1/*
2 * Copyright 2001-2018 The OpenSSL Project Authors. All Rights Reserved.
3 *
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8 */
9
10#include "e_os.h"
11#include <openssl/e_os2.h>
12#include <openssl/err.h>
13#include <openssl/ui.h>
14
15#ifndef OPENSSL_NO_UI_CONSOLE
16/*
17 * need for #define _POSIX_C_SOURCE arises whenever you pass -ansi to gcc
18 * [maybe others?], because it masks interfaces not discussed in standard,
19 * sigaction and fileno included. -pedantic would be more appropriate for the
20 * intended purposes, but we can't prevent users from adding -ansi.
21 */
22# if defined(OPENSSL_SYS_VXWORKS)
23# include <sys/types.h>
24# endif
25
26# if !defined(_POSIX_C_SOURCE) && defined(OPENSSL_SYS_VMS)
27# ifndef _POSIX_C_SOURCE
28# define _POSIX_C_SOURCE 2
29# endif
30# endif
31# include <signal.h>
32# include <stdio.h>
33# include <string.h>
34# include <errno.h>
35
36# if !defined(OPENSSL_SYS_MSDOS) && !defined(OPENSSL_SYS_VMS)
37# include <unistd.h>
38/*
39 * If unistd.h defines _POSIX_VERSION, we conclude that we are on a POSIX
40 * system and have sigaction and termios.
41 */
42# if defined(_POSIX_VERSION) && _POSIX_VERSION>=199309L
43
44# define SIGACTION
45# if !defined(TERMIOS) && !defined(TERMIO) && !defined(SGTTY)
46# define TERMIOS
47# endif
48
49# endif
50# endif
51
52# include "ui_local.h"
53# include "internal/cryptlib.h"
54
55# ifdef OPENSSL_SYS_VMS /* prototypes for sys$whatever */
56# include <starlet.h>
57# ifdef __DECC
58# pragma message disable DOLLARID
59# endif
60# endif
61
62# ifdef WIN_CONSOLE_BUG
63# include <windows.h>
64# ifndef OPENSSL_SYS_WINCE
65# include <wincon.h>
66# endif
67# endif
68
69/*
70 * There are 6 types of terminal interface supported, TERMIO, TERMIOS, VMS,
71 * MSDOS, WIN32 Console and SGTTY.
72 *
73 * If someone defines one of the macros TERMIO, TERMIOS or SGTTY, it will
74 * remain respected. Otherwise, we default to TERMIOS except for a few
75 * systems that require something different.
76 *
77 * Note: we do not use SGTTY unless it's defined by the configuration. We
78 * may eventually opt to remove its use entirely.
79 */
80
81# if !defined(TERMIOS) && !defined(TERMIO) && !defined(SGTTY)
82
83# if defined(_LIBC)
84# undef TERMIOS
85# define TERMIO
86# undef SGTTY
87/*
88 * We know that VMS, MSDOS, VXWORKS, use entirely other mechanisms.
89 */
90# elif !defined(OPENSSL_SYS_VMS) \
91 && !defined(OPENSSL_SYS_MSDOS) \
92 && !defined(OPENSSL_SYS_VXWORKS)
93# define TERMIOS
94# undef TERMIO
95# undef SGTTY
96# endif
97
98# endif
99
100# if defined(OPENSSL_SYS_VXWORKS)
101# undef TERMIOS
102# undef TERMIO
103# undef SGTTY
104# endif
105
106# ifdef TERMIOS
107# include <termios.h>
108# define TTY_STRUCT struct termios
109# define TTY_FLAGS c_lflag
110# define TTY_get(tty,data) tcgetattr(tty,data)
111# define TTY_set(tty,data) tcsetattr(tty,TCSANOW,data)
112# endif
113
114# ifdef TERMIO
115# include <termio.h>
116# define TTY_STRUCT struct termio
117# define TTY_FLAGS c_lflag
118# define TTY_get(tty,data) ioctl(tty,TCGETA,data)
119# define TTY_set(tty,data) ioctl(tty,TCSETA,data)
120# endif
121
122# ifdef SGTTY
123# include <sgtty.h>
124# define TTY_STRUCT struct sgttyb
125# define TTY_FLAGS sg_flags
126# define TTY_get(tty,data) ioctl(tty,TIOCGETP,data)
127# define TTY_set(tty,data) ioctl(tty,TIOCSETP,data)
128# endif
129
130# if !defined(_LIBC) && !defined(OPENSSL_SYS_MSDOS) && !defined(OPENSSL_SYS_VMS)
131# include <sys/ioctl.h>
132# endif
133
134# ifdef OPENSSL_SYS_MSDOS
135# include <conio.h>
136# endif
137
138# ifdef OPENSSL_SYS_VMS
139# include <ssdef.h>
140# include <iodef.h>
141# include <ttdef.h>
142# include <descrip.h>
143struct IOSB {
144 short iosb$w_value;
145 short iosb$w_count;
146 long iosb$l_info;
147};
148# endif
149
150# ifndef NX509_SIG
151# define NX509_SIG 32
152# endif
153
154/* Define globals. They are protected by a lock */
155# ifdef SIGACTION
156static struct sigaction savsig[NX509_SIG];
157# else
158static void (*savsig[NX509_SIG]) (int);
159# endif
160
161# ifdef OPENSSL_SYS_VMS
162static struct IOSB iosb;
163static $DESCRIPTOR(terminal, "TT");
164static long tty_orig[3], tty_new[3]; /* XXX Is there any guarantee that this
165 * will always suffice for the actual
166 * structures? */
167static long status;
168static unsigned short channel = 0;
169# elif defined(_WIN32) && !defined(_WIN32_WCE)
170static DWORD tty_orig, tty_new;
171# else
172# if !defined(OPENSSL_SYS_MSDOS) || defined(__DJGPP__)
173static TTY_STRUCT tty_orig, tty_new;
174# endif
175# endif
176static FILE *tty_in, *tty_out;
177static int is_a_tty;
178
179/* Declare static functions */
180# if !defined(OPENSSL_SYS_WINCE)
181static int read_till_nl(FILE *);
182static void recsig(int);
183static void pushsig(void);
184static void popsig(void);
185# endif
186# if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
187static int noecho_fgets(char *buf, int size, FILE *tty);
188# endif
189static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl);
190
191static int read_string(UI *ui, UI_STRING *uis);
192static int write_string(UI *ui, UI_STRING *uis);
193
194static int open_console(UI *ui);
195static int echo_console(UI *ui);
196static int noecho_console(UI *ui);
197static int close_console(UI *ui);
198
199/*
200 * The following function makes sure that info and error strings are printed
201 * before any prompt.
202 */
203static int write_string(UI *ui, UI_STRING *uis)
204{
205 switch (UI_get_string_type(uis)) {
206 case UIT_ERROR:
207 case UIT_INFO:
208 fputs(UI_get0_output_string(uis), tty_out);
209 fflush(tty_out);
210 break;
211 case UIT_NONE:
212 case UIT_PROMPT:
213 case UIT_VERIFY:
214 case UIT_BOOLEAN:
215 break;
216 }
217 return 1;
218}
219
220static int read_string(UI *ui, UI_STRING *uis)
221{
222 int ok = 0;
223
224 switch (UI_get_string_type(uis)) {
225 case UIT_BOOLEAN:
226 fputs(UI_get0_output_string(uis), tty_out);
227 fputs(UI_get0_action_string(uis), tty_out);
228 fflush(tty_out);
229 return read_string_inner(ui, uis,
230 UI_get_input_flags(uis) & UI_INPUT_FLAG_ECHO,
231 0);
232 case UIT_PROMPT:
233 fputs(UI_get0_output_string(uis), tty_out);
234 fflush(tty_out);
235 return read_string_inner(ui, uis,
236 UI_get_input_flags(uis) & UI_INPUT_FLAG_ECHO,
237 1);
238 case UIT_VERIFY:
239 fprintf(tty_out, "Verifying - %s", UI_get0_output_string(uis));
240 fflush(tty_out);
241 if ((ok = read_string_inner(ui, uis,
242 UI_get_input_flags(uis) &
243 UI_INPUT_FLAG_ECHO, 1)) <= 0)
244 return ok;
245 if (strcmp(UI_get0_result_string(uis), UI_get0_test_string(uis)) != 0) {
246 fprintf(tty_out, "Verify failure\n");
247 fflush(tty_out);
248 return 0;
249 }
250 break;
251 case UIT_NONE:
252 case UIT_INFO:
253 case UIT_ERROR:
254 break;
255 }
256 return 1;
257}
258
259# if !defined(OPENSSL_SYS_WINCE)
260/* Internal functions to read a string without echoing */
261static int read_till_nl(FILE *in)
262{
263# define SIZE 4
264 char buf[SIZE + 1];
265
266 do {
267 if (!fgets(buf, SIZE, in))
268 return 0;
269 } while (strchr(buf, '\n') == NULL);
270 return 1;
271}
272
273static volatile sig_atomic_t intr_signal;
274# endif
275
276static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
277{
278 static int ps;
279 int ok;
280 char result[BUFSIZ];
281 int maxsize = BUFSIZ - 1;
282# if !defined(OPENSSL_SYS_WINCE)
283 char *p = NULL;
284 int echo_eol = !echo;
285
286 intr_signal = 0;
287 ok = 0;
288 ps = 0;
289
290 pushsig();
291 ps = 1;
292
293 if (!echo && !noecho_console(ui))
294 goto error;
295 ps = 2;
296
297 result[0] = '\0';
298# if defined(_WIN32)
299 if (is_a_tty) {
300 DWORD numread;
301# if defined(CP_UTF8)
302 if (GetEnvironmentVariableW(L"OPENSSL_WIN32_UTF8", NULL, 0) != 0) {
303 WCHAR wresult[BUFSIZ];
304
305 if (ReadConsoleW(GetStdHandle(STD_INPUT_HANDLE),
306 wresult, maxsize, &numread, NULL)) {
307 if (numread >= 2 &&
308 wresult[numread-2] == L'\r' &&
309 wresult[numread-1] == L'\n') {
310 wresult[numread-2] = L'\n';
311 numread--;
312 }
313 wresult[numread] = '\0';
314 if (WideCharToMultiByte(CP_UTF8, 0, wresult, -1,
315 result, sizeof(result), NULL, 0) > 0)
316 p = result;
317
318 OPENSSL_cleanse(wresult, sizeof(wresult));
319 }
320 } else
321# endif
322 if (ReadConsoleA(GetStdHandle(STD_INPUT_HANDLE),
323 result, maxsize, &numread, NULL)) {
324 if (numread >= 2 &&
325 result[numread-2] == '\r' && result[numread-1] == '\n') {
326 result[numread-2] = '\n';
327 numread--;
328 }
329 result[numread] = '\0';
330 p = result;
331 }
332 } else
333# elif defined(OPENSSL_SYS_MSDOS)
334 if (!echo) {
335 noecho_fgets(result, maxsize, tty_in);
336 p = result; /* FIXME: noecho_fgets doesn't return errors */
337 } else
338# endif
339 p = fgets(result, maxsize, tty_in);
