2016-05-17 18:52:22 +00:00
|
|
|
/*
|
|
|
|
* Copyright 1995-2016 The OpenSSL Project Authors. All Rights Reserved.
|
1998-12-21 11:00:56 +00:00
|
|
|
*
|
2016-05-17 18:52:22 +00:00
|
|
|
* Licensed under the OpenSSL license (the "License"). You may not use
|
|
|
|
* this file except in compliance with the License. You can obtain a copy
|
|
|
|
* in the file LICENSE in the source distribution or at
|
|
|
|
* https://www.openssl.org/source/license.html
|
1998-12-21 11:00:56 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <time.h>
|
2015-05-14 14:56:48 +00:00
|
|
|
#include "internal/cryptlib.h"
|
2016-01-05 04:00:33 +00:00
|
|
|
#include <openssl/opensslconf.h>
|
2017-07-20 14:20:47 +00:00
|
|
|
#include "internal/rand_int.h"
|
2016-03-18 18:30:20 +00:00
|
|
|
#include <openssl/engine.h>
|
2017-04-06 09:30:03 +00:00
|
|
|
#include "internal/thread_once.h"
|
2017-06-22 13:21:43 +00:00
|
|
|
#include "rand_lcl.h"
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2003-01-30 17:39:26 +00:00
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
2001-09-25 20:23:40 +00:00
|
|
|
/* non-NULL if default_RAND_meth is ENGINE-provided */
|
2017-06-22 13:21:43 +00:00
|
|
|
static ENGINE *funct_ref;
|
|
|
|
static CRYPTO_RWLOCK *rand_engine_lock;
|
2003-01-30 17:39:26 +00:00
|
|
|
#endif
|
2017-06-22 13:21:43 +00:00
|
|
|
static CRYPTO_RWLOCK *rand_meth_lock;
|
|
|
|
static const RAND_METHOD *default_RAND_meth;
|
|
|
|
static CRYPTO_ONCE rand_init = CRYPTO_ONCE_STATIC_INIT;
|
2017-04-06 09:30:03 +00:00
|
|
|
|
2017-07-18 13:39:21 +00:00
|
|
|
#ifdef OPENSSL_RAND_SEED_RDTSC
|
|
|
|
/*
|
|
|
|
* IMPORTANT NOTE: It is not currently possible to use this code
|
|
|
|
* because we are not sure about the amount of randomness. Some
|
|
|
|
* SP900 tests have been run, but there is internal skepticism.
|
|
|
|
* So for now this code is not used.
|
|
|
|
*/
|
|
|
|
# error "RDTSC enabled? Should not be possible!"
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Since we get some randomness from the low-order bits of the
|
|
|
|
* high-speec clock, it can help. But don't return a status since
|
|
|
|
* it's not sufficient to indicate whether or not the seeding was
|
|
|
|
* done.
|
|
|
|
*/
|
|
|
|
void rand_rdtsc(void)
|
|
|
|
{
|
|
|
|
unsigned char c;
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 0; i < 10; i++) {
|
|
|
|
c = (unsigned char)(OPENSSL_rdtsc() & 0xFF);
|
|
|
|
RAND_add(&c, 1, 0.5);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifdef OPENSSL_RAND_SEED_RDCPU
|
|
|
|
size_t OPENSSL_ia32_rdseed(void);
|
|
|
|
size_t OPENSSL_ia32_rdrand(void);
|
|
|
|
|
|
|
|
extern unsigned int OPENSSL_ia32cap_P[];
|
|
|
|
|
|
|
|
int rand_rdcpu(void)
|
|
|
|
{
|
|
|
|
size_t i, s;
|
|
|
|
|
|
|
|
/* If RDSEED is available, use that. */
|
|
|
|
if ((OPENSSL_ia32cap_P[1] & (1 << 18)) != 0) {
|
|
|
|
for (i = 0; i < RANDOMNESS_NEEDED; i += sizeof(s)) {
|
|
|
|
s = OPENSSL_ia32_rdseed();
|
|
|
|
if (s == 0)
|
|
|
|
break;
|
|
|
|
RAND_add(&s, (int)sizeof(s), sizeof(s));
|
|
|
|
}
|
|
|
|
if (i >= RANDOMNESS_NEEDED)
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Second choice is RDRAND. */
|
|
|
|
if ((OPENSSL_ia32cap_P[1] & (1 << (62 - 32))) != 0) {
|
|
|
|
for (i = 0; i < RANDOMNESS_NEEDED; i += sizeof(s)) {
|
|
|
|
s = OPENSSL_ia32_rdrand();
|
|
|
|
if (s == 0)
|
|
|
|
break;
|
|
|
|
RAND_add(&s, (int)sizeof(s), sizeof(s));
|
|
|
|
}
|
|
|
|
if (i >= RANDOMNESS_NEEDED)
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
#endif
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
DEFINE_RUN_ONCE_STATIC(do_rand_init)
|
2017-04-06 09:30:03 +00:00
|
|
|
{
|
2017-04-07 14:26:10 +00:00
|
|
|
int ret = 1;
|
2017-04-06 09:30:03 +00:00
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
|
|
|
rand_engine_lock = CRYPTO_THREAD_lock_new();
|
2017-04-07 14:26:10 +00:00
|
|
|
ret &= rand_engine_lock != NULL;
|
2017-04-06 09:30:03 +00:00
|
|
|
#endif
|
|
|
|
rand_meth_lock = CRYPTO_THREAD_lock_new();
|
2017-04-07 14:26:10 +00:00
|
|
|
ret &= rand_meth_lock != NULL;
|
|
|
|
return ret;
|
2017-04-06 09:30:03 +00:00
|
|
|
}
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2017-06-22 13:21:43 +00:00
|
|
|
void rand_cleanup_int(void)
|
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = default_RAND_meth;
|
|
|
|
|
|
|
|
if (meth != NULL && meth->cleanup != NULL)
|
|
|
|
meth->cleanup();
|
|
|
|
RAND_set_rand_method(NULL);
|
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
|
|
|
CRYPTO_THREAD_lock_free(rand_engine_lock);
|
|
|
|
#endif
|
|
|
|
CRYPTO_THREAD_lock_free(rand_meth_lock);
|
2017-06-27 16:04:37 +00:00
|
|
|
rand_drbg_cleanup();
|
2017-06-22 13:21:43 +00:00
|
|
|
}
|
|
|
|
|
2001-09-25 20:23:40 +00:00
|
|
|
int RAND_set_rand_method(const RAND_METHOD *meth)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
2017-06-22 13:21:43 +00:00
|
|
|
if (!RUN_ONCE(&rand_init, do_rand_init))
|
2017-04-06 09:30:03 +00:00
|
|
|
return 0;
|
|
|
|
|
|
|
|
CRYPTO_THREAD_write_lock(rand_meth_lock);
|
2003-01-30 17:39:26 +00:00
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
2016-02-25 17:09:06 +00:00
|
|
|
ENGINE_finish(funct_ref);
|
|
|
|
funct_ref = NULL;
|
2003-01-30 17:39:26 +00:00
|
|
|
#endif
|
2015-01-22 03:40:55 +00:00
|
|
|
default_RAND_meth = meth;
|
2017-04-06 09:30:03 +00:00
|
|
|
CRYPTO_THREAD_unlock(rand_meth_lock);
|
2015-01-22 03:40:55 +00:00
|
|
|
return 1;
|
|
|
|
}
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2001-04-18 04:18:16 +00:00
|
|
|
const RAND_METHOD *RAND_get_rand_method(void)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
2017-04-06 09:30:03 +00:00
|
|
|
const RAND_METHOD *tmp_meth = NULL;
|
|
|
|
|
2017-06-22 13:21:43 +00:00
|
|
|
if (!RUN_ONCE(&rand_init, do_rand_init))
|
2017-04-06 09:30:03 +00:00
|
|
|
return NULL;
|
|
|
|
|
|
|
|
CRYPTO_THREAD_write_lock(rand_meth_lock);
|
2017-06-22 13:21:43 +00:00
|
|
|
if (default_RAND_meth == NULL) {
|
2003-01-30 17:39:26 +00:00
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
2017-06-22 13:21:43 +00:00
|
|
|
ENGINE *e;
|
|
|
|
|
|
|
|
/* If we have an engine that can do RAND, use it. */
|
|
|
|
if ((e = ENGINE_get_default_RAND()) != NULL
|
|
|
|
&& (tmp_meth = ENGINE_get_RAND(e)) != NULL) {
|
2015-01-22 03:40:55 +00:00
|
|
|
funct_ref = e;
|
2017-06-22 13:21:43 +00:00
|
|
|
default_RAND_meth = tmp_meth;
|
|
|
|
} else {
|
|
|
|
ENGINE_finish(e);
|
|
|
|
default_RAND_meth = &openssl_rand_meth;
|
|
|
|
}
|
|
|
|
#else
|
|
|
|
default_RAND_meth = &openssl_rand_meth;
|
2003-01-30 17:39:26 +00:00
|
|
|
#endif
|
2015-01-22 03:40:55 +00:00
|
|
|
}
|
2017-04-06 09:30:03 +00:00
|
|
|
tmp_meth = default_RAND_meth;
|
|
|
|
CRYPTO_THREAD_unlock(rand_meth_lock);
|
|
|
|
return tmp_meth;
|
2015-01-22 03:40:55 +00:00
|
|
|
}
|
2001-09-25 20:23:40 +00:00
|
|
|
|
2003-01-30 17:39:26 +00:00
|
|
|
#ifndef OPENSSL_NO_ENGINE
|
2001-09-25 20:23:40 +00:00
|
|
|
int RAND_set_rand_engine(ENGINE *engine)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *tmp_meth = NULL;
|
2017-04-06 09:30:03 +00:00
|
|
|
|
2017-06-22 13:21:43 +00:00
|
|
|
if (!RUN_ONCE(&rand_init, do_rand_init))
|
2017-04-06 09:30:03 +00:00
|
|
|
return 0;
|
|
|
|
|
2017-06-22 13:21:43 +00:00
|
|
|
if (engine != NULL) {
|
2015-01-22 03:40:55 +00:00
|
|
|
if (!ENGINE_init(engine))
|
|
|
|
return 0;
|
|
|
|
tmp_meth = ENGINE_get_RAND(engine);
|
2016-02-25 17:09:06 +00:00
|
|
|
if (tmp_meth == NULL) {
|
2015-01-22 03:40:55 +00:00
|
|
|
ENGINE_finish(engine);
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
2017-04-06 09:30:03 +00:00
|
|
|
CRYPTO_THREAD_write_lock(rand_engine_lock);
|
2015-01-22 03:40:55 +00:00
|
|
|
/* This function releases any prior ENGINE so call it first */
|
|
|
|
RAND_set_rand_method(tmp_meth);
|
|
|
|
funct_ref = engine;
|
2017-04-06 09:30:03 +00:00
|
|
|
CRYPTO_THREAD_unlock(rand_engine_lock);
|
2015-01-22 03:40:55 +00:00
|
|
|
return 1;
|
|
|
|
}
|
2003-01-30 17:39:26 +00:00
|
|
|
#endif
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2008-11-12 03:58:08 +00:00
|
|
|
void RAND_seed(const void *buf, int num)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = RAND_get_rand_method();
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
if (meth->seed != NULL)
|
2015-01-22 03:40:55 +00:00
|
|
|
meth->seed(buf, num);
|
|
|
|
}
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2017-06-22 13:21:43 +00:00
|
|
|
void RAND_add(const void *buf, int num, double randomness)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = RAND_get_rand_method();
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
if (meth->add != NULL)
|
|
|
|
meth->add(buf, num, randomness);
|
2015-01-22 03:40:55 +00:00
|
|
|
}
|
2000-01-13 20:59:17 +00:00
|
|
|
|
2008-11-12 03:58:08 +00:00
|
|
|
int RAND_bytes(unsigned char *buf, int num)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = RAND_get_rand_method();
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
if (meth->bytes != NULL)
|
2015-01-22 03:40:55 +00:00
|
|
|
return meth->bytes(buf, num);
|
2017-06-19 16:58:06 +00:00
|
|
|
RANDerr(RAND_F_RAND_BYTES, RAND_R_FUNC_NOT_IMPLEMENTED);
|
2017-06-22 13:21:43 +00:00
|
|
|
return -1;
|
2015-01-22 03:40:55 +00:00
|
|
|
}
|
1998-12-21 11:00:56 +00:00
|
|
|
|
2016-01-05 04:00:33 +00:00
|
|
|
#if OPENSSL_API_COMPAT < 0x10100000L
|
2008-11-12 03:58:08 +00:00
|
|
|
int RAND_pseudo_bytes(unsigned char *buf, int num)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = RAND_get_rand_method();
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
if (meth->pseudorand != NULL)
|
2015-01-22 03:40:55 +00:00
|
|
|
return meth->pseudorand(buf, num);
|
2017-06-22 13:21:43 +00:00
|
|
|
return -1;
|
2015-01-22 03:40:55 +00:00
|
|
|
}
|
2015-02-26 13:52:30 +00:00
|
|
|
#endif
|
2000-03-02 14:34:58 +00:00
|
|
|
|
|
|
|
int RAND_status(void)
|
2015-01-22 03:40:55 +00:00
|
|
|
{
|
|
|
|
const RAND_METHOD *meth = RAND_get_rand_method();
|
2017-06-22 13:21:43 +00:00
|
|
|
|
|
|
|
if (meth->status != NULL)
|
2015-01-22 03:40:55 +00:00
|
|
|
return meth->status();
|
|
|
|
return 0;
|
|
|
|
}
|