xref: /openssh-portable/sshbuf-misc.c (revision 12848191)
1 /*	$OpenBSD: sshbuf-misc.c,v 1.16 2020/06/22 05:54:10 djm Exp $	*/
2 /*
3  * Copyright (c) 2011 Damien Miller
4  *
5  * Permission to use, copy, modify, and distribute this software for any
6  * purpose with or without fee is hereby granted, provided that the above
7  * copyright notice and this permission notice appear in all copies.
8  *
9  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16  */
17 
18 #include "includes.h"
19 
20 #include <sys/types.h>
21 #include <sys/socket.h>
22 #include <netinet/in.h>
23 #include <errno.h>
24 #include <stdlib.h>
25 #ifdef HAVE_STDINT_H
26 # include <stdint.h>
27 #endif
28 #include <stdio.h>
29 #include <limits.h>
30 #include <string.h>
31 #include <resolv.h>
32 #include <ctype.h>
33 
34 #include "ssherr.h"
35 #define SSHBUF_INTERNAL
36 #include "sshbuf.h"
37 
38 void
sshbuf_dump_data(const void * s,size_t len,FILE * f)39 sshbuf_dump_data(const void *s, size_t len, FILE *f)
40 {
41 	size_t i, j;
42 	const u_char *p = (const u_char *)s;
43 
44 	for (i = 0; i < len; i += 16) {
45 		fprintf(f, "%.4zu: ", i);
46 		for (j = i; j < i + 16; j++) {
47 			if (j < len)
48 				fprintf(f, "%02x ", p[j]);
49 			else
50 				fprintf(f, "   ");
51 		}
52 		fprintf(f, " ");
53 		for (j = i; j < i + 16; j++) {
54 			if (j < len) {
55 				if  (isascii(p[j]) && isprint(p[j]))
56 					fprintf(f, "%c", p[j]);
57 				else
58 					fprintf(f, ".");
59 			}
60 		}
61 		fprintf(f, "\n");
62 	}
63 }
64 
65 void
sshbuf_dump(const struct sshbuf * buf,FILE * f)66 sshbuf_dump(const struct sshbuf *buf, FILE *f)
67 {
68 	fprintf(f, "buffer %p len = %zu\n", buf, sshbuf_len(buf));
69 	sshbuf_dump_data(sshbuf_ptr(buf), sshbuf_len(buf), f);
70 }
71 
72 char *
sshbuf_dtob16(struct sshbuf * buf)73 sshbuf_dtob16(struct sshbuf *buf)
74 {
75 	size_t i, j, len = sshbuf_len(buf);
76 	const u_char *p = sshbuf_ptr(buf);
77 	char *ret;
78 	const char hex[] = "0123456789abcdef";
79 
80 	if (len == 0)
81 		return strdup("");
82 	if (SIZE_MAX / 2 <= len || (ret = malloc(len * 2 + 1)) == NULL)
83 		return NULL;
84 	for (i = j = 0; i < len; i++) {
85 		ret[j++] = hex[(p[i] >> 4) & 0xf];
86 		ret[j++] = hex[p[i] & 0xf];
87 	}
88 	ret[j] = '\0';
89 	return ret;
90 }
91 
92 int
sshbuf_dtob64(const struct sshbuf * d,struct sshbuf * b64,int wrap)93 sshbuf_dtob64(const struct sshbuf *d, struct sshbuf *b64, int wrap)
94 {
95 	size_t i, slen = 0;
96 	char *s = NULL;
97 	int r;
98 
99 	if (d == NULL || b64 == NULL || sshbuf_len(d) >= SIZE_MAX / 2)
100 		return SSH_ERR_INVALID_ARGUMENT;
101 	if (sshbuf_len(d) == 0)
102 		return 0;
103 	slen = ((sshbuf_len(d) + 2) / 3) * 4 + 1;
104 	if ((s = malloc(slen)) == NULL)
105 		return SSH_ERR_ALLOC_FAIL;
106 	if (b64_ntop(sshbuf_ptr(d), sshbuf_len(d), s, slen) == -1) {
107 		r = SSH_ERR_INTERNAL_ERROR;
108 		goto fail;
109 	}
110 	if (wrap) {
111 		for (i = 0; s[i] != '\0'; i++) {
112 			if ((r = sshbuf_put_u8(b64, s[i])) != 0)
113 				goto fail;
114 			if (i % 70 == 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
115 				goto fail;
116 		}
117 		if ((i - 1) % 70 != 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
118 			goto fail;
119 	} else {
120 		if ((r = sshbuf_put(b64, s, strlen(s))) != 0)
121 			goto fail;
122 	}
123 	/* Success */
124 	r = 0;
125  fail:
126 	freezero(s, slen);
127 	return r;
128 }
129 
130 char *
sshbuf_dtob64_string(const struct sshbuf * buf,int wrap)131 sshbuf_dtob64_string(const struct sshbuf *buf, int wrap)
132 {
133 	struct sshbuf *tmp;
134 	char *ret;
135 
136 	if ((tmp = sshbuf_new()) == NULL)
137 		return NULL;
138 	if (sshbuf_dtob64(buf, tmp, wrap) != 0) {
139 		sshbuf_free(tmp);
140 		return NULL;
141 	}
142 	ret = sshbuf_dup_string(tmp);
143 	sshbuf_free(tmp);
