Fix the error detection in psa_generate_random

If a call to mbedtls_psa_get_random other than the last one failed,
this went undetected.

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
This commit is contained in:
Gilles Peskine 2021-01-05 14:10:59 +01:00
parent 71ddab9154
commit 0c59ba88cb

View file

@ -6394,19 +6394,20 @@ psa_status_t psa_generate_random( uint8_t *output,
#else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */ #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
int ret = 0;
while( output_size > 0 ) while( output_size > 0 )
{ {
size_t request_size = size_t request_size =
( output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ? ( output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
MBEDTLS_PSA_RANDOM_MAX_REQUEST : MBEDTLS_PSA_RANDOM_MAX_REQUEST :
output_size ); output_size );
ret = mbedtls_psa_get_random( MBEDTLS_PSA_RANDOM_STATE, int ret = mbedtls_psa_get_random( MBEDTLS_PSA_RANDOM_STATE,
output, request_size ); output, request_size );
if( ret != 0 )
return( mbedtls_to_psa_error( ret ) );
output_size -= request_size; output_size -= request_size;
output += request_size; output += request_size;
} }
return( mbedtls_to_psa_error( ret ) ); return( PSA_SUCCESS );
#endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */ #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
} }