progs/perftest.c: Use from Glibc syscall numbers.
[catacomb] / symm / hmac-def.h
CommitLineData
79ba130c 1/* -*-c-*-
2 *
79ba130c 3 * Definitions for HMAC and NMAC
4 *
5 * (c) 1999 Straylight/Edgeware
6 */
7
45c0fd36 8/*----- Licensing notice --------------------------------------------------*
79ba130c 9 *
10 * This file is part of Catacomb.
11 *
12 * Catacomb is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU Library General Public License as
14 * published by the Free Software Foundation; either version 2 of the
15 * License, or (at your option) any later version.
45c0fd36 16 *
79ba130c 17 * Catacomb is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU Library General Public License for more details.
45c0fd36 21 *
79ba130c 22 * You should have received a copy of the GNU Library General Public
23 * License along with Catacomb; if not, write to the Free
24 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
25 * MA 02111-1307, USA.
26 */
27
79ba130c 28#ifndef CATACOMB_HMAC_DEF_H
29#define CATACOMB_HMAC_DEF_H
30
31#ifdef __cplusplus
32 extern "C" {
33#endif
34
35/*----- Header files ------------------------------------------------------*/
36
28ef1f45 37#include <assert.h>
79ba130c 38#include <stdlib.h>
39#include <string.h>
40
41#include <mLib/bits.h>
42#include <mLib/sub.h>
43
28ef1f45 44#ifndef CATACOMB_ARENA_H
45# include "arena.h"
46#endif
47
79ba130c 48#ifndef CATACOMB_GMAC_H
49# include "gmac.h"
50#endif
51
52#ifndef CATACOMB_PARANOIA_H
53# include "paranoia.h"
54#endif
55
56/*----- Macros ------------------------------------------------------------*/
57
58/* --- @HMAC_DEF@ --- *
59 *
60 * Arguments: @PRE@, @pre@ = prefixes for the underlying hash function
61 *
62 * Use: Creates implementations for the HMAC and NMAC functions.
63 */
64
aaae9cab
MW
65#define HMAC_DEF(PRE, pre) HMAC_DEFX(PRE, pre, #pre, #pre)
66#define HMAC_DEFX(PRE, pre, name, fname) \
79ba130c 67 \
28ef1f45 68/* --- Useful constants --- */ \
69 \
c148759d 70const octet pre##_hmackeysz[] = \
b67d9ed1 71 { KSZ_ANY | KSZ_16BIT, PRE##_HASHSZ/256, PRE##_HASHSZ%256 }; \
c148759d 72const octet pre##_sslmackeysz[] = \
b67d9ed1 73 { KSZ_ANY | KSZ_16BIT, PRE##_HASHSZ/256, PRE##_HASHSZ%256 }; \
c148759d 74const octet pre##_nmackeysz[] = \
b67d9ed1 75 { KSZ_SET | KSZ_16BIT, 2*PRE##_HASHSZ/256, 2*PRE##_HASHSZ%256, 0, 0 }; \
28ef1f45 76 \
79ba130c 77/* --- @pre_nmacinit@ --- * \
78 * \
79 * Arguments: @pre_macctx *key@ = pointer to a MAC key object \
80 * @const void *ok@ = pointer to outer hash init vector \
81 * @const void *ik@ = pointer to inner hash init vector \
82 * \
83 * Returns: --- \
84 * \
85 * Use: Initializes a MAC key for doing NMAC hashing. \
86 */ \
87 \
88void pre##_nmacinit(pre##_mackey *key, const void *ok, const void *ik) \
89{ \
c850c0da 90 memcpy(key->ochain, ok, PRE##_STATESZ); \
91 memcpy(key->ichain, ik, PRE##_STATESZ); \
79ba130c 92 key->ocount = key->icount = 0; \
93} \
94 \
95/* --- @pre_hmacinit@ --- * \
96 * \
97 * Arguments: @pre_mackey *key@ = pointer to MAC key object \
98 * @const void *k@ = pointer to key to use \
99 * @size_t sz@ = size of key data \
100 * \
101 * Returns: --- \
102 * \
103 * Use: Initializes a MAC key for doing HMAC hashing. Keys \
104 * longer than the hash function's output size aren't very \
105 * useful, but are accepted. Keys longer than the hash's \
106 * block size are also accepted; they are hashed before \
107 * use, as specified in RFC2104. \
108 */ \
109 \
110void pre##_hmacinit(pre##_mackey *key, const void *k, size_t sz) \
111{ \
112 int i; \
113 const octet *kbuf = k; \
114 pre##_ctx ctx; \
94df4e8c 115 octet hbuf[PRE##_HASHSZ], buf[PRE##_BUFSZ]; \
79ba130c 116 \
117 if (sz > PRE##_BUFSZ) { \
118 pre##_init(&ctx); \
119 pre##_hash(&ctx, k, sz); \
94df4e8c
MW
120 pre##_done(&ctx, hbuf); \
121 kbuf = hbuf; \
79ba130c 122 sz = PRE##_HASHSZ; \
123 } \
124 \
125 pre##_init(&ctx); \
94df4e8c
MW
126 memset(buf, 0x5c, PRE##_BUFSZ); \
127 for (i = 0; i < sz; i++) buf[i] ^= kbuf[i]; \
128 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
129 key->ocount = pre##_state(&ctx, key->ochain); \
79ba130c 130 \
131 pre##_init(&ctx); \
94df4e8c
MW
132 memset(buf, 0x36, PRE##_BUFSZ); \
133 for (i = 0; i < sz; i++) buf[i] ^= kbuf[i]; \
134 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
135 key->icount = pre##_state(&ctx, key->ichain); \
79ba130c 136 \
79ba130c 137 BURN(ctx); \
138} \
139 \
36c67859 140/* --- @pre_sslmacinit@ --- * \
141 * \
142 * Arguments: @pre_mackey *key@ = pointer to MAC key object \
143 * @const void *k@ = pointer to key to use \
144 * @size_t sz@ = size of key data \
145 * \
146 * Returns: --- \
147 * \
148 * Use: Initializes a MAC key for doing hasing using the SSL3 \
149 * variant of HMAC. \
150 */ \
151 \
152void pre##_sslmacinit(pre##_mackey *key, const void *k, size_t sz) \
153{ \
36c67859 154 const octet *kbuf = k; \
155 pre##_ctx ctx; \
94df4e8c 156 octet hbuf[PRE##_HASHSZ], buf[PRE##_BUFSZ]; \
36c67859 157 \
158 if (sz > PRE##_BUFSZ) { \
159 pre##_init(&ctx); \
160 pre##_hash(&ctx, k, sz); \
94df4e8c
MW
161 pre##_done(&ctx, hbuf); \
162 kbuf = hbuf; \
36c67859 163 sz = PRE##_HASHSZ; \
164 } \
165 \
166 pre##_init(&ctx); \
94df4e8c
MW
167 memcpy(buf, kbuf, sz); \
168 memset(buf + sz, 0x5c, PRE##_BUFSZ - sz); \
169 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
170 key->ocount = pre##_state(&ctx, key->ochain); \
36c67859 171 \
172 pre##_init(&ctx); \
94df4e8c
MW
173 memcpy(buf, kbuf, sz); \
174 memset(buf + sz, 0x36, PRE##_BUFSZ - sz); \
175 pre##_hash(&ctx, buf, PRE##_BUFSZ); \
176 key->icount = pre##_state(&ctx, key->ichain); \
36c67859 177 \
36c67859 178 BURN(ctx); \
179} \
180 \
79ba130c 181/* --- @pre_macinit@ --- * \
182 * \
183 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
184 * @const pre_mackey *key@ = pointer to MAC key block \
185 * \
186 * Returns: --- \
187 * \
188 * Use: Instantiates a MAC context from a key block. \
189 */ \
190 \
191void pre##_macinit(pre##_macctx *ctx, const pre##_mackey *key) \
192{ \
c850c0da 193 memcpy(ctx->chain, key->ochain, PRE##_STATESZ); \
79ba130c 194 ctx->count = key->ocount; \
195 pre##_set(&ctx->ctx, key->ichain, key->icount); \
196} \
197 \
198/* --- @pre_machash@ --- * \
199 * \
200 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
201 * @const void *buf@ = pointer to buffer \
202 * @size_t sz@ = size of the buffer \
203 * \
204 * Returns: --- \
205 * \
206 * Use: Hashes a buffer. \
207 */ \
208 \
209void pre##_machash(pre##_macctx *ctx, const void *buf, size_t sz) \
