mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
libpv: Remove unused code
Remove all the code just pvattest-C used from libpv. z(get)dump is the only user as of now. Acked-by: Marc Hartmayer <mhartmay@linux.ibm.com> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
This commit is contained in:
+1
-12
@@ -9,10 +9,7 @@ GLIB2_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags glib-2.0)
|
||||
GLIB2_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs glib-2.0)
|
||||
LIBCRYPTO_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags libcrypto)
|
||||
LIBCRYPTO_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcrypto)
|
||||
LIBCURL_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags libcurl)
|
||||
LIBCURL_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcurl)
|
||||
LDLIBS += $(GLIB2_LIBS) $(LIBCRYPTO_LIBS) $(LIBCURL_LIBS)
|
||||
|
||||
LDLIBS += $(GLIB2_LIBS) $(LIBCRYPTO_LIBS)
|
||||
WARNINGS := -Wall -Wextra -Wshadow \
|
||||
-Wcast-align -Wwrite-strings -Wmissing-prototypes \
|
||||
-Wmissing-declarations -Wredundant-decls -Wnested-externs \
|
||||
@@ -24,18 +21,15 @@ WARNINGS := -Wall -Wextra -Wshadow \
|
||||
ALL_CFLAGS += -DOPENSSL_API_COMPAT=0x10101000L \
|
||||
$(GLIB2_CFLAGS) \
|
||||
$(LIBCRYPTO_CFLAGS) \
|
||||
$(LIBCURL_CFLAGS) \
|
||||
$(WARNINGS) \
|
||||
$(NULL)
|
||||
|
||||
BUILD_TARGETS := skip-$(LIB)
|
||||
ifneq (${HAVE_OPENSSL},0)
|
||||
ifneq (${HAVE_GLIB2},0)
|
||||
ifneq (${HAVE_LIBCURL},0)
|
||||
BUILD_TARGETS := $(LIB)
|
||||
endif
|
||||
endif
|
||||
endif
|
||||
|
||||
sources := $(wildcard *.c)
|
||||
objects := $(patsubst %.c,%.o,$(sources))
|
||||
@@ -82,9 +76,4 @@ skip-$(LIB):
|
||||
"openssl-devel / libssl-dev version >= 1.1.1", \
|
||||
"HAVE_OPENSSL=0", \
|
||||
"-I.")
|
||||
$(call check_dep, \
|
||||
"$(LIB)", \
|
||||
"curl/curl.h", \
|
||||
"libcurl-devel", \
|
||||
"HAVE_LIBCURL=0")
|
||||
touch $@
|
||||
|
||||
-1706
File diff suppressed because it is too large
Load Diff
@@ -1,45 +0,0 @@
|
||||
/*
|
||||
* Libpv common functions.
|
||||
*
|
||||
* Copyright IBM Corp. 2022
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*
|
||||
*/
|
||||
/* Must be included before any other header */
|
||||
#include "config.h"
|
||||
|
||||
#include "libpv/common.h"
|
||||
#include "libpv/cert.h"
|
||||
#include "libpv/curl.h"
|
||||
|
||||
/* setup and tear down */
|
||||
int pv_init(void)
|
||||
{
|
||||
static size_t openssl_initalized;
|
||||
|
||||
if (g_once_init_enter(&openssl_initalized)) {
|
||||
if (OPENSSL_VERSION_NUMBER < 0x1000100fL)
|
||||
g_assert_not_reached();
|
||||
#if OPENSSL_VERSION_NUMBER < 0x10100000L
|
||||
SSL_library_init();
|
||||
SSL_load_error_strings();
|
||||
#else
|
||||
OPENSSL_init_crypto(0, NULL);
|
||||
#endif
|
||||
|
||||
if (pv_curl_init() != 0)
|
||||
return -1;
|
||||
|
||||
pv_cert_init();
|
||||
g_once_init_leave(&openssl_initalized, 1);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
void pv_cleanup(void)
|
||||
{
|
||||
pv_cert_cleanup();
|
||||
pv_curl_cleanup();
|
||||
}
|
||||
-216
@@ -17,7 +17,6 @@
|
||||
#include "lib/zt_common.h"
|
||||
#include "libpv/crypto.h"
|
||||
#include "libpv/glib-helper.h"
|
||||
#include "libpv/hash.h"
|
||||
|
||||
char *pv_get_openssl_errors(void)
|
||||
{
|
||||
@@ -46,59 +45,6 @@ int pv_BIO_reset(BIO *b)
|
||||
return 1;
|
||||
}
|
||||
|
||||
GBytes *pv_generate_rand_data(size_t size, GError **error)
|
||||
{
|
||||
g_autofree uint8_t *data = NULL;
|
||||
|
||||
if (size > INT_MAX) {
|
||||
g_set_error_literal(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_RANDOMIZATION,
|
||||
"Too many random data requested. Split it up");
|
||||
OPENSSL_clear_free(data, size);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
data = g_malloc(size);
|
||||
if (RAND_bytes(data, (int)size) != 1) {
|
||||
g_set_error_literal(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_RANDOMIZATION,
|
||||
"The required amount of random data is not available");
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return pv_sec_gbytes_new_take(g_steal_pointer(&data), size);
|
||||
}
|
||||
|
||||
GBytes *pv_generate_key(const EVP_CIPHER *cipher, GError **error)
|
||||
{
|
||||
int size;
|
||||
|
||||
pv_wrapped_g_assert(cipher);
|
||||
|
||||
size = EVP_CIPHER_key_length(cipher);
|
||||
if (size <= 0) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_KEYGENERATION,
|
||||
"Unknown cipher");
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return pv_generate_rand_data((guint)size, error);
|
||||
}
|
||||
|
||||
GBytes *pv_generate_iv(const EVP_CIPHER *cipher, GError **error)
|
||||
{
|
||||
int size;
|
||||
|
||||
pv_wrapped_g_assert(cipher);
|
||||
|
||||
size = EVP_CIPHER_iv_length(cipher);
|
||||
if (size <= 0) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_KEYGENERATION,
|
||||
"Unknown cipher");
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return pv_generate_rand_data((guint)size, error);
|
||||
}
|
||||
|
||||
static int64_t pv_gcm_encrypt_decrypt(GBytes *input, GBytes *aad, const PvCipherParms *parms,
|
||||
GBytes **output, GBytes **tagp, enum PvCryptoMode mode,
|
||||
GError **error)
|
||||
@@ -360,168 +306,6 @@ GBytes *pv_hkdf_extract_and_expand(size_t derived_key_len, GBytes *key, GBytes *
|
||||
return pv_sec_gbytes_new_take(g_steal_pointer(&derived_key), derived_key_len);
|
||||
}
|
||||
|
||||
EVP_PKEY *pv_generate_ec_key(int nid, GError **error)
|
||||
{
|
||||
g_autoptr(EVP_PKEY_CTX) ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_EC, NULL);
|
||||
g_autoptr(EVP_PKEY) ret = NULL;
|
||||
|
||||
g_assert(ctx);
|
||||
|
||||
if (EVP_PKEY_keygen_init(ctx) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_KEYGENERATION,
|
||||
_("EC key could not be auto-generated"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (EVP_PKEY_CTX_set_ec_paramgen_curve_nid(ctx, nid) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_KEYGENERATION,
|
||||
_("EC key could not be auto-generated"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (EVP_PKEY_keygen(ctx, &ret) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_KEYGENERATION,
|
||||
_("EC key could not be auto-generated"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
/* Convert a EVP_PKEY to the key format used in the PV header */
|
||||
PvEcdhPubKey *pv_evp_pkey_to_ecdh_pub_key(EVP_PKEY *key, GError **error)
|
||||
{
|
||||
g_autofree PvEcdhPubKey *ret = g_new0(PvEcdhPubKey, 1);
|
||||
g_autoptr(BIGNUM) pub_x_big = NULL, pub_y_big = NULL;
|
||||
g_autoptr(EC_KEY) ec_key = NULL;
|
||||
const EC_POINT *pub_key;
|
||||
const EC_GROUP *grp;
|
||||
|
||||
pv_wrapped_g_assert(key);
|
||||
|
||||
ec_key = EVP_PKEY_get1_EC_KEY(key);
|
||||
if (!ec_key) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Key has the wrong type"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
pub_key = EC_KEY_get0_public_key(ec_key);
|
||||
if (!pub_key) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Failed to get public key"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
grp = EC_KEY_get0_group(ec_key);
|
||||
if (!grp) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Failed to get EC group"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
pub_x_big = BN_new();
|
||||
if (!pub_x_big)
|
||||
g_abort();
|
||||
|
||||
pub_y_big = BN_new();
|
||||
if (!pub_y_big)
|
||||
g_abort();
|
||||
|
||||
if (EC_POINT_get_affine_coordinates_GFp(grp, pub_key, pub_x_big, pub_y_big, NULL) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Cannot convert key to internal format"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (BN_bn2binpad(pub_x_big, ret->x, sizeof(ret->x)) < 0) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Cannot convert key to internal format"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (BN_bn2binpad(pub_y_big, ret->y, sizeof(ret->y)) < 0) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Cannot convert key to internal format"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
static GBytes *derive_key(EVP_PKEY *key1, EVP_PKEY *key2, GError **error)
|
||||
{
|
||||
g_autoptr(EVP_PKEY_CTX) ctx = NULL;
|
||||
uint8_t *data = NULL;
|
||||
size_t data_size, key_size;
|
||||
|
||||
ctx = EVP_PKEY_CTX_new(key1, NULL);
|
||||
if (!ctx)
|
||||
g_abort();
|
||||
|
||||
if (EVP_PKEY_derive_init(ctx) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Key derivation failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (EVP_PKEY_derive_set_peer(ctx, key2) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Key derivation failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* Determine buffer length */
|
||||
if (EVP_PKEY_derive(ctx, NULL, &key_size) != 1) {
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_DERIVE,
|
||||
_("Key derivation failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
data_size = key_size;
|
||||
data = OPENSSL_malloc(data_size);
|
||||
if (!data)
|
||||
g_abort();
|
||||
if (EVP_PKEY_derive(ctx, data, &data_size) != 1) {
|
||||
OPENSSL_clear_free(data, data_size);
|
||||
g_set_error(error, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_DERIVE,
|
||||
_("Key derivation failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
g_assert(data_size == key_size);
|
||||
return pv_sec_gbytes_new_take(g_steal_pointer(&data), data_size);
|
||||
}
|
||||
|
||||
GBytes *pv_derive_exchange_key(EVP_PKEY *cust, EVP_PKEY *host, GError **error)
|
||||
{
|
||||
const guint8 append[] = { 0x00, 0x00, 0x00, 0x01 };
|
||||
g_autoptr(GBytes) derived_key = NULL, ret = NULL;
|
||||
g_autoptr(GByteArray) der_key_ga = NULL;
|
||||
g_autofree uint8_t *raw = NULL;
|
||||
size_t raw_len;
|
||||
|
||||
pv_wrapped_g_assert(cust);
|
||||
pv_wrapped_g_assert(host);
|
||||
|
||||
derived_key = derive_key(cust, host, error);
|
||||
if (!derived_key)
|
||||
return NULL;
|
||||
|
||||
der_key_ga = g_bytes_unref_to_array(g_steal_pointer(&derived_key));
|
||||
/* ANSI X.9.63-2011: 66 bytes x with leading 7 bits and
|
||||
* concatenate 32 bit int '1'
|
||||
*/
|
||||
der_key_ga = g_byte_array_append(der_key_ga, append, sizeof(append));
|
||||
/* free GBytesArray and get underlying data */
|
||||
raw_len = der_key_ga->len;
|
||||
raw = g_byte_array_free(g_steal_pointer(&der_key_ga), FALSE);
|
||||
|
||||
ret = pv_sha256_hash(raw, raw_len, error);
|
||||
OPENSSL_cleanse(raw, raw_len);
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
GQuark pv_crypto_error_quark(void)
|
||||
{
|
||||
return g_quark_from_static_string("pv-crypto-error-quark");
|
||||
|
||||
-116
@@ -1,116 +0,0 @@
|
||||
/*
|
||||
* Libcurl utils
|
||||
*
|
||||
* Copyright IBM Corp. 2020
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*/
|
||||
/* Must be included before any other header */
|
||||
#include "config.h"
|
||||
|
||||
#include <curl/curl.h>
|
||||
#include <stdio.h>
|
||||
|
||||
#include "lib/zt_common.h"
|
||||
#include "libpv/curl.h"
|
||||
|
||||
struct UserData {
|
||||
GByteArray *buffer;
|
||||
uint max_size;
|
||||
};
|
||||
|
||||
static size_t write_callback(char *ptr, size_t size, size_t nmemb, void *userdata)
|
||||
{
|
||||
g_assert(userdata);
|
||||
struct UserData *data = (struct UserData *)userdata;
|
||||
GByteArray *buffer = data->buffer;
|
||||
uint64_t actual_size;
|
||||
size_t err;
|
||||
|
||||
g_assert(buffer);
|
||||
|
||||
if (!g_uint64_checked_mul(&actual_size, size, nmemb))
|
||||
g_abort();
|
||||
|
||||
/* Signal an error condition by returning a amount that differs
|
||||
* from the amount passed to the callback. This results in a
|
||||
* CURLE_WRITE_ERROR.
