#ifndef _KERNELOBJECT_H
#define _KERNELOBJECT_H
#ifdef __cplusplus
extern "C" {
#endif
#include <security/pkcs11t.h>
#include "kernelSession.h"
#include "kernelSlot.h"
#define KERNELTOKEN_OBJECT_MAGIC 0xECF0B003
#define KERNEL_CREATE_OBJ 1
#define KERNEL_GEN_KEY 2
#define RSA_PRI_ATTR_COUNT 7
#define RSA_PUB_ATTR_COUNT 3
#define DSA_ATTR_COUNT 4
#define EC_ATTR_COUNT 2
typedef struct secret_key_obj {
CK_BYTE *sk_value;
CK_ULONG sk_value_len;
} secret_key_obj_t;
typedef struct attribute_info {
CK_ATTRIBUTE attr;
struct attribute_info *next;
} attribute_info_t;
typedef attribute_info_t *CK_ATTRIBUTE_INFO_PTR;
typedef struct biginteger {
CK_BYTE *big_value;
CK_ULONG big_value_len;
} biginteger_t;
typedef struct rsa_pub_key {
biginteger_t modulus;
CK_ULONG modulus_bits;
biginteger_t pub_exponent;
} rsa_pub_key_t;
typedef struct dsa_pub_key {
biginteger_t prime;
biginteger_t subprime;
biginteger_t base;
biginteger_t value;
} dsa_pub_key_t;
typedef struct dh_pub_key {
biginteger_t prime;
biginteger_t base;
biginteger_t value;
} dh_pub_key_t;
typedef struct ec_pub_key {
biginteger_t point;
} ec_pub_key_t;
typedef struct public_key_obj {
union {
rsa_pub_key_t rsa_pub_key;
dsa_pub_key_t dsa_pub_key;
dh_pub_key_t dh_pub_key;
ec_pub_key_t ec_pub_key;
} key_type_u;
} public_key_obj_t;
typedef struct rsa_pri_key {
biginteger_t modulus;
biginteger_t pub_exponent;
biginteger_t pri_exponent;
biginteger_t prime_1;
biginteger_t prime_2;
biginteger_t exponent_1;
biginteger_t exponent_2;
biginteger_t coefficient;
} rsa_pri_key_t;
typedef struct dsa_pri_key {
biginteger_t prime;
biginteger_t subprime;
biginteger_t base;
biginteger_t value;
} dsa_pri_key_t;
typedef struct dh_pri_key {
biginteger_t prime;
biginteger_t base;
biginteger_t value;
CK_ULONG value_bits;
} dh_pri_key_t;
typedef struct ec_pri_key {
biginteger_t value;
} ec_pri_key_t;
typedef struct private_key_obj {
union {
rsa_pri_key_t rsa_pri_key;
dsa_pri_key_t dsa_pri_key;
dh_pri_key_t dh_pri_key;
ec_pri_key_t ec_pri_key;
} key_type_u;
} private_key_obj_t;
typedef struct object {
boolean_t is_lib_obj;
crypto_object_id_t k_handle;
CK_OBJECT_CLASS class;
CK_KEY_TYPE key_type;
CK_ULONG magic_marker;
uint64_t bool_attr_mask;
CK_MECHANISM_TYPE mechanism;
pthread_mutex_t object_mutex;
struct object *next;
struct object *prev;
CK_ATTRIBUTE_INFO_PTR extra_attrlistp;
CK_ULONG extra_attrcount;
union {
secret_key_obj_t *secret_key;
public_key_obj_t *public_key;
private_key_obj_t *private_key;
} object_class_u;
CK_SESSION_HANDLE session_handle;
uint32_t obj_refcnt;
pthread_cond_t obj_free_cond;
uint32_t obj_delete_sync;
} kernel_object_t;
typedef struct find_context {
kernel_object_t **objs_found;
CK_ULONG num_results;
CK_ULONG next_result_index;
} find_context_t;
#define MAX_OBJ_TO_BE_FREED 300
typedef struct obj_to_be_freed_list {
kernel_object_t *first;
kernel_object_t *last;
uint32_t count;
pthread_mutex_t obj_to_be_free_mutex;
} object_to_be_freed_list_t;
extern object_to_be_freed_list_t obj_delay_freed;
#define OBJ_SEC(o) \
(o->object_class_u.secret_key)
#define OBJ_SEC_VALUE(o) \
(o->object_class_u.secret_key->sk_value)
#define OBJ_SEC_VALUE_LEN(o) \
(o->object_class_u.secret_key->sk_value_len)
#define OBJ_PUB(o) \
((o)->object_class_u.public_key)
#define KEY_PUB_RSA(k) \
&((k)->key_type_u.rsa_pub_key)
#define OBJ_PUB_RSA_MOD(o) \
&((o)->object_class_u.public_key->key_type_u.rsa_pub_key.modulus)
#define KEY_PUB_RSA_MOD(k) \
&((k)->key_type_u.rsa_pub_key.modulus)
#define OBJ_PUB_RSA_PUBEXPO(o) \
&((o)->object_class_u.public_key->key_type_u.rsa_pub_key.pub_exponent)
#define KEY_PUB_RSA_PUBEXPO(k) \
&((k)->key_type_u.rsa_pub_key.pub_exponent)
#define OBJ_PUB_RSA_MOD_BITS(o) \
((o)->object_class_u.public_key->key_type_u.rsa_pub_key.modulus_bits)
#define KEY_PUB_RSA_MOD_BITS(k) \
((k)->key_type_u.rsa_pub_key.modulus_bits)
#define KEY_PUB_DSA(k) \
&((k)->key_type_u.dsa_pub_key)
#define OBJ_PUB_DSA_PRIME(o) \
&((o)->object_class_u.public_key->key_type_u.dsa_pub_key.prime)
#define KEY_PUB_DSA_PRIME(k) \
&((k)->key_type_u.dsa_pub_key.prime)
#define OBJ_PUB_DSA_SUBPRIME(o) \
&((o)->object_class_u.public_key->key_type_u.dsa_pub_key.subprime)
#define KEY_PUB_DSA_SUBPRIME(k) \
&((k)->key_type_u.dsa_pub_key.subprime)
#define OBJ_PUB_DSA_BASE(o) \
&((o)->object_class_u.public_key->key_type_u.dsa_pub_key.base)
#define KEY_PUB_DSA_BASE(k) \
&((k)->key_type_u.dsa_pub_key.base)
#define OBJ_PUB_DSA_VALUE(o) \
&((o)->object_class_u.public_key->key_type_u.dsa_pub_key.value)
#define KEY_PUB_DSA_VALUE(k) \
&((k)->key_type_u.dsa_pub_key.value)
#define KEY_PUB_DH(k) \
&((k)->key_type_u.dh_pub_key)
#define OBJ_PUB_DH_PRIME(o) \
&((o)->object_class_u.public_key->key_type_u.dh_pub_key.prime)
#define KEY_PUB_DH_PRIME(k) \
&((k)->key_type_u.dh_pub_key.prime)
#define OBJ_PUB_DH_BASE(o) \
&((o)->object_class_u.public_key->key_type_u.dh_pub_key.base)
#define KEY_PUB_DH_BASE(k) \
&((k)->key_type_u.dh_pub_key.base)
#define OBJ_PUB_DH_VALUE(o) \
&((o)->object_class_u.public_key->key_type_u.dh_pub_key.value)
#define KEY_PUB_DH_VALUE(k) \
&((k)->key_type_u.dh_pub_key.value)
#define OBJ_PUB_EC_POINT(o) \
&((o)->object_class_u.public_key->key_type_u.ec_pub_key.point)
#define KEY_PUB_EC_POINT(k) \
&((k)->key_type_u.ec_pub_key.point)
#define OBJ_PRI(o) \
((o)->object_class_u.private_key)
#define KEY_PRI_RSA(k) \
&((k)->key_type_u.rsa_pri_key)
#define OBJ_PRI_RSA_MOD(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.modulus)
#define KEY_PRI_RSA_MOD(k) \
&((k)->key_type_u.rsa_pri_key.modulus)
#define OBJ_PRI_RSA_PUBEXPO(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.pub_exponent)
#define KEY_PRI_RSA_PUBEXPO(k) \
&((k)->key_type_u.rsa_pri_key.pub_exponent)
#define OBJ_PRI_RSA_PRIEXPO(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.pri_exponent)
#define KEY_PRI_RSA_PRIEXPO(k) \
&((k)->key_type_u.rsa_pri_key.pri_exponent)
#define OBJ_PRI_RSA_PRIME1(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.prime_1)
#define KEY_PRI_RSA_PRIME1(k) \
&((k)->key_type_u.rsa_pri_key.prime_1)
#define OBJ_PRI_RSA_PRIME2(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.prime_2)
#define KEY_PRI_RSA_PRIME2(k) \
&((k)->key_type_u.rsa_pri_key.prime_2)
#define OBJ_PRI_RSA_EXPO1(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.exponent_1)
#define KEY_PRI_RSA_EXPO1(k) \
&((k)->key_type_u.rsa_pri_key.exponent_1)
#define OBJ_PRI_RSA_EXPO2(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.exponent_2)
#define KEY_PRI_RSA_EXPO2(k) \
&((k)->key_type_u.rsa_pri_key.exponent_2)
#define OBJ_PRI_RSA_COEF(o) \
&((o)->object_class_u.private_key->key_type_u.rsa_pri_key.coefficient)
#define KEY_PRI_RSA_COEF(k) \
&((k)->key_type_u.rsa_pri_key.coefficient)
#define KEY_PRI_DSA(k) \
&((k)->key_type_u.dsa_pri_key)
#define OBJ_PRI_DSA_PRIME(o) \
&((o)->object_class_u.private_key->key_type_u.dsa_pri_key.prime)
#define KEY_PRI_DSA_PRIME(k) \
&((k)->key_type_u.dsa_pri_key.prime)
#define OBJ_PRI_DSA_SUBPRIME(o) \
&((o)->object_class_u.private_key->key_type_u.dsa_pri_key.subprime)
#define KEY_PRI_DSA_SUBPRIME(k) \
&((k)->key_type_u.dsa_pri_key.subprime)
#define OBJ_PRI_DSA_BASE(o) \
&((o)->object_class_u.private_key->key_type_u.dsa_pri_key.base)
#define KEY_PRI_DSA_BASE(k) \
&((k)->key_type_u.dsa_pri_key.base)
#define OBJ_PRI_DSA_VALUE(o) \
&((o)->object_class_u.private_key->key_type_u.dsa_pri_key.value)
#define KEY_PRI_DSA_VALUE(k) \
&((k)->key_type_u.dsa_pri_key.value)
#define KEY_PRI_DH(k) \
&((k)->key_type_u.dh_pri_key)
#define OBJ_PRI_DH_PRIME(o) \
&((o)->object_class_u.private_key->key_type_u.dh_pri_key.prime)
#define KEY_PRI_DH_PRIME(k) \
&((k)->key_type_u.dh_pri_key.prime)
#define OBJ_PRI_DH_BASE(o) \
&((o)->object_class_u.private_key->key_type_u.dh_pri_key.base)
#define KEY_PRI_DH_BASE(k) \
&((k)->key_type_u.dh_pri_key.base)
#define OBJ_PRI_DH_VALUE(o) \
&((o)->object_class_u.private_key->key_type_u.dh_pri_key.value)
#define KEY_PRI_DH_VALUE(k) \
&((k)->key_type_u.dh_pri_key.value)
#define OBJ_PRI_DH_VAL_BITS(o) \
((o)->object_class_u.private_key->key_type_u.dh_pri_key.value_bits)
#define KEY_PRI_DH_VAL_BITS(k) \
((k)->key_type_u.dh_pri_key.value_bits)
#define OBJ_PRI_EC_VALUE(o) \
&((o)->object_class_u.private_key->key_type_u.ec_pri_key.value)
#define KEY_PRI_EC_VALUE(k) \
&((k)->key_type_u.ec_pri_key.value)
#define DERIVE_BOOL_ON 0x00000001
#define LOCAL_BOOL_ON 0x00000002
#define SENSITIVE_BOOL_ON 0x00000004
#define SECONDARY_AUTH_BOOL_ON 0x00000008
#define ENCRYPT_BOOL_ON 0x00000010
#define DECRYPT_BOOL_ON 0x00000020
#define SIGN_BOOL_ON 0x00000040
#define SIGN_RECOVER_BOOL_ON 0x00000080
#define VERIFY_BOOL_ON 0x00000100
#define VERIFY_RECOVER_BOOL_ON 0x00000200
#define WRAP_BOOL_ON 0x00000400
#define UNWRAP_BOOL_ON 0x00000800
#define TRUSTED_BOOL_ON 0x00001000
#define EXTRACTABLE_BOOL_ON 0x00002000
#define ALWAYS_SENSITIVE_BOOL_ON 0x00004000
#define NEVER_EXTRACTABLE_BOOL_ON 0x00008000
#define PRIVATE_BOOL_ON 0x00010000
#define TOKEN_BOOL_ON 0x00020000
#define MODIFIABLE_BOOL_ON 0x00040000
#define SECRET_KEY_DEFAULT (ENCRYPT_BOOL_ON|\
DECRYPT_BOOL_ON|\
SIGN_BOOL_ON|\
VERIFY_BOOL_ON|\
WRAP_BOOL_ON|\
UNWRAP_BOOL_ON|\
EXTRACTABLE_BOOL_ON|\
MODIFIABLE_BOOL_ON)
#define PUBLIC_KEY_DEFAULT (ENCRYPT_BOOL_ON|\
WRAP_BOOL_ON|\
VERIFY_BOOL_ON|\
VERIFY_RECOVER_BOOL_ON|\
MODIFIABLE_BOOL_ON)
#define PRIVATE_KEY_DEFAULT (DECRYPT_BOOL_ON|\
UNWRAP_BOOL_ON|\
SIGN_BOOL_ON|\
SIGN_RECOVER_BOOL_ON|\
EXTRACTABLE_BOOL_ON|\
MODIFIABLE_BOOL_ON)
#define OBJECT_IS_DELETING 1
#define OBJECT_REFCNT_WAITING 2
#define HANDLE2OBJECT_COMMON(hObject, object_p, rv, REFCNT_CODE) { \
object_p = (kernel_object_t *)(hObject); \
if ((object_p == NULL) || \
(object_p->magic_marker != KERNELTOKEN_OBJECT_MAGIC)) {\
rv = CKR_OBJECT_HANDLE_INVALID; \
} else { \
(void) pthread_mutex_lock(&object_p->object_mutex); \
if (!(object_p->obj_delete_sync & OBJECT_IS_DELETING)) { \
REFCNT_CODE; \
rv = CKR_OK; \
} else { \
rv = CKR_OBJECT_HANDLE_INVALID; \
} \
(void) pthread_mutex_unlock(&object_p->object_mutex); \
} \
}
#define HANDLE2OBJECT(hObject, object_p, rv) \
HANDLE2OBJECT_COMMON(hObject, object_p, rv, object_p->obj_refcnt++)
#define HANDLE2OBJECT_DESTROY(hObject, object_p, rv) \
HANDLE2OBJECT_COMMON(hObject, object_p, rv, )
#define OBJ_REFRELE(object_p) { \
(void) pthread_mutex_lock(&object_p->object_mutex); \
if ((--object_p->obj_refcnt) == 0 && \
(object_p->obj_delete_sync & OBJECT_REFCNT_WAITING)) { \
(void) pthread_cond_signal(&object_p->obj_free_cond); \
} \
(void) pthread_mutex_unlock(&object_p->object_mutex); \
}
void kernel_cleanup_object(kernel_object_t *objp);
CK_RV kernel_add_object(CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount,
CK_ULONG *objecthandle_p, kernel_session_t *sp);
CK_RV kernel_delete_session_object(kernel_session_t *sp, kernel_object_t *objp,
boolean_t lock_held, boolean_t wrapper_only);
void kernel_cleanup_extra_attr(kernel_object_t *object_p);
CK_RV kernel_copy_extra_attr(CK_ATTRIBUTE_INFO_PTR old_attrp,
kernel_object_t *object_p);
void kernel_cleanup_object_bigint_attrs(kernel_object_t *object_p);
CK_RV kernel_build_object(CK_ATTRIBUTE_PTR template, CK_ULONG ulAttrNum,
kernel_object_t *new_object, kernel_session_t *sp, uint_t);
CK_RV kernel_copy_object(kernel_object_t *old_object,
kernel_object_t **new_object, boolean_t copy_everything,
kernel_session_t *sp);
void kernel_merge_object(kernel_object_t *old_object,
kernel_object_t *new_object);
CK_RV kernel_get_attribute(kernel_object_t *object_p,
CK_ATTRIBUTE_PTR template);
CK_RV kernel_set_attribute(kernel_object_t *object_p,
CK_ATTRIBUTE_PTR template, boolean_t copy, kernel_session_t *sp);
void copy_bigint_attr(biginteger_t *src, biginteger_t *dst);
void kernel_add_object_to_session(kernel_object_t *objp, kernel_session_t *sp);
CK_RV kernel_copy_public_key_attr(public_key_obj_t *old_pub_key_obj_p,
public_key_obj_t **new_pub_key_obj_p, CK_KEY_TYPE key_type);
CK_RV kernel_copy_private_key_attr(private_key_obj_t *old_pri_key_obj_p,
private_key_obj_t **new_pri_key_obj_p, CK_KEY_TYPE key_type);
CK_RV kernel_copy_secret_key_attr(secret_key_obj_t *old_secret_key_obj_p,
secret_key_obj_t **new_secret_key_obj_p);
CK_RV kernel_validate_attr(CK_ATTRIBUTE_PTR template, CK_ULONG ulAttrNum,
CK_OBJECT_CLASS *class);
CK_RV kernel_find_objects_init(kernel_session_t *sp,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount);
void kernel_find_objects_final(kernel_session_t *sp);
void kernel_find_objects(kernel_session_t *sp,
CK_OBJECT_HANDLE *obj_found, CK_ULONG max_obj_requested,
CK_ULONG *found_obj_count);
void kernel_process_find_attr(CK_OBJECT_CLASS *pclasses,
CK_ULONG *num_result_pclasses, CK_ATTRIBUTE_PTR pTemplate,
CK_ULONG ulCount);
boolean_t kernel_find_match_attrs(kernel_object_t *obj,
CK_OBJECT_CLASS *pclasses, CK_ULONG num_pclasses,
CK_ATTRIBUTE *tmpl_attr, CK_ULONG num_attr);
CK_ATTRIBUTE_PTR get_extra_attr(CK_ATTRIBUTE_TYPE type, kernel_object_t *obj);
CK_RV get_string_from_template(CK_ATTRIBUTE_PTR dest, CK_ATTRIBUTE_PTR src);
void string_attr_cleanup(CK_ATTRIBUTE_PTR template);
void kernel_add_token_object_to_slot(kernel_object_t *objp,
kernel_slot_t *pslot);
void kernel_remove_token_object_from_slot(kernel_slot_t *pslot,
kernel_object_t *objp);
CK_RV kernel_delete_token_object(kernel_slot_t *pslot, kernel_session_t *sp,
kernel_object_t *obj, boolean_t lock_held, boolean_t wrapper_only);
void kernel_cleanup_pri_objects_in_slot(kernel_slot_t *pslot,
kernel_session_t *sp);
CK_RV kernel_get_object_size(kernel_object_t *objp, CK_ULONG_PTR pulSize);
void kernel_object_delay_free(kernel_object_t *objp);
#ifdef __cplusplus
}
#endif
#endif