Coverage Report

Created: 2025-11-11 06:20

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/openssl/providers/implementations/signature/slh_dsa_sig.c
Line
Count
Source
1
/*
2
 * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <openssl/core_names.h>
11
#include <openssl/err.h>
12
#include <openssl/rand.h>
13
#include <openssl/proverr.h>
14
#include <openssl/self_test.h>
15
#include "prov/implementations.h"
16
#include "prov/providercommon.h"
17
#include "prov/provider_ctx.h"
18
#include "prov/der_slh_dsa.h"
19
#include "crypto/slh_dsa.h"
20
#include "internal/cryptlib.h"
21
#include "internal/sizes.h"
22
#include "internal/fips.h"
23
#include "providers/implementations/signature/slh_dsa_sig.inc"
24
25
#define SLH_DSA_MAX_ADD_RANDOM_LEN 32
26
27
#define SLH_DSA_MESSAGE_ENCODE_RAW  0
28
0
#define SLH_DSA_MESSAGE_ENCODE_PURE 1
29
30
static OSSL_FUNC_signature_sign_message_init_fn slh_dsa_sign_msg_init;
31
static OSSL_FUNC_signature_sign_fn slh_dsa_sign;
32
static OSSL_FUNC_signature_verify_message_init_fn slh_dsa_verify_msg_init;
33
static OSSL_FUNC_signature_verify_fn slh_dsa_verify;
34
static OSSL_FUNC_signature_digest_sign_init_fn slh_dsa_digest_signverify_init;
35
static OSSL_FUNC_signature_digest_sign_fn slh_dsa_digest_sign;
36
static OSSL_FUNC_signature_digest_verify_fn slh_dsa_digest_verify;
37
static OSSL_FUNC_signature_freectx_fn slh_dsa_freectx;
38
static OSSL_FUNC_signature_dupctx_fn slh_dsa_dupctx;
39
static OSSL_FUNC_signature_set_ctx_params_fn slh_dsa_set_ctx_params;
40
static OSSL_FUNC_signature_settable_ctx_params_fn slh_dsa_settable_ctx_params;
41
42
#ifdef FIPS_MODULE
43
static FIPS_DEFERRED_TEST slh_sig_deferred_tests[] = {
44
    {
45
        "SLH-DSA-SHA2-128f",
46
        FIPS_DEFERRED_KAT_SIGNATURE,
47
        FIPS_DEFERRED_TEST_INIT
48
    },
49
    {
50
        "SLH-DSA-SHAKE-128f",
51
        FIPS_DEFERRED_KAT_SIGNATURE,
52
        FIPS_DEFERRED_TEST_INIT
53
    },
54
    { NULL, 0, 0 },
55
};
56
#endif
57
58
static int slh_dsa_self_check(OSSL_LIB_CTX *libctx)
59
0
{
60
0
    if (!ossl_prov_is_running())
61
0
        return 0;
62
63
#ifdef FIPS_MODULE
64
    return FIPS_deferred_self_tests(libctx, slh_sig_deferred_tests);
65
#else
66
0
    return 1;
67
0
#endif
68
0
}
69
70
/*
71
 * NOTE: Any changes to this structure may require updating slh_dsa_dupctx().
