• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

randombit / botan / 6546858227

17 Oct 2023 12:02PM UTC coverage: 91.71% (+0.002%) from 91.708%
6546858227

push

github

randombit
Merge GH #3760 Move constant time memory comparisons to ct_utils.h

80095 of 87335 relevant lines covered (91.71%)

8508512.25 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

79.1
/src/lib/ffi/ffi.cpp
1
/*
2
* (C) 2015,2017 Jack Lloyd
3
*
4
* Botan is released under the Simplified BSD License (see license.txt)
5
*/
6

7
#include <botan/ffi.h>
8

9
#include <botan/base64.h>
10
#include <botan/hex.h>
11
#include <botan/mem_ops.h>
12
#include <botan/version.h>
13
#include <botan/internal/ct_utils.h>
14
#include <botan/internal/ffi_util.h>
15
#include <botan/internal/os_utils.h>
16
#include <cstdio>
17
#include <cstdlib>
18

19
namespace Botan_FFI {
20

21
// NOLINTNEXTLINE(*-avoid-non-const-global-variables)
22
thread_local std::string g_last_exception_what;
94,511✔
23

24
int ffi_error_exception_thrown(const char* func_name, const char* exn, int rc) {
13✔
25
   g_last_exception_what.assign(exn);
13✔
26

27
   std::string val;
13✔
28
   if(Botan::OS::read_env_variable(val, "BOTAN_FFI_PRINT_EXCEPTIONS") == true && !val.empty()) {
13✔
29
      static_cast<void>(std::fprintf(stderr, "in %s exception '%s' returning %d\n", func_name, exn, rc));
×
30
   }
31
   return rc;
13✔
32
}
13✔
33

34
int botan_view_str_bounce_fn(botan_view_ctx vctx, const char* str, size_t len) {
68✔
35
   return botan_view_bin_bounce_fn(vctx, reinterpret_cast<const uint8_t*>(str), len);
68✔
36
}
37

38
int botan_view_bin_bounce_fn(botan_view_ctx vctx, const uint8_t* buf, size_t len) {
155✔
39
   if(vctx == nullptr || buf == nullptr) {
155✔
40
      return BOTAN_FFI_ERROR_NULL_POINTER;
41
   }
42

43
   botan_view_bounce_struct* ctx = static_cast<botan_view_bounce_struct*>(vctx);
155✔
44

45
   const size_t avail = *ctx->out_len;
155✔
46
   *ctx->out_len = len;
155✔
47

48
   if(avail < len || ctx->out_ptr == nullptr) {
155✔
49
      if(ctx->out_ptr) {
72✔
50
         Botan::clear_mem(ctx->out_ptr, avail);
×
51
      }
52
      return BOTAN_FFI_ERROR_INSUFFICIENT_BUFFER_SPACE;
72✔
53
   } else {
54
      Botan::copy_mem(ctx->out_ptr, buf, len);
83✔
55
      return BOTAN_FFI_SUCCESS;
83✔
56
   }
57
}
58

59
namespace {
60

61
int ffi_map_error_type(Botan::ErrorType err) {
7✔
62
   switch(err) {
7✔
63
      case Botan::ErrorType::Unknown:
64
         return BOTAN_FFI_ERROR_UNKNOWN_ERROR;
65

66
      case Botan::ErrorType::SystemError:
×
67
      case Botan::ErrorType::IoError:
×
68
      case Botan::ErrorType::Pkcs11Error:
×
69
      case Botan::ErrorType::CommonCryptoError:
×
70
      case Botan::ErrorType::TPMError:
×
71
      case Botan::ErrorType::ZlibError:
×
72
      case Botan::ErrorType::Bzip2Error:
×
73
      case Botan::ErrorType::LzmaError:
×
74
      case Botan::ErrorType::DatabaseError:
×
75
         return BOTAN_FFI_ERROR_SYSTEM_ERROR;
×
76

