diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index e43f340..271d9a8 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -42,10 +42,6 @@ set(GNS_PROTOS ) set(GNS_SRCS - "common/crypto_bcrypt.cpp" - "common/crypto_openssl.cpp" - "common/crypto_25519_donna.cpp" - "common/crypto_25519_openssl.cpp" "common/crypto_textencode.cpp" "common/keypair.cpp" "common/steamid.cpp" @@ -69,9 +65,14 @@ set(GNS_SRCS ) if(GNS_CRYPTO_25519_OPENSSL) - # No additional sources needed! -elseif(GNS_CRYPTO_25519_REF) + target_compile_definitions(${GNS_TARGET} PRIVATE STEAMNETWORKINGSOCKETS_CRYPTO_25519_OPENSSL) set(GNS_SRCS ${GNS_SRCS} + "common/crypto_25519_openssl.cpp" + ) +elseif(GNS_CRYPTO_25519_REF) + target_compile_definitions(${GNS_TARGET} PRIVATE VALVE_CRYPTO_25519_DONNA) + set(GNS_SRCS ${GNS_SRCS} + "common/crypto_25519_donna.cpp" "external/curve25519-donna/curve25519.c" "external/curve25519-donna/curve25519_VALVE_sse2.c" "external/ed25519-donna/ed25519_VALVE.c" @@ -82,11 +83,16 @@ else() endif() if(GNS_CRYPTO_AES_OPENSSL) + target_compile_definitions(${GNS_TARGET} PRIVATE STEAMNETWORKINGSOCKETS_CRYPTO_VALVEOPENSSL) set(GNS_SRCS ${GNS_SRCS} + "common/crypto_openssl.cpp" "common/opensslwrapper.cpp" ) elseif(GNS_CRYPTO_AES_BCRYPT) - # No additional sources + target_compile_definitions(${GNS_TARGET} PRIVATE STEAMNETWORKINGSOCKETS_CRYPTO_BCRYPT) + set(GNS_SRCS ${GNS_SRCS} + "common/crypto_bcrypt.cpp" + ) else() message(FATAL_ERROR "Unknown AES implementation") endif() @@ -281,6 +287,4 @@ target_compile_definitions(GameNetworkingSockets_s INTERFACE STEAMNETWORKINGSOCK gamenetworkingsockets_common(GameNetworkingSockets_s) add_sanitizers(GameNetworkingSockets_s) -configure_file(gnsconfig.h.in.cmake gnsconfig.h) - # vim: set ts=4 sts=4 sw=4 noet: diff --git a/src/common/crypto_25519_donna.cpp b/src/common/crypto_25519_donna.cpp index cf3b79d..35b7705 100644 --- a/src/common/crypto_25519_donna.cpp +++ b/src/common/crypto_25519_donna.cpp @@ -1,10 +1,8 @@ //========= Copyright Valve LLC, All rights reserved. ======================== -#include "gnsconfig.h" - -#ifdef GNS_CRYPTO_25519_REF - #include "crypto.h" +#ifdef VALVE_CRYPTO_25519_DONNA + #ifdef _WIN64 #include "intrin.h" #endif diff --git a/src/common/crypto_25519_openssl.cpp b/src/common/crypto_25519_openssl.cpp index 87c36fe..b31a933 100644 --- a/src/common/crypto_25519_openssl.cpp +++ b/src/common/crypto_25519_openssl.cpp @@ -1,11 +1,8 @@ //========= Copyright Valve LLC, All rights reserved. ======================== - -#include "gnsconfig.h" - -#ifdef GNS_CRYPTO_25519_OPENSSL - #include "crypto.h" +#ifdef STEAMNETWORKINGSOCKETS_CRYPTO_25519_OPENSSL + #include #if OPENSSL_VERSION_NUMBER < 0x10101000 diff --git a/src/common/crypto_bcrypt.cpp b/src/common/crypto_bcrypt.cpp index ec45263..ec0a2d7 100644 --- a/src/common/crypto_bcrypt.cpp +++ b/src/common/crypto_bcrypt.cpp @@ -1,12 +1,10 @@ //========= Copyright Valve LLC, All rights reserved. ======================== +#include "crypto.h" -#include "gnsconfig.h" - -#ifdef GNS_CRYPTO_AES_BCRYPT +#ifdef STEAMNETWORKINGSOCKETS_CRYPTO_BCRYPT #include #include -#include "crypto.h" #include #include @@ -113,12 +111,12 @@ bool AES_GCM_CipherContext::InitCipher( const void *pKey, size_t cbKey, size_t c if (!ctx->pbKeyObject) return false; - if ( (ret = BCryptGenerateSymmetricKey(ctx->hAlgAES, &ctx->hKey, ctx->pbKeyObject, ctx->cbKeyObject, ( PUCHAR )pKey, cbKey, 0 )) != 0 ) + if ( (ret = BCryptGenerateSymmetricKey(ctx->hAlgAES, &ctx->hKey, ctx->pbKeyObject, ctx->cbKeyObject, ( PUCHAR )pKey, (ULONG)cbKey, 0 )) != 0 ) return false; AssertFatal( ctx->hKey != INVALID_HANDLE_VALUE ); - m_cbIV = cbIV; - m_cbTag = cbTag; + m_cbIV = (uint32)cbIV; + m_cbTag = (uint32)cbTag; return true; } @@ -139,12 +137,12 @@ bool AES_GCM_EncryptContext::Encrypt( paddingInfo.cbTag = m_cbTag; paddingInfo.pbNonce = ( PUCHAR )pIV; paddingInfo.cbNonce = m_cbIV; - paddingInfo.cbAuthData = cbAuthenticationData; + paddingInfo.cbAuthData = (ULONG)cbAuthenticationData; paddingInfo.pbAuthData = cbAuthenticationData ? (PUCHAR)pAdditionalAuthenticationData : NULL; ULONG ct_size; NTSTATUS status = BCryptEncrypt( ctx->hKey, - ( PUCHAR )pPlaintextData, cbPlaintextData, + ( PUCHAR )pPlaintextData, (ULONG)cbPlaintextData, &paddingInfo, NULL, 0, ( PUCHAR )pEncryptedDataAndTag, *pcbEncryptedDataAndTag, @@ -176,12 +174,12 @@ bool AES_GCM_DecryptContext::Decrypt( paddingInfo.cbTag = m_cbTag; paddingInfo.pbNonce = (PUCHAR)pIV; paddingInfo.cbNonce = m_cbIV; - paddingInfo.cbAuthData = cbAuthenticationData; + paddingInfo.cbAuthData = (ULONG)cbAuthenticationData; paddingInfo.pbAuthData = cbAuthenticationData ? (PUCHAR)pAdditionalAuthenticationData : NULL; ULONG pt_size; NTSTATUS status = BCryptDecrypt( ctx->hKey, - ( PUCHAR )pEncryptedDataAndTag, cbEncryptedDataAndTag, + ( PUCHAR )pEncryptedDataAndTag, (ULONG)cbEncryptedDataAndTag, &paddingInfo, NULL, 0, ( PUCHAR )pPlaintextData, *pcbPlaintextData, diff --git a/src/common/crypto_openssl.cpp b/src/common/crypto_openssl.cpp index 9b8c0f3..339370a 100644 --- a/src/common/crypto_openssl.cpp +++ b/src/common/crypto_openssl.cpp @@ -1,12 +1,7 @@ //========= Copyright Valve LLC, All rights reserved. ======================== -#include "gnsconfig.h" - -#ifdef GNS_CRYPTO_AES_OPENSSL - -// Note: not using precompiled headers! This file is included directly by -// several different projects and may include Crypto++ headers depending -// on compile-time defines, which in turn pulls in other odd dependencies +#include "crypto.h" +#ifdef STEAMNETWORKINGSOCKETS_CRYPTO_VALVEOPENSSL #if defined(_WIN32) #ifdef __MINGW32__ @@ -33,6 +28,13 @@ #include "opensslwrapper.h" +#if OPENSSL_VERSION_NUMBER < 0x10100000 +inline void EVP_MD_CTX_free( EVP_MD_CTX *ctx ) +{ + EVP_MD_CTX_destroy( ctx ); +} +#endif + void OneTimeCryptoInitOpenSSL() { static bool once; @@ -449,4 +451,4 @@ void CCrypto::GenerateHMAC256( const uint8 *pubData, uint32 cubData, const uint8 VerifyFatal(EVP_DigestSignFinal(mdctx.ctx, *pOutputDigest, &needed) == 1); } -#endif //GNS_CRYPTO_AES_OPENSSL +#endif //STEAMNETWORKINGSOCKETS_CRYPTO_VALVEOPENSSL diff --git a/src/external/curve25519-donna/curve25519-donna-scalarmult-sse2.h b/src/external/curve25519-donna/curve25519-donna-scalarmult-sse2.h index e0ef14c..d45d27f 100644 --- a/src/external/curve25519-donna/curve25519-donna-scalarmult-sse2.h +++ b/src/external/curve25519-donna/curve25519-donna-scalarmult-sse2.h @@ -11,7 +11,7 @@ curve25519_scalarmult_donna(curve25519_key mypublic, const curve25519_key n, con packed32bignum25519 qx, qz, pqz, pqx; packed64bignum25519 nq, sq, sqscalar, prime, primex, primez, nqpq; bignum25519mulprecomp preq; - size_t bit, lastbit, i; + uint32_t bit, lastbit, i; curve25519_expand(nqpqx, basepoint); curve25519_mul_precompute(&preq, nqpqx); diff --git a/src/external/ed25519-donna/ed25519_VALVE.c b/src/external/ed25519-donna/ed25519_VALVE.c index d0914de..806cac2 100644 --- a/src/external/ed25519-donna/ed25519_VALVE.c +++ b/src/external/ed25519-donna/ed25519_VALVE.c @@ -373,34 +373,34 @@ static void ed25519_hash( uint8_t *hash, const uint8_t *in, size_t inlen ) { ed2 -#ifdef _WIN32 -/* Win32 always has RtlGenRandom to act as an entropy source for ed25519_sign_open_batch */ - -#ifndef NO_ED25519_RANDOMBYTES_IMPL -#define WIN32_LEAN_AND_MEAN -#define NOGDI -#include -void ed25519_randombytes_unsafe(void *p, size_t len) { - // the Microsoft CRT imports RtlGenRandom as a direct link to SystemFunction036 in advapi32.dll - // so we can safely do the same - it can never be removed without breaking all VC2010 apps. - static BOOLEAN (WINAPI *pfnRtlGenRandom)( void *, unsigned long ); - if ( !pfnRtlGenRandom ) { - pfnRtlGenRandom = ( BOOLEAN (WINAPI *)( void *, unsigned long ) ) GetProcAddress( LoadLibraryA("advapi32.dll"), "SystemFunction036" ); - } - (*pfnRtlGenRandom)( p, (unsigned long) len ); -} -#endif - -#else - -/* Other platforms - ed25519_sign_open_batch will explode without an entropy source; - remap the function name so that linking will fail, rather than exploding at runtime */ -#define ed25519_sign_open_batch ed25519_sign_open_batch_DO_NOT_USE - -#ifndef NO_ED25519_RANDOMBYTES_IMPL -void ed25519_randombytes_unsafe(void *p, size_t len) { /*boom*/ *(volatile int*)0 = 1; } -#endif - -#endif +//#ifdef _WIN32 +///* Win32 always has RtlGenRandom to act as an entropy source for ed25519_sign_open_batch */ +// +//#ifndef NO_ED25519_RANDOMBYTES_IMPL +//#define WIN32_LEAN_AND_MEAN +//#define NOGDI +//#include +//void ed25519_randombytes_unsafe(void *p, size_t len) { +// // the Microsoft CRT imports RtlGenRandom as a direct link to SystemFunction036 in advapi32.dll +// // so we can safely do the same - it can never be removed without breaking all VC2010 apps. +// static BOOLEAN (WINAPI *pfnRtlGenRandom)( void *, unsigned long ); +// if ( !pfnRtlGenRandom ) { +// pfnRtlGenRandom = ( BOOLEAN (WINAPI *)( void *, unsigned long ) ) GetProcAddress( LoadLibraryA("advapi32.dll"), "SystemFunction036" ); +// } +// (*pfnRtlGenRandom)( p, (unsigned long) len ); +//} +//#endif +// +//#else +// +///* Other platforms - ed25519_sign_open_batch will explode without an entropy source; +// remap the function name so that linking will fail, rather than exploding at runtime */ +//#define ed25519_sign_open_batch ed25519_sign_open_batch_DO_NOT_USE +// +//#ifndef NO_ED25519_RANDOMBYTES_IMPL +//void ed25519_randombytes_unsafe(void *p, size_t len) { /*boom*/ *(volatile int*)0 = 1; } +//#endif +// +//#endif #include "ed25519.c" diff --git a/src/gnsconfig.h.in.cmake b/src/gnsconfig.h.in.cmake deleted file mode 100644 index fca3482..0000000 --- a/src/gnsconfig.h.in.cmake +++ /dev/null @@ -1,11 +0,0 @@ -/* AES-GCM implmented using Windows Crypto API: Next Generation (CNG) functions */ -#cmakedefine GNS_CRYPTO_AES_BCRYPT - -/* AES-GCM implemented using OpenSSL */ -#cmakedefine GNS_CRYPTO_AES_OPENSSL - -/* ed25519/curve25519 using reference C implementation */ -#cmakedefine GNS_CRYPTO_25519_REF - -/* ed25519/curve25519 using OpenSSL implementation */ -#cmakedefine GNS_CRYPTO_25519_OPENSSL \ No newline at end of file diff --git a/src/meson.build b/src/meson.build index e899b5f..4644b11 100644 --- a/src/meson.build +++ b/src/meson.build @@ -31,27 +31,6 @@ if not use_bcrypt endif endif -conf_data = configuration_data() - -conf_data.set('GNS_CRYPTO_AES_BCRYPT', false) -conf_data.set('GNS_CRYPTO_AES_OPENSSL', false) -conf_data.set('GNS_CRYPTO_25519_REF', false) -conf_data.set('GNS_CRYPTO_25519_OPENSSL', false) - -if use_bcrypt - conf_data.set('GNS_CRYPTO_AES_BCRYPT', true) - conf_data.set('GNS_CRYPTO_25519_REF', true) -else - conf_data.set('GNS_CRYPTO_AES_OPENSSL', true) - if good_libcrypto.found() - conf_data.set('GNS_CRYPTO_25519_OPENSSL', true) - else - conf_data.set('GNS_CRYPTO_25519_REF', true) - endif -endif - -configure_file(output: 'gnsconfig.h', configuration: conf_data) - dependencies += [ dep_threads, dependency('protobuf', version: '>=3.0.0'), @@ -81,10 +60,6 @@ protobuf_sources = [ ] sources = [ - 'common/crypto_bcrypt.cpp', - 'common/crypto_openssl.cpp', - 'common/crypto_25519_donna.cpp', - 'common/crypto_25519_openssl.cpp', 'common/crypto_textencode.cpp', 'common/keypair.cpp', 'common/steamid.cpp', @@ -109,16 +84,27 @@ sources = [ if use_bcrypt dependencies += [ c_compiler.find_library('bcrypt') ] - cpp_flags += [ '-DED25519_HASH_BCRYPT' ] + sources += [ 'common/crypto_bcrypt.cpp' ] + cpp_flags += [ '-DED25519_HASH_BCRYPT', '-DSTEAMNETWORKINGSOCKETS_CRYPTO_BCRYPT' ] else + cpp_flags += [ '-DSTEAMNETWORKINGSOCKETS_CRYPTO_VALVEOPENSSL' ] sources += [ 'common/opensslwrapper.cpp', + 'common/crypto_openssl.cpp', ] + + // Use OpenSSL for 25519 if possible + if good_libcrypto.found() + cpp_flags += [ '-DSTEAMNETWORKINGSOCKETS_CRYPTO_25519_OPENSSL' ] + sources += [ 'common/crypto_25519_openssl.cpp' ] + endif endif -# Select 25519 crypto provider +# Use reference 25519 crypto implementation? if use_bcrypt or not good_libcrypto.found() + cpp_flags += [ '-DVALVE_CRYPTO_25519_DONNA' ] sources += [ + 'common/crypto_25519_donna.cpp', 'external/curve25519-donna/curve25519.c', 'external/curve25519-donna/curve25519_VALVE_sse2.c', 'external/ed25519-donna/ed25519_VALVE.c',