1 /*
2  * Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.
3  * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
4  *
5  * Licensed under the Apache License 2.0 (the "License").  You may not use
6  * this file except in compliance with the License.  You can obtain a copy
7  * in the file LICENSE in the source distribution or at
8  * https://www.openssl.org/source/license.html
9  */
10 
11 /* We need to use some engine deprecated APIs */
12 #define OPENSSL_SUPPRESS_DEPRECATED
13 
14 #include "eng_local.h"
15 
16 /*
17  * The linked-list of pointers to engine types. engine_list_head incorporates
18  * an implicit structural reference but engine_list_tail does not - the
19  * latter is a computational optimization and only points to something that
20  * is already pointed to by its predecessor in the list (or engine_list_head
21  * itself). In the same way, the use of the "prev" pointer in each ENGINE is
22  * to save excessive list iteration, it doesn't correspond to an extra
23  * structural reference. Hence, engine_list_head, and each non-null "next"
24  * pointer account for the list itself assuming exactly 1 structural
25  * reference on each list member.
26  */
27 static ENGINE *engine_list_head = NULL;
28 static ENGINE *engine_list_tail = NULL;
29 
30 /*
31  * The linked list of currently loaded dynamic engines.
32  */
33 static ENGINE *engine_dyn_list_head = NULL;
34 static ENGINE *engine_dyn_list_tail = NULL;
35 
36 /*
37  * This cleanup function is only needed internally. If it should be called,
38  * we register it with the "engine_cleanup_int()" stack to be called during
39  * cleanup.
40  */
41 
engine_list_cleanup(void)42 static void engine_list_cleanup(void)
43 {
44     ENGINE *iterator = engine_list_head;
45 
46     while (iterator != NULL) {
47         ENGINE_remove(iterator);
48         iterator = engine_list_head;
49     }
50     return;
51 }
52 
53 /*
54  * These static functions starting with a lower case "engine_" always take
55  * place when global_engine_lock has been locked up.
56  */
engine_list_add(ENGINE * e)57 static int engine_list_add(ENGINE *e)
58 {
59     int conflict = 0;
60     ENGINE *iterator = NULL;
61 
62     if (e == NULL) {
63         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
64         return 0;
65     }
66     iterator = engine_list_head;
67     while (iterator && !conflict) {
68         conflict = (strcmp(iterator->id, e->id) == 0);
69         iterator = iterator->next;
70     }
71     if (conflict) {
72         ERR_raise(ERR_LIB_ENGINE, ENGINE_R_CONFLICTING_ENGINE_ID);
73         return 0;
74     }
75     if (engine_list_head == NULL) {
76         /* We are adding to an empty list. */
77         if (engine_list_tail) {
78             ERR_raise(ERR_LIB_ENGINE, ENGINE_R_INTERNAL_LIST_ERROR);
79             return 0;
80         }
81         /*
82          * The first time the list allocates, we should register the cleanup.
83          */
84         if (!engine_cleanup_add_last(engine_list_cleanup)) {
85             ERR_raise(ERR_LIB_ENGINE, ENGINE_R_INTERNAL_LIST_ERROR);
86             return 0;
87         }
88         engine_list_head = e;
89         e->prev = NULL;
90     } else {
91         /* We are adding to the tail of an existing list. */
92         if ((engine_list_tail == NULL) || (engine_list_tail->next != NULL)) {
93             ERR_raise(ERR_LIB_ENGINE, ENGINE_R_INTERNAL_LIST_ERROR);
94             return 0;
95         }
96         engine_list_tail->next = e;
97         e->prev = engine_list_tail;
98     }
99     /*
100      * Having the engine in the list assumes a structural reference.
101      */
102     e->struct_ref++;
103     ENGINE_REF_PRINT(e, 0, 1);
104     /* However it came to be, e is the last item in the list. */
105     engine_list_tail = e;
106     e->next = NULL;
107     return 1;
108 }
109 
engine_list_remove(ENGINE * e)110 static int engine_list_remove(ENGINE *e)
111 {
112     ENGINE *iterator;
113 
114     if (e == NULL) {
115         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
116         return 0;
117     }
118     /* We need to check that e is in our linked list! */
119     iterator = engine_list_head;
120     while (iterator && (iterator != e))
121         iterator = iterator->next;
122     if (iterator == NULL) {
123         ERR_raise(ERR_LIB_ENGINE, ENGINE_R_ENGINE_IS_NOT_IN_LIST);
124         return 0;
125     }
126     /* un-link e from the chain. */
127     if (e->next)
128         e->next->prev = e->prev;
129     if (e->prev)
130         e->prev->next = e->next;
131     /* Correct our head/tail if necessary. */
132     if (engine_list_head == e)
133         engine_list_head = e->next;
134     if (engine_list_tail == e)
135         engine_list_tail = e->prev;
136     engine_free_util(e, 0);
137     return 1;
138 }
139 
140 /* Add engine to dynamic engine list. */
engine_add_dynamic_id(ENGINE * e,ENGINE_DYNAMIC_ID dynamic_id,int not_locked)141 int engine_add_dynamic_id(ENGINE *e, ENGINE_DYNAMIC_ID dynamic_id,
142                           int not_locked)
143 {
144     int result = 0;
145     ENGINE *iterator = NULL;
146 
147     if (e == NULL)
148         return 0;
149 
150     if (e->dynamic_id == NULL && dynamic_id == NULL)
151         return 0;
152 
153     if (not_locked && !CRYPTO_THREAD_write_lock(global_engine_lock))
154         return 0;
155 
156     if (dynamic_id != NULL) {
157         iterator = engine_dyn_list_head;
158         while (iterator != NULL) {
159             if (iterator->dynamic_id == dynamic_id)
160                 goto err;
161             iterator = iterator->next;
162         }
163         if (e->dynamic_id != NULL)
164             goto err;
165         e->dynamic_id = dynamic_id;
166     }
167 
168     if (engine_dyn_list_head == NULL) {
169         /* We are adding to an empty list. */
170         if (engine_dyn_list_tail != NULL)
171             goto err;
172         engine_dyn_list_head = e;
173         e->prev_dyn = NULL;
174     } else {
175         /* We are adding to the tail of an existing list. */
176         if (engine_dyn_list_tail == NULL
177             || engine_dyn_list_tail->next_dyn != NULL)
178             goto err;
179         engine_dyn_list_tail->next_dyn = e;
180         e->prev_dyn = engine_dyn_list_tail;
181     }
182 
183     engine_dyn_list_tail = e;
184     e->next_dyn = NULL;
185     result = 1;
186 
187  err:
188     if (not_locked)
189         CRYPTO_THREAD_unlock(global_engine_lock);
190     return result;
191 }
192 
193 /* Remove engine from dynamic engine list. */
engine_remove_dynamic_id(ENGINE * e,int not_locked)194 void engine_remove_dynamic_id(ENGINE *e, int not_locked)
195 {
196     if (e == NULL || e->dynamic_id == NULL)
197         return;
198 
199     if (not_locked && !CRYPTO_THREAD_write_lock(global_engine_lock))
200         return;
201 
202     e->dynamic_id = NULL;
203 
204     /* un-link e from the chain. */
205     if (e->next_dyn != NULL)
206         e->next_dyn->prev_dyn = e->prev_dyn;
207     if (e->prev_dyn != NULL)
208         e->prev_dyn->next_dyn = e->next_dyn;
209     /* Correct our head/tail if necessary. */
210     if (engine_dyn_list_head == e)
211         engine_dyn_list_head = e->next_dyn;
212     if (engine_dyn_list_tail == e)
213         engine_dyn_list_tail = e->prev_dyn;
214 
215     if (not_locked)
216         CRYPTO_THREAD_unlock(global_engine_lock);
217 }
218 
219 /* Get the first/last "ENGINE" type available. */
