1 /*
2  * Copyright 2014 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #include <keymaster/serializable.h>
18 
19 #include <assert.h>
20 
21 #include <keymaster/android_keymaster_utils.h>
22 
23 namespace keymaster {
24 
25 namespace {
26 
27 /* Performs an overflow-checked bounds check */
buffer_bound_check(const uint8_t * buf,const uint8_t * end,size_t len)28 bool buffer_bound_check(const uint8_t* buf, const uint8_t* end, size_t len) {
29     uintptr_t buf_next;
30     bool overflow_occurred = __builtin_add_overflow(__pval(buf), len, &buf_next);
31     return (!overflow_occurred) && (buf_next <= __pval(end));
32 }
33 
34 }  // namespace
35 
append_to_buf(uint8_t * buf,const uint8_t * end,const void * data,size_t data_len)36 uint8_t* append_to_buf(uint8_t* buf, const uint8_t* end, const void* data, size_t data_len) {
37     if (buffer_bound_check(buf, end, data_len)) {
38         memcpy(buf, data, data_len);
39         return buf + data_len;
40     } else {
41         return buf;
42     }
43 }
44 
copy_from_buf(const uint8_t ** buf_ptr,const uint8_t * end,void * dest,size_t size)45 bool copy_from_buf(const uint8_t** buf_ptr, const uint8_t* end, void* dest, size_t size) {
46     if (buffer_bound_check(*buf_ptr, end, size)) {
47         memcpy(dest, *buf_ptr, size);
48         *buf_ptr += size;
49         return true;
50     } else {
51         return false;
52     }
53 }
54 
copy_size_and_data_from_buf(const uint8_t ** buf_ptr,const uint8_t * end,size_t * size,UniquePtr<uint8_t[]> * dest)55 bool copy_size_and_data_from_buf(const uint8_t** buf_ptr, const uint8_t* end, size_t* size,
56                                  UniquePtr<uint8_t[]>* dest) {
57     if (!copy_uint32_from_buf(buf_ptr, end, size)) return false;
58 
59     if (*size == 0) {
60         dest->reset();
61         return true;
62     }
63 
64     if (buffer_bound_check(*buf_ptr, end, *size)) {
65         dest->reset(new (std::nothrow) uint8_t[*size]);
66         if (!dest->get()) {
67             return false;
68         }
69         return copy_from_buf(buf_ptr, end, dest->get(), *size);
70     } else {
71         return false;
72     }
73 }
74 
reserve(size_t size)75 bool Buffer::reserve(size_t size) {
76     if (available_write() < size) {
77         if (!valid_buffer_state()) {
78             return false;
79         }
80 
81         size_t new_size = buffer_size_ + size - available_write();
82         uint8_t* new_buffer = new (std::nothrow) uint8_t[new_size];
83         if (!new_buffer) return false;
84         memcpy(new_buffer, buffer_.get() + read_position_, available_read());
85         memset_s(buffer_.get(), 0, buffer_size_);
86         buffer_.reset(new_buffer);
87         buffer_size_ = new_size;
88         write_position_ -= read_position_;
89         read_position_ = 0;
90     }
91     return true;
92 }
93 
Reinitialize(size_t size)94 bool Buffer::Reinitialize(size_t size) {
95     Clear();
96     buffer_.reset(new (std::nothrow) uint8_t[size]);
97     if (!buffer_.get()) return false;
98     buffer_size_ = size;
99     read_position_ = 0;
100     write_position_ = 0;
101     return true;
102 }
103 
Reinitialize(const void * data,size_t data_len)104 bool Buffer::Reinitialize(const void* data, size_t data_len) {
105     Clear();
106     if (__pval(data) + data_len < __pval(data))  // Pointer wrap check
107         return false;
108     buffer_.reset(new (std::nothrow) uint8_t[data_len]);
109     if (!buffer_.get()) return false;
110     buffer_size_ = data_len;
111     memcpy(buffer_.get(), data, data_len);
112     read_position_ = 0;
113     write_position_ = buffer_size_;
114     return true;
115 }
116 
available_write() const117 size_t Buffer::available_write() const {
118     assert(buffer_size_ >= write_position_);
119     return buffer_size_ - write_position_;
120 }
121 
available_read() const122 size_t Buffer::available_read() const {
123     assert(buffer_size_ >= write_position_);
124     assert(write_position_ >= read_position_);
125     return write_position_ - read_position_;
126 }
127 
valid_buffer_state() const128 bool Buffer::valid_buffer_state() const {
129     return (buffer_size_ >= write_position_) && (write_position_ >= read_position_);
130 }
131 
write(const uint8_t * src,size_t write_length)132 bool Buffer::write(const uint8_t* src, size_t write_length) {
133     if (available_write() < write_length) return false;
134     memcpy(buffer_.get() + write_position_, src, write_length);
135     write_position_ += write_length;
136     return true;
137 }
138 
read(uint8_t * dest,size_t read_length)139 bool Buffer::read(uint8_t* dest, size_t read_length) {
140     if (available_read() < read_length) return false;
141     memcpy(dest, buffer_.get() + read_position_, read_length);
142     read_position_ += read_length;
143     return true;
144 }
145 
advance_write(int distance)146 bool Buffer::advance_write(int distance) {
147     if (distance < 0) {
148         return false;
149     }
150 
151     const size_t validated_distance = static_cast<size_t>(distance);
152     const size_t new_write_position = write_position_ + validated_distance;
153 
154     if (new_write_position <= buffer_size_ && new_write_position >= write_position_) {
155         write_position_ = new_write_position;
156         return true;
157     }
158     return false;
159 }
160 
SerializedSize() const161 size_t Buffer::SerializedSize() const {
162     return sizeof(uint32_t) + available_read();
163 }
164 
Serialize(uint8_t * buf,const uint8_t * end) const165 uint8_t* Buffer::Serialize(uint8_t* buf, const uint8_t* end) const {
166     return append_size_and_data_to_buf(buf, end, peek_read(), available_read());
167 }
168 
Deserialize(const uint8_t ** buf_ptr,const uint8_t * end)169 bool Buffer::Deserialize(const uint8_t** buf_ptr, const uint8_t* end) {
170     Clear();
171     if (!copy_size_and_data_from_buf(buf_ptr, end, &buffer_size_, &buffer_)) {
172         buffer_.reset();
173         buffer_size_ = 0;
174         return false;
175     }
176     write_position_ = buffer_size_;
177     return true;
178 }
179 
Clear()180 void Buffer::Clear() {
181     memset_s(buffer_.get(), 0, buffer_size_);
182     buffer_.reset();
183     read_position_ = 0;
184     write_position_ = 0;
185     buffer_size_ = 0;
186 }
187 
188 }  // namespace keymaster
189