context.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616
  1. /*
  2. * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include "crypto/cryptlib.h"
  10. #include <openssl/conf.h>
  11. #include "internal/thread_once.h"
  12. #include "internal/property.h"
  13. #include "internal/core.h"
  14. #include "internal/bio.h"
  15. #include "internal/provider.h"
  16. #include "crypto/context.h"
  17. struct ossl_lib_ctx_st {
  18. CRYPTO_RWLOCK *lock, *rand_crngt_lock;
  19. OSSL_EX_DATA_GLOBAL global;
  20. void *property_string_data;
  21. void *evp_method_store;
  22. void *provider_store;
  23. void *namemap;
  24. void *property_defns;
  25. void *global_properties;
  26. void *drbg;
  27. void *drbg_nonce;
  28. #ifndef FIPS_MODULE
  29. void *provider_conf;
  30. void *bio_core;
  31. void *child_provider;
  32. OSSL_METHOD_STORE *decoder_store;
  33. OSSL_METHOD_STORE *encoder_store;
  34. OSSL_METHOD_STORE *store_loader_store;
  35. void *self_test_cb;
  36. #endif
  37. void *rand_crngt;
  38. #ifdef FIPS_MODULE
  39. void *thread_event_handler;
  40. void *fips_prov;
  41. #endif
  42. unsigned int ischild:1;
  43. };
  44. int ossl_lib_ctx_write_lock(OSSL_LIB_CTX *ctx)
  45. {
  46. return CRYPTO_THREAD_write_lock(ossl_lib_ctx_get_concrete(ctx)->lock);
  47. }
  48. int ossl_lib_ctx_read_lock(OSSL_LIB_CTX *ctx)
  49. {
  50. return CRYPTO_THREAD_read_lock(ossl_lib_ctx_get_concrete(ctx)->lock);
  51. }
  52. int ossl_lib_ctx_unlock(OSSL_LIB_CTX *ctx)
  53. {
  54. return CRYPTO_THREAD_unlock(ossl_lib_ctx_get_concrete(ctx)->lock);
  55. }
  56. int ossl_lib_ctx_is_child(OSSL_LIB_CTX *ctx)
  57. {
  58. ctx = ossl_lib_ctx_get_concrete(ctx);
  59. if (ctx == NULL)
  60. return 0;
  61. return ctx->ischild;
  62. }
  63. static void context_deinit_objs(OSSL_LIB_CTX *ctx);
  64. static int context_init(OSSL_LIB_CTX *ctx)
  65. {
  66. int exdata_done = 0;
  67. ctx->lock = CRYPTO_THREAD_lock_new();
  68. if (ctx->lock == NULL)
  69. return 0;
  70. ctx->rand_crngt_lock = CRYPTO_THREAD_lock_new();
  71. if (ctx->rand_crngt_lock == NULL)
  72. goto err;
  73. /* Initialize ex_data. */
  74. if (!ossl_do_ex_data_init(ctx))
  75. goto err;
  76. exdata_done = 1;
  77. /* P2. We want evp_method_store to be cleaned up before the provider store */
  78. ctx->evp_method_store = ossl_method_store_new(ctx);
  79. if (ctx->evp_method_store == NULL)
  80. goto err;
  81. #ifndef FIPS_MODULE
  82. /* P2. Must be freed before the provider store is freed */
  83. ctx->provider_conf = ossl_prov_conf_ctx_new(ctx);
  84. if (ctx->provider_conf == NULL)
  85. goto err;
  86. #endif
  87. /* P2. */
  88. ctx->drbg = ossl_rand_ctx_new(ctx);
  89. if (ctx->drbg == NULL)
  90. goto err;
  91. #ifndef FIPS_MODULE
  92. /* P2. We want decoder_store to be cleaned up before the provider store */
  93. ctx->decoder_store = ossl_method_store_new(ctx);
  94. if (ctx->decoder_store == NULL)
  95. goto err;
  96. /* P2. We want encoder_store to be cleaned up before the provider store */
  97. ctx->encoder_store = ossl_method_store_new(ctx);
  98. if (ctx->encoder_store == NULL)
  99. goto err;
  100. /* P2. We want loader_store to be cleaned up before the provider store */
  101. ctx->store_loader_store = ossl_method_store_new(ctx);
  102. if (ctx->store_loader_store == NULL)
  103. goto err;
  104. #endif
