2 * Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the OpenSSL license (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
10 #ifndef HEADER_PACKET_LOCL_H
11 # define HEADER_PACKET_LOCL_H
14 # include <openssl/bn.h>
15 # include <openssl/buffer.h>
16 # include <openssl/crypto.h>
17 # include <openssl/e_os2.h>
19 # include "internal/numbers.h"
26 /* Pointer to where we are currently reading from */
27 const unsigned char *curr;
28 /* Number of bytes remaining */
32 /* Internal unchecked shorthand; don't use outside this file. */
33 static ossl_inline void packet_forward(PACKET *pkt, size_t len)
36 pkt->remaining -= len;
40 * Returns the number of bytes remaining to be read in the PACKET
42 static ossl_inline size_t PACKET_remaining(const PACKET *pkt)
44 return pkt->remaining;
48 * Returns a pointer to the first byte after the packet data.
49 * Useful for integrating with non-PACKET parsing code.
50 * Specifically, we use PACKET_end() to verify that a d2i_... call
51 * has consumed the entire packet contents.
53 static ossl_inline const unsigned char *PACKET_end(const PACKET *pkt)
55 return pkt->curr + pkt->remaining;
59 * Returns a pointer to the PACKET's current position.
60 * For use in non-PACKETized APIs.
62 static ossl_inline const unsigned char *PACKET_data(const PACKET *pkt)
68 * Initialise a PACKET with |len| bytes held in |buf|. This does not make a
69 * copy of the data so |buf| must be present for the whole time that the PACKET
72 __owur static ossl_inline int PACKET_buf_init(PACKET *pkt,
73 const unsigned char *buf,
76 /* Sanity check for negative values. */
77 if (len > (size_t)(SIZE_MAX / 2))
85 /* Initialize a PACKET to hold zero bytes. */
86 static ossl_inline void PACKET_null_init(PACKET *pkt)
93 * Returns 1 if the packet has length |num| and its contents equal the |num|
94 * bytes read from |ptr|. Returns 0 otherwise (lengths or contents not equal).
95 * If lengths are equal, performs the comparison in constant time.
97 __owur static ossl_inline int PACKET_equal(const PACKET *pkt, const void *ptr,
100 if (PACKET_remaining(pkt) != num)
102 return CRYPTO_memcmp(pkt->curr, ptr, num) == 0;
106 * Peek ahead and initialize |subpkt| with the next |len| bytes read from |pkt|.
107 * Data is not copied: the |subpkt| packet will share its underlying buffer with
108 * the original |pkt|, so data wrapped by |pkt| must outlive the |subpkt|.
110 __owur static ossl_inline int PACKET_peek_sub_packet(const PACKET *pkt,
111 PACKET *subpkt, size_t len)
113 if (PACKET_remaining(pkt) < len)
116 return PACKET_buf_init(subpkt, pkt->curr, len);
120 * Initialize |subpkt| with the next |len| bytes read from |pkt|. Data is not
121 * copied: the |subpkt| packet will share its underlying buffer with the
122 * original |pkt|, so data wrapped by |pkt| must outlive the |subpkt|.
124 __owur static ossl_inline int PACKET_get_sub_packet(PACKET *pkt,
125 PACKET *subpkt, size_t len)
127 if (!PACKET_peek_sub_packet(pkt, subpkt, len))
130 packet_forward(pkt, len);
136 * Peek ahead at 2 bytes in network order from |pkt| and store the value in
139 __owur static ossl_inline int PACKET_peek_net_2(const PACKET *pkt,
142 if (PACKET_remaining(pkt) < 2)
145 *data = ((unsigned int)(*pkt->curr)) << 8;
146 *data |= *(pkt->curr + 1);
151 /* Equivalent of n2s */
152 /* Get 2 bytes in network order from |pkt| and store the value in |*data| */
153 __owur static ossl_inline int PACKET_get_net_2(PACKET *pkt, unsigned int *data)
155 if (!PACKET_peek_net_2(pkt, data))
158 packet_forward(pkt, 2);
164 * Peek ahead at 3 bytes in network order from |pkt| and store the value in
167 __owur static ossl_inline int PACKET_peek_net_3(const PACKET *pkt,
170 if (PACKET_remaining(pkt) < 3)
173 *data = ((unsigned long)(*pkt->curr)) << 16;
174 *data |= ((unsigned long)(*(pkt->curr + 1))) << 8;
175 *data |= *(pkt->curr + 2);
180 /* Equivalent of n2l3 */
181 /* Get 3 bytes in network order from |pkt| and store the value in |*data| */
182 __owur static ossl_inline int PACKET_get_net_3(PACKET *pkt, unsigned long *data)
184 if (!PACKET_peek_net_3(pkt, data))
187 packet_forward(pkt, 3);
193 * Peek ahead at 4 bytes in network order from |pkt| and store the value in
196 __owur static ossl_inline int PACKET_peek_net_4(const PACKET *pkt,
199 if (PACKET_remaining(pkt) < 4)
202 *data = ((unsigned long)(*pkt->curr)) << 24;
203 *data |= ((unsigned long)(*(pkt->curr + 1))) << 16;
204 *data |= ((unsigned long)(*(pkt->curr + 2))) << 8;
205 *data |= *(pkt->curr + 3);
210 /* Equivalent of n2l */
211 /* Get 4 bytes in network order from |pkt| and store the value in |*data| */
212 __owur static ossl_inline int PACKET_get_net_4(PACKET *pkt, unsigned long *data)
214 if (!PACKET_peek_net_4(pkt, data))
217 packet_forward(pkt, 4);
222 /* Peek ahead at 1 byte from |pkt| and store the value in |*data| */
223 __owur static ossl_inline int PACKET_peek_1(const PACKET *pkt,
226 if (!PACKET_remaining(pkt))
234 /* Get 1 byte from |pkt| and store the value in |*data| */
235 __owur static ossl_inline int PACKET_get_1(PACKET *pkt, unsigned int *data)
237 if (!PACKET_peek_1(pkt, data))
240 packet_forward(pkt, 1);
246 * Peek ahead at 4 bytes in reverse network order from |pkt| and store the value
249 __owur static ossl_inline int PACKET_peek_4(const PACKET *pkt,
252 if (PACKET_remaining(pkt) < 4)
256 *data |= ((unsigned long)(*(pkt->curr + 1))) << 8;
257 *data |= ((unsigned long)(*(pkt->curr + 2))) << 16;
258 *data |= ((unsigned long)(*(pkt->curr + 3))) << 24;
263 /* Equivalent of c2l */
265 * Get 4 bytes in reverse network order from |pkt| and store the value in
268 __owur static ossl_inline int PACKET_get_4(PACKET *pkt, unsigned long *data)
270 if (!PACKET_peek_4(pkt, data))
273 packet_forward(pkt, 4);
279 * Peek ahead at |len| bytes from the |pkt| and store a pointer to them in
280 * |*data|. This just points at the underlying buffer that |pkt| is using. The
281 * caller should not free this data directly (it will be freed when the
282 * underlying buffer gets freed
284 __owur static ossl_inline int PACKET_peek_bytes(const PACKET *pkt,
285 const unsigned char **data,
288 if (PACKET_remaining(pkt) < len)
297 * Read |len| bytes from the |pkt| and store a pointer to them in |*data|. This
298 * just points at the underlying buffer that |pkt| is using. The caller should
299 * not free this data directly (it will be freed when the underlying buffer gets
302 __owur static ossl_inline int PACKET_get_bytes(PACKET *pkt,
303 const unsigned char **data,
306 if (!PACKET_peek_bytes(pkt, data, len))
309 packet_forward(pkt, len);
314 /* Peek ahead at |len| bytes from |pkt| and copy them to |data| */
315 __owur static ossl_inline int PACKET_peek_copy_bytes(const PACKET *pkt,
319 if (PACKET_remaining(pkt) < len)
322 memcpy(data, pkt->curr, len);
328 * Read |len| bytes from |pkt| and copy them to |data|.
329 * The caller is responsible for ensuring that |data| can hold |len| bytes.
331 __owur static ossl_inline int PACKET_copy_bytes(PACKET *pkt,
332 unsigned char *data, size_t len)
334 if (!PACKET_peek_copy_bytes(pkt, data, len))
337 packet_forward(pkt, len);
343 * Copy packet data to |dest|, and set |len| to the number of copied bytes.
344 * If the packet has more than |dest_len| bytes, nothing is copied.
345 * Returns 1 if the packet data fits in |dest_len| bytes, 0 otherwise.
346 * Does not forward PACKET position (because it is typically the last thing
347 * done with a given PACKET).
