Coverage Report

Created: 2026-09-03 06:08

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/opensc/src/tests/fuzzing/fuzz_pkcs15_encode.c
Line
Count
Source
1
/*
2
 * fuzz_pkcs15_encode.c: Fuzzer for encoding functions
3
 *
4
 * Copyright (C) 2022 Red Hat, Inc.
5
 *
6
 * Author: Veronika Hanulikova <vhanulik@redhat.com>
7
 *
8
 * This library is free software; you can redistribute it and/or
9
 * modify it under the terms of the GNU Lesser General Public
10
 * License as published by the Free Software Foundation; either
11
 * version 2.1 of the License, or (at your option) any later version.
12
 *
13
 * This library is distributed in the hope that it will be useful,
14
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
16
 * Lesser General Public License for more details.
17
 *
18
 * You should have received a copy of the GNU General Public License
19
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
20
 */
21
22
#ifdef HAVE_CONFIG_H
23
#include "config.h"
24
#endif
25
26
#include "fuzzer_reader.h"
27
#include "libopensc/pkcs15.h"
28
#include "libopensc/internal.h"
29
30
31
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size)
32
15.2k
{
33
15.2k
  struct sc_context       *ctx = NULL;
34
15.2k
  struct sc_card          *card = NULL;
35
15.2k
  struct sc_pkcs15_card   *p15card = NULL;
36
15.2k
  struct sc_pkcs15_object *obj;
37
15.2k
  unsigned char           *unused_space = NULL;
38
15.2k
  size_t                   unused_space_len = 0;
39
40
15.2k
  sc_establish_context(&ctx, "fuzz");
41
15.2k
  if (!ctx)
42
0
    return 0;
43
44
15.2k
  if (fuzz_connect_card(ctx, &card, NULL, Data, Size) != SC_SUCCESS)
45
3.25k
    goto err;
46
47
12.0k
  if (sc_pkcs15_bind(card, NULL, &p15card) != 0)
48
7.74k
    goto err;
49
50
31.3k
  for (obj = p15card->obj_list; obj != NULL; obj = obj->next) {
51
27.1k
    u8 *buf = NULL;
52
27.1k
    size_t buf_len = 0;
53
27.1k
    struct sc_pkcs15_object *key_object = NULL;
54
27.1k
    sc_pkcs15_pubkey_t *pkey = NULL;
55
27.1k
    switch (obj->type & SC_PKCS15_TYPE_CLASS_MASK) {
56
246
    case SC_PKCS15_TYPE_PUBKEY:
57
246
      sc_pkcs15_encode_pukdf_entry(ctx, obj, &buf, &buf_len);
58
246
      sc_pkcs15_read_pubkey(p15card, obj, &pkey);
59
246
      sc_pkcs15_free_pubkey(pkey);
60
246
      break;
61
1.77k
    case SC_PKCS15_TYPE_PRKEY:
62
1.77k
      sc_pkcs15_encode_prkdf_entry(ctx, obj, &buf, &buf_len);
63
1.77k
      break;
64
20.6k
    case SC_PKCS15_TYPE_DATA_OBJECT:
65
20.6k
      sc_pkcs15_encode_dodf_entry(ctx, obj, &buf, &buf_len);
66
20.6k
      break;
67
0
    case SC_PKCS15_TYPE_SKEY:
68
0
      sc_pkcs15_encode_skdf_entry(ctx, obj, &buf, &buf_len);
69
0
      break;
70
3.92k
    case SC_PKCS15_TYPE_AUTH:
71
3.92k
      sc_pkcs15_encode_aodf_entry(ctx, obj, &buf, &buf_len);
72
3.92k
      break;
73
572
    case SC_PKCS15_TYPE_CERT:
74
572
      sc_pkcs15_encode_cdf_entry(ctx, obj, &buf, &buf_len);
75
572
      sc_pkcs15_prkey_attrs_from_cert(p15card, obj, &key_object);
76
572
      break;
77
27.1k
    }
78
27.1k
    free(buf);
79
27.1k
  }
80
4.26k
  sc_pkcs15_encode_unusedspace(ctx, p15card, &unused_space, &unused_space_len);
81
4.26k
  free(unused_space);
82
83
15.2k
err:
84
15.2k
  sc_pkcs15_card_free(p15card);
85
15.2k
  sc_disconnect_card(card);
86
15.2k
  sc_release_context(ctx);
87
88
15.2k
  return 0;
89
4.26k
}