Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 2 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 8 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -58,3 +58,11 @@ tls_codec_derive = { path = "./tls_codec/derive" }
x509-tsp = { path = "./x509-tsp" }
x509-cert = { path = "./x509-cert" }
x509-ocsp = { path = "./x509-ocsp" }

[patch.crates-io.elliptic-curve]
git = "https://github.com/RustCrypto/traits.git"
branch = "elliptic-curve/der-error-fixups"

[patch.crates-io.ecdsa]
git = "https://github.com/RustCrypto/signatures.git"
branch = "der-error-fixups"
2 changes: 1 addition & 1 deletion der/src/asn1/any.rs
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ impl<'a> AnyRef<'a> {
T: Choice<'a> + DecodeValue<'a>,
{
if !T::can_decode(self.tag) {
return Err(self.tag.unexpected_error(None).into());
return Err(self.tag.unexpected_error(None).to_error().into());
}

let header = Header {
Expand Down
13 changes: 7 additions & 6 deletions der/src/asn1/bit_string.rs
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ impl<'a> BitStringRef<'a> {
/// from the final octet. This number is 0 if the value is octet-aligned.
pub fn new(unused_bits: u8, bytes: &'a [u8]) -> Result<Self> {
if (unused_bits > Self::MAX_UNUSED_BITS) || (unused_bits != 0 && bytes.is_empty()) {
return Err(Self::TAG.value_error());
return Err(Self::TAG.value_error().into());
}

let inner = BytesRef::new(bytes).map_err(|_| Self::TAG.length_error())?;
Expand Down Expand Up @@ -206,8 +206,9 @@ impl<'a, const N: usize> TryFrom<BitStringRef<'a>> for [u8; N] {

fn try_from(bit_string: BitStringRef<'a>) -> Result<Self> {
let bytes: &[u8] = TryFrom::try_from(bit_string)?;

bytes.try_into().map_err(|_| Tag::BitString.length_error())
bytes
.try_into()
.map_err(|_| Tag::BitString.length_error().into())
}
}

Expand All @@ -217,7 +218,7 @@ impl<'a> TryFrom<BitStringRef<'a>> for &'a [u8] {
fn try_from(bit_string: BitStringRef<'a>) -> Result<&'a [u8]> {
bit_string
.as_bytes()
.ok_or_else(|| Tag::BitString.value_error())
.ok_or_else(|| Tag::BitString.value_error().into())
}
}

Expand Down Expand Up @@ -400,7 +401,7 @@ mod allocating {
bit_string
.as_bytes()
.map(|bytes| bytes.to_vec())
.ok_or_else(|| Tag::BitString.value_error())
.ok_or_else(|| Tag::BitString.value_error().into())
}
}

Expand Down Expand Up @@ -620,7 +621,7 @@ mod tests {
fn reject_unused_bits_in_empty_string() {
assert_eq!(
parse_bitstring(&[0x03]).err().unwrap().kind(),
Tag::BitString.value_error().kind()
Tag::BitString.value_error()
)
}

Expand Down
4 changes: 2 additions & 2 deletions der/src/asn1/bmp_string.rs
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ impl BmpString {
let bytes = bytes.into();

if bytes.len() % 2 != 0 {
return Err(Tag::BmpString.length_error());
return Err(Tag::BmpString.length_error().into());
}

let ret = Self {
Expand All @@ -34,7 +34,7 @@ impl BmpString {
// Character is in the Basic Multilingual Plane
Ok(c) if (c as u64) < u64::from(u16::MAX) => (),
// Characters outside Basic Multilingual Plane or unpaired surrogates
_ => return Err(Tag::BmpString.value_error()),
_ => return Err(Tag::BmpString.value_error().into()),
}
}

Expand Down
2 changes: 1 addition & 1 deletion der/src/asn1/boolean.rs
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ impl<'a> DecodeValue<'a> for bool {
match reader.read_byte()? {
FALSE_OCTET => Ok(false),
TRUE_OCTET => Ok(true),
_ => Err(Self::TAG.non_canonical_error()),
_ => Err(reader.error(Self::TAG.non_canonical_error())),
}
}
}
Expand Down
10 changes: 5 additions & 5 deletions der/src/asn1/generalized_time.rs
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ impl GeneralizedTime {
pub fn from_unix_duration(unix_duration: Duration) -> Result<Self> {
DateTime::from_unix_duration(unix_duration)
.map(Into::into)
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}

/// Get the duration of this timestamp since `UNIX_EPOCH`.
Expand All @@ -62,7 +62,7 @@ impl GeneralizedTime {
pub fn from_system_time(time: SystemTime) -> Result<Self> {
DateTime::try_from(time)
.map(Into::into)
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}

/// Convert to [`SystemTime`].
Expand All @@ -79,7 +79,7 @@ impl<'a> DecodeValue<'a> for GeneralizedTime {

fn decode_value<R: Reader<'a>>(reader: &mut R, header: Header) -> Result<Self> {
if Self::LENGTH != usize::try_from(header.length)? {
return Err(Self::TAG.value_error());
return Err(reader.error(Self::TAG.value_error()));
}

let mut bytes = [0u8; Self::LENGTH];
Expand Down Expand Up @@ -117,10 +117,10 @@ impl<'a> DecodeValue<'a> for GeneralizedTime {
let second = datetime::decode_decimal(Self::TAG, sec1, sec2)?;

DateTime::new(year, month, day, hour, minute, second)
.map_err(|_| Self::TAG.value_error())
.map_err(|_| reader.error(Self::TAG.value_error()))
.and_then(|dt| Self::from_unix_duration(dt.unix_duration()))
}
_ => Err(Self::TAG.value_error()),
_ => Err(reader.error(Self::TAG.value_error())),
}
}
}
Expand Down
8 changes: 4 additions & 4 deletions der/src/asn1/ia5_string.rs
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,12 @@ impl<'a> Ia5StringRef<'a> {

// Validate all characters are within IA5String's allowed set
if input.iter().any(|&c| c > 0x7F) {
return Err(Self::TAG.value_error());
return Err(Self::TAG.value_error().into());
}

StrRef::from_bytes(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}

Expand Down Expand Up @@ -122,7 +122,7 @@ mod allocation {

StrOwned::from_bytes(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}

Expand Down Expand Up @@ -181,7 +181,7 @@ mod allocation {

StrOwned::new(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}
}
Expand Down
18 changes: 10 additions & 8 deletions der/src/asn1/integer/int.rs
Original file line number Diff line number Diff line change
Expand Up @@ -21,11 +21,11 @@ macro_rules! impl_encoding_traits {
let max_length = u32::from(header.length) as usize;

if max_length == 0 {
return Err(Tag::Integer.length_error());
return Err(reader.error(Tag::Integer.length_error()));
}

if max_length > buf.len() {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

let bytes = reader.read_into(&mut buf[..max_length])?;
Expand All @@ -40,7 +40,7 @@ macro_rules! impl_encoding_traits {

// Ensure we compute the same encoded length as the original any value
if header.length != result.value_len()? {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -144,7 +144,7 @@ impl<'a> DecodeValue<'a> for IntRef<'a> {

// Ensure we compute the same encoded length as the original any value.
if result.value_len()? != header.length {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -238,7 +238,7 @@ mod allocating {

// Ensure we compute the same encoded length as the original any value.
if result.value_len()? != header.length {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -375,13 +375,15 @@ mod allocating {

/// Ensure `INTEGER` is canonically encoded.
fn validate_canonical(bytes: &[u8]) -> Result<()> {
let non_canonical_error = Tag::Integer.non_canonical_error().into();

// The `INTEGER` type always encodes a signed value and we're decoding
// as signed here, so we allow a zero extension or sign extension byte,
// but only as permitted under DER canonicalization.
match bytes {
[] => Err(Tag::Integer.non_canonical_error()),
[0x00, byte, ..] if *byte < 0x80 => Err(Tag::Integer.non_canonical_error()),
[0xFF, byte, ..] if *byte >= 0x80 => Err(Tag::Integer.non_canonical_error()),
[] => Err(non_canonical_error),
[0x00, byte, ..] if *byte < 0x80 => Err(non_canonical_error),
[0xFF, byte, ..] if *byte >= 0x80 => Err(non_canonical_error),
_ => Ok(()),
}
}
Expand Down
16 changes: 8 additions & 8 deletions der/src/asn1/integer/uint.rs
Original file line number Diff line number Diff line change
Expand Up @@ -25,19 +25,19 @@ macro_rules! impl_encoding_traits {
let max_length = u32::from(header.length) as usize;

if max_length == 0 {
return Err(Tag::Integer.length_error());
return Err(reader.error(Tag::Integer.length_error()));
}

if max_length > buf.len() {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

let bytes = reader.read_into(&mut buf[..max_length])?;
let result = Self::from_be_bytes(decode_to_array(bytes)?);

// Ensure we compute the same encoded length as the original any value
if header.length != result.value_len()? {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -127,7 +127,7 @@ impl<'a> DecodeValue<'a> for UintRef<'a> {

// Ensure we compute the same encoded length as the original any value.
if result.value_len()? != header.length {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -221,7 +221,7 @@ mod allocating {

// Ensure we compute the same encoded length as the original any value.
if result.value_len()? != header.length {
return Err(Self::TAG.non_canonical_error());
return Err(reader.error(Self::TAG.non_canonical_error()));
}

Ok(result)
Expand Down Expand Up @@ -328,11 +328,11 @@ pub(crate) fn decode_to_slice(bytes: &[u8]) -> Result<&[u8]> {
// integer (since we're decoding an unsigned integer).
// We expect all such cases to have a leading `0x00` byte.
match bytes {
[] => Err(Tag::Integer.non_canonical_error()),
[] => Err(Tag::Integer.non_canonical_error().into()),
[0] => Ok(bytes),
[0, byte, ..] if *byte < 0x80 => Err(Tag::Integer.non_canonical_error()),
[0, byte, ..] if *byte < 0x80 => Err(Tag::Integer.non_canonical_error().into()),
[0, rest @ ..] => Ok(rest),
[byte, ..] if *byte >= 0x80 => Err(Tag::Integer.value_error()),
[byte, ..] if *byte >= 0x80 => Err(Tag::Integer.value_error().into()),
_ => Ok(bytes),
}
}
Expand Down
8 changes: 4 additions & 4 deletions der/src/asn1/internal_macros.rs
Original file line number Diff line number Diff line change
Expand Up @@ -148,7 +148,7 @@ macro_rules! impl_custom_class {

// the encoding shall be constructed if the base encoding is constructed
if header.tag.is_constructed() != T::CONSTRUCTED {
return Err(header.tag.non_canonical_error().into());
return Err(reader.error(header.tag.non_canonical_error()).into());
}

// read_nested checks if header matches decoded length
Expand Down Expand Up @@ -186,7 +186,7 @@ macro_rules! impl_custom_class {

// encoding shall be constructed
if !header.tag.is_constructed() {
return Err(header.tag.non_canonical_error().into());
return Err(reader.error(header.tag.non_canonical_error()).into());
}
match header.tag {
Tag::$class_enum_name { number, .. } => Ok(Self {
Expand All @@ -197,7 +197,7 @@ macro_rules! impl_custom_class {
T::decode(reader)
})?,
}),
tag => Err(tag.unexpected_error(None).into()),
tag => Err(reader.error(tag.unexpected_error(None)).into())
}
}
}
Expand Down Expand Up @@ -264,7 +264,7 @@ macro_rules! impl_custom_class {
tag_mode: TagMode::default(),
value: T::from_der(any.value())?,
}),
tag => Err(tag.unexpected_error(None).into()),
tag => Err(tag.unexpected_error(None).to_error().into()),
}
}
}
Expand Down
4 changes: 2 additions & 2 deletions der/src/asn1/octet_string.rs
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ impl<'a, const N: usize> TryFrom<OctetStringRef<'a>> for [u8; N] {
octet_string
.as_bytes()
.try_into()
.map_err(|_| Tag::OctetString.length_error())
.map_err(|_| Tag::OctetString.length_error().into())
}
}

Expand All @@ -140,7 +140,7 @@ impl<'a, const N: usize> TryFrom<OctetStringRef<'a>> for heapless::Vec<u8, N> {
octet_string
.as_bytes()
.try_into()
.map_err(|_| Tag::OctetString.length_error())
.map_err(|_| Tag::OctetString.length_error().into())
}
}

Expand Down
8 changes: 4 additions & 4 deletions der/src/asn1/printable_string.rs
Original file line number Diff line number Diff line change
Expand Up @@ -83,13 +83,13 @@ impl<'a> PrintableStringRef<'a> {
| b':'
| b'='
| b'?' => (),
_ => return Err(Self::TAG.value_error()),
_ => return Err(Self::TAG.value_error().into()),
}
}

StrRef::from_bytes(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}

Expand Down Expand Up @@ -173,7 +173,7 @@ mod allocation {

StrOwned::from_bytes(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}

Expand Down Expand Up @@ -236,7 +236,7 @@ mod allocation {

StrOwned::new(input)
.map(|inner| Self { inner })
.map_err(|_| Self::TAG.value_error())
.map_err(|_| Self::TAG.value_error().into())
}
}
}
Expand Down
Loading