/ OSX / libsecurity_codesigning / lib / singlediskrep.h
singlediskrep.h
 1  /*
 2   * Copyright (c) 2007,2011,2014 Apple Inc. All Rights Reserved.
 3   * 
 4   * @APPLE_LICENSE_HEADER_START@
 5   * 
 6   * This file contains Original Code and/or Modifications of Original Code
 7   * as defined in and that are subject to the Apple Public Source License
 8   * Version 2.0 (the 'License'). You may not use this file except in
 9   * compliance with the License. Please obtain a copy of the License at
10   * http://www.opensource.apple.com/apsl/ and read it before using this
11   * file.
12   * 
13   * The Original Code and all software distributed under the License are
14   * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15   * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16   * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17   * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18   * Please see the License for the specific language governing rights and
19   * limitations under the License.
20   * 
21   * @APPLE_LICENSE_HEADER_END@
22   */
23  
24  //
25  // singlediskrep - semi-abstract diskrep for a single file of some kind
26  //
27  #ifndef _H_SINGLEDISKREP
28  #define _H_SINGLEDISKREP
29  
30  #include "diskrep.h"
31  #include <security_utilities/unix++.h>
32  
33  namespace Security {
34  namespace CodeSigning {
35  
36  
37  //
38  // A slight specialization of DiskRep that knows that it's working with a single
39  // file at a path that is both the canonical and main executable path. This is a common
40  // pattern.
41  //
42  // A SingleDiskRep is not a fully formed DiskRep in its own right. It must be further
43  // subclassed.
44  //
45  class SingleDiskRep : public DiskRep {
46  public:
47  	SingleDiskRep(const std::string &path);
48  
49  	CFDataRef identification();								// partial file hash
50  	std::string mainExecutablePath();						// base path
51  	CFURLRef copyCanonicalPath();							// base path
52  	size_t signingLimit();									// size of file
53  	size_t execSegLimit(const Architecture *arch);			// size of executable segment
54  	UnixPlusPlus::FileDesc &fd();							// readable fd for this file
55  	void flush();											// close cached fd
56  
57  	bool appleInternalForcePlatform() const;
58  
59  	std::string recommendedIdentifier(const SigningContext &ctx); // basename(path)
60  
61  	void strictValidate(const CodeDirectory* cd, const ToleratedErrors& tolerated, SecCSFlags flags);
62  
63  public:
64  	class Writer;
65  	
66  protected:
67  	std::string path() const { return mPath; }
68  
69  private:
70  	std::string mPath;
71  	UnixPlusPlus::AutoFileDesc mFd;							// open file (cached)
72  };
73  
74  
75  //
76  // A Writer for a SingleDiskRep
77  //
78  class SingleDiskRep::Writer : public DiskRep::Writer {
79  public:
80  	Writer(SingleDiskRep *r, uint32_t attrs = 0) : DiskRep::Writer(attrs), rep(r) { }
81  
82  	UnixPlusPlus::FileDesc &fd();
83  
84  private:
85  	RefPointer<SingleDiskRep> rep;							// underlying SingleDiskRep
86  	UnixPlusPlus::AutoFileDesc mFd;							// cached writable fd
87  };
88  
89  
90  
91  } // end namespace CodeSigning
92  } // end namespace Security
93  
94  #endif // !_H_SINGLEDISKREP