From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.ffmpeg.org (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTPS id 5CFE14DD12 for ; Wed, 4 Jun 2025 16:26:51 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.ffmpeg.org (Postfix) with ESMTP id 2733768D678; Wed, 4 Jun 2025 19:26:48 +0300 (EEST) Received: from out162-62-58-216.mail.qq.com (out162-62-58-216.mail.qq.com [162.62.58.216]) by ffbox0-bg.ffmpeg.org (Postfix) with ESMTPS id 1146468D61A for ; Wed, 4 Jun 2025 19:26:40 +0300 (EEST) Received: from localhost.localdomain ([2408:8411:6090:6c74:30f5:445f:b355:db87]) by newxmesmtplogicsvrszb20-0.qq.com (NewEsmtp) with SMTP id 6A428224; Thu, 05 Jun 2025 00:26:36 +0800 X-QQ-mid: xmsmtpt1749054396tmdnyc8zn Message-ID: X-QQ-XMAILINFO: Nxcyh1H/ItmfJXhhnwYAYntxBD9dUWiKPQzW9vfxoGlNTWITw5gJTmJ5IxYfb+ hfyor/4VFG0b9f3n2S0MIDHNhv17ueOSHMYjVrui8bJ+hqYthn2D4eN3zfSmwtYLjIG4/BJJ/fNm Xp/D8uztFw+8jhsi+bVh7HsDNbh/aBqOIgNxQNBX/Xb+6Yv4Z3K2eXbH9xqb74pQRvWNRiYgXARk fgIoLJaRRrHbLXu6ETzqiWgWSvfg7qmx9UX8wTchOdMtQU/96ivpkbC/wacSOfgtiBcNGroO+smc 4TvYPv1M+8Q5XMj+kR+HY/jGdT0yICHfO9AO49VwNkQNVdQS7a3j3KNgpMx5XcEleB6sBeH8uqIz IVjytRLcR1BuOqBZc5SL19x28n57C0JIUm8Cln8WbCNJA4odelrBRrQRYM3QM7XX24UhgrVtS5PD 3S70FKn0L4XVVbaAQhRE93txGPSzFVsl/wHSTuBLIHczk+XcKmX5Uz4PgxVvJCd/pbfa+nQZqWkW yBKbccErPACn38HIp0pKsxqnJI83ZO4gOoNfeR8nPtih7u7EG8b3BUv9k15fo9lreFjFbATy2B7j vZxqsv6hDxtP3ub2h4Nd/yTxKIguVk3lkFJxrloiA3YFHUY+RIxYSUN6kZNs25j/Pw44tsrrX7oA oDmF1uvG6yT1uvrrgKSQ5zAo7NaEVNr6R0gToBxbCA6w27GKOAVZ/hrzqhIfnIf5IvPGLDUVzCUS wPdc+v1IDwXlIqokz3vW04OMbArU8d22ngsZCiFGF9Qlhch56bSQ+k0ebjNoldfr9RjBCWLLqUoi AKBwPldiAto053aLNtrCs3g8leq2UDQgXU6FpzC8hbpZVQCZnN5BSL1dXUgy5bwR4z6NCaRpCoM+ 8mJb/p33PrFlv/zk2jFew0F8+22O4R9wgcdUzr8QwrCyB6rPiX32aonBHg4bAKvSLAq36UIg6LLn 0mvhyIlFlTg6mJkRq+vJwtTSeAI4KCQP36VY7mdco= X-QQ-XMRINFO: OD9hHCdaPRBwq3WW+NvGbIU= To: ffmpeg-devel@ffmpeg.org Date: Thu, 5 Jun 2025 00:26:34 +0800 X-OQ-MSGID: <20250604162634.79280-1-jacklau1222@qq.com> X-Mailer: git-send-email 2.49.0 MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH] avformat/tls_openssl: fix build error when openssl version < 3 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Jack Lau via ffmpeg-devel Reply-To: FFmpeg development discussions and patches Cc: Jack Lau Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: fix the missing data structure pkey in the tls_context Signed-off-by: Jack Lau --- libavformat/tls_openssl.c | 30 +++++++++++++++++------------- 1 file changed, 17 insertions(+), 13 deletions(-) diff --git a/libavformat/tls_openssl.c