1*ee116499SAntonio Huete Jimenez /* $OpenBSD: sshbuf-misc.c,v 1.18 2022/01/22 00:43:43 djm Exp $ */
236e94dc5SPeter Avalos /*
336e94dc5SPeter Avalos * Copyright (c) 2011 Damien Miller
436e94dc5SPeter Avalos *
536e94dc5SPeter Avalos * Permission to use, copy, modify, and distribute this software for any
636e94dc5SPeter Avalos * purpose with or without fee is hereby granted, provided that the above
736e94dc5SPeter Avalos * copyright notice and this permission notice appear in all copies.
836e94dc5SPeter Avalos *
936e94dc5SPeter Avalos * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
1036e94dc5SPeter Avalos * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
1136e94dc5SPeter Avalos * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
1236e94dc5SPeter Avalos * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
1336e94dc5SPeter Avalos * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1436e94dc5SPeter Avalos * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1536e94dc5SPeter Avalos * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1636e94dc5SPeter Avalos */
1736e94dc5SPeter Avalos
1836e94dc5SPeter Avalos #include "includes.h"
1936e94dc5SPeter Avalos
2036e94dc5SPeter Avalos #include <sys/types.h>
2136e94dc5SPeter Avalos #include <sys/socket.h>
2236e94dc5SPeter Avalos #include <netinet/in.h>
2336e94dc5SPeter Avalos #include <errno.h>
2436e94dc5SPeter Avalos #include <stdlib.h>
25e9778795SPeter Avalos #ifdef HAVE_STDINT_H
26e9778795SPeter Avalos # include <stdint.h>
27e9778795SPeter Avalos #endif
2836e94dc5SPeter Avalos #include <stdio.h>
2936e94dc5SPeter Avalos #include <limits.h>
3036e94dc5SPeter Avalos #include <string.h>
3136e94dc5SPeter Avalos #include <resolv.h>
3236e94dc5SPeter Avalos #include <ctype.h>
33*ee116499SAntonio Huete Jimenez #include <unistd.h>
3436e94dc5SPeter Avalos
3536e94dc5SPeter Avalos #include "ssherr.h"
3636e94dc5SPeter Avalos #define SSHBUF_INTERNAL
3736e94dc5SPeter Avalos #include "sshbuf.h"
3836e94dc5SPeter Avalos
3936e94dc5SPeter Avalos void
sshbuf_dump_data(const void * s,size_t len,FILE * f)4036e94dc5SPeter Avalos sshbuf_dump_data(const void *s, size_t len, FILE *f)
4136e94dc5SPeter Avalos {
4236e94dc5SPeter Avalos size_t i, j;
4336e94dc5SPeter Avalos const u_char *p = (const u_char *)s;
4436e94dc5SPeter Avalos
4536e94dc5SPeter Avalos for (i = 0; i < len; i += 16) {
46e9778795SPeter Avalos fprintf(f, "%.4zu: ", i);
4736e94dc5SPeter Avalos for (j = i; j < i + 16; j++) {
4836e94dc5SPeter Avalos if (j < len)
4936e94dc5SPeter Avalos fprintf(f, "%02x ", p[j]);
5036e94dc5SPeter Avalos else
5136e94dc5SPeter Avalos fprintf(f, " ");
5236e94dc5SPeter Avalos }
5336e94dc5SPeter Avalos fprintf(f, " ");
5436e94dc5SPeter Avalos for (j = i; j < i + 16; j++) {
5536e94dc5SPeter Avalos if (j < len) {
5636e94dc5SPeter Avalos if (isascii(p[j]) && isprint(p[j]))
5736e94dc5SPeter Avalos fprintf(f, "%c", p[j]);
5836e94dc5SPeter Avalos else
5936e94dc5SPeter Avalos fprintf(f, ".");
6036e94dc5SPeter Avalos }
6136e94dc5SPeter Avalos }
6236e94dc5SPeter Avalos fprintf(f, "\n");
