1*62c56f98SSadaf Ebrahimi #define MBEDTLS_ALLOW_PRIVATE_ACCESS
2*62c56f98SSadaf Ebrahimi
3*62c56f98SSadaf Ebrahimi #include <stdint.h>
4*62c56f98SSadaf Ebrahimi #include <stdlib.h>
5*62c56f98SSadaf Ebrahimi #include <string.h>
6*62c56f98SSadaf Ebrahimi #include "mbedtls/pk.h"
7*62c56f98SSadaf Ebrahimi #include "mbedtls/entropy.h"
8*62c56f98SSadaf Ebrahimi #include "mbedtls/ctr_drbg.h"
9*62c56f98SSadaf Ebrahimi #include "common.h"
10*62c56f98SSadaf Ebrahimi
11*62c56f98SSadaf Ebrahimi //4 Kb should be enough for every bug ;-)
12*62c56f98SSadaf Ebrahimi #define MAX_LEN 0x1000
13*62c56f98SSadaf Ebrahimi
14*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_PK_PARSE_C) && defined(MBEDTLS_CTR_DRBG_C) && defined(MBEDTLS_ENTROPY_C)
15*62c56f98SSadaf Ebrahimi const char *pers = "fuzz_privkey";
16*62c56f98SSadaf Ebrahimi #endif // MBEDTLS_PK_PARSE_C && MBEDTLS_CTR_DRBG_C && MBEDTLS_ENTROPY_C
17*62c56f98SSadaf Ebrahimi
LLVMFuzzerTestOneInput(const uint8_t * Data,size_t Size)18*62c56f98SSadaf Ebrahimi int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size)
19*62c56f98SSadaf Ebrahimi {
20*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_PK_PARSE_C) && defined(MBEDTLS_CTR_DRBG_C) && defined(MBEDTLS_ENTROPY_C)
21*62c56f98SSadaf Ebrahimi int ret;
22*62c56f98SSadaf Ebrahimi mbedtls_pk_context pk;
23*62c56f98SSadaf Ebrahimi mbedtls_ctr_drbg_context ctr_drbg;
24*62c56f98SSadaf Ebrahimi mbedtls_entropy_context entropy;
25*62c56f98SSadaf Ebrahimi
26*62c56f98SSadaf Ebrahimi if (Size > MAX_LEN) {
27*62c56f98SSadaf Ebrahimi //only work on small inputs
28*62c56f98SSadaf Ebrahimi Size = MAX_LEN;
29*62c56f98SSadaf Ebrahimi }
30*62c56f98SSadaf Ebrahimi
31*62c56f98SSadaf Ebrahimi mbedtls_ctr_drbg_init(&ctr_drbg);
32*62c56f98SSadaf Ebrahimi mbedtls_entropy_init(&entropy);
33*62c56f98SSadaf Ebrahimi mbedtls_pk_init(&pk);
34*62c56f98SSadaf Ebrahimi
35*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_USE_PSA_CRYPTO)
36*62c56f98SSadaf Ebrahimi psa_status_t status = psa_crypto_init();
37*62c56f98SSadaf Ebrahimi if (status != PSA_SUCCESS) {
38*62c56f98SSadaf Ebrahimi goto exit;
39*62c56f98SSadaf Ebrahimi }
40*62c56f98SSadaf Ebrahimi #endif /* MBEDTLS_USE_PSA_CRYPTO */
41*62c56f98SSadaf Ebrahimi
42*62c56f98SSadaf Ebrahimi if (mbedtls_ctr_drbg_seed(&ctr_drbg, dummy_entropy, &entropy,
43*62c56f98SSadaf Ebrahimi (const unsigned char *) pers, strlen(pers)) != 0) {
44*62c56f98SSadaf Ebrahimi goto exit;
45*62c56f98SSadaf Ebrahimi }
46*62c56f98SSadaf Ebrahimi
47*62c56f98SSadaf Ebrahimi ret = mbedtls_pk_parse_key(&pk, Data, Size, NULL, 0,
48*62c56f98SSadaf Ebrahimi dummy_random, &ctr_drbg);
49*62c56f98SSadaf Ebrahimi if (ret == 0) {
50*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_RSA_C)
51*62c56f98SSadaf Ebrahimi if (mbedtls_pk_get_type(&pk) == MBEDTLS_PK_RSA) {
52*62c56f98SSadaf Ebrahimi mbedtls_mpi N, P, Q, D, E, DP, DQ, QP;
53*62c56f98SSadaf Ebrahimi mbedtls_rsa_context *rsa;
54*62c56f98SSadaf Ebrahimi
55*62c56f98SSadaf Ebrahimi mbedtls_mpi_init(&N); mbedtls_mpi_init(&P); mbedtls_mpi_init(&Q);
56*62c56f98SSadaf Ebrahimi mbedtls_mpi_init(&D); mbedtls_mpi_init(&E); mbedtls_mpi_init(&DP);
57*62c56f98SSadaf Ebrahimi mbedtls_mpi_init(&DQ); mbedtls_mpi_init(&QP);
58*62c56f98SSadaf Ebrahimi
59*62c56f98SSadaf Ebrahimi rsa = mbedtls_pk_rsa(pk);
60*62c56f98SSadaf Ebrahimi if (mbedtls_rsa_export(rsa, &N, &P, &Q, &D, &E) != 0) {
61*62c56f98SSadaf Ebrahimi abort();
62*62c56f98SSadaf Ebrahimi }
63*62c56f98SSadaf Ebrahimi if (mbedtls_rsa_export_crt(rsa, &DP, &DQ, &QP) != 0) {
64*62c56f98SSadaf Ebrahimi abort();
65*62c56f98SSadaf Ebrahimi }
66*62c56f98SSadaf Ebrahimi
67*62c56f98SSadaf Ebrahimi mbedtls_mpi_free(&N); mbedtls_mpi_free(&P); mbedtls_mpi_free(&Q);
68*62c56f98SSadaf Ebrahimi mbedtls_mpi_free(&D); mbedtls_mpi_free(&E); mbedtls_mpi_free(&DP);
69*62c56f98SSadaf Ebrahimi mbedtls_mpi_free(&DQ); mbedtls_mpi_free(&QP);
70*62c56f98SSadaf Ebrahimi } else
71*62c56f98SSadaf Ebrahimi #endif
72*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_ECP_C)
73*62c56f98SSadaf Ebrahimi if (mbedtls_pk_get_type(&pk) == MBEDTLS_PK_ECKEY ||
74*62c56f98SSadaf Ebrahimi mbedtls_pk_get_type(&pk) == MBEDTLS_PK_ECKEY_DH) {
75*62c56f98SSadaf Ebrahimi mbedtls_ecp_keypair *ecp = mbedtls_pk_ec(pk);
76*62c56f98SSadaf Ebrahimi mbedtls_ecp_group_id grp_id = ecp->grp.id;
77*62c56f98SSadaf Ebrahimi const mbedtls_ecp_curve_info *curve_info =
78*62c56f98SSadaf Ebrahimi mbedtls_ecp_curve_info_from_grp_id(grp_id);
79*62c56f98SSadaf Ebrahimi
80*62c56f98SSadaf Ebrahimi /* If the curve is not supported, the key should not have been
81*62c56f98SSadaf Ebrahimi * accepted. */
82*62c56f98SSadaf Ebrahimi if (curve_info == NULL) {
83*62c56f98SSadaf Ebrahimi abort();
84*62c56f98SSadaf Ebrahimi }
85*62c56f98SSadaf Ebrahimi } else
86*62c56f98SSadaf Ebrahimi #endif
87*62c56f98SSadaf Ebrahimi {
88*62c56f98SSadaf Ebrahimi /* The key is valid but is not of a supported type.
89*62c56f98SSadaf Ebrahimi * This should not happen. */
90*62c56f98SSadaf Ebrahimi abort();
91*62c56f98SSadaf Ebrahimi }
92*62c56f98SSadaf Ebrahimi }
93*62c56f98SSadaf Ebrahimi exit:
94*62c56f98SSadaf Ebrahimi mbedtls_entropy_free(&entropy);
95*62c56f98SSadaf Ebrahimi mbedtls_ctr_drbg_free(&ctr_drbg);
96*62c56f98SSadaf Ebrahimi mbedtls_pk_free(&pk);
97*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_USE_PSA_CRYPTO)
98*62c56f98SSadaf Ebrahimi mbedtls_psa_crypto_free();
99*62c56f98SSadaf Ebrahimi #endif /* MBEDTLS_USE_PSA_CRYPTO */
100*62c56f98SSadaf Ebrahimi #else
101*62c56f98SSadaf Ebrahimi (void) Data;
102*62c56f98SSadaf Ebrahimi (void) Size;
103*62c56f98SSadaf Ebrahimi #endif // MBEDTLS_PK_PARSE_C && MBEDTLS_CTR_DRBG_C && MBEDTLS_ENTROPY_C
104*62c56f98SSadaf Ebrahimi
105*62c56f98SSadaf Ebrahimi return 0;
106*62c56f98SSadaf Ebrahimi }
107