2 * Copyright (c) 2006-2014 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
25 * SecItemSchema.c - CoreFoundation-based constants and functions for
26 access to Security items (certificates, keys, identities, and
30 #include "SecItemSchema.h"
31 #include "keychain/securityd/SecDbKeychainItem.h"
32 #include <keychain/ckks/CKKS.h>
33 #include "CheckV12DevEnabled.h"
36 // MARK Keychain version 6 schema
38 #define __FLAGS(ARG, ...) SECDBFLAGS(__VA_ARGS__)
39 #define SECDBFLAGS(ARG, ...) __FLAGS_##ARG | __FLAGS(__VA_ARGS__)
41 #define SecDbFlags(P,L,I,S,A,D,R,C,H,B,Z,E,N,U,V,Y) (__FLAGS_##P|__FLAGS_##L|__FLAGS_##I|__FLAGS_##S|__FLAGS_##A|__FLAGS_##D|__FLAGS_##R|__FLAGS_##C|__FLAGS_##H|__FLAGS_##B|__FLAGS_##Z|__FLAGS_##E|__FLAGS_##N|__FLAGS_##U|__FLAGS_##V|__FLAGS_##Y)
44 #define __FLAGS_P kSecDbPrimaryKeyFlag
45 #define __FLAGS_L kSecDbInFlag
46 #define __FLAGS_I kSecDbIndexFlag
47 #define __FLAGS_S kSecDbSHA1ValueInFlag
48 #define __FLAGS_A kSecDbReturnAttrFlag
49 #define __FLAGS_D kSecDbReturnDataFlag
50 #define __FLAGS_R kSecDbReturnRefFlag
51 #define __FLAGS_C kSecDbInCryptoDataFlag
52 #define __FLAGS_H kSecDbInHashFlag
53 #define __FLAGS_B kSecDbInBackupFlag
54 #define __FLAGS_Z kSecDbDefault0Flag
55 #define __FLAGS_E kSecDbDefaultEmptyFlag
56 #define __FLAGS_N kSecDbNotNullFlag
57 #define __FLAGS_U kSecDbInAuthenticatedDataFlag
58 #define __FLAGS_V0 kSecDbSyncPrimaryKeyV0
59 #define __FLAGS_V2 (kSecDbSyncPrimaryKeyV0 | kSecDbSyncPrimaryKeyV2)
60 #define __FLAGS_Y kSecDbSyncFlag
62 // ,----------------- P : Part of primary key
63 // / ,---------------- L : Stored in local database
64 // / / ,--------------- I : Attribute wants an index in the database
65 // / / / ,-------------- S : SHA1 hashed attribute value in database (implies L)
66 // / / / / ,------------- A : Returned to client as attribute in queries
67 // / / / / / ,------------ D : Returned to client as data in queries
68 // / / / / / / ,----------- R : Returned to client as ref/persistent ref in queries
69 // / / / / / / / ,---------- C : Part of encrypted blob
70 // / / / / / / / / ,--------- H : Attribute is part of item SHA1 hash (Implied by C)
71 // / / / / / / / / / ,-------- B : Attribute is part of iTunes/iCloud backup bag
72 // / / / / / / / / / / ,------- Z : Attribute has a default value of 0
73 // / / / / / / / / / / / ,------ E : Attribute has a default value of "" or empty data
74 // / / / / / / / / / / / / ,----- N : Attribute must have a value
75 // / / / / / / / / / / / / / ,---- U : Attribute is stored in authenticated, but not necessarily encrypted data
76 // / / / / / / / / / / / / / / ,--- V0: Sync primary key version
77 // / / / / / / / / / / / / / / / ,- Y : Attribute should be synced
78 // | | | | | | | | | | | | | | | |
79 // common to all | | | | | | | | | | | | | | | |
80 SECDB_ATTR(v6rowid
, "rowid", RowId
, SecDbFlags( ,L
, , , , ,R
, , ,B
, , , , , , ), NULL
, NULL
);
81 SECDB_ATTR(v6cdat
, "cdat", CreationDate
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), SecDbKeychainItemCopyCurrentDate
, NULL
);
82 SECDB_ATTR(v6mdat
, "mdat",ModificationDate
,SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), SecDbKeychainItemCopyCurrentDate
, NULL
);
83 SECDB_ATTR(v6labl
, "labl", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
84 SECDB_ATTR(v6data
, "data", EncryptedData
, SecDbFlags( ,L
, , , , , , , ,B
, , , , , , ), SecDbKeychainItemCopyEncryptedData
, NULL
);
85 SECDB_ATTR(v6agrp
, "agrp", String
, SecDbFlags(P
,L
,I
, ,A
, , , ,H
, , , ,N
,U
,V0
,Y
), NULL
, NULL
);
86 SECDB_ATTR(v6pdmn
, "pdmn", Access
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
87 SECDB_ATTR(v6sync
, "sync", Sync
, SecDbFlags(P
,L
,I
, ,A
, , , ,H
, ,Z
, ,N
,U
,V0
, ), NULL
, NULL
);
88 SECDB_ATTR(v6tomb
, "tomb", Tomb
, SecDbFlags( ,L
, , , , , , ,H
, ,Z
, ,N
,U
, ,Y
), NULL
, NULL
);
89 SECDB_ATTR(v6sha1
, "sha1", SHA1
, SecDbFlags( ,L
,I
, ,A
, ,R
, , , , , , , , ,Y
), SecDbKeychainItemCopySHA1
, NULL
);
90 SECDB_ATTR(v6accc
, "accc", AccessControl
, SecDbFlags( , , , ,A
, , , , , , , , , , , ), NULL
, NULL
);
91 SECDB_ATTR(v6v_Data
, "v_Data", Data
, SecDbFlags( , , , , ,D
, ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
92 SECDB_ATTR(v6v_pk
, "v_pk", PrimaryKey
, SecDbFlags( , , , , , , , , , , , , , , , ), SecDbKeychainItemCopyPrimaryKey
, NULL
);
93 SECDB_ATTR(v7vwht
, "vwht", String
, SecDbFlags(P
,L
,I
, ,A
, , , ,H
, , , , ,U
,V2
,Y
), NULL
, NULL
);
94 SECDB_ATTR(v7tkid
, "tkid", String
, SecDbFlags(P
,L
,I
, ,A
, , , ,H
, , , , ,U
,V2
,Y
), NULL
, NULL
);
95 SECDB_ATTR(v7utomb
, "u_Tomb", UTomb
, SecDbFlags( , , , , , , , , , , , , , , , ), NULL
, NULL
);
96 SECDB_ATTR(v8musr
, "musr", UUID
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
,U
, ,Y
), NULL
, NULL
);
97 // genp and inet and keys | | | | | | | | | | | | | | | |
98 SECDB_ATTR(v6crtr
, "crtr", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
99 SECDB_ATTR(v6alis
, "alis", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
100 // genp and inet | | | | | | | | | | | | | | | |
101 SECDB_ATTR(v6desc
, "desc", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
102 SECDB_ATTR(v6icmt
, "icmt", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
103 SECDB_ATTR(v6type
, "type", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
104 SECDB_ATTR(v6invi
, "invi", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
105 SECDB_ATTR(v6nega
, "nega", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
106 SECDB_ATTR(v6cusi
, "cusi", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
107 SECDB_ATTR(v6prot
, "prot", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
108 SECDB_ATTR(v6scrp
, "scrp", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
109 SECDB_ATTR(v6acct
, "acct", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
110 // genp only | | | | | | | | | | | | | | | |
111 SECDB_ATTR(v6svce
, "svce", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
112 SECDB_ATTR(v6gena
, "gena", Blob
, SecDbFlags( ,L
, ,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
113 // inet only | | | | | | | | | | | | | | | |
114 SECDB_ATTR(v6sdmn
, "sdmn", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
115 SECDB_ATTR(v6srvr
, "srvr", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
116 SECDB_ATTR(v6ptcl
, "ptcl", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
117 SECDB_ATTR(v6atyp
, "atyp", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
118 SECDB_ATTR(v6port
, "port", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
119 SECDB_ATTR(v6path
, "path", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
120 // cert only | | | | | | | | | | | | | | | |
121 SECDB_ATTR(v6ctyp
, "ctyp", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
122 SECDB_ATTR(v6cenc
, "cenc", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
123 SECDB_ATTR(v6subj
, "subj", Data
, SecDbFlags( ,L
,I
,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
124 SECDB_ATTR(v6issr
, "issr", Data
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
125 SECDB_ATTR(v6slnr
, "slnr", Data
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
126 SECDB_ATTR(v6skid
, "skid", Data
, SecDbFlags( ,L
,I
,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
127 SECDB_ATTR(v6pkhh
, "pkhh", Data
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
128 // cert attributes that share names with common ones but have different flags
129 SECDB_ATTR(v6certalis
, "alis", Blob
, SecDbFlags( ,L
,I
,S
,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
130 // keys only | | | | | | | | | | | | | | | |
131 SECDB_ATTR(v6kcls
, "kcls", Number
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
132 SECDB_ATTR(v6perm
, "perm", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
133 SECDB_ATTR(v6priv
, "priv", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
134 SECDB_ATTR(v6modi
, "modi", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
135 SECDB_ATTR(v6klbl
, "klbl", Data
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
136 SECDB_ATTR(v6atag
, "atag", Blob
, SecDbFlags(P
,L
,I
,S
,A
, , ,C
,H
, , ,E
,N
, ,V0
,Y
), NULL
, NULL
);
137 SECDB_ATTR(v6bsiz
, "bsiz", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
138 SECDB_ATTR(v6esiz
, "esiz", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
139 SECDB_ATTR(v6sdat
, "sdat", Date
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
140 SECDB_ATTR(v6edat
, "edat", Date
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
141 SECDB_ATTR(v6sens
, "sens", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
142 SECDB_ATTR(v6asen
, "asen", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
143 SECDB_ATTR(v6extr
, "extr", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
144 SECDB_ATTR(v6next
, "next", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
145 SECDB_ATTR(v6encr
, "encr", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
146 SECDB_ATTR(v6decr
, "decr", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
147 SECDB_ATTR(v6drve
, "drve", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
148 SECDB_ATTR(v6sign
, "sign", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
149 SECDB_ATTR(v6vrfy
, "vrfy", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
150 SECDB_ATTR(v6snrc
, "snrc", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
151 SECDB_ATTR(v6vyrc
, "vyrc", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
152 SECDB_ATTR(v6wrap
, "wrap", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
153 SECDB_ATTR(v6unwp
, "unwp", Number
, SecDbFlags( ,L
,I
, ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
154 // keys attributes that share names with common ones but have different flags
155 SECDB_ATTR(v6keytype
, "type", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
156 SECDB_ATTR(v6keycrtr
, "crtr", Number
, SecDbFlags(P
,L
,I
, ,A
, , ,C
,H
, ,Z
, ,N
, ,V0
,Y
), NULL
, NULL
);
157 // | | | | | | | | | | | | | | |
158 SECDB_ATTR(v6version
, "version", Number
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , ,Y
), NULL
, NULL
);
159 SECDB_ATTR(v91minor
, "minor", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
, , ,Y
), NULL
, NULL
);
161 SECDB_ATTR(v10_1pcsservice
, "pcss", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
162 SECDB_ATTR(v10_1pcspublickey
, "pcsk", Blob
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
163 SECDB_ATTR(v10_1pcspublicidentity
,"pcsi", Blob
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, , , , , , ,Y
), NULL
, NULL
);
165 SECDB_ATTR(v10itemuuid
, "UUID", String
, SecDbFlags( ,L
,I
, , , , , , , , , , ,U
, , ), NULL
, NULL
);
166 SECDB_ATTR(v10syncuuid
, "UUID", String
, SecDbFlags(P
,L
,I
, , , , , , , , , , ,U
, , ), NULL
, NULL
);
167 SECDB_ATTR(v10parentKeyUUID
, "parentKeyUUID", String
, SecDbFlags( ,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
168 SECDB_ATTR(v10currentKeyUUID
,"currentKeyUUID",String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
169 SECDB_ATTR(v10wrappedkey
, "wrappedkey", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
170 SECDB_ATTR(v10encrypteditem
, "encitem", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
171 SECDB_ATTR(v10gencount
, "gencount", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
, , , ), NULL
, NULL
);
172 SECDB_ATTR(v10action
, "action", String
, SecDbFlags( ,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
173 SECDB_ATTR(v10state
, "state", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
174 SECDB_ATTR(v10waituntiltime
, "waituntil", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
175 SECDB_ATTR(v10encodedCKRecord
, "ckrecord", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
176 SECDB_ATTR(v10_1wasCurrent
, "wascurrent", Number
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
177 SECDB_ATTR(v10accessgroup
, "accessgroup", String
, SecDbFlags( ,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
178 SECDB_ATTR(v10keyclass
, "keyclass", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
179 SECDB_ATTR(v10currentkey
, "currentkey", Number
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
180 SECDB_ATTR(v10ckzone
, "ckzone", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
181 SECDB_ATTR(v10ckzonecreated
, "ckzonecreated", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, , ,N
, , ), NULL
, NULL
);
182 SECDB_ATTR(v10ckzonesubscribed
,"ckzonesubscribed", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
, , , ), NULL
, NULL
);
183 SECDB_ATTR(v10ratelimiter
, "ratelimiter", Blob
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
184 SECDB_ATTR(v10changetoken
, "changetoken", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
185 SECDB_ATTR(v10lastfetchtime
, "lastfetch", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
186 SECDB_ATTR(v10itempersistentref
,"persistref", UUID
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
187 SECDB_ATTR(v10sysbound
, "sysb", Number
, SecDbFlags( ,L
, , ,A
, , ,C
,H
, ,Z
, , , , , ), NULL
, NULL
);
188 SECDB_ATTR(v10encryptionver
, "encver", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
,U
, , ), NULL
, NULL
);
190 SECDB_ATTR(v10primaryKey
, "primaryKey", String
, SecDbFlags(P
,L
,I
, ,A
, , , , , , , ,N
,U
, , ), NULL
, NULL
);
191 SECDB_ATTR(v10publickeyHash
, "publickeyHash", Blob
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
192 SECDB_ATTR(v10publickey
, "publickey", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
193 SECDB_ATTR(v10backupData
, "backupData", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
195 SECDB_ATTR(v10_1digest
, "digest", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
196 SECDB_ATTR(v10_1signatures
, "signatures", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
197 SECDB_ATTR(v10_1signerID
, "signerID", String
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
198 SECDB_ATTR(v10_1leafIDs
, "leafIDs", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
199 SECDB_ATTR(v10_1peerManIDs
, "peerManifests", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
200 SECDB_ATTR(v10_1entryDigests
,"entryDigests", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
201 SECDB_ATTR(v10_2currentItems
,"currentItems", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
202 SECDB_ATTR(v10_2futureData
, "futureData", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
203 SECDB_ATTR(v10_2schema
, "schema", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
204 SECDB_ATTR(v10_1encRecord
, "ckrecord", Blob
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
206 SECDB_ATTR(v10_1keyArchiveHash
, "key_archive_hash", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
207 SECDB_ATTR(v10_1keyArchive
, "key_archive", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
208 SECDB_ATTR(v10_1archivedKey
, "archived_key", String
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
209 SECDB_ATTR(v10_1keyArchiveName
, "keyarchive_name", String
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
210 SECDB_ATTR(v10_1optionalEncodedCKRecord
, "ckrecord", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
211 SECDB_ATTR(v10_1archiveEscrowID
,"archive_escrowid", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
213 SECDB_ATTR(v10_1itempersistentref
,"persistref", UUID
, SecDbFlags( ,L
,I
, , , , , , , , , ,N
,U
, , ), NULL
, NULL
);
215 SECDB_ATTR(v10_1currentItemUUID
,"currentItemUUID",String
, SecDbFlags(P
,L
,I
, , , , , , , , , , , , , ), NULL
, NULL
);
216 SECDB_ATTR(v10_4currentItemUUID
,"currentItemUUID",String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
217 SECDB_ATTR(v10_1currentPtrIdentifier
,"identifier",String
, SecDbFlags(P
,L
,I
, , , , , , , , , , , , , ), NULL
, NULL
);
219 SECDB_ATTR(v10_2device
, "device", String
, SecDbFlags(P
,L
,I
, , , , , , , , , , , , , ), NULL
, NULL
);
220 SECDB_ATTR(v10_2peerid
, "peerid", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
221 SECDB_ATTR(v10_2circleStatus
,"circlestatus", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
222 SECDB_ATTR(v10_2keyState
, "keystate", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
223 SECDB_ATTR(v10_2currentTLK
, "currentTLK", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
224 SECDB_ATTR(v10_2currentClassA
,"currentClassA",String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
225 SECDB_ATTR(v10_2currentClassC
,"currentClassC",String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
227 SECDB_ATTR(v10_4lastFixup
, "lastfixup", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, , ,N
, , ), NULL
, NULL
);
229 SECDB_ATTR(v10_5senderPeerID
,"senderpeerid", String
, SecDbFlags(P
,L
,I
, , , , , , , , , , , , , ), NULL
, NULL
);
230 SECDB_ATTR(v10_5recvPeerID
, "recvpeerid", String
, SecDbFlags(P
,L
,I
, , , , , , , , , , , , , ), NULL
, NULL
);
231 SECDB_ATTR(v10_5recvPubKey
, "recvpubenckey", Blob
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
232 SECDB_ATTR(v10_5curve
, "curve", Number
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
233 SECDB_ATTR(v10_5poisoned
, "poisoned", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
, , , ), NULL
, NULL
);
234 SECDB_ATTR(v10_5epoch
, "epoch", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
, , , ), NULL
, NULL
);
235 SECDB_ATTR(v10_5signature
, "signature", Blob
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
236 SECDB_ATTR(v10_5version
