projects
/
tinc
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
perform cheap checks first
[tinc]
/
src
/
openssl
/
prf.c
diff --git
a/src/openssl/prf.c
b/src/openssl/prf.c
index
943bd62
..
37af2ef
100644
(file)
--- a/
src/openssl/prf.c
+++ b/
src/openssl/prf.c
@@
-29,11
+29,12
@@
We use SHA512 instead of MD5 and SHA1.
*/
We use SHA512 instead of MD5 and SHA1.
*/
-static bool prf_xor(int nid, const char *secret, size_t secretlen, char *seed, size_t seedlen, char *out, s
s
ize_t outlen) {
+static bool prf_xor(int nid, const char *secret, size_t secretlen, char *seed, size_t seedlen, char *out, size_t outlen) {
digest_t *digest = digest_open_by_nid(nid, -1);
digest_t *digest = digest_open_by_nid(nid, -1);
- if(!digest)
+ if(!digest)
{
return false;
return false;
+ }
if(!digest_set_key(digest, secret, secretlen)) {
digest_close(digest);
if(!digest_set_key(digest, secret, secretlen)) {
digest_close(digest);
@@
-54,14
+55,21
@@
static bool prf_xor(int nid, const char *secret, size_t secretlen, char *seed, s
while(outlen > 0) {
/* Inner HMAC */
while(outlen > 0) {
/* Inner HMAC */
- digest_create(digest, data, len + seedlen, data);
+ if(!digest_create(digest, data, len + seedlen, data)) {
+ digest_close(digest);
+ return false;
+ }
/* Outer HMAC */
/* Outer HMAC */
- digest_create(digest, data, len + seedlen, hash);
+ if(!digest_create(digest, data, len + seedlen, hash)) {
+ digest_close(digest);
+ return false;
+ }
/* XOR the results of the outer HMAC into the out buffer */
/* XOR the results of the outer HMAC into the out buffer */
- for(
int i = 0; i < len && i < outlen; i++)
+ for(
size_t i = 0; i < len && i < outlen; i++) {
*out++ ^= hash[i];
*out++ ^= hash[i];
+ }
outlen -= len;
}
outlen -= len;
}