2014-08-25 10:18:34 +00:00
|
|
|
/*
|
2014-05-06 14:23:05 +00:00
|
|
|
* s3fs - FUSE-based file system backed by Amazon S3
|
|
|
|
*
|
2017-05-07 11:24:17 +00:00
|
|
|
* Copyright(C) 2007 Randy Rizun <rrizun@gmail.com>
|
2014-05-06 14:23:05 +00:00
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version 2
|
|
|
|
* of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
*/
|
|
|
|
|
2023-11-19 01:00:16 +00:00
|
|
|
#include <cerrno>
|
|
|
|
#include <cstdio>
|
|
|
|
#include <cstdlib>
|
|
|
|
#include <cstring>
|
2014-05-06 14:23:05 +00:00
|
|
|
#include <pthread.h>
|
|
|
|
#include <unistd.h>
|
|
|
|
#include <syslog.h>
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include <nss.h>
|
|
|
|
#include <pk11pub.h>
|
|
|
|
#include <hasht.h>
|
|
|
|
#include <prinit.h>
|
|
|
|
#include <string>
|
|
|
|
#include <map>
|
|
|
|
|
|
|
|
#include "common.h"
|
2020-08-22 12:40:53 +00:00
|
|
|
#include "s3fs.h"
|
2014-05-06 14:23:05 +00:00
|
|
|
#include "s3fs_auth.h"
|
2022-07-30 03:06:47 +00:00
|
|
|
#include "s3fs_logger.h"
|
2014-05-06 14:23:05 +00:00
|
|
|
|
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for version
|
|
|
|
//-------------------------------------------------------------------
|
2019-01-23 23:44:50 +00:00
|
|
|
const char* s3fs_crypt_lib_name()
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2023-11-14 13:15:17 +00:00
|
|
|
static constexpr char version[] = "NSS";
|
2014-05-06 14:23:05 +00:00
|
|
|
|
2020-08-22 12:40:53 +00:00
|
|
|
return version;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for global init
|
|
|
|
//-------------------------------------------------------------------
|
2019-01-23 23:44:50 +00:00
|
|
|
bool s3fs_init_global_ssl()
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
PR_Init(PR_USER_THREAD, PR_PRIORITY_NORMAL, 0);
|
2018-05-27 10:48:03 +00:00
|
|
|
|
2023-07-27 12:56:58 +00:00
|
|
|
if(SECSuccess != NSS_NoDB_Init(nullptr)){
|
2020-08-22 12:40:53 +00:00
|
|
|
S3FS_PRN_ERR("Failed NSS_NoDB_Init call.");
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
return true;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
2019-01-23 23:44:50 +00:00
|
|
|
bool s3fs_destroy_global_ssl()
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
NSS_Shutdown();
|
|
|
|
PL_ArenaFinish();
|
|
|
|
PR_Cleanup();
|
|
|
|
return true;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for crypt lock
|
|
|
|
//-------------------------------------------------------------------
|
2019-01-23 23:44:50 +00:00
|
|
|
bool s3fs_init_crypt_mutex()
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
return true;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
2019-01-23 23:44:50 +00:00
|
|
|
bool s3fs_destroy_crypt_mutex()
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
return true;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for HMAC
|
|
|
|
//-------------------------------------------------------------------
|
2023-08-19 14:29:00 +00:00
|
|
|
static std::unique_ptr<unsigned char[]> s3fs_HMAC_RAW(const void* key, size_t keylen, const unsigned char* data, size_t datalen, unsigned int* digestlen, bool is_sha256)
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2023-08-19 14:29:00 +00:00
|
|
|
if(!key || !data || !digestlen){
|
|
|
|
return nullptr;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
PK11SlotInfo* Slot;
|
|
|
|
PK11SymKey* pKey;
|
|
|
|
PK11Context* Context;
|
|
|
|
unsigned char tmpdigest[64];
|
|
|
|
SECItem KeySecItem = {siBuffer, reinterpret_cast<unsigned char*>(const_cast<void*>(key)), static_cast<unsigned int>(keylen)};
|
2023-07-27 12:56:58 +00:00
|
|
|
SECItem NullSecItem = {siBuffer, nullptr, 0};
|
2020-08-22 12:40:53 +00:00
|
|
|
|
2023-07-27 12:56:58 +00:00
|
|
|
if(nullptr == (Slot = PK11_GetInternalKeySlot())){
|
2023-08-19 14:29:00 +00:00
|
|
|
return nullptr;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
2023-07-27 12:56:58 +00:00
|
|
|
if(nullptr == (pKey = PK11_ImportSymKey(Slot, (is_sha256 ? CKM_SHA256_HMAC : CKM_SHA_1_HMAC), PK11_OriginUnwrap, CKA_SIGN, &KeySecItem, nullptr))){
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_FreeSlot(Slot);
|
2023-08-19 14:29:00 +00:00
|
|
|
return nullptr;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
2023-07-27 12:56:58 +00:00
|
|
|
if(nullptr == (Context = PK11_CreateContextBySymKey((is_sha256 ? CKM_SHA256_HMAC : CKM_SHA_1_HMAC), CKA_SIGN, pKey, &NullSecItem))){
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_FreeSymKey(pKey);
|
|
|
|
PK11_FreeSlot(Slot);
|
2023-08-19 14:29:00 +00:00
|
|
|
return nullptr;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
*digestlen = 0;
|
|
|
|
if(SECSuccess != PK11_DigestBegin(Context) ||
|
|
|
|
SECSuccess != PK11_DigestOp(Context, data, datalen) ||
|
|
|
|
SECSuccess != PK11_DigestFinal(Context, tmpdigest, digestlen, sizeof(tmpdigest)) )
|
|
|
|
{
|
|
|
|
PK11_DestroyContext(Context, PR_TRUE);
|
|
|
|
PK11_FreeSymKey(pKey);
|
|
|
|
PK11_FreeSlot(Slot);
|
2023-08-19 14:29:00 +00:00
|
|
|
return nullptr;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
2014-05-06 14:23:05 +00:00
|
|
|
PK11_DestroyContext(Context, PR_TRUE);
|
|
|
|
PK11_FreeSymKey(pKey);
|
|
|
|
PK11_FreeSlot(Slot);
|
|
|
|
|
2023-08-19 14:29:00 +00:00
|
|
|
std::unique_ptr<unsigned char[]> digest(new unsigned char[*digestlen]);
|
|
|
|
memcpy(digest.get(), tmpdigest, *digestlen);
|
2014-05-06 14:23:05 +00:00
|
|
|
|
2023-08-19 14:29:00 +00:00
|
|
|
return digest;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
2023-08-19 14:29:00 +00:00
|
|
|
std::unique_ptr<unsigned char[]> s3fs_HMAC(const void* key, size_t keylen, const unsigned char* data, size_t datalen, unsigned int* digestlen)
|
2015-02-02 16:36:08 +00:00
|
|
|
{
|
2023-08-19 14:29:00 +00:00
|
|
|
return s3fs_HMAC_RAW(key, keylen, data, datalen, digestlen, false);
|
2015-02-02 16:36:08 +00:00
|
|
|
}
|
|
|
|
|
2023-08-19 14:29:00 +00:00
|
|
|
std::unique_ptr<unsigned char[]> s3fs_HMAC256(const void* key, size_t keylen, const unsigned char* data, size_t datalen, unsigned int* digestlen)
|
2015-02-02 16:36:08 +00:00
|
|
|
{
|
2023-08-19 14:29:00 +00:00
|
|
|
return s3fs_HMAC_RAW(key, keylen, data, datalen, digestlen, true);
|
2015-02-02 16:36:08 +00:00
|
|
|
}
|
|
|
|
|
2014-05-06 14:23:05 +00:00
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for MD5
|
|
|
|
//-------------------------------------------------------------------
|
2023-08-06 15:17:15 +00:00
|
|
|
bool s3fs_md5(const unsigned char* data, size_t datalen, md5_t* result)
|
|
|
|
{
|
|
|
|
PK11Context* md5ctx;
|
|
|
|
unsigned int md5outlen;
|
|
|
|
md5ctx = PK11_CreateDigestContext(SEC_OID_MD5);
|
|
|
|
|
|
|
|
PK11_DigestOp(md5ctx, data, datalen);
|
|
|
|
PK11_DigestFinal(md5ctx, result->data(), &md5outlen, result->size());
|
|
|
|
PK11_DestroyContext(md5ctx, PR_TRUE);
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2023-08-05 00:36:22 +00:00
|
|
|
bool s3fs_md5_fd(int fd, off_t start, off_t size, md5_t* result)
|
2014-05-06 14:23:05 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11Context* md5ctx;
|
2020-09-12 06:00:23 +00:00
|
|
|
off_t bytes;
|
2020-08-22 12:40:53 +00:00
|
|
|
unsigned int md5outlen;
|
|
|
|
|
|
|
|
if(-1 == size){
|
|
|
|
struct stat st;
|
|
|
|
if(-1 == fstat(fd, &st)){
|
2023-08-05 00:36:22 +00:00
|
|
|
return false;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
2020-09-12 06:00:23 +00:00
|
|
|
size = st.st_size;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
2020-08-22 12:40:53 +00:00
|
|
|
|
|
|
|
md5ctx = PK11_CreateDigestContext(SEC_OID_MD5);
|
|
|
|
|
2020-09-12 06:00:23 +00:00
|
|
|
for(off_t total = 0; total < size; total += bytes){
|
2020-09-14 10:49:45 +00:00
|
|
|
off_t len = 512;
|
|
|
|
unsigned char buf[len];
|
|
|
|
bytes = len < (size - total) ? len : (size - total);
|
2020-08-22 12:40:53 +00:00
|
|
|
bytes = pread(fd, buf, bytes, start + total);
|
|
|
|
if(0 == bytes){
|
|
|
|
// end of file
|
|
|
|
break;
|
|
|
|
}else if(-1 == bytes){
|
|
|
|
// error
|
|
|
|
S3FS_PRN_ERR("file read error(%d)", errno);
|
|
|
|
PK11_DestroyContext(md5ctx, PR_TRUE);
|
2023-08-05 00:36:22 +00:00
|
|
|
return false;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
|
|
|
PK11_DigestOp(md5ctx, buf, bytes);
|
|
|
|
}
|
2023-08-05 00:36:22 +00:00
|
|
|
PK11_DigestFinal(md5ctx, result->data(), &md5outlen, result->size());
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_DestroyContext(md5ctx, PR_TRUE);
|
2014-05-06 14:23:05 +00:00
|
|
|
|
2023-08-05 00:36:22 +00:00
|
|
|
return false;
|
2014-05-06 14:23:05 +00:00
|
|
|
}
|
|
|
|
|
2015-02-02 16:36:08 +00:00
|
|
|
//-------------------------------------------------------------------
|
|
|
|
// Utility Function for SHA256
|
|
|
|
//-------------------------------------------------------------------
|
2023-08-05 00:36:22 +00:00
|
|
|
bool s3fs_sha256(const unsigned char* data, size_t datalen, sha256_t* digest)
|
2015-02-02 16:36:08 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11Context* sha256ctx;
|
|
|
|
unsigned int sha256outlen;
|
|
|
|
sha256ctx = PK11_CreateDigestContext(SEC_OID_SHA256);
|
2015-02-02 16:36:08 +00:00
|
|
|
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_DigestOp(sha256ctx, data, datalen);
|
2023-08-05 00:36:22 +00:00
|
|
|
PK11_DigestFinal(sha256ctx, digest->data(), &sha256outlen, digest->size());
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_DestroyContext(sha256ctx, PR_TRUE);
|
2015-02-02 16:36:08 +00:00
|
|
|
|
2020-08-22 12:40:53 +00:00
|
|
|
return true;
|
2015-02-02 16:36:08 +00:00
|
|
|
}
|
|
|
|
|
2023-08-05 00:36:22 +00:00
|
|
|
bool s3fs_sha256_fd(int fd, off_t start, off_t size, sha256_t* result)
|
2015-02-02 16:36:08 +00:00
|
|
|
{
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11Context* sha256ctx;
|
2020-09-12 06:00:23 +00:00
|
|
|
off_t bytes;
|
2020-08-22 12:40:53 +00:00
|
|
|
unsigned int sha256outlen;
|
|
|
|
|
|
|
|
if(-1 == size){
|
|
|
|
struct stat st;
|
|
|
|
if(-1 == fstat(fd, &st)){
|
2023-08-05 00:36:22 +00:00
|
|
|
return false;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
2020-09-12 06:00:23 +00:00
|
|
|
size = st.st_size;
|
2015-02-02 16:36:08 +00:00
|
|
|
}
|
2020-08-22 12:40:53 +00:00
|
|
|
|
|
|
|
sha256ctx = PK11_CreateDigestContext(SEC_OID_SHA256);
|
|
|
|
|
2020-09-12 06:00:23 +00:00
|
|
|
for(off_t total = 0; total < size; total += bytes){
|
2020-09-14 10:49:45 +00:00
|
|
|
off_t len = 512;
|
|
|
|
unsigned char buf[len];
|
|
|
|
bytes = len < (size - total) ? len : (size - total);
|
2020-08-22 12:40:53 +00:00
|
|
|
bytes = pread(fd, buf, bytes, start + total);
|
|
|
|
if(0 == bytes){
|
|
|
|
// end of file
|
|
|
|
break;
|
|
|
|
}else if(-1 == bytes){
|
|
|
|
// error
|
|
|
|
S3FS_PRN_ERR("file read error(%d)", errno);
|
|
|
|
PK11_DestroyContext(sha256ctx, PR_TRUE);
|
2023-08-05 00:36:22 +00:00
|
|
|
return false;
|
2020-08-22 12:40:53 +00:00
|
|
|
}
|
|
|
|
PK11_DigestOp(sha256ctx, buf, bytes);
|
|
|
|
}
|
2023-08-05 00:36:22 +00:00
|
|
|
PK11_DigestFinal(sha256ctx, result->data(), &sha256outlen, result->size());
|
2020-08-22 12:40:53 +00:00
|
|
|
PK11_DestroyContext(sha256ctx, PR_TRUE);
|
2015-02-02 16:36:08 +00:00
|
|
|
|
2023-08-05 00:36:22 +00:00
|
|
|
return true;
|
2015-02-02 16:36:08 +00:00
|
|
|
}
|
|
|
|
|
2014-09-07 15:08:27 +00:00
|
|
|
/*
|
|
|
|
* Local variables:
|
2020-08-22 12:40:53 +00:00
|
|
|
* tab-width: 4
|
|
|
|
* c-basic-offset: 4
|
2014-09-07 15:08:27 +00:00
|
|
|
* End:
|
2020-08-22 12:40:53 +00:00
|
|
|
* vim600: expandtab sw=4 ts=4 fdm=marker
|
|
|
|
* vim<600: expandtab sw=4 ts=4
|
2014-09-07 15:08:27 +00:00
|
|
|
*/
|