Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 17 additions & 2 deletions deps/ncrypto/ncrypto.cc
Original file line number Diff line number Diff line change
Expand Up @@ -4401,11 +4401,26 @@ Result<BIOPointer, bool> EVPKeyPointer::writePrivateKey(
break;
}
case PKEncodingType::PKCS8: {
EVP_PKEY* export_key = get();
#if NCRYPTO_USE_OPENSSL3_PROVIDER
// OpenSSL's provider EC PKCS8 encoders temporarily change encoding flags.
// Use an independent key so concurrent exports do not change the source.
EVPKeyPointer key_copy;
if ((isA(KeyAlgorithm::EC) || isA(KeyAlgorithm::SM2)) &&
EVP_PKEY_get0_provider(get()) != nullptr) {
key_copy.reset(EVP_PKEY_dup(get()));
if (!key_copy) {
return Result<BIOPointer, bool>(false,
mark_pop_error_on_return.peekError());
}
export_key = key_copy.get();
}
#endif
switch (config.format) {
case PKFormatType::PEM: {
// Encode PKCS#8 as PEM.
err = PEM_write_bio_PKCS8PrivateKey(bio.get(),
get(),
export_key,
config.cipher,
passphrase.data,
passphrase.len,
Expand All @@ -4415,7 +4430,7 @@ Result<BIOPointer, bool> EVPKeyPointer::writePrivateKey(
}
case PKFormatType::DER: {
err = i2d_PKCS8PrivateKey_bio(bio.get(),
get(),
export_key,
config.cipher,
passphrase.data,
passphrase.len,
Expand Down
2 changes: 0 additions & 2 deletions src/crypto/crypto_ec.cc
Original file line number Diff line number Diff line change
Expand Up @@ -479,7 +479,6 @@ Maybe<void> EcKeyGenTraits::AdditionalConfig(
bool ExportJWKEcKey(Environment* env,
const KeyObjectData& key,
Local<Object> target) {
Mutex::ScopedLock lock(key.mutex());
const auto& m_pkey = key.GetAsymmetricKey();
DCHECK(m_pkey.isA(KeyAlgorithm::EC));

Expand Down Expand Up @@ -624,7 +623,6 @@ KeyObjectData ImportJWKEcKey(Environment* env, Local<Object> jwk) {
bool GetEcKeyDetail(Environment* env,
const KeyObjectData& key,
Local<Object> target) {
Mutex::ScopedLock lock(key.mutex());
const auto& m_pkey = key.GetAsymmetricKey();
DCHECK(m_pkey.isA(KeyAlgorithm::EC));

Expand Down
2 changes: 0 additions & 2 deletions src/crypto/crypto_kem.cc
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,6 @@ KEMEncapsulateJob::KEMEncapsulateJob(Environment* env,
void KEMEncapsulateJob::DoThreadPoolWork() {
ncrypto::ClearErrorOnReturn clear_error_on_return;
AdditionalParams* params = CryptoJob<KEMEncapsulateTraits>::params();
Mutex::ScopedLock lock(params->key.mutex());
auto result = ncrypto::KEM::Encapsulate(params->key.GetAsymmetricKey());
if (result) {
out_.emplace();
Expand Down Expand Up @@ -223,7 +222,6 @@ bool KEMDecapsulateTraits::DeriveBits(Environment* env,
ByteSource* out,
CryptoJobMode mode,
CryptoErrorStore* errors) {
Mutex::ScopedLock lock(params.key.mutex());
const auto& private_key = params.key.GetAsymmetricKey();

return DoKEMDecapsulate(
Expand Down
20 changes: 1 addition & 19 deletions src/crypto/crypto_keys.cc
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,6 @@ KeyObjectData ImportJWKSecretKey(Environment* env, Local<Object> jwk) {
static bool ExportJWKRawKey(Environment* env,
const KeyObjectData& key,
Local<Object> target) {
Mutex::ScopedLock lock(key.mutex());
auto result =
key.GetAsymmetricKey().exportRawJwk(key.GetKeyType() == kKeyTypePrivate);
if (!result) {
Expand Down Expand Up @@ -416,7 +415,6 @@ bool KeyObjectData::ToEncodedPublicKey(
return ExportJWKInner(
env, addRefWithType(KeyType::kKeyTypePublic), *out, false);
} else if (config.format == EVPKeyPointer::PKFormatType::RAW_PUBLIC) {
Mutex::ScopedLock lock(mutex());
const auto& pkey = GetAsymmetricKey();
const auto* algorithm = pkey.getAlgorithm();
if (algorithm == &KeyAlgorithm::EC) {
Expand Down Expand Up @@ -471,7 +469,6 @@ bool KeyObjectData::ToEncodedPrivateKey(
return ExportJWKInner(
env, addRefWithType(KeyType::kKeyTypePrivate), *out, false);
} else if (config.format == EVPKeyPointer::PKFormatType::RAW_PRIVATE) {
Mutex::ScopedLock lock(mutex());
const auto& pkey = GetAsymmetricKey();
const auto* algorithm = pkey.getAlgorithm();
if (algorithm == &KeyAlgorithm::EC) {
Expand All @@ -497,7 +494,6 @@ bool KeyObjectData::ToEncodedPrivateKey(
return Buffer::Copy(env, raw_data.get<const char>(), raw_data.size())
.ToLocal(out);
} else if (config.format == EVPKeyPointer::PKFormatType::RAW_SEED) {
Mutex::ScopedLock lock(mutex());
const auto& pkey = GetAsymmetricKey();
auto raw_data = pkey.rawSeed();
if (!raw_data) {
Expand Down Expand Up @@ -1053,13 +1049,10 @@ KeyObjectData::KeyObjectData(std::nullptr_t)

KeyObjectData::KeyObjectData(ByteSource symmetric_key)
: key_type_(KeyType::kKeyTypeSecret),
mutex_(std::make_shared<Mutex>()),
data_(std::make_shared<Data>(std::move(symmetric_key))) {}

KeyObjectData::KeyObjectData(KeyType type, EVPKeyPointer&& pkey)
: key_type_(type),
mutex_(std::make_shared<Mutex>()),
data_(std::make_shared<Data>(std::move(pkey))) {}
: key_type_(type), data_(std::make_shared<Data>(std::move(pkey))) {}

void KeyObjectData::Data::MemoryInfo(MemoryTracker* tracker) const {
if (asymmetric_key) {
Expand All @@ -1076,11 +1069,6 @@ void KeyObjectData::MemoryInfo(MemoryTracker* tracker) const {
tracker->TrackField("data", data_);
}

Mutex& KeyObjectData::mutex() const {
if (!mutex_) mutex_ = std::make_shared<Mutex>();
return *mutex_.get();
}

KeyObjectData KeyObjectData::CreateSecret(ByteSource key) {
return KeyObjectData(std::move(key));
}
Expand Down Expand Up @@ -1475,7 +1463,6 @@ void KeyObjectHandle::RawPublicKey(
const KeyObjectData& data = key->Data();
CHECK_NE(data.GetKeyType(), kKeyTypeSecret);

Mutex::ScopedLock lock(data.mutex());
const auto& pkey = data.GetAsymmetricKey();

const bool is_raw_supported = pkey.supportsRawPublic();
Expand Down Expand Up @@ -1503,7 +1490,6 @@ void KeyObjectHandle::RawPrivateKey(
const KeyObjectData& data = key->Data();
CHECK_EQ(data.GetKeyType(), kKeyTypePrivate);

Mutex::ScopedLock lock(data.mutex());
const auto& pkey = data.GetAsymmetricKey();

const bool is_raw_supported = pkey.supportsRawPrivate();
Expand Down Expand Up @@ -1531,7 +1517,6 @@ void KeyObjectHandle::ExportECPublicRaw(
const KeyObjectData& data = key->Data();
CHECK_NE(data.GetKeyType(), kKeyTypeSecret);

Mutex::ScopedLock lock(data.mutex());
const auto& m_pkey = data.GetAsymmetricKey();
if (!m_pkey.isA(KeyAlgorithm::EC)) {
return THROW_ERR_CRYPTO_INCOMPATIBLE_KEY_OPTIONS(env);
Expand Down Expand Up @@ -1570,7 +1555,6 @@ void KeyObjectHandle::ExportECPrivateRaw(
const KeyObjectData& data = key->Data();
CHECK_EQ(data.GetKeyType(), kKeyTypePrivate);

Mutex::ScopedLock lock(data.mutex());
const auto& m_pkey = data.GetAsymmetricKey();
if (!m_pkey.isA(KeyAlgorithm::EC)) {
return THROW_ERR_CRYPTO_INCOMPATIBLE_KEY_OPTIONS(env);
Expand All @@ -1593,7 +1577,6 @@ void KeyObjectHandle::ExportECPrivatePkcs8(
ASSIGN_OR_RETURN_UNWRAP(&key, args.This());
const KeyObjectData& data = key->Data();
CHECK_EQ(data.GetKeyType(), kKeyTypePrivate);
Mutex::ScopedLock lock(data.mutex());
auto encoded = ncrypto::Ec::ExportPrivatePkcs8(data.GetAsymmetricKey());
if (!encoded) {
return THROW_ERR_CRYPTO_OPERATION_FAILED(env,
Expand All @@ -1612,7 +1595,6 @@ void KeyObjectHandle::RawSeed(const v8::FunctionCallbackInfo<v8::Value>& args) {
const KeyObjectData& data = key->Data();
CHECK_EQ(data.GetKeyType(), kKeyTypePrivate);

Mutex::ScopedLock lock(data.mutex());
const auto& pkey = data.GetAsymmetricKey();

auto raw_data = pkey.rawSeed();
Expand Down
17 changes: 6 additions & 11 deletions src/crypto/crypto_keys.h
Original file line number Diff line number Diff line change
Expand Up @@ -54,8 +54,8 @@ class KeyObjectData final : public MemoryRetainer {

KeyType GetKeyType() const;

// These functions allow unprotected access to the raw key material and should
// only be used to implement cryptographic operations requiring the key.
// The key material is immutable and can be used concurrently by operations
// with separate contexts.
const ncrypto::EVPKeyPointer& GetAsymmetricKey() const;
const char* GetSymmetricKey() const;
size_t GetSymmetricKeySize() const;
Expand All @@ -64,8 +64,6 @@ class KeyObjectData final : public MemoryRetainer {
SET_MEMORY_INFO_NAME(KeyObjectData)
SET_SELF_SIZE(KeyObjectData)

Mutex& mutex() const;

static v8::Maybe<ncrypto::EVPKeyPointer::PublicKeyEncodingConfig>
GetPublicKeyEncodingFromJs(const v8::FunctionCallbackInfo<v8::Value>& args,
unsigned int* offset,
Expand Down Expand Up @@ -97,11 +95,11 @@ class KeyObjectData final : public MemoryRetainer {
v8::Local<v8::Value>* out);

inline KeyObjectData addRef() const {
return KeyObjectData(key_type_, mutex_, data_);
return KeyObjectData(key_type_, data_);
}

inline KeyObjectData addRefWithType(KeyType type) const {
return KeyObjectData(type, mutex_, data_);
return KeyObjectData(type, data_);
}

private:
Expand All @@ -115,7 +113,6 @@ class KeyObjectData final : public MemoryRetainer {
const char* default_msg);

KeyType key_type_;
mutable std::shared_ptr<Mutex> mutex_;

struct Data final : public MemoryRetainer {
const ByteSource symmetric_key;
Expand All @@ -131,10 +128,8 @@ class KeyObjectData final : public MemoryRetainer {
};
std::shared_ptr<Data> data_;

KeyObjectData(KeyType type,
std::shared_ptr<Mutex> mutex,
std::shared_ptr<Data> data)
: key_type_(type), mutex_(std::move(mutex)), data_(std::move(data)) {}
KeyObjectData(KeyType type, std::shared_ptr<Data> data)
: key_type_(type), data_(std::move(data)) {}
};

class KeyObjectHandle : public BaseObject {
Expand Down
3 changes: 0 additions & 3 deletions src/crypto/crypto_rsa.cc
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,6 @@ WebCryptoCipherStatus RSA_Cipher(Environment* env,
const ByteSource& in,
ByteSource* out) {
CHECK_NE(key_data.GetKeyType(), kKeyTypeSecret);
Mutex::ScopedLock lock(key_data.mutex());
const auto& m_pkey = key_data.GetAsymmetricKey();
const ncrypto::Rsa::CipherParams nparams{
.padding = params.padding,
Expand Down Expand Up @@ -299,7 +298,6 @@ WebCryptoCipherStatus RSACipherTraits::DoCipher(Environment* env,
bool ExportJWKRsaKey(Environment* env,
const KeyObjectData& key,
Local<Object> target) {
Mutex::ScopedLock lock(key.mutex());
const auto& m_pkey = key.GetAsymmetricKey();

const ncrypto::Rsa rsa = m_pkey;
Expand Down Expand Up @@ -527,7 +525,6 @@ KeyObjectData ImportJWKRsaKey(Environment* env, Local<Object> jwk) {
bool GetRsaKeyDetail(Environment* env,
const KeyObjectData& key,
Local<Object> target) {
Mutex::ScopedLock lock(key.mutex());
const auto& m_pkey = key.GetAsymmetricKey();

const auto rsa = ncrypto::Rsa::PublicOnly(m_pkey);
Expand Down
1 change: 0 additions & 1 deletion src/crypto/crypto_sig.cc
Original file line number Diff line number Diff line change
Expand Up @@ -712,7 +712,6 @@ Maybe<void> SignTraits::AdditionalConfig(
}
// If this is an EC key (assuming ECDSA) we need to convert the
// the signature from WebCrypto format into DER format...
Mutex::ScopedLock lock(params->key.mutex());
const auto& akey = params->key.GetAsymmetricKey();
if (UseP1363Encoding(akey, params->dsa_encoding)) {
params->signature = ConvertSignatureToDER(akey, signature.ToByteSource());
Expand Down
Loading
Loading