From: Marc-André Lureau <marcandre.lureau@redhat.com>
Propagate the error when qcrypto_x509_get_pk_algorithm fails, instead of
falling through to return 0 (success) with *errp set.
Fixes: e8317c4c9f68 ("crypto/x509-utils: Add helper functions for DIAG 320 subcode 2")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
---
crypto/x509-utils.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c
index 34cbfca26bff..edcc44de80d3 100644
--- a/crypto/x509-utils.c
+++ b/crypto/x509-utils.c
@@ -319,6 +319,9 @@ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **errp)
int curve_id;
algo = qcrypto_x509_get_pk_algorithm(cert, size, errp);
+ if (algo < 0) {
+ return -1;
+ }
if (algo != GNUTLS_PK_ECDSA) {
return 0;
}
--
2.55.0.543.g5ebe2ebe4ea8
On Mon, Aug 31, 2026 at 04:10:09PM +0400, marcandre.lureau@redhat.com wrote:
> From: Marc-André Lureau <marcandre.lureau@redhat.com>
>
> Propagate the error when qcrypto_x509_get_pk_algorithm fails, instead of
> falling through to return 0 (success) with *errp set.
>
> Fixes: e8317c4c9f68 ("crypto/x509-utils: Add helper functions for DIAG 320 subcode 2")
> Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
> ---
> crypto/x509-utils.c | 3 +++
> 1 file changed, 3 insertions(+)
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
and queued.
With regards,
Daniel
--
|: https://berrange.com ~~ https://hachyderm.io/@berrange :|
|: https://libvirt.org ~~ https://entangle-photo.org :|
|: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
Reviewed-by: Zhuoying Cai <zycai@linux.ibm.com>
On 8/31/26 8:10 AM, marcandre.lureau@redhat.com wrote:
> From: Marc-André Lureau <marcandre.lureau@redhat.com>
>
> Propagate the error when qcrypto_x509_get_pk_algorithm fails, instead of
> falling through to return 0 (success) with *errp set.
>
> Fixes: e8317c4c9f68 ("crypto/x509-utils: Add helper functions for DIAG 320 subcode 2")
> Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
> ---
> crypto/x509-utils.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c
> index 34cbfca26bff..edcc44de80d3 100644
> --- a/crypto/x509-utils.c
> +++ b/crypto/x509-utils.c
> @@ -319,6 +319,9 @@ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **errp)
> int curve_id;
>
> algo = qcrypto_x509_get_pk_algorithm(cert, size, errp);
> + if (algo < 0) {
> + return -1;
> + }
> if (algo != GNUTLS_PK_ECDSA) {
> return 0;
> }
© 2016 - 2026 Red Hat, Inc.