|
Packit |
aea12f |
/*
|
|
Packit |
aea12f |
* Copyright (C) 2008-2012 Free Software Foundation, Inc.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* Author: Nikos Mavrogiannopoulos
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* This file is part of GnuTLS.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* The GnuTLS is free software; you can redistribute it and/or
|
|
Packit |
aea12f |
* modify it under the terms of the GNU Lesser General Public License
|
|
Packit |
aea12f |
* as published by the Free Software Foundation; either version 2.1 of
|
|
Packit |
aea12f |
* the License, or (at your option) any later version.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* This library is distributed in the hope that it will be useful, but
|
|
Packit |
aea12f |
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
Packit |
aea12f |
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Packit |
aea12f |
* Lesser General Public License for more details.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* You should have received a copy of the GNU Lesser General Public License
|
|
Packit |
aea12f |
* along with this program. If not, see <https://www.gnu.org/licenses/>
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
*/
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
/* This file handles all the internal functions that cope with random data.
|
|
Packit |
aea12f |
*/
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
#include "gnutls_int.h"
|
|
Packit |
aea12f |
#include "errors.h"
|
|
Packit |
aea12f |
#include <random.h>
|
|
Packit |
aea12f |
#include "locks.h"
|
|
Packit |
aea12f |
#include <fips.h>
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
#include "gthreads.h"
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
#if defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
|
|
Packit |
aea12f |
extern gnutls_crypto_rnd_st _gnutls_fuzz_rnd_ops;
|
|
Packit |
aea12f |
#endif
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
/* Per thread context of random generator, and a flag to indicate initialization */
|
|
Packit |
aea12f |
static _Thread_local void *gnutls_rnd_ctx;
|
|
Packit |
aea12f |
static _Thread_local unsigned rnd_initialized = 0;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
struct rnd_ctx_list_st {
|
|
Packit |
aea12f |
void *ctx;
|
|
Packit |
aea12f |
struct rnd_ctx_list_st *next;
|
|
Packit |
aea12f |
};
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
/* A global list of all allocated contexts - to be
|
|
Packit |
aea12f |
* used during deinitialization. */
|
|
Packit |
aea12f |
GNUTLS_STATIC_MUTEX(gnutls_rnd_ctx_list_mutex);
|
|
Packit |
aea12f |
static struct rnd_ctx_list_st *head = NULL;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
static int append(void *ctx)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
struct rnd_ctx_list_st *e = gnutls_malloc(sizeof(*e));
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
if (e == NULL)
|
|
Packit |
aea12f |
return gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
e->ctx = ctx;
|
|
Packit |
aea12f |
e->next = head;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
head = e;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
return 0;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
inline static int _gnutls_rnd_init(void)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
if (unlikely(!rnd_initialized)) {
|
|
Packit |
aea12f |
int ret;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
if (_gnutls_rnd_ops.init == NULL) {
|
|
Packit |
aea12f |
rnd_initialized = 1;
|
|
Packit |
aea12f |
return 0;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
if (_gnutls_rnd_ops.init(&gnutls_rnd_ctx) < 0) {
|
|
Packit |
aea12f |
gnutls_assert();
|
|
Packit |
aea12f |
return GNUTLS_E_RANDOM_FAILED;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
GNUTLS_STATIC_MUTEX_LOCK(gnutls_rnd_ctx_list_mutex);
|
|
Packit |
aea12f |
ret = append(gnutls_rnd_ctx);
|
|
Packit |
aea12f |
GNUTLS_STATIC_MUTEX_UNLOCK(gnutls_rnd_ctx_list_mutex);
|
|
Packit |
aea12f |
if (ret < 0) {
|
|
Packit |
aea12f |
gnutls_assert();
|
|
Packit |
aea12f |
_gnutls_rnd_ops.deinit(gnutls_rnd_ctx);
|
|
Packit |
aea12f |
return ret;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
rnd_initialized = 1;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
return 0;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
int _gnutls_rnd_preinit(void)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
int ret;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
#if defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
|
|
Packit |
aea12f |
# warning Insecure PRNG is enabled
|
|
Packit |
aea12f |
ret = gnutls_crypto_rnd_register(100, &_gnutls_fuzz_rnd_ops);
|
|
Packit |
aea12f |
if (ret < 0)
|
|
Packit |
aea12f |
return ret;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
#elif defined(ENABLE_FIPS140)
|
|
Packit |
aea12f |
/* The FIPS140 random generator is only enabled when we are compiled
|
|
Packit Service |
991b93 |
* with FIPS support, _and_ the system is in FIPS installed state.
