]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
[v9_10] timing safe memory comparisons
authorEvan Hunt <each@isc.org>
Tue, 18 Aug 2015 01:28:27 +0000 (18:28 -0700)
committerEvan Hunt <each@isc.org>
Tue, 18 Aug 2015 01:28:27 +0000 (18:28 -0700)
4183. [cleanup] Use timing-safe memory comparisons in cryptographic
code. Also, the timing-safe comparison functions have
been renamed to avoid possible confusion with
memcmp(). [RT #40148]

(cherry picked from commit 420a43c8d8028992a4e9c170022f97bfac689025)

21 files changed:
CHANGES
bin/dig/dighost.c
bin/dnssec/dnssec-signzone.c
bin/named/client.c
lib/dns/client.c
lib/dns/hmac_link.c
lib/dns/nsec3.c
lib/dns/opensslgost_link.c
lib/dns/opensslrsa_link.c
lib/dns/pkcs11dh_link.c
lib/dns/pkcs11dsa_link.c
lib/dns/pkcs11ecdsa_link.c
lib/dns/pkcs11gost_link.c
lib/dns/pkcs11rsa_link.c
lib/dns/spnego.c
lib/isc/hmacmd5.c
lib/isc/hmacsha.c
lib/isc/include/isc/safe.h
lib/isc/safe.c
lib/isc/tests/safe_test.c
lib/isccc/cc.c

diff --git a/CHANGES b/CHANGES
index f06b34dbc1e480f3a6a4382c8e8d14b71270542e..2d2caf7597a56de3931617dd8614ad269bc56bcc 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,8 @@
+4183.  [cleanup]       Use timing-safe memory comparisons in cryptographic
+                       code. Also, the timing-safe comparison functions have
+                       been renamed to avoid possible confusion with
+                       memcmp(). [RT #40148]
+
 4182.  [cleanup]       Use mnemonics for RR class and type comparisons.
                        [RT #40297]
 
index 447a5c1161afcd7440ec096728c602c2f785ecf5..ca82f8eafa960277d3adcdb3ba33c7cc3c1bfc81 100644 (file)
@@ -84,6 +84,7 @@
 #include <isc/print.h>
 #include <isc/random.h>
 #include <isc/result.h>
+#include <isc/safe.h>
 #include <isc/serial.h>
 #include <isc/sockaddr.h>
 #include <isc/string.h>
@@ -3422,7 +3423,7 @@ process_sit(dig_lookup_t *l, dns_message_t *msg,
 
        INSIST(msg->sitok == 0 && msg->sitbad == 0);
        if (optlen >= len && optlen >= 8U) {
-               if (memcmp(isc_buffer_current(optbuf), sit, 8) == 0) {
+               if (isc_safe_memequal(isc_buffer_current(optbuf), sit, 8)) {
                        msg->sitok = 1;
                } else {
                        printf(";; Warning: SIT client cookie mismatch\n");
index 1f52608b8f1a4bd9983425d11a4155a8ceb0f549..657a508b3415fe0f135f050584746c1e40f9ef9a 100644 (file)
@@ -52,6 +52,7 @@
 #include <isc/random.h>
 #include <isc/rwlock.h>
 #include <isc/serial.h>
+#include <isc/safe.h>
 #include <isc/stdio.h>
 #include <isc/stdlib.h>
 #include <isc/string.h>
@@ -765,7 +766,7 @@ hashlist_add_dns_name(hashlist_t *l, /*const*/ dns_name_t *name,
 
 static int
 hashlist_comp(const void *a, const void *b) {
-       return (memcmp(a, b, hash_length + 1));
+       return (isc_safe_memcompare(a, b, hash_length + 1));
 }
 
 static void
@@ -792,7 +793,7 @@ hashlist_hasdup(hashlist_t *l) {
                next += l->length;
                if (next[l->length-1] != 0)
                        continue;
-               if (memcmp(current, next, l->length - 1) == 0)
+               if (isc_safe_memequal(current, next, l->length - 1))
                        return (ISC_TRUE);
                current = next;
        }
@@ -2020,7 +2021,7 @@ nsec3clean(dns_name_t *name, dns_dbnode_t *node,
                if (exists && nsec3.hash == hashalg &&
                    nsec3.iterations == iterations &&
                    nsec3.salt_length == salt_len &&
-                   !memcmp(nsec3.salt, salt, salt_len))
+                   isc_safe_memequal(nsec3.salt, salt, salt_len))
                        continue;
                dns_rdatalist_init(&rdatalist);
                rdatalist.rdclass = rdata.rdclass;
@@ -2708,7 +2709,7 @@ set_nsec3params(isc_boolean_t update, isc_boolean_t set_salt,
 
