]> git.ipfire.org Git - thirdparty/tor.git/commitdiff
Quick-and-dirty fuzzer for inner-encrypted layer of hsv3 desc.
authorNick Mathewson <nickm@torproject.org>
Tue, 8 Jun 2021 15:01:47 +0000 (11:01 -0400)
committerNick Mathewson <nickm@torproject.org>
Tue, 8 Jun 2021 15:24:34 +0000 (11:24 -0400)
Based on hsv3 outer-layer fuzzer; some code may be unnecessary.

scripts/codegen/fuzzing_include_am.py
src/feature/hs/hs_descriptor.c
src/feature/hs/hs_descriptor.h
src/test/fuzz/fuzz_hsdescv3_inner.c [new file with mode: 0644]
src/test/fuzz/include.am

index b52b956f819c9b12697676cf89b037242b096113..d2d73a3c06d0e27a08fb88bc539a4ce7c0971b05 100755 (executable)
@@ -11,11 +11,10 @@ FUZZERS = """
        diff
        diff-apply
        extrainfo
-       hsdescv2
        hsdescv3
+       hsdescv3-inner
        http
        http-connect
-       iptsv2
        microdesc
        socks
        strops
index 10eca2176b218bddd78c345774e9d5421667af6e..cad442718b0165e6210fff7d0aadaafc1d6cac97 100644 (file)
@@ -1639,10 +1639,10 @@ desc_decrypt_superencrypted(const hs_descriptor_t *desc, char **decrypted_out)
  * decrypted_out which contains the encrypted layer of the descriptor.
  * Return the length of decrypted_out on success else 0 is returned and
  * decrypted_out is set to NULL. */
-static size_t
-desc_decrypt_encrypted(const hs_descriptor_t *desc,
-                       const curve25519_secret_key_t *client_auth_sk,
-                       char **decrypted_out)
+MOCK_IMPL(STATIC size_t,
+desc_decrypt_encrypted,(const hs_descriptor_t *desc,
+                        const curve25519_secret_key_t *client_auth_sk,
+                        char **decrypted_out))
 {
   size_t encrypted_len = 0;
   char *encrypted_plaintext = NULL;
@@ -2259,7 +2259,7 @@ desc_decode_superencrypted_v3(const hs_descriptor_t *desc,
 
 /** Decode the version 3 encrypted section of the given descriptor desc. The
  * desc_encrypted_out will be populated with the decoded data. */
-static hs_desc_decode_status_t
+STATIC hs_desc_decode_status_t
 desc_decode_encrypted_v3(const hs_descriptor_t *desc,
                          const curve25519_secret_key_t *client_auth_sk,
                          hs_desc_encrypted_data_t *desc_encrypted_out)
index 7e437faeb8805b04431acf2fe7d66e95dfd85046..5f3531fac79a81b61b2659b9810df9966a069f39 100644 (file)
@@ -339,6 +339,16 @@ MOCK_DECL(STATIC size_t, decrypt_desc_layer,(const hs_descriptor_t *desc,
                                              bool is_superencrypted_layer,
                                              char **decrypted_out));
 
+STATIC hs_desc_decode_status_t desc_decode_encrypted_v3(
+                         const hs_descriptor_t *desc,
+                         const curve25519_secret_key_t *client_auth_sk,
+                         hs_desc_encrypted_data_t *desc_encrypted_out);
+
+MOCK_DECL(STATIC size_t, desc_decrypt_encrypted,(
+                        const hs_descriptor_t *desc,
+                        const curve25519_secret_key_t *client_auth_sk,
+                        char **decrypted_out));
+
 #endif /* defined(HS_DESCRIPTOR_PRIVATE) */
 
 #endif /* !defined(TOR_HS_DESCRIPTOR_H) */
diff --git a/src/test/fuzz/fuzz_hsdescv3_inner.c b/src/test/fuzz/fuzz_hsdescv3_inner.c
new file mode 100644 (file)
index 0000000..5aa719f
--- /dev/null
@@ -0,0 +1,119 @@
+/* Copyright (c) 2017-2021, The Tor Project, Inc. */
+/* See LICENSE for licensing information */
+
+#define HS_DESCRIPTOR_PRIVATE
+
+#include "core/or/or.h"
+#include "trunnel/ed25519_cert.h" /* Trunnel interface. */
+#include "lib/crypt_ops/crypto_ed25519.h"
+#include "feature/hs/hs_descriptor.h"
+#include "feature/dirparse/unparseable.h"
+
+#include "test/fuzz/fuzzing.h"
+
+static void
+mock_dump_desc__nodump(const char *desc, const char *type)
+{
+  (void)desc;
+  (void)type;
+}
+
+static int
+mock_rsa_ed25519_crosscert_check(const uint8_t *crosscert,
+                                 const size_t crosscert_len,
+                                 const crypto_pk_t *rsa_id_key,
+                                 const ed25519_public_key_t *master_key,
+                                 const time_t reject_if_expired_before)
+{
+  (void) crosscert;
+  (void) crosscert_len;
+  (void) rsa_id_key;
+  (void) master_key;
+  (void) reject_if_expired_before;
+  return 0;
+}
+
+static size_t
+mock_decrypt_desc_layer(const hs_descriptor_t *desc,
+                        const uint8_t *descriptor_cookie,
+                        bool is_superencrypted_layer,
+                        char **decrypted_out)
+{
+  (void)is_superencrypted_layer;
+  (void)desc;
+  (void)descriptor_cookie;
+  const size_t overhead = HS_DESC_ENCRYPTED_SALT_LEN + DIGEST256_LEN;
+  const uint8_t *encrypted_blob = (is_superencrypted_layer)
+    ? desc->plaintext_data.superencrypted_blob
+    : desc->superencrypted_data.encrypted_blob;
+  size_t encrypted_blob_size = (is_superencrypted_layer)
+    ? desc->plaintext_data.superencrypted_blob_size
+    : desc->superencrypted_data.encrypted_blob_size;
+
+  if (encrypted_blob_size < overhead)
+    return 0;
+  *decrypted_out = tor_memdup_nulterm(
+                   encrypted_blob + HS_DESC_ENCRYPTED_SALT_LEN,
+                   encrypted_blob_size - overhead);
+  size_t result = strlen(*decrypted_out);
+  if (result) {
+    return result;
+  } else {
+    tor_free(*decrypted_out);
+    return 0;
+  }
+}
+
+static const uint8_t *decrypted_data = NULL;
+static size_t decrypted_len = 0;
+static size_t
+mock_desc_decrypt_encrypted(const hs_descriptor_t *desc,
+                        const curve25519_secret_key_t *client_auth_sk,
+                        char **decrypted_out)
+{
+  (void)desc;
+  (void)client_auth_sk;
+  *decrypted_out = (char*)tor_memdup_nulterm(decrypted_data, decrypted_len);
+  return decrypted_len;
+}
+
+int
+fuzz_init(void)
+{
+  disable_signature_checking();
+  MOCK(dump_desc, mock_dump_desc__nodump);
+  MOCK(rsa_ed25519_crosscert_check, mock_rsa_ed25519_crosscert_check);
+  MOCK(decrypt_desc_layer, mock_decrypt_desc_layer);
+  MOCK(desc_decrypt_encrypted, mock_desc_decrypt_encrypted);
+  ed25519_init();
+  return 0;
+}
+
+int
+fuzz_cleanup(void)
+{
+  return 0;
+}
+
+int
+fuzz_main(const uint8_t *data, size_t sz)
+{
+  decrypted_data = data;
+  decrypted_len = sz;
+
+  hs_descriptor_t *desc = tor_malloc_zero(sizeof(hs_descriptor_t));
+  hs_desc_encrypted_data_t *output = tor_malloc_zero(sizeof(*output));
+  curve25519_secret_key_t *client_auth_sk = NULL;
+  hs_desc_decode_status_t status;
+
+  status = desc_decode_encrypted_v3(desc, client_auth_sk, output);
+  if (status == HS_DESC_DECODE_OK) {
+    log_debug(LD_GENERAL, "Decoding okay");
+  } else {
+    log_debug(LD_GENERAL, "Decoding failed");
+  }
+
+  hs_descriptor_free(desc);
+  hs_desc_encrypted_data_free(output);
+  return 0;
+}
index 9bdced9e6fdd1fb3bc6687f651207105f3a3c292..a72df754a8b3272a3dc9b25c59856cbe1d390bb9 100644 (file)
@@ -93,6 +93,16 @@ src_test_fuzz_fuzz_hsdescv3_LDFLAGS = $(FUZZING_LDFLAG)
 src_test_fuzz_fuzz_hsdescv3_LDADD = $(FUZZING_LIBS)
 endif
 
+if UNITTESTS_ENABLED
+src_test_fuzz_fuzz_hsdescv3_inner_SOURCES = \
+       src/test/fuzz/fuzzing_common.c \
+       src/test/fuzz/fuzz_hsdescv3_inner.c
+src_test_fuzz_fuzz_hsdescv3_inner_CPPFLAGS = $(FUZZING_CPPFLAGS)
+src_test_fuzz_fuzz_hsdescv3_inner_CFLAGS = $(FUZZING_CFLAGS)
+src_test_fuzz_fuzz_hsdescv3_inner_LDFLAGS = $(FUZZING_LDFLAG)
+src_test_fuzz_fuzz_hsdescv3_inner_LDADD = $(FUZZING_LIBS)
+endif
+
 if UNITTESTS_ENABLED
 src_test_fuzz_fuzz_http_SOURCES = \
        src/test/fuzz/fuzzing_common.c \
@@ -161,6 +171,7 @@ FUZZERS = \
        src/test/fuzz/fuzz-diff-apply \
        src/test/fuzz/fuzz-extrainfo \
        src/test/fuzz/fuzz-hsdescv3 \
+       src/test/fuzz/fuzz-hsdescv3-inner \
        src/test/fuzz/fuzz-http \
        src/test/fuzz/fuzz-http-connect \
        src/test/fuzz/fuzz-microdesc \
@@ -226,6 +237,15 @@ src_test_fuzz_lf_fuzz_hsdescv3_LDFLAGS = $(LIBFUZZER_LDFLAG)
 src_test_fuzz_lf_fuzz_hsdescv3_LDADD = $(LIBFUZZER_LIBS)
 endif
 
+if UNITTESTS_ENABLED
+src_test_fuzz_lf_fuzz_hsdescv3_inner_SOURCES = \
+       $(src_test_fuzz_fuzz_hsdescv3_inner_SOURCES)
+src_test_fuzz_lf_fuzz_hsdescv3_inner_CPPFLAGS = $(LIBFUZZER_CPPFLAGS)
+src_test_fuzz_lf_fuzz_hsdescv3_inner_CFLAGS = $(LIBFUZZER_CFLAGS)
+src_test_fuzz_lf_fuzz_hsdescv3_inner_LDFLAGS = $(LIBFUZZER_LDFLAG)
+src_test_fuzz_lf_fuzz_hsdescv3_inner_LDADD = $(LIBFUZZER_LIBS)
+endif
+
 if UNITTESTS_ENABLED
 src_test_fuzz_lf_fuzz_http_SOURCES = \
        $(src_test_fuzz_fuzz_http_SOURCES)
@@ -287,6 +307,7 @@ LIBFUZZER_FUZZERS = \
        src/test/fuzz/lf-fuzz-diff-apply \
        src/test/fuzz/lf-fuzz-extrainfo \
        src/test/fuzz/lf-fuzz-hsdescv3 \
+       src/test/fuzz/lf-fuzz-hsdescv3-inner \
        src/test/fuzz/lf-fuzz-http \
        src/test/fuzz/lf-fuzz-http-connect \
        src/test/fuzz/lf-fuzz-microdesc \
@@ -343,6 +364,13 @@ src_test_fuzz_liboss_fuzz_hsdescv3_a_CPPFLAGS = $(LIBOSS_FUZZ_CPPFLAGS)
 src_test_fuzz_liboss_fuzz_hsdescv3_a_CFLAGS = $(LIBOSS_FUZZ_CFLAGS)
 endif
 
+if UNITTESTS_ENABLED
+src_test_fuzz_liboss_fuzz_hsdescv3_inner_a_SOURCES = \
+       $(src_test_fuzz_fuzz_hsdescv3_inner_SOURCES)
+src_test_fuzz_liboss_fuzz_hsdescv3_inner_a_CPPFLAGS = $(LIBOSS_FUZZ_CPPFLAGS)
+src_test_fuzz_liboss_fuzz_hsdescv3_inner_a_CFLAGS = $(LIBOSS_FUZZ_CFLAGS)
+endif
+
 if UNITTESTS_ENABLED
 src_test_fuzz_liboss_fuzz_http_a_SOURCES = \
        $(src_test_fuzz_fuzz_http_SOURCES)
@@ -392,6 +420,7 @@ OSS_FUZZ_FUZZERS = \
        src/test/fuzz/liboss-fuzz-diff-apply.a \
        src/test/fuzz/liboss-fuzz-extrainfo.a \
        src/test/fuzz/liboss-fuzz-hsdescv3.a \
+       src/test/fuzz/liboss-fuzz-hsdescv3-inner.a \
        src/test/fuzz/liboss-fuzz-http.a \
        src/test/fuzz/liboss-fuzz-http-connect.a \
        src/test/fuzz/liboss-fuzz-microdesc.a \