o
    
c|(                     @   s\   d dl Z d dlmZmZmZ d dlmZ d dlmZm	Z	 e j
r%d dlmZ G dd dZdS )    N)
InvalidTagUnsupportedAlgorithm_Reasons)ciphers)
algorithmsmodes)Backendc                   @   s   e Zd ZdZdZdZdddeddfd	d
ZdedefddZ	dededefddZ
defddZdedefddZdeddfddZedeje fddZdS )_CipherContext   r   i?backendr   	operationreturnNc                 C   s8  || _ || _|| _|| _d | _t| jtjr| jjd | _	nd| _	| j j
 }| j j|| j j
j}| j j}z|t|t|f }W n tyY   td|j|rS|jn|tjw || j ||}|| j jjkrd|}	|d urx|	d|7 }	|	d| j  7 }	t|	tjt|tjr| j j|j}
n2t|tjr| j j|j}
n#t|tjr| j j|j }
nt|t!j"r| j j|j }
n| j jj}
| j j
#||| j jj| j jj| j jj|}| j $|dk | j j
%|t&|j'}| j $|dk t|tj(r=| j j
)|| j j
j*t&|
| j jj}| j $|dk |j+d ur=| j j
)|| j j
j,t&|j+|j+}| j $|dk |j+| _| j j
#|| j jj| j jj| j j|j'|
|}| j - }| j j
}|dkr|j.rr|d /|j0|j1s|j2r|d /|j3|j4rt5d| j j$|dk|d	 | j j
6|d || _7d S )
N   r
   z6cipher {} in {} mode is not supported by this backend.zcipher {0.name} zin {0.name} mode z_is not supported by this backend (Your version of OpenSSL may be too old. Current version: {}.)r   z+In XTS mode duplicated keys are not allowederrors)8_backend_cipher_mode
_operation_tag
isinstancer   BlockCipherAlgorithm
block_size_block_size_bytes_libEVP_CIPHER_CTX_new_ffigcEVP_CIPHER_CTX_free_cipher_registrytypeKeyErrorr   formatnamer   UNSUPPORTED_CIPHERNULLopenssl_version_textr   ModeWithInitializationVectorfrom_bufferinitialization_vectorModeWithTweaktweakModeWithNoncenoncer   ChaCha20EVP_CipherInit_exopenssl_assertEVP_CIPHER_CTX_set_key_lengthlenkeyGCMEVP_CIPHER_CTX_ctrlEVP_CTRL_AEAD_SET_IVLENtagEVP_CTRL_AEAD_SET_TAG_consume_errors$CRYPTOGRAPHY_OPENSSL_111D_OR_GREATER_lib_reason_matchERR_LIB_EVPEVP_R_XTS_DUPLICATED_KEYSCryptography_HAS_PROVIDERSERR_LIB_PROVPROV_R_XTS_DUPLICATED_KEYS
ValueErrorEVP_CIPHER_CTX_set_padding_ctx)selfr   ciphermoder   ctxregistryadapter
evp_ciphermsgiv_nonceresr   lib rO   Y/opt/certbot/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/ciphers.py__init__   s   
	





	
z_CipherContext.__init__datac                 C   s2   t t|| j d }| ||}t|d | S )Nr
   )	bytearrayr2   r   update_intobytes)rD   rR   bufnrO   rO   rP   update   s   z_CipherContext.updaterV   c                 C   s  t |}t ||| j d k rtdt || j d d}d}| jjd}| jjj|dd}| jj|}||kr|| }	|| }
t| j	|| }| jj
| j|	||
|}|dkrlt| jtjrl| j  td| j|dk ||7 }||d 7 }||ks<|S )Nr
   z1buffer must be at least {} bytes for this payloadr   int *T)require_writablezeIn XTS mode you must supply at least a full block in the first update call. For AES this is 16 bytes.)r2   r   rA   r"   r   r   newr(   min_MAX_CHUNK_SIZEr   EVP_CipherUpdaterC   r   r   r   XTSr9   r0   )rD   rR   rV   total_data_lendata_processed	total_outoutlen
baseoutbuf	baseinbufoutbufinbufinlenrM   rO   rO   rP   rT      s8   
z_CipherContext.update_intoc                 C   s  | j | jkrt| jtjr| jd u rtd| jj	
d| j}| jj	
d}| jj| j||}|dkrt| j }|sDt| jtjrDt| jj}| jj|d |j|jpl|joa|d |j|jpl|jol|d j|jk|d tdt| jtjr| j | jkr| jj	
d| j}| jj| j| jjj| j|}| j|dk | jj	|d d  | _ | jj!| j}| j|dk | jj	|d |d  S )Nz4Authentication tag must be provided when decrypting.zunsigned char[]rY   r   r   zFThe length of the provided data is not a multiple of the block length.r
   )"r   _DECRYPTr   r   r   ModeWithAuthenticationTagr7   rA   r   r   r[   r   r   EVP_CipherFinal_exrC   r9   r4   r   r0   r;   r<   'EVP_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTHr>   r?   PROV_R_WRONG_FINAL_BLOCK_LENGTHCRYPTOGRAPHY_IS_BORINGSSLreason*CIPHER_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTH_ENCRYPTr5   EVP_CTRL_AEAD_GET_TAGbufferr   EVP_CIPHER_CTX_reset)rD   rV   rc   rM   r   rN   tag_bufrO   rO   rP   finalize   sn   


z_CipherContext.finalizer7   c                 C   s~   t |}|| jjk rtd| jj|| jkr td| j| jj| j	| jjj
t ||}| j|dk || _|  S )Nz.Authentication tag must be {} bytes or longer.z0Authentication tag cannot be more than {} bytes.r   )r2   r   _min_tag_lengthrA   r"   r   r   r   r5   rC   r8   r0   r   rv   )rD   r7   tag_lenrM   rO   rO   rP   finalize_with_tag   s&   
z _CipherContext.finalize_with_tagc                 C   sN   | j jd}| j j| j| j jj|| j j|t|}| j 	|dk d S )NrY   r   )
r   r   r[   r   r^   rC   r%   r(   r2   r0   )rD   rR   rc   rM   rO   rO   rP   authenticate_additional_data  s   z+_CipherContext.authenticate_additional_datac                 C   s   | j S )N)r   )rD   rO   rO   rP   r7     s   z_CipherContext.tag)__name__
__module____qualname__rq   ri   r]   intrQ   rU   rX   rT   rv   ry   rz   propertytypingOptionalr7   rO   rO   rO   rP   r	      s$    
{#@r	   )r   cryptography.exceptionsr   r   r   cryptography.hazmat.primitivesr   &cryptography.hazmat.primitives.ciphersr   r   TYPE_CHECKING,cryptography.hazmat.backends.openssl.backendr   r	   rO   rO   rO   rP   <module>   s   