        if (!update && set_salt) {
                if (salt_length != orig_saltlen ||
-                   memcmp(saltbuf, orig_salt, salt_length) != 0)
+                   !isc_safe_memequal(saltbuf, orig_salt, salt_length))
                        fatal("An NSEC3 chain exists with a different salt. "
                              "Use -u to update it.");
        } else if (!set_salt) {
index 973f412f54f75976459b7d33708a24445e669c51..683305c1510b831b48da94fb76ce6153c3ba6edf 100644 (file)
@@ -24,6 +24,7 @@
 #include <isc/print.h>
 #include <isc/queue.h>
 #include <isc/random.h>
+#include <isc/safe.h>
 #include <isc/serial.h>
 #include <isc/stats.h>
 #include <isc/stdio.h>
@@ -1716,7 +1717,7 @@ process_sit(ns_client_t *client, isc_buffer_t *buf, size_t optlen) {
        isc_buffer_init(&db, dbuf, sizeof(dbuf));
        compute_sit(client, when, nonce, &db);
 
-       if (memcmp(old, dbuf, SIT_SIZE) != 0) {
+       if (!isc_safe_memequal(old, dbuf, SIT_SIZE)) {
                isc_stats_increment(ns_g_server->nsstats,
                                    dns_nsstatscounter_sitnomatch);
                return;
index 04efc9af13c3a9cf4b25555874387f3476c61095..ea329c4622b7fa868a760045ea63c7a50134e9fd 100644 (file)
@@ -14,8 +14,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: client.c,v 1.14 2011/03/12 04:59:47 tbox Exp $ */
-
 #include <config.h>
 
 #include <stddef.h>
@@ -24,6 +22,7 @@
 #include <isc/buffer.h>
 #include <isc/mem.h>
 #include <isc/mutex.h>
+#include <isc/safe.h>
 #include <isc/sockaddr.h>
 #include <isc/socket.h>
 #include <isc/task.h>
index fad20a02d3db9dcd8335ba22c117c6654faea986..794ff866172709f853df6e0e895bef320d18e8db 100644 (file)
@@ -139,7 +139,7 @@ hmacmd5_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_MD5_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_MD5_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
@@ -424,7 +424,7 @@ hmacsha1_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA1_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA1_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
@@ -709,7 +709,7 @@ hmacsha224_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA224_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA224_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
@@ -996,7 +996,7 @@ hmacsha256_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA256_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA256_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
@@ -1283,7 +1283,7 @@ hmacsha384_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA384_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA384_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
@@ -1570,7 +1570,7 @@ hmacsha512_compare(const dst_key_t *key1, const dst_key_t *key2) {
        else if (hkey1 == NULL || hkey2 == NULL)
                return (ISC_FALSE);
 
-       if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA512_BLOCK_LENGTH))
+       if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA512_BLOCK_LENGTH))
                return (ISC_TRUE);
        else
                return (ISC_FALSE);
index ff1282b9beacab152f6fef768cf3426ef0dc2a2b..de49f25e1ce89e8d6c1d36490ded165684d385b6 100644 (file)
@@ -25,6 +25,7 @@
 #include <isc/log.h>
 #include <isc/string.h>
 #include <isc/util.h>
+#include <isc/safe.h>
 
 #include <dst/dst.h>
 
@@ -1925,7 +1926,7 @@ dns_nsec3_noexistnodata(dns_rdatatype_t type, dns_name_t* name,
         * Work out what this NSEC3 covers.
         * Inside (<0) or outside (>=0).
         */
-       scope = memcmp(owner, nsec3.next, nsec3.next_length);
+       scope = isc_safe_memcompare(owner, nsec3.next, nsec3.next_length);
 
        /*
         * Prepare to compute all the hashes.
@@ -1950,7 +1951,7 @@ dns_nsec3_noexistnodata(dns_rdatatype_t type, dns_name_t* name,
                        return (ISC_R_IGNORE);
                }
 
-               order = memcmp(hash, owner, length);
+               order = isc_safe_memcompare(hash, owner, length);
                if (first && order == 0) {
                        /*
                         * The hashes are the same.
index 23996487368846ce1c72dd5a00ee9a83893be423..8fcefe48787b9ee001213ae3910921f18ae862b6 100644 (file)
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id: opensslgost_link.c,v 1.5 2011/01/19 23:47:12 tbox Exp $ */
-
 #include <config.h>
 
 #if defined(OPENSSL) && defined(HAVE_OPENSSL_GOST)
 
 #include <isc/entropy.h>
 #include <isc/mem.h>
+#include <isc/safe.h>
 #include <isc/string.h>
 #include <isc/util.h>
 
@@ -308,7 +307,7 @@ opensslgost_todns(const dst_key_t *key, isc_buffer_t *data) {
        p = der;
        len = i2d_PUBKEY(pkey, &p);
        INSIST(len == sizeof(der));
-       INSIST(memcmp(gost_prefix, der, 37) == 0);
+       INSIST(isc_safe_memequal(gost_prefix, der, 37));
        memmove(r.base, der + 37, 64);
        isc_buffer_add(data, 64);
 
index 821ef6c259be61243d021cd834edc618f867d7fa..a6b5108c15249a82d2a806b5ffa45bbb4a63355f 100644 (file)
@@ -650,9 +650,10 @@ opensslrsa_verify2(dst_context_t *dctx, int maxbits, const isc_region_t *sig) {
                                                DST_R_VERIFYFAILURE));
                        if (status != (int)(prefixlen + digestlen))
                                return (DST_R_VERIFYFAILURE);
-                       if (memcmp(original, prefix, prefixlen))
+                       if (!isc_safe_memequal(original, prefix, prefixlen))
                                return (DST_R_VERIFYFAILURE);
-                       if (memcmp(original + prefixlen, digest, digestlen))
+                       if (!isc_safe_memequal(original + prefixlen,
+                                           digest, digestlen))
                                return (DST_R_VERIFYFAILURE);
                        status = 1;
                }
index 12e98ca94879b1e372158630784b1e7ae1a3a440..30ca03139894e1c9a48d9f3bdaca7bda8216f931 100644 (file)
@@ -276,7 +276,8 @@ pkcs11dh_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dh1, CKA_BASE);
@@ -285,7 +286,8 @@ pkcs11dh_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dh1, CKA_VALUE);
@@ -294,7 +296,8 @@ pkcs11dh_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dh1, CKA_VALUE2);
@@ -302,7 +305,8 @@ pkcs11dh_compare(const dst_key_t *key1, const dst_key_t *key2) {
        if (((attr1 != NULL) || (attr2 != NULL)) &&
            ((attr1 == NULL) || (attr2 == NULL) ||
             (attr1->ulValueLen != attr2->ulValueLen) ||
-            memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+            !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                               attr1->ulValueLen)))
                return (ISC_FALSE);
 
        if (!dh1->ontoken && !dh2->ontoken)
@@ -333,7 +337,8 @@ pkcs11dh_paramcompare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dh1, CKA_BASE);
@@ -342,7 +347,8 @@ pkcs11dh_paramcompare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        return (ISC_TRUE);
@@ -682,13 +688,13 @@ pkcs11dh_todns(const dst_key_t *key, isc_buffer_t *data) {
 
        isc_buffer_availableregion(data, &r);
 
-       if ((glen == 1) && (memcmp(pk11_dh_bn2, base, glen) == 0) &&
+       if ((glen == 1) && isc_safe_memequal(pk11_dh_bn2, base, glen) &&
            (((plen == sizeof(pk11_dh_bn768)) &&
-             (memcmp(pk11_dh_bn768, prime, plen) == 0)) ||
+             isc_safe_memequal(pk11_dh_bn768, prime, plen)) ||
             ((plen == sizeof(pk11_dh_bn1024)) &&
-             (memcmp(pk11_dh_bn1024, prime, plen) == 0)) ||
+             isc_safe_memequal(pk11_dh_bn1024, prime, plen)) ||
             ((plen == sizeof(pk11_dh_bn1536)) &&
-             (memcmp(pk11_dh_bn1536, prime, plen) == 0)))) {
+             isc_safe_memequal(pk11_dh_bn1536, prime, plen)))) {
                plen = 1;
                glen = 0;
        }
@@ -699,10 +705,11 @@ pkcs11dh_todns(const dst_key_t *key, isc_buffer_t *data) {
 
