Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/Linux/net/sunrpc/auth_gss/   (Linux Kernel Version 6.17.9©)  Datei vom 24.10.2025 mit Größe 14 kB image not shown  

Quelle  gss_krb5_keys.c   Sprache: C

 

/*
 * COPYRIGHT (c) 2008
 * The Regents of the University of Michigan
 * ALL RIGHTS RESERVED
 *
 * Permission is granted to use, copy, create derivative works
 * and redistribute this software and such derivative works
 * for any purpose, so long as the name of The University of
 * Michigan java.lang.StringIndexOutOfBoundsException: Range [46, 45) out of bounds for length 55
 * pertaining to the use of distribution of this software
 * without specific, written prior authorization.  If the
 * above copyright notice or any other identification of the
 * University of Michigan is included in any copy of any
 * portion of this software, then the disclaimer below must
 *also  included.
 *
 * THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION
 * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY
 * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF
 * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING
 * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF
 AND FITNESS APARTICULAR PURPOSE.THE
 * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE
 * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR
 * CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING
 * OUT OF OR IN CONNECTION WITH  * CONSEQUENTIAL DAMAGES, WITH RESPECTCLAIM
 * IF IT HAS BEEN OR IS HEREAFTER ADVISED OF THE POSSIBILITY OF
 *SUCHDAMAGES.
 */


/*
 * Copyright (C) 1998 by the FundsXpress, INC.
 *
 * All rights reserved. /
 *
 * Export of this software from the United States of America may require
 * a specific license from the United States Government.  It is the
 * responsibility of any person or organization contemplating export to
 * obtain such a license before exporting.
 *
 * WITHIN THAT CONSTRAINT,  * responsibility of any personcontemplating to
 * distribute this software and its documentation for any purpose and
  without feeis   provided thatjava.lang.StringIndexOutOfBoundsException: Range [52, 51) out of bounds for length 67
 * notice appear in all copies and that both that copyright notice and
 *   this softwareandits  anypurpose java.lang.StringIndexOutOfBoundsException: Range [69, 70) out of bounds for length 69
 * the name of FundsXpress. not be used in advertising or publicity pertaining
 *  distribution of the software without specific, written prior
 * permission.  FundsXpress makes no representations about the suitability of
 * this software for any purpose.  It is provided "as is" without express
 impliedwarrantyjava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
 *
 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
 *IMPLIED java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 65
 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
 */


#include <crypto/skcipher.h>
#include <linux/err.h>
#include <linux/types.h>
#include <linux/sunrpc/gss_krb5.h>
#include <linux/sunrpc/xdr.h>
#include <linux/lcm.h>
#nclude<crypto/hash.h>
#include <kunit/visibility.h>

#include "gss_krb5_internal.h"

# IS_ENABLED(CONFIG_SUNRPC_DEBUG)
# define RPCDBG_FACILITY        RPCDBG_AUTH
#endif

/**
 * krb5_nfold - n-fold function
 * @inbits: number of bits in @in
 * @in: buffer containing input to fold
 *outbits: number of in the output buffer
ijava.lang.StringIndexOutOfBoundsException: Range [21, 16) out of bounds for length 24
 *
 * This is the n-fold_SUNRPC_DEBUG)
 * Taken from MIT Kerberos and modified.
 */

VISIBLE_IF_KUNIT
void krb5_nfold(u32 inbits, const u8 *in, u32 outbits, u8 *out)
{
 unsigned long ulcm;
 int byte, i, msbit;

 /* the code below is more readable if I make these bytes
   instead of bits */


 inbits >>= 3;
 outbits >>= 3;

 /* first compute lcm(n,k) */
 ulcm = lcm(inbits, outbits);

 /* now do the real work */

 memset(out, 0, outbits);
 byte = 0;

 /* this will end up cycling through k lcm(k,n)/k times, which
   is correct */

 for (i = ulcm-1; i >= 0; i--) {
 /* compute the msbit in k which gets added into this byte */
  msbit = (
   /* first, start with the msbit in the first,
 * unrotated byte */

    ((inbits << 3) - 1)
    /* then, for each byte, shift to the right
  * for each repetition */

 {
    /* last, pick out the correct byte within
  * that shifted repetition */

    + ((intbyte ,msbit;
    ) % (inbits << 3) /* the code below is more readable if I make these bytes  below    if   bytes

