Commit c8c8fcc9fc for openssl.org

commit c8c8fcc9fc3cc92a093767979cc251f7dda42695
Author: Denis Pronin <dannftk@yandex.ru>
Date:   Tue Nov 19 07:57:07 2024 +0300

    preserve data constness when getting issuer name's and subject's hash

    CLA:trivial

    Signed-off-by: Denis Pronin <dannftk@yandex.ru>

    Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
    Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
    Reviewed-by: Neil Horman <nhorman@openssl.org>
    MergeDate: Mon Feb 23 13:13:33 2026
    (Merged from https://github.com/openssl/openssl/pull/25991)

diff --git a/crypto/x509/x509_cmp.c b/crypto/x509/x509_cmp.c
index 69753c2ede..b3e42f56c2 100644
--- a/crypto/x509/x509_cmp.c
+++ b/crypto/x509/x509_cmp.c
@@ -102,13 +102,13 @@ X509_NAME *X509_get_issuer_name(const X509 *a)
     return a->cert_info.issuer;
 }

-unsigned long X509_issuer_name_hash(X509 *x)
+unsigned long X509_issuer_name_hash(const X509 *x)
 {
     return X509_NAME_hash_ex(x->cert_info.issuer, NULL, NULL, NULL);
 }

 #ifndef OPENSSL_NO_MD5
-unsigned long X509_issuer_name_hash_old(X509 *x)
+unsigned long X509_issuer_name_hash_old(const X509 *x)
 {
     return X509_NAME_hash_old(x->cert_info.issuer);
 }
@@ -129,13 +129,13 @@ const ASN1_INTEGER *X509_get0_serialNumber(const X509 *a)
     return &a->cert_info.serialNumber;
 }

-unsigned long X509_subject_name_hash(X509 *x)
+unsigned long X509_subject_name_hash(const X509 *x)
 {
     return X509_NAME_hash_ex(x->cert_info.subject, NULL, NULL, NULL);
 }

 #ifndef OPENSSL_NO_MD5
-unsigned long X509_subject_name_hash_old(X509 *x)
+unsigned long X509_subject_name_hash_old(const X509 *x)
 {
     return X509_NAME_hash_old(x->cert_info.subject);
 }
diff --git a/doc/man3/X509_get_subject_name.pod b/doc/man3/X509_get_subject_name.pod
index 56c5404a43..42dddc8f12 100644
--- a/doc/man3/X509_get_subject_name.pod
+++ b/doc/man3/X509_get_subject_name.pod
@@ -19,11 +19,11 @@ get X509_NAME hashes or get and set issuer or subject names

  X509_NAME *X509_get_subject_name(const X509 *x);
  int X509_set_subject_name(X509 *x, const X509_NAME *name);
- unsigned long X509_subject_name_hash(X509 *x);
+ unsigned long X509_subject_name_hash(const X509 *x);

  X509_NAME *X509_get_issuer_name(const X509 *x);
  int X509_set_issuer_name(X509 *x, const X509_NAME *name);
- unsigned long X509_issuer_name_hash(X509 *x);
+ unsigned long X509_issuer_name_hash(const X509 *x);

  X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req);
  int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name);
diff --git a/include/openssl/x509.h.in b/include/openssl/x509.h.in
index b0d3494d9c..2f13b025bf 100644
--- a/include/openssl/x509.h.in
+++ b/include/openssl/x509.h.in
@@ -792,14 +792,14 @@ int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b);
 unsigned long X509_issuer_and_serial_hash(const X509 *a);

 int X509_issuer_name_cmp(const X509 *a, const X509 *b);
-unsigned long X509_issuer_name_hash(X509 *a);
+unsigned long X509_issuer_name_hash(const X509 *a);

 int X509_subject_name_cmp(const X509 *a, const X509 *b);
-unsigned long X509_subject_name_hash(X509 *x);
+unsigned long X509_subject_name_hash(const X509 *x);

 #ifndef OPENSSL_NO_MD5
-unsigned long X509_issuer_name_hash_old(X509 *a);
-unsigned long X509_subject_name_hash_old(X509 *x);
+unsigned long X509_issuer_name_hash_old(const X509 *a);
+unsigned long X509_subject_name_hash_old(const X509 *x);
 #endif

 #define X509_ADD_FLAG_DEFAULT 0