        uint16_toregion(plen, &r);
        if (plen == 1) {
-               if (memcmp(pk11_dh_bn768, prime, sizeof(pk11_dh_bn768)) == 0)
+               if (isc_safe_memequal(pk11_dh_bn768, prime,
+                                     sizeof(pk11_dh_bn768)))
                        *r.base = 1;
-               else if (memcmp(pk11_dh_bn1024, prime,
-                               sizeof(pk11_dh_bn1024)) == 0)
+               else if (isc_safe_memequal(pk11_dh_bn1024, prime,
+                                          sizeof(pk11_dh_bn1024)))
                        *r.base = 2;
                else
                        *r.base = 3;
@@ -819,7 +826,7 @@ pkcs11dh_fromdns(dst_key_t *key, isc_buffer_t *data) {
                }
                else {
                        base = r.base;
-                       if (memcmp(base, pk11_dh_bn2, glen) == 0) {
+                       if (isc_safe_memequal(base, pk11_dh_bn2, glen)) {
                                base = pk11_dh_bn2;
                                glen_ = sizeof(pk11_dh_bn2);
                        }
index 6b7d5f6752ba26c6533cc488cb10cd685838c454..7a0787c48d51f03496c43e5ece2096303f64339b 100644 (file)
@@ -14,8 +14,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id$ */
-
 #ifdef PKCS11CRYPTO
 
 #include <config.h>
@@ -443,7 +441,8 @@ pkcs11dsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dsa1, CKA_SUBPRIME);
@@ -452,7 +451,8 @@ pkcs11dsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dsa1, CKA_BASE);
@@ -461,7 +461,8 @@ pkcs11dsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dsa1, CKA_VALUE);
@@ -470,7 +471,8 @@ pkcs11dsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(dsa1, CKA_VALUE2);
@@ -478,7 +480,8 @@ pkcs11dsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
        if (((attr1 != NULL) || (attr2 != NULL)) &&
            ((attr1 == NULL) || (attr2 == NULL) ||
             (attr1->ulValueLen != attr2->ulValueLen) ||
-            memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+            !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                               attr1->ulValueLen)))
                return (ISC_FALSE);
 
        if (!dsa1->ontoken && !dsa2->ontoken)
index d57be91970a185568f9dd5c30c4ae0b14dc5c148..bca32b1cba61a792e6f893ed263bc2ff782f3598 100644 (file)
@@ -14,8 +14,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id$ */
-
 #include <config.h>
 
 #if defined(PKCS11CRYPTO) && defined(HAVE_PKCS11_ECDSA)
@@ -398,7 +396,8 @@ pkcs11ecdsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(ec1, CKA_EC_POINT);
@@ -407,7 +406,8 @@ pkcs11ecdsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(ec1, CKA_VALUE);
@@ -415,7 +415,8 @@ pkcs11ecdsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
        if (((attr1 != NULL) || (attr2 != NULL)) &&
            ((attr1 == NULL) || (attr2 == NULL) ||
             (attr1->ulValueLen != attr2->ulValueLen) ||
-            memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+            !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                               attr1->ulValueLen)))
                return (ISC_FALSE);
 
        if (!ec1->ontoken && !ec2->ontoken)
index 1816d734de2da3530c0e5333ecffe16608752ddb..ff728005f13aa9d9b0cc19e227bfa2556b9059b4 100644 (file)
@@ -14,8 +14,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id$ */
-
 #include <config.h>
 
