Re: About multi-thread unsafe for APIs defined in crypto/objects/obj_dat.c

Benjamin Kaduk via openssl-dev <[email protected]> Wed, 24 Jan 2018 08:11:08 -0600
Newsgroups gmane.comp.encryption.openssl.devel
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2069411021902889704==
Content-Type: multipart/alternative;
 boundary="------------1272DE15FEDEF8E2E245C483"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------1272DE15FEDEF8E2E245C483
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit

On 01/23/2018 07:19 PM, Salz, Rich via openssl-dev wrote:
>
>   * OpenSSL APIs, which makes the following OpenSSL documentation
>     statement invalid
>     (https://www.openssl.org/docs/man1.0.2/crypto/threads.html
>     <https://urldefense.proofpoint.com/v2/url?u=https-3A__www.openssl.org_docs_man1.0.2_crypto_threads.html&d=DwMFAw&c=96ZbZZcaMF4w0F4jpN6LZg&r=4LM0GbR0h9Fvx86FtsKI-w&m=ZS_kRxGa4vj0O6wqfY-6q7kwVT0WiIMkFqw1XWHym4o&s=GK3QtuXP-8j_1nbRihxeJGLAIYXt1BNIyh3WHP6EJlY&e=>)
>
>  
>
>   * "OpenSSL can safely be used in multi-threaded applications
>     provided that at least two callback functions are set,
>     locking_function and threadid_func."
>
>  
>
>   * Is there any planning to fix this issue?
>
>  
>
>  
>
> Well, the most likely fix is to make the “safely” wording be more
> vague, which I doubt you’ll like.  But I doubt anyone on the team has
> much interest in fixing 1.0.2 locking issues.
>
>

Who said they were 1.0.2-specific?  Master's obj_dat.c still has a
completely unlocked OBJ_new_nid() that is a public API function; AFAICT
the issue is still present.

-Ben

--------------1272DE15FEDEF8E2E245C483
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    On 01/23/2018 07:19 PM, Salz, Rich via openssl-dev wrote:<br>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <meta name="Title" content="">
      <meta name="Keywords" content="">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:"Courier New";
	panose-1:2 7 3 9 2 2 5 2 4 4;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"PT Serif";
	panose-1:2 10 6 3 4 5 5 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
span.msoIns
	{mso-style-type:export-only;
	mso-style-name:"";
	text-decoration:underline;
	color:teal;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1946960878;
	mso-list-type:hybrid;
	mso-list-template-ids:1257645086 -1722887838 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New",serif;}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New",serif;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New",serif;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style>
      <div class="WordSection1">
        <ul style="margin-top:0in" type="disc">
          <li style="color:black;margin-left:0in;mso-list:l0 level1
            lfo1"><span style="font-size:12.0pt">OpenSSL APIs, which
              makes the following OpenSSL documentation statement
              invalid (<a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__www.openssl.org_docs_man1.0.2_crypto_threads.html&amp;d=DwMFAw&amp;c=96ZbZZcaMF4w0F4jpN6LZg&amp;r=4LM0GbR0h9Fvx86FtsKI-w&amp;m=ZS_kRxGa4vj0O6wqfY-6q7kwVT0WiIMkFqw1XWHym4o&amp;s=GK3QtuXP-8j_1nbRihxeJGLAIYXt1BNIyh3WHP6EJlY&amp;e="
                moz-do-not-send="true">https://www.openssl.org/docs/man1.0.2/crypto/threads.html</a>)<o:p></o:p></span></li>
        </ul>
        <p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
        <ul style="margin-top:0in" type="disc">
          <li style="color:black;margin-left:0in;mso-list:l0 level1
            lfo1"><span style="font-size:12.0pt">"</span><span
              style="font-size:14.0pt;font-family:&quot;PT
              Serif&quot;;color:#222222;background:#F8F8F8">OpenSSL can
              safely be used in multi-threaded applications provided
              that at least two callback functions are set,
              locking_function and threadid_func."</span><span
              style="font-size:12.0pt"><o:p></o:p></span></li>
        </ul>
        <p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
        <ul style="margin-top:0in" type="disc">
          <li style="color:black;margin-left:0in;mso-list:l0 level1
            lfo1"><span style="font-size:12.0pt">Is there any planning
              to fix this issue?<o:p></o:p></span></li>
        </ul>
        <p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
        <p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
        <p><span style="font-size:12.0pt;color:black">Well, the most
            likely fix is to make the “safely” wording be more vague,
            which I doubt you’ll like.  But I doubt anyone on the team
            has much interest in fixing 1.0.2 locking issues.<o:p></o:p></span></p>
      </div>
      <br>
    </blockquote>
    <br>
    Who said they were 1.0.2-specific?  Master's obj_dat.c still has a
    completely unlocked OBJ_new_nid() that is a public API function;
    AFAICT the issue is still present.<br>
    <br>
    -Ben<br>
  </body>
</html>

--------------1272DE15FEDEF8E2E245C483--

--===============2069411021902889704==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

--===============2069411021902889704==--