update main-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2024-01-25 21:57:46 +00:00
11 changed files with 642 additions and 567 deletions
+3
View File
@@ -313,6 +313,9 @@ crypto_test_data = [
"src/crypto/hpke/hpke_test_vectors.txt",
"src/crypto/keccak/keccak_tests.txt",
"src/crypto/kyber/kyber_tests.txt",
"src/crypto/pkcs8/test/bad1.p12",
"src/crypto/pkcs8/test/bad2.p12",
"src/crypto/pkcs8/test/bad3.p12",
"src/crypto/pkcs8/test/empty_password.p12",
"src/crypto/pkcs8/test/empty_password_ber.p12",
"src/crypto/pkcs8/test/empty_password_ber_nested.p12",
+563 -536
View File
File diff suppressed because one or more lines are too long
+3
View File
@@ -699,6 +699,9 @@
"src/crypto/hpke/hpke_test_vectors.txt",
"src/crypto/keccak/keccak_tests.txt",
"src/crypto/kyber/kyber_tests.txt",
"src/crypto/pkcs8/test/bad1.p12",
"src/crypto/pkcs8/test/bad2.p12",
"src/crypto/pkcs8/test/bad3.p12",
"src/crypto/pkcs8/test/empty_password.p12",
"src/crypto/pkcs8/test/empty_password_ber.p12",
"src/crypto/pkcs8/test/empty_password_ber_nested.p12",
+20 -18
View File
@@ -378,7 +378,8 @@ void DES_set_odd_parity(DES_cblock *key) {
}
}
static void DES_encrypt1(uint32_t *data, const DES_key_schedule *ks, int enc) {
static void DES_encrypt1(uint32_t data[2], const DES_key_schedule *ks,
int enc) {
uint32_t l, r, t, u;
r = data[0];
@@ -442,7 +443,8 @@ static void DES_encrypt1(uint32_t *data, const DES_key_schedule *ks, int enc) {
data[1] = r;
}
static void DES_encrypt2(uint32_t *data, const DES_key_schedule *ks, int enc) {
static void DES_encrypt2(uint32_t data[2], const DES_key_schedule *ks,
int enc) {
uint32_t l, r, t, u;
r = data[0];
@@ -499,7 +501,7 @@ static void DES_encrypt2(uint32_t *data, const DES_key_schedule *ks, int enc) {
data[1] = CRYPTO_rotr_u32(r, 3);
}
void DES_encrypt3(uint32_t *data, const DES_key_schedule *ks1,
void DES_encrypt3(uint32_t data[2], const DES_key_schedule *ks1,
const DES_key_schedule *ks2, const DES_key_schedule *ks3) {
uint32_t l, r;
@@ -508,9 +510,9 @@ void DES_encrypt3(uint32_t *data, const DES_key_schedule *ks1,
IP(l, r);
data[0] = l;
data[1] = r;
DES_encrypt2((uint32_t *)data, ks1, DES_ENCRYPT);
DES_encrypt2((uint32_t *)data, ks2, DES_DECRYPT);
DES_encrypt2((uint32_t *)data, ks3, DES_ENCRYPT);
DES_encrypt2(data, ks1, DES_ENCRYPT);
DES_encrypt2(data, ks2, DES_DECRYPT);
DES_encrypt2(data, ks3, DES_ENCRYPT);
l = data[0];
r = data[1];
FP(r, l);
@@ -518,7 +520,7 @@ void DES_encrypt3(uint32_t *data, const DES_key_schedule *ks1,
data[1] = r;
}
void DES_decrypt3(uint32_t *data, const DES_key_schedule *ks1,
void DES_decrypt3(uint32_t data[2], const DES_key_schedule *ks1,
const DES_key_schedule *ks2, const DES_key_schedule *ks3) {
uint32_t l, r;
@@ -527,9 +529,9 @@ void DES_decrypt3(uint32_t *data, const DES_key_schedule *ks1,
IP(l, r);
data[0] = l;
data[1] = r;
DES_encrypt2((uint32_t *)data, ks3, DES_DECRYPT);
DES_encrypt2((uint32_t *)data, ks2, DES_ENCRYPT);
DES_encrypt2((uint32_t *)data, ks1, DES_DECRYPT);
DES_encrypt2(data, ks3, DES_DECRYPT);
DES_encrypt2(data, ks2, DES_ENCRYPT);
DES_encrypt2(data, ks1, DES_DECRYPT);
l = data[0];
r = data[1];
FP(r, l);
@@ -576,7 +578,7 @@ void DES_ncbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin1 ^= tout1;
tin[1] = tin1;
DES_encrypt1((uint32_t *)tin, schedule, DES_ENCRYPT);
DES_encrypt1(tin, schedule, DES_ENCRYPT);
tout0 = tin[0];
l2c(tout0, out);
tout1 = tin[1];
@@ -588,7 +590,7 @@ void DES_ncbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin1 ^= tout1;
tin[1] = tin1;
DES_encrypt1((uint32_t *)tin, schedule, DES_ENCRYPT);
DES_encrypt1(tin, schedule, DES_ENCRYPT);
tout0 = tin[0];
l2c(tout0, out);
tout1 = tin[1];
@@ -605,7 +607,7 @@ void DES_ncbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
c2l(in, tin1);
tin[1] = tin1;
DES_encrypt1((uint32_t *)tin, schedule, DES_DECRYPT);
DES_encrypt1(tin, schedule, DES_DECRYPT);
tout0 = tin[0] ^ xor0;
tout1 = tin[1] ^ xor1;
l2c(tout0, out);
@@ -618,7 +620,7 @@ void DES_ncbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
c2l(in, tin1);
tin[1] = tin1;
DES_encrypt1((uint32_t *)tin, schedule, DES_DECRYPT);
DES_encrypt1(tin, schedule, DES_DECRYPT);
