A pure Python ASN.1 library. Supports dict and sets.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

482 lines
11 KiB

  1. #!/usr/bin/env python
  2. # A Pure Python ASN.1 encoder/decoder w/ a calling interface in the spirit
  3. # of pickle. It will automaticly do the correct thing if possible.
  4. #
  5. # This uses a profile of ASN.1.
  6. #
  7. # All lengths must be specified. That is that End-of-contents octets
  8. # MUST not be used. The shorted form of length encoding MUST be used.
  9. # A longer length encoding MUST be rejected.
  10. import math
  11. import os
  12. import pdb
  13. import sys
  14. import unittest
  15. __all__ = [ 'dumps', 'loads', 'ASN1Coder' ]
  16. def _numtostr(n):
  17. hs = '%x' % n
  18. if len(hs) & 1 == 1:
  19. hs = '0' + hs
  20. bs = hs.decode('hex')
  21. return bs
  22. def _encodelen(l):
  23. '''Takes l as a length value, and returns a byte string that
  24. represents l per ASN.1 rules.'''
  25. if l < 128:
  26. return chr(l)
  27. bs = _numtostr(l)
  28. return chr(len(bs) | 0x80) + bs
  29. def _decodelen(d, pos=0):
  30. '''Returns the length, and number of bytes required.'''
  31. odp = ord(d[pos])
  32. if odp < 128:
  33. return ord(d[pos]), 1
  34. else:
  35. l = odp & 0x7f
  36. return int(d[pos + 1:pos + 1 + l].encode('hex'), 16), l + 1
  37. class Test_codelen(unittest.TestCase):
  38. _testdata = [
  39. (2, '\x02'),
  40. (127, '\x7f'),
  41. (128, '\x81\x80'),
  42. (255, '\x81\xff'),
  43. (256, '\x82\x01\x00'),
  44. (65536-1, '\x82\xff\xff'),
  45. (65536, '\x83\x01\x00\x00'),
  46. ]
  47. def test_el(self):
  48. for i, j in self._testdata:
  49. self.assertEqual(_encodelen(i), j)
  50. self.assertEqual(_decodelen(j), (i, len(j)))
  51. def _splitfloat(f):
  52. m, e = math.frexp(f)
  53. # XXX - less than ideal
  54. while m != math.trunc(m):
  55. m *= 2
  56. e -= 1
  57. return m, e
  58. class TestSplitFloat(unittest.TestCase):
  59. def test_sf(self):
  60. for a, b in [ (0x2421, -32), (0x5382f, 238),
  61. (0x1fa8c3b094adf1, 971) ]:
  62. self.assertEqual(_splitfloat(a * 2**b), (a, b))
  63. class ASN1Object:
  64. def __init__(self, tag):
  65. self._tag = tag
  66. class ASN1Coder(object):
  67. def __init__(self):
  68. pass
  69. _typemap = {
  70. bool: 'bool',
  71. dict: 'dict',
  72. float: 'float',
  73. int: 'int',
  74. list: 'list',
  75. long: 'int',
  76. set: 'set',
  77. str: 'bytes',
  78. type(None): 'null',
  79. unicode: 'unicode',
  80. }
  81. _tagmap = {
  82. '\x01': 'bool',
  83. '\x02': 'int',
  84. '\x04': 'bytes',
  85. '\x05': 'null',
  86. '\x09': 'float',
  87. '\x0c': 'unicode',
  88. '\x30': 'list',
  89. '\x31': 'set',
  90. '\xc0': 'dict',
  91. #'xxx': 'datetime',
  92. }
  93. _typetag = dict((v, k) for k, v in _tagmap.iteritems())
  94. @staticmethod
  95. def enc_int(obj):
  96. l = obj.bit_length()
  97. l += 1 # space for sign bit
  98. l = (l + 7) // 8
  99. if obj < 0:
  100. obj += 1 << (l * 8) # twos-complement conversion
  101. v = _numtostr(obj)
  102. if len(v) != l:
  103. # XXX - is this a problem for signed values?
  104. v = '\x00' + v # add sign octect
  105. return _encodelen(l) + v
  106. @staticmethod
  107. def dec_int(d, pos, end):
  108. if pos == end:
  109. return 0, end
  110. v = int(d[pos:end].encode('hex'), 16)
  111. av = 1 << ((end - pos) * 8 - 1) # sign bit
  112. if v > av:
  113. v -= av * 2 # twos-complement conversion
  114. return v, end
  115. @staticmethod
  116. def enc_bool(obj):
  117. return '\x01' + ('\xff' if obj else '\x00')
  118. def dec_bool(self, d, pos, end):
  119. v = self.dec_int(d, pos, end)[0]
  120. if v not in (-1, 0):
  121. raise ValueError('invalid bool value: %d' % v)
  122. return bool(v), end
  123. @staticmethod
  124. def enc_null(obj):
  125. return '\x00'
  126. @staticmethod
  127. def dec_null(d, pos, end):
  128. return None, end
  129. def enc_dict(self, obj):
  130. #it = list(obj.iteritems())
  131. #it.sort()
  132. r = ''.join(self.dumps(k) + self.dumps(v) for k, v in obj.iteritems())
  133. return _encodelen(len(r)) + r
  134. def dec_dict(self, d, pos, end):
  135. r = {}
  136. vend = pos
  137. while pos < end:
  138. k, kend = self._loads(d, pos, end)
  139. #if kend > end:
  140. # raise ValueError('key past end')
  141. v, vend = self._loads(d, kend, end)
  142. if vend > end:
  143. raise ValueError('value past end')
  144. r[k] = v
  145. pos = vend
  146. return r, vend
  147. def enc_set(self, obj):
  148. r = ''.join(self.dumps(x) for x in obj)
  149. return _encodelen(len(r)) + r
  150. def dec_set(self, d, pos, end):
  151. r, end = self.dec_list(d, pos, end)
  152. return set(r), end
  153. def enc_list(self, obj):
  154. r = ''.join(self.dumps(x) for x in obj)
  155. return _encodelen(len(r)) + r
  156. def dec_list(self, d, pos, end):
  157. r = []
  158. vend = pos
  159. while pos < end:
  160. v, vend = self._loads(d, pos, end)
  161. if vend > end:
  162. raise ValueError('load past end')
  163. r.append(v)
  164. pos = vend
  165. return r, vend
  166. @staticmethod
  167. def enc_bytes(obj):
  168. return _encodelen(len(obj)) + obj
  169. @staticmethod
  170. def dec_bytes(d, pos, end):
  171. return d[pos:end], end
  172. @staticmethod
  173. def enc_unicode(obj):
  174. encobj = obj.encode('utf-8')
  175. return _encodelen(len(encobj)) + encobj
  176. def dec_unicode(self, d, pos, end):
  177. return d[pos:end].decode('utf-8'), end
  178. @staticmethod
  179. def enc_float(obj):
  180. s = math.copysign(1, obj)
  181. if math.isnan(obj):
  182. return _encodelen(1) + chr(0b01000010)
  183. elif math.isinf(obj):
  184. if s == 1:
  185. return _encodelen(1) + chr(0b01000000)
  186. else:
  187. return _encodelen(1) + chr(0b01000001)
  188. elif obj == 0:
  189. if s == 1:
  190. return _encodelen(0)
  191. else:
  192. return _encodelen(1) + chr(0b01000011)
  193. m, e = _splitfloat(obj)
  194. # Binary encoding
  195. val = 0x80
  196. if m < 0:
  197. val |= 0x40
  198. m = -m
  199. # Base 2
  200. el = (e.bit_length() + 7 + 1) // 8 # + 1 is sign bit
  201. if e < 0:
  202. e += 256**el # convert negative to twos-complement
  203. if el > 3:
  204. v = 0x3
  205. encexp = _encodelen(el) + _numtostr(e)
  206. else:
  207. v = el - 1
  208. encexp = _numtostr(e)
  209. r = chr(val) + encexp + _numtostr(m)
  210. return _encodelen(len(r)) + r
  211. def dec_float(self, d, pos, end):
  212. if pos == end:
  213. return float(0), end
  214. v = ord(d[pos])
  215. if v == 0b01000000:
  216. return float('inf'), end
  217. elif v == 0b01000001:
  218. return float('-inf'), end
  219. elif v == 0b01000010:
  220. return float('nan'), end
  221. elif v == 0b01000011:
  222. return float('-0'), end
  223. elif v & 0b110000:
  224. raise ValueError('base must be 2')
  225. elif v & 0b1100:
  226. raise ValueError('scaling factor must be 0')
  227. elif v & 0b11000000 == 0:
  228. raise ValueError('decimal encoding not supported')
  229. #elif v & 0b11000000 == 0b01000000:
  230. # raise ValueError('invalid encoding')
  231. if v & 3 == 3:
  232. pexp = pos + 2
  233. explen = ord(d[pos + 1])
  234. if explen <= 3:
  235. raise ValueError('must use other length encoding')
  236. eexp = pos + 2 + explen
  237. else:
  238. pexp = pos + 1
  239. eexp = pos + 1 + (v & 3) + 1
  240. exp = self.dec_int(d, pexp, eexp)[0]
  241. n = float(int(d[eexp:end].encode('hex'), 16))
  242. r = n * 2 ** exp
  243. if v & 0b1000000:
  244. r = -r
  245. return r, end
  246. def dumps(self, obj):
  247. tf = self._typemap[type(obj)]
  248. fun = getattr(self, 'enc_%s' % tf)
  249. return self._typetag[tf] + fun(obj)
  250. def _loads(self, data, pos, end):
  251. tag = data[pos]
  252. l, b = _decodelen(data, pos + 1)
  253. if len(data) < pos + 1 + b + l:
  254. raise ValueError('string not long enough')
  255. # XXX - enforce that len(data) == end?
  256. end = pos + 1 + b + l
  257. t = self._tagmap[tag]
  258. fun = getattr(self, 'dec_%s' % t)
  259. return fun(data, pos + 1 + b, end)
  260. def loads(self, data, pos=0, end=None, consume=False):
  261. if end is None:
  262. end = len(data)
  263. r, e = self._loads(data, pos, end)
  264. if consume and e != end:
  265. raise ValueError('entire string not consumed')
  266. return r
  267. def deeptypecmp(obj, o):
  268. #print 'dtc:', `obj`, `o`
  269. if type(obj) != type(o):
  270. return False
  271. if type(obj) in (str, unicode):
  272. return True
  273. if type(obj) in (list, set):
  274. for i, j in zip(obj, o):
  275. if not deeptypecmp(i, j):
  276. return False
  277. if type(obj) in (dict,):
  278. itms = obj.items()
  279. itms.sort()
  280. nitms = o.items()
  281. nitms.sort()
  282. for (k, v), (nk, nv) in zip(itms, nitms):
  283. if not deeptypecmp(k, nk):
  284. return False
  285. if not deeptypecmp(v, nv):
  286. return False
  287. return True
  288. class Test_deeptypecmp(unittest.TestCase):
  289. def test_true(self):
  290. for i in ((1,1), ('sldkfj', 'sldkfj')
  291. ):
  292. self.assertTrue(deeptypecmp(*i))
  293. def test_false(self):
  294. for i in (([[]], [{}]), ([1], ['str']), ([], set()),
  295. ({1: 2, 5: u'sdlkfj'}, {1: 2, 5: 'sdlkfj'}),
  296. ({1: 2, u'sdlkfj': 5}, {1: 2, 'sdlkfj': 5}),
  297. ):
  298. self.assertFalse(deeptypecmp(*i))
  299. def genfailures(obj):
  300. s = dumps(obj)
  301. for i in xrange(len(s)):
  302. for j in (chr(x) for x in xrange(256)):
  303. ts = s[:i] + j + s[i + 1:]
  304. if ts == s:
  305. continue
  306. try:
  307. o = loads(ts, consume=True)
  308. if o != obj or not deeptypecmp(o, obj):
  309. raise ValueError
  310. except (ValueError, KeyError, IndexError):
  311. pass
  312. except Exception:
  313. raise
  314. else:
  315. raise AssertionError('uncaught modification: %s, byte %d, orig: %02x' % (ts.encode('hex'), i, ord(s[i])))
