Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2021-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_responder_lib.h"
8 : :
9 : : #if LIBSPDM_ENABLE_CAPABILITY_CHAL_CAP
10 : :
11 : : #if (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP) && \
12 : : (LIBSPDM_SEND_CHALLENGE_SUPPORT)
13 : 1 : static void init_encap_state(libspdm_context_t *spdm_context)
14 : : {
15 : 1 : spdm_context->encap_context.request_id = 0;
16 : 1 : spdm_context->encap_context.last_encap_request_size = 0;
17 : 1 : libspdm_zero_mem(&spdm_context->encap_context.last_encap_request_header,
18 : : sizeof(spdm_context->encap_context.last_encap_request_header));
19 : 1 : spdm_context->encap_context.payload_buffer_size = 0;
20 : 1 : spdm_context->encap_context.flow_type = LIBSPDM_ENCAP_FLOW_BASIC_MUT_AUTH;
21 : :
22 : : /* Clear Cache. */
23 : 1 : libspdm_reset_message_mut_b(spdm_context);
24 : 1 : libspdm_reset_message_mut_c(spdm_context);
25 : 1 : }
26 : : #endif /* (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (...) */
27 : :
28 : 28 : libspdm_return_t libspdm_get_response_challenge_auth(libspdm_context_t *spdm_context,
29 : : size_t request_size,
30 : : const void *request,
31 : : size_t *response_size,
32 : : void *response)
33 : : {
34 : : const spdm_challenge_request_t *spdm_request;
35 : : size_t spdm_request_size;
36 : : spdm_challenge_auth_response_t *spdm_response;
37 : : bool result;
38 : : size_t signature_size;
39 : : uint8_t slot_id;
40 : : uint32_t hash_size;
41 : : uint32_t measurement_summary_hash_size;
42 : : uint8_t *ptr;
43 : : uint8_t auth_attribute;
44 : : libspdm_return_t status;
45 : : uint8_t slot_mask;
46 : : uint8_t *opaque_data;
47 : : size_t opaque_data_size;
48 : : size_t request_context_size;
49 : : const void *request_context;
50 : : size_t spdm_response_size;
51 : :
52 : 28 : spdm_request = request;
53 : :
54 : : /* -=[Check Parameters Phase]=- */
55 [ - + ]: 28 : LIBSPDM_ASSERT(spdm_request->header.request_response_code == SPDM_CHALLENGE);
56 : :
57 [ + + ]: 28 : if (spdm_request->header.spdm_version != libspdm_get_connection_version(spdm_context)) {
58 : 2 : return libspdm_generate_error_response(spdm_context,
59 : : SPDM_ERROR_CODE_VERSION_MISMATCH, 0,
60 : : response_size, response);
61 : : }
62 [ + + ]: 26 : if (spdm_context->response_state != LIBSPDM_RESPONSE_STATE_NORMAL) {
63 : 4 : return libspdm_responder_handle_response_state(
64 : : spdm_context,
65 : 4 : spdm_request->header.request_response_code,
66 : : response_size, response);
67 : : }
68 [ + + ]: 22 : if (spdm_context->last_spdm_request_session_id_valid) {
69 : 1 : return libspdm_generate_error_response(spdm_context,
70 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
71 : : response_size, response);
72 : : }
73 [ + + ]: 21 : if (!libspdm_is_capabilities_flag_supported(
74 : : spdm_context, false, 0,
75 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_CHAL_CAP)) {
76 : 2 : return libspdm_generate_error_response(
77 : : spdm_context, SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
78 : : SPDM_CHALLENGE, response_size, response);
79 : : }
80 [ + + ]: 19 : if (spdm_context->connection_info.connection_state < LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
81 : 2 : return libspdm_generate_error_response(spdm_context,
82 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST,
83 : : 0, response_size, response);
84 : : }
85 : :
86 [ - + ]: 17 : if (request_size < sizeof(spdm_challenge_request_t)) {
87 : 0 : return libspdm_generate_error_response(spdm_context,
88 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
89 : : response_size, response);
90 : : }
91 : 17 : spdm_request_size = sizeof(spdm_challenge_request_t);
92 [ + + ]: 17 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
93 [ - + ]: 2 : if (request_size < sizeof(spdm_challenge_request_t) + SPDM_REQ_CONTEXT_SIZE) {
94 : 0 : return libspdm_generate_error_response(spdm_context,
95 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
96 : : response_size, response);
97 : : }
98 : 2 : spdm_request_size += SPDM_REQ_CONTEXT_SIZE;
99 : : }
100 [ + + ]: 17 : if (spdm_request->header.param2 > 0) {
101 [ + + ]: 6 : if (!libspdm_is_capabilities_flag_supported(
102 : : spdm_context, false, 0,
103 : 3 : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP) ||
104 [ + - ]: 3 : (spdm_context->connection_info.algorithm.measurement_spec == 0) ||
105 [ - + ]: 3 : (spdm_context->connection_info.algorithm.measurement_hash_algo == 0) ) {
106 : 3 : return libspdm_generate_error_response (spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
107 : : 0, response_size, response);
108 : : }
109 : : }
110 : :
111 : 14 : slot_id = spdm_request->header.param1;
112 : :
113 [ + + + + ]: 14 : if ((slot_id != 0xFF) && (slot_id >= SPDM_MAX_SLOT_COUNT)) {
114 : 1 : return libspdm_generate_error_response(spdm_context,
115 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
116 : : response_size, response);
117 : : }
118 : :
119 [ + + ]: 13 : if (slot_id != 0xFF) {
120 [ + + ]: 12 : if (spdm_context->local_context.local_cert_chain_provision[slot_id] == NULL) {
121 : 1 : return libspdm_generate_error_response(
122 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
123 : : 0, response_size, response);
124 : : }
125 : : } else {
126 [ - + ]: 1 : if (spdm_context->local_context.local_public_key_provision == NULL) {
127 : 0 : return libspdm_generate_error_response(
128 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
129 : : 0, response_size, response);
130 : : }
131 : : }
132 : :
133 [ + + ]: 12 : if ((spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) &&
134 [ + + + - ]: 2 : spdm_context->connection_info.multi_key_conn_rsp &&
135 : : (slot_id != 0xFF)) {
136 [ + - ]: 1 : if ((spdm_context->local_context.local_key_usage_bit_mask[slot_id] &
137 : : SPDM_KEY_USAGE_BIT_MASK_CHALLENGE_USE) == 0) {
138 : 1 : return libspdm_generate_error_response(
139 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
140 : : 0, response_size, response);
141 : : }
142 : : }
143 : :
144 [ - + ]: 11 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
145 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
146 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
147 : : } else {
148 : 11 : signature_size = libspdm_get_asym_signature_size(
149 : : spdm_context->connection_info.algorithm.base_asym_algo);
150 : : }
151 : 11 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
152 : 11 : measurement_summary_hash_size = libspdm_get_measurement_summary_hash_size(
153 : 11 : spdm_context, false, spdm_request->header.param2);
154 [ + + ]: 11 : if ((measurement_summary_hash_size == 0) &&
155 [ - + ]: 8 : (spdm_request->header.param2 != SPDM_CHALLENGE_REQUEST_NO_MEASUREMENT_SUMMARY_HASH)) {
156 : 0 : return libspdm_generate_error_response(spdm_context,
157 : : SPDM_ERROR_CODE_INVALID_REQUEST,
158 : : 0, response_size, response);
159 : : }
160 : :
161 [ + + ]: 11 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
162 : 1 : request_context_size = SPDM_REQ_CONTEXT_SIZE;
163 : 1 : request_context = spdm_request + 1;
164 : : } else {
165 : 10 : request_context_size = 0;
166 : 10 : request_context = NULL;
167 : : }
168 : :
169 : : /* response_size should be large enough to hold a challenge response without opaque data. */
170 [ - + ]: 11 : LIBSPDM_ASSERT(*response_size >= sizeof(spdm_challenge_auth_response_t) + hash_size +
171 : : SPDM_NONCE_SIZE + measurement_summary_hash_size + sizeof(uint16_t) +
172 : : SPDM_REQ_CONTEXT_SIZE + signature_size);
173 : :
174 : 11 : libspdm_zero_mem(response, *response_size);
175 : 11 : spdm_response = response;
176 : :
177 : 11 : libspdm_reset_message_buffer_via_request_code(spdm_context, NULL,
178 : 11 : spdm_request->header.request_response_code);
179 : :
180 : 11 : spdm_response->header.spdm_version = spdm_request->header.spdm_version;
181 : 11 : spdm_response->header.request_response_code = SPDM_CHALLENGE_AUTH;
