Sitelet https://github.com/RustCrypto/formats/pull/2453
Skip to content

pkcs1: decode RsaPssParamsRef/RsaOaepParamsRef from non-'static input - #2453

Open
yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/pkcs1-params-non-static
Open

yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/pkcs1-params-non-static

Conversation

@yuxi-liu-wired

Copy link
Copy Markdown
Contributor

Since #2411 (unreleased; pkcs1 v0.8.0-rc.4 is fine) the RsaPssParams/RsaOaepParams impls require AlgorithmIdentifier<Params>: From<AlgorithmIdentifierRef<'static>>. With Params = AnyRef<'a> that only holds for 'a = 'static. So on master this does not compile:

fn salt_len(der: &[u8]) -> u8 {
    RsaPssParamsRef::from_der(der).unwrap().salt_len
    // error[E0521]: borrowed data escapes outside of function
    //   argument requires that `'1` must outlive `'static`
}

The same applies to RsaOaepParamsRef, and to encoding any *Ref params that borrow non-'static data (e.g. an OAEP label from a buffer). The existing tests only decode const byte strings, so they still passed.

Changes:

  • DecodeValue/TryFrom<&'a [u8]> require From<AlgorithmIdentifierRef<'a>>, i.e. the input lifetime.
  • EncodeValue checks for the default MGF (MGF1 with SHA-1) through AsAlgorithmIdentifierRef instead of constructing a default and comparing with ==. It no longer needs the From bound or Params: PartialEq.

Every bound is relaxed and none is added, so nothing that compiles today stops compiling. The new ref_params_non_static_input test decodes and re-encodes both types from a stack buffer; on master it fails to compile with the error above.

This PR was produced by AI agents (Claude) and reviewed by me before submission.

… input

Since RustCrypto#2411 the params impls require
`AlgorithmIdentifier<Params>: From<AlgorithmIdentifierRef<'static>>`. With
`Params = AnyRef<'a>` that only holds for `'a = 'static`, so
`RsaPssParamsRef::from_der(&buf)` and `RsaOaepParamsRef::from_der(&buf)`
(and encoding any `*Ref` params that borrow non-`'static` data) failed to
compile unless `buf` was `'static`. The existing tests only decode
`const` byte strings, so this went unnoticed.

Decoding now requires `From<AlgorithmIdentifierRef<'a>>` (the input
lifetime), and encoding compares the MGF against MGF1-SHA1 through
`AsAlgorithmIdentifierRef`, so it no longer needs the `From` bound or
`Params: PartialEq`. All bounds are relaxed; none is added.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant