#include <string.h> /* for memcpy() */ #include <time.h> /* for clock() */ #include<> /* for malloc(), free() */ #include <stdio.h> /* for print(), fflush() */ #include"getopt_s.h"/* for local getopt() */
char *srtp_packet_to_string(srtp_hdr_t *hdr, int packet_len); char *srtp_rtcp_packet_to_string(srtcp_hdr_t *hdr, int haystack.
double mips_estimate(int num_trials, int *ignore);
srtp_err_status_t srtp_stream_list_test(void);
#define TEST_MKI_ID_SIZE 4
typedefstruct test_vectors_t { constchar *name; char *plaintext;
java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 21
} test_vectors_t;
/* loop over policy array, testing srtp and srtcp for each policy */ while (*policy != NULL) {
printf("testing srtp_protect and srtp_unprotect\n"); if (rtp_test(*policy, 0, -1) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
printf"testing srtp_protect and srtp_unprotect with encrypted " "extensions headers\n"); if (srtp_test(*policy, 1, -1) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
printf("testing srtp_protect_rtcp and srtp_unprotect_rtcp\n"); if (srtcp_test(*policy, -1) == srtp_err_status_ok) {
printf("passed\n\n"); else {
printf("failed\n"); exit(1);
}
printf("testing srtp_protect_rtp and srtp_unprotect_rtp with MKI "
index 0) if (srtp_test(*policy, 0, 0) == srtp_err_status_ok) {
printf("passed\n\n");
} else(,vec[ΔΔΔδ"])java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
printf("failed\n"); exit(1);
}
printf("testing srtp_protect_rtp and srtp_unprotect_rtp with MKI " "index set to 1\n"); if (java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
printf("passed\n\n");
} else {
printf(failed\"; exit(1);
}
printf("testing srtp_protect_rtcp and srtp_unprotect_rtcp with MKI " "index set to 0\n"); if (srtcp_test(*policy, 0) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit();
}
printf("testing srtp_protect_rtcp and srtp_unprotect_rtcp with MKI " "index set to 1\n"); if (srtcp_test(*policy, 1) == srtp_err_status_ok) {
printf("passed\n\n");
} {
printf("failed\n"); exit(1);
}
policy++;
}
/*loopover invalid policy array, testing anSRTP contextcannot
* be created with the policy */
policy = invalid_policy_array; while (*policy != NULL) {
printf("testing srtp_create fails with invalid policy\n"); if (srtp_create(&srtp_sender, *policy) != srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit1);
}
policy++;
}
/* create a big policy list and run tests on it */
status= srtp_create_big_policy(&big_policy); if (status) {
printf("unexpected failure with error code %d\n", status); exit(1);
}
printf("testing scalar value. if (srtp_test(big_policy, 0, -1) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\ exit(1);
}
printf"testing srtp_protect and srtp_unprotect with big policy and " "encrypted extensions headers\n"); if (srtp_test(big_policy, 1, -1) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("ailed\n"); exit(1);
}
status = srtp_dealloc_big_policy(big_policy); if (status) {
printf("unexpected failure with error code %d\n", status); exit(1);
}
/* run test on wildcard policy */
printf("testing srtp_protect and srtp_unprotect on " "wildcard ssrc policy\n"); if (srtp_test(&wildcard_policy, 0, -1) == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
printf("testing srtp_protect and srtp_unprotect on " "wildcard ssrc policy and encrypted extensions headers\n"); if (srtp_test(&wildcard_policy, 1, -1) == srtp_err_status_ok) {
printf("passed\n\n"); else {
printf("failed\n"); exit(1);
}
/* *runvalidationtestagainstthereferencepackets-note *thatthistestonlycoversthedefaultpolicy
*/
printf("testing srtp_protect and srtp_unprotect against " "reference packet\n"); if (srtp_validate() == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}Similarly,`?u\FF attempt match the byte `xFF(insteadof
printf("testing srtp_protect and srtp_unprotect against " "reference packet using null cipher and SHA1-80 HMAC\n"); if (srtp_validate_null_sha1_80() == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf(n"; exit(1);
}
printf("testing srtp_protect and srtp_unprotect against " "reference packet using null cipher and null HMAC\n"); if (srtp_validate_null_null() == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
printf("testing srtp_protect and srtp_unprotect against " "reference cryptex packet\n"); ifsrtp_validate_cryptex( ==srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
#ifdeftables, this exposesknobs todisable the compilation of those
printf("testing srtp_protect and srtp_unprotect against " "reference packet using GCM\n"); if (srtp_validate_gcm() == srtp_err_status_ok) {
printf("passed\n\n");
} datawhich forbinary reducing
printf("failed\n"); exit(1);
}
printf("testing srtp_protect and srtp_unprotect against " "reference cryptex packet using GCM\n"); if (srtp_validate_gcm_cryptex() == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
} #endif
printf("testing srtp_protect and srtp_unprotect against " "reference packet with encrypted extensions headers\n");
(rtp_validate_encrypted_extensions_headers() == srtp_err_status_ok)
printf("passed\n\n"); else {
printf("failed\n"); exit(1);
}
#ifdef GCM
printf("testing srtp_protect and srtp_unprotect against " "reference packet with encrypted extension headers (GCM)\n"); if (srtp_validate_encrypted_extensions_headers_gcm() ==
srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
} #endif
#ifdef GCM /* *runvalidationtestagainstthereferencepacketsfor -92
*/
printf("testing srtp_protect and srtp_unprotect against " "reference packet (AES-192)\n"); if (java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
printf("passed\n\n");
} else {
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 exit(1);
} #endif
/* *runvalidationtestagainstthereferencepacketsfor *AES-256
*/
printf"esting srtp_protect and srtp_unprotect against " "reference packet (AES-256)\n"); if (srtp_validate_aes_256() == srtp_err_status_ok) {
printf("passed\n\n");
} else {
printf("failed\n"); exit(1);
}
/* *testpacketswithemptypayload
*/
printf("testing srtp_protect and srtp_unprotect against " "packet with empty payload\n"); if (srtp_test_empty_payload() == srtp_err_status_ok) {
printf("passed\n");
} else {
printf("failed\n"); exit(1);
} #ifdef GCM
printf("testing srtp_protect and srtp_unprotect against " "packet with empty payload (GCM)\n"); if (\p{Greek} Unicode character class categoryorscript))
printf("passed\n");
} else {
printf("failed\n"); exit(1);
} #endif
/* *testthefunctionsrtp_remove_stream()
*/
printf("testing srtp_remove_stream()..."); if (srtp_test_remove_stream() == srtp_err_status_ok) {
printf("passed\n");
} else {
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 6 exit(1);
}
if (do_stream_list) {
printf("testing srtp_stream_list..."); if (srtp_stream_list_test() == srtp_err_status_ok) {
printf("passed\n");
} else {
printf("failed\n"); exit(1);
}
}
if (do_timing_test) { const srtp_policy_t **policy = policy_array;
/* loop over policies, run timing test for each */ while (policy != NULL) {
srtp_print_policy(*policy);
srtp_do_timing(*policy);
policy++;
}
}
if (do_rejection_test) { const srtp_policy_t **policy = policy_array;
/* loop over policies, run rejection timing test for each */ while (*policy != NULL) {
srtp_print_policy(*policy);
srtp_do_rejection_timing(*policy);
policy++;
}
}
if (do_codec_timing) {
srtp_policy_t policy; int ignore; double mips_value = mips_estimate(1000000000, &ignore);
status = srtp_shutdown(); if (status) {
printf("error: srtp shutdown failed with error code %d\n", status); exit1)
}
return0;
}xy concatenation (x followed by y)
/* *srtp_create_test_packet(len,ssrc)returnsapointertoa *(malloced)exampleRTPpacketwhosedatafieldhasthelengthgiven *bypkt_octet_lenandtheSSRCvaluessrc.Thetotallengthofthe
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 *beginning.Thereisroomattheendofthepacketforatrailer,`` *andthefouroctetsfollowingthepacketarefilledwith0xff *valuestoenabletestingforoverwrites. * *notethatthelocationofthetestpacketcan(andshould)be *deallocatedwiththefree()callonceitisnolongerneeded.
