Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2024-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_requester_lib.h"
8 : :
9 : : #if LIBSPDM_ENABLE_CAPABILITY_GET_KEY_PAIR_INFO_CAP
10 : :
11 : : #pragma pack(1)
12 : : typedef struct {
13 : : spdm_message_header_t header;
14 : : uint8_t total_key_pairs;
15 : : uint8_t key_pair_id;
16 : : uint16_t capabilities;
17 : : uint16_t key_usage_capabilities;
18 : : uint16_t current_key_usage;
19 : : uint32_t asym_algo_capabilities;
20 : : uint32_t current_asym_algo;
21 : : uint16_t public_key_info_len;
22 : : uint8_t assoc_cert_slot_mask;
23 : : uint8_t public_key_info[SPDM_MAX_PUBLIC_KEY_INFO_LEN];
24 : : uint8_t pqc_asym_algo_cap_len;
25 : : uint32_t pqc_asym_algo_capabilities;
26 : : uint8_t current_pqc_asym_algo_len;
27 : : uint32_t current_pqc_asym_algo;
28 : : } libspdm_key_pair_info_response_max_t;
29 : : #pragma pack()
30 : :
31 : : /**
32 : : * This function sends GET_KEY_PAIR_INFO and receives KEY_PAIR_INFO *
33 : : *
34 : : * @param spdm_context A pointer to the SPDM context.
35 : : *
36 : : **/
37 : 21 : static libspdm_return_t libspdm_try_get_key_pair_info(libspdm_context_t *spdm_context,
38 : : const uint32_t *session_id,
39 : : uint8_t key_pair_id,
40 : : uint8_t *total_key_pairs,
41 : : uint16_t *capabilities,
42 : : uint16_t *key_usage_capabilities,
43 : : uint16_t *current_key_usage,
44 : : uint32_t *asym_algo_capabilities,
45 : : uint32_t *current_asym_algo,
46 : : uint32_t *pqc_asym_algo_capabilities,
47 : : uint32_t *current_pqc_asym_algo,
48 : : uint8_t *assoc_cert_slot_mask,
49 : : uint16_t *public_key_info_len,
50 : : void *public_key_info
51 : : )
52 : : {
53 : : libspdm_return_t status;
54 : : spdm_get_key_pair_info_request_t *spdm_request;
55 : : size_t spdm_request_size;
56 : : libspdm_key_pair_info_response_max_t *spdm_response;
57 : : size_t spdm_response_size;
58 : : uint8_t *message;
59 : : size_t message_size;
60 : : size_t transport_header_size;
61 : : libspdm_session_info_t *session_info;
62 : : libspdm_session_state_t session_state;
63 : : uint8_t pqc_asym_algo_cap_raw_len;
64 : : uint8_t pqc_asym_algo_cap_copy_len;
65 : : uint8_t current_pqc_asym_algo_raw_len;
66 : : uint8_t current_pqc_asym_algo_copy_len;
67 : : uint8_t *ptr;
68 : : uint32_t rsp_pqc_asym_algo_capabilities;
69 : : uint32_t rsp_current_pqc_asym_algo;
70 : :
71 : : /* -=[Check Parameters Phase]=- */
72 [ - + ]: 21 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_13) {
73 : 0 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
74 : : }
75 : :
76 [ - + ]: 21 : if (key_pair_id == 0) {
77 : 0 : return LIBSPDM_STATUS_INVALID_PARAMETER;
78 : : }
79 : :
80 : : /* -=[Verify State Phase]=- */
81 [ - + ]: 21 : if (!libspdm_is_capabilities_flag_supported(
82 : : spdm_context, true, 0,
83 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_GET_KEY_PAIR_INFO_CAP)) {
84 : 0 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
85 : : }
86 [ - + ]: 21 : if (spdm_context->connection_info.connection_state < LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
87 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
88 : : }
89 : :
90 : 21 : session_info = NULL;
91 [ - + ]: 21 : if (session_id != NULL) {
92 : 0 : session_info = libspdm_get_session_info_via_session_id(spdm_context, *session_id);
93 [ # # ]: 0 : if (session_info == NULL) {
94 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
95 : : }
96 : 0 : session_state = libspdm_secured_message_get_session_state(
97 : : session_info->secured_message_context);
98 [ # # ]: 0 : if (session_state != LIBSPDM_SESSION_STATE_ESTABLISHED) {
99 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
100 : : }
101 : : }
102 : :
103 : : /* -=[Construct Request Phase]=- */
104 : 21 : transport_header_size = spdm_context->local_context.capability.transport_header_size;
105 : 21 : status = libspdm_acquire_sender_buffer (spdm_context, &message_size, (void **)&message);
106 [ - + ]: 21 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
107 : 0 : return status;
108 : : }
109 [ - + ]: 21 : LIBSPDM_ASSERT (message_size >= transport_header_size +
110 : : spdm_context->local_context.capability.transport_tail_size);
111 : 21 : spdm_request = (void *)(message + transport_header_size);
112 : 21 : spdm_request_size = message_size - transport_header_size -
113 : 21 : spdm_context->local_context.capability.transport_tail_size;
114 : :
115 [ - + ]: 21 : LIBSPDM_ASSERT(spdm_request_size >= sizeof(spdm_get_key_pair_info_request_t));
116 : 21 : spdm_request->header.spdm_version = libspdm_get_connection_version (spdm_context);
117 : 21 : spdm_request->header.request_response_code = SPDM_GET_KEY_PAIR_INFO;
118 : 21 : spdm_request->header.param1 = 0;
119 : 21 : spdm_request->header.param2 = 0;
120 : 21 : spdm_request->key_pair_id = key_pair_id;
121 : 21 : spdm_request_size = sizeof(spdm_get_key_pair_info_request_t);
122 : :
123 : : /* -=[Send Request Phase]=- */
124 : 21 : status = libspdm_send_spdm_request(spdm_context, session_id, spdm_request_size, spdm_request);
125 [ + + ]: 21 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
126 : 1 : libspdm_release_sender_buffer (spdm_context);
127 : 1 : return status;
128 : : }
129 : 20 : libspdm_release_sender_buffer (spdm_context);
130 : 20 : spdm_request = (void *)spdm_context->last_spdm_request;
131 : :
132 : : /* -=[Receive Response Phase]=- */
133 : 20 : status = libspdm_acquire_receiver_buffer (spdm_context, &message_size, (void **)&message);
134 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
135 : 0 : return status;
136 : : }
137 [ - + ]: 20 : LIBSPDM_ASSERT (message_size >= transport_header_size);
138 : 20 : spdm_response = (void *)(message);
139 : 20 : spdm_response_size = message_size;
140 : :
141 : 20 : status = libspdm_receive_spdm_response(
142 : : spdm_context, session_id, &spdm_response_size, (void **)&spdm_response);
143 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
144 : 0 : goto receive_done;
145 : : }
146 : :
147 : : /* -=[Validate Response Phase]=- */
148 [ - + ]: 20 : if (spdm_response_size < sizeof(spdm_message_header_t)) {
149 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
150 : 0 : goto receive_done;
151 : : }
152 [ - + ]: 20 : if (spdm_response->header.request_response_code == SPDM_ERROR) {
153 : 0 : status = libspdm_handle_error_response_main(
154 : : spdm_context, session_id,
155 : : &spdm_response_size,
156 : : (void **)&spdm_response, SPDM_GET_KEY_PAIR_INFO, SPDM_KEY_PAIR_INFO);
157 [ # # ]: 0 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
158 : 0 : goto receive_done;
159 : : }
160 [ - + ]: 20 : } else if (spdm_response->header.request_response_code != SPDM_KEY_PAIR_INFO) {
161 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
162 : 0 : goto receive_done;
163 : : }
164 [ - + ]: 20 : if (spdm_response->header.spdm_version != spdm_request->header.spdm_version) {
165 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
166 : 0 : goto receive_done;
167 : : }
168 : :
169 [ + + ]: 20 : if (spdm_response_size < sizeof(spdm_key_pair_info_response_t)) {
170 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
171 : 1 : goto receive_done;
172 : : }
173 : :
174 [ + + ]: 19 : if ((spdm_response->key_pair_id != key_pair_id) ||
175 [ + + ]: 18 : (spdm_response->key_pair_id > (spdm_response->total_key_pairs))) {
176 : 2 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
177 : 2 : goto receive_done;
178 : : }
179 : :
180 : 17 : if (spdm_response_size < sizeof(spdm_key_pair_info_response_t) +
181 [ - + ]: 17 : spdm_response->public_key_info_len) {
182 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
183 : 0 : goto receive_done;
184 : : }
185 : :
186 : 17 : rsp_pqc_asym_algo_capabilities = 0;
187 : 17 : rsp_current_pqc_asym_algo = 0;
188 [ + + ]: 17 : if (spdm_response->header.spdm_version >= SPDM_MESSAGE_VERSION_14) {
189 : 1 : if (spdm_response_size < sizeof(spdm_key_pair_info_response_t) +
190 [ - + ]: 1 : spdm_response->public_key_info_len + sizeof(uint8_t)) {
191 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
192 : 0 : goto receive_done;
193 : : }
194 : 1 : ptr = (uint8_t *)spdm_response + sizeof(spdm_key_pair_info_response_t) + spdm_response->public_key_info_len;
195 : :
196 : 1 : pqc_asym_algo_cap_raw_len = *ptr;
197 : 1 : if (spdm_response_size < sizeof(spdm_key_pair_info_response_t) +
198 : 1 : spdm_response->public_key_info_len + sizeof(uint8_t) +
199 [ - + ]: 1 : pqc_asym_algo_cap_raw_len + sizeof(uint8_t)) {
200 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
201 : 0 : goto receive_done;
202 : : }
203 : 1 : pqc_asym_algo_cap_copy_len = (uint8_t)LIBSPDM_MIN(pqc_asym_algo_cap_raw_len,
204 : : sizeof(uint32_t));
205 : 1 : libspdm_copy_mem (&rsp_pqc_asym_algo_capabilities, sizeof(rsp_pqc_asym_algo_capabilities),
206 : 1 : ptr + sizeof(uint8_t), pqc_asym_algo_cap_copy_len);
207 : :
208 : 1 : current_pqc_asym_algo_raw_len = *(ptr + sizeof(uint8_t) + pqc_asym_algo_cap_raw_len);
209 : 1 : if (spdm_response_size < sizeof(spdm_key_pair_info_response_t) +
210 : 1 : spdm_response->public_key_info_len + sizeof(uint8_t) +
211 [ - + ]: 1 : pqc_asym_algo_cap_raw_len + sizeof(uint8_t) +
212 : : current_pqc_asym_algo_raw_len) {
213 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
214 : 0 : goto receive_done;
215 : : }
216 : 1 : current_pqc_asym_algo_copy_len = (uint8_t)LIBSPDM_MIN(current_pqc_asym_algo_raw_len,
217 : : sizeof(uint32_t));
218 : 1 : libspdm_copy_mem (&rsp_current_pqc_asym_algo, sizeof(rsp_current_pqc_asym_algo),
219 : 1 : ptr + sizeof(uint8_t) + pqc_asym_algo_cap_raw_len + sizeof(uint8_t),
220 : : current_pqc_asym_algo_copy_len);
221 : :
222 : 1 : rsp_pqc_asym_algo_capabilities &= SPDM_KEY_PAIR_PQC_ASYM_ALGO_CAP_MASK;
223 : 1 : rsp_current_pqc_asym_algo &= SPDM_KEY_PAIR_PQC_ASYM_ALGO_CAP_MASK;
224 : : } else {
225 : 16 : spdm_response_size = sizeof(spdm_key_pair_info_response_t) + spdm_response->public_key_info_len;
226 : : }
227 : :
228 : : /* -=[Process Response Phase]=- */
229 : :
230 : : /*If responder doesn't support SET_KEY_PAIR_INFO_CAP, the capabilities should be 0*/
231 [ + + ]: 17 : if ((!libspdm_is_capabilities_flag_supported(
232 : : spdm_context, true, 0,
233 : 1 : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_SET_KEY_PAIR_INFO_CAP)) &&
234 [ + - ]: 1 : ((spdm_response->capabilities & SPDM_KEY_PAIR_CAP_MASK) != 0)) {
235 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
236 : 1 : goto receive_done;
237 : : }
238 : :
239 : 16 : *total_key_pairs = spdm_response->total_key_pairs;
240 : 16 : *capabilities = spdm_response->capabilities & SPDM_KEY_PAIR_CAP_MASK;
241 [ + + ]: 16 : if (((*capabilities & SPDM_KEY_PAIR_CAP_SHAREABLE_CAP) != 0) &&
242 [ + - ]: 1 : ((*capabilities & SPDM_KEY_PAIR_CAP_CERT_ASSOC_CAP) == 0)) {
243 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
244 : 1 : goto receive_done;
245 : : }
246 : :
247 : 15 : *key_usage_capabilities = (spdm_response->key_usage_capabilities) & SPDM_KEY_USAGE_BIT_MASK;
248 [ + + ]: 15 : if (*key_usage_capabilities == 0) {
249 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
250 : 1 : goto receive_done;
251 : : }
252 : 14 : *current_key_usage = (spdm_response->current_key_usage) & SPDM_KEY_USAGE_BIT_MASK;
253 [ + + ]: 14 : if ((*key_usage_capabilities | *current_key_usage) != *key_usage_capabilities) {
254 : 2 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
255 : 2 : goto receive_done;
256 : : }
257 : :
258 : 12 : *asym_algo_capabilities = (spdm_response->asym_algo_capabilities) &
259 : : SPDM_KEY_PAIR_ASYM_ALGO_CAP_MASK;
260 [ + + ]: 12 : if (*asym_algo_capabilities == 0) {
261 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
262 : 1 : goto receive_done;
263 : : }
264 : 11 : *current_asym_algo = (spdm_response->current_asym_algo) & SPDM_KEY_PAIR_ASYM_ALGO_CAP_MASK;
265 [ + + ]: 11 : if (!libspdm_onehot0(*current_asym_algo)) {
266 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
267 : 1 : goto receive_done;
268 : : }
269 [ + + ]: 10 : if ((*asym_algo_capabilities | *current_asym_algo) != *asym_algo_capabilities) {
270 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
271 : 1 : goto receive_done;
272 : : }
273 : :
274 [ - + ]: 9 : if (!libspdm_onehot0(rsp_current_pqc_asym_algo)) {
275 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
276 : 0 : goto receive_done;
277 : : }
278 [ - + ]: 9 : if ((rsp_pqc_asym_algo_capabilities | rsp_current_pqc_asym_algo) != rsp_pqc_asym_algo_capabilities) {
279 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
280 : 0 : goto receive_done;
281 : : }
282 [ + + - + ]: 9 : if ((*current_asym_algo != 0) && (rsp_current_pqc_asym_algo != 0)) {
283 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
284 : 0 : goto receive_done;
285 : : }
286 : :
287 [ + - ]: 9 : if (pqc_asym_algo_capabilities != NULL) {
288 : 9 : *pqc_asym_algo_capabilities = rsp_pqc_asym_algo_capabilities;
289 : : }
290 [ + - ]: 9 : if (current_pqc_asym_algo != NULL) {
291 : 9 : *current_pqc_asym_algo = rsp_current_pqc_asym_algo;
292 : : }
293 : :
294 : 9 : *assoc_cert_slot_mask = spdm_response->assoc_cert_slot_mask;
295 [ + + ]: 9 : if (!libspdm_onehot0(*assoc_cert_slot_mask) &&
296 [ + - + - ]: 2 : (((*capabilities & SPDM_KEY_PAIR_CAP_SHAREABLE_CAP) == 0) &&
297 : 1 : (libspdm_is_capabilities_flag_supported(
298 : : spdm_context, true, 0,
299 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_SET_KEY_PAIR_INFO_CAP)))) {
300 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
301 : 1 : goto receive_done;
302 : : }
303 : :
304 [ + + ]: 8 : if (*public_key_info_len < spdm_response->public_key_info_len) {
305 : 1 : status = LIBSPDM_STATUS_BUFFER_TOO_SMALL;
306 : 1 : goto receive_done;
307 : : }
308 : 7 : *public_key_info_len = spdm_response->public_key_info_len;
309 : :
310 : 7 : libspdm_copy_mem(public_key_info,
311 : 7 : spdm_response->public_key_info_len,
312 : 7 : spdm_response->public_key_info,
313 : 7 : spdm_response->public_key_info_len);
314 : :
315 : 7 : status = LIBSPDM_STATUS_SUCCESS;
316 : :
317 : : /* -=[Log Message Phase]=- */
318 : : #if LIBSPDM_ENABLE_MSG_LOG
319 : 7 : libspdm_append_msg_log(spdm_context, spdm_response, spdm_response_size);
320 : : #endif /* LIBSPDM_ENABLE_MSG_LOG */
321 : :
322 : 20 : receive_done:
323 : 20 : libspdm_release_receiver_buffer (spdm_context);
324 : 20 : return status;
325 : : }
326 : :
327 : 21 : libspdm_return_t libspdm_get_key_pair_info(void *spdm_context, const uint32_t *session_id,
328 : : uint8_t key_pair_id, uint8_t *total_key_pairs,
329 : : uint16_t *capabilities,
330 : : uint16_t *key_usage_capabilities,
331 : : uint16_t *current_key_usage,
332 : : uint32_t *asym_algo_capabilities,
333 : : uint32_t *current_asym_algo,
334 : : uint32_t *pqc_asym_algo_capabilities,
335 : : uint32_t *current_pqc_asym_algo,
336 : : uint8_t *assoc_cert_slot_mask,
337 : : uint16_t *public_key_info_len,
338 : : void *public_key_info
339 : : )
340 : : {
341 : : libspdm_context_t *context;
342 : : size_t retry;
343 : : uint64_t retry_delay_time;
344 : : libspdm_return_t status;
345 : :
346 : 21 : context = spdm_context;
347 : 21 : context->crypto_request = true;
348 : 21 : retry = context->retry_times;
349 : 21 : retry_delay_time = context->retry_delay_time;
350 : : do {
351 : 21 : status = libspdm_try_get_key_pair_info(context, session_id, key_pair_id,
352 : : total_key_pairs, capabilities,
353 : : key_usage_capabilities, current_key_usage,
354 : : asym_algo_capabilities, current_asym_algo,
355 : : pqc_asym_algo_capabilities, current_pqc_asym_algo,
356 : : assoc_cert_slot_mask, public_key_info_len,
357 : : public_key_info);
358 [ + - ]: 21 : if (status != LIBSPDM_STATUS_BUSY_PEER) {
359 : 21 : return status;
360 : : }
361 : :
362 : 0 : libspdm_sleep(retry_delay_time);
363 [ # # ]: 0 : } while (retry-- != 0);
364 : :
365 : 0 : return status;
366 : : }
367 : :
368 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_GET_KEY_PAIR_INFO_CAP */
|