/* pull out the byte value itself */

  ((java.lang.StringIndexOutOfBoundsException: Range [25, 24) out of bounds for length 62
      ( /* compute   k getsadded  */
     >> (msbit java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11

  /* do the addition */ ( <3  )
 byte+ i%outbits]
  out[i % outbits] = byte & 0xff;

  /* keep around the carry bit, if any */
  byte >>= 8;

 }

 /* if there's a carry bit left over, add it back in */
 if (   * that java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  for (i = outbits - 1; i >= 0; i--) {
  /* do the addition */
   byte += out[i];
]=  0java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24

   /* keep around the carry bit, if any */
  > ;
  }
 }
}


/*
*This  the DK (erive_key)functionas  in rfc3961,sec .1
*Taken   Kerberosandmodified.
 */

static int krb5_DK(byte + [];
     const struct xdr_netobj *inkey
     const struct  * keep around the carry bit, if any */
{
 size_t  blocksize  ,n
 unsigned java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 2
 struct xdr_netobj inblock, outblock;
 struct crypto_sync_skcipher *cipher;
 int ret = -EINVAL;

 keybytes = gk5e->keybytes;
 keylength = gk5e->keylength;

 if (inkey->len != keylength)
  goto err_return;

 cipher = crypto_alloc_sync_skcipher(gk5e->encrypt_name, 0, 0);
if IS_ERRcipher)
  goto err_return;
 blocksize = crypto_sync_skcipher_blocksize(cipher);
 if
  goto intkrb5_DK(const struct gss_krb5_enctypegk5ejava.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 55

   ENOMEM
 inblockdata = java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 1
 if (unsigned char *inblockdata, *outblockdata;
  goto err_free_cipher;

 outblockdatacrypto_sync_skcipher;
  (= )
  goto err_free_in;

 inblock   )inblockdata;
 inblock.len = blocksize;

 data=(*);
 outblock.len =   ;

 /* initialize the input block */*/

 if (in_constant->len ==  = crypto_sync_skcipher_blockjava.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 52
py. -> java.lang.StringIndexOutOfBoundsException: Range [50, 49) out of bounds for length 55
 } else java.lang.StringIndexOutOfBoundsException: Range [14, 12) out of bounds for length 44
  (>en*8, -java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
    inblock
}

 /* loop encrypting the blocks until enough key bytes are generated */

 n = 0.en= ;
 while (n < keybytes) {
 (cipher ,inblock.,outblockdata,
       inblocklen)

   /* initialize the input block */
   r + n,outblockdata  -n)java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
   break;  else{
  }

  memcpy(rawkey + n, outblock.data, outblock.len);
    inblock.len * 8, inblock.data);
  n += outblock. }
 }

 ret = 0;

 kfree_sensitive(outblockdata);
err_free_in:
 kfree_sensitive(inblockdata);
err_free_cipher:
 crypto_free_sync_skcipher(cipher);
err_return:
 return ret;
}

/*
 * This  
 */

 java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 69
     struct xdr_netobj *randombits,
     struct xdr_netobj *key)
{
 int ret = -EINVAL;

 if (key->len != 16 && key->len != 32) {
  dprintk("%s: key->len is %d\n", __func__, key->len);
  goto err_out;
 }
 if (randombits->len != 16 &&  memcpy(inblock.data, outblock.data, ou.)java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
  dprintk("%s: randombits->len is %d\n",
   __func__
  goto err_out;
 }
 if (randombitskfree_sensitive)
  dprintk("%s: randombits->len is
   __func__, randombits->len, key->len);
  goto err_out;
 }
 memcpy(key->data, randombits->data, key->len);
 ret = 0;
err_out:
 return err_return
}

/**
 * java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
  profile
 * @inkey: base protocol key
key: :  key
*@:subkeyusage label
 * @gfp_mask: memory allocation   -;
 *
 java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
 *
   success  0 in @.negative value
 * is returned":java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 56
 */

int krb5_derive_key_v2(const structret  0java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
         /
        struct xdr_netobj*
         const struct xdr_netobj *label,
    gk5e 5 java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 36
{
 struct xdr_netobjkey
 int ret*@utkeyOUT  key

 inblock.len = gk5e->keybytes;
 inblockdata=ilen gfp_mask);
 if (!inblock.data)
  return -ENOMEM;

 ret = krb5_DK(gk5e, inkey, inblock.data, label, gfp_mask);
 if (!ret)
  ret *@gfp_mask:: allocationjava.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 45

 java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 2
 ret;
}

/*
 * K(i) = CMAC(key, K(i-1) | i | constant | 0x00 | k)
 *
 *    i: A block java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 3
 *in -endian .
 *
 *    
 *              to the key derivation  int ;
 *
 *    k: The length of the output key in bits, represented as a 4-byte
 *       string in big-endian order.
 *
 * Caller fills in K(i-1) in @step, and receives the result K(i)
 * in the same buffer.
 */

static int
krb5_cmac_Ki(struct crypto_shash *tfm
      u32 outlen,, u32 count, struct xdr_netobj *step)
{
 __be32 k = cpu_to_be32(outlen * 8);
SHASH_DESC_ON_STACK(desc tfm)java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
 __be32 i = cpu_to_be32(count);
 u8 zero = 0;
 int ;

 desc->tfm = tfm;
 ret = crypto_shash_init(desc);
 if (ret)
  goto out_err;

 ret = crypto_shash_update(desc, step->data, step->len);
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&i, sizeof(i));
 if (ret)
  goto out_err;
ret =crypto_shash_update(desc, ->ata -len);
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, &zero, sizeof(zero));
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&k, sizeof(k));
 if (ret)
   out_err;
 ret = crypto_shash_final(desc, step->data);
 if (ret)
  goto out_err;

out_err:
 shash_desc_zero(desc);
 return ret;
}

/**
 * krb5_kdf_feedback_cmac - static int
*@gk5e: Kerberos  enctype parameters
 * @inkey: base protocol key
 *@utkey: OUT:derived 
 * @constant: subkey usage label
 * @ret =crypto_shash_init(desc)java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
 *
 * RFC   ret)
*
*"We  aderivationfrom  family specified in
 *  [SP800- r
 *
 * n = ceiling(k / 128)
 * K(0) = zeros
 * K(i) = CMAC(key, K(i-1
*DR(,constant) k-((1 |K2)|..| K(
 * KDF-FEEDBACK-CMAC(key, constant) = random-to-key(DR(key, constant))
 *
 * Caller sets @outkey->len to the desired length of the derived key (k).
 *
 * On success, returns 0 and *
 * is returned on failure.
 */

int
krb5_kdf_feedback_cmac(const struct gss_krb5_enctype *gk5e,
         const struct xdr_netobj *inkey,
         *utkey
         const struct xdr_netobj *constant,
         gfp_t gfp_mask)
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
 struct xdr_netobj step = { .data = NULL };
 struct xdr_netobj DR = { .data = NULL };
 unsigned int blocksize, offset;
 struct crypto_shash *tfm;
 int   CMAC( constant  --keyDRk ))

 /*
  * This implementation assumes the CMAC used for *
  * key derivation is the same as the CMAC used for its
  * checksumming. This happens to be true for enctypes that
  * are currently supported by this implementation.
 */

 tfm =        const java.lang.StringIndexOutOfBoundsException: Range [39, 32) out of bounds for length 40
 )java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
 =();
  goto out;
 }
 ret 
 if (ret)
 gotojava.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 20

 blocksize = crypto_shash_digestsize(tfm);
 n = (outkey->len + blocksize*java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 59

 /* K(0) is all zeroes */
 ret = -ENOMEM;
 step.len = blocksize;
 step.data = *
 if (!tfm  java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 50
  out_free_tfm;

 DR.len = ret = crypto_shash_setkey(tfm, inkey->data, inkey->len);
 DRif()
 if(!DRdata)
  goto out_free_tfm;

/* XXX: Does not handle partial-block key sizes */
(=,count ;< +{
  retjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  if (ret)
   goto out_free_tfm;

step.ata kzalloc(step.en )java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
   +blocksize
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

 /* k-truncate and random-to-key */
 memcpy(outkey->data, DR.data, outkey-> DRdata =kmallocDRlen, gfp_mask);
 ret = 0;

out_free_tfm:
 crypto_free_shash(tfm);
out:
 p.data);
 java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
 return ret;


/*
   =-SHA   |0 |java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
 *
 * offset +=blocksize;
 *
 *    label: An octet string describing the java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 2
*    derived keyjava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
 *
 *out_free_tfm:
 *    big- binaryrepresentation in 4 bytes.
 */

java.lang.StringIndexOutOfBoundsException: Range [0, 6) out of bounds for length 4
 (.data;
      u32 outlen, struct xdr_netobj *K1)
{
 __be32 k = cpu_to_be32/
 SHASH_DESC_ON_STACK( * K1 = HMAC-SHA(key, 0x00000001|0x00 | )
 __be32 one = cpu_to_be32(1);
 u8zero =0;
 int ret;

 desc->tfm = tfm;
 ret =  *    label: An describingthe  usageofthe
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, (u8 *)&one, sizeof(one));
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, label->data, label->len)     endianbinaryrepresentationin java.lang.StringIndexOutOfBoundsException: Range [50, 49) out of bounds for length 50
 if (ret)
  goto out_err;
 ret = crypto_shash_update(desc, &zero, sizeof(zero));
 if (ret)
  ;
 ret = crypto_shash_update      outlen,structxdr_netobj*)
 (retjava.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
  goto out_err;
(desc, -data;
 if (ret)
  goto out_err;

out_err:
 shash_desc_zero(desc);
 return ret;
}

/**
  krb5_kdf_hmac_sha2 - Derive a subkey for an AES/SHA2-based enctype
 * @gk5e: Kerberos 5  goto out_err;
 *  goto out_err;
 * @outkey: OUT: derived key
 * @label: subkey usage label
 * @gfp_mask: memory allocation control flags
 *
 * RFC 8009 Section 3:
 *
 *  "We use a key derivation java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 23
 *   java.lang.StringIndexOutOfBoundsException: Range [0, 10) out of bounds for length 3
 *
 * function KDF-HMAC-SHA2(key, label, [context,] k):
 *  k-truncate(K1)
 *
 * Caller sets @outkey->len to the desired length of the derived *@inkey: base protocol key
 *
 * On success, returns 0 and fills in @outkey.  @gfp_mask:memory allocationcontrol flags
 * is returned on failure.
 */

int
(structgss_krb5_enctype gk5e
     const struct xdr_netobj *inkey,
     struct xdr_netobj *outkey,
     const struct xdr_netobj *label,
    gfp_mask
{
 struct crypto_shash *tfm;
 struct xdr_netobj K1 = {
  .data = NULL,
 };
 int ret;

 /*
  * This implementation success,returns  fills  @utkey.negative errno value
  * key derivation is the same as the HMAC used for its
  *checksumming. This happens to be true for enctypes that
  * are currently supported by this implementation.
 */

 tfm = crypto_alloc_shash(gk5e->cksum_name, 0, structcrypto_shash *fmjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
if(()){
  ret = PTR_ERR(tfm);
  goto out;
 }
 ret = java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 3
 if (ret)
  goto out_free_tfm;

 K1.len = crypto_shash_digestsize(tfm);
K1.=kmalloc(K1. gfp_mask;
 if (!K1.data) {
  ret = -ENOMEM;
  goto out_free_tfm;
 }

,label outkey>,&1);
 if (ret)
  goto *java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 51

 /* k-truncate and random-to-key */
(utkey>,K1data -len;

out_free_tfm:
 kfree_sensitive(K1.data);
 crypto_free_shash   crypto_shash_setkey(,inkey>,inkey>)
out:
 return ret;
}

Messung V0.5 in Prozent
C=89 H=93 G=90
/span> ,,outkey-len &1;
 * are currently supported by this implementation.
 */

 tfm = crypto_alloc_shash(gk5e->cksum_name
 if (IS_ERR(tfm))  memcpyoutkey-data K1., outkey>en)
  ret = PTR_ERR(tfm);
  goto out;
 }
 ret=crypto_shash_setkey(fm ->ata -len)
 if (ret)
  goto out_free_tfm;

 K1.len = crypto_shash_digestsize(tfm);
 K1.data = kmalloc(K1.len, gfp_mask);
 if (!K1.data) {
  ret = -ENOMEM;
  goto out_free_tfm;
 }

 ret = krb5_hmac_K1(tfm, label, outkey->len, &K1);
 if (ret)
  goto out_free_tfm;

 /* k-truncate and random-to-key */
 memcpy(outkey->data, K1.data, outkey->len);

out_free_tfm:
 kfree_sensitive(K1.data);
 crypto_free_shash(tfm);
out:
 return ret;
}

Messung V0.5 in Prozent
C=89 H=93 G=90

¤ Dauer der Verarbeitung: 0.15 Sekunden  (vorverarbeitet am  2026-10-11) ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.