Coverage Report

Created: 2023-06-08 06:41

/src/openssl/crypto/asn1/a_d2i_fp.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <stdio.h>
11
#include <limits.h>
12
#include "internal/cryptlib.h"
13
#include "internal/numbers.h"
14
#include <openssl/buffer.h>
15
#include <openssl/asn1.h>
16
#include "internal/asn1.h"
17
#include "crypto/asn1.h"
18
19
#ifndef NO_OLD_ASN1
20
# ifndef OPENSSL_NO_STDIO
21
22
void *ASN1_d2i_fp(void *(*xnew) (void), d2i_of_void *d2i, FILE *in, void **x)
23
0
{
24
0
    BIO *b;
25
0
    void *ret;
26
27
0
    if ((b = BIO_new(BIO_s_file())) == NULL) {
28
0
        ERR_raise(ERR_LIB_ASN1, ERR_R_BUF_LIB);
29
0
        return NULL;
30
0
    }
31
0
    BIO_set_fp(b, in, BIO_NOCLOSE);
32
0
    ret = ASN1_d2i_bio(xnew, d2i, b, x);
33
0
    BIO_free(b);
34
0
    return ret;
35
0
}
36
# endif
37
38
void *ASN1_d2i_bio(void *(*xnew) (void), d2i_of_void *d2i, BIO *in, void **x)
39
0
{
40
0
    BUF_MEM *b = NULL;
41
0
    const unsigned char *p;
42
0
    void *ret = NULL;
43
0
    int len;
44
45
0
    len = asn1_d2i_read_bio(in, &b);
46
0
    if (len < 0)
47
0
        goto err;
48
49
0
    p = (unsigned char *)b->data;
50
0
    ret = d2i(x, &p, len);
51
0
 err:
52
0
    BUF_MEM_free(b);
53
0
    return ret;
54
0
}
55
56
#endif
57
58
void *ASN1_item_d2i_bio_ex(const ASN1_ITEM *it, BIO *in, void *x,
59
                           OSSL_LIB_CTX *libctx, const char *propq)
60
0
{
61
0
    BUF_MEM *b = NULL;
62
0
    const unsigned char *p;
63
0
    void *ret = NULL;
64
0
    int len;
65
66
0
    if (in == NULL)
67
0
        return NULL;
68
0
    len = asn1_d2i_read_bio(in, &b);
69
0
    if (len < 0)
70
0
        goto err;
71
72
0
    p = (const unsigned char *)b->data;
73
0
    ret = ASN1_item_d2i_ex(x, &p, len, it, libctx, propq);
74
0
 err:
75
0
    BUF_MEM_free(b);
76
0
    return ret;
77
0
}
78
79
void *ASN1_item_d2i_bio(const ASN1_ITEM *it, BIO *in, void *x)
80
0
{
81
0
    return ASN1_item_d2i_bio_ex(it, in, x, NULL, NULL);
82
0
}
83
84
#ifndef OPENSSL_NO_STDIO
85
void *ASN1_item_d2i_fp_ex(const ASN1_ITEM *it, FILE *in, void *x,
86
                          OSSL_LIB_CTX *libctx, const char *propq)
87
0
{
88
0
    BIO *b;
89
0
    char *ret;
90
91
0
    if ((b = BIO_new(BIO_s_file())) == NULL) {
92
0
        ERR_raise(ERR_LIB_ASN1, ERR_R_BUF_LIB);
93
0
        return NULL;
94
0
    }
95
0
    BIO_set_fp(b, in, BIO_NOCLOSE);
96
0
    ret = ASN1_item_d2i_bio_ex(it, b, x, libctx, propq);
97
0
    BIO_free(b);
98
0
    return ret;
99
0
}
100
101
void *ASN1_item_d2i_fp(const ASN1_ITEM *it, FILE *in, void *x)
102
0
{
103
0
    return ASN1_item_d2i_fp_ex(it, in, x, NULL, NULL);
104
0
}
105
#endif
106
107
41.8k
#define HEADER_SIZE   8
108
41.8k
#define ASN1_CHUNK_INITIAL_SIZE (16 * 1024)
109
int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
110
41.8k
{
111
41.8k
    BUF_MEM *b;
112
41.8k
    unsigned char *p;
113
41.8k
    int i;
114
41.8k
    size_t want = HEADER_SIZE;
115
41.8k
    uint32_t eos = 0;
116
41.8k
    size_t off = 0;
117
41.8k
    size_t len = 0;
118
41.8k
    size_t diff;
119
120
41.8k
    const unsigned char *q;
121
41.8k
    long slen;
122
41.8k
    int inf, tag, xclass;
123
124
41.8k
    b = BUF_MEM_new();
125
41.8k
    if (b == NULL) {
126
0
        ERR_raise(ERR_LIB_ASN1, ERR_R_BUF_LIB);
127
0
        return -1;
128
0
    }
129
130
41.8k
    ERR_set_mark();
131
41.8k
    for (;;) {
132
41.8k
        diff = len - off;
133
41.8k
        if (want >= diff) {
134
41.8k
            want -= diff;
135
136
41.8k
            if (len + want < len || !BUF_MEM_grow_clean(b, len + want)) {
137
0
                ERR_raise(ERR_LIB_ASN1, ERR_R_BUF_LIB);
138
0
                goto err;
139
0
            }
140
41.8k
            i = BIO_read(in, &(b->data[len]), want);
141
41.8k
            if (i < 0 && diff == 0) {
142
0
                ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA);
143
0
                goto err;
144
0
            }
145
41.8k
            if (i > 0) {
146
41.8k
                if (len + i < len) {
147
0
                    ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
148
0
                    goto err;
149
0
                }
150
41.8k
                len += i;
151
41.8k
            }
152
41.8k
        }
153
        /* else data already loaded */
154
155
41.8k
        p = (unsigned char *)&(b->data[off]);
156
41.8k
        q = p;
157
41.8k
        diff = len - off;
158
41.8k
        if (diff == 0)
159
0
            goto err;
160
41.8k
        inf = ASN1_get_object(&q, &slen, &tag, &xclass, diff);
161
41.8k
        if (inf & 0x80) {
162
41.8k
            unsigned long e;
163
164
41.8k
            e = ERR_GET_REASON(ERR_peek_last_error());
165
41.8k
            if (e != ASN1_R_TOO_LONG)
166
0
                goto err;
167
41.8k
            ERR_pop_to_mark();
168
41.8k
        }
169
41.8k
        i = q - p;            /* header length */
170
41.8k
        off += i;               /* end of data */
171
172
41.8k
        if (inf & 1) {
173
            /* no data body so go round again */
174
0
            if (eos == UINT32_MAX) {
175
0
                ERR_raise(ERR_LIB_ASN1, ASN1_R_HEADER_TOO_LONG);
176
0
                goto err;
177
0
            }
178
0
            eos++;
179
0
            want = HEADER_SIZE;
180
41.8k
        } else if (eos && (slen == 0) && (tag == V_ASN1_EOC)) {
181
            /* eos value, so go back and read another header */
182
0
            eos--;
183
0
            if (eos == 0)
184
0
                break;
185
0
            else
186
0
                want = HEADER_SIZE;
187
41.8k
        } else {
188
            /* suck in slen bytes of data */
189
41.8k
            want = slen;
190
41.8k
            if (want > (len - off)) {
191
41.8k
                size_t chunk_max = ASN1_CHUNK_INITIAL_SIZE;
192
193
41.8k
                want -= (len - off);
194
41.8k
                if (want > INT_MAX /* BIO_read takes an int length */  ||
195
41.8k
                    len + want < len) {
196
0
                    ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
197
0
                    goto err;
198
0
                }
199
83.7k
                while (want > 0) {
200
                    /*
201
                     * Read content in chunks of increasing size
202
                     * so we can return an error for EOF without
203
                     * having to allocate the entire content length
204
                     * in one go.
205
                     */
206
41.8k
                    size_t chunk = want > chunk_max ? chunk_max : want;
207
208
41.8k
                    if (!BUF_MEM_grow_clean(b, len + chunk)) {
209
0
                        ERR_raise(ERR_LIB_ASN1, ERR_R_BUF_LIB);
210
0
                        goto err;
211
0
                    }
212
41.8k
                    want -= chunk;
213
83.7k
                    while (chunk > 0) {
214
41.8k
                        i = BIO_read(in, &(b->data[len]), chunk);
215
41.8k
                        if (i <= 0) {
216
0
                            ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA);
217
0
                            goto err;
218
0
                        }
219
                    /*
220
                     * This can't overflow because |len+want| didn't
221
                     * overflow.
222
                     */
223
41.8k
                        len += i;
224
41.8k
                        chunk -= i;
225
41.8k
                    }
226
41.8k
                    if (chunk_max < INT_MAX/2)
227
41.8k
                        chunk_max *= 2;
228
41.8k
                }
229
41.8k
            }
230
41.8k
            if (off + slen < off) {
231
0
                ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
232
0
                goto err;
233
0
            }
234
41.8k
            off += slen;
235
41.8k
            if (eos == 0) {
236
41.8k
                break;
237
41.8k
            } else
238
0
                want = HEADER_SIZE;
239
41.8k
        }
240
41.8k
    }
241
242
41.8k
    if (off > INT_MAX) {
243
0
        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
244
0
        goto err;
245
0
    }
246
247
41.8k
    *pb = b;
248
41.8k
    return off;
249
0
 err:
250
0
    ERR_clear_last_mark();
251
0
    BUF_MEM_free(b);
252
0
    return -1;
253
41.8k
}