|
||||
*/
|
||||
err = actual_size + 1;
|
||||
|
||||
if (actual_size > G_MAXUINT)
|
||||
return err;
|
||||
|
||||
data->buffer = g_byte_array_append(buffer, (uint8_t *)ptr, (uint)actual_size);
|
||||
if (data->buffer->len > data->max_size)
|
||||
return err;
|
||||
|
||||
return actual_size;
|
||||
}
|
||||
|
||||
int pv_curl_init(void)
|
||||
{
|
||||
if (curl_global_init(CURL_GLOBAL_ALL) != 0)
|
||||
return -1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
void pv_curl_cleanup(void)
|
||||
{
|
||||
curl_global_cleanup();
|
||||
}
|
||||
|
||||
GByteArray *curl_download(const char *url, long timeout_ms, uint max_size, GError **err)
|
||||
{
|
||||
g_autoptr(GByteArray) ret = NULL;
|
||||
g_autoptr(CURL) handle = NULL;
|
||||
g_autofree char *agent = NULL;
|
||||
struct UserData userdata;
|
||||
CURLcode rc;
|
||||
|
||||
/* set up curl session */
|
||||
handle = curl_easy_init();
|
||||
if (!handle)
|
||||
g_abort();
|
||||
|
||||
/* follow redirection */
|
||||
rc = curl_easy_setopt(handle, CURLOPT_FOLLOWLOCATION, 1L);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
rc = curl_easy_setopt(handle, CURLOPT_TIMEOUT_MS, timeout_ms);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
rc = curl_easy_setopt(handle, CURLOPT_NOSIGNAL, 1L);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
agent = g_strdup_printf("%s/%s", GETTEXT_PACKAGE, RELEASE_STRING);
|
||||
rc = curl_easy_setopt(handle, CURLOPT_USERAGENT, agent);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
rc = curl_easy_setopt(handle, CURLOPT_WRITEFUNCTION, write_callback);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
ret = g_byte_array_new();
|
||||
userdata.buffer = ret;
|
||||
userdata.max_size = max_size;
|
||||
rc = curl_easy_setopt(handle, CURLOPT_WRITEDATA, (void *)&userdata);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
rc = curl_easy_setopt(handle, CURLOPT_URL, url);
|
||||
if (rc != CURLE_OK)
|
||||
goto curl_err;
|
||||
|
||||
rc = curl_easy_perform(handle);
|
||||
if (rc != CURLE_OK) {
|
||||
g_set_error(err, PV_CURL_ERROR, PV_CURL_ERROR_DOWNLOAD_FAILED,
|
||||
_("download failed: %s"), curl_easy_strerror(rc));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return g_steal_pointer(&ret);
|
||||
curl_err:
|
||||
g_set_error(err, PV_CURL_ERROR, PV_CURL_ERROR_CURL_INIT_FAILED,
|
||||
_("cURL initialization failed: %s"), curl_easy_strerror(rc));
|
||||
return NULL;
|
||||
}
|
||||
-153
@@ -1,153 +0,0 @@
|
||||
/*
|
||||
* Hashing functions.
