Skip to content
Commit Detail

Commit 0d99bf2

Author
James M Snell <jsnell@cloudflare.com> 2026-03-16 20:45:30 -0700
Parents
7b87c36
Tree
edf9f9d
Fix pre-existing assertion bugs in digest and AES-CTR

`OpenSSLDigestContext::close()` used `KJ_ASSERT(size, buf.size())`
which asserts `size != 0` with `buf.size()` as debug context (comma
operator). This was intended to verify `size == buf.size()` — the
safety check was a no-op. All other digest finalization sites use `==`.

`AesCtrKey::process()` used `KJ_DASSERT` (debug-only) for output
length bounds checks after `EVP_CipherUpdate` and `EVP_CipherFinal`.
The equivalent checks in AES-GCM and AES-CBC use `KJ_ASSERT`. In
release builds, a buffer overrun from OpenSSL would go undetected.

Files changed

2 files changed~2 modified