2 * Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the OpenSSL license (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
10 #include <internal/cryptlib_int.h>
11 #include <openssl/err.h>
12 #include <internal/rand.h>
13 #include <internal/bio.h>
14 #include <openssl/evp.h>
15 #include <internal/evp_int.h>
16 #include <internal/conf.h>
17 #include <internal/async.h>
18 #include <internal/engine.h>
19 #include <internal/comp.h>
20 #include <internal/err.h>
21 #include <internal/err_int.h>
22 #include <internal/objects.h>
25 #include <internal/thread_once.h>
26 #include <internal/dso.h>
28 static int stopped = 0;
31 * Since per-thread-specific-data destructors are not universally
32 * available, i.e. not on Windows, only below CRYPTO_THREAD_LOCAL key
33 * is assumed to have destructor associated. And then an effort is made
34 * to call this single destructor on non-pthread platform[s].
36 * Initial value is "impossible". It is used as guard value to shortcut
37 * destructor for threads terminating before libcrypto is initialized or
38 * after it's de-initialized. Access to the key doesn't have to be
39 * serialized for the said threads, because they didn't use libcrypto
40 * and it doesn't matter if they pick "impossible" or derefernce real
41 * key value and pull NULL past initialization in the first thread that
42 * intends to use libcrypto.
46 CRYPTO_THREAD_LOCAL value;
47 } destructor_key = { -1 };
49 static void ossl_init_thread_stop(struct thread_local_inits_st *locals);
51 static void ossl_init_thread_destructor(void *local)
53 ossl_init_thread_stop((struct thread_local_inits_st *)local);
56 static struct thread_local_inits_st *ossl_init_get_thread_local(int alloc)
58 struct thread_local_inits_st *local =
59 CRYPTO_THREAD_get_local(&destructor_key.value);
63 && (local = OPENSSL_zalloc(sizeof(*local))) != NULL
64 && !CRYPTO_THREAD_set_local(&destructor_key.value, local)) {
69 CRYPTO_THREAD_set_local(&destructor_key.value, NULL);
75 typedef struct ossl_init_stop_st OPENSSL_INIT_STOP;
76 struct ossl_init_stop_st {
77 void (*handler)(void);
78 OPENSSL_INIT_STOP *next;
81 static OPENSSL_INIT_STOP *stop_handlers = NULL;
82 static CRYPTO_RWLOCK *init_lock = NULL;
84 static CRYPTO_ONCE base = CRYPTO_ONCE_STATIC_INIT;
85 static int base_inited = 0;
86 DEFINE_RUN_ONCE_STATIC(ossl_init_base)
88 CRYPTO_THREAD_LOCAL key;
90 #ifdef OPENSSL_INIT_DEBUG
91 fprintf(stderr, "OPENSSL_INIT: ossl_init_base: Setting up stop handlers\n");
93 if (!CRYPTO_THREAD_init_local(&key, ossl_init_thread_destructor))
95 if ((init_lock = CRYPTO_THREAD_lock_new()) == NULL)
97 #ifndef OPENSSL_SYS_UEFI
98 if (atexit(OPENSSL_cleanup) != 0)
101 OPENSSL_cpuid_setup();
103 destructor_key.value = key;
108 #ifdef OPENSSL_INIT_DEBUG
109 fprintf(stderr, "OPENSSL_INIT: ossl_init_base not ok!\n");
111 CRYPTO_THREAD_lock_free(init_lock);
114 CRYPTO_THREAD_cleanup_local(&key);
118 static CRYPTO_ONCE load_crypto_nodelete = CRYPTO_ONCE_STATIC_INIT;
119 DEFINE_RUN_ONCE_STATIC(ossl_init_load_crypto_nodelete)
121 #ifdef OPENSSL_INIT_DEBUG
122 fprintf(stderr, "OPENSSL_INIT: ossl_init_load_crypto_nodelete()\n");
124 #if !defined(OPENSSL_NO_DSO) && !defined(OPENSSL_USE_NODELETE)
127 HMODULE handle = NULL;
130 /* We don't use the DSO route for WIN32 because there is a better way */
131 ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
132 | GET_MODULE_HANDLE_EX_FLAG_PIN,
133 (void *)&base_inited, &handle);
135 # ifdef OPENSSL_INIT_DEBUG
136 fprintf(stderr, "OPENSSL_INIT: obtained DSO reference? %s\n",
137 (ret == TRUE ? "No!" : "Yes."));
139 return (ret == TRUE) ? 1 : 0;
143 * Deliberately leak a reference to ourselves. This will force the library
144 * to remain loaded until the atexit() handler is run at process exit.
