blob: bebe3580bdda9a3ea9df684898522b5a4bce9c73 [file] [log] [blame]
Paul Bakker17373852011-01-06 14:20:01 +00001/**
Gilles Peskine2091f3a2021-02-12 23:34:01 +01002 * \file md.c
Paul Bakker9af723c2014-05-01 13:03:14 +02003 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +00004 * \brief Generic message digest wrapper for mbed TLS
Paul Bakker17373852011-01-06 14:20:01 +00005 *
6 * \author Adriaan de Jong <dejong@fox-it.com>
7 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02008 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02009 * SPDX-License-Identifier: Apache-2.0
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License"); you may
12 * not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
Paul Bakker17373852011-01-06 14:20:01 +000022 */
23
Gilles Peskinedb09ef62020-06-03 01:43:33 +020024#include "common.h"
Paul Bakker17373852011-01-06 14:20:01 +000025
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010026/*
27 * Availability of functions in this module is controlled by two
28 * feature macros:
29 * - MBEDTLS_MD_C enables the whole module;
30 * - MBEDTLS_MD_LIGHT enables only functions for hashing and accessing
31 * most hash metadata (everything except string names); is it
32 * automatically set whenever MBEDTLS_MD_C is defined.
33 *
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +010034 * In this file, functions from MD_LIGHT are at the top, MD_C at the end.
35 *
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010036 * In the future we may want to change the contract of some functions
37 * (behaviour with NULL arguments) depending on whether MD_C is defined or
38 * only MD_LIGHT. Also, the exact scope of MD_LIGHT might vary.
39 *
40 * For these reasons, we're keeping MD_LIGHT internal for now.
41 */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +010042#if defined(MBEDTLS_MD_LIGHT)
Paul Bakker17373852011-01-06 14:20:01 +000043
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +000044#include "mbedtls/md.h"
Chris Jonesdaacb592021-03-09 17:03:29 +000045#include "md_wrap.h"
Andres Amaya Garcia1f6301b2018-04-17 09:51:09 -050046#include "mbedtls/platform_util.h"
Janos Follath24eed8d2019-11-22 13:21:35 +000047#include "mbedtls/error.h"
Paul Bakker17373852011-01-06 14:20:01 +000048
Gilles Peskine84867cf2019-07-19 15:46:03 +020049#include "mbedtls/md5.h"
50#include "mbedtls/ripemd160.h"
51#include "mbedtls/sha1.h"
52#include "mbedtls/sha256.h"
53#include "mbedtls/sha512.h"
54
Gilles Peskine12612e52022-10-22 20:07:28 +020055#if defined(MBEDTLS_MD_SOME_PSA)
56#include <psa/crypto.h>
Manuel Pégourié-Gonnard9b146392023-03-09 15:56:14 +010057#include "psa_crypto_core.h"
Gilles Peskine12612e52022-10-22 20:07:28 +020058#endif
59
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010060#include "mbedtls/platform.h"
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010061
Rich Evans00ab4702015-02-06 13:43:58 +000062#include <string.h>
Paul Bakker17373852011-01-06 14:20:01 +000063
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +020064#if defined(MBEDTLS_FS_IO)
65#include <stdio.h>
Paul Bakkeraf5c85f2011-04-18 03:47:52 +000066#endif
67
Gilles Peskine83d9e092022-10-22 18:32:43 +020068#if defined(MBEDTLS_MD_CAN_MD5)
Gilles Peskine84867cf2019-07-19 15:46:03 +020069const mbedtls_md_info_t mbedtls_md5_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020070 "MD5",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020071 MBEDTLS_MD_MD5,
Gilles Peskine84867cf2019-07-19 15:46:03 +020072 16,
73 64,
74};
75#endif
76
Gilles Peskine83d9e092022-10-22 18:32:43 +020077#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Gilles Peskine84867cf2019-07-19 15:46:03 +020078const mbedtls_md_info_t mbedtls_ripemd160_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020079 "RIPEMD160",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020080 MBEDTLS_MD_RIPEMD160,
Gilles Peskine84867cf2019-07-19 15:46:03 +020081 20,
82 64,
83};
84#endif
85
Gilles Peskine83d9e092022-10-22 18:32:43 +020086#if defined(MBEDTLS_MD_CAN_SHA1)
Gilles Peskine84867cf2019-07-19 15:46:03 +020087const mbedtls_md_info_t mbedtls_sha1_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020088 "SHA1",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020089 MBEDTLS_MD_SHA1,
Gilles Peskine84867cf2019-07-19 15:46:03 +020090 20,
91 64,
92};
93#endif
94
Gilles Peskine83d9e092022-10-22 18:32:43 +020095#if defined(MBEDTLS_MD_CAN_SHA224)
Gilles Peskine84867cf2019-07-19 15:46:03 +020096const mbedtls_md_info_t mbedtls_sha224_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020097 "SHA224",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020098 MBEDTLS_MD_SHA224,
Gilles Peskine84867cf2019-07-19 15:46:03 +020099 28,
100 64,
101};
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200102#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200103
