| 1 | /* -*-c-*- |
| 2 | * |
| 3 | * Public-key cryptography |
| 4 | * |
| 5 | * (c) 2004 Straylight/Edgeware |
| 6 | */ |
| 7 | |
| 8 | /*----- Licensing notice --------------------------------------------------* |
| 9 | * |
| 10 | * This file is part of the Python interface to Catacomb. |
| 11 | * |
| 12 | * Catacomb/Python is free software; you can redistribute it and/or modify |
| 13 | * it under the terms of the GNU General Public License as published by |
| 14 | * the Free Software Foundation; either version 2 of the License, or |
| 15 | * (at your option) any later version. |
| 16 | * |
| 17 | * Catacomb/Python is distributed in the hope that it will be useful, |
| 18 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 19 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 20 | * GNU General Public License for more details. |
| 21 | * |
| 22 | * You should have received a copy of the GNU General Public License |
| 23 | * along with Catacomb/Python; if not, write to the Free Software Foundation, |
| 24 | * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. |
| 25 | */ |
| 26 | |
| 27 | /*----- Header files ------------------------------------------------------*/ |
| 28 | |
| 29 | #include "catacomb-python.h" |
| 30 | |
| 31 | /*----- DSA and similar ---------------------------------------------------*/ |
| 32 | |
| 33 | typedef struct dsa_pyobj { |
| 34 | PyObject_HEAD |
| 35 | PyObject *G, *u, *p, *rng, *hash; |
| 36 | gdsa d; |
| 37 | } dsa_pyobj; |
| 38 | |
| 39 | static PyTypeObject *dsapub_pytype, *dsapriv_pytype; |
| 40 | static PyTypeObject *kcdsapub_pytype, *kcdsapriv_pytype; |
| 41 | #define DSA_D(o) (&((dsa_pyobj *)(o))->d) |
| 42 | #define DSA_G(o) (((dsa_pyobj *)(o))->G) |
| 43 | #define DSA_U(o) (((dsa_pyobj *)(o))->u) |
| 44 | #define DSA_P(o) (((dsa_pyobj *)(o))->p) |
| 45 | #define DSA_RNG(o) (((dsa_pyobj *)(o))->rng) |
| 46 | #define DSA_HASH(o) (((dsa_pyobj *)(o))->hash) |
| 47 | |
| 48 | static void dsa_pydealloc(PyObject *me) |
| 49 | { |
| 50 | dsa_pyobj *g = (dsa_pyobj *)me; |
| 51 | Py_DECREF(g->G); Py_DECREF(g->u); Py_DECREF(g->p); |
| 52 | Py_DECREF(g->rng); Py_DECREF(g->hash); |
| 53 | FREEOBJ(me); |
| 54 | } |
| 55 | |
| 56 | static PyObject *dsa_setup(PyTypeObject *ty, PyObject *G, PyObject *u, |
| 57 | PyObject *p, PyObject *rng, PyObject *hash, |
| 58 | void (*calcpub)(group *, ge *, mp *)) |
| 59 | { |
| 60 | dsa_pyobj *g; |
| 61 | ge *pp; |
| 62 | |
| 63 | g = PyObject_New(dsa_pyobj, ty); |
| 64 | if (p) Py_INCREF(p); |
| 65 | if (!u) { |
| 66 | g->d.u = 0; |
| 67 | u = Py_None; |
| 68 | } else { |
| 69 | if ((g->d.u = getmp(u)) == 0) |
| 70 | goto end; |
| 71 | if (MP_PYCHECK(u)) Py_INCREF(u); |
| 72 | else u = mp_pywrap(g->d.u); |
| 73 | } |
| 74 | if (!p) { |
| 75 | assert(g->d.u); assert(calcpub); |
| 76 | pp = G_CREATE(GROUP_G(G)); |
| 77 | calcpub(GROUP_G(G), pp, g->d.u); |
| 78 | p = ge_pywrap(G, pp); |
| 79 | } else if (GROUP_G(G) != GE_G(p) && !group_samep(GROUP_G(G), GE_G(p))) |
| 80 | TYERR("public key not from group"); |
| 81 | g->d.g = GROUP_G(G); |
| 82 | g->d.p = GE_X(p); |
| 83 | g->d.r = GRAND_R(rng); |
| 84 | g->d.h = GCHASH_CH(hash); |
| 85 | g->G = G; Py_INCREF(G); g->u = u; g->p = p; |
| 86 | g->rng = rng; Py_INCREF(rng); g->hash = hash; Py_INCREF(hash); |
| 87 | return ((PyObject *)g); |
| 88 | end: |
| 89 | if (p) Py_DECREF(p); |
| 90 | FREEOBJ(g); |
| 91 | return (0); |
| 92 | } |
| 93 | |
| 94 | static PyObject *dsapub_pynew(PyTypeObject *ty, |
| 95 | PyObject *arg, PyObject *kw) |
| 96 | { |
| 97 | PyObject *G, *p, *rng = rand_pyobj, *hash = sha_pyobj; |
| 98 | PyObject *rc = 0; |
| 99 | static const char *const kwlist[] = { "G", "p", "hash", "rng", 0 }; |
| 100 | |
| 101 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!|O!O!:new", KWLIST, |
| 102 | group_pytype, &G, |
| 103 | ge_pytype, &p, |
| 104 | gchash_pytype, &hash, |
| 105 | grand_pytype, &rng) || |
| 106 | (rc = dsa_setup(dsapub_pytype, G, 0, p, rng, hash, 0)) == 0) |
| 107 | goto end; |
| 108 | end: |
| 109 | return (rc); |
| 110 | } |
| 111 | |
| 112 | static PyObject *dsameth_beginhash(PyObject *me, PyObject *arg) |
| 113 | { |
| 114 | if (!PyArg_ParseTuple(arg, ":beginhash")) return (0); |
| 115 | return (ghash_pywrap(DSA_HASH(me), gdsa_beginhash(DSA_D(me)))); |
| 116 | } |
| 117 | |
| 118 | static PyObject *dsameth_endhash(PyObject *me, PyObject *arg) |
| 119 | { |
| 120 | ghash *h; |
| 121 | PyObject *rc; |
| 122 | if (!PyArg_ParseTuple(arg, "O&:endhash", convghash, &h)) return (0); |
| 123 | gdsa_endhash(DSA_D(me), h); |
| 124 | h = GH_COPY(h); |
| 125 | rc = bytestring_pywrap(0, GH_CLASS(h)->hashsz); |
| 126 | GH_DONE(h, PyString_AS_STRING(rc)); |
| 127 | GH_DESTROY(h); |
| 128 | return (rc); |
| 129 | } |
| 130 | |
| 131 | static PyObject *dsameth_sign(PyObject *me, PyObject *arg, PyObject *kw) |
| 132 | { |
| 133 | gdsa_sig s = GDSA_SIG_INIT; |
| 134 | char *p; |
| 135 | Py_ssize_t n; |
| 136 | mp *k = 0; |
| 137 | PyObject *rc = 0; |
| 138 | static const char *const kwlist[] = { "msg", "k", 0 }; |
| 139 | |
| 140 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:sign", KWLIST, |
| 141 | &p, &n, convmp, &k)) |
| 142 | goto end; |
| 143 | if (n != DSA_D(me)->h->hashsz) |
| 144 | VALERR("bad message length (doesn't match hash size)"); |
| 145 | gdsa_sign(DSA_D(me), &s, p, k); |
| 146 | rc = Py_BuildValue("(NN)", mp_pywrap(s.r), mp_pywrap(s.s)); |
| 147 | end: |
| 148 | mp_drop(k); |
| 149 | return (rc); |
| 150 | } |
| 151 | |
| 152 | static PyObject *dsameth_verify(PyObject *me, PyObject *arg) |
| 153 | { |
| 154 | char *p; |
| 155 | Py_ssize_t n; |
| 156 | gdsa_sig s = GDSA_SIG_INIT; |
| 157 | PyObject *rc = 0; |
| 158 | |
| 159 | if (!PyArg_ParseTuple(arg, "s#(O&O&):verify", |
| 160 | &p, &n, convmp, &s.r, convmp, &s.s)) |
| 161 | goto end; |
| 162 | if (n != DSA_D(me)->h->hashsz) |
| 163 | VALERR("bad message length (doesn't match hash size)"); |
| 164 | rc = getbool(!gdsa_verify(DSA_D(me), &s, p)); |
| 165 | end: |
| 166 | mp_drop(s.r); |
| 167 | mp_drop(s.s); |
| 168 | return (rc); |
| 169 | } |
| 170 | |
| 171 | static void dsa_calcpub(group *g, ge *p, mp *u) { G_EXP(g, p, g->g, u); } |
| 172 | |
| 173 | static PyObject *dsapriv_pynew(PyTypeObject *ty, |
| 174 | PyObject *arg, PyObject *kw) |
| 175 | { |
| 176 | PyObject *G, *p = 0, *u, *rng = rand_pyobj, *hash = sha_pyobj; |
| 177 | PyObject *rc = 0; |
| 178 | static const char *const kwlist[] = { "G", "u", "p", "hash", "rng", 0 }; |
| 179 | |
| 180 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O|O!O!O!:new", KWLIST, |
| 181 | group_pytype, &G, |
| 182 | &u, |
| 183 | ge_pytype, &p, |
| 184 | gchash_pytype, &hash, |
| 185 | grand_pytype, &rng) || |
| 186 | (rc = dsa_setup(dsapriv_pytype, G, u, p, rng, hash, dsa_calcpub)) == 0) |
| 187 | goto end; |
| 188 | end: |
| 189 | return (rc); |
| 190 | } |
| 191 | |
| 192 | static PyMethodDef dsapub_pymethods[] = { |
| 193 | #define METHNAME(name) dsameth_##name |
| 194 | METH (beginhash, "D.beginhash() -> hash object") |
| 195 | METH (endhash, "D.endhash(H) -> BYTES") |
| 196 | METH (verify, "D.verify(MSG, (R, S)) -> true/false") |
| 197 | #undef METHNAME |
| 198 | { 0 } |
| 199 | }; |
| 200 | |
| 201 | static PyMethodDef dsapriv_pymethods[] = { |
| 202 | #define METHNAME(name) dsameth_##name |
| 203 | KWMETH(sign, "D.sign(MSG, [k = K]) -> R, S") |
| 204 | #undef METHNAME |
| 205 | { 0 } |
| 206 | }; |
| 207 | |
| 208 | static PyMemberDef dsapub_pymembers[] = { |
| 209 | #define MEMBERSTRUCT dsa_pyobj |
| 210 | MEMBER(G, T_OBJECT, READONLY, "D.G -> group to work in") |
| 211 | MEMBER(p, T_OBJECT, READONLY, "D.p -> public key (group element") |
| 212 | MEMBER(rng, T_OBJECT, READONLY, "D.rng -> random number generator") |
| 213 | MEMBER(hash, T_OBJECT, READONLY, "D.hash -> hash class") |
| 214 | #undef MEMBERSTRUCT |
| 215 | { 0 } |
| 216 | }; |
| 217 | |
| 218 | static PyMemberDef dsapriv_pymembers[] = { |
| 219 | #define MEMBERSTRUCT dsa_pyobj |
| 220 | MEMBER(u, T_OBJECT, READONLY, "D.u -> private key (exponent)") |
| 221 | #undef MEMBERSTRUCT |
| 222 | { 0 } |
| 223 | }; |
| 224 | |
| 225 | static PyTypeObject dsapub_pytype_skel = { |
| 226 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 227 | "DSAPub", /* @tp_name@ */ |
| 228 | sizeof(dsa_pyobj), /* @tp_basicsize@ */ |
| 229 | 0, /* @tp_itemsize@ */ |
| 230 | |
| 231 | dsa_pydealloc, /* @tp_dealloc@ */ |
| 232 | 0, /* @tp_print@ */ |
| 233 | 0, /* @tp_getattr@ */ |
| 234 | 0, /* @tp_setattr@ */ |
| 235 | 0, /* @tp_compare@ */ |
| 236 | 0, /* @tp_repr@ */ |
| 237 | 0, /* @tp_as_number@ */ |
| 238 | 0, /* @tp_as_sequence@ */ |
| 239 | 0, /* @tp_as_mapping@ */ |
| 240 | 0, /* @tp_hash@ */ |
| 241 | 0, /* @tp_call@ */ |
| 242 | 0, /* @tp_str@ */ |
| 243 | 0, /* @tp_getattro@ */ |
| 244 | 0, /* @tp_setattro@ */ |
| 245 | 0, /* @tp_as_buffer@ */ |
| 246 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 247 | Py_TPFLAGS_BASETYPE, |
| 248 | |
| 249 | /* @tp_doc@ */ |
| 250 | "DSAPub(GROUP, P, [hash = sha], [rng = rand]): DSA public key.", |
| 251 | |
| 252 | 0, /* @tp_traverse@ */ |
| 253 | 0, /* @tp_clear@ */ |
| 254 | 0, /* @tp_richcompare@ */ |
| 255 | 0, /* @tp_weaklistoffset@ */ |
| 256 | 0, /* @tp_iter@ */ |
| 257 | 0, /* @tp_iternext@ */ |
| 258 | dsapub_pymethods, /* @tp_methods@ */ |
| 259 | dsapub_pymembers, /* @tp_members@ */ |
| 260 | 0, /* @tp_getset@ */ |
| 261 | 0, /* @tp_base@ */ |
| 262 | 0, /* @tp_dict@ */ |
| 263 | 0, /* @tp_descr_get@ */ |
| 264 | 0, /* @tp_descr_set@ */ |
| 265 | 0, /* @tp_dictoffset@ */ |
| 266 | 0, /* @tp_init@ */ |
| 267 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 268 | dsapub_pynew, /* @tp_new@ */ |
| 269 | 0, /* @tp_free@ */ |
| 270 | 0 /* @tp_is_gc@ */ |
| 271 | }; |
| 272 | |
| 273 | static PyTypeObject dsapriv_pytype_skel = { |
| 274 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 275 | "DSAPriv", /* @tp_name@ */ |
| 276 | sizeof(dsa_pyobj), /* @tp_basicsize@ */ |
| 277 | 0, /* @tp_itemsize@ */ |
| 278 | |
| 279 | 0, /* @tp_dealloc@ */ |
| 280 | 0, /* @tp_print@ */ |
| 281 | 0, /* @tp_getattr@ */ |
| 282 | 0, /* @tp_setattr@ */ |
| 283 | 0, /* @tp_compare@ */ |
| 284 | 0, /* @tp_repr@ */ |
| 285 | 0, /* @tp_as_number@ */ |
| 286 | 0, /* @tp_as_sequence@ */ |
| 287 | 0, /* @tp_as_mapping@ */ |
| 288 | 0, /* @tp_hash@ */ |
| 289 | 0, /* @tp_call@ */ |
| 290 | 0, /* @tp_str@ */ |
| 291 | 0, /* @tp_getattro@ */ |
| 292 | 0, /* @tp_setattro@ */ |
| 293 | 0, /* @tp_as_buffer@ */ |
| 294 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 295 | Py_TPFLAGS_BASETYPE, |
| 296 | |
| 297 | /* @tp_doc@ */ |
| 298 | "DSAPriv(GROUP, U, [p = u G], [hash = sha], [rng = rand]): DSA private key.", |
| 299 | |
| 300 | 0, /* @tp_traverse@ */ |
| 301 | 0, /* @tp_clear@ */ |
| 302 | 0, /* @tp_richcompare@ */ |
| 303 | 0, /* @tp_weaklistoffset@ */ |
| 304 | 0, /* @tp_iter@ */ |
| 305 | 0, /* @tp_iternext@ */ |
| 306 | dsapriv_pymethods, /* @tp_methods@ */ |
| 307 | dsapriv_pymembers, /* @tp_members@ */ |
| 308 | 0, /* @tp_getset@ */ |
| 309 | 0, /* @tp_base@ */ |
| 310 | 0, /* @tp_dict@ */ |
| 311 | 0, /* @tp_descr_get@ */ |
| 312 | 0, /* @tp_descr_set@ */ |
| 313 | 0, /* @tp_dictoffset@ */ |
| 314 | 0, /* @tp_init@ */ |
| 315 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 316 | dsapriv_pynew, /* @tp_new@ */ |
| 317 | 0, /* @tp_free@ */ |
| 318 | 0 /* @tp_is_gc@ */ |
| 319 | }; |
| 320 | |
| 321 | static PyObject *kcdsapub_pynew(PyTypeObject *ty, |
| 322 | PyObject *arg, PyObject *kw) |
| 323 | { |
| 324 | PyObject *G, *p, *rng = rand_pyobj, *hash = has160_pyobj; |
| 325 | PyObject *rc = 0; |
| 326 | static const char *const kwlist[] = { "G", "p", "hash", "rng", 0 }; |
| 327 | |
| 328 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!|O!O!:new", KWLIST, |
| 329 | group_pytype, &G, |
| 330 | ge_pytype, &p, |
| 331 | gchash_pytype, &hash, |
| 332 | grand_pytype, &rng) || |
| 333 | (rc = dsa_setup(kcdsapub_pytype, G, 0, p, rng, hash, 0)) == 0) |
| 334 | goto end; |
| 335 | end: |
| 336 | return (rc); |
| 337 | } |
| 338 | |
| 339 | static void kcdsa_calcpub(group *g, ge *p, mp *u) |
| 340 | { |
| 341 | mp *uinv = mp_modinv(MP_NEW, u, g->r); |
| 342 | G_EXP(g, p, g->g, uinv); |
| 343 | mp_drop(uinv); |
| 344 | } |
| 345 | |
| 346 | static PyObject *kcdsapriv_pynew(PyTypeObject *ty, |
| 347 | PyObject *arg, PyObject *kw) |
| 348 | { |
| 349 | PyObject *G, *u, *p = 0, *rng = rand_pyobj, *hash = has160_pyobj; |
| 350 | PyObject *rc = 0; |
| 351 | static const char *const kwlist[] = { "G", "u", "p", "hash", "rng", 0 }; |
| 352 | |
| 353 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O|O!O!O!:new", KWLIST, |
| 354 | group_pytype, &G, |
| 355 | &u, |
| 356 | ge_pytype, &p, |
| 357 | gchash_pytype, &hash, |
| 358 | grand_pytype, &rng) || |
| 359 | (rc = dsa_setup(kcdsapriv_pytype, G, u, p, |
| 360 | rng, hash, kcdsa_calcpub)) == 0) |
| 361 | goto end; |
| 362 | end: |
| 363 | return (rc); |
| 364 | } |
| 365 | |
| 366 | static PyObject *kcdsameth_beginhash(PyObject *me, PyObject *arg) |
| 367 | { |
| 368 | if (!PyArg_ParseTuple(arg, ":beginhash")) return (0); |
| 369 | return (ghash_pywrap(DSA_HASH(me), gkcdsa_beginhash(DSA_D(me)))); |
| 370 | } |
| 371 | |
| 372 | static PyObject *kcdsameth_endhash(PyObject *me, PyObject *arg) |
| 373 | { |
| 374 | ghash *h; |
| 375 | PyObject *rc; |
| 376 | if (!PyArg_ParseTuple(arg, "O&:endhash", convghash, &h)) return (0); |
| 377 | gkcdsa_endhash(DSA_D(me), h); |
| 378 | h = GH_COPY(h); |
| 379 | rc = bytestring_pywrap(0, GH_CLASS(h)->hashsz); |
| 380 | GH_DONE(h, PyString_AS_STRING(rc)); |
| 381 | GH_DESTROY(h); |
| 382 | return (rc); |
| 383 | } |
| 384 | |
| 385 | static PyObject *kcdsameth_sign(PyObject *me, PyObject *arg, PyObject *kw) |
| 386 | { |
| 387 | gkcdsa_sig s = GKCDSA_SIG_INIT; |
| 388 | char *p; |
| 389 | Py_ssize_t n; |
| 390 | mp *k = 0; |
| 391 | PyObject *r = 0, *rc = 0; |
| 392 | static const char *const kwlist[] = { "msg", "k", 0 }; |
| 393 | |
| 394 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:sign", KWLIST, |
| 395 | &p, &n, convmp, &k)) |
| 396 | goto end; |
| 397 | if (n != DSA_D(me)->h->hashsz) |
| 398 | VALERR("bad message length (doesn't match hash size)"); |
| 399 | r = bytestring_pywrap(0, DSA_D(me)->h->hashsz); |
| 400 | s.r = (octet *)PyString_AS_STRING(r); |
| 401 | gkcdsa_sign(DSA_D(me), &s, p, k); |
| 402 | rc = Py_BuildValue("(ON)", r, mp_pywrap(s.s)); |
| 403 | end: |
| 404 | Py_XDECREF(r); |
| 405 | mp_drop(k); |
| 406 | return (rc); |
| 407 | } |
| 408 | |
| 409 | static PyObject *kcdsameth_verify(PyObject *me, PyObject *arg) |
| 410 | { |
| 411 | char *p; |
| 412 | Py_ssize_t n, rn; |
| 413 | gkcdsa_sig s = GKCDSA_SIG_INIT; |
| 414 | PyObject *rc = 0; |
| 415 | |
| 416 | if (!PyArg_ParseTuple(arg, "s#(s#O&):verify", |
| 417 | &p, &n, &s.r, &rn, convmp, &s.s)) |
| 418 | goto end; |
| 419 | if (n != DSA_D(me)->h->hashsz) |
| 420 | VALERR("bad message length (doesn't match hash size)"); |
| 421 | if (rn != DSA_D(me)->h->hashsz) |
| 422 | VALERR("bad signature `r' length (doesn't match hash size)"); |
| 423 | rc = getbool(!gkcdsa_verify(DSA_D(me), &s, p)); |
| 424 | end: |
| 425 | mp_drop(s.s); |
| 426 | return (rc); |
| 427 | } |
| 428 | |
| 429 | static PyMethodDef kcdsapub_pymethods[] = { |
| 430 | #define METHNAME(name) kcdsameth_##name |
| 431 | METH (beginhash, "D.beginhash() -> hash object") |
| 432 | METH (endhash, "D.endhash(H) -> BYTES") |
| 433 | METH (verify, "D.verify(MSG, (R, S)) -> true/false") |
| 434 | #undef METHNAME |
| 435 | { 0 } |
| 436 | }; |
| 437 | |
| 438 | static PyMethodDef kcdsapriv_pymethods[] = { |
| 439 | #define METHNAME(name) kcdsameth_##name |
| 440 | KWMETH(sign, "D.sign(MSG, [k = K]) -> R, S") |
| 441 | #undef METHNAME |
| 442 | { 0 } |
| 443 | }; |
| 444 | |
| 445 | static PyTypeObject kcdsapub_pytype_skel = { |
| 446 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 447 | "KCDSAPub", /* @tp_name@ */ |
| 448 | sizeof(dsa_pyobj), /* @tp_basicsize@ */ |
| 449 | 0, /* @tp_itemsize@ */ |
| 450 | |
| 451 | dsa_pydealloc, /* @tp_dealloc@ */ |
| 452 | 0, /* @tp_print@ */ |
| 453 | 0, /* @tp_getattr@ */ |
| 454 | 0, /* @tp_setattr@ */ |
| 455 | 0, /* @tp_compare@ */ |
| 456 | 0, /* @tp_repr@ */ |
| 457 | 0, /* @tp_as_number@ */ |
| 458 | 0, /* @tp_as_sequence@ */ |
| 459 | 0, /* @tp_as_mapping@ */ |
| 460 | 0, /* @tp_hash@ */ |
| 461 | 0, /* @tp_call@ */ |
| 462 | 0, /* @tp_str@ */ |
| 463 | 0, /* @tp_getattro@ */ |
| 464 | 0, /* @tp_setattro@ */ |
| 465 | 0, /* @tp_as_buffer@ */ |
| 466 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 467 | Py_TPFLAGS_BASETYPE, |
| 468 | |
| 469 | /* @tp_doc@ */ |
| 470 | "KCDSAPub(GROUP, P, [hash = sha], [rng = rand]): KCDSA public key.", |
| 471 | |
| 472 | 0, /* @tp_traverse@ */ |
| 473 | 0, /* @tp_clear@ */ |
| 474 | 0, /* @tp_richcompare@ */ |
| 475 | 0, /* @tp_weaklistoffset@ */ |
| 476 | 0, /* @tp_iter@ */ |
| 477 | 0, /* @tp_iternext@ */ |
| 478 | kcdsapub_pymethods, /* @tp_methods@ */ |
| 479 | dsapub_pymembers, /* @tp_members@ */ |
| 480 | 0, /* @tp_getset@ */ |
| 481 | 0, /* @tp_base@ */ |
| 482 | 0, /* @tp_dict@ */ |
| 483 | 0, /* @tp_descr_get@ */ |
| 484 | 0, /* @tp_descr_set@ */ |
| 485 | 0, /* @tp_dictoffset@ */ |
| 486 | 0, /* @tp_init@ */ |
| 487 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 488 | kcdsapub_pynew, /* @tp_new@ */ |
| 489 | 0, /* @tp_free@ */ |
| 490 | 0 /* @tp_is_gc@ */ |
| 491 | }; |
| 492 | |
| 493 | static PyTypeObject kcdsapriv_pytype_skel = { |
| 494 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 495 | "KCDSAPriv", /* @tp_name@ */ |
| 496 | sizeof(dsa_pyobj), /* @tp_basicsize@ */ |
| 497 | 0, /* @tp_itemsize@ */ |
| 498 | |
| 499 | 0, /* @tp_dealloc@ */ |
| 500 | 0, /* @tp_print@ */ |
| 501 | 0, /* @tp_getattr@ */ |
| 502 | 0, /* @tp_setattr@ */ |
| 503 | 0, /* @tp_compare@ */ |
| 504 | 0, /* @tp_repr@ */ |
| 505 | 0, /* @tp_as_number@ */ |
| 506 | 0, /* @tp_as_sequence@ */ |
| 507 | 0, /* @tp_as_mapping@ */ |
| 508 | 0, /* @tp_hash@ */ |
| 509 | 0, /* @tp_call@ */ |
| 510 | 0, /* @tp_str@ */ |
| 511 | 0, /* @tp_getattro@ */ |
| 512 | 0, /* @tp_setattro@ */ |
| 513 | 0, /* @tp_as_buffer@ */ |
| 514 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 515 | Py_TPFLAGS_BASETYPE, |
| 516 | |
| 517 | /* @tp_doc@ */ |
| 518 | "KCDSAPriv(GROUP, U, [p = u G], [hash = sha], [rng = rand]): KCDSA private key.", |
| 519 | |
| 520 | 0, /* @tp_traverse@ */ |
| 521 | 0, /* @tp_clear@ */ |
| 522 | 0, /* @tp_richcompare@ */ |
| 523 | 0, /* @tp_weaklistoffset@ */ |
| 524 | 0, /* @tp_iter@ */ |
| 525 | 0, /* @tp_iternext@ */ |
| 526 | kcdsapriv_pymethods, /* @tp_methods@ */ |
| 527 | dsapriv_pymembers, /* @tp_members@ */ |
| 528 | 0, /* @tp_getset@ */ |
| 529 | 0, /* @tp_base@ */ |
| 530 | 0, /* @tp_dict@ */ |
| 531 | 0, /* @tp_descr_get@ */ |
| 532 | 0, /* @tp_descr_set@ */ |
| 533 | 0, /* @tp_dictoffset@ */ |
| 534 | 0, /* @tp_init@ */ |
| 535 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 536 | kcdsapriv_pynew, /* @tp_new@ */ |
| 537 | 0, /* @tp_free@ */ |
| 538 | 0 /* @tp_is_gc@ */ |
| 539 | }; |
| 540 | |
| 541 | /*----- RSA ---------------------------------------------------------------*/ |
| 542 | |
| 543 | typedef struct rsapub_pyobj { |
| 544 | PyObject_HEAD |
| 545 | rsa_pub pub; |
| 546 | rsa_pubctx pubctx; |
| 547 | } rsapub_pyobj; |
| 548 | |
| 549 | #define RSA_PUB(o) (&((rsapub_pyobj *)(o))->pub) |
| 550 | #define RSA_PUBCTX(o) (&((rsapub_pyobj *)(o))->pubctx) |
| 551 | |
| 552 | typedef struct rsapriv_pyobj { |
| 553 | PyObject_HEAD |
| 554 | rsa_pub pub; |
| 555 | rsa_pubctx pubctx; |
| 556 | rsa_priv priv; |
| 557 | rsa_privctx privctx; |
| 558 | PyObject *rng; |
| 559 | } rsapriv_pyobj; |
| 560 | |
| 561 | #define RSA_PRIV(o) (&((rsapriv_pyobj *)(o))->priv) |
| 562 | #define RSA_PRIVCTX(o) (&((rsapriv_pyobj *)(o))->privctx) |
| 563 | #define RSA_RNG(o) (((rsapriv_pyobj *)(o))->rng) |
| 564 | |
| 565 | static PyTypeObject *rsapub_pytype, *rsapriv_pytype; |
| 566 | |
| 567 | static PyObject *rsapub_pynew(PyTypeObject *ty, |
| 568 | PyObject *arg, PyObject *kw) |
| 569 | { |
| 570 | rsa_pub rp = { 0 }; |
| 571 | rsapub_pyobj *o; |
| 572 | static const char *const kwlist[] = { "n", "e", 0 }; |
| 573 | |
| 574 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&:new", KWLIST, |
| 575 | convmp, &rp.n, convmp, &rp.e)) |
| 576 | goto end; |
| 577 | if (!MP_ODDP(rp.n)) VALERR("RSA modulus must be even"); |
| 578 | o = (rsapub_pyobj *)ty->tp_alloc(ty, 0); |
| 579 | o->pub = rp; |
| 580 | rsa_pubcreate(&o->pubctx, &o->pub); |
| 581 | return ((PyObject *)o); |
| 582 | end: |
| 583 | rsa_pubfree(&rp); |
| 584 | return (0); |
| 585 | } |
| 586 | |
| 587 | static void rsapub_pydealloc(PyObject *me) |
| 588 | { |
| 589 | rsa_pubdestroy(RSA_PUBCTX(me)); |
| 590 | rsa_pubfree(RSA_PUB(me)); |
| 591 | FREEOBJ(me); |
| 592 | } |
| 593 | |
| 594 | static PyObject *rsaget_n(PyObject *me, void *hunoz) |
| 595 | { return mp_pywrap(MP_COPY(RSA_PUB(me)->n)); } |
| 596 | |
| 597 | static PyObject *rsaget_e(PyObject *me, void *hunoz) |
| 598 | { return mp_pywrap(MP_COPY(RSA_PUB(me)->e)); } |
| 599 | |
| 600 | static PyObject *rsameth_pubop(PyObject *me, PyObject *arg) |
| 601 | { |
| 602 | mp *x = 0; |
| 603 | PyObject *rc = 0; |
| 604 | |
| 605 | if (!PyArg_ParseTuple(arg, "O&:pubop", convmp, &x)) goto end; |
| 606 | rc = mp_pywrap(rsa_pubop(RSA_PUBCTX(me), MP_NEW, x)); |
| 607 | end: |
| 608 | mp_drop(x); |
| 609 | return (rc); |
| 610 | } |
| 611 | |
| 612 | static PyObject *rsapriv_dopywrap(PyTypeObject *ty, |
| 613 | rsa_priv *rp, PyObject *rng) |
| 614 | { |
| 615 | rsapriv_pyobj *o; |
| 616 | |
| 617 | o = (rsapriv_pyobj *)ty->tp_alloc(ty, 0); |
| 618 | o->priv = *rp; |
| 619 | o->pub.n = rp->n; |
| 620 | o->pub.e = rp->e; |
| 621 | rsa_privcreate(&o->privctx, &o->priv, &rand_global); |
| 622 | rsa_pubcreate(&o->pubctx, &o->pub); |
| 623 | if (!rng) { |
| 624 | rng = Py_None; |
| 625 | Py_INCREF(rng); |
| 626 | } |
| 627 | o->rng = rng; |
| 628 | return ((PyObject *)o); |
| 629 | } |
| 630 | |
| 631 | PyObject *rsapriv_pywrap(rsa_priv *rp) |
| 632 | { return rsapriv_dopywrap(rsapriv_pytype, rp, 0); } |
| 633 | |
| 634 | static PyObject *rsapriv_pynew(PyTypeObject *ty, |
| 635 | PyObject *arg, PyObject *kw) |
| 636 | { |
| 637 | rsa_priv rp = { 0 }; |
| 638 | PyObject *rng = Py_None; |
| 639 | static const char *const kwlist[] = |
| 640 | { "n", "e", "d", "p", "q", "dp", "dq", "q_inv", "rng", 0 }; |
| 641 | |
| 642 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&O&O&O&O&O&O&O&O:new", KWLIST, |
| 643 | convmp, &rp.n, convmp, &rp.e, |
| 644 | convmp, &rp.d, |
| 645 | convmp, &rp.p, convmp, &rp.q, |
| 646 | convmp, &rp.dp, convmp, &rp.dq, |
| 647 | convmp, &rp.q_inv, |
| 648 | &rng)) |
| 649 | goto end; |
| 650 | if ((rp.n && !MP_ODDP(rp.n)) || |
| 651 | (rp.p && !MP_ODDP(rp.p)) || |
| 652 | (rp.q && !MP_ODDP(rp.q))) |
| 653 | VALERR("RSA modulus and factors must be odd"); |
| 654 | if (rsa_recover(&rp)) VALERR("couldn't construct private key"); |
| 655 | if (rng != Py_None && !GRAND_PYCHECK(rng)) |
| 656 | TYERR("not a random number source"); |
| 657 | Py_INCREF(rng); |
| 658 | return (rsapriv_dopywrap(ty, &rp, rng)); |
| 659 | end: |
| 660 | rsa_privfree(&rp); |
| 661 | return (0); |
| 662 | } |
| 663 | |
| 664 | static void rsapriv_pydealloc(PyObject *me) |
| 665 | { |
| 666 | RSA_PRIVCTX(me)->r = &rand_global; |
| 667 | rsa_privdestroy(RSA_PRIVCTX(me)); |
| 668 | rsa_privfree(RSA_PRIV(me)); |
| 669 | Py_DECREF(RSA_RNG(me)); |
| 670 | FREEOBJ(me); |
| 671 | } |
| 672 | |
| 673 | static PyObject *rsaget_d(PyObject *me, void *hunoz) |
| 674 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->d)); } |
| 675 | |
| 676 | static PyObject *rsaget_p(PyObject *me, void *hunoz) |
| 677 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->p)); } |
| 678 | |
| 679 | static PyObject *rsaget_q(PyObject *me, void *hunoz) |
| 680 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->q)); } |
| 681 | |
| 682 | static PyObject *rsaget_dp(PyObject *me, void *hunoz) |
| 683 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->dp)); } |
| 684 | |
| 685 | static PyObject *rsaget_dq(PyObject *me, void *hunoz) |
| 686 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->dq)); } |
| 687 | |
| 688 | static PyObject *rsaget_q_inv(PyObject *me, void *hunoz) |
| 689 | { return mp_pywrap(MP_COPY(RSA_PRIV(me)->q_inv)); } |
| 690 | |
| 691 | static PyObject *rsaget_rng(PyObject *me, void *hunoz) |
| 692 | { RETURN_OBJ(RSA_RNG(me)); } |
| 693 | |
| 694 | static int rsaset_rng(PyObject *me, PyObject *val, void *hunoz) |
| 695 | { |
| 696 | int rc = -1; |
| 697 | if (!val) |
| 698 | val = Py_None; |
| 699 | else if (val != Py_None && !GRAND_PYCHECK(val)) |
| 700 | TYERR("expected grand or None"); |
| 701 | Py_DECREF(RSA_RNG(me)); |
| 702 | RSA_RNG(me) = val; |
| 703 | Py_INCREF(val); |
| 704 | rc = 0; |
| 705 | end: |
| 706 | return (rc); |
| 707 | } |
| 708 | |
| 709 | static PyObject *rsameth_privop(PyObject *me, PyObject *arg, PyObject *kw) |
| 710 | { |
| 711 | PyObject *rng = RSA_RNG(me); |
| 712 | mp *x = 0; |
| 713 | PyObject *rc = 0; |
| 714 | static const char *const kwlist[] = { "x", "rng", 0 }; |
| 715 | |
| 716 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O:privop", KWLIST, |
| 717 | convmp, &x, &rng)) |
| 718 | goto end; |
| 719 | if (rng != Py_None && !GRAND_PYCHECK(rng)) |
| 720 | TYERR("not a random number source"); |
| 721 | RSA_PRIVCTX(me)->r = (rng == Py_None) ? 0 : GRAND_R(rng); |
| 722 | rc = mp_pywrap(rsa_privop(RSA_PRIVCTX(me), MP_NEW, x)); |
| 723 | end: |
| 724 | mp_drop(x); |
| 725 | return (rc); |
| 726 | } |
| 727 | |
| 728 | static PyObject *meth__RSAPriv_generate(PyObject *me, |
| 729 | PyObject *arg, PyObject *kw) |
| 730 | { |
| 731 | grand *r = &rand_global; |
| 732 | unsigned nbits; |
| 733 | unsigned n = 0; |
| 734 | rsa_priv rp; |
| 735 | mp *e = 0; |
| 736 | struct excinfo exc = EXCINFO_INIT; |
| 737 | pypgev evt = { { 0 } }; |
| 738 | static const char *const kwlist[] = |
| 739 | { "class", "nbits", "event", "rng", "nsteps", "e", 0 }; |
| 740 | PyObject *rc = 0; |
| 741 | |
| 742 | evt.exc = &exc; |
| 743 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "OO&|O&O&O&O&:generate", KWLIST, |
| 744 | &me, convuint, &nbits, convpgev, &evt, |
| 745 | convgrand, &r, convuint, &n, |
| 746 | convmp, &e)) |
| 747 | goto end; |
| 748 | if (e) MP_COPY(e); |
| 749 | else e = mp_fromulong(MP_NEW, 65537); |
| 750 | if (rsa_gen_e(&rp, nbits, e, r, n, evt.ev.proc, evt.ev.ctx)) |
| 751 | PGENERR(&exc); |
| 752 | rc = rsapriv_pywrap(&rp); |
| 753 | end: |
| 754 | droppgev(&evt); |
| 755 | mp_drop(e); |
| 756 | return (rc); |
| 757 | } |
| 758 | |
| 759 | static PyGetSetDef rsapub_pygetset[] = { |
| 760 | #define GETSETNAME(op, name) rsa##op##_##name |
| 761 | GET (n, "R.n -> N") |
| 762 | GET (e, "R.e -> E") |
| 763 | #undef GETSETNAME |
| 764 | { 0 } |
| 765 | }; |
| 766 | |
| 767 | static PyMethodDef rsapub_pymethods[] = { |
| 768 | #define METHNAME(name) rsameth_##name |
| 769 | METH (pubop, "R.pubop(X) -> X^E (mod N)") |
| 770 | #undef METHNAME |
| 771 | { 0 } |
| 772 | }; |
| 773 | |
| 774 | static PyGetSetDef rsapriv_pygetset[] = { |
| 775 | #define GETSETNAME(op, name) rsa##op##_##name |
| 776 | GET (d, "R.d -> D") |
| 777 | GET (p, "R.p -> P") |
| 778 | GET (q, "R.q -> Q") |
| 779 | GET (dp, "R.dp -> D mod (P - 1)") |
| 780 | GET (dq, "R.dq -> D mod (Q - 1)") |
| 781 | GET (q_inv, "R.q_inv -> Q^{-1} mod P") |
| 782 | GETSET(rng, "R.rng -> random number source for blinding") |
| 783 | #undef GETSETNAME |
| 784 | { 0 } |
| 785 | }; |
| 786 | |
| 787 | static PyMethodDef rsapriv_pymethods[] = { |
| 788 | #define METHNAME(name) rsameth_##name |
| 789 | KWMETH(privop, "R.privop(X, [rng = None]) -> X^D (mod N)") |
| 790 | #undef METHNAME |
| 791 | { 0 } |
| 792 | }; |
| 793 | |
| 794 | static PyTypeObject rsapub_pytype_skel = { |
| 795 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 796 | "RSAPub", /* @tp_name@ */ |
| 797 | sizeof(rsapub_pyobj), /* @tp_basicsize@ */ |
| 798 | 0, /* @tp_itemsize@ */ |
| 799 | |
| 800 | rsapub_pydealloc, /* @tp_dealloc@ */ |
| 801 | 0, /* @tp_print@ */ |
| 802 | 0, /* @tp_getattr@ */ |
| 803 | 0, /* @tp_setattr@ */ |
| 804 | 0, /* @tp_compare@ */ |
| 805 | 0, /* @tp_repr@ */ |
| 806 | 0, /* @tp_as_number@ */ |
| 807 | 0, /* @tp_as_sequence@ */ |
| 808 | 0, /* @tp_as_mapping@ */ |
| 809 | 0, /* @tp_hash@ */ |
| 810 | 0, /* @tp_call@ */ |
| 811 | 0, /* @tp_str@ */ |
| 812 | 0, /* @tp_getattro@ */ |
| 813 | 0, /* @tp_setattro@ */ |
| 814 | 0, /* @tp_as_buffer@ */ |
| 815 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 816 | Py_TPFLAGS_BASETYPE, |
| 817 | |
| 818 | /* @tp_doc@ */ |
| 819 | "RSAPub(N, E): RSA public key.", |
| 820 | |
| 821 | 0, /* @tp_traverse@ */ |
| 822 | 0, /* @tp_clear@ */ |
| 823 | 0, /* @tp_richcompare@ */ |
| 824 | 0, /* @tp_weaklistoffset@ */ |
