Coverage Report

Created: 2026-09-20 06:33

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wolfssl-normal-math/wolfcrypt/src/cryptocb.c
Line
Count
Source
1
/* cryptocb.c
2
 *
3
 * Copyright (C) 2006-2026 wolfSSL Inc.
4
 *
5
 * This file is part of wolfSSL.
6
 *
7
 * wolfSSL is free software; you can redistribute it and/or modify
8
 * it under the terms of the GNU General Public License as published by
9
 * the Free Software Foundation; either version 3 of the License, or
10
 * (at your option) any later version.
11
 *
12
 * wolfSSL is distributed in the hope that it will be useful,
13
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15
 * GNU General Public License for more details.
16
 *
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program; if not, write to the Free Software
19
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20
 */
21
22
/* This framework provides a central place for crypto hardware integration
23
   using the devId scheme. If not supported return `CRYPTOCB_UNAVAILABLE`. */
24
25
/*
26
Crypto Callback Build Options:
27
 * WOLF_CRYPTO_CB:      Master enable for crypto callback       default: off
28
 *                      framework. Required for all options below.
29
 * WOLF_CRYPTO_CB_FIND: Enable find device callback functions   default: off
30
 *                      Allows lookup of registered crypto devices.
31
 * WOLF_CRYPTO_CB_CMD:  Enable command callbacks invoked during default: off
32
 *                      register and unregister of crypto devices.
33
 * WOLF_CRYPTO_CB_COPY: Enable copy callback for algorithm      default: off
34
 *                      structures (hash, cipher state copying).
35
 * WOLF_CRYPTO_CB_FREE: Enable free callback for algorithm      default: off
36
 *                      structures (cleanup of crypto objects).
37
 * WOLF_CRYPTO_CB_AES_SETKEY: Enable callback for AES key setup default: off
38
 * WOLF_CRYPTO_CB_RSA_PAD: Enable callback for RSA padding      default: off
39
 *                      operations (custom padding handling).
40
 * DEBUG_CRYPTOCB:      Enable debug InfoString functions        default: off
41
 *
42
 * Device ID options:
43
 * WC_USE_DEVID:        Specify a default device ID to use      default: off
44
 *                      when no hardware device is detected.
45
 * WC_NO_DEFAULT_DEVID: Disable automatic default device ID     default: off
46
 *                      selection. Requires explicit devId passing.
47
 * WOLFSSL_CAAM_DEVID:  Device ID constant (value 7) for NXP    default: off
48
 *                      CAAM hardware crypto.
49
 *
50
 * Algorithm-specific callback options:
51
 * NO_SHA2_CRYPTO_CB:   Disable crypto callbacks for SHA-384    default: off
52
 *                      and SHA-512 operations.
53
 * WOLF_CRYPTO_CB_NO_SHA512_FALLBACK:                           default: off
54
 *                      Do not fall back to the generic SHA-512
55
 *                      callback for SHA-384, SHA-512/224 and
56
 *                      SHA-512/256 when no variant-specific
57
 *                      callback is registered. Required for
58
 *                      backends whose hash context has no
59
 *                      digest[] state field or that keep the
60
 *                      hash state on the device (auto-enabled
61
 *                      for Renesas FSPSM).
62
 * WOLF_CRYPTO_CB_ONLY_ECC: Use only callbacks for ECC          default: off
63
 * WOLF_CRYPTO_CB_ONLY_RSA: Use only callbacks for RSA          default: off
64
 * WOLF_CRYPTO_CB_ONLY_SHA256: Use only callbacks for SHA-256   default: off
65
 * WOLF_CRYPTO_CB_ONLY_SHA512: Use only callbacks for SHA-512   default: off
66
 * WOLF_CRYPTO_CB_ONLY_AES: Use only callbacks for AES          default: off
67
 * WOLF_CRYPTO_CB_ONLY_ED25519: Use only callbacks for Ed25519  default: off
68
 * WOLF_CRYPTO_CB_ONLY_CURVE25519: Use only callbacks for X25519 default: off
69
 */
70
71
#include <wolfssl/wolfcrypt/libwolfssl_sources.h>
72
73
#ifdef WOLF_CRYPTO_CB
74
75
#include <wolfssl/wolfcrypt/cryptocb.h>
76
77
#if defined(WOLFSSL_ASYNC_CRYPT) && !defined(WOLF_CRYPTO_CB_ASYNC_POLL) && \
78
    !defined(WOLFSSL_ASYNC_CRYPT_SW) && !defined(HAVE_INTEL_QA) && \
79
    !defined(HAVE_CAVIUM) && !defined(WOLF_CRYPTO_CB_ASYNC_NO_WARN)
80
    #warning "crypto callbacks with async crypt cannot complete TLS 1.2 \
81
record ciphers (TLS 1.3 resumes them by re-invoking the callback). Define \
82
WOLF_CRYPTO_CB_ASYNC_POLL to enable them, or WOLF_CRYPTO_CB_ASYNC_NO_WARN to \
83
silence."
84
#endif
85
86
#ifdef HAVE_ARIA
87
    #include <wolfssl/wolfcrypt/port/aria/aria-cryptocb.h>
88
#endif
89
90
#ifdef WOLFSSL_CAAM
91
    #include <wolfssl/wolfcrypt/port/caam/wolfcaam.h>
92
#endif
93
94
/* Fixed table, read without a lock on every offloaded operation. Lookups
95
 * match on devId, so an entry is filled before devId is stored and cleared
96
 * after devId is retired, with a WC_BARRIER() between the two so the
97
 * compiler cannot reorder them. Serializing register/unregister against each
98
 * other, and against operations already dispatched to that device, remains
99
 * the caller's job. */
100
101
typedef struct CryptoCb {
102
    int devId;
103
    CryptoDevCallbackFunc cb;
104
    void* ctx;
105
} CryptoCb;
106
static WC_THREADSHARED CryptoCb gCryptoDev[MAX_CRYPTO_DEVID_CALLBACKS];
107
108
#ifdef WOLF_CRYPTO_CB_FIND
109
static CryptoDevCallbackFind CryptoCb_FindCb = NULL;
110
#endif
111
112
#ifdef DEBUG_CRYPTOCB
113
static const char* GetAlgoTypeStr(int algo)
114
{
115
    switch (algo) { /* enum wc_AlgoType */
116
#ifdef WOLF_CRYPTO_CB_CMD
117
        case WC_ALGO_TYPE_NONE:   return "None-Command";
118
#endif
119
        case WC_ALGO_TYPE_HASH:   return "Hash";
120
        case WC_ALGO_TYPE_CIPHER: return "Cipher";
121
        case WC_ALGO_TYPE_PK:     return "PK";
122
        case WC_ALGO_TYPE_RNG:    return "RNG";
123
        case WC_ALGO_TYPE_SEED:   return "Seed";
124
        case WC_ALGO_TYPE_HMAC:   return "HMAC";
125
        case WC_ALGO_TYPE_CMAC:   return "CMAC";
126
        case WC_ALGO_TYPE_CERT:   return "Cert";
127
        case WC_ALGO_TYPE_KDF:    return "KDF";
128
#ifdef WOLF_CRYPTO_CB_COPY
129
        case WC_ALGO_TYPE_COPY:   return "Copy";
130
#endif /* WOLF_CRYPTO_CB_COPY */
131
#ifdef WOLF_CRYPTO_CB_FREE
132
        case WC_ALGO_TYPE_FREE:   return "Free";
133
#endif /* WOLF_CRYPTO_CB_FREE */
134
#ifdef WOLF_CRYPTO_CB_SETKEY
135
        case WC_ALGO_TYPE_SETKEY: return "SetKey";
136
#endif /* WOLF_CRYPTO_CB_SETKEY */
137
#ifdef WOLF_CRYPTO_CB_EXPORT_KEY
138
        case WC_ALGO_TYPE_EXPORT_KEY: return "ExportKey";
139
#endif /* WOLF_CRYPTO_CB_EXPORT_KEY */
140
#ifdef WOLF_CRYPTO_CB_KEYSTORE
141
        case WC_ALGO_TYPE_KEYSTORE: return "KeyStore";
142
#endif /* WOLF_CRYPTO_CB_KEYSTORE */
143
    }
144
    return NULL;
145
}
146
#ifdef WOLF_CRYPTO_CB_SETKEY
147
static const char* GetSetKeyTypeStr(int type)
148
{
149
    switch (type) {
150
        case WC_SETKEY_NONE:      return "None";
151
        case WC_SETKEY_HMAC:      return "HMAC";
152
        case WC_SETKEY_RSA_PUB:   return "RSA-Pub";
153
        case WC_SETKEY_RSA_PRIV:  return "RSA-Priv";
154
        case WC_SETKEY_ECC_PUB:   return "ECC-Pub";
155
        case WC_SETKEY_ECC_PRIV:  return "ECC-Priv";
156
        case WC_SETKEY_AES:       return "AES";
157
        default:                  break;
158
    }
159
    return NULL;
160
}
161
#endif /* WOLF_CRYPTO_CB_SETKEY */
162
static const char* GetPkTypeStr(int pk)
163
{
164
    switch (pk) {
165
        case WC_PK_TYPE_RSA: return "RSA";
166
        case WC_PK_TYPE_RSA_PSS_VERIFY: return "RSA-PSS-Verify";
167
        case WC_PK_TYPE_DH: return "DH";
168
        case WC_PK_TYPE_ECDH: return "ECDH";
169
        case WC_PK_TYPE_ECDSA_SIGN: return "ECDSA-Sign";
170
        case WC_PK_TYPE_ECDSA_VERIFY: return "ECDSA-Verify";
171
        case WC_PK_TYPE_ED25519_SIGN: return "ED25519-Sign";
172
        case WC_PK_TYPE_ED25519_VERIFY: return "ED25519-Verify";
173
        case WC_PK_TYPE_ED448: return "ED448-Sign";
174
        case WC_PK_TYPE_ED448_VERIFY: return "ED448-Verify";
175
        case WC_PK_TYPE_CURVE25519: return "CURVE25519";
176
        case WC_PK_TYPE_RSA_KEYGEN: return "RSA KeyGen";
177
        case WC_PK_TYPE_EC_KEYGEN: return "ECC KeyGen";
178
        case WC_PK_TYPE_EC_GET_SIZE: return "ECC GetSize";
179
        case WC_PK_TYPE_EC_GET_SIG_SIZE: return "ECC GetSigSize";
180
        case WC_PK_TYPE_EC_MAKE_PUB: return "ECC MakePub";
181
        case WC_PK_TYPE_EC_CHECK_PUB_KEY: return "ECC CheckPubKey";
182
        case WC_PK_TYPE_ED25519_MAKE_PUB: return "ED25519 MakePub";
183
        case WC_PK_TYPE_ED25519_CHECK_KEY: return "ED25519 CheckKey";
184
        case WC_PK_TYPE_CURVE25519_MAKE_PUB: return "CURVE25519 MakePub";
185
        case WC_PK_TYPE_CURVE25519_GENERIC: return "CURVE25519 Generic";
186
        case WC_PK_TYPE_CURVE448: return "CURVE448";
187
        case WC_PK_TYPE_CURVE448_KEYGEN: return "CURVE448 KeyGen";
188
        case WC_PK_TYPE_CURVE448_MAKE_PUB: return "CURVE448 MakePub";
189
        case WC_PK_TYPE_CURVE448_GENERIC: return "CURVE448 Generic";
190
#if defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_FRODOKEM)
191
        case WC_PK_TYPE_PQC_KEM_KEYGEN: return "PQC KEM KeyGen";
192
        case WC_PK_TYPE_PQC_KEM_ENCAPS: return "PQC KEM Encapsulate";
193
        case WC_PK_TYPE_PQC_KEM_DECAPS: return "PQC KEM Decapsulate";
194
#endif
195
#if defined(WOLFSSL_HAVE_MLDSA) || defined(HAVE_FALCON) || \
196
    defined(WOLFSSL_HAVE_SLHDSA)
197
        case WC_PK_TYPE_PQC_SIG_KEYGEN: return "PQC Sig KeyGen";
198
        case WC_PK_TYPE_PQC_SIG_KEYGEN_SEED: return "PQC Sig KeyGen Seed";
199
        case WC_PK_TYPE_PQC_SIG_SIGN: return "PQC Sig Sign";
200
        case WC_PK_TYPE_PQC_SIG_VERIFY: return "PQC Sig Verify";
201
        case WC_PK_TYPE_PQC_SIG_CHECK_PRIV_KEY: return "PQC Sig CheckPrivKey";
202
        case WC_PK_TYPE_PQC_SIG_SIGN_MSG: return "PQC Sig SignMsg";
203
        case WC_PK_TYPE_PQC_SIG_VERIFY_MSG: return "PQC Sig VerifyMsg";
204
#endif
205
#if defined(WOLFSSL_HAVE_LMS) || defined(WOLFSSL_HAVE_XMSS)
206
        case WC_PK_TYPE_PQC_STATEFUL_SIG_KEYGEN:
207
            return "PQC Stateful Sig KeyGen";
208
        case WC_PK_TYPE_PQC_STATEFUL_SIG_SIGN:
209
            return "PQC Stateful Sig Sign";
210
        case WC_PK_TYPE_PQC_STATEFUL_SIG_VERIFY:
211
            return "PQC Stateful Sig Verify";
212
        case WC_PK_TYPE_PQC_STATEFUL_SIG_SIGS_LEFT:
213
            return "PQC Stateful Sig SigsLeft";
214
#endif
215
    }
216
    return NULL;
217
}
218
#if !defined(NO_AES) || !defined(NO_DES3)
219
static const char* GetCipherTypeStr(int cipher)
220
{
221
    switch (cipher) {
222
        case WC_CIPHER_AES: return "AES ECB";
223
        case WC_CIPHER_AES_CBC: return "AES CBC";
224
        case WC_CIPHER_AES_GCM: return "AES GCM";
225
        case WC_CIPHER_AES_CTR: return "AES CTR";
226
        case WC_CIPHER_AES_XTS: return "AES XTS";
227
        case WC_CIPHER_AES_CFB: return "AES CFB";
228
        case WC_CIPHER_AES_OFB: return "AES OFB";
229
        case WC_CIPHER_AES_KEYWRAP: return "AES KeyWrap";
230
        case WC_CIPHER_DES3: return "DES3";
231
        case WC_CIPHER_DES: return "DES";
232
        case WC_CIPHER_CHACHA: return "ChaCha20";
233
    }
234
    return NULL;
235
}
236
#endif /* !NO_AES || !NO_DES3 */
237
static const char* GetHashTypeStr(int hash)
238
{
239
    switch (hash) {
240
        case WC_HASH_TYPE_MD2: return "MD2";
241
        case WC_HASH_TYPE_MD4: return "MD4";
242
        case WC_HASH_TYPE_MD5: return "MD5";
243
        case WC_HASH_TYPE_SHA: return "SHA-1";
244
        case WC_HASH_TYPE_SHA224: return "SHA-224";
245
        case WC_HASH_TYPE_SHA256: return "SHA-256";
246
        case WC_HASH_TYPE_SHA384: return "SHA-384";
247
        case WC_HASH_TYPE_SHA512: return "SHA-512";
248
        case WC_HASH_TYPE_MD5_SHA: return "MD5-SHA1";
249
        case WC_HASH_TYPE_SHA3_224: return "SHA3-224";
250
        case WC_HASH_TYPE_SHA3_256: return "SHA3-256";
251
        case WC_HASH_TYPE_SHA3_384: return "SHA3-384";
252
        case WC_HASH_TYPE_SHA3_512: return "SHA3-512";
253
        case WC_HASH_TYPE_BLAKE2B: return "Blake2B";
254
        case WC_HASH_TYPE_BLAKE2S: return "Blake2S";
255
    }
256
    return NULL;
257
}
258
259
#ifdef WOLFSSL_CMAC
260
static const char* GetCmacTypeStr(int type)
261
{
262
    switch (type) {
263
        case WC_CMAC_AES: return "AES";
264
    }
265
    return NULL;
266
}
267
#endif  /* WOLFSSL_CMAC */
268
269
#ifndef NO_RSA
270
static const char* GetRsaType(int type)
271
{
272
    switch (type) {
273
        case RSA_PUBLIC_ENCRYPT:  return "Public Encrypt";
274
        case RSA_PUBLIC_DECRYPT:  return "Public Decrypt";
275
        case RSA_PRIVATE_ENCRYPT: return "Private Encrypt";
276
        case RSA_PRIVATE_DECRYPT: return "Private Decrypt";
277
    }
278
    return NULL;
279
}
280
#endif
281
282
#ifdef WOLF_CRYPTO_CB_CMD
283
static const char* GetCryptoCbCmdTypeStr(int type)
284
{
285
    switch (type) {
286
        case WC_CRYPTOCB_CMD_TYPE_REGISTER:   return "Register";
287
        case WC_CRYPTOCB_CMD_TYPE_UNREGISTER: return "UnRegister";
288
    }
289
    return NULL;
290
}
291
#endif
292
293
294
#if (defined(HAVE_HKDF) && !defined(NO_HMAC)) || defined(HAVE_CMAC_KDF)
295
static const char* GetKdfTypeStr(int type)
296
{
297
    switch (type) {
298
        case WC_KDF_TYPE_HKDF:
299
            return "HKDF";
300
        case WC_KDF_TYPE_HKDF_EXTRACT:
301
            return "HKDF Extract";
302
        case WC_KDF_TYPE_HKDF_EXPAND:
303
            return "HKDF Expand";
304
        case WC_KDF_TYPE_TWOSTEP_CMAC:
305
            return "TWOSTEP_CMAC";
306
    }
307
    return NULL;
308
}
309
#endif
310
311
void wc_CryptoCb_InfoString(wc_CryptoInfo* info)
312
{
313
    if (info == NULL)
314
        return;
315
316
    if (info->algo_type == WC_ALGO_TYPE_PK) {
317
    #ifndef NO_RSA
318
        if (info->pk.type == WC_PK_TYPE_RSA) {
319
            printf("Crypto CB: %s %s (%d), %s, Len %d\n",
320
                GetAlgoTypeStr(info->algo_type),
321
                GetPkTypeStr(info->pk.type), info->pk.type,
322
                GetRsaType(info->pk.rsa.type), info->pk.rsa.inLen);
323
        }
324
        else
325
    #endif
326
        {
327
            printf("Crypto CB: %s %s (%d)\n",
328
                GetAlgoTypeStr(info->algo_type),
329
                GetPkTypeStr(info->pk.type), info->pk.type);
330
        }
331
    }
332
#if !defined(NO_AES) || !defined(NO_DES3)
333
    else if (info->algo_type == WC_ALGO_TYPE_CIPHER) {
334
        printf("Crypto CB: %s %s (%d) (%p ctx)\n",
335
            GetAlgoTypeStr(info->algo_type),
336
            GetCipherTypeStr(info->cipher.type),
337
            info->cipher.type, (void*)info->cipher.ctx);
338
    }
339
#endif /* !NO_AES || !NO_DES3 */
340
#if !defined(NO_SHA) || !defined(NO_SHA256) || \
341
    defined(WOLFSSL_SHA512) || defined(WOLFSSL_SHA384) || defined(WOLFSSL_SHA3)
342
    else if (info->algo_type == WC_ALGO_TYPE_HASH) {
343
        printf("Crypto CB: %s %s (%d) (%p ctx) %s\n",
344
            GetAlgoTypeStr(info->algo_type),
345
            GetHashTypeStr(info->hash.type),
346
            info->hash.type, (void*)info->hash.ctx,
347
            (info->hash.in != NULL) ? "Update" : "Final");
348
    }
349
#endif
350
#ifndef NO_HMAC
351
    else if (info->algo_type == WC_ALGO_TYPE_HMAC) {
352
        printf("Crypto CB: %s %s (%d) (%p ctx) %s\n",
353
            GetAlgoTypeStr(info->algo_type),
354
            GetHashTypeStr(info->hmac.macType),
355
            info->hmac.macType, (void*)info->hmac.hmac,
356
            (info->hmac.in != NULL) ? "Update" : "Final");
357
    }
358
#endif
359
#ifdef WOLFSSL_CMAC
360
    else if (info->algo_type == WC_ALGO_TYPE_CMAC) {
361
        printf("Crypto CB: %s %s (%d) (%p ctx) %s %s %s\n",
362
            GetAlgoTypeStr(info->algo_type),
363
            GetCmacTypeStr(info->cmac.type),
364
            info->cmac.type, (void*)info->cmac.cmac,
365
            (info->cmac.key != NULL) ? "Init " : "",
366
            (info->cmac.in != NULL) ? "Update " : "",
367
            (info->cmac.out != NULL) ? "Final" : "");
368
    }
369
#endif
370
#ifdef WOLF_CRYPTO_CB_CMD
371
    else if (info->algo_type == WC_ALGO_TYPE_NONE) {
372
        printf("Crypto CB: %s %s (%d)\n",
373
            GetAlgoTypeStr(info->algo_type),
374
            GetCryptoCbCmdTypeStr(info->cmd.type), info->cmd.type);
375
    }
376
#endif
377
#ifdef WOLF_CRYPTO_CB_COPY
378
    else if (info->algo_type == WC_ALGO_TYPE_COPY) {
379
        printf("Crypto CB: %s %s Type=%d\n",
380
            GetAlgoTypeStr(info->algo_type),
381
            GetAlgoTypeStr(info->copy.algo), info->copy.type);
382
    }
383
#endif /* WOLF_CRYPTO_CB_COPY */
384
#ifdef WOLF_CRYPTO_CB_FREE
385
    else if (info->algo_type == WC_ALGO_TYPE_FREE) {
386
        printf("Crypto CB: %s %s Type=%d\n",
387
            GetAlgoTypeStr(info->algo_type),
388
            GetAlgoTypeStr(info->free.algo), info->free.type);
389
    }
390
#endif /* WOLF_CRYPTO_CB_FREE */
391
#ifdef WOLF_CRYPTO_CB_SETKEY
392
    else if (info->algo_type == WC_ALGO_TYPE_SETKEY) {
393
        printf("Crypto CB: %s %s KeySz=%u\n",
394
            GetAlgoTypeStr(info->algo_type),
395
            GetSetKeyTypeStr(info->setkey.type), info->setkey.keySz);
396
    }
397
#endif /* WOLF_CRYPTO_CB_SETKEY */
398
#ifdef WOLF_CRYPTO_CB_EXPORT_KEY
399
    else if (info->algo_type == WC_ALGO_TYPE_EXPORT_KEY) {
400
        printf("Crypto CB: %s Type=%d\n",
401
            GetAlgoTypeStr(info->algo_type), info->export_key.type);
402
    }
403
#endif /* WOLF_CRYPTO_CB_EXPORT_KEY */
404
#ifdef WOLF_CRYPTO_CB_KEYSTORE
405
    else if (info->algo_type == WC_ALGO_TYPE_KEYSTORE) {
406
        printf("Crypto CB: %s Type=%d\n",
407
            GetAlgoTypeStr(info->algo_type), info->keystore.type);
408
    }
409
#endif /* WOLF_CRYPTO_CB_KEYSTORE */
410
#if (defined(HAVE_HKDF) && !defined(NO_HMAC)) || \
411
    defined(HAVE_CMAC_KDF)
412
    else if (info->algo_type == WC_ALGO_TYPE_KDF) {
413
        printf("Crypto CB: %s %s (%d)\n", GetAlgoTypeStr(info->algo_type),
414
               GetKdfTypeStr(info->kdf.type), info->kdf.type);
415
    }
416
#endif
417
    else {
418
        printf("CryptoCb: %s \n", GetAlgoTypeStr(info->algo_type));
419
    }
420
}
421
#endif /* DEBUG_CRYPTOCB */
422
423
/* Search through listed devices and return the first matching device ID
424
 * found. */
425
static CryptoCb* wc_CryptoCb_GetDevice(int devId)
426
24.8k
{
427
24.8k
    int i;
428
24.9k
    for (i = 0; i < MAX_CRYPTO_DEVID_CALLBACKS; i++) {
429
24.9k
        if (gCryptoDev[i].devId == devId) {
430
            /* Pairs with the publish barrier in wc_CryptoCb_RegisterDevice():
431
             * cb and ctx must not be read before the devId that selected
432
             * this entry. */
433
24.8k
            WC_BARRIER();
434
24.8k
            return &gCryptoDev[i];
435
24.8k
        }
436
24.9k
    }
437
11
    return NULL;
438
24.8k
}
439
440
/* Find a slot that nothing is using yet. A slot that is part way through
441
 * being registered has a callback but no devId, so check both fields. */
442
static CryptoCb* wc_CryptoCb_GetFreeDevice(void)
443
11
{
444
11
    int i;
445
11
    for (i = 0; i < MAX_CRYPTO_DEVID_CALLBACKS; i++) {
446
11
        if ((gCryptoDev[i].devId == INVALID_DEVID) &&
447
11
            (gCryptoDev[i].cb == NULL)) {
448
11
            return &gCryptoDev[i];
449
11
        }
450
11
    }
451
0
    return NULL;
452
11
}
453
454
/* Returns 1 if the given device ID is currently registered, 0 otherwise.
455
 * INVALID_DEVID marks free table slots, so it is never reported registered. */
456
int wc_CryptoCb_IsDeviceRegistered(int devId)
457
0
{
458
0
    if (devId == INVALID_DEVID)
459
0
        return 0;
460
0
    return wc_CryptoCb_GetDevice(devId) != NULL;
461
0
}
462
463
464
/* Filters through find callback set when trying to get the device,
465
 * returns the device found on success and null if not found. */
466
static CryptoCb* wc_CryptoCb_FindDevice(int devId, int algoType)
467
76.0k
{
468
76.0k
    int localDevId = devId;
469
470
#ifdef WOLF_CRYPTO_CB_FIND
471
    if (CryptoCb_FindCb != NULL) {
472
        localDevId = CryptoCb_FindCb(devId, algoType);
473
    }
474
#endif /* WOLF_CRYPTO_CB_FIND */
475
76.0k
    (void)algoType;
476
76.0k
    return wc_CryptoCb_GetDevice(localDevId);
477
76.0k
}
478
479
480
static CryptoCb* wc_CryptoCb_FindDeviceByIndex(int startIdx)
481
72.8k
{
482
72.8k
    int i;
483
646k
    for (i=startIdx; i<MAX_CRYPTO_DEVID_CALLBACKS; i++) {
484
574k
        if (gCryptoDev[i].devId != INVALID_DEVID)
485
1.13k
            return &gCryptoDev[i];
486
574k
    }
487
71.7k
    return NULL;
488
72.8k
}
489
490
static WC_INLINE int wc_CryptoCb_TranslateErrorCode(int ret)
491
76.0k
{
492
76.0k
    if (ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN)) {
493
        /* backwards compatibility for older NOT_COMPILED_IN syntax */
494
1.58k
        ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
495
1.58k
    }
496
76.0k
    return ret;
497
76.0k
}
498
499
/* Helper function to reset a device entry to invalid */
500
static WC_INLINE void wc_CryptoCb_ClearDev(CryptoCb *dev)
501
88
{
502
    /* Retire the entry, then clear the rest of it. */
503
88
    dev->devId = INVALID_DEVID;
504
88
    WC_BARRIER();
505
88
    dev->cb    = NULL;
506
88
    dev->ctx   = NULL;
507
88
}
508
509
void wc_CryptoCb_Init(void)
510
27
{
511
27
    int i;
512
243
    for (i = 0; i < MAX_CRYPTO_DEVID_CALLBACKS; i++) {
513
216
        wc_CryptoCb_ClearDev(&gCryptoDev[i]);
514
216
    }
515
27
}
516
517
void wc_CryptoCb_Cleanup(void)
518
16
{
519
16
    int i;
520
144
    for (i = 0; i < MAX_CRYPTO_DEVID_CALLBACKS; i++) {
521
128
        if(gCryptoDev[i].devId != INVALID_DEVID) {
522
0
            wc_CryptoCb_UnRegisterDevice(gCryptoDev[i].devId);
523
0
        }
524
128
    }
525
16
}
526
527
int wc_CryptoCb_GetDevIdAtIndex(int startIdx)
528
72.8k
{
529
72.8k
    int devId = INVALID_DEVID;
530
72.8k
    CryptoCb* dev = wc_CryptoCb_FindDeviceByIndex(startIdx);
531
72.8k
    if (dev) {
532
1.13k
        devId = dev->devId;
533
1.13k
    }
534
72.8k
    return devId;
535
72.8k
}
536
537
#if defined(WOLFSSL_ASYNC_CRYPT) && defined(WOLF_CRYPTO_CB_ASYNC_POLL)
538
/* Returns WC_PENDING_E while in-flight, 0 or an error when done. */
539
int wc_CryptoCb_Poll(int devId)
540
{
541
    /* Default hard-fails: a missing or unregistered device cannot complete
542
     * the pending job, so never report "no pending" and leave the output
543
     * buffer unfilled. */
544
    int ret = WC_NO_ERR_TRACE(WC_HW_E);
545
    /* Resolve with WC_ALGO_TYPE_CIPHER, the algo the op was submitted under, so
546
     * a WOLF_CRYPTO_CB_FIND remap lands on the same device as the submit. */
547
    CryptoCb* dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_CIPHER);
548
    if (dev != NULL && dev->cb != NULL) {
549
        wc_CryptoInfo info;
550
        XMEMSET(&info, 0, sizeof(info));
551
        info.algo_type = WC_ALGO_TYPE_ASYNC_POLL;
552
        /* Call with the resolved device id (dev->devId), matching submit-time
553
         * dispatch, so a remapped device is invoked under its own id. */
554
        ret = dev->cb(dev->devId, &info, dev->ctx);
555
        if (ret == WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE) ||
556
            ret == WC_NO_ERR_TRACE(NOT_COMPILED_IN) ||
557
            ret == WC_NO_ERR_TRACE(WC_NO_PENDING_E)) {
558
            /* Device cannot complete the in-flight job (no poll support, or it
559
             * reports nothing pending for an op we are polling): fail hard
560
             * rather than let the async layer treat it as done. */
561
            ret = WC_NO_ERR_TRACE(WC_HW_E);
562
        }
563
    }
564
    return ret;
565
}
566
#endif /* WOLFSSL_ASYNC_CRYPT && WOLF_CRYPTO_CB_ASYNC_POLL */
567
568
569
#ifdef WOLF_CRYPTO_CB_FIND
570
/* Used to register a find device function. Useful for cases where the
571
 * device ID in the struct may not have been set but still wanting to use
572
 * a specific crypto callback device ID. The find callback is global and
573
 * not thread safe. */
574
void wc_CryptoCb_SetDeviceFindCb(CryptoDevCallbackFind cb)
575
{
576
    CryptoCb_FindCb = cb;
577
}
578
#endif
579
580
int wc_CryptoCb_RegisterDevice(int devId, CryptoDevCallbackFunc cb, void* ctx)
581
11
{
582
11
    int rc = 0;
583
11
    CryptoCb* dev;
584
585
    /* INVALID_DEVID marks a free slot and cannot be registered as a device. */
586
11
    if (devId == INVALID_DEVID)
587
0
        return BAD_FUNC_ARG;
588
589
    /* Reject re-registration of an already-registered device ID. */
590
11
    if (wc_CryptoCb_GetDevice(devId) != NULL)
591
0
        return ALREADY_E;
592
593
    /* find a free slot */
594
11
    dev = wc_CryptoCb_GetFreeDevice();
595
11
    if (dev == NULL)
596
0
        return BUFFER_E; /* out of devices */
597
598
    /* Fill the entry before publishing it - see the note on gCryptoDev. */
599
11
    dev->cb    = cb;
600
11
    dev->ctx   = ctx;
601
602
#ifdef WOLF_CRYPTO_CB_CMD
603
    if (cb != NULL) {
604
        /* Invoke callback with register command */
605
        wc_CryptoInfo info;
606
        XMEMSET(&info, 0, sizeof(info));
607
        info.algo_type = WC_ALGO_TYPE_NONE;
608
        info.cmd.type  = WC_CRYPTOCB_CMD_TYPE_REGISTER;
609
        info.cmd.ctx   = ctx;  /* cb may update on success */
610
611
        rc = cb(devId, &info, ctx);
612
        if (rc == 0) {
613
            /* Success.  Update dev->ctx */
614
            dev->ctx = info.cmd.ctx;
615
        }
616
        else if ((rc == WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) ||
617
                 (rc == WC_NO_ERR_TRACE(NOT_COMPILED_IN))) {
618
            /* Not implemented.  Return success*/
619
            rc = 0;
620
        }
621
        else {
622
            /* Error in callback register cmd. Don't register */
623
            wc_CryptoCb_ClearDev(dev);
624
            return rc;
625
        }
626
    }
627
#endif
628
629
    /* Publish the entry last, after everything it points at is in place.
630
     * The slot is therefore not discoverable from the register command
631
     * itself - a handler must not dispatch through, or re-register, its
632
     * own devId (a nested register of it would claim a second slot). */
633
11
    WC_BARRIER();
634
11
    dev->devId = devId;
635
636
11
    return rc;
637
11
}
638
639
void wc_CryptoCb_UnRegisterDevice(int devId)
640
0
{
641
0
    CryptoCb* dev = NULL;
642
643
    /* Can't unregister the invalid device */
644
0
    if (devId == INVALID_DEVID)
645
0
        return;
646
647
    /* Find the matching dev */
648
0
    dev = wc_CryptoCb_GetDevice(devId);
649
0
    if (dev == NULL)
650
0
        return;
651
652
#ifdef WOLF_CRYPTO_CB_CMD
653
    if (dev->cb != NULL) {
654
        /* Invoke callback with unregister command.*/
655
        wc_CryptoInfo info;
656
        XMEMSET(&info, 0, sizeof(info));
657
        info.algo_type = WC_ALGO_TYPE_NONE;
658
        info.cmd.type  = WC_CRYPTOCB_CMD_TYPE_UNREGISTER;
659
        info.cmd.ctx   = NULL;  /* Not used */
660
661
        /* Ignore errors here */
662
        dev->cb(devId, &info, dev->ctx);
663
    }
664
#endif
665
0
    wc_CryptoCb_ClearDev(dev);
666
0
}
667
668
#ifndef NO_RSA
669
int wc_CryptoCb_Rsa(const byte* in, word32 inLen, byte* out,
670
    word32* outLen, int type, RsaKey* key, WC_RNG* rng)
671
0
{
672
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
673
0
    CryptoCb* dev;
674
675
0
    if (key == NULL)
676
0
        return ret;
677
678
    /* locate registered callback */
679
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
680
0
    if (dev && dev->cb) {
681
0
        wc_CryptoInfo cryptoInfo;
682
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
683
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
684
0
        cryptoInfo.pk.type = WC_PK_TYPE_RSA;
685
0
        cryptoInfo.pk.rsa.in = in;
686
0
        cryptoInfo.pk.rsa.inLen = inLen;
687
0
        cryptoInfo.pk.rsa.out = out;
688
0
        cryptoInfo.pk.rsa.outLen = outLen;
689
0
        cryptoInfo.pk.rsa.type = type;
690
0
        cryptoInfo.pk.rsa.key = key;
691
0
        cryptoInfo.pk.rsa.rng = rng;
692
693
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
694
0
    }
695
696
0
    return wc_CryptoCb_TranslateErrorCode(ret);
697
0
}
698
699
#ifdef WOLF_CRYPTO_CB_RSA_PAD
700
int wc_CryptoCb_RsaPad(const byte* in, word32 inLen, byte* out,
701
                       word32* outLen, int type, RsaKey* key, WC_RNG* rng,
702
                       RsaPadding *padding)
703
{
704
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
705
    CryptoCb* dev;
706
    int pk_type;
707
708
    if (key == NULL)
709
        return ret;
710
711
    /* locate registered callback */
712
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
713
714
    if (padding != NULL) {
715
        switch (padding->pad_type) {
716
        case WC_RSA_PKCSV15_PAD:
717
            pk_type = WC_PK_TYPE_RSA_PKCS;
718
            break;
719
        case WC_RSA_PSS_PAD:
720
            pk_type = WC_PK_TYPE_RSA_PSS;
721
            break;
722
        case WC_RSA_OAEP_PAD:
723
            pk_type = WC_PK_TYPE_RSA_OAEP;
724
            break;
725
        default:
726
            pk_type = WC_PK_TYPE_RSA;
727
        }
728
    } else {
729
        pk_type = WC_PK_TYPE_RSA;
730
    }
731
732
    if (dev && dev->cb) {
733
        wc_CryptoInfo cryptoInfo;
734
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
735
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
736
        cryptoInfo.pk.type = pk_type;
737
        cryptoInfo.pk.rsa.in = in;
738
        cryptoInfo.pk.rsa.inLen = inLen;
739
        cryptoInfo.pk.rsa.out = out;
740
        cryptoInfo.pk.rsa.outLen = outLen;
741
        cryptoInfo.pk.rsa.type = type;
742
        cryptoInfo.pk.rsa.key = key;
743
        cryptoInfo.pk.rsa.rng = rng;
744
        cryptoInfo.pk.rsa.padding = padding;
745
746
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
747
    }
748
749
    return wc_CryptoCb_TranslateErrorCode(ret);
750
}
751
752
/* Verify an RSA-PSS signature on the device (padding included). Passes both the
753
 * signature and digest so the device does the whole verify and returns a verdict. */
754
int wc_CryptoCb_RsaPssVerify(const byte* sig, word32 sigSz, const byte* digest,
755
    word32 digestSz, enum wc_HashType hash, int mgf, int saltLen, RsaKey* key,
756
    int* res, byte* out, word32 outSz, word32* outLen)
757
{
758
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
759
    CryptoCb* dev;
760
761
    if (key == NULL)
762
        return ret;
763
764
    /* locate registered callback */
765
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
766
767
    if (dev && dev->cb) {
768
        wc_CryptoInfo cryptoInfo;
769
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
770
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
771
        cryptoInfo.pk.type = WC_PK_TYPE_RSA_PSS_VERIFY;
772
        cryptoInfo.pk.rsa_pss_verify.sig = sig;
773
        cryptoInfo.pk.rsa_pss_verify.sigSz = sigSz;
774
        cryptoInfo.pk.rsa_pss_verify.digest = digest;
775
        cryptoInfo.pk.rsa_pss_verify.digestSz = digestSz;
776
        cryptoInfo.pk.rsa_pss_verify.hash = hash;
777
        cryptoInfo.pk.rsa_pss_verify.mgf = mgf;
778
        cryptoInfo.pk.rsa_pss_verify.saltLen = saltLen;
779
        cryptoInfo.pk.rsa_pss_verify.key = key;
780
        cryptoInfo.pk.rsa_pss_verify.res = res;
781
        cryptoInfo.pk.rsa_pss_verify.out = out;
782
        cryptoInfo.pk.rsa_pss_verify.outSz = outSz;
783
        cryptoInfo.pk.rsa_pss_verify.outLen = outLen;
784
785
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
786
    }
787
788
    return wc_CryptoCb_TranslateErrorCode(ret);
789
}
790
#endif /* WOLF_CRYPTO_CB_RSA_PAD */
791
792
#ifdef WOLFSSL_KEY_GEN
793
int wc_CryptoCb_MakeRsaKey(RsaKey* key, int size, long e, WC_RNG* rng)
794
0
{
795
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
796
0
    CryptoCb* dev;
797
798
0
    if (key == NULL)
799
0
        return ret;
800
801
    /* locate registered callback */
802
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
803
0
    if (dev && dev->cb) {
804
0
        wc_CryptoInfo cryptoInfo;
805
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
806
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
807
0
        cryptoInfo.pk.type = WC_PK_TYPE_RSA_KEYGEN;
808
0
        cryptoInfo.pk.rsakg.key = key;
809
0
        cryptoInfo.pk.rsakg.size = size;
810
0
        cryptoInfo.pk.rsakg.e = e;
811
0
        cryptoInfo.pk.rsakg.rng = rng;
812
813
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
814
0
    }
815
816
0
    return wc_CryptoCb_TranslateErrorCode(ret);
817
0
}
818
#endif
819
820
int wc_CryptoCb_RsaCheckPrivKey(RsaKey* key, const byte* pubKey,
821
    word32 pubKeySz)
822
0
{
823
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
824
0
    CryptoCb* dev;
825
826
0
    if (key == NULL)
827
0
        return ret;
828
829
    /* locate registered callback */
830
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
831
0
    if (dev && dev->cb) {
832
0
        wc_CryptoInfo cryptoInfo;
833
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
834
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
835
0
        cryptoInfo.pk.type = WC_PK_TYPE_RSA_CHECK_PRIV_KEY;
836
0
        cryptoInfo.pk.rsa_check.key = key;
837
0
        cryptoInfo.pk.rsa_check.pubKey = pubKey;
838
0
        cryptoInfo.pk.rsa_check.pubKeySz = pubKeySz;
839
840
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
841
0
    }
842
843
0
    return wc_CryptoCb_TranslateErrorCode(ret);
844
0
}
845
846
int wc_CryptoCb_RsaGetSize(const RsaKey* key, int* keySize)
847
0
{
848
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
849
0
    CryptoCb* dev;
850
851
0
    if (key == NULL)
852
0
        return ret;
853
854
    /* locate registered callback */
855
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
856
0
    if (dev && dev->cb) {
857
0
        wc_CryptoInfo cryptoInfo;
858
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
859
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
860
0
        cryptoInfo.pk.type = WC_PK_TYPE_RSA_GET_SIZE;
861
0
        cryptoInfo.pk.rsa_get_size.key = key;
862
0
        cryptoInfo.pk.rsa_get_size.keySize = keySize;
863
864
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
865
0
    }
866
867
0
    return wc_CryptoCb_TranslateErrorCode(ret);
868
0
}
869
#endif /* !NO_RSA */
870
871
#ifdef HAVE_ECC
872
#ifdef HAVE_ECC_DHE
873
int wc_CryptoCb_MakeEccKey(WC_RNG* rng, int keySize, ecc_key* key, int curveId)
874
0
{
875
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
876
0
    CryptoCb* dev;
877
878
0
    if (key == NULL)
879
0
        return ret;
880
881
    /* locate registered callback */
882
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
883
0
    if (dev && dev->cb) {
884
0
        wc_CryptoInfo cryptoInfo;
885
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
886
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
887
0
        cryptoInfo.pk.type = WC_PK_TYPE_EC_KEYGEN;
888
0
        cryptoInfo.pk.eckg.rng = rng;
889
0
        cryptoInfo.pk.eckg.size = keySize;
890
0
        cryptoInfo.pk.eckg.key = key;
891
0
        cryptoInfo.pk.eckg.curveId = curveId;
892
893
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
894
0
    }
895
896
0
    return wc_CryptoCb_TranslateErrorCode(ret);
897
0
}
898
899
int wc_CryptoCb_Ecdh(ecc_key* private_key, ecc_key* public_key,
900
    byte* out, word32* outlen)
901
0
{
902
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
903
0
    CryptoCb* dev;
904
905
0
    if (private_key == NULL)
906
0
        return ret;
907
908
    /* locate registered callback */
909
0
    dev = wc_CryptoCb_FindDevice(private_key->devId, WC_ALGO_TYPE_PK);
910
0
    if (dev && dev->cb) {
911
0
        wc_CryptoInfo cryptoInfo;
912
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
913
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
914
0
        cryptoInfo.pk.type = WC_PK_TYPE_ECDH;
915
0
        cryptoInfo.pk.ecdh.private_key = private_key;
916
0
        cryptoInfo.pk.ecdh.public_key = public_key;
917
0
        cryptoInfo.pk.ecdh.out = out;
918
0
        cryptoInfo.pk.ecdh.outlen = outlen;
919
920
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
921
0
    }
922
923
0
    return wc_CryptoCb_TranslateErrorCode(ret);
924
0
}
925
#endif
926
927
#ifdef HAVE_ECC_SIGN
928
int wc_CryptoCb_EccSign(const byte* in, word32 inlen, byte* out,
929
    word32 *outlen, WC_RNG* rng, ecc_key* key)
930
0
{
931
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
932
0
    CryptoCb* dev;
933
934
0
    if (key == NULL)
935
0
        return ret;
936
937
    /* locate registered callback */
938
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
939
0
    if (dev && dev->cb) {
940
0
        wc_CryptoInfo cryptoInfo;
941
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
942
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
943
0
        cryptoInfo.pk.type = WC_PK_TYPE_ECDSA_SIGN;
944
0
        cryptoInfo.pk.eccsign.in = in;
945
0
        cryptoInfo.pk.eccsign.inlen = inlen;
946
0
        cryptoInfo.pk.eccsign.out = out;
947
0
        cryptoInfo.pk.eccsign.outlen = outlen;
948
0
        cryptoInfo.pk.eccsign.rng = rng;
949
0
        cryptoInfo.pk.eccsign.key = key;
950
951
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
952
0
    }
953
954
0
    return wc_CryptoCb_TranslateErrorCode(ret);
955
0
}
956
#endif
957
958
#ifdef HAVE_ECC_VERIFY
959
int wc_CryptoCb_EccVerify(const byte* sig, word32 siglen,
960
    const byte* hash, word32 hashlen, int* res, ecc_key* key)
961
0
{
962
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
963
0
    CryptoCb* dev;
964
965
0
    if (key == NULL)
966
0
        return ret;
967
968
    /* locate registered callback */
969
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
970
0
    if (dev && dev->cb) {
971
0
        wc_CryptoInfo cryptoInfo;
972
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
973
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
974
0
        cryptoInfo.pk.type = WC_PK_TYPE_ECDSA_VERIFY;
975
0
        cryptoInfo.pk.eccverify.sig = sig;
976
0
        cryptoInfo.pk.eccverify.siglen = siglen;
977
0
        cryptoInfo.pk.eccverify.hash = hash;
978
0
        cryptoInfo.pk.eccverify.hashlen = hashlen;
979
0
        cryptoInfo.pk.eccverify.res = res;
980
0
        cryptoInfo.pk.eccverify.key = key;
981
982
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
983
0
    }
984
985
0
    return wc_CryptoCb_TranslateErrorCode(ret);
986
0
}
987
#endif
988
989
#ifdef HAVE_ECC_CHECK_KEY
990
int wc_CryptoCb_EccCheckPrivKey(ecc_key* key, const byte* pubKey,
991
    word32 pubKeySz)
992
0
{
993
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
994
0
    CryptoCb* dev;
995
996
0
    if (key == NULL)
997
0
        return ret;
998
999
    /* locate registered callback */
1000
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1001
0
    if (dev && dev->cb) {
1002
0
        wc_CryptoInfo cryptoInfo;
1003
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1004
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1005
0
        cryptoInfo.pk.type = WC_PK_TYPE_EC_CHECK_PRIV_KEY;
1006
0
        cryptoInfo.pk.ecc_check.key = key;
1007
0
        cryptoInfo.pk.ecc_check.pubKey = pubKey;
1008
0
        cryptoInfo.pk.ecc_check.pubKeySz = pubKeySz;
1009
1010
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1011
0
    }
1012
1013
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1014
0
}
1015
#endif
1016
1017
int wc_CryptoCb_EccGetSize(const ecc_key* key, int* keySize)
1018
0
{
1019
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1020
0
    CryptoCb* dev;
1021
1022
0
    if (key == NULL)
1023
0
        return ret;
1024
1025
    /* locate registered callback */
1026
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1027
0
    if (dev && dev->cb) {
1028
0
        wc_CryptoInfo cryptoInfo;
1029
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1030
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1031
0
        cryptoInfo.pk.type = WC_PK_TYPE_EC_GET_SIZE;
1032
0
        cryptoInfo.pk.ecc_get_size.key = key;
1033
0
        cryptoInfo.pk.ecc_get_size.keySize = keySize;
1034
1035
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1036
0
    }
1037
1038
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1039
0
}
1040
1041
int wc_CryptoCb_EccGetSigSize(const ecc_key* key, int* sigSize)
1042
0
{
1043
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1044
0
    CryptoCb* dev;
1045
1046
0
    if (key == NULL)
1047
0
        return ret;
1048
1049
    /* locate registered callback */
1050
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1051
0
    if (dev && dev->cb) {
1052
0
        wc_CryptoInfo cryptoInfo;
1053
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1054
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1055
0
        cryptoInfo.pk.type = WC_PK_TYPE_EC_GET_SIG_SIZE;
1056
0
        cryptoInfo.pk.ecc_get_sig_size.key = key;
1057
0
        cryptoInfo.pk.ecc_get_sig_size.sigSize = sigSize;
1058
1059
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1060
0
    }
1061
1062
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1063
0
}
1064
1065
int wc_CryptoCb_EccMakePub(ecc_key* key, ecc_point* pubOut)
1066
0
{
1067
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1068
0
    CryptoCb* dev;
1069
1070
0
    if (key == NULL || pubOut == NULL || key->dp == NULL)
1071
0
        return ret;
1072
1073
0
    if (key->dp->size > MAX_ECC_BYTES)
1074
0
        return ret;
1075
1076
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1077
0
    if (dev && dev->cb) {
1078
0
        wc_CryptoInfo cryptoInfo;
1079
0
        word32 curveSz = (word32)key->dp->size;
1080
0
        word32 ptSz    = 1 + 2 * curveSz;          /* X9.63 uncompressed length */
1081
0
        word32 outSz   = 1 + 2 * MAX_ECC_BYTES;    /* buffer size on input */
1082
0
        WC_DECLARE_VAR(buf, byte, (1 + 2 * MAX_ECC_BYTES), key->heap);
1083
0
        WC_ALLOC_VAR_EX(buf, byte, (1 + 2 * MAX_ECC_BYTES), key->heap,
1084
0
            DYNAMIC_TYPE_ECC_BUFFER, return MEMORY_E);
1085
1086
        /* zero the result buffer so a handler that returns success without
1087
         * writing output is rejected deterministically by the tag check */
1088
0
        XMEMSET(buf, 0, ptSz);
1089
1090
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1091
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1092
0
        cryptoInfo.pk.type = WC_PK_TYPE_EC_MAKE_PUB;
1093
0
        cryptoInfo.pk.ecc_make_pub.key = key;
1094
0
        cryptoInfo.pk.ecc_make_pub.pubOut = buf;
1095
0
        cryptoInfo.pk.ecc_make_pub.pubOutSz = &outSz;
1096
1097
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1098
1099
        /* deserialize X9.63 uncompressed result into pubOut; reject a result
1100
         * whose size is not exactly the curve's X9.63 length */
1101
0
        if (ret == 0) {
1102
0
            if (outSz != ptSz || buf[0] != ECC_POINT_UNCOMP) {
1103
0
                ret = BUFFER_E;
1104
0
            }
1105
0
            else {
1106
0
                int err = mp_read_unsigned_bin(pubOut->x, buf + 1, curveSz);
1107
0
                if (err == MP_OKAY)
1108
0
                    err = mp_read_unsigned_bin(pubOut->y, buf + 1 + curveSz,
1109
0
                        curveSz);
1110
0
                if (err == MP_OKAY)
1111
0
                    err = mp_set(pubOut->z, 1);
1112
0
                if (err != MP_OKAY)
1113
0
                    ret = err;
1114
0
            }
1115
0
        }
1116
1117
0
        WC_FREE_VAR_EX(buf, key->heap, DYNAMIC_TYPE_ECC_BUFFER);
1118
0
    }
1119
1120
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1121
0
}
1122
1123
#ifdef HAVE_ECC_CHECK_KEY
1124
int wc_CryptoCb_EccCheckPubKey(ecc_key* key, int checkOrder, int checkPriv)
1125
0
{
1126
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1127
0
    CryptoCb* dev;
1128
1129
0
    if (key == NULL || key->dp == NULL)
1130
0
        return ret;
1131
1132
0
    if (key->dp->size > MAX_ECC_BYTES)
1133
0
        return ret;
1134
1135
    /* locate registered callback */
1136
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1137
0
    if (dev && dev->cb) {
1138
0
        wc_CryptoInfo cryptoInfo;
1139
0
        word32 curveSz = (word32)key->dp->size;
1140
0
        word32 ptSz    = 1 + 2 * curveSz;
1141
0
        word32 xSz     = curveSz;
1142
0
        word32 ySz     = curveSz;
1143
        /* a key with no host-side public point is represented by
1144
         * ECC_PRIVATEKEY_ONLY and crosses as pubKey = NULL / pubKeySz = 0.
1145
         * If the key state says a public point exists, serialize it even when
1146
         * the coordinates are invalid (e.g. 0,0) so the device can reject the
1147
         * actual input instead of seeing "no public point". */
1148
0
        int havePub    = (key->type != ECC_PRIVATEKEY_ONLY);
1149
0
        WC_DECLARE_VAR(buf, byte, (1 + 2 * MAX_ECC_BYTES), key->heap);
1150
1151
0
        ret = MP_OKAY;
1152
0
        if (havePub) {
1153
0
            WC_ALLOC_VAR_EX(buf, byte, (1 + 2 * MAX_ECC_BYTES), key->heap,
1154
0
                DYNAMIC_TYPE_ECC_BUFFER, return MEMORY_E);
1155
            /* serialize key->pubkey to X9.63 uncompressed (0x04 || X || Y) */
1156
0
            buf[0] = ECC_POINT_UNCOMP;
1157
0
            ret = wc_export_int(key->pubkey.x, buf + 1, &xSz, curveSz,
1158
0
                WC_TYPE_UNSIGNED_BIN);
1159
0
            if (ret == MP_OKAY)
1160
0
                ret = wc_export_int(key->pubkey.y, buf + 1 + curveSz, &ySz,
1161
0
                    curveSz, WC_TYPE_UNSIGNED_BIN);
1162
0
        }
1163
1164
0
        if (ret == MP_OKAY) {
1165
0
            XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1166
0
            cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1167
0
            cryptoInfo.pk.type = WC_PK_TYPE_EC_CHECK_PUB_KEY;
1168
0
            cryptoInfo.pk.ecc_check_pub.key = key;
1169
0
            cryptoInfo.pk.ecc_check_pub.pubKey = havePub ? buf : NULL;
1170
0
            cryptoInfo.pk.ecc_check_pub.pubKeySz = havePub ? ptSz : 0;
1171
0
            cryptoInfo.pk.ecc_check_pub.checkOrder = checkOrder;
1172
0
            cryptoInfo.pk.ecc_check_pub.checkPriv = checkPriv;
1173
1174
0
            ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1175
0
        }
1176
1177
0
        if (havePub) {
1178
0
            WC_FREE_VAR_EX(buf, key->heap, DYNAMIC_TYPE_ECC_BUFFER);
1179
0
        }
1180
0
    }
1181
1182
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1183
0
}
1184
#endif /* HAVE_ECC_CHECK_KEY */
1185
1186
#ifdef HAVE_ECC_ENCRYPT
1187
int wc_CryptoCb_EciesEncrypt(int devId, ecc_key* privKey, ecc_key* pubKey,
1188
    const byte* msg, word32 msgSz, byte* out, word32* outSz, ecEncCtx* ctx,
1189
    int compressed)
1190
0
{
1191
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1192
0
    CryptoCb* dev;
1193
1194
0
    if (privKey == NULL)
1195
0
        return ret;
1196
1197
    /* find the registered callback.  The device comes from the ECIES
1198
     * context, not from privKey->devId. */
1199
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1200
0
    if (dev && dev->cb) {
1201
0
        wc_CryptoInfo cryptoInfo;
1202
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1203
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1204
0
        cryptoInfo.pk.type = WC_PK_TYPE_ECIES_ENCRYPT;
1205
0
        cryptoInfo.pk.eciesencrypt.privKey = privKey;
1206
0
        cryptoInfo.pk.eciesencrypt.pubKey = pubKey;
1207
0
        cryptoInfo.pk.eciesencrypt.msg = msg;
1208
0
        cryptoInfo.pk.eciesencrypt.msgSz = msgSz;
1209
0
        cryptoInfo.pk.eciesencrypt.out = out;
1210
0
        cryptoInfo.pk.eciesencrypt.outSz = outSz;
1211
0
        cryptoInfo.pk.eciesencrypt.ctx = ctx;
1212
0
        cryptoInfo.pk.eciesencrypt.compressed = compressed;
1213
1214
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1215
0
    }
1216
1217
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1218
0
}
1219
1220
int wc_CryptoCb_EciesDecrypt(int devId, ecc_key* privKey, ecc_key* pubKey,
1221
    const byte* msg, word32 msgSz, byte* out, word32* outSz, ecEncCtx* ctx)
1222
0
{
1223
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1224
0
    CryptoCb* dev;
1225
1226
0
    if (privKey == NULL)
1227
0
        return ret;
1228
1229
    /* find the registered callback.  The device comes from the ECIES
1230
     * context, not from privKey->devId. */
1231
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1232
0
    if (dev && dev->cb) {
1233
0
        wc_CryptoInfo cryptoInfo;
1234
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1235
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1236
0
        cryptoInfo.pk.type = WC_PK_TYPE_ECIES_DECRYPT;
1237
0
        cryptoInfo.pk.eciesdecrypt.privKey = privKey;
1238
0
        cryptoInfo.pk.eciesdecrypt.pubKey = pubKey;
1239
0
        cryptoInfo.pk.eciesdecrypt.msg = msg;
1240
0
        cryptoInfo.pk.eciesdecrypt.msgSz = msgSz;
1241
0
        cryptoInfo.pk.eciesdecrypt.out = out;
1242
0
        cryptoInfo.pk.eciesdecrypt.outSz = outSz;
1243
0
        cryptoInfo.pk.eciesdecrypt.ctx = ctx;
1244
1245
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1246
0
    }
1247
1248
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1249
0
}
1250
#endif /* HAVE_ECC_ENCRYPT */
1251
#endif /* HAVE_ECC */
1252
1253
#ifdef HAVE_CURVE25519
1254
int wc_CryptoCb_Curve25519Gen(WC_RNG* rng, int keySize,
1255
    curve25519_key* key)
1256
0
{
1257
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1258
0
    CryptoCb* dev;
1259
1260
0
    if (key == NULL)
1261
0
        return ret;
1262
1263
    /* locate registered callback */
1264
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1265
0
    if (dev && dev->cb) {
1266
0
        wc_CryptoInfo cryptoInfo;
1267
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1268
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1269
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE25519_KEYGEN;
1270
0
        cryptoInfo.pk.curve25519kg.rng = rng;
1271
0
        cryptoInfo.pk.curve25519kg.size = keySize;
1272
0
        cryptoInfo.pk.curve25519kg.key = key;
1273
1274
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1275
0
    }
1276
1277
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1278
0
}
1279
1280
int wc_CryptoCb_Curve25519(curve25519_key* private_key,
1281
    curve25519_key* public_key, byte* out, word32* outlen, int endian)
1282
0
{
1283
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1284
0
    CryptoCb* dev;
1285
1286
0
    if (private_key == NULL)
1287
0
        return ret;
1288
1289
    /* locate registered callback */
1290
0
    dev = wc_CryptoCb_FindDevice(private_key->devId, WC_ALGO_TYPE_PK);
1291
0
    if (dev && dev->cb) {
1292
0
        wc_CryptoInfo cryptoInfo;
1293
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1294
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1295
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE25519;
1296
0
        cryptoInfo.pk.curve25519.private_key = private_key;
1297
0
        cryptoInfo.pk.curve25519.public_key = public_key;
1298
0
        cryptoInfo.pk.curve25519.out = out;
1299
0
        cryptoInfo.pk.curve25519.outlen = outlen;
1300
0
        cryptoInfo.pk.curve25519.endian = endian;
1301
1302
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1303
0
    }
1304
1305
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1306
0
}
1307
1308
int wc_CryptoCb_Curve25519MakePub(int devId, int public_size, byte* pub,
1309
    int private_size, const byte* priv)
1310
948
{
1311
948
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1312
948
    CryptoCb* dev;
1313
1314
948
    if (pub == NULL || priv == NULL)
1315
0
        return ret;
1316
1317
    /* locate registered callback */
1318
948
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1319
    /* only a caller that selected no device settles for the first registered
1320
     * one; a devId names the single device allowed to see the scalar */
1321
948
    if ((dev == NULL || dev->cb == NULL) && (devId == INVALID_DEVID))
1322
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
1323
948
    if (dev && dev->cb) {
1324
948
        wc_CryptoInfo cryptoInfo;
1325
948
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1326
948
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1327
948
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE25519_MAKE_PUB;
1328
948
        cryptoInfo.pk.curve25519makepub.pub = pub;
1329
948
        cryptoInfo.pk.curve25519makepub.pubSz = (word32)public_size;
1330
948
        cryptoInfo.pk.curve25519makepub.priv = priv;
1331
948
        cryptoInfo.pk.curve25519makepub.privSz = (word32)private_size;
1332
1333
948
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1334
948
    }
1335
1336
948
    return wc_CryptoCb_TranslateErrorCode(ret);
1337
948
}
1338
1339
int wc_CryptoCb_Curve25519Generic(int devId, int public_size, byte* pub,
1340
    int private_size, const byte* priv, int basepoint_size,
1341
    const byte* basepoint)
1342
0
{
1343
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1344
0
    CryptoCb* dev;
1345
1346
0
    if (pub == NULL || priv == NULL || basepoint == NULL)
1347
0
        return ret;
1348
1349
    /* locate registered callback */
1350
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1351
    /* only a caller that selected no device settles for the first registered
1352
     * one; a devId names the single device allowed to see the scalar */
1353
0
    if ((dev == NULL || dev->cb == NULL) && (devId == INVALID_DEVID))
1354
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
1355
0
    if (dev && dev->cb) {
1356
0
        wc_CryptoInfo cryptoInfo;
1357
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1358
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1359
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE25519_GENERIC;
1360
0
        cryptoInfo.pk.curve25519generic.pub = pub;
1361
0
        cryptoInfo.pk.curve25519generic.pubSz = (word32)public_size;
1362
0
        cryptoInfo.pk.curve25519generic.priv = priv;
1363
0
        cryptoInfo.pk.curve25519generic.privSz = (word32)private_size;
1364
0
        cryptoInfo.pk.curve25519generic.basepoint = basepoint;
1365
0
        cryptoInfo.pk.curve25519generic.basepointSz = (word32)basepoint_size;
1366
1367
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1368
0
    }
1369
1370
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1371
0
}
1372
#endif /* HAVE_CURVE25519 */
1373
1374
#ifdef HAVE_ED25519
1375
int wc_CryptoCb_Ed25519Gen(WC_RNG* rng, int keySize,
1376
    ed25519_key* key)
1377
0
{
1378
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1379
0
    CryptoCb* dev;
1380
1381
0
    if (key == NULL)
1382
0
        return ret;
1383
1384
    /* locate registered callback */
1385
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1386
0
    if (dev && dev->cb) {
1387
0
        wc_CryptoInfo cryptoInfo;
1388
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1389
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1390
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED25519_KEYGEN;
1391
0
        cryptoInfo.pk.ed25519kg.rng = rng;
1392
0
        cryptoInfo.pk.ed25519kg.size = keySize;
1393
0
        cryptoInfo.pk.ed25519kg.key = key;
1394
1395
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1396
0
    }
1397
1398
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1399
0
}
1400
1401
int wc_CryptoCb_Ed25519Sign(const byte* in, word32 inLen, byte* out,
1402
                            word32 *outLen, ed25519_key* key, byte type,
1403
                            const byte* context, byte contextLen)
1404
0
{
1405
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1406
0
    CryptoCb* dev;
1407
1408
0
    if (key == NULL)
1409
0
        return ret;
1410
1411
    /* locate registered callback */
1412
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1413
0
    if (dev && dev->cb) {
1414
0
        wc_CryptoInfo cryptoInfo;
1415
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1416
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1417
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED25519_SIGN;
1418
0
        cryptoInfo.pk.ed25519sign.in = in;
1419
0
        cryptoInfo.pk.ed25519sign.inLen = inLen;
1420
0
        cryptoInfo.pk.ed25519sign.out = out;
1421
0
        cryptoInfo.pk.ed25519sign.outLen = outLen;
1422
0
        cryptoInfo.pk.ed25519sign.key = key;
1423
0
        cryptoInfo.pk.ed25519sign.type = type;
1424
0
        cryptoInfo.pk.ed25519sign.context = context;
1425
0
        cryptoInfo.pk.ed25519sign.contextLen = contextLen;
1426
1427
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1428
0
    }
1429
1430
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1431
0
}
1432
1433
int wc_CryptoCb_Ed25519Verify(const byte* sig, word32 sigLen,
1434
    const byte* msg, word32 msgLen, int* res, ed25519_key* key, byte type,
1435
    const byte* context, byte contextLen)
1436
0
{
1437
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1438
0
    CryptoCb* dev;
1439
1440
0
    if (key == NULL)
1441
0
        return ret;
1442
1443
    /* locate registered callback */
1444
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1445
0
    if (dev && dev->cb) {
1446
0
        wc_CryptoInfo cryptoInfo;
1447
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1448
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1449
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED25519_VERIFY;
1450
0
        cryptoInfo.pk.ed25519verify.sig = sig;
1451
0
        cryptoInfo.pk.ed25519verify.sigLen = sigLen;
1452
0
        cryptoInfo.pk.ed25519verify.msg = msg;
1453
0
        cryptoInfo.pk.ed25519verify.msgLen = msgLen;
1454
0
        cryptoInfo.pk.ed25519verify.res = res;
1455
0
        cryptoInfo.pk.ed25519verify.key = key;
1456
0
        cryptoInfo.pk.ed25519verify.type = type;
1457
0
        cryptoInfo.pk.ed25519verify.context = context;
1458
0
        cryptoInfo.pk.ed25519verify.contextLen = contextLen;
1459
1460
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1461
0
    }
1462
1463
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1464
0
}
1465
1466
int wc_CryptoCb_Ed25519MakePub(ed25519_key* key, byte* pubKey, word32 pubKeySz)
1467
0
{
1468
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1469
0
    CryptoCb* dev;
1470
1471
0
    if (key == NULL || pubKey == NULL || pubKeySz != ED25519_PUB_KEY_SIZE)
1472
0
        return ret;
1473
1474
    /* locate registered callback */
1475
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1476
0
    if (dev && dev->cb) {
1477
0
        wc_CryptoInfo cryptoInfo;
1478
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1479
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1480
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED25519_MAKE_PUB;
1481
0
        cryptoInfo.pk.ed25519makepub.key = key;
1482
0
        cryptoInfo.pk.ed25519makepub.pubOut = pubKey;
1483
0
        cryptoInfo.pk.ed25519makepub.pubOutSz = pubKeySz;
1484
1485
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1486
0
    }
1487
1488
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1489
0
}
1490
1491
int wc_CryptoCb_Ed25519CheckKey(ed25519_key* key)
1492
0
{
1493
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1494
0
    CryptoCb* dev;
1495
1496
0
    if (key == NULL)
1497
0
        return ret;
1498
1499
    /* locate registered callback */
1500
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1501
0
    if (dev && dev->cb) {
1502
0
        wc_CryptoInfo cryptoInfo;
1503
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1504
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1505
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED25519_CHECK_KEY;
1506
0
        cryptoInfo.pk.ed25519checkkey.key = key;
1507
        /* key->p is already the compressed wire form; cross it as bytes so a
1508
         * device can validate the actual input without touching key internals
1509
         */
1510
0
        cryptoInfo.pk.ed25519checkkey.pubKey = key->p;
1511
0
        cryptoInfo.pk.ed25519checkkey.pubKeySz = ED25519_PUB_KEY_SIZE;
1512
0
        cryptoInfo.pk.ed25519checkkey.checkPriv = key->privKeySet ? 1 : 0;
1513
1514
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1515
0
    }
1516
1517
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1518
0
}
1519
#endif /* HAVE_ED25519 */
1520
1521
#ifdef HAVE_CURVE448
1522
int wc_CryptoCb_Curve448Gen(WC_RNG* rng, int keySize,
1523
    curve448_key* key)
1524
0
{
1525
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1526
0
    CryptoCb* dev;
1527
1528
0
    if (key == NULL)
1529
0
        return ret;
1530
1531
    /* locate registered callback */
1532
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1533
0
    if (dev && dev->cb) {
1534
0
        wc_CryptoInfo cryptoInfo;
1535
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1536
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1537
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE448_KEYGEN;
1538
0
        cryptoInfo.pk.curve448kg.rng = rng;
1539
0
        cryptoInfo.pk.curve448kg.size = keySize;
1540
0
        cryptoInfo.pk.curve448kg.key = key;
1541
1542
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1543
0
    }
1544
1545
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1546
0
}
1547
1548
int wc_CryptoCb_Curve448(curve448_key* private_key,
1549
    curve448_key* public_key, byte* out, word32* outlen, int endian)
1550
0
{
1551
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1552
0
    CryptoCb* dev;
1553
1554
0
    if (private_key == NULL)
1555
0
        return ret;
1556
1557
    /* locate registered callback */
1558
0
    dev = wc_CryptoCb_FindDevice(private_key->devId, WC_ALGO_TYPE_PK);
1559
0
    if (dev && dev->cb) {
1560
0
        wc_CryptoInfo cryptoInfo;
1561
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1562
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1563
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE448;
1564
0
        cryptoInfo.pk.curve448.private_key = private_key;
1565
0
        cryptoInfo.pk.curve448.public_key = public_key;
1566
0
        cryptoInfo.pk.curve448.out = out;
1567
0
        cryptoInfo.pk.curve448.outlen = outlen;
1568
0
        cryptoInfo.pk.curve448.endian = endian;
1569
1570
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1571
0
    }
1572
1573
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1574
0
}
1575
1576
int wc_CryptoCb_Curve448MakePub(int devId, int public_size, byte* pub,
1577
    int private_size, const byte* priv)
1578
0
{
1579
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1580
0
    CryptoCb* dev;
1581
1582
0
    if (pub == NULL || priv == NULL)
1583
0
        return ret;
1584
1585
    /* locate registered callback */
1586
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1587
    /* only a caller that selected no device settles for the first registered
1588
     * one; a devId names the single device allowed to see the scalar */
1589
0
    if ((dev == NULL || dev->cb == NULL) && (devId == INVALID_DEVID))
1590
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
1591
0
    if (dev && dev->cb) {
1592
0
        wc_CryptoInfo cryptoInfo;
1593
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1594
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1595
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE448_MAKE_PUB;
1596
0
        cryptoInfo.pk.curve448makepub.pub = pub;
1597
0
        cryptoInfo.pk.curve448makepub.pubSz = (word32)public_size;
1598
0
        cryptoInfo.pk.curve448makepub.priv = priv;
1599
0
        cryptoInfo.pk.curve448makepub.privSz = (word32)private_size;
1600
1601
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1602
0
    }
1603
1604
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1605
0
}
1606
1607
int wc_CryptoCb_Curve448Generic(int devId, int public_size, byte* pub,
1608
    int private_size, const byte* priv, int basepoint_size,
1609
    const byte* basepoint)
1610
0
{
1611
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1612
0
    CryptoCb* dev;
1613
1614
0
    if (pub == NULL || priv == NULL || basepoint == NULL)
1615
0
        return ret;
1616
1617
    /* locate registered callback */
1618
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1619
    /* only a caller that selected no device settles for the first registered
1620
     * one; a devId names the single device allowed to see the scalar */
1621
0
    if ((dev == NULL || dev->cb == NULL) && (devId == INVALID_DEVID))
1622
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
1623
0
    if (dev && dev->cb) {
1624
0
        wc_CryptoInfo cryptoInfo;
1625
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1626
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1627
0
        cryptoInfo.pk.type = WC_PK_TYPE_CURVE448_GENERIC;
1628
0
        cryptoInfo.pk.curve448generic.pub = pub;
1629
0
        cryptoInfo.pk.curve448generic.pubSz = (word32)public_size;
1630
0
        cryptoInfo.pk.curve448generic.priv = priv;
1631
0
        cryptoInfo.pk.curve448generic.privSz = (word32)private_size;
1632
0
        cryptoInfo.pk.curve448generic.basepoint = basepoint;
1633
0
        cryptoInfo.pk.curve448generic.basepointSz = (word32)basepoint_size;
1634
1635
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1636
0
    }
1637
1638
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1639
0
}
1640
#endif /* HAVE_CURVE448 */
1641
1642
#ifdef HAVE_ED448
1643
int wc_CryptoCb_Ed448Sign(const byte* in, word32 inLen, byte* out,
1644
    word32 *outLen, ed448_key* key, byte type, const byte* context,
1645
    byte contextLen)
1646
0
{
1647
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1648
0
    CryptoCb* dev;
1649
1650
0
    if (key == NULL)
1651
0
        return ret;
1652
1653
    /* locate registered callback */
1654
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1655
0
    if (dev && dev->cb) {
1656
0
        wc_CryptoInfo cryptoInfo;
1657
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1658
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1659
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED448;
1660
0
        cryptoInfo.pk.ed448sign.in = in;
1661
0
        cryptoInfo.pk.ed448sign.inLen = inLen;
1662
0
        cryptoInfo.pk.ed448sign.out = out;
1663
0
        cryptoInfo.pk.ed448sign.outLen = outLen;
1664
0
        cryptoInfo.pk.ed448sign.key = key;
1665
0
        cryptoInfo.pk.ed448sign.type = type;
1666
0
        cryptoInfo.pk.ed448sign.context = context;
1667
0
        cryptoInfo.pk.ed448sign.contextLen = contextLen;
1668
1669
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1670
0
    }
1671
1672
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1673
0
}
1674
1675
int wc_CryptoCb_Ed448Verify(const byte* sig, word32 sigLen,
1676
    const byte* msg, word32 msgLen, int* res, ed448_key* key, byte type,
1677
    const byte* context, byte contextLen)
1678
0
{
1679
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1680
0
    CryptoCb* dev;
1681
1682
0
    if (key == NULL)
1683
0
        return ret;
1684
1685
    /* locate registered callback */
1686
0
    dev = wc_CryptoCb_FindDevice(key->devId, WC_ALGO_TYPE_PK);
1687
0
    if (dev && dev->cb) {
1688
0
        wc_CryptoInfo cryptoInfo;
1689
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1690
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1691
0
        cryptoInfo.pk.type = WC_PK_TYPE_ED448_VERIFY;
1692
0
        cryptoInfo.pk.ed448verify.sig = sig;
1693
0
        cryptoInfo.pk.ed448verify.sigLen = sigLen;
1694
0
        cryptoInfo.pk.ed448verify.msg = msg;
1695
0
        cryptoInfo.pk.ed448verify.msgLen = msgLen;
1696
0
        cryptoInfo.pk.ed448verify.res = res;
1697
0
        cryptoInfo.pk.ed448verify.key = key;
1698
0
        cryptoInfo.pk.ed448verify.type = type;
1699
0
        cryptoInfo.pk.ed448verify.context = context;
1700
0
        cryptoInfo.pk.ed448verify.contextLen = contextLen;
1701
1702
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1703
0
    }
1704
1705
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1706
0
}
1707
#endif /* HAVE_ED448 */
1708
1709
#if defined(WOLFSSL_HAVE_LMS) || defined(WOLFSSL_HAVE_XMSS)
1710
int wc_CryptoCb_PqcStatefulSigGetDevId(int type, void* key)
1711
{
1712
    int devId = INVALID_DEVID;
1713
1714
    if (key == NULL)
1715
        return devId;
1716
1717
#if defined(WOLFSSL_HAVE_LMS)
1718
    if (type == WC_PQC_STATEFUL_SIG_TYPE_LMS) {
1719
        devId = ((LmsKey*)key)->devId;
1720
    }
1721
#endif
1722
#if defined(WOLFSSL_HAVE_XMSS)
1723
    if (type == WC_PQC_STATEFUL_SIG_TYPE_XMSS) {
1724
        devId = ((XmssKey*)key)->devId;
1725
    }
1726
#endif
1727
1728
    return devId;
1729
}
1730
1731
int wc_CryptoCb_PqcStatefulSigKeyGen(int type, void* key, WC_RNG* rng)
1732
{
1733
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1734
    int devId = INVALID_DEVID;
1735
    CryptoCb* dev;
1736
1737
    if (key == NULL)
1738
        return ret;
1739
1740
    devId = wc_CryptoCb_PqcStatefulSigGetDevId(type, key);
1741
    if (devId == INVALID_DEVID)
1742
        return ret;
1743
1744
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1745
    if (dev && dev->cb) {
1746
        wc_CryptoInfo cryptoInfo;
1747
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1748
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1749
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_STATEFUL_SIG_KEYGEN;
1750
        cryptoInfo.pk.pqc_stateful_sig_kg.rng = rng;
1751
        cryptoInfo.pk.pqc_stateful_sig_kg.key = key;
1752
        cryptoInfo.pk.pqc_stateful_sig_kg.type = type;
1753
1754
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1755
    }
1756
1757
    return wc_CryptoCb_TranslateErrorCode(ret);
1758
}
1759
1760
int wc_CryptoCb_PqcStatefulSigSign(const byte* msg, word32 msgSz, byte* out,
1761
    word32* outSz, int type, void* key)
1762
{
1763
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1764
    int devId = INVALID_DEVID;
1765
    CryptoCb* dev;
1766
1767
    if (key == NULL)
1768
        return ret;
1769
1770
    devId = wc_CryptoCb_PqcStatefulSigGetDevId(type, key);
1771
    if (devId == INVALID_DEVID)
1772
        return ret;
1773
1774
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1775
    if (dev && dev->cb) {
1776
        wc_CryptoInfo cryptoInfo;
1777
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1778
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1779
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_STATEFUL_SIG_SIGN;
1780
        cryptoInfo.pk.pqc_stateful_sig_sign.msg = msg;
1781
        cryptoInfo.pk.pqc_stateful_sig_sign.msgSz = msgSz;
1782
        cryptoInfo.pk.pqc_stateful_sig_sign.out = out;
1783
        cryptoInfo.pk.pqc_stateful_sig_sign.outSz = outSz;
1784
        cryptoInfo.pk.pqc_stateful_sig_sign.key = key;
1785
        cryptoInfo.pk.pqc_stateful_sig_sign.type = type;
1786
1787
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1788
    }
1789
1790
    return wc_CryptoCb_TranslateErrorCode(ret);
1791
}
1792
1793
int wc_CryptoCb_PqcStatefulSigVerify(const byte* sig, word32 sigSz,
1794
    const byte* msg, word32 msgSz, int* res, int type, void* key)
1795
{
1796
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1797
    int devId = INVALID_DEVID;
1798
    CryptoCb* dev;
1799
1800
    if (key == NULL)
1801
        return ret;
1802
1803
    devId = wc_CryptoCb_PqcStatefulSigGetDevId(type, key);
1804
    if (devId == INVALID_DEVID)
1805
        return ret;
1806
1807
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1808
    if (dev && dev->cb) {
1809
        wc_CryptoInfo cryptoInfo;
1810
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1811
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1812
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_STATEFUL_SIG_VERIFY;
1813
        cryptoInfo.pk.pqc_stateful_sig_verify.sig = sig;
1814
        cryptoInfo.pk.pqc_stateful_sig_verify.sigSz = sigSz;
1815
        cryptoInfo.pk.pqc_stateful_sig_verify.msg = msg;
1816
        cryptoInfo.pk.pqc_stateful_sig_verify.msgSz = msgSz;
1817
        cryptoInfo.pk.pqc_stateful_sig_verify.res = res;
1818
        cryptoInfo.pk.pqc_stateful_sig_verify.key = key;
1819
        cryptoInfo.pk.pqc_stateful_sig_verify.type = type;
1820
1821
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1822
    }
1823
1824
    return wc_CryptoCb_TranslateErrorCode(ret);
1825
}
1826
1827
int wc_CryptoCb_PqcStatefulSigSigsLeft(int type, void* key, word32* sigsLeft)
1828
{
1829
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1830
    int devId = INVALID_DEVID;
1831
    CryptoCb* dev;
1832
1833
    if (key == NULL)
1834
        return ret;
1835
1836
    devId = wc_CryptoCb_PqcStatefulSigGetDevId(type, key);
1837
    if (devId == INVALID_DEVID)
1838
        return ret;
1839
1840
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1841
    if (dev && dev->cb) {
1842
        wc_CryptoInfo cryptoInfo;
1843
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1844
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1845
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_STATEFUL_SIG_SIGS_LEFT;
1846
        cryptoInfo.pk.pqc_stateful_sig_sigs_left.key = key;
1847
        cryptoInfo.pk.pqc_stateful_sig_sigs_left.sigsLeft = sigsLeft;
1848
        cryptoInfo.pk.pqc_stateful_sig_sigs_left.type = type;
1849
1850
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1851
    }
1852
1853
    return wc_CryptoCb_TranslateErrorCode(ret);
1854
}
1855
#endif /* WOLFSSL_HAVE_LMS || WOLFSSL_HAVE_XMSS */
1856
1857
#if defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_FRODOKEM)
1858
int wc_CryptoCb_PqcKemGetDevId(int type, void* key)
1859
0
{
1860
0
    int devId = INVALID_DEVID;
1861
1862
0
    if (key == NULL)
1863
0
        return devId;
1864
1865
    /* get devId */
1866
0
#ifdef WOLFSSL_HAVE_MLKEM
1867
0
    if (type == WC_PQC_KEM_TYPE_MLKEM) {
1868
0
        devId = ((MlKemKey*) key)->devId;
1869
0
    }
1870
0
#endif
1871
#ifdef WOLFSSL_HAVE_FRODOKEM
1872
    if (type == WC_PQC_KEM_TYPE_FRODOKEM) {
1873
        devId = ((FrodoKemKey*) key)->devId;
1874
    }
1875
#endif
1876
1877
0
    return devId;
1878
0
}
1879
1880
int wc_CryptoCb_MakePqcKemKey(WC_RNG* rng, int type, int keySize, void* key)
1881
0
{
1882
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1883
0
    int devId = INVALID_DEVID;
1884
0
    CryptoCb* dev;
1885
1886
0
    if (key == NULL)
1887
0
        return ret;
1888
1889
    /* get devId */
1890
0
    devId = wc_CryptoCb_PqcKemGetDevId(type, key);
1891
0
    if (devId == INVALID_DEVID)
1892
0
        return ret;
1893
1894
    /* locate registered callback */
1895
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1896
0
    if (dev && dev->cb) {
1897
0
        wc_CryptoInfo cryptoInfo;
1898
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1899
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1900
0
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_KEM_KEYGEN;
1901
0
        cryptoInfo.pk.pqc_kem_kg.rng = rng;
1902
0
        cryptoInfo.pk.pqc_kem_kg.size = keySize;
1903
0
        cryptoInfo.pk.pqc_kem_kg.key = key;
1904
0
        cryptoInfo.pk.pqc_kem_kg.type = type;
1905
1906
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1907
0
    }
1908
1909
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1910
0
}
1911
1912
int wc_CryptoCb_PqcEncapsulate(byte* ciphertext, word32 ciphertextLen,
1913
    byte* sharedSecret, word32 sharedSecretLen, WC_RNG* rng, int type,
1914
    void* key)
1915
0
{
1916
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1917
0
    int devId = INVALID_DEVID;
1918
0
    CryptoCb* dev;
1919
1920
0
    if (key == NULL)
1921
0
        return ret;
1922
1923
    /* get devId */
1924
0
    devId = wc_CryptoCb_PqcKemGetDevId(type, key);
1925
0
    if (devId == INVALID_DEVID)
1926
0
        return ret;
1927
1928
    /* locate registered callback */
1929
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1930
0
    if (dev && dev->cb) {
1931
0
        wc_CryptoInfo cryptoInfo;
1932
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1933
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1934
0
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_KEM_ENCAPS;
1935
0
        cryptoInfo.pk.pqc_encaps.ciphertext = ciphertext;
1936
0
        cryptoInfo.pk.pqc_encaps.ciphertextLen = ciphertextLen;
1937
0
        cryptoInfo.pk.pqc_encaps.sharedSecret = sharedSecret;
1938
0
        cryptoInfo.pk.pqc_encaps.sharedSecretLen = sharedSecretLen;
1939
0
        cryptoInfo.pk.pqc_encaps.rng = rng;
1940
0
        cryptoInfo.pk.pqc_encaps.key = key;
1941
0
        cryptoInfo.pk.pqc_encaps.type = type;
1942
1943
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1944
0
    }
1945
1946
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1947
0
}
1948
1949
int wc_CryptoCb_PqcDecapsulate(const byte* ciphertext, word32 ciphertextLen,
1950
    byte* sharedSecret, word32 sharedSecretLen, int type, void* key)
1951
0
{
1952
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
1953
0
    int devId = INVALID_DEVID;
1954
0
    CryptoCb* dev;
1955
1956
0
    if (key == NULL)
1957
0
        return ret;
1958
1959
    /* get devId */
1960
0
    devId = wc_CryptoCb_PqcKemGetDevId(type, key);
1961
0
    if (devId == INVALID_DEVID)
1962
0
        return ret;
1963
1964
    /* locate registered callback */
1965
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
1966
0
    if (dev && dev->cb) {
1967
0
        wc_CryptoInfo cryptoInfo;
1968
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
1969
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
1970
0
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_KEM_DECAPS;
1971
0
        cryptoInfo.pk.pqc_decaps.ciphertext = ciphertext;
1972
0
        cryptoInfo.pk.pqc_decaps.ciphertextLen = ciphertextLen;
1973
0
        cryptoInfo.pk.pqc_decaps.sharedSecret = sharedSecret;
1974
0
        cryptoInfo.pk.pqc_decaps.sharedSecretLen = sharedSecretLen;
1975
0
        cryptoInfo.pk.pqc_decaps.key = key;
1976
0
        cryptoInfo.pk.pqc_decaps.type = type;
1977
1978
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
1979
0
    }
1980
1981
0
    return wc_CryptoCb_TranslateErrorCode(ret);
1982
0
}
1983
#endif /* WOLFSSL_HAVE_MLKEM || WOLFSSL_HAVE_FRODOKEM */
1984
1985
#if defined(HAVE_FALCON) || defined(WOLFSSL_HAVE_MLDSA) || \
1986
    defined(WOLFSSL_HAVE_SLHDSA)
1987
int wc_CryptoCb_PqcSigGetDevId(int type, void* key)
1988
{
1989
    int devId = INVALID_DEVID;
1990
1991
    if (key == NULL)
1992
        return devId;
1993
1994
    /* get devId */
1995
#if defined(WOLFSSL_HAVE_MLDSA)
1996
    if (type == WC_PQC_SIG_TYPE_MLDSA) {
1997
        devId = ((wc_MlDsaKey*) key)->devId;
1998
    }
1999
#endif
2000
#if defined(HAVE_FALCON)
2001
    if (type == WC_PQC_SIG_TYPE_FALCON) {
2002
        devId = ((falcon_key*) key)->devId;
2003
    }
2004
#endif
2005
#if defined(WOLFSSL_HAVE_SLHDSA)
2006
    if (type == WC_PQC_SIG_TYPE_SLHDSA) {
2007
        devId = ((SlhDsaKey*) key)->devId;
2008
    }
2009
#endif
2010
2011
    return devId;
2012
}
2013
2014
int wc_CryptoCb_MakePqcSignatureKey(WC_RNG* rng, int type, int keySize,
2015
    void* key)
2016
{
2017
    return wc_CryptoCb_MakePqcSignatureKeyEx(rng, type, keySize, NULL, 0, key);
2018
}
2019
2020
int wc_CryptoCb_MakePqcSignatureKeyEx(WC_RNG* rng, int type, int keySize,
2021
    const byte* seed, word32 seedSz, void* key)
2022
{
2023
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2024
    int devId = INVALID_DEVID;
2025
    CryptoCb* dev;
2026
2027
    if (key == NULL)
2028
        return ret;
2029
2030
    /* get devId; an unbound key still goes through the find callback */
2031
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2032
#ifndef WOLF_CRYPTO_CB_FIND
2033
    if (devId == INVALID_DEVID)
2034
        return ret;
2035
#endif
2036
2037
    /* locate registered callback. A slot sits at INVALID_DEVID while it is
2038
     * being registered or retired, so never dispatch through one. */
2039
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2040
    if (dev && dev->cb && (dev->devId != INVALID_DEVID)) {
2041
        wc_CryptoInfo cryptoInfo;
2042
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2043
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2044
        /* Seeded generation is a different operation: a device that does not
2045
         * know this type declines and the caller keeps the seed. */
2046
        cryptoInfo.pk.type = (seed != NULL) ? WC_PK_TYPE_PQC_SIG_KEYGEN_SEED :
2047
            WC_PK_TYPE_PQC_SIG_KEYGEN;
2048
        cryptoInfo.pk.pqc_sig_kg.rng = rng;
2049
        cryptoInfo.pk.pqc_sig_kg.size = keySize;
2050
        cryptoInfo.pk.pqc_sig_kg.key = key;
2051
        cryptoInfo.pk.pqc_sig_kg.type = type;
2052
        cryptoInfo.pk.pqc_sig_kg.seed = seed;
2053
        cryptoInfo.pk.pqc_sig_kg.seedSz = seedSz;
2054
2055
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2056
    }
2057
2058
    return wc_CryptoCb_TranslateErrorCode(ret);
2059
}
2060
2061
int wc_CryptoCb_PqcSign(const byte* in, word32 inlen, byte* out, word32 *outlen,
2062
    const byte* context, byte contextLen, word32 preHashType, WC_RNG* rng,
2063
    int type, void* key)
2064
{
2065
    return wc_CryptoCb_PqcSignEx(in, inlen, out, outlen, context, contextLen,
2066
        preHashType, rng, NULL, 0, type, key);
2067
}
2068
2069
int wc_CryptoCb_PqcSignEx(const byte* in, word32 inlen, byte* out,
2070
    word32 *outlen, const byte* context, byte contextLen, word32 preHashType,
2071
    WC_RNG* rng, const byte* addRnd, byte addRndSz, int type, void* key)
2072
{
2073
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2074
    int devId = INVALID_DEVID;
2075
    CryptoCb* dev;
2076
2077
    if (key == NULL)
2078
        return ret;
2079
2080
    /* get devId; an unbound key still goes through the find callback */
2081
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2082
2083
    /* locate registered callback */
2084
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2085
    if (dev && dev->cb) {
2086
        wc_CryptoInfo cryptoInfo;
2087
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2088
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2089
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_SIG_SIGN;
2090
        cryptoInfo.pk.pqc_sign.in = in;
2091
        cryptoInfo.pk.pqc_sign.inlen = inlen;
2092
        cryptoInfo.pk.pqc_sign.out = out;
2093
        cryptoInfo.pk.pqc_sign.outlen = outlen;
2094
        cryptoInfo.pk.pqc_sign.context = context;
2095
        cryptoInfo.pk.pqc_sign.contextLen = contextLen;
2096
        cryptoInfo.pk.pqc_sign.preHashType = preHashType;
2097
        cryptoInfo.pk.pqc_sign.rng = rng;
2098
        cryptoInfo.pk.pqc_sign.addRnd = addRnd;
2099
        cryptoInfo.pk.pqc_sign.addRndSz = addRndSz;
2100
        cryptoInfo.pk.pqc_sign.key = key;
2101
        cryptoInfo.pk.pqc_sign.type = type;
2102
2103
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2104
    }
2105
2106
    return wc_CryptoCb_TranslateErrorCode(ret);
2107
}
2108
2109
int wc_CryptoCb_PqcSignMsg(const byte* mprime, word32 mprimeSz, byte* out,
2110
    word32* outlen, WC_RNG* rng, const byte* addRnd, byte addRndSz, int type,
2111
    void* key)
2112
{
2113
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2114
    int devId = INVALID_DEVID;
2115
    CryptoCb* dev;
2116
2117
    if (key == NULL)
2118
        return ret;
2119
2120
    /* get devId; an unbound key still goes through the find callback */
2121
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2122
2123
    /* locate registered callback */
2124
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2125
    if (dev && dev->cb) {
2126
        wc_CryptoInfo cryptoInfo;
2127
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2128
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2129
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_SIG_SIGN_MSG;
2130
        cryptoInfo.pk.pqc_sign.in = mprime;
2131
        cryptoInfo.pk.pqc_sign.inlen = mprimeSz;
2132
        cryptoInfo.pk.pqc_sign.out = out;
2133
        cryptoInfo.pk.pqc_sign.outlen = outlen;
2134
        cryptoInfo.pk.pqc_sign.preHashType = WC_HASH_TYPE_NONE;
2135
        cryptoInfo.pk.pqc_sign.rng = rng;
2136
        cryptoInfo.pk.pqc_sign.addRnd = addRnd;
2137
        cryptoInfo.pk.pqc_sign.addRndSz = addRndSz;
2138
        cryptoInfo.pk.pqc_sign.key = key;
2139
        cryptoInfo.pk.pqc_sign.type = type;
2140
2141
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2142
    }
2143
2144
