Commit 217fa8a195 for openssl.org
commit 217fa8a195799a55a3d8d818462ddf35507c96a1
Author: Frederik Wedel-Heinen <frederik.wedel-heinen@dencrypt.dk>
Date: Thu Jul 2 07:10:09 2026 +0200
Removes redundant SSLv3 version checks and check against TLS1_VERSION_MAJOR instead of SSL3_VERSION_MAJOR.
Reviewed-by: Andrew Dinh <andrewd@openssl.org>
Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
Merge-date: Fri Oct 2 07:28:05 2026
Merged-from: https://github.com/openssl/openssl/pull/31823
diff --git a/ssl/record/methods/tls_common.c b/ssl/record/methods/tls_common.c
index bda1a17b9d..5773cb393c 100644
--- a/ssl/record/methods/tls_common.c
+++ b/ssl/record/methods/tls_common.c
@@ -1349,7 +1349,7 @@ int tls_int_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers,
}
if ((rl->options & SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS) == 0
- && rl->version <= TLS1_VERSION
+ && rl->version == TLS1_VERSION
&& !EVP_CIPHER_is_a(ciph, "NULL")
&& !EVP_CIPHER_is_a(ciph, "RC4")) {
/*
diff --git a/ssl/record/methods/tlsany_meth.c b/ssl/record/methods/tlsany_meth.c
index f6b362eb5e..55d5f77c4b 100644
--- a/ssl/record/methods/tlsany_meth.c
+++ b/ssl/record/methods/tlsany_meth.c
@@ -48,7 +48,7 @@ static int tls_validate_record_header(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec)
const int version1_3 = rl->isdtls ? DTLS1_3_VERSION : TLS1_3_VERSION;
if (rl->version == TLS_ANY_VERSION) {
- if ((rec->rec_version >> 8) != SSL3_VERSION_MAJOR) {
+ if ((rec->rec_version >> 8) != TLS1_VERSION_MAJOR) {
if (rl->is_first_record) {
unsigned char *p;
diff --git a/ssl/ssl_asn1.c b/ssl/ssl_asn1.c
index 12cd62d773..67adc9d365 100644
--- a/ssl/ssl_asn1.c
+++ b/ssl/ssl_asn1.c
@@ -289,7 +289,7 @@ SSL_SESSION *d2i_SSL_SESSION_ex(SSL_SESSION **a, const unsigned char **pp,
goto err;
}
- if ((as->ssl_version >> 8) != SSL3_VERSION_MAJOR
+ if ((as->ssl_version >> 8) != TLS1_VERSION_MAJOR
&& (as->ssl_version >> 8) != DTLS1_VERSION_MAJOR
&& as->ssl_version != DTLS1_BAD_VER) {
ERR_raise(ERR_LIB_SSL, SSL_R_UNSUPPORTED_SSL_VERSION);
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
index 1d9f239afe..7e1ec200da 100644
--- a/ssl/ssl_ciph.c
+++ b/ssl/ssl_ciph.c
@@ -550,8 +550,7 @@ int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
const EVP_CIPHER *evp = NULL;
if (use_etm
- || s->ssl_version >> 8 != TLS1_VERSION_MAJOR
- || s->ssl_version < TLS1_VERSION)
+ || s->ssl_version >> 8 != TLS1_VERSION_MAJOR)
return 1;
if (c->algorithm_enc == SSL_RC4
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
index 238e9d386c..240ae9bb6e 100644
--- a/ssl/ssl_lib.c
+++ b/ssl/ssl_lib.c
@@ -4199,11 +4199,7 @@ int SSL_export_keying_material(SSL *s, unsigned char *out, size_t olen,
{
SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s);
- if (sc == NULL)
- return -1;
-
- if (sc->session == NULL
- || (sc->version < TLS1_VERSION && sc->version != DTLS1_BAD_VER))
+ if (sc == NULL || sc->session == NULL)
return -1;
return sc->ssl.method->ssl3_enc->export_keying_material(sc, out, olen, label,
diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c
index 3684360829..2b7be830a2 100644
--- a/ssl/statem/extensions_clnt.c
+++ b/ssl/statem/extensions_clnt.c
@@ -40,7 +40,7 @@ EXT_RETURN tls_construct_ctos_renegotiate(SSL_CONNECTION *s, WPACKET *pkt,
&& ssl_security(s, SSL_SECOP_VERSION, 0, TLS1_VERSION, NULL)
&& s->min_proto_version <= TLS1_VERSION)) {
/*
- * For TLS <= 1.0 SCSV is used instead, and for TLS 1.3 this
+ * For TLSv1.0 SCSV is used instead, and for TLS 1.3 this
* extension isn't used at all.
*/
return EXT_RETURN_NOT_SENT;
diff --git a/ssl/statem/statem.c b/ssl/statem/statem.c
index b8a31857bf..fa49ed85e6 100644
--- a/ssl/statem/statem.c
+++ b/ssl/statem/statem.c
@@ -435,7 +435,7 @@ static int state_machine(SSL_CONNECTION *s, int server)
goto end;
}
} else {
- if ((s->version >> 8) != SSL3_VERSION_MAJOR) {
+ if ((s->version >> 8) != TLS1_VERSION_MAJOR) {
SSLfatal(s, SSL_AD_NO_ALERT, ERR_R_INTERNAL_ERROR);
goto end;
}
diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c
index 1ecdb87a85..dacc0169fe 100644
--- a/ssl/t1_lib.c
+++ b/ssl/t1_lib.c
@@ -3130,7 +3130,7 @@ SSL_TICKET_STATUS tls_get_ticket_from_client(SSL_CONNECTION *s,
* (e.g. TLSv1.3) behave as if no ticket present to permit stateful
* resumption.
*/
- if (s->version <= SSL3_VERSION || !tls_use_ticket(s))
+ if (!tls_use_ticket(s))
return SSL_TICKET_NONE;
ticketext = &hello->pre_proc_exts[TLSEXT_IDX_session_ticket];