Home | History | Annotate | Line # | Download | only in evp
      1 /*
      2  * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
      3  *
      4  * Licensed under the Apache License 2.0 (the "License").  You may not use
      5  * this file except in compliance with the License.  You can obtain a copy
      6  * in the file LICENSE in the source distribution or at
      7  * https://www.openssl.org/source/license.html
      8  */
      9 
     10 /* We need to use some engine deprecated APIs */
     11 #define OPENSSL_SUPPRESS_DEPRECATED
     12 
     13 #include <stdio.h>
     14 #include <openssl/objects.h>
     15 #include <openssl/evp.h>
     16 #include <openssl/ec.h>
     17 #ifndef FIPS_MODULE
     18 #include <openssl/engine.h>
     19 #endif
     20 #include <openssl/params.h>
     21 #include <openssl/core_names.h>
     22 #include "internal/cryptlib.h"
     23 #include "internal/nelem.h"
     24 #include "internal/provider.h"
     25 #include "internal/core.h"
     26 #include "crypto/evp.h"
     27 #include "evp_local.h"
     28 
     29 static void cleanup_old_md_data(EVP_MD_CTX *ctx, int force)
     30 {
     31     if (ctx->digest != NULL) {
     32         if (ctx->digest->cleanup != NULL
     33             && !EVP_MD_CTX_test_flags(ctx, EVP_MD_CTX_FLAG_CLEANED))
     34             ctx->digest->cleanup(ctx);
     35         if (ctx->md_data != NULL && ctx->digest->ctx_size > 0
     36             && (!EVP_MD_CTX_test_flags(ctx, EVP_MD_CTX_FLAG_REUSE)
     37                 || force)) {
     38             OPENSSL_clear_free(ctx->md_data, ctx->digest->ctx_size);
     39             ctx->md_data = NULL;
     40         }
     41     }
     42 }
     43 
     44 void evp_md_ctx_clear_digest(EVP_MD_CTX *ctx, int force, int keep_fetched)
     45 {
     46     if (ctx->algctx != NULL) {
     47         if (ctx->digest != NULL && ctx->digest->freectx != NULL)
     48             ctx->digest->freectx(ctx->algctx);
     49         ctx->algctx = NULL;
     50         EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_CLEANED);
     51     }
     52 
     53     /* Code below to be removed when legacy support is dropped. */
     54 
     55     /*
     56      * Don't assume ctx->md_data was cleaned in EVP_Digest_Final, because
     57      * sometimes only copies of the context are ever finalised.
     58      */
     59     cleanup_old_md_data(ctx, force);
     60     if (force)
     61         ctx->digest = NULL;
     62 
     63 #if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_ENGINE)
     64     ENGINE_finish(ctx->engine);
     65     ctx->engine = NULL;
     66 #endif
     67 
     68     /* Non legacy code, this has to be later than the ctx->digest cleaning */
     69     if (!keep_fetched) {
     70         EVP_MD_free(ctx->fetched_digest);
     71         ctx->fetched_digest = NULL;
     72         ctx->reqdigest = NULL;
     73     }
     74 }
     75 
     76 static int evp_md_ctx_reset_ex(EVP_MD_CTX *ctx, int keep_fetched)
     77 {
     78     if (ctx == NULL)
     79         return 1;
     80 
     81     /*
     82      * pctx should be freed by the user of EVP_MD_CTX
     83      * if EVP_MD_CTX_FLAG_KEEP_PKEY_CTX is set
     84      */
     85     if (!EVP_MD_CTX_test_flags(ctx, EVP_MD_CTX_FLAG_KEEP_PKEY_CTX)) {
     86         EVP_PKEY_CTX_free(ctx->pctx);
     87         ctx->pctx = NULL;
     88     }
     89 
     90     evp_md_ctx_clear_digest(ctx, 0, keep_fetched);
     91     if (!keep_fetched)
     92         OPENSSL_cleanse(ctx, sizeof(*ctx));
     93 
     94     return 1;
     95 }
     96 
     97 /* This call frees resources associated with the context */
     98 int EVP_MD_CTX_reset(EVP_MD_CTX *ctx)
     99 {
    100     return evp_md_ctx_reset_ex(ctx, 0);
    101 }
    102 
    103 #ifndef FIPS_MODULE
    104 EVP_MD_CTX *evp_md_ctx_new_ex(EVP_PKEY *pkey, const ASN1_OCTET_STRING *id,
    105     OSSL_LIB_CTX *libctx, const char *propq)
    106 {
    107     EVP_MD_CTX *ctx;
    108     EVP_PKEY_CTX *pctx = NULL;
    109 
    110     if ((ctx = EVP_MD_CTX_new()) == NULL
    111         || (pctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, propq)) == NULL) {
    112         ERR_raise(ERR_LIB_ASN1, ERR_R_EVP_LIB);
    113         goto err;
    114     }
    115 
    116     if (id != NULL && EVP_PKEY_CTX_set1_id(pctx, id->data, id->length) <= 0)
    117         goto err;
    118 
    119     EVP_MD_CTX_set_pkey_ctx(ctx, pctx);
    120     return ctx;
    121 
    122 err:
    123     EVP_PKEY_CTX_free(pctx);
    124     EVP_MD_CTX_free(ctx);
    125     return NULL;
    126 }
    127 #endif
    128 
    129 EVP_MD_CTX *EVP_MD_CTX_new(void)
    130 {
    131     return OPENSSL_zalloc(sizeof(EVP_MD_CTX));
    132 }
    133 
    134 void EVP_MD_CTX_free(EVP_MD_CTX *ctx)
    135 {
    136     if (ctx == NULL)
    137         return;
    138 
    139     EVP_MD_CTX_reset(ctx);
    140     OPENSSL_free(ctx);
    141 }
    142 
    143 int evp_md_ctx_free_algctx(EVP_MD_CTX *ctx)
    144 {
    145     if (ctx->algctx != NULL) {
    146         if (!ossl_assert(ctx->digest != NULL)) {
    147             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    148             return 0;
    149         }
    150         if (ctx->digest->freectx != NULL)
    151             ctx->digest->freectx(ctx->algctx);
    152         ctx->algctx = NULL;
    153     }
    154     return 1;
    155 }
    156 
    157 static int evp_md_init_internal(EVP_MD_CTX *ctx, const EVP_MD *type,
    158     const OSSL_PARAM params[], ENGINE *impl)
    159 {
    160 #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
    161     ENGINE *tmpimpl = NULL;
    162 #endif
    163 
    164 #if !defined(FIPS_MODULE)
    165     if (ctx->pctx != NULL
    166         && EVP_PKEY_CTX_IS_SIGNATURE_OP(ctx->pctx)
    167         && ctx->pctx->op.sig.algctx != NULL) {
    168         /*
    169          * Prior to OpenSSL 3.0 calling EVP_DigestInit_ex() on an mdctx
    170          * previously initialised with EVP_DigestSignInit() would retain
    171          * information about the key, and re-initialise for another sign
    172          * operation. So in that case we redirect to EVP_DigestSignInit()
    173          */
    174         if (ctx->pctx->operation == EVP_PKEY_OP_SIGNCTX)
    175             return EVP_DigestSignInit(ctx, NULL, type, impl, NULL);
    176         if (ctx->pctx->operation == EVP_PKEY_OP_VERIFYCTX)
    177             return EVP_DigestVerifyInit(ctx, NULL, type, impl, NULL);
    178         ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
    179         return 0;
    180     }
    181 #endif
    182 
    183     EVP_MD_CTX_clear_flags(ctx, EVP_MD_CTX_FLAG_CLEANED | EVP_MD_CTX_FLAG_FINALISED);
    184 
    185     if (type != NULL) {
    186         ctx->reqdigest = type;
    187     } else {
    188         if (ctx->digest == NULL) {
    189             ERR_raise(ERR_LIB_EVP, EVP_R_NO_DIGEST_SET);
    190             return 0;
    191         }
    192         type = ctx->digest;
    193     }
    194 
    195     /* Code below to be removed when legacy support is dropped. */
    196 #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
    197     /*
    198      * Whether it's nice or not, "Inits" can be used on "Final"'d contexts so
    199      * this context may already have an ENGINE! Try to avoid releasing the
    200      * previous handle, re-querying for an ENGINE, and having a
    201      * reinitialisation, when it may all be unnecessary.
    202      */
    203     if (ctx->engine != NULL
    204         && ctx->digest != NULL
    205         && type->type == ctx->digest->type)
    206         goto skip_to_init;
    207 
    208     /*
    209      * Ensure an ENGINE left lying around from last time is cleared (the
    210      * previous check attempted to avoid this if the same ENGINE and
    211      * EVP_MD could be used).
    212      */
    213     ENGINE_finish(ctx->engine);
    214     ctx->engine = NULL;
    215 
    216     if (impl == NULL)
    217         tmpimpl = ENGINE_get_digest_engine(type->type);
    218 #endif
    219 
    220     /*
    221      * If there are engines involved or EVP_MD_CTX_FLAG_NO_INIT is set then we
    222      * should use legacy handling for now.
    223      */
    224     if (impl != NULL
    225 #if !defined(OPENSSL_NO_ENGINE)
    226         || ctx->engine != NULL
    227 #if !defined(FIPS_MODULE)
    228         || tmpimpl != NULL
    229 #endif
    230 #endif
    231         || (ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0
    232         || (type != NULL && type->origin == EVP_ORIG_METH)
    233         || (type == NULL && ctx->digest != NULL
    234             && ctx->digest->origin == EVP_ORIG_METH)) {
    235         /* If we were using provided hash before, cleanup algctx */
    236         if (!evp_md_ctx_free_algctx(ctx))
    237             return 0;
    238         if (ctx->digest == ctx->fetched_digest)
    239             ctx->digest = NULL;
    240         EVP_MD_free(ctx->fetched_digest);
    241         ctx->fetched_digest = NULL;
    242         goto legacy;
    243     }
    244 
    245     cleanup_old_md_data(ctx, 1);
    246 
    247     /* Start of non-legacy code below */
    248     if (ctx->digest == type) {
    249         if (!ossl_assert(type->prov != NULL)) {
    250             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    251             return 0;
    252         }
    253     } else {
    254         if (!evp_md_ctx_free_algctx(ctx))
    255             return 0;
    256     }
    257 
    258     if (type->prov == NULL) {
    259 #ifdef FIPS_MODULE
    260         /* We only do explicit fetches inside the FIPS module */
    261         ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    262         return 0;
    263 #else
    264         /* The NULL digest is a special case */
    265         EVP_MD *provmd = EVP_MD_fetch(NULL,
    266             type->type != NID_undef ? OBJ_nid2sn(type->type)
    267                                     : "NULL",
    268             "");
    269 
    270         if (provmd == NULL) {
    271             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    272             return 0;
    273         }
    274         type = provmd;
    275         EVP_MD_free(ctx->fetched_digest);
    276         ctx->fetched_digest = provmd;
    277 #endif
    278     }
    279 
    280     if (type->prov != NULL && ctx->fetched_digest != type) {
    281         if (!EVP_MD_up_ref((EVP_MD *)type)) {
    282             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    283             return 0;
    284         }
    285         EVP_MD_free(ctx->fetched_digest);
    286         ctx->fetched_digest = (EVP_MD *)type;
    287     }
    288     ctx->digest = type;
    289     if (ctx->algctx == NULL) {
    290         ctx->algctx = ctx->digest->newctx(ossl_provider_ctx(type->prov));
    291         if (ctx->algctx == NULL) {
    292             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    293             return 0;
    294         }
    295     }
    296 
    297     if (ctx->digest->dinit == NULL) {
    298         ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    299         return 0;
    300     }
    301 
    302     return ctx->digest->dinit(ctx->algctx, params);
    303 
    304     /* Code below to be removed when legacy support is dropped. */
    305 legacy:
    306 
    307 #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
    308     if (type) {
    309         if (impl != NULL) {
    310             if (!ENGINE_init(impl)) {
    311                 ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    312                 return 0;
    313             }
    314         } else {
    315             /* Ask if an ENGINE is reserved for this job */
    316             impl = tmpimpl;
    317         }
    318         if (impl != NULL) {
    319             /* There's an ENGINE for this job ... (apparently) */
    320             const EVP_MD *d = ENGINE_get_digest(impl, type->type);
    321 
    322             if (d == NULL) {
    323                 ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
    324                 ENGINE_finish(impl);
    325                 return 0;
    326             }
    327             /* We'll use the ENGINE's private digest definition */
    328             type = d;
    329             /*
    330              * Store the ENGINE functional reference so we know 'type' came
    331              * from an ENGINE and we need to release it when done.
