Repository navigation
Fix RSA modulus, output and scratch bounds (N-146) - #168
Merged
Merged
Conversation
…-146) ami_crypto_method_rsa (src/tls/ami_tls_crypto.c) had the vendored method's shape: the output compared with the exponent's length, the scratch length never given to ami_rsa_exponentiate(), the setup and extract statuses dropped. It now checks the output against the modulus, passes and checks the scratch in the vendored operation's units and formula, and returns those statuses. The modulus ceiling comes with the vendored init it delegates to. tests/fuzz/tls_rsa_bounds (32-bit, beside tls_rsa_key_regression) runs the same contracts on crypto_method_rsa and ours: a 4096-bit modulus accepted and a 4104-bit or zero one refused with the context untouched; a real 2048-bit signature verified into an output exactly the modulus long; one byte short refused with nothing written at or past it (a canary inside the test's own array); an overlong exponent an error; and the vendored operation's scratch one USHORT short refused, exactly enough used. Benign only: no oversized exponentiation is run. Pairs with tinic/netxduo b96bbb26 (local, not pushed), off fork master defce9de; the gitlink is NOT moved. Unfixed (defce9de + main's ami_tls_crypto.c): 13 of 22 checks fail. Fixed: 22/22. HOST32 25 -> 26. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ntrols (N-146 amendment) ami_crypto_method_rsa_init() now refuses 0, non-byte and over AMI_TLS_RSA_MAX_MODULUS_BITS (4096) itself, before the vendored init: that ceiling, NX_CRYPTO_MAX_RSA_MODULUS_SIZE, may be raised by a build, but AMI_TLS_POWM_SCRATCH_LIMBS is fixed, and a _Static_assert now ties the two (C68K_POWM_SCRATCH_LIMBS(128, 1) = 2704). ami_rsa_exponentiate() counts the scratch in limb-rounded lengths, as the vendored operation now does. tls_rsa_bounds adds: a 2047-bit (non-byte) modulus refused by both methods; a valid public exponent zero-padded past the modulus length still verifying (the reason there is no explicit exponent <= modulus check); and the vendored operation with a 257-byte modulus refusing 913 USHORTs and accepting 914 (7 * 260 + 8 bytes). Coverage limits: the CRT path is exercised by tls_rsa_key_regression's signing only, not by this test; the extract-status propagation is source-only. Pairs with tinic/netxduo 4bf8d7e1. Unfixed: 18 of 30 checks fail; fixed 30/30; host32 26/26. CHANGELOG: the N-146 entry from 636e213 covers this. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…146) Brings in PR167's X.509 field repair and its test, and moves the netxduo gitlink to 4bf8d7e1, the reviewed fork master that carries the RSA bounds (b96bbb26 + 4bf8d7e1 on top of defce9de). CHANGELOG: both Unreleased entries kept, N-146's and X.509's. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
tinic
added a commit
that referenced
this pull request
Oct 3, 2026
third_party/netxduo stays at the review-only topic pin bb340972, which contains main's pin 4bf8d7e1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bounds RSA initialization to supported keys, checks output capacity against the modulus, accounts for rounded scratch carves, and propagates setup/extraction errors in both vendor and accelerated methods. Pins independently reviewed NetX 4bf8d7e1. Own accelerated capacity stays 4096 bits independently of configurable vendor limits.
Exact combined head: 44e9433. Primary reviewed source and fixture, with independent amended-tip review. Focused combined-head contracts: RSA bounds 30/0; signing regression 24/0; diff check and shell syntax pass. Earlier amended checks include host32 26/26 and m68000/m68020 production compiles. Normal required CI remains the integration gate.
No malformed network reproduction or oversized exponentiation. Extraction-error propagation is source-reviewed; CRT coverage is the existing signing regression. X509 main changes and cleaned changelog retained. Delete the temporary branch after merge; preserve pending work.