update main-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2024-01-23 21:56:03 +00:00
51 changed files with 365 additions and 41485 deletions
+17 -6
View File
@@ -81,8 +81,6 @@ class SpanBase {
template <typename T>
class Span : private internal::SpanBase<const T> {
private:
static const size_t npos = static_cast<size_t>(-1);
// Heuristically test whether C is a container type that can be converted into
// a Span by checking for data() and size() member functions.
//
@@ -93,6 +91,19 @@ class Span : private internal::SpanBase<const T> {
std::is_integral<decltype(std::declval<C>().size())>::value>;
public:
static const size_t npos = static_cast<size_t>(-1);
using element_type = T;
using value_type = std::remove_cv_t<T>;
using size_type = size_t;
using difference_type = ptrdiff_t;
using pointer = T *;
using const_pointer = const T *;
using reference = T &;
using const_reference = const T &;
using iterator = T *;
using const_iterator = const T *;
constexpr Span() : Span(nullptr, 0) {}
constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
@@ -113,10 +124,10 @@ class Span : private internal::SpanBase<const T> {
constexpr size_t size() const { return size_; }
constexpr bool empty() const { return size_ == 0; }
constexpr T *begin() const { return data_; }
constexpr const T *cbegin() const { return data_; }
constexpr T *end() const { return data_ + size_; }
constexpr const T *cend() const { return end(); }
constexpr iterator begin() const { return data_; }
constexpr const_iterator cbegin() const { return data_; }
constexpr iterator end() const { return data_ + size_; }
constexpr const_iterator cend() const { return end(); }
constexpr T &front() const {
if (size_ == 0) {
+12 -9
View File
@@ -19,8 +19,8 @@ namespace {
// blobs. It makes a copy of the der::Inputs.
class CertErrorParams2Der : public CertErrorParams {
public:
CertErrorParams2Der(const char *name1, const der::Input &der1,
const char *name2, const der::Input &der2)
CertErrorParams2Der(const char *name1, der::Input der1, const char *name2,
der::Input der2)
: name1_(name1),
der1_(der1.AsString()),
name2_(name2),
@@ -43,9 +43,11 @@ class CertErrorParams2Der : public CertErrorParams {
static void AppendDer(const char *name, const std::string &der,
std::string *out) {
*out += name;
// TODO(crbug.com/boringssl/661): Introduce a convenience function to go
// from a Span<const char> to a Span<const uint8_t>.
*out +=
": " + bssl::string_util::HexEncode(
reinterpret_cast<const uint8_t *>(der.data()), der.size());
": " + bssl::string_util::HexEncode(MakeConstSpan(
reinterpret_cast<const uint8_t *>(der.data()), der.size()));
}
const char *name1_;
@@ -104,16 +106,17 @@ class CertErrorParams2SizeT : public CertErrorParams {
CertErrorParams::CertErrorParams() = default;
CertErrorParams::~CertErrorParams() = default;
std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(
const char *name, const der::Input &der) {
std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(const char *name,
der::Input der) {
BSSL_CHECK(name);
return std::make_unique<CertErrorParams2Der>(name, der, nullptr,
der::Input());
}
std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(
const char *name1, const der::Input &der1, const char *name2,
const der::Input &der2) {
std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(const char *name1,
der::Input der1,
const char *name2,
der::Input der2) {
BSSL_CHECK(name1);
BSSL_CHECK(name2);
return std::make_unique<CertErrorParams2Der>(name1, der1, name2, der2);
+2 -3
View File
@@ -39,12 +39,11 @@ class OPENSSL_EXPORT CertErrorParams {
// Creates a parameter object that holds a copy of |der|, and names it |name|
// in debug string outputs.
OPENSSL_EXPORT std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(
const char *name, const der::Input &der);
const char *name, der::Input der);
// Same as CreateCertErrorParams1Der() but has a second DER blob.
OPENSSL_EXPORT std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(
const char *name1, const der::Input &der1, const char *name2,
const der::Input &der2);
const char *name1, der::Input der1, const char *name2, der::Input der2);
// Creates a parameter object that holds a single size_t value. |name| is used
// when pretty-printing the parameters.
+6 -6
View File
@@ -130,7 +130,7 @@ bool ParsePolicyQualifiers(bool restrict_to_known_qualifiers,
// bmpString BMPString (SIZE (1..200)),
// utf8String UTF8String (SIZE (1..200)) }
bool ParseCertificatePoliciesExtensionImpl(
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
std::vector<der::Input> *policy_oids,
std::vector<PolicyInformation> *policy_informations, CertErrors *errors) {
BSSL_CHECK(policy_oids);
@@ -227,7 +227,7 @@ PolicyInformation::~PolicyInformation() = default;
PolicyInformation::PolicyInformation(const PolicyInformation &) = default;
PolicyInformation::PolicyInformation(PolicyInformation &&) = default;
bool ParseCertificatePoliciesExtension(const der::Input &extension_value,
bool ParseCertificatePoliciesExtension(der::Input extension_value,
std::vector<PolicyInformation> *policies,
CertErrors *errors) {
std::vector<der::Input> unused_policy_oids;
@@ -237,7 +237,7 @@ bool ParseCertificatePoliciesExtension(const der::Input &extension_value,
}
bool ParseCertificatePoliciesExtensionOids(
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
std::vector<der::Input> *policy_oids, CertErrors *errors) {
return ParseCertificatePoliciesExtensionImpl(
extension_value, fail_parsing_unknown_qualifier_oids, policy_oids,
@@ -251,7 +251,7 @@ bool ParseCertificatePoliciesExtensionOids(
// inhibitPolicyMapping [1] SkipCerts OPTIONAL }
//
// SkipCerts ::= INTEGER (0..MAX)
bool ParsePolicyConstraints(const der::Input &policy_constraints_tlv,
bool ParsePolicyConstraints(der::Input policy_constraints_tlv,
ParsedPolicyConstraints *out) {
der::Parser parser(policy_constraints_tlv);
@@ -318,7 +318,7 @@ bool ParsePolicyConstraints(const der::Input &policy_constraints_tlv,
//
// SkipCerts ::= INTEGER (0..MAX)
std::optional<uint8_t> ParseInhibitAnyPolicy(
const der::Input &inhibit_any_policy_tlv) {
der::Input inhibit_any_policy_tlv) {
der::Parser parser(inhibit_any_policy_tlv);
std::optional<uint8_t> num_certs = std::make_optional<uint8_t>();
@@ -340,7 +340,7 @@ std::optional<uint8_t> ParseInhibitAnyPolicy(
// PolicyMappings ::= SEQUENCE SIZE (1..MAX) OF SEQUENCE {
// issuerDomainPolicy CertPolicyId,
// subjectDomainPolicy CertPolicyId }
bool ParsePolicyMappings(const der::Input &policy_mappings_tlv,
bool ParsePolicyMappings(der::Input policy_mappings_tlv,
std::vector<ParsedPolicyMapping> *mappings) {
mappings->clear();
+5 -6
View File
@@ -73,7 +73,7 @@ struct OPENSSL_EXPORT PolicyInformation {
// The values in |policies| are only valid as long as |extension_value| is (as
// it references data).
OPENSSL_EXPORT bool ParseCertificatePoliciesExtension(
const der::Input &extension_value, std::vector<PolicyInformation> *policies,
der::Input extension_value, std::vector<PolicyInformation> *policies,
CertErrors *errors);
// Parses a certificatePolicies extension and stores the policy OIDs in
@@ -94,7 +94,7 @@ OPENSSL_EXPORT bool ParseCertificatePoliciesExtension(
// The values in |policy_oids| are only valid as long as |extension_value| is
// (as it references data).
OPENSSL_EXPORT bool ParseCertificatePoliciesExtensionOids(
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
std::vector<der::Input> *policy_oids, CertErrors *errors);
struct ParsedPolicyConstraints {
@@ -106,12 +106,12 @@ struct ParsedPolicyConstraints {
// Parses a PolicyConstraints SEQUENCE as defined by RFC 5280. Returns true on
// success, and sets |out|.
[[nodiscard]] OPENSSL_EXPORT bool ParsePolicyConstraints(
const der::Input &policy_constraints_tlv, ParsedPolicyConstraints *out);
der::Input policy_constraints_tlv, ParsedPolicyConstraints *out);
// Parses an InhibitAnyPolicy as defined by RFC 5280. Returns num certs on
// success, or empty if parser fails.
[[nodiscard]] OPENSSL_EXPORT std::optional<uint8_t> ParseInhibitAnyPolicy(
const der::Input &inhibit_any_policy_tlv);
der::Input inhibit_any_policy_tlv);
struct ParsedPolicyMapping {
der::Input issuer_domain_policy;
@@ -121,8 +121,7 @@ struct ParsedPolicyMapping {
// Parses a PolicyMappings SEQUENCE as defined by RFC 5280. Returns true on
// success, and sets |mappings|.
[[nodiscard]] OPENSSL_EXPORT bool ParsePolicyMappings(
const der::Input &policy_mappings_tlv,
std::vector<ParsedPolicyMapping> *mappings);
der::Input policy_mappings_tlv, std::vector<ParsedPolicyMapping> *mappings);
} // namespace bssl
+5 -5
View File
@@ -26,7 +26,7 @@ namespace {
// In dotted notation: 2.5.29.28
inline constexpr uint8_t kIssuingDistributionPointOid[] = {0x55, 0x1d, 0x1c};
[[nodiscard]] bool NormalizeNameTLV(const der::Input &name_tlv,
[[nodiscard]] bool NormalizeNameTLV(der::Input name_tlv,
std::string *out_normalized_name) {
der::Parser parser(name_tlv);
der::Input name_rdn;
@@ -48,7 +48,7 @@ bool ContainsExactMatchingName(std::vector<std::string_view> a,
} // namespace
bool ParseCrlCertificateList(const der::Input &crl_tlv,
bool ParseCrlCertificateList(der::Input crl_tlv,
der::Input *out_tbs_cert_list_tlv,
der::Input *out_signature_algorithm_tlv,
der::BitString *out_signature_value) {
@@ -92,7 +92,7 @@ bool ParseCrlCertificateList(const der::Input &crl_tlv,
return true;
}
bool ParseCrlTbsCertList(const der::Input &tbs_tlv, ParsedCrlTbsCertList *out) {
bool ParseCrlTbsCertList(der::Input tbs_tlv, ParsedCrlTbsCertList *out) {
der::Parser parser(tbs_tlv);
// TBSCertList ::= SEQUENCE {
@@ -196,7 +196,7 @@ bool ParseCrlTbsCertList(const der::Input &tbs_tlv, ParsedCrlTbsCertList *out) {
}
bool ParseIssuingDistributionPoint(
const der::Input &extension_value,
der::Input extension_value,
std::unique_ptr<GeneralNames> *out_distribution_point_names,
ContainedCertsType *out_only_contains_cert_type) {
der::Parser idp_extension_value_parser(extension_value);
@@ -303,7 +303,7 @@ bool ParseIssuingDistributionPoint(
}
CRLRevocationStatus GetCRLStatusForCert(
const der::Input &cert_serial, CrlVersion crl_version,
der::Input cert_serial, CrlVersion crl_version,
const std::optional<der::Input> &revoked_certificates_tlv) {
if (!revoked_certificates_tlv.has_value()) {
// RFC 5280 Section 5.1.2.6: "When there are no revoked certificates, the
+4 -4
View File
@@ -43,7 +43,7 @@ enum class CRLRevocationStatus {
// signatureAlgorithm AlgorithmIdentifier,
// signatureValue BIT STRING }
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlCertificateList(
const der::Input &crl_tlv, der::Input *out_tbs_cert_list_tlv,
der::Input crl_tlv, der::Input *out_tbs_cert_list_tlv,
der::Input *out_signature_algorithm_tlv,
der::BitString *out_signature_value);
@@ -77,7 +77,7 @@ enum class CRLRevocationStatus {
// -- if present, version MUST be v2
// }
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlTbsCertList(
const der::Input &tbs_tlv, ParsedCrlTbsCertList *out);
der::Input tbs_tlv, ParsedCrlTbsCertList *out);
// Represents a CRL "Version" from RFC 5280. TBSCertList reuses the same
// Version definition from TBSCertificate, however only v1(not present) and
@@ -180,12 +180,12 @@ enum class ContainedCertsType {
// indirectCRL [4] BOOLEAN DEFAULT FALSE,
// onlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE }
[[nodiscard]] OPENSSL_EXPORT bool ParseIssuingDistributionPoint(
const der::Input &extension_value,
der::Input extension_value,
std::unique_ptr<GeneralNames> *out_distribution_point_names,
ContainedCertsType *out_only_contains_cert_type);
OPENSSL_EXPORT CRLRevocationStatus
GetCRLStatusForCert(const der::Input &cert_serial, CrlVersion crl_version,
GetCRLStatusForCert(der::Input cert_serial, CrlVersion crl_version,
const std::optional<der::Input> &revoked_certificates_tlv);
// Checks the revocation status of the certificate |cert| by using the
+1 -1
View File
@@ -10,7 +10,7 @@
namespace bssl {
bool ParseEKUExtension(const der::Input &extension_value,
bool ParseEKUExtension(der::Input extension_value,
std::vector<der::Input> *eku_oids) {
der::Parser extension_parser(extension_value);
der::Parser sequence_parser;
+1 -1
View File
@@ -75,7 +75,7 @@ inline constexpr uint8_t kOCSPSigning[] = {0x2b, 0x06, 0x01, 0x05,
//
// Note: The returned OIDs are only as valid as long as the data pointed to by
// |extension_value| is valid.
OPENSSL_EXPORT bool ParseEKUExtension(const der::Input &extension_value,
OPENSSL_EXPORT bool ParseEKUExtension(der::Input extension_value,
std::vector<der::Input> *eku_oids);
} // namespace bssl
+1 -1
View File
@@ -13,7 +13,7 @@ namespace bssl {
namespace {
// Helper method to check if an EKU is present in a std::vector of EKUs.
bool HasEKU(const std::vector<der::Input> &list, const der::Input &eku) {
bool HasEKU(const std::vector<der::Input> &list, der::Input eku) {
for (const auto &oid : list) {
if (oid == eku) {
return true;
+10 -11
View File
@@ -44,8 +44,8 @@ GeneralNames::GeneralNames() = default;
GeneralNames::~GeneralNames() = default;
// static
std::unique_ptr<GeneralNames> GeneralNames::Create(
const der::Input &general_names_tlv, CertErrors *errors) {
std::unique_ptr<GeneralNames> GeneralNames::Create(der::Input general_names_tlv,
CertErrors *errors) {
BSSL_CHECK(errors);
// RFC 5280 section 4.2.1.6:
@@ -66,7 +66,7 @@ std::unique_ptr<GeneralNames> GeneralNames::Create(
// static
std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
const der::Input &general_names_value, CertErrors *errors) {
der::Input general_names_value, CertErrors *errors) {
BSSL_CHECK(errors);
auto general_names = std::make_unique<GeneralNames>();
@@ -96,7 +96,7 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
}
[[nodiscard]] bool ParseGeneralName(
const der::Input &input,
der::Input input,
GeneralNames::ParseGeneralNameIPAddressType ip_address_type,
GeneralNames *subtrees, CertErrors *errors) {
BSSL_CHECK(errors);
@@ -170,8 +170,8 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
// version 4, as specified in [RFC791], the octet string MUST contain
// exactly four octets. For IP version 6, as specified in [RFC2460],
// the octet string MUST contain exactly sixteen octets.
if ((value.Length() != kIPv4AddressSize &&
value.Length() != kIPv6AddressSize)) {
if ((value.size() != kIPv4AddressSize &&
value.size() != kIPv6AddressSize)) {
errors->AddError(kFailedParsingIp);
return false;
}
@@ -188,14 +188,13 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
// constraint for "class C" subnet 192.0.2.0 is represented as the
// octets C0 00 02 00 FF FF FF 00, representing the CIDR notation
// 192.0.2.0/24 (mask 255.255.255.0).
if (value.Length() != kIPv4AddressSize * 2 &&
value.Length() != kIPv6AddressSize * 2) {
if (value.size() != kIPv4AddressSize * 2 &&
value.size() != kIPv6AddressSize * 2) {
errors->AddError(kFailedParsingIp);
return false;
}
der::Input addr(value.UnsafeData(), value.Length() / 2);
der::Input mask(value.UnsafeData() + value.Length() / 2,
value.Length() / 2);
der::Input addr = value.first(value.size() / 2);
der::Input mask = value.subspan(value.size() / 2);
if (!IsValidNetmask(mask)) {
errors->AddError(kFailedParsingIp);
return false;
+4 -4
View File
@@ -63,13 +63,13 @@ struct OPENSSL_EXPORT GeneralNames {
// |general_names_tlv|, so is only valid as long as |general_names_tlv| is.
// Returns nullptr on failure, and may fill |errors| with
// additional information. |errors| must be non-null.
static std::unique_ptr<GeneralNames> Create(
const der::Input &general_names_tlv, CertErrors *errors);
static std::unique_ptr<GeneralNames> Create(der::Input general_names_tlv,
CertErrors *errors);
// As above, but takes the GeneralNames sequence value, without the tag and
// length.
static std::unique_ptr<GeneralNames> CreateFromValue(
const der::Input &general_names_value, CertErrors *errors);
der::Input general_names_value, CertErrors *errors);
// DER-encoded OtherName values.
std::vector<der::Input> other_names;
@@ -122,7 +122,7 @@ struct OPENSSL_EXPORT GeneralNames {
// |errors| must be non-null.
// TODO(mattm): should this be a method on GeneralNames?
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralName(
const der::Input &input,
der::Input input,
GeneralNames::ParseGeneralNameIPAddressType ip_address_type,
GeneralNames *subtrees, CertErrors *errors);
+10 -16
View File
@@ -4,8 +4,6 @@
#include "input.h"
#include <algorithm>
#include <openssl/base.h>
namespace bssl::der {
@@ -20,42 +18,38 @@ std::string_view Input::AsStringView() const {
data_.size());
}
bssl::Span<const uint8_t> Input::AsSpan() const { return data_; }
bool operator==(const Input &lhs, const Input &rhs) {
return lhs.AsSpan() == rhs.AsSpan();
bool operator==(Input lhs, Input rhs) {
return MakeConstSpan(lhs) == MakeConstSpan(rhs);
}
bool operator!=(const Input &lhs, const Input &rhs) { return !(lhs == rhs); }
bool operator!=(Input lhs, Input rhs) { return !(lhs == rhs); }
ByteReader::ByteReader(const Input &in)
: data_(in.UnsafeData()), len_(in.Length()) {}
ByteReader::ByteReader(Input in) : data_(in) {}
bool ByteReader::ReadByte(uint8_t *byte_p) {
if (!HasMore()) {
return false;
}
*byte_p = *data_;
*byte_p = data_[0];
Advance(1);
return true;
}
bool ByteReader::ReadBytes(size_t len, Input *out) {
if (len > len_) {
if (len > data_.size()) {
return false;
}
*out = Input(data_, len);
*out = Input(data_.first(len));
Advance(len);
return true;
}
// Returns whether there is any more data to be read.
bool ByteReader::HasMore() { return len_ > 0; }
bool ByteReader::HasMore() { return !data_.empty(); }
void ByteReader::Advance(size_t len) {
BSSL_CHECK(len <= len_);
data_ += len;
len_ -= len;
BSSL_CHECK(len <= data_.size());
data_ = data_.subspan(len);
}
} // namespace bssl::der
+44 -26
View File
@@ -26,6 +26,10 @@ namespace bssl::der {
// difficult to read memory outside of an Input. ByteReader provides a simple
// API for reading through the Input sequentially. For more complicated uses,
// multiple instances of a ByteReader for a particular Input can be created.
//
// TODO(crbug.com/boringssl/661): This class will gradually be replaced with
// bssl::Span<const uint8_t>. Avoid relying on APIs that are not part of
// bssl::Span.
class OPENSSL_EXPORT Input {
public:
// Creates an empty Input, one from which no data can be read.
@@ -34,29 +38,36 @@ class OPENSSL_EXPORT Input {
// Creates an Input from a span. The constructed Input is only valid as long
// as |data| points to live memory. If constructed from, say, a
// |std::vector<uint8_t>|, mutating the vector will invalidate the Input.
constexpr explicit Input(bssl::Span<const uint8_t> data) : data_(data) {}
constexpr Input(bssl::Span<const uint8_t> data) : data_(data) {}
// Creates an Input from the given |data| and |len|.
constexpr explicit Input(const uint8_t *data, size_t len)
: data_(bssl::MakeConstSpan(data, len)) {}
: data_(MakeConstSpan(data, len)) {}
// Creates an Input from a std::string_view. The constructed Input is only
// valid as long as |data| points to live memory. If constructed from, say, a
// |std::string|, mutating the vector will invalidate the Input.
explicit Input(std::string_view str)
: data_(bssl::MakeConstSpan(reinterpret_cast<const uint8_t *>(str.data()),
str.size())) {}
// Returns the length in bytes of an Input's data.
constexpr size_t Length() const { return data_.size(); }
// Returns a pointer to the Input's data. This method is marked as "unsafe"
// because access to the Input's data should be done through ByteReader
// instead. This method should only be used where using a ByteReader truly
// is not an option.
constexpr const uint8_t *UnsafeData() const { return data_.data(); }
: data_(MakeConstSpan(reinterpret_cast<const uint8_t *>(str.data()),
str.size())) {}
// The following APIs have the same semantics as in |bssl::Span|.
constexpr Span<const uint8_t>::iterator begin() const {
return data_.begin();
}
constexpr Span<const uint8_t>::iterator end() const { return data_.end(); }
constexpr const uint8_t *data() const { return data_.data(); }
constexpr size_t size() const { return data_.size(); }
constexpr bool empty() const { return data_.empty(); }
constexpr uint8_t operator[](size_t idx) const { return data_[idx]; }
constexpr uint8_t front() const { return data_.front(); }
constexpr uint8_t back() const { return data_.back(); }
constexpr Input subspan(size_t pos = 0,
size_t len = Span<const uint8_t>::npos) const {
return Input(data_.subspan(pos, len));
}
constexpr Input first(size_t len) const { return Input(data_.first(len)); }
constexpr Input last(size_t len) const { return Input(data_.last(len)); }
// Returns a copy of the data represented by this object as a std::string.
std::string AsString() const;
@@ -66,29 +77,37 @@ class OPENSSL_EXPORT Input {
// this Input.
std::string_view AsStringView() const;
// Deprecated: This class implicitly converts to bssl::Span<const uint8_t>.
//
// Returns a span pointing to the same data as the Input. The resulting span
// must not outlive the data that was used to construct this Input.
bssl::Span<const uint8_t> AsSpan() const;
Span<const uint8_t> AsSpan() const { return *this; }
// Deprecated: Use size() instead.
constexpr size_t Length() const { return size(); }
// Deprecated: Use data() instead.
constexpr const uint8_t *UnsafeData() const { return data(); }
private:
// TODO(crbug.com/770501): Replace this type with span altogether.
bssl::Span<const uint8_t> data_;
Span<const uint8_t> data_;
};
// Return true if |lhs|'s data and |rhs|'s data are byte-wise equal.
OPENSSL_EXPORT bool operator==(const Input &lhs, const Input &rhs);
OPENSSL_EXPORT bool operator==(Input lhs, Input rhs);
// Return true if |lhs|'s data and |rhs|'s data are not byte-wise equal.
OPENSSL_EXPORT bool operator!=(const Input &lhs, const Input &rhs);
OPENSSL_EXPORT bool operator!=(Input lhs, Input rhs);
// Returns true if |lhs|'s data is lexicographically less than |rhs|'s data.
OPENSSL_EXPORT constexpr bool operator<(const Input &lhs, const Input &rhs) {
OPENSSL_EXPORT constexpr bool operator<(Input lhs, Input rhs) {
// This is `std::lexicographical_compare`, but that's not `constexpr` until
// C++-20.
auto *it1 = lhs.UnsafeData();
auto *it2 = rhs.UnsafeData();
const auto *end1 = lhs.UnsafeData() + lhs.Length();
const auto *end2 = rhs.UnsafeData() + rhs.Length();
auto *it1 = lhs.data();
auto *it2 = rhs.data();
const auto *end1 = lhs.data() + lhs.size();
const auto *end2 = rhs.data() + rhs.size();
for (; it1 != end1 && it2 != end2; ++it1, ++it2) {
if (*it1 < *it2) {
return true;
@@ -119,7 +138,7 @@ OPENSSL_EXPORT constexpr bool operator<(const Input &lhs, const Input &rhs) {
class OPENSSL_EXPORT ByteReader {
public:
// Creates a ByteReader to read the data represented by an Input.
explicit ByteReader(const Input &in);
explicit ByteReader(Input in);
// Reads a single byte from the input source, putting the byte read in
// |*byte_p|. If a byte cannot be read from the input (because there is
@@ -132,7 +151,7 @@ class OPENSSL_EXPORT ByteReader {
[[nodiscard]] bool ReadBytes(size_t len, Input *out);
// Returns how many bytes are left to read.
size_t BytesLeft() const { return len_; }
size_t BytesLeft() const { return data_.size(); }
// Returns whether there is any more data to be read.
bool HasMore();
@@ -140,8 +159,7 @@ class OPENSSL_EXPORT ByteReader {
private:
void Advance(size_t len);
const uint8_t *data_;
size_t len_;
bssl::Span<const uint8_t> data_;
};
} // namespace bssl::der
+7 -7
View File
@@ -48,7 +48,7 @@ TEST(InputTest, AsString) {
TEST(InputTest, StaticArray) {
Input input(kInput);
EXPECT_EQ(std::size(kInput), input.Length());
EXPECT_EQ(std::size(kInput), input.size());
Input input2(kInput);
EXPECT_EQ(input, input2);
@@ -56,17 +56,17 @@ TEST(InputTest, StaticArray) {
TEST(InputTest, ConstExpr) {
constexpr Input default_input;
static_assert(default_input.Length() == 0);
static_assert(default_input.UnsafeData() == nullptr);
static_assert(default_input.size() == 0);
static_assert(default_input.data() == nullptr);
constexpr Input const_array_input(kInput);
static_assert(const_array_input.Length() == 4);
static_assert(const_array_input.UnsafeData() == kInput);
static_assert(const_array_input.size() == 4);
static_assert(const_array_input.data() == kInput);
static_assert(default_input < const_array_input);
constexpr Input ptr_len_input(kInput, 2);
static_assert(ptr_len_input.Length() == 2);
static_assert(ptr_len_input.UnsafeData() == kInput);
static_assert(ptr_len_input.size() == 2);
static_assert(ptr_len_input.data() == kInput);
static_assert(ptr_len_input < const_array_input);
Input runtime_input(kInput2, 2);
+5 -5
View File
@@ -7,11 +7,11 @@
namespace bssl {
bool IsValidNetmask(der::Input mask) {
if (mask.Length() != kIPv4AddressSize && mask.Length() != kIPv6AddressSize) {
if (mask.size() != kIPv4AddressSize && mask.size() != kIPv6AddressSize) {
return false;
}
for (size_t i = 0; i < mask.Length(); i++) {
for (size_t i = 0; i < mask.size(); i++) {
uint8_t b = mask[i];
if (b != 0xff) {
// b must be all ones followed by all zeros, so ~b must be all zeros
@@ -21,7 +21,7 @@ bool IsValidNetmask(der::Input mask) {
return false;
}
// The remaining bytes must be all zeros.
for (size_t j = i + 1; j < mask.Length(); j++) {
for (size_t j = i + 1; j < mask.size(); j++) {
if (mask[j] != 0) {
return false;
}
@@ -35,10 +35,10 @@ bool IsValidNetmask(der::Input mask) {
bool IPAddressMatchesWithNetmask(der::Input addr1, der::Input addr2,
der::Input mask) {
if (addr1.Length() != addr2.Length() || addr1.Length() != mask.Length()) {
if (addr1.size() != addr2.size() || addr1.size() != mask.size()) {
return false;
}
for (size_t i = 0; i < addr1.Length(); i++) {
for (size_t i = 0; i < addr1.size(); i++) {
if ((addr1[i] & mask[i]) != (addr2[i] & mask[i])) {
return false;
}
+8 -8
View File
@@ -117,7 +117,7 @@ bool DNSNameMatches(std::string_view name, std::string_view dns_constraint,
// NOTE: |subtrees| is not pre-initialized by the function(it is expected to be
// a default initialized object), and it will be modified regardless of the
// return value.
[[nodiscard]] bool ParseGeneralSubtrees(const der::Input &value,
[[nodiscard]] bool ParseGeneralSubtrees(der::Input value,
GeneralNames *subtrees,
CertErrors *errors) {
BSSL_CHECK(errors);
@@ -278,7 +278,7 @@ NameConstraints::~NameConstraints() = default;
// static
std::unique_ptr<NameConstraints> NameConstraints::Create(
const der::Input &extension_value, bool is_critical, CertErrors *errors) {
der::Input extension_value, bool is_critical, CertErrors *errors) {
BSSL_CHECK(errors);
auto name_constraints = std::make_unique<NameConstraints>();
@@ -288,7 +288,7 @@ std::unique_ptr<NameConstraints> NameConstraints::Create(
return name_constraints;
}
bool NameConstraints::Parse(const der::Input &extension_value, bool is_critical,
bool NameConstraints::Parse(der::Input extension_value, bool is_critical,
CertErrors *errors) {
BSSL_CHECK(errors);
@@ -348,7 +348,7 @@ bool NameConstraints::Parse(const der::Input &extension_value, bool is_critical,
return true;
}
void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
void NameConstraints::IsPermittedCert(der::Input subject_rdn_sequence,
const GeneralNames *subject_alt_names,
CertErrors *errors) const {
// Checking NameConstraints is O(number_of_names * number_of_constraints).
@@ -381,7 +381,7 @@ void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
} else {
constraint_count += excluded_subtrees_.directory_names.size() +
permitted_subtrees_.directory_names.size();
name_count = subject_rdn_sequence.Length();
name_count = subject_rdn_sequence.size();
}
// Upper bound the number of possible checks, checking for overflow.
size_t check_count = constraint_count * name_count;
@@ -502,7 +502,7 @@ void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
// This code assumes that criticality condition is checked by the caller, and
// therefore only needs to avoid the IsPermittedDirectoryName check against an
// empty subject in such a case.
if (subject_alt_names && subject_rdn_sequence.Length() == 0) {
if (subject_alt_names && subject_rdn_sequence.empty()) {
return;
}
@@ -647,7 +647,7 @@ bool NameConstraints::IsPermittedDNSName(std::string_view name) const {
}
bool NameConstraints::IsPermittedDirectoryName(
const der::Input &name_rdn_sequence) const {
der::Input name_rdn_sequence) const {
for (const auto &excluded_name : excluded_subtrees_.directory_names) {
if (VerifyNameInSubtree(name_rdn_sequence, excluded_name)) {
return false;
@@ -669,7 +669,7 @@ bool NameConstraints::IsPermittedDirectoryName(
return false;
}
bool NameConstraints::IsPermittedIP(const der::Input &ip) const {
bool NameConstraints::IsPermittedIP(der::Input ip) const {
for (const auto &excluded_ip : excluded_subtrees_.ip_address_ranges) {
if (IPAddressMatchesWithNetmask(ip, excluded_ip.first,
excluded_ip.second)) {
+7 -6
View File
@@ -31,8 +31,9 @@ class OPENSSL_EXPORT NameConstraints {
// marked critical. Returns nullptr if parsing the the extension failed.
// The object may reference data from |extension_value|, so is only valid as
// long as |extension_value| is.
static std::unique_ptr<NameConstraints> Create(
const der::Input &extension_value, bool is_critical, CertErrors *errors);
static std::unique_ptr<NameConstraints> Create(der::Input extension_value,
bool is_critical,
CertErrors *errors);
// Tests if a certificate is allowed by the name constraints.
// |subject_rdn_sequence| should be the DER-encoded value of the subject's
@@ -42,7 +43,7 @@ class OPENSSL_EXPORT NameConstraints {
// If the certificate is not allowed, an error will be added to |errors|.
// Note that this method does not check hostname or IP address in commonName,
// which is deprecated (crbug.com/308330).
void IsPermittedCert(const der::Input &subject_rdn_sequence,
void IsPermittedCert(der::Input subject_rdn_sequence,
const GeneralNames *subject_alt_names,
CertErrors *errors) const;
@@ -62,10 +63,10 @@ class OPENSSL_EXPORT NameConstraints {
// Returns true if the directoryName |name_rdn_sequence| is permitted.
// |name_rdn_sequence| should be the DER-encoded RDNSequence value (not
// including the Sequence tag.)
bool IsPermittedDirectoryName(const der::Input &name_rdn_sequence) const;
bool IsPermittedDirectoryName(der::Input name_rdn_sequence) const;
// Returns true if the iPAddress |ip| is permitted.
bool IsPermittedIP(const der::Input &ip) const;
bool IsPermittedIP(der::Input ip) const;
// Returns a bitfield of GeneralNameTypes of all the types constrained by this
// NameConstraints. Name types that aren't supported will only be present if
@@ -87,7 +88,7 @@ class OPENSSL_EXPORT NameConstraints {
const GeneralNames &excluded_subtrees() const { return excluded_subtrees_; }
private:
[[nodiscard]] bool Parse(const der::Input &extension_value, bool is_critical,
[[nodiscard]] bool Parse(der::Input extension_value, bool is_critical,
CertErrors *errors);
GeneralNames permitted_subtrees_;
+1 -2
View File
@@ -58,8 +58,7 @@ namespace {
}
::testing::AssertionResult IsPermittedCert(
const NameConstraints *name_constraints,
const der::Input &subject_rdn_sequence,
const NameConstraints *name_constraints, der::Input subject_rdn_sequence,
const GeneralNames *subject_alt_names) {
CertErrors errors;
name_constraints->IsPermittedCert(subject_rdn_sequence, subject_alt_names,
+20 -23
View File
@@ -37,7 +37,7 @@ OCSPResponse::~OCSPResponse() = default;
// issuerKeyHash OCTET STRING, -- Hash of issuer's public key
// serialNumber CertificateSerialNumber
// }
bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out) {
bool ParseOCSPCertID(der::Input raw_tlv, OCSPCertID *out) {
der::Parser outer_parser(raw_tlv);
der::Parser parser;
if (!outer_parser.ReadSequence(&parser)) {
@@ -82,7 +82,7 @@ namespace {
// revocationTime GeneralizedTime,
// revocationReason [0] EXPLICIT CRLReason OPTIONAL
// }
bool ParseRevokedInfo(const der::Input &raw_tlv, OCSPCertStatus *out) {
bool ParseRevokedInfo(der::Input raw_tlv, OCSPCertStatus *out) {
der::Parser parser(raw_tlv);
if (!parser.ReadGeneralizedTime(&(out->revocation_time))) {
return false;
@@ -130,7 +130,7 @@ bool ParseRevokedInfo(const der::Input &raw_tlv, OCSPCertStatus *out) {
// }
//
// UnknownInfo ::= NULL
bool ParseCertStatus(const der::Input &raw_tlv, OCSPCertStatus *out) {
bool ParseCertStatus(der::Input raw_tlv, OCSPCertStatus *out) {
der::Parser parser(raw_tlv);
der::Tag status_tag;
der::Input status;
@@ -158,13 +158,13 @@ bool ParseCertStatus(const der::Input &raw_tlv, OCSPCertStatus *out) {
// Writes the hash of |value| as an OCTET STRING to |cbb|, using |hash_type| as
// the algorithm. Returns true on success.
bool AppendHashAsOctetString(const EVP_MD *hash_type, CBB *cbb,
const der::Input &value) {
der::Input value) {
CBB octet_string;
unsigned hash_len;
uint8_t hash_buffer[EVP_MAX_MD_SIZE];
return CBB_add_asn1(cbb, &octet_string, CBS_ASN1_OCTETSTRING) &&
EVP_Digest(value.UnsafeData(), value.Length(), hash_buffer, &hash_len,
EVP_Digest(value.data(), value.size(), hash_buffer, &hash_len,
hash_type, nullptr) &&
CBB_add_bytes(&octet_string, hash_buffer, hash_len) && CBB_flush(cbb);
}
@@ -178,8 +178,7 @@ bool AppendHashAsOctetString(const EVP_MD *hash_type, CBB *cbb,
// nextUpdate [0] EXPLICIT GeneralizedTime OPTIONAL,
// singleExtensions [1] EXPLICIT Extensions OPTIONAL
// }
bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
OCSPSingleResponse *out) {
bool ParseOCSPSingleResponse(der::Input raw_tlv, OCSPSingleResponse *out) {
der::Parser outer_parser(raw_tlv);
der::Parser parser;
if (!outer_parser.ReadSequence(&parser)) {
@@ -235,8 +234,7 @@ namespace {
// byName [1] Name,
// byKey [2] KeyHash
// }
bool ParseResponderID(const der::Input &raw_tlv,
OCSPResponseData::ResponderID *out) {
bool ParseResponderID(der::Input raw_tlv, OCSPResponseData::ResponderID *out) {
der::Parser parser(raw_tlv);
der::Tag id_tag;
der::Input id_input;
@@ -256,7 +254,7 @@ bool ParseResponderID(const der::Input &raw_tlv,
if (key_parser.HasMore()) {
return false;
}
if (key_hash.Length() != SHA_DIGEST_LENGTH) {
if (key_hash.size() != SHA_DIGEST_LENGTH) {
return false;
}
@@ -277,7 +275,7 @@ bool ParseResponderID(const der::Input &raw_tlv,
// responses SEQUENCE OF SingleResponse,
// responseExtensions [1] EXPLICIT Extensions OPTIONAL
// }
bool ParseOCSPResponseData(const der::Input &raw_tlv, OCSPResponseData *out) {
bool ParseOCSPResponseData(der::Input raw_tlv, OCSPResponseData *out) {
der::Parser outer_parser(raw_tlv);
der::Parser parser;
if (!outer_parser.ReadSequence(&parser)) {
@@ -357,7 +355,7 @@ namespace {
// signature BIT STRING,
// certs [0] EXPLICIT SEQUENCE OF Certificate OPTIONAL
// }
bool ParseBasicOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
bool ParseBasicOCSPResponse(der::Input raw_tlv, OCSPResponse *out) {
der::Parser outer_parser(raw_tlv);
der::Parser parser;
if (!outer_parser.ReadSequence(&parser)) {
@@ -425,7 +423,7 @@ bool ParseBasicOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
// responseType OBJECT IDENTIFIER,
// response OCTET STRING
// }
bool ParseOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
bool ParseOCSPResponse(der::Input raw_tlv, OCSPResponse *out) {
der::Parser outer_parser(raw_tlv);
der::Parser parser;
if (!outer_parser.ReadSequence(&parser)) {
@@ -494,12 +492,11 @@ bool ParseOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
namespace {
// Checks that the |type| hash of |value| is equal to |hash|
bool VerifyHash(const EVP_MD *type, const der::Input &hash,
const der::Input &value) {
bool VerifyHash(const EVP_MD *type, der::Input hash, der::Input value) {
unsigned value_hash_len;
uint8_t value_hash[EVP_MAX_MD_SIZE];
if (!EVP_Digest(value.UnsafeData(), value.Length(), value_hash,
&value_hash_len, type, nullptr)) {
if (!EVP_Digest(value.data(), value.size(), value_hash, &value_hash_len, type,
nullptr)) {
return false;
}
@@ -521,10 +518,10 @@ bool VerifyHash(const EVP_MD *type, const der::Input &hash,
// algorithm OBJECT IDENTIFIER,
// parameters ANY DEFINED BY algorithm OPTIONAL }
//
bool GetSubjectPublicKeyBytes(const der::Input &spki_tlv, der::Input *spk_tlv) {
bool GetSubjectPublicKeyBytes(der::Input spki_tlv, der::Input *spk_tlv) {
CBS outer, inner, alg, spk;
uint8_t unused_bit_count;
CBS_init(&outer, spki_tlv.UnsafeData(), spki_tlv.Length());
CBS_init(&outer, spki_tlv.data(), spki_tlv.size());
// The subjectPublicKey field includes the unused bit count. For this
// application, the unused bit count must be zero, and is not included in
// the result. We extract the subjectPubicKey bit string, verify the first
@@ -735,7 +732,7 @@ std::shared_ptr<const ParsedCertificate> OCSPParseCertificate(
// Parse ResponseData and return false if any unhandled critical extensions are
// found. No known critical ResponseData extensions exist.
bool ParseOCSPResponseDataExtensions(
const der::Input &response_extensions,
der::Input response_extensions,
OCSPVerifyResult::ResponseStatus *response_details) {
std::map<der::Input, ParsedExtension> extensions;
if (!ParseExtensions(response_extensions, &extensions)) {
@@ -760,7 +757,7 @@ bool ParseOCSPResponseDataExtensions(
// to be marked critical, but since it is handled by Chrome, we will overlook
// the flag setting.
bool ParseOCSPSingleResponseExtensions(
const der::Input &single_extensions,
der::Input single_extensions,
OCSPVerifyResult::ResponseStatus *response_details) {
std::map<der::Input, ParsedExtension> extensions;
if (!ParseExtensions(single_extensions, &extensions)) {
@@ -1060,8 +1057,8 @@ bool CreateOCSPRequest(const ParsedCertificate *cert,
if (!CBB_add_asn1(&req_cert, &serial_number, CBS_ASN1_INTEGER)) {
return false;
}
if (!CBB_add_bytes(&serial_number, cert->tbs().serial_number.UnsafeData(),
cert->tbs().serial_number.Length())) {
if (!CBB_add_bytes(&serial_number, cert->tbs().serial_number.data(),
cert->tbs().serial_number.size())) {
return false;
}
+4 -5
View File
@@ -230,7 +230,7 @@ inline constexpr uint8_t kBasicOCSPResponseOid[] = {
//
// On failure |out| has an undefined state. Some of its fields may have been
// updated during parsing, whereas others may not have been changed.
OPENSSL_EXPORT bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out);
OPENSSL_EXPORT bool ParseOCSPCertID(der::Input raw_tlv, OCSPCertID *out);
// Parses a DER-encoded OCSP "SingleResponse" as specified by RFC 6960. Returns
// true on success and sets the results in |out|. The resulting |out|
@@ -239,7 +239,7 @@ OPENSSL_EXPORT bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out);
//
// On failure |out| has an undefined state. Some of its fields may have been
// updated during parsing, whereas others may not have been changed.
OPENSSL_EXPORT bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
OPENSSL_EXPORT bool ParseOCSPSingleResponse(der::Input raw_tlv,
OCSPSingleResponse *out);
// Parses a DER-encoded OCSP "ResponseData" as specified by RFC 6960. Returns
@@ -249,7 +249,7 @@ OPENSSL_EXPORT bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
//
// On failure |out| has an undefined state. Some of its fields may have been
// updated during parsing, whereas others may not have been changed.
OPENSSL_EXPORT bool ParseOCSPResponseData(const der::Input &raw_tlv,
OPENSSL_EXPORT bool ParseOCSPResponseData(der::Input raw_tlv,
OCSPResponseData *out);
// Parses a DER-encoded "OCSPResponse" as specified by RFC 6960. Returns true
@@ -259,8 +259,7 @@ OPENSSL_EXPORT bool ParseOCSPResponseData(const der::Input &raw_tlv,
//
// On failure |out| has an undefined state. Some of its fields may have been
// updated during parsing, whereas others may not have been changed.
OPENSSL_EXPORT bool ParseOCSPResponse(const der::Input &raw_tlv,
OCSPResponse *out);
OPENSSL_EXPORT bool ParseOCSPResponse(der::Input raw_tlv, OCSPResponse *out);
// Checks the revocation status of the certificate |certificate_der| by using
// the DER-encoded |raw_response|.
+22 -24
View File
@@ -74,7 +74,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
"Serial number is not a valid INTEGER");
// Returns true if |input| is a SEQUENCE and nothing else.
[[nodiscard]] bool IsSequenceTLV(const der::Input &input) {
[[nodiscard]] bool IsSequenceTLV(der::Input input) {
der::Parser parser(input);
der::Parser unused_sequence_parser;
if (!parser.ReadSequence(&unused_sequence_parser)) {
@@ -101,8 +101,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
// Implementations SHOULD be prepared to accept any version certificate.
// At a minimum, conforming implementations MUST recognize version 3
// certificates.
[[nodiscard]] bool ParseVersion(const der::Input &in,
CertificateVersion *version) {
[[nodiscard]] bool ParseVersion(der::Input in, CertificateVersion *version) {
der::Parser parser(in);
uint64_t version64;
if (!parser.ReadUint64(&version64)) {
@@ -133,8 +132,8 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
[[nodiscard]] bool BitStringIsAllZeros(const der::BitString &bits) {
// Note that it is OK to read from the unused bits, since BitString parsing
// guarantees they are all zero.
for (size_t i = 0; i < bits.bytes().Length(); ++i) {
if (bits.bytes()[i] != 0) {
for (uint8_t b : bits.bytes()) {
if (b != 0) {
return false;
}
}
@@ -148,7 +147,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
// DistributionPointName ::= CHOICE {
// fullName [0] GeneralNames,
// nameRelativeToCRLIssuer [1] RelativeDistinguishedName }
bool ParseDistributionPointName(const der::Input &dp_name,
bool ParseDistributionPointName(der::Input dp_name,
ParsedDistributionPoint *distribution_point) {
der::Parser parser(dp_name);
std::optional<der::Input> der_full_name;
@@ -250,7 +249,7 @@ ParsedTbsCertificate::ParsedTbsCertificate(ParsedTbsCertificate &&other) =
ParsedTbsCertificate::~ParsedTbsCertificate() = default;
bool VerifySerialNumber(const der::Input &value, bool warnings_only,
bool VerifySerialNumber(der::Input value, bool warnings_only,
CertErrors *errors) {
// If |warnings_only| was set to true, the exact same errors will be logged,
// only they will be logged with a lower severity (warning rather than error).
@@ -271,7 +270,7 @@ bool VerifySerialNumber(const der::Input &value, bool warnings_only,
if (negative) {
errors->AddWarning(kSerialNumberIsNegative);
}
if (value.Length() == 1 && value[0] == 0) {
if (value.size() == 1 && value[0] == 0) {
errors->AddWarning(kSerialNumberIsZero);
}
@@ -280,9 +279,9 @@ bool VerifySerialNumber(const der::Input &value, bool warnings_only,
// Certificate users MUST be able to handle serialNumber values up to 20
// octets. Conforming CAs MUST NOT use serialNumber values longer than 20
// octets.
if (value.Length() > 20) {
if (value.size() > 20) {
errors->Add(error_severity, kSerialNumberLengthOver20,
CreateCertErrorParams1SizeT("length", value.Length()));
CreateCertErrorParams1SizeT("length", value.size()));
return false;
}
@@ -309,8 +308,7 @@ bool ReadUTCOrGeneralizedTime(der::Parser *parser, der::GeneralizedTime *out) {
return false;
}
bool ParseValidity(const der::Input &validity_tlv,
der::GeneralizedTime *not_before,
bool ParseValidity(der::Input validity_tlv, der::GeneralizedTime *not_before,
der::GeneralizedTime *not_after) {
der::Parser parser(validity_tlv);
@@ -348,7 +346,7 @@ bool ParseValidity(const der::Input &validity_tlv,
return true;
}
bool ParseCertificate(const der::Input &certificate_tlv,
bool ParseCertificate(der::Input certificate_tlv,
der::Input *out_tbs_certificate_tlv,
der::Input *out_signature_algorithm_tlv,
der::BitString *out_signature_value,
@@ -423,7 +421,7 @@ bool ParseCertificate(const der::Input &certificate_tlv,
// extensions [3] EXPLICIT Extensions OPTIONAL
// -- If present, version MUST be v3
// }
bool ParseTbsCertificate(const der::Input &tbs_tlv,
bool ParseTbsCertificate(der::Input tbs_tlv,
const ParseCertificateOptions &options,
ParsedTbsCertificate *out, CertErrors *errors) {
// The rest of this function assumes that |errors| is non-null.
@@ -608,7 +606,7 @@ bool ParseTbsCertificate(const der::Input &tbs_tlv,
// -- corresponding to the extension type identified
// -- by extnID
// }
bool ParseExtension(const der::Input &extension_tlv, ParsedExtension *out) {
bool ParseExtension(der::Input extension_tlv, ParsedExtension *out) {
der::Parser parser(extension_tlv);
// Extension ::= SEQUENCE {
@@ -659,7 +657,7 @@ bool ParseExtension(const der::Input &extension_tlv, ParsedExtension *out) {
}
OPENSSL_EXPORT bool ParseExtensions(
const der::Input &extensions_tlv,
der::Input extensions_tlv,
std::map<der::Input, ParsedExtension> *extensions) {
der::Parser parser(extensions_tlv);
@@ -708,7 +706,7 @@ OPENSSL_EXPORT bool ParseExtensions(
}
OPENSSL_EXPORT bool ConsumeExtension(
const der::Input &oid,
der::Input oid,
std::map<der::Input, ParsedExtension> *unconsumed_extensions,
ParsedExtension *extension) {
auto it = unconsumed_extensions->find(oid);
@@ -721,7 +719,7 @@ OPENSSL_EXPORT bool ConsumeExtension(
return true;
}
bool ParseBasicConstraints(const der::Input &basic_constraints_tlv,
bool ParseBasicConstraints(der::Input basic_constraints_tlv,
ParsedBasicConstraints *out) {
der::Parser parser(basic_constraints_tlv);
@@ -780,7 +778,7 @@ bool ParseBasicConstraints(const der::Input &basic_constraints_tlv,
// TODO(crbug.com/1314019): return std::optional<BitString> when converting
// has_key_usage_ and key_usage_ into single std::optional field.
bool ParseKeyUsage(const der::Input &key_usage_tlv, der::BitString *key_usage) {
bool ParseKeyUsage(der::Input key_usage_tlv, der::BitString *key_usage) {
der::Parser parser(key_usage_tlv);
std::optional<der::BitString> key_usage_internal = parser.ReadBitString();
if (!key_usage_internal) {
@@ -805,7 +803,7 @@ bool ParseKeyUsage(const der::Input &key_usage_tlv, der::BitString *key_usage) {
}
bool ParseAuthorityInfoAccess(
const der::Input &authority_info_access_tlv,
der::Input authority_info_access_tlv,
std::vector<AuthorityInfoAccessDescription> *out_access_descriptions) {
der::Parser parser(authority_info_access_tlv);
@@ -853,7 +851,7 @@ bool ParseAuthorityInfoAccess(
}
bool ParseAuthorityInfoAccessURIs(
const der::Input &authority_info_access_tlv,
der::Input authority_info_access_tlv,
std::vector<std::string_view> *out_ca_issuers_uris,
std::vector<std::string_view> *out_ocsp_uris) {
std::vector<AuthorityInfoAccessDescription> access_descriptions;
@@ -896,7 +894,7 @@ ParsedDistributionPoint::ParsedDistributionPoint(
ParsedDistributionPoint::~ParsedDistributionPoint() = default;
bool ParseCrlDistributionPoints(
const der::Input &extension_value,
der::Input extension_value,
std::vector<ParsedDistributionPoint> *distribution_points) {
distribution_points->clear();
@@ -935,7 +933,7 @@ ParsedAuthorityKeyIdentifier &ParsedAuthorityKeyIdentifier::operator=(
ParsedAuthorityKeyIdentifier &&other) = default;
bool ParseAuthorityKeyIdentifier(
const der::Input &extension_value,
der::Input extension_value,
ParsedAuthorityKeyIdentifier *authority_key_identifier) {
// RFC 5280, section 4.2.1.1.
// AuthorityKeyIdentifier ::= SEQUENCE {
@@ -993,7 +991,7 @@ bool ParseAuthorityKeyIdentifier(
return true;
}
bool ParseSubjectKeyIdentifier(const der::Input &extension_value,
bool ParseSubjectKeyIdentifier(der::Input extension_value,
der::Input *subject_key_identifier) {
// SubjectKeyIdentifier ::= KeyIdentifier
//
+15 -15
View File
@@ -56,7 +56,7 @@ struct ParsedTbsCertificate;
// |errors| must be a non-null destination for any errors/warnings. If
// |warnings_only| is set to true, then what would ordinarily be errors are
// instead added as warnings.
[[nodiscard]] OPENSSL_EXPORT bool VerifySerialNumber(const der::Input &value,
[[nodiscard]] OPENSSL_EXPORT bool VerifySerialNumber(der::Input value,
bool warnings_only,
CertErrors *errors);
@@ -81,7 +81,7 @@ struct ParsedTbsCertificate;
//
// Note that upon success it is NOT guaranteed that |*not_before <= *not_after|.
[[nodiscard]] OPENSSL_EXPORT bool ParseValidity(
const der::Input &validity_tlv, der::GeneralizedTime *not_before,
der::Input validity_tlv, der::GeneralizedTime *not_before,
der::GeneralizedTime *not_after);
struct OPENSSL_EXPORT ParseCertificateOptions {
@@ -130,7 +130,7 @@ struct OPENSSL_EXPORT ParseCertificateOptions {
//
// Parsing guarantees that this is a valid BIT STRING.
[[nodiscard]] OPENSSL_EXPORT bool ParseCertificate(
const der::Input &certificate_tlv, der::Input *out_tbs_certificate_tlv,
der::Input certificate_tlv, der::Input *out_tbs_certificate_tlv,
der::Input *out_signature_algorithm_tlv,
der::BitString *out_signature_value, CertErrors *out_errors);
@@ -167,7 +167,7 @@ struct OPENSSL_EXPORT ParseCertificateOptions {
// -- If present, version MUST be v3
// }
[[nodiscard]] OPENSSL_EXPORT bool ParseTbsCertificate(
const der::Input &tbs_tlv, const ParseCertificateOptions &options,
der::Input tbs_tlv, const ParseCertificateOptions &options,
ParsedTbsCertificate *out, CertErrors *errors);
// Represents a "Version" from RFC 5280:
@@ -318,8 +318,8 @@ struct OPENSSL_EXPORT ParsedExtension {
//
// On failure |out| has an undefined state. Some of its fields may have been
// updated during parsing, whereas others may not have been changed.
[[nodiscard]] OPENSSL_EXPORT bool ParseExtension(
const der::Input &extension_tlv, ParsedExtension *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseExtension(der::Input extension_tlv,
ParsedExtension *out);
// From RFC 5280:
//
@@ -431,14 +431,14 @@ inline constexpr uint8_t kMSApplicationPoliciesOid[] = {
// bytes in |extensions_tlv|, so that data must be kept alive.
// On failure |extensions| may be partially written to and should not be used.
[[nodiscard]] OPENSSL_EXPORT bool ParseExtensions(
const der::Input &extensions_tlv,
der::Input extensions_tlv,
std::map<der::Input, ParsedExtension> *extensions);
// Removes the extension with OID |oid| from |unconsumed_extensions| and fills
// |extension| with the matching extension value. If there was no extension
// matching |oid| then returns |false|.
[[nodiscard]] OPENSSL_EXPORT bool ConsumeExtension(
const der::Input &oid,
der::Input oid,
std::map<der::Input, ParsedExtension> *unconsumed_extensions,
ParsedExtension *extension);
@@ -457,7 +457,7 @@ struct ParsedBasicConstraints {
// The maximum allowed value of pathLenConstraints will be whatever can fit
// into a uint8_t.
[[nodiscard]] OPENSSL_EXPORT bool ParseBasicConstraints(
const der::Input &basic_constraints_tlv, ParsedBasicConstraints *out);
der::Input basic_constraints_tlv, ParsedBasicConstraints *out);
// KeyUsageBit contains the index for a particular key usage. The index is
// measured from the most significant bit of a bit string.
@@ -497,7 +497,7 @@ enum KeyUsageBit {
//
// To test if a particular key usage is set, call, e.g.:
// key_usage->AssertsBit(KEY_USAGE_BIT_DIGITAL_SIGNATURE);
[[nodiscard]] OPENSSL_EXPORT bool ParseKeyUsage(const der::Input &key_usage_tlv,
[[nodiscard]] OPENSSL_EXPORT bool ParseKeyUsage(der::Input key_usage_tlv,
der::BitString *key_usage);
struct AuthorityInfoAccessDescription {
@@ -514,7 +514,7 @@ struct AuthorityInfoAccessDescription {
// No validation is performed on the contents of the
// AuthorityInfoAccessDescription fields.
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityInfoAccess(
const der::Input &authority_info_access_tlv,
der::Input authority_info_access_tlv,
std::vector<AuthorityInfoAccessDescription> *out_access_descriptions);
// Parses the Authority Information Access extension defined by RFC 5280,
@@ -536,7 +536,7 @@ struct AuthorityInfoAccessDescription {
// accessLocation types other than uniformResourceIdentifier are silently
// ignored.
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityInfoAccessURIs(
const der::Input &authority_info_access_tlv,
der::Input authority_info_access_tlv,
std::vector<std::string_view> *out_ca_issuers_uris,
std::vector<std::string_view> *out_ocsp_uris);
@@ -572,7 +572,7 @@ struct OPENSSL_EXPORT ParsedDistributionPoint {
// DistributionPoint). Return true on success, and fills |distribution_points|
// with values that reference data in |distribution_points_tlv|.
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlDistributionPoints(
const der::Input &distribution_points_tlv,
der::Input distribution_points_tlv,
std::vector<ParsedDistributionPoint> *distribution_points);
// Represents the AuthorityKeyIdentifier extension defined by RFC 5280 section
@@ -608,14 +608,14 @@ struct OPENSSL_EXPORT ParsedAuthorityKeyIdentifier {
// in |extension_value|. On failure the state of |authority_key_identifier| is
// not guaranteed.
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityKeyIdentifier(
const der::Input &extension_value,
der::Input extension_value,
ParsedAuthorityKeyIdentifier *authority_key_identifier);
// Parses the value of a subjectKeyIdentifier extension. Returns true on
// success and |subject_key_identifier| references data in |extension_value|.
// On failure the state of |subject_key_identifier| is not guaranteed.
[[nodiscard]] OPENSSL_EXPORT bool ParseSubjectKeyIdentifier(
const der::Input &extension_value, der::Input *subject_key_identifier);
der::Input extension_value, der::Input *subject_key_identifier);
} // namespace bssl
+7 -12
View File
@@ -19,7 +19,7 @@ namespace {
// string on error.
std::string OidToString(der::Input oid) {
CBS cbs;
CBS_init(&cbs, oid.UnsafeData(), oid.Length());
CBS_init(&cbs, oid.data(), oid.size());
bssl::UniquePtr<char> text(CBS_asn1_oid_to_text(&cbs));
if (!text) {
return std::string();
@@ -104,8 +104,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
if (type_string.empty()) {
return false;
}
value_string =
"#" + bssl::string_util::HexEncode(value.UnsafeData(), value.Length());
value_string = "#" + bssl::string_util::HexEncode(value);
}
if (value_string.empty()) {
@@ -116,7 +115,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
bool nonprintable = false;
for (unsigned int i = 0; i < unescaped.length(); ++i) {
unsigned char c = static_cast<unsigned char>(unescaped[i]);
uint8_t c = static_cast<uint8_t>(unescaped[i]);
if (i == 0 && c == '#') {
value_string += "\\#";
} else if (i == 0 && c == ' ') {
@@ -129,11 +128,8 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
value_string += c;
} else if (c < 32 || c > 126) {
nonprintable = true;
std::string h;
h += c;
value_string +=
"\\" + bssl::string_util::HexEncode(
reinterpret_cast<const uint8_t *>(h.data()), h.length());
"\\" + bssl::string_util::HexEncode(MakeConstSpan(&c, 1));
} else {
value_string += c;
}
@@ -142,8 +138,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
// If we have non-printable characters in a TeletexString, we hex encode
// since we don't handle Teletex control codes.
if (nonprintable && value_tag == der::kTeletexString) {
value_string = "#" + bssl::string_util::HexEncode(value.UnsafeData(),
value.Length());
value_string = "#" + bssl::string_util::HexEncode(value);
}
}
@@ -184,7 +179,7 @@ bool ReadRdn(der::Parser *parser, RelativeDistinguishedName *out) {
return out->size() != 0;
}
bool ParseName(const der::Input &name_tlv, RDNSequence *out) {
bool ParseName(der::Input name_tlv, RDNSequence *out) {
der::Parser name_parser(name_tlv);
der::Input name_value;
if (!name_parser.ReadTag(der::kSequence, &name_value)) {
@@ -193,7 +188,7 @@ bool ParseName(const der::Input &name_tlv, RDNSequence *out) {
return ParseNameValue(name_value, out);
}
bool ParseNameValue(const der::Input &name_value, RDNSequence *out) {
bool ParseNameValue(der::Input name_value, RDNSequence *out) {
der::Parser rdn_sequence_parser(name_value);
while (rdn_sequence_parser.HasMore()) {
der::Parser rdn_parser;
+2 -2
View File
@@ -140,11 +140,11 @@ typedef std::vector<RelativeDistinguishedName> RDNSequence;
// Parses a DER-encoded "Name" as specified by 5280. Returns true on success
// and sets the results in |out|.
[[nodiscard]] OPENSSL_EXPORT bool ParseName(const der::Input &name_tlv,
[[nodiscard]] OPENSSL_EXPORT bool ParseName(der::Input name_tlv,
RDNSequence *out);
// Parses a DER-encoded "Name" value (without the sequence tag & length) as
// specified by 5280. Returns true on success and sets the results in |out|.
[[nodiscard]] OPENSSL_EXPORT bool ParseNameValue(const der::Input &name_value,
[[nodiscard]] OPENSSL_EXPORT bool ParseNameValue(der::Input name_value,
RDNSequence *out);
// Formats a RDNSequence |rdn_sequence| per RFC2253 as an ASCII string and
+31 -32
View File
@@ -16,11 +16,11 @@ namespace bssl::der {
namespace {
bool ParseBoolInternal(const Input &in, bool *out, bool relaxed) {
bool ParseBoolInternal(Input in, bool *out, bool relaxed) {
// According to ITU-T X.690 section 8.2, a bool is encoded as a single octet
// where the octet of all zeroes is FALSE and a non-zero value for the octet
// is TRUE.
if (in.Length() != 1) {
if (in.size() != 1) {
return false;
}
ByteReader data(in);
@@ -128,28 +128,28 @@ bool ValidateGeneralizedTime(const GeneralizedTime &time) {
// Returns the number of bytes of numeric precision in a DER encoded INTEGER
// value. |in| must be a valid DER encoding of an INTEGER for this to work.
//
// Normally the precision of the number is exactly in.Length(). However when
// Normally the precision of the number is exactly in.size(). However when
// encoding positive numbers using DER it is possible to have a leading zero
// (to prevent number from being interpreted as negative).
//
// For instance a 160-bit positive number might take 21 bytes to encode. This
// function will return 20 in such a case.
size_t GetUnsignedIntegerLength(const Input &in) {
size_t GetUnsignedIntegerLength(Input in) {
der::ByteReader reader(in);
uint8_t first_byte;
if (!reader.ReadByte(&first_byte)) {
return 0; // Not valid DER as |in| was empty.
}
if (first_byte == 0 && in.Length() > 1) {
return in.Length() - 1;
if (first_byte == 0 && in.size() > 1) {
return in.size() - 1;
}
return in.Length();
return in.size();
}
} // namespace
bool ParseBool(const Input &in, bool *out) {
bool ParseBool(Input in, bool *out) {
return ParseBoolInternal(in, out, false /* relaxed */);
}
@@ -157,7 +157,7 @@ bool ParseBool(const Input &in, bool *out) {
// have either all bits zero (false) or all bits one (true). To support
// malformed certs, we recognized the BER encoding instead of failing to
// parse.
bool ParseBoolRelaxed(const Input &in, bool *out) {
bool ParseBoolRelaxed(Input in, bool *out) {
return ParseBoolInternal(in, out, true /* relaxed */);
}
@@ -165,9 +165,9 @@ bool ParseBoolRelaxed(const Input &in, bool *out) {
// in the smallest number of octets. If the encoding consists of more than
// one octet, then the bits of the first octet and the most significant bit
// of the second octet must not be all zeroes or all ones.
bool IsValidInteger(const Input &in, bool *negative) {
bool IsValidInteger(Input in, bool *negative) {
CBS cbs;
CBS_init(&cbs, in.UnsafeData(), in.Length());
CBS_init(&cbs, in.data(), in.size());
int negative_int;
if (!CBS_is_valid_asn1_integer(&cbs, &negative_int)) {
return false;
@@ -177,7 +177,7 @@ bool IsValidInteger(const Input &in, bool *negative) {
return true;
}
bool ParseUint64(const Input &in, uint64_t *out) {
bool ParseUint64(Input in, uint64_t *out) {
// Reject non-minimally encoded numbers and negative numbers.
bool negative;
if (!IsValidInteger(in, &negative) || negative) {
@@ -201,7 +201,7 @@ bool ParseUint64(const Input &in, uint64_t *out) {
return true;
}
bool ParseUint8(const Input &in, uint8_t *out) {
bool ParseUint8(Input in, uint8_t *out) {
// TODO(eroman): Implement this more directly.
uint64_t value;
if (!ParseUint64(in, &value)) {
@@ -216,13 +216,12 @@ bool ParseUint8(const Input &in, uint8_t *out) {
return true;
}
BitString::BitString(const Input &bytes, uint8_t unused_bits)
BitString::BitString(Input bytes, uint8_t unused_bits)
: bytes_(bytes), unused_bits_(unused_bits) {
BSSL_CHECK(unused_bits < 8);
BSSL_CHECK(unused_bits == 0 || bytes.Length() != 0);
BSSL_CHECK(unused_bits == 0 || !bytes.empty());
// The unused bits must be zero.
