8#include <botan/roughtime.h>
10#include <botan/base64.h>
11#include <botan/hash.h>
12#include <botan/mem_ops.h>
13#include <botan/pubkey.h>
15#include <botan/internal/socket_udp.h>
16#include <botan/internal/stl_util.h>
29struct is_array : std::false_type {};
31template <
class T, std::
size_t N>
32struct is_array<std::array<T, N>> : std::true_type {};
35T impl_from_little_endian(
const uint8_t* t,
const size_t i)
36 requires(
sizeof(T) <=
sizeof(int64_t))
38 return T(
static_cast<int64_t
>(t[i]) << i * 8) + (i == 0 ? T(0) : impl_from_little_endian<T>(t, i - 1));
42T from_little_endian(
const uint8_t* t) {
43 return impl_from_little_endian<T>(t,
sizeof(T) - 1);
47T copy(
const uint8_t* t)
48 requires(is_array<T>::value)
54T copy(
const uint8_t* t)
55 requires(!is_array<T>::value)
58 return from_little_endian<T>(t);
62std::map<std::string, std::vector<uint8_t>> unpack_roughtime_packet(T bytes) {
63 if(bytes.size() < 8) {
66 const auto buf = bytes.data();
67 const uint32_t num_tags = buf[0];
68 const uint32_t start_content = num_tags * 8;
69 if(start_content > bytes.size()) {
72 uint32_t start = start_content;
73 std::map<std::string, std::vector<uint8_t>> tags;
74 for(uint32_t i = 0; i < num_tags; ++i) {
76 ((i + 1) == num_tags) ? bytes.size() : start_content + from_little_endian<uint32_t>(buf + 4 + i * 4);
77 if(end > bytes.size()) {
84 const char label[] = {label_ptr[0], label_ptr[1], label_ptr[2], label_ptr[3], 0};
85 auto ret = tags.emplace(label, std::vector<uint8_t>(buf + start, buf + end));
89 start =
static_cast<uint32_t
>(end);
95T get(
const std::map<std::string, std::vector<uint8_t>>& map,
const std::string& label) {
96 const auto& tag = map.find(label);
97 if(tag == map.end()) {
100 if(tag->second.size() !=
sizeof(T)) {
103 return copy<T>(tag->second.data());
106const std::vector<uint8_t>& get_v(
const std::map<std::string, std::vector<uint8_t>>& map,
const std::string& label) {
107 const auto& tag = map.find(label);
108 if(tag == map.end()) {
115 const std::vector<uint8_t>& payload,
116 const std::array<uint8_t, 64>& signature) {
117 constexpr std::string_view context(
"RoughTime v1 response signature\0", 32);
120 verifier.update(context);
121 verifier.update(payload);
122 return verifier.check_signature(signature.data(), signature.size());
125std::array<uint8_t, 64> hashLeaf(
const std::array<uint8_t, 64>& leaf) {
126 std::array<uint8_t, 64> ret{};
129 hash->update(leaf.data(), leaf.size());
130 hash->final(ret.data());
134void hashNode(std::span<uint8_t, 64> hash, std::span<const uint8_t, 64> node,
bool reverse) {
138 h->update(node.data(), node.size());
139 h->update(hash.data(), hash.size());
141 h->update(hash.data(), hash.size());
142 h->update(node.data(), node.size());
144 h->final(hash.data());
147template <
size_t N,
typename T>
148std::array<uint8_t, N> vector_to_array(std::vector<uint8_t, T> vec) {
149 if(vec.size() != N) {
150 throw std::logic_error(
"Invalid vector size");
159 if(nonce.size() != 64) {
168 std::array<uint8_t, request_min_size> buf = {{2, 0, 0, 0, 64, 0, 0, 0,
'N',
'O',
'N',
'C',
'P',
'A',
'D', 0xff}};
170 std::memset(buf.data() + 16 + nonce.
get_nonce().size(), 0, buf.size() - 16 - nonce.
get_nonce().size());
175 const auto response_v = unpack_roughtime_packet(response);
176 const auto cert = unpack_roughtime_packet(get_v(response_v,
"CERT"));
177 const auto cert_dele = get<std::array<uint8_t, 72>>(cert,
"DELE");
178 const auto cert_sig = get<std::array<uint8_t, 64>>(cert,
"SIG");
179 const auto cert_dele_v = unpack_roughtime_packet(cert_dele);
180 const auto srep = get_v(response_v,
"SREP");
181 const auto srep_v = unpack_roughtime_packet(srep);
183 const auto cert_dele_pubk = get<std::array<uint8_t, 32>>(cert_dele_v,
"PUBK");
184 const auto sig = get<std::array<uint8_t, 64>>(response_v,
"SIG");
189 const auto indx = get<uint32_t>(response_v,
"INDX");
190 const auto path = get_v(response_v,
"PATH");
191 const auto srep_root = get<std::array<uint8_t, 64>>(srep_v,
"ROOT");
192 const size_t size = path.size();
193 const size_t levels = size / 64;
196 throw Roughtime_Error(
"Merkle tree path size must be multiple of 64 bytes");
198 if(indx >= (1U << levels)) {
205 for(std::size_t level = 0; level < levels; ++level) {
206 hashNode(hash, slicer.
take<64>(), index % 2 == 1);
210 if(srep_root != hash) {
214 const auto cert_dele_maxt =
sys_microseconds64(get<microseconds64>(cert_dele_v,
"MAXT"));
215 const auto cert_dele_mint =
sys_microseconds64(get<microseconds64>(cert_dele_v,
"MINT"));
217 const auto srep_radi = get<microseconds32>(srep_v,
"RADI");
218 if(srep_midp < cert_dele_mint) {
221 if(srep_midp > cert_dele_maxt) {
224 return {cert_dele, cert_sig, srep_midp, srep_radi};
228 constexpr std::string_view context(
"RoughTime v1 delegation signature--\0", 36);
231 verifier.
update(m_cert_dele.data(), m_cert_dele.size());
236 std::array<uint8_t, 64> ret{};
237 const auto blind_arr = blind.
get_nonce();
239 hash->update(previous_response);
240 hash->update(hash->final());
241 hash->update(blind_arr.data(), blind_arr.size());
242 hash->final(ret.data());
248 std::istringstream ss{std::string(str)};
249 const std::string ERROR_MESSAGE =
"Line does not have 4 space separated fields";
250 for(std::string s; std::getline(ss, s);) {
253 end = s.find(
' ', start);
254 if(end == std::string::npos) {
257 const auto publicKeyType = s.substr(start, end - start);
258 if(publicKeyType !=
"ed25519") {
263 end = s.find(
' ', start);
264 if(end == std::string::npos) {
270 end = s.find(
' ', start);
271 if(end == std::string::npos) {
274 if((end - start) != 88) {
277 const auto vec =
base64_decode(s.substr(start, end - start));
278 const auto nonceOrBlind =
Nonce(vector_to_array<64>(
base64_decode(s.substr(start, end - start))));
281 end = s.find(
' ', start);
282 if(end != std::string::npos) {
287 m_links.push_back({response, serverPublicKey, nonceOrBlind});
293 for(
size_t i = 0; i < m_links.size(); ++i) {
294 const auto& l = m_links[i];
295 const auto nonce = i > 0 ?
nonce_from_blind(m_links[i - 1].response(), l.nonce_or_blind()) : l.nonce_or_blind();
297 if(!response.validate(l.public_key())) {
306 return m_links.empty() ? blind :
nonce_from_blind(m_links.back().response(), blind);
310 if(max_chain_size <= 0) {
314 while(m_links.size() >= max_chain_size) {
315 if(m_links.size() == 1) {
316 auto new_link_updated = new_link;
320 m_links.push_back(new_link_updated);
323 if(m_links.size() >= 2) {
324 m_links[1].nonce_or_blind() =
327 m_links.erase(m_links.begin());
329 m_links.push_back(new_link);
334 s.reserve((7 + 1 + 88 + 1 + 44 + 1 + 480) * m_links.size());
335 for(
const auto& link : m_links) {
340 s +=
base64_encode(link.nonce_or_blind().get_nonce().data(), link.nonce_or_blind().get_nonce().size());
348std::vector<uint8_t>
online_request(std::string_view uri,
const Nonce& nonce, std::chrono::milliseconds timeout) {
349 const std::chrono::system_clock::time_point start_time = std::chrono::system_clock::now();
356 socket->write(encoded.data(), encoded.size());
358 if(std::chrono::system_clock::now() - start_time > timeout) {
362 std::vector<uint8_t> buffer;
363 buffer.resize(360 + 64 * 10 + 1);
365 const auto n = socket->read(buffer.data(), buffer.size());
367 if(n == 0 || std::chrono::system_clock::now() - start_time > timeout) {
371 if(n == buffer.size()) {
380 std::vector<Server_Information> servers;
381 std::istringstream ss{std::string(str)};
383 const std::string ERROR_MESSAGE =
"Line does not have at least 5 space separated fields";
384 for(std::string s; std::getline(ss, s);) {
387 end = s.find(
' ', start);
388 if(end == std::string::npos) {
391 const auto name = s.substr(start, end - start);
394 end = s.find(
' ', start);
395 if(end == std::string::npos) {
398 const auto publicKeyType = s.substr(start, end - start);
399 if(publicKeyType !=
"ed25519") {
404 end = s.find(
' ', start);
406 if(end == std::string::npos) {
409 const auto publicKeyBase64 = s.substr(start, end - start);
413 end = s.find(
' ', start);
414 if(end == std::string::npos) {
417 const auto protocol = s.substr(start, end - start);
418 if(protocol !=
"udp") {
422 const auto addresses = [&]() {
423 std::vector<std::string> addr;
426 end = s.find(
' ', start);
427 const auto address = s.substr(start, (end == std::string::npos) ? std::string::npos : end - start);
428 if(address.empty()) {
431 addr.push_back(address);
432 if(end == std::string::npos) {
437 if(addresses.empty()) {
441 servers.push_back({name, publicKey, addresses});
std::span< const uint8_t > take(const size_t count)
static std::unique_ptr< HashFunction > create_or_throw(std::string_view algo_spec, std::string_view provider="")
bool check_signature(const uint8_t sig[], size_t length)
void append(const Link &new_link, size_t max_chain_size)
std::string to_string() const
Nonce next_nonce(const Nonce &blind) const
std::vector< Response > responses() const
const Nonce & nonce_or_blind() const
const std::array< uint8_t, 64 > & get_nonce() const
std::chrono::time_point< std::chrono::system_clock, microseconds64 > sys_microseconds64
static Response from_bits(const std::vector< uint8_t > &response, const Nonce &nonce)
bool validate(const Ed25519_PublicKey &pk) const
std::unique_ptr< SocketUDP > BOTAN_TEST_API open_socket_udp(std::string_view hostname, std::string_view service, std::chrono::microseconds timeout)
std::vector< Server_Information > servers_from_str(std::string_view str)
std::vector< uint8_t > online_request(std::string_view uri, const Nonce &nonce, std::chrono::milliseconds timeout)
Nonce nonce_from_blind(const std::vector< uint8_t > &previous_response, const Nonce &blind)
std::array< uint8_t, request_min_size > encode_request(const Nonce &nonce)
const unsigned request_min_size
size_t base64_encode(char out[], const uint8_t in[], size_t input_length, size_t &input_consumed, bool final_inputs)
size_t base64_decode(uint8_t out[], const char in[], size_t input_length, size_t &input_consumed, bool final_inputs, bool ignore_ws)
std::vector< T > unlock(const secure_vector< T > &in)
bool verify_signature(std::span< const uint8_t, ED448_LEN > pk, bool phflag, std::span< const uint8_t > context, std::span< const uint8_t > sig, std::span< const uint8_t > msg)
Verify a signature(RFC 8032 5.2.7).
const char * cast_uint8_ptr_to_char(const uint8_t *b)
constexpr void typecast_copy(ToR &&out, const FromR &in)