]> git.saurik.com Git - apple/security.git/blob - OSX/libsecurity_codesigning/lib/sigblob.h
Security-58286.251.4.tar.gz
[apple/security.git] / OSX / libsecurity_codesigning / lib / sigblob.h
1 /*
2 * Copyright (c) 2006,2011-2012,2014 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24 //
25 // sigblob - signature (Super)Blob types
26 //
27 #ifndef _H_SIGBLOB
28 #define _H_SIGBLOB
29
30 #include "codedirectory.h"
31 #include <security_utilities/superblob.h>
32 #include <CoreFoundation/CFData.h>
33
34 namespace Security {
35 namespace CodeSigning {
36
37
38 //
39 // An EmbeddedSignatureBlob is a SuperBlob indexed by component slot number.
40 // This is what we embed in Mach-O images. It is also what we use for detached
41 // signatures for non-Mach-O binaries.
42 //
43 class EmbeddedSignatureBlob : public SuperBlobCore<EmbeddedSignatureBlob, 0xfade0cc0, uint32_t> {
44 typedef SuperBlobCore<EmbeddedSignatureBlob, 0xfade0cc0, uint32_t> _Core;
45 public:
46 static CFDataRef blobData(CodeDirectory::SpecialSlot slot, BlobCore const *blob);
47 CFDataRef component(CodeDirectory::SpecialSlot slot) const;
48
49 class Maker : public _Core::Maker {
50 public:
51 void component(CodeDirectory::SpecialSlot type, CFDataRef data);
52 };
53 };
54
55
56 //
57 // A DetachedSignatureBlob collects multiple architectures' worth of
58 // EmbeddedSignatureBlobs into one, well, Super-SuperBlob.
59 // This is what we use for Mach-O detached signatures.
60 //
61 typedef SuperBlob<0xfade0cc1> DetachedSignatureBlob; // indexed by main architecture
62
63
64 //
65 // The linkers produces a superblob of dependency records from its dylib inputs
66 //
67 typedef SuperBlob<0xfade0c05> LibraryDependencyBlob; // indexed sequentially from 0
68
69
70 //
71 // An entitlement blob is used for embedding entitlement configuration data
72 //
73 class EntitlementBlob : public Blob<EntitlementBlob, 0xfade7171> {
74 public:
75 CFDictionaryRef entitlements() const;
76 };
77
78 //
79 // Similar, but in DER representation.
80 //
81 class EntitlementDERBlob : public Blob<EntitlementDERBlob, kSecCodeMagicEntitlementDER> {
82 public:
83 static EntitlementDERBlob *alloc(size_t length);
84
85 uint8_t *der() { return data; }
86 const uint8_t *der() const { return data; }
87 size_t derLength() const { return BlobCore::length() - sizeof(BlobCore); }
88
89 private:
90 uint8_t data[0];
91 };
92
93
94 } // end namespace CodeSigning
95 } // end namespace Security
96
97 #endif // !_H_SIGBLOB