2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
25 #ifndef _SECURITY_SOSCLOUDCIRCLESERVER_H_
26 #define _SECURITY_SOSCLOUDCIRCLESERVER_H_
28 #include <Security/SecureObjectSync/SOSCloudCircle.h>
29 #include <Security/SecureObjectSync/SOSAccount.h>
35 // MARK: Server versions of our SPI
37 bool SOSCCTryUserCredentials_Server(CFStringRef user_label
, CFDataRef user_password
, CFErrorRef
*error
);
38 bool SOSCCSetUserCredentials_Server(CFStringRef user_label
, CFDataRef user_password
, CFErrorRef
*error
);
39 bool SOSCCSetUserCredentialsAndDSID_Server(CFStringRef user_label
, CFDataRef user_password
, CFStringRef dsid
, CFErrorRef
*error
);
41 bool SOSCCCanAuthenticate_Server(CFErrorRef
*error
);
42 bool SOSCCPurgeUserCredentials_Server(CFErrorRef
*error
);
44 SOSCCStatus
SOSCCThisDeviceIsInCircle_Server(CFErrorRef
*error
);
45 bool SOSCCRequestToJoinCircle_Server(CFErrorRef
* error
);
46 bool SOSCCRequestToJoinCircleAfterRestore_Server(CFErrorRef
* error
);
47 CFStringRef
SOSCCCopyDeviceID_Server(CFErrorRef
*error
);
48 bool SOSCCSetDeviceID_Server(CFStringRef IDS
, CFErrorRef
*error
);
49 HandleIDSMessageReason
SOSCCHandleIDSMessage_Server(CFDictionaryRef messageDict
, CFErrorRef
* error
);
50 bool SOSCCRequestSyncWithPeerOverKVS_Server(CFStringRef peerID
, CFErrorRef
*error
);
51 bool SOSCCRequestSyncWithPeerOverIDS_Server(CFStringRef deviceID
, CFErrorRef
*error
);
53 bool SOSCCIDSServiceRegistrationTest_Server(CFStringRef message
, CFErrorRef
*error
);
54 bool SOSCCIDSPingTest_Server(CFStringRef message
, CFErrorRef
*error
);
55 bool SOSCCIDSDeviceIDIsAvailableTest_Server(CFErrorRef
*error
);
57 bool SOSCCRemoveThisDeviceFromCircle_Server(CFErrorRef
* error
);
58 bool SOSCCRemovePeersFromCircle_Server(CFArrayRef peers
, CFErrorRef
* error
);
59 bool SOSCCLoggedOutOfAccount_Server(CFErrorRef
*error
);
60 bool SOSCCBailFromCircle_Server(uint64_t limit_in_seconds
, CFErrorRef
* error
);
61 bool SOSCCRequestEnsureFreshParameters_Server(CFErrorRef
* error
);
64 bool SOSCCApplyToARing_Server(CFStringRef ringName
, CFErrorRef
*error
);
65 bool SOSCCWithdrawlFromARing_Server(CFStringRef ringName
, CFErrorRef
*error
);
66 SOSRingStatus
SOSCCRingStatus_Server(CFStringRef ringName
, CFErrorRef
*error
);
67 CFStringRef
SOSCCGetAllTheRings_Server(CFErrorRef
*error
);
68 bool SOSCCEnableRing_Server(CFStringRef ringName
, CFErrorRef
*error
);
71 CFArrayRef
SOSCCCopyGenerationPeerInfo_Server(CFErrorRef
* error
);
72 CFArrayRef
SOSCCCopyApplicantPeerInfo_Server(CFErrorRef
* error
);
73 CFArrayRef
SOSCCCopyValidPeerPeerInfo_Server(CFErrorRef
* error
);
74 bool SOSCCValidateUserPublic_Server(CFErrorRef
* error
);
76 CFArrayRef
SOSCCCopyNotValidPeerPeerInfo_Server(CFErrorRef
* error
);
77 CFArrayRef
SOSCCCopyRetirementPeerInfo_Server(CFErrorRef
* error
);
78 CFArrayRef
SOSCCCopyViewUnawarePeerInfo_Server(CFErrorRef
* error
);
79 bool SOSCCRejectApplicants_Server(CFArrayRef applicants
, CFErrorRef
* error
);
80 bool SOSCCAcceptApplicants_Server(CFArrayRef applicants
, CFErrorRef
* error
);
82 SOSPeerInfoRef
SOSCCCopyMyPeerInfo_Server(CFErrorRef
* error
);
83 CFArrayRef
SOSCCCopyEngineState_Server(CFErrorRef
* error
);
85 CFArrayRef
SOSCCCopyPeerPeerInfo_Server(CFErrorRef
* error
);
86 CFArrayRef
SOSCCCopyConcurringPeerPeerInfo_Server(CFErrorRef
* error
);
87 bool SOSCCCheckPeerAvailability_Server(CFErrorRef
*error
);
88 bool SOSCCkSecXPCOpIsThisDeviceLastBackup_Server(CFErrorRef
*error
);
89 bool SOSCCkSecXPCOpIsThisDeviceLastBackup_Server(CFErrorRef
*error
);
90 bool SOSCCAccountSetToNew_Server(CFErrorRef
*error
);
91 bool SOSCCResetToOffering_Server(CFErrorRef
* error
);
92 bool SOSCCResetToEmpty_Server(CFErrorRef
* error
);
94 CFBooleanRef
SOSCCPeersHaveViewsEnabled_Server(CFArrayRef viewNames
, CFErrorRef
