1. Aug 04, 2022
  2. Jul 12, 2022
    • Alex Chernyakhovsky's avatar
      0982212c
    • Alex Chernyakhovsky's avatar
      Add macOS release steps to Github Actions · 7f0c3a41
      Alex Chernyakhovsky authored
      This change ports the Travis CI release workflow for macOS to Github
      Actions. Note that while this is functionally identical to the
      previous Travis CI flow, no work has been done to update the macOS
      build scripts to build for arm64.
      7f0c3a41
    • Alex Chernyakhovsky's avatar
      Add release action on Linux · f0b0108c
      Alex Chernyakhovsky authored
      This Github Actions workflow uses a Linux-based running to create the
      release tarball for mosh. This is necessary since mosh does not check
      in the autoconf/automake generated files, so the default release
      action source download is missing files that are needed for
      distributions that use the upstream-provided ./configure script.
      f0b0108c
  3. Jul 06, 2022
  4. Jun 28, 2022
  5. Jun 23, 2022
    • Benjamin Barenblat's avatar
      Go back to internal OCB implementation · bacc0240
      Benjamin Barenblat authored
      After further discussion, the Mosh maintainers have decided to stick
      with the internal OCB implementation for this release. Restore support
      for using OpenSSL’s AES but internal OCB. To make this commit easy to
      audit, restore the code exactly, including calls to AES functions that
      are deprecated in OpenSSL 3; a future commit will update ocb_internal.cc
      to use EVP instead of directly calling the AES primitives.
      
      In anticipation of future changes, preserve support for OpenSSL’s
      AES-OCB, but don’t compile it in. Add
      --with-crypto-library=openssl-with-openssl-ocb and
      --with-crypto-library=openssl-with-internal-ocb options to configure so
      that developers can easily test Mosh using OpenSSL’s AES-OCB. These
      options are intended only for testing, are undocumented, and are not
      subject to any API stability guarantees.
      
      Rework configure to look for all possible cryptography libraries first
      and then dispatch on --with-crypto-library as appropriate.
      bacc0240
  6. Jun 14, 2022
    • Alex Chernyakhovsky's avatar
      Use OpenSSL native OCB-AES implementation · 135a11a2
      Alex Chernyakhovsky authored
      OpenSSL 3.0 deprecated many of the functions that ocb.cc used to
      implement OCB-AES, causing a build failure when -Wdeprecated collided
      with -Werror. Debian temporarily fixed this by suppressing the error
      in #1191.
      
      Since mosh 1.4 will be the next stable release of mosh, it should not
      depend on deprecated functions in OpenSSL. Since version 1.1.0,
      OpenSSL natively supports OCB-AES through the EVP_CIPHER API. @cgull
      started early support for this in #924.
      
      This change extends upon the previous work by @cgull in a few ways
      
       * EVP_CipherInit_ex is called in ae_init to set up the
         EVP_CIPHER_CTX. It is later called in ae_encrypt and ae_decrypt
         just to load nonce (IV in OpenSSL EVP parlance), which reduces the
         amount of initialization done per-packet. However, due to OpenSSL
         API limitations, two copies of the EVP_CIPHER_CTX are kept: one for
         encryption, and one for decryption.
      
       * Adds missing support for an external tag, rather than just one
         appended to the ciphertext
      
       * Support for non-default-sized tags
      
      as well as some improved error handling.
      
      Note that this change raises the minimum OpenSSL version for Mosh to
      1.1.0. OpenSSL does not provide security support for versions prior to
      1.1 at this time, so this is in principle reasonable dependency. If we
      want to continue to support distributions (such as RHEL7) which
      continue to be supported by their vendor but use an unsupported
      OpenSSL, then some future work will have to restore the ocb.cc
      implementation that uses the deprecated functions.
      
      Bugs: #1174
      135a11a2
  7. Jun 07, 2022
    • Benjamin Barenblat's avatar
      Separate OpenSSL-based OCB implementation from others · a563093f
      Benjamin Barenblat authored
      Split src/crypto/ocb.cc into two files – one containing the AES-OCB
      implementation backed by OpenSSL, and the other containing
      implementations backed by Apple Common Crypto and Nettle. This paves the
      way for a new OpenSSL implementation that uses OpenSSL 1.1’s OCB support
      directly, rather than one that merely uses OpenSSL to provide the
      underlying block cipher.
      
      Remove support for rijndael-alg-fst.c and compiler-provided AES
      intrinsics, since they’re not in use anymore. (Mosh can still use
      hardware-accelerated AES if it’s available; it just now relies
      exclusively on the underlying cryptography library to accelerate AES if
      possible.)
      
      Update the build system to conditionally compile in either
      ocb_openssl.cc or ocb_internal.cc, depending on which cryptography
      library you pass to ./configure.
      
      To make this commit easy to audit, ocb_openssl.cc and ocb_internal.cc
      are trivially diffable against ocb.cc (now deleted). Expected diffs
      consist of a copyr...
      a563093f
  8. May 31, 2022
  9. Feb 05, 2022
  10. Dec 11, 2021
  11. Dec 09, 2021
  12. Nov 05, 2021
  13. Oct 29, 2021
  14. Oct 21, 2021
  15. Aug 27, 2021
  16. Jul 21, 2021
  17. Jul 14, 2021
  18. Dec 06, 2020
  19. May 18, 2020