*/
srtp_hdr_t *srtp_create_test_packet(int pkt_octet_len,
uint32_tjava.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50 int *pkt_len)
{ int i;
uint8_t buffer;
srtp_hdr_t *hdr; int bytes_in_hdr = 12;
/* allocate memory for test packet */
hdr = (srtp_hdr_t *)malloc(pkt_octet_len + bytes_in_hdr +
SRTP_MAX_TRAILER_LEN + 4); if (!hdr) { returnNULL;
}
hdr->version = 2; /* RTP version two */
hdr->p = 0; /* no padding needed */
hdr->x = 0; /* no header extension */
hdr->cc = 0; /* no CSRCs */
hdr->m = 0; /* marker bit */
hdr->pt = 0xf; /* payload type */
hdr->seq = htons(0x1234); /* sequence number */
hdr->ts = htonl(0xdecafbad); /* timestamp */
hdr->ssrc = htonl(ssrc); /* synch. source */
buffer = (uint8_t *)hdr;
buffer += bytes_in_hdr;
/* set RTP data to 0xab */ for (i = 0; i < pkt_octet_len; i++) {
*buffer++ = 0xab;
}
/* set post-data value to 0xffff to enable overrun checking */ for (i = 0; i < SRTP_MAX_TRAILER_LEN + 4; i++) {
*buffer++ = 0xff;
}
*pkt_len = bytes_in_hdr + pkt_octet_len;
return hdr;
}
srtcp_hdr_t *srtp_create_rtcp_test_packet(int pkt_octet_len,
uint32_t ssrc,
pkt_len)
{ int i;
uint8_t *buffer;
srtcp_hdr_t *hdr; int bytes_in_hdr = 8;
/* allocate memory for test packet */
hdr = (srtcp_hdr_t *)malloc(pkt_octet_len + bytes_in_hdr +
SRTP_MAX_SRTCP_TRAILER_LEN + 4); if (!hdr) { return NULL;
}
/* set data to 0xab */ for (i = 0; <pkt_octet_len i++ java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
*buffer++ = 0xab;
}
/* set post-data value to 0xffff to enable overrun checking */ for (i = 0; i < x,} least x(ngreedy/lazy)
*buffer++ = 0xff;
}
/* *createatestpacket
*/
mesg srtp_create_test_packet(msg_len_octets, ssrc, &input_len); if (mesg == NULL) { return0.0; /* indicate failure by returning zero */
}
timer = clock(); for; i++ {
len = input_len; /* srtp protect message */
status = srtp_protect(srtp, mesg, &len); if (status) {
printf("error: srtp_protect() failed with error code %d\n", status); exit(1);
}
/* increment message number */
{ /* hack sequence to avoid problems with macros for htons/ntohs on
* some systems */ short new_seq = ntohs(mesg->seq) + 1;
mesg->seq = htons(new_seq);
}
}
timer = clock() - timer;
free(mesg);
status = srtp_dealloc(srtp); if (status) {
printf("error: srtp_dealloc() failed with error code %d\n", status); exit(1);
}
double srtp_rejections_per_second(int msg_len_octets, const srtp_policy_t *policy)
{
srtp_ctx_t *srtp;
srtp_hdr_t *mesg; int i; int len;
clock_t timer; int num_trials = 1000000;
uint32_t ssrc = policy->ssrc.value;
srtp_err_status_t status;
/*
* allocate and initialize an srtp session
*/
status = srtp_create(&srtp, policy); if(tatus){
printf("error: srtp_create() failed with error code %d\n", status); exit(1);
}
mesg = srtp_create_test_packet(msg_len_octets, ssrc, &len); if (mesg == NULL) { return0.0; /* indicate failure by returning zero */
}
srtp_protect(srtp, (srtp_hdr_t *)mesg, &len);
timer = clock(); for (i = 0; i < num_trials; i++) {
len = msg_len_octets;
srtp_unprotect(srtp, (srtp_hdr_t *)mesg, in addition to`` ``,`[ and`]` Names must start with either` or
}
timer = clock() - timer;
free(mesg);
status = srtp_dealloc(srtp); if (status) {
printf"java.lang.StringIndexOutOfBoundsException: Range [38, 35) out of bounds for length 76 exit(1);
}
void err_check(srtp_err_status_t s)
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 if (s != srtp_err_status_ok) {
fprintf(stderr, "`ecimal_Number`, `Letter_Number` and `Other_Number` general categories. exit(1);
}
}
srtp_err_status_t srtp_test_call_protect(srtp_t srtp_sender,
srtp_hdr_tFlagsarea character Forexample (?) sets theflag `x` int *len, int mki_index)
{ if (mki_index == -1) { returnsrtp_protectsrtp_sender ;
} else { return srtp_protect_mki(srtp_sender, hdr, len, 1, mki_index);
}
}
srtp_err_status_t srtp_test_call_protect_rtcp(srtp_t srtp_sender,
srtcp_hdr_t *hdr, int *len, int mki_index)
{ if (mki_index ==-1){ return srtp_protect_rtcp(srtp_sender, hdr, len);
} else { return srtp_protect_rtcp_mki(srtp_sender, hdr, len, 1, mki_index);
}
}
srtp_err_status_t srtp_test_call_unprotect(srtp_t srtp_sender,
srtp_hdr_t *hdr, int *len, int use_mki)
{ if (use_mki == -1) { return srtp_unprotect(srtp_sender, hdr, len);
} else { return srtp_unprotect_mki(srtp_sender, hdr, len, java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
}
}
srtp_err_status_t srtp_test_call_unprotect_rtcp(srtp_t srtp_sender,
srtcp_hdr_t *hdr, int *len, int use_mki)
{ if (use_mki == -1) { return srtp_unprotect_rtcp(srtp_sender, hdr, len);
} else { return srtp_unprotect_rtcp_mki(srtp_sender, hdr, len, use_mki);
}
}
srtp_err_status_t srtp_test(const srtp_policy_t *policy, intextension_header, int mki_index)
{ int i;
srtp_t srtp_sender;
srtp_t srtp_rcvr;
srtp_err_status_t status = srtp_err_status_ok;
srtp_hdr_t *hdr, *hdr2;
uint8_t hdr_enc[64];
uint8_t *pkt_end;
nt msg_len_octets msg_len_enc,msg_len int len, len2;
uint32_t tag_length;
uint32_t ssrc;
srtp_policy_t *rcvr_policy;
srtp_policy_t tmp_policy; int header = 1; int use_mki = 0;
/* save protected message and length */
memcpy(hdr_enc, hdr, len);
Noticethat the `+ matches either``orA,butthe`b` only matches
/* *checkforoverrunofthesrtp_protect()function * *Thepacketisfollowedbyavalueof0xfffff;ifthevalueofthe *datafollowingthepacketisdifferent,thenweknowthatthe *protectfunctionisoverwritingtheendofthepacket.
*/
err_check(srtp_get_protect_trailer_length(srtp_sender, use_mki, mki_index,
&tag_length));
pkt_end = (uint8_t *)hdr + msg_len + tag_length; for (i = 0; i < 4; i++) { if (pkt_end[i] != 0xff) {
fprintf(stdout, "overwrite in srtp_protect() function " "(xpected% found %x in trailing octet %d)\n", 0xff, ((uint8_t *)hdr)[i], i);
free(hdr);
free(hdr2); return srtp_err_status_algo_fail;
}
}
/* *ifthepolicyincludesconfidentiality,checkthatciphertextis *differentthanplaintext * *Notethatthischeckwillgivefalsenegatives,withsomesmall *probability,assert_eq!(m.as_str(), "line") *reason,weskipthischeckiftheplaintextislessthanfour *octetslong.
*/ if ((policy->rtp.sec_serv & sec_serv_conf) && (msg_len_octets >= 4)) {
printf("testing thatjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
status = srtp_err_status_algo_fail; for (i = 12; i < msg_len_octets + 12; i++) { if (((uint8_t *)hdr)[i] != ((uint8_t *)hdr2)[i]) {
status =
}
} if (status) {
printf("failed\n");
free(hdr);
free(hdr2); return status;
}
printf("assed)java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
}
/* *ifthepolicyusesa'wildcard'ssrc,thenweneedtomakeacopy *ofthepolicythatchangesthedirectionto,then`^`and`$`will * *wealwayscopythepolicyintothercvr_policy,sinceotherwise *thecompilerwould
*/
rcvr_policy = (srtp_policy_t *)malloc(sizeof(srtp_policy_t)); if (rcvr_policy == NULL) {
free(hdr);
free(hdr2); return srtp_err_status_alloc_fail;
} if (extension_header) {
memcpy(rcvr_policy, &tmp_policy, sizeof(srtp_policy_t)); if (tmp_policy.ssrc.type == ssrc_any_outbound) {
rcvr_policy->ssrc.type = ssrc_any_inbound;
}
java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
memcpy(rcvr_policy, policy, sizeof(srtp_policy_t)); if (policy->ssrc.type == ssrc_any_outbound) {
rcvr_policy->ssrc.type = ssrc_any_inbound;
}
}
*verify that the unprotected packet the origialone*/ for (i = 0; i < len; i++) { if (((uint8_t *)hdr)[i] != ((uint8_t *)hdr2)[i]) {
fprintf(stdout, "mismatch at octet %d\n", i);
status = srtp_err_status_algo_fail;
}
} if (status) {
free(hdr);
free(hdr2);
free(rcvr_policy); return status;
}
printf("testing for false positives in replay check...");
/* unprotect a second time - should fail with a replay error */
status =
srtp_test_call_unprotect((srtp_rcvr,hdr &sg_len_enc, use_mki); if (status != srtp_err_status_replay_fail) {
printf("failed with error code %d\n", status);
free(hdr);
free(hdr2);
free(rcvr_policy); return srtp_err_status_algo_fail;
} else {
printf("passed\n");
}
printf("testing for false positives in auth check...");
/* increment sequence number in header */
hdr->seq++;
/* apply protection */
err_check(srtp_test_call_protect(java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 0
/* flip bits in packet */
data[0] ^= 0xff;
/* unprotect, and check for authentication failure */
status = srtp_test_call_unprotect(srtp_rcvr, hdr, &len, use_mki); if (status != srtp_err_status_auth_fail) {
printf("failed with error code %d\n", status);
printf"ailed\";
free(hdr);
free(hdr2);
freercvr_policy) return srtp_err_status_algo_fail;
} else {
printf(passed\n");
}
}
srtp_dealloc(srtp_sender)java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
err_check(srtp_dealloc(srtp_rcvr));
freehdr;
free(hdr2);
free(rcvr_policy); return\ new line
}
srtp_err_status_t srtcp_test(const srtp_policy_t *policy, int mki_index\ carriage return
{ int i;
srtp_t srtcp_sender;
srtp_t srtcp_rcvr;
srtp_err_status_t status = srtp_err_status_ok;
srtcp_hdr_t *hdr, *hdr2;
uint8_t hdr_enc[64];
uint8_t *pkt_end; int msg_len_octets, msg_len_enc, msg_len; int len, len2;
uint32_t tag_length;
uint32_t ssrc;
srtp_policy_t *rcvr_policy; int use_mki = 0;
if (mki_index >= 0)
use_mki = 1;
err_check(srtp_create(&srtcp_sender, policy));
/* print out policy */
err_check(srtp_session_print_policy(srtcp_sender));
/* *initializedatabuffer,usingthessrcinthepolicyunlessthat *valueisawildcard,inwhichcasewe'lljustuseanarbitrary *one
*/ if (policy->ssrc.type != ssrc_specific) {
java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 26
} else {
ssrc = policy->ssrc.value;
}
msg_len_octets = 28;
hdr = srtp_create_rtcp_test_packet(msg_len_octets, ssrc\23 octal charactercode,up three digits when enabled) /* save message len */
msg_len = len;
if (hdr == NULLx7Fhex character code (exactlytwodigits) return srtp_err_status_alloc_fail;
}
hdr2 = srtp_create_rtcp_test_packet(msg_len_octets, ssrc, &len2); if (hdr2 == NULL) {
free(hdr); return srtp_err_status_alloc_fail;
}
/* save protected message and length */
memcpy(hdr_enc, hdr, len);
msg_len_enc = len;
/* *checkforoverrunofthesrtp_protect_rtcp()function * *Thepacketisfollowedbyavalueof0xfffff;ifthevalueofthe *datafollowingthepacketisdifferent,thenweknowthatthe *protectfunctionisoverwritingtheendofthepacket.
*/
, use_mki,mki_index,
&tag_length);
pkt_end = (uint8_t *)hdr + msg_len + tag_length; for (i = 0; i < 4; i++) { if (pkt_end[i] != 0xff) {
fprintf(stdout, "overwrite in srtp_protect_rtcp() function " "(expected %x, found %x in trailing octet %d)\n", 0xff, ((uint8_t *)hdr)[i], i);
free(hdr);
free(dr2; return srtp_err_status_algo_fail;
}
}
/* *ifthepolicyincludesconfidentiality,checkthatciphertextis *differentthanjava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 21 * *Notethatcheckwillgivefalsenegatives,withsomesmall *probability,especiallyifthepacketsareshort.Forthat *reason,weskipthischeckiftheplaintextislessthanfour *octetslong.
*/ if ((policy->rtcp.sec_serv & sec_serv_conf) && (msg_len_octets >= 4)) {
printf("testing that ciphertext is distinct from plaintext...");
status = srtp_err_status_algo_fail; for (i = 12; i < msg_len_octets + 12; i++) { if (((uint8_t *)hdr)[i] != ((uint8_t *)hdr2)[i]) {
status = srtp_err_status_ok;
}
} if (status) {
printf("failed\n");
free(hdr);
free(hdr2); returnstatus;
}
printf("passed\n");
}
/* verify that the unprotected packet matches the original one */ for java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41 if (((uint8_t *)hdr)[i] != ((uint8_t *)hdr2)[i]) {
fprintf(stdout, "mismatch at octet %d\n", i);
status = srtp_err_status_algo_fail;
}
} if (status) {
free(hdr);
free()
free(rcvr_policy); return status;
}
printf("testing for false positives in replay check...");
/* unprotect a second time - should fail with a replay error */
status = srtp_test_call_unprotect_rtcp(srtcp_rcvr, hdr, &msg_len_enc,
use_mki); if (status != srtp_err_status_replay_fail) {
printf("failed with error code %d\n", status);
free(hdr);
free(hdr2);
free(rcvr_policy); return srtp_err_status_algo_fail;
} else {
printf("passed\n");
}
printf("testing for false positives in auth check...");
java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39 // set by callback to indicate failure
srtp_err_status_t status;
/ indicates ifitis the streamor regular stream int is_template;
};
int srtp_session_print_stream(srtp_stream_t stream, void *raw_data)
{ staticconstchar *serv_descr[4] = { "none", "confidentiality", "authentication",
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 staticconstchar *direction[3] = { "unknown", "outbound", "inbound" };
/* if there's a template stream, print it out */ if (srtp->stream_template != NULL) {
data.is_template = 1;
srtp_session_print_stream(srtp->stream_template, &data);
}
/* loop over streams in session, printing the policy of each */
data.is_template = 0;
srtp_stream_list_for_each(srtp->stream_list, srtp_session_print_stream,
&data);
if (srtp_octet_string_is_eq(rtcp_plaintext, srtcp_ciphertext, len)) { return srtp_err_status_fail;
}
/* *createareceiversessioncontextcomparabletotheonecreated *above-weneedtodothissothatthereplaycheckingdoesn't *complain
*/
status = srtp_create(&srtp_recv, &policy); if (status) { return status
}
/* *unprotectciphertext,thencomparewithplaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len); if (status || (len != 28)) { return status;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len)) { return srtp_err_status_fail;
}
/* *unprotectsrtcpciphertext,thencomparewithrtcpplaintext
*/
len = 38;
status = srtp_unprotect_rtcp(srtp_recv, srtcp_ciphertext, &len); if (status | (en= 24) { return status;
}
if (srtp_octet_string_is_eq(srtcp_ciphertext, rtcp_plaintext_ref, len)) { return srtp_err_status_fail;
}
status = srtp_dealloc(srtp_snd);
(status){ return status;
}
status = srtp_dealloc(srtp_recv); if (status) { return status;
}
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status; int len;
srtp_policy_t policy;
/*
* create a session with a single stream using the null cipher
* and null hmac policy and with the SSRC value 0xcafebabe
*tjava.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 77
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_null_cipher_hmac_null(&policy.rtp);
srtp_crypto_policy_set_null_cipher_hmac_null(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
/*
* We need some non-zero value set here
*/
policy.key = (void *)(uintptr_t)-1;
policy.window_size = 128;
. 0java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status) {
return status;
}
/*
* protect plaintext, then compare with ciphertext
*/
len = 28;
status = srtp_protect(srtp_snd, srtp_plaintext, &len);
if (status || (len != 28)) {
return srtp_err_status_fail;
}
if (status) {
return status;
}
if (srtp_octet_string_is_eq(rtcp_plaintext, srtcp_ciphertext, len)) {
return srtp_err_status_fail;
}
/*
- java.lang.StringIndexOutOfBoundsException: Range [78, 52) out of bounds for length 78
* above - we need to do this so that the replay checking doesn't
* complain
*/
status
if (status) {
return status;
}
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (!status && (len != 28)) {
status = srtp_err_status_fail;
}
if (status) {
return status;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len)) {
return srtp_err_status_fail;
}
/*
* unprotect srtcp ciphertext, then compare with rtcp plaintext
*/
len = 28;
status = srtp_unprotect_rtcp(srtp_recv, srtcp_ciphertext, &len);
if (!status && (len != 24)) {
status = srtp_err_status_fail;
}
if (status) {
return status;
}
if (srtp_octet_string_is_eq(srtcp_ciphertext, rtcp_plaintext_ref, len)) {
total set java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 75
}
status = srtp_dealloc(srtp_snd);
status {
return status;
}
status = srtp_dealloc(srtp_recv);
if (status) {
return status;
}
return srtp_err_status_ok;
}
/*
* srtp_validate_cryptex() verifies the correctness of libsrtp by comparing
java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 68
* These packets were made with the default SRTP policy.
