Files
libreoffice/package/source/zipapi/sha1context.cxx
Michael Stahl 9188ea83c3 tdf#114939 package,comphelper: Try both real SHA1 and StarOffice SHA1
... when importing ODF documents.

In CreatePackageEncryptionData(), add a 3rd SHA1 password hash,
PackageSHA1CorrectEncryptionKey, to EncryptionData.

Use it in ZipPackageStream::getDataStream(), which has 3 fall-backs
for SHA1 bugs now.

Also add a CorrectSHA1DigestContext, to be used together with
PackageSHA1CorrectEncryptionKey, and rename the existing one to
StarOfficeSHA1DigestContext, to be used together with the existing
2 PackageSHA1{UTF8,MS1252}EncryptionKey.

The fallback won't be used very often anyway: for the password SHA1
to be wrong, you need a password between 52 and 55 bytes long,
and for the SHA1/1K checksum to be wrong, you need a file
smaller than 1K with compressed size mod 64 between 52 and 55;
all XML files have enough random "chaff" added to be too large.

Test that we can read both correct SHA1 and StarOffice SHA1.

Change-Id: I988fa489b5e40c7657f404f18538f637d54d28f1
2018-01-12 23:31:43 +01:00

129 lines
3.9 KiB
C++

/* -*- Mode: C++; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- */
/*
* This file is part of the LibreOffice project.
*
* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
*
* This file incorporates work covered by the following license notice:
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed
* with this work for additional information regarding copyright
* ownership. The ASF licenses this file to you under the Apache
* License, Version 2.0 (the "License"); you may not use this file
* except in compliance with the License. You may obtain a copy of
* the License at http://www.apache.org/licenses/LICENSE-2.0 .
*/
#include <sal/config.h>
#include <comphelper/hash.hxx>
#include <com/sun/star/lang/DisposedException.hpp>
#include <rtl/digest.h>
#include <rtl/ref.hxx>
#include "sha1context.hxx"
using namespace ::com::sun::star;
// static
uno::Reference<xml::crypto::XDigestContext> StarOfficeSHA1DigestContext::Create()
{
::rtl::Reference<StarOfficeSHA1DigestContext> xResult = new StarOfficeSHA1DigestContext();
xResult->m_pDigest = rtl_digest_createSHA1();
if ( !xResult->m_pDigest )
throw uno::RuntimeException("Can not create cipher!" );
return uno::Reference< xml::crypto::XDigestContext >( xResult.get() );
}
StarOfficeSHA1DigestContext::~StarOfficeSHA1DigestContext()
{
if ( m_pDigest )
{
rtl_digest_destroySHA1( m_pDigest );
m_pDigest = nullptr;
}
}
void SAL_CALL StarOfficeSHA1DigestContext::updateDigest(const uno::Sequence<::sal_Int8>& aData)
{
::osl::MutexGuard aGuard( m_aMutex );
if ( !m_pDigest )
throw lang::DisposedException();
if ( rtl_Digest_E_None != rtl_digest_updateSHA1( m_pDigest, aData.getConstArray(), aData.getLength() ) )
{
rtl_digest_destroySHA1( m_pDigest );
m_pDigest = nullptr;
throw uno::RuntimeException();
}
}
uno::Sequence<::sal_Int8> SAL_CALL StarOfficeSHA1DigestContext::finalizeDigestAndDispose()
{
::osl::MutexGuard aGuard( m_aMutex );
if ( !m_pDigest )
throw lang::DisposedException();
uno::Sequence< sal_Int8 > aResult( RTL_DIGEST_LENGTH_SHA1 );
if ( rtl_Digest_E_None != rtl_digest_getSHA1( m_pDigest, reinterpret_cast< sal_uInt8* >( aResult.getArray() ), aResult.getLength() ) )
{
rtl_digest_destroySHA1( m_pDigest );
m_pDigest = nullptr;
throw uno::RuntimeException();
}
rtl_digest_destroySHA1( m_pDigest );
m_pDigest = nullptr;
return aResult;
}
uno::Reference<xml::crypto::XDigestContext> CorrectSHA1DigestContext::Create()
{
return new CorrectSHA1DigestContext();
}
struct CorrectSHA1DigestContext::Impl
{
::osl::Mutex m_Mutex;
::comphelper::Hash m_Hash{::comphelper::HashType::SHA1};
bool m_bDisposed{false};
};
CorrectSHA1DigestContext::CorrectSHA1DigestContext()
: m_pImpl(new Impl)
{
}
CorrectSHA1DigestContext::~CorrectSHA1DigestContext()
{
}
void SAL_CALL CorrectSHA1DigestContext::updateDigest(const uno::Sequence<::sal_Int8>& rData)
{
::osl::MutexGuard aGuard(m_pImpl->m_Mutex);
if (m_pImpl->m_bDisposed)
throw lang::DisposedException();
m_pImpl->m_Hash.update(reinterpret_cast<unsigned char const*>(rData.getConstArray()), rData.getLength());
}
uno::Sequence<::sal_Int8> SAL_CALL CorrectSHA1DigestContext::finalizeDigestAndDispose()
{
::osl::MutexGuard aGuard(m_pImpl->m_Mutex);
if (m_pImpl->m_bDisposed)
throw lang::DisposedException();
m_pImpl->m_bDisposed = true;
std::vector<unsigned char> const sha1(m_pImpl->m_Hash.finalize());
return uno::Sequence<sal_Int8>(reinterpret_cast<sal_Int8 const*>(sha1.data()), sha1.size());
}
/* vim:set shiftwidth=4 softtabstop=4 expandtab: */