author | chegar |
Thu, 17 Oct 2019 20:54:25 +0100 | |
branch | datagramsocketimpl-branch |
changeset 58679 | 9c3209ff7550 |
parent 58678 | 9cf78a70fa4f |
parent 55410 | c3b354fdbaa4 |
permissions | -rw-r--r-- |
2 | 1 |
/* |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
2 |
* Copyright (c) 2003, 2019, Oracle and/or its affiliates. All rights reserved. |
2 | 3 |
*/ |
4 |
||
5 |
/* Copyright (c) 2002 Graz University of Technology. All rights reserved. |
|
6 |
* |
|
7 |
* Redistribution and use in source and binary forms, with or without |
|
8 |
* modification, are permitted provided that the following conditions are met: |
|
9 |
* |
|
10 |
* 1. Redistributions of source code must retain the above copyright notice, |
|
11 |
* this list of conditions and the following disclaimer. |
|
12 |
* |
|
13 |
* 2. Redistributions in binary form must reproduce the above copyright notice, |
|
14 |
* this list of conditions and the following disclaimer in the documentation |
|
15 |
* and/or other materials provided with the distribution. |
|
16 |
* |
|
17 |
* 3. The end-user documentation included with the redistribution, if any, must |
|
18 |
* include the following acknowledgment: |
|
19 |
* |
|
20 |
* "This product includes software developed by IAIK of Graz University of |
|
21 |
* Technology." |
|
22 |
* |
|
23 |
* Alternately, this acknowledgment may appear in the software itself, if |
|
24 |
* and wherever such third-party acknowledgments normally appear. |
|
25 |
* |
|
26 |
* 4. The names "Graz University of Technology" and "IAIK of Graz University of |
|
27 |
* Technology" must not be used to endorse or promote products derived from |
|
28 |
* this software without prior written permission. |
|
29 |
* |
|
30 |
* 5. Products derived from this software may not be called |
|
31 |
* "IAIK PKCS Wrapper", nor may "IAIK" appear in their name, without prior |
|
32 |
* written permission of Graz University of Technology. |
|
33 |
* |
|
34 |
* THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESSED OR IMPLIED |
|
35 |
* WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED |
|
36 |
* WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |
|
37 |
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE LICENSOR BE |
|
38 |
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, |
|
39 |
* OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, |
|
40 |
* PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, |
|
41 |
* OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON |
|
42 |
* ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, |
|
43 |
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
|
44 |
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE |
|
45 |
* POSSIBILITY OF SUCH DAMAGE. |
|
46 |
*/ |
|
47 |
||
48 |
#include "pkcs11wrapper.h" |
|
49 |
||
50 |
#include <stdio.h> |
|
51 |
#include <stdlib.h> |
|
52 |
#include <string.h> |
|
53 |
#include <assert.h> |
|
14414
f338be3ef659
8001579: Cleanup warnings in security native code
jzavgren
parents:
14342
diff
changeset
|
54 |
#include "jlong.h" |
2 | 55 |
|
56 |
#include "sun_security_pkcs11_wrapper_PKCS11.h" |
|
57 |
||
58 |
#ifdef P11_ENABLE_C_SIGNINIT |
|
59 |
/* |
|
60 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
61 |
* Method: C_SignInit |
|
62 |
* Signature: (JLsun/security/pkcs11/wrapper/CK_MECHANISM;J)V |
|
63 |
* Parametermapping: *PKCS11* |
|
64 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
65 |
* @param jobject jMechanism CK_MECHANISM_PTR pMechanism |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
66 |
* @param jlong jKeyHandle CK_OBJECT_HANDLE hKey |
2 | 67 |
*/ |
68 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1SignInit |
|
69 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jobject jMechanism, jlong jKeyHandle) |
|
70 |
{ |
|
71 |
CK_SESSION_HANDLE ckSessionHandle; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
72 |
CK_MECHANISM_PTR ckpMechanism = NULL; |
2 | 73 |
CK_OBJECT_HANDLE ckKeyHandle; |
74 |
CK_RV rv; |
|
75 |
||
76 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
77 |
if (ckpFunctions == NULL) { return; } |
|
78 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
79 |
TRACE0("DEBUG: C_SignInit\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
80 |
|
2 | 81 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
82 |
|
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
83 |
ckpMechanism = jMechanismToCKMechanismPtr(env, jMechanism); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
84 |
if ((*env)->ExceptionCheck(env)) { return; } |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
85 |
|
2 | 86 |
ckKeyHandle = jLongToCKULong(jKeyHandle); |
87 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
88 |
rv = (*ckpFunctions->C_SignInit)(ckSessionHandle, ckpMechanism, ckKeyHandle); |
2 | 89 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
90 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK || |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
91 |
(ckpMechanism->pParameter == NULL)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
92 |
freeCKMechanismPtr(ckpMechanism); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
93 |
} else { |
55410
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
94 |
(*env)->SetLongField(env, jMechanism, mech_pHandleID, ptr_to_jlong(ckpMechanism)); |
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
95 |
TRACE1("DEBUG C_SignInit: stored pMech = 0x%lX\n", ptr_to_jlong(ckpMechanism)); |
2 | 96 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
97 |
TRACE0("FINISHED\n"); |
2 | 98 |
} |
99 |
#endif |
|
100 |
||
101 |
#ifdef P11_ENABLE_C_SIGN |
|
102 |
/* |
|
103 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
104 |
* Method: C_Sign |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
105 |
* Signature: (J[BI)[B |
2 | 106 |
* Parametermapping: *PKCS11* |
107 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
108 |
* @param jbyteArray jData CK_BYTE_PTR pData |
|
109 |
* CK_ULONG ulDataLen |
|
110 |
* @return jbyteArray jSignature CK_BYTE_PTR pSignature |
|
111 |
* CK_ULONG_PTR pulSignatureLen |
|
112 |
*/ |
|
113 |
JNIEXPORT jbyteArray JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1Sign |
|
114 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jbyteArray jData) |
|
115 |
{ |
|
116 |
CK_SESSION_HANDLE ckSessionHandle; |
|
117 |
CK_BYTE_PTR ckpData = NULL_PTR; |
|
118 |
CK_ULONG ckDataLength; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
119 |
CK_BYTE_PTR bufP; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
120 |
CK_ULONG ckSignatureLength; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
121 |
CK_BYTE BUF[MAX_STACK_BUFFER_LEN]; |
3321
fed33393bc52
6823905: crash in sun.security.pkcs11.wrapper.PKCS11.C_Sign during stress-test
valeriep
parents:
2180
diff
changeset
|
122 |
jbyteArray jSignature = NULL; |
2 | 123 |
CK_RV rv; |
124 |
||
125 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
126 |
if (ckpFunctions == NULL) { return NULL; } |
|
127 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
128 |
TRACE0("DEBUG: C_Sign\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
129 |
|
2 | 130 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
131 |
jByteArrayToCKByteArray(env, jData, &ckpData, &ckDataLength); |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
132 |
if ((*env)->ExceptionCheck(env)) { |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
133 |
return NULL; |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
134 |
} |
2 | 135 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
136 |
TRACE1("DEBUG C_Sign: data length = %lu\n", ckDataLength); |
2 | 137 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
138 |
// unknown signature length |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
139 |
bufP = BUF; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
140 |
ckSignatureLength = MAX_STACK_BUFFER_LEN; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
141 |
|
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
142 |
rv = (*ckpFunctions->C_Sign)(ckSessionHandle, ckpData, ckDataLength, |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
143 |
bufP, &ckSignatureLength); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
144 |
|
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
145 |
TRACE1("DEBUG C_Sign: ret rv=0x%lX\n", rv); |
2 | 146 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
147 |
if (ckAssertReturnValueOK(env, rv) == CK_ASSERT_OK) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
148 |
jSignature = ckByteArrayToJByteArray(env, bufP, ckSignatureLength); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
149 |
TRACE1("DEBUG C_Sign: signature length = %lu\n", ckSignatureLength); |
2 | 150 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
151 |
|
2 | 152 |
free(ckpData); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
153 |
if (bufP != BUF) { free(bufP); } |
2 | 154 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
155 |
