1. Aug 21, 2012
  2. Aug 17, 2012
  3. Aug 16, 2012
  4. Aug 15, 2012
    • isaacs's avatar
      npm: Upgrade to 1.1.49 · 3ccee087
      isaacs authored
      - node-gyp@0.6.5
      - abstracted-out configs
      - publishing over proxies
      - bugfixes to all the deps
      3ccee087
    • Ben Noordhuis's avatar
      crypto: fix uninitialized memory access in openssl · 2c13cbbc
      Ben Noordhuis authored
      ASN1_STRING_to_UTF8() passes an ASN1_STRING to ASN1_STRING_set() but forgot to
      initialize the `length` field.
      
      Fixes the following valgrind error:
      
        $ valgrind -q --track-origins=yes --num-callers=19 \
            out/Debug/node test/simple/test-tls-client-abort.js
        ==2690== Conditional jump or move depends on uninitialised value(s)
        ==2690==    at 0x784B69: ASN1_STRING_set (asn1_lib.c:382)
        ==2690==    by 0x809564: ASN1_mbstring_ncopy (a_mbstr.c:204)
        ==2690==    by 0x8090F0: ASN1_mbstring_copy (a_mbstr.c:86)
        ==2690==    by 0x782F1F: ASN1_STRING_to_UTF8 (a_strex.c:570)
        ==2690==    by 0x78F090: asn1_string_canon (x_name.c:409)
        ==2690==    by 0x78EF17: x509_name_canon (x_name.c:354)
        ==2690==    by 0x78EA7D: x509_name_ex_d2i (x_name.c:210)
        ==2690==    by 0x788058: ASN1_item_ex_d2i (tasn_dec.c:239)
        ==2690==    by 0x7890D4: asn1_template_noexp_d2i (tasn_dec.c:746)
        ==2690==    by 0x788CB6: asn1_template_ex_d2i (tasn_dec.c:607)
        ==2690==    by 0x78877A: ASN1_item_ex_d2i (tasn_dec.c:448)
        ==2690==    by 0x7890D4: asn1_template_noexp_d2i (tasn_dec.c:746)
        ==2690==    by 0x788CB6: asn1_template_ex_d2i (tasn_dec.c:607)
        ==2690==    by 0x78877A: ASN1_item_ex_d2i (tasn_dec.c:448)
        ==2690==    by 0x787C93: ASN1_item_d2i (tasn_dec.c:136)
        ==2690==    by 0x78F5E4: d2i_X509 (x_x509.c:141)
        ==2690==    by 0x7C9B91: PEM_ASN1_read_bio (pem_oth.c:81)
        ==2690==    by 0x7CA506: PEM_read_bio_X509 (pem_x509.c:67)
        ==2690==    by 0x703C9A: node::crypto::SecureContext::AddRootCerts(v8::Arguments const&) (node_crypto.cc:497)
        ==2690==  Uninitialised value was created by a stack allocation
        ==2690==    at 0x782E89: ASN1_STRING_to_UTF8 (a_strex.c:560)
      2c13cbbc
    • Ben Noordhuis's avatar
      test: fix up `make valgrind-test` · 90ea6810
      Ben Noordhuis authored
      * valgrind complained too much about memory leaks from the V8 heap to be
        useful, run it with --leak-check=no. Not ideal, needs to be revisited,
        preferably with a suppression file.
      
      * tools/run-valgrind.py didn't deal with tests that logged to stderr, rewrite
        the heuristic and make valgrind write to a socket instead of stderr.
      
      Fixes #3869.
      90ea6810
    • Ben Noordhuis's avatar
      test: raise pummel/test-net-throttle write req size · bcb5bdeb
      Ben Noordhuis authored
      pummel/test-net-throttle assumes that a couple of big write requests result in
      some of them getting queued because the kernel's send buffer fills up.
      
      Said assumption breaks on systems with large send buffers. Raise the size of
      the write request to ameliorate the issue.
      
      This is a back-port of commit 67705555 from the master branch.
      bcb5bdeb
    • Ben Noordhuis's avatar
      de32b389
    • Ben Noordhuis's avatar
      buffer, crypto: fix buffer decoding · 786e1e87
      Ben Noordhuis authored
      Before this commit, DecodeWrite() mistakenly tried to convert buffers to
      UTF-8 strings which:
      
        a) produced invalid character sequences when the buffer contained
           octets > 127, and
        b) lead to spurious test failures because DecodeWrite() wrote less bytes
           than DecodeBytes() said it would, with the remainder either containing
           zeros or garbage
      
      Fix that by simply copying the buffer's data to the target buffer when the
      encoding is BINARY or by converting the buffer to a binary string when it's
      UTF8 or ASCII.
      
      Fixes #3651, #3866.
      786e1e87
  5. Aug 14, 2012
    • isaacs's avatar
      module: use 'repl' as the filename arg if missing · 22804a9e
      isaacs authored
      Fix #3859
      22804a9e
    • isaacs's avatar
      events: emitter.listeners() should not have side effects · 50c7d80f
      isaacs authored
      Fixes #3803
      50c7d80f
    • jbergstroem's avatar
      bench: fetch port from env · 8eccc417
      jbergstroem authored
      http_simple.js honors $PORT, http_simple_bench.sh should too.
      8eccc417
    • Ben Noordhuis's avatar
      tls: fix segfault in pummel/test-tls-ci-reneg-attack · c492d43f
      Ben Noordhuis authored
      Commit 4e5fe2d4 changed the way how process.nextTick() works:
      
          process.nextTick(function foo() {
            process.nextTick(function bar() {
              // ...
            });
          });
      
      Before said commit, foo() and bar() used to run on separate event loop ticks
      but that is no longer the case.
      
      However, that's exactly the behavior that the TLS renegotiation attack guard
      relies on. It gets called by OpenSSL and needs to defer the 'error' event to a
      later tick because the default action is to destroy the TLS context - the same
      context that OpenSSL currently operates on.
      
      When things change underneath your feet, bad things happen and OpenSSL is no
      exception. Ergo, use setImmediate() instead of process.nextTick() to ensure
      that the 'error' event is actually emitted at a later tick.
      
      Fixes #3840.
      c492d43f
  6. Aug 13, 2012