  105. /* P1. Needs to be freed before the child provider data is freed */
  106. ctx->provider_store = ossl_provider_store_new(ctx);
  107. if (ctx->provider_store == NULL)
  108. goto err;
  109. /* Default priority. */
  110. ctx->property_string_data = ossl_property_string_data_new(ctx);
  111. if (ctx->property_string_data == NULL)
  112. goto err;
  113. ctx->namemap = ossl_stored_namemap_new(ctx);
  114. if (ctx->namemap == NULL)
  115. goto err;
  116. ctx->property_defns = ossl_property_defns_new(ctx);
  117. if (ctx->property_defns == NULL)
  118. goto err;
  119. ctx->global_properties = ossl_ctx_global_properties_new(ctx);
  120. if (ctx->global_properties == NULL)
  121. goto err;
  122. #ifndef FIPS_MODULE
  123. ctx->bio_core = ossl_bio_core_globals_new(ctx);
  124. if (ctx->bio_core == NULL)
  125. goto err;
  126. #endif
  127. ctx->drbg_nonce = ossl_prov_drbg_nonce_ctx_new(ctx);
  128. if (ctx->drbg_nonce == NULL)
  129. goto err;
  130. #ifndef FIPS_MODULE
  131. ctx->self_test_cb = ossl_self_test_set_callback_new(ctx);
  132. if (ctx->self_test_cb == NULL)
  133. goto err;
  134. #endif
  135. #ifdef FIPS_MODULE
  136. ctx->thread_event_handler = ossl_thread_event_ctx_new(ctx);
  137. if (ctx->thread_event_handler == NULL)
  138. goto err;
  139. ctx->fips_prov = ossl_fips_prov_ossl_ctx_new(ctx);
  140. if (ctx->fips_prov == NULL)
  141. goto err;
  142. #endif
  143. /* Low priority. */
  144. #ifndef FIPS_MODULE
  145. ctx->child_provider = ossl_child_prov_ctx_new(ctx);
  146. if (ctx->child_provider == NULL)
  147. goto err;
  148. #endif
  149. /* Everything depends on properties, so we also pre-initialise that */
  150. if (!ossl_property_parse_init(ctx))
  151. goto err;
  152. return 1;
  153. err:
  154. context_deinit_objs(ctx);
  155. if (exdata_done)
  156. ossl_crypto_cleanup_all_ex_data_int(ctx);
  157. CRYPTO_THREAD_lock_free(ctx->rand_crngt_lock);
  158. CRYPTO_THREAD_lock_free(ctx->lock);
  159. memset(ctx, '\0', sizeof(*ctx));
  160. return 0;
  161. }
  162. static void context_deinit_objs(OSSL_LIB_CTX *ctx)
  163. {
  164. /* P2. We want evp_method_store to be cleaned up before the provider store */
  165. if (ctx->evp_method_store != NULL) {
  166. ossl_method_store_free(ctx->evp_method_store);
  167. ctx->evp_method_store = NULL;
  168. }
  169. /* P2. */
  170. if (ctx->drbg != NULL) {
  171. ossl_rand_ctx_free(ctx->drbg);
  172. ctx->drbg = NULL;
  173. }
  174. #ifndef FIPS_MODULE
  175. /* P2. */
  176. if (ctx->provider_conf != NULL) {
  177. ossl_prov_conf_ctx_free(ctx->provider_conf);
  178. ctx->provider_conf = NULL;
  179. }
  180. /* P2. We want decoder_store to be cleaned up before the provider store */
  181. if (ctx->decoder_store != NULL) {
  182. ossl_method_store_free(ctx->decoder_store);
  183. ctx->decoder_store = NULL;
  184. }
  185. /* P2. We want encoder_store to be cleaned up before the provider store */
  186. if (ctx->encoder_store != NULL) {
  187. ossl_method_store_free(ctx->encoder_store);
  188. ctx->encoder_store = NULL;
  189. }
  190. /* P2. We want loader_store to be cleaned up before the provider store */
  191. if (ctx->store_loader_store != NULL) {
  192. ossl_method_store_free(ctx->store_loader_store);
  193. ctx->store_loader_store = NULL;
  194. }
  195. #endif
  196. /* P1. Needs to be freed before the child provider data is freed */