, "version", Number
, SecDbFlags( ,L
, , , , , , , , ,Z
, ,N
,U
, , ), NULL
, NULL
);
238 SECDB_ATTR(v11_1osversion
, "osversion", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
239 SECDB_ATTR(v11_1lastunlock
, "lastunlock", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
241 SECDB_ATTR(v11_2actualKeyclass
, "actualKeyclass", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
243 SECDB_ATTR(v11_5octagonpeerid
, "octagonpeerid", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
244 SECDB_ATTR(v11_5octagonStatus
, "octagonstatus", String
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
246 SECDB_ATTR(v11_6moreComing
, "morecoming", Number
, SecDbFlags( ,L
, , , , , , , , , , , , , , ), NULL
, NULL
);
248 SECDB_ATTR(v12_backupUUIDPrimary
, "backupUUID", UUID
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
249 SECDB_ATTR(v12_backupUUID
, "backupUUID", UUID
, SecDbFlags( ,L
,I
, , , , , , , , ,E
, , , , ), NULL
, NULL
);
250 SECDB_ATTR(v12_backupBag
, "backupbag", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
251 SECDB_ATTR(v12_defaultValue
, "defaultvalue", Number
, SecDbFlags( ,L
,I
, , , , , , , ,Z
, , , , , ), NULL
, NULL
);
252 SECDB_ATTR(v12_keyClassSigningKey
, "signingkey", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
253 SECDB_ATTR(v12_recoveryType
, "recoverytype", String
, SecDbFlags(P
,L
,I
, , , , , , , , , ,N
, , , ), NULL
, NULL
);
254 SECDB_ATTR(v12_recoverySet
, "recoveryset", Blob
, SecDbFlags( ,L
, , , , , , , , , , ,N
, , , ), NULL
, NULL
);
255 SECDB_ATTR(v12_metadatakeydata
, "metadatakeydata", Blob
, SecDbFlags( ,L
, , , , , , , , , ,E
, , , , ), NULL
, NULL
);
257 const SecDbClass v12_backupbags_class
= {
258 .name
= CFSTR("backupbags"),
261 &v12_backupUUIDPrimary
, // primary
268 const SecDbClass v12_backupkeyclasssigningkeys_class
= {
269 .name
= CFSTR("backupkeyclasssigningkeys"),
272 &v10keyclass
, // primary
273 &v12_backupUUIDPrimary
, // primary
274 &v12_keyClassSigningKey
,
279 const SecDbClass v12_backuprecoverysets_class
= {
280 .name
= CFSTR("backuprecoverysets"),
283 &v12_backupUUIDPrimary
, // primary
284 &v12_recoveryType
, // primary
290 const SecDbClass v12_metadatakeys_class
= {
291 .name
= CFSTR("metadatakeys"),
295 &v11_2actualKeyclass
,
297 &v12_metadatakeydata
,
302 const SecDbClass v12_genp_class
= {
303 .name
= CFSTR("genp"),
340 &v10_1pcspublicidentity
,
341 &v10_1itempersistentref
,
347 const SecDbClass v12_inet_class
= {
348 .name
= CFSTR("inet"),
389 &v10_1pcspublicidentity
,
390 &v10_1itempersistentref
,
396 const SecDbClass v12_cert_class
= {
397 .name
= CFSTR("cert"),
429 &v10_1pcspublicidentity
,
430 &v10_1itempersistentref
,
436 const SecDbClass v12_keys_class
= {
437 .name
= CFSTR("keys"),
487 &v10_1pcspublicidentity
,
488 &v10_1itempersistentref
,
494 const SecDbClass v11_6_ckstate_class
= {
495 .name
= CFSTR("ckstate"),
500 &v10ckzonesubscribed
,
510 const SecDbClass v11_5_ckdevicestate_class
= {
511 .name
= CFSTR("ckdevicestate"),
531 const SecDbClass v11_2_metadatakeys_class
= {
532 .name
= CFSTR("metadatakeys"),
536 &v11_2actualKeyclass
,
542 const SecDbClass v11_1_ckdevicestate_class
= {
543 .name
= CFSTR("ckdevicestate"),
561 const SecDbClass v11_metadatakeys_class
= {
562 .name
= CFSTR("metadatakeys"),
571 const SecDbClass v10_5_tlkshare_class
= {
572 .name
= CFSTR("tlkshare"),
592 const SecDbClass v10_4_current_item_class
= {
593 .name
= CFSTR("currentitems"),
597 &v10_1currentPtrIdentifier
,
598 &v10_4currentItemUUID
,
605 const SecDbClass v10_4_ckstate_class
= {
606 .name
= CFSTR("ckstate"),
611 &v10ckzonesubscribed
,
620 const SecDbClass v10_3_ckdevicestate_class
= {
621 .name
= CFSTR("ckdevicestate"),
637 const SecDbClass v10_2_ckmanifest_class
= {
638 .name
= CFSTR("ckmanifest"),
656 const SecDbClass v10_2_pending_manifest_class
= {
657 .name
= CFSTR("pending_manifest"),
675 const SecDbClass v10_1_ckmanifest_class
= {
676 .name
= CFSTR("ckmanifest"),
691 const SecDbClass v10_1_pending_manifest_class
= {
692 .name
= CFSTR("pending_manifest"),
707 const SecDbClass v10_1_ckmanifest_leaf_class
= {
708 .name
= CFSTR("ckmanifest_leaf"),
720 const SecDbClass v10_1_pending_manifest_leaf_class
= {
721 .name
= CFSTR("pending_manifest_leaf"),
733 const SecDbClass v10_1_genp_class
= {
734 .name
= CFSTR("genp"),
771 &v10_1pcspublicidentity
,
772 &v10_1itempersistentref
,
777 const SecDbClass v10_1_inet_class
= {
778 .name
= CFSTR("inet"),
819 &v10_1pcspublicidentity
,
820 &v10_1itempersistentref
,
825 const SecDbClass v10_1_cert_class
= {
826 .name
= CFSTR("cert"),
858 &v10_1pcspublicidentity
,
859 &v10_1itempersistentref
,
864 const SecDbClass v10_1_keys_class
= {
865 .name
= CFSTR("keys"),
915 &v10_1pcspublicidentity
,
916 &v10_1itempersistentref
,
921 const SecDbClass v10_0_tversion_class
= {
922 .name
= CFSTR("tversion"),
932 const SecDbClass v10_2_outgoing_queue_class
= {
933 .name
= CFSTR("outgoingqueue"),
947 &v10_1optionalEncodedCKRecord
,
950 &v10_1pcspublicidentity
,
955 const SecDbClass v10_2_incoming_queue_class
= {
956 .name
= CFSTR("incomingqueue"),
968 &v10_1optionalEncodedCKRecord
,
971 &v10_1pcspublicidentity
,
977 const SecDbClass v10_1_outgoing_queue_class
= {
978 .name
= CFSTR("outgoingqueue"),
994 &v10_1pcspublicidentity
,
999 const SecDbClass v10_1_incoming_queue_class
= {
1000 .name
= CFSTR("incomingqueue"),
1014 &v10_1pcspublicidentity
,
1020 const SecDbClass v10_0_outgoing_queue_class
= {
1021 .name
= CFSTR("outgoingqueue"),
1039 const SecDbClass v10_0_incoming_queue_class
= {
1040 .name
= CFSTR("incomingqueue"),
1056 const SecDbClass v10_0_sync_key_class
= {
1057 .name
= CFSTR("synckeys"),
1067 &v10encodedCKRecord
,
1072 // Stores the "Current Key" records, and parentKeyUUID refers to items in the synckeys table
1073 // Wouldn't foreign keys be nice?
