mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-06 15:58:39 +09:00
nss: update nss to hg rev 395a93dbc02e with vc2013 patch applied
This commit is contained in:
parent
50f657b9c7
commit
b0e724dc85
84 changed files with 14198 additions and 661 deletions
|
|
@ -1,18 +1,5 @@
|
|||
|
||||
1 function with some indirect sub-type change:
|
||||
|
||||
[C]'function SECStatus CERT_AddOCSPAcceptableResponses(CERTOCSPRequest*, SECOidTag, ...)' at ocsp.c:2203:1 has some indirect sub-type changes:
|
||||
parameter 2 of type 'typedef SECOidTag' has sub-type changes:
|
||||
underlying type 'enum __anonymous_enum__' at secoidt.h:34:1 changed:
|
||||
type size hasn't changed
|
||||
4 enumerator insertions:
|
||||
'__anonymous_enum__::SEC_OID_X509_ANY_EXT_KEY_USAGE' value '357'
|
||||
'__anonymous_enum__::SEC_OID_EXT_KEY_USAGE_IPSEC_IKE' value '358'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_END' value '359'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_INTERMEDIATE' value '360'
|
||||
|
||||
1 enumerator change:
|
||||
'__anonymous_enum__::SEC_OID_TOTAL' from value '357' to '361' at secoidt.h:34:1
|
||||
|
||||
1 Added function:
|
||||
|
||||
'function SECOidTag HASH_GetHashOidTagByHashType(HASH_HashType)' {HASH_GetHashOidTagByHashType@@NSS_3.43}
|
||||
|
||||
|
|
|
|||
|
|
@ -1,18 +0,0 @@
|
|||
|
||||
1 function with some indirect sub-type change:
|
||||
|
||||
[C]'function SECStatus NSS_GetAlgorithmPolicy(SECOidTag, PRUint32*)' at secoid.c:2217:1 has some indirect sub-type changes:
|
||||
parameter 1 of type 'typedef SECOidTag' has sub-type changes:
|
||||
underlying type 'enum __anonymous_enum__' at secoidt.h:34:1 changed:
|
||||
type size hasn't changed
|
||||
4 enumerator insertions:
|
||||
'__anonymous_enum__::SEC_OID_X509_ANY_EXT_KEY_USAGE' value '357'
|
||||
'__anonymous_enum__::SEC_OID_EXT_KEY_USAGE_IPSEC_IKE' value '358'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_END' value '359'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_INTERMEDIATE' value '360'
|
||||
|
||||
1 enumerator change:
|
||||
'__anonymous_enum__::SEC_OID_TOTAL' from value '357' to '361' at secoidt.h:34:1
|
||||
|
||||
|
||||
|
||||
|
|
@ -1,48 +0,0 @@
|
|||
|
||||
1 function with some indirect sub-type change:
|
||||
|
||||
[C]'function PK11SymKey* NSS_CMSContentInfo_GetBulkKey(NSSCMSContentInfo*)' at cmscinfo.c:363:1 has some indirect sub-type changes:
|
||||
parameter 1 of type 'NSSCMSContentInfo*' has sub-type changes:
|
||||
in pointed to type 'typedef NSSCMSContentInfo' at cmst.h:54:1:
|
||||
underlying type 'struct NSSCMSContentInfoStr' at cmst.h:126:1 changed:
|
||||
type size hasn't changed
|
||||
1 data member changes (2 filtered):
|
||||
type of 'NSSCMSContent NSSCMSContentInfoStr::content' changed:
|
||||
underlying type 'union NSSCMSContentUnion' at cmst.h:113:1 changed:
|
||||
type size hasn't changed
|
||||
1 data member changes (3 filtered):
|
||||
type of 'NSSCMSEncryptedData* NSSCMSContentUnion::encryptedData' changed:
|
||||
in pointed to type 'typedef NSSCMSEncryptedData' at cmst.h:65:1:
|
||||
underlying type 'struct NSSCMSEncryptedDataStr' at cmst.h:463:1 changed:
|
||||
type size hasn't changed
|
||||
1 data member changes (1 filtered):
|
||||
type of 'NSSCMSAttribute** NSSCMSEncryptedDataStr::unprotectedAttr' changed:
|
||||
in pointed to type 'NSSCMSAttribute*':
|
||||
in pointed to type 'typedef NSSCMSAttribute' at cmst.h:69:1:
|
||||
underlying type 'struct NSSCMSAttributeStr' at cmst.h:482:1 changed:
|
||||
type size hasn't changed
|
||||
1 data member change:
|
||||
type of 'SECOidData* NSSCMSAttributeStr::typeTag' changed:
|
||||
in pointed to type 'typedef SECOidData' at secoidt.h:16:1:
|
||||
underlying type 'struct SECOidDataStr' at secoidt.h:513:1 changed:
|
||||
type size hasn't changed
|
||||
1 data member change:
|
||||
type of 'SECOidTag SECOidDataStr::offset' changed:
|
||||
underlying type 'enum __anonymous_enum__' at secoidt.h:34:1 changed:
|
||||
type size hasn't changed
|
||||
4 enumerator insertions:
|
||||
'__anonymous_enum__::SEC_OID_X509_ANY_EXT_KEY_USAGE' value '357'
|
||||
'__anonymous_enum__::SEC_OID_EXT_KEY_USAGE_IPSEC_IKE' value '358'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_END' value '359'
|
||||
'__anonymous_enum__::SEC_OID_IPSEC_IKE_INTERMEDIATE' value '360'
|
||||
|
||||
1 enumerator change:
|
||||
'__anonymous_enum__::SEC_OID_TOTAL' from value '357' to '361' at secoidt.h:34:1
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -1 +1 @@
|
|||
NSS_3_40_BRANCH
|
||||
NSS_3_42_BRANCH
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
4.20
|
||||
4.21
|
||||
|
||||
# The first line of this file must contain the human readable NSPR
|
||||
# version number, which is the minimum required version of NSPR
|
||||
|
|
|
|||
|
|
@ -2260,7 +2260,6 @@ print_hex(int amt, unsigned char *buf)
|
|||
void
|
||||
Usage(void)
|
||||
{
|
||||
PR_fprintf(PR_STDERR, "SSLTAP (C) 1997, 1998 Netscape Communications Corporation.\n");
|
||||
PR_fprintf(PR_STDERR, "Usage: ssltap [-vhfsxl] [-p port] hostname:port\n");
|
||||
PR_fprintf(PR_STDERR, " -v [prints version string]\n");
|
||||
PR_fprintf(PR_STDERR, " -h [outputs hex instead of ASCII]\n");
|
||||
|
|
|
|||
|
|
@ -39,8 +39,6 @@ HIGHMEM_LDFLAG = -Zhigh-mem
|
|||
endif
|
||||
|
||||
ifndef NO_SHARED_LIB
|
||||
WRAP_MALLOC_LIB =
|
||||
WRAP_MALLOC_CFLAGS =
|
||||
DSO_CFLAGS =
|
||||
DSO_PIC_CFLAGS =
|
||||
MKSHLIB = $(CXX) $(CXXFLAGS) $(DSO_LDOPTS) -o $@
|
||||
|
|
|
|||
|
|
@ -10,3 +10,4 @@
|
|||
*/
|
||||
|
||||
#error "Do not include this header file."
|
||||
|
||||
|
|
|
|||
|
|
@ -26,6 +26,16 @@ include $(CORE_DEPTH)/coreconf/config.mk
|
|||
# (4) Include "local" platform-dependent assignments (OPTIONAL). #
|
||||
#######################################################################
|
||||
|
||||
# Don't build sysinit gtests unless we are also building libnsssysinit.
|
||||
# See lib/Makefile for the corresponding rules.
|
||||
ifndef MOZILLA_CLIENT
|
||||
ifeq ($(OS_ARCH),Linux)
|
||||
ifneq ($(NSS_BUILD_UTIL_ONLY),1)
|
||||
SYSINIT_GTEST=sysinit_gtest
|
||||
endif
|
||||
endif
|
||||
endif
|
||||
|
||||
|
||||
#######################################################################
|
||||
# (5) Execute "global" rules. (OPTIONAL) #
|
||||
|
|
|
|||
0
security/nss/gtests/__init__.py
Normal file
0
security/nss/gtests/__init__.py
Normal file
0
security/nss/gtests/common/__init__.py
Normal file
0
security/nss/gtests/common/__init__.py
Normal file
2993
security/nss/gtests/common/testvectors/chachapoly-vectors.h
Normal file
2993
security/nss/gtests/common/testvectors/chachapoly-vectors.h
Normal file
File diff suppressed because it is too large
Load diff
1819
security/nss/gtests/common/testvectors/curve25519-vectors.h
Normal file
1819
security/nss/gtests/common/testvectors/curve25519-vectors.h
Normal file
File diff suppressed because it is too large
Load diff
1535
security/nss/gtests/common/testvectors/gcm-vectors.h
Normal file
1535
security/nss/gtests/common/testvectors/gcm-vectors.h
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -0,0 +1,117 @@
|
|||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
/* This file is generated from sources in nss/gtests/common/wycheproof
|
||||
* automatically and should not be touched manually.
|
||||
* Generation is trigged by calling ./mach wycheproof */
|
||||
|
||||
#ifndef chachapoly_vectors_h__
|
||||
#define chachapoly_vectors_h__
|
||||
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
typedef struct chacha_testvector_str {
|
||||
uint32_t id;
|
||||
std::vector<uint8_t> Data;
|
||||
std::vector<uint8_t> AAD;
|
||||
std::vector<uint8_t> Key;
|
||||
std::vector<uint8_t> IV;
|
||||
std::vector<uint8_t> CT;
|
||||
bool invalid_tag;
|
||||
bool invalid_iv;
|
||||
} chacha_testvector;
|
||||
|
||||
// ChaCha20/Poly1305 Test Vector 1, RFC 7539
|
||||
// <http://tools.ietf.org/html/rfc7539#section-2.8.2>
|
||||
// ChaCha20/Poly1305 Test Vector 2, RFC 7539
|
||||
// <http://tools.ietf.org/html/rfc7539#appendix-A.5>
|
||||
const chacha_testvector kChaCha20Vectors[] = {
|
||||
{0,
|
||||
{0x4c, 0x61, 0x64, 0x69, 0x65, 0x73, 0x20, 0x61, 0x6e, 0x64, 0x20, 0x47,
|
||||
0x65, 0x6e, 0x74, 0x6c, 0x65, 0x6d, 0x65, 0x6e, 0x20, 0x6f, 0x66, 0x20,
|
||||
0x74, 0x68, 0x65, 0x20, 0x63, 0x6c, 0x61, 0x73, 0x73, 0x20, 0x6f, 0x66,
|
||||
0x20, 0x27, 0x39, 0x39, 0x3a, 0x20, 0x49, 0x66, 0x20, 0x49, 0x20, 0x63,
|
||||
0x6f, 0x75, 0x6c, 0x64, 0x20, 0x6f, 0x66, 0x66, 0x65, 0x72, 0x20, 0x79,
|
||||
0x6f, 0x75, 0x20, 0x6f, 0x6e, 0x6c, 0x79, 0x20, 0x6f, 0x6e, 0x65, 0x20,
|
||||
0x74, 0x69, 0x70, 0x20, 0x66, 0x6f, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20,
|
||||
0x66, 0x75, 0x74, 0x75, 0x72, 0x65, 0x2c, 0x20, 0x73, 0x75, 0x6e, 0x73,
|
||||
0x63, 0x72, 0x65, 0x65, 0x6e, 0x20, 0x77, 0x6f, 0x75, 0x6c, 0x64, 0x20,
|
||||
0x62, 0x65, 0x20, 0x69, 0x74, 0x2e},
|
||||
{0x50, 0x51, 0x52, 0x53, 0xc0, 0xc1, 0xc2, 0xc3, 0xc4, 0xc5, 0xc6, 0xc7},
|
||||
{0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87, 0x88, 0x89, 0x8a,
|
||||
0x8b, 0x8c, 0x8d, 0x8e, 0x8f, 0x90, 0x91, 0x92, 0x93, 0x94, 0x95,
|
||||
0x96, 0x97, 0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f},
|
||||
{0x07, 0x00, 0x00, 0x00, 0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47},
|
||||
{0xd3, 0x1a, 0x8d, 0x34, 0x64, 0x8e, 0x60, 0xdb, 0x7b, 0x86, 0xaf, 0xbc,
|
||||
0x53, 0xef, 0x7e, 0xc2, 0xa4, 0xad, 0xed, 0x51, 0x29, 0x6e, 0x08, 0xfe,
|
||||
0xa9, 0xe2, 0xb5, 0xa7, 0x36, 0xee, 0x62, 0xd6, 0x3d, 0xbe, 0xa4, 0x5e,
|
||||
0x8c, 0xa9, 0x67, 0x12, 0x82, 0xfa, 0xfb, 0x69, 0xda, 0x92, 0x72, 0x8b,
|
||||
0x1a, 0x71, 0xde, 0x0a, 0x9e, 0x06, 0x0b, 0x29, 0x05, 0xd6, 0xa5, 0xb6,
|
||||
0x7e, 0xcd, 0x3b, 0x36, 0x92, 0xdd, 0xbd, 0x7f, 0x2d, 0x77, 0x8b, 0x8c,
|
||||
0x98, 0x03, 0xae, 0xe3, 0x28, 0x09, 0x1b, 0x58, 0xfa, 0xb3, 0x24, 0xe4,
|
||||
0xfa, 0xd6, 0x75, 0x94, 0x55, 0x85, 0x80, 0x8b, 0x48, 0x31, 0xd7, 0xbc,
|
||||
0x3f, 0xf4, 0xde, 0xf0, 0x8e, 0x4b, 0x7a, 0x9d, 0xe5, 0x76, 0xd2, 0x65,
|
||||
0x86, 0xce, 0xc6, 0x4b, 0x61, 0x16, 0x1a, 0xe1, 0x0b, 0x59, 0x4f, 0x09,
|
||||
0xe2, 0x6a, 0x7e, 0x90, 0x2e, 0xcb, 0xd0, 0x60, 0x06, 0x91},
|
||||
false,
|
||||
false},
|
||||
{1,
|
||||
{0x49, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x65, 0x74, 0x2d, 0x44, 0x72, 0x61,
|
||||
0x66, 0x74, 0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x64, 0x72, 0x61, 0x66,
|
||||
0x74, 0x20, 0x64, 0x6f, 0x63, 0x75, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x20,
|
||||
0x76, 0x61, 0x6c, 0x69, 0x64, 0x20, 0x66, 0x6f, 0x72, 0x20, 0x61, 0x20,
|
||||
0x6d, 0x61, 0x78, 0x69, 0x6d, 0x75, 0x6d, 0x20, 0x6f, 0x66, 0x20, 0x73,
|
||||
0x69, 0x78, 0x20, 0x6d, 0x6f, 0x6e, 0x74, 0x68, 0x73, 0x20, 0x61, 0x6e,
|
||||
0x64, 0x20, 0x6d, 0x61, 0x79, 0x20, 0x62, 0x65, 0x20, 0x75, 0x70, 0x64,
|
||||
0x61, 0x74, 0x65, 0x64, 0x2c, 0x20, 0x72, 0x65, 0x70, 0x6c, 0x61, 0x63,
|
||||
0x65, 0x64, 0x2c, 0x20, 0x6f, 0x72, 0x20, 0x6f, 0x62, 0x73, 0x6f, 0x6c,
|
||||
0x65, 0x74, 0x65, 0x64, 0x20, 0x62, 0x79, 0x20, 0x6f, 0x74, 0x68, 0x65,
|
||||
0x72, 0x20, 0x64, 0x6f, 0x63, 0x75, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x20,
|
||||
0x61, 0x74, 0x20, 0x61, 0x6e, 0x79, 0x20, 0x74, 0x69, 0x6d, 0x65, 0x2e,
|
||||
0x20, 0x49, 0x74, 0x20, 0x69, 0x73, 0x20, 0x69, 0x6e, 0x61, 0x70, 0x70,
|
||||
0x72, 0x6f, 0x70, 0x72, 0x69, 0x61, 0x74, 0x65, 0x20, 0x74, 0x6f, 0x20,
|
||||
0x75, 0x73, 0x65, 0x20, 0x49, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x65, 0x74,
|
||||
0x2d, 0x44, 0x72, 0x61, 0x66, 0x74, 0x73, 0x20, 0x61, 0x73, 0x20, 0x72,
|
||||
0x65, 0x66, 0x65, 0x72, 0x65, 0x6e, 0x63, 0x65, 0x20, 0x6d, 0x61, 0x74,
|
||||
0x65, 0x72, 0x69, 0x61, 0x6c, 0x20, 0x6f, 0x72, 0x20, 0x74, 0x6f, 0x20,
|
||||
0x63, 0x69, 0x74, 0x65, 0x20, 0x74, 0x68, 0x65, 0x6d, 0x20, 0x6f, 0x74,
|
||||
0x68, 0x65, 0x72, 0x20, 0x74, 0x68, 0x61, 0x6e, 0x20, 0x61, 0x73, 0x20,
|
||||
0x2f, 0xe2, 0x80, 0x9c, 0x77, 0x6f, 0x72, 0x6b, 0x20, 0x69, 0x6e, 0x20,
|
||||
0x70, 0x72, 0x6f, 0x67, 0x72, 0x65, 0x73, 0x73, 0x2e, 0x2f, 0xe2, 0x80,
|
||||
0x9d},
|
||||
{0xf3, 0x33, 0x88, 0x86, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x4e, 0x91},
|
||||
{0x1c, 0x92, 0x40, 0xa5, 0xeb, 0x55, 0xd3, 0x8a, 0xf3, 0x33, 0x88,
|
||||
0x86, 0x04, 0xf6, 0xb5, 0xf0, 0x47, 0x39, 0x17, 0xc1, 0x40, 0x2b,
|
||||
0x80, 0x09, 0x9d, 0xca, 0x5c, 0xbc, 0x20, 0x70, 0x75, 0xc0},
|
||||
{0x00, 0x00, 0x00, 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08},
|
||||
{0x64, 0xa0, 0x86, 0x15, 0x75, 0x86, 0x1a, 0xf4, 0x60, 0xf0, 0x62, 0xc7,
|
||||
0x9b, 0xe6, 0x43, 0xbd, 0x5e, 0x80, 0x5c, 0xfd, 0x34, 0x5c, 0xf3, 0x89,
|
||||
0xf1, 0x08, 0x67, 0x0a, 0xc7, 0x6c, 0x8c, 0xb2, 0x4c, 0x6c, 0xfc, 0x18,
|
||||
0x75, 0x5d, 0x43, 0xee, 0xa0, 0x9e, 0xe9, 0x4e, 0x38, 0x2d, 0x26, 0xb0,
|
||||
0xbd, 0xb7, 0xb7, 0x3c, 0x32, 0x1b, 0x01, 0x00, 0xd4, 0xf0, 0x3b, 0x7f,
|
||||
0x35, 0x58, 0x94, 0xcf, 0x33, 0x2f, 0x83, 0x0e, 0x71, 0x0b, 0x97, 0xce,
|
||||
0x98, 0xc8, 0xa8, 0x4a, 0xbd, 0x0b, 0x94, 0x81, 0x14, 0xad, 0x17, 0x6e,
|
||||
0x00, 0x8d, 0x33, 0xbd, 0x60, 0xf9, 0x82, 0xb1, 0xff, 0x37, 0xc8, 0x55,
|
||||
0x97, 0x97, 0xa0, 0x6e, 0xf4, 0xf0, 0xef, 0x61, 0xc1, 0x86, 0x32, 0x4e,
|
||||
0x2b, 0x35, 0x06, 0x38, 0x36, 0x06, 0x90, 0x7b, 0x6a, 0x7c, 0x02, 0xb0,
|
||||
0xf9, 0xf6, 0x15, 0x7b, 0x53, 0xc8, 0x67, 0xe4, 0xb9, 0x16, 0x6c, 0x76,
|
||||
0x7b, 0x80, 0x4d, 0x46, 0xa5, 0x9b, 0x52, 0x16, 0xcd, 0xe7, 0xa4, 0xe9,
|
||||
0x90, 0x40, 0xc5, 0xa4, 0x04, 0x33, 0x22, 0x5e, 0xe2, 0x82, 0xa1, 0xb0,
|
||||
0xa0, 0x6c, 0x52, 0x3e, 0xaf, 0x45, 0x34, 0xd7, 0xf8, 0x3f, 0xa1, 0x15,
|
||||
0x5b, 0x00, 0x47, 0x71, 0x8c, 0xbc, 0x54, 0x6a, 0x0d, 0x07, 0x2b, 0x04,
|
||||
0xb3, 0x56, 0x4e, 0xea, 0x1b, 0x42, 0x22, 0x73, 0xf5, 0x48, 0x27, 0x1a,
|
||||
0x0b, 0xb2, 0x31, 0x60, 0x53, 0xfa, 0x76, 0x99, 0x19, 0x55, 0xeb, 0xd6,
|
||||
0x31, 0x59, 0x43, 0x4e, 0xce, 0xbb, 0x4e, 0x46, 0x6d, 0xae, 0x5a, 0x10,
|
||||
0x73, 0xa6, 0x72, 0x76, 0x27, 0x09, 0x7a, 0x10, 0x49, 0xe6, 0x17, 0xd9,
|
||||
0x1d, 0x36, 0x10, 0x94, 0xfa, 0x68, 0xf0, 0xff, 0x77, 0x98, 0x71, 0x30,
|
||||
0x30, 0x5b, 0xea, 0xba, 0x2e, 0xda, 0x04, 0xdf, 0x99, 0x7b, 0x71, 0x4d,
|
||||
0x6c, 0x6f, 0x2c, 0x29, 0xa6, 0xad, 0x5c, 0xb4, 0x02, 0x2b, 0x02, 0x70,
|
||||
0x9b, 0xee, 0xad, 0x9d, 0x67, 0x89, 0x0c, 0xbb, 0x22, 0x39, 0x23, 0x36,
|
||||
0xfe, 0xa1, 0x85, 0x1f, 0x38},
|
||||
false,
|
||||
false}};
|
||||
|
||||
#endif // chachapoly_vectors_h__
|
||||
|
|
@ -0,0 +1,75 @@
|
|||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
#ifndef curve25519_vectors_h__
|
||||
#define curve25519_vectors_h__
|
||||
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
typedef struct curve25519_testvector_str {
|
||||
std::vector<uint8_t> private_key;
|
||||
std::vector<uint8_t> public_key;
|
||||
std::vector<uint8_t> secret;
|
||||
bool valid;
|
||||
} curve25519_testvector;
|
||||
|
||||
const curve25519_testvector kCurve25519Vectors[] = {
|
||||
{{0x30, 0x67, 0x02, 0x01, 0x00, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48,
|
||||
0xce, 0x3d, 0x02, 0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda,
|
||||
0x47, 0x0f, 0x01, 0x04, 0x4c, 0x30, 0x4a, 0x02, 0x01, 0x01, 0x04, 0x20,
|
||||
0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5, 0x7d, 0x3c, 0x16, 0xc1, 0x72,
|
||||
0x51, 0xb2, 0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb, 0xc0, 0x99, 0x2a,
|
||||
0xb1, 0x77, 0xfb, 0xa5, 0x1d, 0xb9, 0x2c, 0x2a, 0xa1, 0x23, 0x03, 0x21,
|
||||
0x00, 0x85, 0x20, 0xf0, 0x09, 0x89, 0x30, 0xa7, 0x54, 0x74, 0x8b, 0x7d,
|
||||
0xdc, 0xb4, 0x3e, 0xf7, 0x5a, 0x0d, 0xbf, 0x3a, 0x0d, 0x26, 0x38, 0x1a,
|
||||
0xf4, 0xeb, 0xa4, 0xa9, 0x8e, 0xaa, 0x9b, 0x4e, 0x6a},
|
||||
{0x30, 0x39, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x21, 0x00, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3,
|
||||
0x5b, 0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
|
||||
0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f},
|
||||
{0x4a, 0x5d, 0x9d, 0x5b, 0xa4, 0xce, 0x2d, 0xe1, 0x72, 0x8e, 0x3b,
|
||||
0xf4, 0x80, 0x35, 0x0f, 0x25, 0xe0, 0x7e, 0x21, 0xc9, 0x47, 0xd1,
|
||||
0x9e, 0x33, 0x76, 0xf0, 0x9b, 0x3c, 0x1e, 0x16, 0x17, 0x42},
|
||||
true},
|
||||
|
||||
// A public key that's too short (31 bytes).
|
||||
{{0x30, 0x67, 0x02, 0x01, 0x00, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48,
|
||||
0xce, 0x3d, 0x02, 0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda,
|
||||
0x47, 0x0f, 0x01, 0x04, 0x4c, 0x30, 0x4a, 0x02, 0x01, 0x01, 0x04, 0x20,
|
||||
0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5, 0x7d, 0x3c, 0x16, 0xc1, 0x72,
|
||||
0x51, 0xb2, 0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb, 0xc0, 0x99, 0x2a,
|
||||
0xb1, 0x77, 0xfb, 0xa5, 0x1d, 0xb9, 0x2c, 0x2a, 0xa1, 0x23, 0x03, 0x21,
|
||||
0x00, 0x85, 0x20, 0xf0, 0x09, 0x89, 0x30, 0xa7, 0x54, 0x74, 0x8b, 0x7d,
|
||||
0xdc, 0xb4, 0x3e, 0xf7, 0x5a, 0x0d, 0xbf, 0x3a, 0x0d, 0x26, 0x38, 0x1a,
|
||||
0xf4, 0xeb, 0xa4, 0xa9, 0x8e, 0xaa, 0x9b, 0x4e, 0x6a},
|
||||
{0x30, 0x38, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x20, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3, 0x5b,
|
||||
0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b, 0x78,
|
||||
0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f},
|
||||
{},
|
||||
false},
|
||||
|
||||
// A public key that's too long (33 bytes).
|
||||
{{0x30, 0x67, 0x02, 0x01, 0x00, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48,
|
||||
0xce, 0x3d, 0x02, 0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda,
|
||||
0x47, 0x0f, 0x01, 0x04, 0x4c, 0x30, 0x4a, 0x02, 0x01, 0x01, 0x04, 0x20,
|
||||
0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5, 0x7d, 0x3c, 0x16, 0xc1, 0x72,
|
||||
0x51, 0xb2, 0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb, 0xc0, 0x99, 0x2a,
|
||||
0xb1, 0x77, 0xfb, 0xa5, 0x1d, 0xb9, 0x2c, 0x2a, 0xa1, 0x23, 0x03, 0x21,
|
||||
0x00, 0x85, 0x20, 0xf0, 0x09, 0x89, 0x30, 0xa7, 0x54, 0x74, 0x8b, 0x7d,
|
||||
0xdc, 0xb4, 0x3e, 0xf7, 0x5a, 0x0d, 0xbf, 0x3a, 0x0d, 0x26, 0x38, 0x1a,
|
||||
0xf4, 0xeb, 0xa4, 0xa9, 0x8e, 0xaa, 0x9b, 0x4e, 0x6a},
|
||||
{0x30, 0x3a, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x22, 0x00, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3,
|
||||
0x5b, 0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
|
||||
0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f, 0x34},
|
||||
{},
|
||||
false}};
|
||||
|
||||
#endif // curve25519_vectors_h__
|
||||
197
security/nss/gtests/common/testvectors_base/gcm-vectors_base.h
Normal file
197
security/nss/gtests/common/testvectors_base/gcm-vectors_base.h
Normal file
|
|
@ -0,0 +1,197 @@
|
|||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
/* This file is generated from sources in nss/gtests/common/wycheproof
|
||||
* automatically and should not be touched manually.
|
||||
* Generation is trigged by calling ./mach wycheproof */
|
||||
|
||||
#ifndef gcm_vectors_h__
|
||||
#define gcm_vectors_h__
|
||||
|
||||
#include <string>
|
||||
|
||||
typedef struct gcm_kat_str {
|
||||
uint32_t test_id;
|
||||
std::string key;
|
||||
std::string plaintext;
|
||||
std::string additional_data;
|
||||
std::string iv;
|
||||
std::string hash_key;
|
||||
std::string ghash;
|
||||
std::string result;
|
||||
bool invalid_ct;
|
||||
bool invalid_iv;
|
||||
} gcm_kat_value;
|
||||
|
||||
/*
|
||||
* http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/gcm/gcm-revised-spec.pdf
|
||||
*/
|
||||
const gcm_kat_value kGcmKatValues[] = {
|
||||
{1, "00000000000000000000000000000000", "", "", "000000000000000000000000",
|
||||
"66e94bd4ef8a2c3b884cfa59ca342b2e", "00000000000000000000000000000000",
|
||||
"58e2fccefa7e3061367f1d57a4e7455a", false, false},
|
||||
|
||||
{2, "00000000000000000000000000000000", "00000000000000000000000000000000",
|
||||
"", "000000000000000000000000", "66e94bd4ef8a2c3b884cfa59ca342b2e",
|
||||
"f38cbb1ad69223dcc3457ae5b6b0f885",
|
||||
"0388dace60b6a392f328c2b971b2fe78ab6e47d42cec13bdf53a67b21257bddf", false,
|
||||
false},
|
||||
|
||||
{3, "feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b391aafd255",
|
||||
"", "cafebabefacedbaddecaf888", "b83b533708bf535d0aa6e52980d53b78",
|
||||
"7f1b32b81b820d02614f8895ac1d4eac",
|
||||
"42831ec2217774244b7221b784d0d49ce3aa212f2c02a4e035c17e2329aca12e21d514b25"
|
||||
"466931c7d8f6a5aac84aa051ba30b396a0aac973d58e091473f59854d5c2af327cd64a62c"
|
||||
"f35abd2ba6fab4",
|
||||
false, false},
|
||||
|
||||
{4, "feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbaddecaf888",
|
||||
"b83b533708bf535d0aa6e52980d53b78", "698e57f70e6ecc7fd9463b7260a9ae5f",
|
||||
"42831ec2217774244b7221b784d0d49ce3aa212f2c02a4e035c17e2329aca12e21d514b25"
|
||||
"466931c7d8f6a5aac84aa051ba30b396a0aac973d58e0915bc94fbc3221a5db94fae95ae7"
|
||||
"121a47",
|
||||
false, false},
|
||||
|
||||
{5, "feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbad",
|
||||
"b83b533708bf535d0aa6e52980d53b78", "df586bb4c249b92cb6922877e444d37b",
|
||||
"61353b4c2806934a777ff51fa22a4755699b2a714fcdc6f83766e5f97b6c742373806900e"
|
||||
"49f24b22b097544d4896b424989b5e1ebac0f07c23f45983612d2e79e3b0785561be14aac"
|
||||
"a2fccb",
|
||||
false, false},
|
||||
|
||||
{6, "feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2",
|
||||
"9313225df88406e555909c5aff5269aa6a7a9538534f7da1e4c303d2a318a728c3c0c9515"
|
||||
"6809539fcf0e2429a6b525416aedbf5a0de6a57a637b39b",
|
||||
"b83b533708bf535d0aa6e52980d53b78", "1c5afe9760d3932f3c9a878aac3dc3de",
|
||||
"8ce24998625615b603a033aca13fb894be9112a5c3a211a8ba262a3cca7e2ca701e4a9a4f"
|
||||
"ba43c90ccdcb281d48c7c6fd62875d2aca417034c34aee5619cc5aefffe0bfa462af43c16"
|
||||
"99d050",
|
||||
false, false},
|
||||
|
||||
{7, "000000000000000000000000000000000000000000000000", "", "",
|
||||
"000000000000000000000000", "aae06992acbf52a3e8f4a96ec9300bd7",
|
||||
"00000000000000000000000000000000", "cd33b28ac773f74ba00ed1f312572435",
|
||||
false, false},
|
||||
|
||||
{8, "000000000000000000000000000000000000000000000000",
|
||||
"00000000000000000000000000000000", "", "000000000000000000000000",
|
||||
"aae06992acbf52a3e8f4a96ec9300bd7", "e2c63f0ac44ad0e02efa05ab6743d4ce",
|
||||
"98e7247c07f0fe411c267e4384b0f6002ff58d80033927ab8ef4d4587514f0fb", false,
|
||||
false},
|
||||
|
||||
{9, "feffe9928665731c6d6a8f9467308308feffe9928665731c",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b391aafd255",
|
||||
"", "cafebabefacedbaddecaf888", "466923ec9ae682214f2c082badb39249",
|
||||
"51110d40f6c8fff0eb1ae33445a889f0",
|
||||
"3980ca0b3c00e841eb06fac4872a2757859e1ceaa6efd984628593b40ca1e19c7d773d00c"
|
||||
"144c525ac619d18c84a3f4718e2448b2fe324d9ccda2710acade2569924a7c8587336bfb1"
|
||||
"18024db8674a14",
|
||||
false, false},
|
||||
|
||||
{10, "feffe9928665731c6d6a8f9467308308feffe9928665731c",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbaddecaf888",
|
||||
"466923ec9ae682214f2c082badb39249", "ed2ce3062e4a8ec06db8b4c490e8a268",
|
||||
"3980ca0b3c00e841eb06fac4872a2757859e1ceaa6efd984628593b40ca1e19c7d773d00c"
|
||||
"144c525ac619d18c84a3f4718e2448b2fe324d9ccda27102519498e80f1478f37ba55bd6d"
|
||||
"27618c",
|
||||
false, false},
|
||||
|
||||
{11, "feffe9928665731c6d6a8f9467308308feffe9928665731c",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbad",
|
||||
"466923ec9ae682214f2c082badb39249", "1e6a133806607858ee80eaf237064089",
|
||||
"0f10f599ae14a154ed24b36e25324db8c566632ef2bbb34f8347280fc4507057fddc29df9"
|
||||
"a471f75c66541d4d4dad1c9e93a19a58e8b473fa0f062f765dcc57fcf623a24094fcca40d"
|
||||
"3533f8",
|
||||
false, false},
|
||||
|
||||
{12, "feffe9928665731c6d6a8f9467308308feffe9928665731c",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2",
|
||||
"9313225df88406e555909c5aff5269aa6a7a9538534f7da1e4c303d2a318a728c3c0c9515"
|
||||
"6809539fcf0e2429a6b525416aedbf5a0de6a57a637b39b",
|
||||
"466923ec9ae682214f2c082badb39249", "82567fb0b4cc371801eadec005968e94",
|
||||
"d27e88681ce3243c4830165a8fdcf9ff1de9a1d8e6b447ef6ef7b79828666e4581e79012a"
|
||||
"f34ddd9e2f037589b292db3e67c036745fa22e7e9b7373bdcf566ff291c25bbb8568fc3d3"
|
||||
"76a6d9",
|
||||
false, false},
|
||||
|
||||
{13, "0000000000000000000000000000000000000000000000000000000000000000", "",
|
||||
"", "000000000000000000000000", "dc95c078a2408989ad48a21492842087",
|
||||
"00000000000000000000000000000000", "530f8afbc74536b9a963b4f1c4cb738b",
|
||||
false, false},
|
||||
|
||||
{14, "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"00000000000000000000000000000000", "", "000000000000000000000000",
|
||||
"dc95c078a2408989ad48a21492842087", "83de425c5edc5d498f382c441041ca92",
|
||||
"cea7403d4d606b6e074ec5d3baf39d18d0d1c8a799996bf0265b98b5d48ab919", false,
|
||||
false},
|
||||
|
||||
{15, "feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b391aafd255",
|
||||
"", "cafebabefacedbaddecaf888", "acbef20579b4b8ebce889bac8732dad7",
|
||||
"4db870d37cb75fcb46097c36230d1612",
|
||||
"522dc1f099567d07f47f37a32a84427d643a8cdcbfe5c0c97598a2bd2555d1aa8cb08e485"
|
||||
"90dbb3da7b08b1056828838c5f61e6393ba7a0abcc9f662898015adb094dac5d93471bdec"
|
||||
"1a502270e3cc6c",
|
||||
false, false},
|
||||
|
||||
{16, "feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbaddecaf888",
|
||||
"acbef20579b4b8ebce889bac8732dad7", "8bd0c4d8aacd391e67cca447e8c38f65",
|
||||
"522dc1f099567d07f47f37a32a84427d643a8cdcbfe5c0c97598a2bd2555d1aa8cb08e485"
|
||||
"90dbb3da7b08b1056828838c5f61e6393ba7a0abcc9f66276fc6ece0f4e1768cddf8853bb"
|
||||
"2d551b",
|
||||
false, false},
|
||||
|
||||
{17, "feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2", "cafebabefacedbad",
|
||||
"acbef20579b4b8ebce889bac8732dad7", "75a34288b8c68f811c52b2e9a2f97f63",
|
||||
"c3762df1ca787d32ae47c13bf19844cbaf1ae14d0b976afac52ff7d79bba9de0feb582d33"
|
||||
"934a4f0954cc2363bc73f7862ac430e64abe499f47c9b1f3a337dbf46a792c45e454913fe"
|
||||
"2ea8f2",
|
||||
false, false},
|
||||
|
||||
{18, "feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308",
|
||||
"d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c959"
|
||||
"56809532fcf0e2449a6b525b16aedf5aa0de657ba637b39",
|
||||
"feedfacedeadbeeffeedfacedeadbeefabaddad2",
|
||||
"9313225df88406e555909c5aff5269aa6a7a9538534f7da1e4c303d2a318a728c3c0c9515"
|
||||
"6809539fcf0e2429a6b525416aedbf5a0de6a57a637b39b",
|
||||
"acbef20579b4b8ebce889bac8732dad7", "d5ffcf6fc5ac4d69722187421a7f170b",
|
||||
"5a8def2f0c9e53f1f75d7853659e2a20eeb2b22aafde6419a058ab4f6f746bf40fc0c3b78"
|
||||
"0f244452da3ebf1c5d82cdea2418997200ef82e44ae7e3fa44a8266ee1c8eb0c8b5d4cf5a"
|
||||
"e9f19a",
|
||||
false, false},
|
||||
|
||||
/* Extra, non-NIST, test case to test 64-bit binary multiplication carry
|
||||
* correctness. This is a GHASH-only test. */
|
||||
{19, "", "", "", "", "0000000000000000fcefef64ffc4766c",
|
||||
"3561e34e52d8b598f9937982512fff27",
|
||||
"0000000000000000ffcef9ebbffdbd8b00000000000000000000000000000000", false,
|
||||
false}};
|
||||
|
||||
#endif // gcm_vectors_h__
|
||||
0
security/nss/gtests/common/wycheproof/__init__.py
Normal file
0
security/nss/gtests/common/wycheproof/__init__.py
Normal file
191
security/nss/gtests/common/wycheproof/genTestVectors.py
Normal file
191
security/nss/gtests/common/wycheproof/genTestVectors.py
Normal file
|
|
@ -0,0 +1,191 @@
|
|||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
# You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
import json
|
||||
import os
|
||||
import subprocess
|
||||
|
||||
script_dir = os.path.dirname(os.path.abspath(__file__))
