Files
s390-tools/rust/pv
Marc Hartmayer cf70a27d76 pv: Restrict CRL downloads to HTTP(S) and limit redirects
Only allow CRL downloads over HTTP and HTTPS to avoid accessing
unexpected protocol handlers.

The Rust curl bindings do not expose support for configuring allowed
protocols or the maximum number of redirects [1][2][3]. Therefore,
redirect handling is implemented manually, validating each redirect
target and enforcing a maximum of five redirects.

The redirect limit also prevents infinite redirect loops.

[1] https://curl.se/libcurl/c/CURLOPT_PROTOCOLS_STR.html
[2] https://curl.se/libcurl/c/CURLOPT_REDIR_PROTOCOLS_STR.html
[3] https://curl.se/libcurl/c/CURLOPT_MAXREDIRS.html

Fixes: c6f621d0dc ("rust: Add library for pv tools")
Assisted-by: IBM Bob:1.0.5
Signed-off-by: Marc Hartmayer <marc@linux.ibm.com>
Reviewed-by: Steffen Eiden <seiden@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
2026-07-20 15:25:58 +02:00
..
2026-06-22 16:43:02 +02:00
2024-05-27 16:53:03 +02:00

s390_pv - library for pv-tools

This library is intended to be used by tools and libraries that are used for creating and managing IBM Secure Execution guests. pv provides abstraction layers for encryption, secure memory management, and accessing the uvdevice.

If your project is not targeted to provide tooling for and/or managing of IBM Secure execution guests, do not use this crate.

OpenSSL 1.1.0+ is required

If you do not need any OpenSSL features use s390_pv_core. This crate reexports all symbols from s390_pv_core. If your project uses this crate do not include s390_pv_core as well.

Import crate

The recommended way of importing this crate is:

cargo add s390_pv --rename pv