base64.c 10 KB


  1. /*
  2. * RFC 1521 base64 encoding/decoding
  3. *
  4. * Copyright The Mbed TLS Contributors
  5. * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  6. *
  7. * This file is provided under the Apache License 2.0, or the
  8. * GNU General Public License v2.0 or later.
  9. *
  10. * **********
  11. * Apache License 2.0:
  12. *
  13. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  14. * not use this file except in compliance with the License.
  15. * You may obtain a copy of the License at
  16. *
  17. * http://www.apache.org/licenses/LICENSE-2.0
  18. *
  19. * Unless required by applicable law or agreed to in writing, software
  20. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  21. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  22. * See the License for the specific language governing permissions and
  23. * limitations under the License.
  24. *
  25. * **********
  26. *
  27. * **********
  28. * GNU General Public License v2.0 or later:
  29. *
  30. * This program is free software; you can redistribute it and/or modify
  31. * it under the terms of the GNU General Public License as published by
  32. * the Free Software Foundation; either version 2 of the License, or
  33. * (at your option) any later version.
  34. *
  35. * This program is distributed in the hope that it will be useful,
  36. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  37. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  38. * GNU General Public License for more details.
  39. *
  40. * You should have received a copy of the GNU General Public License along
  41. * with this program; if not, write to the Free Software Foundation, Inc.,
  42. * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
  43. *
  44. * **********
  45. */
  46. #if !defined(MBEDTLS_CONFIG_FILE)
  47. #include "mbedtls/config.h"
  48. #else
  49. #include MBEDTLS_CONFIG_FILE
  50. #endif
  51. #if defined(MBEDTLS_BASE64_C)
  52. #include "mbedtls/base64.h"
  53. #include <stdint.h>
  54. #if defined(MBEDTLS_SELF_TEST)
  55. #include <string.h>
  56. #if defined(MBEDTLS_PLATFORM_C)
  57. #include "mbedtls/platform.h"
  58. #else
  59. #include <stdio.h>
  60. #define mbedtls_printf printf
  61. #endif /* MBEDTLS_PLATFORM_C */
  62. #endif /* MBEDTLS_SELF_TEST */
  63. #define BASE64_SIZE_T_MAX ( (size_t) -1 ) /* SIZE_T_MAX is not standard */
  64. /* Return 0xff if low <= c <= high, 0 otherwise.
  65. *
  66. * Constant flow with respect to c.
  67. */
  68. static unsigned char mask_of_range( unsigned char low, unsigned char high,
  69. unsigned char c )
  70. {
  71. /* low_mask is: 0 if low <= c, 0x...ff if low > c */
  72. unsigned low_mask = ( (unsigned) c - low ) >> 8;
  73. /* high_mask is: 0 if c <= high, 0x...ff if high > c */
  74. unsigned high_mask = ( (unsigned) high - c ) >> 8;
  75. return( ~( low_mask | high_mask ) & 0xff );
  76. }
  77. /* Given a value in the range 0..63, return the corresponding Base64 digit.
  78. * The implementation assumes that letters are consecutive (e.g. ASCII
  79. * but not EBCDIC).
  80. */
  81. static unsigned char enc_char( unsigned char val )
  82. {
  83. unsigned char digit = 0;
  84. /* For each range of values, if val is in that range, mask digit with
  85. * the corresponding value. Since val can only be in a single range,
  86. * only at most one masking will change digit. */
  87. digit |= mask_of_range( 0, 25, val ) & ( 'A' + val );
  88. digit |= mask_of_range( 26, 51, val ) & ( 'a' + val - 26 );
  89. digit |= mask_of_range( 52, 61, val ) & ( '0' + val - 52 );
  90. digit |= mask_of_range( 62, 62, val ) & '+';
  91. digit |= mask_of_range( 63, 63, val ) & '/';
  92. return( digit );
  93. }
  94. /*
  95. * Encode a buffer into base64 format
  96. */
  97. int mbedtls_base64_encode( unsigned char *dst, size_t dlen, size_t *olen,
  98. const unsigned char *src, size_t slen )
  99. {
  100. size_t i, n;
  101. int C1, C2, C3;
  102. unsigned char *p;
  103. if( slen == 0 )
  104. {
  105. *olen = 0;
  106. return( 0 );
  107. }
  108. n = slen / 3 + ( slen % 3 != 0 );
  109. if( n > ( BASE64_SIZE_T_MAX - 1 ) / 4 )
  110. {
  111. *olen = BASE64_SIZE_T_MAX;
  112. return( MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL );
  113. }
  114. n *= 4;
  115. if( ( dlen < n + 1 ) || ( NULL == dst ) )
  116. {
  117. *olen = n + 1;
  118. return( MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL );
  119. }
  120. n = ( slen / 3 ) * 3;
  121. for( i = 0, p = dst; i < n; i += 3 )
  122. {
  123. C1 = *src++;
  124. C2 = *src++;
  125. C3 = *src++;
  126. *p++ = enc_char( ( C1 >> 2 ) & 0x3F );
  127. *p++ = enc_char( ( ( ( C1 & 3 ) << 4 ) + ( C2 >> 4 ) ) & 0x3F );
  128. *p++ = enc_char( ( ( ( C2 & 15 ) << 2 ) + ( C3 >> 6 ) ) & 0x3F );
  129. *p++ = enc_char( C3 & 0x3F );
  130. }
  131. if( i < slen )
  132. {
  133. C1 = *src++;
  134. C2 = ( ( i + 1 ) < slen ) ? *src++ : 0;
  135. *p++ = enc_char( ( C1 >> 2 ) & 0x3F );
  136. *p++ = enc_char( ( ( ( C1 & 3 ) << 4 ) + ( C2 >> 4 ) ) & 0x3F );
  137. if( ( i + 1 ) < slen )
  138. *p++ = enc_char( ( ( C2 & 15 ) << 2 ) & 0x3F );
  139. else *p++ = '=';
  140. *p++ = '=';
  141. }
  142. *olen = p - dst;
  143. *p = 0;
  144. return( 0 );
  145. }
  146. /* Given a Base64 digit, return its value.
  147. * If c is not a Base64 digit ('A'..'Z', 'a'..'z', '0'..'9', '+' or '/'),
  148. * return -1.
  149. *
  150. * The implementation assumes that letters are consecutive (e.g. ASCII
  151. * but not EBCDIC).
  152. *
  153. * The implementation is constant-flow (no branch or memory access depending
  154. * on the value of c) unless the compiler inlines and optimizes a specific
  155. * access.
  156. */
  157. static signed char dec_value( unsigned char c )
  158. {
  159. unsigned char val = 0;
  160. /* For each range of digits, if c is in that range, mask val with
  161. * the corresponding value. Since c can only be in a single range,
  162. * only at most one masking will change val. Set val to one plus
  163. * the desired value so that it stays 0 if c is in none of the ranges. */
  164. val |= mask_of_range( 'A', 'Z', c ) & ( c - 'A' + 0 + 1 );
  165. val |= mask_of_range( 'a', 'z', c ) & ( c - 'a' + 26 + 1 );
  166. val |= mask_of_range( '0', '9', c ) & ( c - '0' + 52 + 1 );
  167. val |= mask_of_range( '+', '+', c ) & ( c - '+' + 62 + 1 );
  168. val |= mask_of_range( '/', '/', c ) & ( c - '/' + 63 + 1 );
  169. /* At this point, val is 0 if c is an invalid digit and v+1 if c is
  170. * a digit with the value v. */
  171. return( val - 1 );
  172. }
  173. /*
  174. * Decode a base64-formatted buffer
  175. */
  176. int mbedtls_base64_decode( unsigned char *dst, size_t dlen, size_t *olen,
  177. const unsigned char *src, size_t slen )
  178. {
  179. size_t i; /* index in source */
  180. size_t n; /* number of digits or trailing = in source */
  181. uint32_t x; /* value accumulator */
  182. unsigned accumulated_digits = 0;
  183. unsigned equals = 0;
  184. int spaces_present = 0;
  185. unsigned char *p;
  186. /* First pass: check for validity and get output length */
  187. for( i = n = 0; i < slen; i++ )
  188. {
  189. /* Skip spaces before checking for EOL */
  190. spaces_present = 0;
  191. while( i < slen && src[i] == ' ' )
  192. {
  193. ++i;
  194. spaces_present = 1;
  195. }
  196. /* Spaces at end of buffer are OK */
  197. if( i == slen )
  198. break;
  199. if( ( slen - i ) >= 2 &&
  200. src[i] == '\r' && src[i + 1] == '\n' )
  201. continue;
  202. if( src[i] == '\n' )
  203. continue;
  204. /* Space inside a line is an error */
  205. if( spaces_present )
  206. return( MBEDTLS_ERR_BASE64_INVALID_CHARACTER );
  207. if( src[i] > 127 )
  208. return( MBEDTLS_ERR_BASE64_INVALID_CHARACTER );
  209. if( src[i] == '=' )
  210. {
  211. if( ++equals > 2 )
  212. return( MBEDTLS_ERR_BASE64_INVALID_CHARACTER );
  213. }
  214. else
  215. {
  216. if( equals != 0 )
  217. return( MBEDTLS_ERR_BASE64_INVALID_CHARACTER );
  218. if( dec_value( src[i] ) < 0 )
  219. return( MBEDTLS_ERR_BASE64_INVALID_CHARACTER );
  220. }
  221. n++;
  222. }
  223. if( n == 0 )
  224. {
  225. *olen = 0;
  226. return( 0 );
  227. }
  228. /* The following expression is to calculate the following formula without
  229. * risk of integer overflow in n:
  230. * n = ( ( n * 6 ) + 7 ) >> 3;
  231. */
  232. n = ( 6 * ( n >> 3 ) ) + ( ( 6 * ( n & 0x7 ) + 7 ) >> 3 );
  233. n -= equals;
  234. if( dst == NULL || dlen < n )
  235. {
  236. *olen = n;
  237. return( MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL );
  238. }
  239. equals = 0;
  240. for( x = 0, p = dst; i > 0; i--, src++ )
  241. {
  242. if( *src == '\r' || *src == '\n' || *src == ' ' )
  243. continue;
  244. x = x << 6;
  245. if( *src == '=' )
  246. ++equals;
  247. else
  248. x |= dec_value( *src );
  249. if( ++accumulated_digits == 4 )
  250. {
  251. accumulated_digits = 0;
  252. *p++ = (unsigned char)( x >> 16 );
  253. if( equals <= 1 ) *p++ = (unsigned char)( x >> 8 );
  254. if( equals <= 0 ) *p++ = (unsigned char)( x );
  255. }
  256. }
  257. *olen = p - dst;
  258. return( 0 );
  259. }
  260. #if defined(MBEDTLS_SELF_TEST)
  261. static const unsigned char base64_test_dec[64] =
  262. {
  263. 0x24, 0x48, 0x6E, 0x56, 0x87, 0x62, 0x5A, 0xBD,
  264. 0xBF, 0x17, 0xD9, 0xA2, 0xC4, 0x17, 0x1A, 0x01,
  265. 0x94, 0xED, 0x8F, 0x1E, 0x11, 0xB3, 0xD7, 0x09,
  266. 0x0C, 0xB6, 0xE9, 0x10, 0x6F, 0x22, 0xEE, 0x13,
  267. 0xCA, 0xB3, 0x07, 0x05, 0x76, 0xC9, 0xFA, 0x31,
  268. 0x6C, 0x08, 0x34, 0xFF, 0x8D, 0xC2, 0x6C, 0x38,
  269. 0x00, 0x43, 0xE9, 0x54, 0x97, 0xAF, 0x50, 0x4B,
  270. 0xD1, 0x41, 0xBA, 0x95, 0x31, 0x5A, 0x0B, 0x97
  271. };
  272. static const unsigned char base64_test_enc[] =
  273. "JEhuVodiWr2/F9mixBcaAZTtjx4Rs9cJDLbpEG8i7hPK"
  274. "swcFdsn6MWwINP+Nwmw4AEPpVJevUEvRQbqVMVoLlw==";
  275. /*
  276. * Checkup routine
  277. */
  278. int mbedtls_base64_self_test( int verbose )
  279. {
  280. size_t len;
  281. const unsigned char *src;
  282. unsigned char buffer[128];
  283. if( verbose != 0 )
  284. mbedtls_printf( " Base64 encoding test: " );
  285. src = base64_test_dec;
  286. if( mbedtls_base64_encode( buffer, sizeof( buffer ), &len, src, 64 ) != 0 ||
  287. memcmp( base64_test_enc, buffer, 88 ) != 0 )
  288. {
  289. if( verbose != 0 )
  290. mbedtls_printf( "failed\n" );
  291. return( 1 );
  292. }
  293. if( verbose != 0 )
  294. mbedtls_printf( "passed\n Base64 decoding test: " );
  295. src = base64_test_enc;
  296. if( mbedtls_base64_decode( buffer, sizeof( buffer ), &len, src, 88 ) != 0 ||
  297. memcmp( base64_test_dec, buffer, 64 ) != 0 )
  298. {
  299. if( verbose != 0 )
  300. mbedtls_printf( "failed\n" );
  301. return( 1 );
  302. }
  303. if( verbose != 0 )
  304. mbedtls_printf( "passed\n\n" );
  305. return( 0 );
  306. }
  307. #endif /* MBEDTLS_SELF_TEST */
  308. #endif /* MBEDTLS_BASE64_C */