Move more comments that confuse indent
authorMatt Caswell <matt@openssl.org>
Wed, 21 Jan 2015 19:18:47 +0000 (19:18 +0000)
committerMatt Caswell <matt@openssl.org>
Thu, 22 Jan 2015 09:28:49 +0000 (09:28 +0000)
Conflicts:
crypto/dsa/dsa.h
demos/engines/ibmca/hw_ibmca.c
ssl/ssl_locl.h

Reviewed-by: Tim Hudson <tjh@openssl.org>
34 files changed:
apps/apps.c
apps/ca.c
apps/passwd.c
apps/s_apps.h
apps/s_server.c
crypto/bio/bss_bio.c
crypto/bio/bss_rtcp.c
crypto/bn/bn_lib.c
crypto/bn/rsaz_exp.c
crypto/crypto.h
crypto/des/des_ver.h
crypto/dsa/dsa.h
crypto/ec/ec2_oct.c
crypto/ec/ecp_nistp256.c
crypto/ec/ecp_nistp521.c
crypto/ec/ecp_nistputil.c
crypto/ec/ecp_oct.c
crypto/evp/e_aes_cbc_hmac_sha1.c
crypto/evp/e_aes_cbc_hmac_sha256.c
crypto/modes/gcm128.c
crypto/rand/md_rand.c
crypto/seed/seed.h
crypto/x509/x509.h
demos/engines/ibmca/hw_ibmca.c
engines/e_chil.c
engines/e_sureware.c
engines/e_ubsec.c
ssl/d1_pkt.c
ssl/kssl.c
ssl/ssl.h
ssl/ssl_locl.h
ssl/ssl_task.c
ssl/ssltest.c
ssl/t1_enc.c

index 2d7b70a9654874d4c2a60e94e11e2eef7f84bddc..501c464915ae76c03312e5d61045fd365673cee0 100644 (file)
  */
 
 #if !defined(_POSIX_C_SOURCE) && defined(OPENSSL_SYS_VMS)
-#define _POSIX_C_SOURCE 2      /* On VMS, you need to define this to get
-                                  the declaration of fileno().  The value
-                                  2 is to make sure no function defined
-                                  in POSIX-2 is left undefined. */
+/* On VMS, you need to define this to get
+ * the declaration of fileno().  The value
+ * 2 is to make sure no function defined
+ * in POSIX-2 is left undefined.
+ */
+#define _POSIX_C_SOURCE 2
 #endif
 #include <stdio.h>
 #include <stdlib.h>
index 588d8896c99b6bb1a8c3151178fe092afb213fe1..b1311d6b196b342d7ebcee812ca4e115910dff2d 100644 (file)
--- a/apps/ca.c
+++ b/apps/ca.c
@@ -1497,7 +1497,8 @@ bad:
                        }
 
                
-               if (crlnumberfile != NULL)      /* we have a CRL number that need updating */
+               /* we have a CRL number that need updating */
+               if (crlnumberfile != NULL)
                        if (!save_serial(crlnumberfile,"new",crlnumber,NULL)) goto err;
 
                if (crlnumber)
index 8e65ed7cbb976a53f36dee28a6492aa4abf5f33d..e12b5ecea8e92a1b94021fe4d7e1351b0622849c 100644 (file)
@@ -310,7 +310,8 @@ err:
  */
 static char *md5crypt(const char *passwd, const char *magic, const char *salt)
        {
-       static char out_buf[6 + 9 + 24 + 2]; /* "$apr1$..salt..$.......md5hash..........\0" */
+       /* "$apr1$..salt..$.......md5hash..........\0" */
+       static char out_buf[6 + 9 + 24 + 2];
        unsigned char buf[MD5_DIGEST_LENGTH];
        char *salt_out;
        int n;
index f46d1ebe45e00b6066eae00dfad9a5a388dfebb1..edb8992595f7849f43f6db86847653cad6631aeb 100644 (file)
  * Hudson (tjh@cryptsoft.com).
  *
  */
-#if !defined(OPENSSL_SYS_NETWARE)  /* conflicts with winsock2 stuff on netware */
+/* conflicts with winsock2 stuff on netware */
+#if !defined(OPENSSL_SYS_NETWARE)
 #include <sys/types.h>
 #endif
 #include <openssl/opensslconf.h>
index d824a838d48d4e1b70e9ba20738e9552d09dfa05..16dafca2872e3eebaae03f5f6654f3989635ef5d 100644 (file)
 #define APPS_WIN16
 #endif
 
-#if !defined(OPENSSL_SYS_NETWARE)  /* conflicts with winsock2 stuff on netware */
+/* conflicts with winsock2 stuff on netware */
+#if !defined(OPENSSL_SYS_NETWARE)
 #include <sys/types.h>
 #endif
 
index 6d86587ee3276a9c92d3b5d6528eca6662f1590e..b948631cd7cb454ea5e9d46acfe94b1ac2d9c65a 100644 (file)
@@ -151,7 +151,8 @@ static int bio_new(BIO *bio)
                return 0;
 
        b->peer = NULL;
-       b->size = 17*1024; /* enough for one TLS record (just a default) */
+       /* enough for one TLS record (just a default) */
+       b->size = 17*1024;
        b->buf = NULL;
 
        bio->ptr = b;
index dd6038f3bd2599eb073605b5fb629ef628c2fcb5..c8145f7d7904cc9edf30d54f6bd3819b954216d5 100644 (file)
@@ -76,11 +76,16 @@ typedef unsigned short io_channel;
 /*************************************************************************/
 struct io_status { short status, count; long flags; };
 
-struct rpc_msg {               /* Should have member alignment inhibited */
-   char channel;               /* 'A'-app data. 'R'-remote client 'G'-global */
-   char function;              /* 'G'-get, 'P'-put, 'C'-confirm, 'X'-close */
-   unsigned short int length;  /* Amount of data returned or max to return */
-   char data[4092];            /* variable data */
+/* Should have member alignment inhibited */
+struct rpc_msg {
+   /* 'A'-app data. 'R'-remote client 'G'-global */
+   char channel;
+   /* 'G'-get, 'P'-put, 'C'-confirm, 'X'-close */
+   char function;
+   /* Amount of data returned or max to return */
+   unsigned short int length;
+   /* variable data */
+   char data[4092];
 };
 #define RPC_HDR_SIZE (sizeof(struct rpc_msg) - 4092)
 
index 7a8f8c1450177fcf2e2386f3d99a3f154f9ac760..c711b2d6ce58029f692614d4e700da0ae12c5d2d 100644 (file)
@@ -350,6 +350,11 @@ static BN_ULONG *bn_expand_internal(const BIGNUM *b, int words)
                        a0=B[0]; a1=B[1]; a2=B[2]; a3=B[3];
                        A[0]=a0; A[1]=a1; A[2]=a2; A[3]=a3;
                        }
+               /*
+                * workaround for ultrix cc: without 'case 0', the optimizer does
+                * the switch table by doing a=top&3; a--; goto jump_table[a];
+                * which fails for top== 0
+                */
                switch (b->top&3)
                        {
                case 3: A[2]=B[2];
@@ -357,11 +362,6 @@ static BN_ULONG *bn_expand_internal(const BIGNUM *b, int words)
                case 1: A[0]=B[0];
                case 0:
                        ;
-                       /*
-                        * workaround for ultrix cc: without 'case 0', the optimizer does
-                        * the switch table by doing a=top&3; a--; goto jump_table[a];
-                        * which fails for top== 0
-                        */
                        }
                }
 
@@ -508,12 +508,13 @@ BIGNUM *BN_copy(BIGNUM *a, const BIGNUM *b)
                a0=B[0]; a1=B[1]; a2=B[2]; a3=B[3];
                A[0]=a0; A[1]=a1; A[2]=a2; A[3]=a3;
                }
+       /* ultrix cc workaround, see comments in bn_expand_internal */
        switch (b->top&3)
                {
                case 3: A[2]=B[2];
                case 2: A[1]=B[1];
                case 1: A[0]=B[0];
-               case 0: ; /* ultrix cc workaround, see comments in bn_expand_internal */
+               case 0: ;
                }
 #else
        memcpy(a->d,b->d,sizeof(b->d[0])*b->top);
index 54f57601200aaad52fd666d4f2d56250066f8f89..6a1ffe2d4fc3113466443632a8a70aa994514d30 100644 (file)
@@ -60,7 +60,8 @@ void rsaz_1024_red2norm_avx2(void *norm,const void *red);
 # define ALIGN64
 # pragma align 64(one,two80)
 #else
-# define ALIGN64       /* not fatal, might hurt performance a little */
+/* not fatal, might hurt performance a little */
+# define ALIGN64
 #endif
 
 ALIGN64 static const BN_ULONG one[40] = {
index d0e168949a94403cf7c95c67178b759a67cf4ef6..1b1ed5ad89f840cf41a3436470c89d880a152cd7 100644 (file)
@@ -285,7 +285,8 @@ typedef struct bio_st BIO_dummy;
 struct crypto_ex_data_st
        {
        STACK_OF(void) *sk;
-       int dummy; /* gcc is screwing up this data structure :-( */
+       /* gcc is screwing up this data structure :-( */
+       int dummy;
        };
 DECLARE_STACK_OF(void)
 
index d1ada258a65c288c1ff100eeab246ab787845c83..10e889a57249fc4eb3b3f08e2e46ec82cf1fd6b4 100644 (file)
@@ -67,5 +67,7 @@
 #define DES_version OSSL_DES_version
 #define libdes_version OSSL_libdes_version
 
-OPENSSL_EXTERN const char OSSL_DES_version[];  /* SSLeay version string */
-OPENSSL_EXTERN const char OSSL_libdes_version[];       /* old libdes version string */
+/* SSLeay version string */
+OPENSSL_EXTERN const char OSSL_DES_version[];
+/* old libdes version string */
+OPENSSL_EXTERN const char OSSL_libdes_version[];
index a2f8765d0ed700e9982302e340dec631e6f208c6..c4a48f0f56bed30fce67424ddf183a57fe93e60d 100644 (file)
 #endif
 