72
 */
73
typedef struct {
74
    SLH_DSA_KEY *key; /* Note that the key is not owned by this object */
75
    SLH_DSA_HASH_CTX *hash_ctx;
76
    uint8_t context_string[SLH_DSA_MAX_CONTEXT_STRING_LEN];
77
    size_t context_string_len;
78
    uint8_t add_random[SLH_DSA_MAX_ADD_RANDOM_LEN];
79
    size_t add_random_len;
80
    int msg_encode;
81
    int deterministic;
82
    OSSL_LIB_CTX *libctx;
83
    char *propq;
84
    const char *alg;
85
    /* The Algorithm Identifier of the signature algorithm */
86
    uint8_t aid_buf[OSSL_MAX_ALGORITHM_ID_SIZE];
87
    size_t  aid_len;
88
} PROV_SLH_DSA_CTX;
89
90
static void slh_dsa_freectx(void *vctx)
91
0
{
92
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
93
94
0
    ossl_slh_dsa_hash_ctx_free(ctx->hash_ctx);
95
0
    OPENSSL_free(ctx->propq);
96
0
    OPENSSL_cleanse(ctx->add_random, ctx->add_random_len);
97
0
    OPENSSL_free(ctx);
98
0
}
99
100
static void *slh_dsa_newctx(void *provctx, const char *alg, const char *propq)
101
0
{
102
0
    PROV_SLH_DSA_CTX *ctx;
103
104
0
    if (!slh_dsa_self_check(PROV_LIBCTX_OF(provctx)))
105
0
        return NULL;
106
107
0
    ctx = OPENSSL_zalloc(sizeof(PROV_SLH_DSA_CTX));
108
0
    if (ctx == NULL)
109
0
        return NULL;
110
111
0
    ctx->libctx = PROV_LIBCTX_OF(provctx);
112
0
    if (propq != NULL && (ctx->propq = OPENSSL_strdup(propq)) == NULL)
113
0
        goto err;
114
0
    ctx->alg = alg;
115
0
    ctx->msg_encode = SLH_DSA_MESSAGE_ENCODE_PURE;
116
0
    return ctx;
117
0
 err:
118
0
    slh_dsa_freectx(ctx);
119
0
    return NULL;
120
0
}
121
122
static void *slh_dsa_dupctx(void *vctx)
123
0
{
124
0
    PROV_SLH_DSA_CTX *src = (PROV_SLH_DSA_CTX *)vctx;
125
0
    PROV_SLH_DSA_CTX *ret;
126
127
0
    if (!ossl_prov_is_running())
128
0
        return NULL;
129
130
    /*
131
     * Note that the SLH_DSA_KEY is ref counted via EVP_PKEY so we can just copy
132
     * the key here.
133
     */
134
0
    ret = OPENSSL_memdup(src, sizeof(*src));
135
0
    if (ret == NULL)
136
0
        return NULL;
137
0
    ret->propq = NULL;
138
0
    ret->hash_ctx = NULL;
139
0
    if (src->propq != NULL && (ret->propq = OPENSSL_strdup(src->propq)) == NULL)
140
0
        goto err;
141
0
    ret->hash_ctx = ossl_slh_dsa_hash_ctx_dup(src->hash_ctx);
142
0
    if (ret->hash_ctx == NULL)
143
0
        goto err;
144
145
0
    return ret;
146
0
 err:
147
0
    slh_dsa_freectx(ret);
148
0
    return NULL;
149
0
}
150
151
static int slh_dsa_set_alg_id_buffer(PROV_SLH_DSA_CTX *ctx)
152
0
{
153
0
    int ret;
154
0
    WPACKET pkt;
155
0
    uint8_t *aid = NULL;
156
157
    /*
158
     * We do not care about DER writing errors.
159
     * All it really means is that for some reason, there's no
160
     * AlgorithmIdentifier to be had, but the operation itself is
161
     * still valid, just as long as it's not used to construct
162
     * anything that needs an AlgorithmIdentifier.