BSSL_CHECK(bytes.Length() == 0 ||
(bytes[bytes.Length() - 1] & ((1u << unused_bits) - 1)) == 0);
BSSL_CHECK(bytes.empty() || (bytes.back() & ((1u << unused_bits) - 1)) == 0);
}
bool BitString::AssertsBit(size_t bit_index) const {
@@ -231,7 +230,7 @@ bool BitString::AssertsBit(size_t bit_index) const {
// If the bit is outside of the bitstring, by definition it is not
// asserted.
if (byte_index >= bytes_.Length()) {
if (byte_index >= bytes_.size()) {
return false;
}
@@ -247,7 +246,7 @@ bool BitString::AssertsBit(size_t bit_index) const {
return 0 != (byte & (1 << bit_index_in_byte));
}
std::optional<BitString> ParseBitString(const Input &in) {
std::optional<BitString> ParseBitString(Input in) {
ByteReader reader(in);
// From ITU-T X.690, section 8.6.2.2 (applies to BER, CER, DER):
@@ -274,10 +273,10 @@ std::optional<BitString> ParseBitString(const Input &in) {
//
// If the bitstring is empty, there shall be no subsequent octets,
// and the initial octet shall be zero.
if (bytes.Length() == 0) {
if (bytes.empty()) {
return std::nullopt;
}
uint8_t last_byte = bytes[bytes.Length() - 1];
uint8_t last_byte = bytes.back();
// From ITU-T X.690, section 11.2.1 (applies to CER and DER, but not BER):
//
@@ -314,7 +313,7 @@ bool operator>=(const GeneralizedTime &lhs, const GeneralizedTime &rhs) {
return !(lhs < rhs);
}
bool ParseUTCTime(const Input &in, GeneralizedTime *value) {
bool ParseUTCTime(Input in, GeneralizedTime *value) {
ByteReader reader(in);
GeneralizedTime time;
if (!DecimalStringToUint(reader, 2, &time.year) ||
@@ -341,7 +340,7 @@ bool ParseUTCTime(const Input &in, GeneralizedTime *value) {
return true;
}
bool ParseGeneralizedTime(const Input &in, GeneralizedTime *value) {
bool ParseGeneralizedTime(Input in, GeneralizedTime *value) {
ByteReader reader(in);
GeneralizedTime time;
if (!DecimalStringToUint(reader, 4, &time.year) ||
@@ -403,14 +402,14 @@ bool ParsePrintableString(Input in, std::string *out) {
bool ParseTeletexStringAsLatin1(Input in, std::string *out) {
out->clear();
// Convert from Latin-1 to UTF-8.
size_t utf8_length = in.Length();
for (size_t i = 0; i < in.Length(); i++) {
size_t utf8_length = in.size();
for (size_t i = 0; i < in.size(); i++) {
if (in[i] > 0x7f) {
utf8_length++;
}
}
out->reserve(utf8_length);
for (size_t i = 0; i < in.Length(); i++) {
for (size_t i = 0; i < in.size(); i++) {
uint8_t u = in[i];
if (u <= 0x7f) {
out->push_back(u);
@@ -424,14 +423,14 @@ bool ParseTeletexStringAsLatin1(Input in, std::string *out) {
}
bool ParseUniversalString(Input in, std::string *out) {
if (in.Length() % 4 != 0) {
if (in.size() % 4 != 0) {
return false;
}
CBS cbs;
CBS_init(&cbs, in.UnsafeData(), in.Length());
CBS_init(&cbs, in.data(), in.size());
bssl::ScopedCBB cbb;
if (!CBB_init(cbb.get(), in.Length())) {
if (!CBB_init(cbb.get(), in.size())) {
return false;
}
@@ -448,14 +447,14 @@ bool ParseUniversalString(Input in, std::string *out) {
}
bool ParseBmpString(Input in, std::string *out) {
if (in.Length() % 2 != 0) {
if (in.size() % 2 != 0) {
return false;
}
CBS cbs;
CBS_init(&cbs, in.UnsafeData(), in.Length());
CBS_init(&cbs, in.data(), in.size());
bssl::ScopedCBB cbb;
if (!CBB_init(cbb.get(), in.Length())) {
if (!CBB_init(cbb.get(), in.size())) {
return false;
}
+10 -13
View File
@@ -18,11 +18,11 @@ namespace bssl::der {
// Reads a DER-encoded ASN.1 BOOLEAN value from |in| and puts the resulting
// value in |out|. Returns whether the encoded value could successfully be
// read.
[[nodiscard]] OPENSSL_EXPORT bool ParseBool(const Input &in, bool *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseBool(Input in, bool *out);
// Like ParseBool, except it is more relaxed in what inputs it accepts: Any
// value that is a valid BER encoding will be parsed successfully.
[[nodiscard]] OPENSSL_EXPORT bool ParseBoolRelaxed(const Input &in, bool *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseBoolRelaxed(Input in, bool *out);
// Checks the validity of a DER-encoded ASN.1 INTEGER value from |in|, and
// determines the sign of the number. Returns true on success and
@@ -32,8 +32,7 @@ namespace bssl::der {
// in: The value portion of an INTEGER.
// negative: Out parameter that is set to true if the number is negative
// and false otherwise (zero is non-negative).
[[nodiscard]] OPENSSL_EXPORT bool IsValidInteger(const Input &in,
bool *negative);
[[nodiscard]] OPENSSL_EXPORT bool IsValidInteger(Input in, bool *negative);
// Reads a DER-encoded ASN.1 INTEGER value from |in| and puts the resulting
// value in |out|. ASN.1 INTEGERs are arbitrary precision; this function is
@@ -41,10 +40,10 @@ namespace bssl::der {
// and is between 0 and 2^64-1. This function returns false if the value is too
// big to fit in a uint64_t, is negative, or if there is an error reading the
// integer.
[[nodiscard]] OPENSSL_EXPORT bool ParseUint64(const Input &in, uint64_t *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseUint64(Input in, uint64_t *out);
// Same as ParseUint64() but for a uint8_t.
[[nodiscard]] OPENSSL_EXPORT bool ParseUint8(const Input &in, uint8_t *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseUint8(Input in, uint8_t *out);
// The BitString class is a helper for representing a valid parsed BIT STRING.
//
@@ -59,9 +58,9 @@ class OPENSSL_EXPORT BitString {
// |unused_bits| represents the number of bits in the last octet of |bytes|,
// starting from the least significant bit, that are unused. It MUST be < 8.
// And if bytes is empty, then it MUST be 0.
BitString(const Input &bytes, uint8_t unused_bits);
BitString(Input bytes, uint8_t unused_bits);
const Input &bytes() const { return bytes_; }
Input bytes() const { return bytes_; }
uint8_t unused_bits() const { return unused_bits_; }
// Returns true if the bit string contains 1 at the specified position.
@@ -83,8 +82,7 @@ class OPENSSL_EXPORT BitString {
// resulting octet string and number of unused bits.
//
// On failure, returns std::nullopt.
[[nodiscard]] OPENSSL_EXPORT std::optional<BitString> ParseBitString(
const Input &in);
[[nodiscard]] OPENSSL_EXPORT std::optional<BitString> ParseBitString(Input in);
struct OPENSSL_EXPORT GeneralizedTime {
uint16_t year;
@@ -109,15 +107,14 @@ OPENSSL_EXPORT bool operator>=(const GeneralizedTime &lhs,
// Reads a DER-encoded ASN.1 UTCTime value from |in| and puts the resulting
// value in |out|, returning true if the UTCTime could be parsed successfully.
[[nodiscard]] OPENSSL_EXPORT bool ParseUTCTime(const Input &in,
GeneralizedTime *out);
[[nodiscard]] OPENSSL_EXPORT bool ParseUTCTime(Input in, GeneralizedTime *out);
// Reads a DER-encoded ASN.1 GeneralizedTime value from |in| and puts the
// resulting value in |out|, returning true if the GeneralizedTime could
// be parsed successfully. This function is even more restrictive than the
// DER rules - it follows the rules from RFC5280, which does not allow for
// fractional seconds.
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralizedTime(const Input &in,
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralizedTime(Input in,
GeneralizedTime *out);
// Reads a DER-encoded ASN.1 IA5String value from |in| and stores the result in
+2 -2
View File
@@ -317,7 +317,7 @@ TEST(ParseValuesTest, ParseBitStringEmptyNoUnusedBits) {
ASSERT_TRUE(bit_string.has_value());
EXPECT_EQ(0u, bit_string->unused_bits());
EXPECT_EQ(0u, bit_string->bytes().Length());
EXPECT_EQ(0u, bit_string->bytes().size());
EXPECT_FALSE(bit_string->AssertsBit(0));
EXPECT_FALSE(bit_string->AssertsBit(1));
@@ -349,7 +349,7 @@ TEST(ParseValuesTest, ParseBitStringSevenOneBits) {
ASSERT_TRUE(bit_string.has_value());
EXPECT_EQ(1u, bit_string->unused_bits());
EXPECT_EQ(1u, bit_string->bytes().Length());
EXPECT_EQ(1u, bit_string->bytes().size());
EXPECT_EQ(0xFE, bit_string->bytes()[0]);
EXPECT_TRUE(bit_string->AssertsBit(0));
+3 -3
View File
@@ -49,14 +49,14 @@ DEFINE_CERT_ERROR_ID(kFailedParsingAuthorityKeyIdentifier,
DEFINE_CERT_ERROR_ID(kFailedParsingSubjectKeyIdentifier,
"Failed parsing subject key identifier");
[[nodiscard]] bool GetSequenceValue(const der::Input &tlv, der::Input *value) {
[[nodiscard]] bool GetSequenceValue(der::Input tlv, der::Input *value) {
der::Parser parser(tlv);
return parser.ReadTag(der::kSequence, value) && !parser.HasMore();
}
} // namespace
bool ParsedCertificate::GetExtension(const der::Input &extension_oid,
bool ParsedCertificate::GetExtension(der::Input extension_oid,
ParsedExtension *parsed_extension) const {
if (!tbs_.extensions_tlv) {
return false;
@@ -183,7 +183,7 @@ std::shared_ptr<const ParsedCertificate> ParsedCertificate::Create(
// extension (e.g., a key bound only to an email address or URI), then the
// subject name MUST be an empty sequence and the subjectAltName extension
// MUST be critical.
if (subject_value.Length() == 0 &&
if (subject_value.empty() &&
!result->subject_alt_names_extension_.critical) {
errors->AddError(kSubjectAltNameNotCritical);
return nullptr;
+4 -4
View File
@@ -76,15 +76,15 @@ class OPENSSL_EXPORT ParsedCertificate {
ParsedCertificate &operator=(const ParsedCertificate &) = delete;
// Returns the DER-encoded certificate data for this cert.
const der::Input &der_cert() const { return cert_; }
der::Input der_cert() const { return cert_; }
// Returns the CRYPTO_BUFFER backing this object.
CRYPTO_BUFFER *cert_buffer() const { return cert_data_.get(); }
// Accessors for raw fields of the Certificate.
const der::Input &tbs_certificate_tlv() const { return tbs_certificate_tlv_; }
der::Input tbs_certificate_tlv() const { return tbs_certificate_tlv_; }
const der::Input &signature_algorithm_tlv() const {
der::Input signature_algorithm_tlv() const {
return signature_algorithm_tlv_;
}
@@ -245,7 +245,7 @@ class OPENSSL_EXPORT ParsedCertificate {
// Gets the value for extension matching |extension_oid|. Returns false if the
// extension is not present.
bool GetExtension(const der::Input &extension_oid,
bool GetExtension(der::Input extension_oid,
ParsedExtension *parsed_extension) const;
private:
+3 -3
View File
@@ -232,7 +232,7 @@ TEST(ParsedCertificateTest, ExtendedKeyUsage) {
ASSERT_TRUE(cert->GetExtension(der::Input(kExtKeyUsageOid), &extension));
EXPECT_FALSE(extension.critical);
EXPECT_EQ(45u, extension.value.Length());
EXPECT_EQ(45u, extension.value.size());
EXPECT_TRUE(cert->has_extended_key_usage());
EXPECT_EQ(4u, cert->extended_key_usage().size());
@@ -268,7 +268,7 @@ TEST(ParsedCertificateTest, Policies) {
cert->GetExtension(der::Input(kCertificatePoliciesOid), &extension));
EXPECT_FALSE(extension.critical);
EXPECT_EQ(95u, extension.value.Length());
EXPECT_EQ(95u, extension.value.size());
EXPECT_TRUE(cert->has_policy_oids());
EXPECT_EQ(2u, cert->policy_oids().size());
@@ -320,7 +320,7 @@ TEST(ParsedCertificateTest, ExtensionsReal) {
cert->GetExtension(der::Input(kCertificatePoliciesOid), &extension));
EXPECT_FALSE(extension.critical);
EXPECT_EQ(16u, extension.value.Length());
EXPECT_EQ(16u, extension.value.size());
// TODO(eroman): Verify the other extensions' values.
}
+1 -3
View File
@@ -11,9 +11,7 @@ namespace bssl::der {
Parser::Parser() { CBS_init(&cbs_, nullptr, 0); }
Parser::Parser(const Input &input) {
CBS_init(&cbs_, input.UnsafeData(), input.Length());
}
Parser::Parser(Input input) { CBS_init(&cbs_, input.data(), input.size()); }
bool Parser::PeekTagAndValue(Tag *tag, Input *out) {
CBS peeker = cbs_;
+2 -2
View File
@@ -72,7 +72,7 @@ struct GeneralizedTime;
// following code shows an example of how to parse the quux field from the
// encoded data.
