1 /*
2  * Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.
3  *
4  * Licensed under the Apache License 2.0 (the "License").  You may not use
5  * this file except in compliance with the License.  You can obtain a copy
6  * in the file LICENSE in the source distribution or at
7  * https://www.openssl.org/source/license.html
8  */
9 
10 #include <stddef.h>
11 #include <string.h>
12 #include "internal/cryptlib.h"
13 #include "internal/refcount.h"
14 #include <openssl/asn1.h>
15 #include <openssl/asn1t.h>
16 #include <openssl/objects.h>
17 #include <openssl/err.h>
18 #include "asn1_local.h"
19 
20 /* Utility functions for manipulating fields and offsets */
21 
22 /* Add 'offset' to 'addr' */
23 #define offset2ptr(addr, offset) (void *)(((char *) addr) + offset)
24 
25 /*
26  * Given an ASN1_ITEM CHOICE type return the selector value
27  */
28 
ossl_asn1_get_choice_selector(ASN1_VALUE ** pval,const ASN1_ITEM * it)29 int ossl_asn1_get_choice_selector(ASN1_VALUE **pval, const ASN1_ITEM *it)
30 {
31     int *sel = offset2ptr(*pval, it->utype);
32 
33     return *sel;
34 }
35 
ossl_asn1_get_choice_selector_const(const ASN1_VALUE ** pval,const ASN1_ITEM * it)36 int ossl_asn1_get_choice_selector_const(const ASN1_VALUE **pval,
37                                         const ASN1_ITEM *it)
38 {
39     int *sel = offset2ptr(*pval, it->utype);
40 
41     return *sel;
42 }
43 
44 /*
45  * Given an ASN1_ITEM CHOICE type set the selector value, return old value.
46  */
47 
ossl_asn1_set_choice_selector(ASN1_VALUE ** pval,int value,const ASN1_ITEM * it)48 int ossl_asn1_set_choice_selector(ASN1_VALUE **pval, int value,
49                                   const ASN1_ITEM *it)
50 {
51     int *sel, ret;
52 
53     sel = offset2ptr(*pval, it->utype);
54     ret = *sel;
55     *sel = value;
56     return ret;
57 }
58 
59 /*
60  * Do atomic reference counting. The value 'op' decides what to do.
61  * If it is +1 then the count is incremented.
62  * If |op| is 0, count is initialised and set to 1.
63  * If |op| is -1, count is decremented and the return value is the current
64  * reference count or 0 if no reference count is active.
65  * It returns -1 on initialisation error.
66  * Used by ASN1_SEQUENCE construct of X509, X509_REQ, X509_CRL objects
67  */
ossl_asn1_do_lock(ASN1_VALUE ** pval,int op,const ASN1_ITEM * it)68 int ossl_asn1_do_lock(ASN1_VALUE **pval, int op, const ASN1_ITEM *it)
69 {
70     const ASN1_AUX *aux;
71     CRYPTO_RWLOCK **lock;
72     CRYPTO_REF_COUNT *refcnt;
73     int ret = -1;
74 
75     if ((it->itype != ASN1_ITYPE_SEQUENCE)
76         && (it->itype != ASN1_ITYPE_NDEF_SEQUENCE))
77         return 0;
78     aux = it->funcs;
79     if (aux == NULL || (aux->flags & ASN1_AFLG_REFCOUNT) == 0)
80         return 0;
81     lock = offset2ptr(*pval, aux->ref_lock);
82     refcnt = offset2ptr(*pval, aux->ref_offset);
83 
84     switch (op) {
85     case 0:
86         if (!CRYPTO_NEW_REF(refcnt, 1))
87             return -1;
88         *lock = CRYPTO_THREAD_lock_new();
89         if (*lock == NULL) {
90             CRYPTO_FREE_REF(refcnt);
91             ERR_raise(ERR_LIB_ASN1, ERR_R_CRYPTO_LIB);
92             return -1;
93         }
94         ret = 1;
95         break;
96     case 1:
97         if (!CRYPTO_UP_REF(refcnt, &ret))
98             return -1;
99         break;
100     case -1:
101         if (!CRYPTO_DOWN_REF(refcnt, &ret))
102             return -1;  /* failed */
103         REF_PRINT_EX(it->sname, ret, (void *)it);
104         REF_ASSERT_ISNT(ret < 0);
105         if (ret == 0) {
106             CRYPTO_THREAD_lock_free(*lock);
107             *lock = NULL;
108             CRYPTO_FREE_REF(refcnt);
109         }
110         break;
111     }
112 
113     return ret;
114 }
115 
asn1_get_enc_ptr(ASN1_VALUE ** pval,const ASN1_ITEM * it)116 static ASN1_ENCODING *asn1_get_enc_ptr(ASN1_VALUE **pval, const ASN1_ITEM *it)
117 {
118     const ASN1_AUX *aux;
119 
120     if (pval == NULL || *pval == NULL)
121         return NULL;
122     aux = it->funcs;
123     if (aux == NULL || (aux->flags & ASN1_AFLG_ENCODING) == 0)
124         return NULL;
125     return offset2ptr(*pval, aux->enc_offset);
126 }
127 
asn1_get_const_enc_ptr(const ASN1_VALUE ** pval,const ASN1_ITEM * it)128 static const ASN1_ENCODING *asn1_get_const_enc_ptr(const ASN1_VALUE **pval,
129                                                    const ASN1_ITEM *it)
130 {
131     const ASN1_AUX *aux;
132 
133     if (pval == NULL || *pval == NULL)
134         return NULL;
135     aux = it->funcs;
136     if (aux == NULL || (aux->flags & ASN1_AFLG_ENCODING) == 0)
137         return NULL;
138     return offset2ptr(*pval, aux->enc_offset);
139 }
140 
ossl_asn1_enc_init(ASN1_VALUE ** pval,const ASN1_ITEM * it)141 void ossl_asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it)
142 {
143     ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
144 
145     if (enc != NULL) {
146         enc->enc = NULL;