163
     */
164
0
    ctx->aid_len = 0;
165
0
    ret = WPACKET_init_der(&pkt, ctx->aid_buf, sizeof(ctx->aid_buf));
166
0
    ret = ret && ossl_DER_w_algorithmIdentifier_SLH_DSA(&pkt, -1, ctx->key);
167
0
    if (ret && WPACKET_finish(&pkt)) {
168
0
        WPACKET_get_total_written(&pkt, &ctx->aid_len);
169
0
        aid = WPACKET_get_curr(&pkt);
170
0
    }
171
0
    WPACKET_cleanup(&pkt);
172
0
    if (aid != NULL && ctx->aid_len != 0)
173
0
        memmove(ctx->aid_buf, aid, ctx->aid_len);
174
0
    return 1;
175
0
}
176
177
static int slh_dsa_signverify_msg_init(void *vctx, void *vkey,
178
                                       const OSSL_PARAM params[], int operation,
179
                                       const char *desc)
180
0
{
181
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
182
0
    SLH_DSA_KEY *key = vkey;
183
184
0
    if (!ossl_prov_is_running()
185
0
            || ctx == NULL)
186
0
        return 0;
187
188
0
    if (vkey == NULL && ctx->key == NULL) {
189
0
        ERR_raise(ERR_LIB_PROV, PROV_R_NO_KEY_SET);
190
0
        return 0;
191
0
    }
192
193
0
    if (key != NULL) {
194
0
        if (!ossl_slh_dsa_key_type_matches(key, ctx->alg))
195
0
            return 0;
196
0
        ctx->hash_ctx = ossl_slh_dsa_hash_ctx_new(key);
197
0
        if (ctx->hash_ctx == NULL)
198
0
            return 0;
199
0
        ctx->key = vkey;
200
0
    }
201
202
0
    slh_dsa_set_alg_id_buffer(ctx);
203
0
    if (!slh_dsa_set_ctx_params(ctx, params))
204
0
        return 0;
205
0
    return 1;
206
0
}
207
208
static int slh_dsa_sign_msg_init(void *vctx, void *vkey, const OSSL_PARAM params[])
209
0
{
210
0
    return slh_dsa_signverify_msg_init(vctx, vkey, params,
211
0
                                       EVP_PKEY_OP_SIGN, "SLH_DSA Sign Init");
212
0
}
213
214
static int slh_dsa_digest_signverify_init(void *vctx, const char *mdname,
215
                                          void *vkey, const OSSL_PARAM params[])
216
0
{
217
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
218
219
0
    if (mdname != NULL && mdname[0] != '\0') {
220
0
        ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_DIGEST,
221
0
                       "Explicit digest not supported for SLH-DSA operations");
222
0
        return 0;
223
0
    }
224
225
0
    if (vkey == NULL && ctx->key != NULL)
226
0
        return slh_dsa_set_ctx_params(ctx, params);
227
228
0
    return slh_dsa_signverify_msg_init(vctx, vkey, params,
229
0
                                       EVP_PKEY_OP_SIGN, "SLH_DSA Sign Init");
230
0
}
231
232
static int slh_dsa_sign(void *vctx, unsigned char *sig, size_t *siglen,
233
                        size_t sigsize, const unsigned char *msg, size_t msg_len)
234
0
{
235
0
    int ret = 0;
236
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
237
0
    uint8_t add_rand[SLH_DSA_MAX_ADD_RANDOM_LEN], *opt_rand = NULL;
238
0
    size_t n = 0;
239
240
0
    if (!ossl_prov_is_running())
241
0
        return 0;
242
243
0
    if (sig != NULL) {
244
0
        if (ctx->add_random_len != 0) {
245
0
            opt_rand = ctx->add_random;
246
0
        } else if (ctx->deterministic == 0) {
247
0
            n = ossl_slh_dsa_key_get_n(ctx->key);
248
0
            if (RAND_priv_bytes_ex(ctx->libctx, add_rand, n, 0) <= 0)
249
0
                return 0;
250
0
            opt_rand = add_rand;
251
0
        }
252
0
    }
253
0
    ret = ossl_slh_dsa_sign(ctx->hash_ctx, msg, msg_len,
254
0
                            ctx->context_string, ctx->context_string_len,
255
0
                            opt_rand, ctx->msg_encode,
256
0
                            sig, siglen, sigsize);
257
0
    if (opt_rand != add_rand)
258
0
        OPENSSL_cleanse(opt_rand, n);
259
0
    return ret;
260
0
}
261
262
static int slh_dsa_digest_sign(void *vctx, uint8_t *sig, size_t *siglen, size_t sigsize,
263
                               const uint8_t *tbs, size_t tbslen)
264
0
{
265
0
