Commit 6e1771a138 for openssl.org
commit 6e1771a138e801efe3a62adfb4abd73ade5e71cd
Author: Pauli <paul.dale@oracle.com>
Date: Tue Sep 1 15:34:52 2026 +1000
ssl: use generated parser for record options
Replace repeated OSSL_PARAM lookups in the common record-layer option handler with a generated trie decoder.
Assisted-by: ChatGPT:gpt-5.6Sol
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
Merge-date: Fri Oct 2 08:01:03 2026
Merged-from: https://github.com/openssl/openssl/pull/32621
diff --git a/.gitignore b/.gitignore
index a929da336a..4d084af649 100644
--- a/.gitignore
+++ b/.gitignore
@@ -99,6 +99,7 @@ providers/common/include/prov/der_ml_dsa.h
providers/common/include/prov/der_hkdf.h
providers/fips/fipsparams.inc
ssl/t1_lib.inc
+ssl/record/methods/tls_common.inc
providers/implementations/asymciphers/rsa_enc.inc
providers/implementations/asymciphers/sm2_enc.inc
providers/implementations/exchange/dh_exch.inc
diff --git a/build.info b/build.info
index a58317cf89..337c44c60b 100644
--- a/build.info
+++ b/build.info
@@ -81,6 +81,7 @@ DEPEND[]=include/openssl/asn1.h \
include/crypto/ec_params.h \
include/crypto/rsa_params.h \
ssl/t1_lib.inc \
+ ssl/record/methods/tls_common.inc \
providers/implementations/asymciphers/rsa_enc.inc \
providers/implementations/asymciphers/sm2_enc.inc \
providers/implementations/exchange/dh_exch.inc \
@@ -223,6 +224,7 @@ GENERATE[include/openssl/x509_vfy.h]=include/openssl/x509_vfy.h.in
GENERATE[include/crypto/dso_conf.h]=include/crypto/dso_conf.h.in
DEPEND[ssl/t1_lib.inc \
+ ssl/record/methods/tls_common.inc \
providers/implementations/asymciphers/rsa_enc.inc \
providers/implementations/asymciphers/sm2_enc.inc \
providers/implementations/exchange/dh_exch.inc \
@@ -333,6 +335,8 @@ GENERATE[include/crypto/ec_params.h]=\
GENERATE[include/crypto/rsa_params.h]=\
include/crypto/rsa_params.h.in
GENERATE[ssl/t1_lib.inc]=ssl/t1_lib.inc.in
+GENERATE[ssl/record/methods/tls_common.inc]=\
+ ssl/record/methods/tls_common.inc.in
GENERATE[providers/implementations/asymciphers/rsa_enc.inc]=\
providers/implementations/asymciphers/rsa_enc.inc.in
GENERATE[providers/implementations/asymciphers/sm2_enc.inc]=\
diff --git a/ssl/record/methods/tls_common.c b/ssl/record/methods/tls_common.c
index 5773cb393c..fcbf585277 100644
--- a/ssl/record/methods/tls_common.c
+++ b/ssl/record/methods/tls_common.c
@@ -21,6 +21,7 @@
#include "../../ssl_local.h"
#include "../record_local.h"
#include "recmethod_local.h"
+#include "ssl/record/methods/tls_common.inc"
static void tls_int_free(OSSL_RECORD_LAYER *rl);
@@ -1162,36 +1163,37 @@ int tls_release_record(OSSL_RECORD_LAYER *rl, void *rechandle, size_t length)
int tls_set_options(OSSL_RECORD_LAYER *rl, const OSSL_PARAM *options)
{
+ struct tls_set_options_params_st prms;
const OSSL_PARAM *p;
- p = OSSL_PARAM_locate_const(options, OSSL_LIBSSL_RECORD_LAYER_PARAM_OPTIONS);
+ if (!tls_set_options_params_decoder(options, &prms))
+ return 0;
+
+ p = prms.options;
if (p != NULL && !OSSL_PARAM_get_uint64(p, &rl->options)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
}
- p = OSSL_PARAM_locate_const(options, OSSL_LIBSSL_RECORD_LAYER_PARAM_MODE);
+ p = prms.mode;
if (p != NULL && !OSSL_PARAM_get_uint32(p, &rl->mode)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
}
if (rl->direction == OSSL_RECORD_DIRECTION_READ) {
- p = OSSL_PARAM_locate_const(options,
- OSSL_LIBSSL_RECORD_LAYER_READ_BUFFER_LEN);
+ p = prms.rbuf_len;
if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->rbuf.default_len)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
}
} else {
- p = OSSL_PARAM_locate_const(options,
- OSSL_LIBSSL_RECORD_LAYER_PARAM_BLOCK_PADDING);
+ p = prms.blockpad;
if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->block_padding)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
}
- p = OSSL_PARAM_locate_const(options,
- OSSL_LIBSSL_RECORD_LAYER_PARAM_HS_PADDING);
+ p = prms.hspad;
if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->hs_padding)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
@@ -1205,8 +1207,7 @@ int tls_set_options(OSSL_RECORD_LAYER *rl, const OSSL_PARAM *options)
* that is destined for a higher protection level. To simplify the logic
* we don't support that at this stage.
*/
- p = OSSL_PARAM_locate_const(options,
- OSSL_LIBSSL_RECORD_LAYER_PARAM_READ_AHEAD);
+ p = prms.readahead;
if (p != NULL && !OSSL_PARAM_get_int(p, &rl->read_ahead)) {
ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
return 0;
diff --git a/ssl/record/methods/tls_common.inc.in b/ssl/record/methods/tls_common.inc.in
new file mode 100644
index 0000000000..9a34da880b
--- /dev/null
+++ b/ssl/record/methods/tls_common.inc.in
@@ -0,0 +1,32 @@
+/*
+ * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License"). You may not use
+ * this file except in compliance with the License. You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+{-
+use OpenSSL::paramnames qw(produce_param_decoder);
+
+sub produce_ssl_param_decoder {
+ my $decoder = produce_param_decoder(@_);
+
+ # Adapt the provider-oriented decoder errors for libssl.
+ $decoder =~ s|#include "prov/proverr.h"|#include <openssl/err.h>|;
+ $decoder =~ s/ERR_LIB_PROV/ERR_LIB_SSL/g;
+ $decoder =~ s/PROV_R_REPEATED_PARAMETER/ERR_R_PASSED_INVALID_ARGUMENT/g;
+ return $decoder;
+}
+-}
+
+#define tls_set_options_params_list
+{- produce_ssl_param_decoder('tls_set_options_params',
+ (['OSSL_LIBSSL_RECORD_LAYER_PARAM_OPTIONS', 'options', 'uint64'],
+ ['OSSL_LIBSSL_RECORD_LAYER_PARAM_MODE', 'mode', 'uint32'],
+ ['OSSL_LIBSSL_RECORD_LAYER_READ_BUFFER_LEN', 'rbuf_len', 'size_t'],
+ ['OSSL_LIBSSL_RECORD_LAYER_PARAM_BLOCK_PADDING', 'blockpad', 'size_t'],
+ ['OSSL_LIBSSL_RECORD_LAYER_PARAM_HS_PADDING', 'hspad', 'size_t'],
+ ['OSSL_LIBSSL_RECORD_LAYER_PARAM_READ_AHEAD', 'readahead', 'int'],
+ )); -}