Skip to content

Fix RSA modulus, output and scratch bounds (N-146) - #168

Merged
tinic merged 3 commits into
mainfrom
fix/n146-rsa-bounds
Oct 3, 2026
Merged

tinic merged 3 commits into
mainfrom
fix/n146-rsa-bounds

Conversation

@tinic

@tinic tinic commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Bounds RSA initialization to supported keys, checks output capacity against the modulus, accounts for rounded scratch carves, and propagates setup/extraction errors in both vendor and accelerated methods. Pins independently reviewed NetX 4bf8d7e1. Own accelerated capacity stays 4096 bits independently of configurable vendor limits.

Exact combined head: 44e9433. Primary reviewed source and fixture, with independent amended-tip review. Focused combined-head contracts: RSA bounds 30/0; signing regression 24/0; diff check and shell syntax pass. Earlier amended checks include host32 26/26 and m68000/m68020 production compiles. Normal required CI remains the integration gate.

No malformed network reproduction or oversized exponentiation. Extraction-error propagation is source-reviewed; CRT coverage is the existing signing regression. X509 main changes and cleaned changelog retained. Delete the temporary branch after merge; preserve pending work.

tinic and others added 3 commits October 3, 2026 00:38
…-146)

ami_crypto_method_rsa (src/tls/ami_tls_crypto.c) had the vendored method's
shape: the output compared with the exponent's length, the scratch length
never given to ami_rsa_exponentiate(), the setup and extract statuses
dropped.  It now checks the output against the modulus, passes and checks
the scratch in the vendored operation's units and formula, and returns
those statuses.  The modulus ceiling comes with the vendored init it
delegates to.

tests/fuzz/tls_rsa_bounds (32-bit, beside tls_rsa_key_regression) runs the
same contracts on crypto_method_rsa and ours: a 4096-bit modulus accepted
and a 4104-bit or zero one refused with the context untouched; a real
2048-bit signature verified into an output exactly the modulus long; one
byte short refused with nothing written at or past it (a canary inside the
test's own array); an overlong exponent an error; and the vendored
operation's scratch one USHORT short refused, exactly enough used.  Benign
only: no oversized exponentiation is run.

Pairs with tinic/netxduo b96bbb26 (local, not pushed), off fork master
defce9de; the gitlink is NOT moved.  Unfixed (defce9de + main's
ami_tls_crypto.c): 13 of 22 checks fail.  Fixed: 22/22.  HOST32 25 -> 26.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ntrols (N-146 amendment)

ami_crypto_method_rsa_init() now refuses 0, non-byte and over
AMI_TLS_RSA_MAX_MODULUS_BITS (4096) itself, before the vendored init: that
ceiling, NX_CRYPTO_MAX_RSA_MODULUS_SIZE, may be raised by a build, but
AMI_TLS_POWM_SCRATCH_LIMBS is fixed, and a _Static_assert now ties the two
(C68K_POWM_SCRATCH_LIMBS(128, 1) = 2704).  ami_rsa_exponentiate() counts the
scratch in limb-rounded lengths, as the vendored operation now does.

tls_rsa_bounds adds: a 2047-bit (non-byte) modulus refused by both methods;
a valid public exponent zero-padded past the modulus length still verifying
(the reason there is no explicit exponent <= modulus check); and the
vendored operation with a 257-byte modulus refusing 913 USHORTs and
accepting 914 (7 * 260 + 8 bytes).  Coverage limits: the CRT path is
exercised by tls_rsa_key_regression's signing only, not by this test; the
extract-status propagation is source-only.

Pairs with tinic/netxduo 4bf8d7e1.  Unfixed: 18 of 30 checks fail; fixed
30/30; host32 26/26.  CHANGELOG: the N-146 entry from 636e213 covers this.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…146)

Brings in PR167's X.509 field repair and its test, and moves the netxduo
gitlink to 4bf8d7e1, the reviewed fork master that carries the RSA bounds
(b96bbb26 + 4bf8d7e1 on top of defce9de).  CHANGELOG: both Unreleased
entries kept, N-146's and X.509's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@tinic
tinic merged commit 9f08a3e into main Oct 3, 2026
42 of 43 checks passed
@tinic
tinic deleted the fix/n146-rsa-bounds branch October 3, 2026 01:54
tinic added a commit that referenced this pull request Oct 3, 2026
third_party/netxduo stays at the review-only topic pin bb340972, which
contains main's pin 4bf8d7e1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant