]> git.saurik.com Git - apple/security.git/blob - OSX/sec/SOSCircle/SecureObjectSync/SOSAccount.h
Security-57336.1.9.tar.gz
[apple/security.git] / OSX / sec / SOSCircle / SecureObjectSync / SOSAccount.h
1 /*
2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24
25 /*!
26 @header SOSAccount.h
27 The functions provided in SOSCircle.h provide an interface to a
28 secure object syncing circle for a single class
29 */
30
31 #ifndef _SOSACCOUNT_H_
32 #define _SOSACCOUNT_H_
33
34 /* Forward declarations of SOS types. */
35 typedef struct __OpaqueSOSAccount *SOSAccountRef;
36
37
38 #include <CoreFoundation/CoreFoundation.h>
39
40 #include <Security/SecureObjectSync/SOSCircle.h>
41 #include <Security/SecureObjectSync/SOSFullPeerInfo.h>
42 #include <Security/SecureObjectSync/SOSCloudCircle.h>
43 #include <Security/SecureObjectSync/SOSCloudCircleInternal.h>
44 #include <Security/SecureObjectSync/SOSTransportKeyParameter.h>
45 #include <Security/SecureObjectSync/SOSTransportCircle.h>
46 #include <Security/SecureObjectSync/SOSTransportMessage.h>
47 #include <Security/SecureObjectSync/SOSRing.h>
48 #include <Security/SecureObjectSync/SOSPeerInfoSecurityProperties.h>
49
50 #include <dispatch/dispatch.h>
51
52 __BEGIN_DECLS
53
54 #define RETIREMENT_FINALIZATION_SECONDS (24*60*60)
55
56
57 typedef void (^SOSAccountCircleMembershipChangeBlock)(SOSCircleRef new_circle,
58 CFSetRef added_peers, CFSetRef removed_peers,
59 CFSetRef added_applicants, CFSetRef removed_applicants);
60 typedef void (^SOSAccountSyncablePeersBlock)(CFArrayRef trustedPeers, CFArrayRef addedPeers, CFArrayRef removedPeers);
61
62 SOSAccountRef SOSAccountCreate(CFAllocatorRef allocator,
63 CFDictionaryRef gestalt,
64 SOSDataSourceFactoryRef factory);
65 SOSAccountRef SOSAccountCreateBasic(CFAllocatorRef allocator,
66 CFDictionaryRef gestalt,
67 SOSDataSourceFactoryRef factory);
68
69
70 CFTypeID SOSAccountGetTypeID(void);
71
72 //
73 // MARK: Persistent Encode decode
74 //
75
76 SOSAccountRef SOSAccountCreateFromDER(CFAllocatorRef allocator, SOSDataSourceFactoryRef factory,
77 CFErrorRef* error,
78 const uint8_t** der_p, const uint8_t *der_end);
79
80 SOSAccountRef SOSAccountCreateFromDER_V3(CFAllocatorRef allocator,
81 SOSDataSourceFactoryRef factory,
82 CFErrorRef* error,
83 const uint8_t** der_p, const uint8_t *der_end);
84
85 SOSAccountRef SOSAccountCreateFromData(CFAllocatorRef allocator, CFDataRef circleData,
86 SOSDataSourceFactoryRef factory,
87 CFErrorRef* error);
88
89 size_t SOSAccountGetDEREncodedSize(SOSAccountRef cir, CFErrorRef *error);
90 uint8_t* SOSAccountEncodeToDER(SOSAccountRef cir, CFErrorRef* error, const uint8_t* der, uint8_t* der_end);
91 size_t SOSAccountGetDEREncodedSize_V3(SOSAccountRef cir, CFErrorRef *error);
92 uint8_t* SOSAccountEncodeToDER_V3(SOSAccountRef cir, CFErrorRef* error, const uint8_t* der, uint8_t* der_end);
93 CFDataRef SOSAccountCopyEncodedData(SOSAccountRef circle, CFAllocatorRef allocator, CFErrorRef *error);
94 //
95 //MARK: IDS Device ID
96 CFStringRef SOSAccountCopyDeviceID(SOSAccountRef account, CFErrorRef *error);
97 bool SOSAccountSetMyDSID(SOSAccountRef account, CFStringRef IDS, CFErrorRef* errror);
98 bool SOSAccountSendIDSTestMessage(SOSAccountRef account, CFStringRef message, CFErrorRef *error);
99 bool SOSAccountStartPingTest(SOSAccountRef account, CFStringRef message, CFErrorRef *error);
100 bool SOSAccountRetrieveDeviceIDFromIDSKeychainSyncingProxy(SOSAccountRef account, CFErrorRef *error);
101
102 //
103 // MARK: Credential management
104 //
105
106 SecKeyRef SOSAccountGetPrivateCredential(SOSAccountRef account, CFErrorRef* error);
107 CFDataRef SOSAccountGetCachedPassword(SOSAccountRef account, CFErrorRef* error);
108
109 void SOSAccountPurgePrivateCredential(SOSAccountRef account);
110
111 bool SOSAccountTryUserCredentials(SOSAccountRef account,
112 CFStringRef user_account, CFDataRef user_password,
113 CFErrorRef *error);
114
115 bool SOSAccountAssertUserCredentials(SOSAccountRef account,
116 CFStringRef user_account, CFDataRef user_password,
117 CFErrorRef *error);
118
119 bool SOSAccountRetryUserCredentials(SOSAccountRef account);
120 void SOSAccountSetUnTrustedUserPublicKey(SOSAccountRef account, SecKeyRef publicKey);
121
122 bool SOSAccountGenerationSignatureUpdate(SOSAccountRef account, CFErrorRef *error);
123
124 //
125 // MARK: Circle management
126 //
127
128 bool SOSAccountUpdateCircle(SOSAccountRef account, SOSCircleRef circle, CFErrorRef *error);
129 void SOSTransportEachMessage(SOSAccountRef account, CFDictionaryRef updates, CFErrorRef *error);
130
131
132 SOSCCStatus SOSAccountGetCircleStatus(SOSAccountRef account, CFErrorRef* error);
133 bool SOSAccountIsInCircle(SOSAccountRef account, CFErrorRef *error);
134 bool SOSAccountJoinCircles(SOSAccountRef account, CFErrorRef* error);
135 bool SOSAccountJoinCirclesAfterRestore(SOSAccountRef account, CFErrorRef* error);
136 bool SOSAccountLeaveCircle(SOSAccountRef account,CFErrorRef* error);
137 bool SOSAccountBail(SOSAccountRef account, uint64_t limit_in_seconds, CFErrorRef* error);
138 bool SOSAccountAcceptApplicants(SOSAccountRef account, CFArrayRef applicants, CFErrorRef* error);
139 bool SOSAccountRejectApplicants(SOSAccountRef account, CFArrayRef applicants, CFErrorRef* error);
140
141 bool SOSAccountResetToOffering(SOSAccountRef account, CFErrorRef* error);
142 bool SOSAccountResetToEmpty(SOSAccountRef account, CFErrorRef* error);
143 bool SOSValidateUserPublic(SOSAccountRef account, CFErrorRef* error);
144
145 void SOSAccountForEachCirclePeerExceptMe(SOSAccountRef account, void (^action)(SOSPeerInfoRef peer));
146
147 CFArrayRef SOSAccountCopyApplicants(SOSAccountRef account, CFErrorRef *error);
148 CFArrayRef SOSAccountCopyGeneration(SOSAccountRef account, CFErrorRef *error);
149 CFArrayRef SOSAccountCopyValidPeers(SOSAccountRef account, CFErrorRef *error);
150 CFArrayRef SOSAccountCopyPeersToListenTo(SOSAccountRef account, CFErrorRef *error);
151 CFArrayRef SOSAccountCopyNotValidPeers(SOSAccountRef account, CFErrorRef *error);
152 CFArrayRef SOSAccountCopyRetired(SOSAccountRef account, CFErrorRef *error);
153 CFArrayRef SOSAccountCopyPeers(SOSAccountRef account, CFErrorRef *error);
154 CFArrayRef SOSAccountCopyActivePeers(SOSAccountRef account, CFErrorRef *error);
155 CFArrayRef SOSAccountCopyActiveValidPeers(SOSAccountRef account, CFErrorRef *error);
156 CFArrayRef SOSAccountCopyConcurringPeers(SOSAccountRef account, CFErrorRef *error);
157
158 SOSFullPeerInfoRef SOSAccountCopyAccountIdentityPeerInfo(SOSAccountRef account, CFAllocatorRef allocator, CFErrorRef* error);
159 bool SOSAccountIsAccountIdentity(SOSAccountRef account, SOSPeerInfoRef peer_info, CFErrorRef *error);
160
161 enum DepartureReason SOSAccountGetLastDepartureReason(SOSAccountRef account, CFErrorRef* error);
162
163 //
164 // MARK: Change blocks
165 //
166 void SOSAccountAddChangeBlock(SOSAccountRef a, SOSAccountCircleMembershipChangeBlock changeBlock);
167 void SOSAccountRemoveChangeBlock(SOSAccountRef a, SOSAccountCircleMembershipChangeBlock changeBlock);
168
169 void SOSAccountAddSyncablePeerBlock(SOSAccountRef a,
170 CFStringRef ds_name,
171 SOSAccountSyncablePeersBlock changeBlock);
172
173 //
174 // MARK: Local device gestalt change.
175 //
176 bool SOSAccountUpdateGestalt(SOSAccountRef account, CFDictionaryRef new_gestalt);
177
178 bool SOSAccountUpdateFullPeerInfo(SOSAccountRef account, CFSetRef minimumViews);
179
180 SOSViewResultCode SOSAccountUpdateView(SOSAccountRef account, CFStringRef viewname, SOSViewActionCode actionCode, CFErrorRef *error);
181
182 SOSViewResultCode SOSAccountViewStatus(SOSAccountRef account, CFStringRef viewname, CFErrorRef *error);
183
184 bool SOSAccountUpdateViewSets(SOSAccountRef account, CFSetRef enabledViews, CFSetRef disabledViews);
185
186 SOSSecurityPropertyResultCode SOSAccountUpdateSecurityProperty(SOSAccountRef account, CFStringRef property, SOSSecurityPropertyActionCode actionCode, CFErrorRef *error);
187
188 SOSSecurityPropertyResultCode SOSAccountSecurityPropertyStatus(SOSAccountRef account, CFStringRef property, CFErrorRef *error);
189
190
191 bool SOSAccountHandleParametersChange(SOSAccountRef account, CFDataRef updates, CFErrorRef *error);
192
193 bool SOSAccountSyncWithAllPeers(SOSAccountRef account, CFErrorRef *error);
194
195 bool SOSAccountCleanupAfterPeer(SOSAccountRef account, size_t seconds, SOSCircleRef circle,
196 SOSPeerInfoRef cleanupPeer, CFErrorRef* error);
197
198 bool SOSAccountCleanupRetirementTickets(SOSAccountRef account, size_t seconds, CFErrorRef* error);
199
200 bool SOSAccountScanForRetired(SOSAccountRef account, SOSCircleRef circle, CFErrorRef *error);
201
202 SOSCircleRef SOSAccountCloneCircleWithRetirement(SOSAccountRef account, SOSCircleRef starting_circle, CFErrorRef *error);
203
204 bool SOSAccountPostDebugScope(SOSAccountRef account, CFTypeRef scope, CFErrorRef *error);
205
206 //
207 // MARK: Version incompatibility Functions
208 //
209 CFStringRef SOSAccountCopyIncompatibilityInfo(SOSAccountRef account, CFErrorRef* error);
210
211 //
212 // MARK: Backup functions
213 //
214
215 bool SOSAccountStartNewBackup(SOSAccountRef account, CFStringRef viewName, CFErrorRef *error);
216
217 bool SOSAccountSetBackupPublicKey(SOSAccountRef account, CFDataRef backupKey, CFErrorRef *error);
218 bool SOSAccountRemoveBackupPublickey(SOSAccountRef account, CFErrorRef *error);
219 bool SOSAccountSetBSKBagForAllSlices(SOSAccountRef account, CFDataRef backupSlice, bool includeV0, CFErrorRef *error);
220
221 //
222 // MARK: Private functions
223 //
224
225 dispatch_queue_t SOSAccountGetQueue(SOSAccountRef account);
226
227 typedef bool (^SOSAccountSendBlock)(CFStringRef key, CFDataRef message, CFErrorRef *error);
228
229 //
230 // MARK: Utility functions
231 //
232
233 CFStringRef SOSAccountCreateCompactDescription(SOSAccountRef a);
234 CFStringRef SOSInterestListCopyDescription(CFArrayRef interests);
235
236 //
237 // MARK: View Funcitons
238 //
239
240 // Use these to tell the engine what views are common to myPeer and other circle peers
241 CFArrayRef SOSCreateActiveViewIntersectionArrayForPeerID(SOSAccountRef account, CFStringRef peerID);
242 CFDictionaryRef SOSViewsCreateActiveViewMatrixDictionary(SOSAccountRef account, SOSCircleRef circle, CFErrorRef *error);
243
244 //
245 // MARK: Transactional functions
246 //
247
248 void SOSAccountFinishTransaction(SOSAccountRef account);
249
250 const uint8_t* der_decode_cloud_parameters(CFAllocatorRef allocator,
251 CFIndex algorithmID, SecKeyRef* publicKey,
252 CFDataRef *parameters,
253 CFErrorRef* error,
254 const uint8_t* der, const uint8_t* der_end);
255
256 /* CFSet <-> XPC functions */
257 CFSetRef CreateCFSetRefFromXPCObject(xpc_object_t xpcSetDER, CFErrorRef* error);
258 xpc_object_t CreateXPCObjectWithCFSetRef(CFSetRef setref, CFErrorRef *error);
259
260
261 __END_DECLS
262
263 #endif /* !_SOSACCOUNT_H_ */