mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-07-30 22:43:08 +03:00
pkwrite.c: save stack usage for pk_write_key_pem
mbedtls_pk_write_key_pem would allocate 5679 bytes in writing a DER encoded RSA private key. To save stack usage significantly, we use heap memory instead. Signed-off-by: Yanray Wang <yanray.wang@arm.com>
This commit is contained in:
@ -601,14 +601,19 @@ int mbedtls_pk_write_pubkey_pem(mbedtls_pk_context *key, unsigned char *buf, siz
|
|||||||
int mbedtls_pk_write_key_pem(mbedtls_pk_context *key, unsigned char *buf, size_t size)
|
int mbedtls_pk_write_key_pem(mbedtls_pk_context *key, unsigned char *buf, size_t size)
|
||||||
{
|
{
|
||||||
int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
|
int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
|
||||||
unsigned char output_buf[PRV_DER_MAX_BYTES];
|
unsigned char *output_buf = NULL;
|
||||||
|
output_buf = calloc(1, PRV_DER_MAX_BYTES);
|
||||||
|
if (output_buf == NULL) {
|
||||||
|
return MBEDTLS_ERR_PK_ALLOC_FAILED;
|
||||||
|
}
|
||||||
const char *begin, *end;
|
const char *begin, *end;
|
||||||
size_t olen = 0;
|
size_t olen = 0;
|
||||||
|
|
||||||
PK_VALIDATE_RET(key != NULL);
|
PK_VALIDATE_RET(key != NULL);
|
||||||
PK_VALIDATE_RET(buf != NULL || size == 0);
|
PK_VALIDATE_RET(buf != NULL || size == 0);
|
||||||
|
|
||||||
if ((ret = mbedtls_pk_write_key_der(key, output_buf, sizeof(output_buf))) < 0) {
|
if ((ret = mbedtls_pk_write_key_der(key, output_buf, PRV_DER_MAX_BYTES)) < 0) {
|
||||||
|
free(output_buf);
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -624,14 +629,19 @@ int mbedtls_pk_write_key_pem(mbedtls_pk_context *key, unsigned char *buf, size_t
|
|||||||
end = PEM_END_PRIVATE_KEY_EC;
|
end = PEM_END_PRIVATE_KEY_EC;
|
||||||
} else
|
} else
|
||||||
#endif
|
#endif
|
||||||
return MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE;
|
{
|
||||||
|
free(output_buf);
|
||||||
|
return MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE;
|
||||||
|
}
|
||||||
|
|
||||||
if ((ret = mbedtls_pem_write_buffer(begin, end,
|
if ((ret = mbedtls_pem_write_buffer(begin, end,
|
||||||
output_buf + sizeof(output_buf) - ret,
|
output_buf + PRV_DER_MAX_BYTES - ret,
|
||||||
ret, buf, size, &olen)) != 0) {
|
ret, buf, size, &olen)) != 0) {
|
||||||
|
free(output_buf);
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
free(output_buf);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
#endif /* MBEDTLS_PEM_WRITE_C */
|
#endif /* MBEDTLS_PEM_WRITE_C */
|
||||||
|
Reference in New Issue
Block a user