blob: 6f6b6967aa9f07b7365ca2c8f53c3b85b460bab6 [file] [log] [blame]
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -05001/**
2 * \file platform_util.h
3 *
4 * \brief Common and shared functions used by multiple modules in the Mbed TLS
5 * library.
6 */
7/*
Bence Szépkúti1e148272020-08-07 13:07:28 +02008 * Copyright The Mbed TLS Contributors
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -05009 * SPDX-License-Identifier: Apache-2.0
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License"); you may
12 * not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -050022 */
23#ifndef MBEDTLS_PLATFORM_UTIL_H
24#define MBEDTLS_PLATFORM_UTIL_H
25
Bence Szépkútic662b362021-05-27 11:25:03 +020026#include "mbedtls/build_info.h"
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +010027
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -050028#include <stddef.h>
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +010029#if defined(MBEDTLS_HAVE_TIME_DATE)
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010030#include "mbedtls/platform_time.h"
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +010031#include <time.h>
32#endif /* MBEDTLS_HAVE_TIME_DATE */
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -050033
34#ifdef __cplusplus
35extern "C" {
36#endif
37
Andrzej Kurekc470b6b2019-01-31 08:20:20 -050038/* Internal macros meant to be called only from within the library. */
39#define MBEDTLS_INTERNAL_VALIDATE_RET( cond, ret ) do { } while( 0 )
40#define MBEDTLS_INTERNAL_VALIDATE( cond ) do { } while( 0 )
41
Andrzej Kurekc470b6b2019-01-31 08:20:20 -050042/* Internal helper macros for deprecating API constants. */
43#if !defined(MBEDTLS_DEPRECATED_REMOVED)
44#if defined(MBEDTLS_DEPRECATED_WARNING)
45/* Deliberately don't (yet) export MBEDTLS_DEPRECATED here
46 * to avoid conflict with other headers which define and use
47 * it, too. We might want to move all these definitions here at
48 * some point for uniformity. */
49#define MBEDTLS_DEPRECATED __attribute__((deprecated))
50MBEDTLS_DEPRECATED typedef char const * mbedtls_deprecated_string_constant_t;
51#define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) \
52 ( (mbedtls_deprecated_string_constant_t) ( VAL ) )
53MBEDTLS_DEPRECATED typedef int mbedtls_deprecated_numeric_constant_t;
54#define MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( VAL ) \
55 ( (mbedtls_deprecated_numeric_constant_t) ( VAL ) )
56#undef MBEDTLS_DEPRECATED
57#else /* MBEDTLS_DEPRECATED_WARNING */
58#define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) VAL
59#define MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( VAL ) VAL
60#endif /* MBEDTLS_DEPRECATED_WARNING */
61#endif /* MBEDTLS_DEPRECATED_REMOVED */
62
Gilles Peskine463adf42021-09-23 17:28:59 +020063/* Implementation of the check-return facility.
64 * See the user documentation in mbedtls_config.h.
Mateusz Starzyke35f8f62021-08-04 15:38:09 +020065 *
Gilles Peskine463adf42021-09-23 17:28:59 +020066 * Do not use this macro directly to annotate function: instead,
67 * use one of MBEDTLS_CHECK_RETURN_CRITICAL or MBEDTLS_CHECK_RETURN_TYPICAL
68 * depending on how important it is to check the return value.
Mateusz Starzyke35f8f62021-08-04 15:38:09 +020069 */
70#if !defined(MBEDTLS_CHECK_RETURN)
71#if defined(__GNUC__)
Gilles Peskinea33e6932021-09-23 17:46:12 +020072#define MBEDTLS_CHECK_RETURN __attribute__((__warn_unused_result__))
Mateusz Starzyke35f8f62021-08-04 15:38:09 +020073#elif defined(_MSC_VER) && _MSC_VER >= 1700
74#include <sal.h>
75#define MBEDTLS_CHECK_RETURN _Check_return_
76#else
77#define MBEDTLS_CHECK_RETURN
78#endif
79#endif
80
Gilles Peskine463adf42021-09-23 17:28:59 +020081/** Critical-failure function
82 *
83 * This macro appearing at the beginning of the declaration of a function
84 * indicates that its return value should be checked in all applications.
