{"id":20450071,"url":"https://github.com/ooni/oocrypto","last_synced_at":"2026-04-20T07:05:06.223Z","repository":{"id":37183579,"uuid":"494770712","full_name":"ooni/oocrypto","owner":"ooni","description":"Fork of Go crypto/tls with extra patches from the OONI team","archived":false,"fork":false,"pushed_at":"2025-02-09T07:01:59.000Z","size":24253,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":6,"default_branch":"main","last_synced_at":"2025-10-29T06:31:45.440Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://ooni.org","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ooni.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-05-21T12:00:54.000Z","updated_at":"2025-02-09T07:01:30.000Z","dependencies_parsed_at":"2023-02-10T02:01:42.049Z","dependency_job_id":"e99f7fbc-5ce8-43f3-ad98-b8a01bafdef3","html_url":"https://github.com/ooni/oocrypto","commit_stats":{"total_commits":1252,"total_committers":257,"mean_commits":4.871595330739299,"dds":0.8250798722044729,"last_synced_commit":"74768b3e7ed7c029ab81361f23b71f6b574abccb"},"previous_names":[],"tags_count":26,"template":false,"template_full_name":null,"purl":"pkg:github/ooni/oocrypto","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ooni%2Foocrypto","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ooni%2Foocrypto/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ooni%2Foocrypto/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ooni%2Foocrypto/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ooni","download_url":"https://codeload.github.com/ooni/oocrypto/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ooni%2Foocrypto/sbom","scorecard":{"id":707991,"data":{"date":"2025-08-11","repo":{"name":"github.com/ooni/oocrypto","commit":"71bc9266ce436e9b88644a013b6ee404c6bd9838"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.6,"checks":[{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/6 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/go.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ooni/oocrypto/go.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ooni/oocrypto/go.yml/main?enable=pin","Info:   0 out of   2 GitHub-owned GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":8,"reason":"2 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-22T07:17:24.601Z","repository_id":37183579,"created_at":"2025-08-22T07:17:24.601Z","updated_at":"2025-08-22T07:17:24.601Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32036803,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-20T00:18:06.643Z","status":"online","status_checked_at":"2026-04-20T02:00:06.527Z","response_time":94,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-15T10:50:10.544Z","updated_at":"2026-04-20T07:05:06.202Z","avatar_url":"https://github.com/ooni.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# github.com/ooni/oocrypto\n\nThis repository contains a fork of a subset of the Go stdlib's `crypto`\npackage including patches to allow selecting AES hardware support\non Android devices. We documented why we need these patches at OONI in\nthe [Making the OONI Probe Android app more resilient](\nhttps://ooni.org/post/making-ooni-probe-android-more-resilient/) blog post.\n\n## Motivation and maintenance\n\nTo solve our issues with Android apps, we originally forked golang/go\nitself at [ooni/go](https://github.com/ooni/go). However, a full fork of\nGo required us to compile this fork and build Android apps using it,\nwhich was making building OONI excessively complicated. Hence, we later\nchose to just fork the `crypto` package and documented our efforts at\n[ooni/probe#2106](https://github.com/ooni/probe/issues/2106). We\nwill continue to keep this fork up to date as long as it serves our goals.\n\n## Intended usage\n\nYou SHOULD use this package with the exact Go version from which we extracted\nthe source, which is documented in the [Update procedure](#update-procedure) section. The\nstandard library is composed of tightly integrated packages, hence\nusing this code with another Go version could cause subtle security issues.\n\nThe [tls/stdlibwrapper.go](tls/stdlibwrapper.go) file contains an API that allows\nconverting code using `crypto/tls` to code using this package.