projects
/
openssl.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Add session reuse tests.
[openssl.git]
/
apps
/
rehash.c
diff --git
a/apps/rehash.c
b/apps/rehash.c
index 672a42a2e96841deaf5213fca076b2f4a5010a16..38084a247fb854601144a38569a33193afb923a2 100644
(file)
--- a/
apps/rehash.c
+++ b/
apps/rehash.c
@@
-2,7
+2,6
@@
* C implementation based on the original Perl and shell versions
*
* Copyright (c) 2013-2014 Timo Teräs <timo.teras@iki.fi>
* C implementation based on the original Perl and shell versions
*
* Copyright (c) 2013-2014 Timo Teräs <timo.teras@iki.fi>
- * All rights reserved.
*/
/* ====================================================================
* Copyright (c) 2015 The OpenSSL Project. All rights reserved.
*/
/* ====================================================================
* Copyright (c) 2015 The OpenSSL Project. All rights reserved.
@@
-60,7
+59,7
@@
#include "apps.h"
#include "apps.h"
-#if
def unix
+#if
defined(OPENSSL_SYS_UNIX) || defined(__APPLE__)
# include <unistd.h>
# include <stdio.h>
# include <limits.h>
# include <unistd.h>
# include <stdio.h>
# include <limits.h>
@@
-75,6
+74,9
@@
# include <openssl/x509.h>
# include <openssl/x509.h>
+# ifndef NAME_MAX
+# define NAME_MAX 255
+# endif
# define MAX_COLLISIONS 256
typedef struct hentry_st {
# define MAX_COLLISIONS 256
typedef struct hentry_st {
@@
-124,7
+126,10
@@
static int bit_isset(unsigned char *set, unsigned int bit)
}
}
-static void add_entry(enum Type type, unsigned int hash, const char *filename,
+/*
+ * Process an entry; return number of errors.
+ */
+static int add_entry(enum Type type, unsigned int hash, const char *filename,
const unsigned char *digest, int need_symlink,
unsigned short old_id)
{
const unsigned char *digest, int need_symlink,
unsigned short old_id)
{
@@
-151,7
+156,7
@@
static void add_entry(enum Type type, unsigned int hash, const char *filename,
BIO_printf(bio_err,
"%s: skipping duplicate certificate in %s\n",
opt_getprog(), filename);
BIO_printf(bio_err,
"%s: skipping duplicate certificate in %s\n",
opt_getprog(), filename);
- return;
+ return
1
;
}
if (strcmp(filename, ep->filename) == 0) {
found = ep;
}
if (strcmp(filename, ep->filename) == 0) {
found = ep;
@@
-161,12
+166,16
@@
static void add_entry(enum Type type, unsigned int hash, const char *filename,
}
ep = found;
if (ep == NULL) {
}
ep = found;
if (ep == NULL) {
- if (bp->num_needed >= MAX_COLLISIONS)
- return;
+ if (bp->num_needed >= MAX_COLLISIONS) {
+ BIO_printf(bio_err,
+ "%s: hash table overflow for %s\n",
+ opt_getprog(), filename);
+ return 1;
+ }
ep = app_malloc(sizeof(*ep), "collision bucket");
*ep = nilhentry;
ep->old_id = ~0;
ep = app_malloc(sizeof(*ep), "collision bucket");
*ep = nilhentry;
ep->old_id = ~0;
- ep->filename =
BUF
_strdup(filename);
+ ep->filename =
OPENSSL
_strdup(filename);
if (bp->last_entry)
bp->last_entry->next = ep;
if (bp->first_entry == NULL)
if (bp->last_entry)
bp->last_entry->next = ep;
if (bp->first_entry == NULL)
@@
-181,14
+190,19
@@
static void add_entry(enum Type type, unsigned int hash, const char *filename,
bp->num_needed++;
memcpy(ep->digest, digest, evpmdsize);
}
bp->num_needed++;
memcpy(ep->digest, digest, evpmdsize);
}
+ return 0;
}
}
+/*
+ * Check if a symlink goes to the right spot; return 0 if okay.
