1 | /*
|
---|
2 | * Copyright 1995-2019 The OpenSSL Project Authors. All Rights Reserved.
|
---|
3 | *
|
---|
4 | * Licensed under the OpenSSL license (the "License"). You may not use
|
---|
5 | * this file except in compliance with the License. You can obtain a copy
|
---|
6 | * in the file LICENSE in the source distribution or at
|
---|
7 | * https://www.openssl.org/source/license.html
|
---|
8 | */
|
---|
9 |
|
---|
10 | /* Part of the code in here was originally in conf.c, which is now removed */
|
---|
11 |
|
---|
12 | #include <stdio.h>
|
---|
13 | #include <string.h>
|
---|
14 | #include "internal/cryptlib.h"
|
---|
15 | #include "internal/o_dir.h"
|
---|
16 | #include <openssl/lhash.h>
|
---|
17 | #include <openssl/conf.h>
|
---|
18 | #include <openssl/conf_api.h>
|
---|
19 | #include "conf_def.h"
|
---|
20 | #include <openssl/buffer.h>
|
---|
21 | #include <openssl/err.h>
|
---|
22 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
23 | # include <sys/stat.h>
|
---|
24 | # ifdef _WIN32
|
---|
25 | # define stat _stat
|
---|
26 | # define strcasecmp _stricmp
|
---|
27 | # endif
|
---|
28 | #endif
|
---|
29 |
|
---|
30 | #ifndef S_ISDIR
|
---|
31 | # define S_ISDIR(a) (((a) & S_IFMT) == S_IFDIR)
|
---|
32 | #endif
|
---|
33 |
|
---|
34 | /*
|
---|
35 | * The maximum length we can grow a value to after variable expansion. 64k
|
---|
36 | * should be more than enough for all reasonable uses.
|
---|
37 | */
|
---|
38 | #define MAX_CONF_VALUE_LENGTH 65536
|
---|
39 |
|
---|
40 | static int is_keytype(const CONF *conf, char c, unsigned short type);
|
---|
41 | static char *eat_ws(CONF *conf, char *p);
|
---|
42 | static void trim_ws(CONF *conf, char *start);
|
---|
43 | static char *eat_alpha_numeric(CONF *conf, char *p);
|
---|
44 | static void clear_comments(CONF *conf, char *p);
|
---|
45 | static int str_copy(CONF *conf, char *section, char **to, char *from);
|
---|
46 | static char *scan_quote(CONF *conf, char *p);
|
---|
47 | static char *scan_dquote(CONF *conf, char *p);
|
---|
48 | #define scan_esc(conf,p) (((IS_EOF((conf),(p)[1]))?((p)+1):((p)+2)))
|
---|
49 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
50 | static BIO *process_include(char *include, OPENSSL_DIR_CTX **dirctx,
|
---|
51 | char **dirpath);
|
---|
52 | static BIO *get_next_file(const char *path, OPENSSL_DIR_CTX **dirctx);
|
---|
53 | #endif
|
---|
54 |
|
---|
55 | static CONF *def_create(CONF_METHOD *meth);
|
---|
56 | static int def_init_default(CONF *conf);
|
---|
57 | static int def_init_WIN32(CONF *conf);
|
---|
58 | static int def_destroy(CONF *conf);
|
---|
59 | static int def_destroy_data(CONF *conf);
|
---|
60 | static int def_load(CONF *conf, const char *name, long *eline);
|
---|
61 | static int def_load_bio(CONF *conf, BIO *bp, long *eline);
|
---|
62 | static int def_dump(const CONF *conf, BIO *bp);
|
---|
63 | static int def_is_number(const CONF *conf, char c);
|
---|
64 | static int def_to_int(const CONF *conf, char c);
|
---|
65 |
|
---|
66 | static CONF_METHOD default_method = {
|
---|
67 | "OpenSSL default",
|
---|
68 | def_create,
|
---|
69 | def_init_default,
|
---|
70 | def_destroy,
|
---|
71 | def_destroy_data,
|
---|
72 | def_load_bio,
|
---|
73 | def_dump,
|
---|
74 | def_is_number,
|
---|
75 | def_to_int,
|
---|
76 | def_load
|
---|
77 | };
|
---|
78 |
|
---|
79 | static CONF_METHOD WIN32_method = {
|
---|
80 | "WIN32",
|
---|
81 | def_create,
|
---|
82 | def_init_WIN32,
|
---|
83 | def_destroy,
|
---|
84 | def_destroy_data,
|
---|
85 | def_load_bio,
|
---|
86 | def_dump,
|
---|
87 | def_is_number,
|
---|
88 | def_to_int,
|
---|
89 | def_load
|
---|
90 | };
|
---|
91 |
|
---|
