Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(448)

Side by Side Diff: runtime/bin/secure_socket_macos.h

Issue 1852783003: Implements remaining SecurityContext calls for iOS (Closed) Base URL: git@github.com:dart-lang/sdk.git@master
Patch Set: Add RefCntReleaseScope Created 4 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright (c) 2016, the Dart project authors. Please see the AUTHORS file 1 // Copyright (c) 2016, the Dart project authors. Please see the AUTHORS file
2 // for details. All rights reserved. Use of this source code is governed by a 2 // for details. All rights reserved. Use of this source code is governed by a
3 // BSD-style license that can be found in the LICENSE file. 3 // BSD-style license that can be found in the LICENSE file.
4 4
5 #ifndef BIN_SECURE_SOCKET_MACOS_H_ 5 #ifndef BIN_SECURE_SOCKET_MACOS_H_
6 #define BIN_SECURE_SOCKET_MACOS_H_ 6 #define BIN_SECURE_SOCKET_MACOS_H_
7 7
8 #if !defined(BIN_SECURE_SOCKET_H_) 8 #if !defined(BIN_SECURE_SOCKET_H_)
9 #error Do not include secure_socket_macos.h directly. Use secure_socket.h. 9 #error Do not include secure_socket_macos.h directly. Use secure_socket.h.
10 #endif 10 #endif
11 11
12 #include <stdlib.h> 12 #include <stdlib.h>
13 #include <string.h> 13 #include <string.h>
14 #include <stdio.h> 14 #include <stdio.h>
15 #include <sys/types.h> 15 #include <sys/types.h>
16 16
17 #include <CoreFoundation/CoreFoundation.h> 17 #include <CoreFoundation/CoreFoundation.h>
18 #include <Security/SecureTransport.h> 18 #include <Security/SecureTransport.h>
19 #include <Security/Security.h> 19 #include <Security/Security.h>
20 20
21 #include "bin/builtin.h" 21 #include "bin/builtin.h"
22 #include "bin/dartutils.h" 22 #include "bin/dartutils.h"
23 #include "bin/lockers.h"
24 #include "bin/reference_counting.h"
23 #include "bin/socket.h" 25 #include "bin/socket.h"
24 #include "bin/thread.h" 26 #include "bin/thread.h"
25 #include "bin/utils.h" 27 #include "bin/utils.h"
26 28
27 namespace dart { 29 namespace dart {
28 namespace bin { 30 namespace bin {
29 31
30 // Forward declaration of SSLContext. 32 // SSLCertContext wraps the certificates needed for a SecureTransport
31 class SSLCertContext; 33 // connection. Fields are protected by the mutex_ field, and may only be set
34 // once. This is to allow access by both the Dart thread and the IOService
35 // thread. Setters return false if the field was already set.
36 class SSLCertContext : public ReferenceCounted<SSLCertContext> {
37 public:
38 SSLCertContext() :
39 ReferenceCounted(),
40 mutex_(new Mutex()),
41 private_key_(NULL),
42 keychain_(NULL),
43 cert_chain_(NULL),
44 trusted_certs_(NULL),
45 cert_authorities_(NULL),
46 trust_builtin_(false) {
47 }
48
49 ~SSLCertContext() {
50 if (private_key_ != NULL) {
51 CFRelease(private_key_);
52 }
53 if (keychain_ != NULL) {
54 SecKeychainDelete(keychain_);
55 CFRelease(keychain_);
56 }
57 if (cert_chain_ != NULL) {
58 CFRelease(cert_chain_);
59 }
60 if (trusted_certs_ != NULL) {
61 CFRelease(trusted_certs_);
62 }
63 if (cert_authorities_ != NULL) {
64 CFRelease(cert_authorities_);
65 }
66 delete mutex_;
67 }
68
69 SecKeyRef private_key() {
70 MutexLocker m(mutex_);
71 return private_key_;
72 }
73 bool set_private_key(SecKeyRef private_key) {
74 MutexLocker m(mutex_);
75 if (private_key_ != NULL) {
76 return false;
77 }
78 private_key_ = private_key;
79 return true;
80 }
81
82 SecKeychainRef keychain() {
83 MutexLocker m(mutex_);
84 return keychain_;
85 }
86 bool set_keychain(SecKeychainRef keychain) {
87 MutexLocker m(mutex_);
88 if (keychain_ != NULL) {
89 return false;
90 }
91 keychain_ = keychain;
92 return true;
93 }
94
95 CFArrayRef cert_chain() {
96 MutexLocker m(mutex_);
97 return cert_chain_;
98 }
99 bool set_cert_chain(CFArrayRef cert_chain) {
100 MutexLocker m(mutex_);
101 if (cert_chain_ != NULL) {
102 return false;
103 }
104 cert_chain_ = cert_chain;
105 return true;
106 }
107
108 CFArrayRef trusted_certs() {
109 MutexLocker m(mutex_);
110 return trusted_certs_;
111 }
112 bool set_trusted_certs(CFArrayRef trusted_certs) {
113 MutexLocker m(mutex_);
114 if (trusted_certs_ != NULL) {
115 return false;
116 }
117 trusted_certs_ = trusted_certs;
118 return true;
119 }
120
121 CFArrayRef cert_authorities() {
122 MutexLocker m(mutex_);
123 return cert_authorities_;
124 }
125 bool set_cert_authorities(CFArrayRef cert_authorities) {
126 MutexLocker m(mutex_);
127 if (cert_authorities_ != NULL) {
128 return false;
129 }
130 cert_authorities_ = cert_authorities;
131 return true;
132 }
133
134 bool trust_builtin() {
135 MutexLocker m(mutex_);
136 return trust_builtin_;
137 }
138 void set_trust_builtin(bool trust_builtin) {
139 MutexLocker m(mutex_);
140 trust_builtin_ = trust_builtin;
141 }
142
143 private:
144 // The context is accessed both by Dart code and the IOService. This mutex
145 // protects all fields.
