]>
Commit | Line | Data |
---|---|---|
b1ab9ed8 A |
1 | /* |
2 | * Copyright (c) 2011-2012 Apple Inc. All Rights Reserved. | |
3 | * | |
4 | * @APPLE_LICENSE_HEADER_START@ | |
5 | * | |
6 | * This file contains Original Code and/or Modifications of Original Code | |
7 | * as defined in and that are subject to the Apple Public Source License | |
8 | * Version 2.0 (the 'License'). You may not use this file except in | |
9 | * compliance with the License. Please obtain a copy of the License at | |
10 | * http://www.opensource.apple.com/apsl/ and read it before using this | |
11 | * file. | |
12 | * | |
13 | * The Original Code and all software distributed under the License are | |
14 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER | |
15 | * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, | |
16 | * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, | |
17 | * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. | |
18 | * Please see the License for the specific language governing rights and | |
19 | * limitations under the License. | |
20 | * | |
21 | * @APPLE_LICENSE_HEADER_END@ | |
22 | */ | |
23 | #ifndef _H_POLICYENGINE | |
24 | #define _H_POLICYENGINE | |
25 | ||
26 | #include "SecAssessment.h" | |
80e23899 | 27 | #include "opaquewhitelist.h" |
b1ab9ed8 A |
28 | #include "policydb.h" |
29 | #include <security_utilities/globalizer.h> | |
30 | #include <security_utilities/cfutilities.h> | |
31 | #include <security_utilities/hashing.h> | |
32 | #include <security_utilities/sqlite++.h> | |
33 | #include <CoreFoundation/CoreFoundation.h> | |
34 | #include <Security/CodeSigning.h> | |
35 | ||
36 | namespace Security { | |
37 | namespace CodeSigning { | |
38 | ||
39 | ||
40 | typedef uint EngineOperation; | |
41 | enum { | |
42 | opInvalid = 0, | |
43 | opEvaluate, | |
44 | opAddAuthority, | |
45 | opRemoveAuthority, | |
46 | }; | |
47 | ||
48 | ||
49 | class PolicyEngine : public PolicyDatabase { | |
50 | public: | |
51 | PolicyEngine(); | |
52 | virtual ~PolicyEngine(); | |
53 | ||
54 | public: | |
55 | void evaluate(CFURLRef path, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context, CFMutableDictionaryRef result); | |
56 | ||
57 | CFDictionaryRef update(CFTypeRef target, SecAssessmentFlags flags, CFDictionaryRef context); | |
58 | CFDictionaryRef add(CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
59 | CFDictionaryRef remove(CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
60 | CFDictionaryRef enable(CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
61 | CFDictionaryRef disable(CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
62 | CFDictionaryRef find(CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
63 | ||
427c49bc A |
64 | void recordFailure(CFDictionaryRef info); |
65 | ||
b1ab9ed8 | 66 | public: |
80e23899 | 67 | static void addAuthority(SecAssessmentFlags flags, CFMutableDictionaryRef parent, const char *label, SQLite::int64 row = 0, CFTypeRef cacheInfo = NULL, bool weak = false); |
b1ab9ed8 A |
68 | static void addToAuthority(CFMutableDictionaryRef parent, CFStringRef key, CFTypeRef value); |
69 | ||
70 | private: | |
427c49bc | 71 | void evaluateCode(CFURLRef path, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context, CFMutableDictionaryRef result, bool handleUnsigned); |
b1ab9ed8 A |
72 | void evaluateInstall(CFURLRef path, SecAssessmentFlags flags, CFDictionaryRef context, CFMutableDictionaryRef result); |
73 | void evaluateDocOpen(CFURLRef path, SecAssessmentFlags flags, CFDictionaryRef context, CFMutableDictionaryRef result); | |
74 | ||
427c49bc | 75 | void evaluateCodeItem(SecStaticCodeRef code, CFURLRef path, AuthorityType type, SecAssessmentFlags flags, bool nested, CFMutableDictionaryRef result); |
80e23899 | 76 | void adjustValidation(SecStaticCodeRef code); |
427c49bc A |
77 | bool temporarySigning(SecStaticCodeRef code, AuthorityType type, CFURLRef path, SecAssessmentFlags matchFlags); |
78 | void normalizeTarget(CFRef<CFTypeRef> &target, AuthorityType type, CFDictionary &context, std::string *signUnsigned); | |
79 | ||
b1ab9ed8 A |
80 | void selectRules(SQLite::Statement &action, std::string stanza, std::string table, |
81 | CFTypeRef inTarget, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context, std::string suffix = ""); | |
82 | CFDictionaryRef manipulateRules(const std::string &stanza, | |
83 | CFTypeRef target, AuthorityType type, SecAssessmentFlags flags, CFDictionaryRef context); | |
84 | ||
85 | void setOrigin(CFArrayRef chain, CFMutableDictionaryRef result); | |
86 | ||
87 | void recordOutcome(SecStaticCodeRef code, bool allow, AuthorityType type, double expires, SQLite::int64 authority); | |
80e23899 A |
88 | |
89 | private: | |
90 | OpaqueWhitelist mOpaqueWhitelist; | |
b1ab9ed8 A |
91 | }; |
92 | ||
93 | ||
94 | } // end namespace CodeSigning | |
95 | } // end namespace Security | |
96 | ||
97 | #endif //_H_POLICYENGINE |