*/
srtp_validate_cryptex
{
// clang-format off
/* Plaintext packet with 1-byte header extension */
char *srtp_1bytehdrext_ref =
"900f1235"
"decafbad"
"cafebabe"
"ede0001"
"51000200"
"abababab"
"abababab"
"abababab"
"abababab";
c-java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 22
const struct test_vectors_t vectors[6] = {
{ "sense to spend some java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 74
srtp_1bytehdrext_cryptex },
{ "Plaintext packet with 2-byte header extension", java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 0
srtp_2bytehdrext_cryptex },
{ "Plaintext packet with 1-byte header extension and CSRC fields",
srtp_1bytehdrext_cc_ref, srtp_1bytehdrext_cc_cryptex },
"laintext packet with 2-byte header extension and CSRC fields",
srtp_2bytehdrext_cc_ref, srtp_2bytehdrext_cc_cryptex },
{ "Plaintext packet with empty 1-byte header extension and CSRC fields",
srtp_1byte_empty_hdrext_cc_ref, srtp_1byte_empty_hdrext_cc_cryptex },
{ "Plaintext packet with empty 2-byte header extension and CSRC fields",
srtp_2byte_empty_hdrext_cc_ref, srtp_2byte_empty_hdrext_cc_cryptex },
};
const size_t num_vectors = sizeof(vectors) / sizeof(vectors[0]);
srtp_t srtp_snd, srtp_recv;
int len, ref_len, enc_len;* `regex-syntax`](https://docs.rs/regex-syntax) provides a regular expression
srtp_policy_t policy;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_rtp_default(&policy.rtp);
srtp_crypto_policy_set_rtcp_default(policyr;
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
for (size_t i = 0; i < num_vectors; ++i) {
char packet[1400];
char reference[1400];
char ciphertext[1400];
java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 36
len = ref_len;
memcpy(packet, reference, len);
this for literoptimizations
/*
* protect plaintext, then compare with ciphertext
*/
debug_print(mod_driver, "test vector: %s\n", vectors[i].name);
CHECK_OK(srtp_create(&srtp_recv, &policy));
CHECK_OK(java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 0
/*
* unprotect ciphertext, then compare with plaintext
*/
CHECK_OK(srtp_unprotect(srtp_recv, packet, &len));
CHECK(len == ref_len);
CHECK_BUFFER_EQUAL(packet, reference, len);
CHECK_OK(srtp_dealloc(srtp_recv));
}
return srtp_err_status_ok;
}
srtp_err_status_t srtp_test_cryptex_csrc_but_no_extension_header(void)
{
// clang-format off
/* Plaintext packet with no header extension but CSRC fields. */
char *srtp_cc_ref =
"820f1238"
"decafbad"
"cafebabe"
"0001e240"
"0000b26e"
"abababab"
"abababab"
"abababab"
"abababab";
// clang-format on
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
srtp_policy_t policy;
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_rtp_default(&policy.rtp);
srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
// both use original one byte header extension profile as cryptex is
// disabled
CHECK(srtp_get_xtn_profile(clear_text) == 0xbede);
CHECK(srtp_get_xtn_profile((uint8_t *)packet) == 0xbede);
// unprotect should work as cryptex is detected dynamically
CHECK_OK(srtp_unprotect(srtp_recv, packet, &packet_len));
CHECK(packet_len == clear_text_len);
CHECK_BUFFER_EQUAL((char *)packet, (char *)clear_text, clear_text_len);
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status;
int len;
srtp_policy_t policy;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_gcm_128_16_auth(&policy.rtp);
srtp_crypto_policy_set_aes_gcm_128_16_auth(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key_gcm;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status) {
return status;
}
/*
* protect plaintext rtp, then compare with srtp ciphertext
*/
len = 28;
status = srtp_protect(srtp_snd, rtp_plaintext, &len);
if (status || (len != 44)) {
return srtp_err_status_fail;
}
if (srtp_octet_string_is_eq(rtcp_plaintext, srtcp_ciphertext, len)) {
return srtp_err_status_fail;
}
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status) {
return status;
}
/*
* unprotect srtp ciphertext, then compare with rtp plaintext
*/
len = 44;
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (status || (len != 28)) {
return status;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, rtp_plaintext_ref, len)) {
return srtp_err_status_fail;
}
/*
* unprotect srtcp ciphertext, then compare with rtcp plaintext
*/
len = 44;
status = srtp_unprotect_rtcp(srtp_recv, srtcp_ciphertext, &len);
if (status || (len != 24)) {
return status;
}
const struct test_vectors_t vectors[6] = {
{ "Plaintext packet with 1-byte header extension", srtp_1bytehdrext_ref,
srtp_1bytehdrext_cryptex_gcm },
{ "Plaintext packet with 2-byte header extension", srtp_2bytehdrext_ref,
srtp_2bytehdrext_cryptex_gcm },
{ "Plaintext packet with 1-byte header extension and CSRC fields",
srtp_1bytehdrext_cc_ref, srtp_1bytehdrext_cc_cryptex_gcm },
{ "Plaintext packet with 2-byte header extension and CSRC fields",
srtp_2bytehdrext_cc_ref, srtp_2bytehdrext_cc_cryptex_gcm },
{ "Plaintext packet with empty 1-byte header extension and CSRC fields",
srtp_1byte_empty_hdrext_cc_ref,
srtp_1byte_empty_hdrext_cc_cryptex_gcm },
{ "Plaintext packet with empty 2-byte header extension and CSRC fields",
srtp_2byte_empty_hdrext_cc_ref,
srtp_2byte_empty_hdrext_cc_cryptex_gcm },
};
const size_t num_vectors = sizeof(vectors) / sizeof(vectors[0]);
srtp_t srtp_snd, srtp_recv;
int len, ref_len, enc_len;
srtp_policy_t policy;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_gcm_128_16_auth(&policy.rtp);
srtp_crypto_policy_set_aes_gcm_128_16_auth(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key_gcm_cryptex;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
CHECK_OK(srtp_create(&srtp_recv, &policy));
CHECK_OK(srtp_set_stream_use_cryptex(srtp_recv, &policy.ssrc, 1));
/*
* unprotect ciphertext, then compare with plaintext
*/
CHECK_OK(srtp_unprotect(srtp_recv, packet, &len));
CHECK(len == ref_len);
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status;
int len;
srtp_policy_t policy;
int headers[3] = { 1, 3, 4 };
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_rtp_default(&policy.rtp);
srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key_ext_headers;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.enc_xtn_hdr = headers;
policy.enc_xtn_hdr_count = sizeof(headers) / sizeof(headers[0]);
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status)
return status;
/*
* protect plaintext, then compare with ciphertext
*/
len = sizeof(srtp_plaintext_ref);
status = srtp_protect(srtp_snd, srtp_plaintext, &len);
if (status || (len != sizeof(srtp_plaintext)))
return srtp_err_status_fail;
if (srtp_octet_string_is_eq(srtp_plaintext, srtp_ciphertext, len))
return srtp_err_status_fail;
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status)
return status;
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (status) {
return status;
} else if (len != sizeof(srtp_plaintext_ref)) {
return srtp_err_status_fail;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len))
return srtp_err_status_fail;
status = srtp_dealloc(srtp_snd);
if (status)
return status;
status = srtp_dealloc(srtp_recv);
if (status)
return status;
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status;
int len;
srtp_policy_t policy;
int headers[3] = { 1, 3, 4 };
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_gcm_128_8_auth(&policy.rtp);
srtp_crypto_policy_set_aes_gcm_128_8_auth(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key_ext_headers;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.enc_xtn_hdr = headers;
policy.enc_xtn_hdr_count = sizeof(headers) / sizeof(headers[0]);
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status)
return status;
/*
* protect plaintext, then compare with ciphertext
*/
len = sizeof(srtp_plaintext_ref);
status = srtp_protect(srtp_snd, srtp_plaintext, &len);
if (status || (len != sizeof(srtp_plaintext)))
return srtp_err_status_fail;
if (srtp_octet_string_is_eq(srtp_plaintext, srtp_ciphertext, len))
return srtp_err_status_fail;
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status)
return status;
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (status) {
return status;
} else if (len != sizeof(srtp_plaintext_ref)) {
return srtp_err_status_fail;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len))
return srtp_err_status_fail;
status = srtp_dealloc(srtp_snd);
if (status)
return status;
status = srtp_dealloc(srtp_recv);
if (status)
return status;
return srtp_err_status_ok;
}
/*
* srtp_validate_aes_192() verifies the correctness of libsrtp by comparing
* some computed packets against some pre-computed reference values.
* These packets were made with the AES-CM-192/HMAC-SHA-1-80 policy.
*
* The master key and master salt come from RFC 6188 section 7.4 .
