fuzzer.h 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593
  1. /* Copyright (c) 2017, Google Inc.
  2. *
  3. * Permission to use, copy, modify, and/or distribute this software for any
  4. * purpose with or without fee is hereby granted, provided that the above
  5. * copyright notice and this permission notice appear in all copies.
  6. *
  7. * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
  8. * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
  9. * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
  10. * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
  11. * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
  12. * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
  13. * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
  14. #ifndef HEADER_SSL_TEST_FUZZER
  15. #define HEADER_SSL_TEST_FUZZER
  16. #include <assert.h>
  17. #include <stdlib.h>
  18. #include <string.h>
  19. #include <algorithm>
  20. #include <openssl/bio.h>
  21. #include <openssl/bytestring.h>
  22. #include <openssl/err.h>
  23. #include <openssl/evp.h>
  24. #include <openssl/rand.h>
  25. #include <openssl/rsa.h>
  26. #include <openssl/ssl.h>
  27. #include <openssl/x509.h>
  28. #include "../internal.h"
  29. #include "./fuzzer_tags.h"
  30. namespace {
  31. const uint8_t kP256KeyPKCS8[] = {
  32. 0x30, 0x81, 0x87, 0x02, 0x01, 0x00, 0x30, 0x13, 0x06, 0x07, 0x2a, 0x86,
  33. 0x48, 0xce, 0x3d, 0x02, 0x01, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d,
  34. 0x03, 0x01, 0x07, 0x04, 0x6d, 0x30, 0x6b, 0x02, 0x01, 0x01, 0x04, 0x20,
  35. 0x43, 0x09, 0xc0, 0x67, 0x75, 0x21, 0x47, 0x9d, 0xa8, 0xfa, 0x16, 0xdf,
  36. 0x15, 0x73, 0x61, 0x34, 0x68, 0x6f, 0xe3, 0x8e, 0x47, 0x91, 0x95, 0xab,
  37. 0x79, 0x4a, 0x72, 0x14, 0xcb, 0xe2, 0x49, 0x4f, 0xa1, 0x44, 0x03, 0x42,
  38. 0x00, 0x04, 0xde, 0x09, 0x08, 0x07, 0x03, 0x2e, 0x8f, 0x37, 0x9a, 0xd5,
  39. 0xad, 0xe5, 0xc6, 0x9d, 0xd4, 0x63, 0xc7, 0x4a, 0xe7, 0x20, 0xcb, 0x90,
  40. 0xa0, 0x1f, 0x18, 0x18, 0x72, 0xb5, 0x21, 0x88, 0x38, 0xc0, 0xdb, 0xba,
  41. 0xf6, 0x99, 0xd8, 0xa5, 0x3b, 0x83, 0xe9, 0xe3, 0xd5, 0x61, 0x99, 0x73,
  42. 0x42, 0xc6, 0x6c, 0xe8, 0x0a, 0x95, 0x40, 0x41, 0x3b, 0x0d, 0x10, 0xa7,
  43. 0x4a, 0x93, 0xdb, 0x5a, 0xe7, 0xec,
  44. };
  45. const uint8_t kOCSPResponse[] = {0x01, 0x02, 0x03, 0x04};
  46. const uint8_t kSCT[] = {0x00, 0x06, 0x00, 0x04, 0x05, 0x06, 0x07, 0x08};
  47. const uint8_t kCertificateDER[] = {
  48. 0x30, 0x82, 0x02, 0xff, 0x30, 0x82, 0x01, 0xe7, 0xa0, 0x03, 0x02, 0x01,
  49. 0x02, 0x02, 0x11, 0x00, 0xb1, 0x84, 0xee, 0x34, 0x99, 0x98, 0x76, 0xfb,
  50. 0x6f, 0xb2, 0x15, 0xc8, 0x47, 0x79, 0x05, 0x9b, 0x30, 0x0d, 0x06, 0x09,
  51. 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30,
  52. 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x0a, 0x13, 0x07,
  53. 0x41, 0x63, 0x6d, 0x65, 0x20, 0x43, 0x6f, 0x30, 0x1e, 0x17, 0x0d, 0x31,
  54. 0x35, 0x31, 0x31, 0x30, 0x37, 0x30, 0x30, 0x32, 0x34, 0x35, 0x36, 0x5a,
  55. 0x17, 0x0d, 0x31, 0x36, 0x31, 0x31, 0x30, 0x36, 0x30, 0x30, 0x32, 0x34,
  56. 0x35, 0x36, 0x5a, 0x30, 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55,
  57. 0x04, 0x0a, 0x13, 0x07, 0x41, 0x63, 0x6d, 0x65, 0x20, 0x43, 0x6f, 0x30,
  58. 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
  59. 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30,
  60. 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, 0xce, 0x47, 0xcb, 0x11,
  61. 0xbb, 0xd2, 0x9d, 0x8e, 0x9e, 0xd2, 0x1e, 0x14, 0xaf, 0xc7, 0xea, 0xb6,
  62. 0xc9, 0x38, 0x2a, 0x6f, 0xb3, 0x7e, 0xfb, 0xbc, 0xfc, 0x59, 0x42, 0xb9,
  63. 0x56, 0xf0, 0x4c, 0x3f, 0xf7, 0x31, 0x84, 0xbe, 0xac, 0x03, 0x9e, 0x71,
  64. 0x91, 0x85, 0xd8, 0x32, 0xbd, 0x00, 0xea, 0xac, 0x65, 0xf6, 0x03, 0xc8,
  65. 0x0f, 0x8b, 0xfd, 0x6e, 0x58, 0x88, 0x04, 0x41, 0x92, 0x74, 0xa6, 0x57,
  66. 0x2e, 0x8e, 0x88, 0xd5, 0x3d, 0xda, 0x14, 0x3e, 0x63, 0x88, 0x22, 0xe3,
  67. 0x53, 0xe9, 0xba, 0x39, 0x09, 0xac, 0xfb, 0xd0, 0x4c, 0xf2, 0x3c, 0x20,
  68. 0xd6, 0x97, 0xe6, 0xed, 0xf1, 0x62, 0x1e, 0xe5, 0xc9, 0x48, 0xa0, 0xca,
  69. 0x2e, 0x3c, 0x14, 0x5a, 0x82, 0xd4, 0xed, 0xb1, 0xe3, 0x43, 0xc1, 0x2a,
  70. 0x59, 0xa5, 0xb9, 0xc8, 0x48, 0xa7, 0x39, 0x23, 0x74, 0xa7, 0x37, 0xb0,
  71. 0x6f, 0xc3, 0x64, 0x99, 0x6c, 0xa2, 0x82, 0xc8, 0xf6, 0xdb, 0x86, 0x40,
  72. 0xce, 0xd1, 0x85, 0x9f, 0xce, 0x69, 0xf4, 0x15, 0x2a, 0x23, 0xca, 0xea,
  73. 0xb7, 0x7b, 0xdf, 0xfb, 0x43, 0x5f, 0xff, 0x7a, 0x49, 0x49, 0x0e, 0xe7,
  74. 0x02, 0x51, 0x45, 0x13, 0xe8, 0x90, 0x64, 0x21, 0x0c, 0x26, 0x2b, 0x5d,
  75. 0xfc, 0xe4, 0xb5, 0x86, 0x89, 0x43, 0x22, 0x4c, 0xf3, 0x3b, 0xf3, 0x09,
  76. 0xc4, 0xa4, 0x10, 0x80, 0xf2, 0x46, 0xe2, 0x46, 0x8f, 0x76, 0x50, 0xbf,
  77. 0xaf, 0x2b, 0x90, 0x1b, 0x78, 0xc7, 0xcf, 0xc1, 0x77, 0xd0, 0xfb, 0xa9,
  78. 0xfb, 0xc9, 0x66, 0x5a, 0xc5, 0x9b, 0x31, 0x41, 0x67, 0x01, 0xbe, 0x33,
  79. 0x10, 0xba, 0x05, 0x58, 0xed, 0x76, 0x53, 0xde, 0x5d, 0xc1, 0xe8, 0xbb,
  80. 0x9f, 0xf1, 0xcd, 0xfb, 0xdf, 0x64, 0x7f, 0xd7, 0x18, 0xab, 0x0f, 0x94,
  81. 0x28, 0x95, 0x4a, 0xcc, 0x6a, 0xa9, 0x50, 0xc7, 0x05, 0x47, 0x10, 0x41,
  82. 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x50, 0x30, 0x4e, 0x30, 0x0e, 0x06,
  83. 0x03, 0x55, 0x1d, 0x0f, 0x01, 0x01, 0xff, 0x04, 0x04, 0x03, 0x02, 0x05,
  84. 0xa0, 0x30, 0x13, 0x06, 0x03, 0x55, 0x1d, 0x25, 0x04, 0x0c, 0x30, 0x0a,
  85. 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05, 0x07, 0x03, 0x01, 0x30, 0x0c,
  86. 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x02, 0x30, 0x00,
  87. 0x30, 0x19, 0x06, 0x03, 0x55, 0x1d, 0x11, 0x04, 0x12, 0x30, 0x10, 0x82,
  88. 0x0e, 0x66, 0x75, 0x7a, 0x7a, 0x2e, 0x62, 0x6f, 0x72, 0x69, 0x6e, 0x67,
  89. 0x73, 0x73, 0x6c, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
  90. 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82, 0x01, 0x01, 0x00, 0x92,
  91. 0xde, 0xef, 0x96, 0x06, 0x7b, 0xff, 0x71, 0x7d, 0x4e, 0xa0, 0x7d, 0xae,