1074 const SecDbClass v10_0_current_key_class
= {
1075 .name
= CFSTR("currentkeys"),
1081 &v10encodedCKRecord
,
1086 const SecDbClass v10_1_current_item_class
= {
1087 .name
= CFSTR("currentitems"),
1091 &v10_1currentPtrIdentifier
,
1092 &v10_1currentItemUUID
,
1094 &v10encodedCKRecord
,
1099 const SecDbClass v10_1_ckmirror_class
= {
1100 .name
= CFSTR("ckmirror"),
1109 &v10encodedCKRecord
,
1114 &v10_1pcspublicidentity
,
1119 const SecDbClass v10_0_ckmirror_class
= {
1120 .name
= CFSTR("ckmirror"),
1129 &v10encodedCKRecord
,
1135 const SecDbClass v10_0_ckstate_class
= {
1136 .name
= CFSTR("ckstate"),
1141 &v10ckzonesubscribed
,
1150 /* Primary keys: v10primaryKey, v8musr */
1151 /* This table is currently unused */
1152 const SecDbClass v10_0_item_backup_class
= {
1153 .name
= CFSTR("item_backup"),
1157 &v10primaryKey
, // Primary key of the original item, from v6v_pk
1159 &v6sha1
, // Hash of the original item
1160 &v10backupData
, // Data wrapped to backup keybag
1161 &v6pkhh
, // Hash of the public key of the backup bag [v10publickeyHash]
1166 /* Backup Keybag table */
1167 /* Primary keys: v10publickeyHash, v8musr */
1168 /* This table is currently unused */
1169 const SecDbClass v10_0_backup_keybag_class
= {
1170 .name
= CFSTR("backup_keybag"),
1174 &v10publickeyHash
, // Hash of the public key of the backup bag
1176 &v10publickey
, // Public key for the asymmetric backup bag
1177 &v6agrp
, // Used for backup agent
1182 const SecDbClass v10_1_backup_keyarchive_class
= {
1183 .name
= CFSTR("backup_keyarchive"),
1186 &v10_1keyArchiveHash
, // Hash of the key archive
1188 &v10_1keyArchive
, // Serialised key archive
1190 &v10_1optionalEncodedCKRecord
,
1191 &v10_1archiveEscrowID
,
1196 const SecDbClass v10_1_current_archived_keys_class
= {
1197 .name
= CFSTR("archived_key_backup"),
1204 &v10_1keyArchiveHash
,
1207 &v10_1optionalEncodedCKRecord
,
1208 &v10_1archiveEscrowID
,
1213 const SecDbClass v10_1_current_keyarchive_class
= {
1214 .name
= CFSTR("currentkeyarchives"),
1217 &v10_1keyArchiveHash
,
1218 &v10_1keyArchiveName
,
1223 /* An identity which is really a cert + a key, so all cert and keys attrs are
1225 const SecDbClass v_identity_class
= {
1226 .name
= CFSTR("idnt"),
1235 * Add backup/restore mechanism
1237 const SecDbSchema v12_0_schema
= {
1245 &v10_0_tversion_class
,
1246 &v10_2_outgoing_queue_class
,
1247 &v10_2_incoming_queue_class
,
1248 &v10_0_sync_key_class
,
1249 &v10_1_ckmirror_class
,
1250 &v10_0_current_key_class
,
1251 &v11_6_ckstate_class
,
1252 &v10_0_item_backup_class
,
1253 &v10_0_backup_keybag_class
,
1254 &v10_2_ckmanifest_class
,
1255 &v10_2_pending_manifest_class
,
1256 &v10_1_ckmanifest_leaf_class
,
1257 &v10_1_backup_keyarchive_class
,
1258 &v10_1_current_keyarchive_class
,
1259 &v10_1_current_archived_keys_class
,
1260 &v10_1_pending_manifest_leaf_class
,
1261 &v10_4_current_item_class
,
1262 &v11_5_ckdevicestate_class
,
1263 &v10_5_tlkshare_class
,
1264 &v12_metadatakeys_class
,
1265 &v12_backupbags_class
,
1266 &v12_backupkeyclasssigningkeys_class
,
1267 &v12_backuprecoverysets_class
,
1273 * Version 11.6 (Add 'moreComing' field to zone state)
1275 const SecDbSchema v11_6_schema
= {
1283 &v10_0_tversion_class
,
1284 &v10_2_outgoing_queue_class
,
1285 &v10_2_incoming_queue_class
,
1286 &v10_0_sync_key_class
,
1287 &v10_1_ckmirror_class
,
1288 &v10_0_current_key_class
,
1289 &v11_6_ckstate_class
,
1290 &v10_0_item_backup_class
,
1291 &v10_0_backup_keybag_class
,
1292 &v10_2_ckmanifest_class
,
1293 &v10_2_pending_manifest_class
,
1294 &v10_1_ckmanifest_leaf_class
,
1295 &v10_1_backup_keyarchive_class
,
1296 &v10_1_current_keyarchive_class
,
1297 &v10_1_current_archived_keys_class
,
1298 &v10_1_pending_manifest_leaf_class
,
1299 &v10_4_current_item_class
,
1300 &v11_5_ckdevicestate_class
,
1301 &v10_5_tlkshare_class
,
1302 &v11_2_metadatakeys_class
,
1308 * Version 11.5 (Add octagon fields to device state)
1310 const SecDbSchema v11_5_schema
= {
1318 &v10_0_tversion_class
,
1319 &v10_2_outgoing_queue_class
,
1320 &v10_2_incoming_queue_class
,
1321 &v10_0_sync_key_class
,
1322 &v10_1_ckmirror_class
,
1323 &v10_0_current_key_class
,
1324 &v10_4_ckstate_class
,
1325 &v10_0_item_backup_class
,
1326 &v10_0_backup_keybag_class
,
1327 &v10_2_ckmanifest_class
,
1328 &v10_2_pending_manifest_class
,
1329 &v10_1_ckmanifest_leaf_class
,
1330 &v10_1_backup_keyarchive_class
,
1331 &v10_1_current_keyarchive_class
,
1332 &v10_1_current_archived_keys_class
,
1333 &v10_1_pending_manifest_leaf_class
,
1334 &v10_4_current_item_class
,
1335 &v11_5_ckdevicestate_class
,
1336 &v10_5_tlkshare_class
,
1337 &v11_2_metadatakeys_class
,
1344 * Version 11.4 (Add some more indexes)
1346 const SecDbSchema v11_4_schema
= {
1354 &v10_0_tversion_class
,
1355 &v10_2_outgoing_queue_class
,
1356 &v10_2_incoming_queue_class
,
1357 &v10_0_sync_key_class
,
1358 &v10_1_ckmirror_class
,
1359 &v10_0_current_key_class
,
1360 &v10_4_ckstate_class
,
1361 &v10_0_item_backup_class
,
1362 &v10_0_backup_keybag_class
,
1363 &v10_2_ckmanifest_class
,
1364 &v10_2_pending_manifest_class
,
1365 &v10_1_ckmanifest_leaf_class
,
1366 &v10_1_backup_keyarchive_class
,
1367 &v10_1_current_keyarchive_class
,
1368 &v10_1_current_archived_keys_class
,
1369 &v10_1_pending_manifest_leaf_class
,
1370 &v10_4_current_item_class
,
1371 &v11_1_ckdevicestate_class
,
1372 &v10_5_tlkshare_class
,
1373 &v11_2_metadatakeys_class
,
1379 * Version 11.3 (no changes, restores the use of indexes in upgrade code. Gotta go fast!)
1381 const SecDbSchema v11_3_schema
= {
1389 &v10_0_tversion_class
,
1390 &v10_2_outgoing_queue_class
,
1391 &v10_2_incoming_queue_class
,
1392 &v10_0_sync_key_class
,
1393 &v10_1_ckmirror_class
,
1394 &v10_0_current_key_class
,
1395 &v10_4_ckstate_class
,
1396 &v10_0_item_backup_class
,
1397 &v10_0_backup_keybag_class
,
1398 &v10_2_ckmanifest_class
,
1399 &v10_2_pending_manifest_class
,
1400 &v10_1_ckmanifest_leaf_class
,
1401 &v10_1_backup_keyarchive_class
,
1402 &v10_1_current_keyarchive_class
,
1403 &v10_1_current_archived_keys_class
,
1404 &v10_1_pending_manifest_leaf_class
,
1405 &v10_4_current_item_class
,
1406 &v11_1_ckdevicestate_class
,
1407 &v10_5_tlkshare_class
,
1408 &v11_2_metadatakeys_class
,
1416 const SecDbSchema v11_2_schema
= {
1424 &v10_0_tversion_class
,
1425 &v10_2_outgoing_queue_class
,
1426 &v10_2_incoming_queue_class
,
1427 &v10_0_sync_key_class
,
1428 &v10_1_ckmirror_class
,
1429 &v10_0_current_key_class
,
1430 &v10_4_ckstate_class
,
1431 &v10_0_item_backup_class
,
1432 &v10_0_backup_keybag_class
,
1433 &v10_2_ckmanifest_class
,
1434 &v10_2_pending_manifest_class
,
1435 &v10_1_ckmanifest_leaf_class
,
1436 &v10_1_backup_keyarchive_class
,
1437 &v10_1_current_keyarchive_class
,
1438 &v10_1_current_archived_keys_class
,
1439 &v10_1_pending_manifest_leaf_class
,
1440 &v10_4_current_item_class
,
1441 &v11_1_ckdevicestate_class
,
1442 &v10_5_tlkshare_class
,
1443 &v11_2_metadatakeys_class
,
1451 const SecDbSchema v11_1_schema
= {
1459 &v10_0_tversion_class
,
1460 &v10_2_outgoing_queue_class
,
1461 &v10_2_incoming_queue_class
,
1462 &v10_0_sync_key_class
,
1463 &v10_1_ckmirror_class
,
1464 &v10_0_current_key_class
,
1465 &v10_4_ckstate_class
,
1466 &v10_0_item_backup_class
,
1467 &v10_0_backup_keybag_class
,
1468 &v10_2_ckmanifest_class
,
1469 &v10_2_pending_manifest_class
,
1470 &v10_1_ckmanifest_leaf_class
,
1471 &v10_1_backup_keyarchive_class
,
1472 &v10_1_current_keyarchive_class
,
1473 &v10_1_current_archived_keys_class
,
1474 &v10_1_pending_manifest_leaf_class
,
1475 &v10_4_current_item_class
,
1476 &v11_1_ckdevicestate_class
,
1477 &v10_5_tlkshare_class
,
1478 &v11_metadatakeys_class
,
1486 const SecDbSchema v11_schema
= {
1494 &v10_0_tversion_class
,
1495 &v10_2_outgoing_queue_class
,
1496 &v10_2_incoming_queue_class
,
1497 &v10_0_sync_key_class
,
1498 &v10_1_ckmirror_class
,
1499 &v10_0_current_key_class
,
1500 &v10_4_ckstate_class
,
1501 &v10_0_item_backup_class
,
1502 &v10_0_backup_keybag_class
,
1503 &v10_2_ckmanifest_class
,
1504 &v10_2_pending_manifest_class
,
1505 &v10_1_ckmanifest_leaf_class
,
1506 &v10_1_backup_keyarchive_class
,
1507 &v10_1_current_keyarchive_class
,
1508 &v10_1_current_archived_keys_class
,
1509 &v10_1_pending_manifest_leaf_class
,
1510 &v10_4_current_item_class
,
1511 &v10_3_ckdevicestate_class
,
1512 &v10_5_tlkshare_class
,
1513 &v11_metadatakeys_class
,
1522 const SecDbSchema v10_5_schema
= {
1530 &v10_0_tversion_class
,
1531 &v10_2_outgoing_queue_class
,
1532 &v10_2_incoming_queue_class
,