77
      case Botan::ErrorType::NotImplemented:
×
78
         return BOTAN_FFI_ERROR_NOT_IMPLEMENTED;
×
79
      case Botan::ErrorType::OutOfMemory:
×
80
         return BOTAN_FFI_ERROR_OUT_OF_MEMORY;
×
81
      case Botan::ErrorType::InternalError:
×
82
         return BOTAN_FFI_ERROR_INTERNAL_ERROR;
×
83
      case Botan::ErrorType::InvalidObjectState:
2✔
84
         return BOTAN_FFI_ERROR_INVALID_OBJECT_STATE;
2✔
85
      case Botan::ErrorType::KeyNotSet:
2✔
86
         return BOTAN_FFI_ERROR_KEY_NOT_SET;
2✔
87
      case Botan::ErrorType::InvalidArgument:
2✔
88
      case Botan::ErrorType::InvalidNonceLength:
2✔
89
         return BOTAN_FFI_ERROR_BAD_PARAMETER;
2✔
90

91
      case Botan::ErrorType::EncodingFailure:
1✔
92
      case Botan::ErrorType::DecodingFailure:
1✔
93
         return BOTAN_FFI_ERROR_INVALID_INPUT;
1✔
94

95
      case Botan::ErrorType::InvalidTag:
×
96
         return BOTAN_FFI_ERROR_BAD_MAC;
×
97

98
      case Botan::ErrorType::InvalidKeyLength:
×
99
         return BOTAN_FFI_ERROR_INVALID_KEY_LENGTH;
×
100
      case Botan::ErrorType::LookupError:
×
101
         return BOTAN_FFI_ERROR_NOT_IMPLEMENTED;
×
102

103
      case Botan::ErrorType::HttpError:
×
104
         return BOTAN_FFI_ERROR_HTTP_ERROR;
×
105
      case Botan::ErrorType::TLSError:
×
106
         return BOTAN_FFI_ERROR_TLS_ERROR;
×
107
      case Botan::ErrorType::RoughtimeError:
×
108
         return BOTAN_FFI_ERROR_ROUGHTIME_ERROR;
×
109
   }
110

111
   return BOTAN_FFI_ERROR_UNKNOWN_ERROR;
112
}
113

114
}  // namespace
115

116
int ffi_guard_thunk(const char* func_name, const std::function<int()>& thunk) {
94,496✔
117
   g_last_exception_what.clear();
94,496✔
118

119
   try {
94,496✔
120
      return thunk();
188,992✔
121
   } catch(std::bad_alloc&) {
13✔
122
      return ffi_error_exception_thrown(func_name, "bad_alloc", BOTAN_FFI_ERROR_OUT_OF_MEMORY);
×
123
   } catch(Botan_FFI::FFI_Error& e) {
6✔
124
      return ffi_error_exception_thrown(func_name, e.what(), e.error_code());
6✔
125
   } catch(Botan::Exception& e) {
13✔
126
      return ffi_error_exception_thrown(func_name, e.what(), ffi_map_error_type(e.error_type()));
7✔
127
   } catch(std::exception& e) {
7✔
128
      return ffi_error_exception_thrown(func_name, e.what());
×
129
   } catch(...) {
×
130
      return ffi_error_exception_thrown(func_name, "unknown exception");
×
131
   }
×
132

133
   return BOTAN_FFI_ERROR_UNKNOWN_ERROR;
134
}
135

136
}  // namespace Botan_FFI
137

138
extern "C" {
139

140
using namespace Botan_FFI;
141

142
const char* botan_error_last_exception_message() {
2✔
143
   return g_last_exception_what.c_str();
2✔
144
}
145

146
const char* botan_error_description(int err) {
152✔
147
   switch(err) {
152✔
148
      case BOTAN_FFI_SUCCESS:
149
         return "OK";
150

151
      case BOTAN_FFI_INVALID_VERIFIER:
1✔
152
         return "Invalid verifier";
1✔
153

154
      case BOTAN_FFI_ERROR_INVALID_INPUT:
2✔
155
         return "Invalid input";
2✔
156

157
      case BOTAN_FFI_ERROR_BAD_MAC:
1✔
158
         return "Invalid authentication code";
1✔
159

160
      case BOTAN_FFI_ERROR_INSUFFICIENT_BUFFER_SPACE:
1✔
161
         return "Insufficient buffer space";
1✔
162

163
      case BOTAN_FFI_ERROR_STRING_CONVERSION_ERROR:
1✔
164
         return "String conversion error";
1✔
165

166
      case BOTAN_FFI_ERROR_EXCEPTION_THROWN:
1✔
167
         return "Exception thrown";
1✔
168

169
      case BOTAN_FFI_ERROR_OUT_OF_MEMORY:
1✔
170
         return "Out of memory";
1✔
171

172
      case BOTAN_FFI_ERROR_SYSTEM_ERROR:
1✔
173
         return "Error while calling system API";
1✔
174

175
      case BOTAN_FFI_ERROR_INTERNAL_ERROR:
1✔
176
         return "Internal error";
1✔
177

178
      case BOTAN_FFI_ERROR_BAD_FLAG:
1✔
179
         return "Bad flag";
1✔
180

181
      case BOTAN_FFI_ERROR_NULL_POINTER:
1✔
182
         return "Null pointer argument";
1✔
183

184
      case BOTAN_FFI_ERROR_BAD_PARAMETER:
1✔
185
         return "Bad parameter";
1✔
186

187
      case BOTAN_FFI_ERROR_KEY_NOT_SET:
1✔
188
         return "Key not set on object";
1✔
189

190
      case BOTAN_FFI_ERROR_INVALID_KEY_LENGTH:
1✔
191
         return "Invalid key length";
1✔
192

193
      case BOTAN_FFI_ERROR_INVALID_OBJECT_STATE:
1✔
194
         return "Invalid object state";
1✔
195

196
      case BOTAN_FFI_ERROR_NOT_IMPLEMENTED:
2✔
197
         return "Not implemented";
2✔
198

199
      case BOTAN_FFI_ERROR_INVALID_OBJECT:
1✔
200
         return "Invalid object handle";
1✔
201

202
      case BOTAN_FFI_ERROR_TLS_ERROR:
1✔
203
         return "TLS error";
1✔
204

205
      case BOTAN_FFI_ERROR_HTTP_ERROR:
1✔
206
         return "HTTP error";
1✔
207

208
      case BOTAN_FFI_ERROR_UNKNOWN_ERROR:
1✔
209
         return "Unknown error";
1✔
210

211
      default:
129✔
212
         return "Unknown error";
129✔
213
   }
214
}
215

216
/*
217
* Versioning
218
*/
219
uint32_t botan_ffi_api_version() {
3✔
220
   return BOTAN_HAS_FFI;
3✔
221
}
222

223
int botan_ffi_supports_api(uint32_t api_version) {
7✔
224
   // This is the API introduced in 3.2
225
   if(api_version == 20231009) {
7✔
226
      return BOTAN_FFI_SUCCESS;
227
   }
228

229
   // This is the API introduced in 3.1
230
   if(api_version == 20230711) {
6✔
231
      return BOTAN_FFI_SUCCESS;
232
   }
233

234
   // This is the API introduced in 3.0
235
   if(api_version == 20230403) {
6✔
236
      return BOTAN_FFI_SUCCESS;
237
   }
238

239
   // This is the API introduced in 2.18
240
   if(api_version == 20210220) {
5✔
241
      return BOTAN_FFI_SUCCESS;
242
   }
243

244
   // This is the API introduced in 2.13
245
   if(api_version == 20191214) {
5✔
246
      return BOTAN_FFI_SUCCESS;
247
   }
248

249
   // This is the API introduced in 2.8
250
   if(api_version == 20180713) {
5✔
251
      return BOTAN_FFI_SUCCESS;
252
   }
253