    332              */
    333             ctx->engine = impl;
    334         } else
    335             ctx->engine = NULL;
    336     }
    337 #endif
    338     if (ctx->digest != type) {
    339         cleanup_old_md_data(ctx, 1);
    340 
    341         ctx->digest = type;
    342         if (!(ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) && type->ctx_size) {
    343             ctx->update = type->update;
    344             ctx->md_data = OPENSSL_zalloc(type->ctx_size);
    345             if (ctx->md_data == NULL)
    346                 return 0;
    347         }
    348     }
    349 #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
    350 skip_to_init:
    351 #endif
    352 #ifndef FIPS_MODULE
    353     if (ctx->pctx != NULL
    354         && (!EVP_PKEY_CTX_IS_SIGNATURE_OP(ctx->pctx)
    355             || ctx->pctx->op.sig.signature == NULL)) {
    356         int r;
    357         r = EVP_PKEY_CTX_ctrl(ctx->pctx, -1, EVP_PKEY_OP_TYPE_SIG,
    358             EVP_PKEY_CTRL_DIGESTINIT, 0, ctx);
    359         if (r <= 0 && (r != -2))
    360             return 0;
    361     }
    362 #endif
    363     if (ctx->flags & EVP_MD_CTX_FLAG_NO_INIT)
    364         return 1;
    365     return ctx->digest->init(ctx);
    366 }
    367 
    368 int EVP_DigestInit_ex2(EVP_MD_CTX *ctx, const EVP_MD *type,
    369     const OSSL_PARAM params[])
    370 {
    371     return evp_md_init_internal(ctx, type, params, NULL);
    372 }
    373 
    374 int EVP_DigestInit(EVP_MD_CTX *ctx, const EVP_MD *type)
    375 {
    376     EVP_MD_CTX_reset(ctx);
    377     return evp_md_init_internal(ctx, type, NULL, NULL);
    378 }
    379 
    380 int EVP_DigestInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl)
    381 {
    382     return evp_md_init_internal(ctx, type, NULL, impl);
    383 }
    384 
    385 int EVP_DigestUpdate(EVP_MD_CTX *ctx, const void *data, size_t count)
    386 {
    387     if (count == 0)
    388         return 1;
    389 
    390     if ((ctx->flags & EVP_MD_CTX_FLAG_FINALISED) != 0) {
    391         ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
    392         return 0;
    393     }
    394 
    395     if (ctx->pctx != NULL
    396         && EVP_PKEY_CTX_IS_SIGNATURE_OP(ctx->pctx)
    397         && ctx->pctx->op.sig.algctx != NULL) {
    398 #ifndef FIPS_MODULE
    399         /*
    400          * Prior to OpenSSL 3.0 EVP_DigestSignUpdate() and
    401          * EVP_DigestVerifyUpdate() were just macros for EVP_DigestUpdate().
    402          * Some code calls EVP_DigestUpdate() directly even when initialised
    403          * with EVP_DigestSignInit_ex() or
    404          * EVP_DigestVerifyInit_ex(), so we detect that and redirect to
    405          * the correct EVP_Digest*Update() function
    406          */
    407         if (ctx->pctx->operation == EVP_PKEY_OP_SIGNCTX)
    408             return EVP_DigestSignUpdate(ctx, data, count);
    409         if (ctx->pctx->operation == EVP_PKEY_OP_VERIFYCTX)
    410             return EVP_DigestVerifyUpdate(ctx, data, count);
    411 #endif
    412         ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
    413         return 0;
    414     }
    415 
    416     if (ctx->digest == NULL
    417         || ctx->digest->prov == NULL
    418         || (ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0)
    419         goto legacy;
    420 
    421     if (ctx->digest->dupdate == NULL) {
    422         ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
    423         return 0;
    424     }
    425     return ctx->digest->dupdate(ctx->algctx, data, count);
    426 
    427     /* Code below to be removed when legacy support is dropped. */
    428 legacy:
    429     return ctx->update != NULL ? ctx->update(ctx, data, count) : 0;
    430 }
    431 
    432 /* The caller can assume that this removes any secret data from the context */
    433 int EVP_DigestFinal(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *size)
    434 {
    435     int ret;
    436     ret = EVP_DigestFinal_ex(ctx, md, size);
    437     EVP_MD_CTX_reset(ctx);
    438     return ret;
    439 }
    440 
    441 /* The caller can assume that this removes any secret data from the context */
    442 int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *isize)
    443 {
    444     int ret, sz;
    445     size_t size = 0;
    446     size_t mdsize = 0;
    447 
    448     if (ctx->digest == NULL)
    449         return 0;
    450 
    451     sz = EVP_MD_CTX_get_size(ctx);
    452     if (sz < 0)
    453         return 0;
    454     mdsize = sz;
    455     if (ctx->digest->prov == NULL)
    456         goto legacy;
    457 
    458     if (ctx->digest->dfinal == NULL) {
    459         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
    460         return 0;
    461     }
    462 
    463     if ((ctx->flags & EVP_MD_CTX_FLAG_FINALISED) != 0) {
    464         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
    465         return 0;
    466     }
    467 
    468     ret = ctx->digest->dfinal(ctx->algctx, md, &size, mdsize);
    469 
    470     ctx->flags |= EVP_MD_CTX_FLAG_FINALISED;
    471 
    472     if (isize != NULL) {
    473         if (size <= UINT_MAX) {
    474             *isize = (unsigned int)size;
    475         } else {
    476             ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
    477             ret = 0;
    478         }
    479     }
    480 
    481     return ret;
    482 
    483     /* Code below to be removed when legacy support is dropped. */
    484 legacy:
    485     OPENSSL_assert(mdsize <= EVP_MAX_MD_SIZE);
    486     ret = ctx->digest->final(ctx, md);
    487     if (isize != NULL)
    488         *isize = mdsize;
    489     if (ctx->digest->cleanup) {
    490         ctx->digest->cleanup(ctx);
    491         EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_CLEANED);
    492     }
    493     OPENSSL_cleanse(ctx->md_data, ctx->digest->ctx_size);
    494     return ret;
    495 }
    496 
    497 /* This is a one shot operation */
    498 int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *md, size_t size)
    499 {
    500     int ret = 0;
    501     OSSL_PARAM params[2];
    502     size_t i = 0;
    503 
    504     if (ctx->digest == NULL) {
    505         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_NULL_ALGORITHM);
    506         return 0;
    507     }
    508 
    509     if (ctx->digest->prov == NULL)
    510         goto legacy;
    511 
    512     if (ctx->digest->dfinal == NULL) {
    513         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
    514         return 0;
    515     }
    516 
    517     if ((ctx->flags & EVP_MD_CTX_FLAG_FINALISED) != 0) {
    518         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
    519         return 0;
    520     }
    521 
    522     /*
    523      * For backward compatibility we pass the XOFLEN via a param here so that
    524      * older providers can use the supplied value. Ideally we should have just
    525      * used the size passed into ctx->digest->dfinal().
    526      */
    527     params[i++] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, &size);
    528     params[i++] = OSSL_PARAM_construct_end();
    529 
    530     if (EVP_MD_CTX_set_params(ctx, params) >= 0)
    531         ret = ctx->digest->dfinal(ctx->algctx, md, &size, size);
    532 
    533     ctx->flags |= EVP_MD_CTX_FLAG_FINALISED;
    534 
    535     return ret;
    536 
    537 legacy:
    538     if (EVP_MD_xof(ctx->digest)
    539         && size <= INT_MAX
    540         && ctx->digest->md_ctrl(ctx, EVP_MD_CTRL_XOF_LEN, (int)size, NULL)) {
    541         ret = ctx->digest->final(ctx, md);
    542         if (ctx->digest->cleanup != NULL) {
    543             ctx->digest->cleanup(ctx);
    544             EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_CLEANED);
    545         }
    546         OPENSSL_cleanse(ctx->md_data, ctx->digest->ctx_size);
    547     } else {
    548         ERR_raise(ERR_LIB_EVP, EVP_R_NOT_XOF_OR_INVALID_LENGTH);
    549     }
    550 
    551     return ret;
    552 }
    553 
    554 /* EVP_DigestSqueeze() can be called multiple times */
    555 int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *md, size_t size)
    556 {
    557     if (ctx->digest == NULL) {
    558         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_NULL_ALGORITHM);
    559         return 0;
    560     }
    561 
    562     if (ctx->digest->prov == NULL) {
    563         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
    564         return 0;
    565     }
    566 
    567     if (ctx->digest->dsqueeze == NULL) {
    568         ERR_raise(ERR_LIB_EVP, EVP_R_METHOD_NOT_SUPPORTED);
    569         return 0;
    570     }
    571 
    572     return ctx->digest->dsqueeze(ctx->algctx, md, &size, size);
    573 }
    574 
    575 EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)
    576 {
    577     EVP_MD_CTX *out = EVP_MD_CTX_new();
    578 
    579     if (out != NULL && !EVP_MD_CTX_copy_ex(out, in)) {
    580         EVP_MD_CTX_free(out);
    581         out = NULL;
    582     }
    583     return out;
    584 }
    585 
    586 int EVP_MD_CTX_copy(EVP_MD_CTX *out, const EVP_MD_CTX *in)
    587 {
    588     EVP_MD_CTX_reset(out);
    589     return EVP_MD_CTX_copy_ex(out, in);
    590 }
    591 
    592 int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in)
    593 {
    594     int digest_change = 0;
    595     unsigned char *tmp_buf;
    596 
    597     if (in == NULL) {
    598         ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_NULL_PARAMETER);
    599         return 0;
    600     }
    601 
    602     if (in->digest == NULL) {
    603         /* copying uninitialized digest context */
    604         EVP_MD_CTX_reset(out);
    605         if (out->fetched_digest != NULL)
    606             EVP_MD_free(out->fetched_digest);
    607         *out = *in;
    608         goto clone_pkey;
    609     }
    610 
    611     if (in->digest->prov == NULL
    612         || (in->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0)
    613         goto legacy;
    614 
    615     if (in->digest->dupctx == NULL) {
    616         ERR_raise(ERR_LIB_EVP, EVP_R_NOT_ABLE_TO_COPY_CTX);
    617         return 0;
    618     }
    619 
    620     if (out->digest == in->digest && in->digest->copyctx != NULL) {
    621 
    622         in->digest->copyctx(out->algctx, in->algctx);
    623 
    624         EVP_PKEY_CTX_free(out->pctx);
    625         out->pctx = NULL;
    626         cleanup_old_md_data(out, 0);
    627 
    628         out->flags = in->flags;
    629         out->update = in->update;
    630     } else {
    631         evp_md_ctx_reset_ex(out, 1);
    632         digest_change = (out->fetched_digest != in->fetched_digest);
    633 
    634         if (digest_change && in->fetched_digest != NULL
    635             && !EVP_MD_up_ref(in->fetched_digest))
    636             return 0;
    637         if (digest_change && out->fetched_digest != NULL)
    638             EVP_MD_free(out->fetched_digest);
    639         *out = *in;
    640         /* NULL out pointers in case of error */
    641         out->pctx = NULL;
    642         out->algctx = NULL;
    643 
    644         if (in->algctx != NULL) {
    645             out->algctx = in->digest->dupctx(in->algctx);
    646             if (out->algctx == NULL) {
    647                 ERR_raise(ERR_LIB_EVP, EVP_R_NOT_ABLE_TO_COPY_CTX);
    648                 return 0;
    649             }
    650         }
    651     }
    652 
    653 clone_pkey:
    654     /* copied EVP_MD_CTX should free the copied EVP_PKEY_CTX */
    655     EVP_MD_CTX_clear_flags(out, EVP_MD_CTX_FLAG_KEEP_PKEY_CTX);
    656 #ifndef FIPS_MODULE
    657     if (in->pctx != NULL) {
    658         out->pctx = EVP_PKEY_CTX_dup(in->pctx);
    659         if (out->pctx == NULL) {
    660             ERR_raise(ERR_LIB_EVP, EVP_R_NOT_ABLE_TO_COPY_CTX);
    661             EVP_MD_CTX_reset(out);
    662             return 0;
    663         }
    664     }
    665 #endif
    666 
    667     return 1;
    668 
    669     /* Code below to be removed when legacy support is dropped. */
    670 legacy:
    671 #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
    672     /* Make sure it's safe to copy a digest context using an ENGINE */
    673     if (in->engine && !ENGINE_init(in->engine)) {
    674         ERR_raise(ERR_LIB_EVP, ERR_R_ENGINE_LIB);
    675         return 0;
    676     }
    677 #endif
    678 
    679     if (out->digest == in->digest) {
    680         tmp_buf = out->md_data;
    681         EVP_MD_CTX_set_flags(out, EVP_MD_CTX_FLAG_REUSE);
    682     } else
    683         tmp_buf = NULL;
    684     EVP_MD_CTX_reset(out);
    685     memcpy(out, in, sizeof(*out));
    686 
    687     /* copied EVP_MD_CTX should free the copied EVP_PKEY_CTX */
    688     EVP_MD_CTX_clear_flags(out, EVP_MD_CTX_FLAG_KEEP_PKEY_CTX);
    689 
    690     /* Null these variables, since they are getting fixed up
    691      * properly below.  Anything else may cause a memleak and/or
    692      * double free if any of the memory allocations below fail
    693      */
    694     out->md_data = NULL;
    695     out->pctx = NULL;
    696 
    697     if (in->md_data && out->digest->ctx_size) {
    698         if (tmp_buf)
    699             out->md_data = tmp_buf;
    700         else {
    701             out->md_data = OPENSSL_malloc(out->digest->ctx_size);
    702             if (out->md_data == NULL)
    703                 return 0;
    704         }
    705         memcpy(out->md_data, in->md_data, out->digest->ctx_size);
    706     }
    707 
    708     out->update = in->update;
    709 
    710 #ifndef FIPS_MODULE
    711     if (in->pctx) {
    712         out->pctx = EVP_PKEY_CTX_dup(in->pctx);
    713         if (!out->pctx) {
    714             EVP_MD_CTX_reset(out);
    715             return 0;
    716         }
    717     }
    718 #endif
    719 
    720     if (out->digest->copy)
    721         return out->digest->copy(out, in);
    722 
    723     return 1;
    724 }
    725 
    726 int EVP_Digest(const void *data, size_t count,
    727     unsigned char *md, unsigned int *size, const EVP_MD *type,
    728     ENGINE *impl)
    729 {
    730     EVP_MD_CTX *ctx = EVP_MD_CTX_new();
    731     int ret;
    732 
    733     if (ctx == NULL)
    734         return 0;
    735     EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_ONESHOT);
    736     ret = EVP_DigestInit_ex(ctx, type, impl)
    737         && EVP_DigestUpdate(ctx, data, count)
    738         && EVP_DigestFinal_ex(ctx, md, size);
    739     EVP_MD_CTX_free(ctx);
    740 
    741     return ret;
    742 }
    743 
    744 int EVP_Q_digest(OSSL_LIB_CTX *libctx, const char *name, const char *propq,
    745     const void *data, size_t datalen,
    746     unsigned char *md, size_t *mdlen)
    747 {
    748     EVP_MD *digest = EVP_MD_fetch(libctx, name, propq);
    749     unsigned int temp = 0;
    750     int ret = 0;
    751 
    752     if (digest != NULL) {
    753         ret = EVP_Digest(data, datalen, md, &temp, digest, NULL);
    754         EVP_MD_free(digest);
    755     }
    756     if (mdlen != NULL)
    757         *mdlen = temp;
    758     return ret;
    759 }
    760 
    761 int EVP_MD_get_params(const EVP_MD *digest, OSSL_PARAM params[])
    762 {
    763     if (digest != NULL && digest->get_params != NULL)
    764         return digest->get_params(params);
    765     return 0;
    766 }
    767 
    768 const OSSL_PARAM *EVP_MD_gettable_params(const EVP_MD *digest)
    769 {
    770     if (digest != NULL && digest->gettable_params != NULL)
    771         return digest->gettable_params(
    772             ossl_provider_ctx(EVP_MD_get0_provider(digest)));
    773     return NULL;
    774 }
    775 
    776 int EVP_MD_CTX_set_params(EVP_MD_CTX *ctx, const OSSL_PARAM params[])
    777 {
    778     EVP_PKEY_CTX *pctx = ctx->pctx;
    779 
    780     /* If we have a pctx then we should try that first */
    781     if (pctx != NULL
    782         && (pctx->operation == EVP_PKEY_OP_VERIFYCTX
    783             || pctx->operation == EVP_PKEY_OP_SIGNCTX)
    784         && pctx->op.sig.algctx != NULL
    785         && pctx->op.sig.signature->set_ctx_md_params != NULL)
    786         return pctx->op.sig.signature->set_ctx_md_params(pctx->op.sig.algctx,
    787             params);
    788 
    789     if (ctx->digest != NULL && ctx->digest->set_ctx_params != NULL)
    790         return ctx->digest->set_ctx_params(ctx->algctx, params);
    791 
    792     return 0;
    793 }
    794 
    795 const OSSL_PARAM *EVP_MD_settable_ctx_params(const EVP_MD *md)
    796 {
    797     void *provctx;
    798 
    799     if (md != NULL && md->settable_ctx_params != NULL) {
    800         provctx = ossl_provider_ctx(EVP_MD_get0_provider(md));
    801         return md->settable_ctx_params(NULL, provctx);
    802     }
    803     return NULL;
    804 }
    805 
    806 const OSSL_PARAM *EVP_MD_CTX_settable_params(EVP_MD_CTX *ctx)
    807 {
    808     EVP_PKEY_CTX *pctx;
    809     void *alg;
    810 
    811     if (ctx == NULL)
    812         return NULL;
    813 
    814     /* If we have a pctx then we should try that first */
    815     pctx = ctx->pctx;
    816     if (pctx != NULL
    817         && (pctx->operation == EVP_PKEY_OP_VERIFYCTX
    818             || pctx->operation == EVP_PKEY_OP_SIGNCTX)
    819         && pctx->op.sig.algctx != NULL
    820         && pctx->op.sig.signature->settable_ctx_md_params != NULL)
    821         return pctx->op.sig.signature->settable_ctx_md_params(
    822             pctx->op.sig.algctx);
    823 
    824     if (ctx->digest != NULL && ctx->digest->settable_ctx_params != NULL) {
    825         alg = ossl_provider_ctx(EVP_MD_get0_provider(ctx->digest));
    826         return ctx->digest->settable_ctx_params(ctx->algctx, alg);
    827     }
    828 
    829     return NULL;
    830 }
    831 
    832 int EVP_MD_CTX_get_params(EVP_MD_CTX *ctx, OSSL_PARAM params[])
    833 {
    834     EVP_PKEY_CTX *pctx = ctx->pctx;
    835 
    836     /* If we have a pctx then we should try that first */
    837     if (pctx != NULL
    838         && (pctx->operation == EVP_PKEY_OP_VERIFYCTX
    839             || pctx->operation == EVP_PKEY_OP_SIGNCTX)
    840         && pctx->op.sig.algctx != NULL
    841         && pctx->op.sig.signature->get_ctx_md_params != NULL)
    842         return pctx->op.sig.signature->get_ctx_md_params(pctx->op.sig.algctx,
    843             params);
    844 
    845     if (ctx->digest != NULL && ctx->digest->get_ctx_params != NULL)
    846         return ctx->digest->get_ctx_params(ctx->algctx, params);
    847 
    848     return 0;
    849 }
    850 
    851 const OSSL_PARAM *EVP_MD_gettable_ctx_params(const EVP_MD *md)
    852 {
    853     void *provctx;
    854 
    855     if (md != NULL && md->gettable_ctx_params != NULL) {
    856         provctx = ossl_provider_ctx(EVP_MD_get0_provider(md));
    857         return md->gettable_ctx_params(NULL, provctx);
    858     }
    859     return NULL;
    860 }
    861 
    862 const OSSL_PARAM *EVP_MD_CTX_gettable_params(EVP_MD_CTX *ctx)
    863 {
    864     EVP_PKEY_CTX *pctx;
    865     void *provctx;
    866 
    867     if (ctx == NULL)
    868         return NULL;
    869 
    870     /* If we have a pctx then we should try that first */
    871     pctx = ctx->pctx;
    872     if (pctx != NULL
    873         && (pctx->operation == EVP_PKEY_OP_VERIFYCTX
    874             || pctx->operation == EVP_PKEY_OP_SIGNCTX)
    875         && pctx->op.sig.signature != NULL
    876         && pctx->op.sig.signature->gettable_ctx_md_params != NULL
    877         && pctx->op.sig.algctx != NULL)
    878         return pctx->op.sig.signature->gettable_ctx_md_params(
    879             pctx->op.sig.algctx);
    880 
    881     if (ctx->digest != NULL && ctx->digest->gettable_ctx_params != NULL) {
    882         provctx = ossl_provider_ctx(EVP_MD_get0_provider(ctx->digest));
    883         return ctx->digest->gettable_ctx_params(ctx->algctx, provctx);
    884     }
    885     return NULL;
    886 }
    887 
    888 int EVP_MD_CTX_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void *p2)
    889 {
    890     int ret = EVP_CTRL_RET_UNSUPPORTED;
    891     int set_params = 1;
    892     size_t sz;
    893     OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END };
    894 
    895     if (ctx == NULL) {
    896         ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_NULL_PARAMETER);
    897         return 0;
    898     }
    899 
    900     if (ctx->digest != NULL && ctx->digest->prov == NULL)
    901         goto legacy;
    902 
    903     switch (cmd) {
    904     case EVP_MD_CTRL_XOF_LEN:
    905         sz = (size_t)p1;
    906         params[0] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, &sz);
    907         break;
    908     case EVP_MD_CTRL_MICALG:
    909         set_params = 0;
    910         params[0] = OSSL_PARAM_construct_utf8_string(OSSL_DIGEST_PARAM_MICALG,
    911             p2, p1 ? p1 : 9999);
    912         break;
    913     case EVP_CTRL_SSL3_MASTER_SECRET:
    914         params[0] = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_SSL3_MS,
    915             p2, p1);
    916         break;
    917     default:
    918         goto conclude;
    919     }
    920 
    921     if (set_params)
    922         ret = EVP_MD_CTX_set_params(ctx, params);
    923     else
    924         ret = EVP_MD_CTX_get_params(ctx, params);
    925     goto conclude;
    926 
    927     /* Code below to be removed when legacy support is dropped. */
    928 legacy:
    929     if (ctx->digest->md_ctrl == NULL) {
    930         ERR_raise(ERR_LIB_EVP, EVP_R_CTRL_NOT_IMPLEMENTED);
    931         return 0;
    932     }
    933 
    934     ret = ctx->digest->md_ctrl(ctx, cmd, p1, p2);
    935 conclude:
    936     if (ret <= 0)
    937         return 0;
    938     return ret;
    939 }
    940 
    941 EVP_MD *evp_md_new(void)
    942 {
    943     EVP_MD *md = OPENSSL_zalloc(sizeof(*md));
    944 
    945     if (md != NULL && !CRYPTO_NEW_REF(&md->refcnt, 1)) {
    946         OPENSSL_free(md);
    947         return NULL;
    948     }
    949     return md;
    950 }
    951 
    952 /*
    953  * FIPS module note: since internal fetches will be entirely
    954  * provider based, we know that none of its code depends on legacy
    955  * NIDs or any functionality that use them.
    956  */
    957 #ifndef FIPS_MODULE
    958 static void set_legacy_nid(const char *name, void *vlegacy_nid)
    959 {
    960     int nid;
    961     int *legacy_nid = vlegacy_nid;
    962     /*
    963      * We use lowest level function to get the associated method, because
    964      * higher level functions such as EVP_get_digestbyname() have changed
    965      * to look at providers too.
    966      */
    967     const void *legacy_method = OBJ_NAME_get(name, OBJ_NAME_TYPE_MD_METH);
    968 
    969     if (*legacy_nid == -1) /* We found a clash already */
    970         return;
    971 
    972     if (legacy_method == NULL)
    973         return;
    974     nid = EVP_MD_nid(legacy_method);
    975     if (*legacy_nid != NID_undef && *legacy_nid != nid) {
    976         *legacy_nid = -1;
    977         return;
    978     }
    979     *legacy_nid = nid;
    980 }
    981 #endif
    982 
    983 static int evp_md_cache_constants(EVP_MD *md)
    984 {
    985     int ok, xof = 0, algid_absent = 0;
    986     size_t blksz = 0;
    987     size_t mdsize = 0;
    988     OSSL_PARAM params[5];
    989 
    990     /*
    991      * Note that these parameters are 'constants' that are only set up
    992      * during the EVP_MD_fetch(). For this reason the XOF functions set the
    993      * md_size to 0, since the output size is unknown.
    994      */
    995     params[0] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_BLOCK_SIZE, &blksz);
    996     params[1] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_SIZE, &mdsize);
    997     params[2] = OSSL_PARAM_construct_int(OSSL_DIGEST_PARAM_XOF, &xof);
    998     params[3] = OSSL_PARAM_construct_int(OSSL_DIGEST_PARAM_ALGID_ABSENT,
    999         &algid_absent);
   1000     params[4] = OSSL_PARAM_construct_end();
   1001     ok = evp_do_md_getparams(md, params) > 0;
   1002     if (mdsize > INT_MAX || blksz > INT_MAX)
   1003         ok = 0;
   1004     if (ok) {
   1005         md->block_size = (int)blksz;
   1006         md->md_size = (int)mdsize;
   1007         if (xof)
   1008             md->flags |= EVP_MD_FLAG_XOF;
   1009         if (algid_absent)
   1010             md->flags |= EVP_MD_FLAG_DIGALGID_ABSENT;
   1011     }
   1012     return ok;
   1013 }
   1014 
   1015 static void *evp_md_from_algorithm(int name_id,
   1016     const OSSL_ALGORITHM *algodef,
   1017     OSSL_PROVIDER *prov)
   1018 {
   1019     const OSSL_DISPATCH *fns = algodef->implementation;
   1020     EVP_MD *md = NULL;
   1021     int fncnt = 0;
   1022 
   1023     /* EVP_MD_fetch() will set the legacy NID if available */
   1024     if ((md = evp_md_new()) == NULL) {
   1025         ERR_raise(ERR_LIB_EVP, ERR_R_EVP_LIB);
   1026         return NULL;
   1027     }
   1028 
   1029 #ifndef FIPS_MODULE
   1030     md->type = NID_undef;
   1031     if (!evp_names_do_all(prov, name_id, set_legacy_nid, &md->type)
   1032         || md->type == -1) {
   1033         ERR_raise(ERR_LIB_EVP, ERR_R_INTERNAL_ERROR);
   1034         goto err;
   1035     }
   1036 #endif
   1037 
   1038     md->name_id = name_id;
   1039     if ((md->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
   1040         goto err;
   1041 
   1042     md->description = algodef->algorithm_description;
   1043 
   1044     for (; fns->function_id != 0; fns++) {
   1045         switch (fns->function_id) {
   1046         case OSSL_FUNC_DIGEST_NEWCTX:
   1047             if (md->newctx == NULL) {
   1048                 md->newctx = OSSL_FUNC_digest_newctx(fns);
   1049                 fncnt++;
   1050             }
   1051             break;
   1052         case OSSL_FUNC_DIGEST_INIT:
   1053             if (md->dinit == NULL) {
   1054                 md->dinit = OSSL_FUNC_digest_init(fns);
   1055                 fncnt++;
   1056             }
   1057             break;
   1058         case OSSL_FUNC_DIGEST_UPDATE:
   1059             if (md->dupdate == NULL) {
   1060                 md->dupdate = OSSL_FUNC_digest_update(fns);
   1061                 fncnt++;
   1062             }
   1063             break;
   1064         case OSSL_FUNC_DIGEST_FINAL:
   1065             if (md->dfinal == NULL) {
   1066                 md->dfinal = OSSL_FUNC_digest_final(fns);
   1067                 fncnt++;
   1068             }
   1069             break;
   1070         case OSSL_FUNC_DIGEST_SQUEEZE:
   1071             if (md->dsqueeze == NULL) {
   1072                 md->dsqueeze = OSSL_FUNC_digest_squeeze(fns);
   1073                 fncnt++;
   1074             }
   1075             break;
   1076         case OSSL_FUNC_DIGEST_DIGEST:
   1077             if (md->digest == NULL)
   1078                 md->digest = OSSL_FUNC_digest_digest(fns);
   1079             /* We don't increment fnct for this as it is stand alone */
   1080             break;
   1081         case OSSL_FUNC_DIGEST_FREECTX:
   1082             if (md->freectx == NULL) {
   1083                 md->freectx = OSSL_FUNC_digest_freectx(fns);
   1084                 fncnt++;
   1085             }
   1086             break;
   1087         case OSSL_FUNC_DIGEST_DUPCTX:
   1088             if (md->dupctx == NULL)
   1089                 md->dupctx = OSSL_FUNC_digest_dupctx(fns);
   1090             break;
   1091         case OSSL_FUNC_DIGEST_GET_PARAMS:
   1092             if (md->get_params == NULL)
   1093                 md->get_params = OSSL_FUNC_digest_get_params(fns);
   1094             break;
   1095         case OSSL_FUNC_DIGEST_SET_CTX_PARAMS:
   1096             if (md->set_ctx_params == NULL)
   1097                 md->set_ctx_params = OSSL_FUNC_digest_set_ctx_params(fns);
   1098             break;
   1099         case OSSL_FUNC_DIGEST_GET_CTX_PARAMS:
   1100             if (md->get_ctx_params == NULL)
   1101                 md->get_ctx_params = OSSL_FUNC_digest_get_ctx_params(fns);
   1102             break;
   1103         case OSSL_FUNC_DIGEST_GETTABLE_PARAMS:
   1104             if (md->gettable_params == NULL)
   1105                 md->gettable_params = OSSL_FUNC_digest_gettable_params(fns);
   1106             break;
   1107         case OSSL_FUNC_DIGEST_SETTABLE_CTX_PARAMS:
   1108             if (md->settable_ctx_params == NULL)
   1109                 md->settable_ctx_params = OSSL_FUNC_digest_settable_ctx_params(fns);
   1110             break;
   1111         case OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS:
   1112             if (md->gettable_ctx_params == NULL)
   1113                 md->gettable_ctx_params = OSSL_FUNC_digest_gettable_ctx_params(fns);
   1114             break;
   1115         case OSSL_FUNC_DIGEST_COPYCTX:
   1116             if (md->copyctx == NULL)
   1117                 md->copyctx = OSSL_FUNC_digest_copyctx(fns);
   1118             break;
   1119         }
   1120     }
   1121     if ((fncnt != 0 && fncnt != 5 && fncnt != 6)
   1122         || (fncnt == 0 && md->digest == NULL)) {
   1123         /*
   1124          * In order to be a consistent set of functions we either need the
   1125          * whole set of init/update/final etc functions or none of them.
   1126          * The "digest" function can standalone. We at least need one way to
   1127          * generate digests.
   1128          */
   1129         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_PROVIDER_FUNCTIONS);
   1130         goto err;
   1131     }
   1132     if (prov != NULL && !ossl_provider_up_ref(prov))
   1133         goto err;
   1134 
   1135     md->prov = prov;
   1136 
   1137     if (!evp_md_cache_constants(md)) {
   1138         ERR_raise(ERR_LIB_EVP, EVP_R_CACHE_CONSTANTS_FAILED);
   1139         goto err;
   1140     }
   1141 
   1142     return md;
   1143 
   1144 err:
   1145     EVP_MD_free(md);
   1146     return NULL;
   1147 }
   1148 
   1149 static int evp_md_up_ref(void *md)
   1150 {
   1151     return EVP_MD_up_ref(md);
   1152 }
   1153 
   1154 static void evp_md_free(void *md)
   1155 {
   1156     EVP_MD_free(md);
   1157 }
   1158 
   1159 EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
   1160     const char *properties)
   1161 {
   1162     EVP_MD *md = evp_generic_fetch(ctx, OSSL_OP_DIGEST, algorithm, properties,
   1163         evp_md_from_algorithm, evp_md_up_ref, evp_md_free);
   1164 
   1165     return md;
   1166 }
   1167 
   1168 int EVP_MD_up_ref(EVP_MD *md)
   1169 {
   1170     int ref = 0;
   1171 
   1172     if (md->origin == EVP_ORIG_DYNAMIC)
   1173         CRYPTO_UP_REF(&md->refcnt, &ref);
   1174     return 1;
   1175 }
   1176 
   1177 void EVP_MD_free(EVP_MD *md)
   1178 {
   1179     int i;
   1180 
   1181     if (md == NULL || md->origin != EVP_ORIG_DYNAMIC)
   1182         return;
   1183 
   1184     CRYPTO_DOWN_REF(&md->refcnt, &i);
   1185     if (i > 0)
   1186         return;
   1187     evp_md_free_int(md);
   1188 }
   1189 
   1190 void EVP_MD_do_all_provided(OSSL_LIB_CTX *libctx,
   1191     void (*fn)(EVP_MD *mac, void *arg),
   1192     void *arg)
   1193 {
   1194     evp_generic_do_all(libctx, OSSL_OP_DIGEST,
   1195         (void (*)(void *, void *))fn, arg,
   1196         evp_md_from_algorithm, evp_md_up_ref, evp_md_free);
   1197 }
   1198 
   1199 EVP_MD *evp_digest_fetch_from_prov(OSSL_PROVIDER *prov,
   1200     const char *algorithm,
   1201     const char *properties)
   1202 {
   1203     return evp_generic_fetch_from_prov(prov, OSSL_OP_DIGEST,
   1204         algorithm, properties,
   1205         evp_md_from_algorithm,
   1206         evp_md_up_ref,
   1207         evp_md_free);
   1208 }
   1209 
   1210 typedef struct {
   1211     int md_nid;
   1212     int hmac_nid;
   1213 } ossl_hmacmd_pair;
   1214 
   1215 static const ossl_hmacmd_pair ossl_hmacmd_pairs[] = {
   1216     { NID_sha1, NID_hmacWithSHA1 },
   1217     { NID_md5, NID_hmacWithMD5 },
   1218     { NID_sha224, NID_hmacWithSHA224 },
   1219     { NID_sha256, NID_hmacWithSHA256 },
   1220     { NID_sha384, NID_hmacWithSHA384 },
   1221     { NID_sha512, NID_hmacWithSHA512 },
   1222     { NID_id_GostR3411_94, NID_id_HMACGostR3411_94 },
   1223     { NID_id_GostR3411_2012_256, NID_id_tc26_hmac_gost_3411_2012_256 },
   1224     { NID_id_GostR3411_2012_512, NID_id_tc26_hmac_gost_3411_2012_512 },
   1225     { NID_sha3_224, NID_hmac_sha3_224 },
   1226     { NID_sha3_256, NID_hmac_sha3_256 },
   1227     { NID_sha3_384, NID_hmac_sha3_384 },
   1228     { NID_sha3_512, NID_hmac_sha3_512 },
   1229     { NID_sha512_224, NID_hmacWithSHA512_224 },
   1230     { NID_sha512_256, NID_hmacWithSHA512_256 }
   1231 };
   1232 
   1233 int ossl_hmac2mdnid(int hmac_nid)
   1234 {
   1235     int md_nid = NID_undef;
   1236     size_t i;
   1237 
   1238     for (i = 0; i < OSSL_NELEM(ossl_hmacmd_pairs); i++) {
   1239         if (ossl_hmacmd_pairs[i].hmac_nid == hmac_nid) {
   1240             md_nid = ossl_hmacmd_pairs[i].md_nid;
   1241             break;
   1242         }
   1243     }
   1244 
   1245     return md_nid;
   1246 }
   1247 
   1248 int ossl_md2hmacnid(int md_nid)
   1249 {
   1250     int hmac_nid = NID_undef;
   1251     size_t i;
   1252 
   1253     for (i = 0; i < OSSL_NELEM(ossl_hmacmd_pairs); i++) {
   1254         if (ossl_hmacmd_pairs[i].md_nid == md_nid) {
   1255             hmac_nid = ossl_hmacmd_pairs[i].hmac_nid;
   1256             break;
   1257         }
   1258     }
   1259 
   1260     return hmac_nid;
   1261 }
   1262