mirror of
https://github.com/ruby/ruby.git
synced 2022-11-09 12:17:21 -05:00
2e601c284c
The OpenSSL engine of Digest uses the low-level API of OpenSSL, whose use has been discouraged for years for multiple reasons. A long-standing issue on a FIPS-enabled system is that using ::Digest results in crashing the Ruby process, because the low-level API lacks the mechanism to report an error (the policy violation) and thus kills the process as a last resort[1][2]. Also, the upcoming OpenSSL 3.0 will deprecate it for future removal[3]. Compiling with -Wdeprecated-declarations will start to emit warnings. A proper fix for this is to make it use the EVP API instead. This is a non-trivial work as it requires backwards-incompatible changes to the framework interface of Digest::Base and rb_digest_metadata_t. It is more than 15 years ago that the openssl library became part of the standard library. It has implemented the exactly same functionality as OpenSSL::Digest, in fact, as a subclass of Digest::Class. There is not much point in having an identical code in the digest library. Let's just get rid of OpenSSL within digest. This leaves the C implementations and the CommonCrypto engine for Apple systems. A patch is being prepared for the openssl library to provide ::Digest constants for better performance[4]. [1] https://bugs.ruby-lang.org/issues/6946 [2] https://bugs.ruby-lang.org/issues/13681 [3] https://www.openssl.org/docs/OpenSSL300Design.html [4] https://github.com/ruby/openssl/pull/377
66 lines
1.8 KiB
C
66 lines
1.8 KiB
C
/* $RoughId: sha1init.c,v 1.2 2001/07/13 19:49:10 knu Exp $ */
|
|
/* $Id$ */
|
|
|
|
#include <ruby/ruby.h>
|
|
#include "../digest.h"
|
|
#if defined(SHA1_USE_COMMONDIGEST)
|
|
#include "sha1cc.h"
|
|
#else
|
|
#include "sha1.h"
|
|
#endif
|
|
|
|
static const rb_digest_metadata_t sha1 = {
|
|
RUBY_DIGEST_API_VERSION,
|
|
SHA1_DIGEST_LENGTH,
|
|
SHA1_BLOCK_LENGTH,
|
|
sizeof(SHA1_CTX),
|
|
(rb_digest_hash_init_func_t)SHA1_Init,
|
|
(rb_digest_hash_update_func_t)SHA1_Update,
|
|
(rb_digest_hash_finish_func_t)SHA1_Finish,
|
|
};
|
|
|
|
/*
|
|
* Document-class: Digest::SHA1 < Digest::Base
|
|
* A class for calculating message digests using the SHA-1 Secure Hash
|
|
* Algorithm by NIST (the US' National Institute of Standards and
|
|
* Technology), described in FIPS PUB 180-1.
|
|
*
|
|
* See Digest::Instance for digest API.
|
|
*
|
|
* SHA-1 calculates a digest of 160 bits (20 bytes).
|
|
*
|
|
* == Examples
|
|
* require 'digest'
|
|
*
|
|
* # Compute a complete digest
|
|
* Digest::SHA1.hexdigest 'abc' #=> "a9993e36..."
|
|
*
|
|
* # Compute digest by chunks
|
|
* sha1 = Digest::SHA1.new # =>#<Digest::SHA1>
|
|
* sha1.update "ab"
|
|
* sha1 << "c" # alias for #update
|
|
* sha1.hexdigest # => "a9993e36..."
|
|
*
|
|
* # Use the same object to compute another digest
|
|
* sha1.reset
|
|
* sha1 << "message"
|
|
* sha1.hexdigest # => "6f9b9af3..."
|
|
*/
|
|
void
|
|
Init_sha1(void)
|
|
{
|
|
VALUE mDigest, cDigest_Base, cDigest_SHA1;
|
|
|
|
#if 0
|
|
mDigest = rb_define_module("Digest"); /* let rdoc know */
|
|
#endif
|
|
mDigest = rb_digest_namespace();
|
|
cDigest_Base = rb_path2class("Digest::Base");
|
|
|
|
cDigest_SHA1 = rb_define_class_under(mDigest, "SHA1", cDigest_Base);
|
|
|
|
#undef RUBY_UNTYPED_DATA_WARNING
|
|
#define RUBY_UNTYPED_DATA_WARNING 0
|
|
rb_iv_set(cDigest_SHA1, "metadata",
|
|
Data_Wrap_Struct(0, 0, 0, (void *)&sha1));
|
|
}
|