 #define DSA_FLAG_CACHE_MONT_P  0x01
-#define DSA_FLAG_NO_EXP_CONSTTIME       0x02 /* new with 0.9.7h; the built-in DSA
-                                              * implementation now uses constant time
-                                              * modular exponentiation for secret exponents
-                                              * by default. This flag causes the
-                                              * faster variable sliding window method to
-                                              * be used for all exponents.
-                                              */
+/* new with 0.9.7h; the
+ * built-in DSA
+ * implementation now
+ * uses constant time
+ * modular exponentiation
+ * for secret exponents
+ * by default. This flag
+ * causes the faster
+ * variable sliding
+ * window method to be
+ * used for all
+ * exponents.
+ */
+#define DSA_FLAG_NO_EXP_CONSTTIME       0x02
 
 /* If this flag is set the DSA method is FIPS compliant and can be used
  * in FIPS mode. This is set in the validated module method. If an
index c60df5c6f2e3b6bf60981972f535d180b8746091..943b75baf5dc06e7b28e3ee84c03e4c095b5be60 100644 (file)
@@ -390,8 +390,9 @@ int ec_GF2m_simple_oct2point(const EC_GROUP *group, EC_POINT *point,
 
                if (!EC_POINT_set_affine_coordinates_GF2m(group, point, x, y, ctx)) goto err;
                }
-       
-       if (!EC_POINT_is_on_curve(group, point, ctx)) /* test required by X9.62 */
+
+       /* test required by X9.62 */
+       if (!EC_POINT_is_on_curve(group, point, ctx))
                {
                ECerr(EC_F_EC_GF2M_SIMPLE_OCT2POINT, EC_R_POINT_IS_NOT_ON_CURVE);
                goto err;
index f2f8266b115ef3e9b2439c82c71a96b1ce833f18..33fba291556372794b21e55f674eb44fa4af6b20 100644 (file)
@@ -1568,9 +1568,10 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
 
                        if (!skip)
                                {
+                               /* Arg 1 below is for "mixed" */
                                point_add(nq[0], nq[1], nq[2],
                                        nq[0], nq[1], nq[2],
-                                       1 /* mixed */, tmp[0], tmp[1], tmp[2]);
+                                       1, tmp[0], tmp[1], tmp[2]);
                                }
                        else
                                {
@@ -1587,9 +1588,10 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
                        bits |= get_bit(g_scalar, i);
                        /* select the point to add, in constant time */
                        select_point(bits, 16, g_pre_comp[0], tmp);
+                       /* Arg 1 below is for "mixed" */
                        point_add(nq[0], nq[1], nq[2],
                                nq[0], nq[1], nq[2],
-                               1 /* mixed */, tmp[0], tmp[1], tmp[2]);
+                               1, tmp[0], tmp[1], tmp[2]);
                        }
 
                /* do other additions every 5 doublings */
index 78c21f00895f3504a5cb6f9bf75d671d78cd34ad..f97dab67decc99befd150522c14ee6ffa20d3ee9 100644 (file)
@@ -1460,9 +1460,10 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
                        select_point(bits, 16, g_pre_comp, tmp);
                        if (!skip)
                                {
+                               /* The 1 argument below is for "mixed" */
                                point_add(nq[0], nq[1], nq[2],
                                        nq[0], nq[1], nq[2],
-                                       1 /* mixed */, tmp[0], tmp[1], tmp[2]);
+                                       1, tmp[0], tmp[1], tmp[2]);
                                }
                        else
                                {
index 4ab42d814c59b248bc57900f548c1864ae6f7326..c65bb2d911ab41108d5b4e7ef2500a33c83b93cc 100644 (file)
@@ -79,7 +79,8 @@ void ec_GFp_nistp_points_make_affine_internal(size_t num, void *point_array,
                        /* tmp_felem(i-1) is the product of Z(0) .. Z(i-1),
                         * tmp_felem(i) is the inverse of the product of Z(0) .. Z(i)
                         */
-                       felem_mul(tmp_felem(num), tmp_felem(i-1), tmp_felem(i)); /* 1/Z(i) */
+                        /* 1/Z(i) */
+                       felem_mul(tmp_felem(num), tmp_felem(i-1), tmp_felem(i));
                else
                        felem_assign(tmp_felem(num), tmp_felem(0)); /* 1/Z(0) */
 
index c23983d7f74d10202b4de6fe4315b4d1ea18f3ed..0fdd8ad31fc73f3cd844c442bb13a74d9b35fbd2 100644 (file)
@@ -416,8 +416,9 @@ int ec_GFp_simple_oct2point(const EC_GROUP *group, EC_POINT *point,
 
                if (!EC_POINT_set_affine_coordinates_GFp(group, point, x, y, ctx)) goto err;
                }
-       
-       if (!EC_POINT_is_on_curve(group, point, ctx)) /* test required by X9.62 */
+
+       /* test required by X9.62 */
+       if (!EC_POINT_is_on_curve(group, point, ctx))
                {
                ECerr(EC_F_EC_GFP_SIMPLE_OCT2POINT, EC_R_POINT_IS_NOT_ON_CURVE);
                goto err;
index ec76393576800637b0035dd056cf821fd8f5a412..3e41f5d4198bf071f231ed2331f50c5cc2d6a168 100644 (file)
@@ -212,7 +212,8 @@ static size_t tls1_1_multi_block_encrypt(EVP_AES_HMAC_SHA1 *key,
        u64             seqnum;
 #endif
 
