Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2021-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_responder_lib.h"
8 : : #include "internal/libspdm_secured_message_lib.h"
9 : :
10 : : #if LIBSPDM_ENABLE_CAPABILITY_KEY_EX_CAP
11 : :
12 : 16 : bool libspdm_generate_key_exchange_rsp_hmac(libspdm_context_t *spdm_context,
13 : : libspdm_session_info_t *session_info,
14 : : uint8_t *hmac)
15 : : {
16 : : uint8_t hmac_data[LIBSPDM_MAX_HASH_SIZE];
17 : : size_t hash_size;
18 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
19 : : uint8_t slot_id;
20 : : const uint8_t *cert_chain_buffer;
21 : : size_t cert_chain_buffer_size;
22 : : uint8_t *th_curr_data;
23 : : size_t th_curr_data_size;
24 : : libspdm_th_managed_buffer_t th_curr;
25 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
26 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
27 : : bool result;
28 : :
29 : 16 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
30 : :
31 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
32 : : slot_id = session_info->local_used_cert_chain_slot_id;
33 : : LIBSPDM_ASSERT((slot_id < SPDM_MAX_SLOT_COUNT) || (slot_id == 0xFF));
34 : : if (slot_id == 0xFF) {
35 : : result = libspdm_get_local_public_key_buffer(
36 : : spdm_context, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
37 : : if (!result) {
38 : : return false;
39 : : }
40 : : } else {
41 : : libspdm_get_local_cert_chain_buffer(
42 : : spdm_context, slot_id, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
43 : : }
44 : :
45 : : result = libspdm_calculate_th_for_exchange(
46 : : spdm_context, session_info, cert_chain_buffer, cert_chain_buffer_size, &th_curr);
47 : : if (!result) {
48 : : return false;
49 : : }
50 : : th_curr_data = libspdm_get_managed_buffer(&th_curr);
51 : : th_curr_data_size = libspdm_get_managed_buffer_size(&th_curr);
52 : :
53 : : result = libspdm_hash_all (spdm_context->connection_info.algorithm.base_hash_algo,
54 : : th_curr_data, th_curr_data_size, hash_data);
55 : : if (!result) {
56 : : return false;
57 : : }
58 : :
59 : : result = libspdm_hmac_all_with_response_finished_key(
60 : : session_info->secured_message_context, hash_data, hash_size, hmac_data);
61 : : if (!result) {
62 : : return false;
63 : : }
64 : : #else
65 : 16 : result = libspdm_calculate_th_hmac_for_exchange_rsp(
66 : : spdm_context, session_info, &hash_size, hmac_data);
67 [ - + ]: 16 : if (!result) {
68 : 0 : return false;
69 : : }
70 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
71 : 16 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "th_curr hmac - "));
72 : 16 : LIBSPDM_INTERNAL_DUMP_DATA(hmac_data, hash_size);
73 : 16 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
74 : 16 : libspdm_copy_mem(hmac, hash_size, hmac_data, hash_size);
75 : :
76 : 16 : return true;
77 : : }
78 : :
79 : 20 : bool libspdm_generate_key_exchange_rsp_signature(libspdm_context_t *spdm_context,
80 : : libspdm_session_info_t *session_info,
81 : : uint8_t slot_id,
82 : : uint8_t *signature)
83 : : {
84 : : bool result;
85 : : size_t signature_size;
86 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
87 : : uint8_t *th_curr_data;
88 : : size_t th_curr_data_size;
89 : : libspdm_th_managed_buffer_t th_curr;
90 : : const uint8_t *cert_chain_buffer;
91 : : size_t cert_chain_buffer_size;
92 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
93 : : #if ((LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT) && (LIBSPDM_DEBUG_BLOCK_ENABLE)) || \
94 : : !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT)
95 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
96 : : #endif
97 : : #if !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT) || (LIBSPDM_DEBUG_PRINT_ENABLE)
98 : : size_t hash_size;
99 : :
100 : 20 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
101 : : #endif
102 : :
103 [ - + ]: 20 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
104 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
105 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
106 : : } else {
107 : 20 : signature_size = libspdm_get_asym_signature_size(
108 : : spdm_context->connection_info.algorithm.base_asym_algo);
109 : : }
110 : :
111 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
112 : : LIBSPDM_ASSERT((slot_id < SPDM_MAX_SLOT_COUNT) || (slot_id == 0xFF));
113 : : if (slot_id == 0xFF) {
114 : : result = libspdm_get_local_public_key_buffer(
115 : : spdm_context, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
116 : : if (!result) {
117 : : return false;
118 : : }
119 : : } else {
120 : : libspdm_get_local_cert_chain_buffer(
121 : : spdm_context, slot_id, (const void **)&cert_chain_buffer, &cert_chain_buffer_size);
122 : : }
123 : :
124 : : result = libspdm_calculate_th_for_exchange(
125 : : spdm_context, session_info, cert_chain_buffer, cert_chain_buffer_size, &th_curr);
126 : : if (!result) {
127 : : return false;
128 : : }
129 : : th_curr_data = libspdm_get_managed_buffer(&th_curr);
130 : : th_curr_data_size = libspdm_get_managed_buffer_size(&th_curr);
131 : :
132 : : /* Debug code only - required for debug print of th_curr hash below*/
133 : : LIBSPDM_DEBUG_CODE(
134 : : if (!libspdm_hash_all(
135 : : spdm_context->connection_info.algorithm.base_hash_algo,
136 : : th_curr_data, th_curr_data_size, hash_data)) {
137 : : return false;
138 : : }
139 : : );
140 : : #else
141 : 20 : result = libspdm_calculate_th_hash_for_exchange(
142 : : spdm_context, session_info, &hash_size, hash_data);
143 [ - + ]: 20 : if (!result) {
144 : 0 : return false;
145 : : }
146 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
147 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "th_curr hash - "));
148 : 20 : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
149 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
150 : :
151 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
152 : : result = libspdm_responder_data_sign(
153 : : spdm_context,
154 : : spdm_context->connection_info.version,
155 : : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
156 : : SPDM_KEY_EXCHANGE_RSP,
157 : : spdm_context->connection_info.algorithm.base_asym_algo,
158 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
159 : : spdm_context->connection_info.algorithm.base_hash_algo,
160 : : false, th_curr_data, th_curr_data_size, signature, &signature_size);
161 : : #else
162 : 40 : result = libspdm_responder_data_sign(
163 : : spdm_context,
164 : 20 : spdm_context->connection_info.version,
165 : 20 : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
166 : : SPDM_KEY_EXCHANGE_RSP,
167 : : spdm_context->connection_info.algorithm.base_asym_algo,
168 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
169 : : spdm_context->connection_info.algorithm.base_hash_algo,
170 : : true, hash_data, hash_size, signature, &signature_size);
171 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
172 [ + - ]: 20 : if (result) {
173 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "signature - "));
174 : 20 : LIBSPDM_INTERNAL_DUMP_DATA(signature, signature_size);
175 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
176 : : }
177 : 20 : return result;
178 : : }
179 : :
180 : : #if (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP)
181 : : /**
182 : : * Initialize the encapsulated state for session-based mutual authentication.
183 : : *
184 : : * @param spdm_context A pointer to the SPDM context.
185 : : * @param session_info The session that mutual authentication occurs within.
186 : : * @param mut_auth_requested The MutAuthRequested value returned in KEY_EXCHANGE_RSP.
187 : : * @param req_slot_id The Requester's certificate slot.
188 : : **/
189 : 3 : static void init_encap_state(libspdm_context_t *spdm_context,
190 : : libspdm_session_info_t *session_info,
191 : : uint8_t mut_auth_requested,
192 : : uint8_t req_slot_id)
193 : : {
194 : : libspdm_encap_context_t *encap_context;
195 : :
196 [ + + - + ]: 3 : LIBSPDM_ASSERT(
197 : : (mut_auth_requested == SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_ENCAP_REQUEST) ||
198 : : (mut_auth_requested == SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_GET_DIGESTS));
199 : :
200 [ - + ]: 3 : LIBSPDM_ASSERT(req_slot_id < SPDM_MAX_SLOT_COUNT);
201 : :
202 : 3 : encap_context = &session_info->encap_context;
203 : 3 : encap_context->req_slot_id = req_slot_id;
204 : 3 : encap_context->mut_auth_req_slot_id = req_slot_id;
205 : 3 : encap_context->request_id = 0;
206 : 3 : encap_context->last_encap_request_size = 0;
207 : 3 : encap_context->flow_type = LIBSPDM_ENCAP_FLOW_SESS_MUT_AUTH;
208 : :
209 : 3 : libspdm_zero_mem(&encap_context->last_encap_request_header,
210 : : sizeof(encap_context->last_encap_request_header));
211 : 3 : encap_context->payload_buffer_size = 0;
212 : :
213 : : /* Clear cache. */
214 : 3 : libspdm_reset_message_mut_b(spdm_context);
215 : 3 : libspdm_reset_message_mut_c(spdm_context);
216 : :
217 [ + + - ]: 3 : switch (mut_auth_requested) {
218 : 2 : case SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_ENCAP_REQUEST:
219 : 2 : break;
220 : 1 : case SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_GET_DIGESTS:
221 : : /* GET_DIGESTS was embedded in KEY_EXCHANGE_RSP; prime the ACK handler to treat the
222 : : * first DELIVER_ENCAPSULATED_RESPONSE as a DIGESTS reply. */
223 : 1 : encap_context->last_encap_request_header.request_response_code = SPDM_GET_DIGESTS;
224 : 1 : break;
225 : 0 : default:
226 : 0 : LIBSPDM_ASSERT(false);
227 : 0 : break;
228 : : }
229 : 3 : }
230 : : #endif /* (LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP) && (LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP) */
231 : :
232 : 53 : libspdm_return_t libspdm_get_response_key_exchange(libspdm_context_t *spdm_context,
233 : : size_t request_size,
234 : : const void *request,
235 : : size_t *response_size,
236 : : void *response)
237 : : {
238 : : const spdm_key_exchange_request_t *spdm_request;
239 : : spdm_key_exchange_response_t *spdm_response;
240 : : size_t dhe_key_size;
241 : : size_t kem_encap_key_size;
242 : : size_t kem_cipher_text_size;
243 : : size_t req_key_exchange_size;
244 : : size_t rsp_key_exchange_size;
245 : : uint32_t measurement_summary_hash_size;
246 : : uint32_t signature_size;
247 : : uint32_t hmac_size;
248 : : uint8_t *ptr;
249 : : const uint8_t *req_opaque_data;
250 : : uint8_t *rsp_opaque_data;
251 : : uint16_t opaque_data_length;
252 : : bool result;
253 : : uint8_t slot_id;
254 : : uint32_t session_id;
255 : : void *dhe_context;
256 : : void *kem_context;
257 : : libspdm_session_info_t *session_info;
258 : : size_t total_size;
259 : : uint16_t req_session_id;
260 : : uint16_t rsp_session_id;
261 : : libspdm_return_t status;
262 : : size_t opaque_key_exchange_rsp_size;
263 : : bool use_default_opaque_data;
264 : : uint8_t th1_hash_data[LIBSPDM_MAX_HASH_SIZE];
265 : : spdm_version_number_t secured_message_version;
266 : 53 : uint8_t peer_aead_limit_exponent = SECURED_MESSAGE_AEAD_LIMIT_EXPONENT_DEFAULT;
267 : : #if LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP
268 : : uint8_t req_slot_id;
269 : : uint8_t mut_auth_requested;
270 : : bool mandatory_mut_auth;
271 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
272 : :
273 : 53 : spdm_request = request;
274 : :
275 : : /* -=[Check Parameters Phase]=- */
276 [ - + ]: 53 : LIBSPDM_ASSERT(spdm_request->header.request_response_code == SPDM_KEY_EXCHANGE);
277 : :
278 [ - + ]: 53 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_11) {
279 : 0 : return libspdm_generate_error_response(spdm_context,
280 : : SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
281 : : SPDM_KEY_EXCHANGE,
282 : : response_size, response);
283 : : }
284 : :
285 [ - + ]: 53 : if (spdm_request->header.spdm_version != libspdm_get_connection_version(spdm_context)) {
286 : 0 : return libspdm_generate_error_response(spdm_context,
287 : : SPDM_ERROR_CODE_VERSION_MISMATCH, 0,
288 : : response_size, response);
289 : : }
290 [ + + ]: 53 : if (spdm_context->response_state != LIBSPDM_RESPONSE_STATE_NORMAL) {
291 : 4 : return libspdm_responder_handle_response_state(
292 : : spdm_context,
293 : 4 : spdm_request->header.request_response_code,
294 : : response_size, response);
295 : : }
296 [ - + ]: 49 : if (!libspdm_is_capabilities_flag_supported(
297 : : spdm_context, false,
298 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_KEY_EX_CAP,
299 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_KEY_EX_CAP)) {
300 : 0 : return libspdm_generate_error_response(
301 : : spdm_context, SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
302 : : SPDM_KEY_EXCHANGE, response_size, response);
303 : : }
304 : :
305 : : /* While clearing MAC_CAP and setting ENCRYPT_CAP is legal according to DSP0274, libspdm
306 : : * also implements DSP0277 secure messages, which requires at least MAC_CAP to be set.
307 : : */
308 [ + + ]: 49 : if (!libspdm_is_capabilities_flag_supported(
309 : : spdm_context, false,
310 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_MAC_CAP,
311 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MAC_CAP)) {
312 : 6 : return libspdm_generate_error_response(
313 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
314 : : SPDM_KEY_EXCHANGE, response_size, response);
315 : : }
316 : :
317 [ + + ]: 43 : if (spdm_context->connection_info.connection_state < LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
318 : 1 : return libspdm_generate_error_response(spdm_context,
319 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST,
320 : : 0, response_size, response);
321 : : }
322 [ + + ]: 42 : if (libspdm_get_connection_version(spdm_context) >= SPDM_MESSAGE_VERSION_12) {
323 [ - + ]: 7 : if ((spdm_context->connection_info.algorithm.other_params_support &
324 : : SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_MASK) != SPDM_ALGORITHMS_OPAQUE_DATA_FORMAT_1) {
325 : 0 : return libspdm_generate_error_response(
326 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
327 : : 0, response_size, response);
328 : : }
329 : : }
330 [ - + ]: 42 : if (spdm_context->last_spdm_request_session_id_valid) {
331 : 0 : return libspdm_generate_error_response(spdm_context,
332 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST,
333 : : 0, response_size, response);
334 : : }
335 : :
336 [ + + ]: 42 : if (spdm_request->header.param1 > 0) {
337 [ + + ]: 5 : if (!libspdm_is_capabilities_flag_supported(
338 : : spdm_context, false,
339 : 4 : 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP) ||
340 [ + - ]: 4 : (spdm_context->connection_info.algorithm.measurement_spec == 0) ||
341 [ - + ]: 4 : (spdm_context->connection_info.algorithm.measurement_hash_algo == 0) ) {
342 : 1 : return libspdm_generate_error_response(
343 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST,
344 : : 0, response_size, response);
345 : : }
346 : : }
347 : :
348 : 41 : slot_id = spdm_request->header.param2;
349 : :
350 [ + + ]: 41 : if (libspdm_is_capabilities_flag_supported(
351 : : spdm_context, false,
352 : : 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_CERT_CAP)) {
353 [ + + ]: 39 : if (slot_id >= SPDM_MAX_SLOT_COUNT) {
354 : 1 : return libspdm_generate_error_response(spdm_context,
355 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
356 : : response_size, response);
357 : : }
358 [ - + ]: 38 : if (spdm_context->local_context.local_cert_chain_provision[slot_id] == NULL) {
359 : 0 : return libspdm_generate_error_response(spdm_context,
360 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
361 : : response_size, response);
362 : : }
363 : : } else {
364 [ + + ]: 2 : if (slot_id != 0xff) {
365 : 1 : return libspdm_generate_error_response(spdm_context,
366 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
367 : : response_size, response);
368 : : }
369 [ - + ]: 1 : if (spdm_context->local_context.local_public_key_provision == NULL) {
370 : 0 : return libspdm_generate_error_response(spdm_context,
371 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
372 : : response_size, response);
373 : : }
374 : : }
375 : :
376 [ + + ]: 39 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
377 [ + + + - ]: 3 : if (spdm_context->connection_info.multi_key_conn_rsp && (slot_id != 0xff)) {
378 [ + - ]: 1 : if ((spdm_context->local_context.local_key_usage_bit_mask[slot_id] &
379 : : SPDM_KEY_USAGE_BIT_MASK_KEY_EX_USE) == 0) {
380 : 1 : return libspdm_generate_error_response(
381 : : spdm_context, SPDM_ERROR_CODE_INVALID_REQUEST, 0, response_size, response);
382 : : }
383 : : }
384 : :
385 [ + + ]: 2 : if ((spdm_request->session_policy &
386 : : SPDM_KEY_EXCHANGE_REQUEST_SESSION_POLICY_EVENT_ALL_POLICY) != 0) {
387 [ - + ]: 1 : if (!libspdm_is_capabilities_flag_supported(
388 : : spdm_context, false, 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_EVENT_CAP)) {
389 : 0 : return libspdm_generate_error_response(spdm_context,
390 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
391 : : response_size, response);
392 : : }
393 : : }
394 : : }
395 : :
396 [ - + ]: 38 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
397 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
398 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
399 : : } else {
400 : 38 : signature_size = libspdm_get_asym_signature_size(
401 : : spdm_context->connection_info.algorithm.base_asym_algo);
402 : : }
403 : 38 : hmac_size = libspdm_get_hash_size(
404 : : spdm_context->connection_info.algorithm.base_hash_algo);
405 [ - + ]: 38 : if (spdm_context->connection_info.algorithm.kem_alg != 0) {
406 : 0 : kem_encap_key_size = libspdm_get_kem_encap_key_size(
407 : : spdm_context->connection_info.algorithm.kem_alg);
408 : 0 : kem_cipher_text_size = libspdm_get_kem_cipher_text_size(
409 : : spdm_context->connection_info.algorithm.kem_alg);
410 : 0 : req_key_exchange_size = kem_encap_key_size;
411 : 0 : rsp_key_exchange_size = kem_cipher_text_size;
412 : : } else {
413 : 76 : dhe_key_size = libspdm_get_dhe_pub_key_size(
414 : 38 : spdm_context->connection_info.algorithm.dhe_named_group);
415 : 38 : req_key_exchange_size = dhe_key_size;
416 : 38 : rsp_key_exchange_size = dhe_key_size;
417 : : }
418 : 38 : measurement_summary_hash_size = libspdm_get_measurement_summary_hash_size(
419 : 38 : spdm_context, false, spdm_request->header.param1);
420 : :
421 [ + + ]: 38 : if ((measurement_summary_hash_size == 0) &&
422 [ + + ]: 35 : (spdm_request->header.param1 != SPDM_KEY_EXCHANGE_REQUEST_NO_MEASUREMENT_SUMMARY_HASH)) {
423 : 1 : return libspdm_generate_error_response(spdm_context,
424 : : SPDM_ERROR_CODE_INVALID_REQUEST,
425 : : 0, response_size, response);
426 : : }
427 [ + + ]: 37 : if (request_size < sizeof(spdm_key_exchange_request_t) + req_key_exchange_size +
428 : : sizeof(uint16_t)) {
429 : 1 : return libspdm_generate_error_response(spdm_context,
430 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
431 : : response_size, response);
432 : : }
433 : 36 : opaque_data_length = libspdm_read_uint16((const uint8_t *)request +
434 : 36 : sizeof(spdm_key_exchange_request_t) +
435 : : req_key_exchange_size);
436 : 36 : if (request_size < sizeof(spdm_key_exchange_request_t) + req_key_exchange_size +
437 [ - + ]: 36 : sizeof(uint16_t) + opaque_data_length) {
438 : 0 : return libspdm_generate_error_response(spdm_context,
439 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
440 : : response_size, response);
441 : : }
442 : 36 : request_size = sizeof(spdm_key_exchange_request_t) + req_key_exchange_size +
443 : 36 : sizeof(uint16_t) + opaque_data_length;
444 : :
445 [ + - ]: 36 : if (opaque_data_length != 0) {
446 : 36 : req_opaque_data = (const uint8_t *)request + sizeof(spdm_key_exchange_request_t) +
447 : 36 : req_key_exchange_size + sizeof(uint16_t);
448 : :
449 : : /*
450 : : * Here allows integrator generate own opaque data for Key Exchange Response.
451 : : * If libspdm_key_exchange_rsp_opaque_data() returns false,
452 : : * libspdm will generate version selection opaque data.
453 : : */
454 : 36 : opaque_key_exchange_rsp_size = *response_size - sizeof(spdm_key_exchange_response_t) -
455 : 36 : rsp_key_exchange_size - measurement_summary_hash_size -
456 : 36 : sizeof(uint16_t) - signature_size - hmac_size;
457 : :
458 : 36 : use_default_opaque_data = false;
459 : 36 : result = libspdm_key_exchange_rsp_opaque_data(
460 : 36 : spdm_context, spdm_request->header.spdm_version,
461 : 36 : spdm_request->header.param1, slot_id, spdm_request->session_policy,
462 : : req_opaque_data, opaque_data_length, NULL,
463 : : &opaque_key_exchange_rsp_size);
464 [ + + ]: 36 : if (!result) {
465 : 35 : use_default_opaque_data = true;
466 : 35 : opaque_key_exchange_rsp_size =
467 : 35 : libspdm_get_opaque_data_version_selection_data_size(spdm_context);
468 : : }
469 : :
470 [ + + ]: 36 : if (use_default_opaque_data) {
471 : 35 : result = libspdm_process_general_opaque_data_check(spdm_context, opaque_data_length,
472 : : req_opaque_data);
473 [ - + ]: 35 : if (!result) {
474 : 0 : return libspdm_generate_error_response(spdm_context,
475 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
476 : : response_size, response);
477 : : }
478 : 35 : status = libspdm_process_opaque_data_supported_version_data(
479 : : spdm_context, opaque_data_length, req_opaque_data, &secured_message_version);
480 [ - + ]: 35 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
481 : 0 : return libspdm_generate_error_response(spdm_context,
482 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
483 : : response_size, response);
484 : : }
485 : : /* DSP0277 1.3: reserve room for this Responder's AEADlimitOE. The size helper returns 0
486 : : * unless the negotiated secured message version is 1.3 or later. */
487 : 35 : opaque_key_exchange_rsp_size +=
488 : 35 : libspdm_get_opaque_data_aead_limit_element_size(spdm_context,
489 : : secured_message_version);
490 : : } else {
491 : : /* use response buffer to temporarily store opaque data */
492 : 1 : rsp_opaque_data = (uint8_t *)response;
493 : 1 : result = libspdm_key_exchange_rsp_opaque_data(
494 : 1 : spdm_context, spdm_request->header.spdm_version,
495 : 1 : spdm_request->header.param1, slot_id, spdm_request->session_policy,
496 : : req_opaque_data, opaque_data_length, rsp_opaque_data,
497 : : &opaque_key_exchange_rsp_size);
498 [ - + ]: 1 : if (!result) {
499 : 0 : return libspdm_generate_error_response(spdm_context,
500 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
501 : : response_size, response);
502 : : }
503 : : /*
504 : : * parse responder opaque data from integrator
505 : : * to get secured_message_version.
506 : : */
507 : 1 : status = libspdm_process_opaque_data_version_selection_data(
508 : : spdm_context, opaque_key_exchange_rsp_size,
509 : : rsp_opaque_data, &secured_message_version);
510 [ - + ]: 1 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
511 : 0 : return libspdm_generate_error_response(spdm_context,
512 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
513 : : response_size, response);
514 : : }
515 : : }
516 : : /* DSP0277 1.3: read the Requester's AEAD limit from the request (absent -> default 64).
517 : : * This is independent of whether the Responder builds default or custom response opaque
518 : : * data, so it runs for both paths. */
519 : 36 : status = libspdm_process_opaque_data_aead_limit(
520 : : spdm_context, secured_message_version, opaque_data_length, req_opaque_data,
521 : : &peer_aead_limit_exponent);
522 [ - + ]: 36 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
523 : 0 : return libspdm_generate_error_response(spdm_context,
524 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
525 : : response_size, response);
526 : : }
527 : : } else {
528 : 0 : secured_message_version = 0;
529 : 0 : opaque_key_exchange_rsp_size = 0;
530 : 0 : req_opaque_data = NULL;
531 : : }
532 : :
533 : 36 : libspdm_reset_message_buffer_via_request_code(spdm_context, NULL,
534 : 36 : spdm_request->header.request_response_code);
535 : :
536 [ + + ]: 36 : if (libspdm_is_capabilities_flag_supported(
537 : : spdm_context, false,
538 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
539 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
540 : 4 : hmac_size = 0;
541 : : }
542 : :
543 : 36 : req_session_id = spdm_request->req_session_id;
544 : 36 : rsp_session_id = libspdm_allocate_rsp_session_id(spdm_context, false);
545 [ - + ]: 36 : if (rsp_session_id == ((INVALID_SESSION_ID & 0xFFFF0000) >> 16)) {
546 : 0 : return libspdm_generate_error_response(
547 : : spdm_context, SPDM_ERROR_CODE_SESSION_LIMIT_EXCEEDED, 0,
548 : : response_size, response);
549 : : }
550 : 36 : session_id = libspdm_generate_session_id(req_session_id, rsp_session_id);
551 : 36 : session_info = libspdm_assign_session_id(spdm_context, session_id, secured_message_version,
552 : : false);
553 [ - + ]: 36 : if (session_info == NULL) {
554 : 0 : return libspdm_generate_error_response(
555 : : spdm_context, SPDM_ERROR_CODE_SESSION_LIMIT_EXCEEDED, 0,
556 : : response_size, response);
557 : : }
558 : :
559 : : /* DSP0277 1.3: program the session's AEAD limit (min of local and peer) when secured message
560 : : * version 1.3 was negotiated. */
561 [ + + ]: 36 : if (libspdm_get_version_from_version_number(secured_message_version) >=
562 : : SECURED_SPDM_VERSION_13) {
563 : 2 : libspdm_apply_aead_limit_to_session(spdm_context, session_info,
564 : : peer_aead_limit_exponent);
565 : : }
566 : :
567 : 36 : total_size = sizeof(spdm_key_exchange_response_t) + rsp_key_exchange_size +
568 : 36 : measurement_summary_hash_size + sizeof(uint16_t) +
569 : 36 : opaque_key_exchange_rsp_size + signature_size + hmac_size;
570 : :
571 [ - + ]: 36 : LIBSPDM_ASSERT(*response_size >= total_size);
572 : 36 : *response_size = total_size;
573 : 36 : libspdm_zero_mem(response, *response_size);
574 : 36 : spdm_response = response;
575 : :
576 : 36 : spdm_response->header.spdm_version = spdm_request->header.spdm_version;
577 : 36 : spdm_response->header.request_response_code = SPDM_KEY_EXCHANGE_RSP;
578 : :
579 [ + + ]: 36 : if (libspdm_is_capabilities_flag_supported(
580 : : spdm_context, false,
581 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HBEAT_CAP,
582 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HBEAT_CAP)) {
583 : 1 : spdm_response->header.param1 = spdm_context->local_context.heartbeat_period;
584 : : } else {
585 : 35 : spdm_response->header.param1 = 0x00;
586 : : }
587 : :
588 : 36 : session_info->local_used_cert_chain_slot_id = slot_id;
589 : :
590 [ + + ]: 36 : if (libspdm_is_capabilities_flag_supported(
591 : : spdm_context, false,
592 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HBEAT_CAP,
593 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HBEAT_CAP)) {
594 : 1 : session_info->heartbeat_period = spdm_context->local_context.heartbeat_period;
595 : : } else {
596 : 35 : session_info->heartbeat_period = 0x00;
597 : : }
598 : :
599 : 36 : spdm_response->rsp_session_id = rsp_session_id;
600 : 36 : spdm_response->mut_auth_requested = 0;
601 : 36 : spdm_response->req_slot_id_param = 0;
602 : :
603 : : #if LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP
604 [ + + ]: 36 : if (libspdm_is_capabilities_flag_supported(
605 : : spdm_context, false, 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MUT_AUTH_CAP)) {
606 : 25 : req_slot_id = 0;
607 : :
608 : : mut_auth_requested =
609 : 25 : libspdm_key_exchange_start_mut_auth(spdm_context,
610 : : session_id,
611 : 25 : spdm_context->connection_info.version,
612 : : slot_id,
613 : : &req_slot_id,
614 : 25 : spdm_request->session_policy,
615 : : opaque_data_length,
616 : : req_opaque_data,
617 : : &mandatory_mut_auth);
618 [ + + ]: 25 : if (mut_auth_requested != 0) {
619 : 23 : const bool req_pub_key_id_cap = libspdm_is_capabilities_flag_supported(
620 : : spdm_context, false, SPDM_GET_CAPABILITIES_REQUEST_FLAGS_PUB_KEY_ID_CAP, 0);
621 : 23 : const bool req_mut_auth_cap = libspdm_is_capabilities_flag_supported(
622 : : spdm_context, false, SPDM_GET_CAPABILITIES_REQUEST_FLAGS_MUT_AUTH_CAP, 0);
623 : 23 : const bool req_encap_cap = libspdm_is_capabilities_flag_supported(
624 : : spdm_context, false, SPDM_GET_CAPABILITIES_REQUEST_FLAGS_ENCAP_CAP, 0);
625 : 23 : const bool need_encap =
626 : : (mut_auth_requested ==
627 [ + + + + ]: 23 : SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_ENCAP_REQUEST) ||
628 : : (mut_auth_requested ==
629 : : SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_GET_DIGESTS);
630 : :
631 [ + + ]: 23 : switch (mut_auth_requested) {
632 : 15 : case SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED:
633 : : case SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_ENCAP_REQUEST:
634 : : case SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED_WITH_GET_DIGESTS:
635 : 15 : break;
636 : 8 : default:
637 : 8 : libspdm_free_session_id(spdm_context, session_id);
638 : 8 : return libspdm_generate_error_response(spdm_context,
639 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
640 : : response_size, response);
641 : : }
642 : :
643 [ + + + + ]: 15 : if (req_pub_key_id_cap &&
644 : : (mut_auth_requested != SPDM_KEY_EXCHANGE_RESPONSE_MUT_AUTH_REQUESTED)) {
645 : 1 : libspdm_free_session_id(spdm_context, session_id);
646 : 1 : return libspdm_generate_error_response(spdm_context,
647 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
648 : : response_size, response);
649 : : }
650 [ + + ]: 14 : if (!need_encap) {
651 [ + + + + ]: 9 : if (req_pub_key_id_cap ?
652 : : (req_slot_id != 0xf) : (req_slot_id >= SPDM_MAX_SLOT_COUNT)) {
653 : 3 : libspdm_free_session_id(spdm_context, session_id);
654 : 3 : return libspdm_generate_error_response(spdm_context,
655 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
656 : : response_size, response);
657 : : }
658 [ + + ]: 5 : } else if (req_slot_id != 0) {
659 : 2 : libspdm_free_session_id(spdm_context, session_id);
660 : 2 : return libspdm_generate_error_response(spdm_context,
661 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
662 : : response_size, response);
663 : : }
664 : :
665 : : /* If Integrator requires mutual authentication but Requester does not support mutual
666 : : * authentication, or Integrator requires the encapsulated mutual authentication flow
667 : : * and Requester does not support encapsulated messages, then return an error to
668 : : * Requester. */
669 [ + + - + : 9 : if (mandatory_mut_auth && (!req_mut_auth_cap || (need_encap && !req_encap_cap))) {
- - - - ]
670 [ + + ]: 2 : if (libspdm_get_connection_version(spdm_context) >= SPDM_MESSAGE_VERSION_13) {
671 : 1 : libspdm_free_session_id(spdm_context, session_id);
672 : 1 : return libspdm_generate_error_response(spdm_context,
673 : : SPDM_ERROR_CODE_INVALID_POLICY, 0,
674 : : response_size, response);
675 : : } else {
676 : 1 : libspdm_free_session_id(spdm_context, session_id);
677 : 1 : return libspdm_generate_error_response(spdm_context,
678 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
679 : : response_size, response);
680 : : }
681 : : }
682 : :
683 [ + + ]: 7 : if (!need_encap) {
684 : 4 : spdm_response->mut_auth_requested = mut_auth_requested;
685 : 4 : spdm_response->req_slot_id_param = req_slot_id;
686 : : /* There is no encapsulated flow to retrieve the Requester's certificate chain,
687 : : * so the Responder already possesses it. Record the slot that the Requester is
688 : : * being told to sign FINISH with, as FINISH verification reads it.
689 : : * SlotIDParam carries 0xF for a provisioned public key, which libspdm
690 : : * records as 0xFF. */
691 [ + + ]: 4 : session_info->peer_used_cert_chain_slot_id =
692 : : req_pub_key_id_cap ? 0xFF : req_slot_id;
693 : : }
694 : : #if LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP
695 [ + - + - ]: 3 : else if (need_encap && req_encap_cap) {
696 : 3 : spdm_response->mut_auth_requested = mut_auth_requested;
697 : 3 : session_info->peer_used_cert_chain_slot_id = req_slot_id;
698 : 3 : init_encap_state(spdm_context, session_info, mut_auth_requested, req_slot_id);
699 : : }
700 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_ENCAP_CAP */
701 : : }
702 : : }
703 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
704 : :
705 [ - + ]: 20 : if (!libspdm_get_random_number(SPDM_RANDOM_DATA_SIZE, spdm_response->random_data)) {
706 : 0 : libspdm_free_session_id(spdm_context, session_id);
707 : 0 : return libspdm_generate_error_response(spdm_context,
708 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
709 : : response_size, response);
710 : : }
711 : :
712 : 20 : ptr = (void *)(spdm_response + 1);
713 [ - + ]: 20 : if (spdm_context->connection_info.algorithm.kem_alg != 0) {
714 : 0 : kem_context = libspdm_secured_message_kem_new(
715 : 0 : spdm_context->connection_info.version,
716 : : spdm_context->connection_info.algorithm.kem_alg, false);
717 [ # # ]: 0 : if (kem_context == NULL) {
718 : 0 : libspdm_free_session_id(spdm_context, session_id);
719 : 0 : return libspdm_generate_error_response(spdm_context,
720 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
721 : : response_size, response);
722 : : }
723 : :
724 : 0 : result = libspdm_secured_message_kem_encapsulate(
725 : : spdm_context->connection_info.algorithm.kem_alg,
726 : : kem_context,
727 : : (const uint8_t *)request + sizeof(spdm_key_exchange_request_t),
728 : : kem_encap_key_size, ptr, &kem_cipher_text_size, session_info->secured_message_context);
729 : 0 : libspdm_secured_message_kem_free(
730 : : spdm_context->connection_info.algorithm.kem_alg,
731 : : kem_context);
732 [ # # ]: 0 : if (!result) {
733 : 0 : libspdm_free_session_id(spdm_context, session_id);
734 : 0 : return libspdm_generate_error_response(spdm_context,
735 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
736 : : response_size, response);
737 : : }
738 : :
739 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "Calc Self cipher_text (0x%zx):\n", kem_cipher_text_size));
740 : 0 : LIBSPDM_INTERNAL_DUMP_HEX(ptr, kem_cipher_text_size);
741 : :
742 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "Calc peer encap_key (0x%zx):\n", kem_encap_key_size));
743 : 0 : LIBSPDM_INTERNAL_DUMP_HEX((const uint8_t *)request +
744 : : sizeof(spdm_key_exchange_request_t),
745 : : kem_encap_key_size);
746 : :
747 : 0 : ptr += kem_cipher_text_size;
748 : : } else {
749 : 20 : dhe_context = libspdm_secured_message_dhe_new(
750 : 20 : spdm_context->connection_info.version,
751 : 20 : spdm_context->connection_info.algorithm.dhe_named_group, false);
752 [ - + ]: 20 : if (dhe_context == NULL) {
753 : 0 : libspdm_free_session_id(spdm_context, session_id);
754 : 0 : return libspdm_generate_error_response(spdm_context,
755 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
756 : : response_size, response);
757 : : }
758 : :
759 : 20 : result = libspdm_secured_message_dhe_generate_key(
760 : 20 : spdm_context->connection_info.algorithm.dhe_named_group,
761 : : dhe_context, ptr, &dhe_key_size);
762 [ - + ]: 20 : if (!result) {
763 : 0 : libspdm_secured_message_dhe_free(
764 : 0 : spdm_context->connection_info.algorithm.dhe_named_group,
765 : : dhe_context);
766 : 0 : libspdm_free_session_id(spdm_context, session_id);
767 : 0 : return libspdm_generate_error_response(spdm_context,
768 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
769 : : response_size, response);
770 : : }
771 : :
772 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "Calc SelfKey (0x%zx):\n", dhe_key_size));
773 : 20 : LIBSPDM_INTERNAL_DUMP_HEX(ptr, dhe_key_size);
774 : :
775 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "Calc peer_key (0x%zx):\n", dhe_key_size));
776 : 20 : LIBSPDM_INTERNAL_DUMP_HEX((const uint8_t *)request +
777 : : sizeof(spdm_key_exchange_request_t),
778 : : dhe_key_size);
779 : :
780 : 20 : result = libspdm_secured_message_dhe_compute_key(
781 : 20 : spdm_context->connection_info.algorithm.dhe_named_group,
782 : : dhe_context,
783 : : (const uint8_t *)request + sizeof(spdm_key_exchange_request_t),
784 : : dhe_key_size, session_info->secured_message_context);
785 : 20 : libspdm_secured_message_dhe_free(
786 : 20 : spdm_context->connection_info.algorithm.dhe_named_group, dhe_context);
787 [ - + ]: 20 : if (!result) {
788 : 0 : libspdm_free_session_id(spdm_context, session_id);
789 : 0 : return libspdm_generate_error_response(spdm_context,
790 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
791 : : response_size, response);
792 : : }
793 : :
794 : 20 : ptr += dhe_key_size;
795 : : }
796 : :
797 : : #if LIBSPDM_ENABLE_CAPABILITY_MEAS_CAP
798 [ + + ]: 20 : if (libspdm_is_capabilities_flag_supported(
799 : 3 : spdm_context, false, 0, SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP) &&
800 [ + + ]: 3 : ((spdm_request->header.param1 == SPDM_REQUEST_TCB_COMPONENT_MEASUREMENT_HASH) ||
801 [ + - ]: 2 : (spdm_request->header.param1 == SPDM_REQUEST_ALL_MEASUREMENTS_HASH))) {
802 : 3 : result = libspdm_generate_measurement_summary_hash(
803 : : spdm_context,
804 : 3 : spdm_context->connection_info.version,
805 : : spdm_context->connection_info.algorithm.base_hash_algo,
806 : 3 : spdm_context->connection_info.algorithm.measurement_spec,
807 : : spdm_context->connection_info.algorithm.measurement_hash_algo,
808 : 3 : spdm_request->header.param1,
809 : : ptr,
810 : : measurement_summary_hash_size);
811 : :
812 [ - + ]: 3 : if (!result) {
813 : 0 : libspdm_free_session_id(spdm_context, session_id);
814 : 0 : return libspdm_generate_error_response(spdm_context,
815 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
816 : : response_size, response);
817 : : }
818 : : }
819 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_MEAS_CAP */
820 : :
821 : 20 : ptr += measurement_summary_hash_size;
822 : :
823 : 20 : libspdm_write_uint16(ptr, (uint16_t)opaque_key_exchange_rsp_size);
824 : 20 : ptr += sizeof(uint16_t);
825 : :
826 [ + - ]: 20 : if (opaque_key_exchange_rsp_size != 0) {
827 [ + + ]: 20 : if (use_default_opaque_data) {
828 : 19 : size_t version_selection_size =
829 : 19 : libspdm_get_opaque_data_version_selection_data_size(spdm_context);
830 : 19 : libspdm_build_opaque_data_version_selection_data(
831 : : spdm_context, secured_message_version, &version_selection_size, ptr);
832 : : /* DSP0277 1.3: advertise this Responder's own AEAD limit. opaque_key_exchange_rsp_size
833 : : * is the reserved opaque data capacity (version selection + AEAD limit); the append is a
834 : : * no-op unless the negotiated secured message version is 1.3 or later. */
835 : 19 : libspdm_build_opaque_data_aead_limit_element(
836 : : spdm_context, secured_message_version, &opaque_key_exchange_rsp_size, ptr);
837 : : } else {
838 : 1 : result = libspdm_key_exchange_rsp_opaque_data(
839 : 1 : spdm_context, spdm_request->header.spdm_version,
840 : 1 : spdm_request->header.param1, slot_id, spdm_request->session_policy,
841 : : req_opaque_data, opaque_data_length, ptr,
842 : : &opaque_key_exchange_rsp_size);
843 [ - + ]: 1 : if (!result) {
844 : 0 : libspdm_free_session_id(spdm_context, session_id);
845 : 0 : return libspdm_generate_error_response(spdm_context,
846 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
847 : : response_size, response);
848 : : }
849 : : }
850 : 20 : ptr += opaque_key_exchange_rsp_size;
851 : : }
852 : :
853 : 20 : status = libspdm_append_message_k(spdm_context, session_info, false, request, request_size);
854 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
855 : 0 : libspdm_free_session_id(spdm_context, session_id);
856 : 0 : return libspdm_generate_error_response(spdm_context,
857 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
858 : : response_size, response);
859 : : }
860 : :
861 : 20 : status = libspdm_append_message_k(spdm_context, session_info, false, spdm_response,
862 : 20 : (size_t)ptr - (size_t)spdm_response);
863 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
864 : 0 : libspdm_free_session_id(spdm_context, session_id);
865 : 0 : return libspdm_generate_error_response(spdm_context,
866 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
867 : : response_size, response);
868 : : }
869 : 20 : result = libspdm_generate_key_exchange_rsp_signature(
870 : : spdm_context, session_info, slot_id, ptr);
871 [ - + ]: 20 : if (!result) {
872 : 0 : libspdm_free_session_id(spdm_context, session_id);
873 : 0 : return libspdm_generate_error_response(
874 : : spdm_context, SPDM_ERROR_CODE_UNSPECIFIED,
875 : : 0, response_size, response);
876 : : }
877 : :
878 : 20 : status = libspdm_append_message_k(spdm_context, session_info, false, ptr, signature_size);
879 [ - + ]: 20 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
880 : 0 : libspdm_free_session_id(spdm_context, session_id);
881 : 0 : return libspdm_generate_error_response(spdm_context,
882 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
883 : : response_size, response);
884 : : }
885 : :
886 : 20 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "libspdm_generate_session_handshake_key[%x]\n", session_id));
887 : 20 : result = libspdm_calculate_th1_hash(spdm_context, session_info, false, th1_hash_data);
888 [ - + ]: 20 : if (!result) {
889 : 0 : libspdm_free_session_id(spdm_context, session_id);
890 : 0 : return libspdm_generate_error_response(spdm_context,
891 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
892 : : response_size, response);
893 : : }
894 : 20 : result = libspdm_generate_session_handshake_key(
895 : : session_info->secured_message_context, th1_hash_data);
896 [ - + ]: 20 : if (!result) {
897 : 0 : libspdm_free_session_id(spdm_context, session_id);
898 : 0 : return libspdm_generate_error_response(spdm_context,
899 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
900 : : response_size, response);
901 : : }
902 : :
903 : 20 : ptr += signature_size;
904 : :
905 [ + + ]: 20 : if (!libspdm_is_capabilities_flag_supported(
906 : : spdm_context, false,
907 : : SPDM_GET_CAPABILITIES_REQUEST_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP,
908 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_HANDSHAKE_IN_THE_CLEAR_CAP)) {
909 : 16 : result = libspdm_generate_key_exchange_rsp_hmac(spdm_context, session_info, ptr);
910 [ - + ]: 16 : if (!result) {
911 : 0 : libspdm_free_session_id(spdm_context, session_id);
912 : 0 : return libspdm_generate_error_response(
913 : : spdm_context,
914 : : SPDM_ERROR_CODE_UNSPECIFIED,
915 : : 0, response_size, response);
916 : : }
917 : 16 : status = libspdm_append_message_k(spdm_context, session_info, false, ptr, hmac_size);
918 [ - + ]: 16 : if (LIBSPDM_STATUS_IS_ERROR(status)) {
919 : 0 : libspdm_free_session_id(spdm_context, session_id);
920 : 0 : return libspdm_generate_error_response(
921 : : spdm_context, SPDM_ERROR_CODE_UNSPECIFIED,
922 : : 0, response_size, response);
923 : : }
924 : :
925 : 16 : ptr += hmac_size;
926 : : }
927 : :
928 : : #if LIBSPDM_ENABLE_CAPABILITY_EVENT_CAP
929 [ + + ]: 20 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_13) {
930 [ + - ]: 1 : if ((spdm_request->session_policy &
931 : : SPDM_KEY_EXCHANGE_REQUEST_SESSION_POLICY_EVENT_ALL_POLICY) != 0) {
932 [ - + ]: 1 : if (!libspdm_event_subscribe(spdm_context, spdm_context->connection_info.version,
933 : : session_id, LIBSPDM_EVENT_SUBSCRIBE_ALL, 0, 0, NULL)) {
934 : 0 : libspdm_free_session_id(spdm_context, session_id);
935 : 0 : return libspdm_generate_error_response(spdm_context,
936 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
937 : : response_size, response);
938 : : }
939 : : }
940 : : }
941 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_EVENT_CAP */
942 : :
943 : 20 : session_info->mut_auth_requested = spdm_response->mut_auth_requested;
944 [ + + ]: 20 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_12) {
945 : 4 : session_info->session_policy = spdm_request->session_policy;
946 : : }
947 : 20 : libspdm_set_session_state(spdm_context, session_id, LIBSPDM_SESSION_STATE_HANDSHAKING);
948 : :
949 : 20 : return LIBSPDM_STATUS_SUCCESS;
950 : : }
951 : :
952 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_KEY_EX_CAP */
|