Skip to content

Commit 4312559

Browse files
committed
Merge #19296: tests: Add fuzzing harness for AES{CBC,}256{Encrypt,Decrypt}, poly1305_auth, CHKDF_HMAC_SHA256_L32, ChaCha20 and ChaCha20Poly1305AEAD
cca7c57 tests: Add fuzzing harness for ChaCha20Poly1305AEAD (practicalswift) 2fc4e59 tests: Add fuzzing harness for ChaCha20 (practicalswift) e9e8aac tests: Add fuzzing harness for CHKDF_HMAC_SHA256_L32 (practicalswift) ec86ca1 tests: Add fuzzing harness for poly1305_auth(...) (practicalswift) 4cee53b tests: Add fuzzing harness for AES256CBCEncrypt/AES256CBCDecrypt (practicalswift) 9352c32 tests: Add fuzzing harness for AES256Encrypt/AES256Decrypt (practicalswift) Pull request description: Add fuzzing harness for `AES{CBC,}256{Encrypt,Decrypt}`, `poly1305_auth`, `CHKDF_HMAC_SHA256_L32`, `ChaCha20` and `ChaCha20Poly1305AEAD`. See [`doc/fuzzing.md`](https://github.com/bitcoin/bitcoin/blob/master/doc/fuzzing.md) for information on how to fuzz Bitcoin Core. Don't forget to contribute any coverage increasing inputs you find to the [Bitcoin Core fuzzing corpus repo](https://github.com/bitcoin-core/qa-assets). Happy fuzzing :) ACKs for top commit: laanwj: ACK cca7c57 Tree-SHA512: cff9acefe370c12a3663aa55145371df835479c6ab8f6d81bbf84e0f81a9d6b0d94e45ec545f9dd5e1702744eaa7947a1f4ffed0171f446fc080369161afd740
2 parents 2c4093e + cca7c57 commit 4312559

7 files changed

+275
-0
lines changed

src/Makefile.test.include

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,13 @@ FUZZ_TARGETS = \
3434
test/fuzz/coins_deserialize \
3535
test/fuzz/coins_view \
3636
test/fuzz/crypto \
37+
test/fuzz/crypto_aes256 \
38+
test/fuzz/crypto_aes256cbc \
39+
test/fuzz/crypto_chacha20 \
40+
test/fuzz/crypto_chacha20_poly1305_aead \
3741
test/fuzz/crypto_common \
42+
test/fuzz/crypto_hkdf_hmac_sha256_l32 \
43+
test/fuzz/crypto_poly1305 \
3844
test/fuzz/cuckoocache \
3945
test/fuzz/decode_tx \
4046
test/fuzz/descriptor_parse \
@@ -494,12 +500,48 @@ test_fuzz_crypto_LDADD = $(FUZZ_SUITE_LD_COMMON)
494500
test_fuzz_crypto_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
495501
test_fuzz_crypto_SOURCES = test/fuzz/crypto.cpp
496502

503+
test_fuzz_crypto_aes256_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
504+
test_fuzz_crypto_aes256_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
505+
test_fuzz_crypto_aes256_LDADD = $(FUZZ_SUITE_LD_COMMON)
506+
test_fuzz_crypto_aes256_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
507+
test_fuzz_crypto_aes256_SOURCES = test/fuzz/crypto_aes256.cpp
508+
509+
test_fuzz_crypto_aes256cbc_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
510+
test_fuzz_crypto_aes256cbc_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
511+
test_fuzz_crypto_aes256cbc_LDADD = $(FUZZ_SUITE_LD_COMMON)
512+
test_fuzz_crypto_aes256cbc_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
513+
test_fuzz_crypto_aes256cbc_SOURCES = test/fuzz/crypto_aes256cbc.cpp
514+
515+
test_fuzz_crypto_chacha20_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
516+
test_fuzz_crypto_chacha20_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
517+
test_fuzz_crypto_chacha20_LDADD = $(FUZZ_SUITE_LD_COMMON)
518+
test_fuzz_crypto_chacha20_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
519+
test_fuzz_crypto_chacha20_SOURCES = test/fuzz/crypto_chacha20.cpp
520+
521+
test_fuzz_crypto_chacha20_poly1305_aead_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
522+
test_fuzz_crypto_chacha20_poly1305_aead_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
523+
test_fuzz_crypto_chacha20_poly1305_aead_LDADD = $(FUZZ_SUITE_LD_COMMON)
524+
test_fuzz_crypto_chacha20_poly1305_aead_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
525+
test_fuzz_crypto_chacha20_poly1305_aead_SOURCES = test/fuzz/crypto_chacha20_poly1305_aead.cpp
526+
497527
test_fuzz_crypto_common_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
498528
test_fuzz_crypto_common_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
499529
test_fuzz_crypto_common_LDADD = $(FUZZ_SUITE_LD_COMMON)
500530
test_fuzz_crypto_common_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
501531
test_fuzz_crypto_common_SOURCES = test/fuzz/crypto_common.cpp
502532

