Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 1 | /* |
| 2 | * QEMU Crypto hmac algorithms (based on libgcrypt) |
| 3 | * |
| 4 | * Copyright (c) 2016 HUAWEI TECHNOLOGIES CO., LTD. |
| 5 | * |
| 6 | * Authors: |
| 7 | * Longpeng(Mike) <longpeng2@huawei.com> |
| 8 | * |
| 9 | * This work is licensed under the terms of the GNU GPL, version 2 or |
| 10 | * (at your option) any later version. See the COPYING file in the |
| 11 | * top-level directory. |
| 12 | * |
| 13 | */ |
| 14 | |
| 15 | #include "qemu/osdep.h" |
| 16 | #include "qapi/error.h" |
| 17 | #include "crypto/hmac.h" |
Longpeng(Mike) | 14a5a2a | 2017-07-14 14:04:04 -0400 | [diff] [blame] | 18 | #include "hmacpriv.h" |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 19 | #include <gcrypt.h> |
| 20 | |
Markus Armbruster | ef834aa | 2024-09-04 13:18:28 +0200 | [diff] [blame] | 21 | static int qcrypto_hmac_alg_map[QCRYPTO_HASH_ALGO__MAX] = { |
| 22 | [QCRYPTO_HASH_ALGO_MD5] = GCRY_MAC_HMAC_MD5, |
| 23 | [QCRYPTO_HASH_ALGO_SHA1] = GCRY_MAC_HMAC_SHA1, |
| 24 | [QCRYPTO_HASH_ALGO_SHA224] = GCRY_MAC_HMAC_SHA224, |
| 25 | [QCRYPTO_HASH_ALGO_SHA256] = GCRY_MAC_HMAC_SHA256, |
| 26 | [QCRYPTO_HASH_ALGO_SHA384] = GCRY_MAC_HMAC_SHA384, |
| 27 | [QCRYPTO_HASH_ALGO_SHA512] = GCRY_MAC_HMAC_SHA512, |
| 28 | [QCRYPTO_HASH_ALGO_RIPEMD160] = GCRY_MAC_HMAC_RMD160, |
liequan che | d078da8 | 2024-10-30 08:51:46 +0000 | [diff] [blame] | 29 | #ifdef CONFIG_CRYPTO_SM3 |
| 30 | [QCRYPTO_HASH_ALGO_SM3] = GCRY_MAC_HMAC_SM3, |
| 31 | #endif |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 32 | }; |
| 33 | |
| 34 | typedef struct QCryptoHmacGcrypt QCryptoHmacGcrypt; |
| 35 | struct QCryptoHmacGcrypt { |
| 36 | gcry_mac_hd_t handle; |
| 37 | }; |
| 38 | |
Markus Armbruster | ef834aa | 2024-09-04 13:18:28 +0200 | [diff] [blame] | 39 | bool qcrypto_hmac_supports(QCryptoHashAlgo alg) |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 40 | { |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 41 | if (alg < G_N_ELEMENTS(qcrypto_hmac_alg_map) && |
| 42 | qcrypto_hmac_alg_map[alg] != GCRY_MAC_NONE) { |
Daniel P. Berrangé | a7e4275 | 2024-10-30 10:09:30 +0000 | [diff] [blame] | 43 | return gcry_mac_test_algo(qcrypto_hmac_alg_map[alg]) == 0; |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 44 | } |
| 45 | |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 46 | return false; |
| 47 | } |
| 48 | |
Markus Armbruster | ef834aa | 2024-09-04 13:18:28 +0200 | [diff] [blame] | 49 | void *qcrypto_hmac_ctx_new(QCryptoHashAlgo alg, |
Longpeng(Mike) | 14a5a2a | 2017-07-14 14:04:04 -0400 | [diff] [blame] | 50 | const uint8_t *key, size_t nkey, |
| 51 | Error **errp) |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 52 | { |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 53 | QCryptoHmacGcrypt *ctx; |
| 54 | gcry_error_t err; |
| 55 | |
| 56 | if (!qcrypto_hmac_supports(alg)) { |
| 57 | error_setg(errp, "Unsupported hmac algorithm %s", |
Markus Armbruster | ef834aa | 2024-09-04 13:18:28 +0200 | [diff] [blame] | 58 | QCryptoHashAlgo_str(alg)); |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 59 | return NULL; |
| 60 | } |
| 61 | |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 62 | ctx = g_new0(QCryptoHmacGcrypt, 1); |
| 63 | |
| 64 | err = gcry_mac_open(&ctx->handle, qcrypto_hmac_alg_map[alg], |
| 65 | GCRY_MAC_FLAG_SECURE, NULL); |
| 66 | if (err != 0) { |
| 67 | error_setg(errp, "Cannot initialize hmac: %s", |
| 68 | gcry_strerror(err)); |
| 69 | goto error; |
| 70 | } |
| 71 | |
| 72 | err = gcry_mac_setkey(ctx->handle, (const void *)key, nkey); |
| 73 | if (err != 0) { |
| 74 | error_setg(errp, "Cannot set key: %s", |
| 75 | gcry_strerror(err)); |
Longpeng(Mike) | 822d15d | 2017-07-14 14:04:01 -0400 | [diff] [blame] | 76 | gcry_mac_close(ctx->handle); |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 77 | goto error; |
| 78 | } |
| 79 | |
Longpeng(Mike) | 822d15d | 2017-07-14 14:04:01 -0400 | [diff] [blame] | 80 | return ctx; |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 81 | |
| 82 | error: |
| 83 | g_free(ctx); |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 84 | return NULL; |
| 85 | } |
| 86 | |
Longpeng(Mike) | 14a5a2a | 2017-07-14 14:04:04 -0400 | [diff] [blame] | 87 | static void |
| 88 | qcrypto_gcrypt_hmac_ctx_free(QCryptoHmac *hmac) |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 89 | { |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 90 | QCryptoHmacGcrypt *ctx; |
| 91 | |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 92 | ctx = hmac->opaque; |
| 93 | gcry_mac_close(ctx->handle); |
| 94 | |
| 95 | g_free(ctx); |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 96 | } |
| 97 | |
Longpeng(Mike) | 14a5a2a | 2017-07-14 14:04:04 -0400 | [diff] [blame] | 98 | static int |
| 99 | qcrypto_gcrypt_hmac_bytesv(QCryptoHmac *hmac, |
| 100 | const struct iovec *iov, |
| 101 | size_t niov, |
| 102 | uint8_t **result, |
| 103 | size_t *resultlen, |
| 104 | Error **errp) |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 105 | { |
Longpeng(Mike) | 5ce9cfe | 2016-12-13 18:42:57 +0800 | [diff] [blame] | 106 | QCryptoHmacGcrypt *ctx; |
| 107 | gcry_error_t err; |
| 108 | uint32_t ret; |
| 109 | int i; |
| 110 | |
| 111 | ctx = hmac->opaque; |
| 112 | |
| 113 | for (i = 0; i < niov; i++) { |
| 114 | gcry_mac_write(ctx->handle, iov[i].iov_base, iov[i].iov_len); |
| 115 | } |
| 116 | |
| 117 | ret = gcry_mac_get_algo_maclen(qcrypto_hmac_alg_map[hmac->alg]); |
| 118 | if (ret <= 0) { |
| 119 | error_setg(errp, "Unable to get hmac length: %s", |
| 120 | gcry_strerror(ret)); |
| 121 | return -1; |
| 122 | } |
| 123 | |
| 124 | if (*resultlen == 0) { |
| 125 | *resultlen = ret; |
| 126 | *result = g_new0(uint8_t, *resultlen); |
| 127 | } else if (*resultlen != ret) { |
| 128 | error_setg(errp, "Result buffer size %zu is smaller than hmac %d", |
| 129 | *resultlen, ret); |
| 130 | return -1; |
| 131 | } |
| 132 | |
| 133 | err = gcry_mac_read(ctx->handle, *result, resultlen); |
| 134 | if (err != 0) { |
| 135 | error_setg(errp, "Cannot get result: %s", |
| 136 | gcry_strerror(err)); |
| 137 | return -1; |
| 138 | } |
| 139 | |
| 140 | err = gcry_mac_reset(ctx->handle); |
| 141 | if (err != 0) { |
| 142 | error_setg(errp, "Cannot reset hmac context: %s", |
| 143 | gcry_strerror(err)); |
| 144 | return -1; |
| 145 | } |
| 146 | |
| 147 | return 0; |
Longpeng(Mike) | 12a4f21 | 2016-12-13 18:42:56 +0800 | [diff] [blame] | 148 | } |
Longpeng(Mike) | 822d15d | 2017-07-14 14:04:01 -0400 | [diff] [blame] | 149 | |
Longpeng(Mike) | 14a5a2a | 2017-07-14 14:04:04 -0400 | [diff] [blame] | 150 | QCryptoHmacDriver qcrypto_hmac_lib_driver = { |
| 151 | .hmac_bytesv = qcrypto_gcrypt_hmac_bytesv, |
| 152 | .hmac_free = qcrypto_gcrypt_hmac_ctx_free, |
| 153 | }; |