Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2021-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_requester_lib.h"
8 : : #include "internal/libspdm_secured_message_lib.h"
9 : :
10 : 68610 : libspdm_return_t libspdm_send_request(void *spdm_context, const uint32_t *session_id,
11 : : bool is_app_message,
12 : : size_t request_size, void *request)
13 : : {
14 : : libspdm_context_t *context;
15 : : libspdm_return_t status;
16 : : uint8_t *message;
17 : : size_t message_size;
18 : : uint64_t timeout;
19 : : uint8_t *scratch_buffer;
20 : : size_t scratch_buffer_size;
21 : : size_t transport_header_size;
22 : : uint8_t *sender_buffer;
23 : : size_t sender_buffer_size;
24 : :
25 : 68610 : context = spdm_context;
26 : :
27 [ + + ]: 68610 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
28 : : "libspdm_send_spdm_request[%x] msg %s(0x%x), size (0x%zx): \n",
29 : : (session_id != NULL) ? *session_id : 0x0,
30 : : libspdm_get_code_str(((spdm_message_header_t *)request)->request_response_code),
31 : : ((spdm_message_header_t *)request)->request_response_code, request_size));
32 : 68610 : LIBSPDM_INTERNAL_DUMP_HEX(request, request_size);
33 : :
34 : 68610 : transport_header_size = context->local_context.capability.transport_header_size;
35 : 68610 : libspdm_get_scratch_buffer(context, (void **)&scratch_buffer, &scratch_buffer_size);
36 : 68610 : libspdm_get_sender_buffer(context, (void **)&sender_buffer, &sender_buffer_size);
37 : :
38 : : /* This is a problem because original code assumes request is in the sender buffer,
39 : : * when it can really be using the scratch space for chunking.
40 : : * Did not want to modify all request handlers to pass this information,
41 : : * so just making the determination here by examining scratch/sender buffers.
42 : : * This may be something that should be refactored in the future. */
43 : : #if LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP
44 : : /* If message is in the scratch buffer then sender_buffer can/will be NULL, so first check for
45 : : * NULLness before performing pointer arithmetic with it. */
46 [ + + + - ]: 68610 : if ((sender_buffer != NULL) && ((uint8_t *)request >= sender_buffer) &&
47 [ - + ]: 2988 : ((uint8_t *)request < (sender_buffer + sender_buffer_size))) {
48 : 0 : message = sender_buffer;
49 : 0 : message_size = sender_buffer_size;
50 : : } else {
51 : 68610 : if ((uint8_t *)request >=
52 [ + - ]: 68610 : scratch_buffer + libspdm_get_scratch_buffer_sender_receiver_offset(spdm_context)
53 : 68610 : && (uint8_t *)request <
54 : 137220 : scratch_buffer + libspdm_get_scratch_buffer_sender_receiver_offset(spdm_context)
55 [ + + ]: 68610 : + libspdm_get_scratch_buffer_sender_receiver_capacity(spdm_context)) {
56 : 131280 : message = scratch_buffer +
57 : 65640 : libspdm_get_scratch_buffer_sender_receiver_offset(spdm_context);
58 : 65640 : message_size = libspdm_get_scratch_buffer_sender_receiver_capacity(spdm_context);
59 : 2970 : } else if ((uint8_t *)request >=
60 : 5940 : scratch_buffer +
61 [ + - ]: 2970 : libspdm_get_scratch_buffer_large_sender_receiver_offset(spdm_context)
62 : 2970 : && (uint8_t *)request <
63 : : scratch_buffer +
64 : 2970 : libspdm_get_scratch_buffer_large_sender_receiver_offset(spdm_context) +
65 [ + - ]: 2970 : libspdm_get_scratch_buffer_large_sender_receiver_capacity(spdm_context)) {
66 : 5940 : message = scratch_buffer +
67 : 2970 : libspdm_get_scratch_buffer_large_sender_receiver_offset(spdm_context);
68 : 2970 : message_size = libspdm_get_scratch_buffer_large_sender_receiver_capacity(spdm_context);
69 : : }
70 : : }
71 : : #else /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
72 : : message = sender_buffer;
73 : : message_size = sender_buffer_size;
74 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
75 : :
76 [ + + ]: 68610 : if (session_id != NULL) {
77 : : /* For secure message, message is in sender buffer, we need copy it to scratch buffer.
78 : : * transport_message is always in sender buffer. */
79 : :
80 : 288 : libspdm_copy_mem (scratch_buffer + transport_header_size,
81 : : scratch_buffer_size - transport_header_size,
82 : : request, request_size);
83 : 288 : request = scratch_buffer + transport_header_size;
84 : : }
85 : :
86 : : /* backup it to last_spdm_request, because the caller wants to compare it with response */
87 [ + + ]: 68610 : if (((const spdm_message_header_t *)request)->request_response_code != SPDM_RESPOND_IF_READY
88 [ + + ]: 68581 : && ((const spdm_message_header_t *)request)->request_response_code != SPDM_CHUNK_GET
89 [ + + ]: 2959 : && ((const spdm_message_header_t *)request)->request_response_code != SPDM_CHUNK_SEND) {
90 : 2941 : libspdm_copy_mem (context->last_spdm_request,
91 : 2941 : libspdm_get_scratch_buffer_last_spdm_request_capacity(context),
92 : : request,
93 : : request_size);
94 : 2941 : context->last_spdm_request_size = request_size;
95 : : }
96 : :
97 : 68610 : status = context->transport_encode_message(
98 : : context, session_id, is_app_message, true, request_size,
99 : : request, &message_size, (void **)&message);
100 [ + + ]: 68610 : if (session_id != NULL) {
101 : : /* clean up secure message which was copied to scratch buffer */
102 : 288 : libspdm_zero_mem(request, request_size);
103 : : }
104 [ - + ]: 68610 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
105 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "transport_encode_message status - %x\n", status));
106 [ # # # # ]: 0 : if ((session_id != NULL) &&
107 [ # # ]: 0 : ((status == LIBSPDM_STATUS_SEQUENCE_NUMBER_OVERFLOW) ||
108 : : (status == LIBSPDM_STATUS_CRYPTO_ERROR))) {
109 : 0 : libspdm_free_session_id(context, *session_id);
110 : : }
111 : 0 : return status;
112 : : }
113 : :
114 : 68610 : timeout = context->local_context.capability.rtt;
115 : 68610 : status = context->send_message(context, message_size, message, timeout);
116 : :
117 [ + + ]: 68610 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
118 [ + + ]: 31 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "libspdm_send_spdm_request[%x] status - %x\n",
119 : : (session_id != NULL) ? *session_id : 0x0, status));
120 : : }
121 : :
122 : 68610 : return status;
123 : : }
124 : :
125 : 68562 : libspdm_return_t libspdm_receive_response(void *spdm_context, const uint32_t *session_id,
126 : : bool is_app_message,
127 : : size_t *response_size,
128 : : void **response)
129 : : {
130 : : libspdm_context_t *context;
131 : : void *temp_session_context;
132 : : libspdm_return_t status;
133 : : uint8_t *message;
134 : : size_t message_size;
135 : : uint32_t *message_session_id;
136 : : uint32_t message_id;
137 : : bool is_message_app_message;
138 : : uint64_t timeout;
139 : : size_t transport_header_size;
140 : : uint8_t *scratch_buffer;
141 : : size_t scratch_buffer_size;
142 : : void *backup_response;
143 : : size_t backup_response_size;
144 : : bool reset_key_update;
145 : : bool result;
146 : :
147 : 68562 : context = spdm_context;
148 : :
149 [ + + ]: 68562 : if (context->crypto_request) {
150 : 68217 : timeout = context->local_context.capability.rtt +
151 : 68217 : ((uint64_t)1 << context->connection_info.capability.ct_exponent);
152 : : } else {
153 : 345 : timeout = context->local_context.capability.rtt + context->local_context.capability.st1;
154 : : }
155 : :
156 : 68562 : message = *response;
157 : 68562 : message_size = *response_size;
158 : 68562 : status = context->receive_message(context, &message_size, (void **)&message, timeout);
159 [ + + ]: 68562 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
160 [ + + ]: 28 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
161 : : "libspdm_receive_spdm_response[%x] status - %x\n",
162 : : (session_id != NULL) ? *session_id : 0x0, status));
163 : 28 : return status;
164 : : }
165 : :
166 : : /*
167 : : * The storage transport encoding, defined by DSP0286, does not indicate
168 : : * if we are/are not in a secure session in the transport data. This is
169 : : * different to most other transport encodings, which includes session
170 : : * information in the encoding.
171 : : *
172 : : * As such if we are in a secure session, session_id != NULL, we set
173 : : * message_session_id to be non-NULL to indicate to the lower layer
174 : : * that we are in a secure session.
175 : : */
176 [ + + ]: 68534 : if (session_id != NULL) {
177 : 273 : message_session_id = &message_id;
178 : 273 : message_id = *session_id;
179 : : } else {
180 : 68261 : message_session_id = NULL;
181 : : }
182 : 68534 : is_message_app_message = false;
183 : :
184 : : /* always use scratch buffer for the response.
185 : : * if it is secured message, this scratch buffer will be used.
186 : : * if it is normal message, the response ptr will point to receiver buffer. */
187 : 68534 : transport_header_size = context->local_context.capability.transport_header_size;
188 : 68534 : libspdm_get_scratch_buffer (context, (void **)&scratch_buffer, &scratch_buffer_size);
189 : : #if LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP
190 : 68534 : *response = scratch_buffer + libspdm_get_scratch_buffer_secure_message_offset() +
191 : : transport_header_size;
192 : 68534 : *response_size = libspdm_get_scratch_buffer_secure_message_capacity(context) -
193 : : transport_header_size;
194 : : #else
195 : : *response = scratch_buffer + transport_header_size;
196 : : *response_size = scratch_buffer_size - transport_header_size;
197 : : #endif
198 : :
199 : 68534 : backup_response = *response;
200 : 68534 : backup_response_size = *response_size;
201 : :
202 : 68534 : status = context->transport_decode_message(
203 : : context, &message_session_id, &is_message_app_message,
204 : : false, message_size, message, response_size, response);
205 : :
206 : 68534 : reset_key_update = false;
207 : 68534 : temp_session_context = NULL;
208 : :
209 [ + + ]: 68534 : if (status == LIBSPDM_STATUS_SESSION_TRY_DISCARD_KEY_UPDATE) {
210 : : /* Failed to decode, but have backup keys. Try rolling back before aborting.