0fee61eb 210 { pre##_hash(&ctx->ctx, buf, sz); } \
79ba130c 211 \
212/* --- @pre_macdone@ --- * \
213 * \
214 * Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
215 * @void *mac@ = pointer to buffer to receive MAC \
216 * \
217 * Returns: --- \
218 * \
219 * Use: Returns the result of a MAC computation. \
220 */ \
221 \
222void pre##_macdone(pre##_macctx *ctx, void *mac) \
223{ \
224 pre##_done(&ctx->ctx, mac); \
225 pre##_set(&ctx->ctx, ctx->chain, ctx->count); \
226 pre##_hash(&ctx->ctx, mac, PRE##_HASHSZ); \
227 pre##_done(&ctx->ctx, mac); \
228} \
229 \
230/* --- Generic MAC interface --- */ \
231 \
4dafd519 232static const gmac_ops gkops, gnkops, gsslkops; \
2a62e96d 233static const ghash_ops gops, gnops, gsslops; \
79ba130c 234 \
235typedef struct gkctx { \
236 gmac m; \
2a62e96d 237 const ghash_ops *gops; \
79ba130c 238 pre##_mackey k; \
239} gkctx; \
240 \
241typedef struct gctx { \
242 ghash h; \
243 pre##_macctx c; \
a351d052 244 octet buf[PRE##_HASHSZ]; \
79ba130c 245} gctx; \
246 \
247static ghash *gkinit(gmac *m) \
248{ \
249 gkctx *gk = (gkctx *)m; \
28ef1f45 250 gctx *g = S_CREATE(gctx); \
2a62e96d 251 g->h.ops = gk->gops; \
79ba130c 252 pre##_macinit(&g->c, &gk->k); \
253 return (&g->h); \
254} \
255 \
256static gmac *gkey(const void *k, size_t sz) \
257{ \
28ef1f45 258 gkctx *gk = S_CREATE(gkctx); \
79ba130c 259 gk->m.ops = &gkops; \
2a62e96d 260 gk->gops = &gops; \
79ba130c 261 pre##_hmacinit(&gk->k, k, sz); \
262 return (&gk->m); \
263} \
264 \
2a62e96d 265static gmac *gnkey(const void *k, size_t sz) \
266{ \
267 gkctx *gk = S_CREATE(gkctx); \
268 const octet *kk = k; \
269 assert(keysz(sz, pre##_nmackeysz) == sz); \
4dafd519 270 gk->m.ops = &gnkops; \
2a62e96d 271 gk->gops = &gnops; \
272 pre##_nmacinit(&gk->k, kk, kk + PRE##_STATESZ); \
273 return (&gk->m); \
274} \
275 \
36c67859 276static gmac *gsslkey(const void *k, size_t sz) \
277{ \
278 gkctx *gk = S_CREATE(gkctx); \
4dafd519 279 gk->m.ops = &gsslkops; \
2a62e96d 280 gk->gops = &gsslops; \
36c67859 281 pre##_sslmacinit(&gk->k, k, sz); \
282 return (&gk->m); \
283} \
284 \
79ba130c 285static void ghhash(ghash *h, const void *p, size_t sz) \
286{ \
287 gctx *g = (gctx *)h; \
288 pre##_machash(&g->c, p, sz); \
289} \
290 \
a351d052 291static octet *ghdone(ghash *h, void *buf) \
79ba130c 292{ \
293 gctx *g = (gctx *)h; \
a351d052 294 if (!buf) \
295 buf = g->buf; \
79ba130c 296 pre##_macdone(&g->c, buf); \
a351d052 297 return (buf); \
79ba130c 298} \
299 \
d2fdbc2c 300static ghash *ghcopy(ghash *h) \
301{ \
302 gctx *g = (gctx *)h; \
303 gctx *gg = S_CREATE(gctx); \
304 memcpy(gg, g, sizeof(gctx)); \
305 return (&gg->h); \
306} \
307 \
79ba130c 308static void ghdestroy(ghash *h) \
309{ \
310 gctx *g = (gctx *)h; \
28ef1f45 311 BURN(*g); \
312 S_DESTROY(g); \
79ba130c 313} \
314 \
315static void gkdestroy(gmac *m) \
316{ \
317 gkctx *gk = (gkctx *)m; \
28ef1f45 318 BURN(*gk); \
319 S_DESTROY(gk); \
320} \
321 \
322static ghash *ghinit(void) \
323{ \
324 assert(((void)"Attempt to instantiate an unkeyed MAC", 0)); \
325 return (0); \
79ba130c 326} \
327 \
2a62e96d 328const gcmac pre##_nmac = \
aaae9cab 329 { name "-nmac", PRE##_HASHSZ, pre##_nmackeysz, gnkey }; \
28ef1f45 330const gcmac pre##_hmac = \
aaae9cab 331 { name "-hmac", PRE##_HASHSZ, pre##_hmackeysz, gkey }; \