+ * This can be -1 if bad filename, or an error count.
+ */
static int handle_symlink(const char *filename, const char *fullpath)
{
unsigned int hash = 0;
int i, type, id;
unsigned char ch;
static int handle_symlink(const char *filename, const char *fullpath)
{
unsigned int hash = 0;
int i, type, id;
unsigned char ch;
- char linktarget[
NAME
_MAX], *endptr;
+ char linktarget[
PATH
_MAX], *endptr;
ssize_t n;
for (i = 0; i < 8; i++) {
ssize_t n;
for (i = 0; i < 8; i++) {
@@
-214,41
+228,51
@@
static int handle_symlink(const char *filename, const char *fullpath)
return -1;
linktarget[n] = 0;
return -1;
linktarget[n] = 0;
- add_entry(type, hash, linktarget, NULL, 0, id);
- return 0;
+ return add_entry(type, hash, linktarget, NULL, 0, id);
}
}
+/*
+ * process a file, return number of errors.
+ */
static int do_file(const char *filename, const char *fullpath, enum Hash h)
{
static int do_file(const char *filename, const char *fullpath, enum Hash h)
{
- STACK_OF (X509_INFO) *inf;
+ STACK_OF (X509_INFO) *inf
= NULL
;
X509_INFO *x;
X509_NAME *name = NULL;
BIO *b;
const char *ext;
unsigned char digest[EVP_MAX_MD_SIZE];
X509_INFO *x;
X509_NAME *name = NULL;
BIO *b;
const char *ext;
unsigned char digest[EVP_MAX_MD_SIZE];
- int i, type, ret = -1;
+ int type, errs = 0;
+ size_t i;
+ /* Does it end with a recognized extension? */
if ((ext = strrchr(filename, '.')) == NULL)
if ((ext = strrchr(filename, '.')) == NULL)
-
return 0
;
- for (i = 0; i <
(int)
OSSL_NELEM(extensions); i++) {
+
goto end
;
+ for (i = 0; i < OSSL_NELEM(extensions); i++) {
if (strcasecmp(extensions[i], ext + 1) == 0)
break;
}
if (strcasecmp(extensions[i], ext + 1) == 0)
break;
}
- if (i >=
(int)
OSSL_NELEM(extensions))
-
return -1
;
+ if (i >= OSSL_NELEM(extensions))
+
goto end
;
- if ((b = BIO_new_file(fullpath, "r")) == NULL)
- return -1;
+ /* Does it have X.509 data in it? */
+ if ((b = BIO_new_file(fullpath, "r")) == NULL) {
+ BIO_printf(bio_err, "%s: skipping %s, cannot open file\n",
+ opt_getprog(), filename);
+ errs++;
+ goto end;
+ }
inf = PEM_X509_INFO_read_bio(b, NULL, NULL, NULL);
BIO_free(b);
if (inf == NULL)
inf = PEM_X509_INFO_read_bio(b, NULL, NULL, NULL);
BIO_free(b);
if (inf == NULL)
-
return -1
;
+
goto end
;
if (sk_X509_INFO_num(inf) != 1) {
BIO_printf(bio_err,
"%s: skipping %s,"
"it does not contain exactly one certificate or CRL\n",
opt_getprog(), filename);
if (sk_X509_INFO_num(inf) != 1) {
BIO_printf(bio_err,
"%s: skipping %s,"
"it does not contain exactly one certificate or CRL\n",
opt_getprog(), filename);
+ /* This is not an error. */
goto end;
}
x = sk_X509_INFO_value(inf, 0);
goto end;
}
x = sk_X509_INFO_value(inf, 0);
@@
-260,19
+284,25
@@
static int do_file(const char *filename, const char *fullpath, enum Hash h)
type = TYPE_CRL;
name = X509_CRL_get_issuer(x->crl);
X509_CRL_digest(x->crl, evpmd, digest, NULL);
type = TYPE_CRL;
name = X509_CRL_get_issuer(x->crl);
X509_CRL_digest(x->crl, evpmd, digest, NULL);
+ } else {
+ ++errs;
+ goto end;
}
if (name) {
if ((h == HASH_NEW) || (h == HASH_BOTH))
}
if (name) {
if ((h == HASH_NEW) || (h == HASH_BOTH))
- add_entry(type, X509_NAME_hash(name), filename, digest, 1, ~0);
+
errs +=
add_entry(type, X509_NAME_hash(name), filename, digest, 1, ~0);
if ((h == HASH_OLD) || (h == HASH_BOTH))
if ((h == HASH_OLD) || (h == HASH_BOTH))
- add_entry(type, X509_NAME_hash_old(name), filename, digest, 1, ~0);
+
errs +=
add_entry(type, X509_NAME_hash_old(name), filename, digest, 1, ~0);
}
end:
sk_X509_INFO_pop_free(inf, X509_INFO_free);
}
end:
sk_X509_INFO_pop_free(inf, X509_INFO_free);
- return
ret
;
+ return
errs
;
}
}
+/*
+ * Process a directory; return number of errors found.
+ */
static int do_dir(const char *dirname, enum Hash h)
{
BUCKET *bp, *nextbp;
static int do_dir(const char *dirname, enum Hash h)
{
BUCKET *bp, *nextbp;
@@
-280,14
+310,19
@@
static int do_dir(const char *dirname, enum Hash h)
OPENSSL_DIR_CTX *d = NULL;
struct stat st;
unsigned char idmask[MAX_COLLISIONS / 8];
OPENSSL_DIR_CTX *d = NULL;
struct stat st;
unsigned char idmask[MAX_COLLISIONS / 8];
- int i, n, nextid, buflen, ret = -1;
+ int n, nextid, buflen, errs = 0;
+ size_t i;
const char *pathsep;
const char *filename;
char *buf;
const char *pathsep;
const char *filename;
char *buf;
+ if (app_access(dirname, W_OK) < 0) {
+ BIO_printf(bio_err, "Skipping %s, can't write\n", dirname);
+ return 1;
+ }
buflen = strlen(dirname);
pathsep = (buflen && dirname[buflen - 1] == '/') ? "" : "/";
buflen = strlen(dirname);
pathsep = (buflen && dirname[buflen - 1] == '/') ? "" : "/";
- buflen += NAME_MAX +
2
;
+ buflen += NAME_MAX +
1 + 1
;
buf = app_malloc(buflen, "filename buffer");
if (verbose)
buf = app_malloc(buflen, "filename buffer");
if (verbose)
@@
-301,11
+336,11
@@
static int do_dir(const char *dirname, enum Hash h)
continue;
if (S_ISLNK(st.st_mode) && handle_symlink(filename, buf) == 0)
continue;
continue;
if (S_ISLNK(st.st_mode) && handle_symlink(filename, buf) == 0)
continue;
- do_file(filename, buf, h);
+
errs +=
do_file(filename, buf, h);
}
OPENSSL_DIR_end(&d);
}
OPENSSL_DIR_end(&d);
- for (i = 0; i <
(int)
OSSL_NELEM(hash_table); i++) {
+ for (i = 0; i < OSSL_NELEM(hash_table); i++) {
for (bp = hash_table[i]; bp; bp = nextbp) {
nextbp = bp->next;
nextid = 0;
for (bp = hash_table[i]; bp; bp = nextbp) {
nextbp = bp->next;
nextid = 0;
@@
-334,15
+369,19
@@
static int do_dir(const char *dirname, enum Hash h)
if (verbose)
BIO_printf(bio_out, "link %s -> %s\n",
ep->filename, &buf[n]);
if (verbose)
BIO_printf(bio_out, "link %s -> %s\n",
ep->filename, &buf[n]);
- if (unlink(buf) < 0 && errno != ENOENT)
+ if (unlink(buf) < 0 && errno != ENOENT)
{
BIO_printf(bio_err,
"%s: Can't unlink %s, %s\n",
opt_getprog(), buf, strerror(errno));
BIO_printf(bio_err,
"%s: Can't unlink %s, %s\n",
opt_getprog(), buf, strerror(errno));
- if (symlink(ep->filename, buf) < 0)
+ errs++;
+ }
+ if (symlink(ep->filename, buf) < 0) {
BIO_printf(bio_err,
"%s: Can't symlink %s, %s\n",
opt_getprog(), ep->filename,
strerror(errno));
BIO_printf(bio_err,
"%s: Can't symlink %s, %s\n",
opt_getprog(), ep->filename,
strerror(errno));
+ errs++;
+ }
} else if (remove_links) {
/* Link to be deleted */
snprintf(buf, buflen, "%s%s%n%08x.%s%d",
} else if (remove_links) {
/* Link to be deleted */
snprintf(buf, buflen, "%s%s%n%08x.%s%d",
@@
-351,10
+390,12
@@
static int do_dir(const char *dirname, enum Hash h)
if (verbose)
BIO_printf(bio_out, "unlink %s\n",
&buf[n]);
if (verbose)
BIO_printf(bio_out, "unlink %s\n",
&buf[n]);
- if (unlink(buf) < 0 && errno != ENOENT)
+ if (unlink(buf) < 0 && errno != ENOENT)
{
BIO_printf(bio_err,
"%s: Can't unlink %s, %s\n",
opt_getprog(), buf, strerror(errno));
BIO_printf(bio_err,
"%s: Can't unlink %s, %s\n",
opt_getprog(), buf, strerror(errno));
+ errs++;
+ }
}
OPENSSL_free(ep->filename);
OPENSSL_free(ep);
}
OPENSSL_free(ep->filename);
OPENSSL_free(ep);
@@
-363,10
+404,9
@@
static int do_dir(const char *dirname, enum Hash h)
}
hash_table[i] = NULL;
}
}
hash_table[i] = NULL;
}
- ret = 0;
OPENSSL_free(buf);
OPENSSL_free(buf);
- return
ret
;
+ return
errs
;
}
typedef enum OPTION_choice {
}
typedef enum OPTION_choice {
@@
-390,7
+430,7
@@
int rehash_main(int argc, char **argv)
{
const char *env, *prog;
char *e, *m;
{
const char *env, *prog;
char *e, *m;
- int
ret
= 0;
+ int
errs
= 0;
OPTION_CHOICE o;
enum Hash h = HASH_NEW;
OPTION_CHOICE o;
enum Hash h = HASH_NEW;
@@
-426,18
+466,18
@@
int rehash_main(int argc, char **argv)
if (*argv) {
while (*argv)
if (*argv) {
while (*argv)
-
ret |
= do_dir(*argv++, h);
+
errs +
= do_dir(*argv++, h);
} else if ((env = getenv("SSL_CERT_DIR")) != NULL) {
} else if ((env = getenv("SSL_CERT_DIR")) != NULL) {
- m =
BUF
_strdup(env);
+ m =
OPENSSL
_strdup(env);
for (e = strtok(m, ":"); e != NULL; e = strtok(NULL, ":"))
for (e = strtok(m, ":"); e != NULL; e = strtok(NULL, ":"))
-
ret |
= do_dir(e, h);
+
errs +
= do_dir(e, h);
OPENSSL_free(m);
} else {
OPENSSL_free(m);
} else {
-
ret |
= do_dir("/etc/ssl/certs", h);
+
errs +
= do_dir("/etc/ssl/certs", h);
}
end:
}
end:
- return
ret ? 2 : 0
;
+ return
errs
;
}
#else
}
#else
@@
-451,4
+491,4
@@
int rehash_main(int argc, char **argv)
return (1);
}
return (1);
}
-#endif
+#endif
/* defined(OPENSSL_SYS_UNIX) || defined(__APPLE__) */