Re: About multi-thread unsafe for APIs defined in crypto/objects/obj_dat.c
Benjamin Kaduk via openssl-dev <[email protected]> Wed, 24 Jan 2018 08:11:08 -0600
| Newsgroups | gmane.comp.encryption.openssl.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============2069411021902889704==
Content-Type: multipart/alternative;
boundary="------------1272DE15FEDEF8E2E245C483"
Content-Language: en-US
This is a multi-part message in MIME format.
--------------1272DE15FEDEF8E2E245C483
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
On 01/23/2018 07:19 PM, Salz, Rich via openssl-dev wrote:
>
> * OpenSSL APIs, which makes the following OpenSSL documentation
> statement invalid
> (https://www.openssl.org/docs/man1.0.2/crypto/threads.html
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__www.openssl.org_docs_man1.0.2_crypto_threads.html&d=DwMFAw&c=96ZbZZcaMF4w0F4jpN6LZg&r=4LM0GbR0h9Fvx86FtsKI-w&m=ZS_kRxGa4vj0O6wqfY-6q7kwVT0WiIMkFqw1XWHym4o&s=GK3QtuXP-8j_1nbRihxeJGLAIYXt1BNIyh3WHP6EJlY&e=>)
>
>
>
> * "OpenSSL can safely be used in multi-threaded applications
> provided that at least two callback functions are set,
> locking_function and threadid_func."
>
>
>
> * Is there any planning to fix this issue?
>
>
>
>
>
> Well, the most likely fix is to make the “safely” wording be more
> vague, which I doubt you’ll like. But I doubt anyone on the team has
> much interest in fixing 1.0.2 locking issues.
>
>
Who said they were 1.0.2-specific? Master's obj_dat.c still has a
completely unlocked OBJ_new_nid() that is a public API function; AFAICT
the issue is still present.
-Ben
--------------1272DE15FEDEF8E2E245C483
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
On 01/23/2018 07:19 PM, Salz, Rich via openssl-dev wrote:<br>
<blockquote type="cite"
cite="mid:[email protected]">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Title" content="">
<meta name="Keywords" content="">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Courier New";
panose-1:2 7 3 9 2 2 5 2 4 4;}
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"PT Serif";
panose-1:2 10 6 3 4 5 5 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.msoIns
{mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
color:teal;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1946960878;
mso-list-type:hybrid;
mso-list-template-ids:1257645086 -1722887838 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;
mso-fareast-font-family:Calibri;
mso-bidi-font-family:"Times New Roman";}
@list l0:level2
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New",serif;}
@list l0:level3
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
@list l0:level4
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Symbol;}
@list l0:level5
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New",serif;}
@list l0:level6
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
@list l0:level7
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Symbol;}
@list l0:level8
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:"Courier New",serif;}
@list l0:level9
{mso-level-number-format:bullet;
mso-level-text:;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;
font-family:Wingdings;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style>
<div class="WordSection1">
<ul style="margin-top:0in" type="disc">
<li style="color:black;margin-left:0in;mso-list:l0 level1
lfo1"><span style="font-size:12.0pt">OpenSSL APIs, which
makes the following OpenSSL documentation statement
invalid (<a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__www.openssl.org_docs_man1.0.2_crypto_threads.html&d=DwMFAw&c=96ZbZZcaMF4w0F4jpN6LZg&r=4LM0GbR0h9Fvx86FtsKI-w&m=ZS_kRxGa4vj0O6wqfY-6q7kwVT0WiIMkFqw1XWHym4o&s=GK3QtuXP-8j_1nbRihxeJGLAIYXt1BNIyh3WHP6EJlY&e="
moz-do-not-send="true">https://www.openssl.org/docs/man1.0.2/crypto/threads.html</a>)<o:p></o:p></span></li>
</ul>
<p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
<ul style="margin-top:0in" type="disc">
<li style="color:black;margin-left:0in;mso-list:l0 level1
lfo1"><span style="font-size:12.0pt">"</span><span
style="font-size:14.0pt;font-family:"PT
Serif";color:#222222;background:#F8F8F8">OpenSSL can
safely be used in multi-threaded applications provided
that at least two callback functions are set,
locking_function and threadid_func."</span><span
style="font-size:12.0pt"><o:p></o:p></span></li>
</ul>
<p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
<ul style="margin-top:0in" type="disc">
<li style="color:black;margin-left:0in;mso-list:l0 level1
lfo1"><span style="font-size:12.0pt">Is there any planning
to fix this issue?<o:p></o:p></span></li>
</ul>
<p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
<p><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
<p><span style="font-size:12.0pt;color:black">Well, the most
likely fix is to make the “safely” wording be more vague,
which I doubt you’ll like. But I doubt anyone on the team
has much interest in fixing 1.0.2 locking issues.<o:p></o:p></span></p>
</div>
<br>
</blockquote>
<br>
Who said they were 1.0.2-specific? Master's obj_dat.c still has a
completely unlocked OBJ_new_nid() that is a public API function;
AFAICT the issue is still present.<br>
<br>
-Ben<br>
</body>
</html>
--------------1272DE15FEDEF8E2E245C483--
--===============2069411021902889704==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
--===============2069411021902889704==--