36c67859 332const gcmac pre##_sslmac = \
aaae9cab 333 { name "-sslmac", PRE##_HASHSZ, pre##_sslmackeysz, gsslkey }; \
28ef1f45 334static const gmac_ops gkops = { &pre##_hmac, gkinit, gkdestroy }; \
2a62e96d 335static const gmac_ops gnkops = { &pre##_nmac, gkinit, gkdestroy }; \
336static const gmac_ops gsslkops = { &pre##_sslmac, gkinit, gkdestroy }; \
aaae9cab 337static const gchash gch = { name "-hmac", PRE##_HASHSZ, ghinit }; \
79ba130c 338static const ghash_ops gops = \
d2fdbc2c 339 { &gch, ghhash, ghdone, ghdestroy, ghcopy }; \
aaae9cab 340static const gchash gnch = { name "-nmac", PRE##_HASHSZ, ghinit }; \
2a62e96d 341static const ghash_ops gnops = \
4dafd519 342 { &gnch, ghhash, ghdone, ghdestroy, ghcopy }; \
aaae9cab 343static const gchash gsslch = { name "-sslmac", PRE##_HASHSZ, ghinit }; \
2a62e96d 344static const ghash_ops gsslops = \
4dafd519 345 { &gsslch, ghhash, ghdone, ghdestroy, ghcopy }; \
79ba130c 346 \
aaae9cab
MW
347HMAC_TESTX(PRE, pre, name, fname)
348
349#define HMAC_TEST(PRE, pre) HMAC_TESTX(PRE, pre, #pre, #pre)
79ba130c 350
351/* --- @HMAC_TEST@ --- *
352 *
353 * Arguments: @PRE@, @pre@ = prefixes for hash-specfic definitions
354 *
355 * Use: Standard test rig for MAC functions.
356 */
357
358#ifdef TEST_RIG
359
360#include <stdio.h>
361
141c1284 362#include <mLib/macros.h>
79ba130c 363#include <mLib/dstr.h>
364#include <mLib/quis.h>
365#include <mLib/testrig.h>
366
aaae9cab 367#define HMAC_TESTX(PRE, pre, name, fname) \
79ba130c 368 \
369static int macverify(dstr *v) \
370{ \
371 pre##_macctx cctx; \
372 pre##_mackey ckey; \
373 int ok = 1; \
374 int i; \
375 octet *p; \
376 int szs[] = { 1, 7, 192, -1, 0 }, *ip; \
377 size_t csz; \
378 dstr d; \
379 \
380 dstr_create(&d); \
381 dstr_ensure(&d, PRE##_HASHSZ); \
382 d.len = PRE##_HASHSZ; \
383 \
384 pre##_hmacinit(&ckey, v[1].buf, v[1].len); \
385 \
386 for (ip = szs; *ip; ip++) { \
387 i = *ip; \
388 csz = v[0].len; \
389 if (i == -1) \
390 i = csz; \
391 if (i > csz) \
392 continue; \
393 p = (octet *)v[0].buf; \
394 pre##_macinit(&cctx, &ckey); \
395 while (csz) { \
396 if (i > csz) \
397 i = csz; \
398 pre##_machash(&cctx, p, i); \
399 p += i; \
400 csz -= i; \
401 } \
402 pre##_macdone(&cctx, d.buf); \
141c1284 403 if (MEMCMP(d.buf, !=, v[2].buf, PRE##_HASHSZ)) { \
79ba130c 404 printf("\nfail:\n\tstep = %i\n\tinput = `%s'\n\tkey = ", \
405 *ip, v[0].buf); \
406 type_hex.dump(&v[1], stdout); \
407 fputs("\n\texpected = ", stdout); \
408 type_hex.dump(&v[2], stdout); \
409 fputs("\n\tcomputed = ", stdout); \
410 type_hex.dump(&d, stdout); \
411 putchar('\n'); \
412 ok = 0; \
413 } \
414 } \
415 \
416 dstr_destroy(&d); \
417 return (ok); \
418} \
419 \
420static test_chunk macdefs[] = { \
aaae9cab 421 { name "-hmac", macverify, \
79ba130c 422 { &type_string, &type_hex, &type_hex, 0 } }, \
423 { 0, 0, { 0 } } \
424}; \
425 \
426int main(int argc, char *argv[]) \
427{ \
428 ego(argv[0]); \
aaae9cab 429 test_run(argc, argv, macdefs, SRCDIR"/t/" fname); \
79ba130c 430 return (0); \
431}
432
433#else
aaae9cab 434# define HMAC_TESTX(PRE, pre, name, fname)
79ba130c 435#endif
436
437/*----- That's all, folks -------------------------------------------------*/
438
439#ifdef __cplusplus
440 }
441#endif
442
443#endif