test_rng.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355
  1. /*
  2. * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <string.h>
  10. #include <stdlib.h>
  11. #include <openssl/core_dispatch.h>
  12. #include <openssl/e_os2.h>
  13. #include <openssl/params.h>
  14. #include <openssl/core_names.h>
  15. #include <openssl/evp.h>
  16. #include <openssl/err.h>
  17. #include <openssl/randerr.h>
  18. #include "prov/securitycheck.h"
  19. #include "prov/providercommon.h"
  20. #include "prov/provider_ctx.h"
  21. #include "prov/provider_util.h"
  22. #include "prov/implementations.h"
  23. static OSSL_FUNC_rand_newctx_fn test_rng_new;
  24. static OSSL_FUNC_rand_freectx_fn test_rng_free;
  25. static OSSL_FUNC_rand_instantiate_fn test_rng_instantiate;
  26. static OSSL_FUNC_rand_uninstantiate_fn test_rng_uninstantiate;
  27. static OSSL_FUNC_rand_generate_fn test_rng_generate;
  28. static OSSL_FUNC_rand_reseed_fn test_rng_reseed;
  29. static OSSL_FUNC_rand_nonce_fn test_rng_nonce;
  30. static OSSL_FUNC_rand_settable_ctx_params_fn test_rng_settable_ctx_params;
  31. static OSSL_FUNC_rand_set_ctx_params_fn test_rng_set_ctx_params;
  32. static OSSL_FUNC_rand_gettable_ctx_params_fn test_rng_gettable_ctx_params;
  33. static OSSL_FUNC_rand_get_ctx_params_fn test_rng_get_ctx_params;
  34. static OSSL_FUNC_rand_verify_zeroization_fn test_rng_verify_zeroization;
  35. static OSSL_FUNC_rand_enable_locking_fn test_rng_enable_locking;
  36. static OSSL_FUNC_rand_lock_fn test_rng_lock;
  37. static OSSL_FUNC_rand_unlock_fn test_rng_unlock;
  38. static OSSL_FUNC_rand_get_seed_fn test_rng_get_seed;
  39. typedef struct {
  40. void *provctx;
  41. unsigned int generate;
  42. int state;
  43. unsigned int strength;
  44. size_t max_request;
  45. unsigned char *entropy, *nonce;
  46. size_t entropy_len, entropy_pos, nonce_len;
  47. CRYPTO_RWLOCK *lock;
  48. uint32_t seed;
  49. } PROV_TEST_RNG;
  50. static void *test_rng_new(void *provctx, void *parent,
  51. const OSSL_DISPATCH *parent_dispatch)
  52. {
  53. PROV_TEST_RNG *t;
  54. t = OPENSSL_zalloc(sizeof(*t));
  55. if (t == NULL)
  56. return NULL;
  57. t->max_request = INT_MAX;
  58. t->provctx = provctx;
  59. t->state = EVP_RAND_STATE_UNINITIALISED;
  60. return t;
  61. }
  62. static void test_rng_free(void *vtest)
  63. {
  64. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  65. if (t == NULL)
  66. return;
  67. OPENSSL_free(t->entropy);
  68. OPENSSL_free(t->nonce);
  69. CRYPTO_THREAD_lock_free(t->lock);
  70. OPENSSL_free(t);
  71. }
  72. static int test_rng_instantiate(void *vtest, unsigned int strength,
  73. int prediction_resistance,
  74. const unsigned char *pstr, size_t pstr_len,
  75. const OSSL_PARAM params[])
  76. {
  77. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  78. if (!test_rng_set_ctx_params(t, params) || strength > t->strength)
  79. return 0;
  80. t->state = EVP_RAND_STATE_READY;
  81. t->entropy_pos = 0;
  82. t->seed = 221953166; /* Value doesn't matter, so long as it isn't zero */
  83. return 1;
  84. }
  85. static int test_rng_uninstantiate(void *vtest)
  86. {
  87. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  88. t->entropy_pos = 0;
  89. t->state = EVP_RAND_STATE_UNINITIALISED;
  90. return 1;
  91. }
  92. static unsigned char gen_byte(PROV_TEST_RNG *t)
  93. {
  94. uint32_t n;
  95. /*
  96. * Implement the 32 bit xorshift as suggested by George Marsaglia in:
  97. * https://doi.org/10.18637/jss.v008.i14
  98. *
  99. * This is a very fast PRNG so there is no need to extract bytes one at a
  100. * time and use the entire value each time.
  101. */
  102. n = t->seed;
  103. n ^= n << 13;
  104. n ^= n >> 17;
  105. n ^= n << 5;
  106. t->seed = n;
  107. return n & 0xff;
  108. }
  109. static int test_rng_generate(void *vtest, unsigned char *out, size_t outlen,
  110. unsigned int strength, int prediction_resistance,
  111. const unsigned char *adin, size_t adin_len)
  112. {
  113. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  114. size_t i;
  115. if (strength > t->strength)
  116. return 0;
  117. if (t->generate) {
  118. for (i = 0; i < outlen; i++)
  119. out[i] = gen_byte(t);
  120. } else {
  121. if (t->entropy_len - t->entropy_pos < outlen)
  122. return 0;
  123. memcpy(out, t->entropy + t->entropy_pos, outlen);
  124. t->entropy_pos += outlen;
  125. }
  126. return 1;
  127. }
  128. static int test_rng_reseed(ossl_unused void *vtest,
  129. ossl_unused int prediction_resistance,
  130. ossl_unused const unsigned char *ent,
  131. ossl_unused size_t ent_len,
  132. ossl_unused const unsigned char *adin,
  133. ossl_unused size_t adin_len)
  134. {
  135. return 1;
  136. }
  137. static size_t test_rng_nonce(void *vtest, unsigned char *out,
  138. unsigned int strength, size_t min_noncelen,
  139. size_t max_noncelen)
  140. {
  141. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  142. size_t i;
  143. if (strength > t->strength)
  144. return 0;
  145. if (t->generate) {
  146. for (i = 0; i < min_noncelen; i++)
  147. out[i] = gen_byte(t);
  148. return min_noncelen;
  149. }
  150. if (t->nonce == NULL)
  151. return 0;
  152. i = t->nonce_len > max_noncelen ? max_noncelen : t->nonce_len;
  153. if (out != NULL)
  154. memcpy(out, t->nonce, i);
  155. return i;
  156. }
  157. static int test_rng_get_ctx_params(void *vtest, OSSL_PARAM params[])
  158. {
  159. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  160. OSSL_PARAM *p;
  161. p = OSSL_PARAM_locate(params, OSSL_RAND_PARAM_STATE);
  162. if (p != NULL && !OSSL_PARAM_set_int(p, t->state))
  163. return 0;
  164. p = OSSL_PARAM_locate(params, OSSL_RAND_PARAM_STRENGTH);
  165. if (p != NULL && !OSSL_PARAM_set_int(p, t->strength))
  166. return 0;
  167. p = OSSL_PARAM_locate(params, OSSL_RAND_PARAM_MAX_REQUEST);
  168. if (p != NULL && !OSSL_PARAM_set_size_t(p, t->max_request))
  169. return 0;
  170. p = OSSL_PARAM_locate(params, OSSL_RAND_PARAM_GENERATE);
  171. if (p != NULL && !OSSL_PARAM_set_uint(p, t->generate))
  172. return 0;
  173. #ifdef FIPS_MODULE
  174. p = OSSL_PARAM_locate(params, OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR);
  175. if (p != NULL && !OSSL_PARAM_set_int(p, 0))
  176. return 0;
  177. #endif /* FIPS_MODULE */
  178. return 1;
  179. }
  180. static const OSSL_PARAM *test_rng_gettable_ctx_params(ossl_unused void *vtest,
  181. ossl_unused void *provctx)
  182. {
  183. static const OSSL_PARAM known_gettable_ctx_params[] = {
  184. OSSL_PARAM_int(OSSL_RAND_PARAM_STATE, NULL),
  185. OSSL_PARAM_uint(OSSL_RAND_PARAM_STRENGTH, NULL),
  186. OSSL_PARAM_size_t(OSSL_RAND_PARAM_MAX_REQUEST, NULL),
  187. OSSL_PARAM_uint(OSSL_RAND_PARAM_GENERATE, NULL),
  188. OSSL_FIPS_IND_GETTABLE_CTX_PARAM()
  189. OSSL_PARAM_END
  190. };
  191. return known_gettable_ctx_params;
  192. }
  193. static int test_rng_set_ctx_params(void *vtest, const OSSL_PARAM params[])
  194. {
  195. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  196. const OSSL_PARAM *p;
  197. void *ptr = NULL;
  198. size_t size = 0;
  199. if (ossl_param_is_empty(params))
  200. return 1;
  201. p = OSSL_PARAM_locate_const(params, OSSL_RAND_PARAM_STRENGTH);
  202. if (p != NULL && !OSSL_PARAM_get_uint(p, &t->strength))
  203. return 0;
  204. p = OSSL_PARAM_locate_const(params, OSSL_RAND_PARAM_TEST_ENTROPY);
  205. if (p != NULL) {
  206. if (!OSSL_PARAM_get_octet_string(p, &ptr, 0, &size))
  207. return 0;
  208. OPENSSL_free(t->entropy);
  209. t->entropy = ptr;
  210. t->entropy_len = size;
