3
ãdej(  ã               @   s\   d dl Z d dlmZmZmZ d dlmZ d dlmZm	Z	 e j
rJd dlmZ G dd„ dƒZdS )é    N)Ú
InvalidTagÚUnsupportedAlgorithmÚ_Reasons)Úciphers)Ú
algorithmsÚmodes)ÚBackendc               @   s’   e Zd ZdZdZdZdeddœdd	„Zeed
œdd„Z	eeedœdd„Z
edœdd„Zeedœdd„Zedd
œdd„Zeeje dœdd„ƒZdS )Ú_CipherContexté   r   é   é   r   N)ÚbackendÚ	operationÚreturnc             C   sR  || _ || _|| _|| _d | _t| jtjƒr<| jjd | _	nd| _	| j j
jƒ }| j jj|| j j
jƒ}| j j}y|t|ƒt|ƒf }W n4 tk
r¸   tdj|j|r¨|jn|ƒtjƒ‚Y nX || j ||ƒ}|| j jjk�r"d|j› d�}	|d k	�r|	d|j› d�7 }	|	dj| j jƒ ƒ7 }	t|	tjƒ‚t|tjƒ�rB| j jj|jƒ}
njt|tjƒ�rb| j jj|jƒ}
nJt|tjƒ�r‚| j jj|j ƒ}
n*t|t!j"ƒ�r¢| j jj|j ƒ}
n
| j jj}
| j j
j#||| j jj| j jj| j jj|ƒ}| j j$|d	kƒ | j j
j%|t&|j'ƒƒ}| j j$|d	kƒ t|tj(ƒ�r”| j j
j)|| j j
j*t&|
ƒ| j jjƒ}| j j$|d	kƒ |j+d k	�r”| j j
j)|| j j
j,t&|j+ƒ|j+ƒ}| j j$|d	kƒ |j+| _| j j
j#|| j jj| j jj| j jj|j'ƒ|
|ƒ}| j j-ƒ }| j j
}|d	k�r$|j.�rþ|d	 j/|j0|j1ƒ�s|j2�r$|d	 j/|j3|j4ƒ�r$t5d
ƒ‚| j j$|d	k|d� | j j
j6|d	ƒ || _7d S )Né   r
   z6cipher {} in {} mode is not supported by this backend.zcipher ú zin z mode z_is not supported by this backend (Your version of OpenSSL may be too old. Current version: {}.)r   z+In XTS mode duplicated keys are not allowed)Úerrors)8Ú_backendZ_cipherÚ_modeÚ
_operationÚ_tagÚ
isinstancer   ZBlockCipherAlgorithmÚ
block_sizeÚ_block_size_bytesÚ_libZEVP_CIPHER_CTX_newÚ_ffiÚgcZEVP_CIPHER_CTX_freeZ_cipher_registryÚtypeÚKeyErrorr   ÚformatÚnamer   ZUNSUPPORTED_CIPHERÚNULLZopenssl_version_textr   ZModeWithInitializationVectorÚfrom_bufferZinitialization_vectorZModeWithTweakZtweakZModeWithNonceÚnoncer   ZChaCha20ZEVP_CipherInit_exÚopenssl_assertZEVP_CIPHER_CTX_set_key_lengthÚlenÚkeyÚGCMÚEVP_CIPHER_CTX_ctrlZEVP_CTRL_AEAD_SET_IVLENÚtagÚEVP_CTRL_AEAD_SET_TAGÚ_consume_errorsZ$CRYPTOGRAPHY_OPENSSL_111D_OR_GREATERÚ_lib_reason_matchÚERR_LIB_EVPZEVP_R_XTS_DUPLICATED_KEYSÚCryptography_HAS_PROVIDERSÚERR_LIB_PROVZPROV_R_XTS_DUPLICATED_KEYSÚ
ValueErrorZEVP_CIPHER_CTX_set_paddingÚ_ctx)Úselfr   ÚcipherÚmoder   ÚctxÚregistryÚadapterZ
evp_cipherÚmsgZiv_nonceÚresr   Úlib© r;   úc/var/www/agendate/envp3/lib/python3.6/site-packages/cryptography/hazmat/backends/openssl/ciphers.pyÚ__init__   s¨    




z_CipherContext.__init__)Údatar   c             C   s2   t t|ƒ| j d ƒ}| j||ƒ}t|d |… ƒS )Nr
   )Ú	bytearrayr%   r   Úupdate_intoÚbytes)r2   r>   ÚbufÚnr;   r;   r<   Úupdate�   s    z_CipherContext.update)r>   rB   r   c             C   s
  t |ƒ}t |ƒ|| j d k r:tdjt |ƒ| j d ƒƒ‚d}d}| jjjdƒ}| jjj|dd�}| jjj|ƒ}x”||k�r|| }	|| }
t| j	|| ƒ}| jj
j| j|	||
|ƒ}|dkrÞt| jtjƒrÞ| jjƒ  tdƒ‚n| jj|dkƒ ||7 }||d 7 }qrW |S )Nr
   z1buffer must be at least {} bytes for this payloadr   zint *T)Zrequire_writablezeIn XTS mode you must supply at least a full block in the first update call. For AES this is 16 bytes.)r%   r   r0   r   r   r   Únewr"   ÚminÚ_MAX_CHUNK_SIZEr   ÚEVP_CipherUpdater1   r   r   r   ZXTSr+   r$   )r2   r>   rB   Ztotal_data_lenZdata_processedZ	total_outÚoutlenZ
baseoutbufZ	baseinbufZoutbufZinbufZinlenr9   r;   r;   r<   r@   ”   s0    
z_CipherContext.update_into)r   c             C   sš  | j | jkr,t| jtjƒr,| jd kr,tdƒ‚| jj	j
d| jƒ}| jj	j
dƒ}| jjj| j||ƒ}|dkrê| jjƒ }| rŠt| jtjƒrŠt‚| jj}| jj|d j|j|jƒpÚ|jrÆ|d j|j|jƒpÚ|joÚ|d j|jk|d� tdƒ‚t| jtjƒ�r`| j | jk�r`| jj	j
d| jƒ}| jjj| j| jjj| j|ƒ}| jj|dkƒ | jj	j|ƒd d … | _ | jjj!| jƒ}| jj|dkƒ | jj	j|ƒd |d … S )Nz4Authentication tag must be provided when decrypting.zunsigned char[]zint *r   )r   zFThe length of the provided data is not a multiple of the block length.r
   )"r   Ú_DECRYPTr   r   r   ZModeWithAuthenticationTagr)   r0   r   r   rE   r   r   ZEVP_CipherFinal_exr1   r+   r'   r   r$   r,   r-   Z'EVP_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTHr.   r/   ZPROV_R_WRONG_FINAL_BLOCK_LENGTHZCRYPTOGRAPHY_IS_BORINGSSLÚreasonZ*CIPHER_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTHÚ_ENCRYPTr(   ZEVP_CTRL_AEAD_GET_TAGÚbufferr   ZEVP_CIPHER_CTX_reset)r2   rB   rI   r9   r   r:   Ztag_bufr;   r;   r<   Úfinalize·   sR    


z_CipherContext.finalize)r)   r   c             C   s€   t |ƒ}|| jjk r(tdj| jjƒƒ‚n|| jkrBtdj| jƒƒ‚| jjj| j	| jjj
t |ƒ|ƒ}| jj|dkƒ || _| jƒ S )Nz.Authentication tag must be {} bytes or longer.z0Authentication tag cannot be more than {} bytes.r   )r%   r   Z_min_tag_lengthr0   r   r   r   r   r(   r1   r*   r$   r   rN   )r2   r)   Ztag_lenr9   r;   r;   r<   Úfinalize_with_tag÷   s    

z _CipherContext.finalize_with_tagc             C   sN   | j jjdƒ}| j jj| j| j jj|| j jj|ƒt|ƒƒ}| j j	|dkƒ d S )Nzint *r   )
r   r   rE   r   rH   r1   r!   r"   r%   r$   )r2   r>   rI   r9   r;   r;   r<   Úauthenticate_additional_data  s    
z+_CipherContext.authenticate_additional_datac             C   s   | j S )N)r   )r2   r;   r;   r<   r)     s    z_CipherContext.tagi   @iÿÿÿ?)Ú__name__Ú
__module__Ú__qualname__rL   rJ   rG   Úintr=   rA   rD   r@   rN   rO   rP   ÚpropertyÚtypingÚOptionalr)   r;   r;   r;   r<   r	      s   y#@r	   )rV   Zcryptography.exceptionsr   r   r   Zcryptography.hazmat.primitivesr   Z&cryptography.hazmat.primitives.ciphersr   r   ÚTYPE_CHECKINGZ,cryptography.hazmat.backends.openssl.backendr   r	   r;   r;   r;   r<   Ú<module>   s   