Coverage Report

Created: 2026-09-28 06:27

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/freeradius-server/src/lib/tls/base.h
Line
Count
Source
1
#pragma once
2
/*
3
 *  This program is free software; you can redistribute it and/or modify
4
 *  it under the terms of the GNU General Public License as published by
5
 *  the Free Software Foundation; either version 2 of the License, or
6
 *  (at your option) any later version.
7
 *
8
 *  This program is distributed in the hope that it will be useful,
9
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
10
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11
 *  GNU General Public License for more details.
12
 *
13
 *  You should have received a copy of the GNU General Public License
14
 *  along with this program; if not, write to the Free Software
15
 *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
16
 */
17
#ifdef WITH_TLS
18
/**
19
 * $Id: e997d401c2e23d0aab2dcf070e2274b1e79129bf $
20
 *
21
 * @file lib/tls/tls.h
22
 * @brief Structures and prototypes for TLS wrappers
23
 *
24
 * @copyright 2010 Network RADIUS SARL (legal@networkradius.com)
25
 * @copyright 2016 The FreeRADIUS project
26
 */
27
RCSIDH(tls_h, "$Id: e997d401c2e23d0aab2dcf070e2274b1e79129bf $")
28
29
#include "openssl_user_macros.h"
30
31
#include <freeradius-devel/server/cf_parse.h>
32
#include <freeradius-devel/server/tmpl.h>
33
#include <freeradius-devel/unlang/function.h>
34
35
#undef HAVE_OPENSSL_OCSP_H
36
37
#include <openssl/ssl.h>
38
#include <openssl/err.h>
39
40
#include "cache.h"
41
#include "conf.h"
42
#include "index.h"
43
#include "session.h"
44
45
#ifdef __cplusplus
46
extern "C" {
47
#endif
48
extern int fr_tls_ex_index_vps;
49
extern int fr_tls_max_threads;
50
51
/** Drain log messages from an OpenSSL bio and print them using the specified logging macro
52
 *
53
 * @param _macro Logging macro e.g. RDEBUG.
54
 * @param _prefix Prefix, should be "" if not used.
55
 * @param _queue OpenSSL BIO.
56
 */
57
#define FR_OPENSSL_DRAIN_LOG_QUEUE(_macro, _prefix, _queue) \
58
do {\
59
  char const *_p = NULL, *_q, *_end; \
60
  size_t _len; \
61
  _len = BIO_get_mem_data(_queue, &_p); \
62
  _end = _p + _len; \
63
  if (!_p) break; \
64
  while ((_q = memchr(_p, '\n', _end - _p))) { \
65
    _macro(_prefix "%.*s", (int) (_q - _p), _p); \
66
    _p = _q + 1; \
67
  } \
68
  if (_p != _end) _macro(_prefix "%.*s", (int) (_end - _p), _p); \
69
  (void) BIO_reset(_queue); \
70
} while (0)
71
72
/** Drain errors from an OpenSSL bio and print print them using the specified logging macro
73
 *
74
 * @param _macro Logging macro e.g. RDEBUG.
75
 * @param _prefix Prefix, should be "" if not used.
76
 * @param _queue OpenSSL BIO.
77
 */
78
#define FR_OPENSSL_DRAIN_ERROR_QUEUE(_macro, _prefix, _queue) \
79
do {\
80
  ERR_print_errors(_queue); \
81
  FR_OPENSSL_DRAIN_LOG_QUEUE(_macro, _prefix, _queue); \
82
} while (0)
83
84
extern conf_parser_t fr_tls_server_config[];
85
extern conf_parser_t fr_tls_client_config[];
86
87
/** Holds the temporary context
88
 *
89
 */
90
extern _Thread_local TALLOC_CTX *ssl_talloc_ctx;
91
92
/** Bind any memory allocated by an OpenSSL function to the object it created
93
 *
94
 * This is a horrible workaround for OpenSSL memory leaks.  But should always
95
 * work, unless OpenSSL allocates memory for global structures whilst allocating
96
 * non-global ones.
97
 *
98
 * It is technically threadsafe as ssl_talloc_ctx is thread specific.
99
 *
100
 * This should always work so long as OpenSSL does not become talloc aware and
101
 * so will free the allocated object last, after doing manual cleanups.
102
 *
103
 @code{.c}
104
   FR_OPENSSL_BIND_MEMORY(ctx = SSL_CTX_new(TLS_method()));
105
   if (!ctx) ..error
106
 @endcode
107
 * @param _expr   The call to the OpenSSL function and storage of the
108
 *      result.
109
 */
110
#define FR_OPENSSL_BIND_OBJ_MEMORY(_expr) \
111
do { \
112
  void *_nmem; \
113
  MEM(ssl_talloc_ctx = talloc_init_const(STRINGIFY(_expr))); \
114
  _nmem = (_expr);\
115
  if (!_nmem) { \
116
    TALLOC_FREE(ssl_talloc_ctx); \
117
  } else { \
118
    talloc_steal(_nmem, ssl_talloc_ctx); \
119
  } \
120
  ssl_talloc_ctx = NULL; \
121
} while (0)
122
123
/** Bind all memory allocated from this point until the next instance of FR_OPENSSL_BIND_MEMORY_END to _obj
124
 *
125
 * @param[in] _obj  to bind memory to.
126
 */
127
#define FR_OPENSSL_BIND_MEMORY_BEGIN(_obj) \
128
do { \
129
  if (fr_cond_assert(!ssl_talloc_ctx && (_obj))) { \
130
    MEM(ssl_talloc_ctx = talloc_init_const(STRINGIFY(_obj))); \
131
    talloc_steal(_obj, ssl_talloc_ctx); \
132
  } \
133
} while(0)
134
135
#define FR_OPENSSL_BIND_MEMORY_END ssl_talloc_ctx = NULL
136
137
/*
138
 *  tls/ctx.c
139
 */
140
141
/** Return the tls config associated with a SSL_CTX
142
 *
143
 * @param[in] ssl_ctx to retrieve the configuration from.
144
 * @return #fr_tls_conf_t associated with the ctx.
145
 */
146
static inline fr_tls_conf_t *fr_tls_ctx_conf(SSL_CTX *ssl_ctx)
147
0
{
148
  return talloc_get_type_abort(SSL_CTX_get_ex_data(ssl_ctx, FR_TLS_EX_INDEX_CONF), fr_tls_conf_t);
149
0
}
Unexecuted instantiation: base.c:fr_tls_ctx_conf
Unexecuted instantiation: cache.c:fr_tls_ctx_conf
Unexecuted instantiation: conf.c:fr_tls_ctx_conf
Unexecuted instantiation: connection.c:fr_tls_ctx_conf
Unexecuted instantiation: pairs.c:fr_tls_ctx_conf
Unexecuted instantiation: session.c:fr_tls_ctx_conf
Unexecuted instantiation: strerror.c:fr_tls_ctx_conf
Unexecuted instantiation: virtual_server.c:fr_tls_ctx_conf
150
151
SSL_CTX   *fr_tls_ctx_alloc(fr_tls_conf_t const *conf, bool client);
152
153
/*
154
 *  tls/base.c
155
 */
156
int   fr_openssl_thread_init(size_t async_pool_size_init, size_t async_pool_size_max);
157
158
int   fr_openssl_init(void);
159
160
int   fr_openssl_fips_mode(bool enabled);
161
162
void    fr_openssl_free(void);
163
164
int   fr_tls_dict_init(void);
165
166
void    fr_tls_dict_free(void);
167
168
/*
169
 *  tls/virtual_server.c
170
 */
171
unlang_action_t fr_tls_call_push(request_t *child, unlang_function_no_result_t resume,
172
               fr_tls_conf_t *conf, fr_tls_session_t *tls_session, bool cache_required);
173
174
#ifdef __cplusplus
175
}
176
#endif
177
#endif /* WITH_TLS */