LCOV - code coverage report
Current view: top level - spdm_common_lib - libspdm_com_crypto_service.c (source / functions) Coverage Total Hit
Test: coverage.info Lines: 81.6 % 365 298
Test Date: 2026-10-01 20:56:25 Functions: 95.5 % 22 21
Branches: 70.6 % 201 142

             Branch data     Line data    Source code
       1                 :             : /**
       2                 :             :  *  Copyright Notice:
       3                 :             :  *  Copyright 2021-2026 DMTF. All rights reserved.
       4                 :             :  *  License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
       5                 :             :  **/
       6                 :             : 
       7                 :             : #include "internal/libspdm_common_lib.h"
       8                 :             : 
       9                 :          68 : uint8_t libspdm_slot_id_to_key_pair_id (
      10                 :             :     void *spdm_context,
      11                 :             :     uint8_t slot_id,
      12                 :             :     bool is_requester)
      13                 :             : {
      14                 :             :     libspdm_context_t *context;
      15                 :             : 
      16                 :          68 :     context = spdm_context;
      17   [ +  +  +  + ]:          68 :     if (slot_id == 0xFF || slot_id == 0xF) {
      18                 :           6 :         return 0;
      19                 :             :     }
      20         [ +  + ]:          62 :     if (is_requester) {
      21         [ +  - ]:          13 :         if (!context->connection_info.multi_key_conn_req) {
      22                 :          13 :             return 0;
      23                 :             :         }
      24                 :             :     } else {
      25         [ +  + ]:          49 :         if (!context->connection_info.multi_key_conn_rsp) {
      26                 :          47 :             return 0;
      27                 :             :         }
      28                 :             :     }
      29         [ -  + ]:           2 :     LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
      30                 :           2 :     return context->local_context.local_key_pair_id[slot_id];
      31                 :             : }
      32                 :             : 
      33                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
      34                 :             : void libspdm_get_peer_cert_chain_buffer(void *spdm_context,
      35                 :             :                                         uint8_t slot_id,
      36                 :             :                                         const void **cert_chain_buffer,
      37                 :             :                                         size_t *cert_chain_buffer_size)
      38                 :             : {
      39                 :             : 
      40                 :             :     libspdm_context_t *context;
      41                 :             : 
      42                 :             :     context = spdm_context;
      43                 :             : 
      44                 :             :     LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
      45                 :             : 
      46                 :             :     *cert_chain_buffer = context->connection_info.peer_used_cert_chain[slot_id].buffer;
      47                 :             :     *cert_chain_buffer_size = context->connection_info.peer_used_cert_chain[slot_id].buffer_size;
      48                 :             : }
      49                 :             : 
      50                 :             : void libspdm_get_peer_cert_chain_data(void *spdm_context,
      51                 :             :                                       uint8_t slot_id,
      52                 :             :                                       const void **cert_chain_data,
      53                 :             :                                       size_t *cert_chain_data_size)
      54                 :             : {
      55                 :             :     libspdm_context_t *context;
      56                 :             :     size_t hash_size;
      57                 :             : 
      58                 :             :     context = spdm_context;
      59                 :             :     hash_size = libspdm_get_hash_size(context->connection_info.algorithm.base_hash_algo);
      60                 :             : 
      61                 :             :     libspdm_get_peer_cert_chain_buffer(context, slot_id, cert_chain_data, cert_chain_data_size);
      62                 :             :     *cert_chain_data = (const uint8_t *)*cert_chain_data + sizeof(spdm_cert_chain_t) + hash_size;
      63                 :             :     *cert_chain_data_size = *cert_chain_data_size - (sizeof(spdm_cert_chain_t) + hash_size);
      64                 :             : }
      65                 :             : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
      66                 :             : 
      67                 :          50 : void libspdm_get_local_cert_chain_buffer(void *spdm_context,
      68                 :             :                                          uint8_t slot_id,
      69                 :             :                                          const void **cert_chain_buffer,
      70                 :             :                                          size_t *cert_chain_buffer_size)
      71                 :             : {
      72                 :             :     libspdm_context_t *context;
      73                 :             : 
      74                 :          50 :     context = spdm_context;
      75                 :             : 
      76         [ -  + ]:          50 :     LIBSPDM_ASSERT(context->local_context.local_cert_chain_provision[slot_id] != NULL);
      77         [ -  + ]:          50 :     LIBSPDM_ASSERT(context->local_context.local_cert_chain_provision_size[slot_id] != 0);
      78                 :             : 
      79                 :          50 :     *cert_chain_buffer = context->local_context.local_cert_chain_provision[slot_id];
      80                 :          50 :     *cert_chain_buffer_size = context->local_context.local_cert_chain_provision_size[slot_id];
      81                 :          50 : }
      82                 :             : 
      83                 :           0 : bool libspdm_get_local_cert_chain_data(void *spdm_context,
      84                 :             :                                        uint8_t slot_id,
      85                 :             :                                        const void **cert_chain_data,
      86                 :             :                                        size_t *cert_chain_data_size)
      87                 :             : {
      88                 :             :     libspdm_context_t *context;
      89                 :             :     size_t hash_size;
      90                 :             : 
      91                 :           0 :     context = spdm_context;
      92                 :             : 
      93                 :           0 :     libspdm_get_local_cert_chain_buffer(context, slot_id, cert_chain_data, cert_chain_data_size);
      94                 :             : 
      95                 :           0 :     hash_size = libspdm_get_hash_size(context->connection_info.algorithm.base_hash_algo);
      96                 :             : 
      97                 :           0 :     *cert_chain_data = (const uint8_t *)*cert_chain_data + sizeof(spdm_cert_chain_t) + hash_size;
      98                 :           0 :     *cert_chain_data_size = *cert_chain_data_size - (sizeof(spdm_cert_chain_t) + hash_size);
      99                 :             : 
     100                 :           0 :     return true;
     101                 :             : }
     102                 :             : 
     103                 :           3 : bool libspdm_get_peer_public_key_buffer(void *spdm_context,
     104                 :             :                                         const void **peer_public_key_buffer,
     105                 :             :                                         size_t *peer_public_key_buffer_size)
     106                 :             : {
     107                 :             :     libspdm_context_t *context;
     108                 :             : 
     109                 :           3 :     context = spdm_context;
     110         [ +  - ]:           3 :     if (context->local_context.peer_public_key_provision_size != 0) {
     111                 :           3 :         *peer_public_key_buffer = context->local_context.peer_public_key_provision;
     112                 :           3 :         *peer_public_key_buffer_size = context->local_context.peer_public_key_provision_size;
     113                 :           3 :         return true;
     114                 :             :     }
     115                 :           0 :     return false;
     116                 :             : }
     117                 :             : 
     118                 :           2 : bool libspdm_get_local_public_key_buffer(void *spdm_context,
     119                 :             :                                          const void **local_public_key_buffer,
     120                 :             :                                          size_t *local_public_key_buffer_size)
     121                 :             : {
     122                 :             :     libspdm_context_t *context;
     123                 :             : 
     124                 :           2 :     context = spdm_context;
     125         [ +  - ]:           2 :     if (context->local_context.local_public_key_provision_size != 0) {
     126                 :           2 :         *local_public_key_buffer = context->local_context.local_public_key_provision;
     127                 :           2 :         *local_public_key_buffer_size = context->local_context.local_public_key_provision_size;
     128                 :           2 :         return true;
     129                 :             :     }
     130                 :           0 :     return false;
     131                 :             : }
     132                 :             : 
     133                 :             : #if !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT)
     134                 :        3320 : void libspdm_free_peer_leaf_cert_public_key(libspdm_context_t *context, uint8_t slot_id)
     135                 :             : {
     136                 :             :     void *pubkey_context;
     137                 :             : 
     138                 :        3320 :     pubkey_context = context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
     139         [ +  + ]:        3320 :     if (pubkey_context == NULL) {
     140                 :        3251 :         return;
     141                 :             :     }
     142                 :             : 
     143         [ +  + ]:          69 :     if (context->local_context.is_requester) {
     144         [ -  + ]:          39 :         if (context->connection_info.algorithm.pqc_asym_algo != 0) {
     145                 :           0 :             libspdm_pqc_asym_free(context->connection_info.algorithm.pqc_asym_algo,
     146                 :             :                                   pubkey_context);
     147                 :             :         } else {
     148                 :          39 :             libspdm_asym_free(context->connection_info.algorithm.base_asym_algo, pubkey_context);
     149                 :             :         }
     150                 :             :     } else {
     151         [ -  + ]:          30 :         if (context->connection_info.algorithm.req_pqc_asym_alg != 0) {
     152                 :           0 :             libspdm_req_pqc_asym_free(context->connection_info.algorithm.req_pqc_asym_alg,
     153                 :             :                                       pubkey_context);
     154                 :             :         } else {
     155                 :          30 :             libspdm_req_asym_free(context->connection_info.algorithm.req_base_asym_alg,
     156                 :             :                                   pubkey_context);
     157                 :             :         }
     158                 :             :     }
     159                 :          69 :     context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key = NULL;
     160                 :             : }
     161                 :             : #endif /* !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT) */
     162                 :             : 
     163                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     164                 :             : bool libspdm_calculate_l1l2(libspdm_context_t *spdm_context,
     165                 :             :                             void *session_info,
     166                 :             :                             libspdm_l1l2_managed_buffer_t *l1l2)
     167                 :             : {
     168                 :             :     libspdm_return_t status;
     169                 :             :     libspdm_session_info_t *spdm_session_info;
     170                 :             : 
     171                 :             :     spdm_session_info = session_info;
     172                 :             : 
     173                 :             :     libspdm_init_managed_buffer(l1l2, sizeof(l1l2->buffer));
     174                 :             : 
     175                 :             :     if ((spdm_context->connection_info.version >> SPDM_VERSION_NUMBER_SHIFT_BIT) >
     176                 :             :         SPDM_MESSAGE_VERSION_11) {
     177                 :             : 
     178                 :             :         /* Need append VCA since 1.2 script*/
     179                 :             : 
     180                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
     181                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     182                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     183                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     184                 :             :         status = libspdm_append_managed_buffer(
     185                 :             :             l1l2,
     186                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     187                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     188                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     189                 :             :             return false;
     190                 :             :         }
     191                 :             :     }
     192                 :             : 
     193                 :             :     if (spdm_session_info == NULL) {
     194                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_m data :\n"));
     195                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     196                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_m),
     197                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_m));
     198                 :             :         status = libspdm_append_managed_buffer(
     199                 :             :             l1l2,
     200                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_m),
     201                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_m));
     202                 :             :     } else {
     203                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_m in session :\n"));
     204                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     205                 :             :             libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_m),
     206                 :             :             libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_m));
     207                 :             :         status = libspdm_append_managed_buffer(
     208                 :             :             l1l2,
     209                 :             :             libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_m),
     210                 :             :             libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_m));
     211                 :             :     }
     212                 :             :     if (LIBSPDM_STATUS_IS_ERROR(status)) {
     213                 :             :         return false;
     214                 :             :     }
     215                 :             : 
     216                 :             :     /* Debug code only - calculate and print value of l1l2 hash*/
     217                 :             :     LIBSPDM_DEBUG_CODE(
     218                 :             :         uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
     219                 :             :         uint32_t hash_size = libspdm_get_hash_size(
     220                 :             :             spdm_context->connection_info.algorithm.base_hash_algo);
     221                 :             :         if (!libspdm_hash_all(
     222                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
     223                 :             :                 libspdm_get_managed_buffer(l1l2),
     224                 :             :                 libspdm_get_managed_buffer_size(l1l2), hash_data)) {
     225                 :             :         return false;
     226                 :             :     }
     227                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "l1l2 hash - "));
     228                 :             :         LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
     229                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     230                 :             :         );
     231                 :             : 
     232                 :             :     return true;
     233                 :             : }
     234                 :             : #else
     235                 :          42 : bool libspdm_calculate_l1l2_hash(libspdm_context_t *spdm_context,
     236                 :             :                                  void *session_info,
     237                 :             :                                  size_t *l1l2_hash_size, void *l1l2_hash)
     238                 :             : {
     239                 :             :     libspdm_session_info_t *spdm_session_info;
     240                 :             :     bool result;
     241                 :             : 
     242                 :             :     uint32_t hash_size;
     243                 :             : 
     244                 :          42 :     spdm_session_info = session_info;
     245                 :             : 
     246                 :          42 :     hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
     247                 :             : 
     248         [ +  + ]:          42 :     if (spdm_session_info == NULL) {
     249                 :          39 :         result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     250                 :             :                                      spdm_context->transcript.digest_context_l1l2, l1l2_hash);
     251                 :             :     } else {
     252                 :           3 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_m in session :\n"));
     253                 :           3 :         result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     254                 :             :                                      spdm_session_info->session_transcript.digest_context_l1l2,
     255                 :             :                                      l1l2_hash);
     256                 :             :     }
     257         [ -  + ]:          42 :     if (!result) {
     258                 :           0 :         return false;
     259                 :             :     }
     260                 :          42 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "l1l2 hash - "));
     261                 :          42 :     LIBSPDM_INTERNAL_DUMP_DATA(l1l2_hash, hash_size);
     262                 :          42 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     263                 :             : 
     264                 :          42 :     *l1l2_hash_size = hash_size;
     265                 :             : 
     266                 :          42 :     return true;
     267                 :             : }
     268                 :             : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
     269                 :             : 
     270                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     271                 :             : /*
     272                 :             :  * This function calculates m1m2.
     273                 :             :  *
     274                 :             :  * @param  context                       A pointer to the SPDM context.
     275                 :             :  * @param  is_mut                        Indicate if this is from mutual authentication.
     276                 :             :  * @param  m1m2                          The buffer to store the m1m2
     277                 :             :  */
     278                 :             : static bool libspdm_calculate_m1m2(void *context, bool is_mut,
     279                 :             :                                    libspdm_m1m2_managed_buffer_t *m1m2)
     280                 :             : {
     281                 :             :     libspdm_context_t *spdm_context;
     282                 :             :     libspdm_return_t status;
     283                 :             : 
     284                 :             :     spdm_context = context;
     285                 :             : 
     286                 :             :     libspdm_init_managed_buffer(m1m2, sizeof(m1m2->buffer));
     287                 :             : 
     288                 :             :     if (is_mut) {
     289                 :             :         if ((spdm_context->connection_info.version >> SPDM_VERSION_NUMBER_SHIFT_BIT) >
     290                 :             :             SPDM_MESSAGE_VERSION_11) {
     291                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
     292                 :             :             LIBSPDM_INTERNAL_DUMP_HEX(
     293                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     294                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     295                 :             :             status = libspdm_append_managed_buffer(
     296                 :             :                 m1m2,
     297                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     298                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     299                 :             :             if (LIBSPDM_STATUS_IS_ERROR(status)) {
     300                 :             :                 return false;
     301                 :             :             }
     302                 :             :         }
     303                 :             : 
     304                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_mut_b data :\n"));
     305                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     306                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_b),
     307                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_b));
     308                 :             :         status = libspdm_append_managed_buffer(
     309                 :             :             m1m2,
     310                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_b),
     311                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_b));
     312                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     313                 :             :             return false;
     314                 :             :         }
     315                 :             : 
     316                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_mut_c data :\n"));
     317                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     318                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_c),
     319                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_c));
     320                 :             :         status = libspdm_append_managed_buffer(
     321                 :             :             m1m2,
     322                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_c),
     323                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_c));
     324                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     325                 :             :             return false;
     326                 :             :         }
     327                 :             : 
     328                 :             :         /* Debug code only - calculate and print value of m1m2 mut hash*/
     329                 :             :         LIBSPDM_DEBUG_CODE(
     330                 :             :             uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
     331                 :             :             uint32_t hash_size = libspdm_get_hash_size(
     332                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo);
     333                 :             :             if (!libspdm_hash_all(
     334                 :             :                     spdm_context->connection_info.algorithm.base_hash_algo,
     335                 :             :                     libspdm_get_managed_buffer(m1m2),
     336                 :             :                     libspdm_get_managed_buffer_size(m1m2), hash_data)) {
     337                 :             :             return false;
     338                 :             :         }
     339                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 Mut hash - "));
     340                 :             :             LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
     341                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     342                 :             :             );
     343                 :             : 
     344                 :             :     } else {
     345                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
     346                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     347                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     348                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     349                 :             :         status = libspdm_append_managed_buffer(
     350                 :             :             m1m2,
     351                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     352                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     353                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     354                 :             :             return false;
     355                 :             :         }
     356                 :             : 
     357                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_b data :\n"));
     358                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     359                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_b),
     360                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_b));
     361                 :             :         status = libspdm_append_managed_buffer(
     362                 :             :             m1m2,
     363                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_b),
     364                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_b));
     365                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     366                 :             :             return false;
     367                 :             :         }
     368                 :             : 
     369                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_c data :\n"));
     370                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     371                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_c),
     372                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_c));
     373                 :             :         status = libspdm_append_managed_buffer(
     374                 :             :             m1m2,
     375                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_c),
     376                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_c));
     377                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     378                 :             :             return false;
     379                 :             :         }
     380                 :             : 
     381                 :             :         /* Debug code only - calculate and print value of m1m2 hash*/
     382                 :             :         LIBSPDM_DEBUG_CODE(
     383                 :             :             uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
     384                 :             :             uint32_t hash_size = libspdm_get_hash_size(
     385                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo);
     386                 :             :             if (!libspdm_hash_all(
     387                 :             :                     spdm_context->connection_info.algorithm.base_hash_algo,
     388                 :             :                     libspdm_get_managed_buffer(m1m2),
     389                 :             :                     libspdm_get_managed_buffer_size(m1m2), hash_data)) {
     390                 :             :             return false;
     391                 :             :         }
     392                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 hash - "));
     393                 :             :             LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
     394                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     395                 :             :             );
     396                 :             :     }
     397                 :             : 
     398                 :             :     return true;
     399                 :             : }
     400                 :             : #else
     401                 :             : /*
     402                 :             :  * This function calculates m1m2 hash.
     403                 :             :  *
     404                 :             :  * @param  context                       A pointer to the SPDM context.
     405                 :             :  * @param  is_mut                        Indicate if this is from mutual authentication.
     406                 :             :  * @param  m1m2_hash_size               size in bytes of the m1m2 hash
     407                 :             :  * @param  m1m2_hash                   The buffer to store the m1m2 hash
     408                 :             :  */
     409                 :          38 : static bool libspdm_calculate_m1m2_hash(void *context, bool is_mut,
     410                 :             :                                         size_t *m1m2_hash_size,
     411                 :             :                                         void *m1m2_hash)
     412                 :             : {
     413                 :             :     libspdm_context_t *spdm_context;
     414                 :             :     uint32_t hash_size;
     415                 :             :     bool result;
     416                 :             : 
     417                 :          38 :     spdm_context = context;
     418                 :             : 
     419                 :          38 :     hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
     420                 :             : 
     421         [ +  + ]:          38 :     if (is_mut) {
     422                 :           8 :         result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     423                 :             :                                      spdm_context->transcript.digest_context_mut_m1m2, m1m2_hash);
     424         [ -  + ]:           8 :         if (!result) {
     425                 :           0 :             return false;
     426                 :             :         }
     427                 :           8 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 Mut hash - "));
     428                 :           8 :         LIBSPDM_INTERNAL_DUMP_DATA(m1m2_hash, hash_size);
     429                 :           8 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     430                 :             : 
     431                 :             :     } else {
     432                 :          30 :         result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     433                 :             :                                      spdm_context->transcript.digest_context_m1m2, m1m2_hash);
     434         [ -  + ]:          30 :         if (!result) {
     435                 :           0 :             return false;
     436                 :             :         }
     437                 :          30 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 hash - "));
     438                 :          30 :         LIBSPDM_INTERNAL_DUMP_DATA(m1m2_hash, hash_size);
     439                 :          30 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     440                 :             :     }
     441                 :             : 
     442                 :          38 :     *m1m2_hash_size = hash_size;
     443                 :             : 
     444                 :          38 :     return true;
     445                 :             : }
     446                 :             : #endif
     447                 :             : 
     448                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     449                 :             : static bool libspdm_calculate_il1il2(libspdm_context_t *spdm_context,
     450                 :             :                                      void *session_info,
     451                 :             :                                      bool is_mut,
     452                 :             :                                      libspdm_il1il2_managed_buffer_t *il1il2)
     453                 :             : {
     454                 :             :     libspdm_return_t status;
     455                 :             :     libspdm_session_info_t *spdm_session_info;
     456                 :             : 
     457                 :             :     spdm_session_info = session_info;
     458                 :             : 
     459                 :             :     libspdm_init_managed_buffer(il1il2, sizeof(il1il2->buffer));
     460                 :             : 
     461                 :             : 
     462                 :             :     if (is_mut) {
     463                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
     464                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     465                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     466                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     467                 :             :         status = libspdm_append_managed_buffer(
     468                 :             :             il1il2,
     469                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     470                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     471                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     472                 :             :             return false;
     473                 :             :         }
     474                 :             : 
     475                 :             :         if (spdm_session_info == NULL) {
     476                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_encap_e data :\n"));
     477                 :             :             LIBSPDM_INTERNAL_DUMP_HEX(
     478                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_encap_e),
     479                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_encap_e));
     480                 :             :             status = libspdm_append_managed_buffer(
     481                 :             :                 il1il2,
     482                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_encap_e),
     483                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_encap_e));
     484                 :             :         } else {
     485                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_encap_e in session :\n"));
     486                 :             :             LIBSPDM_INTERNAL_DUMP_HEX(
     487                 :             :                 libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_encap_e),
     488                 :             :                 libspdm_get_managed_buffer_size(
     489                 :             :                     &spdm_session_info->session_transcript.message_encap_e));
     490                 :             :             status = libspdm_append_managed_buffer(
     491                 :             :                 il1il2,
     492                 :             :                 libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_encap_e),
     493                 :             :                 libspdm_get_managed_buffer_size(
     494                 :             :                     &spdm_session_info->session_transcript.message_encap_e));
     495                 :             :         }
     496                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     497                 :             :             return false;
     498                 :             :         }
     499                 :             : 
     500                 :             :         /* Debug code only - calculate and print value of il1il2 hash*/
     501                 :             :         LIBSPDM_DEBUG_CODE(
     502                 :             :             uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
     503                 :             :             uint32_t hash_size = libspdm_get_hash_size(
     504                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo);
     505                 :             :             if (!libspdm_hash_all(
     506                 :             :                     spdm_context->connection_info.algorithm.base_hash_algo,
     507                 :             :                     libspdm_get_managed_buffer(il1il2),
     508                 :             :                     libspdm_get_managed_buffer_size(il1il2), hash_data)) {
     509                 :             :             return false;
     510                 :             :         }
     511                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 mut hash - "));
     512                 :             :             LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
     513                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     514                 :             :             );
     515                 :             :     } else {
     516                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
     517                 :             :         LIBSPDM_INTERNAL_DUMP_HEX(
     518                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     519                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     520                 :             :         status = libspdm_append_managed_buffer(
     521                 :             :             il1il2,
     522                 :             :             libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
     523                 :             :             libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
     524                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     525                 :             :             return false;
     526                 :             :         }
     527                 :             : 
     528                 :             :         if (spdm_session_info == NULL) {
     529                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_e data :\n"));
     530                 :             :             LIBSPDM_INTERNAL_DUMP_HEX(
     531                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_e),
     532                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_e));
     533                 :             :             status = libspdm_append_managed_buffer(
     534                 :             :                 il1il2,
     535                 :             :                 libspdm_get_managed_buffer(&spdm_context->transcript.message_e),
     536                 :             :                 libspdm_get_managed_buffer_size(&spdm_context->transcript.message_e));
     537                 :             :         } else {
     538                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_e in session :\n"));
     539                 :             :             LIBSPDM_INTERNAL_DUMP_HEX(
     540                 :             :                 libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_e),
     541                 :             :                 libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_e));
     542                 :             :             status = libspdm_append_managed_buffer(
     543                 :             :                 il1il2,
     544                 :             :                 libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_e),
     545                 :             :                 libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_e));
     546                 :             :         }
     547                 :             :         if (LIBSPDM_STATUS_IS_ERROR(status)) {
     548                 :             :             return false;
     549                 :             :         }
     550                 :             : 
     551                 :             :         /* Debug code only - calculate and print value of il1il2 hash*/
     552                 :             :         LIBSPDM_DEBUG_CODE(
     553                 :             :             uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
     554                 :             :             uint32_t hash_size = libspdm_get_hash_size(
     555                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo);
     556                 :             :             if (!libspdm_hash_all(
     557                 :             :                     spdm_context->connection_info.algorithm.base_hash_algo,
     558                 :             :                     libspdm_get_managed_buffer(il1il2),
     559                 :             :                     libspdm_get_managed_buffer_size(il1il2), hash_data)) {
     560                 :             :             return false;
     561                 :             :         }
     562                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 hash - "));
     563                 :             :             LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
     564                 :             :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     565                 :             :             );
     566                 :             :     }
     567                 :             : 
     568                 :             :     return true;
     569                 :             : }
     570                 :             : #else
     571                 :          31 : static bool libspdm_calculate_il1il2_hash(libspdm_context_t *spdm_context,
     572                 :             :                                           void *session_info, bool is_encap,
     573                 :             :                                           size_t *il1il2_hash_size, void *il1il2_hash)
     574                 :             : {
     575                 :             :     libspdm_session_info_t *spdm_session_info;
     576                 :             :     bool result;
     577                 :             : 
     578                 :             :     uint32_t hash_size;
     579                 :             : 
     580                 :          31 :     spdm_session_info = session_info;
     581                 :             : 
     582                 :          31 :     hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
     583                 :             : 
     584         [ +  + ]:          31 :     if (spdm_session_info == NULL) {
     585         [ +  + ]:          26 :         if (is_encap) {
     586                 :          12 :             result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     587                 :             :                                          spdm_context->transcript.digest_context_encap_il1il2,
     588                 :             :                                          il1il2_hash);
     589                 :             :         } else {
     590                 :          14 :             result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     591                 :             :                                          spdm_context->transcript.digest_context_il1il2,
     592                 :             :                                          il1il2_hash);
     593                 :             :         }
     594                 :             :     } else {
     595         [ +  + ]:           5 :         if (is_encap) {
     596                 :           2 :             result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     597                 :             :                                          spdm_session_info->session_transcript.digest_context_encap_il1il2,
     598                 :             :                                          il1il2_hash);
     599                 :             :         } else {
     600                 :           3 :             result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
     601                 :             :                                          spdm_session_info->session_transcript.digest_context_il1il2,
     602                 :             :                                          il1il2_hash);
     603                 :             :         }
     604                 :             :     }
     605         [ -  + ]:          31 :     if (!result) {
     606                 :           0 :         return false;
     607                 :             :     }
     608                 :          31 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 hash - "));
     609                 :          31 :     LIBSPDM_INTERNAL_DUMP_DATA(il1il2_hash, hash_size);
     610                 :          31 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
     611                 :             : 
     612                 :          31 :     *il1il2_hash_size = hash_size;
     613                 :             : 
     614                 :          31 :     return true;
     615                 :             : }
     616                 :             : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
     617                 :             : 
     618                 :          45 : bool libspdm_generate_cert_chain_hash(libspdm_context_t *spdm_context,
     619                 :             :                                       size_t slot_id, uint8_t *hash)
     620                 :             : {
     621         [ -  + ]:          45 :     LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
     622                 :          45 :     return libspdm_hash_all(
     623                 :             :         spdm_context->connection_info.algorithm.base_hash_algo,
     624                 :             :         spdm_context->local_context.local_cert_chain_provision[slot_id],
     625                 :             :         spdm_context->local_context.local_cert_chain_provision_size[slot_id], hash);
     626                 :             : }
     627                 :             : 
     628                 :           2 : bool libspdm_generate_public_key_hash(libspdm_context_t *spdm_context,
     629                 :             :                                       uint8_t *hash)
     630                 :             : {
     631                 :           2 :     return libspdm_hash_all(
     632                 :             :         spdm_context->connection_info.algorithm.base_hash_algo,
     633                 :             :         spdm_context->local_context.local_public_key_provision,
     634                 :             :         spdm_context->local_context.local_public_key_provision_size, hash);
     635                 :             : }
     636                 :             : 
     637                 :          13 : uint8_t libspdm_get_cert_slot_mask(libspdm_context_t *spdm_context)
     638                 :             : {
     639                 :             :     size_t index;
     640                 :             :     uint8_t slot_mask;
     641                 :             : 
     642                 :          13 :     slot_mask = 0;
     643         [ +  + ]:         117 :     for (index = 0; index < SPDM_MAX_SLOT_COUNT; index++) {
     644         [ +  + ]:         104 :         if (spdm_context->local_context.local_cert_chain_provision[index] != NULL) {
     645                 :          14 :             slot_mask |= (1 << index);
     646                 :             :         }
     647                 :             :     }
     648                 :             : 
     649                 :          13 :     return slot_mask;
     650                 :             : }
     651                 :             : 
     652                 :          23 : uint8_t libspdm_get_cert_slot_count(libspdm_context_t *spdm_context)
     653                 :             : {
     654                 :             :     size_t index;
     655                 :             :     uint8_t slot_count;
     656                 :             : 
     657                 :          23 :     slot_count = 0;
     658         [ +  + ]:         207 :     for (index = 0; index < SPDM_MAX_SLOT_COUNT; index++) {
     659         [ +  + ]:         184 :         if (spdm_context->local_context.local_cert_chain_provision[index] != NULL) {
     660                 :          32 :             slot_count++;
     661                 :             :         }
     662                 :             :     }
     663                 :             : 
     664                 :          23 :     return slot_count;
     665                 :             : }
     666                 :             : 
     667                 :             : #if LIBSPDM_CERT_PARSE_SUPPORT
     668                 :          40 : bool libspdm_verify_peer_cert_chain_buffer_integrity(libspdm_context_t *spdm_context,
     669                 :             :                                                      const void *cert_chain_buffer,
     670                 :             :                                                      size_t cert_chain_buffer_size)
     671                 :             : {
     672                 :             :     bool result;
     673                 :             :     uint8_t cert_model;
     674                 :             :     bool is_requester;
     675                 :             : 
     676                 :          40 :     is_requester = spdm_context->local_context.is_requester;
     677                 :             : 
     678                 :          40 :     cert_model = SPDM_CERTIFICATE_INFO_CERT_MODEL_ALIAS_CERT;
     679                 :             :     /* Responder does not determine Requester's certificate model */
     680         [ +  + ]:          40 :     if (is_requester) {
     681         [ +  + ]:          37 :         if ((spdm_context->connection_info.capability.flags &
     682                 :             :              SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_ALIAS_CERT_CAP) == 0) {
     683                 :          34 :             cert_model = SPDM_CERTIFICATE_INFO_CERT_MODEL_DEVICE_CERT;
     684                 :             :         }
     685                 :             :     }
     686                 :             : 
     687         [ +  + ]:          40 :     if (is_requester) {
     688                 :          37 :         result = libspdm_verify_certificate_chain_buffer(
     689                 :          37 :             libspdm_get_connection_version(spdm_context),
     690                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     691                 :             :             spdm_context->connection_info.algorithm.base_asym_algo,
     692                 :             :             spdm_context->connection_info.algorithm.pqc_asym_algo,
     693                 :             :             cert_chain_buffer, cert_chain_buffer_size,
     694                 :             :             false, cert_model);
     695                 :             :     } else {
     696                 :           3 :         result = libspdm_verify_certificate_chain_buffer(
     697                 :           3 :             libspdm_get_connection_version(spdm_context),
     698                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     699                 :           3 :             spdm_context->connection_info.algorithm.req_base_asym_alg,
     700                 :             :             spdm_context->connection_info.algorithm.req_pqc_asym_alg,
     701                 :             :             cert_chain_buffer, cert_chain_buffer_size,
     702                 :             :             true, cert_model);
     703                 :             :     }
     704                 :             : 
     705                 :          40 :     return result;
     706                 :             : }
     707                 :             : 
     708                 :          32 : bool libspdm_verify_peer_cert_chain_buffer_authority(libspdm_context_t *spdm_context,
     709                 :             :                                                      const void *cert_chain_buffer,
     710                 :             :                                                      size_t cert_chain_buffer_size,
     711                 :             :                                                      const void **trust_anchor,
     712                 :             :                                                      size_t *trust_anchor_size)
     713                 :             : {
     714                 :             :     const uint8_t *root_cert;
     715                 :             :     size_t root_cert_size;
     716                 :             :     uint8_t root_cert_index;
     717                 :             :     size_t root_cert_hash_size;
     718                 :             :     uint8_t root_cert_hash[LIBSPDM_MAX_HASH_SIZE];
     719                 :             :     const uint8_t *received_root_cert;
     720                 :             :     size_t received_root_cert_size;
     721                 :             :     bool result;
     722                 :             : 
     723                 :          32 :     root_cert_index = 0;
     724                 :          32 :     root_cert = spdm_context->local_context.peer_root_cert_provision[root_cert_index];
     725                 :          32 :     root_cert_size = spdm_context->local_context.peer_root_cert_provision_size[root_cert_index];
     726                 :             : 
     727                 :          32 :     root_cert_hash_size = libspdm_get_hash_size(
     728                 :             :         spdm_context->connection_info.algorithm.base_hash_algo);
     729                 :             : 
     730   [ +  +  +  - ]:          32 :     if ((root_cert != NULL) && (root_cert_size != 0)) {
     731   [ +  -  +  - ]:          63 :         while ((root_cert != NULL) && (root_cert_size != 0)) {
     732                 :          63 :             result = libspdm_hash_all(
     733                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
     734                 :             :                 root_cert, root_cert_size, root_cert_hash);
     735         [ -  + ]:          63 :             if (!result) {
     736                 :           0 :                 LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     737                 :             :                                "!!! verify_peer_cert_chain_buffer - FAIL (hash calculation) !!!\n"));
     738                 :           0 :                 return false;
     739                 :             :             }
     740                 :             : 
     741         [ +  + ]:          63 :             if (libspdm_consttime_is_mem_equal((const uint8_t *)cert_chain_buffer +
     742                 :             :                                                sizeof(spdm_cert_chain_t),
     743                 :             :                                                root_cert_hash, root_cert_hash_size)) {
     744                 :          24 :                 break;
     745                 :             :             }
     746                 :             : 
     747                 :             :             #if (LIBSPDM_MAX_ROOT_CERT_SUPPORT) > 1
     748         [ +  + ]:          39 :             if ((root_cert_index < ((LIBSPDM_MAX_ROOT_CERT_SUPPORT) -1)) &&
     749         [ +  + ]:          38 :                 (spdm_context->local_context.peer_root_cert_provision[root_cert_index + 1] !=
     750                 :             :                  NULL)) {
     751                 :          34 :                 root_cert_index++;
     752                 :          34 :                 root_cert = spdm_context->local_context.peer_root_cert_provision[root_cert_index];
     753                 :          34 :                 root_cert_size =
     754                 :          34 :                     spdm_context->local_context.peer_root_cert_provision_size[root_cert_index];
     755                 :             :             } else
     756                 :             :             #endif /* LIBSPDM_MAX_ROOT_CERT_SUPPORT */
     757                 :             :             {
     758                 :           5 :                 LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     759                 :             :                                "!!! verify_peer_cert_chain_buffer - "
     760                 :             :                                "FAIL (all root cert hash mismatch) !!!\n"));
     761                 :           5 :                 return false;
     762                 :             :             }
     763                 :             :         }
     764                 :             : 
     765                 :          24 :         result = libspdm_x509_get_cert_from_cert_chain(
     766                 :          24 :             (const uint8_t *)cert_chain_buffer + sizeof(spdm_cert_chain_t) + root_cert_hash_size,
     767                 :          24 :             cert_chain_buffer_size - sizeof(spdm_cert_chain_t) - root_cert_hash_size,
     768                 :             :             0, &received_root_cert, &received_root_cert_size);
     769         [ -  + ]:          24 :         if (!result) {
     770                 :           0 :             LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     771                 :             :                            "!!! verify_peer_cert_chain_buffer - FAIL (cert retrieval fail) !!!\n"));
     772                 :           0 :             return false;
     773                 :             :         }
     774         [ +  + ]:          24 :         if (libspdm_is_root_certificate(received_root_cert, received_root_cert_size)) {
     775         [ +  - ]:          23 :             if ((root_cert != NULL) &&
     776         [ -  + ]:          23 :                 !libspdm_consttime_is_mem_equal(received_root_cert, root_cert, root_cert_size)) {
     777                 :           0 :                 LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     778                 :             :                                "!!! verify_peer_cert_chain_buffer - "
     779                 :             :                                "FAIL (root cert mismatch) !!!\n"));
     780                 :           0 :                 return false;
     781                 :             :             }
     782                 :             :         } else {
     783         [ -  + ]:           1 :             if (!libspdm_x509_verify_cert(received_root_cert, received_root_cert_size,
     784                 :             :                                           root_cert, root_cert_size)) {
     785                 :           0 :                 LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     786                 :             :                                "!!! verify_peer_cert_chain_buffer - "
     787                 :             :                                "FAIL (received root cert verify failed)!!!\n"));
     788                 :           0 :                 return false;
     789                 :             :             }
     790                 :             :         }
     791         [ +  + ]:          24 :         if (trust_anchor != NULL) {
     792                 :           5 :             *trust_anchor = root_cert;
     793                 :             :         }
     794         [ +  + ]:          24 :         if (trust_anchor_size != NULL) {
     795                 :           5 :             *trust_anchor_size = root_cert_size;
     796                 :             :         }
     797                 :             :     }
     798                 :             :     /*
     799                 :             :      * When there is no root_cert in local_context, the return is true too.
     800                 :             :      * No root_cert means the caller wants to verify the trust anchor of the cert chain.
     801                 :             :      */
     802                 :          27 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_peer_cert_chain_buffer - PASS !!!\n"));
     803                 :             : 
     804                 :          27 :     return true;
     805                 :             : }
     806                 :             : #endif
     807                 :             : 
     808                 :          15 : bool libspdm_generate_challenge_auth_signature(libspdm_context_t *spdm_context,
     809                 :             :                                                bool is_requester,
     810                 :             :                                                uint8_t slot_id,
     811                 :             :                                                uint8_t *signature)
     812                 :             : {
     813                 :             :     bool result;
     814                 :             :     size_t signature_size;
     815                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     816                 :             :     libspdm_m1m2_managed_buffer_t m1m2;
     817                 :             :     uint8_t *m1m2_buffer;
     818                 :             :     size_t m1m2_buffer_size;
     819                 :             : #else
     820                 :             :     uint8_t m1m2_hash[LIBSPDM_MAX_HASH_SIZE];
     821                 :             :     size_t m1m2_hash_size;
     822                 :             : #endif
     823                 :             : 
     824                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     825                 :             :     result = libspdm_calculate_m1m2(spdm_context, is_requester, &m1m2);
     826                 :             :     m1m2_buffer = libspdm_get_managed_buffer(&m1m2);
     827                 :             :     m1m2_buffer_size = libspdm_get_managed_buffer_size(&m1m2);
     828                 :             : #else
     829                 :          15 :     m1m2_hash_size = sizeof(m1m2_hash);
     830                 :          15 :     result = libspdm_calculate_m1m2_hash(spdm_context, is_requester, &m1m2_hash_size, &m1m2_hash);
     831                 :             : #endif
     832         [ +  + ]:          15 :     if (is_requester) {
     833                 :           4 :         libspdm_reset_message_mut_b(spdm_context);
     834                 :           4 :         libspdm_reset_message_mut_c(spdm_context);
     835                 :             :     } else {
     836                 :          11 :         libspdm_reset_message_b(spdm_context);
     837                 :          11 :         libspdm_reset_message_c(spdm_context);
     838                 :             :     }
     839         [ -  + ]:          15 :     if (!result) {
     840                 :           0 :         return false;
     841                 :             :     }
     842                 :             : 
     843         [ +  + ]:          15 :     if (is_requester) {
     844                 :             : #if LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP
     845         [ -  + ]:           4 :         if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
     846                 :           0 :             signature_size = libspdm_get_req_pqc_asym_signature_size(
     847                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg);
     848                 :             :         } else {
     849                 :           4 :             signature_size = libspdm_get_req_asym_signature_size(
     850                 :           4 :                 spdm_context->connection_info.algorithm.req_base_asym_alg);
     851                 :             :         }
     852                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     853                 :             :         result = libspdm_requester_data_sign(
     854                 :             :             spdm_context,
     855                 :             :             spdm_context->connection_info.version,
     856                 :             :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
     857                 :             :             SPDM_CHALLENGE_AUTH,
     858                 :             :             spdm_context->connection_info.algorithm.req_base_asym_alg,
     859                 :             :             spdm_context->connection_info.algorithm.req_pqc_asym_alg,
     860                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     861                 :             :             false, m1m2_buffer, m1m2_buffer_size, signature, &signature_size);
     862                 :             : #else
     863                 :           8 :         result = libspdm_requester_data_sign(
     864                 :             :             spdm_context,
     865                 :           4 :             spdm_context->connection_info.version,
     866                 :           4 :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
     867                 :             :             SPDM_CHALLENGE_AUTH,
     868                 :           4 :             spdm_context->connection_info.algorithm.req_base_asym_alg,
     869                 :             :             spdm_context->connection_info.algorithm.req_pqc_asym_alg,
     870                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     871                 :             :             true, m1m2_hash, m1m2_hash_size, signature, &signature_size);
     872                 :             : #endif
     873                 :             : #else /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
     874                 :             :         result = false;
     875                 :             : #endif /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
     876                 :             :     } else {
     877         [ -  + ]:          11 :         if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
     878                 :           0 :             signature_size = libspdm_get_pqc_asym_signature_size(
     879                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo);
     880                 :             :         } else {
     881                 :          11 :             signature_size = libspdm_get_asym_signature_size(
     882                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo);
     883                 :             :         }
     884                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     885                 :             :         result = libspdm_responder_data_sign(
     886                 :             :             spdm_context,
     887                 :             :             spdm_context->connection_info.version,
     888                 :             :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
     889                 :             :             SPDM_CHALLENGE_AUTH,
     890                 :             :             spdm_context->connection_info.algorithm.base_asym_algo,
     891                 :             :             spdm_context->connection_info.algorithm.pqc_asym_algo,
     892                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     893                 :             :             false, m1m2_buffer, m1m2_buffer_size, signature,
     894                 :             :             &signature_size);
     895                 :             : #else
     896                 :          22 :         result = libspdm_responder_data_sign(
     897                 :             :             spdm_context,
     898                 :          11 :             spdm_context->connection_info.version,
     899                 :          11 :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
     900                 :             :             SPDM_CHALLENGE_AUTH,
     901                 :             :             spdm_context->connection_info.algorithm.base_asym_algo,
     902                 :             :             spdm_context->connection_info.algorithm.pqc_asym_algo,
     903                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
     904                 :             :             true, m1m2_hash, m1m2_hash_size, signature,
     905                 :             :             &signature_size);
     906                 :             : #endif
     907                 :             :     }
     908                 :             : 
     909                 :          15 :     return result;
     910                 :             : }
     911                 :             : 
     912                 :          24 : bool libspdm_verify_certificate_chain_hash(libspdm_context_t *spdm_context,
     913                 :             :                                            uint8_t slot_id,
     914                 :             :                                            const void *certificate_chain_hash,
     915                 :             :                                            size_t certificate_chain_hash_size)
     916                 :             : {
     917                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
     918                 :             :     size_t hash_size;
     919                 :             :     uint8_t cert_chain_buffer_hash[LIBSPDM_MAX_HASH_SIZE];
     920                 :             :     const uint8_t *cert_chain_buffer;
     921                 :             :     size_t cert_chain_buffer_size;
     922                 :             :     bool result;
     923                 :             : 
     924                 :             :     libspdm_get_peer_cert_chain_buffer(spdm_context,
     925                 :             :                                        slot_id,
     926                 :             :                                        (const void **)&cert_chain_buffer,
     927                 :             :                                        &cert_chain_buffer_size);
     928                 :             : 
     929                 :             :     hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
     930                 :             : 
     931                 :             :     result = libspdm_hash_all(spdm_context->connection_info.algorithm.base_hash_algo,
     932                 :             :                               cert_chain_buffer, cert_chain_buffer_size,
     933                 :             :                               cert_chain_buffer_hash);
     934                 :             :     if (!result) {
     935                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     936                 :             :                        "!!! verify_certificate_chain_hash - FAIL (hash calculation) !!!\n"));
     937                 :             :         return false;
     938                 :             :     }
     939                 :             : 
     940                 :             :     if (hash_size != certificate_chain_hash_size) {
     941                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
     942                 :             :         return false;
     943                 :             :     }
     944                 :             :     if (!libspdm_consttime_is_mem_equal(certificate_chain_hash, cert_chain_buffer_hash,
     945                 :             :                                         certificate_chain_hash_size)) {
     946                 :             :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
     947                 :             :         return false;
     948                 :             :     }
     949                 :             : #else
     950         [ -  + ]:          24 :     LIBSPDM_ASSERT(
     951                 :             :         spdm_context->connection_info.peer_used_cert_chain[slot_id].buffer_hash_size != 0);
     952                 :             : 
     953         [ -  + ]:          24 :     if (spdm_context->connection_info.peer_used_cert_chain[slot_id].buffer_hash_size !=
     954                 :             :         certificate_chain_hash_size) {
     955                 :           0 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
     956                 :           0 :         return false;
     957                 :             :     }
     958                 :             : 
     959         [ -  + ]:          24 :     if (!libspdm_consttime_is_mem_equal(certificate_chain_hash,
     960                 :          24 :                                         spdm_context->connection_info.peer_used_cert_chain[slot_id].
     961                 :             :                                         buffer_hash, certificate_chain_hash_size)) {
     962                 :           0 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
     963                 :           0 :         return false;
     964                 :             :     }
     965                 :             : #endif
     966                 :          24 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_certificate_chain_hash - PASS !!!\n"));
     967                 :          24 :     return true;
     968                 :             : }
     969                 :             : 
     970                 :           2 : bool libspdm_verify_public_key_hash(libspdm_context_t *spdm_context,
     971                 :             :                                     const void *public_key_hash,
     972                 :             :                                     size_t public_key_hash_size)
     973                 :             : {
     974                 :             :     size_t hash_size;
     975                 :             :     uint8_t public_key_buffer_hash[LIBSPDM_MAX_HASH_SIZE];
     976                 :             :     bool result;
     977                 :             : 
     978                 :           2 :     hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
     979                 :             : 
     980                 :           2 :     result = libspdm_hash_all(spdm_context->connection_info.algorithm.base_hash_algo,
     981                 :             :                               spdm_context->local_context.peer_public_key_provision,
     982                 :             :                               spdm_context->local_context.peer_public_key_provision_size,
     983                 :             :                               public_key_buffer_hash);
     984         [ -  + ]:           2 :     if (!result) {
     985                 :           0 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
     986                 :             :                        "!!! verify_public_key_hash - FAIL (hash calculation) !!!\n"));
     987                 :           0 :         return false;
     988                 :             :     }
     989                 :             : 
     990         [ -  + ]:           2 :     if (hash_size != public_key_hash_size) {
     991                 :           0 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_public_key_hash - FAIL !!!\n"));
     992                 :           0 :         return false;
     993                 :             :     }
     994         [ -  + ]:           2 :     if (!libspdm_consttime_is_mem_equal(public_key_hash, public_key_buffer_hash,
     995                 :             :                                         public_key_hash_size)) {
     996                 :           0 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_public_key_hash - FAIL !!!\n"));
     997                 :           0 :         return false;
     998                 :             :     }
     999                 :             : 
    1000                 :           2 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_public_key_hash - PASS !!!\n"));
    1001                 :           2 :     return true;
    1002                 :             : }
    1003                 :             : 
    1004                 :          23 : bool libspdm_verify_challenge_auth_signature(libspdm_context_t *spdm_context,
    1005                 :             :                                              bool is_requester,
    1006                 :             :                                              uint8_t slot_id,
    1007                 :             :                                              const void *sign_data,
    1008                 :             :                                              size_t sign_data_size)
    1009                 :             : {
    1010                 :             :     bool result;
    1011                 :             :     void *context;
    1012                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1013                 :             :     libspdm_m1m2_managed_buffer_t m1m2;
    1014                 :             :     uint8_t *m1m2_buffer;
    1015                 :             :     size_t m1m2_buffer_size;
    1016                 :             :     const uint8_t *cert_buffer;
    1017                 :             :     size_t cert_buffer_size;
    1018                 :             :     const uint8_t *cert_chain_data;
    1019                 :             :     size_t cert_chain_data_size;
    1020                 :             : #else
    1021                 :             :     uint8_t m1m2_hash[LIBSPDM_MAX_HASH_SIZE];
    1022                 :             :     size_t m1m2_hash_size;
    1023                 :             : #endif
    1024                 :             : 
    1025                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1026                 :             :     result = libspdm_calculate_m1m2(spdm_context, !is_requester, &m1m2);
    1027                 :             :     m1m2_buffer = libspdm_get_managed_buffer(&m1m2);
    1028                 :             :     m1m2_buffer_size = libspdm_get_managed_buffer_size(&m1m2);
    1029                 :             : #else
    1030                 :          23 :     m1m2_hash_size = sizeof(m1m2_hash);
    1031                 :          23 :     result = libspdm_calculate_m1m2_hash(spdm_context, !is_requester, &m1m2_hash_size, &m1m2_hash);
    1032                 :             : #endif
    1033         [ +  + ]:          23 :     if (is_requester) {
    1034                 :          19 :         libspdm_reset_message_b(spdm_context);
    1035                 :          19 :         libspdm_reset_message_c(spdm_context);
    1036                 :             :     } else {
    1037                 :           4 :         libspdm_reset_message_mut_b(spdm_context);
    1038                 :           4 :         libspdm_reset_message_mut_c(spdm_context);
    1039                 :             :     }
    1040         [ -  + ]:          23 :     if (!result) {
    1041                 :           0 :         return false;
    1042                 :             :     }
    1043                 :             : 
    1044         [ +  + ]:          23 :     if (slot_id == 0xFF) {
    1045         [ +  + ]:           2 :         if (is_requester) {
    1046         [ -  + ]:           1 :             if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1047                 :           0 :                 result = libspdm_pqc_asym_get_public_key_from_der(
    1048                 :             :                     spdm_context->connection_info.algorithm.pqc_asym_algo,
    1049                 :           0 :                     spdm_context->local_context.peer_public_key_provision,
    1050                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1051                 :             :                     &context);
    1052                 :             :             } else {
    1053                 :           1 :                 result = libspdm_asym_get_public_key_from_der(
    1054                 :             :                     spdm_context->connection_info.algorithm.base_asym_algo,
    1055                 :           1 :                     spdm_context->local_context.peer_public_key_provision,
    1056                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1057                 :             :                     &context);
    1058                 :             :             }
    1059                 :             :         } else {
    1060         [ -  + ]:           1 :             if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1061                 :           0 :                 result = libspdm_req_pqc_asym_get_public_key_from_der(
    1062                 :             :                     spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1063                 :           0 :                     spdm_context->local_context.peer_public_key_provision,
    1064                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1065                 :             :                     &context);
    1066                 :             :             } else {
    1067                 :           1 :                 result = libspdm_req_asym_get_public_key_from_der(
    1068                 :           1 :                     spdm_context->connection_info.algorithm.req_base_asym_alg,
    1069                 :           1 :                     spdm_context->local_context.peer_public_key_provision,
    1070                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1071                 :             :                     &context);
    1072                 :             :             }
    1073                 :             :         }
    1074         [ -  + ]:           2 :         if (!result) {
    1075                 :           0 :             return false;
    1076                 :             :         }
    1077                 :             :     } else {
    1078                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1079                 :             :         libspdm_get_peer_cert_chain_data(
    1080                 :             :             spdm_context, slot_id, (const void **)&cert_chain_data, &cert_chain_data_size);
    1081                 :             : 
    1082                 :             :         /* Get leaf cert from cert chain*/
    1083                 :             :         result = libspdm_x509_get_cert_from_cert_chain(
    1084                 :             :             cert_chain_data, cert_chain_data_size, -1, &cert_buffer, &cert_buffer_size);
    1085                 :             :         if (!result) {
    1086                 :             :             return false;
    1087                 :             :         }
    1088                 :             : 
    1089                 :             :         if (is_requester) {
    1090                 :             :             if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1091                 :             :                 result = libspdm_pqc_asym_get_public_key_from_x509(
    1092                 :             :                     spdm_context->connection_info.algorithm.pqc_asym_algo,
    1093                 :             :                     cert_buffer, cert_buffer_size, &context);
    1094                 :             :             } else {
    1095                 :             :                 result = libspdm_asym_get_public_key_from_x509(
    1096                 :             :                     spdm_context->connection_info.algorithm.base_asym_algo,
    1097                 :             :                     cert_buffer, cert_buffer_size, &context);
    1098                 :             :             }
    1099                 :             :         } else {
    1100                 :             :             if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1101                 :             :                 result = libspdm_req_pqc_asym_get_public_key_from_x509(
    1102                 :             :                     spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1103                 :             :                     cert_buffer, cert_buffer_size, &context);
    1104                 :             :             } else {
    1105                 :             :                 result = libspdm_req_asym_get_public_key_from_x509(
    1106                 :             :                     spdm_context->connection_info.algorithm.req_base_asym_alg,
    1107                 :             :                     cert_buffer, cert_buffer_size, &context);
    1108                 :             :             }
    1109                 :             :         }
    1110                 :             :         if (!result) {
    1111                 :             :             return false;
    1112                 :             :         }
    1113                 :             : #else
    1114                 :          21 :         context = spdm_context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
    1115         [ -  + ]:          21 :         LIBSPDM_ASSERT(context != NULL);
    1116                 :             : #endif
    1117                 :             :     }
    1118                 :             : 
    1119         [ +  + ]:          23 :     if (is_requester) {
    1120                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1121                 :             :         if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1122                 :             :             result = libspdm_pqc_asym_verify(
    1123                 :             :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1124                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo,
    1125                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1126                 :             :                 context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size);
    1127                 :             :             libspdm_pqc_asym_free(
    1128                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo, context);
    1129                 :             :         } else {
    1130                 :             :             result = libspdm_asym_verify_ex(
    1131                 :             :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1132                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo,
    1133                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1134                 :             :                 context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size,
    1135                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1136                 :             :             libspdm_asym_free(
    1137                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo, context);
    1138                 :             :         }
    1139                 :             : #else
    1140         [ -  + ]:          19 :         if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1141                 :           0 :             result = libspdm_pqc_asym_verify_hash(
    1142                 :           0 :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1143                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo,
    1144                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1145                 :             :                 context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size);
    1146         [ #  # ]:           0 :             if (slot_id == 0xFF) {
    1147                 :           0 :                 libspdm_pqc_asym_free(
    1148                 :             :                     spdm_context->connection_info.algorithm.pqc_asym_algo, context);
    1149                 :             :             }
    1150                 :             :         } else {
    1151                 :          19 :             result = libspdm_asym_verify_hash_ex(
    1152                 :          19 :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1153                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo,
    1154                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1155                 :             :                 context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size,
    1156                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1157         [ +  + ]:          19 :             if (slot_id == 0xFF) {
    1158                 :           1 :                 libspdm_asym_free(