|
|
Packit |
aea12f |
*/
|
|
Packit Service |
991b93 |
if (_gnutls_fips_mode_enabled() != 0) {
|
|
Packit |
aea12f |
ret = gnutls_crypto_rnd_register(100, &_gnutls_fips_rnd_ops);
|
|
Packit |
aea12f |
if (ret < 0)
|
|
Packit |
aea12f |
return ret;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
#endif
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
ret = _rnd_system_entropy_init();
|
|
Packit |
aea12f |
if (ret < 0) {
|
|
Packit |
aea12f |
gnutls_assert();
|
|
Packit |
aea12f |
return GNUTLS_E_RANDOM_FAILED;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
return 0;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
void _gnutls_rnd_deinit(void)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
if (_gnutls_rnd_ops.deinit != NULL) {
|
|
Packit |
aea12f |
struct rnd_ctx_list_st *e = head, *next;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
while(e != NULL) {
|
|
Packit |
aea12f |
next = e->next;
|
|
Packit |
aea12f |
_gnutls_rnd_ops.deinit(e->ctx);
|
|
Packit |
aea12f |
gnutls_free(e);
|
|
Packit |
aea12f |
e = next;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
head = NULL;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
rnd_initialized = 0;
|
|
Packit |
aea12f |
_rnd_system_entropy_deinit();
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
return;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
/**
|
|
Packit |
aea12f |
* gnutls_rnd:
|
|
Packit |
aea12f |
* @level: a security level
|
|
Packit |
aea12f |
* @data: place to store random bytes
|
|
Packit |
aea12f |
* @len: The requested size
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* This function will generate random data and store it to output
|
|
Packit |
aea12f |
* buffer. The value of @level should be one of %GNUTLS_RND_NONCE,
|
|
Packit |
aea12f |
* %GNUTLS_RND_RANDOM and %GNUTLS_RND_KEY. See the manual and
|
|
Packit |
aea12f |
* %gnutls_rnd_level_t for detailed information.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* This function is thread-safe and also fork-safe.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* Returns: Zero on success, or a negative error code on error.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* Since: 2.12.0
|
|
Packit |
aea12f |
**/
|
|
Packit |
aea12f |
int gnutls_rnd(gnutls_rnd_level_t level, void *data, size_t len)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
int ret;
|
|
Packit |
aea12f |
FAIL_IF_LIB_ERROR;
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
if (unlikely((ret=_gnutls_rnd_init()) < 0))
|
|
Packit |
aea12f |
return gnutls_assert_val(ret);
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
if (likely(len > 0)) {
|
|
Packit |
aea12f |
return _gnutls_rnd_ops.rnd(gnutls_rnd_ctx, level, data,
|
|
Packit |
aea12f |
len);
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
return 0;
|
|
Packit |
aea12f |
}
|
|
Packit |
aea12f |
|
|
Packit |
aea12f |
/**
|
|
Packit |
aea12f |
* gnutls_rnd_refresh:
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* This function refreshes the random generator state.
|
|
Packit |
aea12f |
* That is the current precise time, CPU usage, and
|
|
Packit |
aea12f |
* other values are input into its state.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* On a slower rate input from /dev/urandom is mixed too.
|
|
Packit |
aea12f |
*
|
|
Packit |
aea12f |
* Since: 3.1.7
|
|
Packit |
aea12f |
**/
|
|
Packit |
aea12f |
void gnutls_rnd_refresh(void)
|
|
Packit |
aea12f |
{
|
|
Packit |
aea12f |
if (rnd_initialized && _gnutls_rnd_ops.rnd_refresh)
|
|
Packit |
aea12f |
_gnutls_rnd_ops.rnd_refresh(gnutls_rnd_ctx);
|
|
Packit |
aea12f |
}
|