b/libavformat/tls_openssl.c index b589d5d90a..bddeee9af8 100644 --- a/libavformat/tls_openssl.c +++ b/libavformat/tls_openssl.c @@ -467,6 +467,7 @@ typedef struct TLSContext { TLSShared tls_shared; SSL_CTX *ctx; SSL *ssl; + EVP_PKEY *pkey; #if OPENSSL_VERSION_NUMBER >= 0x1010000fL BIO_METHOD* url_bio_method; #endif @@ -811,7 +812,7 @@ static av_cold int openssl_init_ca_key_cert(URLContext *h) int ret; TLSContext *p = h->priv_data; TLSShared *c = &p->tls_shared; - EVP_PKEY *pkey = NULL; + EVP_PKEY *pkey = p->pkey; X509 *cert = NULL; /* setup ca, private key, certificate */ if (c->ca_file) { @@ -876,6 +877,9 @@ static int dtls_start(URLContext *h, const char *url, int flags, AVDictionary ** int ret = 0; c->is_dtls = 1; const char* ciphers = "ALL"; +#if OPENSSL_VERSION_NUMBER < 0x10002000L // v1.0.2 + EC_KEY *ec_key; +#endif /** * The profile for OpenSSL's SRTP is SRTP_AES128_CM_SHA1_80, see ssl/d1_srtp.c. * The profile for FFmpeg's SRTP is SRTP_AES128_CM_HMAC_SHA1_80, see libavformat/srtp.c. @@ -908,15 +912,6 @@ static int dtls_start(URLContext *h, const char *url, int flags, AVDictionary ** } #endif -#if OPENSSL_VERSION_NUMBER < 0x10100000L // v1.1.x -#if OPENSSL_VERSION_NUMBER < 0x10002000L // v1.0.2 - if (ctx->dtls_eckey) - SSL_CTX_set_tmp_ecdh(p->ctx, p->dtls_eckey); -#else - SSL_CTX_set_ecdh_auto(p->ctx, 1); -#endif -#endif - /** * We activate "ALL" cipher suites to align with the peer's capabilities, * ensuring maximum compatibility. @@ -930,6 +925,17 @@ static int dtls_start(URLContext *h, const char *url, int flags, AVDictionary ** ret = openssl_init_ca_key_cert(h); if (ret < 0) goto fail; +#if OPENSSL_VERSION_NUMBER < 0x10100000L // v1.1.x +#if OPENSSL_VERSION_NUMBER < 0x10002000L // v1.0.2 + if (p->pkey) + ec_key = EVP_PKEY_get1_EC_KEY(p->pkey); + if (ec_key) + SSL_CTX_set_tmp_ecdh(p->ctx, ec_key); +#else + SSL_CTX_set_ecdh_auto(p->ctx, 1); +#endif +#endif + /* Server will send Certificate Request. */ SSL_CTX_set_verify(p->ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, openssl_dtls_verify_callback); /* The depth count is "level 0:peer certificate", "level 1: CA certificate", @@ -1015,9 +1021,7 @@ static av_cold int dtls_close(URLContext *h) av_freep(&ctx->tls_shared.fingerprint); av_freep(&ctx->tls_shared.cert_buf); av_freep(&ctx->tls_shared.key_buf); -#if OPENSSL_VERSION_NUMBER < 0x30000000L /* OpenSSL 3.0 */ - EC_KEY_free(ctx->dtls_eckey); -#endif + EVP_PKEY_free(ctx->pkey); return 0; } -- 2.49.0 _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".