[tls] Fix building with TLS_VERSION_MAX set to TLS version 1.1

Commit 356bb14 ("[tls] Detect version downgrade attacks") introduced a
build failure under -Werror and -Wtype-limits when TLS_VERSION_MAX is
set to TLS_VERSION_TLS_1_1 due to the constructed test that checks if
an unsigned integer is less than zero.

Downgrade attack detection is impossible anyway when the maximum
version offered is TLS version 1.1, and so this always-false test is
perfectly correct: the desired outcome is that the downgrade detection
is optimised out at build time.

Fix the build error by adjusting the comparison to be performed using
signed integers to avoid the -Wtype-limits check.  Add a separate
check that the maximum version is higher than TLS_VERSION_TLS_1_1 to
ensure that the whole downgrade detection code block is optimised out
as dead code if it cannot ever be reached.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-18 15:01:12 +01:00
parent 01081fd911
commit 1135b79660
+4 -3
View File
@@ -2771,11 +2771,12 @@ static int tls_new_server_hello ( struct tls_connection *tls,
tls, ( version >> 8 ), ( version & 0xff ) );
/* Check for downgrade attacks */
if ( ( version < TLS_VERSION_MAX ) &&
if ( ( TLS_VERSION_TLS_1_1 < TLS_VERSION_MAX ) &&
( version < TLS_VERSION_MAX ) &&
( memcmp ( hello_a->random.downgrade.magic, downgrade_magic,
sizeof ( hello_a->random.downgrade.magic ) ) == 0 ) &&
( hello_a->random.downgrade.version <
( TLS_VERSION_MAX - TLS_VERSION_TLS_1_1 ) ) ) {
( ( hello_a->random.downgrade.version + TLS_VERSION_TLS_1_1 ) <
TLS_VERSION_MAX ) ) {
DBGC ( tls, "TLS %p detected downgrade attack:\n", tls );
DBGC_HDA ( tls, 0, &hello_a->random.downgrade,
sizeof ( hello_a->random.downgrade ) );