Matt Caswell a2f27fd750 Move the rand_nonce_lock code into drbg_lib.c 5 éve
..
aes 66ad63e801 Make basic AES ciphers available from within the FIPS providers 5 éve
aria 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
asn1 6aa2e59e1c Add d2i_KeyParams/i2d_KeyParams API's. 5 éve
async 9f5a87fd66 add an additional async notification communication method based on callback 5 éve
bf 8b00b7b8b3 Following the license change, modify the boilerplates in crypto/bf/ 6 éve
bio d34bce03ac Add testing of RDONLY memory BIOs 5 éve
blake2 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
bn 3e3dcf9ab8 Call RSA generation callback at the correct time. 5 éve
buffer 0c4fa1f10d Following the license change, modify the boilerplates in crypto/buffer/ 6 éve
camellia 5593d9c952 Following the license change, modify the boilerplates in crypto/camellia/ 6 éve
cast a5024e0609 Following the license change, modify the boilerplates in crypto/cast/ 6 éve
chacha 302aa3c26d s390x assembly pack: remove chacha20 dependency on non-base memnonics 5 éve
cmac 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
cmp 8869ad4a39 Certificate Management Protocol (CMP, RFC 4210) extension to OpenSSL 5 éve
cms 19e512a824 Add the content type attribute to additional CMS signerinfo. 5 éve
comp 48f66f8115 Following the license change, modify the boilerplates in crypto/comp/ 6 éve
conf f4a96507fb crypto/conf: openssl_config_int() returns unitialized value 5 éve
crmf 8869ad4a39 Certificate Management Protocol (CMP, RFC 4210) extension to OpenSSL 5 éve
ct 5477e84273 Following the license change, modify the boilerplates in crypto/ct/ 6 éve
des df4439186f Remove unnecessary trailing whitespace 5 éve
dh 70b0b977f7 Change default RSA, DSA and DH size to 2048 bit 5 éve
dsa cd4c83b524 The SHA256 is not a mandatory digest for DSA. 5 éve
dso 31b6ed76df Rework DSO API conditions and configuration option 5 éve
ec 8be6a4ed02 Fix various mistakes in ec_GFp_nistp_recode_scalar_bits comment. 5 éve
engine 21d9856986 Coverity CID 1444957: Error handling issues 5 éve
err be5fc053ed Replace EVP_MAC_CTX_copy() by EVP_MAC_CTX_dup() 5 éve
ess 9fdcc21fdc constify *_dup() and *i2d_*() and related functions as far as possible, introducing DECLARE_ASN1_DUP_FUNCTION 5 éve
evp 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
gmac 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
hmac 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
idea aa2d9a76b4 Following the license change, modify the boilerplates in crypto/idea/ 6 éve
include da0d114cd9 Convert drbg_lib to use OPENSSL_CTX for its global data 5 éve
kdf be5fc053ed Replace EVP_MAC_CTX_copy() by EVP_MAC_CTX_dup() 5 éve
kmac 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
lhash 319e518a5a Make some EVP code available from within the FIPS module 5 éve
md2 4911f55362 Following the license change, modify the boilerplates in crypto/mdN/ 6 éve
md4 4911f55362 Following the license change, modify the boilerplates in crypto/mdN/ 6 éve
md5 d5e5e2ffaf Move digests to providers 5 éve
mdc2 2bcb0fc862 Following the license change, modify the boilerplates in crypto/mdc2/ 6 éve
modes be5fc053ed Replace EVP_MAC_CTX_copy() by EVP_MAC_CTX_dup() 5 éve
objects 53bfacf220 Fix GOST OID 5 éve
ocsp 878dc8dd95 Join the x509 and x509v3 directories 5 éve
pem 8cf85d4899 Fix the allocation size in EVP_OpenInit and PEM_SignFinal 5 éve
perlasm 3062468b0a s390x assembly pack: update perlasm module 5 éve
pkcs12 9fdcc21fdc constify *_dup() and *i2d_*() and related functions as far as possible, introducing DECLARE_ASN1_DUP_FUNCTION 5 éve
pkcs7 9fdcc21fdc constify *_dup() and *i2d_*() and related functions as far as possible, introducing DECLARE_ASN1_DUP_FUNCTION 5 éve
poly1305 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
property b6db5b3d50 Remove file reference from property documentation. 5 éve
rand a2f27fd750 Move the rand_nonce_lock code into drbg_lib.c 5 éve
rc2 5e4435a760 Following the license change, modify the boilerplates in crypto/rcN/ 6 éve
rc4 1039c78255 Build: correct assembler generation in crypto/rc4/build.info 5 éve
rc5 5e4435a760 Following the license change, modify the boilerplates in crypto/rcN/ 6 éve
ripemd 57946a26b6 Following the license change, modify the boilerplates in crypto/ripemd/ 6 éve
rsa 70b0b977f7 Change default RSA, DSA and DH size to 2048 bit 5 éve
seed 39c44eee7f Following the license change, modify the boilerplates in crypto/seed/ 6 éve
sha d5e5e2ffaf Move digests to providers 5 éve
siphash 7ed66e2634 Change EVP_MAC method from copy to dup 5 éve
sm2 8267becb8b Support SM2 certificate verification 5 éve
sm3 d5e5e2ffaf Move digests to providers 5 éve
sm4 f9f859adc6 Following the license change, modify the boilerplates in crypto/smN/ 6 éve
srp df4439186f Remove unnecessary trailing whitespace 5 éve
stack 3593266d1c Make core code available within the FIPS module 5 éve
store 5c0d0c86af Following the license change, modify the boilerplates in crypto/store/ 6 éve
