Commit Detail
Commit 0d99bf2
Fix pre-existing assertion bugs in digest and AES-CTR `OpenSSLDigestContext::close()` used `KJ_ASSERT(size, buf.size())` which asserts `size != 0` with `buf.size()` as debug context (comma operator). This was intended to verify `size == buf.size()` — the safety check was a no-op. All other digest finalization sites use `==`. `AesCtrKey::process()` used `KJ_DASSERT` (debug-only) for output length bounds checks after `EVP_CipherUpdate` and `EVP_CipherFinal`. The equivalent checks in AES-GCM and AES-CBC use `KJ_ASSERT`. In release builds, a buffer overrun from OpenSSL would go undetected.
Files changed
2 files changed~2 modified