2 * Routines to support checksumming of bytes.
4 * Copyright (C) 1996 Andrew Tridgell
5 * Copyright (C) 1996 Paul Mackerras
6 * Copyright (C) 2004-2022 Wayne Davison
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * In addition, as a special exception, the copyright holders give
14 * permission to dynamically link rsync with the OpenSSL and xxhash
15 * libraries when those libraries are being distributed in compliance
16 * with their license terms, and to distribute a dynamically linked
17 * combination of rsync and these libraries. This is also considered
18 * to be covered under the GPL's System Libraries exception.
20 * This program is distributed in the hope that it will be useful,
21 * but WITHOUT ANY WARRANTY; without even the implied warranty of
22 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
23 * GNU General Public License for more details.
25 * You should have received a copy of the GNU General Public License along
26 * with this program; if not, visit the http://fsf.org website.
33 # if XXH_VERSION_NUMBER >= 800
34 # define SUPPORT_XXH3 1
39 extern int whole_file;
40 extern int checksum_seed;
41 extern int protocol_version;
42 extern int proper_seed_order;
43 extern const char *checksum_choice;
45 #define NNI_BUILTIN (1<<0)
46 #define NNI_EVP (1<<1)
47 #define NNI_EVP_OK (1<<2)
49 struct name_num_item valid_checksums_items[] = {
51 { CSUM_XXH3_128, 0, "xxh128", NULL },
52 { CSUM_XXH3_64, 0, "xxh3", NULL },
55 { CSUM_XXH64, 0, "xxh64", NULL },
56 { CSUM_XXH64, 0, "xxhash", NULL },
58 { CSUM_MD5, NNI_BUILTIN|NNI_EVP, "md5", NULL },
59 { CSUM_MD4, NNI_BUILTIN|NNI_EVP, "md4", NULL },
60 { CSUM_NONE, 0, "none", NULL },
64 struct name_num_obj valid_checksums = {
65 "checksum", NULL, 0, 0, valid_checksums_items
68 struct name_num_item valid_auth_checksums_items[] = {
69 { CSUM_MD5, NNI_BUILTIN|NNI_EVP, "md5", NULL },
70 { CSUM_MD4, NNI_BUILTIN|NNI_EVP, "md4", NULL },
74 struct name_num_obj valid_auth_checksums = {
75 "daemon auth checksum", NULL, 0, 0, valid_auth_checksums_items
78 /* These cannot make use of openssl, so they're marked just as built-in */
79 struct name_num_item implied_checksum_md4 =
80 { CSUM_MD4, NNI_BUILTIN, "md4", NULL };
81 struct name_num_item implied_checksum_md5 =
82 { CSUM_MD5, NNI_BUILTIN, "md5", NULL };
84 struct name_num_item *xfer_sum_nni; /* used for the transfer checksum2 computations */
85 const EVP_MD *xfer_sum_evp_md;
87 struct name_num_item *file_sum_nni; /* used for the pre-transfer --checksum computations */
88 const EVP_MD *file_sum_evp_md;
92 EVP_MD_CTX *ctx_evp = NULL;
94 static int initialized_choices = 0;
96 struct name_num_item *parse_csum_name(const char *name, int len)
98 struct name_num_item *nni;
103 init_checksum_choices();
105 if (!name || (len == 4 && strncasecmp(name, "auto", 4) == 0)) {
106 if (protocol_version >= 30) {
107 if (!proper_seed_order)
108 return &implied_checksum_md5;
112 if (protocol_version >= 27)
113 implied_checksum_md4.num = CSUM_MD4_OLD;
114 else if (protocol_version >= 21)
115 implied_checksum_md4.num = CSUM_MD4_BUSTED;
117 implied_checksum_md4.num = CSUM_MD4_ARCHAIC;
118 return &implied_checksum_md4;
122 nni = get_nni_by_name(&valid_checksums, name, len);
125 rprintf(FERROR, "unknown checksum name: %s\n", name);
126 exit_cleanup(RERR_UNSUPPORTED);
132 static const EVP_MD *csum_evp_md(struct name_num_item *nni)
136 if (!(nni->flags & NNI_EVP))
140 if (nni->num == CSUM_MD5)
144 emd = EVP_get_digestbyname(nni->name);
145 if (emd && !(nni->flags & NNI_EVP_OK)) { /* Make sure it works before we advertise it */
146 if (!ctx_evp && !(ctx_evp = EVP_MD_CTX_create()))
147 out_of_memory("csum_evp_md");
148 /* Some routines are marked as legacy and are not enabled in the openssl.cnf file.
