mirror of
https://code.briarproject.org/briar/briar.git
synced 2026-02-11 18:29:05 +01:00
Check the return value from Signature.verify(). *cough*
This commit is contained in:
@@ -1,8 +1,7 @@
|
||||
package net.sf.briar.api.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.SignatureException;
|
||||
import java.security.GeneralSecurityException;
|
||||
|
||||
public interface BatchBuilder {
|
||||
|
||||
@@ -13,5 +12,5 @@ public interface BatchBuilder {
|
||||
void setSignature(byte[] sig);
|
||||
|
||||
/** Builds and returns the batch. */
|
||||
Batch build() throws IOException, SignatureException, InvalidKeyException;
|
||||
Batch build() throws IOException, GeneralSecurityException;
|
||||
}
|
||||
|
||||
@@ -1,8 +1,7 @@
|
||||
package net.sf.briar.api.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.SignatureException;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.util.Map;
|
||||
|
||||
public interface HeaderBuilder {
|
||||
@@ -20,5 +19,5 @@ public interface HeaderBuilder {
|
||||
void setSignature(byte[] sig);
|
||||
|
||||
/** Builds and returns the header. */
|
||||
Header build() throws IOException, SignatureException, InvalidKeyException;
|
||||
Header build() throws IOException, GeneralSecurityException;
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package net.sf.briar.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.security.KeyPair;
|
||||
import java.security.MessageDigest;
|
||||
import java.security.Signature;
|
||||
@@ -24,13 +24,12 @@ public class IncomingBatchBuilder extends BatchBuilderImpl {
|
||||
this.sig = sig;
|
||||
}
|
||||
|
||||
public Batch build() throws IOException, SignatureException,
|
||||
InvalidKeyException {
|
||||
public Batch build() throws IOException, GeneralSecurityException {
|
||||
if(sig == null) throw new IllegalStateException();
|
||||
byte[] raw = getSignableRepresentation();
|
||||
signature.initVerify(keyPair.getPublic());
|
||||
signature.update(raw);
|
||||
signature.verify(sig);
|
||||
if(!signature.verify(sig)) throw new SignatureException();
|
||||
messageDigest.reset();
|
||||
messageDigest.update(raw);
|
||||
messageDigest.update(sig);
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package net.sf.briar.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.security.KeyPair;
|
||||
import java.security.MessageDigest;
|
||||
import java.security.Signature;
|
||||
@@ -28,13 +28,12 @@ class IncomingHeaderBuilder extends HeaderBuilderImpl {
|
||||
this.sig = sig;
|
||||
}
|
||||
|
||||
public Header build() throws IOException, SignatureException,
|
||||
InvalidKeyException {
|
||||
public Header build() throws IOException, GeneralSecurityException {
|
||||
if(sig == null) throw new IllegalStateException();
|
||||
byte[] raw = getSignableRepresentation();
|
||||
signature.initVerify(keyPair.getPublic());
|
||||
signature.update(raw);
|
||||
signature.verify(sig);
|
||||
if(!signature.verify(sig)) throw new SignatureException();
|
||||
messageDigest.reset();
|
||||
messageDigest.update(raw);
|
||||
messageDigest.update(sig);
|
||||
|
||||
@@ -1,11 +1,10 @@
|
||||
package net.sf.briar.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.security.KeyPair;
|
||||
import java.security.MessageDigest;
|
||||
import java.security.Signature;
|
||||
import java.security.SignatureException;
|
||||
|
||||
import net.sf.briar.api.protocol.Batch;
|
||||
import net.sf.briar.api.protocol.BatchId;
|
||||
@@ -22,8 +21,7 @@ public class OutgoingBatchBuilder extends BatchBuilderImpl {
|
||||
throw new UnsupportedOperationException();
|
||||
}
|
||||
|
||||
public Batch build() throws IOException, SignatureException,
|
||||
InvalidKeyException {
|
||||
public Batch build() throws IOException, GeneralSecurityException {
|
||||
byte[] raw = getSignableRepresentation();
|
||||
signature.initSign(keyPair.getPrivate());
|
||||
signature.update(raw);
|
||||
|
||||
@@ -1,11 +1,10 @@
|
||||
package net.sf.briar.protocol;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.security.KeyPair;
|
||||
import java.security.MessageDigest;
|
||||
import java.security.Signature;
|
||||
import java.security.SignatureException;
|
||||
import java.util.HashSet;
|
||||
import java.util.Set;
|
||||
|
||||
@@ -26,8 +25,7 @@ public class OutgoingHeaderBuilder extends HeaderBuilderImpl {
|
||||
throw new UnsupportedOperationException();
|
||||
}
|
||||
|
||||
public Header build() throws IOException, SignatureException,
|
||||
InvalidKeyException {
|
||||
public Header build() throws IOException, GeneralSecurityException {
|
||||
byte[] raw = getSignableRepresentation();
|
||||
signature.initSign(keyPair.getPrivate());
|
||||
signature.update(raw);
|
||||
|
||||
@@ -3,6 +3,8 @@ package net.sf.briar.protocol;
|
||||
import java.io.File;
|
||||
import java.io.FileInputStream;
|
||||
import java.io.FileOutputStream;
|
||||
import java.io.RandomAccessFile;
|
||||
import java.security.GeneralSecurityException;
|
||||
import java.security.KeyPair;
|
||||
import java.security.KeyPairGenerator;
|
||||
import java.security.MessageDigest;
|
||||
@@ -149,6 +151,55 @@ public class BundleReadWriteTest extends TestCase {
|
||||
r.close();
|
||||
}
|
||||
|
||||
|
||||
@Test
|
||||
public void testModifyingBundleBreaksSignature() throws Exception {
|
||||
|
||||
testWriteBundle();
|
||||
|
||||
RandomAccessFile f = new RandomAccessFile(bundle, "rw");
|
||||
f.seek(bundle.length() - 50);
|
||||
byte b = f.readByte();
|
||||
f.seek(bundle.length() - 50);
|
||||
f.writeByte(b + 1);
|
||||
f.close();
|
||||
|
||||
MessageParser messageParser = new MessageParser() {
|
||||
public Message parseMessage(byte[] body) throws FormatException,
|
||||
SignatureException {
|
||||
// FIXME: Really parse the message
|
||||
return message;
|
||||
}
|
||||
};
|
||||
Provider<HeaderBuilder> headerBuilderProvider =
|
||||
new Provider<HeaderBuilder>() {
|
||||
public HeaderBuilder get() {
|
||||
return new IncomingHeaderBuilder(keyPair, sig, digest, wf);
|
||||
}
|
||||
};
|
||||
Provider<BatchBuilder> batchBuilderProvider =
|
||||
new Provider<BatchBuilder>() {
|
||||
public BatchBuilder get() {
|
||||
return new IncomingBatchBuilder(keyPair, sig, digest, wf);
|
||||
}
|
||||
};
|
||||
|
||||
FileInputStream in = new FileInputStream(bundle);
|
||||
Reader reader = new ReaderFactoryImpl().createReader(in);
|
||||
BundleReader r = new BundleReaderImpl(reader, bundle.length(),
|
||||
messageParser, headerBuilderProvider, batchBuilderProvider);
|
||||
|
||||
Header h = r.getHeader();
|
||||
assertEquals(acks, h.getAcks());
|
||||
assertEquals(subs, h.getSubscriptions());
|
||||
assertEquals(transports, h.getTransports());
|
||||
try {
|
||||
r.getNextBatch();
|
||||
assertTrue(false);
|
||||
} catch(GeneralSecurityException expected) {}
|
||||
r.close();
|
||||
}
|
||||
|
||||
@After
|
||||
public void tearDown() {
|
||||
TestUtils.deleteTestDirectory(testDir);
|
||||
|
||||
Reference in New Issue
Block a user