  92. 0xb8, 0x22, 0xb4, 0x2c, 0xf7, 0x96, 0x9c, 0x37, 0x1d, 0x8f, 0xe7, 0xd9,
  93. 0x47, 0xff, 0x3f, 0xe9, 0x35, 0x95, 0x0e, 0xdd, 0xdc, 0x7f, 0xc8, 0x8a,
  94. 0x1e, 0x36, 0x1d, 0x38, 0x47, 0xfc, 0x76, 0xd2, 0x1f, 0x98, 0xa1, 0x36,
  95. 0xac, 0xc8, 0x70, 0x38, 0x0a, 0x3d, 0x51, 0x8d, 0x0f, 0x03, 0x1b, 0xef,
  96. 0x62, 0xa1, 0xcb, 0x2b, 0x4a, 0x8c, 0x12, 0x2b, 0x54, 0x50, 0x9a, 0x6b,
  97. 0xfe, 0xaf, 0xd9, 0xf6, 0xbf, 0x58, 0x11, 0x58, 0x5e, 0xe5, 0x86, 0x1e,
  98. 0x3b, 0x6b, 0x30, 0x7e, 0x72, 0x89, 0xe8, 0x6b, 0x7b, 0xb7, 0xaf, 0xef,
  99. 0x8b, 0xa9, 0x3e, 0xb0, 0xcd, 0x0b, 0xef, 0xb0, 0x0c, 0x96, 0x2b, 0xc5,
  100. 0x3b, 0xd5, 0xf1, 0xc2, 0xae, 0x3a, 0x60, 0xd9, 0x0f, 0x75, 0x37, 0x55,
  101. 0x4d, 0x62, 0xd2, 0xed, 0x96, 0xac, 0x30, 0x6b, 0xda, 0xa1, 0x48, 0x17,
  102. 0x96, 0x23, 0x85, 0x9a, 0x57, 0x77, 0xe9, 0x22, 0xa2, 0x37, 0x03, 0xba,
  103. 0x49, 0x77, 0x40, 0x3b, 0x76, 0x4b, 0xda, 0xc1, 0x04, 0x57, 0x55, 0x34,
  104. 0x22, 0x83, 0x45, 0x29, 0xab, 0x2e, 0x11, 0xff, 0x0d, 0xab, 0x55, 0xb1,
  105. 0xa7, 0x58, 0x59, 0x05, 0x25, 0xf9, 0x1e, 0x3d, 0xb7, 0xac, 0x04, 0x39,
  106. 0x2c, 0xf9, 0xaf, 0xb8, 0x68, 0xfb, 0x8e, 0x35, 0x71, 0x32, 0xff, 0x70,
  107. 0xe9, 0x46, 0x6d, 0x5c, 0x06, 0x90, 0x88, 0x23, 0x48, 0x0c, 0x50, 0xeb,
  108. 0x0a, 0xa9, 0xae, 0xe8, 0xfc, 0xbe, 0xa5, 0x76, 0x94, 0xd7, 0x64, 0x22,
  109. 0x38, 0x98, 0x17, 0xa4, 0x3a, 0xa7, 0x59, 0x9f, 0x1d, 0x3b, 0x75, 0x90,
  110. 0x1a, 0x81, 0xef, 0x19, 0xfb, 0x2b, 0xb7, 0xa7, 0x64, 0x61, 0x22, 0xa4,
  111. 0x6f, 0x7b, 0xfa, 0x58, 0xbb, 0x8c, 0x4e, 0x77, 0x67, 0xd0, 0x5d, 0x58,
  112. 0x76, 0x8a, 0xbb,
  113. };
  114. const uint8_t kRSAPrivateKeyDER[] = {
  115. 0x30, 0x82, 0x04, 0xa5, 0x02, 0x01, 0x00, 0x02, 0x82, 0x01, 0x01, 0x00,
  116. 0xce, 0x47, 0xcb, 0x11, 0xbb, 0xd2, 0x9d, 0x8e, 0x9e, 0xd2, 0x1e, 0x14,
  117. 0xaf, 0xc7, 0xea, 0xb6, 0xc9, 0x38, 0x2a, 0x6f, 0xb3, 0x7e, 0xfb, 0xbc,
  118. 0xfc, 0x59, 0x42, 0xb9, 0x56, 0xf0, 0x4c, 0x3f, 0xf7, 0x31, 0x84, 0xbe,
  119. 0xac, 0x03, 0x9e, 0x71, 0x91, 0x85, 0xd8, 0x32, 0xbd, 0x00, 0xea, 0xac,
  120. 0x65, 0xf6, 0x03, 0xc8, 0x0f, 0x8b, 0xfd, 0x6e, 0x58, 0x88, 0x04, 0x41,
  121. 0x92, 0x74, 0xa6, 0x57, 0x2e, 0x8e, 0x88, 0xd5, 0x3d, 0xda, 0x14, 0x3e,
  122. 0x63, 0x88, 0x22, 0xe3, 0x53, 0xe9, 0xba, 0x39, 0x09, 0xac, 0xfb, 0xd0,
  123. 0x4c, 0xf2, 0x3c, 0x20, 0xd6, 0x97, 0xe6, 0xed, 0xf1, 0x62, 0x1e, 0xe5,
  124. 0xc9, 0x48, 0xa0, 0xca, 0x2e, 0x3c, 0x14, 0x5a, 0x82, 0xd4, 0xed, 0xb1,
  125. 0xe3, 0x43, 0xc1, 0x2a, 0x59, 0xa5, 0xb9, 0xc8, 0x48, 0xa7, 0x39, 0x23,
  126. 0x74, 0xa7, 0x37, 0xb0, 0x6f, 0xc3, 0x64, 0x99, 0x6c, 0xa2, 0x82, 0xc8,
  127. 0xf6, 0xdb, 0x86, 0x40, 0xce, 0xd1, 0x85, 0x9f, 0xce, 0x69, 0xf4, 0x15,
  128. 0x2a, 0x23, 0xca, 0xea, 0xb7, 0x7b, 0xdf, 0xfb, 0x43, 0x5f, 0xff, 0x7a,
  129. 0x49, 0x49, 0x0e, 0xe7, 0x02, 0x51, 0x45, 0x13, 0xe8, 0x90, 0x64, 0x21,
  130. 0x0c, 0x26, 0x2b, 0x5d, 0xfc, 0xe4, 0xb5, 0x86, 0x89, 0x43, 0x22, 0x4c,
  131. 0xf3, 0x3b, 0xf3, 0x09, 0xc4, 0xa4, 0x10, 0x80, 0xf2, 0x46, 0xe2, 0x46,
  132. 0x8f, 0x76, 0x50, 0xbf, 0xaf, 0x2b, 0x90, 0x1b, 0x78, 0xc7, 0xcf, 0xc1,
  133. 0x77, 0xd0, 0xfb, 0xa9, 0xfb, 0xc9, 0x66, 0x5a, 0xc5, 0x9b, 0x31, 0x41,
  134. 0x67, 0x01, 0xbe, 0x33, 0x10, 0xba, 0x05, 0x58, 0xed, 0x76, 0x53, 0xde,
  135. 0x5d, 0xc1, 0xe8, 0xbb, 0x9f, 0xf1, 0xcd, 0xfb, 0xdf, 0x64, 0x7f, 0xd7,
  136. 0x18, 0xab, 0x0f, 0x94, 0x28, 0x95, 0x4a, 0xcc, 0x6a, 0xa9, 0x50, 0xc7,
  137. 0x05, 0x47, 0x10, 0x41, 0x02, 0x03, 0x01, 0x00, 0x01, 0x02, 0x82, 0x01,
  138. 0x01, 0x00, 0xa8, 0x47, 0xb9, 0x4a, 0x06, 0x47, 0x93, 0x71, 0x3d, 0xef,
  139. 0x7b, 0xca, 0xb4, 0x7c, 0x0a, 0xe6, 0x82, 0xd0, 0xe7, 0x0d, 0xa9, 0x08,
  140. 0xf6, 0xa4, 0xfd, 0xd8, 0x73, 0xae, 0x6f, 0x56, 0x29, 0x5e, 0x25, 0x72,
  141. 0xa8, 0x30, 0x44, 0x73, 0xcf, 0x56, 0x26, 0xb9, 0x61, 0xde, 0x42, 0x81,
  142. 0xf4, 0xf0, 0x1f, 0x5d, 0xcb, 0x47, 0xf2, 0x26, 0xe9, 0xe0, 0x93, 0x28,
  143. 0xa3, 0x10, 0x3b, 0x42, 0x1e, 0x51, 0x11, 0x12, 0x06, 0x5e, 0xaf, 0xce,
  144. 0xb0, 0xa5, 0x14, 0xdd, 0x82, 0x58, 0xa1, 0xa4, 0x12, 0xdf, 0x65, 0x1d,
  145. 0x51, 0x70, 0x64, 0xd5, 0x58, 0x68, 0x11, 0xa8, 0x6a, 0x23, 0xc2, 0xbf,
  146. 0xa1, 0x25, 0x24, 0x47, 0xb3, 0xa4, 0x3c, 0x83, 0x96, 0xb7, 0x1f, 0xf4,
  147. 0x44, 0xd4, 0xd1, 0xe9, 0xfc, 0x33, 0x68, 0x5e, 0xe2, 0x68, 0x99, 0x9c,
  148. 0x91, 0xe8, 0x72, 0xc9, 0xd7, 0x8c, 0x80, 0x20, 0x8e, 0x77, 0x83, 0x4d,
  149. 0xe4, 0xab, 0xf9, 0x74, 0xa1, 0xdf, 0xd3, 0xc0, 0x0d, 0x5b, 0x05, 0x51,
  150. 0xc2, 0x6f, 0xb2, 0x91, 0x02, 0xec, 0xc0, 0x02, 0x1a, 0x5c, 0x91, 0x05,
  151. 0xf1, 0xe3, 0xfa, 0x65, 0xc2, 0xad, 0x24, 0xe6, 0xe5, 0x3c, 0xb6, 0x16,
  152. 0xf1, 0xa1, 0x67, 0x1a, 0x9d, 0x37, 0x56, 0xbf, 0x01, 0xd7, 0x3b, 0x35,
  153. 0x30, 0x57, 0x73, 0xf4, 0xf0, 0x5e, 0xa7, 0xe8, 0x0a, 0xc1, 0x94, 0x17,
  154. 0xcf, 0x0a, 0xbd, 0xf5, 0x31, 0xa7, 0x2d, 0xf7, 0xf5, 0xd9, 0x8c, 0xc2,
  155. 0x01, 0xbd, 0xda, 0x16, 0x8e, 0xb9, 0x30, 0x40, 0xa6, 0x6e, 0xbd, 0xcd,
  156. 0x4d, 0x84, 0x67, 0x4e, 0x0b, 0xce, 0xd5, 0xef, 0xf8, 0x08, 0x63, 0x02,
  157. 0xc6, 0xc7, 0xf7, 0x67, 0x92, 0xe2, 0x23, 0x9d, 0x27, 0x22, 0x1d, 0xc6,
  158. 0x67, 0x5e, 0x66, 0xbf, 0x03, 0xb8, 0xa9, 0x67, 0xd4, 0x39, 0xd8, 0x75,
  159. 0xfa, 0xe8, 0xed, 0x56, 0xb8, 0x81, 0x02, 0x81, 0x81, 0x00, 0xf7, 0x46,
  160. 0x68, 0xc6, 0x13, 0xf8, 0xba, 0x0f, 0x83, 0xdb, 0x05, 0xa8, 0x25, 0x00,
  161. 0x70, 0x9c, 0x9e, 0x8b, 0x12, 0x34, 0x0d, 0x96, 0xcf, 0x0d, 0x98, 0x9b,
  162. 0x8d, 0x9c, 0x96, 0x78, 0xd1, 0x3c, 0x01, 0x8c, 0xb9, 0x35, 0x5c, 0x20,
  163. 0x42, 0xb4, 0x38, 0xe3, 0xd6, 0x54, 0xe7, 0x55, 0xd6, 0x26, 0x8a, 0x0c,
  164. 0xf6, 0x1f, 0xe0, 0x04, 0xc1, 0x22, 0x42, 0x19, 0x61, 0xc4, 0x94, 0x7c,
  165. 0x07, 0x2e, 0x80, 0x52, 0xfe, 0x8d, 0xe6, 0x92, 0x3a, 0x91, 0xfe, 0x72,
  166. 0x99, 0xe1, 0x2a, 0x73, 0x76, 0xb1, 0x24, 0x20, 0x67, 0xde, 0x28, 0xcb,
  167. 0x0e, 0xe6, 0x52, 0xb5, 0xfa, 0xfb, 0x8b, 0x1e, 0x6a, 0x1d, 0x09, 0x26,
  168. 0xb9, 0xa7, 0x61, 0xba, 0xf8, 0x79, 0xd2, 0x66, 0x57, 0x28, 0xd7, 0x31,
  169. 0xb5, 0x0b, 0x27, 0x19, 0x1e, 0x6f, 0x46, 0xfc, 0x54, 0x95, 0xeb, 0x78,
  170. 0x01, 0xb6, 0xd9, 0x79, 0x5a, 0x4d, 0x02, 0x81, 0x81, 0x00, 0xd5, 0x8f,
  171. 0x16, 0x53, 0x2f, 0x57, 0x93, 0xbf, 0x09, 0x75, 0xbf, 0x63, 0x40, 0x3d,
  172. 0x27, 0xfd, 0x23, 0x21, 0xde, 0x9b, 0xe9, 0x73, 0x3f, 0x49, 0x02, 0xd2,
  173. 0x38, 0x96, 0xcf, 0xc3, 0xba, 0x92, 0x07, 0x87, 0x52, 0xa9, 0x35, 0xe3,
  174. 0x0c, 0xe4, 0x2f, 0x05, 0x7b, 0x37, 0xa5, 0x40, 0x9c, 0x3b, 0x94, 0xf7,
  175. 0xad, 0xa0, 0xee, 0x3a, 0xa8, 0xfb, 0x1f, 0x11, 0x1f, 0xd8, 0x9a, 0x80,
  176. 0x42, 0x3d, 0x7f, 0xa4, 0xb8, 0x9a, 0xaa, 0xea, 0x72, 0xc1, 0xe3, 0xed,
  177. 0x06, 0x60, 0x92, 0x37, 0xf9, 0xba, 0xfb, 0x9e, 0xed, 0x05, 0xa6, 0xd4,
  178. 0x72, 0x68, 0x4f, 0x63, 0xfe, 0xd6, 0x10, 0x0d, 0x4f, 0x0a, 0x93, 0xc6,
  179. 0xb9, 0xd7, 0xaf, 0xfd, 0xd9, 0x57, 0x7d, 0xcb, 0x75, 0xe8, 0x93, 0x2b,
  180. 0xae, 0x4f, 0xea, 0xd7, 0x30, 0x0b, 0x58, 0x44, 0x82, 0x0f, 0x84, 0x5d,
  181. 0x62, 0x11, 0x78, 0xea, 0x5f, 0xc5, 0x02, 0x81, 0x81, 0x00, 0x82, 0x0c,
  182. 0xc1, 0xe6, 0x0b, 0x72, 0xf1, 0x48, 0x5f, 0xac, 0xbd, 0x98, 0xe5, 0x7d,
  183. 0x09, 0xbd, 0x15, 0x95, 0x47, 0x09, 0xa1, 0x6c, 0x03, 0x91, 0xbf, 0x05,
  184. 0x70, 0xc1, 0x3e, 0x52, 0x64, 0x99, 0x0e, 0xa7, 0x98, 0x70, 0xfb, 0xf6,
  185. 0xeb, 0x9e, 0x25, 0x9d, 0x8e, 0x88, 0x30, 0xf2, 0xf0, 0x22, 0x6c, 0xd0,
  186. 0xcc, 0x51, 0x8f, 0x5c, 0x70, 0xc7, 0x37, 0xc4, 0x69, 0xab, 0x1d, 0xfc,
  187. 0xed, 0x3a, 0x03, 0xbb, 0xa2, 0xad, 0xb6, 0xea, 0x89, 0x6b, 0x67, 0x4b,
  188. 0x96, 0xaa, 0xd9, 0xcc, 0xc8, 0x4b, 0xfa, 0x18, 0x21, 0x08, 0xb2, 0xa3,
  189. 0xb9, 0x3e, 0x61, 0x99, 0xdc, 0x5a, 0x97, 0x9c, 0x73, 0x6a, 0xb9, 0xf9,
  190. 0x68, 0x03, 0x24, 0x5f, 0x55, 0x77, 0x9c, 0xb4, 0xbe, 0x7a, 0x78, 0x53,
  191. 0x68, 0x48, 0x69, 0x53, 0xc8, 0xb1, 0xf5, 0xbf, 0x98, 0x2d, 0x11, 0x1e,
  192. 0x98, 0xa8, 0x36, 0x50, 0xa0, 0xb1, 0x02, 0x81, 0x81, 0x00, 0x90, 0x88,
  193. 0x30, 0x71, 0xc7, 0xfe, 0x9b, 0x6d, 0x95, 0x37, 0x6d, 0x79, 0xfc, 0x85,
  194. 0xe7, 0x44, 0x78, 0xbc, 0x79, 0x6e, 0x47, 0x86, 0xc9, 0xf3, 0xdd, 0xc6,
  195. 0xec, 0xa9, 0x94, 0x9f, 0x40, 0xeb, 0x87, 0xd0, 0xdb, 0xee, 0xcd, 0x1b,
  196. 0x87, 0x23, 0xff, 0x76, 0xd4, 0x37, 0x8a, 0xcd, 0xb9, 0x6e, 0xd1, 0x98,
  197. 0xf6, 0x97, 0x8d, 0xe3, 0x81, 0x6d, 0xc3, 0x4e, 0xd1, 0xa0, 0xc4, 0x9f,
  198. 0xbd, 0x34, 0xe5, 0xe8, 0x53, 0x4f, 0xca, 0x10, 0xb5, 0xed, 0xe7, 0x16,
  199. 0x09, 0x54, 0xde, 0x60, 0xa7, 0xd1, 0x16, 0x6e, 0x2e, 0xb7, 0xbe, 0x7a,
  200. 0xd5, 0x9b, 0x26, 0xef, 0xe4, 0x0e, 0x77, 0xfa, 0xa9, 0xdd, 0xdc, 0xb9,
  201. 0x88, 0x19, 0x23, 0x70, 0xc7, 0xe1, 0x60, 0xaf, 0x8c, 0x73, 0x04, 0xf7,
  202. 0x71, 0x17, 0x81, 0x36, 0x75, 0xbb, 0x97, 0xd7, 0x75, 0xb6, 0x8e, 0xbc,
  203. 0xac, 0x9c, 0x6a, 0x9b, 0x24, 0x89, 0x02, 0x81, 0x80, 0x5a, 0x2b, 0xc7,
  204. 0x6b, 0x8c, 0x65, 0xdb, 0x04, 0x73, 0xab, 0x25, 0xe1, 0x5b, 0xbc, 0x3c,
  205. 0xcf, 0x5a, 0x3c, 0x04, 0xae, 0x97, 0x2e, 0xfd, 0xa4, 0x97, 0x1f, 0x05,
  206. 0x17, 0x27, 0xac, 0x7c, 0x30, 0x85, 0xb4, 0x82, 0x3f, 0x5b, 0xb7, 0x94,
  207. 0x3b, 0x7f, 0x6c, 0x0c, 0xc7, 0x16, 0xc6, 0xa0, 0xbd, 0x80, 0xb0, 0x81,
  208. 0xde, 0xa0, 0x23, 0xa6, 0xf6, 0x75, 0x33, 0x51, 0x35, 0xa2, 0x75, 0x55,
  209. 0x70, 0x4d, 0x42, 0xbb, 0xcf, 0x54, 0xe4, 0xdb, 0x2d, 0x88, 0xa0, 0x7a,
  210. 0xf2, 0x17, 0xa7, 0xdd, 0x13, 0x44, 0x9f, 0x5f, 0x6b, 0x2c, 0x42, 0x42,
  211. 0x8b, 0x13, 0x4d, 0xf9, 0x5b, 0xf8, 0x33, 0x42, 0xd9, 0x9e, 0x50, 0x1c,
  212. 0x7c, 0xbc, 0xfa, 0x62, 0x85, 0x0b, 0xcf, 0x99, 0xda, 0x9e, 0x04, 0x90,
  213. 0xb2, 0xc6, 0xb2, 0x0a, 0x2a, 0x7c, 0x6d, 0x6a, 0x40, 0xfc, 0xf5, 0x50,
  214. 0x98, 0x46, 0x89, 0x82, 0x40,
  215. };
  216. const uint8_t kALPNProtocols[] = {
  217. 0x01, 'a', 0x02, 'a', 'a', 0x03, 'a', 'a', 'a',
  218. };
  219. int ALPNSelectCallback(SSL *ssl, const uint8_t **out, uint8_t *out_len,
  220. const uint8_t *in, unsigned in_len, void *arg) {
  221. static const uint8_t kProtocol[] = {'a', 'a'};
  222. *out = kProtocol;
  223. *out_len = sizeof(kProtocol);
  224. return SSL_TLSEXT_ERR_OK;
  225. }
  226. int NPNSelectCallback(SSL *ssl, uint8_t **out, uint8_t *out_len,
  227. const uint8_t *in, unsigned in_len, void *arg) {
  228. static const uint8_t kProtocol[] = {'a', 'a'};
  229. *out = const_cast<uint8_t *>(kProtocol);
  230. *out_len = sizeof(kProtocol);
  231. return SSL_TLSEXT_ERR_OK;
  232. }
  233. int NPNAdvertiseCallback(SSL *ssl, const uint8_t **out, unsigned *out_len,
  234. void *arg) {
  235. static const uint8_t kProtocols[] = {
  236. 0x01, 'a', 0x02, 'a', 'a', 0x03, 'a', 'a', 'a',
  237. };
  238. *out = kProtocols;
  239. *out_len = sizeof(kProtocols);
  240. return SSL_TLSEXT_ERR_OK;
  241. }
  242. class TLSFuzzer {
  243. public:
  244. enum Protocol {
  245. kTLS,
  246. kDTLS,
  247. };
  248. enum Role {
  249. kClient,
  250. kServer,
  251. };
  252. TLSFuzzer(Protocol protocol, Role role)
  253. : debug_(getenv("BORINGSSL_FUZZER_DEBUG") != nullptr),
  254. protocol_(protocol),
  255. role_(role) {
  256. if (!Init()) {
  257. abort();
  258. }
  259. }
  260. static void MoveBIOs(SSL *dest, SSL *src) {
  261. BIO *rbio = SSL_get_rbio(src);
  262. BIO_up_ref(rbio);
  263. SSL_set0_rbio(dest, rbio);
  264. BIO *wbio = SSL_get_wbio(src);
  265. BIO_up_ref(wbio);
  266. SSL_set0_wbio(dest, wbio);
  267. SSL_set0_rbio(src, nullptr);
  268. SSL_set0_wbio(src, nullptr);
  269. }
  270. int TestOneInput(const uint8_t *buf, size_t len) {
  271. RAND_reset_for_fuzzing();
  272. CBS cbs;
  273. CBS_init(&cbs, buf, len);
  274. bssl::UniquePtr<SSL> ssl = SetupTest(&cbs);
  275. if (!ssl) {
  276. if (debug_) {
  277. fprintf(stderr, "Error parsing parameters.\n");
  278. }
  279. return 0;
  280. }
  281. if (role_ == kClient) {
  282. SSL_set_renegotiate_mode(ssl.get(), ssl_renegotiate_freely);
  283. SSL_set_tlsext_host_name(ssl.get(), "hostname");
  284. }
  285. // ssl_handoff may or may not be used.
  286. bssl::UniquePtr<SSL> ssl_handoff(SSL_new(ctx_.get()));
  287. bssl::UniquePtr<SSL> ssl_handback(SSL_new(ctx_.get()));
  288. SSL_set_accept_state(ssl_handoff.get());
  289. SSL_set0_rbio(ssl.get(), MakeBIO(CBS_data(&cbs), CBS_len(&cbs)).release());
  290. SSL_set0_wbio(ssl.get(), BIO_new(BIO_s_mem()));
  291. SSL *ssl_handshake = ssl.get();
  292. bool handshake_successful = false;
  293. bool handback_successful = false;
  294. for (;;) {
  295. int ret = SSL_do_handshake(ssl_handshake);
  296. if (ret < 0 && SSL_get_error(ssl_handshake, ret) == SSL_ERROR_HANDOFF) {
  297. MoveBIOs(ssl_handoff.get(), ssl.get());
  298. // Ordinarily we would call SSL_serialize_handoff(ssl.get(). But for
  299. // fuzzing, use the serialized handoff that's getting fuzzed.
  300. if (!SSL_apply_handoff(ssl_handoff.get(), handoff_)) {
  301. if (debug_) {
  302. fprintf(stderr, "Handoff failed.\n");
  303. }
  304. break;
  305. }
  306. ssl_handshake = ssl_handoff.get();
  307. } else if (ret < 0 &&
  308. SSL_get_error(ssl_handshake, ret) == SSL_ERROR_HANDBACK) {
  309. MoveBIOs(ssl_handback.get(), ssl_handoff.get());
  310. if (!SSL_apply_handback(ssl_handback.get(), handback_)) {
  311. if (debug_) {
  312. fprintf(stderr, "Handback failed.\n");
  313. }
  314. break;
  315. }
  316. handback_successful = true;
  317. ssl_handshake = ssl_handback.get();
  318. } else {
  319. handshake_successful = ret == 1;
  320. break;
  321. }
  322. }
  323. if (debug_) {
  324. if (!handshake_successful) {
  325. fprintf(stderr, "Handshake failed.\n");
  326. } else if (handback_successful) {
  327. fprintf(stderr, "Handback successful.\n");
  328. }
  329. }
  330. if (handshake_successful) {
  331. // Keep reading application data until error or EOF.
  332. uint8_t tmp[1024];
  333. for (;;) {
  334. if (SSL_read(ssl_handshake, tmp, sizeof(tmp)) <= 0) {
  335. break;
  336. }
  337. }
  338. }
  339. if (debug_) {
  340. ERR_print_errors_fp(stderr);
  341. }
  342. ERR_clear_error();
  343. return 0;
  344. }
  345. private:
  346. // Init initializes |ctx_| with settings common to all inputs.
  347. bool Init() {
  348. ctx_.reset(SSL_CTX_new(protocol_ == kDTLS ? DTLS_method() : TLS_method()));
  349. bssl::UniquePtr<EVP_PKEY> pkey(EVP_PKEY_new());
  350. bssl::UniquePtr<RSA> privkey(RSA_private_key_from_bytes(
  351. kRSAPrivateKeyDER, sizeof(kRSAPrivateKeyDER)));
  352. if (!ctx_ || !privkey || !pkey ||
  353. !EVP_PKEY_set1_RSA(pkey.get(), privkey.get()) ||
  354. !SSL_CTX_use_PrivateKey(ctx_.get(), pkey.get())) {
  355. return false;
  356. }
  357. const uint8_t *bufp = kCertificateDER;
  358. bssl::UniquePtr<X509> cert(d2i_X509(NULL, &bufp, sizeof(kCertificateDER)));
  359. if (!cert ||
  360. !SSL_CTX_use_certificate(ctx_.get(), cert.get()) ||
  361. !SSL_CTX_set_ocsp_response(ctx_.get(), kOCSPResponse,
  362. sizeof(kOCSPResponse)) ||
  363. !SSL_CTX_set_signed_cert_timestamp_list(ctx_.get(), kSCT,
  364. sizeof(kSCT))) {
  365. return false;
  366. }
  367. // When accepting peer certificates, allow any certificate.
  368. SSL_CTX_set_cert_verify_callback(
  369. ctx_.get(),
  370. [](X509_STORE_CTX *store_ctx, void *arg) -> int { return 1; }, nullptr);
  371. SSL_CTX_enable_signed_cert_timestamps(ctx_.get());
  372. SSL_CTX_enable_ocsp_stapling(ctx_.get());
  373. // Enable versions and ciphers that are off by default.
  374. if (!SSL_CTX_set_strict_cipher_list(ctx_.get(), "ALL:NULL-SHA")) {
  375. return false;
  376. }
  377. if (protocol_ == kTLS &&
  378. !SSL_CTX_set_max_proto_version(ctx_.get(), TLS1_3_VERSION)) {
  379. return false;
  380. }
  381. static const int kCurves[] = {NID_CECPQ2, NID_X25519, NID_X9_62_prime256v1,
  382. NID_secp384r1, NID_secp521r1};
  383. if (!SSL_CTX_set1_curves(ctx_.get(), kCurves,
  384. OPENSSL_ARRAY_SIZE(kCurves))) {
  385. return false;
  386. }
  387. SSL_CTX_set_early_data_enabled(ctx_.get(), 1);
  388. SSL_CTX_set_next_proto_select_cb(ctx_.get(), NPNSelectCallback, nullptr);
  389. SSL_CTX_set_next_protos_advertised_cb(ctx_.get(), NPNAdvertiseCallback,
  390. nullptr);
  391. SSL_CTX_set_alpn_select_cb(ctx_.get(), ALPNSelectCallback, nullptr);
  392. if (SSL_CTX_set_alpn_protos(ctx_.get(), kALPNProtocols,
  393. sizeof(kALPNProtocols)) != 0) {
  394. return false;
  395. }
  396. CBS cbs;
  397. CBS_init(&cbs, kP256KeyPKCS8, sizeof(kP256KeyPKCS8));
  398. pkey.reset(EVP_parse_private_key(&cbs));
  399. if (!pkey || !SSL_CTX_set1_tls_channel_id(ctx_.get(), pkey.get())) {
  400. return false;
  401. }
  402. SSL_CTX_set_tls_channel_id_enabled(ctx_.get(), 1);
  403. return true;
  404. }
  405. // SetupTest parses parameters from |cbs| and returns a newly-configured |SSL|
  406. // object or nullptr on error. On success, the caller should feed the
  407. // remaining input in |cbs| to the SSL stack.