//
// bool ReadQuux(const Input& encoded_value, Input* quux_out) {
// bool ReadQuux(Input encoded_value, Input* quux_out) {
// Parser parser(encoded_value);
// Parser foo_parser;
// if (!parser.ReadSequence(&foo_parser))
@@ -93,7 +93,7 @@ class OPENSSL_EXPORT Parser {
// Creates a parser to parse over the data represented by input. This class
// assumes that the underlying data will not change over the lifetime of
// the Parser object.
explicit Parser(const Input &input);
explicit Parser(Input input);
Parser(const Parser &) = default;
Parser &operator=(const Parser &) = default;
+1 -1
View File
@@ -347,7 +347,7 @@ TEST(ParserTest, ReadBitString) {
EXPECT_FALSE(parser.HasMore());
EXPECT_EQ(1u, bit_string->unused_bits());
ASSERT_EQ(2u, bit_string->bytes().Length());
ASSERT_EQ(2u, bit_string->bytes().size());
EXPECT_EQ(0xAA, bit_string->bytes()[0]);
EXPECT_EQ(0xBE, bit_string->bytes()[1]);
}
File diff suppressed because one or more lines are too long
+6 -4
View File
@@ -32,8 +32,8 @@ using CertIssuerSources = std::vector<CertIssuerSource *>;
// Returns a hex-encoded sha256 of the DER-encoding of |cert|.
std::string FingerPrintParsedCertificate(const bssl::ParsedCertificate *cert) {
uint8_t digest[SHA256_DIGEST_LENGTH];
SHA256(cert->der_cert().UnsafeData(), cert->der_cert().Length(), digest);
return bssl::string_util::HexEncode(digest, sizeof(digest));
SHA256(cert->der_cert().data(), cert->der_cert().size(), digest);
return bssl::string_util::HexEncode(digest);
}
// TODO(mattm): decide how much debug logging to keep.
@@ -621,7 +621,8 @@ bool CertPathIter::GetNextPath(ParsedCertificateList *out_certs,
// trusted root.
if (!cur_path_.Empty()) {
if (delegate->IsDebugLogEnabled()) {
delegate->DebugLog("Issuer is a trust leaf, considering as UNSPECIFIED");
delegate->DebugLog(
"Issuer is a trust leaf, considering as UNSPECIFIED");
}
next_issuer_.trust = CertificateTrust::ForUnspecified();
}
@@ -692,7 +693,8 @@ bool CertPathIter::GetNextPath(ParsedCertificateList *out_certs,
std::move(next_issuer_.cert), &cert_issuer_sources_, trust_store_));
next_issuer_ = IssuerEntry();
if (delegate->IsDebugLogEnabled()) {
delegate->DebugLog("CertPathIter cur_path_ =\n" + cur_path_.PathDebugString());
delegate->DebugLog("CertPathIter cur_path_ =\n" +
cur_path_.PathDebugString());
}
// Continue descending the tree.
continue;
+1 -2
View File
@@ -238,8 +238,7 @@ class PathBuilderPkitsTestDelegate {
const bssl::CertPathBuilderResultPath *result_path =
result.paths[i].get();
msg << "path " << i << " errors:\n"
<< result_path->errors.ToDebugString(result_path->certs)
<< "\n";
<< result_path->errors.ToDebugString(result_path->certs) << "\n";
}
ASSERT_EQ(info.should_validate, result.HasValidPath()) << msg;
}
+9 -11
View File
@@ -1362,9 +1362,7 @@ TEST_F(PathBuilderKeyRolloverTest, ExplorePathsWithPathLimit) {
{0, 4}, // No path limit. Three valid, one partial path should be built
{1, 1}, // One valid path
{2, 3}, // Two valid, one partial
{3, 4},
{4, 4},
{5, 4},
{3, 4}, {4, 4}, {5, 4},
};
// Trust both old and new roots.
@@ -1523,9 +1521,9 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateIntermediates) {
// Create a separate copy of oldintermediate.
std::shared_ptr<const ParsedCertificate> oldintermediate_dupe(
ParsedCertificate::Create(
bssl::UniquePtr<CRYPTO_BUFFER>(CRYPTO_BUFFER_new(
oldintermediate_->der_cert().UnsafeData(),
oldintermediate_->der_cert().Length(), nullptr)),
bssl::UniquePtr<CRYPTO_BUFFER>(
CRYPTO_BUFFER_new(oldintermediate_->der_cert().data(),
oldintermediate_->der_cert().size(), nullptr)),
{}, nullptr));
// Only newroot is a trusted root.
@@ -1590,8 +1588,8 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateIntermediateAndRoot) {
std::shared_ptr<const ParsedCertificate> newroot_dupe(
ParsedCertificate::Create(
bssl::UniquePtr<CRYPTO_BUFFER>(
CRYPTO_BUFFER_new(newroot_->der_cert().UnsafeData(),
newroot_->der_cert().Length(), nullptr)),
CRYPTO_BUFFER_new(newroot_->der_cert().data(),
newroot_->der_cert().size(), nullptr)),
{}, nullptr));
// Only newroot is a trusted root.
@@ -1784,9 +1782,9 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateAsyncIntermediates) {
std::shared_ptr<const ParsedCertificate> oldintermediate_dupe(
ParsedCertificate::Create(
bssl::UniquePtr<CRYPTO_BUFFER>(CRYPTO_BUFFER_new(
oldintermediate_->der_cert().UnsafeData(),
oldintermediate_->der_cert().Length(), nullptr)),
bssl::UniquePtr<CRYPTO_BUFFER>(
CRYPTO_BUFFER_new(oldintermediate_->der_cert().data(),
oldintermediate_->der_cert().size(), nullptr)),
{}, nullptr));
EXPECT_CALL(*target_issuers_req, GetNext(_))
+13 -19
View File
@@ -122,13 +122,8 @@ const uint8_t kOidRsaSsaPss[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
0x0d, 0x01, 0x01, 0x08};
// Returns true if |input| is empty.
[[nodiscard]] bool IsEmpty(const der::Input &input) {
return input.Length() == 0;
}
// Returns true if the entirety of the input is a NULL value.
[[nodiscard]] bool IsNull(const der::Input &input) {
[[nodiscard]] bool IsNull(der::Input input) {
der::Parser parser(input);
der::Input null_value;
if (!parser.ReadTag(der::kNull, &null_value)) {
@@ -136,7 +131,7 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
}
// NULL values are TLV encoded; the value is expected to be empty.
if (!IsEmpty(null_value)) {
if (!null_value.empty()) {
return false;
}
@@ -144,8 +139,8 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
return !parser.HasMore();
}
[[nodiscard]] bool IsNullOrEmpty(const der::Input &input) {
return IsNull(input) || IsEmpty(input);
[[nodiscard]] bool IsNullOrEmpty(der::Input input) {
return IsNull(input) || input.empty();
}
// Parses a MaskGenAlgorithm as defined by RFC 5912:
@@ -215,7 +210,7 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
// Note also that DER encoding (ITU-T X.690 section 11.5) prohibits
// specifying default values explicitly. The parameter should instead be
// omitted to indicate a default value.
std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input &params) {
std::optional<SignatureAlgorithm> ParseRsaPss(der::Input params) {
der::Parser parser(params);
der::Parser params_parser;
if (!parser.ReadSequence(&params_parser)) {
@@ -273,7 +268,7 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input &params) {
} // namespace
[[nodiscard]] bool ParseAlgorithmIdentifier(const der::Input &input,
[[nodiscard]] bool ParseAlgorithmIdentifier(der::Input input,
der::Input *algorithm,
der::Input *parameters) {
der::Parser parser(input);
@@ -308,10 +303,9 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input &params) {
return !algorithm_identifier_parser.HasMore();
}
[[nodiscard]] bool ParseHashAlgorithm(const der::Input &input,
DigestAlgorithm *out) {
[[nodiscard]] bool ParseHashAlgorithm(der::Input input, DigestAlgorithm *out) {
CBS cbs;
CBS_init(&cbs, input.UnsafeData(), input.Length());
CBS_init(&cbs, input.data(), input.size());
const EVP_MD *md = EVP_parse_digest_algorithm(&cbs);
if (md == EVP_sha1()) {
@@ -332,7 +326,7 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input &params) {
}
std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
const der::Input &algorithm_identifier) {
der::Input algorithm_identifier) {
der::Input oid;
der::Input params;
if (!ParseAlgorithmIdentifier(algorithm_identifier, &oid, &params)) {
@@ -365,16 +359,16 @@ std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
// RFC 5912 requires that the parameters for ECDSA algorithms be absent
// ("PARAMS TYPE NULL ARE absent"):
if (oid == der::Input(kOidEcdsaWithSha1) && IsEmpty(params)) {
if (oid == der::Input(kOidEcdsaWithSha1) && params.empty()) {
return SignatureAlgorithm::kEcdsaSha1;
}
if (oid == der::Input(kOidEcdsaWithSha256) && IsEmpty(params)) {
if (oid == der::Input(kOidEcdsaWithSha256) && params.empty()) {
return SignatureAlgorithm::kEcdsaSha256;
}
if (oid == der::Input(kOidEcdsaWithSha384) && IsEmpty(params)) {
if (oid == der::Input(kOidEcdsaWithSha384) && params.empty()) {
return SignatureAlgorithm::kEcdsaSha384;
}
if (oid == der::Input(kOidEcdsaWithSha512) && IsEmpty(params)) {
if (oid == der::Input(kOidEcdsaWithSha512) && params.empty()) {
return SignatureAlgorithm::kEcdsaSha512;
}
+3 -4
View File
@@ -54,7 +54,7 @@ enum class SignatureAlgorithm {
// algorithm OBJECT IDENTIFIER,
// parameters ANY DEFINED BY algorithm OPTIONAL }
[[nodiscard]] OPENSSL_EXPORT bool ParseAlgorithmIdentifier(
const der::Input &input, der::Input *algorithm, der::Input *parameters);
der::Input input, der::Input *algorithm, der::Input *parameters);
// Parses a HashAlgorithm as defined by RFC 5912:
//
@@ -68,14 +68,13 @@ enum class SignatureAlgorithm {
// { IDENTIFIER id-sha384 PARAMS TYPE NULL ARE preferredPresent } |
// { IDENTIFIER id-sha512 PARAMS TYPE NULL ARE preferredPresent }
// }
[[nodiscard]] bool ParseHashAlgorithm(const der::Input &input,
DigestAlgorithm *out);
[[nodiscard]] bool ParseHashAlgorithm(der::Input input, DigestAlgorithm *out);
// Parses an AlgorithmIdentifier into a signature algorithm and returns it, or
// returns `std::nullopt` if `algorithm_identifer` either cannot be parsed or
// is not a recognized signature algorithm.
OPENSSL_EXPORT std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
const der::Input &algorithm_identifier);
der::Input algorithm_identifier);
// Returns the hash to be used with the tls-server-end-point channel binding
// (RFC 5929) or `std::nullopt`, if not supported for this signature algorithm.
+3 -3
View File
@@ -71,11 +71,11 @@ bool StartsWith(std::string_view str, std::string_view prefix) {
return prefix.size() <= str.size() && prefix == str.substr(0, prefix.size());
}
std::string HexEncode(const uint8_t *data, size_t length) {
std::string HexEncode(Span<const uint8_t> data) {
std::ostringstream out;
for (size_t i = 0; i < length; i++) {
for (uint8_t b : data) {
out << std::hex << std::setfill('0') << std::setw(2) << std::uppercase
<< int{data[i]};
<< int{b};
}
return out.str();
}
+3 -2
View File
@@ -10,6 +10,7 @@
#include <vector>
#include <openssl/base.h>
#include <openssl/span.h>
namespace bssl::string_util {
@@ -44,8 +45,8 @@ OPENSSL_EXPORT bool StartsWith(std::string_view str, std::string_view prefix);
// Compares |str1| and |suffix|. Returns true if |str1| ends with |suffix|.
OPENSSL_EXPORT bool EndsWith(std::string_view str, std::string_view suffix);
// Returns a hexadecimal string encoding |data| of length |length|.
OPENSSL_EXPORT std::string HexEncode(const uint8_t *data, size_t length);
// Returns a hexadecimal string encoding |data|.
OPENSSL_EXPORT std::string HexEncode(Span<const uint8_t> data);
// Returns a decimal string representation of |i|.