  211. t->entropy_pos = 0;
  212. ptr = NULL;
  213. }
  214. p = OSSL_PARAM_locate_const(params, OSSL_RAND_PARAM_TEST_NONCE);
  215. if (p != NULL) {
  216. if (!OSSL_PARAM_get_octet_string(p, &ptr, 0, &size))
  217. return 0;
  218. OPENSSL_free(t->nonce);
  219. t->nonce = ptr;
  220. t->nonce_len = size;
  221. }
  222. p = OSSL_PARAM_locate_const(params, OSSL_RAND_PARAM_MAX_REQUEST);
  223. if (p != NULL && !OSSL_PARAM_get_size_t(p, &t->max_request))
  224. return 0;
  225. p = OSSL_PARAM_locate_const(params, OSSL_RAND_PARAM_GENERATE);
  226. if (p != NULL && !OSSL_PARAM_get_uint(p, &t->generate))
  227. return 0;
  228. return 1;
  229. }
  230. static const OSSL_PARAM *test_rng_settable_ctx_params(ossl_unused void *vtest,
  231. ossl_unused void *provctx)
  232. {
  233. static const OSSL_PARAM known_settable_ctx_params[] = {
  234. OSSL_PARAM_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, NULL, 0),
  235. OSSL_PARAM_octet_string(OSSL_RAND_PARAM_TEST_NONCE, NULL, 0),
  236. OSSL_PARAM_uint(OSSL_RAND_PARAM_STRENGTH, NULL),
  237. OSSL_PARAM_size_t(OSSL_RAND_PARAM_MAX_REQUEST, NULL),
  238. OSSL_PARAM_uint(OSSL_RAND_PARAM_GENERATE, NULL),
  239. OSSL_PARAM_END
  240. };
  241. return known_settable_ctx_params;
  242. }
  243. static int test_rng_verify_zeroization(ossl_unused void *vtest)
  244. {
  245. return 1;
  246. }
  247. static size_t test_rng_get_seed(void *vtest, unsigned char **pout,
  248. int entropy, size_t min_len, size_t max_len,
  249. ossl_unused int prediction_resistance,
  250. ossl_unused const unsigned char *adin,
  251. ossl_unused size_t adin_len)
  252. {
  253. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  254. *pout = t->entropy;
  255. return t->entropy_len > max_len ? max_len : t->entropy_len;
  256. }
  257. static int test_rng_enable_locking(void *vtest)
  258. {
  259. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  260. if (t != NULL && t->lock == NULL) {
  261. t->lock = CRYPTO_THREAD_lock_new();
  262. if (t->lock == NULL) {
  263. ERR_raise(ERR_LIB_PROV, RAND_R_FAILED_TO_CREATE_LOCK);
  264. return 0;
  265. }
  266. }
  267. return 1;
  268. }
  269. static int test_rng_lock(void *vtest)
  270. {
  271. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  272. if (t == NULL || t->lock == NULL)
  273. return 1;
  274. return CRYPTO_THREAD_write_lock(t->lock);
  275. }
  276. static void test_rng_unlock(void *vtest)
  277. {
  278. PROV_TEST_RNG *t = (PROV_TEST_RNG *)vtest;
  279. if (t != NULL && t->lock != NULL)
  280. CRYPTO_THREAD_unlock(t->lock);
  281. }
  282. const OSSL_DISPATCH ossl_test_rng_functions[] = {
  283. { OSSL_FUNC_RAND_NEWCTX, (void(*)(void))test_rng_new },
  284. { OSSL_FUNC_RAND_FREECTX, (void(*)(void))test_rng_free },
  285. { OSSL_FUNC_RAND_INSTANTIATE,
  286. (void(*)(void))test_rng_instantiate },
  287. { OSSL_FUNC_RAND_UNINSTANTIATE,
  288. (void(*)(void))test_rng_uninstantiate },
  289. { OSSL_FUNC_RAND_GENERATE, (void(*)(void))test_rng_generate },
  290. { OSSL_FUNC_RAND_RESEED, (void(*)(void))test_rng_reseed },
  291. { OSSL_FUNC_RAND_NONCE, (void(*)(void))test_rng_nonce },
  292. { OSSL_FUNC_RAND_ENABLE_LOCKING, (void(*)(void))test_rng_enable_locking },
  293. { OSSL_FUNC_RAND_LOCK, (void(*)(void))test_rng_lock },
  294. { OSSL_FUNC_RAND_UNLOCK, (void(*)(void))test_rng_unlock },
  295. { OSSL_FUNC_RAND_SETTABLE_CTX_PARAMS,
  296. (void(*)(void))test_rng_settable_ctx_params },
  297. { OSSL_FUNC_RAND_SET_CTX_PARAMS, (void(*)(void))test_rng_set_ctx_params },
  298. { OSSL_FUNC_RAND_GETTABLE_CTX_PARAMS,
  299. (void(*)(void))test_rng_gettable_ctx_params },
  300. { OSSL_FUNC_RAND_GET_CTX_PARAMS, (void(*)(void))test_rng_get_ctx_params },
  301. { OSSL_FUNC_RAND_VERIFY_ZEROIZATION,
  302. (void(*)(void))test_rng_verify_zeroization },
  303. { OSSL_FUNC_RAND_GET_SEED, (void(*)(void))test_rng_get_seed },
  304. OSSL_DISPATCH_END
  305. };