2 * Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 #include "../ssl_local.h"
12 #include <openssl/trace.h>
13 #include <openssl/rand.h>
14 #include <openssl/core_names.h>
15 #include "record_local.h"
16 #include "internal/cryptlib.h"
18 void SSL3_RECORD_release(SSL3_RECORD
*r
, size_t num_recs
)
22 for (i
= 0; i
< num_recs
; i
++) {
23 OPENSSL_free(r
[i
].comp
);
28 void SSL3_RECORD_set_seq_num(SSL3_RECORD
*r
, const unsigned char *seq_num
)
30 memcpy(r
->seq_num
, seq_num
, SEQ_NUM_SIZE
);
33 uint32_t ossl_get_max_early_data(SSL_CONNECTION
*s
)
35 uint32_t max_early_data
;
36 SSL_SESSION
*sess
= s
->session
;
39 * If we are a client then we always use the max_early_data from the
40 * session/psksession. Otherwise we go with the lowest out of the max early
41 * data set in the session and the configured max_early_data.
43 if (!s
->server
&& sess
->ext
.max_early_data
== 0) {
44 if (!ossl_assert(s
->psksession
!= NULL
45 && s
->psksession
->ext
.max_early_data
> 0)) {
46 SSLfatal(s
, SSL_AD_INTERNAL_ERROR
, ERR_R_INTERNAL_ERROR
);
53 max_early_data
= sess
->ext
.max_early_data
;
54 else if (s
->ext
.early_data
!= SSL_EARLY_DATA_ACCEPTED
)
55 max_early_data
= s
->recv_max_early_data
;
57 max_early_data
= s
->recv_max_early_data
< sess
->ext
.max_early_data
58 ? s
->recv_max_early_data
: sess
->ext
.max_early_data
;
60 return max_early_data
;
63 int ossl_early_data_count_ok(SSL_CONNECTION
*s
, size_t length
, size_t overhead
,
66 uint32_t max_early_data
;
68 max_early_data
= ossl_get_max_early_data(s
);
70 if (max_early_data
== 0) {
71 SSLfatal(s
, send
? SSL_AD_INTERNAL_ERROR
: SSL_AD_UNEXPECTED_MESSAGE
,
72 SSL_R_TOO_MUCH_EARLY_DATA
);
76 /* If we are dealing with ciphertext we need to allow for the overhead */
77 max_early_data
+= overhead
;
79 if (s
->early_data_count
+ length
> max_early_data
) {
80 SSLfatal(s
, send
? SSL_AD_INTERNAL_ERROR
: SSL_AD_UNEXPECTED_MESSAGE
,
81 SSL_R_TOO_MUCH_EARLY_DATA
);
84 s
->early_data_count
+= length
;