+4183. [cleanup] Use timing-safe memory comparisons in cryptographic
+ code. Also, the timing-safe comparison functions have
+ been renamed to avoid possible confusion with
+ memcmp(). [RT #40148]
+
4182. [cleanup] Use mnemonics for RR class and type comparisons.
[RT #40297]
#include <isc/print.h>
#include <isc/random.h>
#include <isc/result.h>
+#include <isc/safe.h>
#include <isc/serial.h>
#include <isc/sockaddr.h>
#include <isc/string.h>
INSIST(msg->sitok == 0 && msg->sitbad == 0);
if (optlen >= len && optlen >= 8U) {
- if (memcmp(isc_buffer_current(optbuf), sit, 8) == 0) {
+ if (isc_safe_memequal(isc_buffer_current(optbuf), sit, 8)) {
msg->sitok = 1;
} else {
printf(";; Warning: SIT client cookie mismatch\n");
#include <isc/random.h>
#include <isc/rwlock.h>
#include <isc/serial.h>
+#include <isc/safe.h>
#include <isc/stdio.h>
#include <isc/stdlib.h>
#include <isc/string.h>
static int
hashlist_comp(const void *a, const void *b) {
- return (memcmp(a, b, hash_length + 1));
+ return (isc_safe_memcompare(a, b, hash_length + 1));
}
static void
next += l->length;
if (next[l->length-1] != 0)
continue;
- if (memcmp(current, next, l->length - 1) == 0)
+ if (isc_safe_memequal(current, next, l->length - 1))
return (ISC_TRUE);
current = next;
}
if (exists && nsec3.hash == hashalg &&
nsec3.iterations == iterations &&
nsec3.salt_length == salt_len &&
- !memcmp(nsec3.salt, salt, salt_len))
+ isc_safe_memequal(nsec3.salt, salt, salt_len))
continue;
dns_rdatalist_init(&rdatalist);
rdatalist.rdclass = rdata.rdclass;
if (!update && set_salt) {
if (salt_length != orig_saltlen ||
- memcmp(saltbuf, orig_salt, salt_length) != 0)
+ !isc_safe_memequal(saltbuf, orig_salt, salt_length))
fatal("An NSEC3 chain exists with a different salt. "
"Use -u to update it.");
} else if (!set_salt) {
#include <isc/print.h>
#include <isc/queue.h>
#include <isc/random.h>
+#include <isc/safe.h>
#include <isc/serial.h>
#include <isc/stats.h>
#include <isc/stdio.h>
isc_buffer_init(&db, dbuf, sizeof(dbuf));
compute_sit(client, when, nonce, &db);
- if (memcmp(old, dbuf, SIT_SIZE) != 0) {
+ if (!isc_safe_memequal(old, dbuf, SIT_SIZE)) {
isc_stats_increment(ns_g_server->nsstats,
dns_nsstatscounter_sitnomatch);
return;
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id: client.c,v 1.14 2011/03/12 04:59:47 tbox Exp $ */
-
#include <config.h>
#include <stddef.h>
#include <isc/buffer.h>
#include <isc/mem.h>
#include <isc/mutex.h>
+#include <isc/safe.h>
#include <isc/sockaddr.h>
#include <isc/socket.h>
#include <isc/task.h>
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_MD5_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_MD5_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA1_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA1_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA224_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA224_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA256_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA256_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA384_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA384_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
else if (hkey1 == NULL || hkey2 == NULL)
return (ISC_FALSE);
- if (isc_safe_memcmp(hkey1->key, hkey2->key, ISC_SHA512_BLOCK_LENGTH))
+ if (isc_safe_memequal(hkey1->key, hkey2->key, ISC_SHA512_BLOCK_LENGTH))
return (ISC_TRUE);
else
return (ISC_FALSE);
#include <isc/log.h>
#include <isc/string.h>
#include <isc/util.h>
+#include <isc/safe.h>
#include <dst/dst.h>
* Work out what this NSEC3 covers.
* Inside (<0) or outside (>=0).
*/
- scope = memcmp(owner, nsec3.next, nsec3.next_length);
+ scope = isc_safe_memcompare(owner, nsec3.next, nsec3.next_length);
/*
* Prepare to compute all the hashes.
return (ISC_R_IGNORE);
}
- order = memcmp(hash, owner, length);
+ order = isc_safe_memcompare(hash, owner, length);
if (first && order == 0) {
/*
* The hashes are the same.