    return slh_dsa_sign(vctx, sig, siglen, sigsize, tbs, tbslen);
266
0
}
267
268
static int slh_dsa_verify_msg_init(void *vctx, void *vkey, const OSSL_PARAM params[])
269
0
{
270
0
    return slh_dsa_signverify_msg_init(vctx, vkey, params, EVP_PKEY_OP_VERIFY,
271
0
                                       "SLH_DSA Verify Init");
272
0
}
273
274
static int slh_dsa_verify(void *vctx, const uint8_t *sig, size_t siglen,
275
                          const uint8_t *msg, size_t msg_len)
276
0
{
277
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
278
279
0
    if (!ossl_prov_is_running())
280
0
        return 0;
281
0
    return ossl_slh_dsa_verify(ctx->hash_ctx, msg, msg_len,
282
0
                               ctx->context_string, ctx->context_string_len,
283
0
                               ctx->msg_encode, sig, siglen);
284
0
}
285
static int slh_dsa_digest_verify(void *vctx, const uint8_t *sig, size_t siglen,
286
                                 const uint8_t *tbs, size_t tbslen)
287
0
{
288
0
    return slh_dsa_verify(vctx, sig, siglen, tbs, tbslen);
289
0
}
290
291
static int slh_dsa_set_ctx_params(void *vctx, const OSSL_PARAM params[])
292
0
{
293
0
    PROV_SLH_DSA_CTX *pctx = (PROV_SLH_DSA_CTX *)vctx;
294
0
    struct slh_dsa_set_ctx_params_st p;
295
296
0
    if (pctx == NULL || !slh_dsa_set_ctx_params_decoder(params, &p))
297
0
        return 0;
298
299
0
    if (p.context != NULL) {
300
0
        void *vp = pctx->context_string;
301
302
0
        if (!OSSL_PARAM_get_octet_string(p.context, &vp,
303
0
                                         sizeof(pctx->context_string),
304
0
                                         &(pctx->context_string_len))) {
305
0
            pctx->context_string_len = 0;
306
0
            return 0;
307
0
        }
308
0
    }
309
310
0
    if (p.entropy != NULL) {
311
0
        void *vp = pctx->add_random;
312
0
        size_t n = ossl_slh_dsa_key_get_n(pctx->key);
313
314
0
        if (!OSSL_PARAM_get_octet_string(p.entropy, &vp, n, &(pctx->add_random_len))
315
0
                || pctx->add_random_len != n) {
316
0
            pctx->add_random_len = 0;
317
0
            return 0;
318
0
        }
319
0
    }
320
321
0
    if (p.det != NULL && !OSSL_PARAM_get_int(p.det, &pctx->deterministic))
322
0
        return 0;
323
324
0
    if (p.msgenc != NULL && !OSSL_PARAM_get_int(p.msgenc, &pctx->msg_encode))
325
0
        return 0;
326
0
    return 1;
327
0
}
328
329
static const OSSL_PARAM *slh_dsa_settable_ctx_params(void *vctx,
330
                                                     ossl_unused void *provctx)
331
0
{
332
0
    return slh_dsa_set_ctx_params_list;
333
0
}
334
335
static const OSSL_PARAM *slh_dsa_gettable_ctx_params(ossl_unused void *vctx,
336
                                                     ossl_unused void *provctx)
337
0
{
338
0
    return slh_dsa_get_ctx_params_list;
339
0
}
340
341
static int slh_dsa_get_ctx_params(void *vctx, OSSL_PARAM *params)
342
0
{
343
0
    PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;
344
0
    struct slh_dsa_get_ctx_params_st p;
345
346
0
    if (ctx == NULL || !slh_dsa_get_ctx_params_decoder(params, &p))
347
0
        return 0;
348
349
0
    if (p.algid != NULL
350
0
        && !OSSL_PARAM_set_octet_string(p.algid,
351
0
                                        ctx->aid_len == 0 ? NULL : ctx->aid_buf,
352
0
                                        ctx->aid_len))
353
0
        return 0;
354
355
0
    return 1;
356
0
}
357
358
#define MAKE_SIGNATURE_FUNCTIONS(alg, fn)                                      \
359
    static OSSL_FUNC_signature_newctx_fn slh_dsa_##fn##_newctx;                \
360
    static void *slh_dsa_##fn##_newctx(void *provctx, const char *propq)       \
361
0
    {                                                                          \
362
0
        return slh_dsa_newctx(provctx, alg, propq);                            \
363
0
    }                                                                          \