  197. if (ctx->provider_store != NULL) {
  198. ossl_provider_store_free(ctx->provider_store);
  199. ctx->provider_store = NULL;
  200. }
  201. /* Default priority. */
  202. if (ctx->property_string_data != NULL) {
  203. ossl_property_string_data_free(ctx->property_string_data);
  204. ctx->property_string_data = NULL;
  205. }
  206. if (ctx->namemap != NULL) {
  207. ossl_stored_namemap_free(ctx->namemap);
  208. ctx->namemap = NULL;
  209. }
  210. if (ctx->property_defns != NULL) {
  211. ossl_property_defns_free(ctx->property_defns);
  212. ctx->property_defns = NULL;
  213. }
  214. if (ctx->global_properties != NULL) {
  215. ossl_ctx_global_properties_free(ctx->global_properties);
  216. ctx->global_properties = NULL;
  217. }
  218. #ifndef FIPS_MODULE
  219. if (ctx->bio_core != NULL) {
  220. ossl_bio_core_globals_free(ctx->bio_core);
  221. ctx->bio_core = NULL;
  222. }
  223. #endif
  224. if (ctx->drbg_nonce != NULL) {
  225. ossl_prov_drbg_nonce_ctx_free(ctx->drbg_nonce);
  226. ctx->drbg_nonce = NULL;
  227. }
  228. #ifndef FIPS_MODULE
  229. if (ctx->self_test_cb != NULL) {
  230. ossl_self_test_set_callback_free(ctx->self_test_cb);
  231. ctx->self_test_cb = NULL;
  232. }
  233. #endif
  234. if (ctx->rand_crngt != NULL) {
  235. ossl_rand_crng_ctx_free(ctx->rand_crngt);
  236. ctx->rand_crngt = NULL;
  237. }
  238. #ifdef FIPS_MODULE
  239. if (ctx->thread_event_handler != NULL) {
  240. ossl_thread_event_ctx_free(ctx->thread_event_handler);
  241. ctx->thread_event_handler = NULL;
  242. }
  243. if (ctx->fips_prov != NULL) {
  244. ossl_fips_prov_ossl_ctx_free(ctx->fips_prov);
  245. ctx->fips_prov = NULL;
  246. }
  247. #endif
  248. /* Low priority. */
  249. #ifndef FIPS_MODULE
  250. if (ctx->child_provider != NULL) {
  251. ossl_child_prov_ctx_free(ctx->child_provider);
  252. ctx->child_provider = NULL;
  253. }
  254. #endif
  255. }
  256. static int context_deinit(OSSL_LIB_CTX *ctx)
  257. {
  258. if (ctx == NULL)
  259. return 1;
  260. ossl_ctx_thread_stop(ctx);
  261. context_deinit_objs(ctx);
  262. ossl_crypto_cleanup_all_ex_data_int(ctx);
  263. CRYPTO_THREAD_lock_free(ctx->rand_crngt_lock);
  264. CRYPTO_THREAD_lock_free(ctx->lock);
  265. ctx->rand_crngt_lock = NULL;
  266. ctx->lock = NULL;
  267. return 1;
  268. }
  269. #ifndef FIPS_MODULE
  270. /* The default default context */
  271. static OSSL_LIB_CTX default_context_int;
  272. static CRYPTO_ONCE default_context_init = CRYPTO_ONCE_STATIC_INIT;
  273. static CRYPTO_THREAD_LOCAL default_context_thread_local;
  274. static int default_context_inited = 0;
  275. DEFINE_RUN_ONCE_STATIC(default_context_do_init)
  276. {
  277. if (!CRYPTO_THREAD_init_local(&default_context_thread_local, NULL))
  278. goto err;
  279. if (!context_init(&default_context_int))
  280. goto deinit_thread;
  281. default_context_inited = 1;
  282. return 1;
  283. deinit_thread:
  284. CRYPTO_THREAD_cleanup_local(&default_context_thread_local);
  285. err:
  286. return 0;
  287. }
  288. void ossl_lib_ctx_default_deinit(void)
  289. {
  290. if (!default_context_inited)
  291. return;
  292. context_deinit(&default_context_int);
  293. CRYPTO_THREAD_cleanup_local(&default_context_thread_local);
  294. default_context_inited = 0;
  295. }
  296. static OSSL_LIB_CTX *get_thread_default_context(void)
  297. {
  298. if (!RUN_ONCE(&default_context_init, default_context_do_init))
  299. return NULL;
  300. return CRYPTO_THREAD_get_local(&default_context_thread_local);
  301. }
  302. static OSSL_LIB_CTX *get_default_context(void)
  303. {
  304. OSSL_LIB_CTX *current_defctx = get_thread_default_context();
  305. if (current_defctx == NULL)
  306. current_defctx = &default_context_int;
  307. return current_defctx;
  308. }
  309. static int set_default_context(OSSL_LIB_CTX *defctx)
  310. {
  311. if (defctx == &default_context_int)
  312. defctx = NULL;
  313. return CRYPTO_THREAD_set_local(&default_context_thread_local, defctx);
  314. }
  315. #endif
  316. OSSL_LIB_CTX *OSSL_LIB_CTX_new(void)
  317. {
  318. OSSL_LIB_CTX *ctx = OPENSSL_zalloc(sizeof(*ctx));
  319. if (ctx != NULL && !context_init(ctx)) {
  320. OPENSSL_free(ctx);
  321. ctx = NULL;
  322. }
  323. return ctx;
  324. }
  325. #ifndef FIPS_MODULE
  326. OSSL_LIB_CTX *OSSL_LIB_CTX_new_from_dispatch(const OSSL_CORE_HANDLE *handle,
  327. const OSSL_DISPATCH *in)
  328. {
  329. OSSL_LIB_CTX *ctx = OSSL_LIB_CTX_new();
  330. if (ctx == NULL)
  331. return NULL;
  332. if (!ossl_bio_init_core(ctx, in)) {
  333. OSSL_LIB_CTX_free(ctx);
  334. return NULL;
  335. }
  336. return ctx;
  337. }
  338. OSSL_LIB_CTX *OSSL_LIB_CTX_new_child(const OSSL_CORE_HANDLE *handle,
  339. const OSSL_DISPATCH *in)
  340. {
  341. OSSL_LIB_CTX *ctx = OSSL_LIB_CTX_new_from_dispatch(handle, in);
  342. if (ctx == NULL)
  343. return NULL;
  344. if (!ossl_provider_init_as_child(ctx, handle, in)) {
  345. OSSL_LIB_CTX_free(ctx);
  346. return NULL;
  347. }
  348. ctx->ischild = 1;
  349. return ctx;
  350. }
  351. int OSSL_LIB_CTX_load_config(OSSL_LIB_CTX *ctx, const char *config_file)
  352. {
  353. return CONF_modules_load_file_ex(ctx, config_file, NULL, 0) > 0;
  354. }
  355. #endif
  356. void OSSL_LIB_CTX_free(OSSL_LIB_CTX *ctx)
  357. {
  358. if (ossl_lib_ctx_is_default(ctx))
  359. return;
  360. #ifndef FIPS_MODULE
  361. if (ctx->ischild)
  362. ossl_provider_deinit_child(ctx);
  363. #endif
  364. context_deinit(ctx);
  365. OPENSSL_free(ctx);
  366. }
  367. #ifndef FIPS_MODULE
  368. OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void)
  369. {
  370. if (!RUN_ONCE(&default_context_init, default_context_do_init))
  371. return NULL;
  372. return &default_context_int;
  373. }
  374. OSSL_LIB_CTX *OSSL_LIB_CTX_set0_default(OSSL_LIB_CTX *libctx)
  375. {
  376. OSSL_LIB_CTX *current_defctx;
  377. if ((current_defctx = get_default_context()) != NULL) {
  378. if (libctx != NULL)
  379. set_default_context(libctx);
  380. return current_defctx;
  381. }
  382. return NULL;
  383. }
  384. void ossl_release_default_drbg_ctx(void)
  385. {
  386. /* early release of the DRBG in global default libctx */
  387. if (default_context_int.drbg != NULL) {
  388. ossl_rand_ctx_free(default_context_int.drbg);
  389. default_context_int.drbg = NULL;
  390. }
  391. }
  392. #endif
  393. OSSL_LIB_CTX *ossl_lib_ctx_get_concrete(OSSL_LIB_CTX *ctx)
  394. {
  395. #ifndef FIPS_MODULE
  396. if (ctx == NULL)
  397. return get_default_context();
  398. #endif
  399. return ctx;
  400. }
  401. int ossl_lib_ctx_is_default(OSSL_LIB_CTX *ctx)
  402. {
  403. #ifndef FIPS_MODULE
  404. if (ctx == NULL || ctx == get_default_context())
  405. return 1;
  406. #endif
  407. return 0;
  408. }
  409. int ossl_lib_ctx_is_global_default(OSSL_LIB_CTX *ctx)
  410. {
  411. #ifndef FIPS_MODULE
  412. if (ossl_lib_ctx_get_concrete(ctx) == &default_context_int)
  413. return 1;
  414. #endif
  415. return 0;
  416. }
  417. void *ossl_lib_ctx_get_data(OSSL_LIB_CTX *ctx, int index)
  418. {
  419. void *p;
  420. ctx = ossl_lib_ctx_get_concrete(ctx);
  421. if (ctx == NULL)
  422. return NULL;
  423. switch (index) {
  424. case OSSL_LIB_CTX_PROPERTY_STRING_INDEX:
  425. return ctx->property_string_data;
  426. case OSSL_LIB_CTX_EVP_METHOD_STORE_INDEX:
  427. return ctx->evp_method_store;
  428. case OSSL_LIB_CTX_PROVIDER_STORE_INDEX:
  429. return ctx->provider_store;
  430. case OSSL_LIB_CTX_NAMEMAP_INDEX:
  431. return ctx->namemap;
  432. case OSSL_LIB_CTX_PROPERTY_DEFN_INDEX:
  433. return ctx->property_defns;
  434. case OSSL_LIB_CTX_GLOBAL_PROPERTIES:
  435. return ctx->global_properties;
  436. case OSSL_LIB_CTX_DRBG_INDEX:
  437. return ctx->drbg;
  438. case OSSL_LIB_CTX_DRBG_NONCE_INDEX:
  439. return ctx->drbg_nonce;
  440. #ifndef FIPS_MODULE
  441. case OSSL_LIB_CTX_PROVIDER_CONF_INDEX:
  442. return ctx->provider_conf;
  443. case OSSL_LIB_CTX_BIO_CORE_INDEX:
  444. return ctx->bio_core;
  445. case OSSL_LIB_CTX_CHILD_PROVIDER_INDEX:
  446. return ctx->child_provider;
  447. case OSSL_LIB_CTX_DECODER_STORE_INDEX:
  448. return ctx->decoder_store;
  449. case OSSL_LIB_CTX_ENCODER_STORE_INDEX:
  450. return ctx->encoder_store;
  451. case OSSL_LIB_CTX_STORE_LOADER_STORE_INDEX:
  452. return ctx->store_loader_store;
  453. case OSSL_LIB_CTX_SELF_TEST_CB_INDEX:
  454. return ctx->self_test_cb;
  455. #endif
  456. case OSSL_LIB_CTX_RAND_CRNGT_INDEX: {
  457. /*
  458. * rand_crngt must be lazily initialized because it calls into
  459. * libctx, so must not be called from context_init, else a deadlock
  460. * will occur.
  461. *
  462. * We use a separate lock because code called by the instantiation
  463. * of rand_crngt is liable to try and take the libctx lock.
  464. */
  465. if (CRYPTO_THREAD_read_lock(ctx->rand_crngt_lock) != 1)
  466. return NULL;
  467. if (ctx->rand_crngt == NULL) {
  468. CRYPTO_THREAD_unlock(ctx->rand_crngt_lock);
  469. if (CRYPTO_THREAD_write_lock(ctx->rand_crngt_lock) != 1)
  470. return NULL;
  471. if (ctx->rand_crngt == NULL)
  472. ctx->rand_crngt = ossl_rand_crng_ctx_new(ctx);
  473. }
  474. p = ctx->rand_crngt;
  475. CRYPTO_THREAD_unlock(ctx->rand_crngt_lock);
  476. return p;
  477. }
  478. #ifdef FIPS_MODULE
  479. case OSSL_LIB_CTX_THREAD_EVENT_HANDLER_INDEX:
  480. return ctx->thread_event_handler;
  481. case OSSL_LIB_CTX_FIPS_PROV_INDEX:
  482. return ctx->fips_prov;
  483. #endif
  484. default:
  485. return NULL;
  486. }
  487. }
  488. OSSL_EX_DATA_GLOBAL *ossl_lib_ctx_get_ex_data_global(OSSL_LIB_CTX *ctx)
  489. {
  490. ctx = ossl_lib_ctx_get_concrete(ctx);
  491. if (ctx == NULL)
  492. return NULL;
  493. return &ctx->global;
  494. }
  495. const char *ossl_lib_ctx_get_descriptor(OSSL_LIB_CTX *libctx)
  496. {
  497. #ifdef FIPS_MODULE
  498. return "FIPS internal library context";
  499. #else
  500. if (ossl_lib_ctx_is_global_default(libctx))
  501. return "Global default library context";
  502. if (ossl_lib_ctx_is_default(libctx))
  503. return "Thread-local default library context";
  504. return "Non-default library context";
  505. #endif
  506. }