Skip to content

Commit f6cb914

Browse files
committed
conformance check: emit alert if non-zero padding
1 parent ccd37b9 commit f6cb914

2 files changed

Lines changed: 10 additions & 17 deletions

File tree

‎ssl/ech/ech_internal.c‎

Lines changed: 9 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1739,7 +1739,7 @@ static unsigned char *hpke_decrypt_encch(SSL_CONNECTION *s,
17391739
size_t aad_len, unsigned char *aad,
17401740
int forhrr, size_t *innerlen)
17411741
{
1742-
size_t cipherlen = 0;
1742+
size_t cipherlen = 0, zind = 0;
17431743
unsigned char *cipher = NULL;
17441744
size_t senderpublen = 0;
17451745
unsigned char *senderpub = NULL;
@@ -1876,24 +1876,18 @@ static unsigned char *hpke_decrypt_encch(SSL_CONNECTION *s,
18761876
SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION);
18771877
goto paderr;
18781878
}
1879-
/*
1880-
* The RFC calls for that padding to be all zeros. I'm not so
1881-
* keen on that being a good idea to enforce, so we'll make it
1882-
* easy to not do so (but check by default)
1883-
*/
1884-
#define CHECKZEROS
1885-
#ifdef CHECKZEROS
1886-
{
1887-
size_t zind = 0;
1879+
/* The RFC calls for that padding to be all zeros */
18881880

1889-
if (*innerlen < ch_len)
1881+
if (*innerlen < ch_len) {
1882+
SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION);
1883+
goto paderr;
1884+
}
1885+
for (zind = ch_len; zind != *innerlen; zind++) {
1886+
if (clear[zind] != 0x00) {
1887+
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION);
18901888
goto paderr;
1891-
for (zind = ch_len; zind != *innerlen; zind++) {
1892-
if (clear[zind] != 0x00)
1893-
goto paderr;
18941889
}
18951890
}
1896-
#endif
18971891
*innerlen = ch_len;
18981892
#ifdef OSSL_ECH_SUPERVERBOSE
18991893
ossl_ech_pbuf("unpadded clear", clear, *innerlen);

‎test/ech_corrupt_test.c‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -495,8 +495,7 @@ static TEST_ECHINNER test_inners[] = {
495495
encoded_inner_outers, sizeof(encoded_inner_outers),
496496
bad_pad_encoded_inner_post, sizeof(bad_pad_encoded_inner_post),
497497
0, /* expected result */
498-
SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC },
499-
498+
SSL_R_TLS_ALERT_ILLEGAL_PARAMETER },
500499
/*
501500
* 6. unsupported extension instead of outers - resulting decoded
502501
* inner missing so much it seems to be the wrong protocol

0 commit comments

Comments
 (0)