HEIMDAL: move code from source4/heimdal* to third_party/heimdal*
[Samba.git] / third_party / heimdal / lib / asn1 / check-common.c
blob8a6b5dacd3b609c1d66aa5893cc7bac026c82f44
1 /*
2 * Copyright (c) 1999 - 2006 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
4 * All rights reserved.
6 * Portions Copyright (c) 2009 Apple Inc. All rights reserved.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
10 * are met:
12 * 1. Redistributions of source code must retain the above copyright
13 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
19 * 3. Neither the name of the Institute nor the names of its contributors
20 * may be used to endorse or promote products derived from this software
21 * without specific prior written permission.
23 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * SUCH DAMAGE.
36 #include <config.h>
37 #ifdef HAVE_SYS_MMAN_H
38 #include <sys/mman.h>
39 #endif
40 #include <stdio.h>
41 #include <string.h>
42 #include <err.h>
43 #include <roken.h>
45 #include "asn1-common.h"
46 #include "check-common.h"
48 struct map_page {
49 void *start;
50 size_t size;
51 void *data_start;
52 size_t data_size;
53 enum map_type type;
56 /* #undef HAVE_MMAP */
58 void *
59 map_alloc(enum map_type type, const void *buf,
60 size_t size, struct map_page **map)
62 #ifndef HAVE_MMAP
63 unsigned char *p;
64 size_t len = size + sizeof(long) * 2;
65 int i;
67 *map = ecalloc(1, sizeof(**map));
69 p = emalloc(len);
70 (*map)->type = type;
71 (*map)->start = p;
72 (*map)->size = len;
73 (*map)->data_start = p + sizeof(long);
74 for (i = sizeof(long); i > 0; i--)
75 p[sizeof(long) - i] = 0xff - i;
76 for (i = sizeof(long); i > 0; i--)
77 p[len - i] = 0xff - i;
78 #else
79 unsigned char *p;
80 int flags, ret, fd;
81 size_t pagesize = getpagesize();
83 *map = ecalloc(1, sizeof(**map));
85 (*map)->type = type;
87 #ifdef MAP_ANON
88 flags = MAP_ANON;
89 fd = -1;
90 #else
91 flags = 0;
92 fd = open ("/dev/zero", O_RDONLY);
93 if(fd < 0)
94 err (1, "open /dev/zero");
95 #endif
96 flags |= MAP_PRIVATE;
98 (*map)->size = size + pagesize - (size % pagesize) + pagesize * 2;
100 p = (unsigned char *)mmap(0, (*map)->size, PROT_READ | PROT_WRITE,
101 flags, fd, 0);
102 if (p == (unsigned char *)MAP_FAILED)
103 err (1, "mmap");
105 (*map)->start = p;
107 ret = mprotect (p, pagesize, 0);
108 if (ret < 0)
109 err (1, "mprotect");
111 ret = mprotect (p + (*map)->size - pagesize, pagesize, 0);
112 if (ret < 0)
113 err (1, "mprotect");
115 switch (type) {
116 case OVERRUN:
117 (*map)->data_start = p + (*map)->size - pagesize - size;
118 break;
119 case UNDERRUN:
120 (*map)->data_start = p + pagesize;
121 break;
122 default:
123 abort();
125 #endif
126 (*map)->data_size = size;
127 if (buf)
128 memcpy((*map)->data_start, buf, size);
129 return (*map)->data_start;
132 void
133 map_free(struct map_page *map, const char *test_name, const char *map_name)
135 #ifndef HAVE_MMAP
136 unsigned char *p = map->start;
137 int i;
139 for (i = sizeof(long); i > 0; i--)
140 if (p[sizeof(long) - i] != 0xff - i)
141 errx(1, "%s: %s underrun %d\n", test_name, map_name, i);
142 for (i = sizeof(long); i > 0; i--)
143 if (p[map->size - i] != 0xff - i)
144 errx(1, "%s: %s overrun %lu\n", test_name, map_name,
145 (unsigned long)map->size - i);
146 free(map->start);
147 #else
148 int ret;
150 ret = munmap (map->start, map->size);
151 if (ret < 0)
152 err (1, "munmap");
153 #endif
154 free(map);
157 static void
158 print_bytes (unsigned const char *buf, size_t len)
160 int i;
162 for (i = 0; i < len; ++i)
163 printf ("%02x ", buf[i]);
166 #ifndef MAP_FAILED
167 #define MAP_FAILED (-1)
168 #endif
170 static char *current_test = "<uninit>";
171 static char *current_state = "<uninit>";
173 static RETSIGTYPE
174 segv_handler(int sig)
176 int fd;
177 char msg[] = "SIGSEGV i current test: ";
178 /* For compilers that insist we check write(2)'s result here */
179 int e = 1;
181 fd = open("/dev/stdout", O_WRONLY, 0600);
182 if (fd >= 0) {
184 if (write(fd, msg, sizeof(msg)) == -1 ||
185 write(fd, current_test, strlen(current_test)) == -1 ||
186 write(fd, " ", 1) == -1 ||
187 write(fd, current_state, strlen(current_state)) == -1 ||
188 write(fd, "\n", 1) == -1)
189 e = 2;
190 (void) close(fd);
192 _exit(e);
196 generic_test (const struct test_case *tests,
197 unsigned ntests,
198 size_t data_size,
199 int (ASN1CALL *encode)(unsigned char *, size_t, void *, size_t *),
200 size_t (ASN1CALL *length)(void *),
201 int (ASN1CALL *decode)(unsigned char *, size_t, void *, size_t *),
202 void (ASN1CALL *free_data)(void *),
203 int (*cmp)(void *a, void *b),
204 int (ASN1CALL *copy)(const void *from, void *to))
206 unsigned char *buf, *buf2;
207 int i;
208 int failures = 0;
209 void *data;
210 struct map_page *data_map, *buf_map, *buf2_map;
212 #ifdef HAVE_SIGACTION
213 struct sigaction sa, osa;
214 #endif
216 for (i = 0; i < ntests; ++i) {
217 int ret;
218 size_t sz, consumed_sz, length_sz, buf_sz;
219 void *to = NULL;
221 current_test = tests[i].name;
223 current_state = "init";
225 #ifdef HAVE_SIGACTION
226 sigemptyset (&sa.sa_mask);
227 sa.sa_flags = 0;
228 #ifdef SA_RESETHAND
229 sa.sa_flags |= SA_RESETHAND;
230 #endif
231 sa.sa_handler = segv_handler;
232 sigaction (SIGSEGV, &sa, &osa);
233 #endif
235 data = map_alloc(OVERRUN, NULL, data_size, &data_map);
237 buf_sz = tests[i].byte_len;
238 buf = map_alloc(UNDERRUN, NULL, buf_sz, &buf_map);
240 current_state = "encode";
241 ret = (*encode) (buf + buf_sz - 1, buf_sz,
242 tests[i].val, &sz);
243 if (ret != 0) {
244 printf ("encoding of %s failed %d\n", tests[i].name, ret);
245 ++failures;
246 continue;
248 if (sz != tests[i].byte_len) {
249 printf ("encoding of %s has wrong len (%lu != %lu)\n",
250 tests[i].name,
251 (unsigned long)sz, (unsigned long)tests[i].byte_len);
252 ++failures;
253 continue;
256 current_state = "length";
257 length_sz = (*length) (tests[i].val);
258 if (sz != length_sz) {
259 printf ("length for %s is bad (%lu != %lu)\n",
260 tests[i].name, (unsigned long)length_sz, (unsigned long)sz);
261 ++failures;
262 continue;
265 current_state = "memcmp";
266 if (memcmp (buf, tests[i].bytes, tests[i].byte_len) != 0) {
267 printf ("encoding of %s has bad bytes:\n"
268 "correct: ", tests[i].name);
269 print_bytes ((unsigned char *)tests[i].bytes, tests[i].byte_len);
270 printf ("\nactual: ");
271 print_bytes (buf, sz);
272 printf ("\n");
273 #if 0
274 rk_dumpdata("correct", tests[i].bytes, tests[i].byte_len);
275 rk_dumpdata("actual", buf, sz);
276 exit (1);
277 #endif
278 ++failures;
279 continue;
282 buf2 = map_alloc(OVERRUN, buf, sz, &buf2_map);
284 current_state = "decode";
285 ret = (*decode) (buf2, sz, data, &consumed_sz);
286 if (ret != 0) {
287 printf ("decoding of %s failed %d\n", tests[i].name, ret);
288 ++failures;
289 continue;
291 if (sz != consumed_sz) {
292 printf ("different length decoding %s (%ld != %ld)\n",
293 tests[i].name,
294 (unsigned long)sz, (unsigned long)consumed_sz);
295 ++failures;
296 continue;
298 current_state = "cmp";
299 if ((*cmp)(data, tests[i].val) != 0) {
300 printf ("%s: comparison failed\n", tests[i].name);
301 ++failures;
302 continue;
305 current_state = "copy";
306 if (copy) {
307 to = emalloc(data_size);
308 ret = (*copy)(data, to);
309 if (ret != 0) {
310 printf ("copy of %s failed %d\n", tests[i].name, ret);
311 ++failures;
312 continue;
315 current_state = "cmp-copy";
316 if ((*cmp)(data, to) != 0) {
317 printf ("%s: copy comparison failed\n", tests[i].name);
318 ++failures;
319 continue;
323 current_state = "free";
324 if (free_data) {
325 (*free_data)(data);
326 if (to) {
327 (*free_data)(to);
328 free(to);
332 current_state = "free";
333 map_free(buf_map, tests[i].name, "encode");
334 map_free(buf2_map, tests[i].name, "decode");
335 map_free(data_map, tests[i].name, "data");
337 #ifdef HAVE_SIGACTION
338 sigaction (SIGSEGV, &osa, NULL);
339 #endif
341 current_state = "done";
342 return failures;
346 * check for failures
348 * a test size (byte_len) of -1 means that the test tries to trigger a
349 * integer overflow (and later a malloc of to little memory), just
350 * allocate some memory and hope that is enough for that test.
354 generic_decode_fail (const struct test_case *tests,
355 unsigned ntests,
356 size_t data_size,
357 int (ASN1CALL *decode)(unsigned char *, size_t, void *, size_t *))
359 unsigned char *buf;
360 int i;
361 int failures = 0;
362 void *data;
363 struct map_page *data_map, *buf_map;
365 #ifdef HAVE_SIGACTION
366 struct sigaction sa, osa;
367 #endif
369 for (i = 0; i < ntests; ++i) {
370 int ret;
371 size_t sz;
372 const void *bytes;
374 current_test = tests[i].name;
376 current_state = "init";
378 #ifdef HAVE_SIGACTION
379 sigemptyset (&sa.sa_mask);
380 sa.sa_flags = 0;
381 #ifdef SA_RESETHAND
382 sa.sa_flags |= SA_RESETHAND;
383 #endif
384 sa.sa_handler = segv_handler;
385 sigaction (SIGSEGV, &sa, &osa);
386 #endif
388 data = map_alloc(OVERRUN, NULL, data_size, &data_map);
390 if (tests[i].byte_len < 0xffffff && tests[i].byte_len >= 0) {
391 sz = tests[i].byte_len;
392 bytes = tests[i].bytes;
393 } else {
394 sz = 4096;
395 bytes = NULL;
398 buf = map_alloc(OVERRUN, bytes, sz, &buf_map);
400 if (tests[i].byte_len == -1)
401 memset(buf, 0, sz);
403 current_state = "decode";
404 ret = (*decode) (buf, tests[i].byte_len, data, &sz);
405 if (ret == 0) {
406 printf ("sucessfully decoded %s\n", tests[i].name);
407 ++failures;
408 continue;
411 current_state = "free";
412 if (buf)
413 map_free(buf_map, tests[i].name, "encode");
414 map_free(data_map, tests[i].name, "data");
416 #ifdef HAVE_SIGACTION
417 sigaction (SIGSEGV, &osa, NULL);
418 #endif
420 current_state = "done";
421 return failures;