Commit 05902ff40b for openssl.org
commit 05902ff40b3251e2a913a24a60268263e18fe2c3
Author: Mounir IDRASSI <mounir.idrassi@idrix.fr>
Date: Sun Sep 6 08:40:39 2026 +0900
crypto/ct/ct_log.c: handle negative returns when loading a log store
CTLOG_STORE_load_file() treats a negative CONF_parse_list() return as
success, even when the callback failed to allocate the log name.
Check for non-positive parser returns so internal errors produce the
documented 0 return value, preserving the existing invalid-entry handling.
Add a regression using the existing allocation failure framework and a
configuration referencing a missing log section. Loading must return 0
both normally and when allocations fail. Return -1 from the test on
unexpected success so ADD_MFAIL_NO_CHECK_TEST cannot mask the failure.
Resolves: https://github.com/openssl/openssl/issues/32703
References: 70073f3e3aeb "Treat boolean functions as booleans"
Complements: 68efafc51378 "Add checks on sk_TYPE_push() returned value"
Complements: e57036f2bf81 "Fix some memory error handling in CT"
Assisted-by: Codex:gpt-6-astra
Reviewed-by: Saša NedvÄ›dický <sashan@openssl.org>
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Merge-date: Fri Oct 9 20:40:44 2026
Merged-from: https://github.com/openssl/openssl/pull/32704
diff --git a/crypto/ct/ct_log.c b/crypto/ct/ct_log.c
index 8c1184984f..53e0a2c791 100644
--- a/crypto/ct/ct_log.c
+++ b/crypto/ct/ct_log.c
@@ -236,7 +236,8 @@ int CTLOG_STORE_load_file(CTLOG_STORE *store, const char *file)
goto end;
}
- if (!CONF_parse_list(enabled_logs, ',', 1, ctlog_store_load_log, load_ctx) || load_ctx->invalid_log_entries > 0) {
+ if (CONF_parse_list(enabled_logs, ',', 1, ctlog_store_load_log, load_ctx) <= 0
+ || load_ctx->invalid_log_entries > 0) {
ERR_raise(ERR_LIB_CT, CT_R_LOG_CONF_INVALID);
goto end;
}
diff --git a/test/ct/log_list_missing_section.cnf b/test/ct/log_list_missing_section.cnf
new file mode 100644
index 0000000000..5c201c89ca
--- /dev/null
+++ b/test/ct/log_list_missing_section.cnf
@@ -0,0 +1,8 @@
+# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
+#
+# Licensed under the Apache License 2.0 (the "License"). You may not use
+# this file except in compliance with the License. You can obtain a copy
+# in the file LICENSE in the source distribution or at
+# https://www.openssl.org/source/license.html
+
+enabled_logs = missing_section
diff --git a/test/ct_test.c b/test/ct_test.c
index 51cad3eaae..968205f7a1 100644
--- a/test/ct_test.c
+++ b/test/ct_test.c
@@ -509,6 +509,29 @@ static int test_ctlog_from_base64(void)
return 1;
}
+static int test_ctlog_store_load_file_mfail(void)
+{
+ CTLOG_STORE *store = NULL;
+ char *file = NULL;
+ int ret, result = -1;
+
+ if (!TEST_ptr(file = test_mk_file_path(ct_dir, "log_list_missing_section.cnf"))
+ || !TEST_ptr(store = CTLOG_STORE_new()))
+ goto end;
+
+ MFAIL_start();
+ ret = CTLOG_STORE_load_file(store, file);
+ MFAIL_end();
+
+ /* A missing log section must fail, even if an allocation fails. */
+ result = TEST_int_eq(ret, 0) ? 1 : -1;
+
+end:
+ CTLOG_STORE_free(store);
+ OPENSSL_free(file);
+ return result;
+}
+
static int test_ctlog_store_add0_log(void)
{
CTLOG_STORE *store = NULL;
@@ -653,6 +676,7 @@ int setup_tests(void)
ADD_TEST(test_encode_tls_sct);
ADD_TEST(test_default_ct_policy_eval_ctx_time_is_now);
ADD_TEST(test_ctlog_from_base64);
+ ADD_MFAIL_NO_CHECK_TEST(test_ctlog_store_load_file_mfail);
ADD_TEST(test_ctlog_store_add0_log);
ADD_TEST(test_ctlog_store_add0_log_validates_sct);
ADD_TEST(test_ctlog_store_add0_log_null);