|
||||
|
||||
# Imports a JSON testvector file.
|
||||
def import_testvector(file):
|
||||
"""Import a JSON testvector file and return an array of the contained objects."""
|
||||
with open(file) as f:
|
||||
vectors = json.loads(f.read())
|
||||
return vectors
|
||||
|
||||
# Convert a test data string to a hex array.
|
||||
def string_to_hex_array(string):
|
||||
"""Convert a string of hex chars to a string representing a C-format array of hex bytes."""
|
||||
b = bytearray.fromhex(string)
|
||||
result = '{' + ', '.join("{:#04x}".format(x) for x in b) + '}'
|
||||
return result
|
||||
|
||||
# Writes one AES-GCM testvector into C-header format. (Not clang-format conform)
|
||||
class AESGCM():
|
||||
"""Class that provides the generator function for a single AES-GCM test case."""
|
||||
|
||||
def format_testcase(self, vector):
|
||||
"""Format an AES-GCM testcase object. Return a string in C-header format."""
|
||||
result = '{{ {},\n'.format(vector['tcId'])
|
||||
for key in ['key', 'msg', 'aad', 'iv']:
|
||||
result += ' \"{}\",\n'.format(vector[key])
|
||||
result += ' \"\",\n'
|
||||
result += ' \"{}\",\n'.format(vector['tag'])
|
||||
result += ' \"{}\",\n'.format(vector['ct'] + vector['tag'])
|
||||
result += ' {},\n'.format(str(vector['result'] == 'invalid').lower())
|
||||
result += ' {}}},\n\n'.format(str('ZeroLengthIv' in vector['flags']).lower())
|
||||
|
||||
return result
|
||||
|
||||
# Writes one ChaChaPoly testvector into C-header format. (Not clang-format conform)
|
||||
class ChaChaPoly():
|
||||
"""Class that provides the generator function for a single ChaCha test case."""
|
||||
|
||||
def format_testcase(self, testcase):
|
||||
"""Format an ChaCha testcase object. Return a string in C-header format."""
|
||||
result = '\n// Comment: {}'.format(testcase['comment'])
|
||||
result += '\n{{{},\n'.format(testcase['tcId']-1)
|
||||
for key in ['msg', 'aad', 'key', 'iv']:
|
||||
result += '{},\n'.format(string_to_hex_array(testcase[key]))
|
||||
ct = testcase['ct'] + testcase['tag']
|
||||
result += '{},\n'.format(string_to_hex_array(ct))
|
||||
result += '{},\n'.format(str(testcase['result'] == 'invalid').lower())
|
||||
result += '{}}},\n'.format(str(testcase['comment'] == 'invalid nonce size').lower())
|
||||
|
||||
return result
|
||||
|
||||
# Writes one Curve25519 testvector into C-header format. (Not clang-format conform)
|
||||
class Curve25519():
|
||||
"""Class that provides the generator function for a single curve25519 test case."""
|
||||
|
||||
# Static pkcs8 and skpi wrappers for the raw keys from Wycheproof.
|
||||
# The public key section of the pkcs8 wrapper is filled up with 0's, which is
|
||||
# not correct, but acceptable for the tests at this moment because
|
||||
# validity of the public key is not checked.
|
||||
# It's still necessary because of
|
||||
# https://searchfox.org/nss/rev/7bc70a3317b800aac07bad83e74b6c79a9ec5bff/lib/pk11wrap/pk11pk12.c#171
|
||||
pkcs8WrapperStart = "3067020100301406072a8648ce3d020106092b06010401da470f01044c304a0201010420"
|
||||
pkcs8WrapperEnd = "a1230321000000000000000000000000000000000000000000000000000000000000000000"
|
||||
spkiWrapper = "3039301406072a8648ce3d020106092b06010401da470f01032100"
|
||||
|
||||
def format_testcase(self, testcase):
|
||||
result = '\n// Comment: {}'.format(testcase['comment'])
|
||||
result += '\n{{{},\n'.format(string_to_hex_array(self.pkcs8WrapperStart + testcase['private'] + self.pkcs8WrapperEnd))
|
||||
result += '{},\n'.format(string_to_hex_array(self.spkiWrapper + testcase['public']))
|
||||
result += '{},\n'.format(string_to_hex_array(testcase['shared']))
|
||||
|
||||
# Flag 'acceptable' cases with secret == 0 as invalid for NSS.
|
||||
# Flag 'acceptable' cases with forbidden public key values as invalid for NSS.
|
||||
# Flag 'acceptable' cases with small public key (0 or 1) as invalid for NSS.
|
||||
valid = testcase['result'] in ['valid', 'acceptable'] \
|
||||
and not testcase['shared'] == "0000000000000000000000000000000000000000000000000000000000000000" \
|
||||
and not testcase["public"] == "daffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" \
|
||||
and not testcase["public"] == "dbffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" \
|
||||
and not 'Small public key' in testcase['flags']
|
||||
result += '{}}},\n'.format(str(valid).lower())
|
||||
|
||||
return result
|
||||
|
||||
def generate_vectors_file(params):
|
||||
"""
|
||||
Generate and store a .h-file with test vectors for one test.
|
||||
|
||||
params -- Dictionary with parameters for test vector generation for the desired test.
|
||||
"""
|
||||
|
||||
cases = import_testvector(os.path.join(script_dir, params['source_dir'] + params['source_file']))
|
||||
|
||||
with open(os.path.join(script_dir, params['base'])) as base:
|
||||
header = base.read()
|
||||
|
||||
header = header[:params['crop_size_start']]
|
||||
header += '\n\n// Testvectors from project wycheproof\n'
|
||||
header += '// <https://github.com/google/wycheproof>\n'
|
||||
vectors_file = header + params['array_init']
|
||||
|
||||
for group in cases['testGroups']:
|
||||
for test in group['tests']:
|
||||
vectors_file += params['formatter'].format_testcase(test)
|
||||
|
||||
vectors_file = vectors_file[:params['crop_size_end']] + '};\n\n'
|
||||
vectors_file += params['finish']
|
||||
|
||||
with open(os.path.join(script_dir, params['target']), 'w') as target:
|
||||
target.write(vectors_file)
|
||||
|
||||
# Parameters that describe the generation of a testvector file for each supoorted testself.
|
||||
# source -- relaive path the wycheproof JSON source file with testvectorsself.
|
||||
# base -- relative path to the pre-fabricated .h-file with general defintions and non-wycheproof vectors.
|
||||
# target -- relative path to where the finished .h-file is written.
|
||||
# crop_size_start -- number of characters removed from the end of the base file at start.
|
||||
# array_init -- string to initialize the c-header style array of testvectors.
|
||||
# formatter -- the test case formatter class to be used for this test.
|
||||
# crop_size_end -- number of characters removed from the end of the last generated test vector to close the array definiton.
|
||||
# finish -- string to re-insert at the end and finish the file. (identical to chars cropped at the start)
|
||||
# comment -- additional comments to add to the file just before defintion of the test vector array.
|
||||
aes_gcm_params = {
|
||||
'source_dir': 'source_vectors/',
|
||||
'source_file': 'aes_gcm_test.json',
|
||||
'base': '../testvectors_base/gcm-vectors_base.h',
|
||||
'target': '../testvectors/gcm-vectors.h',
|
||||
'crop_size_start': -27,
|
||||
'array_init': 'const gcm_kat_value kGcmWycheproofVectors[] = {\n',
|
||||
'formatter' : AESGCM(),
|
||||
'crop_size_end': -3,
|
||||
'finish': '#endif // gcm_vectors_h__\n',
|
||||
'comment' : ''
|
||||
}
|
||||
|
||||
chacha_poly_params = {
|
||||
'source_dir': 'source_vectors/',
|
||||
'source_file': 'chacha20_poly1305_test.json',
|
||||
'base': '../testvectors_base/chachapoly-vectors_base.h',
|
||||
'target': '../testvectors/chachapoly-vectors.h',
|
||||
'crop_size_start': -35,
|
||||
'array_init': 'const chacha_testvector kChaCha20WycheproofVectors[] = {\n',
|
||||
'formatter' : ChaChaPoly(),
|
||||
'crop_size_end': -2,
|
||||
'finish': '#endif // chachapoly_vectors_h__\n',
|
||||
'comment' : ''
|
||||
}
|
||||
|
||||
curve25519_params = {
|
||||
'source_dir': 'source_vectors/',
|
||||
'source_file': 'x25519_test.json',
|
||||
'base': '../testvectors_base/curve25519-vectors_base.h',
|
||||
'target': '../testvectors/curve25519-vectors.h',
|
||||
'crop_size_start': -34,
|
||||
'array_init': 'const curve25519_testvector kCurve25519WycheproofVectors[] = {\n',
|
||||
'formatter' : Curve25519(),
|
||||
'crop_size_end': -2,
|
||||
'finish': '#endif // curve25519_vectors_h__\n',
|
||||
'comment' : '// The public key section of the pkcs8 wrapped private key is\n\
|
||||
// filled up with 0\'s, which is not correct, but acceptable for the\n\
|
||||
// tests at this moment because validity of the public key is not checked.\n'
|
||||
}
|
||||
|
||||
def update_tests(tests):
|
||||
|
||||
remote = "https://raw.githubusercontent.com/google/wycheproof/master/testvectors/"
|
||||
for test in tests:
|
||||
subprocess.check_call(['wget', remote+test['source_file'], '-O',
|
||||
'gtests/common/wycheproof/source_vectors/' +test['source_file'],
|
||||
'--no-check-certificate'])
|
||||
|
||||
def generate_test_vectors():
|
||||
"""Generate C-header files for all supported tests."""
|
||||
all_tests = [aes_gcm_params, chacha_poly_params, curve25519_params]
|
||||
update_tests(all_tests)
|
||||
for test in all_tests:
|
||||
generate_vectors_file(test)
|
||||
|
||||
def main():
|
||||
generate_test_vectors()
|
||||
|
||||
if __name__ == '__main__':
|
||||
main()
|
||||
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
|
|
@ -0,0 +1,956 @@
|
|||
{
|
||||
"algorithm" : "X25519",
|
||||
"generatorVersion" : "0.4.12",
|
||||
"notes" : {
|
||||
"LowOrderPublic" : "Curve25519 or its twist contains some points of low order. This test vector contains a public key with such a point. While many libraries reject such public keys, doing so is not a strict requirement according to RFC 7748.",
|
||||
"Small public key" : "The public key is insecure and does not belong to a valid private key. Some libraries reject such keys.",
|
||||
"Twist" : "Public keys are either points on curve25519 or points on its twist. Implementations may either reject such keys or compute X25519 using the twist. If a point multiplication is performed then it is important that the result is correct, since otherwise attacks with invalid keys are possible."
|
||||
},
|
||||
"numberOfTests" : 87,
|
||||
"header" : [],
|
||||
"testGroups" : [
|
||||
{
|
||||
"curve" : "curve25519",
|
||||
"tests" : [
|
||||
{
|
||||
"tcId" : 1,
|
||||
"comment" : "normal case",
|
||||
"curve" : "curve25519",
|
||||
"public" : "9c647d9ae589b9f58fdc3ca4947efbc915c4b2e08e744a0edf469dac59c8f85a",
|
||||
"private" : "4852834d9d6b77dadeabaaf2e11dca66d19fe74993a7bec36c6e16a0983feaba",
|
||||
"shared" : "87b7f212b627f7a54ca5e0bcdaddd5389d9de6156cdbcf8ebe14ffbcfb436551",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 2,
|
||||
"comment" : "normal case",
|
||||
"curve" : "curve25519",
|
||||
"public" : "9c647d9ae589b9f58fdc3ca4947efbc915c4b2e08e744a0edf469dac59c8f85a",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "4b82bd8650ea9b81a42181840926a4ffa16434d1bf298de1db87efb5b0a9e34e",
|
||||
"result" : "valid",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 3,
|
||||
"comment" : "public key on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "63aa40c6e38346c5caf23a6df0a5e6c80889a08647e551b3563449befcfc9733",
|
||||
"private" : "588c061a50804ac488ad774ac716c3f5ba714b2712e048491379a500211998a8",
|
||||
"shared" : "b1a707519495ffffb298ff941716b06dfab87cf8d91123fe2be9a233dda22212",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 4,
|
||||
"comment" : "public key on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0f83c36fded9d32fadf4efa3ae93a90bb5cfa66893bc412c43fa7287dbb99779",
|
||||
"private" : "b05bfd32e55325d9fd648cb302848039000b390e44d521e58aab3b29a6960ba8",
|
||||
"shared" : "67dd4a6e165533534c0e3f172e4ab8576bca923a5f07b2c069b4c310ff2e935b",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 5,
|
||||
"comment" : "public key on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0b8211a2b6049097f6871c6c052d3c5fc1ba17da9e32ae458403b05bb283092a",
|
||||
"private" : "70e34bcbe1f47fbc0fddfd7c1e1aa53d57bfe0f66d243067b424bb6210bed19c",
|
||||
"shared" : "4a0638cfaa9ef1933b47f8939296a6b25be541ef7f70e844c0bcc00b134de64a",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 6,
|
||||
"comment" : "public key on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "343ac20a3b9c6a27b1008176509ad30735856ec1c8d8fcae13912d08d152f46c",
|
||||
"private" : "68c1f3a653a4cdb1d37bba94738f8b957a57beb24d646e994dc29a276aad458d",
|
||||
"shared" : "399491fce8dfab73b4f9f611de8ea0b27b28f85994250b0f475d585d042ac207",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 7,
|
||||
"comment" : "public key on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "fa695fc7be8d1be5bf704898f388c452bafdd3b8eae805f8681a8d15c2d4e142",
|
||||
"private" : "d877b26d06dff9d9f7fd4c5b3769f8cdd5b30516a5ab806be324ff3eb69ea0b2",
|
||||
"shared" : "2c4fe11d490a53861776b13b4354abd4cf5a97699db6e6c68c1626d07662f758",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 8,
|
||||
"comment" : "public key = 0",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "207494038f2bb811d47805bcdf04a2ac585ada7f2f23389bfd4658f9ddd4debc",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Small public key"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 9,
|
||||
"comment" : "public key = 1",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0100000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "202e8972b61c7e61930eb9450b5070eae1c670475685541f0476217e4818cfab",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Small public key"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 10,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0200000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "38dde9f3e7b799045f9ac3793d4a9277dadeadc41bec0290f81f744f73775f84",
|
||||
"shared" : "9a2cfe84ff9c4a9739625cae4a3b82a906877a441946f8d7b3d795fe8f5d1639",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 11,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0300000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "9857a914e3c29036fd9a442ba526b5cdcdf28216153e636c10677acab6bd6aa5",
|
||||
"shared" : "4da4e0aa072c232ee2f0fa4e519ae50b52c1edd08a534d4ef346c2e106d21d60",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 12,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffff030000f8ffff1f0000c0ffffff000000feffff070000f0ffff3f000000",
|
||||
"private" : "48e2130d723305ed05e6e5894d398a5e33367a8c6aac8fcdf0a88e4b42820db7",
|
||||
"shared" : "9ed10c53747f647f82f45125d3de15a1e6b824496ab40410ffcc3cfe95760f3b",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 13,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "000000fcffff070000e0ffff3f000000ffffff010000f8ffff0f0000c0ffff7f",
|
||||
"private" : "28f41011691851b3a62b641553b30d0dfddcb8fffcf53700a7be2f6a872e9fb0",
|
||||
"shared" : "cf72b4aa6aa1c9f894f4165b86109aa468517648e1f0cc70e1ab08460176506b",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 14,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "00000000ffffffff00000000ffffffff00000000ffffffff00000000ffffff7f",
|
||||
"private" : "18a93b6499b9f6b3225ca02fef410e0adec23532321d2d8ef1a6d602a8c65b83",
|
||||
"shared" : "5d50b62836bb69579410386cf7bb811c14bf85b1c7b17e5924c7ffea91ef9e12",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 15,
|
||||
"comment" : "edge case on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eaffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "c01d1305a1338a1fcac2ba7e2e032b427e0b04903165aca957d8d0553d8717b0",
|
||||
"shared" : "19230eb148d5d67c3c22ab1daeff80a57eae4265ce2872657b2c8099fc698e50",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 16,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0400000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "386f7f16c50731d64f82e6a170b142a4e34f31fd7768fcb8902925e7d1e21abe",
|
||||
"shared" : "0fcab5d842a078d7a71fc59b57bfb4ca0be6873b49dcdb9f44e14ae8fbdfa542",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 17,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffffff00000000ffffffff00000000ffffffff00000000ffffffff00000000",
|
||||
"private" : "e023a289bd5e90fa2804ddc019a05ef3e79d434bb6ea2f522ecb643a75296e95",
|
||||
"shared" : "54ce8f2275c077e3b1306a3939c5e03eef6bbb88060544758d9fef59b0bc3e4f",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 18,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff03",
|
||||
"private" : "68f010d62ee8d926053a361c3a75c6ea4ebdc8606ab285003a6f8f4076b01e83",
|
||||
"shared" : "f136775c5beb0af8110af10b20372332043cab752419678775a223df57c9d30d",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 19,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "fffffffbfffffbffffdfffffdffffffffefffffefffff7fffff7ffffbfffff3f",
|
||||
"private" : "58ebcb35b0f8845caf1ec630f96576b62c4b7b6c36b29deb2cb0084651755c96",
|
||||
"shared" : "bf9affd06b844085586460962ef2146ff3d4533d9444aab006eb88cc3054407d",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 20,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff3f",
|
||||
"private" : "188c4bc5b9c44b38bb658b9b2ae82d5b01015e093184b17cb7863503a783e1bb",
|
||||
"shared" : "d480de04f699cb3be0684a9cc2e31281ea0bc5a9dcc157d3d20158d46ca5246d",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 21,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "fffffffffeffff7ffffffffffeffff7ffffffffffeffff7ffffffffffeffff7f",
|
||||
"private" : "e06c11bb2e13ce3dc7673f67f5482242909423a9ae95ee986a988d98faee23a2",
|
||||
"shared" : "4c4401cce6b51e4cb18f2790246c9bf914db667750a1cb89069092af07292276",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 22,
|
||||
"comment" : "edge case for public key",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ebffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "c0658c46dde18129293877535b1162b6f9f5414a23cf4d2cbc140a4d99da2b8f",
|
||||
"shared" : "578ba8cc2dbdc575afcf9df2b3ee6189f5337d6854c79b4ce165ea12293b3a0f",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 23,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e0eb7a7c3b41b8ae1656e3faf19fc46ada098deb9c32b1fd866205165f49b800",
|
||||
"private" : "10255c9230a97a30a458ca284a629669293a31890cda9d147febc7d1e22d6bb1",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 24,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "5f9c95bca3508c24b1d0b1559c83ef5b04445cc4581c8e86d8224eddd09f1157",
|
||||
"private" : "78f1e8edf14481b389448dac8f59c70b038e7cf92ef2c7eff57a72466e115296",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 25,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "a0a05a3e8f9f44204d5f8059a94ac7dfc39a49ac016dd743dbfa43c5d671fd88",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 26,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "d0dbb3ed1906663f15420af31f4eaf6509d9a9949723500605ad7c1c6e7450a9",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 27,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "c0b1d0eb22b244fe3291140072cdd9d989b5f0ecd96c100feb5bca241c1d9f8f",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 28,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0000000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "480bf45f594942a8bc0f3353c6e8b8853d77f351f1c2ca6c2d1abf8a00b4229c",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 29,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0100000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "30f993fcf8514fc89bd8db14cd43ba0d4b2530e73c4276a05e1b145d420cedb4",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 30,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e0eb7a7c3b41b8ae1656e3faf19fc46ada098deb9c32b1fd866205165f49b880",
|
||||
"private" : "c04974b758380e2a5b5df6eb09bb2f6b3434f982722a8e676d3da251d1b3de83",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 31,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "5f9c95bca3508c24b1d0b1559c83ef5b04445cc4581c8e86d8224eddd09f11d7",
|
||||
"private" : "502a31373db32446842fe5add3e024022ea54f274182afc3d9f1bb3d39534eb5",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 32,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "90fa6417b0e37030fd6e43eff2abaef14c6793117a039cf621318ba90f4e98be",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 33,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "78ad3f26027f1c9fdd975a1613b947779bad2cf2b741ade01840885a30bb979c",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 34,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "98e23de7b1e0926ed9c87e7b14baf55f497a1d7096f93977680e44dc1c7b7b8b",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"LowOrderPublic"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 35,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 36,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0100000000000000000000000000000000000000000000000000000000000000",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 37,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 38,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "5f9c95bca3508c24b1d0b1559c83ef5b04445cc4581c8e86d8224eddd09f1157",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 39,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e0eb7a7c3b41b8ae1656e3faf19fc46ada098deb9c32b1fd866205165f49b800",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 40,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 41,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 42,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0000000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 43,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0100000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 44,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 45,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "5f9c95bca3508c24b1d0b1559c83ef5b04445cc4581c8e86d8224eddd09f11d7",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 46,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e0eb7a7c3b41b8ae1656e3faf19fc46ada098deb9c32b1fd866205165f49b880",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 47,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 48,
|
||||
"comment" : "public key with low order",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "1064a67da639a8f6df4fbea2d63358b65bca80a770712e14ea8a72df5a3313ae",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 49,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "efffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "f01e48dafac9d7bcf589cbc382c878d18bda3550589ffb5d50b523bebe329dae",
|
||||
"shared" : "bd36a0790eb883098c988b21786773de0b3a4df162282cf110de18dd484ce74b",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 50,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "f0ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "288796bc5aff4b81a37501757bc0753a3c21964790d38699308debc17a6eaf8d",
|
||||
"shared" : "b4e0dd76da7b071728b61f856771aa356e57eda78a5b1655cc3820fb5f854c5c",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 51,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "f1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "98df845f6651bf1138221f119041f72b6dbc3c4ace7143d99fd55ad867480da8",
|
||||
"shared" : "6fdf6c37611dbd5304dc0f2eb7c9517eb3c50e12fd050ac6dec27071d4bfc034",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 52,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"private" : "f09498e46f02f878829e78b803d316a2ed695d0498a08abdf8276930e24edcb0",
|
||||
"shared" : "4c8fc4b1c6ab88fb21f18f6d4c810240d4e94651ba44f7a2c863cec7dc56602d",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 53,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0200000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "1813c10a5c7f21f96e17f288c0cc37607c04c5f5aea2db134f9e2ffc66bd9db8",
|
||||
"shared" : "1cd0b28267dc541c642d6d7dca44a8b38a63736eef5c4e6501ffbbb1780c033c",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 54,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0300000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "7857fb808653645a0beb138a64f5f4d733a45ea84c3cda11a9c06f7e7139149e",
|
||||
"shared" : "8755be01c60a7e825cff3e0e78cb3aa4333861516aa59b1c51a8b2a543dfa822",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 55,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0400000000000000000000000000000000000000000000000000000000000080",
|
||||
"private" : "e03aa842e2abc56e81e87b8b9f417b2a1e5913c723eed28d752f8d47a59f498f",
|
||||
"shared" : "54c9a1ed95e546d27822a360931dda60a1df049da6f904253c0612bbdc087476",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 56,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "daffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "f8f707b7999b18cb0d6b96124f2045972ca274bfc154ad0c87038c24c6d0d4b2",
|
||||
"shared" : "cc1f40d743cdc2230e1043daba8b75e810f1fbab7f255269bd9ebb29e6bf494f",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 57,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "dbffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "a034f684fa631e1a348118c1ce4c98231f2d9eec9ba5365b4a05d69a785b0796",
|
||||
"shared" : "54998ee43a5b007bf499f078e736524400a8b5c7e9b9b43771748c7cdf880412",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 58,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "dcffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "30b6c6a0f2ffa680768f992ba89e152d5bc9893d38c9119be4f767bfab6e0ca5",
|
||||
"shared" : "ead9b38efdd723637934e55ab717a7ae09eb86a21dc36a3feeb88b759e391e09",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 59,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "eaffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "901b9dcf881e01e027575035d40b43bdc1c5242e030847495b0c7286469b6591",
|
||||
"shared" : "602ff40789b54b41805915fe2a6221f07a50ffc2c3fc94cf61f13d7904e88e0e",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 60,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ebffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "8046677c28fd82c9a1bdb71a1a1a34faba1225e2507fe3f54d10bd5b0d865f8e",
|
||||
"shared" : "e00ae8b143471247ba24f12c885536c3cb981b58e1e56b2baf35c12ae1f79c26",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 61,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "efffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "602f7e2f68a846b82cc269b1d48e939886ae54fd636c1fe074d710127d472491",
|
||||
"shared" : "98cb9b50dd3fc2b0d4f2d2bf7c5cfdd10c8fcd31fc40af1ad44f47c131376362",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 62,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "f0ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "60887b3dc72443026ebedbbbb70665f42b87add1440e7768fbd7e8e2ce5f639d",
|
||||
"shared" : "38d6304c4a7e6d9f7959334fb5245bd2c754525d4c91db950206926234c1f633",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 63,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "f1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "78d31dfa854497d72d8def8a1b7fb006cec2d8c4924647c93814ae56faeda495",
|
||||
"shared" : "786cd54996f014a5a031ec14db812ed08355061fdb5de680a800ac521f318e23",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 64,
|
||||
"comment" : "public key >= p",
|
||||
"curve" : "curve25519",
|
||||
"public" : "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"private" : "c04c5baefa8302ddded6a4bb957761b4eb97aefa4fc3b8043085f96a5659b3a5",
|
||||
"shared" : "29ae8bc73e9b10a08b4f681c43c3e0ac1a171d31b38f1a48efba29ae639ea134",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 65,
|
||||
"comment" : "RFC 7748",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e6db6867583030db3594c1a424b15f7c726624ec26b3353b10a903a6d0ab1c4c",
|
||||
"private" : "a046e36bf0527c9d3b16154b82465edd62144c0ac1fc5a18506a2244ba449a44",
|
||||
"shared" : "c3da55379de9c6908e94ea4df28d084f32eccf03491c71f754b4075577a28552",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 66,
|
||||
"comment" : "RFC 7748",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e5210f12786811d3f4b7959d0538ae2c31dbe7106fc03c3efc4cd549c715a413",
|
||||
"private" : "4866e9d4d1b4673c5ad22691957d6af5c11b6421e0ea01d42ca4169e7918ba4d",
|
||||
"shared" : "95cbde9476e8907d7aade45cb4b873f88b595a68799fa152e6f8f7647aac7957",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 67,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "0ab4e76380d84dde4f6833c58f2a9fb8f83bb0169b172be4b6e0592887741a36",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "0200000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 68,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "89e10d5701b4337d2d032181538b1064bd4084401ceca1fd12663a1959388000",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "0900000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 69,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "2b55d3aa4a8f80c8c0b2ae5f933e85af49beac36c2fa7394bab76c8933f8f81d",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "1000000000000000000000000000000000000000000000000000000000000000",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 70,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "63e5b1fe9601fe84385d8866b0421262f78fbfa5aff9585e626679b18547d959",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "feffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff3f",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 71,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "e428f3dac17809f827a522ce32355058d07369364aa78902ee10139b9f9dd653",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "fcffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff3f",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 72,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "b3b50e3ed3a407b95de942ef74575b5ab8a10c09ee103544d60bdfed8138ab2b",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "f9ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff3f",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 73,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "213fffe93d5ea8cd242e462844029922c43c77c9e3e42f562f485d24c501a20b",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "f3ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff3f",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 74,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "91b232a178b3cd530932441e6139418f72172292f1da4c1834fc5ebfefb51e3f",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff03",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 75,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "045c6e11c5d332556c7822fe94ebf89b56a3878dc27ca079103058849fabcb4f",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "e5ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 76,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "1ca2190b71163539063c35773bda0c9c928e9136f0620aeb093f099197b7f74e",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "e3ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 77,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "f76e9010ac33c5043b2d3b76a842171000c4916222e9e85897a0aec7f6350b3c",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "ddffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 78,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "bb72688d8f8aa7a39cd6060cd5c8093cdec6fe341937c3886a99346cd07faa55",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "dbffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 79,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "88fddea193391c6a5933ef9b71901549447205aae9da928a6b91a352ba10f41f",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000000002",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 80,
|
||||
"comment" : "edge case for shared secret",
|
||||
"curve" : "curve25519",
|
||||
"public" : "303b392f153116cad9cc682a00ccc44c95ff0d3bbe568beb6c4e739bafdc2c68",
|
||||
"private" : "a0a4f130b98a5be4b1cedb7cb85584a3520e142d474dc9ccb909a073a976bf63",
|
||||
"shared" : "0000000000000000000000000000000000000000000000000000000000008000",
|
||||
"result" : "acceptable",
|
||||
"flags" : [
|
||||
"Twist"
|
||||
]
|
||||
},
|
||||
{
|
||||
"tcId" : 81,
|
||||
"comment" : "checking for overflow",
|
||||
"curve" : "curve25519",
|
||||
"public" : "fd300aeb40e1fa582518412b49b208a7842b1e1f056a040178ea4141534f652d",
|
||||
"private" : "c81724704000b26d31703cc97e3a378d56fad8219361c88cca8bd7c5719b12b2",
|
||||
"shared" : "b734105dc257585d73b566ccb76f062795ccbec89128e52b02f3e59639f13c46",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 82,
|
||||
"comment" : "checking for overflow",
|
||||
"curve" : "curve25519",
|
||||
"public" : "c8ef79b514d7682677bc7931e06ee5c27c9b392b4ae9484473f554e6678ecc2e",
|
||||
"private" : "c81724704000b26d31703cc97e3a378d56fad8219361c88cca8bd7c5719b12b2",
|
||||
"shared" : "647a46b6fc3f40d62141ee3cee706b4d7a9271593a7b143e8e2e2279883e4550",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 83,
|
||||
"comment" : "checking for overflow",
|
||||
"curve" : "curve25519",
|
||||
"public" : "64aeac2504144861532b7bbcb6c87d67dd4c1f07ebc2e06effb95aecc6170b2c",
|
||||
"private" : "c81724704000b26d31703cc97e3a378d56fad8219361c88cca8bd7c5719b12b2",
|
||||
"shared" : "4ff03d5fb43cd8657a3cf37c138cadcecce509e4eba089d0ef40b4e4fb946155",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 84,
|
||||
"comment" : "checking for overflow",
|
||||
"curve" : "curve25519",
|
||||
"public" : "bf68e35e9bdb7eee1b50570221860f5dcdad8acbab031b14974cc49013c49831",
|
||||
"private" : "c81724704000b26d31703cc97e3a378d56fad8219361c88cca8bd7c5719b12b2",
|
||||
"shared" : "21cee52efdbc812e1d021a4af1e1d8bc4db3c400e4d2a2c56a3926db4d99c65b",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 85,
|
||||
"comment" : "checking for overflow",
|
||||
"curve" : "curve25519",
|
||||
"public" : "5347c491331a64b43ddc683034e677f53dc32b52a52a577c15a83bf298e99f19",
|
||||
"private" : "c81724704000b26d31703cc97e3a378d56fad8219361c88cca8bd7c5719b12b2",
|
||||
"shared" : "18cb89e4e20c0c2bd324305245266c9327690bbe79acb88f5b8fb3f74eca3e52",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 86,
|
||||
"comment" : "private key == -1 (mod order)",
|
||||
"curve" : "curve25519",
|
||||
"public" : "258e04523b8d253ee65719fc6906c657192d80717edc828fa0af21686e2faa75",
|
||||
"private" : "a023cdd083ef5bb82f10d62e59e15a6800000000000000000000000000000050",
|
||||
"shared" : "258e04523b8d253ee65719fc6906c657192d80717edc828fa0af21686e2faa75",
|
||||
"result" : "valid",
|
||||
"flags" : []
|
||||
},
|
||||
{
|
||||
"tcId" : 87,
|
||||
"comment" : "private key == 1 (mod order) on twist",
|
||||
"curve" : "curve25519",
|
||||
"public" : "2eae5ec3dd494e9f2d37d258f873a8e6e9d0dbd1e383ef64d98bb91b3e0be035",
|
||||
"private" : "58083dd261ad91eff952322ec824c682ffffffffffffffffffffffffffffff5f",
|
||||
"shared" : "2eae5ec3dd494e9f2d37d258f873a8e6e9d0dbd1e383ef64d98bb91b3e0be035",
|
||||
"result" : "acceptable",
|
||||
"flags" : []
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
@ -2,7 +2,7 @@
|
|||
// License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
// You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
#include "gcm-vectors.h"
|
||||
#include "testvectors/gcm-vectors.h"
|
||||
#include "gtest/gtest.h"
|
||||
#include "util.h"
|
||||
|
||||
|
|
|
|||
|
|
@ -26,6 +26,7 @@ NSS_SRCDIRS = \
|
|||
pk11_gtest \
|
||||
softoken_gtest \
|
||||
ssl_gtest \
|
||||
$(SYSINIT_GTEST) \
|
||||
nss_bogo_shim \
|
||||
$(NULL)
|
||||
endif
|
||||
|
|
|
|||
|
|
@ -12,7 +12,7 @@
|
|||
|
||||
#include "nss_scoped_ptrs.h"
|
||||
|
||||
#include "gcm-vectors.h"
|
||||
#include "testvectors/gcm-vectors.h"
|
||||
#include "gtest/gtest.h"
|
||||
#include "util.h"
|
||||
|
||||
|
|
@ -26,7 +26,11 @@ class Pkcs11AesGcmTest : public ::testing::TestWithParam<gcm_kat_value> {
|
|||
std::vector<uint8_t> plaintext = hex_string_to_bytes(val.plaintext);
|
||||
std::vector<uint8_t> aad = hex_string_to_bytes(val.additional_data);
|
||||
std::vector<uint8_t> result = hex_string_to_bytes(val.result);
|
||||
|
||||
bool invalid_ct = val.invalid_ct;
|
||||
bool invalid_iv = val.invalid_iv;
|
||||
std::stringstream s;
|
||||
s << "Test #" << val.test_id << " failed.";
|
||||
std::string msg = s.str();
|
||||
// Ignore GHASH-only vectors.
