update main-with-bazel from master branch
This commit is contained in:
@@ -81,8 +81,6 @@ class SpanBase {
|
||||
template <typename T>
|
||||
class Span : private internal::SpanBase<const T> {
|
||||
private:
|
||||
static const size_t npos = static_cast<size_t>(-1);
|
||||
|
||||
// Heuristically test whether C is a container type that can be converted into
|
||||
// a Span by checking for data() and size() member functions.
|
||||
//
|
||||
@@ -93,6 +91,19 @@ class Span : private internal::SpanBase<const T> {
|
||||
std::is_integral<decltype(std::declval<C>().size())>::value>;
|
||||
|
||||
public:
|
||||
static const size_t npos = static_cast<size_t>(-1);
|
||||
|
||||
using element_type = T;
|
||||
using value_type = std::remove_cv_t<T>;
|
||||
using size_type = size_t;
|
||||
using difference_type = ptrdiff_t;
|
||||
using pointer = T *;
|
||||
using const_pointer = const T *;
|
||||
using reference = T &;
|
||||
using const_reference = const T &;
|
||||
using iterator = T *;
|
||||
using const_iterator = const T *;
|
||||
|
||||
constexpr Span() : Span(nullptr, 0) {}
|
||||
constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
|
||||
|
||||
@@ -113,10 +124,10 @@ class Span : private internal::SpanBase<const T> {
|
||||
constexpr size_t size() const { return size_; }
|
||||
constexpr bool empty() const { return size_ == 0; }
|
||||
|
||||
constexpr T *begin() const { return data_; }
|
||||
constexpr const T *cbegin() const { return data_; }
|
||||
constexpr T *end() const { return data_ + size_; }
|
||||
constexpr const T *cend() const { return end(); }
|
||||
constexpr iterator begin() const { return data_; }
|
||||
constexpr const_iterator cbegin() const { return data_; }
|
||||
constexpr iterator end() const { return data_ + size_; }
|
||||
constexpr const_iterator cend() const { return end(); }
|
||||
|
||||
constexpr T &front() const {
|
||||
if (size_ == 0) {
|
||||
|
||||
@@ -19,8 +19,8 @@ namespace {
|
||||
// blobs. It makes a copy of the der::Inputs.
|
||||
class CertErrorParams2Der : public CertErrorParams {
|
||||
public:
|
||||
CertErrorParams2Der(const char *name1, const der::Input &der1,
|
||||
const char *name2, const der::Input &der2)
|
||||
CertErrorParams2Der(const char *name1, der::Input der1, const char *name2,
|
||||
der::Input der2)
|
||||
: name1_(name1),
|
||||
der1_(der1.AsString()),
|
||||
name2_(name2),
|
||||
@@ -43,9 +43,11 @@ class CertErrorParams2Der : public CertErrorParams {
|
||||
static void AppendDer(const char *name, const std::string &der,
|
||||
std::string *out) {
|
||||
*out += name;
|
||||
// TODO(crbug.com/boringssl/661): Introduce a convenience function to go
|
||||
// from a Span<const char> to a Span<const uint8_t>.
|
||||
*out +=
|
||||
": " + bssl::string_util::HexEncode(
|
||||
reinterpret_cast<const uint8_t *>(der.data()), der.size());
|
||||
": " + bssl::string_util::HexEncode(MakeConstSpan(
|
||||
reinterpret_cast<const uint8_t *>(der.data()), der.size()));
|
||||
}
|
||||
|
||||
const char *name1_;
|
||||
@@ -104,16 +106,17 @@ class CertErrorParams2SizeT : public CertErrorParams {
|
||||
CertErrorParams::CertErrorParams() = default;
|
||||
CertErrorParams::~CertErrorParams() = default;
|
||||
|
||||
std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(
|
||||
const char *name, const der::Input &der) {
|
||||
std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(const char *name,
|
||||
der::Input der) {
|
||||
BSSL_CHECK(name);
|
||||
return std::make_unique<CertErrorParams2Der>(name, der, nullptr,
|
||||
der::Input());
|
||||
}
|
||||
|
||||
std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(
|
||||
const char *name1, const der::Input &der1, const char *name2,
|
||||
const der::Input &der2) {
|
||||
std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(const char *name1,
|
||||
der::Input der1,
|
||||
const char *name2,
|
||||
der::Input der2) {
|
||||
BSSL_CHECK(name1);
|
||||
BSSL_CHECK(name2);
|
||||
return std::make_unique<CertErrorParams2Der>(name1, der1, name2, der2);
|
||||
|
||||
@@ -39,12 +39,11 @@ class OPENSSL_EXPORT CertErrorParams {
|
||||
// Creates a parameter object that holds a copy of |der|, and names it |name|
|
||||
// in debug string outputs.
|
||||
OPENSSL_EXPORT std::unique_ptr<CertErrorParams> CreateCertErrorParams1Der(
|
||||
const char *name, const der::Input &der);
|
||||
const char *name, der::Input der);
|
||||
|
||||
// Same as CreateCertErrorParams1Der() but has a second DER blob.
|
||||
OPENSSL_EXPORT std::unique_ptr<CertErrorParams> CreateCertErrorParams2Der(
|
||||
const char *name1, const der::Input &der1, const char *name2,
|
||||
const der::Input &der2);
|
||||
const char *name1, der::Input der1, const char *name2, der::Input der2);
|
||||
|
||||
// Creates a parameter object that holds a single size_t value. |name| is used
|
||||
// when pretty-printing the parameters.
|
||||
|
||||
@@ -130,7 +130,7 @@ bool ParsePolicyQualifiers(bool restrict_to_known_qualifiers,
|
||||
// bmpString BMPString (SIZE (1..200)),
|
||||
// utf8String UTF8String (SIZE (1..200)) }
|
||||
bool ParseCertificatePoliciesExtensionImpl(
|
||||
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
std::vector<der::Input> *policy_oids,
|
||||
std::vector<PolicyInformation> *policy_informations, CertErrors *errors) {
|
||||
BSSL_CHECK(policy_oids);
|
||||
@@ -227,7 +227,7 @@ PolicyInformation::~PolicyInformation() = default;
|
||||
PolicyInformation::PolicyInformation(const PolicyInformation &) = default;
|
||||
PolicyInformation::PolicyInformation(PolicyInformation &&) = default;
|
||||
|
||||
bool ParseCertificatePoliciesExtension(const der::Input &extension_value,
|
||||
bool ParseCertificatePoliciesExtension(der::Input extension_value,
|
||||
std::vector<PolicyInformation> *policies,
|
||||
CertErrors *errors) {
|
||||
std::vector<der::Input> unused_policy_oids;
|
||||
@@ -237,7 +237,7 @@ bool ParseCertificatePoliciesExtension(const der::Input &extension_value,
|
||||
}
|
||||
|
||||
bool ParseCertificatePoliciesExtensionOids(
|
||||
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
std::vector<der::Input> *policy_oids, CertErrors *errors) {
|
||||
return ParseCertificatePoliciesExtensionImpl(
|
||||
extension_value, fail_parsing_unknown_qualifier_oids, policy_oids,
|
||||
@@ -251,7 +251,7 @@ bool ParseCertificatePoliciesExtensionOids(
|
||||
// inhibitPolicyMapping [1] SkipCerts OPTIONAL }
|
||||
//
|
||||
// SkipCerts ::= INTEGER (0..MAX)
|
||||
bool ParsePolicyConstraints(const der::Input &policy_constraints_tlv,
|
||||
bool ParsePolicyConstraints(der::Input policy_constraints_tlv,
|
||||
ParsedPolicyConstraints *out) {
|
||||
der::Parser parser(policy_constraints_tlv);
|
||||
|
||||
@@ -318,7 +318,7 @@ bool ParsePolicyConstraints(const der::Input &policy_constraints_tlv,
|
||||
//
|
||||
// SkipCerts ::= INTEGER (0..MAX)
|
||||
std::optional<uint8_t> ParseInhibitAnyPolicy(
|
||||
const der::Input &inhibit_any_policy_tlv) {
|
||||
der::Input inhibit_any_policy_tlv) {
|
||||
der::Parser parser(inhibit_any_policy_tlv);
|
||||
std::optional<uint8_t> num_certs = std::make_optional<uint8_t>();
|
||||
|
||||
@@ -340,7 +340,7 @@ std::optional<uint8_t> ParseInhibitAnyPolicy(
|
||||
// PolicyMappings ::= SEQUENCE SIZE (1..MAX) OF SEQUENCE {
|
||||
// issuerDomainPolicy CertPolicyId,
|
||||
// subjectDomainPolicy CertPolicyId }
|
||||
bool ParsePolicyMappings(const der::Input &policy_mappings_tlv,
|
||||
bool ParsePolicyMappings(der::Input policy_mappings_tlv,
|
||||
std::vector<ParsedPolicyMapping> *mappings) {
|
||||
mappings->clear();
|
||||
|
||||
|
||||
@@ -73,7 +73,7 @@ struct OPENSSL_EXPORT PolicyInformation {
|
||||
// The values in |policies| are only valid as long as |extension_value| is (as
|
||||
// it references data).
|
||||
OPENSSL_EXPORT bool ParseCertificatePoliciesExtension(
|
||||
const der::Input &extension_value, std::vector<PolicyInformation> *policies,
|
||||
der::Input extension_value, std::vector<PolicyInformation> *policies,
|
||||
CertErrors *errors);
|
||||
|
||||
// Parses a certificatePolicies extension and stores the policy OIDs in
|
||||
@@ -94,7 +94,7 @@ OPENSSL_EXPORT bool ParseCertificatePoliciesExtension(
|
||||
// The values in |policy_oids| are only valid as long as |extension_value| is
|
||||
// (as it references data).
|
||||
OPENSSL_EXPORT bool ParseCertificatePoliciesExtensionOids(
|
||||
const der::Input &extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
der::Input extension_value, bool fail_parsing_unknown_qualifier_oids,
|
||||
std::vector<der::Input> *policy_oids, CertErrors *errors);
|
||||
|
||||
struct ParsedPolicyConstraints {
|
||||
@@ -106,12 +106,12 @@ struct ParsedPolicyConstraints {
|
||||
// Parses a PolicyConstraints SEQUENCE as defined by RFC 5280. Returns true on
|
||||
// success, and sets |out|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParsePolicyConstraints(
|
||||
const der::Input &policy_constraints_tlv, ParsedPolicyConstraints *out);
|
||||
der::Input policy_constraints_tlv, ParsedPolicyConstraints *out);
|
||||
|
||||
// Parses an InhibitAnyPolicy as defined by RFC 5280. Returns num certs on
|
||||
// success, or empty if parser fails.
|
||||
[[nodiscard]] OPENSSL_EXPORT std::optional<uint8_t> ParseInhibitAnyPolicy(
|
||||
const der::Input &inhibit_any_policy_tlv);
|
||||
der::Input inhibit_any_policy_tlv);
|
||||
|
||||
struct ParsedPolicyMapping {
|
||||
der::Input issuer_domain_policy;
|
||||
@@ -121,8 +121,7 @@ struct ParsedPolicyMapping {
|
||||
// Parses a PolicyMappings SEQUENCE as defined by RFC 5280. Returns true on
|
||||
// success, and sets |mappings|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParsePolicyMappings(
|
||||
const der::Input &policy_mappings_tlv,
|
||||
std::vector<ParsedPolicyMapping> *mappings);
|
||||
der::Input policy_mappings_tlv, std::vector<ParsedPolicyMapping> *mappings);
|
||||
|
||||
} // namespace bssl
|
||||
|
||||
|
||||
+5
-5
@@ -26,7 +26,7 @@ namespace {
|
||||
// In dotted notation: 2.5.29.28
|
||||
inline constexpr uint8_t kIssuingDistributionPointOid[] = {0x55, 0x1d, 0x1c};
|
||||
|
||||
[[nodiscard]] bool NormalizeNameTLV(const der::Input &name_tlv,
|
||||
[[nodiscard]] bool NormalizeNameTLV(der::Input name_tlv,
|
||||
std::string *out_normalized_name) {
|
||||
der::Parser parser(name_tlv);
|
||||
der::Input name_rdn;
|
||||
@@ -48,7 +48,7 @@ bool ContainsExactMatchingName(std::vector<std::string_view> a,
|
||||
|
||||
} // namespace
|
||||
|
||||
bool ParseCrlCertificateList(const der::Input &crl_tlv,
|
||||
bool ParseCrlCertificateList(der::Input crl_tlv,
|
||||
der::Input *out_tbs_cert_list_tlv,
|
||||
der::Input *out_signature_algorithm_tlv,
|
||||
der::BitString *out_signature_value) {
|
||||
@@ -92,7 +92,7 @@ bool ParseCrlCertificateList(const der::Input &crl_tlv,
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseCrlTbsCertList(const der::Input &tbs_tlv, ParsedCrlTbsCertList *out) {
|
||||
bool ParseCrlTbsCertList(der::Input tbs_tlv, ParsedCrlTbsCertList *out) {
|
||||
der::Parser parser(tbs_tlv);
|
||||
|
||||
// TBSCertList ::= SEQUENCE {
|
||||
@@ -196,7 +196,7 @@ bool ParseCrlTbsCertList(const der::Input &tbs_tlv, ParsedCrlTbsCertList *out) {
|
||||
}
|
||||
|
||||
bool ParseIssuingDistributionPoint(
|
||||
const der::Input &extension_value,
|
||||
der::Input extension_value,
|
||||
std::unique_ptr<GeneralNames> *out_distribution_point_names,
|
||||
ContainedCertsType *out_only_contains_cert_type) {
|
||||
der::Parser idp_extension_value_parser(extension_value);
|
||||
@@ -303,7 +303,7 @@ bool ParseIssuingDistributionPoint(
|
||||
}
|
||||
|
||||
CRLRevocationStatus GetCRLStatusForCert(
|
||||
const der::Input &cert_serial, CrlVersion crl_version,
|
||||
der::Input cert_serial, CrlVersion crl_version,
|
||||
const std::optional<der::Input> &revoked_certificates_tlv) {
|
||||
if (!revoked_certificates_tlv.has_value()) {
|
||||
// RFC 5280 Section 5.1.2.6: "When there are no revoked certificates, the
|
||||
|
||||
+4
-4
@@ -43,7 +43,7 @@ enum class CRLRevocationStatus {
|
||||
// signatureAlgorithm AlgorithmIdentifier,
|
||||
// signatureValue BIT STRING }
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlCertificateList(
|
||||
const der::Input &crl_tlv, der::Input *out_tbs_cert_list_tlv,
|
||||
der::Input crl_tlv, der::Input *out_tbs_cert_list_tlv,
|
||||
der::Input *out_signature_algorithm_tlv,
|
||||
der::BitString *out_signature_value);
|
||||
|
||||
@@ -77,7 +77,7 @@ enum class CRLRevocationStatus {
|
||||
// -- if present, version MUST be v2
|
||||
// }
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlTbsCertList(
|
||||
const der::Input &tbs_tlv, ParsedCrlTbsCertList *out);
|
||||
der::Input tbs_tlv, ParsedCrlTbsCertList *out);
|
||||
|
||||
// Represents a CRL "Version" from RFC 5280. TBSCertList reuses the same
|
||||
// Version definition from TBSCertificate, however only v1(not present) and
|
||||
@@ -180,12 +180,12 @@ enum class ContainedCertsType {
|
||||
// indirectCRL [4] BOOLEAN DEFAULT FALSE,
|
||||
// onlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE }
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseIssuingDistributionPoint(
|
||||
const der::Input &extension_value,
|
||||
der::Input extension_value,
|
||||
std::unique_ptr<GeneralNames> *out_distribution_point_names,
|
||||
ContainedCertsType *out_only_contains_cert_type);
|
||||
|
||||
OPENSSL_EXPORT CRLRevocationStatus
|
||||
GetCRLStatusForCert(const der::Input &cert_serial, CrlVersion crl_version,
|
||||
GetCRLStatusForCert(der::Input cert_serial, CrlVersion crl_version,
|
||||
const std::optional<der::Input> &revoked_certificates_tlv);
|
||||
|
||||
// Checks the revocation status of the certificate |cert| by using the
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
|
||||
namespace bssl {
|
||||
|
||||
bool ParseEKUExtension(const der::Input &extension_value,
|
||||
bool ParseEKUExtension(der::Input extension_value,
|
||||
std::vector<der::Input> *eku_oids) {
|
||||
der::Parser extension_parser(extension_value);
|
||||
der::Parser sequence_parser;
|
||||
|
||||
@@ -75,7 +75,7 @@ inline constexpr uint8_t kOCSPSigning[] = {0x2b, 0x06, 0x01, 0x05,
|
||||
//
|
||||
// Note: The returned OIDs are only as valid as long as the data pointed to by
|
||||
// |extension_value| is valid.
