LCOV - code coverage report
Current view: top level - spdm_responder_lib - libspdm_rsp_set_key_pair_info_ack.c (source / functions) Coverage Total Hit
Test: coverage.info Lines: 77.9 % 149 116
Test Date: 2026-10-01 20:56:25 Functions: 100.0 % 1 1
Branches: 61.5 % 156 96

             Branch data     Line data    Source code
       1                 :             : /**
       2                 :             :  *  Copyright Notice:
       3                 :             :  *  Copyright 2024-2026 DMTF. All rights reserved.
       4                 :             :  *  License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
       5                 :             :  **/
       6                 :             : 
       7                 :             : #include "internal/libspdm_responder_lib.h"
       8                 :             : 
       9                 :             : #if LIBSPDM_ENABLE_CAPABILITY_SET_KEY_PAIR_INFO_CAP
      10                 :             : 
      11                 :          26 : libspdm_return_t libspdm_get_response_set_key_pair_info_ack(libspdm_context_t *spdm_context,
      12                 :             :                                                             size_t request_size,
      13                 :             :                                                             const void *request,
      14                 :             :                                                             size_t *response_size,
      15                 :             :                                                             void *response)
      16                 :             : {
      17                 :             :     const spdm_set_key_pair_info_request_t *spdm_request;
      18                 :             :     spdm_set_key_pair_info_ack_response_t *spdm_response;
      19                 :             : 
      20                 :             :     libspdm_session_info_t *session_info;
      21                 :             :     const uint32_t *session_id;
      22                 :             :     libspdm_session_state_t session_state;
      23                 :             : 
      24                 :             :     uint16_t capabilities;
      25                 :             :     uint16_t key_usage_capabilities;
      26                 :             :     uint16_t current_key_usage;
      27                 :             :     uint32_t asym_algo_capabilities;
      28                 :             :     uint32_t current_asym_algo;
      29                 :             :     uint32_t pqc_asym_algo_capabilities;
      30                 :             :     uint32_t current_pqc_asym_algo;
      31                 :             :     uint8_t assoc_cert_slot_mask;
      32                 :             :     uint8_t key_pair_id;
      33                 :             :     uint8_t total_key_pairs;
      34                 :             :     bool result;
      35                 :             : 
      36                 :             :     uint16_t desired_key_usage;
      37                 :             :     uint32_t desired_asym_algo;
      38                 :             :     uint8_t desired_assoc_cert_slot_mask;
      39                 :             :     uint8_t desired_pqc_asym_algo_len;
      40                 :             :     uint32_t desired_pqc_asym_algo;
      41                 :             :     uint8_t operation;
      42                 :             :     bool need_reset;
      43                 :             :     const uint8_t *ptr;
      44                 :             : 
      45                 :          26 :     spdm_request = request;
      46                 :             : 
      47                 :             :     /* -=[Check Parameters Phase]=- */
      48         [ -  + ]:          26 :     LIBSPDM_ASSERT(spdm_request->header.request_response_code == SPDM_SET_KEY_PAIR_INFO);
      49                 :             : 
      50         [ +  + ]:          26 :     if (libspdm_get_connection_version(spdm_context) < SPDM_MESSAGE_VERSION_13) {
      51                 :           1 :         return libspdm_generate_error_response(spdm_context,
      52                 :             :                                                SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
      53                 :             :                                                SPDM_SET_KEY_PAIR_INFO,
      54                 :             :                                                response_size, response);
      55                 :             :     }
      56                 :             : 
      57         [ +  + ]:          25 :     if (spdm_request->header.spdm_version != libspdm_get_connection_version(spdm_context)) {
      58                 :           1 :         return libspdm_generate_error_response(spdm_context,
      59                 :             :                                                SPDM_ERROR_CODE_VERSION_MISMATCH, 0,
      60                 :             :                                                response_size, response);
      61                 :             :     }
      62                 :             : 
      63         [ -  + ]:          24 :     if (spdm_context->response_state != LIBSPDM_RESPONSE_STATE_NORMAL) {
      64                 :           0 :         return libspdm_responder_handle_response_state(spdm_context,
      65                 :           0 :                                                        spdm_request->header.request_response_code,
      66                 :             :                                                        response_size, response);
      67                 :             :     }
      68                 :             : 
      69         [ +  + ]:          24 :     if (request_size < sizeof(spdm_set_key_pair_info_request_t)) {
      70                 :           1 :         return libspdm_generate_error_response(spdm_context,
      71                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
      72                 :             :                                                response_size, response);
      73                 :             :     }
      74                 :             : 
      75         [ +  + ]:          23 :     if (spdm_context->connection_info.connection_state <
      76                 :             :         LIBSPDM_CONNECTION_STATE_NEGOTIATED) {
      77                 :           1 :         return libspdm_generate_error_response(
      78                 :             :             spdm_context,
      79                 :             :             SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
      80                 :             :             response_size, response);
      81                 :             :     }
      82                 :             : 
      83                 :          22 :     session_id = NULL;
      84         [ -  + ]:          22 :     if (spdm_context->last_spdm_request_session_id_valid) {
      85                 :           0 :         session_id = &spdm_context->last_spdm_request_session_id;
      86                 :           0 :         session_info = libspdm_get_session_info_via_session_id(
      87                 :             :             spdm_context,
      88                 :             :             spdm_context->last_spdm_request_session_id);
      89         [ #  # ]:           0 :         if (session_info == NULL) {
      90                 :           0 :             return libspdm_generate_error_response(
      91                 :             :                 spdm_context,
      92                 :             :                 SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
      93                 :             :                 response_size, response);
      94                 :             :         }
      95                 :           0 :         session_state = libspdm_secured_message_get_session_state(
      96                 :             :             session_info->secured_message_context);
      97         [ #  # ]:           0 :         if (session_state != LIBSPDM_SESSION_STATE_ESTABLISHED) {
      98                 :           0 :             return libspdm_generate_error_response(
      99                 :             :                 spdm_context,
     100                 :             :                 SPDM_ERROR_CODE_UNEXPECTED_REQUEST, 0,
     101                 :             :                 response_size, response);
     102                 :             :         }
     103                 :             :     }
     104                 :             : 
     105         [ +  + ]:          22 :     if (!libspdm_is_capabilities_flag_supported(
     106                 :             :             spdm_context, false, 0,
     107                 :             :             SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_SET_KEY_PAIR_INFO_CAP)) {
     108                 :           1 :         return libspdm_generate_error_response(
     109                 :             :             spdm_context, SPDM_ERROR_CODE_UNSUPPORTED_REQUEST,
     110                 :             :             SPDM_SET_KEY_PAIR_INFO, response_size, response);
     111                 :             :     }
     112                 :             : 
     113         [ -  + ]:          21 :     LIBSPDM_ASSERT(*response_size >= sizeof(spdm_set_key_pair_info_ack_response_t));
     114                 :             : 
     115                 :          21 :     libspdm_zero_mem(response, *response_size);
     116                 :             : 
     117                 :          21 :     total_key_pairs = 0;
     118                 :          21 :     key_pair_id = spdm_request->key_pair_id;
     119                 :          21 :     result = libspdm_read_key_pair_info(
     120                 :             :         spdm_context,
     121                 :             :         session_id,
     122                 :             :         key_pair_id,
     123                 :             :         &total_key_pairs,
     124                 :             :         &capabilities,
     125                 :             :         &key_usage_capabilities,
     126                 :             :         &current_key_usage,
     127                 :             :         &asym_algo_capabilities,
     128                 :             :         &current_asym_algo,
     129                 :             :         &pqc_asym_algo_capabilities,
     130                 :             :         &current_pqc_asym_algo,
     131                 :             :         &assoc_cert_slot_mask,
     132                 :             :         NULL, NULL);
     133   [ +  +  -  + ]:          21 :     if ((key_pair_id == 0) || (key_pair_id > total_key_pairs)) {
     134                 :           1 :         return libspdm_generate_error_response(spdm_context,
     135                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     136                 :             :                                                response_size, response);
     137                 :             :     }
     138         [ -  + ]:          20 :     if (!result) {
     139                 :           0 :         return libspdm_generate_error_response(spdm_context,
     140                 :             :                                                SPDM_ERROR_CODE_UNSPECIFIED, 0,
     141                 :             :                                                response_size, response);
     142                 :             :     }
     143                 :             : 
     144                 :          20 :     operation = spdm_request->header.param1;
     145                 :             : 
     146                 :             :     /* Validate the Operation value up front, before parsing the operation-specific fields. */
     147         [ -  + ]:          20 :     if (operation > SPDM_SET_KEY_PAIR_INFO_GENERATE_OPERATION) {
     148                 :           0 :         return libspdm_generate_error_response(spdm_context,
     149                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     150                 :             :                                                response_size, response);
     151                 :             :     }
     152                 :             : 
     153         [ +  + ]:          20 :     if (operation != SPDM_SET_KEY_PAIR_INFO_ERASE_OPERATION) {
     154         [ +  + ]:          16 :         if (request_size < sizeof(spdm_set_key_pair_info_request_t) +
     155                 :             :             sizeof(uint8_t) + sizeof(uint16_t) + sizeof(uint32_t) + sizeof(uint8_t)) {
     156                 :           1 :             return libspdm_generate_error_response(spdm_context,
     157                 :             :                                                    SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     158                 :             :                                                    response_size, response);
     159                 :             :         }
     160                 :             : 
     161                 :          15 :         ptr = (const uint8_t*)(spdm_request + 1);
     162                 :          15 :         ptr += sizeof(uint8_t);
     163                 :             : 
     164                 :          15 :         desired_key_usage = libspdm_read_uint16((const uint8_t *)ptr);
     165                 :          15 :         ptr += sizeof(uint16_t);
     166                 :             : 
     167                 :          15 :         desired_asym_algo = libspdm_read_uint32((const uint8_t *)ptr);
     168                 :          15 :         ptr += sizeof(uint32_t);
     169                 :             : 
     170                 :          15 :         desired_assoc_cert_slot_mask = *ptr;
     171                 :          15 :         ptr += sizeof(uint8_t);
     172                 :             : 
     173                 :          15 :         desired_pqc_asym_algo = 0;
     174         [ +  + ]:          15 :         if (spdm_request->header.spdm_version >= SPDM_MESSAGE_VERSION_14) {
     175         [ -  + ]:           9 :             if (request_size < sizeof(spdm_set_key_pair_info_request_t) +
     176                 :             :                 sizeof(uint8_t) + sizeof(uint16_t) + sizeof(uint32_t) + sizeof(uint8_t) +
     177                 :             :                 sizeof(uint8_t)) {
     178                 :           0 :                 return libspdm_generate_error_response(spdm_context,
     179                 :             :                                                        SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     180                 :             :                                                        response_size, response);
     181                 :             :             }
     182                 :             : 
     183                 :           9 :             desired_pqc_asym_algo_len = *ptr;
     184                 :           9 :             ptr += sizeof(uint8_t);
     185                 :             : 
     186                 :           9 :             if (request_size < sizeof(spdm_set_key_pair_info_request_t) +
     187                 :             :                 sizeof(uint8_t) + sizeof(uint16_t) + sizeof(uint32_t) + sizeof(uint8_t) +
     188         [ -  + ]:           9 :                 sizeof(uint8_t) + desired_pqc_asym_algo_len) {
     189                 :           0 :                 return libspdm_generate_error_response(spdm_context,
     190                 :             :                                                        SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     191                 :             :                                                        response_size, response);
     192                 :             :             }
     193                 :             : 
     194         [ -  + ]:           9 :             if (desired_pqc_asym_algo_len > sizeof(uint32_t)) {
     195                 :           0 :                 desired_pqc_asym_algo_len = sizeof(uint32_t);
     196                 :             :             }
     197                 :           9 :             libspdm_copy_mem (&desired_pqc_asym_algo, sizeof(desired_pqc_asym_algo),
     198                 :             :                               ptr, desired_pqc_asym_algo_len);
     199                 :           9 :             ptr += desired_pqc_asym_algo_len;
     200                 :             :         }
     201                 :             : 
     202                 :             :     } else {
     203                 :           4 :         desired_key_usage = 0;
     204                 :           4 :         desired_asym_algo = 0;