1533 &v10_0_sync_key_class
,
1534 &v10_1_ckmirror_class
,
1535 &v10_0_current_key_class
,
1536 &v10_4_ckstate_class
,
1537 &v10_0_item_backup_class
,
1538 &v10_0_backup_keybag_class
,
1539 &v10_2_ckmanifest_class
,
1540 &v10_2_pending_manifest_class
,
1541 &v10_1_ckmanifest_leaf_class
,
1542 &v10_1_backup_keyarchive_class
,
1543 &v10_1_current_keyarchive_class
,
1544 &v10_1_current_archived_keys_class
,
1545 &v10_1_pending_manifest_leaf_class
,
1546 &v10_4_current_item_class
,
1547 &v10_3_ckdevicestate_class
,
1548 &v10_5_tlkshare_class
,
1556 const SecDbSchema v10_4_schema
= {
1564 &v10_0_tversion_class
,
1565 &v10_2_outgoing_queue_class
,
1566 &v10_2_incoming_queue_class
,
1567 &v10_0_sync_key_class
,
1568 &v10_1_ckmirror_class
,
1569 &v10_0_current_key_class
,
1570 &v10_4_ckstate_class
,
1571 &v10_0_item_backup_class
,
1572 &v10_0_backup_keybag_class
,
1573 &v10_2_ckmanifest_class
,
1574 &v10_2_pending_manifest_class
,
1575 &v10_1_ckmanifest_leaf_class
,
1576 &v10_1_backup_keyarchive_class
,
1577 &v10_1_current_keyarchive_class
,
1578 &v10_1_current_archived_keys_class
,
1579 &v10_1_pending_manifest_leaf_class
,
1580 &v10_4_current_item_class
,
1581 &v10_3_ckdevicestate_class
,
1589 const SecDbSchema v10_3_schema
= {
1597 &v10_0_tversion_class
,
1598 &v10_2_outgoing_queue_class
,
1599 &v10_2_incoming_queue_class
,
1600 &v10_0_sync_key_class
,
1601 &v10_1_ckmirror_class
,
1602 &v10_0_current_key_class
,
1603 &v10_0_ckstate_class
,
1604 &v10_0_item_backup_class
,
1605 &v10_0_backup_keybag_class
,
1606 &v10_2_ckmanifest_class
,
1607 &v10_2_pending_manifest_class
,
1608 &v10_1_ckmanifest_leaf_class
,
1609 &v10_1_backup_keyarchive_class
,
1610 &v10_1_current_keyarchive_class
,
1611 &v10_1_current_archived_keys_class
,
1612 &v10_1_pending_manifest_leaf_class
,
1613 &v10_1_current_item_class
,
1614 &v10_3_ckdevicestate_class
,
1622 const SecDbSchema v10_2_schema
= {
1630 &v10_0_tversion_class
,
1631 &v10_2_outgoing_queue_class
,
1632 &v10_2_incoming_queue_class
,
1633 &v10_0_sync_key_class
,
1634 &v10_1_ckmirror_class
,
1635 &v10_0_current_key_class
,
1636 &v10_0_ckstate_class
,
1637 &v10_0_item_backup_class
,
1638 &v10_0_backup_keybag_class
,
1639 &v10_2_ckmanifest_class
,
1640 &v10_2_pending_manifest_class
,
1641 &v10_1_ckmanifest_leaf_class
,
1642 &v10_1_backup_keyarchive_class
,
1643 &v10_1_current_keyarchive_class
,
1644 &v10_1_current_archived_keys_class
,
1645 &v10_1_pending_manifest_leaf_class
,
1646 &v10_1_current_item_class
,
1654 const SecDbSchema v10_1_schema
= {
1662 &v10_0_tversion_class
,
1663 &v10_1_outgoing_queue_class
,
1664 &v10_1_incoming_queue_class
,
1665 &v10_0_sync_key_class
,
1666 &v10_1_ckmirror_class
,
1667 &v10_0_current_key_class
,
1668 &v10_0_ckstate_class
,
1669 &v10_0_item_backup_class
,
1670 &v10_0_backup_keybag_class
,
1671 &v10_1_ckmanifest_class
,
1672 &v10_1_pending_manifest_class
,
1673 &v10_1_ckmanifest_leaf_class
,
1674 &v10_1_backup_keyarchive_class
,
1675 &v10_1_current_keyarchive_class
,
1676 &v10_1_current_archived_keys_class
,
1677 &v10_1_pending_manifest_leaf_class
,
1678 &v10_1_current_item_class
,
1687 const SecDbClass v10_0_genp_class
= {
1688 .name
= CFSTR("genp"),
1722 &v10itempersistentref
,
1728 const SecDbClass v10_0_inet_class
= {
1729 .name
= CFSTR("inet"),
1767 &v10itempersistentref
,
1773 const SecDbClass v10_0_cert_class
= {
1774 .name
= CFSTR("cert"),
1803 &v10itempersistentref
,
1809 const SecDbClass v10_0_keys_class
= {
1810 .name
= CFSTR("keys"),
1857 &v10itempersistentref
,
1863 const SecDbSchema v10_0_schema
= {
1871 &v10_0_tversion_class
,
1872 &v10_0_outgoing_queue_class
,
1873 &v10_0_incoming_queue_class
,
1874 &v10_0_sync_key_class
,
1875 &v10_0_ckmirror_class
,
1876 &v10_0_current_key_class
,
1877 &v10_0_ckstate_class
,
1878 &v10_0_item_backup_class
,
1879 &v10_0_backup_keybag_class
,
1884 const SecDbClass v9_1_tversion_class
= {
1885 .name
= CFSTR("tversion91"),
1895 const SecDbClass v9_1_genp_class
= {
1896 .name
= CFSTR("genp91"),
1933 const SecDbClass v9_1_inet_class
= {
1934 .name
= CFSTR("inet91"),
1975 const SecDbClass v9_1_cert_class
= {
1976 .name
= CFSTR("cert91"),
2008 const SecDbClass v9_1_keys_class
= {
2009 .name
= CFSTR("keys91"),
2060 * Version 9.1 (iOS 10.0 and OSX 10.11.8/10.12 addded minor version.
2062 const SecDbSchema v9_1_schema
= {
2070 &v9_1_tversion_class
,
2075 const SecDbClass v9genp_class
= {
2076 .name
= CFSTR("genp9"),
2113 const SecDbClass v9inet_class
= {
2114 .name
= CFSTR("inet9"),
2155 const SecDbClass v9cert_class
= {
2156 .name
= CFSTR("cert9"),
2188 const SecDbClass v9keys_class
= {
2189 .name
= CFSTR("keys9"),
2239 const SecDbClass v5tversion_class
= {
2240 .name
= CFSTR("tversion5"),
2248 /* Version 9 (iOS 9.3 and OSX 10.11.5) database schema
2249 * Same contents as v8 tables; table names changed to force upgrade
2250 * and correct default values in table.
2252 const SecDbSchema v9_schema
= {
2264 // Version 8 (Internal release iOS 9.3 and OSX 10.11.5) database schema
2265 const SecDbClass v8genp_class
= {
2266 .name
= CFSTR("genp8"),
2303 const SecDbClass v8inet_class
= {
2304 .name
= CFSTR("inet8"),
2345 const SecDbClass v8cert_class
= {
2346 .name
= CFSTR("cert8"),
2378 const SecDbClass v8keys_class
= {
2379 .name
= CFSTR("keys8"),
2429 const SecDbSchema v8_schema
= {
2441 // Version 7 (iOS 9 and OSX 10.11) database schema
2442 const SecDbClass v7genp_class
= {
2443 .name
= CFSTR("genp7"),
2479 const SecDbClass v7inet_class
= {
2480 .name
= CFSTR("inet7"),
2520 const SecDbClass v7cert_class
= {
2521 .name
= CFSTR("cert7"),
2552 const SecDbClass v7keys_class
= {
2553 .name
= CFSTR("keys7"),
2603 const SecDbSchema v7_schema
= {
2616 // Version 6 (iOS 7 and OSX 10.9) database schema
2617 static const SecDbClass v6genp_class
= {
2618 .name
= CFSTR("genp6"),
2651 static const SecDbClass v6inet_class
= {
2652 .name
= CFSTR("inet6"),
2689 static const SecDbClass v6cert_class
= {
2690 .name
= CFSTR("cert6"),
2718 static const SecDbClass v6keys_class
= {
2719 .name
= CFSTR("keys6"),
2765 static const SecDbSchema v6_schema
= {
2778 // Version 5 (iOS 5 & iOS 6) database schema.
2779 static const SecDbClass v5genp_class
= {
2780 .name
= CFSTR("genp5"),
2808 static const SecDbClass v5inet_class
= {
2809 .name
= CFSTR("inet5"),
2841 static const SecDbClass v5cert_class
= {
2842 .name
= CFSTR("cert5"),
2865 static const SecDbClass v5keys_class
= {
2866 .name
= CFSTR("keys5"),
2907 static const SecDbSchema v5_schema
= {
2919 SecDbSchema
const * const * kc_schemas
= NULL
;
2921 const SecDbSchema
*v10_kc_schemas_dev
[] = {
2945 const SecDbSchema
*v10_kc_schemas
[] = {
2968 const SecDbSchema
* const * all_schemas() {
2969 static dispatch_once_t onceToken
;
2970 dispatch_once(&onceToken
, ^{
2971 if (checkV12DevEnabled()) {
2972 secwarning("SecItemSchema: v12 development enabled, returning experimental schema");
2974 secnotice("SecItemSchema", "v12 development disabled, returning production schemas");
2977 if (checkV12DevEnabled() != 0) {
2978 return v10_kc_schemas_dev
;
2980 return v10_kc_schemas
;
2984 const SecDbSchema
* current_schema() {
2985 // For now, the current schema is the first in the list.
2986 return all_schemas()[0];
2989 // class accessors for current schema.
2990 static const SecDbClass
* find_class(const SecDbSchema
* schema
, CFStringRef class_name
) {
2991 for (const SecDbClass
* const *pclass
= schema
->classes
; *pclass
; ++pclass
) {
2992 if( CFEqualSafe((*pclass
)->name
, class_name
) ) {
2999 const SecDbClass
* genp_class() {
3000 static const SecDbClass
* genp
= NULL
;
3001 static dispatch_once_t onceToken
;
3002 dispatch_once(&onceToken
, ^{
3003 genp
= find_class(current_schema(), CFSTR("genp"));
3007 const SecDbClass
* inet_class() {
3008 static const SecDbClass
* inet
= NULL
;
3009 static dispatch_once_t onceToken
;
3010 dispatch_once(&onceToken
, ^{
3011 inet
= find_class(current_schema(), CFSTR("inet"));
3015 const SecDbClass
* cert_class() {
3016 static const SecDbClass
* cert
= NULL
;
3017 static dispatch_once_t onceToken
;
3018 dispatch_once(&onceToken
, ^{
3019 cert
= find_class(current_schema(), CFSTR("cert"));
3023 const SecDbClass
* keys_class() {
3024 static const SecDbClass
* keys
= NULL
;
3025 static dispatch_once_t onceToken
;
3026 dispatch_once(&onceToken
, ^{
3027 keys
= find_class(current_schema(), CFSTR("keys"));
3032 // Not really a class per-se
3033 const SecDbClass
* identity_class() {
3034 return &v_identity_class
;
3037 // Class with 1 element in it which is the database version->
3038 const SecDbClass
* tversion_class() {
3039 static const SecDbClass
* tversion
= NULL
;
3040 static dispatch_once_t onceToken
;
3041 dispatch_once(&onceToken
, ^{
3042 tversion
= find_class(current_schema(), CFSTR("tversion"));