150 if (!err_shelve_state(&err))
153 dso = DSO_dsobyaddr(&base_inited, DSO_FLAG_NO_UNLOAD_ON_FREE);
154 # ifdef OPENSSL_INIT_DEBUG
155 fprintf(stderr, "OPENSSL_INIT: obtained DSO reference? %s\n",
156 (dso == NULL ? "No!" : "Yes."));
158 * In case of No!, it is uncertain our exit()-handlers can still be
159 * called. After dlclose() the whole library might have been unloaded
164 err_unshelve_state(err);
172 static CRYPTO_ONCE load_crypto_strings = CRYPTO_ONCE_STATIC_INIT;
173 static int load_crypto_strings_inited = 0;
174 DEFINE_RUN_ONCE_STATIC(ossl_init_no_load_crypto_strings)
176 /* Do nothing in this case */
180 DEFINE_RUN_ONCE_STATIC(ossl_init_load_crypto_strings)
184 * OPENSSL_NO_AUTOERRINIT is provided here to prevent at compile time
185 * pulling in all the error strings during static linking
187 #if !defined(OPENSSL_NO_ERR) && !defined(OPENSSL_NO_AUTOERRINIT)
188 # ifdef OPENSSL_INIT_DEBUG
189 fprintf(stderr, "OPENSSL_INIT: ossl_init_load_crypto_strings: "
190 "err_load_crypto_strings_int()\n");
192 ret = err_load_crypto_strings_int();
193 load_crypto_strings_inited = 1;
198 static CRYPTO_ONCE add_all_ciphers = CRYPTO_ONCE_STATIC_INIT;
199 DEFINE_RUN_ONCE_STATIC(ossl_init_add_all_ciphers)
202 * OPENSSL_NO_AUTOALGINIT is provided here to prevent at compile time
203 * pulling in all the ciphers during static linking
205 #ifndef OPENSSL_NO_AUTOALGINIT
206 # ifdef OPENSSL_INIT_DEBUG
207 fprintf(stderr, "OPENSSL_INIT: ossl_init_add_all_ciphers: "
208 "openssl_add_all_ciphers_int()\n");
210 openssl_add_all_ciphers_int();
215 static CRYPTO_ONCE add_all_digests = CRYPTO_ONCE_STATIC_INIT;
216 DEFINE_RUN_ONCE_STATIC(ossl_init_add_all_digests)
219 * OPENSSL_NO_AUTOALGINIT is provided here to prevent at compile time
220 * pulling in all the ciphers during static linking
222 #ifndef OPENSSL_NO_AUTOALGINIT
223 # ifdef OPENSSL_INIT_DEBUG
224 fprintf(stderr, "OPENSSL_INIT: ossl_init_add_all_digests: "
225 "openssl_add_all_digests()\n");
227 openssl_add_all_digests_int();
232 DEFINE_RUN_ONCE_STATIC(ossl_init_no_add_algs)
238 static CRYPTO_ONCE config = CRYPTO_ONCE_STATIC_INIT;
239 static int config_inited = 0;
240 static const char *appname;
241 DEFINE_RUN_ONCE_STATIC(ossl_init_config)
243 #ifdef OPENSSL_INIT_DEBUG
245 "OPENSSL_INIT: ossl_init_config: openssl_config(%s)\n",
246 appname == NULL ? "NULL" : appname);
248 openssl_config_int(appname);
252 DEFINE_RUN_ONCE_STATIC(ossl_init_no_config)
254 #ifdef OPENSSL_INIT_DEBUG
256 "OPENSSL_INIT: ossl_init_config: openssl_no_config_int()\n");
258 openssl_no_config_int();
263 static CRYPTO_ONCE async = CRYPTO_ONCE_STATIC_INIT;
264 static int async_inited = 0;
265 DEFINE_RUN_ONCE_STATIC(ossl_init_async)
267 #ifdef OPENSSL_INIT_DEBUG
268 fprintf(stderr, "OPENSSL_INIT: ossl_init_async: async_init()\n");
276 #ifndef OPENSSL_NO_ENGINE
277 static CRYPTO_ONCE engine_openssl = CRYPTO_ONCE_STATIC_INIT;
278 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_openssl)
280 # ifdef OPENSSL_INIT_DEBUG
281 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_openssl: "
282 "engine_load_openssl_int()\n");
284 engine_load_openssl_int();
287 # if !defined(OPENSSL_NO_HW) && \
288 (defined(__OpenBSD__) || defined(__FreeBSD__) || defined(HAVE_CRYPTODEV))
289 static CRYPTO_ONCE engine_cryptodev = CRYPTO_ONCE_STATIC_INIT;
290 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_cryptodev)
292 # ifdef OPENSSL_INIT_DEBUG
293 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_cryptodev: "
294 "engine_load_cryptodev_int()\n");
296 engine_load_cryptodev_int();
301 # ifndef OPENSSL_NO_RDRAND
302 static CRYPTO_ONCE engine_rdrand = CRYPTO_ONCE_STATIC_INIT;
303 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_rdrand)
305 # ifdef OPENSSL_INIT_DEBUG
306 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_rdrand: "
307 "engine_load_rdrand_int()\n");
309 engine_load_rdrand_int();
313 static CRYPTO_ONCE engine_dynamic = CRYPTO_ONCE_STATIC_INIT;
314 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_dynamic)
316 # ifdef OPENSSL_INIT_DEBUG
317 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_dynamic: "
318 "engine_load_dynamic_int()\n");
320 engine_load_dynamic_int();
323 # ifndef OPENSSL_NO_STATIC_ENGINE
324 # if !defined(OPENSSL_NO_HW) && !defined(OPENSSL_NO_HW_PADLOCK)
325 static CRYPTO_ONCE engine_padlock = CRYPTO_ONCE_STATIC_INIT;
326 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_padlock)
328 # ifdef OPENSSL_INIT_DEBUG
329 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_padlock: "
330 "engine_load_padlock_int()\n");
332 engine_load_padlock_int();
336 # if defined(OPENSSL_SYS_WIN32) && !defined(OPENSSL_NO_CAPIENG)
337 static CRYPTO_ONCE engine_capi = CRYPTO_ONCE_STATIC_INIT;
338 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_capi)
340 # ifdef OPENSSL_INIT_DEBUG
341 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_capi: "
342 "engine_load_capi_int()\n");
344 engine_load_capi_int();
348 # if !defined(OPENSSL_NO_AFALGENG)
349 static CRYPTO_ONCE engine_afalg = CRYPTO_ONCE_STATIC_INIT;
350 DEFINE_RUN_ONCE_STATIC(ossl_init_engine_afalg)
352 # ifdef OPENSSL_INIT_DEBUG
353 fprintf(stderr, "OPENSSL_INIT: ossl_init_engine_afalg: "
354 "engine_load_afalg_int()\n");
356 engine_load_afalg_int();
363 #ifndef OPENSSL_NO_COMP
364 static CRYPTO_ONCE zlib = CRYPTO_ONCE_STATIC_INIT;
366 static int zlib_inited = 0;
367 DEFINE_RUN_ONCE_STATIC(ossl_init_zlib)
369 /* Do nothing - we need to know about this for the later cleanup */
375 static void ossl_init_thread_stop(struct thread_local_inits_st *locals)
377 /* Can't do much about this */
382 #ifdef OPENSSL_INIT_DEBUG
383 fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_stop: "
384 "async_delete_thread_state()\n");
386 async_delete_thread_state();
389 if (locals->err_state) {
390 #ifdef OPENSSL_INIT_DEBUG
391 fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_stop: "
392 "err_delete_thread_state()\n");
394 err_delete_thread_state();
397 OPENSSL_free(locals);
400 void OPENSSL_thread_stop(void)
402 if (destructor_key.sane != -1)
403 ossl_init_thread_stop(ossl_init_get_thread_local(0));
406 int ossl_init_thread_start(uint64_t opts)
408 struct thread_local_inits_st *locals;
410 if (!OPENSSL_init_crypto(0, NULL))
413 locals = ossl_init_get_thread_local(1);
418 if (opts & OPENSSL_INIT_THREAD_ASYNC) {
419 #ifdef OPENSSL_INIT_DEBUG
420 fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_start: "
421 "marking thread for async\n");
426 if (opts & OPENSSL_INIT_THREAD_ERR_STATE) {
427 #ifdef OPENSSL_INIT_DEBUG
428 fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_start: "
429 "marking thread for err_state\n");
431 locals->err_state = 1;
437 void OPENSSL_cleanup(void)
439 OPENSSL_INIT_STOP *currhandler, *lasthandler;
440 CRYPTO_THREAD_LOCAL key;
442 /* If we've not been inited then no need to deinit */
446 /* Might be explicitly called and also by atexit */
452 * Thread stop may not get automatically called by the thread library for
453 * the very last thread in some situations, so call it directly.
455 ossl_init_thread_stop(ossl_init_get_thread_local(0));
457 currhandler = stop_handlers;
458 while (currhandler != NULL) {
459 currhandler->handler();
460 lasthandler = currhandler;
461 currhandler = currhandler->next;
462 OPENSSL_free(lasthandler);
464 stop_handlers = NULL;
466 CRYPTO_THREAD_lock_free(init_lock);
469 * We assume we are single-threaded for this function, i.e. no race
470 * conditions for the various "*_inited" vars below.
473 #ifndef OPENSSL_NO_COMP
475 #ifdef OPENSSL_INIT_DEBUG
476 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
477 "comp_zlib_cleanup_int()\n");
479 comp_zlib_cleanup_int();
484 # ifdef OPENSSL_INIT_DEBUG
485 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
491 if (load_crypto_strings_inited) {
492 #ifdef OPENSSL_INIT_DEBUG
493 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
494 "err_free_strings_int()\n");
496 err_free_strings_int();
499 key = destructor_key.value;
500 destructor_key.sane = -1;
501 CRYPTO_THREAD_cleanup_local(&key);
503 #ifdef OPENSSL_INIT_DEBUG
504 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
505 "rand_cleanup_int()\n");
506 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
507 "conf_modules_free_int()\n");
508 #ifndef OPENSSL_NO_ENGINE
509 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
510 "engine_cleanup_int()\n");
512 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
513 "crypto_cleanup_all_ex_data_int()\n");
514 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
515 "bio_sock_cleanup_int()\n");
516 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
518 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
519 "evp_cleanup_int()\n");
520 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
521 "obj_cleanup_int()\n");
522 fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
526 * Note that cleanup order is important:
527 * - rand_cleanup_int could call an ENGINE's RAND cleanup function so
528 * must be called before engine_cleanup_int()
529 * - ENGINEs use CRYPTO_EX_DATA and therefore, must be cleaned up
530 * before the ex data handlers are wiped in CRYPTO_cleanup_all_ex_data().
531 * - conf_modules_free_int() can end up in ENGINE code so must be called
532 * before engine_cleanup_int()
533 * - ENGINEs and additional EVP algorithms might use added OIDs names so
534 * obj_cleanup_int() must be called last
537 conf_modules_free_int();
538 #ifndef OPENSSL_NO_ENGINE
539 engine_cleanup_int();
541 crypto_cleanup_all_ex_data_int();
551 * If this function is called with a non NULL settings value then it must be
552 * called prior to any threads making calls to any OpenSSL functions,
553 * i.e. passing a non-null settings value is assumed to be single-threaded.
555 int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings)
558 if (!(opts & OPENSSL_INIT_BASE_ONLY))
559 CRYPTOerr(CRYPTO_F_OPENSSL_INIT_CRYPTO, ERR_R_INIT_FAIL);
563 if (!RUN_ONCE(&base, ossl_init_base))
566 if (!(opts & OPENSSL_INIT_BASE_ONLY)
567 && !RUN_ONCE(&load_crypto_nodelete,
568 ossl_init_load_crypto_nodelete))
571 if ((opts & OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS)
572 && !RUN_ONCE(&load_crypto_strings,
573 ossl_init_no_load_crypto_strings))
576 if ((opts & OPENSSL_INIT_LOAD_CRYPTO_STRINGS)
577 && !RUN_ONCE(&load_crypto_strings, ossl_init_load_crypto_strings))
580 if ((opts & OPENSSL_INIT_NO_ADD_ALL_CIPHERS)
581 && !RUN_ONCE(&add_all_ciphers, ossl_init_no_add_algs))
584 if ((opts & OPENSSL_INIT_ADD_ALL_CIPHERS)
585 && !RUN_ONCE(&add_all_ciphers, ossl_init_add_all_ciphers))
588 if ((opts & OPENSSL_INIT_NO_ADD_ALL_DIGESTS)
589 && !RUN_ONCE(&add_all_digests, ossl_init_no_add_algs))
592 if ((opts & OPENSSL_INIT_ADD_ALL_DIGESTS)
593 && !RUN_ONCE(&add_all_digests, ossl_init_add_all_digests))
596 if ((opts & OPENSSL_INIT_NO_LOAD_CONFIG)
597 && !RUN_ONCE(&config, ossl_init_no_config))
600 if (opts & OPENSSL_INIT_LOAD_CONFIG) {
602 CRYPTO_THREAD_write_lock(init_lock);
603 appname = (settings == NULL) ? NULL : settings->appname;
604 ret = RUN_ONCE(&config, ossl_init_config);
605 CRYPTO_THREAD_unlock(init_lock);
610 if ((opts & OPENSSL_INIT_ASYNC)
611 && !RUN_ONCE(&async, ossl_init_async))
614 #ifndef OPENSSL_NO_ENGINE
615 if ((opts & OPENSSL_INIT_ENGINE_OPENSSL)
616 && !RUN_ONCE(&engine_openssl, ossl_init_engine_openssl))
618 # if !defined(OPENSSL_NO_HW) && \
619 (defined(__OpenBSD__) || defined(__FreeBSD__) || defined(HAVE_CRYPTODEV))
620 if ((opts & OPENSSL_INIT_ENGINE_CRYPTODEV)
621 && !RUN_ONCE(&engine_cryptodev, ossl_init_engine_cryptodev))
624 # ifndef OPENSSL_NO_RDRAND
625 if ((opts & OPENSSL_INIT_ENGINE_RDRAND)
626 && !RUN_ONCE(&engine_rdrand, ossl_init_engine_rdrand))
629 if ((opts & OPENSSL_INIT_ENGINE_DYNAMIC)
630 && !RUN_ONCE(&engine_dynamic, ossl_init_engine_dynamic))
632 # ifndef OPENSSL_NO_STATIC_ENGINE
633 # if !defined(OPENSSL_NO_HW) && !defined(OPENSSL_NO_HW_PADLOCK)
634 if ((opts & OPENSSL_INIT_ENGINE_PADLOCK)
635 && !RUN_ONCE(&engine_padlock, ossl_init_engine_padlock))
638 # if defined(OPENSSL_SYS_WIN32) && !defined(OPENSSL_NO_CAPIENG)
639 if ((opts & OPENSSL_INIT_ENGINE_CAPI)
640 && !RUN_ONCE(&engine_capi, ossl_init_engine_capi))
643 # if !defined(OPENSSL_NO_AFALGENG)
644 if ((opts & OPENSSL_INIT_ENGINE_AFALG)
645 && !RUN_ONCE(&engine_afalg, ossl_init_engine_afalg))
649 if (opts & (OPENSSL_INIT_ENGINE_ALL_BUILTIN
650 | OPENSSL_INIT_ENGINE_OPENSSL
651 | OPENSSL_INIT_ENGINE_AFALG)) {
652 ENGINE_register_all_complete();
656 #ifndef OPENSSL_NO_COMP
657 if ((opts & OPENSSL_INIT_ZLIB)
658 && !RUN_ONCE(&zlib, ossl_init_zlib))
665 int OPENSSL_atexit(void (*handler)(void))
667 OPENSSL_INIT_STOP *newhand;
669 #if !defined(OPENSSL_NO_DSO) && !defined(OPENSSL_USE_NODELETE)
676 handlersym.func = handler;
679 HMODULE handle = NULL;
683 * We don't use the DSO route for WIN32 because there is a better
686 ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
687 | GET_MODULE_HANDLE_EX_FLAG_PIN,
688 handlersym.sym, &handle);
695 * Deliberately leak a reference to the handler. This will force the
696 * library/code containing the handler to remain loaded until we run the
697 * atexit handler. If -znodelete has been used then this is
704 dso = DSO_dsobyaddr(handlersym.sym, DSO_FLAG_NO_UNLOAD_ON_FREE);
705 # ifdef OPENSSL_INIT_DEBUG
707 "OPENSSL_INIT: OPENSSL_atexit: obtained DSO reference? %s\n",
708 (dso == NULL ? "No!" : "Yes."));
709 /* See same code above in ossl_init_base() for an explanation. */
718 newhand = OPENSSL_malloc(sizeof(*newhand));
722 newhand->handler = handler;
723 newhand->next = stop_handlers;
724 stop_handlers = newhand;