ts 9fdcc21fdc constify *_dup() and *i2d_*() and related functions as far as possible, introducing DECLARE_ASN1_DUP_FUNCTION 5 éve
txt_db 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
ui 5c8b7b4caa Cleanup vxworks support to be able to compile for VxWorks 7 5 éve
whrlpool 677c7ab9ea Following the license change, modify the boilerplates in crypto/whrlpool/ 6 éve
x509 bab6046146 Replace BIO_printf with ASN1_STRING_print in GENERAL_NAME_print 5 éve
LPdir_nyi.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
LPdir_unix.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
LPdir_vms.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
LPdir_win.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
LPdir_win32.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
LPdir_wince.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
README.sparse_array a40f0f6475 Add sparse array data type. 5 éve
alphacpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
arm64cpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
arm_arch.h 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
armcap.c 5f40dd158c crypto/armcap.c, crypto/ppccap.c: stricter use of getauxval() 5 éve
armv4cpuid.pl 3405db97e5 ARM assembly pack: make it Windows-friendly. 5 éve
bsearch.c 5c3f1e34b5 ossl_bsearch(): New generic internal binary search utility function 5 éve
build.info 41525ed628 Ensure we get all the right defines for AES assembler in FIPS module 5 éve
c64xpluscpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
context.c 3593266d1c Make core code available within the FIPS module 5 éve
core_fetch.c d5e5e2ffaf Move digests to providers 5 éve
core_namemap.c f2182a4e6f Create internal number<->name mapping API 5 éve
cpt_err.c 1aedc35fd6 Instead of global data store it in an OPENSSL_CTX 5 éve
cryptlib.c df4439186f Remove unnecessary trailing whitespace 5 éve
ctype.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
cversion.c 47ca833835 Add the possibility to display and use MODULESDIR 5 éve
dllmain.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
ebcdic.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
ex_data.c 1f76076095 Coverity CID 1444951: Null pointer dereferences 5 éve
getenv.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
ia64cpuid.S 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
info.c 0109e030db Add a way for the application to get OpenSSL configuration data 5 éve
init.c a2f27fd750 Move the rand_nonce_lock code into drbg_lib.c 5 éve
mem.c 9efa0ae0b6 Create a FIPS provider and put SHA256 in it 5 éve
mem_clr.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
mem_dbg.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
mem_sec.c 61783db5b5 Use vxRandLib for VxWorks7 5 éve
mips_arch.h 1b9c5f2e2f Fix compiling error for mips32r6 and mips64r6 5 éve
o_dir.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
o_fips.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
o_fopen.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
o_init.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
o_str.c e3b35d2b29 openssl_strerror_r: Fix handling of GNU strerror_r 5 éve
o_time.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
params.c 9830e7ea42 Params conversion tests. 5 éve
pariscid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
ppc_arch.h c8f370485c PPC: Try out if mftb works before using it 5 éve
ppccap.c 41525ed628 Ensure we get all the right defines for AES assembler in FIPS module 5 éve
ppccpuid.pl c8f370485c PPC: Try out if mftb works before using it 5 éve
provider.c 24626a47fb Constify OSSL_PROVIDER getter input parameters 5 éve
provider_conf.c 71849dff56 Rename the PROVIDER_CONF trace to CONF 5 éve
provider_core.c ad14e8e508 Coverity fixes 5 éve
provider_local.h c41f3ae0d9 Replumbing: Add a mechanism to pre-populate the provider store 5 éve
provider_predefined.c 3593266d1c Make core code available within the FIPS module 5 éve
s390x_arch.h 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
s390xcap.c 61d7045bd2 fix --strict-warnings build 5 éve
s390xcpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
sparc_arch.h 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
sparccpuid.S 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
sparcv9cap.c 41525ed628 Ensure we get all the right defines for AES assembler in FIPS module 5 éve
sparse_array.c 8ab53b193a Make the sparse array code use ossl_uintmax_t as its index rather than size_t. 5 éve
threads_none.c 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
threads_pthread.c 3593266d1c Make core code available within the FIPS module 5 éve
threads_win.c 09305a7d0a Avoid linking error for InitializeCriticalSectionAndSpinCount(). 5 éve
trace.c bc362b9b72 Convert the ENGINE_CONF trace calls to use CONF instead 5 éve
uid.c aefb980c45 crypto/uid.c: use own macro as guard rather than AT_SECURE 5 éve
vms_rms.h 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
x86_64cpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve
x86cpuid.pl 0e9725bcb9 Following the license change, modify the boilerplates in crypto/ 6 éve