    1159                 :             :                     spdm_context->connection_info.algorithm.base_asym_algo, context);
    1160                 :             :             }
    1161                 :             :         }
    1162                 :             : #endif
    1163                 :             :     } else {
    1164                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1165                 :             :         if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1166                 :             :             result = libspdm_req_pqc_asym_verify(
    1167                 :             :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1168                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1169                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1170                 :             :                 context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size);
    1171                 :             :             libspdm_req_pqc_asym_free(
    1172                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
    1173                 :             :         } else {
    1174                 :             :             result = libspdm_req_asym_verify_ex(
    1175                 :             :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1176                 :             :                 spdm_context->connection_info.algorithm.req_base_asym_alg,
    1177                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1178                 :             :                 context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size,
    1179                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1180                 :             :             libspdm_req_asym_free(
    1181                 :             :                 spdm_context->connection_info.algorithm.req_base_asym_alg, context);
    1182                 :             :         }
    1183                 :             : #else
    1184         [ -  + ]:           4 :         if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1185                 :           0 :             result = libspdm_req_pqc_asym_verify_hash(
    1186                 :           0 :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1187                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1188                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1189                 :             :                 context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size);
    1190         [ #  # ]:           0 :             if (slot_id == 0xFF) {
    1191                 :           0 :                 libspdm_req_pqc_asym_free(
    1192                 :             :                     spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
    1193                 :             :             }
    1194                 :             :         } else {
    1195                 :           4 :             result = libspdm_req_asym_verify_hash_ex(
    1196                 :           4 :                 spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
    1197                 :           4 :                 spdm_context->connection_info.algorithm.req_base_asym_alg,
    1198                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1199                 :             :                 context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size,
    1200                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1201         [ +  + ]:           4 :             if (slot_id == 0xFF) {
    1202                 :           1 :                 libspdm_req_asym_free(
    1203                 :           1 :                     spdm_context->connection_info.algorithm.req_base_asym_alg, context);
    1204                 :             :             }
    1205                 :             :         }
    1206                 :             : #endif
    1207                 :             :     }
    1208         [ +  + ]:          23 :     if (!result) {
    1209                 :           1 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
    1210                 :             :                        "!!! verify_challenge_signature - FAIL !!!\n"));
    1211                 :           1 :         return false;
    1212                 :             :     }
    1213                 :             : 
    1214                 :          22 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_challenge_signature - PASS !!!\n"));
    1215                 :             : 
    1216                 :          22 :     return true;
    1217                 :             : }
    1218                 :             : 
    1219                 :             : uint32_t
    1220                 :         148 : libspdm_get_measurement_summary_hash_size(libspdm_context_t *spdm_context,
    1221                 :             :                                           bool is_requester,
    1222                 :             :                                           uint8_t measurement_summary_hash_type)
    1223                 :             : {
    1224         [ +  + ]:         148 :     if (!libspdm_is_capabilities_flag_supported(
    1225                 :             :             spdm_context, is_requester, 0,
    1226                 :             :             SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP)) {
    1227                 :          93 :         return 0;
    1228                 :             :     }
    1229                 :             : 
    1230      [ +  +  + ]:          55 :     switch (measurement_summary_hash_type) {
    1231                 :          27 :     case SPDM_REQUEST_NO_MEASUREMENT_SUMMARY_HASH:
    1232                 :          27 :         return 0;
    1233                 :             :         break;
    1234                 :             : 
    1235                 :          26 :     case SPDM_REQUEST_TCB_COMPONENT_MEASUREMENT_HASH:
    1236                 :             :     case SPDM_REQUEST_ALL_MEASUREMENTS_HASH:
    1237                 :          26 :         return libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
    1238                 :             :         break;
    1239                 :           2 :     default:
    1240                 :           2 :         return 0;
    1241                 :             :         break;
    1242                 :             :     }
    1243                 :             : }
    1244                 :             : 
    1245                 :             : #if LIBSPDM_ENABLE_CAPABILITY_ENDPOINT_INFO_CAP
    1246                 :           9 : bool libspdm_generate_endpoint_info_signature(libspdm_context_t *spdm_context,
    1247                 :             :                                               libspdm_session_info_t *session_info,
    1248                 :             :                                               bool is_requester,
    1249                 :             :                                               uint8_t slot_id,
    1250                 :             :                                               uint8_t *signature)
    1251                 :             : {
    1252                 :             :     bool result;
    1253                 :             :     size_t signature_size;
    1254                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1255                 :             :     libspdm_il1il2_managed_buffer_t il1il2;
    1256                 :             :     uint8_t *il1il2_buffer;
    1257                 :             :     size_t il1il2_buffer_size;
    1258                 :             : #else
    1259                 :             :     uint8_t il1il2_hash[LIBSPDM_MAX_HASH_SIZE];
    1260                 :             :     size_t il1il2_hash_size;
    1261                 :             : #endif
    1262                 :             : 
    1263                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1264                 :             :     result = libspdm_calculate_il1il2(spdm_context, session_info, is_requester, &il1il2);
    1265                 :             :     il1il2_buffer = libspdm_get_managed_buffer(&il1il2);
    1266                 :             :     il1il2_buffer_size = libspdm_get_managed_buffer_size(&il1il2);
    1267                 :             : #else
    1268                 :           9 :     il1il2_hash_size = sizeof(il1il2_hash);
    1269                 :           9 :     result = libspdm_calculate_il1il2_hash(spdm_context, session_info, is_requester,
    1270                 :             :                                            &il1il2_hash_size, &il1il2_hash);
    1271                 :             : #endif
    1272         [ +  + ]:           9 :     if (is_requester) {
    1273                 :           5 :         libspdm_reset_message_encap_e(spdm_context, session_info);
    1274                 :             :     } else {
    1275                 :           4 :         libspdm_reset_message_e(spdm_context, session_info);
    1276                 :             :     }
    1277         [ -  + ]:           9 :     if (!result) {
    1278                 :           0 :         return false;
    1279                 :             :     }
    1280                 :             : 
    1281         [ +  + ]:           9 :     if (is_requester) {
    1282         [ -  + ]:           5 :         if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1283                 :           0 :             signature_size = libspdm_get_req_pqc_asym_signature_size(
    1284                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg);
    1285                 :             :         } else {
    1286                 :           5 :             signature_size = libspdm_get_req_asym_signature_size(
    1287                 :           5 :                 spdm_context->connection_info.algorithm.req_base_asym_alg);
    1288                 :             :         }
    1289                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1290                 :             :         result = libspdm_requester_data_sign(
    1291                 :             :             spdm_context,
    1292                 :             :             spdm_context->connection_info.version,
    1293                 :             :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
    1294                 :             :             SPDM_ENDPOINT_INFO,
    1295                 :             :             spdm_context->connection_info.algorithm.req_base_asym_alg,
    1296                 :             :             spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1297                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
    1298                 :             :             false, il1il2_buffer, il1il2_buffer_size, signature, &signature_size);
    1299                 :             : #else
    1300                 :          10 :         result = libspdm_requester_data_sign(
    1301                 :             :             spdm_context,
    1302                 :           5 :             spdm_context->connection_info.version,
    1303                 :           5 :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
    1304                 :             :             SPDM_ENDPOINT_INFO,
    1305                 :           5 :             spdm_context->connection_info.algorithm.req_base_asym_alg,
    1306                 :             :             spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1307                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
    1308                 :             :             true, il1il2_hash, il1il2_hash_size, signature, &signature_size);
    1309                 :             : #endif
    1310                 :             :     } else {
    1311         [ -  + ]:           4 :         if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1312                 :           0 :             signature_size = libspdm_get_pqc_asym_signature_size(
    1313                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo);
    1314                 :             :         } else {
    1315                 :           4 :             signature_size = libspdm_get_asym_signature_size(
    1316                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo);
    1317                 :             :         }
    1318                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1319                 :             :         result = libspdm_responder_data_sign(
    1320                 :             :             spdm_context,
    1321                 :             :             spdm_context->connection_info.version,
    1322                 :             :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
    1323                 :             :             SPDM_ENDPOINT_INFO,
    1324                 :             :             spdm_context->connection_info.algorithm.base_asym_algo,
    1325                 :             :             spdm_context->connection_info.algorithm.pqc_asym_algo,
    1326                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
    1327                 :             :             false, il1il2_buffer, il1il2_buffer_size, signature,
    1328                 :             :             &signature_size);
    1329                 :             : #else
    1330                 :           8 :         result = libspdm_responder_data_sign(
    1331                 :             :             spdm_context,
    1332                 :           4 :             spdm_context->connection_info.version,
    1333                 :           4 :             libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
    1334                 :             :             SPDM_ENDPOINT_INFO,
    1335                 :             :             spdm_context->connection_info.algorithm.base_asym_algo,
    1336                 :             :             spdm_context->connection_info.algorithm.pqc_asym_algo,
    1337                 :             :             spdm_context->connection_info.algorithm.base_hash_algo,
    1338                 :             :             true, il1il2_hash, il1il2_hash_size, signature,
    1339                 :             :             &signature_size);
    1340                 :             : #endif
    1341                 :             :     }
    1342                 :             : 
    1343                 :           9 :     return result;
    1344                 :             : }
    1345                 :             : #endif /* LIBSPDM_ENABLE_CAPABILITY_ENDPOINT_INFO_CAP */
    1346                 :             : 
    1347                 :          22 : bool libspdm_verify_endpoint_info_signature(libspdm_context_t *spdm_context,
    1348                 :             :                                             libspdm_session_info_t *session_info,
    1349                 :             :                                             bool is_requester,
    1350                 :             :                                             uint8_t slot_id,
    1351                 :             :                                             const void *sign_data,
    1352                 :             :                                             size_t sign_data_size)
    1353                 :             : {
    1354                 :             :     bool result;
    1355                 :             :     void *context;
    1356                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1357                 :             :     libspdm_il1il2_managed_buffer_t il1il2;
    1358                 :             :     uint8_t *il1il2_buffer;
