softGeneral.c revision 8047c9fb10f4d3f14385d535d6b23a5eb80c0c0f
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * CDDL HEADER START
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync *
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * The contents of this file are subject to the terms of the
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * Common Development and Distribution License (the "License").
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * You may not use this file except in compliance with the License.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync *
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * or http://www.opensolaris.org/os/licensing.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * See the License for the specific language governing permissions
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * and limitations under the License.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync *
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * When distributing Covered Code, include this CDDL HEADER in each
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * If applicable, add the following below this CDDL HEADER, with the
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * fields enclosed by brackets "[]" replaced with your own identifying
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * information: Portions Copyright [yyyy] [name of copyright owner]
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync *
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * CDDL HEADER END
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/*
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync * Copyright 2006 Sun Microsystems, Inc. All rights reserved.
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync * Use is subject to license terms.
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync */
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync#pragma ident "%Z%%M% %I% %E% SMI"
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync#include <strings.h>
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync#include <errno.h>
930b5f872e89407f445d4000d4e4aaecaa6a0998vboxsync#include <cryptoutil.h>
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include <unistd.h> /* for pid_t */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include <pthread.h>
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include <security/cryptoki.h>
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include "softGlobal.h"
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include "softSession.h"
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include "softObject.h"
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include "softKeystore.h"
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#include "softKeystoreUtil.h"
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync#pragma fini(softtoken_fini)
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncstatic struct CK_FUNCTION_LIST functionList = {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync { 2, 20 }, /* version */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Initialize,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Finalize,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetInfo,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetFunctionList,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetSlotList,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetSlotInfo,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetTokenInfo,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetMechanismList,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetMechanismInfo,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_InitToken,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_InitPIN,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SetPIN,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_OpenSession,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_CloseSession,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_CloseAllSessions,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetSessionInfo,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetOperationState,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SetOperationState,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Login,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Logout,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_CreateObject,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_CopyObject,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DestroyObject,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetObjectSize,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetAttributeValue,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SetAttributeValue,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_FindObjectsInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_FindObjects,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_FindObjectsFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_EncryptInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Encrypt,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_EncryptUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_EncryptFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DecryptInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Decrypt,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DecryptUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DecryptFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DigestInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Digest,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DigestUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DigestKey,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DigestFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Sign,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignRecoverInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignRecover,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_VerifyInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_Verify,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_VerifyUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_VerifyFinal,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_VerifyRecoverInit,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_VerifyRecover,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DigestEncryptUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DecryptDigestUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SignEncryptUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DecryptVerifyUpdate,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GenerateKey,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GenerateKeyPair,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_WrapKey,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_UnwrapKey,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_DeriveKey,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_SeedRandom,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GenerateRandom,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_GetFunctionStatus,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_CancelFunction,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync C_WaitForSlotEvent
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync};
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncboolean_t softtoken_initialized = B_FALSE;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncstatic pid_t softtoken_pid = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/* This mutex protects soft_session_list, all_sessions_closing */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncpthread_mutex_t soft_sessionlist_mutex;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncsoft_session_t *soft_session_list = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncint all_sessions_closing = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncint soft_urandom_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncint soft_urandom_seed_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncint soft_random_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncslot_t soft_slot;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncobj_to_be_freed_list_t obj_delay_freed;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncses_to_be_freed_list_t ses_delay_freed;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/* protects softtoken_initialized and access to C_Initialize/C_Finalize */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncpthread_mutex_t soft_giant_mutex = PTHREAD_MUTEX_INITIALIZER;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncstatic CK_RV finalize_common(boolean_t force, CK_VOID_PTR pReserved);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncstatic void softtoken_fini();
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncCK_RV
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncC_Initialize(CK_VOID_PTR pInitArgs)
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync{
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync int initialize_pid;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync boolean_t supplied_ok;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync CK_RV rv;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * Get lock to insure only one thread enters this
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * function at a time.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_lock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initialize_pid = getpid();
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (softtoken_initialized) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (initialize_pid == softtoken_pid) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * This process has called C_Initialize already
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_CRYPTOKI_ALREADY_INITIALIZED);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync } else {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * A fork has happened and the child is
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * reinitializing. Do a finalize_common to close
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * out any state from the parent, and then
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * continue on.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) finalize_common(B_TRUE, NULL);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (pInitArgs != NULL) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync CK_C_INITIALIZE_ARGS *initargs1 =
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (CK_C_INITIALIZE_ARGS *) pInitArgs;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* pReserved must be NULL */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (initargs1->pReserved != NULL) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_ARGUMENTS_BAD);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * ALL supplied function pointers need to have the value
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * either NULL or non-NULL.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync supplied_ok = (initargs1->CreateMutex == NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->DestroyMutex == NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->LockMutex == NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->UnlockMutex == NULL) ||
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (initargs1->CreateMutex != NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->DestroyMutex != NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->LockMutex != NULL &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync initargs1->UnlockMutex != NULL);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (!supplied_ok) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_ARGUMENTS_BAD);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * When the CKF_OS_LOCKING_OK flag isn't set and mutex
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * function pointers are supplied by an application,
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * return an error. We must be able to use our own primitives.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (!(initargs1->flags & CKF_OS_LOCKING_OK) &&
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (initargs1->CreateMutex != NULL)) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_CANT_LOCK);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Initialize the session list lock */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (pthread_mutex_init(&soft_sessionlist_mutex, NULL) != 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_CANT_LOCK);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync softtoken_initialized = B_TRUE;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync softtoken_pid = initialize_pid;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * token object related initialization
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_slot.authenticated = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_slot.userpin_change_needed = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_slot.token_object_list = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if ((rv = soft_init_token_session()) != CKR_OK) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (rv);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Initialize the slot lock */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (pthread_mutex_init(&soft_slot.slot_mutex, NULL) != 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) soft_destroy_token_session();
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_CANT_LOCK);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Get keystore version because it might not be 1 at this time */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (soft_keystore_get_version(&soft_slot.ks_version, B_FALSE) !=
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_token_present = B_FALSE;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (soft_token_present) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Load all the public token objects from keystore */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if ((rv = soft_get_token_objects_from_keystore(
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync PUB_TOKENOBJS)) != CKR_OK) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_destroy(&soft_slot.slot_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) soft_destroy_token_session();
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (rv);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync } else {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * Invalidate public token objects until the
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * C_OpenSession is called.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_validate_token_objects(B_FALSE);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Initialize the object_to_be_freed list */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_init(&obj_delay_freed.obj_to_be_free_mutex, NULL);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync obj_delay_freed.count = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync obj_delay_freed.first = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync obj_delay_freed.last = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_init(&ses_delay_freed.ses_to_be_free_mutex, NULL);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync ses_delay_freed.count = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync ses_delay_freed.first = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync ses_delay_freed.last = NULL;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_OK);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync}
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * C_Finalize is a wrapper around finalize_common. The
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * soft_giant_mutex should be locked by C_Finalize().
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncCK_RV
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncC_Finalize(CK_VOID_PTR pReserved)
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync{
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync CK_RV rv;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_lock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync rv = finalize_common(B_FALSE, pReserved);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_giant_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (rv);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync}
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync/*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * finalize_common() does the work for C_Finalize. soft_giant_mutex
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * must be held before calling this function.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncstatic CK_RV
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsyncfinalize_common(boolean_t force, CK_VOID_PTR pReserved) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync CK_RV rv = CKR_OK;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync struct object *delay_free_obj, *tmpo;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync struct session *delay_free_ses, *tmps;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (!softtoken_initialized) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_CRYPTOKI_NOT_INITIALIZED);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Check to see if pReseved is NULL */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (pReserved != NULL) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync return (CKR_ARGUMENTS_BAD);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_lock(&soft_sessionlist_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * Set all_sessions_closing flag so any access to any
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * existing sessions will be rejected.
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync all_sessions_closing = 1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_sessionlist_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Delete all the sessions and release the allocated resources */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync rv = soft_delete_all_sessions(force);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_lock(&soft_sessionlist_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Reset all_sessions_closing flag. */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync all_sessions_closing = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_unlock(&soft_sessionlist_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync softtoken_initialized = B_FALSE;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync softtoken_pid = 0;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (soft_urandom_fd > 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) close(soft_urandom_fd);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_urandom_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (soft_urandom_seed_fd > 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) close(soft_urandom_seed_fd);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_urandom_seed_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync if (soft_random_fd > 0) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) close(soft_random_fd);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_random_fd = -1;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /* Destroy the session list lock here */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_destroy(&soft_sessionlist_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * Destroy token object related stuffs
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * 1. Clean up the token object list
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * 2. Destroy slot mutex
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * 3. Destroy mutex in token_session
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync soft_delete_all_in_core_token_objects(ALL_TOKEN);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_destroy(&soft_slot.slot_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) soft_destroy_token_session();
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync /*
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync * free all entries in the delay_freed list
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync */
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync delay_free_obj = obj_delay_freed.first;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync while (delay_free_obj != NULL) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync tmpo = delay_free_obj->next;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync free(delay_free_obj);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync delay_free_obj = tmpo;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync }
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync (void) pthread_mutex_destroy(&obj_delay_freed.obj_to_be_free_mutex);
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync delay_free_ses = ses_delay_freed.first;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync while (delay_free_ses != NULL) {
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync tmps = delay_free_ses->next;
3194da424708abdd288b28d96892b3a5f3f7df0bvboxsync free(delay_free_ses);
delay_free_ses = tmps;
}
(void) pthread_mutex_destroy(&ses_delay_freed.ses_to_be_free_mutex);
return (rv);
}
/*
* softtoken_fini() function required to make sure complete cleanup
* is done if softtoken is ever unloaded without a C_Finalize() call.
*/
static void
softtoken_fini()
{
(void) pthread_mutex_lock(&soft_giant_mutex);
/* if we're not initilized, do not attempt to finalize */
if (!softtoken_initialized) {
(void) pthread_mutex_unlock(&soft_giant_mutex);
return;
}
(void) finalize_common(B_TRUE, NULL_PTR);
(void) pthread_mutex_unlock(&soft_giant_mutex);
}
CK_RV
C_GetInfo(CK_INFO_PTR pInfo)
{
if (!softtoken_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (pInfo == NULL) {
return (CKR_ARGUMENTS_BAD);
}
/* Provide general information in the provided buffer */
pInfo->cryptokiVersion.major = CRYPTOKI_VERSION_MAJOR;
pInfo->cryptokiVersion.minor = CRYPTOKI_VERSION_MINOR;
(void) strncpy((char *)pInfo->manufacturerID,
SOFT_MANUFACTURER_ID, 32);
pInfo->flags = 0;
(void) strncpy((char *)pInfo->libraryDescription,
LIBRARY_DESCRIPTION, 32);
pInfo->libraryVersion.major = LIBRARY_VERSION_MAJOR;
pInfo->libraryVersion.major = LIBRARY_VERSION_MINOR;
return (CKR_OK);
}
CK_RV
C_GetFunctionList(CK_FUNCTION_LIST_PTR_PTR ppFunctionList)
{
if (ppFunctionList == NULL) {
return (CKR_ARGUMENTS_BAD);
}
*ppFunctionList = &functionList;
return (CKR_OK);
}
/*
* PKCS#11 states that C_GetFunctionStatus should always return
* CKR_FUNCTION_NOT_PARALLEL
*/
/*ARGSUSED*/
CK_RV
C_GetFunctionStatus(CK_SESSION_HANDLE hSession)
{
return (CKR_FUNCTION_NOT_PARALLEL);
}
/*
* PKCS#11 states that C_CancelFunction should always return
* CKR_FUNCTION_NOT_PARALLEL
*/
/*ARGSUSED*/
CK_RV
C_CancelFunction(CK_SESSION_HANDLE hSession)
{
return (CKR_FUNCTION_NOT_PARALLEL);
}
/*
* Perform a write that can handle EINTR.
*/
int
looping_write(int fd, void *buf, int len)
{
char *p = buf;
int cc, len2 = 0;
if (len == 0)
return (0);
do {
cc = write(fd, p, len);
if (cc < 0) {
if (errno == EINTR)
continue;
return (cc);
} else if (cc == 0) {
return (len2);
} else {
p += cc;
len2 += cc;
len -= cc;
}
} while (len > 0);
return (len2);
}
/*
* Perform a read that can handle EINTR.
*/
int
looping_read(int fd, void *buf, int len)
{
char *p = buf;
int cc, len2 = 0;
do {
cc = read(fd, p, len);
if (cc < 0) {
if (errno == EINTR)
continue;
return (cc); /* errno is already set */
} else if (cc == 0) {
return (len2);
} else {
p += cc;
len2 += cc;
len -= cc;
}
} while (len > 0);
return (len2);
}