aboutsummaryrefslogtreecommitdiffstats
path: root/test/secmemtest.c
blob: c31f391c59eefaf55bd572bf85cdc696e0de96b1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
/*
 * Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.
 *
 * Licensed under the OpenSSL license (the "License").  You may not use
 * this file except in compliance with the License.  You can obtain a copy
 * in the file LICENSE in the source distribution or at
 * https://www.openssl.org/source/license.html
 */

#include <openssl/crypto.h>

#define perror_line()    perror_line1(__LINE__)
#define perror_line1(l)  perror_line2(l)
#define perror_line2(l)  perror("failed " #l)

int main(int argc, char **argv)
{
#if defined(OPENSSL_SYS_LINUX) || defined(OPENSSL_SYS_UNIX)
    char *p = NULL, *q = NULL, *r = NULL, *s = NULL;

    r = OPENSSL_secure_malloc(20);
    /* r = non-secure 20 */
    if (r == NULL) {
        perror_line();
        return 1;
    }
    if (!CRYPTO_secure_malloc_init(4096, 32)) {
        perror_line();
        return 1;
    }
    if (CRYPTO_secure_allocated(r)) {
        perror_line();
        return 1;
    }
    p = OPENSSL_secure_malloc(20);
    /* r = non-secure 20, p = secure 20 */
    if (!CRYPTO_secure_allocated(p)) {
        perror_line();
        return 1;
    }
    /* 20 secure -> 32-byte minimum allocaton unit */
    if (CRYPTO_secure_used() != 32) {
        perror_line();
        return 1;
    }
    q = OPENSSL_malloc(20);
    /* r = non-secure 20, p = secure 20, q = non-secure 20 */
    if (CRYPTO_secure_allocated(q)) {
        perror_line();
        return 1;
    }
    s = OPENSSL_secure_malloc(20);
    /* r = non-secure 20, p = secure 20, q = non-secure 20, s = secure 20 */
    if (!CRYPTO_secure_allocated(s)) {
        perror_line();
        return 1;
    }
    /* 2 * 20 secure -> 64 bytes allocated */
    if (CRYPTO_secure_used() != 64) {
        perror_line();
        return 1;
    }
    OPENSSL_secure_free(p);
    /* 20 secure -> 32 bytes allocated */
    if (CRYPTO_secure_used() != 32) {
        perror_line();
        return 1;
    }
    OPENSSL_free(q);
    /* should not complete, as secure memory is still allocated */
    if (CRYPTO_secure_malloc_done()) {
        perror_line();
        return 1;
    }
    if (!CRYPTO_secure_malloc_initialized()) {
        perror_line();
        return 1;
    }
    OPENSSL_secure_free(s);
    /* secure memory should now be 0, so done should complete */
    if (CRYPTO_secure_used() != 0) {
        perror_line();
        return 1;
    }
    if (!CRYPTO_secure_malloc_done()) {
        perror_line();
        return 1;
    }
    if (CRYPTO_secure_malloc_initialized()) {
        perror_line();
        return 1;
    }
    /* this can complete - it was not really secure */
    OPENSSL_secure_free(r);
#else
    /* Should fail. */
    if (CRYPTO_secure_malloc_init(4096, 32)) {
        perror_line();
        return 1;
    }
#endif
    return 0;
}