2 * Copyright (c) 2016 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
24 #import <Foundation/Foundation.h>
25 #import "CKKSSQLDatabaseObject.h"
26 #include "keychain/securityd/SecItemServer.h"
27 #include "keychain/securityd/SecItemDb.h"
29 #import "keychain/ckks/CKKS.h"
30 #import "CKKSKeychainView.h"
32 @interface CKKSSQLResult ()
33 @property (nullable) NSString* stringValue;
36 @implementation CKKSSQLResult
37 - (instancetype)init:(NSString* _Nullable)value
39 if((self = [super init])) {
47 return [self.stringValue boolValue];
50 - (NSInteger)asNSInteger
52 return [self.stringValue integerValue];
55 - (NSString* _Nullable)asString
57 return self.stringValue;
60 - (NSNumber* _Nullable)asNSNumberInteger
62 if(self.stringValue == nil) {
65 return [NSNumber numberWithInteger: [self.stringValue integerValue]];
68 - (NSDate* _Nullable)asISO8601Date
70 if(self.stringValue == nil) {
74 NSISO8601DateFormatter* dateFormat = [[NSISO8601DateFormatter alloc] init];
75 return [dateFormat dateFromString:self.stringValue];
78 - (NSData* _Nullable)asBase64DecodedData
80 if(self.stringValue == nil) {
83 return [[NSData alloc] initWithBase64EncodedString:self.stringValue options:0];
87 __thread bool CKKSSQLInTransaction = false;
88 __thread bool CKKSSQLInWriteTransaction = false;
90 @implementation CKKSSQLDatabaseObject
92 + (bool) saveToDatabaseTable: (NSString*) table row: (NSDictionary*) row connection: (SecDbConnectionRef) dbconn error: (NSError * __autoreleasing *) error {
93 __block CFErrorRef cferror = NULL;
96 NSAssert(CKKSSQLInTransaction, @"Must be in a transaction to perform database writes");
97 NSAssert(CKKSSQLInWriteTransaction, @"Must be in a write transaction to perform database writes");
100 bool (^doWithConnection)(SecDbConnectionRef) = ^bool (SecDbConnectionRef dbconn) {
101 NSString * columns = [row.allKeys componentsJoinedByString:@", "];
102 NSMutableString * values = [[NSMutableString alloc] init];
103 for(NSUInteger i = 0; i < [row.allKeys count]; i++) {
105 [values appendString: @",?"];
107 [values appendString: @"?"];
111 NSString *sql = [[NSString alloc] initWithFormat: @"INSERT OR REPLACE into %@ (%@) VALUES (%@);", table, columns, values];
113 SecDbPrepare(dbconn, (__bridge CFStringRef) sql, &cferror, ^void (sqlite3_stmt *stmt) {
114 [row.allKeys enumerateObjectsUsingBlock:^(id _Nonnull key, NSUInteger i, BOOL * _Nonnull stop) {
115 SecDbBindObject(stmt, (int)(i+1), (__bridge CFStringRef) row[key], &cferror);
118 SecDbStep(dbconn, stmt, &cferror, ^(bool *stop) {
119 // don't do anything, I guess?
127 doWithConnection(dbconn);
129 kc_with_dbt(true, &cferror, doWithConnection);
132 bool ret = cferror == NULL;
134 SecTranslateError(error, cferror);
139 + (NSString*) makeWhereClause: (NSDictionary*) whereDict {
143 NSMutableString * whereClause = [[NSMutableString alloc] init];
144 __block bool conjunction = false;
145 [whereDict enumerateKeysAndObjectsUsingBlock: ^(NSString* key, NSNumber* value, BOOL* stop) {
147 [whereClause appendFormat: @" WHERE "];
149 [whereClause appendFormat: @" AND "];
152 if([value class] == [CKKSSQLWhereValue class]) {
153 CKKSSQLWhereValue* obj = (CKKSSQLWhereValue*)value;
154 [whereClause appendFormat: @"%@%@(?)", key, CKKSSQLWhereComparatorAsString(obj.sqlOp)];
156 } else if([value class] == [CKKSSQLWhereColumn class]) {
157 CKKSSQLWhereColumn* obj = (CKKSSQLWhereColumn*)value;
158 [whereClause appendFormat: @"%@%@%@",
160 CKKSSQLWhereComparatorAsString(obj.sqlOp),
161 CKKSSQLWhereColumnNameAsString(obj.columnName)];
163 } else if([value isMemberOfClass:[CKKSSQLWhereIn class]]) {
164 CKKSSQLWhereIn* obj = (CKKSSQLWhereIn*)value;
166 NSMutableArray* q = [NSMutableArray arrayWithCapacity:obj.values.count];
