update master-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2024-01-17 22:52:53 +00:00
8 changed files with 558 additions and 502 deletions
+1
View File
@@ -314,6 +314,7 @@ crypto_test_data = [
"src/crypto/keccak/keccak_tests.txt",
"src/crypto/kyber/kyber_tests.txt",
"src/crypto/pkcs8/test/empty_password.p12",
"src/crypto/pkcs8/test/empty_password_ber.p12",
"src/crypto/pkcs8/test/no_encryption.p12",
"src/crypto/pkcs8/test/nss.p12",
"src/crypto/pkcs8/test/null_password.p12",
+508 -499
View File
File diff suppressed because one or more lines are too long
+1
View File
@@ -700,6 +700,7 @@
"src/crypto/keccak/keccak_tests.txt",
"src/crypto/kyber/kyber_tests.txt",
"src/crypto/pkcs8/test/empty_password.p12",
"src/crypto/pkcs8/test/empty_password_ber.p12",
"src/crypto/pkcs8/test/no_encryption.p12",
"src/crypto/pkcs8/test/nss.p12",
"src/crypto/pkcs8/test/null_password.p12",
+5 -3
View File
@@ -56,13 +56,11 @@ static int is_string_type(CBS_ASN1_TAG tag) {
// found. The value of |orig_in| is not changed. It returns one on success (i.e.
// |*ber_found| was set) and zero on error.
static int cbs_find_ber(const CBS *orig_in, int *ber_found, uint32_t depth) {
CBS in;
if (depth > kMaxDepth) {
return 0;
}
CBS_init(&in, CBS_data(orig_in), CBS_len(orig_in));
CBS in = *orig_in;
*ber_found = 0;
while (CBS_len(&in) > 0) {
@@ -87,6 +85,10 @@ static int cbs_find_ber(const CBS *orig_in, int *ber_found, uint32_t depth) {
!cbs_find_ber(&contents, ber_found, depth + 1)) {
return 0;
}
if (*ber_found) {
// We already found BER. No need to continue parsing.
return 1;
}
}
}
+35
View File
@@ -679,6 +679,38 @@ TEST(CBSTest, BerConvert) {
0xa0, 0x08, 0x04, 0x02, 0x00, 0x01, 0x04, 0x02, 0x02, 0x03,
};
// kWrappedIndefBER contains indefinite-length SEQUENCE, wrapped
// and followed by valid DER. This tests that we correctly identify BER nested
// inside DER.
//
// SEQUENCE {
// SEQUENCE {
// SEQUENCE indefinite {}
// }
// SEQUENCE {}
// }
static const uint8_t kWrappedIndefBER[] = {0x30, 0x08, 0x30, 0x04, 0x30,
0x80, 0x00, 0x00, 0x30, 0x00};
static const uint8_t kWrappedIndefDER[] = {0x30, 0x06, 0x30, 0x02,
0x30, 0x00, 0x30, 0x00};
// kWrappedConstructedStringBER contains a constructed OCTET STRING, wrapped
// and followed by valid DER. This tests that we correctly identify BER nested
// inside DER.
//
// SEQUENCE {
// SEQUENCE {
// [OCTET_STRING CONSTRUCTED] {
// OCTET_STRING {}
// }
// }
// SEQUENCE {}
// }
static const uint8_t kWrappedConstructedStringBER[] = {
0x30, 0x08, 0x30, 0x04, 0x24, 0x02, 0x04, 0x00, 0x30, 0x00};
static const uint8_t kWrappedConstructedStringDER[] = {
0x30, 0x06, 0x30, 0x02, 0x04, 0x00, 0x30, 0x00};
// kConstructedBitString contains a BER constructed BIT STRING. These are not
// supported and thus are left unchanged.
static const uint8_t kConstructedBitStringBER[] = {
@@ -695,6 +727,9 @@ TEST(CBSTest, BerConvert) {
kConstructedStringBER);
ExpectBerConvert("kConstructedBitStringBER", kConstructedBitStringBER,
kConstructedBitStringBER);
ExpectBerConvert("kWrappedIndefBER", kWrappedIndefDER, kWrappedIndefBER);
ExpectBerConvert("kWrappedConstructedStringBER", kWrappedConstructedStringDER,
kWrappedConstructedStringBER);
}
struct BERTest {
+7
View File
@@ -151,6 +151,13 @@ TEST(PKCS12Test, TestEmptyPassword) {
TestImpl("EmptyPassword (empty password)", StringToBytes(data), "", nullptr);
TestImpl("EmptyPassword (null password)", StringToBytes(data), nullptr,
nullptr);
// The above input, modified to have a constructed string.
data = GetTestData("crypto/pkcs8/test/empty_password_ber.p12");
TestImpl("EmptyPassword (BER, empty password)", StringToBytes(data), "",
nullptr);
TestImpl("EmptyPassword (BER, null password)", StringToBytes(data), nullptr,
nullptr);
}
TEST(PKCS12Test, TestNullPassword) {
Binary file not shown.
+1
View File
@@ -147,6 +147,7 @@ set(
crypto/keccak/keccak_tests.txt
crypto/kyber/kyber_tests.txt
crypto/pkcs8/test/empty_password.p12
crypto/pkcs8/test/empty_password_ber.p12
crypto/pkcs8/test/no_encryption.p12
crypto/pkcs8/test/nss.p12
crypto/pkcs8/test/null_password.p12