Fix error detection in contrib/pgcrypto's encrypt_iv() and decrypt_iv().
authorTom Lane
Sat, 28 Jan 2012 04:09:16 +0000 (23:09 -0500)
committerTom Lane
Sat, 28 Jan 2012 04:09:44 +0000 (23:09 -0500)
Due to oversights, the encrypt_iv() and decrypt_iv() functions failed to
report certain types of invalid-input errors, and would instead return
random garbage values.

Marko Kreen, per report from Stefan Kaltenbrunner

contrib/pgcrypto/pgcrypto.c

index 04c90d8672fd7739b789492993d56cf9d348110e..796344f8661f85112d8a39c3f81a2b92c7656690 100644 (file)
@@ -342,8 +342,8 @@ pg_encrypt_iv(PG_FUNCTION_ARGS)
    err = px_combo_init(c, (uint8 *) VARDATA(key), klen,
                        (uint8 *) VARDATA(iv), ivlen);
    if (!err)
-       px_combo_encrypt(c, (uint8 *) VARDATA(data), dlen,
-                        (uint8 *) VARDATA(res), &rlen);
+       err = px_combo_encrypt(c, (uint8 *) VARDATA(data), dlen,
+                              (uint8 *) VARDATA(res), &rlen);
 
    px_combo_free(c);
 
@@ -396,8 +396,8 @@ pg_decrypt_iv(PG_FUNCTION_ARGS)
    err = px_combo_init(c, (uint8 *) VARDATA(key), klen,
                        (uint8 *) VARDATA(iv), ivlen);
    if (!err)
-       px_combo_decrypt(c, (uint8 *) VARDATA(data), dlen,
-                        (uint8 *) VARDATA(res), &rlen);
+       err = px_combo_decrypt(c, (uint8 *) VARDATA(data), dlen,
+                              (uint8 *) VARDATA(res), &rlen);
 
    px_combo_free(c);