Coverage Report

Created: 2026-09-04 06:51

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/openssl/include/crypto/md32_common.inc
Line
Count
Source
1
/*
2
 * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
/*-
11
 * This is a generic 32 bit "collector" for message digest algorithms.
12
 * Whenever needed it collects input character stream into chunks of
13
 * 32 bit values and invokes a block function that performs actual hash
14
 * calculations.
15
 *
16
 * Porting guide.
17
 *
18
 * Obligatory macros:
19
 *
20
 * DATA_ORDER_IS_BIG_ENDIAN or DATA_ORDER_IS_LITTLE_ENDIAN
21
 *      this macro defines byte order of input stream.
22
 * HASH_CBLOCK
23
 *      size of a unit chunk HASH_BLOCK operates on.
24
 * HASH_LONG
25
 *      has to be at least 32 bit wide.
26
 * HASH_CTX
27
 *      context structure that at least contains following
28
 *      members:
29
 *              typedef struct {
30
 *                      ...
31
 *                      HASH_LONG       Nl,Nh;
32
 *                      either {
33
 *                      HASH_LONG       data[HASH_LBLOCK];
34
 *                      unsigned char   data[HASH_CBLOCK];
35
 *                      };
36
 *                      unsigned int    num;
37
 *                      ...
38
 *                      } HASH_CTX;
39
 *      data[] vector is expected to be zeroed upon first call to
40
 *      HASH_UPDATE.
41
 * HASH_UPDATE
42
 *      name of "Update" function, implemented here.
43
 * HASH_TRANSFORM
44
 *      name of "Transform" function, implemented here.
45
 * HASH_FINAL
46
 *      name of "Final" function, implemented here.
47
 * HASH_BLOCK_DATA_ORDER
48
 *      name of "block" function capable of treating *unaligned* input
49
 *      message in original (data) byte order, implemented externally.
50
 * HASH_MAKE_STRING
51
 *      macro converting context variables to an ASCII hash string.
52
 *
53
 * MD5 example:
54
 *
55
 *      #define DATA_ORDER_IS_LITTLE_ENDIAN
56
 *
57
 *      #define HASH_LONG               MD5_LONG
58
 *      #define HASH_CTX                MD5_CTX
59
 *      #define HASH_CBLOCK             MD5_CBLOCK
60
 *      #define HASH_UPDATE             MD5_Update
61
 *      #define HASH_TRANSFORM          MD5_Transform
62
 *      #define HASH_FINAL              MD5_Final
63
 *      #define HASH_BLOCK_DATA_ORDER   md5_block_data_order
64
 */
65
66
#ifndef OSSL_CRYPTO_MD32_COMMON_H
67
#define OSSL_CRYPTO_MD32_COMMON_H
68
#pragma once
69
70
#include <openssl/crypto.h>
71
/*
72
 * For ossl_(un)likely
73
 */
74
#include <internal/common.h>
75
76
#if !defined(DATA_ORDER_IS_BIG_ENDIAN) && !defined(DATA_ORDER_IS_LITTLE_ENDIAN)
77
#error "DATA_ORDER must be defined!"
78
#endif
79
80
#ifndef HASH_CBLOCK
81
#error "HASH_CBLOCK must be defined!"
82
#endif
83
#ifndef HASH_LONG
84
#error "HASH_LONG must be defined!"
85
#endif
86
#ifndef HASH_CTX
87
#error "HASH_CTX must be defined!"
88
#endif
89
90
#ifndef HASH_UPDATE
91
#error "HASH_UPDATE must be defined!"
92
#endif
93
#ifndef HASH_TRANSFORM
94
#error "HASH_TRANSFORM must be defined!"
95
#endif
96
#ifndef HASH_FINAL
97
#error "HASH_FINAL must be defined!"
98
#endif
99
100
#ifndef HASH_BLOCK_DATA_ORDER
101
#error "HASH_BLOCK_DATA_ORDER must be defined!"
102
#endif
103
104
6.41G
#define ROTATE(a, n) (((a) << (n)) | (((a) & 0xffffffff) >> (32 - (n))))
105
106
#ifndef PEDANTIC
107
#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
108
#if defined(__riscv_zbb) || defined(__riscv_zbkb)
109
#if __riscv_xlen == 64
110
#undef ROTATE
111
#define ROTATE(x, n) ({ MD32_REG_T ret;            \
112
                       asm ("roriw %0, %1, %2"        \
113
                       : "=r"(ret)                    \
114
                       : "r"(x), "i"(32 - (n))); ret; })
115
#endif
116
#if __riscv_xlen == 32
117
#undef ROTATE
118
#define ROTATE(x, n) ({ MD32_REG_T ret;            \
119
                       asm ("rori %0, %1, %2"         \
120
                       : "=r"(ret)                    \
121
                       : "r"(x), "i"(32 - (n))); ret; })
122
#endif
123
#  elif defined(__e2k__)
124
#   undef ROTATE
125
#   define ROTATE(a,n)  ( (__builtin_constant_p(n) && (n) > 16) \
126
                          ? __builtin_e2k_scrs((a), 32 - (n))   \
127
                          : __builtin_e2k_scls((a),      (n))   )
128
#endif
129
#endif
130
#endif
131
132
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
133
134
192M
#define HOST_c2l(c, l) (l = (((unsigned long)(*((c)++))) << 24), \
135
192M
    l |= (((unsigned long)(*((c)++))) << 16),                    \
136
192M
    l |= (((unsigned long)(*((c)++))) << 8),                     \
137
192M
    l |= (((unsigned long)(*((c)++)))))
138
45.0k
#define HOST_l2c(l, c) (*((c)++) = (unsigned char)(((l) >> 24) & 0xff), \
139
45.0k
    *((c)++) = (unsigned char)(((l) >> 16) & 0xff),                     \
140
45.0k
    *((c)++) = (unsigned char)(((l) >> 8) & 0xff),                      \
141
45.0k
    *((c)++) = (unsigned char)(((l)) & 0xff),                           \
142
45.0k
    l)
143
144
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
145
146
82.4M
#define HOST_c2l(c, l) (l = (((unsigned long)(*((c)++)))), \
147
82.4M
    l |= (((unsigned long)(*((c)++))) << 8),               \
148
82.4M
    l |= (((unsigned long)(*((c)++))) << 16),              \
149
82.4M
    l |= (((unsigned long)(*((c)++))) << 24))
150
1.33k
#define HOST_l2c(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
151
1.33k
    *((c)++) = (unsigned char)(((l) >> 8) & 0xff),                \
152
1.33k
    *((c)++) = (unsigned char)(((l) >> 16) & 0xff),               \
153
1.33k
    *((c)++) = (unsigned char)(((l) >> 24) & 0xff),               \
154
1.33k
    l)
155
156
#endif
157
158
/*
159
 * Time for some action :-)
160
 */
161
162
#ifdef HASH_UPDATE_THUNK
163
int HASH_UPDATE(void *cp, const unsigned char *data_, size_t len);
164
int HASH_UPDATE(void *cp, const unsigned char *data_, size_t len)
165
#else
166
int HASH_UPDATE(HASH_CTX *c, const void *data_, size_t len)
167
#endif
168
9.53k
{
169
#ifdef HASH_UPDATE_THUNK
170
8.92k
    HASH_CTX *c = (HASH_CTX *)cp;
171
#endif
172
9.53k
    const unsigned char *data = data_;
173
9.53k
    unsigned char *p;
174
9.53k
    HASH_LONG l;
175
9.53k
    size_t n;
176
177
9.53k
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
9.53k
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
9.53k
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
9.53k
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
9.53k
    c->Nl = l;
186
187
9.53k
    n = c->num;
188
9.53k
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
9.53k
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
9.53k
    if (n > 0) {
220
        /* Process chunks */
221
9.53k
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
9.53k
        n *= HASH_CBLOCK;
223
9.53k
        data += n;
224
9.53k
        len -= n;
225
9.53k
    }
226
    /* Buffer any left over data */
227
9.53k
    if (len != 0) {
228
416
        p = (unsigned char *)c->data;
229
416
        c->num = (unsigned int)len;
230
416
        memcpy(p, data, len);
231
416
    }
232
9.53k
    return 1;
233
9.53k
}
MD4_Update
Line
Count
Source
168
120
{
169
#ifdef HASH_UPDATE_THUNK
170
    HASH_CTX *c = (HASH_CTX *)cp;
171
#endif
172
120
    const unsigned char *data = data_;
173
120
    unsigned char *p;
174
120
    HASH_LONG l;
175
120
    size_t n;
176
177
120
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
120
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
120
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
120
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
120
    c->Nl = l;
186
187
120
    n = c->num;
188
120
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
120
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
120
    if (n > 0) {
220
        /* Process chunks */
221
120
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
120
        n *= HASH_CBLOCK;
223
120
        data += n;
224
120
        len -= n;
225
120
    }
226
    /* Buffer any left over data */
227
120
    if (len != 0) {
228
49
        p = (unsigned char *)c->data;
229
49
        c->num = (unsigned int)len;
230
49
        memcpy(p, data, len);
231
49
    }
232
120
    return 1;
233
120
}
MD5_Update
Line
Count
Source
168
168
{
169
#ifdef HASH_UPDATE_THUNK
170
    HASH_CTX *c = (HASH_CTX *)cp;
171
#endif
172
168
    const unsigned char *data = data_;
173
168
    unsigned char *p;
174
168
    HASH_LONG l;
175
168
    size_t n;
176
177
168
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
168
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
168
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
168
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
168
    c->Nl = l;
186
187
168
    n = c->num;
188
168
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
168
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
168
    if (n > 0) {
220
        /* Process chunks */
221
168
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
168
        n *= HASH_CBLOCK;
223
168
        data += n;
224
168
        len -= n;
225
168
    }
226
    /* Buffer any left over data */
227
168
    if (len != 0) {
228
50
        p = (unsigned char *)c->data;
229
50
        c->num = (unsigned int)len;
230
50
        memcpy(p, data, len);
231
50
    }
232
168
    return 1;
233
168
}
RIPEMD160_Update
Line
Count
Source
168
134
{
169
#ifdef HASH_UPDATE_THUNK
170
    HASH_CTX *c = (HASH_CTX *)cp;
171
#endif
172
134
    const unsigned char *data = data_;
173
134
    unsigned char *p;
174
134
    HASH_LONG l;
175
134
    size_t n;
176
177
134
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
134
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
134
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
134
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
134
    c->Nl = l;
186
187
134
    n = c->num;
188
134
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
134
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
134
    if (n > 0) {
220
        /* Process chunks */
221
134
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
134
        n *= HASH_CBLOCK;
223
134
        data += n;
224
134
        len -= n;
225
134
    }
226
    /* Buffer any left over data */
227
134
    if (len != 0) {
228
58
        p = (unsigned char *)c->data;
229
58
        c->num = (unsigned int)len;
230
58
        memcpy(p, data, len);
231
58
    }
232
134
    return 1;
233
134
}
SHA1_Update_thunk
Line
Count
Source
168
222
{
169
222
#ifdef HASH_UPDATE_THUNK
170
222
    HASH_CTX *c = (HASH_CTX *)cp;
171
222
#endif
172
222
    const unsigned char *data = data_;
173
222
    unsigned char *p;
174
222
    HASH_LONG l;
175
222
    size_t n;
176
177
222
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
222
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
222
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
222
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
222
    c->Nl = l;
186
187
222
    n = c->num;
188
222
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
222
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
222
    if (n > 0) {
220
        /* Process chunks */
221
222
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
222
        n *= HASH_CBLOCK;
223
222
        data += n;
224
222
        len -= n;
225
222
    }
226
    /* Buffer any left over data */
227
222
    if (len != 0) {
228
74
        p = (unsigned char *)c->data;
229
74
        c->num = (unsigned int)len;
230
74
        memcpy(p, data, len);
231
74
    }
232
222
    return 1;
233
222
}
SHA256_Update_thunk
Line
Count
Source
168
8.70k
{
169
8.70k
#ifdef HASH_UPDATE_THUNK
170
8.70k
    HASH_CTX *c = (HASH_CTX *)cp;
171
8.70k
#endif
172
8.70k
    const unsigned char *data = data_;
173
8.70k
    unsigned char *p;
174
8.70k
    HASH_LONG l;
175
8.70k
    size_t n;
176
177
8.70k
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
8.70k
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
8.70k
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
8.70k
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
8.70k
    c->Nl = l;
186
187
8.70k
    n = c->num;
188
8.70k
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
8.70k
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
8.70k
    if (n > 0) {
220
        /* Process chunks */
221
8.70k
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
8.70k
        n *= HASH_CBLOCK;
223
8.70k
        data += n;
224
8.70k
        len -= n;
225
8.70k
    }
226
    /* Buffer any left over data */
227
8.70k
    if (len != 0) {
228
110
        p = (unsigned char *)c->data;
229
110
        c->num = (unsigned int)len;
230
110
        memcpy(p, data, len);
231
110
    }
232
8.70k
    return 1;
233
8.70k
}
ossl_sm3_update
Line
Count
Source
168
186
{
169
#ifdef HASH_UPDATE_THUNK
170
    HASH_CTX *c = (HASH_CTX *)cp;
171
#endif
172
186
    const unsigned char *data = data_;
173
186
    unsigned char *p;
174
186
    HASH_LONG l;
175
186
    size_t n;
176
177
186
    if (ossl_unlikely(len == 0))
178
0
        return 1;
179
180
186
    l = (c->Nl + (((HASH_LONG)len) << 3)) & 0xffffffffUL;
181
186
    if (ossl_unlikely(l < c->Nl)) /* overflow */
182
0
        c->Nh++;
183
186
    c->Nh += (HASH_LONG)(len >> 29); /* might cause compiler warning on
184
                                      * 16-bit */
185
186
    c->Nl = l;
186
187
186
    n = c->num;
188
186
    if (ossl_likely(n != 0)) {
189
        /* Gets here if we already have buffered input data */
190
0
        p = (unsigned char *)c->data;
191
192
0
        if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) {
193
            /*
194
             * If there is enough input to fill the buffer then fill the
195
             * buffer and process a single chunk.
196
             */
197
0
            memcpy(p + n, data, HASH_CBLOCK - n);
198
0
            HASH_BLOCK_DATA_ORDER(c, p, 1);
199
0
            n = HASH_CBLOCK - n;
200
0
            data += n;
201
0
            len -= n;
202
0
            c->num = 0;
203
            /*
204
             * We use memset rather than OPENSSL_cleanse() here deliberately.
205
             * Using OPENSSL_cleanse() here could be a performance issue. It
206
             * will get properly cleansed on finalisation so this isn't a
207
             * security problem.
208
             */
209
0
            memset(p, 0, HASH_CBLOCK); /* keep it zeroed */
210
0
        } else {
211
            /* Otherwise just keep filling the buffer */
212
0
            memcpy(p + n, data, len);
213
0
            c->num += (unsigned int)len;
214
0
            return 1;
215
0
        }
216
0
    }
217
218
186
    n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */
219
186
    if (n > 0) {
220
        /* Process chunks */
221
186
        HASH_BLOCK_DATA_ORDER(c, data, n);
222
186
        n *= HASH_CBLOCK;
223
186
        data += n;
224
186
        len -= n;
225
186
    }
226
    /* Buffer any left over data */
227
186
    if (len != 0) {
228
75
        p = (unsigned char *)c->data;
229
75
        c->num = (unsigned int)len;
230
75
        memcpy(p, data, len);
231
75
    }
232
186
    return 1;
233
186
}
234
235
void HASH_TRANSFORM(HASH_CTX *c, const unsigned char *data)
236
0
{
237
0
    HASH_BLOCK_DATA_ORDER(c, data, 1); /* Process a single chunk */
238
0
}
Unexecuted instantiation: MD4_Transform
Unexecuted instantiation: MD5_Transform
Unexecuted instantiation: RIPEMD160_Transform
Unexecuted instantiation: SHA1_Transform
Unexecuted instantiation: SHA256_Transform
Unexecuted instantiation: ossl_sm3_transform
239
240
int HASH_FINAL(unsigned char *md, HASH_CTX *c)
241
4.77k
{
242
4.77k
    unsigned char *p = (unsigned char *)c->data;
243
4.77k
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
4.77k
    p[n] = 0x80; /* there is always room for one */
250
4.77k
    n++;
251
252
4.77k
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
165
        memset(p + n, 0, HASH_CBLOCK - n);
258
165
        n = 0;
259
165
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
165
    }
261
    /* Add zero padding - but leave enough room for L */
262
4.77k
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
4.77k
    p += HASH_CBLOCK - 8;
266
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
4.56k
    (void)HOST_l2c(c->Nh, p);
268
4.56k
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
211
    (void)HOST_l2c(c->Nl, p);
271
211
    (void)HOST_l2c(c->Nh, p);
272
#endif
273
4.77k
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
4.77k
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
4.77k
    c->num = 0;
277
4.77k
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
4.77k
    HASH_MAKE_STRING(c, md);
283
4.35k
#endif
284
285
4.35k
    return 1;
286
4.77k
}
MD4_Final
Line
Count
Source
241
60
{
242
60
    unsigned char *p = (unsigned char *)c->data;
243
60
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
60
    p[n] = 0x80; /* there is always room for one */
250
60
    n++;
251
252
60
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
21
        memset(p + n, 0, HASH_CBLOCK - n);
258
21
        n = 0;
259
21
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
21
    }
261
    /* Add zero padding - but leave enough room for L */
262
60
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
60
    p += HASH_CBLOCK - 8;
266
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
    (void)HOST_l2c(c->Nh, p);
268
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
60
    (void)HOST_l2c(c->Nl, p);
271
60
    (void)HOST_l2c(c->Nh, p);
272
60
#endif
273
60
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
60
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
60
    c->num = 0;
277
60
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
60
    HASH_MAKE_STRING(c, md);
283
60
#endif
284
285
60
    return 1;
286
60
}
MD5_Final
Line
Count
Source
241
84
{
242
84
    unsigned char *p = (unsigned char *)c->data;
243
84
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
84
    p[n] = 0x80; /* there is always room for one */
250
84
    n++;
251
252
84
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
20
        memset(p + n, 0, HASH_CBLOCK - n);
258
20
        n = 0;
259
20
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
20
    }
261
    /* Add zero padding - but leave enough room for L */
262
84
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
84
    p += HASH_CBLOCK - 8;
266
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
    (void)HOST_l2c(c->Nh, p);
268
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
84
    (void)HOST_l2c(c->Nl, p);
271
84
    (void)HOST_l2c(c->Nh, p);
272
84
#endif
273
84
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
84
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
84
    c->num = 0;
277
84
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
84
    HASH_MAKE_STRING(c, md);
283
84
#endif
284
285
84
    return 1;
286
84
}
RIPEMD160_Final
Line
Count
Source
241
67
{
242
67
    unsigned char *p = (unsigned char *)c->data;
243
67
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
67
    p[n] = 0x80; /* there is always room for one */
250
67
    n++;
251
252
67
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
25
        memset(p + n, 0, HASH_CBLOCK - n);
258
25
        n = 0;
259
25
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
25
    }
261
    /* Add zero padding - but leave enough room for L */
262
67
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
67
    p += HASH_CBLOCK - 8;
266
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
    (void)HOST_l2c(c->Nh, p);
268
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
67
    (void)HOST_l2c(c->Nl, p);
271
67
    (void)HOST_l2c(c->Nh, p);
272
67
#endif
273
67
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
67
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
67
    c->num = 0;
277
67
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
67
    HASH_MAKE_STRING(c, md);
283
67
#endif
284
285
67
    return 1;
286
67
}
SHA1_Final
Line
Count
Source
241
111
{
242
111
    unsigned char *p = (unsigned char *)c->data;
243
111
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
111
    p[n] = 0x80; /* there is always room for one */
250
111
    n++;
251
252
111
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
26
        memset(p + n, 0, HASH_CBLOCK - n);
258
26
        n = 0;
259
26
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
26
    }
261
    /* Add zero padding - but leave enough room for L */
262
111
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
111
    p += HASH_CBLOCK - 8;
266
111
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
111
    (void)HOST_l2c(c->Nh, p);
268
111
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
    (void)HOST_l2c(c->Nl, p);
271
    (void)HOST_l2c(c->Nh, p);
272
#endif
273
111
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
111
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
111
    c->num = 0;
277
111
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
111
    HASH_MAKE_STRING(c, md);
283
111
#endif
284
285
111
    return 1;
286
111
}
SHA256_Final
Line
Count
Source
241
4.35k
{
242
4.35k
    unsigned char *p = (unsigned char *)c->data;
243
4.35k
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
4.35k
    p[n] = 0x80; /* there is always room for one */
250
4.35k
    n++;
251
252
4.35k
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
34
        memset(p + n, 0, HASH_CBLOCK - n);
258
34
        n = 0;
259
34
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
34
    }
261
    /* Add zero padding - but leave enough room for L */
262
4.35k
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
4.35k
    p += HASH_CBLOCK - 8;
266
4.35k
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
4.35k
    (void)HOST_l2c(c->Nh, p);
268
4.35k
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
    (void)HOST_l2c(c->Nl, p);
271
    (void)HOST_l2c(c->Nh, p);
272
#endif
273
4.35k
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
4.35k
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
4.35k
    c->num = 0;
277
4.35k
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
4.35k
    HASH_MAKE_STRING(c, md);
283
4.35k
#endif
284
285
4.35k
    return 1;
286
4.35k
}
ossl_sm3_final
Line
Count
Source
241
93
{
242
93
    unsigned char *p = (unsigned char *)c->data;
243
93
    size_t n = c->num;
244
245
    /*
246
     * Pad the input by adding a 1 bit + K zero bits + input length (L)
247
     * as a 64 bit value. K must align the data to a chunk boundary.
248
     */
249
93
    p[n] = 0x80; /* there is always room for one */
250
93
    n++;
251
252
93
    if (n > (HASH_CBLOCK - 8)) {
253
        /*
254
         * If there is not enough room in the buffer to add L, then fill the
255
         * current buffer with zeros, and process the chunk
256
         */
257
39
        memset(p + n, 0, HASH_CBLOCK - n);
258
39
        n = 0;
259
39
        HASH_BLOCK_DATA_ORDER(c, p, 1);
260
39
    }
261
    /* Add zero padding - but leave enough room for L */
262
93
    memset(p + n, 0, HASH_CBLOCK - 8 - n);
263
264
    /* Add the 64 bit L value to the end of the buffer */
265
93
    p += HASH_CBLOCK - 8;
266
93
#if defined(DATA_ORDER_IS_BIG_ENDIAN)
267
93
    (void)HOST_l2c(c->Nh, p);
268
93
    (void)HOST_l2c(c->Nl, p);
269
#elif defined(DATA_ORDER_IS_LITTLE_ENDIAN)
270
    (void)HOST_l2c(c->Nl, p);
271
    (void)HOST_l2c(c->Nh, p);
272
#endif
273
93
    p -= HASH_CBLOCK;
274
    /* Process the final padded chunk */
275
93
    HASH_BLOCK_DATA_ORDER(c, p, 1);
276
93
    c->num = 0;
277
93
    OPENSSL_cleanse(p, HASH_CBLOCK);
278
279
#ifndef HASH_MAKE_STRING
280
#error "HASH_MAKE_STRING must be defined!"
281
#else
282
93
    HASH_MAKE_STRING(c, md);
283
93
#endif
284
285
93
    return 1;
286
93
}
287
288
#ifndef MD32_REG_T
289
#if defined(__alpha) || defined(__sparcv9) || defined(__mips)
290
#define MD32_REG_T long
291
/*
292
 * This comment was originally written for MD5, which is why it
293
 * discusses A-D. But it basically applies to all 32-bit digests,
294
 * which is why it was moved to common header file.
295
 *
296
 * In case you wonder why A-D are declared as long and not
297
 * as MD5_LONG. Doing so results in slight performance
298
 * boost on LP64 architectures. The catch is we don't
299
 * really care if 32 MSBs of a 64-bit register get polluted
300
 * with eventual overflows as we *save* only 32 LSBs in
301
 * *either* case. Now declaring 'em long excuses the compiler
302
 * from keeping 32 MSBs zeroed resulting in 13% performance
303
 * improvement under SPARC Solaris7/64 and 5% under AlphaLinux.
304
 * Well, to be honest it should say that this *prevents*
305
 * performance degradation.
306
 */
307
#else
308
/*
309
 * Above is not absolute and there are LP64 compilers that
310
 * generate better code if MD32_REG_T is defined int. The above
311
 * pre-processor condition reflects the circumstances under which
312
 * the conclusion was made and is subject to further extension.
313
 */
314
#define MD32_REG_T int
315
#endif
316
#endif
317
318
#endif