| 825 | 0, /* @tp_iter@ */ |
| 826 | 0, /* @tp_iternext@ */ |
| 827 | rsapub_pymethods, /* @tp_methods@ */ |
| 828 | 0, /* @tp_members@ */ |
| 829 | rsapub_pygetset, /* @tp_getset@ */ |
| 830 | 0, /* @tp_base@ */ |
| 831 | 0, /* @tp_dict@ */ |
| 832 | 0, /* @tp_descr_get@ */ |
| 833 | 0, /* @tp_descr_set@ */ |
| 834 | 0, /* @tp_dictoffset@ */ |
| 835 | 0, /* @tp_init@ */ |
| 836 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 837 | rsapub_pynew, /* @tp_new@ */ |
| 838 | 0, /* @tp_free@ */ |
| 839 | 0 /* @tp_is_gc@ */ |
| 840 | }; |
| 841 | |
| 842 | static PyTypeObject rsapriv_pytype_skel = { |
| 843 | PyObject_HEAD_INIT(0) 0, /* Header */ |
| 844 | "RSAPriv", /* @tp_name@ */ |
| 845 | sizeof(rsapriv_pyobj), /* @tp_basicsize@ */ |
| 846 | 0, /* @tp_itemsize@ */ |
| 847 | |
| 848 | rsapriv_pydealloc, /* @tp_dealloc@ */ |
| 849 | 0, /* @tp_print@ */ |
| 850 | 0, /* @tp_getattr@ */ |
| 851 | 0, /* @tp_setattr@ */ |
| 852 | 0, /* @tp_compare@ */ |
| 853 | 0, /* @tp_repr@ */ |
| 854 | 0, /* @tp_as_number@ */ |
| 855 | 0, /* @tp_as_sequence@ */ |
| 856 | 0, /* @tp_as_mapping@ */ |
| 857 | 0, /* @tp_hash@ */ |
| 858 | 0, /* @tp_call@ */ |
| 859 | 0, /* @tp_str@ */ |
| 860 | 0, /* @tp_getattro@ */ |
| 861 | 0, /* @tp_setattro@ */ |
| 862 | 0, /* @tp_as_buffer@ */ |
| 863 | Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ |
| 864 | Py_TPFLAGS_BASETYPE, |
| 865 | |
| 866 | /* @tp_doc@ */ |
| 867 | "RSAPriv(..., [rng = rand]): RSA private key.\n\ |
| 868 | Keywords: n, e, d, p, q, dp, dq, q_inv; must provide enough", |
| 869 | |
| 870 | 0, /* @tp_traverse@ */ |
| 871 | 0, /* @tp_clear@ */ |
| 872 | 0, /* @tp_richcompare@ */ |
| 873 | 0, /* @tp_weaklistoffset@ */ |
| 874 | 0, /* @tp_iter@ */ |
| 875 | 0, /* @tp_iternext@ */ |
| 876 | rsapriv_pymethods, /* @tp_methods@ */ |
| 877 | 0, /* @tp_members@ */ |
| 878 | rsapriv_pygetset, /* @tp_getset@ */ |
| 879 | 0, /* @tp_base@ */ |
| 880 | 0, /* @tp_dict@ */ |
| 881 | 0, /* @tp_descr_get@ */ |
| 882 | 0, /* @tp_descr_set@ */ |
| 883 | 0, /* @tp_dictoffset@ */ |
| 884 | 0, /* @tp_init@ */ |
| 885 | PyType_GenericAlloc, /* @tp_alloc@ */ |
| 886 | rsapriv_pynew, /* @tp_new@ */ |
| 887 | 0, /* @tp_free@ */ |
| 888 | 0 /* @tp_is_gc@ */ |
| 889 | }; |
| 890 | |
| 891 | /*----- RSA padding schemes -----------------------------------------------*/ |
| 892 | |
| 893 | static PyObject *meth__p1crypt_encode(PyObject *me, |
| 894 | PyObject *arg, PyObject *kw) |
| 895 | { |
| 896 | pkcs1 p1; |
| 897 | char *m, *ep; |
| 898 | Py_ssize_t msz, epsz; |
| 899 | unsigned long nbits; |
| 900 | PyObject *rc = 0; |
| 901 | octet *b = 0; |
| 902 | size_t sz; |
| 903 | mp *x; |
| 904 | static const char *const kwlist[] = { "msg", "nbits", "ep", "rng", 0 }; |
| 905 | |
| 906 | p1.r = &rand_global; ep = 0; epsz = 0; |
| 907 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|s#O&:encode", KWLIST, |
| 908 | &m, &msz, convulong, &nbits, |
| 909 | &ep, &epsz, convgrand, &p1.r)) |
| 910 | goto end; |
| 911 | sz = (nbits + 7)/8; |
| 912 | p1.ep = ep; p1.epsz = epsz; |
| 913 | if (epsz + msz + 11 > sz) VALERR("buffer underflow"); |
| 914 | b = xmalloc(sz); |
| 915 | x = pkcs1_cryptencode(MP_NEW, m, msz, b, sz, nbits, &p1); |
| 916 | rc = mp_pywrap(x); |
| 917 | end: |
| 918 | xfree(b); |
| 919 | return (rc); |
| 920 | } |
| 921 | |
| 922 | static PyObject *meth__p1crypt_decode(PyObject *me, |
| 923 | PyObject *arg, PyObject *kw) |
| 924 | { |
| 925 | pkcs1 p1; |
| 926 | char *ep; |
| 927 | Py_ssize_t epsz; |
| 928 | unsigned long nbits; |
| 929 | int n; |
| 930 | PyObject *rc = 0; |
| 931 | octet *b = 0; |
| 932 | size_t sz; |
| 933 | mp *x = 0; |
| 934 | static const char *const kwlist[] = { "ct", "nbits", "ep", "rng", 0 }; |
| 935 | |
| 936 | p1.r = &rand_global; ep = 0; epsz = 0; |
| 937 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&|s#O&:decode", KWLIST, |
| 938 | convmp, &x, convulong, &nbits, |
| 939 | &ep, &epsz, convgrand, &p1.r)) |
| 940 | goto end; |
| 941 | sz = (nbits + 7)/8; |
| 942 | p1.ep = ep; p1.epsz = epsz; |
| 943 | if (epsz + 11 > sz) VALERR("buffer underflow"); |
| 944 | b = xmalloc(sz); |
| 945 | if ((n = pkcs1_cryptdecode(x, b, sz, nbits, &p1)) < 0) |
| 946 | VALERR("decryption failed"); |
| 947 | rc = bytestring_pywrap(b, n); |
| 948 | end: |
| 949 | mp_drop(x); |
| 950 | xfree(b); |
| 951 | return (rc); |
| 952 | } |
| 953 | |
| 954 | static PyObject *meth__p1sig_encode(PyObject *me, |
| 955 | PyObject *arg, PyObject *kw) |
| 956 | { |
| 957 | pkcs1 p1; |
| 958 | char *m, *ep; |
| 959 | Py_ssize_t msz, epsz; |
| 960 | unsigned long nbits; |
| 961 | PyObject *rc = 0; |
| 962 | octet *b = 0; |
| 963 | size_t sz; |
| 964 | mp *x; |
| 965 | static const char *const kwlist[] = { "msg", "nbits", "ep", "rng", 0 }; |
| 966 | |
| 967 | p1.r = &rand_global; ep = 0; epsz = 0; |
| 968 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|s#O&:encode", KWLIST, |
| 969 | &m, &msz, convulong, &nbits, |
| 970 | &ep, &epsz, convgrand, &p1.r)) |
| 971 | goto end; |
| 972 | sz = (nbits + 7)/8; |
| 973 | p1.ep = ep; p1.epsz = epsz; |
| 974 | if (epsz + msz + 11 > sz) VALERR("buffer underflow"); |
| 975 | b = xmalloc(sz); |
| 976 | x = pkcs1_sigencode(MP_NEW, m, msz, b, sz, nbits, &p1); |
| 977 | rc = mp_pywrap(x); |
| 978 | end: |
| 979 | xfree(b); |
| 980 | return (rc); |
| 981 | } |
| 982 | |
| 983 | static PyObject *meth__p1sig_decode(PyObject *me, |
| 984 | PyObject *arg, PyObject *kw) |
| 985 | { |
| 986 | pkcs1 p1; |
| 987 | char *ep; |
| 988 | Py_ssize_t epsz; |
| 989 | unsigned long nbits; |
| 990 | int n; |
| 991 | PyObject *hukairz; |
| 992 | PyObject *rc = 0; |
| 993 | octet *b = 0; |
| 994 | size_t sz; |
| 995 | mp *x = 0; |
| 996 | static const char *const kwlist[] = |
| 997 | { "msg", "sig", "nbits", "ep", "rng", 0 }; |
| 998 | |