340 if (p == NULL)
341 goto error;
342 if (feof(tty_in))
343 goto error;
344 if (ferror(tty_in))
345 goto error;
346 if ((p = (char *)strchr(result, '\n')) != NULL) {
347 if (strip_nl)
348 *p = '\0';
349 } else if (!read_till_nl(tty_in))
350 goto error;
351 if (UI_set_result(ui, uis, result) >= 0)
352 ok = 1;
353
354 error:
355 if (intr_signal == SIGINT)
356 ok = -1;
357 if (echo_eol)
358 fprintf(tty_out, "\n");
359 if (ps >= 2 && !echo && !echo_console(ui))
360 ok = 0;
361
362 if (ps >= 1)
363 popsig();
364# else
365 ok = 1;
366# endif
367
368 OPENSSL_cleanse(result, BUFSIZ);
369 return ok;
370}
371
372/* Internal functions to open, handle and close a channel to the console. */
373static int open_console(UI *ui)
374{
375 CRYPTO_THREAD_write_lock(ui->lock);
376 is_a_tty = 1;
377
378# if defined(OPENSSL_SYS_VXWORKS)
379 tty_in = stdin;
380 tty_out = stderr;
381# elif defined(_WIN32) && !defined(_WIN32_WCE)
382 if ((tty_out = fopen("conout$", "w")) == NULL)
383 tty_out = stderr;
384
385 if (GetConsoleMode(GetStdHandle(STD_INPUT_HANDLE), &tty_orig)) {
386 tty_in = stdin;
387 } else {
388 is_a_tty = 0;
389 if ((tty_in = fopen("conin$", "r")) == NULL)
390 tty_in = stdin;
391 }
392# else
393# ifdef OPENSSL_SYS_MSDOS
394# define DEV_TTY "con"
395# else
396# define DEV_TTY "/dev/tty"
397# endif
398 if ((tty_in = fopen(DEV_TTY, "r")) == NULL)
399 tty_in = stdin;
400 if ((tty_out = fopen(DEV_TTY, "w")) == NULL)
401 tty_out = stderr;
402# endif
403
404# if defined(TTY_get) && !defined(OPENSSL_SYS_VMS)
405 if (TTY_get(fileno(tty_in), &tty_orig) == -1) {
406# ifdef ENOTTY
407 if (errno == ENOTTY)
408 is_a_tty = 0;
409 else
410# endif
411# ifdef EINVAL
412 /*
413 * Ariel Glenn reports that solaris can return EINVAL instead.
414 * This should be ok
415 */
416 if (errno == EINVAL)
417 is_a_tty = 0;
418 else
419# endif
420# ifdef ENXIO
421 /*
422 * Solaris can return ENXIO.
423 * This should be ok
424 */
425 if (errno == ENXIO)
426 is_a_tty = 0;
427 else
428# endif
429# ifdef EIO
430 /*
431 * Linux can return EIO.
432 * This should be ok
433 */
434 if (errno == EIO)
435 is_a_tty = 0;
436 else
437# endif
438# ifdef ENODEV
439 /*
440 * MacOS X returns ENODEV (Operation not supported by device),
441 * which seems appropriate.
442 */
443 if (errno == ENODEV)
444 is_a_tty = 0;
445 else
446# endif
447 {
448 char tmp_num[10];
449 BIO_snprintf(tmp_num, sizeof(tmp_num) - 1, "%d", errno);
450 UIerr(UI_F_OPEN_CONSOLE, UI_R_UNKNOWN_TTYGET_ERRNO_VALUE);
451 ERR_add_error_data(2, "errno=", tmp_num);
452
453 return 0;
454 }
455 }
456# endif
457# ifdef OPENSSL_SYS_VMS
458 status = sys$assign(&terminal, &channel, 0, 0);
459
460 /* if there isn't a TT device, something is very wrong */
461 if (status != SS$_NORMAL) {
462 char tmp_num[12];
463
464 BIO_snprintf(tmp_num, sizeof(tmp_num) - 1, "%%X%08X", status);
465 UIerr(UI_F_OPEN_CONSOLE, UI_R_SYSASSIGN_ERROR);
466 ERR_add_error_data(2, "status=", tmp_num);
467 return 0;
468 }
469
470 status = sys$qiow(0, channel, IO$_SENSEMODE, &iosb, 0, 0, tty_orig, 12,
471 0, 0, 0, 0);
472
473 /* If IO$_SENSEMODE doesn't work, this is not a terminal device */
474 if ((status != SS$_NORMAL) || (iosb.iosb$w_value != SS$_NORMAL))