Gilles Peskine83d9e092022-10-22 18:32:43 +0200104#if defined(MBEDTLS_MD_CAN_SHA256)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200105const mbedtls_md_info_t mbedtls_sha256_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200106 "SHA256",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200107 MBEDTLS_MD_SHA256,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200108 32,
109 64,
110};
111#endif
112
Gilles Peskine83d9e092022-10-22 18:32:43 +0200113#if defined(MBEDTLS_MD_CAN_SHA384)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200114const mbedtls_md_info_t mbedtls_sha384_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200115 "SHA384",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200116 MBEDTLS_MD_SHA384,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200117 48,
118 128,
119};
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200120#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200121
Gilles Peskine83d9e092022-10-22 18:32:43 +0200122#if defined(MBEDTLS_MD_CAN_SHA512)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200123const mbedtls_md_info_t mbedtls_sha512_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200124 "SHA512",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200125 MBEDTLS_MD_SHA512,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200126 64,
127 128,
128};
129#endif
130
Gilles Peskine449bd832023-01-11 14:50:10 +0100131const mbedtls_md_info_t *mbedtls_md_info_from_type(mbedtls_md_type_t md_type)
Paul Bakker17373852011-01-06 14:20:01 +0000132{
Gilles Peskine449bd832023-01-11 14:50:10 +0100133 switch (md_type) {
Gilles Peskine83d9e092022-10-22 18:32:43 +0200134#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200135 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100136 return &mbedtls_md5_info;
Paul Bakker17373852011-01-06 14:20:01 +0000137#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200138#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200139 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100140 return &mbedtls_ripemd160_info;
Manuel Pégourié-Gonnarde4d47a62014-01-17 20:41:32 +0100141#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200142#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200143 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100144 return &mbedtls_sha1_info;
Paul Bakker17373852011-01-06 14:20:01 +0000145#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200146#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200147 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100148 return &mbedtls_sha224_info;
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200149#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200150#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200151 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100152 return &mbedtls_sha256_info;
Paul Bakker17373852011-01-06 14:20:01 +0000153#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200154#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200155 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100156 return &mbedtls_sha384_info;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200157#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200158#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200159 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100160 return &mbedtls_sha512_info;
Paul Bakker17373852011-01-06 14:20:01 +0000161#endif
162 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100163 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000164 }
165}
166
Gilles Peskine12612e52022-10-22 20:07:28 +0200167#if defined(MBEDTLS_MD_SOME_PSA)
168static psa_algorithm_t psa_alg_of_md(const mbedtls_md_info_t *info)
169{
170 switch (info->type) {
171#if defined(MBEDTLS_MD_MD5_VIA_PSA)
172 case MBEDTLS_MD_MD5:
173 return PSA_ALG_MD5;
174#endif
175#if defined(MBEDTLS_MD_RIPEMD160_VIA_PSA)
176 case MBEDTLS_MD_RIPEMD160:
177 return PSA_ALG_RIPEMD160;
178#endif
179#if defined(MBEDTLS_MD_SHA1_VIA_PSA)
180 case MBEDTLS_MD_SHA1:
181 return PSA_ALG_SHA_1;
182#endif
183#if defined(MBEDTLS_MD_SHA224_VIA_PSA)
184 case MBEDTLS_MD_SHA224:
185 return PSA_ALG_SHA_224;
186#endif
187#if defined(MBEDTLS_MD_SHA256_VIA_PSA)
188 case MBEDTLS_MD_SHA256:
189 return PSA_ALG_SHA_256;
190#endif
191#if defined(MBEDTLS_MD_SHA384_VIA_PSA)
192 case MBEDTLS_MD_SHA384:
193 return PSA_ALG_SHA_384;
194#endif
195#if defined(MBEDTLS_MD_SHA512_VIA_PSA)
196 case MBEDTLS_MD_SHA512:
197 return PSA_ALG_SHA_512;
198#endif
199 default:
200 return PSA_ALG_NONE;
201 }
202}
203
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100204static int md_can_use_psa(const mbedtls_md_info_t *info)
Gilles Peskine12612e52022-10-22 20:07:28 +0200205{
Manuel Pégourié-Gonnard9b146392023-03-09 15:56:14 +0100206 psa_algorithm_t alg = psa_alg_of_md(info);
207 if (alg == PSA_ALG_NONE) {
208 return 0;
209 }
210
211 return psa_can_do_hash(alg);
Gilles Peskine12612e52022-10-22 20:07:28 +0200212}
213
214static int mbedtls_md_error_from_psa(psa_status_t status)
215{
216 switch (status) {
217 case PSA_SUCCESS:
218 return 0;
219 case PSA_ERROR_NOT_SUPPORTED:
220 return MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE;
221 case PSA_ERROR_INSUFFICIENT_MEMORY:
222 return MBEDTLS_ERR_MD_ALLOC_FAILED;
223 default:
224 return MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED;
225 }
226}
227#endif /* MBEDTLS_MD_SOME_PSA */
228
Gilles Peskine449bd832023-01-11 14:50:10 +0100229void mbedtls_md_init(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200230{
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100231 /* Note: this sets engine (if present) to MBEDTLS_MD_ENGINE_LEGACY */
Gilles Peskine449bd832023-01-11 14:50:10 +0100232 memset(ctx, 0, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200233}
234
Gilles Peskine449bd832023-01-11 14:50:10 +0100235void mbedtls_md_free(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200236{
Gilles Peskine449bd832023-01-11 14:50:10 +0100237 if (ctx == NULL || ctx->md_info == NULL) {
Paul Bakker84bbeb52014-07-01 14:53:22 +0200238 return;
Gilles Peskine449bd832023-01-11 14:50:10 +0100239 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200240
Gilles Peskine449bd832023-01-11 14:50:10 +0100241 if (ctx->md_ctx != NULL) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200242#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100243 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200244 psa_hash_abort(ctx->md_ctx);
245 } else
246#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100247 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200248#if defined(MBEDTLS_MD5_C)
249 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100250 mbedtls_md5_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200251 break;
252#endif
253#if defined(MBEDTLS_RIPEMD160_C)
254 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100255 mbedtls_ripemd160_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200256 break;
257#endif
258#if defined(MBEDTLS_SHA1_C)
259 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100260 mbedtls_sha1_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200261 break;
262#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200263#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200264 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100265 mbedtls_sha256_free(ctx->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200266 break;
267#endif
268#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200269 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100270 mbedtls_sha256_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200271 break;
272#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200273#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200274 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100275 mbedtls_sha512_free(ctx->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200276 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200277#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200278#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200279 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100280 mbedtls_sha512_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200281 break;
282#endif
283 default:
284 /* Shouldn't happen */
285 break;
286 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100287 mbedtls_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200288 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200289
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100290#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100291 if (ctx->hmac_ctx != NULL) {
292 mbedtls_platform_zeroize(ctx->hmac_ctx,
293 2 * ctx->md_info->block_size);
294 mbedtls_free(ctx->hmac_ctx);
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100295 }
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100296#endif
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100297
Gilles Peskine449bd832023-01-11 14:50:10 +0100298 mbedtls_platform_zeroize(ctx, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200299}
300
Gilles Peskine449bd832023-01-11 14:50:10 +0100301int mbedtls_md_clone(mbedtls_md_context_t *dst,
302 const mbedtls_md_context_t *src)
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200303{
Gilles Peskine449bd832023-01-11 14:50:10 +0100304 if (dst == NULL || dst->md_info == NULL ||
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200305 src == NULL || src->md_info == NULL ||
Gilles Peskine449bd832023-01-11 14:50:10 +0100306 dst->md_info != src->md_info) {
307 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200308 }
309
Gilles Peskine12612e52022-10-22 20:07:28 +0200310#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100311 if (src->engine != dst->engine) {
312 /* This can happen with src set to legacy because PSA wasn't ready
313 * yet, and dst to PSA because it became ready in the meantime.
314 * We currently don't support that case (we'd need to re-allocate
315 * md_ctx to the size of the appropriate MD context). */
316 return MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE;
317 }
318
319 if (src->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200320 psa_status_t status = psa_hash_clone(src->md_ctx, dst->md_ctx);
321 return mbedtls_md_error_from_psa(status);
322 }
323#endif
324
Gilles Peskine449bd832023-01-11 14:50:10 +0100325 switch (src->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200326#if defined(MBEDTLS_MD5_C)
327 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100328 mbedtls_md5_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200329 break;
330#endif
331#if defined(MBEDTLS_RIPEMD160_C)
332 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100333 mbedtls_ripemd160_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200334 break;
335#endif
336#if defined(MBEDTLS_SHA1_C)
337 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100338 mbedtls_sha1_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200339 break;
340#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200341#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200342 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100343 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200344 break;
345#endif
346#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200347 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100348 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200349 break;
350#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200351#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200352 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100353 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200354 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200355#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200356#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200357 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100358 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200359 break;
360#endif
361 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100362 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200363 }
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200364
Gilles Peskine449bd832023-01-11 14:50:10 +0100365 return 0;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200366}
367
Gilles Peskine449bd832023-01-11 14:50:10 +0100368#define ALLOC(type) \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200369 do { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100370 ctx->md_ctx = mbedtls_calloc(1, sizeof(mbedtls_##type##_context)); \
371 if (ctx->md_ctx == NULL) \
372 return MBEDTLS_ERR_MD_ALLOC_FAILED; \
373 mbedtls_##type##_init(ctx->md_ctx); \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200374 } \
Gilles Peskine449bd832023-01-11 14:50:10 +0100375 while (0)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200376
Gilles Peskine449bd832023-01-11 14:50:10 +0100377int mbedtls_md_setup(mbedtls_md_context_t *ctx, const mbedtls_md_info_t *md_info, int hmac)
Paul Bakker17373852011-01-06 14:20:01 +0000378{
Gilles Peskine449bd832023-01-11 14:50:10 +0100379 if (md_info == NULL || ctx == NULL) {
380 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
381 }
Paul Bakker17373852011-01-06 14:20:01 +0000382
Gilles Peskined15c7402020-08-19 12:03:11 +0200383 ctx->md_info = md_info;
384 ctx->md_ctx = NULL;
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100385#if defined(MBEDTLS_MD_C)
Gilles Peskined15c7402020-08-19 12:03:11 +0200386 ctx->hmac_ctx = NULL;
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100387#else
388 if (hmac != 0) {
389 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
390 }
391#endif
Gilles Peskined15c7402020-08-19 12:03:11 +0200392
Gilles Peskine12612e52022-10-22 20:07:28 +0200393#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100394 if (md_can_use_psa(ctx->md_info)) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200395 ctx->md_ctx = mbedtls_calloc(1, sizeof(psa_hash_operation_t));
396 if (ctx->md_ctx == NULL) {
397 return MBEDTLS_ERR_MD_ALLOC_FAILED;
398 }
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100399 ctx->engine = MBEDTLS_MD_ENGINE_PSA;
Gilles Peskine12612e52022-10-22 20:07:28 +0200400 } else
401#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100402 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200403#if defined(MBEDTLS_MD5_C)
404 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100405 ALLOC(md5);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200406 break;
407#endif
408#if defined(MBEDTLS_RIPEMD160_C)
409 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100410 ALLOC(ripemd160);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200411 break;
412#endif
413#if defined(MBEDTLS_SHA1_C)
414 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100415 ALLOC(sha1);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200416 break;
417#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200418#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200419 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100420 ALLOC(sha256);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200421 break;
422#endif
423#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200424 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100425 ALLOC(sha256);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200426 break;
427#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200428#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200429 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100430 ALLOC(sha512);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200431 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200432#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200433#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200434 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100435 ALLOC(sha512);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200436 break;
437#endif
438 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100439 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200440 }
Paul Bakker17373852011-01-06 14:20:01 +0000441
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100442#if defined(MBEDTLS_MD_C)
Gilles Peskine449bd832023-01-11 14:50:10 +0100443 if (hmac != 0) {
444 ctx->hmac_ctx = mbedtls_calloc(2, md_info->block_size);
445 if (ctx->hmac_ctx == NULL) {
446 mbedtls_md_free(ctx);
447 return MBEDTLS_ERR_MD_ALLOC_FAILED;
Manuel Pégourié-Gonnard4063ceb2015-03-25 16:08:53 +0100448 }
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100449 }
Manuel Pégourié-Gonnard39a376a2023-03-09 17:21:40 +0100450#endif
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100451
Gilles Peskine449bd832023-01-11 14:50:10 +0100452 return 0;
Paul Bakker17373852011-01-06 14:20:01 +0000453}
Gilles Peskine84867cf2019-07-19 15:46:03 +0200454#undef ALLOC
Paul Bakker17373852011-01-06 14:20:01 +0000455
Gilles Peskine449bd832023-01-11 14:50:10 +0100456int mbedtls_md_starts(mbedtls_md_context_t *ctx)
Paul Bakker562535d2011-01-20 16:42:01 +0000457{
Gilles Peskine449bd832023-01-11 14:50:10 +0100458 if (ctx == NULL || ctx->md_info == NULL) {
459 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
460 }
Paul Bakker562535d2011-01-20 16:42:01 +0000461
Gilles Peskine12612e52022-10-22 20:07:28 +0200462#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100463 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
464 psa_algorithm_t alg = psa_alg_of_md(ctx->md_info);
Gilles Peskine12612e52022-10-22 20:07:28 +0200465 psa_hash_abort(ctx->md_ctx);
466 psa_status_t status = psa_hash_setup(ctx->md_ctx, alg);
467 return mbedtls_md_error_from_psa(status);
468 }
469#endif
470
Gilles Peskine449bd832023-01-11 14:50:10 +0100471 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200472#if defined(MBEDTLS_MD5_C)
473 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100474 return mbedtls_md5_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200475#endif
476#if defined(MBEDTLS_RIPEMD160_C)
477 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100478 return mbedtls_ripemd160_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200479#endif
480#if defined(MBEDTLS_SHA1_C)
481 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100482 return mbedtls_sha1_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200483#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200484#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200485 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100486 return mbedtls_sha256_starts(ctx->md_ctx, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200487#endif
488#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200489 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100490 return mbedtls_sha256_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200491#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200492#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200493 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100494 return mbedtls_sha512_starts(ctx->md_ctx, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200495#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200496#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200497 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100498 return mbedtls_sha512_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200499#endif
500 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100501 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200502 }
Paul Bakker562535d2011-01-20 16:42:01 +0000503}
504
Gilles Peskine449bd832023-01-11 14:50:10 +0100505int mbedtls_md_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000506{
Gilles Peskine449bd832023-01-11 14:50:10 +0100507 if (ctx == NULL || ctx->md_info == NULL) {
508 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
509 }
Paul Bakker17373852011-01-06 14:20:01 +0000510
Gilles Peskine12612e52022-10-22 20:07:28 +0200511#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100512 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200513 psa_status_t status = psa_hash_update(ctx->md_ctx, input, ilen);
514 return mbedtls_md_error_from_psa(status);
515 }
516#endif
517
Gilles Peskine449bd832023-01-11 14:50:10 +0100518 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200519#if defined(MBEDTLS_MD5_C)
520 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100521 return mbedtls_md5_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200522#endif
523#if defined(MBEDTLS_RIPEMD160_C)
524 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100525 return mbedtls_ripemd160_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200526#endif
527#if defined(MBEDTLS_SHA1_C)
528 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100529 return mbedtls_sha1_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200530#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200531#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200532 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100533 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200534#endif
535#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200536 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100537 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200538#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200539#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200540 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100541 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200542#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200543#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200544 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100545 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200546#endif
547 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100548 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200549 }
Paul Bakker17373852011-01-06 14:20:01 +0000550}
551
Gilles Peskine449bd832023-01-11 14:50:10 +0100552int mbedtls_md_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000553{
Gilles Peskine449bd832023-01-11 14:50:10 +0100554 if (ctx == NULL || ctx->md_info == NULL) {
555 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
556 }
Paul Bakker17373852011-01-06 14:20:01 +0000557
Gilles Peskine12612e52022-10-22 20:07:28 +0200558#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100559 if (ctx->engine == MBEDTLS_MD_ENGINE_PSA) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200560 size_t size = ctx->md_info->size;
561 psa_status_t status = psa_hash_finish(ctx->md_ctx,
562 output, size, &size);
563 return mbedtls_md_error_from_psa(status);
564 }
565#endif
566
Gilles Peskine449bd832023-01-11 14:50:10 +0100567 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200568#if defined(MBEDTLS_MD5_C)
569 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100570 return mbedtls_md5_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200571#endif
572#if defined(MBEDTLS_RIPEMD160_C)
573 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100574 return mbedtls_ripemd160_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200575#endif
576#if defined(MBEDTLS_SHA1_C)
577 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100578 return mbedtls_sha1_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200579#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200580#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200581 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100582 return mbedtls_sha256_finish(ctx->md_ctx, output);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200583#endif
584#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200585 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100586 return mbedtls_sha256_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200587#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200588#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200589 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100590 return mbedtls_sha512_finish(ctx->md_ctx, output);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200591#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200592#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200593 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100594 return mbedtls_sha512_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200595#endif
596 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100597 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200598 }
Paul Bakker17373852011-01-06 14:20:01 +0000599}
600
Gilles Peskine449bd832023-01-11 14:50:10 +0100601int mbedtls_md(const mbedtls_md_info_t *md_info, const unsigned char *input, size_t ilen,
602 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000603{
Gilles Peskine449bd832023-01-11 14:50:10 +0100604 if (md_info == NULL) {
605 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
606 }
Paul Bakker17373852011-01-06 14:20:01 +0000607
Gilles Peskine12612e52022-10-22 20:07:28 +0200608#if defined(MBEDTLS_MD_SOME_PSA)
Manuel Pégourié-Gonnardf48b1f82023-03-14 10:50:52 +0100609 if (md_can_use_psa(md_info)) {
Gilles Peskine12612e52022-10-22 20:07:28 +0200610 size_t size = md_info->size;
Manuel Pégourié-Gonnardd8ea37f2023-03-09 10:46:22 +0100611 psa_status_t status = psa_hash_compute(psa_alg_of_md(md_info),
Gilles Peskine12612e52022-10-22 20:07:28 +0200612 input, ilen,
613 output, size, &size);
614 return mbedtls_md_error_from_psa(status);
615 }
616#endif
617
Gilles Peskine449bd832023-01-11 14:50:10 +0100618 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200619#if defined(MBEDTLS_MD5_C)
620 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100621 return mbedtls_md5(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200622#endif
623#if defined(MBEDTLS_RIPEMD160_C)
624 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100625 return mbedtls_ripemd160(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200626#endif
627#if defined(MBEDTLS_SHA1_C)
628 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100629 return mbedtls_sha1(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200630#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200631#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200632 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100633 return mbedtls_sha256(input, ilen, output, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200634#endif
635#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200636 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100637 return mbedtls_sha256(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200638#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200639#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200640 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100641 return mbedtls_sha512(input, ilen, output, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200642#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200643#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200644 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100645 return mbedtls_sha512(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200646#endif
647 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100648 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200649 }
Paul Bakker17373852011-01-06 14:20:01 +0000650}
651
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100652unsigned char mbedtls_md_get_size(const mbedtls_md_info_t *md_info)
653{
654 if (md_info == NULL) {
655 return 0;
656 }
657
658 return md_info->size;
659}
660
661mbedtls_md_type_t mbedtls_md_get_type(const mbedtls_md_info_t *md_info)
662{
663 if (md_info == NULL) {
664 return MBEDTLS_MD_NONE;
665 }
666
667 return md_info->type;
668}
669
670/************************************************************************
671 * Functions above this separator are part of MBEDTLS_MD_LIGHT, *
672 * functions below are only available when MBEDTLS_MD_C is set. *
673 ************************************************************************/
674#if defined(MBEDTLS_MD_C)
675
676/*
677 * Reminder: update profiles in x509_crt.c when adding a new hash!
678 */
679static const int supported_digests[] = {
680
Gilles Peskine83d9e092022-10-22 18:32:43 +0200681#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100682 MBEDTLS_MD_SHA512,
683#endif
684
Gilles Peskine83d9e092022-10-22 18:32:43 +0200685#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100686 MBEDTLS_MD_SHA384,
687#endif
688
Gilles Peskine83d9e092022-10-22 18:32:43 +0200689#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100690 MBEDTLS_MD_SHA256,
691#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200692#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100693 MBEDTLS_MD_SHA224,
694#endif
695
Gilles Peskine83d9e092022-10-22 18:32:43 +0200696#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100697 MBEDTLS_MD_SHA1,
698#endif
699
Gilles Peskine83d9e092022-10-22 18:32:43 +0200700#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100701 MBEDTLS_MD_RIPEMD160,
702#endif