ENGINE_get_first(void)220 ENGINE *ENGINE_get_first(void)
221 {
222     ENGINE *ret;
223 
224     if (!RUN_ONCE(&engine_lock_init, do_engine_lock_init)) {
225         ERR_raise(ERR_LIB_ENGINE, ERR_R_MALLOC_FAILURE);
226         return NULL;
227     }
228 
229     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
230         return NULL;
231     ret = engine_list_head;
232     if (ret) {
233         ret->struct_ref++;
234         ENGINE_REF_PRINT(ret, 0, 1);
235     }
236     CRYPTO_THREAD_unlock(global_engine_lock);
237     return ret;
238 }
239 
ENGINE_get_last(void)240 ENGINE *ENGINE_get_last(void)
241 {
242     ENGINE *ret;
243 
244     if (!RUN_ONCE(&engine_lock_init, do_engine_lock_init)) {
245         ERR_raise(ERR_LIB_ENGINE, ERR_R_MALLOC_FAILURE);
246         return NULL;
247     }
248 
249     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
250         return NULL;
251     ret = engine_list_tail;
252     if (ret) {
253         ret->struct_ref++;
254         ENGINE_REF_PRINT(ret, 0, 1);
255     }
256     CRYPTO_THREAD_unlock(global_engine_lock);
257     return ret;
258 }
259 
260 /* Iterate to the next/previous "ENGINE" type (NULL = end of the list). */
ENGINE_get_next(ENGINE * e)261 ENGINE *ENGINE_get_next(ENGINE *e)
262 {
263     ENGINE *ret = NULL;
264     if (e == NULL) {
265         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
266         return NULL;
267     }
268     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
269         return NULL;
270     ret = e->next;
271     if (ret) {
272         /* Return a valid structural reference to the next ENGINE */
273         ret->struct_ref++;
274         ENGINE_REF_PRINT(ret, 0, 1);
275     }
276     CRYPTO_THREAD_unlock(global_engine_lock);
277     /* Release the structural reference to the previous ENGINE */
278     ENGINE_free(e);
279     return ret;
280 }
281 
ENGINE_get_prev(ENGINE * e)282 ENGINE *ENGINE_get_prev(ENGINE *e)
283 {
284     ENGINE *ret = NULL;
285     if (e == NULL) {
286         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
287         return NULL;
288     }
289     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
290         return NULL;
291     ret = e->prev;
292     if (ret) {
293         /* Return a valid structural reference to the next ENGINE */
294         ret->struct_ref++;
295         ENGINE_REF_PRINT(ret, 0, 1);
296     }
297     CRYPTO_THREAD_unlock(global_engine_lock);
298     /* Release the structural reference to the previous ENGINE */
299     ENGINE_free(e);
300     return ret;
301 }
302 
303 /* Add another "ENGINE" type into the list. */
ENGINE_add(ENGINE * e)304 int ENGINE_add(ENGINE *e)
305 {
306     int to_return = 1;
307     if (e == NULL) {
308         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
309         return 0;
310     }
311     if ((e->id == NULL) || (e->name == NULL)) {
312         ERR_raise(ERR_LIB_ENGINE, ENGINE_R_ID_OR_NAME_MISSING);
313         return 0;
314     }
315     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
316         return 0;
317     if (!engine_list_add(e)) {
318         ERR_raise(ERR_LIB_ENGINE, ENGINE_R_INTERNAL_LIST_ERROR);
319         to_return = 0;
320     }
321     CRYPTO_THREAD_unlock(global_engine_lock);
322     return to_return;
323 }
324 
325 /* Remove an existing "ENGINE" type from the array. */
ENGINE_remove(ENGINE * e)326 int ENGINE_remove(ENGINE *e)
327 {
328     int to_return = 1;
329     if (e == NULL) {
330         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
331         return 0;
332     }
333     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
334         return 0;
335     if (!engine_list_remove(e)) {
336         ERR_raise(ERR_LIB_ENGINE, ENGINE_R_INTERNAL_LIST_ERROR);
337         to_return = 0;
338     }
339     CRYPTO_THREAD_unlock(global_engine_lock);
