Skip to content

Compat layer: escape control characters in X509 print output - #11682

Open
padelsbach wants to merge 11 commits into
wolfSSL:masterfrom
padelsbach:byteray-med-x509
Open

padelsbach wants to merge 11 commits into
wolfSSL:masterfrom
padelsbach:byteray-med-x509

Conversation

@padelsbach

@padelsbach padelsbach commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

Escape control characters in the compat layer print functions, matching
OpenSSL. Previously certificate, CRL and CSR fields were printed as-is,
so a crafted certificate could inject content into the output:

  • CR/LF can add fake lines, such as a second Subject: or alt name, to
    output that applications log or show to users
  • ESC can add terminal escape sequences when the output goes to a
    terminal

Fixes issues:
-M05-2
-M05-3
-M05-4
-M05-5
-M05-6
-M05-7
-M05-8
-M05-9
-M19-2

Testing

Added unit tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:35
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .rodata -24 B, .text +256 B (+0.0%, 792,516 B / 1,048,576 B, total: 76% used)

gcc-arm-cortex-m4-pq

  • FLASH: .text +64 B (+0.0%, 308,656 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .rodata -8 B, .text +2,432 B (+0.7%, 340,904 B / 1,048,576 B, total: 33% used)

linuxkm-standard

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Some general-name paths remain injectable, and expanded values can unexpectedly make printing fail.

2 open findings
What changed in this PR

Adds control-character escaping to OpenSSL-compatible X.509 print output.

Changes:

  • Escapes control characters in certificate, CRL, CSR, SAN, and ACERT fields.
  • Adds regression tests and a memory-BIO test helper.
  • Corrects verification parameter hostFlags inheritance.
File Description
src/​x509.c Implements escaping and hostFlags inheritance.
wolfssl/​openssl/​x509.h Enables control escaping for one-line names.
tests/​utils.c Adds memory-BIO conversion helper.
tests/​utils.h Declares the BIO helper.
tests/​api.c Tests certificate, CRL, CSR, and SAN output.
tests/​api/​test_ossl_x509_acert.c Tests ACERT escaping.
tests/​api/​test_ossl_x509_acert.h Registers the ACERT test.
tests/​api/​test_ossl_x509_vp.c Tests hostFlags inheritance.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/x509.c Outdated
Comment thread tests/api.c
@padelsbach

Copy link
Copy Markdown
Contributor Author

jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants