-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathgcm_decrypt_reader.go
95 lines (77 loc) · 1.83 KB
/
gcm_decrypt_reader.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
package openssl_gcm
import (
"bytes"
"fmt"
"io"
"github.com/spacemonkeygo/openssl"
)
const (
GcmTagMaxlen = openssl.GCM_TAG_MAXLEN
)
type gcmDecryptReader struct {
src io.Reader
ctx openssl.AuthenticatedDecryptionCipherCtx
eof bool
buf *bytes.Buffer // for finalize small bytes
tag *bytes.Buffer
off int64
size int64
// TODO possible to know the remaining bytes before eof instead of specifying size?
}
func NewGcmDecryptReader(r io.Reader, key, iv, aad []byte, size int64) (*gcmDecryptReader, error) {
ctx, err := openssl.NewGCMDecryptionCipherCtx(len(key)*8, nil, key, iv)
if err != nil {
return nil, fmt.Errorf("Failed making GCM decryption ctx: %v", err)
}
if len(aad) > 0 {
err = ctx.ExtraData(aad)
if err != nil {
return nil, fmt.Errorf("Failed to add authenticated data: %v", err)
}
}
return &gcmDecryptReader{
src: r,
ctx: ctx,
buf: &bytes.Buffer{},
tag: &bytes.Buffer{},
size: size - GcmTagMaxlen,
}, nil
}
func (r *gcmDecryptReader) Read(p []byte) (int, error) {
if r.eof {
return r.buf.Read(p)
}
n, err := r.src.Read(p)
if err == io.EOF {
if err := r.ctx.SetTag(r.tag.Bytes()); err != nil {
return n, fmt.Errorf("Failed to set an expected GCM tag: %v", err)
}
data, err := r.ctx.DecryptFinal()
if err != nil {
return len(data), fmt.Errorf("Failed to finalize decryption: %v", err)
}
r.buf.Write(data)
r.eof = true
return r.buf.Read(p)
} else if err != nil {
return n, err
}
r.off += int64(n)
if r.off > r.size {
d := int(r.off % r.size)
d %= cap(p)
if d == 0 {
d = n
}
r.tag.Write(p[n-d : n])
n -= d
}
if n > 0 {
data, err := r.ctx.DecryptUpdate(p[:n])
if err != nil {
return len(data), fmt.Errorf("Failed to perform a decryption: %v", err)
}
copy(p, data)
} // TODO if n == 0, read the remaining bytes and finalize
return n, nil
}