149 * If we can't init the emd, we'll fall back to our built-in code. */
150 if (EVP_DigestInit_ex(ctx_evp, emd, NULL) == 0)
153 nni->flags = (nni->flags & ~NNI_BUILTIN) | NNI_EVP_OK;
156 nni->flags &= ~NNI_EVP;
163 void parse_checksum_choice(int final_call)
165 if (valid_checksums.negotiated_nni)
166 xfer_sum_nni = file_sum_nni = valid_checksums.negotiated_nni;
168 char *cp = checksum_choice ? strchr(checksum_choice, ',') : NULL;
170 xfer_sum_nni = parse_csum_name(checksum_choice, cp - checksum_choice);
171 file_sum_nni = parse_csum_name(cp+1, -1);
173 xfer_sum_nni = file_sum_nni = parse_csum_name(checksum_choice, -1);
174 if (am_server && checksum_choice)
175 validate_choice_vs_env(NSTR_CHECKSUM, xfer_sum_nni->num, file_sum_nni->num);
177 xfer_sum_len = csum_len_for_type(xfer_sum_nni->num, 0);
178 file_sum_len = csum_len_for_type(file_sum_nni->num, 0);
179 xfer_sum_evp_md = csum_evp_md(xfer_sum_nni);
180 file_sum_evp_md = csum_evp_md(file_sum_nni);
182 if (xfer_sum_nni->num == CSUM_NONE)
185 /* Snag the checksum name for both write_batch's option output & the following debug output. */
186 if (valid_checksums.negotiated_nni)
187 checksum_choice = valid_checksums.negotiated_nni->name;
188 else if (checksum_choice == NULL)
189 checksum_choice = xfer_sum_nni->name;
191 if (final_call && DEBUG_GTE(NSTR, am_server ? 3 : 1)) {
192 rprintf(FINFO, "%s%s checksum: %s\n",
193 am_server ? "Server" : "Client",
194 valid_checksums.negotiated_nni ? " negotiated" : "",
199 int csum_len_for_type(int cst, BOOL flist_csum)
204 case CSUM_MD4_ARCHAIC:
205 /* The oldest checksum code is rather weird: the file-list code only sent
206 * 2-byte checksums, but all other checksums were full MD4 length. */
207 return flist_csum ? 2 : MD4_DIGEST_LEN;
210 case CSUM_MD4_BUSTED:
211 return MD4_DIGEST_LEN;
213 return MD5_DIGEST_LEN;
219 default: /* paranoia to prevent missing case values */
220 exit_cleanup(RERR_UNSUPPORTED);
225 /* Returns 0 if the checksum is not canonical (i.e. it includes a seed value).
226 * Returns 1 if the public sum order matches our internal sum order.
227 * Returns -1 if the public sum order is the reverse of our internal sum order.
229 int canonical_checksum(int csum_type)
233 case CSUM_MD4_ARCHAIC:
235 case CSUM_MD4_BUSTED:
244 default: /* paranoia to prevent missing case values */
245 exit_cleanup(RERR_UNSUPPORTED);
250 #ifndef USE_ROLL_SIMD /* See simd-checksum-*.cpp. */
252 a simple 32 bit checksum that can be updated from either end
253 (inspired by Mark Adler's Adler-32 checksum)
255 uint32 get_checksum1(char *buf1, int32 len)
259 schar *buf = (schar *)buf1;
262 for (i = 0; i < (len-4); i+=4) {
263 s2 += 4*(s1 + buf[i]) + 3*buf[i+1] + 2*buf[i+2] + buf[i+3] + 10*CHAR_OFFSET;
264 s1 += (buf[i+0] + buf[i+1] + buf[i+2] + buf[i+3] + 4*CHAR_OFFSET);
266 for (; i < len; i++) {
267 s1 += (buf[i]+CHAR_OFFSET); s2 += s1;
269 return (s1 & 0xffff) + (s2 << 16);
273 void get_checksum2(char *buf, int32 len, char *sum)
276 if (xfer_sum_evp_md) {
277 static EVP_MD_CTX *evp = NULL;
279 if (!evp && !(evp = EVP_MD_CTX_create()))
280 out_of_memory("get_checksum2");
281 EVP_DigestInit_ex(evp, xfer_sum_evp_md, NULL);
283 SIVALu(seedbuf, 0, checksum_seed);
284 EVP_DigestUpdate(evp, seedbuf, 4);
286 EVP_DigestUpdate(evp, (uchar *)buf, len);
287 EVP_DigestFinal_ex(evp, (uchar *)sum, NULL);
290 switch (xfer_sum_nni->num) {
291 #ifdef SUPPORT_XXHASH
293 SIVAL64(sum, 0, XXH64(buf, len, checksum_seed));
298 SIVAL64(sum, 0, XXH3_64bits_withSeed(buf, len, checksum_seed));
300 case CSUM_XXH3_128: {
301 XXH128_hash_t digest = XXH3_128bits_withSeed(buf, len, checksum_seed);
302 SIVAL64(sum, 0, digest.low64);
303 SIVAL64(sum, 8, digest.high64);
311 if (proper_seed_order) {
313 SIVALu(seedbuf, 0, checksum_seed);
314 md5_update(&m5, seedbuf, 4);
316 md5_update(&m5, (uchar *)buf, len);
318 md5_update(&m5, (uchar *)buf, len);
320 SIVALu(seedbuf, 0, checksum_seed);
321 md5_update(&m5, seedbuf, 4);
324 md5_result(&m5, (uchar *)sum);
329 case CSUM_MD4_BUSTED:
330 case CSUM_MD4_ARCHAIC: {
341 buf1 = new_array(char, len+4);
345 memcpy(buf1, buf, len);
347 SIVAL(buf1,len,checksum_seed);
351 for (i = 0; i + CSUM_CHUNK <= len; i += CSUM_CHUNK)
352 mdfour_update(&m, (uchar *)(buf1+i), CSUM_CHUNK);
355 * Prior to version 27 an incorrect MD4 checksum was computed
356 * by failing to call mdfour_tail() for block sizes that
357 * are multiples of 64. This is fixed by calling mdfour_update()
358 * even when there are no more bytes.
360 if (len - i > 0 || xfer_sum_nni->num > CSUM_MD4_BUSTED)
361 mdfour_update(&m, (uchar *)(buf1+i), len-i);
363 mdfour_result(&m, (uchar *)sum);
366 default: /* paranoia to prevent missing case values */
367 exit_cleanup(RERR_UNSUPPORTED);
371 void file_checksum(const char *fname, const STRUCT_STAT *st_p, char *sum)
373 struct map_struct *buf;
374 OFF_T i, len = st_p->st_size;
378 fd = do_open(fname, O_RDONLY, 0);
380 memset(sum, 0, file_sum_len);
384 buf = map_file(fd, len, MAX_MAP_SIZE, CHUNK_SIZE);
387 if (file_sum_evp_md) {
388 static EVP_MD_CTX *evp = NULL;
389 if (!evp && !(evp = EVP_MD_CTX_create()))
390 out_of_memory("file_checksum");
392 EVP_DigestInit_ex(evp, file_sum_evp_md, NULL);
394 for (i = 0; i + CHUNK_SIZE <= len; i += CHUNK_SIZE)
395 EVP_DigestUpdate(evp, (uchar *)map_ptr(buf, i, CHUNK_SIZE), CHUNK_SIZE);
397 remainder = (int32)(len - i);
399 EVP_DigestUpdate(evp, (uchar *)map_ptr(buf, i, remainder), remainder);
401 EVP_DigestFinal_ex(evp, (uchar *)sum, NULL);
404 switch (file_sum_nni->num) {
405 #ifdef SUPPORT_XXHASH
407 static XXH64_state_t* state = NULL;
408 if (!state && !(state = XXH64_createState()))
409 out_of_memory("file_checksum");
411 XXH64_reset(state, 0);
413 for (i = 0; i + CHUNK_SIZE <= len; i += CHUNK_SIZE)
414 XXH64_update(state, (uchar *)map_ptr(buf, i, CHUNK_SIZE), CHUNK_SIZE);
416 remainder = (int32)(len - i);
418 XXH64_update(state, (uchar *)map_ptr(buf, i, remainder), remainder);
420 SIVAL64(sum, 0, XXH64_digest(state));
426 static XXH3_state_t* state = NULL;
427 if (!state && !(state = XXH3_createState()))
428 out_of_memory("file_checksum");
430 XXH3_64bits_reset(state);
432 for (i = 0; i + CHUNK_SIZE <= len; i += CHUNK_SIZE)
433 XXH3_64bits_update(state, (uchar *)map_ptr(buf, i, CHUNK_SIZE), CHUNK_SIZE);
435 remainder = (int32)(len - i);
437 XXH3_64bits_update(state, (uchar *)map_ptr(buf, i, remainder), remainder);
439 SIVAL64(sum, 0, XXH3_64bits_digest(state));
442 case CSUM_XXH3_128: {
443 XXH128_hash_t digest;
444 static XXH3_state_t* state = NULL;
445 if (!state && !(state = XXH3_createState()))
446 out_of_memory("file_checksum");
448 XXH3_128bits_reset(state);
450 for (i = 0; i + CHUNK_SIZE <= len; i += CHUNK_SIZE)
451 XXH3_128bits_update(state, (uchar *)map_ptr(buf, i, CHUNK_SIZE), CHUNK_SIZE);
453 remainder = (int32)(len - i);
455 XXH3_128bits_update(state, (uchar *)map_ptr(buf, i, remainder), remainder);
457 digest = XXH3_128bits_digest(state);
458 SIVAL64(sum, 0, digest.low64);
459 SIVAL64(sum, 8, digest.high64);
468 for (i = 0; i + CHUNK_SIZE <= len; i += CHUNK_SIZE)
469 md5_update(&m5, (uchar *)map_ptr(buf, i, CHUNK_SIZE), CHUNK_SIZE);
471 remainder = (int32)(len - i);
473 md5_update(&m5, (uchar *)map_ptr(buf, i, remainder), remainder);
475 md5_result(&m5, (uchar *)sum);
480 case CSUM_MD4_BUSTED:
481 case CSUM_MD4_ARCHAIC: {
486 for (i = 0; i + CSUM_CHUNK <= len; i += CSUM_CHUNK)
487 mdfour_update(&m, (uchar *)map_ptr(buf, i, CSUM_CHUNK), CSUM_CHUNK);
489 /* Prior to version 27 an incorrect MD4 checksum was computed
490 * by failing to call mdfour_tail() for block sizes that
491 * are multiples of 64. This is fixed by calling mdfour_update()
492 * even when there are no more bytes. */
493 remainder = (int32)(len - i);
494 if (remainder > 0 || file_sum_nni->num > CSUM_MD4_BUSTED)
495 mdfour_update(&m, (uchar *)map_ptr(buf, i, remainder), remainder);
497 mdfour_result(&m, (uchar *)sum);
501 rprintf(FERROR, "Invalid checksum-choice for --checksum: %s (%d)\n",
502 file_sum_nni->name, file_sum_nni->num);
503 exit_cleanup(RERR_UNSUPPORTED);
510 static int32 sumresidue;
511 static md_context ctx_md;
512 #ifdef SUPPORT_XXHASH
513 static XXH64_state_t* xxh64_state;
516 static XXH3_state_t* xxh3_state;
518 static struct name_num_item *cur_sum_nni;
519 static const EVP_MD *cur_sum_evp_md;
522 int sum_init(struct name_num_item *nni, int seed)
527 nni = parse_csum_name(NULL, 0);
529 cur_sum_len = csum_len_for_type(nni->num, 0);
530 cur_sum_evp_md = csum_evp_md(nni);
533 if (cur_sum_evp_md) {
534 if (!ctx_evp && !(ctx_evp = EVP_MD_CTX_create()))
535 out_of_memory("file_checksum");
536 EVP_DigestInit_ex(ctx_evp, cur_sum_evp_md, NULL);
539 switch (cur_sum_nni->num) {
540 #ifdef SUPPORT_XXHASH
542 if (!xxh64_state && !(xxh64_state = XXH64_createState()))
543 out_of_memory("sum_init");
544 XXH64_reset(xxh64_state, 0);
549 if (!xxh3_state && !(xxh3_state = XXH3_createState()))
550 out_of_memory("sum_init");
551 XXH3_64bits_reset(xxh3_state);
554 if (!xxh3_state && !(xxh3_state = XXH3_createState()))
555 out_of_memory("sum_init");
556 XXH3_128bits_reset(xxh3_state);
563 mdfour_begin(&ctx_md);
567 case CSUM_MD4_BUSTED:
568 case CSUM_MD4_ARCHAIC:
569 mdfour_begin(&ctx_md);
576 default: /* paranoia to prevent missing case values */
577 exit_cleanup(RERR_UNSUPPORTED);
584 * Feed data into an MD4 accumulator, md. The results may be
585 * retrieved using sum_end(). md is used for different purposes at
586 * different points during execution.
588 * @todo Perhaps get rid of md and just pass in the address each time.
589 * Very slightly clearer and slower.
