60 Commits
Author SHA1 Message Date
David Benjamin 815fec1839 Replace OPENSSL_ARRAY_SIZE with std::size
In the STL, <iterator> has a std::size for arrays. Some of these could
also just be ranged for loops. One static_assert could not use
std::size(out->whatever) because out was not a compile-time value, but
std::extent_v<decltype(out->whatever)> works instead.

Change-Id: I28007c79f5583e09167b81a34a447e205ee6dd9b
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/81658
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2025-08-28 12:22:59 -07:00
Adam Langley 8ef8f5838a Switch to using a derivation function in CTR-DRBG.
Upcoming NIST rule changes are expected to effectively require us to
pass in larger entropy inputs to the DRBG, which requires us to use the
"derivation function" option from 800-90A.

This change implements the derivation function and splits the entropy
and nonce arguments out, as needed for this style of DRBG.

Since we have external users of the existing CTR-DRBG mode, that is
still supported, but all internal uses will now use a derivation
function.

Change-Id: I8079e9f4c6238e91c68fef1e40189211f4142555
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/79768
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2025-08-13 11:36:32 -07:00
David Benjamin ea482ed0e7 Switch a bit more of libcrypto to scopers
There was no real organization to which files I looked at here. Mostly
just bounced around. At some point we'll probably need to set up some
more infrastructure though:

- For functions to return UniquePtr, they need to stop being C linkage,
  which is something we want to do anyway.

- For types to use UniquePtr, we need to get them out of malloc/free and
  into the realm of constructors and destructors. That probably means
  moving some of the helpers from ssl/internal.h to crypto/internal.h.

- UniquePtr is not very good at buffers. We should probably move Array
  Vector, and InPlaceVector to crypto/internal.h.

Change-Id: I90ebc917051d354c0e447598f382db6b22eb8813
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/78687
Auto-Submit: David Benjamin <davidben@google.com>
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2025-04-17 20:07:10 -07:00
Bob Beck 60ac01873b Pull SLH-DSA test out of BORINGSSL_self_check()
FIPS: this changes the entry point for running the self tests.

Change-Id: I1ddef5b05e68effd1290d5e4428c278fd43bc4f7
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/77927
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
Reviewed-by: Adam Langley <agl@google.com>
Auto-Submit: Bob Beck <bbe@google.com>
2025-03-25 11:33:28 -07:00
Bob Beck 9ba6410319 Make bcm use internal AES functions
This prevents problems davidben and I noticed with bcm reaching
out of the module for AES.

Change-Id: I95dc57e8735140ebc296aa005f08677ef24acbe3
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/77827
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
2025-03-20 00:11:39 -07:00
Adam Langley 704dc8deff Add SLH-DSA self tests
Change-Id: I411bf8c2501f91f28f31e0da7a18025e2a47d756
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/76389
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2025-03-03 16:56:12 -08:00
Adam Langley 3494965215 Add ML-DSA self tests.
Change-Id: I640b1f57de2544d9329cba83352d0d51debc092c
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/76388
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2025-03-03 16:07:04 -08:00
Adam Langley 5e73d0302c Add ML-KEM self-tests.
For some reason I had thought that NIST weren't doing this stuff for new
algorithms, but they are. The following quote is from IG 10.3.A:

> if the module implements ML-KEM decapsulation, the module shall have a CAST for the ML-KEM decapsulation mechanism. The decapsulation algorithm of ML-KEM accepts a decapsulation key (dk) and a ML-KEM ciphertext (c) as input, does not use any randomness, and outputs a shared secret (K’). The CAST shall use the ML-KEM decapsulation algorithm (i.e., Algorithm 21 in FIPS 203), and for a KAT, using fixed/predetermined dk and c values, to compare the resulting outputs to precomputed value of K'. Note21: The ML-KEM decapsulation CASTs shall cover both the implicit rejection and (unnamed) non-rejection paths.
>
> The above CASTs shall be performed on at least one of the following parameter-sets for MLKEM that are implemented in the approved mode: ML-KEM-512, ML-KEM-768, or ML-KEM-1024.
>
> if the module implements ML-KEM key generation, the module shall have an ML-KEM key generation CAST. The ML-KEM key generation does not take input and outputs an encapsulation key (ek) and a decapsulation key (dk). The CAST shall use the ML-KEM key generation algorithm (i.e., Algorithm 19 in FIPS 203), and for a KAT, using a fixed/predetermined random values (i.e., z and d), to compare the resulting outputs to the pre-computed values of ek and dk.
>
> For key pairs generated for use with approved KEMs in FIPS 203, the PCT (described by the tester in TE10.35.01) shall consist of applying the encapsulation key ek to encapsulate a shared secret K leading to ciphertext c, and then applying decapsulation key dk to retrieve the same shared secret K. The PCT passes if the two shared secret K values are equal.

Change-Id: Ic5704e1e59fb9876ce666a88518a37f61fd7d6b9
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/76387
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2025-03-03 16:02:03 -08:00
David Benjamin 33d1049b1f Switch the license to Apache 2.0, matching OpenSSL upstream
We use the standard Apache 2.0 file header, described in "APPENDIX: How
to apply the Apache License to your work."

This was primarily automated by running:

  git ls-tree -r --name-only HEAD | xargs go run ./util/relicense.go

See go/boringssl-relicensing-triage for the results of triaging the
output of the tool.

As part of this, switch from taking fiat-crypto under MIT license to
Apache 2.0. (It is licensed under MIT OR Apache-2.0 OR BSD-1-Clause.)

The copyright_summary tool can also be used to confirm we didn't
accidentally drop any copyright lines:

  # Run before the CL
  git grep -l Copyright | xargs go run ./util/copyright_summary.go  -out /tmp/old.json
  # Run after the CL
  git grep -l Copyright | xargs go run ./util/copyright_summary.go  -compare /tmp/old.json

Bug: 364634028
Change-Id: I17c50e761e9d077a1f92e25969e50ed35e320c59
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/75852
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2025-02-03 15:05:16 -08:00
David Benjamin 6f4159567d Start maintaining an AUTHORS file
Following the guidance in
https://opensource.google/documentation/reference/releasing/authors,
start maintaining an AUTHORS file.

Update all existing Google copyright lines to 'The BoringSSL Authors'
per the document. This CL also changes the styling to match the new
guidance: removed the '(c)' and the comma.

All other existing copyright lines are left unmodified. Going forward,
our preference will be that new contributions to BoringSSL use 'The
BoringSSL Authors', optionally adding to the AUTHORS file if the
contributor desires.

To avoid being presumptuous, this CL does *not* proactively list every
past contributor in the BoringSSL half of the AUTHORS file. Past
contributors are welcome to send us a patch to be added, or request that
we add you. (Listed or not, the commit log continues to be a more
accurate record, and any existing non-Google copyright lines were left
unmodified.)

The OpenSSL half of the AUTHORS file is seeded with the contents of the
current OpenSSL AUTHORS file, as of writing. The current contents in the
latest revision of the 1.1.1 branch
(b372b1f76450acdfed1e2301a39810146e28b02c) and master
(d992e8729ee38b082482dc010e090bb20d1c7bd5) are identical, just formatted
in text vs Markdown.

Note when reviewing: CONTRIBUTING.md and AUTHORS contain non-mechanical
changes.

Bug: 364634028
Change-Id: I319d0ee63ec021ad85e248e8e3304b9cf9566681
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/74149
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2024-12-11 13:52:41 -08:00
Adam Langley 5813c2c10c crypto: switch to C++
This change switches nearly all of BoringSSL to use C++. The public
functions still use the C ABI, and so code written in C can still use
BoringSSL. Also the use of the C++ standard library is minimal and no
run-time requirement for it is intended.

Change-Id: I902d2f51a3c8d6bd0dc4aabe1b192a15d7b788e8
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/72747
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: Bob Beck <bbe@google.com>
2024-11-26 21:10:44 +00:00
David Benjamin 5cce3fbd23 Build with -Wextra-semi in Clang
This would have caught
https://boringssl-review.googlesource.com/c/boringssl/+/73029

The other instances didn't break because Chromium builds our fuzzers
(and thus our headers) with stricter warnings than our source files.
Probably worth being consistent there, but meanwhile go ahead and turn
on this warning.

Change-Id: I0cff2648f25a0d7f87de6a27f4af6ea891fff663
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/73267
Commit-Queue: Bob Beck <bbe@google.com>
Auto-Submit: David Benjamin <davidben@google.com>
Reviewed-by: Bob Beck <bbe@google.com>
2024-11-20 19:54:46 +00:00
Adam Langley 453207b73e Have modulewrapper print more of its build environment.
It's useful for auditing purposes if modulewrapper can print information
about the FIPS module within it. Also, we have a function,
`CRYPTO_has_asm`, which reports whether assembly code is enabled or not.
But that function wasn't implemented within the FIPS module and thus
it reported the condition of libcrypto instead. This change moves it into
the FIPS module so that it reports the condition there, which is what we
care about.

Change-Id: I66ac8936c6d8dd7b5260ec7a68405d58a63990fb
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/72327
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
Auto-Submit: Adam Langley <agl@google.com>
2024-10-23 00:24:31 +00:00
David Benjamin f8cadd8974 Indirect stderr through a function
This is the only instance of BCM consuming a non-code external symbol.

Bug: 362530616
Change-Id: Iefc555092c5278e9b3c3c9d894a2bc84ecb9d875
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/70847
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2024-10-02 20:03:47 +00:00
David Benjamin a89348cd05 Fix some missing includes in BCM
These were getting by because bcm.c #includes everything together.

Change-Id: I1eb4aad891f0051c4f869202c6554f5864cd3a76
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/70810
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2024-09-03 23:24:02 +00:00
David Benjamin 3a138e4369 Rename bcm.c fragments to foo.c.inc
Having the files named .c but included causes a ton of problems with
build systems. Many of our build systems care about three categories of
files:

- public headers, available to downstream targets
- source files, each of which is compiled as a compilation unit
- internal headers, not available to downstream targets

There is usually a check, in Bazel called layering_check that enforces
source files only include headers that are declared somewhere
appropriate. The bcm.c fragments, under this classification, are
internal headers.

However, in both GN and Bazel, internal headers and sources
both go in the source list. They are distinguished only by file
extension. When FIPS fragments have a .c file extension, they are
misinterpreted as source files, and many things break.

Rename them. Either .h and .inc would be sufficient. Because we had to
disable Bazel's parse_headers feature, there is no difference (AFAICT)
in their handling. Also, these files actually pass the parse_headers
feature, even though they don't have an include guard. Still, the tech
of the style guide suggests that .inc is probably the better file
extension.

https://google.github.io/styleguide/cppguide.html#Self_contained_Headers

I used .c.inc rather than plain .inc so that we can easily
rename them back to .c when we solve https://crbug.com/362530616.

Note that, as .inc is not as common of a file extension, people working
on BoringSSL may need to reconfigure their editors to map .inc to C/C++.

Update-Note: Some downstream builds have been working around this by
building the fragments individually and excluding bcm.c. This change
will break those workarounds but also remove the need for it. It should
now be consistently possible to build BoringSSL without modifying the
file list.

Bug: 362664827
Change-Id: I933115c37843317a066e24a1092728c9afce35f5
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/70689
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
2024-08-29 18:33:42 +00:00
David Benjamin d520396e55 Move ECDSA_SIG out of BCM
This CL adjusts the libcrypto <-> BCM ECDSA interface. Previously, we
used ECDSA_do_sign and ECDSA_do_verify. This meant we have an allocated
BIGNUM-based type (ECDSA_SIG) at the boundary.

Instead use the fixed-width P1363 format at the boundary, which is nice
and straightforward. For now, I haven't exported it out of anything,
though we do have some things (Channel ID, WebCrypto) which actually
want this format, so that may be worth revisiting later.

Bug: 42290602
Change-Id: Ifbe0600fd23addc5f05141d18baad21a669ceca8
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/66829
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
Auto-Submit: David Benjamin <davidben@google.com>
2024-08-26 17:11:38 +00:00
David Benjamin afd52e91df Fix some enum issues in the test-only BORINGSSL_FIPS_COUNTERS build
This fixes b/342634459.

enums are weird. They're neither tight sum types, nor ints with
designated values but something in between.

By default (i.e. if you do not say `enum Foo : int`, which isn't in C
until very new versions), an enum's range of valid values is the
smallest hypothetical-bit-width signed or unsigned integer that can fit
all the values. So, the following enum can only hold 0, 1, 2, or 3, and
all values outside that range are UB.

  enum E {
    A = 0,
    B = 2,
  }

Meanwhile, enum is signed and can hold values -2, -1, 0, 1:

  enum E {
    A = -1,
    B = 1,
  }

This is incredibly bizarre. This has two consequences. First, clang
emits a warning like the following:

.../boringssl/crypto/fipsmodule/self_check/fips.c:75:15: error: result of comparison of unsigned enum expression < 0 is always false [-Werror,-Wtautological-unsigned-enum-zero
-compare]
   75 |   if (counter < 0 || counter > fips_counter_max) {
      |       ~~~~~~~ ^ ~

Second, this loop over enum values in the unit test trips UBSan.

[----------] 1 test from CryptoTest
[ RUN      ] CryptoTest.FIPSCountersEVP_AEAD
.../boringssl/crypto/crypto_test.cc:51:8: runtime error: load of value 4, which is not a valid value for type 'fips_counter_t'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior /usr/local/google/home/davidben/boringssl/crypto/crypto_test.cc:51:8

To avoid this, just do our arithemetic in integer space and only move to
enums at the edges.

Change-Id: Icbd0e41604ce2aa67be8d394b03c7de50062199c
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/68768
Commit-Queue: David Benjamin <davidben@google.com>
Auto-Submit: David Benjamin <davidben@google.com>
Reviewed-by: Bob Beck <bbe@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2024-05-24 21:44:57 +00:00
David Benjamin dd68e4bb4d Add OPENSSL_zalloc
OpenSSL added a similar helper function. It's very, very common for us
to malloc something an then zero it. This saves some effort. Also
replace some more malloc + memcpy pairs with memdup.

Change-Id: I1e765c8774a0d15742827c39a1f16df9748ef247
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/63345
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
Auto-Submit: David Benjamin <davidben@google.com>
2023-10-05 18:38:27 +00:00
Adam Langley 7ae2b910c1 Split TLS 1.0 and 1.2 self checks.
While it's the same code path, NIST may consider these different
functions and thus want separate checks for them.

Change-Id: Ic391b5e656b22c5e11d94ec22398346669833bd9
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/62087
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2023-08-02 00:14:47 +00:00
David Benjamin 70be01270b Use constant curve-specific groups whenever possible
Also remove unnecessary EC_GROUP_free calls. EC_GROUP_free is only
necessary in codepaths where arbitrary groups are possible.

Bug: 20
Change-Id: I3dfb7f07b890ab002ba8a302724d8bc671590cfe
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/60932
Reviewed-by: Bob Beck <bbe@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2023-07-11 20:07:57 +00:00
David Benjamin a0afd6ae2c Add some missing includes
When building BCM sources individually, this gets missed.

Change-Id: I58858da441daaeffc5e54b653f5436fe817c4178
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/59306
Auto-Submit: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2023-04-26 02:31:44 +00:00
Adam Langley 480344d4fa Move TLS 1.3 KDF functions into the FIPS module.
Change-Id: I32a40a73f96e029ac9096af826d15b22d9dcad28
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/58745
Auto-Submit: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2023-04-17 16:39:03 +00:00
Adam Langley d3acd45456 Move HKDF into the FIPS module.
Change-Id: I7c5b0a24c26b83779cf889d890e2c18ae13187c3
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/58725
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2023-04-14 22:58:17 +00:00
hehe.li 785bb12634 Disable blinding for boringssl_self_test_rsa().
Disable blinding for boringssl_self_test_rsa() to avoid an entropy draw like
the 'k' value for ECDSA is fixed to avoid an entropy draw in boringssl_self_test_ecc().

The boringssl_self_test_rsa() use entropy to generate the blinding factor and
the inverse of blinding factor. Running boringssl_self_test_rsa() from init stage of OS
on some devices as the kernel's entropy pool is not yet initialized, causing the process
to block for seconds.

Bug: None
Change-Id: I4c1119c9950553eec030bedf36ec22ab41088f20
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/55545
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2022-12-08 23:11:03 +00:00
Adam Langley 24c01865dc Expose the CTR_DRBG API.
Change-Id: Ie071dcd94d2ae8aa8ee148682f9b0054ed9e3501
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/52445
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2022-07-26 21:25:34 +00:00
Adam Langley 118a892d2d Add a service indicator for FIPS 140-3.
This is cribbed, with perimssion, from AWS-LC. The FIPS service
indicator[1] signals when an approved service has been completed.

[1] FIPS 140-3 IG 2.4.C

Change-Id: Ib40210d69b3823f4d2a500b23a1606f8d6942f81
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/52568
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2022-05-23 23:37:16 +00:00
Adam Langley a56d941c44 Add function to return the name of the FIPS module.
Change-Id: I3eab2393d4fe48c900d67240c7decf223d78c2f1
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/52425
Commit-Queue: Bob Beck <bbe@google.com>
Reviewed-by: Bob Beck <bbe@google.com>
2022-05-05 14:26:18 +00:00
Adam Langley c6e8f3ed08 Add a function to return a FIPS version.
We need a function that returns a version that links to a certificate.
Previously we have used the git hash as the version of our modules but
the source cannot contain its own hash. Thus this change defines a new
format for FIPS module versions which will be filled in once we're ready
to define a version.

Change-Id: Ie4641945119106bc47e8da94ed8a45a86abb6f92
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51986
Reviewed-by: David Benjamin <davidben@google.com>
2022-03-21 19:31:37 +00:00
Adam Langley 7f4057ec10 Add a function to tell if an algorithm is FIPS approved.
Change-Id: I934376ead1bc3e4e8349540c4a3da99cd0b49181
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51985
Reviewed-by: David Benjamin <davidben@google.com>
2022-03-21 19:31:15 +00:00
Adam Langley d258de7248 Include rsa/internal.h for |...no_self_test| functions.
Change-Id: I9aac529f181068746c5099ad08b6471887184202
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51725
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2022-03-08 15:08:44 +00:00
Adam Langley 4b55af0fc5 Make FFDH self tests lazy.
Change-Id: I7ac046a2422d79b77a231ab65325402658144390
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51566
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-25 18:01:54 +00:00
Adam Langley 3053b739ba Make ECC self tests lazy.
Change-Id: I1b7e4bd5403031232fc1e1ffb3c6e40decac23b9
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51565
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-25 18:01:46 +00:00
Adam Langley 1c2e61efef Make RSA self-test lazy.
We need to ensure that all public functions that end up doing a
cryptographic RSA operation run the self-tests first. We could do that
by putting calls in the lower-most functions but the self-tests must run
operations without creating a cycle. Therefore calls are placed as low
down as possible except where it would conflict with the self-tests.
Some functions need to be split so that there's a private version that
doesn't require that the self tests have passed.

Here's the call-graph that I used for this:

                   ┌───────────────────────────┐
                   │      private_decrypt      │
                   └───────────────────────────┘
                     │
                     │
                     ▼
                   ┌───────────────────────────┐
                   │          decrypt          │
                   └───────────────────────────┘
                     │
                     │
                     ▼
                   ┌───────────────────────────┐
                   │      default_decrypt      │
                   └───────────────────────────┘
                     │
                     │
                     ▼
                   ┌───────────────────────────┐
                   │     private_transform     │   ◀┐
                   └───────────────────────────┘    │
                     │                              │
                     │                              │
                     ▼                              │
                   ┌───────────────────────────┐    │
                   │ default_private_transform │    │
                   └───────────────────────────┘    │
                   ┌───────────────────────────┐    │
                   │      private_encrypt      │    │
                   └───────────────────────────┘    │
  ┌───────────────┐  │                              │
  │ sign_pss_mgf1 │  │                              │
  └───────────────┘\ ▼                              │
  ┌────────┐       ┌───────────────────────────┐    │
  │  sign  │ ──▶   │         sign_raw          │    │
  └────────┘       └───────────────────────────┘    │
                     │                              │
                     │                              │
                     ▼                              │
                   ┌───────────────────────────┐    │
                   │     default_sign_raw      │   ─┘
                   └───────────────────────────┘
                 ┌−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−┐
                 ╎         Verification          ╎
                 ╎                               ╎
                 ╎ ┌───────────────────────────┐ ╎
                 ╎ │      public_decrypt       │ ╎
                 ╎ └───────────────────────────┘ ╎
                 ╎   │                           ╎
                 ╎   │                           ╎
                 ╎   │                           ╎
┌−−−−−−−−−−−−−−−−    │                           ╎
╎                    ▼                           ╎
╎ ┌────────┐       ┌───────────────────────────┐ ╎
╎ │ verify │ ────▶ │        verify_raw         │ ╎
╎ └────────┘       └───────────────────────────┘ ╎
╎                                                ╎
└−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−┘
                 ┌−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−┐
                 ╎          Encryption           ╎
                 ╎                               ╎
                 ╎ ┌───────────────────────────┐ ╎
                 ╎ │      public_encrypt       │ ╎
                 ╎ └───────────────────────────┘ ╎
                 ╎   │                           ╎
                 ╎   │                           ╎
                 ╎   ▼                           ╎
                 ╎ ┌───────────────────────────┐ ╎
                 ╎ │          encrypt          │ ╎
                 ╎ └───────────────────────────┘ ╎
                 ╎                               ╎
                 └−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−┘

Speed difference looks to be in the noise.

Before:

Did 19716 RSA 2048 signing operations in 10050000us (1961.8 ops/sec)
Did 712000 RSA 2048 verify (same key) operations in 10007156us (71149.1 ops/sec)
Did 590000 RSA 2048 verify (fresh key) operations in 10004296us (58974.7 ops/sec)
Did 101866 RSA 2048 private key parse operations in 10090285us (10095.5 ops/sec)
Did 2919 RSA 4096 signing operations in 10019359us (291.3 ops/sec)
Did 203000 RSA 4096 verify (same key) operations in 10008421us (20282.9 ops/sec)
Did 175000 RSA 4096 verify (fresh key) operations in 10026353us (17454.0 ops/sec)
Did 30900 RSA 4096 private key parse operations in 10090073us (3062.4 ops/sec)

After:

Did 19525 RSA 2048 signing operations in 10000499us (1952.4 ops/sec)
Did 706000 RSA 2048 verify (same key) operations in 10002172us (70584.7 ops/sec)
Did 588000 RSA 2048 verify (fresh key) operations in 10010856us (58736.2 ops/sec)
Did 101864 RSA 2048 private key parse operations in 10063474us (10122.2 ops/sec)
Did 2919 RSA 4096 signing operations in 10037480us (290.8 ops/sec)
Did 203000 RSA 4096 verify (same key) operations in 10026966us (20245.4 ops/sec)
Did 175000 RSA 4096 verify (fresh key) operations in 10032281us (17443.7 ops/sec)
Did 31416 RSA 4096 private key parse operations in 10031047us (3131.9 ops/sec)

Change-Id: I8dec8a33066717b7078f160e3f93c33cd354bb0c
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51426
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-19 13:08:10 +00:00
Adam Langley 8f7cb2f7c6 Drop, now unused, KAT value.
Change-Id: Ief328bb2a8b6264226a89233c9fba0e4621de9d7
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51425
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2022-02-15 21:54:26 +00:00
Adam Langley d04c32a3d8 Break FIPS tests differently.
FIPS validation requires showing that the continuous and start-up tests
are effective by breaking them. Traditionally BoringSSL used #defines
that tweaked the expected values. However, 140-3 now requires that the
inputs be changed, not the expected outputs.

Also, the number of tests is going to increase. Since slower platforms
already took too long to compile BoringSSL n times (once for each test
to break) we want something faster too.

Therefore all the known-answer tests (KATs) are changed such that a Go
program can find and replace the input value in order to break them.
Thus we only need to recompile once to disable the integrity test.

The runtime tests still need a #define to break, but that #define is now
put in a header file so that only the module need be recompiled, not
everything as in the previous system.

Change-Id: Ib621198e6ad02253e29af0ccd978e3c3830ad54c
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51329
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2022-02-15 19:57:20 +00:00
Adam Langley f8235e4993 Don't forget hmac.h in self_check.h.
Builds that compile the FIPS stuff separately don't get this header from
other files.

Change-Id: I8a1b30ae360b08d4f4b9f804cd234998889477bc
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51405
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2022-02-15 15:57:46 +00:00
Adam Langley 9cad13eea1 Perform SHA-$x and HMAC KAT before integrity check.
AS10.20 requires that the self-test for the integrity algorithm pass
before the integrity check itself. IG 10.3.A requires an HMAC self-test
now. Therefore run these tests before the integrity check.

Since we also need the ability to run all self-tests, both SHA
self-tests and the HMAC test are run again when running self-tests.
I'm assuming that they're so fast that it doesn't matter.

Change-Id: I6b23b6fd3cb6107edd7420bc8680780719bd41d2
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51328
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-14 21:08:12 +00:00
Adam Langley b0ed28e257 Add a couple of spaces to check_test.
The word “calculated” is two letters longer than “expected” and it's
nice to line up the ouptuts.

Change-Id: Idac70e62d98fbe26c430f03f4643ba295e40853d
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51327
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-14 21:04:24 +00:00
Adam Langley 15565a8984 Split FIPS KATs into fast and slow groups.
The provision of FIPS that allowed the tests to be skipped based on a
flag-file has been removed in 140-3. Therefore we expect to run the fast
KATs on start-up, but to defer to slower ones until the functionality in
question is first used. So this change splits off the fast KATs and
removes support for skipping KATs based on a flag-file.

Change-Id: Ib24cb1739cfef93e4a1349d786a0257ee1083cfb
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51326
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-14 21:04:09 +00:00
Adam Langley a919539777 Move DES out of the FIPS module.
FIPS no longer likes it.

Change-Id: I32a4ba93a5849927ff75aa72b816cdc669e8a0af
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/51325
Reviewed-by: David Benjamin <davidben@google.com>
2022-02-14 21:01:14 +00:00
David Benjamin 91b8924969 Switch kModuleDigestSize to a macro.
Although the compiler will hopefully optimize it out, this is
technically a VLA. The new Android NDK now warns about this.

Change-Id: Ib9f38dc73c40e90ab61105f29a635c453f1477a1
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/50185
Commit-Queue: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2021-10-27 18:20:39 +00:00
Adam Langley 4aef687fcf Zero out FIPS counters.
MSAN doesn't like the counters starting at whatever value malloc
found to be free.

Change-Id: I0968e61e0025db35b82291fde5d1e193aef77c1e
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/46444
Commit-Queue: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2021-03-29 21:03:11 +00:00
Bradley Hess b09f283a03 Add a Windows no-op impl of BORINGSSL_self_test
Change-Id: Id5b5b639023d30a8ebd763d02e1787fbf9d79288
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/46245
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2021-03-18 17:18:44 +00:00
David Benjamin fb855a28fe Move fips.c into a subdirectory.
The build scripts distinguish between normal files and bcm.c fragments
based on whether code is in a subdirectory inside crypto/fipsmodule.

Bug: 401
Change-Id: Ieba88178e4f8e19f020e56e2567d5736a34bb43f
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/46224
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
2021-03-17 16:40:27 +00:00
David Benjamin 409ea2837d Add ECDSA nonce-testing functions.
There are a few places where it is useful to run ECDSA with a specified
nonce:

- An ECDSA KAT in the module self-check

- Unit tests for particular test vectors

- Fuzzing the implementation (requested by the cryptofuzz project)

This replaces the fixed_k machinery with a separate function. Although
they are effectively the same, I've used two different functions.
One is internal and only used in the module self-check. The other is
exported for unit tests and cryptofuzz but marked with a for_testing.
(Chromium's presubmits flag uses of "for_testing" functions outside of
unit tests. The KAT version isn't in a test per se, so it's a separate
function.)

Bug: 391
Change-Id: I0f764d89bf0ac2081307e1079623d508fb0f2df7
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45867
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2021-02-25 22:43:53 +00:00
Adam Langley 48cbd69dee Add various function calls to test_fips.
test_fips probably needs to exercise everything that we have self-tests
for.

(The following change will eliminate the duplication of the code to
create the FFDH group. For reasons, that can't be done in this change.)

Change-Id: Ia72064db77381e7cf396a34b4723b2607f26f00b
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45404
Reviewed-by: Adam Langley <alangley@gmail.com>
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
2021-02-04 17:40:21 +00:00
David Benjamin bb43a45d6d Add missing include to self_check.c.
This fixes the build for folks not using bcm.c.

Change-Id: I47935d8af7cb5a12ff2918ee2a8774182681d930
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45384
Commit-Queue: David Benjamin <davidben@google.com>
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: Adam Langley <agl@google.com>
2021-02-02 21:34:40 +00:00
Adam Langley 5cf02188fe Add FFDH FIPS self-test.
This invovles a |2048|^|225| modexp, which is far from ideal, but is now
required in FIPS mode.

Change-Id: Id7384b4ba92aa74e971231bc44fa0f10434d18e2
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45085
Commit-Queue: Adam Langley <agl@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2021-01-27 22:48:11 +00:00
Adam Langley 9dae0ac4f0 Add digest.h to self_check.c
This covers the use of EVP_sha256() added in 8846533744.

Change-Id: I8cd4c8e271de6a0b9a926e7186c7b24ffe849d67
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/44224
Commit-Queue: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
2020-11-30 20:06:59 +00:00