-       if (RAND_bytes((IVs=blocks[0].c),16*x4)<=0)     /* ask for IVs in bulk */
+       /* ask for IVs in bulk */
+       if (RAND_bytes((IVs=blocks[0].c),16*x4)<=0)
                return 0;
 
        ctx = (SHA1_MB_CTX *)(storage+32-((size_t)storage%32)); /* align */
@@ -229,7 +230,8 @@ static size_t tls1_1_multi_block_encrypt(EVP_AES_HMAC_SHA1 *key,
        /* populate descriptors with pointers and IVs */
        hash_d[0].ptr = inp;
        ciph_d[0].inp = inp;
-       ciph_d[0].out = out+5+16;       /* 5+16 is place for header and explicit IV */
+       /* 5+16 is place for header and explicit IV */
+       ciph_d[0].out = out+5+16;
        memcpy(ciph_d[0].out-16,IVs,16);
        memcpy(ciph_d[0].iv,IVs,16);    IVs += 16;
 
index 752004703c6bfc8342bb378a55b5abd956f9e076..448878b0b2c692157f597724d6868dc13c9676c0 100644 (file)
@@ -227,7 +227,8 @@ static size_t tls1_1_multi_block_encrypt(EVP_AES_HMAC_SHA256 *key,
        /* populate descriptors with pointers and IVs */
        hash_d[0].ptr = inp;
        ciph_d[0].inp = inp;
-       ciph_d[0].out = out+5+16;       /* 5+16 is place for header and explicit IV */
+       /* 5+16 is place for header and explicit IV */
+       ciph_d[0].out = out+5+16;
        memcpy(ciph_d[0].out-16,IVs,16);
        memcpy(ciph_d[0].iv,IVs,16);    IVs += 16;
 
index 5140d27082a6506cd36ea1600d4ca66ae051edc0..5d108e562be8c00fd6204144e648fd32cc8ff327 100644 (file)
@@ -2089,7 +2089,8 @@ static const u8   T19[]= {
 /* Test Case 20 */
 #define K20 K1
 #define A20 A1
-static const u8 IV20[64]={0xff,0xff,0xff,0xff};        /* this results in 0xff in counter LSB */
+/* this results in 0xff in counter LSB */
+static const u8 IV20[64]={0xff,0xff,0xff,0xff};
 static const u8        P20[288];
 static const u8        C20[]= {
                        0x56,0xb3,0x37,0x3c,0xa9,0xef,0x6e,0x4a,
index 888b4eb8dd0bd94bb340e0d3aa803cd5327ce70e..ba62046ba5faff9d139f24abd2831b9a06a7257f 100644 (file)
@@ -147,7 +147,8 @@ static unsigned int crypto_lock_rand = 0; /* may be set only when a thread
                                            * holds CRYPTO_LOCK_RAND
                                            * (to prevent double locking) */
 /* access to lockin_thread is synchronized by CRYPTO_LOCK_RAND2 */
-static CRYPTO_THREADID locking_threadid; /* valid iff crypto_lock_rand is set */
+/* valid iff crypto_lock_rand is set */
+static CRYPTO_THREADID locking_threadid;
 
 
 #ifdef PREDICT
@@ -504,7 +505,8 @@ int ssleay_rand_bytes(unsigned char *buf, int num, int pseudo, int lock)
 
                for (i=0; i<MD_DIGEST_LENGTH/2; i++)
                        {
-                       state[st_idx++]^=local_md[i]; /* may compete with other threads */
+                       /* may compete with other threads */
+                       state[st_idx++]^=local_md[i];
                        if (st_idx >= st_num)
                                st_idx=0;
                        if (i < j)
index c50fdd360733fdc4151d128e3161406d15782adf..ec639456e743ec0007b2563d7335cf909e71992d 100644 (file)
@@ -89,7 +89,8 @@
 #error SEED is disabled.
 #endif
 
-#ifdef AES_LONG /* look whether we need 'long' to get 32 bits */
+/* look whether we need 'long' to get 32 bits */
+#ifdef AES_LONG
 # ifndef SEED_LONG
 #  define SEED_LONG 1
 # endif
index a2dc593d60c7bbffdf3dda2849bc19753f8a7198..060342b73c4f1fb1d3164fc818b7685b791caaa9 100644 (file)
@@ -571,7 +571,8 @@ X509_ALGOR *encryption;
 } PBE2PARAM;
 
 typedef struct PBKDF2PARAM_st {
-ASN1_TYPE *salt;       /* Usually OCTET STRING but could be anything */
+/* Usually OCTET STRING but could be anything */
+ASN1_TYPE *salt;
 ASN1_INTEGER *iter;
 ASN1_INTEGER *keylength;
 X509_ALGOR *prf;
@@ -582,7 +583,8 @@ X509_ALGOR *prf;
 
 struct pkcs8_priv_key_info_st
         {
-        int broken;     /* Flag for various broken formats */
+        /* Flag for various broken formats */
+        int broken;
 #define PKCS8_OK               0
 #define PKCS8_NO_OCTET         1
 #define PKCS8_EMBEDDED_PARAM   2
@@ -590,7 +592,8 @@ struct pkcs8_priv_key_info_st
 #define PKCS8_NEG_PRIVKEY      4
         ASN1_INTEGER *version;
         X509_ALGOR *pkeyalg;
-        ASN1_TYPE *pkey; /* Should be OCTET STRING but some are broken */
+        /* Should be OCTET STRING but some are broken */
+        ASN1_TYPE *pkey;
         STACK_OF(X509_ATTRIBUTE) *attributes;
         };
 
index fa690a2286942251d3480eb7f3a678f4daa919cf..8838b0015e13789ec205b6a8e50a08f5da913e84 100644 (file)
@@ -916,5 +916,5 @@ IMPLEMENT_DYNAMIC_BIND_FN(bind_fn)
 #endif /* ENGINE_DYNAMIC_SUPPORT */\r
 \r
 \r
-#endif /* !OPENSSL_NO_HW_IBMCA */\r
+#endif /* !OPENSSL_NO_HW_IBMCA */
 #endif /* !OPENSSL_NO_HW */
index 9999fcc77525287e99692a7718707734fcd6db2d..d1ee0c8fefb91f594260dd81c9d2daca5db29f53 100644 (file)
@@ -419,7 +419,8 @@ void ENGINE_load_chil(void)
 static DSO *hwcrhk_dso = NULL;
 static HWCryptoHook_ContextHandle hwcrhk_context = 0;
 #ifndef OPENSSL_NO_RSA
-static int hndidx_rsa = -1;    /* Index for KM handle.  Not really used yet. */
+/* Index for KM handle.  Not really used yet. */
+static int hndidx_rsa = -1;
 #endif
 
 /* These are the function pointers that are (un)set when the library has
index d4dac55d0eade9896b423f77ece33eb4f5c4a4d5..f9167c45ddb05661c2d871ec0ebd8b71bd3b6d98 100644 (file)
@@ -337,10 +337,12 @@ void ENGINE_load_sureware(void)
  * implicitly. */
 static DSO *surewarehk_dso = NULL;
 #ifndef OPENSSL_NO_RSA
-static int rsaHndidx = -1;     /* Index for KM handle.  Not really used yet. */
+/* Index for KM handle.  Not really used yet. */
+static int rsaHndidx = -1;
 #endif
 #ifndef OPENSSL_NO_DSA
-static int dsaHndidx = -1;     /* Index for KM handle.  Not really used yet. */
+/* Index for KM handle.  Not really used yet. */
+static int dsaHndidx = -1;
 #endif
 
 /* These are the function pointers that are (un)set when the library has
index 458f37e996ec53a43ba5640882d44a8828d3107b..bf20d527d02a7e276c05441ba6c17954dd5a6394 100644 (file)
@@ -782,9 +782,13 @@ static DSA_SIG *ubsec_dsa_do_sign(const unsigned char *dgst, int dlen, DSA *dsa)
                goto err;
        }
 
-       if (p_UBSEC_dsa_sign_ioctl(fd, 0, /* compute hash before signing */
+       if (p_UBSEC_dsa_sign_ioctl(fd,
+               /* compute hash before signing */
+               0,
                (unsigned char *)dgst, d_len,
-               NULL, 0,  /* compute random value */
+               NULL,
+               /* compute random value */
+               0,
                (unsigned char *)dsa->p->d, BN_num_bits(dsa->p), 
                (unsigned char *)dsa->q->d, BN_num_bits(dsa->q),
                (unsigned char *)dsa->g->d, BN_num_bits(dsa->g),
index 298e6ec3bcae48ca584cb6414f11e1fd86e03f8b..41e4cfa77e2418e566648b61946767f9366628e7 100644 (file)
@@ -714,7 +714,8 @@ again:
                        {
                        if(dtls1_buffer_record(s, &(s->d1->unprocessed_rcds), rr->seq_num)<0)
                                return -1;
-                       dtls1_record_bitmap_update(s, bitmap);/* Mark receipt of record. */
+                       /* Mark receipt of record. */
+                       dtls1_record_bitmap_update(s, bitmap);
                        }
                rr->length = 0;
                s->packet_length = 0;
index f2b34bc876ffe68d823cd2c117859deb32becc8d..6f100eede5ebaaba03ba38ff7d0903162f5edf41 100644 (file)
@@ -1813,8 +1813,10 @@ kssl_ctx_show(KSSL_CTX *kssl_ctx)
 
     krb5rc = krb5_kt_get_entry(krb5context, krb5keytab, 
                                 princ,
-                                0 /* IGNORE_VNO */,
-                                0 /* IGNORE_ENCTYPE */,
+                                /* IGNORE_VNO */
+                                0,
+                                /* IGNORE_ENCTYPE */
+                                0,
                                 &entry);
     if ( krb5rc == KRB5_KT_NOTFOUND ) {
         rc = 1;
@@ -1898,7 +1900,8 @@ void kssl_krb5_free_data_contents(krb5_context context, krb5_data *data)
        krb5_free_data_contents(NULL, data);
 #endif
        }
-#endif /* !OPENSSL_SYS_WINDOWS && !OPENSSL_SYS_WIN32 */
+#endif
+/* !OPENSSL_SYS_WINDOWS && !OPENSSL_SYS_WIN32 */
 
 
 /*  Given pointers to KerberosTime and struct tm structs, convert the
index 4816abd908764c71e0689f1a06d48739081da389..a8b2ae01a96c1ba179ccd3c2662a8946ec47427f 100644 (file)
--- a/ssl/ssl.h
+++ b/ssl/ssl.h
@@ -599,7 +599,8 @@ struct ssl_session_st
  * the workaround is not needed.  Unfortunately some broken SSL/TLS
  * implementations cannot handle it at all, which is why we include
  * it in SSL_OP_ALL. */
-#define SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS              0x00000800L /* added in 0.9.6e */
+/* added in 0.9.6e */
+#define SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS              0x00000800L
 
 /* SSL_OP_ALL: various bug workarounds that should be rather harmless.
  *             This used to be 0x000FFFFFL before 0.9.7. */
@@ -1715,27 +1716,40 @@ DECLARE_PEM_rw(SSL_SESSION, SSL_SESSION)
 
 /* These alert types are for SSLv3 and TLSv1 */
 #define SSL_AD_CLOSE_NOTIFY            SSL3_AD_CLOSE_NOTIFY
-#define SSL_AD_UNEXPECTED_MESSAGE      SSL3_AD_UNEXPECTED_MESSAGE /* fatal */
-#define SSL_AD_BAD_RECORD_MAC          SSL3_AD_BAD_RECORD_MAC     /* fatal */
+/* fatal */
+#define SSL_AD_UNEXPECTED_MESSAGE      SSL3_AD_UNEXPECTED_MESSAGE
+/* fatal */
+#define SSL_AD_BAD_RECORD_MAC          SSL3_AD_BAD_RECORD_MAC
 #define SSL_AD_DECRYPTION_FAILED       TLS1_AD_DECRYPTION_FAILED
 #define SSL_AD_RECORD_OVERFLOW         TLS1_AD_RECORD_OVERFLOW
-#define SSL_AD_DECOMPRESSION_FAILURE   SSL3_AD_DECOMPRESSION_FAILURE/* fatal */
-#define SSL_AD_HANDSHAKE_FAILURE       SSL3_AD_HANDSHAKE_FAILURE/* fatal */
-#define SSL_AD_NO_CERTIFICATE          SSL3_AD_NO_CERTIFICATE /* Not for TLS */
+/* fatal */
+#define SSL_AD_DECOMPRESSION_FAILURE   SSL3_AD_DECOMPRESSION_FAILURE
+/* fatal */
+#define SSL_AD_HANDSHAKE_FAILURE       SSL3_AD_HANDSHAKE_FAILURE
+/* Not for TLS */
+#define SSL_AD_NO_CERTIFICATE          SSL3_AD_NO_CERTIFICATE
 #define SSL_AD_BAD_CERTIFICATE         SSL3_AD_BAD_CERTIFICATE
 #define SSL_AD_UNSUPPORTED_CERTIFICATE SSL3_AD_UNSUPPORTED_CERTIFICATE
 #define SSL_AD_CERTIFICATE_REVOKED     SSL3_AD_CERTIFICATE_REVOKED
 #define SSL_AD_CERTIFICATE_EXPIRED     SSL3_AD_CERTIFICATE_EXPIRED
 #define SSL_AD_CERTIFICATE_UNKNOWN     SSL3_AD_CERTIFICATE_UNKNOWN
-#define SSL_AD_ILLEGAL_PARAMETER       SSL3_AD_ILLEGAL_PARAMETER   /* fatal */
-#define SSL_AD_UNKNOWN_CA              TLS1_AD_UNKNOWN_CA      /* fatal */
-#define SSL_AD_ACCESS_DENIED           TLS1_AD_ACCESS_DENIED   /* fatal */
-#define SSL_AD_DECODE_ERROR            TLS1_AD_DECODE_ERROR    /* fatal */
+/* fatal */
+#define SSL_AD_ILLEGAL_PARAMETER       SSL3_AD_ILLEGAL_PARAMETER
+/* fatal */
+#define SSL_AD_UNKNOWN_CA              TLS1_AD_UNKNOWN_CA
+/* fatal */
+#define SSL_AD_ACCESS_DENIED           TLS1_AD_ACCESS_DENIED
+/* fatal */
+#define SSL_AD_DECODE_ERROR            TLS1_AD_DECODE_ERROR
 #define SSL_AD_DECRYPT_ERROR           TLS1_AD_DECRYPT_ERROR
-#define SSL_AD_EXPORT_RESTRICTION      TLS1_AD_EXPORT_RESTRICTION/* fatal */
-#define SSL_AD_PROTOCOL_VERSION                TLS1_AD_PROTOCOL_VERSION /* fatal */
-#define SSL_AD_INSUFFICIENT_SECURITY   TLS1_AD_INSUFFICIENT_SECURITY/* fatal */
-#define SSL_AD_INTERNAL_ERROR          TLS1_AD_INTERNAL_ERROR  /* fatal */
+/* fatal */
+#define SSL_AD_EXPORT_RESTRICTION      TLS1_AD_EXPORT_RESTRICTION
+/* fatal */
+#define SSL_AD_PROTOCOL_VERSION                TLS1_AD_PROTOCOL_VERSION
+/* fatal */
+#define SSL_AD_INSUFFICIENT_SECURITY   TLS1_AD_INSUFFICIENT_SECURITY
+/* fatal */
+#define SSL_AD_INTERNAL_ERROR          TLS1_AD_INTERNAL_ERROR
 #define SSL_AD_USER_CANCELLED          TLS1_AD_USER_CANCELLED
 #define SSL_AD_NO_RENEGOTIATION                TLS1_AD_NO_RENEGOTIATION
 #define SSL_AD_UNSUPPORTED_EXTENSION   TLS1_AD_UNSUPPORTED_EXTENSION
@@ -1743,8 +1757,10 @@ DECLARE_PEM_rw(SSL_SESSION, SSL_SESSION)
 #define SSL_AD_UNRECOGNIZED_NAME       TLS1_AD_UNRECOGNIZED_NAME
 #define SSL_AD_BAD_CERTIFICATE_STATUS_RESPONSE TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE
 #define SSL_AD_BAD_CERTIFICATE_HASH_VALUE TLS1_AD_BAD_CERTIFICATE_HASH_VALUE
-#define SSL_AD_UNKNOWN_PSK_IDENTITY     TLS1_AD_UNKNOWN_PSK_IDENTITY /* fatal */
-#define SSL_AD_INAPPROPRIATE_FALLBACK  TLS1_AD_INAPPROPRIATE_FALLBACK /* fatal */
+/* fatal */
+#define SSL_AD_UNKNOWN_PSK_IDENTITY     TLS1_AD_UNKNOWN_PSK_IDENTITY
+/* fatal */
+#define SSL_AD_INAPPROPRIATE_FALLBACK  TLS1_AD_INAPPROPRIATE_FALLBACK
 
