Coverage Report

Created: 2025-03-09 06:52

/src/libressl/crypto/evp/m_sigver.c
Line
Count
Source (jump to first uncovered line)
1
/* $OpenBSD: m_sigver.c,v 1.27 2024/04/09 13:52:41 beck Exp $ */
2
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
3
 * project 2006.
4
 */
5
/* ====================================================================
6
 * Copyright (c) 2006,2007 The OpenSSL Project.  All rights reserved.
7
 *
8
 * Redistribution and use in source and binary forms, with or without
9
 * modification, are permitted provided that the following conditions
10
 * are met:
11
 *
12
 * 1. Redistributions of source code must retain the above copyright
13
 *    notice, this list of conditions and the following disclaimer.
14
 *
15
 * 2. Redistributions in binary form must reproduce the above copyright
16
 *    notice, this list of conditions and the following disclaimer in
17
 *    the documentation and/or other materials provided with the
18
 *    distribution.
19
 *
20
 * 3. All advertising materials mentioning features or use of this
21
 *    software must display the following acknowledgment:
22
 *    "This product includes software developed by the OpenSSL Project
23
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
24
 *
25
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26
 *    endorse or promote products derived from this software without
27
 *    prior written permission. For written permission, please contact
28
 *    licensing@OpenSSL.org.
29
 *
30
 * 5. Products derived from this software may not be called "OpenSSL"
31
 *    nor may "OpenSSL" appear in their names without prior written
32
 *    permission of the OpenSSL Project.
33
 *
34
 * 6. Redistributions of any form whatsoever must retain the following
35
 *    acknowledgment:
36
 *    "This product includes software developed by the OpenSSL Project
37
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
38
 *
39
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
43
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50
 * OF THE POSSIBILITY OF SUCH DAMAGE.
51
 * ====================================================================
52
 *
53
 * This product includes cryptographic software written by Eric Young
54
 * (eay@cryptsoft.com).  This product includes software written by Tim
55
 * Hudson (tjh@cryptsoft.com).
56
 *
57
 */
58
59
#include <stdio.h>
60
61
#include <openssl/err.h>
62
#include <openssl/evp.h>
63
#include <openssl/objects.h>
64
#include <openssl/x509.h>
65
66
#include "evp_local.h"
67
68
static int
69
update_oneshot_only(EVP_MD_CTX *ctx, const void *data, size_t datalen)
70
0
{
71
0
  EVPerror(EVP_R_ONLY_ONESHOT_SUPPORTED);
72
0
  return 0;
73
0
}
74
75
static int
76
do_sigver_init(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, const EVP_MD *type,
77
    EVP_PKEY *pkey, int ver)
78
16.8k
{
79
16.8k
  if (ctx->pctx == NULL)
80
6.96k
    ctx->pctx = EVP_PKEY_CTX_new(pkey, NULL);
81
16.8k
  if (ctx->pctx == NULL)
82
0
    return 0;
83
84
16.8k
  if (!(ctx->pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM)) {
85
16.8k
    if (type == NULL) {
86
0
      int def_nid;
87
0
      if (EVP_PKEY_get_default_digest_nid(pkey, &def_nid) > 0)
88
0
        type = EVP_get_digestbynid(def_nid);
89
0
    }
90
91
16.8k
    if (type == NULL) {
92
0
      EVPerror(EVP_R_NO_DEFAULT_DIGEST);
93
0
      return 0;
94
0
    }
95
16.8k
  }
96
97
16.8k
  if (ver) {
98
196
    if (ctx->pctx->pmeth->digestverify != NULL) {
99
0
      ctx->pctx->operation = EVP_PKEY_OP_VERIFY;
100
0
      ctx->update = update_oneshot_only;
101
196
    } else if (EVP_PKEY_verify_init(ctx->pctx) <= 0)
102
0
      return 0;
103
16.6k
  } else {
104
16.6k
    if (ctx->pctx->pmeth->signctx_init) {
105
15.2k
      if (ctx->pctx->pmeth->signctx_init(ctx->pctx, ctx) <= 0)
106
0
        return 0;
107
15.2k
      ctx->pctx->operation = EVP_PKEY_OP_SIGNCTX;
108
15.2k
    } else if (ctx->pctx->pmeth->digestsign != NULL) {
109
0
      ctx->pctx->operation = EVP_PKEY_OP_SIGN;
110
0
      ctx->update = update_oneshot_only;
111
1.46k
    } else if (EVP_PKEY_sign_init(ctx->pctx) <= 0)
112
0
      return 0;
113
16.6k
  }
114
16.8k
  if (EVP_PKEY_CTX_set_signature_md(ctx->pctx, type) <= 0)
115
0
    return 0;
116
16.8k
  if (pctx)
117
1.64k
    *pctx = ctx->pctx;
118
16.8k
  if (ctx->pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM)
119
0
    return 1;
120
16.8k
  if (!EVP_DigestInit_ex(ctx, type, NULL))
121
0
    return 0;
122
16.8k
  return 1;
123
16.8k
}
124
125
int
126
EVP_DigestSignInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, const EVP_MD *type,
127
    ENGINE *e, EVP_PKEY *pkey)
128
16.6k
{
129
16.6k
  return do_sigver_init(ctx, pctx, type, pkey, 0);
130
16.6k
}
131
LCRYPTO_ALIAS(EVP_DigestSignInit);
132
133
int
134
EVP_DigestVerifyInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, const EVP_MD *type,
135
    ENGINE *e, EVP_PKEY *pkey)
136
196
{
137
196
  return do_sigver_init(ctx, pctx, type, pkey, 1);
138
196
}
139
LCRYPTO_ALIAS(EVP_DigestVerifyInit);
140
141
static int
142
evp_digestsignfinal_sigctx_custom(EVP_MD_CTX *ctx, unsigned char *sigret,
143
    size_t *siglen)
144
0
{
145
0
  EVP_PKEY_CTX *pctx = ctx->pctx;
146
0
  EVP_PKEY_CTX *dctx = NULL;
147
0
  int ret = 0;
148
149
0
  if (sigret == NULL)
150
0
    return pctx->pmeth->signctx(pctx, sigret, siglen, ctx);
151
152
  /* XXX - support EVP_MD_CTX_FLAG_FINALISE? */
153
0
  if ((dctx = EVP_PKEY_CTX_dup(pctx)) == NULL)
154
0
    goto err;
155
156
0
  if (!dctx->pmeth->signctx(dctx, sigret, siglen, ctx))
157
0
    goto err;
158
159
0
  ret = 1;
160
161
0
 err:
162
0
  EVP_PKEY_CTX_free(dctx);
163
164
0
  return ret;
165
0
}
166
167
int
168
EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sigret, size_t *siglen)
169
19.1k
{
170
19.1k
  EVP_PKEY_CTX *pctx = ctx->pctx;
171
19.1k
  EVP_MD_CTX *md_ctx = NULL;
172
19.1k
  unsigned char md[EVP_MAX_MD_SIZE];
173
19.1k
  unsigned int mdlen = 0;
174
19.1k
  int s;
175
19.1k
  int ret = 0;
176
177
19.1k
  if (pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM)