 #if defined(PKCS11CRYPTO) && defined(HAVE_PKCS11_GOST)
@@ -444,7 +442,8 @@ pkcs11gost_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(gost1, CKA_VALUE2);
@@ -452,7 +451,8 @@ pkcs11gost_compare(const dst_key_t *key1, const dst_key_t *key2) {
        if (((attr1 != NULL) || (attr2 != NULL)) &&
            ((attr1 == NULL) || (attr2 == NULL) ||
             (attr1->ulValueLen != attr2->ulValueLen) ||
-            memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+            !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                               attr1->ulValueLen)))
                return (ISC_FALSE);
 
        if (!gost1->ontoken && !gost2->ontoken)
@@ -856,7 +856,7 @@ pkcs11gost_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
                        buf[36] += adj;
                        buf[38] += adj;
                }
-               if (memcmp(priv.elements[0].data, buf, 39) != 0)
+               if (!isc_safe_memequal(priv.elements[0].data, buf, 39))
                        DST_RET(DST_R_INVALIDPRIVATEKEY);
                priv.elements[0].tag = TAG_GOST_PRIVRAW;
                priv.elements[0].length -= 39;
index 4a443b1f8e76f14a7c1ed4a03fd695dbfeebc3f7..758a9d86b4b4622334023e2852c5b18aad96edc6 100644 (file)
@@ -506,7 +506,8 @@ pkcs11rsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(rsa1, CKA_PUBLIC_EXPONENT);
@@ -515,7 +516,8 @@ pkcs11rsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
                return (ISC_TRUE);
        else if ((attr1 == NULL) || (attr2 == NULL) ||
                 (attr1->ulValueLen != attr2->ulValueLen) ||
-                memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+                !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                                   attr1->ulValueLen))
                return (ISC_FALSE);
 
        attr1 = pk11_attribute_bytype(rsa1, CKA_PRIVATE_EXPONENT);
@@ -523,7 +525,8 @@ pkcs11rsa_compare(const dst_key_t *key1, const dst_key_t *key2) {
        if (((attr1 != NULL) || (attr2 != NULL)) &&
            ((attr1 == NULL) || (attr2 == NULL) ||
             (attr1->ulValueLen != attr2->ulValueLen) ||
-            memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+            !isc_safe_memequal(attr1->pValue, attr2->pValue,
+                               attr1->ulValueLen)))
                return (ISC_FALSE);
 
        if (!rsa1->ontoken && !rsa2->ontoken)
@@ -1177,7 +1180,7 @@ rsa_check(pk11_object_t *rsa, pk11_object_t *pubrsa) {
        if (priv_exp != NULL) {
                if (priv_explen != pub_explen)
                        return (DST_R_INVALIDPRIVATEKEY);
-               if (memcmp(priv_exp, pub_exp, pub_explen) != 0)
+               if (!isc_safe_memequal(priv_exp, pub_exp, pub_explen))
                        return (DST_R_INVALIDPRIVATEKEY);
        } else {
                privattr->pValue = pub_exp;
@@ -1202,7 +1205,7 @@ rsa_check(pk11_object_t *rsa, pk11_object_t *pubrsa) {
        if (priv_mod != NULL) {
                if (priv_modlen != pub_modlen)
                        return (DST_R_INVALIDPRIVATEKEY);
-               if (memcmp(priv_mod, pub_mod, pub_modlen) != 0)
+               if (!isc_safe_memequal(priv_mod, pub_mod, pub_modlen))
                        return (DST_R_INVALIDPRIVATEKEY);
        } else {
                privattr->pValue = pub_mod;
index 6ae1123018f61d911c3bb4f6c1efa9b0d3d82ed2..0de332fc6a6892ca33e98a3621a7ad8f3d68e744 100644 (file)
@@ -14,8 +14,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id$ */
-
 /*! \file
  * \brief
  * Portable SPNEGO implementation.
 #include <isc/mem.h>
 #include <isc/once.h>
 #include <isc/random.h>
+#include <isc/safe.h>
 #include <isc/string.h>
 #include <isc/time.h>
 #include <isc/util.h>
@@ -395,7 +394,7 @@ cmp_gss_type(gss_buffer_t token, gss_OID gssoid)
        if (((OM_uint32) *p++) != gssoid->length)
                return (GSS_S_DEFECTIVE_TOKEN);
 
-       return (memcmp(p, gssoid->elements, gssoid->length));
+       return (isc_safe_memcompare(p, gssoid->elements, gssoid->length));
 }
 
