From bebf03ab18a3bc9fbb537fcf821b0b53f8db1b81 Mon Sep 17 00:00:00 2001 From: Mark Wooding Date: Fri, 9 Nov 2018 15:35:14 +0000 Subject: [PATCH] algorithms.c, etc.: Support the new AEAD abstraction. The new machinery means we can reimplement `secret_box' and `secret_unbox' using Catacomb's `..._naclbox' AE scheme. --- algorithms.c | 1094 ++++++++++++++++++++++++++++++++++++++++++++++++++ algorithms.py | 1 + catacomb-python.h | 111 +++++ catacomb.c | 2 + catacomb/__init__.py | 38 +- debian/control | 2 +- setup.py | 2 +- 7 files changed, 1235 insertions(+), 15 deletions(-) diff --git a/algorithms.c b/algorithms.c index 50ae068..d73981e 100644 --- a/algorithms.c +++ b/algorithms.c @@ -710,6 +710,1082 @@ static PyTypeObject gcipher_pytype_skel = { 0 /* @tp_is_gc@ */ }; +/*----- Authenticated encryption ------------------------------------------*/ + +PyTypeObject *gcaead_pytype, *gaeadkey_pytype; +PyTypeObject *gcaeadaad_pytype, *gaeadaad_pytype; +PyTypeObject *gcaeadenc_pytype, *gaeadenc_pytype; +PyTypeObject *gcaeaddec_pytype, *gaeaddec_pytype; + +CONVFUNC(gcaead, gcaead *, GCAEAD_AEC) +CONVFUNC(gaeadkey, gaead_key *, GAEADKEY_K) + +PyObject *gaeadkey_pywrap(PyObject *cobj, gaead_key *k) +{ + gaeadkey_pyobj *gk; + + if (!cobj) cobj = gcaead_pywrap((/*unconst*/ gcaead *)GAEAD_CLASS(k)); + else Py_INCREF(cobj); + gk = PyObject_NEW(gaeadkey_pyobj, (PyTypeObject *)cobj); + gk->k = k; + return ((PyObject *)gk); +} + +static PyObject *gaeadkey_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "k", 0 }; + char *k; + Py_ssize_t sz; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", KWLIST, &k, &sz)) + goto end; + if (keysz(sz, GCAEAD_AEC(ty)->keysz) != sz) VALERR("bad key length"); + return (gaeadkey_pywrap((PyObject *)ty, + GAEAD_KEY(GCAEAD_AEC(ty), k, sz))); +end: + return (0); +} + +PyObject *gcaead_pywrap(gcaead *aec) +{ + gcaead_pyobj *gck; + gcaeadaad_pyobj *gca; + gcaeadenc_pyobj *gce; + gcaeaddec_pyobj *gcd; + +#define MKTYPE(obj, thing, newfn, namefmt) do { \ + (obj) = newtype(gcaead_pytype, 0, 0); \ + (obj)->ty.ht_name = PyString_FromFormat(namefmt, aec->name); \ + (obj)->ty.ht_type.tp_name = PyString_AS_STRING((obj)->ty.ht_name); \ + (obj)->ty.ht_type.tp_basicsize = sizeof(gaead##thing##_pyobj); \ + (obj)->ty.ht_type.tp_base = gaead##thing##_pytype; \ + Py_INCREF(gaead##thing##_pytype); \ + (obj)->ty.ht_type.tp_flags = \ + (Py_TPFLAGS_DEFAULT | Py_TPFLAGS_BASETYPE | Py_TPFLAGS_HEAPTYPE); \ + (obj)->ty.ht_type.tp_alloc = PyType_GenericAlloc; \ + (obj)->ty.ht_type.tp_free = 0; \ + (obj)->ty.ht_type.tp_new = newfn; \ + typeready(&(obj)->ty.ht_type); \ +} while (0) + + MKTYPE(gck, key, gaeadkey_pynew, "%s(key)"); + MKTYPE(gca, aad, abstract_pynew, "%s(aad-hash)"); + MKTYPE(gce, enc, abstract_pynew, "%s(encrypt)"); + MKTYPE(gcd, dec, abstract_pynew, "%s(decrypt)"); + +#undef MKTYPE + + gck->aec = aec; gck->aad = gca; gck->enc = gce; gck->dec = gcd; + gca->key = gce->key = gcd->key = gck; + return ((PyObject *)gck); +} + +static void gaeadkey_pydealloc(PyObject *me) + { GAEAD_DESTROY(GAEADKEY_K(me)); Py_DECREF(me->ob_type); FREEOBJ(me); } + +static PyObject *gcaeget_name(PyObject *me, void *hunoz) + { return (PyString_FromString(GCAEAD_AEC(me)->name)); } + +static PyObject *gcaeget_keysz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->keysz)); } + +static PyObject *gcaeget_noncesz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->noncesz)); } + +static PyObject *gcaeget_tagsz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->tagsz)); } + +static PyObject *gcaeget_blksz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->blksz)); } + +static PyObject *gcaeget_bufsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->bufsz)); } + +static PyObject *gcaeget_ohd(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->ohd)); } + +static PyObject *gcaeget_flags(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->f)); } + +static PyGetSetDef gcaead_pygetset[] = { +#define GETSETNAME(op, name) gcae##op##_##name + GET (keysz, "AEC.keysz -> acceptable key sizes") + GET (noncesz, "AEC.noncesz -> acceptable nonce sizes") + GET (tagsz, "AEC.tagsz -> acceptable tag sizes") + GET (blksz, "AEC.blksz -> block size, or zero") + GET (bufsz, "AEC.bufsz -> amount of data buffered internally") + GET (ohd, "AEC.ohd -> maximum encryption overhead") + GET (name, "AEC.name -> name of this kind of AEAD scheme") + GET (flags, "AEC.flags -> mask of `AEADF_...' flags") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaekmeth_aad(PyObject *me, PyObject *arg) +{ + const gaead_key *k = GAEADKEY_K(me); + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, ":aad")) return (0); + if (k->ops->c->f&AEADF_AADNDEP) + VALERR("aad must be associated with enc/dec op"); + rc = gaeadaad_pywrap((PyObject *)GCAEAD_AAD(me->ob_type), + GAEAD_AAD(k), 0, 0); +end: + return (rc); +} + +static int check_aead_encdec(const gcaead *aec, unsigned *f_out, size_t nsz, + PyObject *hszobj, size_t *hsz_out, + PyObject *mszobj, size_t *msz_out, + PyObject *tszobj, size_t *tsz_out) +{ + unsigned f = 0, miss; + int rc = -1; + + if (hszobj != Py_None) + { f |= AEADF_PCHSZ; if (!convszt(hszobj, hsz_out)) goto end; } + if (mszobj != Py_None) + { f |= AEADF_PCMSZ; if (!convszt(mszobj, msz_out)) goto end; } + if (tszobj != Py_None) + { f |= AEADF_PCTSZ; if (!convszt(tszobj, tsz_out)) goto end; } + miss = aec->f&~f; + if (miss&AEADF_PCHSZ) VALERR("header length precommitment required"); + if (miss&AEADF_PCMSZ) VALERR("message length precommitment required"); + if (miss&AEADF_PCTSZ) VALERR("tag length precommitment required"); + if (keysz(nsz, aec->noncesz) != nsz) VALERR("bad nonce length"); + if (tszobj != Py_None && keysz(*tsz_out, aec->tagsz) != *tsz_out) + VALERR("bad tag length"); + *f_out = f | aec->f; rc = 0; +end: + return (rc); +} + +static PyObject *gaekmeth_enc(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "msz", "tsz", 0 }; + const gaead_key *k = GAEADKEY_K(me); + gaead_enc *e; + PyObject *rc = 0; + char *n; Py_ssize_t nsz; + PyObject *hszobj = Py_None, *mszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, msz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|OOO:enc", KWLIST, + &n, &nsz, &hszobj, &mszobj, &tszobj)) + goto end; + if (check_aead_encdec(k->ops->c, &f, nsz, + hszobj, &hsz, mszobj, &msz, tszobj, &tsz)) + goto end; + e = GAEAD_ENC(GAEADKEY_K(me), n, nsz, hsz, msz, tsz); + if (!e) VALERR("bad aead parameter combination"); + rc = gaeadenc_pywrap((PyObject *)GCAEAD_ENC(me->ob_type), + e, f, hsz, msz, tsz); +end: + return (rc); +} + +static PyObject *gaekmeth_dec(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "csz", "tsz", 0 }; + const gaead_key *k = GAEADKEY_K(me); + gaead_dec *d; + PyObject *rc = 0; + char *n; Py_ssize_t nsz; + PyObject *hszobj = Py_None, *cszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, csz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|OOO:dec", KWLIST, + &n, &nsz, &hszobj, &cszobj, &tszobj)) + goto end; + if (check_aead_encdec(k->ops->c, &f, nsz, + hszobj, &hsz, cszobj, &csz, tszobj, &tsz)) + goto end; + d = GAEAD_DEC(GAEADKEY_K(me), n, nsz, hsz, csz, tsz); + if (!d) VALERR("bad aead parameter combination"); + rc = gaeaddec_pywrap((PyObject *)GCAEAD_DEC(me->ob_type), + d, f, hsz, csz, tsz); +end: + return (rc); +} + +static PyMethodDef gaeadkey_pymethods[] = { +#define METHNAME(name) gaekmeth_##name + METH (aad, "KEY.aad() -> AAD") + KWMETH(enc, "KEY.enc(NONCE, [hsz], [msz], [tsz]) -> ENC") + KWMETH(dec, "KEY.dec(NONCE, [hsz], [csz], [tsz]) -> DEC") +#undef METHNAME + { 0 } +}; + +PyObject *gaeadaad_pywrap(PyObject *cobj, gaead_aad *a, + unsigned f, size_t hsz) +{ + gaeadaad_pyobj *ga; + + assert(cobj); Py_INCREF(cobj); + ga = PyObject_NEW(gaeadaad_pyobj, (PyTypeObject *)cobj); + ga->a = a; ga->f = f; ga->hsz = hsz; ga->hlen = 0; + return ((PyObject *)ga); +} + +static void gaeadaad_pydealloc(PyObject *me) +{ + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + + if (ga->a) GAEAD_DESTROY(ga->a); + Py_DECREF(me->ob_type); FREEOBJ(me); +} + +static int gaea_check(PyObject *me) +{ + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + int rc = -1; + + if ((ga->f&AEADF_DEAD) || !ga->a) VALERR("aad object no longer active"); + rc = 0; +end: + return (rc); +} + +static void gaea_invalidate(gaeadaad_pyobj *ga) + { if (ga) ga->f |= AEADF_DEAD; } + +static void gaea_sever(gaeadaad_pyobj **ga_inout) +{ + gaeadaad_pyobj *ga = *ga_inout; + if (ga) { ga->f |= AEADF_DEAD; ga->a = 0; Py_DECREF(ga); *ga_inout = 0; } +} + +static PyObject *gaeaget_hsz(PyObject *me, void *hunoz) +{ + if (gaea_check(me)) return (0); + else if (GAEADAAD_F(me)&AEADF_PCHSZ) return getulong(GAEADAAD_HSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaeaget_hlen(PyObject *me, void *hunoz) + { return (gaea_check(me) ? 