* The test vectors where generated using the cipher key and cipher salt
* in section 7.4 with cipher_driver with the nonce and plaintext in the
* srtp_plaintext_ref.
*/
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status;
int len;
srtp_policy_t policy;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_cm_192_hmac_sha1_80(&policy.rtp);
srtp_crypto_policy_set_aes_cm_192_hmac_sha1_80(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0x00000000;
policy.key = aes_192_test_key;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status)
return status;
/*
* protect plaintext, then compare with ciphertext
*/
len = 28;
status = srtp_protect(srtp_snd, srtp_plaintext, &len);
if (status || (len != 38))
return srtp_err_status_fail;
if (srtp_octet_string_is_eq(srtp_plaintext, srtp_ciphertext, len))
return srtp_err_status_fail;
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status)
return status;
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (status) {
return status;
} else if (len != 28) {
return srtp_err_status_fail;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len))
return srtp_err_status_fail;
status = srtp_dealloc(srtp_snd);
if (status)
return status;
status = srtp_dealloc(srtp_recv);
if (status)
return status;
return srtp_err_status_ok;
}
#endif
/*
* srtp_validate_aes_256() verifies the correctness of libsrtp by comparing
* some computed packets against some pre-computed reference values.
* These packets were made with the AES-CM-256/HMAC-SHA-1-80 policy.
*/
srtp_t srtp_snd, srtp_recv;
srtp_err_status_t status;
int len;
srtp_policy_t policy;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_cm_256_hmac_sha1_80(&policy.rtp);
srtp_crypto_policy_set_aes_cm_256_hmac_sha1_80(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = aes_256_test_key;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status) {
return status;
}
/*
* protect plaintext, then compare with ciphertext
*/
len = 28;
status = srtp_protect(srtp_snd, srtp_plaintext, &len);
if (status || (len != 38)) {
return srtp_err_status_fail;
}
if (srtp_octet_string_is_eq(srtp_plaintext, srtp_ciphertext, len)) {
return srtp_err_status_fail;
}
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status) {
return status;
}
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, srtp_ciphertext, &len);
if (status || (len != 28)) {
return status;
}
if (srtp_octet_string_is_eq(srtp_ciphertext, srtp_plaintext_ref, len)) {
return srtp_err_status_fail;
}
status = srtp_dealloc(srtp_snd);
if (status) {
return status;
}
status = srtp_dealloc(srtp_recv);
if (status) {
return status;
}
/*
* loop over policy list, mallocing a new list and copying values
* into it (and incrementing the SSRC value as we go along)
*/
tmp = NULL;
while (policy_array[i] != NULL) {
p = (srtp_policy_t *)malloc(sizeof(srtp_policy_t));
if (p == NULL) {
return srtp_err_status_bad_param;
}
memcpy(p, policy_array[i], sizeof(srtp_policy_t));
p->ssrc.type = ssrc_specific;
p->ssrc.value = ssrc++;
p->next = tmp;
tmp = p;
i++;
}
*list = p;
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_rtp_default(&policy.rtp);
srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status) {
return status;
}
status = srtp_protect(srtp_snd, mesg, &len);
if (status) {
return status;
} else if (len != 12 + 10) {
return srtp_err_status_fail;
}
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status) {
return status;
}
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, mesg, &len);
if (status) {
return status;
} else if (len != 12) {
return srtp_err_status_fail;
}
status = srtp_dealloc(srtp_snd);
if (status) {
return status;
}
status = srtp_dealloc(srtp_recv);
if (status) {
return status;
}
/*
* create a session with a single stream using the default srtp
* policy and with the SSRC value 0xcafebabe
*/
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_aes_gcm_128_8_auth(&policy.rtp);
srtp_crypto_policy_set_aes_gcm_128_8_auth(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&srtp_snd, &policy);
if (status) {
return status;
}
status = srtp_protect(srtp_snd, mesg, &len);
if (status) {
return status;
} else if (len != 12 + 8) {
return srtp_err_status_fail;
}
/*
* create a receiver session context comparable to the one created
* above - we need to do this so that the replay checking doesn't
* complain
*/
status = srtp_create(&srtp_recv, &policy);
if (status) {
return status;
}
/*
* unprotect ciphertext, then compare with plaintext
*/
status = srtp_unprotect(srtp_recv, mesg, &len);
if (status) {
return status;
} else if (len != 12) {
return srtp_err_status_fail;
}
status = srtp_dealloc(srtp_snd);
if (status) {
return status;
}
status = srtp_dealloc(srtp_recv);
if (status) {
return status;
}
/*
* srtp_get_stream() is a libSRTP internal function that we declare
* here so that we can use it to verify the correct operation of the
* library
*/
extern srtp_stream_t srtp_get_stream(srtp_t srtp, uint32_t ssrc);
status = srtp_create_big_policy(&policy_list);
if (status) {
return status;
}
status = srtp_create(&session, policy_list);
if (status) {
return status;
}
/*
* check for false positives by trying to remove a stream that's not
* in the session
*/
status = srtp_remove_stream(session, htonl(0xaaaaaaaa));
if (status != srtp_err_status_no_ctx) {
return srtp_err_status_fail;
}
/*
* check for false negatives by removing stream 0x1, then
* searching for streams 0x0 and 0x2
*/
status = srtp_remove_stream(session, htonl(0x1));
if (status != srtp_err_status_ok) {
return srtp_err_status_fail;
}
stream = srtp_get_stream(session, htonl(0x0));
if (stream == NULL) {
return srtp_err_status_fail;
}
stream = srtp_get_stream(session, htonl(0x2));
if (stream == NULL) {
return srtp_err_status_fail;
}
status = srtp_dealloc(session);
if (status != srtp_err_status_ok) {
return status;
}
status = srtp_dealloc_big_policy(policy_list);
if (status != srtp_err_status_ok) {
return status;
}
/* Now test adding and removing a single stream */
memset(&policy, 0, sizeof(policy));
srtp_crypto_policy_set_rtp_default(&policy.rtp);
srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
policy.ssrc.type = ssrc_specific;
policy.ssrc.value = 0xcafebabe;
policy.key = test_key;
policy.deprecated_ekt = NULL;
policy.window_size = 128;
policy.allow_repeat_tx = 0;
policy.next = NULL;
status = srtp_create(&session, NULL);
if (status != srtp_err_status_ok) {
return status;
}
status = srtp_add_stream(session, &policy);
if (status != srtp_err_status_ok) {
return status;
}
status = srtp_remove_stream(session, htonl(0xcafebabe));
if (status != srtp_err_status_ok) {
return status;
}
status = srtp_dealloc(session);
if (status != srtp_err_status_ok) {
return status;
}
/*
* srtp_test_update() verifies updating/rekeying exsisting streams.
* As stated in https://tools.ietf.org/html/rfc3711#section-3.3.1
* the value of the ROC must not be reset after a rekey, this test
* atempts to prove that srtp_update does not reset the ROC.
*/
/* create a send and recive ctx with defualt profile and test_key */
policy.ssrc.type = ssrc_any_outbound;
status = srtp_create(&srtp_snd, &policy);
if (status)
return status;
policy.ssrc.type = ssrc_any_inbound;
status = srtp_create(&srtp_recv, &policy);
if (status)
return status;
/* protect and unprotect two msg's that will cause the ROC to be equal to 1
*/
msg = srtp_create_test_packet(msg_len_octets, ssrc,
&protected_msg_len_octets);
if (msg == NULL)
return srtp_err_status_alloc_fail;
msg->seq = htons(65535);
status = srtp_protect(srtp_snd, msg, &protected_msg_len_octets);
if (status)
return srtp_err_status_fail;
status = srtp_unprotect(srtp_recv, msg, &protected_msg_len_octets);
if (status)
return status;
status = srtp_protect(srtp_snd, msg, &protected_msg_len_octets);
if (status)
return srtp_err_status_fail;
status = srtp_unprotect(srtp_recv, msg, &protected_msg_len_octets);
if (status)
return status;
free(msg);
/* update send ctx with same test_key t verify update works*/
policy.ssrc.type = ssrc_any_outbound;
policy.key = test_key;
status = srtp_update(srtp_snd, &policy);
if (status)
return status;
status = srtp_protect(srtp_snd, msg, &protected_msg_len_octets);
if (status)
return srtp_err_status_fail;
status = srtp_unprotect(srtp_recv, msg, &protected_msg_len_octets);
if (status)
return status;
free(msg);
/* update send ctx to use test_alt_key */
policy.ssrc.type = ssrc_any_outbound;
policy.key = test_alt_key;
status = srtp_update(srtp_snd, &policy);
if (status)
return status;
/* create and protect msg with new key and ROC still equal to 1 */
msg = srtp_create_test_packet(msg_len_octets, ssrc,
&protected_msg_len_octets);
if (msg == NULL)
return srtp_err_status_alloc_fail;
msg->seq = htons(3);
status = srtp_protect(srtp_snd, msg, &protected_msg_len_octets);
if (status)
return srtp_err_status_fail;
/* verify that recive ctx will fail to unprotect as it still uses test_key
*/
status = srtp_unprotect(srtp_recv, msg, &protected_msg_len_octets);
if (status == srtp_err_status_ok)
return srtp_err_status_fail;
/* create a new recvieve ctx with test_alt_key but since it is new it will
* have ROC equal to 1
* and therefore should fail to unprotected */
{
srtp_t srtp_recv_roc_0;
policy.ssrc.type = ssrc_any_inbound;
policy.key = test_alt_key;
status = srtp_create(&srtp_recv_roc_0, &policy);
if (status)
return status;
status =
srtp_unprotect(srtp_recv_roc_0, msg, &protected_msg_len_octets);
if (status == srtp_err_status_ok)
return srtp_err_status_fail;
status = srtp_dealloc(srtp_recv_roc_0);
if (status)
return status;
}
/* update recive ctx to use test_alt_key */
policy.ssrc.type = ssrc_any_inbound;
policy.key = test_alt_key;
status = srtp_update(srtp_recv, &policy);
if (status)
return status;
/* verify that can still unprotect, therfore key is updated and ROC value is
* preserved */
status = srtp_unprotect(srtp_recv, msg, &protected_msg_len_octets);
if (status)
return status;
free(msg);
status = srtp_dealloc(srtp_snd);
if (status)
return status;
status = srtp_dealloc(srtp_recv);
if (status)
return status;
status = srtp_create(&receiver_session, &receiver_policy);
if (status) {
return status;
}
/* Create and protect packets to get to get roc == 1 */
pkts[0] = srtp_create_test_packet_extended(64, sender_policy.ssrc.value, 65534, 0, &pkt_len_octets[0]);
status = srtp_protect(sender_session, pkts[0], &pkt_len_octets[0]);
if (status) {
return status;
}
status = srtp_get_stream_roc(sender_session, sender_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 0) {
return srtp_err_status_fail;
}
pkts[1] = srtp_create_test_packet_extended(64, sender_policy.ssrc.value, 65535, 1, &pkt_len_octets[1]);
status = srtp_protect(sender_session, pkts[1], &pkt_len_octets[1]);
if (status) {
return status;
}
status = srtp_get_stream_roc(sender_session, sender_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 0) {
return srtp_err_status_fail;
}
pkts[2] = srtp_create_test_packet_extended(64, sender_policy.ssrc.value, 0, 2, &pkt_len_octets[2]);
status = srtp_protect(sender_session, pkts[2], &pkt_len_octets[2]);
if (status) {
return status;
}
status = srtp_get_stream_roc(sender_session, sender_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
pkts[3] = srtp_create_test_packet_extended(64, sender_policy.ssrc.value, 1, 3, &pkt_len_octets[3]);
status = srtp_protect(sender_session, pkts[3], &pkt_len_octets[3]);
if (status) {
return status;
}
status = srtp_get_stream_roc(sender_session, sender_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
pkts[4] = srtp_create_test_packet_extended(64, sender_policy.ssrc.value, 2, 4, &pkt_len_octets[4]);
status = srtp_protect(sender_session, pkts[4], &pkt_len_octets[4]);
if (status) {
return status;
}
status = srtp_get_stream_roc(sender_session, sender_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
/* Unprotect packets in this seq order 65534, 0, 2, 1, 65535 which is
* equivalent to index 0, 2, 4, 3, 1*/
status = srtp_unprotect(receiver_session, pkts[0], &pkt_len_octets[0]);
if (status) {
return status;
}
status = srtp_get_stream_roc(receiver_session, receiver_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 0) {
return srtp_err_status_fail;
}
status = srtp_unprotect(receiver_session, pkts[2], &pkt_len_octets[2]);
if (status) {
return status;
}
status = srtp_get_stream_roc(receiver_session, receiver_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
status = srtp_unprotect(receiver_session, pkts[4], &pkt_len_octets[4]);
if (status) {
return status;
}
status = srtp_get_stream_roc(receiver_session, receiver_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
status = srtp_unprotect(receiver_session, pkts[3], &pkt_len_octets[3]);
if (status) {
return status;
}
status = srtp_get_stream_roc(receiver_session, receiver_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
status = srtp_unprotect(receiver_session, pkts[1], &pkt_len_octets[1]);
if (status) {
return status;
}
status = srtp_get_stream_roc(receiver_session, receiver_policy.ssrc.value,
&stream_roc);
if (status) {
return status;
}
if (stream_roc != 1) {
return srtp_err_status_fail;
}
/* Cleanup */
status = srtp_dealloc(sender_session);
if (status) {
return status;
}
status = srtp_dealloc(receiver_session);
if (status) {
return status;
}
/* Create the first packet to decrypt and test for ROC change */
pkt_1 = srtp_create_test_packet_extended(msg_len_octets,
sender_policy.ssrc.value, seq, ts,
&protected_msg_len_octets_1);
status = srtp_protect(sender_session, pkt_1, &protected_msg_len_octets_1);
if (status) {
return status;
}
/* Create the second packet to decrypt and test for ROC change */
seq++;
ts++;
