Index | Thread | Search

From:
Theo Buehler <tb@theobuehler.org>
Subject:
rpki-client: rename valid_x509() to valid_cert()
To:
tech@openbsd.org
Date:
Thu, 24 Sep 2026 16:04:49 +0200

Download raw body.

Thread
API taking a struct cert usually has a cert in its name, so valid_x509()
is misnamed after today's surgery. Fix this.

Index: extern.h
===================================================================
RCS file: /cvs/src/usr.sbin/rpki-client/extern.h,v
diff -u -p -r1.298 extern.h
--- extern.h	24 Sep 2026 13:58:36 -0000	1.298
+++ extern.h	24 Sep 2026 14:02:55 -0000
@@ -831,7 +831,7 @@ int		 valid_hash(unsigned char *, size_t
 int		 valid_filename(const char *, size_t);
 int		 valid_uri(const char *, size_t, const char *);
 int		 valid_origin(const char *, const char *);
-int		 valid_x509(char *, X509_STORE_CTX *, struct cert *,
+int		 valid_cert(char *, X509_STORE_CTX *, struct cert *,
 		    struct auth *, struct crl *, const char **);
 int		 valid_rsc(const char *, struct cert *, struct rsc *);
 int		 valid_econtent_version(const char *, const ASN1_INTEGER *,
Index: filemode.c
===================================================================
RCS file: /cvs/src/usr.sbin/rpki-client/filemode.c,v
diff -u -p -r1.90 filemode.c
--- filemode.c	24 Sep 2026 13:58:36 -0000	1.90
+++ filemode.c	24 Sep 2026 14:02:55 -0000
@@ -224,7 +224,7 @@ parse_load_certchain(char *uri)
 		uri = filestack[i - 1];
 
 		crl = crl_get(&crls, a);
-		if (!valid_x509(uri, ctx, cert, a, crl, &errstr)) {
+		if (!valid_cert(uri, ctx, cert, a, crl, &errstr)) {
 			if (errstr != NULL)
 				warnx("%s: %s", uri, errstr);
 			goto fail;
@@ -595,7 +595,7 @@ proc_parser_file(char *file, unsigned ch
 		a = parse_load_certchain(aia);
 		c = crl_get(&crls, a);
 
-		if ((status = valid_x509(file, ctx, cert, a, c, &errstr))) {
+		if ((status = valid_cert(file, ctx, cert, a, c, &errstr))) {
 			switch (type) {
 			case RTYPE_ASPA:
 				status = aspa->valid;
Index: parser.c
===================================================================
RCS file: /cvs/src/usr.sbin/rpki-client/parser.c,v
diff -u -p -r1.188 parser.c
--- parser.c	24 Sep 2026 13:58:36 -0000	1.188
+++ parser.c	24 Sep 2026 14:02:55 -0000
@@ -220,7 +220,7 @@ proc_parser_roa(char *file, const unsign
 		goto out;
 	crl = crl_get(&crls, a);
 
-	if (!valid_x509(file, ctx, cert, a, crl, &errstr)) {
+	if (!valid_cert(file, ctx, cert, a, crl, &errstr)) {
 		warnx("%s: %s", file, errstr);
 		goto out;
 	}
@@ -262,7 +262,7 @@ proc_parser_spl(char *file, const unsign
 		goto out;
 	crl = crl_get(&crls, a);
 
-	if (!valid_x509(file, ctx, cert, a, crl, &errstr)) {
+	if (!valid_cert(file, ctx, cert, a, crl, &errstr)) {
 		warnx("%s: %s", file, errstr);
 		goto out;
 	}
@@ -440,7 +440,7 @@ proc_parser_mft_pre(struct entity *entp,
 	a = find_issuer(file, entp->certid, mft->aki, NULL);
 	if (a == NULL)
 		goto err;
-	if (!valid_x509(file, ctx, cert, a, *crl, errstr))
+	if (!valid_cert(file, ctx, cert, a, *crl, errstr))
 		goto err;
 	cert_free(cert);
 	cert = NULL;
@@ -625,7 +625,7 @@ proc_parser_cert(char *file, const unsig
 		goto out;
 	crl = crl_get(&crls, a);
 
-	if (!valid_x509(file, ctx, cert, a, crl, &errstr)) {
+	if (!valid_cert(file, ctx, cert, a, crl, &errstr)) {
 		if (errstr != NULL)
 			warnx("%s: %s", file, errstr);
 		goto out;
@@ -786,7 +786,7 @@ proc_parser_aspa(char *file, const unsig
 		goto out;
 	crl = crl_get(&crls, a);
 
-	if (!valid_x509(file, ctx, cert, a, crl, &errstr)) {
+	if (!valid_cert(file, ctx, cert, a, crl, &errstr)) {
 		warnx("%s: %s", file, errstr);
 		goto out;
 	}
@@ -827,7 +827,7 @@ proc_parser_tak(char *file, const unsign
 		goto out;
 	crl = crl_get(&crls, a);
 
-	if (!valid_x509(file, ctx, cert, a, crl, &errstr)) {
+	if (!valid_cert(file, ctx, cert, a, crl, &errstr)) {
 		warnx("%s: %s", file, errstr);
 		goto out;
 	}
Index: validate.c
===================================================================
RCS file: /cvs/src/usr.sbin/rpki-client/validate.c,v
diff -u -p -r1.89 validate.c
--- validate.c	24 Sep 2026 13:58:36 -0000	1.89
+++ validate.c	24 Sep 2026 14:02:55 -0000
@@ -408,7 +408,7 @@ pretty_revocation_time(X509 *x509, X509_
  * returned by X509_verify_cert_error_string().
  */
 int
-valid_x509(char *file, X509_STORE_CTX *store_ctx, struct cert *cert,
+valid_cert(char *file, X509_STORE_CTX *store_ctx, struct cert *cert,
     struct auth *a, struct crl *crl, const char **errstr)
 {
 	X509			*x509 = cert->x509;