update main-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2023-05-16 22:09:44 +00:00
14 changed files with 301 additions and 233 deletions
+1 -3
View File
@@ -414,9 +414,7 @@ crypto_sources = [
"src/crypto/rand_extra/rand_extra.c",
"src/crypto/rand_extra/windows.c",
"src/crypto/rc4/rc4.c",
"src/crypto/refcount_c11.c",
"src/crypto/refcount_no_threads.c",
"src/crypto/refcount_win.c",
"src/crypto/refcount.c",
"src/crypto/rsa_extra/rsa_asn1.c",
"src/crypto/rsa_extra/rsa_crypt.c",
"src/crypto/rsa_extra/rsa_print.c",
+1 -3
View File
@@ -407,9 +407,7 @@ add_library(
src/crypto/rand_extra/rand_extra.c
src/crypto/rand_extra/windows.c
src/crypto/rc4/rc4.c
src/crypto/refcount_c11.c
src/crypto/refcount_no_threads.c
src/crypto/refcount_win.c
src/crypto/refcount.c
src/crypto/rsa_extra/rsa_asn1.c
src/crypto/rsa_extra/rsa_crypt.c
src/crypto/rsa_extra/rsa_print.c
+1 -3
View File
@@ -143,9 +143,7 @@
"src/crypto/rand_extra/rand_extra.c",
"src/crypto/rand_extra/windows.c",
"src/crypto/rc4/rc4.c",
"src/crypto/refcount_c11.c",
"src/crypto/refcount_no_threads.c",
"src/crypto/refcount_win.c",
"src/crypto/refcount.c",
"src/crypto/rsa_extra/rsa_asn1.c",
"src/crypto/rsa_extra/rsa_crypt.c",
"src/crypto/rsa_extra/rsa_print.c",
+1 -3
View File
@@ -202,9 +202,7 @@ add_library(
rand_extra/rand_extra.c
rand_extra/windows.c
rc4/rc4.c
refcount_c11.c
refcount_no_threads.c
refcount_win.c
refcount.c
rsa_extra/rsa_asn1.c
rsa_extra/rsa_crypt.c
rsa_extra/rsa_print.c
+24 -22
View File
@@ -38,7 +38,7 @@ static_assert(MADV_WIPEONFORK == 18, "MADV_WIPEONFORK is not 18");
DEFINE_STATIC_ONCE(g_fork_detect_once);
DEFINE_STATIC_MUTEX(g_fork_detect_lock);
DEFINE_BSS_GET(volatile char *, g_fork_detect_addr);
DEFINE_BSS_GET(CRYPTO_atomic_u32 *, g_fork_detect_addr);
DEFINE_BSS_GET(uint64_t, g_fork_generation);
DEFINE_BSS_GET(int, g_force_madv_wipeonfork);
DEFINE_BSS_GET(int, g_force_madv_wipeonfork_enabled);
@@ -70,7 +70,7 @@ static void init_fork_detect(void) {
return;
}
*((volatile char *) addr) = 1;
CRYPTO_atomic_store_u32(addr, 1);
*g_fork_detect_addr_bss_get() = addr;
*g_fork_generation_bss_get() = 1;
}
@@ -83,16 +83,12 @@ uint64_t CRYPTO_get_fork_generation(void) {
// is initialised atomically, even if multiple threads enter this function
// concurrently.
//
// In the limit, the kernel may clear WIPEONFORK pages while a multi-threaded
// process is running. (For example, because a VM was cloned.) Therefore a
// lock is used below to synchronise the potentially multiple threads that may
// concurrently observe the cleared flag.
// Additionally, while the kernel will only clear WIPEONFORK at a point when a
// child process is single-threaded, the child may become multi-threaded
// before it observes this. Therefore, we must synchronize the logic below.
CRYPTO_once(g_fork_detect_once_bss_get(), init_fork_detect);
// This pointer is |volatile| because the value pointed to may be changed by
// external forces (i.e. the kernel wiping the page) thus the compiler must
// not assume that it has exclusive access to it.
volatile char *const flag_ptr = *g_fork_detect_addr_bss_get();
CRYPTO_atomic_u32 *const flag_ptr = *g_fork_detect_addr_bss_get();
if (flag_ptr == NULL) {
// Our kernel is too old to support |MADV_WIPEONFORK| or
// |g_force_madv_wipeonfork| is set.