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id: opensslgost_link.c,v 1.5 2011/01/19 23:47:12 tbox Exp $ */
-
#include <config.h>
#if defined(OPENSSL) && defined(HAVE_OPENSSL_GOST)
#include <isc/entropy.h>
#include <isc/mem.h>
+#include <isc/safe.h>
#include <isc/string.h>
#include <isc/util.h>
p = der;
len = i2d_PUBKEY(pkey, &p);
INSIST(len == sizeof(der));
- INSIST(memcmp(gost_prefix, der, 37) == 0);
+ INSIST(isc_safe_memequal(gost_prefix, der, 37));
memmove(r.base, der + 37, 64);
isc_buffer_add(data, 64);
DST_R_VERIFYFAILURE));
if (status != (int)(prefixlen + digestlen))
return (DST_R_VERIFYFAILURE);
- if (memcmp(original, prefix, prefixlen))
+ if (!isc_safe_memequal(original, prefix, prefixlen))
return (DST_R_VERIFYFAILURE);
- if (memcmp(original + prefixlen, digest, digestlen))
+ if (!isc_safe_memequal(original + prefixlen,
+ digest, digestlen))
return (DST_R_VERIFYFAILURE);
status = 1;
}
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dh1, CKA_BASE);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dh1, CKA_VALUE);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dh1, CKA_VALUE2);
if (((attr1 != NULL) || (attr2 != NULL)) &&
((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen)))
return (ISC_FALSE);
if (!dh1->ontoken && !dh2->ontoken)
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dh1, CKA_BASE);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
return (ISC_TRUE);
isc_buffer_availableregion(data, &r);
- if ((glen == 1) && (memcmp(pk11_dh_bn2, base, glen) == 0) &&
+ if ((glen == 1) && isc_safe_memequal(pk11_dh_bn2, base, glen) &&
(((plen == sizeof(pk11_dh_bn768)) &&
- (memcmp(pk11_dh_bn768, prime, plen) == 0)) ||
+ isc_safe_memequal(pk11_dh_bn768, prime, plen)) ||
((plen == sizeof(pk11_dh_bn1024)) &&
- (memcmp(pk11_dh_bn1024, prime, plen) == 0)) ||
+ isc_safe_memequal(pk11_dh_bn1024, prime, plen)) ||
((plen == sizeof(pk11_dh_bn1536)) &&
- (memcmp(pk11_dh_bn1536, prime, plen) == 0)))) {
+ isc_safe_memequal(pk11_dh_bn1536, prime, plen)))) {
plen = 1;
glen = 0;
}
uint16_toregion(plen, &r);
if (plen == 1) {
- if (memcmp(pk11_dh_bn768, prime, sizeof(pk11_dh_bn768)) == 0)
+ if (isc_safe_memequal(pk11_dh_bn768, prime,
+ sizeof(pk11_dh_bn768)))
*r.base = 1;
- else if (memcmp(pk11_dh_bn1024, prime,
- sizeof(pk11_dh_bn1024)) == 0)
+ else if (isc_safe_memequal(pk11_dh_bn1024, prime,
+ sizeof(pk11_dh_bn1024)))
*r.base = 2;
else
*r.base = 3;
}
else {
base = r.base;
- if (memcmp(base, pk11_dh_bn2, glen) == 0) {
+ if (isc_safe_memequal(base, pk11_dh_bn2, glen)) {
base = pk11_dh_bn2;
glen_ = sizeof(pk11_dh_bn2);
}
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id$ */
-
#ifdef PKCS11CRYPTO
#include <config.h>
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dsa1, CKA_SUBPRIME);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dsa1, CKA_BASE);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dsa1, CKA_VALUE);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(dsa1, CKA_VALUE2);
if (((attr1 != NULL) || (attr2 != NULL)) &&
((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen)))
