Module: PQCrypto::Seal::IOAPI
- Defined in:
- lib/pq_crypto/seal/io.rb
Constant Summary collapse
- DEFAULT_CHUNK_SIZE =
1024 * 1024
Class Method Summary collapse
- .add_recipient_file(source, destination, with:, recipient:, current_recipients:, **options) ⇒ Object
- .atomic_destination(destination) ⇒ Object
- .copy_exact(input, output, length, chunk_size) ⇒ Object
- .copy_exact_encrypted(input, output, encryptor, length, chunk_size) ⇒ Object
- .decrypt_file(source, destination, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, **limits) ⇒ Object
- .decrypt_frame_io(input, output, with:, **options) ⇒ Object
- .decrypt_io(input, output, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, strict_eof: true, **limits) ⇒ Object
- .decrypt_to_staging(input, staging, with:, chunk_size:, strict_eof:, **limits) ⇒ Object
- .drop_recipient_stanza_file(source, destination, with:, remaining_recipients:, **options) ⇒ Object
- .encrypt_file(source, destination, **options) ⇒ Object
- .encrypt_frame_io(input, output, size:, to:, **options) ⇒ Object
- .encrypt_io(input, output, size:, to:, metadata: "".b, public_metadata: "".b, recipient_capacity: Format::DEFAULT_RECIPIENT_CAPACITY, slot_size: Format::DEFAULT_SLOT_SIZE, padding: :padme, chunk_size: DEFAULT_CHUNK_SIZE, strict_size: true) ⇒ Object
- .fsync_directory(directory) ⇒ Object
- .inspect_file(source) ⇒ Object
- .new_staging(prefix, staging_directory) ⇒ Object
- .parse_verified_staging(staging, expected_size) ⇒ Object
- .read_exact(io, length) ⇒ Object
- .read_header(input) ⇒ Object
- .rebuild_recipients_file(source, destination, with:, recipients:, chunk_size: DEFAULT_CHUNK_SIZE) ⇒ Object
- .rotate_dek_file(source, destination, with:, recipients:, padding: :preserve, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE) ⇒ Object
- .seal(name, *args, **kwargs) ⇒ Object
- .unlink_open_tempfile(tempfile) ⇒ Object
- .validate_chunk_size(value) ⇒ Object
- .write_random_encrypted(output, encryptor, length, chunk_size) ⇒ Object
Class Method Details
.add_recipient_file(source, destination, with:, recipient:, current_recipients:, **options) ⇒ Object
142 143 144 145 146 147 |
# File 'lib/pq_crypto/seal/io.rb', line 142 def add_recipient_file(source, destination, with:, recipient:, current_recipients:, **) rebuild_recipients_file( source, destination, with: with, recipients: Array(current_recipients) + [recipient], ** ) end |
.atomic_destination(destination) ⇒ Object
246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 |
# File 'lib/pq_crypto/seal/io.rb', line 246 def atomic_destination(destination) path = File.(destination) directory = File.dirname(path) FileUtils.mkdir_p(directory) temp = Tempfile.new([".#{File.basename(path)}.", ".pqcseal"], directory) temp.binmode temp.chmod(0o600) begin yield temp temp.flush temp.fsync temp.close File.rename(temp.path, path) fsync_directory(directory) ensure temp.close! rescue nil end end |
.copy_exact(input, output, length, chunk_size) ⇒ Object
294 295 296 297 298 299 300 301 302 |
# File 'lib/pq_crypto/seal/io.rb', line 294 def copy_exact(input, output, length, chunk_size) remaining = length while remaining.positive? chunk = input.read([remaining, chunk_size].min) raise EOFError, "staging input is truncated" unless chunk && !chunk.empty? output.write(chunk) remaining -= chunk.bytesize end end |
.copy_exact_encrypted(input, output, encryptor, length, chunk_size) ⇒ Object
271 272 273 274 275 276 277 278 279 280 281 |
# File 'lib/pq_crypto/seal/io.rb', line 271 def copy_exact_encrypted(input, output, encryptor, length, chunk_size) copied = 0 while copied < length chunk = input.read([chunk_size, length - copied].min) break unless chunk && !chunk.empty? chunk = chunk.b output.write(encryptor.update(chunk)) copied += chunk.bytesize end copied end |
.decrypt_file(source, destination, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, **limits) ⇒ Object
91 92 93 94 95 96 97 98 99 100 101 102 |
# File 'lib/pq_crypto/seal/io.rb', line 91 def decrypt_file(source, destination, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, **limits) File.open(source, "rb") do |input| atomic_destination(destination) do |tmp| decrypt_io( input, tmp, with: with, staging_directory: staging_directory, chunk_size: chunk_size, strict_eof: true, **limits ) end end destination end |
.decrypt_frame_io(input, output, with:, **options) ⇒ Object
73 74 75 |
# File 'lib/pq_crypto/seal/io.rb', line 73 def decrypt_frame_io(input, output, with:, **) decrypt_io(input, output, with: with, strict_eof: false, **) end |
.decrypt_io(input, output, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, strict_eof: true, **limits) ⇒ Object
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 |
# File 'lib/pq_crypto/seal/io.rb', line 50 def decrypt_io(input, output, with:, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE, strict_eof: true, **limits) limits = Format::LIMIT_DEFAULTS.merge(limits) chunk_size = validate_chunk_size(chunk_size) staging = new_staging("pqcrypto-seal-inner", staging_directory) opened = decrypt_to_staging( input, staging, with: with, chunk_size: chunk_size, strict_eof: strict_eof, **limits ) staging.flush staging.rewind content_offset, content_length, = parse_verified_staging(staging, opened[:header].padded_inner_length) if content_length > Integer(limits[:max_plaintext_bytes]) seal(:wipe_string!, ) raise ResourceLimitError, "plaintext #{content_length} exceeds max_plaintext_bytes #{limits[:max_plaintext_bytes]}" end staging.seek(content_offset, ::IO::SEEK_SET) copy_exact(staging, output, content_length, chunk_size) Opened.from_header(opened[:header], opened[:section], data: nil, metadata: ) ensure staging.close! if defined?(staging) && staging end |
.decrypt_to_staging(input, staging, with:, chunk_size:, strict_eof:, **limits) ⇒ Object
189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 |
# File 'lib/pq_crypto/seal/io.rb', line 189 def decrypt_to_staging(input, staging, with:, chunk_size:, strict_eof:, **limits) limits = Format::LIMIT_DEFAULTS.merge(limits) header = read_header(input) Format.check_resource_limits!( padded_inner_length: header.padded_inner_length, **Format.pre_auth_limits(limits) ) section = Format.parse_section(read_exact(input, Format.section_length(header)), 0, header) estimated = header.raw.bytesize + section.raw.bytesize + header.padded_inner_length + Format::TAG_BYTES Format.check_resource_limits!( padded_inner_length: header.padded_inner_length, envelope_bytes: estimated, **Format.pre_auth_limits(limits) ) dek = seal(:unwrap_dek, header, section, with) decryptor = Native::Decryptor.new(dek, header.payload_nonce, Native.sha256(header.raw)) remaining = header.padded_inner_length while remaining.positive? take = [remaining, chunk_size].min staging.write(decryptor.update(read_exact(input, take))) remaining -= take end tag = read_exact(input, Format::TAG_BYTES) raise FormatError, "trailing bytes after envelope" if strict_eof && !input.read(1).nil? decryptor.final(tag) { header: header, section: section } ensure seal(:wipe_string!, dek) if defined?(dek) end |
.drop_recipient_stanza_file(source, destination, with:, remaining_recipients:, **options) ⇒ Object
149 150 151 |
# File 'lib/pq_crypto/seal/io.rb', line 149 def drop_recipient_stanza_file(source, destination, with:, remaining_recipients:, **) rebuild_recipients_file(source, destination, with: with, recipients: remaining_recipients, **) end |
.encrypt_file(source, destination, **options) ⇒ Object
81 82 83 84 85 86 87 88 89 |
# File 'lib/pq_crypto/seal/io.rb', line 81 def encrypt_file(source, destination, **) File.open(source, "rb") do |input| size = input.stat.size atomic_destination(destination) do |tmp| encrypt_io(input, tmp, size: size, strict_size: true, **) end end destination end |
.encrypt_frame_io(input, output, size:, to:, **options) ⇒ Object
77 78 79 |
# File 'lib/pq_crypto/seal/io.rb', line 77 def encrypt_frame_io(input, output, size:, to:, **) encrypt_io(input, output, size: size, to: to, strict_size: false, **) end |
.encrypt_io(input, output, size:, to:, metadata: "".b, public_metadata: "".b, recipient_capacity: Format::DEFAULT_RECIPIENT_CAPACITY, slot_size: Format::DEFAULT_SLOT_SIZE, padding: :padme, chunk_size: DEFAULT_CHUNK_SIZE, strict_size: true) ⇒ Object
12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 |
# File 'lib/pq_crypto/seal/io.rb', line 12 def encrypt_io(input, output, size:, to:, metadata: "".b, public_metadata: "".b, recipient_capacity: Format::DEFAULT_RECIPIENT_CAPACITY, slot_size: Format::DEFAULT_SLOT_SIZE, padding: :padme, chunk_size: DEFAULT_CHUNK_SIZE, strict_size: true) content_size = Integer(size) raise ArgumentError, "size must be non-negative" if content_size.negative? = String().b seal(:validate_private_metadata!, ) recipients = seal(:normalize_public_keys, to) capacity = Format.validate_capacity!(recipient_capacity, recipients.length) slot_size = Format.validate_slot_size!(slot_size) chunk_size = validate_chunk_size(chunk_size) parts = nil parts = seal( :materialize_crypto_parts, recipients: recipients, capacity: capacity, slot_size: slot_size, padding: padding, public_metadata: , content_size: content_size, metadata_size: .bytesize ) output.write(parts[:header]) output.write(parts[:section]) encryptor = Native::Encryptor.new(parts[:dek], parts[:payload_nonce], parts[:header_hash]) output.write(encryptor.update(parts[:inner_prefix])) output.write(encryptor.update()) unless .empty? copied = copy_exact_encrypted(input, output, encryptor, content_size, chunk_size) raise EOFError, "input ended after #{copied} of #{content_size} bytes" unless copied == content_size if strict_size raise ArgumentError, "input contains more bytes than declared size" unless input.read(1).nil? end write_random_encrypted(output, encryptor, parts[:padded_inner_length] - parts[:raw_inner_length], chunk_size) output.write(encryptor.final) output ensure seal(:wipe_string!, parts[:dek]) if parts seal(:wipe_string!, ) if .is_a?(String) && !.frozen? end |
.fsync_directory(directory) ⇒ Object
265 266 267 268 269 |
# File 'lib/pq_crypto/seal/io.rb', line 265 def fsync_directory(directory) File.open(directory, "r") { |dir| dir.fsync } rescue SystemCallError, IOError nil end |
.inspect_file(source) ⇒ Object
179 180 181 182 183 184 185 186 187 |
# File 'lib/pq_crypto/seal/io.rb', line 179 def inspect_file(source) File.open(source, "rb") do |input| header = read_header(input) section = Format.parse_section(read_exact(input, Format.section_length(header)), 0, header) total = header.raw.bytesize + section.raw.bytesize + header.padded_inner_length + Format::TAG_BYTES raise FormatError, "file length does not match envelope" unless File.size(source) == total Inspection.from_header(header, section, envelope_bytes: total) end end |
.new_staging(prefix, staging_directory) ⇒ Object
315 316 317 318 319 320 321 |
# File 'lib/pq_crypto/seal/io.rb', line 315 def new_staging(prefix, staging_directory) tempfile = Tempfile.new([prefix, ".bin"], staging_directory) tempfile.binmode tempfile.chmod(0o600) unlink_open_tempfile(tempfile) tempfile end |
.parse_verified_staging(staging, expected_size) ⇒ Object
217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 |
# File 'lib/pq_crypto/seal/io.rb', line 217 def parse_verified_staging(staging, expected_size) raise FormatError, "staging size mismatch" unless staging.stat.size == expected_size staging.rewind prefix = read_exact(staging, 14) version = prefix.getbyte(0) flags = prefix.getbyte(1) raise FormatError, "unsupported inner version" unless version == Format::INNER_VERSION raise FormatError, "unknown inner flags" unless flags == Format::INNER_FLAGS hi, lo, = prefix.byteslice(2, 12).unpack("NNN") content_length = (hi << 32) | lo raise FormatError, "private metadata is too large" if > Format::MAX_PRIVATE_METADATA_BYTES minimum = 14 + + content_length raise FormatError, "inner lengths exceed authenticated frame" if minimum > expected_size = read_exact(staging, ) [14 + , content_length, ] end |
.read_exact(io, length) ⇒ Object
304 305 306 307 308 309 310 311 312 313 |
# File 'lib/pq_crypto/seal/io.rb', line 304 def read_exact(io, length) return "".b if length.zero? buffer = +"".b while buffer.bytesize < length chunk = io.read(length - buffer.bytesize) raise EOFError, "truncated envelope" unless chunk && !chunk.empty? buffer << chunk.b end buffer end |
.read_header(input) ⇒ Object
234 235 236 237 238 239 240 |
# File 'lib/pq_crypto/seal/io.rb', line 234 def read_header(input) prefix_len = Format::MAGIC.bytesize + 1 + 4 initial = read_exact(input, prefix_len) header_length = initial.byteslice(Format::MAGIC.bytesize + 1, 4).unpack1("N") raise FormatError, "invalid header length" if header_length < initial.bytesize || header_length > Format::MAX_HEADER_BYTES Format.parse_header(initial + read_exact(input, header_length - initial.bytesize)) end |
.rebuild_recipients_file(source, destination, with:, recipients:, chunk_size: DEFAULT_CHUNK_SIZE) ⇒ Object
104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 |
# File 'lib/pq_crypto/seal/io.rb', line 104 def rebuild_recipients_file(source, destination, with:, recipients:, chunk_size: DEFAULT_CHUNK_SIZE) chunk_size = validate_chunk_size(chunk_size) File.open(source, "rb") do |input| header = read_header(input) old_section = Format.parse_section(read_exact(input, Format.section_length(header)), 0, header) dek = seal(:unwrap_dek, header, old_section, with) public_keys = seal(:normalize_public_keys, recipients) Format.validate_capacity!(header.recipient_capacity, public_keys.length) new_section = seal( :build_recipient_section, recipients: public_keys, capacity: header.recipient_capacity, slot_size: header.slot_size, payload_id: header.payload_id, header_hash: Native.sha256(header.raw), dek: dek, wrap_suite_id: Format::WRAP_SUITE_MLKEM768_X25519_AEGIS256 ) atomic_destination(destination) do |tmp| tmp.write(header.raw) tmp.write(new_section) verifier = Native::Decryptor.new(dek, header.payload_nonce, Native.sha256(header.raw)) remaining = header.padded_inner_length while remaining.positive? take = [remaining, chunk_size].min ciphertext_chunk = read_exact(input, take) tmp.write(ciphertext_chunk) seal(:wipe_string!, verifier.update(ciphertext_chunk)) remaining -= take end payload_tag = read_exact(input, Format::TAG_BYTES) raise FormatError, "trailing bytes after envelope" unless input.read(1).nil? verifier.final(payload_tag) tmp.write(payload_tag) end ensure seal(:wipe_string!, dek) if defined?(dek) end destination end |
.rotate_dek_file(source, destination, with:, recipients:, padding: :preserve, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE) ⇒ Object
153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 |
# File 'lib/pq_crypto/seal/io.rb', line 153 def rotate_dek_file(source, destination, with:, recipients:, padding: :preserve, staging_directory: nil, chunk_size: DEFAULT_CHUNK_SIZE) plaintext = new_staging("pqcrypto-seal-rotation", staging_directory) opened = nil File.open(source, "rb") do |input| opened = decrypt_io(input, plaintext, with: with, staging_directory: staging_directory, chunk_size: chunk_size, strict_eof: true) end plaintext.flush plaintext.rewind info = inspect_file(source) padding = { to: info.envelope_bytes } if padding == :preserve atomic_destination(destination) do |tmp| encrypt_io( plaintext, tmp, size: plaintext.stat.size, to: recipients, metadata: opened., public_metadata: opened., recipient_capacity: info.recipient_capacity, slot_size: info.slot_size, padding: padding, chunk_size: chunk_size, strict_size: true ) end destination ensure plaintext.close! if defined?(plaintext) && plaintext seal(:wipe_string!, opened.) if defined?(opened) && opened && opened. end |
.seal(name, *args, **kwargs) ⇒ Object
242 243 244 |
# File 'lib/pq_crypto/seal/io.rb', line 242 def seal(name, *args, **kwargs) Seal.send(name, *args, **kwargs) end |
.unlink_open_tempfile(tempfile) ⇒ Object
323 324 325 326 327 |
# File 'lib/pq_crypto/seal/io.rb', line 323 def unlink_open_tempfile(tempfile) tempfile.unlink rescue SystemCallError, IOError, NotImplementedError nil end |
.validate_chunk_size(value) ⇒ Object
329 330 331 332 333 |
# File 'lib/pq_crypto/seal/io.rb', line 329 def validate_chunk_size(value) size = Integer(value) raise ArgumentError, "chunk_size must be positive" unless size.positive? size end |
.write_random_encrypted(output, encryptor, length, chunk_size) ⇒ Object
283 284 285 286 287 288 289 290 291 292 |
# File 'lib/pq_crypto/seal/io.rb', line 283 def write_random_encrypted(output, encryptor, length, chunk_size) remaining = length while remaining.positive? take = [remaining, chunk_size].min random = Native.random_bytes(take) output.write(encryptor.update(random)) seal(:wipe_string!, random) remaining -= take end end |