LCOV - code coverage report
Current view: top level - tls - s2n_server_new_session_ticket.c (source / functions) Hit Total Coverage
Test: unit_test_coverage.info Lines: 220 220 100.0 %
Date: 2026-10-06 07:26:09 Functions: 10 10 100.0 %
Branches: 154 296 52.0 %

           Branch data     Line data    Source code
       1                 :            : /*
       2                 :            :  * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
       3                 :            :  *
       4                 :            :  * Licensed under the Apache License, Version 2.0 (the "License").
       5                 :            :  * You may not use this file except in compliance with the License.
       6                 :            :  * A copy of the License is located at
       7                 :            :  *
       8                 :            :  *  http://aws.amazon.com/apache2.0
       9                 :            :  *
      10                 :            :  * or in the "license" file accompanying this file. This file is distributed
      11                 :            :  * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either
      12                 :            :  * express or implied. See the License for the specific language governing
      13                 :            :  * permissions and limitations under the License.
      14                 :            :  */
      15                 :            : 
      16                 :            : #include <time.h>
      17                 :            : 
      18                 :            : #include "api/s2n.h"
      19                 :            : #include "error/s2n_errno.h"
      20                 :            : #include "stuffer/s2n_stuffer.h"
      21                 :            : #include "tls/s2n_alerts.h"
      22                 :            : #include "tls/s2n_connection.h"
      23                 :            : #include "tls/s2n_record.h"
      24                 :            : #include "tls/s2n_resume.h"
      25                 :            : #include "tls/s2n_tls.h"
      26                 :            : #include "tls/s2n_tls13_handshake.h"
      27                 :            : #include "utils/s2n_random.h"
      28                 :            : #include "utils/s2n_safety.h"
      29                 :            : 
      30                 :            : /*
      31                 :            :  * The maximum size of the NewSessionTicket message, not taking into account the
      32                 :            :  * ticket itself.
      33                 :            :  *
      34                 :            :  * To get the actual maximum size required for the NewSessionTicket message, we'll need
      35                 :            :  * to add the size of the ticket, which is much less predictable.
      36                 :            :  *
      37                 :            :  * This constant is enforced via unit tests.
      38                 :            :  */
      39                 :        300 : #define S2N_TLS13_MAX_FIXED_NEW_SESSION_TICKET_SIZE 112
      40                 :            : 
      41                 :            : int s2n_server_nst_recv(struct s2n_connection *conn)
      42                 :         20 : {
      43         [ -  + ]:         20 :     POSIX_GUARD(s2n_stuffer_read_uint32(&conn->handshake.io, &conn->ticket_lifetime_hint));
      44                 :            : 
      45                 :         20 :     uint16_t session_ticket_len = 0;
      46         [ -  + ]:         20 :     POSIX_GUARD(s2n_stuffer_read_uint16(&conn->handshake.io, &session_ticket_len));
      47                 :            : 
      48         [ +  + ]:         20 :     if (session_ticket_len > 0) {
      49         [ -  + ]:         19 :         POSIX_GUARD(s2n_realloc(&conn->client_ticket, session_ticket_len));
      50                 :            : 
      51         [ -  + ]:         19 :         POSIX_GUARD(s2n_stuffer_read(&conn->handshake.io, &conn->client_ticket));
      52                 :            : 
      53         [ +  + ]:         19 :         if (conn->config->session_ticket_cb != NULL) {
      54                 :          7 :             size_t session_len = s2n_connection_get_session_length(conn);
      55                 :            : 
      56                 :            :             /* Alloc some memory for the serialized session ticket */
      57                 :          7 :             DEFER_CLEANUP(struct s2n_blob mem = { 0 }, s2n_free);
      58         [ -  + ]:          7 :             POSIX_GUARD(s2n_alloc(&mem,
      59                 :          7 :                     S2N_STATE_FORMAT_LEN + S2N_SESSION_TICKET_SIZE_LEN + conn->client_ticket.size + S2N_TLS12_STATE_SIZE_IN_BYTES));
      60                 :            : 
      61         [ -  + ]:          7 :             POSIX_GUARD(s2n_connection_get_session(conn, mem.data, session_len));
      62                 :          7 :             uint32_t session_lifetime = s2n_connection_get_session_ticket_lifetime_hint(conn);
      63                 :            : 
      64                 :          7 :             struct s2n_session_ticket ticket = { .ticket_data = mem, .session_lifetime = session_lifetime };
      65                 :            : 
      66 [ -  + ][ #  # ]:          7 :             POSIX_ENSURE(conn->config->session_ticket_cb(conn, conn->config->session_ticket_ctx, &ticket) >= S2N_SUCCESS,
      67                 :          7 :                     S2N_ERR_CANCELLED);
      68                 :          7 :         }
      69                 :         19 :     }
      70                 :            : 
      71                 :         20 :     return S2N_SUCCESS;
      72                 :         20 : }
      73                 :            : 
      74                 :            : static S2N_RESULT s2n_generate_ticket_lifetime(struct s2n_connection *conn, uint64_t key_intro_time,
      75                 :            :         uint32_t *ticket_lifetime)
      76                 :        407 : {
      77 [ #  # ][ -  + ]:        407 :     RESULT_ENSURE_REF(conn);
      78 [ -  + ][ #  # ]:        407 :     RESULT_ENSURE_REF(conn->config);
      79 [ -  + ][ #  # ]:        407 :     RESULT_ENSURE_MUT(ticket_lifetime);
      80                 :            : 
      81                 :        407 :     uint64_t now = 0;
      82         [ -  + ]:        407 :     RESULT_GUARD(s2n_config_wall_clock(conn->config, &now));
      83                 :            : 
      84                 :            :     /* Calculate ticket key age */
      85 [ #  # ][ -  + ]:        407 :     RESULT_ENSURE_GTE(now, key_intro_time);
      86                 :        407 :     uint64_t ticket_key_age_in_nanos = now - key_intro_time;
      87                 :            : 
      88                 :            :     /* Calculate remaining key lifetime */
      89                 :        407 :     uint64_t key_lifetime_in_nanos = conn->config->encrypt_decrypt_key_lifetime_in_nanos + conn->config->decrypt_key_lifetime_in_nanos;
      90 [ -  + ][ #  # ]:        407 :     RESULT_ENSURE_GTE(key_lifetime_in_nanos, ticket_key_age_in_nanos);
      91                 :        407 :     uint32_t remaining_key_lifetime = (key_lifetime_in_nanos - ticket_key_age_in_nanos) / ONE_SEC_IN_NANOS;
      92                 :            : 
      93                 :        407 :     uint32_t session_lifetime = conn->config->session_state_lifetime_in_nanos / ONE_SEC_IN_NANOS;
      94                 :            : 
      95                 :            :     /* Min of remaining key lifetime and session */
      96         [ +  + ]:        407 :     uint32_t min_lifetime = S2N_MIN(remaining_key_lifetime, session_lifetime);
      97                 :            : 
      98                 :            :     /* In TLS1.3 we take into account keying material lifetime */
      99         [ +  + ]:        407 :     if (conn->actual_protocol_version == S2N_TLS13) {
     100                 :        388 :         uint32_t key_material_lifetime = conn->server_keying_material_lifetime;
     101                 :        388 :         struct s2n_psk *chosen_psk = conn->psk_params.chosen_psk;
     102         [ +  + ]:        388 :         if (chosen_psk) {
     103 [ -  + ][ #  # ]:        186 :             RESULT_ENSURE_GTE(chosen_psk->keying_material_expiration, now);
     104                 :        186 :             uint32_t psk_key_material_lifetime = (chosen_psk->keying_material_expiration - now) / ONE_SEC_IN_NANOS;
     105         [ -  + ]:        186 :             key_material_lifetime = S2N_MIN(key_material_lifetime, psk_key_material_lifetime);
     106                 :        186 :         }
     107         [ +  - ]:        388 :         min_lifetime = S2N_MIN(min_lifetime, key_material_lifetime);
     108                 :        388 :     }
     109                 :            : 
     110                 :            :     /**
     111                 :            :      *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     112                 :            :      *# Servers MUST NOT use any value greater than
     113                 :            :      *# 604800 seconds (7 days).
     114                 :            :      **/
     115         [ +  - ]:        407 :     *ticket_lifetime = S2N_MIN(min_lifetime, ONE_WEEK_IN_SEC);
     116                 :            : 
     117                 :        407 :     return S2N_RESULT_OK;
     118                 :        407 : }
     119                 :            : 
     120                 :            : int s2n_server_nst_send(struct s2n_connection *conn)
     121                 :         23 : {
     122 [ -  + ][ #  # ]:         23 :     POSIX_ENSURE_REF(conn);
     123                 :            : 
     124                 :         23 :     uint8_t data[S2N_TLS12_TICKET_SIZE_IN_BYTES] = { 0 };
     125                 :         23 :     struct s2n_blob session_ticket = { 0 };
     126         [ -  + ]:         23 :     POSIX_GUARD(s2n_blob_init(&session_ticket, data, sizeof(data)));
     127                 :            : 
     128                 :         23 :     uint32_t lifetime_hint_in_secs = 0;
     129                 :            : 
     130                 :            :     /* Send a zero-length ticket in the NewSessionTicket message if the server changes 
     131                 :            :      * its mind mid-handshake or if there are no valid encrypt keys currently available. 
     132                 :            :      *
     133                 :            :      *= https://www.rfc-editor.org/rfc/rfc5077#section-3.3
     134                 :            :      *# If the server determines that it does not want to include a
     135                 :            :      *# ticket after it has included the SessionTicket extension in the
     136                 :            :      *# ServerHello, then it sends a zero-length ticket in the
     137                 :            :      *# NewSessionTicket handshake message.
     138                 :            :      **/
     139         [ +  + ]:         23 :     if (s2n_result_is_error(s2n_server_nst_write(conn, &lifetime_hint_in_secs, &session_ticket))) {
     140         [ -  + ]:          3 :         POSIX_GUARD(s2n_stuffer_write_uint32(&conn->handshake.io, 0));
     141         [ -  + ]:          3 :         POSIX_GUARD(s2n_stuffer_write_uint16(&conn->handshake.io, 0));
     142                 :          3 :         return S2N_SUCCESS;
     143                 :          3 :     }
     144                 :            : 
     145         [ -  + ]:         20 :     POSIX_GUARD(s2n_stuffer_write_uint32(&conn->handshake.io, lifetime_hint_in_secs));
     146         [ -  + ]:         20 :     POSIX_GUARD(s2n_stuffer_write_uint16(&conn->handshake.io, session_ticket.size));
     147         [ -  + ]:         20 :     POSIX_GUARD(s2n_stuffer_write(&conn->handshake.io, &session_ticket));
     148                 :            : 
     149                 :            :     /* For parity with TLS1.3, track the single ticket sent.
     150                 :            :      * This simplifies s2n_connection_get_tickets_sent.
     151                 :            :      */
     152                 :         20 :     conn->tickets_sent++;
     153                 :         20 :     return S2N_SUCCESS;
     154                 :         20 : }
     155                 :            : 
     156                 :            : S2N_RESULT s2n_server_nst_write(struct s2n_connection *conn, uint32_t *lifetime_hint_in_secs,
     157                 :            :         struct s2n_blob *session_ticket)
     158                 :         23 : {
     159 [ #  # ][ -  + ]:         23 :     RESULT_ENSURE_REF(conn);
     160 [ +  - ][ +  + ]:         23 :     RESULT_ENSURE(s2n_server_sending_nst(conn), S2N_ERR_SENDING_NST);
                 [ +  - ]
     161                 :            : 
     162                 :         21 :     struct s2n_stuffer output = { 0 };
     163         [ -  + ]:         21 :     RESULT_GUARD_POSIX(s2n_stuffer_init(&output, session_ticket));
     164                 :            : 
     165                 :         21 :     struct s2n_ticket_key *key = s2n_get_ticket_encrypt_decrypt_key(conn->config);
     166 [ +  - ][ +  + ]:         21 :     RESULT_ENSURE(key != NULL, S2N_ERR_NO_TICKET_ENCRYPT_DECRYPT_KEY);
     167                 :            : 
     168         [ -  + ]:         20 :     RESULT_GUARD(s2n_generate_ticket_lifetime(conn, key->intro_timestamp, lifetime_hint_in_secs));
     169         [ -  + ]:         20 :     RESULT_GUARD(s2n_resume_encrypt_session_ticket(conn, key, &output));
     170                 :            : 
     171                 :         20 :     return S2N_RESULT_OK;
     172                 :         20 : }
     173                 :            : 
     174                 :            : S2N_RESULT s2n_tls13_server_nst_send(struct s2n_connection *conn, s2n_blocked_status *blocked)
     175                 :      51445 : {
     176 [ #  # ][ -  + ]:      51445 :     RESULT_ENSURE_REF(conn);
     177 [ +  + ][ +  - ]:      51445 :     RESULT_ENSURE_GTE(conn->actual_protocol_version, S2N_TLS13);
     178                 :            : 
     179                 :            :     /* Usually tickets are sent immediately after the handshake.
     180                 :            :      * If possible, reuse the handshake IO stuffer before it's wiped.
     181                 :            :      *
     182                 :            :      * Note: handshake.io isn't explicitly dedicated to only reading or only writing,
     183                 :            :      * so we have to be careful using it outside of s2n_negotiate.
     184                 :            :      * If we use it for writing here, we CAN'T use it for reading any post-handshake messages.
     185                 :            :      */
     186                 :      51444 :     struct s2n_stuffer *nst_stuffer = &conn->handshake.io;
     187                 :            : 
     188 [ +  + ][ +  + ]:      51444 :     if (conn->mode != S2N_SERVER || !conn->config->use_tickets) {
     189                 :      50978 :         return S2N_RESULT_OK;
     190                 :      50978 :     }
     191                 :            : 
     192                 :            :     /* Don't issue tickets under client auth: resumption is not supported in that
     193                 :            :      * case (see s2n_select_resumption_psk), so the ticket could never be used.
     194                 :            :      */
     195         [ +  + ]:        466 :     if (s2n_connection_is_client_auth_enabled(conn)) {
     196                 :          2 :         return S2N_RESULT_OK;
     197                 :          2 :     }
     198                 :            : 
     199                 :            :     /* Legacy behavior is that the s2n server sends a NST even if the client did not indicate support
     200                 :            :      * for resumption or does not support the psk_dhe_ke mode. This is potentially wasteful so we 
     201                 :            :      * choose to not extend this behavior to QUIC.
     202                 :            :      */
     203 [ +  + ][ +  + ]:        464 :     if (conn->quic_enabled && conn->psk_params.psk_ke_mode != S2N_PSK_DHE_KE) {
     204                 :          3 :         return S2N_RESULT_OK;
     205                 :          3 :     }
     206                 :            : 
     207                 :            :     /* No-op if all tickets already sent.
     208                 :            :      * Clean up the stuffer used for the ticket to conserve memory. */
     209         [ +  + ]:        461 :     if (conn->tickets_to_send == conn->tickets_sent) {
     210         [ -  + ]:        160 :         RESULT_GUARD_POSIX(s2n_stuffer_resize(nst_stuffer, 0));
     211                 :        160 :         return S2N_RESULT_OK;
     212                 :        160 :     }
     213                 :            : 
     214                 :            :     /**
     215                 :            :      *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     216                 :            :      *# Note that in principle it is possible to continue issuing new tickets
     217                 :            :      *# which indefinitely extend the lifetime of the keying material
     218                 :            :      *# originally derived from an initial non-PSK handshake (which was most
     219                 :            :      *# likely tied to the peer's certificate). It is RECOMMENDED that
     220                 :            :      *# implementations place limits on the total lifetime of such keying
     221                 :            :      *# material; these limits should take into account the lifetime of the
     222                 :            :      *# peer's certificate, the likelihood of intervening revocation, and the
     223                 :            :      *# time since the peer's online CertificateVerify signature.
     224                 :            :      */
     225         [ +  + ]:        301 :     if (s2n_result_is_error(s2n_psk_validate_keying_material(conn))) {
     226                 :          1 :         conn->tickets_to_send = conn->tickets_sent;
     227                 :          1 :         return S2N_RESULT_OK;
     228                 :          1 :     }
     229                 :            : 
     230 [ #  # ][ -  + ]:        300 :     RESULT_ENSURE(conn->tickets_sent <= conn->tickets_to_send, S2N_ERR_INTEGER_OVERFLOW);
     231                 :            : 
     232                 :        300 :     size_t session_state_size = 0;
     233         [ -  + ]:        300 :     RESULT_GUARD(s2n_connection_get_session_state_size(conn, &session_state_size));
     234                 :        300 :     const size_t maximum_nst_size = session_state_size + S2N_TLS13_MAX_FIXED_NEW_SESSION_TICKET_SIZE;
     235         [ +  + ]:        300 :     if (s2n_stuffer_space_remaining(nst_stuffer) < maximum_nst_size) {
     236         [ -  + ]:        129 :         RESULT_GUARD_POSIX(s2n_stuffer_resize(nst_stuffer, maximum_nst_size));
     237                 :        129 :     }
     238                 :            : 
     239         [ +  + ]:        599 :     while (conn->tickets_to_send - conn->tickets_sent > 0) {
     240         [ +  + ]:        325 :         if (s2n_result_is_error(s2n_tls13_server_nst_write(conn, nst_stuffer))) {
     241                 :          5 :             return S2N_RESULT_OK;
     242                 :          5 :         }
     243                 :            : 
     244         [ +  + ]:        320 :         RESULT_GUARD(s2n_post_handshake_write_records(conn, blocked));
     245                 :        320 :     }
     246                 :            : 
     247                 :        274 :     return S2N_RESULT_OK;
     248                 :        300 : }
     249                 :            : 
     250                 :            : /** 
     251                 :            :  *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     252                 :            :  *# A per-ticket value that is unique across all tickets
     253                 :            :  *# issued on this connection.
     254                 :            :  **/
     255                 :            : static S2N_RESULT s2n_generate_ticket_nonce(uint16_t value, struct s2n_blob *output)
     256                 :        387 : {
     257 [ #  # ][ -  + ]:        387 :     RESULT_ENSURE_MUT(output);
     258                 :            : 
     259                 :        387 :     struct s2n_stuffer stuffer = { 0 };
     260         [ -  + ]:        387 :     RESULT_GUARD_POSIX(s2n_stuffer_init(&stuffer, output));
     261         [ -  + ]:        387 :     RESULT_GUARD_POSIX(s2n_stuffer_write_uint16(&stuffer, value));
     262                 :            : 
     263                 :        387 :     return S2N_RESULT_OK;
     264                 :        387 : }
     265                 :            : 
     266                 :            : /** 
     267                 :            :  *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     268                 :            :  *# A securely generated, random 32-bit value that is
     269                 :            :  *# used to obscure the age of the ticket that the client includes in
     270                 :            :  *# the "pre_shared_key" extension.
     271                 :            :  **/
     272                 :            : static S2N_RESULT s2n_generate_ticket_age_add(struct s2n_blob *random_data, uint32_t *ticket_age_add)
     273                 :        387 : {
     274 [ -  + ][ #  # ]:        387 :     RESULT_ENSURE_REF(random_data);
     275 [ -  + ][ #  # ]:        387 :     RESULT_ENSURE_REF(ticket_age_add);
     276                 :            : 
     277                 :        387 :     struct s2n_stuffer stuffer = { 0 };
     278         [ -  + ]:        387 :     RESULT_GUARD_POSIX(s2n_stuffer_init(&stuffer, random_data));
     279         [ -  + ]:        387 :     RESULT_GUARD_POSIX(s2n_stuffer_skip_write(&stuffer, random_data->size));
     280         [ -  + ]:        387 :     RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(&stuffer, ticket_age_add));
     281                 :            : 
     282                 :        387 :     return S2N_RESULT_OK;
     283                 :        387 : }
     284                 :            : 
     285                 :            : /**
     286                 :            :  *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     287                 :            :  *# The PSK associated with the ticket is computed as:
     288                 :            :  *#
     289                 :            :  *#    HKDF-Expand-Label(resumption_master_secret,
     290                 :            :  *#                     "resumption", ticket_nonce, Hash.length)
     291                 :            :  **/
     292                 :            : static int s2n_generate_session_secret(struct s2n_connection *conn, struct s2n_blob *nonce, struct s2n_blob *output)
     293                 :        855 : {
     294 [ -  + ][ #  # ]:        855 :     POSIX_ENSURE_REF(conn);
     295 [ -  + ][ #  # ]:        855 :     POSIX_ENSURE_REF(nonce);
     296 [ -  + ][ #  # ]:        855 :     POSIX_ENSURE_REF(output);
     297                 :            : 
     298         [ -  + ]:        855 :     s2n_tls13_connection_keys(secrets, conn);
     299                 :        855 :     struct s2n_blob master_secret = { 0 };
     300         [ -  + ]:        855 :     POSIX_GUARD(s2n_blob_init(&master_secret, conn->secrets.version.tls13.resumption_master_secret, secrets.size));
     301         [ -  + ]:        855 :     POSIX_GUARD(s2n_realloc(output, secrets.size));
     302         [ -  + ]:        855 :     POSIX_GUARD_RESULT(s2n_tls13_derive_session_ticket_secret(&secrets, &master_secret, nonce, output));
     303                 :            : 
     304                 :        855 :     return S2N_SUCCESS;
     305                 :        855 : }
     306                 :            : 
     307                 :            : S2N_RESULT s2n_tls13_server_nst_write(struct s2n_connection *conn, struct s2n_stuffer *output)
     308                 :        429 : {
     309 [ -  + ][ #  # ]:        429 :     RESULT_ENSURE_REF(conn);
     310 [ -  + ][ #  # ]:        429 :     RESULT_ENSURE_REF(output);
     311                 :            : 
     312                 :        429 :     struct s2n_ticket_key *key = s2n_get_ticket_encrypt_decrypt_key(conn->config);
     313 [ +  + ][ +  - ]:        429 :     RESULT_ENSURE(key != NULL, S2N_ERR_NO_TICKET_ENCRYPT_DECRYPT_KEY);
     314                 :            : 
     315                 :        424 :     struct s2n_ticket_fields *ticket_fields = &conn->tls13_ticket_fields;
     316                 :            : 
     317                 :            :     /* Write message type because session resumption in TLS13 is a post-handshake message */
     318         [ -  + ]:        424 :     RESULT_GUARD_POSIX(s2n_stuffer_write_uint8(output, TLS_SERVER_NEW_SESSION_TICKET));
     319                 :            : 
     320                 :        424 :     struct s2n_stuffer_reservation message_size = { 0 };
     321         [ -  + ]:        424 :     RESULT_GUARD_POSIX(s2n_stuffer_reserve_uint24(output, &message_size));
     322                 :            : 
     323                 :        424 :     uint32_t ticket_lifetime_in_secs = 0;
     324         [ -  + ]:        424 :     RESULT_GUARD(s2n_generate_ticket_lifetime(conn, key->intro_timestamp, &ticket_lifetime_in_secs));
     325                 :            : 
     326 [ +  + ][ +  - ]:        424 :     RESULT_ENSURE(ticket_lifetime_in_secs > 0, S2N_ERR_ZERO_LIFETIME_TICKET);
     327         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_write_uint32(output, ticket_lifetime_in_secs));
     328                 :            : 
     329                 :            :     /* Get random data to use as ticket_age_add value */
     330                 :        422 :     uint8_t data[sizeof(uint32_t)] = { 0 };
     331                 :        422 :     struct s2n_blob random_data = { 0 };
     332         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_blob_init(&random_data, data, sizeof(data)));
     333                 :            :     /** 
     334                 :            :      *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     335                 :            :      *#  The server MUST generate a fresh value
     336                 :            :      *#  for each ticket it sends.
     337                 :            :      **/
     338         [ -  + ]:        422 :     RESULT_GUARD(s2n_get_private_random_data(&random_data));
     339         [ -  + ]:        422 :     RESULT_GUARD(s2n_generate_ticket_age_add(&random_data, &ticket_fields->ticket_age_add));
     340         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_write_uint32(output, ticket_fields->ticket_age_add));
     341                 :            : 
     342                 :            :     /* Write ticket nonce */
     343                 :        422 :     uint8_t nonce_data[sizeof(uint16_t)] = { 0 };
     344                 :        422 :     struct s2n_blob nonce = { 0 };
     345         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_blob_init(&nonce, nonce_data, sizeof(nonce_data)));
     346         [ -  + ]:        422 :     RESULT_GUARD(s2n_generate_ticket_nonce(conn->tickets_sent, &nonce));
     347         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_write_uint8(output, nonce.size));
     348         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_write_bytes(output, nonce.data, nonce.size));
     349                 :            : 
     350                 :            :     /* Derive individual session ticket secret */
     351         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_generate_session_secret(conn, &nonce, &ticket_fields->session_secret));
     352                 :            : 
     353                 :            :     /* Write ticket */
     354                 :        422 :     struct s2n_stuffer_reservation ticket_size = { 0 };
     355         [ -  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_reserve_uint16(output, &ticket_size));
     356         [ -  + ]:        422 :     RESULT_GUARD(s2n_resume_encrypt_session_ticket(conn, key, output));
     357         [ +  + ]:        422 :     RESULT_GUARD_POSIX(s2n_stuffer_write_vector_size(&ticket_size));
     358                 :            : 
     359         [ -  + ]:        421 :     RESULT_GUARD_POSIX(s2n_extension_list_send(S2N_EXTENSION_LIST_NST, conn, output));
     360                 :            : 
     361         [ -  + ]:        421 :     RESULT_GUARD_POSIX(s2n_stuffer_write_vector_size(&message_size));
     362                 :            : 
     363 [ +  - ][ +  + ]:        421 :     RESULT_ENSURE(conn->tickets_sent < UINT16_MAX, S2N_ERR_INTEGER_OVERFLOW);
     364                 :        420 :     conn->tickets_sent++;
     365                 :            : 
     366                 :        420 :     return S2N_RESULT_OK;
     367                 :        421 : }
     368                 :            : 
     369                 :            : /**
     370                 :            :  *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     371                 :            :  *#     struct {
     372                 :            :  *#         uint32 ticket_lifetime;
     373                 :            :  *#         uint32 ticket_age_add;
     374                 :            :  *#         opaque ticket_nonce<0..255>;
     375                 :            :  *#         opaque ticket<1..2^16-1>;
     376                 :            :  *#         Extension extensions<0..2^16-2>;
     377                 :            :  *#      } NewSessionTicket;
     378                 :            : **/
     379                 :            : S2N_RESULT s2n_tls13_server_nst_recv(struct s2n_connection *conn, struct s2n_stuffer *input)
     380                 :        487 : {
     381 [ #  # ][ -  + ]:        487 :     RESULT_ENSURE_REF(conn);
     382 [ -  + ][ #  # ]:        487 :     RESULT_ENSURE_REF(input);
     383 [ -  + ][ #  # ]:        487 :     RESULT_ENSURE_REF(conn->config);
     384                 :            : 
     385 [ +  + ][ +  - ]:        487 :     RESULT_ENSURE(conn->actual_protocol_version >= S2N_TLS13, S2N_ERR_BAD_MESSAGE);
     386 [ +  + ][ +  - ]:        486 :     RESULT_ENSURE(conn->mode == S2N_CLIENT, S2N_ERR_BAD_MESSAGE);
     387                 :            : 
     388         [ +  + ]:        483 :     if (!conn->config->use_tickets) {
     389                 :          1 :         return S2N_RESULT_OK;
     390                 :          1 :     }
     391                 :        482 :     struct s2n_ticket_fields *ticket_fields = &conn->tls13_ticket_fields;
     392                 :            : 
     393                 :            :     /* Handle `ticket_lifetime` field */
     394                 :        482 :     uint32_t ticket_lifetime = 0;
     395         [ -  + ]:        482 :     RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(input, &ticket_lifetime));
     396                 :            :     /**
     397                 :            :      *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     398                 :            :      *# Servers MUST NOT use any value greater than
     399                 :            :      *# 604800 seconds (7 days).
     400                 :            :      */
     401 [ +  + ][ +  - ]:        482 :     RESULT_ENSURE(ticket_lifetime <= ONE_WEEK_IN_SEC, S2N_ERR_BAD_MESSAGE);
     402                 :            :     /**
     403                 :            :      *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
     404                 :            :      *# The value of zero indicates that the
     405                 :            :      *# ticket should be discarded immediately.
     406                 :            :      */
     407         [ +  + ]:        481 :     if (ticket_lifetime == 0) {
     408                 :          1 :         return S2N_RESULT_OK;
     409                 :          1 :     }
     410                 :        480 :     conn->ticket_lifetime_hint = ticket_lifetime;
     411                 :            : 
     412                 :            :     /* Handle `ticket_age_add` field */
     413         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(input, &ticket_fields->ticket_age_add));
     414                 :            : 
     415                 :            :     /* Handle `ticket_nonce` field */
     416                 :        480 :     uint8_t ticket_nonce_len = 0;
     417         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_stuffer_read_uint8(input, &ticket_nonce_len));
     418                 :        480 :     uint8_t nonce_data[UINT8_MAX] = { 0 };
     419                 :        480 :     struct s2n_blob nonce = { 0 };
     420         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_blob_init(&nonce, nonce_data, ticket_nonce_len));
     421         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_stuffer_read_bytes(input, nonce.data, ticket_nonce_len));
     422         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_generate_session_secret(conn, &nonce, &ticket_fields->session_secret));
     423                 :            : 
     424                 :            :     /* Handle `ticket` field */
     425                 :        480 :     uint16_t session_ticket_len = 0;
     426         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_stuffer_read_uint16(input, &session_ticket_len));
     427 [ -  + ][ #  # ]:        480 :     RESULT_ENSURE(session_ticket_len > 0, S2N_ERR_SAFETY);
     428         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_realloc(&conn->client_ticket, session_ticket_len));
     429         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_stuffer_read(input, &conn->client_ticket));
     430                 :            : 
     431                 :            :     /* Handle `extensions` field */
     432         [ -  + ]:        480 :     RESULT_GUARD_POSIX(s2n_extension_list_recv(S2N_EXTENSION_LIST_NST, conn, input));
     433                 :            : 
     434         [ +  + ]:        480 :     if (conn->config->session_ticket_cb != NULL) {
     435                 :            :         /* Retrieve serialized session data */
     436                 :        433 :         const uint16_t session_state_size = s2n_connection_get_session_length(conn);
     437                 :        433 :         DEFER_CLEANUP(struct s2n_blob session_state = { 0 }, s2n_free);
     438         [ -  + ]:        433 :         RESULT_GUARD_POSIX(s2n_realloc(&session_state, session_state_size));
     439         [ -  + ]:        433 :         RESULT_GUARD_POSIX(s2n_connection_get_session(conn, session_state.data, session_state.size));
     440                 :            : 
     441                 :        433 :         struct s2n_session_ticket ticket = {
     442                 :        433 :             .ticket_data = session_state,
     443                 :        433 :             .session_lifetime = ticket_lifetime
     444                 :        433 :         };
     445 [ -  + ][ #  # ]:        433 :         RESULT_ENSURE(conn->config->session_ticket_cb(conn, conn->config->session_ticket_ctx, &ticket) >= S2N_SUCCESS,
     446                 :        433 :                 S2N_ERR_CANCELLED);
     447                 :        433 :     }
     448                 :            : 
     449                 :        480 :     return S2N_RESULT_OK;
     450                 :        480 : }

Generated by: LCOV version 1.14