178
0
    return evp_digestsignfinal_sigctx_custom(ctx, sigret, siglen);
179
180
19.1k
  if (sigret == NULL) {
181
2.41k
    if (ctx->pctx->pmeth->signctx != NULL) {
182
947
      if (ctx->pctx->pmeth->signctx(ctx->pctx, NULL,
183
947
          siglen, ctx) <= 0)
184
0
        return 0;
185
947
      return 1;
186
947
    }
187
188
1.46k
    if ((s = EVP_MD_size(ctx->digest)) < 0)
189
0
      return 0;
190
1.46k
    if (EVP_PKEY_sign(ctx->pctx, NULL, siglen, NULL, s) <= 0)
191
0
      return 0;
192
193
1.46k
    return 1;
194
1.46k
  }
195
196
  /* Use a copy since EVP_DigestFinal_ex() clears secrets. */
197
16.7k
  if ((md_ctx = EVP_MD_CTX_new()) == NULL)
198
0
    goto err;
199
16.7k
  if (!EVP_MD_CTX_copy_ex(md_ctx, ctx))
200
0
    goto err;
201
16.7k
  if (md_ctx->pctx->pmeth->signctx != NULL) {
202
15.2k
    if (md_ctx->pctx->pmeth->signctx(md_ctx->pctx,
203
15.2k
        sigret, siglen, md_ctx) <= 0)
204
0
      goto err;
205
15.2k
  } else {
206
1.46k
    if (!EVP_DigestFinal_ex(md_ctx, md, &mdlen))
207
0
      goto err;
208
    /* Use the original ctx since secrets were cleared. */
209
1.46k
    if (EVP_PKEY_sign(ctx->pctx, sigret, siglen, md, mdlen) <= 0)
210
0
      goto err;
211
1.46k
  }
212
213
16.7k
  ret = 1;
214
215
16.7k
 err:
216
16.7k
  EVP_MD_CTX_free(md_ctx);
217
218
16.7k
  return ret;
219
16.7k
}
220
LCRYPTO_ALIAS(EVP_DigestSignFinal);
221
222
int
223
EVP_DigestSign(EVP_MD_CTX *ctx, unsigned char *sigret, size_t *siglen,
224
    const unsigned char *tbs, size_t tbslen)
225
2.93k
{
226
2.93k
  if (ctx->pctx->pmeth->digestsign != NULL)
227
0
    return ctx->pctx->pmeth->digestsign(ctx, sigret, siglen,
228
0
        tbs, tbslen);
229
230
2.93k
  if (sigret != NULL) {
231
1.46k
    if (EVP_DigestSignUpdate(ctx, tbs, tbslen) <= 0)
232
0
      return 0;
233
1.46k
  }
234
235
2.93k
  return EVP_DigestSignFinal(ctx, sigret, siglen);
236
2.93k
}
237
LCRYPTO_ALIAS(EVP_DigestSign);
238
239
int
240
EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig, size_t siglen)
241
196
{
242
196
  EVP_MD_CTX tmp_ctx;
243
196
  unsigned char md[EVP_MAX_MD_SIZE];
244
196
  int r;
245
196
  unsigned int mdlen = 0;
246
247
196
  EVP_MD_CTX_legacy_clear(&tmp_ctx);
248
196
  if (!EVP_MD_CTX_copy_ex(&tmp_ctx, ctx))
249
0
    return -1;
250
196
  r = EVP_DigestFinal_ex(&tmp_ctx, md, &mdlen);
251
196
  EVP_MD_CTX_cleanup(&tmp_ctx);
252
196
  if (!r)
253
0
    return r;
254
196
  return EVP_PKEY_verify(ctx->pctx, sig, siglen, md, mdlen);
255
196
}
256
LCRYPTO_ALIAS(EVP_DigestVerifyFinal);
257
258
int
259
EVP_DigestVerify(EVP_MD_CTX *ctx, const unsigned char *sigret, size_t siglen,
260
    const unsigned char *tbs, size_t tbslen)
261
196
{
262
196
  if (ctx->pctx->pmeth->digestverify != NULL)
263
0
    return ctx->pctx->pmeth->digestverify(ctx, sigret, siglen,
264
0
        tbs, tbslen);
265
266
196
  if (EVP_DigestVerifyUpdate(ctx, tbs, tbslen) <= 0)
267
0
    return -1;
268
269
196
  return EVP_DigestVerifyFinal(ctx, sigret, siglen);
270
196
}
271
LCRYPTO_ALIAS(EVP_DigestVerify);