]>
git.saurik.com Git - apple/security.git/blob - OSX/libsecurity_codesigning/lib/singlediskrep.cpp
   2  * Copyright (c) 2006-2011,2014 Apple Inc. All Rights Reserved. 
   4  * @APPLE_LICENSE_HEADER_START@ 
   6  * This file contains Original Code and/or Modifications of Original Code 
   7  * as defined in and that are subject to the Apple Public Source License 
   8  * Version 2.0 (the 'License'). You may not use this file except in 
   9  * compliance with the License. Please obtain a copy of the License at 
  10  * http://www.opensource.apple.com/apsl/ and read it before using this 
  13  * The Original Code and all software distributed under the License are 
  14  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 
  15  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 
  16  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 
  17  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 
  18  * Please see the License for the specific language governing rights and 
  19  * limitations under the License. 
  21  * @APPLE_LICENSE_HEADER_END@ 
  25 // singlediskrep - semi-abstract diskrep for a single file of some kind 
  27 #include "singlediskrep.h" 
  28 #include "csutilities.h" 
  29 #include <security_utilities/cfutilities.h> 
  33 namespace CodeSigning 
{ 
  35 using namespace UnixPlusPlus
; 
  39 // Construct a SingleDiskRep 
  41 SingleDiskRep::SingleDiskRep(const std::string 
&path
) 
  48 // The default binary identification of a SingleDiskRep is the (SHA-1) hash 
  49 // of the entire file itself. 
  51 CFDataRef 
SingleDiskRep::identification() 
  55         hashFileData(this->fd(), &hash
); 
  58         return makeCFData(digest
, sizeof(digest
)); 
  63 // Both the canonical and main executable path of a SingleDiskRep is, well, its path. 
  65 CFURLRef 
SingleDiskRep::copyCanonicalPath() 
  67         return makeCFURL(mPath
); 
  70 string 
SingleDiskRep::mainExecutablePath() 
  77 // The default signing limit is the size of the file. 
  78 // This will do unless the signing data gets creatively stuck in there somewhere. 
  80 size_t SingleDiskRep::signingLimit() 
  82         return fd().fileSize(); 
  86 // A lazily opened read-only file descriptor for the path. 
  88 FileDesc 
&SingleDiskRep::fd() 
  91                 mFd
.open(mPath
, O_RDONLY
); 
  99 void SingleDiskRep::flush() 
 106 // The recommended identifier of a SingleDiskRep is, absent any better clue, 
 107 // the basename of its path. 
 109 string 
SingleDiskRep::recommendedIdentifier(const SigningContext 
&) 
 111         return canonicalIdentifier(mPath
); 
 116 // Paranoid validation 
 118 void SingleDiskRep::strictValidate(const CodeDirectory
* cd
, const ToleratedErrors
& tolerated
, SecCSFlags flags
) 
 120         DiskRep::strictValidate(cd
, tolerated
, flags
); 
 122         // code limit must cover (exactly) the entire file 
 123         if (cd 
&& cd
->signingLimit() != signingLimit()) 
 124                 MacOSError::throwMe(errSecCSSignatureInvalid
); 
 132 FileDesc 
&SingleDiskRep::Writer::fd() 
 135                 mFd
.open(rep
->path(), O_RDWR
); 
 140 } // end namespace CodeSigning 
 141 } // end namespace Security