    1359                 :             :     size_t il1il2_buffer_size;
    1360                 :             :     const uint8_t *cert_chain_data;
    1361                 :             :     size_t cert_chain_data_size;
    1362                 :             :     const uint8_t *cert_buffer;
    1363                 :             :     size_t cert_buffer_size;
    1364                 :             : #else
    1365                 :             :     uint8_t il1il2_hash[LIBSPDM_MAX_HASH_SIZE];
    1366                 :             :     size_t il1il2_hash_size;
    1367                 :             : #endif
    1368                 :             : 
    1369                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1370                 :             :     result = libspdm_calculate_il1il2(spdm_context, session_info,!is_requester, &il1il2);
    1371                 :             :     il1il2_buffer = libspdm_get_managed_buffer(&il1il2);
    1372                 :             :     il1il2_buffer_size = libspdm_get_managed_buffer_size(&il1il2);
    1373                 :             : #else
    1374                 :          22 :     il1il2_hash_size = sizeof(il1il2_hash);
    1375                 :          22 :     result = libspdm_calculate_il1il2_hash(spdm_context, session_info, !is_requester,
    1376                 :          22 :                                            &il1il2_hash_size, il1il2_hash);
    1377                 :             : #endif
    1378         [ +  + ]:          22 :     if (is_requester) {
    1379                 :          13 :         libspdm_reset_message_e(spdm_context, session_info);
    1380                 :             :     } else {
    1381                 :           9 :         libspdm_reset_message_encap_e(spdm_context, session_info);
    1382                 :             :     }
    1383         [ -  + ]:          22 :     if (!result) {
    1384                 :           0 :         return false;
    1385                 :             :     }
    1386                 :             : 
    1387         [ +  + ]:          22 :     if (slot_id == 0xF) {
    1388         [ +  + ]:           4 :         if (is_requester) {
    1389         [ +  - ]:           2 :             if (spdm_context->connection_info.algorithm.base_asym_algo != 0) {
    1390                 :           2 :                 result = libspdm_asym_get_public_key_from_der(
    1391                 :             :                     spdm_context->connection_info.algorithm.base_asym_algo,
    1392                 :           2 :                     spdm_context->local_context.peer_public_key_provision,
    1393                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1394                 :             :                     &context);
    1395                 :             :             }
    1396         [ -  + ]:           2 :             if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1397                 :           0 :                 result = libspdm_pqc_asym_get_public_key_from_der(
    1398                 :             :                     spdm_context->connection_info.algorithm.pqc_asym_algo,
    1399                 :           0 :                     spdm_context->local_context.peer_public_key_provision,
    1400                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1401                 :             :                     &context);
    1402                 :             :             }
    1403                 :             :         } else {
    1404         [ +  - ]:           2 :             if (spdm_context->connection_info.algorithm.req_base_asym_alg != 0) {
    1405                 :           2 :                 result = libspdm_req_asym_get_public_key_from_der(
    1406                 :           2 :                     spdm_context->connection_info.algorithm.req_base_asym_alg,
    1407                 :           2 :                     spdm_context->local_context.peer_public_key_provision,
    1408                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1409                 :             :                     &context);
    1410                 :             :             }
    1411         [ -  + ]:           2 :             if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1412                 :           0 :                 result = libspdm_req_pqc_asym_get_public_key_from_der(
    1413                 :             :                     spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1414                 :           0 :                     spdm_context->local_context.peer_public_key_provision,
    1415                 :             :                     spdm_context->local_context.peer_public_key_provision_size,
    1416                 :             :                     &context);
    1417                 :             :             }
    1418                 :             :         }
    1419         [ -  + ]:           4 :         if (!result) {
    1420                 :           0 :             return false;
    1421                 :             :         }
    1422                 :             :     } else {
    1423                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1424                 :             :         libspdm_get_peer_cert_chain_data(
    1425                 :             :             spdm_context, slot_id, (const void **)&cert_chain_data, &cert_chain_data_size);
    1426                 :             : 
    1427                 :             :         /* Get leaf cert from cert chain*/
    1428                 :             :         result = libspdm_x509_get_cert_from_cert_chain(cert_chain_data,
    1429                 :             :                                                        cert_chain_data_size, -1,
    1430                 :             :                                                        &cert_buffer, &cert_buffer_size);
    1431                 :             :         if (!result) {
    1432                 :             :             return false;
    1433                 :             :         }
    1434                 :             : 
    1435                 :             :         if (is_requester) {
    1436                 :             :             result = libspdm_asym_get_public_key_from_x509(
    1437                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo,
    1438                 :             :                 cert_buffer, cert_buffer_size, &context);
    1439                 :             :         } else {
    1440                 :             :             result = libspdm_req_asym_get_public_key_from_x509(
    1441                 :             :                 spdm_context->connection_info.algorithm.req_base_asym_alg,
    1442                 :             :                 cert_buffer, cert_buffer_size, &context);
    1443                 :             :         }
    1444                 :             :         if (!result) {
    1445                 :             :             return false;
    1446                 :             :         }
    1447                 :             : #else
    1448                 :          18 :         context = spdm_context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
    1449         [ -  + ]:          18 :         LIBSPDM_ASSERT(context != NULL);
    1450                 :             : #endif
    1451                 :             :     }
    1452                 :             : 
    1453         [ +  + ]:          22 :     if (is_requester) {
    1454         [ +  - ]:          13 :         if (spdm_context->connection_info.algorithm.base_asym_algo != 0) {
    1455                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1456                 :             :             result = libspdm_asym_verify_ex(
    1457                 :             :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1458                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo,
    1459                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1460                 :             :                 context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size,
    1461                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1462                 :             :             libspdm_asym_free(
    1463                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo, context);
    1464                 :             : #else
    1465                 :          13 :             result = libspdm_asym_verify_hash_ex(
    1466                 :          13 :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1467                 :             :                 spdm_context->connection_info.algorithm.base_asym_algo,
    1468                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1469                 :             :                 context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size,
    1470                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1471         [ +  + ]:          13 :             if (slot_id == 0xF) {
    1472                 :           2 :                 libspdm_asym_free(
    1473                 :             :                     spdm_context->connection_info.algorithm.base_asym_algo, context);
    1474                 :             :             }
    1475                 :             : #endif
    1476                 :             :         }
    1477         [ -  + ]:          13 :         if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
    1478                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1479                 :             :             result = libspdm_pqc_asym_verify(
    1480                 :             :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1481                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo,
    1482                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1483                 :             :                 context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size);
    1484                 :             :             libspdm_pqc_asym_free(
    1485                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo, context);
    1486                 :             : #else
    1487                 :           0 :             result = libspdm_pqc_asym_verify_hash(
    1488                 :           0 :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1489                 :             :                 spdm_context->connection_info.algorithm.pqc_asym_algo,
    1490                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1491                 :             :                 context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size);
    1492         [ #  # ]:           0 :             if (slot_id == 0xF) {
    1493                 :           0 :                 libspdm_pqc_asym_free(
    1494                 :             :                     spdm_context->connection_info.algorithm.pqc_asym_algo, context);
    1495                 :             :             }
    1496                 :             : #endif
    1497                 :             :         }
    1498                 :             :     } else {
    1499         [ +  - ]:           9 :         if (spdm_context->connection_info.algorithm.req_base_asym_alg != 0) {
    1500                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1501                 :             :             result = libspdm_req_asym_verify_ex(
    1502                 :             :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1503                 :             :                 spdm_context->connection_info.algorithm.req_base_asym_alg,
    1504                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1505                 :             :                 context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size,
    1506                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1507                 :             :             libspdm_req_asym_free(
    1508                 :             :                 spdm_context->connection_info.algorithm.req_base_asym_alg, context);
    1509                 :             : #else
    1510                 :           9 :             result = libspdm_req_asym_verify_hash_ex(
    1511                 :           9 :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1512                 :           9 :                 spdm_context->connection_info.algorithm.req_base_asym_alg,
    1513                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1514                 :             :                 context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size,
    1515                 :             :                 &spdm_context->spdm_10_11_verify_signature_endian);
    1516         [ +  + ]:           9 :             if (slot_id == 0xF) {
    1517                 :           2 :                 libspdm_req_asym_free(
    1518                 :           2 :                     spdm_context->connection_info.algorithm.req_base_asym_alg, context);
    1519                 :             :             }
    1520                 :             : #endif
    1521                 :             :         }
    1522         [ -  + ]:           9 :         if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
    1523                 :             : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
    1524                 :             :             result = libspdm_req_pqc_asym_verify(
    1525                 :             :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1526                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1527                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1528                 :             :                 context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size);
    1529                 :             :             libspdm_req_pqc_asym_free(
    1530                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
    1531                 :             : #else
    1532                 :           0 :             result = libspdm_req_pqc_asym_verify_hash(
    1533                 :           0 :                 spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
    1534                 :             :                 spdm_context->connection_info.algorithm.req_pqc_asym_alg,
    1535                 :             :                 spdm_context->connection_info.algorithm.base_hash_algo,
    1536                 :             :                 context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size);
    1537         [ #  # ]:           0 :             if (slot_id == 0xF) {
    1538                 :           0 :                 libspdm_req_pqc_asym_free(
    1539                 :             :                     spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
    1540                 :             :             }
    1541                 :             : #endif
    1542                 :             :         }
    1543                 :             :     }
    1544         [ +  + ]:          22 :     if (!result) {
    1545                 :           3 :         LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_endpoint_info_signature - FAIL !!!\n"));
    1546                 :           3 :         return false;
    1547                 :             :     }
    1548                 :             : 
    1549                 :          19 :     LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_endpoint_info_signature - PASS !!!\n"));
    1550                 :          19 :     return true;
    1551                 :             : }
        

Generated by: LCOV version 2.0-1