Blame lib/random.c

Packit Service 4684c1
/*
Packit Service 4684c1
 * Copyright (C) 2008-2012 Free Software Foundation, Inc.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Author: Nikos Mavrogiannopoulos
Packit Service 4684c1
 *
Packit Service 4684c1
 * This file is part of GnuTLS.
Packit Service 4684c1
 *
Packit Service 4684c1
 * The GnuTLS is free software; you can redistribute it and/or
Packit Service 4684c1
 * modify it under the terms of the GNU Lesser General Public License
Packit Service 4684c1
 * as published by the Free Software Foundation; either version 2.1 of
Packit Service 4684c1
 * the License, or (at your option) any later version.
Packit Service 4684c1
 *
Packit Service 4684c1
 * This library is distributed in the hope that it will be useful, but
Packit Service 4684c1
 * WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 4684c1
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit Service 4684c1
 * Lesser General Public License for more details.
Packit Service 4684c1
 *
Packit Service 4684c1
 * You should have received a copy of the GNU Lesser General Public License
Packit Service 4684c1
 * along with this program.  If not, see <https://www.gnu.org/licenses/>
Packit Service 4684c1
 *
Packit Service 4684c1
 */
Packit Service 4684c1
Packit Service 4684c1
/* This file handles all the internal functions that cope with random data.
Packit Service 4684c1
 */
Packit Service 4684c1
Packit Service 4684c1
#include "gnutls_int.h"
Packit Service 4684c1
#include "errors.h"
Packit Service 4684c1
#include <random.h>
Packit Service 4684c1
#include "locks.h"
Packit Service 4684c1
#include <fips.h>
Packit Service 4684c1
Packit Service 4684c1
#include "gthreads.h"
Packit Service 4684c1
Packit Service 4684c1
#if defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
Packit Service 4684c1
extern gnutls_crypto_rnd_st _gnutls_fuzz_rnd_ops;
Packit Service 4684c1
#endif
Packit Service 4684c1
Packit Service 4684c1
/* Per thread context of random generator, and a flag to indicate initialization */
Packit Service 4684c1
static _Thread_local void *gnutls_rnd_ctx;
Packit Service 4684c1
static _Thread_local unsigned rnd_initialized = 0;
Packit Service 4684c1
Packit Service 4684c1
struct rnd_ctx_list_st {
Packit Service 4684c1
	void *ctx;
Packit Service 4684c1
	struct rnd_ctx_list_st *next;
Packit Service 4684c1
};
Packit Service 4684c1
Packit Service 4684c1
/* A global list of all allocated contexts - to be
Packit Service 4684c1
 * used during deinitialization. */
Packit Service 4684c1
GNUTLS_STATIC_MUTEX(gnutls_rnd_ctx_list_mutex);
Packit Service 4684c1
static struct rnd_ctx_list_st *head = NULL;
Packit Service 4684c1
Packit Service 4684c1
static int append(void *ctx)
Packit Service 4684c1
{
Packit Service 4684c1
	struct rnd_ctx_list_st *e = gnutls_malloc(sizeof(*e));
Packit Service 4684c1
Packit Service 4684c1
	if (e == NULL)
Packit Service 4684c1
		return gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
Packit Service 4684c1
Packit Service 4684c1
	e->ctx = ctx;
Packit Service 4684c1
	e->next = head;
Packit Service 4684c1
Packit Service 4684c1
	head = e;
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
inline static int _gnutls_rnd_init(void)
Packit Service 4684c1
{
Packit Service 4684c1
	if (unlikely(!rnd_initialized)) {
Packit Service 4684c1
		int ret;
Packit Service 4684c1
Packit Service 4684c1
		if (_gnutls_rnd_ops.init == NULL) {
Packit Service 4684c1
			rnd_initialized = 1;
Packit Service 4684c1
			return 0;
Packit Service 4684c1
		}
Packit Service 4684c1
Packit Service 4684c1
		if (_gnutls_rnd_ops.init(&gnutls_rnd_ctx) < 0) {
Packit Service 4684c1
			gnutls_assert();
Packit Service 4684c1
			return GNUTLS_E_RANDOM_FAILED;
Packit Service 4684c1
		}
Packit Service 4684c1
Packit Service 4684c1
		GNUTLS_STATIC_MUTEX_LOCK(gnutls_rnd_ctx_list_mutex);
Packit Service 4684c1
		ret = append(gnutls_rnd_ctx);
Packit Service 4684c1
		GNUTLS_STATIC_MUTEX_UNLOCK(gnutls_rnd_ctx_list_mutex);
Packit Service 4684c1
		if (ret < 0) {
Packit Service 4684c1
			gnutls_assert();
Packit Service 4684c1
			_gnutls_rnd_ops.deinit(gnutls_rnd_ctx);
Packit Service 4684c1
			return ret;
Packit Service 4684c1
		}
Packit Service 4684c1
Packit Service 4684c1
		rnd_initialized = 1;
Packit Service 4684c1
	}
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
int _gnutls_rnd_preinit(void)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
Packit Service 4684c1
#if defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
Packit Service 4684c1
# warning Insecure PRNG is enabled
Packit Service 4684c1
	ret = gnutls_crypto_rnd_register(100, &_gnutls_fuzz_rnd_ops);
Packit Service 4684c1
	if (ret < 0)
Packit Service 4684c1
		return ret;
Packit Service 4684c1
Packit Service 4684c1
#elif defined(ENABLE_FIPS140)
Packit Service 4684c1
	/* The FIPS140 random generator is only enabled when we are compiled
Packit Service 4684c1
	 * with FIPS support, _and_ the system is in FIPS installed state.
