core-lightning/tests/fuzz/fuzz-hsm_encryption.c
Rusty Russell 06a54606a3 check-includes: allow redundant "config.h"
We should actually be including this (as it may define _GNU_SOURCE
etc) before any system headers.  But where we include <assert.h> we
often didn't, because check-includes would complain that the headers
included it too.

Weaken that check, and include config.h in C files before assert.h.

Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
2021-02-04 12:02:36 +10:30

45 lines
1.4 KiB
C

#include "config.h"
#include <assert.h>
#include <tests/fuzz/libfuzz.h>
#include <bitcoin/privkey.h>
#include <ccan/mem/mem.h>
#include <ccan/short_types/short_types.h>
#include <ccan/tal/tal.h>
#include <common/hsm_encryption.h>
#include <common/utils.h>
void init(int *argc, char ***argv)
{
}
void run(const uint8_t *data, size_t size)
{
/* 4294967295 is crypto_pwhash_argon2id_PASSWD_MAX. libfuzzer won't
* generate inputs that large in practice, but hey. */
if (size > 32 && size < 4294967295) {
struct secret *hsm_secret, decrypted_hsm_secret, encryption_key;
char *passphrase;
struct encrypted_hsm_secret encrypted_secret;
/* Take the first 32 bytes as the plaintext hsm_secret seed,
* and the remaining ones as the passphrase. */
hsm_secret = (struct secret *)tal_dup_arr(NULL, u8, data, 32, 0);
passphrase = to_string(NULL, data + 32, size - 32);
/* A valid seed, a valid passphrase. This should not fail. */
assert(!hsm_secret_encryption_key(passphrase, &encryption_key));
/* Roundtrip */
assert(encrypt_hsm_secret(&encryption_key, hsm_secret,
&encrypted_secret));
assert(decrypt_hsm_secret(&encryption_key, &encrypted_secret,
&decrypted_hsm_secret));
assert(memeq(hsm_secret->data, sizeof(hsm_secret->data),
decrypted_hsm_secret.data,
sizeof(decrypted_hsm_secret.data)));
tal_free(hsm_secret);
tal_free(passphrase);
}
}