TRACE0("FINISHED\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
156 |
return jSignature; |
2 | 157 |
} |
158 |
#endif |
|
159 |
||
160 |
#ifdef P11_ENABLE_C_SIGNUPDATE |
|
161 |
/* |
|
162 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
163 |
* Method: C_SignUpdate |
|
164 |
* Signature: (J[BII)V |
|
165 |
* Parametermapping: *PKCS11* |
|
166 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
167 |
* @param jbyteArray jPart CK_BYTE_PTR pPart |
|
168 |
* CK_ULONG ulPartLen |
|
169 |
*/ |
|
170 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1SignUpdate |
|
171 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jlong directIn, jbyteArray jIn, jint jInOfs, jint jInLen) |
|
172 |
{ |
|
173 |
CK_SESSION_HANDLE ckSessionHandle; |
|
174 |
CK_RV rv; |
|
175 |
CK_BYTE_PTR bufP; |
|
176 |
CK_BYTE BUF[MAX_STACK_BUFFER_LEN]; |
|
177 |
jsize bufLen; |
|
178 |
||
179 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
180 |
if (ckpFunctions == NULL) { return; } |
|
181 |
||
182 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
183 |
||
184 |
if (directIn != 0) { |
|
14414
f338be3ef659
8001579: Cleanup warnings in security native code
jzavgren
parents:
14342
diff
changeset
|
185 |
rv = (*ckpFunctions->C_SignUpdate)(ckSessionHandle, (CK_BYTE_PTR) jlong_to_ptr(directIn), jInLen); |
2 | 186 |
ckAssertReturnValueOK(env, rv); |
187 |
return; |
|
188 |
} |
|
189 |
||
190 |
if (jInLen <= MAX_STACK_BUFFER_LEN) { |
|
191 |
bufLen = MAX_STACK_BUFFER_LEN; |
|
192 |
bufP = BUF; |
|
193 |
} else { |
|
194 |
bufLen = min(MAX_HEAP_BUFFER_LEN, jInLen); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
195 |
bufP = (CK_BYTE_PTR) malloc((size_t)bufLen); |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
196 |
if (bufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
197 |
throwOutOfMemoryError(env, 0); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
198 |
return; |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
199 |
} |
2 | 200 |
} |
201 |
||
202 |
while (jInLen > 0) { |
|
203 |
jsize chunkLen = min(bufLen, jInLen); |
|
204 |
(*env)->GetByteArrayRegion(env, jIn, jInOfs, chunkLen, (jbyte *)bufP); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
205 |
if ((*env)->ExceptionCheck(env)) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
206 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
207 |
} |
2 | 208 |
rv = (*ckpFunctions->C_SignUpdate)(ckSessionHandle, bufP, chunkLen); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
209 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
210 |
goto cleanup; |
2 | 211 |
} |
212 |
jInOfs += chunkLen; |
|
213 |
jInLen -= chunkLen; |
|
214 |
} |
|
215 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
216 |
cleanup: |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
217 |
if (bufP != BUF) { free(bufP); } |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
218 |
|
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
219 |
return; |
2 | 220 |
} |
221 |
#endif |
|
222 |
||
223 |
#ifdef P11_ENABLE_C_SIGNFINAL |
|
224 |
/* |
|
225 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
226 |
* Method: C_SignFinal |
|
227 |
* Signature: (J)[B |
|
228 |
* Parametermapping: *PKCS11* |
|
229 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
230 |
* @return jbyteArray jSignature CK_BYTE_PTR pSignature |
|
231 |
* CK_ULONG_PTR pulSignatureLen |
|
232 |
*/ |
|
233 |
JNIEXPORT jbyteArray JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1SignFinal |
|
234 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jint jExpectedLength) |
|
235 |
{ |
|
236 |
CK_SESSION_HANDLE ckSessionHandle; |
|
237 |
jbyteArray jSignature = NULL; |
|
238 |
CK_RV rv; |
|
239 |
CK_BYTE BUF[MAX_STACK_BUFFER_LEN]; |
|
240 |
CK_BYTE_PTR bufP = BUF; |
|
241 |
CK_ULONG ckSignatureLength = MAX_STACK_BUFFER_LEN; |
|
242 |
||
243 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
244 |
if (ckpFunctions == NULL) { return NULL; } |
|
245 |
||
246 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
247 |
||
14414
f338be3ef659
8001579: Cleanup warnings in security native code
jzavgren
parents:
14342
diff
changeset
|
248 |
if ((jExpectedLength > 0) && ((CK_ULONG)jExpectedLength < ckSignatureLength)) { |
2 | 249 |
ckSignatureLength = jExpectedLength; |
250 |
} |
|
251 |
||
252 |
rv = (*ckpFunctions->C_SignFinal)(ckSessionHandle, bufP, &ckSignatureLength); |
|
253 |
if (rv == CKR_BUFFER_TOO_SMALL) { |
|
254 |
bufP = (CK_BYTE_PTR) malloc(ckSignatureLength); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
255 |
if (bufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
256 |
throwOutOfMemoryError(env, 0); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
257 |
return NULL; |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
258 |
} |
2 | 259 |
rv = (*ckpFunctions->C_SignFinal)(ckSessionHandle, bufP, &ckSignatureLength); |
260 |
} |
|
261 |
if (ckAssertReturnValueOK(env, rv) == CK_ASSERT_OK) { |
|
262 |
jSignature = ckByteArrayToJByteArray(env, bufP, ckSignatureLength); |
|
263 |
} |
|
264 |
||
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
265 |
if (bufP != BUF) { free(bufP); } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
266 |
|
2 | 267 |
return jSignature; |
268 |
} |
|
269 |
#endif |
|
270 |
||
271 |
#ifdef P11_ENABLE_C_SIGNRECOVERINIT |
|
272 |
/* |
|
273 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
274 |
* Method: C_SignRecoverInit |
|
275 |
* Signature: (JLsun/security/pkcs11/wrapper/CK_MECHANISM;J)V |
|
276 |
* Parametermapping: *PKCS11* |
|
277 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
278 |
* @param jobject jMechanism CK_MECHANISM_PTR pMechanism |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
279 |
* @param jlong jKeyHandle CK_OBJECT_HANDLE hKey |
2 | 280 |
*/ |
281 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1SignRecoverInit |
|
282 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jobject jMechanism, jlong jKeyHandle) |
|
283 |
{ |
|
284 |
CK_SESSION_HANDLE ckSessionHandle; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
285 |
CK_MECHANISM_PTR ckpMechanism = NULL; |
2 | 286 |
CK_OBJECT_HANDLE ckKeyHandle; |
287 |
CK_RV rv; |
|
288 |
||
289 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
290 |
if (ckpFunctions == NULL) { return; } |
|
291 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
292 |
TRACE0("DEBUG: C_SignRecoverInit\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
293 |
|
2 | 294 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
295 |
ckpMechanism = jMechanismToCKMechanismPtr(env, jMechanism); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
296 |
if ((*env)->ExceptionCheck(env)) { return; } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
297 |
|
2 | 298 |
ckKeyHandle = jLongToCKULong(jKeyHandle); |
299 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
300 |
rv = (*ckpFunctions->C_SignRecoverInit)(ckSessionHandle, ckpMechanism, ckKeyHandle); |
2 | 301 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
302 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK || |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
303 |
(ckpMechanism->pParameter == NULL)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
304 |
freeCKMechanismPtr(ckpMechanism); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
305 |
} else { |
55410
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
306 |
(*env)->SetLongField(env, jMechanism, mech_pHandleID, ptr_to_jlong(ckpMechanism)); |
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
307 |
TRACE1("DEBUG C_SignRecoverInit, stored pMech = 0x%lX\n", ptr_to_jlong(ckpMechanism)); |
2 | 308 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
309 |
TRACE0("FINISHED\n"); |
2 | 310 |
} |
311 |
#endif |
|
312 |
||
313 |
#ifdef P11_ENABLE_C_SIGNRECOVER |
|
314 |
/* |
|
315 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
316 |
* Method: C_SignRecover |
|
317 |
* Signature: (J[BII[BII)I |
|
318 |
* Parametermapping: *PKCS11* |
|
319 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
320 |
* @param jbyteArray jData CK_BYTE_PTR pData |
|
321 |
* CK_ULONG ulDataLen |
|
322 |
* @return jbyteArray jSignature CK_BYTE_PTR pSignature |
|
323 |
* CK_ULONG_PTR pulSignatureLen |
|
324 |
*/ |
|
325 |
JNIEXPORT jint JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1SignRecover |
|
326 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jbyteArray jIn, jint jInOfs, jint jInLen, jbyteArray jOut, jint jOutOfs, jint jOutLen) |
|
327 |
{ |
|
328 |
CK_SESSION_HANDLE ckSessionHandle; |
|
329 |
CK_RV rv; |
|
330 |
CK_BYTE INBUF[MAX_STACK_BUFFER_LEN]; |
|
331 |
CK_BYTE OUTBUF[MAX_STACK_BUFFER_LEN]; |
|
332 |
CK_BYTE_PTR inBufP; |
|
333 |
CK_BYTE_PTR outBufP = OUTBUF; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
334 |
CK_ULONG ckSignatureLength = 0; |
2 | 335 |
|
336 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
337 |
if (ckpFunctions == NULL) { return 0; } |
|
338 |
||
339 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
340 |
||
341 |
if (jInLen <= MAX_STACK_BUFFER_LEN) { |
|
342 |
inBufP = INBUF; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
343 |
ckSignatureLength = MAX_STACK_BUFFER_LEN; |
2 | 344 |
} else { |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
345 |
inBufP = (CK_BYTE_PTR) malloc((size_t)jInLen); |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
346 |
if (inBufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
347 |
throwOutOfMemoryError(env, 0); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
348 |
return 0; |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
349 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
350 |
ckSignatureLength = jInLen; |
2 | 351 |
} |
352 |
||
353 |
(*env)->GetByteArrayRegion(env, jIn, jInOfs, jInLen, (jbyte *)inBufP); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
354 |
if ((*env)->ExceptionCheck(env)) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
355 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
356 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
357 |
|
2 | 358 |
rv = (*ckpFunctions->C_SignRecover)(ckSessionHandle, inBufP, jInLen, outBufP, &ckSignatureLength); |
359 |
/* re-alloc larger buffer if it fits into our Java buffer */ |
|
360 |
if ((rv == CKR_BUFFER_TOO_SMALL) && (ckSignatureLength <= jIntToCKULong(jOutLen))) { |
|
361 |
outBufP = (CK_BYTE_PTR) malloc(ckSignatureLength); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
362 |
if (outBufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
363 |
throwOutOfMemoryError(env, 0); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
364 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
365 |
} |
2 | 366 |
rv = (*ckpFunctions->C_SignRecover)(ckSessionHandle, inBufP, jInLen, outBufP, &ckSignatureLength); |
367 |
} |
|
368 |
if (ckAssertReturnValueOK(env, rv) == CK_ASSERT_OK) { |
|
369 |
(*env)->SetByteArrayRegion(env, jOut, jOutOfs, ckSignatureLength, (jbyte *)outBufP); |
|
370 |
} |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
371 |
cleanup: |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
372 |
if (inBufP != INBUF) { free(inBufP); } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
373 |
if (outBufP != OUTBUF) { free(outBufP); } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
374 |
|
2 | 375 |
return ckSignatureLength; |
376 |
} |
|
377 |
#endif |
|
378 |
||
379 |
#ifdef P11_ENABLE_C_VERIFYINIT |
|
380 |
/* |
|
381 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
382 |
* Method: C_VerifyInit |
|
383 |
* Signature: (JLsun/security/pkcs11/wrapper/CK_MECHANISM;J)V |
|
384 |
* Parametermapping: *PKCS11* |
|
385 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
386 |
* @param jobject jMechanism CK_MECHANISM_PTR pMechanism |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
387 |
* @param jlong jKeyHandle CK_OBJECT_HANDLE hKey |
2 | 388 |
*/ |
389 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1VerifyInit |
|
390 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jobject jMechanism, jlong jKeyHandle) |
|
391 |
{ |
|
392 |
CK_SESSION_HANDLE ckSessionHandle; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
393 |
CK_MECHANISM_PTR ckpMechanism = NULL; |
2 | 394 |
CK_OBJECT_HANDLE ckKeyHandle; |
395 |
CK_RV rv; |
|
396 |
||
397 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
398 |
if (ckpFunctions == NULL) { return; } |
|
399 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
400 |
TRACE0("DEBUG: C_VerifyInit\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
401 |
|
2 | 402 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
403 |
ckpMechanism = jMechanismToCKMechanismPtr(env, jMechanism); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
404 |
if ((*env)->ExceptionCheck(env)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
405 |
return; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
406 |
} |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
407 |
|
2 | 408 |
ckKeyHandle = jLongToCKULong(jKeyHandle); |
409 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
410 |
rv = (*ckpFunctions->C_VerifyInit)(ckSessionHandle, ckpMechanism, ckKeyHandle); |
2 | 411 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
412 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK || |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
413 |
(ckpMechanism->pParameter == NULL)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
414 |
freeCKMechanismPtr(ckpMechanism); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
415 |
} else { |
55410
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
416 |
(*env)->SetLongField(env, jMechanism, mech_pHandleID, ptr_to_jlong(ckpMechanism)); |
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
417 |
TRACE1("DEBUG C_VerifyInit: stored pMech = 0x%lX\n", ptr_to_jlong(ckpMechanism)); |
2 | 418 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
419 |
TRACE0("FINISHED\n"); |
2 | 420 |
} |
421 |
#endif |
|
422 |
||
423 |
#ifdef P11_ENABLE_C_VERIFY |
|
424 |
/* |
|
425 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
426 |
* Method: C_Verify |
|
427 |
* Signature: (J[B[B)V |
|
428 |
* Parametermapping: *PKCS11* |
|
429 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
430 |
* @param jbyteArray jData CK_BYTE_PTR pData |
|
431 |
* CK_ULONG ulDataLen |
|
432 |
* @param jbyteArray jSignature CK_BYTE_PTR pSignature |
|
433 |
* CK_ULONG_PTR pulSignatureLen |
|
434 |
*/ |
|
435 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1Verify |
|
436 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jbyteArray jData, jbyteArray jSignature) |
|
437 |
{ |
|
438 |
CK_SESSION_HANDLE ckSessionHandle; |
|
439 |
CK_BYTE_PTR ckpData = NULL_PTR; |
|
440 |
CK_BYTE_PTR ckpSignature = NULL_PTR; |
|
441 |
CK_ULONG ckDataLength; |
|
442 |
CK_ULONG ckSignatureLength; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
443 |
CK_RV rv = 0; |
2 | 444 |
|
445 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
446 |
if (ckpFunctions == NULL) { return; } |
|
447 |
||
448 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
449 |
|
2 | 450 |
jByteArrayToCKByteArray(env, jData, &ckpData, &ckDataLength); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
451 |
if ((*env)->ExceptionCheck(env)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
452 |
return; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
453 |
} |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
454 |
|
2 | 455 |
jByteArrayToCKByteArray(env, jSignature, &ckpSignature, &ckSignatureLength); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
456 |
if ((*env)->ExceptionCheck(env)) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
457 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
458 |
} |
2 | 459 |
|
460 |
/* verify the signature */ |
|
461 |
rv = (*ckpFunctions->C_Verify)(ckSessionHandle, ckpData, ckDataLength, ckpSignature, ckSignatureLength); |
|
462 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
463 |
cleanup: |
2 | 464 |
free(ckpData); |
465 |
free(ckpSignature); |
|
466 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
467 |
ckAssertReturnValueOK(env, rv); |
2 | 468 |
} |
469 |
#endif |
|
470 |
||
471 |
#ifdef P11_ENABLE_C_VERIFYUPDATE |
|
472 |
/* |
|
473 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
474 |
* Method: C_VerifyUpdate |
|
475 |
* Signature: (J[BII)V |
|
476 |
* Parametermapping: *PKCS11* |
|
477 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
478 |
* @param jbyteArray jPart CK_BYTE_PTR pPart |
|
479 |
* CK_ULONG ulPartLen |
|
480 |
*/ |
|
481 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1VerifyUpdate |
|
482 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jlong directIn, jbyteArray jIn, jint jInOfs, jint jInLen) |
|
483 |
{ |
|
484 |
CK_SESSION_HANDLE ckSessionHandle; |
|
485 |
CK_RV rv; |
|
486 |
CK_BYTE_PTR bufP; |
|
487 |
CK_BYTE BUF[MAX_STACK_BUFFER_LEN]; |
|
488 |
jsize bufLen; |
|
489 |
||
490 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
491 |
if (ckpFunctions == NULL) { return; } |
|
492 |
||
493 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
494 |
||
495 |
if (directIn != 0) { |
|
14414
f338be3ef659
8001579: Cleanup warnings in security native code
jzavgren
parents:
14342
diff
changeset
|
496 |
rv = (*ckpFunctions->C_VerifyUpdate)(ckSessionHandle, (CK_BYTE_PTR)jlong_to_ptr(directIn), jInLen); |
2 | 497 |
ckAssertReturnValueOK(env, rv); |
498 |
return; |
|
499 |
} |
|
500 |
||
501 |
if (jInLen <= MAX_STACK_BUFFER_LEN) { |
|
502 |
bufLen = MAX_STACK_BUFFER_LEN; |
|
503 |
bufP = BUF; |
|
504 |
} else { |
|
505 |
bufLen = min(MAX_HEAP_BUFFER_LEN, jInLen); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
506 |
bufP = (CK_BYTE_PTR) malloc((size_t)bufLen); |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
507 |
if (bufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
508 |
throwOutOfMemoryError(env, 0); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
509 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
510 |
} |
2 | 511 |
} |
512 |
||
513 |
while (jInLen > 0) { |