92 | CONF_METHOD *NCONF_default(void)
|
---|
93 | {
|
---|
94 | return &default_method;
|
---|
95 | }
|
---|
96 |
|
---|
97 | CONF_METHOD *NCONF_WIN32(void)
|
---|
98 | {
|
---|
99 | return &WIN32_method;
|
---|
100 | }
|
---|
101 |
|
---|
102 | static CONF *def_create(CONF_METHOD *meth)
|
---|
103 | {
|
---|
104 | CONF *ret;
|
---|
105 |
|
---|
106 | ret = OPENSSL_malloc(sizeof(*ret));
|
---|
107 | if (ret != NULL)
|
---|
108 | if (meth->init(ret) == 0) {
|
---|
109 | OPENSSL_free(ret);
|
---|
110 | ret = NULL;
|
---|
111 | }
|
---|
112 | return ret;
|
---|
113 | }
|
---|
114 |
|
---|
115 | static int def_init_default(CONF *conf)
|
---|
116 | {
|
---|
117 | if (conf == NULL)
|
---|
118 | return 0;
|
---|
119 |
|
---|
120 | conf->meth = &default_method;
|
---|
121 | conf->meth_data = (void *)CONF_type_default;
|
---|
122 | conf->data = NULL;
|
---|
123 |
|
---|
124 | return 1;
|
---|
125 | }
|
---|
126 |
|
---|
127 | static int def_init_WIN32(CONF *conf)
|
---|
128 | {
|
---|
129 | if (conf == NULL)
|
---|
130 | return 0;
|
---|
131 |
|
---|
132 | conf->meth = &WIN32_method;
|
---|
133 | conf->meth_data = (void *)CONF_type_win32;
|
---|
134 | conf->data = NULL;
|
---|
135 |
|
---|
136 | return 1;
|
---|
137 | }
|
---|
138 |
|
---|
139 | static int def_destroy(CONF *conf)
|
---|
140 | {
|
---|
141 | if (def_destroy_data(conf)) {
|
---|
142 | OPENSSL_free(conf);
|
---|
143 | return 1;
|
---|
144 | }
|
---|
145 | return 0;
|
---|
146 | }
|
---|
147 |
|
---|
148 | static int def_destroy_data(CONF *conf)
|
---|
149 | {
|
---|
150 | if (conf == NULL)
|
---|
151 | return 0;
|
---|
152 | _CONF_free_data(conf);
|
---|
153 | return 1;
|
---|
154 | }
|
---|
155 |
|
---|
156 | static int def_load(CONF *conf, const char *name, long *line)
|
---|
157 | {
|
---|
158 | int ret;
|
---|
159 | BIO *in = NULL;
|
---|
160 |
|
---|
161 | #ifdef OPENSSL_SYS_VMS
|
---|
162 | in = BIO_new_file(name, "r");
|
---|
163 | #else
|
---|
164 | in = BIO_new_file(name, "rb");
|
---|
165 | #endif
|
---|
166 | if (in == NULL) {
|
---|
167 | if (ERR_GET_REASON(ERR_peek_last_error()) == BIO_R_NO_SUCH_FILE)
|
---|
168 | CONFerr(CONF_F_DEF_LOAD, CONF_R_NO_SUCH_FILE);
|
---|
169 | else
|
---|
170 | CONFerr(CONF_F_DEF_LOAD, ERR_R_SYS_LIB);
|
---|
171 | return 0;
|
---|
172 | }
|
---|
173 |
|
---|
174 | ret = def_load_bio(conf, in, line);
|
---|
175 | BIO_free(in);
|
---|
176 |
|
---|
177 | return ret;
|
---|
178 | }
|
---|
179 |
|
---|
180 | static int def_load_bio(CONF *conf, BIO *in, long *line)
|
---|
181 | {
|
---|
182 | /* The macro BUFSIZE conflicts with a system macro in VxWorks */
|
---|
183 | #define CONFBUFSIZE 512
|
---|
184 | int bufnum = 0, i, ii;
|
---|
185 | BUF_MEM *buff = NULL;
|
---|
186 | char *s, *p, *end;
|
---|
187 | int again;
|
---|
188 | long eline = 0;
|
---|
189 | char btmp[DECIMAL_SIZE(eline) + 1];
|
---|
190 | CONF_VALUE *v = NULL, *tv;
|
---|
191 | CONF_VALUE *sv = NULL;
|
---|
192 | char *section = NULL, *buf;
|
---|
193 | char *start, *psection, *pname;
|
---|
194 | void *h = (void *)(conf->data);
|
---|
195 | STACK_OF(BIO) *biosk = NULL;
|
---|
196 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
197 | char *dirpath = NULL;
|
---|
198 | OPENSSL_DIR_CTX *dirctx = NULL;
|
---|
199 | #endif
|
---|
200 |
|
---|
201 | if ((buff = BUF_MEM_new()) == NULL) {
|
---|
202 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_BUF_LIB);
|
---|
203 | goto err;
|
---|
204 | }
|
---|
205 |
|
---|
206 | section = OPENSSL_strdup("default");
|
---|
207 | if (section == NULL) {
|
---|
208 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
209 | goto err;
|
---|
210 | }
|
---|
211 |
|
---|
212 | if (_CONF_new_data(conf) == 0) {
|
---|
