Coverage Report

Created: 2025-06-13 06:58

/src/openssl31/crypto/asn1/tasn_utl.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <stddef.h>
11
#include <string.h>
12
#include "internal/cryptlib.h"
13
#include "internal/refcount.h"
14
#include <openssl/asn1.h>
15
#include <openssl/asn1t.h>
16
#include <openssl/objects.h>
17
#include <openssl/err.h>
18
#include "asn1_local.h"
19
20
/* Utility functions for manipulating fields and offsets */
21
22
/* Add 'offset' to 'addr' */
23
702M
#define offset2ptr(addr, offset) (void *)(((char *) addr) + offset)
24
25
/*
26
 * Given an ASN1_ITEM CHOICE type return the selector value
27
 */
28
29
int ossl_asn1_get_choice_selector(ASN1_VALUE **pval, const ASN1_ITEM *it)
30
6.48M
{
31
6.48M
    int *sel = offset2ptr(*pval, it->utype);
32
33
6.48M
    return *sel;
34
6.48M
}
35
36
int ossl_asn1_get_choice_selector_const(const ASN1_VALUE **pval,
37
                                        const ASN1_ITEM *it)
38
16.9M
{
39
16.9M
    int *sel = offset2ptr(*pval, it->utype);
40
41
16.9M
    return *sel;
42
16.9M
}
43
44
/*
45
 * Given an ASN1_ITEM CHOICE type set the selector value, return old value.
46
 */
47
48
int ossl_asn1_set_choice_selector(ASN1_VALUE **pval, int value,
49
                                  const ASN1_ITEM *it)
50
10.1M
{
51
10.1M
    int *sel, ret;
52
53
10.1M
    sel = offset2ptr(*pval, it->utype);
54
10.1M
    ret = *sel;
55
10.1M
    *sel = value;
56
10.1M
    return ret;
57
10.1M
}
58
59
/*
60
 * Do atomic reference counting. The value 'op' decides what to do.
61
 * If it is +1 then the count is incremented.
62
 * If |op| is 0, lock is initialised and count is set to 1.
63
 * If |op| is -1, count is decremented and the return value is the current
64
 * reference count or 0 if no reference count is active.
65
 * It returns -1 on initialisation error.
66
 * Used by ASN1_SEQUENCE construct of X509, X509_REQ, X509_CRL objects
67
 */
68
int ossl_asn1_do_lock(ASN1_VALUE **pval, int op, const ASN1_ITEM *it)
69
58.7M
{
70
58.7M
    const ASN1_AUX *aux;
71
58.7M
    CRYPTO_REF_COUNT *lck;
72
58.7M
    CRYPTO_RWLOCK **lock;
73
58.7M
    int ret = -1;
74
75
58.7M
    if ((it->itype != ASN1_ITYPE_SEQUENCE)
76
58.7M
        && (it->itype != ASN1_ITYPE_NDEF_SEQUENCE))
77
0
        return 0;
78
58.7M
    aux = it->funcs;
79
58.7M
    if (aux == NULL || (aux->flags & ASN1_AFLG_REFCOUNT) == 0)
80
57.6M
        return 0;
81
1.11M
    lck = offset2ptr(*pval, aux->ref_offset);
82
1.11M
    lock = offset2ptr(*pval, aux->ref_lock);
83
84
1.11M
    switch (op) {
85
513k
    case 0:
86
513k
        *lck = ret = 1;
87
513k
        *lock = CRYPTO_THREAD_lock_new();
88
513k
        if (*lock == NULL) {
89
0
            ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE);
90
0
            return -1;
91
0
        }
92
513k
        break;
93
513k
    case 1:
94
0
        if (!CRYPTO_UP_REF(lck, &ret, *lock))
95
0
            return -1;
96
0
        break;
97
605k
    case -1:
98
605k
        if (!CRYPTO_DOWN_REF(lck, &ret, *lock))
99
0
            return -1;  /* failed */
100
605k
        REF_PRINT_EX(it->sname, ret, (void *)it);
101
605k
        REF_ASSERT_ISNT(ret < 0);
102
605k
        if (ret == 0) {
103
513k
            CRYPTO_THREAD_lock_free(*lock);
104
513k
            *lock = NULL;
105
513k
        }
106
605k
        break;
107
1.11M
    }
108
109
1.11M
    return ret;
110
1.11M
}
111
112
static ASN1_ENCODING *asn1_get_enc_ptr(ASN1_VALUE **pval, const ASN1_ITEM *it)
113
147M
{
114
147M
    const ASN1_AUX *aux;
115
116
147M
    if (pval == NULL || *pval == NULL)
117
0
        return NULL;
118
147M
    aux = it->funcs;
119
147M
    if (aux == NULL || (aux->flags & ASN1_AFLG_ENCODING) == 0)
120
144M
        return NULL;
121
2.98M
    return offset2ptr(*pval, aux->enc_offset);
122
147M
}
123
124
static const ASN1_ENCODING *asn1_get_const_enc_ptr(const ASN1_VALUE **pval,
125
                                                   const ASN1_ITEM *it)
126
87.5M
{
127
87.5M
    const ASN1_AUX *aux;
128
129
87.5M
    if (pval == NULL || *pval == NULL)
130
0
        return NULL;
131
87.5M
    aux = it->funcs;
132
87.5M
    if (aux == NULL || (aux->flags & ASN1_AFLG_ENCODING) == 0)
133
86.3M
        return NULL;
134
1.20M
    return offset2ptr(*pval, aux->enc_offset);
135
87.5M
}
136
137
void ossl_asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it)
138
58.0M
{
139
58.0M
    ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
140
141
58.0M
    if (enc != NULL) {
142
1.10M
        enc->enc = NULL;
143
1.10M
        enc->len = 0;
144
1.10M
        enc->modified = 1;
145
1.10M
    }
146
58.0M
}
147
148
void ossl_asn1_enc_free(ASN1_VALUE **pval, const ASN1_ITEM *it)
149
58.8M
{
150
58.8M
    ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
151
152
58.8M
    if (enc != NULL) {
153
1.10M
        OPENSSL_free(enc->enc);
154
1.10M
        enc->enc = NULL;
155
1.10M
        enc->len = 0;
156
1.10M
        enc->modified = 1;
157
1.10M
    }
158
58.8M
}
159
160
int ossl_asn1_enc_save(ASN1_VALUE **pval, const unsigned char *in, int inlen,
161
                       const ASN1_ITEM *it)
162
30.1M
{
163
30.1M
    ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
164
165
30.1M
    if (enc == NULL)
166
29.4M
        return 1;
167
168
768k
    OPENSSL_free(enc->enc);
169
768k
    if (inlen <= 0)
170
0
        return 0;
171
768k
    if ((enc->enc = OPENSSL_malloc(inlen)) == NULL) {
172
0
        ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE);
173
0
        return 0;
174
0
    }
175
768k
    memcpy(enc->enc, in, inlen);
176
768k
    enc->len = inlen;
177
768k
    enc->modified = 0;
178
179
768k
    return 1;
180
768k
}
181
182
int ossl_asn1_enc_restore(int *len, unsigned char **out, const ASN1_VALUE **pval,
183
                          const ASN1_ITEM *it)
184
87.5M
{
185
87.5M
    const ASN1_ENCODING *enc = asn1_get_const_enc_ptr(pval, it);
186
187
87.5M
    if (enc == NULL || enc->modified)
188
86.3M
        return 0;
189
1.20M
    if (out) {
190
378k
        memcpy(*out, enc->enc, enc->len);
191
378k
        *out += enc->len;
192
378k
    }
193
1.20M
    if (len != NULL)
194
1.20M
        *len = enc->len;
195
1.20M
    return 1;
196
87.5M
}
197
198
/* Given an ASN1_TEMPLATE get a pointer to a field */
199
ASN1_VALUE **ossl_asn1_get_field_ptr(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt)
200
397M
{
201
397M
    ASN1_VALUE **pvaltmp = offset2ptr(*pval, tt->offset);
202
203
    /*
204
     * NOTE for BOOLEAN types the field is just a plain int so we can't
205
     * return int **, so settle for (int *).
206
     */
207
397M
    return pvaltmp;
208
397M
}
209
210
/* Given an ASN1_TEMPLATE get a const pointer to a field */
211
const ASN1_VALUE **ossl_asn1_get_const_field_ptr(const ASN1_VALUE **pval,
212
                                                 const ASN1_TEMPLATE *tt)
213
263M
{
214
263M
    return offset2ptr(*pval, tt->offset);
215
263M
}
216
217
/*
218
 * Handle ANY DEFINED BY template, find the selector, look up the relevant
219
 * ASN1_TEMPLATE in the table and return it.
220
 */
221
222
const ASN1_TEMPLATE *ossl_asn1_do_adb(const ASN1_VALUE *val,
223
                                      const ASN1_TEMPLATE *tt,
224
                                      int nullerr)
225
478M
{
226
478M
    const ASN1_ADB *adb;
227
478M
    const ASN1_ADB_TABLE *atbl;
228
478M
    long selector;
229
478M
    const ASN1_VALUE **sfld;
230
478M
    int i;
231
232
478M
    if ((tt->flags & ASN1_TFLG_ADB_MASK) == 0)
233
476M
        return tt;
234
235
    /* Else ANY DEFINED BY ... get the table */
236
2.02M
    adb = ASN1_ADB_ptr(tt->item);
237
238
    /* Get the selector field */
239
2.02M
    sfld = offset2ptr(val, adb->offset);
240
241
    /* Check if NULL */
242
2.02M
    if (*sfld == NULL) {
243
777k
        if (adb->null_tt == NULL)
244
777k
            goto err;
245
0
        return adb->null_tt;
246
777k
    }
247
248
    /*
249
     * Convert type to a long: NB: don't check for NID_undef here because it
250
     * might be a legitimate value in the table
251
     */
252
1.25M
    if ((tt->flags & ASN1_TFLG_ADB_OID) != 0)
253
1.25M
        selector = OBJ_obj2nid((ASN1_OBJECT *)*sfld);
254
0
    else
255
0
        selector = ASN1_INTEGER_get((ASN1_INTEGER *)*sfld);
256
257
    /* Let application callback translate value */
258
1.25M
    if (adb->adb_cb != NULL && adb->adb_cb(&selector) == 0) {
259
0
        ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
260
0
        return NULL;
261
0
    }
262
263
    /*
264
     * Try to find matching entry in table Maybe should check application
265
     * types first to allow application override? Might also be useful to
266
     * have a flag which indicates table is sorted and we can do a binary
267
     * search. For now stick to a linear search.
268
     */
269
270
8.36M
    for (atbl = adb->tbl, i = 0; i < adb->tblcount; i++, atbl++)
271
7.42M
        if (atbl->value == selector)
272
309k
            return &atbl->tt;
273
274
    /* FIXME: need to search application table too */
275
276
    /* No match, return default type */
277
942k
    if (!adb->default_tt)
278
0
        goto err;
279
942k
    return adb->default_tt;
280
281
777k
 err:
282
    /* FIXME: should log the value or OID of unsupported type */
283
777k
    if (nullerr)
284
777k
        ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
285
777k
    return NULL;
286
942k
}