703
Gilles Peskine83d9e092022-10-22 18:32:43 +0200704#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100705 MBEDTLS_MD_MD5,
706#endif
707
708 MBEDTLS_MD_NONE
709};
710
711const int *mbedtls_md_list(void)
712{
713 return supported_digests;
714}
715
716const mbedtls_md_info_t *mbedtls_md_info_from_string(const char *md_name)
717{
718 if (NULL == md_name) {
719 return NULL;
720 }
721
722 /* Get the appropriate digest information */
Gilles Peskine83d9e092022-10-22 18:32:43 +0200723#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100724 if (!strcmp("MD5", md_name)) {
725 return mbedtls_md_info_from_type(MBEDTLS_MD_MD5);
726 }
727#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200728#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100729 if (!strcmp("RIPEMD160", md_name)) {
730 return mbedtls_md_info_from_type(MBEDTLS_MD_RIPEMD160);
731 }
732#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200733#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100734 if (!strcmp("SHA1", md_name) || !strcmp("SHA", md_name)) {
735 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA1);
736 }
737#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200738#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100739 if (!strcmp("SHA224", md_name)) {
740 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA224);
741 }
742#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200743#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100744 if (!strcmp("SHA256", md_name)) {
745 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
746 }
747#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200748#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100749 if (!strcmp("SHA384", md_name)) {
750 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA384);
751 }
752#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200753#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100754 if (!strcmp("SHA512", md_name)) {
755 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA512);
756 }
757#endif
758 return NULL;
759}
760
761const mbedtls_md_info_t *mbedtls_md_info_from_ctx(
762 const mbedtls_md_context_t *ctx)
763{
764 if (ctx == NULL) {
765 return NULL;
766 }
767
768 return ctx->MBEDTLS_PRIVATE(md_info);
769}
770
771#if defined(MBEDTLS_FS_IO)
Gilles Peskine449bd832023-01-11 14:50:10 +0100772int mbedtls_md_file(const mbedtls_md_info_t *md_info, const char *path, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000773{
Janos Follath24eed8d2019-11-22 13:21:35 +0000774 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200775 FILE *f;
776 size_t n;
777 mbedtls_md_context_t ctx;
778 unsigned char buf[1024];
Paul Bakker9c021ad2011-06-09 15:55:11 +0000779
Gilles Peskine449bd832023-01-11 14:50:10 +0100780 if (md_info == NULL) {
781 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
782 }
Paul Bakker17373852011-01-06 14:20:01 +0000783
Gilles Peskine449bd832023-01-11 14:50:10 +0100784 if ((f = fopen(path, "rb")) == NULL) {
785 return MBEDTLS_ERR_MD_FILE_IO_ERROR;
786 }
Manuel Pégourié-Gonnardbcc03082015-06-24 00:09:29 +0200787
Gilles Peskineda0913b2022-06-30 17:03:40 +0200788 /* Ensure no stdio buffering of secrets, as such buffers cannot be wiped. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100789 mbedtls_setbuf(f, NULL);
Gilles Peskineda0913b2022-06-30 17:03:40 +0200790
Gilles Peskine449bd832023-01-11 14:50:10 +0100791 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200792
Gilles Peskine449bd832023-01-11 14:50:10 +0100793 if ((ret = mbedtls_md_setup(&ctx, md_info, 0)) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200794 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100795 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200796
Gilles Peskine449bd832023-01-11 14:50:10 +0100797 if ((ret = mbedtls_md_starts(&ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100798 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100799 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200800
Gilles Peskine449bd832023-01-11 14:50:10 +0100801 while ((n = fread(buf, 1, sizeof(buf), f)) > 0) {
802 if ((ret = mbedtls_md_update(&ctx, buf, n)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100803 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100804 }
805 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200806
Gilles Peskine449bd832023-01-11 14:50:10 +0100807 if (ferror(f) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200808 ret = MBEDTLS_ERR_MD_FILE_IO_ERROR;
Gilles Peskine449bd832023-01-11 14:50:10 +0100809 } else {
810 ret = mbedtls_md_finish(&ctx, output);
811 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200812
813cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100814 mbedtls_platform_zeroize(buf, sizeof(buf));
815 fclose(f);
816 mbedtls_md_free(&ctx);
Paul Bakker9c021ad2011-06-09 15:55:11 +0000817
Gilles Peskine449bd832023-01-11 14:50:10 +0100818 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000819}
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100820#endif /* MBEDTLS_FS_IO */
Paul Bakker17373852011-01-06 14:20:01 +0000821
Gilles Peskine449bd832023-01-11 14:50:10 +0100822int mbedtls_md_hmac_starts(mbedtls_md_context_t *ctx, const unsigned char *key, size_t keylen)
Paul Bakker17373852011-01-06 14:20:01 +0000823{
Janos Follath24eed8d2019-11-22 13:21:35 +0000824 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200825 unsigned char sum[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100826 unsigned char *ipad, *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100827
Gilles Peskine449bd832023-01-11 14:50:10 +0100828 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
829 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
830 }
Paul Bakker17373852011-01-06 14:20:01 +0000831
Gilles Peskine449bd832023-01-11 14:50:10 +0100832 if (keylen > (size_t) ctx->md_info->block_size) {
833 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100834 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100835 }
836 if ((ret = mbedtls_md_update(ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100837 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100838 }
839 if ((ret = mbedtls_md_finish(ctx, sum)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100840 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100841 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100842
