2011-06-30 17:46:53 +02:00
|
|
|
/* Copyright (c) 2000, 2011, Oracle and/or its affiliates. All rights reserved.
|
2001-12-06 14:10:51 +02:00
|
|
|
|
|
|
|
This program is free software; you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
2006-12-23 20:17:15 +01:00
|
|
|
the Free Software Foundation; version 2 of the License.
|
2001-12-06 14:10:51 +02:00
|
|
|
|
|
|
|
This program is distributed in the hope that it will be useful,
|
2001-07-24 14:07:46 +08:00
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
2001-12-06 14:10:51 +02:00
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2001-12-06 14:10:51 +02:00
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with this program; if not, write to the Free Software
|
2011-06-30 17:46:53 +02:00
|
|
|
Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2003-08-27 02:51:39 +03:00
|
|
|
#include "vio_priv.h"
|
2001-07-24 14:07:46 +08:00
|
|
|
|
|
|
|
#ifdef HAVE_OPENSSL
|
|
|
|
|
2008-02-18 23:29:39 +01:00
|
|
|
static my_bool ssl_algorithms_added = FALSE;
|
|
|
|
static my_bool ssl_error_strings_loaded= FALSE;
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2002-06-11 11:20:31 +03:00
|
|
|
static unsigned char dh512_p[]=
|
|
|
|
{
|
2001-09-01 05:51:52 +08:00
|
|
|
0xDA,0x58,0x3C,0x16,0xD9,0x85,0x22,0x89,0xD0,0xE4,0xAF,0x75,
|
|
|
|
0x6F,0x4C,0xCA,0x92,0xDD,0x4B,0xE5,0x33,0xB8,0x04,0xFB,0x0F,
|
|
|
|
0xED,0x94,0xEF,0x9C,0x8A,0x44,0x03,0xED,0x57,0x46,0x50,0xD3,
|
|
|
|
0x69,0x99,0xDB,0x29,0xD7,0x76,0x27,0x6B,0xA2,0xD3,0xD4,0x12,
|
|
|
|
0xE2,0x18,0xF4,0xDD,0x1E,0x08,0x4C,0xF6,0xD8,0x00,0x3E,0x7C,
|
|
|
|
0x47,0x74,0xE8,0x33,
|
|
|
|
};
|
2002-06-11 11:20:31 +03:00
|
|
|
|
2001-09-01 05:51:52 +08:00
|
|
|
static unsigned char dh512_g[]={
|
|
|
|
0x02,
|
|
|
|
};
|
|
|
|
|
|
|
|
static DH *get_dh512(void)
|
|
|
|
{
|
2002-06-11 11:20:31 +03:00
|
|
|
DH *dh;
|
|
|
|
if ((dh=DH_new()))
|
|
|
|
{
|
|
|
|
dh->p=BN_bin2bn(dh512_p,sizeof(dh512_p),NULL);
|
|
|
|
dh->g=BN_bin2bn(dh512_g,sizeof(dh512_g),NULL);
|
|
|
|
if (! dh->p || ! dh->g)
|
|
|
|
{
|
|
|
|
DH_free(dh);
|
|
|
|
dh=0;
|
|
|
|
}
|
|
|
|
}
|
2001-09-01 05:51:52 +08:00
|
|
|
return(dh);
|
|
|
|
}
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2002-06-11 11:20:31 +03:00
|
|
|
|
2001-05-20 14:04:46 +02:00
|
|
|
static void
|
|
|
|
report_errors()
|
|
|
|
{
|
|
|
|
unsigned long l;
|
|
|
|
const char* file;
|
|
|
|
const char* data;
|
|
|
|
int line,flags;
|
|
|
|
|
|
|
|
DBUG_ENTER("report_errors");
|
|
|
|
|
|
|
|
while ((l=ERR_get_error_line_data(&file,&line,&data,&flags)) != 0)
|
|
|
|
{
|
2002-09-18 21:04:49 +03:00
|
|
|
#ifndef DBUG_OFF /* Avoid warning */
|
2001-05-20 14:04:46 +02:00
|
|
|
char buf[200];
|
|
|
|
DBUG_PRINT("error", ("OpenSSL: %s:%s:%d:%s\n", ERR_error_string(l,buf),
|
2002-06-11 11:20:31 +03:00
|
|
|
file,line,(flags & ERR_TXT_STRING) ? data : "")) ;
|
2002-09-18 21:04:49 +03:00
|
|
|
#endif
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