167 for(NSString* value in obj.values) {
172 NSString* binds = [q componentsJoinedByString:@", "];
174 [whereClause appendFormat:@"%@ IN (%@)", key, binds];
177 [whereClause appendFormat: @"%@=(?)", key];
185 + (NSString*) groupByClause: (NSArray*) columns {
189 NSMutableString * groupByClause = [[NSMutableString alloc] init];
190 __block bool conjunction = false;
191 [columns enumerateObjectsUsingBlock: ^(NSString* column, NSUInteger i, BOOL* stop) {
193 [groupByClause appendFormat: @" GROUP BY "];
195 [groupByClause appendFormat: @", "];
198 [groupByClause appendFormat: @"%@", column];
202 return groupByClause;
205 + (NSString*)orderByClause: (NSArray*) columns {
206 if(!columns || columns.count == 0u) {
209 NSMutableString * orderByClause = [[NSMutableString alloc] init];
210 __block bool conjunction = false;
211 [columns enumerateObjectsUsingBlock: ^(NSString* column, NSUInteger i, BOOL* stop) {
213 [orderByClause appendFormat: @" ORDER BY "];
215 [orderByClause appendFormat: @", "];
218 [orderByClause appendFormat: @"%@", column];
222 return orderByClause;
225 + (void)bindWhereClause:(sqlite3_stmt*)stmt whereDict:(NSDictionary*)whereDict cferror:(CFErrorRef*)cferror
227 __block int whereLocation = 1;
229 [whereDict.allKeys enumerateObjectsUsingBlock:^(id _Nonnull key, NSUInteger i, BOOL * _Nonnull stop) {
230 if([whereDict[key] class] == [CKKSSQLWhereValue class]) {
231 CKKSSQLWhereValue* obj = (CKKSSQLWhereValue*)whereDict[key];
232 SecDbBindObject(stmt, whereLocation, (__bridge CFStringRef)obj.value, cferror);
235 } else if([whereDict[key] class] == [CKKSSQLWhereColumn class]) {
237 } else if([whereDict[key] isMemberOfClass:[CKKSSQLWhereIn class]]) {
238 CKKSSQLWhereIn* obj = (CKKSSQLWhereIn*)whereDict[key];
240 for(NSString* value in obj.values) {
241 SecDbBindObject(stmt, whereLocation, (__bridge CFStringRef)value, cferror);
246 SecDbBindObject(stmt, whereLocation, (__bridge CFStringRef) whereDict[key], cferror);
252 + (bool) deleteFromTable: (NSString*) table where: (NSDictionary*) whereDict connection:(SecDbConnectionRef) dbconn error: (NSError * __autoreleasing *) error {
253 __block CFErrorRef cferror = NULL;
256 NSAssert(CKKSSQLInTransaction, @"Must be in a transaction to perform database writes");
257 NSAssert(CKKSSQLInWriteTransaction, @"Must be in a write transaction to perform database writes");
260 bool (^doWithConnection)(SecDbConnectionRef) = ^bool (SecDbConnectionRef dbconn) {
261 NSString* whereClause = [CKKSSQLDatabaseObject makeWhereClause: whereDict];
263 NSString * sql = [[NSString alloc] initWithFormat: @"DELETE FROM %@%@;", table, whereClause];
264 SecDbPrepare(dbconn, (__bridge CFStringRef) sql, &cferror, ^void (sqlite3_stmt *stmt) {
265 [self bindWhereClause:stmt whereDict:whereDict cferror:&cferror];
267 SecDbStep(dbconn, stmt, &cferror, ^(bool *stop) {
274 doWithConnection(dbconn);
276 kc_with_dbt(true, &cferror, doWithConnection);
279 // Deletes finish in a single step, so if we didn't get an error, the delete 'happened'
280 bool status = (cferror == nil);
283 *error = (NSError*) CFBridgingRelease(cferror);
285 CFReleaseNull(cferror);
291 + (bool)queryDatabaseTable:(NSString*)table
292 where:(NSDictionary*)whereDict
293 columns:(NSArray*)names
294 groupBy:(NSArray*)groupColumns
295 orderBy:(NSArray*)orderColumns
297 processRow:(void (^)(NSDictionary<NSString*, CKKSSQLResult*>*)) processRow
298 error:(NSError * __autoreleasing *) error {
299 __block CFErrorRef cferror = NULL;
301 kc_with_dbt(true, &cferror, ^bool (SecDbConnectionRef dbconn) {
302 NSString * columns = [names componentsJoinedByString:@", "];
303 NSString * whereClause = [CKKSSQLDatabaseObject makeWhereClause: whereDict];
304 NSString * groupByClause = [CKKSSQLDatabaseObject groupByClause: groupColumns];
305 NSString * orderByClause = [CKKSSQLDatabaseObject orderByClause: orderColumns];
306 NSString * limitClause = (limit > 0 ? [NSString stringWithFormat:@" LIMIT %lu", limit] : @"");
308 NSString * sql = [[NSString alloc] initWithFormat: @"SELECT %@ FROM %@%@%@%@%@;", columns, table, whereClause, groupByClause, orderByClause, limitClause];
309 SecDbPrepare(dbconn, (__bridge CFStringRef) sql, &cferror, ^void (sqlite3_stmt *stmt) {
310 [self bindWhereClause:stmt whereDict:whereDict cferror:&cferror];
312 SecDbStep(dbconn, stmt, &cferror, ^(bool *stop) {
313 __block NSMutableDictionary<NSString*, CKKSSQLResult*>* row = [[NSMutableDictionary alloc] init];
315 [names enumerateObjectsUsingBlock:^(id _Nonnull name, NSUInteger i, BOOL * _Nonnull stop) {
316 const char * col = (const char *) sqlite3_column_text(stmt, (int)i);
317 row[name] = [[CKKSSQLResult alloc] init:col ? [NSString stringWithUTF8String:col] : nil];
326 bool ret = (cferror == NULL);
327 SecTranslateError(error, cferror);
331 + (NSString *)quotedString:(NSString *)string
333 char *quotedMaxField = sqlite3_mprintf("%q", [string UTF8String]);
334 if (quotedMaxField == NULL) {
337 NSString *rstring = [NSString stringWithUTF8String:quotedMaxField];
338 sqlite3_free(quotedMaxField);
342 + (bool)queryMaxValueForField:(NSString*)maxField
343 inTable:(NSString*)table
344 where:(NSDictionary*)whereDict
345 columns:(NSArray*)names
346 processRow:(void (^)(NSDictionary<NSString*, CKKSSQLResult*>*))processRow
348 __block CFErrorRef cferror = NULL;
350 kc_with_dbt(false, &cferror, ^bool(SecDbConnectionRef dbconn) {
351 NSString *quotedMaxField = [self quotedString:maxField];
352 NSString *quotedTable = [self quotedString:table];
354 NSMutableArray<NSString *>* quotedNames = [NSMutableArray array];
355 for (NSString *element in names) {
356 [quotedNames addObject:[self quotedString:element]];
359 NSString* columns = [[quotedNames componentsJoinedByString:@", "] stringByAppendingFormat:@", %@", quotedMaxField];
360 NSString* whereClause = [CKKSSQLDatabaseObject makeWhereClause:whereDict];
362 NSString* sql = [[NSString alloc] initWithFormat:@"SELECT %@ FROM %@%@", columns, quotedTable, whereClause];
363 SecDbPrepare(dbconn, (__bridge CFStringRef)sql, &cferror, ^(sqlite3_stmt* stmt) {
364 [self bindWhereClause:stmt whereDict:whereDict cferror:&cferror];
366 SecDbStep(dbconn, stmt, &cferror, ^(bool*stop) {
367 __block NSMutableDictionary<NSString*, CKKSSQLResult*>* row = [[NSMutableDictionary alloc] init];
369 [names enumerateObjectsUsingBlock:^(id _Nonnull name, NSUInteger i, BOOL * _Nonnull stop) {
370 const char * col = (const char *) sqlite3_column_text(stmt, (int)i);
371 row[name] = [[CKKSSQLResult alloc] init:col ? [NSString stringWithUTF8String:col] : nil];
381 bool ret = (cferror == NULL);
385 + (BOOL)performCKKSTransaction:(CKKSDatabaseTransactionResult (^)(void))block
387 CFErrorRef cferror = NULL;
388 bool ok = kc_with_dbt(true, &cferror, ^bool (SecDbConnectionRef dbconn) {
389 CFErrorRef cferrorInternal = NULL;
390 bool ret = kc_transaction_type(dbconn, kSecDbExclusiveRemoteCKKSTransactionType, &cferrorInternal, ^bool{
391 CKKSDatabaseTransactionResult result = CKKSDatabaseTransactionRollback;
393 CKKSSQLInTransaction = true;
394 CKKSSQLInWriteTransaction = true;
396 CKKSSQLInWriteTransaction = false;
397 CKKSSQLInTransaction = false;
398 return result == CKKSDatabaseTransactionCommit;
400 if(cferrorInternal) {
401 ckkserror_global("ckkssql", "error performing database transaction, major problems ahead: %@", cferrorInternal);
403 CFReleaseNull(cferrorInternal);
408 ckkserror_global("ckkssql", "error performing database operation, major problems ahead: %@", cferror);
