Commit 6e1771a138 for openssl.org

commit 6e1771a138e801efe3a62adfb4abd73ade5e71cd
Author: Pauli <paul.dale@oracle.com>
Date:   Tue Sep 1 15:34:52 2026 +1000

    ssl: use generated parser for record options

    Replace repeated OSSL_PARAM lookups in the common record-layer option handler with a generated trie decoder.

    Assisted-by: ChatGPT:gpt-5.6Sol
    Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
    Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
    Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
    Merge-date: Fri Oct  2 08:01:03 2026
    Merged-from: https://github.com/openssl/openssl/pull/32621

diff --git a/.gitignore b/.gitignore
index a929da336a..4d084af649 100644
--- a/.gitignore
+++ b/.gitignore
@@ -99,6 +99,7 @@ providers/common/include/prov/der_ml_dsa.h
 providers/common/include/prov/der_hkdf.h
 providers/fips/fipsparams.inc
 ssl/t1_lib.inc
+ssl/record/methods/tls_common.inc
 providers/implementations/asymciphers/rsa_enc.inc
 providers/implementations/asymciphers/sm2_enc.inc
 providers/implementations/exchange/dh_exch.inc
diff --git a/build.info b/build.info
index a58317cf89..337c44c60b 100644
--- a/build.info
+++ b/build.info
@@ -81,6 +81,7 @@ DEPEND[]=include/openssl/asn1.h \
          include/crypto/ec_params.h \
          include/crypto/rsa_params.h \
          ssl/t1_lib.inc \
+         ssl/record/methods/tls_common.inc \
          providers/implementations/asymciphers/rsa_enc.inc \
          providers/implementations/asymciphers/sm2_enc.inc \
          providers/implementations/exchange/dh_exch.inc \
@@ -223,6 +224,7 @@ GENERATE[include/openssl/x509_vfy.h]=include/openssl/x509_vfy.h.in
 GENERATE[include/crypto/dso_conf.h]=include/crypto/dso_conf.h.in

 DEPEND[ssl/t1_lib.inc \
+       ssl/record/methods/tls_common.inc \
        providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/asymciphers/sm2_enc.inc \
        providers/implementations/exchange/dh_exch.inc \
@@ -333,6 +335,8 @@ GENERATE[include/crypto/ec_params.h]=\
 GENERATE[include/crypto/rsa_params.h]=\
     include/crypto/rsa_params.h.in
 GENERATE[ssl/t1_lib.inc]=ssl/t1_lib.inc.in
+GENERATE[ssl/record/methods/tls_common.inc]=\
+    ssl/record/methods/tls_common.inc.in
 GENERATE[providers/implementations/asymciphers/rsa_enc.inc]=\
     providers/implementations/asymciphers/rsa_enc.inc.in
 GENERATE[providers/implementations/asymciphers/sm2_enc.inc]=\
diff --git a/ssl/record/methods/tls_common.c b/ssl/record/methods/tls_common.c
index 5773cb393c..fcbf585277 100644
--- a/ssl/record/methods/tls_common.c
+++ b/ssl/record/methods/tls_common.c
@@ -21,6 +21,7 @@
 #include "../../ssl_local.h"
 #include "../record_local.h"
 #include "recmethod_local.h"
+#include "ssl/record/methods/tls_common.inc"

 static void tls_int_free(OSSL_RECORD_LAYER *rl);

@@ -1162,36 +1163,37 @@ int tls_release_record(OSSL_RECORD_LAYER *rl, void *rechandle, size_t length)

 int tls_set_options(OSSL_RECORD_LAYER *rl, const OSSL_PARAM *options)
 {
+    struct tls_set_options_params_st prms;
     const OSSL_PARAM *p;

-    p = OSSL_PARAM_locate_const(options, OSSL_LIBSSL_RECORD_LAYER_PARAM_OPTIONS);
+    if (!tls_set_options_params_decoder(options, &prms))
+        return 0;
+
+    p = prms.options;
     if (p != NULL && !OSSL_PARAM_get_uint64(p, &rl->options)) {
         ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
         return 0;
     }

-    p = OSSL_PARAM_locate_const(options, OSSL_LIBSSL_RECORD_LAYER_PARAM_MODE);
+    p = prms.mode;
     if (p != NULL && !OSSL_PARAM_get_uint32(p, &rl->mode)) {
         ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
         return 0;
     }

     if (rl->direction == OSSL_RECORD_DIRECTION_READ) {
-        p = OSSL_PARAM_locate_const(options,
-            OSSL_LIBSSL_RECORD_LAYER_READ_BUFFER_LEN);
+        p = prms.rbuf_len;
         if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->rbuf.default_len)) {
             ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
             return 0;
         }
     } else {
-        p = OSSL_PARAM_locate_const(options,
-            OSSL_LIBSSL_RECORD_LAYER_PARAM_BLOCK_PADDING);
+        p = prms.blockpad;
         if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->block_padding)) {
             ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
             return 0;
         }
-        p = OSSL_PARAM_locate_const(options,
-            OSSL_LIBSSL_RECORD_LAYER_PARAM_HS_PADDING);
+        p = prms.hspad;
         if (p != NULL && !OSSL_PARAM_get_size_t(p, &rl->hs_padding)) {
             ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
             return 0;
@@ -1205,8 +1207,7 @@ int tls_set_options(OSSL_RECORD_LAYER *rl, const OSSL_PARAM *options)
          * that is destined for a higher protection level. To simplify the logic
          * we don't support that at this stage.
          */
-        p = OSSL_PARAM_locate_const(options,
-            OSSL_LIBSSL_RECORD_LAYER_PARAM_READ_AHEAD);
+        p = prms.readahead;
         if (p != NULL && !OSSL_PARAM_get_int(p, &rl->read_ahead)) {
             ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_GET_PARAMETER);
             return 0;
diff --git a/ssl/record/methods/tls_common.inc.in b/ssl/record/methods/tls_common.inc.in
new file mode 100644
index 0000000000..9a34da880b
--- /dev/null
+++ b/ssl/record/methods/tls_common.inc.in
@@ -0,0 +1,32 @@
+/*
+ * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+{-
+use OpenSSL::paramnames qw(produce_param_decoder);
+
+sub produce_ssl_param_decoder {
+    my $decoder = produce_param_decoder(@_);
+
+    # Adapt the provider-oriented decoder errors for libssl.
+    $decoder =~ s|#include "prov/proverr.h"|#include <openssl/err.h>|;
+    $decoder =~ s/ERR_LIB_PROV/ERR_LIB_SSL/g;
+    $decoder =~ s/PROV_R_REPEATED_PARAMETER/ERR_R_PASSED_INVALID_ARGUMENT/g;
+    return $decoder;
+}
+-}
+
+#define tls_set_options_params_list
+{- produce_ssl_param_decoder('tls_set_options_params',
+                         (['OSSL_LIBSSL_RECORD_LAYER_PARAM_OPTIONS',       'options',  'uint64'],
+                          ['OSSL_LIBSSL_RECORD_LAYER_PARAM_MODE',          'mode',     'uint32'],
+                          ['OSSL_LIBSSL_RECORD_LAYER_READ_BUFFER_LEN',     'rbuf_len', 'size_t'],
+                          ['OSSL_LIBSSL_RECORD_LAYER_PARAM_BLOCK_PADDING', 'blockpad', 'size_t'],
+                          ['OSSL_LIBSSL_RECORD_LAYER_PARAM_HS_PADDING',    'hspad',    'size_t'],
+                          ['OSSL_LIBSSL_RECORD_LAYER_PARAM_READ_AHEAD',   'readahead', 'int'],
+                         )); -}