Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2021-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_requester_lib.h"
8 : : #include "internal/libspdm_secured_message_lib.h"
9 : :
10 : : #if LIBSPDM_ENABLE_CAPABILITY_KEY_EX_CAP
11 : :
12 : : #pragma pack(1)
13 : : typedef struct {
14 : : spdm_message_header_t header;
15 : : uint16_t req_session_id;
16 : : uint8_t session_policy;
17 : : uint8_t reserved;
18 : : uint8_t random_data[SPDM_RANDOM_DATA_SIZE];
19 : : uint8_t exchange_data[LIBSPDM_REQ_EXCHANGE_DATA_MAX_SIZE];
20 : : uint16_t opaque_length;
21 : : uint8_t opaque_data[SPDM_MAX_OPAQUE_DATA_SIZE];
22 : : } libspdm_key_exchange_request_mine_t;
23 : :
24 : : typedef struct {
25 : : spdm_message_header_t header;
26 : : uint16_t rsp_session_id;
27 : : uint8_t mut_auth_requested;
28 : : uint8_t req_slot_id_param;
29 : : uint8_t random_data[SPDM_RANDOM_DATA_SIZE];
30 : : uint8_t exchange_data[LIBSPDM_RSP_EXCHANGE_DATA_MAX_SIZE];
31 : : uint8_t measurement_summary_hash[LIBSPDM_MAX_HASH_SIZE];
32 : : uint16_t opaque_length;
33 : : uint8_t opaque_data[SPDM_MAX_OPAQUE_DATA_SIZE];
34 : : uint8_t signature[LIBSPDM_RSP_SIGNATURE_DATA_MAX_SIZE];
35 : : uint8_t verify_data[LIBSPDM_MAX_HASH_SIZE];
36 : : } libspdm_key_exchange_response_max_t;
37 : : #pragma pack()
38 : :
39 : 20 : bool libspdm_verify_key_exchange_rsp_hmac(libspdm_context_t *spdm_context,
40 : : libspdm_session_info_t *session_info,
41 : : const void *hmac_data,
42 : : size_t hmac_data_size)
43 : : {
44 : : size_t hash_size;
45 : : uint8_t calc_hmac_data[LIBSPDM_MAX_HASH_SIZE];
46 : : bool result;
47 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
48 : : uint8_t slot_id;
49 : : const uint8_t *cert_chain_buffer;
50 : : size_t cert_chain_buffer_size;
51 : : uint8_t *th_curr_data;
52 : : size_t th_curr_data_size;
53 : : libspdm_th_managed_buffer_t th_curr;
54 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
55 : : #endif
56 : :
57 : 20 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
58 [ - + ]: 20 : LIBSPDM_ASSERT(hash_size == hmac_data_size);
59 : :
60 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
61 : : slot_id = session_info->peer_used_cert_chain_slot_id;
62 : : LIBSPDM_ASSERT((slot_id < SPDM_MAX_SLOT_COUNT) || (slot_id == 0xFF));
63 : : if (slot_id == 0xFF) {
64 : : result = libspdm_get_peer_public_key_buffer(
65 : : spdm_context, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
66 : : if (!result) {
67 : : return false;
68 : : }
69 : : } else {
70 : : libspdm_get_peer_cert_chain_buffer(
71 : : spdm_context, slot_id, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
72 : : }
73 : :
74 : : result = libspdm_calculate_th_for_exchange(
75 : : spdm_context, session_info, cert_chain_buffer,
76 : : cert_chain_buffer_size, &th_curr);
77 : : if (!result) {
78 : : return false;
79 : : }
80 : : th_curr_data = libspdm_get_managed_buffer(&th_curr);
81 : : th_curr_data_size = libspdm_get_managed_buffer_size(&th_curr);
82 : :
83 : : result = libspdm_hash_all (spdm_context->connection_info.algorithm.base_hash_algo,
84 : : th_curr_data, th_curr_data_size, hash_data);
85 : : if (!result) {
86 : : return false;
87 : : }
88 : :
89 : : result = libspdm_hmac_all_with_response_finished_key(
90 : : session_info->secured_message_context, hash_data,
91 : : hash_size, calc_hmac_data);
92 : : if (!result) {
93 : : return false;
94 : : }
95 : : #else
96 : 20 : result = libspdm_calculate_th_hmac_for_exchange_rsp(
97 : : spdm_context, session_info, &hash_size, calc_hmac_data);
98 [ - + ]: 20 : if (!result) {
99 : 0 : return false;
100 : : }
101 : : #endif
102 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "th_curr hmac - "));
103 : 20 : LIBSPDM_INTERNAL_DUMP_DATA(calc_hmac_data, hash_size);
104 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
105 : :
106 [ - + ]: 20 : if (!libspdm_consttime_is_mem_equal(calc_hmac_data, hmac_data, hash_size)) {
107 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_key_exchange_hmac - FAIL !!!\n"));
108 : 0 : return false;
109 : : }
110 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_key_exchange_hmac - PASS !!!\n"));
111 : :
112 : 20 : return true;
113 : : }
114 : :
115 : 23 : bool libspdm_verify_key_exchange_rsp_signature(
116 : : libspdm_context_t *spdm_context, libspdm_session_info_t *session_info,
117 : : const void *sign_data, size_t sign_data_size)
118 : : {
119 : : bool result;
120 : : void *context;
121 : : uint8_t slot_id;
122 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
123 : : const uint8_t *cert_chain_buffer;
124 : : size_t cert_chain_buffer_size;
125 : : uint8_t *th_curr_data;
126 : : size_t th_curr_data_size;
127 : : libspdm_th_managed_buffer_t th_curr;
128 : : const uint8_t *cert_chain_data;
129 : : size_t cert_chain_data_size;
130 : : const uint8_t *cert_buffer;
131 : : size_t cert_buffer_size;
132 : : #endif
133 : : #if !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT) || (LIBSPDM_DEBUG_PRINT_ENABLE)
134 : : size_t hash_size;
135 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
136 : :
137 : 23 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
138 : : #endif
139 : :
140 : 23 : slot_id = session_info->peer_used_cert_chain_slot_id;
141 [ + + - + ]: 23 : LIBSPDM_ASSERT((slot_id < SPDM_MAX_SLOT_COUNT) || (slot_id == 0xFF));
142 : :
143 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
144 : : if (slot_id == 0xFF) {
145 : : result = libspdm_get_peer_public_key_buffer(
146 : : spdm_context, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
147 : : if (!result) {
148 : : return false;
149 : : }
150 : : } else {
151 : : libspdm_get_peer_cert_chain_buffer(
152 : : spdm_context, slot_id, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
153 : : }
154 : :
155 : : result = libspdm_calculate_th_for_exchange(
156 : : spdm_context, session_info, cert_chain_buffer,
157 : : cert_chain_buffer_size, &th_curr);
158 : : if (!result) {
159 : : return false;
160 : : }
161 : : th_curr_data = libspdm_get_managed_buffer(&th_curr);
162 : : th_curr_data_size = libspdm_get_managed_buffer_size(&th_curr);
163 : :
164 : : /* Debug code only - required for debug print of th_curr hash below*/
165 : : LIBSPDM_DEBUG_CODE(
166 : : if (!libspdm_hash_all(
167 : : spdm_context->connection_info.algorithm.base_hash_algo,
168 : : th_curr_data, th_curr_data_size, hash_data)) {
169 : : return false;
170 : : }
171 : : );
172 : : #else
173 : 23 : result = libspdm_calculate_th_hash_for_exchange(
174 : : spdm_context, session_info, &hash_size, hash_data);
175 [ - + ]: 23 : if (!result) {
176 : 0 : return false;
177 : : }
178 : : #endif
179 : 23 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "th_curr hash - "));
180 : 23 : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
181 : 23 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
182 : :
183 : 23 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "signature - "));
184 : 23 : LIBSPDM_INTERNAL_DUMP_DATA(sign_data, sign_data_size);
185 : 23 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
186 : :
187 [ + + ]: 23 : if (slot_id == 0xFF) {
188 [ - + ]: 1 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
189 : 0 : result = libspdm_pqc_asym_get_public_key_from_der(
190 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
191 : 0 : spdm_context->local_context.peer_public_key_provision,
192 : : spdm_context->local_context.peer_public_key_provision_size,
193 : : &context);
194 : : } else {
195 : 1 : result = libspdm_asym_get_public_key_from_der(
196 : : spdm_context->connection_info.algorithm.base_asym_algo,
197 : 1 : spdm_context->local_context.peer_public_key_provision,
198 : : spdm_context->local_context.peer_public_key_provision_size,
199 : : &context);
200 : : }
201 [ - + ]: 1 : if (!result) {
202 : 0 : return false;
203 : : }
204 : : } else {
205 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
206 : : /* Get leaf cert from cert chain*/
207 : : libspdm_get_peer_cert_chain_data(
208 : : spdm_context, slot_id, (const void **)&cert_chain_data, &cert_chain_data_size);
209 : :
210 : : result = libspdm_x509_get_cert_from_cert_chain(
211 : : cert_chain_data, cert_chain_data_size, -1, &cert_buffer, &cert_buffer_size);
212 : : if (!result) {
213 : : return false;
214 : : }
215 : :
216 : : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
217 : : result = libspdm_pqc_asym_get_public_key_from_x509(
218 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
219 : : cert_buffer, cert_buffer_size, &context);
220 : : } else {
221 : : result = libspdm_asym_get_public_key_from_x509(
222 : : spdm_context->connection_info.algorithm.base_asym_algo,
223 : : cert_buffer, cert_buffer_size, &context);
224 : : }
225 : : if (!result) {
226 : : return false;
227 : : }
228 : : #else
229 : 22 : context = spdm_context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
230 [ - + ]: 22 : LIBSPDM_ASSERT(context != NULL);
231 : : #endif
232 : : }
233 : :
234 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
235 : : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
236 : : result = libspdm_pqc_asym_verify(
237 : : spdm_context->connection_info.version, SPDM_KEY_EXCHANGE_RSP,
238 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
239 : : spdm_context->connection_info.algorithm.base_hash_algo,
240 : : context, th_curr_data, th_curr_data_size, sign_data, sign_data_size);
241 : : libspdm_pqc_asym_free(spdm_context->connection_info.algorithm.pqc_asym_algo, context);
242 : : } else {
243 : : result = libspdm_asym_verify_ex(
244 : : spdm_context->connection_info.version, SPDM_KEY_EXCHANGE_RSP,
245 : : spdm_context->connection_info.algorithm.base_asym_algo,
246 : : spdm_context->connection_info.algorithm.base_hash_algo,
247 : : context, th_curr_data, th_curr_data_size, sign_data, sign_data_size,
248 : : &spdm_context->spdm_10_11_verify_signature_endian);
249 : : libspdm_asym_free(spdm_context->connection_info.algorithm.base_asym_algo, context);
250 : : }
251 : : #else
252 [ - + ]: 23 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
253 : 0 : result = libspdm_pqc_asym_verify_hash(
254 : 0 : spdm_context->connection_info.version, SPDM_KEY_EXCHANGE_RSP,
255 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
256 : : spdm_context->connection_info.algorithm.base_hash_algo,
257 : : context, hash_data, hash_size, sign_data, sign_data_size);
258 [ # # ]: 0 : if (slot_id == 0xFF) {
259 : 0 : libspdm_pqc_asym_free(spdm_context->connection_info.algorithm.pqc_asym_algo, context);
260 : : }
261 : : } else {
262 : 23 : result = libspdm_asym_verify_hash_ex(
263 : 23 : spdm_context->connection_info.version, SPDM_KEY_EXCHANGE_RSP,
264 : : spdm_context->connection_info.algorithm.base_asym_algo,
265 : : spdm_context->connection_info.algorithm.base_hash_algo,
266 : : context, hash_data, hash_size, sign_data, sign_data_size,
267 : : &spdm_context->spdm_10_11_verify_signature_endian);
268 [ + + ]: 23 : if (slot_id == 0xFF) {
269 : 1 : libspdm_asym_free(spdm_context->connection_info.algorithm.base_asym_algo, context);
270 : : }
271 : : }
272 : : #endif
273 [ + + ]: 23 : if (!result) {
274 : 2 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_key_exchange_signature - FAIL !!!\n"));
275 : 2 : return false;
276 : : }
277 : 21 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_key_exchange_signature - PASS !!!\n"));
278 : :
279 : 21 : return true;
280 : : }
281 : :
282 : : /**
283 : : * This function sends KEY_EXCHANGE and receives KEY_EXCHANGE_RSP for SPDM key exchange.
284 : : *
285 : : * @param spdm_context A pointer to the SPDM context.
286 : : * @param measurement_hash_type Measurement_hash_type to the KEY_EXCHANGE request.
287 : : * @param slot_id slot_id to the KEY_EXCHANGE request.
288 : : * @param session_policy The policy for the session.
289 : : * @param session_id session_id from the KEY_EXCHANGE_RSP response.
290 : : * @param heartbeat_period Heartbeat_period from the KEY_EXCHANGE_RSP response.
291 : : * @param req_slot_id_param req_slot_id_param from the KEY_EXCHANGE_RSP response.
292 : : * @param measurement_hash Measurement_hash from the KEY_EXCHANGE_RSP response.
293 : : * @param requester_random_in If not NULL, a buffer that holds the requester random data (32 bytes)
294 : : * @param requester_random If not NULL, a buffer to hold the requester random data (32 bytes).
295 : : * @param responder_random If not NULL, a buffer to hold the responder random data (32 bytes).
296 : : **/
297 : 104 : static libspdm_return_t libspdm_try_send_receive_key_exchange(
298 : : libspdm_context_t *spdm_context, uint8_t measurement_hash_type,
299 : : uint8_t slot_id, uint8_t session_policy, uint32_t *session_id,
300 : : uint8_t *heartbeat_period,
301 : : uint8_t *req_slot_id_param, void *measurement_hash,
302 : : const void *requester_random_in,
303 : : void *requester_random, void *responder_random,
304 : : const void *requester_opaque_data, size_t requester_opaque_data_size,
305 : : void *responder_opaque_data, size_t *responder_opaque_data_size)
306 : : {
307 : : bool result;
308 : : libspdm_return_t status;
309 : : libspdm_key_exchange_request_mine_t *spdm_request;
310 : : size_t spdm_request_size;
311 : : libspdm_key_exchange_response_max_t *spdm_response;
312 : : size_t spdm_response_size;
313 : : size_t dhe_key_size;
314 : : size_t kem_encap_key_size;
315 : : size_t kem_cipher_text_size;
316 : : size_t req_key_exchange_size;
317 : : size_t rsp_key_exchange_size;
318 : : uint32_t measurement_summary_hash_size;
319 : : uint32_t signature_size;
320 : : uint32_t hmac_size;
321 : : uint8_t *ptr;
322 : : void *measurement_summary_hash;
323 : : uint16_t opaque_length;
324 : : uint8_t *signature;
325 : : uint8_t *verify_data;
326 : : void *dhe_context;
327 : : void *kem_context;
328 : : uint16_t req_session_id;
329 : : uint16_t rsp_session_id;
330 : : libspdm_session_info_t *session_info;
331 : : size_t opaque_key_exchange_req_size;
332 : : uint8_t th1_hash_data[LIBSPDM_MAX_HASH_SIZE];
333 : : uint8_t *message;
334 : : size_t message_size;
335 : : size_t transport_header_size;
336 : : uint8_t mut_auth_requested;
337 : : spdm_version_number_t secured_message_version;
338 : 104 : uint8_t peer_aead_limit_exponent = SECURED_MESSAGE_AEAD_LIMIT_EXPONENT_DEFAULT;
339 : :
340 : : /* -=[Check Parameters Phase]=- */
341 [ + + - + ]: 104 : LIBSPDM_ASSERT((slot_id < SPDM_MAX_SLOT_COUNT) || (slot_id == 0xff));
342 [ + + - + ]: 104 : LIBSPDM_ASSERT((slot_id != 0xff) ||
343 : : (spdm_context->local_context.peer_public_key_provision_size != 0));
344 [ + + + + : 104 : LIBSPDM_ASSERT(measurement_hash_type == SPDM_KEY_EXCHANGE_REQUEST_NO_MEASUREMENT_SUMMARY_HASH ||
- + ]
345 : : measurement_hash_type == SPDM_KEY_EXCHANGE_REQUEST_TCB_COMPONENT_MEASUREMENT_HASH ||
346 : : measurement_hash_type == SPDM_KEY_EXCHANGE_REQUEST_ALL_MEASUREMENTS_HASH);
347 [ - + - - : 104 : LIBSPDM_ASSERT((libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_13) ||
- - ]
348 : : ((session_policy & SPDM_KEY_EXCHANGE_REQUEST_SESSION_POLICY_EVENT_ALL_POLICY)
349 : : == 0) ||
350 : : libspdm_is_capabilities_flag_supported(
351 : : spdm_context, true, 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_EVENT_CAP));
352 : :
353 : : /* -=[Verify State Phase]=- */
354 [ - + ]: 104 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_11) {
355 : 0 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
356 : : }
357 : :
358 [ + + ]: 104 : if (!libspdm_is_capabilities_flag_supported(
359 : : spdm_context, true,
360 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_KEY_EX_CAP,
361 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_KEY_EX_CAP)) {
362 : 3 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
363 : : }
364 : :
365 : : /* While clearing MAC_CAP and setting ENCRYPT_CAP is legal according to DSP0274, libspdm
366 : : * also implements DSP0277 secure messages, which requires at least MAC_CAP to be set.
367 : : */
368 [ + + ]: 101 : if (!libspdm_is_capabilities_flag_supported(
369 : : spdm_context, true,
370 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_MAC_CAP,
371 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MAC_CAP)) {
372 : 6 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
373 : : }
374 : :
375 [ + + ]: 95 : if (spdm_context->connection_info.connection_state < LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
376 : 2 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
377 : : }
378 : :
379 [ + + ]: 93 : if (libspdm_get_connection_version(spdm_context) >= SPDM_MESSAGE_VERSION_12) {
380 [ - + ]: 3 : if ((spdm_context->connection_info.algorithm.other_params_support &
381 : : SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_MASK) != SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_1) {
382 : 0 : return LIBSPDM_STATUS_INVALID_STATE_PEER;
383 : : }
384 : : }
385 : :
386 : 93 : req_session_id = libspdm_allocate_req_session_id(spdm_context, false);
387 [ - + ]: 93 : if (req_session_id == (INVALID_SESSION_ID & 0xFFFF)) {
388 : 0 : return LIBSPDM_STATUS_SESSION_NUMBER_EXCEED;
389 : : }
390 : :
391 : 93 : libspdm_reset_message_buffer_via_request_code(spdm_context, NULL, SPDM_KEY_EXCHANGE);
392 : :
393 : : /* -=[Construct Request Phase]=- */
394 : 93 : transport_header_size = spdm_context->local_context.capability.transport_header_size;
395 : 93 : status = libspdm_acquire_sender_buffer (spdm_context, &message_size, (void **)&message);
396 [ + + ]: 93 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
397 : 1 : return status;
398 : : }
399 [ - + ]: 92 : LIBSPDM_ASSERT (message_size >= transport_header_size +
400 : : spdm_context->local_context.capability.transport_tail_size);
401 : 92 : spdm_request = (void *)(message + transport_header_size);
402 : 92 : spdm_request_size = message_size - transport_header_size -
403 : 92 : spdm_context->local_context.capability.transport_tail_size;
404 : :
405 [ - + ]: 92 : LIBSPDM_ASSERT (spdm_request_size >= sizeof(spdm_key_exchange_request_t));
406 : 92 : spdm_request->header.spdm_version = libspdm_get_connection_version (spdm_context);
407 : 92 : spdm_request->header.request_response_code = SPDM_KEY_EXCHANGE;
408 : 92 : spdm_request->header.param1 = measurement_hash_type;
409 : 92 : spdm_request->header.param2 = slot_id;
410 [ + + ]: 92 : if (requester_random_in == NULL) {
411 [ - + ]: 91 : if (!libspdm_get_random_number(SPDM_RANDOM_DATA_SIZE, spdm_request->random_data)) {
412 : 0 : libspdm_release_sender_buffer (spdm_context);
413 : 0 : return LIBSPDM_STATUS_LOW_ENTROPY;
414 : : }
415 : : } else {
416 : 1 : libspdm_copy_mem(spdm_request->random_data, sizeof(spdm_request->random_data),
417 : : requester_random_in, SPDM_RANDOM_DATA_SIZE);
418 : : }
419 : 92 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "RequesterRandomData (0x%x) - ",
420 : : SPDM_RANDOM_DATA_SIZE));
421 : 92 : LIBSPDM_INTERNAL_DUMP_DATA(spdm_request->random_data, SPDM_RANDOM_DATA_SIZE);
422 : 92 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
423 [ + + ]: 92 : if (requester_random != NULL) {
424 : 1 : libspdm_copy_mem(requester_random, SPDM_RANDOM_DATA_SIZE,
425 : 1 : spdm_request->random_data, SPDM_RANDOM_DATA_SIZE);
426 : : }
427 : :
428 : 92 : spdm_request->req_session_id = req_session_id;
429 [ + + ]: 92 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_12) {
430 : 3 : spdm_request->session_policy = session_policy;
431 : : } else {
432 : 89 : spdm_request->session_policy = 0;
433 : : }
434 : 92 : spdm_request->reserved = 0;
435 : :
436 : 92 : ptr = spdm_request->exchange_data;
437 : 92 : dhe_context = NULL;
438 : 92 : kem_context = NULL;
439 [ - + ]: 92 : if (spdm_context->connection_info.algorithm.kem_alg != 0) {
440 : 0 : kem_encap_key_size = libspdm_get_kem_encap_key_size(
441 : : spdm_context->connection_info.algorithm.kem_alg);
442 : 0 : kem_cipher_text_size = libspdm_get_kem_cipher_text_size(
443 : : spdm_context->connection_info.algorithm.kem_alg);
444 : 0 : kem_context = libspdm_secured_message_kem_new(
445 : 0 : spdm_context->connection_info.version,
446 : : spdm_context->connection_info.algorithm.kem_alg, true);
447 [ # # ]: 0 : if (kem_context == NULL) {
448 : 0 : libspdm_release_sender_buffer (spdm_context);
449 : 0 : return LIBSPDM_STATUS_CRYPTO_ERROR;
450 : : }
451 : :
452 [ # # ]: 0 : LIBSPDM_ASSERT (spdm_request_size >= sizeof(spdm_key_exchange_request_t) + kem_encap_key_size);
453 : 0 : result = libspdm_secured_message_kem_generate_key(
454 : : spdm_context->connection_info.algorithm.kem_alg,
455 : : kem_context, ptr, &kem_encap_key_size);
456 [ # # ]: 0 : if (!result) {
457 : 0 : libspdm_secured_message_kem_free(
458 : : spdm_context->connection_info.algorithm.kem_alg, kem_context);
459 : 0 : libspdm_release_sender_buffer (spdm_context);
460 : 0 : return LIBSPDM_STATUS_CRYPTO_ERROR;
461 : : }
462 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "RequesterKey (0x%zx):\n", kem_encap_key_size));
463 : 0 : LIBSPDM_INTERNAL_DUMP_HEX(ptr, kem_encap_key_size);
464 : 0 : ptr += kem_encap_key_size;
465 : 0 : req_key_exchange_size = kem_encap_key_size;
466 : 0 : rsp_key_exchange_size = kem_cipher_text_size;
467 : : } else {
468 : 184 : dhe_key_size = libspdm_get_dhe_pub_key_size(
469 : 92 : spdm_context->connection_info.algorithm.dhe_named_group);
470 : 92 : dhe_context = libspdm_secured_message_dhe_new(
471 : 92 : spdm_context->connection_info.version,
472 : 92 : spdm_context->connection_info.algorithm.dhe_named_group, true);
473 [ - + ]: 92 : if (dhe_context == NULL) {
474 : 0 : libspdm_release_sender_buffer (spdm_context);
475 : 0 : return LIBSPDM_STATUS_CRYPTO_ERROR;
476 : : }
477 : :
478 [ - + ]: 92 : LIBSPDM_ASSERT (spdm_request_size >= sizeof(spdm_key_exchange_request_t) + dhe_key_size);
479 : 92 : result = libspdm_secured_message_dhe_generate_key(
480 : 92 : spdm_context->connection_info.algorithm.dhe_named_group,
481 : : dhe_context, ptr, &dhe_key_size);
482 [ - + ]: 92 : if (!result) {
483 : 0 : libspdm_secured_message_dhe_free(
484 : 0 : spdm_context->connection_info.algorithm.dhe_named_group, dhe_context);
485 : 0 : libspdm_release_sender_buffer (spdm_context);
486 : 0 : return LIBSPDM_STATUS_CRYPTO_ERROR;
487 : : }
488 : 92 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "RequesterKey (0x%zx):\n", dhe_key_size));
489 : 92 : LIBSPDM_INTERNAL_DUMP_HEX(ptr, dhe_key_size);
490 : 92 : ptr += dhe_key_size;
491 : 92 : req_key_exchange_size = dhe_key_size;
492 : 92 : rsp_key_exchange_size = dhe_key_size;
493 : : }
494 : :
495 [ + + ]: 92 : if (requester_opaque_data != NULL) {
496 [ - + ]: 1 : LIBSPDM_ASSERT(requester_opaque_data_size <= SPDM_MAX_OPAQUE_DATA_SIZE);
497 : :
498 [ - + ]: 1 : LIBSPDM_ASSERT (spdm_request_size >= sizeof(spdm_key_exchange_request_t) +
499 : : req_key_exchange_size +
500 : : sizeof(uint16_t) + requester_opaque_data_size);
501 : :
502 : 1 : libspdm_write_uint16(ptr, (uint16_t)requester_opaque_data_size);
503 : 1 : ptr += sizeof(uint16_t);
504 : :
505 : 1 : libspdm_copy_mem(ptr,
506 : 1 : (spdm_request_size - (sizeof(spdm_key_exchange_request_t) +
507 : : req_key_exchange_size)),
508 : : requester_opaque_data, requester_opaque_data_size);
509 : 1 : opaque_key_exchange_req_size = requester_opaque_data_size;
510 : : } else {
511 : : size_t supported_version_size;
512 : :
513 : : spdm_version_number_t local_max_secured_version =
514 : 91 : libspdm_local_max_secured_message_version(spdm_context);
515 : :
516 : 91 : supported_version_size =
517 : 91 : libspdm_get_opaque_data_supported_version_data_size(spdm_context);
518 : : /* DSP0277 1.3: also advertise this endpoint's AEAD limit in the request opaque data when it
519 : : * offers secured message version 1.3 (no version is negotiated yet at request time). */
520 : 91 : opaque_key_exchange_req_size = supported_version_size +
521 : 91 : libspdm_get_opaque_data_aead_limit_element_size(
522 : : spdm_context, local_max_secured_version);
523 [ - + ]: 91 : LIBSPDM_ASSERT (spdm_request_size >= sizeof(spdm_key_exchange_request_t) +
524 : : req_key_exchange_size +
525 : : sizeof(uint16_t) + opaque_key_exchange_req_size);
526 : :
527 : 91 : libspdm_write_uint16(ptr, (uint16_t)opaque_key_exchange_req_size);
528 : 91 : ptr += sizeof(uint16_t);
529 : :
530 : : /* opaque_key_exchange_req_size holds the reserved opaque data capacity (supported version +
531 : : * AEAD limit); it is the capacity passed to the append below. */
532 : 91 : libspdm_build_opaque_data_supported_version_data(
533 : : spdm_context, &supported_version_size, ptr);
534 : 91 : libspdm_build_opaque_data_aead_limit_element(
535 : : spdm_context, local_max_secured_version, &opaque_key_exchange_req_size, ptr);
536 : : }
537 : 92 : ptr += opaque_key_exchange_req_size;
538 : :
539 : 92 : spdm_request_size = (size_t)ptr - (size_t)spdm_request;
540 : :
541 : : /* -=[Send Request Phase]=- */
542 : 92 : status = libspdm_send_spdm_request(spdm_context, NULL, spdm_request_size, spdm_request);
543 [ + + ]: 92 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
544 : 2 : libspdm_release_sender_buffer (spdm_context);
545 : 2 : goto free_exchange;
546 : : }
547 : 90 : libspdm_release_sender_buffer (spdm_context);
548 : 90 : spdm_request = (void *)spdm_context->last_spdm_request;
549 : :
550 : : /* -=[Receive Response Phase]=- */
551 : 90 : status = libspdm_acquire_receiver_buffer (spdm_context, &message_size, (void **)&message);
552 [ + + ]: 90 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
553 : 1 : goto free_exchange;
554 : : }
555 [ - + ]: 89 : LIBSPDM_ASSERT (message_size >= transport_header_size);
556 : 89 : spdm_response = (void *)(message);
557 : 89 : spdm_response_size = message_size;
558 : :
559 : 89 : status = libspdm_receive_spdm_response(
560 : : spdm_context, NULL, &spdm_response_size, (void **)&spdm_response);
561 [ - + ]: 89 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
562 : 0 : goto receive_done;
563 : : }
564 : :
565 : : /* -=[Validate Response Phase]=- */
566 [ - + ]: 89 : if (spdm_response_size < sizeof(spdm_message_header_t)) {
567 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
568 : 0 : goto receive_done;
569 : : }
570 [ + + ]: 89 : if (spdm_response->header.request_response_code == SPDM_ERROR) {
571 : 46 : status = libspdm_handle_error_response_main(
572 : : spdm_context, NULL, &spdm_response_size,
573 : : (void **)&spdm_response, SPDM_KEY_EXCHANGE,
574 : : SPDM_KEY_EXCHANGE_RSP);
575 [ + + ]: 46 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
576 : 45 : goto receive_done;
577 : : }
578 [ + + ]: 43 : } else if (spdm_response->header.request_response_code != SPDM_KEY_EXCHANGE_RSP) {
579 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
580 : 1 : goto receive_done;
581 : : }
582 [ + + ]: 43 : if (spdm_response->header.spdm_version != spdm_request->header.spdm_version) {
583 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
584 : 1 : goto receive_done;
585 : : }
586 [ - + ]: 42 : if (spdm_response_size < sizeof(spdm_key_exchange_response_t)) {
587 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
588 : 0 : goto receive_done;
589 : : }
590 : :
591 [ + + ]: 42 : if (!libspdm_is_capabilities_flag_supported(
592 : : spdm_context, true,
593 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HBEAT_CAP,
594 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HBEAT_CAP)) {
595 [ + + ]: 40 : if (spdm_response->header.param1 != 0) {
596 : 2 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
597 : 2 : goto receive_done;
598 : : }
599 : : }
600 [ + + ]: 40 : if (heartbeat_period != NULL) {
601 : 36 : *heartbeat_period = spdm_response->header.param1;
602 : : }
603 : :
604 : 40 : *req_slot_id_param = spdm_response->req_slot_id_param & 0xf;
605 : 40 : mut_auth_requested = spdm_response->mut_auth_requested & 0x7;
606 : :
607 [ + + ]: 40 : if (mut_auth_requested != 0) {
608 : 13 : const bool mut_auth_cap_both = libspdm_is_capabilities_flag_supported(
609 : : spdm_context, true,
610 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_MUT_AUTH_CAP,
611 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MUT_AUTH_CAP);
612 : 13 : const bool cert_cap = libspdm_is_capabilities_flag_supported(
613 : : spdm_context, true,
614 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_CERT_CAP,
615 : : 0);
616 : 13 : const bool pub_key_id_cap = libspdm_is_capabilities_flag_supported(
617 : : spdm_context, true,
618 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_PUB_KEY_ID_CAP,
619 : : 0);
620 : :
621 [ + + ]: 13 : if (!mut_auth_cap_both) {
622 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
623 : 1 : goto receive_done;
624 : : }
625 [ + + + + ]: 12 : if ((mut_auth_requested != SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED) &&
626 : : (mut_auth_requested !=
627 [ + + ]: 7 : SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_ENCAP_REQUEST) &&
628 : : (mut_auth_requested !=
629 : : SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_GET_DIGESTS)) {
630 : 6 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
631 : 6 : goto receive_done;
632 : : }
633 : :
634 [ + + ]: 6 : if (mut_auth_requested == SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED) {
635 : : /* Non-encapsulated flow.
636 : : * Requester has either CERT_CAP or PUB_KEY_ID_CAP set. */
637 : :
638 [ + + - + : 2 : if ((cert_cap && (*req_slot_id_param >= SPDM_MAX_SLOT_COUNT)) ||
- + ]
639 [ # # ]: 0 : (pub_key_id_cap && (*req_slot_id_param != 0xf))) {
640 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
641 : 1 : goto receive_done;
642 : : }
643 [ - + ]: 1 : if ((spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) &&
644 [ # # ]: 0 : spdm_context->connection_info.multi_key_conn_req &&
645 [ # # ]: 0 : (*req_slot_id_param != 0xf)) {
646 [ # # ]: 0 : if ((spdm_context->local_context.local_key_usage_bit_mask[*req_slot_id_param] &
647 : : SPDM_KEY_USAGE_BIT_MASK_KEY_EX_USE) == 0) {
648 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
649 : 0 : goto receive_done;
650 : : }
651 : : }
652 : : } else {
653 : : /* Encapsulated flow. */
654 : :
655 : : /* If Responder has Requester's public key then it cannot use the encapsulated flow. */
656 [ + + ]: 4 : if (pub_key_id_cap) {
657 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
658 : 1 : goto receive_done;
659 : : }
660 : : /* Encapsulated flow requires support for encapsulated messages by both endpoints. */
661 [ + + ]: 3 : if (!libspdm_is_encap_supported(spdm_context)) {
662 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
663 : 1 : goto receive_done;
664 : : }
665 : : }
666 : : }
667 : :
668 [ - + ]: 30 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
669 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
670 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
671 : : } else {
672 : 30 : signature_size = libspdm_get_asym_signature_size(
673 : : spdm_context->connection_info.algorithm.base_asym_algo);
674 : : }
675 : 30 : measurement_summary_hash_size = libspdm_get_measurement_summary_hash_size(
676 : : spdm_context, true, measurement_hash_type);
677 : 30 : hmac_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
678 : :
679 [ + + ]: 30 : if (libspdm_is_capabilities_flag_supported(
680 : : spdm_context, true,
681 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
682 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
683 : 1 : hmac_size = 0;
684 : : }
685 : :
686 : 30 : if (spdm_response_size <
687 : 30 : sizeof(spdm_key_exchange_response_t) + rsp_key_exchange_size +
688 [ + + ]: 30 : measurement_summary_hash_size + sizeof(uint16_t) + signature_size + hmac_size) {
689 : 4 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
690 : 4 : goto receive_done;
691 : : }
692 : :
693 : 26 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "ResponderRandomData (0x%x) - ", SPDM_RANDOM_DATA_SIZE));
694 : 26 : LIBSPDM_INTERNAL_DUMP_DATA(spdm_response->random_data, SPDM_RANDOM_DATA_SIZE);
695 : 26 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
696 [ + + ]: 26 : if (responder_random != NULL) {
697 : 1 : libspdm_copy_mem(responder_random, SPDM_RANDOM_DATA_SIZE,
698 : 1 : spdm_response->random_data, SPDM_RANDOM_DATA_SIZE);
699 : : }
700 : :
701 : 26 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "ResponderKey (0x%zx):\n", rsp_key_exchange_size));
702 : 26 : LIBSPDM_INTERNAL_DUMP_HEX(spdm_response->exchange_data, rsp_key_exchange_size);
703 : :
704 : 26 : ptr = spdm_response->exchange_data;
705 : 26 : ptr += rsp_key_exchange_size;
706 : :
707 : 26 : measurement_summary_hash = ptr;
708 : 26 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "measurement_summary_hash (0x%x) - ",
709 : : measurement_summary_hash_size));
710 : 26 : LIBSPDM_INTERNAL_DUMP_DATA(measurement_summary_hash, measurement_summary_hash_size);
711 : 26 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
712 : :
713 : 26 : ptr += measurement_summary_hash_size;
714 : :
715 : 26 : opaque_length = libspdm_read_uint16((const uint8_t *)ptr);
716 [ + + ]: 26 : if (opaque_length > SPDM_MAX_OPAQUE_DATA_SIZE) {
717 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
718 : 1 : goto receive_done;
719 : : }
720 : 25 : ptr += sizeof(uint16_t);
721 : 25 : if (spdm_response_size <
722 : 25 : sizeof(spdm_key_exchange_response_t) + rsp_key_exchange_size +
723 : 25 : measurement_summary_hash_size + sizeof(uint16_t) +
724 [ + + ]: 25 : opaque_length + signature_size + hmac_size) {
725 : 2 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
726 : 2 : goto receive_done;
727 : : }
728 : 23 : secured_message_version = 0;
729 [ + + ]: 23 : if (opaque_length != 0) {
730 : 22 : result = libspdm_process_general_opaque_data_check(spdm_context, opaque_length, ptr);
731 [ - + ]: 22 : if (!result) {
732 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
733 : 0 : goto receive_done;
734 : : }
735 : 22 : status = libspdm_process_opaque_data_version_selection_data(
736 : : spdm_context, opaque_length, ptr, &secured_message_version);
737 [ - + ]: 22 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
738 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
739 : 0 : goto receive_done;
740 : : }
741 : : /* DSP0277 1.3: read the Responder's AEAD limit (absent -> default 64). */
742 : 22 : status = libspdm_process_opaque_data_aead_limit(
743 : : spdm_context, secured_message_version, opaque_length, ptr,
744 : : &peer_aead_limit_exponent);
745 [ - + ]: 22 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
746 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
747 : 0 : goto receive_done;
748 : : }
749 : : }
750 : :
751 [ + + + - ]: 23 : if ((responder_opaque_data != NULL) && (responder_opaque_data_size != NULL)) {
752 [ - + ]: 1 : if (opaque_length >= *responder_opaque_data_size) {
753 : 0 : status = LIBSPDM_STATUS_BUFFER_TOO_SMALL;
754 : 0 : goto receive_done;
755 : : }
756 : 1 : libspdm_copy_mem(responder_opaque_data, *responder_opaque_data_size, ptr, opaque_length);
757 : 1 : *responder_opaque_data_size = opaque_length;
758 : : }
759 : :
760 : 23 : ptr += opaque_length;
761 : :
762 : 23 : spdm_response_size = sizeof(spdm_key_exchange_response_t) +
763 : 23 : rsp_key_exchange_size + measurement_summary_hash_size +
764 : 23 : sizeof(uint16_t) + opaque_length + signature_size + hmac_size;
765 : :
766 : 23 : rsp_session_id = spdm_response->rsp_session_id;
767 : 23 : *session_id = libspdm_generate_session_id(req_session_id, rsp_session_id);
768 : 23 : session_info = libspdm_assign_session_id(spdm_context, *session_id, secured_message_version,
769 : : false);
770 [ - + ]: 23 : if (session_info == NULL) {
771 : 0 : status = LIBSPDM_STATUS_SESSION_NUMBER_EXCEED;
772 : 0 : goto receive_done;
773 : : }
774 : 23 : session_info->peer_used_cert_chain_slot_id = slot_id;
775 : 23 : session_info->local_used_cert_chain_slot_id = *req_slot_id_param;
776 : :
777 : : /* DSP0277 1.3: program the session's AEAD limit (min of local and peer) when secured message
778 : : * version 1.3 was negotiated. */
779 [ - + ]: 23 : if (libspdm_get_version_from_version_number(secured_message_version) >=
780 : : SECURED_SPDM_VERSION_13) {
781 : 0 : libspdm_apply_aead_limit_to_session(spdm_context, session_info,
782 : : peer_aead_limit_exponent);
783 : : }
784 : :
785 : : /* -=[Process Response Phase]=- */
786 : 23 : status = libspdm_append_message_k(spdm_context, session_info, true, spdm_request,
787 : : spdm_request_size);
788 [ - + ]: 23 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
789 : 0 : libspdm_free_session_id(spdm_context, *session_id);
790 : 0 : goto receive_done;
791 : : }
792 : :
793 : 23 : status = libspdm_append_message_k(spdm_context, session_info, true, spdm_response,
794 : 23 : spdm_response_size - signature_size - hmac_size);
795 [ - + ]: 23 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
796 : 0 : libspdm_free_session_id(spdm_context, *session_id);
797 : 0 : goto receive_done;
798 : : }
799 : :
800 : 23 : signature = ptr;
801 : 23 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "signature (0x%x):\n", signature_size));
802 : 23 : LIBSPDM_INTERNAL_DUMP_HEX(signature, signature_size);
803 : 23 : ptr += signature_size;
804 : 23 : result = libspdm_verify_key_exchange_rsp_signature(
805 : : spdm_context, session_info, signature, signature_size);
806 [ + + ]: 23 : if (!result) {
807 : 2 : libspdm_free_session_id(spdm_context, *session_id);
808 : 2 : status = LIBSPDM_STATUS_VERIF_FAIL;
809 : 2 : goto receive_done;
810 : : }
811 : :
812 : 21 : status = libspdm_append_message_k(spdm_context, session_info, true, signature, signature_size);
813 [ - + ]: 21 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
814 : 0 : libspdm_free_session_id(spdm_context, *session_id);
815 : 0 : goto receive_done;
816 : : }
817 : :
818 [ - + ]: 21 : if (spdm_context->connection_info.algorithm.kem_alg != 0) {
819 : 0 : result = libspdm_secured_message_kem_decapsulate(
820 : : spdm_context->connection_info.algorithm.kem_alg,
821 : 0 : kem_context, spdm_response->exchange_data, kem_cipher_text_size,
822 : : session_info->secured_message_context);
823 : 0 : libspdm_secured_message_kem_free(
824 : : spdm_context->connection_info.algorithm.kem_alg, kem_context);
825 : 0 : kem_context = NULL;
826 : : } else {
827 : 21 : result = libspdm_secured_message_dhe_compute_key(
828 : 21 : spdm_context->connection_info.algorithm.dhe_named_group,
829 : 21 : dhe_context, spdm_response->exchange_data, dhe_key_size,
830 : : session_info->secured_message_context);
831 : 21 : libspdm_secured_message_dhe_free(
832 : 21 : spdm_context->connection_info.algorithm.dhe_named_group, dhe_context);
833 : 21 : dhe_context = NULL;
834 : : }
835 [ - + ]: 21 : if (!result) {
836 : 0 : libspdm_free_session_id(spdm_context, *session_id);
837 : 0 : status = LIBSPDM_STATUS_CRYPTO_ERROR;
838 : 0 : goto receive_done;
839 : : }
840 : :
841 : 21 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "libspdm_generate_session_handshake_key[%x]\n",
842 : : *session_id));
843 : 21 : result = libspdm_calculate_th1_hash(spdm_context, session_info, true, th1_hash_data);
844 [ - + ]: 21 : if (!result) {
845 : 0 : libspdm_free_session_id(spdm_context, *session_id);
846 : 0 : status = LIBSPDM_STATUS_CRYPTO_ERROR;
847 : 0 : goto receive_done;
848 : : }
849 : 21 : result = libspdm_generate_session_handshake_key(
850 : : session_info->secured_message_context, th1_hash_data);
851 [ - + ]: 21 : if (!result) {
852 : 0 : libspdm_free_session_id(spdm_context, *session_id);
853 : 0 : status = LIBSPDM_STATUS_CRYPTO_ERROR;
854 : 0 : goto receive_done;
855 : : }
856 : :
857 [ + + ]: 21 : if (!libspdm_is_capabilities_flag_supported(
858 : : spdm_context, true,
859 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
860 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
861 : 20 : verify_data = ptr;
862 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "verify_data (0x%x):\n", hmac_size));
863 : 20 : LIBSPDM_INTERNAL_DUMP_HEX(verify_data, hmac_size);
864 : 20 : result = libspdm_verify_key_exchange_rsp_hmac(
865 : : spdm_context, session_info, verify_data, hmac_size);
866 [ - + ]: 20 : if (!result) {
867 : 0 : libspdm_free_session_id(spdm_context, *session_id);
868 : 0 : status = LIBSPDM_STATUS_VERIF_FAIL;
869 : 0 : goto receive_done;
870 : : }
871 : 20 : ptr += hmac_size;
872 : :
873 : 20 : status = libspdm_append_message_k(spdm_context, session_info, true, verify_data, hmac_size);
874 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
875 : 0 : libspdm_free_session_id(spdm_context, *session_id);
876 : 0 : goto receive_done;
877 : : }
878 : : }
879 : :
880 [ + - ]: 21 : if (measurement_hash != NULL) {
881 : 21 : libspdm_copy_mem(measurement_hash, measurement_summary_hash_size,
882 : : measurement_summary_hash, measurement_summary_hash_size);
883 : : }
884 : 21 : session_info->heartbeat_period = spdm_response->header.param1;
885 : 21 : session_info->mut_auth_requested = mut_auth_requested;
886 : 21 : session_info->session_policy = session_policy;
887 : :
888 : : /* -=[Update State Phase]=- */
889 : 21 : libspdm_secured_message_set_session_state(
890 : : session_info->secured_message_context, LIBSPDM_SESSION_STATE_HANDSHAKING);
891 : :
892 : : /* -=[Log Message Phase]=- */
893 : : #if LIBSPDM_ENABLE_MSG_LOG
894 : 21 : libspdm_append_msg_log(spdm_context, spdm_response, spdm_response_size);
895 : : #endif /* LIBSPDM_ENABLE_MSG_LOG */
896 : :
897 : 21 : status = LIBSPDM_STATUS_SUCCESS;
898 : :
899 : 89 : receive_done:
900 : 89 : libspdm_release_receiver_buffer (spdm_context);
901 : 92 : free_exchange:
902 [ + + ]: 92 : if (dhe_context != NULL) {
903 : 71 : libspdm_secured_message_dhe_free(
904 : 71 : spdm_context->connection_info.algorithm.dhe_named_group, dhe_context);
905 : : }
906 [ - + ]: 92 : if (kem_context != NULL) {
907 : 0 : libspdm_secured_message_kem_free(
908 : : spdm_context->connection_info.algorithm.kem_alg, kem_context);
909 : : }
910 : 92 : return status;
911 : : }
912 : :
913 : 100 : libspdm_return_t libspdm_send_receive_key_exchange(
914 : : libspdm_context_t *spdm_context, uint8_t measurement_hash_type,
915 : : uint8_t slot_id, uint8_t session_policy, uint32_t *session_id,
916 : : uint8_t *heartbeat_period,
917 : : uint8_t *req_slot_id_param, void *measurement_hash)
918 : : {
919 : : size_t retry;
920 : : uint64_t retry_delay_time;
921 : : libspdm_return_t status;
922 : :
923 : 100 : spdm_context->crypto_request = true;
924 : 100 : retry = spdm_context->retry_times;
925 : 100 : retry_delay_time = spdm_context->retry_delay_time;
926 : : do {
927 : 101 : status = libspdm_try_send_receive_key_exchange(
928 : : spdm_context, measurement_hash_type, slot_id, session_policy,
929 : : session_id, heartbeat_period, req_slot_id_param,
930 : : measurement_hash,
931 : : NULL, NULL, NULL, NULL, 0, NULL, NULL);
932 [ + + ]: 101 : if (status != LIBSPDM_STATUS_BUSY_PEER) {
933 : 98 : return status;
934 : : }
935 : :
936 : 3 : libspdm_sleep(retry_delay_time);
937 [ + + ]: 3 : } while (retry-- != 0);
938 : :
939 : 2 : return status;
940 : : }
941 : :
942 : 3 : libspdm_return_t libspdm_send_receive_key_exchange_ex(
943 : : libspdm_context_t *spdm_context, uint8_t measurement_hash_type,
944 : : uint8_t slot_id, uint8_t session_policy, uint32_t *session_id,
945 : : uint8_t *heartbeat_period,
946 : : uint8_t *req_slot_id_param, void *measurement_hash,
947 : : const void *requester_random_in,
948 : : void *requester_random, void *responder_random,
949 : : const void *requester_opaque_data,
950 : : size_t requester_opaque_data_size,
951 : : void *responder_opaque_data,
952 : : size_t *responder_opaque_data_size)
953 : : {
954 : : size_t retry;
955 : : uint64_t retry_delay_time;
956 : : libspdm_return_t status;
957 : :
958 : 3 : spdm_context->crypto_request = true;
959 : 3 : retry = spdm_context->retry_times;
960 : 3 : retry_delay_time = spdm_context->retry_delay_time;
961 : : do {
962 : 3 : status = libspdm_try_send_receive_key_exchange(
963 : : spdm_context, measurement_hash_type, slot_id, session_policy,
964 : : session_id, heartbeat_period, req_slot_id_param,
965 : : measurement_hash, requester_random_in,
966 : : requester_random, responder_random,
967 : : requester_opaque_data, requester_opaque_data_size,
968 : : responder_opaque_data, responder_opaque_data_size);
969 [ + - ]: 3 : if (status != LIBSPDM_STATUS_BUSY_PEER) {
970 : 3 : return status;
971 : : }
972 : :
973 : 0 : libspdm_sleep(retry_delay_time);
974 [ # # ]: 0 : } while (retry-- != 0);
975 : :
976 : 0 : return status;
977 : : }
978 : :
979 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_KEY_EX_CAP */
|