Address style check nits for SLH-DSA

Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/25882)
This commit is contained in:
slontis 2024-11-13 10:59:10 +11:00 committed by Tomas Mraz
parent 148f4d23e1
commit db5846a7e0
13 changed files with 175 additions and 166 deletions

View File

@ -46,9 +46,6 @@ static int slh_sign_internal(SLH_DSA_CTX *ctx, const SLH_DSA_KEY *priv,
int ret = 0; int ret = 0;
const SLH_DSA_PARAMS *params = ctx->params; const SLH_DSA_PARAMS *params = ctx->params;
size_t sig_len_expected = params->sig_len; size_t sig_len_expected = params->sig_len;
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_ADRS_DECLARE(adrs);
uint8_t m_digest[SLH_MAX_M]; uint8_t m_digest[SLH_MAX_M];
const uint8_t *md; /* The first md_len bytes of m_digest */ const uint8_t *md; /* The first md_len bytes of m_digest */
size_t md_len = MD_LEN(params); /* The size of the digest |md| */ size_t md_len = MD_LEN(params); /* The size of the digest |md| */
@ -61,6 +58,10 @@ static int slh_sign_internal(SLH_DSA_CTX *ctx, const SLH_DSA_KEY *priv,
uint64_t tree_id; uint64_t tree_id;
uint32_t leaf_id; uint32_t leaf_id;
SLH_ADRS_DECLARE(adrs);
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
if (sig_len != NULL) if (sig_len != NULL)
*sig_len = sig_len_expected; *sig_len = sig_len_expected;

View File

@ -79,10 +79,11 @@ static int slh_fors_node(SLH_DSA_CTX *ctx, const uint8_t *sk_seed,
uint32_t height, uint8_t *node, size_t node_len) uint32_t height, uint8_t *node, size_t node_len)
{ {
int ret = 0; int ret = 0;
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
uint8_t sk[SLH_MAX_N], lnode[SLH_MAX_N], rnode[SLH_MAX_N]; uint8_t sk[SLH_MAX_N], lnode[SLH_MAX_N], rnode[SLH_MAX_N];
uint32_t n = ctx->params->n; uint32_t n = ctx->params->n;
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
if (height == 0) { if (height == 0) {
/* Gets here for leaf nodes */ /* Gets here for leaf nodes */
if (!slh_fors_sk_gen(ctx, sk_seed, pk_seed, adrs, node_id, if (!slh_fors_sk_gen(ctx, sk_seed, pk_seed, adrs, node_id,
@ -211,13 +212,6 @@ int ossl_slh_fors_pk_from_sig(SLH_DSA_CTX *ctx, PACKET *fors_sig_rpkt,
SLH_ADRS adrs, uint8_t *pk_out, size_t pk_out_len) SLH_ADRS adrs, uint8_t *pk_out, size_t pk_out_len)
{ {
int ret = 0; int ret = 0;
SLH_ADRS_DECLARE(pk_adrs);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_ADRS_FN_DECLARE(adrsf, set_tree_index);
SLH_ADRS_FN_DECLARE(adrsf, set_tree_height);
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_HASH_FN_DECLARE(hashf, F);
SLH_HASH_FN_DECLARE(hashf, H);
uint32_t i, j, aoff = 0; uint32_t i, j, aoff = 0;
uint32_t ids[SLH_MAX_K]; uint32_t ids[SLH_MAX_K];
const SLH_DSA_PARAMS *params = ctx->params; const SLH_DSA_PARAMS *params = ctx->params;
@ -231,6 +225,14 @@ int ossl_slh_fors_pk_from_sig(SLH_DSA_CTX *ctx, PACKET *fors_sig_rpkt,
uint8_t *node0, *node1; /* Pointers into roots[] */ uint8_t *node0, *node1; /* Pointers into roots[] */
WPACKET root_pkt, *wroot_pkt = &root_pkt; /* Points to |roots| buffer */ WPACKET root_pkt, *wroot_pkt = &root_pkt; /* Points to |roots| buffer */
SLH_ADRS_DECLARE(pk_adrs);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_ADRS_FN_DECLARE(adrsf, set_tree_index);
SLH_ADRS_FN_DECLARE(adrsf, set_tree_height);
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_HASH_FN_DECLARE(hashf, F);
SLH_HASH_FN_DECLARE(hashf, H);
if (!WPACKET_init_static_len(wroot_pkt, roots, sizeof(roots), 0)) if (!WPACKET_init_static_len(wroot_pkt, roots, sizeof(roots), 0))
return 0; return 0;

View File

@ -41,25 +41,31 @@ typedef struct slh_hash_ctx_st {
*/ */
typedef int (OSSL_SLH_HASHFUNC_H_MSG)(SLH_HASH_CTX *ctx, const uint8_t *r, typedef int (OSSL_SLH_HASHFUNC_H_MSG)(SLH_HASH_CTX *ctx, const uint8_t *r,
const uint8_t *pk_seed, const uint8_t *pk_root, const uint8_t *pk_seed, const uint8_t *pk_root,
const uint8_t *msg, size_t msg_len, uint8_t *out, size_t out_len); const uint8_t *msg, size_t msg_len,
uint8_t *out, size_t out_len);
typedef int (OSSL_SLH_HASHFUNC_PRF)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed, typedef int (OSSL_SLH_HASHFUNC_PRF)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed,
const uint8_t *sk_seed, const SLH_ADRS adrs, const uint8_t *sk_seed, const SLH_ADRS adrs,
uint8_t *out, size_t out_len); uint8_t *out, size_t out_len);
typedef int (OSSL_SLH_HASHFUNC_PRF_MSG)(SLH_HASH_CTX *ctx, const uint8_t *sk_prf, typedef int (OSSL_SLH_HASHFUNC_PRF_MSG)(SLH_HASH_CTX *ctx, const uint8_t *sk_prf,
const uint8_t *opt_rand, const uint8_t *msg, size_t msg_len, WPACKET *pkt); const uint8_t *opt_rand,
const uint8_t *msg, size_t msg_len,
WPACKET *pkt);
typedef int (OSSL_SLH_HASHFUNC_F)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed, typedef int (OSSL_SLH_HASHFUNC_F)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed,
const SLH_ADRS adrs, const uint8_t *m1, size_t m1_len, const SLH_ADRS adrs,
const uint8_t *m1, size_t m1_len,
uint8_t *out, size_t out_len); uint8_t *out, size_t out_len);
typedef int (OSSL_SLH_HASHFUNC_H)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed, typedef int (OSSL_SLH_HASHFUNC_H)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed,
const SLH_ADRS adrs, const uint8_t *m1, const uint8_t *m2, const SLH_ADRS adrs,
const uint8_t *m1, const uint8_t *m2,
uint8_t *out, size_t out_len); uint8_t *out, size_t out_len);
typedef int (OSSL_SLH_HASHFUNC_T)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed, typedef int (OSSL_SLH_HASHFUNC_T)(SLH_HASH_CTX *ctx, const uint8_t *pk_seed,
const SLH_ADRS adrs, const uint8_t *m1, size_t m1_len, const SLH_ADRS adrs,
const uint8_t *m1, size_t m1_len,
uint8_t *out, size_t out_len); uint8_t *out, size_t out_len);
typedef struct slh_hash_func_st { typedef struct slh_hash_func_st {

View File

@ -22,7 +22,7 @@
* @param sk_seed The private key seed of size |n| * @param sk_seed The private key seed of size |n|
* @param pk_seed The public key seed of size |n| * @param pk_seed The public key seed of size |n|
* @param tree_id Index of the XMSS tree that will sign the message * @param tree_id Index of the XMSS tree that will sign the message
* @param leaf_id Index of the WOTS+ key within the XMSS tree that will signed the message * @param leaf_id Index of the WOTS+ key within the XMSS tree that will sign the message
* @param sig_wpkt A WPACKET object to write the Hypertree Signature to. * @param sig_wpkt A WPACKET object to write the Hypertree Signature to.
* @returns 1 on success, or 0 on error. * @returns 1 on success, or 0 on error.
*/ */

View File

@ -142,12 +142,6 @@ int ossl_slh_wots_pk_gen(SLH_DSA_CTX *ctx,
SLH_ADRS adrs, uint8_t *pk_out, size_t pk_out_len) SLH_ADRS adrs, uint8_t *pk_out, size_t pk_out_len)
{ {
int ret = 0; int ret = 0;
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_HASH_FN_DECLARE(hashf, PRF);
SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
SLH_ADRS_DECLARE(sk_adrs);
SLH_ADRS_DECLARE(wots_pk_adrs);
size_t n = ctx->params->n; size_t n = ctx->params->n;
size_t i, len = SLH_WOTS_LEN(n); /* 2 * n + 3 */ size_t i, len = SLH_WOTS_LEN(n); /* 2 * n + 3 */
uint8_t sk[SLH_MAX_N]; uint8_t sk[SLH_MAX_N];
@ -155,6 +149,13 @@ int ossl_slh_wots_pk_gen(SLH_DSA_CTX *ctx,
WPACKET pkt, *tmp_wpkt = &pkt; /* Points to the |tmp| buffer */ WPACKET pkt, *tmp_wpkt = &pkt; /* Points to the |tmp| buffer */
size_t tmp_len = 0; size_t tmp_len = 0;
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_HASH_FN_DECLARE(hashf, PRF);
SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
SLH_ADRS_DECLARE(sk_adrs);
SLH_ADRS_DECLARE(wots_pk_adrs);
if (!WPACKET_init_static_len(tmp_wpkt, tmp, sizeof(tmp), 0)) if (!WPACKET_init_static_len(tmp_wpkt, tmp, sizeof(tmp), 0))
return 0; return 0;
adrsf->copy(sk_adrs, adrs); adrsf->copy(sk_adrs, adrs);
@ -206,18 +207,18 @@ int ossl_slh_wots_sign(SLH_DSA_CTX *ctx, const uint8_t *msg,
SLH_ADRS adrs, WPACKET *sig_wpkt) SLH_ADRS adrs, WPACKET *sig_wpkt)
{ {
int ret = 0; int ret = 0;
uint8_t msg_and_csum_nibbles[SLH_WOTS_LEN_MAX]; /* size is >= 2 * n + 3 */
uint8_t sk[SLH_MAX_N];
size_t i;
size_t n = ctx->params->n;
size_t len1 = SLH_WOTS_LEN1(n); /* 2 * n = the msg length in nibbles */
size_t len = len1 + SLH_WOTS_LEN2; /* 2 * n + 3 (3 checksum nibbles) */
SLH_ADRS_DECLARE(sk_adrs);
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx); SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf); SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_HASH_FN_DECLARE(hashf, PRF); SLH_HASH_FN_DECLARE(hashf, PRF);
SLH_ADRS_FN_DECLARE(adrsf, set_chain_address); SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
SLH_ADRS_DECLARE(sk_adrs);
uint8_t msg_and_csum_nibbles[SLH_WOTS_LEN_MAX]; /* size is >= 2 * n + 3 */
uint8_t sk[SLH_MAX_N];
size_t i, len1, len;
size_t n = ctx->params->n;
len1 = SLH_WOTS_LEN1(n); /* 2 * n is for the message length in nibbles */
len = len1 + SLH_WOTS_LEN2; /* 2 * n + 3 (3 checksum nibbles) */
/* /*
* Convert n message bytes to 2*n base w=16 integers * Convert n message bytes to 2*n base w=16 integers
@ -269,19 +270,20 @@ int ossl_slh_wots_pk_from_sig(SLH_DSA_CTX *ctx,
uint8_t *pk_out, size_t pk_out_len) uint8_t *pk_out, size_t pk_out_len)
{ {
int ret = 0; int ret = 0;
SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
SLH_ADRS_DECLARE(wots_pk_adrs);
uint8_t msg_and_csum_nibbles[SLH_WOTS_LEN_MAX]; uint8_t msg_and_csum_nibbles[SLH_WOTS_LEN_MAX];
size_t i, len1, len, n = ctx->params->n; size_t i;
const uint8_t *sig_i; /* Pointer into |pkt_sig| buffer */ size_t n = ctx->params->n;
size_t len1 = SLH_WOTS_LEN1(n);
size_t len = len1 + SLH_WOTS_LEN2; /* 2n + 3 */
const uint8_t *sig_i; /* Pointer into |sig_rpkt| buffer */
uint8_t tmp[SLH_WOTS_LEN_MAX * SLH_MAX_N]; uint8_t tmp[SLH_WOTS_LEN_MAX * SLH_MAX_N];
WPACKET pkt, *tmp_pkt = &pkt; WPACKET pkt, *tmp_pkt = &pkt;
size_t tmp_len = 0; size_t tmp_len = 0;
len1 = SLH_WOTS_LEN1(n); SLH_HASH_FUNC_DECLARE(ctx, hashf, hctx);
len = len1 + SLH_WOTS_LEN2; /* 2n + 3 */ SLH_ADRS_FUNC_DECLARE(ctx, adrsf);
SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
SLH_ADRS_DECLARE(wots_pk_adrs);
if (!WPACKET_init_static_len(tmp_pkt, tmp, sizeof(tmp), 0)) if (!WPACKET_init_static_len(tmp_pkt, tmp, sizeof(tmp), 0))
return 0; return 0;

View File

@ -463,30 +463,30 @@ static const OSSL_ALGORITHM deflt_signature[] = {
{ PROV_NAMES_CMAC, "provider=default", ossl_mac_legacy_cmac_signature_functions }, { PROV_NAMES_CMAC, "provider=default", ossl_mac_legacy_cmac_signature_functions },
#endif #endif
#ifndef OPENSSL_NO_SLH_DSA #ifndef OPENSSL_NO_SLH_DSA
{ PROV_NAMES_SLH_DSA_SHA2_128S, "provider=default", ossl_slh_dsa_sha2_128s_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_128S, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_128S }, ossl_slh_dsa_sha2_128s_signature_functions, PROV_DESCS_SLH_DSA_SHA2_128S },
{ PROV_NAMES_SLH_DSA_SHA2_128F, "provider=default", ossl_slh_dsa_sha2_128f_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_128F, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_128F }, ossl_slh_dsa_sha2_128f_signature_functions, PROV_DESCS_SLH_DSA_SHA2_128F },
{ PROV_NAMES_SLH_DSA_SHA2_192S, "provider=default", ossl_slh_dsa_sha2_192s_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_192S, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_192S }, ossl_slh_dsa_sha2_192s_signature_functions, PROV_DESCS_SLH_DSA_SHA2_192S },
{ PROV_NAMES_SLH_DSA_SHA2_192F, "provider=default", ossl_slh_dsa_sha2_192f_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_192F, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_192F }, ossl_slh_dsa_sha2_192f_signature_functions, PROV_DESCS_SLH_DSA_SHA2_192F },
{ PROV_NAMES_SLH_DSA_SHA2_256S, "provider=default", ossl_slh_dsa_sha2_256s_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_256S, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_256S }, ossl_slh_dsa_sha2_256s_signature_functions, PROV_DESCS_SLH_DSA_SHA2_256S },
{ PROV_NAMES_SLH_DSA_SHA2_256F, "provider=default", ossl_slh_dsa_sha2_256f_signature_functions, { PROV_NAMES_SLH_DSA_SHA2_256F, "provider=default",
PROV_DESCS_SLH_DSA_SHA2_256F }, ossl_slh_dsa_sha2_256f_signature_functions, PROV_DESCS_SLH_DSA_SHA2_256F },
{ PROV_NAMES_SLH_DSA_SHAKE_128S, "provider=default", ossl_slh_dsa_shake_128s_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_128S, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_128S }, ossl_slh_dsa_shake_128s_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_128S },
{ PROV_NAMES_SLH_DSA_SHAKE_128F, "provider=default", ossl_slh_dsa_shake_128f_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_128F, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_128F }, ossl_slh_dsa_shake_128f_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_128F },
{ PROV_NAMES_SLH_DSA_SHAKE_192S, "provider=default", ossl_slh_dsa_shake_192s_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_192S, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_192S }, ossl_slh_dsa_shake_192s_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_192S },
{ PROV_NAMES_SLH_DSA_SHAKE_192F, "provider=default", ossl_slh_dsa_shake_192f_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_192F, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_192F }, ossl_slh_dsa_shake_192f_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_192F },
{ PROV_NAMES_SLH_DSA_SHAKE_256S, "provider=default", ossl_slh_dsa_shake_256s_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_256S, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_256S }, ossl_slh_dsa_shake_256s_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_256S },
{ PROV_NAMES_SLH_DSA_SHAKE_256F, "provider=default", ossl_slh_dsa_shake_256f_signature_functions, { PROV_NAMES_SLH_DSA_SHAKE_256F, "provider=default",
PROV_DESCS_SLH_DSA_SHAKE_256F }, ossl_slh_dsa_shake_256f_signature_functions, PROV_DESCS_SLH_DSA_SHAKE_256F },
#endif /* OPENSSL_NO_SLH_DSA */ #endif /* OPENSSL_NO_SLH_DSA */
{ NULL, NULL, NULL } { NULL, NULL, NULL }
}; };

View File

@ -147,15 +147,13 @@ static int slh_sign(void *vctx, unsigned char *sig, size_t *siglen,
return ret; return ret;
} }
static int slh_verify_msg_init(void *vctx, void *vkey, static int slh_verify_msg_init(void *vctx, void *vkey, const OSSL_PARAM params[])
const OSSL_PARAM params[])
{ {
return slh_signverify_msg_init(vctx, vkey, params, EVP_PKEY_OP_VERIFY, return slh_signverify_msg_init(vctx, vkey, params, EVP_PKEY_OP_VERIFY,
"SLH_DSA Verify Init"); "SLH_DSA Verify Init");
} }
static int slh_verify(void *vctx, static int slh_verify(void *vctx, const unsigned char *sig, size_t siglen,
const unsigned char *sig, size_t siglen,
const unsigned char *msg, size_t msg_len) const unsigned char *msg, size_t msg_len)
{ {
PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx; PROV_SLH_DSA_CTX *ctx = (PROV_SLH_DSA_CTX *)vctx;