533+
test_fuzz_crypto_hkdf_hmac_sha256_l32_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
534+
test_fuzz_crypto_hkdf_hmac_sha256_l32_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
535+
test_fuzz_crypto_hkdf_hmac_sha256_l32_LDADD = $(FUZZ_SUITE_LD_COMMON)
536+
test_fuzz_crypto_hkdf_hmac_sha256_l32_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
537+
test_fuzz_crypto_hkdf_hmac_sha256_l32_SOURCES = test/fuzz/crypto_hkdf_hmac_sha256_l32.cpp
538+
539+
test_fuzz_crypto_poly1305_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
540+
test_fuzz_crypto_poly1305_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
541+
test_fuzz_crypto_poly1305_LDADD = $(FUZZ_SUITE_LD_COMMON)
542+
test_fuzz_crypto_poly1305_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
543+
test_fuzz_crypto_poly1305_SOURCES = test/fuzz/crypto_poly1305.cpp
544+
503545
test_fuzz_cuckoocache_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
504546
test_fuzz_cuckoocache_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
505547
test_fuzz_cuckoocache_LDADD = $(FUZZ_SUITE_LD_COMMON)

src/test/fuzz/crypto_aes256.cpp

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/aes.h>
6+
#include <test/fuzz/FuzzedDataProvider.h>
7+
#include <test/fuzz/fuzz.h>
8+
#include <test/fuzz/util.h>
9+
10+
#include <cassert>
11+
#include <cstdint>
12+
#include <vector>
13+
14+
void test_one_input(const std::vector<uint8_t>& buffer)
15+
{
16+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
17+
const std::vector<uint8_t> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES256_KEYSIZE);
18+
19+
AES256Encrypt encrypt{key.data()};
20+
AES256Decrypt decrypt{key.data()};
21+
22+
while (fuzzed_data_provider.ConsumeBool()) {
23+
const std::vector<uint8_t> plaintext = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES_BLOCKSIZE);
24+
std::vector<uint8_t> ciphertext(AES_BLOCKSIZE);
25+
encrypt.Encrypt(ciphertext.data(), plaintext.data());
26+
std::vector<uint8_t> decrypted_plaintext(AES_BLOCKSIZE);
27+
decrypt.Decrypt(decrypted_plaintext.data(), ciphertext.data());
28+
assert(decrypted_plaintext == plaintext);
29+
}
30+
}

src/test/fuzz/crypto_aes256cbc.cpp

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/aes.h>
6+
#include <test/fuzz/FuzzedDataProvider.h>
7+
#include <test/fuzz/fuzz.h>
8+
#include <test/fuzz/util.h>
9+
10+
#include <cassert>
11+
#include <cstdint>
12+
#include <vector>
13+
14+
void test_one_input(const std::vector<uint8_t>& buffer)
15+
{
16+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
17+
const std::vector<uint8_t> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES256_KEYSIZE);
18+
const std::vector<uint8_t> iv = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES_BLOCKSIZE);
19+
const bool pad = fuzzed_data_provider.ConsumeBool();
20+
21+
AES256CBCEncrypt encrypt{key.data(), iv.data(), pad};
22+
AES256CBCDecrypt decrypt{key.data(), iv.data(), pad};
23+
24+
while (fuzzed_data_provider.ConsumeBool()) {
25+
const std::vector<uint8_t> plaintext = ConsumeRandomLengthByteVector(fuzzed_data_provider);
26+
std::vector<uint8_t> ciphertext(plaintext.size() + AES_BLOCKSIZE);
27+
const int encrypt_ret = encrypt.Encrypt(plaintext.data(), plaintext.size(), ciphertext.data());
28+
ciphertext.resize(encrypt_ret);
29+
std::vector<uint8_t> decrypted_plaintext(ciphertext.size());
30+
const int decrypt_ret = decrypt.Decrypt(ciphertext.data(), ciphertext.size(), decrypted_plaintext.data());
31+
decrypted_plaintext.resize(decrypt_ret);
32+
assert(decrypted_plaintext == plaintext || (!pad && plaintext.size() % AES_BLOCKSIZE != 0 && encrypt_ret == 0 && decrypt_ret == 0));
33+
}
34+
}

