Page MenuHomeFreeBSD

Stop using des_cblock * for arguments to DES functions.
ClosedPublic

Authored by jhb on Aug 24 2019, 12:11 AM.
Tags
None
Referenced Files
F103221162: D21389.id61302.diff
Fri, Nov 22, 9:06 AM
Unknown Object (File)
Thu, Nov 21, 7:57 AM
Unknown Object (File)
Tue, Nov 19, 11:07 AM
Unknown Object (File)
Mon, Nov 18, 8:18 PM
Unknown Object (File)
Mon, Nov 18, 7:38 PM
Unknown Object (File)
Mon, Nov 18, 4:48 PM
Unknown Object (File)
Mon, Nov 11, 4:47 AM
Unknown Object (File)
Sep 30 2024, 2:00 PM
Subscribers
None

Details

Summary

This amounts to a char ** since it is a char[8] *. Evil casts mostly
resolved the fact that what was actually passed in were plain char *.
Instead, change the DES functions to use 'unsigned char *' for keys
and for input and output buffers.

Test Plan
  • amd64 GENERIC builds, waiting for a tinderbox to finish

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Looks sane to me. Thanks for digging to the bottom of this rathole...

This revision is now accepted and ready to land.Aug 24 2019, 12:23 AM

Bit sad to be fixing DES in 2019 but unfortunately, this looks correct to me...

sys/crypto/des/des_setkey.c
70–88 ↗(On Diff #61196)

These routines must have been totally broken before?

sys/crypto/des/des_setkey.c
70–88 ↗(On Diff #61196)

It would seem so unless code actually invoked them correctly (which is doubtful). I think the kgssapi code was using these but using a bogus cast such that they probably didn't work. Probably would have panicked if you used plain DES with kgssapi it looks like.