144 	return ret;
145 }
146 
147 int
sshbuf_b64tod(struct sshbuf * buf,const char * b64)148 sshbuf_b64tod(struct sshbuf *buf, const char *b64)
149 {
150 	size_t plen = strlen(b64);
151 	int nlen, r;
152 	u_char *p;
153 
154 	if (plen == 0)
155 		return 0;
156 	if ((p = malloc(plen)) == NULL)
157 		return SSH_ERR_ALLOC_FAIL;
158 	if ((nlen = b64_pton(b64, p, plen)) < 0) {
159 		freezero(p, plen);
160 		return SSH_ERR_INVALID_FORMAT;
161 	}
162 	if ((r = sshbuf_put(buf, p, nlen)) < 0) {
163 		freezero(p, plen);
164 		return r;
165 	}
166 	freezero(p, plen);
167 	return 0;
168 }
169 
170 int
sshbuf_dtourlb64(const struct sshbuf * d,struct sshbuf * b64,int wrap)171 sshbuf_dtourlb64(const struct sshbuf *d, struct sshbuf *b64, int wrap)
172 {
173 	int r = SSH_ERR_INTERNAL_ERROR;
174 	u_char *p;
175 	struct sshbuf *b = NULL;
176 	size_t i, l;
177 
178 	if ((b = sshbuf_new()) == NULL)
179 		return SSH_ERR_ALLOC_FAIL;
180 	/* Encode using regular base64; we'll transform it once done */
181 	if ((r = sshbuf_dtob64(d, b, wrap)) != 0)
182 		goto out;
183 	/* remove padding from end of encoded string*/
184 	for (;;) {
185 		l = sshbuf_len(b);
186 		if (l <= 1 || sshbuf_ptr(b) == NULL) {
187 			r = SSH_ERR_INTERNAL_ERROR;
188 			goto out;
189 		}
190 		if (sshbuf_ptr(b)[l - 1] != '=')
191 			break;
192 		if ((r = sshbuf_consume_end(b, 1)) != 0)
193 			goto out;
194 	}
195 	/* Replace characters with rfc4648 equivalents */
196 	l = sshbuf_len(b);
197 	if ((p = sshbuf_mutable_ptr(b)) == NULL) {
198 		r = SSH_ERR_INTERNAL_ERROR;
199 		goto out;
200 	}
201 	for (i = 0; i < l; i++) {
202 		if (p[i] == '+')
203 			p[i] = '-';
204 		else if (p[i] == '/')
205 			p[i] = '_';
206 	}
207 	r = sshbuf_putb(b64, b);
208  out:
209 	sshbuf_free(b);
210 	return r;
211 }
212 
213 char *
sshbuf_dup_string(struct sshbuf * buf)214 sshbuf_dup_string(struct sshbuf *buf)
215 {
216 	const u_char *p = NULL, *s = sshbuf_ptr(buf);
217 	size_t l = sshbuf_len(buf);
218 	char *r;
219 
220 	if (s == NULL || l > SIZE_MAX)
221 		return NULL;
222 	/* accept a nul only as the last character in the buffer */
223 	if (l > 0 && (p = memchr(s, '\0', l)) != NULL) {
224 		if (p != s + l - 1)
225 			return NULL;
226 		l--; /* the nul is put back below */
227 	}
228 	if ((r = malloc(l + 1)) == NULL)
229 		return NULL;
230 	if (l > 0)
231 		memcpy(r, s, l);
232 	r[l] = '\0';
233 	return r;
234 }
235 
236 int
sshbuf_cmp(const struct sshbuf * b,size_t offset,const void * s,size_t len)237 sshbuf_cmp(const struct sshbuf *b, size_t offset,
238     const void *s, size_t len)
239 {
240 	if (sshbuf_ptr(b) == NULL)
241 		return SSH_ERR_INTERNAL_ERROR;
242 	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
243 		return SSH_ERR_INVALID_ARGUMENT;
244 	if (offset + len > sshbuf_len(b))
245 		return SSH_ERR_MESSAGE_INCOMPLETE;
246 	if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0)
247 		return SSH_ERR_INVALID_FORMAT;
248 	return 0;
249 }
250 
251 int
sshbuf_find(const struct sshbuf * b,size_t start_offset,const void * s,size_t len,size_t * offsetp)252 sshbuf_find(const struct sshbuf *b, size_t start_offset,
253     const void *s, size_t len, size_t *offsetp)
254 {
255 	void *p;
256 
257 	if (offsetp != NULL)
258 		*offsetp = 0;
259 	if (sshbuf_ptr(b) == NULL)
260 		return SSH_ERR_INTERNAL_ERROR;
261 	if (start_offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
262 		return SSH_ERR_INVALID_ARGUMENT;
263 	if (start_offset > sshbuf_len(b) || start_offset + len > sshbuf_len(b))
264 		return SSH_ERR_MESSAGE_INCOMPLETE;
265 	if ((p = memmem(sshbuf_ptr(b) + start_offset,
266 	    sshbuf_len(b) - start_offset, s, len)) == NULL)
267 		return SSH_ERR_INVALID_FORMAT;
268 	if (offsetp != NULL)
269 		*offsetp = (const u_char *)p - sshbuf_ptr(b);
270 	return 0;
271 }
272