return (ISC_FALSE);
if (!dsa1->ontoken && !dsa2->ontoken)
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id$ */
-
#include <config.h>
#if defined(PKCS11CRYPTO) && defined(HAVE_PKCS11_ECDSA)
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(ec1, CKA_EC_POINT);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(ec1, CKA_VALUE);
if (((attr1 != NULL) || (attr2 != NULL)) &&
((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen)))
return (ISC_FALSE);
if (!ec1->ontoken && !ec2->ontoken)
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id$ */
-
#include <config.h>
#if defined(PKCS11CRYPTO) && defined(HAVE_PKCS11_GOST)
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(gost1, CKA_VALUE2);
if (((attr1 != NULL) || (attr2 != NULL)) &&
((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen)))
return (ISC_FALSE);
if (!gost1->ontoken && !gost2->ontoken)
buf[36] += adj;
buf[38] += adj;
}
- if (memcmp(priv.elements[0].data, buf, 39) != 0)
+ if (!isc_safe_memequal(priv.elements[0].data, buf, 39))
DST_RET(DST_R_INVALIDPRIVATEKEY);
priv.elements[0].tag = TAG_GOST_PRIVRAW;
priv.elements[0].length -= 39;
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(rsa1, CKA_PUBLIC_EXPONENT);
return (ISC_TRUE);
else if ((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen))
return (ISC_FALSE);
attr1 = pk11_attribute_bytype(rsa1, CKA_PRIVATE_EXPONENT);
if (((attr1 != NULL) || (attr2 != NULL)) &&
((attr1 == NULL) || (attr2 == NULL) ||
(attr1->ulValueLen != attr2->ulValueLen) ||
- memcmp(attr1->pValue, attr2->pValue, attr1->ulValueLen)))
+ !isc_safe_memequal(attr1->pValue, attr2->pValue,
+ attr1->ulValueLen)))
return (ISC_FALSE);
if (!rsa1->ontoken && !rsa2->ontoken)
if (priv_exp != NULL) {
if (priv_explen != pub_explen)
return (DST_R_INVALIDPRIVATEKEY);
- if (memcmp(priv_exp, pub_exp, pub_explen) != 0)
+ if (!isc_safe_memequal(priv_exp, pub_exp, pub_explen))
return (DST_R_INVALIDPRIVATEKEY);
} else {
privattr->pValue = pub_exp;
if (priv_mod != NULL) {
if (priv_modlen != pub_modlen)
return (DST_R_INVALIDPRIVATEKEY);
- if (memcmp(priv_mod, pub_mod, pub_modlen) != 0)
+ if (!isc_safe_memequal(priv_mod, pub_mod, pub_modlen))
return (DST_R_INVALIDPRIVATEKEY);
} else {
privattr->pValue = pub_mod;
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id$ */
-
/*! \file
* \brief
* Portable SPNEGO implementation.
#include <isc/mem.h>
#include <isc/once.h>
#include <isc/random.h>
+#include <isc/safe.h>
#include <isc/string.h>
#include <isc/time.h>
#include <isc/util.h>
if (((OM_uint32) *p++) != gssoid->length)
return (GSS_S_DEFECTIVE_TOKEN);
- return (memcmp(p, gssoid->elements, gssoid->length));
+ return (isc_safe_memcompare(p, gssoid->elements, gssoid->length));
}
/* accept_sec_context.c */
return (GSS_S_DEFECTIVE_TOKEN);
}
if (mech_len == GSS_KRB5_MECH->length &&
- memcmp(GSS_KRB5_MECH->elements,
- mechbuf + sizeof(mechbuf) - mech_len,
- mech_len) == 0) {
+ isc_safe_memequal(GSS_KRB5_MECH->elements,
+ mechbuf + sizeof(mechbuf) - mech_len,
+ mech_len))
+ {
found = 1;
break;
}
if (mech_len == GSS_MSKRB5_MECH->length &&