 /* accept_sec_context.c */
@@ -635,16 +634,18 @@ gss_accept_sec_context_spnego(OM_uint32 *minor_status,
                        return (GSS_S_DEFECTIVE_TOKEN);
                }
                if (mech_len == GSS_KRB5_MECH->length &&
-                   memcmp(GSS_KRB5_MECH->elements,
-                          mechbuf + sizeof(mechbuf) - mech_len,
-                          mech_len) == 0) {
+                   isc_safe_memequal(GSS_KRB5_MECH->elements,
+                                     mechbuf + sizeof(mechbuf) - mech_len,
+                                     mech_len))
+               {
                        found = 1;
                        break;
                }
                if (mech_len == GSS_MSKRB5_MECH->length &&
-                   memcmp(GSS_MSKRB5_MECH->elements,
-                          mechbuf + sizeof(mechbuf) - mech_len,
-                          mech_len) == 0) {
+                   isc_safe_memequal(GSS_MSKRB5_MECH->elements,
+                                     mechbuf + sizeof(mechbuf) - mech_len,
+                                     mech_len))
+               {
                        found = 1;
                        if (i == 0)
                                pref = GSS_MSKRB5_MECH;
@@ -715,7 +716,7 @@ gssapi_verify_mech_header(u_char ** str,
        p += foo;
        if (mech_len != mech->length)
                return (GSS_S_BAD_MECH);
-       if (memcmp(p, mech->elements, mech->length) != 0)
+       if (!isc_safe_memequal(p, mech->elements, mech->length))
                return (GSS_S_BAD_MECH);
        p += mech_len;
        *str = p;
@@ -1668,7 +1669,7 @@ spnego_reply(OM_uint32 *minor_status,
                buf = input_token->value;
                buf_size = input_token->length;
        } else if ((size_t)mech_len == GSS_KRB5_MECH->length &&
-                  memcmp(GSS_KRB5_MECH->elements, p, mech_len) == 0)
+                  isc_safe_memequal(GSS_KRB5_MECH->elements, p, mech_len))
                return (gss_init_sec_context(minor_status,
                                             initiator_cred_handle,
                                             context_handle,
@@ -1683,7 +1684,7 @@ spnego_reply(OM_uint32 *minor_status,
                                             ret_flags,
                                             time_rec));
        else if ((size_t)mech_len == GSS_SPNEGO_MECH->length &&
-                memcmp(GSS_SPNEGO_MECH->elements, p, mech_len) == 0) {
+                isc_safe_memequal(GSS_SPNEGO_MECH->elements, p, mech_len)) {
                ret = gssapi_spnego_decapsulate(minor_status,
                                                input_token,
                                                &buf,
@@ -1721,9 +1722,9 @@ spnego_reply(OM_uint32 *minor_status,
                          resp.supportedMech,
                          &oidlen);
        if (ret || oidlen != GSS_KRB5_MECH->length ||
-           memcmp(oidbuf + sizeof(oidbuf) - oidlen,
-                  GSS_KRB5_MECH->elements,
-                  oidlen) != 0) {
+           !isc_safe_memequal(oidbuf + sizeof(oidbuf) - oidlen,
+                             GSS_KRB5_MECH->elements, oidlen))
+       {
                free_NegTokenResp(&resp);
                return GSS_S_BAD_MECH;
        }
index 5f77323e6c0bf905a42d24b1c9b63469a8642dca..f2a0b11d9d40d41b25203be09ec7dbdb0d62d9e2 100644 (file)
@@ -326,5 +326,5 @@ isc_hmacmd5_verify2(isc_hmacmd5_t *ctx, unsigned char *digest, size_t len) {
 
        REQUIRE(len <= ISC_MD5_DIGESTLENGTH);
        isc_hmacmd5_sign(ctx, newdigest);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
index c03a27ac777bcf761cb4c38e05f09d745993d1c3..db42cda2950cab34dcd996eb150e37779b011c0b 100644 (file)
@@ -978,7 +978,7 @@ isc_hmacsha1_verify(isc_hmacsha1_t *ctx, unsigned char *digest, size_t len) {
 
        REQUIRE(len <= ISC_SHA1_DIGESTLENGTH);
        isc_hmacsha1_sign(ctx, newdigest, ISC_SHA1_DIGESTLENGTH);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
 
 /*
@@ -991,7 +991,7 @@ isc_hmacsha224_verify(isc_hmacsha224_t *ctx, unsigned char *digest, size_t len)
 
        REQUIRE(len <= ISC_SHA224_DIGESTLENGTH);
        isc_hmacsha224_sign(ctx, newdigest, ISC_SHA224_DIGESTLENGTH);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
 
