#include <unistd.h>
#include <string.h>
#include <cryptoutil.h>
#include <pthread.h>
#include <security/cryptoki.h>
#include "pkcs11Global.h"
#include "pkcs11Slot.h"
#include "pkcs11Conf.h"
#include "pkcs11Session.h"
#include "metaGlobal.h"
#pragma init(pkcs11_init)
#pragma fini(pkcs11_fini)
static struct CK_FUNCTION_LIST functionList = {
{ 2, 20 },
C_Initialize,
C_Finalize,
C_GetInfo,
C_GetFunctionList,
C_GetSlotList,
C_GetSlotInfo,
C_GetTokenInfo,
C_GetMechanismList,
C_GetMechanismInfo,
C_InitToken,
C_InitPIN,
C_SetPIN,
C_OpenSession,
C_CloseSession,
C_CloseAllSessions,
C_GetSessionInfo,
C_GetOperationState,
C_SetOperationState,
C_Login,
C_Logout,
C_CreateObject,
C_CopyObject,
C_DestroyObject,
C_GetObjectSize,
C_GetAttributeValue,
C_SetAttributeValue,
C_FindObjectsInit,
C_FindObjects,
C_FindObjectsFinal,
C_EncryptInit,
C_Encrypt,
C_EncryptUpdate,
C_EncryptFinal,
C_DecryptInit,
C_Decrypt,
C_DecryptUpdate,
C_DecryptFinal,
C_DigestInit,
C_Digest,
C_DigestUpdate,
C_DigestKey,
C_DigestFinal,
C_SignInit,
C_Sign,
C_SignUpdate,
C_SignFinal,
C_SignRecoverInit,
C_SignRecover,
C_VerifyInit,
C_Verify,
C_VerifyUpdate,
C_VerifyFinal,
C_VerifyRecoverInit,
C_VerifyRecover,
C_DigestEncryptUpdate,
C_DecryptDigestUpdate,
C_SignEncryptUpdate,
C_DecryptVerifyUpdate,
C_GenerateKey,
C_GenerateKeyPair,
C_WrapKey,
C_UnwrapKey,
C_DeriveKey,
C_SeedRandom,
C_GenerateRandom,
C_GetFunctionStatus,
C_CancelFunction,
C_WaitForSlotEvent
};
boolean_t pkcs11_initialized = B_FALSE;
boolean_t pkcs11_cant_create_threads = B_FALSE;
boolean_t fini_called = B_FALSE;
static boolean_t pkcs11_atfork_initialized = B_FALSE;
static pid_t pkcs11_pid = 0;
static pthread_mutex_t globalmutex = PTHREAD_MUTEX_INITIALIZER;
static CK_RV finalize_common(CK_VOID_PTR pReserved);
static void pkcs11_init();
static void pkcs11_fini();
static void
pkcs11_fork_prepare(void)
{
int i;
if (pkcs11_initialized) {
if (slottable != NULL) {
(void) pthread_mutex_lock(&slottable->st_mutex);
for (i = slottable->st_first;
i <= slottable->st_last; i++) {
if (slottable->st_slots[i] != NULL) {
(void) pthread_mutex_lock(
&slottable->st_slots[i]->sl_mutex);
}
}
}
}
}
static void
pkcs11_fork_parent(void)
{
int i;
if (pkcs11_initialized) {
if (slottable != NULL) {
for (i = slottable->st_first;
i <= slottable->st_last; i++) {
if (slottable->st_slots[i] != NULL) {
(void) pthread_mutex_unlock(
&slottable->st_slots[i]->sl_mutex);
}
}
}
(void) pthread_mutex_unlock(&slottable->st_mutex);
}
}
static void
pkcs11_fork_child(void)
{
int i;
if (pkcs11_initialized) {
if (slottable != NULL) {
for (i = slottable->st_first;
i <= slottable->st_last; i++) {
if (slottable->st_slots[i] != NULL) {
(void) pthread_mutex_unlock(
&slottable->st_slots[i]->sl_mutex);
}
}
}
(void) pthread_mutex_unlock(&slottable->st_mutex);
}
(void) pthread_mutex_destroy(&globalmutex);
(void) pthread_mutex_init(&globalmutex, NULL);
}
static void
pkcs11_fork_child_fini(void)
{
pkcs11_fini();
}
CK_RV
C_Initialize(CK_VOID_PTR pInitArgs)
{
CK_RV rv;
uentrylist_t *pliblist = NULL;
int initialize_pid;
(void) pthread_mutex_lock(&globalmutex);
initialize_pid = getpid();
if (pkcs11_initialized) {
if (initialize_pid == pkcs11_pid) {
(void) pthread_mutex_unlock(&globalmutex);
return (CKR_CRYPTOKI_ALREADY_INITIALIZED);
} else {
(void) finalize_common(NULL);
}
}
if (pInitArgs != NULL) {
CK_C_INITIALIZE_ARGS_PTR initargs =
(CK_C_INITIALIZE_ARGS_PTR) pInitArgs;
if (initargs->pReserved != NULL) {
rv = CKR_ARGUMENTS_BAD;
goto errorexit;
}
if (!(((initargs->CreateMutex != NULL) &&
(initargs->LockMutex != NULL) &&
(initargs->UnlockMutex != NULL) &&
(initargs->DestroyMutex != NULL)) ||
((initargs->CreateMutex == NULL) &&
(initargs->LockMutex == NULL) &&
(initargs->UnlockMutex == NULL) &&
(initargs->DestroyMutex == NULL)))) {
rv = CKR_ARGUMENTS_BAD;
goto errorexit;
}
if (!(initargs->flags & CKF_OS_LOCKING_OK)) {
if (initargs->CreateMutex != NULL) {
rv = CKR_CANT_LOCK;
goto errorexit;
}
}
if (initargs->flags & CKF_LIBRARY_CANT_CREATE_OS_THREADS) {
pkcs11_cant_create_threads = B_TRUE;
}
}
rv = pkcs11_slottable_initialize();
if (rv != CKR_OK)
goto errorexit;
if (get_pkcs11conf_info(&pliblist) != SUCCESS) {
rv = CKR_FUNCTION_FAILED;
goto errorexit;
}
rv = pkcs11_slot_mapping(pliblist, pInitArgs);
if (rv != CKR_OK)
goto errorexit;
pkcs11_initialized = B_TRUE;
pkcs11_pid = initialize_pid;
if (!pkcs11_atfork_initialized) {
(void) pthread_atfork(NULL, NULL, pkcs11_fork_child_fini);
pkcs11_atfork_initialized = B_TRUE;
}
(void) pthread_mutex_unlock(&globalmutex);
free_uentrylist(pliblist);
return (CKR_OK);
errorexit:
if (slottable)
(void) pkcs11_slottable_delete();
if (pliblist)
(void) free_uentrylist(pliblist);
(void) pthread_mutex_unlock(&globalmutex);
return (rv);
}
CK_RV
C_Finalize(CK_VOID_PTR pReserved)
{
CK_RV rv;
(void) pthread_mutex_lock(&globalmutex);
rv = finalize_common(pReserved);
(void) pthread_mutex_unlock(&globalmutex);
return (rv);
}
static CK_RV
finalize_common(CK_VOID_PTR pReserved)
{
CK_RV rv;
if (!pkcs11_initialized) {
return (CKR_CRYPTOKI_NOT_INITIALIZED);
}
if (pReserved != NULL) {
return (CKR_ARGUMENTS_BAD);
}
purefastpath = B_FALSE;
policyfastpath = B_FALSE;
fast_funcs = NULL;
fast_slot = 0;
pkcs11_initialized = B_FALSE;
pkcs11_cant_create_threads = B_FALSE;
pkcs11_pid = 0;
(void) pthread_mutex_lock(&slottable->st_mutex);
if (slottable->st_wfse_active) {
while (slottable->st_wfse_active) {
if (slottable->st_blocking) {
slottable->st_list_signaled = B_TRUE;
(void) pthread_cond_signal(
&slottable->st_wait_cond);
(void) pthread_mutex_unlock(
&slottable->st_mutex);
(void) pthread_join(slottable->st_tid, NULL);
}
}
} else {
(void) pthread_mutex_unlock(&slottable->st_mutex);
}
rv = pkcs11_slottable_delete();
return (rv);
}
static void
pkcs11_init()
{
(void) pthread_atfork(pkcs11_fork_prepare,
pkcs11_fork_parent, pkcs11_fork_child);
}
static void
pkcs11_fini()
{
(void) pthread_mutex_lock(&globalmutex);
if (!pkcs11_initialized) {
(void) pthread_mutex_unlock(&globalmutex);
return;
}
fini_called = B_TRUE;
(void) finalize_common(NULL_PTR);
(void) pthread_mutex_unlock(&globalmutex);
}
CK_RV
C_GetInfo(CK_INFO_PTR pInfo)
{
if (purefastpath || policyfastpath) {
return (fast_funcs->C_GetInfo(pInfo));
}
if (!pkcs11_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (pInfo == NULL) {
return (CKR_ARGUMENTS_BAD);
}
(void) strncpy((char *)pInfo->manufacturerID, MANUFACTURER_ID,
PKCS11_STRING_LENGTH);
(void) strncpy((char *)pInfo->libraryDescription,
LIBRARY_DESCRIPTION, PKCS11_STRING_LENGTH);
pInfo->cryptokiVersion.major = CRYPTOKI_VERSION_MAJOR;
pInfo->cryptokiVersion.minor = CRYPTOKI_VERSION_MINOR;
pInfo->flags = 0;
pInfo->libraryVersion.major = LIBRARY_VERSION_MAJOR;
pInfo->libraryVersion.minor = LIBRARY_VERSION_MINOR;
return (CKR_OK);
}
CK_RV
C_GetFunctionList(CK_FUNCTION_LIST_PTR_PTR ppFunctionList)
{
if (ppFunctionList == NULL) {
return (CKR_ARGUMENTS_BAD);
}
*ppFunctionList = &functionList;
return (CKR_OK);
}
CK_RV
C_GetFunctionStatus(CK_SESSION_HANDLE hSession)
{
return (CKR_FUNCTION_NOT_PARALLEL);
}
CK_RV
C_CancelFunction(CK_SESSION_HANDLE hSession)
{
return (CKR_FUNCTION_NOT_PARALLEL);
}