No Branch/Tag Specified
arm
asyncnotedecryption
danger
dev
dev-aarch64
dev-mac
dev-old-randomx
divzaddrs
dragonx
duke
freebsd
getfilterednotes
hip39
insync
jahway603
master
mvstuff
onryo
p2p_privacy
ramhash
relaytx
rx-largepages
setbestchain
warmup
witness_cache
wolfssl
wolfssl_win
z_createrawtransaction
z_importwallet
z_signmessage
v0.11.2.z0
v0.11.2.z1
v0.11.2.z2
v0.11.2.z3
v0.11.2.z4
v0.11.2.z5
v0.11.2.z6
v0.11.2.z7
v0.11.2.z8
v0.11.2.z9
v1.0.0
v1.0.0-beta1
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.1
v1.0.10
v1.0.10-1
v1.0.11
v1.0.11-rc1
v1.0.12
v1.0.12-rc1
v1.0.13
v1.0.13-rc1
v1.0.13-rc2
v1.0.14
v1.0.14-rc1
v1.0.15
v1.0.15-rc1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7-1
v1.0.8
v1.0.8-1
v1.0.9
v1.1.0
v1.1.0-rc1
v1.1.1
v1.1.1-rc1
v1.1.1-rc2
v1.1.2
v1.1.2-rc1
v2.0.0
v2.0.0-rc1
v2.0.1
v3.0.0
v3.1.0
v3.1.1
v3.10.0
v3.10.1
v3.10.2
v3.2.0
v3.2.1
v3.2.1-alpha
v3.2.1-beta
v3.2.2
v3.2.3
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.5.2
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.7.0
v3.7.1
v3.8.0
v3.9.0
v3.9.1
v3.9.2
v3.9.3
v3.9.4
Labels
bounty up to 500 HUSH 2001-5000 bounty
bounty between 2001 and 5000 HUSH 501-2000 bounty
bounty between 501 and 2000 HUSH arm
something doesn't work on arm beginners
for new developers bug
may or may not be a bug build
problems building documentation
not enough information feature
new feature high priority
high priority i2p
related to i2p low priority
low priority medium priority
medium priority question
something is not clear release
release label or issue related to it testing
related to testing tor
related to tor wontfix
this won't be fixed
Apply labels
Clear labels
0-500 bounty
bounty up to 500 HUSH 2001-5000 bounty
bounty between 2001 and 5000 HUSH 501-2000 bounty
bounty between 501 and 2000 HUSH arm
something doesn't work on arm beginners
for new developers bug
may or may not be a bug build
problems building documentation
not enough information feature
new feature high priority
high priority i2p
related to i2p low priority
low priority medium priority
medium priority question
something is not clear release
release label or issue related to it testing
related to testing tor
related to tor wontfix
this won't be fixed
No Label
0-500 bounty
2001-5000 bounty
501-2000 bounty
arm
beginners
bug
build
documentation
feature
high priority
i2p
low priority
medium priority
question
release
testing
tor
wontfix
Milestone
Set milestone
Clear milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
2 Participants
Assign users
Clear assignees
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.
No due date set.
Dependencies
This issue currently doesn't have any dependencies.
Reference in new issue
There is no content yet.
Delete Branch '%!s(MISSING)'
Deleting a branch is permanent. It CANNOT be undone. Continue?
No
Yes
TLDR: We use wolfssl 4.6 and when we tried to upgrade to 4.7 we discovered that it seems to be backward incompatible, i.e. nodes using 4.7 could not talk to nodes using 4.6 via TLS, hence no nodes can talk to each other, because SSL is required.
Details:
wolfSSL_CTX_set_min_proto_version(tlsCtx, TLS1_3_VERSION)
@jahway603 I updated the
wolfssl
branch so that it is the latest dev branch but using wolfssl 4.7.0 instead of 4.6.0 . If you are able to try that branch out and we can work together to see exactly what SSL errors happen when trying to connect to the rest of the network, that will give us more data for the bug report. We could also try a new version of wolfssl but I have no idea if stuff is backward compatible and our code might not even compile with the most recent wolfssl versions. I think if we can identify exactly what changed between 4.6.0 and 4.7.0 and point out exactly how wolfssl broke backcompat between those 2 versions, that will help wolfssl understand exactly what happened and hopefully suggest an upgrade path for us.We now use wolfssl 5.2.0 on the
wolfssl
branch.It seems that
wolfSSL_X509_verify
changed it's error code from returning WOLFSSL_SUCCESS (1) to WOLFSSL_ERROR_NONE (0) . Since wolfssl does not have any tests for this function my guess is that they did this on accident. Disabling our error checking makes our code work with 4.8.0 through 5.2.0 . 5.3.0 is not compatible with our code since they changed the names of many things.Commit
809c0a4b38
disables the error check which allows our full node to correctly startup and then make connections to peers@jahway603 I was able to do a fresh sync on the
wolfssl
branch with 5.2.0@duke I was also able to do a complete fresh sync on the
wolfssl
branch with 5.2.0.ok,
wolfssl
branch has been merged intodev
, closing this