crypto: fix build with nettle >= 3.0.0
[qemu.git] / crypto / cipher-nettle.c
1 /*
2 * QEMU Crypto cipher nettle algorithms
3 *
4 * Copyright (c) 2015 Red Hat, Inc.
5 *
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
10 *
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
15 *
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
18 *
19 */
20
21 #include <nettle/nettle-types.h>
22 #include <nettle/aes.h>
23 #include <nettle/des.h>
24 #include <nettle/cbc.h>
25
26 #if CONFIG_NETTLE_VERSION_MAJOR < 3
27 typedef nettle_crypt_func nettle_cipher_func;
28 #endif
29
30 typedef struct QCryptoCipherNettle QCryptoCipherNettle;
31 struct QCryptoCipherNettle {
32 void *ctx_encrypt;
33 void *ctx_decrypt;
34 nettle_cipher_func *alg_encrypt;
35 nettle_cipher_func *alg_decrypt;
36 uint8_t *iv;
37 size_t niv;
38 };
39
40 bool qcrypto_cipher_supports(QCryptoCipherAlgorithm alg)
41 {
42 switch (alg) {
43 case QCRYPTO_CIPHER_ALG_DES_RFB:
44 case QCRYPTO_CIPHER_ALG_AES_128:
45 case QCRYPTO_CIPHER_ALG_AES_192:
46 case QCRYPTO_CIPHER_ALG_AES_256:
47 return true;
48 default:
49 return false;
50 }
51 }
52
53
54 QCryptoCipher *qcrypto_cipher_new(QCryptoCipherAlgorithm alg,
55 QCryptoCipherMode mode,
56 const uint8_t *key, size_t nkey,
57 Error **errp)
58 {
59 QCryptoCipher *cipher;
60 QCryptoCipherNettle *ctx;
61 uint8_t *rfbkey;
62
63 switch (mode) {
64 case QCRYPTO_CIPHER_MODE_ECB:
65 case QCRYPTO_CIPHER_MODE_CBC:
66 break;
67 default:
68 error_setg(errp, "Unsupported cipher mode %d", mode);
69 return NULL;
70 }
71
72 if (!qcrypto_cipher_validate_key_length(alg, nkey, errp)) {
73 return NULL;
74 }
75
76 cipher = g_new0(QCryptoCipher, 1);
77 cipher->alg = alg;
78 cipher->mode = mode;
79
80 ctx = g_new0(QCryptoCipherNettle, 1);
81
82 switch (alg) {
83 case QCRYPTO_CIPHER_ALG_DES_RFB:
84 ctx->ctx_encrypt = g_new0(struct des_ctx, 1);
85 ctx->ctx_decrypt = NULL; /* 1 ctx can do both */
86 rfbkey = qcrypto_cipher_munge_des_rfb_key(key, nkey);
87 des_set_key(ctx->ctx_encrypt, rfbkey);
88 g_free(rfbkey);
89
90 ctx->alg_encrypt = (nettle_cipher_func *)des_encrypt;
91 ctx->alg_decrypt = (nettle_cipher_func *)des_decrypt;
92
93 ctx->niv = DES_BLOCK_SIZE;
94 break;
95
96 case QCRYPTO_CIPHER_ALG_AES_128:
97 case QCRYPTO_CIPHER_ALG_AES_192:
98 case QCRYPTO_CIPHER_ALG_AES_256:
99 ctx->ctx_encrypt = g_new0(struct aes_ctx, 1);
100 ctx->ctx_decrypt = g_new0(struct aes_ctx, 1);
101
102 aes_set_encrypt_key(ctx->ctx_encrypt, nkey, key);
103 aes_set_decrypt_key(ctx->ctx_decrypt, nkey, key);
104
105 ctx->alg_encrypt = (nettle_cipher_func *)aes_encrypt;
106 ctx->alg_decrypt = (nettle_cipher_func *)aes_decrypt;
107
108 ctx->niv = AES_BLOCK_SIZE;
109 break;
110 default:
111 error_setg(errp, "Unsupported cipher algorithm %d", alg);
112 goto error;
113 }
114
115 ctx->iv = g_new0(uint8_t, ctx->niv);
116 cipher->opaque = ctx;
117
118 return cipher;
119
120 error:
121 g_free(cipher);
122 g_free(ctx);
123 return NULL;
124 }
125
126
127 void qcrypto_cipher_free(QCryptoCipher *cipher)
128 {
129 QCryptoCipherNettle *ctx;
130
131 if (!cipher) {
132 return;
133 }
134
135 ctx = cipher->opaque;
136 g_free(ctx->iv);
137 g_free(ctx->ctx_encrypt);
138 g_free(ctx->ctx_decrypt);
139 g_free(ctx);
140 g_free(cipher);
141 }
142
143
144 int qcrypto_cipher_encrypt(QCryptoCipher *cipher,
145 const void *in,
146 void *out,
147 size_t len,
148 Error **errp)
149 {
150 QCryptoCipherNettle *ctx = cipher->opaque;
151
152 switch (cipher->mode) {
153 case QCRYPTO_CIPHER_MODE_ECB:
154 ctx->alg_encrypt(ctx->ctx_encrypt, len, out, in);
155 break;
156
157 case QCRYPTO_CIPHER_MODE_CBC:
158 cbc_encrypt(ctx->ctx_encrypt, ctx->alg_encrypt,
159 ctx->niv, ctx->iv,
160 len, out, in);
161 break;
162 default:
163 error_setg(errp, "Unsupported cipher algorithm %d",
164 cipher->alg);
165 return -1;
166 }
167 return 0;
168 }
169
170
171 int qcrypto_cipher_decrypt(QCryptoCipher *cipher,
172 const void *in,
173 void *out,
174 size_t len,
175 Error **errp)
176 {
177 QCryptoCipherNettle *ctx = cipher->opaque;
178
179 switch (cipher->mode) {
180 case QCRYPTO_CIPHER_MODE_ECB:
181 ctx->alg_decrypt(ctx->ctx_decrypt ? ctx->ctx_decrypt : ctx->ctx_encrypt,
182 len, out, in);
183 break;
184
185 case QCRYPTO_CIPHER_MODE_CBC:
186 cbc_decrypt(ctx->ctx_decrypt ? ctx->ctx_decrypt : ctx->ctx_encrypt,
187 ctx->alg_decrypt, ctx->niv, ctx->iv,
188 len, out, in);
189 break;
190 default:
191 error_setg(errp, "Unsupported cipher algorithm %d",
192 cipher->alg);
193 return -1;
194 }
195 return 0;
196 }
197
198 int qcrypto_cipher_setiv(QCryptoCipher *cipher,
199 const uint8_t *iv, size_t niv,
200 Error **errp)
201 {
202 QCryptoCipherNettle *ctx = cipher->opaque;
203 if (niv != ctx->niv) {
204 error_setg(errp, "Expected IV size %zu not %zu",
205 ctx->niv, niv);
206 return -1;
207 }
208 memcpy(ctx->iv, iv, niv);
209 return 0;
210 }