182 : 11 : auth_attribute = (uint8_t)(slot_id & 0xF);
183 : :
184 : : #if (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP) && \
185 : : (LIBSPDM_SEND_CHALLENGE_SUPPORT)
186 [ + - ]: 11 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_11) {
187 [ + + ]: 11 : if (libspdm_is_capabilities_flag_supported(
188 : : spdm_context, false,
189 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_MUT_AUTH_CAP,
190 [ + - ]: 1 : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MUT_AUTH_CAP) &&
191 : 1 : libspdm_is_capabilities_flag_supported(
192 : : spdm_context, false,
193 [ - + ]: 1 : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_CHAL_CAP, 0) &&
194 : 1 : (libspdm_is_capabilities_flag_supported(
195 : : spdm_context, false,
196 [ # # ]: 0 : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_CERT_CAP, 0) ||
197 : 0 : libspdm_is_capabilities_flag_supported(
198 : : spdm_context, false,
199 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_PUB_KEY_ID_CAP, 0))) {
200 [ + - ]: 1 : if (libspdm_challenge_start_mut_auth(spdm_context,
201 : 1 : spdm_context->connection_info.version,
202 : : slot_id,
203 : : request_context_size,
204 : : request_context)) {
205 : 1 : auth_attribute |= SPDM_CHALLENGE_AUTH_RESPONSE_ATTRIBUTE_BASIC_MUT_AUTH_REQ;
206 : 1 : init_encap_state(spdm_context);
207 : 1 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO,
208 : : "Basic mutual authentication is a deprecated feature.\n"));
209 : : }
210 : : }
211 : : }
212 : : #endif /* (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (...) */
213 : :
214 : 11 : spdm_response->header.param1 = auth_attribute;
215 : :
216 [ + + ]: 11 : if (slot_id == 0xFF) {
217 : 1 : spdm_response->header.param2 = 0;
218 : : } else {
219 : 10 : slot_mask = libspdm_get_cert_slot_mask(spdm_context);
220 [ + - ]: 10 : if (slot_mask != 0) {
221 : 10 : spdm_response->header.param2 = slot_mask;
222 : : } else {
223 : 0 : return libspdm_generate_error_response(
224 : : spdm_context, SPDM_ERROR_CODE_UNSPECIFIED,
225 : : 0, response_size, response);
226 : : }
227 : : }
228 : :
229 : 11 : ptr = (void *)(spdm_response + 1);
230 [ + + ]: 11 : if (slot_id == 0xFF) {
231 : 1 : result = libspdm_generate_public_key_hash(spdm_context, ptr);
232 : : } else {
233 : 10 : result = libspdm_generate_cert_chain_hash(spdm_context, slot_id, ptr);
234 : : }
235 [ - + ]: 11 : if (!result) {
236 : 0 : return libspdm_generate_error_response(spdm_context,
237 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
238 : : response_size, response);
239 : : }
240 : 11 : ptr += hash_size;
241 : :
242 : 11 : result = libspdm_get_random_number(SPDM_NONCE_SIZE, ptr);
243 [ - + ]: 11 : if (!result) {
244 : 0 : return libspdm_generate_error_response(spdm_context,
245 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
246 : : response_size, response);
247 : : }
248 : 11 : ptr += SPDM_NONCE_SIZE;
249 : :
250 : : #if LIBSPDM_ENABLE_CAPABILITY_MEAS_CAP
251 [ + + ]: 11 : if (libspdm_is_capabilities_flag_supported(
252 : 3 : spdm_context, false, 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP) &&
253 [ + + ]: 3 : ((spdm_request->header.param2 == SPDM_REQUEST_TCB_COMPONENT_MEASUREMENT_HASH) ||
254 [ + - ]: 2 : (spdm_request->header.param2 == SPDM_REQUEST_ALL_MEASUREMENTS_HASH))) {
255 : 3 : result = libspdm_generate_measurement_summary_hash(
256 : : spdm_context,
257 : 3 : spdm_context->connection_info.version,
258 : : spdm_context->connection_info.algorithm.base_hash_algo,
259 : 3 : spdm_context->connection_info.algorithm.measurement_spec,
260 : : spdm_context->connection_info.algorithm.measurement_hash_algo,
261 : 3 : spdm_request->header.param2,
262 : : ptr,
263 : : measurement_summary_hash_size);
264 : :
265 [ - + ]: 3 : if (!result) {
266 : 0 : return libspdm_generate_error_response(spdm_context,
267 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
268 : : response_size, response);
269 : : }
270 : : }
271 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_MEAS_CAP */
272 : :
273 : 11 : ptr += measurement_summary_hash_size;
274 : :
275 : 11 : opaque_data_size = *response_size - (sizeof(spdm_challenge_auth_response_t) + hash_size +
276 : 11 : SPDM_NONCE_SIZE + measurement_summary_hash_size +
277 : 11 : sizeof(uint16_t) + signature_size);
278 : 11 : opaque_data =
279 : 11 : (uint8_t*)response + sizeof(spdm_challenge_auth_response_t) + hash_size + SPDM_NONCE_SIZE +
280 : 11 : measurement_summary_hash_size + sizeof(uint16_t);
281 : :
282 [ + + ]: 11 : if ((libspdm_get_connection_version(spdm_context) >= SPDM_MESSAGE_VERSION_12) &&
283 [ + - ]: 1 : ((spdm_context->connection_info.algorithm.other_params_support &
284 : : SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_MASK) == SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_NONE)) {
285 : 1 : opaque_data_size = 0;
286 : : } else {
287 : 10 : result = libspdm_challenge_opaque_data(
288 : : spdm_context,
289 : 10 : spdm_context->connection_info.version,
290 : : slot_id,
291 : : request_context_size,
292 : : request_context,
293 : : opaque_data, &opaque_data_size);
294 [ - + ]: 10 : if (!result) {
295 : 0 : return libspdm_generate_error_response(
296 : : spdm_context, SPDM_ERROR_CODE_UNSPECIFIED,
297 : : 0, response_size, response);
298 : : }
299 : : }
300 : :
301 : : /*write opaque_data_size*/
302 : 11 : libspdm_write_uint16 (ptr, (uint16_t)opaque_data_size);
303 : 11 : ptr += sizeof(uint16_t);
304 : :
305 : : /*the opaque_data is stored by libspdm_challenge_opaque_data*/
306 : 11 : ptr += opaque_data_size;
307 : :
308 [ + + ]: 11 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
309 : 1 : libspdm_copy_mem(ptr, SPDM_REQ_CONTEXT_SIZE,
310 : 1 : spdm_request + 1, SPDM_REQ_CONTEXT_SIZE);
311 : 1 : ptr += SPDM_REQ_CONTEXT_SIZE;
312 : : }
313 : :
314 : : /*get actual response size*/
315 : 11 : spdm_response_size =
316 : : sizeof(spdm_challenge_auth_response_t) + hash_size +
317 : 11 : SPDM_NONCE_SIZE + measurement_summary_hash_size +
318 : 11 : sizeof(uint16_t) + opaque_data_size + signature_size;
319 [ + + ]: 11 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
320 : 1 : spdm_response_size += SPDM_REQ_CONTEXT_SIZE;
321 : : }
322 : :
323 [ - + ]: 11 : LIBSPDM_ASSERT(*response_size >= spdm_response_size);
324 : :
325 : 11 : *response_size = spdm_response_size;
326 : :
327 : : /* Calc Sign*/
328 : :
329 : 11 : status = libspdm_append_message_c(spdm_context, spdm_request, spdm_request_size);
330 [ - + ]: 11 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
331 : 0 : return libspdm_generate_error_response(spdm_context,
332 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
333 : : response_size, response);
334 : : }
335 : :
336 : 11 : status = libspdm_append_message_c(spdm_context, spdm_response,
337 : 11 : (size_t)ptr - (size_t)spdm_response);
338 [ - + ]: 11 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
339 : 0 : libspdm_reset_message_c(spdm_context);
340 : 0 : return libspdm_generate_error_response(spdm_context,
341 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
342 : : response_size, response);
343 : : }
344 : 11 : result = libspdm_generate_challenge_auth_signature(spdm_context, false, slot_id, ptr);
345 [ - + ]: 11 : if (!result) {
346 : 0 : libspdm_reset_message_c(spdm_context);
347 : 0 : return libspdm_generate_error_response(
348 : : spdm_context, SPDM_ERROR_CODE_UNSPECIFIED,
349 : : 0, response_size, response);
350 : : }
351 : 11 : ptr += signature_size;
352 : :
353 [ + + ]: 11 : if ((auth_attribute & SPDM_CHALLENGE_AUTH_RESPONSE_ATTRIBUTE_BASIC_MUT_AUTH_REQ) == 0) {
354 : 10 : libspdm_set_connection_state(spdm_context,
355 : : LIBSPDM_CONNECTION_STATE_AUTHENTICATED);
356 : : }
357 : :
358 : 11 : libspdm_reset_message_b(spdm_context);
359 : 11 : libspdm_reset_message_c(spdm_context);
360 : :
361 : 11 : return LIBSPDM_STATUS_SUCCESS;
362 : : }
363 : :
364 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_CHAL_CAP */
|