Blame lib/nettle/rnd-fuzzer.c

Packit Service 4684c1
/*
Packit Service 4684c1
 * Copyright (C) 2017 Red Hat
Packit Service 4684c1
 * Copyright (C) 1995-2017 Free Software Foundation, Inc.
Packit Service 4684c1
 * This file is part of the GNU C Library.
Packit Service 4684c1
 * Contributed by Ulrich Drepper <drepper@gnu.ai.mit.edu>, August 1995.
Packit Service 4684c1
 *
Packit Service 4684c1
 * This file is part of GnuTLS.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Libgcrypt is free software; you can redistribute it and/or modify
Packit Service 4684c1
 * it under the terms of the GNU Lesser General Public License as
Packit Service 4684c1
 * published by the Free Software Foundation; either version 2.1 of
Packit Service 4684c1
 * the License, or (at your option) any later version.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Libgcrypt is distributed in the hope that it will be useful,
Packit Service 4684c1
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 4684c1
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit Service 4684c1
 * GNU Lesser General Public License for more details.
Packit Service 4684c1
 *
Packit Service 4684c1
 * You should have received a copy of the GNU Lesser General Public
Packit Service 4684c1
 * License along with this program; if not, see <https://www.gnu.org/licenses/>.
Packit Service 4684c1
 */
Packit Service 4684c1
Packit Service 4684c1
#include <config.h>
Packit Service 4684c1
#include <stdio.h>
Packit Service 4684c1
#include <stdlib.h>
Packit Service 4684c1
#include <errno.h>
Packit Service 4684c1
#include <sys/types.h>
Packit Service 4684c1
#include <drbg-aes.h>
Packit Service 4684c1
#include <fips.h>
Packit Service 4684c1
Packit Service 4684c1
#include "gnutls_int.h"
Packit Service 4684c1
#include "errors.h"
Packit Service 4684c1
#include <stdlib.h>
Packit Service 4684c1
#include <rnd-common.h>
Packit Service 4684c1
Packit Service 4684c1
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
Packit Service 4684c1
Packit Service 4684c1
struct r48_rand_data {
Packit Service 4684c1
	unsigned short int __x[3];	/* Current state.  */
Packit Service 4684c1
	unsigned short int __old_x[3];	/* Old state.  */
Packit Service 4684c1
	unsigned short int __c;	/* Additive const. in congruential formula.  */
Packit Service 4684c1
	unsigned short int __init;	/* Flag for initializing.  */
Packit Service 4684c1
	__extension__ unsigned long long int __a;	/* Factor in congruential
Packit Service 4684c1
							   formula.  */
Packit Service 4684c1
};
Packit Service 4684c1
Packit Service 4684c1
#ifdef __clang__
Packit Service 4684c1
__attribute__((no_sanitize("integer")))
Packit Service 4684c1
#endif
Packit Service 4684c1
static int
Packit Service 4684c1
__r48_rand_iterate(unsigned short int xsubi[3], struct r48_rand_data *buffer)
Packit Service 4684c1
{
Packit Service 4684c1
	uint64_t X;
Packit Service 4684c1
	uint64_t result;
Packit Service 4684c1
Packit Service 4684c1
	/* Initialize buffer, if not yet done.  */
Packit Service 4684c1
	if (unlikely(!buffer->__init)) {
Packit Service 4684c1
		buffer->__a = 0x5deece66dull;
Packit Service 4684c1
		buffer->__c = 0xb;
Packit Service 4684c1
		buffer->__init = 1;
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	/* Do the real work.  We choose a data type which contains at least
Packit Service 4684c1
	   48 bits.  Because we compute the modulus it does not care how
Packit Service 4684c1
	   many bits really are computed.  */
Packit Service 4684c1
Packit Service 4684c1
	X = (uint64_t) xsubi[2] << 32 | (uint32_t) xsubi[1] << 16 | xsubi[0];
Packit Service 4684c1
Packit Service 4684c1
	result = X * buffer->__a + buffer->__c;
Packit Service 4684c1
Packit Service 4684c1
	xsubi[0] = result & 0xffff;
Packit Service 4684c1
	xsubi[1] = (result >> 16) & 0xffff;
Packit Service 4684c1
	xsubi[2] = (result >> 32) & 0xffff;
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
#ifdef __clang__
Packit Service 4684c1
__attribute__((no_sanitize("integer")))
Packit Service 4684c1
#elif defined __GNUC__
Packit Service 4684c1
__attribute__((no_sanitize("shift-base")))
Packit Service 4684c1
#endif
Packit Service 4684c1
static int
Packit Service 4684c1
r48_r(unsigned short int xsubi[3], struct r48_rand_data *buffer,
Packit Service 4684c1
      long int *result)
Packit Service 4684c1
{
Packit Service 4684c1
	/* Compute next state.  */
Packit Service 4684c1
	if (__r48_rand_iterate(xsubi, buffer) < 0)
Packit Service 4684c1
		return -1;
Packit Service 4684c1
Packit Service 4684c1
	/* Store the result.  */
Packit Service 4684c1
	*result = (int32_t) ((xsubi[2] << 16) | xsubi[1]);
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static int r48(struct r48_rand_data *buffer, long int *result)
Packit Service 4684c1
{
Packit Service 4684c1
	return r48_r(buffer->__x, buffer, result);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
/* This is a dummy random generator intended to be reproducible
Packit Service 4684c1
 * for use in fuzzying targets.
Packit Service 4684c1
 */
Packit Service 4684c1
Packit Service 4684c1
static int _rngfuzz_init(void **_ctx)
Packit Service 4684c1
{
Packit Service 4684c1
	*_ctx = calloc(1, sizeof(struct r48_rand_data));
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static int _rngfuzz_rnd(void *_ctx, int level, void *buffer, size_t length)
Packit Service 4684c1
{
Packit Service 4684c1
	struct r48_rand_data *ctx = _ctx;
Packit Service 4684c1
	uint8_t *p = buffer;
Packit Service 4684c1
	long r;
Packit Service 4684c1
	unsigned i;
Packit Service 4684c1
Packit Service 4684c1
	memset(ctx, 0, sizeof(*ctx));
Packit Service 4684c1
Packit Service 4684c1
	for (i = 0; i < length; i++) {
Packit Service 4684c1
		r48(ctx, &r);
Packit Service 4684c1
		p[i] = r;
Packit Service 4684c1
	}
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void _rngfuzz_deinit(void *_ctx)
Packit Service 4684c1
{
Packit Service 4684c1
	struct r48_rand_data *ctx = _ctx;
Packit Service 4684c1
Packit Service 4684c1
	free(ctx);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void _rngfuzz_refresh(void *_ctx)
Packit Service 4684c1
{
Packit Service 4684c1
	/* this is predictable RNG. Don't refresh */
Packit Service 4684c1
	return;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
gnutls_crypto_rnd_st _gnutls_fuzz_rnd_ops = {
Packit Service 4684c1
	.init = _rngfuzz_init,
Packit Service 4684c1
	.deinit = _rngfuzz_deinit,
Packit Service 4684c1
	.rnd = _rngfuzz_rnd,
Packit Service 4684c1
	.rnd_refresh = _rngfuzz_refresh,
Packit Service 4684c1
	.self_test = NULL,
Packit Service 4684c1
};
Packit Service 4684c1
Packit Service 4684c1
#endif /* FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION */