X-Git-Url: https://git.saurik.com/apple/xnu.git/blobdiff_plain/0a7de7458d150b5d4dffc935ba399be265ef0a1a..HEAD:/bsd/kern/chunklist.h diff --git a/bsd/kern/chunklist.h b/bsd/kern/chunklist.h index b4fe59d01..adffd552e 100644 --- a/bsd/kern/chunklist.h +++ b/bsd/kern/chunklist.h @@ -1,19 +1,60 @@ #ifndef _CHUNKLIST_H #define _CHUNKLIST_H - #include +/* + * Boot argument for disabling trust in rev2 development key(s) + * Set by boot.efi + */ +#define CHUNKLIST_NO_REV2_DEV "-chunklist-no-rev2-dev" + +/* + * Boot argument for disabling trust in rev1 chunklists + * Set by boot.efi + */ +#define CHUNKLIST_NO_REV1 "-chunklist-no-rev1" + +/* + * Boot argument for obtaining current security epoch + * Set by boot.efi + */ +#define CHUNKLIST_SECURITY_EPOCH "chunklist-security-epoch" +#define CHUNKLIST_MIN_SECURITY_EPOCH 0 + /* * Chunklist file format */ +#define CHUNKLIST_MAGIC 0x4C4B4E43 +#define CHUNKLIST_FILE_VERSION_10 1 +#define CHUNKLIST_CHUNK_METHOD_10 1 +#define CHUNKLIST_SIGNATURE_METHOD_REV1 1 +#define CHUNKLIST_SIGNATURE_METHOD_REV2 3 +#define CHUNKLIST_REV1_SIG_LEN 256 +#define CHUNKLIST_REV2_SIG_LEN 808 +#define CHUNKLIST_PUBKEY_LEN (2048/8) +#define CHUNKLIST_SIGNATURE_LEN (2048/8) + +struct efi_guid_t { + uint32_t data1; + uint16_t data2; + uint16_t data3; + uint8_t data4[8]; +} __attribute__((packed)); -#define CHUNKLIST_MAGIC 0x4C4B4E43 -#define CHUNKLIST_FILE_VERSION_10 1 -#define CHUNKLIST_CHUNK_METHOD_10 1 -#define CHUNKLIST_SIGNATURE_METHOD_10 1 -#define CHUNKLIST_SIG_LEN 256 -#define CHUNKLIST_PUBKEY_LEN (2048/8) +// 45E7BC51-913C-42AC-96A2-10712FFBEBA7 +#define CHUNKLIST_REV2_SIG_HASH_GUID \ +{ \ + 0x45E7BC51, 0x913C, 0x42AC, { 0x96, 0xA2, 0x10, 0x71, 0x2F, 0xFB, 0xEB, 0xA7 } \ +}; + +// A7717414-C616-4977-9420-844712A735BF +#define EFI_CERT_TYPE_RSA2048_SHA256 \ +{ \ + 0xa7717414, 0xc616, 0x4977, { 0x94, 0x20, 0x84, 0x47, 0x12, 0xa7, 0x35, 0xbf } \ +} + +#define WIN_CERT_TYPE_EFI_GUID 0x0EF1 struct chunklist_hdr { uint32_t cl_magic; @@ -32,23 +73,24 @@ struct chunklist_chunk { uint8_t chunk_sha256[SHA256_DIGEST_LENGTH]; } __attribute__((packed)); -struct chunklist_sig { - uint8_t cl_sig[CHUNKLIST_SIG_LEN]; -}; - - -/* - * Chunklist signing public keys - */ +struct rev2_chunklist_certificate { + uint32_t length; + uint8_t revision; + uint8_t security_epoch; + uint16_t certificate_type; + guid_t certificate_guid; + guid_t hash_type_guid; + uint8_t rsa_public_key[CHUNKLIST_PUBKEY_LEN]; + uint8_t rsa_signature[CHUNKLIST_SIGNATURE_LEN]; +} __attribute__((packed)); struct chunklist_pubkey { - const bool isprod; + const boolean_t is_production; const uint8_t key[CHUNKLIST_PUBKEY_LEN]; }; -const struct chunklist_pubkey chunklist_pubkeys[] = { -}; - -#define CHUNKLIST_NPUBKEYS (sizeof(chunklist_pubkeys)/sizeof(chunklist_pubkeys[0])) - -#endif +int authenticate_root_with_chunklist(const char *rootdmg_path, boolean_t *out_enforced); +int authenticate_root_version_check(void); +int authenticate_bootkc_uuid(void); +int authenticate_libkern_uuid(void); +#endif /* _CHUNKLIST_H */