Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 163 additions & 3 deletions deps/ncrypto/ncrypto.cc
Original file line numberDiff line numberDiff line change
Expand Up@@ -4481,12 +4481,79 @@ bool SSLCtxPointer::setCipherSuites(const char* ciphers) {

// ============================================================================

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
Cipher::Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher)
: cipher_(cipher.get()), fetched_cipher_(std::move(cipher)) {}
#endif

Cipher::Cipher(const Cipher& other) : cipher_(other.cipher_) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
cipher_ = nullptr;
}
}
#endif
}

Cipher& Cipher::operator=(const Cipher& other) {
if (this == &other) return *this;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
if (other.fetched_cipher_ != nullptr) {
if (EVP_CIPHER_up_ref(other.fetched_cipher_.get()) == 1) {
fetched_cipher_.reset(other.fetched_cipher_.get());
} else {
fetched_cipher_.reset();
cipher_ = nullptr;
return *this;
}
} else {
fetched_cipher_.reset();
}
#endif
cipher_ = other.cipher_;
return *this;
}

const Cipher Cipher::FromName(const char* name) {
return Cipher(EVP_get_cipherbyname(name));
const EVP_CIPHER* cipher = EVP_get_cipherbyname(name);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
MarkPopErrorOnReturn mark_pop_error_on_return;
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched(
EVP_CIPHER_fetch(nullptr, name, nullptr));
if (fetched == nullptr) return Cipher();

const int mode = EVP_CIPHER_mode(fetched.get());
const bool is_siv_mode =
#if OPENSSL_WITH_AES_SIV
mode == EVP_CIPH_SIV_MODE ||
#endif
#if OPENSSL_WITH_AES_GCM_SIV
mode == EVP_CIPH_GCM_SIV_MODE ||
#endif
false;
if (is_siv_mode) return Cipher(std::move(fetched));

return Cipher();
#else
return Cipher();
#endif
}

const Cipher Cipher::FromNid(int nid) {
return Cipher(EVP_get_cipherbynid(nid));
const EVP_CIPHER* cipher = EVP_get_cipherbynid(nid);
if (cipher != nullptr) return Cipher(cipher);

#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return FromName(name);
#endif

return Cipher();
}

const Cipher Cipher::FromCtx(const CipherCtxPointer& ctx) {
Expand DownExpand Up@@ -4540,6 +4607,24 @@ bool Cipher::isOcbMode() const {
return getMode() == EVP_CIPH_OCB_MODE;
}

bool Cipher::isSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isGcmSivMode() const {
if (!cipher_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool Cipher::isStreamMode() const {
if (!cipher_) return false;
return getMode() == EVP_CIPH_STREAM_CIPHER;
Expand DownExpand Up@@ -4594,6 +4679,14 @@ std::string_view Cipher::getModeLabel() const {
return "ocb";
case EVP_CIPH_OFB_MODE:
return "ofb";
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
return "siv";
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
return "gcm-siv";
#endif
case EVP_CIPH_WRAP_MODE:
return "wrap";
case EVP_CIPH_XTS_MODE:
Expand All@@ -4608,7 +4701,16 @@ const char* Cipher::getName() const {
if (!cipher_) return {};
// OBJ_nid2sn(EVP_CIPHER_nid(cipher)) is used here instead of
// EVP_CIPHER_name(cipher) for compatibility with BoringSSL.
return OBJ_nid2sn(getNid());
const int nid = getNid();
if (nid != NID_undef) {
const char* name = OBJ_nid2sn(nid);
if (name != nullptr) return name;
}
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
return EVP_CIPHER_get0_name(cipher_);
#else
return {};
#endif
}

bool Cipher::isSupportedAuthenticatedMode() const {
Expand All@@ -4617,6 +4719,12 @@ bool Cipher::isSupportedAuthenticatedMode() const {
case EVP_CIPH_GCM_MODE:
#ifndef OPENSSL_NO_OCB
case EVP_CIPH_OCB_MODE:
#endif
#if OPENSSL_WITH_AES_SIV
case EVP_CIPH_SIV_MODE:
#endif
#if OPENSSL_WITH_AES_GCM_SIV
case EVP_CIPH_GCM_SIV_MODE:
#endif
return true;
case EVP_CIPH_STREAM_CIPHER:
Expand DownExpand Up@@ -4730,6 +4838,24 @@ bool CipherCtxPointer::isWrapMode() const {
return getMode() == EVP_CIPH_WRAP_MODE;
}

bool CipherCtxPointer::isSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_SIV
return getMode() == EVP_CIPH_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isGcmSivMode() const {
if (!ctx_) return false;
#if OPENSSL_WITH_AES_GCM_SIV
return getMode() == EVP_CIPH_GCM_SIV_MODE;
#else
return false;
#endif
}

bool CipherCtxPointer::isChaCha20Poly1305() const {
if (!ctx_) return false;
return getNid() == NID_chacha20_poly1305;
Expand DownExpand Up@@ -6178,6 +6304,22 @@ struct CipherCallbackContext {
void operator()(const char* name) { cb(name); }
};

#if OPENSSL_WITH_AES_SIV
constexpr const char* kProviderOnlyAesSivCiphers[] = {
"aes-128-siv",
"aes-192-siv",
"aes-256-siv",
};
#endif

#if OPENSSL_WITH_AES_GCM_SIV
constexpr const char* kProviderOnlyAesGcmSivCiphers[] = {
"aes-128-gcm-siv",
"aes-192-gcm-siv",
"aes-256-gcm-siv",
};
#endif

#if OPENSSL_VERSION_MAJOR >= 3
template <class TypeName,
TypeName* fetch_type(OSSL_LIB_CTX*, const char*, const char*),
Expand DownExpand Up@@ -6244,6 +6386,24 @@ void Cipher::ForEach(Cipher::CipherNameCallback callback) {
array_push_back<EVP_CIPHER>,
#endif
&context);
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
auto maybe_push_provider_only_cipher = [&](const char* name) {
EVP_CIPHER* cipher = EVP_CIPHER_fetch(nullptr, name, nullptr);
if (cipher == nullptr) return;
EVP_CIPHER_free(cipher);
context.cb(name);
};
#endif
#if OPENSSL_WITH_AES_SIV
for (const char* name : kProviderOnlyAesSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#if OPENSSL_WITH_AES_GCM_SIV
for (const char* name : kProviderOnlyAesGcmSivCiphers) {
maybe_push_provider_only_cipher(name);
}
#endif
#endif
}

Expand Down
27 changes: 25 additions & 2 deletions deps/ncrypto/ncrypto.h
Original file line numberDiff line numberDiff line change
Expand Up@@ -105,6 +105,18 @@
#define OPENSSL_WITH_EVP_MAC 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 0)
#define OPENSSL_WITH_AES_SIV 1
#else
#define OPENSSL_WITH_AES_SIV 0
#endif

#if !defined(OPENSSL_IS_BORINGSSL) && OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_AES_GCM_SIV 1
#else
#define OPENSSL_WITH_AES_GCM_SIV 0
#endif

#if defined(OPENSSL_IS_BORINGSSL) || OPENSSL_VERSION_PREREQ(3, 2)
#define OPENSSL_WITH_SIGNATURE_CONTEXT_STRING 1
#else
Expand DownExpand Up@@ -437,9 +449,12 @@ class Cipher final {

Cipher() = default;
Cipher(const EVP_CIPHER* cipher) : cipher_(cipher) {}
Cipher(const Cipher&) = default;
Cipher& operator=(const Cipher&) = default;
Cipher(const Cipher& other);
Cipher& operator=(const Cipher& other);
inline Cipher& operator=(const EVP_CIPHER* cipher) {
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
fetched_cipher_.reset();
#endif
cipher_ = cipher;
return *this;
}
Expand All@@ -462,6 +477,8 @@ class Cipher final {
bool isCtrMode() const;
bool isCcmMode() const;
bool isOcbMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isStreamMode() const;
bool isChaCha20Poly1305() const;

Expand DownExpand Up@@ -533,6 +550,10 @@ class Cipher final {

private:
const EVP_CIPHER* cipher_ = nullptr;
#if OPENSSL_WITH_AES_SIV || OPENSSL_WITH_AES_GCM_SIV
explicit Cipher(DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> cipher);
DeleteFnPtr<EVP_CIPHER, EVP_CIPHER_free> fetched_cipher_;
#endif
};

// ============================================================================
Expand DownExpand Up@@ -933,6 +954,8 @@ class CipherCtxPointer final {
bool isOcbMode() const;
bool isCcmMode() const;
bool isWrapMode() const;
bool isSivMode() const;
bool isGcmSivMode() const;
bool isChaCha20Poly1305() const;

bool update(const Buffer<const unsigned char>& in,
Expand Down
Loading
Loading