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_128s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_128f_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_192s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_192f_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_256s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_sha2_256f_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_128s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_128f_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_192s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_192f_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_256s_newctx
Unexecuted instantiation: slh_dsa_sig.c:slh_dsa_shake_256f_newctx
364
    const OSSL_DISPATCH ossl_slh_dsa_##fn##_signature_functions[] = {          \
365
        { OSSL_FUNC_SIGNATURE_NEWCTX, (void (*)(void))slh_dsa_##fn##_newctx }, \
366
        { OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_INIT,                               \
367
          (void (*)(void))slh_dsa_sign_msg_init },                             \
368
        { OSSL_FUNC_SIGNATURE_SIGN, (void (*)(void))slh_dsa_sign },            \
369
        { OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_INIT,                             \
370
          (void (*)(void))slh_dsa_verify_msg_init },                           \
371
        { OSSL_FUNC_SIGNATURE_VERIFY, (void (*)(void))slh_dsa_verify },        \
372
        { OSSL_FUNC_SIGNATURE_DIGEST_SIGN_INIT,                                \
373
          (void (*)(void))slh_dsa_digest_signverify_init },                    \
374
        { OSSL_FUNC_SIGNATURE_DIGEST_SIGN,                                     \
375
          (void (*)(void))slh_dsa_digest_sign },                               \
376
        { OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_INIT,                              \
377
          (void (*)(void))slh_dsa_digest_signverify_init },                    \
378
        { OSSL_FUNC_SIGNATURE_DIGEST_VERIFY,                                   \
379
          (void (*)(void))slh_dsa_digest_verify },                             \
380
        { OSSL_FUNC_SIGNATURE_FREECTX, (void (*)(void))slh_dsa_freectx },      \
381
        { OSSL_FUNC_SIGNATURE_DUPCTX, (void (*)(void))slh_dsa_dupctx },        \
382
        { OSSL_FUNC_SIGNATURE_SET_CTX_PARAMS, (void (*)(void))slh_dsa_set_ctx_params },\
383
        { OSSL_FUNC_SIGNATURE_SETTABLE_CTX_PARAMS,                             \
384
          (void (*)(void))slh_dsa_settable_ctx_params },                       \
385
        { OSSL_FUNC_SIGNATURE_GET_CTX_PARAMS,                                  \
386
          (void (*)(void))slh_dsa_get_ctx_params },                            \
387
        { OSSL_FUNC_SIGNATURE_GETTABLE_CTX_PARAMS,                             \
388
          (void (*)(void))slh_dsa_gettable_ctx_params },                       \
389
        OSSL_DISPATCH_END                                                      \
390
    }
391
392
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-128s", sha2_128s);
393
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-128f", sha2_128f);
394
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-192s", sha2_192s);
395
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-192f", sha2_192f);
396
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-256s", sha2_256s);
397
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHA2-256f", sha2_256f);
398
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-128s", shake_128s);
399
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-128f", shake_128f);
400
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-192s", shake_192s);
401
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-192f", shake_192f);
402
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-256s", shake_256s);
403
MAKE_SIGNATURE_FUNCTIONS("SLH-DSA-SHAKE-256f", shake_256f);