85 * Omitting the check is very likely to indicate a bug in the application
86 * and will result in a compile-time warning if #MBEDTLS_CHECK_RETURN
87 * is implemented for the compiler in use.
88 *
89 * \note The use of this macro is a work in progress.
90 * This macro may be added to more functions in the future.
91 * Such an extension is not considered an API break, provided that
92 * there are near-unavoidable circumstances under which the function
93 * can fail. For example, signature/MAC/AEAD verification functions,
94 * and functions that require a random generator, are considered
95 * return-check-critical.
96 */
97#define MBEDTLS_CHECK_RETURN_CRITICAL MBEDTLS_CHECK_RETURN
98
99/** Ordinary-failure function
100 *
101 * This macro appearing at the beginning of the declaration of a function
102 * indicates that its return value should be generally be checked in portable
103 * applications. Omitting the check will result in a compile-time warning if
Gilles Peskine409fbbe2021-09-27 16:17:51 +0200104 * #MBEDTLS_CHECK_RETURN is implemented for the compiler in use and
105 * #MBEDTLS_CHECK_RETURN_WARNING is enabled in the compile-time configuration.
Gilles Peskine463adf42021-09-23 17:28:59 +0200106 *
Gilles Peskinefcc93d72021-09-30 18:56:17 +0200107 * You can use #MBEDTLS_IGNORE_RETURN to explicitly ignore the return value
108 * of a function that is annotated with #MBEDTLS_CHECK_RETURN.
109 *
Gilles Peskine463adf42021-09-23 17:28:59 +0200110 * \note The use of this macro is a work in progress.
111 * This macro will be added to more functions in the future.
112 * Eventually this should appear before most functions returning
113 * an error code (as \c int in the \c mbedtls_xxx API or
114 * as ::psa_status_t in the \c psa_xxx API).
115 */
Gilles Peskine9a7d4c22021-09-23 18:07:36 +0200116#if defined(MBEDTLS_CHECK_RETURN_WARNING)
Gilles Peskine463adf42021-09-23 17:28:59 +0200117#define MBEDTLS_CHECK_RETURN_TYPICAL MBEDTLS_CHECK_RETURN
Gilles Peskine9a7d4c22021-09-23 18:07:36 +0200118#else
119#define MBEDTLS_CHECK_RETURN_TYPICAL
120#endif
Gilles Peskine463adf42021-09-23 17:28:59 +0200121
122/** Benign-failure function
123 *
124 * This macro appearing at the beginning of the declaration of a function
125 * indicates that it is rarely useful to check its return value.
126 *
127 * This macro has an empty expansion. It exists for documentation purposes:
128 * a #MBEDTLS_CHECK_RETURN_OPTIONAL annotation indicates that the function
129 * has been analyzed for return-check usefuless, whereas the lack of
130 * an annotation indicates that the function has not been analyzed and its
131 * return-check usefulness is unknown.
132 */
133#define MBEDTLS_CHECK_RETURN_OPTIONAL
134
Mateusz Starzyk5c4ca322021-08-05 13:56:48 +0200135/** \def MBEDTLS_IGNORE_RETURN
136 *
Gilles Peskinefcc93d72021-09-30 18:56:17 +0200137 * Call this macro with one argument, a function call, to suppress a warning
138 * from #MBEDTLS_CHECK_RETURN due to that function call.
139 */
140#if !defined(MBEDTLS_IGNORE_RETURN)
Gilles Peskine252b7582021-09-30 18:54:51 +0200141/* GCC doesn't silence the warning with just (void)(result).
142 * !(void)(result) is known to work up at least up to GCC 10, as well
143 * as with Clang and MSVC.
