Coverage Report

Created: 2026-09-12 06:55

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/openssl36/crypto/x509/x_attrib.c
Line
Count
Source
1
/*
2
 * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <stdio.h>
11
#include "internal/cryptlib.h"
12
#include <openssl/objects.h>
13
#include <openssl/asn1t.h>
14
#include <openssl/x509.h>
15
#include "x509_local.h"
16
#include <crypto/x509.h>
17
18
/*-
19
 * X509_ATTRIBUTE: this has the following form:
20
 *
21
 * typedef struct x509_attributes_st
22
 *      {
23
 *      ASN1_OBJECT *object;
24
 *      STACK_OF(ASN1_TYPE) *set;
25
 *      } X509_ATTRIBUTE;
26
 *
27
 */
28
29
ASN1_SEQUENCE(X509_ATTRIBUTE) = {
30
    ASN1_SIMPLE(X509_ATTRIBUTE, object, ASN1_OBJECT),
31
    ASN1_SET_OF(X509_ATTRIBUTE, set, ASN1_ANY)
32
3.47M
} ASN1_SEQUENCE_END(X509_ATTRIBUTE)
33
3.47M
34
3.47M
IMPLEMENT_ASN1_FUNCTIONS(X509_ATTRIBUTE)
35
3.47M
IMPLEMENT_ASN1_DUP_FUNCTION(X509_ATTRIBUTE)
36
3.47M
37
3.47M
X509_ATTRIBUTE *X509_ATTRIBUTE_create(int nid, int atrtype, void *value)
38
3.47M
{
39
0
    X509_ATTRIBUTE *ret = NULL;
40
0
    ASN1_TYPE *val = NULL;
41
0
    ASN1_OBJECT *oid;
42
43
0
    if ((oid = OBJ_nid2obj(nid)) == NULL)
44
0
        return NULL;
45
0
    if ((ret = X509_ATTRIBUTE_new()) == NULL)
46
0
        return NULL;
47
0
    ret->object = oid;
48
0
    if ((val = ASN1_TYPE_new()) == NULL)
49
0
        goto err;
50
0
    if (!sk_ASN1_TYPE_push(ret->set, val))
51
0
        goto err;
52
53
0
    ASN1_TYPE_set(val, atrtype, value);
54
0
    return ret;
55
0
err:
56
0
    X509_ATTRIBUTE_free(ret);
57
0
    ASN1_TYPE_free(val);
58
0
    return NULL;
59
0
}
60
61
static int print_oid(BIO *out, const ASN1_OBJECT *oid)
62
7.91k
{
63
7.91k
    const char *ln;
64
7.91k
    char objbuf[80];
65
7.91k
    int rc;
66
67
7.91k
    if (OBJ_obj2txt(objbuf, sizeof(objbuf), oid, 1) <= 0)
68
1
        return 0;
69
7.91k
    ln = OBJ_nid2ln(OBJ_obj2nid(oid));
70
7.91k
    rc = (ln != NULL)
71
7.91k
        ? BIO_printf(out, "%s (%s)", objbuf, ln)
72
7.91k
        : BIO_printf(out, "%s", objbuf);
73
7.91k
    return (rc >= 0);
74
7.91k
}
75
76
int ossl_print_attribute_value(BIO *out,
77
    int obj_nid,
78
    const ASN1_TYPE *av,
79
    int indent)
80
310k
{
81
310k
    ASN1_STRING *str;
82
310k
    unsigned char *value;
83
310k
    X509_NAME *xn = NULL;
84
310k
    int64_t int_val;
85
310k
    int ret = 1;
86
87
310k
    switch (av->type) {
88
15.3k
    case V_ASN1_BOOLEAN:
89
15.3k
        if (av->value.boolean) {
90
13.7k
            return BIO_printf(out, "%*sTRUE", indent, "") >= 4;
91
13.7k
        } else {
92
1.59k
            return BIO_printf(out, "%*sFALSE", indent, "") >= 5;
93
1.59k
        }
94
95
8.86k
    case V_ASN1_INTEGER:
96
21.9k
    case V_ASN1_ENUMERATED:
97
21.9k
        if (BIO_printf(out, "%*s", indent, "") < 0)
98
0
            return 0;
99
21.9k
        if (ASN1_ENUMERATED_get_int64(&int_val, av->value.integer) > 0) {
100
12.2k
            return BIO_printf(out, "%lld", (long long int)int_val) > 0;
101
12.2k
        }
102
9.72k
        str = av->value.integer;
103
9.72k
        return ossl_bio_print_hex(out, str->data, str->length);
104
105
2.50k
    case V_ASN1_BIT_STRING:
106
2.50k
        if (BIO_printf(out, "%*s", indent, "") < 0)
107
0
            return 0;
108
2.50k
        return ossl_bio_print_hex(out, av->value.bit_string->data,
109
2.50k
            av->value.bit_string->length);
110
111
7.38k
    case V_ASN1_OCTET_STRING:
112
15.0k
    case V_ASN1_VIDEOTEXSTRING:
113
15.0k
        if (BIO_printf(out, "%*s", indent, "") < 0)
114
0
            return 0;
115
15.0k
        return ossl_bio_print_hex(out, av->value.octet_string->data,
116
15.0k
            av->value.octet_string->length);
117
118
2.72k
    case V_ASN1_NULL:
119
2.72k
        return BIO_printf(out, "%*sNULL", indent, "") >= 4;
120
121
4.89k
    case V_ASN1_OBJECT:
122
4.89k
        if (BIO_printf(out, "%*s", indent, "") < 0)
123
0
            return 0;
124
4.89k
        return print_oid(out, av->value.object);
125
126
    /*
127
     * ObjectDescriptor is an IMPLICIT GraphicString, but GeneralString is a
128
     * superset supported by OpenSSL, so we will use that anywhere a
129
     * GraphicString is needed here.
130
     */
131
3.23k
    case V_ASN1_GENERALSTRING:
132
7.87k
    case V_ASN1_GRAPHICSTRING:
133
14.5k
    case V_ASN1_OBJECT_DESCRIPTOR:
134
14.5k
        return BIO_printf(out, "%*s%.*s", indent, "",
135
14.5k
                   av->value.generalstring->length,
136
14.5k
                   av->value.generalstring->data)
137
14.5k
            >= 0;
138
139
        /* EXTERNAL would go here. */
140
        /* EMBEDDED PDV would go here. */
141
142
3.55k
    case V_ASN1_UTF8STRING:
143
3.55k
        return BIO_printf(out, "%*s%.*s", indent, "",
144
3.55k
                   av->value.utf8string->length,
145
3.55k
                   av->value.utf8string->data)
146
3.55k
            >= 0;
147
148
2.04k
    case V_ASN1_REAL:
149
2.04k
        return BIO_printf(out, "%*sREAL", indent, "") >= 4;
150
151
        /* RELATIVE-OID would go here. */
152
        /* TIME would go here. */
153
154
81.7k
    case V_ASN1_SEQUENCE:
155
81.7k
        switch (obj_nid) {
156
77.9k
        case NID_undef: /* Unrecognized OID. */
157
77.9k
            break;
158
        /* Attribute types with DN syntax. */
159
92
        case NID_member:
160
163
        case NID_roleOccupant:
161
256
        case NID_seeAlso:
162
256
        case NID_manager:
163
256
        case NID_documentAuthor:
164
256
        case NID_secretary:
165
256
        case NID_associatedName:
166
256
        case NID_dITRedirect:
167
303
        case NID_owner:
168
            /*
169
             * d2i_ functions increment the ppin pointer. See doc/man3/d2i_X509.pod.
170
             * This preserves the original  pointer. We don't want to corrupt this
171
             * value.
172
             */
173
303
            value = av->value.sequence->data;
174
303
            xn = d2i_X509_NAME(NULL,
175
303
                (const unsigned char **)&value,
176
303
                av->value.sequence->length);
177
303
            if (xn == NULL) {
178
31
                BIO_puts(out, "(COULD NOT DECODE DISTINGUISHED NAME)\n");
179
31
                return 0;
180
31
            }
181
272
            if (X509_NAME_print_ex(out, xn, indent, XN_FLAG_SEP_CPLUS_SPC) <= 0)
182
0
                ret = 0;
183
272
            X509_NAME_free(xn);
184
272
            return ret;
185
186
3.50k
        default:
187
3.50k
            break;
188
81.7k
        }
189
81.4k
        return ASN1_parse_dump(out, av->value.sequence->data,
190
81.4k
                   av->value.sequence->length, indent, 1)
191
81.4k
            > 0;
192
193
73.5k
    case V_ASN1_SET:
194
73.5k
        return ASN1_parse_dump(out, av->value.set->data,
195
73.5k
                   av->value.set->length, indent, 1)
196
73.5k
            > 0;
197
198
    /*
199
     * UTCTime ::= [UNIVERSAL 23] IMPLICIT VisibleString
200
     * GeneralizedTime ::= [UNIVERSAL 24] IMPLICIT VisibleString
201
     * VisibleString is a superset for NumericString, so it will work for that.
202
     */
203
2.13k
    case V_ASN1_VISIBLESTRING:
204
3.17k
    case V_ASN1_UTCTIME:
205
3.59k
    case V_ASN1_GENERALIZEDTIME:
206
10.2k
    case V_ASN1_NUMERICSTRING:
207
10.2k
        return BIO_printf(out, "%*s%.*s", indent, "",
208
10.2k
                   av->value.visiblestring->length,
209
10.2k
                   av->value.visiblestring->data)
210
10.2k
            >= 0;
211
212
3.25k
    case V_ASN1_PRINTABLESTRING:
213
3.25k
        return BIO_printf(out, "%*s%.*s", indent, "",
214
3.25k
                   av->value.printablestring->length,
215
3.25k
                   av->value.printablestring->data)
216
3.25k
            >= 0;
217
218
7.94k
    case V_ASN1_T61STRING:
219
7.94k
        return BIO_printf(out, "%*s%.*s", indent, "",
220
7.94k
                   av->value.t61string->length,
221
7.94k
                   av->value.t61string->data)
222
7.94k
            >= 0;
223
224
1.41k
    case V_ASN1_IA5STRING:
225
1.41k
        return BIO_printf(out, "%*s%.*s", indent, "",
226
1.41k
                   av->value.ia5string->length,
227
1.41k
                   av->value.ia5string->data)
228
1.41k
            >= 0;
229
230
    /* UniversalString would go here. */
231
    /* CHARACTER STRING would go here. */
232
    /* BMPString would go here. */
233
    /* DATE would go here. */
234
    /* TIME-OF-DAY would go here. */
235
    /* DATE-TIME would go here. */
236
    /* DURATION would go here. */
237
    /* OID-IRI would go here. */
238
    /* RELATIVE-OID-IRI would go here. */
239
240
    /* Would it be appropriate to just hexdump? */
241
49.5k
    default:
242
49.5k
        return BIO_printf(out,
243
49.5k
                   "%*s<Unsupported tag %d>",
244
49.5k
                   indent,
245
49.5k
                   "",
246
49.5k
                   av->type)
247
49.5k
            >= 0;
248
310k
    }
249
310k
}