475 is_a_tty = 0;
476# endif
477 return 1;
478}
479
480static int noecho_console(UI *ui)
481{
482# ifdef TTY_FLAGS
483 memcpy(&(tty_new), &(tty_orig), sizeof(tty_orig));
484 tty_new.TTY_FLAGS &= ~ECHO;
485# endif
486
487# if defined(TTY_set) && !defined(OPENSSL_SYS_VMS)
488 if (is_a_tty && (TTY_set(fileno(tty_in), &tty_new) == -1))
489 return 0;
490# endif
491# ifdef OPENSSL_SYS_VMS
492 if (is_a_tty) {
493 tty_new[0] = tty_orig[0];
494 tty_new[1] = tty_orig[1] | TT$M_NOECHO;
495 tty_new[2] = tty_orig[2];
496 status = sys$qiow(0, channel, IO$_SETMODE, &iosb, 0, 0, tty_new, 12,
497 0, 0, 0, 0);
498 if ((status != SS$_NORMAL) || (iosb.iosb$w_value != SS$_NORMAL)) {
499 char tmp_num[2][12];
500
501 BIO_snprintf(tmp_num[0], sizeof(tmp_num[0]) - 1, "%%X%08X",
502 status);
503 BIO_snprintf(tmp_num[1], sizeof(tmp_num[1]) - 1, "%%X%08X",
504 iosb.iosb$w_value);
505 UIerr(UI_F_NOECHO_CONSOLE, UI_R_SYSQIOW_ERROR);
506 ERR_add_error_data(5, "status=", tmp_num[0],
507 ",", "iosb.iosb$w_value=", tmp_num[1]);
508 return 0;
509 }
510 }
511# endif
512# if defined(_WIN32) && !defined(_WIN32_WCE)
513 if (is_a_tty) {
514 tty_new = tty_orig;
515 tty_new &= ~ENABLE_ECHO_INPUT;
516 SetConsoleMode(GetStdHandle(STD_INPUT_HANDLE), tty_new);
517 }
518# endif
519 return 1;
520}
521
522static int echo_console(UI *ui)
523{
524# if defined(TTY_set) && !defined(OPENSSL_SYS_VMS)
525 memcpy(&(tty_new), &(tty_orig), sizeof(tty_orig));
526 if (is_a_tty && (TTY_set(fileno(tty_in), &tty_new) == -1))
527 return 0;
528# endif
529# ifdef OPENSSL_SYS_VMS
530 if (is_a_tty) {
531 tty_new[0] = tty_orig[0];
532 tty_new[1] = tty_orig[1];
533 tty_new[2] = tty_orig[2];
534 status = sys$qiow(0, channel, IO$_SETMODE, &iosb, 0, 0, tty_new, 12,
535 0, 0, 0, 0);
536 if ((status != SS$_NORMAL) || (iosb.iosb$w_value != SS$_NORMAL)) {
537 char tmp_num[2][12];
538
539 BIO_snprintf(tmp_num[0], sizeof(tmp_num[0]) - 1, "%%X%08X",
540 status);
541 BIO_snprintf(tmp_num[1], sizeof(tmp_num[1]) - 1, "%%X%08X",
542 iosb.iosb$w_value);
543 UIerr(UI_F_ECHO_CONSOLE, UI_R_SYSQIOW_ERROR);
544 ERR_add_error_data(5, "status=", tmp_num[0],
545 ",", "iosb.iosb$w_value=", tmp_num[1]);
546 return 0;
547 }
548 }
549# endif
550# if defined(_WIN32) && !defined(_WIN32_WCE)
551 if (is_a_tty) {
552 tty_new = tty_orig;
553 SetConsoleMode(GetStdHandle(STD_INPUT_HANDLE), tty_new);
554 }
555# endif
556 return 1;
557}
558
559static int close_console(UI *ui)
560{
561 if (tty_in != stdin)
562 fclose(tty_in);
563 if (tty_out != stderr)
564 fclose(tty_out);
565# ifdef OPENSSL_SYS_VMS
566 status = sys$dassgn(channel);
567 if (status != SS$_NORMAL) {
568 char tmp_num[12];
569
570 BIO_snprintf(tmp_num, sizeof(tmp_num) - 1, "%%X%08X", status);
571 UIerr(UI_F_CLOSE_CONSOLE, UI_R_SYSDASSGN_ERROR);
572 ERR_add_error_data(2, "status=", tmp_num);
573 return 0;
574 }
575# endif
576 CRYPTO_THREAD_unlock(ui->lock);
577
578 return 1;
579}
580
581# if !defined(OPENSSL_SYS_WINCE)
582/* Internal functions to handle signals and act on them */
583static void pushsig(void)
584{
585# ifndef OPENSSL_SYS_WIN32
586 int i;
587# endif
588# ifdef SIGACTION
589 struct sigaction sa;
590
591 memset(&sa, 0, sizeof(sa));
592 sa.sa_handler = recsig;
593# endif
594
595# ifdef OPENSSL_SYS_WIN32
596 savsig[SIGABRT] = signal(SIGABRT, recsig);
597 savsig[SIGFPE] = signal(SIGFPE, recsig);
598 savsig[SIGILL] = signal(SIGILL, recsig);
599 savsig[SIGINT] = signal(SIGINT, recsig);
600 savsig[SIGSEGV] = signal(SIGSEGV, recsig);
601 savsig[SIGTERM] = signal(SIGTERM, recsig);
602# else
603 for (i = 1; i < NX509_SIG; i++) {
604# ifdef SIGUSR1
605 if (i == SIGUSR1)
606 continue;
607# endif
608# ifdef SIGUSR2
609 if (i == SIGUSR2)
610 continue;
611# endif
612# ifdef SIGKILL
613 if (i == SIGKILL) /* We can't make any action on that. */
614 continue;
615# endif
616# ifdef SIGACTION
617 sigaction(i, &sa, &savsig[i]);
618# else
619 savsig[i] = signal(i, recsig);
620# endif
621 }
622# endif
623
624# ifdef SIGWINCH
625 signal(SIGWINCH, SIG_DFL);
626# endif
627}
628
629static void popsig(void)
630{
631# ifdef OPENSSL_SYS_WIN32
632 signal(SIGABRT, savsig[SIGABRT]);
633 signal(SIGFPE, savsig[SIGFPE]);
634 signal(SIGILL, savsig[SIGILL]);
635 signal(SIGINT, savsig[SIGINT]);
636 signal(SIGSEGV, savsig[SIGSEGV]);
637 signal(SIGTERM, savsig[SIGTERM]);
638# else
639 int i;
640 for (i = 1; i < NX509_SIG; i++) {
641# ifdef SIGUSR1
642 if (i == SIGUSR1)
643 continue;
644# endif
645# ifdef SIGUSR2
646 if (i == SIGUSR2)
647 continue;
648# endif
649# ifdef SIGACTION
650 sigaction(i, &savsig[i], NULL);
651# else
652 signal(i, savsig[i]);
653# endif
654 }
655# endif
656}
657
658static void recsig(int i)
659{
660 intr_signal = i;
661}
662# endif
663
664/* Internal functions specific for Windows */
665# if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
666static int noecho_fgets(char *buf, int size, FILE *tty)
667{
668 int i;
669 char *p;
670
671 p = buf;
672 for (;;) {
673 if (size == 0) {
674 *p = '\0';
675 break;
676 }
677 size--;
678# if defined(_WIN32)
679 i = _getch();
680# else
681 i = getch();
682# endif
683 if (i == '\r')
684 i = '\n';
685 *(p++) = i;
686 if (i == '\n') {
687 *p = '\0';
688 break;
689 }
690 }
691# ifdef WIN_CONSOLE_BUG
692 /*
693 * Win95 has several evil console bugs: one of these is that the last
694 * character read using getch() is passed to the next read: this is
695 * usually a CR so this can be trouble. No STDIO fix seems to work but
696 * flushing the console appears to do the trick.
697 */
698 {
699 HANDLE inh;
700 inh = GetStdHandle(STD_INPUT_HANDLE);
701 FlushConsoleInputBuffer(inh);
702 }
703# endif
704 return strlen(buf);
705}
706# endif
707
708static UI_METHOD ui_openssl = {
709 "OpenSSL default user interface",
710 open_console,
711 write_string,
712 NULL, /* No flusher is needed for command lines */
713 read_string,
714 close_console,
715 NULL
716};
717
718/* The method with all the built-in console thingies */
719UI_METHOD *UI_OpenSSL(void)
720{
721 return &ui_openssl;
722}
723
724static const UI_METHOD *default_UI_meth = &ui_openssl;
725
726#else
727
728static const UI_METHOD *default_UI_meth = NULL;
729
730#endif
731
732void UI_set_default_method(const UI_METHOD *meth)
733{
734 default_UI_meth = meth;
735}
736
737const UI_METHOD *UI_get_default_method(void)
738{
739 return default_UI_meth;
740}
741