Repository navigation
Validate HKDF-Extract buffers before mutating state (N-160) - #171
Merged
Merged
Conversation
netxduo 12d4f5f2 -> 9663fe4b: NX_CRYPTO_HKDF_EXTRACT returns NX_CRYPTO_POINTER_ERROR for a NULL output, or a NULL input with a length, before it stores anything in its context. A NULL empty IKM, the salt test, the size check and in-place derivation are unchanged. tests/x509/test_hkdf_extract_ptr runs the TLS wrapper's sequence through the vendor HKDF, HMAC and SHA-256: RFC 5869 A.1 and A.3, an empty IKM as NULL and as a pointer (against an independently computed PRK), output aliasing the salt, the unchanged salt and size refusals, and both new refusals with the context compared byte for byte. 12d4f5f2 passes the 16 valid checks; the refusals are not run against it. Host census 549 -> 550. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Narrow defensive pointer-contract repair: reject null output and null nonempty input in HKDF-Extract before mutating metadata. Preserve valid empty IKM (NULL+0), current salt behavior, length errors and output/salt aliasing. Pins reviewed NetX master 9663fe4bd0baeae72183c0968efe927f5bdaa647. Maintained benign fixture includes valid RFC 5869 A.1/A.3, independent empty-message HMAC PRK controls and metadata/output canaries. Old source executes only valid controls, never invalid pointer calls. Primary full source/fixture review and independent exact-tip review found no blocker. Inspected owner results: strict 32-bit and LP64 ASan/UBSan 21 checks/0 failures; old valid controls 16/0; focused registered CMake test 21/0, census 550; changed-file m68k Werror compile passes. These are inspected owner executions, not a primary rerun or replacement for required CI. Current shipping callers supply valid buffers, so this is latent misuse/error-path hardening, not a reproduced beta7 traffic defect. All normal required checks remain required; cleanup follows actual merge.