Coverage Report

Created: 2026-05-24 07:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/openssl35/crypto/bio/bss_dgram_pair.c
Line
Count
Source
1
/*
2
 * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
#include <stdio.h>
11
#include <errno.h>
12
#include "bio_local.h"
13
#include "internal/cryptlib.h"
14
#include "internal/safe_math.h"
15
16
#if !defined(OPENSSL_NO_DGRAM) && !defined(OPENSSL_NO_SOCK)
17
18
OSSL_SAFE_MATH_UNSIGNED(size_t, size_t)
19
20
/* ===========================================================================
21
 * Byte-wise ring buffer which supports pushing and popping blocks of multiple
22
 * bytes at a time.
23
 */
24
struct ring_buf {
25
    unsigned char *start; /* start of buffer */
26
    size_t len; /* size of buffer allocation in bytes */
27
    size_t count; /* number of bytes currently pushed */
28
    /*
29
     * These index into start. Where idx[0] == idx[1], the buffer is full
30
     * (if count is nonzero) and empty otherwise.
31
     */
32
    size_t idx[2]; /* 0: head, 1: tail */
33
};
34
35
static int ring_buf_init(struct ring_buf *r, size_t nbytes)
36
265k
{
37
265k
    r->start = OPENSSL_malloc(nbytes);
38
265k
    if (r->start == NULL)
39
0
        return 0;
40
41
265k
    r->len = nbytes;
42
265k
    r->idx[0] = r->idx[1] = r->count = 0;
43
265k
    return 1;
44
265k
}
45
46
static void ring_buf_destroy(struct ring_buf *r)
47
265k
{
48
265k
    OPENSSL_free(r->start);
49
265k
    r->start = NULL;
50
265k
    r->len = 0;
51
265k
    r->count = 0;
52
265k
}
53
54
/*
55
 * Get a pointer to the next place to write data to be pushed to the ring buffer
56
 * (idx=0), or the next data to be popped from the ring buffer (idx=1). The
57
 * pointer is written to *buf and the maximum number of bytes which can be
58
 * read/written are written to *len. After writing data to the buffer, call
59
 * ring_buf_push/pop() with the number of bytes actually read/written, which
60
 * must not exceed the returned length.
61
 */
62
static void ring_buf_head_tail(struct ring_buf *r, int idx, uint8_t **buf, size_t *len)
63
134M
{
64
134M
    size_t max_len = r->len - r->idx[idx];
65
66
134M
    if (idx == 0 && max_len > r->len - r->count)
67
12.0M
        max_len = r->len - r->count;
68
134M
    if (idx == 1 && max_len > r->count)
69
99.2M
        max_len = r->count;
70
71
134M
    *buf = (uint8_t *)r->start + r->idx[idx];
72
134M
    *len = max_len;
73
134M
}
74
75
32.1M
#define ring_buf_head(r, buf, len) ring_buf_head_tail((r), 0, (buf), (len))
76
102M
#define ring_buf_tail(r, buf, len) ring_buf_head_tail((r), 1, (buf), (len))
77
78
/*
79
 * Commit bytes to the ring buffer previously filled after a call to
80
 * ring_buf_head().
81
 */
82
static void ring_buf_push_pop(struct ring_buf *r, int idx, size_t num_bytes)
83
56.2M
{
84
56.2M
    size_t new_idx;
85
86
    /* A single push/pop op cannot wrap around, though it can reach the end.
87
     * If the caller adheres to the convention of using the length returned
88
     * by ring_buf_head/tail(), this cannot happen.
89
     */
90
56.2M
    if (!ossl_assert(num_bytes <= r->len - r->idx[idx]))
91
0
        return;
92
93
    /*
94
     * Must not overfill the buffer, or pop more than is in the buffer either.
95
     */
96
56.2M
    if (!ossl_assert(idx != 0 ? num_bytes <= r->count
97
56.2M
                              : num_bytes + r->count <= r->len))
98
0
        return;
99
100
    /* Update the index. */
101
56.2M
    new_idx = r->idx[idx] + num_bytes;
102
56.2M
    if (new_idx == r->len)
103
273k
        new_idx = 0;
104
105
56.2M
    r->idx[idx] = new_idx;
106
56.2M
    if (idx != 0)
107
24.0M
        r->count -= num_bytes;
108
32.1M
    else
109
32.1M
        r->count += num_bytes;
110
56.2M
}
111
112
32.1M
#define ring_buf_push(r, num_bytes) ring_buf_push_pop((r), 0, (num_bytes))
113
24.0M
#define ring_buf_pop(r, num_bytes) ring_buf_push_pop((r), 1, (num_bytes))
114
115
static void ring_buf_clear(struct ring_buf *r)
116
0
{
117
0
    r->idx[0] = r->idx[1] = r->count = 0;
118
0
}
119
120
static int ring_buf_resize(struct ring_buf *r, size_t nbytes)
121
41.1k
{
122
41.1k
    unsigned char *new_start;
123
124
41.1k
    if (r->start == NULL)
125
0
        return ring_buf_init(r, nbytes);
126
127
41.1k
    if (nbytes == r->len)
128
0
        return 1;
129
130
41.1k
    if (r->count > 0 && nbytes < r->len)
131
        /* fail shrinking the ring buffer when there is any data in it */
132
0
        return 0;
133
134
41.1k
    new_start = OPENSSL_realloc(r->start, nbytes);
135
41.1k
    if (new_start == NULL)
136
0
        return 0;
137
138
    /* Moving tail if it is after (or equal to) head */
139
41.1k
    if (r->count > 0) {
140
41.1k
        if (r->idx[0] <= r->idx[1]) {
141
41.1k
            size_t offset = nbytes - r->len;
142
143
41.1k
            memmove(new_start + r->idx[1] + offset, new_start + r->idx[1],
144
41.1k
                r->len - r->idx[1]);
145
41.1k
            r->idx[1] += offset;
146
41.1k
        }
147
41.1k
    } else {
148
        /* just reset the head/tail because it might be pointing outside */
149
0
        r->idx[0] = r->idx[1] = 0;
150
0
    }
151
152
41.1k
    r->start = new_start;
153
41.1k
    r->len = nbytes;
154
155
41.1k
    return 1;
156
41.1k
}
157
158
/* ===========================================================================
159
 * BIO_s_dgram_pair is documented in BIO_s_dgram_pair(3).
160
 *
161
 * INTERNAL DATA STRUCTURE
162
 *
163
 * This is managed internally by using a bytewise ring buffer which supports
164
 * pushing and popping spans of multiple bytes at once. The ring buffer stores
165
 * internal packets which look like this:
166
 *
167
 *   struct dgram_hdr hdr;
168
 *   uint8_t data[];
169
 *
170
 * The header contains the length of the data and metadata such as
171
 * source/destination addresses.
172
 *
173
 * The datagram pair BIO is designed to support both traditional
174
 * BIO_read/BIO_write (likely to be used by applications) as well as
175
 * BIO_recvmmsg/BIO_sendmmsg.