843 keylen = ctx->md_info->size;
844 key = sum;
845 }
846
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100847 ipad = (unsigned char *) ctx->hmac_ctx;
848 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
849
Gilles Peskine449bd832023-01-11 14:50:10 +0100850 memset(ipad, 0x36, ctx->md_info->block_size);
851 memset(opad, 0x5C, ctx->md_info->block_size);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100852
Gilles Peskine449bd832023-01-11 14:50:10 +0100853 mbedtls_xor(ipad, ipad, key, keylen);
854 mbedtls_xor(opad, opad, key, keylen);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100855
Gilles Peskine449bd832023-01-11 14:50:10 +0100856 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100857 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100858 }
859 if ((ret = mbedtls_md_update(ctx, ipad,
860 ctx->md_info->block_size)) != 0) {
Andres Amaya Garcia42e5e102017-07-20 16:27:03 +0100861 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100862 }
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100863
864cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100865 mbedtls_platform_zeroize(sum, sizeof(sum));
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100866
Gilles Peskine449bd832023-01-11 14:50:10 +0100867 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000868}
869
Gilles Peskine449bd832023-01-11 14:50:10 +0100870int mbedtls_md_hmac_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000871{
Gilles Peskine449bd832023-01-11 14:50:10 +0100872 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
873 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
874 }
Paul Bakker17373852011-01-06 14:20:01 +0000875
Gilles Peskine449bd832023-01-11 14:50:10 +0100876 return mbedtls_md_update(ctx, input, ilen);
Paul Bakker17373852011-01-06 14:20:01 +0000877}
878
Gilles Peskine449bd832023-01-11 14:50:10 +0100879int mbedtls_md_hmac_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000880{
Janos Follath24eed8d2019-11-22 13:21:35 +0000881 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200882 unsigned char tmp[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100883 unsigned char *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100884
Gilles Peskine449bd832023-01-11 14:50:10 +0100885 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
886 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
887 }
Paul Bakker17373852011-01-06 14:20:01 +0000888
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100889 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
890
Gilles Peskine449bd832023-01-11 14:50:10 +0100891 if ((ret = mbedtls_md_finish(ctx, tmp)) != 0) {
892 return ret;
893 }
894 if ((ret = mbedtls_md_starts(ctx)) != 0) {
895 return ret;
896 }
897 if ((ret = mbedtls_md_update(ctx, opad,
898 ctx->md_info->block_size)) != 0) {
899 return ret;
900 }
901 if ((ret = mbedtls_md_update(ctx, tmp,
902 ctx->md_info->size)) != 0) {
903 return ret;
904 }
905 return mbedtls_md_finish(ctx, output);
Paul Bakker17373852011-01-06 14:20:01 +0000906}
907
Gilles Peskine449bd832023-01-11 14:50:10 +0100908int mbedtls_md_hmac_reset(mbedtls_md_context_t *ctx)
Paul Bakker17373852011-01-06 14:20:01 +0000909{
Janos Follath24eed8d2019-11-22 13:21:35 +0000910 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100911 unsigned char *ipad;
912
Gilles Peskine449bd832023-01-11 14:50:10 +0100913 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
914 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
915 }
Paul Bakker17373852011-01-06 14:20:01 +0000916
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100917 ipad = (unsigned char *) ctx->hmac_ctx;
918
Gilles Peskine449bd832023-01-11 14:50:10 +0100919 if ((ret = mbedtls_md_starts(ctx)) != 0) {
920 return ret;
921 }
922 return mbedtls_md_update(ctx, ipad, ctx->md_info->block_size);
Paul Bakker17373852011-01-06 14:20:01 +0000923}
924
Gilles Peskine449bd832023-01-11 14:50:10 +0100925int mbedtls_md_hmac(const mbedtls_md_info_t *md_info,
926 const unsigned char *key, size_t keylen,
927 const unsigned char *input, size_t ilen,
928 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000929{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200930 mbedtls_md_context_t ctx;
Janos Follath24eed8d2019-11-22 13:21:35 +0000931 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100932
Gilles Peskine449bd832023-01-11 14:50:10 +0100933 if (md_info == NULL) {
934 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
935 }
Paul Bakker17373852011-01-06 14:20:01 +0000936
Gilles Peskine449bd832023-01-11 14:50:10 +0100937 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100938
Gilles Peskine449bd832023-01-11 14:50:10 +0100939 if ((ret = mbedtls_md_setup(&ctx, md_info, 1)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100940 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100941 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100942
Gilles Peskine449bd832023-01-11 14:50:10 +0100943 if ((ret = mbedtls_md_hmac_starts(&ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100944 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100945 }
946 if ((ret = mbedtls_md_hmac_update(&ctx, input, ilen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100947 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100948 }
949 if ((ret = mbedtls_md_hmac_finish(&ctx, output)) != 0) {
Andres Amaya Garciaaa464ef2017-07-21 14:21:53 +0100950 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100951 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100952
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100953cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100954 mbedtls_md_free(&ctx);
Paul Bakker17373852011-01-06 14:20:01 +0000955
Gilles Peskine449bd832023-01-11 14:50:10 +0100956 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000957}
958
Gilles Peskine449bd832023-01-11 14:50:10 +0100959const char *mbedtls_md_get_name(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100960{
Gilles Peskine449bd832023-01-11 14:50:10 +0100961 if (md_info == NULL) {
962 return NULL;
963 }
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100964
965 return md_info->name;
966}
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100967
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200968#endif /* MBEDTLS_MD_C */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +0100969
970#endif /* MBEDTLS_MD_LIGHT */