146 Mutex* mutex_;
147
148 SecKeyRef private_key_;
149 SecKeychainRef keychain_;
150
151 // CFArrays of SecCertificateRef.
152 CFArrayRef cert_chain_;
153 CFArrayRef trusted_certs_;
154 CFArrayRef cert_authorities_;
155
156 bool trust_builtin_;
157
158 DISALLOW_COPY_AND_ASSIGN(SSLCertContext);
159 };
32 160
33 // SSLFilter encapsulates the SecureTransport code in a filter that communicates 161 // SSLFilter encapsulates the SecureTransport code in a filter that communicates
34 // with the containing _SecureFilterImpl Dart object through four shared 162 // with the containing _SecureFilterImpl Dart object through four shared
35 // ExternalByteArray buffers, for reading and writing plaintext, and 163 // ExternalByteArray buffers, for reading and writing plaintext, and
36 // reading and writing encrypted text. The filter handles handshaking 164 // reading and writing encrypted text. The filter handles handshaking
37 // and certificate verification. 165 // and certificate verification.
38 class SSLFilter { 166 class SSLFilter : public ReferenceCounted<SSLFilter> {
39 public: 167 public:
40 // These enums must agree with those in sdk/lib/io/secure_socket.dart. 168 // These enums must agree with those in sdk/lib/io/secure_socket.dart.
41 enum BufferIndex { 169 enum BufferIndex {
42 kReadPlaintext, 170 kReadPlaintext,
43 kWritePlaintext, 171 kWritePlaintext,
44 kReadEncrypted, 172 kReadEncrypted,
45 kWriteEncrypted, 173 kWriteEncrypted,
46 kNumBuffers, 174 kNumBuffers,
47 kFirstEncrypted = kReadEncrypted 175 kFirstEncrypted = kReadEncrypted
48 }; 176 };
49 177
50 SSLFilter() 178 SSLFilter()
51 : cert_context_(NULL), 179 : ReferenceCounted(),
180 cert_context_(NULL),
52 ssl_context_(NULL), 181 ssl_context_(NULL),
53 peer_certs_(NULL), 182 peer_certs_(NULL),
54 string_start_(NULL), 183 string_start_(NULL),
55 string_length_(NULL), 184 string_length_(NULL),
56 handshake_complete_(NULL), 185 handshake_complete_(NULL),
57 bad_certificate_callback_(NULL), 186 bad_certificate_callback_(NULL),
58 in_handshake_(false), 187 in_handshake_(false),
59 connected_(false), 188 connected_(false),
60 bad_cert_(false), 189 bad_cert_(false),
61 is_server_(false), 190 is_server_(false),
(...skipping 48 matching lines...) Expand 10 before | Expand all | Expand 10 after
110 OSStatus ProcessWritePlaintextBuffer(intptr_t start, 239 OSStatus ProcessWritePlaintextBuffer(intptr_t start,
111 intptr_t end, 240 intptr_t end,
112 intptr_t* bytes_processed); 241 intptr_t* bytes_processed);
113 242
114 // These calls can block on IO, and should only be invoked from 243 // These calls can block on IO, and should only be invoked from
115 // from ProcessAllBuffers from ProcessFilterRequest. 244 // from ProcessAllBuffers from ProcessFilterRequest.
116 OSStatus EvaluatePeerTrust(); 245 OSStatus EvaluatePeerTrust();
117 OSStatus Handshake(); 246 OSStatus Handshake();
118 Dart_Handle InvokeBadCertCallback(SecCertificateRef peer_cert); 247 Dart_Handle InvokeBadCertCallback(SecCertificateRef peer_cert);
119 248
120 SSLCertContext* cert_context_; 249 RetainedPointer<SSLCertContext> cert_context_;
121 SSLContextRef ssl_context_; 250 SSLContextRef ssl_context_;
122 CFArrayRef peer_certs_; 251 CFArrayRef peer_certs_;
123 252
124 // starts and ends filled in at the start of ProcessAllBuffers. 253 // starts and ends filled in at the start of ProcessAllBuffers.
125 // If these are NULL, then try to get the pointers out of 254 // If these are NULL, then try to get the pointers out of
126 // dart_buffer_objects_. 255 // dart_buffer_objects_.
127 uint8_t* buffers_[kNumBuffers]; 256 uint8_t* buffers_[kNumBuffers];
128 intptr_t* buffer_starts_[kNumBuffers]; 257 intptr_t* buffer_starts_[kNumBuffers];
129 intptr_t* buffer_ends_[kNumBuffers]; 258 intptr_t* buffer_ends_[kNumBuffers];
130 intptr_t buffer_size_; 259 intptr_t buffer_size_;
131 intptr_t encrypted_buffer_size_; 260 intptr_t encrypted_buffer_size_;
132 Dart_PersistentHandle string_start_; 261 Dart_PersistentHandle string_start_;
133 Dart_PersistentHandle string_length_; 262 Dart_PersistentHandle string_length_;
134 Dart_PersistentHandle dart_buffer_objects_[kNumBuffers]; 263 Dart_PersistentHandle dart_buffer_objects_[kNumBuffers];
135 Dart_PersistentHandle handshake_complete_; 264 Dart_PersistentHandle handshake_complete_;
136 Dart_PersistentHandle bad_certificate_callback_; 265 Dart_PersistentHandle bad_certificate_callback_;
137 bool in_handshake_; 266 bool in_handshake_;
138 bool connected_; 267 bool connected_;
139 bool bad_cert_; 268 bool bad_cert_;
140 bool is_server_; 269 bool is_server_;
141 char* hostname_; 270 char* hostname_;
142 271
143 DISALLOW_COPY_AND_ASSIGN(SSLFilter); 272 DISALLOW_COPY_AND_ASSIGN(SSLFilter);
144 }; 273 };
145 274
146 // Where the argument to the constructor is the handle for an object
147 // implementing List<int>, this class creates a scope in which the memory
148 // backing the list can be accessed.
149 //
150 // Do not make Dart_ API calls while in a ScopedMemBuffer.
151 // Do not call Dart_PropagateError while in a ScopedMemBuffer.
152 class ScopedMemBuffer {
153 public:
154 explicit ScopedMemBuffer(Dart_Handle object) {
155 if (!Dart_IsTypedData(object) && !Dart_IsList(object)) {
156 Dart_ThrowException(DartUtils::NewDartArgumentError(
157 "Argument is not a List<int>"));
158 }
159
160 uint8_t* bytes = NULL;
161 intptr_t bytes_len = 0;
162 bool is_typed_data = false;
163 if (Dart_IsTypedData(object)) {
164 is_typed_data = true;
165 Dart_TypedData_Type typ;
166 ThrowIfError(Dart_TypedDataAcquireData(
167 object,
168 &typ,
169 reinterpret_cast<void**>(&bytes),
170 &bytes_len));
171 } else {
172 ASSERT(Dart_IsList(object));
173 ThrowIfError(Dart_ListLength(object, &bytes_len));
174 bytes = Dart_ScopeAllocate(bytes_len);
175 ASSERT(bytes != NULL);
176 ThrowIfError(Dart_ListGetAsBytes(object, 0, bytes, bytes_len));
177 }
178
179 object_ = object;
180 bytes_ = bytes;
181 bytes_len_ = bytes_len;
182 is_typed_data_ = is_typed_data;
183 }
184
185 ~ScopedMemBuffer() {
186 if (is_typed_data_) {
187 ThrowIfError(Dart_TypedDataReleaseData(object_));
188 }
189 }
190
191 uint8_t* get() const { return bytes_; }
192 intptr_t length() const { return bytes_len_; }
193
194 private:
195 Dart_Handle object_;
196 uint8_t* bytes_;
197 intptr_t bytes_len_;
198 bool is_typed_data_;
199
200 DISALLOW_ALLOCATION();
201 DISALLOW_COPY_AND_ASSIGN(ScopedMemBuffer);
202 };
203
204 } // namespace bin 275 } // namespace bin
205 } // namespace dart 276 } // namespace dart
206 277
207 #endif // BIN_SECURE_SOCKET_MACOS_H_ 278 #endif // BIN_SECURE_SOCKET_MACOS_H_
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698