接前一篇文章:tpm2-tools源码分析之tpm2_rsaencrypt.c(1)
本文对tpm2_rsaencrypt.c中的tpm2_tool_onstart函数进行详细解析。
先再次贴出该函数源码:
static bool tpm2_tool_onstart(tpm2_options **opts) {
static const struct option topts[] = {
{"output", required_argument, NULL, 'o'},
{"key-context", required_argument, NULL, 'c'},
{"scheme", required_argument, NULL, 's'},
{"label", required_argument, NULL, 'l'},
};
*opts = tpm2_options_new("o:c:s:l:", ARRAY_LEN(topts), topts, on_option,
on_args, 0);
return *opts != NULL;
}
tpm2_options结构的定义在tpm2-tools/lib/tpm2_options.h中,代码如下:
struct tpm2_options {
struct {
tpm2_option_handler on_opt;
tpm2_arg_handler on_arg;
} callbacks;
char *short_opts;
size_t len;
uint32_t flags;
struct option long_opts[];
};
typedef struct tpm2_options tpm2_options;
struct option的定义在/usr/include/bits/getopt_ext.h中,代码如下:
struct option
{
const char *name;
/* has_arg can't be an enum because some compilers complain about
type mismatches in all the code that assumes it is an int. */
int has_arg;
int *flag;
int val;
};
on_option函数的实现在同文件(tools/tpm2_rsaencrypt.c)中,如下:
static bool on_option(char key, char *value) {
switch (key) {
case 'c':
ctx.context_arg = value;
break;
case 'o':
ctx.output_path = value;
break;
case 's':
ctx.scheme_str = value;
break;
case 'l':
return tpm2_util_get_label(value, &ctx.label);
}
return true;
}
要更好地理解这些选项乃至tpm2_tool_onstart函数的功能,需要与tpm2_rsaencrypt命令的说明相结合来看。tpm2_rsaencrypt命令的详细说明参见:
tpm2-tools/tpm2_rsaencrypt.1.md at master · tpm2-software/tpm2-tools · GitHub
下载了源码后,在tpm2-tools/man/tpm2_rsaencrypt.1.md中。
其中的参数说明如下:
OPTIONS
-c, --key-context=OBJECT:
Context object pointing to the the public portion of RSA key to use for encryption. —— 指向用于加密的RSA密钥公共部分的上下文对象。
-o, --output=FILE:
Optional output file path to record the encrypted data to. The default is to print the binary encrypted data to stdout. —— 用于将加密数据记录到的可选输出文件路径。默认将二进制加密数据打印到标准输出(stdout)。
-s, --scheme=FORMAT:
Optional, set the padding scheme (defaults to rsaes). —— 可选,设置填充方案(默认为rsaes)。
- null - TPM_ALG_NULL uses the key's scheme if set.
- rsaes - TPM_ALG_RSAES which is RSAES_PKCSV1.5.
- oaep - TPM_ALG_OAEP which is RSAES_OAEP.
-l, --label=FILE or STRING:
Optional, set the label data. Can either be a string or file path. The TPM requires the last byte of the label to be zero, this is handled internally to the tool. No other embedded 0 bytes can exist or the TPM will truncate your label. —— 可选,设置标签数据。可以是字符串或文件路径。TPM要求标签的最后一个字节为零,这是在工具内部处理的。不存在其它嵌入的0字节,否则TPM将截断你的标签。
ARGUMENT the command line argument specifies the path of the file with data to be encrypted. —— 指定包含要被加密的数据的文件路径的命令行参数。
tpm2_options_new函数属于公共代码,在tpm2-tools/lib/tpm2_options.c中,代码如下:
tpm2_options *tpm2_options_new(const char *short_opts, size_t len,
const struct option *long_opts, tpm2_option_handler on_opt,
tpm2_arg_handler on_arg, uint32_t flags) {
tpm2_options *opts = calloc(1, sizeof(*opts) + (sizeof(*long_opts) * len));
if (!opts) {
LOG_ERR("oom");
return NULL;
}
/*
* On NULL, just make it a zero length string so we don't have to keep
* checking it for NULL.
*/
if (!short_opts) {
short_opts = "";
}
opts->short_opts = strdup(short_opts);
if (!opts->short_opts) {
LOG_ERR("oom");
free(opts);
return NULL;
}
opts->callbacks.on_opt = on_opt;
opts->callbacks.on_arg = on_arg;
opts->len = len;
opts->flags = flags;
memcpy(opts->long_opts, long_opts, len * sizeof(*long_opts));
return opts;
}
tpm2_new_options函数很容易理解,其功能是基于tpm2_tool_onstart函数中的struct option topts构建tpm2_options实例(*opts)。
至此,tpm2_rsaencrypt.c中的tpm2_tool_onstart函数就基本分析完了。