349 __owur static ossl_inline int PACKET_copy_all(const PACKET *pkt,
351 size_t dest_len, size_t *len)
353 if (PACKET_remaining(pkt) > dest_len) {
357 *len = pkt->remaining;
358 memcpy(dest, pkt->curr, pkt->remaining);
363 * Copy |pkt| bytes to a newly allocated buffer and store a pointer to the
364 * result in |*data|, and the length in |len|.
365 * If |*data| is not NULL, the old data is OPENSSL_free'd.
366 * If the packet is empty, or malloc fails, |*data| will be set to NULL.
367 * Returns 1 if the malloc succeeds and 0 otherwise.
368 * Does not forward PACKET position (because it is typically the last thing
369 * done with a given PACKET).
371 __owur static ossl_inline int PACKET_memdup(const PACKET *pkt,
372 unsigned char **data, size_t *len)
380 length = PACKET_remaining(pkt);
385 *data = OPENSSL_memdup(pkt->curr, length);
394 * Read a C string from |pkt| and copy to a newly allocated, NUL-terminated
395 * buffer. Store a pointer to the result in |*data|.
396 * If |*data| is not NULL, the old data is OPENSSL_free'd.
397 * If the data in |pkt| does not contain a NUL-byte, the entire data is
398 * copied and NUL-terminated.
399 * Returns 1 if the malloc succeeds and 0 otherwise.
400 * Does not forward PACKET position (because it is typically the last thing done
401 * with a given PACKET).
403 __owur static ossl_inline int PACKET_strndup(const PACKET *pkt, char **data)
407 /* This will succeed on an empty packet, unless pkt->curr == NULL. */
408 *data = OPENSSL_strndup((const char *)pkt->curr, PACKET_remaining(pkt));
409 return (*data != NULL);
412 /* Returns 1 if |pkt| contains at least one 0-byte, 0 otherwise. */
413 static ossl_inline int PACKET_contains_zero_byte(const PACKET *pkt)
415 return memchr(pkt->curr, 0, pkt->remaining) != NULL;
418 /* Move the current reading position forward |len| bytes */
419 __owur static ossl_inline int PACKET_forward(PACKET *pkt, size_t len)
421 if (PACKET_remaining(pkt) < len)
424 packet_forward(pkt, len);
430 * Reads a variable-length vector prefixed with a one-byte length, and stores
431 * the contents in |subpkt|. |pkt| can equal |subpkt|.
432 * Data is not copied: the |subpkt| packet will share its underlying buffer with
433 * the original |pkt|, so data wrapped by |pkt| must outlive the |subpkt|.
434 * Upon failure, the original |pkt| and |subpkt| are not modified.
436 __owur static ossl_inline int PACKET_get_length_prefixed_1(PACKET *pkt,
440 const unsigned char *data;
442 if (!PACKET_get_1(&tmp, &length) ||
443 !PACKET_get_bytes(&tmp, &data, (size_t)length)) {
449 subpkt->remaining = length;
455 * Like PACKET_get_length_prefixed_1, but additionally, fails when there are
456 * leftover bytes in |pkt|.
458 __owur static ossl_inline int PACKET_as_length_prefixed_1(PACKET *pkt,
462 const unsigned char *data;
464 if (!PACKET_get_1(&tmp, &length) ||
465 !PACKET_get_bytes(&tmp, &data, (size_t)length) ||
466 PACKET_remaining(&tmp) != 0) {
472 subpkt->remaining = length;
478 * Reads a variable-length vector prefixed with a two-byte length, and stores
479 * the contents in |subpkt|. |pkt| can equal |subpkt|.
480 * Data is not copied: the |subpkt| packet will share its underlying buffer with
481 * the original |pkt|, so data wrapped by |pkt| must outlive the |subpkt|.
482 * Upon failure, the original |pkt| and |subpkt| are not modified.
484 __owur static ossl_inline int PACKET_get_length_prefixed_2(PACKET *pkt,
488 const unsigned char *data;
491 if (!PACKET_get_net_2(&tmp, &length) ||
492 !PACKET_get_bytes(&tmp, &data, (size_t)length)) {
498 subpkt->remaining = length;
504 * Like PACKET_get_length_prefixed_2, but additionally, fails when there are
505 * leftover bytes in |pkt|.
507 __owur static ossl_inline int PACKET_as_length_prefixed_2(PACKET *pkt,
511 const unsigned char *data;
514 if (!PACKET_get_net_2(&tmp, &length) ||
515 !PACKET_get_bytes(&tmp, &data, (size_t)length) ||
516 PACKET_remaining(&tmp) != 0) {
522 subpkt->remaining = length;
528 * Reads a variable-length vector prefixed with a three-byte length, and stores
529 * the contents in |subpkt|. |pkt| can equal |subpkt|.
530 * Data is not copied: the |subpkt| packet will share its underlying buffer with
531 * the original |pkt|, so data wrapped by |pkt| must outlive the |subpkt|.
532 * Upon failure, the original |pkt| and |subpkt| are not modified.
534 __owur static ossl_inline int PACKET_get_length_prefixed_3(PACKET *pkt,
537 unsigned long length;
538 const unsigned char *data;
540 if (!PACKET_get_net_3(&tmp, &length) ||
541 !PACKET_get_bytes(&tmp, &data, (size_t)length)) {
547 subpkt->remaining = length;
552 /* Writeable packets */
554 typedef struct wpacket_sub WPACKET_SUB;
556 /* The parent WPACKET_SUB if we have one or NULL otherwise */
560 * Offset into the buffer where the length of this WPACKET goes. We use an
561 * offset in case the buffer grows and gets reallocated.
565 /* Number of bytes in the packet_len or 0 if we don't write the length */
568 /* Number of bytes written to the buf prior to this packet starting */
571 /* Flags for this sub-packet */
575 typedef struct wpacket_st WPACKET;
577 /* The buffer where we store the output data */
581 * Offset into the buffer where we are currently writing. We use an offset
582 * in case the buffer grows and gets reallocated.
586 /* Number of bytes written so far */
589 /* Maximum number of bytes we will allow to be written to this WPACKET */
592 /* Our sub-packets (always at least one if not finished) */
599 #define WPACKET_FLAGS_NONE 0
601 /* Error on WPACKET_close() if no data written to the WPACKET */
602 #define WPACKET_FLAGS_NON_ZERO_LENGTH 1
605 * Abandon all changes on WPACKET_close() if no data written to the WPACKET,
606 * i.e. this does not write out a zero packet length
608 #define WPACKET_FLAGS_ABANDON_ON_ZERO_LENGTH 2
612 * Initialise a WPACKET with the buffer in |buf|. The buffer must exist
613 * for the whole time that the WPACKET is being used. Additionally |lenbytes| of
614 * data is preallocated at the start of the buffer to store the length of the
615 * WPACKET once we know it.
617 int WPACKET_init_len(WPACKET *pkt, BUF_MEM *buf, size_t lenbytes);
620 * Same as WPACKET_init_len except there is no preallocation of the WPACKET
623 int WPACKET_init(WPACKET *pkt, BUF_MEM *buf);
626 * Set the flags to be applied to the current sub-packet
628 int WPACKET_set_flags(WPACKET *pkt, unsigned int flags);
631 * Closes the most recent sub-packet. It also writes out the length of the
632 * packet to the required location (normally the start of the WPACKET) if
633 * appropriate. The top level WPACKET should be closed using WPACKET_finish()
634 * instead of this function.
636 int WPACKET_close(WPACKET *pkt);
639 * The same as WPACKET_close() but only for the top most WPACKET. Additionally
640 * frees memory resources for this WPACKET.
642 int WPACKET_finish(WPACKET *pkt);
645 * Initialise a new sub-packet. Additionally |lenbytes| of data is preallocated
646 * at the start of the sub-packet to store its length once we know it. Don't
647 * call this directly. Use the convenience macros below instead.
649 int WPACKET_start_sub_packet_len__(WPACKET *pkt, size_t lenbytes);
652 * Convenience macros for calling WPACKET_start_sub_packet_len with different
655 #define WPACKET_start_sub_packet_u8(pkt) \
656 WPACKET_start_sub_packet_len__((pkt), 1)
657 #define WPACKET_start_sub_packet_u16(pkt) \
658 WPACKET_start_sub_packet_len__((pkt), 2)
659 #define WPACKET_start_sub_packet_u24(pkt) \
660 WPACKET_start_sub_packet_len__((pkt), 3)
661 #define WPACKET_start_sub_packet_u32(pkt) \
662 WPACKET_start_sub_packet_len__((pkt), 4)
665 * Same as WPACKET_start_sub_packet_len__() except no bytes are pre-allocated
666 * for the sub-packet length.
668 int WPACKET_start_sub_packet(WPACKET *pkt);
671 * Allocate bytes in the WPACKET for the output. This reserves the bytes
672 * and counts them as "written", but doesn't actually do the writing. A pointer
673 * to the allocated bytes is stored in |*allocbytes|.