147         enc->len = 0;
148         enc->modified = 1;
149     }
150 }
151 
ossl_asn1_enc_free(ASN1_VALUE ** pval,const ASN1_ITEM * it)152 void ossl_asn1_enc_free(ASN1_VALUE **pval, const ASN1_ITEM *it)
153 {
154     ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
155 
156     if (enc != NULL) {
157         OPENSSL_free(enc->enc);
158         enc->enc = NULL;
159         enc->len = 0;
160         enc->modified = 1;
161     }
162 }
163 
ossl_asn1_enc_save(ASN1_VALUE ** pval,const unsigned char * in,long inlen,const ASN1_ITEM * it)164 int ossl_asn1_enc_save(ASN1_VALUE **pval, const unsigned char *in, long inlen,
165                        const ASN1_ITEM *it)
166 {
167     ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
168 
169     if (enc == NULL)
170         return 1;
171 
172     OPENSSL_free(enc->enc);
173     if (inlen <= 0) {
174         enc->enc = NULL;
175         return 0;
176     }
177     if ((enc->enc = OPENSSL_malloc(inlen)) == NULL)
178         return 0;
179     memcpy(enc->enc, in, inlen);
180     enc->len = inlen;
181     enc->modified = 0;
182 
183     return 1;
184 }
185 
ossl_asn1_enc_restore(int * len,unsigned char ** out,const ASN1_VALUE ** pval,const ASN1_ITEM * it)186 int ossl_asn1_enc_restore(int *len, unsigned char **out, const ASN1_VALUE **pval,
187                           const ASN1_ITEM *it)
188 {
189     const ASN1_ENCODING *enc = asn1_get_const_enc_ptr(pval, it);
190 
191     if (enc == NULL || enc->modified)
192         return 0;
193     if (out) {
194         memcpy(*out, enc->enc, enc->len);
195         *out += enc->len;
196     }
197     if (len != NULL)
198         *len = enc->len;
199     return 1;
200 }
201 
202 /* Given an ASN1_TEMPLATE get a pointer to a field */
ossl_asn1_get_field_ptr(ASN1_VALUE ** pval,const ASN1_TEMPLATE * tt)203 ASN1_VALUE **ossl_asn1_get_field_ptr(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt)
204 {
205     ASN1_VALUE **pvaltmp = offset2ptr(*pval, tt->offset);
206 
207     /*
208      * NOTE for BOOLEAN types the field is just a plain int so we can't
209      * return int **, so settle for (int *).
210      */
211     return pvaltmp;
212 }
213 
214 /* Given an ASN1_TEMPLATE get a const pointer to a field */
ossl_asn1_get_const_field_ptr(const ASN1_VALUE ** pval,const ASN1_TEMPLATE * tt)215 const ASN1_VALUE **ossl_asn1_get_const_field_ptr(const ASN1_VALUE **pval,
216                                                  const ASN1_TEMPLATE *tt)
217 {
218     return offset2ptr(*pval, tt->offset);
219 }
220 
221 /*
222  * Handle ANY DEFINED BY template, find the selector, look up the relevant
223  * ASN1_TEMPLATE in the table and return it.
224  */
225 
ossl_asn1_do_adb(const ASN1_VALUE * val,const ASN1_TEMPLATE * tt,int nullerr)226 const ASN1_TEMPLATE *ossl_asn1_do_adb(const ASN1_VALUE *val,
227                                       const ASN1_TEMPLATE *tt,
228                                       int nullerr)
229 {
230     const ASN1_ADB *adb;
231     const ASN1_ADB_TABLE *atbl;
232     long selector;
233     const ASN1_VALUE **sfld;
234     int i;
235 
236     if ((tt->flags & ASN1_TFLG_ADB_MASK) == 0)
237         return tt;
238 
239     /* Else ANY DEFINED BY ... get the table */
240     adb = ASN1_ADB_ptr(tt->item);
241 
242     /* Get the selector field */
243     sfld = offset2ptr(val, adb->offset);
244 
245     /* Check if NULL */
246     if (*sfld == NULL) {
247         if (adb->null_tt == NULL)
248             goto err;
249         return adb->null_tt;
250     }
251 
252     /*
253      * Convert type to a long: NB: don't check for NID_undef here because it
254      * might be a legitimate value in the table
255      */
256     if ((tt->flags & ASN1_TFLG_ADB_OID) != 0)
257         selector = OBJ_obj2nid((ASN1_OBJECT *)*sfld);
258     else
259         selector = ASN1_INTEGER_get((ASN1_INTEGER *)*sfld);
260 
261     /* Let application callback translate value */
262     if (adb->adb_cb != NULL && adb->adb_cb(&selector) == 0) {
263         ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
264         return NULL;
265     }
266 
267     /*
268      * Try to find matching entry in table Maybe should check application
269      * types first to allow application override? Might also be useful to
270      * have a flag which indicates table is sorted and we can do a binary
271      * search. For now stick to a linear search.
272      */
273 
274     for (atbl = adb->tbl, i = 0; i < adb->tblcount; i++, atbl++)
275         if (atbl->value == selector)
276             return &atbl->tt;
277 
278     /* FIXME: need to search application table too */
279 
280     /* No match, return default type */
281     if (!adb->default_tt)
282         goto err;
283     return adb->default_tt;
284 
285  err:
286     /* FIXME: should log the value or OID of unsupported type */
287     if (nullerr)
288         ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
289     return NULL;
290 }
291