hostname);
return -1;
}
- snprintf(path, sizeof(path), PROXY_SERVER_CERT_FORMAT, hostname);
+ result = snprintf(path, sizeof(path), PROXY_SERVER_CERT_FORMAT, hostname);
+ if (result < 0) {
+ LOG_PERROR(LOG_ERROR,
+ "initialize_tls_session_client(): snprintf failed");
+ return -1;
+ } else if ((size_t)result >= sizeof(path)) {
+ LOG(LOG_ERROR,
+ "initialize_tls_session_client(): snprintf buffer too short");
+ return -1;
+ }
result = gnutls_certificate_allocate_credentials(x509_cred);
if (GNUTLS_E_SUCCESS != result) {
result = gnutls_certificate_set_x509_trust_file(*x509_cred,
PROXY_CA_FILE,
GNUTLS_X509_FMT_PEM);
+ if (0 >= result) {
+ LOG(LOG_ERROR,
+ "initialize_tls_session_client(): can't read CA file: '%s'",
+ PROXY_CA_FILE);
+ gnutls_certificate_free_credentials(*x509_cred);
+ return -1;
+ }
+ }
/* If the invalid hostname was specified do nothing, we use a self-signed
* certificate in this case. */
- } else {
- result = 1;
- }
- if (0 >= result) {
- LOG(LOG_ERROR,
- "initialize_tls_session_client(): can't read CA file: '%s'",
- PROXY_CA_FILE);
- gnutls_certificate_free_credentials(*x509_cred);
- return -1;
- }
+
/* And certificate for this website and proxy's private key. */
if (!use_invalid_cert) {
result = gnutls_certificate_set_x509_key_file(*x509_cred,
#define RESPONSE_ERROR "500 Internal Server Error"
#define RESPONSE_MSG "Server certificate validation failed, check logs."
+ int result;
char buffer[sizeof(HTTP_RESPONSE_FORMAT) - 1 /* '\0' */
- 4 * 2 /* four %s */
+ (sizeof(RESPONSE_ERROR) - 1 /* '\0' */) * 3
+ sizeof(RESPONSE_MSG) - 1 /* '\0' */
+ 1 /* '\0' */];
- snprintf(buffer, sizeof(buffer),
- HTTP_RESPONSE_FORMAT,
- RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_MSG);
+ result = snprintf(buffer, sizeof(buffer),
+ HTTP_RESPONSE_FORMAT,
+ RESPONSE_ERROR, RESPONSE_ERROR, RESPONSE_ERROR,
+ RESPONSE_MSG);
+ if (result < 0) {
+ LOG_PERROR(LOG_ERROR,
+ "tls_send_invalid_cert_message(): snprintf failed");
+ return;
+ } else if ((size_t)result >= sizeof(buffer)) {
+ LOG(LOG_ERROR,
+ "tls_send_invalid_cert_message(): snprintf buffer too short");
+ return;
+ }
gnutls_record_send(session, buffer, sizeof(buffer) - 1);
/* don't send trailing '\0' */