 /*
@@ -1004,7 +1004,7 @@ isc_hmacsha256_verify(isc_hmacsha256_t *ctx, unsigned char *digest, size_t len)
 
        REQUIRE(len <= ISC_SHA256_DIGESTLENGTH);
        isc_hmacsha256_sign(ctx, newdigest, ISC_SHA256_DIGESTLENGTH);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
 
 /*
@@ -1017,7 +1017,7 @@ isc_hmacsha384_verify(isc_hmacsha384_t *ctx, unsigned char *digest, size_t len)
 
        REQUIRE(len <= ISC_SHA384_DIGESTLENGTH);
        isc_hmacsha384_sign(ctx, newdigest, ISC_SHA384_DIGESTLENGTH);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
 
 /*
@@ -1030,5 +1030,5 @@ isc_hmacsha512_verify(isc_hmacsha512_t *ctx, unsigned char *digest, size_t len)
 
        REQUIRE(len <= ISC_SHA512_DIGESTLENGTH);
        isc_hmacsha512_sign(ctx, newdigest, ISC_SHA512_DIGESTLENGTH);
-       return (isc_safe_memcmp(digest, newdigest, len));
+       return (isc_safe_memequal(digest, newdigest, len));
 }
index 89d56def73fdf7000bef158d46331c01ec458cd4..b2495e962fdfd0a3643eea9acf54c88d7aabf92b 100644 (file)
 ISC_LANG_BEGINDECLS
 
 isc_boolean_t
-isc_safe_memcmp(const void *s1, const void *s2, size_t n);
+isc_safe_memequal(const void *s1, const void *s2, size_t n);
 /*%<
- * Clone of libc memcmp() safe to differential timing attacks.
+ * Returns ISC_TRUE iff. two blocks of memory are equal, otherwise
+ * ISC_FALSE.
+ *
+ */
+
+int
+isc_safe_memcompare(const void *b1, const void *b2, size_t len);
+/*%<
+ * Clone of libc memcmp() which is safe to differential timing attacks.
  */
 
 ISC_LANG_ENDDECLS
index fd27687188722c1ab6da79089143228d58b78239..a6d010ff649e7f17fc56c235d50edee66c1eeebb 100644 (file)
@@ -1,5 +1,6 @@
 /*
- * Copyright (C) 2013  Internet Systems Consortium, Inc. ("ISC")
+ * Copyright (C) 2013, 2015  Internet Systems Consortium, Inc. ("ISC")
+ * Copyright (c) 2014 Google Inc.
  *
  * Permission to use, copy, modify, and/or distribute this software for any
  * purpose with or without fee is hereby granted, provided that the above
@@ -14,8 +15,6 @@
  * PERFORMANCE OF THIS SOFTWARE.
  */
 
-/* $Id$ */
-
 /*! \file */
 
 #include <config.h>
@@ -28,7 +27,7 @@
 #endif
 
 isc_boolean_t
-isc_safe_memcmp(const void *s1, const void *s2, size_t n) {
+isc_safe_memequal(const void *s1, const void *s2, size_t n) {
        isc_uint8_t acc = 0;
 
        if (n != 0U) {
@@ -40,3 +39,30 @@ isc_safe_memcmp(const void *s1, const void *s2, size_t n) {
        }
        return (ISC_TF(acc == 0));
 }
+
+
+int
+isc_safe_memcompare(const void *b1, const void *b2, size_t len) {
+        const unsigned char *p1 = b1, *p2 = b2;
+        size_t i;
+        int res = 0, done = 0;
+
+        for (i = 0; i < len; i++) {
+                /* lt is -1 if p1[i] < p2[i]; else 0. */
+                int lt = (p1[i] - p2[i]) >> CHAR_BIT;
+
+                /* gt is -1 if p1[i] > p2[i]; else 0. */
+                int gt = (p2[i] - p1[i]) >> CHAR_BIT;
+
+                /* cmp is 1 if p1[i] > p2[i]; -1 if p1[i] < p2[i]; else 0. */
+                int cmp = lt - gt;
+
+                /* set res = cmp if !done. */
+                res |= cmp & ~done;
+
+                /* set done if p1[i] != p2[i]. */
+                done |= lt | gt;
+        }
+
+        return (res);
+}
index 7b7ac39926e39a71ae240478141863191c8112c0..113ec8efc5b35890997189fba070bef75d24b098 100644 (file)
 #include <isc/safe.h>
 #include <isc/util.h>
 
