blob: 4223c865ba8784b3701a635e6d79bf574fe5ddd5 [file] [log] [blame]
Paul Bakker17373852011-01-06 14:20:01 +00001/**
Gilles Peskine2091f3a2021-02-12 23:34:01 +01002 * \file md.c
Paul Bakker9af723c2014-05-01 13:03:14 +02003 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +00004 * \brief Generic message digest wrapper for mbed TLS
Paul Bakker17373852011-01-06 14:20:01 +00005 *
6 * \author Adriaan de Jong <dejong@fox-it.com>
7 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02008 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02009 * SPDX-License-Identifier: Apache-2.0
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License"); you may
12 * not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
Paul Bakker17373852011-01-06 14:20:01 +000022 */
23
Gilles Peskinedb09ef62020-06-03 01:43:33 +020024#include "common.h"
Paul Bakker17373852011-01-06 14:20:01 +000025
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010026/*
27 * Availability of functions in this module is controlled by two
28 * feature macros:
29 * - MBEDTLS_MD_C enables the whole module;
30 * - MBEDTLS_MD_LIGHT enables only functions for hashing and accessing
31 * most hash metadata (everything except string names); is it
32 * automatically set whenever MBEDTLS_MD_C is defined.
33 *
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +010034 * In this file, functions from MD_LIGHT are at the top, MD_C at the end.
35 *
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010036 * In the future we may want to change the contract of some functions
37 * (behaviour with NULL arguments) depending on whether MD_C is defined or
38 * only MD_LIGHT. Also, the exact scope of MD_LIGHT might vary.
39 *
40 * For these reasons, we're keeping MD_LIGHT internal for now.
41 */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +010042#if defined(MBEDTLS_MD_LIGHT)
Paul Bakker17373852011-01-06 14:20:01 +000043
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +000044#include "mbedtls/md.h"
Chris Jonesdaacb592021-03-09 17:03:29 +000045#include "md_wrap.h"
Andres Amaya Garcia1f6301b2018-04-17 09:51:09 -050046#include "mbedtls/platform_util.h"
Janos Follath24eed8d2019-11-22 13:21:35 +000047#include "mbedtls/error.h"
Paul Bakker17373852011-01-06 14:20:01 +000048
Gilles Peskine84867cf2019-07-19 15:46:03 +020049#include "mbedtls/md5.h"
50#include "mbedtls/ripemd160.h"
51#include "mbedtls/sha1.h"
52#include "mbedtls/sha256.h"
53#include "mbedtls/sha512.h"
Pol Henarejos4712d4c2022-05-20 14:17:14 +020054#include "mbedtls/sha3.h"
Gilles Peskine84867cf2019-07-19 15:46:03 +020055
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +020056#if defined(MBEDTLS_PSA_CRYPTO_C)
Gilles Peskine12612e52022-10-22 20:07:28 +020057#include <psa/crypto.h>
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +020058#include "md_psa.h"
Manuel Pégourié-Gonnardddbf61a2023-03-28 12:14:01 +020059#include "mbedtls/psa_util.h"
Pol Henarejos4712d4c2022-05-20 14:17:14 +020060#endif
Paul Bakker17373852011-01-06 14:20:01 +000061
Gilles Peskine12612e52022-10-22 20:07:28 +020062#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnard9b146392023-03-09 15:56:14 +010063#include "psa_crypto_core.h"
Gilles Peskine12612e52022-10-22 20:07:28 +020064#endif
65
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010066#include "mbedtls/platform.h"
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010067
Rich Evans00ab4702015-02-06 13:43:58 +000068#include <string.h>
Paul Bakker17373852011-01-06 14:20:01 +000069
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +020070#if defined(MBEDTLS_FS_IO)
71#include <stdio.h>
Paul Bakkeraf5c85f2011-04-18 03:47:52 +000072#endif
73
Manuel Pégourié-Gonnardcf61a742023-05-25 09:11:41 +020074/* See comment above MBEDTLS_MD_MAX_SIZE in md.h */
75#if defined(MBEDTLS_PSA_CRYPTO_C) && MBEDTLS_MD_MAX_SIZE < PSA_HASH_MAX_SIZE
76#error "Internal error: MBEDTLS_MD_MAX_SIZE < PSA_HASH_MAX_SIZE"
77#endif
78
Gilles Peskine83d9e092022-10-22 18:32:43 +020079#if defined(MBEDTLS_MD_CAN_MD5)
Gilles Peskine84867cf2019-07-19 15:46:03 +020080const mbedtls_md_info_t mbedtls_md5_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020081 "MD5",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020082 MBEDTLS_MD_MD5,
Gilles Peskine84867cf2019-07-19 15:46:03 +020083 16,
84 64,
85};
86#endif
87
Gilles Peskine83d9e092022-10-22 18:32:43 +020088#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Gilles Peskine84867cf2019-07-19 15:46:03 +020089const mbedtls_md_info_t mbedtls_ripemd160_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020090 "RIPEMD160",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020091 MBEDTLS_MD_RIPEMD160,
Gilles Peskine84867cf2019-07-19 15:46:03 +020092 20,
93 64,
94};
95#endif
96
Gilles Peskine83d9e092022-10-22 18:32:43 +020097#if defined(MBEDTLS_MD_CAN_SHA1)
Gilles Peskine84867cf2019-07-19 15:46:03 +020098const mbedtls_md_info_t mbedtls_sha1_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020099 "SHA1",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200100 MBEDTLS_MD_SHA1,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200101 20,
102 64,
103};
104#endif
105
Gilles Peskine83d9e092022-10-22 18:32:43 +0200106#if defined(MBEDTLS_MD_CAN_SHA224)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200107const mbedtls_md_info_t mbedtls_sha224_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200108 "SHA224",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200109 MBEDTLS_MD_SHA224,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200110 28,
111 64,
112};
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200113#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200114
Gilles Peskine83d9e092022-10-22 18:32:43 +0200115#if defined(MBEDTLS_MD_CAN_SHA256)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200116const mbedtls_md_info_t mbedtls_sha256_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200117 "SHA256",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200118 MBEDTLS_MD_SHA256,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200119 32,
120 64,
121};
122#endif
123
Gilles Peskine83d9e092022-10-22 18:32:43 +0200124#if defined(MBEDTLS_MD_CAN_SHA384)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200125const mbedtls_md_info_t mbedtls_sha384_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200126 "SHA384",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200127 MBEDTLS_MD_SHA384,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200128 48,
129 128,
130};
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200131#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200132
Gilles Peskine83d9e092022-10-22 18:32:43 +0200133#if defined(MBEDTLS_MD_CAN_SHA512)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200134const mbedtls_md_info_t mbedtls_sha512_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200135 "SHA512",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200136 MBEDTLS_MD_SHA512,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200137 64,
138 128,
139};
140#endif
141
Dave Rodgmanff45d442023-06-08 10:11:34 +0100142#if defined(MBEDTLS_MD_CAN_SHA3_224)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200143const mbedtls_md_info_t mbedtls_sha3_224_info = {
144 "SHA3-224",
145 MBEDTLS_MD_SHA3_224,
146 28,
147 144,
148};
Dave Rodgmanff45d442023-06-08 10:11:34 +0100149#endif
150
151#if defined(MBEDTLS_MD_CAN_SHA3_256)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200152const mbedtls_md_info_t mbedtls_sha3_256_info = {
153 "SHA3-256",
154 MBEDTLS_MD_SHA3_256,
155 32,
156 136,
157};
Dave Rodgmanff45d442023-06-08 10:11:34 +0100158#endif
159
160#if defined(MBEDTLS_MD_CAN_SHA3_384)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200161const mbedtls_md_info_t mbedtls_sha3_384_info = {
162 "SHA3-384",
163 MBEDTLS_MD_SHA3_384,
164 48,
165 104,
166};
Dave Rodgmanff45d442023-06-08 10:11:34 +0100167#endif
168
169#if defined(MBEDTLS_MD_CAN_SHA3_512)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200170const mbedtls_md_info_t mbedtls_sha3_512_info = {
171 "SHA3-512",
172 MBEDTLS_MD_SHA3_512,
173 64,
174 72,
175};
176#endif
177
Gilles Peskine449bd832023-01-11 14:50:10 +0100178const mbedtls_md_info_t *mbedtls_md_info_from_type(mbedtls_md_type_t md_type)
Paul Bakker17373852011-01-06 14:20:01 +0000179{
Gilles Peskine449bd832023-01-11 14:50:10 +0100180 switch (md_type) {
Gilles Peskine83d9e092022-10-22 18:32:43 +0200181#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200182 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100183 return &mbedtls_md5_info;
Paul Bakker17373852011-01-06 14:20:01 +0000184#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200185#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200186 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100187 return &mbedtls_ripemd160_info;
Manuel Pégourié-Gonnarde4d47a62014-01-17 20:41:32 +0100188#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200189#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200190 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100191 return &mbedtls_sha1_info;
Paul Bakker17373852011-01-06 14:20:01 +0000192#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200193#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200194 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100195 return &mbedtls_sha224_info;
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200196#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200197#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200198 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100199 return &mbedtls_sha256_info;
Paul Bakker17373852011-01-06 14:20:01 +0000200#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200201#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200202 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100203 return &mbedtls_sha384_info;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200204#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200205#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200206 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100207 return &mbedtls_sha512_info;
Paul Bakker17373852011-01-06 14:20:01 +0000208#endif
Dave Rodgman6d4933e2023-06-08 16:03:54 +0100209#if defined(MBEDTLS_MD_CAN_SHA3_224)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200210 case MBEDTLS_MD_SHA3_224:
Pol Henarejosa6779282023-02-08 00:50:04 +0100211 return &mbedtls_sha3_224_info;
Dave Rodgman6d4933e2023-06-08 16:03:54 +0100212#endif
213#if defined(MBEDTLS_MD_CAN_SHA3_256)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200214 case MBEDTLS_MD_SHA3_256:
Pol Henarejosa6779282023-02-08 00:50:04 +0100215 return &mbedtls_sha3_256_info;
Dave Rodgman6d4933e2023-06-08 16:03:54 +0100216#endif
217#if defined(MBEDTLS_MD_CAN_SHA3_384)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200218 case MBEDTLS_MD_SHA3_384:
Pol Henarejosa6779282023-02-08 00:50:04 +0100219 return &mbedtls_sha3_384_info;
Dave Rodgman6d4933e2023-06-08 16:03:54 +0100220#endif
221#if defined(MBEDTLS_MD_CAN_SHA3_512)
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200222 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100223 return &mbedtls_sha3_512_info;
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200224#endif
Paul Bakker17373852011-01-06 14:20:01 +0000225 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100226 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000227 }
228}
229
Gilles Peskine12612e52022-10-22 20:07:28 +0200230#if defined(MBEDTLS_MD_SOME_PSA)
231static psa_algorithm_t psa_alg_of_md(const mbedtls_md_info_t *info)
Max Fillinger0bb38332021-12-28 16:32:00 +0100232{
Gilles Peskine12612e52022-10-22 20:07:28 +0200233 switch (info->type) {
234#if defined(MBEDTLS_MD_MD5_VIA_PSA)
235 case MBEDTLS_MD_MD5:
236 return PSA_ALG_MD5;
237#endif
238#if defined(MBEDTLS_MD_RIPEMD160_VIA_PSA)
239 case MBEDTLS_MD_RIPEMD160:
240 return PSA_ALG_RIPEMD160;
241#endif
242#if defined(MBEDTLS_MD_SHA1_VIA_PSA)
243 case MBEDTLS_MD_SHA1:
244 return PSA_ALG_SHA_1;
245#endif
246#if defined(MBEDTLS_MD_SHA224_VIA_PSA)
247 case MBEDTLS_MD_SHA224:
248 return PSA_ALG_SHA_224;
249#endif
250#if defined(MBEDTLS_MD_SHA256_VIA_PSA)
251 case MBEDTLS_MD_SHA256:
252 return PSA_ALG_SHA_256;
253#endif
254#if defined(MBEDTLS_MD_SHA384_VIA_PSA)
255 case MBEDTLS_MD_SHA384:
256 return PSA_ALG_SHA_384;
257#endif
258#if defined(MBEDTLS_MD_SHA512_VIA_PSA)
259 case MBEDTLS_MD_SHA512:
260 return PSA_ALG_SHA_512;
261#endif
Dave Rodgman852b6c32023-07-05 19:47:08 +0100262#if defined(MBEDTLS_MD_SHA3_224_VIA_PSA)
263 case MBEDTLS_MD_SHA3_224:
264 return PSA_ALG_SHA3_224;
265#endif
266#if defined(MBEDTLS_MD_SHA3_256_VIA_PSA)
267 case MBEDTLS_MD_SHA3_256:
268 return PSA_ALG_SHA3_256;
269#endif
270#if defined(MBEDTLS_MD_SHA3_384_VIA_PSA)
271 case MBEDTLS_MD_SHA3_384:
272 return PSA_ALG_SHA3_384;
273#endif
274#if defined(MBEDTLS_MD_SHA3_512_VIA_PSA)
275 case MBEDTLS_MD_SHA3_512:
276 return PSA_ALG_SHA3_512;
277#endif
Gilles Peskine12612e52022-10-22 20:07:28 +0200278 default:
279 return PSA_ALG_NONE;
280 }
281}
282
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100283static int md_can_use_psa(const mbedtls_md_info_t *info)
Gilles Peskine12612e52022-10-22 20:07:28 +0200284{
Manuel Pégourié-Gonnard9b146392023-03-09 15:56:14 +0100285 psa_algorithm_t alg = psa_alg_of_md(info);
286 if (alg == PSA_ALG_NONE) {
287 return 0;
Gilles Peskine449bd832023-01-11 14:50:10 +0100288 }
Max Fillinger0bb38332021-12-28 16:32:00 +0100289
Manuel Pégourié-Gonnard9b146392023-03-09 15:56:14 +0100290 return psa_can_do_hash(alg);
Max Fillinger0bb38332021-12-28 16:32:00 +0100291}
Gilles Peskine12612e52022-10-22 20:07:28 +0200292#endif /* MBEDTLS_MD_SOME_PSA */
293
Gilles Peskine449bd832023-01-11 14:50:10 +0100294void mbedtls_md_init(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200295{
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100296 /* Note: this sets engine (if present) to MBEDTLS_MD_ENGINE_LEGACY */
Gilles Peskine449bd832023-01-11 14:50:10 +0100297 memset(ctx, 0, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200298}
299
Gilles Peskine449bd832023-01-11 14:50:10 +0100300void mbedtls_md_free(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200301{
Gilles Peskine449bd832023-01-11 14:50:10 +0100302 if (ctx == NULL || ctx->md_info == NULL) {
Paul Bakker84bbeb52014-07-01 14:53:22 +0200303 return;
Gilles Peskine449bd832023-01-11 14:50:10 +0100304 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200305
Gilles Peskine449bd832023-01-11 14:50:10 +0100306 if (ctx->md_ctx != NULL) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200307#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100308 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200309 psa_hash_abort(ctx->md_ctx);