|
514 |
jsize chunkLen = min(bufLen, jInLen); |
|
515 |
(*env)->GetByteArrayRegion(env, jIn, jInOfs, chunkLen, (jbyte *)bufP); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
516 |
if ((*env)->ExceptionCheck(env)) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
517 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
518 |
} |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
519 |
|
2 | 520 |
rv = (*ckpFunctions->C_VerifyUpdate)(ckSessionHandle, bufP, chunkLen); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
521 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
522 |
goto cleanup; |
2 | 523 |
} |
524 |
jInOfs += chunkLen; |
|
525 |
jInLen -= chunkLen; |
|
526 |
} |
|
527 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
528 |
cleanup: |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
529 |
if (bufP != BUF) { free(bufP); } |
2 | 530 |
} |
531 |
#endif |
|
532 |
||
533 |
#ifdef P11_ENABLE_C_VERIFYFINAL |
|
534 |
/* |
|
535 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
536 |
* Method: C_VerifyFinal |
|
537 |
* Signature: (J[B)V |
|
538 |
* Parametermapping: *PKCS11* |
|
539 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
540 |
* @param jbyteArray jSignature CK_BYTE_PTR pSignature |
|
541 |
* CK_ULONG ulSignatureLen |
|
542 |
*/ |
|
543 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1VerifyFinal |
|
544 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jbyteArray jSignature) |
|
545 |
{ |
|
546 |
CK_SESSION_HANDLE ckSessionHandle; |
|
547 |
CK_BYTE_PTR ckpSignature = NULL_PTR; |
|
548 |
CK_ULONG ckSignatureLength; |
|
549 |
CK_RV rv; |
|
550 |
||
551 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
552 |
if (ckpFunctions == NULL) { return; } |
|
553 |
||
554 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
555 |
jByteArrayToCKByteArray(env, jSignature, &ckpSignature, &ckSignatureLength); |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
556 |
if ((*env)->ExceptionCheck(env)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
557 |
return; |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
558 |
} |
2 | 559 |
|
560 |
/* verify the signature */ |
|
561 |
rv = (*ckpFunctions->C_VerifyFinal)(ckSessionHandle, ckpSignature, ckSignatureLength); |
|
562 |
||
563 |
free(ckpSignature); |
|
564 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
565 |
ckAssertReturnValueOK(env, rv); |
2 | 566 |
} |
567 |
#endif |
|
568 |
||
569 |
#ifdef P11_ENABLE_C_VERIFYRECOVERINIT |
|
570 |
/* |
|
571 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
572 |
* Method: C_VerifyRecoverInit |
|
573 |
* Signature: (JLsun/security/pkcs11/wrapper/CK_MECHANISM;J)V |
|
574 |
* Parametermapping: *PKCS11* |
|
575 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
576 |
* @param jobject jMechanism CK_MECHANISM_PTR pMechanism |
|
577 |
* @return jlong jKeyHandle CK_OBJECT_HANDLE hKey |
|
578 |
*/ |
|
579 |
JNIEXPORT void JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1VerifyRecoverInit |
|
580 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jobject jMechanism, jlong jKeyHandle) |
|
581 |
{ |
|
582 |
CK_SESSION_HANDLE ckSessionHandle; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
583 |
CK_MECHANISM_PTR ckpMechanism = NULL; |
2 | 584 |
CK_OBJECT_HANDLE ckKeyHandle; |
585 |
CK_RV rv; |
|
586 |
||
587 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
588 |
if (ckpFunctions == NULL) { return; } |
|
589 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
590 |
TRACE0("DEBUG: C_VerifyRecoverInit\n"); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
591 |
|
2 | 592 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
593 |
ckpMechanism = jMechanismToCKMechanismPtr(env, jMechanism); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
594 |
if ((*env)->ExceptionCheck(env)) { return; } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
595 |
|
2 | 596 |
ckKeyHandle = jLongToCKULong(jKeyHandle); |
597 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
598 |
rv = (*ckpFunctions->C_VerifyRecoverInit)(ckSessionHandle, ckpMechanism, ckKeyHandle); |
2 | 599 |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
600 |
if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK || |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
601 |
(ckpMechanism->pParameter == NULL)) { |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
602 |
freeCKMechanismPtr(ckpMechanism); |
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
603 |
} else { |
55410
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
604 |
(*env)->SetLongField(env, jMechanism, mech_pHandleID, ptr_to_jlong(ckpMechanism)); |
c3b354fdbaa4
8225695: 32-bit build failures after JDK-8080462 (Update SunPKCS11 provider with PKCS11 v2.40 support)
shade
parents:
55332
diff
changeset
|
605 |
TRACE1("DEBUG C_VerifyRecoverInit: stored pMech = 0x%lX\n", ptr_to_jlong(ckpMechanism)); |
2 | 606 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
607 |
TRACE0("FINISHED\n"); |
2 | 608 |
} |
609 |
#endif |
|
610 |
||
611 |
#ifdef P11_ENABLE_C_VERIFYRECOVER |
|
612 |
/* |
|
613 |
* Class: sun_security_pkcs11_wrapper_PKCS11 |
|
614 |
* Method: C_VerifyRecover |
|
615 |
* Signature: (J[BII[BII)I |
|
616 |
* Parametermapping: *PKCS11* |
|
617 |
* @param jlong jSessionHandle CK_SESSION_HANDLE hSession |
|
618 |
* @param jbyteArray jSignature CK_BYTE_PTR pSignature |
|
619 |
* CK_ULONG ulSignatureLen |
|
620 |
* @return jbyteArray jData CK_BYTE_PTR pData |
|
621 |
* CK_ULONG_PTR pulDataLen |
|
622 |
*/ |
|
623 |
JNIEXPORT jint JNICALL Java_sun_security_pkcs11_wrapper_PKCS11_C_1VerifyRecover |
|
624 |
(JNIEnv *env, jobject obj, jlong jSessionHandle, jbyteArray jIn, jint jInOfs, jint jInLen, jbyteArray jOut, jint jOutOfs, jint jOutLen) |
|
625 |
{ |
|
626 |
CK_SESSION_HANDLE ckSessionHandle; |
|
627 |
CK_RV rv; |
|
628 |
CK_BYTE INBUF[MAX_STACK_BUFFER_LEN]; |
|
629 |
CK_BYTE OUTBUF[MAX_STACK_BUFFER_LEN]; |
|
630 |
CK_BYTE_PTR inBufP; |
|
631 |
CK_BYTE_PTR outBufP = OUTBUF; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
632 |
CK_ULONG ckDataLength = 0; |
2 | 633 |
|
634 |
CK_FUNCTION_LIST_PTR ckpFunctions = getFunctionList(env, obj); |
|
635 |
if (ckpFunctions == NULL) { return 0; } |
|
636 |
||
637 |
ckSessionHandle = jLongToCKULong(jSessionHandle); |
|
638 |
||
639 |
if (jInLen <= MAX_STACK_BUFFER_LEN) { |
|
640 |
inBufP = INBUF; |
|
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
641 |
ckDataLength = MAX_STACK_BUFFER_LEN; |
2 | 642 |
} else { |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
643 |
inBufP = (CK_BYTE_PTR) malloc((size_t)jInLen); |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
644 |
if (inBufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
645 |
throwOutOfMemoryError(env, 0); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
646 |
return 0; |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
647 |
} |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
648 |
ckDataLength = jInLen; |
2 | 649 |
} |
650 |
||
651 |
(*env)->GetByteArrayRegion(env, jIn, jInOfs, jInLen, (jbyte *)inBufP); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
652 |
if ((*env)->ExceptionCheck(env)) { |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
653 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
654 |
} |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
655 |
|
2 | 656 |
rv = (*ckpFunctions->C_VerifyRecover)(ckSessionHandle, inBufP, jInLen, outBufP, &ckDataLength); |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
657 |
|
2 | 658 |
/* re-alloc larger buffer if it fits into our Java buffer */ |
659 |
if ((rv == CKR_BUFFER_TOO_SMALL) && (ckDataLength <= jIntToCKULong(jOutLen))) { |
|
660 |
outBufP = (CK_BYTE_PTR) malloc(ckDataLength); |
|
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
661 |
if (outBufP == NULL) { |
10798
413b731e1818
7103549: Remove dependencies on libjava and libjvm from security libraries
chegar
parents:
5506
diff
changeset
|
662 |
throwOutOfMemoryError(env, 0); |
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
663 |
goto cleanup; |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
664 |
} |
2 | 665 |
rv = (*ckpFunctions->C_VerifyRecover)(ckSessionHandle, inBufP, jInLen, outBufP, &ckDataLength); |
666 |
} |
|
667 |
if (ckAssertReturnValueOK(env, rv) == CK_ASSERT_OK) { |
|
668 |
(*env)->SetByteArrayRegion(env, jOut, jOutOfs, ckDataLength, (jbyte *)outBufP); |
|
669 |
} |
|
670 |
||
55332
f492567244ab
8080462: Update SunPKCS11 provider with PKCS11 v2.40 support
valeriep
parents:
47216
diff
changeset
|
671 |
cleanup: |
2180
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
672 |
if (inBufP != INBUF) { free(inBufP); } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
673 |
if (outBufP != OUTBUF) { free(outBufP); } |
9994f4f08a59
6812738: SSL stress test with GF leads to 32 bit max process size in less than 5 minutes with PCKS11 provider
valeriep
parents:
2
diff
changeset
|
674 |
|
2 | 675 |
return ckDataLength; |
676 |
} |
|
677 |
#endif |