0 : getulong(GAEADAAD_HLEN(me))); } + +static PyGetSetDef gaeadaad_pygetset[] = { +#define GETSETNAME(op, name) gaea##op##_##name + GET (hsz, "AAD.hsz -> precommitted header length or `None'") + GET (hlen, "AAD.hlen -> header length so far") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaeameth_copy(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, ":copy")) goto end; + if (gaea_check(me)) goto end; + if (GAEADAAD_F(me)&AEADF_AADNDEP) + VALERR("can't duplicate nonce-dependent aad"); + rc = gaeadaad_pywrap((PyObject *)me->ob_type, + GAEAD_DUP(GAEADAAD_A(me)), 0, 0); +end: + return (rc); +} + +static int gaeadaad_hash(PyObject *me, const void *h, size_t hsz) +{ + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + int rc = -1; + + if (gaea_check(me)) goto end; + if ((ga->f&AEADF_NOAAD) && hsz) + VALERR("header data not permitted"); + if ((ga->f&AEADF_PCHSZ) && hsz > ga->hsz - ga->hlen) + VALERR("too large for precommitted header length"); + GAEAD_HASH(ga->a, h, hsz); ga->hlen += hsz; + rc = 0; +end: + return (rc); +} + + +static PyObject *gaeameth_hash(PyObject *me, PyObject *arg) +{ + char *h; Py_ssize_t hsz; + + if (!PyArg_ParseTuple(arg, "s#:hash", &h, &hsz)) return (0); + if (gaeadaad_hash(me, h, hsz)) return (0); + RETURN_ME; +} + +#define GAEAMETH_HASHU_(n, W, w) \ + static PyObject *gaeameth_hashu##w(PyObject *me, PyObject *arg) \ + { \ + uint##n x; octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) return (0); \ + STORE##W(b, x); if (gaeadaad_hash(me, b, sizeof(b))) return (0); \ + RETURN_ME; \ + } +DOUINTCONV(GAEAMETH_HASHU_) + +#define GAEAMETH_HASHBUF_(n, W, w) \ + static PyObject *gaeameth_hashbuf##w(PyObject *me, PyObject *arg) \ + { \ + char *p; Py_ssize_t sz; octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "s#:hashbuf" #w, &p, &sz)) goto end; \ + if (sz > MASK##n) TYERR("string too long"); \ + STORE##W(b, sz); if (gaeadaad_hash(me, b, sizeof(b))) goto end; \ + if (gaeadaad_hash(me, p, sz)) goto end; \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(GAEAMETH_HASHBUF_) + +static PyObject *gaeameth_hashstrz(PyObject *me, PyObject *arg) +{ + char *p; + if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); + if (gaeadaad_hash(me, p, strlen(p) + 1)) return (0); + RETURN_ME; +} + +static PyMethodDef gaeadaad_pymethods[] = { +#define METHNAME(name) gaeameth_##name + METH (copy, "AAD.copy() -> AAD'") + METH (hash, "AAD.hash(H)") +#define METHU_(n, W, w) METH(hashu##w, "AAD.hashu" #w "(WORD)") + DOUINTCONV(METHU_) +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "AAD.hashbuf" #w "(BYTES)") + DOUINTCONV(METHBUF_) +#undef METHBUF_ + METH (hashstrz, "AAD.hashstrz(STRING)") +#undef METHNAME + { 0 } +}; + +PyObject *gaeadenc_pywrap(PyObject *cobj, gaead_enc *e, unsigned f, + size_t hsz, size_t msz, size_t tsz) +{ + gaeadenc_pyobj *ge; + + assert(cobj); Py_INCREF(cobj); + ge = PyObject_NEW(gaeadenc_pyobj, (PyTypeObject *)cobj); + ge->e = e; ge->f = f; ge->hsz = hsz; ge->msz = msz; ge->tsz = tsz; + ge->aad = 0; ge->mlen = 0; + return ((PyObject *)ge); +} + +static void gaeadenc_pydealloc(PyObject *me) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + + gaea_sever(&ge->aad); GAEAD_DESTROY(ge->e); + Py_DECREF(me->ob_type); FREEOBJ(me); +} + +static PyObject *gaeeget_hsz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCHSZ) return getulong(GAEADENC_HSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaeeget_msz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCMSZ) return getulong(GAEADENC_MSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaeeget_tsz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCTSZ) return getulong(GAEADENC_TSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaeeget_mlen(PyObject *me, void *hunoz) + { return getulong(GAEADENC_MLEN(me)); } + +static PyGetSetDef gaeadenc_pygetset[] = { +#define GETSETNAME(op, name) gaee##op##_##name + GET (hsz, "ENC.hsz -> precommitted header length or `None'") + GET (msz, "ENC.msz -> precommitted message length or `None'") + GET (tsz, "ENC.tsz -> precommitted tag length or `None'") + GET (mlen, "ENC.mlen -> message length so far") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaeemeth_aad(PyObject *me, PyObject *arg) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, ":aad")) return (0); + if (!(ge->f&AEADF_AADNDEP)) + rc = gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(ge->ob_type)->aad, + GAEAD_AAD(ge->e), 0, 0); + else { + if ((ge->f&AEADF_AADFIRST) && ge->mlen) + VALERR("too late for aad"); + if (!ge->aad) + ge->aad = (gaeadaad_pyobj *) + gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(ge->ob_type)->aad, + GAEAD_AAD(ge->e), ge->f&AEADF_PCHSZ, ge->hsz); + Py_INCREF(ge->aad); + rc = (PyObject *)ge->aad; + } +end: + return (rc); +} + +static PyObject *gaeemeth_reinit(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "msz", "tsz", 0 }; + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + char *n; Py_ssize_t nsz; + PyObject *hszobj = Py_None, *mszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, msz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|OOO:enc", KWLIST, + &n, &nsz, &hszobj, &mszobj, &tszobj)) + goto end; + if (check_aead_encdec(ge->e->ops->c, &f, nsz, + hszobj, &hsz, mszobj, &msz, tszobj, &tsz)) + goto end; + if (GAEAD_REINIT(ge->e, n, nsz, hsz, msz, tsz)) + VALERR("bad aead parameter combination"); + gaea_sever(&ge->aad); + ge->f = f; ge->hsz = hsz; ge->msz = msz; ge->tsz = tsz; +end: + return (0); +} + +static PyObject *gaeemeth_encrypt(PyObject *me, PyObject *arg) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + char *m; Py_ssize_t msz; + char *c = 0; size_t csz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, "s#:encrypt", &m, &msz)) goto end; + if (ge->f&AEADF_AADFIRST) { + if ((ge->f&AEADF_PCHSZ) && (ge->aad ? ge->aad->hlen : 0) != ge->hsz) + VALERR("header doesn't match precommitted length"); + gaea_invalidate(ge->aad); + } + if ((ge->f&AEADF_PCMSZ) && msz > ge->msz - ge->mlen) + VALERR("too large for precommitted message length"); + csz = msz + ge->e->ops->c->bufsz; c = xmalloc(csz); buf_init(&b, c, csz); + err = GAEAD_ENCRYPT(ge->e, m, msz, &b); assert(!err); (void)err; + buf_flip(&b); rc = bytestring_pywrapbuf(&b); ge->mlen += msz; +end: + xfree(c); + return (rc); +} + +static PyObject *gaeemeth_done(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "tsz", "aad", 0 }; + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + PyObject *aad = Py_None; + char *c = 0; size_t csz; buf b; + PyObject *tszobj = Py_None; PyObject *tag; size_t tsz; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|OO:done", KWLIST, + &tszobj, &aad)) + goto end; + if (tszobj != Py_None && !convszt(tszobj, &tsz)) goto end; + if (aad != Py_None && + !PyObject_TypeCheck(aad, + (PyTypeObject *)GCAEADENC_KEY(me->ob_type)->aad)) + TYERR("wanted aad"); + if ((ge->f&AEADF_AADNDEP) && aad != Py_None && aad != (PyObject *)ge->aad) + VALERR("mismatched aad"); + if ((ge->f&AEADF_PCHSZ) && + (aad == Py_None ? 0 : GAEADAAD_HLEN(aad)) != ge->hsz) + VALERR("header doesn't match precommitted length"); + if ((ge->f&AEADF_PCMSZ) && ge->mlen != ge->msz) + VALERR("message doesn't match precommitted length"); + if (tszobj == Py_None) { + if (ge->f&AEADF_PCTSZ) tsz = ge->tsz; + else tsz = keysz(0, ge->e->ops->c->tagsz); + } else { + if ((ge->f&AEADF_PCTSZ) && tsz != ge->tsz) + VALERR("tag length doesn't match precommitted value"); + if (keysz(tsz, ge->e->ops->c->tagsz) != tsz) VALERR("bad tag length"); + } + csz = ge->e->ops->c->bufsz; c = xmalloc(csz); buf_init(&b, c, csz); + tag = bytestring_pywrap(0, tsz); + err = GAEAD_DONE(ge->e, aad == Py_None ? 