|
||||
if (key.empty()) {
|
||||
return;
|
||||
|
|
@ -50,7 +54,7 @@ class Pkcs11AesGcmTest : public ::testing::TestWithParam<gcm_kat_value> {
|
|||
// Import key.
|
||||
ScopedPK11SymKey symKey(PK11_ImportSymKey(
|
||||
slot.get(), mech, PK11_OriginUnwrap, CKA_ENCRYPT, &keyItem, nullptr));
|
||||
EXPECT_TRUE(!!symKey);
|
||||
ASSERT_TRUE(!!symKey) << msg;
|
||||
|
||||
// Encrypt.
|
||||
unsigned int outputLen = 0;
|
||||
|
|
@ -58,11 +62,21 @@ class Pkcs11AesGcmTest : public ::testing::TestWithParam<gcm_kat_value> {
|
|||
SECStatus rv =
|
||||
PK11_Encrypt(symKey.get(), mech, ¶ms, output.data(), &outputLen,
|
||||
output.size(), plaintext.data(), plaintext.size());
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
ASSERT_EQ(outputLen, output.size());
|
||||
if (invalid_iv) {
|
||||
EXPECT_EQ(rv, SECFailure) << msg;
|
||||
return;
|
||||
} else {
|
||||
EXPECT_EQ(rv, SECSuccess) << msg;
|
||||
}
|
||||
|
||||
ASSERT_EQ(outputLen, output.size()) << msg;
|
||||
|
||||
// Check ciphertext and tag.
|
||||
EXPECT_EQ(result, output);
|
||||
if (invalid_ct) {
|
||||
EXPECT_NE(result, output) << msg;
|
||||
} else {
|
||||
EXPECT_EQ(result, output) << msg;
|
||||
}
|
||||
|
||||
// Decrypt.
|
||||
unsigned int decryptedLen = 0;
|
||||
|
|
@ -72,13 +86,13 @@ class Pkcs11AesGcmTest : public ::testing::TestWithParam<gcm_kat_value> {
|
|||
rv =
|
||||
PK11_Decrypt(symKey.get(), mech, ¶ms, decrypted.data(),
|
||||
&decryptedLen, decrypted.size(), output.data(), outputLen);
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
ASSERT_EQ(decryptedLen, plaintext.size());
|
||||
EXPECT_EQ(rv, SECSuccess) << msg;
|
||||
ASSERT_EQ(decryptedLen, plaintext.size()) << msg;
|
||||
|
||||
// Check the plaintext.
|
||||
EXPECT_EQ(plaintext,
|
||||
std::vector<uint8_t>(decrypted.begin(),
|
||||
decrypted.begin() + decryptedLen));
|
||||
EXPECT_EQ(plaintext, std::vector<uint8_t>(decrypted.begin(),
|
||||
decrypted.begin() + decryptedLen))
|
||||
<< msg;
|
||||
}
|
||||
|
||||
SECStatus EncryptWithIV(std::vector<uint8_t>& iv) {
|
||||
|
|
@ -117,6 +131,9 @@ TEST_P(Pkcs11AesGcmTest, TestVectors) { RunTest(GetParam()); }
|
|||
INSTANTIATE_TEST_CASE_P(NISTTestVector, Pkcs11AesGcmTest,
|
||||
::testing::ValuesIn(kGcmKatValues));
|
||||
|
||||
INSTANTIATE_TEST_CASE_P(WycheproofTestVector, Pkcs11AesGcmTest,
|
||||
::testing::ValuesIn(kGcmWycheproofVectors));
|
||||
|
||||
TEST_F(Pkcs11AesGcmTest, ZeroLengthIV) {
|
||||
std::vector<uint8_t> iv(0);
|
||||
EXPECT_EQ(EncryptWithIV(iv), SECFailure);
|
||||
|
|
|
|||
|
|
@ -12,110 +12,19 @@
|
|||
#include "cpputil.h"
|
||||
#include "nss_scoped_ptrs.h"
|
||||
|
||||
#include "testvectors/chachapoly-vectors.h"
|
||||
#include "gtest/gtest.h"
|
||||
|
||||
namespace nss_test {
|
||||
|
||||
// ChaCha20/Poly1305 Test Vector 1, RFC 7539
|
||||
// <http://tools.ietf.org/html/rfc7539#section-2.8.2>
|
||||
const uint8_t kTestVector1Data[] = {
|
||||
0x4c, 0x61, 0x64, 0x69, 0x65, 0x73, 0x20, 0x61, 0x6e, 0x64, 0x20, 0x47,
|
||||
0x65, 0x6e, 0x74, 0x6c, 0x65, 0x6d, 0x65, 0x6e, 0x20, 0x6f, 0x66, 0x20,
|
||||
0x74, 0x68, 0x65, 0x20, 0x63, 0x6c, 0x61, 0x73, 0x73, 0x20, 0x6f, 0x66,
|
||||
0x20, 0x27, 0x39, 0x39, 0x3a, 0x20, 0x49, 0x66, 0x20, 0x49, 0x20, 0x63,
|
||||
0x6f, 0x75, 0x6c, 0x64, 0x20, 0x6f, 0x66, 0x66, 0x65, 0x72, 0x20, 0x79,
|
||||
0x6f, 0x75, 0x20, 0x6f, 0x6e, 0x6c, 0x79, 0x20, 0x6f, 0x6e, 0x65, 0x20,
|
||||
0x74, 0x69, 0x70, 0x20, 0x66, 0x6f, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20,
|
||||
0x66, 0x75, 0x74, 0x75, 0x72, 0x65, 0x2c, 0x20, 0x73, 0x75, 0x6e, 0x73,
|
||||
0x63, 0x72, 0x65, 0x65, 0x6e, 0x20, 0x77, 0x6f, 0x75, 0x6c, 0x64, 0x20,
|
||||
0x62, 0x65, 0x20, 0x69, 0x74, 0x2e};
|
||||
const uint8_t kTestVector1AAD[] = {0x50, 0x51, 0x52, 0x53, 0xc0, 0xc1,
|
||||
0xc2, 0xc3, 0xc4, 0xc5, 0xc6, 0xc7};
|
||||
const uint8_t kTestVector1Key[] = {
|
||||
0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87, 0x88, 0x89, 0x8a,
|
||||
0x8b, 0x8c, 0x8d, 0x8e, 0x8f, 0x90, 0x91, 0x92, 0x93, 0x94, 0x95,
|
||||
0x96, 0x97, 0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f};
|
||||
const uint8_t kTestVector1IV[] = {0x07, 0x00, 0x00, 0x00, 0x40, 0x41,
|
||||
0x42, 0x43, 0x44, 0x45, 0x46, 0x47};
|
||||
const uint8_t kTestVector1CT[] = {
|
||||
0xd3, 0x1a, 0x8d, 0x34, 0x64, 0x8e, 0x60, 0xdb, 0x7b, 0x86, 0xaf, 0xbc,
|
||||
0x53, 0xef, 0x7e, 0xc2, 0xa4, 0xad, 0xed, 0x51, 0x29, 0x6e, 0x08, 0xfe,
|
||||
0xa9, 0xe2, 0xb5, 0xa7, 0x36, 0xee, 0x62, 0xd6, 0x3d, 0xbe, 0xa4, 0x5e,
|
||||
0x8c, 0xa9, 0x67, 0x12, 0x82, 0xfa, 0xfb, 0x69, 0xda, 0x92, 0x72, 0x8b,
|
||||
0x1a, 0x71, 0xde, 0x0a, 0x9e, 0x06, 0x0b, 0x29, 0x05, 0xd6, 0xa5, 0xb6,
|
||||
0x7e, 0xcd, 0x3b, 0x36, 0x92, 0xdd, 0xbd, 0x7f, 0x2d, 0x77, 0x8b, 0x8c,
|
||||
0x98, 0x03, 0xae, 0xe3, 0x28, 0x09, 0x1b, 0x58, 0xfa, 0xb3, 0x24, 0xe4,
|
||||
0xfa, 0xd6, 0x75, 0x94, 0x55, 0x85, 0x80, 0x8b, 0x48, 0x31, 0xd7, 0xbc,
|
||||
0x3f, 0xf4, 0xde, 0xf0, 0x8e, 0x4b, 0x7a, 0x9d, 0xe5, 0x76, 0xd2, 0x65,
|
||||
0x86, 0xce, 0xc6, 0x4b, 0x61, 0x16, 0x1a, 0xe1, 0x0b, 0x59, 0x4f, 0x09,
|
||||
0xe2, 0x6a, 0x7e, 0x90, 0x2e, 0xcb, 0xd0, 0x60, 0x06, 0x91};
|
||||
|
||||
// ChaCha20/Poly1305 Test Vector 2, RFC 7539
|
||||
// <http://tools.ietf.org/html/rfc7539#appendix-A.5>
|
||||
const uint8_t kTestVector2Data[] = {
|
||||
0x49, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x65, 0x74, 0x2d, 0x44, 0x72, 0x61,
|
||||
0x66, 0x74, 0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x64, 0x72, 0x61, 0x66,
|
||||
0x74, 0x20, 0x64, 0x6f, 0x63, 0x75, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x20,
|
||||
0x76, 0x61, 0x6c, 0x69, 0x64, 0x20, 0x66, 0x6f, 0x72, 0x20, 0x61, 0x20,
|
||||
0x6d, 0x61, 0x78, 0x69, 0x6d, 0x75, 0x6d, 0x20, 0x6f, 0x66, 0x20, 0x73,
|
||||
0x69, 0x78, 0x20, 0x6d, 0x6f, 0x6e, 0x74, 0x68, 0x73, 0x20, 0x61, 0x6e,
|
||||
0x64, 0x20, 0x6d, 0x61, 0x79, 0x20, 0x62, 0x65, 0x20, 0x75, 0x70, 0x64,
|
||||
0x61, 0x74, 0x65, 0x64, 0x2c, 0x20, 0x72, 0x65, 0x70, 0x6c, 0x61, 0x63,
|
||||
0x65, 0x64, 0x2c, 0x20, 0x6f, 0x72, 0x20, 0x6f, 0x62, 0x73, 0x6f, 0x6c,
|
||||
0x65, 0x74, 0x65, 0x64, 0x20, 0x62, 0x79, 0x20, 0x6f, 0x74, 0x68, 0x65,
|
||||
0x72, 0x20, 0x64, 0x6f, 0x63, 0x75, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x20,
|
||||
0x61, 0x74, 0x20, 0x61, 0x6e, 0x79, 0x20, 0x74, 0x69, 0x6d, 0x65, 0x2e,
|
||||
0x20, 0x49, 0x74, 0x20, 0x69, 0x73, 0x20, 0x69, 0x6e, 0x61, 0x70, 0x70,
|
||||
0x72, 0x6f, 0x70, 0x72, 0x69, 0x61, 0x74, 0x65, 0x20, 0x74, 0x6f, 0x20,
|
||||
0x75, 0x73, 0x65, 0x20, 0x49, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x65, 0x74,
|
||||
0x2d, 0x44, 0x72, 0x61, 0x66, 0x74, 0x73, 0x20, 0x61, 0x73, 0x20, 0x72,
|
||||
0x65, 0x66, 0x65, 0x72, 0x65, 0x6e, 0x63, 0x65, 0x20, 0x6d, 0x61, 0x74,
|
||||
0x65, 0x72, 0x69, 0x61, 0x6c, 0x20, 0x6f, 0x72, 0x20, 0x74, 0x6f, 0x20,
|
||||
0x63, 0x69, 0x74, 0x65, 0x20, 0x74, 0x68, 0x65, 0x6d, 0x20, 0x6f, 0x74,
|
||||
0x68, 0x65, 0x72, 0x20, 0x74, 0x68, 0x61, 0x6e, 0x20, 0x61, 0x73, 0x20,
|
||||
0x2f, 0xe2, 0x80, 0x9c, 0x77, 0x6f, 0x72, 0x6b, 0x20, 0x69, 0x6e, 0x20,
|
||||
0x70, 0x72, 0x6f, 0x67, 0x72, 0x65, 0x73, 0x73, 0x2e, 0x2f, 0xe2, 0x80,
|
||||
0x9d};
|
||||
const uint8_t kTestVector2AAD[] = {0xf3, 0x33, 0x88, 0x86, 0x00, 0x00,
|
||||
0x00, 0x00, 0x00, 0x00, 0x4e, 0x91};
|
||||
const uint8_t kTestVector2Key[] = {
|
||||
0x1c, 0x92, 0x40, 0xa5, 0xeb, 0x55, 0xd3, 0x8a, 0xf3, 0x33, 0x88,
|
||||
0x86, 0x04, 0xf6, 0xb5, 0xf0, 0x47, 0x39, 0x17, 0xc1, 0x40, 0x2b,
|
||||
0x80, 0x09, 0x9d, 0xca, 0x5c, 0xbc, 0x20, 0x70, 0x75, 0xc0};
|
||||
const uint8_t kTestVector2IV[] = {0x00, 0x00, 0x00, 0x00, 0x01, 0x02,
|
||||
0x03, 0x04, 0x05, 0x06, 0x07, 0x08};
|
||||
const uint8_t kTestVector2CT[] = {
|
||||
0x64, 0xa0, 0x86, 0x15, 0x75, 0x86, 0x1a, 0xf4, 0x60, 0xf0, 0x62, 0xc7,
|
||||
0x9b, 0xe6, 0x43, 0xbd, 0x5e, 0x80, 0x5c, 0xfd, 0x34, 0x5c, 0xf3, 0x89,
|
||||
0xf1, 0x08, 0x67, 0x0a, 0xc7, 0x6c, 0x8c, 0xb2, 0x4c, 0x6c, 0xfc, 0x18,
|
||||
0x75, 0x5d, 0x43, 0xee, 0xa0, 0x9e, 0xe9, 0x4e, 0x38, 0x2d, 0x26, 0xb0,
|
||||
0xbd, 0xb7, 0xb7, 0x3c, 0x32, 0x1b, 0x01, 0x00, 0xd4, 0xf0, 0x3b, 0x7f,
|
||||
0x35, 0x58, 0x94, 0xcf, 0x33, 0x2f, 0x83, 0x0e, 0x71, 0x0b, 0x97, 0xce,
|
||||
0x98, 0xc8, 0xa8, 0x4a, 0xbd, 0x0b, 0x94, 0x81, 0x14, 0xad, 0x17, 0x6e,
|
||||
0x00, 0x8d, 0x33, 0xbd, 0x60, 0xf9, 0x82, 0xb1, 0xff, 0x37, 0xc8, 0x55,
|
||||
0x97, 0x97, 0xa0, 0x6e, 0xf4, 0xf0, 0xef, 0x61, 0xc1, 0x86, 0x32, 0x4e,
|
||||
0x2b, 0x35, 0x06, 0x38, 0x36, 0x06, 0x90, 0x7b, 0x6a, 0x7c, 0x02, 0xb0,
|
||||
0xf9, 0xf6, 0x15, 0x7b, 0x53, 0xc8, 0x67, 0xe4, 0xb9, 0x16, 0x6c, 0x76,
|
||||
0x7b, 0x80, 0x4d, 0x46, 0xa5, 0x9b, 0x52, 0x16, 0xcd, 0xe7, 0xa4, 0xe9,
|
||||
0x90, 0x40, 0xc5, 0xa4, 0x04, 0x33, 0x22, 0x5e, 0xe2, 0x82, 0xa1, 0xb0,
|
||||
0xa0, 0x6c, 0x52, 0x3e, 0xaf, 0x45, 0x34, 0xd7, 0xf8, 0x3f, 0xa1, 0x15,
|
||||
0x5b, 0x00, 0x47, 0x71, 0x8c, 0xbc, 0x54, 0x6a, 0x0d, 0x07, 0x2b, 0x04,
|
||||
0xb3, 0x56, 0x4e, 0xea, 0x1b, 0x42, 0x22, 0x73, 0xf5, 0x48, 0x27, 0x1a,
|
||||
0x0b, 0xb2, 0x31, 0x60, 0x53, 0xfa, 0x76, 0x99, 0x19, 0x55, 0xeb, 0xd6,
|
||||
0x31, 0x59, 0x43, 0x4e, 0xce, 0xbb, 0x4e, 0x46, 0x6d, 0xae, 0x5a, 0x10,
|
||||
0x73, 0xa6, 0x72, 0x76, 0x27, 0x09, 0x7a, 0x10, 0x49, 0xe6, 0x17, 0xd9,
|
||||
0x1d, 0x36, 0x10, 0x94, 0xfa, 0x68, 0xf0, 0xff, 0x77, 0x98, 0x71, 0x30,
|
||||
0x30, 0x5b, 0xea, 0xba, 0x2e, 0xda, 0x04, 0xdf, 0x99, 0x7b, 0x71, 0x4d,
|
||||
0x6c, 0x6f, 0x2c, 0x29, 0xa6, 0xad, 0x5c, 0xb4, 0x02, 0x2b, 0x02, 0x70,
|
||||
0x9b, 0xee, 0xad, 0x9d, 0x67, 0x89, 0x0c, 0xbb, 0x22, 0x39, 0x23, 0x36,
|
||||
0xfe, 0xa1, 0x85, 0x1f, 0x38};
|
||||
|
||||
class Pkcs11ChaCha20Poly1305Test : public ::testing::Test {
|
||||
class Pkcs11ChaCha20Poly1305Test
|
||||
: public ::testing::TestWithParam<chacha_testvector> {
|
||||
public:
|
||||
void EncryptDecrypt(PK11SymKey* symKey, const uint8_t* data, size_t data_len,
|
||||
const uint8_t* aad, size_t aad_len, const uint8_t* iv,
|
||||
size_t iv_len, const uint8_t* ct = nullptr,
|
||||
size_t ct_len = 0) {
|
||||
void EncryptDecrypt(PK11SymKey* symKey, const bool invalid_iv,
|
||||
const bool invalid_tag, const uint8_t* data,
|
||||
size_t data_len, const uint8_t* aad, size_t aad_len,
|
||||
const uint8_t* iv, size_t iv_len,
|
||||
const uint8_t* ct = nullptr, size_t ct_len = 0) {
|
||||
// Prepare AEAD params.
|
||||
CK_NSS_AEAD_PARAMS aead_params;
|
||||
aead_params.pNonce = toUcharPtr(iv);
|
||||
|
|
@ -130,81 +39,94 @@ class Pkcs11ChaCha20Poly1305Test : public ::testing::Test {
|
|||
// Encrypt.
|
||||
unsigned int outputLen = 0;
|
||||
std::vector<uint8_t> output(data_len + aead_params.ulTagLen);
|
||||
SECStatus rv = PK11_Encrypt(symKey, mech, ¶ms, &output[0], &outputLen,
|
||||
output.size(), data, data_len);
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
SECStatus rv = PK11_Encrypt(symKey, mech, ¶ms, output.data(),
|
||||
&outputLen, output.size(), data, data_len);
|
||||
|
||||
// Return if encryption failure was expected due to invalid IV.
|
||||
// Without valid ciphertext, all further tests can be skipped.
|
||||
if (invalid_iv) {
|
||||
EXPECT_EQ(rv, SECFailure);
|
||||
return;
|
||||
} else {
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
}
|
||||
|
||||
// Check ciphertext and tag.
|
||||
if (ct) {
|
||||
EXPECT_TRUE(!memcmp(ct, &output[0], outputLen));
|
||||
ASSERT_EQ(ct_len, outputLen);
|
||||
EXPECT_TRUE(!memcmp(ct, output.data(), outputLen) != invalid_tag);
|
||||
}
|
||||
|
||||
// Decrypt.
|
||||
unsigned int decryptedLen = 0;
|
||||
std::vector<uint8_t> decrypted(data_len);
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, &decrypted[0], &decryptedLen,
|
||||
decrypted.size(), &output[0], outputLen);
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, decrypted.data(), &decryptedLen,
|
||||
decrypted.size(), output.data(), outputLen);
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
|
||||
// Check the plaintext.
|
||||
EXPECT_TRUE(!memcmp(data, &decrypted[0], decryptedLen));
|
||||
ASSERT_EQ(data_len, decryptedLen);
|
||||
EXPECT_TRUE(!memcmp(data, decrypted.data(), decryptedLen));
|
||||
|
||||
// Decrypt with bogus data.
|
||||
{
|
||||
// Skip if there's no data to modify.
|
||||
if (outputLen != 0) {
|
||||
std::vector<uint8_t> bogusCiphertext(output);
|
||||
bogusCiphertext[0] ^= 0xff;
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, &decrypted[0], &decryptedLen,
|
||||
decrypted.size(), &bogusCiphertext[0], outputLen);
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, decrypted.data(), &decryptedLen,
|
||||
decrypted.size(), bogusCiphertext.data(), outputLen);
|
||||
EXPECT_NE(rv, SECSuccess);
|
||||
}
|
||||
|
||||
// Decrypt with bogus tag.
|
||||
{
|
||||
// Skip if there's no tag to modify.
|
||||
if (outputLen != 0) {
|
||||
std::vector<uint8_t> bogusTag(output);
|
||||
bogusTag[outputLen - 1] ^= 0xff;
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, &decrypted[0], &decryptedLen,
|
||||
decrypted.size(), &bogusTag[0], outputLen);
|
||||
rv = PK11_Decrypt(symKey, mech, ¶ms, decrypted.data(), &decryptedLen,
|
||||
decrypted.size(), bogusTag.data(), outputLen);
|
||||
EXPECT_NE(rv, SECSuccess);
|
||||
}
|
||||
|
||||
// Decrypt with bogus IV.
|
||||
{
|
||||
// iv_len == 0 is invalid and should be caught earlier.
|
||||
// Still skip, if there's no IV to modify.
|
||||
if (iv_len != 0) {
|
||||
SECItem bogusParams(params);
|
||||
CK_NSS_AEAD_PARAMS bogusAeadParams(aead_params);
|
||||
bogusParams.data = reinterpret_cast<unsigned char*>(&bogusAeadParams);
|
||||
|
||||
std::vector<uint8_t> bogusIV(iv, iv + iv_len);
|
||||
bogusAeadParams.pNonce = toUcharPtr(&bogusIV[0]);
|
||||
bogusAeadParams.pNonce = toUcharPtr(bogusIV.data());
|
||||
bogusIV[0] ^= 0xff;
|
||||
|
||||
rv = PK11_Decrypt(symKey, mech, &bogusParams, &decrypted[0],
|
||||
&decryptedLen, data_len, &output[0], outputLen);
|
||||
rv = PK11_Decrypt(symKey, mech, &bogusParams, decrypted.data(),
|
||||
&decryptedLen, data_len, output.data(), outputLen);
|
||||
EXPECT_NE(rv, SECSuccess);
|
||||
}
|
||||
|
||||
// Decrypt with bogus additional data.
|
||||
{
|
||||
// Skip when AAD was empty and can't be modified.
|
||||
// Alternatively we could generate random aad.
|
||||
if (aad_len != 0) {
|
||||
SECItem bogusParams(params);
|
||||
CK_NSS_AEAD_PARAMS bogusAeadParams(aead_params);
|
||||
bogusParams.data = reinterpret_cast<unsigned char*>(&bogusAeadParams);
|
||||
|
||||
std::vector<uint8_t> bogusAAD(aad, aad + aad_len);
|
||||
bogusAeadParams.pAAD = toUcharPtr(&bogusAAD[0]);
|
||||
bogusAeadParams.pAAD = toUcharPtr(bogusAAD.data());
|
||||
bogusAAD[0] ^= 0xff;
|
||||
|
||||
rv = PK11_Decrypt(symKey, mech, &bogusParams, &decrypted[0],
|
||||
&decryptedLen, data_len, &output[0], outputLen);
|
||||
rv = PK11_Decrypt(symKey, mech, &bogusParams, decrypted.data(),
|
||||
&decryptedLen, data_len, output.data(), outputLen);
|
||||
EXPECT_NE(rv, SECSuccess);
|
||||
}
|
||||
}
|
||||
|
||||
void EncryptDecrypt(const uint8_t* key, size_t key_len, const uint8_t* data,
|
||||
size_t data_len, const uint8_t* aad, size_t aad_len,
|
||||
const uint8_t* iv, size_t iv_len, const uint8_t* ct,
|
||||
size_t ct_len) {
|
||||
void EncryptDecrypt(const chacha_testvector testvector) {
|
||||
ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
|
||||
SECItem keyItem = {siBuffer, toUcharPtr(key),
|
||||
static_cast<unsigned int>(key_len)};
|
||||
SECItem keyItem = {siBuffer, toUcharPtr(testvector.Key.data()),
|
||||
static_cast<unsigned int>(testvector.Key.size())};
|
||||
|
||||
// Import key.
|
||||
ScopedPK11SymKey symKey(PK11_ImportSymKey(
|
||||
|
|
@ -212,18 +134,17 @@ class Pkcs11ChaCha20Poly1305Test : public ::testing::Test {
|
|||
EXPECT_TRUE(!!symKey);
|
||||
|
||||
// Check.
|
||||
EncryptDecrypt(symKey.get(), data, data_len, aad, aad_len, iv, iv_len, ct,
|
||||
ct_len);
|
||||
EncryptDecrypt(symKey.get(), testvector.invalid_iv, testvector.invalid_tag,
|
||||
testvector.Data.data(), testvector.Data.size(),
|
||||
testvector.AAD.data(), testvector.AAD.size(),
|
||||
testvector.IV.data(), testvector.IV.size(),
|
||||
testvector.CT.data(), testvector.CT.size());
|
||||
}
|
||||
|
||||
protected:
|
||||
CK_MECHANISM_TYPE mech = CKM_NSS_CHACHA20_POLY1305;
|
||||
};
|
||||
|
||||
#define ENCRYPT_DECRYPT(v) \
|
||||
EncryptDecrypt(v##Key, sizeof(v##Key), v##Data, sizeof(v##Data), v##AAD, \
|
||||
sizeof(v##AAD), v##IV, sizeof(v##IV), v##CT, sizeof(v##CT));
|
||||
|
||||
TEST_F(Pkcs11ChaCha20Poly1305Test, GenerateEncryptDecrypt) {
|
||||
// Generate a random key.
|
||||
ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
|
||||
|
|
@ -232,30 +153,31 @@ TEST_F(Pkcs11ChaCha20Poly1305Test, GenerateEncryptDecrypt) {
|
|||
|
||||
// Generate random data.
|
||||
std::vector<uint8_t> data(512);
|
||||
SECStatus rv = PK11_GenerateRandomOnSlot(slot.get(), &data[0], data.size());
|
||||
SECStatus rv =
|
||||
PK11_GenerateRandomOnSlot(slot.get(), data.data(), data.size());
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
|
||||
// Generate random AAD.
|
||||
std::vector<uint8_t> aad(16);
|
||||
rv = PK11_GenerateRandomOnSlot(slot.get(), &aad[0], aad.size());
|
||||
rv = PK11_GenerateRandomOnSlot(slot.get(), aad.data(), aad.size());
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
|
||||
// Generate random IV.
|
||||
std::vector<uint8_t> iv(12);
|
||||
rv = PK11_GenerateRandomOnSlot(slot.get(), &iv[0], iv.size());
|
||||
rv = PK11_GenerateRandomOnSlot(slot.get(), iv.data(), iv.size());
|
||||
EXPECT_EQ(rv, SECSuccess);
|
||||
|
||||
// Check.
|
||||
EncryptDecrypt(symKey.get(), &data[0], data.size(), &aad[0], aad.size(),
|
||||
&iv[0], iv.size());
|
||||
EncryptDecrypt(symKey.get(), false, false, data.data(), data.size(),
|
||||
aad.data(), aad.size(), iv.data(), iv.size());
|
||||
}
|
||||
|
||||
TEST_F(Pkcs11ChaCha20Poly1305Test, CheckTestVector1) {
|
||||
ENCRYPT_DECRYPT(kTestVector1);
|
||||
}
|
||||
TEST_P(Pkcs11ChaCha20Poly1305Test, TestVectors) { EncryptDecrypt(GetParam()); }
|
||||
|
||||
TEST_F(Pkcs11ChaCha20Poly1305Test, CheckTestVector2) {
|
||||
ENCRYPT_DECRYPT(kTestVector2);
|
||||
}
|
||||
INSTANTIATE_TEST_CASE_P(NSSTestVector, Pkcs11ChaCha20Poly1305Test,
|
||||
::testing::ValuesIn(kChaCha20Vectors));
|
||||
|
||||
INSTANTIATE_TEST_CASE_P(WycheproofTestVector, Pkcs11ChaCha20Poly1305Test,
|
||||
::testing::ValuesIn(kChaCha20WycheproofVectors));
|
||||
|
||||
} // namespace nss_test
|
||||
|
|
|
|||
|
|
@ -9,49 +9,13 @@
|
|||
#include "cpputil.h"
|
||||
#include "nss_scoped_ptrs.h"
|
||||
|
||||
#include "testvectors/curve25519-vectors.h"
|
||||
#include "gtest/gtest.h"
|
||||
|
||||
namespace nss_test {
|
||||
|
||||
// <https://tools.ietf.org/html/rfc7748#section-6.1>
|
||||
const uint8_t kPkcs8[] = {
|
||||
0x30, 0x67, 0x02, 0x01, 0x00, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48,
|
||||
0xce, 0x3d, 0x02, 0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda,
|
||||
0x47, 0x0f, 0x01, 0x04, 0x4c, 0x30, 0x4a, 0x02, 0x01, 0x01, 0x04, 0x20,
|
||||
0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5, 0x7d, 0x3c, 0x16, 0xc1, 0x72,
|
||||
0x51, 0xb2, 0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb, 0xc0, 0x99, 0x2a,
|
||||
0xb1, 0x77, 0xfb, 0xa5, 0x1d, 0xb9, 0x2c, 0x2a, 0xa1, 0x23, 0x03, 0x21,
|
||||
0x00, 0x85, 0x20, 0xf0, 0x09, 0x89, 0x30, 0xa7, 0x54, 0x74, 0x8b, 0x7d,
|
||||
0xdc, 0xb4, 0x3e, 0xf7, 0x5a, 0x0d, 0xbf, 0x3a, 0x0d, 0x26, 0x38, 0x1a,
|
||||
0xf4, 0xeb, 0xa4, 0xa9, 0x8e, 0xaa, 0x9b, 0x4e, 0x6a};
|
||||
const uint8_t kSpki[] = {
|
||||
0x30, 0x39, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x21, 0x00, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3,
|
||||
0x5b, 0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
|
||||
0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f};
|
||||
const uint8_t kSecret[] = {0x4a, 0x5d, 0x9d, 0x5b, 0xa4, 0xce, 0x2d, 0xe1,
|
||||
0x72, 0x8e, 0x3b, 0xf4, 0x80, 0x35, 0x0f, 0x25,
|
||||
0xe0, 0x7e, 0x21, 0xc9, 0x47, 0xd1, 0x9e, 0x33,
|
||||
0x76, 0xf0, 0x9b, 0x3c, 0x1e, 0x16, 0x17, 0x42};
|
||||
|
||||
// A public key that's too short (31 bytes).
|
||||
const uint8_t kSpkiShort[] = {
|
||||
0x30, 0x38, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x20, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3, 0x5b,
|
||||
0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b, 0x78,
|
||||
0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f};
|
||||
|
||||
// A public key that's too long (33 bytes).
|
||||
const uint8_t kSpkiLong[] = {
|
||||
0x30, 0x3a, 0x30, 0x14, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02,
|
||||
0x01, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0xda, 0x47, 0x0f, 0x01,
|
||||
0x03, 0x22, 0x00, 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1, 0xb4, 0xd3,
|
||||
0x5b, 0x61, 0xc2, 0xec, 0xe4, 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
|
||||
0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14, 0x6f, 0x88, 0x2b, 0x4f, 0x34};
|
||||
|
||||
class Pkcs11Curve25519Test : public ::testing::Test {
|
||||
class Pkcs11Curve25519Test
|
||||
: public ::testing::TestWithParam<curve25519_testvector> {
|
||||
protected:
|
||||
void Derive(const uint8_t* pkcs8, size_t pkcs8_len, const uint8_t* spki,
|
||||
size_t spki_len, const uint8_t* secret, size_t secret_len,
|
||||
|
|
@ -84,7 +48,7 @@ class Pkcs11Curve25519Test : public ::testing::Test {
|
|||
ScopedPK11SymKey symKey(PK11_PubDeriveWithKDF(
|
||||
privKey.get(), pubKey.get(), false, nullptr, nullptr, CKM_ECDH1_DERIVE,
|
||||
CKM_SHA512_HMAC, CKA_DERIVE, 0, CKD_NULL, nullptr, nullptr));
|
||||
EXPECT_EQ(expect_success, !!symKey);
|
||||
ASSERT_EQ(expect_success, !!symKey);
|
||||
|
||||
if (expect_success) {
|
||||
rv = PK11_ExtractKeyValue(symKey.get());
|
||||
|
|
@ -94,22 +58,22 @@ class Pkcs11Curve25519Test : public ::testing::Test {
|
|||
EXPECT_EQ(secret_len, keyData->len);
|
||||
EXPECT_EQ(memcmp(keyData->data, secret, secret_len), 0);
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
void Derive(const curve25519_testvector testvector) {
|
||||
Derive(testvector.private_key.data(), testvector.private_key.size(),
|
||||
testvector.public_key.data(), testvector.public_key.size(),
|
||||
testvector.secret.data(), testvector.secret.size(),
|
||||
testvector.valid);
|
||||
};
|
||||
};
|
||||
|
||||
TEST_F(Pkcs11Curve25519Test, DeriveSharedSecret) {
|
||||
Derive(kPkcs8, sizeof(kPkcs8), kSpki, sizeof(kSpki), kSecret, sizeof(kSecret),
|
||||
true);
|
||||
}
|
||||
TEST_P(Pkcs11Curve25519Test, TestVectors) { Derive(GetParam()); }
|
||||
|
||||
TEST_F(Pkcs11Curve25519Test, DeriveSharedSecretShort) {
|
||||
Derive(kPkcs8, sizeof(kPkcs8), kSpkiShort, sizeof(kSpkiShort), nullptr, 0,
|
||||
false);
|
||||
}
|
||||
INSTANTIATE_TEST_CASE_P(NSSTestVector, Pkcs11Curve25519Test,
|
||||
::testing::ValuesIn(kCurve25519Vectors));
|
||||
|
||||
TEST_F(Pkcs11Curve25519Test, DeriveSharedSecretLong) {
|
||||
Derive(kPkcs8, sizeof(kPkcs8), kSpkiLong, sizeof(kSpkiLong), nullptr, 0,
|
||||
false);
|
||||
}
|
||||
INSTANTIATE_TEST_CASE_P(WycheproofTestVector, Pkcs11Curve25519Test,
|
||||
::testing::ValuesIn(kCurve25519WycheproofVectors));
|
||||
|
||||
} // namespace nss_test
|
||||
|
|
|
|||
334
security/nss/gtests/pk11_gtest/pk11_import_unittest.cc
Normal file
334
security/nss/gtests/pk11_gtest/pk11_import_unittest.cc
Normal file
|
|
@ -0,0 +1,334 @@
|
|||
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
||||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
#include <memory>
|
||||
#include "nss.h"
|
||||
#include "pk11pub.h"
|
||||
#include "pk11pqg.h"
|
||||
#include "prerror.h"
|
||||
#include "secoid.h"
|
||||
|
||||
#include "cpputil.h"
|
||||
#include "nss_scoped_ptrs.h"
|
||||
#include "gtest/gtest.h"
|
||||
#include "databuffer.h"
|
||||
|
||||
namespace nss_test {
|
||||
|
||||
// This deleter deletes a set of objects, unlike the deleter on
|
||||
// ScopedPK11GenericObject, which only deletes one.
|
||||
struct PK11GenericObjectsDeleter {
|
||||
void operator()(PK11GenericObject* objs) {
|
||||
if (objs) {
|
||||
PK11_DestroyGenericObjects(objs);
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
class Pk11KeyImportTestBase : public ::testing::Test {
|
||||
public:
|
||||
Pk11KeyImportTestBase(CK_MECHANISM_TYPE mech) : mech_(mech) {}
|
||||
virtual ~Pk11KeyImportTestBase() = default;
|
||||
|
||||
void SetUp() override {
|
||||
slot_.reset(PK11_GetInternalKeySlot());
|
||||
ASSERT_TRUE(slot_);
|
||||
|
||||
static const uint8_t pw[] = "pw";
|
||||
SECItem pwItem = {siBuffer, toUcharPtr(pw), sizeof(pw)};
|
||||
password_.reset(SECITEM_DupItem(&pwItem));
|
||||
}
|
||||
|
||||
void Test() {
|
||||
// Generate a key and export it.
|
||||
KeyType key_type;
|
||||
ScopedSECKEYEncryptedPrivateKeyInfo key_info;
|
||||
ScopedSECItem public_value;
|
||||
GenerateAndExport(&key_type, &key_info, &public_value);
|
||||
ASSERT_NE(nullptr, key_info);
|
||||
ASSERT_NE(nullptr, public_value);
|
||||
|
||||
// Now import the encrypted key.
|
||||
static const uint8_t nick[] = "nick";
|
||||
SECItem nickname = {siBuffer, toUcharPtr(nick), sizeof(nick)};
|
||||
SECKEYPrivateKey* priv_tmp;
|
||||
SECStatus rv = PK11_ImportEncryptedPrivateKeyInfoAndReturnKey(
|
||||
slot_.get(), key_info.get(), password_.get(), &nickname,
|
||||
public_value.get(), PR_TRUE, PR_TRUE, key_type, 0, &priv_tmp, NULL);
|
||||
ASSERT_EQ(SECSuccess, rv) << "PK11_ImportEncryptedPrivateKeyInfo failed "
|
||||
<< PORT_ErrorToName(PORT_GetError());
|
||||
ScopedSECKEYPrivateKey priv_key(priv_tmp);
|
||||
ASSERT_NE(nullptr, priv_key);
|
||||
|
||||
CheckForPublicKey(priv_key, public_value.get());
|
||||
}
|
||||
|
||||
protected:
|
||||
class ParamHolder {
|
||||
public:
|
||||
virtual ~ParamHolder() = default;
|
||||
virtual void* get() = 0;
|
||||
};
|
||||
|
||||
virtual std::unique_ptr<ParamHolder> MakeParams() = 0;
|
||||
|
||||
CK_MECHANISM_TYPE mech_;
|
||||
|
||||
private:
|
||||
void CheckForPublicKey(const ScopedSECKEYPrivateKey& priv_key,
|
||||
const SECItem* expected_public) {
|
||||
// Verify the public key exists.
|
||||
StackSECItem priv_id;
|
||||
SECStatus rv = PK11_ReadRawAttribute(PK11_TypePrivKey, priv_key.get(),
|
||||
CKA_ID, &priv_id);
|
||||
ASSERT_EQ(SECSuccess, rv) << "Couldn't read CKA_ID from private key: "
|
||||
<< PORT_ErrorToName(PORT_GetError());
|
||||
|
||||
CK_ATTRIBUTE_TYPE value_type = CKA_VALUE;
|
||||
switch (SECKEY_GetPrivateKeyType(priv_key.get())) {
|
||||
case rsaKey:
|
||||
value_type = CKA_MODULUS;
|
||||
break;
|
||||
|
||||
case dhKey:
|
||||
case dsaKey:
|
||||
value_type = CKA_VALUE;
|
||||
break;
|
||||
|
||||
case ecKey:
|
||||
value_type = CKA_EC_POINT;
|
||||
break;
|
||||
|
||||
default:
|
||||
FAIL() << "unknown key type";
|
||||
}
|
||||
|
||||
std::unique_ptr<PK11GenericObject, PK11GenericObjectsDeleter> objs(
|
||||
PK11_FindGenericObjects(slot_.get(), CKO_PUBLIC_KEY));
|
||||
ASSERT_NE(nullptr, objs);
|
||||
for (PK11GenericObject* obj = objs.get(); obj != nullptr;
|
||||
obj = PK11_GetNextGenericObject(obj)) {
|
||||
StackSECItem pub_id;
|
||||
rv = PK11_ReadRawAttribute(PK11_TypeGeneric, obj, CKA_ID, &pub_id);
|
||||
if (rv != SECSuccess) {
|
||||
// Can't read CKA_ID from object.
|
||||
continue;
|
||||
}
|
||||
if (!SECITEM_ItemsAreEqual(&priv_id, &pub_id)) {
|
||||
// This isn't the object we're looking for.
|
||||
continue;
|
||||
}
|
||||
|
||||
StackSECItem token;
|
||||
rv = PK11_ReadRawAttribute(PK11_TypeGeneric, obj, CKA_TOKEN, &token);
|
||||
ASSERT_EQ(SECSuccess, rv);
|
||||
ASSERT_EQ(1U, token.len);
|
||||
ASSERT_NE(0, token.data[0]);
|
||||
|
||||
StackSECItem value;
|
||||
rv = PK11_ReadRawAttribute(PK11_TypeGeneric, obj, value_type, &value);
|
||||
ASSERT_EQ(SECSuccess, rv);
|
||||
|
||||
// CKA_EC_POINT isn't stable, see Bug 1520649.
|
||||
if (value_type == CKA_EC_POINT) {
|
||||
continue;
|
||||
}
|
||||
|
||||
ASSERT_TRUE(SECITEM_ItemsAreEqual(expected_public, &value))
|
||||
<< "expected: "
|
||||
<< DataBuffer(expected_public->data, expected_public->len)
|
||||
<< std::endl
|
||||
<< "actual: " << DataBuffer(value.data, value.len) << std::endl;
|
||||
}
|
||||
}
|
||||
|
||||
void GenerateAndExport(KeyType* key_type,
|
||||
ScopedSECKEYEncryptedPrivateKeyInfo* key_info,
|
||||
ScopedSECItem* public_value) {
|
||||
auto params = MakeParams();
|
||||
ASSERT_NE(nullptr, params);
|
||||
|
||||
SECKEYPublicKey* pub_tmp;
|
||||
ScopedSECKEYPrivateKey priv_key(
|
||||
PK11_GenerateKeyPair(slot_.get(), mech_, params->get(), &pub_tmp,
|
||||
PR_FALSE, PR_TRUE, nullptr));
|
||||
ASSERT_NE(nullptr, priv_key) << "PK11_GenerateKeyPair failed: "
|
||||
<< PORT_ErrorToName(PORT_GetError());
|
||||
ScopedSECKEYPublicKey pub_key(pub_tmp);
|
||||
ASSERT_NE(nullptr, pub_key);
|
||||
|
||||
// Wrap and export the key.
|
||||
ScopedSECKEYEncryptedPrivateKeyInfo epki(PK11_ExportEncryptedPrivKeyInfo(
|
||||
slot_.get(), SEC_OID_AES_256_CBC, password_.get(), priv_key.get(), 1,
|
||||
nullptr));
|
||||
ASSERT_NE(nullptr, epki) << "PK11_ExportEncryptedPrivKeyInfo failed: "
|
||||
<< PORT_ErrorToName(PORT_GetError());
|
||||
|
||||
// Save the public value, which we will need on import */
|
||||
SECItem* pub_val;
|
||||
KeyType t = SECKEY_GetPublicKeyType(pub_key.get());
|
||||
switch (t) {
|
||||
case rsaKey:
|
||||
pub_val = &pub_key->u.rsa.modulus;
|
||||
break;
|
||||
case dhKey:
|
||||
pub_val = &pub_key->u.dh.publicValue;
|
||||
break;
|
||||
case dsaKey:
|
||||
pub_val = &pub_key->u.dsa.publicValue;
|
||||
break;
|
||||
case ecKey:
|
||||
pub_val = &pub_key->u.ec.publicValue;
|
||||
break;
|
||||
default:
|
||||
FAIL() << "Unknown key type";
|
||||
}
|
||||
|
||||
CheckForPublicKey(priv_key, pub_val);
|
||||
|
||||
*key_type = t;
|
||||
key_info->swap(epki);
|
||||
public_value->reset(SECITEM_DupItem(pub_val));
|
||||
}
|
||||
|
||||
ScopedPK11SlotInfo slot_;
|
||||
ScopedSECItem password_;
|
||||
};
|
||||
|
||||
class Pk11KeyImportTest
|
||||
: public Pk11KeyImportTestBase,
|
||||
public ::testing::WithParamInterface<CK_MECHANISM_TYPE> {
|
||||
public:
|
||||
Pk11KeyImportTest() : Pk11KeyImportTestBase(GetParam()) {}
|
||||
virtual ~Pk11KeyImportTest() = default;
|
||||
|
||||
protected:
|
||||
std::unique_ptr<ParamHolder> MakeParams() override {
|
||||
switch (mech_) {
|
||||
case CKM_RSA_PKCS_KEY_PAIR_GEN:
|
||||
return std::unique_ptr<ParamHolder>(new RsaParamHolder());
|
||||
|
||||
case CKM_DSA_KEY_PAIR_GEN:
|
||||
case CKM_DH_PKCS_KEY_PAIR_GEN: {
|
||||
PQGParams* pqg_params = nullptr;
|
||||
PQGVerify* pqg_verify = nullptr;
|
||||
const unsigned int key_size = 1024;
|
||||
SECStatus rv = PK11_PQG_ParamGenV2(key_size, 0, key_size / 16,
|
||||
&pqg_params, &pqg_verify);
|
||||
if (rv != SECSuccess) {
|
||||
ADD_FAILURE() << "PK11_PQG_ParamGenV2 failed";
|
||||
return nullptr;
|
||||
}
|
||||
EXPECT_NE(nullptr, pqg_verify);
|
||||
EXPECT_NE(nullptr, pqg_params);
|
||||
PK11_PQG_DestroyVerify(pqg_verify);
|
||||
if (mech_ == CKM_DSA_KEY_PAIR_GEN) {
|
||||
return std::unique_ptr<ParamHolder>(new PqgParamHolder(pqg_params));
|
||||
}
|
||||
return std::unique_ptr<ParamHolder>(new DhParamHolder(pqg_params));
|
||||
}
|
||||
|
||||
default:
|
||||
ADD_FAILURE() << "unknown OID " << mech_;
|
||||
}
|
||||
return nullptr;
|
||||
}
|
||||
|
||||
private:
|
||||
class RsaParamHolder : public ParamHolder {
|
||||
public:
|
||||
RsaParamHolder()
|
||||
: params_({/*.keySizeInBits = */ 1024, /*.pe = */ 0x010001}) {}
|
||||
~RsaParamHolder() = default;
|
||||
|
||||
void* get() override { return ¶ms_; }
|
||||
|
||||
private:
|
||||
PK11RSAGenParams params_;
|
||||
};
|
||||
|
||||
class PqgParamHolder : public ParamHolder {
|
||||
public:
|
||||
PqgParamHolder(PQGParams* params) : params_(params) {}
|
||||
~PqgParamHolder() = default;
|
||||
|
||||
void* get() override { return params_.get(); }
|
||||
|
||||
private:
|
||||
ScopedPQGParams params_;
|
||||
};
|
||||
|
||||
class DhParamHolder : public PqgParamHolder {
|
||||
public:
|
||||
DhParamHolder(PQGParams* params)
|
||||
: PqgParamHolder(params),
|
||||
params_({/*.arena = */ nullptr,
|
||||
/*.prime = */ params->prime,
|
||||
/*.base = */ params->base}) {}
|
||||
~DhParamHolder() = default;
|
||||
|
||||
void* get() override { return ¶ms_; }
|
||||
|
||||
private:
|
||||
SECKEYDHParams params_;
|
||||
};
|
||||
};
|
||||
|
||||
TEST_P(Pk11KeyImportTest, GenerateExportImport) { Test(); }
|
||||
|
||||
INSTANTIATE_TEST_CASE_P(Pk11KeyImportTest, Pk11KeyImportTest,
|
||||
::testing::Values(CKM_RSA_PKCS_KEY_PAIR_GEN,
|
||||
CKM_DSA_KEY_PAIR_GEN));
|
||||
// Note: NSS is currently unable export wrapped DH keys, so this doesn't test
|
||||
// CKM_DH_PKCS_KEY_PAIR_GEN.
|
||||
|
||||
class Pk11KeyImportTestEC : public Pk11KeyImportTestBase,
|
||||
public ::testing::WithParamInterface<SECOidTag> {
|
||||
public:
|
||||
Pk11KeyImportTestEC() : Pk11KeyImportTestBase(CKM_EC_KEY_PAIR_GEN) {}
|
||||
virtual ~Pk11KeyImportTestEC() = default;
|
||||
|
||||
protected:
|
||||
std::unique_ptr<ParamHolder> MakeParams() override {
|
||||
return std::unique_ptr<ParamHolder>(new EcParamHolder(GetParam()));
|
||||
}
|
||||
|
||||
private:
|
||||
class EcParamHolder : public ParamHolder {
|
||||
public:
|
||||
EcParamHolder(SECOidTag curve_oid) {
|
||||
SECOidData* curve = SECOID_FindOIDByTag(curve_oid);
|
||||
EXPECT_NE(nullptr, curve);
|
||||
|
||||
size_t plen = curve->oid.len + 2;
|
||||
extra_.reset(new uint8_t[plen]);
|
||||
extra_[0] = SEC_ASN1_OBJECT_ID;
|
||||
extra_[1] = static_cast<uint8_t>(curve->oid.len);
|
||||
memcpy(&extra_[2], curve->oid.data, curve->oid.len);
|
||||
|
||||
ec_params_ = {/*.type = */ siBuffer,
|
||||
/*.data = */ extra_.get(),
|
||||
/*.len = */ static_cast<unsigned int>(plen)};
|
||||
}
|
||||
~EcParamHolder() = default;
|
||||
|
||||
void* get() override { return &ec_params_; }
|
||||
|
||||
private:
|
||||
SECKEYECParams ec_params_;
|
||||
std::unique_ptr<uint8_t[]> extra_;
|
||||
};
|
||||
};
|
||||
|
||||
TEST_P(Pk11KeyImportTestEC, GenerateExportImport) { Test(); }
|
||||
|
||||
INSTANTIATE_TEST_CASE_P(Pk11KeyImportTestEC, Pk11KeyImportTestEC,
|
||||
::testing::Values(SEC_OID_SECG_EC_SECP256R1,
|
||||
SEC_OID_SECG_EC_SECP384R1,
|
||||
SEC_OID_SECG_EC_SECP521R1,
|
||||
SEC_OID_CURVE25519));
|
||||
|
||||
} // namespace nss_test
|
||||
|
|
@ -93,6 +93,20 @@ TEST_F(Pkcs11RsaPssTest, GenerateAndSignAndVerify) {
|
|||
EXPECT_EQ(rv, SECFailure);
|
||||
}
|
||||
|
||||
TEST_F(Pkcs11RsaPssTest, NoLeakWithInvalidExponent) {
|
||||
// Attempt to generate an RSA key with a public exponent of 1. This should
|
||||
// fail, but it shouldn't leak memory.
|
||||
PK11RSAGenParams rsaGenParams = {1024, 0x01};
|
||||
|
||||
// Generate RSA key pair.
|
||||
ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
|
||||
SECKEYPublicKey* pubKey = nullptr;
|
||||
SECKEYPrivateKey* privKey =
|
||||
PK11_GenerateKeyPair(slot.get(), CKM_RSA_PKCS_KEY_PAIR_GEN, &rsaGenParams,
|
||||
&pubKey, false, false, nullptr);
|
||||
EXPECT_FALSE(privKey);
|
||||
EXPECT_FALSE(pubKey);
|
||||
}
|
||||
class Pkcs11RsaPssVectorTest
|
||||
: public Pkcs11RsaPssTest,
|
||||
public ::testing::WithParamInterface<Pkcs11SignatureTestParams> {};
|
||||
|
|
|
|||
53
security/nss/gtests/ssl_gtest/ssl_debug_env_unittest.cc
Normal file
53
security/nss/gtests/ssl_gtest/ssl_debug_env_unittest.cc
Normal file
|
|
@ -0,0 +1,53 @@
|
|||
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
||||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
#include <cstdlib>
|
||||
#include <fstream>
|
||||
#include <sstream>
|
||||
|
||||
#include "gtest_utils.h"
|
||||
#include "tls_connect.h"
|
||||
|
||||
namespace nss_test {
|
||||
|
||||
extern "C" {
|
||||
extern FILE* ssl_trace_iob;
|
||||
|
||||
#ifdef NSS_ALLOW_SSLKEYLOGFILE
|
||||
extern FILE* ssl_keylog_iob;
|
||||
#endif
|
||||
}
|
||||
|
||||
// These tests ensure that when the associated environment variables are unset
|
||||
// that the lazily-initialized defaults are what they are supposed to be.
|
||||
|
||||
#ifdef DEBUG
|
||||
TEST_P(TlsConnectGeneric, DebugEnvTraceFileNotSet) {
|
||||
char* ev = PR_GetEnvSecure("SSLDEBUGFILE");
|
||||
if (ev && ev[0]) {
|
||||
// note: should use GTEST_SKIP when GTest gets updated to support it
|
||||
return;
|
||||
}
|
||||
|
||||
Connect();
|
||||
EXPECT_EQ(stderr, ssl_trace_iob);
|
||||
}
|
||||
#endif
|
||||
|
||||
#ifdef NSS_ALLOW_SSLKEYLOGFILE
|
||||
TEST_P(TlsConnectGeneric, DebugEnvKeylogFileNotSet) {
|
||||
char* ev = PR_GetEnvSecure("SSLKEYLOGFILE");
|
||||
if (ev && ev[0]) {
|
||||
// note: should use GTEST_SKIP when GTest gets updated to support it
|
||||
return;
|
||||
}
|
||||
|
||||
Connect();
|
||||
EXPECT_EQ(nullptr, ssl_keylog_iob);
|
||||
}
|
||||
#endif
|
||||
|
||||
} // namespace nss_test
|
||||
|
|
@ -269,4 +269,11 @@ TEST_F(TlsConnectStreamTls13, Tls14ClientHelloWithSupportedVersions) {
|
|||
ASSERT_LT(static_cast<uint32_t>(SSL_LIBRARY_VERSION_TLS_1_2), version);
|
||||
}
|
||||
|
||||
// Offer 1.3 but with ClientHello.legacy_version == SSL 3.0. This
|
||||
// causes a protocol version alert. See RFC 8446 Appendix D.5.
|
||||
TEST_F(TlsConnectStreamTls13, Ssl30ClientHelloWithSupportedVersions) {
|
||||
MakeTlsFilter<TlsClientHelloVersionSetter>(client_, SSL_LIBRARY_VERSION_3_0);
|
||||
ConnectExpectAlert(server_, kTlsAlertProtocolVersion);
|
||||
}
|
||||
|
||||
} // namespace nss_test
|
||||
|
|
|
|||
43
security/nss/gtests/sysinit_gtest/Makefile
Normal file
43
security/nss/gtests/sysinit_gtest/Makefile
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
#! gmake
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
|
||||
#######################################################################
|
||||
# (1) Include initial platform-independent assignments (MANDATORY). #
|
||||
#######################################################################
|
||||
|
||||
include manifest.mn
|
||||
|
||||
#######################################################################
|
||||
# (2) Include "global" configuration information. (OPTIONAL) #
|
||||
#######################################################################
|
||||
|
||||
include $(CORE_DEPTH)/coreconf/config.mk
|
||||
|
||||
#######################################################################
|
||||
# (3) Include "component" configuration information. (OPTIONAL) #
|
||||
#######################################################################
|
||||
|
||||
|
||||
#######################################################################
|
||||
# (4) Include "local" platform-dependent assignments (OPTIONAL). #
|
||||
#######################################################################
|
||||
|
||||
include ../common/gtest.mk
|
||||
|
||||
#######################################################################
|
||||
# (5) Execute "global" rules. (OPTIONAL) #
|
||||
#######################################################################
|
||||
|
||||
include $(CORE_DEPTH)/coreconf/rules.mk
|
||||
|
||||
#######################################################################
|
||||
# (6) Execute "component" rules. (OPTIONAL) #
|
||||
#######################################################################
|
||||
|
||||
|
||||
#######################################################################
|
||||
# (7) Execute "local" rules. (OPTIONAL). #
|
||||
#######################################################################
|
||||
164
security/nss/gtests/sysinit_gtest/getUserDB_unittest.cc
Normal file
164
security/nss/gtests/sysinit_gtest/getUserDB_unittest.cc
Normal file
|
|
@ -0,0 +1,164 @@
|
|||
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
||||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
#include "gtest/gtest.h"
|
||||
#include "prenv.h"
|
||||
#include "seccomon.h"
|
||||
|
||||
#include <stdlib.h>
|
||||
#include <string>
|
||||
#include <unistd.h>
|
||||
#include <sys/stat.h>
|
||||
|
||||
namespace nss_test {
|
||||
|
||||
// Return the path to user's NSS database.
|
||||
extern "C" char *getUserDB(void);
|
||||
|
||||
class Sysinit : public ::testing::Test {
|
||||
protected:
|
||||
void SetUp() {
|
||||
home_var_ = PR_GetEnvSecure("HOME");
|
||||
if (home_var_) {
|
||||
old_home_dir_ = home_var_;
|
||||
}
|
||||
xdg_data_home_var_ = PR_GetEnvSecure("XDG_DATA_HOME");
|
||||
if (xdg_data_home_var_) {
|
||||
old_xdg_data_home_ = xdg_data_home_var_;
|
||||
ASSERT_EQ(0, unsetenv("XDG_DATA_HOME"));
|
||||
}
|
||||
char tmp[] = "/tmp/nss-tmp.XXXXXX";
|
||||
tmp_home_ = mkdtemp(tmp);
|
||||
ASSERT_EQ(0, setenv("HOME", tmp_home_.c_str(), 1));
|
||||
}
|
||||
|
||||
void TearDown() {
|
||||
// Set HOME back to original
|
||||
if (home_var_) {
|
||||
ASSERT_EQ(0, setenv("HOME", old_home_dir_.c_str(), 1));
|
||||
} else {
|
||||
ASSERT_EQ(0, unsetenv("HOME"));
|
||||
}
|
||||
// Set XDG_DATA_HOME back to original
|
||||
if (xdg_data_home_var_) {
|
||||
ASSERT_EQ(0, setenv("XDG_DATA_HOME", old_xdg_data_home_.c_str(), 1));
|
||||
}
|
||||
// Remove test dirs.
|
||||
if (!nssdir_.empty()) {
|
||||
ASSERT_EQ(0, RemoveEmptyDirsFromStart(nssdir_, tmp_home_));
|
||||
}
|
||||
}
|
||||
|
||||
// Remove all dirs within @start from @path containing only empty dirs.
|
||||
// Assumes @start already exists.
|
||||
// Upon successful completion, return 0. Otherwise, -1.
|
||||
static int RemoveEmptyDirsFromStart(std::string path, std::string start) {
|
||||
if (path.find(start) == std::string::npos) {
|
||||
return -1;
|
||||
}
|
||||
std::string temp = path;
|
||||
if (rmdir(temp.c_str())) {
|
||||
return -1;
|
||||
}
|
||||
for (size_t i = temp.length() - 1; i > start.length(); --i) {
|
||||
if (temp[i] == '/') {
|
||||
temp[i] = '\0';
|
||||
if (rmdir(temp.c_str())) {
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (rmdir(start.c_str())) {
|
||||
return -1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
// Create empty dirs appending @path to @start with mode @mode.
|
||||
// Assumes @start already exists.
|
||||
// Upon successful completion, return the string @start + @path.