213 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
214 | goto err;
|
---|
215 | }
|
---|
216 |
|
---|
217 | sv = _CONF_new_section(conf, section);
|
---|
218 | if (sv == NULL) {
|
---|
219 | CONFerr(CONF_F_DEF_LOAD_BIO, CONF_R_UNABLE_TO_CREATE_NEW_SECTION);
|
---|
220 | goto err;
|
---|
221 | }
|
---|
222 |
|
---|
223 | bufnum = 0;
|
---|
224 | again = 0;
|
---|
225 | for (;;) {
|
---|
226 | if (!BUF_MEM_grow(buff, bufnum + CONFBUFSIZE)) {
|
---|
227 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_BUF_LIB);
|
---|
228 | goto err;
|
---|
229 | }
|
---|
230 | p = &(buff->data[bufnum]);
|
---|
231 | *p = '\0';
|
---|
232 | read_retry:
|
---|
233 | BIO_gets(in, p, CONFBUFSIZE - 1);
|
---|
234 | p[CONFBUFSIZE - 1] = '\0';
|
---|
235 | ii = i = strlen(p);
|
---|
236 | if (i == 0 && !again) {
|
---|
237 | /* the currently processed BIO is at EOF */
|
---|
238 | BIO *parent;
|
---|
239 |
|
---|
240 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
241 | /* continue processing with the next file from directory */
|
---|
242 | if (dirctx != NULL) {
|
---|
243 | BIO *next;
|
---|
244 |
|
---|
245 | if ((next = get_next_file(dirpath, &dirctx)) != NULL) {
|
---|
246 | BIO_vfree(in);
|
---|
247 | in = next;
|
---|
248 | goto read_retry;
|
---|
249 | } else {
|
---|
250 | OPENSSL_free(dirpath);
|
---|
251 | dirpath = NULL;
|
---|
252 | }
|
---|
253 | }
|
---|
254 | #endif
|
---|
255 | /* no more files in directory, continue with processing parent */
|
---|
256 | if ((parent = sk_BIO_pop(biosk)) == NULL) {
|
---|
257 | /* everything processed get out of the loop */
|
---|
258 | break;
|
---|
259 | } else {
|
---|
260 | BIO_vfree(in);
|
---|
261 | in = parent;
|
---|
262 | goto read_retry;
|
---|
263 | }
|
---|
264 | }
|
---|
265 | again = 0;
|
---|
266 | while (i > 0) {
|
---|
267 | if ((p[i - 1] != '\r') && (p[i - 1] != '\n'))
|
---|
268 | break;
|
---|
269 | else
|
---|
270 | i--;
|
---|
271 | }
|
---|
272 | /*
|
---|
273 | * we removed some trailing stuff so there is a new line on the end.
|
---|
274 | */
|
---|
275 | if (ii && i == ii)
|
---|
276 | again = 1; /* long line */
|
---|
277 | else {
|
---|
278 | p[i] = '\0';
|
---|
279 | eline++; /* another input line */
|
---|
280 | }
|
---|
281 |
|
---|
282 | /* we now have a line with trailing \r\n removed */
|
---|
283 |
|
---|
284 | /* i is the number of bytes */
|
---|
285 | bufnum += i;
|
---|
286 |
|
---|
287 | v = NULL;
|
---|
288 | /* check for line continuation */
|
---|
289 | if (bufnum >= 1) {
|
---|
290 | /*
|
---|
291 | * If we have bytes and the last char '\\' and second last char
|
---|
292 | * is not '\\'
|
---|
293 | */
|
---|
294 | p = &(buff->data[bufnum - 1]);
|
---|
295 | if (IS_ESC(conf, p[0]) && ((bufnum <= 1) || !IS_ESC(conf, p[-1]))) {
|
---|
296 | bufnum--;
|
---|
297 | again = 1;
|
---|
298 | }
|
---|
299 | }
|
---|
300 | if (again)
|
---|
301 | continue;
|
---|
302 | bufnum = 0;
|
---|
303 | buf = buff->data;
|
---|
304 |
|
---|
305 | clear_comments(conf, buf);
|
---|
306 | s = eat_ws(conf, buf);
|
---|
307 | if (IS_EOF(conf, *s))
|
---|
308 | continue; /* blank line */
|
---|
309 | if (*s == '[') {
|
---|
310 | char *ss;
|
---|
311 |
|
---|
312 | s++;
|
---|
313 | start = eat_ws(conf, s);
|
---|
314 | ss = start;
|
---|
315 | again:
|
---|
316 | end = eat_alpha_numeric(conf, ss);
|
---|
317 | p = eat_ws(conf, end);
|
---|
318 | if (*p != ']') {
|
---|
319 | if (*p != '\0' && ss != p) {
|
---|
320 | ss = p;
|
---|
321 | goto again;
|
---|
322 | }
|
---|
323 | CONFerr(CONF_F_DEF_LOAD_BIO,
|
---|
324 | CONF_R_MISSING_CLOSE_SQUARE_BRACKET);
|
---|
325 | goto err;
|
---|
326 | }
|
---|
327 | *end = '\0';
|
---|
328 | if (!str_copy(conf, NULL, §ion, start))
|
---|
329 | goto err;
|
---|
330 | if ((sv = _CONF_get_section(conf, section)) == NULL)
|
---|
331 | sv = _CONF_new_section(conf, section);
|
---|
332 | if (sv == NULL) {
|
---|
333 | CONFerr(CONF_F_DEF_LOAD_BIO,
|
---|
334 | CONF_R_UNABLE_TO_CREATE_NEW_SECTION);
|
---|
335 | goto err;
|
---|
336 | }
|
---|
337 | continue;
|
---|
338 | } else {
|
---|
339 | pname = s;
|
---|
340 | end = eat_alpha_numeric(conf, s);
|
---|
341 | if ((end[0] == ':') && (end[1] == ':')) {
|
---|
342 | *end = '\0';
|
---|
343 | end += 2;
|
---|
344 | psection = pname;
|
---|
345 | pname = end;
|
---|
346 | end = eat_alpha_numeric(conf, end);
|
---|
347 | } else {
|
---|
348 | psection = section;
|
---|
349 | }
|
---|
350 | p = eat_ws(conf, end);
|
---|
351 | if (strncmp(pname, ".include", 8) == 0
|
---|
352 | && (p != pname + 8 || *p == '=')) {
|
---|
353 | char *include = NULL;
|
---|
354 | BIO *next;
|
---|
355 |
|
---|
356 | if (*p == '=') {
|
---|
357 | p++;
|
---|
358 | p = eat_ws(conf, p);
|
---|
359 | }
|
---|
360 | trim_ws(conf, p);
|
---|
361 | if (!str_copy(conf, psection, &include, p))
|
---|
362 | goto err;
|
---|
363 | /* get the BIO of the included file */
|
---|
364 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
365 | next = process_include(include, &dirctx, &dirpath);
|
---|
366 | if (include != dirpath) {
|
---|
367 | /* dirpath will contain include in case of a directory */
|
---|
368 | OPENSSL_free(include);
|
---|
369 | }
|
---|
370 | #else
|
---|
371 | next = BIO_new_file(include, "r");
|
---|
372 | OPENSSL_free(include);
|
---|
373 | #endif
|
---|
374 | if (next != NULL) {
|
---|
375 | /* push the currently processing BIO onto stack */
|
---|
376 | if (biosk == NULL) {
|
---|
377 | if ((biosk = sk_BIO_new_null()) == NULL) {
|
---|
378 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
379 | goto err;
|
---|
380 | }
|
---|
381 | }
|
---|
382 | if (!sk_BIO_push(biosk, in)) {
|
---|
383 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
384 | goto err;
|
---|
385 | }
|
---|
386 | /* continue with reading from the included BIO */
|
---|
387 | in = next;
|
---|
388 | }
|
---|
389 | continue;
|
---|
390 | } else if (*p != '=') {
|
---|
391 | CONFerr(CONF_F_DEF_LOAD_BIO, CONF_R_MISSING_EQUAL_SIGN);
|
---|
392 | goto err;
|
---|
393 | }
|
---|
394 | *end = '\0';
|
---|
395 | p++;
|
---|
396 | start = eat_ws(conf, p);
|
---|
397 | trim_ws(conf, start);
|
---|
398 |
|
---|
399 | if ((v = OPENSSL_malloc(sizeof(*v))) == NULL) {
|
---|
400 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
401 | goto err;
|
---|
402 | }
|
---|
403 | v->name = OPENSSL_strdup(pname);
|
---|
404 | v->value = NULL;
|
---|
405 | if (v->name == NULL) {
|
---|
406 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
407 | goto err;
|
---|
408 | }
|
---|
409 | if (!str_copy(conf, psection, &(v->value), start))
|
---|
410 | goto err;
|
---|
411 |
|
---|
412 | if (strcmp(psection, section) != 0) {
|
---|
413 | if ((tv = _CONF_get_section(conf, psection))
|
---|
414 | == NULL)
|
---|
415 | tv = _CONF_new_section(conf, psection);
|
---|
416 | if (tv == NULL) {
|
---|
417 | CONFerr(CONF_F_DEF_LOAD_BIO,
|
---|
418 | CONF_R_UNABLE_TO_CREATE_NEW_SECTION);
|
---|
419 | goto err;
|
---|
420 | }
|
---|
421 | } else
|
---|
422 | tv = sv;
|
---|
423 | if (_CONF_add_string(conf, tv, v) == 0) {
|
---|
424 | CONFerr(CONF_F_DEF_LOAD_BIO, ERR_R_MALLOC_FAILURE);
|
---|
425 | goto err;
|
---|
426 | }
|
---|
427 | v = NULL;
|
---|
428 | }
|
---|
429 | }
|
---|
430 | BUF_MEM_free(buff);
|
---|
431 | OPENSSL_free(section);
|
---|
432 | /*
|
---|
433 | * No need to pop, since we only get here if the stack is empty.
|
---|
434 | * If this causes a BIO leak, THE ISSUE IS SOMEWHERE ELSE!
|
---|
435 | */
|
---|
436 | sk_BIO_free(biosk);
|
---|
437 | return 1;
|
---|
438 | err:
|
---|
439 | BUF_MEM_free(buff);
|
---|
440 | OPENSSL_free(section);
|
---|
441 | /*
|
---|
442 | * Since |in| is the first element of the stack and should NOT be freed
|
---|
443 | * here, we cannot use sk_BIO_pop_free(). Instead, we pop and free one
|
---|
444 | * BIO at a time, making sure that the last one popped isn't.
|
---|
445 | */
|
---|
446 | while (sk_BIO_num(biosk) > 0) {
|
---|
447 | BIO *popped = sk_BIO_pop(biosk);
|
---|
448 | BIO_vfree(in);
|
---|
449 | in = popped;
|
---|
450 | }
|
---|
451 | sk_BIO_free(biosk);
|
---|
452 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
453 | OPENSSL_free(dirpath);
|
---|
454 | if (dirctx != NULL)
|
---|
455 | OPENSSL_DIR_end(&dirctx);
|
---|
456 | #endif
|
---|
457 | if (line != NULL)
|
---|
458 | *line = eline;
|
---|
459 | BIO_snprintf(btmp, sizeof(btmp), "%ld", eline);
|
---|
460 | ERR_add_error_data(2, "line ", btmp);
|
---|
461 | if (h != conf->data) {
|
---|
462 | CONF_free(conf->data);
|
---|
463 | conf->data = NULL;
|
---|
464 | }
|
---|
465 | if (v != NULL) {
|
---|
466 | OPENSSL_free(v->name);
|
---|
467 | OPENSSL_free(v->value);
|
---|
468 | OPENSSL_free(v);
|
---|
469 | }
|
---|
470 | return 0;
|
---|
471 | }
|
---|
472 |
|
---|
473 | static void clear_comments(CONF *conf, char *p)
|
---|
474 | {
|
---|
475 | for (;;) {
|
---|
476 | if (IS_FCOMMENT(conf, *p)) {
|
---|
477 | *p = '\0';
|
---|
478 | return;
|
---|
479 | }
|
---|
480 | if (!IS_WS(conf, *p)) {
|
---|
481 | break;
|
---|
482 | }
|
---|
483 | p++;
|
---|
484 | }
|
---|
485 |
|
---|
486 | for (;;) {
|
---|
487 | if (IS_COMMENT(conf, *p)) {
|
---|
488 | *p = '\0';
|
---|
489 | return;
|
---|
490 | }
|
---|
491 | if (IS_DQUOTE(conf, *p)) {
|
---|
492 | p = scan_dquote(conf, p);
|
---|
493 | continue;
|
---|
494 | }
|
---|
495 | if (IS_QUOTE(conf, *p)) {
|
---|
496 | p = scan_quote(conf, p);
|
---|
497 | continue;
|
---|
498 | }
|
---|
499 | if (IS_ESC(conf, *p)) {
|
---|
500 | p = scan_esc(conf, p);
|
---|
501 | continue;
|
---|
502 | }
|
---|
503 | if (IS_EOF(conf, *p))
|
---|
504 | return;
|
---|
505 | else
|
---|
506 | p++;
|
---|
507 | }
|
---|
508 | }
|
---|
509 |
|
---|
510 | static int str_copy(CONF *conf, char *section, char **pto, char *from)
|
---|
511 | {
|
---|
512 | int q, r, rr = 0, to = 0, len = 0;
|
---|
513 | char *s, *e, *rp, *p, *rrp, *np, *cp, v;
|
---|
514 | BUF_MEM *buf;
|
---|
515 |
|
---|
516 | if ((buf = BUF_MEM_new()) == NULL)
|
---|
517 | return 0;
|
---|
518 |
|
---|
519 | len = strlen(from) + 1;
|
---|
520 | if (!BUF_MEM_grow(buf, len))
|
---|
521 | goto err;
|
---|
522 |
|
---|
523 | for (;;) {
|
---|
524 | if (IS_QUOTE(conf, *from)) {
|
---|
525 | q = *from;
|
---|
526 | from++;
|
---|
527 | while (!IS_EOF(conf, *from) && (*from != q)) {
|
---|
528 | if (IS_ESC(conf, *from)) {
|
---|
529 | from++;
|
---|
530 | if (IS_EOF(conf, *from))
|
---|
531 | break;
|
---|
532 | }
|
---|
533 | buf->data[to++] = *(from++);
|
---|
534 | }
|
---|
535 | if (*from == q)
|
---|
536 | from++;
|
---|
537 | } else if (IS_DQUOTE(conf, *from)) {
|
---|
538 | q = *from;
|
---|
539 | from++;
|
---|
540 | while (!IS_EOF(conf, *from)) {
|
---|
541 | if (*from == q) {
|
---|
542 | if (*(from + 1) == q) {
|
---|
543 | from++;
|
---|
544 | } else {
|
---|
545 | break;
|
---|
546 | }
|
---|
547 | }
|
---|
548 | buf->data[to++] = *(from++);
|
---|
549 | }
|
---|
550 | if (*from == q)
|
---|
551 | from++;
|
---|
552 | } else if (IS_ESC(conf, *from)) {
|
---|
553 | from++;
|
---|
554 | v = *(from++);
|
---|
555 | if (IS_EOF(conf, v))
|
---|
556 | break;
|
---|
557 | else if (v == 'r')
|
---|
558 | v = '\r';
|
---|
559 | else if (v == 'n')
|
---|
560 | v = '\n';
|
---|
561 | else if (v == 'b')
|
---|
562 | v = '\b';
|
---|
563 | else if (v == 't')
|
---|
564 | v = '\t';
|
---|
565 | buf->data[to++] = v;
|
---|
566 | } else if (IS_EOF(conf, *from))
|
---|
567 | break;
|
---|
568 | else if (*from == '$') {
|
---|
569 | size_t newsize;
|
---|
570 |
|
---|
571 | /* try to expand it */
|
---|
572 | rrp = NULL;
|
---|
573 | s = &(from[1]);
|
---|
574 | if (*s == '{')
|
---|
575 | q = '}';
|
---|
576 | else if (*s == '(')
|
---|
577 | q = ')';
|
---|
578 | else
|
---|
579 | q = 0;
|
---|
580 |
|
---|
581 | if (q)
|
---|
582 | s++;
|
---|
583 | cp = section;
|
---|
584 | e = np = s;
|
---|
585 | while (IS_ALNUM(conf, *e))
|
---|
586 | e++;
|
---|
587 | if ((e[0] == ':') && (e[1] == ':')) {
|
---|
588 | cp = np;
|
---|
589 | rrp = e;
|
---|
590 | rr = *e;
|
---|
591 | *rrp = '\0';
|
---|
592 | e += 2;
|
---|
593 | np = e;
|
---|
594 | while (IS_ALNUM(conf, *e))
|
---|
595 | e++;
|
---|
596 | }
|
---|
597 | r = *e;
|
---|
598 | *e = '\0';
|
---|
599 | rp = e;
|
---|
600 | if (q) {
|
---|
601 | if (r != q) {
|
---|
602 | CONFerr(CONF_F_STR_COPY, CONF_R_NO_CLOSE_BRACE);
|
---|
603 | goto err;
|
---|
604 | }
|
---|
605 | e++;
|
---|
606 | }
|
---|
607 | /*-
|
---|
608 | * So at this point we have
|
---|
609 | * np which is the start of the name string which is
|
---|
610 | * '\0' terminated.
|
---|
611 | * cp which is the start of the section string which is
|
---|
612 | * '\0' terminated.
|
---|
613 | * e is the 'next point after'.
|
---|
614 | * r and rr are the chars replaced by the '\0'
|
---|
615 | * rp and rrp is where 'r' and 'rr' came from.
|
---|
616 | */
|
---|
617 | p = _CONF_get_string(conf, cp, np);
|
---|
618 | if (rrp != NULL)
|
---|
619 | *rrp = rr;
|
---|
620 | *rp = r;
|
---|
621 | if (p == NULL) {
|
---|
622 | CONFerr(CONF_F_STR_COPY, CONF_R_VARIABLE_HAS_NO_VALUE);
|
---|
623 | goto err;
|
---|
624 | }
|
---|
625 | newsize = strlen(p) + buf->length - (e - from);
|
---|
626 | if (newsize > MAX_CONF_VALUE_LENGTH) {
|
---|
627 | CONFerr(CONF_F_STR_COPY, CONF_R_VARIABLE_EXPANSION_TOO_LONG);
|
---|
628 | goto err;
|
---|
629 | }
|
---|
630 | if (!BUF_MEM_grow_clean(buf, newsize)) {
|
---|
631 | CONFerr(CONF_F_STR_COPY, ERR_R_MALLOC_FAILURE);
|
---|
632 | goto err;
|
---|
633 | }
|
---|
634 | while (*p)
|
---|
635 | buf->data[to++] = *(p++);
|
---|
636 |
|
---|
637 | /*
|
---|
638 | * Since we change the pointer 'from', we also have to change the
|
---|
639 | * perceived length of the string it points at. /RL
|
---|
640 | */
|
---|
641 | len -= e - from;
|
---|
642 | from = e;
|
---|
643 |
|
---|
644 | /*
|
---|
645 | * In case there were no braces or parenthesis around the
|
---|
646 | * variable reference, we have to put back the character that was
|
---|
647 | * replaced with a '\0'. /RL
|
---|
648 | */
|
---|
649 | *rp = r;
|
---|
650 | } else
|
---|
651 | buf->data[to++] = *(from++);
|
---|
652 | }
|
---|
653 | buf->data[to] = '\0';
|
---|
654 | OPENSSL_free(*pto);
|
---|
655 | *pto = buf->data;
|
---|
656 | OPENSSL_free(buf);
|
---|
657 | return 1;
|
---|
658 | err:
|
---|
659 | BUF_MEM_free(buf);
|
---|
660 | return 0;
|
---|
661 | }
|
---|
662 |
|
---|
663 | #ifndef OPENSSL_NO_POSIX_IO
|
---|
664 | /*
|
---|
665 | * Check whether included path is a directory.
|
---|
666 | * Returns next BIO to process and in case of a directory
|
---|
667 | * also an opened directory context and the include path.
|
---|
668 | */
|
---|
669 | static BIO *process_include(char *include, OPENSSL_DIR_CTX **dirctx,
|
---|
670 | char **dirpath)
|
---|
671 | {
|
---|
672 | struct stat st = { 0 };
|
---|
673 | BIO *next;
|
---|
674 |
|
---|
675 | if (stat(include, &st) < 0) {
|
---|
676 | SYSerr(SYS_F_STAT, errno);
|
---|
677 | ERR_add_error_data(1, include);
|
---|
678 | /* missing include file is not fatal error */
|
---|
679 | return NULL;
|
---|
680 | }
|
---|
681 |
|
---|
682 | if (S_ISDIR(st.st_mode)) {
|
---|
683 | if (*dirctx != NULL) {
|
---|
684 | CONFerr(CONF_F_PROCESS_INCLUDE,
|
---|
685 | CONF_R_RECURSIVE_DIRECTORY_INCLUDE);
|
---|
686 | ERR_add_error_data(1, include);
|
---|
687 | return NULL;
|
---|
688 | }
|
---|
689 | /* a directory, load its contents */
|
---|
690 | if ((next = get_next_file(include, dirctx)) != NULL)
|
---|
691 | *dirpath = include;
|
---|
692 | return next;
|
---|
693 | }
|
---|
694 |
|
---|
695 | next = BIO_new_file(include, "r");
|
---|
696 | return next;
|
---|
697 | }
|
---|
698 |
|
---|
699 | /*
|
---|
700 | * Get next file from the directory path.
|
---|
701 | * Returns BIO of the next file to read and updates dirctx.
|
---|
702 | */
|
---|
703 | static BIO *get_next_file(const char *path, OPENSSL_DIR_CTX **dirctx)
|
---|
704 | {
|
---|
705 | const char *filename;
|
---|
706 | size_t pathlen;
|
---|
707 |
|
---|
708 | pathlen = strlen(path);
|
---|
709 | while ((filename = OPENSSL_DIR_read(dirctx, path)) != NULL) {
|
---|
710 | size_t namelen;
|
---|
711 |
|
---|
712 | namelen = strlen(filename);
|
---|
713 |
|
---|
714 |
|
---|
715 | if ((namelen > 5 && strcasecmp(filename + namelen - 5, ".conf") == 0)
|
---|
716 | || (namelen > 4 && strcasecmp(filename + namelen - 4, ".cnf") == 0)) {
|
---|
717 | size_t newlen;
|
---|
718 | char *newpath;
|
---|
719 | BIO *bio;
|
---|
720 |
|
---|
721 | newlen = pathlen + namelen + 2;
|
---|
722 | newpath = OPENSSL_zalloc(newlen);
|
---|
723 | if (newpath == NULL) {
|
---|
724 | CONFerr(CONF_F_GET_NEXT_FILE, ERR_R_MALLOC_FAILURE);
|
---|
725 | break;
|
---|
726 | }
|
---|
727 | #ifdef OPENSSL_SYS_VMS
|
---|
728 | /*
|
---|
729 | * If the given path isn't clear VMS syntax,
|
---|
730 | * we treat it as on Unix.
|
---|
731 | */
|
---|
732 | if (path[pathlen - 1] == ']'
|
---|
733 | || path[pathlen - 1] == '>'
|
---|
734 | || path[pathlen - 1] == ':') {
|
---|
735 | /* Clear VMS directory syntax, just copy as is */
|
---|
736 | OPENSSL_strlcpy(newpath, path, newlen);
|
---|
737 | }
|
---|
738 | #endif
|
---|
739 | if (newpath[0] == '\0') {
|
---|
740 | OPENSSL_strlcpy(newpath, path, newlen);
|
---|
741 | OPENSSL_strlcat(newpath, "/", newlen);
|
---|
742 | }
|
---|
743 | OPENSSL_strlcat(newpath, filename, newlen);
|
---|
744 |
|
---|
745 | bio = BIO_new_file(newpath, "r");
|
---|
746 | OPENSSL_free(newpath);
|
---|
747 | /* Errors when opening files are non-fatal. */
|
---|
748 | if (bio != NULL)
|
---|
749 | return bio;
|
---|
750 | }
|
---|
751 | }
|
---|
752 | OPENSSL_DIR_end(dirctx);
|
---|
753 | *dirctx = NULL;
|
---|
754 | return NULL;
|
---|
755 | }
|
---|
756 | #endif
|
---|
757 |
|
---|
758 | static int is_keytype(const CONF *conf, char c, unsigned short type)
|
---|
759 | {
|
---|
760 | const unsigned short * keytypes = (const unsigned short *) conf->meth_data;
|
---|
761 | unsigned char key = (unsigned char)c;
|
---|
762 |
|
---|
763 | #ifdef CHARSET_EBCDIC
|
---|
764 | # if CHAR_BIT > 8
|
---|
765 | if (key > 255) {
|
---|
766 | /* key is out of range for os_toascii table */
|
---|
767 | return 0;
|
---|
768 | }
|
---|
769 | # endif
|
---|
770 | /* convert key from ebcdic to ascii */
|
---|
771 | key = os_toascii[key];
|
---|
772 | #endif
|
---|
773 |
|
---|
774 | if (key > 127) {
|
---|
775 | /* key is not a seven bit ascii character */
|
---|
776 | return 0;
|
---|
777 | }
|
---|
778 |
|
---|
779 | return (keytypes[key] & type) ? 1 : 0;
|
---|
780 | }
|
---|
781 |
|
---|
782 | static char *eat_ws(CONF *conf, char *p)
|
---|
783 | {
|
---|
784 | while (IS_WS(conf, *p) && (!IS_EOF(conf, *p)))
|
---|
785 | p++;
|
---|
786 | return p;
|
---|
787 | }
|
---|
788 |
|
---|
789 | static void trim_ws(CONF *conf, char *start)
|
---|
790 | {
|
---|
791 | char *p = start;
|
---|
792 |
|
---|
793 | while (!IS_EOF(conf, *p))
|
---|
794 | p++;
|
---|
795 | p--;
|
---|
796 | while ((p >= start) && IS_WS(conf, *p))
|
---|
797 | p--;
|
---|
798 | p++;
|
---|
799 | *p = '\0';
|
---|
800 | }
|
---|
801 |
|
---|
802 | static char *eat_alpha_numeric(CONF *conf, char *p)
|
---|
803 | {
|
---|
804 | for (;;) {
|
---|
805 | if (IS_ESC(conf, *p)) {
|
---|
806 | p = scan_esc(conf, p);
|
---|
807 | continue;
|
---|
808 | }
|
---|
809 | if (!IS_ALNUM_PUNCT(conf, *p))
|
---|
810 | return p;
|
---|
811 | p++;
|
---|
812 | }
|
---|
813 | }
|
---|
814 |
|
---|
815 | static char *scan_quote(CONF *conf, char *p)
|
---|
816 | {
|
---|
817 | int q = *p;
|
---|
818 |
|
---|
819 | p++;
|
---|
820 | while (!(IS_EOF(conf, *p)) && (*p != q)) {
|
---|
821 | if (IS_ESC(conf, *p)) {
|
---|
822 | p++;
|
---|
823 | if (IS_EOF(conf, *p))
|
---|
824 | return p;
|
---|
825 | }
|
---|
826 | p++;
|
---|
827 | }
|
---|
828 | if (*p == q)
|
---|
829 | p++;
|
---|
830 | return p;
|
---|
831 | }
|
---|
832 |
|
---|
833 | static char *scan_dquote(CONF *conf, char *p)
|
---|
834 | {
|
---|
835 | int q = *p;
|
---|
836 |
|
---|
837 | p++;
|
---|
838 | while (!(IS_EOF(conf, *p))) {
|
---|
839 | if (*p == q) {
|
---|
840 | if (*(p + 1) == q) {
|
---|
841 | p++;
|
---|
842 | } else {
|
---|
843 | break;
|
---|
844 | }
|
---|
845 | }
|
---|
846 | p++;
|
---|
847 | }
|
---|
848 | if (*p == q)
|
---|
849 | p++;
|
---|
850 | return p;
|
---|
851 | }
|
---|
852 |
|
---|
853 | static void dump_value_doall_arg(const CONF_VALUE *a, BIO *out)
|
---|
854 | {
|
---|
855 | if (a->name)
|
---|
856 | BIO_printf(out, "[%s] %s=%s\n", a->section, a->name, a->value);
|
---|
857 | else
|
---|
858 | BIO_printf(out, "[[%s]]\n", a->section);
|
---|
859 | }
|
---|
860 |
|
---|
861 | IMPLEMENT_LHASH_DOALL_ARG_CONST(CONF_VALUE, BIO);
|
---|
862 |
|
---|
863 | static int def_dump(const CONF *conf, BIO *out)
|
---|
864 | {
|
---|
865 | lh_CONF_VALUE_doall_BIO(conf->data, dump_value_doall_arg, out);
|
---|
866 | return 1;
|
---|
867 | }
|
---|
868 |
|
---|
869 | static int def_is_number(const CONF *conf, char c)
|
---|
870 | {
|
---|
871 | return IS_NUMBER(conf, c);
|
---|
872 | }
|
---|
873 |
|
---|
874 | static int def_to_int(const CONF *conf, char c)
|
---|
875 | {
|
---|
876 | return c - '0';
|
---|
877 | }
|
---|