Path: blob/master/src/jdk.crypto.cryptoki/share/native/libj2pkcs11/j2secmod.c
41152 views
/*1* Copyright (c) 2005, 2014, Oracle and/or its affiliates. All rights reserved.2* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.3*4* This code is free software; you can redistribute it and/or modify it5* under the terms of the GNU General Public License version 2 only, as6* published by the Free Software Foundation. Oracle designates this7* particular file as subject to the "Classpath" exception as provided8* by Oracle in the LICENSE file that accompanied this code.9*10* This code is distributed in the hope that it will be useful, but WITHOUT11* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or12* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License13* version 2 for more details (a copy is included in the LICENSE file that14* accompanied this code).15*16* You should have received a copy of the GNU General Public License version17* 2 along with this work; if not, write to the Free Software Foundation,18* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.19*20* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA21* or visit www.oracle.com if you need additional information or have any22* questions.23*/2425#include <stdio.h>26#include <stdlib.h>27#include <string.h>2829// #define SECMOD_DEBUG3031#include "j2secmod.h"32#include "jni_util.h"333435JNIEXPORT jboolean JNICALL Java_sun_security_pkcs11_Secmod_nssVersionCheck36(JNIEnv *env, jclass thisClass, jlong jHandle, jstring jVersion)37{38int res = 0;39FPTR_VersionCheck versionCheck;40const char *requiredVersion;4142versionCheck = (FPTR_VersionCheck)findFunction(env, jHandle,43"NSS_VersionCheck");44if (versionCheck == NULL) {45return JNI_FALSE;46}4748requiredVersion = (*env)->GetStringUTFChars(env, jVersion, NULL);49if (requiredVersion == NULL) {50return JNI_FALSE;51}5253res = versionCheck(requiredVersion);54dprintf2("-version >=%s: %d\n", requiredVersion, res);55(*env)->ReleaseStringUTFChars(env, jVersion, requiredVersion);5657return (res == 0) ? JNI_FALSE : JNI_TRUE;58}5960/*61* Initializes NSS.62* The NSS_INIT_OPTIMIZESPACE flag is supplied by the caller.63* The NSS_Init* functions are mapped to the NSS_Initialize function.64*/65JNIEXPORT jboolean JNICALL Java_sun_security_pkcs11_Secmod_nssInitialize66(JNIEnv *env, jclass thisClass, jstring jFunctionName, jlong jHandle, jstring jConfigDir, jboolean jNssOptimizeSpace)67{68int res = 0;69FPTR_Initialize initialize =70(FPTR_Initialize)findFunction(env, jHandle, "NSS_Initialize");71#ifdef SECMOD_DEBUG72FPTR_GetError getError =73(FPTR_GetError)findFunction(env, jHandle, "PORT_GetError");74#endif // SECMOD_DEBUG75unsigned int flags = 0x00;76const char *configDir = NULL;77const char *functionName = NULL;78const char *configFile = NULL;7980/* If we cannot initialize, exit now */81if (initialize == NULL) {82res = 1;83goto cleanup;84}8586functionName = (*env)->GetStringUTFChars(env, jFunctionName, NULL);87if (functionName == NULL) {88res = 1;89goto cleanup;90}9192if (jConfigDir != NULL) {93configDir = (*env)->GetStringUTFChars(env, jConfigDir, NULL);94if (!configDir) {95res = 1;96goto cleanup;97}98}99100if (jNssOptimizeSpace == JNI_TRUE) {101flags = 0x20; // NSS_INIT_OPTIMIZESPACE flag102}103104configFile = "secmod.db";105if (configDir != NULL && strncmp("sql:", configDir, 4U) == 0) {106configFile = "pkcs11.txt";107}108109/*110* If the NSS_Init function is requested then call NSS_Initialize to111* open the Cert, Key and Security Module databases, read only.112*/113if (strcmp("NSS_Init", functionName) == 0) {114flags = flags | 0x01; // NSS_INIT_READONLY flag115res = initialize(configDir, "", "", configFile, flags);116117/*118* If the NSS_InitReadWrite function is requested then call119* NSS_Initialize to open the Cert, Key and Security Module