176
 */
177
struct bio_dgram_pair_st;
178
static int dgram_pair_write(BIO *bio, const char *buf, int sz_);
179
static int dgram_pair_read(BIO *bio, char *buf, int sz_);
180
static int dgram_mem_read(BIO *bio, char *buf, int sz_);
181
static long dgram_pair_ctrl(BIO *bio, int cmd, long num, void *ptr);
182
static long dgram_mem_ctrl(BIO *bio, int cmd, long num, void *ptr);
183
static int dgram_pair_init(BIO *bio);
184
static int dgram_mem_init(BIO *bio);
185
static int dgram_pair_free(BIO *bio);
186
static int dgram_pair_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride,
187
    size_t num_msg, uint64_t flags,
188
    size_t *num_processed);
189
static int dgram_pair_recvmmsg(BIO *b, BIO_MSG *msg, size_t stride,
190
    size_t num_msg, uint64_t flags,
191
    size_t *num_processed);
192
193
static int dgram_pair_ctrl_destroy_bio_pair(BIO *bio1);
194
static size_t dgram_pair_read_inner(struct bio_dgram_pair_st *b, uint8_t *buf,
195
    size_t sz);
196
197
93.1M
#define BIO_MSG_N(array, n) (*(BIO_MSG *)((char *)(array) + (n) * stride))
198
199
static const BIO_METHOD dgram_pair_method = {
200
    BIO_TYPE_DGRAM_PAIR,
201
    "BIO dgram pair",
202
    bwrite_conv,
203
    dgram_pair_write,
204
    bread_conv,
205
    dgram_pair_read,
206
    NULL, /* dgram_pair_puts */
207
    NULL, /* dgram_pair_gets */
208
    dgram_pair_ctrl,
209
    dgram_pair_init,
210
    dgram_pair_free,
211
    NULL, /* dgram_pair_callback_ctrl */
212
    dgram_pair_sendmmsg,
213
    dgram_pair_recvmmsg,
214
};
215
216
static const BIO_METHOD dgram_mem_method = {
217
    BIO_TYPE_DGRAM_MEM,
218
    "BIO dgram mem",
219
    bwrite_conv,
220
    dgram_pair_write,
221
    bread_conv,
222
    dgram_mem_read,
223
    NULL, /* dgram_pair_puts */
224
    NULL, /* dgram_pair_gets */
225
    dgram_mem_ctrl,
226
    dgram_mem_init,
227
    dgram_pair_free,
228
    NULL, /* dgram_pair_callback_ctrl */
229
    dgram_pair_sendmmsg,
230
    dgram_pair_recvmmsg,
231
};
232
233
const BIO_METHOD *BIO_s_dgram_pair(void)
234
0
{
235
0
    return &dgram_pair_method;
236
0
}
237
238
const BIO_METHOD *BIO_s_dgram_mem(void)
239
265k
{
240
265k
    return &dgram_mem_method;
241
265k
}
242
243
struct dgram_hdr {
244
    size_t len; /* payload length in bytes, not including this struct */
245
    BIO_ADDR src_addr, dst_addr; /* family == 0: not present */
246
};
247
248
struct bio_dgram_pair_st {
249
    /* The other half of the BIO pair. NULL for dgram_mem. */
250
    BIO *peer;
251
    /* Writes are directed to our own ringbuf and reads to our peer. */
252
    struct ring_buf rbuf;
253
    /* Requested size of rbuf buffer in bytes once we initialize. */
254
    size_t req_buf_len;
255
    /* Largest possible datagram size */
256
    size_t mtu;
257
    /* Capability flags. */
258
    uint32_t cap;
259
    /* The local address to use (if set) */
260
    BIO_ADDR *local_addr;
261
    /*
262
     * This lock protects updates to our rbuf. Since writes are directed to our
263
     * own rbuf, this means we use this lock for writes and our peer's lock for
264
     * reads.
265
     */
266
    CRYPTO_RWLOCK *lock;
267
    unsigned int no_trunc : 1; /* Reads fail if they would truncate */
268
    unsigned int local_addr_enable : 1; /* Can use BIO_MSG->local? */
269
    unsigned int role : 1; /* Determines lock order */
270
    unsigned int grows_on_write : 1; /* Set for BIO_s_dgram_mem only */
271
};
272
273
0
#define MIN_BUF_LEN (1024)
274
275
177M
#define is_dgram_pair(b) (b->peer != NULL)
276
277
static int dgram_pair_init(BIO *bio)
278
265k
{
279
265k
    struct bio_dgram_pair_st *b = OPENSSL_zalloc(sizeof(*b));
280
281
265k
    if (b == NULL)
282
0
        return 0;
283
284
265k
    b->mtu = 1472; /* conservative default MTU */
285
    /* default buffer size */
286
265k
    b->req_buf_len = 9 * (sizeof(struct dgram_hdr) + b->mtu);
287
288
265k
    b->lock = CRYPTO_THREAD_lock_new();
289
265k
    if (b->lock == NULL) {
290
0
        OPENSSL_free(b);
291
0
        return 0;
292
0
    }
293
294
265k
    bio->ptr = b;
295
265k
    return 1;
296
265k
}
297
298
static int dgram_mem_init(BIO *bio)
299
265k
{
300
265k
    struct bio_dgram_pair_st *b;
301
302
265k
    if (!dgram_pair_init(bio))
303
0
        return 0;
304
305
265k
    b = bio->ptr;
306
307
265k
    if (ring_buf_init(&b->rbuf, b->req_buf_len) == 0) {
308
0
        dgram_pair_free(bio);
309
0
        ERR_raise(ERR_LIB_BIO, ERR_R_BIO_LIB);
310
0
        return 0;
311
0
    }
312
313
265k
    b->grows_on_write = 1;
314
315
265k
    bio->init = 1;
316
265k
    return 1;
317
265k
}
318
319
static int dgram_pair_free(BIO *bio)
320
265k
{
321
265k
    struct bio_dgram_pair_st *b;
322
323
265k
    if (bio == NULL)
324
0
        return 0;
325
326
265k
    b = bio->ptr;
327
265k
    if (!ossl_assert(b != NULL))
328
0
        return 0;
329
330
    /* We are being freed. Disconnect any peer and destroy buffers. */
331
265k
    dgram_pair_ctrl_destroy_bio_pair(bio);
332
333
265k
    CRYPTO_THREAD_lock_free(b->lock);
334
265k
    OPENSSL_free(b);
335
265k
    return 1;
336
265k
}
337
338
/* BIO_make_bio_pair (BIO_C_MAKE_BIO_PAIR) */
339
static int dgram_pair_ctrl_make_bio_pair(BIO *bio1, BIO *bio2)
340
0
{
341
0
    struct bio_dgram_pair_st *b1, *b2;
342
343
    /* peer must be non-NULL. */
344
0
    if (bio1 == NULL || bio2 == NULL) {
345
0
        ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
346
0
        return 0;
347
0
    }
348
349
    /* Ensure the BIO we have been passed is actually a dgram pair BIO. */
350
0
    if (bio1->method != &dgram_pair_method || bio2->method != &dgram_pair_method) {
351
0
        ERR_raise_data(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT,
352
0
            "both BIOs must be BIO_dgram_pair");
353
0
        return 0;
354
0
    }
355
356
0
    b1 = bio1->ptr;
357
0
    b2 = bio2->ptr;
358
359
0
    if (!ossl_assert(b1 != NULL && b2 != NULL)) {
360
0
        ERR_raise(ERR_LIB_BIO, BIO_R_UNINITIALIZED);
361
0
        return 0;
362
0
    }
363
364
    /*
365
     * This ctrl cannot be used to associate a BIO pair half which is already
366
     * associated.
367
     */
368
0
    if (b1->peer != NULL || b2->peer != NULL) {
369
0
        ERR_raise_data(ERR_LIB_BIO, BIO_R_IN_USE,
370
0
            "cannot associate a BIO_dgram_pair which is already in use");
371
0
        return 0;
372
0
    }
373
374
0
    if (!ossl_assert(b1->req_buf_len >= MIN_BUF_LEN
375
0
            && b2->req_buf_len >= MIN_BUF_LEN)) {
376
0
        ERR_raise(ERR_LIB_BIO, BIO_R_UNINITIALIZED);
377
0
        return 0;
378
0
    }
379
380
0
    if (b1->rbuf.len != b1->req_buf_len)
381
0
        if (ring_buf_init(&b1->rbuf, b1->req_buf_len) == 0) {
382
0
            ERR_raise(ERR_LIB_BIO, ERR_R_BIO_LIB);
383
0
            return 0;
384
0
        }
385
386
0
    if (b2->rbuf.len != b2->req_buf_len)
387
0
        if (ring_buf_init(&b2->rbuf, b2->req_buf_len) == 0) {
388
0
            ERR_raise(ERR_LIB_BIO, ERR_R_BIO_LIB);
389
0
            ring_buf_destroy(&b1->rbuf);
390
0
            return 0;
391
0
        }
392
393
0
    b1->peer = bio2;
394
0
    b2->peer = bio1;
395
0
    b1->role = 0;
396
0
    b2->role = 1;
397
0
    bio1->init = 1;
398
0
    bio2->init = 1;
399
0
    return 1;
400
0
}
401
402
/* BIO_destroy_bio_pair (BIO_C_DESTROY_BIO_PAIR) */
403
static int dgram_pair_ctrl_destroy_bio_pair(BIO *bio1)
404
265k
{
405
265k
    BIO *bio2;
406
265k
    struct bio_dgram_pair_st *b1 = bio1->ptr, *b2;
407
408
265k
    ring_buf_destroy(&b1->rbuf);
409
265k
    bio1->init = 0;
410
411
265k
    BIO_ADDR_free(b1->local_addr);
412
413
    /* Early return if we don't have a peer. */
414
265k
    if (b1->peer == NULL)
415
265k
        return 1;
416
417
0
    bio2 = b1->peer;
418
0
    b2 = bio2->ptr;
419
420
    /* Invariant. */
421
0
    if (!ossl_assert(b2->peer == bio1))
422
0
        return 0;
423
424
    /* Free buffers. */
425
0
    ring_buf_destroy(&b2->rbuf);
426
427
0
    bio2->init = 0;
428
0
    b1->peer = NULL;
429
0
    b2->peer = NULL;
430
0
    return 1;
431
0
}
432
433
/* BIO_eof (BIO_CTRL_EOF) */
434
static int dgram_pair_ctrl_eof(BIO *bio)
435
0
{
436
0
    struct bio_dgram_pair_st *b = bio->ptr, *peerb;
437
438
0
    if (!ossl_assert(b != NULL))
439
0
        return -1;
440
441
    /* If we aren't initialized, we can never read anything */
442
0
    if (!bio->init)
443
0
        return 1;
444
0
    if (!is_dgram_pair(b))
445
0
        return 0;
446
447
0
    peerb = b->peer->ptr;
448
0
    if (!ossl_assert(peerb != NULL))
449
0
        return -1;
450
451
    /*
452
     * Since we are emulating datagram semantics, never indicate EOF so long as
453
     * we have a peer.
454
     */
455
0
    return 0;
456
0
}
457
458
/* BIO_set_write_buf_size (BIO_C_SET_WRITE_BUF_SIZE) */
459
static int dgram_pair_ctrl_set_write_buf_size(BIO *bio, size_t len)
460
0
{
461
0
    struct bio_dgram_pair_st *b = bio->ptr;
462
463
    /* Changing buffer sizes is not permitted while a peer is connected. */
464
0
    if (b->peer != NULL) {
465
0
        ERR_raise(ERR_LIB_BIO, BIO_R_IN_USE);
466
0
        return 0;
467
0
    }
468
469
    /* Enforce minimum size. */
470
0
    if (len < MIN_BUF_LEN)
471
0
        len = MIN_BUF_LEN;
472
473
0
    if (b->rbuf.start != NULL) {
474
0
        if (!ring_buf_resize(&b->rbuf, len))
475
0
            return 0;
476
0
    }
477
478
0
    b->req_buf_len = len;
479
0
    b->grows_on_write = 0;
480
0
    return 1;
481
0
}
482
483
/* BIO_reset (BIO_CTRL_RESET) */
484
static int dgram_pair_ctrl_reset(BIO *bio)
485
0
{
486
0
    struct bio_dgram_pair_st *b = bio->ptr;
487
488
0
    ring_buf_clear(&b->rbuf);
489
0
    return 1;
490
0
}
491
492
/* BIO_pending (BIO_CTRL_PENDING) (Threadsafe) */
493
static size_t dgram_pair_ctrl_pending(BIO *bio)
494
0
{
495
0
    size_t saved_idx, saved_count;
496
0
    struct bio_dgram_pair_st *b = bio->ptr, *readb;
497
0
    struct dgram_hdr hdr;
498
0
    size_t l;
499
500
    /* Safe to check; init may not change during this call */
501
0
    if (!bio->init)
502
0
        return 0;
503
0
    if (is_dgram_pair(b))
504
0
        readb = b->peer->ptr;
505
0
    else
506
0
        readb = b;
507
508
0
    if (CRYPTO_THREAD_write_lock(readb->lock) == 0)
509
0
        return 0;
510
511
0
    saved_idx = readb->rbuf.idx[1];
512
0
    saved_count = readb->rbuf.count;
513
514
0
    l = dgram_pair_read_inner(readb, (uint8_t *)&hdr, sizeof(hdr));
515
516
0
    readb->rbuf.idx[1] = saved_idx;
517
0
    readb->rbuf.count = saved_count;
518
519
0
    CRYPTO_THREAD_unlock(readb->lock);
520
521
0
    if (!ossl_assert(l == 0 || l == sizeof(hdr)))
522
0
        return 0;
523
524
0
    return l > 0 ? hdr.len : 0;
525
0
}
526
527
/* BIO_get_write_guarantee (BIO_C_GET_WRITE_GUARANTEE) (Threadsafe) */
528
static size_t dgram_pair_ctrl_get_write_guarantee(BIO *bio)
529
0
{
530
0
    size_t l;
531
0
    struct bio_dgram_pair_st *b = bio->ptr;
532
533
0
    if (CRYPTO_THREAD_read_lock(b->lock) == 0)
534
0
        return 0;
535
536
0
    l = b->rbuf.len - b->rbuf.count;
537
0
    if (l >= sizeof(struct dgram_hdr))
538
0
        l -= sizeof(struct dgram_hdr);
539
540
    /*
541
     * If the amount of buffer space would not be enough to accommodate the
542
     * worst-case size of a datagram, report no space available.
543
     */
544
0
    if (l < b->mtu)
545
0
        l = 0;
546
547
0
    CRYPTO_THREAD_unlock(b->lock);
548
0
    return l;
549
0
}
550
551
/* BIO_dgram_get_local_addr_cap (BIO_CTRL_DGRAM_GET_LOCAL_ADDR_CAP) */
552
static int dgram_pair_ctrl_get_local_addr_cap(BIO *bio)
553
0
{
554
0
    struct bio_dgram_pair_st *b = bio->ptr, *readb;
555
556
0
    if (!bio->init)
557
0
        return 0;
558
559
0
    if (is_dgram_pair(b))
560
0
        readb = b->peer->ptr;
561
0
    else
562
0
        readb = b;
563
564
0
    return (~readb->cap & (BIO_DGRAM_CAP_HANDLES_SRC_ADDR | BIO_DGRAM_CAP_PROVIDES_DST_ADDR)) == 0;
565
0
}
566
567
/* BIO_dgram_get_effective_caps (BIO_CTRL_DGRAM_GET_EFFECTIVE_CAPS) */
568
static int dgram_pair_ctrl_get_effective_caps(BIO *bio)
569
0
{
570
0
    struct bio_dgram_pair_st *b = bio->ptr, *peerb;
571
572
0
    if (b->peer == NULL)
573
0
        return 0;
574
575
0
    peerb = b->peer->ptr;
576
577
0
    return peerb->cap;
578
0
}
579
580
/* BIO_dgram_get_caps (BIO_CTRL_DGRAM_GET_CAPS) */
581
static uint32_t dgram_pair_ctrl_get_caps(BIO *bio)
582
134k
{
583
134k
    struct bio_dgram_pair_st *b = bio->ptr;
584
585
134k
    return b->cap;
586
134k
}
587
588
/* BIO_dgram_set_caps (BIO_CTRL_DGRAM_SET_CAPS) */
589
static int dgram_pair_ctrl_set_caps(BIO *bio, uint32_t caps)
590
52.2k
{
591
52.2k
    struct bio_dgram_pair_st *b = bio->ptr;
592
593
52.2k
    b->cap = caps;
594
52.2k
    return 1;
595
52.2k
}
596
597
/* BIO_dgram_get_local_addr_enable (BIO_CTRL_DGRAM_GET_LOCAL_ADDR_ENABLE) */
598
static int dgram_pair_ctrl_get_local_addr_enable(BIO *bio)
599
0
{
600
0
    struct bio_dgram_pair_st *b = bio->ptr;
601
602
0
    return b->local_addr_enable;
603
0
}
604
605
/* BIO_dgram_set_local_addr_enable (BIO_CTRL_DGRAM_SET_LOCAL_ADDR_ENABLE) */
606
static int dgram_pair_ctrl_set_local_addr_enable(BIO *bio, int enable)
607
0
{
608
0
    struct bio_dgram_pair_st *b = bio->ptr;
609
610
0
    if (dgram_pair_ctrl_get_local_addr_cap(bio) == 0)
611
0
        return 0;
612
613
0
    b->local_addr_enable = (enable != 0 ? 1 : 0);
614
0
    return 1;
615
0
}
616
617
/* BIO_dgram_get_mtu (BIO_CTRL_DGRAM_GET_MTU) */
618
static int dgram_pair_ctrl_get_mtu(BIO *bio)
619
61.6k
{
620
61.6k
    struct bio_dgram_pair_st *b = bio->ptr;
621
622
61.6k
    return b->mtu;
623
61.6k
}
624
625
/* BIO_dgram_set_mtu (BIO_CTRL_DGRAM_SET_MTU) */
626
static int dgram_pair_ctrl_set_mtu(BIO *bio, size_t mtu)
627
0
{
628
0
    struct bio_dgram_pair_st *b = bio->ptr, *peerb;
629
630
0
    b->mtu = mtu;
631
632
0
    if (b->peer != NULL) {
633
0
        peerb = b->peer->ptr;
634
0
        peerb->mtu = mtu;
635
0
    }
636
637
0
    return 1;
638
0
}
639
640
/* BIO_dgram_set0_local_addr (BIO_CTRL_DGRAM_SET0_LOCAL_ADDR) */
641
static int dgram_pair_ctrl_set0_local_addr(BIO *bio, BIO_ADDR *addr)
642
0
{
643
0
    struct bio_dgram_pair_st *b = bio->ptr;
644
645
0
    BIO_ADDR_free(b->local_addr);
646
0
    b->local_addr = addr;
647
0
    return 1;
648
0
}
649
650
/* Partially threadsafe (some commands) */
651
static long dgram_mem_ctrl(BIO *bio, int cmd, long num, void *ptr)
652
66.6M
{
653
66.6M
    long ret = 1;
654
66.6M
    struct bio_dgram_pair_st *b = bio->ptr;
655
656
66.6M
    if (!ossl_assert(b != NULL))
657
0
        return 0;
658
659
66.6M
    switch (cmd) {
660
    /*
661
     * BIO_set_write_buf_size: Set the size of the ring buffer used for storing
662
     * datagrams. No more writes can be performed once the buffer is filled up,
663
     * until reads are performed. This cannot be used after a peer is connected.
664
     */
665
0
    case BIO_C_SET_WRITE_BUF_SIZE: /* Non-threadsafe */
666
0
        ret = (long)dgram_pair_ctrl_set_write_buf_size(bio, (size_t)num);
667
0
        break;
668
669
    /*
670
     * BIO_get_write_buf_size: Get ring buffer size.
671
     */
672
0
    case BIO_C_GET_WRITE_BUF_SIZE: /* Non-threadsafe */
673
0
        ret = (long)b->req_buf_len;
674
0
        break;
675
676
    /*
677
     * BIO_reset: Clear all data which was written to this side of the pair.
678
     */
679
0
    case BIO_CTRL_RESET: /* Non-threadsafe */
680
0
        dgram_pair_ctrl_reset(bio);
681
0
        break;
682
683
    /*
684
     * BIO_get_write_guarantee: Any BIO_write providing a buffer less than or
685
     * equal to this value is guaranteed to succeed.
686
     */
687
0
    case BIO_C_GET_WRITE_GUARANTEE: /* Threadsafe */
688
0
        ret = (long)dgram_pair_ctrl_get_write_guarantee(bio);
689
0
        break;
690
691
    /* BIO_pending: Bytes available to read. */
692
0
    case BIO_CTRL_PENDING: /* Threadsafe */
693
0
        ret = (long)dgram_pair_ctrl_pending(bio);
694
0
        break;
695
696
    /* BIO_flush: No-op. */
697
0
    case BIO_CTRL_FLUSH: /* Threadsafe */
698
0
        break;
699
700
    /* BIO_dgram_get_no_trunc */
701
0
    case BIO_CTRL_DGRAM_GET_NO_TRUNC: /* Non-threadsafe */
702
0
        ret = (long)b->no_trunc;
703
0
        break;
704
705
    /* BIO_dgram_set_no_trunc */
706
0
    case BIO_CTRL_DGRAM_SET_NO_TRUNC: /* Non-threadsafe */
707
0
        b->no_trunc = (num > 0);
708
0
        break;
709
710
    /* BIO_dgram_get_local_addr_enable */
711
0
    case BIO_CTRL_DGRAM_GET_LOCAL_ADDR_ENABLE: /* Non-threadsafe */
712
0
        *(int *)ptr = (int)dgram_pair_ctrl_get_local_addr_enable(bio);
713
0
        break;
714
715
    /* BIO_dgram_set_local_addr_enable */
716
0
    case BIO_CTRL_DGRAM_SET_LOCAL_ADDR_ENABLE: /* Non-threadsafe */
717
0
        ret = (long)dgram_pair_ctrl_set_local_addr_enable(bio, num);
718
0
        break;
719
720
    /* BIO_dgram_get_local_addr_cap: Can local addresses be supported? */
721
0
    case BIO_CTRL_DGRAM_GET_LOCAL_ADDR_CAP: /* Non-threadsafe */
722
0
        ret = (long)dgram_pair_ctrl_get_local_addr_cap(bio);
723
0
        break;
724
725
    /* BIO_dgram_get_effective_caps */
726
88.9k
    case BIO_CTRL_DGRAM_GET_EFFECTIVE_CAPS: /* Non-threadsafe */
727
    /* BIO_dgram_get_caps */
728
88.9k
    case BIO_CTRL_DGRAM_GET_CAPS: /* Non-threadsafe */
729
88.9k
        ret = (long)dgram_pair_ctrl_get_caps(bio);
730
88.9k
        break;
731
732
    /* BIO_dgram_set_caps */
733
29.6k
    case BIO_CTRL_DGRAM_SET_CAPS: /* Non-threadsafe */
734
29.6k
        ret = (long)dgram_pair_ctrl_set_caps(bio, (uint32_t)num);
735
29.6k
        break;
736
737
    /* BIO_dgram_get_mtu */
738
39.1k
    case BIO_CTRL_DGRAM_GET_MTU: /* Non-threadsafe */
739
39.1k
        ret = (long)dgram_pair_ctrl_get_mtu(bio);
740
39.1k
        break;
741
742
    /* BIO_dgram_set_mtu */
743
0
    case BIO_CTRL_DGRAM_SET_MTU: /* Non-threadsafe */
744
0
        ret = (long)dgram_pair_ctrl_set_mtu(bio, (uint32_t)num);
745
0
        break;
746
747
0
    case BIO_CTRL_DGRAM_SET0_LOCAL_ADDR:
748
0
        ret = (long)dgram_pair_ctrl_set0_local_addr(bio, (BIO_ADDR *)ptr);
749
0
        break;
750
751
    /*
752
     * BIO_eof: Returns whether this half of the BIO pair is empty of data to
753
     * read.
754
     */
755
0
    case BIO_CTRL_EOF: /* Non-threadsafe */
756
0
        ret = (long)dgram_pair_ctrl_eof(bio);
757
0
        break;
758
759
66.5M
    default:
760
66.5M
        ret = 0;
761
66.5M
        break;
762
66.6M
    }
763
764
66.6M
    return ret;
765
66.6M
}
766
767
static long dgram_pair_ctrl(BIO *bio, int cmd, long num, void *ptr)
768
0
{
769
0
    long ret = 1;
770
771
0
    switch (cmd) {
772
    /*
773
     * BIO_make_bio_pair: this is usually used by BIO_new_dgram_pair, though it
774
     * may be used manually after manually creating each half of a BIO pair
775
     * using BIO_new. This only needs to be called on one of the BIOs.
776
     */
777
0
    case BIO_C_MAKE_BIO_PAIR: /* Non-threadsafe */
778
0
        ret = (long)dgram_pair_ctrl_make_bio_pair(bio, (BIO *)ptr);
779
0
        break;
780
781
    /*
782
     * BIO_destroy_bio_pair: Manually disconnect two halves of a BIO pair so
783
     * that they are no longer peers.
784
     */
785
0
    case BIO_C_DESTROY_BIO_PAIR: /* Non-threadsafe */
786
0
        dgram_pair_ctrl_destroy_bio_pair(bio);
787
0
        break;
788
789
    /* BIO_dgram_get_effective_caps */
790
0
    case BIO_CTRL_DGRAM_GET_EFFECTIVE_CAPS: /* Non-threadsafe */
791
0
        ret = (long)dgram_pair_ctrl_get_effective_caps(bio);
792
0
        break;
793
794
0
    default:
795
0
        ret = dgram_mem_ctrl(bio, cmd, num, ptr);
796
0
        break;
797
0
    }
798
799
0
    return ret;
800
0
}
801
802
int BIO_new_bio_dgram_pair(BIO **pbio1, size_t writebuf1,
803
    BIO **pbio2, size_t writebuf2)
804
0
{
805
0
    int ret = 0;
806
0
    long r;
807
0
    BIO *bio1 = NULL, *bio2 = NULL;
808
809
0
    bio1 = BIO_new(BIO_s_dgram_pair());
810
0
    if (bio1 == NULL)
811
0
        goto err;
812
813
0
    bio2 = BIO_new(BIO_s_dgram_pair());
814
0
    if (bio2 == NULL)
815
0
        goto err;
816
817
0
    if (writebuf1 > 0) {
818
0
        r = BIO_set_write_buf_size(bio1, writebuf1);
819
0
        if (r == 0)
820
0
            goto err;
821
0
    }
822
823
0
    if (writebuf2 > 0) {
824
0
        r = BIO_set_write_buf_size(bio2, writebuf2);
825
0
        if (r == 0)
826
0
            goto err;
827
0
    }
828
829
0
    r = BIO_make_bio_pair(bio1, bio2);
830
0
    if (r == 0)
831
0
        goto err;
832
833
0
    ret = 1;
834
0
err:
835
0
    if (ret == 0) {
836
0
        BIO_free(bio1);
837
0
        bio1 = NULL;
838
0
        BIO_free(bio2);
839
0
        bio2 = NULL;
840
0
    }
841
842
0
    *pbio1 = bio1;
843
0
    *pbio2 = bio2;
844
0
    return ret;
845
0
}
846
847
/* Must hold peer write lock */
848
static size_t dgram_pair_read_inner(struct bio_dgram_pair_st *b, uint8_t *buf, size_t sz)
849
102M
{
850
102M
    size_t total_read = 0;
851
852
    /*
853
     * We repeat pops from the ring buffer for as long as we have more
854
     * application *buffer to fill until we fail. We may not be able to pop
855
     * enough data to fill the buffer in one operation if the ring buffer wraps
856
     * around, but there may still be more data available.
857
     */
858
126M
    while (sz > 0) {
859
102M
        uint8_t *src_buf = NULL;
860
102M
        size_t src_len = 0;
861
862
        /*
863
         * There are two BIO instances, each with a ringbuf. We read from the
864
         * peer ringbuf and write to our own ringbuf.
865
         */
866
102M
        ring_buf_tail(&b->rbuf, &src_buf, &src_len);
867
102M
        if (src_len == 0)
868
78.7M
            break;
869
870
24.0M
        if (src_len > sz)
871
14.9M
            src_len = sz;
872
873
24.0M
        if (buf != NULL)
874
23.9M
            memcpy(buf, src_buf, src_len);
875
876
24.0M
        ring_buf_pop(&b->rbuf, src_len);
877
878
24.0M
        if (buf != NULL)
879
23.9M
            buf += src_len;
880
24.0M
        total_read += src_len;
881
24.0M
        sz -= src_len;
882
24.0M
    }
883
884
102M
    return total_read;
885
102M
}
886
887
/*
888
 * Must hold peer write lock. Returns number of bytes processed or negated BIO
889
 * response code.
890
 */
891
static ossl_ssize_t dgram_pair_read_actual(BIO *bio, char *buf, size_t sz,
892
    BIO_ADDR *local, BIO_ADDR *peer,
893
    int is_multi)
894
90.6M
{
895
90.6M
    size_t l, trunc = 0, saved_idx, saved_count;
896
90.6M
    struct bio_dgram_pair_st *b = bio->ptr, *readb;
897
90.6M
    struct dgram_hdr hdr;
898
899
90.6M
    if (!is_multi)
900
27.0k
        BIO_clear_retry_flags(bio);
901
902
90.6M
    if (!bio->init)
903
0
        return -BIO_R_UNINITIALIZED;
904
905
90.6M
    if (!ossl_assert(b != NULL))
906
0
        return -BIO_R_TRANSFER_ERROR;
907
908
90.6M
    if (is_dgram_pair(b))
909
0
        readb = b->peer->ptr;
910
90.6M
    else
911
90.6M
        readb = b;
912
90.6M
    if (!ossl_assert(readb != NULL && readb->rbuf.start != NULL))
913
0
        return -BIO_R_TRANSFER_ERROR;
914
915
90.6M
    if (sz > 0 && buf == NULL)
916
0
        return -BIO_R_INVALID_ARGUMENT;
917
918
    /* If the caller wants to know the local address, it must be enabled */
919
90.6M
    if (local != NULL && b->local_addr_enable == 0)
920
0
        return -BIO_R_LOCAL_ADDR_NOT_AVAILABLE;
921
922
    /* Read the header. */
923
90.6M
    saved_idx = readb->rbuf.idx[1];
924
90.6M
    saved_count = readb->rbuf.count;
925
90.6M
    l = dgram_pair_read_inner(readb, (uint8_t *)&hdr, sizeof(hdr));
926
90.6M
    if (l == 0) {
927
        /* Buffer was empty. */
928
78.7M
        if (!is_multi)
929
11.1k
            BIO_set_retry_read(bio);
930
78.7M
        return -BIO_R_NON_FATAL;
931
78.7M
    }
932
933
11.9M
    if (!ossl_assert(l == sizeof(hdr)))
934
        /*
935
         * This should not be possible as headers (and their following payloads)
936
         * should always be written atomically.
937
         */
938
0
        return -BIO_R_BROKEN_PIPE;
939
940
11.9M
    if (sz > hdr.len) {
941
11.8M
        sz = hdr.len;
942
11.8M
    } else if (sz < hdr.len) {
943
        /* Truncation is occurring. */
944
44.1k
        trunc = hdr.len - sz;
945
44.1k
        if (b->no_trunc) {
946
            /* Restore original state. */
947
0
            readb->rbuf.idx[1] = saved_idx;
948
0
            readb->rbuf.count = saved_count;
949
0
            return -BIO_R_NON_FATAL;
950
0
        }
951
44.1k
    }
952
953
11.9M
    l = dgram_pair_read_inner(readb, (uint8_t *)buf, sz);
954
11.9M
    if (!ossl_assert(l == sz))
955
        /* We were somehow not able to read the entire datagram. */
956
0
        return -BIO_R_TRANSFER_ERROR;
957
958
    /*
959
     * If the datagram was truncated due to an inadequate buffer, discard the
960
     * remainder.
961
     */
962
11.9M
    if (trunc > 0 && !ossl_assert(dgram_pair_read_inner(readb, NULL, trunc) == trunc))
963
        /* We were somehow not able to read/skip the entire datagram. */
964
0
        return -BIO_R_TRANSFER_ERROR;
965
966
11.9M
    if (local != NULL)
967
0
        *local = hdr.dst_addr;
968
11.9M
    if (peer != NULL)
969
11.9M
        *peer = hdr.src_addr;
970
971
11.9M
    return (ossl_ssize_t)l;
972
11.9M
}
973
974
/* Threadsafe */
975
static int dgram_pair_lock_both_write(struct bio_dgram_pair_st *a,
976
    struct bio_dgram_pair_st *b)
977
0
{
978
0
    struct bio_dgram_pair_st *x, *y;
979
980
0
    x = (a->role == 1) ? a : b;
981
0
    y = (a->role == 1) ? b : a;
982
983
0
    if (!ossl_assert(a->role != b->role))
984
0
        return 0;
985
986
0
    if (!ossl_assert(a != b && x != y))
987
0
        return 0;
988
989
0
    if (CRYPTO_THREAD_write_lock(x->lock) == 0)
990
0
        return 0;
991
992
0
    if (CRYPTO_THREAD_write_lock(y->lock) == 0) {
993
0
        CRYPTO_THREAD_unlock(x->lock);
994
0
        return 0;
995
0
    }
996
997
0
    return 1;
998
0
}
999
1000
static void dgram_pair_unlock_both(struct bio_dgram_pair_st *a,
1001
    struct bio_dgram_pair_st *b)
1002
0
{
1003
0
    CRYPTO_THREAD_unlock(a->lock);
1004
0
    CRYPTO_THREAD_unlock(b->lock);
1005
0
}
1006
1007
/* Threadsafe */
1008
static int dgram_pair_read(BIO *bio, char *buf, int sz_)
1009
0
{
1010
0
    int ret;
1011
0
    ossl_ssize_t l;
1012
0
    struct bio_dgram_pair_st *b = bio->ptr, *peerb;
1013
1014
0
    if (sz_ < 0) {
1015
0
        ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
1016
0
        return -1;
1017
0
    }
1018
1019
0
    if (b->peer == NULL) {
1020
0
        ERR_raise(ERR_LIB_BIO, BIO_R_BROKEN_PIPE);
1021
0
        return -1;
1022
0
    }
1023
1024
0
    peerb = b->peer->ptr;
1025
1026
    /*
1027
     * For BIO_read we have to acquire both locks because we touch the retry
1028
     * flags on the local bio. (This is avoided in the recvmmsg case as it does
1029
     * not touch the retry flags.)
1030
     */
1031
0
    if (dgram_pair_lock_both_write(peerb, b) == 0) {
1032
0
        ERR_raise(ERR_LIB_BIO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
1033
0
        return -1;
1034
0
    }
1035
1036
0
    l = dgram_pair_read_actual(bio, buf, (size_t)sz_, NULL, NULL, 0);
1037
0
    if (l < 0) {
1038
0
        if (l != -BIO_R_NON_FATAL)
1039
0
            ERR_raise(ERR_LIB_BIO, -l);
1040
0
        ret = -1;
1041
0
    } else {
1042
0
        ret = (int)l;
1043
0
    }
1044
1045
0
    dgram_pair_unlock_both(peerb, b);
1046
0
    return ret;
1047
0
}
1048
1049
/* Threadsafe */
1050
static int dgram_pair_recvmmsg(BIO *bio, BIO_MSG *msg,
1051
    size_t stride, size_t num_msg,
1052
    uint64_t flags,
1053
    size_t *num_processed)
1054
78.7M
{
1055
78.7M
    int ret;
1056
78.7M
    ossl_ssize_t l;
1057
78.7M
    BIO_MSG *m;
1058
78.7M
    size_t i;
1059
78.7M
    struct bio_dgram_pair_st *b = bio->ptr, *readb;
1060
1061
78.7M
    if (num_msg == 0) {
1062
0
        *num_processed = 0;
1063
0
        return 1;
1064
0
    }
1065
1066
78.7M
    if (!bio->init) {
1067
0
        ERR_raise(ERR_LIB_BIO, BIO_R_BROKEN_PIPE);
1068
0
        *num_processed = 0;
1069
0
        return 0;
1070
0
    }
1071
1072
78.7M
    if (is_dgram_pair(b))
1073
0
        readb = b->peer->ptr;
1074
78.7M
    else
1075
78.7M
        readb = b;
1076
1077
78.7M
    if (CRYPTO_THREAD_write_lock(readb->lock) == 0) {
1078
0
        ERR_raise(ERR_LIB_BIO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
1079
0
        *num_processed = 0;
1080
0
        return 0;
1081
0
    }
1082
1083
90.7M
    for (i = 0; i < num_msg; ++i) {
1084
90.6M
        m = &BIO_MSG_N(msg, i);
1085
90.6M
        l = dgram_pair_read_actual(bio, m->data, m->data_len,
1086
90.6M
            m->local, m->peer, 1);
1087
90.6M
        if (l < 0) {
1088
78.6M
            *num_processed = i;
1089
78.6M
            if (i > 0) {
1090
8.90M
                ret = 1;
1091
69.7M
            } else {
1092
69.7M
                ERR_raise(ERR_LIB_BIO, -l);
1093
69.7M
                ret = 0;
1094
69.7M
            }
1095
78.6M
            goto out;
1096
78.6M
        }
1097
1098
11.9M
        m->data_len = l;
1099
11.9M
        m->flags = 0;
1100
11.9M
    }
1101
1102
93.5k
    *num_processed = i;
1103
93.5k
    ret = 1;
1104
78.7M
out:
1105
78.7M
    CRYPTO_THREAD_unlock(readb->lock);
1106
78.7M
    return ret;
1107
93.5k
}
1108
1109
/* Threadsafe */
1110
static int dgram_mem_read(BIO *bio, char *buf, int sz_)
1111
27.0k
{
1112
27.0k
    int ret;
1113
27.0k
    ossl_ssize_t l;
1114
27.0k
    struct bio_dgram_pair_st *b = bio->ptr;
1115
1116
27.0k
    if (sz_ < 0) {
1117
0
        ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
1118
0
        return -1;
1119
0
    }
1120
1121
27.0k
    if (CRYPTO_THREAD_write_lock(b->lock) == 0) {
1122
0
        ERR_raise(ERR_LIB_BIO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
1123
0
        return -1;
1124
0
    }
1125
1126
27.0k
    l = dgram_pair_read_actual(bio, buf, (size_t)sz_, NULL, NULL, 0);
1127
27.0k
    if (l < 0) {
1128
11.1k
        if (l != -BIO_R_NON_FATAL)
1129
11.1k
            ERR_raise(ERR_LIB_BIO, -l);
1130
11.1k
        ret = -1;
1131
15.9k
    } else {
1132
15.9k
        ret = (int)l;
1133
15.9k
    }
1134
1135
27.0k
    CRYPTO_THREAD_unlock(b->lock);
1136
27.0k
    return ret;
1137
27.0k
}
1138
1139
/*
1140
 * Calculate the array growth based on the target size.
1141
 *
1142
 * The growth factor is a rational number and is defined by a numerator
1143
 * and a denominator.  According to Andrew Koenig in his paper "Why Are
1144
 * Vectors Efficient?" from JOOP 11(5) 1998, this factor should be less
1145
 * than the golden ratio (1.618...).
1146
 *
1147
 * We use an expansion factor of 8 / 5 = 1.6
1148
 */
1149
static const size_t max_rbuf_size = SIZE_MAX / 2; /* unlimited in practice */
1150
static ossl_inline size_t compute_rbuf_growth(size_t target, size_t current)
1151
41.1k
{
1152
41.1k
    int err = 0;
1153
1154
84.7k
    while (current < target) {
1155
43.6k
        if (current >= max_rbuf_size)
1156
0
            return 0;
1157
1158
43.6k
        current = safe_muldiv_size_t(current, 8, 5, &err);
1159
43.6k
        if (err)
1160
0
            return 0;
1161
43.6k
        if (current >= max_rbuf_size)
1162
0
            current = max_rbuf_size;
1163
43.6k
    }
1164
41.1k
    return current;
1165
41.1k
}
1166
1167
/* Must hold local write lock */
1168
static size_t dgram_pair_write_inner(struct bio_dgram_pair_st *b,
1169
    const uint8_t *buf, size_t sz)
1170
31.9M
{
1171
31.9M
    size_t total_written = 0;
1172
1173
    /*
1174
     * We repeat pushes to the ring buffer for as long as we have data until we
1175
     * fail. We may not be able to push in one operation if the ring buffer
1176
     * wraps around, but there may still be more room for data.
1177
     */
1178
64.1M
    while (sz > 0) {
1179
32.1M
        size_t dst_len;
1180
32.1M
        uint8_t *dst_buf;
1181
1182
        /*
1183
         * There are two BIO instances, each with a ringbuf. We write to our own
1184
         * ringbuf and read from the peer ringbuf.
1185
         */
1186
32.1M
        ring_buf_head(&b->rbuf, &dst_buf, &dst_len);
1187
32.1M
        if (dst_len == 0) {
1188
41.1k
            size_t new_len;
1189
1190
41.1k
            if (!b->grows_on_write) /* resize only if size not set explicitly */
1191
0
                break;
1192
            /* increase the size */
1193
41.1k
            new_len = compute_rbuf_growth(b->req_buf_len + sz, b->req_buf_len);
1194
41.1k
            if (new_len == 0 || !ring_buf_resize(&b->rbuf, new_len))
1195
0
                break;
1196
41.1k
            b->req_buf_len = new_len;
1197
41.1k
        }
1198
1199
32.1M
        if (dst_len > sz)
1200
31.9M
            dst_len = sz;
1201
1202
32.1M
        memcpy(dst_buf, buf, dst_len);
1203
32.1M
        ring_buf_push(&b->rbuf, dst_len);
1204
1205
32.1M
        buf += dst_len;
1206
32.1M
        sz -= dst_len;
1207
32.1M
        total_written += dst_len;
1208
32.1M
    }
1209
1210
31.9M
    return total_written;
1211
31.9M
}
1212
1213
/*
1214
 * Must hold local write lock. Returns number of bytes processed or negated BIO
1215
 * response code.
1216
 */
1217
static ossl_ssize_t dgram_pair_write_actual(BIO *bio, const char *buf, size_t sz,
1218
    const BIO_ADDR *local, const BIO_ADDR *peer,
1219
    int is_multi)
1220
8.46M
{
1221
8.46M
    static const BIO_ADDR zero_addr;
1222
8.46M
    size_t saved_idx, saved_count;
1223
8.46M
    struct bio_dgram_pair_st *b = bio->ptr, *readb;
1224
8.46M
    struct dgram_hdr hdr = { 0 };
1225
1226
8.46M
    if (!is_multi)
1227
7.25M
        BIO_clear_retry_flags(bio);
1228
1229
8.46M
    if (!bio->init)
1230
0
        return -BIO_R_UNINITIALIZED;
1231
1232
8.46M
    if (!ossl_assert(b != NULL && b->rbuf.start != NULL))
1233
0
        return -BIO_R_TRANSFER_ERROR;
1234
1235
8.46M
    if (sz > 0 && buf == NULL)
1236
0
        return -BIO_R_INVALID_ARGUMENT;
1237
1238
8.46M
    if (local != NULL && b->local_addr_enable == 0)
1239
0
        return -BIO_R_LOCAL_ADDR_NOT_AVAILABLE;
1240
1241
8.46M
    if (is_dgram_pair(b))
1242
0
        readb = b->peer->ptr;
1243
8.46M
    else
1244
8.46M
        readb = b;
1245
8.46M
    if (peer != NULL && (readb->cap & BIO_DGRAM_CAP_HANDLES_DST_ADDR) == 0)
1246
0
        return -BIO_R_PEER_ADDR_NOT_AVAILABLE;
1247
1248
8.46M
    hdr.len = sz;
1249
8.46M
    hdr.dst_addr = (peer != NULL ? *peer : zero_addr);
1250
8.46M
    if (local == NULL)
1251
8.46M
        local = b->local_addr;
1252
8.46M
    hdr.src_addr = (local != NULL ? *local : zero_addr);
1253
1254
8.46M
    saved_idx = b->rbuf.idx[0];
1255
8.46M
    saved_count = b->rbuf.count;
1256
8.46M
    if (dgram_pair_write_inner(b, (const uint8_t *)&hdr, sizeof(hdr)) != sizeof(hdr)
1257
8.46M
        || dgram_pair_write_inner(b, (const uint8_t *)buf, sz) != sz) {
1258
        /*
1259
         * We were not able to push the header and the entirety of the payload
1260
         * onto the ring buffer, so abort and roll back the ring buffer state.
1261
         */
1262
0
        b->rbuf.idx[0] = saved_idx;
1263
0
        b->rbuf.count = saved_count;
1264
0
        if (!is_multi)
1265
0
            BIO_set_retry_write(bio);
1266
0
        return -BIO_R_NON_FATAL;
1267
0
    }
1268
1269
8.46M
    return sz;
1270
8.46M
}
1271
1272
/* Threadsafe */
1273
static int dgram_pair_write(BIO *bio, const char *buf, int sz_)
1274
13.4M
{
1275
13.4M
    int ret;
1276
13.4M
    ossl_ssize_t l;
1277
13.4M
    struct bio_dgram_pair_st *b = bio->ptr;
1278
1279
13.4M
    if (sz_ < 0) {
1280
0
        ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
1281
0
        return -1;
1282
0
    }
1283
1284
13.4M
    if (CRYPTO_THREAD_write_lock(b->lock) == 0) {
1285
0
        ERR_raise(ERR_LIB_BIO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
1286
0
        return -1;
1287
0
    }
1288
1289
13.4M
    l = dgram_pair_write_actual(bio, buf, (size_t)sz_, NULL, NULL, 0);
1290
13.4M
    if (l < 0) {
1291
0
        ERR_raise(ERR_LIB_BIO, -l);
1292
0
        ret = -1;
1293
13.4M
    } else {
1294
13.4M
        ret = (int)l;
1295
13.4M
    }
1296
1297
13.4M
    CRYPTO_THREAD_unlock(b->lock);
1298
13.4M
    return ret;
1299
13.4M
}
1300
1301
/* Threadsafe */
1302
static int dgram_pair_sendmmsg(BIO *bio, BIO_MSG *msg,
1303
    size_t stride, size_t num_msg,
1304
    uint64_t flags, size_t *num_processed)
1305
2.50M
{
1306
2.50M
    ossl_ssize_t ret, l;
1307
2.50M
    BIO_MSG *m;
1308
2.50M
    size_t i;
1309
2.50M
    struct bio_dgram_pair_st *b = bio->ptr;
1310
1311
2.50M
    if (num_msg == 0) {
1312
0
        *num_processed = 0;
1313
0
        return 1;
1314
0
    }
1315
1316
2.50M
    if (CRYPTO_THREAD_write_lock(b->lock) == 0) {
1317
0
        ERR_raise(ERR_LIB_BIO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
1318
0
        *num_processed = 0;
1319
0
        return 0;
1320
0
    }
1321
1322
5.03M
    for (i = 0; i < num_msg; ++i) {
1323
2.53M
        m = &BIO_MSG_N(msg, i);
1324
2.53M
        l = dgram_pair_write_actual(bio, m->data, m->data_len,
1325
2.53M
            m->local, m->peer, 1);
1326
2.53M
        if (l < 0) {
1327
0
            *num_processed = i;
1328
0
            if (i > 0) {
1329
0
                ret = 1;
1330
0
            } else {
1331
0
                ERR_raise(ERR_LIB_BIO, -l);
1332
0
                ret = 0;
1333
0
            }
1334
0
            goto out;
1335
0
        }
1336
1337
2.53M
        m->flags = 0;
1338
2.53M
    }
1339
1340
2.50M
    *num_processed = i;
1341
2.50M
    ret = 1;
1342
2.50M
out:
1343
2.50M
    CRYPTO_THREAD_unlock(b->lock);
1344
2.50M
    return ret;
1345
2.50M
}
1346
1347
#endif