1 /*
2  * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
3  *
4  * Licensed under the Apache License 2.0 (the "License").  You may not use
5  * this file except in compliance with the License.  You can obtain a copy
6  * in the file LICENSE in the source distribution or at
7  * https://www.openssl.org/source/license.html
8  */
9 
10 #include "internal/e_os.h"
11 #include <stdio.h>
12 #include <string.h>
13 #include "internal/conf.h"
14 #include "crypto/ctype.h"
15 #include <openssl/crypto.h>
16 #include <openssl/err.h>
17 #include <openssl/conf.h>
18 #include <openssl/conf_api.h>
19 #include "conf_local.h"
20 #include <openssl/lhash.h>
21 
22 static CONF_METHOD *default_CONF_method = NULL;
23 
24 /* Init a 'CONF' structure from an old LHASH */
25 
CONF_set_nconf(CONF * conf,LHASH_OF (CONF_VALUE)* hash)26 void CONF_set_nconf(CONF *conf, LHASH_OF(CONF_VALUE) *hash)
27 {
28     if (default_CONF_method == NULL)
29         default_CONF_method = NCONF_default();
30 
31     default_CONF_method->init(conf);
32     conf->data = hash;
33 }
34 
35 /*
36  * The following section contains the "CONF classic" functions, rewritten in
37  * terms of the new CONF interface.
38  */
39 
CONF_set_default_method(CONF_METHOD * meth)40 int CONF_set_default_method(CONF_METHOD *meth)
41 {
42     default_CONF_method = meth;
43     return 1;
44 }
45 
LHASH_OF(CONF_VALUE)46 LHASH_OF(CONF_VALUE) *CONF_load(LHASH_OF(CONF_VALUE) *conf, const char *file,
47                                 long *eline)
48 {
49     LHASH_OF(CONF_VALUE) *ltmp;
50     BIO *in = NULL;
51 
52 #ifdef OPENSSL_SYS_VMS
53     in = BIO_new_file(file, "r");
54 #else
55     in = BIO_new_file(file, "rb");
56 #endif
57     if (in == NULL) {
58         ERR_raise(ERR_LIB_CONF, ERR_R_SYS_LIB);
59         return NULL;
60     }
61 
62     ltmp = CONF_load_bio(conf, in, eline);
63     BIO_free(in);
64 
65     return ltmp;
66 }
67 
68 #ifndef OPENSSL_NO_STDIO
LHASH_OF(CONF_VALUE)69 LHASH_OF(CONF_VALUE) *CONF_load_fp(LHASH_OF(CONF_VALUE) *conf, FILE *fp,
70                                    long *eline)
71 {
72     BIO *btmp;
73     LHASH_OF(CONF_VALUE) *ltmp;
74     if ((btmp = BIO_new_fp(fp, BIO_NOCLOSE)) == NULL) {
75         ERR_raise(ERR_LIB_CONF, ERR_R_BUF_LIB);
76         return NULL;
77     }
78     ltmp = CONF_load_bio(conf, btmp, eline);
79     BIO_free(btmp);
80     return ltmp;
81 }
82 #endif
83 
LHASH_OF(CONF_VALUE)84 LHASH_OF(CONF_VALUE) *CONF_load_bio(LHASH_OF(CONF_VALUE) *conf, BIO *bp,
85                                     long *eline)
86 {
87     CONF ctmp;
88     int ret;
89 
90     CONF_set_nconf(&ctmp, conf);
91 
92     ret = NCONF_load_bio(&ctmp, bp, eline);
93     if (ret)
94         return ctmp.data;
95     return NULL;
96 }
97 
STACK_OF(CONF_VALUE)98 STACK_OF(CONF_VALUE) *CONF_get_section(LHASH_OF(CONF_VALUE) *conf,
99                                        const char *section)
100 {
101     if (conf == NULL) {
102         return NULL;
103     } else {
104         CONF ctmp;
105 
106         CONF_set_nconf(&ctmp, conf);
107         return NCONF_get_section(&ctmp, section);
108     }
109 }
110 
CONF_get_string(LHASH_OF (CONF_VALUE)* conf,const char * group,const char * name)111 char *CONF_get_string(LHASH_OF(CONF_VALUE) *conf, const char *group,
112                       const char *name)
113 {
114     if (conf == NULL) {
115         return NCONF_get_string(NULL, group, name);
116     } else {
117         CONF ctmp;
118 
119         CONF_set_nconf(&ctmp, conf);
120         return NCONF_get_string(&ctmp, group, name);
121     }
122 }
123 
CONF_get_number(LHASH_OF (CONF_VALUE)* conf,const char * group,const char * name)124 long CONF_get_number(LHASH_OF(CONF_VALUE) *conf, const char *group,
125                      const char *name)
126 {
127     int status;
128     long result = 0;
129 
130     ERR_set_mark();
131     if (conf == NULL) {
132         status = NCONF_get_number_e(NULL, group, name, &result);
133     } else {
134         CONF ctmp;
135 
136         CONF_set_nconf(&ctmp, conf);
137         status = NCONF_get_number_e(&ctmp, group, name, &result);
138     }
139     ERR_pop_to_mark();
140     return status == 0 ? 0L : result;
141 }
142 
CONF_free(LHASH_OF (CONF_VALUE)* conf)143 void CONF_free(LHASH_OF(CONF_VALUE) *conf)
144 {
145     CONF ctmp;
146     CONF_set_nconf(&ctmp, conf);
147     NCONF_free_data(&ctmp);
148 }
149 
150 #ifndef OPENSSL_NO_STDIO
CONF_dump_fp(LHASH_OF (CONF_VALUE)* conf,FILE * out)151 int CONF_dump_fp(LHASH_OF(CONF_VALUE) *conf, FILE *out)
152 {
153     BIO *btmp;
154     int ret;
155 
156     if ((btmp = BIO_new_fp(out, BIO_NOCLOSE)) == NULL) {
157         ERR_raise(ERR_LIB_CONF, ERR_R_BUF_LIB);
158         return 0;
159     }
160     ret = CONF_dump_bio(conf, btmp);
161     BIO_free(btmp);
162     return ret;
163 }
164 #endif
165 
CONF_dump_bio(LHASH_OF (CONF_VALUE)* conf,BIO * out)166 int CONF_dump_bio(LHASH_OF(CONF_VALUE) *conf, BIO *out)
167 {
168     CONF ctmp;
169 
170     CONF_set_nconf(&ctmp, conf);
171     return NCONF_dump_bio(&ctmp, out);
172 }
173 
174 /*
175  * The following section contains the "New CONF" functions.  They are
176  * completely centralised around a new CONF structure that may contain
177  * basically anything, but at least a method pointer and a table of data.
178  * These functions are also written in terms of the bridge functions used by
179  * the "CONF classic" functions, for consistency.
180  */
181 
NCONF_new_ex(OSSL_LIB_CTX * libctx,CONF_METHOD * meth)182 CONF *NCONF_new_ex(OSSL_LIB_CTX *libctx, CONF_METHOD *meth)
183 {
184     CONF *ret;
185 
186     if (meth == NULL)
187         meth = NCONF_default();
188 
189     ret = meth->create(meth);
190     if (ret == NULL) {
191         ERR_raise(ERR_LIB_CONF, ERR_R_CONF_LIB);
192         return NULL;
193     }
194     ret->libctx = libctx;
195 
196     return ret;
197 }
198 
NCONF_new(CONF_METHOD * meth)199 CONF *NCONF_new(CONF_METHOD *meth)
200 {
201     return NCONF_new_ex(NULL, meth);
202 }
203 
NCONF_free(CONF * conf)204 void NCONF_free(CONF *conf)
205 {
206     if (conf == NULL)
207         return;
208     conf->meth->destroy(conf);
209 }
210 
NCONF_free_data(CONF * conf)211 void NCONF_free_data(CONF *conf)
212 {
213     if (conf == NULL)
214         return;
215     conf->meth->destroy_data(conf);
216 }
217 
NCONF_get0_libctx(const CONF * conf)218 OSSL_LIB_CTX *NCONF_get0_libctx(const CONF *conf)
219 {
220     return conf->libctx;
221 }
222 
223 typedef STACK_OF(OPENSSL_CSTRING) SECTION_NAMES;
224 
225 IMPLEMENT_LHASH_DOALL_ARG_CONST(CONF_VALUE, SECTION_NAMES);
226 
collect_section_name(const CONF_VALUE * v,SECTION_NAMES * names)227 static void collect_section_name(const CONF_VALUE *v, SECTION_NAMES *names)
228 {
229     /* A section is a CONF_VALUE with name == NULL */
230     if (v->name == NULL)
231         /* A failure to push cannot be handled so we ignore the result. */
232         (void)sk_OPENSSL_CSTRING_push(names, v->section);
233 }
234 
section_name_cmp(OPENSSL_CSTRING const * a,OPENSSL_CSTRING const * b)235 static int section_name_cmp(OPENSSL_CSTRING const *a, OPENSSL_CSTRING const *b)
236 {
237     return strcmp(*a, *b);
238 }
239 
STACK_OF(OPENSSL_CSTRING)240 STACK_OF(OPENSSL_CSTRING) *NCONF_get_section_names(const CONF *cnf)
241 {
242     SECTION_NAMES *names;
243 
244     if ((names = sk_OPENSSL_CSTRING_new(section_name_cmp)) == NULL)
245         return NULL;
246     lh_CONF_VALUE_doall_SECTION_NAMES(cnf->data, collect_section_name, names);
247     sk_OPENSSL_CSTRING_sort(names);
248     return names;
249 }
250 
NCONF_load(CONF * conf,const char * file,long * eline)251 int NCONF_load(CONF *conf, const char *file, long *eline)
252 {
253     if (conf == NULL) {
254         ERR_raise(ERR_LIB_CONF, CONF_R_NO_CONF);
255         return 0;
256     }
257 
258     return conf->meth->load(conf, file, eline);
259 }
260 
261 #ifndef OPENSSL_NO_STDIO
NCONF_load_fp(CONF * conf,FILE * fp,long * eline)262 int NCONF_load_fp(CONF *conf, FILE *fp, long *eline)
263 {
264     BIO *btmp;
265     int ret;
266     if ((btmp = BIO_new_fp(fp, BIO_NOCLOSE)) == NULL) {
267         ERR_raise(ERR_LIB_CONF, ERR_R_BUF_LIB);
268         return 0;
269     }
270     ret = NCONF_load_bio(conf, btmp, eline);
271     BIO_free(btmp);
272     return ret;
273 }
274 #endif
275 
NCONF_load_bio(CONF * conf,BIO * bp,long * eline)276 int NCONF_load_bio(CONF *conf, BIO *bp, long *eline)
277 {
278     if (conf == NULL) {
279         ERR_raise(ERR_LIB_CONF, CONF_R_NO_CONF);
280         return 0;
281     }
282 
283     return conf->meth->load_bio(conf, bp, eline);
284 }
285 
STACK_OF(CONF_VALUE)286 STACK_OF(CONF_VALUE) *NCONF_get_section(const CONF *conf, const char *section)
287 {
288     if (conf == NULL) {
289         ERR_raise(ERR_LIB_CONF, CONF_R_NO_CONF);
290         return NULL;
291     }
292 
293     if (section == NULL) {
294         ERR_raise(ERR_LIB_CONF, CONF_R_NO_SECTION);
295         return NULL;
296     }
297 
298     return _CONF_get_section_values(conf, section);
299 }
300 
NCONF_get_string(const CONF * conf,const char * group,const char * name)301 char *NCONF_get_string(const CONF *conf, const char *group, const char *name)
302 {
303     char *s = _CONF_get_string(conf, group, name);
304 
305     /*
306      * Since we may get a value from an environment variable even if conf is
307      * NULL, let's check the value first
308      */
309     if (s)
310         return s;
311 
312     if (conf == NULL) {
313         ERR_raise(ERR_LIB_CONF, CONF_R_NO_CONF_OR_ENVIRONMENT_VARIABLE);
314         return NULL;
315     }
316     ERR_raise_data(ERR_LIB_CONF, CONF_R_NO_VALUE,
317                    "group=%s name=%s", group, name);
318     return NULL;
319 }
320 
default_is_number(const CONF * conf,char c)321 static int default_is_number(const CONF *conf, char c)
322 {
323     return ossl_isdigit(c);
324 }
325 
default_to_int(const CONF * conf,char c)326 static int default_to_int(const CONF *conf, char c)
327 {
328     return (int)(c - '0');
329 }
330 
NCONF_get_number_e(const CONF * conf,const char * group,const char * name,long * result)331 int NCONF_get_number_e(const CONF *conf, const char *group, const char *name,
332                        long *result)
333 {
334     char *str;
335     long res;
336     int (*is_number)(const CONF *, char) = &default_is_number;
337     int (*to_int)(const CONF *, char) = &default_to_int;
338 
339     if (result == NULL) {
340         ERR_raise(ERR_LIB_CONF, ERR_R_PASSED_NULL_PARAMETER);
341         return 0;
342     }
343 
344     str = NCONF_get_string(conf, group, name);
345 
346     if (str == NULL)
347         return 0;
348 
349     if (conf != NULL) {
350         if (conf->meth->is_number != NULL)
351             is_number = conf->meth->is_number;
352         if (conf->meth->to_int != NULL)
353             to_int = conf->meth->to_int;
354     }
355     for (res = 0; is_number(conf, *str); str++) {
356         const int d = to_int(conf, *str);
357 
358         if (res > (LONG_MAX - d) / 10L) {
359             ERR_raise(ERR_LIB_CONF, CONF_R_NUMBER_TOO_LARGE);
360             return 0;
361         }
362         res = res * 10 + d;
363     }
364 
365     *result = res;
366     return 1;
367 }
368 
_CONF_get_number(const CONF * conf,const char * section,const char * name)369 long _CONF_get_number(const CONF *conf, const char *section,
370                       const char *name)
371 {
372     int status;
373     long result = 0;
374 
375     ERR_set_mark();
376     status = NCONF_get_number_e(conf, section, name, &result);
377     ERR_pop_to_mark();
378     return status == 0 ? 0L : result;
379 }
380 
381 #ifndef OPENSSL_NO_STDIO
NCONF_dump_fp(const CONF * conf,FILE * out)382 int NCONF_dump_fp(const CONF *conf, FILE *out)
383 {
384     BIO *btmp;
385     int ret;
386     if ((btmp = BIO_new_fp(out, BIO_NOCLOSE)) == NULL) {
387         ERR_raise(ERR_LIB_CONF, ERR_R_BUF_LIB);
388         return 0;
389     }
390     ret = NCONF_dump_bio(conf, btmp);
391     BIO_free(btmp);
392     return ret;
393 }
394 #endif
395 
NCONF_dump_bio(const CONF * conf,BIO * out)396 int NCONF_dump_bio(const CONF *conf, BIO *out)
397 {
398     if (conf == NULL) {
399         ERR_raise(ERR_LIB_CONF, CONF_R_NO_CONF);
400         return 0;
401     }
402 
403     return conf->meth->dump(conf, out);
404 }
405 
406 /*
407  * These routines call the C malloc/free, to avoid intermixing with
408  * OpenSSL function pointers before the library is initialized.
409  */
OPENSSL_INIT_new(void)410 OPENSSL_INIT_SETTINGS *OPENSSL_INIT_new(void)
411 {
412     OPENSSL_INIT_SETTINGS *ret = malloc(sizeof(*ret));
413 
414     if (ret == NULL)
415         return NULL;
416 
417     memset(ret, 0, sizeof(*ret));
418     ret->flags = DEFAULT_CONF_MFLAGS;
419 
420     return ret;
421 }
422 
423 
424 #ifndef OPENSSL_NO_STDIO
425 /*
426  * If CRYPTO_set_mem_functions is called after this, then
427  * memory allocation and deallocation in this function can
428  * become disjointed. Avoid this by always using standard
429  * strdup & free instead of OPENSSL_strdup & OPENSSL_free.
430  */
OPENSSL_INIT_set_config_filename(OPENSSL_INIT_SETTINGS * settings,const char * filename)431 int OPENSSL_INIT_set_config_filename(OPENSSL_INIT_SETTINGS *settings,
432                                      const char *filename)
433 {
434     char *newfilename = NULL;
435 
436     if (filename != NULL) {
437         newfilename = strdup(filename);
438         if (newfilename == NULL)
439             return 0;
440     }
441 
442     free(settings->filename);
443     settings->filename = newfilename;
444 
445     return 1;
446 }
447 
OPENSSL_INIT_set_config_file_flags(OPENSSL_INIT_SETTINGS * settings,unsigned long flags)448 void OPENSSL_INIT_set_config_file_flags(OPENSSL_INIT_SETTINGS *settings,
449                                         unsigned long flags)
450 {
451     settings->flags = flags;
452 }
453 
454 /*
455  * If CRYPTO_set_mem_functions is called after this, then
456  * memory allocation and deallocation in this function can
457  * become disjointed. Avoid this by always using standard
458  * strdup & free instead of OPENSSL_strdup & OPENSSL_free.
459  */
OPENSSL_INIT_set_config_appname(OPENSSL_INIT_SETTINGS * settings,const char * appname)460 int OPENSSL_INIT_set_config_appname(OPENSSL_INIT_SETTINGS *settings,
461                                     const char *appname)
462 {
463     char *newappname = NULL;
464 
465     if (appname != NULL) {
466         newappname = strdup(appname);
467         if (newappname == NULL)
468             return 0;
469     }
470 
471     free(settings->appname);
472     settings->appname = newappname;
473 
474     return 1;
475 }
476 #endif
477 
OPENSSL_INIT_free(OPENSSL_INIT_SETTINGS * settings)478 void OPENSSL_INIT_free(OPENSSL_INIT_SETTINGS *settings)
479 {
480     if (settings == NULL)
481         return;
482 
483     free(settings->filename);
484     free(settings->appname);
485     free(settings);
486 }
487