Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,19 @@ env:
TESTS: yes

jobs:
scan-build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: setup
run: |
sudo apt-get update && sudo apt-get install -y libcunit1-dev libtool libtool-bin exuberant-ctags clang-tools
./autogen.sh
- name: check
run: |
$GITHUB_WORKSPACE/configure --enable-tests
scan-build --status-bugs make V=0

build-linux-autotools:
runs-on: ubuntu-latest
strategy:
Expand Down Expand Up @@ -54,6 +67,7 @@ jobs:
cd build_test
cmake -DWARNING_TO_ERROR=ON -Dmake_tests=ON ..
cmake --build .

build-macos-cmake:
name: Build for macOS using CMake
runs-on: macos-latest
Expand Down
3 changes: 3 additions & 0 deletions ccm.c
Original file line number Diff line number Diff line change
Expand Up @@ -287,6 +287,9 @@ dtls_ccm_decrypt_message(rijndael_ctx *ctx, size_t M, size_t L,
msg += lm;
}

/* Check that SET_COUNTER() does not overflow in L shift */
assert(L <= 8);

/* calculate S_0 */
SET_COUNTER(A, L, 0, counter_tmp);
rijndael_encrypt(ctx, A, S);
Expand Down
12 changes: 5 additions & 7 deletions dtls.c
Original file line number Diff line number Diff line change
Expand Up @@ -2444,7 +2444,6 @@ dtls_check_ecdsa_signature_elem(uint8 *data, size_t data_length,
if (ret <= 0)
return ret;
data += ret;
data_length -= ret;

return data - data_orig;
}
Expand Down Expand Up @@ -2481,8 +2480,6 @@ check_client_certificate_verify(dtls_context_t *ctx,
if (ret < 0) {
return ret;
}
data += ret;
data_length -= ret;

copy_hs_hash(peer, &hs_hash);

Expand Down Expand Up @@ -3086,6 +3083,7 @@ dtls_send_certificate_verify_ecdh(dtls_context_t *ctx, dtls_peer_t *peer,

dtls_hash_finalize(sha256hash, &hs_hash);

assert(key);
/* sign the ephemeral and its paramaters */
dtls_ecdsa_create_sig_hash(key->priv_key, DTLS_EC_KEY_SIZE,
sha256hash, sizeof(sha256hash),
Expand Down Expand Up @@ -3485,7 +3483,6 @@ check_server_certificate(dtls_context_t *ctx,

memcpy(config->keyx.ecdsa.other_pub_y, data,
sizeof(config->keyx.ecdsa.other_pub_y));
data += sizeof(config->keyx.ecdsa.other_pub_y);

err = CALL(ctx, verify_ecdsa_key, &peer->session,
config->keyx.ecdsa.other_pub_x,
Expand Down Expand Up @@ -3569,8 +3566,6 @@ check_server_key_exchange_ecdsa(dtls_context_t *ctx,
if (ret < 0) {
return ret;
}
data += ret;
data_length -= ret;

ret = dtls_ecdsa_verify_sig(config->keyx.ecdsa.other_pub_x, config->keyx.ecdsa.other_pub_y,
sizeof(config->keyx.ecdsa.other_pub_x),
Expand Down Expand Up @@ -3727,7 +3722,7 @@ check_server_hellodone(dtls_context_t *ctx,
{
int res;
#ifdef DTLS_ECC
const dtls_ecdsa_key_t *ecdsa_key;
const dtls_ecdsa_key_t *ecdsa_key = NULL;
#endif /* DTLS_ECC */

dtls_handshake_parameters_t *handshake = peer->handshake_params;
Expand Down Expand Up @@ -4783,6 +4778,9 @@ dtls_handle_message(dtls_context_t *ctx,
dtls_info("received close_notify alert, peer has been invalidated\n");
else
dtls_warn("received fatal alert, peer has been invalidated\n");
/* handle alert has invalidated peer */
peer = NULL;
/* no more valid records after fatal alerts */
return 0;
} else {
dtls_stop_retransmission(ctx, peer);
Expand Down
1 change: 0 additions & 1 deletion dtls_debug.c
Original file line number Diff line number Diff line change
Expand Up @@ -191,7 +191,6 @@ dsrv_print_addr(const session_t *addr, char *buf, size_t len) {
return 0;
}
p += err;
len -= err;

return p - buf;
#else /* ! HAVE_INET_NTOP */
Expand Down
7 changes: 0 additions & 7 deletions sha2/sha2.c
Original file line number Diff line number Diff line change
Expand Up @@ -575,8 +575,6 @@ void dtls_sha256_transform(dtls_sha256_ctx* context, const sha2_byte* data) {
context->state[6] += g;
context->state[7] += h;

/* Clean up */
a = b = c = d = e = f = g = h = T1 = T2 = 0;
}

#endif /* SHA2_UNROLL_TRANSFORM */
Expand Down Expand Up @@ -608,8 +606,6 @@ void dtls_sha256_update(dtls_sha256_ctx* context, const sha2_byte *data, size_t
/* The buffer is not yet full */
MEMCPY_BCOPY(&context->buffer[usedspace], data, len);
context->bitcount += len << 3;
/* Clean up: */
usedspace = freespace = 0;
return;
}
}
Expand All @@ -625,8 +621,6 @@ void dtls_sha256_update(dtls_sha256_ctx* context, const sha2_byte *data, size_t
MEMCPY_BCOPY(context->buffer, data, len);
context->bitcount += len << 3;
}
/* Clean up: */
usedspace = freespace = 0;
}

void dtls_sha256_final(uint8_t digest[DTLS_SHA256_DIGEST_LENGTH], dtls_sha256_ctx* context) {
Expand Down Expand Up @@ -686,7 +680,6 @@ void dtls_sha256_final(uint8_t digest[DTLS_SHA256_DIGEST_LENGTH], dtls_sha256_ct

/* Clean up state data: */
MEMSET_BZERO(context, sizeof(*context));
usedspace = 0;
}

char *dtls_sha256_end(dtls_sha256_ctx* context, char buffer[DTLS_SHA256_DIGEST_STRING_LENGTH]) {
Expand Down
1 change: 0 additions & 1 deletion tests/dtls-client.c
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,6 @@ try_send(struct dtls_context_t *ctx, session_t *dst, size_t len, char *buf) {
res = dtls_write(ctx, dst, (uint8 *)buf, len);
if (res >= 0) {
memmove(buf, buf + res, len - res);
len -= res;
}
}

Expand Down
1 change: 1 addition & 0 deletions tests/unit-tests/test_ecc.c
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,7 @@ t_test_ecc_ecdsa0(void) {
ecc_ec_mult(BasePointx, BasePointy, ecdsaTestSecret, pub_x, pub_y);

ret = ecc_ecdsa_sign(ecdsaTestSecret, ecdsaTestMessage, ecdsaTestRand1, tempx, tempy);
CU_ASSERT(ret == 0);

memset(tempy, 0, sizeof(tempy));
ret = ecc_ecdsa_validate(pub_x, pub_y, ecdsaTestMessage, tempx, tempy);
Expand Down
Loading