|
||||
|
||||
* Copyright IBM Corp. 2022
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*/
|
||||
/* Must be included before any other header */
|
||||
#include "config.h"
|
||||
|
||||
#include "libpv/crypto.h"
|
||||
#include "libpv/hash.h"
|
||||
|
||||
GBytes *pv_sha256_hash(uint8_t *buf, size_t size, GError **error)
|
||||
{
|
||||
g_autoptr(EVP_MD_CTX) ctx = NULL;
|
||||
|
||||
ctx = pv_digest_ctx_new(EVP_sha256(), error);
|
||||
if (!ctx)
|
||||
return NULL;
|
||||
|
||||
if (pv_digest_ctx_update_raw(ctx, buf, size, error) != 0)
|
||||
return NULL;
|
||||
|
||||
return pv_digest_ctx_finalize(ctx, error);
|
||||
}
|
||||
|
||||
EVP_MD_CTX *pv_digest_ctx_new(const EVP_MD *md, GError **error)
|
||||
{
|
||||
g_autoptr(EVP_MD_CTX) ctx = EVP_MD_CTX_new();
|
||||
|
||||
if (!ctx) {
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
_("Hash context generation failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (EVP_DigestInit_ex(ctx, md, NULL) != 1) {
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
_("EVP_DigestInit_ex failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return g_steal_pointer(&ctx);
|
||||
}
|
||||
|
||||
int pv_digest_ctx_update_raw(EVP_MD_CTX *ctx, const uint8_t *buf, size_t size, GError **error)
|
||||
{
|
||||
if (!buf || size == 0)
|
||||
return 0;
|
||||
|
||||
if (EVP_DigestUpdate(ctx, buf, size) != 1) {
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
_("EVP_DigestUpdate failed"));
|
||||
return -1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int pv_digest_ctx_update(EVP_MD_CTX *ctx, GBytes *data, GError **error)
|
||||
{
|
||||
const uint8_t *buf;
|
||||
size_t buf_size;
|
||||
|
||||
if (!data)
|
||||
return 0;
|
||||
buf = g_bytes_get_data((GBytes *)data, &buf_size);
|
||||
return pv_digest_ctx_update_raw(ctx, buf, buf_size, error);
|
||||
}
|
||||
|
||||
GBytes *pv_digest_ctx_finalize(EVP_MD_CTX *ctx, GError **error)
|
||||
{
|
||||
int md_size = EVP_MD_size(EVP_MD_CTX_md(ctx));
|
||||
g_autofree uint8_t *digest = NULL;
|
||||
unsigned int digest_size;
|
||||
|
||||
g_assert(md_size > 0);
|
||||
|
||||
digest = g_malloc0((uint)md_size);
|
||||
if (EVP_DigestFinal_ex(ctx, digest, &digest_size) != 1) {
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
_("EVP_DigestFinal_ex failed"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
g_assert(digest_size == (uint)md_size);
|
||||
return g_bytes_new_take(g_steal_pointer(&digest), digest_size);
|
||||
}
|
||||
|
||||
HMAC_CTX *pv_hmac_ctx_new(GBytes *key, const EVP_MD *md, GError **error)
|
||||
{
|
||||
g_autoptr(HMAC_CTX) ctx = HMAC_CTX_new();
|
||||
const uint8_t *key_data;
|
||||
size_t key_size;
|
||||
|
||||
key_data = g_bytes_get_data(key, &key_size);
|
||||
|
||||
if (HMAC_Init_ex(ctx, key_data, (int)key_size, md, NULL) != 1) {
|
||||
g_autofree char *openssl_err_msg = pv_get_openssl_errors();
|
||||
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
"unable to create HMAC context: %s", openssl_err_msg);
|
||||
return NULL;
|
||||
}
|
||||
return g_steal_pointer(&ctx);
|
||||
}
|
||||
|
||||
int pv_hmac_ctx_update_raw(HMAC_CTX *ctx, const void *buf, size_t size, GError **error)
|
||||
{
|
||||
if (!buf || size == 0)
|
||||
return 0;
|
||||
|
||||
if (HMAC_Update(ctx, buf, size) != 1) {
|
||||
g_autofree char *openssl_err_msg = pv_get_openssl_errors();
|
||||
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
"unable to add data to HMAC context: %s", openssl_err_msg);
|
||||
return -1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int pv_hmac_ctx_update(HMAC_CTX *ctx, GBytes *data, GError **error)
|
||||
{
|
||||
const uint8_t *buf;
|
||||
size_t buf_size;
|
||||
|
||||
if (!data)
|
||||
return 0;
|
||||
buf = g_bytes_get_data((GBytes *)data, &buf_size);
|
||||
return pv_hmac_ctx_update_raw(ctx, buf, buf_size, error);
|
||||
}
|
||||
|
||||
GBytes *pv_hamc_ctx_finalize(HMAC_CTX *ctx, GError **error)
|
||||
{
|
||||
int md_size = EVP_MD_size(HMAC_CTX_get_md(ctx));
|
||||
g_autofree uint8_t *hmac = NULL;
|
||||
unsigned int hmac_size = 0;
|
||||
|
||||
g_assert(md_size > 0);
|
||||
|
||||
hmac = g_malloc0((unsigned int)md_size);
|
||||
|
||||
if (HMAC_Final(ctx, hmac, &hmac_size) != 1) {
|
||||
g_autofree char *openssl_err_msg = pv_get_openssl_errors();
|
||||
|
||||
g_set_error(error, PV_HASH_ERROR, PV_HASH_ERROR_INTERNAL,
|
||||
"unable to calculate HMAC: %s", openssl_err_msg);
|
||||
return NULL;
|
||||
}
|
||||
return g_bytes_new_take(g_steal_pointer(&hmac), hmac_size);
|
||||
}
|
||||
Reference in New Issue
Block a user