Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 30 additions & 16 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4486,26 +4486,40 @@ const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
}

const Cipher Cipher::EMPTY = Cipher();
const Cipher Cipher::AES_128_CBC = Cipher::FromNid(NID_aes_128_cbc);
const Cipher Cipher::AES_192_CBC = Cipher::FromNid(NID_aes_192_cbc);
const Cipher Cipher::AES_256_CBC = Cipher::FromNid(NID_aes_256_cbc);
const Cipher Cipher::AES_128_CTR = Cipher::FromNid(NID_aes_128_ctr);
const Cipher Cipher::AES_192_CTR = Cipher::FromNid(NID_aes_192_ctr);
const Cipher Cipher::AES_256_CTR = Cipher::FromNid(NID_aes_256_ctr);
const Cipher Cipher::AES_128_GCM = Cipher::FromNid(NID_aes_128_gcm);
const Cipher Cipher::AES_192_GCM = Cipher::FromNid(NID_aes_192_gcm);
const Cipher Cipher::AES_256_GCM = Cipher::FromNid(NID_aes_256_gcm);
const Cipher Cipher::AES_128_KW = Cipher::FromNid(NID_id_aes128_wrap);
const Cipher Cipher::AES_192_KW = Cipher::FromNid(NID_id_aes192_wrap);
const Cipher Cipher::AES_256_KW = Cipher::FromNid(NID_id_aes256_wrap);

// The well-known ciphers are resolved lazily rather than in static
// initializers: EVP_get_cipherbynid() triggers OPENSSL_init_crypto(), and
// doing that while the executable is still being loaded adds the full cost
// of OpenSSL initialization to every process startup, even when crypto is
// never used.
#define NCRYPTO_LAZY_CIPHER(name, nid) \
const Cipher& Cipher::name() { \
static const Cipher cipher = Cipher::FromNid(nid); \
return cipher; \
}

NCRYPTO_LAZY_CIPHER(AES_128_CBC, NID_aes_128_cbc)
NCRYPTO_LAZY_CIPHER(AES_192_CBC, NID_aes_192_cbc)
NCRYPTO_LAZY_CIPHER(AES_256_CBC, NID_aes_256_cbc)
NCRYPTO_LAZY_CIPHER(AES_128_CTR, NID_aes_128_ctr)
NCRYPTO_LAZY_CIPHER(AES_192_CTR, NID_aes_192_ctr)
NCRYPTO_LAZY_CIPHER(AES_256_CTR, NID_aes_256_ctr)
NCRYPTO_LAZY_CIPHER(AES_128_GCM, NID_aes_128_gcm)
NCRYPTO_LAZY_CIPHER(AES_192_GCM, NID_aes_192_gcm)
NCRYPTO_LAZY_CIPHER(AES_256_GCM, NID_aes_256_gcm)
NCRYPTO_LAZY_CIPHER(AES_128_KW, NID_id_aes128_wrap)
NCRYPTO_LAZY_CIPHER(AES_192_KW, NID_id_aes192_wrap)
NCRYPTO_LAZY_CIPHER(AES_256_KW, NID_id_aes256_wrap)

#ifndef OPENSSL_IS_BORINGSSL
const Cipher Cipher::AES_128_OCB = Cipher::FromNid(NID_aes_128_ocb);
const Cipher Cipher::AES_192_OCB = Cipher::FromNid(NID_aes_192_ocb);
const Cipher Cipher::AES_256_OCB = Cipher::FromNid(NID_aes_256_ocb);
NCRYPTO_LAZY_CIPHER(AES_128_OCB, NID_aes_128_ocb)
NCRYPTO_LAZY_CIPHER(AES_192_OCB, NID_aes_192_ocb)
NCRYPTO_LAZY_CIPHER(AES_256_OCB, NID_aes_256_ocb)
#endif

const Cipher Cipher::CHACHA20_POLY1305 = Cipher::FromNid(NID_chacha20_poly1305);
NCRYPTO_LAZY_CIPHER(CHACHA20_POLY1305, NID_chacha20_poly1305)

