#ifndef _SECURITYD_SECDBITEM_H_
#define _SECURITYD_SECDBITEM_H_
#include <CoreFoundation/CoreFoundation.h>
#include <TargetConditionals.h>
#include <corecrypto/ccsha1.h> // For CCSHA1_OUTPUT_SIZE
#include <sqlite3.h>
#include <utilities/SecCFError.h>
#include <utilities/SecCFWrappers.h>
#include <utilities/SecDb.h>
#include <utilities/SecAKSWrappers.h>
#if TARGET_OS_MAC && !(TARGET_OS_EMBEDDED || TARGET_IPHONE_SIMULATOR)
#define USE_KEYSTORE 1
#elif TARGET_OS_EMBEDDED && !TARGET_IPHONE_SIMULATOR
#define USE_KEYSTORE 1
#else
#define USE_KEYSTORE 0
#endif
#if USE_KEYSTORE
#include <Kernel/IOKit/crypto/AppleKeyStoreDefs.h>
#endif
__BEGIN_DECLS
#if USE_KEYSTORE
typedef int32_t keyclass_t;
#else
#define kAppleKeyStoreKeyWrap 0
#define kAppleKeyStoreKeyUnwrap 1
typedef int32_t keyclass_t;
typedef int32_t key_handle_t;
enum key_classes {
key_class_ak = 6,
key_class_ck,
key_class_dk,
key_class_aku,
key_class_cku,
key_class_dku
};
#endif
typedef enum {
kSecDbBlobAttr, kSecDbDataAttr,
kSecDbStringAttr,
kSecDbNumberAttr,
kSecDbDateAttr,
kSecDbCreationDateAttr,
kSecDbModificationDateAttr,
kSecDbSHA1Attr,
kSecDbRowIdAttr,
kSecDbEncryptedDataAttr,
kSecDbPrimaryKeyAttr,
kSecDbSyncAttr,
kSecDbTombAttr,
kSecDbAccessAttr
} SecDbAttrKind;
enum {
kSecDbPrimaryKeyFlag = (1 << 0), kSecDbInFlag = (1 << 1), kSecDbIndexFlag = (1 << 2), kSecDbSHA1ValueInFlag = (1 << 3), kSecDbReturnAttrFlag = (1 << 4),
kSecDbReturnDataFlag = (1 << 5),
kSecDbReturnRefFlag = (1 << 6),
kSecDbInCryptoDataFlag = (1 << 7),
kSecDbInHashFlag = (1 << 8),
kSecDbInBackupFlag = (1 << 9),
kSecDbDefault0Flag = (1 << 10), kSecDbDefaultEmptyFlag = (1 << 11), kSecDbNotNullFlag = (1 << 12), };
#define SecVersionDbFlag(v) ((v & 0xFF) << 8)
#define SecDbFlagGetVersion(flags) ((flags >> 8) & 0xFF)
#define SECDB_ATTR(var, name, kind, flags) const SecDbAttr var = { CFSTR(name), kSecDb ## kind ## Attr, flags }
typedef struct SecDbAttr {
CFStringRef name;
SecDbAttrKind kind;
CFOptionFlags flags;
} SecDbAttr;
typedef struct SecDbClass {
CFStringRef name;
const SecDbAttr *attrs[];
} SecDbClass;
typedef struct Pair *SecDbPairRef;
typedef struct Query *SecDbQueryRef;
typedef uint32_t ReturnTypeMask;
enum
{
kSecReturnDataMask = 1 << 0,
kSecReturnAttributesMask = 1 << 1,
kSecReturnRefMask = 1 << 2,
kSecReturnPersistentRefMask = 1 << 3,
};
enum
{
kSecMatchUnlimited = kCFNotFound
};
typedef struct Pair
{
const void *key;
const void *value;
} Pair;
typedef struct Query
{
const SecDbClass *q_class;
CFMutableDictionaryRef q_item;
CFIndex q_match_begin;
CFIndex q_match_end;
CFIndex q_attr_end;
CFErrorRef q_error;
ReturnTypeMask q_return_type;
CFDataRef q_data;
CFTypeRef q_ref;
sqlite_int64 q_row_id;
CFArrayRef q_use_item_list;
CFBooleanRef q_use_tomb;
#if defined(MULTIPLE_KEYCHAINS)
CFArrayRef q_use_keychain;
CFArrayRef q_use_keychain_list;
#endif
CFIndex q_limit;
bool q_sync;
bool q_changed;
bool q_sync_changed;
keybag_handle_t q_keybag;
keyclass_t q_keyclass;
CFDataRef q_primary_key_digest;
CFArrayRef q_match_issuer;
CFMutableArrayRef corrupted_rows;
Pair q_pairs[];
} Query;
#define SecDbForEachAttr(class, attr) for (const SecDbAttr * const* _pattr = (class)->attrs, *attr = *_pattr; attr; attr = *(++_pattr))
#define SecDbForEachAttrWithMask(class, attr, flag_mask) SecDbForEachAttr(class, attr) if ((attr->flags & (flag_mask)) == (flag_mask))
bool ks_encrypt_data(keybag_handle_t keybag, keyclass_t keyclass, CFDataRef plainText, CFDataRef *pBlob, CFErrorRef *error);
bool ks_decrypt_data(keybag_handle_t keybag, keyclass_t *pkeyclass, CFDataRef blob, CFDataRef *pPlainText,
uint32_t *version_p, CFErrorRef *error);
CFDataRef kc_copy_sha1(size_t len, const void *data, CFErrorRef *error);
CFDataRef kc_copy_plist_sha1(CFPropertyListRef plist, CFErrorRef *error);
CFDataRef kc_plist_copy_der(CFPropertyListRef plist, CFErrorRef *error);
Query *query_create(const SecDbClass *qclass, CFDictionaryRef query, CFErrorRef *error);
bool query_destroy(Query *q, CFErrorRef *error);
typedef struct SecDbItem *SecDbItemRef;
enum SecDbItemState {
kSecDbItemDirty, kSecDbItemEncrypted, kSecDbItemClean, kSecDbItemDecrypting, kSecDbItemEncrypting, };
struct SecDbItem {
CFRuntimeBase _base;
const SecDbClass *class;
keyclass_t keyclass;
keybag_handle_t keybag;
enum SecDbItemState _edataState;
CFMutableDictionaryRef attributes;
};
bool SecDbItemDecrypt(SecDbItemRef item, CFDataRef edata, CFErrorRef *error);
CFTypeID SecDbItemGetTypeID(void);
static inline size_t SecDbClassAttrCount(const SecDbClass *dbClass) {
size_t n_attrs = 0;
SecDbForEachAttr(dbClass, attr) { n_attrs++; }
return n_attrs;
}
const SecDbAttr *SecDbClassAttrWithKind(const SecDbClass *class, SecDbAttrKind kind, CFErrorRef *error);
SecDbItemRef SecDbItemCreateWithAttributes(CFAllocatorRef allocator, const SecDbClass *class, CFDictionaryRef attributes, keybag_handle_t keybag, CFErrorRef *error);
const SecDbClass *SecDbItemGetClass(SecDbItemRef item);
const keybag_handle_t SecDbItemGetKeybag(SecDbItemRef item);
bool SecDbItemSetKeybag(SecDbItemRef item, keybag_handle_t keybag, CFErrorRef *error);
keyclass_t SecDbItemGetKeyclass(SecDbItemRef item, CFErrorRef *error);
bool SecDbItemSetKeyclass(SecDbItemRef item, keyclass_t keyclass, CFErrorRef *error);
CFTypeRef SecDbItemGetCachedValueWithName(SecDbItemRef item, CFStringRef name);
CF_RETURNS_NOT_RETAINED CFTypeRef SecDbItemGetValue(SecDbItemRef item, const SecDbAttr *desc, CFErrorRef *error);
bool SecDbItemSetValue(SecDbItemRef item, const SecDbAttr *desc, CFTypeRef value, CFErrorRef *error);
bool SecDbItemSetValues(SecDbItemRef item, CFDictionaryRef values, CFErrorRef *error);
bool SecDbItemSetValueWithName(SecDbItemRef item, CFStringRef name, CFTypeRef value, CFErrorRef *error);
sqlite3_int64 SecDbItemGetRowId(SecDbItemRef item, CFErrorRef *error);
bool SecDbItemSetRowId(SecDbItemRef item, sqlite3_int64 rowid, CFErrorRef *error);
bool SecDbItemIsSyncable(SecDbItemRef item);
bool SecDbItemSetSyncable(SecDbItemRef item, bool sync, CFErrorRef *error);
bool SecDbItemIsTombstone(SecDbItemRef item);
CFMutableDictionaryRef SecDbItemCopyPListWithMask(SecDbItemRef item, CFOptionFlags mask, CFErrorRef *error);
CFDataRef SecDbItemGetPrimaryKey(SecDbItemRef item, CFErrorRef *error);
CFDataRef SecDbItemGetSHA1(SecDbItemRef item, CFErrorRef *error);
CFDataRef SecDbItemCopyEncryptedDataToBackup(SecDbItemRef item, uint64_t handle, CFErrorRef *error);
SecDbItemRef SecDbItemCreateWithStatement(CFAllocatorRef allocator, const SecDbClass *class, sqlite3_stmt *stmt, keybag_handle_t keybag, CFErrorRef *error, bool (^return_attr)(const SecDbAttr *attr));
SecDbItemRef SecDbItemCreateWithEncryptedData(CFAllocatorRef allocator, const SecDbClass *class,
CFDataRef edata, keybag_handle_t keybag, CFErrorRef *error);
SecDbItemRef SecDbItemCreateWithPrimaryKey(CFAllocatorRef allocator, const SecDbClass *class, CFDataRef primary_key);
#if 0
SecDbItemRef SecDbItemCreateWithRowId(CFAllocatorRef allocator, const SecDbClass *class, sqlite_int64 row_id, keybag_handle_t keybag, CFErrorRef *error);
#endif
SecDbItemRef SecDbItemCopyWithUpdates(SecDbItemRef item, CFDictionaryRef updates, CFErrorRef *error);
SecDbItemRef SecDbItemCopyTombstone(SecDbItemRef item, CFErrorRef *error);
bool SecDbItemInsertOrReplace(SecDbItemRef item, SecDbConnectionRef dbconn, CFErrorRef *error, void(^duplicate)(SecDbItemRef item, SecDbItemRef *replace));
bool SecDbItemInsert(SecDbItemRef item, SecDbConnectionRef dbconn, CFErrorRef *error);
bool SecDbItemDelete(SecDbItemRef item, SecDbConnectionRef dbconn, bool makeTombstone, CFErrorRef *error);
bool SecDbItemDoUpdate(SecDbItemRef old_item, SecDbItemRef new_item, SecDbConnectionRef dbconn, CFErrorRef *error, bool (^use_attr_in_where)(const SecDbAttr *attr));
bool SecDbItemUpdate(SecDbItemRef old_item, SecDbItemRef new_item, SecDbConnectionRef dbconn, bool makeTombstone, CFErrorRef *error);
bool SecDbItemSelect(SecDbQueryRef query, SecDbConnectionRef dbconn, CFErrorRef *error,
bool (^use_attr_in_where)(const SecDbAttr *attr),
bool (^add_where_sql)(CFMutableStringRef sql, bool *needWhere),
bool (^bind_added_where)(sqlite3_stmt *stmt, int col),
void (^handle_row)(SecDbItemRef item, bool *stop));
CFStringRef SecDbItemCopySelectSQL(SecDbQueryRef query,
bool (^return_attr)(const SecDbAttr *attr),
bool (^use_attr_in_where)(const SecDbAttr *attr),
bool (^add_where_sql)(CFMutableStringRef sql, bool *needWhere));
bool SecDbItemSelectBind(SecDbQueryRef query, sqlite3_stmt *stmt, CFErrorRef *error,
bool (^use_attr_in_where)(const SecDbAttr *attr),
bool (^bind_added_where)(sqlite3_stmt *stmt, int col));
void SecDbAppendElement(CFMutableStringRef sql, CFStringRef value, bool *needComma);
void SecDbAppendWhereOrAnd(CFMutableStringRef sql, bool *needWhere);
void SecDbAppendWhereOrAndEquals(CFMutableStringRef sql, CFStringRef col, bool *needWhere);
typedef struct SecItemDb *SecItemDbRef;
typedef struct SecItemDbConnection *SecItemDbConnectionRef;
struct SecItemDb {
CFRuntimeBase _base;
SecDbRef db;
CFDictionaryRef classes; };
struct SecItemDbConnection {
SecDbConnectionRef db;
};
SecItemDbRef SecItemDbCreate(SecDbRef db);
SecItemDbRef SecItemDbRegisterClass(SecItemDbRef db, const SecDbClass *class, void(^upgrade)(SecDbItemRef item, uint32_t current_version));
SecItemDbConnectionRef SecItemDbAquireConnection(SecItemDbRef db);
void SecItemDbReleaseConnection(SecItemDbRef db, SecItemDbConnectionRef dbconn);
bool SecItemDbInsert(SecItemDbConnectionRef dbconn, SecDbItemRef item, CFErrorRef *error);
bool SecItemDbDelete(SecItemDbConnectionRef dbconn, SecDbItemRef item, CFErrorRef *error);
bool SecItemDbDoUpdate(SecItemDbConnectionRef dbconn, SecDbItemRef old_item, SecDbItemRef new_item, CFErrorRef *error,
bool (^use_attr_in_where)(const SecDbAttr *attr));
bool SecItemDbUpdate(SecItemDbConnectionRef dbconn, SecDbItemRef old_item, SecDbItemRef new_item, CFErrorRef *error);
bool SecItemDbSelect(SecItemDbConnectionRef dbconn, SecDbQueryRef query, CFErrorRef *error,
bool (^use_attr_in_where)(const SecDbAttr *attr),
bool (^add_where_sql)(CFMutableStringRef sql, bool *needWhere),
bool (^bind_added_where)(sqlite3_stmt *stmt, int col),
void (^handle_row)(SecDbItemRef item, bool *stop));
CFStringRef copyString(CFTypeRef obj);
CFDataRef copyData(CFTypeRef obj);
CFTypeRef copyBlob(CFTypeRef obj);
CFDataRef copySHA1(CFTypeRef obj);
CFTypeRef copyNumber(CFTypeRef obj);
CFDateRef copyDate(CFTypeRef obj);
__END_DECLS
#endif