6336e94dc5SPeter Avalos }
6436e94dc5SPeter Avalos }
6536e94dc5SPeter Avalos
6636e94dc5SPeter Avalos void
sshbuf_dump(const struct sshbuf * buf,FILE * f)6750a69bb5SSascha Wildner sshbuf_dump(const struct sshbuf *buf, FILE *f)
6836e94dc5SPeter Avalos {
6950a69bb5SSascha Wildner fprintf(f, "buffer len = %zu\n", sshbuf_len(buf));
7036e94dc5SPeter Avalos sshbuf_dump_data(sshbuf_ptr(buf), sshbuf_len(buf), f);
7136e94dc5SPeter Avalos }
7236e94dc5SPeter Avalos
7336e94dc5SPeter Avalos char *
sshbuf_dtob16(struct sshbuf * buf)7436e94dc5SPeter Avalos sshbuf_dtob16(struct sshbuf *buf)
7536e94dc5SPeter Avalos {
7636e94dc5SPeter Avalos size_t i, j, len = sshbuf_len(buf);
7736e94dc5SPeter Avalos const u_char *p = sshbuf_ptr(buf);
7836e94dc5SPeter Avalos char *ret;
7936e94dc5SPeter Avalos const char hex[] = "0123456789abcdef";
8036e94dc5SPeter Avalos
8136e94dc5SPeter Avalos if (len == 0)
8236e94dc5SPeter Avalos return strdup("");
8336e94dc5SPeter Avalos if (SIZE_MAX / 2 <= len || (ret = malloc(len * 2 + 1)) == NULL)
8436e94dc5SPeter Avalos return NULL;
8536e94dc5SPeter Avalos for (i = j = 0; i < len; i++) {
8636e94dc5SPeter Avalos ret[j++] = hex[(p[i] >> 4) & 0xf];
8736e94dc5SPeter Avalos ret[j++] = hex[p[i] & 0xf];
8836e94dc5SPeter Avalos }
8936e94dc5SPeter Avalos ret[j] = '\0';
9036e94dc5SPeter Avalos return ret;
9136e94dc5SPeter Avalos }
9236e94dc5SPeter Avalos
930cbfa66cSDaniel Fojt int
sshbuf_dtob64(const struct sshbuf * d,struct sshbuf * b64,int wrap)940cbfa66cSDaniel Fojt sshbuf_dtob64(const struct sshbuf *d, struct sshbuf *b64, int wrap)
9536e94dc5SPeter Avalos {
960cbfa66cSDaniel Fojt size_t i, slen = 0;
970cbfa66cSDaniel Fojt char *s = NULL;
9836e94dc5SPeter Avalos int r;
9936e94dc5SPeter Avalos
1000cbfa66cSDaniel Fojt if (d == NULL || b64 == NULL || sshbuf_len(d) >= SIZE_MAX / 2)
1010cbfa66cSDaniel Fojt return SSH_ERR_INVALID_ARGUMENT;
1020cbfa66cSDaniel Fojt if (sshbuf_len(d) == 0)
1030cbfa66cSDaniel Fojt return 0;
1040cbfa66cSDaniel Fojt slen = ((sshbuf_len(d) + 2) / 3) * 4 + 1;
1050cbfa66cSDaniel Fojt if ((s = malloc(slen)) == NULL)
1060cbfa66cSDaniel Fojt return SSH_ERR_ALLOC_FAIL;
1070cbfa66cSDaniel Fojt if (b64_ntop(sshbuf_ptr(d), sshbuf_len(d), s, slen) == -1) {
1080cbfa66cSDaniel Fojt r = SSH_ERR_INTERNAL_ERROR;
1090cbfa66cSDaniel Fojt goto fail;
1100cbfa66cSDaniel Fojt }
1110cbfa66cSDaniel Fojt if (wrap) {
1120cbfa66cSDaniel Fojt for (i = 0; s[i] != '\0'; i++) {
1130cbfa66cSDaniel Fojt if ((r = sshbuf_put_u8(b64, s[i])) != 0)
1140cbfa66cSDaniel Fojt goto fail;
1150cbfa66cSDaniel Fojt if (i % 70 == 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
1160cbfa66cSDaniel Fojt goto fail;
1170cbfa66cSDaniel Fojt }
1180cbfa66cSDaniel Fojt if ((i - 1) % 70 != 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
1190cbfa66cSDaniel Fojt goto fail;
1200cbfa66cSDaniel Fojt } else {
1210cbfa66cSDaniel Fojt if ((r = sshbuf_put(b64, s, strlen(s))) != 0)
1220cbfa66cSDaniel Fojt goto fail;
1230cbfa66cSDaniel Fojt }
1240cbfa66cSDaniel Fojt /* Success */
1250cbfa66cSDaniel Fojt r = 0;
1260cbfa66cSDaniel Fojt fail:
1270cbfa66cSDaniel Fojt freezero(s, slen);
1280cbfa66cSDaniel Fojt return r;
1290cbfa66cSDaniel Fojt }
1300cbfa66cSDaniel Fojt
1310cbfa66cSDaniel Fojt char *
sshbuf_dtob64_string(const struct sshbuf * buf,int wrap)1320cbfa66cSDaniel Fojt sshbuf_dtob64_string(const struct sshbuf *buf, int wrap)
1330cbfa66cSDaniel Fojt {
1340cbfa66cSDaniel Fojt struct sshbuf *tmp;
1350cbfa66cSDaniel Fojt char *ret;
1360cbfa66cSDaniel Fojt
1370cbfa66cSDaniel Fojt if ((tmp = sshbuf_new()) == NULL)
13836e94dc5SPeter Avalos return NULL;
1390cbfa66cSDaniel Fojt if (sshbuf_dtob64(buf, tmp, wrap) != 0) {
1400cbfa66cSDaniel Fojt sshbuf_free(tmp);
14136e94dc5SPeter Avalos return NULL;
14236e94dc5SPeter Avalos }
1430cbfa66cSDaniel Fojt ret = sshbuf_dup_string(tmp);
1440cbfa66cSDaniel Fojt sshbuf_free(tmp);
14536e94dc5SPeter Avalos return ret;
14636e94dc5SPeter Avalos }
14736e94dc5SPeter Avalos
14836e94dc5SPeter Avalos int
sshbuf_b64tod(struct sshbuf * buf,const char * b64)14936e94dc5SPeter Avalos sshbuf_b64tod(struct sshbuf *buf, const char *b64)
15036e94dc5SPeter Avalos {
15136e94dc5SPeter Avalos size_t plen = strlen(b64);
15236e94dc5SPeter Avalos int nlen, r;
15336e94dc5SPeter Avalos u_char *p;
15436e94dc5SPeter Avalos
15536e94dc5SPeter Avalos if (plen == 0)
15636e94dc5SPeter Avalos return 0;
15736e94dc5SPeter Avalos if ((p = malloc(plen)) == NULL)
15836e94dc5SPeter Avalos return SSH_ERR_ALLOC_FAIL;
15936e94dc5SPeter Avalos if ((nlen = b64_pton(b64, p, plen)) < 0) {
1600cbfa66cSDaniel Fojt freezero(p, plen);
16136e94dc5SPeter Avalos return SSH_ERR_INVALID_FORMAT;
16236e94dc5SPeter Avalos }
16336e94dc5SPeter Avalos if ((r = sshbuf_put(buf, p, nlen)) < 0) {
1640cbfa66cSDaniel Fojt freezero(p, plen);
16536e94dc5SPeter Avalos return r;
16636e94dc5SPeter Avalos }
1670cbfa66cSDaniel Fojt freezero(p, plen);
16836e94dc5SPeter Avalos return 0;
16936e94dc5SPeter Avalos }
17036e94dc5SPeter Avalos
17150a69bb5SSascha Wildner int
sshbuf_dtourlb64(const struct sshbuf * d,struct sshbuf * b64,int wrap)17250a69bb5SSascha Wildner sshbuf_dtourlb64(const struct sshbuf *d, struct sshbuf *b64, int wrap)
17350a69bb5SSascha Wildner {
17450a69bb5SSascha Wildner int r = SSH_ERR_INTERNAL_ERROR;
17550a69bb5SSascha Wildner u_char *p;
17650a69bb5SSascha Wildner struct sshbuf *b = NULL;
17750a69bb5SSascha Wildner size_t i, l;
17850a69bb5SSascha Wildner
17950a69bb5SSascha Wildner if ((b = sshbuf_new()) == NULL)
18050a69bb5SSascha Wildner return SSH_ERR_ALLOC_FAIL;
18150a69bb5SSascha Wildner /* Encode using regular base64; we'll transform it once done */
18250a69bb5SSascha Wildner if ((r = sshbuf_dtob64(d, b, wrap)) != 0)
18350a69bb5SSascha Wildner goto out;
18450a69bb5SSascha Wildner /* remove padding from end of encoded string*/
18550a69bb5SSascha Wildner for (;;) {
18650a69bb5SSascha Wildner l = sshbuf_len(b);
18750a69bb5SSascha Wildner if (l <= 1 || sshbuf_ptr(b) == NULL) {
18850a69bb5SSascha Wildner r = SSH_ERR_INTERNAL_ERROR;
18950a69bb5SSascha Wildner goto out;
19050a69bb5SSascha Wildner }
19150a69bb5SSascha Wildner if (sshbuf_ptr(b)[l - 1] != '=')
19250a69bb5SSascha Wildner break;
