Replace pointers to cipher_t/digest_t in connection_t with structs.
[tinc] / src / openssl / digest.c
index 9c3ab1e..71eaec7 100644 (file)
@@ -18,8 +18,6 @@
 */
 
 #include "../system.h"
-#include "../utils.h"
-#include "../xalloc.h"
 
 #include <openssl/err.h>
 #include <openssl/hmac.h>
 #include "../digest.h"
 #include "../logger.h"
 
-static digest_t *digest_open(const EVP_MD *evp_md, int maclength) {
-       digest_t *digest = xzalloc(sizeof(*digest));
+static void digest_open(digest_t *digest, const EVP_MD *evp_md, size_t maclength) {
        digest->digest = evp_md;
 
-       int digestlen = EVP_MD_size(digest->digest);
+       size_t digestlen = EVP_MD_size(digest->digest);
 
-       if(maclength > digestlen || maclength < 0) {
+       if(maclength == DIGEST_ALGO_SIZE || maclength > digestlen) {
                digest->maclength = digestlen;
        } else {
                digest->maclength = maclength;
        }
-
-       return digest;
 }
 
-digest_t *digest_open_by_name(const char *name, int maclength) {
+bool digest_open_by_name(digest_t *digest, const char *name, size_t maclength) {
        const EVP_MD *evp_md = EVP_get_digestbyname(name);
 
        if(!evp_md) {
@@ -51,10 +46,11 @@ digest_t *digest_open_by_name(const char *name, int maclength) {
                return false;
        }
 
-       return digest_open(evp_md, maclength);
+       digest_open(digest, evp_md, maclength);
+       return true;
 }
 
-digest_t *digest_open_by_nid(int nid, int maclength) {
+bool digest_open_by_nid(digest_t *digest, int nid, size_t maclength) {
        const EVP_MD *evp_md = EVP_get_digestbynid(nid);
 
        if(!evp_md) {
@@ -62,13 +58,18 @@ digest_t *digest_open_by_nid(int nid, int maclength) {
                return false;
        }
 
-       return digest_open(evp_md, maclength);
+       digest_open(digest, evp_md, maclength);
+       return true;
 }
 
 bool digest_set_key(digest_t *digest, const void *key, size_t len) {
-       digest->key = xrealloc(digest->key, len);
-       memcpy(digest->key, key, len);
-       digest->keylength = len;
+       digest->hmac_ctx = HMAC_CTX_new();
+       HMAC_Init_ex(digest->hmac_ctx, key, (int)len, digest->digest, NULL);
+
+       if(!digest->hmac_ctx) {
+               abort();
+       }
+
        return true;
 }
 
@@ -77,35 +78,43 @@ void digest_close(digest_t *digest) {
                return;
        }
 
-       free(digest->key);
-       free(digest);
+       if(digest->md_ctx) {
+               EVP_MD_CTX_destroy(digest->md_ctx);
+       }
+
+       if(digest->hmac_ctx) {
+               HMAC_CTX_free(digest->hmac_ctx);
+       }
+
+       memset(digest, 0, sizeof(*digest));
 }
 
 bool digest_create(digest_t *digest, const void *indata, size_t inlen, void *outdata) {
        size_t len = EVP_MD_size(digest->digest);
        unsigned char tmpdata[len];
 
-       if(digest->key) {
-               if(!HMAC(digest->digest, digest->key, digest->keylength, indata, inlen, tmpdata, NULL)) {
+       if(digest->hmac_ctx) {
+               if(!HMAC_Init_ex(digest->hmac_ctx, NULL, 0, NULL, NULL)
+                               || !HMAC_Update(digest->hmac_ctx, indata, inlen)
+                               || !HMAC_Final(digest->hmac_ctx, tmpdata, NULL)) {
                        logger(DEBUG_ALWAYS, LOG_DEBUG, "Error creating digest: %s", ERR_error_string(ERR_get_error(), NULL));
                        return false;
                }
        } else {
-               EVP_MD_CTX *ctx = EVP_MD_CTX_create();
+               if(!digest->md_ctx) {
+                       digest->md_ctx = EVP_MD_CTX_create();
+               }
 
-               if(!ctx) {
+               if(!digest->md_ctx) {
                        abort();
                }
 
-               if(!EVP_DigestInit(ctx, digest->digest)
-                               || !EVP_DigestUpdate(ctx, indata, inlen)
-                               || !EVP_DigestFinal(ctx, tmpdata, NULL)) {
+               if(!EVP_DigestInit(digest->md_ctx, digest->digest)
+                               || !EVP_DigestUpdate(digest->md_ctx, indata, inlen)
+                               || !EVP_DigestFinal(digest->md_ctx, tmpdata, NULL)) {
                        logger(DEBUG_ALWAYS, LOG_DEBUG, "Error creating digest: %s", ERR_error_string(ERR_get_error(), NULL));
-                       EVP_MD_CTX_destroy(ctx);
                        return false;
                }
-
-               EVP_MD_CTX_destroy(ctx);
        }
 
        memcpy(outdata, tmpdata, digest->maclength);