Packit Service 4684c1
	 */
Packit Service 4684c1
	if (_gnutls_fips_mode_enabled() != 0) {
Packit Service 4684c1
		ret = gnutls_crypto_rnd_register(100, &_gnutls_fips_rnd_ops);
Packit Service 4684c1
		if (ret < 0)
Packit Service 4684c1
			return ret;
Packit Service 4684c1
	}
Packit Service 4684c1
#endif
Packit Service 4684c1
Packit Service 4684c1
	ret = _rnd_system_entropy_init();
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		gnutls_assert();
Packit Service 4684c1
		return GNUTLS_E_RANDOM_FAILED;
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
void _gnutls_rnd_deinit(void)
Packit Service 4684c1
{
Packit Service 4684c1
	if (_gnutls_rnd_ops.deinit != NULL) {
Packit Service 4684c1
		struct rnd_ctx_list_st *e = head, *next;
Packit Service 4684c1
Packit Service 4684c1
		while(e != NULL) {
Packit Service 4684c1
			next = e->next;
Packit Service 4684c1
			_gnutls_rnd_ops.deinit(e->ctx);
Packit Service 4684c1
			gnutls_free(e);
Packit Service 4684c1
			e = next;
Packit Service 4684c1
		}
Packit Service 4684c1
		head = NULL;
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	rnd_initialized = 0;
Packit Service 4684c1
	_rnd_system_entropy_deinit();
Packit Service 4684c1
Packit Service 4684c1
	return;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
/**
Packit Service 4684c1
 * gnutls_rnd:
Packit Service 4684c1
 * @level: a security level
Packit Service 4684c1
 * @data: place to store random bytes
Packit Service 4684c1
 * @len: The requested size
Packit Service 4684c1
 *
Packit Service 4684c1
 * This function will generate random data and store it to output
Packit Service 4684c1
 * buffer. The value of @level should be one of %GNUTLS_RND_NONCE,
Packit Service 4684c1
 * %GNUTLS_RND_RANDOM and %GNUTLS_RND_KEY. See the manual and
Packit Service 4684c1
 * %gnutls_rnd_level_t for detailed information.
Packit Service 4684c1
 *
Packit Service 4684c1
 * This function is thread-safe and also fork-safe.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Returns: Zero on success, or a negative error code on error.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Since: 2.12.0
Packit Service 4684c1
 **/
Packit Service 4684c1
int gnutls_rnd(gnutls_rnd_level_t level, void *data, size_t len)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	FAIL_IF_LIB_ERROR;
Packit Service 4684c1
Packit Service 4684c1
	if (unlikely((ret=_gnutls_rnd_init()) < 0))
Packit Service 4684c1
		return gnutls_assert_val(ret);
Packit Service 4684c1
Packit Service 4684c1
	if (likely(len > 0)) {
Packit Service 4684c1
		return _gnutls_rnd_ops.rnd(gnutls_rnd_ctx, level, data,
Packit Service 4684c1
					   len);
Packit Service 4684c1
	}
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
/**
Packit Service 4684c1
 * gnutls_rnd_refresh:
Packit Service 4684c1
 *
Packit Service 4684c1
 * This function refreshes the random generator state.
Packit Service 4684c1
 * That is the current precise time, CPU usage, and
Packit Service 4684c1
 * other values are input into its state.
Packit Service 4684c1
 *
Packit Service 4684c1
 * On a slower rate input from /dev/urandom is mixed too.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Since: 3.1.7
Packit Service 4684c1
 **/
Packit Service 4684c1
void gnutls_rnd_refresh(void)
Packit Service 4684c1
{
Packit Service 4684c1
	if (rnd_initialized && _gnutls_rnd_ops.rnd_refresh)
Packit Service 4684c1
		_gnutls_rnd_ops.rnd_refresh(gnutls_rnd_ctx);
Packit Service 4684c1
}