From: Marc-André Lureau <marcandre.lureau@redhat.com> Propagate the error when qcrypto_x509_get_pk_algorithm fails, instead of falling through to return 0 (success) with *errp set. Fixes: e8317c4c9f68 ("crypto/x509-utils: Add helper functions for DIAG 320 subcode 2") Reviewed-by: Zhuoying Cai <zycai@linux.ibm.com> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com> Signed-off-by: Daniel P. Berrangé <berrange@redhat.com> --- crypto/x509-utils.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index 34cbfca26b..edcc44de80 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -319,6 +319,9 @@ int qcrypto_x509_check_ecc_curve_p521(uint8_t *cert, size_t size, Error **errp) int curve_id; algo = qcrypto_x509_get_pk_algorithm(cert, size, errp); + if (algo < 0) { + return -1; + } if (algo != GNUTLS_PK_ECDSA) { return 0; } -- 2.55.0