@@ -105,28 +101,34 @@ uint64_t CRYPTO_get_fork_generation(void) {
return 0;
}
struct CRYPTO_STATIC_MUTEX *const lock = g_fork_detect_lock_bss_get();
// In the common case, try to observe the flag without taking a lock. This
// avoids cacheline contention in the PRNG.
uint64_t *const generation_ptr = g_fork_generation_bss_get();
CRYPTO_STATIC_MUTEX_lock_read(lock);
uint64_t current_generation = *generation_ptr;
if (*flag_ptr) {
CRYPTO_STATIC_MUTEX_unlock_read(lock);
return current_generation;
if (CRYPTO_atomic_load_u32(flag_ptr) != 0) {
// If we observe a non-zero flag, it is safe to read |generation_ptr|
// without a lock. The flag and generation number are fixed for this copy of
// the address space.
return *generation_ptr;
}
CRYPTO_STATIC_MUTEX_unlock_read(lock);
// The flag was zero. The generation number must be incremented, but other
// threads may have concurrently observed the zero, so take a lock before
// incrementing.
struct CRYPTO_STATIC_MUTEX *const lock = g_fork_detect_lock_bss_get();
CRYPTO_STATIC_MUTEX_lock_write(lock);
current_generation = *generation_ptr;
if (*flag_ptr == 0) {
uint64_t current_generation = *generation_ptr;
if (CRYPTO_atomic_load_u32(flag_ptr) == 0) {
// A fork has occurred.
*flag_ptr = 1;
current_generation++;
if (current_generation == 0) {
// Zero means fork detection isn't supported, so skip that value.
current_generation = 1;
}
// We must update |generation_ptr| before |flag_ptr|. Other threads may
// observe |flag_ptr| without taking a lock.
*generation_ptr = current_generation;
CRYPTO_atomic_store_u32(flag_ptr, 1);
}
CRYPTO_STATIC_MUTEX_unlock_write(lock);
+27 -8
View File
@@ -65,6 +65,9 @@ struct rand_thread_state {
// last_block_valid is non-zero iff |last_block| contains data from
// |get_seed_entropy|.
int last_block_valid;
// fork_unsafe_buffering is non-zero iff, when |drbg| was last (re)seeded,
// fork-unsafe buffering was enabled.
int fork_unsafe_buffering;
#if defined(BORINGSSL_FIPS)
// last_block contains the previous block from |get_seed_entropy|.
@@ -72,6 +75,10 @@ struct rand_thread_state {
// next and prev form a NULL-terminated, double-linked list of all states in
// a process.
struct rand_thread_state *next, *prev;
// clear_drbg_lock synchronizes between uses of |drbg| and
// |rand_thread_state_clear_all| clearing it. This lock should be uncontended
// in the common case, except on shutdown.
CRYPTO_MUTEX clear_drbg_lock;
#endif
};
@@ -82,18 +89,19 @@ struct rand_thread_state {
// called when the whole process is exiting.
DEFINE_BSS_GET(struct rand_thread_state *, thread_states_list);
DEFINE_STATIC_MUTEX(thread_states_list_lock);
DEFINE_STATIC_MUTEX(state_clear_all_lock);
static void rand_thread_state_clear_all(void) __attribute__((destructor));
static void rand_thread_state_clear_all(void) {
CRYPTO_STATIC_MUTEX_lock_write(thread_states_list_lock_bss_get());
CRYPTO_STATIC_MUTEX_lock_write(state_clear_all_lock_bss_get());
for (struct rand_thread_state *cur = *thread_states_list_bss_get();
cur != NULL; cur = cur->next) {
CRYPTO_MUTEX_lock_write(&cur->clear_drbg_lock);
CTR_DRBG_clear(&cur->drbg);
}
// The locks are deliberately left locked so that any threads that are still
// running will hang if they try to call |RAND_bytes|.
// running will hang if they try to call |RAND_bytes|. It also ensures
// |rand_thread_state_free| cannot free any thread state while we've taken the
// lock.
