misc check strenghtens and debug guards

This commit is contained in:
Sergio R. Caprile
2026-07-16 15:10:19 -03:00
parent e2e2db8900
commit cb57182ee0
3 changed files with 36 additions and 20 deletions
+18 -10
View File
@@ -15923,10 +15923,9 @@ int gcm_crypt_and_tag(
prepare the gcm context with the keying material, we simply
invoke each of the three GCM sub-functions in turn...
*/
gcm_start(ctx, mode, iv, iv_len, add, add_len);
gcm_update(ctx, length, input, output);
gcm_finish(ctx, tag, tag_len);
return (0);
if (gcm_start(ctx, mode, iv, iv_len, add, add_len) != 0) return -1;
if (gcm_update(ctx, length, input, output) != 0) return -1;
return gcm_finish(ctx, tag, tag_len);
}
/******************************************************************************
@@ -18327,7 +18326,9 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
// Parse version (should be 0)
MG_VERBOSE(("Before version: offset=%d, bytes: %02x %02x %02x %02x",
(int) (p - der), p[0], p[1], p[2], p[3]));
(int) (p - der), p < end ? p[0] : 0xFF,
p + 1 < end ? p[1] : 0xFF, p + 2 < end ? p[2] : 0xFF,
p + 3 < end ? p[3] : 0xFF));
if (mg_rsa_parse_der_int(&p, end, &version) < 0) {
MG_ERROR(("Failed to parse version"));
return -1;
@@ -18338,7 +18339,10 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
// Parse the 8 components: n, e, d, p, q, dP, dQ, qInv
MG_VERBOSE(("Before n: offset=%d, bytes: %02x %02x %02x %02x %02x %02x",
(int) (p - der), p[0], p[1], p[2], p[3], p[4], p[5]));
(int) (p - der), p < end ? p[0] : 0xFF,
p + 1 < end ? p[1] : 0xFF, p + 2 < end ? p[2] : 0xFF,
p + 3 < end ? p[3] : 0xFF, p + 4 < end ? p[4] : 0xFF,
p + 5 < end ? p[5] : 0xFF));
if (mg_rsa_parse_der_int(&p, end, &key->n) < 0) {
MG_ERROR(("Failed to parse n (modulus)"));
return -1;
@@ -18346,10 +18350,14 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
MG_VERBOSE(("Parsed n: %d bytes, offset now=%d, consumed=%d bytes total",
(int) key->n.len, (int) (p - der), (int) (p - der)));
MG_VERBOSE((" First 8 bytes of n: %02x %02x %02x %02x %02x %02x %02x %02x",
(unsigned char) key->n.buf[0], (unsigned char) key->n.buf[1],
(unsigned char) key->n.buf[2], (unsigned char) key->n.buf[3],
(unsigned char) key->n.buf[4], (unsigned char) key->n.buf[5],
(unsigned char) key->n.buf[6], (unsigned char) key->n.buf[7]));
key->n.len > 0 ? (unsigned char) key->n.buf[0] : 0xFF,
key->n.len > 1 ? (unsigned char) key->n.buf[1] : 0xFF,
key->n.len > 2 ? (unsigned char) key->n.buf[2] : 0xFF,
key->n.len > 3 ? (unsigned char) key->n.buf[3] : 0xFF,
key->n.len > 4 ? (unsigned char) key->n.buf[4] : 0xFF,
key->n.len > 5 ? (unsigned char) key->n.buf[5] : 0xFF,
key->n.len > 6 ? (unsigned char) key->n.buf[6] : 0xFF,
key->n.len > 7 ? (unsigned char) key->n.buf[7] : 0xFF));
MG_VERBOSE((" Next bytes after n: %02x %02x %02x %02x %02x %02x",
p < end ? p[0] : 0xFF, p + 1 < end ? p[1] : 0xFF,
p + 2 < end ? p[2] : 0xFF, p + 3 < end ? p[3] : 0xFF,
+3 -4
View File
@@ -1061,10 +1061,9 @@ int gcm_crypt_and_tag(
prepare the gcm context with the keying material, we simply
invoke each of the three GCM sub-functions in turn...
*/
gcm_start(ctx, mode, iv, iv_len, add, add_len);
gcm_update(ctx, length, input, output);
gcm_finish(ctx, tag, tag_len);
return (0);
if (gcm_start(ctx, mode, iv, iv_len, add, add_len) != 0) return -1;
if (gcm_update(ctx, length, input, output) != 0) return -1;
return gcm_finish(ctx, tag, tag_len);
}
/******************************************************************************
+15 -6
View File
@@ -2323,7 +2323,9 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
// Parse version (should be 0)
MG_VERBOSE(("Before version: offset=%d, bytes: %02x %02x %02x %02x",
(int) (p - der), p[0], p[1], p[2], p[3]));
(int) (p - der), p < end ? p[0] : 0xFF,
p + 1 < end ? p[1] : 0xFF, p + 2 < end ? p[2] : 0xFF,
p + 3 < end ? p[3] : 0xFF));
if (mg_rsa_parse_der_int(&p, end, &version) < 0) {
MG_ERROR(("Failed to parse version"));
return -1;
@@ -2334,7 +2336,10 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
// Parse the 8 components: n, e, d, p, q, dP, dQ, qInv
MG_VERBOSE(("Before n: offset=%d, bytes: %02x %02x %02x %02x %02x %02x",
(int) (p - der), p[0], p[1], p[2], p[3], p[4], p[5]));
(int) (p - der), p < end ? p[0] : 0xFF,
p + 1 < end ? p[1] : 0xFF, p + 2 < end ? p[2] : 0xFF,
p + 3 < end ? p[3] : 0xFF, p + 4 < end ? p[4] : 0xFF,
p + 5 < end ? p[5] : 0xFF));
if (mg_rsa_parse_der_int(&p, end, &key->n) < 0) {
MG_ERROR(("Failed to parse n (modulus)"));
return -1;
@@ -2342,10 +2347,14 @@ static int mg_rsa_parse_key(const uint8_t *der, size_t dersz,
MG_VERBOSE(("Parsed n: %d bytes, offset now=%d, consumed=%d bytes total",
(int) key->n.len, (int) (p - der), (int) (p - der)));
MG_VERBOSE((" First 8 bytes of n: %02x %02x %02x %02x %02x %02x %02x %02x",
(unsigned char) key->n.buf[0], (unsigned char) key->n.buf[1],
(unsigned char) key->n.buf[2], (unsigned char) key->n.buf[3],
(unsigned char) key->n.buf[4], (unsigned char) key->n.buf[5],
(unsigned char) key->n.buf[6], (unsigned char) key->n.buf[7]));
key->n.len > 0 ? (unsigned char) key->n.buf[0] : 0xFF,
key->n.len > 1 ? (unsigned char) key->n.buf[1] : 0xFF,
key->n.len > 2 ? (unsigned char) key->n.buf[2] : 0xFF,
key->n.len > 3 ? (unsigned char) key->n.buf[3] : 0xFF,
key->n.len > 4 ? (unsigned char) key->n.buf[4] : 0xFF,
key->n.len > 5 ? (unsigned char) key->n.buf[5] : 0xFF,
key->n.len > 6 ? (unsigned char) key->n.buf[6] : 0xFF,
key->n.len > 7 ? (unsigned char) key->n.buf[7] : 0xFF));
MG_VERBOSE((" Next bytes after n: %02x %02x %02x %02x %02x %02x",
p < end ? p[0] : 0xFF, p + 1 < end ? p[1] : 0xFF,
p + 2 < end ? p[2] : 0xFF, p + 3 < end ? p[3] : 0xFF,