src/test/fuzz/crypto_chacha20.cpp

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/chacha20.h>
6+
#include <test/fuzz/FuzzedDataProvider.h>
7+
#include <test/fuzz/fuzz.h>
8+
#include <test/fuzz/util.h>
9+
10+
#include <cstdint>
11+
#include <vector>
12+
13+
void test_one_input(const std::vector<uint8_t>& buffer)
14+
{
15+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
16+
17+
ChaCha20 chacha20;
18+
if (fuzzed_data_provider.ConsumeBool()) {
19+
const std::vector<unsigned char> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, fuzzed_data_provider.ConsumeIntegralInRange<size_t>(16, 32));
20+
chacha20 = ChaCha20{key.data(), key.size()};
21+
}
22+
while (fuzzed_data_provider.ConsumeBool()) {
23+
switch (fuzzed_data_provider.ConsumeIntegralInRange(0, 4)) {
24+
case 0: {
25+
const std::vector<unsigned char> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, fuzzed_data_provider.ConsumeIntegralInRange<size_t>(16, 32));
26+
chacha20.SetKey(key.data(), key.size());
27+
break;
28+
}
29+
case 1: {
30+
chacha20.SetIV(fuzzed_data_provider.ConsumeIntegral<uint64_t>());
31+
break;
32+
}
33+
case 2: {
34+
chacha20.Seek(fuzzed_data_provider.ConsumeIntegral<uint64_t>());
35+
break;
36+
}
37+
case 3: {
38+
std::vector<uint8_t> output(fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, 4096));
39+
chacha20.Keystream(output.data(), output.size());
40+
break;
41+
}
42+
case 4: {
43+
std::vector<uint8_t> output(fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, 4096));
44+
const std::vector<uint8_t> input = ConsumeFixedLengthByteVector(fuzzed_data_provider, output.size());
45+
chacha20.Crypt(input.data(), output.data(), input.size());
46+
break;
47+
}
48+
}
49+
}
50+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/chacha_poly_aead.h>
6+
#include <crypto/poly1305.h>
7+
#include <test/fuzz/FuzzedDataProvider.h>
8+
#include <test/fuzz/fuzz.h>
9+
#include <test/fuzz/util.h>
10+
11+
#include <cassert>
12+
#include <cstdint>
13+
#include <limits>
14+
#include <vector>
15+
16+
void test_one_input(const std::vector<uint8_t>& buffer)
17+
{
18+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
19+
20+
const std::vector<uint8_t> k1 = ConsumeFixedLengthByteVector(fuzzed_data_provider, CHACHA20_POLY1305_AEAD_KEY_LEN);
21+
const std::vector<uint8_t> k2 = ConsumeFixedLengthByteVector(fuzzed_data_provider, CHACHA20_POLY1305_AEAD_KEY_LEN);
22+
23+
ChaCha20Poly1305AEAD aead(k1.data(), k1.size(), k2.data(), k2.size());
24+
uint64_t seqnr_payload = 0;
25+
uint64_t seqnr_aad = 0;
26+
int aad_pos = 0;
27+
size_t buffer_size = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, 4096);
28+
std::vector<uint8_t> in(buffer_size + CHACHA20_POLY1305_AEAD_AAD_LEN + POLY1305_TAGLEN, 0);
29+
std::vector<uint8_t> out(buffer_size + CHACHA20_POLY1305_AEAD_AAD_LEN + POLY1305_TAGLEN, 0);
30+
bool is_encrypt = fuzzed_data_provider.ConsumeBool();
31+
while (fuzzed_data_provider.ConsumeBool()) {
32+
switch (fuzzed_data_provider.ConsumeIntegralInRange<int>(0, 6)) {
33+
case 0: {
34+
buffer_size = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(64, 4096);
35+
in = std::vector<uint8_t>(buffer_size + CHACHA20_POLY1305_AEAD_AAD_LEN + POLY1305_TAGLEN, 0);
36+
out = std::vector<uint8_t>(buffer_size + CHACHA20_POLY1305_AEAD_AAD_LEN + POLY1305_TAGLEN, 0);
37+
break;
38+
}
39+
case 1: {
40+
(void)aead.Crypt(seqnr_payload, seqnr_aad, aad_pos, out.data(), out.size(), in.data(), buffer_size, is_encrypt);
41+
break;
42+
}
43+
case 2: {
44+
uint32_t len = 0;
45+
const bool ok = aead.GetLength(&len, seqnr_aad, aad_pos, in.data());
46+
assert(ok);
47+
break;
48+
}
49+
case 3: {
50+
seqnr_payload += 1;
51+
aad_pos += CHACHA20_POLY1305_AEAD_AAD_LEN;
52+
if (aad_pos + CHACHA20_POLY1305_AEAD_AAD_LEN > CHACHA20_ROUND_OUTPUT) {
53+
aad_pos = 0;
54+
seqnr_aad += 1;
55+
}
56+
break;
57+
}
58+
case 4: {
59+
seqnr_payload = fuzzed_data_provider.ConsumeIntegral<int>();
60+
break;
61+
}
62+
case 5: {
63+
seqnr_aad = fuzzed_data_provider.ConsumeIntegral<int>();
64+
break;
65+
}
66+
case 6: {
67+
is_encrypt = fuzzed_data_provider.ConsumeBool();
68+
break;
69+
}
70+
}
71+
}
72+
}
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/hkdf_sha256_32.h>
6+
#include <test/fuzz/FuzzedDataProvider.h>
7+
#include <test/fuzz/fuzz.h>
8+
#include <test/fuzz/util.h>
9+
10+
#include <cstdint>
11+
#include <string>
12+
#include <vector>
13+
14+
void test_one_input(const std::vector<uint8_t>& buffer)
15+
{
16+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
17+
18+
const std::vector<uint8_t> initial_key_material = ConsumeRandomLengthByteVector(fuzzed_data_provider);
19+
20+
CHKDF_HMAC_SHA256_L32 hkdf_hmac_sha256_l32(initial_key_material.data(), initial_key_material.size(), fuzzed_data_provider.ConsumeRandomLengthString(1024));
21+
while (fuzzed_data_provider.ConsumeBool()) {
22+
std::vector<uint8_t> out(32);
23+
hkdf_hmac_sha256_l32.Expand32(fuzzed_data_provider.ConsumeRandomLengthString(128), out.data());
24+
}
25+
}

src/test/fuzz/crypto_poly1305.cpp

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <crypto/poly1305.h>
6+
#include <test/fuzz/FuzzedDataProvider.h>
7+
#include <test/fuzz/fuzz.h>
8+
#include <test/fuzz/util.h>
9+
10+
#include <cstdint>
11+
#include <vector>
12+
13+
void test_one_input(const std::vector<uint8_t>& buffer)
14+
{
15+
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
16+
17+
const std::vector<uint8_t> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, POLY1305_KEYLEN);
18+
const std::vector<uint8_t> in = ConsumeRandomLengthByteVector(fuzzed_data_provider);
19+
20+
std::vector<uint8_t> tag_out(POLY1305_TAGLEN);
21+
poly1305_auth(tag_out.data(), in.data(), in.size(), key.data());
22+
}

0 commit comments

Comments
 (0)