f31522130f
Build system (5 gaps hardened): - COOKBOOK_OFFLINE defaults to true (fork-mode) - normalize_patch handles diff -ruN format - New 'repo validate-patches' command (25/25 relibc patches) - 14 patched Qt/Wayland/display recipes added to protected list - relibc archive regenerated with current patch chain Boot fixes (fixable): - Full ISO EFI partition: 16 MiB → 1 MiB (matches mini, BIOS hardcoded 2 MiB offset) - D-Bus system bus: absolute /usr/bin/dbus-daemon path (was skipped) - redbear-sessiond: absolute /usr/bin/redbear-sessiond path (was skipped) - daemon framework: silenced spurious INIT_NOTIFY warnings for oneshot_async services (P0-daemon-silence-init-notify.patch) - udev-shim: demoted INIT_NOTIFY warning to INFO (expected for oneshot_async) - relibc: comprehensive named semaphores (sem_open/close/unlink) replacing upstream todo!() stubs - greeterd: Wayland socket timeout 15s → 30s (compositor DRM wait) - greeter-ui: built and linked (header guard unification, sem_compat stubs removed) - mc: un-ignored in both configs, fixed glib/libiconv/pcre2 transitive deps - greeter config: removed stale keymapd dependency from display/greeter services - prefix toolchain: relibc headers synced, _RELIBC_STDLIB_H guard unified Unfixable (diagnosed, upstream): - i2c-hidd: abort on no-I2C-hardware (QEMU) — process::exit → relibc abort - kded6/greeter-ui: page fault 0x8 — Qt library null deref - Thread panics fd != -1 — Rust std library on Redox - DHCP timeout / eth0 MAC — QEMU user-mode networking - hwrngd/thermald — no hardware RNG/thermal in VM - live preload allocation — BIOS memory fragmentation, continues on demand
58 lines
2.0 KiB
C++
58 lines
2.0 KiB
C++
// Copyright (C) 2016 The Qt Company Ltd.
|
|
// SPDX-License-Identifier: LicenseRef-Qt-Commercial OR GPL-3.0-only
|
|
|
|
#include <QtNetwork/qsslconfiguration.h>
|
|
#include <QtCore/QCoreApplication>
|
|
#include <QtCore/QTextStream>
|
|
#include <stdio.h>
|
|
|
|
int main(int argc, char **argv)
|
|
{
|
|
QCoreApplication app(argc, argv);
|
|
|
|
if (argc < 3) {
|
|
QTextStream out(stdout);
|
|
out << "Usage: " << argv[0] << " host port [options]" << Qt::endl;
|
|
out << "The options can be one or more of the following:" << Qt::endl;
|
|
out << "enable_empty_fragments" << Qt::endl;
|
|
out << "disable_session_tickets" << Qt::endl;
|
|
out << "disable_compression" << Qt::endl;
|
|
out << "disable_sni" << Qt::endl;
|
|
out << "enable_unsafe_reneg" << Qt::endl;
|
|
return 1;
|
|
}
|
|
|
|
QString host = QString::fromLocal8Bit(argv[1]);
|
|
int port = QString::fromLocal8Bit(argv[2]).toInt();
|
|
|
|
QSslConfiguration config = QSslConfiguration::defaultConfiguration();
|
|
|
|
for (int i=3; i < argc; i++) {
|
|
QString option = QString::fromLocal8Bit(argv[i]);
|
|
|
|
if (option == QStringLiteral("enable_empty_fragments"))
|
|
config.setSslOption(QSsl::SslOptionDisableEmptyFragments, false);
|
|
else if (option == QStringLiteral("disable_session_tickets"))
|
|
config.setSslOption(QSsl::SslOptionDisableSessionTickets, true);
|
|
else if (option == QStringLiteral("disable_compression"))
|
|
config.setSslOption(QSsl::SslOptionDisableCompression, true);
|
|
else if (option == QStringLiteral("disable_sni"))
|
|
config.setSslOption(QSsl::SslOptionDisableServerNameIndication, true);
|
|
else if (option == QStringLiteral("enable_unsafe_reneg"))
|
|
config.setSslOption(QSsl::SslOptionDisableLegacyRenegotiation, false);
|
|
}
|
|
|
|
QSslConfiguration::setDefaultConfiguration(config);
|
|
|
|
QSslSocket socket;
|
|
//socket.setSslConfiguration(config);
|
|
socket.connectToHostEncrypted(host, port);
|
|
|
|
if ( !socket.waitForEncrypted() ) {
|
|
qDebug() << socket.errorString();
|
|
return 1;
|
|
}
|
|
|
|
return 0;
|
|
}
|