144 *
145 * https://gcc.gnu.org/onlinedocs/gcc-3.4.6/gcc/Non_002dbugs.html
146 * https://stackoverflow.com/questions/40576003/ignoring-warning-wunused-result
147 * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=66425#c34
Mateusz Starzyk5c4ca322021-08-05 13:56:48 +0200148 */
Gilles Peskine252b7582021-09-30 18:54:51 +0200149#define MBEDTLS_IGNORE_RETURN(result) ( (void) !( result ) )
Gilles Peskinefcc93d72021-09-30 18:56:17 +0200150#endif
Mateusz Starzyk5c4ca322021-08-05 13:56:48 +0200151
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -0500152/**
153 * \brief Securely zeroize a buffer
154 *
Andres Amaya Garcia56e06db2018-04-24 08:37:52 -0500155 * The function is meant to wipe the data contained in a buffer so
156 * that it can no longer be recovered even if the program memory
157 * is later compromised. Call this function on sensitive data
158 * stored on the stack before returning from a function, and on
159 * sensitive data stored on the heap before freeing the heap
160 * object.
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -0500161 *
Andres Amaya Garcia56e06db2018-04-24 08:37:52 -0500162 * It is extremely difficult to guarantee that calls to
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -0500163 * mbedtls_platform_zeroize() are not removed by aggressive
164 * compiler optimizations in a portable way. For this reason, Mbed
165 * TLS provides the configuration option
166 * MBEDTLS_PLATFORM_ZEROIZE_ALT, which allows users to configure
167 * mbedtls_platform_zeroize() to use a suitable implementation for
168 * their platform and needs
Andres Amaya Garcia56e06db2018-04-24 08:37:52 -0500169 *
170 * \param buf Buffer to be zeroized
171 * \param len Length of the buffer in bytes
172 *
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -0500173 */
174void mbedtls_platform_zeroize( void *buf, size_t len );
175
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100176#if defined(MBEDTLS_HAVE_TIME_DATE)
177/**
Hanno Beckerc52ef402018-09-05 16:28:59 +0100178 * \brief Platform-specific implementation of gmtime_r()
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100179 *
Hanno Beckerc52ef402018-09-05 16:28:59 +0100180 * The function is a thread-safe abstraction that behaves
Hanno Becker03b2bd42018-09-06 09:08:55 +0100181 * similarly to the gmtime_r() function from Unix/POSIX.
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100182 *
Hanno Becker6a739782018-09-05 15:06:19 +0100183 * Mbed TLS will try to identify the underlying platform and
Hanno Beckerc52ef402018-09-05 16:28:59 +0100184 * make use of an appropriate underlying implementation (e.g.
Hanno Becker6a739782018-09-05 15:06:19 +0100185 * gmtime_r() for POSIX and gmtime_s() for Windows). If this is
186 * not possible, then gmtime() will be used. In this case, calls
187 * from the library to gmtime() will be guarded by the mutex
188 * mbedtls_threading_gmtime_mutex if MBEDTLS_THREADING_C is
189 * enabled. It is recommended that calls from outside the library
190 * are also guarded by this mutex.
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100191 *
Hanno Becker6a739782018-09-05 15:06:19 +0100192 * If MBEDTLS_PLATFORM_GMTIME_R_ALT is defined, then Mbed TLS will
193 * unconditionally use the alternative implementation for
194 * mbedtls_platform_gmtime_r() supplied by the user at compile time.
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100195 *
Hanno Becker272675f2018-09-05 14:03:02 +0100196 * \param tt Pointer to an object containing time (in seconds) since the
Hanno Becker48a816f2018-09-05 15:22:22 +0100197 * epoch to be converted
Hanno Becker272675f2018-09-05 14:03:02 +0100198 * \param tm_buf Pointer to an object where the results will be stored
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100199 *
200 * \return Pointer to an object of type struct tm on success, otherwise
201 * NULL
202 */
Hanno Becker6a739782018-09-05 15:06:19 +0100203struct tm *mbedtls_platform_gmtime_r( const mbedtls_time_t *tt,
204 struct tm *tm_buf );
Andres Amaya Garcia1abb3682018-08-16 21:42:09 +0100205#endif /* MBEDTLS_HAVE_TIME_DATE */
206
Andres Amaya Garcia904e1ef2018-04-17 09:16:30 -0500207#ifdef __cplusplus
208}
209#endif
210
211#endif /* MBEDTLS_PLATFORM_UTIL_H */