|
|
|
DBUG_VOID_RETURN;
|
|
|
|
}
|
|
|
|
|
2009-07-23 13:38:11 +02:00
|
|
|
static const char*
|
|
|
|
ssl_error_string[] =
|
|
|
|
{
|
|
|
|
"No error",
|
|
|
|
"Unable to get certificate",
|
|
|
|
"Unable to get private key",
|
|
|
|
"Private key does not match the certificate public key"
|
|
|
|
"SSL_CTX_set_default_verify_paths failed",
|
|
|
|
"Failed to set ciphers to use",
|
|
|
|
"SSL_CTX_new failed"
|
|
|
|
};
|
|
|
|
|
|
|
|
const char*
|
|
|
|
sslGetErrString(enum enum_ssl_init_error e)
|
|
|
|
{
|
|
|
|
DBUG_ASSERT(SSL_INITERR_NOERROR < e && e < SSL_INITERR_LASTERR);
|
|
|
|
return ssl_error_string[e];
|
|
|
|
}
|
2001-05-20 14:04:46 +02:00
|
|
|
|
|
|
|
static int
|
2009-07-23 13:38:11 +02:00
|
|
|
vio_set_cert_stuff(SSL_CTX *ctx, const char *cert_file, const char *key_file,
|
|
|
|
enum enum_ssl_init_error* error)
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
|
|
|
DBUG_ENTER("vio_set_cert_stuff");
|
2006-11-20 22:42:06 +02:00
|
|
|
DBUG_PRINT("enter", ("ctx: 0x%lx cert_file: %s key_file: %s",
|
|
|
|
(long) ctx, cert_file, key_file));
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2012-08-11 15:43:04 +05:30
|
|
|
if (!cert_file && key_file)
|
|
|
|
cert_file= key_file;
|
|
|
|
|
|
|
|
if (!key_file && cert_file)
|
|
|
|
key_file= cert_file;
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2012-08-11 15:43:04 +05:30
|
|
|
if (cert_file &&
|
|
|
|
SSL_CTX_use_certificate_file(ctx, cert_file, SSL_FILETYPE_PEM) <= 0)
|
|
|
|
{
|
|
|
|
*error= SSL_INITERR_CERT;
|
|
|
|
DBUG_PRINT("error",("%s from file '%s'", sslGetErrString(*error), cert_file));
|
|
|
|
DBUG_EXECUTE("error", ERR_print_errors_fp(DBUG_FILE););
|
|
|
|
fprintf(stderr, "SSL error: %s from '%s'\n", sslGetErrString(*error),
|
|
|
|
cert_file);
|
|
|
|
fflush(stderr);
|
|
|
|
DBUG_RETURN(1);
|
|
|
|
}
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2012-08-11 15:43:04 +05:30
|
|
|
if (key_file &&
|
|
|
|
SSL_CTX_use_PrivateKey_file(ctx, key_file, SSL_FILETYPE_PEM) <= 0)
|
|
|
|
{
|
|
|
|
*error= SSL_INITERR_KEY;
|
|
|
|
DBUG_PRINT("error", ("%s from file '%s'", sslGetErrString(*error), key_file));
|
|
|
|
DBUG_EXECUTE("error", ERR_print_errors_fp(DBUG_FILE););
|
|
|
|
fprintf(stderr, "SSL error: %s from '%s'\n", sslGetErrString(*error),
|
|
|
|
key_file);
|
|
|
|
fflush(stderr);
|
|
|
|
DBUG_RETURN(1);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
If we are using DSA, we can copy the parameters from the private key
|
|
|
|
Now we know that a key and cert have been set against the SSL context
|
|
|
|
*/
|
|
|
|
if (cert_file && !SSL_CTX_check_private_key(ctx))
|
|
|
|
{
|
|
|
|
*error= SSL_INITERR_NOMATCH;
|
|
|
|
DBUG_PRINT("error", ("%s",sslGetErrString(*error)));
|
|
|
|
DBUG_EXECUTE("error", ERR_print_errors_fp(DBUG_FILE););
|
|
|
|
fprintf(stderr, "SSL error: %s\n", sslGetErrString(*error));
|
|
|
|
fflush(stderr);
|
|
|
|
DBUG_RETURN(1);
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
2012-08-11 15:43:04 +05:30
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
DBUG_RETURN(0);
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
static void check_ssl_init()
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
|
|
|
if (!ssl_algorithms_added)
|
|
|
|
{
|
2006-03-10 16:41:14 +01:00
|
|
|
ssl_algorithms_added= TRUE;
|
2005-11-29 12:15:48 +04:00
|
|
|
SSL_library_init();
|
2001-07-24 14:07:46 +08:00
|
|
|
OpenSSL_add_all_algorithms();
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2001-05-20 14:04:46 +02:00
|
|
|
if (!ssl_error_strings_loaded)
|
|
|
|
{
|
2006-03-10 16:41:14 +01:00
|
|
|
ssl_error_strings_loaded= TRUE;
|
2001-05-20 14:04:46 +02:00
|
|
|
SSL_load_error_strings();
|
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
/************************ VioSSLFd **********************************/
|
2006-05-08 17:14:06 +02:00
|
|
|
static struct st_VioSSLFd *
|
2006-03-10 16:41:14 +01:00
|
|
|
new_VioSSLFd(const char *key_file, const char *cert_file,
|
|
|
|
const char *ca_file, const char *ca_path,
|
2012-05-15 13:18:42 +03:00
|
|
|
const char *cipher, my_bool is_client_method,
|
2009-07-23 13:38:11 +02:00
|
|
|
enum enum_ssl_init_error* error)
|
2006-03-10 16:41:14 +01:00
|
|
|
{
|
|
|
|
DH *dh;
|
|
|
|
struct st_VioSSLFd *ssl_fd;
|
|
|
|
DBUG_ENTER("new_VioSSLFd");
|
2007-02-23 13:13:55 +02:00
|
|
|
DBUG_PRINT("enter",
|
|
|
|
("key_file: '%s' cert_file: '%s' ca_file: '%s' ca_path: '%s' "
|
|
|
|
"cipher: '%s'",
|
|
|
|
key_file ? key_file : "NULL",
|
|
|
|
cert_file ? cert_file : "NULL",
|
|
|
|
ca_file ? ca_file : "NULL",
|
|
|
|
ca_path ? ca_path : "NULL",
|
|
|
|
cipher ? cipher : "NULL"));
|
2006-03-10 16:41:14 +01:00
|
|
|
|
|
|
|
check_ssl_init();
|
|
|
|
|
|
|
|
if (!(ssl_fd= ((struct st_VioSSLFd*)
|
|
|
|
my_malloc(sizeof(struct st_VioSSLFd),MYF(0)))))
|
|
|
|
DBUG_RETURN(0);
|
|
|
|
|
2012-05-15 13:12:22 +03:00
|
|
|
if (!(ssl_fd->ssl_context= SSL_CTX_new(is_client_method ?
|
|
|
|
TLSv1_client_method() :
|
|
|
|
TLSv1_server_method())))
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
2009-07-23 13:38:11 +02:00
|
|
|
*error= SSL_INITERR_MEMFAIL;
|
|
|
|
DBUG_PRINT("error", ("%s", sslGetErrString(*error)));
|
2001-05-20 14:04:46 +02:00
|
|
|
report_errors();
|
Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled
Essentially, the problem is that safemalloc is excruciatingly
slow as it checks all allocated blocks for overrun at each
memory management primitive, yielding a almost exponential
slowdown for the memory management functions (malloc, realloc,
free). The overrun check basically consists of verifying some
bytes of a block for certain magic keys, which catches some
simple forms of overrun. Another minor problem is violation
of aliasing rules and that its own internal list of blocks
is prone to corruption.
Another issue with safemalloc is rather the maintenance cost
as the tool has a significant impact on the server code.
Given the magnitude of memory debuggers available nowadays,
especially those that are provided with the platform malloc
implementation, maintenance of a in-house and largely obsolete
memory debugger becomes a burden that is not worth the effort
due to its slowness and lack of support for detecting more
common forms of heap corruption.
Since there are third-party tools that can provide the same
functionality at a lower or comparable performance cost, the
solution is to simply remove safemalloc. Third-party tools
can provide the same functionality at a lower or comparable
performance cost.
The removal of safemalloc also allows a simplification of the
malloc wrappers, removing quite a bit of kludge: redefinition
of my_malloc, my_free and the removal of the unused second
argument of my_free. Since free() always check whether the
supplied pointer is null, redudant checks are also removed.
Also, this patch adds unit testing for my_malloc and moves
my_realloc implementation into the same file as the other
memory allocation primitives.
client/mysqldump.c:
Pass my_free directly as its signature is compatible with the
callback type -- which wasn't the case for free_table_ent.
2010-07-08 18:20:08 -03:00
|
|
|
my_free(ssl_fd);
|
2006-03-10 16:41:14 +01:00
|
|
|
DBUG_RETURN(0);
|
2001-09-30 10:46:20 +08:00
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2007-04-02 13:12:59 +02:00
|
|
|
/*
|
|
|
|
Set the ciphers that can be used
|
|
|
|
NOTE: SSL_CTX_set_cipher_list will return 0 if
|
|
|
|
none of the provided ciphers could be selected
|
|
|
|
*/
|
|
|
|
if (cipher &&
|
|
|
|
SSL_CTX_set_cipher_list(ssl_fd->ssl_context, cipher) == 0)
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
2009-07-23 13:38:11 +02:00
|
|
|
*error= SSL_INITERR_CIPHERS;
|
|
|
|
DBUG_PRINT("error", ("%s", sslGetErrString(*error)));
|
2001-05-20 14:04:46 +02:00
|
|
|
report_errors();
|
2006-11-07 15:20:24 +01:00
|
|
|
SSL_CTX_free(ssl_fd->ssl_context);
|
Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled
Essentially, the problem is that safemalloc is excruciatingly
slow as it checks all allocated blocks for overrun at each
memory management primitive, yielding a almost exponential
slowdown for the memory management functions (malloc, realloc,
free). The overrun check basically consists of verifying some
bytes of a block for certain magic keys, which catches some
simple forms of overrun. Another minor problem is violation
of aliasing rules and that its own internal list of blocks
is prone to corruption.
Another issue with safemalloc is rather the maintenance cost
as the tool has a significant impact on the server code.
Given the magnitude of memory debuggers available nowadays,
especially those that are provided with the platform malloc
implementation, maintenance of a in-house and largely obsolete
memory debugger becomes a burden that is not worth the effort
due to its slowness and lack of support for detecting more
common forms of heap corruption.
Since there are third-party tools that can provide the same
functionality at a lower or comparable performance cost, the
solution is to simply remove safemalloc. Third-party tools
can provide the same functionality at a lower or comparable
performance cost.
The removal of safemalloc also allows a simplification of the
malloc wrappers, removing quite a bit of kludge: redefinition
of my_malloc, my_free and the removal of the unused second
argument of my_free. Since free() always check whether the
supplied pointer is null, redudant checks are also removed.
Also, this patch adds unit testing for my_malloc and moves
my_realloc implementation into the same file as the other
memory allocation primitives.
client/mysqldump.c:
Pass my_free directly as its signature is compatible with the
callback type -- which wasn't the case for free_table_ent.