310 } else
311#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100312 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200313#if defined(MBEDTLS_MD5_C)
314 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100315 mbedtls_md5_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200316 break;
317#endif
318#if defined(MBEDTLS_RIPEMD160_C)
319 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100320 mbedtls_ripemd160_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200321 break;
322#endif
323#if defined(MBEDTLS_SHA1_C)
324 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100325 mbedtls_sha1_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200326 break;
327#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200328#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200329 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100330 mbedtls_sha256_free(ctx->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200331 break;
332#endif
333#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200334 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100335 mbedtls_sha256_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200336 break;
337#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200338#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200339 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100340 mbedtls_sha512_free(ctx->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200341 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200342#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200343#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200344 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100345 mbedtls_sha512_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200346 break;
347#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200348#if defined(MBEDTLS_SHA3_C)
349 case MBEDTLS_MD_SHA3_224:
350 case MBEDTLS_MD_SHA3_256:
351 case MBEDTLS_MD_SHA3_384:
352 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100353 mbedtls_sha3_free(ctx->md_ctx);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200354 break;
355#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200356 default:
357 /* Shouldn't happen */
358 break;
359 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100360 mbedtls_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200361 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200362
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100363#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100364 if (ctx->hmac_ctx != NULL) {
365 mbedtls_platform_zeroize(ctx->hmac_ctx,
366 2 * ctx->md_info->block_size);
367 mbedtls_free(ctx->hmac_ctx);
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100368 }
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100369#endif
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100370
Gilles Peskine449bd832023-01-11 14:50:10 +0100371 mbedtls_platform_zeroize(ctx, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200372}
373
Gilles Peskine449bd832023-01-11 14:50:10 +0100374int mbedtls_md_clone(mbedtls_md_context_t *dst,
375 const mbedtls_md_context_t *src)
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200376{
Gilles Peskine449bd832023-01-11 14:50:10 +0100377 if (dst == NULL || dst->md_info == NULL ||
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200378 src == NULL || src->md_info == NULL ||
Gilles Peskine449bd832023-01-11 14:50:10 +0100379 dst->md_info != src->md_info) {
380 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200381 }
382
Gilles Peskine12612e52022-10-22 20:07:28 +0200383#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100384 if (src->engine != dst->engine) {
385 /* This can happen with src set to legacy because PSA wasn't ready
386 * yet, and dst to PSA because it became ready in the meantime.
387 * We currently don't support that case (we'd need to re-allocate
388 * md_ctx to the size of the appropriate MD context). */
389 return MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE;
390 }
391
392 if (src->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200393 psa_status_t status = psa_hash_clone(src->md_ctx, dst->md_ctx);
394 return mbedtls_md_error_from_psa(status);
395 }
396#endif
397
Gilles Peskine449bd832023-01-11 14:50:10 +0100398 switch (src->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200399#if defined(MBEDTLS_MD5_C)
400 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100401 mbedtls_md5_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200402 break;
403#endif
404#if defined(MBEDTLS_RIPEMD160_C)
405 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100406 mbedtls_ripemd160_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200407 break;
408#endif
409#if defined(MBEDTLS_SHA1_C)
410 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100411 mbedtls_sha1_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200412 break;
413#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200414#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200415 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100416 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200417 break;
418#endif
419#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200420 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100421 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200422 break;
423#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200424#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200425 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100426 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200427 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200428#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200429#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200430 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100431 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200432 break;
433#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200434#if defined(MBEDTLS_SHA3_C)
435 case MBEDTLS_MD_SHA3_224:
436 case MBEDTLS_MD_SHA3_256:
437 case MBEDTLS_MD_SHA3_384:
438 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100439 mbedtls_sha3_clone(dst->md_ctx, src->md_ctx);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200440 break;
441#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200442 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100443 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200444 }
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200445
Gilles Peskine449bd832023-01-11 14:50:10 +0100446 return 0;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200447}
448
Gilles Peskine449bd832023-01-11 14:50:10 +0100449#define ALLOC(type) \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200450 do { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100451 ctx->md_ctx = mbedtls_calloc(1, sizeof(mbedtls_##type##_context)); \
452 if (ctx->md_ctx == NULL) \
453 return MBEDTLS_ERR_MD_ALLOC_FAILED; \
454 mbedtls_##type##_init(ctx->md_ctx); \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200455 } \
Gilles Peskine449bd832023-01-11 14:50:10 +0100456 while (0)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200457
Gilles Peskine449bd832023-01-11 14:50:10 +0100458int mbedtls_md_setup(mbedtls_md_context_t *ctx, const mbedtls_md_info_t *md_info, int hmac)
Paul Bakker17373852011-01-06 14:20:01 +0000459{
Thomas Daubney73cfde82023-05-30 15:34:28 +0100460#if defined(MBEDTLS_MD_C)
461 if (ctx == NULL) {
462 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
463 }
464#endif
465 if (md_info == NULL) {
Gilles Peskine449bd832023-01-11 14:50:10 +0100466 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
467 }
Paul Bakker17373852011-01-06 14:20:01 +0000468
Gilles Peskined15c7402020-08-19 12:03:11 +0200469 ctx->md_info = md_info;
470 ctx->md_ctx = NULL;
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100471#if defined(MBEDTLS_MD_C)
Gilles Peskined15c7402020-08-19 12:03:11 +0200472 ctx->hmac_ctx = NULL;
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100473#else
474 if (hmac != 0) {
475 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
476 }
477#endif
Gilles Peskined15c7402020-08-19 12:03:11 +0200478
Gilles Peskine12612e52022-10-22 20:07:28 +0200479#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100480 if (md_can_use_psa(ctx->md_info)) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200481 ctx->md_ctx = mbedtls_calloc(1, sizeof(psa_hash_operation_t));
482 if (ctx->md_ctx == NULL) {
483 return MBEDTLS_ERR_MD_ALLOC_FAILED;
484 }
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100485 ctx->engine = MBEDTLS_MD_ENGINE_PSA;
Gilles Peskine12612e52022-10-22 20:07:28 +0200486 } else
487#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100488 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200489#if defined(MBEDTLS_MD5_C)
490 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100491 ALLOC(md5);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200492 break;
493#endif
494#if defined(MBEDTLS_RIPEMD160_C)
495 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100496 ALLOC(ripemd160);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200497 break;
498#endif
499#if defined(MBEDTLS_SHA1_C)
500 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100501 ALLOC(sha1);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200502 break;
503#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200504#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200505 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100506 ALLOC(sha256);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200507 break;
508#endif
509#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200510 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100511 ALLOC(sha256);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200512 break;
513#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200514#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200515 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100516 ALLOC(sha512);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200517 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200518#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200519#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200520 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100521 ALLOC(sha512);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200522 break;
523#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200524#if defined(MBEDTLS_SHA3_C)
525 case MBEDTLS_MD_SHA3_224:
526 case MBEDTLS_MD_SHA3_256:
527 case MBEDTLS_MD_SHA3_384:
528 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100529 ALLOC(sha3);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200530 break;
531#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200532 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100533 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200534 }
Paul Bakker17373852011-01-06 14:20:01 +0000535
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100536#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100537 if (hmac != 0) {
538 ctx->hmac_ctx = mbedtls_calloc(2, md_info->block_size);
539 if (ctx->hmac_ctx == NULL) {
540 mbedtls_md_free(ctx);
541 return MBEDTLS_ERR_MD_ALLOC_FAILED;
Manuel Pégourié-Gonnard4063ceb2015-03-25 16:08:53 +0100542 }
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100543 }
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100544#endif
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100545
Gilles Peskine449bd832023-01-11 14:50:10 +0100546 return 0;
Paul Bakker17373852011-01-06 14:20:01 +0000547}
Gilles Peskine84867cf2019-07-19 15:46:03 +0200548#undef ALLOC
Paul Bakker17373852011-01-06 14:20:01 +0000549
Gilles Peskine449bd832023-01-11 14:50:10 +0100550int mbedtls_md_starts(mbedtls_md_context_t *ctx)
Paul Bakker562535d2011-01-20 16:42:01 +0000551{
Thomas Daubney73cfde82023-05-30 15:34:28 +0100552#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100553 if (ctx == NULL || ctx->md_info == NULL) {
554 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
555 }
Thomas Daubney73cfde82023-05-30 15:34:28 +0100556#endif
Paul Bakker562535d2011-01-20 16:42:01 +0000557
Gilles Peskine12612e52022-10-22 20:07:28 +0200558#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100559 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
560 psa_algorithm_t alg = psa_alg_of_md(ctx->md_info);
Gilles Peskine12612e52022-10-22 20:07:28 +0200561 psa_hash_abort(ctx->md_ctx);
562 psa_status_t status = psa_hash_setup(ctx->md_ctx, alg);
563 return mbedtls_md_error_from_psa(status);
564 }
565#endif
566
Gilles Peskine449bd832023-01-11 14:50:10 +0100567 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200568#if defined(MBEDTLS_MD5_C)
569 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100570 return mbedtls_md5_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200571#endif
572#if defined(MBEDTLS_RIPEMD160_C)
573 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100574 return mbedtls_ripemd160_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200575#endif
576#if defined(MBEDTLS_SHA1_C)
577 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100578 return mbedtls_sha1_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200579#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200580#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200581 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100582 return mbedtls_sha256_starts(ctx->md_ctx, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200583#endif
584#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200585 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100586 return mbedtls_sha256_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200587#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200588#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200589 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100590 return mbedtls_sha512_starts(ctx->md_ctx, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200591#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200592#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200593 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100594 return mbedtls_sha512_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200595#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200596#if defined(MBEDTLS_SHA3_C)
597 case MBEDTLS_MD_SHA3_224:
Pol Henarejosa6779282023-02-08 00:50:04 +0100598 return mbedtls_sha3_starts(ctx->md_ctx, MBEDTLS_SHA3_224);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200599 case MBEDTLS_MD_SHA3_256:
Pol Henarejosa6779282023-02-08 00:50:04 +0100600 return mbedtls_sha3_starts(ctx->md_ctx, MBEDTLS_SHA3_256);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200601 case MBEDTLS_MD_SHA3_384:
Pol Henarejosa6779282023-02-08 00:50:04 +0100602 return mbedtls_sha3_starts(ctx->md_ctx, MBEDTLS_SHA3_384);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200603 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100604 return mbedtls_sha3_starts(ctx->md_ctx, MBEDTLS_SHA3_512);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200605#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200606 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100607 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200608 }
Paul Bakker562535d2011-01-20 16:42:01 +0000609}
610
Gilles Peskine449bd832023-01-11 14:50:10 +0100611int mbedtls_md_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000612{
Thomas Daubney73cfde82023-05-30 15:34:28 +0100613#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100614 if (ctx == NULL || ctx->md_info == NULL) {
615 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
616 }
Thomas Daubney73cfde82023-05-30 15:34:28 +0100617#endif
Paul Bakker17373852011-01-06 14:20:01 +0000618
Gilles Peskine12612e52022-10-22 20:07:28 +0200619#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100620 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200621 psa_status_t status = psa_hash_update(ctx->md_ctx, input, ilen);
622 return mbedtls_md_error_from_psa(status);
623 }
624#endif
625
Gilles Peskine449bd832023-01-11 14:50:10 +0100626 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200627#if defined(MBEDTLS_MD5_C)
628 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100629 return mbedtls_md5_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200630#endif
631#if defined(MBEDTLS_RIPEMD160_C)
632 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100633 return mbedtls_ripemd160_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200634#endif
635#if defined(MBEDTLS_SHA1_C)
636 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100637 return mbedtls_sha1_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200638#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200639#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200640 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100641 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200642#endif
643#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200644 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100645 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200646#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200647#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200648 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100649 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200650#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200651#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200652 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100653 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200654#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200655#if defined(MBEDTLS_SHA3_C)
656 case MBEDTLS_MD_SHA3_224:
657 case MBEDTLS_MD_SHA3_256:
658 case MBEDTLS_MD_SHA3_384:
659 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100660 return mbedtls_sha3_update(ctx->md_ctx, input, ilen);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200661#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200662 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100663 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200664 }
Paul Bakker17373852011-01-06 14:20:01 +0000665}
666
Gilles Peskine449bd832023-01-11 14:50:10 +0100667int mbedtls_md_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000668{
Thomas Daubney73cfde82023-05-30 15:34:28 +0100669#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100670 if (ctx == NULL || ctx->md_info == NULL) {
671 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
672 }
Thomas Daubney73cfde82023-05-30 15:34:28 +0100673#endif
Paul Bakker17373852011-01-06 14:20:01 +0000674
Gilles Peskine12612e52022-10-22 20:07:28 +0200675#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100676 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200677 size_t size = ctx->md_info->size;
678 psa_status_t status = psa_hash_finish(ctx->md_ctx,
679 output, size, &size);
680 return mbedtls_md_error_from_psa(status);
681 }
682#endif
683
Gilles Peskine449bd832023-01-11 14:50:10 +0100684 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200685#if defined(MBEDTLS_MD5_C)
686 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100687 return mbedtls_md5_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200688#endif
689#if defined(MBEDTLS_RIPEMD160_C)
690 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100691 return mbedtls_ripemd160_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200692#endif
693#if defined(MBEDTLS_SHA1_C)
694 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100695 return mbedtls_sha1_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200696#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200697#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200698 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100699 return mbedtls_sha256_finish(ctx->md_ctx, output);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200700#endif
701#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200702 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100703 return mbedtls_sha256_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200704#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200705#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200706 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100707 return mbedtls_sha512_finish(ctx->md_ctx, output);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200708#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200709#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200710 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100711 return mbedtls_sha512_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200712#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200713#if defined(MBEDTLS_SHA3_C)
714 case MBEDTLS_MD_SHA3_224:
715 case MBEDTLS_MD_SHA3_256:
716 case MBEDTLS_MD_SHA3_384:
717 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100718 return mbedtls_sha3_finish(ctx->md_ctx, output, ctx->md_info->size);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200719#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200720 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100721 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200722 }
Paul Bakker17373852011-01-06 14:20:01 +0000723}
724
Gilles Peskine449bd832023-01-11 14:50:10 +0100725int mbedtls_md(const mbedtls_md_info_t *md_info, const unsigned char *input, size_t ilen,
726 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000727{
Gilles Peskine449bd832023-01-11 14:50:10 +0100728 if (md_info == NULL) {
729 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
730 }
Paul Bakker17373852011-01-06 14:20:01 +0000731
Gilles Peskine12612e52022-10-22 20:07:28 +0200732#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100733 if (md_can_use_psa(md_info)) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200734 size_t size = md_info->size;