}
#endif
@@ -326,6 +334,7 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
}
const uint64_t fork_generation = CRYPTO_get_fork_generation();
const int fork_unsafe_buffering = rand_fork_unsafe_buffering_enabled();
// Additional data is mixed into every CTR-DRBG call to protect, as best we
// can, against forks & VM clones. We do not over-read this information and
@@ -340,7 +349,7 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
// entropy is used. This can be expensive (one read per |RAND_bytes| call)
// and so is disabled when we have fork detection, or if the application has
// promised not to fork.
if (fork_generation != 0 || rand_fork_unsafe_buffering_enabled()) {
if (fork_generation != 0 || fork_unsafe_buffering) {
OPENSSL_memset(additional_data, 0, sizeof(additional_data));
} else if (!have_rdrand()) {
// No alternative so block for OS entropy.
@@ -383,8 +392,10 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
}
state->calls = 0;
state->fork_generation = fork_generation;
state->fork_unsafe_buffering = fork_unsafe_buffering;
#if defined(BORINGSSL_FIPS)
CRYPTO_MUTEX_init(&state->clear_drbg_lock);
if (state != &stack_state) {
CRYPTO_STATIC_MUTEX_lock_write(thread_states_list_lock_bss_get());
struct rand_thread_state **states_list = thread_states_list_bss_get();
@@ -400,7 +411,14 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
}
if (state->calls >= kReseedInterval ||
state->fork_generation != fork_generation) {
// If we've forked since |state| was last seeded, reseed.
state->fork_generation != fork_generation ||
// If |state| was seeded from a state with different fork-safety
// preferences, reseed. Suppose |state| was fork-safe, then forked into
// two children, but each of the children never fork and disable fork
// safety. The children must reseed to avoid working from the same PRNG
// state.
state->fork_unsafe_buffering != fork_unsafe_buffering) {
uint8_t seed[CTR_DRBG_ENTROPY_LEN];
uint8_t reseed_additional_data[CTR_DRBG_ENTROPY_LEN] = {0};
size_t reseed_additional_data_len = 0;
@@ -410,7 +428,7 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
// Take a read lock around accesses to |state->drbg|. This is needed to
// avoid returning bad entropy if we race with
// |rand_thread_state_clear_all|.
CRYPTO_STATIC_MUTEX_lock_read(state_clear_all_lock_bss_get());
CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
#endif
if (!CTR_DRBG_reseed(&state->drbg, seed, reseed_additional_data,
reseed_additional_data_len)) {
@@ -418,9 +436,10 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
}
state->calls = 0;
state->fork_generation = fork_generation;
state->fork_unsafe_buffering = fork_unsafe_buffering;
} else {
#if defined(BORINGSSL_FIPS)
CRYPTO_STATIC_MUTEX_lock_read(state_clear_all_lock_bss_get());
CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
#endif
}
@@ -449,7 +468,7 @@ void RAND_bytes_with_additional_data(uint8_t *out, size_t out_len,
}
#if defined(BORINGSSL_FIPS)
CRYPTO_STATIC_MUTEX_unlock_read(state_clear_all_lock_bss_get());
CRYPTO_MUTEX_unlock_read(&state->clear_drbg_lock);
#endif
}
+129 -19
View File
@@ -155,6 +155,32 @@
#if defined(OPENSSL_THREADS) && !defined(OPENSSL_PTHREADS) && \
defined(OPENSSL_WINDOWS)
#define OPENSSL_WINDOWS_THREADS
#endif
// Determine the atomics implementation to use with C.
#if !defined(__cplusplus)
#if !defined(OPENSSL_C11_ATOMIC) && defined(OPENSSL_THREADS) && \
!defined(__STDC_NO_ATOMICS__) && defined(__STDC_VERSION__) && \
__STDC_VERSION__ >= 201112L
#define OPENSSL_C11_ATOMIC
#endif
// Older MSVC does not support C11 atomics, so we fallback to the Windows APIs.
// When both are available (e.g. clang-cl), we prefer the C11 ones. The Windows
// APIs don't allow some operations to be implemented as efficiently. This can
// be removed once we can rely on
// https://devblogs.microsoft.com/cppblog/c11-atomics-in-visual-studio-2022-version-17-5-preview-2/
#if !defined(OPENSSL_C11_ATOMIC) && defined(OPENSSL_THREADS) && \
defined(OPENSSL_WINDOWS)
#define OPENSSL_WINDOWS_ATOMIC
#endif
#endif // !__cplusplus
#if defined(OPENSSL_C11_ATOMIC)
#include <stdatomic.h>
#endif
#if defined(OPENSSL_WINDOWS_THREADS) || defined(OPENSSL_WINDOWS_ATOMIC)
OPENSSL_MSVC_PRAGMA(warning(push, 3))
#include <windows.h>
OPENSSL_MSVC_PRAGMA(warning(pop))
@@ -539,33 +565,117 @@ typedef pthread_once_t CRYPTO_once_t;
OPENSSL_EXPORT void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void));
// Reference counting.
// Atomics.
//
// The following functions provide an API analogous to <stdatomic.h> from C11
// and abstract between a few variations on atomics we need to support.
// Automatically enable C11 atomics if implemented.
#if !defined(OPENSSL_C11_ATOMIC) && defined(OPENSSL_THREADS) && \
!defined(__STDC_NO_ATOMICS__) && defined(__STDC_VERSION__) && \
__STDC_VERSION__ >= 201112L
#define OPENSSL_C11_ATOMIC
#endif
#if defined(__cplusplus)
// Older MSVC does not support C11 atomics, so we fallback to the Windows APIs.
// This can be removed once we can rely on
// https://devblogs.microsoft.com/cppblog/c11-atomics-in-visual-studio-2022-version-17-5-preview-2/
#if !defined(OPENSSL_C11_ATOMIC) && defined(OPENSSL_THREADS) && \
defined(OPENSSL_WINDOWS)
#define OPENSSL_WINDOWS_ATOMIC
#endif
// In C++, we can't easily detect whether C will use |OPENSSL_C11_ATOMIC| or
// |OPENSSL_WINDOWS_ATOMIC|. Instead, we define a layout-compatible type without
// the corresponding functions. When we can rely on C11 atomics in MSVC, that
// will no longer be a concern.
typedef uint32_t CRYPTO_atomic_u32;
#elif defined(OPENSSL_C11_ATOMIC)
typedef _Atomic uint32_t CRYPTO_atomic_u32;
// This should be const, but the |OPENSSL_WINDOWS_ATOMIC| implementation is not
// const due to Windows limitations. When we can rely on C11 atomics, make this
// const-correct.
OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
return atomic_load(val);
}
OPENSSL_INLINE int CRYPTO_atomic_compare_exchange_weak_u32(
CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
return atomic_compare_exchange_weak(val, expected, desired);
}
OPENSSL_INLINE void CRYPTO_atomic_store_u32(CRYPTO_atomic_u32 *val,
uint32_t desired) {
atomic_store(val, desired);
}
#elif defined(OPENSSL_WINDOWS_ATOMIC)
typedef LONG CRYPTO_atomic_u32;
OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(volatile CRYPTO_atomic_u32 *val) {
// This is not ideal because it still writes to a cacheline. MSVC is not able
// to optimize this to a true atomic read, and Windows does not provide an
// InterlockedLoad function.
//
// The Windows documentation [1] does say "Simple reads and writes to
// properly-aligned 32-bit variables are atomic operations", but this is not
// phrased in terms of the C11 and C++11 memory models, and indeed a read or
// write seems to produce slightly different code on MSVC than a sequentially
// consistent std::atomic::load in C++. Moreover, it is unclear if non-MSVC
// compilers on Windows provide the same guarantees. Thus we avoid relying on
// this and instead still use an interlocked function. This is still
// preferable a global mutex, and eventually this code will be replaced by
// [2]. Additionally, on clang-cl, we'll use the |OPENSSL_C11_ATOMIC| path.
//
// [1] https://learn.microsoft.com/en-us/windows/win32/sync/interlocked-variable-access
// [2] https://devblogs.microsoft.com/cppblog/c11-atomics-in-visual-studio-2022-version-17-5-preview-2/
return (uint32_t)InterlockedCompareExchange(val, 0, 0);
}
OPENSSL_INLINE int CRYPTO_atomic_compare_exchange_weak_u32(
volatile CRYPTO_atomic_u32 *val, uint32_t *expected32, uint32_t desired) {
LONG expected = (LONG)*expected32;
LONG actual = InterlockedCompareExchange(val, (LONG)desired, expected);
*expected32 = (uint32_t)actual;
return actual == expected;
}
OPENSSL_INLINE void CRYPTO_atomic_store_u32(volatile CRYPTO_atomic_u32 *val,
uint32_t desired) {
InterlockedExchange(val, (LONG)desired);
}
#elif !defined(OPENSSL_THREADS)
typedef uint32_t CRYPTO_atomic_u32;
OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
return *val;
}
OPENSSL_INLINE int CRYPTO_atomic_compare_exchange_weak_u32(
CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
if (*val != *expected) {
*expected = *val;
return 0;
}
*val = desired;
return 1;
}
OPENSSL_INLINE void CRYPTO_atomic_store_u32(CRYPTO_atomic_u32 *val,
uint32_t desired) {
*val = desired;
}
#else
// Require some atomics implementation. Contact BoringSSL maintainers if you
// have a platform with fails this check.
//
// Note this check can only be done in C. From C++, we don't know whether the
// corresponding C mode would support C11 atomics.
#if !defined(__cplusplus) && defined(OPENSSL_THREADS) && \
!defined(OPENSSL_C11_ATOMIC) && !defined(OPENSSL_WINDOWS_ATOMIC)
#error "Thread-compatible configurations require atomics"
#endif
// See the comment in the |__cplusplus| section above.
static_assert(sizeof(CRYPTO_atomic_u32) == sizeof(uint32_t),
"CRYPTO_atomic_u32 does not match uint32_t size");
static_assert(alignof(CRYPTO_atomic_u32) == alignof(uint32_t),
"CRYPTO_atomic_u32 does not match uint32_t alignment");
// Reference counting.
// CRYPTO_REFCOUNT_MAX is the value at which the reference count saturates.
#define CRYPTO_REFCOUNT_MAX 0xffffffff
+6 -12
View File
@@ -17,13 +17,12 @@
#include <stdlib.h>
#include "../fipsmodule/rand/internal.h"
#include "../internal.h"
// g_buffering_enabled is true if fork-unsafe buffering has been enabled.
static int g_buffering_enabled = 0;
// g_lock protects |g_buffering_enabled|.
static struct CRYPTO_STATIC_MUTEX g_lock = CRYPTO_STATIC_MUTEX_INIT;
// g_buffering_enabled is one if fork-unsafe buffering has been enabled and zero
// otherwise.
static CRYPTO_atomic_u32 g_buffering_enabled = 0;
#if !defined(OPENSSL_WINDOWS)
void RAND_enable_fork_unsafe_buffering(int fd) {
@@ -32,15 +31,10 @@ void RAND_enable_fork_unsafe_buffering(int fd) {
abort();
}
CRYPTO_STATIC_MUTEX_lock_write(&g_lock);
g_buffering_enabled = 1;
CRYPTO_STATIC_MUTEX_unlock_write(&g_lock);
CRYPTO_atomic_store_u32(&g_buffering_enabled, 1);
}
#endif
int rand_fork_unsafe_buffering_enabled(void) {
CRYPTO_STATIC_MUTEX_lock_read(&g_lock);
const int ret = g_buffering_enabled;
CRYPTO_STATIC_MUTEX_unlock_read(&g_lock);
return ret;
return CRYPTO_atomic_load_u32(&g_buffering_enabled) != 0;
}
+24 -12
View File
@@ -56,7 +56,7 @@ TEST(RandTest, NotObviouslyBroken) {
#if !defined(OPENSSL_WINDOWS) && !defined(OPENSSL_IOS) && \
!defined(OPENSSL_FUCHSIA) && !defined(BORINGSSL_UNSAFE_DETERMINISTIC_MODE)
static bool ForkAndRand(bssl::Span<uint8_t> out) {
static bool ForkAndRand(bssl::Span<uint8_t> out, bool fork_unsafe_buffering) {
int pipefds[2];
if (pipe(pipefds) < 0) {
perror("pipe");
@@ -76,6 +76,9 @@ static bool ForkAndRand(bssl::Span<uint8_t> out) {
if (child == 0) {
// This is the child. Generate entropy and write it to the parent.