  408. bssl::UniquePtr<SSL> SetupTest(CBS *cbs) {
  409. // |ctx| is shared between runs, so we must clear any modifications to it
  410. // made later on in this function.
  411. SSL_CTX_flush_sessions(ctx_.get(), 0);
  412. handoff_ = {};
  413. handback_ = {};
  414. bssl::UniquePtr<SSL> ssl(SSL_new(ctx_.get()));
  415. if (role_ == kServer) {
  416. SSL_set_accept_state(ssl.get());
  417. } else {
  418. SSL_set_connect_state(ssl.get());
  419. }
  420. for (;;) {
  421. uint16_t tag;
  422. if (!CBS_get_u16(cbs, &tag)) {
  423. return nullptr;
  424. }
  425. switch (tag) {
  426. case kDataTag:
  427. return ssl;
  428. case kSessionTag: {
  429. CBS data;
  430. if (!CBS_get_u24_length_prefixed(cbs, &data)) {
  431. return nullptr;
  432. }
  433. bssl::UniquePtr<SSL_SESSION> session(SSL_SESSION_from_bytes(
  434. CBS_data(&data), CBS_len(&data), ctx_.get()));
  435. if (!session) {
  436. return nullptr;
  437. }
  438. if (role_ == kServer) {
  439. SSL_CTX_add_session(ctx_.get(), session.get());
  440. } else {
  441. SSL_set_session(ssl.get(), session.get());
  442. }
  443. break;
  444. }
  445. case kRequestClientCert:
  446. if (role_ == kClient) {
  447. return nullptr;
  448. }
  449. SSL_set_verify(ssl.get(), SSL_VERIFY_PEER, nullptr);
  450. break;
  451. case kHandoffTag: {
  452. CBS handoff;
  453. if (!CBS_get_u24_length_prefixed(cbs, &handoff)) {
  454. return nullptr;
  455. }
  456. handoff_.CopyFrom(handoff);
  457. bssl::SSL_set_handoff_mode(ssl.get(), 1);
  458. break;
  459. }
  460. case kHandbackTag: {
  461. CBS handback;
  462. if (!CBS_get_u24_length_prefixed(cbs, &handback)) {
  463. return nullptr;
  464. }
  465. handback_.CopyFrom(handback);
  466. bssl::SSL_set_handoff_mode(ssl.get(), 1);
  467. break;
  468. }
  469. default:
  470. return nullptr;
  471. }
  472. }
  473. }
  474. struct BIOData {
  475. Protocol protocol;
  476. CBS cbs;
  477. };
  478. bssl::UniquePtr<BIO> MakeBIO(const uint8_t *in, size_t len) {
  479. BIOData *b = new BIOData;
  480. b->protocol = protocol_;
  481. CBS_init(&b->cbs, in, len);
  482. bssl::UniquePtr<BIO> bio(BIO_new(&kBIOMethod));
  483. bio->init = 1;
  484. bio->ptr = b;
  485. return bio;
  486. }
  487. static int BIORead(BIO *bio, char *out, int len) {
  488. assert(bio->method == &kBIOMethod);
  489. BIOData *b = reinterpret_cast<BIOData *>(bio->ptr);
  490. if (b->protocol == kTLS) {
  491. len = std::min(static_cast<size_t>(len), CBS_len(&b->cbs));
  492. memcpy(out, CBS_data(&b->cbs), len);
  493. CBS_skip(&b->cbs, len);
  494. return len;
  495. }
  496. // Preserve packet boundaries for DTLS.
  497. CBS packet;
  498. if (!CBS_get_u24_length_prefixed(&b->cbs, &packet)) {
  499. return -1;
  500. }
  501. len = std::min(static_cast<size_t>(len), CBS_len(&packet));
  502. memcpy(out, CBS_data(&packet), len);
  503. return len;
  504. }
  505. static int BIODestroy(BIO *bio) {
  506. assert(bio->method == &kBIOMethod);
  507. BIOData *b = reinterpret_cast<BIOData *>(bio->ptr);
  508. delete b;
  509. return 1;
  510. }
  511. static const BIO_METHOD kBIOMethod;
  512. bool debug_;
  513. Protocol protocol_;
  514. Role role_;
  515. bssl::UniquePtr<SSL_CTX> ctx_;
  516. bssl::Array<uint8_t> handoff_, handback_;
  517. };
  518. const BIO_METHOD TLSFuzzer::kBIOMethod = {
  519. 0, // type
  520. nullptr, // name
  521. nullptr, // bwrite
  522. TLSFuzzer::BIORead,
  523. nullptr, // bputs
  524. nullptr, // bgets
  525. nullptr, // ctrl
  526. nullptr, // create
  527. TLSFuzzer::BIODestroy,
  528. nullptr, // callback_ctrl
  529. };
  530. } // namespace
  531. #endif // HEADER_SSL_TEST_FUZZER