Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 6 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -249,13 +249,12 @@ jobs:
mkdir -p "$ANDROID_HOME"
unzip -q android-tools.zip -d "$ANDROID_HOME"
yes | "$SDKMANAGER" --sdk_root="$ANDROID_HOME" --licenses || true
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" tools
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" platform-tools
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" 'build-tools;30.0.3'
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" 'platforms;android-26'
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" 'extras;android;m2repository'
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" 'ndk;27.3.13750724'
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" 'cmake;3.22.1'
"$SDKMANAGER" --sdk_root="$ANDROID_HOME" \
platform-tools \
'build-tools;30.0.3' \
'platforms;android-26' \
'ndk;27.3.13750724' \
'cmake;3.22.1'

- name: Build with Gradle
shell: bash
Expand Down
6 changes: 5 additions & 1 deletion CAPABILITIES.md
Original file line number Diff line number Diff line change
Expand Up @@ -134,11 +134,13 @@ Key-restricted versions of the AES ciphers.
The RC4 stream cipher.

* `ChaCha20/NONE/NoPadding`
* `ChaCha20/Poly1305/NoPadding`
* `ChaCha20/Poly1305/NoPadding` (alias: `ChaCha20-Poly1305`)
* `XChaCha20/Poly1305/NoPadding` (alias: `XChaCha20-Poly1305`)

ChaCha with 20 rounds, 96-bit nonce, and 32-bit counter as described in
[RFC 7539](https://tools.ietf.org/html/rfc7539), either with or without a Poly1305 AEAD
authenticator.
`XChaCha20/Poly1305/NoPadding` provides an extended 192-bit nonce for safer random generation (see [draft-irtf-cfrg-xchacha](https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-xchacha)).

* `DESEDE/CBC/NoPadding`
* `DESEDE/CBC/PKCS5Padding`
Expand All @@ -165,6 +167,7 @@ should use `RSA/ECB/OAEPPadding` and initialize it with an

* `AES`
* `ChaCha20`
* `XChaCha20`
* `DESEDE`
* `EC`
* `GCM`
Expand Down Expand Up @@ -204,6 +207,7 @@ Conscrypt's EC AlgorithmParameters implementation only supports named curves.
* `AES`
* `ARC4`
* `ChaCha20`
* `XChaCha20`
* `DESEDE`
* `HmacMD5`
* `HmacSHA1`
Expand Down
4 changes: 0 additions & 4 deletions android-stub/src/main/java/com/android/libcore/Flags.java
Original file line number Diff line number Diff line change
Expand Up @@ -20,10 +20,6 @@
public final class Flags {
private Flags() {}

public static boolean networkSecurityPolicyReasonCtEnabledApi() {
throw new RuntimeException("Stub!");
}

public static boolean networkSecurityPolicyEchApi() {
throw new RuntimeException("Stub!");
}
Expand Down
6 changes: 6 additions & 0 deletions android/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,12 @@ android {
"${rootDir}/common/src/test/java",
"${rootDir}/openjdk/src/test/java",
]
excludes = [
'org/conscrypt/ConscryptOpenJdkSuite.java',
'org/conscrypt/EchConfigListTest.java',
'org/conscrypt/EchConfigMismatchExceptionTest.java',
'org/conscrypt/PlatformTest.java',
]
}
resources {
srcDirs = [
Expand Down
51 changes: 50 additions & 1 deletion android/src/main/java/org/conscrypt/Platform.java
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,6 @@ final public class Platform {

private static Method m_getCurveName;
static {
NativeCrypto.setTlsV1DeprecationStatus(DEPRECATED_TLS_V1, ENABLED_TLS_V1);
try {
m_getCurveName = ECParameterSpec.class.getDeclaredMethod("getCurveName");
m_getCurveName.setAccessible(true);
Expand Down Expand Up @@ -886,4 +885,54 @@ public static boolean isPakeSupported() {
public static boolean isSdkGreater(int sdk) {
return Build.VERSION.SDK_INT > sdk;
}

private static class X509NativeAllocationRegistryHolder {
private static final Object REGISTRY;
private static final Method REGISTER_METHOD;

static {
Object registry = null;
Method registerMethod = null;
try {
Class<?> narClass = Class.forName("libcore.util.NativeAllocationRegistry");
Method createMethod =
narClass.getMethod("createMalloced", ClassLoader.class, long.class);
ClassLoader classLoader = OpenSSLX509Certificate.class.getClassLoader();
if (classLoader == null) {
classLoader = ClassLoader.getSystemClassLoader();
}
registry = createMethod.invoke(null,
classLoader,
NativeCrypto.get_X509_free_func());
registerMethod =
narClass.getMethod("registerNativeAllocation", Object.class, long.class);
} catch (ReflectiveOperationException ignored) {
registry = null;
registerMethod = null;
} catch (Throwable t) {
registry = null;
registerMethod = null;
Log.w(TAG, "Could not initialize NativeAllocationRegistry", t);
}
REGISTRY = registry;
REGISTER_METHOD = registerMethod;
}
}

public static boolean registerX509CertificateAllocation(
OpenSSLX509Certificate cert, long nativePtr) {
if (X509NativeAllocationRegistryHolder.REGISTRY != null
&& X509NativeAllocationRegistryHolder.REGISTER_METHOD != null) {
try {
X509NativeAllocationRegistryHolder.REGISTER_METHOD.invoke(
X509NativeAllocationRegistryHolder.REGISTRY, cert, nativePtr);
return true;
} catch (ReflectiveOperationException ignored) {
// Do nothing.
} catch (Throwable t) {
Log.w(TAG, "Could not register native allocation", t);
}
}
return false;
}
}
Loading
Loading