1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
//! The module's error state, where every crate can see it.
//!
//! A cryptographic module that finds itself wrong -- a known-answer test that
//! fails, corruption detected by its host -- must stop producing output, and
//! must not start again until it is restarted. `ic_fips` runs the tests and
//! holds the rest of the module's state, but the primitive crates cannot
//! depend on it: it depends on them. So the one fact they all need lives
//! here, below them, as a flag that can be set and never cleared.
//!
//! Once [`enter_error_state`] has been called, every operation in this
//! library that can report an error reports
//! [`ErrorKind::ModuleErrorState`] and does nothing else: encryption and decryption, signing and verification,
//! key generation and agreement, MACs made from a key, key derivation and
//! random generation. The operations that return `bool` return `false`.
//!
//! # What this does not gate
//!
//! What has no error to return cannot refuse, and goes on working in the
//! error state:
//!
//! - Hash functions and XOFs: `Sha256::new`, `update` and `finalize`, and
//! BLAKE2 with or without a key.
//! - KMAC, whose constructor and `mac` are infallible. Only `verify` refuses.
//! - A MAC object's `update` and `finalize`, once it exists. HMAC, CMAC and
//! Poly1305 refuse where they are made, in `Mac::new`.
//! - ML-KEM's `keygen_deterministic` and `encapsulate_deterministic`, the
//! interfaces that take their randomness as arguments.
//!
//! One thing that could refuse is left ungated on purpose: a block cipher
//! object's `encrypt_block`, `decrypt_block` and `encrypt_blocks`. They are
//! the inner loop of every mode, and every mode refuses at its own entry, as
//! does `BlockCipher::new`; a check per block would be paid by all of them
//! to stop only raw single-block use of a key made before the failure.
//!
//! Parsing and encoding, which use no key, are not gated either.
//!
//! Nor does anything here require the self-tests to have run. A primitive
//! called before `ic_fips::initialize` works; only a module that has failed
//! refuses. `ic_fips::check` remains the gate for that and for approved
//! mode.
//!
//! # Cost
//!
//! One relaxed load of one byte per operation.
use crate::;
use ;
static FAILED: AtomicBool = new;
/// Put the module into its error state.
///
/// There is no way back short of restarting the process, by design: nothing
/// in this library clears the flag. Applications call
/// `ic_fips::enter_error_state`, which calls this.
/// Pass on the result of a conditional self-test, entering the error state
/// if it failed.
///
/// A conditional self-test is one a module runs on its own work as it goes:
/// the pairwise consistency test on a key pair it has just generated. Its
/// input is the module's own output, never a caller's, so a failure is not
/// something a peer can cause -- it means this module computed two things
/// that should agree and do not, and nothing it computes afterwards can be
/// vouched for.
///
/// Key generation wraps its test in this. The test functions themselves do
/// not enter the state, so that they can be shown rejecting a mismatched
/// pair without ending the process that shows it.
/// Whether the module is in its error state.
/// `Ok(())` unless the module is in its error state.
///
/// The first line of every operation that can refuse:
///
/// ```
/// fn service() -> ic_core::Result<()> {
/// ic_core::module::operational()?;
/// // ...
/// Ok(())
/// }
/// # service().unwrap();
/// ```