/src/cryptofuzz/modules/botan/module.cpp
Line  | Count  | Source (jump to first uncovered line)  | 
1  |  | #include "module.h"  | 
2  |  | #include <cryptofuzz/util.h>  | 
3  |  | #include <cryptofuzz/repository.h>  | 
4  |  | #include <botan/aead.h>  | 
5  |  | #include <botan/ber_dec.h>  | 
6  |  | #include <botan/bigint.h>  | 
7  |  | #include <botan/cipher_mode.h>  | 
8  |  | #include <botan/curve25519.h>  | 
9  |  | #include <botan/dh.h>  | 
10  |  | #include <botan/dl_group.h>  | 
11  |  | #include <botan/dsa.h>  | 
12  |  | #include <botan/ecdsa.h>  | 
13  |  | #include <botan/ecgdsa.h>  | 
14  |  | #include <botan/ed25519.h>  | 
15  |  | #include <botan/hash.h>  | 
16  |  | #include <botan/kdf.h>  | 
17  |  | #include <botan/mac.h>  | 
18  |  | #include <botan/pubkey.h>  | 
19  |  | #include <botan/pwdhash.h>  | 
20  |  | #include <botan/system_rng.h>  | 
21  |  | #include "bn_ops.h"  | 
22  |  |  | 
23  |  | namespace cryptofuzz { | 
24  |  | namespace module { | 
25  |  |  | 
26  |  | Botan::Botan(void) :  | 
27  | 4  |     Module("Botan") { | 
28  | 4  |     if ( setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1) != 0 ) { | 
29  | 0  |         abort();  | 
30  | 0  |     }  | 
31  |  |  | 
32  |  |     /* Add a few curves */  | 
33  |  |  | 
34  | 4  |     { | 
35  | 4  |         const ::Botan::OID secp112r1_oid("1.3.132.0.6"); | 
36  | 4  |         const ::Botan::EC_Group secp112r1(  | 
37  | 4  |                 ::Botan::BigInt("4451685225093714772084598273548427"), | 
38  | 4  |                 ::Botan::BigInt("4451685225093714772084598273548424"), | 
39  | 4  |                 ::Botan::BigInt("2061118396808653202902996166388514"), | 
40  | 4  |                 ::Botan::BigInt("188281465057972534892223778713752"), | 
41  | 4  |                 ::Botan::BigInt("3419875491033170827167861896082688"), | 
42  | 4  |                 ::Botan::BigInt("4451685225093714776491891542548933"), | 
43  | 4  |                 1,  | 
44  | 4  |                 secp112r1_oid);  | 
45  | 4  |         ::Botan::OID::register_oid(secp112r1_oid, "secp112r1");  | 
46  | 4  |     }  | 
47  |  |  | 
48  | 4  |     { | 
49  | 4  |         const ::Botan::OID secp112r2_oid("1.3.132.0.7"); | 
50  | 4  |         const ::Botan::EC_Group secp112r2(  | 
51  | 4  |                 ::Botan::BigInt("4451685225093714772084598273548427"), | 
52  | 4  |                 ::Botan::BigInt("1970543761890640310119143205433388"), | 
53  | 4  |                 ::Botan::BigInt("1660538572255285715897238774208265"), | 
54  | 4  |                 ::Botan::BigInt("1534098225527667214992304222930499"), | 
55  | 4  |                 ::Botan::BigInt("3525120595527770847583704454622871"), | 
56  | 4  |                 ::Botan::BigInt("1112921306273428674967732714786891"), | 
57  | 4  |                 4,  | 
58  | 4  |                 secp112r2_oid);  | 
59  | 4  |         ::Botan::OID::register_oid(secp112r2_oid, "secp112r2");  | 
60  | 4  |     }  | 
61  |  |  | 
62  | 4  |     { | 
63  | 4  |         const ::Botan::OID secp128r1_oid("1.3.132.0.28"); | 
64  | 4  |         const ::Botan::EC_Group secp128r1(  | 
65  | 4  |                 ::Botan::BigInt("340282366762482138434845932244680310783"), | 
66  | 4  |                 ::Botan::BigInt("340282366762482138434845932244680310780"), | 
67  | 4  |                 ::Botan::BigInt("308990863222245658030922601041482374867"), | 
68  | 4  |                 ::Botan::BigInt("29408993404948928992877151431649155974"), | 
69  | 4  |                 ::Botan::BigInt("275621562871047521857442314737465260675"), | 
70  | 4  |                 ::Botan::BigInt("340282366762482138443322565580356624661"), | 
71  | 4  |                 1,  | 
72  | 4  |                 secp128r1_oid);  | 
73  | 4  |         ::Botan::OID::register_oid(secp128r1_oid, "secp128r1");  | 
74  | 4  |     }  | 
75  |  |  | 
76  | 4  |     { | 
77  | 4  |         const ::Botan::OID secp128r2_oid("1.3.132.0.29"); | 
78  | 4  |         const ::Botan::EC_Group secp128r2(  | 
79  | 4  |                 ::Botan::BigInt("340282366762482138434845932244680310783"), | 
80  | 4  |                 ::Botan::BigInt("284470887156368047300405921324061011681"), | 
81  | 4  |                 ::Botan::BigInt("126188322377389722996253562430093625949"), | 
82  | 4  |                 ::Botan::BigInt("164048790688614013222215505581242564928"), | 
83  | 4  |                 ::Botan::BigInt("52787839253935625605232456597451787076"), | 
84  | 4  |                 ::Botan::BigInt("85070591690620534603955721926813660579"), | 
85  | 4  |                 4,  | 
86  | 4  |                 secp128r2_oid);  | 
87  | 4  |         ::Botan::OID::register_oid(secp128r2_oid, "secp128r2");  | 
88  | 4  |     }  | 
89  | 4  | }  | 
90  |  |  | 
91  |  | #if !defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
92  |  |  #define BOTAN_FUZZER_RNG Botan_detail::Fuzzer_RNG rng(ds);  | 
93  |  | #else  | 
94  | 0  |  #define BOTAN_FUZZER_RNG ::Botan::System_RNG rng;  | 
95  |  | #endif /* CRYPTOFUZZ_BOTAN_IS_ORACLE */  | 
96  |  |  | 
97  |  | #if !defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
98  |  |  #define BOTAN_SET_GLOBAL_DS CF_NORET(util::SetGlobalDs(&ds));  | 
99  |  |  #define BOTAN_UNSET_GLOBAL_DS CF_NORET(util::UnsetGlobalDs());  | 
100  |  | #else  | 
101  |  |  #define BOTAN_SET_GLOBAL_DS  | 
102  |  |  #define BOTAN_UNSET_GLOBAL_DS  | 
103  |  | #endif  | 
104  |  |  | 
105  |  | namespace Botan_detail { | 
106  |  |  | 
107  |  | #if !defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
108  |  |     class Fuzzer_RNG final : public ::Botan::RandomNumberGenerator { | 
109  |  |         private:  | 
110  |  |             Datasource& ds;  | 
111  |  |         public:  | 
112  |  |             Fuzzer_RNG(Datasource& ds) :  | 
113  |  |                 ds(ds)  | 
114  |  |             { } | 
115  |  |  | 
116  |  |             bool is_seeded() const override { return true; } | 
117  |  |  | 
118  |  |             bool accepts_input() const override { return false; } | 
119  |  |  | 
120  |  |             void clear() override {} | 
121  |  |  | 
122  |  |             virtual void fill_bytes_with_input(  | 
123  |  |                     std::span<uint8_t> output,  | 
124  |  |                     std::span<const uint8_t> input) override { | 
125  |  |                 (void)input;  | 
126  |  |  | 
127  |  |                 if ( output.empty() ) { | 
128  |  |                     return;  | 
129  |  |                 }  | 
130  |  |  | 
131  |  |                 const auto data = ds.GetData(0, output.size(), output.size());  | 
132  |  |  | 
133  |  |                 std::copy(data.begin(), data.end(), output.begin());  | 
134  |  |             }  | 
135  |  |  | 
136  |  |             std::string name() const override { return "Fuzzer_RNG"; } | 
137  |  |     };  | 
138  |  | #endif /* CRYPTOFUZZ_BOTAN_IS_ORACLE */  | 
139  |  |  | 
140  | 266  |     const std::string parenthesize(const std::string parent, const std::string child) { | 
141  | 266  |         static const std::string pOpen("("); | 
142  | 266  |         static const std::string pClose(")"); | 
143  |  |  | 
144  | 266  |         return parent + pOpen + child + pClose;  | 
145  | 266  |     }  | 
146  |  |  | 
147  | 266  |     std::optional<std::string> DigestIDToString(const uint64_t digestType, const bool altShake = false, const bool isHmac = false) { | 
148  | 266  | #include "digest_string_lut.h"  | 
149  | 266  |         std::optional<std::string> ret = std::nullopt;  | 
150  |  |  | 
151  | 266  |         CF_CHECK_NE(LUT.find(digestType), LUT.end());  | 
152  |  |  | 
153  | 266  |         if ( isHmac == false ) { | 
154  | 266  |             if (    digestType == CF_DIGEST("SIPHASH64") || | 
155  | 266  |                     digestType == CF_DIGEST("SIPHASH128") ) { | 
156  | 0  |                 return std::nullopt;  | 
157  | 0  |             }  | 
158  | 266  |         }  | 
159  | 266  |         if ( altShake == true && digestType == CF_DIGEST("SHAKE128") ) { | 
160  | 0  |             ret = "SHAKE-128(256)";  | 
161  | 266  |         } else if ( altShake == true && digestType == CF_DIGEST("SHAKE256") ) { | 
162  | 0  |             ret = "SHAKE-256(512)";  | 
163  | 266  |         } else if ( altShake == true && digestType == CF_DIGEST("SHAKE256_114") ) { | 
164  | 0  |             ret = "SHAKE-256(912)"; /* 114 bytes * 8 = 912 bits */  | 
165  | 266  |         } else { | 
166  | 266  |             ret = LUT.at(digestType);  | 
167  | 266  |         }  | 
168  | 266  | end:  | 
169  | 266  |         return ret;  | 
170  | 266  |     }  | 
171  |  |  | 
172  |  | } /* namespace Botan_detail */  | 
173  |  |  | 
174  | 0  | std::optional<component::Digest> Botan::OpDigest(operation::Digest& op) { | 
175  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
176  | 0  |     std::optional<component::Digest> ret = std::nullopt;  | 
177  | 0  |     std::unique_ptr<::Botan::HashFunction> hash = nullptr;  | 
178  | 0  |     util::Multipart parts;  | 
179  | 0  |     size_t numClears = 0;  | 
180  |  |  | 
181  |  |     /* Initialize */  | 
182  | 0  |     { | 
183  | 0  |         BOTAN_SET_GLOBAL_DS  | 
184  |  | 
  | 
185  | 0  |         std::optional<std::string> algoString;  | 
186  | 0  |         CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get()), std::nullopt);  | 
187  | 0  |         CF_CHECK_NE(hash = ::Botan::HashFunction::create(*algoString), nullptr);  | 
188  |  | 
  | 
189  | 0  |         parts = util::ToParts(ds, op.cleartext);  | 
190  | 0  |     }  | 
191  |  |  | 
192  | 0  | again:  | 
193  |  |     /* Process */  | 
194  | 0  |     for (const auto& part : parts) { | 
195  | 0  |         hash->update(part.first, part.second);  | 
196  | 0  |         bool clear = false;  | 
197  |  | 
  | 
198  | 0  |         if ( numClears < 3 ) { | 
199  | 0  |             try { | 
200  |  | #if !defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
201  |  |                 clear = ds.Get<bool>();  | 
202  |  | #endif /* CRYPTOFUZZ_BOTAN_IS_ORACLE */  | 
203  | 0  |             } catch ( ... ) { } | 
204  | 0  |         }  | 
205  |  | 
  | 
206  | 0  |         if ( clear == true ) { | 
207  | 0  |             hash->clear();  | 
208  | 0  |             numClears++;  | 
209  | 0  |             goto again;  | 
210  | 0  |         }  | 
211  | 0  |     }  | 
212  |  |  | 
213  |  |     /* Finalize */  | 
214  | 0  |     { | 
215  | 0  |         const auto res = hash->final();  | 
216  | 0  |         ret = component::Digest(res.data(), res.size());  | 
217  | 0  |     }  | 
218  |  | 
  | 
219  | 0  | end:  | 
220  | 0  |     BOTAN_UNSET_GLOBAL_DS  | 
221  |  | 
  | 
222  | 0  |     return ret;  | 
223  | 0  | }  | 
224  |  |  | 
225  | 0  | std::optional<component::MAC> Botan::OpHMAC(operation::HMAC& op) { | 
226  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
227  | 0  |     std::optional<component::MAC> ret = std::nullopt;  | 
228  | 0  |     std::unique_ptr<::Botan::MessageAuthenticationCode> hmac = nullptr;  | 
229  | 0  |     util::Multipart parts;  | 
230  |  | 
  | 
231  | 0  |     try { | 
232  |  |         /* Initialize */  | 
233  | 0  |         { | 
234  | 0  |             BOTAN_SET_GLOBAL_DS  | 
235  |  | 
  | 
236  | 0  |             std::optional<std::string> algoString;  | 
237  | 0  |             CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get(), true, true), std::nullopt);  | 
238  |  | 
  | 
239  | 0  |             std::string hmacString;  | 
240  | 0  |             if (  | 
241  | 0  |                     op.digestType.Is(CF_DIGEST("SIPHASH64")) || | 
242  | 0  |                     op.digestType.Is(CF_DIGEST("BLAKE2B_MAC")) ) { | 
243  | 0  |                 hmacString = *algoString;  | 
244  | 0  |             } else { | 
245  | 0  |                 hmacString = Botan_detail::parenthesize("HMAC", *algoString); | 
246  | 0  |             }  | 
247  |  | 
  | 
248  | 0  |             CF_CHECK_NE(hmac = ::Botan::MessageAuthenticationCode::create(hmacString), nullptr);  | 
249  |  | 
  | 
250  | 0  |             try { | 
251  | 0  |                 hmac->set_key(op.cipher.key.GetPtr(), op.cipher.key.GetSize());  | 
252  | 0  |             } catch ( ... ) { | 
253  | 0  |                 goto end;  | 
254  | 0  |             }  | 
255  |  |  | 
256  | 0  |             parts = util::ToParts(ds, op.cleartext);  | 
257  | 0  |         }  | 
258  |  |  | 
259  |  |         /* Process */  | 
260  | 0  |         for (const auto& part : parts) { | 
261  | 0  |             hmac->update(part.first, part.second);  | 
262  | 0  |         }  | 
263  |  |  | 
264  |  |         /* Finalize */  | 
265  | 0  |         { | 
266  | 0  |             const auto res = hmac->final();  | 
267  | 0  |             ret = component::MAC(res.data(), res.size());  | 
268  | 0  |         }  | 
269  |  | 
  | 
270  | 0  |     } catch ( ... ) { } | 
271  |  |  | 
272  | 0  | end:  | 
273  | 0  |     BOTAN_UNSET_GLOBAL_DS  | 
274  |  | 
  | 
275  | 0  |     return ret;  | 
276  | 0  | }  | 
277  |  |  | 
278  |  | namespace Botan_detail { | 
279  |  |  | 
280  | 0  |     std::optional<std::string> CipherIDToString(const uint64_t digestType, const bool withMode = true) { | 
281  | 0  | #include "cipher_string_lut.h"  | 
282  | 0  |         std::optional<std::string> ret = std::nullopt;  | 
283  |  | 
  | 
284  | 0  |         CF_CHECK_NE(LUT.find(digestType), LUT.end());  | 
285  | 0  |         ret = withMode ? LUT.at(digestType).first : LUT.at(digestType).second;  | 
286  | 0  | end:  | 
287  | 0  |         return ret;  | 
288  | 0  |     }  | 
289  |  |  | 
290  |  |     template <class OperationType>  | 
291  |  |     const uint8_t* GetInPtr(const OperationType& op);  | 
292  |  |  | 
293  |  |     template <>  | 
294  | 0  |     const uint8_t* GetInPtr(const operation::SymmetricEncrypt& op) { | 
295  | 0  |         return op.cleartext.GetPtr();  | 
296  | 0  |     }  | 
297  |  |  | 
298  |  |     template <>  | 
299  | 0  |     const uint8_t* GetInPtr(const operation::SymmetricDecrypt& op) { | 
300  | 0  |         return op.ciphertext.GetPtr();  | 
301  | 0  |     }  | 
302  |  |  | 
303  |  |     template <class OperationType>  | 
304  |  |     size_t GetInSize(const OperationType& op);  | 
305  |  |  | 
306  |  |     template <>  | 
307  | 0  |     size_t GetInSize(const operation::SymmetricEncrypt& op) { | 
308  | 0  |         return op.cleartext.GetSize();  | 
309  | 0  |     }  | 
310  |  |  | 
311  |  |     template <>  | 
312  | 0  |     size_t GetInSize(const operation::SymmetricDecrypt& op) { | 
313  | 0  |         return op.ciphertext.GetSize();  | 
314  | 0  |     }  | 
315  |  |  | 
316  |  |     template <class OperationType>  | 
317  |  |     ::Botan::Cipher_Dir GetCryptType(void);  | 
318  |  |  | 
319  |  |     template <>  | 
320  | 0  |     ::Botan::Cipher_Dir GetCryptType<operation::SymmetricEncrypt>(void) { | 
321  | 0  |         return ::Botan::Cipher_Dir::Encryption;  | 
322  | 0  |     }  | 
323  |  |  | 
324  |  |     template <>  | 
325  | 0  |     ::Botan::Cipher_Dir GetCryptType<operation::SymmetricDecrypt>(void) { | 
326  | 0  |         return ::Botan::Cipher_Dir::Decryption;  | 
327  | 0  |     }  | 
328  |  |  | 
329  |  |     template <class OperationType>  | 
330  |  |     std::optional<size_t> GetTagSize(const OperationType& op);  | 
331  |  |  | 
332  |  |     template <>  | 
333  | 0  |     std::optional<size_t> GetTagSize<>(const operation::SymmetricEncrypt& op) { | 
334  | 0  |         if ( op.tagSize == std::nullopt ) { | 
335  | 0  |             return std::nullopt;  | 
336  | 0  |         }  | 
337  |  |  | 
338  | 0  |         return *op.tagSize;  | 
339  | 0  |     }  | 
340  |  |  | 
341  |  |     template <>  | 
342  | 0  |     std::optional<size_t> GetTagSize<>(const operation::SymmetricDecrypt& op) { | 
343  | 0  |         if ( op.tag == std::nullopt ) { | 
344  | 0  |             return std::nullopt;  | 
345  | 0  |         }  | 
346  |  |  | 
347  | 0  |         return op.tag->GetSize();  | 
348  | 0  |     }  | 
349  |  |  | 
350  |  |     template <class OperationType>  | 
351  |  |     const uint8_t* GetTagPtr(const OperationType& op);  | 
352  |  |  | 
353  |  |     template <>  | 
354  | 0  |     const uint8_t* GetTagPtr<>(const operation::SymmetricEncrypt& op) { | 
355  | 0  |         (void)op;  | 
356  |  | 
  | 
357  | 0  |         return nullptr;  | 
358  | 0  |     }  | 
359  |  |  | 
360  |  |     template <>  | 
361  | 0  |     const uint8_t* GetTagPtr<>(const operation::SymmetricDecrypt& op) { | 
362  | 0  |         if ( op.tag == std::nullopt ) { | 
363  | 0  |             return nullptr;  | 
364  | 0  |         }  | 
365  |  |  | 
366  | 0  |         return op.tag->GetPtr();  | 
367  | 0  |     }  | 
368  |  |  | 
369  |  |     template <class CryptClass>  | 
370  |  |     void SetAAD(std::shared_ptr<CryptClass> crypt, const std::optional<component::AAD>& aad);  | 
371  |  |  | 
372  |  |     template <>  | 
373  | 0  |     void SetAAD<>(std::shared_ptr<::Botan::AEAD_Mode> crypt, const std::optional<component::AAD>& aad) { | 
374  | 0  |         if ( aad != std::nullopt ) { | 
375  | 0  |             crypt->set_associated_data(aad->Get());  | 
376  | 0  |         }  | 
377  | 0  |     }  | 
378  |  |  | 
379  |  |     template <>  | 
380  | 0  |     void SetAAD<>(std::shared_ptr<::Botan::Cipher_Mode> crypt, const std::optional<component::AAD>& aad) { | 
381  | 0  |         (void)crypt;  | 
382  | 0  |         (void)aad;  | 
383  | 0  |     }  | 
384  |  |  | 
385  |  |     template <class OperationType>  | 
386  | 0  |     ::Botan::secure_vector<uint8_t> GetInData(const OperationType& op) { | 
387  | 0  |         const auto inPtr = GetInPtr(op);  | 
388  | 0  |         ::Botan::secure_vector<uint8_t> ret(inPtr, inPtr + GetInSize(op));  | 
389  |  | 
  | 
390  | 0  |         if ( GetCryptType<OperationType>() == ::Botan::Cipher_Dir::Encryption ) { | 
391  | 0  |             return ret;  | 
392  | 0  |         }  | 
393  |  |  | 
394  | 0  |         const auto tagSize = GetTagSize(op);  | 
395  |  | 
  | 
396  | 0  |         if ( tagSize == std::nullopt || *tagSize == 0 ) { | 
397  | 0  |             return ret;  | 
398  | 0  |         }  | 
399  |  |  | 
400  |  |         /* Append the tag */  | 
401  |  |  | 
402  | 0  |         ret.resize(ret.size() + *tagSize);  | 
403  |  | 
  | 
404  | 0  |         memcpy(ret.data() + GetInSize(op), GetTagPtr(op), *tagSize);  | 
405  |  | 
  | 
406  | 0  |         return ret;  | 
407  | 0  |     } Unexecuted instantiation: std::__1::vector<unsigned char, Botan::secure_allocator<unsigned char> > cryptofuzz::module::Botan_detail::GetInData<cryptofuzz::operation::SymmetricEncrypt>(cryptofuzz::operation::SymmetricEncrypt const&) Unexecuted instantiation: std::__1::vector<unsigned char, Botan::secure_allocator<unsigned char> > cryptofuzz::module::Botan_detail::GetInData<cryptofuzz::operation::SymmetricDecrypt>(cryptofuzz::operation::SymmetricDecrypt const&)  | 
408  |  |  | 
409  |  |     template <class ReturnType>  | 
410  |  |     ReturnType ToReturnType(const ::Botan::secure_vector<uint8_t>& data, std::optional<size_t> tagSize);  | 
411  |  |  | 
412  |  |     template <>  | 
413  | 0  |     component::Ciphertext ToReturnType(const ::Botan::secure_vector<uint8_t>& data, std::optional<size_t> tagSize) { | 
414  | 0  |         if ( tagSize == std::nullopt ) { | 
415  | 0  |             return component::Ciphertext(Buffer(data.data(), data.size()));  | 
416  | 0  |         }  | 
417  |  |  | 
418  | 0  |         const size_t ciphertextSize = data.size() - *tagSize;  | 
419  |  | 
  | 
420  | 0  |         return component::Ciphertext(Buffer(data.data(), ciphertextSize), Buffer(data.data() + ciphertextSize, *tagSize));  | 
421  | 0  |     }  | 
422  |  |  | 
423  |  |     template <>  | 
424  | 0  |     component::Cleartext ToReturnType(const ::Botan::secure_vector<uint8_t>& data, std::optional<size_t> tagSize) { | 
425  | 0  |         (void)tagSize;  | 
426  |  | 
  | 
427  | 0  |         return component::Cleartext(Buffer(data.data(), data.size()));  | 
428  | 0  |     }  | 
429  |  |  | 
430  |  |     template <class ReturnType, class OperationType, class CryptClass>  | 
431  | 0  |         std::optional<ReturnType> Crypt(OperationType& op, Datasource& ds) { | 
432  | 0  |             std::optional<ReturnType> ret = std::nullopt;  | 
433  |  | 
  | 
434  | 0  |             if ( typeid(CryptClass) == typeid(::Botan::Cipher_Mode) ) { | 
435  | 0  |                 if ( op.aad != std::nullopt ) { | 
436  | 0  |                     return std::nullopt;  | 
437  | 0  |                 }  | 
438  | 0  |                 if ( GetTagSize(op) != std::nullopt ) { | 
439  | 0  |                     return std::nullopt;  | 
440  | 0  |                 }  | 
441  | 0  |             }  | 
442  |  |  | 
443  | 0  |             std::shared_ptr<CryptClass> crypt = nullptr;  | 
444  | 0  |             const ::Botan::SymmetricKey key(op.cipher.key.GetPtr(), op.cipher.key.GetSize());  | 
445  | 0  |             const ::Botan::InitializationVector iv(op.cipher.iv.GetPtr(), op.cipher.iv.GetSize());  | 
446  | 0  |             ::Botan::secure_vector<uint8_t> in = GetInData(op);  | 
447  | 0  |             ::Botan::secure_vector<uint8_t> out;  | 
448  | 0  |             bool useOneShot = true;  | 
449  | 0  |             util::Multipart parts;  | 
450  |  | 
  | 
451  | 0  |             const std::optional<size_t> tagSize = GetTagSize(op);  | 
452  |  | 
  | 
453  | 0  |             try { | 
454  |  |                 /* Initialize */  | 
455  | 0  |                 { | 
456  | 0  |                     std::optional<std::string> _algoString;  | 
457  | 0  |                     CF_CHECK_NE(_algoString = Botan_detail::CipherIDToString(op.cipher.cipherType.Get()), std::nullopt);  | 
458  | 0  |                     std::string algoString;  | 
459  | 0  |                     if ( tagSize == std::nullopt ) { | 
460  | 0  |                         algoString = Botan_detail::parenthesize(*_algoString, std::to_string(0));  | 
461  | 0  |                     } else { | 
462  | 0  |                         algoString = Botan_detail::parenthesize(*_algoString, std::to_string(*tagSize));  | 
463  | 0  |                     }  | 
464  |  | 
  | 
465  | 0  |                     CF_CHECK_NE(crypt = CryptClass::create(algoString, GetCryptType<OperationType>()), nullptr);  | 
466  | 0  |                     crypt->set_key(key);  | 
467  |  | 
  | 
468  | 0  |                     SetAAD(crypt, op.aad);  | 
469  |  | 
  | 
470  | 0  |                     crypt->start(iv.bits_of());  | 
471  | 0  |                     if ( crypt->update_granularity() == 1 ) { | 
472  | 0  |                         try { | 
473  | 0  |                             useOneShot = ds.Get<bool>();  | 
474  | 0  |                         } catch ( fuzzing::datasource::Datasource::OutOfData ) { } | 
475  | 0  |                     }  | 
476  | 0  |                     if ( useOneShot == false ) { | 
477  | 0  |                         parts = util::ToParts(ds, GetInPtr(op), GetInSize(op));  | 
478  | 0  |                     }  | 
479  | 0  |                 }  | 
480  |  |  | 
481  |  |                 /* Process */  | 
482  | 0  |                 { | 
483  | 0  |                     if ( useOneShot == true ) { | 
484  | 0  |                         crypt->finish(in);  | 
485  | 0  |                     } else { | 
486  | 0  |                         for (const auto& part : parts) { | 
487  | 0  |                             std::vector<uint8_t> tmp(part.first, part.first + part.second);  | 
488  | 0  |                             const auto num = crypt->process(tmp.data(), tmp.size());  | 
489  | 0  |                             out.insert(out.end(), tmp.begin(), tmp.begin() + num);  | 
490  | 0  |                         }  | 
491  | 0  |                         crypt->finish(out, out.size());  | 
492  | 0  |                     }  | 
493  | 0  |                 }  | 
494  |  |  | 
495  |  |                 /* Finalize */  | 
496  | 0  |                 { | 
497  |  |                     /* TODO take max output size in consideration */  | 
498  |  | 
  | 
499  | 0  |                     if ( useOneShot == true ) { | 
500  | 0  |                         ret = ToReturnType<ReturnType>(in, tagSize);  | 
501  | 0  |                     } else { | 
502  | 0  |                         ret = ToReturnType<ReturnType>(::Botan::secure_vector<uint8_t>(out.data(), out.data() + out.size()), tagSize);  | 
503  | 0  |                     }  | 
504  | 0  |                 }  | 
505  | 0  |             } catch ( ... ) { } | 
506  | 0  | end:  | 
507  |  | 
  | 
508  | 0  |             return ret;  | 