591 void sum_update(const char *p, int32 len)
594 if (cur_sum_evp_md) {
595 EVP_DigestUpdate(ctx_evp, (uchar *)p, len);
598 switch (cur_sum_nni->num) {
599 #ifdef SUPPORT_XXHASH
601 XXH64_update(xxh64_state, p, len);
606 XXH3_64bits_update(xxh3_state, p, len);
609 XXH3_128bits_update(xxh3_state, p, len);
613 md5_update(&ctx_md, (uchar *)p, len);
617 case CSUM_MD4_BUSTED:
618 case CSUM_MD4_ARCHAIC:
619 if (len + sumresidue < CSUM_CHUNK) {
620 memcpy(ctx_md.buffer + sumresidue, p, len);
626 int32 i = CSUM_CHUNK - sumresidue;
627 memcpy(ctx_md.buffer + sumresidue, p, i);
628 mdfour_update(&ctx_md, (uchar *)ctx_md.buffer, CSUM_CHUNK);
633 while (len >= CSUM_CHUNK) {
634 mdfour_update(&ctx_md, (uchar *)p, CSUM_CHUNK);
641 memcpy(ctx_md.buffer, p, sumresidue);
645 default: /* paranoia to prevent missing case values */
646 exit_cleanup(RERR_UNSUPPORTED);
650 /* The sum buffer only needs to be as long as the current checksum's digest
651 * len, not MAX_DIGEST_LEN. Note that for CSUM_MD4_ARCHAIC that is the full
652 * MD4_DIGEST_LEN even if the file-list code is going to ignore all but the
653 * first 2 bytes of it. */
654 void sum_end(char *sum)
657 if (cur_sum_evp_md) {
658 EVP_DigestFinal_ex(ctx_evp, (uchar *)sum, NULL);
661 switch (cur_sum_nni->num) {
662 #ifdef SUPPORT_XXHASH
664 SIVAL64(sum, 0, XXH64_digest(xxh64_state));
669 SIVAL64(sum, 0, XXH3_64bits_digest(xxh3_state));
671 case CSUM_XXH3_128: {
672 XXH128_hash_t digest = XXH3_128bits_digest(xxh3_state);
673 SIVAL64(sum, 0, digest.low64);
674 SIVAL64(sum, 8, digest.high64);
679 md5_result(&ctx_md, (uchar *)sum);
683 mdfour_update(&ctx_md, (uchar *)ctx_md.buffer, sumresidue);
684 mdfour_result(&ctx_md, (uchar *)sum);
686 case CSUM_MD4_BUSTED:
687 case CSUM_MD4_ARCHAIC:
689 mdfour_update(&ctx_md, (uchar *)ctx_md.buffer, sumresidue);
690 mdfour_result(&ctx_md, (uchar *)sum);
695 default: /* paranoia to prevent missing case values */
696 exit_cleanup(RERR_UNSUPPORTED);
700 #if defined SUPPORT_XXH3 || defined USE_OPENSSL
701 static void verify_digest(struct name_num_item *nni, BOOL check_auth_list)
704 static int xxh3_result = 0;
707 static int prior_num = 0, prior_flags = 0, prior_result = 0;
711 if (nni->num == CSUM_XXH3_64 || nni->num == CSUM_XXH3_128) {
715 for (j = 0; j < (int)sizeof buf; j++)
716 buf[j] = ' ' + (j % 96);
718 sum_update(buf, 32816);
719 sum_update(buf, 31152);
720 sum_update(buf, 32474);
721 sum_update(buf, 9322);
722 xxh3_result = XXH3_64bits_digest(xxh3_state) != 0xadbcf16d4678d1de ? -1 : 1;
725 nni->num = CSUM_gone;
731 if (BITS_SETnUNSET(nni->flags, NNI_EVP, NNI_BUILTIN|NNI_EVP_OK)) {
732 if (nni->num == prior_num && nni->flags == prior_flags) {
733 nni->flags = prior_result;
734 if (!(nni->flags & NNI_EVP))
735 nni->num = CSUM_gone;
737 prior_num = nni->num;
738 prior_flags = nni->flags;
739 if (!csum_evp_md(nni))
740 nni->num = CSUM_gone;
741 prior_result = nni->flags;
742 if (check_auth_list && (nni = get_nni_by_num(&valid_auth_checksums, prior_num)) != NULL)
743 verify_digest(nni, False);
750 void init_checksum_choices()
752 struct name_num_item *nni;
754 if (initialized_choices)
757 #if defined SUPPORT_XXH3 || defined USE_OPENSSL
758 for (nni = valid_checksums.list; nni->name; nni++)
759 verify_digest(nni, True);
761 for (nni = valid_auth_checksums.list; nni->name; nni++)
762 verify_digest(nni, False);
765 initialized_choices = 1;