tout0 = tin[0] ^ xor0;
tout1 = tin[1] ^ xor1;
l2cn(tout0, tout1, out, len);
@@ -678,7 +680,7 @@ void DES_ede3_cbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin[1] = tin1;
DES_encrypt3((uint32_t *)tin, ks1, ks2, ks3);
DES_encrypt3(tin, ks1, ks2, ks3);
tout0 = tin[0];
tout1 = tin[1];
@@ -692,7 +694,7 @@ void DES_ede3_cbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin[1] = tin1;
DES_encrypt3((uint32_t *)tin, ks1, ks2, ks3);
DES_encrypt3(tin, ks1, ks2, ks3);
tout0 = tin[0];
tout1 = tin[1];
@@ -716,7 +718,7 @@ void DES_ede3_cbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin[1] = tin1;
DES_decrypt3((uint32_t *)tin, ks1, ks2, ks3);
DES_decrypt3(tin, ks1, ks2, ks3);
tout0 = tin[0];
tout1 = tin[1];
@@ -736,7 +738,7 @@ void DES_ede3_cbc_encrypt(const uint8_t *in, uint8_t *out, size_t len,
tin[0] = tin0;
tin[1] = tin1;
DES_decrypt3((uint32_t *)tin, ks1, ks2, ks3);
DES_decrypt3(tin, ks1, ks2, ks3);
tout0 = tin[0];
tout1 = tin[1];
+14
View File
@@ -58,6 +58,7 @@
#define OPENSSL_HEADER_DES_INTERNAL_H
#include <openssl/base.h>
#include <openssl/des.h>
#include "../internal.h"
@@ -231,6 +232,19 @@ how to use xors :-) I got it to its final state.
#define HALF_ITERATIONS 8
// Private functions.
//
// These functions are only exported for use in |decrepit|.
OPENSSL_EXPORT void DES_decrypt3(uint32_t data[2], const DES_key_schedule *ks1,
const DES_key_schedule *ks2,
const DES_key_schedule *ks3);
OPENSSL_EXPORT void DES_encrypt3(uint32_t data[2], const DES_key_schedule *ks1,
const DES_key_schedule *ks2,
const DES_key_schedule *ks3);
#if defined(__cplusplus)
} // extern C
#endif
+36
View File
@@ -656,3 +656,39 @@ TEST(PKCS12Test, CreateWithAlias) {
ASSERT_EQ(alias, std::string(reinterpret_cast<const char *>(parsed_alias),
static_cast<size_t>(alias_len)));
}
// PKCS#12 is built on top of PKCS#7, a misdesigned, overgeneralized combinator
// format. One of the features of PKCS#7 is that the content of every
// ContentInfo may be omitted, to indicate that the value is "supplied by other
// means". This is commonly used for "detached signatures", where the signature
// is supplied separately.
//
// This does not make sense in the context of PKCS#12. But because PKCS#7
// combined many unrelated use cases into the same format, so PKCS#12 (and any
// other use of PKCS#7) must account for and reject inputs.
TEST(PKCS12Test, MissingContent) {
{
std::string data = GetTestData("crypto/pkcs8/test/bad1.p12");
bssl::UniquePtr<STACK_OF(X509)> certs(sk_X509_new_null());
ASSERT_TRUE(certs);
EVP_PKEY *key = nullptr;
CBS cbs = StringToBytes(data);
EXPECT_FALSE(PKCS12_get_key_and_certs(&key, certs.get(), &cbs, ""));
}
{
std::string data = GetTestData("crypto/pkcs8/test/bad2.p12");
bssl::UniquePtr<STACK_OF(X509)> certs(sk_X509_new_null());
ASSERT_TRUE(certs);
EVP_PKEY *key = nullptr;
CBS cbs = StringToBytes(data);
EXPECT_FALSE(PKCS12_get_key_and_certs(&key, certs.get(), &cbs, ""));
}
{
std::string data = GetTestData("crypto/pkcs8/test/bad3.p12");
bssl::UniquePtr<STACK_OF(X509)> certs(sk_X509_new_null());
ASSERT_TRUE(certs);
EVP_PKEY *key = nullptr;
CBS cbs = StringToBytes(data);
EXPECT_FALSE(PKCS12_get_key_and_certs(&key, certs.get(), &cbs, ""));
}
}
Binary file not shown.
Binary file not shown.
Binary file not shown.
-13
View File
@@ -163,19 +163,6 @@ OPENSSL_EXPORT void DES_ede3_cfb_encrypt(const uint8_t *in, uint8_t *out,
DES_cblock *ivec, int enc);
// Private functions.
//
// These functions are only exported for use in |decrepit|.
OPENSSL_EXPORT void DES_decrypt3(uint32_t *data, const DES_key_schedule *ks1,
const DES_key_schedule *ks2,
const DES_key_schedule *ks3);
OPENSSL_EXPORT void DES_encrypt3(uint32_t *data, const DES_key_schedule *ks1,
const DES_key_schedule *ks2,
const DES_key_schedule *ks3);
#if defined(__cplusplus)
} // extern C
#endif
+3
View File
@@ -146,6 +146,9 @@ set(
crypto/hpke/hpke_test_vectors.txt
crypto/keccak/keccak_tests.txt
crypto/kyber/kyber_tests.txt
crypto/pkcs8/test/bad1.p12
crypto/pkcs8/test/bad2.p12
crypto/pkcs8/test/bad3.p12
crypto/pkcs8/test/empty_password.p12
crypto/pkcs8/test/empty_password_ber.p12
crypto/pkcs8/test/empty_password_ber_nested.p12