1- // Copyright (c) Microsoft Corporation. All Rights Reserved. See License.txt in the project root for license information.
1+ // Copyright (c) Microsoft Corporation. All Rights Reserved. See License.txt in the project root for license information.
22
33module internal FSharp.Compiler.AbstractIL.StrongNameSign
44
@@ -126,9 +126,11 @@ type BlobReader =
126126 val mutable _blob : byte array
127127 val mutable _offset : int
128128 new ( blob: byte array) = { _ blob = blob; _ offset = 0 }
129-
130- member x.Offset with get() = x._ offset and set ( v ) = x._ offset <- v
131-
129+
130+ member x.Offset
131+ with get () = x._ offset
132+ and set ( v ) = x._ offset <- v
133+
132134 member x.ReadInt32 () : int =
133135 let offset = x._ offset
134136 x._ offset <- offset + 4
@@ -144,34 +146,40 @@ type BlobReader =
144146 x._ offset <- x._ offset + length
145147 arr |> Array.rev
146148
147- let RSAParametersFromBlob blob keyType =
149+ /// Decodes an RSA functional blob into RSAParameters.
150+ /// Ref: https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-wincrypt-publickeystruc
151+ let RSAParametersFromBlob blob =
148152 let mutable reader = BlobReader blob
149153
150- let header = reader.ReadInt32()
151- if header <> 0x00000206 && header <> 0x00000207 && keyType = KeyType.KeyPair then
152- raise ( CryptographicException( getResourceString ( FSComp.SR.ilSignPrivateKeyExpected ())))
153-
154- reader.ReadInt32() |> ignore // ALG_ID
154+ // Skip PUBLICKEYSTRUC (8 bytes): bType(1), bVersion(1), reserved(2), aiKeyAlg(4)
155+ reader.ReadInt32() |> ignore
156+ reader.ReadInt32() |> ignore
155157
156- if reader.ReadInt32() <> RSA_ PRIV_ MAGIC then
157- raise ( CryptographicException( getResourceString ( FSComp.SR.ilSignRsaKeyExpected ()))) // 'RSA2'
158+ // Read RSAPUBKEY header (starts with magic)
159+ // Ref: https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-wincrypt-rsapubkey
160+ let magic = reader.ReadInt32()
158161
159- let byteLen , halfLen =
160- let bitLen = reader.ReadInt32 ( )
162+ if magic <> RSA _ PUB _ MAGIC && magic <> RSA _ PRIV _ MAGIC then
163+ raise ( CryptographicException ( getResourceString ( FSComp.SR.ilSignRsaKeyExpected ())) )
161164
162- match bitLen % 16 with
163- | 0 -> ( bitLen / 8 , bitLen / 16 )
164- | _ -> raise ( CryptographicException( getResourceString ( FSComp.SR.ilSignInvalidBitLen ())))
165+ let bitLen = reader.ReadInt32()
166+ let byteLen , halfLen = ( bitLen / 8 , bitLen / 16 )
165167
166168 let mutable key = RSAParameters()
167- key.Exponent <- reader.ReadBigInteger 4
169+ key.Exponent <- reader.ReadBigInteger 4 // pubexp (4 bytes)
168170 key.Modulus <- reader.ReadBigInteger byteLen
169- key.P <- reader.ReadBigInteger halfLen
170- key.Q <- reader.ReadBigInteger halfLen
171- key.DP <- reader.ReadBigInteger halfLen
172- key.DQ <- reader.ReadBigInteger halfLen
173- key.InverseQ <- reader.ReadBigInteger halfLen
174- key.D <- reader.ReadBigInteger byteLen
171+
172+ // IMPORTANT: Conditional reading based on Magic.
173+ // Private fields (P, Q, DP, DQ, InverseQ, D) follow the modulus ONLY in PrivateKeyBlobs (RSA2).