  316. _coder = ASN1Coder()
  317. dumps = _coder.dumps
  318. loads = _coder.loads
  319. class TestCode(unittest.TestCase):
  320. def test_primv(self):
  321. self.assertEqual(dumps(-257), '0202feff'.decode('hex'))
  322. self.assertEqual(dumps(-256), '0202ff00'.decode('hex'))
  323. self.assertEqual(dumps(-255), '0202ff01'.decode('hex'))
  324. self.assertEqual(dumps(-1), '0201ff'.decode('hex'))
  325. self.assertEqual(dumps(5), '020105'.decode('hex'))
  326. self.assertEqual(dumps(128), '02020080'.decode('hex'))
  327. self.assertEqual(dumps(256), '02020100'.decode('hex'))
  328. self.assertEqual(dumps(False), '010100'.decode('hex'))
  329. self.assertEqual(dumps(True), '0101ff'.decode('hex'))
  330. self.assertEqual(dumps(None), '0500'.decode('hex'))
  331. self.assertEqual(dumps(.15625), '090380fb05'.decode('hex'))
  332. def test_fuzzing(self):
  333. genfailures(float(1))
  334. genfailures([ 1, 2, 'sdlkfj' ])
  335. genfailures({ 1: 2, 5: 'sdlkfj' })
  336. genfailures(set([ 1, 2, 'sdlkfj' ]))
  337. def test_consume(self):
  338. b = dumps(5)
  339. self.assertRaises(ValueError, loads, b + '398473', consume=True)
  340. # XXX - still possible that an internal data member
  341. # doesn't consume all
  342. # XXX - test that sets are ordered properly
  343. # XXX - test that dicts are ordered properly..
  344. def test_nan(self):
  345. s = dumps(float('nan'))
  346. v = loads(s)
  347. self.assertTrue(math.isnan(v))
  348. def test_invalids(self):
  349. # Add tests for base 8, 16 floats among others
  350. for v in [ '010101',
  351. '0903040001', # float scaling factor
  352. '0903840001', # float scaling factor
  353. '0903100001', # float base
  354. '0903900001', # float base
  355. '0903000001', # float decimal encoding
  356. '0903830001', # float exponent encoding
  357. '3007020101020102040673646c6b666a', # list short string still valid
  358. 'c007020101020102020105040673646c6b666a', # dict short value still valid
  359. ]:
  360. self.assertRaises(ValueError, loads, v.decode('hex'))
  361. def test_cryptoutilasn1(self):
  362. '''Test DER sequences generated by Crypto.Util.asn1.'''
  363. for s, v in [ ('\x02\x03$\x8a\xf9', 2394873),
  364. ('\x05\x00', None),
  365. ('\x02\x03\x00\x96I', 38473),
  366. ('\x04\x81\xc8' + '\x00' * 200, '\x00' * 200),
  367. ]:
  368. self.assertEqual(loads(s), v)
  369. def test_longstrings(self):
  370. for i in (203, 65484):
  371. s = os.urandom(i)
  372. v = dumps(s)
  373. self.assertEqual(loads(v), s)
  374. def test_dumps(self):
  375. for i in [ None,
  376. True, False,
  377. -1, 0, 1, 255, 256, -255, -256, 23498732498723, -2398729387234, (1<<2383) + 23984734, (-1<<1983) + 23984723984,
  378. float(0), float('-0'), float('inf'), float('-inf'), float(1.0), float(-1.0),
  379. float('353.3487'), float('2387.23873e492'), float('2387.348732e-392'),
  380. float('.15625'),
  381. 'weoifjwef',
  382. u'\U0001f4a9',
  383. [],
  384. {},
  385. set(), set((1,2,3)), set((1,'sjlfdkj', None, float('inf'))),
  386. ]:
  387. s = dumps(i)
  388. o = loads(s)
  389. self.assertEqual(i, o)
  390. tobj = { 1: 'dflkj', 5: u'sdlkfj', 'float': 1, 'largeint': 1<<342, 'list': [ 1, 2, u'str', 'str' ] }
  391. out = dumps(tobj)
  392. self.assertEqual(tobj, loads(out))
  393. def test_loads(self):
  394. self.assertRaises(ValueError, loads, '\x00\x02\x00')