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100735 psa_status_t status = psa_hash_compute(psa_alg_of_md(md_info),
Gilles Peskine12612e52022-10-22 20:07:28 +0200736 input, ilen,
737 output, size, &size);
738 return mbedtls_md_error_from_psa(status);
739 }
740#endif
741
Gilles Peskine449bd832023-01-11 14:50:10 +0100742 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200743#if defined(MBEDTLS_MD5_C)
744 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100745 return mbedtls_md5(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200746#endif
747#if defined(MBEDTLS_RIPEMD160_C)
748 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100749 return mbedtls_ripemd160(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200750#endif
751#if defined(MBEDTLS_SHA1_C)
752 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100753 return mbedtls_sha1(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200754#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200755#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200756 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100757 return mbedtls_sha256(input, ilen, output, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200758#endif
759#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200760 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100761 return mbedtls_sha256(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200762#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200763#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200764 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100765 return mbedtls_sha512(input, ilen, output, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200766#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200767#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200768 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100769 return mbedtls_sha512(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200770#endif
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200771#if defined(MBEDTLS_SHA3_C)
772 case MBEDTLS_MD_SHA3_224:
Pol Henarejosa6779282023-02-08 00:50:04 +0100773 return mbedtls_sha3(MBEDTLS_SHA3_224, input, ilen, output, md_info->size);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200774 case MBEDTLS_MD_SHA3_256:
Pol Henarejosa6779282023-02-08 00:50:04 +0100775 return mbedtls_sha3(MBEDTLS_SHA3_256, input, ilen, output, md_info->size);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200776 case MBEDTLS_MD_SHA3_384:
Pol Henarejosa6779282023-02-08 00:50:04 +0100777 return mbedtls_sha3(MBEDTLS_SHA3_384, input, ilen, output, md_info->size);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200778 case MBEDTLS_MD_SHA3_512:
Pol Henarejosa6779282023-02-08 00:50:04 +0100779 return mbedtls_sha3(MBEDTLS_SHA3_512, input, ilen, output, md_info->size);
Pol Henarejos4712d4c2022-05-20 14:17:14 +0200780#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200781 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100782 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200783 }
Paul Bakker17373852011-01-06 14:20:01 +0000784}
785
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100786unsigned char mbedtls_md_get_size(const mbedtls_md_info_t *md_info)
787{
788 if (md_info == NULL) {
789 return 0;
790 }
791
792 return md_info->size;
793}
794
795mbedtls_md_type_t mbedtls_md_get_type(const mbedtls_md_info_t *md_info)
796{
797 if (md_info == NULL) {
798 return MBEDTLS_MD_NONE;
799 }
800
801 return md_info->type;
802}
803
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +0200804#if defined(MBEDTLS_PSA_CRYPTO_C)
805psa_algorithm_t mbedtls_md_psa_alg_from_type(mbedtls_md_type_t md_type)
806{
807 switch (md_type) {
808#if defined(MBEDTLS_MD_CAN_MD5)
809 case MBEDTLS_MD_MD5:
810 return PSA_ALG_MD5;
811#endif
812#if defined(MBEDTLS_MD_CAN_RIPEMD160)
813 case MBEDTLS_MD_RIPEMD160:
814 return PSA_ALG_RIPEMD160;
815#endif
816#if defined(MBEDTLS_MD_CAN_SHA1)
817 case MBEDTLS_MD_SHA1:
818 return PSA_ALG_SHA_1;
819#endif
820#if defined(MBEDTLS_MD_CAN_SHA224)
821 case MBEDTLS_MD_SHA224:
822 return PSA_ALG_SHA_224;
823#endif
824#if defined(MBEDTLS_MD_CAN_SHA256)
825 case MBEDTLS_MD_SHA256:
826 return PSA_ALG_SHA_256;
827#endif
828#if defined(MBEDTLS_MD_CAN_SHA384)
829 case MBEDTLS_MD_SHA384:
830 return PSA_ALG_SHA_384;
831#endif
832#if defined(MBEDTLS_MD_CAN_SHA512)
833 case MBEDTLS_MD_SHA512:
834 return PSA_ALG_SHA_512;
835#endif
Dave Rodgman3a498a62023-07-05 18:58:04 +0100836#if defined(MBEDTLS_MD_CAN_SHA3_224)
837 case MBEDTLS_MD_SHA3_224:
838 return PSA_ALG_SHA3_224;
839#endif
840#if defined(MBEDTLS_MD_CAN_SHA3_256)
841 case MBEDTLS_MD_SHA3_256:
842 return PSA_ALG_SHA3_256;
843#endif
844#if defined(MBEDTLS_MD_CAN_SHA3_384)
845 case MBEDTLS_MD_SHA3_384:
846 return PSA_ALG_SHA3_384;
847#endif
848#if defined(MBEDTLS_MD_CAN_SHA3_512)
849 case MBEDTLS_MD_SHA3_512:
850 return PSA_ALG_SHA3_512;
851#endif
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +0200852 default:
853 return PSA_ALG_NONE;
854 }
855}
856
857mbedtls_md_type_t mbedtls_md_type_from_psa_alg(psa_algorithm_t psa_alg)
858{
859 switch (psa_alg) {
860#if defined(MBEDTLS_MD_CAN_MD5)
861 case PSA_ALG_MD5:
862 return MBEDTLS_MD_MD5;
863#endif
864#if defined(MBEDTLS_MD_CAN_RIPEMD160)
865 case PSA_ALG_RIPEMD160:
866 return MBEDTLS_MD_RIPEMD160;
867#endif
868#if defined(MBEDTLS_MD_CAN_SHA1)
869 case PSA_ALG_SHA_1:
870 return MBEDTLS_MD_SHA1;
871#endif
872#if defined(MBEDTLS_MD_CAN_SHA224)
873 case PSA_ALG_SHA_224:
874 return MBEDTLS_MD_SHA224;
875#endif
876#if defined(MBEDTLS_MD_CAN_SHA256)
877 case PSA_ALG_SHA_256:
878 return MBEDTLS_MD_SHA256;
879#endif
880#if defined(MBEDTLS_MD_CAN_SHA384)
881 case PSA_ALG_SHA_384:
882 return MBEDTLS_MD_SHA384;
883#endif
884#if defined(MBEDTLS_MD_CAN_SHA512)
885 case PSA_ALG_SHA_512:
886 return MBEDTLS_MD_SHA512;
887#endif
Dave Rodgman3a498a62023-07-05 18:58:04 +0100888#if defined(MBEDTLS_MD_CAN_SHA3_224)
889 case PSA_ALG_SHA3_224:
890 return MBEDTLS_MD_SHA3_224;
891#endif
892#if defined(MBEDTLS_MD_CAN_SHA3_256)
893 case PSA_ALG_SHA3_256:
894 return MBEDTLS_MD_SHA3_256;
895#endif
896#if defined(MBEDTLS_MD_CAN_SHA3_384)
897 case PSA_ALG_SHA3_384:
898 return MBEDTLS_MD_SHA3_384;
899#endif
900#if defined(MBEDTLS_MD_CAN_SHA3_512)
901 case PSA_ALG_SHA3_512:
902 return MBEDTLS_MD_SHA3_512;
903#endif
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +0200904 default:
905 return MBEDTLS_MD_NONE;
906 }
907}
908
909int mbedtls_md_error_from_psa(psa_status_t status)
910{
Manuel Pégourié-Gonnardb3b54ab2023-03-29 12:36:34 +0200911 return PSA_TO_MBEDTLS_ERR_LIST(status, psa_to_md_errors,
912 psa_generic_status_to_mbedtls);
Manuel Pégourié-Gonnard36fb12e2023-03-28 11:33:23 +0200913}
914#endif /* MBEDTLS_PSA_CRYPTO_C */
915
916
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100917/************************************************************************
918 * Functions above this separator are part of MBEDTLS_MD_LIGHT, *
919 * functions below are only available when MBEDTLS_MD_C is set. *
920 ************************************************************************/
921#if defined(MBEDTLS_MD_C)
922
923/*
924 * Reminder: update profiles in x509_crt.c when adding a new hash!
925 */
926static const int supported_digests[] = {
927
Gilles Peskine83d9e092022-10-22 18:32:43 +0200928#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100929 MBEDTLS_MD_SHA512,
930#endif
931
Gilles Peskine83d9e092022-10-22 18:32:43 +0200932#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100933 MBEDTLS_MD_SHA384,
934#endif
935
Gilles Peskine83d9e092022-10-22 18:32:43 +0200936#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100937 MBEDTLS_MD_SHA256,
938#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200939#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100940 MBEDTLS_MD_SHA224,
941#endif
942
Gilles Peskine83d9e092022-10-22 18:32:43 +0200943#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100944 MBEDTLS_MD_SHA1,
945#endif
946
Gilles Peskine83d9e092022-10-22 18:32:43 +0200947#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100948 MBEDTLS_MD_RIPEMD160,
949#endif
950
Gilles Peskine83d9e092022-10-22 18:32:43 +0200951#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100952 MBEDTLS_MD_MD5,
953#endif
954
Dave Rodgmanff45d442023-06-08 10:11:34 +0100955#if defined(MBEDTLS_MD_CAN_SHA3_224)
Pol Henarejosd06c6fc2023-05-05 16:01:18 +0200956 MBEDTLS_MD_SHA3_224,
Dave Rodgmanff45d442023-06-08 10:11:34 +0100957#endif
958
959#if defined(MBEDTLS_MD_CAN_SHA3_256)
Pol Henarejosd06c6fc2023-05-05 16:01:18 +0200960 MBEDTLS_MD_SHA3_256,
Dave Rodgmanff45d442023-06-08 10:11:34 +0100961#endif
962
963#if defined(MBEDTLS_MD_CAN_SHA3_384)
Pol Henarejosd06c6fc2023-05-05 16:01:18 +0200964 MBEDTLS_MD_SHA3_384,
Dave Rodgmanff45d442023-06-08 10:11:34 +0100965#endif
966
967#if defined(MBEDTLS_MD_CAN_SHA3_512)
Pol Henarejosd06c6fc2023-05-05 16:01:18 +0200968 MBEDTLS_MD_SHA3_512,
969#endif
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100970
971 MBEDTLS_MD_NONE
972};
973
974const int *mbedtls_md_list(void)
975{
976 return supported_digests;
977}
978
979const mbedtls_md_info_t *mbedtls_md_info_from_string(const char *md_name)
980{
981 if (NULL == md_name) {
982 return NULL;
983 }
984
985 /* Get the appropriate digest information */
Gilles Peskine83d9e092022-10-22 18:32:43 +0200986#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100987 if (!strcmp("MD5", md_name)) {
988 return mbedtls_md_info_from_type(MBEDTLS_MD_MD5);
989 }
990#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200991#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100992 if (!strcmp("RIPEMD160", md_name)) {
993 return mbedtls_md_info_from_type(MBEDTLS_MD_RIPEMD160);
994 }
995#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200996#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100997 if (!strcmp("SHA1", md_name) || !strcmp("SHA", md_name)) {
998 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA1);
999 }
1000#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +02001001#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +01001002 if (!strcmp("SHA224", md_name)) {
1003 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA224);
1004 }
1005#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +02001006#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +01001007 if (!strcmp("SHA256", md_name)) {
1008 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
1009 }
1010#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +02001011#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +01001012 if (!strcmp("SHA384", md_name)) {
1013 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA384);
1014 }
1015#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +02001016#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +01001017 if (!strcmp("SHA512", md_name)) {
1018 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA512);
1019 }
1020#endif
Dave Rodgmanff45d442023-06-08 10:11:34 +01001021#if defined(MBEDTLS_MD_CAN_SHA3_224)
Pol Henarejosd06c6fc2023-05-05 16:01:18 +02001022 if (!strcmp("SHA3-224", md_name)) {
1023 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA3_224);
Dave Rodgmanff45d442023-06-08 10:11:34 +01001024 }
1025#endif
1026#if defined(MBEDTLS_MD_CAN_SHA3_256)
1027 if (!strcmp("SHA3-256", md_name)) {
Pol Henarejosd06c6fc2023-05-05 16:01:18 +02001028 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA3_256);
Dave Rodgmanff45d442023-06-08 10:11:34 +01001029 }
1030#endif
1031#if defined(MBEDTLS_MD_CAN_SHA3_384)
1032 if (!strcmp("SHA3-384", md_name)) {
Pol Henarejosd06c6fc2023-05-05 16:01:18 +02001033 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA3_384);
Dave Rodgmanff45d442023-06-08 10:11:34 +01001034 }
1035#endif
1036#if defined(MBEDTLS_MD_CAN_SHA3_512)
1037 if (!strcmp("SHA3-512", md_name)) {
Pol Henarejosd06c6fc2023-05-05 16:01:18 +02001038 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA3_512);
1039 }
1040#endif
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +01001041 return NULL;
1042}
1043
1044const mbedtls_md_info_t *mbedtls_md_info_from_ctx(
1045 const mbedtls_md_context_t *ctx)
1046{
1047 if (ctx == NULL) {
1048 return NULL;
1049 }
1050
1051 return ctx->MBEDTLS_PRIVATE(md_info);
1052}
1053
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001054#if defined(MBEDTLS_FS_IO)
Gilles Peskine449bd832023-01-11 14:50:10 +01001055int mbedtls_md_file(const mbedtls_md_info_t *md_info, const char *path, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +00001056{
Janos Follath24eed8d2019-11-22 13:21:35 +00001057 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001058 FILE *f;
1059 size_t n;
1060 mbedtls_md_context_t ctx;
1061 unsigned char buf[1024];
Paul Bakker9c021ad2011-06-09 15:55:11 +00001062
Gilles Peskine449bd832023-01-11 14:50:10 +01001063 if (md_info == NULL) {
1064 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1065 }
Paul Bakker17373852011-01-06 14:20:01 +00001066
Gilles Peskine449bd832023-01-11 14:50:10 +01001067 if ((f = fopen(path, "rb")) == NULL) {
1068 return MBEDTLS_ERR_MD_FILE_IO_ERROR;
1069 }
Manuel Pégourié-Gonnardbcc03082015-06-24 00:09:29 +02001070
Gilles Peskineda0913b2022-06-30 17:03:40 +02001071 /* Ensure no stdio buffering of secrets, as such buffers cannot be wiped. */
Gilles Peskine449bd832023-01-11 14:50:10 +01001072 mbedtls_setbuf(f, NULL);
Gilles Peskineda0913b2022-06-30 17:03:40 +02001073
Gilles Peskine449bd832023-01-11 14:50:10 +01001074 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001075
Gilles Peskine449bd832023-01-11 14:50:10 +01001076 if ((ret = mbedtls_md_setup(&ctx, md_info, 0)) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001077 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001078 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001079
Gilles Peskine449bd832023-01-11 14:50:10 +01001080 if ((ret = mbedtls_md_starts(&ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001081 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001082 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001083
Gilles Peskine449bd832023-01-11 14:50:10 +01001084 while ((n = fread(buf, 1, sizeof(buf), f)) > 0) {
1085 if ((ret = mbedtls_md_update(&ctx, buf, n)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001086 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001087 }
1088 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001089
Gilles Peskine449bd832023-01-11 14:50:10 +01001090 if (ferror(f) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001091 ret = MBEDTLS_ERR_MD_FILE_IO_ERROR;
Gilles Peskine449bd832023-01-11 14:50:10 +01001092 } else {
1093 ret = mbedtls_md_finish(&ctx, output);
1094 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001095
1096cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +01001097 mbedtls_platform_zeroize(buf, sizeof(buf));
1098 fclose(f);
1099 mbedtls_md_free(&ctx);
Paul Bakker9c021ad2011-06-09 15:55:11 +00001100
Gilles Peskine449bd832023-01-11 14:50:10 +01001101 return ret;
Paul Bakker17373852011-01-06 14:20:01 +00001102}
