2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-24 17:11:27 +01:00
|
|
|
|
2015-08-28 09:27:15 +02:00
|
|
|
|
2016-03-22 13:12:39 +01:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2016-03-22 13:12:41 +01:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-24 17:11:27 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-12 14:04:40 -07:00
|
|
|
|
2012-09-24 17:11:27 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-05-26 13:05:32 +02:00
|
|
|
|
2012-09-24 17:11:27 +01:00
|
|
|
|
2013-01-30 11:30:06 +02:00
|
|
|
|
2012-09-24 17:11:27 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-05-26 23:19:55 +02:00
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_from_buffer(): return error code
mpi_read_from_buffer() reads a MPI from a buffer into a newly allocated
MPI instance. It expects the buffer's leading two bytes to contain the
number of bits, followed by the actual payload.
On failure, it returns NULL and updates the in/out argument ret_nread
somewhat inconsistently:
- If the given buffer is too short to contain the leading two bytes
encoding the number of bits or their value is unsupported, then
ret_nread will be cleared.
- If the allocation of the resulting MPI instance fails, ret_nread is left
as is.
The only user of mpi_read_from_buffer(), digsig_verify_rsa(), simply checks
for a return value of NULL and returns -ENOMEM if that happens.
While this is all of cosmetic nature only, there is another error condition
which currently isn't detectable by the caller of mpi_read_from_buffer():
if the given buffer is too small to hold the number of bits as encoded in
its first two bytes, the return value will be non-NULL and *ret_nread > 0.
In preparation of communicating this condition to the caller, let
mpi_read_from_buffer() return error values by means of the ERR_PTR()
mechanism.
Make the sole caller of mpi_read_from_buffer(), digsig_verify_rsa(),
check the return value for IS_ERR() rather than == NULL. If IS_ERR() is
true, return the associated error value rather than the fixed -ENOMEM.
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-05-26 23:19:51 +02:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_from_buffer(): return error code
mpi_read_from_buffer() reads a MPI from a buffer into a newly allocated
MPI instance. It expects the buffer's leading two bytes to contain the
number of bits, followed by the actual payload.
On failure, it returns NULL and updates the in/out argument ret_nread
somewhat inconsistently:
- If the given buffer is too short to contain the leading two bytes
encoding the number of bits or their value is unsupported, then
ret_nread will be cleared.
- If the allocation of the resulting MPI instance fails, ret_nread is left
as is.
The only user of mpi_read_from_buffer(), digsig_verify_rsa(), simply checks
for a return value of NULL and returns -ENOMEM if that happens.
While this is all of cosmetic nature only, there is another error condition
which currently isn't detectable by the caller of mpi_read_from_buffer():
if the given buffer is too small to hold the number of bits as encoded in
its first two bytes, the return value will be non-NULL and *ret_nread > 0.
In preparation of communicating this condition to the caller, let
mpi_read_from_buffer() return error values by means of the ERR_PTR()
mechanism.
Make the sole caller of mpi_read_from_buffer(), digsig_verify_rsa(),
check the return value for IS_ERR() rather than == NULL. If IS_ERR() is
true, return the associated error value rather than the fixed -ENOMEM.
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-05-26 23:19:51 +02:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
2013-01-30 11:30:06 +02:00
|
|
|
|
2016-05-26 23:19:53 +02:00
|
|
|
|
2016-05-26 23:19:54 +02:00
|
|
|
|
|
|
|
|
|
2016-05-26 23:19:53 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-05-26 23:19:55 +02:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
lib/mpi: mpi_read_from_buffer(): return error code
mpi_read_from_buffer() reads a MPI from a buffer into a newly allocated
MPI instance. It expects the buffer's leading two bytes to contain the
number of bits, followed by the actual payload.
On failure, it returns NULL and updates the in/out argument ret_nread
somewhat inconsistently:
- If the given buffer is too short to contain the leading two bytes
encoding the number of bits or their value is unsupported, then
ret_nread will be cleared.
- If the allocation of the resulting MPI instance fails, ret_nread is left
as is.
The only user of mpi_read_from_buffer(), digsig_verify_rsa(), simply checks
for a return value of NULL and returns -ENOMEM if that happens.
While this is all of cosmetic nature only, there is another error condition
which currently isn't detectable by the caller of mpi_read_from_buffer():
if the given buffer is too small to hold the number of bits as encoded in
its first two bytes, the return value will be non-NULL and *ret_nread > 0.
In preparation of communicating this condition to the caller, let
mpi_read_from_buffer() return error values by means of the ERR_PTR()
mechanism.
Make the sole caller of mpi_read_from_buffer(), digsig_verify_rsa(),
check the return value for IS_ERR() rather than == NULL. If IS_ERR() is
true, return the associated error value rather than the fixed -ENOMEM.
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-05-26 23:19:51 +02:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2016-05-26 23:19:53 +02:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-17 14:46:59 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-11-13 12:01:32 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2016-03-22 13:12:41 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2016-02-17 14:46:59 +01:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2015-11-13 12:01:32 +01:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2016-02-17 14:46:59 +01:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2015-11-13 12:01:32 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
2015-08-24 07:52:14 -07:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2016-03-22 13:12:40 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2016-03-22 13:12:41 +01:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2016-03-22 13:12:41 +01:00
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-22 13:12:42 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-24 07:52:14 -07:00
|
|
|
|
2015-06-15 13:18:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-08-31 14:05:16 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-22 13:12:39 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-11-13 12:01:32 +01:00
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:21 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-22 13:12:43 +01:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-22 13:12:43 +01:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2016-03-22 13:12:43 +01:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-18 12:45:18 +02:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2015-10-18 12:45:18 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_raw_from_sgl(): don't include leading zero SGEs in nbytes
At the very beginning of mpi_read_raw_from_sgl(), the leading zeros of
the input scatterlist are counted:
lzeros = 0;
for_each_sg(sgl, sg, ents, i) {
...
if (/* sg contains nonzero bytes */)
break;
/* sg contains nothing but zeros here */
ents--;
lzeros = 0;
}
Later on, the total number of trailing nonzero bytes is calculated by
subtracting the number of leading zero bytes from the total number of input
bytes:
nbytes -= lzeros;
However, since lzeros gets reset to zero for each completely zero leading
sg in the loop above, it doesn't include those.
Besides wasting resources by allocating a too large output buffer,
this mistake propagates into the calculation of x, the number of
leading zeros within the most significant output limb:
x = BYTES_PER_MPI_LIMB - nbytes % BYTES_PER_MPI_LIMB;
What's more, the low order bytes of the output, equal in number to the
extra bytes in nbytes, are left uninitialized.
Fix this by adjusting nbytes for each completely zero leading scatterlist
entry.
Fixes: 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers")
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-03-22 13:12:44 +01:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-07-28 13:29:17 +08:00
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_raw_from_sgl(): don't include leading zero SGEs in nbytes
At the very beginning of mpi_read_raw_from_sgl(), the leading zeros of
the input scatterlist are counted:
lzeros = 0;
for_each_sg(sgl, sg, ents, i) {
...
if (/* sg contains nonzero bytes */)
break;
/* sg contains nothing but zeros here */
ents--;
lzeros = 0;
}
Later on, the total number of trailing nonzero bytes is calculated by
subtracting the number of leading zero bytes from the total number of input
bytes:
nbytes -= lzeros;
However, since lzeros gets reset to zero for each completely zero leading
sg in the loop above, it doesn't include those.
Besides wasting resources by allocating a too large output buffer,
this mistake propagates into the calculation of x, the number of
leading zeros within the most significant output limb:
x = BYTES_PER_MPI_LIMB - nbytes % BYTES_PER_MPI_LIMB;
What's more, the low order bytes of the output, equal in number to the
extra bytes in nbytes, are left uninitialized.
Fix this by adjusting nbytes for each completely zero leading scatterlist
entry.
Fixes: 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers")
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-03-22 13:12:44 +01:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
2017-08-10 08:06:18 +02:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2017-08-10 08:06:18 +02:00
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_raw_from_sgl(): sanitize meaning of indices
Within the byte reading loop in mpi_read_raw_sgl(), there are two
housekeeping indices used, z and x.
At all times, the index z represents the number of output bytes covered
by the input SGEs for which processing has completed so far. This includes
any leading zero bytes within the most significant limb.
The index x changes its meaning after the first outer loop's iteration
though: while processing the first input SGE, it represents
"number of leading zero bytes in most significant output limb" +
"current position within current SGE"
For the remaining SGEs OTOH, x corresponds just to
"current position within current SGE"
After all, it is only the sum of z and x that has any meaning for the
output buffer and thus, the
"number of leading zero bytes in most significant output limb"
part can be moved away from x into z from the beginning, opening up the
opportunity for cleaner code.
Before the outer loop iterating over the SGEs, don't initialize z with
zero, but with the number of leading zero bytes in the most significant
output limb. For the inner loop iterating over a single SGE's bytes,
get rid of the buf_shift offset to x' bounds and let x run from zero to
sg->length - 1.
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-03-22 13:18:07 +01:00
|
|
|
|
|
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-07-28 13:29:17 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
lib/mpi: mpi_read_raw_from_sgl(): sanitize meaning of indices
Within the byte reading loop in mpi_read_raw_sgl(), there are two
housekeeping indices used, z and x.
At all times, the index z represents the number of output bytes covered
by the input SGEs for which processing has completed so far. This includes
any leading zero bytes within the most significant limb.
The index x changes its meaning after the first outer loop's iteration
though: while processing the first input SGE, it represents
"number of leading zero bytes in most significant output limb" +
"current position within current SGE"
For the remaining SGEs OTOH, x corresponds just to
"current position within current SGE"
After all, it is only the sum of z and x that has any meaning for the
output buffer and thus, the
"number of leading zero bytes in most significant output limb"
part can be moved away from x into z from the beginning, opening up the
opportunity for cleaner code.
Before the outer loop iterating over the SGEs, don't initialize z with
zero, but with the number of leading zero bytes in the most significant
output limb. For the inner loop iterating over a single SGE's bytes,
get rid of the buf_shift offset to x' bounds and let x run from zero to
sg->length - 1.
Signed-off-by: Nicolai Stange <nicstange@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2016-03-22 13:18:07 +01:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-29 19:32:22 +08:00
|
|
|
|
2015-10-08 09:26:50 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|