1e1051a39Sopenharmony_ci/* 2e1051a39Sopenharmony_ci * Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved. 3e1051a39Sopenharmony_ci * 4e1051a39Sopenharmony_ci * Licensed under the Apache License 2.0 (the "License"). You may not use 5e1051a39Sopenharmony_ci * this file except in compliance with the License. You can obtain a copy 6e1051a39Sopenharmony_ci * in the file LICENSE in the source distribution or at 7e1051a39Sopenharmony_ci * https://www.openssl.org/source/license.html 8e1051a39Sopenharmony_ci */ 9e1051a39Sopenharmony_ci 10e1051a39Sopenharmony_ci#include <string.h> 11e1051a39Sopenharmony_ci#include <openssl/pem.h> /* PEM_def_callback() */ 12e1051a39Sopenharmony_ci#include "internal/thread_once.h" 13e1051a39Sopenharmony_ci#include "ui_local.h" 14e1051a39Sopenharmony_ci 15e1051a39Sopenharmony_ci#ifndef BUFSIZ 16e1051a39Sopenharmony_ci#define BUFSIZ 256 17e1051a39Sopenharmony_ci#endif 18e1051a39Sopenharmony_ci 19e1051a39Sopenharmony_ciint UI_UTIL_read_pw_string(char *buf, int length, const char *prompt, 20e1051a39Sopenharmony_ci int verify) 21e1051a39Sopenharmony_ci{ 22e1051a39Sopenharmony_ci char buff[BUFSIZ]; 23e1051a39Sopenharmony_ci int ret; 24e1051a39Sopenharmony_ci 25e1051a39Sopenharmony_ci ret = 26e1051a39Sopenharmony_ci UI_UTIL_read_pw(buf, buff, (length > BUFSIZ) ? BUFSIZ : length, 27e1051a39Sopenharmony_ci prompt, verify); 28e1051a39Sopenharmony_ci OPENSSL_cleanse(buff, BUFSIZ); 29e1051a39Sopenharmony_ci return ret; 30e1051a39Sopenharmony_ci} 31e1051a39Sopenharmony_ci 32e1051a39Sopenharmony_ciint UI_UTIL_read_pw(char *buf, char *buff, int size, const char *prompt, 33e1051a39Sopenharmony_ci int verify) 34e1051a39Sopenharmony_ci{ 35e1051a39Sopenharmony_ci int ok = -2; 36e1051a39Sopenharmony_ci UI *ui; 37e1051a39Sopenharmony_ci 38e1051a39Sopenharmony_ci if (size < 1) 39e1051a39Sopenharmony_ci return -1; 40e1051a39Sopenharmony_ci 41e1051a39Sopenharmony_ci ui = UI_new(); 42e1051a39Sopenharmony_ci if (ui != NULL) { 43e1051a39Sopenharmony_ci ok = UI_add_input_string(ui, prompt, 0, buf, 0, size - 1); 44e1051a39Sopenharmony_ci if (ok >= 0 && verify) 45e1051a39Sopenharmony_ci ok = UI_add_verify_string(ui, prompt, 0, buff, 0, size - 1, buf); 46e1051a39Sopenharmony_ci if (ok >= 0) 47e1051a39Sopenharmony_ci ok = UI_process(ui); 48e1051a39Sopenharmony_ci UI_free(ui); 49e1051a39Sopenharmony_ci } 50e1051a39Sopenharmony_ci return ok; 51e1051a39Sopenharmony_ci} 52e1051a39Sopenharmony_ci 53e1051a39Sopenharmony_ci/* 54e1051a39Sopenharmony_ci * Wrapper around pem_password_cb, a method to help older APIs use newer 55e1051a39Sopenharmony_ci * ones. 56e1051a39Sopenharmony_ci */ 57e1051a39Sopenharmony_cistruct pem_password_cb_data { 58e1051a39Sopenharmony_ci pem_password_cb *cb; 59e1051a39Sopenharmony_ci int rwflag; 60e1051a39Sopenharmony_ci}; 61e1051a39Sopenharmony_ci 62e1051a39Sopenharmony_cistatic void ui_new_method_data(void *parent, void *ptr, CRYPTO_EX_DATA *ad, 63e1051a39Sopenharmony_ci int idx, long argl, void *argp) 64e1051a39Sopenharmony_ci{ 65e1051a39Sopenharmony_ci /* 66e1051a39Sopenharmony_ci * Do nothing, the data is allocated externally and assigned later with 67e1051a39Sopenharmony_ci * CRYPTO_set_ex_data() 68e1051a39Sopenharmony_ci */ 69e1051a39Sopenharmony_ci} 70e1051a39Sopenharmony_ci 71e1051a39Sopenharmony_cistatic int ui_dup_method_data(CRYPTO_EX_DATA *to, const CRYPTO_EX_DATA *from, 72e1051a39Sopenharmony_ci void **pptr, int idx, long argl, void *argp) 73e1051a39Sopenharmony_ci{ 74e1051a39Sopenharmony_ci if (*pptr != NULL) { 75e1051a39Sopenharmony_ci *pptr = OPENSSL_memdup(*pptr, sizeof(struct pem_password_cb_data)); 76e1051a39Sopenharmony_ci if (*pptr != NULL) 77e1051a39Sopenharmony_ci return 1; 78e1051a39Sopenharmony_ci } 79e1051a39Sopenharmony_ci return 0; 80e1051a39Sopenharmony_ci} 81e1051a39Sopenharmony_ci 82e1051a39Sopenharmony_cistatic void ui_free_method_data(void *parent, void *ptr, CRYPTO_EX_DATA *ad, 83e1051a39Sopenharmony_ci int idx, long argl, void *argp) 84e1051a39Sopenharmony_ci{ 85e1051a39Sopenharmony_ci OPENSSL_free(ptr); 86e1051a39Sopenharmony_ci} 87e1051a39Sopenharmony_ci 88e1051a39Sopenharmony_cistatic CRYPTO_ONCE get_index_once = CRYPTO_ONCE_STATIC_INIT; 89e1051a39Sopenharmony_cistatic int ui_method_data_index = -1; 90e1051a39Sopenharmony_ciDEFINE_RUN_ONCE_STATIC(ui_method_data_index_init) 91e1051a39Sopenharmony_ci{ 92e1051a39Sopenharmony_ci ui_method_data_index = CRYPTO_get_ex_new_index(CRYPTO_EX_INDEX_UI_METHOD, 93e1051a39Sopenharmony_ci 0, NULL, ui_new_method_data, 94e1051a39Sopenharmony_ci ui_dup_method_data, 95e1051a39Sopenharmony_ci ui_free_method_data); 96e1051a39Sopenharmony_ci return 1; 97e1051a39Sopenharmony_ci} 98e1051a39Sopenharmony_ci 99e1051a39Sopenharmony_cistatic int ui_open(UI *ui) 100e1051a39Sopenharmony_ci{ 101e1051a39Sopenharmony_ci return 1; 102e1051a39Sopenharmony_ci} 103e1051a39Sopenharmony_cistatic int ui_read(UI *ui, UI_STRING *uis) 104e1051a39Sopenharmony_ci{ 105e1051a39Sopenharmony_ci switch (UI_get_string_type(uis)) { 106e1051a39Sopenharmony_ci case UIT_PROMPT: 107e1051a39Sopenharmony_ci { 108e1051a39Sopenharmony_ci int len; 109e1051a39Sopenharmony_ci char result[PEM_BUFSIZE + 1]; /* reserve one byte at the end */ 110e1051a39Sopenharmony_ci const struct pem_password_cb_data *data = 111e1051a39Sopenharmony_ci UI_method_get_ex_data(UI_get_method(ui), ui_method_data_index); 112e1051a39Sopenharmony_ci int maxsize = UI_get_result_maxsize(uis); 113e1051a39Sopenharmony_ci 114e1051a39Sopenharmony_ci if (maxsize > PEM_BUFSIZE) 115e1051a39Sopenharmony_ci maxsize = PEM_BUFSIZE; 116e1051a39Sopenharmony_ci len = data->cb(result, maxsize, data->rwflag, 117e1051a39Sopenharmony_ci UI_get0_user_data(ui)); 118e1051a39Sopenharmony_ci if (len > maxsize) 119e1051a39Sopenharmony_ci return -1; 120e1051a39Sopenharmony_ci if (len >= 0) 121e1051a39Sopenharmony_ci result[len] = '\0'; 122e1051a39Sopenharmony_ci if (len < 0) 123e1051a39Sopenharmony_ci return len; 124e1051a39Sopenharmony_ci if (UI_set_result_ex(ui, uis, result, len) >= 0) 125e1051a39Sopenharmony_ci return 1; 126e1051a39Sopenharmony_ci return 0; 127e1051a39Sopenharmony_ci } 128e1051a39Sopenharmony_ci case UIT_VERIFY: 129e1051a39Sopenharmony_ci case UIT_NONE: 130e1051a39Sopenharmony_ci case UIT_BOOLEAN: 131e1051a39Sopenharmony_ci case UIT_INFO: 132e1051a39Sopenharmony_ci case UIT_ERROR: 133e1051a39Sopenharmony_ci break; 134e1051a39Sopenharmony_ci } 135e1051a39Sopenharmony_ci return 1; 136e1051a39Sopenharmony_ci} 137e1051a39Sopenharmony_cistatic int ui_write(UI *ui, UI_STRING *uis) 138e1051a39Sopenharmony_ci{ 139e1051a39Sopenharmony_ci return 1; 140e1051a39Sopenharmony_ci} 141e1051a39Sopenharmony_cistatic int ui_close(UI *ui) 142e1051a39Sopenharmony_ci{ 143e1051a39Sopenharmony_ci return 1; 144e1051a39Sopenharmony_ci} 145e1051a39Sopenharmony_ci 146e1051a39Sopenharmony_ciUI_METHOD *UI_UTIL_wrap_read_pem_callback(pem_password_cb *cb, int rwflag) 147e1051a39Sopenharmony_ci{ 148e1051a39Sopenharmony_ci struct pem_password_cb_data *data = NULL; 149e1051a39Sopenharmony_ci UI_METHOD *ui_method = NULL; 150e1051a39Sopenharmony_ci 151e1051a39Sopenharmony_ci if ((data = OPENSSL_zalloc(sizeof(*data))) == NULL 152e1051a39Sopenharmony_ci || (ui_method = UI_create_method("PEM password callback wrapper")) == NULL 153e1051a39Sopenharmony_ci || UI_method_set_opener(ui_method, ui_open) < 0 154e1051a39Sopenharmony_ci || UI_method_set_reader(ui_method, ui_read) < 0 155e1051a39Sopenharmony_ci || UI_method_set_writer(ui_method, ui_write) < 0 156e1051a39Sopenharmony_ci || UI_method_set_closer(ui_method, ui_close) < 0 157e1051a39Sopenharmony_ci || !RUN_ONCE(&get_index_once, ui_method_data_index_init) 158e1051a39Sopenharmony_ci || !UI_method_set_ex_data(ui_method, ui_method_data_index, data)) { 159e1051a39Sopenharmony_ci UI_destroy_method(ui_method); 160e1051a39Sopenharmony_ci OPENSSL_free(data); 161e1051a39Sopenharmony_ci return NULL; 162e1051a39Sopenharmony_ci } 163e1051a39Sopenharmony_ci data->rwflag = rwflag; 164e1051a39Sopenharmony_ci data->cb = cb != NULL ? cb : PEM_def_callback; 165e1051a39Sopenharmony_ci 166e1051a39Sopenharmony_ci return ui_method; 167e1051a39Sopenharmony_ci} 168