Conversation
Prevent SIGABRT from libsodium sodium_misuse when digest_size is 0 by validating in _checkparams and generichash_blake2b_final.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
generichash_blake2b_final()aborts the interpreter withSIGABRTwhen called on aBlake2Statewhosedigest_sizeis0. The same invalid size also causes a poor failure mode throughgenerichash_blake2b_init()/generichash_blake2b_salt_personal()(RuntimeErroror abort) because_checkparams()only enforced an upper bound.libsodium's
blake2b_final()callssodium_misuse()whenoutlenis 0 (!outlen || outlen > BLAKE2B_OUTBYTES). This is the zero-length counterpart of #964 (oversized digest); #965 covers the upper bound.Fixes #967.
Fix
digest_size < 1in_checkparams()so init/one-shot paths raiseValueError.state.digest_size < 1ingenerichash_blake2b_final()so a directly constructedBlake2State(0)raisesValueErrorinstead of aborting.Sizes
1..BYTES_MAX(including values belowBYTES_MIN) remain accepted, matching current libsodium C behavior.Testing
tests/test_generichash.py:test_generichash_blake2b_final_rejects_zero_directly_constructed_statetest_generichash_blake2b_init_rejects_zero_digest_sizetest_generichash_blake2b_salt_personal_rejects_zero_digest_sizegenerichash_blake2b_final(Blake2State(0))exits with SIGABRT; with this change it raisesValueError: Digest_size less than 1.PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 pytest tests/test_generichash.py::test_generichash_blake2b_final_rejects_zero_directly_constructed_state tests/test_generichash.py::test_generichash_blake2b_init_rejects_zero_digest_size tests/test_generichash.py::test_generichash_blake2b_salt_personal_rejects_zero_digest_size→ passed.