Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(51)

Side by Side Diff: runtime/bin/secure_socket_ios.h

Issue 1852783003: Implements remaining SecurityContext calls for iOS (Closed) Base URL: git@github.com:dart-lang/sdk.git@master
Patch Set: Address comments Created 4 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « runtime/bin/secure_socket_boringssl.cc ('k') | runtime/bin/secure_socket_ios.cc » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright (c) 2016, the Dart project authors. Please see the AUTHORS file 1 // Copyright (c) 2016, the Dart project authors. Please see the AUTHORS file
2 // for details. All rights reserved. Use of this source code is governed by a 2 // for details. All rights reserved. Use of this source code is governed by a
3 // BSD-style license that can be found in the LICENSE file. 3 // BSD-style license that can be found in the LICENSE file.
4 4
5 #ifndef BIN_SECURE_SOCKET_MACOS_H_ 5 #ifndef BIN_SECURE_SOCKET_IOS_H_
6 #define BIN_SECURE_SOCKET_MACOS_H_ 6 #define BIN_SECURE_SOCKET_IOS_H_
7 7
8 #if !defined(BIN_SECURE_SOCKET_H_) 8 #if !defined(BIN_SECURE_SOCKET_H_)
9 #error Do not include secure_socket_macos.h directly. Use secure_socket.h. 9 #error Do not include secure_socket_macos.h directly. Use secure_socket.h.
10 #endif 10 #endif
11 11
12 #include <stdlib.h> 12 #include <stdlib.h>
13 #include <string.h> 13 #include <string.h>
14 #include <stdio.h> 14 #include <stdio.h>
15 #include <sys/types.h> 15 #include <sys/types.h>
16 16
17 #include <CoreFoundation/CoreFoundation.h> 17 #include <CoreFoundation/CoreFoundation.h>
18 #include <Security/SecureTransport.h> 18 #include <Security/SecureTransport.h>
19 #include <Security/Security.h> 19 #include <Security/Security.h>
20 20
21 #include "bin/builtin.h" 21 #include "bin/builtin.h"
22 #include "bin/dartutils.h" 22 #include "bin/dartutils.h"
23 #include "bin/lockers.h"
24 #include "bin/reference_counting.h"
23 #include "bin/socket.h" 25 #include "bin/socket.h"
24 #include "bin/thread.h" 26 #include "bin/thread.h"
25 #include "bin/utils.h" 27 #include "bin/utils.h"
26 28
27 namespace dart { 29 namespace dart {
28 namespace bin { 30 namespace bin {
29 31
30 // Forward declaration of SSLContext. 32 // SSLCertContext wraps the certificates needed for a SecureTransport
31 class SSLCertContext; 33 // connection. Fields are protected by the mutex_ field, and may only be set
34 // once. This is to allow access by both the Dart thread and the IOService
35 // thread. Setters return false if the field was already set.
36 class SSLCertContext : public ReferenceCounted<SSLCertContext> {
37 public:
38 SSLCertContext() :
39 ReferenceCounted(),
40 mutex_(new Mutex()),
41 trusted_certs_(NULL),
42 identity_(NULL),
43 cert_chain_(NULL),
44 trust_builtin_(false) {}
45
46 ~SSLCertContext() {
47 {
48 MutexLocker m(mutex_);
49 if (trusted_certs_ != NULL) {
50 CFRelease(trusted_certs_);
51 }
52 if (identity_ != NULL) {
53 CFRelease(identity_);
54 }
55 if (cert_chain_ != NULL) {
56 CFRelease(cert_chain_);
57 }
58 }
59 delete mutex_;
60 }
61
62 CFMutableArrayRef trusted_certs() {
63 MutexLocker m(mutex_);
64 return trusted_certs_;
65 }
66 void add_trusted_cert(SecCertificateRef trusted_cert) {
67 // Takes ownership of trusted_cert.
68 MutexLocker m(mutex_);
69 if (trusted_certs_ == NULL) {
70 trusted_certs_ = CFArrayCreateMutable(NULL, 0, &kCFTypeArrayCallBacks);
71 }
72 CFArrayAppendValue(trusted_certs_, trusted_cert);
73 CFRelease(trusted_cert); // trusted_cert is retained by the array.
74 }
75
76 SecIdentityRef identity() {
77 MutexLocker m(mutex_);
78 return identity_;
79 }
80 bool set_identity(SecIdentityRef identity) {
81 MutexLocker m(mutex_);
82 if (identity_ == NULL) {
83 identity_ = identity;
84 return true;
85 }
86 return false;
87 }
88
89 CFArrayRef cert_chain() {
90 MutexLocker m(mutex_);
91 return cert_chain_;
92 }
93 bool set_cert_chain(CFArrayRef cert_chain) {
94 MutexLocker m(mutex_);
95 if (cert_chain_ == NULL) {
96 cert_chain_ = cert_chain;
97 return true;
98 }
99 return false;
100 }
101
102 bool trust_builtin() {
103 MutexLocker m(mutex_);
104 return trust_builtin_;
105 }
106 void set_trust_builtin(bool trust_builtin) {
107 MutexLocker m(mutex_);
108 trust_builtin_ = trust_builtin;
109 }
110
111 private:
112 // The context is accessed both by Dart code and the IOService. This mutex
113 // protects all fields.
114 Mutex* mutex_;
115 CFMutableArrayRef trusted_certs_;
116 SecIdentityRef identity_;
117 CFArrayRef cert_chain_;
118 bool trust_builtin_;
119
120 DISALLOW_COPY_AND_ASSIGN(SSLCertContext);
121 };
32 122
33 // SSLFilter encapsulates the SecureTransport code in a filter that communicates 123 // SSLFilter encapsulates the SecureTransport code in a filter that communicates
34 // with the containing _SecureFilterImpl Dart object through four shared 124 // with the containing _SecureFilterImpl Dart object through four shared
35 // ExternalByteArray buffers, for reading and writing plaintext, and 125 // ExternalByteArray buffers, for reading and writing plaintext, and
36 // reading and writing encrypted text. The filter handles handshaking 126 // reading and writing encrypted text. The filter handles handshaking
37 // and certificate verification. 127 // and certificate verification.
38 class SSLFilter { 128 class SSLFilter : public ReferenceCounted<SSLFilter> {
39 public: 129 public:
40 // These enums must agree with those in sdk/lib/io/secure_socket.dart. 130 // These enums must agree with those in sdk/lib/io/secure_socket.dart.
41 enum BufferIndex { 131 enum BufferIndex {
42 kReadPlaintext, 132 kReadPlaintext,
43 kWritePlaintext, 133 kWritePlaintext,
44 kReadEncrypted, 134 kReadEncrypted,
45 kWriteEncrypted, 135 kWriteEncrypted,
46 kNumBuffers, 136 kNumBuffers,
47 kFirstEncrypted = kReadEncrypted 137 kFirstEncrypted = kReadEncrypted
48 }; 138 };
49 139
50 SSLFilter() 140 SSLFilter()
51 : cert_context_(NULL), 141 : ReferenceCounted(),
142 cert_context_(NULL),
52 ssl_context_(NULL), 143 ssl_context_(NULL),
53 peer_certs_(NULL), 144 peer_certs_(NULL),
54 string_start_(NULL), 145 string_start_(NULL),
55 string_length_(NULL), 146 string_length_(NULL),
56 handshake_complete_(NULL), 147 handshake_complete_(NULL),
57 bad_certificate_callback_(NULL), 148 bad_certificate_callback_(NULL),
58 in_handshake_(false), 149 in_handshake_(false),
59 connected_(false), 150 connected_(false),
60 bad_cert_(false), 151 bad_cert_(false),
61 is_server_(false), 152 is_server_(false),
(...skipping 48 matching lines...) Expand 10 before | Expand all | Expand 10 after
110 OSStatus ProcessWritePlaintextBuffer(intptr_t start, 201 OSStatus ProcessWritePlaintextBuffer(intptr_t start,
111 intptr_t end, 202 intptr_t end,
112 intptr_t* bytes_processed); 203 intptr_t* bytes_processed);
113 204
114 // These calls can block on IO, and should only be invoked from 205 // These calls can block on IO, and should only be invoked from
115 // from ProcessAllBuffers from ProcessFilterRequest. 206 // from ProcessAllBuffers from ProcessFilterRequest.
116 OSStatus EvaluatePeerTrust(); 207 OSStatus EvaluatePeerTrust();
117 OSStatus Handshake(); 208 OSStatus Handshake();
118 Dart_Handle InvokeBadCertCallback(SecCertificateRef peer_cert); 209 Dart_Handle InvokeBadCertCallback(SecCertificateRef peer_cert);
119 210
120 SSLCertContext* cert_context_; 211 RetainedPointer<SSLCertContext> cert_context_;
121 SSLContextRef ssl_context_; 212 SSLContextRef ssl_context_;
122 CFArrayRef peer_certs_; 213 CFArrayRef peer_certs_;
123 214
124 // starts and ends filled in at the start of ProcessAllBuffers. 215 // starts and ends filled in at the start of ProcessAllBuffers.
125 // If these are NULL, then try to get the pointers out of 216 // If these are NULL, then try to get the pointers out of
126 // dart_buffer_objects_. 217 // dart_buffer_objects_.
127 uint8_t* buffers_[kNumBuffers]; 218 uint8_t* buffers_[kNumBuffers];
128 intptr_t* buffer_starts_[kNumBuffers]; 219 intptr_t* buffer_starts_[kNumBuffers];
129 intptr_t* buffer_ends_[kNumBuffers]; 220 intptr_t* buffer_ends_[kNumBuffers];
130 intptr_t buffer_size_; 221 intptr_t buffer_size_;
131 intptr_t encrypted_buffer_size_; 222 intptr_t encrypted_buffer_size_;
132 Dart_PersistentHandle string_start_; 223 Dart_PersistentHandle string_start_;
133 Dart_PersistentHandle string_length_; 224 Dart_PersistentHandle string_length_;
134 Dart_PersistentHandle dart_buffer_objects_[kNumBuffers]; 225 Dart_PersistentHandle dart_buffer_objects_[kNumBuffers];
135 Dart_PersistentHandle handshake_complete_; 226 Dart_PersistentHandle handshake_complete_;
136 Dart_PersistentHandle bad_certificate_callback_; 227 Dart_PersistentHandle bad_certificate_callback_;
137 bool in_handshake_; 228 bool in_handshake_;
138 bool connected_; 229 bool connected_;
139 bool bad_cert_; 230 bool bad_cert_;
140 bool is_server_; 231 bool is_server_;
141 char* hostname_; 232 char* hostname_;
142 233
143 DISALLOW_COPY_AND_ASSIGN(SSLFilter); 234 DISALLOW_COPY_AND_ASSIGN(SSLFilter);
144 }; 235 };
145 236
146 // Where the argument to the constructor is the handle for an object
147 // implementing List<int>, this class creates a scope in which the memory
148 // backing the list can be accessed.
149 //
150 // Do not make Dart_ API calls while in a ScopedMemBuffer.
151 // Do not call Dart_PropagateError while in a ScopedMemBuffer.
152 class ScopedMemBuffer {
153 public:
154 explicit ScopedMemBuffer(Dart_Handle object) {
155 if (!Dart_IsTypedData(object) && !Dart_IsList(object)) {
156 Dart_ThrowException(DartUtils::NewDartArgumentError(
157 "Argument is not a List<int>"));
158 }
159
160 uint8_t* bytes = NULL;
161 intptr_t bytes_len = 0;
162 bool is_typed_data = false;
163 if (Dart_IsTypedData(object)) {
164 is_typed_data = true;
165 Dart_TypedData_Type typ;
166 ThrowIfError(Dart_TypedDataAcquireData(
167 object,
168 &typ,
169 reinterpret_cast<void**>(&bytes),
170 &bytes_len));
171 } else {
172 ASSERT(Dart_IsList(object));
173 ThrowIfError(Dart_ListLength(object, &bytes_len));
174 bytes = Dart_ScopeAllocate(bytes_len);
175 ASSERT(bytes != NULL);
176 ThrowIfError(Dart_ListGetAsBytes(object, 0, bytes, bytes_len));
177 }
178
179 object_ = object;
180 bytes_ = bytes;
181 bytes_len_ = bytes_len;
182 is_typed_data_ = is_typed_data;
183 }
184
185 ~ScopedMemBuffer() {
186 if (is_typed_data_) {
187 ThrowIfError(Dart_TypedDataReleaseData(object_));
188 }
189 }
190
191 uint8_t* get() const { return bytes_; }
192 intptr_t length() const { return bytes_len_; }
193
194 private:
195 Dart_Handle object_;
196 uint8_t* bytes_;
197 intptr_t bytes_len_;
198 bool is_typed_data_;
199
200 DISALLOW_ALLOCATION();
201 DISALLOW_COPY_AND_ASSIGN(ScopedMemBuffer);
202 };
203
204 } // namespace bin 237 } // namespace bin
205 } // namespace dart 238 } // namespace dart
206 239
207 #endif // BIN_SECURE_SOCKET_MACOS_H_ 240 #endif // BIN_SECURE_SOCKET_IOS_H_
OLDNEW
« no previous file with comments | « runtime/bin/secure_socket_boringssl.cc ('k') | runtime/bin/secure_socket_ios.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698