qapi-schema: dump-guest-memory: Improve text
[qemu/ar7.git] / crypto / secret.c
blob9a9257a7f00f4df2aa25256ab0c331c5226308a4
1 /*
2 * QEMU crypto secret support
4 * Copyright (c) 2015 Red Hat, Inc.
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
21 #include "crypto/secret.h"
22 #include "crypto/cipher.h"
23 #include "qom/object_interfaces.h"
24 #include "qemu/base64.h"
25 #include "trace.h"
28 static void
29 qcrypto_secret_load_data(QCryptoSecret *secret,
30 uint8_t **output,
31 size_t *outputlen,
32 Error **errp)
34 char *data = NULL;
35 size_t length = 0;
36 GError *gerr = NULL;
38 *output = NULL;
39 *outputlen = 0;
41 if (secret->file) {
42 if (secret->data) {
43 error_setg(errp,
44 "'file' and 'data' are mutually exclusive");
45 return;
47 if (!g_file_get_contents(secret->file, &data, &length, &gerr)) {
48 error_setg(errp,
49 "Unable to read %s: %s",
50 secret->file, gerr->message);
51 g_error_free(gerr);
52 return;
54 *output = (uint8_t *)data;
55 *outputlen = length;
56 } else if (secret->data) {
57 *outputlen = strlen(secret->data);
58 *output = (uint8_t *)g_strdup(secret->data);
59 } else {
60 error_setg(errp, "Either 'file' or 'data' must be provided");
65 static void qcrypto_secret_decrypt(QCryptoSecret *secret,
66 const uint8_t *input,
67 size_t inputlen,
68 uint8_t **output,
69 size_t *outputlen,
70 Error **errp)
72 uint8_t *key = NULL, *ciphertext = NULL, *iv = NULL;
73 size_t keylen, ciphertextlen, ivlen;
74 QCryptoCipher *aes = NULL;
75 uint8_t *plaintext = NULL;
77 *output = NULL;
78 *outputlen = 0;
80 if (qcrypto_secret_lookup(secret->keyid,
81 &key, &keylen,
82 errp) < 0) {
83 goto cleanup;
86 if (keylen != 32) {
87 error_setg(errp, "Key should be 32 bytes in length");
88 goto cleanup;
91 if (!secret->iv) {
92 error_setg(errp, "IV is required to decrypt secret");
93 goto cleanup;
96 iv = qbase64_decode(secret->iv, -1, &ivlen, errp);
97 if (!iv) {
98 goto cleanup;
100 if (ivlen != 16) {
101 error_setg(errp, "IV should be 16 bytes in length not %zu",
102 ivlen);
103 goto cleanup;
106 aes = qcrypto_cipher_new(QCRYPTO_CIPHER_ALG_AES_256,
107 QCRYPTO_CIPHER_MODE_CBC,
108 key, keylen,
109 errp);
110 if (!aes) {
111 goto cleanup;
114 if (qcrypto_cipher_setiv(aes, iv, ivlen, errp) < 0) {
115 goto cleanup;
118 if (secret->format == QCRYPTO_SECRET_FORMAT_BASE64) {
119 ciphertext = qbase64_decode((const gchar*)input,
120 inputlen,
121 &ciphertextlen,
122 errp);
123 if (!ciphertext) {
124 goto cleanup;
126 plaintext = g_new0(uint8_t, ciphertextlen + 1);
127 } else {
128 ciphertextlen = inputlen;
129 plaintext = g_new0(uint8_t, inputlen + 1);
131 if (qcrypto_cipher_decrypt(aes,
132 ciphertext ? ciphertext : input,
133 plaintext,
134 ciphertextlen,
135 errp) < 0) {
136 plaintext = NULL;
137 goto cleanup;
140 if (plaintext[ciphertextlen - 1] > 16 ||
141 plaintext[ciphertextlen - 1] > ciphertextlen) {
142 error_setg(errp, "Incorrect number of padding bytes (%d) "
143 "found on decrypted data",
144 (int)plaintext[ciphertextlen - 1]);
145 g_free(plaintext);
146 plaintext = NULL;
147 goto cleanup;
150 /* Even though plaintext may contain arbitrary NUL
151 * ensure it is explicitly NUL terminated.
153 ciphertextlen -= plaintext[ciphertextlen - 1];
154 plaintext[ciphertextlen] = '\0';
156 *output = plaintext;
157 *outputlen = ciphertextlen;
159 cleanup:
160 g_free(ciphertext);
161 g_free(iv);
162 g_free(key);
163 qcrypto_cipher_free(aes);
167 static void qcrypto_secret_decode(const uint8_t *input,
168 size_t inputlen,
169 uint8_t **output,
170 size_t *outputlen,
171 Error **errp)
173 *output = qbase64_decode((const gchar*)input,
174 inputlen,
175 outputlen,
176 errp);
180 static void
181 qcrypto_secret_prop_set_loaded(Object *obj,
182 bool value,
183 Error **errp)
185 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
187 if (value) {
188 Error *local_err = NULL;
189 uint8_t *input = NULL;
190 size_t inputlen = 0;
191 uint8_t *output = NULL;
192 size_t outputlen = 0;
194 qcrypto_secret_load_data(secret, &input, &inputlen, &local_err);
195 if (local_err) {
196 error_propagate(errp, local_err);
197 return;
200 if (secret->keyid) {
201 qcrypto_secret_decrypt(secret, input, inputlen,
202 &output, &outputlen, &local_err);
203 g_free(input);
204 if (local_err) {
205 error_propagate(errp, local_err);
206 return;
208 input = output;
209 inputlen = outputlen;
210 } else {
211 if (secret->format != QCRYPTO_SECRET_FORMAT_RAW) {
212 qcrypto_secret_decode(input, inputlen,
213 &output, &outputlen, &local_err);
214 g_free(input);
215 if (local_err) {
216 error_propagate(errp, local_err);
217 return;
219 input = output;
220 inputlen = outputlen;
224 secret->rawdata = input;
225 secret->rawlen = inputlen;
226 } else {
227 g_free(secret->rawdata);
228 secret->rawlen = 0;
233 static bool
234 qcrypto_secret_prop_get_loaded(Object *obj,
235 Error **errp G_GNUC_UNUSED)
237 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
238 return secret->data != NULL;
242 static void
243 qcrypto_secret_prop_set_format(Object *obj,
244 int value,
245 Error **errp G_GNUC_UNUSED)
247 QCryptoSecret *creds = QCRYPTO_SECRET(obj);
249 creds->format = value;
253 static int
254 qcrypto_secret_prop_get_format(Object *obj,
255 Error **errp G_GNUC_UNUSED)
257 QCryptoSecret *creds = QCRYPTO_SECRET(obj);
259 return creds->format;
263 static void
264 qcrypto_secret_prop_set_data(Object *obj,
265 const char *value,
266 Error **errp)
268 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
270 g_free(secret->data);
271 secret->data = g_strdup(value);
275 static char *
276 qcrypto_secret_prop_get_data(Object *obj,
277 Error **errp)
279 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
280 return g_strdup(secret->data);
284 static void
285 qcrypto_secret_prop_set_file(Object *obj,
286 const char *value,
287 Error **errp)
289 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
291 g_free(secret->file);
292 secret->file = g_strdup(value);
296 static char *
297 qcrypto_secret_prop_get_file(Object *obj,
298 Error **errp)
300 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
301 return g_strdup(secret->file);
305 static void
306 qcrypto_secret_prop_set_iv(Object *obj,
307 const char *value,
308 Error **errp)
310 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
312 g_free(secret->iv);
313 secret->iv = g_strdup(value);
317 static char *
318 qcrypto_secret_prop_get_iv(Object *obj,
319 Error **errp)
321 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
322 return g_strdup(secret->iv);
326 static void
327 qcrypto_secret_prop_set_keyid(Object *obj,
328 const char *value,
329 Error **errp)
331 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
333 g_free(secret->keyid);
334 secret->keyid = g_strdup(value);
338 static char *
339 qcrypto_secret_prop_get_keyid(Object *obj,
340 Error **errp)
342 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
343 return g_strdup(secret->keyid);
347 static void
348 qcrypto_secret_complete(UserCreatable *uc, Error **errp)
350 object_property_set_bool(OBJECT(uc), true, "loaded", errp);
354 static void
355 qcrypto_secret_init(Object *obj)
357 object_property_add_bool(obj, "loaded",
358 qcrypto_secret_prop_get_loaded,
359 qcrypto_secret_prop_set_loaded,
360 NULL);
361 object_property_add_enum(obj, "format",
362 "QCryptoSecretFormat",
363 QCryptoSecretFormat_lookup,
364 qcrypto_secret_prop_get_format,
365 qcrypto_secret_prop_set_format,
366 NULL);
367 object_property_add_str(obj, "data",
368 qcrypto_secret_prop_get_data,
369 qcrypto_secret_prop_set_data,
370 NULL);
371 object_property_add_str(obj, "file",
372 qcrypto_secret_prop_get_file,
373 qcrypto_secret_prop_set_file,
374 NULL);
375 object_property_add_str(obj, "keyid",
376 qcrypto_secret_prop_get_keyid,
377 qcrypto_secret_prop_set_keyid,
378 NULL);
379 object_property_add_str(obj, "iv",
380 qcrypto_secret_prop_get_iv,
381 qcrypto_secret_prop_set_iv,
382 NULL);
386 static void
387 qcrypto_secret_finalize(Object *obj)
389 QCryptoSecret *secret = QCRYPTO_SECRET(obj);
391 g_free(secret->iv);
392 g_free(secret->file);
393 g_free(secret->keyid);
394 g_free(secret->rawdata);
395 g_free(secret->data);
398 static void
399 qcrypto_secret_class_init(ObjectClass *oc, void *data)
401 UserCreatableClass *ucc = USER_CREATABLE_CLASS(oc);
403 ucc->complete = qcrypto_secret_complete;
407 int qcrypto_secret_lookup(const char *secretid,
408 uint8_t **data,
409 size_t *datalen,
410 Error **errp)
412 Object *obj;
413 QCryptoSecret *secret;
415 obj = object_resolve_path_component(
416 object_get_objects_root(), secretid);
417 if (!obj) {
418 error_setg(errp, "No secret with id '%s'", secretid);
419 return -1;
422 secret = (QCryptoSecret *)
423 object_dynamic_cast(obj,
424 TYPE_QCRYPTO_SECRET);
425 if (!secret) {
426 error_setg(errp, "Object with id '%s' is not a secret",
427 secretid);
428 return -1;
431 if (!secret->rawdata) {
432 error_setg(errp, "Secret with id '%s' has no data",
433 secretid);
434 return -1;
437 *data = g_new0(uint8, secret->rawlen + 1);
438 memcpy(*data, secret->rawdata, secret->rawlen);
439 (*data)[secret->rawlen] = '\0';
440 *datalen = secret->rawlen;
442 return 0;
446 char *qcrypto_secret_lookup_as_utf8(const char *secretid,
447 Error **errp)
449 uint8_t *data;
450 size_t datalen;
452 if (qcrypto_secret_lookup(secretid,
453 &data,
454 &datalen,
455 errp) < 0) {
456 return NULL;
459 if (!g_utf8_validate((const gchar*)data, datalen, NULL)) {
460 error_setg(errp,
461 "Data from secret %s is not valid UTF-8",
462 secretid);
463 g_free(data);
464 return NULL;
467 return (char *)data;
471 char *qcrypto_secret_lookup_as_base64(const char *secretid,
472 Error **errp)
474 uint8_t *data;
475 size_t datalen;
476 char *ret;
478 if (qcrypto_secret_lookup(secretid,
479 &data,
480 &datalen,
481 errp) < 0) {
482 return NULL;
485 ret = g_base64_encode(data, datalen);
486 g_free(data);
487 return ret;
491 static const TypeInfo qcrypto_secret_info = {
492 .parent = TYPE_OBJECT,
493 .name = TYPE_QCRYPTO_SECRET,
494 .instance_size = sizeof(QCryptoSecret),
495 .instance_init = qcrypto_secret_init,
496 .instance_finalize = qcrypto_secret_finalize,
497 .class_size = sizeof(QCryptoSecretClass),
498 .class_init = qcrypto_secret_class_init,
499 .interfaces = (InterfaceInfo[]) {
500 { TYPE_USER_CREATABLE },
506 static void
507 qcrypto_secret_register_types(void)
509 type_register_static(&qcrypto_secret_info);
513 type_init(qcrypto_secret_register_types);