QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 1 | // Copyright (c) 2017 The Chromium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "net/third_party/quiche/src/quic/core/tls_server_handshaker.h" |
| 6 | |
| 7 | #include <memory> |
vasilvv | 872e7a3 | 2019-03-12 16:42:44 -0700 | [diff] [blame] | 8 | #include <string> |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 9 | |
| 10 | #include "third_party/boringssl/src/include/openssl/pool.h" |
| 11 | #include "third_party/boringssl/src/include/openssl/ssl.h" |
| 12 | #include "net/third_party/quiche/src/quic/core/crypto/quic_crypto_server_config.h" |
| 13 | #include "net/third_party/quiche/src/quic/core/crypto/transport_parameters.h" |
| 14 | #include "net/third_party/quiche/src/quic/platform/api/quic_logging.h" |
| 15 | #include "net/third_party/quiche/src/quic/platform/api/quic_ptr_util.h" |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 16 | |
| 17 | namespace quic { |
| 18 | |
| 19 | TlsServerHandshaker::SignatureCallback::SignatureCallback( |
| 20 | TlsServerHandshaker* handshaker) |
| 21 | : handshaker_(handshaker) {} |
| 22 | |
| 23 | void TlsServerHandshaker::SignatureCallback::Run(bool ok, |
vasilvv | c48c871 | 2019-03-11 13:38:16 -0700 | [diff] [blame] | 24 | std::string signature) { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 25 | if (handshaker_ == nullptr) { |
| 26 | return; |
| 27 | } |
| 28 | if (ok) { |
| 29 | handshaker_->cert_verify_sig_ = std::move(signature); |
| 30 | } |
| 31 | State last_state = handshaker_->state_; |
| 32 | handshaker_->state_ = STATE_SIGNATURE_COMPLETE; |
| 33 | handshaker_->signature_callback_ = nullptr; |
| 34 | if (last_state == STATE_SIGNATURE_PENDING) { |
| 35 | handshaker_->AdvanceHandshake(); |
| 36 | } |
| 37 | } |
| 38 | |
| 39 | void TlsServerHandshaker::SignatureCallback::Cancel() { |
| 40 | handshaker_ = nullptr; |
| 41 | } |
| 42 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 43 | // static |
| 44 | bssl::UniquePtr<SSL_CTX> TlsServerHandshaker::CreateSslCtx() { |
nharper | 6ebe83b | 2019-06-13 17:43:52 -0700 | [diff] [blame] | 45 | return TlsServerConnection::CreateSslCtx(); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 46 | } |
| 47 | |
| 48 | TlsServerHandshaker::TlsServerHandshaker(QuicCryptoStream* stream, |
| 49 | QuicSession* session, |
| 50 | SSL_CTX* ssl_ctx, |
| 51 | ProofSource* proof_source) |
| 52 | : TlsHandshaker(stream, session, ssl_ctx), |
| 53 | proof_source_(proof_source), |
nharper | 6ebe83b | 2019-06-13 17:43:52 -0700 | [diff] [blame] | 54 | crypto_negotiated_params_(new QuicCryptoNegotiatedParameters), |
| 55 | tls_connection_(ssl_ctx, this) { |
zhongyi | 546cc45 | 2019-04-12 15:27:49 -0700 | [diff] [blame] | 56 | DCHECK_EQ(PROTOCOL_TLS1_3, |
| 57 | session->connection()->version().handshake_protocol); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 58 | |
| 59 | // Configure the SSL to be a server. |
| 60 | SSL_set_accept_state(ssl()); |
| 61 | |
| 62 | if (!SetTransportParameters()) { |
| 63 | CloseConnection(QUIC_HANDSHAKE_FAILED, |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 64 | "Server failed to set Transport Parameters"); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 65 | } |
| 66 | } |
| 67 | |
| 68 | TlsServerHandshaker::~TlsServerHandshaker() { |
| 69 | CancelOutstandingCallbacks(); |
| 70 | } |
| 71 | |
| 72 | void TlsServerHandshaker::CancelOutstandingCallbacks() { |
| 73 | if (signature_callback_) { |
| 74 | signature_callback_->Cancel(); |
| 75 | signature_callback_ = nullptr; |
| 76 | } |
| 77 | } |
| 78 | |
| 79 | bool TlsServerHandshaker::GetBase64SHA256ClientChannelID( |