|
||||
OPENSSL_EXPORT bool ParseEKUExtension(const der::Input &extension_value,
|
||||
OPENSSL_EXPORT bool ParseEKUExtension(der::Input extension_value,
|
||||
std::vector<der::Input> *eku_oids);
|
||||
|
||||
} // namespace bssl
|
||||
|
||||
@@ -13,7 +13,7 @@ namespace bssl {
|
||||
namespace {
|
||||
|
||||
// Helper method to check if an EKU is present in a std::vector of EKUs.
|
||||
bool HasEKU(const std::vector<der::Input> &list, const der::Input &eku) {
|
||||
bool HasEKU(const std::vector<der::Input> &list, der::Input eku) {
|
||||
for (const auto &oid : list) {
|
||||
if (oid == eku) {
|
||||
return true;
|
||||
|
||||
+10
-11
@@ -44,8 +44,8 @@ GeneralNames::GeneralNames() = default;
|
||||
GeneralNames::~GeneralNames() = default;
|
||||
|
||||
// static
|
||||
std::unique_ptr<GeneralNames> GeneralNames::Create(
|
||||
const der::Input &general_names_tlv, CertErrors *errors) {
|
||||
std::unique_ptr<GeneralNames> GeneralNames::Create(der::Input general_names_tlv,
|
||||
CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
|
||||
// RFC 5280 section 4.2.1.6:
|
||||
@@ -66,7 +66,7 @@ std::unique_ptr<GeneralNames> GeneralNames::Create(
|
||||
|
||||
// static
|
||||
std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
|
||||
const der::Input &general_names_value, CertErrors *errors) {
|
||||
der::Input general_names_value, CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
|
||||
auto general_names = std::make_unique<GeneralNames>();
|
||||
@@ -96,7 +96,7 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
|
||||
}
|
||||
|
||||
[[nodiscard]] bool ParseGeneralName(
|
||||
const der::Input &input,
|
||||
der::Input input,
|
||||
GeneralNames::ParseGeneralNameIPAddressType ip_address_type,
|
||||
GeneralNames *subtrees, CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
@@ -170,8 +170,8 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
|
||||
// version 4, as specified in [RFC791], the octet string MUST contain
|
||||
// exactly four octets. For IP version 6, as specified in [RFC2460],
|
||||
// the octet string MUST contain exactly sixteen octets.
|
||||
if ((value.Length() != kIPv4AddressSize &&
|
||||
value.Length() != kIPv6AddressSize)) {
|
||||
if ((value.size() != kIPv4AddressSize &&
|
||||
value.size() != kIPv6AddressSize)) {
|
||||
errors->AddError(kFailedParsingIp);
|
||||
return false;
|
||||
}
|
||||
@@ -188,14 +188,13 @@ std::unique_ptr<GeneralNames> GeneralNames::CreateFromValue(
|
||||
// constraint for "class C" subnet 192.0.2.0 is represented as the
|
||||
// octets C0 00 02 00 FF FF FF 00, representing the CIDR notation
|
||||
// 192.0.2.0/24 (mask 255.255.255.0).
|
||||
if (value.Length() != kIPv4AddressSize * 2 &&
|
||||
value.Length() != kIPv6AddressSize * 2) {
|
||||
if (value.size() != kIPv4AddressSize * 2 &&
|
||||
value.size() != kIPv6AddressSize * 2) {
|
||||
errors->AddError(kFailedParsingIp);
|
||||
return false;
|
||||
}
|
||||
der::Input addr(value.UnsafeData(), value.Length() / 2);
|
||||
der::Input mask(value.UnsafeData() + value.Length() / 2,
|
||||
value.Length() / 2);
|
||||
der::Input addr = value.first(value.size() / 2);
|
||||
der::Input mask = value.subspan(value.size() / 2);
|
||||
if (!IsValidNetmask(mask)) {
|
||||
errors->AddError(kFailedParsingIp);
|
||||
return false;
|
||||
|
||||
@@ -63,13 +63,13 @@ struct OPENSSL_EXPORT GeneralNames {
|
||||
// |general_names_tlv|, so is only valid as long as |general_names_tlv| is.
|
||||
// Returns nullptr on failure, and may fill |errors| with
|
||||
// additional information. |errors| must be non-null.
|
||||
static std::unique_ptr<GeneralNames> Create(
|
||||
const der::Input &general_names_tlv, CertErrors *errors);
|
||||
static std::unique_ptr<GeneralNames> Create(der::Input general_names_tlv,
|
||||
CertErrors *errors);
|
||||
|
||||
// As above, but takes the GeneralNames sequence value, without the tag and
|
||||
// length.
|
||||
static std::unique_ptr<GeneralNames> CreateFromValue(
|
||||
const der::Input &general_names_value, CertErrors *errors);
|
||||
der::Input general_names_value, CertErrors *errors);
|
||||
|
||||
// DER-encoded OtherName values.
|
||||
std::vector<der::Input> other_names;
|
||||
@@ -122,7 +122,7 @@ struct OPENSSL_EXPORT GeneralNames {
|
||||
// |errors| must be non-null.
|
||||
// TODO(mattm): should this be a method on GeneralNames?
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralName(
|
||||
const der::Input &input,
|
||||
der::Input input,
|
||||
GeneralNames::ParseGeneralNameIPAddressType ip_address_type,
|
||||
GeneralNames *subtrees, CertErrors *errors);
|
||||
|
||||
|
||||
+10
-16
@@ -4,8 +4,6 @@
|
||||
|
||||
#include "input.h"
|
||||
|
||||
#include <algorithm>
|
||||
|
||||
#include <openssl/base.h>
|
||||
|
||||
namespace bssl::der {
|
||||
@@ -20,42 +18,38 @@ std::string_view Input::AsStringView() const {
|
||||
data_.size());
|
||||
}
|
||||
|
||||
bssl::Span<const uint8_t> Input::AsSpan() const { return data_; }
|
||||
|
||||
bool operator==(const Input &lhs, const Input &rhs) {
|
||||
return lhs.AsSpan() == rhs.AsSpan();
|
||||
bool operator==(Input lhs, Input rhs) {
|
||||
return MakeConstSpan(lhs) == MakeConstSpan(rhs);
|
||||
}
|
||||
|
||||
bool operator!=(const Input &lhs, const Input &rhs) { return !(lhs == rhs); }
|
||||
bool operator!=(Input lhs, Input rhs) { return !(lhs == rhs); }
|
||||
|
||||
ByteReader::ByteReader(const Input &in)
|
||||
: data_(in.UnsafeData()), len_(in.Length()) {}
|
||||
ByteReader::ByteReader(Input in) : data_(in) {}
|
||||
|
||||
bool ByteReader::ReadByte(uint8_t *byte_p) {
|
||||
if (!HasMore()) {
|
||||
return false;
|
||||
}
|
||||
*byte_p = *data_;
|
||||
*byte_p = data_[0];
|
||||
Advance(1);
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ByteReader::ReadBytes(size_t len, Input *out) {
|
||||
if (len > len_) {
|
||||
if (len > data_.size()) {
|
||||
return false;
|
||||
}
|
||||
*out = Input(data_, len);
|
||||
*out = Input(data_.first(len));
|
||||
Advance(len);
|
||||
return true;
|
||||
}
|
||||
|
||||
// Returns whether there is any more data to be read.
|
||||
bool ByteReader::HasMore() { return len_ > 0; }
|
||||
bool ByteReader::HasMore() { return !data_.empty(); }
|
||||
|
||||
void ByteReader::Advance(size_t len) {
|
||||
BSSL_CHECK(len <= len_);
|
||||
data_ += len;
|
||||
len_ -= len;
|
||||
BSSL_CHECK(len <= data_.size());
|
||||
data_ = data_.subspan(len);
|
||||
}
|
||||
|
||||
} // namespace bssl::der
|
||||
|
||||
+44
-26
@@ -26,6 +26,10 @@ namespace bssl::der {
|
||||
// difficult to read memory outside of an Input. ByteReader provides a simple
|
||||
// API for reading through the Input sequentially. For more complicated uses,
|
||||
// multiple instances of a ByteReader for a particular Input can be created.
|
||||
//
|
||||
// TODO(crbug.com/boringssl/661): This class will gradually be replaced with
|
||||
// bssl::Span<const uint8_t>. Avoid relying on APIs that are not part of
|
||||
// bssl::Span.
|
||||
class OPENSSL_EXPORT Input {
|
||||
public:
|
||||
// Creates an empty Input, one from which no data can be read.
|
||||
@@ -34,29 +38,36 @@ class OPENSSL_EXPORT Input {
|
||||
// Creates an Input from a span. The constructed Input is only valid as long
|
||||
// as |data| points to live memory. If constructed from, say, a
|
||||
// |std::vector<uint8_t>|, mutating the vector will invalidate the Input.
|
||||
constexpr explicit Input(bssl::Span<const uint8_t> data) : data_(data) {}
|
||||
constexpr Input(bssl::Span<const uint8_t> data) : data_(data) {}
|
||||
|
||||
// Creates an Input from the given |data| and |len|.
|
||||
constexpr explicit Input(const uint8_t *data, size_t len)
|
||||
: data_(bssl::MakeConstSpan(data, len)) {}
|
||||
: data_(MakeConstSpan(data, len)) {}
|
||||
|
||||
// Creates an Input from a std::string_view. The constructed Input is only
|
||||
// valid as long as |data| points to live memory. If constructed from, say, a
|
||||
// |std::string|, mutating the vector will invalidate the Input.
|
||||
explicit Input(std::string_view str)
|
||||
: data_(bssl::MakeConstSpan(reinterpret_cast<const uint8_t *>(str.data()),
|
||||
str.size())) {}
|
||||
|
||||
// Returns the length in bytes of an Input's data.
|
||||
constexpr size_t Length() const { return data_.size(); }
|
||||
|
||||
// Returns a pointer to the Input's data. This method is marked as "unsafe"
|
||||
// because access to the Input's data should be done through ByteReader
|
||||
// instead. This method should only be used where using a ByteReader truly
|
||||
// is not an option.
|
||||
constexpr const uint8_t *UnsafeData() const { return data_.data(); }
|
||||
: data_(MakeConstSpan(reinterpret_cast<const uint8_t *>(str.data()),
|
||||
str.size())) {}
|
||||
|
||||
// The following APIs have the same semantics as in |bssl::Span|.
|
||||
constexpr Span<const uint8_t>::iterator begin() const {
|
||||
return data_.begin();
|
||||
}
|
||||
constexpr Span<const uint8_t>::iterator end() const { return data_.end(); }
|
||||
constexpr const uint8_t *data() const { return data_.data(); }
|
||||
constexpr size_t size() const { return data_.size(); }
|
||||
constexpr bool empty() const { return data_.empty(); }
|
||||
constexpr uint8_t operator[](size_t idx) const { return data_[idx]; }
|
||||
constexpr uint8_t front() const { return data_.front(); }
|
||||
constexpr uint8_t back() const { return data_.back(); }
|
||||
constexpr Input subspan(size_t pos = 0,
|
||||
size_t len = Span<const uint8_t>::npos) const {
|
||||
return Input(data_.subspan(pos, len));
|
||||
}
|
||||
constexpr Input first(size_t len) const { return Input(data_.first(len)); }
|
||||
constexpr Input last(size_t len) const { return Input(data_.last(len)); }
|
||||
|
||||
// Returns a copy of the data represented by this object as a std::string.
|
||||
std::string AsString() const;
|
||||
@@ -66,29 +77,37 @@ class OPENSSL_EXPORT Input {
|
||||
// this Input.
|
||||
std::string_view AsStringView() const;
|
||||
|
||||
// Deprecated: This class implicitly converts to bssl::Span<const uint8_t>.
|
||||
//
|
||||
// Returns a span pointing to the same data as the Input. The resulting span
|
||||
// must not outlive the data that was used to construct this Input.
|
||||
bssl::Span<const uint8_t> AsSpan() const;
|
||||
Span<const uint8_t> AsSpan() const { return *this; }
|
||||
|
||||
// Deprecated: Use size() instead.
|
||||
constexpr size_t Length() const { return size(); }
|
||||
|
||||
// Deprecated: Use data() instead.
|
||||
constexpr const uint8_t *UnsafeData() const { return data(); }
|
||||
|
||||
private:
|
||||
// TODO(crbug.com/770501): Replace this type with span altogether.
|
||||
bssl::Span<const uint8_t> data_;
|
||||
Span<const uint8_t> data_;
|
||||
};
|
||||
|
||||
// Return true if |lhs|'s data and |rhs|'s data are byte-wise equal.
|
||||
OPENSSL_EXPORT bool operator==(const Input &lhs, const Input &rhs);
|
||||
OPENSSL_EXPORT bool operator==(Input lhs, Input rhs);
|
||||
|
||||
// Return true if |lhs|'s data and |rhs|'s data are not byte-wise equal.
|
||||
OPENSSL_EXPORT bool operator!=(const Input &lhs, const Input &rhs);
|
||||
OPENSSL_EXPORT bool operator!=(Input lhs, Input rhs);
|
||||
|
||||
// Returns true if |lhs|'s data is lexicographically less than |rhs|'s data.
|
||||
OPENSSL_EXPORT constexpr bool operator<(const Input &lhs, const Input &rhs) {
|
||||
OPENSSL_EXPORT constexpr bool operator<(Input lhs, Input rhs) {
|
||||
// This is `std::lexicographical_compare`, but that's not `constexpr` until
|
||||
// C++-20.
|
||||
auto *it1 = lhs.UnsafeData();
|
||||
auto *it2 = rhs.UnsafeData();
|
||||
const auto *end1 = lhs.UnsafeData() + lhs.Length();
|
||||
const auto *end2 = rhs.UnsafeData() + rhs.Length();
|
||||
auto *it1 = lhs.data();
|
||||
auto *it2 = rhs.data();
|
||||
const auto *end1 = lhs.data() + lhs.size();
|
||||
const auto *end2 = rhs.data() + rhs.size();
|
||||
for (; it1 != end1 && it2 != end2; ++it1, ++it2) {
|
||||
if (*it1 < *it2) {
|
||||
return true;
|
||||
@@ -119,7 +138,7 @@ OPENSSL_EXPORT constexpr bool operator<(const Input &lhs, const Input &rhs) {
|
||||
class OPENSSL_EXPORT ByteReader {
|
||||
public:
|
||||
// Creates a ByteReader to read the data represented by an Input.
|
||||
explicit ByteReader(const Input &in);
|
||||
explicit ByteReader(Input in);
|
||||
|
||||
// Reads a single byte from the input source, putting the byte read in
|
||||
// |*byte_p|. If a byte cannot be read from the input (because there is
|
||||
@@ -132,7 +151,7 @@ class OPENSSL_EXPORT ByteReader {
|
||||
[[nodiscard]] bool ReadBytes(size_t len, Input *out);
|
||||
|
||||
// Returns how many bytes are left to read.
|
||||
size_t BytesLeft() const { return len_; }
|
||||
size_t BytesLeft() const { return data_.size(); }
|
||||
|
||||
// Returns whether there is any more data to be read.
|
||||
bool HasMore();
|
||||
@@ -140,8 +159,7 @@ class OPENSSL_EXPORT ByteReader {
|
||||
private:
|
||||
void Advance(size_t len);
|
||||
|
||||
const uint8_t *data_;
|
||||
size_t len_;
|
||||
bssl::Span<const uint8_t> data_;
|
||||
};
|
||||
|
||||
} // namespace bssl::der
|
||||
|
||||
@@ -48,7 +48,7 @@ TEST(InputTest, AsString) {
|
||||
|
||||
TEST(InputTest, StaticArray) {
|
||||
Input input(kInput);
|
||||
EXPECT_EQ(std::size(kInput), input.Length());
|
||||
EXPECT_EQ(std::size(kInput), input.size());
|
||||
|
||||
Input input2(kInput);
|
||||
EXPECT_EQ(input, input2);
|
||||
@@ -56,17 +56,17 @@ TEST(InputTest, StaticArray) {
|
||||
|
||||
TEST(InputTest, ConstExpr) {
|
||||
constexpr Input default_input;
|
||||
static_assert(default_input.Length() == 0);
|
||||
static_assert(default_input.UnsafeData() == nullptr);
|
||||
static_assert(default_input.size() == 0);
|
||||
static_assert(default_input.data() == nullptr);
|
||||
|
||||
constexpr Input const_array_input(kInput);
|
||||
static_assert(const_array_input.Length() == 4);
|
||||
static_assert(const_array_input.UnsafeData() == kInput);
|
||||
static_assert(const_array_input.size() == 4);
|
||||
static_assert(const_array_input.data() == kInput);
|
||||
static_assert(default_input < const_array_input);
|
||||
|
||||
constexpr Input ptr_len_input(kInput, 2);
|
||||
static_assert(ptr_len_input.Length() == 2);
|
||||
static_assert(ptr_len_input.UnsafeData() == kInput);
|
||||
static_assert(ptr_len_input.size() == 2);
|
||||
static_assert(ptr_len_input.data() == kInput);
|
||||
static_assert(ptr_len_input < const_array_input);
|
||||
|
||||
Input runtime_input(kInput2, 2);
|
||||
|
||||
+5
-5
@@ -7,11 +7,11 @@
|
||||
namespace bssl {
|
||||
|
||||
bool IsValidNetmask(der::Input mask) {
|
||||
if (mask.Length() != kIPv4AddressSize && mask.Length() != kIPv6AddressSize) {
|
||||
if (mask.size() != kIPv4AddressSize && mask.size() != kIPv6AddressSize) {
|
||||
return false;
|
||||
}
|
||||
|
||||
for (size_t i = 0; i < mask.Length(); i++) {
|
||||
for (size_t i = 0; i < mask.size(); i++) {
|
||||
uint8_t b = mask[i];
|
||||
if (b != 0xff) {
|
||||
// b must be all ones followed by all zeros, so ~b must be all zeros
|
||||
@@ -21,7 +21,7 @@ bool IsValidNetmask(der::Input mask) {
|
||||
return false;
|
||||
}
|
||||
// The remaining bytes must be all zeros.
|
||||
for (size_t j = i + 1; j < mask.Length(); j++) {
|
||||
for (size_t j = i + 1; j < mask.size(); j++) {
|
||||
if (mask[j] != 0) {
|
||||
return false;
|
||||
}
|
||||
@@ -35,10 +35,10 @@ bool IsValidNetmask(der::Input mask) {
|
||||
|
||||
bool IPAddressMatchesWithNetmask(der::Input addr1, der::Input addr2,
|
||||
der::Input mask) {
|
||||
if (addr1.Length() != addr2.Length() || addr1.Length() != mask.Length()) {
|
||||
if (addr1.size() != addr2.size() || addr1.size() != mask.size()) {
|
||||
return false;
|
||||
}
|
||||
for (size_t i = 0; i < addr1.Length(); i++) {
|
||||
for (size_t i = 0; i < addr1.size(); i++) {
|
||||
if ((addr1[i] & mask[i]) != (addr2[i] & mask[i])) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -117,7 +117,7 @@ bool DNSNameMatches(std::string_view name, std::string_view dns_constraint,
|
||||
// NOTE: |subtrees| is not pre-initialized by the function(it is expected to be
|
||||
// a default initialized object), and it will be modified regardless of the
|
||||
// return value.
|
||||
[[nodiscard]] bool ParseGeneralSubtrees(const der::Input &value,
|
||||
[[nodiscard]] bool ParseGeneralSubtrees(der::Input value,
|
||||
GeneralNames *subtrees,
|
||||
CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
@@ -278,7 +278,7 @@ NameConstraints::~NameConstraints() = default;
|
||||
|
||||
// static
|
||||
std::unique_ptr<NameConstraints> NameConstraints::Create(
|
||||
const der::Input &extension_value, bool is_critical, CertErrors *errors) {
|
||||
der::Input extension_value, bool is_critical, CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
|
||||
auto name_constraints = std::make_unique<NameConstraints>();
|
||||
@@ -288,7 +288,7 @@ std::unique_ptr<NameConstraints> NameConstraints::Create(
|
||||
return name_constraints;
|
||||
}
|
||||
|
||||
bool NameConstraints::Parse(const der::Input &extension_value, bool is_critical,
|
||||
bool NameConstraints::Parse(der::Input extension_value, bool is_critical,
|
||||
CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
|
||||
@@ -348,7 +348,7 @@ bool NameConstraints::Parse(const der::Input &extension_value, bool is_critical,
|
||||
return true;
|
||||
}
|
||||
|
||||
void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
|
||||
void NameConstraints::IsPermittedCert(der::Input subject_rdn_sequence,
|
||||
const GeneralNames *subject_alt_names,
|
||||
CertErrors *errors) const {
|
||||
// Checking NameConstraints is O(number_of_names * number_of_constraints).
|
||||
@@ -381,7 +381,7 @@ void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
|
||||
} else {
|
||||
constraint_count += excluded_subtrees_.directory_names.size() +
|
||||
permitted_subtrees_.directory_names.size();
|
||||
name_count = subject_rdn_sequence.Length();
|
||||
name_count = subject_rdn_sequence.size();
|
||||
}
|
||||
// Upper bound the number of possible checks, checking for overflow.
|
||||
size_t check_count = constraint_count * name_count;
|
||||
@@ -502,7 +502,7 @@ void NameConstraints::IsPermittedCert(const der::Input &subject_rdn_sequence,
|
||||
// This code assumes that criticality condition is checked by the caller, and
|
||||
// therefore only needs to avoid the IsPermittedDirectoryName check against an
|
||||
// empty subject in such a case.
|
||||
if (subject_alt_names && subject_rdn_sequence.Length() == 0) {
|
||||
if (subject_alt_names && subject_rdn_sequence.empty()) {
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -647,7 +647,7 @@ bool NameConstraints::IsPermittedDNSName(std::string_view name) const {
|
||||
}
|
||||
|
||||
bool NameConstraints::IsPermittedDirectoryName(
|
||||
const der::Input &name_rdn_sequence) const {
|
||||
der::Input name_rdn_sequence) const {
|
||||
for (const auto &excluded_name : excluded_subtrees_.directory_names) {
|
||||
if (VerifyNameInSubtree(name_rdn_sequence, excluded_name)) {
|
||||
return false;
|
||||
@@ -669,7 +669,7 @@ bool NameConstraints::IsPermittedDirectoryName(
|
||||
return false;
|
||||
}
|
||||
|
||||
bool NameConstraints::IsPermittedIP(const der::Input &ip) const {
|
||||
bool NameConstraints::IsPermittedIP(der::Input ip) const {
|
||||
for (const auto &excluded_ip : excluded_subtrees_.ip_address_ranges) {
|
||||
if (IPAddressMatchesWithNetmask(ip, excluded_ip.first,
|
||||
excluded_ip.second)) {
|
||||
|
||||
@@ -31,8 +31,9 @@ class OPENSSL_EXPORT NameConstraints {
|
||||
// marked critical. Returns nullptr if parsing the the extension failed.
|
||||
// The object may reference data from |extension_value|, so is only valid as
|
||||
// long as |extension_value| is.
|
||||
static std::unique_ptr<NameConstraints> Create(
|
||||
const der::Input &extension_value, bool is_critical, CertErrors *errors);
|
||||
static std::unique_ptr<NameConstraints> Create(der::Input extension_value,
|
||||
bool is_critical,
|
||||
CertErrors *errors);
|
||||
|
||||
// Tests if a certificate is allowed by the name constraints.
|
||||
// |subject_rdn_sequence| should be the DER-encoded value of the subject's
|
||||
@@ -42,7 +43,7 @@ class OPENSSL_EXPORT NameConstraints {
|
||||
// If the certificate is not allowed, an error will be added to |errors|.
|
||||
// Note that this method does not check hostname or IP address in commonName,
|
||||
// which is deprecated (crbug.com/308330).
|
||||
void IsPermittedCert(const der::Input &subject_rdn_sequence,
|
||||
void IsPermittedCert(der::Input subject_rdn_sequence,
|
||||
const GeneralNames *subject_alt_names,
|
||||
CertErrors *errors) const;
|
||||
|
||||
@@ -62,10 +63,10 @@ class OPENSSL_EXPORT NameConstraints {
|
||||
// Returns true if the directoryName |name_rdn_sequence| is permitted.
|
||||
// |name_rdn_sequence| should be the DER-encoded RDNSequence value (not
|
||||
// including the Sequence tag.)
|
||||
bool IsPermittedDirectoryName(const der::Input &name_rdn_sequence) const;
|
||||
bool IsPermittedDirectoryName(der::Input name_rdn_sequence) const;
|
||||
|
||||
// Returns true if the iPAddress |ip| is permitted.
|
||||
bool IsPermittedIP(const der::Input &ip) const;
|
||||
bool IsPermittedIP(der::Input ip) const;
|
||||
|
||||
// Returns a bitfield of GeneralNameTypes of all the types constrained by this
|
||||
// NameConstraints. Name types that aren't supported will only be present if
|
||||
@@ -87,7 +88,7 @@ class OPENSSL_EXPORT NameConstraints {
|
||||
const GeneralNames &excluded_subtrees() const { return excluded_subtrees_; }
|
||||
|
||||
private:
|
||||
[[nodiscard]] bool Parse(const der::Input &extension_value, bool is_critical,
|
||||
[[nodiscard]] bool Parse(der::Input extension_value, bool is_critical,
|
||||
CertErrors *errors);
|
||||
|
||||
GeneralNames permitted_subtrees_;
|
||||
|
||||
@@ -58,8 +58,7 @@ namespace {
|
||||
}
|
||||
|
||||
::testing::AssertionResult IsPermittedCert(
|
||||
const NameConstraints *name_constraints,
|
||||
const der::Input &subject_rdn_sequence,
|
||||
const NameConstraints *name_constraints, der::Input subject_rdn_sequence,
|
||||
const GeneralNames *subject_alt_names) {
|
||||
CertErrors errors;
|
||||
name_constraints->IsPermittedCert(subject_rdn_sequence, subject_alt_names,
|
||||
|
||||
+20
-23
@@ -37,7 +37,7 @@ OCSPResponse::~OCSPResponse() = default;
|
||||
// issuerKeyHash OCTET STRING, -- Hash of issuer's public key
|
||||
// serialNumber CertificateSerialNumber
|
||||
// }
|
||||
bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out) {
|
||||
bool ParseOCSPCertID(der::Input raw_tlv, OCSPCertID *out) {
|
||||
der::Parser outer_parser(raw_tlv);
|
||||
der::Parser parser;
|
||||
if (!outer_parser.ReadSequence(&parser)) {
|
||||
@@ -82,7 +82,7 @@ namespace {
|
||||
// revocationTime GeneralizedTime,
|
||||
// revocationReason [0] EXPLICIT CRLReason OPTIONAL
|
||||
// }
|
||||
bool ParseRevokedInfo(const der::Input &raw_tlv, OCSPCertStatus *out) {
|
||||
bool ParseRevokedInfo(der::Input raw_tlv, OCSPCertStatus *out) {
|
||||
der::Parser parser(raw_tlv);
|
||||
if (!parser.ReadGeneralizedTime(&(out->revocation_time))) {
|
||||
return false;
|
||||
@@ -130,7 +130,7 @@ bool ParseRevokedInfo(const der::Input &raw_tlv, OCSPCertStatus *out) {
|
||||
// }
|
||||
//
|
||||
// UnknownInfo ::= NULL
|
||||
bool ParseCertStatus(const der::Input &raw_tlv, OCSPCertStatus *out) {
|
||||
bool ParseCertStatus(der::Input raw_tlv, OCSPCertStatus *out) {
|
||||
der::Parser parser(raw_tlv);
|
||||
der::Tag status_tag;
|
||||
der::Input status;
|
||||
@@ -158,13 +158,13 @@ bool ParseCertStatus(const der::Input &raw_tlv, OCSPCertStatus *out) {
|
||||
// Writes the hash of |value| as an OCTET STRING to |cbb|, using |hash_type| as
|
||||
// the algorithm. Returns true on success.
|
||||
bool AppendHashAsOctetString(const EVP_MD *hash_type, CBB *cbb,
|
||||
const der::Input &value) {
|
||||
der::Input value) {
|
||||
CBB octet_string;
|
||||
unsigned hash_len;
|
||||
uint8_t hash_buffer[EVP_MAX_MD_SIZE];
|
||||
|
||||
return CBB_add_asn1(cbb, &octet_string, CBS_ASN1_OCTETSTRING) &&
|
||||
EVP_Digest(value.UnsafeData(), value.Length(), hash_buffer, &hash_len,
|
||||
EVP_Digest(value.data(), value.size(), hash_buffer, &hash_len,
|
||||
hash_type, nullptr) &&
|
||||
CBB_add_bytes(&octet_string, hash_buffer, hash_len) && CBB_flush(cbb);
|
||||
}
|
||||
@@ -178,8 +178,7 @@ bool AppendHashAsOctetString(const EVP_MD *hash_type, CBB *cbb,
|
||||
// nextUpdate [0] EXPLICIT GeneralizedTime OPTIONAL,
|
||||
// singleExtensions [1] EXPLICIT Extensions OPTIONAL
|
||||
// }
|
||||
bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
|
||||
OCSPSingleResponse *out) {
|
||||
bool ParseOCSPSingleResponse(der::Input raw_tlv, OCSPSingleResponse *out) {
|
||||
der::Parser outer_parser(raw_tlv);
|
||||
der::Parser parser;
|
||||
if (!outer_parser.ReadSequence(&parser)) {
|
||||
@@ -235,8 +234,7 @@ namespace {
|
||||
// byName [1] Name,
|
||||
// byKey [2] KeyHash
|
||||
// }
|
||||
bool ParseResponderID(const der::Input &raw_tlv,
|
||||
OCSPResponseData::ResponderID *out) {
|
||||
bool ParseResponderID(der::Input raw_tlv, OCSPResponseData::ResponderID *out) {
|
||||
der::Parser parser(raw_tlv);
|
||||
der::Tag id_tag;
|
||||
der::Input id_input;
|
||||
@@ -256,7 +254,7 @@ bool ParseResponderID(const der::Input &raw_tlv,
|
||||
if (key_parser.HasMore()) {
|
||||
return false;
|
||||
}
|
||||
if (key_hash.Length() != SHA_DIGEST_LENGTH) {
|
||||
if (key_hash.size() != SHA_DIGEST_LENGTH) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -277,7 +275,7 @@ bool ParseResponderID(const der::Input &raw_tlv,
|
||||
// responses SEQUENCE OF SingleResponse,
|
||||
// responseExtensions [1] EXPLICIT Extensions OPTIONAL
|
||||
// }
|
||||
bool ParseOCSPResponseData(const der::Input &raw_tlv, OCSPResponseData *out) {
|
||||
bool ParseOCSPResponseData(der::Input raw_tlv, OCSPResponseData *out) {
|
||||
der::Parser outer_parser(raw_tlv);
|
||||
der::Parser parser;
|
||||
if (!outer_parser.ReadSequence(&parser)) {
|
||||
@@ -357,7 +355,7 @@ namespace {
|
||||
// signature BIT STRING,
|
||||
// certs [0] EXPLICIT SEQUENCE OF Certificate OPTIONAL
|
||||
// }
|
||||
bool ParseBasicOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
|
||||
bool ParseBasicOCSPResponse(der::Input raw_tlv, OCSPResponse *out) {
|
||||
der::Parser outer_parser(raw_tlv);
|
||||
der::Parser parser;
|
||||
if (!outer_parser.ReadSequence(&parser)) {
|
||||
@@ -425,7 +423,7 @@ bool ParseBasicOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
|
||||
// responseType OBJECT IDENTIFIER,
|
||||
// response OCTET STRING
|
||||
// }
|
||||
bool ParseOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
|
||||
bool ParseOCSPResponse(der::Input raw_tlv, OCSPResponse *out) {
|
||||
der::Parser outer_parser(raw_tlv);
|
||||
der::Parser parser;
|
||||
if (!outer_parser.ReadSequence(&parser)) {
|
||||
@@ -494,12 +492,11 @@ bool ParseOCSPResponse(const der::Input &raw_tlv, OCSPResponse *out) {
|
||||
namespace {
|
||||
|
||||
// Checks that the |type| hash of |value| is equal to |hash|
|
||||
bool VerifyHash(const EVP_MD *type, const der::Input &hash,
|
||||
const der::Input &value) {
|
||||
bool VerifyHash(const EVP_MD *type, der::Input hash, der::Input value) {
|
||||
unsigned value_hash_len;
|
||||
uint8_t value_hash[EVP_MAX_MD_SIZE];
|
||||
if (!EVP_Digest(value.UnsafeData(), value.Length(), value_hash,
|
||||
&value_hash_len, type, nullptr)) {
|
||||
if (!EVP_Digest(value.data(), value.size(), value_hash, &value_hash_len, type,
|
||||
nullptr)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -521,10 +518,10 @@ bool VerifyHash(const EVP_MD *type, const der::Input &hash,
|
||||
// algorithm OBJECT IDENTIFIER,
|
||||
// parameters ANY DEFINED BY algorithm OPTIONAL }
|
||||
//
|
||||
bool GetSubjectPublicKeyBytes(const der::Input &spki_tlv, der::Input *spk_tlv) {
|
||||
bool GetSubjectPublicKeyBytes(der::Input spki_tlv, der::Input *spk_tlv) {
|
||||
CBS outer, inner, alg, spk;
|
||||
uint8_t unused_bit_count;
|
||||
CBS_init(&outer, spki_tlv.UnsafeData(), spki_tlv.Length());
|
||||
CBS_init(&outer, spki_tlv.data(), spki_tlv.size());
|
||||
// The subjectPublicKey field includes the unused bit count. For this
|
||||
// application, the unused bit count must be zero, and is not included in
|
||||
// the result. We extract the subjectPubicKey bit string, verify the first
|
||||
@@ -735,7 +732,7 @@ std::shared_ptr<const ParsedCertificate> OCSPParseCertificate(
|
||||
// Parse ResponseData and return false if any unhandled critical extensions are
|
||||
// found. No known critical ResponseData extensions exist.
|
||||
bool ParseOCSPResponseDataExtensions(
|
||||
const der::Input &response_extensions,
|
||||
der::Input response_extensions,
|
||||
OCSPVerifyResult::ResponseStatus *response_details) {
|
||||
std::map<der::Input, ParsedExtension> extensions;
|
||||
if (!ParseExtensions(response_extensions, &extensions)) {
|
||||
@@ -760,7 +757,7 @@ bool ParseOCSPResponseDataExtensions(
|
||||
// to be marked critical, but since it is handled by Chrome, we will overlook
|
||||
// the flag setting.
|
||||
bool ParseOCSPSingleResponseExtensions(
|
||||
const der::Input &single_extensions,
|
||||
der::Input single_extensions,
|
||||
OCSPVerifyResult::ResponseStatus *response_details) {
|
||||
std::map<der::Input, ParsedExtension> extensions;
|
||||
if (!ParseExtensions(single_extensions, &extensions)) {
|
||||
@@ -1060,8 +1057,8 @@ bool CreateOCSPRequest(const ParsedCertificate *cert,
|
||||
if (!CBB_add_asn1(&req_cert, &serial_number, CBS_ASN1_INTEGER)) {
|
||||
return false;
|
||||
}
|
||||
if (!CBB_add_bytes(&serial_number, cert->tbs().serial_number.UnsafeData(),
|
||||
cert->tbs().serial_number.Length())) {
|
||||
if (!CBB_add_bytes(&serial_number, cert->tbs().serial_number.data(),
|
||||
cert->tbs().serial_number.size())) {
|
||||
return false;
|
||||
}
|
||||
|
||||
|
||||
+4
-5
@@ -230,7 +230,7 @@ inline constexpr uint8_t kBasicOCSPResponseOid[] = {
|
||||
//
|
||||
// On failure |out| has an undefined state. Some of its fields may have been
|
||||
// updated during parsing, whereas others may not have been changed.
|
||||
OPENSSL_EXPORT bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out);
|
||||
OPENSSL_EXPORT bool ParseOCSPCertID(der::Input raw_tlv, OCSPCertID *out);
|
||||
|
||||
// Parses a DER-encoded OCSP "SingleResponse" as specified by RFC 6960. Returns
|
||||
// true on success and sets the results in |out|. The resulting |out|
|
||||
@@ -239,7 +239,7 @@ OPENSSL_EXPORT bool ParseOCSPCertID(const der::Input &raw_tlv, OCSPCertID *out);
|
||||
//
|
||||
// On failure |out| has an undefined state. Some of its fields may have been
|
||||
// updated during parsing, whereas others may not have been changed.
|
||||
OPENSSL_EXPORT bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
|
||||
OPENSSL_EXPORT bool ParseOCSPSingleResponse(der::Input raw_tlv,
|
||||
OCSPSingleResponse *out);
|
||||
|
||||
// Parses a DER-encoded OCSP "ResponseData" as specified by RFC 6960. Returns
|
||||
@@ -249,7 +249,7 @@ OPENSSL_EXPORT bool ParseOCSPSingleResponse(const der::Input &raw_tlv,
|
||||
//
|
||||
// On failure |out| has an undefined state. Some of its fields may have been
|
||||
// updated during parsing, whereas others may not have been changed.
|
||||
OPENSSL_EXPORT bool ParseOCSPResponseData(const der::Input &raw_tlv,
|
||||
OPENSSL_EXPORT bool ParseOCSPResponseData(der::Input raw_tlv,
|
||||
OCSPResponseData *out);
|
||||
|
||||
// Parses a DER-encoded "OCSPResponse" as specified by RFC 6960. Returns true
|
||||
@@ -259,8 +259,7 @@ OPENSSL_EXPORT bool ParseOCSPResponseData(const der::Input &raw_tlv,
|
||||
//
|
||||
// On failure |out| has an undefined state. Some of its fields may have been
|
||||
// updated during parsing, whereas others may not have been changed.
|
||||
OPENSSL_EXPORT bool ParseOCSPResponse(const der::Input &raw_tlv,
|
||||
OCSPResponse *out);
|
||||
OPENSSL_EXPORT bool ParseOCSPResponse(der::Input raw_tlv, OCSPResponse *out);
|
||||
|
||||
// Checks the revocation status of the certificate |certificate_der| by using
|
||||
// the DER-encoded |raw_response|.
|
||||
|
||||
@@ -74,7 +74,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
|
||||
"Serial number is not a valid INTEGER");
|
||||
|
||||
// Returns true if |input| is a SEQUENCE and nothing else.
|
||||
[[nodiscard]] bool IsSequenceTLV(const der::Input &input) {
|
||||
[[nodiscard]] bool IsSequenceTLV(der::Input input) {
|
||||
der::Parser parser(input);
|
||||
der::Parser unused_sequence_parser;
|
||||
if (!parser.ReadSequence(&unused_sequence_parser)) {
|
||||
@@ -101,8 +101,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
|
||||
// Implementations SHOULD be prepared to accept any version certificate.
|
||||
// At a minimum, conforming implementations MUST recognize version 3
|
||||
// certificates.
|
||||
[[nodiscard]] bool ParseVersion(const der::Input &in,
|
||||
CertificateVersion *version) {
|
||||
[[nodiscard]] bool ParseVersion(der::Input in, CertificateVersion *version) {
|
||||
der::Parser parser(in);
|
||||
uint64_t version64;
|
||||
if (!parser.ReadUint64(&version64)) {
|
||||
@@ -133,8 +132,8 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
|
||||
[[nodiscard]] bool BitStringIsAllZeros(const der::BitString &bits) {
|
||||
// Note that it is OK to read from the unused bits, since BitString parsing
|
||||
// guarantees they are all zero.
|
||||
for (size_t i = 0; i < bits.bytes().Length(); ++i) {
|
||||
if (bits.bytes()[i] != 0) {
|
||||
for (uint8_t b : bits.bytes()) {
|
||||
if (b != 0) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -148,7 +147,7 @@ DEFINE_CERT_ERROR_ID(kSerialNumberNotValidInteger,
|
||||
// DistributionPointName ::= CHOICE {
|
||||
// fullName [0] GeneralNames,
|
||||
// nameRelativeToCRLIssuer [1] RelativeDistinguishedName }
|
||||
bool ParseDistributionPointName(const der::Input &dp_name,
|
||||
bool ParseDistributionPointName(der::Input dp_name,
|
||||
ParsedDistributionPoint *distribution_point) {
|
||||
der::Parser parser(dp_name);
|
||||
std::optional<der::Input> der_full_name;
|
||||
@@ -250,7 +249,7 @@ ParsedTbsCertificate::ParsedTbsCertificate(ParsedTbsCertificate &&other) =
|
||||
|
||||
ParsedTbsCertificate::~ParsedTbsCertificate() = default;
|
||||
|
||||
bool VerifySerialNumber(const der::Input &value, bool warnings_only,
|
||||
bool VerifySerialNumber(der::Input value, bool warnings_only,
|
||||
CertErrors *errors) {
|
||||
// If |warnings_only| was set to true, the exact same errors will be logged,
|
||||
// only they will be logged with a lower severity (warning rather than error).
|
||||
@@ -271,7 +270,7 @@ bool VerifySerialNumber(const der::Input &value, bool warnings_only,
|
||||
if (negative) {
|
||||
errors->AddWarning(kSerialNumberIsNegative);
|
||||
}
|
||||
if (value.Length() == 1 && value[0] == 0) {
|
||||
if (value.size() == 1 && value[0] == 0) {
|
||||
errors->AddWarning(kSerialNumberIsZero);
|
||||
}
|
||||
|
||||
@@ -280,9 +279,9 @@ bool VerifySerialNumber(const der::Input &value, bool warnings_only,
|
||||
// Certificate users MUST be able to handle serialNumber values up to 20
|
||||
// octets. Conforming CAs MUST NOT use serialNumber values longer than 20
|
||||
// octets.
|
||||
if (value.Length() > 20) {
|
||||
if (value.size() > 20) {
|
||||
errors->Add(error_severity, kSerialNumberLengthOver20,
|
||||
CreateCertErrorParams1SizeT("length", value.Length()));
|
||||
CreateCertErrorParams1SizeT("length", value.size()));
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -309,8 +308,7 @@ bool ReadUTCOrGeneralizedTime(der::Parser *parser, der::GeneralizedTime *out) {
|
||||
return false;
|
||||
}
|
||||
|
||||
bool ParseValidity(const der::Input &validity_tlv,
|
||||
der::GeneralizedTime *not_before,
|
||||
bool ParseValidity(der::Input validity_tlv, der::GeneralizedTime *not_before,
|
||||
der::GeneralizedTime *not_after) {
|
||||
der::Parser parser(validity_tlv);
|
||||
|
||||
@@ -348,7 +346,7 @@ bool ParseValidity(const der::Input &validity_tlv,
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseCertificate(const der::Input &certificate_tlv,
|
||||
bool ParseCertificate(der::Input certificate_tlv,
|
||||
der::Input *out_tbs_certificate_tlv,
|
||||
der::Input *out_signature_algorithm_tlv,
|
||||
der::BitString *out_signature_value,
|
||||
@@ -423,7 +421,7 @@ bool ParseCertificate(const der::Input &certificate_tlv,
|
||||
// extensions [3] EXPLICIT Extensions OPTIONAL
|
||||
// -- If present, version MUST be v3
|
||||
// }
|
||||
bool ParseTbsCertificate(const der::Input &tbs_tlv,
|
||||
bool ParseTbsCertificate(der::Input tbs_tlv,
|
||||
const ParseCertificateOptions &options,
|
||||
ParsedTbsCertificate *out, CertErrors *errors) {
|
||||
// The rest of this function assumes that |errors| is non-null.
|
||||
@@ -608,7 +606,7 @@ bool ParseTbsCertificate(const der::Input &tbs_tlv,
|
||||
// -- corresponding to the extension type identified
|
||||
// -- by extnID
|
||||
// }
|
||||
bool ParseExtension(const der::Input &extension_tlv, ParsedExtension *out) {
|
||||
bool ParseExtension(der::Input extension_tlv, ParsedExtension *out) {
|
||||
der::Parser parser(extension_tlv);
|
||||
|
||||
// Extension ::= SEQUENCE {
|
||||
@@ -659,7 +657,7 @@ bool ParseExtension(const der::Input &extension_tlv, ParsedExtension *out) {
|
||||
}
|
||||
|
||||
OPENSSL_EXPORT bool ParseExtensions(
|
||||
const der::Input &extensions_tlv,
|
||||
der::Input extensions_tlv,
|
||||
std::map<der::Input, ParsedExtension> *extensions) {
|
||||
der::Parser parser(extensions_tlv);
|
||||
|
||||
@@ -708,7 +706,7 @@ OPENSSL_EXPORT bool ParseExtensions(
|
||||
}
|
||||
|
||||
OPENSSL_EXPORT bool ConsumeExtension(
|
||||
const der::Input &oid,
|
||||
der::Input oid,
|
||||
std::map<der::Input, ParsedExtension> *unconsumed_extensions,
|
||||
ParsedExtension *extension) {
|
||||
auto it = unconsumed_extensions->find(oid);
|
||||
@@ -721,7 +719,7 @@ OPENSSL_EXPORT bool ConsumeExtension(
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseBasicConstraints(const der::Input &basic_constraints_tlv,
|
||||
bool ParseBasicConstraints(der::Input basic_constraints_tlv,
|
||||
ParsedBasicConstraints *out) {
|
||||
der::Parser parser(basic_constraints_tlv);
|
||||
|
||||
@@ -780,7 +778,7 @@ bool ParseBasicConstraints(const der::Input &basic_constraints_tlv,
|
||||
|
||||
// TODO(crbug.com/1314019): return std::optional<BitString> when converting
|
||||
// has_key_usage_ and key_usage_ into single std::optional field.
|
||||
bool ParseKeyUsage(const der::Input &key_usage_tlv, der::BitString *key_usage) {
|
||||
bool ParseKeyUsage(der::Input key_usage_tlv, der::BitString *key_usage) {
|
||||
der::Parser parser(key_usage_tlv);
|
||||
std::optional<der::BitString> key_usage_internal = parser.ReadBitString();
|
||||
if (!key_usage_internal) {
|
||||
@@ -805,7 +803,7 @@ bool ParseKeyUsage(const der::Input &key_usage_tlv, der::BitString *key_usage) {
|
||||
}
|
||||
|
||||
bool ParseAuthorityInfoAccess(
|
||||
const der::Input &authority_info_access_tlv,
|
||||
der::Input authority_info_access_tlv,
|
||||
std::vector<AuthorityInfoAccessDescription> *out_access_descriptions) {
|
||||
der::Parser parser(authority_info_access_tlv);
|
||||
|
||||
@@ -853,7 +851,7 @@ bool ParseAuthorityInfoAccess(
|
||||
}
|
||||
|
||||
bool ParseAuthorityInfoAccessURIs(
|
||||
const der::Input &authority_info_access_tlv,
|
||||
der::Input authority_info_access_tlv,
|
||||
std::vector<std::string_view> *out_ca_issuers_uris,
|
||||
std::vector<std::string_view> *out_ocsp_uris) {
|
||||
std::vector<AuthorityInfoAccessDescription> access_descriptions;
|
||||
@@ -896,7 +894,7 @@ ParsedDistributionPoint::ParsedDistributionPoint(
|
||||
ParsedDistributionPoint::~ParsedDistributionPoint() = default;
|
||||
|
||||
bool ParseCrlDistributionPoints(
|
||||
const der::Input &extension_value,
|
||||
der::Input extension_value,
|
||||
std::vector<ParsedDistributionPoint> *distribution_points) {
|
||||
distribution_points->clear();
|
||||
|
||||
@@ -935,7 +933,7 @@ ParsedAuthorityKeyIdentifier &ParsedAuthorityKeyIdentifier::operator=(
|
||||
ParsedAuthorityKeyIdentifier &&other) = default;
|
||||
|
||||
bool ParseAuthorityKeyIdentifier(
|
||||
const der::Input &extension_value,
|
||||
der::Input extension_value,
|
||||
ParsedAuthorityKeyIdentifier *authority_key_identifier) {
|
||||
// RFC 5280, section 4.2.1.1.
|
||||
// AuthorityKeyIdentifier ::= SEQUENCE {
|
||||
@@ -993,7 +991,7 @@ bool ParseAuthorityKeyIdentifier(
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseSubjectKeyIdentifier(const der::Input &extension_value,
|
||||
bool ParseSubjectKeyIdentifier(der::Input extension_value,
|
||||
der::Input *subject_key_identifier) {
|
||||
// SubjectKeyIdentifier ::= KeyIdentifier
|
||||
//
|
||||
|
||||
+15
-15
@@ -56,7 +56,7 @@ struct ParsedTbsCertificate;
|
||||
// |errors| must be a non-null destination for any errors/warnings. If
|
||||
// |warnings_only| is set to true, then what would ordinarily be errors are
|
||||
// instead added as warnings.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool VerifySerialNumber(const der::Input &value,
|
||||
[[nodiscard]] OPENSSL_EXPORT bool VerifySerialNumber(der::Input value,
|
||||
bool warnings_only,
|
||||
CertErrors *errors);
|
||||
|
||||
@@ -81,7 +81,7 @@ struct ParsedTbsCertificate;
|
||||
//
|
||||
// Note that upon success it is NOT guaranteed that |*not_before <= *not_after|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseValidity(
|
||||
const der::Input &validity_tlv, der::GeneralizedTime *not_before,
|
||||
der::Input validity_tlv, der::GeneralizedTime *not_before,
|
||||
der::GeneralizedTime *not_after);
|
||||
|
||||
struct OPENSSL_EXPORT ParseCertificateOptions {
|
||||
@@ -130,7 +130,7 @@ struct OPENSSL_EXPORT ParseCertificateOptions {
|
||||
//
|
||||
// Parsing guarantees that this is a valid BIT STRING.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseCertificate(
|
||||
const der::Input &certificate_tlv, der::Input *out_tbs_certificate_tlv,
|
||||
der::Input certificate_tlv, der::Input *out_tbs_certificate_tlv,
|
||||
der::Input *out_signature_algorithm_tlv,
|
||||
der::BitString *out_signature_value, CertErrors *out_errors);
|
||||
|
||||
@@ -167,7 +167,7 @@ struct OPENSSL_EXPORT ParseCertificateOptions {
|
||||
// -- If present, version MUST be v3
|
||||
// }
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseTbsCertificate(
|
||||
const der::Input &tbs_tlv, const ParseCertificateOptions &options,
|
||||
der::Input tbs_tlv, const ParseCertificateOptions &options,
|
||||
ParsedTbsCertificate *out, CertErrors *errors);
|
||||
|
||||
// Represents a "Version" from RFC 5280:
|
||||
@@ -318,8 +318,8 @@ struct OPENSSL_EXPORT ParsedExtension {
|
||||
//
|
||||
// On failure |out| has an undefined state. Some of its fields may have been
|
||||
// updated during parsing, whereas others may not have been changed.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseExtension(
|
||||
const der::Input &extension_tlv, ParsedExtension *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseExtension(der::Input extension_tlv,
|
||||
ParsedExtension *out);
|
||||
|
||||
// From RFC 5280:
|
||||
//
|
||||
@@ -431,14 +431,14 @@ inline constexpr uint8_t kMSApplicationPoliciesOid[] = {
|
||||
// bytes in |extensions_tlv|, so that data must be kept alive.
|
||||
// On failure |extensions| may be partially written to and should not be used.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseExtensions(
|
||||
const der::Input &extensions_tlv,
|
||||
der::Input extensions_tlv,
|
||||
std::map<der::Input, ParsedExtension> *extensions);
|
||||
|
||||
// Removes the extension with OID |oid| from |unconsumed_extensions| and fills
|
||||
// |extension| with the matching extension value. If there was no extension
|
||||
// matching |oid| then returns |false|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ConsumeExtension(
|
||||
const der::Input &oid,
|
||||
der::Input oid,
|
||||
std::map<der::Input, ParsedExtension> *unconsumed_extensions,
|
||||
ParsedExtension *extension);
|
||||
|
||||
@@ -457,7 +457,7 @@ struct ParsedBasicConstraints {
|
||||
// The maximum allowed value of pathLenConstraints will be whatever can fit
|
||||
// into a uint8_t.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseBasicConstraints(
|
||||
const der::Input &basic_constraints_tlv, ParsedBasicConstraints *out);
|
||||
der::Input basic_constraints_tlv, ParsedBasicConstraints *out);
|
||||
|
||||
// KeyUsageBit contains the index for a particular key usage. The index is
|
||||
// measured from the most significant bit of a bit string.
|
||||
@@ -497,7 +497,7 @@ enum KeyUsageBit {
|
||||
//
|
||||
// To test if a particular key usage is set, call, e.g.:
|
||||
// key_usage->AssertsBit(KEY_USAGE_BIT_DIGITAL_SIGNATURE);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseKeyUsage(const der::Input &key_usage_tlv,
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseKeyUsage(der::Input key_usage_tlv,
|
||||
der::BitString *key_usage);
|
||||
|
||||
struct AuthorityInfoAccessDescription {
|
||||
@@ -514,7 +514,7 @@ struct AuthorityInfoAccessDescription {
|
||||
// No validation is performed on the contents of the
|
||||
// AuthorityInfoAccessDescription fields.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityInfoAccess(
|
||||
const der::Input &authority_info_access_tlv,
|
||||
der::Input authority_info_access_tlv,
|
||||
std::vector<AuthorityInfoAccessDescription> *out_access_descriptions);
|
||||
|
||||
// Parses the Authority Information Access extension defined by RFC 5280,
|
||||
@@ -536,7 +536,7 @@ struct AuthorityInfoAccessDescription {
|
||||
// accessLocation types other than uniformResourceIdentifier are silently
|
||||
// ignored.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityInfoAccessURIs(
|
||||
const der::Input &authority_info_access_tlv,
|
||||
der::Input authority_info_access_tlv,
|
||||
std::vector<std::string_view> *out_ca_issuers_uris,
|
||||
std::vector<std::string_view> *out_ocsp_uris);
|
||||
|
||||
@@ -572,7 +572,7 @@ struct OPENSSL_EXPORT ParsedDistributionPoint {
|
||||
// DistributionPoint). Return true on success, and fills |distribution_points|
|
||||
// with values that reference data in |distribution_points_tlv|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseCrlDistributionPoints(
|
||||
const der::Input &distribution_points_tlv,
|
||||
der::Input distribution_points_tlv,
|
||||
std::vector<ParsedDistributionPoint> *distribution_points);
|
||||
|
||||
// Represents the AuthorityKeyIdentifier extension defined by RFC 5280 section
|
||||
@@ -608,14 +608,14 @@ struct OPENSSL_EXPORT ParsedAuthorityKeyIdentifier {
|
||||
// in |extension_value|. On failure the state of |authority_key_identifier| is
|
||||
// not guaranteed.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseAuthorityKeyIdentifier(
|
||||
const der::Input &extension_value,
|
||||
der::Input extension_value,
|
||||
ParsedAuthorityKeyIdentifier *authority_key_identifier);
|
||||
|
||||
// Parses the value of a subjectKeyIdentifier extension. Returns true on
|
||||
// success and |subject_key_identifier| references data in |extension_value|.
|
||||
// On failure the state of |subject_key_identifier| is not guaranteed.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseSubjectKeyIdentifier(
|
||||
const der::Input &extension_value, der::Input *subject_key_identifier);
|
||||
der::Input extension_value, der::Input *subject_key_identifier);
|
||||
|
||||
} // namespace bssl
|
||||
|
||||
|
||||
+7
-12
@@ -19,7 +19,7 @@ namespace {
|
||||
// string on error.
|
||||
std::string OidToString(der::Input oid) {
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, oid.UnsafeData(), oid.Length());
|
||||
CBS_init(&cbs, oid.data(), oid.size());
|
||||
bssl::UniquePtr<char> text(CBS_asn1_oid_to_text(&cbs));
|
||||
if (!text) {
|
||||
return std::string();
|
||||
@@ -104,8 +104,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
|
||||
if (type_string.empty()) {
|
||||
return false;
|
||||
}
|
||||
value_string =
|
||||
"#" + bssl::string_util::HexEncode(value.UnsafeData(), value.Length());
|
||||
value_string = "#" + bssl::string_util::HexEncode(value);
|
||||
}
|
||||
|
||||
if (value_string.empty()) {
|
||||
@@ -116,7 +115,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
|
||||
|
||||
bool nonprintable = false;
|
||||
for (unsigned int i = 0; i < unescaped.length(); ++i) {
|
||||
unsigned char c = static_cast<unsigned char>(unescaped[i]);
|
||||
uint8_t c = static_cast<uint8_t>(unescaped[i]);
|
||||
if (i == 0 && c == '#') {
|
||||
value_string += "\\#";
|
||||
} else if (i == 0 && c == ' ') {
|
||||
@@ -129,11 +128,8 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
|
||||
value_string += c;
|
||||
} else if (c < 32 || c > 126) {
|
||||
nonprintable = true;
|
||||
std::string h;
|
||||
h += c;
|
||||
value_string +=
|
||||
"\\" + bssl::string_util::HexEncode(
|
||||
reinterpret_cast<const uint8_t *>(h.data()), h.length());
|
||||
"\\" + bssl::string_util::HexEncode(MakeConstSpan(&c, 1));
|
||||
} else {
|
||||
value_string += c;
|
||||
}
|
||||
@@ -142,8 +138,7 @@ bool X509NameAttribute::AsRFC2253String(std::string *out) const {
|
||||
// If we have non-printable characters in a TeletexString, we hex encode
|
||||
// since we don't handle Teletex control codes.
|
||||
if (nonprintable && value_tag == der::kTeletexString) {
|
||||
value_string = "#" + bssl::string_util::HexEncode(value.UnsafeData(),
|
||||
value.Length());
|
||||
value_string = "#" + bssl::string_util::HexEncode(value);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -184,7 +179,7 @@ bool ReadRdn(der::Parser *parser, RelativeDistinguishedName *out) {
|
||||
return out->size() != 0;
|
||||
}
|
||||
|
||||
bool ParseName(const der::Input &name_tlv, RDNSequence *out) {
|
||||
bool ParseName(der::Input name_tlv, RDNSequence *out) {
|
||||
der::Parser name_parser(name_tlv);
|
||||
der::Input name_value;
|
||||
if (!name_parser.ReadTag(der::kSequence, &name_value)) {
|
||||
@@ -193,7 +188,7 @@ bool ParseName(const der::Input &name_tlv, RDNSequence *out) {
|
||||
return ParseNameValue(name_value, out);
|
||||
}
|
||||
|
||||
bool ParseNameValue(const der::Input &name_value, RDNSequence *out) {
|
||||
bool ParseNameValue(der::Input name_value, RDNSequence *out) {
|
||||
der::Parser rdn_sequence_parser(name_value);
|
||||
while (rdn_sequence_parser.HasMore()) {
|
||||
der::Parser rdn_parser;
|
||||
|
||||
@@ -140,11 +140,11 @@ typedef std::vector<RelativeDistinguishedName> RDNSequence;
|
||||
|
||||
// Parses a DER-encoded "Name" as specified by 5280. Returns true on success
|
||||
// and sets the results in |out|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseName(const der::Input &name_tlv,
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseName(der::Input name_tlv,
|
||||
RDNSequence *out);
|
||||
// Parses a DER-encoded "Name" value (without the sequence tag & length) as
|
||||
// specified by 5280. Returns true on success and sets the results in |out|.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseNameValue(const der::Input &name_value,
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseNameValue(der::Input name_value,
|
||||
RDNSequence *out);
|
||||
|
||||
// Formats a RDNSequence |rdn_sequence| per RFC2253 as an ASCII string and
|
||||
|
||||
+31
-32
@@ -16,11 +16,11 @@ namespace bssl::der {
|
||||
|
||||
namespace {
|
||||
|
||||
bool ParseBoolInternal(const Input &in, bool *out, bool relaxed) {
|
||||
bool ParseBoolInternal(Input in, bool *out, bool relaxed) {
|
||||
// According to ITU-T X.690 section 8.2, a bool is encoded as a single octet
|
||||
// where the octet of all zeroes is FALSE and a non-zero value for the octet
|
||||
// is TRUE.
|
||||
if (in.Length() != 1) {
|
||||
if (in.size() != 1) {
|
||||
return false;
|
||||
}
|
||||
ByteReader data(in);
|
||||
@@ -128,28 +128,28 @@ bool ValidateGeneralizedTime(const GeneralizedTime &time) {
|
||||
// Returns the number of bytes of numeric precision in a DER encoded INTEGER
|
||||
// value. |in| must be a valid DER encoding of an INTEGER for this to work.
|
||||
//
|
||||
// Normally the precision of the number is exactly in.Length(). However when
|
||||
// Normally the precision of the number is exactly in.size(). However when
|
||||
// encoding positive numbers using DER it is possible to have a leading zero
|
||||
// (to prevent number from being interpreted as negative).
|
||||
//
|
||||
// For instance a 160-bit positive number might take 21 bytes to encode. This
|
||||
// function will return 20 in such a case.
|
||||
size_t GetUnsignedIntegerLength(const Input &in) {
|
||||
size_t GetUnsignedIntegerLength(Input in) {
|
||||
der::ByteReader reader(in);
|
||||
uint8_t first_byte;
|
||||
if (!reader.ReadByte(&first_byte)) {
|
||||
return 0; // Not valid DER as |in| was empty.
|
||||
}
|
||||
|
||||
if (first_byte == 0 && in.Length() > 1) {
|
||||
return in.Length() - 1;
|
||||
if (first_byte == 0 && in.size() > 1) {
|
||||
return in.size() - 1;
|
||||
}
|
||||
return in.Length();
|
||||
return in.size();
|
||||
}
|
||||
|
||||
} // namespace
|
||||
|
||||
bool ParseBool(const Input &in, bool *out) {
|
||||
bool ParseBool(Input in, bool *out) {
|
||||
return ParseBoolInternal(in, out, false /* relaxed */);
|
||||
}
|
||||
|
||||
@@ -157,7 +157,7 @@ bool ParseBool(const Input &in, bool *out) {
|
||||
// have either all bits zero (false) or all bits one (true). To support
|
||||
// malformed certs, we recognized the BER encoding instead of failing to
|
||||
// parse.
|
||||
bool ParseBoolRelaxed(const Input &in, bool *out) {
|
||||
bool ParseBoolRelaxed(Input in, bool *out) {
|
||||
return ParseBoolInternal(in, out, true /* relaxed */);
|
||||
}
|
||||
|
||||
@@ -165,9 +165,9 @@ bool ParseBoolRelaxed(const Input &in, bool *out) {
|
||||
// in the smallest number of octets. If the encoding consists of more than
|
||||
// one octet, then the bits of the first octet and the most significant bit
|
||||
// of the second octet must not be all zeroes or all ones.
|
||||
bool IsValidInteger(const Input &in, bool *negative) {
|
||||
bool IsValidInteger(Input in, bool *negative) {
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, in.UnsafeData(), in.Length());
|
||||
CBS_init(&cbs, in.data(), in.size());
|
||||
int negative_int;
|
||||
if (!CBS_is_valid_asn1_integer(&cbs, &negative_int)) {
|
||||
return false;
|
||||
@@ -177,7 +177,7 @@ bool IsValidInteger(const Input &in, bool *negative) {
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseUint64(const Input &in, uint64_t *out) {
|
||||
bool ParseUint64(Input in, uint64_t *out) {
|
||||
// Reject non-minimally encoded numbers and negative numbers.
|
||||
bool negative;
|
||||
if (!IsValidInteger(in, &negative) || negative) {
|
||||
@@ -201,7 +201,7 @@ bool ParseUint64(const Input &in, uint64_t *out) {
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseUint8(const Input &in, uint8_t *out) {
|
||||
bool ParseUint8(Input in, uint8_t *out) {
|
||||
// TODO(eroman): Implement this more directly.
|
||||
uint64_t value;
|
||||
if (!ParseUint64(in, &value)) {
|
||||
@@ -216,13 +216,12 @@ bool ParseUint8(const Input &in, uint8_t *out) {
|
||||
return true;
|
||||
}
|
||||
|
||||
BitString::BitString(const Input &bytes, uint8_t unused_bits)
|
||||
BitString::BitString(Input bytes, uint8_t unused_bits)
|
||||
: bytes_(bytes), unused_bits_(unused_bits) {
|
||||
BSSL_CHECK(unused_bits < 8);
|
||||
BSSL_CHECK(unused_bits == 0 || bytes.Length() != 0);
|
||||
BSSL_CHECK(unused_bits == 0 || !bytes.empty());
|
||||
// The unused bits must be zero.
|
||||
BSSL_CHECK(bytes.Length() == 0 ||
|
||||
(bytes[bytes.Length() - 1] & ((1u << unused_bits) - 1)) == 0);
|
||||
BSSL_CHECK(bytes.empty() || (bytes.back() & ((1u << unused_bits) - 1)) == 0);
|
||||
}
|
||||
|
||||
bool BitString::AssertsBit(size_t bit_index) const {
|
||||
@@ -231,7 +230,7 @@ bool BitString::AssertsBit(size_t bit_index) const {
|
||||
|
||||
// If the bit is outside of the bitstring, by definition it is not
|
||||
// asserted.
|
||||
if (byte_index >= bytes_.Length()) {
|
||||
if (byte_index >= bytes_.size()) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -247,7 +246,7 @@ bool BitString::AssertsBit(size_t bit_index) const {
|
||||
return 0 != (byte & (1 << bit_index_in_byte));
|
||||
}
|
||||
|
||||
std::optional<BitString> ParseBitString(const Input &in) {
|
||||
std::optional<BitString> ParseBitString(Input in) {
|
||||
ByteReader reader(in);
|
||||
|
||||
// From ITU-T X.690, section 8.6.2.2 (applies to BER, CER, DER):
|
||||
@@ -274,10 +273,10 @@ std::optional<BitString> ParseBitString(const Input &in) {
|
||||
//
|
||||
// If the bitstring is empty, there shall be no subsequent octets,
|
||||
// and the initial octet shall be zero.
|
||||
if (bytes.Length() == 0) {
|
||||
if (bytes.empty()) {
|
||||
return std::nullopt;
|
||||
}
|
||||
uint8_t last_byte = bytes[bytes.Length() - 1];
|
||||
uint8_t last_byte = bytes.back();
|
||||
|
||||
// From ITU-T X.690, section 11.2.1 (applies to CER and DER, but not BER):
|
||||
//
|
||||
@@ -314,7 +313,7 @@ bool operator>=(const GeneralizedTime &lhs, const GeneralizedTime &rhs) {
|
||||
return !(lhs < rhs);
|
||||
}
|
||||
|
||||
bool ParseUTCTime(const Input &in, GeneralizedTime *value) {
|
||||
bool ParseUTCTime(Input in, GeneralizedTime *value) {
|
||||
ByteReader reader(in);
|
||||
GeneralizedTime time;
|
||||
if (!DecimalStringToUint(reader, 2, &time.year) ||
|
||||
@@ -341,7 +340,7 @@ bool ParseUTCTime(const Input &in, GeneralizedTime *value) {
|
||||
return true;
|
||||
}
|
||||
|
||||
bool ParseGeneralizedTime(const Input &in, GeneralizedTime *value) {
|
||||
bool ParseGeneralizedTime(Input in, GeneralizedTime *value) {
|
||||
ByteReader reader(in);
|
||||
GeneralizedTime time;
|
||||
if (!DecimalStringToUint(reader, 4, &time.year) ||
|
||||
@@ -403,14 +402,14 @@ bool ParsePrintableString(Input in, std::string *out) {
|
||||
bool ParseTeletexStringAsLatin1(Input in, std::string *out) {
|
||||
out->clear();
|
||||
// Convert from Latin-1 to UTF-8.
|
||||
size_t utf8_length = in.Length();
|
||||
for (size_t i = 0; i < in.Length(); i++) {
|
||||
size_t utf8_length = in.size();
|
||||
for (size_t i = 0; i < in.size(); i++) {
|
||||
if (in[i] > 0x7f) {
|
||||
utf8_length++;
|
||||
}
|
||||
}
|
||||
out->reserve(utf8_length);
|
||||
for (size_t i = 0; i < in.Length(); i++) {
|
||||
for (size_t i = 0; i < in.size(); i++) {
|
||||
uint8_t u = in[i];
|
||||
if (u <= 0x7f) {
|
||||
out->push_back(u);
|
||||
@@ -424,14 +423,14 @@ bool ParseTeletexStringAsLatin1(Input in, std::string *out) {
|
||||
}
|
||||
|
||||
bool ParseUniversalString(Input in, std::string *out) {
|
||||
if (in.Length() % 4 != 0) {
|
||||
if (in.size() % 4 != 0) {
|
||||
return false;
|
||||
}
|
||||
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, in.UnsafeData(), in.Length());
|
||||
CBS_init(&cbs, in.data(), in.size());
|
||||
bssl::ScopedCBB cbb;
|
||||
if (!CBB_init(cbb.get(), in.Length())) {
|
||||
if (!CBB_init(cbb.get(), in.size())) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -448,14 +447,14 @@ bool ParseUniversalString(Input in, std::string *out) {
|
||||
}
|
||||
|
||||
bool ParseBmpString(Input in, std::string *out) {
|
||||
if (in.Length() % 2 != 0) {
|
||||
if (in.size() % 2 != 0) {
|
||||
return false;
|
||||
}
|
||||
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, in.UnsafeData(), in.Length());
|
||||
CBS_init(&cbs, in.data(), in.size());
|
||||
bssl::ScopedCBB cbb;
|
||||
if (!CBB_init(cbb.get(), in.Length())) {
|
||||
if (!CBB_init(cbb.get(), in.size())) {
|
||||
return false;
|
||||
}
|
||||
|
||||
|
||||
+10
-13
@@ -18,11 +18,11 @@ namespace bssl::der {
|
||||
// Reads a DER-encoded ASN.1 BOOLEAN value from |in| and puts the resulting
|
||||
// value in |out|. Returns whether the encoded value could successfully be
|
||||
// read.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseBool(const Input &in, bool *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseBool(Input in, bool *out);
|
||||
|
||||
// Like ParseBool, except it is more relaxed in what inputs it accepts: Any
|
||||
// value that is a valid BER encoding will be parsed successfully.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseBoolRelaxed(const Input &in, bool *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseBoolRelaxed(Input in, bool *out);
|
||||
|
||||
// Checks the validity of a DER-encoded ASN.1 INTEGER value from |in|, and
|
||||
// determines the sign of the number. Returns true on success and
|
||||
@@ -32,8 +32,7 @@ namespace bssl::der {
|
||||
// in: The value portion of an INTEGER.
|
||||
// negative: Out parameter that is set to true if the number is negative
|
||||
// and false otherwise (zero is non-negative).
|
||||
[[nodiscard]] OPENSSL_EXPORT bool IsValidInteger(const Input &in,
|
||||
bool *negative);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool IsValidInteger(Input in, bool *negative);
|
||||
|
||||
// Reads a DER-encoded ASN.1 INTEGER value from |in| and puts the resulting
|
||||
// value in |out|. ASN.1 INTEGERs are arbitrary precision; this function is
|
||||
@@ -41,10 +40,10 @@ namespace bssl::der {
|
||||
// and is between 0 and 2^64-1. This function returns false if the value is too
|
||||
// big to fit in a uint64_t, is negative, or if there is an error reading the
|
||||
// integer.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUint64(const Input &in, uint64_t *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUint64(Input in, uint64_t *out);
|
||||
|
||||
// Same as ParseUint64() but for a uint8_t.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUint8(const Input &in, uint8_t *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUint8(Input in, uint8_t *out);
|
||||
|
||||
// The BitString class is a helper for representing a valid parsed BIT STRING.
|
||||
//
|
||||
@@ -59,9 +58,9 @@ class OPENSSL_EXPORT BitString {
|
||||
// |unused_bits| represents the number of bits in the last octet of |bytes|,
|
||||
// starting from the least significant bit, that are unused. It MUST be < 8.
|
||||
// And if bytes is empty, then it MUST be 0.
|
||||
BitString(const Input &bytes, uint8_t unused_bits);
|
||||
BitString(Input bytes, uint8_t unused_bits);
|
||||
|
||||
const Input &bytes() const { return bytes_; }
|
||||
Input bytes() const { return bytes_; }
|
||||
uint8_t unused_bits() const { return unused_bits_; }
|
||||
|
||||
// Returns true if the bit string contains 1 at the specified position.
|
||||
@@ -83,8 +82,7 @@ class OPENSSL_EXPORT BitString {
|
||||
// resulting octet string and number of unused bits.
|
||||
//
|
||||
// On failure, returns std::nullopt.
|
||||
[[nodiscard]] OPENSSL_EXPORT std::optional<BitString> ParseBitString(
|
||||
const Input &in);
|
||||
[[nodiscard]] OPENSSL_EXPORT std::optional<BitString> ParseBitString(Input in);
|
||||
|
||||
struct OPENSSL_EXPORT GeneralizedTime {
|
||||
uint16_t year;
|
||||
@@ -109,15 +107,14 @@ OPENSSL_EXPORT bool operator>=(const GeneralizedTime &lhs,
|
||||
|
||||
// Reads a DER-encoded ASN.1 UTCTime value from |in| and puts the resulting
|
||||
// value in |out|, returning true if the UTCTime could be parsed successfully.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUTCTime(const Input &in,
|
||||
GeneralizedTime *out);
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseUTCTime(Input in, GeneralizedTime *out);
|
||||
|
||||
// Reads a DER-encoded ASN.1 GeneralizedTime value from |in| and puts the
|
||||
// resulting value in |out|, returning true if the GeneralizedTime could
|
||||
// be parsed successfully. This function is even more restrictive than the
|
||||
// DER rules - it follows the rules from RFC5280, which does not allow for
|
||||
// fractional seconds.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralizedTime(const Input &in,
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseGeneralizedTime(Input in,
|
||||
GeneralizedTime *out);
|
||||
|
||||
// Reads a DER-encoded ASN.1 IA5String value from |in| and stores the result in
|
||||
|
||||
@@ -317,7 +317,7 @@ TEST(ParseValuesTest, ParseBitStringEmptyNoUnusedBits) {
|
||||
ASSERT_TRUE(bit_string.has_value());
|
||||
|
||||
EXPECT_EQ(0u, bit_string->unused_bits());
|
||||
EXPECT_EQ(0u, bit_string->bytes().Length());
|
||||
EXPECT_EQ(0u, bit_string->bytes().size());
|
||||
|
||||
EXPECT_FALSE(bit_string->AssertsBit(0));
|
||||
EXPECT_FALSE(bit_string->AssertsBit(1));
|
||||
@@ -349,7 +349,7 @@ TEST(ParseValuesTest, ParseBitStringSevenOneBits) {
|
||||
ASSERT_TRUE(bit_string.has_value());
|
||||
|
||||
EXPECT_EQ(1u, bit_string->unused_bits());
|
||||
EXPECT_EQ(1u, bit_string->bytes().Length());
|
||||
EXPECT_EQ(1u, bit_string->bytes().size());
|
||||
EXPECT_EQ(0xFE, bit_string->bytes()[0]);
|
||||
|
||||
EXPECT_TRUE(bit_string->AssertsBit(0));
|
||||
|
||||
@@ -49,14 +49,14 @@ DEFINE_CERT_ERROR_ID(kFailedParsingAuthorityKeyIdentifier,
|
||||
DEFINE_CERT_ERROR_ID(kFailedParsingSubjectKeyIdentifier,
|
||||
"Failed parsing subject key identifier");
|
||||
|
||||
[[nodiscard]] bool GetSequenceValue(const der::Input &tlv, der::Input *value) {
|
||||
[[nodiscard]] bool GetSequenceValue(der::Input tlv, der::Input *value) {
|
||||
der::Parser parser(tlv);
|
||||
return parser.ReadTag(der::kSequence, value) && !parser.HasMore();
|
||||
}
|
||||
|
||||
} // namespace
|
||||
|
||||
bool ParsedCertificate::GetExtension(const der::Input &extension_oid,
|
||||
bool ParsedCertificate::GetExtension(der::Input extension_oid,
|
||||
ParsedExtension *parsed_extension) const {
|
||||
if (!tbs_.extensions_tlv) {
|
||||
return false;
|
||||
@@ -183,7 +183,7 @@ std::shared_ptr<const ParsedCertificate> ParsedCertificate::Create(
|
||||
// extension (e.g., a key bound only to an email address or URI), then the
|
||||
// subject name MUST be an empty sequence and the subjectAltName extension
|
||||
// MUST be critical.
|
||||
if (subject_value.Length() == 0 &&
|
||||
if (subject_value.empty() &&
|
||||
!result->subject_alt_names_extension_.critical) {
|
||||
errors->AddError(kSubjectAltNameNotCritical);
|
||||
return nullptr;
|
||||
|
||||
@@ -76,15 +76,15 @@ class OPENSSL_EXPORT ParsedCertificate {
|
||||
ParsedCertificate &operator=(const ParsedCertificate &) = delete;
|
||||
|
||||
// Returns the DER-encoded certificate data for this cert.
|
||||
const der::Input &der_cert() const { return cert_; }
|
||||
der::Input der_cert() const { return cert_; }
|
||||
|
||||
// Returns the CRYPTO_BUFFER backing this object.
|
||||
CRYPTO_BUFFER *cert_buffer() const { return cert_data_.get(); }
|
||||
|
||||
// Accessors for raw fields of the Certificate.
|
||||
const der::Input &tbs_certificate_tlv() const { return tbs_certificate_tlv_; }
|
||||
der::Input tbs_certificate_tlv() const { return tbs_certificate_tlv_; }
|
||||
|
||||
const der::Input &signature_algorithm_tlv() const {
|
||||
der::Input signature_algorithm_tlv() const {
|
||||
return signature_algorithm_tlv_;
|
||||
}
|
||||
|
||||
@@ -245,7 +245,7 @@ class OPENSSL_EXPORT ParsedCertificate {
|
||||
|
||||
// Gets the value for extension matching |extension_oid|. Returns false if the
|
||||
// extension is not present.
|
||||
bool GetExtension(const der::Input &extension_oid,
|
||||
bool GetExtension(der::Input extension_oid,
|
||||
ParsedExtension *parsed_extension) const;
|
||||
|
||||
private:
|
||||
|
||||
@@ -232,7 +232,7 @@ TEST(ParsedCertificateTest, ExtendedKeyUsage) {
|
||||
ASSERT_TRUE(cert->GetExtension(der::Input(kExtKeyUsageOid), &extension));
|
||||
|
||||
EXPECT_FALSE(extension.critical);
|
||||
EXPECT_EQ(45u, extension.value.Length());
|
||||
EXPECT_EQ(45u, extension.value.size());
|
||||
|
||||
EXPECT_TRUE(cert->has_extended_key_usage());
|
||||
EXPECT_EQ(4u, cert->extended_key_usage().size());
|
||||
@@ -268,7 +268,7 @@ TEST(ParsedCertificateTest, Policies) {
|
||||
cert->GetExtension(der::Input(kCertificatePoliciesOid), &extension));
|
||||
|
||||
EXPECT_FALSE(extension.critical);
|
||||
EXPECT_EQ(95u, extension.value.Length());
|
||||
EXPECT_EQ(95u, extension.value.size());
|
||||
|
||||
EXPECT_TRUE(cert->has_policy_oids());
|
||||
EXPECT_EQ(2u, cert->policy_oids().size());
|
||||
@@ -320,7 +320,7 @@ TEST(ParsedCertificateTest, ExtensionsReal) {
|
||||
cert->GetExtension(der::Input(kCertificatePoliciesOid), &extension));
|
||||
|
||||
EXPECT_FALSE(extension.critical);
|
||||
EXPECT_EQ(16u, extension.value.Length());
|
||||
EXPECT_EQ(16u, extension.value.size());
|
||||
|
||||
// TODO(eroman): Verify the other extensions' values.
|
||||
}
|
||||
|
||||
+1
-3
@@ -11,9 +11,7 @@ namespace bssl::der {
|
||||
|
||||
Parser::Parser() { CBS_init(&cbs_, nullptr, 0); }
|
||||
|
||||
Parser::Parser(const Input &input) {
|
||||
CBS_init(&cbs_, input.UnsafeData(), input.Length());
|
||||
}
|
||||
Parser::Parser(Input input) { CBS_init(&cbs_, input.data(), input.size()); }
|
||||
|
||||
bool Parser::PeekTagAndValue(Tag *tag, Input *out) {
|
||||
CBS peeker = cbs_;
|
||||
|
||||
+2
-2
@@ -72,7 +72,7 @@ struct GeneralizedTime;
|
||||
// following code shows an example of how to parse the quux field from the
|
||||
// encoded data.
|
||||
//
|
||||
// bool ReadQuux(const Input& encoded_value, Input* quux_out) {
|
||||
// bool ReadQuux(Input encoded_value, Input* quux_out) {
|
||||
// Parser parser(encoded_value);
|
||||
// Parser foo_parser;
|
||||
// if (!parser.ReadSequence(&foo_parser))
|
||||
@@ -93,7 +93,7 @@ class OPENSSL_EXPORT Parser {
|
||||
// Creates a parser to parse over the data represented by input. This class
|
||||
// assumes that the underlying data will not change over the lifetime of
|
||||
// the Parser object.
|
||||
explicit Parser(const Input &input);
|
||||
explicit Parser(Input input);
|
||||
|
||||
Parser(const Parser &) = default;
|
||||
Parser &operator=(const Parser &) = default;
|
||||
|
||||
@@ -347,7 +347,7 @@ TEST(ParserTest, ReadBitString) {
|
||||
EXPECT_FALSE(parser.HasMore());
|
||||
|
||||
EXPECT_EQ(1u, bit_string->unused_bits());
|
||||
ASSERT_EQ(2u, bit_string->bytes().Length());
|
||||
ASSERT_EQ(2u, bit_string->bytes().size());
|
||||
EXPECT_EQ(0xAA, bit_string->bytes()[0]);
|
||||
EXPECT_EQ(0xBE, bit_string->bytes()[1]);
|
||||
}
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -32,8 +32,8 @@ using CertIssuerSources = std::vector<CertIssuerSource *>;
|
||||
// Returns a hex-encoded sha256 of the DER-encoding of |cert|.
|
||||
std::string FingerPrintParsedCertificate(const bssl::ParsedCertificate *cert) {
|
||||
uint8_t digest[SHA256_DIGEST_LENGTH];
|
||||
SHA256(cert->der_cert().UnsafeData(), cert->der_cert().Length(), digest);
|
||||
return bssl::string_util::HexEncode(digest, sizeof(digest));
|
||||
SHA256(cert->der_cert().data(), cert->der_cert().size(), digest);
|
||||
return bssl::string_util::HexEncode(digest);
|
||||
}
|
||||
|
||||
// TODO(mattm): decide how much debug logging to keep.
|
||||
@@ -621,7 +621,8 @@ bool CertPathIter::GetNextPath(ParsedCertificateList *out_certs,
|
||||
// trusted root.
|
||||
if (!cur_path_.Empty()) {
|
||||
if (delegate->IsDebugLogEnabled()) {
|
||||
delegate->DebugLog("Issuer is a trust leaf, considering as UNSPECIFIED");
|
||||
delegate->DebugLog(
|
||||
"Issuer is a trust leaf, considering as UNSPECIFIED");
|
||||
}
|
||||
next_issuer_.trust = CertificateTrust::ForUnspecified();
|
||||
}
|
||||
@@ -692,7 +693,8 @@ bool CertPathIter::GetNextPath(ParsedCertificateList *out_certs,
|
||||
std::move(next_issuer_.cert), &cert_issuer_sources_, trust_store_));
|
||||
next_issuer_ = IssuerEntry();
|
||||
if (delegate->IsDebugLogEnabled()) {
|
||||
delegate->DebugLog("CertPathIter cur_path_ =\n" + cur_path_.PathDebugString());
|
||||
delegate->DebugLog("CertPathIter cur_path_ =\n" +
|
||||
cur_path_.PathDebugString());
|
||||
}
|
||||
// Continue descending the tree.
|
||||
continue;
|
||||
|
||||
@@ -238,8 +238,7 @@ class PathBuilderPkitsTestDelegate {
|
||||
const bssl::CertPathBuilderResultPath *result_path =
|
||||
result.paths[i].get();
|
||||
msg << "path " << i << " errors:\n"
|
||||
<< result_path->errors.ToDebugString(result_path->certs)
|
||||
<< "\n";
|
||||
<< result_path->errors.ToDebugString(result_path->certs) << "\n";
|
||||
}
|
||||
ASSERT_EQ(info.should_validate, result.HasValidPath()) << msg;
|
||||
}
|
||||
|
||||
@@ -1362,9 +1362,7 @@ TEST_F(PathBuilderKeyRolloverTest, ExplorePathsWithPathLimit) {
|
||||
{0, 4}, // No path limit. Three valid, one partial path should be built
|
||||
{1, 1}, // One valid path
|
||||
{2, 3}, // Two valid, one partial
|
||||
{3, 4},
|
||||
{4, 4},
|
||||
{5, 4},
|
||||
{3, 4}, {4, 4}, {5, 4},
|
||||
};
|
||||
|
||||
// Trust both old and new roots.
|
||||
@@ -1523,9 +1521,9 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateIntermediates) {
|
||||
// Create a separate copy of oldintermediate.
|
||||
std::shared_ptr<const ParsedCertificate> oldintermediate_dupe(
|
||||
ParsedCertificate::Create(
|
||||
bssl::UniquePtr<CRYPTO_BUFFER>(CRYPTO_BUFFER_new(
|
||||
oldintermediate_->der_cert().UnsafeData(),
|
||||
oldintermediate_->der_cert().Length(), nullptr)),
|
||||
bssl::UniquePtr<CRYPTO_BUFFER>(
|
||||
CRYPTO_BUFFER_new(oldintermediate_->der_cert().data(),
|
||||
oldintermediate_->der_cert().size(), nullptr)),
|
||||
{}, nullptr));
|
||||
|
||||
// Only newroot is a trusted root.
|
||||
@@ -1590,8 +1588,8 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateIntermediateAndRoot) {
|
||||
std::shared_ptr<const ParsedCertificate> newroot_dupe(
|
||||
ParsedCertificate::Create(
|
||||
bssl::UniquePtr<CRYPTO_BUFFER>(
|
||||
CRYPTO_BUFFER_new(newroot_->der_cert().UnsafeData(),
|
||||
newroot_->der_cert().Length(), nullptr)),
|
||||
CRYPTO_BUFFER_new(newroot_->der_cert().data(),
|
||||
newroot_->der_cert().size(), nullptr)),
|
||||
{}, nullptr));
|
||||
|
||||
// Only newroot is a trusted root.
|
||||
@@ -1784,9 +1782,9 @@ TEST_F(PathBuilderKeyRolloverTest, TestDuplicateAsyncIntermediates) {
|
||||
|
||||
std::shared_ptr<const ParsedCertificate> oldintermediate_dupe(
|
||||
ParsedCertificate::Create(
|
||||
bssl::UniquePtr<CRYPTO_BUFFER>(CRYPTO_BUFFER_new(
|
||||
oldintermediate_->der_cert().UnsafeData(),
|
||||
oldintermediate_->der_cert().Length(), nullptr)),
|
||||
bssl::UniquePtr<CRYPTO_BUFFER>(
|
||||
CRYPTO_BUFFER_new(oldintermediate_->der_cert().data(),
|
||||
oldintermediate_->der_cert().size(), nullptr)),
|
||||
{}, nullptr));
|
||||
|
||||
EXPECT_CALL(*target_issuers_req, GetNext(_))
|
||||
|
||||
@@ -122,13 +122,8 @@ const uint8_t kOidRsaSsaPss[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
|
||||
const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
|
||||
0x0d, 0x01, 0x01, 0x08};
|
||||
|
||||
// Returns true if |input| is empty.
|
||||
[[nodiscard]] bool IsEmpty(const der::Input &input) {
|
||||
return input.Length() == 0;
|
||||
}
|
||||
|
||||
// Returns true if the entirety of the input is a NULL value.
|
||||
[[nodiscard]] bool IsNull(const der::Input &input) {
|
||||
[[nodiscard]] bool IsNull(der::Input input) {
|
||||
der::Parser parser(input);
|
||||
der::Input null_value;
|
||||
if (!parser.ReadTag(der::kNull, &null_value)) {
|
||||
@@ -136,7 +131,7 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
|
||||
}
|
||||
|
||||
// NULL values are TLV encoded; the value is expected to be empty.
|
||||
if (!IsEmpty(null_value)) {
|
||||
if (!null_value.empty()) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -144,8 +139,8 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
|
||||
return !parser.HasMore();
|
||||
}
|
||||
|
||||
[[nodiscard]] bool IsNullOrEmpty(const der::Input &input) {
|
||||
return IsNull(input) || IsEmpty(input);
|
||||
[[nodiscard]] bool IsNullOrEmpty(der::Input input) {
|
||||
return IsNull(input) || input.empty();
|
||||
}
|
||||
|
||||
// Parses a MaskGenAlgorithm as defined by RFC 5912:
|
||||
@@ -215,7 +210,7 @@ const uint8_t kOidMgf1[] = {0x2a, 0x86, 0x48, 0x86, 0xf7,
|
||||
// Note also that DER encoding (ITU-T X.690 section 11.5) prohibits
|
||||
// specifying default values explicitly. The parameter should instead be
|
||||
// omitted to indicate a default value.
|
||||
std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input ¶ms) {
|
||||
std::optional<SignatureAlgorithm> ParseRsaPss(der::Input params) {
|
||||
der::Parser parser(params);
|
||||
der::Parser params_parser;
|
||||
if (!parser.ReadSequence(¶ms_parser)) {
|
||||
@@ -273,7 +268,7 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input ¶ms) {
|
||||
|
||||
} // namespace
|
||||
|
||||
[[nodiscard]] bool ParseAlgorithmIdentifier(const der::Input &input,
|
||||
[[nodiscard]] bool ParseAlgorithmIdentifier(der::Input input,
|
||||
der::Input *algorithm,
|
||||
der::Input *parameters) {
|
||||
der::Parser parser(input);
|
||||
@@ -308,10 +303,9 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input ¶ms) {
|
||||
return !algorithm_identifier_parser.HasMore();
|
||||
}
|
||||
|
||||
[[nodiscard]] bool ParseHashAlgorithm(const der::Input &input,
|
||||
DigestAlgorithm *out) {
|
||||
[[nodiscard]] bool ParseHashAlgorithm(der::Input input, DigestAlgorithm *out) {
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, input.UnsafeData(), input.Length());
|
||||
CBS_init(&cbs, input.data(), input.size());
|
||||
const EVP_MD *md = EVP_parse_digest_algorithm(&cbs);
|
||||
|
||||
if (md == EVP_sha1()) {
|
||||
@@ -332,7 +326,7 @@ std::optional<SignatureAlgorithm> ParseRsaPss(const der::Input ¶ms) {
|
||||
}
|
||||
|
||||
std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
|
||||
const der::Input &algorithm_identifier) {
|
||||
der::Input algorithm_identifier) {
|
||||
der::Input oid;
|
||||
der::Input params;
|
||||
if (!ParseAlgorithmIdentifier(algorithm_identifier, &oid, ¶ms)) {
|
||||
@@ -365,16 +359,16 @@ std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
|
||||
|
||||
// RFC 5912 requires that the parameters for ECDSA algorithms be absent
|
||||
// ("PARAMS TYPE NULL ARE absent"):
|
||||
if (oid == der::Input(kOidEcdsaWithSha1) && IsEmpty(params)) {
|
||||
if (oid == der::Input(kOidEcdsaWithSha1) && params.empty()) {
|
||||
return SignatureAlgorithm::kEcdsaSha1;
|
||||
}
|
||||
if (oid == der::Input(kOidEcdsaWithSha256) && IsEmpty(params)) {
|
||||
if (oid == der::Input(kOidEcdsaWithSha256) && params.empty()) {
|
||||
return SignatureAlgorithm::kEcdsaSha256;
|
||||
}
|
||||
if (oid == der::Input(kOidEcdsaWithSha384) && IsEmpty(params)) {
|
||||
if (oid == der::Input(kOidEcdsaWithSha384) && params.empty()) {
|
||||
return SignatureAlgorithm::kEcdsaSha384;
|
||||
}
|
||||
if (oid == der::Input(kOidEcdsaWithSha512) && IsEmpty(params)) {
|
||||
if (oid == der::Input(kOidEcdsaWithSha512) && params.empty()) {
|
||||
return SignatureAlgorithm::kEcdsaSha512;
|
||||
}
|
||||
|
||||
|
||||
@@ -54,7 +54,7 @@ enum class SignatureAlgorithm {
|
||||
// algorithm OBJECT IDENTIFIER,
|
||||
// parameters ANY DEFINED BY algorithm OPTIONAL }
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParseAlgorithmIdentifier(
|
||||
const der::Input &input, der::Input *algorithm, der::Input *parameters);
|
||||
der::Input input, der::Input *algorithm, der::Input *parameters);
|
||||
|
||||
// Parses a HashAlgorithm as defined by RFC 5912:
|
||||
//
|
||||
@@ -68,14 +68,13 @@ enum class SignatureAlgorithm {
|
||||
// { IDENTIFIER id-sha384 PARAMS TYPE NULL ARE preferredPresent } |
|
||||
// { IDENTIFIER id-sha512 PARAMS TYPE NULL ARE preferredPresent }
|
||||
// }
|
||||
[[nodiscard]] bool ParseHashAlgorithm(const der::Input &input,
|
||||
DigestAlgorithm *out);
|
||||
[[nodiscard]] bool ParseHashAlgorithm(der::Input input, DigestAlgorithm *out);
|
||||
|
||||
// Parses an AlgorithmIdentifier into a signature algorithm and returns it, or
|
||||
// returns `std::nullopt` if `algorithm_identifer` either cannot be parsed or
|
||||
// is not a recognized signature algorithm.
|
||||
OPENSSL_EXPORT std::optional<SignatureAlgorithm> ParseSignatureAlgorithm(
|
||||
const der::Input &algorithm_identifier);
|
||||
der::Input algorithm_identifier);
|
||||
|
||||
// Returns the hash to be used with the tls-server-end-point channel binding
|
||||
// (RFC 5929) or `std::nullopt`, if not supported for this signature algorithm.
|
||||
|
||||
@@ -71,11 +71,11 @@ bool StartsWith(std::string_view str, std::string_view prefix) {
|
||||
return prefix.size() <= str.size() && prefix == str.substr(0, prefix.size());
|
||||
}
|
||||
|
||||
std::string HexEncode(const uint8_t *data, size_t length) {
|
||||
std::string HexEncode(Span<const uint8_t> data) {
|
||||
std::ostringstream out;
|
||||
for (size_t i = 0; i < length; i++) {
|
||||
for (uint8_t b : data) {
|
||||
out << std::hex << std::setfill('0') << std::setw(2) << std::uppercase
|
||||
<< int{data[i]};
|
||||
<< int{b};
|
||||
}
|
||||
return out.str();
|
||||
}
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
#include <vector>
|
||||
|
||||
#include <openssl/base.h>
|
||||
#include <openssl/span.h>
|
||||
|
||||
namespace bssl::string_util {
|
||||
|
||||
@@ -44,8 +45,8 @@ OPENSSL_EXPORT bool StartsWith(std::string_view str, std::string_view prefix);
|
||||
// Compares |str1| and |suffix|. Returns true if |str1| ends with |suffix|.
|
||||
OPENSSL_EXPORT bool EndsWith(std::string_view str, std::string_view suffix);
|
||||
|
||||
// Returns a hexadecimal string encoding |data| of length |length|.
|
||||
OPENSSL_EXPORT std::string HexEncode(const uint8_t *data, size_t length);
|
||||
// Returns a hexadecimal string encoding |data|.
|
||||
OPENSSL_EXPORT std::string HexEncode(Span<const uint8_t> data);
|
||||
|
||||
// Returns a decimal string representation of |i|.
|
||||
OPENSSL_EXPORT std::string NumberToDecimalString(int i);
|
||||
|
||||
@@ -99,10 +99,10 @@ TEST(StringUtilTest, StartsWithNoCase) {
|
||||
}
|
||||
|
||||
TEST(StringUtilTest, HexEncode) {
|
||||
std::string hex(bssl::string_util::HexEncode(nullptr, 0));
|
||||
std::string hex(bssl::string_util::HexEncode({}));
|
||||
EXPECT_EQ(hex.length(), 0U);
|
||||
uint8_t bytes[] = {0x01, 0xff, 0x02, 0xfe, 0x03, 0x80, 0x81};
|
||||
hex = bssl::string_util::HexEncode(bytes, sizeof(bytes));
|
||||
hex = bssl::string_util::HexEncode(bytes);
|
||||
EXPECT_EQ(hex, "01FF02FE038081");
|
||||
}
|
||||
|
||||
|
||||
@@ -47,11 +47,10 @@ bool GetValue(std::string_view prefix, std::string_view line,
|
||||
// hex-encoded string on error.
|
||||
std::string OidToString(der::Input oid) {
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, oid.UnsafeData(), oid.Length());
|
||||
CBS_init(&cbs, oid.data(), oid.size());
|
||||
bssl::UniquePtr<char> text(CBS_asn1_oid_to_text(&cbs));
|
||||
if (!text) {
|
||||
return "invalid:" +
|
||||
bssl::string_util::HexEncode(oid.UnsafeData(), oid.Length());
|
||||
return "invalid:" + bssl::string_util::HexEncode(oid);
|
||||
}
|
||||
return text.get();
|
||||
}
|
||||
@@ -130,14 +129,14 @@ std::string GetTestRoot(void) {
|
||||
|
||||
namespace der {
|
||||
|
||||
void PrintTo(const Input &data, ::std::ostream *os) {
|
||||
void PrintTo(Input data, ::std::ostream *os) {
|
||||
size_t len;
|
||||
if (!EVP_EncodedLength(&len, data.Length())) {
|
||||
if (!EVP_EncodedLength(&len, data.size())) {
|
||||
*os << "[]";
|
||||
return;
|
||||
}
|
||||
std::vector<uint8_t> encoded(len);
|
||||
len = EVP_EncodeBlock(encoded.data(), data.UnsafeData(), data.Length());
|
||||
len = EVP_EncodeBlock(encoded.data(), data.data(), data.size());
|
||||
// Skip the trailing \0.