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +02001103#endif /* MBEDTLS_FS_IO */
Paul Bakker17373852011-01-06 14:20:01 +00001104
Gilles Peskine449bd832023-01-11 14:50:10 +01001105int mbedtls_md_hmac_starts(mbedtls_md_context_t *ctx, const unsigned char *key, size_t keylen)
Paul Bakker17373852011-01-06 14:20:01 +00001106{
Janos Follath24eed8d2019-11-22 13:21:35 +00001107 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001108 unsigned char sum[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001109 unsigned char *ipad, *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001110
Gilles Peskine449bd832023-01-11 14:50:10 +01001111 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
1112 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1113 }
Paul Bakker17373852011-01-06 14:20:01 +00001114
Gilles Peskine449bd832023-01-11 14:50:10 +01001115 if (keylen > (size_t) ctx->md_info->block_size) {
1116 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001117 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001118 }
1119 if ((ret = mbedtls_md_update(ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001120 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001121 }
1122 if ((ret = mbedtls_md_finish(ctx, sum)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001123 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001124 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001125
1126 keylen = ctx->md_info->size;
1127 key = sum;
1128 }
1129
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001130 ipad = (unsigned char *) ctx->hmac_ctx;
1131 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
1132
Gilles Peskine449bd832023-01-11 14:50:10 +01001133 memset(ipad, 0x36, ctx->md_info->block_size);
1134 memset(opad, 0x5C, ctx->md_info->block_size);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001135
Gilles Peskine449bd832023-01-11 14:50:10 +01001136 mbedtls_xor(ipad, ipad, key, keylen);
1137 mbedtls_xor(opad, opad, key, keylen);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001138
Gilles Peskine449bd832023-01-11 14:50:10 +01001139 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001140 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001141 }
1142 if ((ret = mbedtls_md_update(ctx, ipad,
1143 ctx->md_info->block_size)) != 0) {
Andres Amaya Garcia42e5e102017-07-20 16:27:03 +01001144 goto cleanup;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001145 }
1146
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001147cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +01001148 mbedtls_platform_zeroize(sum, sizeof(sum));
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001149
Gilles Peskine449bd832023-01-11 14:50:10 +01001150 return ret;
Paul Bakker17373852011-01-06 14:20:01 +00001151}
1152
Gilles Peskine449bd832023-01-11 14:50:10 +01001153int mbedtls_md_hmac_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +00001154{
Gilles Peskine449bd832023-01-11 14:50:10 +01001155 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
1156 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1157 }
Paul Bakker17373852011-01-06 14:20:01 +00001158
Gilles Peskine449bd832023-01-11 14:50:10 +01001159 return mbedtls_md_update(ctx, input, ilen);
Paul Bakker17373852011-01-06 14:20:01 +00001160}
1161
Gilles Peskine449bd832023-01-11 14:50:10 +01001162int mbedtls_md_hmac_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +00001163{
Janos Follath24eed8d2019-11-22 13:21:35 +00001164 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001165 unsigned char tmp[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001166 unsigned char *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001167
Gilles Peskine449bd832023-01-11 14:50:10 +01001168 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
1169 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1170 }
Paul Bakker17373852011-01-06 14:20:01 +00001171
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001172 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
1173
Gilles Peskine449bd832023-01-11 14:50:10 +01001174 if ((ret = mbedtls_md_finish(ctx, tmp)) != 0) {
1175 return ret;
1176 }
1177 if ((ret = mbedtls_md_starts(ctx)) != 0) {
1178 return ret;
1179 }
1180 if ((ret = mbedtls_md_update(ctx, opad,
1181 ctx->md_info->block_size)) != 0) {
1182 return ret;
1183 }
1184 if ((ret = mbedtls_md_update(ctx, tmp,
1185 ctx->md_info->size)) != 0) {
1186 return ret;
1187 }
1188 return mbedtls_md_finish(ctx, output);
Paul Bakker17373852011-01-06 14:20:01 +00001189}
1190
Gilles Peskine449bd832023-01-11 14:50:10 +01001191int mbedtls_md_hmac_reset(mbedtls_md_context_t *ctx)
Paul Bakker17373852011-01-06 14:20:01 +00001192{
Janos Follath24eed8d2019-11-22 13:21:35 +00001193 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001194 unsigned char *ipad;
1195
Gilles Peskine449bd832023-01-11 14:50:10 +01001196 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
1197 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1198 }
Paul Bakker17373852011-01-06 14:20:01 +00001199
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +01001200 ipad = (unsigned char *) ctx->hmac_ctx;
1201
Gilles Peskine449bd832023-01-11 14:50:10 +01001202 if ((ret = mbedtls_md_starts(ctx)) != 0) {
1203 return ret;
1204 }
1205 return mbedtls_md_update(ctx, ipad, ctx->md_info->block_size);
Paul Bakker17373852011-01-06 14:20:01 +00001206}
1207
Gilles Peskine449bd832023-01-11 14:50:10 +01001208int mbedtls_md_hmac(const mbedtls_md_info_t *md_info,
1209 const unsigned char *key, size_t keylen,
1210 const unsigned char *input, size_t ilen,
1211 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +00001212{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001213 mbedtls_md_context_t ctx;
Janos Follath24eed8d2019-11-22 13:21:35 +00001214 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001215
Gilles Peskine449bd832023-01-11 14:50:10 +01001216 if (md_info == NULL) {
1217 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
1218 }
Paul Bakker17373852011-01-06 14:20:01 +00001219
Gilles Peskine449bd832023-01-11 14:50:10 +01001220 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001221
Gilles Peskine449bd832023-01-11 14:50:10 +01001222 if ((ret = mbedtls_md_setup(&ctx, md_info, 1)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001223 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001224 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001225
Gilles Peskine449bd832023-01-11 14:50:10 +01001226 if ((ret = mbedtls_md_hmac_starts(&ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001227 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001228 }
1229 if ((ret = mbedtls_md_hmac_update(&ctx, input, ilen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001230 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001231 }
1232 if ((ret = mbedtls_md_hmac_finish(&ctx, output)) != 0) {
Andres Amaya Garciaaa464ef2017-07-21 14:21:53 +01001233 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +01001234 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +01001235
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +01001236cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +01001237 mbedtls_md_free(&ctx);
Paul Bakker17373852011-01-06 14:20:01 +00001238
Gilles Peskine449bd832023-01-11 14:50:10 +01001239 return ret;
Paul Bakker17373852011-01-06 14:20:01 +00001240}
1241
Gilles Peskine449bd832023-01-11 14:50:10 +01001242const char *mbedtls_md_get_name(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +01001243{
Gilles Peskine449bd832023-01-11 14:50:10 +01001244 if (md_info == NULL) {
1245 return NULL;
1246 }
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +01001247
1248 return md_info->name;
1249}
1250
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001251#endif /* MBEDTLS_MD_C */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +01001252
1253#endif /* MBEDTLS_MD_LIGHT */