Skip to content
This repository has been archived by the owner on Jul 29, 2024. It is now read-only.

add assert for signature length check to stop API misuse. #187

Merged
merged 1 commit into from
Dec 25, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 7 additions & 3 deletions spdmlib/src/crypto/spdm_ring/asym_verify_impl.rs
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,11 @@ fn asym_verify(
// add ASN.1 for the ECDSA binary signature
fn ecc_signature_bin_to_der(signature: &[u8], der_signature: &mut [u8]) -> SpdmResult<usize> {
let sign_size = signature.len();
assert_eq!(sign_size % 2, 0);
assert!(
// prevent API misuse
sign_size == crate::protocol::ECDSA_ECC_NIST_P256_KEY_SIZE
|| sign_size == crate::protocol::ECDSA_ECC_NIST_P384_KEY_SIZE
);
let half_size = sign_size / 2;

let mut r_index = half_size;
Expand Down Expand Up @@ -205,15 +209,15 @@ mod tests {
}
#[test]
fn test_case1_ecc_signature_bin_to_der() {
let signature = &mut [0x00u8; 32];
let signature = &mut [0x00u8; 64];
for i in 10..signature.len() {
signature[i] = 0xff;
}

let der_signature = &mut [0u8; 64];

let der_sign_size = ecc_signature_bin_to_der(signature, der_signature).unwrap();
assert_eq!(der_sign_size, 30);
assert_eq!(der_sign_size, 62);
}
#[test]
fn test_case2_ecc_signature_bin_to_der() {
Expand Down
5 changes: 5 additions & 0 deletions spdmlib_crypto_mbedtls/src/asym_verify_impl.rs
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,11 @@ fn asym_verify(
// add ASN.1 for the ECDSA binary signature
fn ecc_signature_bin_to_der(signature: &[u8], der_signature: &mut [u8]) -> SpdmResult<usize> {
let sign_size = signature.len();
assert!(
// prevent API misuse
sign_size == spdmlib::protocol::ECDSA_ECC_NIST_P256_KEY_SIZE
|| sign_size == spdmlib::protocol::ECDSA_ECC_NIST_P384_KEY_SIZE
);
let half_size = sign_size / 2;

let mut r_index = half_size;
Expand Down
Loading