Skip to content

Commit

Permalink
mh_sha1_murmur3_x64_128: return invalid algorithm if FIPS mode is ena…
Browse files Browse the repository at this point in the history
…bled at start of the function

Signed-off-by: Pablo de Lara <pablo.de.lara.guarch@intel.com>
  • Loading branch information
pablodelara authored and tkanteck committed May 2, 2024
1 parent 3e138b3 commit 37eccb0
Show file tree
Hide file tree
Showing 2 changed files with 24 additions and 21 deletions.
21 changes: 9 additions & 12 deletions mh_sha1_murmur3_x64_128/mh_sha1_murmur3_x64_128.c
Original file line number Diff line number Diff line change
Expand Up @@ -79,14 +79,13 @@ int
isal_mh_sha1_murmur3_x64_128_init(struct mh_sha1_murmur3_x64_128_ctx *ctx,
const uint64_t murmur_seed)
{
#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
#ifdef SAFE_PARAM
if (ctx == NULL)
return ISAL_CRYPTO_ERR_NULL_CTX;
#endif

#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
return mh_sha1_murmur3_x64_128_init(ctx, murmur_seed);
#endif
}
Expand All @@ -95,16 +94,15 @@ int
isal_mh_sha1_murmur3_x64_128_update(struct mh_sha1_murmur3_x64_128_ctx *ctx, const void *buffer,
const uint32_t len)
{
#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
#ifdef SAFE_PARAM
if (ctx == NULL)
return ISAL_CRYPTO_ERR_NULL_CTX;
if (buffer == NULL)
return ISAL_CRYPTO_ERR_NULL_SRC;
#endif

#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
return mh_sha1_murmur3_x64_128_update(ctx, buffer, len);
#endif
}
Expand All @@ -113,16 +111,15 @@ int
isal_mh_sha1_murmur3_x64_128_finalize(struct mh_sha1_murmur3_x64_128_ctx *ctx, void *mh_sha1_digest,
void *murmur3_x64_128_digest)
{
#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
#ifdef SAFE_PARAM
if (ctx == NULL)
return ISAL_CRYPTO_ERR_NULL_CTX;
if (mh_sha1_digest == NULL || murmur3_x64_128_digest == NULL)
return ISAL_CRYPTO_ERR_NULL_AUTH;
#endif

#ifdef FIPS_MODE
return ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO;
#else
return mh_sha1_murmur3_x64_128_finalize(ctx, mh_sha1_digest, murmur3_x64_128_digest);
#endif
}
Expand Down
24 changes: 15 additions & 9 deletions mh_sha1_murmur3_x64_128/mh_sha1_murmur3_x64_128_param_test.c
Original file line number Diff line number Diff line change
Expand Up @@ -50,15 +50,17 @@ test_mh_sha1_murmur3_x64_128_init_api(void)
return retval;
}

#ifdef FIPS_MODE
// Check for invalid algorithm error
ret = isal_mh_sha1_murmur3_x64_128_init(ctx, seed);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_init);
#else
// check null ctx
ret = isal_mh_sha1_murmur3_x64_128_init(NULL, seed);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NULL_CTX, func_name, exit_init);

// check valid params
ret = isal_mh_sha1_murmur3_x64_128_init(ctx, seed);
#ifdef FIPS_MODE
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_init);
#else
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NONE, func_name, exit_init);
#endif

Expand Down Expand Up @@ -86,6 +88,11 @@ test_mh_sha1_murmur3_x64_128_update_api(void)
goto exit_update;
}

#ifdef FIPS_MODE
// Check for invalid algorithm error
ret = isal_mh_sha1_murmur3_x64_128_update(ctx, buff, len);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_update);
#else
// check null ctx
ret = isal_mh_sha1_murmur3_x64_128_update(NULL, buff, len);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NULL_CTX, func_name, exit_update);
Expand All @@ -96,9 +103,6 @@ test_mh_sha1_murmur3_x64_128_update_api(void)

// check valid params
ret = isal_mh_sha1_murmur3_x64_128_update(ctx, buff, len);
#ifdef FIPS_MODE
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_update);
#else
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NONE, func_name, exit_update);
#endif

Expand Down Expand Up @@ -126,6 +130,11 @@ test_mh_sha1_murmur3_x64_128_finalize_api(void)
return retval;
}

#ifdef FIPS_MODE
// Check for invalid algorithm error
ret = isal_mh_sha1_murmur3_x64_128_finalize(ctx, mh_sha1_digest, murmur3_x64_128_digest);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_finalize);
#else
// check null ctx
ret = isal_mh_sha1_murmur3_x64_128_finalize(NULL, mh_sha1_digest, murmur3_x64_128_digest);
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NULL_CTX, func_name, exit_finalize);
Expand All @@ -140,9 +149,6 @@ test_mh_sha1_murmur3_x64_128_finalize_api(void)

// check valid params
ret = isal_mh_sha1_murmur3_x64_128_finalize(ctx, mh_sha1_digest, murmur3_x64_128_digest);
#ifdef FIPS_MODE
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_FIPS_INVALID_ALGO, func_name, exit_finalize);
#else
CHECK_RETURN_GOTO(ret, ISAL_CRYPTO_ERR_NONE, func_name, exit_finalize);
#endif

Expand Down

0 comments on commit 37eccb0

Please sign in to comment.