- memcmp(GSS_MSKRB5_MECH->elements,
- mechbuf + sizeof(mechbuf) - mech_len,
- mech_len) == 0) {
+ isc_safe_memequal(GSS_MSKRB5_MECH->elements,
+ mechbuf + sizeof(mechbuf) - mech_len,
+ mech_len))
+ {
found = 1;
if (i == 0)
pref = GSS_MSKRB5_MECH;
p += foo;
if (mech_len != mech->length)
return (GSS_S_BAD_MECH);
- if (memcmp(p, mech->elements, mech->length) != 0)
+ if (!isc_safe_memequal(p, mech->elements, mech->length))
return (GSS_S_BAD_MECH);
p += mech_len;
*str = p;
buf = input_token->value;
buf_size = input_token->length;
} else if ((size_t)mech_len == GSS_KRB5_MECH->length &&
- memcmp(GSS_KRB5_MECH->elements, p, mech_len) == 0)
+ isc_safe_memequal(GSS_KRB5_MECH->elements, p, mech_len))
return (gss_init_sec_context(minor_status,
initiator_cred_handle,
context_handle,
ret_flags,
time_rec));
else if ((size_t)mech_len == GSS_SPNEGO_MECH->length &&
- memcmp(GSS_SPNEGO_MECH->elements, p, mech_len) == 0) {
+ isc_safe_memequal(GSS_SPNEGO_MECH->elements, p, mech_len)) {
ret = gssapi_spnego_decapsulate(minor_status,
input_token,
&buf,
resp.supportedMech,
&oidlen);
if (ret || oidlen != GSS_KRB5_MECH->length ||
- memcmp(oidbuf + sizeof(oidbuf) - oidlen,
- GSS_KRB5_MECH->elements,
- oidlen) != 0) {
+ !isc_safe_memequal(oidbuf + sizeof(oidbuf) - oidlen,
+ GSS_KRB5_MECH->elements, oidlen))
+ {
free_NegTokenResp(&resp);
return GSS_S_BAD_MECH;
}
REQUIRE(len <= ISC_MD5_DIGESTLENGTH);
isc_hmacmd5_sign(ctx, newdigest);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
REQUIRE(len <= ISC_SHA1_DIGESTLENGTH);
isc_hmacsha1_sign(ctx, newdigest, ISC_SHA1_DIGESTLENGTH);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
/*
REQUIRE(len <= ISC_SHA224_DIGESTLENGTH);
isc_hmacsha224_sign(ctx, newdigest, ISC_SHA224_DIGESTLENGTH);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
/*
REQUIRE(len <= ISC_SHA256_DIGESTLENGTH);
isc_hmacsha256_sign(ctx, newdigest, ISC_SHA256_DIGESTLENGTH);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
/*
REQUIRE(len <= ISC_SHA384_DIGESTLENGTH);
isc_hmacsha384_sign(ctx, newdigest, ISC_SHA384_DIGESTLENGTH);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
/*
REQUIRE(len <= ISC_SHA512_DIGESTLENGTH);
isc_hmacsha512_sign(ctx, newdigest, ISC_SHA512_DIGESTLENGTH);
- return (isc_safe_memcmp(digest, newdigest, len));
+ return (isc_safe_memequal(digest, newdigest, len));
}
ISC_LANG_BEGINDECLS
isc_boolean_t
-isc_safe_memcmp(const void *s1, const void *s2, size_t n);
+isc_safe_memequal(const void *s1, const void *s2, size_t n);
/*%<
- * Clone of libc memcmp() safe to differential timing attacks.
+ * Returns ISC_TRUE iff. two blocks of memory are equal, otherwise
+ * ISC_FALSE.
+ *
+ */
+
+int
+isc_safe_memcompare(const void *b1, const void *b2, size_t len);
+/*%<
+ * Clone of libc memcmp() which is safe to differential timing attacks.
*/
ISC_LANG_ENDDECLS
/*
- * Copyright (C) 2013 Internet Systems Consortium, Inc. ("ISC")
+ * Copyright (C) 2013, 2015 Internet Systems Consortium, Inc. ("ISC")
+ * Copyright (c) 2014 Google Inc.
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* PERFORMANCE OF THIS SOFTWARE.
