1 // 2 // Copyright (C) 2018 The Android Open Source Project 3 // 4 // Licensed under the Apache License, Version 2.0 (the "License"); 5 // you may not use this file except in compliance with the License. 6 // You may obtain a copy of the License at 7 // 8 // http://www.apache.org/licenses/LICENSE-2.0 9 // 10 // Unless required by applicable law or agreed to in writing, software 11 // distributed under the License is distributed on an "AS IS" BASIS, 12 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 // See the License for the specific language governing permissions and 14 // limitations under the License. 15 // 16 17 #ifndef UPDATE_ENGINE_PAYLOAD_CONSUMER_PAYLOAD_METADATA_H_ 18 #define UPDATE_ENGINE_PAYLOAD_CONSUMER_PAYLOAD_METADATA_H_ 19 20 #include <inttypes.h> 21 22 #include <string> 23 #include <vector> 24 25 #include <base/macros.h> 26 #include <brillo/secure_blob.h> 27 28 #include "update_engine/common/error_code.h" 29 #include "update_engine/common/platform_constants.h" 30 #include "update_engine/payload_consumer/payload_verifier.h" 31 #include "update_engine/update_metadata.pb.h" 32 33 namespace chromeos_update_engine { 34 35 enum class MetadataParseResult { 36 kSuccess, 37 kError, 38 kInsufficientData, 39 }; 40 41 // This class parses payload metadata and validate its signature. 42 class PayloadMetadata { 43 public: 44 static const uint64_t kDeltaVersionOffset; 45 static const uint64_t kDeltaVersionSize; 46 static const uint64_t kDeltaManifestSizeOffset; 47 static const uint64_t kDeltaManifestSizeSize; 48 static const uint64_t kDeltaMetadataSignatureSizeSize; 49 50 PayloadMetadata() = default; 51 52 // Attempts to parse the update payload header starting from the beginning of 53 // |payload|. On success, returns kMetadataParseSuccess. Returns 54 // kMetadataParseInsufficientData if more data is needed to parse the complete 55 // metadata. Returns kMetadataParseError if the metadata can't be parsed given 56 // the payload. 57 MetadataParseResult ParsePayloadHeader(const brillo::Blob& payload, 58 ErrorCode* error); 59 // Simpler version of the above, returns true on success. 60 bool ParsePayloadHeader(const brillo::Blob& payload); 61 62 // Given the |payload|, verifies that the signed hash of its metadata matches 63 // |metadata_signature| (if present) or the metadata signature in payload 64 // itself (if present). Returns ErrorCode::kSuccess on match or a suitable 65 // error code otherwise. This method must be called before any part of the 66 // metadata is parsed so that a man-in-the-middle attack on the SSL connection 67 // to the payload server doesn't exploit any vulnerability in the code that 68 // parses the protocol buffer. 69 ErrorCode ValidateMetadataSignature( 70 const brillo::Blob& payload, 71 const std::string& metadata_signature, 72 const PayloadVerifier& payload_verifier) const; 73 74 // Returns the major payload version. If the version was not yet parsed, 75 // returns zero. GetMajorVersion()76 uint64_t GetMajorVersion() const { return major_payload_version_; } 77 78 // Returns the size of the payload metadata, which includes the payload header 79 // and the manifest. If the header was not yet parsed, returns zero. GetMetadataSize()80 uint64_t GetMetadataSize() const { return metadata_size_; } 81 82 // Returns the size of the payload metadata signature. If the header was not 83 // yet parsed, returns zero. GetMetadataSignatureSize()84 uint32_t GetMetadataSignatureSize() const { return metadata_signature_size_; } 85 86 // Set |*out_manifest| to the manifest in |payload|. 87 // Returns true on success. 88 bool GetManifest(const brillo::Blob& payload, 89 DeltaArchiveManifest* out_manifest) const; 90 91 private: 92 // Set |*out_offset| to the byte offset at which the manifest protobuf begins 93 // in a payload. Return true on success, false if the offset is unknown. 94 bool GetManifestOffset(uint64_t* out_offset) const; 95 96 // Set |*out_offset| to the byte offset where the size of the metadata 97 // signature is stored in a payload. Return true on success, if this field is 98 // not present in the payload, return false. 99 bool GetMetadataSignatureSizeOffset(uint64_t* out_offset) const; 100 101 uint64_t metadata_size_{0}; 102 uint64_t manifest_size_{0}; 103 uint32_t metadata_signature_size_{0}; 104 uint64_t major_payload_version_{0}; 105 106 DISALLOW_COPY_AND_ASSIGN(PayloadMetadata); 107 }; 108 109 } // namespace chromeos_update_engine 110 111 #endif // UPDATE_ENGINE_PAYLOAD_CONSUMER_PAYLOAD_METADATA_H_ 112