dschinazi | 17d4242 | 2019-06-18 16:35:07 -0700 | [diff] [blame] | 80 | std::string* /*output*/) const { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 81 | // Channel ID is not supported when TLS is used in QUIC. |
| 82 | return false; |
| 83 | } |
| 84 | |
| 85 | void TlsServerHandshaker::SendServerConfigUpdate( |
dschinazi | 17d4242 | 2019-06-18 16:35:07 -0700 | [diff] [blame] | 86 | const CachedNetworkParameters* /*cached_network_params*/) { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 87 | // SCUP messages aren't supported when using the TLS handshake. |
| 88 | } |
| 89 | |
| 90 | uint8_t TlsServerHandshaker::NumHandshakeMessages() const { |
| 91 | // TODO(nharper): Return a sensible value here. |
| 92 | return 0; |
| 93 | } |
| 94 | |
| 95 | uint8_t TlsServerHandshaker::NumHandshakeMessagesWithServerNonces() const { |
| 96 | // TODO(nharper): Return a sensible value here. |
| 97 | return 0; |
| 98 | } |
| 99 | |
| 100 | int TlsServerHandshaker::NumServerConfigUpdateMessagesSent() const { |
| 101 | // SCUP messages aren't supported when using the TLS handshake. |
| 102 | return 0; |
| 103 | } |
| 104 | |
| 105 | const CachedNetworkParameters* |
| 106 | TlsServerHandshaker::PreviousCachedNetworkParams() const { |
| 107 | return nullptr; |
| 108 | } |
| 109 | |
| 110 | bool TlsServerHandshaker::ZeroRttAttempted() const { |
| 111 | // TODO(nharper): Support 0-RTT with TLS 1.3 in QUIC. |
| 112 | return false; |
| 113 | } |
| 114 | |
| 115 | void TlsServerHandshaker::SetPreviousCachedNetworkParams( |
dschinazi | 17d4242 | 2019-06-18 16:35:07 -0700 | [diff] [blame] | 116 | CachedNetworkParameters /*cached_network_params*/) {} |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 117 | |
| 118 | bool TlsServerHandshaker::ShouldSendExpectCTHeader() const { |
| 119 | return false; |
| 120 | } |
| 121 | |
| 122 | bool TlsServerHandshaker::encryption_established() const { |
| 123 | return encryption_established_; |
| 124 | } |
| 125 | |
| 126 | bool TlsServerHandshaker::handshake_confirmed() const { |
| 127 | return handshake_confirmed_; |
| 128 | } |
| 129 | |
| 130 | const QuicCryptoNegotiatedParameters& |
| 131 | TlsServerHandshaker::crypto_negotiated_params() const { |
| 132 | return *crypto_negotiated_params_; |
| 133 | } |
| 134 | |
| 135 | CryptoMessageParser* TlsServerHandshaker::crypto_message_parser() { |
| 136 | return TlsHandshaker::crypto_message_parser(); |
| 137 | } |
| 138 | |
nharper | 486a8a9 | 2019-08-28 16:25:10 -0700 | [diff] [blame] | 139 | size_t TlsServerHandshaker::BufferSizeLimitForLevel( |
| 140 | EncryptionLevel level) const { |
| 141 | return TlsHandshaker::BufferSizeLimitForLevel(level); |
| 142 | } |
| 143 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 144 | void TlsServerHandshaker::AdvanceHandshake() { |
| 145 | if (state_ == STATE_CONNECTION_CLOSED) { |
| 146 | QUIC_LOG(INFO) << "TlsServerHandshaker received handshake message after " |
| 147 | "connection was closed"; |
| 148 | return; |
| 149 | } |
| 150 | if (state_ == STATE_HANDSHAKE_COMPLETE) { |
| 151 | // TODO(nharper): Handle post-handshake messages. |
| 152 | return; |
| 153 | } |
| 154 | |
| 155 | int rv = SSL_do_handshake(ssl()); |
| 156 | if (rv == 1) { |
| 157 | FinishHandshake(); |
| 158 | return; |
| 159 | } |
| 160 | |
| 161 | int ssl_error = SSL_get_error(ssl(), rv); |
| 162 | bool should_close = true; |
| 163 | switch (state_) { |
| 164 | case STATE_LISTENING: |
| 165 | case STATE_SIGNATURE_COMPLETE: |
| 166 | should_close = ssl_error != SSL_ERROR_WANT_READ; |
| 167 | break; |
| 168 | case STATE_SIGNATURE_PENDING: |
| 169 | should_close = ssl_error != SSL_ERROR_WANT_PRIVATE_KEY_OPERATION; |
| 170 | break; |
| 171 | default: |
| 172 | should_close = true; |
| 173 | } |
| 174 | if (should_close && state_ != STATE_CONNECTION_CLOSED) { |
| 175 | QUIC_LOG(WARNING) << "SSL_do_handshake failed; SSL_get_error returns " |
| 176 | << ssl_error << ", state_ = " << state_; |
| 177 | ERR_print_errors_fp(stderr); |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 178 | CloseConnection(QUIC_HANDSHAKE_FAILED, |
| 179 | "Server observed TLS handshake failure"); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 180 | } |
| 181 | } |
| 182 | |
| 183 | void TlsServerHandshaker::CloseConnection(QuicErrorCode error, |
vasilvv | c48c871 | 2019-03-11 13:38:16 -0700 | [diff] [blame] | 184 | const std::string& reason_phrase) { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 185 | state_ = STATE_CONNECTION_CLOSED; |
| 186 | stream()->CloseConnectionWithDetails(error, reason_phrase); |
| 187 | } |
| 188 | |
| 189 | bool TlsServerHandshaker::ProcessTransportParameters( |
vasilvv | c48c871 | 2019-03-11 13:38:16 -0700 | [diff] [blame] | 190 | std::string* error_details) { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 191 | TransportParameters client_params; |
| 192 | const uint8_t* client_params_bytes; |
| 193 | size_t params_bytes_len; |
| 194 | SSL_get_peer_quic_transport_params(ssl(), &client_params_bytes, |
| 195 | ¶ms_bytes_len); |
| 196 | if (params_bytes_len == 0 || |
dschinazi | 6c84c14 | 2019-07-31 09:11:49 -0700 | [diff] [blame] | 197 | !ParseTransportParameters(session()->connection()->version(), |
| 198 | Perspective::IS_CLIENT, client_params_bytes, |
| 199 | params_bytes_len, &client_params)) { |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 200 | *error_details = "Unable to parse Transport Parameters"; |
| 201 | return false; |
| 202 | } |
dschinazi | 6cf4d2a | 2019-04-30 16:20:23 -0700 | [diff] [blame] | 203 | |
| 204 | // When interoperating with non-Google implementations that do not send |
| 205 | // the version extension, set it to what we expect. |
| 206 | if (client_params.version == 0) { |
| 207 | client_params.version = |
| 208 | CreateQuicVersionLabel(session()->connection()->version()); |
| 209 | } |
| 210 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 211 | if (CryptoUtils::ValidateClientHelloVersion( |
| 212 | client_params.version, session()->connection()->version(), |
| 213 | session()->supported_versions(), error_details) != QUIC_NO_ERROR || |
| 214 | session()->config()->ProcessTransportParameters( |
| 215 | client_params, CLIENT, error_details) != QUIC_NO_ERROR) { |
| 216 | return false; |
| 217 | } |
| 218 | |
| 219 | session()->OnConfigNegotiated(); |
| 220 | return true; |
| 221 | } |
| 222 | |
| 223 | bool TlsServerHandshaker::SetTransportParameters() { |
| 224 | TransportParameters server_params; |
| 225 | server_params.perspective = Perspective::IS_SERVER; |
| 226 | server_params.supported_versions = |
| 227 | CreateQuicVersionLabelVector(session()->supported_versions()); |
| 228 | server_params.version = |
| 229 | CreateQuicVersionLabel(session()->connection()->version()); |
| 230 | |
| 231 | if (!session()->config()->FillTransportParameters(&server_params)) { |
| 232 | return false; |
| 233 | } |
| 234 | |
| 235 | // TODO(nharper): Provide an actual value for the stateless reset token. |
| 236 | server_params.stateless_reset_token.resize(16); |
| 237 | std::vector<uint8_t> server_params_bytes; |
dschinazi | 6c84c14 | 2019-07-31 09:11:49 -0700 | [diff] [blame] | 238 | if (!SerializeTransportParameters(session()->connection()->version(), |
| 239 | server_params, &server_params_bytes) || |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 240 | SSL_set_quic_transport_params(ssl(), server_params_bytes.data(), |
