use crate::context::Function;
use crate::error::{Result, Rv};
use crate::mechanism::Mechanism;
use crate::object::ObjectHandle;
use crate::session::Session;
use cryptoki_sys::*;
use std::convert::TryInto;
impl Session {
pub fn decrypt(
&self,
mechanism: &Mechanism,
key: ObjectHandle,
encrypted_data: &[u8],
) -> Result<Vec<u8>> {
let mut mechanism: CK_MECHANISM = mechanism.into();
let mut data_len = 0;
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::DecryptInit)?;
}
unsafe {
Rv::from(get_pkcs11!(self.client(), C_Decrypt)(
self.handle(),
encrypted_data.as_ptr() as *mut u8,
encrypted_data.len().try_into()?,
std::ptr::null_mut(),
&mut data_len,
))
.into_result(Function::Decrypt)?;
}
let mut data = vec![0; data_len.try_into()?];
unsafe {
Rv::from(get_pkcs11!(self.client(), C_Decrypt)(
self.handle(),
encrypted_data.as_ptr() as *mut u8,
encrypted_data.len().try_into()?,
data.as_mut_ptr(),
&mut data_len,
))
.into_result(Function::Decrypt)?;
}
data.truncate(data_len.try_into()?);
Ok(data)
}
pub fn decrypt_init(&self, mechanism: &Mechanism, key: ObjectHandle) -> Result<()> {
let mut mechanism: CK_MECHANISM = mechanism.into();
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::DecryptInit)?;
}
Ok(())
}
pub fn decrypt_update(&self, encrypted_data: &[u8]) -> Result<Vec<u8>> {
let mut data_len = 0;
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptUpdate)(
self.handle(),
encrypted_data.as_ptr() as *mut u8,
encrypted_data.len().try_into()?,
std::ptr::null_mut(),
&mut data_len,
))
.into_result(Function::DecryptUpdate)?;
}
let mut data = vec![0; data_len.try_into()?];
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptUpdate)(
self.handle(),
encrypted_data.as_ptr() as *mut u8,
encrypted_data.len().try_into()?,
data.as_mut_ptr(),
&mut data_len,
))
.into_result(Function::DecryptUpdate)?;
}
data.truncate(data_len.try_into()?);
Ok(data)
}
pub fn decrypt_final(&self) -> Result<Vec<u8>> {
let mut data_len = 0;
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptFinal)(
self.handle(),
std::ptr::null_mut(),
&mut data_len,
))
.into_result(Function::DecryptFinal)?;
}
let mut data = vec![0; data_len.try_into()?];
unsafe {
Rv::from(get_pkcs11!(self.client(), C_DecryptFinal)(
self.handle(),
data.as_mut_ptr(),
&mut data_len,
))
.into_result(Function::DecryptFinal)?;
}
data.truncate(data_len.try_into()?);
Ok(data)
}
}