1 2017-07-19 NIIBE Yutaka <gniibe@fsij.org>
3 * src/mod.c (mod_inv): Clear TMP.
5 * src/configure (REVISION): Generate even when no git.
7 * polarssl/library/bignum.c (mpi_exp_mod): Call mpi_grow for X
8 after the initialization of RR.
10 2017-07-18 NIIBE Yutaka <gniibe@fsij.org>
12 * src/configure: Bark when no git available.
14 2017-07-18 Anthony Romano <anthony.romano@coreos.com>
18 2017-07-18 Anthony Romano <anthony.romano@coreos.com>
20 * src/main.c (MEMORY_SIZE, MEM_HEAD_IS_CORRUPT, MEM_HEAD_CHECK):
22 (gnuk_malloc, gnuk_free): Add calls to MEM_HEAD_CHECK.
24 * src/gnuk.h (FATAL_HEAP): New.
26 2017-07-18 Anthony Romano <anthony.romano@coreos.com>
28 * src/openpgp-do.c (gpg_reset_algo_attr): New.
29 (rw_algorithm_attr): Use gpg_reset_algo_attr.
32 2017-07-18 Anthony Romano <anthony.romano@coreos.com>
34 * src/mod.c (mod_reduce): Clean up unused code.
36 2017-07-18 Anthony Romano <anthony.romano@coreos.com>
38 * src/call-rsa.c (modulus_calc): Free modulus on error.
39 (rsa_genkey): Remove bogus check, and call chopstx_cleanup_pop
40 with 1 to release p_q_modulus on error. Assign NULL to clp.arg
41 when it's goes with no error.
43 * src/main.c (gnuk_free): Allow NULL.
45 2017-07-18 NIIBE Yutaka <gniibe@fsij.org>
47 * Update chopstx (with USBIP emulation).
49 2017-05-12 NIIBE Yutaka <gniibe@fsij.org>
53 2017-04-28 NIIBE Yutaka <gniibe@fsij.org>
55 * src/mcu-stm32f103.c: New.
56 (check_crc32, sram_address): New.
58 * src/usb_ctrl.c (download_check_crc32): Use check_crc32 and
61 * src/openpgp-do.c (gpg_write_digital_signature_counter): Fix
64 2017-04-27 NIIBE Yutaka <gniibe@fsij.org>
66 * src/gnuk.ld.in (_data_pool): Move to the end.
68 * src/flash.c (flash_init): Return address of end of data object.
69 * src/openpgp.c (gpg_init): Get address of end of data object.
70 * src/openpgp-do.c (gpg_data_scan): Check the end address.
72 2017-02-02 NIIBE Yutaka <gniibe@fsij.org>
76 * src/gnuk.ld.in (__process1_stack_size__): Increase by 0x20.
77 * chopstx: Update to 1.3.
78 * src/configure: Add BLUE_PILL in the help message.
80 2017-02-01 NIIBE Yutaka <gniibe@fsij.org>
82 * README: Update README. Thanks to Paul Fertser.
84 2017-01-02 Szczepan Zalega <szczepan@nitrokey.com>
86 * tool/upgrade_by_passwd.py: Add file extention check.
88 2017-02-01 NIIBE Yutaka <gniibe@fsij.org>
90 * tool/upgrade_by_passwd.py (main): More verbose messages
91 suggested by Szczepan Zalega <szczepan@nitrokey.com>.
93 * tool/gnuk_token.py (USB_PRODUCT_LIST): New.
94 (gnuk_devices_by_vidpid): Support searching by USB_PRODUCT_LIST.
95 Thanks to Szczepan Zalega <szczepan@nitrokey.com>.
97 * tool/usb_strings.py: Use gnuk_token.py.
99 2016-10-21 Niibe Yutaka <gniibe@fsij.org>
101 * src/ecc.c (check_secret): Fix condition.
103 2016-10-15 NIIBE Yutaka <gniibe@fsij.org>
107 * tool/gnuk_put_binary_libusb.py (main): Likewise.
108 * tool/upgrade_by_passwd.py (main): Add call of cmd_select_openpgp
111 * src/openpgp.c (gpg_init): flash_init_keys shoule be after
112 gpg_data_scan since flash_init_keys accesses Data Object for
115 * src/usb-ccid.c (ccid_power_on): Don't waste stack.
117 2016-10-14 Niibe Yutaka <gniibe@fsij.org>
119 * src/usb-ccid.c (ccid_power_on) [LIFE_CYCLE_MANAGEMENT_SUPPORT]:
120 Change LCS value in ATR at run time.
122 * src/openpgp.c (gpg_init): Handle FILE_CARD_TERMINATED.
123 (cmd_select_file): Don't return AID.
124 (cmd_activate_file, cmd_terminate_df): New.
125 (process_command_apdu): Let return GPG_NO_RECORD() when
128 * src/openpgp-do.c (gpg_do_terminate): New.
129 (gpg_data_scan): Handle p_start is NULL.
130 (do_hist_bytes): Remove.
132 * src/flash.c (flash_data): Change the value from 0x0000.
133 (flash_init): Support termination state. Fix handling
134 of the boundary case where gen0 is 0xfffe.
135 (flash_terminate, flash_activate): New.
136 (flash_copying_gc): Skip 0xffff for generation number.
138 2016-10-13 Niibe Yutaka <gniibe@fsij.org>
140 * src/status-code.h: Rename from openpgp.h.
142 * chopstx: Update to 1.2.
144 * tests: New test suite for OpenPGP card with PyTest.
146 * src/configure (factory_reset): New.
148 * src/usb-ccid.c (ccid_power_on): Use ATR_head and historical
151 * src/openpgp-do.c (rw_algorithm_attr): Clear fingerprint, timestamp,
152 and possibly ds_counter.
154 2016-10-12 Niibe Yutaka <gniibe@fsij.org>
156 * test/features/steps.py (cmd_reset_retry_counter): Fix.
157 * tool/gnuk_token.py (gnuk_token.cmd_reset_retry_counter): Fix.
158 (gnuk_token.cmd_select_openpgp): Fix P2.
160 2016-09-02 Niibe Yutaka <gniibe@fsij.org>
162 * src/configure (REVISION): Fix the detection of .git.
163 It may be a regular file (if it's created by worktree).
165 2016-08-24 Niibe Yutaka <gniibe@fsij.org>
167 * test/features/steps.py (ini): Use GLC (the global context),
168 instead of FTC (the feature context), so that token only is
171 2016-08-03 Niibe Yutaka <gniibe@fsij.org>
173 * tool/hub_ctrl.py: Port to Python 3.
175 2016-07-11 NIIBE Yutaka <gniibe@fsij.org>
179 * src/usb-ccid.c (ccid_power_on): Fix call of chopstx_create.
180 * src/usb-msc.c (msc_init): Ditto.
181 * src/pin-cir.c (cir_init): Ditto.
182 * src/neug.c (neug_init): Ditto.
183 * src/main.c (main): Ditto.
185 * src/usb-ccid.c (struct ccid): Arrange for smaller footprint.
186 * src/gnuk.h (struct apdu): Likewise.
188 * src/usb-ccid.c (ccid_card_change_signal): Don't touch ccid_state_p.
189 (ccid_state_p): This is constant.
191 * src/configure (output_vendor_product_serial_strings): Add const
194 * src/usb-ccid.c (epo_init, epi_init): Simplify without notify method.
195 (EP1_IN_Callback, EP1_OUT_Callback): Call notify_tx and notify_icc
198 2016-07-09 NIIBE Yutaka <gniibe@fsij.org>
200 * src/openpgp.c (openpgp_card_thread): Don't need to get SELF.
202 2016-07-06 NIIBE Yutaka <gniibe@fsij.org>
204 * src/pin-cir.c (cir_getchar): Use chopstx_poll.
205 * src/usb-ccid.c (usb_tx_done): Fix ifdef condition.
206 * src/usb_ctrl.c (usb_ctrl_write_finish): Fix ifdef nesting.
208 2016-07-04 NIIBE Yutaka <gniibe@fsij.org>
210 * doc/conf.py: Remove 'sphinx.ext.pngmath' and 'sphinx.ext.mathjax'.
211 Reported by Kenji Rikitake.
213 2016-07-01 NIIBE Yutaka <gniibe@fsij.org>
215 * chopstx: Update to 1.1.
216 * src/usb-ccid.c (poll_event_intr, ccid_thread): Follow the
219 2016-06-21 Niibe Yutaka <gniibe@fsij.org>
221 * doc/index.rst: Update documentation by an example
224 2016-06-17 Niibe Yutaka <gniibe@fsij.org>
226 * chopstx: Update to 1.0.
228 2016-06-15 NIIBE Yutaka <gniibe@fsij.org>
230 * src/gnuk.ld.in (__process2_stack_size__): Update
231 thread size for rng by examining NeuG.
233 * src/usb-ccid.c (poll_event_intr): New.
235 2016-06-14 Niibe Yutaka <gniibe@fsij.org>
237 * regnual/regnual.c (usb_device_reset): Rename from
239 (usb_ctrl_write_finish): Rename from usb_cb_ctrl_write_finish.
240 (usb_setup): Rename from usb_cb_setup.
241 (usb_get_descriptor): Rename from usb_cb_get_descriptor.
242 (usb_set_configuration): New.
243 (usb_interrupt_handler): New.
245 * src/usb-ccid.c (usb_tx_done): Rename from usb_cb_tx_done.
246 (usb_rx_ready): Rename from usb_cb_rx_ready.
247 (usb_event_handle): New.
248 (ccid_thread): Use usb_event_handle.
250 * src/usb-msc.c (EP6_IN_Callback): Update to new USB API.
251 (EP6_OUT_Callback): Likewise.
253 * src/usb_ctrl.c (usb_device_reset): Rename from
255 (vcom_port_data_setup): Update to new USB API.
256 (usb_ctrl_write_finish): Rename from usb_cb_ctrl_write_finish.
257 (usb_setup): Rename from usb_cb_setup.
258 (usb_set_configuration): New, based on usb_cb_handle_event.
259 (usb_set_interface): Rename from usb_cb_interface.
260 (usb_get_interface): New.
261 (usb_get_status_interface): New.
263 * src/usb_desc.c (usb_get_descriptor): Rename from
264 usb_cb_get_descriptor.
266 2016-06-02 Niibe Yutaka <gniibe@fsij.org>
268 * regnual/regnual.c (usb_cb_tx_done): Follow the change of USB
271 * regnual/reset.c: Rename from sys.c.
273 2016-06-01 Niibe Yutaka <gniibe@fsij.org>
275 * tool/stlinkv2.py (stlinkv2.__init__): Don't
276 call setConfiguration.
278 * tool/gnuk_token.py (gnuk_token, regnual): Don't
279 call setAltInterface, it's not needed.
281 * src/usb-ccid.c (ccid_notify_slot_change): New.
282 (ccid_thread): Call ccid_notify_slot_change at
283 interface_reset and EV_CARD_CHANGE.
285 2016-05-31 NIIBE Yutaka <gniibe@fsij.org>
287 * src/usb_stm32f103.c, src/stm32f103.h: Remove.
288 * src/adc_stm32f103.c, src/sys.c: Remove.
290 * src/usb_ctrl.c (usb_cb_interface): call ccid_usb_reset.
291 (usb_cb_handle_event): Likewise.
293 * src/usb-ccid.c (ccid_thread): Handle RESET->CONFIGURE process
295 (ccid_thread): Handle SET_INTERFACE correctly.
297 * polarssl/library/aes.c (FT0, FT1, FT2): Add "weak" flag.
299 * src/neug.c: Update from NeuG.
301 * src/usb_desc.c (usb_cb_get_descriptor): Only valid if USE_SYS3.
303 * src/Makefile.in (USE_SYS, USE_USB, USE_ADC): Enabled.
306 * src/sys.c, src/sys.h: Remove.
307 * src/usb_stm32f103.c, src/usb_lld.h: Remove.
308 * src/adc_stm32f103.c, src/adc.h: Remove.
310 * chopstx: Update to 0.12.
312 2016-05-21 Niibe Yutaka <gniibe@fsij.org>
314 * src/main.c (led_blink, main): Fix LED blink protocol.
316 2016-05-20 NIIBE Yutaka <gniibe@fsij.org>
319 * src/usb-ccid.c (ccid_thread): Fix timeout.
320 (icc_handle_timeout, icc_send_status): Tweak.
322 2016-05-19 Niibe Yutaka <gniibe@fsij.org>
324 * src/usb_ctrl.c (usb_cb_ctrl_write_finish): Set bDeviceState.
326 * src/usb-ccid.c: Rename from usb-icc.c.
327 (ccid_thread): Handle reGNUal upgrade.
329 * src/Makefile.in (CSRC): Follow the change.
331 * chopstx: Update to 0.11.
333 2016-05-18 Niibe Yutaka <gniibe@fsij.org>
335 * src/gnuk.ld.in: Tweak thread size.
336 * src/main.c (main): Use chopstx_setpriority.
337 * src/usb-icc.c (ccid_init): Use new eventflag API.
339 * regnual/regnual.c (nvic_enable_intr): New.
340 (main): Call nvic_enable_intr.
344 2016-05-16 Niibe Yutaka <gniibe@fsij.org>
346 * regnual/regnual.c (usb_cb_rx_ready, usb_cb_tx_done)
347 (usb_cb_device_reset): Follow the change of USB API.
350 * src/sys.c: Update from Chopstx.
352 2016-05-13 Niibe Yutaka <gniibe@fsij.org>
354 * src/neug.c (rng): Call chopstx_claim_irq before adc_start.
355 Remove call of chopstx_release_irq.
357 2016-05-12 Niibe Yutaka <gniibe@fsij.org>
360 * src/sys.c: Update from Chopstx.
361 * src/usb_lld.h: Likewise.
362 * src/usb_stm32f103.c: Likewise.
364 * src/usb_ctrl.c (usb_intr): Follow the change of USB API.
365 (usb_cb_rx_ready, usb_cb_tx_done): Likewise.
367 * src/adc.h: Remove unused declarations.
369 2016-03-08 Niibe Yutaka <gniibe@fsij.org>
371 * tool/gnuk_token.py (gnuk_token.__init__, regnual.__init__):
372 Don't call setConfiguration method.
374 * src/usb_lld.h (usb_cb_ctrl_write_finish): Change the API of
375 callback, which possibly needs INDEX, VALUE, and LEN parameters.
376 (usb_lld_set_data_to_recv): Fix the type of P.
377 (USB_DEVICE_DESCRIPTOR_TYPE, USB_CONFIGURATION_DESCRIPTOR_TYPE)
378 (USB_STRING_DESCRIPTOR_TYPE, USB_INTERFACE_DESCRIPTOR_TYPE)
379 (USB_ENDPOINT_DESCRIPTOR_TYPE): Remove, as we have the enumeration
380 values for same things.
382 * src/usb_stm32f103.c (handle_in0): Follow the change.
383 * src/usb_ctrl.c (usb_cb_ctrl_write_finish): Likewise.
385 * src/usb_desc.c (usb_cb_get_descriptor): Use HID_INTERFACE.
386 (device_desc, config_desc, string_descriptors)
387 (usb_cb_get_descriptor): Use the enumeration types.
388 * src/configure: Use the enumeration types.
390 * regnual/regnual.c: Follow the change of usb_lld.h.
392 2016-02-09 Niibe Yutaka <gniibe@fsij.org>
394 * src/openpgp.c (cmd_verify): Support VERIFY reset, which is
395 described in the specification V2.2 and V3.1.
397 * polarssl/library/bignum.c (mpi_exp_mod): Fix to our local
398 change. Thanks to Aidan Thornton for the failure test case.
400 Fix of mpi_div_mpi from upstream.
401 * polarssl/library/bignum.c (int_clz, int_div_int): New.
402 (mpi_div_mpi): Use int_div_int.
404 2016-02-09 Niibe Yutaka <gniibe@fsij.org>
406 * src/openpgp.c (s2k): Include the unique ID of MCU into the
407 computation of S2K function.
409 2016-02-08 Niibe Yutaka <gniibe@fsij.org>
411 * src/modp256r1.c (modp256r1_add, modp256r1_sub): Keep the result
413 (modp256r1_reduce): Fix wrong calculation.
414 * src/modp256k1.c (modp256k1_add, modp256k1_sub): Likewise.
415 Thanks to Aidan Thornton.
417 2016-02-05 Niibe Yutaka <gniibe@fsij.org>
419 * src/configure: Add submodule check suggested by Elliott
422 2015-11-30 perillamint <perillamint@gentoo.moe>
424 * src/openpgp.c (card_thread): Fix offset of bConfirmPIN.
426 2015-09-18 Niibe Yutaka <gniibe@fsij.org>
430 * src/openpgp-do.c (proc_key_import): Fix error return.
431 (rw_algorithm_attr): Check it's not ALGO_RSA2K.
433 2015-09-17 Niibe Yutaka <gniibe@fsij.org>
437 2015-09-15 Niibe Yutaka <gniibe@fsij.org>
439 * chopstx: Update to 0.10.
441 * src/main.c (main): Don't join after calling ccid_usb_reset.
442 * src/usb-icc.c (ccid_thread): Don't finish on reset, but
445 * src/usb_ctrl.c (usb_cb_device_reset): Stop the interface.
447 * src/usb_stm32f103.c (std_set_interface): Bug fix for conf.
449 * src/gnuk.ld.in (__process3_stack_size__): Increase stack size of
451 (__process2_stack_size__): Increase stack size of RNG.
452 (__process4_stack_size__): Increase stack size of USB.
453 (__main_stack_size__): Decrease stack size of exception handlers.
454 (__process1_stack_size__): Decrease stack size of CCID.
456 2015-09-14 Niibe Yutaka <gniibe@fsij.org>
458 * src/gnuk.h (LED_GNUK_EXEC): New.
459 * src/main.c, src/usb-icc.c, src/usb_ctrl.c: icc_state_p access
462 2015-09-11 Niibe Yutaka <gniibe@fsij.org>
464 * tool/upgrade_by_passwd.py (main): Loop until finding reGNUal
467 2015-09-10 Niibe Yutaka <gniibe@fsij.org>
469 * src/call-rsa.c (rsa_cleanup): New.
470 (rsa_sign, rsa_decrypt, rsa_genkey): Allow cancellation.
471 * src/openpgp.c (cmd_pso, cmd_internal_authenticate): Cancellation
472 is handled by each functions in case of RSA.
474 2015-09-09 Niibe Yutaka <gniibe@fsij.org>
476 * src/sys.h: Update from Chopstx.
477 * src/adc_stm32f103.c: Update from NeuG.
479 * src/openpgp.c (process_command_apdu): Protect command execution
480 against cancelling the execution thread.
481 (cmd_pso, cmd_internal_authenticate): Allow cancellation.
483 * src/main.c (main): Handle LED_USB_RESET.
485 * src/usb-icc.c (ccid_usb_reset): New.
486 (ccid_thread): Upon receival of EV_USB_RESET, finish
487 the thread, canceling the card thread.
489 2015-09-08 Niibe Yutaka <gniibe@fsij.org>
491 * src/gnuk.h (EV_USB_RESET, LED_USB_RESET): New.
493 * src/usb_ctrl.c (CDC_CTRL_DTR): New.
494 (vcom_port_data_setup): Distinguish detail->value for DTR.
496 * src/configure (help): Add ST_DONGLE and ST_NUCLEO_F103.
498 2015-09-04 Niibe Yutaka <gniibe@fsij.org>
500 * src/openpgp-do.c (do_openpgpcard_aid): Use upper bytes of unique
501 ID of MCU; same as USB serial number.
503 * src/configure (help): Add NITROKEY_START.
505 2015-08-26 Mateusz Zalega <mateusz@nitrokey.com>
507 * GNUK_USB_DEVICE_ID: Add Nitrokey Start.
509 2015-08-05 Niibe Yutaka <gniibe@fsij.org>
513 2015-08-04 Niibe Yutaka <gniibe@fsij.org>
515 * src/adc_stm32f103.c: Update from NeuG 1.0.3.
517 * chopstx: Update to 0.08.
520 2015-08-03 Niibe Yutaka <gniibe@fsij.org>
522 * test/features/steps.py (set_msg): Python3 fix.
523 * test/generate_keys.py: Likewise.
524 * test/rsa_keys.py: Likewise.
526 * tool/gnuk_token.py (gnuk_token.download, gnuk_token.execute)
527 (regnual.download): Python3 fix.
528 (list_to_string): Remove.
530 * tool/upgrade_by_passwd.py (maian): Python3 fix.
531 * tool/usb_strings.py (main): Python3 fix.
533 2015-07-31 Niibe Yutaka <gniibe@fsij.org>
535 * src/configure (output_vendor_product_serial_strings): Fix sed
536 script when string is short. Remove empty line.
538 * regnual/regnual.c (usb_cb_ctrl_write_finish, usb_cb_setup)
539 (usb_cb_get_descriptor, usb_cb_interface): Follow the change
542 * tool/stlinkv2.py: Support ST-Link/V2-1.
544 2015-07-28 Niibe Yutaka <gniibe@fsij.org>
546 * tool/stlinkv2.py: Fix for Python3. Thanks to Bertrand Jacquin.
548 * tool/gpg_agent.py: Fix for Python3.
550 * src/usb-msc.c: Update from Fraucheky.
552 * src/usb_stm32f103.c (struct DATA_INFO): Remove offset.
553 (struct DEVICE_INFO): Integrate CONTROL_INFO.
555 2015-07-27 Niibe Yutaka <gniibe@fsij.org>
557 * src/usb_stm32f103.c (usb_lld_reply_request): New.
558 (usb_lld_set_data_to_send): Remove.
559 (usb_lld_set_data_to_recv): Not a macro but a function.
560 (std_get_status): Don't use statically allocated memory.
561 (std_get_configuration): Use usb_lld_reply_request.
562 (handle_setup0): Follow the change.
563 * src/usb_ctrl.c (vcom_port_data_setup, usb_cb_setup)
564 (usb_cb_interface): Use usb_lld_reply_request.
565 * src/usb_desc.c (usb_cb_get_descriptor): Likewise.
567 2015-07-24 Niibe Yutaka <gniibe@fsij.org>
569 * tool/gnuk_put_binary.py: Remove.
570 * tool/gnuk_remove_keys.py: Remove.
572 2015-07-23 Niibe Yutaka <gniibe@fsij.org>
574 * src/configure (nl): New. Follow the change of NeuG.
576 2015-07-21 Niibe Yutaka <gniibe@fsij.org>
580 2015-07-20 Niibe Yutaka <gniibe@fsij.org>
582 * src/openpgp-do.c (gpg_do_keygen): Support ECC.
583 * src/call-ec.c (ecc_check_secret): New.
584 * src/ecc.c (check_secret): New.
586 2015-07-18 Niibe Yutaka <gniibe@fsij.org>
588 * src/configure (keygen): It's always enabled.
589 * src/openpgp-do.c (gpg_do_keygen): Support key generation.
590 * src/openpgp.c (cmd_pgp_gakp): Likewise.
591 * src/call-rsa.c (rsa_genkey): Likewise.
592 * src/random.c (random_gen): Likewise.
593 * src/Makefile.in (KEYGEN_SUPPORT): Remove.
594 * polarssl/include/polarssl/config.h (POLARSSL_GENPRIME): Define.
596 2015-07-16 Niibe Yutaka <gniibe@fsij.org>
598 * src/configure (FLASH_PAGE_SIZE, FLASH_SIZE, MEMORY_SIZE)
599 [sys1_compat]: Use safe values for common binary.
600 (TARGET_DEFINE): Remove.
602 2015-07-15 Niibe Yutaka <gniibe@fsij.org>
604 * tool/usb_strings.py (field): Add 'Board'.
606 * regnual/regnual.c (usb_cb_get_descriptor): Update.
607 * src/usb_ctrl.c (usb_cb_interface): Call usb_lld_write.
608 * src/usb_desc.c (usb_cb_get_descriptor): Support sys_board_name,
610 * src/usb_lld.h (usb_cb_get_descriptor): Add last argument length
612 * src/usb_stm32f103.c (handle_setup0): Allow setup callback to
613 call usb_lld_write with ENDP0.
614 * src/usb_conf.h (NUM_STRING_DESC): Remove.
616 * src/configure [!sys1_compat] (CONFIG): Don't include target
619 * src/flash.c: Detect flash_page_size at runtime.
621 * src/main.c: Remove dependency to board.h.
623 * src/neug.c: Update from NeuG 1.0.2.
624 * src/adc_stm32f103.c: Update.
626 * chopstx: Update to 0.07.
629 * src/gnuk.ld.in: Update.
631 * tool/stlinkv2.py (stlinkv2.get_chip_id): New. Detect flash
633 (main): Call stlinkv2.get_chip_id after MCU reset and stop.
636 2015-07-11 Niibe Yutaka <gniibe@fsij.org>
638 * src/configure (help): Add STM32_PRIMER2 and CQ_STARM.
640 * chopstx: Update to 0.06.
642 * tool/stlinkv2.py: Support 512kB version of STM32F103.
643 The size of executable file should be even.
645 2015-07-07 Niibe Yutaka <gniibe@fsij.org>
647 * src/Makefile.in (CSRC): Add ecc-mont.c.
649 * src/ecc-mont.c (mod25638_mul_121665): Fix.
650 (ecdh_compute_public_25519, ecdh_decrypt_curve25519): New.
652 * src/openpgp.c (cmd_pso): Support ALGO_CURVE25519.
654 * src/openpgp-do.c (algorithm_attr_cv25519): New.
655 (rw_algorithm_attr, get_algo_attr_data_object)
656 (gpg_get_algo_attr_key_size, gpg_do_write_prvkey)
657 (proc_key_import, gpg_do_public_key): Support ALGO_CURVE25519.
659 * src/gnuk.h (ALGO_CURVE25519): New.
661 2015-07-06 Niibe Yutaka <gniibe@fsij.org>
663 Enhancement for FSM-55.
664 * tool/stlinkv2.py (stlinkv2.control_nrst): New.
665 (stlinkv2.get_rdp_key,has_spi_flash,has_protection): New.
666 (stlinkv2.get_core_id): Rename.
667 (stlinkv2.blank_check): Use self.flash_size.
668 (stlinkv2.start): Call control_nrst. Call get_core_id.
669 Distinguishing chip, and set rdp_key, flash_size and require_nrst.
670 (stlinkv2.flash_write): Use self.flash_block_size.
671 (main): Call control_nrst.
672 (prog_flash_write_body, prog_option_bytes_write_body)
673 (prog_blank_check_body): Support Cortex-M0.
674 (main): Call API V2 halt twice.
675 * tool/asm-thumb/*.S: Updated for Cortex-M0.
677 2015-06-30 Niibe Yutaka <gniibe@fsij.org>
679 * src/sys.c: Update from chopstx/example-cdc/sys.c.
681 * src/main.c (device_initialize_once): Apply change of NeuG.
683 2015-06-03 Niibe Yutaka <gniibe@fsij.org>
687 * test/ecc_nistp256_keys.py: New.
689 * tool/upgrade_by_passwd.py: Remove -p option and add -f option.
691 * tool/gnuk_token.py (gnuk_token.download): Add verbose flag.
692 (regnual.download): Ditto.
694 * tool/gnuk_upgrade.py: Use gnuk_token module.
696 2015-06-02 Niibe Yutaka <gniibe@fsij.org>
698 * src/openpgp.c (cmd_pso): Support OpenPGPcard spec v3.0.
700 2015-04-20 Niibe Yutaka <gniibe@fsij.org>
702 * chopstx: Upgrade to 0.05.
704 2015-04-19 Niibe Yutaka <gniibe@fsij.org>
706 * src/gnuk.h (CCID_CARD_INIT): New.
707 * src/usb_desc.c (gnukConfigDescriptor): Update dwDefaultClock,
708 dwMaximumClock, dwFeatures, and bClassEnvelope.
709 * src/usb_ctrl.c (freq_table): Change the value to 4000MHz.
710 (usb_cb_handle_event): Call ccid_card_change_signal after configure.
711 * src/usb-icc.c (ccid_thread): Change EV_CARD_CHANGE handling.
713 2015-04-18 Niibe Yutaka <gniibe@fsij.org>
715 * src/main.c (main): Call chopstx_main_init.
716 * src/Makefile.in (DEFS): Remove CHX_PRIO_MAIN.
718 2015-04-17 Niibe Yutaka <gniibe@fsij.org>
720 * src/configure: Fix shell syntax.
722 2015-03-31 Niibe Yutaka <gniibe@fsij.org>
724 * src/usb_conf.h (ICC_NUM_INTERFACES, HID_NUM_INTERFACES)
725 (HID_NUM_INTERFACES, VCOM_NUM_INTERFACES, MSC_NUM_INTERFACES)
726 (NUM_INTERFACES): Define here (moved from usb_desc.c).
727 (ICC_INTERFACE, HID_INTERFACE, VCOM_INTERFACE_0, VCOM_INTERFACE_1)
728 (MSC_INTERFACE): New.
729 * src/usb_ctrl.c (gnuk_setup_endpoints_for_interface)
730 (usb_cb_setup, usb_cb_ctrl_write_finish): Use *_INTERFACE.
731 * src/usb_desc.c (gnukConfigDescriptor): Likewise.
733 2015-03-06 Niibe Yutaka <gniibe@fsij.org>
735 * src/ecc-edwards.c (eddsa_sign_25519): Return 0.
737 2015-02-25 Niibe Yutaka <gniibe@fsij.org>
739 * src/openpgp.c (cmd_internal_authenticate): Fix storing to
742 2015-02-10 Niibe Yutaka <gniibe@fsij.org>
744 * src/openpgp.c (cmd_pso): Fix counter update for EdDSA. Thanks
745 to Jonathan Schleifer.
747 * src/call-rsa.c (rsa_sign): Don't set res_APDU_len.
748 (rsa_decrypt): Likewise, but get OUTPUT_LEN_P as an argument.
750 2015-02-09 Niibe Yutaka <gniibe@fsij.org>
752 * src/openpgp.c (cmd_pso): Fix EdDSA. Use GPG_KEY_FOR_SIGNING.
754 2014-12-15 Niibe Yutaka <gniibe@fsij.org>
758 2014-12-13 Niibe Yutaka <gniibe@fsij.org>
760 * src/flash.c (flash_key_getpage, flash_key_release_page): New.
762 * src/openpgp-do.c (gpg_do_delete_prvkey): New arg.
763 (rw_algorithm_attr): Call gpg_do_delete_prvkey with CLEAN_PAGE_FULL.
765 2014-12-12 Niibe Yutaka <gniibe@fsij.org>
767 * src/Makefile.in (build/bignum.o): Specific OPT for this target.
769 * src/configure (target): Default is FST-01.
770 (--with-dfu): FST-01 doesn't have DFU. If set, it must be
773 * boards/STBEE_MINI: Remove, since it is now supported by Chopstx.
775 * test/features/802_get_data_static.feature: Reflect the change
776 of extended capabilities.
777 * test/features/402_get_data_static.feature: Ditto.
778 * test/features/002_get_data_static.feature: Ditto.
780 * test/features/003_keyattr_change.feature: New test.
782 * src/usb_lld.h: Don't use 'extern' for function declarations.
783 * src/usb-icc.c (end_cmd_apdu_data): Fix Le handling.
785 2014-12-11 Niibe Yutaka <gniibe@fsij.org>
787 * chopstx: Upgrade to 0.04.
788 * src/syc.c: Update from 0.04.
790 2014-12-10 Niibe Yutaka <gniibe@fsij.org>
792 * src/ecc-cdh.c: Remove as smartcard only does
793 a part of ECDH computation as gpg-agent does.
795 * src/chconf.h, src/halconf.h: Remove files needed for ChibiOS/RT.
797 2014-12-09 Niibe Yutaka <gniibe@fsij.org>
799 * src/call-ec.c (ecc_compute_public): Rename, as we share
800 same routine among ECDSA and ECDH.
803 2014-12-09 Niibe Yutaka <gniibe@fsij.org>
805 * src/ecc.c (compute_kP): Bug fix. It's P, not G.
806 (point_is_on_the_curve): Bug fix.
808 2014-12-03 Niibe Yutaka <gniibe@fsij.org>
810 Changes for RSA-4096.
812 * src/gnuk.h (MAX_CMD_APDU_DATA_SIZE, MAX_RES_APDU_DATA_SIZE):
813 Send/Recv buffer should be bigger.
814 * polarssl/library/bignum.c (mpi_exp_mod): Don't consume much.
815 * polarssl/library/rsa.c (rsa_rsaes_pkcs1_v15_decrypt): buffer
816 allocation size should be variable.
818 2014-12-01 Niibe Yutaka <gniibe@fsij.org>
820 * src/Makefile.in (DEFS): Don't define compile time preference of
823 * src/openpgp-do.c (proc_key_import): Support modifiable key algo
826 2014-11-21 Niibe Yutaka <gniibe@fsij.org>
828 * src/gnuk.h (ALGO_RSA4K, ALGO_NISTP256R1, ALGO_SECP256K1)
829 (ALGO_ED25519, ALGO_RSA2K): New.
830 (struct key_data_internal): Move to ...
831 * src/openpgp-do.c (struct key_data_internal): ... here.
832 (CHECKSUM_ADDR, kdi_len): New.
833 (CKDC_CALC, CKDC_CHECK): New.
834 (compute_key_data_checksum): Add arg PRVKEY_LEN.
835 (gpg_do_load_prvkey, gpg_do_delete_prvkey): Support modifiable key
837 (gpg_do_write_prvkey, gpg_do_public_key, gpg_do_keygen): Likewise.
838 (gpg_do_clear_prvkey): Use MAX_PRVKEY_LEN.
840 * src/openpgp.c (gpg_init): Call flash_init_keys after
842 (cmd_pso): Support modifiable key algo attributes.
843 (cmd_internal_authenticate): Likewise.
845 2014-11-21 Niibe Yutaka <gniibe@fsij.org>
847 * src/openpgp-do.c (algorithm_attr_rsa2k): Rename from *_rsa.
848 (algorithm_attr_rsa4k): New.
849 (get_algo_attr_pointer, kk_to_nr, gpg_get_algo_attr)
850 (get_algo_attr_data_object, gpg_get_algo_attr_key_size): New.
851 (rw_algorithm_attr): New.
852 (gpg_do_table): Register rw_algorithm_attr for GPG_DO_ALG_*.
853 (gpg_data_scan, gpg_data_copy): Handle algo attributes.
855 (rw_pw_status): Fix checking against redundant write.
857 2014-11-20 Niibe Yutaka <gniibe@fsij.org>
859 * src/openpgp-do.c (extended_capabilities): Key attributes can be
862 2014-11-20 Niibe Yutaka <gniibe@fsij.org>
864 * src/gnuk.h (NR_NONE, NR_DO__FIRST__): Remove.
866 (NR_KEY_ALGO_ATTR_SIG, NR_KEY_ALGO_ATTR_DEC)
867 (NR_KEY_ALGO_ATTR_AUT): New.
869 * src/openpgp-do.c (gpg_do_load_prvkey, gpg_do_delete_prvkey)
870 (gpg_do_write_prvkey, gpg_do_chks_prvkey, gpg_data_scan)
871 (gpg_data_copy, gpg_do_read_simple)
872 (gpg_do_write_simple): Don't use NR_DO__FIRST__.
873 (gpg_do_put_data): Don't use NR_NONE any more.
874 (do_tag_to_nr): Use -1 to specify NONE.
876 * src/flash.c (flash_enum_clear, flash_enum_write_internal)
877 (flash_enum_write): New.
879 2014-11-19 Niibe Yutaka <gniibe@fsij.org>
881 * src/gnuk.h (FIRMWARE_UPDATE_KEY_CONTENT_LEN): New.
882 (size_of_key): New enum.
884 * src/openpgp.c (gpg_get_firmware_update_key)
885 (cmd_read_binary, cmd_external_authenticate): Use
886 FIRMWARE_UPDATE_KEY_CONTENT_LEN.
888 * src/flash.c (KEY_SIZE): Remove.
889 (key_available_at): Add new arg as KEY_SIZE.
890 (flash_check_all_other_keys_released): Likewise.
891 (flash_key_fill_zero_as_released, flash_key_release): Likewise.
893 (flash_init): Move initializing keys into another function.
894 (flash_init_keys): New function.
896 (flash_key_alloc): Use gpg_get_algo_attr_key_size.
897 (flash_key_write): Add new arg as KEY_DATA_LEN.
899 (flash_write_binary): Use FIRMWARE_UPDATE_KEY_CONTENT_LEN.
901 2014-09-16 Niibe Yutaka <gniibe@fsij.org>
903 * src/gnuk.h (MAX_PRVKEY_LEN): New.
904 (KEY_CONTENT_LEN): Remove.
906 * src/call-rsa.c (RSA_SIGNATURE_LENGTH): Remove.
907 (rsa_sign, rsa_verify, rsa_genkey): Add new arg: PUBKEY_LEN.
908 (rsa_decrypt): Don't use KEY_CONTENT_LEN.
910 2014-06-19 Niibe Yutaka <gniibe@fsij.org>
912 * src/ecc-mont.c (compute_nQ): Add comment.
914 * src/mod.c (mod_inv): Fix comment. X^-1 = 0 when X=0
915 is important for Montgomery curve computation.
917 2014-06-05 Niibe Yutaka <gniibe@fsij.org>
919 * tool/add_openpgp_authkey_from_gpgssh.py: New.
921 2014-04-17 Niibe Yutaka <gniibe@fsij.org>
923 * src/muladd_256.h (MULADD_256_ASM): New.
924 (MULADD_256): Use MULADD_256_ASM.
925 * src/ecc-mont.c (mod25638_mul_121665): Add asm implementation.
927 * src/bn.c (bn256_add_uint, bn256_sub_uint): Simplify.
928 * src/mod25638.c (mod25638_add, mod25638_sub): Simplify.
929 (n25638, add19): Remove.
930 (ADDWORD_256): Add s_ as source pointer.
931 (mod25519_reduce): Remove a call to memcpy. Use bn256_add_uint.
932 * src/ecc-edwards.c (point_double): Simplify.
934 2014-04-16 Niibe Yutaka <gniibe@fsij.org>
938 2014-04-15 Niibe Yutaka <gniibe@fsij.org>
940 * src/ecc-mont.c: New.
942 * src/mod25638.c (p25519): Move from ecc-edwards.c.
943 (mod25519_reduce, add19): Likewise.
944 (mod25638_reduce) [!ASM_IMPLEMENTATION]: Use bn256_add_uint.
946 2014-04-14 Niibe Yutaka <gniibe@fsij.org>
948 * src/jpc.c (jpc_to_ac): Error check before mod_inv.
950 * src/mod.c (mod_inv): No return value (if N==0 returns ZERO).
952 * src/bn.c [BN256_NO_RANDOM]: Only include "random.h" if needed.
954 2014-04-08 Niibe Yutaka <gniibe@fsij.org>
956 * src/mod.c (mod_inv): Use MAX_GCD_STEPS_BN256.
957 Return failure or success.
958 * src/jpc.c (jpc_to_ac): Use mod_inv.
959 * src/modp256k1.c (modp256k1_inv): Remove.
960 * src/modp256r1.c (modp256r1_inv): Remove.
962 2014-04-07 Niibe Yutaka <gniibe@fsij.org>
964 * src/openpgp-do.c (algorithm_attr_ed25519): It's OID only.
966 2014-04-03 Niibe Yutaka <gniibe@fsij.org>
968 * src/ecc-edwards.c (eddsa_sign_25519): Change type of OUT.
969 * src/openpgp.c (cmd_internal_authenticate): Have a buffer.
971 * src/flash.c (flash_init): Fix key address finder.
973 2014-04-02 Niibe Yutaka <gniibe@fsij.org>
975 * src/openpgp-do.c (proc_key_import): Handle EdDSA.
976 (algorithm_attr_ed25519): Fix OID and add ID for SHA512.
978 2014-04-01 Niibe Yutaka <gniibe@fsij.org>
980 * src/ecc-edwards.c (eddsa_compute_public_25519): New.
982 * src/openpgp-do.c (algorithm_attr_ed25519): New.
983 (gpg_do_write_prvkey, proc_key_import, gpg_do_public_key): Add
986 2014-03-31 Niibe Yutaka <gniibe@fsij.org>
988 * src/ecc-edwards.c (eddsa_sign_25519): Rename and API change.
990 * src/openpgp-do.c (gpg_do_load_prvkey, gpg_do_delete_prvkey)
991 (gpg_do_write_prvkey, gpg_do_public_key, gpg_do_keygen): Follow
992 the change of PRVKEY_DATA and KEY_DATA.
994 * src/flash.c (key_available_at): New.
995 (flash_init): Initilize KD.
997 * src/gnuk.h (struct prvkey_data): Remove member KEY_ADDR.
998 (struct key_data): Addd member KEY_ADDR.
1000 * src/openpgp-do.c (gpg_do_keygen): Bug fix. Reset the signature
1001 counter when new key is generated.
1003 * src/flash.c (flash_key_alloc): Change API, supply KK.
1005 2014-03-29 Niibe Yutaka <gniibe@fsij.org>
1007 * src/ecc-edwards.c (point_double, point_add): Rename.
1008 (mod25519_reduce): New.
1010 2014-03-28 Niibe Yutaka <gniibe@fsij.org>
1012 * misc/t-eddsa.c (main): Update for new API of eddsa_25519.
1014 * src/ecc-edwards.c (compute_kG_25519): Tune for 252-bit.
1015 (eddsa_25519): Public key should be provided by caller.
1016 (eddsa_public_key_25519): New.
1018 2014-03-27 Niibe Yutaka <gniibe@fsij.org>
1020 * src/ecc-edwards.c (ed_add_25638): Remove the third argument.
1021 (compute_kG_25519): The curve is complete, we don't need to avoid
1022 identity element as NIST curve or secp256k1 curve.
1023 (eddsa_25519): Change the API, with A and the seed.
1025 2014-03-26 Niibe Yutaka <gniibe@fsij.org>
1027 * src/mod25638.c (mod25638_reduce): New.
1028 (mod25638_mul, mod25638_sqr): Use mod25638_reduce.
1030 * src/ecc-edwards.c (ptc_to_ac_25519): No need to subtract p25519.
1032 2014-03-25 Niibe Yutaka <gniibe@fsij.org>
1034 * misc/t-eddsa.c: New.
1036 * src/ecc-edwards.c (bnX_mul_C, mod_reduce_M): New.
1039 2014-03-20 Niibe Yutaka <gniibe@fsij.org>
1041 * src/ecc-edwards.c (ed_add_25638): Fix for X == A.
1042 (main): Compute pre-computed tables.
1043 (precomputed_KG, precomputed_2E_KG): Add.
1044 (compute_kG_25519): New.
1046 2014-03-19 Niibe Yutaka <gniibe@fsij.org>
1048 * src/bn.c (bn256_add): Fix for X == B.
1049 (bn256_sub): Likewise.
1051 * src/ecc-edwards.c: New.
1053 2014-03-18 Niibe Yutaka <gniibe@fsij.org>
1055 * src/mod25638.c (mod25638_add, mod25638_sub, mod25638_sqr)
1056 (mod25638_shift): New.
1058 2014-03-13 Niibe Yutaka <gniibe@fsij.org>
1060 * src/mod25638.c: Rename from fe25519.c.
1061 * src/mod25638.h: Likewise.
1063 2014-03-07 Niibe Yutaka <gniibe@fsij.org>
1067 2014-02-25 Niibe Yutaka <gniibe@fsij.org>
1069 * src/openpgp-do.c (gpg_do_public_key): Don't put OID.
1071 * src/configure [certdo] (gnuk.ld): Add TIM_SIZE and EXT_SIZE.
1072 Thanks to Vasily Evseenko for the bug report.
1074 2014-02-21 Niibe Yutaka <gniibe@fsij.org>
1076 * src/ecc.c (compute_kG): Compute higer index at first.
1077 (point_is_on_the_curve): Don't use coefficient_a if it's zero.
1079 * src/jpc.c (jpc_double): Care coefficient A.
1081 * src/ec_p256r1.c (COEFFICIENT_A_IS_MINUS_3): New.
1082 * src/ec_p256k1.c (COEFFICIENT_A_IS_ZERO): New.
1083 * src/jpc_p256r1.c (COEFFICIENT_A_IS_MINUS_3): Likewise.
1084 * src/jpc_p256k1.c (COEFFICIENT_A_IS_MINUS_3): Likewise.
1086 * src/modp256k1.c (modp256k1_shift): Bug fix.
1088 2014-02-20 Niibe Yutaka <gniibe@fsij.org>
1090 * src/Makefile.in (CSRC): Add files of p256k1.
1092 * src/openpgp.c (cmd_pso): Support p256k1 for signature.
1094 * src/openpgp-do.c (algorithm_attr_p256k1): New.
1095 (gpg_do_write_prvkey): Support p256k1 for signature.
1096 (proc_key_import, gpg_do_table, gpg_do_public_key): Likewise.
1098 * src/Makefile.in (DEFS): Add -DRSA_SIG.
1100 * src/openpgp-do.c (gpg_do_write_prvkey): Use _p256r1.
1101 * src/openpgp.c (cmd_internal_authenticate): Likewise.
1103 * src/call-ec_p256k1.c: New. Use call-ec.c.
1104 * src/call-ec_p256r1.c: Use call-ec.c.
1105 * src/call-ec.c: New.
1106 (ecdsa_sign): Change the signature.
1108 2014-02-19 Niibe Yutaka <gniibe@fsij.org>
1110 * tool/calc_precompute_table_ecc.py: New.
1112 * src/ec_p256k1.c: New. Use ecc.c.
1113 * src/ec_p256k1.h: New.
1114 * src/ec_p256r1.c: Use ecc.c.
1117 2014-02-18 Niibe Yutaka <gniibe@fsij.org>
1119 * src/jpc_p256k1.c: New. Use jpc.c.
1120 * src/jpc_p256r1.c: Use jpc.c.
1123 * src/sha256.c (memcpy_output_bswap32): Bug fix.
1125 * src/modp256k1.h, src/modp256k1.c: New.
1127 2014-02-17 Niibe Yutaka <gniibe@fsij.org>
1129 * src/Makefile.in (CSRC): Follow the changes of filenames.
1131 * src/modp256r1.c (modp256r1_add, modp256r1_sub, S3)
1132 (modp256r1_mul, modp256r1_sqr, modp256r1_inv, modp256r1_shift):
1133 Use new function names.
1134 * src/jpc_p256r1.c (jpc_double_p256r1, jpc_add_ac_signed_p256r1)
1135 (jpc_to_ac_p256r1): Likewise.
1136 * src/ec_p256r1.c (point_is_on_the_curve)
1137 (compute_kG_p256r1, compute_kP_p256r1): Likewise.
1138 * src/call-ec_p256r1.c (ecdsa_sign): Likewise.
1140 * src/modp256r1.h: Rename from modp256.h.
1141 * src/jpc-ac_p256r1.h: Rename from jpc-ac.h.
1142 * src/ec_p256r1.h: Rename from ec_p256.h.
1144 * src/modp256r1.c: Rename from modp256.c.
1145 * src/jpc_p256r1.c: Rename from jpc.c.
1146 * src/ec_p256r1.c: Rename from ec_p256.c.
1147 * src/call-ec_p256r1.c: Rename from call-ec_p256.c.
1149 2014-02-05 NIIBE Yutaka <gniibe@fsij.org>
1151 * src/sha512.h, src/sha512.c: New.
1153 * src/sha256.c (initial_state): Don't export, it's internal.
1154 (memcpy_output_bswap32): Rename and remove last argument.
1156 2014-01-28 Niibe Yutaka <gniibe@fsij.org>
1158 * src/muladd_256.h: New.
1159 * src/bn.c (bn256_mul, bn256_sqr): Assembler implementation.
1161 * src/ec_p256.c (get_vk_kP): Bug fix.
1162 (compute_kP): Bug fix for index table.
1164 2014-01-27 Niibe Yutaka <gniibe@fsij.org>
1166 * src/ec_p256.c (get_vk_kP): New.
1167 (naf4_257_set, naf4_257_get, compute_naf4_257): Remove.
1168 (compute_kP): Change the argument, fixing for constant time.
1170 2014-01-24 Niibe Yutaka <gniibe@fsij.org>
1172 * src/ec_p256.c (get_vk): New.
1173 (compute_kG): Fix for constant time.
1174 (compute_kP): Simplify.
1176 2014-01-23 Niibe Yutaka <gniibe@fsij.org>
1178 * src/jpc.c (jpc_add_ac_signed): Fix for constant time.
1180 * src/ec_p256.c (ecdsa): Bug fix for k selection.
1182 2014-01-22 Niibe Yutaka <gniibe@fsij.org>
1184 * src/modp256.c (modp256_inv): Fix for constant time.
1186 * src/bn.c (bn256_sqr): Fix for constant time.
1188 * src/mod.c (mod_inv): Fix for constant time.
1190 * src/ec_p256.c (compute_kG): Simplify.
1192 * src/jpc.c (jpc_double): Support calling with A = infinity.
1194 2014-01-21 Niibe Yutaka <gniibe@fsij.org>
1196 * src/jpc.c (jpc_add_ac_signed): Bug fix for A check.
1198 * src/ec_p256.c (ecdsa): Fix for constant time.
1200 * src/modp256.c (modp256_add, modp256_sub, modp256_reduce)
1201 (modp256_shift): Fix for constant time.
1202 (modp256_inv): Likewise (not fully constant time, yet).
1204 * src/mod.c (mod_reduce): Fix for constant time.
1205 (mod_inv): Likewise (not fully constant time, yet).
1207 * src/bn.h (bn256, bn512): words -> word.
1208 * src/ec_p256.h (naf4_257): Likewise.
1210 2014-01-20 Niibe Yutaka <gniibe@fsij.org>
1212 * src/fe25519.h, src/fe25519.c: New.
1214 2014-01-15 Niibe Yutaka <gniibe@fsij.org>
1216 * src/bn.c (bn256_is_zero, bn256_is_ge, bn256_cmp): Computation
1217 should be constant time.
1219 2013-12-25 Niibe Yutaka <gniibe@fsij.org>
1223 * tool/gnuk_token.py (gnuk_token.__init__, regnual.__init__): Fix
1224 the argument of setAltInterface.
1225 * tool/gnuk_upgrade.py: Likewise.
1226 * tool/dfuse.py (DFU_STM32.__init__): Likewise.
1227 * tool/stlinkv2.py (stlinkv2.__init__): Likewise.
1229 2013-12-24 Niibe Yutaka <gniibe@fsij.org>
1231 * polarssl/include/polarssl/bn_mul.h (MULADDC_1024_CORE)
1232 (MULADDC_1024_LOOP): Use younger number registers more for shorter
1233 instructions and better performance.
1234 * polarssl/library/bignum.c (mpi_montsqr): Likewise. Change loop
1235 structure and conditional branch for better performance.
1237 2013-12-23 Niibe Yutaka <gniibe@fsij.org>
1239 * polarssl/library/bignum.c (mpi_montmul): Computation
1240 time should not depends on input.
1241 (mpi_montmul, mpi_montred, mpi_montsqr): Change the API.
1242 (mpi_exp_mod): Follow the change of the API. Allocate memory on
1243 stack instead of malloc.
1245 * src/gnuk.ld.in (__process3_stack_size__): Increase stack size.
1247 2013-12-20 Niibe Yutaka <gniibe@fsij.org>
1251 * src/usb_ctrl.c (USB_FSIJ_GNUK_CARD_CHANGE): New.
1252 (usb_cb_setup): Support USB_FSIJ_GNUK_CARD_CHANGE.
1253 * src/usb-icc.c (ccid_card_change_signal): New argument HOW.
1255 2013-12-20 Niibe Yutaka <gniibe@fsij.org>
1257 * polarssl/include/polarssl/bn_mul.h (MULADDC_1024_CORE)
1258 (MULADDC_CORE): Reorder instructions for more speed up.
1259 * polarssl/library/bignum.c (mpi_montsqr): Likewise.
1261 2013-12-19 Niibe Yutaka <gniibe@fsij.org>
1263 * src/configure (--enable-hid-card-change): New (experimental).
1264 * src/config.h.in (HID_CARD_CHANGE_DEFINE): New.
1265 * src/usb_ctrl.c (gnuk_setup_endpoints_for_interface)
1266 (usb_cb_setup, usb_cb_ctrl_write_finish): Conditionalize
1267 HID_CARD_CHANGE_SUPPORT.
1268 * src/usb_desc.c (gnukDeviceDescriptor, usb_cb_get_descriptor):
1271 2013-12-19 Niibe Yutaka <gniibe@fsij.org>
1273 * src/openpgp.c (S2KCOUNT): It's now 192, as the threat model
1274 of Gnuk Token is different.
1276 2013-12-19 Niibe Yutaka <gniibe@fsij.org>
1278 * polarssl/library/bignum.c (mpi_montsqr): New.
1279 (mpi_exp_mod): Use mpi_montsqr.
1281 Note that this change introduces a vulnerability by the
1282 Yarom/Falkner flush+reload cache side-channel attack. When this
1283 code is used on general purpose computer where we can observe
1284 which code is executed (sqr or mul), it's not safe.
1286 2013-12-16 Niibe Yutaka <gniibe@fsij.org>
1288 * polarssl/include/polarssl/bn_mul.h (MULADDC_1024_CORE)
1289 (MULADDC_1024_LOOP, MULADDC_HUIT, MULADDC_INIT, MULADDC_CORE)
1290 (MULADDC_STOP) [__arm__]: The value of input B won't change.
1291 More acculate specification for asm statement.
1293 * polarssl/library/bignum.c (mpi_cmp_abs_limbs): New.
1294 (mpi_montmul): Change the signature and use the upper half of T.
1295 (mpi_montred): Likewise.
1296 (mpi_exp_mod): Use improved mpi_montmul and mpi_montred.
1297 (mpi_sub_hlp, mpi_mul_hlp): Add const qualifier for S.
1299 2013-12-13 Niibe Yutaka <gniibe@fsij.org>
1301 * polarssl/library/bignum.c (mpi_exp_mod): Initialize lower
1302 half of T with zero.
1303 (mpi_montmul): Don't need to clear lower half of
1304 T, as we keep zero. Call mpi_sub_hlp with upper half of T.
1305 (mpi_montred): Ditto.
1307 * polarssl/library/bignum.c (mpi_montmul, mpi_montred): Minimize
1308 number of limbs for T.
1309 (mpi_exp_mod): Only allocate N-n * 2 for T.
1310 Only allocate N->n for X, W[i], and RR.
1312 2013-12-13 Niibe Yutaka <gniibe@fsij.org>
1314 * tool/upgrade_by_passwd.py (main): Support -k to specify KEYNO.
1316 2013-12-13 Niibe Yutaka <gniibe@fsij.org>
1318 * src/usb_ctrl.c (HID_LED_STATUS_CARDCHANGE): Rename from
1319 HID_LED_STATUS_NUMLOCK.
1321 * tool/gnuk_token.py (gnuk_token.stop_gnuk): Detach kernel
1324 2013-12-12 Niibe Yutaka <gniibe@fsij.org>
1326 * src/openpgp-do.c (do_openpgpcard_aid): Coerce to volatile to
1327 force memory access at run time.
1329 2013-12-11 Niibe Yutaka <gniibe@fsij.org>
1331 * regnual/sys.c (entry): Fix relocation calculation.
1333 2013-11-27 Niibe Yutaka <gniibe@fsij.org>
1335 * src/stm32f103.h (AFIO_MAPR_SWJ_CFG_DISABLE): New.
1336 * src/sys.c: Likewise.
1338 2013-11-26 Niibe Yutaka <gniibe@fsij.org>
1340 * src/usb_desc.c (hid_report_desc): New.
1341 (ICC_TOTAL_LENGTH): Update.
1342 (HID_TOTAL_LENGTH, HID_NUM_INTERFACES): New.
1343 (W_TOTAL_LENGTH, NUM_INTERFACES): Update.
1344 (gnukConfigDescriptor): Add IN2 interrupt endpoint descriptor.
1345 Add HID interface descriptor.
1346 (usb_cb_get_descriptor): Handle HID.
1348 * src/usb_ctrl.c (NUM_INTERFACES, MSC_INTERFACE_NO): Add 1.
1349 (USB_HID_REQ_*, HID_LED_STATUS_NUMLOCK): New.
1350 (gnuk_setup_endpoints_for_interface): Add ENDP2 interrupt
1352 (usb_cb_setup): Handle HID requests.
1353 (usb_cb_ctrl_write_finish): Likewise.
1355 * src/usb-icc.c (ccid_card_change_signal): New.
1356 (ccid_thread): Handle card change.
1357 (icc_error, icc_send_status): Handle ICC_STATE_NOCARD state.
1358 (icc_handle_data): Add the case of ICC_STATE_NOCARD.
1359 (EP2_IN_Callback): New.
1361 2013-11-26 Niibe Yutaka <gniibe@fsij.org>
1363 * src/pin-dial.c: Remove.
1364 * src/configure: Remove pin-dial support.
1366 2013-11-25 Niibe Yutaka <gniibe@fsij.org>
1368 * src/Makefile.in (HEXOUTPUT_MAKE_OPTION): New.
1369 * src/configure (HEXOUTPUT_MAKE_OPTION): New.
1370 * src/main.c: Include board.h.
1371 * src/stm32f103.h (EXTI0_IRQ, EXTI1_IRQ): New.
1373 2013-11-18 Niibe Yutaka <gniibe@fsij.org>
1375 * regnual/sys.c (entry): Bug fix of clearing BSS.
1377 * src/usb_stm32f103.c: Update from NeuG.
1378 (usb_handle_transfer): Add argument ISTR_VALUE.
1380 * src/openpgp.c (card_thread): Add noinline attribute.
1382 * src/usb-icc.c (ccid_thread): Join the OpenPGP thread.
1383 Add noinline attribute.
1385 2013-11-15 Niibe Yutaka <gniibe@fsij.org>
1387 * src/configure (options): Add --enable-sys1-compat.
1389 2013-11-12 Niibe Yutaka <gniibe@fsij.org>
1391 * chopstx: Upgrade to 0.03.
1393 * src/usb_desc.c (usb_initial_feature): Remove.
1394 (USB_SELF_POWERED): Move to ...
1395 * src/usb_conf.h (USB_SELF_POWERED): ... here.
1396 * src/usb_ctrl.c (usb_cb_device_reset, usb_intr): Follow the
1399 2013-11-11 Niibe Yutaka <gniibe@fsij.org>
1401 * src/adc_stm32f103.c (adc_wait_completion): Update from NeuG 1.0.
1403 2013-11-03 Niibe Yutaka <gniibe@fsij.org>
1405 * regnual/regnual.c (usb_cb_get_descriptor): Update to new API.
1407 * src/usb_lld.h (usb_initial_feature): Remove.
1409 * chopstx: Update to 0.01.
1410 * src/pin-cir.c: Chatter fix to 200ms.
1411 * src/main.c: Fix bDeviceState.
1413 2013-11-02 Niibe Yutaka <gniibe@fsij.org>
1415 * src/usb_lld.h, src/usb_stm32f103.c (std_get_descriptor): Change
1416 the API of usb_cb_get_descriptor.
1417 * src/usb_desc.c: Follow the change.
1418 * src/usb_conf.h: Modify for CCID INT and HID usage.
1420 2013-11-02 Niibe Yutaka <gniibe@fsij.org>
1422 * src/pin-cir.c: Port to Chopstx.
1425 * src/configure (TIM_SIZE, EXT_SIZE): New.
1426 * src/gnuk.ld.in (__process6_stack_size__)
1427 (__process7_stack_size__): New.
1428 * src/main.c (main): Call cir_init.
1429 * src/openpgp.c (openpgp_card_thread): Rename from GPGthread.
1430 * src/usb-icc.c (icc_power_on): Follow the change.
1432 2013-11-01 Niibe Yutaka <gniibe@fsij.org>
1434 * src/sys.c: Update from Chopstx.
1435 * src/usb_lld.h: Remove interrupt definition.
1436 * src/stm32f103.h: Add AFIO, EXTI, and TIMER constants.
1438 2013-10-31 Niibe Yutaka <gniibe@fsij.org>
1440 * src/main.c (main): Call msc_init before USB interrupt thread.
1441 * src/gnuk.h, src/usb-msc.h, src/usb-msc.c, src/pin-dnd.c: Port to
1443 * src/openpgp.c (get_pinpad_input): Follow the change.
1444 * src/usb_ctrl.c (gnuk_setup_endpoints_for_interface): Don't stall
1447 2013-10-24 Niibe Yutaka <gniibe@fsij.org>
1449 * src/Makefile.in (DEFS): Add -DCHX_PRIO_MAIN=5 for LED blink.
1450 * src/main.c (PRIO_CCID): It's now 3 (was: 2).
1452 2013-10-24 Niibe Yutaka <gniibe@fsij.org>
1454 * src/gnuk.ld.in (.gnuk_flash): Three pages for three keys.
1455 * src/flash.c (FLASH_KEYSTORE_SIZE): Likewise.
1456 (flash_keystore_release): Remove.
1457 (flash_key_fill_zero_as_released)
1458 (flash_check_all_other_keys_released, flash_key_release): New.
1459 (flash_init, flash_key_alloc): New method to handle free space.
1460 * src/openpgp-do.c (fetch_four_bytes): New.
1461 (gpg_do_load_prvkey, gpg_do_delete_prvkey, gpg_do_public_key): Use
1463 (gpg_do_delete_prvkey): Call flash_key_release.
1465 2013-10-23 Niibe Yutaka <gniibe@fsij.org>
1467 * test/features/010_setup_passphrase.feature
1468 * test/features/030_key_registration.feature
1469 * test/features/040_passphrase_change.feature
1470 * test/features/410_setup_passphrase.feature
1471 * test/features/430_key_registration.feature
1472 * test/features/201_keygen.feature
1473 * test/features/601_keygen.feature: Modified to support new way of
1474 pass phrase reset by key import / key generation.
1476 * test/features/201_keygen.feature
1477 * test/features/601_keygen.feature
1478 * test/features/202_setup_passphrase.feature
1479 * test/features/602_setup_passphrase.feature: Rename to change
1482 2013-10-23 Niibe Yutaka <gniibe@fsij.org>
1484 * src/openpgp-do.c (gpg_do_write_prvkey): Bug fix of adding
1487 2013-10-22 Niibe Yutaka <gniibe@fsij.org>
1489 * src/openpgp-do.c (gpg_do_write_prvkey): Bug fix.
1491 2013-10-15 Niibe Yutaka <gniibe@fsij.org>
1493 * src/openpgp.c (cmd_change_password, cmd_reset_user_password): It
1494 is now error to change User's pass phrase with no keys.
1496 * src/openpgp-do.c (proc_resetting_code): Likewise for resetting
1498 (gpg_do_delete_prvkey): New.
1499 (gpg_do_write_prvkey): Make sure to delete the key before writing.
1500 User's pass phrase is always the one of factory setting.
1501 (gpg_do_chks_prvkey): Support removing the key.
1502 (proc_key_import): Use gpg_do_delete_prvkey.
1503 (gpg_do_keygen): Use factory setting pass phrase.
1505 2013-10-11 Niibe Yutaka <gniibe@fsij.org>
1507 * src/ac.c (verify_user_0, verify_admin_00): Fix conditions.
1509 * src/openpgp-do.c (gpg_do_write_prvkey): Delete keystring
1510 information from data object of NR_DO_KEYSTRING_PW3.
1512 (gpg_do_keygen): Likewise.
1514 * src/openpgp.c (cmd_reset_user_password): Likewise.
1516 2013-10-10 Niibe Yutaka <gniibe@fsij.org>
1518 * src/gnuk.h (S2K_ITER): Remove. It's determined at compile time.
1520 * src/openpgp-do.c (proc_resetting_code, gpg_do_write_prvkey)
1521 (proc_key_import): Remove "iteration" field.
1523 * src/openpgp.c (cmd_change_password): Likewise.
1525 2013-10-10 Niibe Yutaka <gniibe@fsij.org>
1527 * src/openpgp-do.c (gpg_do_write_prvkey): Access of data object
1528 considering garbage collection.
1530 * src/openpgp.c (cmd_change_password): Call gpg_do_write_simple
1531 after accessing the data object (it may cause garbage collection).
1533 2013-10-10 Niibe Yutaka <gniibe@fsij.org>
1535 * polarssl/library/bignum.c (mpi_montred): Constant time for
1536 carry propagation. Bug fix for carry propagation.
1537 (mpi_exp_mod): Bug fix. Shrink the size of RR as same as X.
1539 2013-10-09 Niibe Yutaka <gniibe@fsij.org>
1541 * src/ac.c (verify_user_0, verify_admin_00, verify_admin_0): Add a
1542 flag to save into keystring_md_pw3. Add SALT handling.
1543 (decode_iterate_count, calc_md, gpg_set_pw3): Remove.
1545 * src/openpgp-do.c (proc_resetting_code, gpg_do_write_prvkey)
1546 (gpg_do_keygen): Add SALT handling.
1547 * src/openpgp.c (cmd_change_password, cmd_reset_user_password)
1549 * src/random.c (random_get_salt): Rename from get_salt.
1551 2013-10-09 Niibe Yutaka <gniibe@fsij.org>
1553 * src/openpgp-do.c (gpg_do_write_prvkey): Remove information (but
1554 pass phrase length) for admin from keystring data object.
1555 (proc_key_import): Recover admin keystring to DO when key deletion.
1557 2013-10-09 Niibe Yutaka <gniibe@fsij.org>
1559 * src/ac.c (verify_user_0, verify_admin_00): Handle PW_LEN_MASK.
1560 * src/openpgp-do.c (proc_resetting_code, gpg_do_write_prvkey):
1563 * src/openpgp.c (cmd_change_password, cmd_reset_user_password):
1564 Handle PW_LEN_KEYSTRING_BIT.
1566 2013-10-09 Niibe Yutaka <gniibe@fsij.org>
1568 * src/ac.c (verify_admin_00): New. Add authentication by loading
1570 (verify_admin_0): Use verify_admin_00.
1572 * src/openpgp.c (cmd_change_password): Admin keystring handling as
1575 2013-10-08 Niibe Yutaka <gniibe@fsij.org>
1577 * src/openpgp.c (modify_binary): Allow odd size of certificate.
1579 * polarssl/library/rsa.c: Update from PolarSSL 1.2.10.
1580 * polarssl/include/polarssl/rsa.h: Ditto.
1582 2013-10-07 Niibe Yutaka <gniibe@fsij.org>
1584 * polarssl/library/bignum.c (mpi_sub_hlp): Return CARRY.
1585 (mpi_sub_abs): Carry propagatoin is done here.
1586 (mpi_mul_hlp_mm): Remove.
1587 (mpi_mul_hlp): Return CARRY, computation in constant time.
1588 (mpi_mul_mpi): Change the order of computation not to propagate
1590 (mpi_montmul): Minimum zero-ing of D and reduce usage of temporary
1591 memory, by one word. Use carry of mpi_mul_hlp. Use
1592 NEED_SUBTRACTION against timing attack.
1593 (mpi_exp_mod): Minimum usage of temporary memory.
1595 2013-10-06 Niibe Yutaka <gniibe@fsij.org>
1597 * polarssl/library/bignum.c (mpi_mul_hlp_mm): New. Handle
1598 extra-carry in constant time to mitigate timing attack.
1599 (mpi_montmul): Use mpi_mul_hlp_mm.
1600 * src/call-rsa.c (rsa_sign, rsa_decrypt, rsa_verify): Don't
1603 2013-10-05 Niibe Yutaka <gniibe@fsij.org>
1605 * polarssl/include/polarssl/aes.h: Update from PolarSSL 1.2.9.
1606 * polarssl/include/polarssl/bignum.h: Ditto.
1607 * polarssl/include/polarssl/config.h: Ditto.
1608 * polarssl/include/polarssl/rsa.h: Ditto.
1609 * polarssl/library/aes.c, polarssl/library/bignum.c: Ditto.
1610 * polarssl/library/rsa.c: Ditto. Fix rsa_free.
1611 * src/call-rsa.c (rsa_sign, modulus_calc, rsa_decrypt)
1612 (rsa_verify): Follow changes of PolarSSL 1.2.9 with RSA blinding.
1613 Better error checking.
1615 2013-10-04 Niibe Yutaka <gniibe@fsij.org>
1617 * src/main.c (gnuk_malloc): Update ->neighbor field of a chunk on
1619 (gnuk_free): Access free list after getting the lock.
1621 2013-10-01 Niibe Yutaka <gniibe@fsij.org>
1623 * src/random.c (random_gen): Bug fix for INDEXed copy.
1625 * src/call-rsa.c (rsa_genkey): Call neug_flush and prng_seed.
1626 * polarssl/library/bignum.c (small_prime): More constants.
1627 (prng_seed, jkiss, mpi_fill_pseudo_random): New.
1628 (mpi_is_prime): Use mpi_fill_pseudo_random.
1630 2013-09-30 Niibe Yutaka <gniibe@fsij.org>
1632 * polarssl/library/bignum.c (mpi_is_prime): Enable trial divisions
1634 Add Fermat primality test.
1635 (mpi_gen_prime): Limit random value so that two MSBs of result will
1638 2013-09-27 Niibe Yutaka <gniibe@fsij.org>
1640 * polarssl/include/polarssl/bignum.h (mpi_is_prime): ifdef-out.
1641 * polarssl/library/bignum.c (mpi_is_prime): It's now internal
1642 function, assuming we already know its coprime to small primes.
1643 (M): New constant MPI. Multiply primes 2*...*691.
1644 (MAX_A): New constant MPI. 2^1024 / M - 1.
1645 (mpi_gen_prime): Specialize for 1024-bit, using Fouque-Tibouchi
1648 2013-09-25 Niibe Yutaka <gniibe@fsij.org>
1650 * src/sha256.h, src/adc.h
1651 * src/neug.c, src/adc_stm32f103.c: Update from NeuG 0.11.
1653 * chopstx: Upgrade to new Chopstx 0.00.
1655 * VERSION: New file.
1657 * src/configure (SERIALNO, SERIALNO_STR_LEN_DEFINE): New.
1658 (REVISION): Use the file VERSION if it doesn't have .git.
1659 Thanks to Sumedha Widyadharma for the bug report.
1661 * src/config.h.in (SERIALNO_STR_LEN_DEFINE): New.
1662 * src/main.c (ID_OFFSET): Use SERIALNO_STR_LEN.
1663 * src/usb_desc.c (gnukStringSerial): Remove. It's now
1664 generated in usb-strings.c.inc.
1666 * src/ec_p256.c (compute_kP): Fix for impossible cases.
1667 (point_is_on_the_curve): New.
1668 (coefficient_a, coefficient_b): New.
1670 2013-09-20 Niibe Yutaka <gniibe@fsij.org>
1672 * src/call-ec_p256.c (ecdsa_compute_public): Handle possible
1673 error (where key_data is the order).
1675 * src/ec_p256.c (compute_kG, compute_kP): Handle errors.
1677 * src/jpc.c (jpc_to_ac): Return -1 on error.
1678 (jpc_add_ac_signed): Handle the case where A=inf.
1680 * src/modp256.c (modp256_inv): Handle error case.
1682 * src/bn.c (bn256_cmp): New.
1684 2013-07-19 Niibe Yutaka <gniibe@fsij.org>
1686 * src/gnuk.ld.in: Layout change following NeuG.
1687 (_end): Add alignment of 16.
1689 * src/neug.c, src/adc.h, src/adc_stm32f103.c: Update from NeuG.
1691 * src/main.c [DFU_SUPPORT] (main): Fix calling
1692 flash_erase_all_and_exec.
1694 * src/openpgp-do.c (gpg_do_write_prvkey, gpg_do_keygen): Fix
1695 allocated memory handling. Clean up before free.
1696 * src/call-rsa.c (modulus_calc, rsa_genkey): Fix removing const.
1697 * src/call-ec_p256.c (ecdsa_compute_public): Likewise.
1699 2013-07-18 Niibe Yutaka <gniibe@fsij.org>
1702 * src/Makefile.in: Change for Chopstx.
1703 * src/configure: Likewise.
1704 * src/gnuk.h, src/gnuk.ld.in: Likewise.
1705 * src/ac.c: Include stdint.h and string.h, not ch.h.
1706 * src/call-rsa.c, src/debug.c, src/flash.c: Likewise.
1707 * src/call-ec_p256.c, src/usb_desc.c
1708 * src/openpgp-do.c, src/random.c: Likewise.
1709 * src/openpgp.c: Likewise. Use eventflag of Chopstx.
1710 * src/usb-icc.c: Likewise.
1711 * src/usb_ctrl.c: Update for Chopstx.
1713 * src/stdlib.h: Use gnuk_malloc and gnuk_free for malloc/free.
1714 * src/config.h.in: Move FLASH_PAGE_SIZE in board.h.
1715 * polarssl/library/aes.c (FT0, FT1, FT2): Export (for sys 2.0).
1716 * src/main.c (struct stdout, _write, EP3_IN_Callback)
1717 (EP5_OUT_Callback): Rewrite for Chopstx. No independent thread
1719 (display_fatal_code, emit_led, display_status_code, led_blink):
1720 Use primitives of Chopstx.
1721 (main): Changes for Chopstx.
1722 (gnuk_malloc_init, sbrk, gnuk_malloc, gnuk_free): New.
1724 2013-06-20 Niibe Yutaka <gniibe@fsij.org>
1726 * src/sys.c, src/sys.h, src/neug.c, src/adc.h
1727 * src/adc_stm32f103.c, src/usb_stm32f103.c: Update from NeuG 0.10.
1728 * src/stm32f103.h: New. From NeuG 0.10.
1730 2013-06-18 Niibe Yutaka <gniibe@fsij.org>
1732 * src/openpgp-do.c (gpg_do_write_prvkey, proc_key_import, gpg_do_table)
1733 (gpg_do_public_key) [RSA_AUTH]: Conditional compilation for RSA/ECDSA.
1734 * src/openpgp.c (cmd_internal_authenticate) [RSA_AUTH]: Likewise.
1736 * src/modp256.c (p256): Add const qualifier.
1738 2013-03-19 Niibe Yutaka <gniibe@fsij.org>
1740 * src/random.c (random_gen): New (was: random_byte).
1742 * src/call-rsa.c (rsa_sign): Follow change of API.
1743 (rsa_genkey): Use random_gen.
1744 (modulus_calc, rsa_decrypt, rsa_verify): Follow change of API.
1745 * src/openpgp-do.c (encrypt, decrypt): Likewise.
1747 * polarssl/include/polarssl/aes.h: Updated from PolarSSL 1.2.6.
1748 * polarssl/library/aes.c: Ditto.
1749 * polarssl/include/polarssl/rsa.h: Ditto.
1750 * polarssl/library/rsa.c: Ditto.
1751 * polarssl/include/polarssl/bignum.h: Ditto.
1752 * polarssl/library/bignum.c: Ditto.
1753 * polarssl: Move from polarssl-0.14.0, and needed files only.
1755 2013-03-15 Niibe Yutaka <gniibe@fsij.org>
1757 * regnual/regnual.ld (.bss): Put at RAM1. This makes reGNUal can
1758 be loaded on the lower address.
1760 * regnual/sys.c (entry): Don't change SP. Put alignment.
1762 * regnual/regnual.c (usb_cb_get_descriptor): Fix adding break.
1764 2013-03-14 Niibe Yutaka <gniibe@fsij.org>
1766 * tool/stlinkv2.py (stlinkv2.start): Call write_debug_reg to run
1769 2013-03-12 Niibe Yutaka <gniibe@fsij.org>
1771 * src/gnuk.ld.in (__process_stack_size__): Increase (was: 0x200).
1773 * tool/stlinkv2.py (stlinkv2.exit_from_debug_swd)
1774 (stlinkv2.exit_from_debug_swim): New.
1775 (stlinkv2.start): Call exit_from_debug_swd or
1776 exit_from_debug_swim.
1778 2013-03-09 Niibe Yutaka <gniibe@fsij.org>
1780 * src/openpgp-do.c (gpg_do_public_key): Add OID for ECDSA.
1781 (gpg_do_write_prvkey): Add PUBKEY_LEN for ECDSA.
1783 * src/flash.c (flash_key_write): Argument change for ECDSA key.
1785 * src/main.c (calculate_regnual_entry_address): New.
1786 (main): Use calculate_regnual_entry_address for entry point.
1788 * src/openpgp-do.c (gpg_do_write_prvkey): Coerce KDI.DATA to
1791 * src/usb_stm32f103.c (handle_setup0): Fix selecting handler.
1793 2013-03-08 Niibe Yutaka <gniibe@fsij.org>
1795 Relocatable reGNUal.
1797 * regnual/regnual.ld (MEMORY): 0x1400 was the value of Gnuk 1.0.1.
1799 (.text): Include .text.entry next to the .vectors.
1802 * regnual/sys.c (entry): Now, it's at .text.entry section.
1804 Don't use absolute values which causes relocations, but
1807 * regnual/Makefile (CFLAGS): Add -fpie.
1809 2013-03-07 Niibe Yutaka <gniibe@fsij.org>
1811 Follow the USB stack change.
1813 * regnual/regnual.c (usb_cb_device_reset): Rename from
1814 regnual_device_reset.
1815 (mem): Change type to uint32_t.
1816 (mem_info): Removed.
1817 (fetch): Avoid pointer punning.
1818 (usb_cb_ctrl_write_finish): Rename from regnual_ctrl_write_finish.
1819 (usb_cb_setup): Rename from regnual_setup.
1820 (usb_cb_get_descriptor): Rename from regnual_get_descriptor.
1821 (usb_cb_handle_event): Rename regnual_usb_event.
1822 (usb_cb_interface): Rename regnual_interface.
1823 (Device_Method): Remove.
1824 (usb_cb_get_descriptor): Not use struct Descriptor.
1826 2013-03-06 Niibe Yutaka <gniibe@fsij.org>
1828 USB stack implementation improvement.
1830 * src/usb_stm32f103.c (Device_Method, method_p): Remove.
1831 (usb_interrupt_handler): Call usb_cb_device_reset.
1832 (std_get_descriptor): Call usb_cb_get_descriptor.
1833 (std_set_configuration): Call usb_cb_handle_event.
1834 (std_get_status, std_get_interface, std_set_interface): Call
1836 (handle_setup0): Call usb_cb_setup.
1837 (handle_in0): Call usb_cb_handle_event and
1838 usb_cb_ctrl_write_finish.
1839 (request_handler): Remove.
1840 (handle_setup0): Call std_* directly, not indirectly by
1842 (ep_intr_handler_IN, ep_intr_handler_OUT): Remove.
1843 (usb_handle_transfer): Call EP*_Callback directly, not indirectly
1844 by ep_intr_handler_IN, ep_intr_handler_OUT.
1846 * src/usb_lld.h (struct usb_device_method, Device_Method): Remove.
1847 (usb_cb_device_reset, usb_cb_ctrl_write_finish)
1848 (usb_cb_setup, usb_cb_get_descriptor, usb_cb_handle_event)
1849 (usb_cb_interface): Define callbacks.
1850 (usb_initial_feature): New.
1851 (struct Descriptor): Move to ...
1852 * src/usb_desc.c: ... here.
1853 (usb_initial_feature): New.
1854 (usb_cb_get_descriptor): Rename from gnuk_get_descriptor and move
1857 * src/usb_ctrl.c (usb_cb_device_reset): Rename from
1859 (usb_cb_setup): Rename from gnuk_setup.
1860 (usb_cb_ctrl_write_finish): Rename from gnuk_ctrl_write_finish.
1861 (usb_cb_event): Rename from gnuk_usb_event.
1862 (usb_cb_interface): Rename from gnuk_interface.
1863 (Device_Method): Remove.
1865 * src/main.c (main): Use usb_initial_feature.
1867 2013-02-27 Niibe Yutaka <gniibe@fsij.org>
1869 * src/usb-icc.c (set_sw1sw2): Arguments are C and CHUNK_LEN.
1870 Fix reporting remaining bytes.
1871 (icc_send_data_block_gr): Follow the arguments change of
1874 2013-02-26 Niibe Yutaka <gniibe@fsij.org>
1876 * regnual/regnual.ld (MEMORY): Fix start address.
1878 * src/random.c (random_fini): New.
1879 * src/main.c (main): Call random_fini.
1881 2013-02-25 Niibe Yutaka <gniibe@fsij.org>
1883 * src/configure: Correct typo in help text.
1885 * src/gnuk.h (struct key_data_internal): Use uint32_t.
1886 * src/openpgp-do.c (do_openpgpcard_aid): Fix calculation of VID.
1887 (compute_key_data_checksum): Don't use type-punning pointer.
1888 (gpg_do_write_prvkey): Use coercing to char *.
1890 2013-02-22 Niibe Yutaka <gniibe@fsij.org>
1892 * src/openpgp-do.c (gpg_do_public_key): Add header of EC point.
1894 * src/openpgp-do.c (GPG_DO_DISCRETIONARY, cmp_discretionary): New.
1895 (cmp_app_data): Change to factor out GPG_DO_DISCRETIONARY.
1896 (gpg_do_table): Add GPG_DO_DISCRETIONARY.
1898 2013-02-21 Niibe Yutaka <gniibe@fsij.org>
1900 * src/gnuk.ld.in (MEMORY): Fix adding FLASH_SIZE unit.
1902 * src/call-ec_p256.c (ecdsa_sign): Fix secret key access.
1904 2013-02-20 Niibe Yutaka <gniibe@fsij.org>
1906 * src/openpgp.c (cmd_internal_authenticate): Support ECDSA for
1909 * src/openpgp-do.c (algorithm_attr_ecdsa): New.
1910 (algorithm_attr_rsa): Rename (was: algorithm_attr).
1911 (gpg_do_table): Change for GPG_DO_ALG_AUT.
1912 (gpg_do_write_prvkey): Support ECDSA key for authentication.
1913 (proc_key_import): Likewise.
1914 (gpg_do_public_key): Likewise.
1916 * src/call-ec_p256.c: New.
1917 * src/Makefile.in: Add call-ec_p256.c.
1918 * src/call-rsa.c (modulus_free): Remove.
1920 2013-02-19 Niibe Yutaka <gniibe@fsij.org>
1922 * regnual/regnual.ld (MEMORY): Fix address of regnual.
1924 * regnual/Makefile (MCFLAGS): Remove -mfix-cortex-m3-ldrd.
1925 (CFLAGS): Add output to .lst.
1926 * src/Makefile.in (MCFLAGS): Remove.
1928 * src/sha256.c: Update from NeuG 0.05.
1930 * ChibiOS_2.0.8: Remove.
1932 2013-02-18 Niibe Yutaka <gniibe@fsij.org>
1934 Changes for new ChibiOS/RT.
1935 * src/main.c: Include adc.h.
1936 (main): Call halInit, adc_init, and chSysInit (change for
1938 * src/random.h: New.
1939 * src/ac.c, src/bn.c, src/call-rsa.c, src/main.c: Include random.h.
1940 * src/openpgp.c, src/openpgp-do.c: Likewise.
1941 * src/configure, src/gnuk.ld.in: Add MEMORY_SIZE.
1942 * src/ec_p256.c: Fix call of bn256_add_uint.
1943 * boards/STM8S_DISCOVERY/*: Update for ChibiOS/RT 2.4.x.
1944 * boards/CQ_STARM/*: Likewise.
1945 * boards/FST_01_00/*: Likewise.
1946 * boards/OLIMEX_STM32_H103/*: Likewise.
1947 * boards/STBEE/*: Likewise.
1948 * boards/STBEE_MINI/*: Likewise.
1949 * boards/STM32_PRIMER2/*: Likewise.
1951 Merge ec_p256 branch.
1952 * src/Makefile.in: Add ECC files.
1953 * src/bn.h, src/bn.c: New.
1954 * src/jpc-ac.h, src/jpc.c: New.
1955 * src/ec_p256.h, src/ec_p256.c, src/ecc-cdh.c: New.
1956 * src/mod.h, src/mod.c, src/modp256.h, src/modp256.c: New.
1958 2013-02-17 Niibe Yutaka <gniibe@fsij.org>
1960 * chibios: New submodule for ChibioS/RT 2.4.x.
1961 * boards/FST_01/*: Update for ChibiOS/RT 2.4.x.
1962 * boards/common/mcuconf-common.h: Ditto.
1964 * src/chconf.h, src/halconf.h, src/Makefile.in, src/gnuk.ld.in:
1965 Update for ChibiOS/RT 2.4.x.
1967 * src/main.c, src/openpgp.c, src/usb-icc.c: Follow the change of
1969 * boards/common/board-common.c: Rename from hwinit.c.
1970 * src/usb_stm32f103.c: Rename from usb_lld.c.
1972 * src/neug.h, src/neug.c: Update NeuG 0.05.
1973 * src/adc_stm32f103.c, src/adc.h: New from NeuG 0.05.
1975 * src/random.c: Follow the change of NeuG 0.05.