1
0
mirror of https://github.com/golang/go synced 2024-11-24 08:20:03 -07:00
go/src
Roland Shoemaker cc43e191ce crypto/x509: don't allow too long serials
Don't create certificates that have serial numbers that are longer
than 20 octets (when encoded), since these are explicitly disallowed
by RFC 5280.

Change-Id: I292b7001f45bed0971b2d519b6de26f0b90860ae
Reviewed-on: https://go-review.googlesource.com/c/go/+/400377
Reviewed-by: Roland Shoemaker <roland@golang.org>
Run-TryBot: Roland Shoemaker <roland@golang.org>
Auto-Submit: Roland Shoemaker <roland@golang.org>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
2022-04-14 22:52:29 +00:00
..
archive all: gofmt main repo 2022-04-11 16:34:30 +00:00
bufio
builtin all: gofmt main repo 2022-04-11 16:34:30 +00:00
bytes all: gofmt main repo 2022-04-11 16:34:30 +00:00
cmd cmd/compile: modify switches of strings to use jump table for lengths 2022-04-14 21:16:11 +00:00
compress all: gofmt main repo 2022-04-11 16:34:30 +00:00
container all: gofmt main repo 2022-04-11 16:34:30 +00:00
context all: gofmt main repo 2022-04-11 16:34:30 +00:00
crypto crypto/x509: don't allow too long serials 2022-04-14 22:52:29 +00:00
database/sql all: gofmt main repo 2022-04-11 16:34:30 +00:00
debug debug/dwarf: better stmt list attr checking in LineReader 2022-04-14 18:00:13 +00:00
embed all: gofmt main repo 2022-04-11 16:34:30 +00:00
encoding encoding/pem: fix stack overflow in Decode 2022-04-12 15:19:32 +00:00
errors
expvar all: gofmt main repo 2022-04-11 16:34:30 +00:00
flag all: gofmt main repo 2022-04-11 16:34:30 +00:00
fmt all: gofmt main repo 2022-04-11 16:34:30 +00:00
go go/ast, go/printer: recognize export and extern line directives 2022-04-11 22:03:44 +00:00
hash all: gofmt main repo 2022-04-11 16:34:30 +00:00
html all: gofmt main repo 2022-04-11 16:34:30 +00:00
image all: gofmt main repo 2022-04-11 16:34:30 +00:00
index/suffixarray all: gofmt main repo 2022-04-11 16:34:30 +00:00
internal all: gofmt main repo 2022-04-11 16:34:30 +00:00
io
log all: gofmt main repo 2022-04-11 16:34:30 +00:00
math math: improve documentation of Copysign 2022-04-14 17:42:53 +00:00
mime all: gofmt main repo 2022-04-11 16:34:30 +00:00
net net/http/httptest: allow multiple fields be present in one Trailer field 2022-04-11 23:17:38 +00:00
os os: mark Solaris nam/door/port files as irregular 2022-04-12 01:41:47 +00:00
path all: gofmt main repo 2022-04-11 16:34:30 +00:00
plugin all: separate doc comment from //go: directives 2022-04-05 17:54:15 +00:00
reflect all: gofmt main repo 2022-04-11 16:34:30 +00:00
regexp all: gofmt main repo 2022-04-11 16:34:30 +00:00
runtime runtime: port memmove, memclr to register ABI on riscv64 2022-04-13 01:15:22 +00:00
sort sort: use pdqsort 2022-04-13 20:16:24 +00:00
strconv all: gofmt main repo 2022-04-11 16:34:30 +00:00
strings all: gofmt main repo 2022-04-11 16:34:30 +00:00
sync all: gofmt main repo 2022-04-11 16:34:30 +00:00
syscall syscall: check correct group in Faccessat 2022-04-12 21:12:19 +00:00
testdata
testing all: gofmt main repo 2022-04-11 16:34:30 +00:00
text all: gofmt main repo 2022-04-11 16:34:30 +00:00
time all: gofmt main repo 2022-04-11 16:34:30 +00:00
unicode all: gofmt main repo 2022-04-11 16:34:30 +00:00
unsafe all: gofmt main repo 2022-04-11 16:34:30 +00:00
vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod
go.sum
make.bash cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00
make.bat cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00
Make.dist
make.rc cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00
race.bash
race.bat
README.vendor
run.bash cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00
run.bat cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00
run.rc cmd/dist: move more environment logic into cmd/dist from make and run scripts 2022-04-05 21:45:19 +00:00

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.