*/
-/* $Id$ */
-
/*! \file */
#include <config.h>
#endif
isc_boolean_t
-isc_safe_memcmp(const void *s1, const void *s2, size_t n) {
+isc_safe_memequal(const void *s1, const void *s2, size_t n) {
isc_uint8_t acc = 0;
if (n != 0U) {
}
return (ISC_TF(acc == 0));
}
+
+
+int
+isc_safe_memcompare(const void *b1, const void *b2, size_t len) {
+ const unsigned char *p1 = b1, *p2 = b2;
+ size_t i;
+ int res = 0, done = 0;
+
+ for (i = 0; i < len; i++) {
+ /* lt is -1 if p1[i] < p2[i]; else 0. */
+ int lt = (p1[i] - p2[i]) >> CHAR_BIT;
+
+ /* gt is -1 if p1[i] > p2[i]; else 0. */
+ int gt = (p2[i] - p1[i]) >> CHAR_BIT;
+
+ /* cmp is 1 if p1[i] > p2[i]; -1 if p1[i] < p2[i]; else 0. */
+ int cmp = lt - gt;
+
+ /* set res = cmp if !done. */
+ res |= cmp & ~done;
+
+ /* set done if p1[i] != p2[i]. */
+ done |= lt | gt;
+ }
+
+ return (res);
+}
#include <isc/safe.h>
#include <isc/util.h>
-ATF_TC(isc_safe_memcmp);
-ATF_TC_HEAD(isc_safe_memcmp, tc) {
- atf_tc_set_md_var(tc, "descr", "safe memcmp()");
+ATF_TC(isc_safe_memequal);
+ATF_TC_HEAD(isc_safe_memequal, tc) {
+ atf_tc_set_md_var(tc, "descr", "safe memequal()");
}
-ATF_TC_BODY(isc_safe_memcmp, tc) {
+ATF_TC_BODY(isc_safe_memequal, tc) {
UNUSED(tc);
- ATF_CHECK(isc_safe_memcmp("test", "test", 4));
- ATF_CHECK(!isc_safe_memcmp("test", "tesc", 4));
- ATF_CHECK(isc_safe_memcmp("\x00\x00\x00\x00", "\x00\x00\x00\x00", 4));
- ATF_CHECK(!isc_safe_memcmp("\x00\x00\x00\x00", "\x00\x00\x00\x01", 4));
- ATF_CHECK(!isc_safe_memcmp("\x00\x00\x00\x02", "\x00\x00\x00\x00", 4));
+ ATF_CHECK(isc_safe_memequal("test", "test", 4));
+ ATF_CHECK(!isc_safe_memequal("test", "tesc", 4));
+ ATF_CHECK(isc_safe_memequal("\x00\x00\x00\x00",
+ "\x00\x00\x00\x00", 4));
+ ATF_CHECK(!isc_safe_memequal("\x00\x00\x00\x00",
+ "\x00\x00\x00\x01", 4));
+ ATF_CHECK(!isc_safe_memequal("\x00\x00\x00\x02",
+ "\x00\x00\x00\x00", 4));
+}
+
+ATF_TC(isc_safe_memcompare);
+ATF_TC_HEAD(isc_safe_memcompare, tc) {
+ atf_tc_set_md_var(tc, "descr", "safe memcompare()");
+}
+ATF_TC_BODY(isc_safe_memcompare, tc) {
+ UNUSED(tc);
+
+ ATF_CHECK(isc_safe_memcompare("test", "test", 4) == 0);
+ ATF_CHECK(isc_safe_memcompare("test", "tesc", 4) > 0);
+ ATF_CHECK(isc_safe_memcompare("test", "tesy", 4) < 0);
+ ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x00",
+ "\x00\x00\x00\x00", 4) == 0);
+ ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x00",
+ "\x00\x00\x00\x01", 4) < 0);
+ ATF_CHECK(isc_safe_memcompare("\x00\x00\x00\x02",
+ "\x00\x00\x00\x00", 4) > 0);
}
/*
* Main
*/
ATF_TP_ADD_TCS(tp) {
- ATF_TP_ADD_TC(tp, isc_safe_memcmp);
+ ATF_TP_ADD_TC(tp, isc_safe_memequal);
+ ATF_TP_ADD_TC(tp, isc_safe_memcompare);
return (atf_no_error());
}
-
unsigned char *value;
value = (unsigned char *) isccc_sexpr_tostring(hmac);
- if (!isc_safe_memcmp(value, digestb64, HMD5_LENGTH))
+ if (!isc_safe_memequal(value, digestb64, HMD5_LENGTH))
return (ISCCC_R_BADAUTH);
} else {
unsigned char *value;
value = (unsigned char *) isccc_sexpr_tostring(hmac);
GET8(valalg, value);
if ((valalg != algorithm) ||
- (!isc_safe_memcmp(value, digestb64, HSHA_LENGTH)))
+ !isc_safe_memequal(value, digestb64, HSHA_LENGTH))
return (ISCCC_R_BADAUTH);
}