From patchwork Mon Apr 13 13:30:44 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Laurent Pinchart X-Patchwork-Id: 3445 Return-Path: Received: from perceval.ideasonboard.com (perceval.ideasonboard.com [213.167.242.64]) by lancelot.ideasonboard.com (Postfix) with ESMTPS id B842662DE4 for ; Mon, 13 Apr 2020 15:31:08 +0200 (CEST) Authentication-Results: lancelot.ideasonboard.com; dkim=pass (1024-bit key; unprotected) header.d=ideasonboard.com header.i=@ideasonboard.com header.b="G2iXcS/I"; dkim-atps=neutral Received: from pendragon.bb.dnainternet.fi (81-175-216-236.bb.dnainternet.fi [81.175.216.236]) by perceval.ideasonboard.com (Postfix) with ESMTPSA id 1E8731227 for ; Mon, 13 Apr 2020 15:31:07 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ideasonboard.com; s=mail; t=1586784667; bh=AxO0nZQ6d9fVCxUDKBOnPH/O6PjuHIL8cMXHju01h5k=; h=From:To:Subject:Date:In-Reply-To:References:From; b=G2iXcS/Ipyf3qkl2U08wPEcj8vt5EwhEWClVUy9uo7IAyFNez8i1buVFYt2uGlGsC SyYb1XDzwuL2PPoyXb0Qsq0JFHfN4vf5KPNbLdldYTPXvBkcf4rPfVm6HXKPEFN3zA J5H/efAoJd+ipgfuyFTa/N7VyksGQQ+jAaQsa3UY= From: Laurent Pinchart To: libcamera-devel@lists.libcamera.org Date: Mon, 13 Apr 2020 16:30:44 +0300 Message-Id: <20200413133047.11913-9-laurent.pinchart@ideasonboard.com> X-Mailer: git-send-email 2.24.1 In-Reply-To: <20200413133047.11913-1-laurent.pinchart@ideasonboard.com> References: <20200413133047.11913-1-laurent.pinchart@ideasonboard.com> MIME-Version: 1.0 Subject: [libcamera-devel] [PATCH v2 08/11] libcamera: Add PubKey class X-BeenThere: libcamera-devel@lists.libcamera.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 13 Apr 2020 13:31:10 -0000 Add a new PubKey class to handle public key signature verification. The implementation is based on the gnutls library, which is added as an optional dependency. If gnutls is not found, signature verification will unconditionally fail. Signed-off-by: Laurent Pinchart Reviewed-by: Niklas Söderlund --- Changes since v1: - Guard forward declaration of struct gnutls_pubkey_st with #ifdef HAVE_GNUTLS --- src/libcamera/include/meson.build | 1 + src/libcamera/include/pub_key.h | 38 ++++++++++++ src/libcamera/meson.build | 7 +++ src/libcamera/pub_key.cpp | 97 +++++++++++++++++++++++++++++++ 4 files changed, 143 insertions(+) create mode 100644 src/libcamera/include/pub_key.h create mode 100644 src/libcamera/pub_key.cpp diff --git a/src/libcamera/include/meson.build b/src/libcamera/include/meson.build index 921ed5a063cb..5aaa99472e4a 100644 --- a/src/libcamera/include/meson.build +++ b/src/libcamera/include/meson.build @@ -21,6 +21,7 @@ libcamera_headers = files([ 'message.h', 'pipeline_handler.h', 'process.h', + 'pub_key.h', 'semaphore.h', 'thread.h', 'utils.h', diff --git a/src/libcamera/include/pub_key.h b/src/libcamera/include/pub_key.h new file mode 100644 index 000000000000..f35bf3738c6f --- /dev/null +++ b/src/libcamera/include/pub_key.h @@ -0,0 +1,38 @@ +/* SPDX-License-Identifier: LGPL-2.1-or-later */ +/* + * Copyright (C) 2020, Google Inc. + * + * pub_key.h - Public key signature verification + */ +#ifndef __LIBCAMERA_PUB_KEY_H__ +#define __LIBCAMERA_PUB_KEY_H__ + +#include + +#include + +#if HAVE_GNUTLS +struct gnutls_pubkey_st; +#endif + +namespace libcamera { + +class PubKey +{ +public: + PubKey(Span key); + ~PubKey(); + + bool isValid() const { return valid_; } + bool verify(Span data, Span sig) const; + +private: + bool valid_; +#if HAVE_GNUTLS + struct gnutls_pubkey_st *pubkey_; +#endif +}; + +} /* namespace libcamera */ + +#endif /* __LIBCAMERA_PUB_KEY_H__ */ diff --git a/src/libcamera/meson.build b/src/libcamera/meson.build index 4f5c41678781..c2a657e4938c 100644 --- a/src/libcamera/meson.build +++ b/src/libcamera/meson.build @@ -34,6 +34,7 @@ libcamera_sources = files([ 'pipeline_handler.cpp', 'pixelformats.cpp', 'process.cpp', + 'pub_key.cpp', 'request.cpp', 'semaphore.cpp', 'signal.cpp', @@ -61,8 +62,13 @@ subdir('proxy') libatomic = cc.find_library('atomic', required : false) libdl = cc.find_library('dl') +libgnutls = cc.find_library('gnutls', required : false) libudev = dependency('libudev', required : false) +if libgnutls.found() + config_h.set('HAVE_GNUTLS', 1) +endif + if libudev.found() config_h.set('HAVE_LIBUDEV', 1) libcamera_sources += files([ @@ -98,6 +104,7 @@ libcamera_sources += version_cpp libcamera_deps = [ libatomic, libdl, + libgnutls, libudev, dependency('threads'), ] diff --git a/src/libcamera/pub_key.cpp b/src/libcamera/pub_key.cpp new file mode 100644 index 000000000000..064d2dd200e1 --- /dev/null +++ b/src/libcamera/pub_key.cpp @@ -0,0 +1,97 @@ +/* SPDX-License-Identifier: LGPL-2.1-or-later */ +/* + * Copyright (C) 2020, Google Inc. + * + * pub_key.cpp - Public key signature verification + */ + +#include "pub_key.h" + +#if HAVE_GNUTLS +#include +#endif + +/** + * \file pub_key.h + * \brief Public key signature verification + */ + +namespace libcamera { + +/** + * \class PubKey + * \brief Public key wrapper for signature verification + * + * The PubKey class wraps a public key and implements signature verification. It + * only supports RSA keys and the RSA-SHA256 signature algorithm. + */ + +/** + * \brief Construct a PubKey from key data + * \param[in] key Key data encoded in DER format + */ +PubKey::PubKey(Span key) + : valid_(false) +{ +#if HAVE_GNUTLS + int ret = gnutls_pubkey_init(&pubkey_); + if (ret < 0) + return; + + const gnutls_datum_t gnuTlsKey{ + const_cast(key.data()), + static_cast(key.size()) + }; + ret = gnutls_pubkey_import(pubkey_, &gnuTlsKey, GNUTLS_X509_FMT_DER); + if (ret < 0) + return; + + valid_ = true; +#endif +} + +PubKey::~PubKey() +{ +#if HAVE_GNUTLS + gnutls_pubkey_deinit(pubkey_); +#endif +} + +/** + * \fn bool PubKey::isValid() const + * \brief Check is the public key is valid + * \return True if the public key is valid, false otherwise + */ + +/** + * \brief Verify signature on data + * \param[in] data The signed data + * \param[in] sig The signature + * + * Verify that the signature \a sig matches the signed \a data for the public + * key. The signture algorithm is hardcoded to RSA-SHA256. + * + * \return True if the signature is valid, false otherwise + */ +bool PubKey::verify(Span data, Span sig) const +{ +#if HAVE_GNUTLS + const gnutls_datum_t gnuTlsData{ + const_cast(data.data()), + static_cast(data.size()) + }; + + const gnutls_datum_t gnuTlsSig{ + const_cast(sig.data()), + static_cast(sig.size()) + }; + + int ret = gnutls_pubkey_verify_data2(pubkey_, GNUTLS_SIGN_RSA_SHA256, 0, + &gnuTlsData, &gnuTlsSig); + return ret >= 0; +#else + return false; +#endif +} + +} /* namespace libcamera */