]> git.saurik.com Git - apple/security.git/blob - keychain/SecureObjectSync/SOSInternal.h
Security-59306.11.20.tar.gz
[apple/security.git] / keychain / SecureObjectSync / SOSInternal.h
1 /*
2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24
25 #ifndef _SOSINTERNAL_H_
26 #define _SOSINTERNAL_H_
27
28 #include <CoreFoundation/CoreFoundation.h>
29
30 #include <Security/SecKey.h>
31
32 #include <Security/SecItemShim.h>
33
34 #include <Security/SecureObjectSync/SOSCloudCircle.h>
35
36 #include <utilities/SecCFWrappers.h>
37
38 #include <corecrypto/ccec.h>
39
40 __BEGIN_DECLS
41
42 #define ENABLE_IDS 0
43
44 #define kSOSPeerIDLengthMax (26)
45 #define CC_STATISVALID 0x8000000000000000
46 #define CC_UKEY_TRUSTED 0x4000000000000000
47 #define CC_CAN_AUTH 0x2000000000000000
48 #define CC_PEER_IS_IN 0x1000000000000000
49 #define CC_MASK 0x0fffffffffffffff
50
51 enum {
52 // Public errors are first (See SOSCloudCircle)
53
54 kSOSErrorFirstPrivateError = 1024,
55
56 kSOSErrorAllocationFailure = 1024,
57 kSOSErrorEncodeFailure = 1025,
58 kSOSErrorNameMismatch = 1026,
59 kSOSErrorSendFailure = 1027,
60 kSOSErrorProcessingFailure = 1028,
61 kSOSErrorDecodeFailure = 1029,
62
63 kSOSErrorAlreadyPeer = 1030,
64 kSOSErrorNotApplicant = 1031,
65 kSOSErrorPeerNotFound = 1032,
66
67 kSOSErrorNoKey = 1033,
68 kSOSErrorBadKey = 1034,
69 kSOSErrorBadFormat = 1035,
70 kSOSErrorNoCircleName = 1036,
71 kSOSErrorNoCircle = 1037,
72 kSOSErrorBadSignature = 1038,
73 kSOSErrorReplay = 1039,
74
75 kSOSErrorUnexpectedType = 1040,
76
77 kSOSErrorUnsupported = 1041,
78 kSOSErrorInvalidMessage = 1042,
79 kSOSErrorNoRing = 1043,
80
81 kSOSErrorNoiCloudPeer = 1044,
82 kSOSErrorParam = 1045,
83 kSOSErrorNotInCircle = 1046,
84 kSOSErrorKeysNeedAttention = 1047,
85 };
86
87 extern const CFStringRef SOSTransportMessageTypeIDSV2;
88 extern const CFStringRef SOSTransportMessageTypeKVS;
89 extern const CFStringRef kSOSDSIDKey;
90 extern const SOSCCStatus kSOSNoCachedValue;
91
92 // Returns false unless errorCode is 0.
93 bool SOSErrorCreate(CFIndex errorCode, CFErrorRef *error, CFDictionaryRef formatOptions, CFStringRef descriptionString, ...);
94
95 bool SOSCreateError(CFIndex errorCode, CFStringRef descriptionString, CFErrorRef previousError, CFErrorRef *newError);
96
97 bool SOSCreateErrorWithFormat(CFIndex errorCode, CFErrorRef previousError, CFErrorRef *newError,
98 CFDictionaryRef formatOptions, CFStringRef formatString, ...)
99 CF_FORMAT_FUNCTION(5,6);
100
101 bool SOSCreateErrorWithFormatAndArguments(CFIndex errorCode, CFErrorRef previousError, CFErrorRef *newError,
102 CFDictionaryRef formatOptions, CFStringRef formatString, va_list args)
103 CF_FORMAT_FUNCTION(5,0);
104
105
106 static inline bool SOSClearErrorIfTrue(bool condition, CFErrorRef *error) {
107 if(condition && error && *error) {
108 secdebug("errorBug", "Got Success and Error (dropping error): %@", *error);
109 CFReleaseNull(*error);
110 }
111 return true;
112 }
113
114 static inline bool isSOSErrorCoded(CFErrorRef error, CFIndex sosErrorCode) {
115 return error && CFErrorGetCode(error) == sosErrorCode && CFEqualSafe(CFErrorGetDomain(error), kSOSErrorDomain);
116 }
117
118 //
119 // Backup Key handling
120 //
121 ccec_const_cp_t SOSGetBackupKeyCurveParameters(void);
122 bool SOSGenerateDeviceBackupFullKey(ccec_full_ctx_t generatedKey, ccec_const_cp_t cp, CFDataRef entropy, CFErrorRef* error);
123
124 bool SOSPerformWithDeviceBackupFullKey(ccec_const_cp_t cp, CFDataRef entropy, CFErrorRef *error, void (^operation)(ccec_full_ctx_t fullKey));
125
126 //
127 // Wrapping and Unwrapping
128 //
129
130 CFMutableDataRef SOSCopyECWrappedData(ccec_pub_ctx_t ec_ctx, CFDataRef data, CFErrorRef *error);
131 bool SOSPerformWithUnwrappedData(ccec_full_ctx_t ec_ctx, CFDataRef data, CFErrorRef *error,
132 void (^operation)(size_t size, uint8_t *buffer));
133 CFMutableDataRef SOSCopyECUnwrappedData(ccec_full_ctx_t ec_ctx, CFDataRef data, CFErrorRef *error);
134 //
135 // Utility Functions
136 //
137 OSStatus GenerateECPair(int keySize, SecKeyRef* public, SecKeyRef *full);
138 OSStatus GeneratePermanentECPair(int keySize, SecKeyRef* public, SecKeyRef *full);
139
140 CFStringRef SOSItemsChangedCopyDescription(CFDictionaryRef changes, bool is_sender);
141
142 CFStringRef SOSCopyHashBufAsString(uint8_t *digest, size_t len);
143 CFStringRef SOSCopyIDOfDataBuffer(CFDataRef data, CFErrorRef *error);
144 CFStringRef SOSCopyIDOfDataBufferWithLength(CFDataRef data, CFIndex len, CFErrorRef *error);
145
146 CFStringRef SOSCopyIDOfKey(SecKeyRef key, CFErrorRef *error);
147 CFStringRef SOSCopyIDOfKeyWithLength(SecKeyRef key, CFIndex len, CFErrorRef *error);
148
149 //
150 // Der encoding accumulation
151 //
152 OS_WARN_RESULT
153 static inline bool accumulate_size(size_t *accumulator, size_t size) {
154 *accumulator += size;
155 return size != 0;
156 }
157
158 // Used for simple timestamping that's DERable (not durable)
159 CFDataRef SOSDateCreate(void);
160
161 CFDataRef CFDataCreateWithDER(CFAllocatorRef allocator, CFIndex size, uint8_t*(^operation)(size_t size, uint8_t *buffer));
162
163
164 // Expanded notification utilities
165 #if __OBJC__
166 @interface SOSCachedNotification : NSObject
167 - (instancetype)init NS_UNAVAILABLE;
168 + (NSString *)notificationName:(const char *)notificationString;
169 @end
170 #endif
171
172 bool SOSCachedNotificationOperation(const char *notificationString, bool (^operation) (int token, bool gtg));
173 uint64_t SOSGetCachedCircleBitmask(void);
174 SOSCCStatus SOSGetCachedCircleStatus(CFErrorRef *error);
175 uint64_t SOSCachedViewBitmask(void);
176 CFSetRef SOSCreateCachedViewStatus(void);
177
178 #if __OBJC__
179 NSDate *SOSCreateRandomDateBetweenNowPlus(NSTimeInterval starting, NSTimeInterval ending);
180 #endif
181
182
183
184 __END_DECLS
185
186 #endif