    return wc_CryptoCb_TranslateErrorCode(ret);
2145
}
2146
2147
int wc_CryptoCb_PqcVerify(const byte* sig, word32 siglen, const byte* msg,
2148
    word32 msglen, const byte* context, byte contextLen, word32 preHashType,
2149
    int* res, int type, void* key)
2150
{
2151
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2152
    int devId = INVALID_DEVID;
2153
    CryptoCb* dev;
2154
2155
    if (key == NULL)
2156
        return ret;
2157
2158
    /* get devId; an unbound key still goes through the find callback */
2159
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2160
2161
    /* locate registered callback */
2162
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2163
    if (dev && dev->cb) {
2164
        wc_CryptoInfo cryptoInfo;
2165
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2166
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2167
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_SIG_VERIFY;
2168
        cryptoInfo.pk.pqc_verify.sig = sig;
2169
        cryptoInfo.pk.pqc_verify.siglen = siglen;
2170
        cryptoInfo.pk.pqc_verify.msg = msg;
2171
        cryptoInfo.pk.pqc_verify.msglen = msglen;
2172
        cryptoInfo.pk.pqc_verify.context = context;
2173
        cryptoInfo.pk.pqc_verify.contextLen = contextLen;
2174
        cryptoInfo.pk.pqc_verify.preHashType = preHashType;
2175
        cryptoInfo.pk.pqc_verify.res = res;
2176
        cryptoInfo.pk.pqc_verify.key = key;
2177
        cryptoInfo.pk.pqc_verify.type = type;
2178
2179
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2180
    }
2181
2182
    return wc_CryptoCb_TranslateErrorCode(ret);
2183
}
2184
2185
int wc_CryptoCb_PqcVerifyMsg(const byte* sig, word32 siglen, const byte* mprime,
2186
    word32 mprimeSz, int* res, int type, void* key)
2187
{
2188
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2189
    int devId = INVALID_DEVID;
2190
    CryptoCb* dev;
2191
2192
    if (key == NULL)
2193
        return ret;
2194
2195
    /* get devId; an unbound key still goes through the find callback */
2196
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2197
2198
    /* locate registered callback */
2199
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2200
    if (dev && dev->cb) {
2201
        wc_CryptoInfo cryptoInfo;
2202
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2203
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2204
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_SIG_VERIFY_MSG;
2205
        cryptoInfo.pk.pqc_verify.sig = sig;
2206
        cryptoInfo.pk.pqc_verify.siglen = siglen;
2207
        cryptoInfo.pk.pqc_verify.msg = mprime;
2208
        cryptoInfo.pk.pqc_verify.msglen = mprimeSz;
2209
        cryptoInfo.pk.pqc_verify.preHashType = WC_HASH_TYPE_NONE;
2210
        cryptoInfo.pk.pqc_verify.res = res;
2211
        cryptoInfo.pk.pqc_verify.key = key;
2212
        cryptoInfo.pk.pqc_verify.type = type;
2213
2214
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2215
    }
2216
2217
    return wc_CryptoCb_TranslateErrorCode(ret);
2218
}
2219
2220
int wc_CryptoCb_PqcSignatureCheckPrivKey(void* key, int type,
2221
    const byte* pubKey, word32 pubKeySz)
2222
{
2223
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2224
    int devId = INVALID_DEVID;
2225
    CryptoCb* dev;
2226
2227
    if (key == NULL)
2228
        return ret;
2229
2230
    /* get devId; an unbound key still goes through the find callback */
2231
    devId = wc_CryptoCb_PqcSigGetDevId(type, key);
2232
2233
    /* locate registered callback */
2234
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_PK);
2235
    if (dev && dev->cb) {
2236
        wc_CryptoInfo cryptoInfo;
2237
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2238
        cryptoInfo.algo_type = WC_ALGO_TYPE_PK;
2239
        cryptoInfo.pk.type = WC_PK_TYPE_PQC_SIG_CHECK_PRIV_KEY;
2240
        cryptoInfo.pk.pqc_sig_check.key = key;
2241
        cryptoInfo.pk.pqc_sig_check.pubKey = pubKey;
2242
        cryptoInfo.pk.pqc_sig_check.pubKeySz = pubKeySz;
2243
        cryptoInfo.pk.pqc_sig_check.type = type;
2244
2245
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2246
    }
2247
2248
    return wc_CryptoCb_TranslateErrorCode(ret);
2249
}
2250
#endif /* HAVE_FALCON || WOLFSSL_HAVE_MLDSA || WOLFSSL_HAVE_SLHDSA */
2251
2252
#ifndef NO_AES
2253
#ifdef HAVE_AESGCM
2254
int wc_CryptoCb_AesGcmEncrypt(Aes* aes, byte* out,
2255
                               const byte* in, word32 sz,
2256
                               const byte* iv, word32 ivSz,
2257
                               byte* authTag, word32 authTagSz,
2258
                               const byte* authIn, word32 authInSz)
2259
0
{
2260
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2261
0
    CryptoCb* dev;
2262
2263
    /* locate registered callback */
2264
0
    if (aes) {
2265
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2266
0
    }
2267
0
    else {
2268
        /* locate first callback and try using it */
2269
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2270
0
    }
2271
2272
0
    if (dev && dev->cb) {
2273
0
        wc_CryptoInfo cryptoInfo;
2274
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2275
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2276
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_GCM;
2277
0
        cryptoInfo.cipher.enc = 1;
2278
0
        cryptoInfo.cipher.aesgcm_enc.aes       = aes;
2279
0
        cryptoInfo.cipher.aesgcm_enc.out       = out;
2280
0
        cryptoInfo.cipher.aesgcm_enc.in        = in;
2281
0
        cryptoInfo.cipher.aesgcm_enc.sz        = sz;
2282
0
        cryptoInfo.cipher.aesgcm_enc.iv        = iv;
2283
0
        cryptoInfo.cipher.aesgcm_enc.ivSz      = ivSz;
2284
0
        cryptoInfo.cipher.aesgcm_enc.authTag   = authTag;
2285
0
        cryptoInfo.cipher.aesgcm_enc.authTagSz = authTagSz;
2286
0
        cryptoInfo.cipher.aesgcm_enc.authIn    = authIn;
2287
0
        cryptoInfo.cipher.aesgcm_enc.authInSz  = authInSz;
2288
2289
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2290
0
    }
2291
2292
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2293
0
}
2294
2295
int wc_CryptoCb_AesGcmDecrypt(Aes* aes, byte* out,
2296
                               const byte* in, word32 sz,
2297
                               const byte* iv, word32 ivSz,
2298
                               const byte* authTag, word32 authTagSz,
2299
                               const byte* authIn, word32 authInSz)
2300
0
{
2301
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2302
0
    CryptoCb* dev;
2303
2304
    /* locate registered callback */
2305
0
    if (aes) {
2306
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2307
0
    }
2308
0
    else {
2309
        /* locate first callback and try using it */
2310
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2311
0
    }
2312
2313
0
    if (dev && dev->cb) {
2314
0
        wc_CryptoInfo cryptoInfo;
2315
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2316
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2317
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_GCM;
2318
0
        cryptoInfo.cipher.enc = 0;
2319
0
        cryptoInfo.cipher.aesgcm_dec.aes       = aes;
2320
0
        cryptoInfo.cipher.aesgcm_dec.out       = out;
2321
0
        cryptoInfo.cipher.aesgcm_dec.in        = in;
2322
0
        cryptoInfo.cipher.aesgcm_dec.sz        = sz;
2323
0
        cryptoInfo.cipher.aesgcm_dec.iv        = iv;
2324
0
        cryptoInfo.cipher.aesgcm_dec.ivSz      = ivSz;
2325
0
        cryptoInfo.cipher.aesgcm_dec.authTag   = authTag;
2326
0
        cryptoInfo.cipher.aesgcm_dec.authTagSz = authTagSz;
2327
0
        cryptoInfo.cipher.aesgcm_dec.authIn    = authIn;
2328
0
        cryptoInfo.cipher.aesgcm_dec.authInSz  = authInSz;
2329
2330
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2331
0
    }
2332
2333
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2334
0
}
2335
#endif /* HAVE_AESGCM */
2336
2337
#ifdef HAVE_AESCCM
2338
int wc_CryptoCb_AesCcmEncrypt(Aes* aes, byte* out,
2339
                               const byte* in, word32 sz,
2340
                               const byte* nonce, word32 nonceSz,
2341
                               byte* authTag, word32 authTagSz,
2342
                               const byte* authIn, word32 authInSz)
2343
0
{
2344
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2345
0
    CryptoCb* dev;
2346
2347
    /* locate registered callback */
2348
0
    if (aes) {
2349
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2350
0
    }
2351
0
    else {
2352
        /* locate first callback and try using it */
2353
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2354
0
    }
2355
2356
0
    if (dev && dev->cb) {
2357
0
        wc_CryptoInfo cryptoInfo;
2358
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2359
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2360
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CCM;
2361
0
        cryptoInfo.cipher.enc = 1;
2362
0
        cryptoInfo.cipher.aesccm_enc.aes       = aes;
2363
0
        cryptoInfo.cipher.aesccm_enc.out       = out;
2364
0
        cryptoInfo.cipher.aesccm_enc.in        = in;
2365
0
        cryptoInfo.cipher.aesccm_enc.sz        = sz;
2366
0
        cryptoInfo.cipher.aesccm_enc.nonce     = nonce;
2367
0
        cryptoInfo.cipher.aesccm_enc.nonceSz   = nonceSz;
2368
0
        cryptoInfo.cipher.aesccm_enc.authTag   = authTag;
2369
0
        cryptoInfo.cipher.aesccm_enc.authTagSz = authTagSz;
2370
0
        cryptoInfo.cipher.aesccm_enc.authIn    = authIn;
2371
0
        cryptoInfo.cipher.aesccm_enc.authInSz  = authInSz;
2372
2373
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2374
0
    }
2375
2376
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2377
0
}
2378
2379
int wc_CryptoCb_AesCcmDecrypt(Aes* aes, byte* out,
2380
                               const byte* in, word32 sz,
2381
                               const byte* nonce, word32 nonceSz,
2382
                               const byte* authTag, word32 authTagSz,
2383
                               const byte* authIn, word32 authInSz)
2384
0
{
2385
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2386
0
    CryptoCb* dev;
2387
2388
    /* locate registered callback */
2389
0
    if (aes) {
2390
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2391
0
    }
2392
0
    else {
2393
        /* locate first callback and try using it */
2394
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2395
0
    }
2396
2397
0
    if (dev && dev->cb) {
2398
0
        wc_CryptoInfo cryptoInfo;
2399
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2400
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2401
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CCM;
2402
0
        cryptoInfo.cipher.enc = 0;
2403
0
        cryptoInfo.cipher.aesccm_dec.aes       = aes;
2404
0
        cryptoInfo.cipher.aesccm_dec.out       = out;
2405
0
        cryptoInfo.cipher.aesccm_dec.in        = in;
2406
0
        cryptoInfo.cipher.aesccm_dec.sz        = sz;
2407
0
        cryptoInfo.cipher.aesccm_dec.nonce     = nonce;
2408
0
        cryptoInfo.cipher.aesccm_dec.nonceSz   = nonceSz;
2409
0
        cryptoInfo.cipher.aesccm_dec.authTag   = authTag;
2410
0
        cryptoInfo.cipher.aesccm_dec.authTagSz = authTagSz;
2411
0
        cryptoInfo.cipher.aesccm_dec.authIn    = authIn;
2412
0
        cryptoInfo.cipher.aesccm_dec.authInSz  = authInSz;
2413
2414
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2415
0
    }
2416
2417
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2418
0
}
2419
#endif /* HAVE_AESCCM */
2420
2421
#ifdef HAVE_AES_CBC
2422
int wc_CryptoCb_AesCbcEncrypt(Aes* aes, byte* out,
2423
                               const byte* in, word32 sz)
2424
0
{
2425
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2426
0
    CryptoCb* dev;
2427
2428
    /* locate registered callback */
2429
0
    if (aes) {
2430
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2431
0
    }
2432
0
    else {
2433
        /* locate first callback and try using it */
2434
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2435
0
    }
2436
2437
0
    if (dev && dev->cb) {
2438
0
        wc_CryptoInfo cryptoInfo;
2439
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2440
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2441
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CBC;
2442
0
        cryptoInfo.cipher.enc = 1;
2443
0
        cryptoInfo.cipher.aescbc.aes = aes;
2444
0
        cryptoInfo.cipher.aescbc.out = out;
2445
0
        cryptoInfo.cipher.aescbc.in = in;
2446
0
        cryptoInfo.cipher.aescbc.sz = sz;
2447
2448
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2449
0
    }
2450
2451
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2452
0
}
2453
2454
int wc_CryptoCb_AesCbcDecrypt(Aes* aes, byte* out,
2455
                               const byte* in, word32 sz)
2456
0
{
2457
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2458
0
    CryptoCb* dev;
2459
2460
    /* locate registered callback */
2461
0
    if (aes) {
2462
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2463
0
    }
2464
0
    else {
2465
        /* locate first callback and try using it */
2466
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2467
0
    }
2468
2469
0
    if (dev && dev->cb) {
2470
0
        wc_CryptoInfo cryptoInfo;
2471
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2472
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2473
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CBC;
2474
0
        cryptoInfo.cipher.enc = 0;
2475
0
        cryptoInfo.cipher.aescbc.aes = aes;
2476
0
        cryptoInfo.cipher.aescbc.out = out;
2477
0
        cryptoInfo.cipher.aescbc.in = in;
2478
0
        cryptoInfo.cipher.aescbc.sz = sz;
2479
2480
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2481
0
    }
2482
2483
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2484
0
}
2485
#endif /* HAVE_AES_CBC */
2486
#ifdef WOLFSSL_AES_COUNTER
2487
int wc_CryptoCb_AesCtrEncrypt(Aes* aes, byte* out,
2488
                               const byte* in, word32 sz)
2489
0
{
2490
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2491
0
    CryptoCb* dev;
2492
2493
    /* locate registered callback */
2494
0
    if (aes) {
2495
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2496
0
    }
2497
0
    else {
2498
        /* locate first callback and try using it */
2499
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2500
0
    }
2501
2502
0
    if (dev && dev->cb) {
2503
0
        wc_CryptoInfo cryptoInfo;
2504
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2505
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2506
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CTR;
2507
0
        cryptoInfo.cipher.enc = 1;
2508
0
        cryptoInfo.cipher.aesctr.aes = aes;
2509
0
        cryptoInfo.cipher.aesctr.out = out;
2510
0
        cryptoInfo.cipher.aesctr.in = in;
2511
0
        cryptoInfo.cipher.aesctr.sz = sz;
2512
2513
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2514
0
    }
2515
2516
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2517
0
}
2518
#endif /* WOLFSSL_AES_COUNTER */
2519
#ifdef WOLFSSL_AES_CFB
2520
int wc_CryptoCb_AesCfbEncrypt(Aes* aes, byte* out,
2521
                               const byte* in, word32 sz)
2522
0
{
2523
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2524
0
    CryptoCb* dev;
2525
2526
    /* locate registered callback */
2527
0
    if (aes) {
2528
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2529
0
    }
2530
0
    else {
2531
        /* locate first callback and try using it */
2532
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2533
0
    }
2534
2535
0
    if (dev && dev->cb) {
2536
0
        wc_CryptoInfo cryptoInfo;
2537
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2538
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2539
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CFB;
2540
0
        cryptoInfo.cipher.enc = 1;
2541
0
        cryptoInfo.cipher.aescfb.aes = aes;
2542
0
        cryptoInfo.cipher.aescfb.out = out;
2543
0
        cryptoInfo.cipher.aescfb.in = in;
2544
0
        cryptoInfo.cipher.aescfb.sz = sz;
2545
2546
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2547
0
    }
2548
2549
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2550
0
}
2551
2552
int wc_CryptoCb_AesCfbDecrypt(Aes* aes, byte* out,
2553
                               const byte* in, word32 sz)
2554
0
{
2555
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2556
0
    CryptoCb* dev;
2557
2558
    /* locate registered callback */
2559
0
    if (aes) {
2560
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2561
0
    }
2562
0
    else {
2563
        /* locate first callback and try using it */
2564
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2565
0
    }
2566
2567
0
    if (dev && dev->cb) {
2568
0
        wc_CryptoInfo cryptoInfo;
2569
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2570
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2571
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_CFB;
2572
0
        cryptoInfo.cipher.enc = 0;
2573
0
        cryptoInfo.cipher.aescfb.aes = aes;
2574
0
        cryptoInfo.cipher.aescfb.out = out;
2575
0
        cryptoInfo.cipher.aescfb.in = in;
2576
0
        cryptoInfo.cipher.aescfb.sz = sz;
2577
2578
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2579
0
    }
2580
2581
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2582
0
}
2583
#endif /* WOLFSSL_AES_CFB */
2584
#ifdef WOLFSSL_AES_OFB
2585
int wc_CryptoCb_AesOfbEncrypt(Aes* aes, byte* out,
2586
                               const byte* in, word32 sz)
2587
0
{
2588
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2589
0
    CryptoCb* dev;
2590
2591
    /* locate registered callback */
2592
0
    if (aes) {
2593
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2594
0
    }
2595
0
    else {
2596
        /* locate first callback and try using it */
2597
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2598
0
    }
2599
2600
0
    if (dev && dev->cb) {
2601
0
        wc_CryptoInfo cryptoInfo;
2602
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2603
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2604
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_OFB;
2605
0
        cryptoInfo.cipher.enc = 1;
2606
0
        cryptoInfo.cipher.aesofb.aes = aes;
2607
0
        cryptoInfo.cipher.aesofb.out = out;
2608
0
        cryptoInfo.cipher.aesofb.in = in;
2609
0
        cryptoInfo.cipher.aesofb.sz = sz;
2610
2611
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2612
0
    }
2613
2614
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2615
0
}
2616
2617
int wc_CryptoCb_AesOfbDecrypt(Aes* aes, byte* out,
2618
                               const byte* in, word32 sz)
2619
0
{
2620
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2621
0
    CryptoCb* dev;
2622
2623
    /* locate registered callback */
2624
0
    if (aes) {
2625
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2626
0
    }
2627
0
    else {
2628
        /* locate first callback and try using it */
2629
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2630
0
    }
2631
2632
0
    if (dev && dev->cb) {
2633
0
        wc_CryptoInfo cryptoInfo;
2634
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2635
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2636
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_OFB;
2637
0
        cryptoInfo.cipher.enc = 0;
2638
0
        cryptoInfo.cipher.aesofb.aes = aes;
2639
0
        cryptoInfo.cipher.aesofb.out = out;
2640
0
        cryptoInfo.cipher.aesofb.in = in;
2641
0
        cryptoInfo.cipher.aesofb.sz = sz;
2642
2643
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2644
0
    }
2645
2646
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2647
0
}
2648
#endif /* WOLFSSL_AES_OFB */
2649
#if defined(HAVE_AES_ECB) || defined(WOLFSSL_AES_DIRECT) || \
2650
    defined(WOLF_CRYPTO_CB_ONLY_AES)
2651
int wc_CryptoCb_AesEcbEncrypt(Aes* aes, byte* out,
2652
                               const byte* in, word32 sz)
2653
126
{
2654
126
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2655
126
    CryptoCb* dev;
2656
2657
    /* locate registered callback */
2658
126
    if (aes) {
2659
126
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2660
126
    }
2661
0
    else {
2662
        /* locate first callback and try using it */
2663
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2664
0
    }
2665
2666
126
    if (dev && dev->cb) {
2667
0
        wc_CryptoInfo cryptoInfo;
2668
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2669
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2670
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_ECB;
2671
0
        cryptoInfo.cipher.enc = 1;
2672
0
        cryptoInfo.cipher.aesecb.aes = aes;
2673
0
        cryptoInfo.cipher.aesecb.out = out;
2674
0
        cryptoInfo.cipher.aesecb.in = in;
2675
0
        cryptoInfo.cipher.aesecb.sz = sz;
2676
2677
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2678
0
    }
2679
2680
126
    return wc_CryptoCb_TranslateErrorCode(ret);
2681
126
}
2682
2683
int wc_CryptoCb_AesEcbDecrypt(Aes* aes, byte* out,
2684
                               const byte* in, word32 sz)
2685
256
{
2686
256
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2687
256
    CryptoCb* dev;
2688
2689
    /* locate registered callback */
2690
256
    if (aes) {
2691
256
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2692
256
    }
2693
0
    else {
2694
        /* locate first callback and try using it */
2695
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2696
0
    }
2697
2698
256
    if (dev && dev->cb) {
2699
0
        wc_CryptoInfo cryptoInfo;
2700
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2701
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2702
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_ECB;
2703
0
        cryptoInfo.cipher.enc = 0;
2704
0
        cryptoInfo.cipher.aesecb.aes = aes;
2705
0
        cryptoInfo.cipher.aesecb.out = out;
2706
0
        cryptoInfo.cipher.aesecb.in = in;
2707
0
        cryptoInfo.cipher.aesecb.sz = sz;
2708
2709
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2710
0
    }
2711
2712
256
    return wc_CryptoCb_TranslateErrorCode(ret);
2713
256
}
2714
#endif /* HAVE_AES_ECB || WOLFSSL_AES_DIRECT || WOLF_CRYPTO_CB_ONLY_AES */
2715
2716
#ifdef HAVE_AES_KEYWRAP
2717
/* On success returns the number of output bytes produced (the callback reports
2718
 * it via aeskeywrap.outResSz), otherwise a negative error or
2719
 * CRYPTOCB_UNAVAILABLE. pad selects RFC 5649 (1) vs RFC 3394 (0). */
2720
int wc_CryptoCb_AesKeyWrap(Aes* aes, const byte* in, word32 inSz, byte* out,
2721
    word32 outSz, const byte* iv, int pad)
2722
0
{
2723
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2724
0
    CryptoCb* dev;
2725
2726
    /* locate registered callback */
2727
0
    if (aes) {
2728
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2729
0
    }
2730
0
    else {
2731
        /* locate first callback and try using it */
2732
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2733
0
    }
2734
2735
0
    if (dev && dev->cb) {
2736
0
        wc_CryptoInfo cryptoInfo;
2737
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2738
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2739
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_KEYWRAP;
2740
0
        cryptoInfo.cipher.enc = 1;
2741
0
        cryptoInfo.cipher.aeskeywrap.aes = aes;
2742
0
        cryptoInfo.cipher.aeskeywrap.in = in;
2743
0
        cryptoInfo.cipher.aeskeywrap.inSz = inSz;
2744
0
        cryptoInfo.cipher.aeskeywrap.out = out;
2745
0
        cryptoInfo.cipher.aeskeywrap.outSz = outSz;
2746
0
        cryptoInfo.cipher.aeskeywrap.iv = iv;
2747
0
        cryptoInfo.cipher.aeskeywrap.pad = pad;
2748
2749
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2750
0
        if (ret == 0) {
2751
            /* device reports the wrapped length */
2752
0
            if (cryptoInfo.cipher.aeskeywrap.outResSz > outSz) {
2753
0
                return BUFFER_E;
2754
0
            }
2755
0
            return (int)cryptoInfo.cipher.aeskeywrap.outResSz;
2756
0
        }
2757
0
    }
2758
2759
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2760
0
}
2761
2762
int wc_CryptoCb_AesKeyUnWrap(Aes* aes, const byte* in, word32 inSz, byte* out,
2763
    word32 outSz, const byte* iv, int pad)
2764
0
{
2765
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2766
0
    CryptoCb* dev;
2767
2768
    /* locate registered callback */
2769
0
    if (aes) {
2770
0
        dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2771
0
    }
2772
0
    else {
2773
        /* locate first callback and try using it */
2774
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2775
0
    }
2776
2777
0
    if (dev && dev->cb) {
2778
0
        wc_CryptoInfo cryptoInfo;
2779
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2780
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2781
0
        cryptoInfo.cipher.type = WC_CIPHER_AES_KEYWRAP;
2782
0
        cryptoInfo.cipher.enc = 0;
2783
0
        cryptoInfo.cipher.aeskeywrap.aes = aes;
2784
0
        cryptoInfo.cipher.aeskeywrap.in = in;
2785
0
        cryptoInfo.cipher.aeskeywrap.inSz = inSz;
2786
0
        cryptoInfo.cipher.aeskeywrap.out = out;
2787
0
        cryptoInfo.cipher.aeskeywrap.outSz = outSz;
2788
0
        cryptoInfo.cipher.aeskeywrap.iv = iv;
2789
0
        cryptoInfo.cipher.aeskeywrap.pad = pad;
2790
2791
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2792
0
        if (ret == 0) {
2793
            /* device reports the recovered length */
2794
0
            if (cryptoInfo.cipher.aeskeywrap.outResSz > outSz) {
2795
0
                return BUFFER_E;
2796
0
            }
2797
0
            return (int)cryptoInfo.cipher.aeskeywrap.outResSz;
2798
0
        }
2799
0
    }
2800
2801
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2802
0
}
2803
#endif /* HAVE_AES_KEYWRAP */
2804
2805
#ifdef WOLF_CRYPTO_CB_AES_SETKEY
2806
int wc_CryptoCb_AesSetKey(Aes* aes, const byte* key, word32 keySz)
2807
{
2808
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2809
    CryptoCb* dev;
2810
2811
    if (aes == NULL || key == NULL)
2812
        return BAD_FUNC_ARG;
2813
2814
    if (aes->devId == INVALID_DEVID)
2815
        return CRYPTOCB_UNAVAILABLE;
2816
2817
    /* locate registered callback */
2818
    dev = wc_CryptoCb_FindDevice(aes->devId, WC_ALGO_TYPE_CIPHER);
2819
    if (dev && dev->cb) {
2820
        wc_CryptoInfo cryptoInfo;
2821
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2822
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2823
        cryptoInfo.cipher.type = WC_CIPHER_AES;
2824
        cryptoInfo.cipher.aessetkey.aes = aes;
2825
        cryptoInfo.cipher.aessetkey.key = key;
2826
        cryptoInfo.cipher.aessetkey.keySz = keySz;
2827
2828
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2829
    }
2830
2831
    return wc_CryptoCb_TranslateErrorCode(ret);
2832
}
2833
#endif /* WOLF_CRYPTO_CB_AES_SETKEY */
2834
#endif /* !NO_AES */
2835
2836
#ifndef NO_DES3
2837
int wc_CryptoCb_Des3Encrypt(Des3* des3, byte* out,
2838
                               const byte* in, word32 sz)
2839
335
{
2840
335
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2841
335
    CryptoCb* dev;
2842
2843
    /* locate registered callback */
2844
335
    if (des3) {
2845
335
        dev = wc_CryptoCb_FindDevice(des3->devId, WC_ALGO_TYPE_CIPHER);
2846
335
    }
2847
0
    else {
2848
        /* locate first callback and try using it */
2849
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2850
0
    }
2851
2852
335
    if (dev && dev->cb) {
2853
0
        wc_CryptoInfo cryptoInfo;
2854
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2855
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2856
0
        cryptoInfo.cipher.type = WC_CIPHER_DES3;
2857
0
        cryptoInfo.cipher.enc = 1;
2858
0
        cryptoInfo.cipher.des3.des = des3;
2859
0
        cryptoInfo.cipher.des3.out = out;
2860
0
        cryptoInfo.cipher.des3.in = in;
2861
0
        cryptoInfo.cipher.des3.sz = sz;
2862
2863
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2864
0
    }
2865
2866
335
    return wc_CryptoCb_TranslateErrorCode(ret);
2867
335
}
2868
2869
int wc_CryptoCb_Des3Decrypt(Des3* des3, byte* out,
2870
                               const byte* in, word32 sz)
2871
117
{
2872
117
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2873
117
    CryptoCb* dev;
2874
2875
    /* locate registered callback */
2876
117
    if (des3) {
2877
117
        dev = wc_CryptoCb_FindDevice(des3->devId, WC_ALGO_TYPE_CIPHER);
2878
117
    }
2879
0
    else {
2880
        /* locate first callback and try using it */
2881
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2882
0
    }
2883
2884
117
    if (dev && dev->cb) {
2885
0
        wc_CryptoInfo cryptoInfo;
2886
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2887
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CIPHER;
2888
0
        cryptoInfo.cipher.type = WC_CIPHER_DES3;
2889
0
        cryptoInfo.cipher.enc = 0;
2890
0
        cryptoInfo.cipher.des3.des = des3;
2891
0
        cryptoInfo.cipher.des3.out = out;
2892
0
        cryptoInfo.cipher.des3.in = in;
2893
0
        cryptoInfo.cipher.des3.sz = sz;
2894
2895
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2896
0
    }
2897
2898
117
    return wc_CryptoCb_TranslateErrorCode(ret);
2899
117
}
2900
#endif /* !NO_DES3 */
2901
2902
#ifndef NO_SHA
2903
int wc_CryptoCb_ShaHash(wc_Sha* sha, const byte* in,
2904
    word32 inSz, byte* digest)
2905
0
{
2906
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2907
0
    CryptoCb* dev;
2908
2909
    /* locate registered callback */
2910
0
    if (sha) {
2911
0
        dev = wc_CryptoCb_FindDevice(sha->devId, WC_ALGO_TYPE_HASH);
2912
0
    }
2913
0
    else {
2914
        /* locate first callback and try using it */
2915
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2916
0
    }
2917
2918
0
    if (dev && dev->cb) {
2919
0
        wc_CryptoInfo cryptoInfo;
2920
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2921
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
2922
0
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA;
2923
0
        cryptoInfo.hash.sha1 = sha;
2924
0
        cryptoInfo.hash.in = in;
2925
0
        cryptoInfo.hash.inSz = inSz;
2926
0
        cryptoInfo.hash.digest = digest;
2927
2928
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2929
0
    }
2930
2931
0
    return wc_CryptoCb_TranslateErrorCode(ret);
2932
0
}
2933
#endif /* !NO_SHA */
2934
2935
#ifdef WOLFSSL_SHA224
2936
int wc_CryptoCb_Sha224Hash(wc_Sha224* sha224, const byte* in,
2937
    word32 inSz, byte* digest)
2938
234
{
2939
234
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2940
234
    CryptoCb* dev;
2941
2942
    /* locate registered callback */
2943
234
    if (sha224) {
2944
234
        dev = wc_CryptoCb_FindDevice(sha224->devId, WC_ALGO_TYPE_HASH);
2945
234
    }
2946
0
    else {
2947
        /* locate first callback and try using it */
2948
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2949
0
    }
2950
2951
234
    if (dev && dev->cb) {
2952
0
        wc_CryptoInfo cryptoInfo;
2953
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2954
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
2955
0
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA224;
2956
0
        cryptoInfo.hash.sha224 = sha224;
2957
0
        cryptoInfo.hash.in = in;
2958
0
        cryptoInfo.hash.inSz = inSz;
2959
0
        cryptoInfo.hash.digest = digest;
2960
2961
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2962
0
    }
2963
2964
234
    return wc_CryptoCb_TranslateErrorCode(ret);
2965
234
}
2966
#endif /* WOLFSSL_SHA224 */
2967
2968
2969
#ifndef NO_SHA256
2970
int wc_CryptoCb_Sha256Hash(wc_Sha256* sha256, const byte* in,
2971
    word32 inSz, byte* digest)
2972
173
{
2973
173
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
2974
173
    CryptoCb* dev;
2975
2976
    /* locate registered callback */
2977
173
    if (sha256) {
2978
173
        dev = wc_CryptoCb_FindDevice(sha256->devId, WC_ALGO_TYPE_HASH);
2979
173
    }
2980
0
    else {
2981
        /* locate first callback and try using it */
2982
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
2983
0
    }
2984
2985
173
    if (dev && dev->cb) {
2986
0
        wc_CryptoInfo cryptoInfo;
2987
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
2988
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
2989
0
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA256;
2990
0
        cryptoInfo.hash.sha256 = sha256;
2991
0
        cryptoInfo.hash.in = in;
2992
0
        cryptoInfo.hash.inSz = inSz;
2993
0
        cryptoInfo.hash.digest = digest;
2994
2995
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
2996
0
    }
2997
2998
173
    return wc_CryptoCb_TranslateErrorCode(ret);
2999
173
}
3000
#endif /* !NO_SHA256 */
3001
3002
#ifdef WOLFSSL_SHA384
3003
int wc_CryptoCb_Sha384Hash(wc_Sha384* sha384, const byte* in,
3004
    word32 inSz, byte* digest)
3005
3.43k
{
3006
3.43k
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3007
3.43k
    CryptoCb* dev;
3008
3009
    /* locate registered callback */
3010
3.43k
    #ifndef NO_SHA2_CRYPTO_CB
3011
3.43k
    if (sha384) {
3012
3.43k
        dev = wc_CryptoCb_FindDevice(sha384->devId, WC_ALGO_TYPE_HASH);
3013
3.43k
    }
3014
0
    else
3015
0
    #endif
3016
0
    {
3017
        /* locate first callback and try using it */
3018
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3019
0
    }
3020
3021
3.43k
    if (dev && dev->cb) {
3022
0
    #if defined(WOLFSSL_SHA512) && !defined(WOLF_CRYPTO_CB_NO_SHA512_FALLBACK)
3023
0
        byte localHash[WC_SHA512_DIGEST_SIZE];
3024
0
    #endif
3025
0
        wc_CryptoInfo cryptoInfo;
3026
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3027
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
3028
0
        cryptoInfo.hash.in = in;
3029
0
        cryptoInfo.hash.inSz = inSz;
3030
3031
        /* try the SHA-384 callback first */
3032
0
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA384;
3033
0
        cryptoInfo.hash.sha384 = sha384;
3034
0
        cryptoInfo.hash.digest = digest;
3035
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3036
0
        ret = wc_CryptoCb_TranslateErrorCode(ret);
3037
0
        if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
3038
0
            return ret;
3039
3040
0
    #if defined(WOLFSSL_SHA512) && !defined(WOLF_CRYPTO_CB_NO_SHA512_FALLBACK)
3041
        /* fall back to the SHA-512 core: SHA-384 is the SHA-512 core with a
3042
         * different IV (in the caller-supplied state) and a 48-byte
3043
         * truncation done here */
3044
0
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA512;
3045
0
        cryptoInfo.hash.sha512 = (wc_Sha512*)sha384;
3046
        /* use local buffer for the final digest so we can truncate */
3047
0
        if (digest != NULL)
3048
0
            cryptoInfo.hash.digest = localHash;
3049
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3050
0
        ret = wc_CryptoCb_TranslateErrorCode(ret);
3051
0
        if (ret == 0 && digest != NULL) {
3052
0
            XMEMCPY(digest, localHash, WC_SHA384_DIGEST_SIZE);
3053
            /* the SHA-512 callback left the SHA-512 IV in the state; write
3054
             * the SHA-384 IV back so the struct is ready for reuse */
3055
0
            if (sha384 != NULL) {
3056
0
                sha384->digest[0] = W64LIT(0xcbbb9d5dc1059ed8);
3057
0
                sha384->digest[1] = W64LIT(0x629a292a367cd507);
3058
0
                sha384->digest[2] = W64LIT(0x9159015a3070dd17);
3059
0
                sha384->digest[3] = W64LIT(0x152fecd8f70e5939);
3060
0
                sha384->digest[4] = W64LIT(0x67332667ffc00b31);
3061
0
                sha384->digest[5] = W64LIT(0x8eb44a8768581511);
3062
0
                sha384->digest[6] = W64LIT(0xdb0c2e0d64f98fa7);
3063
0
                sha384->digest[7] = W64LIT(0x47b5481dbefa4fa4);
3064
0
            }
3065
0
        }
3066
0
        return ret;
3067
0
    #endif /* WOLFSSL_SHA512 && !WOLF_CRYPTO_CB_NO_SHA512_FALLBACK */
3068
0
    }
3069
3070
3.43k
    return wc_CryptoCb_TranslateErrorCode(ret);
3071
3.43k
}
3072
#endif /* WOLFSSL_SHA384 */
3073
3074
#ifdef WOLFSSL_SHA512
3075
int wc_CryptoCb_Sha512Hash(wc_Sha512* sha512, const byte* in,
3076
    word32 inSz, byte* digest
3077
#if !(defined(HAVE_FIPS) && FIPS_VERSION_LT(7,0))
3078
    , size_t digestSz
3079
#endif
3080
    )
3081
1.94k
{
3082
1.94k
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3083
1.94k
    CryptoCb* dev;
3084
#if defined(HAVE_FIPS) && FIPS_VERSION_LT(7,0)
3085
    /* Older FIPS sha512.c snapshots call the 4-arg API (no digestSz). Treat as
3086
     * full-size SHA-512 with no variant dispatch, matching pre-digestSz
3087
     * behavior. */
3088
    size_t digestSz = WC_SHA512_DIGEST_SIZE;
3089
#endif
3090
3091
    /* locate registered callback */
3092
1.94k
    #ifndef NO_SHA2_CRYPTO_CB
3093
1.94k
    if (sha512) {
3094
1.94k
        dev = wc_CryptoCb_FindDevice(sha512->devId, WC_ALGO_TYPE_HASH);
3095
1.94k
    }
3096
0
    else
3097
0
    #endif
3098
0
    {
3099
        /* locate first callback and try using it */
3100
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3101
0
    }
3102
3103
1.94k
    if (dev && dev->cb) {
3104
638
    #ifndef WOLF_CRYPTO_CB_NO_SHA512_FALLBACK
3105
638
        byte localHash[WC_SHA512_DIGEST_SIZE];
3106
638
    #endif
3107
638
        wc_CryptoInfo cryptoInfo;
3108
638
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3109
638
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
3110
638
        cryptoInfo.hash.sha512 = sha512;
3111
638
        cryptoInfo.hash.in = in;
3112
638
        cryptoInfo.hash.inSz = inSz;
3113
638
        cryptoInfo.hash.digest = digest;
3114
3115
        /* try the specific family callbacks first */
3116
638
#if !defined(WOLFSSL_NOSHA512_224)
3117
638
        if (digest != NULL && digestSz == WC_SHA512_224_DIGEST_SIZE) {
3118
0
          cryptoInfo.hash.type = WC_HASH_TYPE_SHA512_224;
3119
0
          ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3120
0
          ret = wc_CryptoCb_TranslateErrorCode(ret);
3121
0
          if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
3122
0
            return ret;
3123
        #ifdef WOLF_CRYPTO_CB_NO_SHA512_FALLBACK
3124
          return ret;
3125
        #endif
3126
0
        }
3127
638
#endif
3128
638
#if !defined(WOLFSSL_NOSHA512_256)
3129
638
        if (digest != NULL && digestSz == WC_SHA512_256_DIGEST_SIZE) {
3130
0
          cryptoInfo.hash.type = WC_HASH_TYPE_SHA512_256;
3131
0
          ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3132
0
          ret = wc_CryptoCb_TranslateErrorCode(ret);
3133
0
          if (ret != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE))
3134
0
            return ret;
3135
        #ifdef WOLF_CRYPTO_CB_NO_SHA512_FALLBACK
3136
          return ret;
3137
        #endif
3138
0
        }
3139
638
#endif
3140
638
        cryptoInfo.hash.type = WC_HASH_TYPE_SHA512;
3141
638
    #ifndef WOLF_CRYPTO_CB_NO_SHA512_FALLBACK
3142
        /* use local buffer if not full size */
3143
638
        if (digest != NULL && digestSz != WC_SHA512_DIGEST_SIZE)
3144
0
            cryptoInfo.hash.digest = localHash;
3145
638
    #endif
3146
638
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3147
638
        ret = wc_CryptoCb_TranslateErrorCode(ret);
3148
638
    #ifndef WOLF_CRYPTO_CB_NO_SHA512_FALLBACK
3149
638
        if (ret == 0 && digest != NULL && digestSz != WC_SHA512_DIGEST_SIZE) {
3150
0
            XMEMCPY(digest, localHash, digestSz);
3151
0
#if !defined(WOLFSSL_NOSHA512_224)
3152
0
            if (sha512 != NULL && digestSz == WC_SHA512_224_DIGEST_SIZE) {
3153
0
              sha512->digest[0] = W64LIT(0x8c3d37c819544da2);
3154
0
              sha512->digest[1] = W64LIT(0x73e1996689dcd4d6);
3155
0
              sha512->digest[2] = W64LIT(0x1dfab7ae32ff9c82);
3156
0
              sha512->digest[3] = W64LIT(0x679dd514582f9fcf);
3157
0
              sha512->digest[4] = W64LIT(0x0f6d2b697bd44da8);
3158
0
              sha512->digest[5] = W64LIT(0x77e36f7304c48942);
3159
0
              sha512->digest[6] = W64LIT(0x3f9d85a86a1d36c8);
3160
0
              sha512->digest[7] = W64LIT(0x1112e6ad91d692a1);
3161
0
            }
3162
0
#endif
3163
0
#if !defined(WOLFSSL_NOSHA512_256)
3164
0
            if (sha512 != NULL && digestSz == WC_SHA512_256_DIGEST_SIZE) {
3165
0
              sha512->digest[0] = W64LIT(0x22312194fc2bf72c);
3166
0
              sha512->digest[1] = W64LIT(0x9f555fa3c84c64c2);
3167
0
              sha512->digest[2] = W64LIT(0x2393b86b6f53b151);
3168
0
              sha512->digest[3] = W64LIT(0x963877195940eabd);
3169
0
              sha512->digest[4] = W64LIT(0x96283ee2a88effe3);
3170
0
              sha512->digest[5] = W64LIT(0xbe5e1e2553863992);
3171
0
              sha512->digest[6] = W64LIT(0x2b0199fc2c85b8aa);
3172
0
              sha512->digest[7] = W64LIT(0x0eb72ddc81c52ca2);
3173
0
            }
3174
0
#endif
3175
0
        }
3176
638
    #endif /* !WOLF_CRYPTO_CB_NO_SHA512_FALLBACK */
3177
638
        return ret;
3178
638
    }
3179
3180
1.30k
    return wc_CryptoCb_TranslateErrorCode(ret);
3181
1.94k
}
3182
#endif /* WOLFSSL_SHA512 */
3183
3184
#if defined(WOLFSSL_SHA3) && (!defined(HAVE_FIPS) || FIPS_VERSION_GE(6, 0))
3185
int wc_CryptoCb_Sha3Hash(wc_Sha3* sha3, int type, const byte* in,
3186
    word32 inSz, byte* digest)
3187
0
{
3188
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3189
0
    CryptoCb* dev;
3190
3191
    /* locate registered callback */
3192
0
    if (sha3) {
3193
0
        dev = wc_CryptoCb_FindDevice(sha3->devId, WC_ALGO_TYPE_HASH);
3194
0
    }
3195
0
    else
3196
0
    {
3197
        /* locate first callback and try using it */
3198
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3199
0
    }
3200
3201
0
    if (dev && dev->cb) {
3202
0
        wc_CryptoInfo cryptoInfo;
3203
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3204
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
3205
0
        cryptoInfo.hash.type = type;
3206
0
        cryptoInfo.hash.sha3 = sha3;
3207
0
        cryptoInfo.hash.in = in;
3208
0
        cryptoInfo.hash.inSz = inSz;
3209
0
        cryptoInfo.hash.digest = digest;
3210
3211
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3212
0
    }
3213
3214
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3215
0
}
3216
3217
#if defined(WOLFSSL_SHAKE128) || defined(WOLFSSL_SHAKE256)
3218
int wc_CryptoCb_Shake(wc_Sha3* shake, int type, const byte* in,
3219
    word32 inSz, byte* out, word32 outSz)
3220
51.2k
{
3221
51.2k
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3222
51.2k
    CryptoCb* dev;
3223
3224
    /* locate registered callback */
3225
51.2k
    if (shake) {
3226
51.2k
        dev = wc_CryptoCb_FindDevice(shake->devId, WC_ALGO_TYPE_HASH);
3227
51.2k
    }
3228
0
    else {
3229
        /* locate first callback and try using it */
3230
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3231
0
    }
3232
3233
51.2k
    if (dev && dev->cb) {
3234
0
        wc_CryptoInfo cryptoInfo;
3235
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3236
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HASH;
3237
0
        cryptoInfo.hash.type = type;
3238
0
        cryptoInfo.hash.sha3 = shake; /* wc_Shake is a wc_Sha3 */
3239
0
        cryptoInfo.hash.in = in;
3240
0
        cryptoInfo.hash.inSz = inSz;
3241
0
        cryptoInfo.hash.digest = out;
3242
0
        cryptoInfo.hash.outSz = outSz;
3243
3244
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3245
0
    }
3246
3247
51.2k
    return wc_CryptoCb_TranslateErrorCode(ret);
3248
51.2k
}
3249
#endif /* WOLFSSL_SHAKE128 || WOLFSSL_SHAKE256 */
3250
#endif /* WOLFSSL_SHA3 && (!HAVE_FIPS || FIPS_VERSION_GE(6, 0)) */
3251
3252
#ifndef NO_HMAC
3253
int wc_CryptoCb_Hmac(Hmac* hmac, int macType, const byte* in, word32 inSz,
3254
    byte* digest)
3255
239
{
3256
239
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3257
239
    CryptoCb* dev;
3258
3259
239
    if (hmac == NULL)
3260
0
        return ret;
3261
3262
    /* locate registered callback */
3263
239
    dev = wc_CryptoCb_FindDevice(hmac->devId, WC_ALGO_TYPE_HMAC);
3264
239
    if (dev && dev->cb) {
3265
0
        wc_CryptoInfo cryptoInfo;
3266
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3267
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_HMAC;
3268
0
        cryptoInfo.hmac.macType = macType;
3269
0
        cryptoInfo.hmac.in = in;
3270
0
        cryptoInfo.hmac.inSz = inSz;
3271
0
        cryptoInfo.hmac.digest = digest;
3272
0
        cryptoInfo.hmac.hmac = hmac;
3273
3274
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3275
0
    }
3276
3277
239
    return wc_CryptoCb_TranslateErrorCode(ret);
3278
239
}
3279
#endif /* !NO_HMAC */
3280
3281
#ifndef WC_NO_RNG
3282
int wc_CryptoCb_RandomBlock(WC_RNG* rng, byte* out, word32 sz)
3283
17.0k
{
3284
17.0k
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3285
17.0k
    CryptoCb* dev;
3286
3287
    /* locate registered callback */
3288
17.0k
    if (rng) {
3289
17.0k
        dev = wc_CryptoCb_FindDevice(rng->devId, WC_ALGO_TYPE_RNG);
3290
17.0k
    }
3291
0
    else {
3292
        /* locate first callback and try using it */
3293
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3294
0
    }
3295
3296
17.0k
    if (dev && dev->cb) {
3297
17.0k
        wc_CryptoInfo cryptoInfo;
3298
17.0k
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3299
17.0k
        cryptoInfo.algo_type = WC_ALGO_TYPE_RNG;
3300
17.0k
        cryptoInfo.rng.rng = rng;
3301
17.0k
        cryptoInfo.rng.out = out;
3302
17.0k
        cryptoInfo.rng.sz = sz;
3303
3304
17.0k
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3305
17.0k
    }
3306
3307
17.0k
    return wc_CryptoCb_TranslateErrorCode(ret);
3308
17.0k
}
3309
3310
int wc_CryptoCb_RandomSeed(OS_Seed* os, byte* seed, word32 sz)
3311
11
{
3312
11
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3313
11
    CryptoCb* dev;
3314
3315
    /* locate registered callback */
3316
11
    dev = wc_CryptoCb_FindDevice(os->devId, WC_ALGO_TYPE_SEED);
3317
11
    if (dev && dev->cb) {
3318
11
        wc_CryptoInfo cryptoInfo;
3319
11
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3320
11
        cryptoInfo.algo_type = WC_ALGO_TYPE_SEED;
3321
11
        cryptoInfo.seed.os = os;
3322
11
        cryptoInfo.seed.seed = seed;
3323
11
        cryptoInfo.seed.sz = sz;
3324
3325
11
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3326
11
    }
3327
3328
11
    return wc_CryptoCb_TranslateErrorCode(ret);
3329
11
}
3330
#endif /* !WC_NO_RNG */
3331
3332
#ifndef NO_CERTS
3333
int wc_CryptoCb_GetCert(int devId, const char *label, word32 labelLen,
3334
                        const byte *id, word32 idLen, byte** out,
3335
                        word32* outSz, int *format, void *heap)
3336
0
{
3337
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3338
0
    CryptoCb* dev;
3339
3340
    /* locate registered callback */
3341
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_CERT);
3342
0
    if (dev && dev->cb) {
3343
0
        wc_CryptoInfo cryptoInfo;
3344
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3345
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CERT;
3346
0
        cryptoInfo.cert.label = label;
3347
0
        cryptoInfo.cert.labelLen = labelLen;
3348
0
        cryptoInfo.cert.id = id;
3349
0
        cryptoInfo.cert.idLen = idLen;
3350
0
        cryptoInfo.cert.heap = heap;
3351
0
        cryptoInfo.cert.certDataOut = out;
3352
0
        cryptoInfo.cert.certSz = outSz;
3353
0
        cryptoInfo.cert.certFormatOut = format;
3354
0
        cryptoInfo.cert.heap = heap;
3355
3356
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3357
0
    }
3358
3359
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3360
0
}
3361
#endif /* ifndef NO_CERTS */
3362
3363
#if defined(WOLFSSL_CMAC)
3364
int wc_CryptoCb_Cmac(Cmac* cmac, const byte* key, word32 keySz,
3365
        const byte* in, word32 inSz, byte* out, word32* outSz, int type,
3366
        void* ctx)
3367
0
{
3368
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3369
0
    CryptoCb* dev;
3370
3371
    /* locate registered callback */
3372
0
    if (cmac) {
3373
0
        dev = wc_CryptoCb_FindDevice(cmac->devId, WC_ALGO_TYPE_CMAC);
3374
0
    }
3375
0
    else {
3376
        /* locate first callback and try using it */
3377
0
        dev = wc_CryptoCb_FindDeviceByIndex(0);
3378
0
    }
3379
0
    if (dev && dev->cb) {
3380
0
        wc_CryptoInfo cryptoInfo;
3381
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3382
0
        cryptoInfo.algo_type = WC_ALGO_TYPE_CMAC;
3383
3384
0
        cryptoInfo.cmac.cmac  = cmac;
3385
0
        cryptoInfo.cmac.ctx   = ctx;
3386
0
        cryptoInfo.cmac.key   = key;
3387
0
        cryptoInfo.cmac.in    = in;
3388
0
        cryptoInfo.cmac.out   = out;
3389
0
        cryptoInfo.cmac.outSz = outSz;
3390
0
        cryptoInfo.cmac.keySz = keySz;
3391
0
        cryptoInfo.cmac.inSz  = inSz;
3392
0
        cryptoInfo.cmac.type  = type;
3393
3394
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3395
0
    }
3396
3397
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3398
0
}
3399
#endif /* WOLFSSL_CMAC */
3400
3401
#ifdef WOLFSSL_SHE
3402
int wc_CryptoCb_SheGetUid(wc_SHE* she, byte* uid, word32 uidSz,
3403
                            const void* ctx)
3404
{
3405
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3406
    CryptoCb* dev;
3407
3408
    if (she == NULL) {
3409
        return BAD_FUNC_ARG;
3410
    }
3411
3412
    /* locate registered callback */
3413
    dev = wc_CryptoCb_FindDevice(she->devId, WC_ALGO_TYPE_SHE);
3414
    if (dev && dev->cb) {
3415
        wc_CryptoInfo cryptoInfo;
3416
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3417
        cryptoInfo.algo_type          = WC_ALGO_TYPE_SHE;
3418
        cryptoInfo.she.she            = she;
3419
        cryptoInfo.she.type           = WC_SHE_GET_UID;
3420
        cryptoInfo.she.ctx            = ctx;
3421
        cryptoInfo.she.op.getUid.uid  = uid;
3422
        cryptoInfo.she.op.getUid.uidSz = uidSz;
3423
3424
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3425
    }
3426
3427
    return wc_CryptoCb_TranslateErrorCode(ret);
3428
}
3429
3430
int wc_CryptoCb_SheGetCounter(wc_SHE* she, word32* counter, const void* ctx)
3431
{
3432
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3433
    CryptoCb* dev;
3434
3435
    if (she == NULL || counter == NULL) {
3436
        return BAD_FUNC_ARG;
3437
    }
3438
3439
    dev = wc_CryptoCb_FindDevice(she->devId, WC_ALGO_TYPE_SHE);
3440
    if (dev && dev->cb) {
3441
        wc_CryptoInfo cryptoInfo;
3442
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3443
        cryptoInfo.algo_type                    = WC_ALGO_TYPE_SHE;
3444
        cryptoInfo.she.she                      = she;
3445
        cryptoInfo.she.type                     = WC_SHE_GET_COUNTER;
3446
        cryptoInfo.she.ctx                      = ctx;
3447
        cryptoInfo.she.op.getCounter.counter    = counter;
3448
3449
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3450
    }
3451
3452
    return wc_CryptoCb_TranslateErrorCode(ret);
3453
}
3454
3455
int wc_CryptoCb_SheGenerateM1M2M3(wc_SHE* she,
3456
                      const byte* uid, word32 uidSz,
3457
                      byte authKeyId, const byte* authKey, word32 authKeySz,
3458
                      byte targetKeyId, const byte* newKey, word32 newKeySz,
3459
                      word32 counter, byte flags,
3460
                      byte* m1, word32 m1Sz,
3461
                      byte* m2, word32 m2Sz,
3462
                      byte* m3, word32 m3Sz)
3463
{
3464
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3465
    CryptoCb* dev;
3466
3467
    if (she == NULL) {
3468
        return BAD_FUNC_ARG;
3469
    }
3470
3471
    dev = wc_CryptoCb_FindDevice(she->devId, WC_ALGO_TYPE_SHE);
3472
    if (dev && dev->cb) {
3473
        wc_CryptoInfo cryptoInfo;
3474
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3475
        cryptoInfo.algo_type                          = WC_ALGO_TYPE_SHE;
3476
        cryptoInfo.she.she                            = she;
3477
        cryptoInfo.she.type                           = WC_SHE_GENERATE_M1M2M3;
3478
        cryptoInfo.she.op.generateM1M2M3.uid          = uid;
3479
        cryptoInfo.she.op.generateM1M2M3.uidSz        = uidSz;
3480
        cryptoInfo.she.op.generateM1M2M3.authKeyId     = authKeyId;
3481
        cryptoInfo.she.op.generateM1M2M3.authKey       = authKey;
3482
        cryptoInfo.she.op.generateM1M2M3.authKeySz     = authKeySz;
3483
        cryptoInfo.she.op.generateM1M2M3.targetKeyId   = targetKeyId;
3484
        cryptoInfo.she.op.generateM1M2M3.newKey        = newKey;
3485
        cryptoInfo.she.op.generateM1M2M3.newKeySz      = newKeySz;
3486
        cryptoInfo.she.op.generateM1M2M3.counter       = counter;
3487
        cryptoInfo.she.op.generateM1M2M3.flags         = flags;
3488
        cryptoInfo.she.op.generateM1M2M3.m1            = m1;
3489
        cryptoInfo.she.op.generateM1M2M3.m1Sz          = m1Sz;
3490
        cryptoInfo.she.op.generateM1M2M3.m2            = m2;
3491
        cryptoInfo.she.op.generateM1M2M3.m2Sz          = m2Sz;
3492
        cryptoInfo.she.op.generateM1M2M3.m3            = m3;
3493
        cryptoInfo.she.op.generateM1M2M3.m3Sz          = m3Sz;
3494
3495
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3496
    }
3497
3498
    return wc_CryptoCb_TranslateErrorCode(ret);
3499
}
3500
3501
int wc_CryptoCb_SheGenerateM4M5(wc_SHE* she,
3502
                      const byte* uid, word32 uidSz,
3503
                      byte authKeyId, byte targetKeyId,
3504
                      const byte* newKey, word32 newKeySz,
3505
                      word32 counter,
3506
                      byte* m4, word32 m4Sz,
3507
                      byte* m5, word32 m5Sz)
3508
{
3509
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3510
    CryptoCb* dev;
3511
3512
    if (she == NULL) {
3513
        return BAD_FUNC_ARG;
3514
    }
3515
3516
    dev = wc_CryptoCb_FindDevice(she->devId, WC_ALGO_TYPE_SHE);
3517
    if (dev && dev->cb) {
3518
        wc_CryptoInfo cryptoInfo;
3519
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3520
        cryptoInfo.algo_type                       = WC_ALGO_TYPE_SHE;
3521
        cryptoInfo.she.she                         = she;
3522
        cryptoInfo.she.type                        = WC_SHE_GENERATE_M4M5;
3523
        cryptoInfo.she.op.generateM4M5.uid         = uid;
3524
        cryptoInfo.she.op.generateM4M5.uidSz       = uidSz;
3525
        cryptoInfo.she.op.generateM4M5.authKeyId    = authKeyId;
3526
        cryptoInfo.she.op.generateM4M5.targetKeyId  = targetKeyId;
3527
        cryptoInfo.she.op.generateM4M5.newKey       = newKey;
3528
        cryptoInfo.she.op.generateM4M5.newKeySz     = newKeySz;
3529
        cryptoInfo.she.op.generateM4M5.counter      = counter;
3530
        cryptoInfo.she.op.generateM4M5.m4           = m4;
3531
        cryptoInfo.she.op.generateM4M5.m4Sz         = m4Sz;
3532
        cryptoInfo.she.op.generateM4M5.m5           = m5;
3533
        cryptoInfo.she.op.generateM4M5.m5Sz         = m5Sz;
3534
3535
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3536
    }
3537
3538
    return wc_CryptoCb_TranslateErrorCode(ret);
3539
}
3540
3541
int wc_CryptoCb_SheExportKey(wc_SHE* she,
3542
                              byte* m1, word32 m1Sz,
3543
                              byte* m2, word32 m2Sz,
3544
                              byte* m3, word32 m3Sz,
3545
                              byte* m4, word32 m4Sz,
3546
                              byte* m5, word32 m5Sz,
3547
                              const void* ctx)
3548
{
3549
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3550
    CryptoCb* dev;
3551
3552
    if (she == NULL) {
3553
        return BAD_FUNC_ARG;
3554
    }
3555
3556
    dev = wc_CryptoCb_FindDevice(she->devId, WC_ALGO_TYPE_SHE);
3557
    if (dev && dev->cb) {
3558
        wc_CryptoInfo cryptoInfo;
3559
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3560
        cryptoInfo.algo_type                = WC_ALGO_TYPE_SHE;
3561
        cryptoInfo.she.she                  = she;
3562
        cryptoInfo.she.type                 = WC_SHE_EXPORT_KEY;
3563
        cryptoInfo.she.ctx                  = ctx;
3564
        cryptoInfo.she.op.exportKey.m1      = m1;
3565
        cryptoInfo.she.op.exportKey.m1Sz    = m1Sz;
3566
        cryptoInfo.she.op.exportKey.m2      = m2;
3567
        cryptoInfo.she.op.exportKey.m2Sz    = m2Sz;
3568
        cryptoInfo.she.op.exportKey.m3      = m3;
3569
        cryptoInfo.she.op.exportKey.m3Sz    = m3Sz;
3570
        cryptoInfo.she.op.exportKey.m4      = m4;
3571
        cryptoInfo.she.op.exportKey.m4Sz    = m4Sz;
3572
        cryptoInfo.she.op.exportKey.m5      = m5;
3573
        cryptoInfo.she.op.exportKey.m5Sz    = m5Sz;
3574
3575
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3576
    }
3577
3578
    return wc_CryptoCb_TranslateErrorCode(ret);
3579
}
3580
#endif /* WOLFSSL_SHE */
3581
3582
/* returns the default dev id for the current build */
3583
int wc_CryptoCb_DefaultDevID(void)
3584
72.8k
{
3585
72.8k
    int ret;
3586
3587
/* Explicitly disable the "default devId" behavior. Ensures that any devId
3588
 * will only be used if explicitly passed as an argument to crypto functions,
3589
 * and never automatically selected. */
3590
#ifdef WC_NO_DEFAULT_DEVID
3591
    ret = INVALID_DEVID;
3592
#else
3593
    /* conditional macro selection based on build */
3594
#ifdef WOLFSSL_CAAM_DEVID
3595
    ret = WOLFSSL_CAAM_DEVID;
3596
#elif defined(HAVE_ARIA)
3597
    ret = WOLFSSL_ARIA_DEVID;
3598
#elif defined(WC_USE_DEVID)
3599
    ret = WC_USE_DEVID;
3600
#else
3601
    /* try first available */
3602
72.8k
    ret = wc_CryptoCb_GetDevIdAtIndex(0);
3603
72.8k
#endif
3604
72.8k
#endif /* WC_NO_DEFAULT_DEVID */
3605
3606
72.8k
    return ret;
3607
72.8k
}
3608
3609
#if defined(HAVE_HKDF) && !defined(NO_HMAC)
3610
int wc_CryptoCb_Hkdf(int hashType, const byte* inKey, word32 inKeySz,
3611
                     const byte* salt, word32 saltSz, const byte* info,
3612
                     word32 infoSz, byte* out, word32 outSz, int devId)
3613
0
{
3614
0
    int       ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3615
0
    CryptoCb* dev;
3616
3617
    /* Find registered callback device */
3618
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KDF);
3619
3620
0
    if (dev && dev->cb) {
3621
0
        wc_CryptoInfo cryptoInfo;
3622
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3623
3624
0
        cryptoInfo.algo_type         = WC_ALGO_TYPE_KDF;
3625
0
        cryptoInfo.kdf.type          = WC_KDF_TYPE_HKDF;
3626
0
        cryptoInfo.kdf.hkdf.hashType = hashType;
3627
0
        cryptoInfo.kdf.hkdf.inKey    = inKey;
3628
0
        cryptoInfo.kdf.hkdf.inKeySz  = inKeySz;
3629
0
        cryptoInfo.kdf.hkdf.salt     = salt;
3630
0
        cryptoInfo.kdf.hkdf.saltSz   = saltSz;
3631
0
        cryptoInfo.kdf.hkdf.info     = info;
3632
0
        cryptoInfo.kdf.hkdf.infoSz   = infoSz;
3633
0
        cryptoInfo.kdf.hkdf.out      = out;
3634
0
        cryptoInfo.kdf.hkdf.outSz    = outSz;
3635
3636
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3637
0
    }
3638
3639
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3640
0
}
3641
3642
/* NOTE: size of 'out' must be the digest size per hashType */
3643
int wc_CryptoCb_Hkdf_Extract(int hashType, const byte* salt, word32 saltSz,
3644
                        const byte* inKey, word32 inKeySz, byte* out, int devId)
3645
0
{
3646
0
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3647
0
    CryptoCb* dev;
3648
3649
    /* Find registered callback device */
3650
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KDF);
3651
3652
0
    if (dev && dev->cb) {
3653
0
        wc_CryptoInfo cryptoInfo;
3654
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3655
3656
0
        cryptoInfo.algo_type                 = WC_ALGO_TYPE_KDF;
3657
0
        cryptoInfo.kdf.type                  = WC_KDF_TYPE_HKDF_EXTRACT;
3658
0
        cryptoInfo.kdf.hkdf_extract.hashType = hashType;
3659
0
        cryptoInfo.kdf.hkdf_extract.salt     = salt;
3660
0
        cryptoInfo.kdf.hkdf_extract.saltSz   = saltSz;
3661
0
        cryptoInfo.kdf.hkdf_extract.inKey    = inKey;
3662
0
        cryptoInfo.kdf.hkdf_extract.inKeySz  = inKeySz;
3663
0
        cryptoInfo.kdf.hkdf_extract.out      = out;
3664
3665
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3666
0
    }
3667
3668
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3669
0
}
3670
3671
int wc_CryptoCb_Hkdf_Expand(int hashType, const byte* inKey, word32 inKeySz,
3672
                     const byte* info, word32 infoSz, byte* out, word32 outSz,
3673
                     int devId)
3674
0
{
3675
0
    int       ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3676
0
    CryptoCb* dev;
3677
3678
    /* Find registered callback device */
3679
0
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KDF);
3680
3681
0
    if (dev && dev->cb) {
3682
0
        wc_CryptoInfo cryptoInfo;
3683
0
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3684
3685
0
        cryptoInfo.algo_type                = WC_ALGO_TYPE_KDF;
3686
0
        cryptoInfo.kdf.type                 = WC_KDF_TYPE_HKDF_EXPAND;
3687
0
        cryptoInfo.kdf.hkdf_expand.hashType = hashType;
3688
0
        cryptoInfo.kdf.hkdf_expand.inKey    = inKey;
3689
0
        cryptoInfo.kdf.hkdf_expand.inKeySz  = inKeySz;
3690
0
        cryptoInfo.kdf.hkdf_expand.info     = info;
3691
0
        cryptoInfo.kdf.hkdf_expand.infoSz   = infoSz;
3692
0
        cryptoInfo.kdf.hkdf_expand.out      = out;
3693
0
        cryptoInfo.kdf.hkdf_expand.outSz    = outSz;
3694
3695
0
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3696
0
    }
3697
3698
0
    return wc_CryptoCb_TranslateErrorCode(ret);
3699
0
}
3700
#endif /* HAVE_HKDF && !NO_HMAC */
3701
3702
#ifdef WOLF_CRYPTO_CB_COPY
3703
/* General copy callback function for algorithm structures
3704
 * devId: The device ID to use for the callback
3705
 * algo: Algorithm type (enum wc_AlgoType) - WC_ALGO_TYPE_HASH,
3706
 *       WC_ALGO_TYPE_CIPHER, etc
3707
 * type: Specific type - for HASH: enum wc_HashType, for CIPHER:
3708
 *       enum wc_CipherType
3709
 * src: Pointer to source structure
3710
 * dst: Pointer to destination structure
3711
 * Returns: 0 on success, negative on error, CRYPTOCB_UNAVAILABLE if not
3712
 *          handled
3713
 */
3714
int wc_CryptoCb_Copy(int devId, int algo, int type, void* src, void* dst)
3715
{
3716
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3717
    CryptoCb* dev;
3718
3719
    /* Find registered callback device */
3720
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_COPY);
3721
    if (dev && dev->cb) {
3722
        wc_CryptoInfo cryptoInfo;
3723
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3724
        cryptoInfo.algo_type = WC_ALGO_TYPE_COPY;
3725
        cryptoInfo.copy.algo = algo;
3726
        cryptoInfo.copy.type = type;
3727
        cryptoInfo.copy.src = src;
3728
        cryptoInfo.copy.dst = dst;
3729
3730
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3731
    }
3732
3733
    return wc_CryptoCb_TranslateErrorCode(ret);
3734
}
3735
#endif /* WOLF_CRYPTO_CB_COPY */
3736
3737
#ifdef WOLF_CRYPTO_CB_FREE
3738
/* General free callback function for algorithm structures
3739
 * devId: The device ID to use for the callback
3740
 * algo: Algorithm type (enum wc_AlgoType) - WC_ALGO_TYPE_HASH,
3741
 *       WC_ALGO_TYPE_CIPHER, etc
3742
 * type: Specific type - for HASH: enum wc_HashType, for CIPHER:
3743
 *       enum wc_CipherType
3744
 * subType: Specific subtype - for PQC: enum wc_PqcKemType,
3745
 *       enum wc_PqcSignatureType
3746
 * obj: Pointer to object structure to free
3747
 * Returns: 0 on success, negative on error, CRYPTOCB_UNAVAILABLE if not
3748
 *          handled
3749
 */
3750
int wc_CryptoCb_Free(int devId, int algo, int type, int subType, void* obj)
3751
{
3752
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3753
    CryptoCb* dev;
3754
3755
    /* Find registered callback device */
3756
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_FREE);
3757
    if (dev && dev->cb) {
3758
        wc_CryptoInfo cryptoInfo;
3759
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3760
        cryptoInfo.algo_type = WC_ALGO_TYPE_FREE;
3761
        cryptoInfo.free.algo = algo;
3762
        cryptoInfo.free.type = type;
3763
        cryptoInfo.free.subType = subType;
3764
        cryptoInfo.free.obj = obj;
3765
3766
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3767
    }
3768
3769
    return wc_CryptoCb_TranslateErrorCode(ret);
3770
}
3771
#endif /* WOLF_CRYPTO_CB_FREE */
3772
3773
#ifdef WOLF_CRYPTO_CB_SETKEY
3774
/* Generic SetKey callback for importing keys into hardware.
