1 /* $OpenBSD: sshbuf-misc.c,v 1.17 2021/08/11 05:21:32 djm Exp $ */ 2 /* 3 * Copyright (c) 2011 Damien Miller 4 * 5 * Permission to use, copy, modify, and distribute this software for any 6 * purpose with or without fee is hereby granted, provided that the above 7 * copyright notice and this permission notice appear in all copies. 8 * 9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 16 */ 17 18 #include "includes.h" 19 20 #include <sys/types.h> 21 #include <sys/socket.h> 22 #include <netinet/in.h> 23 #include <errno.h> 24 #include <stdlib.h> 25 #ifdef HAVE_STDINT_H 26 # include <stdint.h> 27 #endif 28 #include <stdio.h> 29 #include <limits.h> 30 #include <string.h> 31 #include <resolv.h> 32 #include <ctype.h> 33 34 #include "ssherr.h" 35 #define SSHBUF_INTERNAL 36 #include "sshbuf.h" 37 38 void 39 sshbuf_dump_data(const void *s, size_t len, FILE *f) 40 { 41 size_t i, j; 42 const u_char *p = (const u_char *)s; 43 44 for (i = 0; i < len; i += 16) { 45 fprintf(f, "%.4zu: ", i); 46 for (j = i; j < i + 16; j++) { 47 if (j < len) 48 fprintf(f, "%02x ", p[j]); 49 else 50 fprintf(f, " "); 51 } 52 fprintf(f, " "); 53 for (j = i; j < i + 16; j++) { 54 if (j < len) { 55 if (isascii(p[j]) && isprint(p[j])) 56 fprintf(f, "%c", p[j]); 57 else 58 fprintf(f, "."); 59 } 60 } 61 fprintf(f, "\n"); 62 } 63 } 64 65 void 66 sshbuf_dump(const struct sshbuf *buf, FILE *f) 67 { 68 fprintf(f, "buffer len = %zu\n", sshbuf_len(buf)); 69 sshbuf_dump_data(sshbuf_ptr(buf), sshbuf_len(buf), f); 70 } 71 72 char * 73 sshbuf_dtob16(struct sshbuf *buf) 74 { 75 size_t i, j, len = sshbuf_len(buf); 76 const u_char *p = sshbuf_ptr(buf); 77 char *ret; 78 const char hex[] = "0123456789abcdef"; 79 80 if (len == 0) 81 return strdup(""); 82 if (SIZE_MAX / 2 <= len || (ret = malloc(len * 2 + 1)) == NULL) 83 return NULL; 84 for (i = j = 0; i < len; i++) { 85 ret[j++] = hex[(p[i] >> 4) & 0xf]; 86 ret[j++] = hex[p[i] & 0xf]; 87 } 88 ret[j] = '\0'; 89 return ret; 90 } 91 92 int 93 sshbuf_dtob64(const struct sshbuf *d, struct sshbuf *b64, int wrap) 94 { 95 size_t i, slen = 0; 96 char *s = NULL; 97 int r; 98 99 if (d == NULL || b64 == NULL || sshbuf_len(d) >= SIZE_MAX / 2) 100 return SSH_ERR_INVALID_ARGUMENT; 101 if (sshbuf_len(d) == 0) 102 return 0; 103 slen = ((sshbuf_len(d) + 2) / 3) * 4 + 1; 104 if ((s = malloc(slen)) == NULL) 105 return SSH_ERR_ALLOC_FAIL; 106 if (b64_ntop(sshbuf_ptr(d), sshbuf_len(d), s, slen) == -1) { 107 r = SSH_ERR_INTERNAL_ERROR; 108 goto fail; 109 } 110 if (wrap) { 111 for (i = 0; s[i] != '\0'; i++) { 112 if ((r = sshbuf_put_u8(b64, s[i])) != 0) 113 goto fail; 114 if (i % 70 == 69 && (r = sshbuf_put_u8(b64, '\n')) != 0) 115 goto fail; 116 } 117 if ((i - 1) % 70 != 69 && (r = sshbuf_put_u8(b64, '\n')) != 0) 118 goto fail; 119 } else { 120 if ((r = sshbuf_put(b64, s, strlen(s))) != 0) 121 goto fail; 122 } 123 /* Success */ 124 r = 0; 125 fail: 126 freezero(s, slen); 127 return r; 128 } 129 130 char * 131 sshbuf_dtob64_string(const struct sshbuf *buf, int wrap) 132 { 133 struct sshbuf *tmp; 134 char *ret; 135 136 if ((tmp = sshbuf_new()) == NULL) 137 return NULL; 138 if (sshbuf_dtob64(buf, tmp, wrap) != 0) { 139 sshbuf_free(tmp); 140 return NULL; 141 } 142 ret = sshbuf_dup_string(tmp); 143 sshbuf_free(tmp); 144 return ret; 