diff --git a/crates/net/src/tls/handshake.rs b/crates/net/src/tls/handshake.rs index 697a899..b35d72b 100644 --- a/crates/net/src/tls/handshake.rs +++ b/crates/net/src/tls/handshake.rs @@ -199,9 +199,8 @@ fn read_bytes<'a>(data: &'a [u8], offset: &mut usize, len: usize) -> Result<&'a fn random_bytes(buf: &mut [u8]) { // Read from /dev/urandom for random bytes. // This is available on macOS (which is our only target). - if let Ok(mut f) = std::fs::File::open("/dev/urandom") { - let _ = f.read_exact(buf); - } + let mut f = std::fs::File::open("/dev/urandom").expect("failed to open /dev/urandom"); + f.read_exact(buf).expect("failed to read /dev/urandom"); } // --------------------------------------------------------------------------- @@ -699,11 +698,11 @@ pub fn connect(stream: S, server_name: &str) -> Result bool { // Wildcard matching: *.example.com matches foo.example.com if let Some(suffix) = pattern.strip_prefix("*.") { if let Some(rest) = hostname.strip_suffix(suffix) { - // The wildcard must match exactly one label - if rest.ends_with('.') && !rest[..rest.len() - 1].contains('.') { + // The wildcard must match exactly one non-empty label + if rest.ends_with('.') && rest.len() > 1 && !rest[..rest.len() - 1].contains('.') { return true; } }