Detect symmetric crypto errors in PKCS7_decrypt.
[oweals/openssl.git] / crypto / modes / xts128.c
index f3890c8854ddbe8401ae8360d0c4288f95d72cd1..9cf27a25e9607b67cfcd5b696b5cdbf1e9aae77f 100644 (file)
 #endif
 #include <assert.h>
 
-typedef struct {
-       void      *key1, *key2;
-       block128_f block1,block2;
-} XTS128_CONTEXT;
-
-int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx, u64 secno,
+int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx, const unsigned char iv[16],
        const unsigned char *inp, unsigned char *out,
        size_t len, int enc)
 {
        const union { long one; char little; } is_endian = {1};
        union { u64 u[2]; u32 d[4]; u8 c[16]; } tweak, scratch;
+       unsigned int i;
 
        if (len<16) return -1;
 
-       if (is_endian.little) {
-               tweak.u[0] = secno;
-               tweak.u[1] = 0;
-       }
-       else {
-               PUTU32(tweak.c,secno);
-               PUTU32(tweak.c+4,secno>>32);
-               tweak.u[1] = 0;
-       }
+       memcpy(tweak.c, iv, 16);
 
        (*ctx->block2)(tweak.c,tweak.c,ctx->key2);
 
-       if (!enc && len%16) len-=16;
+       if (!enc && (len%16)) len-=16;
 
        while (len>=16) {
 #if defined(STRICT_ALIGNMENT)
@@ -96,93 +84,103 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx, u64 secno,
                scratch.u[1] = ((u64*)inp)[1]^tweak.u[1];
 #endif
                (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
+#if defined(STRICT_ALIGNMENT)
                scratch.u[0] ^= tweak.u[0];
                scratch.u[1] ^= tweak.u[1];
                memcpy(out,scratch.c,16);
+#else
+               ((u64*)out)[0] = scratch.u[0]^=tweak.u[0];
+               ((u64*)out)[1] = scratch.u[1]^=tweak.u[1];
+#endif
                inp += 16;
                out += 16;
                len -= 16;
 
+               if (len==0)     return 0;
+
                if (is_endian.little) {
                        unsigned int carry,res;
                        
                        res = 0x87&(((int)tweak.d[3])>>31);
-                       carry = tweak.u[0]>>63;
+                       carry = (unsigned int)(tweak.u[0]>>63);
                        tweak.u[0] = (tweak.u[0]<<1)^res;
                        tweak.u[1] = (tweak.u[1]<<1)|carry;
                }
                else {
-                       unsigned int carry,c,i;
+                       size_t c;
 
-                       for (carry=0,i=0;i<16;++i) {
-                               c = tweak.c[i];
-                               tweak.c[i] = (c<<1)|carry;
-                               carry = c>>7;
+                       for (c=0,i=0;i<16;++i) {
+                               /*+ substitutes for |, because c is 1 bit */ 
+                               c += ((size_t)tweak.c[i])<<1;
+                               tweak.c[i] = (u8)c;
+                               c = c>>8;
                        }
-                       tweak.c[0] ^= 0x87&(0-carry);
+                       tweak.c[0] ^= (u8)(0x87&(0-c));
                }
        }
-       if (len) {
-               unsigned int i;
-
-               if (enc) {
-                       for (i=0;i<len;++i) {
-                               u8 c = inp[i];
-                               out[i] = scratch.c[i];
-                               scratch.c[i] = c;
-                       }
-                       scratch.u[0] ^= tweak.u[0];
-                       scratch.u[1] ^= tweak.u[1];
-                       (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
-                       scratch.u[0] ^= tweak.u[0];
-                       scratch.u[1] ^= tweak.u[1];
-                       memcpy(out-16,scratch.c,16);
+       if (enc) {
+               for (i=0;i<len;++i) {
+                       u8 c = inp[i];
+                       out[i] = scratch.c[i];
+                       scratch.c[i] = c;
+               }
+               scratch.u[0] ^= tweak.u[0];
+               scratch.u[1] ^= tweak.u[1];
+               (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
+               scratch.u[0] ^= tweak.u[0];
+               scratch.u[1] ^= tweak.u[1];
+               memcpy(out-16,scratch.c,16);
+       }
+       else {
+               union { u64 u[2]; u8 c[16]; } tweak1;
+
+               if (is_endian.little) {
+                       unsigned int carry,res;
+
+                       res = 0x87&(((int)tweak.d[3])>>31);
+                       carry = (unsigned int)(tweak.u[0]>>63);
+                       tweak1.u[0] = (tweak.u[0]<<1)^res;
+                       tweak1.u[1] = (tweak.u[1]<<1)|carry;
                }
                else {
-                       union { u64 u[2]; u8 c[16]; } tweak1;
-
-                       if (is_endian.little) {
-                               unsigned int carry,res;
-       
-                               res = 0x87&(((int)tweak.d[3])>>31);
-                               carry = tweak.u[0]>>63;
-                               tweak1.u[0] = (tweak.u[0]<<1)^res;
-                               tweak1.u[1] = (tweak.u[1]<<1)|carry;
-                       }
-                       else {
-                               unsigned int carry,c;
-
-                               for (carry=0,i=0;i<16;++i) {
-                                       c = tweak.c[i];
-                                       tweak1.c[i] = (c<<1)|carry;
-                                       carry = c>>7;
-                               }
-                               tweak1.c[0] ^= 0x87&(0-carry);
+                       size_t c;
+
+                       for (c=0,i=0;i<16;++i) {
+                               /*+ substitutes for |, because c is 1 bit */ 
+                               c += ((size_t)tweak.c[i])<<1;
+                               tweak1.c[i] = (u8)c;
+                               c = c>>8;
                        }
+                       tweak1.c[0] ^= (u8)(0x87&(0-c));
+               }
 #if defined(STRICT_ALIGNMENT)
-                       memcpy(scratch.c,inp,16);
-                       scratch.u[0] ^= tweak1.u[0];
-                       scratch.u[1] ^= tweak1.u[1];
+               memcpy(scratch.c,inp,16);
+               scratch.u[0] ^= tweak1.u[0];
+               scratch.u[1] ^= tweak1.u[1];
 #else
-                       scratch.u[0] = ((u64*)inp)[0]^tweak1.u[0];
-                       scratch.u[1] = ((u64*)inp)[1]^tweak1.u[1];
+               scratch.u[0] = ((u64*)inp)[0]^tweak1.u[0];
+               scratch.u[1] = ((u64*)inp)[1]^tweak1.u[1];
 #endif
-                       (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
-                       scratch.u[0] ^= tweak1.u[0];
-                       scratch.u[1] ^= tweak1.u[1];
-
-                       for (i=0;i<len;++i) {
-                               u8 c = inp[16+i];
-                               out[16+i] = scratch.c[i];
-                               scratch.c[i] = c;
-                       }
-                       scratch.u[0] ^= tweak.u[0];
-                       scratch.u[1] ^= tweak.u[1];
-                       (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
-                       scratch.u[0] ^= tweak.u[0];
-                       scratch.u[1] ^= tweak.u[1];
-                       memcpy (out,scratch.c,16);
+               (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
+               scratch.u[0] ^= tweak1.u[0];
+               scratch.u[1] ^= tweak1.u[1];
+
+               for (i=0;i<len;++i) {
+                       u8 c = inp[16+i];
+                       out[16+i] = scratch.c[i];
+                       scratch.c[i] = c;
                }
+               scratch.u[0] ^= tweak.u[0];
+               scratch.u[1] ^= tweak.u[1];
+               (*ctx->block1)(scratch.c,scratch.c,ctx->key1);
+#if defined(STRICT_ALIGNMENT)
+               scratch.u[0] ^= tweak.u[0];
+               scratch.u[1] ^= tweak.u[1];
+               memcpy (out,scratch.c,16);
+#else
+               ((u64*)out)[0] = scratch.u[0]^tweak.u[0];
+               ((u64*)out)[1] = scratch.u[1]^tweak.u[1];
+#endif
        }
 
        return 0;