1 /*
2 * Copyright 2014 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17 #include <keymaster/serializable.h>
18
19 #include <assert.h>
20
21 #include <keymaster/android_keymaster_utils.h>
22
23 namespace keymaster {
24
__buffer_bound_check(const uint8_t * buf,const uint8_t * end,size_t len)25 bool __buffer_bound_check(const uint8_t* buf, const uint8_t* end, size_t len) {
26 uintptr_t buf_next;
27 bool overflow_occurred = __builtin_add_overflow(__pval(buf), len, &buf_next);
28 return (!overflow_occurred) && (buf_next <= __pval(end));
29 }
30
append_to_buf(uint8_t * buf,const uint8_t * end,const void * data,size_t data_len)31 uint8_t* append_to_buf(uint8_t* buf, const uint8_t* end, const void* data, size_t data_len) {
32 if (__buffer_bound_check(buf, end, data_len)) {
33 memcpy(buf, data, data_len);
34 return buf + data_len;
35 } else {
36 return buf;
37 }
38 }
39
copy_from_buf(const uint8_t ** buf_ptr,const uint8_t * end,void * dest,size_t size)40 bool copy_from_buf(const uint8_t** buf_ptr, const uint8_t* end, void* dest, size_t size) {
41 if (__buffer_bound_check(*buf_ptr, end, size)) {
42 memcpy(dest, *buf_ptr, size);
43 *buf_ptr += size;
44 return true;
45 } else {
46 return false;
47 }
48 }
49
copy_size_and_data_from_buf(const uint8_t ** buf_ptr,const uint8_t * end,size_t * size,UniquePtr<uint8_t[]> * dest)50 bool copy_size_and_data_from_buf(const uint8_t** buf_ptr, const uint8_t* end, size_t* size,
51 UniquePtr<uint8_t[]>* dest) {
52 if (!copy_uint32_from_buf(buf_ptr, end, size)) return false;
53
54 if (*size == 0) {
55 dest->reset();
56 return true;
57 }
58
59 if (__buffer_bound_check(*buf_ptr, end, *size)) {
60 dest->reset(new (std::nothrow) uint8_t[*size]);
61 if (!dest->get()) {
62 return false;
63 }
64 return copy_from_buf(buf_ptr, end, dest->get(), *size);
65 } else {
66 return false;
67 }
68 }
69
reserve(size_t size)70 bool Buffer::reserve(size_t size) {
71 if (available_write() < size) {
72 if (!valid_buffer_state()) {
73 return false;
74 }
75
76 size_t new_size = buffer_size_ + size - available_write();
77 uint8_t* new_buffer = new (std::nothrow) uint8_t[new_size];
78 if (!new_buffer) return false;
79 memcpy(new_buffer, buffer_.get() + read_position_, available_read());
80 memset_s(buffer_.get(), 0, buffer_size_);
81 buffer_.reset(new_buffer);
82 buffer_size_ = new_size;
83 write_position_ -= read_position_;
84 read_position_ = 0;
85 }
86 return true;
87 }
88
Reinitialize(size_t size)89 bool Buffer::Reinitialize(size_t size) {
90 Clear();
91 buffer_.reset(new (std::nothrow) uint8_t[size]);
92 if (!buffer_.get()) return false;
93 buffer_size_ = size;
94 read_position_ = 0;
95 write_position_ = 0;
96 return true;
97 }
98
Reinitialize(const void * data,size_t data_len)99 bool Buffer::Reinitialize(const void* data, size_t data_len) {
100 Clear();
101 if (__pval(data) + data_len < __pval(data)) // Pointer wrap check
102 return false;
103 buffer_.reset(new (std::nothrow) uint8_t[data_len]);
104 if (!buffer_.get()) return false;
105 buffer_size_ = data_len;
106 memcpy(buffer_.get(), data, data_len);
107 read_position_ = 0;
108 write_position_ = buffer_size_;
109 return true;
110 }
111
available_write() const112 size_t Buffer::available_write() const {
113 assert(buffer_size_ >= write_position_);
114 return buffer_size_ - write_position_;
115 }
116
available_read() const117 size_t Buffer::available_read() const {
118 assert(buffer_size_ >= write_position_);
119 assert(write_position_ >= read_position_);
120 return write_position_ - read_position_;
121 }
122
valid_buffer_state() const123 bool Buffer::valid_buffer_state() const {
124 return (buffer_size_ >= write_position_) && (write_position_ >= read_position_);
125 }
126
write(const uint8_t * src,size_t write_length)127 bool Buffer::write(const uint8_t* src, size_t write_length) {
128 if (available_write() < write_length) return false;
129 memcpy(buffer_.get() + write_position_, src, write_length);
130 write_position_ += write_length;
131 return true;
132 }
133
read(uint8_t * dest,size_t read_length)134 bool Buffer::read(uint8_t* dest, size_t read_length) {
135 if (available_read() < read_length) return false;
136 memcpy(dest, buffer_.get() + read_position_, read_length);
137 read_position_ += read_length;
138 return true;
139 }
140
advance_write(int distance)141 bool Buffer::advance_write(int distance) {
142 if (distance < 0) {
143 return false;
144 }
145
146 const size_t validated_distance = static_cast<size_t>(distance);
147 size_t new_write_position = 0;
148
149 // if an integer overflow occurred or the new position exceeds the buffer_size return false.
150 if (__builtin_add_overflow(write_position_, validated_distance, &new_write_position) ||
151 new_write_position > buffer_size_) {
152 return false;
153 }
154
155 write_position_ = new_write_position;
156 return true;
157 }
158
SerializedSize() const159 size_t Buffer::SerializedSize() const {
160 return sizeof(uint32_t) + available_read();
161 }
162
Serialize(uint8_t * buf,const uint8_t * end) const163 uint8_t* Buffer::Serialize(uint8_t* buf, const uint8_t* end) const {
164 return append_size_and_data_to_buf(buf, end, peek_read(), available_read());
165 }
166
Deserialize(const uint8_t ** buf_ptr,const uint8_t * end)167 bool Buffer::Deserialize(const uint8_t** buf_ptr, const uint8_t* end) {
168 Clear();
169 if (!copy_size_and_data_from_buf(buf_ptr, end, &buffer_size_, &buffer_)) {
170 buffer_.reset();
171 buffer_size_ = 0;
172 return false;
173 }
174 write_position_ = buffer_size_;
175 return true;
176 }
177
Clear()178 void Buffer::Clear() {
179 memset_s(buffer_.get(), 0, buffer_size_);
180 buffer_.reset();
181 read_position_ = 0;
182 write_position_ = 0;
183 buffer_size_ = 0;
184 }
185
186 } // namespace keymaster
187