 #define SSL_ERROR_NONE                 0
 #define SSL_ERROR_SSL                  1
@@ -2127,7 +2143,8 @@ int       SSL_use_certificate_file(SSL *ssl, const char *file, int type);
 int    SSL_CTX_use_RSAPrivateKey_file(SSL_CTX *ctx, const char *file, int type);
 int    SSL_CTX_use_PrivateKey_file(SSL_CTX *ctx, const char *file, int type);
 int    SSL_CTX_use_certificate_file(SSL_CTX *ctx, const char *file, int type);
-int    SSL_CTX_use_certificate_chain_file(SSL_CTX *ctx, const char *file); /* PEM type */
+/* PEM type */
+int    SSL_CTX_use_certificate_chain_file(SSL_CTX *ctx, const char *file);
 STACK_OF(X509_NAME) *SSL_load_client_CA_file(const char *file);
 int    SSL_add_file_cert_subjects_to_stack(STACK_OF(X509_NAME) *stackCAs,
                                            const char *file);
index 2fd822a79626e35a6abdaea16deb3870e1d07caa..052fa03af6361fb639bf3f14dbfa7dfa831e980a 100644 (file)
  */
 
 /* Bits for algorithm_mkey (key exchange algorithm) */
-#define SSL_kRSA               0x00000001L /* RSA key exchange */
-#define SSL_kDHr               0x00000002L /* DH cert, RSA CA cert */
-#define SSL_kDHd               0x00000004L /* DH cert, DSA CA cert */
-#define SSL_kEDH               0x00000008L /* tmp DH key no DH cert */
-#define SSL_kDHE               SSL_kEDH /* forward-compatible synonym */
-#define SSL_kKRB5              0x00000010L /* Kerberos5 key exchange */
-#define SSL_kECDHr             0x00000020L /* ECDH cert, RSA CA cert */
-#define SSL_kECDHe             0x00000040L /* ECDH cert, ECDSA CA cert */
-#define SSL_kEECDH             0x00000080L /* ephemeral ECDH */
-#define SSL_kECDHE             SSL_kEECDH /* forward-compatible synonym */
-#define SSL_kPSK               0x00000100L /* PSK */
-#define SSL_kGOST       0x00000200L /* GOST key exchange */
-#define SSL_kSRP        0x00000400L /* SRP */
+/* RSA key exchange */
+#define SSL_kRSA               0x00000001L
+/* DH cert, RSA CA cert */
+#define SSL_kDHr               0x00000002L
+/* DH cert, DSA CA cert */
+#define SSL_kDHd               0x00000004L
+/* tmp DH key no DH cert */
+#define SSL_kEDH               0x00000008L
+/* forward-compatible synonym */
+#define SSL_kDHE               SSL_kEDH
+/* Kerberos5 key exchange */
+#define SSL_kKRB5              0x00000010L
+/* ECDH cert, RSA CA cert */
+#define SSL_kECDHr             0x00000020L
+/* ECDH cert, ECDSA CA cert */
+#define SSL_kECDHe             0x00000040L
+/* ephemeral ECDH */
+#define SSL_kEECDH             0x00000080L
+/* forward-compatible synonym */
+#define SSL_kECDHE             SSL_kEECDH
+/* PSK */
+#define SSL_kPSK               0x00000100L
+/* GOST key exchange */
+#define SSL_kGOST       0x00000200L
+/* SRP */
+#define SSL_kSRP        0x00000400L
 