close(pipefds[0]);
if (fork_unsafe_buffering) {
RAND_enable_fork_unsafe_buffering(-1);
}
RAND_bytes(out.data(), out.size());
while (!out.empty()) {
ssize_t ret = write(pipefds[1], out.data(), out.size());
@@ -136,18 +139,27 @@ TEST(RandTest, Fork) {
// intentionally uses smaller buffers than the others, to minimize the chance
// of sneaking by with a large enough buffer that we've since reseeded from
// the OS.
uint8_t buf1[16], buf2[16], buf3[16];
ASSERT_TRUE(ForkAndRand(buf1));
ASSERT_TRUE(ForkAndRand(buf2));
RAND_bytes(buf3, sizeof(buf3));
//
// All child processes should have different PRNGs, including the ones that
// disavow fork-safety. Although they are produced by fork, they themselves do
// not fork after that call.
uint8_t bufs[5][16];
ASSERT_TRUE(ForkAndRand(bufs[0], /*fork_unsafe_buffering=*/false));
ASSERT_TRUE(ForkAndRand(bufs[1], /*fork_unsafe_buffering=*/false));
ASSERT_TRUE(ForkAndRand(bufs[2], /*fork_unsafe_buffering=*/true));
ASSERT_TRUE(ForkAndRand(bufs[3], /*fork_unsafe_buffering=*/true));
RAND_bytes(bufs[4], sizeof(bufs[4]));
// All should be different.
EXPECT_NE(Bytes(buf1), Bytes(buf2));
EXPECT_NE(Bytes(buf2), Bytes(buf3));
EXPECT_NE(Bytes(buf1), Bytes(buf3));
EXPECT_NE(Bytes(buf1), Bytes(kZeros));
EXPECT_NE(Bytes(buf2), Bytes(kZeros));
EXPECT_NE(Bytes(buf3), Bytes(kZeros));
// All should be different and non-zero.
for (const auto &buf : bufs) {
EXPECT_NE(Bytes(buf), Bytes(kZeros));
}
for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(bufs); i++) {
for (size_t j = 0; j < i; j++) {
EXPECT_NE(Bytes(bufs[i]), Bytes(bufs[j]))
<< "buffers " << i << " and " << j << " matched";
}
}
}
#endif // !OPENSSL_WINDOWS && !OPENSSL_IOS &&
// !OPENSSL_FUCHSIA && !BORINGSSL_UNSAFE_DETERMINISTIC_MODE
@@ -14,39 +14,35 @@
#include "internal.h"
#if defined(OPENSSL_C11_ATOMIC)
#include <assert.h>
#include <stdalign.h>
#include <stdatomic.h>
#include <stdlib.h>
// See comment above the typedef of CRYPTO_refcount_t about these tests.
static_assert(alignof(CRYPTO_refcount_t) == alignof(_Atomic CRYPTO_refcount_t),
"_Atomic alters the needed alignment of a reference count");
static_assert(sizeof(CRYPTO_refcount_t) == sizeof(_Atomic CRYPTO_refcount_t),
"_Atomic alters the size of a reference count");
static_assert(alignof(CRYPTO_refcount_t) == alignof(CRYPTO_atomic_u32),
"CRYPTO_refcount_t does not match CRYPTO_atomic_u32 alignment");
static_assert(sizeof(CRYPTO_refcount_t) == sizeof(CRYPTO_atomic_u32),
"CRYPTO_refcount_t does not match CRYPTO_atomic_u32 size");
static_assert((CRYPTO_refcount_t)-1 == CRYPTO_REFCOUNT_MAX,
"CRYPTO_REFCOUNT_MAX is incorrect");
void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
_Atomic CRYPTO_refcount_t *count = (_Atomic CRYPTO_refcount_t *) in_count;
uint32_t expected = atomic_load(count);
CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
uint32_t expected = CRYPTO_atomic_load_u32(count);
while (expected != CRYPTO_REFCOUNT_MAX) {
uint32_t new_value = expected + 1;
if (atomic_compare_exchange_weak(count, &expected, new_value)) {
if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
break;
}
}
}
int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
_Atomic CRYPTO_refcount_t *count = (_Atomic CRYPTO_refcount_t *)in_count;
uint32_t expected = atomic_load(count);
CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
uint32_t expected = CRYPTO_atomic_load_u32(count);
for (;;) {
if (expected == 0) {
@@ -55,11 +51,10 @@ int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
return 0;
} else {
const uint32_t new_value = expected - 1;
if (atomic_compare_exchange_weak(count, &expected, new_value)) {
if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
new_value)) {
return new_value == 0;
}
}
}
}
#endif // OPENSSL_C11_ATOMIC
-42
View File
@@ -1,42 +0,0 @@
/* Copyright (c) 2015, Google Inc.
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* copyright notice and this permission notice appear in all copies.
*
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
#include "internal.h"
#include <assert.h>
#include <stdlib.h>
#if !defined(OPENSSL_THREADS)
static_assert((CRYPTO_refcount_t)-1 == CRYPTO_REFCOUNT_MAX,
"CRYPTO_REFCOUNT_MAX is incorrect");
void CRYPTO_refcount_inc(CRYPTO_refcount_t *count) {
if (*count < CRYPTO_REFCOUNT_MAX) {
(*count)++;
}
}
int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *count) {
if (*count == 0) {
abort();
}
if (*count < CRYPTO_REFCOUNT_MAX) {
(*count)--;
}
return *count == 0;
}
#endif // !OPENSSL_THREADS
-89
View File
@@ -1,89 +0,0 @@
/* Copyright (c) 2023, Google Inc.
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* copyright notice and this permission notice appear in all copies.
*
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
#include "internal.h"
#if defined(OPENSSL_WINDOWS_ATOMIC)
#include <windows.h>
// See comment above the typedef of CRYPTO_refcount_t about these tests.
static_assert(alignof(CRYPTO_refcount_t) == alignof(LONG),
"CRYPTO_refcount_t does not match LONG alignment");
static_assert(sizeof(CRYPTO_refcount_t) == sizeof(LONG),
"CRYPTO_refcount_t does not match LONG size");
static_assert((CRYPTO_refcount_t)-1 == CRYPTO_REFCOUNT_MAX,
"CRYPTO_REFCOUNT_MAX is incorrect");
static uint32_t atomic_load_u32(volatile LONG *ptr) {
// This is not ideal because it still writes to a cacheline. MSVC is not able
// to optimize this to a true atomic read, and Windows does not provide an
// InterlockedLoad function.
//
// The Windows documentation [1] does say "Simple reads and writes to
// properly-aligned 32-bit variables are atomic operations", but this is not
// phrased in terms of the C11 and C++11 memory models, and indeed a read or
// write seems to produce slightly different code on MSVC than a sequentially
// consistent std::atomic::load in C++. Moreover, it is unclear if non-MSVC
// compilers on Windows provide the same guarantees. Thus we avoid relying on
// this and instead still use an interlocked function. This is still
// preferable a global mutex, and eventually this code will be replaced by
// [2]. Additionally, on clang-cl, we'll use the |OPENSSL_C11_ATOMIC| path.
//
// [1] https://learn.microsoft.com/en-us/windows/win32/sync/interlocked-variable-access
// [2] https://devblogs.microsoft.com/cppblog/c11-atomics-in-visual-studio-2022-version-17-5-preview-2/
return (uint32_t)InterlockedCompareExchange(ptr, 0, 0);
}
static int atomic_compare_exchange_u32(volatile LONG *ptr, uint32_t *expected32,
uint32_t desired) {
LONG expected = (LONG)*expected32;
LONG actual = InterlockedCompareExchange(ptr, (LONG)desired, expected);
*expected32 = (uint32_t)actual;
return actual == expected;
}
void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
volatile LONG *count = (volatile LONG *)in_count;
uint32_t expected = atomic_load_u32(count);
while (expected != CRYPTO_REFCOUNT_MAX) {
const uint32_t new_value = expected + 1;
if (atomic_compare_exchange_u32(count, &expected, new_value)) {
break;
}
}
}
int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
volatile LONG *count = (volatile LONG *)in_count;
uint32_t expected = atomic_load_u32(count);
for (;;) {
if (expected == 0) {
abort();
} else if (expected == CRYPTO_REFCOUNT_MAX) {
return 0;
} else {
const uint32_t new_value = expected - 1;
if (atomic_compare_exchange_u32(count, &expected, new_value)) {
return new_value == 0;
}
}
}
}
#endif // OPENSSL_WINDOWS_ATOMIC
+1 -1
View File
@@ -100,7 +100,7 @@ typedef union crypto_mutex_st {
// _Atomic qualifier. However, this header is included by C++ programs as well
// as C code that might not set -std=c11. So, in practice, it's not possible to
// do that. Instead we statically assert that the size and native alignment of
// a plain uint32_t and an _Atomic uint32_t are equal in refcount_c11.c.
// a plain uint32_t and an _Atomic uint32_t are equal in refcount.c.
typedef uint32_t CRYPTO_refcount_t;
+75
View File
@@ -5839,6 +5839,81 @@ TEST_P(SSLVersionTest, SessionPropertiesThreads) {
thread.join();
}
}
static void SetValueOnFree(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
int index, long argl, void *argp) {
if (ptr != nullptr) {
*static_cast<long *>(ptr) = argl;
}
}
// Test that one thread can register ex_data while another thread is destroying
// an object that uses it.
TEST(SSLTest, ExDataThreads) {
static bool already_run = false;
if (already_run) {
GTEST_SKIP() << "This test consumes process-global resources and can only "
"be run once in a process. It is not compatible with "
"--gtest_repeat.";
}
already_run = true;
bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
ASSERT_TRUE(ctx);
// Register an initial index, so the threads can exercise having any ex_data.
int first_index =
SSL_get_ex_new_index(-1, nullptr, nullptr, nullptr, SetValueOnFree);
ASSERT_GE(first_index, 0);
// Callers may register indices concurrently with using other indices. This
// may happen if one part of an application is initializing while another part
// is already running.
static constexpr int kNumIndices = 3;
static constexpr int kNumSSLs = 10;
int index[kNumIndices];
long values[kNumSSLs];
std::fill(std::begin(values), std::end(values), -2);
std::vector<std::thread> threads;
for (size_t i = 0; i < kNumIndices; i++) {
threads.emplace_back([&, i] {
index[i] = SSL_get_ex_new_index(static_cast<long>(i), nullptr, nullptr,
nullptr, SetValueOnFree);
ASSERT_GE(index[i], 0);
});
}
for (size_t i = 0; i < kNumSSLs; i++) {
threads.emplace_back([&, i] {
bssl::UniquePtr<SSL> ssl(SSL_new(ctx.get()));
ASSERT_TRUE(ssl);
ASSERT_TRUE(SSL_set_ex_data(ssl.get(), first_index, &values[i]));
});
}
for (auto &thread : threads) {
thread.join();
}
// Each of the SSL threads should have set their flag via ex_data.
for (size_t i = 0; i < kNumSSLs; i++) {
EXPECT_EQ(values[i], -1);
}
// Each of the newly-registered indices should be distinct and work correctly.
static_assert(kNumIndices <= kNumSSLs, "values buffer too small");
std::fill(std::begin(values), std::end(values), -2);
bssl::UniquePtr<SSL> ssl(SSL_new(ctx.get()));
ASSERT_TRUE(ssl);
for (size_t i = 0; i < kNumIndices; i++) {
for (size_t j = 0; j < i; j++) {
EXPECT_NE(index[i], index[j]);
}
ASSERT_TRUE(SSL_set_ex_data(ssl.get(), index[i], &values[i]));
}
ssl = nullptr;
for (size_t i = 0; i < kNumIndices; i++) {
EXPECT_EQ(values[i], static_cast<long>(i));
}
}
#endif // OPENSSL_THREADS
constexpr size_t kNumQUICLevels = 4;