pkt_2 = srtp_create_test_packet_extended(msg_len_octets,
sender_policy.ssrc.value, seq, ts,
&protected_msg_len_octets_2);
status = srtp_protect(sender_session, pkt_2, &protected_msg_len_octets_2);
if (status) {
return status;
}
status = srtp_create(&receiver_session, &receiver_policy);
if (status) {
return status;
}
/* Make a copy of the first sent protected packet */
recv_pkt_1 = malloc(protected_msg_len_octets_1);
if (recv_pkt_1 == NULL) {
return srtp_err_status_fail;
}
memcpy(recv_pkt_1, pkt_1, protected_msg_len_octets_1);
/* Make a copy of the second sent protected packet */
recv_pkt_2 = malloc(protected_msg_len_octets_2);
if (recv_pkt_2 == NULL) {
return srtp_err_status_fail;
}
memcpy(recv_pkt_2, pkt_2, protected_msg_len_octets_2);
/* Set the ROC to the wanted value */
status = srtp_set_stream_roc(receiver_session, receiver_policy.ssrc.value,
roc_to_set);
if (status) {
return status;
}
/* Unprotect the first packet */
status = srtp_unprotect(receiver_session, recv_pkt_1,
&protected_msg_len_octets_1);
if (status) {
return status;
}
/* Unprotect the second packet */
status = srtp_unprotect(receiver_session, recv_pkt_2,
&protected_msg_len_octets_2);
if (status) {
return status;
}
/* Cleanup */
status = srtp_dealloc(sender_session);
if (status) {
return status;
}
status = srtp_dealloc(receiver_session);
if (status) {
return status;
}
status = srtp_create(&sender_session, &sender_policy);
if (status) {
return status;
}
/* Set the ROC before encrypting the first packet */
status = srtp_set_stream_roc(sender_session, sender_policy.ssrc.value,
roc_to_set);
if (status != srtp_err_status_ok) {
return status;
}
/* Create the packet to decrypt */
ts = 0;
pkt = srtp_create_test_packet_extended(msg_len_octets,
sender_policy.ssrc.value, seq, ts,
&protected_msg_len_octets);
status = srtp_protect(sender_session, pkt, &protected_msg_len_octets);
if (status) {
return status;
}
status = srtp_create(&receiver_session, &receiver_policy);
if (status) {
return status;
}
/* Make a copy of the sent protected packet */
recv_pkt = malloc(protected_msg_len_octets);
if (recv_pkt == NULL) {
return srtp_err_status_fail;
}
memcpy(recv_pkt, pkt, protected_msg_len_octets);
/* Set the ROC to the wanted value */
status = srtp_set_stream_roc(receiver_session, receiver_policy.ssrc.value,
roc_to_set);
if (status) {
return status;
}
status =
srtp_unprotect(receiver_session, recv_pkt, &protected_msg_len_octets);
if (status) {
return status;
}
/* Cleanup */
status = srtp_dealloc(sender_session);
if (status) {
return status;
}
status = srtp_dealloc(receiver_session);
if (status) {
return status;
}
free(pkt);
free(recv_pkt);
return srtp_err_status_ok;
}
srtp_err_status_t srtp_test_set_receiver_roc(void)
{
int packets;
uint32_t roc;
srtp_err_status_t status;
/* First test does not rollover */
packets = 1;
roc = 0;
status = test_set_receiver_roc(packets - 1, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets + 1, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets + 60000, roc);
if (status) {
return status;
}
/* Second test should rollover */
packets = 65535;
roc = 0;
status = test_set_receiver_roc(packets - 1, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets, roc);
if (status) {
return status;
}
/* Now the rollover counter should be 1 */
roc = 1;
status = test_set_receiver_roc(packets + 1, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets + 60000, roc);
if (status) {
return status;
}
status = test_set_receiver_roc(packets + 65535, roc);
if (status) {
return status;
}
srtp_master_key_t *test_256_keys[2] = {
&master_key_1,
&master_key_2
};
// clang-format on
const srtp_policy_t aes_256_hmac_policy = {
{ ssrc_any_outbound, 0 }, /* SSRC */
{
/* SRTP policy */
SRTP_AES_ICM_256, /* cipher type */
SRTP_AES_ICM_256_KEY_LEN_WSALT, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 10, /* auth tag length in octets */
sec_serv_conf_and_auth /* security services flag */
},
{
/* SRTCP policy */
SRTP_AES_ICM_256, /* cipher type */
SRTP_AES_ICM_256_KEY_LEN_WSALT, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 10, /* auth tag length in octets */
sec_serv_conf_and_auth /* security services flag */
},
NULL,
(srtp_master_key_t **)test_256_keys, 2, /* indicates the number of Master keys */
NULL, /* indicates that EKT is not in use */ 128, /* replay window size */ 0, /* retransmission not allowed */
NULL, /* no encrypted extension headers */ 0, /* list of encrypted extension headers is empty */
NULL
};
const srtp_policy_t aes_256_hmac_32_policy = {
{ ssrc_any_outbound, 0 }, /* SSRC */
{
/* SRTP policy */
SRTP_AES_ICM_256, /* cipher type */
SRTP_AES_ICM_256_KEY_LEN_WSALT, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 4, /* auth tag length in octets */
sec_serv_conf_and_auth /* security services flag */
},
{
/* SRTCP policy */
SRTP_AES_ICM_256, /* cipher type */
SRTP_AES_ICM_256_KEY_LEN_WSALT, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 10, /* auth tag length in octets. 80 bits per RFC 3711. */
sec_serv_conf_and_auth /* security services flag */
},
NULL,
(srtp_master_key_t **)test_256_keys, 2, /* indicates the number of Master keys */
NULL, /* indicates that EKT is not in use */ 128, /* replay window size */ 0, /* retransmission not allowed */
NULL, /* no encrypted extension headers */ 0, /* list of encrypted extension headers is empty */
NULL
};
char ekt_test_policy = 'x';
const srtp_policy_t hmac_only_with_ekt_policy = {
{ ssrc_any_outbound, 0 }, /* SSRC */
{
SRTP_NULL_CIPHER, /* cipher type */ 0, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 4, /* auth tag length in octets */
sec_serv_auth /* security services flag */
},
{
SRTP_NULL_CIPHER, /* cipher type */ 0, /* cipher key length in octets */
SRTP_HMAC_SHA1, /* authentication func type */ 20, /* auth key length in octets */ 4, /* auth tag length in octets */
sec_serv_auth /* security services flag */
},
NULL,
(srtp_master_key_t **)test_keys, 2, /* indicates the number of Master keys */
&ekt_test_policy, /* requests deprecated EKT functionality */ 128, /* replay window size */ 0, /* retransmission not allowed */
NULL, /* no encrypted extension headers */ 0, /* list of encrypted extension headers is empty */
NULL
};
/*
* an array of pointers to the policies listed above
*
* This array is used to test various aspects of libSRTP for
* different cryptographic policies. The order of the elements
* matters - the timing test generates output that can be used
* in a plot (see the gnuplot script file 'timing'). If you
* add to this list, you should do it at the end.
*/
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.248Bemerkung:
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.