0 : GAEADAAD_A(aad), &b, + PyString_AS_STRING(tag), tsz); + assert(!err); (void)err; + buf_flip(&b); rc = Py_BuildValue("NN", bytestring_pywrapbuf(&b), tag); +end: + xfree(c); + return (rc); +} + +static PyMethodDef gaeadenc_pymethods[] = { +#define METHNAME(name) gaeemeth_##name + METH (aad, "ENC.aad() -> AAD") + KWMETH(reinit, "ENC.reinit(NONCE, [hsz], [msz], [tsz])") + METH (encrypt, "ENC.encrypt(MSG) -> CT") + KWMETH(done, "ENC.done([tsz], [aad]) -> CT, TAG") +#undef METHNAME + { 0 } +}; + +PyObject *gaeaddec_pywrap(PyObject *cobj, gaead_dec *d, unsigned f, + size_t hsz, size_t csz, size_t tsz) +{ + gaeaddec_pyobj *gd; + assert(cobj); Py_INCREF(cobj); + gd = PyObject_NEW(gaeaddec_pyobj, (PyTypeObject *)cobj); + gd->d = d; gd->f = f; gd->hsz = hsz; gd->csz = csz; gd->tsz = tsz; + gd->aad = 0; gd->clen = 0; + return ((PyObject *)gd); +} + +static void gaeaddec_pydealloc(PyObject *me) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + + gaea_sever(&gd->aad); GAEAD_DESTROY(GAEADDEC_D(me)); + Py_DECREF(me->ob_type); FREEOBJ(me); +} + +static PyObject *gaedget_hsz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCHSZ) return getulong(GAEADDEC_HSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_csz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCMSZ) return getulong(GAEADDEC_CSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_tsz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCTSZ) return getulong(GAEADDEC_TSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_clen(PyObject *me, void *hunoz) + { return getulong(GAEADDEC_CLEN(me)); } + +static PyGetSetDef gaeaddec_pygetset[] = { +#define GETSETNAME(op, name) gaed##op##_##name + GET (hsz, "DEC.hsz -> precommitted header length or `None'") + GET (csz, "DEC.csz -> precommitted ciphertext length or `None'") + GET (tsz, "DEC.tsz -> precommitted tag length or `None'") + GET (clen, "DEC.clen -> ciphertext length so far") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaedmeth_aad(PyObject *me, PyObject *arg) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + + if (!PyArg_ParseTuple(arg, ":aad")) return (0); + if (!(gd->f&AEADF_AADNDEP)) + return (gaeadaad_pywrap((PyObject *)GCAEADDEC_KEY(gd->ob_type)->aad, + GAEAD_AAD(gd->d), 0, 0)); + else { + if (!gd->aad) + gd->aad = (gaeadaad_pyobj *) + gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(gd->ob_type)->aad, + GAEAD_AAD(gd->d), gd->f&AEADF_PCHSZ, gd->hsz); + Py_INCREF(gd->aad); + return ((PyObject *)gd->aad); + } +} + +static PyObject *gaedmeth_reinit(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "csz", "tsz", 0 }; + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + char *n; Py_ssize_t nsz; + PyObject *hszobj = Py_None, *cszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, csz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|OOO:enc", KWLIST, + &n, &nsz, &hszobj, &cszobj, &tszobj)) + goto end; + if (check_aead_encdec(gd->d->ops->c, &f, nsz, + hszobj, &hsz, cszobj, &csz, tszobj, &tsz)) + goto end; + if (GAEAD_REINIT(gd->d, n, nsz, hsz, csz, tsz)) + VALERR("bad aead parameter combination"); + gaea_sever(&gd->aad); + gd->f = f; gd->hsz = hsz; gd->csz = csz; gd->tsz = tsz; +end: + return (0); +} + +static PyObject *gaedmeth_decrypt(PyObject *me, PyObject *arg) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + char *c; Py_ssize_t csz; + char *m = 0; size_t msz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, "s#:decrypt", &c, &csz)) goto end; + if (gd->f&AEADF_AADFIRST) { + if ((gd->f&AEADF_PCHSZ) && (gd->aad ? gd->aad->hlen : 0) != gd->hsz) + VALERR("header doesn't match precommitted length"); + gaea_invalidate(gd->aad); + } + if ((gd->f&AEADF_PCMSZ) && csz > gd->csz - gd->clen) + VALERR("too large for precommitted message length"); + msz = csz + gd->d->ops->c->bufsz; m = xmalloc(msz); buf_init(&b, m, msz); + err = GAEAD_DECRYPT(gd->d, c, csz, &b); assert(!err); (void)err; + buf_flip(&b); rc = bytestring_pywrapbuf(&b); gd->clen += csz; +end: + xfree(m); + return (rc); +} + +static PyObject *gaedmeth_done(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "tag", "aad", 0 }; + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + PyObject *aad = Py_None; + char *t; Py_ssize_t tsz; + char *m = 0; size_t msz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O:done", KWLIST, + &t, &tsz, &aad)) + goto end; + if (aad != Py_None && + !PyObject_TypeCheck(aad, + (PyTypeObject *)GCAEADENC_KEY(me->ob_type)->aad)) + TYERR("wanted aad"); + if ((gd->f&AEADF_AADNDEP) && aad != Py_None && aad != (PyObject *)gd->aad) + VALERR("mismatched aad"); + if ((gd->f&AEADF_PCHSZ) && + (aad == Py_None ? 