|
||||
static std::string CreateEmptyDirsFromStart(std::string start,
|
||||
std::string path, mode_t mode) {
|
||||
std::string temp = start + "/";
|
||||
for (size_t i = 1; i < path.length(); ++i) {
|
||||
if (path[i] == '/') {
|
||||
EXPECT_EQ(0, mkdir(temp.c_str(), mode));
|
||||
}
|
||||
temp += path[i];
|
||||
}
|
||||
// We reach the end of string before the last dir is created
|
||||
EXPECT_EQ(0, mkdir(temp.c_str(), mode));
|
||||
return temp;
|
||||
}
|
||||
|
||||
char *home_var_;
|
||||
char *xdg_data_home_var_;
|
||||
std::string old_home_dir_;
|
||||
std::string old_xdg_data_home_;
|
||||
std::string nssdir_;
|
||||
std::string tmp_home_;
|
||||
};
|
||||
|
||||
class SysinitSetXdgUserDataHome : public Sysinit {
|
||||
protected:
|
||||
void SetUp() {
|
||||
Sysinit::SetUp();
|
||||
ASSERT_EQ(0, setenv("XDG_DATA_HOME", tmp_home_.c_str(), 1));
|
||||
}
|
||||
};
|
||||
|
||||
class SysinitSetTrashXdgUserDataHome : public Sysinit {
|
||||
protected:
|
||||
void SetUp() {
|
||||
Sysinit::SetUp();
|
||||
std::string trashPath = tmp_home_ + "/this/path/does/not/exist";
|
||||
ASSERT_EQ(0, setenv("XDG_DATA_HOME", trashPath.c_str(), 1));
|
||||
}
|
||||
|
||||
void TearDown() {
|
||||
ASSERT_EQ(0, rmdir(tmp_home_.c_str()));
|
||||
Sysinit::TearDown();
|
||||
}
|
||||
};
|
||||
|
||||
// Check if $HOME/.pki/nssdb is used if it exists
|
||||
TEST_F(Sysinit, LegacyPath) {
|
||||
nssdir_ = CreateEmptyDirsFromStart(tmp_home_, "/.pki/nssdb", 0760);
|
||||
char *nssdb = getUserDB();
|
||||
ASSERT_EQ(nssdir_, nssdb);
|
||||
PORT_Free(nssdb);
|
||||
}
|
||||
|
||||
// Check if $HOME/.local/share/pki/nssdb is used if:
|
||||
// - $HOME/.pki/nssdb does not exist;
|
||||
// - XDG_DATA_HOME is not set.
|
||||
TEST_F(Sysinit, XdgDefaultPath) {
|
||||
nssdir_ = CreateEmptyDirsFromStart(tmp_home_, "/.local/share", 0755);
|
||||
nssdir_ = CreateEmptyDirsFromStart(nssdir_, "/pki/nssdb", 0760);
|
||||
char *nssdb = getUserDB();
|
||||
ASSERT_EQ(nssdir_, nssdb);
|
||||
PORT_Free(nssdb);
|
||||
}
|
||||
|
||||
// Check if ${XDG_DATA_HOME}/pki/nssdb is used if:
|
||||
// - $HOME/.pki/nssdb does not exist;
|
||||
// - XDG_DATA_HOME is set and the path exists.
|
||||
TEST_F(SysinitSetXdgUserDataHome, XdgSetPath) {
|
||||
// XDG_DATA_HOME is set to HOME
|
||||
nssdir_ = CreateEmptyDirsFromStart(tmp_home_, "/pki/nssdb", 0760);
|
||||
char *nssdb = getUserDB();
|
||||
ASSERT_EQ(nssdir_, nssdb);
|
||||
PORT_Free(nssdb);
|
||||
}
|
||||
|
||||
// Check if it fails when:
|
||||
// - XDG_DATA_HOME is set to a path that does not exist;
|
||||
// - $HOME/.pki/nssdb also does not exist. */
|
||||
TEST_F(SysinitSetTrashXdgUserDataHome, XdgSetToTrashPath) {
|
||||
char *nssdb = getUserDB();
|
||||
ASSERT_EQ(nullptr, nssdb);
|
||||
}
|
||||
|
||||
} // namespace nss_test
|
||||
27
security/nss/gtests/sysinit_gtest/manifest.mn
Normal file
27
security/nss/gtests/sysinit_gtest/manifest.mn
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
CORE_DEPTH = ../..
|
||||
DEPTH = ../..
|
||||
|
||||
MODULE = nss
|
||||
|
||||
CPPSRCS = \
|
||||
getUserDB_unittest.cc \
|
||||
sysinit_gtest.cc \
|
||||
$(NULL)
|
||||
|
||||
INCLUDES += -I$(CORE_DEPTH)/gtests/google_test/gtest/include \
|
||||
-I$(CORE_DEPTH)/gtests/common
|
||||
|
||||
REQUIRES = nspr nss libdbm gtest
|
||||
|
||||
PROGRAM = sysinit_gtest
|
||||
|
||||
EXTRA_LIBS = \
|
||||
$(DIST)/lib/$(LIB_PREFIX)gtest.$(LIB_SUFFIX) $(EXTRA_OBJS) \
|
||||
$(DIST)/lib/$(LIB_PREFIX)nsssysinit.$(LIB_SUFFIX) \
|
||||
$(NULL)
|
||||
|
||||
USE_STATIC_LIBS = 1
|
||||
9
security/nss/gtests/sysinit_gtest/sysinit_gtest.cc
Normal file
9
security/nss/gtests/sysinit_gtest/sysinit_gtest.cc
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
#define GTEST_HAS_RTTI 0
|
||||
#include "gtest/gtest.h"
|
||||
|
||||
int main(int argc, char** argv) {
|
||||
// Start the tests
|
||||
::testing::InitGoogleTest(&argc, argv);
|
||||
int rv = RUN_ALL_TESTS();
|
||||
return rv;
|
||||
}
|
||||
35
security/nss/gtests/sysinit_gtest/sysinit_gtest.gyp
Normal file
35
security/nss/gtests/sysinit_gtest/sysinit_gtest.gyp
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
{
|
||||
'includes': [
|
||||
'../../coreconf/config.gypi',
|
||||
'../common/gtest.gypi'
|
||||
],
|
||||
'targets': [
|
||||
{
|
||||
'target_name': 'sysinit_gtest',
|
||||
'type': 'executable',
|
||||
'sources': [
|
||||
'sysinit_gtest.cc',
|
||||
'getUserDB_unittest.cc',
|
||||
],
|
||||
'dependencies': [
|
||||
'<(DEPTH)/exports.gyp:nss_exports',
|
||||
'<(DEPTH)/gtests/google_test/google_test.gyp:gtest',
|
||||
'<(DEPTH)/lib/sysinit/sysinit.gyp:nsssysinit_static'
|
||||
]
|
||||
}
|
||||
],
|
||||
'target_defaults': {
|
||||
'include_dirs': [
|
||||
'../../lib/sysinit'
|
||||
],
|
||||
'defines': [
|
||||
'NSS_USE_STATIC_LIBS'
|
||||
]
|
||||
},
|
||||
'variables': {
|
||||
'module': 'nss'
|
||||
}
|
||||
}
|
||||
|
|
@ -3,29 +3,30 @@
|
|||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
CORE_DEPTH = ../..
|
||||
DEPTH = ../..
|
||||
DEPTH = ../..
|
||||
MODULE = nss
|
||||
|
||||
CPPSRCS = \
|
||||
util_utf8_unittest.cc \
|
||||
util_b64_unittest.cc \
|
||||
util_pkcs11uri_unittest.cc \
|
||||
util_aligned_malloc_unittest.cc \
|
||||
util_memcmpzero_unittest.cc \
|
||||
$(NULL)
|
||||
util_aligned_malloc_unittest.cc \
|
||||
util_b64_unittest.cc \
|
||||
util_gtests.cc \
|
||||
util_memcmpzero_unittest.cc \
|
||||
util_pkcs11uri_unittest.cc \
|
||||
util_utf8_unittest.cc \
|
||||
$(NULL)
|
||||
|
||||
INCLUDES += \
|
||||
-I$(CORE_DEPTH)/gtests/google_test/gtest/include \
|
||||
-I$(CORE_DEPTH)/gtests/common \
|
||||
-I$(CORE_DEPTH)/cpputil \
|
||||
$(NULL)
|
||||
-I$(CORE_DEPTH)/gtests/google_test/gtest/include \
|
||||
-I$(CORE_DEPTH)/gtests/common \
|
||||
-I$(CORE_DEPTH)/cpputil \
|
||||
$(NULL)
|
||||
|
||||
REQUIRES = nspr gtest
|
||||
|
||||
PROGRAM = util_gtest
|
||||
|
||||
EXTRA_LIBS = \
|
||||
$(DIST)/lib/$(LIB_PREFIX)gtest.$(LIB_SUFFIX) \
|
||||
$(DIST)/lib/$(LIB_PREFIX)nssutil.$(LIB_SUFFIX) \
|
||||
$(DIST)/lib/$(LIB_PREFIX)gtestutil.$(LIB_SUFFIX) \
|
||||
$(NULL)
|
||||
$(DIST)/lib/$(LIB_PREFIX)gtest.$(LIB_SUFFIX) \
|
||||
$(DIST)/lib/$(LIB_PREFIX)nssutil.$(LIB_SUFFIX) \
|
||||
$(DIST)/lib/$(LIB_PREFIX)gtestutil.$(LIB_SUFFIX) \
|
||||
$(NULL)
|
||||
|
|
|
|||
|
|
@ -11,27 +11,17 @@
|
|||
'target_name': 'util_gtest',
|
||||
'type': 'executable',
|
||||
'sources': [
|
||||
'util_utf8_unittest.cc',
|
||||
'util_b64_unittest.cc',
|
||||
'util_pkcs11uri_unittest.cc',
|
||||
'util_aligned_malloc_unittest.cc',
|
||||
'util_b64_unittest.cc',
|
||||
'util_gtests.cc',
|
||||
'util_memcmpzero_unittest.cc',
|
||||
'<(DEPTH)/gtests/common/gtests.cc',
|
||||
'util_pkcs11uri_unittest.cc',
|
||||
'util_utf8_unittest.cc',
|
||||
],
|
||||
'dependencies': [
|
||||
'<(DEPTH)/exports.gyp:nss_exports',
|
||||
'<(DEPTH)/gtests/google_test/google_test.gyp:gtest',
|
||||
'<(DEPTH)/lib/util/util.gyp:nssutil',
|
||||
'<(DEPTH)/lib/nss/nss.gyp:nss_static',
|
||||
'<(DEPTH)/lib/pk11wrap/pk11wrap.gyp:pk11wrap_static',
|
||||
'<(DEPTH)/lib/cryptohi/cryptohi.gyp:cryptohi',
|
||||
'<(DEPTH)/lib/certhigh/certhigh.gyp:certhi',
|
||||
'<(DEPTH)/lib/certdb/certdb.gyp:certdb',
|
||||
'<(DEPTH)/lib/base/base.gyp:nssb',
|
||||
'<(DEPTH)/lib/dev/dev.gyp:nssdev',
|
||||
'<(DEPTH)/lib/pki/pki.gyp:nsspki',
|
||||
'<(DEPTH)/lib/ssl/ssl.gyp:ssl',
|
||||
'<(DEPTH)/lib/libpkix/libpkix.gyp:libpkix',
|
||||
],
|
||||
'conditions': [
|
||||
[ 'OS=="win"', {
|
||||
|
|
|
|||
9
security/nss/gtests/util_gtest/util_gtests.cc
Normal file
9
security/nss/gtests/util_gtest/util_gtests.cc
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
#include <cstdlib>
|
||||
|
||||
#define GTEST_HAS_RTTI 0
|
||||
#include "gtest/gtest.h"
|
||||
|
||||
int main(int argc, char **argv) {
|
||||
::testing::InitGoogleTest(&argc, argv);
|
||||
return RUN_ALL_TESTS();
|
||||
}
|
||||
|
|
@ -202,13 +202,46 @@ HASH_GetHashTypeByOidTag(SECOidTag hashOid)
|
|||
ht = HASH_AlgSHA512;
|
||||
break;
|
||||
default:
|
||||
ht = HASH_AlgNULL;
|
||||
PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
|
||||
break;
|
||||
}
|
||||
return ht;
|
||||
}
|
||||
|
||||
SECOidTag
|
||||
HASH_GetHashOidTagByHashType(HASH_HashType type)
|
||||
{
|
||||
SECOidTag oid = SEC_OID_UNKNOWN;
|
||||
|
||||
switch (type) {
|
||||
case HASH_AlgMD2:
|
||||
oid = SEC_OID_MD2;
|
||||
break;
|
||||
case HASH_AlgMD5:
|
||||
oid = SEC_OID_MD5;
|
||||
break;
|
||||
case HASH_AlgSHA1:
|
||||
oid = SEC_OID_SHA1;
|
||||
break;
|
||||
case HASH_AlgSHA224:
|
||||
oid = SEC_OID_SHA224;
|
||||
break;
|
||||
case HASH_AlgSHA256:
|
||||
oid = SEC_OID_SHA256;
|
||||
break;
|
||||
case HASH_AlgSHA384:
|
||||
oid = SEC_OID_SHA384;
|
||||
break;
|
||||
case HASH_AlgSHA512:
|
||||
oid = SEC_OID_SHA512;
|
||||
break;
|
||||
default:
|
||||
PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
|
||||
break;
|
||||
}
|
||||
return oid;
|
||||
}
|
||||
|
||||
SECOidTag
|
||||
HASH_GetHashOidTagByHMACOidTag(SECOidTag hmacOid)
|
||||
{
|
||||
|
|
|
|||
|
|
@ -53,6 +53,8 @@ extern HASH_HashType HASH_GetHashTypeByOidTag(SECOidTag hashOid);
|
|||
extern SECOidTag HASH_GetHashOidTagByHMACOidTag(SECOidTag hmacOid);
|
||||
extern SECOidTag HASH_GetHMACOidTagByHashOidTag(SECOidTag hashOid);
|
||||
|
||||
extern SECOidTag HASH_GetHashOidTagByHashType(HASH_HashType type);
|
||||
|
||||
SEC_END_PROTOS
|
||||
|
||||
#endif /* _HASH_H_ */
|
||||
|
|
|
|||
|
|
@ -31,32 +31,32 @@
|
|||
* @(#)extern.h 8.4 (Berkeley) 6/16/94
|
||||
*/
|
||||
|
||||
BUFHEAD *__add_ovflpage(HTAB *, BUFHEAD *);
|
||||
int __addel(HTAB *, BUFHEAD *, const DBT *, const DBT *);
|
||||
int __big_delete(HTAB *, BUFHEAD *);
|
||||
int __big_insert(HTAB *, BUFHEAD *, const DBT *, const DBT *);
|
||||
int __big_keydata(HTAB *, BUFHEAD *, DBT *, DBT *, int);
|
||||
int __big_return(HTAB *, BUFHEAD *, int, DBT *, int);
|
||||
int __big_split(HTAB *, BUFHEAD *, BUFHEAD *, BUFHEAD *,
|
||||
uint32, uint32, SPLIT_RETURN *);
|
||||
int __buf_free(HTAB *, int, int);
|
||||
void __buf_init(HTAB *, int);
|
||||
uint32 __call_hash(HTAB *, char *, size_t);
|
||||
int __delpair(HTAB *, BUFHEAD *, int);
|
||||
int __expand_table(HTAB *);
|
||||
int __find_bigpair(HTAB *, BUFHEAD *, int, char *, int);
|
||||
uint16 __find_last_page(HTAB *, BUFHEAD **);
|
||||
void __free_ovflpage(HTAB *, BUFHEAD *);
|
||||
BUFHEAD *__get_buf(HTAB *, uint32, BUFHEAD *, int);
|
||||
int __get_page(HTAB *, char *, uint32, int, int, int);
|
||||
int __ibitmap(HTAB *, int, int, int);
|
||||
uint32 __log2(uint32);
|
||||
int __put_page(HTAB *, char *, uint32, int, int);
|
||||
void __reclaim_buf(HTAB *, BUFHEAD *);
|
||||
int __split_page(HTAB *, uint32, uint32);
|
||||
BUFHEAD *dbm_add_ovflpage(HTAB *, BUFHEAD *);
|
||||
int dbm_addel(HTAB *, BUFHEAD *, const DBT *, const DBT *);
|
||||
int dbm_big_delete(HTAB *, BUFHEAD *);
|
||||
int dbm_big_insert(HTAB *, BUFHEAD *, const DBT *, const DBT *);
|
||||
int dbm_big_keydata(HTAB *, BUFHEAD *, DBT *, DBT *, int);
|
||||
int dbm_big_return(HTAB *, BUFHEAD *, int, DBT *, int);
|
||||
int dbm_big_split(HTAB *, BUFHEAD *, BUFHEAD *, BUFHEAD *,
|
||||
uint32, uint32, SPLIT_RETURN *);
|
||||
int dbm_buf_free(HTAB *, int, int);
|
||||
void dbm_buf_init(HTAB *, int);
|
||||
uint32 dbm_call_hash(HTAB *, char *, size_t);
|
||||
int dbm_delpair(HTAB *, BUFHEAD *, int);
|
||||
int dbm_expand_table(HTAB *);
|
||||
int dbm_find_bigpair(HTAB *, BUFHEAD *, int, char *, int);
|
||||
uint16 dbm_find_last_page(HTAB *, BUFHEAD **);
|
||||
void dbm_free_ovflpage(HTAB *, BUFHEAD *);
|
||||
BUFHEAD *dbm_get_buf(HTAB *, uint32, BUFHEAD *, int);
|
||||
int dbm_get_page(HTAB *, char *, uint32, int, int, int);
|
||||
int dbm_ibitmap(HTAB *, int, int, int);
|
||||
uint32 dbm_log2(uint32);
|
||||
int dbm_put_page(HTAB *, char *, uint32, int, int);
|
||||
void dbm_reclaim_buf(HTAB *, BUFHEAD *);
|
||||
int dbm_split_page(HTAB *, uint32, uint32);
|
||||
|
||||
/* Default hash routine. */
|
||||
extern uint32 (*__default_hash)(const void *, size_t);
|
||||
extern uint32 (*dbm_default_hash)(const void *, size_t);
|
||||
|
||||
#ifdef HASH_STATISTICS
|
||||
extern int hash_accesses, hash_collisions, hash_expansions, hash_overflows;
|
||||
|
|
|
|||
|
|
@ -190,7 +190,7 @@ typedef struct htab { /* Memory resident data structure */
|
|||
#define OADDR_OF(S, O) ((uint32)((uint32)(S) << SPLITSHIFT) + (O))
|
||||
|
||||
#define BUCKET_TO_PAGE(B) \
|
||||
(B) + hashp->HDRPAGES + ((B) ? hashp->SPARES[__log2((uint32)((B) + 1)) - 1] : 0)
|
||||
(B) + hashp->HDRPAGES + ((B) ? hashp->SPARES[dbm_log2((uint32)((B) + 1)) - 1] : 0)
|
||||
#define OADDR_TO_PAGE(B) \
|
||||
BUCKET_TO_PAGE((1 << SPLITNUM((B))) - 1) + OPAGENUM((B));
|
||||
|
||||
|
|
@ -314,28 +314,28 @@ typedef struct htab { /* Memory resident data structure */
|
|||
#define NEXT_FREE hdr.next_free
|
||||
#define H_CHARKEY hdr.h_charkey
|
||||
|
||||
extern uint32 (*__default_hash)(const void *, size_t);
|
||||
void __buf_init(HTAB *hashp, int32 nbytes);
|
||||
int __big_delete(HTAB *hashp, BUFHEAD *bufp);
|
||||
BUFHEAD *__get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage);
|
||||
uint32 __call_hash(HTAB *hashp, char *k, size_t len);
|
||||
extern uint32 (*dbm_default_hash)(const void *, size_t);
|
||||
void dbm_buf_init(HTAB *hashp, int32 nbytes);
|
||||
int dbm_big_delete(HTAB *hashp, BUFHEAD *bufp);
|
||||
BUFHEAD *dbm_get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage);
|
||||
uint32 dbm_call_hash(HTAB *hashp, char *k, size_t len);
|
||||
#include "page.h"
|
||||
extern int __big_split(HTAB *hashp, BUFHEAD *op, BUFHEAD *np,
|
||||
BUFHEAD *big_keyp, uint32 addr, uint32 obucket, SPLIT_RETURN *ret);
|
||||
void __free_ovflpage(HTAB *hashp, BUFHEAD *obufp);
|
||||
BUFHEAD *__add_ovflpage(HTAB *hashp, BUFHEAD *bufp);
|
||||
int __big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val);
|
||||
int __expand_table(HTAB *hashp);
|
||||
uint32 __log2(uint32 num);
|
||||
void __reclaim_buf(HTAB *hashp, BUFHEAD *bp);
|
||||
int __get_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_disk, int is_bitmap);
|
||||
int __put_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_bitmap);
|
||||
int __ibitmap(HTAB *hashp, int pnum, int nbits, int ndx);
|
||||
int __buf_free(HTAB *hashp, int do_free, int to_disk);
|
||||
int __find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size);
|
||||
uint16 __find_last_page(HTAB *hashp, BUFHEAD **bpp);
|
||||
int __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val);
|
||||
int __big_return(HTAB *hashp, BUFHEAD *bufp, int ndx, DBT *val, int set_current);
|
||||
int __delpair(HTAB *hashp, BUFHEAD *bufp, int ndx);
|
||||
int __big_keydata(HTAB *hashp, BUFHEAD *bufp, DBT *key, DBT *val, int set);
|
||||
int __split_page(HTAB *hashp, uint32 obucket, uint32 nbucket);
|
||||
extern int dbm_big_split(HTAB *hashp, BUFHEAD *op, BUFHEAD *np,
|
||||
BUFHEAD *big_keyp, uint32 addr, uint32 obucket, SPLIT_RETURN *ret);
|
||||
void dbm_free_ovflpage(HTAB *hashp, BUFHEAD *obufp);
|
||||
BUFHEAD *dbm_add_ovflpage(HTAB *hashp, BUFHEAD *bufp);
|
||||
int dbm_big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val);
|
||||
int dbm_expand_table(HTAB *hashp);
|
||||
uint32 dbm_log2(uint32 num);
|
||||
void dbm_reclaim_buf(HTAB *hashp, BUFHEAD *bp);
|
||||
int dbm_get_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_disk, int is_bitmap);
|
||||
int dbm_put_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_bitmap);
|
||||
int dbm_ibitmap(HTAB *hashp, int pnum, int nbits, int ndx);
|
||||
int dbm_buf_free(HTAB *hashp, int do_free, int to_disk);
|
||||
int dbm_find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size);
|
||||
uint16 dbm_find_last_page(HTAB *hashp, BUFHEAD **bpp);
|
||||
int dbm_addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val);
|
||||
int dbm_big_return(HTAB *hashp, BUFHEAD *bufp, int ndx, DBT *val, int set_current);
|
||||
int dbm_delpair(HTAB *hashp, BUFHEAD *bufp, int ndx);
|
||||
int dbm_big_keydata(HTAB *hashp, BUFHEAD *bufp, DBT *key, DBT *val, int set);
|
||||
int dbm_split_page(HTAB *hashp, uint32 obucket, uint32 nbucket);
|
||||
|
|
|
|||
|
|
@ -287,16 +287,16 @@ typedef enum { LockOutDatabase,
|
|||
#endif
|
||||
|
||||
/* Access method description structure. */
|
||||
typedef struct __db {
|
||||
typedef struct dbm_db {
|
||||
DBTYPE type; /* Underlying db type. */
|
||||
int (*close)(struct __db *);
|
||||
int (*del)(const struct __db *, const DBT *, uint);
|
||||
int (*get)(const struct __db *, const DBT *, DBT *, uint);
|
||||
int (*put)(const struct __db *, DBT *, const DBT *, uint);
|
||||
int (*seq)(const struct __db *, DBT *, DBT *, uint);
|
||||
int (*sync)(const struct __db *, uint);
|
||||
int (*close)(struct dbm_db *);
|
||||
int (*del)(const struct dbm_db *, const DBT *, uint);
|
||||
int (*get)(const struct dbm_db *, const DBT *, DBT *, uint);
|
||||
int (*put)(const struct dbm_db *, DBT *, const DBT *, uint);
|
||||
int (*seq)(const struct dbm_db *, DBT *, DBT *, uint);
|
||||
int (*sync)(const struct dbm_db *, uint);
|
||||
void *internal; /* Access method private. */
|
||||
int (*fd)(const struct __db *);
|
||||
int (*fd)(const struct dbm_db *);
|
||||
} DB;
|
||||
|
||||
#define BTREEMAGIC 0x053162
|
||||
|
|
@ -412,10 +412,10 @@ dbopen(const char *, int, int, DBTYPE, const void *);
|
|||
void dbSetOrClearDBLock(DBLockFlagEnum type);
|
||||
|
||||
#ifdef __DBINTERFACE_PRIVATE
|
||||
DB *__bt_open(const char *, int, int, const BTREEINFO *, int);
|
||||
DB *__hash_open(const char *, int, int, const HASHINFO *, int);
|
||||
DB *__rec_open(const char *, int, int, const RECNOINFO *, int);
|
||||
void __dbpanic(DB *dbp);
|
||||
DB *dbm_bt_open(const char *, int, int, const BTREEINFO *, int);
|
||||
DB *dbm_hash_open(const char *, int, int, const HASHINFO *, int);
|
||||
DB *dbm_rec_open(const char *, int, int, const RECNOINFO *, int);
|
||||
void dbm_dbpanic(DB *dbp);
|
||||
#endif
|
||||
|
||||
PR_END_EXTERN_C
|
||||
|
|
|
|||
|
|
@ -89,13 +89,13 @@ typedef unsigned int sigset_t;
|
|||
#define SIG_UNBLOCK 2
|
||||
#define SIG_SETMASK 3
|
||||
|
||||
static int __sigtemp; /* For the use of sigprocmask */
|
||||
static int dbm_sigtemp; /* For the use of sigprocmask */
|
||||
|
||||
/* Repeated test of oset != NULL is to avoid "*0". */
|
||||
#define sigprocmask(how, set, oset) \
|
||||
((__sigtemp = \
|
||||
((dbm_sigtemp = \
|
||||
(((how) == SIG_BLOCK) ? sigblock(0) | *(set) : (((how) == SIG_UNBLOCK) ? sigblock(0) & ~(*(set)) : ((how) == SIG_SETMASK ? *(set) : sigblock(0))))), \
|
||||
((oset) ? (*(oset ? oset : set) = sigsetmask(__sigtemp)) : sigsetmask(__sigtemp)), 0)
|
||||
((oset) ? (*(oset ? oset : set) = sigsetmask(dbm_sigtemp)) : sigsetmask(dbm_sigtemp)), 0)
|
||||
#endif
|
||||
|
||||
/*
|
||||
|
|
|
|||
|
|
@ -92,16 +92,16 @@ dbopen(const char *fname, int flags, int mode, DBTYPE type, const void *openinfo
|
|||
/* we don't need btree and recno right now */
|
||||
#if 0
|
||||
case DB_BTREE:
|
||||
return (__bt_open(fname, flags & USE_OPEN_FLAGS,
|
||||
return (dbm_bt_open(fname, flags & USE_OPEN_FLAGS,
|
||||
mode, openinfo, flags & DB_FLAGS));
|
||||
case DB_RECNO:
|
||||
return (__rec_open(fname, flags & USE_OPEN_FLAGS,
|
||||
return (dbm_rec_open(fname, flags & USE_OPEN_FLAGS,
|
||||
mode, openinfo, flags & DB_FLAGS));
|
||||
#endif
|
||||
|
||||
case DB_HASH:
|
||||
return (__hash_open(fname, flags & USE_OPEN_FLAGS,
|
||||
mode, (const HASHINFO *)openinfo, flags & DB_FLAGS));
|
||||
return (dbm_hash_open(fname, flags & USE_OPEN_FLAGS,
|
||||
mode, (const HASHINFO *)openinfo, flags & DB_FLAGS));
|
||||
default:
|
||||
break;
|
||||
}
|
||||
|
|
@ -110,7 +110,7 @@ dbopen(const char *fname, int flags, int mode, DBTYPE type, const void *openinfo
|
|||
}
|
||||
|
||||
static int
|
||||
__dberr()
|
||||
dbm_dberr()
|
||||
{
|
||||
return (RET_ERROR);
|
||||
}
|
||||
|
|
@ -122,13 +122,13 @@ __dberr()
|
|||
* dbp: pointer to the DB structure.
|
||||
*/
|
||||
void
|
||||
__dbpanic(DB *dbp)
|
||||
dbm_dbpanic(DB *dbp)
|
||||
{
|
||||
/* The only thing that can succeed is a close. */
|
||||
dbp->del = (int (*)(const struct __db *, const DBT *, uint))__dberr;
|
||||
dbp->fd = (int (*)(const struct __db *))__dberr;
|
||||
dbp->get = (int (*)(const struct __db *, const DBT *, DBT *, uint))__dberr;
|
||||
dbp->put = (int (*)(const struct __db *, DBT *, const DBT *, uint))__dberr;
|
||||
dbp->seq = (int (*)(const struct __db *, DBT *, DBT *, uint))__dberr;
|
||||
dbp->sync = (int (*)(const struct __db *, uint))__dberr;
|
||||
dbp->del = (int (*)(const struct dbm_db *, const DBT *, uint))dbm_dberr;
|
||||
dbp->fd = (int (*)(const struct dbm_db *))dbm_dberr;
|
||||
dbp->get = (int (*)(const struct dbm_db *, const DBT *, DBT *, uint))dbm_dberr;
|
||||
dbp->put = (int (*)(const struct dbm_db *, DBT *, const DBT *, uint))dbm_dberr;
|
||||
dbp->seq = (int (*)(const struct dbm_db *, DBT *, DBT *, uint))dbm_dberr;
|
||||
dbp->sync = (int (*)(const struct dbm_db *, uint))dbm_dberr;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -85,7 +85,7 @@ static int collect_data(HTAB *, BUFHEAD *, int, int);
|
|||
*-1 ==> ERROR
|
||||
*/
|
||||
extern int
|
||||
__big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
||||
dbm_big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
||||
{
|
||||
register uint16 *p;
|
||||
uint key_size, n, val_size;
|
||||
|
|
@ -114,7 +114,7 @@ __big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
FREESPACE(p) = off - PAGE_META(n);
|
||||
OFFSET(p) = off;
|
||||
p[n] = PARTIAL_KEY;
|
||||
bufp = __add_ovflpage(hashp, bufp);
|
||||
bufp = dbm_add_ovflpage(hashp, bufp);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
n = p[0];
|
||||
|
|
@ -158,7 +158,7 @@ __big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
OFFSET(p) = off;
|
||||
if (val_size) {
|
||||
p[n] = FULL_KEY;
|
||||
bufp = __add_ovflpage(hashp, bufp);
|
||||
bufp = dbm_add_ovflpage(hashp, bufp);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
cp = bufp->page;
|
||||
|
|
@ -182,7 +182,7 @@ __big_insert(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
*-1 => ERROR
|
||||
*/
|
||||
extern int
|
||||
__big_delete(HTAB *hashp, BUFHEAD *bufp)
|
||||
dbm_big_delete(HTAB *hashp, BUFHEAD *bufp)
|
||||
{
|
||||
register BUFHEAD *last_bfp, *rbufp;
|
||||
uint16 *bp, pageno;
|
||||
|
|
@ -207,9 +207,9 @@ __big_delete(HTAB *hashp, BUFHEAD *bufp)
|
|||
break;
|
||||
pageno = bp[bp[0] - 1];
|
||||
rbufp->flags |= BUF_MOD;
|
||||
rbufp = __get_buf(hashp, pageno, rbufp, 0);
|
||||
rbufp = dbm_get_buf(hashp, pageno, rbufp, 0);
|
||||
if (last_bfp)
|
||||
__free_ovflpage(hashp, last_bfp);
|
||||
dbm_free_ovflpage(hashp, last_bfp);
|
||||
last_bfp = rbufp;
|
||||
if (!rbufp)
|
||||
return (-1); /* Error. */
|
||||
|
|
@ -244,9 +244,9 @@ __big_delete(HTAB *hashp, BUFHEAD *bufp)
|
|||
|
||||
bufp->flags |= BUF_MOD;
|
||||
if (rbufp)
|
||||
__free_ovflpage(hashp, rbufp);
|
||||
dbm_free_ovflpage(hashp, rbufp);
|
||||
if (last_bfp != rbufp)
|
||||
__free_ovflpage(hashp, last_bfp);
|
||||
dbm_free_ovflpage(hashp, last_bfp);
|
||||
|
||||
hashp->NKEYS--;
|
||||
return (0);
|
||||
|
|
@ -259,7 +259,7 @@ __big_delete(HTAB *hashp, BUFHEAD *bufp)
|
|||
* -3 error
|
||||
*/
|
||||
extern int
|
||||
__find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size)
|
||||
dbm_find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size)
|
||||
{
|
||||
register uint16 *bp;
|
||||
register char *p;
|
||||
|
|
@ -279,7 +279,7 @@ __find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size)
|
|||
return (-2);
|
||||
kkey += bytes;
|
||||
ksize -= bytes;
|
||||
bufp = __get_buf(hashp, bp[ndx + 2], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[ndx + 2], bufp, 0);
|
||||
if (!bufp)
|
||||
return (-3);
|
||||
p = bufp->page;
|
||||
|
|
@ -306,7 +306,7 @@ __find_bigpair(HTAB *hashp, BUFHEAD *bufp, int ndx, char *key, int size)
|
|||
* bucket)
|
||||
*/
|
||||
extern uint16
|
||||
__find_last_page(HTAB *hashp, BUFHEAD **bpp)
|
||||
dbm_find_last_page(HTAB *hashp, BUFHEAD **bpp)
|
||||
{
|
||||
BUFHEAD *bufp;
|
||||
uint16 *bp, pageno;
|
||||
|
|
@ -332,7 +332,7 @@ __find_last_page(HTAB *hashp, BUFHEAD **bpp)
|
|||
return (0);
|
||||
|
||||
pageno = bp[n - 1];
|
||||
bufp = __get_buf(hashp, pageno, bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, pageno, bufp, 0);
|
||||
if (!bufp)
|
||||
return (0); /* Need to indicate an error! */
|
||||
bp = (uint16 *)bufp->page;
|
||||
|
|
@ -350,7 +350,7 @@ __find_last_page(HTAB *hashp, BUFHEAD **bpp)
|
|||
* index (index should always be 1).
