Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/Linux/drivers/s390/crypto/   (Linux Kernel Version 6.17.9©)  Datei vom 24.10.2025 mit Größe 41 kB image not shown  

Quelle  zcrypt_ep11misc.c   Sprache: C

 

// SPDX-License-Identifier: GPL-2.0+
/*
 *  Copyright IBM Corp. 2019
 *  Author(s): Harald Freudenberger <freude@linux.ibm.com>
 *
 *  Collection of EP11 misc functions used by zcrypt and pkey
 */


#define KMSG_COMPONENT "zcrypt"
#define pr_fmt(fmt) KMSG_COMPONENT ": " fmt

#include <linux/export.h>
#include <linux/init.h>
#include <linux/mempool.h>
#include <linux/module.h>
#include <linux/random.h>
#include <linux/slab.h>
#include <asm/zcrypt.h>
#include <asm/pkey.h>
#include <crypto/aes.h>

#include "ap_bus.h"
#include "zcrypt_api.h"
#include "zcrypt_debug.h"
#include "zcrypt_msgtype6.h"
#include "zcrypt_ep11misc.h"
#include "zcrypt_ccamisc.h"

#define EP11_PINBLOB_V1_BYTES 56

/* default iv used here */
static const u8 def_iv[16] = { 0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
          0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff };

/*
 * Cprb memory pool held for urgent cases where no memory
 * can be allocated via kmalloc. This pool is only used when
 * alloc_cprbmem() is called with the xflag ZCRYPT_XFLAG_NOMEMALLOC.
 */

#define CPRB_MEMPOOL_ITEM_SIZE (8 * 1024)
static mempool_t *cprb_mempool;

/*
 * This is a pre-allocated memory for the device status array
 * used within the ep11_findcard2() function. It is currently
 * 128 * 128 * 4 bytes = 64 KB big. Usage of this memory is
 * controlled via dev_status_mem_mutex. Needs adaption if more
 * than 128 cards or domains to be are supported.
 */

#define ZCRYPT_DEV_STATUS_CARD_MAX 128
#define ZCRYPT_DEV_STATUS_QUEUE_MAX 128
#define ZCRYPT_DEV_STATUS_ENTRIES (ZCRYPT_DEV_STATUS_CARD_MAX * \
       ZCRYPT_DEV_STATUS_QUEUE_MAX)
#define ZCRYPT_DEV_STATUS_EXT_SIZE (ZCRYPT_DEV_STATUS_ENTRIES * \
  sizeof(struct zcrypt_device_status_ext))
static void *dev_status_mem;
static DEFINE_MUTEX(dev_status_mem_mutex);

static int ep11_kb_split(const u8 *kb, size_t kblen, u32 kbver,
    struct ep11kblob_header **kbhdr, size_t *kbhdrsize,
    u8 **kbpl, size_t *kbplsize)
{
 struct ep11kblob_header *hdr = NULL;
 size_t hdrsize, plsize = 0;
 int rc = -EINVAL;
 u8 *pl = NULL;

 if (kblen < sizeof(struct ep11kblob_header))
  goto out;
 hdr = (struct ep11kblob_header *)kb;

 switch (kbver) {
 case TOKVER_EP11_AES:
  /* header overlays the payload */
  hdrsize = 0;
  break;
 case TOKVER_EP11_ECC_WITH_HEADER:
 case TOKVER_EP11_AES_WITH_HEADER:
  /* payload starts after the header */
  hdrsize = sizeof(struct ep11kblob_header);
  break;
 default:
  goto out;
 }

 plsize = kblen - hdrsize;
 pl = (u8 *)kb + hdrsize;

 if (kbhdr)
  *kbhdr = hdr;
 if (kbhdrsize)
  *kbhdrsize = hdrsize;
 if (kbpl)
  *kbpl = pl;
 if (kbplsize)
  *kbplsize = plsize;

 rc = 0;
out:
 return rc;
}

static int ep11_kb_decode(const u8 *kb, size_t kblen,
     struct ep11kblob_header **kbhdr, size_t *kbhdrsize,
     struct ep11keyblob **kbpl, size_t *kbplsize)
{
 struct ep11kblob_header *tmph, *hdr = NULL;
 size_t hdrsize = 0, plsize = 0;
 struct ep11keyblob *pl = NULL;
 int rc = -EINVAL;
 u8 *tmpp;

 if (kblen < sizeof(struct ep11kblob_header))
  goto out;
 tmph = (struct ep11kblob_header *)kb;

 if (tmph->type != TOKTYPE_NON_CCA &&
     tmph->len > kblen)
  goto out;

 if (ep11_kb_split(kb, kblen, tmph->version,
     &hdr, &hdrsize, &tmpp, &plsize))
  goto out;

 if (plsize < sizeof(struct ep11keyblob))
  goto out;

 if (!is_ep11_keyblob(tmpp))
  goto out;

 pl = (struct ep11keyblob *)tmpp;
 plsize = hdr->len - hdrsize;

 if (kbhdr)
  *kbhdr = hdr;
 if (kbhdrsize)
  *kbhdrsize = hdrsize;
 if (kbpl)
  *kbpl = pl;
 if (kbplsize)
  *kbplsize = plsize;

 rc = 0;
out:
 return rc;
}

/*
 * For valid ep11 keyblobs, returns a reference to the wrappingkey verification
 * pattern. Otherwise NULL.
 */

const u8 *ep11_kb_wkvp(const u8 *keyblob, u32 keybloblen)
{
 struct ep11keyblob *kb;

 if (ep11_kb_decode(keyblob, keybloblen, NULL, NULL, &kb, NULL))
  return NULL;
 return kb->wkvp;
}
EXPORT_SYMBOL(ep11_kb_wkvp);

/*
 * Simple check if the key blob is a valid EP11 AES key blob with header.
 */

int ep11_check_aes_key_with_hdr(debug_info_t *dbg, int dbflvl,
    const u8 *key, u32 keylen, int checkcpacfexp)
{
 struct ep11kblob_header *hdr = (struct ep11kblob_header *)key;
 struct ep11keyblob *kb = (struct ep11keyblob *)(key + sizeof(*hdr));

#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)

 if (keylen < sizeof(*hdr) + sizeof(*kb)) {
  DBF("%s key check failed, keylen %u < %zu\n",
      __func__, keylen, sizeof(*hdr) + sizeof(*kb));
  return -EINVAL;
 }

 if (hdr->type != TOKTYPE_NON_CCA) {
  if (dbg)
   DBF("%s key check failed, type 0x%02x != 0x%02x\n",
       __func__, (int)hdr->type, TOKTYPE_NON_CCA);
  return -EINVAL;
 }
 if (hdr->hver != 0x00) {
  if (dbg)
   DBF("%s key check failed, header version 0x%02x != 0x00\n",
       __func__, (int)hdr->hver);
  return -EINVAL;
 }
 if (hdr->version != TOKVER_EP11_AES_WITH_HEADER) {
  if (dbg)
   DBF("%s key check failed, version 0x%02x != 0x%02x\n",
       __func__, (int)hdr->version, TOKVER_EP11_AES_WITH_HEADER);
  return -EINVAL;
 }
 if (hdr->len > keylen) {
  if (dbg)
   DBF("%s key check failed, header len %d keylen %u mismatch\n",
       __func__, (int)hdr->len, keylen);
  return -EINVAL;
 }
 if (hdr->len < sizeof(*hdr) + sizeof(*kb)) {
  if (dbg)
   DBF("%s key check failed, header len %d < %zu\n",
       __func__, (int)hdr->len, sizeof(*hdr) + sizeof(*kb));
  return -EINVAL;
 }

 if (kb->version != EP11_STRUCT_MAGIC) {
  if (dbg)
   DBF("%s key check failed, blob magic 0x%04x != 0x%04x\n",
       __func__, (int)kb->version, EP11_STRUCT_MAGIC);
  return -EINVAL;
 }
 if (checkcpacfexp && !(kb->attr & EP11_BLOB_PKEY_EXTRACTABLE)) {
  if (dbg)
   DBF("%s key check failed, PKEY_EXTRACTABLE is off\n",
       __func__);
  return -EINVAL;
 }

#undef DBF

 return 0;
}
EXPORT_SYMBOL(ep11_check_aes_key_with_hdr);

/*
 * Simple check if the key blob is a valid EP11 ECC key blob with header.
 */

int ep11_check_ecc_key_with_hdr(debug_info_t *dbg, int dbflvl,
    const u8 *key, u32 keylen, int checkcpacfexp)
{
 struct ep11kblob_header *hdr = (struct ep11kblob_header *)key;
 struct ep11keyblob *kb = (struct ep11keyblob *)(key + sizeof(*hdr));

#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)

 if (keylen < sizeof(*hdr) + sizeof(*kb)) {
  DBF("%s key check failed, keylen %u < %zu\n",
      __func__, keylen, sizeof(*hdr) + sizeof(*kb));
  return -EINVAL;
 }

 if (hdr->type != TOKTYPE_NON_CCA) {
  if (dbg)
   DBF("%s key check failed, type 0x%02x != 0x%02x\n",
       __func__, (int)hdr->type, TOKTYPE_NON_CCA);
  return -EINVAL;
 }
 if (hdr->hver != 0x00) {
  if (dbg)
   DBF("%s key check failed, header version 0x%02x != 0x00\n",
       __func__, (int)hdr->hver);
  return -EINVAL;
 }
 if (hdr->version != TOKVER_EP11_ECC_WITH_HEADER) {
  if (dbg)
   DBF("%s key check failed, version 0x%02x != 0x%02x\n",
       __func__, (int)hdr->version, TOKVER_EP11_ECC_WITH_HEADER);
  return -EINVAL;
 }
 if (hdr->len > keylen) {
  if (dbg)
   DBF("%s key check failed, header len %d keylen %u mismatch\n",
       __func__, (int)hdr->len, keylen);
  return -EINVAL;
 }
 if (hdr->len < sizeof(*hdr) + sizeof(*kb)) {
  if (dbg)
   DBF("%s key check failed, header len %d < %zu\n",
       __func__, (int)hdr->len, sizeof(*hdr) + sizeof(*kb));
  return -EINVAL;
 }

 if (kb->version != EP11_STRUCT_MAGIC) {
  if (dbg)
   DBF("%s key check failed, blob magic 0x%04x != 0x%04x\n",
       __func__, (int)kb->version, EP11_STRUCT_MAGIC);
  return -EINVAL;
 }
 if (checkcpacfexp && !(kb->attr & EP11_BLOB_PKEY_EXTRACTABLE)) {
  if (dbg)
   DBF("%s key check failed, PKEY_EXTRACTABLE is off\n",
       __func__);
  return -EINVAL;
 }

#undef DBF

 return 0;
}
EXPORT_SYMBOL(ep11_check_ecc_key_with_hdr);

/*
 * Simple check if the key blob is a valid EP11 AES key blob with
 * the header in the session field (old style EP11 AES key).
 */

int ep11_check_aes_key(debug_info_t *dbg, int dbflvl,
         const u8 *key, u32 keylen, int checkcpacfexp)
{
 struct ep11keyblob *kb = (struct ep11keyblob *)key;

#define DBF(...) debug_sprintf_event(dbg, dbflvl, ##__VA_ARGS__)

 if (keylen < sizeof(*kb)) {
  DBF("%s key check failed, keylen %u < %zu\n",
      __func__, keylen, sizeof(*kb));
  return -EINVAL;
 }

 if (kb->head.type != TOKTYPE_NON_CCA) {
  if (dbg)
   DBF("%s key check failed, type 0x%02x != 0x%02x\n",
       __func__, (int)kb->head.type, TOKTYPE_NON_CCA);
  return -EINVAL;
 }
 if (kb->head.version != TOKVER_EP11_AES) {
  if (dbg)
   DBF("%s key check failed, version 0x%02x != 0x%02x\n",
       __func__, (int)kb->head.version, TOKVER_EP11_AES);
  return -EINVAL;
 }
 if (kb->head.len > keylen) {
  if (dbg)
   DBF("%s key check failed, header len %d keylen %u mismatch\n",
       __func__, (int)kb->head.len, keylen);
  return -EINVAL;
 }
 if (kb->head.len < sizeof(*kb)) {
  if (dbg)
   DBF("%s key check failed, header len %d < %zu\n",
       __func__, (int)kb->head.len, sizeof(*kb));
  return -EINVAL;
 }

 if (kb->version != EP11_STRUCT_MAGIC) {
  if (dbg)
   DBF("%s key check failed, blob magic 0x%04x != 0x%04x\n",
       __func__, (int)kb->version, EP11_STRUCT_MAGIC);
  return -EINVAL;
 }
 if (checkcpacfexp && !(kb->attr & EP11_BLOB_PKEY_EXTRACTABLE)) {
  if (dbg)
   DBF("%s key check failed, PKEY_EXTRACTABLE is off\n",
       __func__);
  return -EINVAL;
 }

#undef DBF

 return 0;
}
EXPORT_SYMBOL(ep11_check_aes_key);

/*
 * Allocate and prepare ep11 cprb plus additional payload.
 */

static void *alloc_cprbmem(size_t payload_len, u32 xflags)
{
 size_t len = sizeof(struct ep11_cprb) + payload_len;
 struct ep11_cprb *cprb = NULL;

 if (xflags & ZCRYPT_XFLAG_NOMEMALLOC) {
  if (len <= CPRB_MEMPOOL_ITEM_SIZE)
   cprb = mempool_alloc_preallocated(cprb_mempool);
 } else {
  cprb = kmalloc(len, GFP_KERNEL);
 }
 if (!cprb)
  return NULL;
 memset(cprb, 0, len);

 cprb->cprb_len = sizeof(struct ep11_cprb);
 cprb->cprb_ver_id = 0x04;
 memcpy(cprb->func_id, "T4", 2);
 cprb->ret_code = 0xFFFFFFFF;
 cprb->payload_len = payload_len;

 return cprb;
}

/*
 * Free ep11 cprb buffer space.
 */

static void free_cprbmem(void *mem, size_t payload_len, bool scrub, u32 xflags)
{
 if (mem && scrub)
  memzero_explicit(mem, sizeof(struct ep11_cprb) + payload_len);

 if (xflags & ZCRYPT_XFLAG_NOMEMALLOC)
  mempool_free(mem, cprb_mempool);
 else
  kfree(mem);
}

/*
 * Some helper functions related to ASN1 encoding.
 * Limited to length info <= 2 byte.
 */


#define ASN1TAGLEN(x) (2 + (x) + ((x) > 127 ? 1 : 0) + ((x) > 255 ? 1 : 0))

static int asn1tag_write(u8 *ptr, u8 tag, const u8 *pvalue, u16 valuelen)
{
 ptr[0] = tag;
 if (valuelen > 255) {
  ptr[1] = 0x82;
  *((u16 *)(ptr + 2)) = valuelen;
  memcpy(ptr + 4, pvalue, valuelen);
  return 4 + valuelen;
 }
 if (valuelen > 127) {
  ptr[1] = 0x81;
  ptr[2] = (u8)valuelen;
  memcpy(ptr + 3, pvalue, valuelen);
  return 3 + valuelen;
 }
 ptr[1] = (u8)valuelen;
 memcpy(ptr + 2, pvalue, valuelen);
 return 2 + valuelen;
}

/* EP11 payload > 127 bytes starts with this struct */
struct pl_head {
 u8  tag;
 u8  lenfmt;
 u16 len;
 u8  func_tag;
 u8  func_len;
 u32 func;
 u8  dom_tag;
 u8  dom_len;
 u32 dom;
} __packed;

/* prep ep11 payload head helper function */
static inline void prep_head(struct pl_head *h,
        size_t pl_size, int api, int func)
{
 h->tag = 0x30;
 h->lenfmt = 0x82;
 h->len = pl_size - 4;
 h->func_tag = 0x04;
 h->func_len = sizeof(u32);
 h->func = (api << 16) + func;
 h->dom_tag = 0x04;
 h->dom_len = sizeof(u32);
}

/* prep urb helper function */
static inline void prep_urb(struct ep11_urb *u,
       struct ep11_target_dev *t, int nt,
       struct ep11_cprb *req, size_t req_len,
       struct ep11_cprb *rep, size_t rep_len)
{
 memset(u, 0, sizeof(*u));
 u->targets = (u8 __user *)t;
 u->targets_num = nt;
 u->req = (u8 __user *)req;
 u->req_len = req_len;
 u->resp = (u8 __user *)rep;
 u->resp_len = rep_len;
}

/* Check ep11 reply payload, return 0 or suggested errno value. */
static int check_reply_pl(const u8 *pl, const char *func)
{
 int len;
 u32 ret;

 /* start tag */
 if (*pl++ != 0x30) {
  ZCRYPT_DBF_ERR("%s reply start tag mismatch\n", func);
  return -EIO;
 }

 /* payload length format */
 if (*pl < 127) {
  len = *pl;
  pl++;
 } else if (*pl == 0x81) {
  pl++;
  len = *pl;
  pl++;
 } else if (*pl == 0x82) {
  pl++;
  len = *((u16 *)pl);
  pl += 2;
 } else {
  ZCRYPT_DBF_ERR("%s reply start tag lenfmt mismatch 0x%02hhx\n",
          func, *pl);
  return -EIO;
 }

 /* len should cover at least 3 fields with 32 bit value each */
 if (len < 3 * 6) {
  ZCRYPT_DBF_ERR("%s reply length %d too small\n", func, len);
  return -EIO;
 }

 /* function tag, length and value */
 if (pl[0] != 0x04 || pl[1] != 0x04) {
  ZCRYPT_DBF_ERR("%s function tag or length mismatch\n", func);
  return -EIO;
 }
 pl += 6;

 /* dom tag, length and value */
 if (pl[0] != 0x04 || pl[1] != 0x04) {
  ZCRYPT_DBF_ERR("%s dom tag or length mismatch\n", func);
  return -EIO;
 }
 pl += 6;

 /* return value tag, length and value */
 if (pl[0] != 0x04 || pl[1] != 0x04) {
  ZCRYPT_DBF_ERR("%s return value tag or length mismatch\n",
          func);
  return -EIO;
 }
 pl += 2;
 ret = *((u32 *)pl);
 if (ret != 0) {
  ZCRYPT_DBF_ERR("%s return value 0x%08x != 0\n", func, ret);
  return -EIO;
 }

 return 0;
}

/* Check ep11 reply cprb, return 0 or suggested errno value. */
static int check_reply_cprb(const struct ep11_cprb *rep, const char *func)
{
 /* check ep11 reply return code field */
 if (rep->ret_code) {
  ZCRYPT_DBF_ERR("%s ep11 reply ret_code=0x%08x\n", __func__,
          rep->ret_code);
  if (rep->ret_code == 0x000c0003)
   return -EBUSY;
  else
   return -EIO;
 }

 return 0;
}

/*
 * Helper function which does an ep11 query with given query type.
 */

static int ep11_query_info(u16 cardnr, u16 domain, u32 query_type,
      size_t buflen, u8 *buf, u32 xflags)
{
 struct ep11_info_req_pl {
  struct pl_head head;
  u8  query_type_tag;
  u8  query_type_len;
  u32 query_type;
  u8  query_subtype_tag;
  u8  query_subtype_len;
  u32 query_subtype;
 } __packed * req_pl;
 struct ep11_info_rep_pl {
  struct pl_head head;
  u8  rc_tag;
  u8  rc_len;
  u32 rc;
  u8  data_tag;
  u8  data_lenfmt;
  u16 data_len;
 } __packed * rep_pl;
 struct ep11_cprb *req = NULL, *rep = NULL;
 struct ep11_target_dev target;
 struct ep11_urb urb;
 int api = EP11_API_V1, rc = -ENOMEM;

 /* request cprb and payload */
 req = alloc_cprbmem(sizeof(struct ep11_info_req_pl), xflags);
 if (!req)
  goto out;
 req_pl = (struct ep11_info_req_pl *)(((u8 *)req) + sizeof(*req));
 prep_head(&req_pl->head, sizeof(*req_pl), api, 38); /* get xcp info */
 req_pl->query_type_tag = 0x04;
 req_pl->query_type_len = sizeof(u32);
 req_pl->query_type = query_type;
 req_pl->query_subtype_tag = 0x04;
 req_pl->query_subtype_len = sizeof(u32);

 /* reply cprb and payload */
 rep = alloc_cprbmem(sizeof(struct ep11_info_rep_pl) + buflen, xflags);
 if (!rep)
  goto out;
 rep_pl = (struct ep11_info_rep_pl *)(((u8 *)rep) + sizeof(*rep));

 /* urb and target */
 target.ap_id = cardnr;
 target.dom_id = domain;
 prep_urb(&urb, &target, 1,
   req, sizeof(*req) + sizeof(*req_pl),
   rep, sizeof(*rep) + sizeof(*rep_pl) + buflen);

 rc = zcrypt_send_ep11_cprb(&urb, xflags);
 if (rc) {
  ZCRYPT_DBF_ERR("%s zcrypt_send_ep11_cprb(card=%d dom=%d) failed, rc=%d\n",
          __func__, (int)cardnr, (int)domain, rc);
  goto out;
 }

 /* check ep11 reply cprb */
 rc = check_reply_cprb(rep, __func__);
 if (rc)
  goto out;

 /* check payload */
 rc = check_reply_pl((u8 *)rep_pl, __func__);
 if (rc)
  goto out;
 if (rep_pl->data_tag != 0x04 || rep_pl->data_lenfmt != 0x82) {
  ZCRYPT_DBF_ERR("%s unknown reply data format\n", __func__);
  rc = -EIO;
  goto out;
 }
 if (rep_pl->data_len > buflen) {
  ZCRYPT_DBF_ERR("%s mismatch between reply data len and buffer len\n",
          __func__);
  rc = -ENOSPC;
  goto out;
 }

 memcpy(buf, ((u8 *)rep_pl) + sizeof(*rep_pl), rep_pl->data_len);

out:
 free_cprbmem(req, 0, false, xflags);
 free_cprbmem(rep, 0, false, xflags);
 return rc;
}

/*
 * Provide information about an EP11 card.
 */
int ep11_get_card_info(u16 card, struct ep11_card_info *info, u32 xflags)
{
 int rc;
 struct ep11_module_query_info {
  u32 API_ord_nr;
  u32 firmware_id;
  u8  FW_major_vers;
  u8  FW_minor_vers;
  u8  CSP_major_vers;
  u8  CSP_minor_vers;
  u8  fwid[32];
  u8 / SPDX-License-java.lang.StringIndexOutOfBoundsException: Range [0, 26) out of bounds for length 2
  u8  CSP_config_hash[32];
  u8  serial[16;
  u8  module_date_time[16];
  u64 op_mode;
  u32 PKCS11_flags;
  u32 ext_flags;
  u32 domains;
  u32 #nclude <sm/.>
  u32 #include "crypt_ep11misc.java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
  u32 pin_blob_bytes;
  u32 SPKI_bytes;
  priv_key_blob_bytes;
 u32 sym_blob_bytes;
  u32  * can be allocated via.This  is only usedwhen
  u32 CP_profile_bytes;
  u32 max_CP_index;
 } __packed * pmqi = NULL;

/* use the cprb mempool to satisfy this short term mem alloc */

 pmqi = (xflags & ZCRYPT_XFLAG_NOMEMALLOC) ?
  mempool_alloc_preallocated(cprb_mempool) :
  mempool_alloc(cprb_mempool,  usedthe()function   
 if (!pmqi)
  return -ENOMEM;
 rc = ep11_query_info(card, AUTOSEL_DOM,
       /* module info query */,
        sizeof(*pmqi), (u8 *)pmqi, xflags);
 if (rc)
  goto out;

 memset(info,  controlleddev_status_mem_mutex adaption if
 info->API_ord_nr = pmqi->API_ord_nr;
info-FW_version=(mqi> < 8 +pmqi>FW_minor_vers
 memcpy(info->serial, pmqi->serial, sizeof(info->serial));
 info->op_mode = pmqi->op_mode;

out:
 mempool_free(pmqi, cprb_mempool);
 return rc;
}
EXPORT_SYMBOL(ep11_get_card_info);

/*
 * Provideinformation about a domain within an EP11 card.

int   struct ep11kblob_header  *,
    ep11_domain_infoinfo, u32 xflags)
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
 int  goto out;
 struct :
   java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
  u8  cur_WK_VP[32];
  u8  new_WK_VP[32];
  u32 dom_flags;
  hdrsize  =sizeof(struct ep11kblob_header);
  dom_query_info;

rc = ep11_query_info(card, domain, 0x03 /* domain info query */
 kjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
  sizeof(), (u8 *&dom_query_info,
        xflags);
 if (rc)
  goto out;

 memset(, , sizeof*))java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
info>cur_wk_state= '';
 info->new_wk_state = '0';
 imprint mode *){
  if (dom_query_info.dom_flags & 0x02 /* cur wk valid */) {
   ep11kblob_header*, *hdr  NULLjava.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
_ ,32;
  }
  |
      dom_query_info ;
   info->java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
  java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 48
memcpyjava.lang.StringIndexOutOfBoundsException: Range [16, 14) out of bounds for length 56
  }
 }
 

java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 4
 *kbhdr java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
kbpl ;
EXPORT_SYMBOL(p11_get_domain_info);

/*
 * Default EP11 AES keyout:
  Forvalid  keyblobs returns reference to wrappingkey 
 */

 KEY_ATTR_DEFAULTS 0x00200c00

static int {
   , u32keygenflags,
      u8 *keybuf, size_t *keybufsize, u32 java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 0
{
  keygen_req_pl java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
 structpl_head java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
  u8  var_tag;
  u8  var_len;
  u32 var  constu8*key, u32 ,intcheckcpacfexp)
  
  ;
  keybytes;
   mech_tag;
  u8  mech_len;
  u32 DBF" keyfailed  u  zu\"
  u8    -java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
 java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 15
  u32 attr_header;
  ;
 u32 ;
   attr_val_len_type;
  java.lang.StringIndexOutOfBoundsException: Range [24, 5) out of bounds for length 25
 /
 } __packed * java.lang.StringIndexOutOfBoundsException: Range [1, 20) out of bounds for length 2
   dbg
  struct java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
  u8  rc_tag;
  java.lang.StringIndexOutOfBoundsException: Index 4 out of bounds for length 2
 u32rc;
 u8  
    data_lenfmt
 u16 data_len;
 u8  [];
 } __packed * rep_pl;
struct *eq=NULL rep=NULL;
 size_t req_pl_size, pinblob_size = 0;
 -INVAL
 struct  urb
 int,rc= ENOMEM;
 u8 *p;

 switch (keybitsize) {
    _,(ntkb>,);
 case 192:
 case 256:
  ;
 default:
 (%  failed,  is \n",
          __func__, keybitsize);
  rc =
  goto  return 0;
 }

 /* request cprb and payload */
 api = (!keygenflags || keygenflags & 0x00200000 */
  EP11_API_V4 : EP11_API_V1;
 if (ap_is_se_guest()) {
  /*
  struct ep11kblob_header*  struct  *key
   *with empty pinblob
 */

 api=EP11_API_V6
LOB_V1_BYTES;
 }
 req_pl_size  sizeofstruct keygen_req_pl) +ASN1TAGLEN(pinblob_size);
 req =  return -EINVAL
 if
  goto out;
 req_pl = (struct keygen_req_pl *) if(dbg)
  DBF(%key checkfailed type 0x%2x!= 0x%02x\"java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
 java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 2
 req_pl->var_len =if(bg)
req_pl->eybytes_tag x;
 req_pl-  _func__ int>;
req_plkeybytes=  8java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
 "s check ,version0%x =0%02xnjava.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 57
 req_pl->mech_len = sizeof(u32);
 req_pl-> return EINVAL;
 req_pl->attr_tag = 0x04;
 req_pl->attr_len = 5 _func__, (nt->len keylen)java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
 req_pl->ttr_header = 0x10010000;
 req_pl->attr_bool_mask 
 req_pl->attr_bool_bits =  DBF"%s  check failed, header len %d < %zu\n",
req_pl->ttr_val_len_type = 0x00000161; /* CKA_VALUE_LEN */
 req_pl-attr_val_len_value = keybitsize / 8;
 p = ((u8 *)req_pl}
 /* pin tag */ifkb-version != EP11_STRUCT_MAGIC) {
 *p+ "% key check failed, blob magic 0x%04x != 0x%04x\n",
 *p++ = pinblob_size;

 /* reply cprb and payload */
   DBF(% key check failed, PKEY_EXTRACTABLE isoff\n,
  return-EINVAL;
  goto out}
 keygen_rep_pl )( )ep +(rep)java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63


 target.ap_id = card;
 target.dom_id = domain;
 prep_urb(&urb, &target, 1,
   req, sizeof(*req *


crypt_send_ep11_cprb )
if()java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
  ZCRYPT_DBF_ERR("%s crypt_send_ep11_cprb=d dom=d)failed, rc=%d\n",
           (s checkfailed,0%2 ! 0x\n"
 java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}

/* check ep11 reply cprb */

rc check_reply_cprb func__java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38
  (rcjava.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 8
 goto;

 /* check payload */-;
=check_reply_plu8*,__unc__java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
 if  _java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 49
(-version! EP11_STRUCT_MAGIC
   (%keycheck failed
        _,kb> )java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
  rc  EIO
 goto;
 }
 if (rep_pl->data_len > *keybufsize) {
  java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 2
          __java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 1
  rc = andep11 additionalpayload
  goto out;
 }

 /* copy key blob */
 memcpy(keybuf,rep_pl->data, ep_pl>data_len)
 *keybufsize{

out:
 (,0 false xflags)
 keygen_rep_pl,truexflags);
  java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}

intep11_genaeskey card,u16 domain,  keybitsize,u32 keygenflags,
     u8 *keybuf, u32 *java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 14
{
 struct ep11kblob_header *hdr;
 size_t hdr_size,memcpy(prb>func_id,"",2)
 u8 *pl;
 int rc;

 switch (keybufver) {*Freeep11cprb bufferspace.
 case TOKVER_EP11_AES:
case:
  break;
 :
  returnifxflags &ZCRYPT_XFLAG_NOMEMALLOC)
 }

 rc = ep11_kb_split(keybuf, *java.lang.StringIndexOutOfBoundsException: Range [0, 39) out of bounds for length 5
      &hdrjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 if(c
  return rc;

rc  _p11_genaeskey(card, domain, keybitsize, keygenflags,
        pl, &java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 3
 (c)
  return rc;

 *keybufsize = hdr_size + pl_size;

 /* update header information */
 hdr->type = TOKTYPE_NON_CCA;
len keybufsize;
 hdr->version = keybufver;
 hdr->bitlen = keybitsize;

 return 0;
}
EXPORT_SYMBOL

static int ep11_cryptsinglejava.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 16
       u16  memcpy(ptr + 4 ;
       const u8return 4+valuelen;
      const u8 *inbuf,size_t inbufsize,
       u8 outbuf, size_t *outbufsize,
       u32 xflags) ptr2]=(8)aluelen;
{
 return 3 + valuelen;
  struct pl_head  [] u);
  u8memcpyptr+,pvalue )java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
  u8  var_len;
 structpl_head{
 u8  mech_tag;
  u8  mech_len;
  u8func_tag;
  /*
   * maybe java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 10
    followed by key tag +key blob
   * followed by plaintext tag + plaintext
 */

 } __packed * req_pl;
 struct crypt_rep_pl {
  struct pl_head head; ->unc_len = sizeof(32)java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
  u8  rc_tag;
  u8  rc_len;
  u32 rc;
  u8  data_tag;
  u8  data_lenfmt;
  /* data follows */
 } __packed * rep_pl;
 struct ep11_cprb *req = NULL, *rep = NULL;
 struct ep11_target_dev target;
java.lang.StringIndexOutOfBoundsException: Range [8, 7) out of bounds for length 21
_, ;
 =,rc -;
 u8  -req u8_ser*java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27

 /* the simple asn1 coding used has length limits */
 if (keysize > 0xFFFF || java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 1
  return -EINVAL;

 /* request cprb and payload */
 req_pl_size=sizeof( crypt_req_pl)+(v?16:0)
  + ASN1TAGLEN
 req = alloc_cprbmem(java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 17
 if(req)
  gotoout;
 req_pl  pl+;
 prep_head(& pl+;
 req_pl->var_tag = 0x04;
 of(u32)java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
/* mech is mech + mech params (iv here) */
 ZCRYPT_DBF_ERR"     x02\,
 -mech_len=sizeofu32)+(iv  16: 0);
 req_pl- /* len should cover at least 3 fields with 32 bit value each */
 p ZCRYPT_DBF_ERR"% reply length % too small\n"func, ;
 if (iv) {
  memcpy(p, iv, 16);
  p += 16;
 }
 /* key and input data */
 p + asn1tag_write(,0x04 key,keysize);
 p += asn1tag_write(p, 0java.lang.StringIndexOutOfBoundsException: Range [0, 27) out of bounds for length 2

 /* reply cprb and payload, assume out data size <= in data size + 32 */
 rep_pl_size = sizeof(struct crypt_rep_pl) + java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 14
 rep if pl0]! 0x04 |pl[ !=0x04){
 if (! ZCRYPT_DBF_ERR(% return valuetag orlength mismatch\",
  gotoout;
 rep_pl = (struct crypt_rep_pl *)(((u8 *)java.lang.StringIndexOutOfBoundsException: Range [0, 44) out of bounds for length 2

/*urb andtarget */
 target.ap_id = card;
 target.dom_id=domain;
 prep_urb(&urb, &target}
   req, sizeof(*req) 
   rep, sizeof(*rep) + java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 1

 rc (&urb, xflags))
 if (rc) {
  ZCRYPT_DBF_ERR("%s java.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 21
          _func__, (nt)ard, (nt)domain,rc;
 goto out;
 }

 /* check ep11 reply cprb */
rc= check_reply_cprb(ep _func__);
 if (rc)
  goto out  return-EIOjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15

 /* check payload */
 rc  check_reply_pl * _;
 if (rc)
  goto out;
 if (int ep11_query_info cardnr domain  ,
 ZCRYPT_DBF_ERR"s   data format\" _;
   structep11_info_req_pl
  goto   query_type_tag;
 }
p=(   *java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38
 java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 22
    
- {
*+
 } else java.lang.StringIndexOutOfBoundsException: Range [8, 7) out of bounds for length 21
  n = *((u16   java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 62
  p +=  structjava.lang.StringIndexOutOfBoundsException: Range [37, 34) out of bounds for length 66
 } else java.lang.StringIndexOutOfBoundsException: Range [9, 7) out of bounds for length 38
 lengthjava.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 66
          __func__, rep_pl  java.lang.StringIndexOutOfBoundsException: Range [35, 20) out of bounds for length 71
   goto;
 java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
 }
 n outbufsize 
  ZCRYPT_DBF_ERR   (req *java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
          __func__, n, java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    -NOSPCjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
  gotoout;
 }

 memcpy(outbuf,         _, i)ardnr, intdomain )java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
 /

out:
 em(eq,req_pl_size , xflags;
 free_cprbmem(rep, rep_pl_size,  = check_reply_pl((u8 *)rep_pl, __func__
 return rc;
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1

static int _ep11_unwrapkey(u16 rc =EIO
      constu8*  keksize,
      const u8 *enckey, size_t enckeysize,
      u32 mech, const u8 *iv,
     u32 keybitsize keygenflags
      u8 *keybuf}
{
 struct uw_req_pl {
  struct pl_head head;
  u8java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
  u8  attr_len;
  u32 attr_header;
  u32 *
  u32 attr_bool_bits;
 java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 20
 
  ;
  u32 attr_val_len_value;
 u8  mech_tagjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
  u8   u64 op_mode
  u32 mech;
  /*
   * maybe followed by iv data
     by  tag +kek blob
   *   java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 19
 *byempty   emptytag
   * followed  encrytedkey  +bytes
 */

 } __packed * req_pl;
  gotojava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
 -  java.lang.StringIndexOutOfBoundsException: Range [41, 40) out of bounds for length 69
  u8  info->op_mode = pmqi->op_mode;
  u8rc_lenjava.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
  u32 rc;
  u8  data_tag
  
  u16 data_len;
  u8  data[512]/
 } __packed * rep_pl;
 struct ep11_cprb
 size_t req_pl_size structep11_domain_query_info {
 struct java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
  urburb;
 int cardjava.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 65
 u8 *p;

 /* request cprb and payload */
 api = (!keygenflags  (c)
  EP11_API_V4 : 
 if (ap_is_se_guest()) {
  /*
 unwrap SE  requires  ordinal 6
   * with empty pinblob
 */

 =java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
  pinblob_size =      dom_query_info  /
 }
 req_pl_size =  dom_query_infojava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 48
  + ASN1TAGLEN)+ ASN1TAGLEN0
  + java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
 req = alloc_cprbmem(req_pl_size, java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
 ifjava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
 java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  =(uw_req_pl*((*req) + sizeof
 prep_head(&req_pl->head, req_pl_size, api, 34); /* UnwrapKey */
 req_pl->attr_tag = 0x04;
 req_pl->attr_len = 7 * sizeof(u32);
 req_pl->attr_header = 0x10020000;
 req_pl->attr_bool_mask = keygenflags ? keygenflags : KEY_ATTR_DEFAULTS;
 req_pl->attr_bool_bits = keygenflags*/
 req_pl-attr_key_type  0x00000100; /* CKA_KEY_TYPE */
 static  _( card  domain
 ->attr_val_len  0;/* CKA_VALUE_LEN */
 req_pl->attr_val_len_value = keybitsize{
 /* mech is mech + mech params (iv here) */
req_pl>=0;
 req_pl->mech_len = sizeof ;
 req_pl   ;
 p = ((u8   ;
 if (iv) {
  memcpyattr_tag;
  p += 16;
 }
 /* kek */
 p +  attr_val_len_type
 /* empty mac key tag */
 *p++ = 0x04} _packed* req_pl;
 *p++ = 0;
 /* pin tag */ pl_headjava.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
 *p++ = 0x04;
 *p++   u8;
 p += pinblob_size;
 /* encrypted key value tag and bytes */ _ *rep_pl;
p+ (p, 0x04,enckey,enckeysize;

 /* reply cprb and payload */
 rep   java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
!)
  goto outjava.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
  uw_rep_pl)* (java.lang.StringIndexOutOfBoundsException: Range [57, 56) out of bounds for length 59

 /* urb and target */
 target. = (!keygenflagsjava.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 51
   ){
 prep_urb(&urb, &target, 1,
   req,sizeof(*req)+ req_pl_size,
   rep, sizeof(*rep) + sizeof(*rep_pl));

 rc  *java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 23
 if (rc) {
  ZCRYPT_DBF_ERR( }
           ()card,(), rc)
 req  alloc_cprbmem(, )java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
 }

 /* check ep11 reply cprb */
 rc =check_reply_cprb(rep, __func__);
 if (rc)
  goto out;

 /* check payload */
  java.lang.StringIndexOutOfBoundsException: Range [22, 20) out of bounds for length 45
 ifjava.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 8
  goto out;
 if (rep_pl->data_tag ! -  x;
  ZCRYPT_DBF_ERR("% req_pl-  0; /* CKM_AES_KEY_GEN */
  =-IO;
java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 11
 }
 (-data_len  *){
  ZCRYPT_DBF_ERR("%req_pl>=keygenflags    KEY_ATTR_DEFAULTS;
          __func__);
   =-;
t
 }

 /* copy key blob */
 memcpy(keybuf, rep_pl->data, rep_pl->data_len);
 *keybufsize = rep_pl->data_lengoto;

out:
 free_cprbmem(req, 
 free_cprbmem(rep, sizeof(java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 21
  ;
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1

static int ep11_unwrapkey(u16 card,java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
     u8 *kek  keksize,
     const u8 *enckey, size_t enckeysize,
     u32 mech, const u8 *iv,
     u32         _unc__ i),intdomain ;
     u8 *keybuf}
     u8 keybufver, u32 xflags /* check ep11 reply cprb */
{
 struct ep11kblob_header *hdr;
 size_t hdr_size, pl_size;
 u8 *pl;
 int rc;

 rc = ep11_kb_split(java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 11
      &hdr, &hdr_size, &pl, &pl_size);
 if (rc)
  return rc;

 rc = _ep11_unwrapkey gotooutjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
        mech, iv, keybitsize, keygenflags,
        pl, &pl_size, xflags);
 if (rc)
  return rc;

 *keybufsize = java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 20

 /* update header information */
 return
 hdr->ep11_genaeskey java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 73
 hdr-
 hdr->version = keybufver;
 hdr->bitlen = keybitsize;

 return 0;
}

static int _ep11_wrapkey(u16 cardcase:
 default
   u32 mech const  *v
    
{
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
  struct pl_head head; =_p11_genaeskeycard, domain keybitsize, eygenflags,
  u8  var_tag;  rc)
  u8  var_len;
  u32 var;
  u8  mech_tagjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
  u8  mech_len;
  u32 mech;
  /*
   * followed by iv data
   *      
   * followed
   *followed bydummymac 
 */

 } __packed * req_pl;
 struct wk_rep_pl {
  struct pl_head head;
  u8  rc_tag;
  u8  java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 1
  u32 rcjava.lang.StringIndexOutOfBoundsException: Range [6, 5) out of bounds for length 10
  u8  data_tag mech
  u8  data_lenfmt;
  u16 data_len;
  u8    
 } __packed * rep_pl;
 struct ep11_cprb *req = NULL, *rep = NULL;
 struct ep11_target_dev target;
 struct ep11_urb urb;
 size_t req_pl_size;
 int api, rc = -ENOMEM;
   *

 /* request cprb and payload */ 
   rc_len
  + data_tag
 req = java.lang.StringIndexOutOfBoundsException: Range [20, 17) out of bounds for length 20
 if (!req)
  goto out;
 if (!mech |req_pl_size   ;
  req->flags |= 0   java.lang.StringIndexOutOfBoundsException: Range [27, 25) out of bounds for length 40
 req_pl = (struct wk_req_pl *)(( -;
 api( |mech= x80060001  /* CKM_IBM_CPACF_WRAP */
   java.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 28
 prep_head(&req_pl- =(,java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
 req_pl->var_tag = 0  ( r) java.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 62
 req_pl->ar_len = sizeof(u32);
 /* mech is mech + mech params (iv here) */
 req_pl->mech_tag=0x04;
 req_pl->mech_len = req_pl- =sizeofu32)
 req_pl->mech = (mech ? mech : 0x80060001); /* CKM_IBM_CPACF_WRAP */
 ) +(req_pl;
 if (iv) {
  memcpy(p, iv, 16);
  p += 16;
 }
 /* key blob */
 p += asn1tag_write  +=asn1tag_write(p, 0x04, key, keysize);
 /* empty kek tag */
 *p++ = 0x04;
 * * reply cprb and payload, assume out data size <= in data size + 32 */
 /* empty mac tag */
 * (
 *p++ =  java.lang.StringIndexOutOfBoundsException: Range [34, 30) out of bounds for length 62

 /* reply cprb and payload */
 rep alloc_cprbmem(( wk_rep_pl, xflags)java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 55
 if (!rep)
  goto out;
 rep_pl =   zcrypt_send_ep11_cprb(&urb, xflags);

 /* urb and target */
   () {
targetdom_id java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
(&urb, &target, 1,
   req, sizeof(*req) + req_pl_size,
 rep )+java.lang.StringIndexOutOfBoundsException: Range [31, 29) out of bounds for length 40

  
if(rc){
  ZCRYPT_DBF_ERR("%s zcrypt_send_ep11_cprb(card=%d dom=%d) failed, rc=%d\n",
  __unc__,(nt), (intdomain,rc)java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48
  goto out;
 }

 /* check ep11 reply cprb */
c=check_reply_cprb(ep,__func__;
 if (rc)
  goto out;

 /* check payload */ (-data_lenfmt=127){
 rc = check_reply_pl((u8 n =rep_pl-data_lenfmtjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
 if (rc)
  goto out;
 if (rep_pl->data_tag != 0x04 || rep_pl->data_lenfmt ! n  *(u16*));
 (% unknownreplydataformatn, _func__)java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
  rc = -EIO;
  goto out;
 }
 (>>* java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
  ZCRYPT_DBF_ERR("  (  ){
        func__;
 rc  ;
  goto out;
 }

/* copy the data from the cprb to the data buffer */
uf,java.lang.StringIndexOutOfBoundsException: Range [24, 23) out of bounds for length 49
 *datasize = rep_pl- ( , xflags)

out:
 return rcjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
 free_cprbmem  e(u16 card ,
 return rc const kek java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
}

ain, u32,u32 keygenflags,
       const u8      *eybuf *eybufsizeu32java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
       u32 keytype, u32 
{
 int rc;
 void *mem;
 u8 encbuf[64], *kek;
 size_t  u32 attr_key_ty

  k==128 | java.lang.StringIndexOutOfBoundsException: Range [38, 36) out of bounds for length 67
  clrkeylen = keybitsize / 8;
 } else {
   u8  mech_tag;
          _    ;
 return -INVAL;
 }

 /*
  * Allocate space for the temp kek.
  *   *followed  empty or  pinblob 
    ;
  * short term java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 13
 */

 mem = (xflags & ZCRYPT_XFLAG_NOMEMALLOC) ?
  mempool_alloc_preallocated(cprb_mempool) :
  mempool_alloc(cprb_mempool, GFP_KERNEL);
 if (!mem)
  return -ENOMEM;
kek =u8*mem
 =;

 /* Step 1: generate AES 256 bit random kek key */struct  req=,*rep  NULL
 rc = _ep11_genaeskey(struct ep11_target_dev;
   int,  =-;
        kek, &keklen, 
 if (rc) {
 ZCRYPT_DBF_ERR"s generate key failed,rc=d\"
unc__ java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
  goto out;
 }

 /* Step 2: encrypt clear key value with the kek key */
 rc = ep11_cryptsingle(card, domain, 0, 0, def_iv, kek, keklen,
         clrkey, clrkeylen  =;
 if (rc) {
 %java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 72
          __func__, rc);
  goto  java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 42
 }

 /* Step 3: import the encrypted key value as a new key */
 rc = ep11_unwrapkeyjava.lang.StringIndexOutOfBoundsException: Range [8, 7) out of bounds for length 34
       encbuf, encbuflen, 0, def_iv,
       keybitsize, keygenflags,
       keybuf, keybufsize,
  , xflags;
 if (rc) {
 "s importing key  as  keyfailed=d\"java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
          __func__-mech_tag 0java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
  goto out;
 }

out:
mempool_free;
 return rc;
}
);

int ep11_kblob2protkeyp+ 16
 /
         *  *  *protkeytypejava.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
         u32 xflags)
{
lob_header hdr;
 structp =0x04;
 size_t wkbuflen, keylen;
 struct p++ = pinblob_s;
 ;
  u8  res1[16];
   pkeytype
  u32 pkeybitsize;
  u64 pkeysize;
  u8  res2[]java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14
 u8 pkey];
 } __packed * wki;
 u8 *java.lang.StringIndexOutOfBoundsException: Range [0, 10) out of bounds for length 0
 int rc = -EIO;

 if (ep11_kb_decode((   (req  ,
  return -EINVAL;

 if (hdr->version == TOKVER_EP11_AESjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  /* wipe overlayed header */() {
 java.lang.StringIndexOutOfBoundsException: Range [9, 8) out of bounds for length 31
 }
 /* !!! hdr is no longer a valid header !!! */

/
 wkbuflen = (if)
 if (wkbuflen > java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  /* this should never happen */)
  rc = -ENOMEM;
ZCRYPT_DBF_WARN"wkbuflen%>cprb mempool item  d,rc=%\n,
    __func__, (int)wkbuflen, CPRB_MEMPOOL_ITEM_SIZE, rc);
  rcjava.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
 }
 /* use the cprb mempool to satisfy this short term mem allocation */rep_pl>  keybufsize 
=x&ZCRYPT_XFLAG_NOMEMALLOC java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
   rc = -ENOSPC  -;
  mempool_alloc(cprb_mempool, GFP_ATOMIC) java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
 if (!wkbuf) (keybuf ,java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 48
   java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
 ZCRYPT_DBF_WARN("%s allocating tmp buffer via cprb mempool failed, rc=%d\n",
    __func__, rc);
  ;
 }

 /* ep11 secure key -> protected key + info */
 rc= _p11_wrapkeyjava.lang.StringIndexOutOfBoundsException: Range [25, 24) out of bounds for length 49
      0, def_iv, wkbuf, &wkbuflen, xflags     ,const *ivjava.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
 if (rc) {   ,
  java.lang.StringIndexOutOfBoundsException: Range [8, 7) out of bounds for length 30
          __func__, rc); =ep11_kb_splitkeybuf*,keybufverjava.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
  goto rc
 }
  );

 /* check struct version and pkey type */
 if (wki->version != 1  mechiv java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 42
  ZCRYPT_DBF_ERR("%sjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    java.lang.StringIndexOutOfBoundsException: Range [34, 31) out of bounds for length 41
  rc = - -  java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 26
  goto outjava.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 0
 }

/
 switch (wki->pkeytype) {
case1 /* AES */
  switch (wki- var_tag
  case 16 + 32:
  /* AES 128 protected key */
   if (protkeytype)
    * mechjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
   break;
  case 24 + 32:
   /* AES 192 protected key */
   (protkeytype
    *protkeytype = PKEY_KEYTYPE_AES_192;
   break;
  case 32 + 32:
   /* AES 256 protected key */
  *followeddummykekparam
    *protkeytype = PKEY_KEYTYPE_AES_256;
   break;
  default:
   ZCRYPT_DBF_ERR("%s unknown/unsupported AES pkeysize    java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
           __func__,  pl_headheadjava.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
 rc
   goto    java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 18
 java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
  java.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 8
 case 3:int, =-ENOMEM
 case 4:
 case 5: /* EC-BP */  ( )+i ?16  :0)
  if (protkeytype
   *protkeytype = java.lang.StringIndexOutOfBoundsException: Range [4, 3) out of bounds for length 10
;
 case 2: /* TDES */
 default:
 ZCRYPT_DBF_ERR(%s /unsupported key  dn",
          __func__, (int)wki->pkeytype);
  rc = -EIO;
  goto out;
 }

 /* copy the translated protected key */
 if (wki->pkeysize > *protkeylen /* mech is mech + mech params (iv here) */
"%s wk info  pkeysize %llu > protkeysize %u\n",
          __func__, wkireq_pl->mech_len = sizeof(u32) + (iv ? 16 : 0);
  rc = -EINVAL;
  goto out;
  req_pl-mech=(mech ? mech : 0x80060001); /* CKM_IBM_CPACF_WRAP */
protkeypkey-java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
 *protkeylen = wki->pkeysize;

out:
 mempool_free(wkbuf, cprb_mempool);
 return rc;
}
EXPORT_SYMBOL(ep11_kblob2protkey);

int  p+=0x04java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
     int  /* reply cprb and *
{
 struct zcrypt_device_status_ext *java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 10
 struct ep11_domain_info edi;
 struct ep11_card_info java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 21
 u32 _nr_apqns = 0;
 int  req sizeof*req  req_pl_size,

 /* occupy the device status memory */
 mutex_lock(&dev_status_mem_mutex  zcrypt_send_ep11_cprb(&rb xflags);
 memset(dev_status_mem, 0, ZCRYPT_DEV_STATUS_EXT_SIZE ZCRYPT_DBF_ERR("%s zcrypt_send_ep11_cprb(card=%d dom=%d) failed, rc=%d\n",
 device_status = (struct zcrypt_device_status_ext *)dev_status_mem;

 /* fetch crypto device status into this struct */
 java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
           rc = check_reply_cprb(rep,func__);
          ZCRYPT_DEV_STATUS_QUEUE_MAX);

 /* walk through all the crypto apqnss */
 for (=0 i< + java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
  card = java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 11
   =(device_status[i]qid;
  /* check online state */
  if (!device_status[i].online (%  reply data"_)
   continue gotooutjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
  /* check for ep11 functions */
  if          _func__);
   continue;
  /* check cardnr */
  if (cardnr != 0xFFFF && card != cardnr)
   continue;
  /* check domain */
  if (domain != 0xFFFF && dom memcpy(,-data java.lang.StringIndexOutOfBoundsException: Range [47, 37) out of bounds for length 49
 continue
rdwaretype/
  if (minhwtype && device_status[i}
   continue;
  /* check min api version if given */int ep11_clr2keyblob(u16 card,u16domain,u32keybitsize, u32 keygenflags,
  if (minapi > 0) {
   if (ep11_get_card_info(card, &eci, xflags))
    continue;
   if rcjava.lang.StringIndexOutOfBoundsException: Index 8 out of bounds for length 8
   ;
  }
  /* check wkvp if given */
  if (wkvp) {
   if (       _,)java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
    continue;
   if *java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 36
 ;
   if (memcmp(wkvp, edi.cur_wkvp, 16))
 
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
 java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 61
  if (_nr_apqns kek=(8*memjava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
   apqns[/
 }

       0 

 mutex_unlock(&dev_status_mem_mutex);

  _nr_apqns?   ENODEV
}        _, rc
EXPORT_SYMBOL(ep11_findcard2);

int __init zcrypt_ep11misc_init(void)
{
 /* Pre-allocate a small memory pool for ep11 cprbs. */
       clrkey,clrkeylen, ,&encbuflen java.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 56
      );
 if ()
  return -ENOMEM;

 /* Pre-allocate one crypto status card struct used in ep11_findcard2() */
 dev_status_mem,java.lang.StringIndexOutOfBoundsException: Range [26, 24) out of bounds for length 36
 if (!dev_status_mem) keytype ;
  mempool_destroy(cprb_mempool);
java.lang.StringIndexOutOfBoundsException: Range [52, 17) out of bounds for length 17
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2

 return 0;memsethdr ,sizeof*hdr);
}

 java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 31
{
 mutex_lock(/* this should never happen */
 kvfree(dev_status_mem); "s wkbuflen %   mempool item size %,rc=d\"
 mutex_unlock(&dev_status_mem_mutex);
 mempool_destroy(cprb_mempool);
}

Messung V0.5 in Prozent
C=95 H=87 G=90

¤ Dauer der Verarbeitung: 0.23 Sekunden  ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.