control/noise: don't panic when handling ciphertext.

Signed-off-by: David Anderson <danderson@tailscale.com>
This commit is contained in:
David Anderson 2021-10-25 16:45:38 -07:00 committed by Dave Anderson
parent 4004b22fe5
commit a63c4ab378

View File

@ -7,6 +7,7 @@
import (
"context"
"crypto/cipher"
"errors"
"fmt"
"hash"
"io"
@ -282,7 +283,7 @@ type symmetricState struct {
ck [blake2s.Size]byte // chaining key used to construct session keys at the end of the handshake
}
func (s *symmetricState) checkFinished() {
func (s *symmetricState) checkFinished() error {
if s.finished {
panic("attempted to use symmetricState after Split was called")
}
@ -352,7 +353,7 @@ func (s *symmetricState) EncryptAndHash(cipher *singleUseCHP, ciphertext, plaint
func (s *symmetricState) DecryptAndHash(cipher *singleUseCHP, plaintext, ciphertext []byte) error {
s.checkFinished()
if len(ciphertext) != len(plaintext)+chp.Overhead {
panic("plaintext is wrong size for given ciphertext")
return errors.New("plaintext is wrong size for given ciphertext")
}
if _, err := cipher.Open(plaintext[:0], ciphertext, s.h[:]); err != nil {
return err