|
||||
*/
|
||||
extern int
|
||||
__big_return(
|
||||
dbm_big_return(
|
||||
HTAB *hashp,
|
||||
BUFHEAD *bufp,
|
||||
int ndx,
|
||||
|
|
@ -364,7 +364,7 @@ __big_return(
|
|||
|
||||
bp = (uint16 *)bufp->page;
|
||||
while (bp[ndx + 1] == PARTIAL_KEY) {
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
bp = (uint16 *)bufp->page;
|
||||
|
|
@ -372,7 +372,7 @@ __big_return(
|
|||
}
|
||||
|
||||
if (bp[ndx + 1] == FULL_KEY) {
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
bp = (uint16 *)bufp->page;
|
||||
|
|
@ -392,7 +392,7 @@ __big_return(
|
|||
len = bp[1] - off;
|
||||
save_p = bufp;
|
||||
save_addr = bufp->addr;
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
bp = (uint16 *)bufp->page;
|
||||
|
|
@ -409,8 +409,8 @@ __big_return(
|
|||
hashp->cbucket++;
|
||||
hashp->cndx = 1;
|
||||
} else {
|
||||
hashp->cpage = __get_buf(hashp,
|
||||
bp[bp[0] - 1], bufp, 0);
|
||||
hashp->cpage = dbm_get_buf(hashp,
|
||||
bp[bp[0] - 1], bufp, 0);
|
||||
if (!hashp->cpage)
|
||||
return (-1);
|
||||
hashp->cndx = 1;
|
||||
|
|
@ -470,7 +470,7 @@ collect_data(
|
|||
save_bufp->flags |= BUF_PIN;
|
||||
|
||||
/* read the length of the buffer */
|
||||
for (totlen = len; bufp; bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0)) {
|
||||
for (totlen = len; bufp; bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0)) {
|
||||
bp = (uint16 *)bufp->page;
|
||||
mylen = hashp->BSIZE - bp[1];
|
||||
|
||||
|
|
@ -502,7 +502,7 @@ collect_data(
|
|||
|
||||
/* copy the buffers back into temp buf */
|
||||
for (bufp = save_bufp; bufp;
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0)) {
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0)) {
|
||||
bp = (uint16 *)bufp->page;
|
||||
mylen = hashp->BSIZE - bp[1];
|
||||
memmove(&hashp->tmp_buf[len], (bufp->page) + bp[1], (size_t)mylen);
|
||||
|
|
@ -522,7 +522,7 @@ collect_data(
|
|||
hashp->cpage = NULL;
|
||||
hashp->cbucket++;
|
||||
} else {
|
||||
hashp->cpage = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
hashp->cpage = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!hashp->cpage)
|
||||
return (-1);
|
||||
else if (!((uint16 *)hashp->cpage->page)[0]) {
|
||||
|
|
@ -538,7 +538,7 @@ collect_data(
|
|||
* Fill in the key and data for this big pair.
|
||||
*/
|
||||
extern int
|
||||
__big_keydata(
|
||||
dbm_big_keydata(
|
||||
HTAB *hashp,
|
||||
BUFHEAD *bufp,
|
||||
DBT *key, DBT *val,
|
||||
|
|
@ -579,10 +579,10 @@ collect_key(
|
|||
free(hashp->tmp_key);
|
||||
if ((hashp->tmp_key = (char *)malloc((size_t)totlen)) == NULL)
|
||||
return (-1);
|
||||
if (__big_return(hashp, bufp, 1, val, set))
|
||||
if (dbm_big_return(hashp, bufp, 1, val, set))
|
||||
return (-1);
|
||||
} else {
|
||||
xbp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
xbp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!xbp || ((totlen =
|
||||
collect_key(hashp, xbp, totlen, val, set)) < 1))
|
||||
return (-1);
|
||||
|
|
@ -601,7 +601,7 @@ collect_key(
|
|||
* -1 => error
|
||||
*/
|
||||
extern int
|
||||
__big_split(
|
||||
dbm_big_split(
|
||||
HTAB *hashp,
|
||||
BUFHEAD *op, /* Pointer to where to put keys that go in old bucket */
|
||||
BUFHEAD *np, /* Pointer to new bucket page */
|
||||
|
|
@ -621,13 +621,13 @@ __big_split(
|
|||
bp = big_keyp;
|
||||
|
||||
/* Now figure out where the big key/data goes */
|
||||
if (__big_keydata(hashp, big_keyp, &key, &val, 0))
|
||||
if (dbm_big_keydata(hashp, big_keyp, &key, &val, 0))
|
||||
return (-1);
|
||||
change = (__call_hash(hashp, (char *)key.data, key.size) != obucket);
|
||||
change = (dbm_call_hash(hashp, (char *)key.data, key.size) != obucket);
|
||||
|
||||
if ((ret->next_addr = __find_last_page(hashp, &big_keyp))) {
|
||||
if ((ret->next_addr = dbm_find_last_page(hashp, &big_keyp))) {
|
||||
if (!(ret->nextp =
|
||||
__get_buf(hashp, ret->next_addr, big_keyp, 0)))
|
||||
dbm_get_buf(hashp, ret->next_addr, big_keyp, 0)))
|
||||
return (-1);
|
||||
;
|
||||
} else
|
||||
|
|
@ -692,7 +692,7 @@ __big_split(
|
|||
tp[0] -= 2;
|
||||
FREESPACE(tp) = free_space + OVFLSIZE;
|
||||
OFFSET(tp) = off;
|
||||
tmpp = __add_ovflpage(hashp, big_keyp);
|
||||
tmpp = dbm_add_ovflpage(hashp, big_keyp);
|
||||
if (!tmpp)
|
||||
return (-1);
|
||||
tp[4] = n;
|
||||
|
|
|
|||
|
|
@ -52,7 +52,7 @@ static uint32 hash3(const void *, size_t);
|
|||
static uint32 hash4(const void *, size_t);
|
||||
|
||||
/* Global default hash function */
|
||||
uint32 (*__default_hash)(const void *, size_t) = hash4;
|
||||
uint32 (*dbm_default_hash)(const void *, size_t) = hash4;
|
||||
|
||||
/*
|
||||
* HASH FUNCTIONS
|
||||
|
|
|
|||
|
|
@ -43,7 +43,7 @@ static char sccsid[] = "@(#)hash_log2.c 8.2 (Berkeley) 5/31/94";
|
|||
#include "mcom_db.h"
|
||||
|
||||
uint32
|
||||
__log2(uint32 num)
|
||||
dbm_log2(uint32 num)
|
||||
{
|
||||
register uint32 i, limit;
|
||||
|
||||
|
|
|
|||
|
|
@ -204,7 +204,7 @@ putpair(char *p, const DBT *key, DBT *val)
|
|||
* -1 error
|
||||
*/
|
||||
extern int
|
||||
__delpair(HTAB *hashp, BUFHEAD *bufp, int ndx)
|
||||
dbm_delpair(HTAB *hashp, BUFHEAD *bufp, int ndx)
|
||||
{
|
||||
register uint16 *bp, newoff;
|
||||
register int n;
|
||||
|
|
@ -214,7 +214,7 @@ __delpair(HTAB *hashp, BUFHEAD *bufp, int ndx)
|
|||
n = bp[0];
|
||||
|
||||
if (bp[ndx + 1] < REAL_KEY)
|
||||
return (__big_delete(hashp, bufp));
|
||||
return (dbm_big_delete(hashp, bufp));
|
||||
if (ndx != 1)
|
||||
newoff = bp[ndx - 1];
|
||||
else
|
||||
|
|
@ -277,7 +277,7 @@ __delpair(HTAB *hashp, BUFHEAD *bufp, int ndx)
|
|||
* -1 ==> Error
|
||||
*/
|
||||
extern int
|
||||
__split_page(HTAB *hashp, uint32 obucket, uint32 nbucket)
|
||||
dbm_split_page(HTAB *hashp, uint32 obucket, uint32 nbucket)
|
||||
{
|
||||
register BUFHEAD *new_bufp, *old_bufp;
|
||||
register uint16 *ino;
|
||||
|
|
@ -292,10 +292,10 @@ __split_page(HTAB *hashp, uint32 obucket, uint32 nbucket)
|
|||
|
||||
copyto = (uint16)hashp->BSIZE;
|
||||
off = (uint16)hashp->BSIZE;
|
||||
old_bufp = __get_buf(hashp, obucket, NULL, 0);
|
||||
old_bufp = dbm_get_buf(hashp, obucket, NULL, 0);
|
||||
if (old_bufp == NULL)
|
||||
return (-1);
|
||||
new_bufp = __get_buf(hashp, nbucket, NULL, 0);
|
||||
new_bufp = dbm_get_buf(hashp, nbucket, NULL, 0);
|
||||
if (new_bufp == NULL)
|
||||
return (-1);
|
||||
|
||||
|
|
@ -331,7 +331,7 @@ __split_page(HTAB *hashp, uint32 obucket, uint32 nbucket)
|
|||
assert(((int)key.size) > -1);
|
||||
#endif
|
||||
|
||||
if (__call_hash(hashp, (char *)key.data, key.size) == obucket) {
|
||||
if (dbm_call_hash(hashp, (char *)key.data, key.size) == obucket) {
|
||||
/* Don't switch page */
|
||||
diff = copyto - off;
|
||||
if (diff) {
|
||||
|
|
@ -443,8 +443,8 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
return DATABASE_CORRUPTED_ERROR;
|
||||
|
||||
if (ino[2] < REAL_KEY && ino[2] != OVFLPAGE) {
|
||||
if ((status = __big_split(hashp, old_bufp,
|
||||
new_bufp, bufp, bufp->addr, obucket, &ret)))
|
||||
if ((status = dbm_big_split(hashp, old_bufp,
|
||||
new_bufp, bufp, bufp->addr, obucket, &ret)))
|
||||
return (status);
|
||||
old_bufp = ret.oldp;
|
||||
if (!old_bufp)
|
||||
|
|
@ -477,7 +477,7 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
scopyto - sizeof(uint16) * (ino[0] + 3);
|
||||
OFFSET(ino) = scopyto;
|
||||
|
||||
bufp = __get_buf(hashp, ov_addr, bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, ov_addr, bufp, 0);
|
||||
if (!bufp)
|
||||
return (-1);
|
||||
|
||||
|
|
@ -487,7 +487,7 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
moved = 0;
|
||||
|
||||
if (last_bfp)
|
||||
__free_ovflpage(hashp, last_bfp);
|
||||
dbm_free_ovflpage(hashp, last_bfp);
|
||||
last_bfp = bufp;
|
||||
}
|
||||
/* Move regular sized pairs of there are any */
|
||||
|
|
@ -506,13 +506,13 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
val.size = ino[n] - ino[n + 1];
|
||||
off = ino[n + 1];
|
||||
|
||||
if (__call_hash(hashp, (char *)key.data, key.size) == obucket) {
|
||||
if (dbm_call_hash(hashp, (char *)key.data, key.size) == obucket) {
|
||||
/* Keep on old page */
|
||||
if (PAIRFITS(op, (&key), (&val)))
|
||||
putpair((char *)op, &key, &val);
|
||||
else {
|
||||
old_bufp =
|
||||
__add_ovflpage(hashp, old_bufp);
|
||||
dbm_add_ovflpage(hashp, old_bufp);
|
||||
if (!old_bufp)
|
||||
return (-1);
|
||||
op = (uint16 *)old_bufp->page;
|
||||
|
|
@ -525,7 +525,7 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
putpair((char *)np, &key, &val);
|
||||
else {
|
||||
new_bufp =
|
||||
__add_ovflpage(hashp, new_bufp);
|
||||
dbm_add_ovflpage(hashp, new_bufp);
|
||||
if (!new_bufp)
|
||||
return (-1);
|
||||
np = (uint16 *)new_bufp->page;
|
||||
|
|
@ -536,7 +536,7 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
}
|
||||
}
|
||||
if (last_bfp)
|
||||
__free_ovflpage(hashp, last_bfp);
|
||||
dbm_free_ovflpage(hashp, last_bfp);
|
||||
return (0);
|
||||
}
|
||||
|
||||
|
|
@ -548,7 +548,7 @@ ugly_split(HTAB *hashp, uint32 obucket, BUFHEAD *old_bufp,
|
|||
* 1 ==> failure
|
||||
*/
|
||||
extern int
|
||||
__addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
||||
dbm_addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
||||
{
|
||||
register uint16 *bp, *sop;
|
||||
int do_expand;
|
||||
|
|
@ -562,7 +562,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
and we need to add another page */
|
||||
break;
|
||||
else if (bp[2] < REAL_KEY && bp[bp[0]] != OVFLPAGE) {
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!bufp) {
|
||||
#ifdef DEBUG
|
||||
assert(0);
|
||||
|
|
@ -585,7 +585,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
return (0);
|
||||
}
|
||||
} else {
|
||||
bufp = __get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, bp[bp[0] - 1], bufp, 0);
|
||||
if (!bufp) {
|
||||
#ifdef DEBUG
|
||||
assert(0);
|
||||
|
|
@ -599,7 +599,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
putpair(bufp->page, key, (DBT *)val);
|
||||
else {
|
||||
do_expand = 1;
|
||||
bufp = __add_ovflpage(hashp, bufp);
|
||||
bufp = dbm_add_ovflpage(hashp, bufp);
|
||||
if (!bufp) {
|
||||
#ifdef DEBUG
|
||||
assert(0);
|
||||
|
|
@ -610,7 +610,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
|
||||
if (PAIRFITS(sop, key, val))
|
||||
putpair((char *)sop, key, (DBT *)val);
|
||||
else if (__big_insert(hashp, bufp, key, val)) {
|
||||
else if (dbm_big_insert(hashp, bufp, key, val)) {
|
||||
#ifdef DEBUG
|
||||
assert(0);
|
||||
#endif
|
||||
|
|
@ -625,7 +625,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
hashp->NKEYS++;
|
||||
if (do_expand ||
|
||||
(hashp->NKEYS / (hashp->MAX_BUCKET + 1) > hashp->FFACTOR))
|
||||
return (__expand_table(hashp));
|
||||
return (dbm_expand_table(hashp));
|
||||
return (0);
|
||||
}
|
||||
|
||||
|
|
@ -636,7 +636,7 @@ __addel(HTAB *hashp, BUFHEAD *bufp, const DBT *key, const DBT *val)
|
|||
* NULL on error
|
||||
*/
|
||||
extern BUFHEAD *
|
||||
__add_ovflpage(HTAB *hashp, BUFHEAD *bufp)
|
||||
dbm_add_ovflpage(HTAB *hashp, BUFHEAD *bufp)
|
||||
{
|
||||
register uint16 *sp;
|
||||
uint16 ndx, ovfl_num;
|
||||
|
|
@ -657,7 +657,7 @@ __add_ovflpage(HTAB *hashp, BUFHEAD *bufp)
|
|||
tmp1 = bufp->addr;
|
||||
tmp2 = bufp->ovfl ? bufp->ovfl->addr : 0;
|
||||
#endif
|
||||
if (!ovfl_num || !(bufp->ovfl = __get_buf(hashp, ovfl_num, bufp, 1)))
|
||||
if (!ovfl_num || !(bufp->ovfl = dbm_get_buf(hashp, ovfl_num, bufp, 1)))
|
||||
return (NULL);
|
||||
bufp->ovfl->flags |= BUF_MOD;
|
||||
#ifdef DEBUG1
|
||||
|
|
@ -687,12 +687,12 @@ __add_ovflpage(HTAB *hashp, BUFHEAD *bufp)
|
|||
* -1 indicates FAILURE
|
||||
*/
|
||||
extern int
|
||||
__get_page(HTAB *hashp,
|
||||
char *p,
|
||||
uint32 bucket,
|
||||
int is_bucket,
|
||||
int is_disk,
|
||||
int is_bitmap)
|
||||
dbm_get_page(HTAB *hashp,
|
||||
char *p,
|
||||
uint32 bucket,
|
||||
int is_bucket,
|
||||
int is_disk,
|
||||
int is_bitmap)
|
||||
{
|
||||
register int fd, page;
|
||||
size_t size;
|
||||
|
|
@ -805,7 +805,7 @@ __get_page(HTAB *hashp,
|
|||
* -1 ==>failure
|
||||
*/
|
||||
extern int
|
||||
__put_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_bitmap)
|
||||
dbm_put_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_bitmap)
|
||||
{
|
||||
register int fd, page;
|
||||
size_t size;
|
||||
|
|
@ -895,7 +895,7 @@ __put_page(HTAB *hashp, char *p, uint32 bucket, int is_bucket, int is_bitmap)
|
|||
* once they are read in.
|
||||
*/
|
||||
extern int
|
||||
__ibitmap(HTAB *hashp, int pnum, int nbits, int ndx)
|
||||
dbm_ibitmap(HTAB *hashp, int pnum, int nbits, int ndx)
|
||||
{
|
||||
uint32 *ip;
|
||||
size_t clearbytes, clearints;
|
||||
|
|
@ -1011,8 +1011,8 @@ overflow_page(HTAB *hashp)
|
|||
* don't have to if we tell init_bitmap not to leave it clear
|
||||
* in the first place.
|
||||
*/
|
||||
if (__ibitmap(hashp,
|
||||
(int)OADDR_OF(splitnum, offset), 1, free_page))
|
||||
if (dbm_ibitmap(hashp,
|
||||
(int)OADDR_OF(splitnum, offset), 1, free_page))
|
||||
return (0);
|
||||
hashp->SPARES[splitnum]++;
|
||||
#ifdef DEBUG2
|
||||
|
|
@ -1084,7 +1084,7 @@ found:
|
|||
* Mark this overflow page as free.
|
||||
*/
|
||||
extern void
|
||||
__free_ovflpage(HTAB *hashp, BUFHEAD *obufp)
|
||||
dbm_free_ovflpage(HTAB *hashp, BUFHEAD *obufp)
|
||||
{
|
||||
uint16 addr;
|
||||
uint32 *freep;
|
||||
|
|
@ -1125,7 +1125,7 @@ __free_ovflpage(HTAB *hashp, BUFHEAD *obufp)
|
|||
(void)fprintf(stderr, "FREE_OVFLPAGE: ADDR: %d BIT: %d PAGE %d\n",
|
||||
obufp->addr, free_bit, free_page);
|
||||
#endif
|
||||
__reclaim_buf(hashp, obufp);
|
||||
dbm_reclaim_buf(hashp, obufp);
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -1236,8 +1236,8 @@ fetch_bitmap(HTAB *hashp, uint32 ndx)
|
|||
return (NULL);
|
||||
if ((hashp->mapp[ndx] = (uint32 *)malloc((size_t)hashp->BSIZE)) == NULL)
|
||||
return (NULL);
|
||||
if (__get_page(hashp,
|
||||
(char *)hashp->mapp[ndx], hashp->BITMAPS[ndx], 0, 1, 1)) {
|
||||
if (dbm_get_page(hashp,
|
||||
(char *)hashp->mapp[ndx], hashp->BITMAPS[ndx], 0, 1, 1)) {
|
||||
free(hashp->mapp[ndx]);
|
||||
hashp->mapp[ndx] = NULL; /* NEW: 9-11-95 */
|
||||
return (NULL);
|
||||
|
|
@ -1253,13 +1253,13 @@ print_chain(int addr)
|
|||
short *bp, oaddr;
|
||||
|
||||
(void)fprintf(stderr, "%d ", addr);
|
||||
bufp = __get_buf(hashp, addr, NULL, 0);
|
||||
bufp = dbm_get_buf(hashp, addr, NULL, 0);
|
||||
bp = (short *)bufp->page;
|
||||
while (bp[0] && ((bp[bp[0]] == OVFLPAGE) ||
|
||||
((bp[0] > 2) && bp[2] < REAL_KEY))) {
|
||||
oaddr = bp[bp[0] - 1];
|
||||
(void)fprintf(stderr, "%d ", (int)oaddr);
|
||||
bufp = __get_buf(hashp, (int)oaddr, bufp, 0);
|
||||
bufp = dbm_get_buf(hashp, (int)oaddr, bufp, 0);
|
||||
bp = (short *)bufp->page;
|
||||
}
|
||||
(void)fprintf(stderr, "\n");
|
||||
|
|
|
|||
|
|
@ -118,7 +118,7 @@ int hash_accesses, hash_collisions, hash_expansions, hash_overflows;
|
|||
* This closes the file, flushing buffers as appropriate.
|
||||
*/
|
||||
static void
|
||||
__remove_database(DB *dbp)
|
||||
dbm_remove_database(DB *dbp)
|
||||
{
|
||||
HTAB *hashp = (HTAB *)dbp->internal;
|
||||
|
||||
|
|
@ -134,7 +134,7 @@ __remove_database(DB *dbp)
|
|||
/* OPEN/CLOSE */
|
||||
|
||||
extern DB *
|
||||
__hash_open(const char *file, int flags, int mode, const HASHINFO *info, int dflags)
|
||||
dbm_hash_open(const char *file, int flags, int mode, const HASHINFO *info, int dflags)
|
||||
{
|
||||
HTAB *hashp = NULL;
|
||||
struct stat statbuf;
|
||||
|
|
@ -199,7 +199,7 @@ __hash_open(const char *file, int flags, int mode, const HASHINFO *info, int dfl
|
|||
if (info && info->hash)
|
||||
hashp->hash = info->hash;
|
||||
else
|
||||
hashp->hash = __default_hash;
|
||||
hashp->hash = dbm_default_hash;
|
||||
|
||||
hdrsize = read(hashp->fp, (char *)&hashp->hdr, sizeof(HASHHDR));
|
||||
if (hdrsize == -1)
|
||||
|
|
@ -243,9 +243,9 @@ __hash_open(const char *file, int flags, int mode, const HASHINFO *info, int dfl
|
|||
|
||||
/* Initialize Buffer Manager */
|
||||
if (info && info->cachesize)
|
||||
__buf_init(hashp, (int32)info->cachesize);
|
||||
dbm_buf_init(hashp, (int32)info->cachesize);
|
||||
else
|
||||
__buf_init(hashp, DEF_BUFSIZE);
|
||||
dbm_buf_init(hashp, DEF_BUFSIZE);
|
||||
|
||||
hashp->new_file = new_table;
|
||||
#ifdef macintosh
|
||||
|
|
@ -331,7 +331,7 @@ init_hash(HTAB *hashp, const char *file, HASHINFO *info)
|
|||
hashp->SSHIFT = DEF_SEGSIZE_SHIFT;
|
||||
hashp->DSIZE = DEF_DIRSIZE;
|
||||
hashp->FFACTOR = DEF_FFACTOR;
|
||||
hashp->hash = __default_hash;
|
||||
hashp->hash = dbm_default_hash;
|
||||
memset(hashp->SPARES, 0, sizeof(hashp->SPARES));
|
||||
memset(hashp->BITMAPS, 0, sizeof(hashp->BITMAPS));
|
||||
|
||||
|
|
@ -353,13 +353,13 @@ init_hash(HTAB *hashp, const char *file, HASHINFO *info)
|
|||
if (hashp->BSIZE > MAX_BSIZE)
|
||||
hashp->BSIZE = MAX_BSIZE;
|
||||
#endif
|
||||
hashp->BSHIFT = __log2((uint32)hashp->BSIZE);
|
||||
hashp->BSHIFT = dbm_log2((uint32)hashp->BSIZE);
|
||||
}
|
||||
|
||||
if (info) {
|
||||
if (info->bsize) {
|
||||
/* Round pagesize up to power of 2 */
|
||||
hashp->BSHIFT = __log2(info->bsize);
|
||||
hashp->BSHIFT = dbm_log2(info->bsize);
|
||||
hashp->BSIZE = 1 << hashp->BSHIFT;
|
||||
if (hashp->BSIZE > MAX_BSIZE) {
|
||||
errno = EINVAL;
|
||||
|
|
@ -406,7 +406,7 @@ init_htab(HTAB *hashp, int nelem)
|
|||
*/
|
||||
nelem = (nelem - 1) / hashp->FFACTOR + 1;
|
||||
|
||||
l2 = __log2((uint32)PR_MAX(nelem, 2));
|
||||
l2 = dbm_log2((uint32)PR_MAX(nelem, 2));
|
||||
nbuckets = 1 << l2;
|
||||
|
||||
hashp->SPARES[l2] = l2 + 1;
|
||||
|
|
@ -415,7 +415,7 @@ init_htab(HTAB *hashp, int nelem)
|
|||
hashp->LAST_FREED = 2;
|
||||
|
||||
/* First bitmap page is at: splitpoint l2 page offset 1 */
|
||||
if (__ibitmap(hashp, (int)OADDR_OF(l2, 1), l2 + 1, 0))
|
||||
if (dbm_ibitmap(hashp, (int)OADDR_OF(l2, 1), l2 + 1, 0))
|
||||
return (-1);
|
||||
|
||||
hashp->MAX_BUCKET = hashp->LOW_MASK = nbuckets - 1;
|
||||
|
|
@ -425,7 +425,7 @@ init_htab(HTAB *hashp, int nelem)
|
|||
1;
|
||||
|
||||
nsegs = (nbuckets - 1) / hashp->SGSIZE + 1;
|
||||
nsegs = 1 << __log2((uint32)nsegs);
|
||||
nsegs = 1 << dbm_log2((uint32)nsegs);
|
||||
|
||||
if (nsegs > hashp->DSIZE)
|
||||
hashp->DSIZE = nsegs;
|
||||
|
|
@ -463,7 +463,7 @@ hdestroy(HTAB *hashp)
|
|||
* Call on buffer manager to free buffers, and if required,
|
||||
* write them to disk.
|
||||
*/
|
||||
if (__buf_free(hashp, 1, hashp->save_file))
|
||||
if (dbm_buf_free(hashp, 1, hashp->save_file))
|
||||
save_errno = errno;
|
||||
if (hashp->dir) {
|
||||
free(*hashp->dir); /* Free initial segments */
|
||||
|
|
@ -585,7 +585,7 @@ hash_sync(const DB *dbp, uint flags)
|
|||
|
||||
if (!hashp->save_file)
|
||||
return (0);
|
||||
if (__buf_free(hashp, 0, 1) || flush_meta(hashp))
|
||||
if (dbm_buf_free(hashp, 0, 1) || flush_meta(hashp))
|
||||
return (DBM_ERROR);
|
||||
#if defined(_WIN32) || defined(_WINDOWS)
|
||||
if (hashp->updateEOF && hashp->filename && !hashp->is_temp) {
|
||||
|
|
@ -635,8 +635,8 @@ flush_meta(HTAB *hashp)
|
|||
}
|
||||
for (i = 0; i < NCACHED; i++)
|
||||
if (hashp->mapp[i])
|
||||
if (__put_page(hashp, (char *)hashp->mapp[i],
|
||||
hashp->BITMAPS[i], 0, 1))
|
||||
if (dbm_put_page(hashp, (char *)hashp->mapp[i],
|
||||
hashp->BITMAPS[i], 0, 1))
|
||||
return (-1);
|
||||
return (0);
|
||||
}
|
||||
|
|
@ -675,7 +675,7 @@ hash_get(
|
|||
#if defined(unix) && defined(DEBUG)
|
||||
printf("\n\nDBM Database has been corrupted, tell Lou...\n\n");
|
||||
#endif
|
||||
__remove_database((DB *)dbp);
|
||||
dbm_remove_database((DB *)dbp);
|
||||
}
|
||||
|
||||
return (rv);
|
||||
|
|
@ -711,7 +711,7 @@ hash_put(
|
|||
#if defined(unix) && defined(DEBUG)
|
||||
printf("\n\nDBM Database has been corrupted, tell Lou...\n\n");
|
||||
#endif
|
||||
__remove_database((DB *)dbp);
|
||||
dbm_remove_database((DB *)dbp);
|
||||
}
|
||||
|
||||
return (rv);
|
||||
|
|
@ -744,7 +744,7 @@ hash_delete(
|
|||
#if defined(unix) && defined(DEBUG)
|
||||
printf("\n\nDBM Database has been corrupted, tell Lou...\n\n");
|
||||
#endif
|
||||
__remove_database((DB *)dbp);
|
||||
dbm_remove_database((DB *)dbp);
|
||||
}
|
||||
|
||||
return (rv);
|
||||
|
|
@ -777,7 +777,7 @@ hash_access(
|
|||
off = hashp->BSIZE;
|
||||
size = key->size;
|
||||
kp = (char *)key->data;
|
||||
rbufp = __get_buf(hashp, __call_hash(hashp, kp, size), NULL, 0);
|
||||
rbufp = dbm_get_buf(hashp, dbm_call_hash(hashp, kp, size), NULL, 0);
|
||||
if (!rbufp)
|
||||
return (DATABASE_CORRUPTED_ERROR);
|
||||
save_bufp = rbufp;
|
||||
|
|
@ -805,7 +805,7 @@ hash_access(
|
|||
|
||||
last_overflow_page_no = *bp;
|
||||
|
||||
rbufp = __get_buf(hashp, *bp, rbufp, 0);
|
||||
rbufp = dbm_get_buf(hashp, *bp, rbufp, 0);
|
||||
if (!rbufp) {
|
||||
save_bufp->flags &= ~BUF_PIN;
|
||||
return (DBM_ERROR);
|
||||
|
|
@ -822,17 +822,17 @@ hash_access(
|
|||
off = hashp->BSIZE;
|
||||
} else if (bp[1] < REAL_KEY) {
|
||||
if ((ndx =
|
||||
__find_bigpair(hashp, rbufp, ndx, kp, (int)size)) > 0)
|
||||
dbm_find_bigpair(hashp, rbufp, ndx, kp, (int)size)) > 0)
|
||||
goto found;
|
||||
if (ndx == -2) {
|
||||
bufp = rbufp;
|
||||
if (!(pageno =
|
||||
__find_last_page(hashp, &bufp))) {
|
||||
dbm_find_last_page(hashp, &bufp))) {
|
||||
ndx = 0;
|
||||
rbufp = bufp;
|
||||
break; /* FOR */
|
||||
}
|
||||
rbufp = __get_buf(hashp, pageno, bufp, 0);
|
||||
rbufp = dbm_get_buf(hashp, pageno, bufp, 0);
|
||||
if (!rbufp) {
|
||||
save_bufp->flags &= ~BUF_PIN;
|
||||
return (DBM_ERROR);
|
||||
|
|
@ -853,7 +853,7 @@ hash_access(
|
|||
switch (action) {
|
||||
case HASH_PUT:
|
||||
case HASH_PUTNEW:
|
||||
if (__addel(hashp, rbufp, key, val)) {
|
||||
if (dbm_addel(hashp, rbufp, key, val)) {
|
||||
save_bufp->flags &= ~BUF_PIN;
|
||||
return (DBM_ERROR);
|
||||
} else {
|
||||
|
|
@ -875,7 +875,7 @@ found:
|
|||
case HASH_GET:
|
||||
bp = (uint16 *)rbufp->page;
|
||||
if (bp[ndx + 1] < REAL_KEY) {
|
||||
if (__big_return(hashp, rbufp, ndx, val, 0))
|
||||
if (dbm_big_return(hashp, rbufp, ndx, val, 0))
|
||||
return (DBM_ERROR);
|
||||
} else {
|
||||
val->data = (uint8 *)rbufp->page + (int)bp[ndx + 1];
|
||||
|
|
@ -883,14 +883,14 @@ found:
|
|||
}
|
||||
break;
|
||||
case HASH_PUT:
|
||||
if ((__delpair(hashp, rbufp, ndx)) ||
|
||||
(__addel(hashp, rbufp, key, val))) {
|
||||
if ((dbm_delpair(hashp, rbufp, ndx)) ||
|
||||
(dbm_addel(hashp, rbufp, key, val))) {
|
||||
save_bufp->flags &= ~BUF_PIN;
|
||||
return (DBM_ERROR);
|
||||
}
|
||||
break;
|
||||
case HASH_DELETE:
|
||||
if (__delpair(hashp, rbufp, ndx))
|
||||
if (dbm_delpair(hashp, rbufp, ndx))
|
||||
return (DBM_ERROR);
|
||||
break;
|
||||
default:
|
||||
|
|
@ -933,7 +933,7 @@ hash_seq(
|
|||
for (bucket = hashp->cbucket;
|
||||
bucket <= (uint32)hashp->MAX_BUCKET;
|
||||
bucket++, hashp->cndx = 1) {
|
||||
bufp = __get_buf(hashp, bucket, NULL, 0);
|
||||
bufp = dbm_get_buf(hashp, bucket, NULL, 0);
|
||||
if (!bufp)
|
||||
return (DBM_ERROR);
|
||||
hashp->cpage = bufp;
|
||||
|
|
@ -955,7 +955,7 @@ hash_seq(
|
|||
#endif
|
||||
while (bp[hashp->cndx + 1] == OVFLPAGE) {
|
||||
bufp = hashp->cpage =
|
||||
__get_buf(hashp, bp[hashp->cndx], bufp, 0);
|
||||
dbm_get_buf(hashp, bp[hashp->cndx], bufp, 0);
|
||||
if (!bufp)
|
||||
return (DBM_ERROR);
|
||||
bp = (uint16 *)(bufp->page);
|
||||
|
|
@ -968,7 +968,7 @@ hash_seq(
|
|||
}
|
||||
ndx = hashp->cndx;
|
||||
if (bp[ndx + 1] < REAL_KEY) {
|
||||
if (__big_keydata(hashp, bufp, key, data, 1))
|
||||
if (dbm_big_keydata(hashp, bufp, key, data, 1))
|
||||
return (DBM_ERROR);
|
||||
} else {
|
||||
key->data = (uint8 *)hashp->cpage->page + bp[ndx];
|
||||
|
|
@ -994,7 +994,7 @@ hash_seq(
|
|||
* -1 ==> Error
|
||||
*/
|
||||
extern int
|
||||
__expand_table(HTAB *hashp)
|
||||
dbm_expand_table(HTAB *hashp)
|
||||
{
|
||||
uint32 old_bucket, new_bucket;
|
||||
int new_segnum, spare_ndx;
|
||||
|
|
@ -1029,7 +1029,7 @@ __expand_table(HTAB *hashp)
|
|||
* * increases), we need to copy the current contents of the spare
|
||||
* split bucket to the next bucket.
