Coverage Report

Created: 2025-06-13 06:57

/src/openssl/crypto/bio/bss_mem.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <stdio.h>
11
#include <errno.h>
12
#include "bio_local.h"
13
#include "internal/cryptlib.h"
14
15
static int mem_write(BIO *h, const char *buf, int num);
16
static int mem_read(BIO *h, char *buf, int size);
17
static int mem_puts(BIO *h, const char *str);
18
static int mem_gets(BIO *h, char *str, int size);
19
static long mem_ctrl(BIO *h, int cmd, long arg1, void *arg2);
20
static int mem_new(BIO *h);
21
static int secmem_new(BIO *h);
22
static int mem_free(BIO *data);
23
static int mem_buf_free(BIO *data);
24
static int mem_buf_sync(BIO *h);
25
26
static const BIO_METHOD mem_method = {
27
    BIO_TYPE_MEM,
28
    "memory buffer",
29
    bwrite_conv,
30
    mem_write,
31
    bread_conv,
32
    mem_read,
33
    mem_puts,
34
    mem_gets,
35
    mem_ctrl,
36
    mem_new,
37
    mem_free,
38
    NULL,                      /* mem_callback_ctrl */
39
};
40
41
static const BIO_METHOD secmem_method = {
42
    BIO_TYPE_MEM,
43
    "secure memory buffer",
44
    bwrite_conv,
45
    mem_write,
46
    bread_conv,
47
    mem_read,
48
    mem_puts,
49
    mem_gets,
50
    mem_ctrl,
51
    secmem_new,
52
    mem_free,
53
    NULL,                      /* mem_callback_ctrl */
54
};
55
56
/*
57
 * BIO memory stores buffer and read pointer
58
 * however the roles are different for read only BIOs.
59
 * In that case the readp just stores the original state
60
 * to be used for reset.
61
 */
62
typedef struct bio_buf_mem_st {
63
    struct buf_mem_st *buf;   /* allocated buffer */
64
    struct buf_mem_st *readp; /* read pointer */
65
} BIO_BUF_MEM;
66
67
/*
68
 * bio->num is used to hold the value to return on 'empty', if it is 0,
69
 * should_retry is not set
70
 */
71
72
const BIO_METHOD *BIO_s_mem(void)
73
108k
{
74
108k
    return &mem_method;
75
108k
}
76
77
const BIO_METHOD *BIO_s_secmem(void)
78
0
{
79
0
    return &secmem_method;
80
0
}
81
82
BIO *BIO_new_mem_buf(const void *buf, int len)
83
40.8k
{
84
40.8k
    BIO *ret;
85
40.8k
    BUF_MEM *b;
86
40.8k
    BIO_BUF_MEM *bb;
87
40.8k
    size_t sz;
88
89
40.8k
    if (buf == NULL) {
90
0
        ERR_raise(ERR_LIB_BIO, ERR_R_PASSED_NULL_PARAMETER);
91
0
        return NULL;
92
0
    }
93
40.8k
    sz = (len < 0) ? strlen(buf) : (size_t)len;
94
40.8k
    if ((ret = BIO_new(BIO_s_mem())) == NULL)
95
0
        return NULL;
96
40.8k
    bb = (BIO_BUF_MEM *)ret->ptr;
97
40.8k
    b = bb->buf;
98
    /* Cast away const and trust in the MEM_RDONLY flag. */
99
40.8k
    b->data = (void *)buf;
100
40.8k
    b->length = sz;
101
40.8k
    b->max = sz;
102
40.8k
    *bb->readp = *bb->buf;
103
40.8k
    ret->flags |= BIO_FLAGS_MEM_RDONLY;
104
    /* Since this is static data retrying won't help */
105
40.8k
    ret->num = 0;
106
40.8k
    return ret;
107
40.8k
}
108
109
static int mem_init(BIO *bi, unsigned long flags)
110
136k
{
111
136k
    BIO_BUF_MEM *bb = OPENSSL_zalloc(sizeof(*bb));
112
113
136k
    if (bb == NULL)
114
0
        return 0;
115
136k
    if ((bb->buf = BUF_MEM_new_ex(flags)) == NULL) {
116
0
        OPENSSL_free(bb);
117
0
        return 0;
118
0
    }
119
136k
    if ((bb->readp = OPENSSL_zalloc(sizeof(*bb->readp))) == NULL) {
120
0
        BUF_MEM_free(bb->buf);
121
0
        OPENSSL_free(bb);
122
0
        return 0;
123
0
    }
124
136k
    *bb->readp = *bb->buf;
125
136k
    bi->shutdown = 1;
126
136k
    bi->init = 1;
127
136k
    bi->num = -1;
128
136k
    bi->ptr = (char *)bb;
129
136k
    return 1;
130
136k
}
131
132
static int mem_new(BIO *bi)
133
136k
{
134
136k
    return mem_init(bi, 0L);
135
136k
}
136
137
static int secmem_new(BIO *bi)
138
0
{
139
0
    return mem_init(bi, BUF_MEM_FLAG_SECURE);
140
0
}
141
142
static int mem_free(BIO *a)
143
136k
{
144
136k
    BIO_BUF_MEM *bb;
145
146
136k
    if (a == NULL)
147
0
        return 0;
148
149
136k
    bb = (BIO_BUF_MEM *)a->ptr;
150
136k
    if (!mem_buf_free(a))
151
0
        return 0;
152
136k
    OPENSSL_free(bb->readp);
153
136k
    OPENSSL_free(bb);
154
136k
    return 1;
155
136k
}
156
157
static int mem_buf_free(BIO *a)
158
136k
{
159
136k
    if (a == NULL)
160
0
        return 0;
161
162
136k
    if (a->shutdown && a->init && a->ptr != NULL) {
163
136k
        BIO_BUF_MEM *bb = (BIO_BUF_MEM *)a->ptr;
164
136k
        BUF_MEM *b = bb->buf;
165
166
136k
        if (a->flags & BIO_FLAGS_MEM_RDONLY)
167
40.8k
            b->data = NULL;
168
136k
        BUF_MEM_free(b);
169
136k
    }
170
136k
    return 1;
171
136k
}
172
173
/*
174
 * Reallocate memory buffer if read pointer differs
175
 * NOT FOR RDONLY
176
 */
177
static int mem_buf_sync(BIO *b)
178
449k
{
179
449k
    if (b != NULL && b->init != 0 && b->ptr != NULL) {
180
449k
        BIO_BUF_MEM *bbm = (BIO_BUF_MEM *)b->ptr;
181
182
449k
        if (bbm->readp->data != bbm->buf->data) {
183
0
            memmove(bbm->buf->data, bbm->readp->data, bbm->readp->length);
184
0
            bbm->buf->length = bbm->readp->length;
185
0
            bbm->readp->data = bbm->buf->data;
186
0
        }
187
449k
    }
188
449k
    return 0;
189
449k
}
190
191
static int mem_read(BIO *b, char *out, int outl)
192
559k
{
193
559k
    int ret = -1;
194
559k
    BIO_BUF_MEM *bbm = (BIO_BUF_MEM *)b->ptr;
195
559k
    BUF_MEM *bm = bbm->readp;
196
197
559k
    if (b->flags & BIO_FLAGS_MEM_RDONLY)
198
81.7k
        bm = bbm->buf;
199
559k
    BIO_clear_retry_flags(b);
200
559k
    ret = (outl >= 0 && (size_t)outl > bm->length) ? (int)bm->length : outl;
201
559k
    if ((out != NULL) && (ret > 0)) {
202
556k
        memcpy(out, bm->data, ret);
203
556k
        bm->length -= ret;
204
556k
        bm->max -= ret;
205
556k
        bm->data += ret;
206
556k
    } else if (bm->length == 0) {
207
2.74k
        ret = b->num;
208
2.74k
        if (ret != 0)
209
2.74k
            BIO_set_retry_read(b);
210
2.74k
    }
211
559k
    return ret;
212
559k
}
213
214
static int mem_write(BIO *b, const char *in, int inl)
215
422k
{
216
422k
    int ret = -1;
217
422k
    int blen;
218
422k
    BIO_BUF_MEM *bbm = (BIO_BUF_MEM *)b->ptr;
219
220
422k
    if (b->flags & BIO_FLAGS_MEM_RDONLY) {
221
0
        ERR_raise(ERR_LIB_BIO, BIO_R_WRITE_TO_READ_ONLY_BIO);
222
0
        goto end;
223
0
    }
224
422k
    BIO_clear_retry_flags(b);
225
422k
    if (inl == 0)
226
0
        return 0;
227
422k
    if (in == NULL) {
228
0
        ERR_raise(ERR_LIB_BIO, ERR_R_PASSED_NULL_PARAMETER);
229
0
        goto end;
230
0
    }
231
422k
    blen = bbm->readp->length;
232
422k
    mem_buf_sync(b);
233
422k
    if (BUF_MEM_grow_clean(bbm->buf, blen + inl) == 0)
234
0
        goto end;
235
422k
    memcpy(bbm->buf->data + blen, in, inl);
236
422k
    *bbm->readp = *bbm->buf;
237
422k
    ret = inl;
238
422k
 end:
239
422k
    return ret;
240
422k
}
241
242
static long mem_ctrl(BIO *b, int cmd, long num, void *ptr)
243
362k
{
244
362k
    long ret = 1;
245
362k
    char **pptr;
246
362k
    BIO_BUF_MEM *bbm = (BIO_BUF_MEM *)b->ptr;
247
362k
    BUF_MEM *bm, *bo;            /* bio_mem, bio_other */
248
362k
    long off, remain;
249
250
362k
    if (b->flags & BIO_FLAGS_MEM_RDONLY) {
251
149k
        bm = bbm->buf;
252
149k
        bo = bbm->readp;
253
212k
    } else {
254
212k
        bm = bbm->readp;
255
212k
        bo = bbm->buf;
256
212k
    }
257
362k
    off = (bm->data == bo->data) ? 0 : bm->data - bo->data;
258
362k
    remain = bm->length;
259
260
362k
    switch (cmd) {
261
0
    case BIO_CTRL_RESET:
262
0
        bm = bbm->buf;
263
0
        if (bm->data != NULL) {
264
0
            if (!(b->flags & BIO_FLAGS_MEM_RDONLY)) {
265
0
                if (!(b->flags & BIO_FLAGS_NONCLEAR_RST)) {