| 999 | p1.r = &rand_global; ep = 0; epsz = 0; |
| 1000 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "OO&O&|s#O&:decode", KWLIST, |
| 1001 | &hukairz, convmp, &x, convulong, &nbits, |
| 1002 | &ep, &epsz, convgrand, &p1.r)) |
| 1003 | goto end; |
| 1004 | sz = (nbits + 7)/8; |
| 1005 | p1.ep = ep; p1.epsz = epsz; |
| 1006 | if (epsz + 10 > sz) VALERR("buffer underflow"); |
| 1007 | b = xmalloc(sz); |
| 1008 | if ((n = pkcs1_sigdecode(x, 0, 0, b, sz, nbits, &p1)) < 0) |
| 1009 | VALERR("verification failed"); |
| 1010 | rc = bytestring_pywrap(b, n); |
| 1011 | end: |
| 1012 | mp_drop(x); |
| 1013 | xfree(b); |
| 1014 | return (rc); |
| 1015 | } |
| 1016 | |
| 1017 | static PyObject *meth__oaep_encode(PyObject *me, |
| 1018 | PyObject *arg, PyObject *kw) |
| 1019 | { |
| 1020 | oaep o; |
| 1021 | char *m, *ep; |
| 1022 | Py_ssize_t msz, epsz; |
| 1023 | unsigned long nbits; |
| 1024 | PyObject *rc = 0; |
| 1025 | octet *b = 0; |
| 1026 | size_t sz; |
| 1027 | mp *x; |
| 1028 | static const char *const kwlist[] = |
| 1029 | { "msg", "nbits", "mgf", "hash", "ep", "rng", 0 }; |
| 1030 | |
| 1031 | o.r = &rand_global; o.cc = &sha_mgf; o.ch = &sha; ep = 0; epsz = 0; |
| 1032 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|O&O&s#O&:encode", KWLIST, |
| 1033 | &m, &msz, convulong, &nbits, |
| 1034 | convgccipher, &o.cc, |
| 1035 | convgchash, &o.ch, |
| 1036 | &ep, &epsz, |
| 1037 | convgrand, &o.r)) |
| 1038 | goto end; |
| 1039 | sz = (nbits + 7)/8; |
| 1040 | o.ep = ep; o.epsz = epsz; |
| 1041 | if (2 * o.ch->hashsz + 2 + msz > sz) VALERR("buffer underflow"); |
| 1042 | b = xmalloc(sz); |
| 1043 | x = oaep_encode(MP_NEW, m, msz, b, sz, nbits, &o); |
| 1044 | rc = mp_pywrap(x); |
| 1045 | end: |
| 1046 | xfree(b); |
| 1047 | return (rc); |
| 1048 | } |
| 1049 | |
| 1050 | static PyObject *meth__oaep_decode(PyObject *me, |
| 1051 | PyObject *arg, PyObject *kw) |
| 1052 | { |
| 1053 | oaep o; |
| 1054 | char *ep; |
| 1055 | Py_ssize_t epsz; |
| 1056 | unsigned long nbits; |
| 1057 | int n; |
| 1058 | PyObject *rc = 0; |
| 1059 | octet *b = 0; |
| 1060 | size_t sz; |
| 1061 | mp *x = 0; |
| 1062 | static const char *const kwlist[] = |
| 1063 | { "ct", "nbits", "mgf", "hash", "ep", "rng", 0 }; |
| 1064 | |
| 1065 | o.r = &rand_global; o.cc = &sha_mgf; o.ch = &sha; ep = 0; epsz = 0; |
| 1066 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&|O&O&s#O&:decode", KWLIST, |
| 1067 | convmp, &x, convulong, &nbits, |
| 1068 | convgccipher, &o.cc, |
| 1069 | convgchash, &o.ch, |
| 1070 | &ep, &epsz, |
| 1071 | convgrand, &o.r)) |
| 1072 | goto end; |
| 1073 | sz = (nbits + 7)/8; |
| 1074 | o.ep = ep; o.epsz = epsz; |
| 1075 | if (2 * o.ch->hashsz > sz) VALERR("buffer underflow"); |
| 1076 | b = xmalloc(sz); |
| 1077 | if ((n = oaep_decode(x, b, sz, nbits, &o)) < 0) |
| 1078 | VALERR("decryption failed"); |
| 1079 | rc = bytestring_pywrap(b, n); |
| 1080 | end: |
| 1081 | mp_drop(x); |
| 1082 | xfree(b); |
| 1083 | return (rc); |
| 1084 | } |
| 1085 | |
| 1086 | static PyObject *meth__pss_encode(PyObject *me, |
| 1087 | PyObject *arg, PyObject *kw) |
| 1088 | { |
| 1089 | pss p; |
| 1090 | char *m; |
| 1091 | Py_ssize_t msz; |
| 1092 | unsigned long nbits; |
| 1093 | PyObject *rc = 0; |
| 1094 | octet *b = 0; |
| 1095 | size_t sz; |
| 1096 | mp *x = 0; |
| 1097 | static const char *const kwlist[] = |
| 1098 | { "msg", "nbits", "mgf", "hash", "saltsz", "rng", 0 }; |
| 1099 | |
| 1100 | p.cc = &sha_mgf; p.ch = &sha; p.r = &rand_global; p.ssz = (size_t)-1; |
| 1101 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|O&O&O&O&:encode", KWLIST, |
| 1102 | &m, &msz, convulong, &nbits, |
| 1103 | convgccipher, &p.cc, |
| 1104 | convgchash, &p.ch, |
| 1105 | convszt, &p.ssz, |
| 1106 | convgrand, &p.r)) |
| 1107 | goto end; |
| 1108 | sz = (nbits + 7)/8; |
| 1109 | if (p.ssz == (size_t)-1) p.ssz = p.ch->hashsz; |
| 1110 | if (p.ch->hashsz + p.ssz + 2 > sz) VALERR("buffer underflow"); |
| 1111 | b = xmalloc(sz); |
| 1112 | x = pss_encode(MP_NEW, m, msz, b, sz, nbits, &p); |
| 1113 | rc = mp_pywrap(x); |
| 1114 | end: |
| 1115 | xfree(b); |
| 1116 | return (rc); |
| 1117 | } |
| 1118 | |
| 1119 | static PyObject *meth__pss_decode(PyObject *me, |
| 1120 | PyObject *arg, PyObject *kw) |
| 1121 | { |
| 1122 | pss p; |
| 1123 | char *m; |
| 1124 | Py_ssize_t msz; |
| 1125 | unsigned long nbits; |
| 1126 | PyObject *rc = 0; |
| 1127 | octet *b = 0; |
| 1128 | size_t sz; |
| 1129 | int n; |
| 1130 | mp *x = 0; |
| 1131 | static const char *const kwlist[] = |
| 1132 | { "msg", "sig", "nbits", "mgf", "hash", "saltsz", "rng", 0 }; |
| 1133 | |
| 1134 | p.cc = &sha_mgf; p.ch = &sha; p.r = &rand_global; p.ssz = (size_t)-1; |
| 1135 | if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&O&|O&O&O&O&:decode", KWLIST, |
| 1136 | &m, &msz, convmp, &x, convulong, &nbits, |
| 1137 | convgccipher, &p.cc, |
| 1138 | convgchash, &p.ch, |
| 1139 | convszt, &p.ssz, |
| 1140 | convgrand, &p.r)) |
| 1141 | goto end; |
| 1142 | sz = (nbits + 7)/8; |
| 1143 | if (p.ssz == (size_t)-1) p.ssz = p.ch->hashsz; |
| 1144 | if (p.ch->hashsz + p.ssz + 2 > sz) VALERR("buffer underflow"); |
| 1145 | b = xmalloc(sz); |
| 1146 | if ((n = pss_decode(x, m, msz, b, sz, nbits, &p)) < 0) |
| 1147 | VALERR("verification failed"); |
| 1148 | rc = Py_None; Py_INCREF(rc); |
| 1149 | end: |
| 1150 | mp_drop(x); |
| 1151 | xfree(b); |
| 1152 | return (rc); |
| 1153 | } |
| 1154 | |
| 1155 | /*----- X25519 and related algorithms -------------------------------------*/ |
| 1156 | |
| 1157 | #define XDHS(_) \ |
| 1158 | _(X25519, x25519) \ |
| 1159 | _(X448, x448) |
| 1160 | |
| 1161 | #define DEFXDH(X, x) \ |
| 1162 | static PyObject *meth_##x(PyObject *me, PyObject *arg) \ |
| 1163 | { \ |
| 1164 | const char *k, *p; \ |
