You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ALTCP TLS client configurations should require server certificate verification when a CA certificate is configured. This keeps certificate validation in the TLS configuration layer and makes the configured trust anchor effective.
what is your solution
Use MBEDTLS_SSL_VERIFY_REQUIRED for client TLS configurations that provide a CA certificate. Keep the existing optional verification mode for server configurations and client configurations without a CA certificate to preserve current compatibility.
action: no fork action run was available after pushing the branch
validation
git diff --check
static source check confirmed both altcp_tls_create_config_client() and altcp_tls_create_config_client_2wayauth() use the shared client configuration path
scons -j4 in bsp/bouffalo_lab/bl808/m0 did not reach compilation because the configured toolchain path /opt/Xuantie-900-gcc-elf-newlib-x86_64-V2.6.1/bin is not available on this Windows host
👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread!
为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。
To ensure your code complies with RT-Thread's coding style, please run the code formatting workflow by following the steps below (If the formatting of CI fails to run).
设置需排除的文件/目录(目录请以"/"结尾)
Set files/directories to exclude (directories should end with "/")
将目标分支设置为 \ Set the target branch to:fix/lwip-altcp-tls-verify
设置PR number为 \ Set the PR number to:11523
等待工作流完成 | Wait for the workflow to complete
格式化后的代码将自动推送至你的分支。
The formatted code will be automatically pushed to your branch.
完成后,提交将自动更新至 fix/lwip-altcp-tls-verify 分支,关联的 Pull Request 也会同步更新。
Once completed, commits will be pushed to the fix/lwip-altcp-tls-verify branch automatically, and the related Pull Request will be updated.
如有问题欢迎联系我们,再次感谢您的贡献!💐
If you have any questions, feel free to reach out. Thanks again for your contribution!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
why to submit this PR
ALTCP TLS client configurations should require server certificate verification when a CA certificate is configured. This keeps certificate validation in the TLS configuration layer and makes the configured trust anchor effective.
what is your solution
Use
MBEDTLS_SSL_VERIFY_REQUIREDfor client TLS configurations that provide a CA certificate. Keep the existing optional verification mode for server configurations and client configurations without a CA certificate to preserve current compatibility.provide the config and bsp
bsp/bouffalo_lab/bl808/m0CONFIG_RT_USING_LWIP212=y,CONFIG_PKG_USING_MBEDTLS=yvalidation
git diff --checkaltcp_tls_create_config_client()andaltcp_tls_create_config_client_2wayauth()use the shared client configuration pathscons -j4inbsp/bouffalo_lab/bl808/m0did not reach compilation because the configured toolchain path/opt/Xuantie-900-gcc-elf-newlib-x86_64-V2.6.1/binis not available on this Windows host