211 : : * message_session_id must be valid for us to have attempted decryption. */
212 [ - + ]: 27 : if (message_session_id == NULL) {
213 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
214 : : }
215 : 27 : temp_session_context = libspdm_get_secured_message_context_via_session_id(
216 : : context, *message_session_id);
217 [ - + ]: 27 : if (temp_session_context == NULL) {
218 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
219 : : }
220 : :
221 : 27 : result = libspdm_activate_update_session_data_key(
222 : : temp_session_context, LIBSPDM_KEY_UPDATE_ACTION_RESPONDER, false);
223 [ - + ]: 27 : if (!result) {
224 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
225 : : }
226 : :
227 : : /* Retry decoding message with backup Requester key.
228 : : * Must reset some of the parameters in case they were modified */
229 [ + - ]: 27 : if (session_id != NULL) {
230 : 27 : *message_session_id = *session_id;
231 : : } else {
232 : 0 : message_session_id = NULL;
233 : : }
234 : 27 : is_message_app_message = false;
235 : 27 : *response = backup_response;
236 : 27 : *response_size = backup_response_size;
237 : 27 : status = context->transport_decode_message(
238 : : context, &message_session_id, &is_message_app_message,
239 : : false, message_size, message, response_size, response);
240 : :
241 : 27 : reset_key_update = true;
242 : : }
243 : :
244 : : /*
245 : : * decoded_message may contain padding zeros due to transport layer alignment requirements.
246 : : * trim the decoded_message size to the maximum data_transfer_size.
247 : : */
248 : 68534 : *response_size = LIBSPDM_MIN(*response_size, context->local_context.capability.data_transfer_size);
249 : :
250 [ + + ]: 68534 : if (session_id != NULL) {
251 [ + + ]: 273 : if (message_session_id == NULL) {
252 [ + - ]: 1 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
253 : : "libspdm_receive_spdm_response[%x] GetSessionId - NULL\n",
254 : : (session_id != NULL) ? *session_id : 0x0));
255 : 1 : goto error;
256 : : }
257 [ - + ]: 272 : if (*message_session_id != *session_id) {
258 [ # # ]: 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
259 : : "libspdm_receive_spdm_response[%x] GetSessionId - %x\n",
260 : : (session_id != NULL) ? *session_id : 0x0, *message_session_id));
261 : 0 : goto error;
262 : : }
263 : : } else {
264 [ - + ]: 68261 : if (message_session_id != NULL) {
265 [ # # ]: 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
266 : : "libspdm_receive_spdm_response[%x] GetSessionId - %x\n",
267 : : (session_id != NULL) ? *session_id : 0x0, *message_session_id));
268 : 0 : goto error;
269 : : }
270 : : }
271 : :
272 [ + + + - ]: 68533 : if ((is_app_message && !is_message_app_message) ||
273 [ + + - + ]: 68533 : (!is_app_message && is_message_app_message)) {
274 [ # # ]: 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
275 : : "libspdm_receive_spdm_response[%x] app_message mismatch\n",
276 : : (session_id != NULL) ? *session_id : 0x0));
277 : 0 : goto error;
278 : : }
279 : :
280 [ - + ]: 68533 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
281 [ # # ]: 0 : if ((session_id != NULL) &&
282 [ # # ]: 0 : (context->last_spdm_error.error_code == SPDM_ERROR_CODE_DECRYPT_ERROR)) {
283 : 0 : libspdm_free_session_id(context, *session_id);
284 : : }
285 [ # # ]: 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
286 : : "libspdm_receive_spdm_response[%x] status - %x\n",
287 : : (session_id != NULL) ? *session_id : 0x0, status));
288 : : } else {
289 [ + + ]: 68533 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
290 : : "libspdm_receive_spdm_response[%x] msg %s(0x%x), size (0x%zx): \n",
291 : : (session_id != NULL) ? *session_id : 0x0,
292 : : libspdm_get_code_str(((spdm_message_header_t *)*response)->
293 : : request_response_code),
294 : : ((spdm_message_header_t *)*response)->request_response_code,
295 : : *response_size));
296 : 68533 : LIBSPDM_INTERNAL_DUMP_HEX(*response, *response_size);
297 : : }
298 : :
299 : : /* Handle special case:
300 : : * If the Responder returns RESPONSE_NOT_READY error to KEY_UPDATE, the Requester needs
301 : : * to activate backup key to parse the error. Then later the Responder will return SUCCESS,
302 : : * the Requester needs new key. So we need to restore the environment by
303 : : * libspdm_create_update_session_data_key() again.*/
304 [ + + ]: 68533 : if (reset_key_update) {
305 : : /* temp_session_context and message_session_id must necessarily
306 : : * be valid for us to reach here. */
307 [ + - - + ]: 27 : if (temp_session_context == NULL || message_session_id == NULL) {
308 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
309 : : }
310 : 27 : result = libspdm_create_update_session_data_key(
311 : : temp_session_context, LIBSPDM_KEY_UPDATE_ACTION_RESPONDER);
312 [ - + ]: 27 : if (!result) {
313 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
314 : : }
315 : : }
316 : :
317 : 68533 : return status;
318 : :
319 : 1 : error:
320 [ - + ]: 1 : if (context->last_spdm_error.error_code == SPDM_ERROR_CODE_DECRYPT_ERROR) {
321 : 0 : return LIBSPDM_STATUS_SESSION_MSG_ERROR;
322 : : } else {
323 : 1 : return LIBSPDM_STATUS_RECEIVE_FAIL;
324 : : }
325 : : }
326 : :
327 : : #if LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP
328 : 15 : static libspdm_return_t libspdm_handle_large_request(
329 : : libspdm_context_t *spdm_context,
330 : : const uint32_t *session_id,
331 : : size_t request_size, void *request)
332 : : {
333 : : libspdm_return_t status;
334 : :
335 : : spdm_chunk_send_request_t *spdm_request;
336 : : spdm_chunk_send_request_14_t *spdm_request_14;
337 : : size_t spdm_request_size;
338 : : spdm_chunk_send_ack_response_t *spdm_response;
339 : : spdm_chunk_send_ack_response_14_t *spdm_response_14;
340 : : size_t response_header_size;
341 : : uint8_t *message;
342 : : size_t message_size;
343 : : void *response;
344 : : size_t response_size;
345 : : size_t transport_header_size;
346 : :
347 : : uint8_t *scratch_buffer;
348 : : size_t scratch_buffer_size;
349 : :
350 : : uint8_t *chunk_ptr;
351 : : size_t copy_size;
352 : : libspdm_chunk_info_t *send_info;
353 : : uint32_t min_data_transfer_size;
354 : : uint64_t max_chunk_data_transfer_size;
355 : : spdm_error_response_t *spdm_error;
356 : :
357 [ - + ]: 15 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_12) {
358 : 0 : return LIBSPDM_STATUS_UNSUPPORTED_CAP;
359 : : }
360 : :
361 : : /* Fail if requester or responder does not support chunk cap */
362 [ - + ]: 15 : if (!libspdm_is_capabilities_flag_supported(
363 : : spdm_context, true,
364 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_CHUNK_CAP,
365 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_CHUNK_CAP)) {
366 : 0 : return LIBSPDM_STATUS_ERROR_PEER;
367 : : }
368 : :
369 : : /* Fail if exceed max chunks */
370 : 15 : min_data_transfer_size = LIBSPDM_MIN(
371 : : spdm_context->connection_info.capability.data_transfer_size,
372 : : spdm_context->local_context.capability.sender_data_transfer_size);
373 : :
374 [ + + ]: 15 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_14) {
375 : : /* chunk seq no wrap not considered in spdm 1.4+ */
376 : :
377 : 13 : max_chunk_data_transfer_size =
378 : 13 : ((size_t) min_data_transfer_size - sizeof(spdm_chunk_send_request_t)) * 65536 -
379 : : sizeof(uint32_t);
380 : : /* max_spdm_msg_size is already checked in caller */
381 : :
382 [ + + ]: 13 : if (request_size > max_chunk_data_transfer_size) {
383 : 1 : return LIBSPDM_STATUS_BUFFER_TOO_SMALL;
384 : : }
385 : : }
386 : : /* now we can get sender buffer */
387 : 14 : transport_header_size = spdm_context->local_context.capability.transport_header_size;
388 : :
389 : 14 : libspdm_get_scratch_buffer(spdm_context, (void **)&scratch_buffer, &scratch_buffer_size);
390 : :
391 : : /* Temporary send/receive buffers for chunking are in the scratch space */
392 : 14 : message = scratch_buffer + libspdm_get_scratch_buffer_sender_receiver_offset(spdm_context);
393 : 14 : message_size = libspdm_get_scratch_buffer_sender_receiver_capacity(spdm_context);
394 : :
395 : 14 : send_info = &spdm_context->chunk_context.send;
396 : 14 : send_info->chunk_in_use = true;
397 : :
398 : : /* The first section of the scratch
399 : : * buffer may be used for other purposes. Use only after that section. */
400 : 28 : send_info->large_message = scratch_buffer +
401 : 14 : libspdm_get_scratch_buffer_large_message_offset(spdm_context);
402 : 14 : send_info->large_message_capacity =
403 : 14 : libspdm_get_scratch_buffer_large_message_capacity(spdm_context);
404 : :
405 : 14 : libspdm_zero_mem(send_info->large_message, send_info->large_message_capacity);
406 : 14 : libspdm_copy_mem(send_info->large_message, send_info->large_message_capacity,
407 : : request, request_size);
408 : :
409 : 14 : send_info->large_message_size = request_size;
410 : 14 : send_info->chunk_bytes_transferred = 0;
411 : 14 : send_info->chunk_seq_no = 0;
412 : 14 : request = NULL; /* Invalidate to prevent accidental use. */
413 : 14 : request_size = 0;
414 : :
415 : : do {
416 [ - + ]: 18 : LIBSPDM_ASSERT(send_info->large_message_capacity >= transport_header_size);
417 : 18 : spdm_request = (spdm_chunk_send_request_t *)((uint8_t *)message + transport_header_size);
418 : 18 : spdm_request_size = message_size - transport_header_size;
419 : :
420 : 18 : spdm_request->header.spdm_version = libspdm_get_connection_version(spdm_context);
421 : 18 : spdm_request->header.request_response_code = SPDM_CHUNK_SEND;
422 : 18 : spdm_request->header.param1 = 0;
423 : 18 : spdm_request->header.param2 = send_info->chunk_handle;
424 : :
425 [ + + ]: 18 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_14) {
426 : 14 : spdm_request->chunk_seq_no = (uint16_t) send_info->chunk_seq_no;
427 : 14 : spdm_request->reserved = 0;
428 : 14 : chunk_ptr = (uint8_t *)(spdm_request + 1);
429 : : } else {
430 : 4 : spdm_request_14 = (spdm_chunk_send_request_14_t *)spdm_request;
431 : 4 : spdm_request_14->chunk_seq_no = send_info->chunk_seq_no;
432 : 4 : chunk_ptr = (uint8_t *)(spdm_request_14 + 1);
433 : : }
434 : :
435 : : LIBSPDM_ASSERT(sizeof(spdm_chunk_send_request_t) == sizeof(spdm_chunk_send_request_14_t));
436 : 18 : if ((min_data_transfer_size - sizeof(spdm_chunk_send_request_t)) <
437 [ + + ]: 18 : (send_info->large_message_size - send_info->chunk_bytes_transferred)) {
438 : 14 : copy_size = min_data_transfer_size - sizeof(spdm_chunk_send_request_t);
439 : : } else {
440 : 4 : copy_size = (send_info->large_message_size - send_info->chunk_bytes_transferred);
441 : : }
442 : :
443 [ + + ]: 18 : if (send_info->chunk_seq_no == 0) {
444 : 14 : libspdm_write_uint32((uint8_t *)(spdm_request + 1),
445 : 14 : (uint32_t)send_info->large_message_size);
446 : 14 : chunk_ptr += sizeof(uint32_t);
447 : 14 : copy_size -= sizeof(uint32_t);
448 : : }
449 : :
450 : 18 : spdm_request->chunk_size = (uint32_t)copy_size;
451 : :
452 : 18 : libspdm_copy_mem(
453 : 18 : chunk_ptr, spdm_request_size - ((uint8_t *)spdm_request - (uint8_t *)message),
454 : 18 : (uint8_t *)send_info->large_message + send_info->chunk_bytes_transferred, copy_size);
455 : :
456 : 18 : send_info->chunk_bytes_transferred += copy_size;
457 [ + + ]: 18 : if (send_info->chunk_bytes_transferred >= send_info->large_message_size) {
458 : 4 : spdm_request->header.param1 |= SPDM_CHUNK_SEND_REQUEST_ATTRIBUTE_LAST_CHUNK;
459 : : }
460 : :
461 : 18 : spdm_request_size = (chunk_ptr + copy_size) - (uint8_t *)spdm_request;
462 : 18 : status = libspdm_send_request(
463 : : spdm_context, session_id, false,
464 : : spdm_request_size, spdm_request);
465 : :
466 [ + + ]: 18 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
467 : 1 : break;
468 : : }
469 : :
470 : 17 : response = message;
471 : 17 : response_size = message_size;
472 : :
473 : 17 : libspdm_zero_mem(response, response_size);
474 : :
475 : 17 : status = libspdm_receive_response(
476 : : spdm_context, session_id, false,
477 : : &response_size, &response);
478 : :
479 [ + + ]: 17 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
480 : 1 : break;
481 : : }
482 : 16 : spdm_response = (void *)(response);
483 : :
484 [ - + ]: 16 : if (response_size < sizeof(spdm_message_header_t)) {
485 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
486 : 0 : break;
487 : : }
488 : :
489 [ + + ]: 16 : if (spdm_response->header.request_response_code == SPDM_ERROR
490 [ + + ]: 3 : && spdm_response->header.param1 != SPDM_ERROR_CODE_LARGE_RESPONSE) {
491 : 2 : status = libspdm_handle_simple_error_response(spdm_context,
492 : 2 : spdm_response->header.param1);
493 : 2 : break;
494 : : }
495 : :
496 [ + + ]: 14 : if (spdm_response->header.spdm_version != libspdm_get_connection_version(spdm_context)) {
497 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
498 : 1 : break;
499 : : }
500 : :
501 [ + + ]: 13 : if (spdm_response->header.request_response_code == SPDM_ERROR
502 [ + - ]: 1 : && spdm_response->header.param1 == SPDM_ERROR_CODE_LARGE_RESPONSE) {
503 : :
504 : : /* It is possible that the CHUNK_SEND_ACK + chunk response is larger
505 : : * than the DATA_TRANSFER_SIZE. In this case an ERROR_LARGE_RESPONSE
506 : : * is returned directly in the response buffer rather than part of
507 : : * the CHUNK_SEND_ACK. Store this error response in scratch buffer
508 : : * to be handled when reading response. Also note that in this case
509 : : * of large response, the CHUNK_SEND_ACK portion is not sent.
510 : : * Only the response portion that requires the CHUNK_GET is sent */
511 [ + - ]: 1 : if (response_size < send_info->large_message_capacity) {
512 : 1 : libspdm_copy_mem(
513 : : send_info->large_message, send_info->large_message_capacity,
514 : : spdm_response, response_size);
515 : 1 : send_info->large_message_size = response_size;
516 : 1 : break;
517 : : } else {
518 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
519 : 0 : break;
520 : : }
521 : : } else {
522 [ - + ]: 12 : if (spdm_response->header.request_response_code != SPDM_CHUNK_SEND_ACK) {
523 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
524 : 0 : break;
525 : : }
526 : :
527 [ + + ]: 12 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_14) {
528 : 9 : response_header_size = sizeof(spdm_chunk_send_ack_response_t);
529 : : } else {
530 : 3 : response_header_size = sizeof(spdm_chunk_send_ack_response_14_t);
531 : 3 : spdm_response_14 = (spdm_chunk_send_ack_response_14_t *)spdm_response;
532 : : }
533 : :
534 [ + + ]: 12 : if (response_size < response_header_size) {
535 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
536 : 1 : break;
537 : : }
538 : 11 : if (spdm_response->header.param1
539 [ + + ]: 11 : & SPDM_CHUNK_SEND_ACK_RESPONSE_ATTRIBUTE_EARLY_ERROR_DETECTED) {
540 : :
541 : 2 : spdm_error = (spdm_error_response_t *)((uint8_t *)spdm_response + response_header_size);
542 [ - + ]: 2 : if (response_size < (response_header_size +
543 : : sizeof(spdm_error_response_t))) {
544 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
545 : 0 : break;
546 : : }
547 [ + - ]: 2 : if ((spdm_error->header.spdm_version !=
548 : 2 : libspdm_get_connection_version(spdm_context)) ||
549 [ - + ]: 2 : (spdm_error->header.request_response_code != SPDM_ERROR)) {
550 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
551 : 0 : break;
552 : : }
553 [ + + ]: 2 : if (spdm_error->header.param1 == SPDM_ERROR_CODE_LARGE_RESPONSE) {
554 : 1 : status = LIBSPDM_STATUS_ERROR_PEER;
555 : 1 : break;
556 : : }
557 : :
558 : : /* Store the error response in scratch buffer to be read by
559 : : * libspdm_receive_spdm_response and returned to its caller
560 : : * and handled in the error response handling flow */
561 : 1 : libspdm_copy_mem(
562 : : send_info->large_message,
563 : : send_info->large_message_capacity,
564 : : (uint8_t *)spdm_response + response_header_size,
565 : : response_size - response_header_size);
566 : :
567 : 1 : send_info->large_message_size =
568 : 1 : (response_size - response_header_size);
569 : 1 : status = LIBSPDM_STATUS_SUCCESS;
570 : 1 : break;
571 : : }
572 [ + + ]: 9 : if (spdm_response->header.param2 != send_info->chunk_handle) {
573 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
574 : 1 : break;
575 : : }
576 [ + + ]: 8 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_14) {
577 [ + + ]: 5 : if (send_info->chunk_seq_no != spdm_response->chunk_seq_no) {
578 : 1 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
579 : 1 : break;
580 : : }
581 : : } else {
582 [ - + ]: 3 : if (send_info->chunk_seq_no != spdm_response_14->chunk_seq_no) {
583 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
584 : 0 : break;
585 : : }
586 : : }
587 : :
588 : 7 : chunk_ptr = (uint8_t *)spdm_response + response_header_size;
589 : 7 : send_info->chunk_seq_no++;
590 : :
591 [ + + ]: 7 : if (send_info->chunk_bytes_transferred >= send_info->large_message_size) {
592 : : /* All bytes have been transferred. Store response in scratch buffer
593 : : * to be read by libspdm_receive_spdm_response */
594 : 3 : libspdm_copy_mem(
595 : : send_info->large_message, send_info->large_message_capacity,
596 : : chunk_ptr, response_size - response_header_size);
597 : 3 : send_info->large_message_size =
598 : 3 : (response_size - response_header_size);
599 : 3 : break;
600 : : }
601 : : }
602 : :
603 : 4 : } while (LIBSPDM_STATUS_IS_SUCCESS(status)
604 [ + - + - ]: 4 : && send_info->chunk_bytes_transferred < send_info->large_message_size);
605 : :
606 [ + + ]: 14 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
607 : 9 : libspdm_zero_mem(send_info->large_message, send_info->large_message_capacity);
608 : 9 : send_info->chunk_in_use = false;
609 : 9 : send_info->chunk_handle++; /* Implicit wrap-around*/
610 : 9 : send_info->chunk_seq_no = 0;
611 : 9 : send_info->chunk_bytes_transferred = 0;
612 : 9 : send_info->large_message = NULL;
613 : 9 : send_info->large_message_size = 0;
614 : 9 : send_info->large_message_capacity = 0;
615 : : }
616 : :
617 : 14 : return status;
618 : : }
619 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
620 : :
621 : 68604 : libspdm_return_t libspdm_send_spdm_request(libspdm_context_t *spdm_context,
622 : : const uint32_t *session_id,
623 : : size_t request_size, void *request)
624 : : {
625 : : libspdm_session_info_t *session_info;
626 : : libspdm_session_state_t session_state;
627 : : libspdm_return_t status;
628 : : #if LIBSPDM_ENABLE_MSG_LOG
629 : : size_t msg_log_size;
630 : : #endif /* LIBSPDM_ENABLE_MSG_LOG */
631 : :
632 : : /* If chunking is not supported then message must fit in both the send buffer and the receive
633 : : * buffer. */
634 [ + + ]: 68604 : if (!libspdm_is_capabilities_flag_supported(
635 : : spdm_context, true,
636 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_CHUNK_CAP,
637 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_CHUNK_CAP)) {
638 [ + + ]: 2938 : if ((spdm_context->connection_info.capability.data_transfer_size != 0) &&
639 [ - + ]: 12 : (request_size > spdm_context->connection_info.capability.data_transfer_size)) {
640 : 0 : return LIBSPDM_STATUS_PEER_BUFFER_TOO_SMALL;
641 : : }
642 [ + - ]: 2938 : if ((spdm_context->local_context.capability.sender_data_transfer_size != 0) &&
643 [ - + ]: 2938 : (request_size > spdm_context->local_context.capability.sender_data_transfer_size)) {
644 : 0 : return LIBSPDM_STATUS_BUFFER_TOO_SMALL;
645 : : }
646 : : }
647 : :
648 [ + + + + ]: 68929 : if ((session_id != NULL) &&
649 : 325 : libspdm_is_capabilities_flag_supported(
650 : : spdm_context, true,
651 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
652 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
653 : 41 : session_info = libspdm_get_session_info_via_session_id(spdm_context, *session_id);
654 [ - + ]: 41 : LIBSPDM_ASSERT(session_info != NULL);
655 [ - + ]: 41 : if (session_info == NULL) {
656 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
657 : : }
658 : 41 : session_state = libspdm_secured_message_get_session_state(
659 : : session_info->secured_message_context);
660 [ + - + - ]: 41 : if ((session_state == LIBSPDM_SESSION_STATE_HANDSHAKING) && !session_info->use_psk) {
661 : 41 : session_id = NULL;
662 : : }
663 : : }
664 : :
665 [ + + ]: 68604 : if ((spdm_context->connection_info.capability.max_spdm_msg_size != 0) &&
666 [ + + ]: 65604 : (request_size > spdm_context->connection_info.capability.max_spdm_msg_size)) {
667 : 1 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "request_size > rsp max_spdm_msg_size\n"));
668 : 1 : return LIBSPDM_STATUS_PEER_BUFFER_TOO_SMALL;
669 : : }
670 [ - + ]: 68603 : LIBSPDM_ASSERT (request_size <= spdm_context->local_context.capability.max_spdm_msg_size);
671 : :
672 : : #if LIBSPDM_ENABLE_MSG_LOG
673 : : /* First save the size of the message log buffer. If there is an error it will be reverted. */
674 : 68603 : msg_log_size = libspdm_get_msg_log_size(spdm_context);
675 : 68603 : libspdm_append_msg_log(spdm_context, request, request_size);
676 : : #endif /* LIBSPDM_ENABLE_MSG_LOG */
677 : :
678 : : /* large SPDM message is the SPDM message whose size is greater than the DataTransferSize of the receiving
679 : : * SPDM endpoint or greater than the transmit buffer size of the sending SPDM endpoint */
680 [ + + ]: 68603 : if (((const spdm_message_header_t *)request)->request_response_code != SPDM_GET_VERSION
681 [ + + ]: 68516 : && ((const spdm_message_header_t *)request)->request_response_code != SPDM_GET_CAPABILITIES
682 [ + + ]: 68387 : && ((spdm_context->connection_info.capability.data_transfer_size != 0 &&
683 [ + + ]: 65582 : request_size > spdm_context->connection_info.capability.data_transfer_size) ||
684 [ + - ]: 68373 : (spdm_context->local_context.capability.sender_data_transfer_size != 0 &&
685 [ + + ]: 68373 : request_size > spdm_context->local_context.capability.sender_data_transfer_size))) {
686 : :
687 : : #if LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP
688 : : /* libspdm_send_request is not called with the original request in this flow.
689 : : * This leads to the last_spdm_request field not having the original request value.
690 : : * The caller assumes the request has been copied to last_spdm_request,
691 : : * so that it can compare last_spdm_request's fields with response fields
692 : : * Therefore the request must be copied to last_spdm_request here. */
693 : :
694 [ + - ]: 15 : if (((const spdm_message_header_t *)request)->request_response_code != SPDM_RESPOND_IF_READY
695 [ + - ]: 15 : && ((const spdm_message_header_t *)request)->request_response_code != SPDM_CHUNK_GET
696 [ + - ]: 15 : && ((const spdm_message_header_t *)request)->request_response_code != SPDM_CHUNK_SEND) {
697 : 15 : libspdm_copy_mem(
698 : : spdm_context->last_spdm_request,
699 : 15 : libspdm_get_scratch_buffer_last_spdm_request_capacity(spdm_context),
700 : : request, request_size);
701 : 15 : spdm_context->last_spdm_request_size = request_size;
702 : : }
703 : :
704 : 15 : status = libspdm_handle_large_request(
705 : : spdm_context, session_id, request_size, request);
706 : : #else /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP*/
707 : : status = LIBSPDM_STATUS_BUFFER_TOO_SMALL;
708 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP*/
709 : : } else {
710 : 68588 : status = libspdm_send_request(spdm_context, session_id, false, request_size, request);
711 : : }
712 : :
713 : : #if LIBSPDM_ENABLE_MSG_LOG
714 : : /* If there is an error in sending the request then revert the request in the message log. */
715 [ + + ]: 68603 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
716 : 40 : spdm_context->msg_log.buffer_size = msg_log_size;
717 : : }
718 : : #endif /* LIBSPDM_ENABLE_MSG_LOG */
719 : :
720 : 68603 : return status;
721 : : }
722 : :
723 : 68547 : libspdm_return_t libspdm_receive_spdm_response(libspdm_context_t *spdm_context,
724 : : const uint32_t *session_id,
725 : : size_t *response_size,
726 : : void **response)
727 : : {
728 : : libspdm_return_t status;
729 : : libspdm_session_info_t *session_info;
730 : : libspdm_session_state_t session_state;
731 : :
732 : : #if LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP
733 : : spdm_message_header_t *spdm_response;
734 : : size_t response_capacity;
735 : : libspdm_chunk_info_t *send_info;
736 : 68547 : bool response_from_chunk = false;
737 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
738 : :
739 [ + + + + ]: 68861 : if ((session_id != NULL) &&
740 : 314 : libspdm_is_capabilities_flag_supported(
741 : : spdm_context, true,
742 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
743 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
744 : 40 : session_info = libspdm_get_session_info_via_session_id(spdm_context, *session_id);
745 [ - + ]: 40 : LIBSPDM_ASSERT(session_info != NULL);
746 [ - + ]: 40 : if (session_info == NULL) {
747 : 0 : return LIBSPDM_STATUS_INVALID_STATE_LOCAL;
748 : : }
749 : 40 : session_state = libspdm_secured_message_get_session_state(
750 : : session_info->secured_message_context);
751 [ + - + - ]: 40 : if ((session_state == LIBSPDM_SESSION_STATE_HANDSHAKING) && !session_info->use_psk) {
752 : 40 : session_id = NULL;
753 : : }
754 : : }
755 : :
756 : : #if !(LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP)
757 : : status = libspdm_receive_response(spdm_context, session_id, false, response_size, response);
758 : : #else /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
759 : 68547 : send_info = &spdm_context->chunk_context.send;
760 [ + + ]: 68547 : if (send_info->chunk_in_use) {
761 : 5 : libspdm_copy_mem(*response, *response_size,
762 : 5 : send_info->large_message, send_info->large_message_size);
763 : 5 : *response_size = send_info->large_message_size;
764 : 5 : response_capacity = send_info->large_message_capacity;
765 : 5 : response_from_chunk = true;
766 : :
767 : : /* This response may either be an actual response or ERROR_LARGE_RESPONSE,
768 : : * the latter which should be handled in the large response handler. */
769 : 5 : libspdm_zero_mem(send_info->large_message, send_info->large_message_capacity);
770 : 5 : send_info->chunk_in_use = false;
771 : 5 : send_info->chunk_handle++; /* Implicit wrap-around*/
772 : 5 : send_info->chunk_seq_no = 0;
773 : 5 : send_info->chunk_bytes_transferred = 0;
774 : 5 : send_info->large_message = NULL;
775 : 5 : send_info->large_message_size = 0;
776 : 5 : send_info->large_message_capacity = 0;
777 : 5 : status = LIBSPDM_STATUS_SUCCESS;
778 : : } else {
779 : 68542 : response_capacity = *response_size;
780 : 68542 : status = libspdm_receive_response(spdm_context, session_id, false, response_size, response);
781 [ + + ]: 68542 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
782 : 27 : goto receive_done;
783 : : }
784 : : }
785 : :
786 : 68520 : spdm_response = (spdm_message_header_t *)(*response);
787 : :
788 [ - + ]: 68520 : if (*response_size < sizeof(spdm_message_header_t)) {
789 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
790 : 0 : goto receive_done;
791 : : }
792 : :
793 [ + + ]: 68520 : if (spdm_response->request_response_code == SPDM_ERROR
794 [ + + ]: 539 : && spdm_response->param1 == SPDM_ERROR_CODE_LARGE_RESPONSE
795 [ - + ]: 11 : && !spdm_context->chunk_context.get.chunk_in_use) {
796 : 11 : status = libspdm_handle_error_large_response(
797 : : spdm_context, session_id,
798 : : response_size, (void *)spdm_response, response_capacity, response_from_chunk);
799 : :
800 [ + + ]: 11 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
801 : 4 : goto receive_done;
802 : : }
803 : :
804 [ - + ]: 7 : if (*response_size < sizeof(spdm_message_header_t)) {
805 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_SIZE;
806 : 0 : goto receive_done;
807 : : }
808 : :
809 : : /* Per the spec, SPDM_VERSION shall not be chunked
810 : : * and should be an unexpected error. */
811 [ - + ]: 7 : if (spdm_response->request_response_code == SPDM_VERSION) {
812 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
813 : 0 : goto receive_done;
814 : : }
815 : :
816 : : /* Per the spec, SPDM_CAPABILITIES shall not be chunked unless
817 : : * the response includes Supported Algorithms. */
818 [ + + ]: 7 : if (spdm_response->request_response_code == SPDM_CAPABILITIES) {
819 [ + - ]: 1 : if ((spdm_response->param1 &
820 : : SPDM_CAPABILITIES_RESPONSE_PARAM1_SUPPORTED_ALGORITHMS) == 0) {
821 : 0 : status = LIBSPDM_STATUS_INVALID_MSG_FIELD;
822 : 0 : goto receive_done;
823 : : }
824 : : }
825 : : }
826 : :
827 : 68516 : receive_done:
828 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHUNK_CAP */
829 : :
830 : 68547 : return status;
831 : : }
|