| 1165 | Py_ssize_t ksz, psz; \ |
| 1166 | PyObject *rc = 0; \ |
| 1167 | if (!PyArg_ParseTuple(arg, "s#s#:" #x, &k, &ksz, &p, &psz)) \ |
| 1168 | goto end; \ |
| 1169 | if (ksz != X##_KEYSZ) VALERR("bad key length"); \ |
| 1170 | if (psz != X##_PUBSZ) VALERR("bad public length"); \ |
| 1171 | rc = bytestring_pywrap(0, X##_OUTSZ); \ |
| 1172 | x((octet *)PyString_AS_STRING(rc), \ |
| 1173 | (const octet *)k, (const octet *)p); \ |
| 1174 | return (rc); \ |
| 1175 | end: \ |
| 1176 | return (0); \ |
| 1177 | } |
| 1178 | XDHS(DEFXDH) |
| 1179 | #undef DEFXDH |
| 1180 | |
| 1181 | /*----- Ed25519 and related algorithms ------------------------------------*/ |
| 1182 | |
| 1183 | #define EDDSAS(_) \ |
| 1184 | _(ED25519, ed25519, -1, ctx) \ |
| 1185 | _(ED448, ed448, 0, ) |
| 1186 | |
| 1187 | #define DEFEDDSA(ED, ed, phdflt, sigver) \ |
| 1188 | \ |
| 1189 | static PyObject *meth_##ed##_pubkey(PyObject *me, PyObject *arg) \ |
| 1190 | { \ |
| 1191 | const char *k; \ |
| 1192 | Py_ssize_t ksz; \ |
| 1193 | PyObject *rc = 0; \ |
| 1194 | if (!PyArg_ParseTuple(arg, "s#:" #ed "_pubkey", &k, &ksz)) \ |
| 1195 | goto end; \ |
| 1196 | rc = bytestring_pywrap(0, ED##_PUBSZ); \ |
| 1197 | ed##_pubkey((octet *)PyString_AS_STRING(rc), k, ksz); \ |
| 1198 | return (rc); \ |
| 1199 | end: \ |
| 1200 | return (0); \ |
| 1201 | } \ |
| 1202 | \ |
| 1203 | static PyObject *meth_##ed##_sign(PyObject *me, PyObject *arg, \ |
| 1204 | PyObject *kw) \ |
| 1205 | { \ |
| 1206 | const char *k, *p = 0, *c = 0, *m; \ |
| 1207 | Py_ssize_t ksz, psz, csz = 0, msz; \ |
| 1208 | int ph = phdflt; \ |
| 1209 | PyObject *rc = 0; \ |
| 1210 | octet pp[ED##_PUBSZ]; \ |
| 1211 | static const char *const kwlist[] = \ |
| 1212 | { "key", "msg", "pub", "perso", "phflag", 0 }; \ |
| 1213 | if (!PyArg_ParseTupleAndKeywords(arg, kw, \ |
| 1214 | "s#s#|s#s#O&:" #ed "_sign", \ |
| 1215 | KWLIST, \ |
| 1216 | &k, &ksz, &m, &msz, &p, &psz, \ |
| 1217 | &c, &csz, convbool, &ph)) \ |
| 1218 | goto end; \ |
| 1219 | if (p && psz != ED##_PUBSZ) VALERR("bad public length"); \ |
| 1220 | if (c && csz > ED##_MAXPERSOSZ) \ |
| 1221 | VALERR("personalization string too long"); \ |
| 1222 | if (c && ph == -1) ph = 0; \ |
| 1223 | if (!p) { p = (const char *)pp; ed##_pubkey(pp, k, ksz); } \ |
| 1224 | rc = bytestring_pywrap(0, ED##_SIGSZ); \ |
| 1225 | ed##sigver##_sign((octet *)PyString_AS_STRING(rc), k, ksz, \ |
| 1226 | (const octet *)p, ph, c, csz, m, msz); \ |
| 1227 | return (rc); \ |
| 1228 | end: \ |
| 1229 | return (0); \ |
| 1230 | } \ |
| 1231 | \ |
| 1232 | static PyObject *meth_##ed##_verify(PyObject *me, \ |
| 1233 | PyObject *arg, PyObject *kw) \ |
| 1234 | { \ |
| 1235 | const char *p, *c = 0, *m, *s; \ |
| 1236 | Py_ssize_t psz, csz = 0, msz, ssz; \ |
| 1237 | int ph = phdflt; \ |
| 1238 | PyObject *rc = 0; \ |
| 1239 | static const char *const kwlist[] = \ |
| 1240 | { "pub", "msg", "sig", "perso", "phflag", 0 }; \ |
| 1241 | if (!PyArg_ParseTupleAndKeywords(arg, kw, \ |
| 1242 | "s#s#s#|s#O&:" #ed "_verify", \ |
| 1243 | KWLIST, \ |
| 1244 | &p, &psz, &m, &msz, &s, &ssz, \ |
| 1245 | &c, &csz, convbool, &ph)) \ |
| 1246 | goto end; \ |
| 1247 | if (psz != ED##_PUBSZ) VALERR("bad public length"); \ |
| 1248 | if (ssz != ED##_SIGSZ) VALERR("bad signature length"); \ |
| 1249 | if (c && csz > ED##_MAXPERSOSZ) \ |
| 1250 | VALERR("personalization string too long"); \ |
| 1251 | if (c && ph == -1) ph = 0; \ |
| 1252 | rc = getbool(!ed##sigver##_verify((const octet *)p, ph, c, csz, \ |
| 1253 | m, msz, (const octet *)s)); \ |
| 1254 | return (rc); \ |
| 1255 | end: \ |
| 1256 | return (0); \ |
| 1257 | } |
| 1258 | EDDSAS(DEFEDDSA) |
| 1259 | #undef DEFEDDSA |
| 1260 | |
| 1261 | /*----- Global stuff ------------------------------------------------------*/ |
| 1262 | |
| 1263 | static PyMethodDef methods[] = { |
| 1264 | #define METHNAME(name) meth_##name |
| 1265 | KWMETH(_p1crypt_encode, 0) |
| 1266 | KWMETH(_p1crypt_decode, 0) |
| 1267 | KWMETH(_p1sig_encode, 0) |
| 1268 | KWMETH(_p1sig_decode, 0) |
| 1269 | KWMETH(_oaep_encode, 0) |
| 1270 | KWMETH(_oaep_decode, 0) |
| 1271 | KWMETH(_pss_encode, 0) |
| 1272 | KWMETH(_pss_decode, 0) |
| 1273 | KWMETH(_RSAPriv_generate, "\ |
| 1274 | generate(NBITS, [event = pgen_nullev], [rng = rand], [nsteps = 0]) -> R") |
| 1275 | #define DEFMETH(X, x) \ |
| 1276 | METH (x, "\ |
| 1277 | " #x "(KEY, PUBLIC) -> SHARED") |
| 1278 | XDHS(DEFMETH) |
| 1279 | #undef DEFMETH |
| 1280 | #define DEFMETH(ED, ed, phdflt, sigver) \ |
| 1281 | METH (ed##_pubkey, "\ |
| 1282 | " #ed "_pubkey(KEY) -> PUBLIC") \ |
| 1283 | KWMETH(ed##_sign, "\ |
| 1284 | " #ed "_sign(KEY, MSG, [pub = PUBLIC], " \ |
| 1285 | "[perso = STRING], [phflag = BOOL]) -> SIG") \ |
| 1286 | KWMETH(ed##_verify, "\ |
| 1287 | " #ed "_verify(PUBLIC, MSG, SIG, " \ |
| 1288 | "[perso = STRING], [phflag = BOOL]) -> BOOL") |
| 1289 | EDDSAS(DEFMETH) |
| 1290 | #undef DEFMETH |
| 1291 | #undef METHNAME |
| 1292 | { 0 } |
| 1293 | }; |
| 1294 | |
| 1295 | void pubkey_pyinit(void) |
| 1296 | { |
| 1297 | INITTYPE(dsapub, root); |
| 1298 | INITTYPE(dsapriv, dsapub); |
| 1299 | INITTYPE(kcdsapub, root); |
| 1300 | INITTYPE(kcdsapriv, kcdsapub); |
| 1301 | INITTYPE(rsapub, root); |
| 1302 | INITTYPE(rsapriv, rsapub); |
| 1303 | addmethods(methods); |
| 1304 | } |
| 1305 | |
| 1306 | void pubkey_pyinsert(PyObject *mod) |
| 1307 | { |
| 1308 | INSERT("DSAPub", dsapub_pytype); |
| 1309 | INSERT("DSAPriv", dsapriv_pytype); |
| 1310 | INSERT("KCDSAPub", kcdsapub_pytype); |
| 1311 | INSERT("KCDSAPriv", kcdsapriv_pytype); |
| 1312 | INSERT("RSAPub", rsapub_pytype); |
| 1313 | INSERT("RSAPriv", rsapriv_pytype); |
| 1314 | } |
| 1315 | |
| 1316 | /*----- That's all, folks -------------------------------------------------*/ |