2010-07-08 18:20:08 -03:00
|
|
|
my_free(ssl_fd);
|
2006-03-10 16:41:14 +01:00
|
|
|
DBUG_RETURN(0);
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
|
2006-05-03 14:09:08 +02:00
|
|
|
/* Load certs from the trusted ca */
|
2006-03-10 16:41:14 +01:00
|
|
|
if (SSL_CTX_load_verify_locations(ssl_fd->ssl_context, ca_file, ca_path) == 0)
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
|
|
|
DBUG_PRINT("warning", ("SSL_CTX_load_verify_locations failed"));
|
2012-08-11 15:43:04 +05:30
|
|
|
if (ca_file || ca_path)
|
|
|
|
{
|
|
|
|
/* fail only if ca file or ca path were supplied and looking into
|
|
|
|
them fails. */
|
|
|
|
*error= SSL_INITERR_BAD_PATHS;
|
|
|
|
DBUG_PRINT("error", ("SSL_CTX_load_verify_locations failed : %s",
|
|
|
|
sslGetErrString(*error)));
|
|
|
|
report_errors();
|
|
|
|
SSL_CTX_free(ssl_fd->ssl_context);
|
2012-08-11 15:52:11 +05:30
|
|
|
my_free(ssl_fd);
|
2012-08-11 15:43:04 +05:30
|
|
|
DBUG_RETURN(0);
|
|
|
|
}
|
|
|
|
|
|
|
|
/* otherwise go use the defaults */
|
2006-03-10 16:41:14 +01:00
|
|
|
if (SSL_CTX_set_default_verify_paths(ssl_fd->ssl_context) == 0)
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
2009-07-23 13:38:11 +02:00
|
|
|
*error= SSL_INITERR_BAD_PATHS;
|
|
|
|
DBUG_PRINT("error", ("%s", sslGetErrString(*error)));
|
2001-05-20 14:04:46 +02:00
|
|
|
report_errors();
|
2006-11-07 15:20:24 +01:00
|
|
|
SSL_CTX_free(ssl_fd->ssl_context);
|
Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled
Essentially, the problem is that safemalloc is excruciatingly
slow as it checks all allocated blocks for overrun at each
memory management primitive, yielding a almost exponential
slowdown for the memory management functions (malloc, realloc,
free). The overrun check basically consists of verifying some
bytes of a block for certain magic keys, which catches some
simple forms of overrun. Another minor problem is violation
of aliasing rules and that its own internal list of blocks
is prone to corruption.
Another issue with safemalloc is rather the maintenance cost
as the tool has a significant impact on the server code.
Given the magnitude of memory debuggers available nowadays,
especially those that are provided with the platform malloc
implementation, maintenance of a in-house and largely obsolete
memory debugger becomes a burden that is not worth the effort
due to its slowness and lack of support for detecting more
common forms of heap corruption.
Since there are third-party tools that can provide the same
functionality at a lower or comparable performance cost, the
solution is to simply remove safemalloc. Third-party tools
can provide the same functionality at a lower or comparable
performance cost.
The removal of safemalloc also allows a simplification of the
malloc wrappers, removing quite a bit of kludge: redefinition
of my_malloc, my_free and the removal of the unused second
argument of my_free. Since free() always check whether the
supplied pointer is null, redudant checks are also removed.
Also, this patch adds unit testing for my_malloc and moves
my_realloc implementation into the same file as the other
memory allocation primitives.
client/mysqldump.c:
Pass my_free directly as its signature is compatible with the
callback type -- which wasn't the case for free_table_ent.
2010-07-08 18:20:08 -03:00
|
|
|
my_free(ssl_fd);
|
2006-03-10 16:41:14 +01:00
|
|
|
DBUG_RETURN(0);
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
}
|
2001-09-01 05:51:52 +08:00
|
|
|
|
2009-07-23 13:38:11 +02:00
|
|
|
if (vio_set_cert_stuff(ssl_fd->ssl_context, cert_file, key_file, error))
|
2006-05-03 14:09:08 +02:00
|
|
|
{
|
|
|
|
DBUG_PRINT("error", ("vio_set_cert_stuff failed"));
|
|
|
|
report_errors();
|
2006-11-07 15:20:24 +01:00
|
|
|
SSL_CTX_free(ssl_fd->ssl_context);
|
Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled
Essentially, the problem is that safemalloc is excruciatingly
slow as it checks all allocated blocks for overrun at each
memory management primitive, yielding a almost exponential
slowdown for the memory management functions (malloc, realloc,
free). The overrun check basically consists of verifying some
bytes of a block for certain magic keys, which catches some
simple forms of overrun. Another minor problem is violation
of aliasing rules and that its own internal list of blocks
is prone to corruption.
Another issue with safemalloc is rather the maintenance cost
as the tool has a significant impact on the server code.
Given the magnitude of memory debuggers available nowadays,
especially those that are provided with the platform malloc
implementation, maintenance of a in-house and largely obsolete
memory debugger becomes a burden that is not worth the effort
due to its slowness and lack of support for detecting more
common forms of heap corruption.
Since there are third-party tools that can provide the same
functionality at a lower or comparable performance cost, the
solution is to simply remove safemalloc. Third-party tools
can provide the same functionality at a lower or comparable
performance cost.
The removal of safemalloc also allows a simplification of the
malloc wrappers, removing quite a bit of kludge: redefinition
of my_malloc, my_free and the removal of the unused second
argument of my_free. Since free() always check whether the
supplied pointer is null, redudant checks are also removed.
Also, this patch adds unit testing for my_malloc and moves
my_realloc implementation into the same file as the other
memory allocation primitives.
client/mysqldump.c:
Pass my_free directly as its signature is compatible with the
callback type -- which wasn't the case for free_table_ent.
2010-07-08 18:20:08 -03:00
|
|
|
my_free(ssl_fd);
|
2006-05-03 14:09:08 +02:00
|
|
|
DBUG_RETURN(0);
|
|
|
|
}
|
2001-09-01 05:51:52 +08:00
|
|
|
|
|
|
|
/* DH stuff */
|
|
|
|
dh=get_dh512();
|
2006-03-10 16:41:14 +01:00
|
|
|
SSL_CTX_set_tmp_dh(ssl_fd->ssl_context, dh);
|
2001-09-01 05:51:52 +08:00
|
|
|
DH_free(dh);
|
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
DBUG_PRINT("exit", ("OK 1"));
|
|
|
|
|
|
|
|
DBUG_RETURN(ssl_fd);
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
/************************ VioSSLConnectorFd **********************************/
|
|
|
|
struct st_VioSSLFd *
|
|
|
|
new_VioSSLConnectorFd(const char *key_file, const char *cert_file,
|
|
|
|
const char *ca_file, const char *ca_path,
|
2011-05-19 10:47:43 +01:00
|
|
|
const char *cipher, enum enum_ssl_init_error* error)
|
2001-05-20 14:04:46 +02:00
|
|
|
{
|
2006-03-10 16:41:14 +01:00
|
|
|
struct st_VioSSLFd *ssl_fd;
|
2006-04-18 17:58:27 +02:00
|
|
|
int verify= SSL_VERIFY_PEER;
|
2007-03-28 12:23:55 +02:00
|
|
|
|
|
|
|
/*
|
|
|
|
Turn off verification of servers certificate if both
|
|
|
|
ca_file and ca_path is set to NULL
|
|
|
|
*/
|
|
|
|
if (ca_file == 0 && ca_path == 0)
|
|
|
|
verify= SSL_VERIFY_NONE;
|
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
if (!(ssl_fd= new_VioSSLFd(key_file, cert_file, ca_file,
|
2012-05-15 13:18:42 +03:00
|
|
|
ca_path, cipher, TRUE, error)))
|
2006-03-10 16:41:14 +01:00
|
|
|
{
|
|
|
|
return 0;
|
|
|
|
}
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2006-05-03 14:09:08 +02:00
|
|
|
/* Init the VioSSLFd as a "connector" ie. the client side */
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2009-10-27 15:11:06 +02:00
|
|
|
SSL_CTX_set_verify(ssl_fd->ssl_context, verify, NULL);
|
2001-07-24 14:07:46 +08:00
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
return ssl_fd;
|
|
|
|
}
|
2005-11-29 12:15:48 +04:00
|
|
|
|
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
/************************ VioSSLAcceptorFd **********************************/
|
2006-05-09 20:50:29 +03:00
|
|
|
struct st_VioSSLFd *
|
2006-03-10 16:41:14 +01:00
|
|
|
new_VioSSLAcceptorFd(const char *key_file, const char *cert_file,
|
|
|
|
const char *ca_file, const char *ca_path,
|
2009-07-23 13:38:11 +02:00
|
|
|
const char *cipher, enum enum_ssl_init_error* error)
|
2006-03-10 16:41:14 +01:00
|
|
|
{
|
|
|
|
struct st_VioSSLFd *ssl_fd;
|
|
|
|
int verify= SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE;
|
|
|
|
if (!(ssl_fd= new_VioSSLFd(key_file, cert_file, ca_file,
|
2012-05-15 13:12:22 +03:00
|
|
|
ca_path, cipher, FALSE, error)))
|
2001-09-30 10:46:20 +08:00
|
|
|
{
|
2006-03-10 16:41:14 +01:00
|
|
|
return 0;
|
2001-09-30 10:46:20 +08:00
|
|
|
}
|
2006-03-10 16:41:14 +01:00
|
|
|
/* Init the the VioSSLFd as a "acceptor" ie. the server side */
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
/* Set max number of cached sessions, returns the previous size */
|
|
|
|
SSL_CTX_sess_set_cache_size(ssl_fd->ssl_context, 128);
|
2001-05-20 14:04:46 +02:00
|
|
|
|
2009-10-27 15:11:06 +02:00
|
|
|
SSL_CTX_set_verify(ssl_fd->ssl_context, verify, NULL);
|
2002-06-11 11:20:31 +03:00
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
/*
|
|
|
|
Set session_id - an identifier for this server session
|
|
|
|
Use the ssl_fd pointer
|
|
|
|
*/
|
|
|
|
SSL_CTX_set_session_id_context(ssl_fd->ssl_context,
|
2006-05-04 10:30:08 +02:00
|
|
|
(const unsigned char *)ssl_fd,
|
2006-03-10 16:41:14 +01:00
|
|
|
sizeof(ssl_fd));
|
2006-05-03 15:59:17 +03:00
|
|
|
|
2006-03-10 16:41:14 +01:00
|
|
|
return ssl_fd;
|
2001-05-20 14:04:46 +02:00
|
|
|
}
|
2006-05-03 15:59:17 +03:00
|
|
|
|
2006-05-09 20:50:29 +03:00
|
|
|
void free_vio_ssl_acceptor_fd(struct st_VioSSLFd *fd)
|
2006-05-03 15:59:17 +03:00
|
|
|
{
|
|
|
|
SSL_CTX_free(fd->ssl_context);
|
Bug#34043: Server loops excessively in _checkchunk() when safemalloc is enabled
Essentially, the problem is that safemalloc is excruciatingly
slow as it checks all allocated blocks for overrun at each
memory management primitive, yielding a almost exponential
slowdown for the memory management functions (malloc, realloc,
free). The overrun check basically consists of verifying some
bytes of a block for certain magic keys, which catches some
simple forms of overrun. Another minor problem is violation
of aliasing rules and that its own internal list of blocks
is prone to corruption.
Another issue with safemalloc is rather the maintenance cost
as the tool has a significant impact on the server code.
Given the magnitude of memory debuggers available nowadays,
especially those that are provided with the platform malloc
implementation, maintenance of a in-house and largely obsolete
memory debugger becomes a burden that is not worth the effort
due to its slowness and lack of support for detecting more
common forms of heap corruption.
Since there are third-party tools that can provide the same
functionality at a lower or comparable performance cost, the
solution is to simply remove safemalloc. Third-party tools
can provide the same functionality at a lower or comparable
performance cost.
The removal of safemalloc also allows a simplification of the
malloc wrappers, removing quite a bit of kludge: redefinition
of my_malloc, my_free and the removal of the unused second
argument of my_free. Since free() always check whether the
supplied pointer is null, redudant checks are also removed.
Also, this patch adds unit testing for my_malloc and moves
my_realloc implementation into the same file as the other
memory allocation primitives.
client/mysqldump.c:
Pass my_free directly as its signature is compatible with the
callback type -- which wasn't the case for free_table_ent.
2010-07-08 18:20:08 -03:00
|
|
|
my_free(fd);
|
2006-05-03 15:59:17 +03:00
|
|
|
}
|
2001-05-20 14:04:46 +02:00
|
|
|
#endif /* HAVE_OPENSSL */
|