derp/derpserver,cmd/derper: use slices.Clip for cert chain copies (#20484)

This commit is contained in:
Mike O'Driscoll 2026-07-15 22:13:27 -04:00 committed by GitHub
parent bf7d815631
commit 71b90de0d4
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 5 additions and 6 deletions

View File

@ -23,6 +23,7 @@
"os"
"path/filepath"
"regexp"
"slices"
"time"
"golang.org/x/crypto/acme"
@ -158,10 +159,9 @@ func (m *manualCertManager) getCertificate(hi *tls.ClientHelloInfo) (*tls.Certif
// Return a shallow copy of the cert with a capacity-clamped chain
// so callers can never mutate the manager's long-lived certificate.
certCopy := new(tls.Certificate)
*certCopy = *m.cert
certCopy.Certificate = certCopy.Certificate[:len(certCopy.Certificate):len(certCopy.Certificate)]
return certCopy, nil
certCopy := *m.cert
certCopy.Certificate = slices.Clip(certCopy.Certificate)
return &certCopy, nil
}
func (m *manualCertManager) HTTPHandler(fallback http.Handler) http.Handler {

View File

@ -744,8 +744,7 @@ func (s *Server) ModifyTLSConfigToAddMetaCert(c *tls.Config) {
// cached value. Return a shallow copy with the meta cert
// appended to a freshly allocated chain slice.
certCopy := *cert
chain := cert.Certificate
certCopy.Certificate = append(chain[:len(chain):len(chain)], s.MetaCert())
certCopy.Certificate = append(slices.Clip(cert.Certificate), s.MetaCert())
return &certCopy, nil
}
}