340     return to_return;
341 }
342 
engine_cpy(ENGINE * dest,const ENGINE * src)343 static void engine_cpy(ENGINE *dest, const ENGINE *src)
344 {
345     dest->id = src->id;
346     dest->name = src->name;
347     dest->rsa_meth = src->rsa_meth;
348 #ifndef OPENSSL_NO_DSA
349     dest->dsa_meth = src->dsa_meth;
350 #endif
351 #ifndef OPENSSL_NO_DH
352     dest->dh_meth = src->dh_meth;
353 #endif
354 #ifndef OPENSSL_NO_EC
355     dest->ec_meth = src->ec_meth;
356 #endif
357     dest->rand_meth = src->rand_meth;
358     dest->ciphers = src->ciphers;
359     dest->digests = src->digests;
360     dest->pkey_meths = src->pkey_meths;
361     dest->destroy = src->destroy;
362     dest->init = src->init;
363     dest->finish = src->finish;
364     dest->ctrl = src->ctrl;
365     dest->load_privkey = src->load_privkey;
366     dest->load_pubkey = src->load_pubkey;
367     dest->cmd_defns = src->cmd_defns;
368     dest->flags = src->flags;
369     dest->dynamic_id = src->dynamic_id;
370     engine_add_dynamic_id(dest, NULL, 0);
371 }
372 
ENGINE_by_id(const char * id)373 ENGINE *ENGINE_by_id(const char *id)
374 {
375     ENGINE *iterator;
376     char *load_dir = NULL;
377     if (id == NULL) {
378         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
379         return NULL;
380     }
381     ENGINE_load_builtin_engines();
382 
383     if (!RUN_ONCE(&engine_lock_init, do_engine_lock_init)) {
384         ERR_raise(ERR_LIB_ENGINE, ERR_R_MALLOC_FAILURE);
385         return NULL;
386     }
387 
388     if (!CRYPTO_THREAD_write_lock(global_engine_lock))
389         return NULL;
390     iterator = engine_list_head;
391     while (iterator && (strcmp(id, iterator->id) != 0))
392         iterator = iterator->next;
393     if (iterator != NULL) {
394         /*
395          * We need to return a structural reference. If this is an ENGINE
396          * type that returns copies, make a duplicate - otherwise increment
397          * the existing ENGINE's reference count.
398          */
399         if (iterator->flags & ENGINE_FLAGS_BY_ID_COPY) {
400             ENGINE *cp = ENGINE_new();
401             if (cp == NULL)
402                 iterator = NULL;
403             else {
404                 engine_cpy(cp, iterator);
405                 iterator = cp;
406             }
407         } else {
408             iterator->struct_ref++;
409             ENGINE_REF_PRINT(iterator, 0, 1);
410         }
411     }
412     CRYPTO_THREAD_unlock(global_engine_lock);
413     if (iterator != NULL)
414         return iterator;
415     /*
416      * Prevent infinite recursion if we're looking for the dynamic engine.
417      */
418     if (strcmp(id, "dynamic")) {
419         if ((load_dir = ossl_safe_getenv("OPENSSL_ENGINES")) == NULL)
420             load_dir = ENGINESDIR;
421         iterator = ENGINE_by_id("dynamic");
422         if (!iterator || !ENGINE_ctrl_cmd_string(iterator, "ID", id, 0) ||
423             !ENGINE_ctrl_cmd_string(iterator, "DIR_LOAD", "2", 0) ||
424             !ENGINE_ctrl_cmd_string(iterator, "DIR_ADD",
425                                     load_dir, 0) ||
426             !ENGINE_ctrl_cmd_string(iterator, "LIST_ADD", "1", 0) ||
427             !ENGINE_ctrl_cmd_string(iterator, "LOAD", NULL, 0))
428             goto notfound;
429         return iterator;
430     }
431  notfound:
432     ENGINE_free(iterator);
433     ERR_raise_data(ERR_LIB_ENGINE, ENGINE_R_NO_SUCH_ENGINE, "id=%s", id);
434     return NULL;
435     /* EEK! Experimental code ends */
436 }
437 
ENGINE_up_ref(ENGINE * e)438 int ENGINE_up_ref(ENGINE *e)
439 {
440     int i;
441     if (e == NULL) {
442         ERR_raise(ERR_LIB_ENGINE, ERR_R_PASSED_NULL_PARAMETER);
443         return 0;
444     }
445     CRYPTO_UP_REF(&e->struct_ref, &i, global_engine_lock);
446     return 1;
447 }
448