     205                 :           4 :         desired_pqc_asym_algo = 0;
     206                 :           4 :         desired_assoc_cert_slot_mask = 0;
     207                 :             :     }
     208                 :             : 
     209   [ -  +  -  - ]:          19 :     if (((capabilities & SPDM_KEY_PAIR_CAP_GEN_KEY_CAP) == 0) &&
     210                 :             :         (operation == SPDM_SET_KEY_PAIR_INFO_GENERATE_OPERATION)) {
     211                 :           0 :         return libspdm_generate_error_response(spdm_context,
     212                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     213                 :             :                                                response_size, response);
     214                 :             :     }
     215   [ -  +  -  - ]:          19 :     if (((capabilities & SPDM_KEY_PAIR_CAP_ERASABLE_CAP) == 0) &&
     216                 :             :         (operation == SPDM_SET_KEY_PAIR_INFO_ERASE_OPERATION)) {
     217                 :           0 :         return libspdm_generate_error_response(spdm_context,
     218                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     219                 :             :                                                response_size, response);
     220                 :             :     }
     221   [ -  +  -  - ]:          19 :     if (((capabilities & SPDM_KEY_PAIR_CAP_CERT_ASSOC_CAP) == 0) &&
     222                 :           0 :         (desired_assoc_cert_slot_mask != 0) &&
     223         [ #  # ]:           0 :         (desired_assoc_cert_slot_mask != assoc_cert_slot_mask)) {
     224                 :           0 :         return libspdm_generate_error_response(spdm_context,
     225                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     226                 :             :                                                response_size, response);
     227                 :             :     }
     228                 :             : 
     229   [ -  +  -  - ]:          19 :     if (((capabilities & SPDM_KEY_PAIR_CAP_KEY_USAGE_CAP) == 0) && (desired_key_usage != 0)) {
     230                 :           0 :         return libspdm_generate_error_response(spdm_context,
     231                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     232                 :             :                                                response_size, response);
     233                 :             :     }
     234         [ +  + ]:          19 :     if ((desired_key_usage != 0) &&
     235         [ -  + ]:           8 :         ((key_usage_capabilities | desired_key_usage) != key_usage_capabilities)) {
     236                 :           0 :         return libspdm_generate_error_response(spdm_context,
     237                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     238                 :             :                                                response_size, response);
     239                 :             :     }
     240                 :             : 
     241   [ -  +  -  - ]:          19 :     if (((capabilities & SPDM_KEY_PAIR_CAP_ASYM_ALGO_CAP) == 0) &&
     242         [ #  # ]:           0 :         ((desired_asym_algo != 0) || (desired_pqc_asym_algo != 0))) {
     243                 :           0 :         return libspdm_generate_error_response(spdm_context,
     244                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     245                 :             :                                                response_size, response);
     246                 :             :     }
     247   [ +  +  -  + ]:          19 :     if (!libspdm_onehot0(desired_asym_algo) || !libspdm_onehot0(desired_pqc_asym_algo)) {
     248                 :           1 :         return libspdm_generate_error_response(spdm_context,
     249                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     250                 :             :                                                response_size, response);
     251                 :             :     }
     252   [ +  +  +  + ]:          18 :     if ((desired_asym_algo != 0) && (desired_pqc_asym_algo != 0)) {
     253                 :           1 :         return libspdm_generate_error_response(spdm_context,
     254                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     255                 :             :                                                response_size, response);
     256                 :             :     }
     257         [ +  + ]:          17 :     if ((desired_asym_algo != 0) &&
     258         [ -  + ]:           4 :         ((asym_algo_capabilities | desired_asym_algo) != asym_algo_capabilities)) {
     259                 :           0 :         return libspdm_generate_error_response(spdm_context,
     260                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     261                 :             :                                                response_size, response);
     262                 :             :     }
     263         [ +  + ]:          17 :     if ((desired_pqc_asym_algo != 0) &&
     264         [ +  - ]:           1 :         ((pqc_asym_algo_capabilities | desired_pqc_asym_algo) != pqc_asym_algo_capabilities)) {
     265                 :             :         /* Per DSP0274 Table 115, the Requester shall only select from bits set in the
     266                 :             :          * capabilities. A DesiredPqcAsymAlgo outside PqcAsymAlgoCapabilities is the same class
     267                 :             :          * of malformed request as the DesiredAsymAlgo case above, so use InvalidRequest for