0 : GAEADAAD_HLEN(aad)) != gd->hsz) + VALERR("header doesn't match precommitted length"); + if ((gd->f&AEADF_PCMSZ) && gd->clen != gd->csz) + VALERR("message doesn't match precommitted length"); + if ((gd->f&AEADF_PCTSZ) && tsz != gd->tsz) + VALERR("tag length doesn't match precommitted value"); + if (keysz(tsz, gd->d->ops->c->tagsz) != tsz) VALERR("bad tag length"); + msz = gd->d->ops->c->bufsz; m = xmalloc(msz); buf_init(&b, m, msz); + err = GAEAD_DONE(gd->d, aad == Py_None ? 0 : GAEADAAD_A(aad), &b, t, tsz); + assert(err >= 0); + if (!err) VALERR("decryption failed"); + buf_flip(&b); rc = bytestring_pywrapbuf(&b); +end: + xfree(m); + return (rc); +} + +static PyMethodDef gaeaddec_pymethods[] = { +#define METHNAME(name) gaedmeth_##name + METH (aad, "DEC.aad() -> AAD") + KWMETH(reinit, "DEC.reinit(NONCE, [hsz], [csz], [tsz])") + METH (decrypt, "DEC.decrypt(CT) -> MSG") + KWMETH(done, "DEC.done(TAG, [aad]) -> MSG | None") +#undef METHNAME + { 0 } +}; + +static PyTypeObject gcaead_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GCAEAD", /* @tp_name@ */ + sizeof(gcaead_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption (key) metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + gcaead_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gaeadkey_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEKey", /* @tp_name@ */ + sizeof(gaeadkey_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadkey_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption key.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + gaeadkey_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gcaeadaad_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEAADClass", /* @tp_name@ */ + sizeof(gcaeadaad_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption additional-data hash metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gaeadaad_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEAAD", /* @tp_name@ */ + sizeof(gaeadaad_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadaad_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption AAD hash.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + gaeadaad_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + gaeadaad_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gcaeadenc_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEEncClass", /* @tp_name@ */ + sizeof(gcaeadenc_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption operation metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gaeadenc_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEEnc", /* @tp_name@ */ + sizeof(gaeadenc_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadenc_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated encryption operation.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + gaeadenc_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + gaeadenc_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gcaeaddec_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEDecClass", /* @tp_name@ */ + sizeof(gcaeaddec_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated decryption operation metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject gaeaddec_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "GAEDec", /* @tp_name@ */ + sizeof(gaeaddec_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeaddec_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Authenticated decryption operation.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + gaeaddec_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + gaeaddec_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + /*----- Hash functions ----------------------------------------------------*/ PyTypeObject *gchash_pytype, *ghash_pytype; @@ -2380,6 +3456,14 @@ void algorithms_pyinit(void) INITTYPE(keyszset, keysz); INITTYPE(gccipher, type); INITTYPE(gcipher, root); + INITTYPE(gcaead, type); + INITTYPE(gaeadkey, root); + INITTYPE(gcaeadaad, type); + INITTYPE(gaeadaad, root); + INITTYPE(gcaeadenc, type); + INITTYPE(gaeadenc, root); + INITTYPE(gcaeaddec, type); + INITTYPE(gaeaddec, root); INITTYPE(gchash, type); INITTYPE(ghash, root); INITTYPE(gcmac, type); @@ -2398,6 +3482,7 @@ void