19350a69bb5SSascha Wildner if ((r = sshbuf_consume_end(b, 1)) != 0)
19450a69bb5SSascha Wildner goto out;
19550a69bb5SSascha Wildner }
19650a69bb5SSascha Wildner /* Replace characters with rfc4648 equivalents */
19750a69bb5SSascha Wildner l = sshbuf_len(b);
19850a69bb5SSascha Wildner if ((p = sshbuf_mutable_ptr(b)) == NULL) {
19950a69bb5SSascha Wildner r = SSH_ERR_INTERNAL_ERROR;
20050a69bb5SSascha Wildner goto out;
20150a69bb5SSascha Wildner }
20250a69bb5SSascha Wildner for (i = 0; i < l; i++) {
20350a69bb5SSascha Wildner if (p[i] == '+')
20450a69bb5SSascha Wildner p[i] = '-';
20550a69bb5SSascha Wildner else if (p[i] == '/')
20650a69bb5SSascha Wildner p[i] = '_';
20750a69bb5SSascha Wildner }
20850a69bb5SSascha Wildner r = sshbuf_putb(b64, b);
20950a69bb5SSascha Wildner out:
21050a69bb5SSascha Wildner sshbuf_free(b);
21150a69bb5SSascha Wildner return r;
21250a69bb5SSascha Wildner }
21350a69bb5SSascha Wildner
214e9778795SPeter Avalos char *
sshbuf_dup_string(struct sshbuf * buf)215e9778795SPeter Avalos sshbuf_dup_string(struct sshbuf *buf)
216e9778795SPeter Avalos {
217e9778795SPeter Avalos const u_char *p = NULL, *s = sshbuf_ptr(buf);
218e9778795SPeter Avalos size_t l = sshbuf_len(buf);
219e9778795SPeter Avalos char *r;
220e9778795SPeter Avalos
221e9778795SPeter Avalos if (s == NULL || l > SIZE_MAX)
222e9778795SPeter Avalos return NULL;
223e9778795SPeter Avalos /* accept a nul only as the last character in the buffer */
224e9778795SPeter Avalos if (l > 0 && (p = memchr(s, '\0', l)) != NULL) {
225e9778795SPeter Avalos if (p != s + l - 1)
226e9778795SPeter Avalos return NULL;
227e9778795SPeter Avalos l--; /* the nul is put back below */
228e9778795SPeter Avalos }
229e9778795SPeter Avalos if ((r = malloc(l + 1)) == NULL)
230e9778795SPeter Avalos return NULL;
231e9778795SPeter Avalos if (l > 0)
232e9778795SPeter Avalos memcpy(r, s, l);
233e9778795SPeter Avalos r[l] = '\0';
234e9778795SPeter Avalos return r;
235e9778795SPeter Avalos }
236e9778795SPeter Avalos
2370cbfa66cSDaniel Fojt int
sshbuf_cmp(const struct sshbuf * b,size_t offset,const void * s,size_t len)2380cbfa66cSDaniel Fojt sshbuf_cmp(const struct sshbuf *b, size_t offset,
2390cbfa66cSDaniel Fojt const void *s, size_t len)
2400cbfa66cSDaniel Fojt {
2410cbfa66cSDaniel Fojt if (sshbuf_ptr(b) == NULL)
2420cbfa66cSDaniel Fojt return SSH_ERR_INTERNAL_ERROR;
2430cbfa66cSDaniel Fojt if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
2440cbfa66cSDaniel Fojt return SSH_ERR_INVALID_ARGUMENT;
2450cbfa66cSDaniel Fojt if (offset + len > sshbuf_len(b))
2460cbfa66cSDaniel Fojt return SSH_ERR_MESSAGE_INCOMPLETE;
2470cbfa66cSDaniel Fojt if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0)
2480cbfa66cSDaniel Fojt return SSH_ERR_INVALID_FORMAT;
2490cbfa66cSDaniel Fojt return 0;
2500cbfa66cSDaniel Fojt }
2510cbfa66cSDaniel Fojt
2520cbfa66cSDaniel Fojt int
sshbuf_find(const struct sshbuf * b,size_t start_offset,const void * s,size_t len,size_t * offsetp)2530cbfa66cSDaniel Fojt sshbuf_find(const struct sshbuf *b, size_t start_offset,
