1 /*
2  *  Generic ASN.1 parsing
3  *
4  *  Copyright The Mbed TLS Contributors
5  *  SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
6  *
7  *  This file is provided under the Apache License 2.0, or the
8  *  GNU General Public License v2.0 or later.
9  *
10  *  **********
11  *  Apache License 2.0:
12  *
13  *  Licensed under the Apache License, Version 2.0 (the "License"); you may
14  *  not use this file except in compliance with the License.
15  *  You may obtain a copy of the License at
16  *
17  *  http://www.apache.org/licenses/LICENSE-2.0
18  *
19  *  Unless required by applicable law or agreed to in writing, software
20  *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
21  *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
22  *  See the License for the specific language governing permissions and
23  *  limitations under the License.
24  *
25  *  **********
26  *
27  *  **********
28  *  GNU General Public License v2.0 or later:
29  *
30  *  This program is free software; you can redistribute it and/or modify
31  *  it under the terms of the GNU General Public License as published by
32  *  the Free Software Foundation; either version 2 of the License, or
33  *  (at your option) any later version.
34  *
35  *  This program is distributed in the hope that it will be useful,
36  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
37  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
38  *  GNU General Public License for more details.
39  *
40  *  You should have received a copy of the GNU General Public License along
41  *  with this program; if not, write to the Free Software Foundation, Inc.,
42  *  51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
43  *
44  *  **********
45  */
46 
47 #if !defined(MBEDTLS_CONFIG_FILE)
48 #include "mbedtls/config.h"
49 #else
50 #include MBEDTLS_CONFIG_FILE
51 #endif
52 
53 #if defined(MBEDTLS_ASN1_PARSE_C)
54 
55 #include "mbedtls/asn1.h"
56 
57 #include <string.h>
58 
59 #if defined(MBEDTLS_BIGNUM_C)
60 #include "mbedtls/bignum.h"
61 #endif
62 
63 #if defined(MBEDTLS_PLATFORM_C)
64 #include "mbedtls/platform.h"
65 #else
66 #include <stdlib.h>
67 #define mbedtls_calloc    calloc
68 #define mbedtls_free       free
69 #endif
70 
71 /* Implementation that should never be optimized out by the compiler */
mbedtls_zeroize(void * v,size_t n)72 static void mbedtls_zeroize( void *v, size_t n ) {
73     volatile unsigned char *p = (unsigned char*)v; while( n-- ) *p++ = 0;
74 }
75 
76 /*
77  * ASN.1 DER decoding routines
78  */
mbedtls_asn1_get_len(unsigned char ** p,const unsigned char * end,size_t * len)79 int mbedtls_asn1_get_len( unsigned char **p,
80                   const unsigned char *end,
81                   size_t *len )
82 {
83     if( ( end - *p ) < 1 )
84         return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
85 
86     if( ( **p & 0x80 ) == 0 )
87         *len = *(*p)++;
88     else
89     {
90         switch( **p & 0x7F )
91         {
92         case 1:
93             if( ( end - *p ) < 2 )
94                 return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
95 
96             *len = (*p)[1];
97             (*p) += 2;
98             break;
99 
100         case 2:
101             if( ( end - *p ) < 3 )
102                 return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
103 
104             *len = ( (size_t)(*p)[1] << 8 ) | (*p)[2];
105             (*p) += 3;
106             break;
107 
108         case 3:
109             if( ( end - *p ) < 4 )
110                 return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
111 
112             *len = ( (size_t)(*p)[1] << 16 ) |
113                    ( (size_t)(*p)[2] << 8  ) | (*p)[3];
114             (*p) += 4;
115             break;
116 
117         case 4:
118             if( ( end - *p ) < 5 )
119                 return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
120 
121             *len = ( (size_t)(*p)[1] << 24 ) | ( (size_t)(*p)[2] << 16 ) |
122                    ( (size_t)(*p)[3] << 8  ) |           (*p)[4];
123             (*p) += 5;
124             break;
125 
126         default:
127             return( MBEDTLS_ERR_ASN1_INVALID_LENGTH );
128         }
129     }
130 
131     if( *len > (size_t) ( end - *p ) )
132         return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
133 
134     return( 0 );
135 }
136 
mbedtls_asn1_get_tag(unsigned char ** p,const unsigned char * end,size_t * len,int tag)137 int mbedtls_asn1_get_tag( unsigned char **p,
138                   const unsigned char *end,
139                   size_t *len, int tag )
140 {
141     if( ( end - *p ) < 1 )
142         return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
143 
144     if( **p != tag )
145         return( MBEDTLS_ERR_ASN1_UNEXPECTED_TAG );
146 
147     (*p)++;
148 
149     return( mbedtls_asn1_get_len( p, end, len ) );
150 }
151 
mbedtls_asn1_get_bool(unsigned char ** p,const unsigned char * end,int * val)152 int mbedtls_asn1_get_bool( unsigned char **p,
153                    const unsigned char *end,
154                    int *val )
155 {
156     int ret;
157     size_t len;
158 
159     if( ( ret = mbedtls_asn1_get_tag( p, end, &len, MBEDTLS_ASN1_BOOLEAN ) ) != 0 )
160         return( ret );
161 
162     if( len != 1 )
163         return( MBEDTLS_ERR_ASN1_INVALID_LENGTH );
164 
165     *val = ( **p != 0 ) ? 1 : 0;
166     (*p)++;
167 
168     return( 0 );
169 }
170 
mbedtls_asn1_get_int(unsigned char ** p,const unsigned char * end,int * val)171 int mbedtls_asn1_get_int( unsigned char **p,
172                   const unsigned char *end,
173                   int *val )
174 {
175     int ret;
176     size_t len;
177 
178     if( ( ret = mbedtls_asn1_get_tag( p, end, &len, MBEDTLS_ASN1_INTEGER ) ) != 0 )
179         return( ret );
180 
181     if( len == 0 || len > sizeof( int ) || ( **p & 0x80 ) != 0 )
182         return( MBEDTLS_ERR_ASN1_INVALID_LENGTH );
183 
184     *val = 0;
185 
186     while( len-- > 0 )
187     {
188         *val = ( *val << 8 ) | **p;
189         (*p)++;
190     }
191 
192     return( 0 );
193 }
194 
195 #if defined(MBEDTLS_BIGNUM_C)
mbedtls_asn1_get_mpi(unsigned char ** p,const unsigned char * end,mbedtls_mpi * X)196 int mbedtls_asn1_get_mpi( unsigned char **p,
197                   const unsigned char *end,
198                   mbedtls_mpi *X )
199 {
200     int ret;
201     size_t len;
202 
203     if( ( ret = mbedtls_asn1_get_tag( p, end, &len, MBEDTLS_ASN1_INTEGER ) ) != 0 )
204         return( ret );
205 
206     ret = mbedtls_mpi_read_binary( X, *p, len );
207 
208     *p += len;
209 
210     return( ret );
211 }
212 #endif /* MBEDTLS_BIGNUM_C */
213 
mbedtls_asn1_get_bitstring(unsigned char ** p,const unsigned char * end,mbedtls_asn1_bitstring * bs)214 int mbedtls_asn1_get_bitstring( unsigned char **p, const unsigned char *end,
215                         mbedtls_asn1_bitstring *bs)
216 {
217     int ret;
218 
219     /* Certificate type is a single byte bitstring */
220     if( ( ret = mbedtls_asn1_get_tag( p, end, &bs->len, MBEDTLS_ASN1_BIT_STRING ) ) != 0 )
221         return( ret );
222 
223     /* Check length, subtract one for actual bit string length */
224     if( bs->len < 1 )
225         return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
226     bs->len -= 1;
227 
228     /* Get number of unused bits, ensure unused bits <= 7 */
229     bs->unused_bits = **p;
230     if( bs->unused_bits > 7 )
231         return( MBEDTLS_ERR_ASN1_INVALID_LENGTH );
232     (*p)++;
233 
234     /* Get actual bitstring */
235     bs->p = *p;
236     *p += bs->len;
237 
238     if( *p != end )
239         return( MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
240 
241     return( 0 );
242 }
243 
244 /*
245  * Get a bit string without unused bits
246  */
mbedtls_asn1_get_bitstring_null(unsigned char ** p,const unsigned char * end,size_t * len)247 int mbedtls_asn1_get_bitstring_null( unsigned char **p, const unsigned char *end,
248                              size_t *len )
249 {
250     int ret;
251 
252     if( ( ret = mbedtls_asn1_get_tag( p, end, len, MBEDTLS_ASN1_BIT_STRING ) ) != 0 )
253         return( ret );
254 
255     if( (*len)-- < 2 || *(*p)++ != 0 )
256         return( MBEDTLS_ERR_ASN1_INVALID_DATA );
257 
258     return( 0 );
259 }
260 
261 
262 
263 /*
264  *  Parses and splits an ASN.1 "SEQUENCE OF <tag>"
265  */
mbedtls_asn1_get_sequence_of(unsigned char ** p,const unsigned char * end,mbedtls_asn1_sequence * cur,int tag)266 int mbedtls_asn1_get_sequence_of( unsigned char **p,
267                           const unsigned char *end,
268                           mbedtls_asn1_sequence *cur,
269                           int tag)
270 {
271     int ret;
272     size_t len;
273     mbedtls_asn1_buf *buf;
274 
275     /* Get main sequence tag */