509  | 0  |         } Unexecuted instantiation: std::__1::optional<cryptofuzz::component::Ciphertext> cryptofuzz::module::Botan_detail::Crypt<cryptofuzz::component::Ciphertext, cryptofuzz::operation::SymmetricEncrypt, Botan::AEAD_Mode>(cryptofuzz::operation::SymmetricEncrypt&, fuzzing::datasource::Datasource&) Unexecuted instantiation: std::__1::optional<cryptofuzz::component::Ciphertext> cryptofuzz::module::Botan_detail::Crypt<cryptofuzz::component::Ciphertext, cryptofuzz::operation::SymmetricEncrypt, Botan::Cipher_Mode>(cryptofuzz::operation::SymmetricEncrypt&, fuzzing::datasource::Datasource&) Unexecuted instantiation: std::__1::optional<cryptofuzz::Buffer> cryptofuzz::module::Botan_detail::Crypt<cryptofuzz::Buffer, cryptofuzz::operation::SymmetricDecrypt, Botan::AEAD_Mode>(cryptofuzz::operation::SymmetricDecrypt&, fuzzing::datasource::Datasource&) Unexecuted instantiation: std::__1::optional<cryptofuzz::Buffer> cryptofuzz::module::Botan_detail::Crypt<cryptofuzz::Buffer, cryptofuzz::operation::SymmetricDecrypt, Botan::Cipher_Mode>(cryptofuzz::operation::SymmetricDecrypt&, fuzzing::datasource::Datasource&)  | 
510  |  |  | 
511  |  | } /* namespace Botan_detail */  | 
512  |  |  | 
513  | 0  | std::optional<component::MAC> Botan::OpCMAC(operation::CMAC& op) { | 
514  | 0  |     if ( !repository::IsCBC(op.cipher.cipherType.Get()) ) { | 
515  | 0  |         return std::nullopt;  | 
516  | 0  |     }  | 
517  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
518  | 0  |     std::optional<component::MAC> ret = std::nullopt;  | 
519  | 0  |     std::unique_ptr<::Botan::MessageAuthenticationCode> cmac = nullptr;  | 
520  | 0  |     util::Multipart parts;  | 
521  |  | 
  | 
522  | 0  |     try { | 
523  |  |         /* Initialize */  | 
524  | 0  |         { | 
525  | 0  |             BOTAN_SET_GLOBAL_DS  | 
526  |  | 
  | 
527  | 0  |             std::optional<std::string> algoString;  | 
528  | 0  |             CF_CHECK_NE(algoString = Botan_detail::CipherIDToString(op.cipher.cipherType.Get(), false), std::nullopt);  | 
529  |  | 
  | 
530  | 0  |             const std::string cmacString = Botan_detail::parenthesize("CMAC", *algoString); | 
531  |  | 
  | 
532  | 0  |             CF_CHECK_NE(cmac = ::Botan::MessageAuthenticationCode::create(cmacString), nullptr);  | 
533  |  | 
  | 
534  | 0  |             try { | 
535  | 0  |                 cmac->set_key(op.cipher.key.GetPtr(), op.cipher.key.GetSize());  | 
536  | 0  |             } catch ( ... ) { | 
537  | 0  |                 goto end;  | 
538  | 0  |             }  | 
539  |  |  | 
540  | 0  |             parts = util::ToParts(ds, op.cleartext);  | 
541  | 0  |         }  | 
542  |  |  | 
543  |  |         /* Process */  | 
544  | 0  |         for (const auto& part : parts) { | 
545  | 0  |             cmac->update(part.first, part.second);  | 
546  | 0  |         }  | 
547  |  |  | 
548  |  |         /* Finalize */  | 
549  | 0  |         { | 
550  | 0  |             const auto res = cmac->final();  | 
551  | 0  |             ret = component::MAC(res.data(), res.size());  | 
552  | 0  |         }  | 
553  |  | 
  | 
554  | 0  |     } catch ( ... ) { } | 
555  |  |  | 
556  | 0  | end:  | 
557  | 0  |     BOTAN_UNSET_GLOBAL_DS  | 
558  |  | 
  | 
559  | 0  |     return ret;  | 
560  | 0  | }  | 
561  |  |  | 
562  | 0  | std::optional<component::Ciphertext> Botan::OpSymmetricEncrypt(operation::SymmetricEncrypt& op) { | 
563  | 0  |     if ( op.cipher.cipherType.Is(CF_CIPHER("CHACHA20_POLY1305")) && op.cipher.iv.GetSize() == 24 ) { | 
564  |  |         /* Botan interpretes CHACHA20_POLY1305 + 192 bits IV as XCHACHA20_POLY1305 */  | 
565  | 0  |         return std::nullopt;  | 
566  | 0  |     }  | 
567  |  |  | 
568  | 0  |     std::optional<component::Ciphertext> ret = std::nullopt;  | 
569  |  | 
  | 
570  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
571  | 0  |     BOTAN_SET_GLOBAL_DS  | 
572  |  | 
  | 
573  | 0  |     if ( cryptofuzz::repository::IsAEAD(op.cipher.cipherType.Get()) ) { | 
574  | 0  |         ret = Botan_detail::Crypt<component::Ciphertext, operation::SymmetricEncrypt, ::Botan::AEAD_Mode>(op, ds);  | 
575  | 0  |     } else { | 
576  | 0  |         ret = Botan_detail::Crypt<component::Ciphertext, operation::SymmetricEncrypt, ::Botan::Cipher_Mode>(op, ds);  | 
577  | 0  |     }  | 
578  |  |  | 
579  |  |     BOTAN_UNSET_GLOBAL_DS  | 
580  |  | 
  | 
581  | 0  |     return ret;  | 
582  | 0  | }  | 
583  |  |  | 
584  | 0  | std::optional<component::Cleartext> Botan::OpSymmetricDecrypt(operation::SymmetricDecrypt& op) { | 
585  | 0  |     if ( op.cipher.cipherType.Is(CF_CIPHER("CHACHA20_POLY1305")) && op.cipher.iv.GetSize() == 24 ) { | 
586  | 0  |         return std::nullopt;  | 
587  | 0  |     }  | 
588  |  |  | 
589  | 0  |     std::optional<component::Cleartext> ret = std::nullopt;  | 
590  |  | 
  | 
591  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
592  | 0  |     BOTAN_SET_GLOBAL_DS  | 
593  |  | 
  | 
594  | 0  |     if ( cryptofuzz::repository::IsAEAD(op.cipher.cipherType.Get()) ) { | 
595  | 0  |         ret = Botan_detail::Crypt<component::Cleartext, operation::SymmetricDecrypt, ::Botan::AEAD_Mode>(op, ds);  | 
596  | 0  |     } else { | 
597  | 0  |         ret = Botan_detail::Crypt<component::Cleartext, operation::SymmetricDecrypt, ::Botan::Cipher_Mode>(op, ds);  | 
598  | 0  |     }  | 
599  |  |  | 
600  |  |     BOTAN_UNSET_GLOBAL_DS  | 
601  |  | 
  | 
602  | 0  |     return ret;  | 
603  | 0  | }  | 
604  |  |  | 
605  | 0  | std::optional<component::Key> Botan::OpKDF_SCRYPT(operation::KDF_SCRYPT& op) { | 
606  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
607  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
608  | 0  |     std::unique_ptr<::Botan::PasswordHashFamily> pwdhash_fam = nullptr;  | 
609  | 0  |     std::unique_ptr<::Botan::PasswordHash> pwdhash = nullptr;  | 
610  | 0  |     uint8_t* out = util::malloc(op.keySize);  | 
611  |  | 
  | 
612  | 0  |     try { | 
613  |  |         /* Initialize */  | 
614  | 0  |         { | 
615  | 0  |             BOTAN_SET_GLOBAL_DS  | 
616  |  | 
  | 
617  | 0  |             CF_CHECK_NE(pwdhash_fam = ::Botan::PasswordHashFamily::create("Scrypt"), nullptr); | 
618  | 0  |             CF_CHECK_NE(pwdhash = pwdhash_fam->from_params(op.N, op.r, op.p), nullptr);  | 
619  |  | 
  | 
620  | 0  |         }  | 
621  |  |  | 
622  |  |         /* Process */  | 
623  | 0  |         { | 
624  | 0  |             pwdhash->derive_key(  | 
625  | 0  |                     out,  | 
626  | 0  |                     op.keySize,  | 
627  | 0  |                     (const char*)op.password.GetPtr(),  | 
628  | 0  |                     op.password.GetSize(),  | 
629  | 0  |                     op.salt.GetPtr(),  | 
630  | 0  |                     op.salt.GetSize());  | 
631  | 0  |         }  | 
632  |  |  | 
633  |  |         /* Finalize */  | 
634  | 0  |         { | 
635  | 0  |             ret = component::Key(out, op.keySize);  | 
636  | 0  |         }  | 
637  | 0  |     } catch ( ... ) { } | 
638  |  |  | 
639  | 0  | end:  | 
640  | 0  |     util::free(out);  | 
641  |  |  | 
642  |  |     BOTAN_UNSET_GLOBAL_DS  | 
643  |  | 
  | 
644  | 0  |     return ret;  | 
645  | 0  | }  | 
646  |  |  | 
647  | 266  | std::optional<component::Key> Botan::OpKDF_HKDF(operation::KDF_HKDF& op) { | 
648  | 266  |     std::optional<component::Key> ret = std::nullopt;  | 
649  | 266  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
650  | 266  |     std::unique_ptr<::Botan::KDF> hkdf = nullptr;  | 
651  |  |  | 
652  | 266  |     try { | 
653  | 266  |         { | 
654  | 266  |             BOTAN_SET_GLOBAL_DS  | 
655  |  |  | 
656  | 266  |             std::optional<std::string> algoString;  | 
657  | 266  |             CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get(), true), std::nullopt);  | 
658  |  |  | 
659  | 266  |             const std::string hkdfString = Botan_detail::parenthesize("HKDF", *algoString); | 
660  | 266  |             hkdf = ::Botan::KDF::create(hkdfString);  | 
661  | 266  |         }  | 
662  |  |  | 
663  | 0  |         { | 
664  | 266  |             auto derived = hkdf->derive_key(op.keySize, op.password.Get(), op.salt.Get(), op.info.Get());  | 
665  |  |  | 
666  | 266  |             ret = component::Key(derived.data(), derived.size());  | 
667  | 266  |         }  | 
668  | 266  |     } catch ( ... ) { } | 
669  |  |  | 
670  | 266  | end:  | 
671  | 266  |     BOTAN_UNSET_GLOBAL_DS  | 
672  |  |  | 
673  | 266  |     return ret;  | 
674  | 266  | }  | 
675  |  |  | 
676  | 0  | std::optional<component::Key> Botan::OpKDF_PBKDF2(operation::KDF_PBKDF2& op) { | 
677  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
678  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
679  | 0  |     std::unique_ptr<::Botan::PasswordHashFamily> pwdhash_fam = nullptr;  | 
680  | 0  |     std::unique_ptr<::Botan::PasswordHash> pwdhash = nullptr;  | 
681  | 0  |     uint8_t* out = util::malloc(op.keySize);  | 
682  |  | 
  | 
683  | 0  |     try { | 
684  |  |         /* Initialize */  | 
685  | 0  |         { | 
686  | 0  |             BOTAN_SET_GLOBAL_DS  | 
687  |  | 
  | 
688  | 0  |             std::optional<std::string> algoString;  | 
689  | 0  |             CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get(), true), std::nullopt);  | 
690  |  | 
  | 
691  | 0  |             const std::string pbkdf2String = Botan_detail::parenthesize("PBKDF2", *algoString); | 
692  | 0  |             CF_CHECK_NE(pwdhash_fam = ::Botan::PasswordHashFamily::create(pbkdf2String), nullptr);  | 
693  |  | 
  | 
694  | 0  |             CF_CHECK_NE(pwdhash = pwdhash_fam->from_params(op.iterations), nullptr);  | 
695  |  | 
  | 
696  | 0  |         }  | 
697  |  |  | 
698  |  |         /* Process */  | 
699  | 0  |         { | 
700  | 0  |             pwdhash->derive_key(  | 
701  | 0  |                     out,  | 
702  | 0  |                     op.keySize,  | 
703  | 0  |                     (const char*)op.password.GetPtr(),  | 
704  | 0  |                     op.password.GetSize(),  | 
705  | 0  |                     op.salt.GetPtr(),  | 
706  | 0  |                     op.salt.GetSize());  | 
707  | 0  |         }  | 
708  |  |  | 
709  |  |         /* Finalize */  | 
710  | 0  |         { | 
711  | 0  |             ret = component::Key(out, op.keySize);  | 
712  | 0  |         }  | 
713  | 0  |     } catch ( ... ) { } | 
714  |  |  | 
715  | 0  | end:  | 
716  | 0  |     util::free(out);  | 
717  |  |  | 
718  |  |     BOTAN_UNSET_GLOBAL_DS  | 
719  |  | 
  | 
720  | 0  |     return ret;  | 
721  | 0  | }  | 
722  |  |  | 
723  | 0  | std::optional<component::Key> Botan::OpKDF_ARGON2(operation::KDF_ARGON2& op) { | 
724  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
725  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
726  | 0  |     std::unique_ptr<::Botan::PasswordHashFamily> pwdhash_fam = nullptr;  | 
727  | 0  |     std::unique_ptr<::Botan::PasswordHash> pwdhash = nullptr;  | 
728  | 0  |     uint8_t* out = util::malloc(op.keySize);  | 
729  |  | 
  | 
730  | 0  |     try { | 
731  |  |         /* Initialize */  | 
732  | 0  |         { | 
733  | 0  |             BOTAN_SET_GLOBAL_DS  | 
734  |  | 
  | 
735  | 0  |             std::string argon2String;  | 
736  |  | 
  | 
737  | 0  |             switch ( op.type ) { | 
738  | 0  |                 case    0:  | 
739  | 0  |                     argon2String = "Argon2d";  | 
740  | 0  |                     break;  | 
741  | 0  |                 case    1:  | 
742  | 0  |                     argon2String = "Argon2i";  | 
743  | 0  |                     break;  | 
744  | 0  |                 case    2:  | 
745  | 0  |                     argon2String = "Argon2id";  | 
746  | 0  |                     break;  | 
747  | 0  |                 default:  | 
748  | 0  |                     goto end;  | 
749  | 0  |             }  | 
750  | 0  |             CF_CHECK_NE(pwdhash_fam = ::Botan::PasswordHashFamily::create(argon2String), nullptr);  | 
751  |  | 
  | 
752  | 0  |             CF_CHECK_NE(pwdhash = pwdhash_fam->from_params(  | 
753  | 0  |                         op.memory,  | 
754  | 0  |                         op.iterations,  | 
755  | 0  |                         op.threads), nullptr);  | 
756  | 0  |         }  | 
757  |  |  | 
758  |  |         /* Process */  | 
759  | 0  |         { | 
760  | 0  |             pwdhash->derive_key(  | 
761  | 0  |                     out,  | 
762  | 0  |                     op.keySize,  | 
763  | 0  |                     (const char*)op.password.GetPtr(),  | 
764  | 0  |                     op.password.GetSize(),  | 
765  | 0  |                     op.salt.GetPtr(),  | 
766  | 0  |                     op.salt.GetSize());  | 
767  | 0  |         }  | 
768  |  |  | 
769  |  |         /* Finalize */  | 
770  | 0  |         { | 
771  | 0  |             ret = component::Key(out, op.keySize);  | 
772  | 0  |         }  | 
773  | 0  |     } catch ( ... ) { } | 
774  |  |  | 
775  | 0  | end:  | 
776  | 0  |     util::free(out);  | 
777  |  |  | 
778  |  |     BOTAN_UNSET_GLOBAL_DS  | 
779  |  | 
  | 
780  | 0  |     return ret;  | 
781  | 0  | }  | 
782  |  |  | 
783  | 0  | std::optional<component::Key> Botan::OpKDF_SP_800_108(operation::KDF_SP_800_108& op) { | 
784  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
785  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
786  | 0  |     uint8_t* out = util::malloc(op.keySize);  | 
787  | 0  |     std::unique_ptr<::Botan::KDF> sp_800_108 = nullptr;  | 
788  |  | 
  | 
789  | 0  |     try { | 
790  | 0  |         BOTAN_SET_GLOBAL_DS  | 
791  |  | 
  | 
792  | 0  |         std::optional<std::string> algoString;  | 
793  | 0  |         CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.mech.type.Get(), true), std::nullopt);  | 
794  |  | 
  | 
795  | 0  |         const std::string hmacString = Botan_detail::parenthesize("HMAC", *algoString); | 
796  | 0  |         std::string sp_800_108_string;  | 
797  | 0  |         switch ( op.mode ) { | 
798  | 0  |             case    0:  | 
799  | 0  |                 sp_800_108_string = Botan_detail::parenthesize("SP800-108-Counter", hmacString); | 
800  | 0  |                 break;  | 
801  | 0  |             case    1:  | 
802  | 0  |                 sp_800_108_string = Botan_detail::parenthesize("SP800-108-Feedback", hmacString); | 
803  | 0  |                 break;  | 
804  | 0  |             case    2:  | 
805  | 0  |                 sp_800_108_string = Botan_detail::parenthesize("SP800-108-Pipeline", hmacString); | 
806  | 0  |                 break;  | 
807  | 0  |             default:  | 
808  | 0  |                 goto end;  | 
809  | 0  |         }  | 
810  |  |  | 
811  | 0  |         sp_800_108 = ::Botan::KDF::create(sp_800_108_string);  | 
812  |  | 
  | 
813  | 0  |         { | 
814  | 0  |             auto derived = sp_800_108->derive_key(op.keySize, op.secret.Get(), op.salt.Get(), op.label.Get());  | 
815  |  | 
  | 
816  | 0  |             ret = component::Key(derived.data(), derived.size());  | 
817  | 0  |         }  | 
818  | 0  |     } catch ( ... ) { } | 
819  |  |  | 
820  | 0  | end:  | 
821  | 0  |     util::free(out);  | 
822  |  |  | 
823  |  |     BOTAN_UNSET_GLOBAL_DS  | 
824  |  | 
  | 
825  | 0  |     return ret;  | 
826  | 0  | }  | 
827  |  |  | 
828  | 0  | std::optional<component::Key> Botan::OpKDF_TLS1_PRF(operation::KDF_TLS1_PRF& op) { | 
829  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
830  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
831  | 0  |     std::unique_ptr<::Botan::KDF> tlsprf = nullptr;  | 
832  |  | 
  | 
833  | 0  |     try { | 
834  | 0  |         BOTAN_SET_GLOBAL_DS  | 
835  |  | 
  | 
836  | 0  |         { | 
837  | 0  |             CF_CHECK_EQ(op.digestType.Get(), CF_DIGEST("MD5_SHA1")); | 
838  | 0  |             CF_CHECK_NE(tlsprf = ::Botan::KDF::create("TLS-PRF()"), nullptr); | 
839  | 0  |         }  | 
840  |  |  | 
841  | 0  |         { | 
842  | 0  |             const auto derived = tlsprf->derive_key(op.keySize, op.secret.Get(), op.seed.Get(), std::vector<uint8_t>{}); | 
843  |  | 
  | 
844  | 0  |             ret = component::Key(derived.data(), derived.size());  | 
845  | 0  |         }  | 
846  | 0  |     } catch ( ... ) { } | 
847  |  |  | 
848  | 0  | end:  | 
849  | 0  |     BOTAN_UNSET_GLOBAL_DS  | 
850  |  | 
  | 
851  | 0  |     return ret;  | 
852  | 0  | }  | 
853  |  |  | 
854  | 0  | std::optional<component::Key> Botan::OpKDF_BCRYPT(operation::KDF_BCRYPT& op) { | 
855  | 0  |     std::optional<component::Key> ret = std::nullopt;  | 
856  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
857  | 0  |     std::unique_ptr<::Botan::PasswordHashFamily> pwdhash_fam = nullptr;  | 
858  | 0  |     std::unique_ptr<::Botan::PasswordHash> pwdhash = nullptr;  | 
859  | 0  |     uint8_t* out = util::malloc(op.keySize);  | 
860  |  | 
  | 
861  | 0  |     try { | 
862  | 0  |         BOTAN_SET_GLOBAL_DS  | 
863  |  |  | 
864  |  |         /* Initialize */  | 
865  | 0  |         { | 
866  | 0  |             CF_CHECK_EQ(op.digestType.Get(), CF_DIGEST("SHA512")); | 
867  | 0  |             CF_CHECK_NE(pwdhash_fam = ::Botan::PasswordHashFamily::create("Bcrypt-PBKDF"), nullptr); | 
868  | 0  |             CF_CHECK_NE(pwdhash = pwdhash_fam->from_params(op.iterations), nullptr);  | 
869  |  | 
  | 
870  | 0  |         }  | 
871  |  |  | 
872  |  |         /* Process */  | 
873  | 0  |         { | 
874  | 0  |             pwdhash->derive_key(  | 
875  | 0  |                     out,  | 
876  | 0  |                     op.keySize,  | 
877  | 0  |                     (const char*)op.secret.GetPtr(),  | 
878  | 0  |                     op.secret.GetSize(),  | 
879  | 0  |                     op.salt.GetPtr(),  | 
880  | 0  |                     op.salt.GetSize());  | 
881  | 0  |         }  | 
882  |  |  | 
883  |  |         /* Finalize */  | 
884  | 0  |         { | 
885  | 0  |             ret = component::Key(out, op.keySize);  | 
886  | 0  |         }  | 
887  | 0  |     } catch ( ... ) { } | 
888  |  |  | 
889  | 0  | end:  | 
890  | 0  |     util::free(out);  | 
891  |  |  | 
892  |  |     BOTAN_UNSET_GLOBAL_DS  | 
893  |  | 
  | 
894  | 0  |     return ret;  | 
895  | 0  | }  | 
896  |  |  | 
897  |  | namespace Botan_detail { | 
898  | 0  |     std::optional<std::string> CurveIDToString(const uint64_t curveID) { | 
899  | 0  | #include "curve_string_lut.h"  | 
900  | 0  |         std::optional<std::string> ret = std::nullopt;  | 
901  |  | 
  | 
902  | 0  |         CF_CHECK_NE(LUT.find(curveID), LUT.end());  | 
903  | 0  |         ret = LUT.at(curveID);  | 
904  | 0  | end:  | 
905  | 0  |         return ret;  | 
906  | 0  |     }  | 
907  |  | } /* namespace Botan_detail */  | 
908  |  |  | 
909  | 0  | std::optional<component::ECC_KeyPair> Botan::OpECC_GenerateKeyPair(operation::ECC_GenerateKeyPair& op) { | 
910  | 0  |     std::optional<component::ECC_KeyPair> ret = std::nullopt;  | 
911  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
912  |  | 
  | 
913  | 0  |     std::optional<std::string> curveString;  | 
914  | 0  |     BOTAN_FUZZER_RNG;  | 
915  |  | 
  | 
916  | 0  |     CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
917  |  | 
  | 
918  | 0  |     try { | 
919  | 0  |         ::Botan::EC_Group group(*curveString);  | 
920  | 0  |         auto priv = ::Botan::ECDSA_PrivateKey(rng, group);  | 
921  |  | 
  | 
922  | 0  |         const auto pub_x = priv.public_point().get_affine_x();  | 
923  | 0  |         const auto pub_y = priv.public_point().get_affine_y();  | 
924  |  | 
  | 
925  | 0  |         { | 
926  | 0  |             const auto pub = std::make_unique<::Botan::ECDSA_PublicKey>(::Botan::ECDSA_PublicKey(group, priv.public_point()));  | 
927  | 0  |             CF_ASSERT(pub->check_key(rng, true) == true, "Generated pubkey fails validation");  | 
928  | 0  |         }  | 
929  |  |  | 
930  | 0  |         ret = { priv.private_value().to_dec_string(), { pub_x.to_dec_string(), pub_y.to_dec_string() } }; | 
931  |  |  | 
932  |  |       /* Catch exception thrown from Botan_detail::Fuzzer_RNG::randomize */  | 
933  | 0  |     } catch ( fuzzing::datasource::Datasource::OutOfData ) { } | 
934  |  |  | 
935  | 0  | end:  | 
936  | 0  |     return ret;  | 
937  | 0  | }  | 
938  |  |  | 
939  | 0  | std::optional<bool> Botan::OpECC_ValidatePubkey(operation::ECC_ValidatePubkey& op) { | 
940  | 0  |     std::optional<bool> ret = std::nullopt;  | 
941  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
942  |  | 
  | 
943  | 0  |     BOTAN_FUZZER_RNG;  | 
944  | 0  |     std::unique_ptr<::Botan::Public_Key> pub = nullptr;  | 
945  |  | 
  | 
946  | 0  |     try { | 
947  | 0  |         std::optional<std::string> curveString;  | 
948  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
949  |  | 
  | 
950  | 0  |         ::Botan::EC_Group group(*curveString);  | 
951  | 0  |         const ::Botan::BigInt pub_x(op.pub.first.ToString(ds));  | 
952  | 0  |         const ::Botan::BigInt pub_y(op.pub.second.ToString(ds));  | 
953  | 0  |         const ::Botan::PointGFp public_point = group.point(pub_x, pub_y);  | 
954  | 0  |         pub = std::make_unique<::Botan::ECDSA_PublicKey>(::Botan::ECDSA_PublicKey(group, public_point));  | 
955  |  | 
  | 
956  | 0  |         ret = pub->check_key(rng, true);  | 
957  | 0  |     } catch ( ... ) { } | 
958  |  |  | 
959  | 0  | end:  | 
960  | 0  |     return ret;  | 
961  | 0  | }  | 
962  |  |  | 
963  | 0  | std::optional<component::ECC_PublicKey> Botan::OpECC_PrivateToPublic(operation::ECC_PrivateToPublic& op) { | 
964  | 0  |     std::optional<component::ECC_PublicKey> ret = std::nullopt;  | 
965  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
966  |  | 
  | 
967  | 0  |     BOTAN_FUZZER_RNG;  | 
968  |  | 
  | 
969  | 0  |     try { | 
970  | 0  |         std::optional<std::string> curveString;  | 
971  |  | 
  | 
972  | 0  |         if ( op.curveType.Get() == CF_ECC_CURVE("x25519") ) { | 
973  | 0  |             uint8_t priv_bytes[32];  | 
974  |  | 
  | 
975  | 0  |             const ::Botan::BigInt priv_bigint(op.priv.ToString(ds));  | 
976  | 0  |             CF_CHECK_GT(priv_bigint, 0);  | 
977  |  | 
  | 
978  | 0  |             priv_bigint.binary_encode(priv_bytes, sizeof(priv_bytes));  | 
979  | 0  |             priv_bytes[0] &= 248;  | 
980  | 0  |             priv_bytes[31] &= 127;  | 
981  | 0  |             priv_bytes[31] |= 64;  | 
982  | 0  |             const ::Botan::secure_vector<uint8_t> priv_vec(priv_bytes, priv_bytes + sizeof(priv_bytes));  | 
983  |  | 
  | 
984  | 0  |             auto priv = ::Botan::X25519_PrivateKey(priv_vec);  | 
985  |  | 
  | 
986  | 0  |             ::Botan::BigInt pub;  | 
987  | 0  |             pub.binary_decode(priv.public_value());  | 
988  |  | 
  | 
989  | 0  |             ret = { pub.to_dec_string(), "0" }; | 
990  | 0  |         } else { | 
991  | 0  |             CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
992  | 0  |             ::Botan::EC_Group group(*curveString);  | 
993  |  | 
  | 
994  | 0  |             const ::Botan::BigInt priv_bn(op.priv.ToString(ds));  | 
995  | 0  |             CF_CHECK_GT(priv_bn, 0);  | 
996  |  | 
  | 
997  | 0  |             auto priv = std::make_unique<::Botan::ECDSA_PrivateKey>(::Botan::ECDSA_PrivateKey(rng, group, priv_bn));  | 
998  |  | 
  | 
999  | 0  |             const auto pub_x = priv->public_point().get_affine_x();  | 
1000  | 0  |             const auto pub_y = priv->public_point().get_affine_y();  | 
1001  |  | 
  | 
1002  | 0  |             ret = { pub_x.to_dec_string(), pub_y.to_dec_string() }; | 
1003  | 0  |         }  | 
1004  | 0  |     } catch ( ... ) { } | 
1005  |  |  | 
1006  | 0  | end:  | 
1007  | 0  |     return ret;  | 
1008  | 0  | }  | 
1009  |  |  | 
1010  |  | namespace Botan_detail { | 
1011  |  |     template <class PrivkeyType, class Operation, bool RFC6979 = true>  | 
1012  | 0  |         std::optional<component::ECDSA_Signature> ECxDSA_Sign(Operation& op) { | 
1013  | 0  |             std::optional<component::ECDSA_Signature> ret = std::nullopt;  | 
1014  | 0  |             Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1015  |  | 
  | 
1016  | 0  |             std::unique_ptr<PrivkeyType> priv = nullptr;  | 
1017  | 0  |             std::unique_ptr<::Botan::Public_Key> pub = nullptr;  | 
1018  | 0  |             std::unique_ptr<::Botan::PK_Signer> signer;  | 
1019  |  | 
  | 
1020  | 0  |             BOTAN_FUZZER_RNG;  | 
1021  |  |  | 
1022  |  |             BOTAN_SET_GLOBAL_DS  | 
1023  |  | 
  | 
1024  | 0  |             if ( RFC6979 == true ) { | 
1025  | 0  |                 CF_CHECK_EQ(op.UseRFC6979Nonce(), true);  | 
1026  | 0  |             } else { | 
1027  | 0  |                 CF_CHECK_EQ(op.UseRandomNonce(), true);  | 
1028  | 0  |             }  | 
1029  |  |  | 
1030  | 0  |             CF_CHECK_EQ(op.digestType.Get(), CF_DIGEST("SHA256")); | 
1031  |  | 
  | 
1032  | 0  |             try { | 
1033  |  |                 /* Initialize */  | 
1034  | 0  |                 { | 
1035  |  | 
  | 
1036  | 0  |                     std::optional<std::string> curveString, algoString;  | 
1037  |  | 
  | 
1038  | 0  |                     CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1039  | 0  |                     ::Botan::EC_Group group(*curveString);  | 
1040  |  |  | 
1041  |  |                     /* Private key */  | 
1042  | 0  |                     { | 
1043  | 0  |                         const ::Botan::BigInt priv_bn(op.priv.ToString(ds));  | 
1044  |  |  | 
1045  |  |                         /* Botan appears to generate a new key if the input key is 0,  | 
1046  |  |                          * so don't do this */  | 
1047  | 0  |                         CF_CHECK_NE(priv_bn, 0);  | 
1048  |  | 
  | 
1049  | 0  |                         priv = std::make_unique<PrivkeyType>(PrivkeyType(rng, group, priv_bn));  | 
1050  | 0  |                     }  | 
1051  |  |  | 
1052  |  |                     /* Prepare signer */  | 
1053  | 0  |                     CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get()), std::nullopt);  | 
1054  |  | 
  | 
1055  | 0  |                     const std::string emsa1String = Botan_detail::parenthesize("EMSA1", *algoString); | 
1056  | 0  |                     signer.reset(new ::Botan::PK_Signer(*priv, rng, emsa1String, ::Botan::Signature_Format::DerSequence));  | 
1057  | 0  |                 }  | 
1058  |  |  | 
1059  |  |                 /* Process */  | 
1060  | 0  |                 { | 
1061  | 0  |                     const auto signature = signer->sign_message(op.cleartext.Get(), rng);  | 
1062  |  |  | 
1063  |  |                     /* Retrieve R and S */  | 
1064  | 0  |                     { | 
1065  | 0  |                         ::Botan::BER_Decoder decoder(signature);  | 
1066  | 0  |                         ::Botan::BER_Decoder ber_sig = decoder.start_sequence();  | 
1067  |  | 
  | 
1068  | 0  |                         size_t count = 0;  | 
1069  |  | 
  | 
1070  | 0  |                         ::Botan::BigInt R;  | 
1071  | 0  |                         ::Botan::BigInt S;  | 
1072  | 0  |                         while(ber_sig.more_items())  | 
1073  | 0  |                         { | 
1074  | 0  |                             switch ( count ) { | 
1075  | 0  |                                 case    0:  | 
1076  | 0  |                                     ber_sig.decode(R);  | 
1077  | 0  |                                     break;  | 
1078  | 0  |                                 case    1:  | 
1079  | 0  |                                     ber_sig.decode(S);  | 
1080  | 0  |                                     break;  | 
1081  | 0  |                                 default:  | 
1082  | 0  |                                     printf("Error: Too many parts in signature BER\n"); | 
1083  | 0  |                                     abort();  | 
1084  | 0  |                             }  | 
1085  |  |  | 
1086  | 0  |                             ++count;  | 
1087  | 0  |                         }  | 
1088  |  |  | 
1089  | 0  |                         if ( op.curveType.Get() == CF_ECC_CURVE("secp256k1") ) { | 
1090  |  |                             /* For compatibility with the secp256k1 library.  | 
1091  |  |                              * See: https://github.com/bitcoin/bips/blob/master/bip-0062.mediawiki#low-s-values-in-signatures  | 
1092  |  |                              */  | 
1093  | 0  |                             if (S > ::Botan::BigInt("57896044618658097711785492504343953926418782139537452191302581570759080747168")) { | 
1094  | 0  |                                 S = ::Botan::BigInt("115792089237316195423570985008687907852837564279074904382605163141518161494337") - S; | 
1095  | 0  |                             }  | 
1096  | 0  |                         } else if ( op.curveType.Get() == CF_ECC_CURVE("secp256r1") ) { | 
1097  |  |                             /* Similar ECDSA signature malleability adjustment for compatibility with trezor-firmware */  | 
1098  | 0  |                             if (S > ::Botan::BigInt("57896044605178124381348723474703786764998477612067880171211129530534256022184")) { | 
1099  | 0  |                                 S = ::Botan::BigInt("115792089210356248762697446949407573529996955224135760342422259061068512044369") - S; | 
1100  | 0  |                             }  | 
1101  | 0  |                         }  | 
1102  |  | 
  | 
1103  | 0  |                         const auto pub_x = priv->public_point().get_affine_x().to_dec_string();  | 
1104  | 0  |                         const auto pub_y = priv->public_point().get_affine_y().to_dec_string();  | 
1105  |  | 
  | 
1106  | 0  |                         const auto R_str = R.to_dec_string();  | 
1107  | 0  |                         const auto S_str = S.to_dec_string();  | 
1108  |  | 
  | 
1109  | 0  |                         ret = component::ECDSA_Signature({ R_str, S_str }, { pub_x, pub_y }); | 
1110  | 0  |                     }  | 
1111  | 0  |                 }  | 
1112  | 0  |             } catch ( ... ) { } | 
1113  |  |  | 
1114  | 0  | end:  | 
1115  | 0  |             BOTAN_UNSET_GLOBAL_DS  | 
1116  |  | 
  | 
1117  | 0  |             return ret;  | 
1118  | 0  |         } Unexecuted instantiation: std::__1::optional<cryptofuzz::component::ECDSA_Signature> cryptofuzz::module::Botan_detail::ECxDSA_Sign<Botan::ECDSA_PrivateKey, cryptofuzz::operation::ECDSA_Sign, true>(cryptofuzz::operation::ECDSA_Sign&) Unexecuted instantiation: std::__1::optional<cryptofuzz::component::ECDSA_Signature> cryptofuzz::module::Botan_detail::ECxDSA_Sign<Botan::ECGDSA_PrivateKey, cryptofuzz::operation::ECGDSA_Sign, false>(cryptofuzz::operation::ECGDSA_Sign&)  | 
1119  |  | } /* namespace Botan_detail */  | 
1120  |  |  | 
1121  | 0  | std::optional<component::ECDSA_Signature> Botan::OpECDSA_Sign(operation::ECDSA_Sign& op) { | 
1122  | 0  |     if ( op.curveType.Is(CF_ECC_CURVE("ed25519")) ) { | 
1123  | 0  |         const auto _priv_bytes = util::DecToBin(op.priv.ToTrimmedString(), 32);  | 
1124  | 0  |         if ( _priv_bytes == std::nullopt ) { | 
1125  | 0  |             return std::nullopt;  | 
1126  | 0  |         }  | 
1127  |  |  | 
1128  | 0  |         const ::Botan::secure_vector<uint8_t> priv_bytes(_priv_bytes->data(), _priv_bytes->data() + _priv_bytes->size());  | 
1129  |  | 
  | 
1130  | 0  |         const auto priv = std::make_unique<::Botan::Ed25519_PrivateKey>(priv_bytes);  | 
1131  |  | 
  | 
1132  | 0  |         std::unique_ptr<::Botan::PK_Signer> signer;  | 
1133  |  | 
  | 
1134  | 0  |         Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1135  | 0  |         BOTAN_FUZZER_RNG;  | 
1136  |  | 
  | 
1137  | 0  |         signer.reset(new ::Botan::PK_Signer(*priv, rng, "Pure", ::Botan::Signature_Format::Standard));  | 
1138  |  | 
  | 
1139  | 0  |         const auto signature = signer->sign_message(op.cleartext.Get(), rng);  | 
1140  | 0  |         CF_ASSERT(signature.size() == 64, "ed25519 signature is not 64 bytes");  | 
1141  |  | 
  | 
1142  | 0  |         const auto pub = priv->get_public_key();  | 
1143  | 0  |         CF_ASSERT(pub.size() == 32, "ed25519 pubkey is not 32 bytes");  | 
1144  |  | 
  | 
1145  | 0  |         const auto ret = component::ECDSA_Signature(  | 
1146  | 0  |                 { util::BinToDec(signature.data(), 32), util::BinToDec(signature.data() + 32, 32) }, | 
1147  | 0  |                 { util::BinToDec(pub.data(), 32), "0"} | 
1148  | 0  |         );  | 
1149  |  | 
  | 
1150  | 0  |         return ret;  | 
1151  | 0  |     }  | 
1152  |  |  | 
1153  | 0  |     return Botan_detail::ECxDSA_Sign<::Botan::ECDSA_PrivateKey, operation::ECDSA_Sign>(op);  | 
1154  | 0  | }  | 
1155  |  |  | 
1156  | 0  | std::optional<component::ECGDSA_Signature> Botan::OpECGDSA_Sign(operation::ECGDSA_Sign& op) { | 
1157  | 0  |     return Botan_detail::ECxDSA_Sign<::Botan::ECGDSA_PrivateKey, operation::ECGDSA_Sign, false>(op);  | 
1158  | 0  | }  | 
1159  |  |  | 
1160  |  | namespace Botan_detail { | 
1161  |  |     template <class PubkeyType, class Operation>  | 
1162  | 0  |         std::optional<bool> ECxDSA_Verify(Operation& op) { | 
1163  | 0  |             std::optional<bool> ret = std::nullopt;  | 
1164  | 0  |             Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1165  |  | 
  | 
1166  | 0  |             ::Botan::secure_vector<uint8_t> sig;  | 
1167  | 0  |             std::unique_ptr<::Botan::Public_Key> pub = nullptr;  | 
1168  | 0  |             std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1169  | 0  |             Buffer CT;  | 
1170  |  | 
  | 
1171  | 0  |             { | 
1172  | 0  |                 BOTAN_SET_GLOBAL_DS  | 
1173  |  | 
  | 
1174  | 0  |                 std::optional<std::string> curveString;  | 
1175  | 0  |                 CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1176  | 0  |                 group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1177  | 0  |             }  | 
1178  |  |  | 
1179  |  |             /* Construct signature */  | 
1180  | 0  |             { | 
1181  | 0  |                 const ::Botan::BigInt R(op.signature.signature.first.ToString(ds));  | 
1182  | 0  |                 const ::Botan::BigInt S(op.signature.signature.second.ToString(ds));  | 
1183  | 0  |                 try { | 
1184  | 0  |                     sig = ::Botan::BigInt::encode_fixed_length_int_pair(R, S, group->get_order_bytes());  | 
1185  | 0  |                 } catch ( ::Botan::Encoding_Error ) { | 
1186  |  |                     /* Invalid signature */  | 
1187  | 0  |                     BOTAN_UNSET_GLOBAL_DS  | 
1188  | 0  |                     return false;  | 
1189  | 0  |                 }  | 
1190  | 0  |             }  | 
1191  |  |  | 
1192  |  |             /* Construct pubkey */  | 
1193  | 0  |             try { | 
1194  | 0  |                 const ::Botan::BigInt pub_x(op.signature.pub.first.ToString(ds));  | 
1195  | 0  |                 const ::Botan::BigInt pub_y(op.signature.pub.second.ToString(ds));  | 
1196  | 0  |                 const ::Botan::PointGFp public_point = group->point(pub_x, pub_y);  | 
1197  | 0  |                 pub = std::make_unique<PubkeyType>(PubkeyType(*group, public_point));  | 
1198  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1199  |  |                 /* Invalid point */  | 
1200  | 0  |                 BOTAN_UNSET_GLOBAL_DS  | 
1201  | 0  |                 return false;  | 
1202  | 0  |             }  | 
1203  |  |  | 
1204  |  |             /* Construct input */  | 
1205  | 0  |             { | 
1206  | 0  |                 if ( op.digestType.Get() == CF_DIGEST("NULL") ) { | 
1207  | 0  |                     CT = op.cleartext.ECDSA_RandomPad(ds, op.curveType);  | 
1208  | 0  |                 } else { | 
1209  | 0  |                     std::optional<std::string> algoString;  | 
1210  | 0  |                     CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get()), std::nullopt);  | 
1211  |  | 
  | 
1212  | 0  |                     auto hash = ::Botan::HashFunction::create(*algoString);  | 
1213  | 0  |                     hash->update(op.cleartext.GetPtr(), op.cleartext.GetSize());  | 
1214  | 0  |                     const auto _CT = hash->final();  | 
1215  | 0  |                     CT = Buffer(_CT.data(), _CT.size()).ECDSA_RandomPad(ds, op.curveType);  | 
1216  | 0  |                 }  | 
1217  | 0  |             }  | 
1218  |  |  | 
1219  | 0  |             ret = ::Botan::PK_Verifier(*pub, "Raw").verify_message(CT.Get(), sig);  | 
1220  |  | 
  | 
1221  | 0  | end:  | 
1222  | 0  |             BOTAN_UNSET_GLOBAL_DS  | 
1223  |  | 
  | 
1224  | 0  |             return ret;  | 
1225  | 0  |         } Unexecuted instantiation: std::__1::optional<bool> cryptofuzz::module::Botan_detail::ECxDSA_Verify<Botan::ECDSA_PublicKey, cryptofuzz::operation::ECDSA_Verify>(cryptofuzz::operation::ECDSA_Verify&) Unexecuted instantiation: std::__1::optional<bool> cryptofuzz::module::Botan_detail::ECxDSA_Verify<Botan::ECGDSA_PublicKey, cryptofuzz::operation::ECGDSA_Verify>(cryptofuzz::operation::ECGDSA_Verify&)  | 
1226  |  | } /* namespace Botan_detail */  | 
1227  |  |  | 
1228  | 0  | std::optional<bool> Botan::OpECDSA_Verify(operation::ECDSA_Verify& op) { | 
1229  | 0  |     if ( op.curveType.Is(CF_ECC_CURVE("ed25519")) ) { | 
1230  | 0  |         const auto pub_bytes = util::DecToBin(op.signature.pub.first.ToTrimmedString(), 32);  | 
1231  | 0  |         if ( pub_bytes == std::nullopt ) { | 
1232  | 0  |             return std::nullopt;  | 
1233  | 0  |         }  | 
1234  | 0  |         const auto pub = std::make_unique<::Botan::Ed25519_PublicKey>(*pub_bytes);  | 
1235  |  | 
  | 
1236  | 0  |         const auto sig_r = util::DecToBin(op.signature.signature.first.ToTrimmedString(), 32);  | 
1237  | 0  |         if ( sig_r == std::nullopt ) { | 
1238  | 0  |             return std::nullopt;  | 
1239  | 0  |         }  | 
1240  |  |  | 
1241  | 0  |         const auto sig_s = util::DecToBin(op.signature.signature.second.ToTrimmedString(), 32);  | 
1242  | 0  |         if ( sig_s == std::nullopt ) { | 
1243  | 0  |             return std::nullopt;  | 
1244  | 0  |         }  | 
1245  |  |  | 
1246  | 0  |         std::vector<uint8_t> sig_bytes(64);  | 
1247  | 0  |         memcpy(sig_bytes.data(), sig_r->data(), 32);  | 
1248  | 0  |         memcpy(sig_bytes.data() + 32, sig_s->data(), 32);  | 
1249  |  | 
  | 
1250  | 0  |         const bool ret = ::Botan::PK_Verifier(*pub, "Pure").verify_message(op.cleartext.Get(), sig_bytes);  | 
1251  | 0  |         return ret;  | 
1252  |  | 
  | 
1253  | 0  |     } else { | 
1254  | 0  |         return Botan_detail::ECxDSA_Verify<::Botan::ECDSA_PublicKey, operation::ECDSA_Verify>(op);  | 
1255  | 0  |     }  | 
1256  | 0  | }  | 
1257  |  |  | 
1258  | 0  | std::optional<bool> Botan::OpECGDSA_Verify(operation::ECGDSA_Verify& op) { | 
1259  | 0  |     return Botan_detail::ECxDSA_Verify<::Botan::ECGDSA_PublicKey, operation::ECGDSA_Verify>(op);  | 
1260  | 0  | }  | 
1261  |  |  | 
1262  | 0  | std::optional<component::ECC_PublicKey> Botan::OpECDSA_Recover(operation::ECDSA_Recover& op) { | 
1263  | 0  |     std::optional<component::ECC_PublicKey> ret = std::nullopt;  | 
1264  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1265  |  | 
  | 
1266  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1267  | 0  |     Buffer CT;  | 
1268  |  | 
  | 
1269  | 0  |     { | 
1270  | 0  |         std::optional<std::string> curveString;  | 
1271  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1272  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1273  | 0  |     }  | 
1274  |  |  | 
1275  |  |     /* Construct input */  | 
1276  | 0  |     { | 
1277  | 0  |         if ( op.digestType.Get() == CF_DIGEST("NULL") ) { | 
1278  | 0  |             CT = op.cleartext.ECDSA_RandomPad(ds, op.curveType);  | 
1279  | 0  |         } else { | 
1280  | 0  |             std::optional<std::string> algoString;  | 
1281  | 0  |             CF_CHECK_NE(algoString = Botan_detail::DigestIDToString(op.digestType.Get()), std::nullopt);  | 
1282  |  | 
  | 
1283  | 0  |             auto hash = ::Botan::HashFunction::create(*algoString);  | 
1284  | 0  |             hash->update(op.cleartext.GetPtr(), op.cleartext.GetSize());  | 
1285  | 0  |             const auto _CT = hash->final();  | 
1286  | 0  |             CT = Buffer(_CT.data(), _CT.size()).ECDSA_RandomPad(ds, op.curveType);  | 
1287  | 0  |         }  | 
1288  | 0  |     }  | 
1289  |  |  | 
1290  | 0  |     { | 
1291  | 0  |         const ::Botan::BigInt R(op.signature.first.ToString(ds));  | 
1292  | 0  |         const ::Botan::BigInt S(op.signature.second.ToString(ds));  | 
1293  |  | 
  | 
1294  | 0  |         std::unique_ptr<::Botan::ECDSA_PublicKey> pub = nullptr;  | 
1295  | 0  |         try { | 
1296  | 0  |             pub = std::make_unique<::Botan::ECDSA_PublicKey>(*group, CT.Get(), R, S, op.id);  | 
1297  |  | 
  | 
1298  | 0  |             ret = { | 
1299  | 0  |                 pub->public_point().get_affine_x().to_dec_string(),  | 
1300  | 0  |                 pub->public_point().get_affine_y().to_dec_string()  | 
1301  | 0  |             };  | 
1302  | 0  |         } catch ( ::Botan::Invalid_State& e ) { | 
1303  | 0  |         } catch ( ::Botan::Decoding_Error& ) { | 
1304  | 0  |         } catch ( ::Botan::Invalid_Argument& ) { | 
1305  |  |             //ret = {"0", "0"}; | 
1306  | 0  |         }  | 
1307  |  | 
  | 
1308  | 0  |     }  | 
1309  |  | 
  | 
1310  | 0  | end:  | 
1311  | 0  |     return ret;  | 
1312  | 0  | }  | 
1313  |  |  | 
1314  | 0  | std::optional<component::Bignum> Botan::OpDH_Derive(operation::DH_Derive& op) { | 
1315  | 0  |     std::optional<component::Bignum> ret = std::nullopt;  | 
1316  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1317  |  | 
  | 
1318  | 0  |     BOTAN_FUZZER_RNG;  | 
1319  |  | 
  | 
1320  | 0  |     try { | 
1321  | 0  |         CF_CHECK_NE(op.priv.ToTrimmedString(), "0");  | 
1322  |  | 
  | 
1323  | 0  |         const ::Botan::BigInt g(op.base.ToString(ds));  | 
1324  | 0  |         const ::Botan::BigInt p(op.prime.ToString(ds));  | 
1325  | 0  |         const ::Botan::DL_Group grp(p, g);  | 
1326  |  | 
  | 
1327  | 0  |         const ::Botan::BigInt _priv(op.priv.ToString(ds));  | 
1328  |  |  | 
1329  |  |         /* Prevent time-out */  | 
1330  | 0  |         CF_CHECK_LT(g.bytes(), 80);  | 
1331  | 0  |         CF_CHECK_LT(p.bytes(), 80);  | 
1332  | 0  |         CF_CHECK_LT(_priv.bytes(), 80);  | 
1333  |  | 
  | 
1334  | 0  |         std::unique_ptr<::Botan::Private_Key> priv(new ::Botan::DH_PrivateKey(grp, _priv));  | 
1335  |  | 
  | 
1336  | 0  |         const ::Botan::BigInt _pub(op.pub.ToString(ds));  | 
1337  | 0  |         ::Botan::DH_PublicKey pub(grp, _pub);  | 
1338  |  | 
  | 
1339  | 0  |         std::unique_ptr<::Botan::PK_Key_Agreement> kas(new ::Botan::PK_Key_Agreement(*priv, rng, "Raw"));  | 
1340  | 0  |         const auto derived_key = kas->derive_key(0, pub.public_value());  | 
1341  |  | 
  | 
1342  | 0  |         const auto derived_str = ::Botan::BigInt(derived_key.bits_of()).to_dec_string();  | 
1343  | 0  |         if ( derived_str != "0" ) { | 
1344  | 0  |             ret = derived_str;  | 
1345  | 0  |         }  | 
1346  | 0  |     } catch ( ... ) { } | 
1347  |  |  | 
1348  | 0  | end:  | 
1349  | 0  |     return ret;  | 
1350  | 0  | }  | 
1351  |  |  | 
1352  | 0  | std::optional<component::ECC_Point> Botan::OpECC_Point_Add(operation::ECC_Point_Add& op) { | 
1353  | 0  |     std::optional<component::ECC_Point> ret = std::nullopt;  | 
1354  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1355  |  | 
  | 
1356  | 0  |     BOTAN_FUZZER_RNG;  | 
1357  |  | 
  | 
1358  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1359  | 0  |     std::unique_ptr<::Botan::PointGFp> a, b;  | 
1360  |  | 
  | 
1361  | 0  |     { | 
1362  | 0  |         std::optional<std::string> curveString;  | 
1363  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1364  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1365  | 0  |     }  | 
1366  |  |  | 
1367  | 0  |     { | 
1368  |  |         /* A */  | 
1369  | 0  |         { | 
1370  | 0  |             const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1371  | 0  |             CF_CHECK_GTE(a_x, 0);  | 
1372  |  | 
  | 
1373  | 0  |             const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1374  | 0  |             CF_CHECK_GTE(a_y, 0);  | 
1375  |  | 
  | 
1376  | 0  |             try { | 
1377  | 0  |                 a = std::make_unique<::Botan::PointGFp>(group->point(a_x, a_y));  | 
1378  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1379  | 0  |                 goto end;  | 
1380  | 0  |             }  | 
1381  | 0  |             CF_CHECK_TRUE(a->on_the_curve());  | 
1382  | 0  |         }  | 
1383  |  |  | 
1384  |  |         /* B */  | 
1385  | 0  |         { | 
1386  | 0  |             const auto b_x = ::Botan::BigInt(op.b.first.ToString(ds));  | 
1387  | 0  |             CF_CHECK_GTE(b_x, 0);  | 
1388  |  | 
  | 
1389  | 0  |             const auto b_y = ::Botan::BigInt(op.b.second.ToString(ds));  | 
1390  | 0  |             CF_CHECK_GTE(b_y, 0);  | 
1391  |  | 
  | 
1392  | 0  |             try { | 
1393  | 0  |                 b = std::make_unique<::Botan::PointGFp>(group->point(b_x, b_y));  | 
1394  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1395  | 0  |                 goto end;  | 
1396  | 0  |             }  | 
1397  |  |  | 
1398  | 0  |             CF_CHECK_TRUE(b->on_the_curve());  | 
1399  | 0  |         }  | 
1400  |  |  | 
1401  | 0  |         const bool is_negation = *a == -(*b);  | 
1402  |  | 
  | 
1403  | 0  |         ::Botan::PointGFp _res = *a + *b;  | 
1404  |  | 
  | 
1405  | 0  |         const bool is_zero = _res.is_zero();  | 
1406  |  |  | 
1407  |  |         /* If A is a negation of B, then addition of both should result in point at infinity */  | 
1408  |  |         /* Otherwise, it should result in non-infinity. */  | 
1409  | 0  |         CF_ASSERT(is_zero == is_negation, "Unexpected point addition result");  | 
1410  | 0  |         CF_CHECK_FALSE(is_zero);  | 
1411  |  | 
  | 
1412  | 0  |         const auto x = _res.get_affine_x();  | 
1413  | 0  |         const auto y = _res.get_affine_y();  | 
1414  |  | 
  | 
1415  | 0  |         ret = { | 
1416  | 0  |             util::HexToDec(x.to_hex_string()),  | 
1417  | 0  |             util::HexToDec(y.to_hex_string()),  | 
1418  | 0  |         };  | 
1419  |  | 
  | 
1420  | 0  |     }  | 
1421  |  |  | 
1422  | 0  | end:  | 
1423  | 0  |     return ret;  | 
1424  | 0  | }  | 
1425  |  |  | 
1426  | 0  | std::optional<component::ECC_Point> Botan::OpECC_Point_Sub(operation::ECC_Point_Sub& op) { | 
1427  | 0  |     std::optional<component::ECC_Point> ret = std::nullopt;  | 
1428  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1429  |  | 
  | 
1430  | 0  |     BOTAN_FUZZER_RNG;  | 
1431  |  | 
  | 
1432  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1433  | 0  |     std::unique_ptr<::Botan::PointGFp> a, b;  | 
1434  |  | 
  | 
1435  | 0  |     { | 
1436  | 0  |         std::optional<std::string> curveString;  | 
1437  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1438  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1439  | 0  |     }  | 
1440  |  |  | 
1441  | 0  |     { | 
1442  |  |         /* A */  | 
1443  | 0  |         { | 
1444  | 0  |             const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1445  | 0  |             CF_CHECK_GTE(a_x, 0);  | 
1446  |  | 
  | 
1447  | 0  |             const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1448  | 0  |             CF_CHECK_GTE(a_y, 0);  | 
1449  |  | 
  | 
1450  | 0  |             try { | 
1451  | 0  |                 a = std::make_unique<::Botan::PointGFp>(group->point(a_x, a_y));  | 
1452  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1453  | 0  |                 goto end;  | 
1454  | 0  |             }  | 
1455  | 0  |             CF_CHECK_TRUE(a->on_the_curve());  | 
1456  | 0  |         }  | 
1457  |  |  | 
1458  |  |         /* B */  | 
1459  | 0  |         { | 
1460  | 0  |             const auto b_x = ::Botan::BigInt(op.b.first.ToString(ds));  | 
1461  | 0  |             CF_CHECK_GTE(b_x, 0);  | 
1462  |  | 
  | 
1463  | 0  |             const auto b_y = ::Botan::BigInt(op.b.second.ToString(ds));  | 
1464  | 0  |             CF_CHECK_GTE(b_y, 0);  | 
1465  |  | 
  | 
1466  | 0  |             try { | 
1467  | 0  |                 b = std::make_unique<::Botan::PointGFp>(group->point(b_x, b_y));  | 
1468  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1469  | 0  |                 goto end;  | 
1470  | 0  |             }  | 
1471  |  |  | 
1472  | 0  |             CF_CHECK_TRUE(b->on_the_curve());  | 
1473  | 0  |         }  | 
1474  |  |  | 
1475  | 0  |         const bool is_eq = *a == *b;  | 
1476  |  | 
  | 
1477  | 0  |         ::Botan::PointGFp _res = *a - *b;  | 
1478  |  | 
  | 
1479  | 0  |         const bool is_zero = _res.is_zero();  | 
1480  |  |  | 
1481  |  |         /* If A equals B, then subtraction of both should result in point at infinity */  | 
1482  |  |         /* Otherwise, it should result in non-infinity. */  | 
1483  | 0  |         CF_ASSERT(is_zero == is_eq, "Unexpected point subtraction result");  | 
1484  | 0  |         CF_CHECK_FALSE(is_zero);  | 
1485  |  | 
  | 
1486  | 0  |         const auto x = _res.get_affine_x();  | 
1487  | 0  |         const auto y = _res.get_affine_y();  | 
1488  |  | 
  | 
1489  | 0  |         ret = { | 
1490  | 0  |             util::HexToDec(x.to_hex_string()),  | 
1491  | 0  |             util::HexToDec(y.to_hex_string()),  | 
1492  | 0  |         };  | 
1493  |  | 
  | 
1494  | 0  |     }  | 
1495  |  |  | 
1496  | 0  | end:  | 
1497  | 0  |     return ret;  | 
1498  | 0  | }  | 
1499  |  |  | 
1500  | 0  | std::optional<component::ECC_Point> Botan::OpECC_Point_Mul(operation::ECC_Point_Mul& op) { | 
1501  | 0  |     std::optional<component::ECC_Point> ret = std::nullopt;  | 
1502  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1503  |  | 
  | 
1504  | 0  |     BOTAN_FUZZER_RNG;  | 
1505  |  | 
  | 
1506  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1507  |  | 
  | 
1508  | 0  |     { | 
1509  | 0  |         std::optional<std::string> curveString;  | 
1510  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1511  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1512  | 0  |     }  | 
1513  |  |  | 
1514  | 0  |     try { | 
1515  | 0  |         const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1516  | 0  |         CF_CHECK_GTE(a_x, 0);  | 
1517  |  | 
  | 
1518  | 0  |         const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1519  | 0  |         CF_CHECK_GTE(a_y, 0);  | 
1520  |  | 
  | 
1521  | 0  |         const auto a = group->point(a_x, a_y);  | 
1522  | 0  |         CF_CHECK_TRUE(a.on_the_curve());  | 
1523  |  | 
  | 
1524  | 0  |         const auto b = ::Botan::BigInt(op.b.ToString(ds));  | 
1525  |  | 
  | 
1526  | 0  |         CF_CHECK_GTE(b, 0);  | 
1527  |  | 
  | 
1528  | 0  |         std::vector<::Botan::BigInt> ws(::Botan::PointGFp::WORKSPACE_SIZE);  | 
1529  |  | 
  | 
1530  | 0  |         bool useBlinding = false;  | 
1531  | 0  | #if defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
1532  | 0  |         try { | 
1533  | 0  |             useBlinding = ds.Get<bool>();  | 
1534  | 0  |         } catch ( fuzzing::datasource::Datasource::OutOfData ) { } | 
1535  | 0  | #endif  | 
1536  |  | 
  | 
1537  | 0  |         ::Botan::PointGFp _res;  | 
1538  |  | 
  | 
1539  | 0  |         if ( useBlinding == false ) { | 
1540  | 0  |             _res = a * b;  | 
1541  | 0  |         } else { | 
1542  | 0  |             _res = group->blinded_var_point_multiply(a, b, rng, ws);  | 
1543  | 0  |         }  | 
1544  |  | 
  | 
1545  | 0  |         const auto x = _res.get_affine_x();  | 
1546  | 0  |         const auto y = _res.get_affine_y();  | 
1547  |  | 
  | 
1548  | 0  |         ret = { | 
1549  | 0  |             util::HexToDec(x.to_hex_string()),  | 
1550  | 0  |             util::HexToDec(y.to_hex_string()),  | 
1551  | 0  |         };  | 
1552  |  | 
  | 
1553  | 0  |     } catch ( ... ) { } | 
1554  |  |  | 
1555  | 0  | end:  | 
1556  | 0  |     return ret;  | 
1557  | 0  | }  | 
1558  |  |  | 
1559  | 0  | std::optional<component::ECC_Point> Botan::OpECC_Point_Neg(operation::ECC_Point_Neg& op) { | 
1560  | 0  |     std::optional<component::ECC_Point> ret = std::nullopt;  | 
1561  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1562  |  | 
  | 
1563  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1564  |  | 
  | 
1565  | 0  |     { | 
1566  | 0  |         std::optional<std::string> curveString;  | 
1567  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1568  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1569  | 0  |     }  | 
1570  |  |  | 
1571  | 0  |     try { | 
1572  | 0  |         const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1573  | 0  |         CF_CHECK_GTE(a_x, 0);  | 
1574  |  | 
  | 
1575  | 0  |         const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1576  | 0  |         CF_CHECK_GTE(a_y, 0);  | 
1577  |  | 
  | 
1578  | 0  |         const auto a = group->point(a_x, a_y);  | 
1579  | 0  |         CF_CHECK_TRUE(a.on_the_curve());  | 
1580  |  | 
  | 
1581  | 0  |         const ::Botan::PointGFp _res = -a;  | 
1582  |  | 
  | 
1583  | 0  |         const auto x = _res.get_affine_x();  | 
1584  | 0  |         const auto y = _res.get_affine_y();  | 
1585  |  | 
  | 
1586  | 0  |         ret = { | 
1587  | 0  |             util::HexToDec(x.to_hex_string()),  | 
1588  | 0  |             util::HexToDec(y.to_hex_string()),  | 
1589  | 0  |         };  | 
1590  |  | 
  | 
1591  | 0  |     } catch ( ... ) { } | 
1592  |  |  | 
1593  | 0  | end:  | 
1594  | 0  |     return ret;  | 
1595  | 0  | }  | 
1596  |  |  | 
1597  | 0  | std::optional<component::ECC_Point> Botan::OpECC_Point_Dbl(operation::ECC_Point_Dbl& op) { | 
1598  | 0  |     std::optional<component::ECC_Point> ret = std::nullopt;  | 
1599  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1600  |  | 
  | 
1601  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1602  |  | 
  | 
1603  | 0  |     { | 
1604  | 0  |         std::optional<std::string> curveString;  | 
1605  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1606  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1607  | 0  |     }  | 
1608  |  |  | 
1609  | 0  |     try { | 
1610  | 0  |         const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1611  | 0  |         CF_CHECK_GTE(a_x, 0);  | 
1612  |  | 
  | 
1613  | 0  |         const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1614  | 0  |         CF_CHECK_GTE(a_y, 0);  | 
1615  |  | 
  | 
1616  | 0  |         const auto a = group->point(a_x, a_y);  | 
1617  | 0  |         CF_CHECK_TRUE(a.on_the_curve());  | 
1618  |  | 
  | 
1619  | 0  |         const ::Botan::PointGFp _res = a + a;  | 
1620  |  | 
  | 
1621  | 0  |         const auto x = _res.get_affine_x();  | 
1622  | 0  |         const auto y = _res.get_affine_y();  | 
1623  |  | 
  | 
1624  | 0  |         ret = { | 
1625  | 0  |             util::HexToDec(x.to_hex_string()),  | 
1626  | 0  |             util::HexToDec(y.to_hex_string()),  | 
1627  | 0  |         };  | 
1628  |  | 
  | 
1629  | 0  |     } catch ( ... ) { } | 
1630  |  |  | 
1631  | 0  | end:  | 
1632  | 0  |     return ret;  | 
1633  | 0  | }  | 
1634  |  |  | 
1635  | 0  | std::optional<bool> Botan::OpECC_Point_Cmp(operation::ECC_Point_Cmp& op) { | 
1636  | 0  |     std::optional<bool> ret = std::nullopt;  | 
1637  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1638  |  | 
  | 
1639  | 0  |     BOTAN_FUZZER_RNG;  | 
1640  |  | 
  | 
1641  | 0  |     std::unique_ptr<::Botan::EC_Group> group = nullptr;  | 
1642  | 0  |     std::unique_ptr<::Botan::PointGFp> a, b;  | 
1643  |  | 
  | 
1644  | 0  |     { | 
1645  | 0  |         std::optional<std::string> curveString;  | 
1646  | 0  |         CF_CHECK_NE(curveString = Botan_detail::CurveIDToString(op.curveType.Get()), std::nullopt);  | 
1647  | 0  |         group = std::make_unique<::Botan::EC_Group>(*curveString);  | 
1648  | 0  |     }  | 
1649  |  |  | 
1650  | 0  |     { | 
1651  |  |         /* A */  | 
1652  | 0  |         { | 
1653  | 0  |             const auto a_x = ::Botan::BigInt(op.a.first.ToString(ds));  | 
1654  | 0  |             CF_CHECK_GTE(a_x, 0);  | 
1655  |  | 
  | 
1656  | 0  |             const auto a_y = ::Botan::BigInt(op.a.second.ToString(ds));  | 
1657  | 0  |             CF_CHECK_GTE(a_y, 0);  | 
1658  |  | 
  | 
1659  | 0  |             try { | 
1660  | 0  |                 a = std::make_unique<::Botan::PointGFp>(group->point(a_x, a_y));  | 
1661  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1662  | 0  |                 goto end;  | 
1663  | 0  |             }  | 
1664  | 0  |             CF_CHECK_TRUE(a->on_the_curve());  | 
1665  | 0  |         }  | 
1666  |  |  | 
1667  |  |         /* B */  | 
1668  | 0  |         { | 
1669  | 0  |             const auto b_x = ::Botan::BigInt(op.b.first.ToString(ds));  | 
1670  | 0  |             CF_CHECK_GTE(b_x, 0);  | 
1671  |  | 
  | 
1672  | 0  |             const auto b_y = ::Botan::BigInt(op.b.second.ToString(ds));  | 
1673  | 0  |             CF_CHECK_GTE(b_y, 0);  | 
1674  |  | 
  | 
1675  | 0  |             try { | 
1676  | 0  |                 b = std::make_unique<::Botan::PointGFp>(group->point(b_x, b_y));  | 
1677  | 0  |             } catch ( ::Botan::Invalid_Argument ) { | 
1678  | 0  |                 goto end;  | 
1679  | 0  |             }  | 
1680  |  |  | 
1681  | 0  |             CF_CHECK_TRUE(b->on_the_curve());  | 
1682  | 0  |         }  | 
1683  |  |  | 
1684  | 0  |         ret = *a == *b;  | 
1685  | 0  |     }  | 
1686  |  |  | 
1687  | 0  | end:  | 
1688  | 0  |     return ret;  | 
1689  | 0  | }  | 
1690  |  |  | 
1691  | 0  | std::optional<bool> Botan::OpDSA_Verify(operation::DSA_Verify& op) { | 
1692  | 0  |     std::optional<bool> ret = std::nullopt;  | 
1693  | 0  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1694  |  | 
  | 
1695  | 0  |     BOTAN_FUZZER_RNG;  | 
1696  |  | 
  | 
1697  | 0  |     try { | 
1698  | 0  |         const auto p = ::Botan::BigInt(op.parameters.p.ToString(ds));  | 
1699  | 0  |         const auto q = ::Botan::BigInt(op.parameters.q.ToString(ds));  | 
1700  | 0  |         const auto g = ::Botan::BigInt(op.parameters.g.ToString(ds));  | 
1701  |  |  | 
1702  |  |         /* Botan can verify signatures with g = 0.  | 
1703  |  |          * Avoid discrepancies with OpenSSL  | 
1704  |  |          */  | 
1705  | 0  |         CF_CHECK_NE(g, 0);  | 
1706  |  | 
  | 
1707  | 0  |         const ::Botan::DL_Group group(p, q, g);  | 
1708  | 0  |         CF_CHECK_TRUE(group.verify_group(rng));  | 
1709  |  | 
  | 
1710  | 0  |         const auto y = ::Botan::BigInt(op.pub.ToString(ds));  | 
1711  | 0  |         const auto pub = std::make_unique<::Botan::DSA_PublicKey>(group, y);  | 
1712  |  | 
  | 
1713  | 0  |         const auto r = ::Botan::BigInt(op.signature.first.ToString(ds));  | 
1714  | 0  |         const auto s = ::Botan::BigInt(op.signature.second.ToString(ds));  | 
1715  |  | 
  | 
1716  | 0  |         const auto sig = ::Botan::BigInt::encode_fixed_length_int_pair(  | 
1717  | 0  |                 r, s, q.bytes());  | 
1718  | 0  |         auto verifier = ::Botan::PK_Verifier(*pub, "Raw");  | 
1719  | 0  |         verifier.update(op.cleartext.Get());  | 
1720  | 0  |         ret = verifier.check_signature(sig);  | 
1721  | 0  |     } catch ( ... ) { | 
1722  | 0  |     }  | 
1723  |  |  | 
1724  | 0  | end:  | 
1725  | 0  |     return ret;  | 
1726  | 0  | }  | 
1727  |  |  | 
1728  | 20.6k  | std::optional<component::Bignum> Botan::OpBignumCalc(operation::BignumCalc& op) { | 
1729  | 20.6k  |     std::optional<component::Bignum> ret = std::nullopt;  | 
1730  |  |  | 
1731  | 20.6k  |     if ( op.modulo ) { | 
1732  | 10.0k  |         switch ( op.calcOp.Get() ) { | 
1733  | 222  |             case    CF_CALCOP("Add(A,B)"): | 
1734  | 244  |             case    CF_CALCOP("Bit(A,B)"): | 
1735  | 294  |             case    CF_CALCOP("CondSet(A,B)"): | 
1736  | 334  |             case    CF_CALCOP("Exp(A,B)"): | 
1737  | 789  |             case    CF_CALCOP("InvMod(A,B)"): | 
1738  | 899  |             case    CF_CALCOP("IsEq(A,B)"): | 
1739  | 912  |             case    CF_CALCOP("IsEven(A)"): | 
1740  | 924  |             case    CF_CALCOP("IsOdd(A)"): | 
1741  | 983  |             case    CF_CALCOP("IsOne(A)"): | 
1742  | 1.04k  |             case    CF_CALCOP("IsZero(A)"): | 
1743  | 1.32k  |             case    CF_CALCOP("LShift1(A)"): | 
1744  | 1.83k  |             case    CF_CALCOP("Mul(A,B)"): | 
1745  | 1.90k  |             case    CF_CALCOP("Not(A)"): | 
1746  | 1.91k  |             case    CF_CALCOP("NumBits(A)"): | 
1747  | 2.33k  |             case    CF_CALCOP("RShift(A,B)"): | 
1748  | 2.36k  |             case    CF_CALCOP("Set(A)"): | 
1749  | 2.57k  |             case    CF_CALCOP("Sqr(A)"): | 
1750  | 3.62k  |             case    CF_CALCOP("Sqrt(A)"): | 
1751  | 3.83k  |             case    CF_CALCOP("Sub(A,B)"): | 
1752  | 3.83k  |                 break;  | 
1753  | 6.18k  |             default:  | 
1754  | 6.18k  |                 return ret;  | 
1755  | 10.0k  |         }  | 
1756  | 10.0k  |     }  | 
1757  | 14.4k  |     Datasource ds(op.modifier.GetPtr(), op.modifier.GetSize());  | 
1758  |  |  | 
1759  | 14.4k  |     Botan_bignum::Bignum res(&ds, "0");  | 
1760  | 14.4k  |     std::vector<Botan_bignum::Bignum> bn{ | 
1761  | 14.4k  |         Botan_bignum::Bignum(&ds, op.bn0.ToString(ds)),  | 
1762  | 14.4k  |         Botan_bignum::Bignum(&ds, op.bn1.ToString(ds)),  | 
1763  | 14.4k  |         Botan_bignum::Bignum(&ds, op.bn2.ToString(ds)),  | 
1764  | 14.4k  |         Botan_bignum::Bignum(&ds, op.bn3.ToString(ds))  | 
1765  | 14.4k  |     };  | 
1766  | 14.4k  |     std::unique_ptr<Botan_bignum::Operation> opRunner = nullptr;  | 
1767  |  |  | 
1768  | 14.4k  |     switch ( op.calcOp.Get() ) { | 
1769  | 238  |         case    CF_CALCOP("Add(A,B)"): | 
1770  | 238  |             opRunner = std::make_unique<Botan_bignum::Add>();  | 
1771  | 238  |             break;  | 
1772  | 214  |         case    CF_CALCOP("Sub(A,B)"): | 
1773  | 214  |             opRunner = std::make_unique<Botan_bignum::Sub>();  | 
1774  | 214  |             break;  | 
1775  | 522  |         case    CF_CALCOP("Mul(A,B)"): | 
1776  | 522  |             opRunner = std::make_unique<Botan_bignum::Mul>();  | 
1777  | 522  |             break;  | 
1778  | 13  |         case    CF_CALCOP("Div(A,B)"): | 
1779  | 13  |             opRunner = std::make_unique<Botan_bignum::Div>();  | 
1780  | 13  |             break;  | 
1781  | 8  |         case    CF_CALCOP("Mod(A,B)"): | 
1782  | 8  |             opRunner = std::make_unique<Botan_bignum::Mod>();  | 
1783  | 8  |             break;  | 
1784  | 475  |         case    CF_CALCOP("ExpMod(A,B,C)"): | 
1785  |  |             /* Too slow with larger values */  | 
1786  | 475  |             CF_CHECK_LT(op.bn0.GetSize(), 1000);  | 
1787  | 473  |             CF_CHECK_LT(op.bn1.GetSize(), 1000);  | 
1788  | 468  |             CF_CHECK_LT(op.bn2.GetSize(), 1000);  | 
1789  |  |  | 
1790  | 464  |             opRunner = std::make_unique<Botan_bignum::ExpMod>();  | 
1791  | 464  |             break;  | 
1792  | 43  |         case    CF_CALCOP("Exp(A,B)"): | 
1793  | 43  |             opRunner = std::make_unique<Botan_bignum::Exp>();  | 
1794  | 43  |             break;  | 
1795  | 275  |         case    CF_CALCOP("Sqr(A)"): | 
1796  | 275  |             opRunner = std::make_unique<Botan_bignum::Sqr>();  | 
1797  | 275  |             break;  | 
1798  | 73  |         case    CF_CALCOP("GCD(A,B)"): | 
1799  | 73  |             opRunner = std::make_unique<Botan_bignum::GCD>();  | 
1800  | 73  |             break;  | 
1801  | 19  |         case    CF_CALCOP("SqrMod(A,B)"): | 
1802  | 19  |             opRunner = std::make_unique<Botan_bignum::SqrMod>();  | 
1803  | 19  |             break;  | 
1804  | 809  |         case    CF_CALCOP("InvMod(A,B)"): | 
1805  | 809  |             opRunner = std::make_unique<Botan_bignum::InvMod>();  | 
1806  | 809  |             break;  | 
1807  | 4  |         case    CF_CALCOP("Cmp(A,B)"): | 
1808  | 4  |             opRunner = std::make_unique<Botan_bignum::Cmp>();  | 
1809  | 4  |             break;  | 
1810  | 255  |         case    CF_CALCOP("LCM(A,B)"): | 
1811  | 255  |             opRunner = std::make_unique<Botan_bignum::LCM>();  | 
1812  | 255  |             break;  | 
1813  | 6  |         case    CF_CALCOP("Abs(A)"): | 
1814  | 6  |             opRunner = std::make_unique<Botan_bignum::Abs>();  | 
1815  | 6  |             break;  | 
1816  | 69  |         case    CF_CALCOP("Jacobi(A,B)"): | 
1817  | 69  |             opRunner = std::make_unique<Botan_bignum::Jacobi>();  | 
1818  | 69  |             break;  | 
1819  | 63  |         case    CF_CALCOP("Neg(A)"): | 
1820  | 63  |             opRunner = std::make_unique<Botan_bignum::Neg>();  | 
1821  | 63  |             break;  | 
1822  | 450  |         case    CF_CALCOP("IsPrime(A)"): | 
1823  | 450  |             opRunner = std::make_unique<Botan_bignum::IsPrime>();  | 
1824  | 450  |             break;  | 
1825  | 439  |         case    CF_CALCOP("RShift(A,B)"): | 
1826  | 439  |             opRunner = std::make_unique<Botan_bignum::RShift>();  | 
1827  | 439  |             break;  | 
1828  | 287  |         case    CF_CALCOP("LShift1(A)"): | 
1829  | 287  |             opRunner = std::make_unique<Botan_bignum::LShift1>();  | 
1830  | 287  |             break;  | 
1831  | 3  |         case    CF_CALCOP("IsNeg(A)"): | 
1832  | 3  |             opRunner = std::make_unique<Botan_bignum::IsNeg>();  | 
1833  | 3  |             break;  | 
1834  | 128  |         case    CF_CALCOP("IsEq(A,B)"): | 
1835  | 128  |             opRunner = std::make_unique<Botan_bignum::IsEq>();  | 
1836  | 128  |             break;  | 
1837  | 2  |         case    CF_CALCOP("IsGt(A,B)"): | 
1838  | 2  |             opRunner = std::make_unique<Botan_bignum::IsGt>();  | 
1839  | 2  |             break;  | 
1840  | 71  |         case    CF_CALCOP("IsGte(A,B)"): | 
1841  | 71  |             opRunner = std::make_unique<Botan_bignum::IsGte>();  | 
1842  | 71  |             break;  | 
1843  | 5  |         case    CF_CALCOP("IsLt(A,B)"): | 
1844  | 5  |             opRunner = std::make_unique<Botan_bignum::IsLt>();  | 
1845  | 5  |             break;  | 
1846  | 37  |         case    CF_CALCOP("IsLte(A,B)"): | 
1847  | 37  |             opRunner = std::make_unique<Botan_bignum::IsLte>();  | 
1848  | 37  |             break;  | 
1849  | 17  |         case    CF_CALCOP("IsEven(A)"): | 
1850  | 17  |             opRunner = std::make_unique<Botan_bignum::IsEven>();  | 
1851  | 17  |             break;  | 
1852  | 16  |         case    CF_CALCOP("IsOdd(A)"): | 
1853  | 16  |             opRunner = std::make_unique<Botan_bignum::IsOdd>();  | 
1854  | 16  |             break;  | 
1855  | 61  |         case    CF_CALCOP("IsZero(A)"): | 
1856  | 61  |             opRunner = std::make_unique<Botan_bignum::IsZero>();  | 
1857  | 61  |             break;  | 
1858  | 2  |         case    CF_CALCOP("IsNotZero(A)"): | 
1859  | 2  |             opRunner = std::make_unique<Botan_bignum::IsNotZero>();  | 
1860  | 2  |             break;  | 
1861  | 62  |         case    CF_CALCOP("IsOne(A)"): | 
1862  | 62  |             opRunner = std::make_unique<Botan_bignum::IsOne>();  | 
1863  | 62  |             break;  | 
1864  | 14  |         case    CF_CALCOP("MulMod(A,B,C)"): | 
1865  | 14  |             opRunner = std::make_unique<Botan_bignum::MulMod>();  | 
1866  | 14  |             break;  | 
1867  | 45  |         case    CF_CALCOP("Bit(A,B)"): | 
1868  | 45  |             opRunner = std::make_unique<Botan_bignum::Bit>();  | 
1869  | 45  |             break;  | 
1870  | 5  |         case    CF_CALCOP("CmpAbs(A,B)"): | 
1871  | 5  |             opRunner = std::make_unique<Botan_bignum::CmpAbs>();  | 
1872  | 5  |             break;  | 
1873  | 61  |         case    CF_CALCOP("SetBit(A,B)"): | 
1874  | 61  |             opRunner = std::make_unique<Botan_bignum::SetBit>();  | 
1875  | 61  |             break;  | 
1876  | 8  |         case    CF_CALCOP("Mod_NIST_192(A)"): | 
1877  | 8  |             opRunner = std::make_unique<Botan_bignum::Mod_NIST_192>();  | 
1878  | 8  |             break;  | 
1879  | 7  |         case    CF_CALCOP("Mod_NIST_224(A)"): | 
1880  | 7  |             opRunner = std::make_unique<Botan_bignum::Mod_NIST_224>();  | 
1881  | 7  |             break;  | 
1882  | 7  |         case    CF_CALCOP("Mod_NIST_256(A)"): | 
1883  | 7  |             opRunner = std::make_unique<Botan_bignum::Mod_NIST_256>();  | 
1884  | 7  |             break;  | 
1885  | 4  |         case    CF_CALCOP("Mod_NIST_384(A)"): | 
1886  | 4  |             opRunner = std::make_unique<Botan_bignum::Mod_NIST_384>();  | 
1887  | 4  |             break;  | 
1888  | 13  |         case    CF_CALCOP("Mod_NIST_521(A)"): | 
1889  | 13  |             opRunner = std::make_unique<Botan_bignum::Mod_NIST_521>();  | 
1890  | 13  |             break;  | 
1891  | 21  |         case    CF_CALCOP("ClearBit(A,B)"): | 
1892  | 21  |             opRunner = std::make_unique<Botan_bignum::ClearBit>();  | 
1893  | 21  |             break;  | 
1894  | 11  |         case    CF_CALCOP("MulAdd(A,B,C)"): | 
1895  | 11  |             opRunner = std::make_unique<Botan_bignum::MulAdd>();  | 
1896  | 11  |             break;  | 
1897  | 93  |         case    CF_CALCOP("MulDiv(A,B,C)"): | 
1898  | 93  |             opRunner = std::make_unique<Botan_bignum::MulDiv>();  | 
1899  | 93  |             break;  | 
1900  | 96  |         case    CF_CALCOP("MulDivCeil(A,B,C)"): | 
1901  | 96  |             opRunner = std::make_unique<Botan_bignum::MulDivCeil>();  | 
1902  | 96  |             break;  | 
1903  | 6  |         case    CF_CALCOP("Exp2(A)"): | 
1904  | 6  |             opRunner = std::make_unique<Botan_bignum::Exp2>();  | 
1905  | 6  |             break;  | 
1906  | 7  |         case    CF_CALCOP("NumLSZeroBits(A)"): | 
1907  | 7  |             opRunner = std::make_unique<Botan_bignum::NumLSZeroBits>();  | 
1908  | 7  |             break;  | 
1909  | 1.31k  |         case    CF_CALCOP("Sqrt(A)"): | 
1910  | 1.31k  |             if ( op.modulo == std::nullopt ) { | 
1911  | 256  |                 opRunner = std::make_unique<Botan_bignum::Sqrt>();  | 
1912  | 1.05k  |             } else { | 
1913  | 1.05k  |                 opRunner = std::make_unique<Botan_bignum::Ressol>();  | 
1914  | 1.05k  |             }  | 
1915  | 1.31k  |             break;  | 
1916  | 10  |         case    CF_CALCOP("AddMod(A,B,C)"): | 
1917  | 10  |             opRunner = std::make_unique<Botan_bignum::AddMod>();  | 
1918  | 10  |             break;  | 
1919  | 89  |         case    CF_CALCOP("SubMod(A,B,C)"): | 
1920  | 89  |             opRunner = std::make_unique<Botan_bignum::SubMod>();  | 
1921  | 89  |             break;  | 
1922  | 7  |         case    CF_CALCOP("NumBits(A)"): | 
1923  | 7  |             opRunner = std::make_unique<Botan_bignum::NumBits>();  | 
1924  | 7  |             break;  | 
1925  | 41  |         case    CF_CALCOP("Set(A)"): | 
1926  | 41  |             opRunner = std::make_unique<Botan_bignum::Set>();  | 
1927  | 41  |             break;  | 
1928  | 82  |         case    CF_CALCOP("CondSet(A,B)"): | 
1929  | 82  |             opRunner = std::make_unique<Botan_bignum::CondSet>();  | 
1930  | 82  |             break;  | 
1931  |  |         /*  | 
1932  |  |         case    CF_CALCOP("Ressol(A,B)"): | 
1933  |  |             opRunner = std::make_unique<Botan_bignum::Ressol>();  | 
1934  |  |             break;  | 
1935  |  |         */  | 
1936  | 86  |         case    CF_CALCOP("Not(A)"): | 
1937  | 86  |             opRunner = std::make_unique<Botan_bignum::Not>();  | 
1938  | 86  |             break;  | 
1939  | 1.02k  |         case    CF_CALCOP("Prime()"): | 
1940  | 1.02k  |             opRunner = std::make_unique<Botan_bignum::Prime>();  | 
1941  | 1.02k  |             break;  | 
1942  | 117  |         case    CF_CALCOP("RandRange(A,B)"): | 
1943  | 117  |             opRunner = std::make_unique<Botan_bignum::RandRange>();  | 
1944  | 117  |             break;  | 
1945  | 34  |         case    CF_CALCOP("IsSquare(A)"): | 
1946  | 34  |             opRunner = std::make_unique<Botan_bignum::IsSquare>();  | 
1947  | 34  |             break;  | 
1948  | 14.4k  |     }  | 
1949  |  |  | 
1950  | 14.4k  |     CF_CHECK_NE(opRunner, nullptr);  | 
1951  |  |  | 
1952  | 7.85k  | #if defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
1953  | 7.85k  |     try { | 
1954  | 7.85k  | #endif  | 
1955  | 7.85k  |         CF_CHECK_EQ(opRunner->Run(  | 
1956  | 7.85k  |                     ds,  | 
1957  | 7.85k  |                     res,  | 
1958  | 7.85k  |                     bn,  | 
1959  | 7.85k  |                     op.modulo ?  | 
1960  | 7.85k  |                         std::optional<Botan_bignum::Bignum>(Botan_bignum::Bignum(op.modulo->ToTrimmedString())) :  | 
1961  | 7.85k  |                         std::nullopt), true);  | 
1962  | 7.44k  | #if defined(CRYPTOFUZZ_BOTAN_IS_ORACLE)  | 
1963  | 7.44k  |     } catch ( ... ) { | 
1964  | 0  |         goto end;  | 
1965  | 0  |     }  | 
1966  | 0  | #endif  | 
1967  |  |  | 
1968  | 7.44k  |     ret = { util::HexToDec(res.Ref().to_hex_string()) }; | 
1969  |  |  | 
1970  | 14.4k  | end:  | 
1971  | 14.4k  |     return ret;  | 
1972  | 7.44k  | }  | 
1973  |  |  | 
1974  | 10.0k  | bool Botan::SupportsModularBignumCalc(void) const { | 
1975  | 10.0k  |     return true;  | 
1976  | 10.0k  | }  | 
1977  |  |  | 
1978  |  | } /* namespace module */  | 
1979  |  | } /* namespace cryptofuzz */  |