|
||||
*/
|
||||
spare_ndx = __log2((uint32)(hashp->MAX_BUCKET + 1));
|
||||
spare_ndx = dbm_log2((uint32)(hashp->MAX_BUCKET + 1));
|
||||
if (spare_ndx > hashp->OVFL_POINT) {
|
||||
hashp->SPARES[spare_ndx] = hashp->SPARES[hashp->OVFL_POINT];
|
||||
hashp->OVFL_POINT = spare_ndx;
|
||||
|
|
@ -1041,7 +1041,7 @@ __expand_table(HTAB *hashp)
|
|||
hashp->HIGH_MASK = new_bucket | hashp->LOW_MASK;
|
||||
}
|
||||
/* Relocate records to the new bucket */
|
||||
return (__split_page(hashp, old_bucket, new_bucket));
|
||||
return (dbm_split_page(hashp, old_bucket, new_bucket));
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -1065,7 +1065,7 @@ hash_realloc(
|
|||
}
|
||||
|
||||
extern uint32
|
||||
__call_hash(HTAB *hashp, char *k, size_t len)
|
||||
dbm_call_hash(HTAB *hashp, char *k, size_t len)
|
||||
{
|
||||
uint32 n, bucket;
|
||||
|
||||
|
|
|
|||
|
|
@ -104,7 +104,7 @@ static BUFHEAD *newbuf(HTAB *, uint32, BUFHEAD *);
|
|||
* address you are seeking.
|
||||
*/
|
||||
extern BUFHEAD *
|
||||
__get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage)
|
||||
dbm_get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage)
|
||||
/* If prev_bp set, indicates a new overflow page. */
|
||||
{
|
||||
register BUFHEAD *bp;
|
||||
|
|
@ -124,7 +124,7 @@ __get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage)
|
|||
/* Grab buffer out of directory */
|
||||
segment_ndx = addr & (hashp->SGSIZE - 1);
|
||||
|
||||
/* valid segment ensured by __call_hash() */
|
||||
/* valid segment ensured by dbm_call_hash() */
|
||||
segp = hashp->dir[addr >> hashp->SSHIFT];
|
||||
#ifdef DEBUG
|
||||
assert(segp != NULL);
|
||||
|
|
@ -140,7 +140,7 @@ __get_buf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp, int newpage)
|
|||
bp = newbuf(hashp, addr, prev_bp);
|
||||
if (!bp)
|
||||
return (NULL);
|
||||
if (__get_page(hashp, bp->page, addr, !prev_bp, is_disk, 0)) {
|
||||
if (dbm_get_page(hashp, bp->page, addr, !prev_bp, is_disk, 0)) {
|
||||
/* free bp and its page */
|
||||
if (prev_bp) {
|
||||
/* if prev_bp is set then the new page that
|
||||
|
|
@ -242,8 +242,8 @@ newbuf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp)
|
|||
}
|
||||
oaddr = shortp[shortp[0] - 1];
|
||||
}
|
||||
if ((bp->flags & BUF_MOD) && __put_page(hashp, bp->page,
|
||||
bp->addr, (int)IS_BUCKET(bp->flags), 0))
|
||||
if ((bp->flags & BUF_MOD) && dbm_put_page(hashp, bp->page,
|
||||
bp->addr, (int)IS_BUCKET(bp->flags), 0))
|
||||
return (NULL);
|
||||
/*
|
||||
* Update the pointer to this page (i.e. invalidate it).
|
||||
|
|
@ -298,8 +298,8 @@ newbuf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp)
|
|||
/* set before __put_page */
|
||||
oaddr = shortp[shortp[0] - 1];
|
||||
}
|
||||
if ((xbp->flags & BUF_MOD) && __put_page(hashp,
|
||||
xbp->page, xbp->addr, 0, 0))
|
||||
if ((xbp->flags & BUF_MOD) && dbm_put_page(hashp,
|
||||
xbp->page, xbp->addr, 0, 0))
|
||||
return (NULL);
|
||||
xbp->addr = 0;
|
||||
xbp->flags = 0;
|
||||
|
|
@ -335,7 +335,7 @@ newbuf(HTAB *hashp, uint32 addr, BUFHEAD *prev_bp)
|
|||
}
|
||||
|
||||
extern void
|
||||
__buf_init(HTAB *hashp, int32 nbytes)
|
||||
dbm_buf_init(HTAB *hashp, int32 nbytes)
|
||||
{
|
||||
BUFHEAD *bfp;
|
||||
int npages;
|
||||
|
|
@ -358,7 +358,7 @@ __buf_init(HTAB *hashp, int32 nbytes)
|
|||
}
|
||||
|
||||
extern int
|
||||
__buf_free(HTAB *hashp, int do_free, int to_disk)
|
||||
dbm_buf_free(HTAB *hashp, int do_free, int to_disk)
|
||||
{
|
||||
BUFHEAD *bp;
|
||||
int status = -1;
|
||||
|
|
@ -370,8 +370,8 @@ __buf_free(HTAB *hashp, int do_free, int to_disk)
|
|||
/* Check that the buffer is valid */
|
||||
if (bp->addr || IS_BUCKET(bp->flags)) {
|
||||
if (to_disk && (bp->flags & BUF_MOD) &&
|
||||
(status = __put_page(hashp, bp->page,
|
||||
bp->addr, IS_BUCKET(bp->flags), 0))) {
|
||||
(status = dbm_put_page(hashp, bp->page,
|
||||
bp->addr, IS_BUCKET(bp->flags), 0))) {
|
||||
|
||||
if (do_free) {
|
||||
if (bp->page)
|
||||
|
|
@ -397,7 +397,7 @@ __buf_free(HTAB *hashp, int do_free, int to_disk)
|
|||
}
|
||||
|
||||
extern void
|
||||
__reclaim_buf(HTAB *hashp, BUFHEAD *bp)
|
||||
dbm_reclaim_buf(HTAB *hashp, BUFHEAD *bp)
|
||||
{
|
||||
bp->ovfl = 0;
|
||||
bp->addr = 0;
|
||||
|
|
|
|||
|
|
@ -99,6 +99,7 @@ swap4b(PRUint32 value)
|
|||
defined(__ARM_ARCH_7__) || \
|
||||
defined(__ARM_ARCH_7A__) || \
|
||||
defined(__ARM_ARCH_7R__)))
|
||||
#if defined(IS_LITTLE_ENDIAN)
|
||||
static __inline__ PRUint32
|
||||
swap4b(PRUint32 value)
|
||||
{
|
||||
|
|
@ -109,6 +110,7 @@ swap4b(PRUint32 value)
|
|||
return ret;
|
||||
}
|
||||
#define SHA_HTONL(x) swap4b(x)
|
||||
#endif
|
||||
|
||||
#endif /* x86 family */
|
||||
|
||||
|
|
|
|||
|
|
@ -61,6 +61,12 @@
|
|||
#define force_inline inline
|
||||
#endif
|
||||
|
||||
#ifdef _MSC_VER
|
||||
#if _MSC_VER < 1900
|
||||
#define inline
|
||||
#endif
|
||||
#endif
|
||||
|
||||
/******************************************************************************/
|
||||
/* Implementing C.fst */
|
||||
/******************************************************************************/
|
||||
|
|
|
|||
|
|
@ -168,6 +168,9 @@ pkix_NameConstraintsChecker_Check(
|
|||
PKIX_PL_CertNameConstraints *mergedNameConstraints = NULL;
|
||||
PKIX_Boolean selfIssued = PKIX_FALSE;
|
||||
PKIX_Boolean lastCert = PKIX_FALSE;
|
||||
PKIX_Boolean treatCommonNameAsDNSName = PKIX_FALSE;
|
||||
PKIX_List *extKeyUsageList = NULL;
|
||||
PKIX_PL_OID *serverAuthOID = NULL;
|
||||
|
||||
PKIX_ENTER(CERTCHAINCHECKER, "pkix_NameConstraintsChecker_Check");
|
||||
PKIX_NULLCHECK_THREE(checker, cert, pNBIOContext);
|
||||
|
|
@ -185,11 +188,38 @@ pkix_NameConstraintsChecker_Check(
|
|||
PKIX_CHECK(pkix_IsCertSelfIssued(cert, &selfIssued, plContext),
|
||||
PKIX_ISCERTSELFISSUEDFAILED);
|
||||
|
||||
if (lastCert) {
|
||||
/* For the last cert, treat the CN as a DNS name for name
|
||||
* constraint check. But only if EKU has id-kp-serverAuth
|
||||
* or EKU is absent. It does not make sense to treat CN
|
||||
* as a DNS name for an OCSP signing certificate, for example.
|
||||
*/
|
||||
PKIX_CHECK(PKIX_PL_Cert_GetExtendedKeyUsage
|
||||
(cert, &extKeyUsageList, plContext),
|
||||
PKIX_CERTGETEXTENDEDKEYUSAGEFAILED);
|
||||
if (extKeyUsageList == NULL) {
|
||||
treatCommonNameAsDNSName = PKIX_TRUE;
|
||||
} else {
|
||||
PKIX_CHECK(PKIX_PL_OID_Create
|
||||
(PKIX_KEY_USAGE_SERVER_AUTH_OID,
|
||||
&serverAuthOID,
|
||||
plContext),
|
||||
PKIX_OIDCREATEFAILED);
|
||||
|
||||
PKIX_CHECK(pkix_List_Contains
|
||||
(extKeyUsageList,
|
||||
(PKIX_PL_Object *) serverAuthOID,
|
||||
&treatCommonNameAsDNSName,
|
||||
plContext),
|
||||
PKIX_LISTCONTAINSFAILED);
|
||||
}
|
||||
}
|
||||
|
||||
/* Check on non self-issued and if so only for last cert */
|
||||
if (selfIssued == PKIX_FALSE ||
|
||||
(selfIssued == PKIX_TRUE && lastCert)) {
|
||||
PKIX_CHECK(PKIX_PL_Cert_CheckNameConstraints
|
||||
(cert, state->nameConstraints, lastCert,
|
||||
(cert, state->nameConstraints, treatCommonNameAsDNSName,
|
||||
plContext),
|
||||
PKIX_CERTCHECKNAMECONSTRAINTSFAILED);
|
||||
}
|
||||
|
|
@ -241,6 +271,8 @@ pkix_NameConstraintsChecker_Check(
|
|||
cleanup:
|
||||
|
||||
PKIX_DECREF(state);
|
||||
PKIX_DECREF(extKeyUsageList);
|
||||
PKIX_DECREF(serverAuthOID);
|
||||
|
||||
PKIX_RETURN(CERTCHAINCHECKER);
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1139,3 +1139,9 @@ CERT_GetCertKeyType;
|
|||
;+ local:
|
||||
;+ *;
|
||||
;+};
|
||||
;+NSS_3.43 { # NSS 3.43 release
|
||||
;+ global:
|
||||
HASH_GetHashOidTagByHashType;
|
||||
;+ local:
|
||||
;+ *;
|
||||
;+};
|
||||
|
|
|
|||
|
|
@ -22,12 +22,12 @@
|
|||
* The format of the version string should be
|
||||
* "<major version>.<minor version>[.<patch level>[.<build number>]][ <ECC>][ <Beta>]"
|
||||
*/
|
||||
#define NSS_VERSION "3.41" _NSS_CUSTOMIZED
|
||||
#define NSS_VERSION "3.43" _NSS_CUSTOMIZED " Beta"
|
||||
#define NSS_VMAJOR 3
|
||||
#define NSS_VMINOR 41
|
||||
#define NSS_VMINOR 43
|
||||
#define NSS_VPATCH 0
|
||||
#define NSS_VBUILD 0
|
||||
#define NSS_BETA PR_FALSE
|
||||
#define NSS_BETA PR_TRUE
|
||||
|
||||
#ifndef RC_INVOKED
|
||||
|
||||
|
|
|
|||
|
|
@ -51,6 +51,10 @@ NSS_CMSContentInfo_Destroy(NSSCMSContentInfo *cinfo)
|
|||
{
|
||||
SECOidTag kind;
|
||||
|
||||
if (cinfo == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
kind = NSS_CMSContentInfo_GetContentTypeTag(cinfo);
|
||||
switch (kind) {
|
||||
case SEC_OID_PKCS7_ENVELOPED_DATA:
|
||||
|
|
@ -86,6 +90,11 @@ NSSCMSContentInfo *
|
|||
NSS_CMSContentInfo_GetChildContentInfo(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
NSSCMSContentInfo *ccinfo = NULL;
|
||||
|
||||
if (cinfo == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
SECOidTag tag = NSS_CMSContentInfo_GetContentTypeTag(cinfo);
|
||||
switch (tag) {
|
||||
case SEC_OID_PKCS7_SIGNED_DATA:
|
||||
|
|
@ -127,6 +136,9 @@ SECStatus
|
|||
NSS_CMSContentInfo_SetDontStream(NSSCMSContentInfo *cinfo, PRBool dontStream)
|
||||
{
|
||||
SECStatus rv;
|
||||
if (cinfo == NULL) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
rv = NSS_CMSContentInfo_Private_Init(cinfo);
|
||||
if (rv != SECSuccess) {
|
||||
|
|
@ -145,15 +157,20 @@ NSS_CMSContentInfo_SetContent(NSSCMSMessage *cmsg, NSSCMSContentInfo *cinfo,
|
|||
SECOidTag type, void *ptr)
|
||||
{
|
||||
SECStatus rv;
|
||||
if (cinfo == NULL || cmsg == NULL) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
cinfo->contentTypeTag = SECOID_FindOIDByTag(type);
|
||||
if (cinfo->contentTypeTag == NULL)
|
||||
if (cinfo->contentTypeTag == NULL) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
/* do not copy the oid, just create a reference */
|
||||
rv = SECITEM_CopyItem(cmsg->poolp, &(cinfo->contentType), &(cinfo->contentTypeTag->oid));
|
||||
if (rv != SECSuccess)
|
||||
if (rv != SECSuccess) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
cinfo->content.pointer = ptr;
|
||||
|
||||
|
|
@ -185,8 +202,9 @@ SECStatus
|
|||
NSS_CMSContentInfo_SetContent_Data(NSSCMSMessage *cmsg, NSSCMSContentInfo *cinfo,
|
||||
SECItem *data, PRBool detached)
|
||||
{
|
||||
if (NSS_CMSContentInfo_SetContent(cmsg, cinfo, SEC_OID_PKCS7_DATA, (void *)data) != SECSuccess)
|
||||
if (NSS_CMSContentInfo_SetContent(cmsg, cinfo, SEC_OID_PKCS7_DATA, (void *)data) != SECSuccess) {
|
||||
return SECFailure;
|
||||
}
|
||||
if (detached) {
|
||||
cinfo->rawContent = NULL;
|
||||
}
|
||||
|
|
@ -230,6 +248,10 @@ NSS_CMSContentInfo_SetContent_EncryptedData(NSSCMSMessage *cmsg, NSSCMSContentIn
|
|||
void *
|
||||
NSS_CMSContentInfo_GetContent(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
SECOidTag tag = cinfo->contentTypeTag
|
||||
? cinfo->contentTypeTag->offset
|
||||
: SEC_OID_UNKNOWN;
|
||||
|
|
@ -260,6 +282,10 @@ NSS_CMSContentInfo_GetInnerContent(NSSCMSContentInfo *cinfo)
|
|||
SECOidTag tag;
|
||||
SECItem *pItem = NULL;
|
||||
|
||||
if (cinfo == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
tag = NSS_CMSContentInfo_GetContentTypeTag(cinfo);
|
||||
if (NSS_CMSType_IsData(tag)) {
|
||||
pItem = cinfo->content.data;
|
||||
|
|
@ -282,6 +308,10 @@ NSS_CMSContentInfo_GetInnerContent(NSSCMSContentInfo *cinfo)
|
|||
SECOidTag
|
||||
NSS_CMSContentInfo_GetContentTypeTag(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo == NULL) {
|
||||
return SEC_OID_UNKNOWN;
|
||||
}
|
||||
|
||||
if (cinfo->contentTypeTag == NULL)
|
||||
cinfo->contentTypeTag = SECOID_FindOID(&(cinfo->contentType));
|
||||
|
||||
|
|
@ -294,11 +324,17 @@ NSS_CMSContentInfo_GetContentTypeTag(NSSCMSContentInfo *cinfo)
|
|||
SECItem *
|
||||
NSS_CMSContentInfo_GetContentTypeOID(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo->contentTypeTag == NULL)
|
||||
cinfo->contentTypeTag = SECOID_FindOID(&(cinfo->contentType));
|
||||
|
||||
if (cinfo->contentTypeTag == NULL)
|
||||
if (cinfo == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (cinfo->contentTypeTag == NULL) {
|
||||
cinfo->contentTypeTag = SECOID_FindOID(&(cinfo->contentType));
|
||||
}
|
||||
|
||||
if (cinfo->contentTypeTag == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return &(cinfo->contentTypeTag->oid);
|
||||
}
|
||||
|
|
@ -310,8 +346,13 @@ NSS_CMSContentInfo_GetContentTypeOID(NSSCMSContentInfo *cinfo)
|
|||
SECOidTag
|
||||
NSS_CMSContentInfo_GetContentEncAlgTag(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo->contentEncAlgTag == SEC_OID_UNKNOWN)
|
||||
if (cinfo == NULL) {
|
||||
return SEC_OID_UNKNOWN;
|
||||
}
|
||||
|
||||
if (cinfo->contentEncAlgTag == SEC_OID_UNKNOWN) {
|
||||
cinfo->contentEncAlgTag = SECOID_GetAlgorithmTag(&(cinfo->contentEncAlg));
|
||||
}
|
||||
|
||||
return cinfo->contentEncAlgTag;
|
||||
}
|
||||
|
|
@ -322,6 +363,10 @@ NSS_CMSContentInfo_GetContentEncAlgTag(NSSCMSContentInfo *cinfo)
|
|||
SECAlgorithmID *
|
||||
NSS_CMSContentInfo_GetContentEncAlg(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return &(cinfo->contentEncAlg);
|
||||
}
|
||||
|
||||
|
|
@ -330,10 +375,14 @@ NSS_CMSContentInfo_SetContentEncAlg(PLArenaPool *poolp, NSSCMSContentInfo *cinfo
|
|||
SECOidTag bulkalgtag, SECItem *parameters, int keysize)
|
||||
{
|
||||
SECStatus rv;
|
||||
if (cinfo == NULL) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
rv = SECOID_SetAlgorithmID(poolp, &(cinfo->contentEncAlg), bulkalgtag, parameters);
|
||||
if (rv != SECSuccess)
|
||||
if (rv != SECSuccess) {
|
||||
return SECFailure;
|
||||
}
|
||||
cinfo->keysize = keysize;
|
||||
return SECSuccess;
|
||||
}
|
||||
|
|
@ -343,27 +392,42 @@ NSS_CMSContentInfo_SetContentEncAlgID(PLArenaPool *poolp, NSSCMSContentInfo *cin
|
|||
SECAlgorithmID *algid, int keysize)
|
||||
{
|
||||
SECStatus rv;
|
||||
if (cinfo == NULL) {
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
rv = SECOID_CopyAlgorithmID(poolp, &(cinfo->contentEncAlg), algid);
|
||||
if (rv != SECSuccess)
|
||||
if (rv != SECSuccess) {
|
||||
return SECFailure;
|
||||
if (keysize >= 0)
|
||||
}
|
||||
if (keysize >= 0) {
|
||||
cinfo->keysize = keysize;
|
||||
}
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
void
|
||||
NSS_CMSContentInfo_SetBulkKey(NSSCMSContentInfo *cinfo, PK11SymKey *bulkkey)
|
||||
{
|
||||
cinfo->bulkkey = PK11_ReferenceSymKey(bulkkey);
|
||||
cinfo->keysize = PK11_GetKeyStrength(cinfo->bulkkey, &(cinfo->contentEncAlg));
|
||||
if (cinfo == NULL) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (bulkkey == NULL) {
|
||||
cinfo->bulkkey = NULL;
|
||||
cinfo->keysize = 0;
|
||||
} else {
|
||||
cinfo->bulkkey = PK11_ReferenceSymKey(bulkkey);
|
||||
cinfo->keysize = PK11_GetKeyStrength(cinfo->bulkkey, &(cinfo->contentEncAlg));
|
||||
}
|
||||
}
|
||||
|
||||
PK11SymKey *
|
||||
NSS_CMSContentInfo_GetBulkKey(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo->bulkkey == NULL)
|
||||
if (cinfo == NULL || cinfo->bulkkey == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return PK11_ReferenceSymKey(cinfo->bulkkey);
|
||||
}
|
||||
|
|
@ -371,5 +435,9 @@ NSS_CMSContentInfo_GetBulkKey(NSSCMSContentInfo *cinfo)
|
|||
int
|
||||
NSS_CMSContentInfo_GetBulkKeySize(NSSCMSContentInfo *cinfo)
|
||||
{
|
||||
if (cinfo == NULL) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
return cinfo->keysize;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -56,7 +56,9 @@ void
|
|||
NSS_CMSDigestedData_Destroy(NSSCMSDigestedData *digd)
|
||||
{
|
||||
/* everything's in a pool, so don't worry about the storage */
|
||||
NSS_CMSContentInfo_Destroy(&(digd->contentInfo));
|
||||
if (digd != NULL) {
|
||||
NSS_CMSContentInfo_Destroy(&(digd->contentInfo));
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -87,7 +87,9 @@ void
|
|||
NSS_CMSEncryptedData_Destroy(NSSCMSEncryptedData *encd)
|
||||
{
|
||||
/* everything's in a pool, so don't worry about the storage */
|
||||
NSS_CMSContentInfo_Destroy(&(encd->contentInfo));
|
||||
if (encd != NULL) {
|
||||
NSS_CMSContentInfo_Destroy(&(encd->contentInfo));
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -144,6 +144,11 @@ NSS_CMSEnvelopedData_Encode_BeforeStart(NSSCMSEnvelopedData *envd)
|
|||
poolp = envd->cmsg->poolp;
|
||||
cinfo = &(envd->contentInfo);
|
||||
|
||||
if (cinfo == NULL) {
|
||||
PORT_SetError(SEC_ERROR_BAD_DATA);
|
||||
goto loser;
|
||||
}
|
||||
|
||||
recipientinfos = envd->recipientInfos;
|
||||
if (recipientinfos == NULL) {
|
||||
PORT_SetError(SEC_ERROR_BAD_DATA);
|
||||
|
|
|
|||
|
|
@ -29,8 +29,9 @@ NSS_CMSMessage_Create(PLArenaPool *poolp)
|
|||
|
||||
if (poolp == NULL) {
|
||||
poolp = PORT_NewArena(1024); /* XXX what is right value? */
|
||||
if (poolp == NULL)
|
||||
if (poolp == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
poolp_is_ours = PR_TRUE;
|
||||
}
|
||||
|
||||
|
|
@ -44,8 +45,9 @@ NSS_CMSMessage_Create(PLArenaPool *poolp)
|
|||
if (mark) {
|
||||
PORT_ArenaRelease(poolp, mark);
|
||||
}
|
||||
} else
|
||||
} else {
|
||||
PORT_FreeArena(poolp, PR_FALSE);
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
|
|
@ -53,8 +55,9 @@ NSS_CMSMessage_Create(PLArenaPool *poolp)
|
|||
cmsg->poolp_is_ours = poolp_is_ours;
|
||||
cmsg->refCount = 1;
|
||||
|
||||
if (mark)
|
||||
if (mark) {
|
||||
PORT_ArenaUnmark(poolp, mark);
|
||||
}
|
||||
|
||||
return cmsg;
|
||||
}
|
||||
|
|
@ -73,8 +76,13 @@ NSS_CMSMessage_SetEncodingParams(NSSCMSMessage *cmsg,
|
|||
NSSCMSGetDecryptKeyCallback decrypt_key_cb, void *decrypt_key_cb_arg,
|
||||
SECAlgorithmID **detached_digestalgs, SECItem **detached_digests)
|
||||
{
|
||||
if (pwfn)
|
||||
if (cmsg == NULL) {
|
||||
return;
|
||||
}
|
||||
if (pwfn) {
|
||||
PK11_SetPasswordFunc(pwfn);
|
||||
}
|
||||
|
||||
cmsg->pwfn_arg = pwfn_arg;
|
||||
cmsg->decrypt_key_cb = decrypt_key_cb;
|
||||
cmsg->decrypt_key_cb_arg = decrypt_key_cb_arg;
|
||||
|
|
@ -88,19 +96,25 @@ NSS_CMSMessage_SetEncodingParams(NSSCMSMessage *cmsg,
|
|||
void
|
||||
NSS_CMSMessage_Destroy(NSSCMSMessage *cmsg)
|
||||
{
|
||||
PORT_Assert(cmsg->refCount > 0);
|
||||
if (cmsg->refCount <= 0) /* oops */
|
||||
if (cmsg == NULL)
|
||||
return;
|
||||
|
||||
cmsg->refCount--; /* thread safety? */
|
||||
if (cmsg->refCount > 0)
|
||||
PORT_Assert(cmsg->refCount > 0);
|
||||
if (cmsg->refCount <= 0) { /* oops */
|
||||
return;
|
||||
}
|
||||
|
||||
cmsg->refCount--; /* thread safety? */
|
||||
if (cmsg->refCount > 0) {
|
||||
return;
|
||||
}
|
||||
|
||||
NSS_CMSContentInfo_Destroy(&(cmsg->contentInfo));
|
||||
|
||||
/* if poolp is not NULL, cmsg is the owner of its arena */
|
||||
if (cmsg->poolp_is_ours)
|
||||
if (cmsg->poolp_is_ours) {
|
||||
PORT_FreeArena(cmsg->poolp, PR_FALSE); /* XXX clear it? */
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -112,8 +126,9 @@ NSS_CMSMessage_Destroy(NSSCMSMessage *cmsg)
|
|||
NSSCMSMessage *
|
||||
NSS_CMSMessage_Copy(NSSCMSMessage *cmsg)
|
||||
{
|
||||
if (cmsg == NULL)
|
||||
if (cmsg == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
PORT_Assert(cmsg->refCount > 0);
|
||||
|
||||
|
|
@ -127,6 +142,10 @@ NSS_CMSMessage_Copy(NSSCMSMessage *cmsg)
|
|||
PLArenaPool *
|
||||
NSS_CMSMessage_GetArena(NSSCMSMessage *cmsg)
|
||||
{
|
||||
if (cmsg == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return cmsg->poolp;
|
||||
}
|
||||
|
||||
|
|
@ -136,6 +155,10 @@ NSS_CMSMessage_GetArena(NSSCMSMessage *cmsg)
|
|||
NSSCMSContentInfo *
|
||||
NSS_CMSMessage_GetContentInfo(NSSCMSMessage *cmsg)
|
||||
{
|
||||
if (cmsg == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return &(cmsg->contentInfo);
|
||||
}
|
||||
|
||||
|
|
@ -147,6 +170,10 @@ NSS_CMSMessage_GetContentInfo(NSSCMSMessage *cmsg)
|
|||
SECItem *
|
||||
NSS_CMSMessage_GetContent(NSSCMSMessage *cmsg)
|
||||
{
|
||||
if (cmsg == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* this is a shortcut */
|
||||
NSSCMSContentInfo *cinfo = NSS_CMSMessage_GetContentInfo(cmsg);
|
||||
SECItem *pItem = NSS_CMSContentInfo_GetInnerContent(cinfo);
|
||||
|
|
@ -164,6 +191,10 @@ NSS_CMSMessage_ContentLevelCount(NSSCMSMessage *cmsg)
|
|||
int count = 0;
|
||||
NSSCMSContentInfo *cinfo;
|
||||
|
||||
if (cmsg == NULL) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* walk down the chain of contentinfos */
|
||||
for (cinfo = &(cmsg->contentInfo); cinfo != NULL;) {
|
||||
count++;
|
||||
|
|
@ -183,6 +214,10 @@ NSS_CMSMessage_ContentLevel(NSSCMSMessage *cmsg, int n)
|
|||
int count = 0;
|
||||
NSSCMSContentInfo *cinfo;
|
||||
|
||||
if (cmsg == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* walk down the chain of contentinfos */
|
||||
for (cinfo = &(cmsg->contentInfo); cinfo != NULL && count < n;
|
||||
cinfo = NSS_CMSContentInfo_GetChildContentInfo(cinfo)) {
|
||||
|
|
@ -200,6 +235,10 @@ NSS_CMSMessage_ContainsCertsOrCrls(NSSCMSMessage *cmsg)
|
|||
{
|
||||
NSSCMSContentInfo *cinfo;
|
||||
|
||||
if (cmsg == NULL) {
|
||||
return PR_FALSE;
|
||||
}
|
||||
|
||||
/* descend into CMS message */
|
||||
for (cinfo = &(cmsg->contentInfo); cinfo != NULL;
|
||||
cinfo = NSS_CMSContentInfo_GetChildContentInfo(cinfo)) {
|
||||
|
|
@ -221,6 +260,10 @@ NSS_CMSMessage_IsEncrypted(NSSCMSMessage *cmsg)
|
|||
{
|
||||
NSSCMSContentInfo *cinfo;
|
||||
|
||||
if (cmsg == NULL) {
|
||||
return PR_FALSE;
|
||||
}
|
||||
|
||||
/* walk down the chain of contentinfos */
|
||||
for (cinfo = &(cmsg->contentInfo); cinfo != NULL;
|
||||
cinfo = NSS_CMSContentInfo_GetChildContentInfo(cinfo)) {
|
||||
|
|
@ -251,13 +294,21 @@ NSS_CMSMessage_IsSigned(NSSCMSMessage *cmsg)
|
|||
{
|
||||
NSSCMSContentInfo *cinfo;
|
||||
|
||||
if (cmsg == NULL) {
|
||||
return PR_FALSE;
|
||||
}
|
||||
|
||||
/* walk down the chain of contentinfos */
|
||||
for (cinfo = &(cmsg->contentInfo); cinfo != NULL;
|
||||
cinfo = NSS_CMSContentInfo_GetChildContentInfo(cinfo)) {
|
||||
switch (NSS_CMSContentInfo_GetContentTypeTag(cinfo)) {
|
||||
case SEC_OID_PKCS7_SIGNED_DATA:
|
||||
if (!NSS_CMSArray_IsEmpty((void **)cinfo->content.signedData->signerInfos))
|
||||
if (cinfo->content.signedData == NULL) {
|
||||
return PR_FALSE;
|
||||
}
|
||||
if (!NSS_CMSArray_IsEmpty((void **)cinfo->content.signedData->signerInfos)) {
|
||||
return PR_TRUE;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
/* callback here for generic wrappers? */
|
||||
|
|
@ -278,8 +329,9 @@ NSS_CMSMessage_IsContentEmpty(NSSCMSMessage *cmsg, unsigned int minLen)
|
|||
{
|
||||
SECItem *item = NULL;
|
||||
|
||||
if (cmsg == NULL)
|
||||
if (cmsg == NULL) {
|
||||
return PR_TRUE;
|
||||
}
|
||||
|
||||
item = NSS_CMSContentInfo_GetContent(NSS_CMSMessage_GetContentInfo(cmsg));
|
||||
|
||||
|
|
|
|||
|
|
@ -239,7 +239,7 @@ NSS_CMSGenericWrapperData_Destroy(SECOidTag type, NSSCMSGenericWrapperData *gd)
|
|||
{
|
||||
const nsscmstypeInfo *typeInfo = nss_cmstype_lookup(type);
|
||||
|
||||
if (typeInfo && typeInfo->destroy) {
|
||||
if (typeInfo && (typeInfo->destroy) && (gd != NULL)) {
|
||||
(*typeInfo->destroy)(gd);
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -457,6 +457,25 @@ smime_choose_cipher(CERTCertificate *scert, CERTCertificate **rcerts)
|
|||
cipher_votes[strong_mapi] += pref;
|
||||
pref--;
|
||||
} else {
|
||||
if (pklen_bits > 3072) {
|
||||
/* While support for AES 256 is a SHOULD+ in RFC 5751
|
||||
* rather than a MUST, RSA and DSA keys longer than 3072
|
||||
* bits provide more than 128 bits of security strength.
