authorization_set.cpp revision f21afff128ac22479c49bdda84f13335ae17d009
15ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden/* 25ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * Copyright (C) 2014 The Android Open Source Project 35ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * 45ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * Licensed under the Apache License, Version 2.0 (the "License"); 55ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * you may not use this file except in compliance with the License. 65ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * You may obtain a copy of the License at 75ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * 85ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * http://www.apache.org/licenses/LICENSE-2.0 95ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * 105ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * Unless required by applicable law or agreed to in writing, software 115ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * distributed under the License is distributed on an "AS IS" BASIS, 125ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 135ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * See the License for the specific language governing permissions and 145ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden * limitations under the License. 155ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden */ 165ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 170f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden#include <keymaster/authorization_set.h> 180f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden 190f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden#include <assert.h> 20f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden#include <stddef.h> 215ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden#include <stdlib.h> 225ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden#include <string.h> 235ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 240f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden#include <new> 255ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 26b6837e7a62a1192e33beef586282812239ee8b28Shawn Willden#include <keymaster/android_keymaster_utils.h> 27f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden#include <keymaster/logger.h> 285ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 295ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdennamespace keymaster { 305ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 315ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenstatic inline bool is_blob_tag(keymaster_tag_t tag) { 325ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return (keymaster_tag_get_type(tag) == KM_BYTES || keymaster_tag_get_type(tag) == KM_BIGNUM); 335ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 345ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 355ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenconst size_t STARTING_ELEMS_CAPACITY = 8; 365ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 372c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn WilldenAuthorizationSet::AuthorizationSet(AuthorizationSetBuilder& builder) { 382c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden elems_ = builder.set.elems_; 392c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.elems_ = NULL; 402c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 412c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden elems_size_ = builder.set.elems_size_; 422c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.elems_size_ = 0; 432c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 442c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden elems_capacity_ = builder.set.elems_capacity_; 452c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.elems_capacity_ = 0; 462c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 472c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden indirect_data_ = builder.set.indirect_data_; 482c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.indirect_data_ = NULL; 492c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 502c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden indirect_data_capacity_ = builder.set.indirect_data_capacity_; 512c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.indirect_data_capacity_ = 0; 522c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 532c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden indirect_data_size_ = builder.set.indirect_data_size_; 542c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.indirect_data_size_ = 0; 552c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 562c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden error_ = builder.set.error_; 572c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden builder.set.error_ = OK; 582c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden} 592c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 608d336ae10df66da4c0433f17c2d42e85baea32c5Shawn WilldenAuthorizationSet::~AuthorizationSet() { 618d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden FreeData(); 628d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden} 6358e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden 64370121346777e13437c275fbe7a975d899cc325cShawn Willdenbool AuthorizationSet::reserve_elems(size_t count) { 65437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() != OK) 66437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden return false; 67437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden 68370121346777e13437c275fbe7a975d899cc325cShawn Willden if (count >= elems_capacity_) { 690f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden keymaster_key_param_t* new_elems = new (std::nothrow) keymaster_key_param_t[count]; 70370121346777e13437c275fbe7a975d899cc325cShawn Willden if (new_elems == NULL) { 71370121346777e13437c275fbe7a975d899cc325cShawn Willden set_invalid(ALLOCATION_FAILURE); 72370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 73370121346777e13437c275fbe7a975d899cc325cShawn Willden } 74370121346777e13437c275fbe7a975d899cc325cShawn Willden memcpy(new_elems, elems_, sizeof(*elems_) * elems_size_); 75370121346777e13437c275fbe7a975d899cc325cShawn Willden delete[] elems_; 76370121346777e13437c275fbe7a975d899cc325cShawn Willden elems_ = new_elems; 77370121346777e13437c275fbe7a975d899cc325cShawn Willden elems_capacity_ = count; 78370121346777e13437c275fbe7a975d899cc325cShawn Willden } 79370121346777e13437c275fbe7a975d899cc325cShawn Willden return true; 80370121346777e13437c275fbe7a975d899cc325cShawn Willden} 81370121346777e13437c275fbe7a975d899cc325cShawn Willden 82370121346777e13437c275fbe7a975d899cc325cShawn Willdenbool AuthorizationSet::reserve_indirect(size_t length) { 83437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() != OK) 84437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden return false; 85437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden 86370121346777e13437c275fbe7a975d899cc325cShawn Willden if (length > indirect_data_capacity_) { 87c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden uint8_t* new_data = new (std::nothrow) uint8_t[length]; 88370121346777e13437c275fbe7a975d899cc325cShawn Willden if (new_data == NULL) { 89370121346777e13437c275fbe7a975d899cc325cShawn Willden set_invalid(ALLOCATION_FAILURE); 90370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 91370121346777e13437c275fbe7a975d899cc325cShawn Willden } 92370121346777e13437c275fbe7a975d899cc325cShawn Willden memcpy(new_data, indirect_data_, indirect_data_size_); 93370121346777e13437c275fbe7a975d899cc325cShawn Willden 94370121346777e13437c275fbe7a975d899cc325cShawn Willden // Fix up the data pointers to point into the new region. 95370121346777e13437c275fbe7a975d899cc325cShawn Willden for (size_t i = 0; i < elems_size_; ++i) { 96370121346777e13437c275fbe7a975d899cc325cShawn Willden if (is_blob_tag(elems_[i].tag)) 97370121346777e13437c275fbe7a975d899cc325cShawn Willden elems_[i].blob.data = new_data + (elems_[i].blob.data - indirect_data_); 98370121346777e13437c275fbe7a975d899cc325cShawn Willden } 99370121346777e13437c275fbe7a975d899cc325cShawn Willden delete[] indirect_data_; 100370121346777e13437c275fbe7a975d899cc325cShawn Willden indirect_data_ = new_data; 101370121346777e13437c275fbe7a975d899cc325cShawn Willden indirect_data_capacity_ = length; 102370121346777e13437c275fbe7a975d899cc325cShawn Willden } 103370121346777e13437c275fbe7a975d899cc325cShawn Willden return true; 104370121346777e13437c275fbe7a975d899cc325cShawn Willden} 105370121346777e13437c275fbe7a975d899cc325cShawn Willden 1065ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::Reinitialize(const keymaster_key_param_t* elems, const size_t count) { 1075ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden FreeData(); 1085ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 109b58dcde804dc9f69f89c620592b910083f32b01cShawn Willden if (elems == NULL || count == 0) { 110b58dcde804dc9f69f89c620592b910083f32b01cShawn Willden error_ = OK; 111b58dcde804dc9f69f89c620592b910083f32b01cShawn Willden return true; 112b58dcde804dc9f69f89c620592b910083f32b01cShawn Willden } 113b58dcde804dc9f69f89c620592b910083f32b01cShawn Willden 114370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!reserve_elems(count)) 115370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 1165ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 117370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!reserve_indirect(ComputeIndirectDataSize(elems, count))) 1185ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 1195ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 120370121346777e13437c275fbe7a975d899cc325cShawn Willden memcpy(elems_, elems, sizeof(keymaster_key_param_t) * count); 121370121346777e13437c275fbe7a975d899cc325cShawn Willden elems_size_ = count; 1225ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden CopyIndirectData(); 123370121346777e13437c275fbe7a975d899cc325cShawn Willden error_ = OK; 1245ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 1255ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 1265ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 1275ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenvoid AuthorizationSet::set_invalid(Error error) { 1285ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden FreeData(); 129370121346777e13437c275fbe7a975d899cc325cShawn Willden error_ = error; 1305ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 1315ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 132f21afff128ac22479c49bdda84f13335ae17d009Shawn Willdenvoid AuthorizationSet::Sort() { 1332c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden qsort(elems_, elems_size_, sizeof(*elems_), 1342c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden reinterpret_cast<int (*)(const void*, const void*)>(keymaster_param_compare)); 135f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden} 136f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden 137f21afff128ac22479c49bdda84f13335ae17d009Shawn Willdenvoid AuthorizationSet::Deduplicate() { 138f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden Sort(); 1392c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 1402c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden size_t invalid_count = 0; 1412c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden for (size_t i = 1; i < size(); ++i) { 1422c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden if (elems_[i - 1].tag == KM_TAG_INVALID) 1432c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden ++invalid_count; 1442c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden else if (keymaster_param_compare(elems_ + i - 1, elems_ + i) == 0) { 1452c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden // Mark dups as invalid. Note that this "leaks" the data referenced by KM_BYTES and 1462c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden // KM_BIGNUM entries, but those are just pointers into indirect_data_, so it will all 1472c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden // get cleaned up. 1482c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden elems_[i - 1].tag = KM_TAG_INVALID; 1492c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden ++invalid_count; 1502c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden } 1512c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden } 1522c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden if (size() > 0 && elems_[size() - 1].tag == KM_TAG_INVALID) 1532c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden ++invalid_count; 1542c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 1552c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden if (invalid_count == 0) 1562c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden return; 1572c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 158f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden Sort(); 159f21afff128ac22479c49bdda84f13335ae17d009Shawn Willden 1602c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden // Since KM_TAG_INVALID == 0, all of the invalid entries are first. 1612c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden elems_size_ -= invalid_count; 1622c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden memmove(elems_, elems_ + invalid_count, size() * sizeof(*elems_)); 1632c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden} 1642c242009007a38b5c8003137fb8ba5a1fdb73b70Shawn Willden 165cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willdenvoid AuthorizationSet::CopyToParamSet(keymaster_key_param_set_t* set) const { 166cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden assert(set); 167cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden 168cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden set->length = size(); 169cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden set->params = 170cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden reinterpret_cast<keymaster_key_param_t*>(malloc(sizeof(keymaster_key_param_t) * size())); 171cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden 172cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden for (size_t i = 0; i < size(); ++i) { 173cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden const keymaster_key_param_t src = (*this)[i]; 174cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden keymaster_key_param_t& dst(set->params[i]); 175cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden 176cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden dst = src; 177cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden keymaster_tag_type_t type = keymaster_tag_get_type(src.tag); 178cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden if (type == KM_BIGNUM || type == KM_BYTES) { 179cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden void* tmp = malloc(src.blob.data_length); 180cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden memcpy(tmp, src.blob.data, src.blob.data_length); 181cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden dst.blob.data = reinterpret_cast<uint8_t*>(tmp); 182cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden } 183cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden } 184cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden} 185cb0d64b02d0df2b9eb692c5b0ea5c36db1000e9aShawn Willden 1865ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenint AuthorizationSet::find(keymaster_tag_t tag, int begin) const { 187437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() != OK) 188437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden return -1; 189437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden 1905ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int i = ++begin; 1918d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden while (i < (int)elems_size_ && elems_[i].tag != tag) 1928d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden ++i; 1935ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (i == (int)elems_size_) 1945ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return -1; 1955ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden else 1965ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return i; 1975ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 1985ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 1995ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenkeymaster_key_param_t empty; 200d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willdenkeymaster_key_param_t& AuthorizationSet::operator[](int at) { 201d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden if (is_valid() == OK && at < (int)elems_size_) { 202d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden return elems_[at]; 203d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden } 204d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden memset(&empty, 0, sizeof(empty)); 205d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden return empty; 206d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden} 207d599b15c0693950bdc72fb867872044fdc484ef5Shawn Willden 2085ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenkeymaster_key_param_t AuthorizationSet::operator[](int at) const { 209437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() == OK && at < (int)elems_size_) { 2108d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return elems_[at]; 2115ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 2125ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden memset(&empty, 0, sizeof(empty)); 2135ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return empty; 2145ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 2155ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 216b5508298cdb1d42eaf8c81aa8a6ac2cbfdeef3c7Shawn Willdenbool AuthorizationSet::push_back(const keymaster_key_param_set_t& set) { 217437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() != OK) 218437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden return false; 219437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden 220b5508298cdb1d42eaf8c81aa8a6ac2cbfdeef3c7Shawn Willden if (!reserve_elems(elems_size_ + set.length)) 221370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 222370121346777e13437c275fbe7a975d899cc325cShawn Willden 223b5508298cdb1d42eaf8c81aa8a6ac2cbfdeef3c7Shawn Willden if (!reserve_indirect(indirect_data_size_ + ComputeIndirectDataSize(set.params, set.length))) 224370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 225370121346777e13437c275fbe7a975d899cc325cShawn Willden 226b5508298cdb1d42eaf8c81aa8a6ac2cbfdeef3c7Shawn Willden for (size_t i = 0; i < set.length; ++i) 227b5508298cdb1d42eaf8c81aa8a6ac2cbfdeef3c7Shawn Willden if (!push_back(set.params[i])) 228370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 229370121346777e13437c275fbe7a975d899cc325cShawn Willden 230370121346777e13437c275fbe7a975d899cc325cShawn Willden return true; 231370121346777e13437c275fbe7a975d899cc325cShawn Willden} 232370121346777e13437c275fbe7a975d899cc325cShawn Willden 2335ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::push_back(keymaster_key_param_t elem) { 234437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden if (is_valid() != OK) 235437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden return false; 236437fbd195e7de57b7dc0c449c04458bd90ef50deShawn Willden 237370121346777e13437c275fbe7a975d899cc325cShawn Willden if (elems_size_ >= elems_capacity_) 238370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!reserve_elems(elems_capacity_ ? elems_capacity_ * 2 : STARTING_ELEMS_CAPACITY)) 2395ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 2405ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 2415ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (is_blob_tag(elem.tag)) { 242370121346777e13437c275fbe7a975d899cc325cShawn Willden if (indirect_data_capacity_ - indirect_data_size_ < elem.blob.data_length) 243370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!reserve_indirect(2 * (indirect_data_capacity_ + elem.blob.data_length))) 2445ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 24558e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden 2465ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden memcpy(indirect_data_ + indirect_data_size_, elem.blob.data, elem.blob.data_length); 2478d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden elem.blob.data = indirect_data_ + indirect_data_size_; 2485ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden indirect_data_size_ += elem.blob.data_length; 2495ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 2505ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 2515ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden elems_[elems_size_++] = elem; 2525ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 2535ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 2545ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 2558d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willdenstatic size_t serialized_size(const keymaster_key_param_t& param) { 2568d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden switch (keymaster_tag_get_type(param.tag)) { 2578d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_INVALID: 2588d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t); 2598d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM: 2608d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM_REP: 261c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT: 262c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT_REP: 2638d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t) * 2; 264c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG: 265c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG_REP: 2668d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_DATE: 2678d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t) + sizeof(uint64_t); 2688d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BOOL: 2698d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t) + 1; 2708d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BIGNUM: 2718d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BYTES: 2728d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t) * 3; 2738d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 27482114e7cbf97f65348d32b2685dd52427525146dShawn Willden 27582114e7cbf97f65348d32b2685dd52427525146dShawn Willden return sizeof(uint32_t); 2768d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden} 2778d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 2788d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willdenstatic uint8_t* serialize(const keymaster_key_param_t& param, uint8_t* buf, const uint8_t* end, 2798d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden const uint8_t* indirect_base) { 280172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, param.tag); 2818d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden switch (keymaster_tag_get_type(param.tag)) { 2828d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_INVALID: 2838d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 2848d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM: 2858d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM_REP: 286172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, param.enumerated); 2878d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 288c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT: 289c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT_REP: 290172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, param.integer); 2918d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 292c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG: 293c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG_REP: 294172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint64_to_buf(buf, end, param.long_integer); 2958d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 2968d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_DATE: 297172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint64_to_buf(buf, end, param.date_time); 2988d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 2998d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BOOL: 3008d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden if (buf < end) 3018d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden *buf = static_cast<uint8_t>(param.boolean); 3028d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden buf++; 3038d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 3048d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BIGNUM: 3058d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BYTES: 306172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, param.blob.data_length); 307172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, param.blob.data - indirect_base); 3088d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 3098d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 3108d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return buf; 3118d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden} 3128d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 313172f8c9be706e27f43022063bbc7f4b0177583acShawn Willdenstatic bool deserialize(keymaster_key_param_t* param, const uint8_t** buf_ptr, const uint8_t* end, 3148d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden const uint8_t* indirect_base, const uint8_t* indirect_end) { 315172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden if (!copy_uint32_from_buf(buf_ptr, end, ¶m->tag)) 3168d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 3178d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 3188d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden switch (keymaster_tag_get_type(param->tag)) { 3198d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_INVALID: 3208d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 3218d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM: 3228d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_ENUM_REP: 323172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden return copy_uint32_from_buf(buf_ptr, end, ¶m->enumerated); 324c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT: 325c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_UINT_REP: 326172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden return copy_uint32_from_buf(buf_ptr, end, ¶m->integer); 327c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG: 328c3ac84f04c4d6d74fa36abfd1cc2e5ac763a8af3Shawn Willden case KM_ULONG_REP: 329172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden return copy_uint64_from_buf(buf_ptr, end, ¶m->long_integer); 3308d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_DATE: 331172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden return copy_uint64_from_buf(buf_ptr, end, ¶m->date_time); 3328d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden break; 3338d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BOOL: 334172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden if (*buf_ptr < end) { 335172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden param->boolean = static_cast<bool>(**buf_ptr); 336172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden (*buf_ptr)++; 3378d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return true; 3388d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 3398d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 3408d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 3418d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BIGNUM: 3428d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden case KM_BYTES: { 3438d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden uint32_t offset; 344172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden if (!copy_uint32_from_buf(buf_ptr, end, ¶m->blob.data_length) || 345172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden !copy_uint32_from_buf(buf_ptr, end, &offset)) 3468d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 34728f2e72909a73788cf636b637f7403984ede3b74Shawn Willden if (param->blob.data_length + offset < param->blob.data_length || // Overflow check 34828f2e72909a73788cf636b637f7403984ede3b74Shawn Willden static_cast<ptrdiff_t>(offset) > indirect_end - indirect_base || 349172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden static_cast<ptrdiff_t>(offset + param->blob.data_length) > indirect_end - indirect_base) 3508d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 3518d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden param->blob.data = indirect_base + offset; 3528d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return true; 3538d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 3548d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 35582114e7cbf97f65348d32b2685dd52427525146dShawn Willden 35682114e7cbf97f65348d32b2685dd52427525146dShawn Willden return false; 3578d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden} 3588d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 3598d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willdensize_t AuthorizationSet::SerializedSizeOfElements() const { 3608d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden size_t size = 0; 3618d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden for (size_t i = 0; i < elems_size_; ++i) { 3628d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden size += serialized_size(elems_[i]); 3638d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 3648d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return size; 3658d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden} 3668d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden 36758e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willdensize_t AuthorizationSet::SerializedSize() const { 3688d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return sizeof(uint32_t) + // Size of indirect_data_ 3698d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden indirect_data_size_ + // indirect_data_ 3708d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden sizeof(uint32_t) + // Number of elems_ 3718d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden sizeof(uint32_t) + // Size of elems_ 3728d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden SerializedSizeOfElements(); // elems_ 3735ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 3745ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 3758d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willdenuint8_t* AuthorizationSet::Serialize(uint8_t* buf, const uint8_t* end) const { 3768d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden buf = append_size_and_data_to_buf(buf, end, indirect_data_, indirect_data_size_); 377172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, elems_size_); 