OPENSSL_EXPORT std::string NumberToDecimalString(int i);
+2 -2
View File
@@ -99,10 +99,10 @@ TEST(StringUtilTest, StartsWithNoCase) {
}
TEST(StringUtilTest, HexEncode) {
std::string hex(bssl::string_util::HexEncode(nullptr, 0));
std::string hex(bssl::string_util::HexEncode({}));
EXPECT_EQ(hex.length(), 0U);
uint8_t bytes[] = {0x01, 0xff, 0x02, 0xfe, 0x03, 0x80, 0x81};
hex = bssl::string_util::HexEncode(bytes, sizeof(bytes));
hex = bssl::string_util::HexEncode(bytes);
EXPECT_EQ(hex, "01FF02FE038081");
}
+6 -7
View File
@@ -47,11 +47,10 @@ bool GetValue(std::string_view prefix, std::string_view line,
// hex-encoded string on error.
std::string OidToString(der::Input oid) {
CBS cbs;
CBS_init(&cbs, oid.UnsafeData(), oid.Length());
CBS_init(&cbs, oid.data(), oid.size());
bssl::UniquePtr<char> text(CBS_asn1_oid_to_text(&cbs));
if (!text) {
return "invalid:" +
bssl::string_util::HexEncode(oid.UnsafeData(), oid.Length());
return "invalid:" + bssl::string_util::HexEncode(oid);
}
return text.get();
}
@@ -130,14 +129,14 @@ std::string GetTestRoot(void) {
namespace der {
void PrintTo(const Input &data, ::std::ostream *os) {
void PrintTo(Input data, ::std::ostream *os) {
size_t len;
if (!EVP_EncodedLength(&len, data.Length())) {
if (!EVP_EncodedLength(&len, data.size())) {
*os << "[]";
return;
}
std::vector<uint8_t> encoded(len);
len = EVP_EncodeBlock(encoded.data(), data.UnsafeData(), data.Length());
len = EVP_EncodeBlock(encoded.data(), data.data(), data.size());
// Skip the trailing \0.
std::string b64_encoded(encoded.begin(), encoded.begin() + len);
*os << "[" << b64_encoded << "]";
@@ -507,7 +506,7 @@ void VerifyUserConstrainedPolicySet(
const std::set<der::Input> &actual_user_constrained_policy_set,
const std::string &errors_file_path) {
std::set<std::string> actual_user_constrained_policy_str_set;
for (const der::Input &der_oid : actual_user_constrained_policy_set) {
for (der::Input der_oid : actual_user_constrained_policy_set) {
actual_user_constrained_policy_str_set.insert(OidToString(der_oid));
}
if (expected_user_constrained_policy_str_set !=
+1 -1
View File
@@ -24,7 +24,7 @@ namespace bssl {
namespace der {
// This function is used by GTest to support EXPECT_EQ() for der::Input.
void PrintTo(const Input &data, ::std::ostream *os);
void PrintTo(Input data, ::std::ostream *os);
} // namespace der
+1 -1
View File
@@ -5,8 +5,8 @@
#ifndef BSSL_PKI_TRUST_STORE_IN_MEMORY_H_
#define BSSL_PKI_TRUST_STORE_IN_MEMORY_H_
#include <unordered_map>
#include <set>
#include <unordered_map>
#include <openssl/base.h>
+5 -5
View File
@@ -150,8 +150,8 @@ void VerifyTimeValidity(const ParsedCertificate &cert,
// compatibility sake.
bool VerifySignatureAlgorithmsMatch(const ParsedCertificate &cert,
CertErrors *errors) {
const der::Input &alg1_tlv = cert.signature_algorithm_tlv();
const der::Input &alg2_tlv = cert.tbs().signature_algorithm_tlv;
der::Input alg1_tlv = cert.signature_algorithm_tlv();
der::Input alg2_tlv = cert.tbs().signature_algorithm_tlv;
// Ensure that the two DER-encoded signature algorithms are byte-for-byte
// equal.
@@ -690,7 +690,7 @@ class PathVerifier {
// Parses |spki| to an EVP_PKEY and checks whether the public key is accepted
// by |delegate_|. On failure parsing returns nullptr. If either parsing the
// key or key policy failed, adds a high-severity error to |errors|.
bssl::UniquePtr<EVP_PKEY> ParseAndCheckPublicKey(const der::Input &spki,
bssl::UniquePtr<EVP_PKEY> ParseAndCheckPublicKey(der::Input spki,
CertErrors *errors);
ValidPolicyGraph valid_policy_graph_;
@@ -799,7 +799,7 @@ void PathVerifier::VerifyPolicies(const ParsedCertificate &cert,
// for policy P and P-Q denote the qualifier set for policy
// P. Perform the following steps in order:
bool cert_has_any_policy = false;
for (const der::Input &p_oid : cert.policy_oids()) {
for (der::Input p_oid : cert.policy_oids()) {
if (p_oid == der::Input(kAnyPolicyOid)) {
cert_has_any_policy = true;
continue;
@@ -1431,7 +1431,7 @@ void PathVerifier::ProcessSingleCertChain(const ParsedCertificate &cert,
}
bssl::UniquePtr<EVP_PKEY> PathVerifier::ParseAndCheckPublicKey(
const der::Input &spki, CertErrors *errors) {
der::Input spki, CertErrors *errors) {
// Parse the public key.
bssl::UniquePtr<EVP_PKEY> pkey;
if (!ParsePublicKey(spki, &pkey)) {
+10 -11
View File
@@ -258,7 +258,7 @@ enum NameMatchType {
//
// RelativeDistinguishedName ::=
// SET SIZE (1..MAX) OF AttributeTypeAndValue
bool VerifyNameMatchInternal(const der::Input &a, const der::Input &b,
bool VerifyNameMatchInternal(der::Input a, der::Input b,
NameMatchType match_type) {
// Empty Names are allowed. RFC 5280 section 4.1.2.4 requires "The issuer
// field MUST contain a non-empty distinguished name (DN)", while section
@@ -308,7 +308,7 @@ bool VerifyNameMatchInternal(const der::Input &a, const der::Input &b,
} // namespace
bool NormalizeName(const der::Input &name_rdn_sequence,
bool NormalizeName(der::Input name_rdn_sequence,
std::string *normalized_rdn_sequence, CertErrors *errors) {
BSSL_CHECK(errors);
@@ -350,8 +350,8 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
// AttributeType ::= OBJECT IDENTIFIER
if (!CBB_add_asn1(&attribute_type_and_value_cbb, &type_cbb,
CBS_ASN1_OBJECT) ||
!CBB_add_bytes(&type_cbb, type_and_value.type.UnsafeData(),
type_and_value.type.Length())) {
!CBB_add_bytes(&type_cbb, type_and_value.type.data(),
type_and_value.type.size())) {
return false;
}
@@ -372,8 +372,8 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
} else {
if (!CBB_add_asn1(&attribute_type_and_value_cbb, &value_cbb,
type_and_value.value_tag) ||
!CBB_add_bytes(&value_cbb, type_and_value.value.UnsafeData(),
type_and_value.value.Length())) {
!CBB_add_bytes(&value_cbb, type_and_value.value.data(),
type_and_value.value.size())) {
return false;
}
}
@@ -394,19 +394,18 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
return true;
}
bool VerifyNameMatch(const der::Input &a_rdn_sequence,
const der::Input &b_rdn_sequence) {
bool VerifyNameMatch(der::Input a_rdn_sequence, der::Input b_rdn_sequence) {
return VerifyNameMatchInternal(a_rdn_sequence, b_rdn_sequence, EXACT_MATCH);
}
bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
const der::Input &parent_rdn_sequence) {
bool VerifyNameInSubtree(der::Input name_rdn_sequence,
der::Input parent_rdn_sequence) {
return VerifyNameMatchInternal(name_rdn_sequence, parent_rdn_sequence,
SUBTREE_MATCH);
}
bool FindEmailAddressesInName(
const der::Input &name_rdn_sequence,
der::Input name_rdn_sequence,
std::vector<std::string> *contained_email_addresses) {
contained_email_addresses->clear();
+6 -6
View File
@@ -24,7 +24,7 @@ class Input;
// outer Sequence tag). Returns false if there was an error parsing or
// normalizing the input, and adds error information to |errors|. |errors| must
// be non-null.
OPENSSL_EXPORT bool NormalizeName(const der::Input &name_rdn_sequence,
OPENSSL_EXPORT bool NormalizeName(der::Input name_rdn_sequence,
std::string *normalized_rdn_sequence,
CertErrors *errors);
@@ -32,16 +32,16 @@ OPENSSL_EXPORT bool NormalizeName(const der::Input &name_rdn_sequence,
// |a_rdn_sequence| and |b_rdn_sequence| should be the DER-encoded RDNSequence
// values (not including the Sequence tag).
// Returns true if |a_rdn_sequence| and |b_rdn_sequence| match.
OPENSSL_EXPORT bool VerifyNameMatch(const der::Input &a_rdn_sequence,
const der::Input &b_rdn_sequence);
OPENSSL_EXPORT bool VerifyNameMatch(der::Input a_rdn_sequence,
der::Input b_rdn_sequence);
// Compares |name_rdn_sequence| and |parent_rdn_sequence| and return true if
// |name_rdn_sequence| is within the subtree defined by |parent_rdn_sequence| as
// defined by RFC 5280 section 7.1. |name_rdn_sequence| and
// |parent_rdn_sequence| should be the DER-encoded sequence values (not
// including the Sequence tag).
OPENSSL_EXPORT bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
const der::Input &parent_rdn_sequence);
OPENSSL_EXPORT bool VerifyNameInSubtree(der::Input name_rdn_sequence,
der::Input parent_rdn_sequence);
// Helper functions:
@@ -53,7 +53,7 @@ OPENSSL_EXPORT bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
// tag, but otherwise have not been validated.
// Returns false if there was a parsing error.
[[nodiscard]] bool FindEmailAddressesInName(
const der::Input &name_rdn_sequence,
der::Input name_rdn_sequence,
std::vector<std::string> *contained_email_addresses);
} // namespace bssl
+15 -24
View File
@@ -33,8 +33,8 @@ bool SHA256UpdateWithLengthPrefixedData(SHA256_CTX *s_ctx, const uint8_t *data,
constexpr uint32_t VerifyCacheKeyVersion = 1;
std::string SignatureVerifyCacheKey(std::string_view algorithm_name,
const der::Input &signed_data,
const der::Input &signature_value_bytes,
der::Input signed_data,
der::Input signature_value_bytes,
EVP_PKEY *public_key) {
SHA256_CTX s_ctx;
bssl::ScopedCBB public_key_cbb;
@@ -50,11 +50,10 @@ std::string SignatureVerifyCacheKey(std::string_view algorithm_name,
algorithm_name.length()) &&
SHA256UpdateWithLengthPrefixedData(&s_ctx, CBB_data(public_key_cbb.get()),
CBB_len(public_key_cbb.get())) &&
SHA256UpdateWithLengthPrefixedData(&s_ctx,
signature_value_bytes.UnsafeData(),
signature_value_bytes.Length()) &&
SHA256UpdateWithLengthPrefixedData(&s_ctx, signed_data.UnsafeData(),
signed_data.Length()) &&
SHA256UpdateWithLengthPrefixedData(&s_ctx, signature_value_bytes.data(),
signature_value_bytes.size()) &&
SHA256UpdateWithLengthPrefixedData(&s_ctx, signed_data.data(),
signed_data.size()) &&
SHA256_Final(digest, &s_ctx)) {
return std::string(reinterpret_cast<char *>(digest), sizeof(digest));
}
@@ -137,13 +136,13 @@ class OpenSSLErrStackTracer {
// { ID secp521r1 } | { ID sect571k1 } | { ID sect571r1 },
// ... -- Extensible
// }
bool ParsePublicKey(const der::Input &public_key_spki,
bool ParsePublicKey(der::Input public_key_spki,
bssl::UniquePtr<EVP_PKEY> *public_key) {
// Parse the SPKI to an EVP_PKEY.
OpenSSLErrStackTracer err_tracer;
CBS cbs;
CBS_init(&cbs, public_key_spki.UnsafeData(), public_key_spki.Length());
CBS_init(&cbs, public_key_spki.data(), public_key_spki.size());
public_key->reset(EVP_parse_public_key(&cbs));
if (!*public_key || CBS_len(&cbs) != 0) {
public_key->reset();
@@ -152,8 +151,7 @@ bool ParsePublicKey(const der::Input &public_key_spki,
return true;
}
bool VerifySignedData(SignatureAlgorithm algorithm,
const der::Input &signed_data,
bool VerifySignedData(SignatureAlgorithm algorithm, der::Input signed_data,
const der::BitString &signature_value,
EVP_PKEY *public_key, SignatureVerifyCache *cache) {
int expected_pkey_id = 1;
@@ -232,7 +230,7 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
if (signature_value.unused_bits() != 0) {
return false;
}
const der::Input &signature_value_bytes = signature_value.bytes();
der::Input signature_value_bytes = signature_value.bytes();
std::string cache_key;
if (cache) {
@@ -269,14 +267,9 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
}
}
if (!EVP_DigestVerifyUpdate(ctx.get(), signed_data.UnsafeData(),
signed_data.Length())) {
return false;
}
bool ret =
1 == EVP_DigestVerifyFinal(ctx.get(), signature_value_bytes.UnsafeData(),
signature_value_bytes.Length());
bool ret = 1 == EVP_DigestVerify(ctx.get(), signature_value_bytes.data(),
signature_value_bytes.size(),
signed_data.data(), signed_data.size());
if (!cache_key.empty()) {
cache->Store(cache_key, ret ? SignatureVerifyCache::Value::kValid
: SignatureVerifyCache::Value::kInvalid);
@@ -285,11 +278,9 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
return ret;
}
bool VerifySignedData(SignatureAlgorithm algorithm,
const der::Input &signed_data,
bool VerifySignedData(SignatureAlgorithm algorithm, der::Input signed_data,
const der::BitString &signature_value,
const der::Input &public_key_spki,
SignatureVerifyCache *cache) {
der::Input public_key_spki, SignatureVerifyCache *cache) {
bssl::UniquePtr<EVP_PKEY> public_key;
if (!ParsePublicKey(public_key_spki, &public_key)) {
return false;
+4 -4
View File
@@ -28,19 +28,19 @@ class Input;
//
// Returns true if verification was successful.
[[nodiscard]] OPENSSL_EXPORT bool VerifySignedData(
SignatureAlgorithm algorithm, const der::Input &signed_data,
SignatureAlgorithm algorithm, der::Input signed_data,
const der::BitString &signature_value, EVP_PKEY *public_key,
SignatureVerifyCache *cache);
// Same as above overload, only the public key is inputted as an SPKI and will
// be parsed internally.
[[nodiscard]] OPENSSL_EXPORT bool VerifySignedData(
SignatureAlgorithm algorithm, const der::Input &signed_data,
const der::BitString &signature_value, const der::Input &public_key_spki,
SignatureAlgorithm algorithm, der::Input signed_data,
const der::BitString &signature_value, der::Input public_key_spki,
SignatureVerifyCache *cache);
[[nodiscard]] OPENSSL_EXPORT bool ParsePublicKey(
const der::Input &public_key_spki, bssl::UniquePtr<EVP_PKEY> *public_key);
der::Input public_key_spki, bssl::UniquePtr<EVP_PKEY> *public_key);
} // namespace bssl