     268                 :             :          * both. */
     269                 :           1 :         return libspdm_generate_error_response(spdm_context,
     270                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     271                 :             :                                                response_size, response);
     272                 :             :     }
     273                 :             : 
     274         [ -  + ]:          16 :     if (((capabilities & SPDM_KEY_PAIR_CAP_SHAREABLE_CAP) == 0) &&
     275         [ #  # ]:           0 :         (!libspdm_onehot0(desired_assoc_cert_slot_mask))) {
     276                 :           0 :         return libspdm_generate_error_response(spdm_context,
     277                 :             :                                                SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     278                 :             :                                                response_size, response);
     279                 :             :     }
     280   [ +  +  -  + ]:          16 :     if ((operation == SPDM_SET_KEY_PAIR_INFO_ERASE_OPERATION) ||
     281                 :             :         (operation == SPDM_SET_KEY_PAIR_INFO_GENERATE_OPERATION)) {
     282         [ +  + ]:           4 :         if (assoc_cert_slot_mask != 0) {
     283                 :           1 :             return libspdm_generate_error_response(spdm_context,
     284                 :             :                                                    SPDM_ERROR_CODE_OPERATION_FAILED, 0,
     285                 :             :                                                    response_size, response);
     286                 :             :         }
     287                 :             :     }
     288                 :             : 
     289                 :             :     /* Per DSP0274, a request for key generation (GenerateKeyPair) when no asymmetric algorithm
     290                 :             :      * has been selected yet should be answered with ERROR(OperationFailed). The algorithm is
     291                 :             :      * selected either by this request (DesiredAsymAlgo/DesiredPqcAsymAlgo) or already configured
     292                 :             :      * for the key pair (CurrentAsymAlgo/CurrentPqcAsymAlgo). */
     293         [ -  + ]:          15 :     if (operation == SPDM_SET_KEY_PAIR_INFO_GENERATE_OPERATION) {
     294   [ #  #  #  # ]:           0 :         if ((desired_asym_algo == 0) && (desired_pqc_asym_algo == 0) &&
     295   [ #  #  #  # ]:           0 :             (current_asym_algo == 0) && (current_pqc_asym_algo == 0)) {
     296                 :           0 :             return libspdm_generate_error_response(spdm_context,
     297                 :             :                                                    SPDM_ERROR_CODE_OPERATION_FAILED, 0,
     298                 :             :                                                    response_size, response);
     299                 :             :         }
     300                 :             :     }
     301                 :             : 
     302                 :             :     /* Per DSP0274, the value of a key pair is bound to its selected asymmetric algorithm
     303                 :             :      * (CurrentAsymAlgo). Once a key pair is generated for a KeyPairID, a ParameterChange that
     304                 :             :      * would change the algorithm of the generated key pair shall be rejected with
     305                 :             :      * InvalidRequest. A key pair is considered generated here when an algorithm is already
     306                 :             :      * configured (CurrentAsymAlgo or CurrentPqcAsymAlgo is set). A desired algorithm of 0 means
     307                 :             :      * "do not change", so only a non-zero desired algorithm that differs from the current one is
     308                 :             :      * rejected. */
     309         [ +  + ]:          15 :     if (operation == SPDM_SET_KEY_PAIR_INFO_CHANGE_OPERATION) {
     310   [ +  +  +  +  :          12 :         if (((current_asym_algo != 0) || (current_pqc_asym_algo != 0)) &&
                   +  + ]
     311         [ +  - ]:           1 :             (((desired_asym_algo != 0) && (desired_asym_algo != current_asym_algo)) ||
     312   [ -  +  -  - ]:           9 :              ((desired_pqc_asym_algo != 0) && (desired_pqc_asym_algo != current_pqc_asym_algo)))) {
     313                 :           0 :             return libspdm_generate_error_response(spdm_context,
     314                 :             :                                                    SPDM_ERROR_CODE_INVALID_REQUEST, 0,
     315                 :             :                                                    response_size, response);
     316                 :             :         }
     317                 :             :     }
     318                 :             : 
     319                 :             :     /* Within one connection a certificate slot resolves to a single KeyPairID for the negotiated
     320                 :             :      * algorithm: DIGESTS returns exactly one KeyPairID per slot. Two different KeyPairIDs of the
     321                 :             :      * SAME asymmetric algorithm must therefore not both be associated with the same slot, otherwise
     322                 :             :      * that slot's KeyPairID would be ambiguous. Reject a request that would associate a slot which
     323                 :             :      * a different, same-algorithm KeyPairID already owns.
     324                 :             :      *
     325                 :             :      * DSP0274 does not define an error code for this conflict; OperationFailed is used here as a
     326                 :             :      * libspdm policy, consistent with the other association-conflict cases in the SET_KEY_PAIR_INFO
     327                 :             :      * error-handling clause. A slot shared across DIFFERENT algorithms is allowed (only one such
     328                 :             :      * key pair is active per connection), so the algorithm is part of the match. */
     329         [ +  + ]:          15 :     if (desired_assoc_cert_slot_mask != 0) {
     330                 :           6 :         uint32_t effective_asym_algo =
     331         [ +  + ]:           6 :             (desired_asym_algo != 0) ? desired_asym_algo : current_asym_algo;
     332                 :           6 :         uint32_t effective_pqc_asym_algo =
     333         [ -  + ]:           6 :             (desired_pqc_asym_algo != 0) ? desired_pqc_asym_algo : current_pqc_asym_algo;
     334                 :             : 
     335   [ +  +  +  - ]:           6 :         if ((effective_asym_algo != 0) || (effective_pqc_asym_algo != 0)) {
     336                 :             :             uint8_t other_key_pair_id;
     337                 :             : 
     338         [ +  + ]:          66 :             for (other_key_pair_id = 1; other_key_pair_id <= total_key_pairs;
     339                 :          60 :                  other_key_pair_id++) {
     340                 :             :                 uint16_t other_capabilities;
     341                 :             :                 uint16_t other_key_usage_capabilities;
     342                 :             :                 uint16_t other_current_key_usage;
     343                 :             :                 uint32_t other_asym_algo_capabilities;
     344                 :             :                 uint32_t other_current_asym_algo;
     345                 :             :                 uint32_t other_pqc_asym_algo_capabilities;
     346                 :             :                 uint32_t other_current_pqc_asym_algo;
     347                 :             :                 uint8_t other_assoc_cert_slot_mask;
     348                 :             : 
     349         [ +  + ]:          61 :                 if (other_key_pair_id == key_pair_id) {
     350                 :           5 :                     continue;
     351                 :             :                 }
     352         [ -  + ]:          56 :                 if (!libspdm_read_key_pair_info(
     353                 :             :                         spdm_context, session_id, other_key_pair_id, &total_key_pairs, &other_capabilities,
     354                 :             :                         &other_key_usage_capabilities, &other_current_key_usage,
     355                 :             :                         &other_asym_algo_capabilities, &other_current_asym_algo,
     356                 :             :                         &other_pqc_asym_algo_capabilities, &other_current_pqc_asym_algo,
     357                 :             :                         &other_assoc_cert_slot_mask, NULL, NULL)) {
     358                 :           0 :                     continue;
     359                 :             :                 }
     360         [ +  + ]:          56 :                 if ((other_current_asym_algo == effective_asym_algo) &&
     361         [ +  - ]:           5 :                     (other_current_pqc_asym_algo == effective_pqc_asym_algo) &&
     362         [ +  + ]:           5 :                     ((other_assoc_cert_slot_mask & desired_assoc_cert_slot_mask) != 0)) {
     363                 :           1 :                     return libspdm_generate_error_response(
     364                 :             :                         spdm_context, SPDM_ERROR_CODE_OPERATION_FAILED, 0,
     365                 :             :                         response_size, response);
     366                 :             :                 }
     367                 :             :             }
     368                 :             :         }
     369                 :             :     }
     370                 :             : 
     371         [ +  + ]:          14 :     if (libspdm_get_connection_version(spdm_context) >= SPDM_MESSAGE_VERSION_14) {
     372                 :           8 :         need_reset = libspdm_is_capabilities_flag_supported(
     373                 :             :             spdm_context, false, 0,
     374                 :             :             SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_SET_KEY_PAIR_RESET_CAP);
     375                 :             :     } else {
     376                 :           6 :         need_reset = false;
     377                 :             :     }
     378                 :          14 :     result = libspdm_write_key_pair_info(
     379                 :             :         spdm_context,
     380                 :             :         session_id,
     381                 :             :         key_pair_id,
     382                 :             :         operation,
     383                 :             :         desired_key_usage,
     384                 :             :         desired_asym_algo,
     385                 :             :         desired_pqc_asym_algo,
     386                 :             :         desired_assoc_cert_slot_mask,
     387                 :             :         &need_reset);
     388         [ -  + ]:          14 :     if (!result) {
     389                 :           0 :         return libspdm_generate_error_response(spdm_context,
     390                 :             :                                                SPDM_ERROR_CODE_OPERATION_FAILED, 0,
     391                 :             :                                                response_size, response);
     392                 :             :     }
     393                 :             : 
     394                 :          14 :     spdm_response = response;
     395                 :          14 :     *response_size = sizeof(spdm_set_key_pair_info_ack_response_t);
     396                 :             : 
     397         [ +  + ]:          14 :     if (need_reset) {
     398                 :           5 :         return libspdm_generate_error_response(spdm_context,
     399                 :             :                                                SPDM_ERROR_CODE_RESET_REQUIRED, 0,
     400                 :             :                                                response_size, response);
     401                 :             :     } else {
     402                 :             :         /* Update context with new key pair information if a reset is not needed. Re-read the key
     403                 :             :          * pair info so the authoritative post-write association and key usage are used (the device
     404                 :             :          * may normalize or apply defaults on a successful write). */
     405                 :           9 :         uint8_t new_assoc_cert_slot_mask = 0;
     406                 :           9 :         uint16_t new_current_key_usage = 0;
     407                 :             :         uint8_t slot_index;
     408                 :             : 
     409                 :           9 :         result = libspdm_read_key_pair_info(
     410                 :             :             spdm_context, session_id, key_pair_id, &total_key_pairs, &capabilities, &key_usage_capabilities,
     411                 :             :             &new_current_key_usage, &asym_algo_capabilities, &current_asym_algo,
     412                 :             :             &pqc_asym_algo_capabilities, &current_pqc_asym_algo, &new_assoc_cert_slot_mask,
     413                 :             :             NULL, NULL);
     414         [ -  + ]:           9 :         if (!result) {
     415                 :           0 :             return libspdm_generate_error_response(spdm_context,
     416                 :             :                                                    SPDM_ERROR_CODE_UNSPECIFIED, 0,
     417                 :             :                                                    response_size, response);
     418                 :             :         }
     419                 :             : 
     420         [ +  + ]:          81 :         for (slot_index = 0; slot_index < SPDM_MAX_SLOT_COUNT; slot_index++) {
     421         [ +  + ]:          72 :             if ((new_assoc_cert_slot_mask & (1 << slot_index)) != 0) {
     422                 :             :                 /* Slot is (still) associated with this KeyPairID. */
     423                 :           4 :                 spdm_context->local_context.local_key_pair_id[slot_index] = key_pair_id;
     424                 :           4 :                 spdm_context->local_context.local_key_usage_bit_mask[slot_index] =
     425                 :             :                     new_current_key_usage;
     426         [ +  + ]:          68 :             } else if (spdm_context->local_context.local_key_pair_id[slot_index] == key_pair_id) {
     427                 :             :                 /* Context still points at this KeyPairID but the slot is no longer in the
     428                 :             :                  * authoritative mask (removed or stale); clear it. */
     429                 :           3 :                 spdm_context->local_context.local_key_pair_id[slot_index] = 0;
     430                 :           3 :                 spdm_context->local_context.local_key_usage_bit_mask[slot_index] = 0;
     431                 :             :             }
     432                 :             :         }
     433                 :             : 
     434                 :           9 :         spdm_response->header.spdm_version = spdm_request->header.spdm_version;
     435                 :           9 :         spdm_response->header.request_response_code = SPDM_SET_KEY_PAIR_INFO_ACK;
     436                 :           9 :         spdm_response->header.param1 = 0;
     437                 :           9 :         spdm_response->header.param2 = 0;
     438                 :             :     }
     439                 :             : 
     440                 :           9 :     return LIBSPDM_STATUS_SUCCESS;
     441                 :             : }
     442                 :             : 
     443                 :             : #endif /*LIBSPDM_ENABLE_CAPABILITY_SET_KEY_PAIR_INFO_CAP*/
        

Generated by: LCOV version 2.0-1