254
   // This is the API introduced in 2.3
255
   if(api_version == 20170815) {
4✔
256
      return BOTAN_FFI_SUCCESS;
257
   }
258

259
   // This is the API introduced in 2.1
260
   if(api_version == 20170327) {
3✔
261
      return BOTAN_FFI_SUCCESS;
262
   }
263

264
   // This is the API introduced in 2.0
265
   if(api_version == 20150515) {
2✔
266
      return BOTAN_FFI_SUCCESS;
1✔
267
   }
268

269
   // Something else:
270
   return -1;
271
}
272

273
const char* botan_version_string() {
2✔
274
   return Botan::version_cstr();
2✔
275
}
276

277
uint32_t botan_version_major() {
2✔
278
   return Botan::version_major();
2✔
279
}
280

281
uint32_t botan_version_minor() {
2✔
282
   return Botan::version_minor();
2✔
283
}
284

285
uint32_t botan_version_patch() {
1✔
286
   return Botan::version_patch();
1✔
287
}
288

289
uint32_t botan_version_datestamp() {
1✔
290
   return Botan::version_datestamp();
1✔
291
}
292

293
int botan_constant_time_compare(const uint8_t* x, const uint8_t* y, size_t len) {
28✔
294
   auto same = Botan::CT::is_equal(x, y, len);
28✔
295
   // Return 0 if same or -1 otherwise
296
   return static_cast<int>(same.select(1, 0)) - 1;
28✔
297
}
298

299
int botan_same_mem(const uint8_t* x, const uint8_t* y, size_t len) {
×
300
   return botan_constant_time_compare(x, y, len);
×
301
}
302

303
int botan_scrub_mem(void* mem, size_t bytes) {
1✔
304
   Botan::secure_scrub_memory(mem, bytes);
1✔
305
   return BOTAN_FFI_SUCCESS;
1✔
306
}
307

308
int botan_hex_encode(const uint8_t* in, size_t len, char* out, uint32_t flags) {
3✔
309
   return ffi_guard_thunk(__func__, [=]() -> int {
3✔
310
      const bool uppercase = (flags & BOTAN_FFI_HEX_LOWER_CASE) == 0;
3✔
311
      Botan::hex_encode(out, in, len, uppercase);
3✔
312
      return BOTAN_FFI_SUCCESS;
3✔
313
   });
3✔
314
}
315

316
int botan_hex_decode(const char* hex_str, size_t in_len, uint8_t* out, size_t* out_len) {
2✔
317
   return ffi_guard_thunk(__func__, [=]() -> int {
2✔
318
      const std::vector<uint8_t> bin = Botan::hex_decode(hex_str, in_len);
2✔
319
      return Botan_FFI::write_vec_output(out, out_len, bin);
2✔
320
   });
4✔
321
}
322

323
int botan_base64_encode(const uint8_t* in, size_t len, char* out, size_t* out_len) {
2✔
324
   return ffi_guard_thunk(__func__, [=]() -> int {
2✔
325
      const std::string base64 = Botan::base64_encode(in, len);
2✔
326
      return Botan_FFI::write_str_output(out, out_len, base64);
2✔
327
   });
4✔
328
}
329

330
int botan_base64_decode(const char* base64_str, size_t in_len, uint8_t* out, size_t* out_len) {
2✔
331
   return ffi_guard_thunk(__func__, [=]() -> int {
2✔
332
      if(*out_len < Botan::base64_decode_max_output(in_len)) {
2✔
333
         *out_len = Botan::base64_decode_max_output(in_len);
1✔
334
         return BOTAN_FFI_ERROR_INSUFFICIENT_BUFFER_SPACE;
1✔
335
      }
336

337
      *out_len = Botan::base64_decode(out, std::string(base64_str, in_len));
1✔
338
      return BOTAN_FFI_SUCCESS;
1✔
339
   });
2✔
340
}
341
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc