pkcs1: decode RsaPssParamsRef/RsaOaepParamsRef from non-'static input - #2453
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
… input Since RustCrypto#2411 the params impls require `AlgorithmIdentifier<Params>: From<AlgorithmIdentifierRef<'static>>`. With `Params = AnyRef<'a>` that only holds for `'a = 'static`, so `RsaPssParamsRef::from_der(&buf)` and `RsaOaepParamsRef::from_der(&buf)` (and encoding any `*Ref` params that borrow non-`'static` data) failed to compile unless `buf` was `'static`. The existing tests only decode `const` byte strings, so this went unnoticed. Decoding now requires `From<AlgorithmIdentifierRef<'a>>` (the input lifetime), and encoding compares the MGF against MGF1-SHA1 through `AsAlgorithmIdentifierRef`, so it no longer needs the `From` bound or `Params: PartialEq`. All bounds are relaxed; none is added.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Since #2411 (unreleased;
pkcs1v0.8.0-rc.4 is fine) theRsaPssParams/RsaOaepParamsimpls requireAlgorithmIdentifier<Params>: From<AlgorithmIdentifierRef<'static>>. WithParams = AnyRef<'a>that only holds for'a = 'static. So on master this does not compile:The same applies to
RsaOaepParamsRef, and to encoding any*Refparams that borrow non-'staticdata (e.g. an OAEP label from a buffer). The existing tests only decodeconstbyte strings, so they still passed.Changes:
DecodeValue/TryFrom<&'a [u8]>requireFrom<AlgorithmIdentifierRef<'a>>, i.e. the input lifetime.EncodeValuechecks for the default MGF (MGF1 with SHA-1) throughAsAlgorithmIdentifierRefinstead of constructing a default and comparing with==. It no longer needs theFrombound orParams: PartialEq.Every bound is relaxed and none is added, so nothing that compiles today stops compiling. The new
ref_params_non_static_inputtest decodes and re-encodes both types from a stack buffer; on master it fails to compile with the error above.This PR was produced by AI agents (Claude) and reviewed by me before submission.