2011-12-20 10:20:44 -08:00
|
|
|
/**
|
|
|
|
* Copyright (C) 2011 Whisper Systems
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
package org.thoughtcrime.securesms.crypto;
|
|
|
|
|
2020-08-19 10:06:26 +10:00
|
|
|
import androidx.annotation.NonNull;
|
2017-04-03 17:23:56 -07:00
|
|
|
|
2018-08-01 11:09:24 -04:00
|
|
|
import org.thoughtcrime.securesms.logging.Log;
|
2017-03-28 12:05:30 -07:00
|
|
|
import org.thoughtcrime.securesms.util.LimitedInputStream;
|
2017-04-13 12:21:38 -07:00
|
|
|
import org.thoughtcrime.securesms.util.Util;
|
2017-03-28 12:05:30 -07:00
|
|
|
|
2011-12-20 10:20:44 -08:00
|
|
|
import java.io.File;
|
|
|
|
import java.io.FileInputStream;
|
|
|
|
import java.io.IOException;
|
2017-03-28 12:05:30 -07:00
|
|
|
import java.io.InputStream;
|
2011-12-20 10:20:44 -08:00
|
|
|
import java.security.InvalidAlgorithmParameterException;
|
|
|
|
import java.security.InvalidKeyException;
|
2017-03-28 12:05:30 -07:00
|
|
|
import java.security.MessageDigest;
|
2011-12-20 10:20:44 -08:00
|
|
|
import java.security.NoSuchAlgorithmException;
|
|
|
|
|
|
|
|
import javax.crypto.Cipher;
|
2017-03-28 12:05:30 -07:00
|
|
|
import javax.crypto.CipherInputStream;
|
2011-12-20 10:20:44 -08:00
|
|
|
import javax.crypto.Mac;
|
|
|
|
import javax.crypto.NoSuchPaddingException;
|
|
|
|
import javax.crypto.spec.IvParameterSpec;
|
|
|
|
import javax.crypto.spec.SecretKeySpec;
|
|
|
|
|
2018-01-24 19:17:44 -08:00
|
|
|
public class ClassicDecryptingPartInputStream {
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2018-01-24 19:17:44 -08:00
|
|
|
private static final String TAG = ClassicDecryptingPartInputStream.class.getSimpleName();
|
2015-06-15 12:26:29 -07:00
|
|
|
|
2011-12-20 10:20:44 -08:00
|
|
|
private static final int IV_LENGTH = 16;
|
|
|
|
private static final int MAC_LENGTH = 20;
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2018-01-24 19:17:44 -08:00
|
|
|
public static InputStream createFor(@NonNull AttachmentSecret attachmentSecret, @NonNull File file)
|
2017-03-28 12:05:30 -07:00
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
if (file.length() <= IV_LENGTH + MAC_LENGTH) {
|
|
|
|
throw new IOException("File too short");
|
|
|
|
}
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2018-01-24 19:17:44 -08:00
|
|
|
verifyMac(attachmentSecret, file);
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
FileInputStream fileStream = new FileInputStream(file);
|
|
|
|
byte[] ivBytes = new byte[IV_LENGTH];
|
|
|
|
readFully(fileStream, ivBytes);
|
|
|
|
|
2017-04-03 17:23:56 -07:00
|
|
|
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding");
|
|
|
|
IvParameterSpec iv = new IvParameterSpec(ivBytes);
|
2018-01-24 19:17:44 -08:00
|
|
|
cipher.init(Cipher.DECRYPT_MODE, new SecretKeySpec(attachmentSecret.getClassicCipherKey(), "AES"), iv);
|
2017-03-28 12:05:30 -07:00
|
|
|
|
2017-04-03 17:23:56 -07:00
|
|
|
return new CipherInputStreamWrapper(new LimitedInputStream(fileStream, file.length() - MAC_LENGTH - IV_LENGTH), cipher);
|
2017-03-28 12:05:30 -07:00
|
|
|
} catch (NoSuchAlgorithmException | NoSuchPaddingException | InvalidKeyException | InvalidAlgorithmParameterException e) {
|
2011-12-20 10:20:44 -08:00
|
|
|
throw new AssertionError(e);
|
|
|
|
}
|
|
|
|
}
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2018-01-24 19:17:44 -08:00
|
|
|
private static void verifyMac(AttachmentSecret attachmentSecret, File file) throws IOException {
|
|
|
|
Mac mac = initializeMac(new SecretKeySpec(attachmentSecret.getClassicMacKey(), "HmacSHA1"));
|
2017-03-28 12:05:30 -07:00
|
|
|
FileInputStream macStream = new FileInputStream(file);
|
|
|
|
InputStream dataStream = new LimitedInputStream(new FileInputStream(file), file.length() - MAC_LENGTH);
|
|
|
|
byte[] theirMac = new byte[MAC_LENGTH];
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
if (macStream.skip(file.length() - MAC_LENGTH) != file.length() - MAC_LENGTH) {
|
|
|
|
throw new IOException("Unable to seek");
|
|
|
|
}
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
readFully(macStream, theirMac);
|
2014-12-12 01:03:24 -08:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
byte[] buffer = new byte[4096];
|
|
|
|
int read;
|
2014-12-12 01:03:24 -08:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
while ((read = dataStream.read(buffer)) != -1) {
|
|
|
|
mac.update(buffer, 0, read);
|
2014-12-12 01:03:24 -08:00
|
|
|
}
|
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
byte[] ourMac = mac.doFinal();
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
if (!MessageDigest.isEqual(ourMac, theirMac)) {
|
|
|
|
throw new IOException("Bad MAC");
|
2013-11-12 12:57:47 +11:00
|
|
|
}
|
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
macStream.close();
|
|
|
|
dataStream.close();
|
|
|
|
}
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
private static Mac initializeMac(SecretKeySpec key) {
|
2011-12-20 10:20:44 -08:00
|
|
|
try {
|
2017-03-28 12:05:30 -07:00
|
|
|
Mac hmac = Mac.getInstance("HmacSHA1");
|
|
|
|
hmac.init(key);
|
2013-11-12 13:31:30 +11:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
return hmac;
|
|
|
|
} catch (NoSuchAlgorithmException | InvalidKeyException e) {
|
2011-12-20 10:20:44 -08:00
|
|
|
throw new AssertionError(e);
|
2014-02-18 16:28:54 -08:00
|
|
|
}
|
2011-12-20 10:20:44 -08:00
|
|
|
}
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2017-03-28 12:05:30 -07:00
|
|
|
private static void readFully(InputStream in, byte[] buffer) throws IOException {
|
2011-12-20 10:20:44 -08:00
|
|
|
int offset = 0;
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2011-12-20 10:20:44 -08:00
|
|
|
for (;;) {
|
2017-03-28 12:05:30 -07:00
|
|
|
int read = in.read(buffer, offset, buffer.length-offset);
|
2014-12-01 18:45:37 +01:00
|
|
|
|
2011-12-20 10:20:44 -08:00
|
|
|
if (read + offset < buffer.length) offset += read;
|
2014-12-01 18:45:37 +01:00
|
|
|
else return;
|
|
|
|
}
|
2011-12-20 10:20:44 -08:00
|
|
|
}
|
2017-04-03 17:23:56 -07:00
|
|
|
|
|
|
|
// Note (4/3/17) -- Older versions of Android have a busted OpenSSL provider that
|
|
|
|
// throws a RuntimeException on a BadPaddingException, so we have to catch
|
|
|
|
// that here in case someone calls close() before reaching the end of the
|
|
|
|
// stream (since close() implicitly calls doFinal())
|
|
|
|
//
|
|
|
|
// See Signal-Android Issue #6477
|
|
|
|
// Android: https://android-review.googlesource.com/#/c/65321/
|
|
|
|
private static class CipherInputStreamWrapper extends CipherInputStream {
|
|
|
|
|
|
|
|
CipherInputStreamWrapper(InputStream is, Cipher c) {
|
|
|
|
super(is, c);
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public void close() throws IOException {
|
|
|
|
try {
|
|
|
|
super.close();
|
|
|
|
} catch (Throwable t) {
|
|
|
|
Log.w(TAG, t);
|
|
|
|
}
|
|
|
|
}
|
2017-04-13 12:21:38 -07:00
|
|
|
|
|
|
|
@Override
|
|
|
|
public long skip(long skipAmount)
|
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
long remaining = skipAmount;
|
|
|
|
|
|
|
|
if (skipAmount <= 0) {
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
byte[] skipBuffer = new byte[4092];
|
|
|
|
|
|
|
|
while (remaining > 0) {
|
|
|
|
int read = super.read(skipBuffer, 0, Util.toIntExact(Math.min(skipBuffer.length, remaining)));
|
|
|
|
|
|
|
|
if (read < 0) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
remaining -= read;
|
|
|
|
}
|
|
|
|
|
|
|
|
return skipAmount - remaining;
|
|
|
|
}
|
2017-04-03 17:23:56 -07:00
|
|
|
}
|
2011-12-20 10:20:44 -08:00
|
|
|
}
|