_subject_key_id(ex);
+ }
+
+ pos = X509_get_ext_by_NID(x, NID_authority_key_identifier, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_get_ext(x, pos);
+ if (ex)
+ p.issuerId += get_cert_issuer_key_id(ex);
+ }
+@@ -4175,35 +4202,35 @@ class MyCSRContext : public CSRContext
+ p.pathLimit = 0;
+ int pos = X509v3_get_ext_by_NID(exts, NID_basic_constraints,
-1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
++ const X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
+ if (ex)
+ get_basic_constraints(ex, &p.isCA, &p.pathLimit);
+ }
+
+ pos = X509v3_get_ext_by_NID(exts, NID_subject_alt_name, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
++ const X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
+ if (ex)
+ subject.unite(get_cert_alt_name(ex));
+ }
+
+ pos = X509v3_get_ext_by_NID(exts, NID_key_usage, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
++ const X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
+ if (ex)
+ p.constraints = get_cert_key_usage(ex);
+ }
+
+ pos = X509v3_get_ext_by_NID(exts, NID_ext_key_usage, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
++ const X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
+ if (ex)
+ p.constraints += get_cert_ext_key_usage(ex);
+ }
+
+ pos = X509v3_get_ext_by_NID(exts, NID_certificate_policies, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
++ const X509_EXTENSION *ex = X509v3_get_ext(exts, pos);
+ if (ex)
+ p.policies = get_cert_policies(ex);
+ }
+@@ -4214,9 +4241,10 @@ class MyCSRContext : public CSRContext
+
+ X509_REQ_get0_signature(x, &signature, nullptr);
+ if (signature) {
+- p.sig = QByteArray(signature->length, 0);
+- for (int i = 0; i < signature->length; i++)
+- p.sig[i] = signature->data[i];
++ const int byte_len = ASN1_STRING_length((const ASN1_STRING
*)signature);
++ p.sig = QByteArray(byte_len, 0);
++ for (int i = 0; i < byte_len; i++)
++ p.sig[i] = ASN1_BIT_STRING_get_bit(signature, i);
+ }
+
+ switch (X509_REQ_get_signature_nid(x)) {
+@@ -4363,9 +4391,9 @@ class MyCRLContext : public CRLContext
+ QCA::CRLEntry::Reason reason = QCA::CRLEntry::Unspecified;
+ int pos = X509_REVOKED_get_ext_by_NID(rev,
NID_crl_reason, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_REVOKED_get_ext(rev, pos);
++ const X509_EXTENSION *ex = X509_REVOKED_get_ext(rev, pos);
+ if (ex) {
+- ASN1_ENUMERATED *result = (ASN1_ENUMERATED
*)X509V3_EXT_d2i(ex);
++ ASN1_ENUMERATED *result = (ASN1_ENUMERATED
*)our_X509V3_EXT_d2i(ex);
+ switch (ASN1_ENUMERATED_get(result)) {
+ case CRL_REASON_UNSPECIFIED:
+ reason = QCA::CRLEntry::Unspecified;
+@@ -4412,9 +4440,10 @@ class MyCRLContext : public CRLContext
+
+ X509_CRL_get0_signature(x, &signature, nullptr);
+ if (signature) {
+- p.sig = QByteArray(signature->length, 0);
+- for (int i = 0; i < signature->length; i++)
+- p.sig[i] = signature->data[i];
++ const int byte_len = ASN1_STRING_length((const ASN1_STRING
*)signature);
++ p.sig = QByteArray(byte_len, 0);
++ for (int i = 0; i < byte_len; i++)
++ p.sig[i] = ASN1_BIT_STRING_get_bit(signature, i);
+ }
+
+ switch (X509_CRL_get_signature_nid(x)) {
+@@ -4454,7 +4483,7 @@ class MyCRLContext : public CRLContext
+
+ int pos = X509_CRL_get_ext_by_NID(x, NID_authority_key_identifier,
-1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_CRL_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_CRL_get_ext(x, pos);
+ if (ex)
+ p.issuerId += get_cert_issuer_key_id(ex);
+ }
+@@ -4462,9 +4491,9 @@ class MyCRLContext : public CRLContext
+ p.number = -1;
+ pos = X509_CRL_get_ext_by_NID(x, NID_crl_number, -1);
+ if (pos != -1) {
+- X509_EXTENSION *ex = X509_CRL_get_ext(x, pos);
++ const X509_EXTENSION *ex = X509_CRL_get_ext(x, pos);
+ if (ex) {
+- ASN1_INTEGER *result = (ASN1_INTEGER *)X509V3_EXT_d2i(ex);
++ ASN1_INTEGER *result = (ASN1_INTEGER
*)our_X509V3_EXT_d2i(ex);
+ p.number = ASN1_INTEGER_get(result);
+ ASN1_INTEGER_free(result);
+ }
+@@ -4994,12 +5023,17 @@ class MyTLSContext : public TLSContext
+ switch (version) {
+ #ifndef OPENSSL_NO_SSL3_METHOD
+ case TLS::SSL_v3:
++#if (OPENSSL_VERSION_NUMBER >= 0x40000000L)
++ // There is no ssl3 in openssl4
++ return {};
++#else
+ // Here should be used TLS_client_method() but on Fedora
+ // it doesn't return any SSL ciphers.
+ ctx = SSL_CTX_new(SSLv3_client_method());
+ SSL_CTX_set_min_proto_version(ctx, SSL3_VERSION);
+ SSL_CTX_set_max_proto_version(ctx, SSL3_VERSION);
+ break;
++#endif
+ #endif
+ case TLS::TLS_v1:
+ ctx = SSL_CTX_new(TLS_client_method());


  • [[SM-Commit] ] GIT changes to master grimoire by Treeve Jelbert (57f88b4e661bf959cd5d6e94dc1ed6d988fc010a), Treeve Jelbert, 08/26/2026

Archive powered by MHonArc 2.6.24.

Top of Page