You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

597 rivejä
25 KiB

  1. /* Copyright (c) 2017, Google Inc.
  2. *
  3. * Permission to use, copy, modify, and/or distribute this software for any
  4. * purpose with or without fee is hereby granted, provided that the above
  5. * copyright notice and this permission notice appear in all copies.
  6. *
  7. * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
  8. * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
  9. * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
  10. * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
  11. * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
  12. * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
  13. * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
  14. #ifndef HEADER_SSL_TEST_FUZZER
  15. #define HEADER_SSL_TEST_FUZZER
  16. #include <assert.h>
  17. #include <stdlib.h>
  18. #include <string.h>
  19. #include <algorithm>
  20. #include <openssl/bio.h>
  21. #include <openssl/bytestring.h>
  22. #include <openssl/err.h>
  23. #include <openssl/evp.h>
  24. #include <openssl/rand.h>
  25. #include <openssl/rsa.h>
  26. #include <openssl/ssl.h>
  27. #include <openssl/x509.h>
  28. #include "../internal.h"
  29. #include "./fuzzer_tags.h"
  30. namespace {
  31. const uint8_t kP256KeyPKCS8[] = {
  32. 0x30, 0x81, 0x87, 0x02, 0x01, 0x00, 0x30, 0x13, 0x06, 0x07, 0x2a, 0x86,
  33. 0x48, 0xce, 0x3d, 0x02, 0x01, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d,
  34. 0x03, 0x01, 0x07, 0x04, 0x6d, 0x30, 0x6b, 0x02, 0x01, 0x01, 0x04, 0x20,
  35. 0x43, 0x09, 0xc0, 0x67, 0x75, 0x21, 0x47, 0x9d, 0xa8, 0xfa, 0x16, 0xdf,
  36. 0x15, 0x73, 0x61, 0x34, 0x68, 0x6f, 0xe3, 0x8e, 0x47, 0x91, 0x95, 0xab,
  37. 0x79, 0x4a, 0x72, 0x14, 0xcb, 0xe2, 0x49, 0x4f, 0xa1, 0x44, 0x03, 0x42,
  38. 0x00, 0x04, 0xde, 0x09, 0x08, 0x07, 0x03, 0x2e, 0x8f, 0x37, 0x9a, 0xd5,
  39. 0xad, 0xe5, 0xc6, 0x9d, 0xd4, 0x63, 0xc7, 0x4a, 0xe7, 0x20, 0xcb, 0x90,
  40. 0xa0, 0x1f, 0x18, 0x18, 0x72, 0xb5, 0x21, 0x88, 0x38, 0xc0, 0xdb, 0xba,
  41. 0xf6, 0x99, 0xd8, 0xa5, 0x3b, 0x83, 0xe9, 0xe3, 0xd5, 0x61, 0x99, 0x73,
  42. 0x42, 0xc6, 0x6c, 0xe8, 0x0a, 0x95, 0x40, 0x41, 0x3b, 0x0d, 0x10, 0xa7,
  43. 0x4a, 0x93, 0xdb, 0x5a, 0xe7, 0xec,
  44. };
  45. const uint8_t kOCSPResponse[] = {0x01, 0x02, 0x03, 0x04};
  46. const uint8_t kSCT[] = {0x00, 0x06, 0x00, 0x04, 0x05, 0x06, 0x07, 0x08};
  47. const uint8_t kCertificateDER[] = {
  48. 0x30, 0x82, 0x02, 0xff, 0x30, 0x82, 0x01, 0xe7, 0xa0, 0x03, 0x02, 0x01,
  49. 0x02, 0x02, 0x11, 0x00, 0xb1, 0x84, 0xee, 0x34, 0x99, 0x98, 0x76, 0xfb,
  50. 0x6f, 0xb2, 0x15, 0xc8, 0x47, 0x79, 0x05, 0x9b, 0x30, 0x0d, 0x06, 0x09,
  51. 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30,
  52. 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x0a, 0x13, 0x07,
  53. 0x41, 0x63, 0x6d, 0x65, 0x20, 0x43, 0x6f, 0x30, 0x1e, 0x17, 0x0d, 0x31,
  54. 0x35, 0x31, 0x31, 0x30, 0x37, 0x30, 0x30, 0x32, 0x34, 0x35, 0x36, 0x5a,
  55. 0x17, 0x0d, 0x31, 0x36, 0x31, 0x31, 0x30, 0x36, 0x30, 0x30, 0x32, 0x34,
  56. 0x35, 0x36, 0x5a, 0x30, 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55,
  57. 0x04, 0x0a, 0x13, 0x07, 0x41, 0x63, 0x6d, 0x65, 0x20, 0x43, 0x6f, 0x30,
  58. 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
  59. 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30,
  60. 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, 0xce, 0x47, 0xcb, 0x11,
  61. 0xbb, 0xd2, 0x9d, 0x8e, 0x9e, 0xd2, 0x1e, 0x14, 0xaf, 0xc7, 0xea, 0xb6,
  62. 0xc9, 0x38, 0x2a, 0x6f, 0xb3, 0x7e, 0xfb, 0xbc, 0xfc, 0x59, 0x42, 0xb9,
  63. 0x56, 0xf0, 0x4c, 0x3f, 0xf7, 0x31, 0x84, 0xbe, 0xac, 0x03, 0x9e, 0x71,
  64. 0x91, 0x85, 0xd8, 0x32, 0xbd, 0x00, 0xea, 0xac, 0x65, 0xf6, 0x03, 0xc8,
  65. 0x0f, 0x8b, 0xfd, 0x6e, 0x58, 0x88, 0x04, 0x41, 0x92, 0x74, 0xa6, 0x57,
  66. 0x2e, 0x8e, 0x88, 0xd5, 0x3d, 0xda, 0x14, 0x3e, 0x63, 0x88, 0x22, 0xe3,
  67. 0x53, 0xe9, 0xba, 0x39, 0x09, 0xac, 0xfb, 0xd0, 0x4c, 0xf2, 0x3c, 0x20,
  68. 0xd6, 0x97, 0xe6, 0xed, 0xf1, 0x62, 0x1e, 0xe5, 0xc9, 0x48, 0xa0, 0xca,
  69. 0x2e, 0x3c, 0x14, 0x5a, 0x82, 0xd4, 0xed, 0xb1, 0xe3, 0x43, 0xc1, 0x2a,
  70. 0x59, 0xa5, 0xb9, 0xc8, 0x48, 0xa7, 0x39, 0x23, 0x74, 0xa7, 0x37, 0xb0,
  71. 0x6f, 0xc3, 0x64, 0x99, 0x6c, 0xa2, 0x82, 0xc8, 0xf6, 0xdb, 0x86, 0x40,
  72. 0xce, 0xd1, 0x85, 0x9f, 0xce, 0x69, 0xf4, 0x15, 0x2a, 0x23, 0xca, 0xea,
  73. 0xb7, 0x7b, 0xdf, 0xfb, 0x43, 0x5f, 0xff, 0x7a, 0x49, 0x49, 0x0e, 0xe7,
  74. 0x02, 0x51, 0x45, 0x13, 0xe8, 0x90, 0x64, 0x21, 0x0c, 0x26, 0x2b, 0x5d,
  75. 0xfc, 0xe4, 0xb5, 0x86, 0x89, 0x43, 0x22, 0x4c, 0xf3, 0x3b, 0xf3, 0x09,
  76. 0xc4, 0xa4, 0x10, 0x80, 0xf2, 0x46, 0xe2, 0x46, 0x8f, 0x76, 0x50, 0xbf,
  77. 0xaf, 0x2b, 0x90, 0x1b, 0x78, 0xc7, 0xcf, 0xc1, 0x77, 0xd0, 0xfb, 0xa9,
  78. 0xfb, 0xc9, 0x66, 0x5a, 0xc5, 0x9b, 0x31, 0x41, 0x67, 0x01, 0xbe, 0x33,
  79. 0x10, 0xba, 0x05, 0x58, 0xed, 0x76, 0x53, 0xde, 0x5d, 0xc1, 0xe8, 0xbb,
  80. 0x9f, 0xf1, 0xcd, 0xfb, 0xdf, 0x64, 0x7f, 0xd7, 0x18, 0xab, 0x0f, 0x94,
  81. 0x28, 0x95, 0x4a, 0xcc, 0x6a, 0xa9, 0x50, 0xc7, 0x05, 0x47, 0x10, 0x41,
  82. 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x50, 0x30, 0x4e, 0x30, 0x0e, 0x06,
  83. 0x03, 0x55, 0x1d, 0x0f, 0x01, 0x01, 0xff, 0x04, 0x04, 0x03, 0x02, 0x05,
  84. 0xa0, 0x30, 0x13, 0x06, 0x03, 0x55, 0x1d, 0x25, 0x04, 0x0c, 0x30, 0x0a,
  85. 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05, 0x07, 0x03, 0x01, 0x30, 0x0c,
  86. 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x02, 0x30, 0x00,
  87. 0x30, 0x19, 0x06, 0x03, 0x55, 0x1d, 0x11, 0x04, 0x12, 0x30, 0x10, 0x82,
  88. 0x0e, 0x66, 0x75, 0x7a, 0x7a, 0x2e, 0x62, 0x6f, 0x72, 0x69, 0x6e, 0x67,
  89. 0x73, 0x73, 0x6c, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
  90. 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82, 0x01, 0x01, 0x00, 0x92,
  91. 0xde, 0xef, 0x96, 0x06, 0x7b, 0xff, 0x71, 0x7d, 0x4e, 0xa0, 0x7d, 0xae,
  92. 0xb8, 0x22, 0xb4, 0x2c, 0xf7, 0x96, 0x9c, 0x37, 0x1d, 0x8f, 0xe7, 0xd9,
  93. 0x47, 0xff, 0x3f, 0xe9, 0x35, 0x95, 0x0e, 0xdd, 0xdc, 0x7f, 0xc8, 0x8a,
  94. 0x1e, 0x36, 0x1d, 0x38, 0x47, 0xfc, 0x76, 0xd2, 0x1f, 0x98, 0xa1, 0x36,
  95. 0xac, 0xc8, 0x70, 0x38, 0x0a, 0x3d, 0x51, 0x8d, 0x0f, 0x03, 0x1b, 0xef,
  96. 0x62, 0xa1, 0xcb, 0x2b, 0x4a, 0x8c, 0x12, 0x2b, 0x54, 0x50, 0x9a, 0x6b,
  97. 0xfe, 0xaf, 0xd9, 0xf6, 0xbf, 0x58, 0x11, 0x58, 0x5e, 0xe5, 0x86, 0x1e,
  98. 0x3b, 0x6b, 0x30, 0x7e, 0x72, 0x89, 0xe8, 0x6b, 0x7b, 0xb7, 0xaf, 0xef,
  99. 0x8b, 0xa9, 0x3e, 0xb0, 0xcd, 0x0b, 0xef, 0xb0, 0x0c, 0x96, 0x2b, 0xc5,
  100. 0x3b, 0xd5, 0xf1, 0xc2, 0xae, 0x3a, 0x60, 0xd9, 0x0f, 0x75, 0x37, 0x55,
  101. 0x4d, 0x62, 0xd2, 0xed, 0x96, 0xac, 0x30, 0x6b, 0xda, 0xa1, 0x48, 0x17,
  102. 0x96, 0x23, 0x85, 0x9a, 0x57, 0x77, 0xe9, 0x22, 0xa2, 0x37, 0x03, 0xba,
  103. 0x49, 0x77, 0x40, 0x3b, 0x76, 0x4b, 0xda, 0xc1, 0x04, 0x57, 0x55, 0x34,
  104. 0x22, 0x83, 0x45, 0x29, 0xab, 0x2e, 0x11, 0xff, 0x0d, 0xab, 0x55, 0xb1,
  105. 0xa7, 0x58, 0x59, 0x05, 0x25, 0xf9, 0x1e, 0x3d, 0xb7, 0xac, 0x04, 0x39,
  106. 0x2c, 0xf9, 0xaf, 0xb8, 0x68, 0xfb, 0x8e, 0x35, 0x71, 0x32, 0xff, 0x70,
  107. 0xe9, 0x46, 0x6d, 0x5c, 0x06, 0x90, 0x88, 0x23, 0x48, 0x0c, 0x50, 0xeb,
  108. 0x0a, 0xa9, 0xae, 0xe8, 0xfc, 0xbe, 0xa5, 0x76, 0x94, 0xd7, 0x64, 0x22,
  109. 0x38, 0x98, 0x17, 0xa4, 0x3a, 0xa7, 0x59, 0x9f, 0x1d, 0x3b, 0x75, 0x90,
  110. 0x1a, 0x81, 0xef, 0x19, 0xfb, 0x2b, 0xb7, 0xa7, 0x64, 0x61, 0x22, 0xa4,
  111. 0x6f, 0x7b, 0xfa, 0x58, 0xbb, 0x8c, 0x4e, 0x77, 0x67, 0xd0, 0x5d, 0x58,
  112. 0x76, 0x8a, 0xbb,
  113. };
  114. const uint8_t kRSAPrivateKeyDER[] = {
  115. 0x30, 0x82, 0x04, 0xa5, 0x02, 0x01, 0x00, 0x02, 0x82, 0x01, 0x01, 0x00,
  116. 0xce, 0x47, 0xcb, 0x11, 0xbb, 0xd2, 0x9d, 0x8e, 0x9e, 0xd2, 0x1e, 0x14,
  117. 0xaf, 0xc7, 0xea, 0xb6, 0xc9, 0x38, 0x2a, 0x6f, 0xb3, 0x7e, 0xfb, 0xbc,
  118. 0xfc, 0x59, 0x42, 0xb9, 0x56, 0xf0, 0x4c, 0x3f, 0xf7, 0x31, 0x84, 0xbe,
  119. 0xac, 0x03, 0x9e, 0x71, 0x91, 0x85, 0xd8, 0x32, 0xbd, 0x00, 0xea, 0xac,
  120. 0x65, 0xf6, 0x03, 0xc8, 0x0f, 0x8b, 0xfd, 0x6e, 0x58, 0x88, 0x04, 0x41,
  121. 0x92, 0x74, 0xa6, 0x57, 0x2e, 0x8e, 0x88, 0xd5, 0x3d, 0xda, 0x14, 0x3e,
  122. 0x63, 0x88, 0x22, 0xe3, 0x53, 0xe9, 0xba, 0x39, 0x09, 0xac, 0xfb, 0xd0,
  123. 0x4c, 0xf2, 0x3c, 0x20, 0xd6, 0x97, 0xe6, 0xed, 0xf1, 0x62, 0x1e, 0xe5,
  124. 0xc9, 0x48, 0xa0, 0xca, 0x2e, 0x3c, 0x14, 0x5a, 0x82, 0xd4, 0xed, 0xb1,
  125. 0xe3, 0x43, 0xc1, 0x2a, 0x59, 0xa5, 0xb9, 0xc8, 0x48, 0xa7, 0x39, 0x23,
  126. 0x74, 0xa7, 0x37, 0xb0, 0x6f, 0xc3, 0x64, 0x99, 0x6c, 0xa2, 0x82, 0xc8,
  127. 0xf6, 0xdb, 0x86, 0x40, 0xce, 0xd1, 0x85, 0x9f, 0xce, 0x69, 0xf4, 0x15,
  128. 0x2a, 0x23, 0xca, 0xea, 0xb7, 0x7b, 0xdf, 0xfb, 0x43, 0x5f, 0xff, 0x7a,
  129. 0x49, 0x49, 0x0e, 0xe7, 0x02, 0x51, 0x45, 0x13, 0xe8, 0x90, 0x64, 0x21,
  130. 0x0c, 0x26, 0x2b, 0x5d, 0xfc, 0xe4, 0xb5, 0x86, 0x89, 0x43, 0x22, 0x4c,
  131. 0xf3, 0x3b, 0xf3, 0x09, 0xc4, 0xa4, 0x10, 0x80, 0xf2, 0x46, 0xe2, 0x46,
  132. 0x8f, 0x76, 0x50, 0xbf, 0xaf, 0x2b, 0x90, 0x1b, 0x78, 0xc7, 0xcf, 0xc1,
  133. 0x77, 0xd0, 0xfb, 0xa9, 0xfb, 0xc9, 0x66, 0x5a, 0xc5, 0x9b, 0x31, 0x41,
  134. 0x67, 0x01, 0xbe, 0x33, 0x10, 0xba, 0x05, 0x58, 0xed, 0x76, 0x53, 0xde,
  135. 0x5d, 0xc1, 0xe8, 0xbb, 0x9f, 0xf1, 0xcd, 0xfb, 0xdf, 0x64, 0x7f, 0xd7,
  136. 0x18, 0xab, 0x0f, 0x94, 0x28, 0x95, 0x4a, 0xcc, 0x6a, 0xa9, 0x50, 0xc7,
  137. 0x05, 0x47, 0x10, 0x41, 0x02, 0x03, 0x01, 0x00, 0x01, 0x02, 0x82, 0x01,
  138. 0x01, 0x00, 0xa8, 0x47, 0xb9, 0x4a, 0x06, 0x47, 0x93, 0x71, 0x3d, 0xef,
  139. 0x7b, 0xca, 0xb4, 0x7c, 0x0a, 0xe6, 0x82, 0xd0, 0xe7, 0x0d, 0xa9, 0x08,
  140. 0xf6, 0xa4, 0xfd, 0xd8, 0x73, 0xae, 0x6f, 0x56, 0x29, 0x5e, 0x25, 0x72,
  141. 0xa8, 0x30, 0x44, 0x73, 0xcf, 0x56, 0x26, 0xb9, 0x61, 0xde, 0x42, 0x81,
  142. 0xf4, 0xf0, 0x1f, 0x5d, 0xcb, 0x47, 0xf2, 0x26, 0xe9, 0xe0, 0x93, 0x28,
  143. 0xa3, 0x10, 0x3b, 0x42, 0x1e, 0x51, 0x11, 0x12, 0x06, 0x5e, 0xaf, 0xce,
  144. 0xb0, 0xa5, 0x14, 0xdd, 0x82, 0x58, 0xa1, 0xa4, 0x12, 0xdf, 0x65, 0x1d,
  145. 0x51, 0x70, 0x64, 0xd5, 0x58, 0x68, 0x11, 0xa8, 0x6a, 0x23, 0xc2, 0xbf,
  146. 0xa1, 0x25, 0x24, 0x47, 0xb3, 0xa4, 0x3c, 0x83, 0x96, 0xb7, 0x1f, 0xf4,
  147. 0x44, 0xd4, 0xd1, 0xe9, 0xfc, 0x33, 0x68, 0x5e, 0xe2, 0x68, 0x99, 0x9c,
  148. 0x91, 0xe8, 0x72, 0xc9, 0xd7, 0x8c, 0x80, 0x20, 0x8e, 0x77, 0x83, 0x4d,
  149. 0xe4, 0xab, 0xf9, 0x74, 0xa1, 0xdf, 0xd3, 0xc0, 0x0d, 0x5b, 0x05, 0x51,
  150. 0xc2, 0x6f, 0xb2, 0x91, 0x02, 0xec, 0xc0, 0x02, 0x1a, 0x5c, 0x91, 0x05,
  151. 0xf1, 0xe3, 0xfa, 0x65, 0xc2, 0xad, 0x24, 0xe6, 0xe5, 0x3c, 0xb6, 0x16,
  152. 0xf1, 0xa1, 0x67, 0x1a, 0x9d, 0x37, 0x56, 0xbf, 0x01, 0xd7, 0x3b, 0x35,
  153. 0x30, 0x57, 0x73, 0xf4, 0xf0, 0x5e, 0xa7, 0xe8, 0x0a, 0xc1, 0x94, 0x17,
  154. 0xcf, 0x0a, 0xbd, 0xf5, 0x31, 0xa7, 0x2d, 0xf7, 0xf5, 0xd9, 0x8c, 0xc2,
  155. 0x01, 0xbd, 0xda, 0x16, 0x8e, 0xb9, 0x30, 0x40, 0xa6, 0x6e, 0xbd, 0xcd,
  156. 0x4d, 0x84, 0x67, 0x4e, 0x0b, 0xce, 0xd5, 0xef, 0xf8, 0x08, 0x63, 0x02,
  157. 0xc6, 0xc7, 0xf7, 0x67, 0x92, 0xe2, 0x23, 0x9d, 0x27, 0x22, 0x1d, 0xc6,
  158. 0x67, 0x5e, 0x66, 0xbf, 0x03, 0xb8, 0xa9, 0x67, 0xd4, 0x39, 0xd8, 0x75,
  159. 0xfa, 0xe8, 0xed, 0x56, 0xb8, 0x81, 0x02, 0x81, 0x81, 0x00, 0xf7, 0x46,
  160. 0x68, 0xc6, 0x13, 0xf8, 0xba, 0x0f, 0x83, 0xdb, 0x05, 0xa8, 0x25, 0x00,
  161. 0x70, 0x9c, 0x9e, 0x8b, 0x12, 0x34, 0x0d, 0x96, 0xcf, 0x0d, 0x98, 0x9b,
  162. 0x8d, 0x9c, 0x96, 0x78, 0xd1, 0x3c, 0x01, 0x8c, 0xb9, 0x35, 0x5c, 0x20,
  163. 0x42, 0xb4, 0x38, 0xe3, 0xd6, 0x54, 0xe7, 0x55, 0xd6, 0x26, 0x8a, 0x0c,
  164. 0xf6, 0x1f, 0xe0, 0x04, 0xc1, 0x22, 0x42, 0x19, 0x61, 0xc4, 0x94, 0x7c,
  165. 0x07, 0x2e, 0x80, 0x52, 0xfe, 0x8d, 0xe6, 0x92, 0x3a, 0x91, 0xfe, 0x72,
  166. 0x99, 0xe1, 0x2a, 0x73, 0x76, 0xb1, 0x24, 0x20, 0x67, 0xde, 0x28, 0xcb,
  167. 0x0e, 0xe6, 0x52, 0xb5, 0xfa, 0xfb, 0x8b, 0x1e, 0x6a, 0x1d, 0x09, 0x26,
  168. 0xb9, 0xa7, 0x61, 0xba, 0xf8, 0x79, 0xd2, 0x66, 0x57, 0x28, 0xd7, 0x31,