|
||||
std::string b64_encoded(encoded.begin(), encoded.begin() + len);
|
||||
*os << "[" << b64_encoded << "]";
|
||||
@@ -507,7 +506,7 @@ void VerifyUserConstrainedPolicySet(
|
||||
const std::set<der::Input> &actual_user_constrained_policy_set,
|
||||
const std::string &errors_file_path) {
|
||||
std::set<std::string> actual_user_constrained_policy_str_set;
|
||||
for (const der::Input &der_oid : actual_user_constrained_policy_set) {
|
||||
for (der::Input der_oid : actual_user_constrained_policy_set) {
|
||||
actual_user_constrained_policy_str_set.insert(OidToString(der_oid));
|
||||
}
|
||||
if (expected_user_constrained_policy_str_set !=
|
||||
|
||||
@@ -24,7 +24,7 @@ namespace bssl {
|
||||
namespace der {
|
||||
|
||||
// This function is used by GTest to support EXPECT_EQ() for der::Input.
|
||||
void PrintTo(const Input &data, ::std::ostream *os);
|
||||
void PrintTo(Input data, ::std::ostream *os);
|
||||
|
||||
} // namespace der
|
||||
|
||||
|
||||
@@ -5,8 +5,8 @@
|
||||
#ifndef BSSL_PKI_TRUST_STORE_IN_MEMORY_H_
|
||||
#define BSSL_PKI_TRUST_STORE_IN_MEMORY_H_
|
||||
|
||||
#include <unordered_map>
|
||||
#include <set>
|
||||
#include <unordered_map>
|
||||
|
||||
#include <openssl/base.h>
|
||||
|
||||
|
||||
@@ -150,8 +150,8 @@ void VerifyTimeValidity(const ParsedCertificate &cert,
|
||||
// compatibility sake.
|
||||
bool VerifySignatureAlgorithmsMatch(const ParsedCertificate &cert,
|
||||
CertErrors *errors) {
|
||||
const der::Input &alg1_tlv = cert.signature_algorithm_tlv();
|
||||
const der::Input &alg2_tlv = cert.tbs().signature_algorithm_tlv;
|
||||
der::Input alg1_tlv = cert.signature_algorithm_tlv();
|
||||
der::Input alg2_tlv = cert.tbs().signature_algorithm_tlv;
|
||||
|
||||
// Ensure that the two DER-encoded signature algorithms are byte-for-byte
|
||||
// equal.
|
||||
@@ -690,7 +690,7 @@ class PathVerifier {
|
||||
// Parses |spki| to an EVP_PKEY and checks whether the public key is accepted
|
||||
// by |delegate_|. On failure parsing returns nullptr. If either parsing the
|
||||
// key or key policy failed, adds a high-severity error to |errors|.
|
||||
bssl::UniquePtr<EVP_PKEY> ParseAndCheckPublicKey(const der::Input &spki,
|
||||
bssl::UniquePtr<EVP_PKEY> ParseAndCheckPublicKey(der::Input spki,
|
||||
CertErrors *errors);
|
||||
|
||||
ValidPolicyGraph valid_policy_graph_;
|
||||
@@ -799,7 +799,7 @@ void PathVerifier::VerifyPolicies(const ParsedCertificate &cert,
|
||||
// for policy P and P-Q denote the qualifier set for policy
|
||||
// P. Perform the following steps in order:
|
||||
bool cert_has_any_policy = false;
|
||||
for (const der::Input &p_oid : cert.policy_oids()) {
|
||||
for (der::Input p_oid : cert.policy_oids()) {
|
||||
if (p_oid == der::Input(kAnyPolicyOid)) {
|
||||
cert_has_any_policy = true;
|
||||
continue;
|
||||
@@ -1431,7 +1431,7 @@ void PathVerifier::ProcessSingleCertChain(const ParsedCertificate &cert,
|
||||
}
|
||||
|
||||
bssl::UniquePtr<EVP_PKEY> PathVerifier::ParseAndCheckPublicKey(
|
||||
const der::Input &spki, CertErrors *errors) {
|
||||
der::Input spki, CertErrors *errors) {
|
||||
// Parse the public key.
|
||||
bssl::UniquePtr<EVP_PKEY> pkey;
|
||||
if (!ParsePublicKey(spki, &pkey)) {
|
||||
|
||||
@@ -258,7 +258,7 @@ enum NameMatchType {
|
||||
//
|
||||
// RelativeDistinguishedName ::=
|
||||
// SET SIZE (1..MAX) OF AttributeTypeAndValue
|
||||
bool VerifyNameMatchInternal(const der::Input &a, const der::Input &b,
|
||||
bool VerifyNameMatchInternal(der::Input a, der::Input b,
|
||||
NameMatchType match_type) {
|
||||
// Empty Names are allowed. RFC 5280 section 4.1.2.4 requires "The issuer
|
||||
// field MUST contain a non-empty distinguished name (DN)", while section
|
||||
@@ -308,7 +308,7 @@ bool VerifyNameMatchInternal(const der::Input &a, const der::Input &b,
|
||||
|
||||
} // namespace
|
||||
|
||||
bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
bool NormalizeName(der::Input name_rdn_sequence,
|
||||
std::string *normalized_rdn_sequence, CertErrors *errors) {
|
||||
BSSL_CHECK(errors);
|
||||
|
||||
@@ -350,8 +350,8 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
// AttributeType ::= OBJECT IDENTIFIER
|
||||
if (!CBB_add_asn1(&attribute_type_and_value_cbb, &type_cbb,
|
||||
CBS_ASN1_OBJECT) ||
|
||||
!CBB_add_bytes(&type_cbb, type_and_value.type.UnsafeData(),
|
||||
type_and_value.type.Length())) {
|
||||
!CBB_add_bytes(&type_cbb, type_and_value.type.data(),
|
||||
type_and_value.type.size())) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -372,8 +372,8 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
} else {
|
||||
if (!CBB_add_asn1(&attribute_type_and_value_cbb, &value_cbb,
|
||||
type_and_value.value_tag) ||
|
||||
!CBB_add_bytes(&value_cbb, type_and_value.value.UnsafeData(),
|
||||
type_and_value.value.Length())) {
|
||||
!CBB_add_bytes(&value_cbb, type_and_value.value.data(),
|
||||
type_and_value.value.size())) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -394,19 +394,18 @@ bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
return true;
|
||||
}
|
||||
|
||||
bool VerifyNameMatch(const der::Input &a_rdn_sequence,
|
||||
const der::Input &b_rdn_sequence) {
|
||||
bool VerifyNameMatch(der::Input a_rdn_sequence, der::Input b_rdn_sequence) {
|
||||
return VerifyNameMatchInternal(a_rdn_sequence, b_rdn_sequence, EXACT_MATCH);
|
||||
}
|
||||
|
||||
bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
|
||||
const der::Input &parent_rdn_sequence) {
|
||||
bool VerifyNameInSubtree(der::Input name_rdn_sequence,
|
||||
der::Input parent_rdn_sequence) {
|
||||
return VerifyNameMatchInternal(name_rdn_sequence, parent_rdn_sequence,
|
||||
SUBTREE_MATCH);
|
||||
}
|
||||
|
||||
bool FindEmailAddressesInName(
|
||||
const der::Input &name_rdn_sequence,
|
||||
der::Input name_rdn_sequence,
|
||||
std::vector<std::string> *contained_email_addresses) {
|
||||
contained_email_addresses->clear();
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@ class Input;
|
||||
// outer Sequence tag). Returns false if there was an error parsing or
|
||||
// normalizing the input, and adds error information to |errors|. |errors| must
|
||||
// be non-null.
|
||||
OPENSSL_EXPORT bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
OPENSSL_EXPORT bool NormalizeName(der::Input name_rdn_sequence,
|
||||
std::string *normalized_rdn_sequence,
|
||||
CertErrors *errors);
|
||||
|
||||
@@ -32,16 +32,16 @@ OPENSSL_EXPORT bool NormalizeName(const der::Input &name_rdn_sequence,
|
||||
// |a_rdn_sequence| and |b_rdn_sequence| should be the DER-encoded RDNSequence
|
||||
// values (not including the Sequence tag).
|
||||
// Returns true if |a_rdn_sequence| and |b_rdn_sequence| match.
|
||||
OPENSSL_EXPORT bool VerifyNameMatch(const der::Input &a_rdn_sequence,
|
||||
const der::Input &b_rdn_sequence);
|
||||
OPENSSL_EXPORT bool VerifyNameMatch(der::Input a_rdn_sequence,
|
||||
der::Input b_rdn_sequence);
|
||||
|
||||
// Compares |name_rdn_sequence| and |parent_rdn_sequence| and return true if
|
||||
// |name_rdn_sequence| is within the subtree defined by |parent_rdn_sequence| as
|
||||
// defined by RFC 5280 section 7.1. |name_rdn_sequence| and
|
||||
// |parent_rdn_sequence| should be the DER-encoded sequence values (not
|
||||
// including the Sequence tag).
|
||||
OPENSSL_EXPORT bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
|
||||
const der::Input &parent_rdn_sequence);
|
||||
OPENSSL_EXPORT bool VerifyNameInSubtree(der::Input name_rdn_sequence,
|
||||
der::Input parent_rdn_sequence);
|
||||
|
||||
// Helper functions:
|
||||
|
||||
@@ -53,7 +53,7 @@ OPENSSL_EXPORT bool VerifyNameInSubtree(const der::Input &name_rdn_sequence,
|
||||
// tag, but otherwise have not been validated.
|
||||
// Returns false if there was a parsing error.
|
||||
[[nodiscard]] bool FindEmailAddressesInName(
|
||||
const der::Input &name_rdn_sequence,
|
||||
der::Input name_rdn_sequence,
|
||||
std::vector<std::string> *contained_email_addresses);
|
||||
|
||||
} // namespace bssl
|
||||
|
||||
@@ -33,8 +33,8 @@ bool SHA256UpdateWithLengthPrefixedData(SHA256_CTX *s_ctx, const uint8_t *data,
|
||||
constexpr uint32_t VerifyCacheKeyVersion = 1;
|
||||
|
||||
std::string SignatureVerifyCacheKey(std::string_view algorithm_name,
|
||||
const der::Input &signed_data,
|
||||
const der::Input &signature_value_bytes,
|
||||
der::Input signed_data,
|
||||
der::Input signature_value_bytes,
|
||||
EVP_PKEY *public_key) {
|
||||
SHA256_CTX s_ctx;
|
||||
bssl::ScopedCBB public_key_cbb;
|
||||
@@ -50,11 +50,10 @@ std::string SignatureVerifyCacheKey(std::string_view algorithm_name,
|
||||
algorithm_name.length()) &&
|
||||
SHA256UpdateWithLengthPrefixedData(&s_ctx, CBB_data(public_key_cbb.get()),
|
||||
CBB_len(public_key_cbb.get())) &&
|
||||
SHA256UpdateWithLengthPrefixedData(&s_ctx,
|
||||
signature_value_bytes.UnsafeData(),
|
||||
signature_value_bytes.Length()) &&
|
||||
SHA256UpdateWithLengthPrefixedData(&s_ctx, signed_data.UnsafeData(),
|
||||
signed_data.Length()) &&
|
||||
SHA256UpdateWithLengthPrefixedData(&s_ctx, signature_value_bytes.data(),
|
||||
signature_value_bytes.size()) &&
|
||||
SHA256UpdateWithLengthPrefixedData(&s_ctx, signed_data.data(),
|
||||
signed_data.size()) &&
|
||||
SHA256_Final(digest, &s_ctx)) {
|
||||
return std::string(reinterpret_cast<char *>(digest), sizeof(digest));
|
||||
}
|
||||
@@ -137,13 +136,13 @@ class OpenSSLErrStackTracer {
|
||||
// { ID secp521r1 } | { ID sect571k1 } | { ID sect571r1 },
|
||||
// ... -- Extensible
|
||||
// }
|
||||
bool ParsePublicKey(const der::Input &public_key_spki,
|
||||
bool ParsePublicKey(der::Input public_key_spki,
|
||||
bssl::UniquePtr<EVP_PKEY> *public_key) {
|
||||
// Parse the SPKI to an EVP_PKEY.
|
||||
OpenSSLErrStackTracer err_tracer;
|
||||
|
||||
CBS cbs;
|
||||
CBS_init(&cbs, public_key_spki.UnsafeData(), public_key_spki.Length());
|
||||
CBS_init(&cbs, public_key_spki.data(), public_key_spki.size());
|
||||
public_key->reset(EVP_parse_public_key(&cbs));
|
||||
if (!*public_key || CBS_len(&cbs) != 0) {
|
||||
public_key->reset();
|
||||
@@ -152,8 +151,7 @@ bool ParsePublicKey(const der::Input &public_key_spki,
|
||||
return true;
|
||||
}
|
||||
|
||||
bool VerifySignedData(SignatureAlgorithm algorithm,
|
||||
const der::Input &signed_data,
|
||||
bool VerifySignedData(SignatureAlgorithm algorithm, der::Input signed_data,
|
||||
const der::BitString &signature_value,
|
||||
EVP_PKEY *public_key, SignatureVerifyCache *cache) {
|
||||
int expected_pkey_id = 1;
|
||||
@@ -232,7 +230,7 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
|
||||
if (signature_value.unused_bits() != 0) {
|
||||
return false;
|
||||
}
|
||||
const der::Input &signature_value_bytes = signature_value.bytes();
|
||||
der::Input signature_value_bytes = signature_value.bytes();
|
||||
|
||||
std::string cache_key;
|
||||
if (cache) {
|
||||
@@ -269,14 +267,9 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
|
||||
}
|
||||
}
|
||||
|
||||
if (!EVP_DigestVerifyUpdate(ctx.get(), signed_data.UnsafeData(),
|
||||
signed_data.Length())) {
|
||||
return false;
|
||||
}
|
||||
|
||||
bool ret =
|
||||
1 == EVP_DigestVerifyFinal(ctx.get(), signature_value_bytes.UnsafeData(),
|
||||
signature_value_bytes.Length());
|
||||
bool ret = 1 == EVP_DigestVerify(ctx.get(), signature_value_bytes.data(),
|
||||
signature_value_bytes.size(),
|
||||
signed_data.data(), signed_data.size());
|
||||
if (!cache_key.empty()) {
|
||||
cache->Store(cache_key, ret ? SignatureVerifyCache::Value::kValid
|
||||
: SignatureVerifyCache::Value::kInvalid);
|
||||
@@ -285,11 +278,9 @@ bool VerifySignedData(SignatureAlgorithm algorithm,
|
||||
return ret;
|
||||
}
|
||||
|
||||
bool VerifySignedData(SignatureAlgorithm algorithm,
|
||||
const der::Input &signed_data,
|
||||
bool VerifySignedData(SignatureAlgorithm algorithm, der::Input signed_data,
|
||||
const der::BitString &signature_value,
|
||||
const der::Input &public_key_spki,
|
||||
SignatureVerifyCache *cache) {
|
||||
der::Input public_key_spki, SignatureVerifyCache *cache) {
|
||||
bssl::UniquePtr<EVP_PKEY> public_key;
|
||||
if (!ParsePublicKey(public_key_spki, &public_key)) {
|
||||
return false;
|
||||
|
||||
@@ -28,19 +28,19 @@ class Input;
|
||||
//
|
||||
// Returns true if verification was successful.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool VerifySignedData(
|
||||
SignatureAlgorithm algorithm, const der::Input &signed_data,
|
||||
SignatureAlgorithm algorithm, der::Input signed_data,
|
||||
const der::BitString &signature_value, EVP_PKEY *public_key,
|
||||
SignatureVerifyCache *cache);
|
||||
|
||||
// Same as above overload, only the public key is inputted as an SPKI and will
|
||||
// be parsed internally.
|
||||
[[nodiscard]] OPENSSL_EXPORT bool VerifySignedData(
|
||||
SignatureAlgorithm algorithm, const der::Input &signed_data,
|
||||
const der::BitString &signature_value, const der::Input &public_key_spki,
|
||||
SignatureAlgorithm algorithm, der::Input signed_data,
|
||||
const der::BitString &signature_value, der::Input public_key_spki,
|
||||
SignatureVerifyCache *cache);
|
||||
|
||||
[[nodiscard]] OPENSSL_EXPORT bool ParsePublicKey(
|
||||
const der::Input &public_key_spki, bssl::UniquePtr<EVP_PKEY> *public_key);
|
||||
der::Input public_key_spki, bssl::UniquePtr<EVP_PKEY> *public_key);
|
||||
|
||||
} // namespace bssl
|
||||
|
||||
|
||||
Reference in New Issue
Block a user