singlediskrep.h
1 /* 2 * Copyright (c) 2007,2011,2014 Apple Inc. All Rights Reserved. 3 * 4 * @APPLE_LICENSE_HEADER_START@ 5 * 6 * This file contains Original Code and/or Modifications of Original Code 7 * as defined in and that are subject to the Apple Public Source License 8 * Version 2.0 (the 'License'). You may not use this file except in 9 * compliance with the License. Please obtain a copy of the License at 10 * http://www.opensource.apple.com/apsl/ and read it before using this 11 * file. 12 * 13 * The Original Code and all software distributed under the License are 14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 18 * Please see the License for the specific language governing rights and 19 * limitations under the License. 20 * 21 * @APPLE_LICENSE_HEADER_END@ 22 */ 23 24 // 25 // singlediskrep - semi-abstract diskrep for a single file of some kind 26 // 27 #ifndef _H_SINGLEDISKREP 28 #define _H_SINGLEDISKREP 29 30 #include "diskrep.h" 31 #include <security_utilities/unix++.h> 32 33 namespace Security { 34 namespace CodeSigning { 35 36 37 // 38 // A slight specialization of DiskRep that knows that it's working with a single 39 // file at a path that is both the canonical and main executable path. This is a common 40 // pattern. 41 // 42 // A SingleDiskRep is not a fully formed DiskRep in its own right. It must be further 43 // subclassed. 44 // 45 class SingleDiskRep : public DiskRep { 46 public: 47 SingleDiskRep(const std::string &path); 48 49 CFDataRef identification(); // partial file hash 50 std::string mainExecutablePath(); // base path 51 CFURLRef copyCanonicalPath(); // base path 52 size_t signingLimit(); // size of file 53 size_t execSegLimit(const Architecture *arch); // size of executable segment 54 UnixPlusPlus::FileDesc &fd(); // readable fd for this file 55 void flush(); // close cached fd 56 57 bool appleInternalForcePlatform() const; 58 59 std::string recommendedIdentifier(const SigningContext &ctx); // basename(path) 60 61 void strictValidate(const CodeDirectory* cd, const ToleratedErrors& tolerated, SecCSFlags flags); 62 63 public: 64 class Writer; 65 66 protected: 67 std::string path() const { return mPath; } 68 69 private: 70 std::string mPath; 71 UnixPlusPlus::AutoFileDesc mFd; // open file (cached) 72 }; 73 74 75 // 76 // A Writer for a SingleDiskRep 77 // 78 class SingleDiskRep::Writer : public DiskRep::Writer { 79 public: 80 Writer(SingleDiskRep *r, uint32_t attrs = 0) : DiskRep::Writer(attrs), rep(r) { } 81 82 UnixPlusPlus::FileDesc &fd(); 83 84 private: 85 RefPointer<SingleDiskRep> rep; // underlying SingleDiskRep 86 UnixPlusPlus::AutoFileDesc mFd; // cached writable fd 87 }; 88 89 90 91 } // end namespace CodeSigning 92 } // end namespace Security 93 94 #endif // !_H_SINGLEDISKREP