|
||||
* So, AES 256 should be used to provide comparable
|
||||
* security. */
|
||||
cipher_abilities[aes256_mapi]++;
|
||||
cipher_votes[aes256_mapi] += pref;
|
||||
pref--;
|
||||
}
|
||||
if (pklen_bits > 1023) {
|
||||
/* RFC 5751 mandates support for AES 128, but also says
|
||||
* that RSA and DSA signature keys SHOULD NOT be less than
|
||||
* 1024 bits. So, cast vote for AES 128 if key length
|
||||
* is at least 1024 bits. */
|
||||
cipher_abilities[aes128_mapi]++;
|
||||
cipher_votes[aes128_mapi] += pref;
|
||||
pref--;
|
||||
}
|
||||
if (pklen_bits > 512) {
|
||||
/* cast votes for the strong algorithm */
|
||||
cipher_abilities[strong_mapi]++;
|
||||
|
|
|
|||
|
|
@ -4838,6 +4838,7 @@ NSC_GenerateKeyPair(CK_SESSION_HANDLE hSession,
|
|||
bitSize = sftk_GetLengthInBits(pubExp.data, pubExp.len);
|
||||
if (bitSize < 2) {
|
||||
crv = CKR_ATTRIBUTE_VALUE_INVALID;
|
||||
PORT_Free(pubExp.data);
|
||||
break;
|
||||
}
|
||||
crv = sftk_AddAttributeType(privateKey, CKA_PUBLIC_EXPONENT,
|
||||
|
|
|
|||
|
|
@ -17,11 +17,11 @@
|
|||
* The format of the version string should be
|
||||
* "<major version>.<minor version>[.<patch level>[.<build number>]][ <ECC>][ <Beta>]"
|
||||
*/
|
||||
#define SOFTOKEN_VERSION "3.41" SOFTOKEN_ECC_STRING
|
||||
#define SOFTOKEN_VERSION "3.43" SOFTOKEN_ECC_STRING " Beta"
|
||||
#define SOFTOKEN_VMAJOR 3
|
||||
#define SOFTOKEN_VMINOR 41
|
||||
#define SOFTOKEN_VMINOR 43
|
||||
#define SOFTOKEN_VPATCH 0
|
||||
#define SOFTOKEN_VBUILD 0
|
||||
#define SOFTOKEN_BETA PR_FALSE
|
||||
#define SOFTOKEN_BETA PR_TRUE
|
||||
|
||||
#endif /* _SOFTKVER_H_ */
|
||||
|
|
|
|||
|
|
@ -5,14 +5,14 @@
|
|||
#define UNUSED_ERROR(x) ER3(SSL_ERROR_UNUSED_##x, (SSL_ERROR_BASE + x), \
|
||||
"Unrecognized SSL error_code.")
|
||||
|
||||
/* SSL-specific security error codes */
|
||||
/* SSL-specific security error codes */
|
||||
/* caller must include "sslerr.h" */
|
||||
|
||||
ER3(SSL_ERROR_EXPORT_ONLY_SERVER, SSL_ERROR_BASE + 0,
|
||||
"Unable to communicate securely. Peer does not support high-grade encryption.")
|
||||
"Unable to communicate securely. Peer does not support high-grade encryption.")
|
||||
|
||||
ER3(SSL_ERROR_US_ONLY_SERVER, SSL_ERROR_BASE + 1,
|
||||
"Unable to communicate securely. Peer requires high-grade encryption which is not supported.")
|
||||
"Unable to communicate securely. Peer requires high-grade encryption which is not supported.")
|
||||
|
||||
ER3(SSL_ERROR_NO_CYPHER_OVERLAP, SSL_ERROR_BASE + 2,
|
||||
"Cannot communicate securely with peer: no common encryption algorithm(s).")
|
||||
|
|
@ -197,7 +197,7 @@ ER3(SSL_ERROR_RX_UNKNOWN_ALERT, (SSL_ERROR_BASE + 57),
|
|||
"SSL received an alert record with an unknown alert description.")
|
||||
|
||||
/*
|
||||
* Received an alert reporting what we did wrong. (more alerts above)
|
||||
* Received an alert reporting what we did wrong. (more alerts above)
|
||||
*/
|
||||
ER3(SSL_ERROR_CLOSE_NOTIFY_ALERT, (SSL_ERROR_BASE + 58),
|
||||
"SSL peer has closed this connection.")
|
||||
|
|
|
|||
|
|
@ -11,6 +11,12 @@
|
|||
#include "sslimpl.h"
|
||||
#include "sslproto.h"
|
||||
|
||||
#ifdef _MSC_VER
|
||||
#if _MSC_VER < 1900
|
||||
#define inline
|
||||
#endif
|
||||
#endif
|
||||
|
||||
SECStatus
|
||||
dtls13_InsertCipherTextHeader(const sslSocket *ss, ssl3CipherSpec *cwSpec,
|
||||
sslBuffer *wrBuf, PRBool *needsLength)
|
||||
|
|
|
|||
|
|
@ -10,6 +10,12 @@
|
|||
#include "prnetdb.h"
|
||||
#include "secport.h"
|
||||
|
||||
#ifdef _MSC_VER
|
||||
#if _MSC_VER < 1900
|
||||
#define inline
|
||||
#endif
|
||||
#endif
|
||||
|
||||
static inline unsigned int
|
||||
sslBloom_Size(unsigned int bits)
|
||||
{
|
||||
|
|
|
|||
|
|
@ -3644,6 +3644,7 @@ ssl_SetDefaultsFromEnvironment(void)
|
|||
char *ev;
|
||||
firsttime = 0;
|
||||
#ifdef DEBUG
|
||||
ssl_trace_iob = NULL;
|
||||
ev = PR_GetEnvSecure("SSLDEBUGFILE");
|
||||
if (ev && ev[0]) {
|
||||
ssl_trace_iob = fopen(ev, "w");
|
||||
|
|
@ -3665,6 +3666,7 @@ ssl_SetDefaultsFromEnvironment(void)
|
|||
}
|
||||
#endif /* DEBUG */
|
||||
#ifdef NSS_ALLOW_SSLKEYLOGFILE
|
||||
ssl_keylog_iob = NULL;
|
||||
ev = PR_GetEnvSecure("SSLKEYLOGFILE");
|
||||
if (ev && ev[0]) {
|
||||
ssl_keylog_iob = fopen(ev, "a");
|
||||
|
|
|
|||
|
|
@ -1573,6 +1573,13 @@ tls13_HandleClientHelloPart2(sslSocket *ss,
|
|||
const sslNamedGroupDef *previousGroup = NULL;
|
||||
PRBool hrr = PR_FALSE;
|
||||
|
||||
/* If the legacy_version field is set to 0x300 or smaller,
|
||||
* reject the connection with protocol_version alert. */
|
||||
if (ss->clientHelloVersion <= SSL_LIBRARY_VERSION_3_0) {
|
||||
FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, protocol_version);
|
||||
goto loser;
|
||||
}
|
||||
|
||||
ss->ssl3.hs.endOfFlight = PR_TRUE;
|
||||
|
||||
if (ssl3_ExtensionNegotiated(ss, ssl_tls13_early_data_xtn)) {
|
||||
|
|
|
|||
|
|
@ -2,14 +2,16 @@
|
|||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
CORE_DEPTH = ../..
|
||||
|
||||
CORE_DEPTH = ../..
|
||||
|
||||
# MODULE public and private header directories are implicitly REQUIRED.
|
||||
MODULE = nss
|
||||
|
||||
CSRCS = nsssysinit.c
|
||||
CSRCS = \
|
||||
nsssysinit.c \
|
||||
$(NULL)
|
||||
|
||||
LIBRARY_NAME = nsssysinit
|
||||
#LIBRARY_VERSION = 3
|
||||
MAPFILE = $(OBJDIR)/nsssysinit.def
|
||||
|
||||
# This part of the code, including all sub-dirs, can be optimized for size
|
||||
export ALLOW_OPT_CODE_SIZE = 1
|
||||
|
|
|
|||
|
|
@ -15,11 +15,10 @@
|
|||
* of pkcs11 modules common to all applications.
|
||||
*/
|
||||
|
||||
/*
|
||||
* OS Specific function to get where the NSS user database should reside.
|
||||
*/
|
||||
#ifndef LINUX
|
||||
#error __FILE__ only builds on Linux.
|
||||
#endif
|
||||
|
||||
#ifdef XP_UNIX
|
||||
#include <unistd.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/types.h>
|
||||
|
|
@ -37,9 +36,41 @@ testdir(char *dir)
|
|||
return S_ISDIR(buf.st_mode);
|
||||
}
|
||||
|
||||
/**
|
||||
* Append given @dir to @path and creates the directory with mode @mode.
|
||||
* Returns 0 if successful, -1 otherwise.
|
||||
* Assumes that the allocation for @path has sufficient space for @dir
|
||||
* to be added.
|
||||
*/
|
||||
static int
|
||||
appendDirAndCreate(char *path, char *dir, mode_t mode)
|
||||
{
|
||||
PORT_Strcat(path, dir);
|
||||
if (!testdir(path)) {
|
||||
if (mkdir(path, mode)) {
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
#define XDG_NSS_USER_PATH1 "/.local"
|
||||
#define XDG_NSS_USER_PATH2 "/share"
|
||||
#define XDG_NSS_USER_PATH3 "/pki"
|
||||
|
||||
#define NSS_USER_PATH1 "/.pki"
|
||||
#define NSS_USER_PATH2 "/nssdb"
|
||||
static char *
|
||||
|
||||
/**
|
||||
* Return the path to user's NSS database.
|
||||
* We search in the following dirs in order:
|
||||
* (1) $HOME/.pki/nssdb;
|
||||
* (2) $XDG_DATA_HOME/pki/nssdb if XDG_DATA_HOME is set;
|
||||
* (3) $HOME/.local/share/pki/nssdb (default XDG_DATA_HOME value).
|
||||
* If (1) does not exist, then the returned dir will be set to either
|
||||
* (2) or (3), depending if XDG_DATA_HOME is set.
|
||||
*/
|
||||
char *
|
||||
getUserDB(void)
|
||||
{
|
||||
char *userdir = PR_GetEnvSecure("HOME");
|
||||
|
|
@ -50,22 +81,47 @@ getUserDB(void)
|
|||
}
|
||||
|
||||
nssdir = PORT_Alloc(strlen(userdir) + sizeof(NSS_USER_PATH1) + sizeof(NSS_USER_PATH2));
|
||||
PORT_Strcpy(nssdir, userdir);
|
||||
PORT_Strcat(nssdir, NSS_USER_PATH1 NSS_USER_PATH2);
|
||||
if (testdir(nssdir)) {
|
||||
/* $HOME/.pki/nssdb exists */
|
||||
return nssdir;
|
||||
} else {
|
||||
/* either $HOME/.pki or $HOME/.pki/nssdb does not exist */
|
||||
PORT_Free(nssdir);
|
||||
}
|
||||
int size = 0;
|
||||
char *xdguserdatadir = PR_GetEnvSecure("XDG_DATA_HOME");
|
||||
if (xdguserdatadir) {
|
||||
size = strlen(xdguserdatadir);
|
||||
} else {
|
||||
size = strlen(userdir) + sizeof(XDG_NSS_USER_PATH1) + sizeof(XDG_NSS_USER_PATH2);
|
||||
}
|
||||
size += sizeof(XDG_NSS_USER_PATH3) + sizeof(NSS_USER_PATH2);
|
||||
|
||||
nssdir = PORT_Alloc(size);
|
||||
if (nssdir == NULL) {
|
||||
return NULL;
|
||||
}
|
||||
PORT_Strcpy(nssdir, userdir);
|
||||
/* verify it exists */
|
||||
if (!testdir(nssdir)) {
|
||||
PORT_Free(nssdir);
|
||||
return NULL;
|
||||
|
||||
if (xdguserdatadir) {
|
||||
PORT_Strcpy(nssdir, xdguserdatadir);
|
||||
if (!testdir(nssdir)) {
|
||||
PORT_Free(nssdir);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
} else {
|
||||
PORT_Strcpy(nssdir, userdir);
|
||||
if (appendDirAndCreate(nssdir, XDG_NSS_USER_PATH1, 0755) ||
|
||||
appendDirAndCreate(nssdir, XDG_NSS_USER_PATH2, 0755)) {
|
||||
PORT_Free(nssdir);
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
PORT_Strcat(nssdir, NSS_USER_PATH1);
|
||||
if (!testdir(nssdir) && mkdir(nssdir, 0760)) {
|
||||
PORT_Free(nssdir);
|
||||
return NULL;
|
||||
}
|
||||
PORT_Strcat(nssdir, NSS_USER_PATH2);
|
||||
if (!testdir(nssdir) && mkdir(nssdir, 0760)) {
|
||||
/* ${XDG_DATA_HOME:-$HOME/.local/share}/pki/nssdb */
|
||||
if (appendDirAndCreate(nssdir, XDG_NSS_USER_PATH3, 0760) ||
|
||||
appendDirAndCreate(nssdir, NSS_USER_PATH2, 0760)) {
|
||||
PORT_Free(nssdir);
|
||||
return NULL;
|
||||
}
|
||||
|
|
@ -93,44 +149,6 @@ userCanModifySystemDB()
|
|||
return (access(NSS_DEFAULT_SYSTEM, W_OK) == 0);
|
||||
}
|
||||
|
||||
#else
|
||||
#ifdef XP_WIN
|
||||
static char *
|
||||
getUserDB(void)
|
||||
{
|
||||
/* use the registry to find the user's NSS_DIR. if no entry exists, create
|
||||
* one in the users Appdir location */
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static char *
|
||||
getSystemDB(void)
|
||||
{
|
||||
/* use the registry to find the system's NSS_DIR. if no entry exists, create
|
||||
* one based on the windows system data area */
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static PRBool
|
||||
userIsRoot()
|
||||
{
|
||||
/* use the registry to find if the user is the system administrator. */
|
||||
return PR_FALSE;
|
||||
}
|
||||
|
||||
static PRBool
|
||||
userCanModifySystemDB()
|
||||
{
|
||||
/* use the registry to find if the user has administrative privilege
|
||||
* to modify the system's nss database. */
|
||||
return PR_FALSE;
|
||||
}
|
||||
|
||||
#else
|
||||
#error "Need to write getUserDB, SystemDB, userIsRoot, and userCanModifySystemDB functions"
|
||||
#endif
|
||||
#endif
|
||||
|
||||
static PRBool
|
||||
getFIPSEnv(void)
|
||||
{
|
||||
|
|
@ -146,7 +164,6 @@ getFIPSEnv(void)
|
|||
}
|
||||
return PR_FALSE;
|
||||
}
|
||||
#ifdef XP_LINUX
|
||||
|
||||
static PRBool
|
||||
getFIPSMode(void)
|
||||
|
|
@ -171,14 +188,6 @@ getFIPSMode(void)
|
|||
return PR_TRUE;
|
||||
}
|
||||
|
||||
#else
|
||||
static PRBool
|
||||
getFIPSMode(void)
|
||||
{
|
||||
return getFIPSEnv();
|
||||
}
|
||||
#endif
|
||||
|
||||
#define NSS_DEFAULT_FLAGS "flags=readonly"
|
||||
|
||||
/* configuration flags according to
|
||||
|
|
|
|||
26
security/nss/lib/sysinit/nsssysinit.def
Normal file
26
security/nss/lib/sysinit/nsssysinit.def
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
;+#
|
||||
;+# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
;+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
;+# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
;+#
|
||||
;+# OK, this file is meant to support SUN, LINUX, AIX and WINDOWS
|
||||
;+# 1. For all unix platforms, the string ";-" means "remove this line"
|
||||
;+# 2. For all unix platforms, the string " DATA " will be removed from any
|
||||
;+# line on which it occurs.
|
||||
;+# 3. Lines containing ";+" will have ";+" removed on SUN and LINUX.
|
||||
;+# On AIX, lines containing ";+" will be removed.
|
||||
;+# 4. For all unix platforms, the string ";;" will thave the ";;" removed.
|
||||
;+# 5. For all unix platforms, after the above processing has taken place,
|
||||
;+# all characters after the first ";" on the line will be removed.
|
||||
;+# And for AIX, the first ";" will also be removed.
|
||||
;+# This file is passed directly to windows. Since ';' is a comment, all UNIX
|
||||
;+# directives are hidden behind ";", ";+", and ";-"
|
||||
;+
|
||||
;+NSS_3.15 { # NSS 3.15 release
|
||||
;+ global:
|
||||
LIBRARY nsssysiniit ;-
|
||||
EXPORTS ;-
|
||||
NSS_ReturnModuleSpecData;
|
||||
;+ local:
|
||||
;+*;
|
||||
;+};
|
||||
|
|
@ -3,29 +3,32 @@
|
|||
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
{
|
||||
'includes': [
|
||||
'../../coreconf/config.gypi'
|
||||
'../../coreconf/config.gypi',
|
||||
],
|
||||
'targets': [
|
||||
{
|
||||
'target_name': 'nsssysinit_static',
|
||||
'type': 'static_library',
|
||||
'sources': [
|
||||
'nsssysinit.c'
|
||||
'nsssysinit.c',
|
||||
],
|
||||
'dependencies': [
|
||||
'<(DEPTH)/exports.gyp:nss_exports',
|
||||
'<(DEPTH)/lib/util/util.gyp:nssutil3'
|
||||
]
|
||||
],
|
||||
},
|
||||
{
|
||||
'target_name': 'nsssysinit',
|
||||
'type': 'shared_library',
|
||||
'dependencies': [
|
||||
'nsssysinit_static'
|
||||
]
|
||||
'nsssysinit_static',
|
||||
],
|
||||
'variables': {
|
||||
'mapfile': 'nsssysinit.def',
|
||||
},
|
||||
}
|
||||
],
|
||||
'variables': {
|
||||
'module': 'nss'
|
||||
'module': 'nss',
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
||||
/* General security error codes */
|
||||
/* General security error codes */
|
||||
/* Caller must #include "secerr.h" */
|
||||
|
||||
ER3(SEC_ERROR_IO, SEC_ERROR_BASE + 0,
|
||||
|
|
@ -54,7 +54,7 @@ ER3(SEC_ERROR_BAD_PASSWORD, SEC_ERROR_BASE + 15,
|
|||
"The security password entered is incorrect.")
|
||||
|
||||
ER3(SEC_ERROR_RETRY_PASSWORD, SEC_ERROR_BASE + 16,
|
||||
"New password entered incorrectly. Please try again.")
|
||||
"New password entered incorrectly. Please try again.")
|
||||
|
||||
ER3(SEC_ERROR_NO_NODELOCK, SEC_ERROR_BASE + 17,
|
||||
"security library: no nodelock.")
|
||||
|
|
@ -96,10 +96,10 @@ ER3(SEC_ERROR_CERT_NO_RESPONSE, (SEC_ERROR_BASE + 29),
|
|||
"Cert Library: No Response")
|
||||
|
||||
ER3(SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE, (SEC_ERROR_BASE + 30),
|
||||
"The certificate issuer's certificate has expired. Check your system date and time.")
|
||||
"The certificate issuer's certificate has expired. Check your system date and time.")
|
||||
|
||||
ER3(SEC_ERROR_CRL_EXPIRED, (SEC_ERROR_BASE + 31),
|
||||
"The CRL for the certificate's issuer has expired. Update it or check your system date and time.")
|
||||
"The CRL for the certificate's issuer has expired. Update it or check your system date and time.")
|
||||
|
||||
ER3(SEC_ERROR_CRL_BAD_SIGNATURE, (SEC_ERROR_BASE + 32),
|
||||
"The CRL for the certificate's issuer has an invalid signature.")
|
||||
|
|
@ -159,7 +159,7 @@ ER3(SEC_ERROR_DECRYPTION_DISALLOWED, (SEC_ERROR_BASE + 49),
|
|||
|
||||
/* Fortezza Alerts */
|
||||
ER3(XP_SEC_FORTEZZA_BAD_CARD, (SEC_ERROR_BASE + 50),
|
||||
"Fortezza card has not been properly initialized. \
|
||||
"Fortezza card has not been properly initialized. \
|
||||
Please remove it and return it to your issuer.")
|
||||
|
||||
ER3(XP_SEC_FORTEZZA_NO_CARD, (SEC_ERROR_BASE + 51),
|
||||
|
|
@ -245,31 +245,31 @@ ER3(SEC_ERROR_IMPORTING_CERTIFICATES, (SEC_ERROR_BASE + 77),
|
|||
"Error attempting to import certificates.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_DECODING_PFX, (SEC_ERROR_BASE + 78),
|
||||
"Unable to import. Decoding error. File not valid.")
|
||||
"Unable to import. Decoding error. File not valid.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_INVALID_MAC, (SEC_ERROR_BASE + 79),
|
||||
"Unable to import. Invalid MAC. Incorrect password or corrupt file.")
|
||||
"Unable to import. Invalid MAC. Incorrect password or corrupt file.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNSUPPORTED_MAC_ALGORITHM, (SEC_ERROR_BASE + 80),
|
||||
"Unable to import. MAC algorithm not supported.")
|
||||
"Unable to import. MAC algorithm not supported.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNSUPPORTED_TRANSPORT_MODE, (SEC_ERROR_BASE + 81),
|
||||
"Unable to import. Only password integrity and privacy modes supported.")
|
||||
"Unable to import. Only password integrity and privacy modes supported.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_CORRUPT_PFX_STRUCTURE, (SEC_ERROR_BASE + 82),
|
||||
"Unable to import. File structure is corrupt.")
|
||||
"Unable to import. File structure is corrupt.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNSUPPORTED_PBE_ALGORITHM, (SEC_ERROR_BASE + 83),
|
||||
"Unable to import. Encryption algorithm not supported.")
|
||||
"Unable to import. Encryption algorithm not supported.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNSUPPORTED_VERSION, (SEC_ERROR_BASE + 84),
|
||||
"Unable to import. File version not supported.")
|
||||
"Unable to import. File version not supported.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_PRIVACY_PASSWORD_INCORRECT, (SEC_ERROR_BASE + 85),
|
||||
"Unable to import. Incorrect privacy password.")
|
||||
"Unable to import. Incorrect privacy password.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_CERT_COLLISION, (SEC_ERROR_BASE + 86),
|
||||
"Unable to import. Same nickname already exists in database.")
|
||||
"Unable to import. Same nickname already exists in database.")
|
||||
|
||||
ER3(SEC_ERROR_USER_CANCELLED, (SEC_ERROR_BASE + 87),
|
||||
"The user pressed cancel.")
|
||||
|
|
@ -290,34 +290,34 @@ ER3(SEC_ERROR_CERT_ADDR_MISMATCH, (SEC_ERROR_BASE + 92),
|
|||
"Address in signing certificate does not match address in message headers.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNABLE_TO_IMPORT_KEY, (SEC_ERROR_BASE + 93),
|
||||
"Unable to import. Error attempting to import private key.")
|
||||
"Unable to import. Error attempting to import private key.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_IMPORTING_CERT_CHAIN, (SEC_ERROR_BASE + 94),
|
||||
"Unable to import. Error attempting to import certificate chain.")
|
||||
"Unable to import. Error attempting to import certificate chain.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNABLE_TO_LOCATE_OBJECT_BY_NAME, (SEC_ERROR_BASE + 95),
|
||||
"Unable to export. Unable to locate certificate or key by nickname.")
|
||||
"Unable to export. Unable to locate certificate or key by nickname.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNABLE_TO_EXPORT_KEY, (SEC_ERROR_BASE + 96),
|
||||
"Unable to export. Private Key could not be located and exported.")
|
||||
"Unable to export. Private Key could not be located and exported.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNABLE_TO_WRITE, (SEC_ERROR_BASE + 97),
|
||||
"Unable to export. Unable to write the export file.")
|
||||
"Unable to export. Unable to write the export file.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_UNABLE_TO_READ, (SEC_ERROR_BASE + 98),
|
||||
"Unable to import. Unable to read the import file.")
|
||||
"Unable to import. Unable to read the import file.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS12_KEY_DATABASE_NOT_INITIALIZED, (SEC_ERROR_BASE + 99),
|
||||
"Unable to export. Key database corrupt or deleted.")
|
||||
"Unable to export. Key database corrupt or deleted.")
|
||||
|
||||
ER3(SEC_ERROR_KEYGEN_FAIL, (SEC_ERROR_BASE + 100),
|
||||
"Unable to generate public/private key pair.")
|
||||
|
||||
ER3(SEC_ERROR_INVALID_PASSWORD, (SEC_ERROR_BASE + 101),
|
||||
"Password entered is invalid. Please pick a different one.")
|
||||
"Password entered is invalid. Please pick a different one.")
|
||||
|
||||
ER3(SEC_ERROR_RETRY_OLD_PASSWORD, (SEC_ERROR_BASE + 102),
|
||||
"Old password entered incorrectly. Please try again.")
|
||||
"Old password entered incorrectly. Please try again.")
|
||||
|
||||
ER3(SEC_ERROR_BAD_NICKNAME, (SEC_ERROR_BASE + 103),
|
||||
"Certificate nickname already in use.")
|
||||
|
|
@ -344,7 +344,7 @@ ER3(SEC_ERROR_OLD_KRL, (SEC_ERROR_BASE + 110),
|
|||
"New KRL is not later than the current one.")
|
||||
|
||||
ER3(SEC_ERROR_CKL_CONFLICT, (SEC_ERROR_BASE + 111),
|
||||
"New CKL has different issuer than current CKL. Delete current CKL.")
|
||||
"New CKL has different issuer than current CKL. Delete current CKL.")
|
||||
|
||||
ER3(SEC_ERROR_CERT_NOT_IN_NAME_SPACE, (SEC_ERROR_BASE + 112),
|
||||
"The Certifying Authority for this certificate is not permitted to issue a \
|
||||
|
|
@ -518,7 +518,7 @@ ER3(SEC_ERROR_PKCS11_GENERAL_ERROR, (SEC_ERROR_BASE + 167),
|
|||
"A PKCS #11 module returned CKR_GENERAL_ERROR, indicating that an unrecoverable error has occurred.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS11_FUNCTION_FAILED, (SEC_ERROR_BASE + 168),
|
||||
"A PKCS #11 module returned CKR_FUNCTION_FAILED, indicating that the requested function could not be performed. Trying the same operation again might succeed.")
|
||||
"A PKCS #11 module returned CKR_FUNCTION_FAILED, indicating that the requested function could not be performed. Trying the same operation again might succeed.")
|
||||
|
||||
ER3(SEC_ERROR_PKCS11_DEVICE_ERROR, (SEC_ERROR_BASE + 169),
|
||||
"A PKCS #11 module returned CKR_DEVICE_ERROR, indicating that a problem has occurred with the token or slot.")
|
||||
|
|
|
|||
|
|
@ -19,12 +19,12 @@
|
|||
* The format of the version string should be
|
||||
* "<major version>.<minor version>[.<patch level>[.<build number>]][ <Beta>]"
|
||||
*/
|
||||
#define NSSUTIL_VERSION "3.41"
|
||||
#define NSSUTIL_VERSION "3.43 Beta"
|
||||
#define NSSUTIL_VMAJOR 3
|
||||
#define NSSUTIL_VMINOR 41
|
||||
#define NSSUTIL_VMINOR 43
|
||||
#define NSSUTIL_VPATCH 0
|
||||
#define NSSUTIL_VBUILD 0
|
||||
#define NSSUTIL_BETA PR_FALSE
|
||||
#define NSSUTIL_BETA PR_TRUE
|
||||
|
||||
SEC_BEGIN_PROTOS
|
||||
|
||||
|
|
|
|||
|
|
@ -17,6 +17,7 @@ import platform
|
|||
import tempfile
|
||||
|
||||
from hashlib import sha256
|
||||
from gtests.common.wycheproof.genTestVectors import generate_test_vectors
|
||||
|
||||
DEVNULL = open(os.devnull, 'wb')
|
||||
cwd = os.path.dirname(os.path.abspath(__file__))
|
||||
|
|
@ -212,6 +213,13 @@ class commandsAction(argparse.Action):
|
|||
for c in commandsAction.commands:
|
||||
print(c)
|
||||
|
||||
class wycheproofAction(argparse.Action):
|
||||
|
||||
def __call__(self, parser, args, values, option_string=None):
|
||||
generate_test_vectors()
|
||||
clangFormat = cfAction(None, None, None)
|
||||
clangFormat(None, args, None)
|
||||
|
||||
|
||||
def parse_arguments():
|
||||
parser = argparse.ArgumentParser(
|
||||
|
|
@ -270,6 +278,18 @@ def parse_arguments():
|
|||
nargs='*',
|
||||
action=commandsAction)
|
||||
|
||||
parser_wycheproof = subparsers.add_parser(
|
||||
'wycheproof',
|
||||
help="generate wycheproof test headers")
|
||||
parser_wycheproof.add_argument(
|
||||
'--noroot',
|
||||
help='On linux, suppress the use of \'sudo\' for running docker.',
|
||||
action='store_true')
|
||||
parser_wycheproof.add_argument(
|
||||
'wycheproof',
|
||||
nargs='*',
|
||||
action=wycheproofAction)
|
||||
|
||||
commandsAction.commands = [c for c in subparsers.choices]
|
||||
return parser.parse_args()
|
||||
|
||||
|
|
|
|||
|
|
@ -29,6 +29,10 @@
|
|||
[ 'OS=="linux"', {
|
||||
'dependencies': [
|
||||
'lib/freebl/freebl.gyp:freeblpriv3',
|
||||
],
|
||||
}],
|
||||
[ 'OS=="linux" and mozilla_client==0', {
|
||||
'dependencies': [
|
||||
'lib/sysinit/sysinit.gyp:nsssysinit',
|
||||
],
|
||||
}],
|
||||
|
|
@ -68,7 +72,7 @@
|
|||
'lib/util/util.gyp:nssutil',
|
||||
],
|
||||
'conditions': [
|
||||
[ 'OS=="linux"', {
|
||||
[ 'OS=="linux" and mozilla_client==0', {
|
||||
'dependencies': [
|
||||
'lib/sysinit/sysinit.gyp:nsssysinit_static',
|
||||
],
|
||||
|
|
@ -201,6 +205,11 @@
|
|||
'cmd/lowhashtest/lowhashtest.gyp:lowhashtest',
|
||||
],
|
||||
}],
|
||||
[ 'OS=="linux" and mozilla_client==0', {
|
||||
'dependencies': [
|
||||
'gtests/sysinit_gtest/sysinit_gtest.gyp:sysinit_gtest',
|
||||
],
|
||||
}],
|
||||
[ 'disable_libpkix==0', {
|
||||
'dependencies': [
|
||||
'cmd/pkix-errcodes/pkix-errcodes.gyp:pkix-errcodes',
|
||||
|
|
|
|||
|
|
@ -10,6 +10,7 @@ import NameConstraints.ca:x:CT,C,C
|
|||
# Name Constrained CA: Name constrained to permited DNSName ".example"
|
||||
import NameConstraints.ncca:x:CT,C,C
|
||||
import NameConstraints.dcisscopy:x:CT,C,C
|
||||
import NameConstraints.ipaca:x:CT,C,C
|
||||
|
||||
# Intermediate 1: Name constrained to permited DNSName ".example"
|
||||
|
||||
|
|
@ -158,4 +159,12 @@ verify NameConstraints.dcissblocked:x
|
|||
verify NameConstraints.dcissallowed:x
|
||||
result pass
|
||||
|
||||
# Subject: "O = IPA.LOCAL 201901211552, CN = OCSP Subsystem"
|
||||
#
|
||||
# This tests that a non server certificate (i.e. id-kp-serverAuth
|
||||
# not present in EKU) does *NOT* have CN treated as dnsName for
|
||||
# purposes of Name Constraints validation
|
||||
verify NameConstraints.ocsp1:x
|
||||
usage 10
|
||||
result pass
|
||||
|
||||
|
|
|
|||
|
|
@ -83,7 +83,7 @@ gtest_cleanup()
|
|||
}
|
||||
|
||||
################## main #################################################
|
||||
GTESTS="prng_gtest certhigh_gtest certdb_gtest der_gtest pk11_gtest util_gtest freebl_gtest softoken_gtest blake2b_gtest"
|
||||
GTESTS="prng_gtest certhigh_gtest certdb_gtest der_gtest pk11_gtest util_gtest freebl_gtest softoken_gtest sysinit_gtest blake2b_gtest"
|
||||
SOURCE_DIR="$PWD"/../..
|
||||
gtest_init $0
|
||||
gtest_start
|
||||
|
|
|
|||
BIN
security/nss/tests/libpkix/certs/NameConstraints.ipaca.cert
Normal file
BIN
security/nss/tests/libpkix/certs/NameConstraints.ipaca.cert
Normal file
Binary file not shown.
BIN
security/nss/tests/libpkix/certs/NameConstraints.ocsp1.cert
Normal file
BIN
security/nss/tests/libpkix/certs/NameConstraints.ocsp1.cert
Normal file
Binary file not shown.
|
|
@ -71,9 +71,7 @@
|
|||
"name" : "test-tls13-legacy-version.py",
|
||||
"arguments": [
|
||||
"-p", "@PORT@"
|
||||
],
|
||||
"comment": "https://bugzilla.mozilla.org/show_bug.cgi?id=1490006",
|
||||
"exp_pass": false
|
||||
]
|
||||
},
|
||||
{
|
||||
"name" : "test-tls13-nociphers.py",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue