1 /*
2  *  Self-test demonstration program
3  *
4  *  Copyright The Mbed TLS Contributors
5  *  SPDX-License-Identifier: Apache-2.0
6  *
7  *  Licensed under the Apache License, Version 2.0 (the "License"); you may
8  *  not use this file except in compliance with the License.
9  *  You may obtain a copy of the License at
10  *
11  *  http://www.apache.org/licenses/LICENSE-2.0
12  *
13  *  Unless required by applicable law or agreed to in writing, software
14  *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15  *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16  *  See the License for the specific language governing permissions and
17  *  limitations under the License.
18  */
19 
20 #define MBEDTLS_ALLOW_PRIVATE_ACCESS
21 
22 #include "mbedtls/build_info.h"
23 
24 #include "mbedtls/entropy.h"
25 #include "mbedtls/hmac_drbg.h"
26 #include "mbedtls/ctr_drbg.h"
27 #include "mbedtls/dhm.h"
28 #include "mbedtls/gcm.h"
29 #include "mbedtls/ccm.h"
30 #include "mbedtls/cmac.h"
31 #include "mbedtls/md5.h"
32 #include "mbedtls/ripemd160.h"
33 #include "mbedtls/sha1.h"
34 #include "mbedtls/sha256.h"
35 #include "mbedtls/sha512.h"
36 #include "mbedtls/des.h"
37 #include "mbedtls/aes.h"
38 #include "mbedtls/camellia.h"
39 #include "mbedtls/aria.h"
40 #include "mbedtls/chacha20.h"
41 #include "mbedtls/poly1305.h"
42 #include "mbedtls/chachapoly.h"
43 #include "mbedtls/base64.h"
44 #include "mbedtls/bignum.h"
45 #include "mbedtls/rsa.h"
46 #include "mbedtls/x509.h"
47 #include "mbedtls/pkcs5.h"
48 #include "mbedtls/ecp.h"
49 #include "mbedtls/ecjpake.h"
50 #include "mbedtls/timing.h"
51 #include "mbedtls/nist_kw.h"
52 
53 #include <string.h>
54 
55 #if defined(MBEDTLS_PLATFORM_C)
56 #include "mbedtls/platform.h"
57 #else
58 #include <stdio.h>
59 #include <stdlib.h>
60 #define mbedtls_calloc     calloc
61 #define mbedtls_free       free
62 #define mbedtls_printf     printf
63 #define mbedtls_snprintf   snprintf
64 #define mbedtls_exit       exit
65 #define MBEDTLS_EXIT_SUCCESS EXIT_SUCCESS
66 #define MBEDTLS_EXIT_FAILURE EXIT_FAILURE
67 #endif
68 
69 #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
70 #include "mbedtls/memory_buffer_alloc.h"
71 #endif
72 
73 
74 #if defined MBEDTLS_SELF_TEST
75 /* Sanity check for malloc. This is not expected to fail, and is rather
76  * intended to display potentially useful information about the platform,
77  * in particular the behavior of malloc(0). */
calloc_self_test(int verbose)78 static int calloc_self_test( int verbose )
79 {
80     int failures = 0;
81     void *empty1 = mbedtls_calloc( 0, 1 );
82     void *empty2 = mbedtls_calloc( 0, 1 );
83     void *buffer1 = mbedtls_calloc( 1, 1 );
84     void *buffer2 = mbedtls_calloc( 1, 1 );
85     uintptr_t old_buffer1;
86 
87     if( empty1 == NULL && empty2 == NULL )
88     {
89         if( verbose )
90             mbedtls_printf( "  CALLOC(0): passed (NULL)\n" );
91     }
92     else if( empty1 == NULL || empty2 == NULL )
93     {
94         if( verbose )
95             mbedtls_printf( "  CALLOC(0): failed (mix of NULL and non-NULL)\n" );
96         ++failures;
97     }
98     else if( empty1 == empty2 )
99     {
100         if( verbose )
101             mbedtls_printf( "  CALLOC(0): passed (same non-null)\n" );
102     }
103     else
104     {
105         if( verbose )
106             mbedtls_printf( "  CALLOC(0): passed (distinct non-null)\n" );
107     }
108 
109     if( buffer1 == NULL || buffer2 == NULL )
110     {
111         if( verbose )
112             mbedtls_printf( "  CALLOC(1): failed (NULL)\n" );
113         ++failures;
114     }
115     else if( buffer1 == buffer2 )
116     {
117         if( verbose )
118             mbedtls_printf( "  CALLOC(1): failed (same buffer twice)\n" );
119         ++failures;
120     }
121     else
122     {
123         if( verbose )
124             mbedtls_printf( "  CALLOC(1): passed\n" );
125     }
126 
127     old_buffer1 = (uintptr_t) buffer1;
128     mbedtls_free( buffer1 );
129     buffer1 = mbedtls_calloc( 1, 1 );
130     if( buffer1 == NULL )
131     {
132         if( verbose )
133             mbedtls_printf( "  CALLOC(1 again): failed (NULL)\n" );
134         ++failures;
135     }
136     else
137     {
138         if( verbose )
139             mbedtls_printf( "  CALLOC(1 again): passed (%s address)\n",
140                             (uintptr_t) old_buffer1 == (uintptr_t) buffer1 ?