databases,120* read/write.121*/122} else if (strcmp("NSS_InitReadWrite", functionName) == 0) {123res = initialize(configDir, "", "", configFile, flags);124125/*126* If the NSS_NoDB_Init function is requested then call127* NSS_Initialize without creating Cert, Key or Security Module128* databases.129*/130} else if (strcmp("NSS_NoDB_Init", functionName) == 0) {131flags = flags | 0x02 // NSS_INIT_NOCERTDB flag132| 0x04 // NSS_INIT_NOMODDB flag133| 0x08 // NSS_INIT_FORCEOPEN flag134| 0x10; // NSS_INIT_NOROOTINIT flag135res = initialize("", "", "", "", flags);136137} else {138res = 2;139}140141cleanup:142if (functionName != NULL) {143(*env)->ReleaseStringUTFChars(env, jFunctionName, functionName);144}145if (configDir != NULL) {146(*env)->ReleaseStringUTFChars(env, jConfigDir, configDir);147}148dprintf1("-res: %d\n", res);149#ifdef SECMOD_DEBUG150if (res == -1) {151if (getError != NULL) {152dprintf1("-NSS error: %d\n", getError());153}154}155#endif // SECMOD_DEBUG156157return (res == 0) ? JNI_TRUE : JNI_FALSE;158}159160JNIEXPORT jobject JNICALL Java_sun_security_pkcs11_Secmod_nssGetModuleList161(JNIEnv *env, jclass thisClass, jlong jHandle, jstring jLibDir)162{163FPTR_GetDBModuleList getModuleList =164(FPTR_GetDBModuleList)findFunction(env, jHandle, "SECMOD_GetDefaultModuleList");165166SECMODModuleList *list;167SECMODModule *module;168jclass jListClass, jModuleClass;169jobject jList, jModule;170jmethodID jListConstructor, jAdd, jModuleConstructor;171jstring jCommonName, jDllName;172jint i, jSlotID;173174if (getModuleList == NULL) {175dprintf("-getmodulelist function not found\n");176return NULL;177}178list = getModuleList();179if (list == NULL) {180dprintf("-module list is null\n");181return NULL;182}183184jListClass = (*env)->FindClass(env, "java/util/ArrayList");185if (jListClass == NULL) {186return NULL;187}188jListConstructor = (*env)->GetMethodID(env, jListClass, "<init>", "()V");189if (jListConstructor == NULL) {190return NULL;191}192jAdd = (*env)->GetMethodID(env, jListClass, "add", "(Ljava/lang/Object;)Z");193if (jAdd == NULL) {194return NULL;195}196jList = (*env)->NewObject(env, jListClass, jListConstructor);197if (jList == NULL) {198return NULL;199}200jModuleClass = (*env)->FindClass(env, "sun/security/pkcs11/Secmod$Module");201if (jModuleClass == NULL) {202return NULL;203}204jModuleConstructor = (*env)->GetMethodID(env, jModuleClass, "<init>",205"(Ljava/lang/String;Ljava/lang/String;Ljava/lang/String;II)V");206if (jModuleConstructor == NULL) {207return NULL;208}209210while (list != NULL) {211module = list->module;212// assert module != null213dprintf1("-commonname: %s\n", module->commonName);214dprintf1("-dllname: %s\n", (module->dllName != NULL) ? module->dllName : "NULL");215dprintf1("-slots: %d\n", module->slotCount);216dprintf1("-loaded: %d\n", module->loaded);217dprintf1("-internal: %d\n", module->internal);218dprintf1("-fips: %d\n", module->isFIPS);219jCommonName = (*env)->NewStringUTF(env, module->commonName);220if (jCommonName == NULL) {221return NULL;222}223if (module->dllName == NULL) {224jDllName = NULL;225} else {226jDllName = (*env)->NewStringUTF(env, module->dllName);227if (jDllName == NULL) {228return NULL;229}230}231for (i = 0; i < module->slotCount; i++ ) {232jSlotID = module->slots[i]->slotID;233if (jDllName == NULL && jSlotID != NETSCAPE_SLOT_ID &&234jSlotID != PRIVATE_KEY_SLOT_ID && jSlotID != FIPS_SLOT_ID) {235// Ignore unknown slot IDs in the NSS Internal Module. See JDK-8265462.236continue;237}238jModule = (*env)->NewObject(env, jModuleClass, jModuleConstructor,239jLibDir, jDllName, jCommonName, i, jSlotID);240if (jModule == NULL) {241return NULL;242}243(*env)->CallVoidMethod(env, jList, jAdd, jModule);244if ((*env)->ExceptionCheck(env)) {245return NULL;246}247}248list = list->next;249}250dprintf("-ok\n");251252return jList;253}254255256