674 * WARNING: the allocated bytes must be filled in immediately, without further
675 * WPACKET_* calls. If not then the underlying buffer may be realloc'd and
676 * change its location.
678 int WPACKET_allocate_bytes(WPACKET *pkt, size_t bytes,
679 unsigned char **allocbytes);
682 * The same as WPACKET_allocate_bytes() except additionally a new sub-packet is
683 * started for the allocated bytes, and then closed immediately afterwards. The
684 * number of length bytes for the sub-packet is in |lenbytes|. Don't call this
685 * directly. Use the convenience macros below instead.
687 int WPACKET_sub_allocate_bytes__(WPACKET *pkt, size_t len,
688 unsigned char **allocbytes, size_t lenbytes);
691 * Convenience macros for calling WPACKET_sub_allocate_bytes with different
694 #define WPACKET_sub_allocate_bytes_u8(pkt, len, bytes) \
695 WPACKET_sub_allocate_bytes__((pkt), (len), (bytes), 1)
696 #define WPACKET_sub_allocate_bytes_u16(pkt, len, bytes) \
697 WPACKET_sub_allocate_bytes__((pkt), (len), (bytes), 2)
698 #define WPACKET_sub_allocate_bytes_u24(pkt, len, bytes) \
699 WPACKET_sub_allocate_bytes__((pkt), (len), (bytes), 3)
700 #define WPACKET_sub_allocate_bytes_u32(pkt, len, bytes) \
701 WPACKET_sub_allocate_bytes__((pkt), (len), (bytes), 4)
704 * Write the value stored in |val| into the WPACKET. The value will consume
705 * |bytes| amount of storage. An error will occur if |val| cannot be
706 * accommodated in |bytes| storage, e.g. attempting to write the value 256 into
707 * 1 byte will fail. Don't call this directly. Use the convenience macros below
710 int WPACKET_put_bytes__(WPACKET *pkt, unsigned int val, size_t bytes);
713 * Convenience macros for calling WPACKET_put_bytes with different
716 #define WPACKET_put_bytes_u8(pkt, val) \
717 WPACKET_put_bytes__((pkt), (val), 1)
718 #define WPACKET_put_bytes_u16(pkt, val) \
719 WPACKET_put_bytes__((pkt), (val), 2)
720 #define WPACKET_put_bytes_u24(pkt, val) \
721 WPACKET_put_bytes__((pkt), (val), 3)
722 #define WPACKET_put_bytes_u32(pkt, val) \
723 WPACKET_sub_allocate_bytes__((pkt), (val), 4)
725 /* Set a maximum size that we will not allow the WPACKET to grow beyond */
726 int WPACKET_set_max_size(WPACKET *pkt, size_t maxsize);
728 /* Copy |len| bytes of data from |*src| into the WPACKET. */
729 int WPACKET_memcpy(WPACKET *pkt, const void *src, size_t len);
732 * Copy |len| bytes of data from |*src| into the WPACKET and prefix with its
733 * length (consuming |lenbytes| of data for the length). Don't call this
734 * directly. Use the convenience macros below instead.
736 int WPACKET_sub_memcpy__(WPACKET *pkt, const void *src, size_t len,
739 /* Convenience macros for calling WPACKET_sub_memcpy with different lengths */
740 #define WPACKET_sub_memcpy_u8(pkt, src, len) \
741 WPACKET_sub_memcpy__((pkt), (src), (len), 1)
742 #define WPACKET_sub_memcpy_u16(pkt, src, len) \
743 WPACKET_sub_memcpy__((pkt), (src), (len), 2)
744 #define WPACKET_sub_memcpy_bytes_u24(pkt, src, len) \
745 WPACKET_sub_memcpy__((pkt), (src), (len), 3)
746 #define WPACKET_sub_memcpy_bytes_u32(pkt, src, len) \
747 WPACKET_sub_memcpy__((pkt), (src), (len), 4)
750 * Return the total number of bytes written so far to the underlying buffer
751 * including any storage allocated for length bytes
753 int WPACKET_get_total_written(WPACKET *pkt, size_t *written);
756 * Returns the length of the current sub-packet. This excludes any bytes
757 * allocated for the length itself.
759 int WPACKET_get_length(WPACKET *pkt, size_t *len);
761 /* Release resources in a WPACKET if a failure has occurred. */
762 void WPACKET_cleanup(WPACKET *pkt);
768 #endif /* HEADER_PACKET_LOCL_H */