3775
 * devId: Device ID for the registered callback
3776
 * type:  enum wc_SetKeyType (AES, HMAC, RSA_PUB, RSA_PRIV, ECC_PUB, ECC_PRIV)
3777
 * obj:   Context struct being operated on (Aes*, Hmac*, RsaKey*, ecc_key*)
3778
 * key:   Key material: raw bytes (AES/HMAC) or temp struct to export from (RSA/ECC)
3779
 * keySz: Key size in bytes (0 when key is a struct pointer)
3780
 * aux:   Auxiliary data (IV, etc.) or NULL
3781
 * auxSz: Aux data size, 0 if unused
3782
 * flags: AES: direction (AES_ENCRYPTION/DECRYPTION). Others: 0
3783
 * Returns: 0 on success, CRYPTOCB_UNAVAILABLE if not handled, negative on error
3784
 */
3785
int wc_CryptoCb_SetKey(int devId, int type, void* obj,
3786
                         void* key, word32 keySz,
3787
                         void* aux, word32 auxSz,
3788
                         int flags)
3789
{
3790
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3791
    CryptoCb* dev;
3792
3793
    /* Find registered callback device */
3794
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_SETKEY);
3795
    if (dev && dev->cb) {
3796
        wc_CryptoInfo cryptoInfo;
3797
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3798
        cryptoInfo.algo_type = WC_ALGO_TYPE_SETKEY;
3799
        cryptoInfo.setkey.type = type;
3800
        cryptoInfo.setkey.obj = obj;
3801
        cryptoInfo.setkey.key = key;
3802
        cryptoInfo.setkey.keySz = keySz;
3803
        cryptoInfo.setkey.aux = aux;
3804
        cryptoInfo.setkey.auxSz = auxSz;
3805
        cryptoInfo.setkey.flags = flags;
3806
3807
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3808
    }
3809
3810
    return wc_CryptoCb_TranslateErrorCode(ret);
3811
}
3812
#endif /* WOLF_CRYPTO_CB_SETKEY */
3813
3814
#ifdef WOLF_CRYPTO_CB_EXPORT_KEY
3815
/* Generic ExportKey callback for exporting key material from hardware.
3816
 * devId: Device ID for the registered callback
3817
 * type:  enum wc_PkType (WC_PK_TYPE_RSA, WC_PK_TYPE_ECDSA, etc.)
3818
 * obj:   Hardware key object (has devCtx, id[], etc.)
3819
 * out:   Software key object to fill (same type as obj, caller-allocated)
3820
 * The callback exports from hardware into the software key. The caller then
3821
 * uses normal software export functions on 'out' and frees it.
3822
 * Returns: 0 on success, CRYPTOCB_UNAVAILABLE if not handled, negative on error
3823
 */
3824
int wc_CryptoCb_ExportKey(int devId, int type, const void* obj, void* out)
3825
{
3826
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3827
    CryptoCb* dev;
3828
3829
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_EXPORT_KEY);
3830
    if (dev && dev->cb) {
3831
        wc_CryptoInfo cryptoInfo;
3832
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3833
        cryptoInfo.algo_type = WC_ALGO_TYPE_EXPORT_KEY;
3834
        cryptoInfo.export_key.type = type;
3835
        cryptoInfo.export_key.obj = obj;
3836
        cryptoInfo.export_key.out = out;
3837
3838
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3839
    }
3840
3841
    return wc_CryptoCb_TranslateErrorCode(ret);
3842
}
3843
#endif /* WOLF_CRYPTO_CB_EXPORT_KEY */
3844
3845
#ifdef WOLF_CRYPTO_CB_KEYSTORE
3846
/* Hardware key store operations. Key references are opaque to wolfCrypt: it
3847
 * copies the pointers through and never interprets them, exactly as it treats
3848
 * the id[] blob on a key object. */
3849
int wc_CryptoCb_KeyStoreImportPlain(int devId,
3850
    const byte* keyRef, word32 keyRefSz,
3851
    word32 keyType, const byte* key, word32 keySz,
3852
    word32 attrs, const void* ctx)
3853
{
3854
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3855
    CryptoCb* dev;
3856
3857
    if (keyRef == NULL || keyRefSz == 0 || key == NULL || keySz == 0) {
3858
        return BAD_FUNC_ARG;
3859
    }
3860
3861
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
3862
    if (dev && dev->cb) {
3863
        wc_CryptoInfo cryptoInfo;
3864
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3865
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
3866
        cryptoInfo.keystore.type = WC_KEYSTORE_IMPORT_PLAIN;
3867
        cryptoInfo.keystore.ctx  = ctx;
3868
        cryptoInfo.keystore.op.importPlain.keyRef   = keyRef;
3869
        cryptoInfo.keystore.op.importPlain.keyRefSz = keyRefSz;
3870
        cryptoInfo.keystore.op.importPlain.keyType  = keyType;
3871
        cryptoInfo.keystore.op.importPlain.key      = key;
3872
        cryptoInfo.keystore.op.importPlain.keySz    = keySz;
3873
        cryptoInfo.keystore.op.importPlain.attrs    = attrs;
3874
3875
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3876
    }
3877
3878
    return wc_CryptoCb_TranslateErrorCode(ret);
3879
}
3880
3881
int wc_CryptoCb_KeyStoreExportPlain(int devId,
3882
    const byte* keyRef, word32 keyRefSz,
3883
    byte* key, word32* keySz, const void* ctx)
3884
{
3885
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3886
    CryptoCb* dev;
3887
3888
    /* key == NULL is the required-size query. Tie buffer and capacity together
3889
     * so a non-NULL buffer cannot arrive with an uninitialised capacity. */
3890
    if (keyRef == NULL || keyRefSz == 0 || keySz == NULL) {
3891
        return BAD_FUNC_ARG;
3892
    }
3893
    if (key != NULL && *keySz == 0) {
3894
        return BAD_FUNC_ARG;
3895
    }
3896
3897
    /* On the query form it is a pure output, so clear it as getInfo does; on
3898
     * the buffer form it carries the capacity in and must be left alone. */
3899
    if (key == NULL) {
3900
        *keySz = 0;
3901
    }
3902
3903
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
3904
    if (dev && dev->cb) {
3905
        wc_CryptoInfo cryptoInfo;
3906
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3907
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
3908
        cryptoInfo.keystore.type = WC_KEYSTORE_EXPORT_PLAIN;
3909
        cryptoInfo.keystore.ctx  = ctx;
3910
        cryptoInfo.keystore.op.exportPlain.keyRef   = keyRef;
3911
        cryptoInfo.keystore.op.exportPlain.keyRefSz = keyRefSz;
3912
        cryptoInfo.keystore.op.exportPlain.key      = key;
3913
        cryptoInfo.keystore.op.exportPlain.keySz    = keySz;
3914
3915
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3916
    }
3917
3918
    return wc_CryptoCb_TranslateErrorCode(ret);
3919
}
3920
3921
int wc_CryptoCb_KeyStoreImportWrapped(int devId,
3922
    const byte* keyRef, word32 keyRefSz, word32 keyType,
3923
    const byte* wrapKeyRef, word32 wrapKeyRefSz,
3924
    word32 format, const byte* blob, word32 blobSz,
3925
    word32 attrs, const void* ctx)
3926
{
3927
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3928
    CryptoCb* dev;
3929
3930
    if (keyRef == NULL || keyRefSz == 0 || blob == NULL || blobSz == 0) {
3931
        return BAD_FUNC_ARG;
3932
    }
3933
    if (wrapKeyRef == NULL && wrapKeyRefSz != 0) {
3934
        return BAD_FUNC_ARG;
3935
    }
3936
3937
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
3938
    if (dev && dev->cb) {
3939
        wc_CryptoInfo cryptoInfo;
3940
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3941
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
3942
        cryptoInfo.keystore.type = WC_KEYSTORE_IMPORT_WRAPPED;
3943
        cryptoInfo.keystore.ctx  = ctx;
3944
        cryptoInfo.keystore.op.importWrapped.keyRef       = keyRef;
3945
        cryptoInfo.keystore.op.importWrapped.keyRefSz     = keyRefSz;
3946
        cryptoInfo.keystore.op.importWrapped.keyType      = keyType;
3947
        cryptoInfo.keystore.op.importWrapped.wrapKeyRef   = wrapKeyRef;
3948
        cryptoInfo.keystore.op.importWrapped.wrapKeyRefSz = wrapKeyRefSz;
3949
        cryptoInfo.keystore.op.importWrapped.blob         = blob;
3950
        cryptoInfo.keystore.op.importWrapped.blobSz       = blobSz;
3951
        cryptoInfo.keystore.op.importWrapped.format       = format;
3952
        cryptoInfo.keystore.op.importWrapped.attrs        = attrs;
3953
3954
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
3955
    }
3956
3957
    return wc_CryptoCb_TranslateErrorCode(ret);
3958
}
3959
3960
int wc_CryptoCb_KeyStoreExportWrapped(int devId,
3961
    const byte* keyRef, word32 keyRefSz,
3962
    const byte* wrapKeyRef, word32 wrapKeyRefSz,
3963
    word32 format, byte* blob, word32* blobSz, const void* ctx)
3964
{
3965
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
3966
    CryptoCb* dev;
3967
3968
    /* blob == NULL is the required-size query. Tie buffer and capacity together
3969
     * so a non-NULL buffer cannot arrive with an uninitialised capacity. */
3970
    if (keyRef == NULL || keyRefSz == 0 || blobSz == NULL) {
3971
        return BAD_FUNC_ARG;
3972
    }
3973
    if (blob != NULL && *blobSz == 0) {
3974
        return BAD_FUNC_ARG;
3975
    }
3976
    if (wrapKeyRef == NULL && wrapKeyRefSz != 0) {
3977
        return BAD_FUNC_ARG;
3978
    }
3979
3980
    /* Cleared only on the query form; see wc_CryptoCb_KeyStoreExportPlain. */
3981
    if (blob == NULL) {
3982
        *blobSz = 0;
3983
    }
3984
3985
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
3986
    if (dev && dev->cb) {
3987
        wc_CryptoInfo cryptoInfo;
3988
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
3989
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
3990
        cryptoInfo.keystore.type = WC_KEYSTORE_EXPORT_WRAPPED;
3991
        cryptoInfo.keystore.ctx  = ctx;
3992
        cryptoInfo.keystore.op.exportWrapped.keyRef       = keyRef;
3993
        cryptoInfo.keystore.op.exportWrapped.keyRefSz     = keyRefSz;
3994
        cryptoInfo.keystore.op.exportWrapped.wrapKeyRef   = wrapKeyRef;
3995
        cryptoInfo.keystore.op.exportWrapped.wrapKeyRefSz = wrapKeyRefSz;
3996
        cryptoInfo.keystore.op.exportWrapped.blob         = blob;
3997
        cryptoInfo.keystore.op.exportWrapped.blobSz       = blobSz;
3998
        cryptoInfo.keystore.op.exportWrapped.format       = format;
3999
4000
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
4001
    }
4002
4003
    return wc_CryptoCb_TranslateErrorCode(ret);
4004
}
4005
4006
int wc_CryptoCb_KeyStoreDerive(int devId,
4007
    const byte* keyRef, word32 keyRefSz, word32 keyType, word32 keySz,
4008
    const byte* srcKeyRef, word32 srcKeyRefSz,
4009
    word32 kdfType, const byte* deriv, word32 derivSz,
4010
    word32 attrs, const void* ctx)
4011
{
4012
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
4013
    CryptoCb* dev;
4014
4015
    if (keyRef == NULL || keyRefSz == 0 ||
4016
        srcKeyRef == NULL || srcKeyRefSz == 0) {
4017
        return BAD_FUNC_ARG;
4018
    }
4019
    if (deriv == NULL && derivSz != 0) {
4020
        return BAD_FUNC_ARG;
4021
    }
4022
4023
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
4024
    if (dev && dev->cb) {
4025
        wc_CryptoInfo cryptoInfo;
4026
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
4027
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
4028
        cryptoInfo.keystore.type = WC_KEYSTORE_DERIVE;
4029
        cryptoInfo.keystore.ctx  = ctx;
4030
        cryptoInfo.keystore.op.derive.keyRef      = keyRef;
4031
        cryptoInfo.keystore.op.derive.keyRefSz    = keyRefSz;
4032
        cryptoInfo.keystore.op.derive.keyType     = keyType;
4033
        cryptoInfo.keystore.op.derive.keySz       = keySz;
4034
        cryptoInfo.keystore.op.derive.srcKeyRef   = srcKeyRef;
4035
        cryptoInfo.keystore.op.derive.srcKeyRefSz = srcKeyRefSz;
4036
        cryptoInfo.keystore.op.derive.deriv       = deriv;
4037
        cryptoInfo.keystore.op.derive.derivSz     = derivSz;
4038
        cryptoInfo.keystore.op.derive.kdfType     = kdfType;
4039
        cryptoInfo.keystore.op.derive.attrs       = attrs;
4040
4041
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
4042
    }
4043
4044
    return wc_CryptoCb_TranslateErrorCode(ret);
4045
}
4046
4047
int wc_CryptoCb_KeyStoreDelete(int devId, const byte* keyRef, word32 keyRefSz,
4048
                               const void* ctx)
4049
{
4050
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
4051
    CryptoCb* dev;
4052
4053
    if (keyRef == NULL || keyRefSz == 0) {
4054
        return BAD_FUNC_ARG;
4055
    }
4056
4057
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
4058
    if (dev && dev->cb) {
4059
        wc_CryptoInfo cryptoInfo;
4060
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
4061
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
4062
        cryptoInfo.keystore.type = WC_KEYSTORE_DELETE;
4063
        cryptoInfo.keystore.ctx  = ctx;
4064
        cryptoInfo.keystore.op.deleteKey.keyRef   = keyRef;
4065
        cryptoInfo.keystore.op.deleteKey.keyRefSz = keyRefSz;
4066
4067
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
4068
    }
4069
4070
    return wc_CryptoCb_TranslateErrorCode(ret);
4071
}
4072
4073
int wc_CryptoCb_KeyStoreGetInfo(int devId, const byte* keyRef, word32 keyRefSz,
4074
    word32* keyType, word32* keyBits, word32* attrs, const void* ctx)
4075
{
4076
    int ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
4077
    CryptoCb* dev;
4078
4079
    if (keyRef == NULL || keyRefSz == 0) {
4080
        return BAD_FUNC_ARG;
4081
    }
4082
4083
    /* Clear the caller's storage first: a device may answer only part of the
4084
     * query, and attrs & WC_KEYSTORE_ATTR_EXPORTABLE is a security decision. */
4085
    if (keyType != NULL) {
4086
        *keyType = 0;
4087
    }
4088
    if (keyBits != NULL) {
4089
        *keyBits = 0;
4090
    }
4091
    if (attrs != NULL) {
4092
        *attrs = 0;
4093
    }
4094
4095
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KEYSTORE);
4096
    if (dev && dev->cb) {
4097
        wc_CryptoInfo cryptoInfo;
4098
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
4099
        cryptoInfo.algo_type = WC_ALGO_TYPE_KEYSTORE;
4100
        cryptoInfo.keystore.type = WC_KEYSTORE_GET_INFO;
4101
        cryptoInfo.keystore.ctx  = ctx;
4102
        cryptoInfo.keystore.op.getInfo.keyRef   = keyRef;
4103
        cryptoInfo.keystore.op.getInfo.keyRefSz = keyRefSz;
4104
        cryptoInfo.keystore.op.getInfo.keyType  = keyType;
4105
        cryptoInfo.keystore.op.getInfo.keyBits  = keyBits;
4106
        cryptoInfo.keystore.op.getInfo.attrs    = attrs;
4107
4108
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
4109
    }
4110
4111
    return wc_CryptoCb_TranslateErrorCode(ret);
4112
}
4113
#endif /* WOLF_CRYPTO_CB_KEYSTORE */
4114
4115
#if defined(HAVE_CMAC_KDF)
4116
/* Crypto callback for NIST SP 800 56C two-step CMAC KDF. See software
4117
 * implementation in wc_KDA_KDF_twostep_cmac for more comments.
4118
 * */
4119
int wc_CryptoCb_Kdf_TwostepCmac(const byte * salt, word32 saltSz,
4120
                                const byte* z, word32 zSz,
4121
                                const byte* fixedInfo, word32 fixedInfoSz,
4122
                                byte* output, word32 outputSz, int devId)
4123
{
4124
    int       ret = WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE);
4125
    CryptoCb* dev;
4126
4127
    /* Find registered callback device */
4128
    dev = wc_CryptoCb_FindDevice(devId, WC_ALGO_TYPE_KDF);
4129
4130
    if (dev && dev->cb) {
4131
        wc_CryptoInfo cryptoInfo;
4132
        XMEMSET(&cryptoInfo, 0, sizeof(cryptoInfo));
4133
4134
        cryptoInfo.algo_type                    = WC_ALGO_TYPE_KDF;
4135
        cryptoInfo.kdf.type                     = WC_KDF_TYPE_TWOSTEP_CMAC;
4136
        cryptoInfo.kdf.twostep_cmac.salt        = salt;
4137
        cryptoInfo.kdf.twostep_cmac.saltSz      = saltSz;
4138
        cryptoInfo.kdf.twostep_cmac.z           = z;
4139
        cryptoInfo.kdf.twostep_cmac.zSz         = zSz;
4140
        cryptoInfo.kdf.twostep_cmac.fixedInfo   = fixedInfo;
4141
        cryptoInfo.kdf.twostep_cmac.fixedInfoSz = fixedInfoSz;
4142
        cryptoInfo.kdf.twostep_cmac.out         = output;
4143
        cryptoInfo.kdf.twostep_cmac.outSz       = outputSz;
4144
4145
        ret = dev->cb(dev->devId, &cryptoInfo, dev->ctx);
4146
    }
4147
4148
    return wc_CryptoCb_TranslateErrorCode(ret);
4149
}
4150
#endif /* HAVE_CMAC_KDF */
4151
4152
#endif /* WOLF_CRYPTO_CB */