410 CFReleaseNull(cferror);
414 + (BOOL)performCKKSReadonlyTransaction:(void(^)(void))block
416 CFErrorRef cferror = NULL;
417 bool ok = kc_with_dbt(true, &cferror, ^bool (SecDbConnectionRef dbconn) {
418 CFErrorRef cferrorInternal = NULL;
419 bool ret = kc_transaction_type(dbconn, kSecDbNormalTransactionType, &cferrorInternal, ^bool{
420 CKKSSQLInTransaction = true;
422 CKKSSQLInTransaction = false;
425 if(cferrorInternal) {
426 ckkserror_global("ckkssql", "error performing database transaction, major problems ahead: %@", cferrorInternal);
428 CFReleaseNull(cferrorInternal);
433 ckkserror_global("ckkssql", "error performing database operation, major problems ahead: %@", cferror);
435 CFReleaseNull(cferror);
439 #pragma mark - Instance methods
441 - (bool) saveToDatabase: (NSError * __autoreleasing *) error {
442 return [self saveToDatabaseWithConnection:nil error: error];
445 - (bool) saveToDatabaseWithConnection: (SecDbConnectionRef) conn error: (NSError * __autoreleasing *) error {
446 // Todo: turn this into a transaction
448 NSDictionary* currentWhereClause = [self whereClauseToFindSelf];
450 // First, if we were loaded from the database and the where clause has changed, delete the old record.
451 if(self.originalSelfWhereClause && ![self.originalSelfWhereClause isEqualToDictionary: currentWhereClause]) {
452 secdebug("ckkssql", "Primary key changed; removing old row at %@", self.originalSelfWhereClause);
453 if(![CKKSSQLDatabaseObject deleteFromTable:[[self class] sqlTable] where: self.originalSelfWhereClause connection:conn error: error]) {
458 bool ok = [CKKSSQLDatabaseObject saveToDatabaseTable: [[self class] sqlTable]
459 row: [self sqlValues]
464 secdebug("ckkssql", "Saved %@", self);
466 secdebug("ckkssql", "Couldn't save %@: %@", self, error ? *error : @"unknown");
471 - (bool) deleteFromDatabase: (NSError * __autoreleasing *) error {
472 bool ok = [CKKSSQLDatabaseObject deleteFromTable:[[self class] sqlTable] where: [self whereClauseToFindSelf] connection:nil error: error];
475 secdebug("ckkssql", "Deleted %@", self);
477 secdebug("ckkssql", "Couldn't delete %@: %@", self, error ? *error : @"unknown");
482 + (bool) deleteAll: (NSError * __autoreleasing *) error {
483 bool ok = [CKKSSQLDatabaseObject deleteFromTable:[self sqlTable] where: nil connection:nil error: error];
486 secdebug("ckkssql", "Deleted all %@", self);
488 secdebug("ckkssql", "Couldn't delete all %@: %@", self, error ? *error : @"unknown");
493 + (instancetype) fromDatabaseWhere: (NSDictionary*) whereDict error: (NSError * __autoreleasing *) error {
494 id ret = [self tryFromDatabaseWhere: whereDict error:error];
497 *error = [NSError errorWithDomain:@"securityd"
498 code:errSecItemNotFound
499 userInfo:@{NSLocalizedDescriptionKey:
500 [NSString stringWithFormat: @"%@ does not exist in database where %@", [self class], whereDict]}];
506 + (instancetype _Nullable) tryFromDatabaseWhere: (NSDictionary*) whereDict error: (NSError * __autoreleasing *) error {
507 __block id ret = nil;
509 [CKKSSQLDatabaseObject queryDatabaseTable: [self sqlTable]
511 columns: [self sqlColumns]
515 processRow: ^(NSDictionary<NSString*, CKKSSQLResult*>* row) {
516 ret = [[self fromDatabaseRow: row] memoizeOriginalSelfWhereClause];
523 + (NSArray*) all: (NSError * __autoreleasing *) error {
524 return [self allWhere: nil error:error];
527 + (NSArray*) allWhere: (NSDictionary*) whereDict error: (NSError * __autoreleasing *) error {
528 __block NSMutableArray* items = [[NSMutableArray alloc] init];
530 [CKKSSQLDatabaseObject queryDatabaseTable: [self sqlTable]
532 columns: [self sqlColumns]
536 processRow: ^(NSDictionary<NSString*, CKKSSQLResult*>* row) {
537 [items addObject: [[self fromDatabaseRow: row] memoizeOriginalSelfWhereClause]];
544 + (NSArray*)fetch: (size_t)count error: (NSError * __autoreleasing *) error {
545 return [self fetch: count where:nil orderBy:nil error:error];
548 + (NSArray*)fetch: (size_t)count where:(NSDictionary*)whereDict error: (NSError * __autoreleasing *) error {
549 return [self fetch: count where:whereDict orderBy:nil error:error];
552 + (NSArray*)fetch:(size_t)count
553 where:(NSDictionary*)whereDict
554 orderBy:(NSArray*) orderColumns
555 error:(NSError * __autoreleasing *) error {
556 __block NSMutableArray* items = [[NSMutableArray alloc] init];
558 [CKKSSQLDatabaseObject queryDatabaseTable: [self sqlTable]
560 columns: [self sqlColumns]
563 limit: (ssize_t) count
564 processRow: ^(NSDictionary<NSString*, CKKSSQLResult*>* row) {
565 [items addObject: [[self fromDatabaseRow: row] memoizeOriginalSelfWhereClause]];
572 - (instancetype) memoizeOriginalSelfWhereClause {
573 _originalSelfWhereClause = [self whereClauseToFindSelf];
577 #pragma mark - Subclass methods
579 + (instancetype)fromDatabaseRow:(NSDictionary<NSString *, CKKSSQLResult*>*)row {
580 @throw [NSException exceptionWithName:NSInternalInconsistencyException
581 reason:[NSString stringWithFormat:@"A subclass must override %@", NSStringFromSelector(_cmd)]
585 + (NSString*) sqlTable {
586 @throw [NSException exceptionWithName:NSInternalInconsistencyException
587 reason:[NSString stringWithFormat:@"A subclass must override %@", NSStringFromSelector(_cmd)]
591 + (NSArray<NSString*>*) sqlColumns {
592 @throw [NSException exceptionWithName:NSInternalInconsistencyException
593 reason:[NSString stringWithFormat:@"A subclass must override %@", NSStringFromSelector(_cmd)]
597 - (NSDictionary<NSString*,NSString*>*) sqlValues {
598 @throw [NSException exceptionWithName:NSInternalInconsistencyException
599 reason:[NSString stringWithFormat:@"A subclass must override %@", NSStringFromSelector(_cmd)]
603 - (NSDictionary<NSString*,NSString*>*) whereClauseToFindSelf {
604 @throw [NSException exceptionWithName:NSInternalInconsistencyException
605 reason:[NSString stringWithFormat:@"A subclass must override %@", NSStringFromSelector(_cmd)]
609 - (instancetype)copyWithZone:(NSZone *)zone {
610 CKKSSQLDatabaseObject *dbCopy = [[[self class] allocWithZone:zone] init];
611 dbCopy->_originalSelfWhereClause = _originalSelfWhereClause;
616 NSString* CKKSSQLWhereComparatorAsString(CKKSSQLWhereComparator comparator)
619 case CKKSSQLWhereComparatorEquals:
621 case CKKSSQLWhereComparatorNotEquals:
623 case CKKSSQLWhereComparatorGreaterThan:
625 case CKKSSQLWhereComparatorLessThan:
630 NSString* CKKSSQLWhereColumnNameAsString(CKKSSQLWhereColumnName columnName)
633 case CKKSSQLWhereColumnNameUUID:
635 case CKKSSQLWhereColumnNameParentKeyUUID:
636 return @"parentKeyUUID";
640 #pragma mark - CKKSSQLWhereColumn
642 @implementation CKKSSQLWhereColumn
643 - (instancetype)initWithOperation:(CKKSSQLWhereComparator)op columnName:(CKKSSQLWhereColumnName)column
645 if((self = [super init])) {
647 _columnName = column;
651 + (instancetype)op:(CKKSSQLWhereComparator)op column:(CKKSSQLWhereColumnName)columnName
653 return [[CKKSSQLWhereColumn alloc] initWithOperation:op columnName:columnName];
657 #pragma mark - CKKSSQLWhereObject
659 @implementation CKKSSQLWhereValue
660 - (instancetype)initWithOperation:(CKKSSQLWhereComparator)op value:(NSString*)value
662 if((self = [super init])) {
668 + (instancetype)op:(CKKSSQLWhereComparator)op value:(NSString*)value
670 return [[CKKSSQLWhereValue alloc] initWithOperation:op value:value];
675 #pragma mark - CKKSSQLWhereIn
677 @implementation CKKSSQLWhereIn : NSObject
678 - (instancetype)initWithValues:(NSArray<NSString*>*)values
680 if((self = [super init])) {