README.sparse_array

The sparse_array.c file contains an implementation of a sparse array that
attempts to be both space and time efficient.

The sparse array is represented using a tree structure. Each node in the
tree contains a block of pointers to either the user supplied leaf values or
to another node.

There are a number of parameters used to define the block size:

OPENSSL_SA_BLOCK_BITS Specifies the number of bits covered by each block
SA_BLOCK_MAX Specifies the number of pointers in each block
SA_BLOCK_MASK Specifies a bit mask to perform modulo block size
SA_BLOCK_MAX_LEVELS Indicates the maximum possible height of the tree

These constants are inter-related:
SA_BLOCK_MAX = 2 ^ OPENSSL_SA_BLOCK_BITS
SA_BLOCK_MASK = SA_BLOCK_MAX - 1
SA_BLOCK_MAX_LEVELS = number of bits in size_t divided by
OPENSSL_SA_BLOCK_BITS rounded up to the next multiple
of OPENSSL_SA_BLOCK_BITS

OPENSSL_SA_BLOCK_BITS can be defined at compile time and this overrides the
built in setting.

As a space and performance optimisation, the height of the tree is usually
less than the maximum possible height. Only sufficient height is allocated to
accommodate the largest index added to the data structure.

The largest index used to add a value to the array determines the tree height:

+----------------------+---------------------+
| Largest Added Index | Height of Tree |
+----------------------+---------------------+
| SA_BLOCK_MAX - 1 | 1 |
| SA_BLOCK_MAX ^ 2 - 1 | 2 |
| SA_BLOCK_MAX ^ 3 - 1 | 3 |
| ... | ... |
| size_t max | SA_BLOCK_MAX_LEVELS |
+----------------------+---------------------+

The tree height is dynamically increased as needed based on additions.

An empty tree is represented by a NULL root pointer. Inserting a value at
index 0 results in the allocation of a top level node full of null pointers
except for the single pointer to the user's data (N = SA_BLOCK_MAX for
breviety):

+----+
|Root|
|Node|
+-+--+
|
|
|
v
+-+-+---+---+---+---+
| 0 | 1 | 2 |...|N-1|
| |nil|nil|...|nil|
+-+-+---+---+---+---+
|
|
|
v
+-+--+
|User|
|Data|
+----+
Index 0


Inserting at element 2N+1 creates a new root node and pushes down the old root
node. It then creates a second second level node to hold the pointer to the
user's new data:

+----+
|Root|
|Node|
+-+--+
|
|
|
v
+-+-+---+---+---+---+
| 0 | 1 | 2 |...|N-1|
| |nil| |...|nil|
+-+-+---+-+-+---+---+
| |
| +------------------+
| |
v v
+-+-+---+---+---+---+ +-+-+---+---+---+---+
| 0 | 1 | 2 |...|N-1| | 0 | 1 | 2 |...|N-1|
|nil| |nil|...|nil| |nil| |nil|...|nil|
+-+-+---+---+---+---+ +---+-+-+---+---+---+
| |
| |
| |
v v
+-+--+ +-+--+
|User| |User|
|Data| |Data|
+----+ +----+
Index 0 Index 2N+1


The nodes themselves are allocated in a sparse manner. Only nodes which exist
along a path from the root of the tree to an added leaf will be allocated.
The complexity is hidden and nodes are allocated on an as needed basis.
Because the data is expected to be sparse this doesn't result in a large waste
of space.

Values can be removed from the sparse array by setting their index position to
NULL. The data structure does not attempt to reclaim nodes or reduce the
height of the tree on removal. For example, now setting index 0 to NULL would
result in:

+----+
|Root|
|Node|
+-+--+
|
|
|
v
+-+-+---+---+---+---+
| 0 | 1 | 2 |...|N-1|
| |nil| |...|nil|
+-+-+---+-+-+---+---+
| |
| +------------------+
| |
v v
+-+-+---+---+---+---+ +-+-+---+---+---+---+
| 0 | 1 | 2 |...|N-1| | 0 | 1 | 2 |...|N-1|
|nil|nil|nil|...|nil| |nil| |nil|...|nil|
+---+---+---+---+---+ +---+-+-+---+---+---+
|
|
|
v
+-+--+
|User|
|Data|
+----+
Index 2N+1


Accesses to elements in the sparse array take O(log n) time where n is the
largest element. The base of the logarithm is SA_BLOCK_MAX, so for moderately
small indices (e.g. NIDs), single level (constant time) access is achievable.
Space usage is O(minimum(m, n log(n)) where m is the number of elements in the
array.

Note: sparse arrays only include pointers to types. Thus, SPARSE_ARRAY_OF(char)
can be used to store a string.