141                             "same" : "different" );
142     }
143 
144     if( verbose )
145         mbedtls_printf( "\n" );
146     mbedtls_free( empty1 );
147     mbedtls_free( empty2 );
148     mbedtls_free( buffer1 );
149     mbedtls_free( buffer2 );
150     return( failures );
151 }
152 #endif /* MBEDTLS_SELF_TEST */
153 
test_snprintf(size_t n,const char * ref_buf,int ref_ret)154 static int test_snprintf( size_t n, const char *ref_buf, int ref_ret )
155 {
156     int ret;
157     char buf[10] = "xxxxxxxxx";
158     const char ref[10] = "xxxxxxxxx";
159 
160     ret = mbedtls_snprintf( buf, n, "%s", "123" );
161     if( ret < 0 || (size_t) ret >= n )
162         ret = -1;
163 
164     if( strncmp( ref_buf, buf, sizeof( buf ) ) != 0 ||
165         ref_ret != ret ||
166         memcmp( buf + n, ref + n, sizeof( buf ) - n ) != 0 )
167     {
168         return( 1 );
169     }
170 
171     return( 0 );
172 }
173 
run_test_snprintf(void)174 static int run_test_snprintf( void )
175 {
176     return( test_snprintf( 0, "xxxxxxxxx",  -1 ) != 0 ||
177             test_snprintf( 1, "",           -1 ) != 0 ||
178             test_snprintf( 2, "1",          -1 ) != 0 ||
179             test_snprintf( 3, "12",         -1 ) != 0 ||
180             test_snprintf( 4, "123",         3 ) != 0 ||
181             test_snprintf( 5, "123",         3 ) != 0 );
182 }
183 
184 /*
185  * Check if a seed file is present, and if not create one for the entropy
186  * self-test. If this fails, we attempt the test anyway, so no error is passed
187  * back.
188  */
189 #if defined(MBEDTLS_SELF_TEST) && defined(MBEDTLS_ENTROPY_C)
190 #if defined(MBEDTLS_ENTROPY_NV_SEED) && !defined(MBEDTLS_NO_PLATFORM_ENTROPY)
create_entropy_seed_file(void)191 static void create_entropy_seed_file( void )
192 {
193     int result;
194     size_t output_len = 0;
195     unsigned char seed_value[MBEDTLS_ENTROPY_BLOCK_SIZE];
196 
197     /* Attempt to read the entropy seed file. If this fails - attempt to write
198      * to the file to ensure one is present. */
199     result = mbedtls_platform_std_nv_seed_read( seed_value,
200                                                     MBEDTLS_ENTROPY_BLOCK_SIZE );
201     if( 0 == result )
202         return;
203 
204     result = mbedtls_platform_entropy_poll( NULL,
205                                             seed_value,
206                                             MBEDTLS_ENTROPY_BLOCK_SIZE,
207                                             &output_len );
208     if( 0 != result )
209         return;
210 
211     if( MBEDTLS_ENTROPY_BLOCK_SIZE != output_len )
212         return;
213 
214     mbedtls_platform_std_nv_seed_write( seed_value, MBEDTLS_ENTROPY_BLOCK_SIZE );
215 }
216 #endif
217 
mbedtls_entropy_self_test_wrapper(int verbose)218 int mbedtls_entropy_self_test_wrapper( int verbose )
219 {
220 #if defined(MBEDTLS_ENTROPY_NV_SEED) && !defined(MBEDTLS_NO_PLATFORM_ENTROPY)
221     create_entropy_seed_file( );
222 #endif
223     return( mbedtls_entropy_self_test( verbose ) );
224 }
225 #endif
226 
227 #if defined(MBEDTLS_SELF_TEST)
228 #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
mbedtls_memory_buffer_alloc_free_and_self_test(int verbose)229 int mbedtls_memory_buffer_alloc_free_and_self_test( int verbose )
230 {
231     if( verbose != 0 )
232     {
233 #if defined(MBEDTLS_MEMORY_DEBUG)
234         mbedtls_memory_buffer_alloc_status( );
235 #endif
236     }
237     mbedtls_memory_buffer_alloc_free( );
238     return( mbedtls_memory_buffer_alloc_self_test( verbose ) );
239 }
240 #endif
241 
242 typedef struct
243 {
244     const char *name;
245     int ( *function )( int );
246 } selftest_t;
247 
248 const selftest_t selftests[] =
249 {
250     {"calloc", calloc_self_test},
251 #if defined(MBEDTLS_MD5_C)
252     {"md5", mbedtls_md5_self_test},
253 #endif
254 #if defined(MBEDTLS_RIPEMD160_C)
255     {"ripemd160", mbedtls_ripemd160_self_test},
256 #endif
257 #if defined(MBEDTLS_SHA1_C)
258     {"sha1", mbedtls_sha1_self_test},
259 #endif
260 #if defined(MBEDTLS_SHA256_C)
261     {"sha256", mbedtls_sha256_self_test},
262 #endif
263 #if defined(MBEDTLS_SHA512_C)
264     {"sha512", mbedtls_sha512_self_test},
265 #endif
266 #if defined(MBEDTLS_DES_C)
267     {"des", mbedtls_des_self_test},
268 #endif
269 #if defined(MBEDTLS_AES_C)
270     {"aes", mbedtls_aes_self_test},
271 #endif
272 #if defined(MBEDTLS_GCM_C) && defined(MBEDTLS_AES_C)
273     {"gcm", mbedtls_gcm_self_test},
274 #endif
275 #if defined(MBEDTLS_CCM_C) && defined(MBEDTLS_AES_C)
276     {"ccm", mbedtls_ccm_self_test},
277 #endif
278 #if defined(MBEDTLS_NIST_KW_C) && defined(MBEDTLS_AES_C)
279     {"nist_kw", mbedtls_nist_kw_self_test},
280 #endif
281 #if defined(MBEDTLS_CMAC_C)
282     {"cmac", mbedtls_cmac_self_test},
283 #endif
284 #if defined(MBEDTLS_CHACHA20_C)
285     {"chacha20", mbedtls_chacha20_self_test},
286 #endif
287 #if defined(MBEDTLS_POLY1305_C)
288     {"poly1305", mbedtls_poly1305_self_test},
289 #endif
290 #if defined(MBEDTLS_CHACHAPOLY_C)
291     {"chacha20-poly1305", mbedtls_chachapoly_self_test},
292 #endif
293 #if defined(MBEDTLS_BASE64_C)
294     {"base64", mbedtls_base64_self_test},
295 #endif
296 #if defined(MBEDTLS_BIGNUM_C)
297     {"mpi", mbedtls_mpi_self_test},
298 #endif
299 #if defined(MBEDTLS_RSA_C)
300     {"rsa", mbedtls_rsa_self_test},
301 #endif
302 #if defined(MBEDTLS_CAMELLIA_C)
303     {"camellia", mbedtls_camellia_self_test},
304 #endif
305 #if defined(MBEDTLS_ARIA_C)
306     {"aria", mbedtls_aria_self_test},
307 #endif
308 #if defined(MBEDTLS_CTR_DRBG_C)
309     {"ctr_drbg", mbedtls_ctr_drbg_self_test},
310 #endif
311 #if defined(MBEDTLS_HMAC_DRBG_C)
312     {"hmac_drbg", mbedtls_hmac_drbg_self_test},
313 #endif
314 #if defined(MBEDTLS_ECP_C)
315     {"ecp", mbedtls_ecp_self_test},
316 #endif
317 #if defined(MBEDTLS_ECJPAKE_C)
318     {"ecjpake", mbedtls_ecjpake_self_test},
319 #endif
320 #if defined(MBEDTLS_DHM_C)
321     {"dhm", mbedtls_dhm_self_test},
322 #endif
323 #if defined(MBEDTLS_ENTROPY_C)
324     {"entropy", mbedtls_entropy_self_test_wrapper},
325 #endif
326 #if defined(MBEDTLS_PKCS5_C)
327     {"pkcs5", mbedtls_pkcs5_self_test},
328 #endif
329 /* Heap test comes last */
330 #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
331     {"memory_buffer_alloc", mbedtls_memory_buffer_alloc_free_and_self_test},
332 #endif
333     {NULL, NULL}
334 };
335 #endif /* MBEDTLS_SELF_TEST */
336 
main(int argc,char * argv[])337 int main( int argc, char *argv[] )
338 {
339 #if defined(MBEDTLS_SELF_TEST)
340     const selftest_t *test;
341 #endif /* MBEDTLS_SELF_TEST */
342     char **argp;
343     int v = 1; /* v=1 for verbose mode */
344     int exclude_mode = 0;
345     int suites_tested = 0, suites_failed = 0;
346 #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C) && defined(MBEDTLS_SELF_TEST)
347     unsigned char buf[1000000];
348 #endif
349     void *pointer;
350 
351     /*
352      * The C standard doesn't guarantee that all-bits-0 is the representation
353      * of a NULL pointer. We do however use that in our code for initializing
354      * structures, which should work on every modern platform. Let's be sure.
355      */
356     memset( &pointer, 0, sizeof( void * ) );
357     if( pointer != NULL )
358     {
359         mbedtls_printf( "all-bits-zero is not a NULL pointer\n" );
360         mbedtls_exit( MBEDTLS_EXIT_FAILURE );
361     }
362 
363     /*
364      * Make sure we have a snprintf that correctly zero-terminates
365      */
366     if( run_test_snprintf() != 0 )
367     {
368         mbedtls_printf( "the snprintf implementation is broken\n" );
369         mbedtls_exit( MBEDTLS_EXIT_FAILURE );
370     }
371 
372     for( argp = argv + ( argc >= 1 ? 1 : argc ); *argp != NULL; ++argp )
373     {
374         if( strcmp( *argp, "--quiet" ) == 0 ||
375             strcmp( *argp, "-q" ) == 0 )
376         {
377             v = 0;
378         }
379         else if( strcmp( *argp, "--exclude" ) == 0 ||
380                  strcmp( *argp, "-x" ) == 0 )
381         {
382             exclude_mode = 1;
383         }
384         else
385             break;
386     }
387 
388     if( v != 0 )
389         mbedtls_printf( "\n" );
390 
391 #if defined(MBEDTLS_SELF_TEST)
392 
393 #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
394     mbedtls_memory_buffer_alloc_init( buf, sizeof(buf) );
395 #endif
396 
397     if( *argp != NULL && exclude_mode == 0 )
398     {
399         /* Run the specified tests */
400         for( ; *argp != NULL; argp++ )
401         {
402             for( test = selftests; test->name != NULL; test++ )
403             {
404                 if( !strcmp( *argp, test->name ) )
405                 {
406                     if( test->function( v )  != 0 )
407                     {
408                         suites_failed++;
409                     }
410                     suites_tested++;
411                     break;
412                 }
413             }
414             if( test->name == NULL )
415             {
416                 mbedtls_printf( "  Test suite %s not available -> failed\n\n", *argp );
417                 suites_failed++;
418             }
419         }
420     }
421     else
422     {
423         /* Run all the tests except excluded ones */
424         for( test = selftests; test->name != NULL; test++ )
425         {
426             if( exclude_mode )
427             {
428                 char **excluded;
429                 for( excluded = argp; *excluded != NULL; ++excluded )
430                 {
431                     if( !strcmp( *excluded, test->name ) )
432                         break;
433                 }
434                 if( *excluded )
435                 {
436                     if( v )
437                         mbedtls_printf( "  Skip: %s\n", test->name );
438                     continue;
439                 }
440             }
441             if( test->function( v )  != 0 )
442             {
443                 suites_failed++;
444             }
445             suites_tested++;
446         }
447     }
448 
449 #else
450     (void) exclude_mode;
451     mbedtls_printf( " MBEDTLS_SELF_TEST not defined.\n" );
452 #endif
453 
454     if( v != 0 )
455     {
456         mbedtls_printf( "  Executed %d test suites\n\n", suites_tested );
457 
458         if( suites_failed > 0)
459         {
460             mbedtls_printf( "  [ %d tests FAIL ]\n\n", suites_failed );
461         }
462         else
463         {
464             mbedtls_printf( "  [ All tests PASS ]\n\n" );
465         }
466 #if defined(_WIN32)
467         mbedtls_printf( "  Press Enter to exit this program.\n" );
468         fflush( stdout ); getchar();
469 #endif
470     }
471 
472     if( suites_failed > 0)
473         mbedtls_exit( MBEDTLS_EXIT_FAILURE );
474 
475     mbedtls_exit( MBEDTLS_EXIT_SUCCESS );
476 }
477