\n\n```Go\nfunc NewClientConnStdlib(conn net.Conn, config *stdlibtls.Config) (*ConnStdlib, error)\n```\n\nThe `NewClientConnStdlib` creates a new client conn taking in input a\n`tls.Config` struct as exposed by the stdlib `crypto/tls` package. The\nfunction returns error if you passed in config fields that we don't\nknow (yet?) how to convert from their stdlib definition to the equivalent\ndefinition of `Config` implemented by this module.\n\nThe returned `ConnStdlib` type implements the following interface, which\nis equivalent to [oohttp](https://github.com/ooni/oohttp)'s `TLSConn`:\n\n```Go\nimport (\n    \"context\"\n    \"crypto/tls\"\n)\n\ntype TLSConn interface {\n    net.Conn\n\n    HandshakeContext(ctx context.Context) error\n\n    ConnectionState() tls.ConnectionState\n\n    NetConn() net.Conn\n}\n```\n\nThese changes are sufficient for OONI to use this library instead\nof using `crypto/tls` as the underlying TLS library.\n\n## License\n\nEach individual file from the `crypto` fork maintains its original\ncopyright and [license](https://github.com/golang/go/blob/master/LICENSE). Any\nchange to such files authored by us keeps the same 3-clause BSD license of\nthe original code. Because we anticipate integrating code under the GPL license\nfrom `Yawning/utls` we chose to license the repository using the GPL.\n\n```\nSPDX-License-Identifier: GPL-3.0-or-later\n```\n\n## Issue tracker\n\nPlease, report issues in the [ooni/probe](https://github.com/ooni/probe)\nrepository. Make sure you mention `oocrypto` in the issue title.\n\n## Patches\n\nCommit [1137f34](https://github.com/ooni/oocrypto/commit/1137f34fc78f7b5165a37f290e0b1c5e2fb074ac)\nmerged go1.17.10 `src/crypto`'s subtree into this repository.\n\n[Subsequent commits](https://github.com/ooni/oocrypto/compare/1137f34fc78f7b5165a37f290e0b1c5e2fb074ac...f09fe46bcb80d2e747b0c0ea9a2835e70710690c)\nremoved unused code and established a procedure to sync with upstream. As part\nof these commits, we replaced `internal/cpu` with `golang.org/x/sys/cpu`.\n\nFinally, we landed [patches](https://github.com/ooni/oocrypto/compare/f09fe46bcb80d2e747b0c0ea9a2835e70710690c...4dff9e0864cd49113a36ac8112cf887cbe215d54)\nto improve hardware capability detection on `android/arm64`.\n\n## Update procedure\n\n(Adapted from ooni/oohttp instructions.)\n\n- [ ] check whether hardware capability detection has been improved upstream\nby reading [os_linux.go](https://github.com/golang/go/blob/go1.22.2/src/runtime/os_linux.go#L251)\nand update the link to `os_linux.go` based on the upstream version that\nwe're tracking with this fork\n\n- [ ] update [UPSTREAM](UPSTREAM), commit the change, and then\nrun the `./tools/merge.bash` script to merge from upstream;\n\n- [ ] fix all the likely merge conflicts\n\n- [ ] delete all the new packages we can safely delete. We can safely\ndelete a package if the package is not `tls` and:\n\n1. either the package does not depend on `internal/cpu`\n\n2. or the documentation of the package does not explicitly state that\nthe package is only secure depending on the CPU configuration, which\ncurrently only holds for `aes` (see [aes/const.go](aes/const.go))\n\n- [ ] ensure that every forked package is never imported by using\nthe following checks (we could also use `go list` as follows\n`GOOS=os GOARCH=arch go list --json ./...`):\n\n1. `git grep 'subtle\"'`\n\n2. `git grep 'tls\"'`\n\n3. `git grep 'aes\"'`\n\n4. `git grep 'alias\"'`\n\n5. `git grep 'boring\"'`\n\n6. `git grep 'godebug\"'`\n\n- [ ] double check whether we need to add more checks to the list above (you\ncan get a list of packages using `tree -d`)\n\n- [ ] ensure that `stdlibwrapper.go` correctly fills `tls.ConnectionState`\nin the `ConnStdlib.ConnectionState` method\n\n- [ ] use `./tools/compare.bash` to make sure the changes with respect\nto upstream are reasonable\n\n- [ ] `go build -v ./...` must succeed\n\n- [ ] `go test -race ./...` must succeed\n\n- [ ] run `go get -u -v ./... \u0026\u0026 go mod tidy`\n\n- [ ] open a pull request using this check-list as its content and merge it preserving history\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fooni%2Foocrypto","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fooni%2Foocrypto","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fooni%2Foocrypto/lists"}