-ATF_TC(isc_safe_memcmp);
-ATF_TC_HEAD(isc_safe_memcmp, tc) {
-       atf_tc_set_md_var(tc, "descr", "safe memcmp()");
+ATF_TC(isc_safe_memequal);
+ATF_TC_HEAD(isc_safe_memequal, tc) {
+       atf_tc_set_md_var(tc, "descr", "safe memequal()");
 }
-ATF_TC_BODY(isc_safe_memcmp, tc) {
+ATF_TC_BODY(isc_safe_memequal, tc) {
        UNUSED(tc);
 
-       ATF_CHECK(isc_safe_memcmp("test", "test", 4));
-       ATF_CHECK(!isc_safe_memcmp("test", "tesc", 4));
-       ATF_CHECK(isc_safe_memcmp("\x00\x00\x00\x00", "\x00\x00\x00\x00", 4));
-       ATF_CHECK(!isc_safe_memcmp("\x00\x00\x00\x00", "\x00\x00\x00\x01", 4));
-       ATF_CHECK(!isc_safe_memcmp("\x00\x00\x00\x02", "\x00\x00\x00\x00", 4));
+       ATF_CHECK(isc_safe_memequal("test", "test", 4));
+       ATF_CHECK(!isc_safe_memequal("test", "tesc", 4));
+       ATF_CHECK(isc_safe_memequal("\x00\x00\x00\x00",
+                                   "\x00\x00\x00\x00", 4));
+       ATF_CHECK(!isc_safe_memequal("\x00\x00\x00\x00",
+                                    "\x00\x00\x00\x01", 4));
+       ATF_CHECK(!isc_safe_memequal("\x00\x00\x00\x02",
+                                    "\x00\x00\x00\x00", 4));
+}
+
+ATF_TC(isc_safe_memcompare);
+ATF_TC_HEAD(isc_safe_memcompare, tc) {
+       atf_tc_set_md_var(tc, "descr", "safe memcompare()");
+}
+ATF_TC_BODY(isc_safe_memcompare, tc) {
+       UNUSED(tc);
+
+       ATF_CHECK(isc_safe_memcompare("test", "test", 4) == 0);
+       ATF_CHECK(isc_safe_memcompare("test", "tesc", 4) > 0);
+       ATF_CHECK(isc_safe_memcompare("test", "tesy", 4) < 0);
+       ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x00",
+                                     "\x00\x00\x00\x00", 4) == 0);
+       ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x00",
+                                     "\x00\x00\x00\x01", 4) < 0);
+       ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x02",
+                                     "\x00\x00\x00\x00", 4) > 0);
 }
 
 /*
  * Main
  */
 ATF_TP_ADD_TCS(tp) {
-       ATF_TP_ADD_TC(tp, isc_safe_memcmp);
+       ATF_TP_ADD_TC(tp, isc_safe_memequal);
+       ATF_TP_ADD_TC(tp, isc_safe_memcompare);
        return (atf_no_error());
 }
-
index 5163ab102563e9c0814aec65143c0fc706a05997..47a3b74c85cbe519f04db5094302b22f60f39080 100644 (file)
@@ -487,7 +487,7 @@ verify(isccc_sexpr_t *alist, unsigned char *data, unsigned int length,
                unsigned char *value;
 
                value = (unsigned char *) isccc_sexpr_tostring(hmac);
-               if (!isc_safe_memcmp(value, digestb64, HMD5_LENGTH))
+               if (!isc_safe_memequal(value, digestb64, HMD5_LENGTH))
                        return (ISCCC_R_BADAUTH);
        } else {
                unsigned char *value;
@@ -496,7 +496,7 @@ verify(isccc_sexpr_t *alist, unsigned char *data, unsigned int length,
                value = (unsigned char *) isccc_sexpr_tostring(hmac);
                GET8(valalg, value);
                if ((valalg != algorithm) ||
-                   (!isc_safe_memcmp(value, digestb64, HSHA_LENGTH)))
+                   !isc_safe_memequal(value, digestb64, HSHA_LENGTH))
                        return (ISCCC_R_BADAUTH);
        }