provider_conf.c 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252
  1. /*
  2. * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <string.h>
  10. #include <openssl/trace.h>
  11. #include <openssl/err.h>
  12. #include <openssl/conf.h>
  13. #include <openssl/safestack.h>
  14. #include "internal/provider.h"
  15. #include "internal/cryptlib.h"
  16. #include "provider_local.h"
  17. DEFINE_STACK_OF(OSSL_PROVIDER)
  18. /* PROVIDER config module */
  19. typedef struct {
  20. STACK_OF(OSSL_PROVIDER) *activated_providers;
  21. } PROVIDER_CONF_GLOBAL;
  22. static void *prov_conf_ossl_ctx_new(OSSL_LIB_CTX *libctx)
  23. {
  24. PROVIDER_CONF_GLOBAL *pcgbl = OPENSSL_zalloc(sizeof(*pcgbl));
  25. if (pcgbl == NULL)
  26. return NULL;
  27. return pcgbl;
  28. }
  29. static void prov_conf_ossl_ctx_free(void *vpcgbl)
  30. {
  31. PROVIDER_CONF_GLOBAL *pcgbl = vpcgbl;
  32. sk_OSSL_PROVIDER_pop_free(pcgbl->activated_providers,
  33. ossl_provider_free);
  34. OSSL_TRACE(CONF, "Cleaned up providers\n");
  35. OPENSSL_free(pcgbl);
  36. }
  37. static const OSSL_LIB_CTX_METHOD provider_conf_ossl_ctx_method = {
  38. /* Must be freed before the provider store is freed */
  39. OSSL_LIB_CTX_METHOD_PRIORITY_2,
  40. prov_conf_ossl_ctx_new,
  41. prov_conf_ossl_ctx_free,
  42. };
  43. static const char *skip_dot(const char *name)
  44. {
  45. const char *p = strchr(name, '.');
  46. if (p != NULL)
  47. return p + 1;
  48. return name;
  49. }
  50. static int provider_conf_params(OSSL_PROVIDER *prov,
  51. OSSL_PROVIDER_INFO *provinfo,
  52. const char *name, const char *value,
  53. const CONF *cnf)
  54. {
  55. STACK_OF(CONF_VALUE) *sect;
  56. int ok = 1;
  57. sect = NCONF_get_section(cnf, value);
  58. if (sect != NULL) {
  59. int i;
  60. char buffer[512];
  61. size_t buffer_len = 0;
  62. OSSL_TRACE1(CONF, "Provider params: start section %s\n", value);
  63. if (name != NULL) {
  64. OPENSSL_strlcpy(buffer, name, sizeof(buffer));
  65. OPENSSL_strlcat(buffer, ".", sizeof(buffer));
  66. buffer_len = strlen(buffer);
  67. }
  68. for (i = 0; i < sk_CONF_VALUE_num(sect); i++) {
  69. CONF_VALUE *sectconf = sk_CONF_VALUE_value(sect, i);
  70. if (buffer_len + strlen(sectconf->name) >= sizeof(buffer))
  71. return 0;
  72. buffer[buffer_len] = '\0';
  73. OPENSSL_strlcat(buffer, sectconf->name, sizeof(buffer));
  74. if (!provider_conf_params(prov, provinfo, buffer, sectconf->value,
  75. cnf))
  76. return 0;
  77. }
  78. OSSL_TRACE1(CONF, "Provider params: finish section %s\n", value);
  79. } else {
  80. OSSL_TRACE2(CONF, "Provider params: %s = %s\n", name, value);
  81. if (prov != NULL)
  82. ok = ossl_provider_add_parameter(prov, name, value);
  83. else
  84. ok = ossl_provider_info_add_parameter(provinfo, name, value);
  85. }
  86. return ok;
  87. }
  88. static int provider_conf_load(OSSL_LIB_CTX *libctx, const char *name,
  89. const char *value, const CONF *cnf)
  90. {
  91. int i;
  92. STACK_OF(CONF_VALUE) *ecmds;
  93. int soft = 0;
  94. OSSL_PROVIDER *prov = NULL;
  95. const char *path = NULL;
  96. long activate = 0;
  97. int ok = 0;
  98. PROVIDER_CONF_GLOBAL *pcgbl
  99. = ossl_lib_ctx_get_data(libctx, OSSL_LIB_CTX_PROVIDER_CONF_INDEX,
  100. &provider_conf_ossl_ctx_method);
  101. name = skip_dot(name);
  102. OSSL_TRACE1(CONF, "Configuring provider %s\n", name);
  103. /* Value is a section containing PROVIDER commands */
  104. ecmds = NCONF_get_section(cnf, value);
  105. if (!ecmds) {
  106. ERR_raise_data(ERR_LIB_CRYPTO, CRYPTO_R_PROVIDER_SECTION_ERROR,
  107. "section=%s not found", value);
  108. return 0;
  109. }
  110. /* Find the needed data first */
  111. for (i = 0; i < sk_CONF_VALUE_num(ecmds); i++) {
  112. CONF_VALUE *ecmd = sk_CONF_VALUE_value(ecmds, i);
  113. const char *confname = skip_dot(ecmd->name);
  114. const char *confvalue = ecmd->value;
  115. OSSL_TRACE2(CONF, "Provider command: %s = %s\n",
  116. confname, confvalue);
  117. /* First handle some special pseudo confs */
  118. /* Override provider name to use */
  119. if (strcmp(confname, "identity") == 0)
  120. name = confvalue;
  121. else if (strcmp(confname, "soft_load") == 0)
  122. soft = 1;
  123. /* Load a dynamic PROVIDER */
  124. else if (strcmp(confname, "module") == 0)
  125. path = confvalue;
  126. else if (strcmp(confname, "activate") == 0)
  127. activate = 1;
  128. }
  129. if (activate) {
  130. prov = ossl_provider_find(libctx, name, 1);
  131. if (prov == NULL)
  132. prov = ossl_provider_new(libctx, name, NULL, 1);
  133. if (prov == NULL) {
  134. if (soft)
  135. ERR_clear_error();
  136. return 0;
  137. }
  138. if (path != NULL)
  139. ossl_provider_set_module_path(prov, path);
  140. ok = provider_conf_params(prov, NULL, NULL, value, cnf);
  141. if (ok) {
  142. if (!ossl_provider_activate(prov, 1, 0)) {
  143. ok = 0;
  144. } else if (!ossl_provider_add_to_store(prov, 0)) {
  145. ossl_provider_deactivate(prov);
  146. ok = 0;
  147. } else {
  148. if (pcgbl->activated_providers == NULL)
  149. pcgbl->activated_providers = sk_OSSL_PROVIDER_new_null();
  150. sk_OSSL_PROVIDER_push(pcgbl->activated_providers, prov);
  151. ok = 1;
  152. }
  153. }
  154. if (!ok)
  155. ossl_provider_free(prov);
  156. } else {
  157. OSSL_PROVIDER_INFO entry;
  158. memset(&entry, 0, sizeof(entry));
  159. ok = 1;
  160. if (name != NULL) {
  161. entry.name = OPENSSL_strdup(name);
  162. if (entry.name == NULL) {
  163. ERR_raise(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE);
  164. ok = 0;
  165. }
  166. }
  167. if (ok && path != NULL) {
  168. entry.path = OPENSSL_strdup(path);
  169. if (entry.path == NULL) {
  170. ERR_raise(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE);
  171. ok = 0;
  172. }
  173. }
  174. if (ok)
  175. ok = provider_conf_params(NULL, &entry, NULL, value, cnf);
  176. if (ok && (entry.path != NULL || entry.parameters != NULL))
  177. ok = ossl_provider_info_add_to_store(libctx, &entry);
  178. if (!ok || (entry.path == NULL && entry.parameters == NULL)) {
  179. ossl_provider_info_clear(&entry);
  180. }
  181. }
  182. return ok;
  183. }
  184. static int provider_conf_init(CONF_IMODULE *md, const CONF *cnf)
  185. {
  186. STACK_OF(CONF_VALUE) *elist;
  187. CONF_VALUE *cval;
  188. int i;
  189. OSSL_TRACE1(CONF, "Loading providers module: section %s\n",
  190. CONF_imodule_get_value(md));
  191. /* Value is a section containing PROVIDERs to configure */
  192. elist = NCONF_get_section(cnf, CONF_imodule_get_value(md));
  193. if (!elist) {
  194. ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_PROVIDER_SECTION_ERROR);
  195. return 0;
  196. }
  197. for (i = 0; i < sk_CONF_VALUE_num(elist); i++) {
  198. cval = sk_CONF_VALUE_value(elist, i);
  199. if (!provider_conf_load(NCONF_get0_libctx((CONF *)cnf),
  200. cval->name, cval->value, cnf))
  201. return 0;
  202. }
  203. return 1;
  204. }
  205. void ossl_provider_add_conf_module(void)
  206. {
  207. OSSL_TRACE(CONF, "Adding config module 'providers'\n");
  208. CONF_module_add("providers", provider_conf_init, NULL);
  209. }