From 46dd8ec9937ed0979ed5089f426ce04d9d431682 Mon Sep 17 00:00:00 2001 From: Adam Langley Date: Wed, 19 Oct 2016 11:10:20 -0700 Subject: [PATCH] Make the loop bounds in keywrap a little more clear. This code reportedly upsets VC++'s static analysis. Make it clear that, yes, we want to count backwards. Change-Id: I5caba219a2b87750d1a9d69b46d336a98c5824c9 Reviewed-on: https://boringssl-review.googlesource.com/11624 Commit-Queue: Adam Langley Commit-Queue: David Benjamin Reviewed-by: David Benjamin CQ-Verified: CQ bot account: commit-bot@chromium.org --- crypto/aes/key_wrap.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/crypto/aes/key_wrap.c b/crypto/aes/key_wrap.c index e955c4756..c8b6a034c 100644 --- a/crypto/aes/key_wrap.c +++ b/crypto/aes/key_wrap.c @@ -59,6 +59,8 @@ static const uint8_t kDefaultIV[] = { 0xa6, 0xa6, 0xa6, 0xa6, 0xa6, 0xa6, 0xa6, 0xa6, }; +static const unsigned kBound = 6; + int AES_wrap_key(const AES_KEY *key, const uint8_t *iv, uint8_t *out, const uint8_t *in, size_t in_len) { /* See RFC 3394, section 2.2.1. */ @@ -77,7 +79,7 @@ int AES_wrap_key(const AES_KEY *key, const uint8_t *iv, uint8_t *out, size_t n = in_len / 8; - for (unsigned j = 0; j < 6; j++) { + for (unsigned j = 0; j < kBound; j++) { for (size_t i = 1; i <= n; i++) { memcpy(A + 8, out + 8 * i, 8); AES_encrypt(A, A, key); @@ -113,7 +115,7 @@ int AES_unwrap_key(const AES_KEY *key, const uint8_t *iv, uint8_t *out, size_t n = (in_len / 8) - 1; - for (unsigned j = 5; j < 6; j--) { + for (unsigned j = kBound - 1; j < kBound; j--) { for (size_t i = n; i > 0; i--) { uint32_t t = (uint32_t)(n * j + i); A[7] ^= t & 0xff;