 /* Bits for algorithm_auth (server authentication) */
-#define SSL_aRSA               0x00000001L /* RSA auth */
-#define SSL_aDSS               0x00000002L /* DSS auth */
-#define SSL_aNULL              0x00000004L /* no auth (i.e. use ADH or AECDH) */
-#define SSL_aDH                0x00000008L /* Fixed DH auth (kDHd or kDHr) */
-#define SSL_aECDH              0x00000010L /* Fixed ECDH auth (kECDHe or kECDHr) */
-#define SSL_aKRB5               0x00000020L /* KRB5 auth */
-#define SSL_aECDSA              0x00000040L /* ECDSA auth*/
-#define SSL_aPSK                0x00000080L /* PSK auth */
-#define SSL_aGOST94                            0x00000100L /* GOST R 34.10-94 signature auth */
-#define SSL_aGOST01                    0x00000200L /* GOST R 34.10-2001 signature auth */
-#define SSL_aSRP               0x00000400L /* SRP auth */
+/* RSA auth */
+#define SSL_aRSA               0x00000001L
+/* DSS auth */
+#define SSL_aDSS               0x00000002L
+/* no auth (i.e. use ADH or AECDH) */
+#define SSL_aNULL              0x00000004L
+/* Fixed DH auth (kDHd or kDHr) */
+#define SSL_aDH                0x00000008L
+/* Fixed ECDH auth (kECDHe or kECDHr) */
+#define SSL_aECDH              0x00000010L
+/* KRB5 auth */
+#define SSL_aKRB5               0x00000020L
+/* ECDSA auth*/
+#define SSL_aECDSA              0x00000040L
+/* PSK auth */
+#define SSL_aPSK                0x00000080L
+/* GOST R 34.10-94 signature auth */
+#define SSL_aGOST94                            0x00000100L
+/* GOST R 34.10-2001 signature auth */
+#define SSL_aGOST01                    0x00000200L
+/* SRP auth */
+#define SSL_aSRP               0x00000400L
 
 
 /* Bits for algorithm_enc (symmetric encryption) */
index 86a9a6013dc8be8a7d2f26ebc659ca60fd376d5b..4381647f2e99664482e98010327db277db60b48b 100644 (file)
@@ -144,11 +144,16 @@ static int s_nbio=0;
 #endif
 #define TEST_SERVER_CERT "SSL_SERVER_CERTIFICATE"
 /*************************************************************************/
-struct rpc_msg {               /* Should have member alignment inhibited */
-   char channel;               /* 'A'-app data. 'R'-remote client 'G'-global */
-   char function;              /* 'G'-get, 'P'-put, 'C'-confirm, 'X'-close */
-   unsigned short int length;  /* Amount of data returned or max to return */
-   char data[4092];            /* variable data */
+/* Should have member alignment inhibited */
+struct rpc_msg {
+    /* 'A'-app data. 'R'-remote client 'G'-global */
+   char channel;
+   /* 'G'-get, 'P'-put, 'C'-confirm, 'X'-close */
+   char function;
+   /* Amount of data returned or max to return */
+   unsigned short int length;
+   /* variable data */
+   char data[4092];
 };
 #define RPC_HDR_SIZE (sizeof(struct rpc_msg) - 4092)
 
index 0bb9fa8731a4abee4ab35f40c7d26a94d85846e3..9ff21171b1cc543511b94cd49154fe4ef5b60973 100644 (file)
@@ -1410,8 +1410,10 @@ bad:
 #ifdef TLSEXT_TYPE_opaque_prf_input
        SSL_CTX_set_tlsext_opaque_prf_input_callback(c_ctx, opaque_prf_input_cb);
        SSL_CTX_set_tlsext_opaque_prf_input_callback(s_ctx, opaque_prf_input_cb);
-       SSL_CTX_set_tlsext_opaque_prf_input_callback_arg(c_ctx, &co1); /* or &co2 or NULL */
-       SSL_CTX_set_tlsext_opaque_prf_input_callback_arg(s_ctx, &so1); /* or &so2 or NULL */
+       /* or &co2 or NULL */
+       SSL_CTX_set_tlsext_opaque_prf_input_callback_arg(c_ctx, &co1);
+       /* or &so2 or NULL */
+       SSL_CTX_set_tlsext_opaque_prf_input_callback_arg(s_ctx, &so1);
 #endif
 
        if (!SSL_CTX_use_certificate_file(s_ctx,server_cert,SSL_FILETYPE_PEM))
index 6a4a69e5147122b4640f77e80c99438ca0e86c4c..7416f732b66c30e77b64692e11be3c064f5f91ed 100644 (file)
@@ -1286,7 +1286,8 @@ int tls1_alert_code(int code)
        case SSL_AD_BAD_CERTIFICATE_HASH_VALUE: return(TLS1_AD_BAD_CERTIFICATE_HASH_VALUE);
        case SSL_AD_UNKNOWN_PSK_IDENTITY:return(TLS1_AD_UNKNOWN_PSK_IDENTITY);
        case SSL_AD_INAPPROPRIATE_FALLBACK:return(TLS1_AD_INAPPROPRIATE_FALLBACK);
-#if 0 /* not appropriate for TLS, not used for DTLS */
+#if 0
+       /* not appropriate for TLS, not used for DTLS */
        case DTLS1_AD_MISSING_HANDSHAKE_MESSAGE: return 
                                          (DTLS1_AD_MISSING_HANDSHAKE_MESSAGE);
 #endif