2540cbfa66cSDaniel Fojt const void *s, size_t len, size_t *offsetp)
2550cbfa66cSDaniel Fojt {
2560cbfa66cSDaniel Fojt void *p;
2570cbfa66cSDaniel Fojt
2580cbfa66cSDaniel Fojt if (offsetp != NULL)
2590cbfa66cSDaniel Fojt *offsetp = 0;
2600cbfa66cSDaniel Fojt if (sshbuf_ptr(b) == NULL)
2610cbfa66cSDaniel Fojt return SSH_ERR_INTERNAL_ERROR;
2620cbfa66cSDaniel Fojt if (start_offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
2630cbfa66cSDaniel Fojt return SSH_ERR_INVALID_ARGUMENT;
2640cbfa66cSDaniel Fojt if (start_offset > sshbuf_len(b) || start_offset + len > sshbuf_len(b))
2650cbfa66cSDaniel Fojt return SSH_ERR_MESSAGE_INCOMPLETE;
2660cbfa66cSDaniel Fojt if ((p = memmem(sshbuf_ptr(b) + start_offset,
2670cbfa66cSDaniel Fojt sshbuf_len(b) - start_offset, s, len)) == NULL)
2680cbfa66cSDaniel Fojt return SSH_ERR_INVALID_FORMAT;
2690cbfa66cSDaniel Fojt if (offsetp != NULL)
2700cbfa66cSDaniel Fojt *offsetp = (const u_char *)p - sshbuf_ptr(b);
2710cbfa66cSDaniel Fojt return 0;
2720cbfa66cSDaniel Fojt }
273*ee116499SAntonio Huete Jimenez
274*ee116499SAntonio Huete Jimenez int
sshbuf_read(int fd,struct sshbuf * buf,size_t maxlen,size_t * rlen)275*ee116499SAntonio Huete Jimenez sshbuf_read(int fd, struct sshbuf *buf, size_t maxlen, size_t *rlen)
276*ee116499SAntonio Huete Jimenez {
277*ee116499SAntonio Huete Jimenez int r, oerrno;
278*ee116499SAntonio Huete Jimenez size_t adjust;
279*ee116499SAntonio Huete Jimenez ssize_t rr;
280*ee116499SAntonio Huete Jimenez u_char *d;
281*ee116499SAntonio Huete Jimenez
282*ee116499SAntonio Huete Jimenez if (rlen != NULL)
283*ee116499SAntonio Huete Jimenez *rlen = 0;
284*ee116499SAntonio Huete Jimenez if ((r = sshbuf_reserve(buf, maxlen, &d)) != 0)
285*ee116499SAntonio Huete Jimenez return r;
286*ee116499SAntonio Huete Jimenez rr = read(fd, d, maxlen);
287*ee116499SAntonio Huete Jimenez oerrno = errno;
288*ee116499SAntonio Huete Jimenez
289*ee116499SAntonio Huete Jimenez /* Adjust the buffer to include only what was actually read */
290*ee116499SAntonio Huete Jimenez if ((adjust = maxlen - (rr > 0 ? rr : 0)) != 0) {
291*ee116499SAntonio Huete Jimenez if ((r = sshbuf_consume_end(buf, adjust)) != 0) {
292*ee116499SAntonio Huete Jimenez /* avoid returning uninitialised data to caller */
293*ee116499SAntonio Huete Jimenez memset(d + rr, '\0', adjust);
294*ee116499SAntonio Huete Jimenez return SSH_ERR_INTERNAL_ERROR; /* shouldn't happen */
295*ee116499SAntonio Huete Jimenez }
296*ee116499SAntonio Huete Jimenez }
297*ee116499SAntonio Huete Jimenez if (rr < 0) {
298*ee116499SAntonio Huete Jimenez errno = oerrno;
299*ee116499SAntonio Huete Jimenez return SSH_ERR_SYSTEM_ERROR;
300*ee116499SAntonio Huete Jimenez } else if (rr == 0) {
301*ee116499SAntonio Huete Jimenez errno = EPIPE;
302*ee116499SAntonio Huete Jimenez return SSH_ERR_SYSTEM_ERROR;
303*ee116499SAntonio Huete Jimenez }
304*ee116499SAntonio Huete Jimenez /* success */
305*ee116499SAntonio Huete Jimenez if (rlen != NULL)
306*ee116499SAntonio Huete Jimenez *rlen = (size_t)rr;
307*ee116499SAntonio Huete Jimenez return 0;
308*ee116499SAntonio Huete Jimenez }
309