1 /* 2 * Copyright (C) 2008 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #ifndef _RECOVERY_VERIFIER_H 18 #define _RECOVERY_VERIFIER_H 19 20 #include <memory> 21 #include <vector> 22 23 #include <openssl/ec_key.h> 24 #include <openssl/rsa.h> 25 #include <openssl/sha.h> 26 27 struct RSADeleter { operatorRSADeleter28 void operator()(RSA* rsa) { 29 RSA_free(rsa); 30 } 31 }; 32 33 struct ECKEYDeleter { operatorECKEYDeleter34 void operator()(EC_KEY* ec_key) { 35 EC_KEY_free(ec_key); 36 } 37 }; 38 39 struct Certificate { 40 typedef enum { 41 KEY_TYPE_RSA, 42 KEY_TYPE_EC, 43 } KeyType; 44 CertificateCertificate45 Certificate(int hash_len_, 46 KeyType key_type_, 47 std::unique_ptr<RSA, RSADeleter>&& rsa_, 48 std::unique_ptr<EC_KEY, ECKEYDeleter>&& ec_) 49 : hash_len(hash_len_), 50 key_type(key_type_), 51 rsa(std::move(rsa_)), 52 ec(std::move(ec_)) {} 53 54 // SHA_DIGEST_LENGTH (SHA-1) or SHA256_DIGEST_LENGTH (SHA-256) 55 int hash_len; 56 KeyType key_type; 57 std::unique_ptr<RSA, RSADeleter> rsa; 58 std::unique_ptr<EC_KEY, ECKEYDeleter> ec; 59 }; 60 61 /* addr and length define a an update package file that has been 62 * loaded (or mmap'ed, or whatever) into memory. Verify that the file 63 * is signed and the signature matches one of the given keys. Return 64 * one of the constants below. 65 */ 66 int verify_file(unsigned char* addr, size_t length, 67 const std::vector<Certificate>& keys); 68 69 bool load_keys(const char* filename, std::vector<Certificate>& certs); 70 71 #define VERIFY_SUCCESS 0 72 #define VERIFY_FAILURE 1 73 74 #endif /* _RECOVERY_VERIFIER_H */ 75