[tls] Allow support for newer TLS versions to be optimised out

The TLS version check already optimises down to a compile-time
constant if the specified version is guaranteed by the configured
minimum supported version.

Extend this check to also take into account the configured maximum
supported version.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-14 15:51:17 +01:00
parent 6872d143d6
commit 47b934676a
+6 -3
View File
@@ -310,12 +310,15 @@ static int tls_ready ( struct tls_connection *tls ) {
*
* Check that TLS connection uses at least the specified protocol
* version. Optimise down to a compile-time constant true result if
* this is already guaranteed by the minimum supported version check.
* this is already guaranteed by the minimum or maximum supported
* version check.
*/
static inline __attribute__ (( always_inline )) int
tls_version ( struct tls_connection *tls, unsigned int version ) {
return ( ( TLS_VERSION_MIN >= version ) ||
( tls->version >= version ) );
return ( ( TLS_VERSION_MAX >= version ) &&
( ( TLS_VERSION_MIN >= version ) ||
( tls->version >= version ) ) );
}
/**