174+ // Ref: https://learn.microsoft.com/en-us/windows/win32/seccrypto/base-provider-key-blobs
175+ if magic = RSA_ PRIV_ MAGIC then
176+ key.P <- reader.ReadBigInteger halfLen
177+ key.Q <- reader.ReadBigInteger halfLen
178+ key.DP <- reader.ReadBigInteger halfLen
179+ key.DQ <- reader.ReadBigInteger halfLen
180+ key.InverseQ <- reader.ReadBigInteger halfLen
181+ key.D <- reader.ReadBigInteger byteLen
182+
175183 key
176184
177185let validateRSAField ( field : byte array MaybeNull ) expected ( name : string ) =
@@ -262,9 +270,9 @@ let toCLRKeyBlob (rsaParameters: RSAParameters) (algId: int) : byte array =
262270
263271 key
264272
265- let createSignature ( hash : byte array ) keyBlob keyType =
273+ let createSignature ( hash : byte array ) keyBlob _keyType =
266274 use rsa = RSA.Create()
267- rsa.ImportParameters( RSAParametersFromBlob keyBlob keyType )
275+ rsa.ImportParameters( RSAParametersFromBlob keyBlob)
268276
269277 let signature =
270278 rsa.SignHash( hash, HashAlgorithmName.SHA1, RSASignaturePadding.Pkcs1)
@@ -304,29 +312,30 @@ let signStream stream keyBlob =
304312 patchSignature stream peReader signature
305313
306314let signatureSize ( pk : byte array ) =
307- if pk.Length < 20 then 0
315+ if ( box pk |> isNull) || pk.Length = 0 then
316+ 0
317+ else if
318+ // Roslyn logic: (keySize < 160) ? 128 : keySize - 32
319+ pk.Length < 160
320+ then
321+ 128
308322 else
309- let reader = BlobReader pk
310- reader.Offset <- 12
311- let bitLen = reader.ReadInt32()
312- let modulusLength = bitLen / 8
313-
314- if modulusLength < 160 then 128 else modulusLength - 32
315- // Key signing
316- type keyContainerName = string
317- type keyPair = byte array
318- type pubkey = byte array
319- type pubkeyOptions = byte array * bool
323+ pk.Length - 32
320324
325+ // Returns a CLR Format Blob public key
321326let getPublicKeyForKeyPair keyBlob =
322327 use rsa = RSA.Create()
323- rsa.ImportParameters( RSAParametersFromBlob keyBlob KeyType.KeyPair )
328+ rsa.ImportParameters( RSAParametersFromBlob keyBlob)
324329 let rsaParameters = rsa.ExportParameters false
325330 toCLRKeyBlob rsaParameters CALG_ RSA_ KEYX
326331
327- let signerGetPublicKeyForKeyPair ( kp : keyPair ) : pubkey = getPublicKeyForKeyPair kp
332+ // Key signing
333+ type keyContainerName = string
334+ type keyPair = byte array
335+ type pubkey = byte array
336+ type pubkeyOptions = byte array * bool
328337
329- let signerSignatureSize ( pk : pubkey ) : int = signatureSize pk
338+ let signerGetPublicKeyForKeyPair ( kp : keyPair ) : pubkey = getPublicKeyForKeyPair kp
330339
331340let signerSignStreamWithKeyPair stream keyBlob = signStream stream keyBlob
332341
@@ -345,37 +354,35 @@ type ILStrongNameSigner =
345354 static member OpenPublicKeyOptions kp p = PublicKeyOptionsSigner( kp, p)
346355
347356 static member OpenPublicKey bytes = PublicKeySigner bytes
348- static member OpenKeyPairFile bytes = KeyPair( bytes)
357+
358+ static member OpenKeyPairFile bytes = KeyPair bytes
359+
349360 static member OpenKeyContainer s = KeyContainer s
350361
351362 member s.IsFullySigned =
352363 match s with
353364 | PublicKeySigner _ -> false
354- | PublicKeyOptionsSigner pko ->
355- let _ , usePublicSign = pko
356- usePublicSign
365+ | PublicKeyOptionsSigner(_, usePublicSign) -> usePublicSign
357366 | KeyPair _ -> true
358367 | KeyContainer _ -> failWithContainerSigningUnsupportedOnThisPlatform ()
359368
360369 member s.PublicKey =
361370 match s with
362371 | PublicKeySigner pk -> pk
363- | PublicKeyOptionsSigner pko ->
364- let pk , _ = pko
365- pk
372+ | PublicKeyOptionsSigner( pk, _) -> pk
366373 | KeyPair kp -> signerGetPublicKeyForKeyPair kp
367374 | KeyContainer _ -> failWithContainerSigningUnsupportedOnThisPlatform ()
368375
369376 member s.SignatureSize =
370- let pkSignatureSize pk =
371- signerSignatureSize pk
372-
373377 match s with
374- | PublicKeySigner pk -> pkSignatureSize pk
375- | PublicKeyOptionsSigner pko ->
376- let pk , _ = pko
377- pkSignatureSize pk
378- | KeyPair kp -> pkSignatureSize ( signerGetPublicKeyForKeyPair kp)
378+ | PublicKeySigner pk -> signatureSize pk
379+
380+ | PublicKeyOptionsSigner( pk, _) -> signatureSize pk
381+
382+ | KeyPair kp ->
383+ let pubKey = signerGetPublicKeyForKeyPair kp
384+ signatureSize pubKey
385+
379386 | KeyContainer _ -> failWithContainerSigningUnsupportedOnThisPlatform ()
380387
381388 member s.SignStream stream =
0 commit comments