Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ bouncycastle-base64 = { path = "./crypto/base64" }
bouncycastle-core = { path = "crypto/core" }
bouncycastle-core-test-framework = { path = "./crypto/core-test-framework" }
bouncycastle-factory = { path = "./crypto/factory" }
bouncycastle-factory-macros = { path = "./crypto/factory-macros" }
bouncycastle-hex = { path = "./crypto/hex" }
bouncycastle-hkdf = { path = "./crypto/hkdf" }
bouncycastle-hmac = { path = "./crypto/hmac" }
Expand Down
12 changes: 12 additions & 0 deletions crypto/factory-macros/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
[package]
name = "bouncycastle-factory-macros"
version.workspace = true
edition.workspace = true

[lib]
proc-macro = true

[dependencies]
syn = { version = "2", features = ["full"] }
quote = "1"
proc-macro2 = "1"
130 changes: 130 additions & 0 deletions crypto/factory-macros/src/factory.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,130 @@
//! Expansion for the `AlgorithmFactory` derive -- see the `AlgorithmFactory` entry point in the
//! crate root.

use proc_macro2::TokenStream;
use quote::quote;
use syn::{DataEnum, DeriveInput, Ident, Path, Type};

use crate::{as_data_enum, single_field_type};

/// Generates the `Default` and `crate::AlgorithmFactory` impls from the per-variant
/// `#[factory(...)]` attributes.
pub(crate) fn expand(input: &DeriveInput) -> syn::Result<TokenStream> {
let enum_name = &input.ident;
let variants = parse_factory_variants(as_data_enum(input)?)?;

let default_128 = variants.iter().find(|v| v.is_default_128_bit);
let default_256 = variants.iter().find(|v| v.is_default_256_bit);
let (Some(default_128), Some(default_256)) = (default_128, default_256) else {
return Err(syn::Error::new_spanned(
input,
"exactly one variant needs `#[factory(default_128_bit)]` and one needs \
`#[factory(default_256_bit)]`",
));
};
let default_128_ident = &default_128.ident;
let default_128_ty = &default_128.ty;
let default_256_ident = &default_256.ident;
let default_256_ty = &default_256.ty;

let idents: Vec<&Ident> = variants.iter().map(|v| &v.ident).collect();
let tys: Vec<&Type> = variants.iter().map(|v| &v.ty).collect();
let name_consts: Vec<&Path> = variants.iter().map(|v| &v.name_const).collect();

Ok(quote! {
impl ::std::default::Default for #enum_name {
fn default() -> #enum_name {
<#enum_name as crate::AlgorithmFactory>::default_128_bit()
}
}

impl crate::AlgorithmFactory for #enum_name {
fn default_128_bit() -> #enum_name {
Self::#default_128_ident(<#default_128_ty>::new())
}

fn default_256_bit() -> #enum_name {
Self::#default_256_ident(<#default_256_ty>::new())
}

fn new(alg_name: &str) -> Result<Self, crate::FactoryError> {
match alg_name {
crate::DEFAULT => Ok(<Self as ::std::default::Default>::default()),
crate::DEFAULT_128_BIT => {
Ok(<Self as crate::AlgorithmFactory>::default_128_bit())
}
crate::DEFAULT_256_BIT => {
Ok(<Self as crate::AlgorithmFactory>::default_256_bit())
}
#(#name_consts => Ok(Self::#idents(<#tys>::new())),)*
_ => Err(crate::FactoryError::UnsupportedAlgorithm(format!(
"The algorithm: \"{}\" is not a known {}",
alg_name,
stringify!(#enum_name),
))),
}
}
}
})
}

/// One enum variant's worth of parsed `#[factory(...)]` configuration.
struct FactoryVariant {
ident: Ident,
ty: Type,
name_const: Path,
is_default_128_bit: bool,
is_default_256_bit: bool,
}

/// Parses the `#[factory(...)]` helper attribute off every variant.
fn parse_factory_variants(data: &DataEnum) -> syn::Result<Vec<FactoryVariant>> {
data.variants
.iter()
.map(|variant| {
let ty = single_field_type(variant)?.clone();

let mut name_const = None;
let mut is_default_128_bit = false;
let mut is_default_256_bit = false;

for attr in &variant.attrs {
if !attr.path().is_ident("factory") {
continue;
}
attr.parse_nested_meta(|meta| {
if meta.path.is_ident("name") {
name_const = Some(meta.value()?.parse::<Path>()?);
Ok(())
} else if meta.path.is_ident("default_128_bit") {
is_default_128_bit = true;
Ok(())
} else if meta.path.is_ident("default_256_bit") {
is_default_256_bit = true;
Ok(())
} else {
Err(meta.error(
"unrecognized `factory` attribute; expected `name`, \
`default_128_bit`, or `default_256_bit`",
))
}
})?;
}

let name_const = name_const.ok_or_else(|| {
syn::Error::new_spanned(
variant,
"every variant needs `#[factory(name = ...)]` giving its algorithm-name constant",
)
})?;

Ok(FactoryVariant {
ident: variant.ident.clone(),
ty,
name_const,
is_default_128_bit,
is_default_256_bit,
})
})
.collect()
}
87 changes: 87 additions & 0 deletions crypto/factory-macros/src/hash.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
//! Expansion for the `Hash` derive -- see the `Hash` entry point in the crate root.

use proc_macro2::TokenStream;
use quote::quote;
use syn::{DataEnum, DeriveInput, Ident};

use crate::{as_data_enum, single_field_type};

/// Generates the `bouncycastle_core::traits::Hash` impl, forwarding every trait method to the
/// wrapped value of whichever variant the enum currently holds.
pub(crate) fn expand(input: &DeriveInput) -> syn::Result<TokenStream> {
let enum_name = &input.ident;
let idents = single_field_variant_idents(as_data_enum(input)?)?;

Ok(quote! {
impl ::bouncycastle_core::traits::Hash for #enum_name {
fn block_bitlen(&self) -> usize {
match self { #(Self::#idents(h) => h.block_bitlen(),)* }
}

fn output_len(&self) -> usize {
match self { #(Self::#idents(h) => h.output_len(),)* }
}

fn hash(self, data: &[u8]) -> Vec<u8> {
match self { #(Self::#idents(h) => h.hash(data),)* }
}

fn hash_out(self, data: &[u8], output: &mut [u8]) -> usize {
output.fill(0);
match self { #(Self::#idents(h) => h.hash_out(data, output),)* }
}

fn do_update(&mut self, data: &[u8]) {
match self { #(Self::#idents(h) => h.do_update(data),)* }
}

fn do_final(self) -> Vec<u8> {
match self { #(Self::#idents(h) => h.do_final(),)* }
}

fn do_final_out(self, output: &mut [u8]) -> usize {
output.fill(0);
match self { #(Self::#idents(h) => h.do_final_out(output),)* }
}

fn do_final_partial_bits(
self,
partial_byte: u8,
num_partial_bits: usize,
) -> Result<Vec<u8>, ::bouncycastle_core::errors::HashError> {
match self {
#(Self::#idents(h) => h.do_final_partial_bits(partial_byte, num_partial_bits),)*
}
}

fn do_final_partial_bits_out(
self,
partial_byte: u8,
num_partial_bits: usize,
output: &mut [u8],
) -> Result<usize, ::bouncycastle_core::errors::HashError> {
match self {
#(Self::#idents(h) => {
h.do_final_partial_bits_out(partial_byte, num_partial_bits, output)
})*
}
}

fn max_security_strength(&self) -> ::bouncycastle_core::traits::SecurityStrength {
match self { #(Self::#idents(h) => h.max_security_strength(),)* }
}
}
})
}

/// Collects each variant's ident, rejecting any variant that isn't a single-field tuple since
/// there would be no unambiguous value to forward the trait methods to.
fn single_field_variant_idents(data: &DataEnum) -> syn::Result<Vec<Ident>> {
data.variants
.iter()
.map(|v| {
single_field_type(v)?;
Ok(v.ident.clone())
})
.collect()
}
96 changes: 96 additions & 0 deletions crypto/factory-macros/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
//! Procedural derive macros that remove per-variant boilerplate from the enum-based algorithm
//! factories in `bouncycastle-factory` (e.g. `HashFactory`).
//!
//! This is a build-time-only proc-macro crate: `syn`/`quote`/`proc-macro2` are used to generate
//! code at compile time and are not linked into any downstream binary.
//!
//! Two derives are provided, meant to be used together on a single-field-tuple-variant enum.
//! Each shares its name with the trait it implements -- the derive lives in the macro namespace
//! and the trait in the type namespace, so e.g. `#[derive(Hash)]` and
//! `impl bouncycastle_core::traits::Hash for X` don't collide, the same way `serde::Serialize`
//! names both a trait and its derive:
//!
//! - [`macro@Hash`] generates the `bouncycastle_core::traits::Hash` trait impl, forwarding every
//! method to whichever variant the enum currently holds.
//! - [`macro@AlgorithmFactory`] generates `Default` and `crate::AlgorithmFactory` trait impls
//! (`new`/`default_128_bit`/`default_256_bit`), reading each variant's algorithm-name constant
//! and default-security-level markers from a `#[factory(...)]` helper attribute.
//!
//! # Usage Examples
//!
//! ```ignore
//! #[derive(Hash, AlgorithmFactory)]
//! pub enum HashFactory {
//! #[factory(name = SHA224_NAME)]
//! SHA224(sha2::SHA224),
//! #[factory(name = SHA3_256_NAME, default_128_bit)]
//! SHA3_256(sha3::SHA3_256),
//! #[factory(name = SHA3_512_NAME, default_256_bit)]
//! SHA3_512(sha3::SHA3_512),
//! }
//! ```
//!
//! # Layout
//!
//! `#[proc_macro_derive]` functions have to live at the crate root, so this file holds only the
//! entry points and the parsing helpers both derives share; each derive's expansion lives in its
//! own module (`hash`, `factory`).

#![forbid(unsafe_code)]
#![forbid(missing_docs)]

mod factory;
mod hash;

use proc_macro::TokenStream;
use syn::{Data, DataEnum, DeriveInput, Fields, Type, parse_macro_input};

/// Derives `bouncycastle_core::traits::Hash` for an enum whose variants are each a single-field
/// tuple wrapping a type that itself implements that trait. Every method is forwarded to the
/// wrapped variant, so adding a new algorithm only requires adding an enum variant -- no match
/// arms to update by hand.
#[proc_macro_derive(Hash, attributes(factory))]
pub fn derive_hash(input: TokenStream) -> TokenStream {
let input = parse_macro_input!(input as DeriveInput);
hash::expand(&input).unwrap_or_else(syn::Error::into_compile_error).into()
}

/// Derives `Default` and `AlgorithmFactory` (`new`/`default_128_bit`/`default_256_bit`) for an
/// enum whose variants are each a single-field tuple, using a `#[factory(...)]` helper attribute
/// on each variant to supply:
///
/// - `name = SOME_NAME_CONST` (required) -- the string constant `AlgorithmFactory::new` matches
/// on to construct that variant.
/// - `default_128_bit` / `default_256_bit` (each required on exactly one variant) -- marks which
/// variant `default_128_bit()`/`default_256_bit()` construct.
///
/// Generated code refers to `AlgorithmFactory`/`FactoryError`/`DEFAULT*` via `crate::`, so this
/// derive is only meant to be used on enums defined inside the `bouncycastle-factory` crate
/// itself.
#[proc_macro_derive(AlgorithmFactory, attributes(factory))]
pub fn derive_algorithm_factory(input: TokenStream) -> TokenStream {
let input = parse_macro_input!(input as DeriveInput);
factory::expand(&input).unwrap_or_else(syn::Error::into_compile_error).into()
}

/// Both derives only make sense on enums; anything else gets a pointed error rather than a
/// confusing failure from deeper in the expansion.
fn as_data_enum(input: &DeriveInput) -> syn::Result<&DataEnum> {
match &input.data {
Data::Enum(data) => Ok(data),
_ => Err(syn::Error::new_spanned(input, "this derive only supports enums")),
}
}

/// The wrapped type of a single-field tuple variant, which is the value both derives forward to.
fn single_field_type(variant: &syn::Variant) -> syn::Result<&Type> {
match &variant.fields {
Fields::Unnamed(fields) if fields.unnamed.len() == 1 => {
Ok(&fields.unnamed.first().expect("just checked len == 1").ty)
}
_ => Err(syn::Error::new_spanned(
variant,
"expected a single-field tuple variant, e.g. `Variant(SomeType)`",
)),
}
}
1 change: 1 addition & 0 deletions crypto/factory/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ edition.workspace = true

[dependencies]
bouncycastle-core.workspace = true
bouncycastle-factory-macros.workspace = true
bouncycastle-hkdf.workspace = true
bouncycastle-hmac.workspace = true
bouncycastle-sha2.workspace = true
Expand Down
Loading
Loading