276     if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
277             MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
278         return( ret );
279 
280     if( *p + len != end )
281         return( MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
282 
283     while( *p < end )
284     {
285         buf = &(cur->buf);
286         buf->tag = **p;
287 
288         if( ( ret = mbedtls_asn1_get_tag( p, end, &buf->len, tag ) ) != 0 )
289             return( ret );
290 
291         buf->p = *p;
292         *p += buf->len;
293 
294         /* Allocate and assign next pointer */
295         if( *p < end )
296         {
297             cur->next = (mbedtls_asn1_sequence*)mbedtls_calloc( 1,
298                                             sizeof( mbedtls_asn1_sequence ) );
299 
300             if( cur->next == NULL )
301                 return( MBEDTLS_ERR_ASN1_ALLOC_FAILED );
302 
303             cur = cur->next;
304         }
305     }
306 
307     /* Set final sequence entry's next pointer to NULL */
308     cur->next = NULL;
309 
310     if( *p != end )
311         return( MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
312 
313     return( 0 );
314 }
315 
mbedtls_asn1_get_alg(unsigned char ** p,const unsigned char * end,mbedtls_asn1_buf * alg,mbedtls_asn1_buf * params)316 int mbedtls_asn1_get_alg( unsigned char **p,
317                   const unsigned char *end,
318                   mbedtls_asn1_buf *alg, mbedtls_asn1_buf *params )
319 {
320     int ret;
321     size_t len;
322 
323     if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
324             MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
325         return( ret );
326 
327     if( ( end - *p ) < 1 )
328         return( MBEDTLS_ERR_ASN1_OUT_OF_DATA );
329 
330     alg->tag = **p;
331     end = *p + len;
332 
333     if( ( ret = mbedtls_asn1_get_tag( p, end, &alg->len, MBEDTLS_ASN1_OID ) ) != 0 )
334         return( ret );
335 
336     alg->p = *p;
337     *p += alg->len;
338 
339     if( *p == end )
340     {
341         mbedtls_zeroize( params, sizeof(mbedtls_asn1_buf) );
342         return( 0 );
343     }
344 
345     params->tag = **p;
346     (*p)++;
347 
348     if( ( ret = mbedtls_asn1_get_len( p, end, &params->len ) ) != 0 )
349         return( ret );
350 
351     params->p = *p;
352     *p += params->len;
353 
354     if( *p != end )
355         return( MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
356 
357     return( 0 );
358 }
359 
mbedtls_asn1_get_alg_null(unsigned char ** p,const unsigned char * end,mbedtls_asn1_buf * alg)360 int mbedtls_asn1_get_alg_null( unsigned char **p,
361                        const unsigned char *end,
362                        mbedtls_asn1_buf *alg )
363 {
364     int ret;
365     mbedtls_asn1_buf params;
366 
367     memset( &params, 0, sizeof(mbedtls_asn1_buf) );
368 
369     if( ( ret = mbedtls_asn1_get_alg( p, end, alg, &params ) ) != 0 )
370         return( ret );
371 
372     if( ( params.tag != MBEDTLS_ASN1_NULL && params.tag != 0 ) || params.len != 0 )
373         return( MBEDTLS_ERR_ASN1_INVALID_DATA );
374 
375     return( 0 );
376 }
377 
mbedtls_asn1_free_named_data(mbedtls_asn1_named_data * cur)378 void mbedtls_asn1_free_named_data( mbedtls_asn1_named_data *cur )
379 {
380     if( cur == NULL )
381         return;
382 
383     mbedtls_free( cur->oid.p );
384     mbedtls_free( cur->val.p );
385 
386     mbedtls_zeroize( cur, sizeof( mbedtls_asn1_named_data ) );
387 }
388 
mbedtls_asn1_free_named_data_list(mbedtls_asn1_named_data ** head)389 void mbedtls_asn1_free_named_data_list( mbedtls_asn1_named_data **head )
390 {
391     mbedtls_asn1_named_data *cur;
392 
393     while( ( cur = *head ) != NULL )
394     {
395         *head = cur->next;
396         mbedtls_asn1_free_named_data( cur );
397         mbedtls_free( cur );
398     }
399 }
400 
mbedtls_asn1_find_named_data(mbedtls_asn1_named_data * list,const char * oid,size_t len)401 mbedtls_asn1_named_data *mbedtls_asn1_find_named_data( mbedtls_asn1_named_data *list,
402                                        const char *oid, size_t len )
403 {
404     while( list != NULL )
405     {
406         if( list->oid.len == len &&
407             memcmp( list->oid.p, oid, len ) == 0 )
408         {
409             break;
410         }
411 
412         list = list->next;
413     }
414 
415     return( list );
416 }
417 
418 #endif /* MBEDTLS_ASN1_PARSE_C */
419