Clean up RSA PMS checking code

This commit is contained in:
Manuel Pégourié-Gonnard 2015-06-23 18:52:09 +02:00
parent 19eef51487
commit b26b75e17b

View file

@ -2888,7 +2888,8 @@ static int ssl_parse_encrypted_pms( ssl_context *ssl,
unsigned char *pms = ssl->handshake->premaster + pms_offset;
unsigned char fake_pms[48], peer_pms[48];
unsigned char mask;
size_t i, diff, peer_pmslen;
size_t i, peer_pmslen;
unsigned int diff;
if( ! pk_can_do( ssl_own_key( ssl ), POLARSSL_PK_RSA ) )
{
@ -2934,7 +2935,7 @@ static int ssl_parse_encrypted_pms( ssl_context *ssl,
sizeof( peer_pms ),
ssl->f_rng, ssl->p_rng );
diff = (size_t) ret;
diff = (unsigned int) ret;
diff |= peer_pmslen ^ 48;
diff |= peer_pms[0] ^ ssl->handshake->max_major_ver;
diff |= peer_pms[1] ^ ssl->handshake->max_minor_ver;
@ -2952,8 +2953,8 @@ static int ssl_parse_encrypted_pms( ssl_context *ssl,
}
ssl->handshake->pmslen = 48;
mask = ( diff | - diff ) >> ( sizeof( size_t ) * 8 - 1 );
mask = (unsigned char)( - ( ret != 0 ) ); /* mask = diff ? 0xff : 0x00 */
/* mask = diff ? 0xff : 0x00 */
mask = - ( diff | - diff ) >> ( sizeof( unsigned int ) * 8 - 1 );
for( i = 0; i < ssl->handshake->pmslen; i++ )
pms[i] = ( mask & fake_pms[i] ) | ( (~mask) & peer_pms[i] );