  169. 0xb5, 0x0b, 0x27, 0x19, 0x1e, 0x6f, 0x46, 0xfc, 0x54, 0x95, 0xeb, 0x78,
  170. 0x01, 0xb6, 0xd9, 0x79, 0x5a, 0x4d, 0x02, 0x81, 0x81, 0x00, 0xd5, 0x8f,
  171. 0x16, 0x53, 0x2f, 0x57, 0x93, 0xbf, 0x09, 0x75, 0xbf, 0x63, 0x40, 0x3d,
  172. 0x27, 0xfd, 0x23, 0x21, 0xde, 0x9b, 0xe9, 0x73, 0x3f, 0x49, 0x02, 0xd2,
  173. 0x38, 0x96, 0xcf, 0xc3, 0xba, 0x92, 0x07, 0x87, 0x52, 0xa9, 0x35, 0xe3,
  174. 0x0c, 0xe4, 0x2f, 0x05, 0x7b, 0x37, 0xa5, 0x40, 0x9c, 0x3b, 0x94, 0xf7,
  175. 0xad, 0xa0, 0xee, 0x3a, 0xa8, 0xfb, 0x1f, 0x11, 0x1f, 0xd8, 0x9a, 0x80,
  176. 0x42, 0x3d, 0x7f, 0xa4, 0xb8, 0x9a, 0xaa, 0xea, 0x72, 0xc1, 0xe3, 0xed,
  177. 0x06, 0x60, 0x92, 0x37, 0xf9, 0xba, 0xfb, 0x9e, 0xed, 0x05, 0xa6, 0xd4,
  178. 0x72, 0x68, 0x4f, 0x63, 0xfe, 0xd6, 0x10, 0x0d, 0x4f, 0x0a, 0x93, 0xc6,
  179. 0xb9, 0xd7, 0xaf, 0xfd, 0xd9, 0x57, 0x7d, 0xcb, 0x75, 0xe8, 0x93, 0x2b,
  180. 0xae, 0x4f, 0xea, 0xd7, 0x30, 0x0b, 0x58, 0x44, 0x82, 0x0f, 0x84, 0x5d,
  181. 0x62, 0x11, 0x78, 0xea, 0x5f, 0xc5, 0x02, 0x81, 0x81, 0x00, 0x82, 0x0c,
  182. 0xc1, 0xe6, 0x0b, 0x72, 0xf1, 0x48, 0x5f, 0xac, 0xbd, 0x98, 0xe5, 0x7d,
  183. 0x09, 0xbd, 0x15, 0x95, 0x47, 0x09, 0xa1, 0x6c, 0x03, 0x91, 0xbf, 0x05,
  184. 0x70, 0xc1, 0x3e, 0x52, 0x64, 0x99, 0x0e, 0xa7, 0x98, 0x70, 0xfb, 0xf6,
  185. 0xeb, 0x9e, 0x25, 0x9d, 0x8e, 0x88, 0x30, 0xf2, 0xf0, 0x22, 0x6c, 0xd0,
  186. 0xcc, 0x51, 0x8f, 0x5c, 0x70, 0xc7, 0x37, 0xc4, 0x69, 0xab, 0x1d, 0xfc,
  187. 0xed, 0x3a, 0x03, 0xbb, 0xa2, 0xad, 0xb6, 0xea, 0x89, 0x6b, 0x67, 0x4b,
  188. 0x96, 0xaa, 0xd9, 0xcc, 0xc8, 0x4b, 0xfa, 0x18, 0x21, 0x08, 0xb2, 0xa3,
  189. 0xb9, 0x3e, 0x61, 0x99, 0xdc, 0x5a, 0x97, 0x9c, 0x73, 0x6a, 0xb9, 0xf9,
  190. 0x68, 0x03, 0x24, 0x5f, 0x55, 0x77, 0x9c, 0xb4, 0xbe, 0x7a, 0x78, 0x53,
  191. 0x68, 0x48, 0x69, 0x53, 0xc8, 0xb1, 0xf5, 0xbf, 0x98, 0x2d, 0x11, 0x1e,
  192. 0x98, 0xa8, 0x36, 0x50, 0xa0, 0xb1, 0x02, 0x81, 0x81, 0x00, 0x90, 0x88,
  193. 0x30, 0x71, 0xc7, 0xfe, 0x9b, 0x6d, 0x95, 0x37, 0x6d, 0x79, 0xfc, 0x85,
  194. 0xe7, 0x44, 0x78, 0xbc, 0x79, 0x6e, 0x47, 0x86, 0xc9, 0xf3, 0xdd, 0xc6,
  195. 0xec, 0xa9, 0x94, 0x9f, 0x40, 0xeb, 0x87, 0xd0, 0xdb, 0xee, 0xcd, 0x1b,
  196. 0x87, 0x23, 0xff, 0x76, 0xd4, 0x37, 0x8a, 0xcd, 0xb9, 0x6e, 0xd1, 0x98,
  197. 0xf6, 0x97, 0x8d, 0xe3, 0x81, 0x6d, 0xc3, 0x4e, 0xd1, 0xa0, 0xc4, 0x9f,
  198. 0xbd, 0x34, 0xe5, 0xe8, 0x53, 0x4f, 0xca, 0x10, 0xb5, 0xed, 0xe7, 0x16,
  199. 0x09, 0x54, 0xde, 0x60, 0xa7, 0xd1, 0x16, 0x6e, 0x2e, 0xb7, 0xbe, 0x7a,
  200. 0xd5, 0x9b, 0x26, 0xef, 0xe4, 0x0e, 0x77, 0xfa, 0xa9, 0xdd, 0xdc, 0xb9,
  201. 0x88, 0x19, 0x23, 0x70, 0xc7, 0xe1, 0x60, 0xaf, 0x8c, 0x73, 0x04, 0xf7,
  202. 0x71, 0x17, 0x81, 0x36, 0x75, 0xbb, 0x97, 0xd7, 0x75, 0xb6, 0x8e, 0xbc,
  203. 0xac, 0x9c, 0x6a, 0x9b, 0x24, 0x89, 0x02, 0x81, 0x80, 0x5a, 0x2b, 0xc7,
  204. 0x6b, 0x8c, 0x65, 0xdb, 0x04, 0x73, 0xab, 0x25, 0xe1, 0x5b, 0xbc, 0x3c,
  205. 0xcf, 0x5a, 0x3c, 0x04, 0xae, 0x97, 0x2e, 0xfd, 0xa4, 0x97, 0x1f, 0x05,
  206. 0x17, 0x27, 0xac, 0x7c, 0x30, 0x85, 0xb4, 0x82, 0x3f, 0x5b, 0xb7, 0x94,
  207. 0x3b, 0x7f, 0x6c, 0x0c, 0xc7, 0x16, 0xc6, 0xa0, 0xbd, 0x80, 0xb0, 0x81,
  208. 0xde, 0xa0, 0x23, 0xa6, 0xf6, 0x75, 0x33, 0x51, 0x35, 0xa2, 0x75, 0x55,
  209. 0x70, 0x4d, 0x42, 0xbb, 0xcf, 0x54, 0xe4, 0xdb, 0x2d, 0x88, 0xa0, 0x7a,
  210. 0xf2, 0x17, 0xa7, 0xdd, 0x13, 0x44, 0x9f, 0x5f, 0x6b, 0x2c, 0x42, 0x42,
  211. 0x8b, 0x13, 0x4d, 0xf9, 0x5b, 0xf8, 0x33, 0x42, 0xd9, 0x9e, 0x50, 0x1c,
  212. 0x7c, 0xbc, 0xfa, 0x62, 0x85, 0x0b, 0xcf, 0x99, 0xda, 0x9e, 0x04, 0x90,
  213. 0xb2, 0xc6, 0xb2, 0x0a, 0x2a, 0x7c, 0x6d, 0x6a, 0x40, 0xfc, 0xf5, 0x50,
  214. 0x98, 0x46, 0x89, 0x82, 0x40,
  215. };
  216. const uint8_t kALPNProtocols[] = {
  217. 0x01, 'a', 0x02, 'a', 'a', 0x03, 'a', 'a', 'a',
  218. };
  219. int ALPNSelectCallback(SSL *ssl, const uint8_t **out, uint8_t *out_len,
  220. const uint8_t *in, unsigned in_len, void *arg) {
  221. static const uint8_t kProtocol[] = {'a', 'a'};
  222. *out = kProtocol;
  223. *out_len = sizeof(kProtocol);
  224. return SSL_TLSEXT_ERR_OK;
  225. }
  226. int NPNSelectCallback(SSL *ssl, uint8_t **out, uint8_t *out_len,
  227. const uint8_t *in, unsigned in_len, void *arg) {
  228. static const uint8_t kProtocol[] = {'a', 'a'};
  229. *out = const_cast<uint8_t *>(kProtocol);
  230. *out_len = sizeof(kProtocol);
  231. return SSL_TLSEXT_ERR_OK;
  232. }
  233. int NPNAdvertiseCallback(SSL *ssl, const uint8_t **out, unsigned *out_len,
  234. void *arg) {
  235. static const uint8_t kProtocols[] = {
  236. 0x01, 'a', 0x02, 'a', 'a', 0x03, 'a', 'a', 'a',
  237. };
  238. *out = kProtocols;
  239. *out_len = sizeof(kProtocols);
  240. return SSL_TLSEXT_ERR_OK;
  241. }
  242. class TLSFuzzer {
  243. public:
  244. enum Protocol {
  245. kTLS,
  246. kDTLS,
  247. };
  248. enum Role {
  249. kClient,
  250. kServer,
  251. };
  252. TLSFuzzer(Protocol protocol, Role role)
  253. : debug_(getenv("BORINGSSL_FUZZER_DEBUG") != nullptr),
  254. protocol_(protocol),
  255. role_(role) {
  256. if (!Init()) {
  257. abort();
  258. }
  259. }
  260. static void MoveBIOs(SSL *dest, SSL *src) {
  261. BIO *rbio = SSL_get_rbio(src);
  262. BIO_up_ref(rbio);
  263. SSL_set0_rbio(dest, rbio);
  264. BIO *wbio = SSL_get_wbio(src);
  265. BIO_up_ref(wbio);
  266. SSL_set0_wbio(dest, wbio);
  267. SSL_set0_rbio(src, nullptr);
  268. SSL_set0_wbio(src, nullptr);
  269. }
  270. int TestOneInput(const uint8_t *buf, size_t len) {
  271. RAND_reset_for_fuzzing();
  272. CBS cbs;
  273. CBS_init(&cbs, buf, len);
  274. bssl::UniquePtr<SSL> ssl = SetupTest(&cbs);
  275. if (!ssl) {
  276. if (debug_) {
  277. fprintf(stderr, "Error parsing parameters.\n");
  278. }
  279. return 0;
  280. }
  281. if (role_ == kClient) {
  282. SSL_set_renegotiate_mode(ssl.get(), ssl_renegotiate_freely);
  283. SSL_set_tlsext_host_name(ssl.get(), "hostname");
  284. }
  285. // ssl_handoff may or may not be used.
  286. bssl::UniquePtr<SSL> ssl_handoff(SSL_new(ctx_.get()));
  287. bssl::UniquePtr<SSL> ssl_handback(SSL_new(ctx_.get()));
  288. SSL_set_accept_state(ssl_handoff.get());
  289. SSL_set0_rbio(ssl.get(), MakeBIO(CBS_data(&cbs), CBS_len(&cbs)).release());
  290. SSL_set0_wbio(ssl.get(), BIO_new(BIO_s_mem()));
  291. SSL *ssl_handshake = ssl.get();
  292. bool handshake_successful = false;
  293. bool handback_successful = false;
  294. for (;;) {
  295. int ret = SSL_do_handshake(ssl_handshake);
  296. if (ret < 0 && SSL_get_error(ssl_handshake, ret) == SSL_ERROR_HANDOFF) {
  297. MoveBIOs(ssl_handoff.get(), ssl.get());
  298. // Ordinarily we would call SSL_serialize_handoff(ssl.get(). But for
  299. // fuzzing, use the serialized handoff that's getting fuzzed.
  300. if (!SSL_apply_handoff(ssl_handoff.get(), handoff_)) {
  301. if (debug_) {
  302. fprintf(stderr, "Handoff failed.\n");
  303. }
  304. break;
  305. }
  306. ssl_handshake = ssl_handoff.get();
  307. } else if (ret < 0 &&
  308. SSL_get_error(ssl_handshake, ret) == SSL_ERROR_HANDBACK) {
  309. MoveBIOs(ssl_handback.get(), ssl_handoff.get());
  310. if (!SSL_apply_handback(ssl_handback.get(), handback_)) {
  311. if (debug_) {
  312. fprintf(stderr, "Handback failed.\n");
  313. }
  314. break;
  315. }
  316. handback_successful = true;
  317. ssl_handshake = ssl_handback.get();
  318. } else {
  319. handshake_successful = ret == 1;
  320. break;
  321. }
  322. }
  323. if (debug_) {
  324. if (!handshake_successful) {
  325. fprintf(stderr, "Handshake failed.\n");
  326. } else if (handback_successful) {
  327. fprintf(stderr, "Handback successful.\n");
  328. }
  329. }
  330. if (handshake_successful) {
  331. // Keep reading application data until error or EOF.
  332. uint8_t tmp[1024];
  333. for (;;) {
  334. if (SSL_read(ssl_handshake, tmp, sizeof(tmp)) <= 0) {
  335. break;
  336. }
  337. }
  338. }
  339. if (debug_) {
  340. ERR_print_errors_fp(stderr);
  341. }
  342. ERR_clear_error();
  343. return 0;
  344. }
  345. private:
  346. // Init initializes |ctx_| with settings common to all inputs.
  347. bool Init() {
  348. ctx_.reset(SSL_CTX_new(protocol_ == kDTLS ? DTLS_method() : TLS_method()));
  349. bssl::UniquePtr<EVP_PKEY> pkey(EVP_PKEY_new());
  350. bssl::UniquePtr<RSA> privkey(RSA_private_key_from_bytes(
  351. kRSAPrivateKeyDER, sizeof(kRSAPrivateKeyDER)));
  352. if (!ctx_ || !privkey || !pkey ||
  353. !EVP_PKEY_set1_RSA(pkey.get(), privkey.get()) ||
  354. !SSL_CTX_use_PrivateKey(ctx_.get(), pkey.get())) {
  355. return false;
  356. }
  357. const uint8_t *bufp = kCertificateDER;
  358. bssl::UniquePtr<X509> cert(d2i_X509(NULL, &bufp, sizeof(kCertificateDER)));
  359. if (!cert ||
  360. !SSL_CTX_use_certificate(ctx_.get(), cert.get()) ||
  361. !SSL_CTX_set_ocsp_response(ctx_.get(), kOCSPResponse,
  362. sizeof(kOCSPResponse)) ||
  363. !SSL_CTX_set_signed_cert_timestamp_list(ctx_.get(), kSCT,
  364. sizeof(kSCT))) {
  365. return false;
  366. }
  367. // When accepting peer certificates, allow any certificate.
  368. SSL_CTX_set_cert_verify_callback(
  369. ctx_.get(),
  370. [](X509_STORE_CTX *store_ctx, void *arg) -> int { return 1; }, nullptr);
  371. SSL_CTX_enable_signed_cert_timestamps(ctx_.get());
  372. SSL_CTX_enable_ocsp_stapling(ctx_.get());
  373. // Enable versions and ciphers that are off by default.
  374. if (!SSL_CTX_set_strict_cipher_list(ctx_.get(), "ALL:NULL-SHA")) {
  375. return false;
  376. }
  377. if (protocol_ == kTLS &&
  378. !SSL_CTX_set_max_proto_version(ctx_.get(), TLS1_3_VERSION)) {
  379. return false;
  380. }
  381. SSL_CTX_set_early_data_enabled(ctx_.get(), 1);
  382. SSL_CTX_set_next_proto_select_cb(ctx_.get(), NPNSelectCallback, nullptr);
  383. SSL_CTX_set_next_protos_advertised_cb(ctx_.get(), NPNAdvertiseCallback,
  384. nullptr);
  385. SSL_CTX_set_alpn_select_cb(ctx_.get(), ALPNSelectCallback, nullptr);
  386. if (SSL_CTX_set_alpn_protos(ctx_.get(), kALPNProtocols,
  387. sizeof(kALPNProtocols)) != 0) {
  388. return false;
  389. }
  390. CBS cbs;
  391. CBS_init(&cbs, kP256KeyPKCS8, sizeof(kP256KeyPKCS8));
  392. pkey.reset(EVP_parse_private_key(&cbs));
  393. if (!pkey || !SSL_CTX_set1_tls_channel_id(ctx_.get(), pkey.get())) {
  394. return false;
  395. }
  396. SSL_CTX_set_tls_channel_id_enabled(ctx_.get(), 1);
  397. return true;
  398. }
  399. // SetupTest parses parameters from |cbs| and returns a newly-configured |SSL|
  400. // object or nullptr on error. On success, the caller should feed the
  401. // remaining input in |cbs| to the SSL stack.
  402. bssl::UniquePtr<SSL> SetupTest(CBS *cbs) {
  403. // |ctx| is shared between runs, so we must clear any modifications to it
  404. // made later on in this function.
  405. SSL_CTX_flush_sessions(ctx_.get(), 0);
  406. handoff_ = {};
  407. handback_ = {};
  408. bssl::UniquePtr<SSL> ssl(SSL_new(ctx_.get()));
  409. if (role_ == kServer) {
  410. SSL_set_accept_state(ssl.get());
  411. } else {
  412. SSL_set_connect_state(ssl.get());
  413. }
  414. for (;;) {
  415. uint16_t tag;
  416. if (!CBS_get_u16(cbs, &tag)) {
  417. return nullptr;
  418. }
  419. switch (tag) {
  420. case kDataTag:
  421. return ssl;
  422. case kSessionTag: {
  423. CBS data;
  424. if (!CBS_get_u24_length_prefixed(cbs, &data)) {
  425. return nullptr;
  426. }
  427. bssl::UniquePtr<SSL_SESSION> session(SSL_SESSION_from_bytes(
  428. CBS_data(&data), CBS_len(&data), ctx_.get()));
  429. if (!session) {
  430. return nullptr;
  431. }
  432. if (role_ == kServer) {
  433. SSL_CTX_add_session(ctx_.get(), session.get());
  434. } else {
  435. SSL_set_session(ssl.get(), session.get());
  436. }
  437. break;
  438. }
  439. case kRequestClientCert:
  440. if (role_ == kClient) {
  441. return nullptr;
  442. }
  443. SSL_set_verify(ssl.get(), SSL_VERIFY_PEER, nullptr);
  444. break;
  445. case kTLS13Variant: {
  446. uint8_t variant;
  447. if (!CBS_get_u8(cbs, &variant)) {
  448. return nullptr;
  449. }
  450. SSL_set_tls13_variant(ssl.get(),
  451. static_cast<tls13_variant_t>(variant));
  452. break;
  453. }
  454. case kHandoffTag: {
  455. CBS handoff;
  456. if (!CBS_get_u24_length_prefixed(cbs, &handoff)) {
  457. return nullptr;
  458. }
  459. handoff_.CopyFrom(handoff);
  460. bssl::SSL_set_handoff_mode(ssl.get(), 1);
  461. break;
  462. }
  463. case kHandbackTag: {
  464. CBS handback;
  465. if (!CBS_get_u24_length_prefixed(cbs, &handback)) {
  466. return nullptr;
  467. }
  468. handback_.CopyFrom(handback);
  469. bssl::SSL_set_handoff_mode(ssl.get(), 1);
  470. break;
  471. }
  472. default:
  473. return nullptr;
  474. }
  475. }
  476. }
  477. struct BIOData {
  478. Protocol protocol;
  479. CBS cbs;
  480. };
  481. bssl::UniquePtr<BIO> MakeBIO(const uint8_t *in, size_t len) {
  482. BIOData *b = new BIOData;
  483. b->protocol = protocol_;
  484. CBS_init(&b->cbs, in, len);
  485. bssl::UniquePtr<BIO> bio(BIO_new(&kBIOMethod));
  486. bio->init = 1;
  487. bio->ptr = b;
  488. return bio;
  489. }
  490. static int BIORead(BIO *bio, char *out, int len) {
  491. assert(bio->method == &kBIOMethod);
  492. BIOData *b = reinterpret_cast<BIOData *>(bio->ptr);
  493. if (b->protocol == kTLS) {
  494. len = std::min(static_cast<size_t>(len), CBS_len(&b->cbs));
  495. memcpy(out, CBS_data(&b->cbs), len);
  496. CBS_skip(&b->cbs, len);
  497. return len;
  498. }
  499. // Preserve packet boundaries for DTLS.
  500. CBS packet;
  501. if (!CBS_get_u24_length_prefixed(&b->cbs, &packet)) {
  502. return -1;
  503. }
  504. len = std::min(static_cast<size_t>(len), CBS_len(&packet));
  505. memcpy(out, CBS_data(&packet), len);
  506. return len;
  507. }
  508. static int BIODestroy(BIO *bio) {
  509. assert(bio->method == &kBIOMethod);
  510. BIOData *b = reinterpret_cast<BIOData *>(bio->ptr);
  511. delete b;
  512. return 1;
  513. }
  514. static const BIO_METHOD kBIOMethod;
  515. bool debug_;
  516. Protocol protocol_;
  517. Role role_;
  518. bssl::UniquePtr<SSL_CTX> ctx_;
  519. bssl::Array<uint8_t> handoff_, handback_;
  520. };
  521. const BIO_METHOD TLSFuzzer::kBIOMethod = {
  522. 0, // type
  523. nullptr, // name
  524. nullptr, // bwrite
  525. TLSFuzzer::BIORead,
  526. nullptr, // bputs
  527. nullptr, // bgets
  528. nullptr, // ctrl
  529. nullptr, // create
  530. TLSFuzzer::BIODestroy,
  531. nullptr, // callback_ctrl
  532. };
  533. } // namespace
  534. #endif // HEADER_SSL_TEST_FUZZER