Safe to link against gem extension?
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Lĩnh vực
- cryptography, security
Hướng nghiên cứu
Bắt đầu bằng cách xem xét các symbol được export từ openssl.so và wrapper API được đề xuất cho BIO, BIO_* và SSL_set_bio. So sánh cách tích hợp C-extension được puma và eventmachine sử dụng, sau đó xác định liệu có thể định nghĩa một API cross-gem được hỗ trợ hay không; công việc được coi là hoàn tất khi đã xác lập cách linking an toàn và mọi phần bổ sung API cần thiết.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Is there any way for one C extension to safely link against another?
Looking at the external symbols in openssl.so, I see the following:
$ nm tmp/x86_64-linux/openssl/3.0.2/openssl.so |
ruby -nae 'g=ARGF.grep(/ T /).map{_1.split[2]}.group_by{_1[/(\A(o|I)|_to)/]}.values.sort_by{-_1.size};
g[0].size.times{|i|puts ("%28s"*4)%g.map{_1[i]}}'
ossl_asn1_get_asn1type Init_openssl DupPKeyPtr asn1integer_to_num
ossl_bin2hex Init_ossl_asn1 DupX509CertPtr asn1str_to_str
ossl_bn_ctx_free Init_ossl_bn DupX509RevokedPtr asn1time_to_time
ossl_bn_ctx_get Init_ossl_cipher GetConfig num_to_asn1integer
ossl_bn_new Init_ossl_config GetPKeyPtr
ossl_bn_value_ptr Init_ossl_dh GetPrivPKeyPtr
ossl_buf2str Init_ossl_digest GetX509AttrPtr
ossl_cipher_new Init_ossl_dsa GetX509CertPtr
ossl_clear_error Init_ossl_ec GetX509CRLPtr
ossl_digest_new Init_ossl_engine GetX509ExtPtr
ossl_digest_update Init_ossl_hmac GetX509NamePtr
ossl_evp_get_cipherbyname Init_ossl_kdf GetX509ReqPtr
ossl_evp_get_digestbyname Init_ossl_ns_spki GetX509StorePtr
ossl_get_errors Init_ossl_ocsp
ossl_make_error Init_ossl_pkcs12
ossl_membio2str Init_ossl_pkcs7
ossl_obj2bio Init_ossl_pkey
ossl_pem_passwd_cb Init_ossl_rand
ossl_pem_passwd_value Init_ossl_rsa
ossl_pkey_check_public_key Init_ossl_ssl
ossl_pkey_export_spki Init_ossl_ssl_session
ossl_pkey_export_traditional Init_ossl_ts
ossl_pkey_new Init_ossl_x509
ossl_pkey_read_generic Init_ossl_x509attr
ossl_protect_x509_ary2sk Init_ossl_x509cert
ossl_raise Init_ossl_x509crl
ossl_str_new Init_ossl_x509ext
ossl_time_split Init_ossl_x509name
ossl_to_der Init_ossl_x509req
ossl_to_der_if_possible Init_ossl_x509revoked
ossl_verify_cb_call Init_ossl_x509store
ossl_x509_ary2sk
ossl_x509_ary2sk0
ossl_x509attr_new
ossl_x509crl_new
ossl_x509crl_sk2ary
ossl_x509ext_new
ossl_x509name_new
ossl_x509name_sk2ary
ossl_x509_new
ossl_x509revoked_new
ossl_x509_sk2ary
ossl_x509_time_adjust
If there's a safe way to do so, I'd like to use a couple of those... and maybe submit a PR with a few more.
I know of at least two gems with their own extensions linking against openssl (puma and eventmachine). It seems to me they would be able to use this gem's implementation with only a few additions to the API, if they could link against the C extension API. In particular, if there were a simple wrapper around the BIO struct, BIO_* functions, and SSL_set_bio, then those gems could be rewritten to use that.
For ease of maintenance and maximum eyeballs on such critical security infrastructure, I'd rather not have a new implementation in every gem with a C extension that needs access to openssl. (n.b. there has been at least three CVEs for gems which depend on eventmachine, all of which probably would've been avoided if eventmachine could've simply used stdlib's openssl)
- Ngôn ngữ chính
- C
- Star
- 276
- Fork
- 200
- Merge trung bình
- 15 giờ 35 phút
- Pull request đã merge (30 ngày)
- 7
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ruby/openssl
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
ruby/openssl#1082 · 4 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
ruby/openssl#1075 · 4 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Unchecked *_set_* callsĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
ruby/openssl#1038 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add a method OpenSSL::PKey#sizeĐang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
ruby/openssl#988 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
python-pillow/Pillow#10087 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
OpenPrinting/cups#1729 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
awslabs/amazon-kinesis-video-streams-webrtc-sdk-c#2406 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
DaveGamble/cJSON#1094 ·
-
status:needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
PX4/PX4-Autopilot#28923 ·
Maintainer thường phản hồi trong vòng 1 ngày