Add b64decode len.

Signed-off-by: Pol Henarejos <pol.henarejos@cttc.es>
This commit is contained in:
Pol Henarejos
2026-05-04 21:10:18 +02:00
parent f8db7613b6
commit e0a8380dcd
3 changed files with 21 additions and 14 deletions

View File

@@ -27,16 +27,6 @@
#include "otp.h" #include "otp.h"
#include "random.h" #include "random.h"
int ct_memcmp(const void *a, const void *b, size_t n) {
const volatile uint8_t *x = (const volatile uint8_t *)a;
const volatile uint8_t *y = (const volatile uint8_t *)b;
uint8_t r = 0;
for (size_t i = 0; i < n; ++i) {
r |= x[i] ^ y[i];
}
return r;
}
static const mbedtls_md_info_t *SHA256(void) { static const mbedtls_md_info_t *SHA256(void) {
return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256); return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
} }
@@ -333,7 +323,9 @@ int base64url_encode(unsigned char *dst, size_t dlen, size_t *olen, const unsign
int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen) { int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen) {
// First convert from base64url to standard base64 // First convert from base64url to standard base64
unsigned char *b64_src = (unsigned char *)malloc(slen + 2); // +2 for padding if needed if ((slen % 4) == 1) return MBEDTLS_ERR_BASE64_INVALID_CHARACTER;
size_t padding = (4 - (slen % 4)) % 4;
unsigned char *b64_src = malloc(slen + padding);
if (b64_src == NULL) { if (b64_src == NULL) {
return PICOKEYS_ERR_MEMORY_FATAL; return PICOKEYS_ERR_MEMORY_FATAL;
} }
@@ -348,7 +340,6 @@ int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsign
b64_src[i] = src[i]; b64_src[i] = src[i];
} }
} }
size_t padding = (4 - (slen % 4)) % 4;
for (size_t i = 0; i < padding; i++) { for (size_t i = 0; i < padding; i++) {
b64_src[slen + i] = '='; b64_src[slen + i] = '=';
} }
@@ -358,3 +349,18 @@ int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsign
free(b64_src); free(b64_src);
return rc; return rc;
} }
int b64url_decoded_len(size_t n, size_t *out_len) {
if (out_len == NULL) return -1;
if ((n % 4) == 1) return -2; // longitud base64url invàlida
size_t pad = (4 - (n % 4)) % 4; // 0,1,2
size_t total = n + pad;
size_t out = (total / 4) * 3;
if (pad == 1) out -= 1;
else if (pad == 2) out -= 2;
*out_len = out;
return 0;
}

View File

@@ -46,7 +46,6 @@ typedef enum {
#define PIN_KDF_DEFAULT_VERSION PIN_KDF_V2 #define PIN_KDF_DEFAULT_VERSION PIN_KDF_V2
extern int ct_memcmp(const void *a, const void *b, size_t n);
// Newer and safe functions // Newer and safe functions
extern void derive_kbase(uint8_t kbase[32]); extern void derive_kbase(uint8_t kbase[32]);
extern void derive_kver(const uint8_t *pin, size_t pin_len, uint8_t kver[32]); extern void derive_kver(const uint8_t *pin, size_t pin_len, uint8_t kver[32]);
@@ -68,6 +67,7 @@ extern mbedtls_ecp_group_id ec_get_curve_from_prime(const uint8_t *prime, size_t
extern uint32_t crc32c(const uint8_t *buf, size_t len); extern uint32_t crc32c(const uint8_t *buf, size_t len);
extern int base64url_encode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen); extern int base64url_encode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen);
extern int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen); extern int base64url_decode(unsigned char *dst, size_t dlen, size_t *olen, const unsigned char *src, size_t slen);
extern int b64url_decoded_len(size_t n, size_t *out_len);
#define PIN_KDF_SIZE(x) (12 + (x) + 16) #define PIN_KDF_SIZE(x) (12 + (x) + 16)

View File

@@ -21,6 +21,7 @@
#include "usb.h" #include "usb.h"
#include "pico_time.h" #include "pico_time.h"
#include "serial.h" #include "serial.h"
#include "mbedtls/constant_time.h"
#include <ctype.h> #include <ctype.h>
#ifdef _WIN32 #ifdef _WIN32
@@ -718,7 +719,7 @@ static int rest_verify_request_signature(const rest_request_t *request, const re
return PICOKEYS_EXEC_ERROR; return PICOKEYS_EXEC_ERROR;
} }
mbedtls_md_free(&ctx); mbedtls_md_free(&ctx);
if (ct_memcmp(hmac, hmac_x, sizeof(hmac)) != 0) { if (mbedtls_ct_memcmp(hmac, hmac_x, sizeof(hmac)) != 0) {
return PICOKEYS_EXEC_ERROR; return PICOKEYS_EXEC_ERROR;
} }
return PICOKEYS_OK; return PICOKEYS_OK;