#undef NCRYPTO_LAZY_CIPHER

bool Cipher::isGcmMode() const {
if (!cipher_) return false;
Expand Down
35 changes: 18 additions & 17 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -502,25 +502,26 @@ class Cipher final {
// Utilities to get various ciphers by type. If the underlying
// implementation does not support the requested cipher, then
// the result will be an empty Cipher object whose bool operator
// will return false.
// will return false. The ciphers are looked up lazily on first use so
// that merely loading the library does not initialize OpenSSL.

static const Cipher EMPTY;
static const Cipher AES_128_CBC;
static const Cipher AES_192_CBC;
static const Cipher AES_256_CBC;
static const Cipher AES_128_CTR;
static const Cipher AES_192_CTR;
static const Cipher AES_256_CTR;
static const Cipher AES_128_GCM;
static const Cipher AES_192_GCM;
static const Cipher AES_256_GCM;
static const Cipher AES_128_KW;
static const Cipher AES_192_KW;
static const Cipher AES_256_KW;
static const Cipher AES_128_OCB;
static const Cipher AES_192_OCB;
static const Cipher AES_256_OCB;
static const Cipher CHACHA20_POLY1305;
static const Cipher& AES_128_CBC();
static const Cipher& AES_192_CBC();
static const Cipher& AES_256_CBC();
static const Cipher& AES_128_CTR();
static const Cipher& AES_192_CTR();
static const Cipher& AES_256_CTR();
static const Cipher& AES_128_GCM();
static const Cipher& AES_192_GCM();
static const Cipher& AES_256_GCM();
static const Cipher& AES_128_KW();
static const Cipher& AES_192_KW();
static const Cipher& AES_256_KW();
static const Cipher& AES_128_OCB();
static const Cipher& AES_192_OCB();
static const Cipher& AES_256_OCB();
static const Cipher& CHACHA20_POLY1305();

struct CipherParams {
int padding;
Expand Down
30 changes: 15 additions & 15 deletions src/crypto/crypto_aes.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,15 +13,15 @@ namespace node::crypto {
constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);

#define VARIANTS_COMMON(V) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM) \
V(CTR_128, AES_CTR_Cipher, ncrypto::Cipher::AES_128_CTR()) \
V(CTR_192, AES_CTR_Cipher, ncrypto::Cipher::AES_192_CTR()) \
V(CTR_256, AES_CTR_Cipher, ncrypto::Cipher::AES_256_CTR()) \
V(CBC_128, AES_Cipher, ncrypto::Cipher::AES_128_CBC()) \
V(CBC_192, AES_Cipher, ncrypto::Cipher::AES_192_CBC()) \
V(CBC_256, AES_Cipher, ncrypto::Cipher::AES_256_CBC()) \
V(GCM_128, AES_Cipher, ncrypto::Cipher::AES_128_GCM()) \
V(GCM_192, AES_Cipher, ncrypto::Cipher::AES_192_GCM()) \
V(GCM_256, AES_Cipher, ncrypto::Cipher::AES_256_GCM()) \
VARIANTS_KW(V)

#ifdef OPENSSL_IS_BORINGSSL
Expand All@@ -33,16 +33,16 @@ constexpr unsigned kNoAuthTagLength = static_cast<unsigned>(-1);
V(KW_256, AES_KW_Cipher, static_cast<const EVP_CIPHER*>(nullptr))
#else
#define VARIANTS_KW(V) \
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW)
V(KW_128, AES_Cipher, ncrypto::Cipher::AES_128_KW()) \
V(KW_192, AES_Cipher, ncrypto::Cipher::AES_192_KW()) \
V(KW_256, AES_Cipher, ncrypto::Cipher::AES_256_KW())
#endif

#if OPENSSL_WITH_AES_OCB
#define VARIANTS_OCB(V) \
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB)
V(OCB_128, AES_Cipher, ncrypto::Cipher::AES_128_OCB()) \
V(OCB_192, AES_Cipher, ncrypto::Cipher::AES_192_OCB()) \
V(OCB_256, AES_Cipher, ncrypto::Cipher::AES_256_OCB())
#else
#define VARIANTS_OCB(V)
#endif
Expand Down
2 changes: 1 addition & 1 deletion src/crypto/crypto_chacha20_poly1305.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,7 +105,7 @@ Maybe<void> ChaCha20Poly1305CipherTraits::AdditionalConfig(
ChaCha20Poly1305CipherConfig* params) {
Environment* env = Environment::GetCurrent(args);

params->cipher = ncrypto::Cipher::CHACHA20_POLY1305;
params->cipher = ncrypto::Cipher::CHACHA20_POLY1305();

#ifndef OPENSSL_IS_BORINGSSL
// On BoringSSL, ChaCha20-Poly1305 is not exposed via the EVP_CIPHER registry
Expand Down
15 changes: 10 additions & 5 deletions src/crypto/crypto_context.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -2507,9 +2507,11 @@ int SecureContext::TicketKeyCallback(SSL* ssl,

ArrayBufferViewContents<unsigned char> aes_key(aes.As<ArrayBufferView>());
if (enc) {
EVP_EncryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
} else {
EVP_DecryptInit_ex(ectx, Cipher::AES_128_CBC, nullptr, aes_key.data(), iv);
EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC(), nullptr, aes_key.data(), iv);
}

return r;
Expand All@@ -2531,8 +2533,11 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
if (enc) {
memcpy(name, sc->ticket_key_name_, sizeof(sc->ticket_key_name_));
if (!ncrypto::CSPRNG(iv, 16) ||
EVP_EncryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
EVP_EncryptInit_ex(ectx,
Cipher::AES_128_CBC(),
nullptr,
sc->ticket_key_aes_,
iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand All@@ -2546,7 +2551,7 @@ int SecureContext::TicketCompatibilityCallback(SSL* ssl,
}

if (EVP_DecryptInit_ex(
ectx, Cipher::AES_128_CBC, nullptr, sc->ticket_key_aes_, iv) <= 0 ||
ectx, Cipher::AES_128_CBC(), nullptr, sc->ticket_key_aes_, iv) <= 0 ||
!InitTicketHmac(
hctx, sc->ticket_key_hmac_, sizeof(sc->ticket_key_hmac_))) {
return -1;
Expand Down
21 changes: 19 additions & 2 deletions src/node.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -533,7 +533,17 @@ static void PlatformInit(ProcessInitializationFlags::Flags flags) {
init_process_flags.store(flags);

if (!(flags & ProcessInitializationFlags::kNoStdioInitialization)) {
atexit(ResetStdio);
// Arrange for ResetStdio() to run at exit. A function-local static with a
// destructor is used instead of atexit() because on macOS atexit() calls
// dladdr() to locate the image that owns the callback, which does a linear
// scan of the (very large) symbol table and costs about a millisecond of
// startup time. Static destructors and atexit() handlers are registered in
// the same list and run in reverse order of registration, so the ordering
// relative to other handlers is unchanged.
static const struct ResetStdioAtExit {
~ResetStdioAtExit() { ResetStdio(); }
} reset_stdio_at_exit;
(void)reset_stdio_at_exit;
}

#ifdef __POSIX__
Expand DownExpand Up@@ -1214,7 +1224,14 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
OPENSSL_INIT_set_config_file_flags(settings,
CONF_MFLAGS_IGNORE_MISSING_FILE);

OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, settings);
// OPENSSL_INIT_NO_ATEXIT: do not let OpenSSL register OPENSSL_cleanup()
// with atexit(). Nothing needs OpenSSL to be torn down when the process
// exits, and on macOS atexit() itself is expensive: it calls dladdr(),
// which linearly scans the executable's (very large) symbol table and
// costs about a millisecond on every process start. This must be part of
// the first OPENSSL_init_crypto() call in the process to take effect.
OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG | OPENSSL_INIT_NO_ATEXIT,
settings);
OPENSSL_INIT_free(settings);

if (ERR_peek_error() != 0) {
Expand Down
Loading