123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285 |
- #ifndef TOR_HS_DESCRIPTOR_H
- #define TOR_HS_DESCRIPTOR_H
- #include <stdint.h>
- #include "or.h"
- #include "address.h"
- #include "container.h"
- #include "crypto.h"
- #include "crypto_ed25519.h"
- #include "ed25519_cert.h"
- #include "torcert.h"
- struct link_specifier_t;
- #define HS_DESC_SUPPORTED_FORMAT_VERSION_MIN 3
- #define HS_DESC_SUPPORTED_FORMAT_VERSION_MAX 3
- #define HS_DESC_DEFAULT_LIFETIME (3 * 60 * 60)
- #define HS_DESC_MAX_LIFETIME (12 * 60 * 60)
- #define HS_DESC_CERT_LIFETIME (54 * 60 * 60)
- #define HS_DESC_ENCRYPTED_SALT_LEN 16
- #define HS_DESC_ENCRYPTED_SECRET_INPUT_LEN \
- ED25519_PUBKEY_LEN + DIGEST256_LEN + sizeof(uint64_t)
- #define HS_DESC_ENCRYPTED_KDF_OUTPUT_LEN \
- CIPHER256_KEY_LEN + CIPHER_IV_LEN + DIGEST256_LEN
- #define HS_DESC_SUPERENC_PLAINTEXT_PAD_MULTIPLE 10000
- #define HS_DESC_MAX_LEN 50000
- #define HS_DESC_ENCRYPTED_KEY_LEN CIPHER256_KEY_LEN
- #define HS_DESC_ENCRYPTED_BIT_SIZE (HS_DESC_ENCRYPTED_KEY_LEN * 8)
- typedef enum {
- HS_DESC_AUTH_ED25519 = 1
- } hs_desc_auth_type_t;
- typedef struct hs_desc_link_specifier_t {
-
- uint8_t type;
-
- union {
-
- tor_addr_port_t ap;
-
- uint8_t legacy_id[DIGEST_LEN];
-
- uint8_t ed25519_id[ED25519_PUBKEY_LEN];
- } u;
- } hs_desc_link_specifier_t;
- typedef struct hs_desc_intro_point_t {
-
- smartlist_t *link_specifiers;
-
- curve25519_public_key_t onion_key;
-
- tor_cert_t *auth_key_cert;
-
- curve25519_public_key_t enc_key;
-
- tor_cert_t *enc_key_cert;
-
- struct {
-
- crypto_pk_t *key;
-
- struct {
- uint8_t *encoded;
- size_t len;
- } cert;
- } legacy;
-
- unsigned int cross_certified : 1;
- } hs_desc_intro_point_t;
- typedef struct hs_desc_encrypted_data_t {
-
- unsigned int create2_ntor : 1;
-
- smartlist_t *intro_auth_types;
-
- unsigned int single_onion_service : 1;
-
- smartlist_t *intro_points;
- } hs_desc_encrypted_data_t;
- typedef struct hs_desc_plaintext_data_t {
-
- uint32_t version;
-
- uint32_t lifetime_sec;
-
- tor_cert_t *signing_key_cert;
-
- ed25519_public_key_t signing_pubkey;
-
- ed25519_public_key_t blinded_pubkey;
-
- uint64_t revision_counter;
-
- uint8_t *superencrypted_blob;
-
- size_t superencrypted_blob_size;
- } hs_desc_plaintext_data_t;
- typedef struct hs_descriptor_t {
-
- hs_desc_plaintext_data_t plaintext_data;
-
- hs_desc_encrypted_data_t encrypted_data;
-
- uint8_t subcredential[DIGEST256_LEN];
- } hs_descriptor_t;
- static inline int
- hs_desc_is_supported_version(uint32_t version)
- {
- if (version < HS_DESC_SUPPORTED_FORMAT_VERSION_MIN ||
- version > HS_DESC_SUPPORTED_FORMAT_VERSION_MAX) {
- return 0;
- }
- return 1;
- }
- void hs_descriptor_free_(hs_descriptor_t *desc);
- #define hs_descriptor_free(desc) \
- FREE_AND_NULL(hs_descriptor_t, hs_descriptor_free_, (desc))
- void hs_desc_plaintext_data_free_(hs_desc_plaintext_data_t *desc);
- #define hs_desc_plaintext_data_free(desc) \
- FREE_AND_NULL(hs_desc_plaintext_data_t, hs_desc_plaintext_data_free_, (desc))
- void hs_desc_encrypted_data_free_(hs_desc_encrypted_data_t *desc);
- #define hs_desc_encrypted_data_free(desc) \
- FREE_AND_NULL(hs_desc_encrypted_data_t, hs_desc_encrypted_data_free_, (desc))
- void hs_desc_link_specifier_free_(hs_desc_link_specifier_t *ls);
- #define hs_desc_link_specifier_free(ls) \
- FREE_AND_NULL(hs_desc_link_specifier_t, hs_desc_link_specifier_free_, (ls))
- hs_desc_link_specifier_t *hs_desc_link_specifier_new(
- const extend_info_t *info, uint8_t type);
- void hs_descriptor_clear_intro_points(hs_descriptor_t *desc);
- MOCK_DECL(int,
- hs_desc_encode_descriptor,(const hs_descriptor_t *desc,
- const ed25519_keypair_t *signing_kp,
- char **encoded_out));
- int hs_desc_decode_descriptor(const char *encoded,
- const uint8_t *subcredential,
- hs_descriptor_t **desc_out);
- int hs_desc_decode_plaintext(const char *encoded,
- hs_desc_plaintext_data_t *plaintext);
- int hs_desc_decode_encrypted(const hs_descriptor_t *desc,
- hs_desc_encrypted_data_t *desc_out);
- size_t hs_desc_obj_size(const hs_descriptor_t *data);
- size_t hs_desc_plaintext_obj_size(const hs_desc_plaintext_data_t *data);
- hs_desc_intro_point_t *hs_desc_intro_point_new(void);
- void hs_desc_intro_point_free_(hs_desc_intro_point_t *ip);
- #define hs_desc_intro_point_free(ip) \
- FREE_AND_NULL(hs_desc_intro_point_t, hs_desc_intro_point_free_, (ip))
- link_specifier_t *hs_desc_lspec_to_trunnel(
- const hs_desc_link_specifier_t *spec);
- #ifdef HS_DESCRIPTOR_PRIVATE
- STATIC char *encode_link_specifiers(const smartlist_t *specs);
- STATIC size_t build_plaintext_padding(const char *plaintext,
- size_t plaintext_len,
- uint8_t **padded_out);
- STATIC smartlist_t *decode_link_specifiers(const char *encoded);
- STATIC hs_desc_intro_point_t *decode_introduction_point(
- const hs_descriptor_t *desc,
- const char *text);
- STATIC int encrypted_data_length_is_valid(size_t len);
- STATIC int cert_is_valid(tor_cert_t *cert, uint8_t type,
- const char *log_obj_type);
- STATIC int desc_sig_is_valid(const char *b64_sig,
- const ed25519_public_key_t *signing_pubkey,
- const char *encoded_desc, size_t encoded_len);
- STATIC size_t decode_superencrypted(const char *message, size_t message_len,
- uint8_t **encrypted_out);
- STATIC void desc_plaintext_data_free_contents(hs_desc_plaintext_data_t *desc);
- MOCK_DECL(STATIC size_t, decrypt_desc_layer,(const hs_descriptor_t *desc,
- const uint8_t *encrypted_blob,
- size_t encrypted_blob_size,
- int is_superencrypted_layer,
- char **decrypted_out));
- #endif
- #endif
|