378172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden buf = append_uint32_to_buf(buf, end, SerializedSizeOfElements()); 3798d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden for (size_t i = 0; i < elems_size_; ++i) { 3808d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden buf = serialize(elems_[i], buf, end, indirect_data_); 3818d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 3828d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return buf; 3835ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 3845ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 385370121346777e13437c275fbe7a975d899cc325cShawn Willdenbool AuthorizationSet::DeserializeIndirectData(const uint8_t** buf_ptr, const uint8_t* end) { 386f2282b3c6690ccfaa7878886f01693ef4f0b3bedShawn Willden UniquePtr<uint8_t[]> indirect_buf; 387f2282b3c6690ccfaa7878886f01693ef4f0b3bedShawn Willden if (!copy_size_and_data_from_buf(buf_ptr, end, &indirect_data_size_, &indirect_buf)) { 388f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden LOG_E("Malformed data found in AuthorizationSet deserialization", 0); 389370121346777e13437c275fbe7a975d899cc325cShawn Willden set_invalid(MALFORMED_DATA); 390370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 391370121346777e13437c275fbe7a975d899cc325cShawn Willden } 392f2282b3c6690ccfaa7878886f01693ef4f0b3bedShawn Willden indirect_data_ = indirect_buf.release(); 393370121346777e13437c275fbe7a975d899cc325cShawn Willden return true; 394370121346777e13437c275fbe7a975d899cc325cShawn Willden} 3955ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 396370121346777e13437c275fbe7a975d899cc325cShawn Willdenbool AuthorizationSet::DeserializeElementsData(const uint8_t** buf_ptr, const uint8_t* end) { 3978d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden uint32_t elements_count; 3988d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden uint32_t elements_size; 399370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!copy_uint32_from_buf(buf_ptr, end, &elements_count) || 400172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden !copy_uint32_from_buf(buf_ptr, end, &elements_size)) { 401f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden LOG_E("Malformed data found in AuthorizationSet deserialization", 0); 40258e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden set_invalid(MALFORMED_DATA); 4035ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 4045ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 4055ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 406834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden // Note that the following validation of elements_count is weak, but it prevents allocation of 407834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden // elems_ arrays which are clearly too large to be reasonable. 40862de26672193373972f2ce968b51cf8335f118f9Shawn Willden if (static_cast<ptrdiff_t>(elements_size) > end - *buf_ptr || 4090f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden elements_count * sizeof(uint32_t) > elements_size || 4100f906ec40f6ade7955c6b967ea522aade54ea2e4Shawn Willden *buf_ptr + (elements_count * sizeof(*elems_)) < *buf_ptr) { 411f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden LOG_E("Malformed data found in AuthorizationSet deserialization", 0); 412834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden set_invalid(MALFORMED_DATA); 413834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden return false; 414834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden } 415834e80747cbb960f8a4028c5c8604bf5218ecdb9Shawn Willden 416370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!reserve_elems(elements_count)) 4175ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 4185ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 4198d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden uint8_t* indirect_end = indirect_data_ + indirect_data_size_; 420172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden const uint8_t* elements_end = *buf_ptr + elements_size; 4218d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden for (size_t i = 0; i < elements_count; ++i) { 422172f8c9be706e27f43022063bbc7f4b0177583acShawn Willden if (!deserialize(elems_ + i, buf_ptr, elements_end, indirect_data_, indirect_end)) { 423f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden LOG_E("Malformed data found in AuthorizationSet deserialization", 0); 4248d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden set_invalid(MALFORMED_DATA); 4258d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return false; 4268d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden } 42758e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden } 428370121346777e13437c275fbe7a975d899cc325cShawn Willden elems_size_ = elements_count; 429370121346777e13437c275fbe7a975d899cc325cShawn Willden return true; 430370121346777e13437c275fbe7a975d899cc325cShawn Willden} 4315ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 432370121346777e13437c275fbe7a975d899cc325cShawn Willdenbool AuthorizationSet::Deserialize(const uint8_t** buf_ptr, const uint8_t* end) { 433370121346777e13437c275fbe7a975d899cc325cShawn Willden FreeData(); 434370121346777e13437c275fbe7a975d899cc325cShawn Willden 435370121346777e13437c275fbe7a975d899cc325cShawn Willden if (!DeserializeIndirectData(buf_ptr, end) || !DeserializeElementsData(buf_ptr, end)) 436370121346777e13437c275fbe7a975d899cc325cShawn Willden return false; 437370121346777e13437c275fbe7a975d899cc325cShawn Willden 438370121346777e13437c275fbe7a975d899cc325cShawn Willden if (indirect_data_size_ != ComputeIndirectDataSize(elems_, elems_size_)) { 439f01329d8692edde9a9ffb88f29f5d684eab481e2Shawn Willden LOG_E("Malformed data found in AuthorizationSet deserialization", 0); 4408d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden set_invalid(MALFORMED_DATA); 4415ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 4425ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 4438d336ae10df66da4c0433f17c2d42e85baea32c5Shawn Willden return true; 4445ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 4455ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 446941d1c4ad4422a796d90010191c11aef0580295eShawn Willdenvoid AuthorizationSet::Clear() { 4471834d5f82a7ad5884c184fd22c702ac9d915af45Shawn Willden memset_s(elems_, 0, elems_size_ * sizeof(keymaster_key_param_t)); 4481834d5f82a7ad5884c184fd22c702ac9d915af45Shawn Willden memset_s(indirect_data_, 0, indirect_data_size_); 449941d1c4ad4422a796d90010191c11aef0580295eShawn Willden elems_size_ = 0; 450941d1c4ad4422a796d90010191c11aef0580295eShawn Willden indirect_data_size_ = 0; 451941d1c4ad4422a796d90010191c11aef0580295eShawn Willden} 452941d1c4ad4422a796d90010191c11aef0580295eShawn Willden 453941d1c4ad4422a796d90010191c11aef0580295eShawn Willdenvoid AuthorizationSet::FreeData() { 454941d1c4ad4422a796d90010191c11aef0580295eShawn Willden Clear(); 45558e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden 45658e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden delete[] elems_; 45758e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden delete[] indirect_data_; 45858e1a5486219a1be9264d4e863a9dd3e393906c3Shawn Willden 4595ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden elems_ = NULL; 4605ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden indirect_data_ = NULL; 4615ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden elems_capacity_ = 0; 4625ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden indirect_data_capacity_ = 0; 463370121346777e13437c275fbe7a975d899cc325cShawn Willden error_ = OK; 4645ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 4655ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 4665ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden/* static */ 4675ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdensize_t AuthorizationSet::ComputeIndirectDataSize(const keymaster_key_param_t* elems, size_t count) { 4685ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden size_t size = 0; 4695ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden for (size_t i = 0; i < count; ++i) { 4705ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (is_blob_tag(elems[i].tag)) { 4715ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden size += elems[i].blob.data_length; 4725ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 4735ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 4745ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return size; 4755ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 4765ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 4775ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenvoid AuthorizationSet::CopyIndirectData() { 478370121346777e13437c275fbe7a975d899cc325cShawn Willden memset_s(indirect_data_, 0, indirect_data_capacity_); 4795ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 4805ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden uint8_t* indirect_data_pos = indirect_data_; 4815ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden for (size_t i = 0; i < elems_size_; ++i) { 482370121346777e13437c275fbe7a975d899cc325cShawn Willden assert(indirect_data_pos <= indirect_data_ + indirect_data_capacity_); 4835ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (is_blob_tag(elems_[i].tag)) { 4845ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden memcpy(indirect_data_pos, elems_[i].blob.data, elems_[i].blob.data_length); 4855ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden elems_[i].blob.data = indirect_data_pos; 4865ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden indirect_data_pos += elems_[i].blob.data_length; 4875ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 4885ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 489370121346777e13437c275fbe7a975d899cc325cShawn Willden assert(indirect_data_pos == indirect_data_ + indirect_data_capacity_); 490370121346777e13437c275fbe7a975d899cc325cShawn Willden indirect_data_size_ = indirect_data_pos - indirect_data_; 4915ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 4925ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 4931fa5d591fe6807665092753a5628d8d470888da4Shawn Willdensize_t AuthorizationSet::GetTagCount(keymaster_tag_t tag) const { 4941fa5d591fe6807665092753a5628d8d470888da4Shawn Willden size_t count = 0; 4951fa5d591fe6807665092753a5628d8d470888da4Shawn Willden for (int pos = -1; (pos = find(tag, pos)) != -1;) 4961fa5d591fe6807665092753a5628d8d470888da4Shawn Willden ++count; 4971fa5d591fe6807665092753a5628d8d470888da4Shawn Willden return count; 4981fa5d591fe6807665092753a5628d8d470888da4Shawn Willden} 4991fa5d591fe6807665092753a5628d8d470888da4Shawn Willden 5005ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueEnum(keymaster_tag_t tag, uint32_t* val) const { 5015ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = find(tag); 5025ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5035ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5045ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 505ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].enumerated; 5065ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5075ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5085ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 5095ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueEnumRep(keymaster_tag_t tag, size_t instance, 5105ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden uint32_t* val) const { 5115ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden size_t count = 0; 5125ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = -1; 5135ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden while (count <= instance) { 5145ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden pos = find(tag, pos); 5155ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5165ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5175ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 5185ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden ++count; 5195ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 520ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].enumerated; 5215ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5225ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5235ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 5245ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueInt(keymaster_tag_t tag, uint32_t* val) const { 5255ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = find(tag); 5265ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5275ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5285ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 529ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].integer; 5305ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5315ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5325ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 5335ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueIntRep(keymaster_tag_t tag, size_t instance, 5345ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden uint32_t* val) const { 5355ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden size_t count = 0; 5365ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = -1; 5375ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden while (count <= instance) { 5385ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden pos = find(tag, pos); 5395ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5405ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5415ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 5425ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden ++count; 5435ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 544ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].integer; 5455ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5465ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5475ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 5485ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueLong(keymaster_tag_t tag, uint64_t* val) const { 5495ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = find(tag); 5505ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5515ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5525ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 553ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].long_integer; 5545ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5555ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5565ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 557eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willdenbool AuthorizationSet::GetTagValueLongRep(keymaster_tag_t tag, size_t instance, 558eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden uint64_t* val) const { 559eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden size_t count = 0; 560eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden int pos = -1; 561eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden while (count <= instance) { 562eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden pos = find(tag, pos); 563eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden if (pos == -1) { 564eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden return false; 565eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden } 566eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden ++count; 567eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden } 568eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden *val = elems_[pos].long_integer; 569eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden return true; 570eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden} 571eb63b9799eadcaa6ef206f8b804d7432e0dab14aShawn Willden 5725ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueDate(keymaster_tag_t tag, uint64_t* val) const { 5735ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = find(tag); 5745ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5755ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5765ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 577ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].date_time; 5785ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5795ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5805ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 5815ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willdenbool AuthorizationSet::GetTagValueBlob(keymaster_tag_t tag, keymaster_blob_t* val) const { 5825ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden int pos = find(tag); 5835ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden if (pos == -1) { 5845ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return false; 5855ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden } 586ebf627f0b50c0979e6cf53668464297703371ebaShawn Willden *val = elems_[pos].blob; 5875ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden return true; 5885ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} 5895ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden 590dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willdenbool AuthorizationSet::GetTagValueBool(keymaster_tag_t tag) const { 591dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden int pos = find(tag); 592dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden if (pos == -1) { 593dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden return false; 594dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden } 595dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden assert(elems_[pos].boolean); 596dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden return elems_[pos].boolean; 597dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden} 598dfa1c030e941cba4e66b362854d84b19298353c9Shawn Willden 599edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willdenbool AuthorizationSet::ContainsEnumValue(keymaster_tag_t tag, uint32_t value) const { 600edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden for (auto& entry : *this) 601edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden if (entry.tag == tag && entry.enumerated == value) 602edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden return true; 603edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden return false; 604edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden} 605edb7994f7d5764fcf06188dc005743f4209deb0fShawn Willden 6065ada7b6c525d2bfd5b556a698ccb11db23e052bbShawn Willden} // namespace keymaster 607