266
0
                    memset(bm->data, 0, bm->max);
267
0
                    bm->length = 0;
268
0
                }
269
0
                *bbm->readp = *bbm->buf;
270
0
            } else {
271
                /* For read only case just reset to the start again */
272
0
                *bbm->buf = *bbm->readp;
273
0
            }
274
0
        }
275
0
        break;
276
54.4k
    case BIO_C_FILE_SEEK:
277
54.4k
        if (num < 0 || num > off + remain)
278
0
            return -1;   /* Can't see outside of the current buffer */
279
280
54.4k
        bm->data = (num != 0) ? bo->data + num : bo->data;
281
54.4k
        bm->length = bo->length - num;
282
54.4k
        bm->max = bo->max - num;
283
54.4k
        off = num;
284
        /* FALLTHRU */
285
217k
    case BIO_C_FILE_TELL:
286
217k
        ret = off;
287
217k
        break;
288
0
    case BIO_CTRL_EOF:
289
0
        ret = (long)(bm->length == 0);
290
0
        break;
291
0
    case BIO_C_SET_BUF_MEM_EOF_RETURN:
292
0
        b->num = (int)num;
293
0
        break;
294
43.5k
    case BIO_CTRL_INFO:
295
43.5k
        ret = (long)bm->length;
296
43.5k
        if (ptr != NULL) {
297
16.3k
            pptr = (char **)ptr;
298
16.3k
            *pptr = (char *)(bm->data);
299
16.3k
        }
300
43.5k
        break;
301
0
    case BIO_C_SET_BUF_MEM:
302
0
        mem_buf_free(b);
303
0
        b->shutdown = (int)num;
304
0
        bbm->buf = ptr;
305
0
        *bbm->readp = *bbm->buf;
306
0
        break;
307
27.2k
    case BIO_C_GET_BUF_MEM_PTR:
308
27.2k
        if (ptr != NULL) {
309
27.2k
            if (!(b->flags & BIO_FLAGS_MEM_RDONLY))
310
27.2k
                mem_buf_sync(b);
311
27.2k
            bm = bbm->buf;
312
27.2k
            pptr = (char **)ptr;
313
27.2k
            *pptr = (char *)bm;
314
27.2k
        }
315
27.2k
        break;
316
0
    case BIO_CTRL_GET_CLOSE:
317
0
        ret = (long)b->shutdown;
318
0
        break;
319
4.54k
    case BIO_CTRL_SET_CLOSE:
320
4.54k
        b->shutdown = (int)num;
321
4.54k
        break;
322
2.71k
    case BIO_CTRL_WPENDING:
323
2.71k
        ret = 0L;
324
2.71k
        break;
325
0
    case BIO_CTRL_PENDING:
326
0
        ret = (long)bm->length;
327
0
        break;
328
0
    case BIO_CTRL_DUP:
329
14.9k
    case BIO_CTRL_FLUSH:
330
14.9k
        ret = 1;
331
14.9k
        break;
332
4.54k
    case BIO_CTRL_PUSH:
333
9.08k
    case BIO_CTRL_POP:
334
50.9k
    default:
335
50.9k
        ret = 0;
336
50.9k
        break;
337
362k
    }
338
362k
    return ret;
339
362k
}
340
341
static int mem_gets(BIO *bp, char *buf, int size)
342
426k
{
343
426k
    int i, j;
344
426k
    int ret = -1;
345
426k
    char *p;
346
426k
    BIO_BUF_MEM *bbm = (BIO_BUF_MEM *)bp->ptr;
347
426k
    BUF_MEM *bm = bbm->readp;
348
349
426k
    if (bp->flags & BIO_FLAGS_MEM_RDONLY)
350
0
        bm = bbm->buf;
351
426k
    BIO_clear_retry_flags(bp);
352
426k
    j = bm->length;
353
426k
    if ((size - 1) < j)
354
290k
        j = size - 1;
355
426k
    if (j <= 0) {
356
0
        *buf = '\0';
357
0
        return 0;
358
0
    }
359
426k
    p = bm->data;
360
24.7M
    for (i = 0; i < j; i++) {
361
24.7M
        if (p[i] == '\n') {
362
426k
            i++;
363
426k
            break;
364
426k
        }
365
24.7M
    }
366
367
    /*
368
     * i is now the max num of bytes to copy, either j or up to
369
     * and including the first newline
370
     */
371
372
426k
    i = mem_read(bp, buf, i);
373
426k
    if (i > 0)
374
426k
        buf[i] = '\0';
375
426k
    ret = i;
376
426k
    return ret;
377
426k
}
378
379
static int mem_puts(BIO *bp, const char *str)
380
372k
{
381
372k
    int n, ret;
382
383
372k
    n = strlen(str);
384
372k
    ret = mem_write(bp, str, n);
385
    /* memory semantics is that it will always work */
386
372k
    return ret;
387
372k
}