*error
);
96 SOSViewResultCode
SOSCCView_Server(CFStringRef view
, SOSViewActionCode action
, CFErrorRef
*error
);
97 bool SOSCCViewSet_Server(CFSetRef enabledView
, CFSetRef disabledViews
);
99 SOSSecurityPropertyResultCode
SOSCCSecurityProperty_Server(CFStringRef property
, SOSSecurityPropertyActionCode action
, CFErrorRef
*error
);
101 CFStringRef
SOSCCCopyIncompatibilityInfo_Server(CFErrorRef
* error
);
102 enum DepartureReason
SOSCCGetLastDepartureReason_Server(CFErrorRef
* error
);
103 bool SOSCCSetLastDepartureReason_Server(enum DepartureReason reason
, CFErrorRef
*error
);
104 bool SOSCCSetHSA2AutoAcceptInfo_Server(CFDataRef pubKey
, CFErrorRef
*error
);
106 bool SOSCCProcessEnsurePeerRegistration_Server(CFErrorRef
* error
);
107 SyncWithAllPeersReason
SOSCCProcessSyncWithAllPeers_Server(CFErrorRef
* error
);
109 SOSPeerInfoRef
SOSCCSetNewPublicBackupKey_Server(CFDataRef newPublicBackup
, CFErrorRef
*error
);
110 bool SOSCCRegisterSingleRecoverySecret_Server(CFDataRef backupSlice
, bool setupV0Only
, CFErrorRef
*error
);
112 bool SOSCCWaitForInitialSync_Server(CFErrorRef
*);
113 CFArrayRef
SOSCCCopyYetToSyncViewsList_Server(CFErrorRef
*);
115 bool SOSWrapToBackupSliceKeyBagForView_Server(CFStringRef viewName
, CFDataRef input
, CFDataRef
* output
, CFDataRef
* bskbEncoded
, CFErrorRef
* error
);
117 SOSBackupSliceKeyBagRef
SOSBackupSliceKeyBagForView(CFStringRef viewName
, CFErrorRef
* error
);
118 CF_RETURNS_RETAINED CFDataRef
SOSWrapToBackupSliceKeyBag(SOSBackupSliceKeyBagRef bskb
, CFDataRef input
, CFErrorRef
* error
);
121 // MARK: Internal kicks.
123 CF_RETURNS_RETAINED CFArrayRef
SOSCCHandleUpdateMessage(CFDictionaryRef updates
);
124 void sync_the_last_data_to_kvs(SOSAccountRef account
, bool waitForeverForSynchronization
);
127 // Expected to be called when the data source changes.
128 void SOSCCSyncWithAllPeers(void);
129 void SOSCCEnsurePeerRegistration(void);
130 void SOSCCAddSyncablePeerBlock(CFStringRef ds_name
, SOSAccountSyncablePeersBlock changeBlock
);
131 dispatch_queue_t
SOSCCGetAccountQueue(void);
134 // MARK: Internal access to local account for tests.
136 typedef SOSDataSourceFactoryRef (^SOSCCAccountDataSourceFactoryBlock
)();
138 SOSAccountRef
SOSKeychainAccountGetSharedAccount(void);
139 bool SOSKeychainAccountSetFactoryForAccount(SOSCCAccountDataSourceFactoryBlock factory
);
142 // MARK: Internal SPIs for testing
144 CFStringRef
CopyOSVersion(void);
145 CFDataRef
SOSCCCopyAccountState_Server(CFErrorRef
* error
);
146 CFDataRef
SOSCCCopyEngineData_Server(CFErrorRef
* error
);
147 bool SOSCCDeleteEngineState_Server(CFErrorRef
* error
);
148 bool SOSCCDeleteAccountState_Server(CFErrorRef
* error
);
152 // MARK: Testing operations, dangerous to call in normal operation.
154 bool SOSKeychainSaveAccountDataAndPurge(CFErrorRef
*error
);
157 // MARK: Constants for where we store persistent information in the keychain
160 extern CFStringRef kSOSInternalAccessGroup
;
162 extern CFStringRef kSOSAccountLabel
;
163 extern CFStringRef kSOSPeerDataLabel
;
165 CFDataRef
SOSItemCopy(CFStringRef label
, CFErrorRef
* error
);
166 bool SOSItemUpdateOrAdd(CFStringRef label
, CFStringRef accessibility
, CFDataRef data
, CFErrorRef
*error
);
168 bool SOSCCSetEscrowRecord_Server(CFStringRef escrow_label
, uint64_t tries
, CFErrorRef
*error
);
169 CFDictionaryRef
SOSCCCopyEscrowRecord_Server(CFErrorRef
*error
);
171 SOSPeerInfoRef
SOSCCCopyApplication_Server(CFErrorRef
*error
);
172 CFDataRef
SOSCCCopyCircleJoiningBlob_Server(SOSPeerInfoRef applicant
, CFErrorRef
*error
);
173 bool SOSCCJoinWithCircleJoiningBlob_Server(CFDataRef joiningBlob
, CFErrorRef
*error
);
175 bool SOSCCAccountHasPublicKey_Server(CFErrorRef
*error
);
176 bool SOSCCAccountIsNew_Server(CFErrorRef
*error
);