Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2024-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_responder_lib.h"
8 : :
9 : : #if LIBSPDM_ENABLE_CAPABILITY_GET_KEY_PAIR_INFO_CAP
10 : :
11 : 11 : libspdm_return_t libspdm_get_response_key_pair_info(libspdm_context_t *spdm_context,
12 : : size_t request_size, const void *request,
13 : : size_t *response_size, void *response)
14 : : {
15 : : const spdm_get_key_pair_info_request_t *spdm_request;
16 : : spdm_key_pair_info_response_t *spdm_response;
17 : :
18 : : libspdm_session_info_t *session_info;
19 : : const uint32_t *session_id;
20 : : libspdm_session_state_t session_state;
21 : :
22 : : uint8_t total_key_pairs;
23 : : uint16_t capabilities;
24 : : uint16_t key_usage_capabilities;
25 : : uint16_t current_key_usage;
26 : : uint32_t asym_algo_capabilities;
27 : : uint32_t current_asym_algo;
28 : : uint32_t pqc_asym_algo_capabilities;
29 : : uint32_t current_pqc_asym_algo;
30 : : uint8_t pqc_asym_algo_cap_len;
31 : : uint8_t current_pqc_asym_algo_len;
32 : : uint16_t public_key_info_len;
33 : : uint8_t assoc_cert_slot_mask;
34 : : uint8_t key_pair_id;
35 : : bool result;
36 : : uint8_t *public_key_info;
37 : : uint8_t *ptr;
38 : :
39 : 11 : spdm_request = request;
40 : :
41 : : /* -=[Check Parameters Phase]=- */
42 [ - + ]: 11 : LIBSPDM_ASSERT(spdm_request->header.request_response_code == SPDM_GET_KEY_PAIR_INFO);
43 : :
44 [ + + ]: 11 : if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_13) {
45 : 1 : return libspdm_generate_error_response(spdm_context,
46 : : SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
47 : : SPDM_GET_KEY_PAIR_INFO,
48 : : response_size, response);
49 : : }
50 : :
51 [ + + ]: 10 : if (spdm_request->header.spdm_version != libspdm_get_connection_version(spdm_context)) {
52 : 1 : return libspdm_generate_error_response(spdm_context,
53 : : SPDM_ERROR_CODE_VERSION_MISMATCH, 0,
54 : : response_size, response);
55 : : }
56 : :
57 [ + + ]: 9 : if (spdm_context->response_state != LIBSPDM_RESPONSE_STATE_NORMAL) {
58 : 1 : return libspdm_responder_handle_response_state(spdm_context,
59 : 1 : spdm_request->header.request_response_code,
60 : : response_size, response);
61 : : }
62 : :
63 [ + + ]: 8 : if (request_size < sizeof(spdm_get_key_pair_info_request_t)) {
64 : 1 : return libspdm_generate_error_response(spdm_context,
65 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
66 : : response_size, response);
67 : : }
68 : :
69 [ + + ]: 7 : if (spdm_context->connection_info.connection_state <
70 : : LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
71 : 1 : return libspdm_generate_error_response(
72 : : spdm_context,
73 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
74 : : response_size, response);
75 : : }
76 : :
77 : 6 : session_id = NULL;
78 [ - + ]: 6 : if (spdm_context->last_spdm_request_session_id_valid) {
79 : 0 : session_id = &spdm_context->last_spdm_request_session_id;
80 : 0 : session_info = libspdm_get_session_info_via_session_id(
81 : : spdm_context,
82 : : spdm_context->last_spdm_request_session_id);
83 [ # # ]: 0 : if (session_info == NULL) {
84 : 0 : return libspdm_generate_error_response(
85 : : spdm_context,
86 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
87 : : response_size, response);
88 : : }
89 : 0 : session_state = libspdm_secured_message_get_session_state(
90 : : session_info->secured_message_context);
91 [ # # ]: 0 : if (session_state != LIBSPDM_SESSION_STATE_ESTABLISHED) {
92 : 0 : return libspdm_generate_error_response(
93 : : spdm_context,
94 : : SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
95 : : response_size, response);
96 : : }
97 : : }
98 : :
99 [ + + ]: 6 : if (!libspdm_is_capabilities_flag_supported(
100 : : spdm_context, false, 0,
101 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_GET_KEY_PAIR_INFO_CAP)) {
102 : 1 : return libspdm_generate_error_response(
103 : : spdm_context, SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
104 : : SPDM_GET_KEY_PAIR_INFO, response_size, response);
105 : : }
106 : :
107 : 5 : key_pair_id = spdm_request->key_pair_id;
108 : :
109 [ - + ]: 5 : LIBSPDM_ASSERT(*response_size >= sizeof(spdm_key_pair_info_response_t));
110 : 5 : public_key_info_len = (uint16_t)(*response_size - sizeof(spdm_key_pair_info_response_t));
111 : 5 : libspdm_zero_mem(response, *response_size);
112 : :
113 : : /* libspdm_read_key_pair_info() always reports total_key_pairs (even on failure), so read first
114 : : * and then validate the range -- identical to the SET_KEY_PAIR_INFO_ACK handler. An invalid
115 : : * key_pair_id (0 or > total_key_pairs) is INVALID_REQUEST; any other read failure is UNSPECIFIED. */
116 : 5 : total_key_pairs = 0;
117 : 5 : public_key_info = (uint8_t*)response + sizeof(spdm_key_pair_info_response_t);
118 : 5 : result = libspdm_read_key_pair_info(
119 : : spdm_context,
120 : : session_id,
121 : : key_pair_id,
122 : : &total_key_pairs,
123 : : &capabilities,
124 : : &key_usage_capabilities,
125 : : ¤t_key_usage,
126 : : &asym_algo_capabilities,
127 : : ¤t_asym_algo,
128 : : &pqc_asym_algo_capabilities,
129 : : ¤t_pqc_asym_algo,
130 : : &assoc_cert_slot_mask,
131 : : &public_key_info_len,
132 : : public_key_info);
133 [ + + + + ]: 5 : if ((key_pair_id == 0) || (key_pair_id > total_key_pairs)) {
134 : 2 : return libspdm_generate_error_response(spdm_context,
135 : : SPDM_ERROR_CODE_INVALID_REQUEST, 0,
136 : : response_size, response);
137 : : }
138 [ - + ]: 3 : if (!result) {
139 : 0 : return libspdm_generate_error_response(spdm_context,
140 : : SPDM_ERROR_CODE_UNSPECIFIED, 0,
141 : : response_size, response);
142 : : }
143 : :
144 : : /*If responder doesn't support SET_KEY_PAIR_INFO_CAP, the capabilities should be 0*/
145 [ + - ]: 3 : if (!libspdm_is_capabilities_flag_supported(
146 : : spdm_context, false, 0,
147 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_SET_KEY_PAIR_INFO_CAP)) {
148 : 3 : capabilities = 0;
149 : : }
150 : :
151 : 3 : spdm_response = response;
152 [ + + ]: 3 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_14) {
153 : : /* The SPDM 1.4 tail is PqcAsymAlgoCapLen (1) + PqcAsymAlgoCapabilities (4) +
154 : : * CurrentPqcAsymAlgoLen (1) + CurrentPqcAsymAlgo (4) = 10 bytes. */
155 : 1 : const size_t pqc_tail_size = sizeof(uint8_t) + sizeof(uint32_t) +
156 : : sizeof(uint8_t) + sizeof(uint32_t);
157 [ - + ]: 1 : LIBSPDM_ASSERT(*response_size >= sizeof(spdm_key_pair_info_response_t) +
158 : : public_key_info_len + pqc_tail_size);
159 : 1 : *response_size = sizeof(spdm_key_pair_info_response_t) + public_key_info_len +
160 : : pqc_tail_size;
161 : : } else {
162 [ - + ]: 2 : LIBSPDM_ASSERT(*response_size >= sizeof(spdm_key_pair_info_response_t));
163 : 2 : *response_size = sizeof(spdm_key_pair_info_response_t) + public_key_info_len;
164 : : }
165 : :
166 : 3 : spdm_response->header.spdm_version = spdm_request->header.spdm_version;
167 : 3 : spdm_response->header.request_response_code = SPDM_KEY_PAIR_INFO;
168 : 3 : spdm_response->header.param1 = 0;
169 : 3 : spdm_response->header.param2 = 0;
170 : 3 : spdm_response->total_key_pairs = total_key_pairs;
171 : 3 : spdm_response->key_pair_id = key_pair_id;
172 : 3 : spdm_response->capabilities = capabilities & SPDM_KEY_PAIR_CAP_MASK;
173 : 3 : spdm_response->key_usage_capabilities = key_usage_capabilities & SPDM_KEY_USAGE_BIT_MASK;
174 : 3 : spdm_response->current_key_usage = current_key_usage & SPDM_KEY_USAGE_BIT_MASK;
175 : 3 : spdm_response->asym_algo_capabilities = asym_algo_capabilities &
176 : : SPDM_KEY_PAIR_ASYM_ALGO_CAP_MASK;
177 : 3 : spdm_response->current_asym_algo = current_asym_algo & SPDM_KEY_PAIR_ASYM_ALGO_CAP_MASK;
178 : 3 : spdm_response->public_key_info_len = public_key_info_len;
179 : 3 : spdm_response->assoc_cert_slot_mask = assoc_cert_slot_mask;
180 : :
181 [ + + ]: 3 : if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_14) {
182 : 1 : ptr = (uint8_t *)spdm_response + sizeof(spdm_key_pair_info_response_t) + public_key_info_len;
183 : 1 : pqc_asym_algo_cap_len = sizeof(pqc_asym_algo_capabilities);
184 : 1 : current_pqc_asym_algo_len = sizeof(current_pqc_asym_algo);
185 : 1 : *ptr = pqc_asym_algo_cap_len;
186 : 1 : ptr += sizeof(uint8_t);
187 : 1 : libspdm_write_uint32 (ptr, pqc_asym_algo_capabilities);
188 : 1 : ptr += sizeof(uint32_t);
189 : 1 : *ptr = current_pqc_asym_algo_len;
190 : 1 : ptr += sizeof(uint8_t);
191 : 1 : libspdm_write_uint32 (ptr, current_pqc_asym_algo);
192 : 1 : ptr += sizeof(uint32_t);
193 : : }
194 : :
195 : 3 : return LIBSPDM_STATUS_SUCCESS;
196 : : }
197 : :
198 : : #endif /*LIBSPDM_ENABLE_CAPABILITY_GET_KEY_PAIR_INFO_CAP*/
|