145 } 146 147 int 148 sshbuf_b64tod(struct sshbuf *buf, const char *b64) 149 { 150 size_t plen = strlen(b64); 151 int nlen, r; 152 u_char *p; 153 154 if (plen == 0) 155 return 0; 156 if ((p = malloc(plen)) == NULL) 157 return SSH_ERR_ALLOC_FAIL; 158 if ((nlen = b64_pton(b64, p, plen)) < 0) { 159 freezero(p, plen); 160 return SSH_ERR_INVALID_FORMAT; 161 } 162 if ((r = sshbuf_put(buf, p, nlen)) < 0) { 163 freezero(p, plen); 164 return r; 165 } 166 freezero(p, plen); 167 return 0; 168 } 169 170 int 171 sshbuf_dtourlb64(const struct sshbuf *d, struct sshbuf *b64, int wrap) 172 { 173 int r = SSH_ERR_INTERNAL_ERROR; 174 u_char *p; 175 struct sshbuf *b = NULL; 176 size_t i, l; 177 178 if ((b = sshbuf_new()) == NULL) 179 return SSH_ERR_ALLOC_FAIL; 180 /* Encode using regular base64; we'll transform it once done */ 181 if ((r = sshbuf_dtob64(d, b, wrap)) != 0) 182 goto out; 183 /* remove padding from end of encoded string*/ 184 for (;;) { 185 l = sshbuf_len(b); 186 if (l <= 1 || sshbuf_ptr(b) == NULL) { 187 r = SSH_ERR_INTERNAL_ERROR; 188 goto out; 189 } 190 if (sshbuf_ptr(b)[l - 1] != '=') 191 break; 192 if ((r = sshbuf_consume_end(b, 1)) != 0) 193 goto out; 194 } 195 /* Replace characters with rfc4648 equivalents */ 196 l = sshbuf_len(b); 197 if ((p = sshbuf_mutable_ptr(b)) == NULL) { 198 r = SSH_ERR_INTERNAL_ERROR; 199 goto out; 200 } 201 for (i = 0; i < l; i++) { 202 if (p[i] == '+') 203 p[i] = '-'; 204 else if (p[i] == '/') 205 p[i] = '_'; 206 } 207 r = sshbuf_putb(b64, b); 208 out: 209 sshbuf_free(b); 210 return r; 211 } 212 213 char * 214 sshbuf_dup_string(struct sshbuf *buf) 215 { 216 const u_char *p = NULL, *s = sshbuf_ptr(buf); 217 size_t l = sshbuf_len(buf); 218 char *r; 219 220 if (s == NULL || l > SIZE_MAX) 221 return NULL; 222 /* accept a nul only as the last character in the buffer */ 223 if (l > 0 && (p = memchr(s, '\0', l)) != NULL) { 224 if (p != s + l - 1) 225 return NULL; 226 l--; /* the nul is put back below */ 227 } 228 if ((r = malloc(l + 1)) == NULL) 229 return NULL; 230 if (l > 0) 231 memcpy(r, s, l); 232 r[l] = '\0'; 233 return r; 234 } 235 236 int 237 sshbuf_cmp(const struct sshbuf *b, size_t offset, 238 const void *s, size_t len) 239 { 240 if (sshbuf_ptr(b) == NULL) 241 return SSH_ERR_INTERNAL_ERROR; 242 if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0) 243 return SSH_ERR_INVALID_ARGUMENT; 244 if (offset + len > sshbuf_len(b)) 245 return SSH_ERR_MESSAGE_INCOMPLETE; 246 if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0) 247 return SSH_ERR_INVALID_FORMAT; 248 return 0; 249 } 250 251 int 252 sshbuf_find(const struct sshbuf *b, size_t start_offset, 253 const void *s, size_t len, size_t *offsetp) 254 { 255 void *p; 256 257 if (offsetp != NULL) 258 *offsetp = 0; 259 if (sshbuf_ptr(b) == NULL) 260 return SSH_ERR_INTERNAL_ERROR; 261 if (start_offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0) 262 return SSH_ERR_INVALID_ARGUMENT; 263 if (start_offset > sshbuf_len(b) || start_offset + len > sshbuf_len(b)) 264 return SSH_ERR_MESSAGE_INCOMPLETE; 265 if ((p = memmem(sshbuf_ptr(b) + start_offset, 266 sshbuf_len(b) - start_offset, s, len)) == NULL) 267 return SSH_ERR_INVALID_FORMAT; 268 if (offsetp != NULL) 269 *offsetp = (const u_char *)p - sshbuf_ptr(b); 270 return 0; 271 } 272