algorithms_pyinit(void) } GEN(gcciphers, cipher) +GEN(gcaeads, aead) GEN(gchashes, hash) GEN(gcmacs, mac) #define gcprp prpinfo @@ -2413,6 +3498,15 @@ void algorithms_pyinsert(PyObject *mod) INSERT("GCCipher", gccipher_pytype); INSERT("GCipher", gcipher_pytype); INSERT("gcciphers", gcciphers()); + INSERT("GCAEAD", gcaead_pytype); + INSERT("GAEKey", gaeadkey_pytype); + INSERT("GAEAADClass", gcaeadaad_pytype); + INSERT("GAEAAD", gaeadaad_pytype); + INSERT("GAEEncClass", gcaeadenc_pytype); + INSERT("GAEEnc", gaeadenc_pytype); + INSERT("GAEDecClass", gcaeaddec_pytype); + INSERT("GAEDec", gaeaddec_pytype); + INSERT("gcaeads", gcaeads()); INSERT("GCHash", gchash_pytype); INSERT("GHash", ghash_pytype); INSERT("gchashes", d = gchashes()); diff --git a/algorithms.py b/algorithms.py index 7f31e60..4b65ce9 100644 --- a/algorithms.py +++ b/algorithms.py @@ -26,6 +26,7 @@ serpent noekeon pmodes = ''' ecb cbc cfb ofb counter cmac pmac1 +ccm eax gcm ocb1 ocb3 '''.split() streamciphers = ''' rc4 seal diff --git a/catacomb-python.h b/catacomb-python.h index d68026d..df29099 100644 --- a/catacomb-python.h +++ b/catacomb-python.h @@ -61,6 +61,7 @@ #include #include +#include #include #include #include @@ -517,6 +518,116 @@ extern PyTypeObject *gcipher_pytype; extern PyObject *gcipher_pywrap(PyObject *, gcipher *); extern int convgcipher(PyObject *, void *); +typedef struct gcaead_pyobj { + PyHeapTypeObject ty; + gcaead *aec; + struct gcaeadaad_pyobj *aad; + struct gcaeadenc_pyobj *enc; + struct gcaeaddec_pyobj *dec; +} gcaead_pyobj; + +extern PyTypeObject *gcaead_pytype; +#define GCAEAD_PYCHECK(o) PyObject_TypeCheck((o), gcaead_pytype) +#define GCAEAD_AEC(o) (((gcaead_pyobj *)(o))->aec) +#define GCAEAD_AAD(o) (((gcaead_pyobj *)(o))->aad) +#define GCAEAD_ENC(o) (((gcaead_pyobj *)(o))->enc) +#define GCAEAD_DEC(o) (((gcaead_pyobj *)(o))->dec) +extern PyObject *gcaead_pywrap(gcaead *); +extern int convgcaead(PyObject *, void *); + +typedef struct gaeadkey_pyobj { + PyObject_HEAD + gaead_key *k; +} gaeadkey_pyobj; + +extern PyTypeObject *gaeadkey_pytype; +#define GAEADKEY_PYCHECK(o) PyObject_TypeCheck((o), gaeadkey_pytype) +#define GAEADKEY_K(o) (((gaeadkey_pyobj *)(o))->k) +extern PyObject *gaeadkey_pywrap(PyObject *, gaead_key *); +extern int convgaeadkey(PyObject *, void *); + +typedef struct gcaeadaad_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeadaad_pyobj; +#define GCAEADAAD_KEY(o) (((gcaeadaad_pyobj *)(o))->key) +extern PyTypeObject *gcaeadaad_pytype; + +typedef struct gaeadaad_pyobj { + PyObject_HEAD + gaead_aad *a; + unsigned f; +#define AEADF_DEAD 32768u + size_t hsz, hlen; +} gaeadaad_pyobj; + +extern PyTypeObject *gaeadaad_pytype; +#define GAEADAAD_PYCHECK(o) PyObject_TypeCheck((o), gaeadaad_pytype) +#define GAEADAAD_A(o) (((gaeadaad_pyobj *)(o))->a) +#define GAEADAAD_F(o) (((gaeadaad_pyobj *)(o))->f) +#define GAEADAAD_HSZ(o) (((gaeadaad_pyobj *)(o))->hsz) +#define GAEADAAD_HLEN(o) (((gaeadaad_pyobj *)(o))->hlen) +extern PyObject *gaeadaad_pywrap(PyObject *, gaead_aad *, unsigned, size_t); +extern int convgaeadaad(PyObject *, void *); + +typedef struct gcaeadenc_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeadenc_pyobj; +#define GCAEADENC_KEY(o) (((gcaeadenc_pyobj *)(o))->key) +extern PyTypeObject *gcaeadenc_pytype; + +typedef struct gaeadenc_pyobj { + PyObject_HEAD + gaead_enc *e; + gaeadaad_pyobj *aad; + unsigned f; + size_t hsz, msz, tsz; + size_t mlen; +} gaeadenc_pyobj; + +extern PyTypeObject *gaeadenc_pytype; +#define GAEADENC_PYCHECK(o) PyObject_TypeCheck((o), gaeadenc_pytype) +#define GAEADENC_AAD(o) (((gaeadenc_pyobj *)(o))->aad) +#define GAEADENC_E(o) (((gaeadenc_pyobj *)(o))->e) +#define GAEADENC_F(o) (((gaeadenc_pyobj *)(o))->f) +#define GAEADENC_HSZ(o) (((gaeadenc_pyobj *)(o))->hsz) +#define GAEADENC_MSZ(o) (((gaeadenc_pyobj *)(o))->msz) +#define GAEADENC_TSZ(o) (((gaeadenc_pyobj *)(o))->tsz) +#define GAEADENC_MLEN(o) (((gaeadenc_pyobj *)(o))->mlen) +extern PyObject *gaeadenc_pywrap(PyObject *, gaead_enc *, unsigned, + size_t, size_t, size_t); +extern int convgaeadenc(PyObject *, void *); + +typedef struct gcaeaddec_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeaddec_pyobj; +#define GCAEADDEC_KEY(o) (((gcaeaddec_pyobj *)(o))->key) +extern PyTypeObject *gcaeaddec_pytype; + +typedef struct gaeaddec_pyobj { + PyObject_HEAD + gaead_dec *d; + gaeadaad_pyobj *aad; + unsigned f; + size_t hsz, csz, tsz; + size_t clen; +} gaeaddec_pyobj; + +extern PyTypeObject *gaeaddec_pytype; +#define GAEADDEC_PYCHECK(o) PyObject_TypeCheck((o), gaeaddec_pytype) +#define GAEADDEC_AAD(o) (((gaeaddec_pyobj *)(o))->aad) +#define GAEADDEC_D(o) (((gaeaddec_pyobj *)(o))->d) +#define GAEADDEC_F(o) (((gaeaddec_pyobj *)(o))->f) +#define GAEADDEC_HSZ(o) (((gaeaddec_pyobj *)(o))->hsz) +#define GAEADDEC_CSZ(o) (((gaeaddec_pyobj *)(o))->csz) +#define GAEADDEC_TSZ(o) (((gaeaddec_pyobj *)(o))->tsz) +#define GAEADDEC_CLEN(o) (((gaeaddec_pyobj *)(o))->clen) +extern PyObject *gaeaddec_pywrap(PyObject *, gaead_dec *, unsigned, + size_t, size_t, size_t); +extern int convgaeaddec(PyObject *, void *); + typedef struct gchash_pyobj { PyHeapTypeObject ty; gchash *ch; diff --git a/catacomb.c b/catacomb.c index f9e8587..b596b5e 100644 --- a/catacomb.c +++ b/catacomb.c @@ -50,6 +50,8 @@ static const struct nameval consts[] = { C(ED25519_KEYSZ), C(ED25519_PUBSZ), C(ED25519_SIGSZ), C(ED25519_MAXPERSOSZ), C(ED448_KEYSZ), C(ED448_PUBSZ), C(ED448_SIGSZ), C(ED448_MAXPERSOSZ), + C(AEADF_PCHSZ), C(AEADF_PCMSZ), C(AEADF_PCTSZ), + C(AEADF_AADNDEP), C(AEADF_AADFIRST), C(AEADF_NOAAD), #define ENTRY(tag, val, str) C(KERR_##tag), KEY_ERRORS(ENTRY) #undef ENTRY diff --git a/catacomb/__init__.py b/catacomb/__init__.py index bb7703e..8038815 100644 --- a/catacomb/__init__.py +++ b/catacomb/__init__.py @@ -102,7 +102,7 @@ def _init(): for j in b: if j[:plen] == pre: setattr(c, j[plen:], classmethod(b[j])) - for i in [gcciphers, gchashes, gcmacs, gcprps]: + for i in [gcciphers, gcaeads, gchashes, gcmacs, gcprps]: for c in i.itervalues(): d[_fixname(c.name)] = c for c in gccrands.itervalues(): @@ -184,6 +184,27 @@ ByteString.__hash__ = str.__hash__ bytes = ByteString.fromhex ###-------------------------------------------------------------------------- +### Symmetric encryption. + +class _tmp: + def encrypt(me, n, m, tsz = None, h = ByteString('')): + if tsz is None: tsz = me.__class__.tagsz.default + e = me.enc(n, len(h), len(m), tsz) + if not len(h): a = None + else: a = e.aad().hash(h) + c0 = e.encrypt(m) + c1, t = e.done(aad = a) + return c0 + c1, t + def decrypt(me, n, c, t, h = ByteString('')): + d = me.dec(n, len(h), len(c), len(t)) + if not len(h): a = None + else: a = d.aad().hash(h) + m = d.decrypt(c) + m += d.done(t, aad = a) + return m +_augment(GAEKey, _tmp) + +###-------------------------------------------------------------------------- ### Hashing. class _tmp: @@ -287,21 +308,12 @@ class KMAC256 (KMAC): _SHAKE = Shake256; _TAGSZ = 32 ### NaCl `secretbox'. def secret_box(k, n, m): - E = xsalsa20(k).setiv(n) - r = E.enczero(poly1305.keysz.default) - s = E.enczero(poly1305.masksz) - y = E.encrypt(m) - t = poly1305(r)(s).hash(y).done() + y, t = salsa20_naclbox(k).encrypt(n, m) return t + y def secret_unbox(k, n, c): - E = xsalsa20(k).setiv(n) - r = E.enczero(poly1305.keysz.default) - s = E.enczero(poly1305.masksz) - y = c[poly1305.tagsz:] - if not poly1305(r)(s).hash(y).check(c[0:poly1305.tagsz]): - raise ValueError, 'decryption failed' - return E.decrypt(c[poly1305.tagsz:]) + tsz = poly1305.tagsz + return salsa20_naclbox(k).decrypt(n, c[tsz:], c[0:tsz]) ###-------------------------------------------------------------------------- ### Multiprecision integers and binary polynomials. diff --git a/debian/control b/debian/control index 6b3942d..3304404 100644 --- a/debian/control +++ b/debian/control @@ -5,7 +5,7 @@ XS-Python-Version: >= 2.6, << 2.8 Maintainer: Mark Wooding Build-Depends: debhelper (>= 9), pkg-config, python (>= 2.6.6-3~), python-all-dev, - mlib-dev (>= 2.2.2.1), catacomb-dev (>= 2.4.0) + mlib-dev (>= 2.2.2.1), catacomb-dev (>= 2.4.2+70) Standards-Version: 3.8.0 Package: python-catacomb diff --git a/setup.py b/setup.py index b5e3fcd..a5a60e2 100755 --- a/setup.py +++ b/setup.py @@ -3,7 +3,7 @@ import distutils.core as DC import mdwsetup as MS -MS.pkg_config('catacomb', '2.4.2+23') +MS.pkg_config('catacomb', '2.4.2-70') MS.pkg_config('mLib', '2.0.4') cat = DC.Extension('catacomb._base', -- 2.11.0