1 /* 2 * Copyright (c) 2021-2023 Huawei Device Co., Ltd. 3 * Licensed under the Apache License, Version 2.0 (the "License"); 4 * you may not use this file except in compliance with the License. 5 * You may obtain a copy of the License at 6 * 7 * http://www.apache.org/licenses/LICENSE-2.0 8 * 9 * Unless required by applicable law or agreed to in writing, software 10 * distributed under the License is distributed on an "AS IS" BASIS, 11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12 * See the License for the specific language governing permissions and 13 * limitations under the License. 14 */ 15 16 #ifndef PERMISSION_POLICY_SET_H 17 #define PERMISSION_POLICY_SET_H 18 19 #include <memory> 20 #include <string> 21 #include <vector> 22 23 #include "access_token.h" 24 #include "callback_manager.h" 25 #include "generic_values.h" 26 #include "permission_def.h" 27 #include "permission_state_full.h" 28 #include "rwlock.h" 29 30 namespace OHOS { 31 namespace Security { 32 namespace AccessToken { 33 struct PermissionPolicySet final { 34 public: PermissionPolicySetfinal35 PermissionPolicySet() : tokenId_(0) {} 36 virtual ~PermissionPolicySet(); 37 38 static std::shared_ptr<PermissionPolicySet> BuildPermissionPolicySet(AccessTokenID tokenId, 39 const std::vector<PermissionStateFull>& permStateList); 40 static std::shared_ptr<PermissionPolicySet> BuildPolicySetWithoutDefCheck(AccessTokenID tokenId, 41 const std::vector<PermissionStateFull>& permStateList); 42 static std::shared_ptr<PermissionPolicySet> RestorePermissionPolicy(AccessTokenID tokenId, 43 const std::vector<GenericValues>& permStateRes); 44 void StorePermissionPolicySet(std::vector<GenericValues>& permStateValueList); 45 void Update(const std::vector<PermissionStateFull>& permStateList); 46 47 int VerifyPermissionStatus(const std::string& permissionName); 48 void GetDefPermissions(std::vector<PermissionDef>& permList); 49 void GetPermissionStateFulls(std::vector<PermissionStateFull>& permList); 50 int QueryPermissionFlag(const std::string& permissionName, int& flag); 51 int32_t UpdatePermissionStatus(const std::string& permissionName, bool isGranted, uint32_t flag); 52 void ToString(std::string& info); 53 bool IsPermissionReqValid(int32_t tokenApl, const std::string& permissionName, 54 const std::vector<std::string>& nativeAcls); 55 void PermStateToString(int32_t tokenApl, const std::vector<std::string>& nativeAcls, std::string& info); 56 void GetPermissionStateList(std::vector<PermissionStateFull>& stateList); 57 void ResetUserGrantPermissionStatus(void); 58 void ClearSecCompGrantedPerm(void); 59 static uint32_t GetFlagWithoutSpecifiedElement(uint32_t fullFlag, uint32_t removedFlag); 60 static uint32_t GetFlagWroteToDb(uint32_t grantFlag); 61 void GetDeletedPermissionListToNotify(std::vector<std::string>& permissionList); 62 void GetGrantedPermissionList(std::vector<std::string>& permissionList); 63 64 void GetPermissionStateList(std::vector<uint32_t>& opCodeList, std::vector<bool>& statusList); 65 private: 66 static void MergePermissionStateFull(std::vector<PermissionStateFull>& permStateList, 67 PermissionStateFull& state); 68 void UpdatePermStateFull(const PermissionStateFull& permOld, PermissionStateFull& permNew); 69 void StorePermissionDef(std::vector<GenericValues>& valueList) const; 70 void StorePermissionState(std::vector<GenericValues>& valueList) const; 71 void PermDefToString(const PermissionDef& def, std::string& info) const; 72 void PermStateFullToString(const PermissionStateFull& state, std::string& info) const; 73 int32_t UpdateSecCompGrantedPermList(const std::string& permissionName, bool isGranted); 74 int32_t UpdatePermStateList(const std::string& permissionName, bool isGranted, uint32_t flag); 75 void SetPermissionFlag(const std::string& permissionName, uint32_t flag, bool needToAdd); 76 void SecCompGrantedPermListUpdated(const std::string& permissionName, bool isToGrant); 77 OHOS::Utils::RWLock permPolicySetLock_; 78 std::vector<PermissionStateFull> permStateList_; 79 std::vector<std::string> secCompGrantedPermList_; 80 AccessTokenID tokenId_; 81 }; 82 } // namespace AccessToken 83 } // namespace Security 84 } // namespace OHOS 85 #endif // PERMISSION_POLICY_SET_H 86 87