| 241 | server_params_bytes.size()) != 1) { |
| 242 | return false; |
| 243 | } |
| 244 | return true; |
| 245 | } |
| 246 | |
| 247 | void TlsServerHandshaker::FinishHandshake() { |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 248 | if (!valid_alpn_received_) { |
| 249 | QUIC_DLOG(ERROR) |
| 250 | << "Server: handshake finished without receiving a known ALPN"; |
| 251 | // TODO(b/130164908) this should send no_application_protocol |
| 252 | // instead of QUIC_HANDSHAKE_FAILED. |
| 253 | CloseConnection(QUIC_HANDSHAKE_FAILED, |
| 254 | "Server did not receive a known ALPN"); |
| 255 | return; |
| 256 | } |
| 257 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 258 | QUIC_LOG(INFO) << "Server: handshake finished"; |
| 259 | state_ = STATE_HANDSHAKE_COMPLETE; |
| 260 | |
| 261 | session()->connection()->SetDefaultEncryptionLevel(ENCRYPTION_FORWARD_SECURE); |
| 262 | session()->NeuterUnencryptedData(); |
| 263 | encryption_established_ = true; |
| 264 | handshake_confirmed_ = true; |
nharper | 8a72e4f | 2019-08-13 19:17:08 -0700 | [diff] [blame] | 265 | session()->OnCryptoHandshakeEvent(QuicSession::HANDSHAKE_CONFIRMED); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 266 | } |
| 267 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 268 | ssl_private_key_result_t TlsServerHandshaker::PrivateKeySign( |
| 269 | uint8_t* out, |
| 270 | size_t* out_len, |
| 271 | size_t max_out, |
| 272 | uint16_t sig_alg, |
| 273 | QuicStringPiece in) { |
| 274 | signature_callback_ = new SignatureCallback(this); |
| 275 | proof_source_->ComputeTlsSignature( |
| 276 | session()->connection()->self_address(), hostname_, sig_alg, in, |
| 277 | std::unique_ptr<SignatureCallback>(signature_callback_)); |
| 278 | if (state_ == STATE_SIGNATURE_COMPLETE) { |
| 279 | return PrivateKeyComplete(out, out_len, max_out); |
| 280 | } |
| 281 | state_ = STATE_SIGNATURE_PENDING; |
| 282 | return ssl_private_key_retry; |
| 283 | } |
| 284 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 285 | ssl_private_key_result_t TlsServerHandshaker::PrivateKeyComplete( |
| 286 | uint8_t* out, |
| 287 | size_t* out_len, |
| 288 | size_t max_out) { |
| 289 | if (state_ == STATE_SIGNATURE_PENDING) { |
| 290 | return ssl_private_key_retry; |
| 291 | } |
| 292 | if (cert_verify_sig_.size() > max_out || cert_verify_sig_.empty()) { |
| 293 | return ssl_private_key_failure; |
| 294 | } |
| 295 | *out_len = cert_verify_sig_.size(); |
| 296 | memcpy(out, cert_verify_sig_.data(), *out_len); |
| 297 | cert_verify_sig_.clear(); |
| 298 | cert_verify_sig_.shrink_to_fit(); |
| 299 | return ssl_private_key_success; |
| 300 | } |
| 301 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 302 | int TlsServerHandshaker::SelectCertificate(int* out_alert) { |
| 303 | const char* hostname = SSL_get_servername(ssl(), TLSEXT_NAMETYPE_host_name); |
| 304 | if (hostname) { |
| 305 | hostname_ = hostname; |
| 306 | } else { |
| 307 | QUIC_LOG(INFO) << "No hostname indicated in SNI"; |
| 308 | } |
| 309 | |
| 310 | QuicReferenceCountedPointer<ProofSource::Chain> chain = |
| 311 | proof_source_->GetCertChain(session()->connection()->self_address(), |
| 312 | hostname_); |
| 313 | if (chain->certs.empty()) { |
| 314 | QUIC_LOG(ERROR) << "No certs provided for host '" << hostname_ << "'"; |
| 315 | return SSL_TLSEXT_ERR_ALERT_FATAL; |
| 316 | } |
| 317 | |
| 318 | std::vector<CRYPTO_BUFFER*> certs; |
| 319 | certs.resize(chain->certs.size()); |
| 320 | for (size_t i = 0; i < certs.size(); i++) { |
| 321 | certs[i] = CRYPTO_BUFFER_new( |
| 322 | reinterpret_cast<const uint8_t*>(chain->certs[i].data()), |
| 323 | chain->certs[i].length(), nullptr); |
| 324 | } |
| 325 | |
nharper | 6ebe83b | 2019-06-13 17:43:52 -0700 | [diff] [blame] | 326 | tls_connection_.SetCertChain(certs); |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 327 | |
| 328 | for (size_t i = 0; i < certs.size(); i++) { |
| 329 | CRYPTO_BUFFER_free(certs[i]); |
| 330 | } |
| 331 | |
vasilvv | c48c871 | 2019-03-11 13:38:16 -0700 | [diff] [blame] | 332 | std::string error_details; |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 333 | if (!ProcessTransportParameters(&error_details)) { |
| 334 | CloseConnection(QUIC_HANDSHAKE_FAILED, error_details); |
| 335 | *out_alert = SSL_AD_INTERNAL_ERROR; |
| 336 | return SSL_TLSEXT_ERR_ALERT_FATAL; |
| 337 | } |
| 338 | |
| 339 | QUIC_LOG(INFO) << "Set " << chain->certs.size() << " certs for server"; |
| 340 | return SSL_TLSEXT_ERR_OK; |
| 341 | } |
| 342 | |
dschinazi | 35e749e | 2019-04-09 09:36:04 -0700 | [diff] [blame] | 343 | int TlsServerHandshaker::SelectAlpn(const uint8_t** out, |
| 344 | uint8_t* out_len, |
| 345 | const uint8_t* in, |
| 346 | unsigned in_len) { |
| 347 | // |in| contains a sequence of 1-byte-length-prefixed values. |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 348 | *out_len = 0; |
| 349 | *out = nullptr; |
dschinazi | 35e749e | 2019-04-09 09:36:04 -0700 | [diff] [blame] | 350 | if (in_len == 0) { |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 351 | QUIC_DLOG(ERROR) << "No ALPN provided by client"; |
| 352 | return SSL_TLSEXT_ERR_NOACK; |
dschinazi | 35e749e | 2019-04-09 09:36:04 -0700 | [diff] [blame] | 353 | } |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 354 | |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 355 | CBS all_alpns; |
| 356 | CBS_init(&all_alpns, in, in_len); |
| 357 | |
vasilvv | ad7424f | 2019-08-30 00:27:14 -0700 | [diff] [blame] | 358 | std::vector<QuicStringPiece> alpns; |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 359 | while (CBS_len(&all_alpns) > 0) { |
| 360 | CBS alpn; |
| 361 | if (!CBS_get_u8_length_prefixed(&all_alpns, &alpn)) { |
| 362 | QUIC_DLOG(ERROR) << "Failed to parse ALPN length"; |
| 363 | return SSL_TLSEXT_ERR_NOACK; |
| 364 | } |
vasilvv | ad7424f | 2019-08-30 00:27:14 -0700 | [diff] [blame] | 365 | |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 366 | const size_t alpn_length = CBS_len(&alpn); |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 367 | if (alpn_length == 0) { |
| 368 | QUIC_DLOG(ERROR) << "Received invalid zero-length ALPN"; |
| 369 | return SSL_TLSEXT_ERR_NOACK; |
| 370 | } |
vasilvv | ad7424f | 2019-08-30 00:27:14 -0700 | [diff] [blame] | 371 | |
| 372 | alpns.emplace_back(reinterpret_cast<const char*>(CBS_data(&alpn)), |
| 373 | alpn_length); |
dschinazi | 35e749e | 2019-04-09 09:36:04 -0700 | [diff] [blame] | 374 | } |
dschinazi | 9145364 | 2019-08-01 11:12:15 -0700 | [diff] [blame] | 375 | |
vasilvv | ad7424f | 2019-08-30 00:27:14 -0700 | [diff] [blame] | 376 | auto selected_alpn = session()->SelectAlpn(alpns); |
| 377 | if (selected_alpn == alpns.end()) { |
| 378 | QUIC_DLOG(ERROR) << "No known ALPN provided by client"; |
| 379 | return SSL_TLSEXT_ERR_NOACK; |
| 380 | } |
| 381 | |
| 382 | session()->OnAlpnSelected(*selected_alpn); |
| 383 | valid_alpn_received_ = true; |
| 384 | *out_len = selected_alpn->size(); |
| 385 | *out = reinterpret_cast<const uint8_t*>(selected_alpn->data()); |
| 386 | return SSL_TLSEXT_ERR_OK; |
dschinazi | 35e749e | 2019-04-09 09:36:04 -0700 | [diff] [blame] | 387 | } |
| 388 | |
QUICHE team | a6ef0a6 | 2019-03-07 20:34:33 -0500 | [diff] [blame] | 389 | } // namespace quic |