blob: a095afc194da3f2cdcd4ac5df6db0fc4826ad599 [file] [log] [blame]
Yi Jinc23fad22017-09-15 17:24:59 -07001/*
2 * Copyright (C) 2017 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17
18
19#include "PrivacyBuffer.h"
20#include "io_util.h"
21
22#include <android/util/protobuf.h>
23#include <deque>
24
25using namespace android::util;
26
27/**
28 * Write the field to buf based on the wire type, iterator will point to next field.
29 * If skip is set to true, no data will be written to buf. Return number of bytes written.
30 */
Yi Jin42711a02017-10-11 18:20:24 -070031void
32PrivacyBuffer::writeFieldOrSkip(uint32_t fieldTag, bool skip)
Yi Jinc23fad22017-09-15 17:24:59 -070033{
Yi Jin42711a02017-10-11 18:20:24 -070034 uint8_t wireType = read_wire_type(fieldTag);
Yi Jinc23fad22017-09-15 17:24:59 -070035 size_t bytesToWrite = 0;
Yi Jin42711a02017-10-11 18:20:24 -070036 uint32_t varint = 0;
37
Yi Jinc23fad22017-09-15 17:24:59 -070038 switch (wireType) {
39 case WIRE_TYPE_VARINT:
Yi Jin42711a02017-10-11 18:20:24 -070040 varint = mData.readRawVarint();
41 if (!skip) {
42 mProto.writeRawVarint(fieldTag);
43 mProto.writeRawVarint(varint);
44 }
45 return;
Yi Jinc23fad22017-09-15 17:24:59 -070046 case WIRE_TYPE_FIXED64:
Yi Jin42711a02017-10-11 18:20:24 -070047 if (!skip) mProto.writeRawVarint(fieldTag);
Yi Jinc23fad22017-09-15 17:24:59 -070048 bytesToWrite = 8;
49 break;
50 case WIRE_TYPE_LENGTH_DELIMITED:
Yi Jin42711a02017-10-11 18:20:24 -070051 bytesToWrite = mData.readRawVarint();
52 if(!skip) mProto.writeLengthDelimitedHeader(read_field_id(fieldTag), bytesToWrite);
Yi Jinc23fad22017-09-15 17:24:59 -070053 break;
54 case WIRE_TYPE_FIXED32:
Yi Jin42711a02017-10-11 18:20:24 -070055 if (!skip) mProto.writeRawVarint(fieldTag);
Yi Jinc23fad22017-09-15 17:24:59 -070056 bytesToWrite = 4;
57 break;
58 }
59 if (skip) {
Yi Jin42711a02017-10-11 18:20:24 -070060 mData.rp()->move(bytesToWrite);
Yi Jinc23fad22017-09-15 17:24:59 -070061 } else {
62 for (size_t i=0; i<bytesToWrite; i++) {
Yi Jin42711a02017-10-11 18:20:24 -070063 mProto.writeRawByte(mData.next());
Yi Jinc23fad22017-09-15 17:24:59 -070064 }
65 }
Yi Jinc23fad22017-09-15 17:24:59 -070066}
67
68/**
69 * Strip next field based on its private policy and request spec, then stores data in buf.
70 * Return NO_ERROR if succeeds, otherwise BAD_VALUE is returned to indicate bad data in FdBuffer.
71 *
72 * The iterator must point to the head of a protobuf formatted field for successful operation.
73 * After exit with NO_ERROR, iterator points to the next protobuf field's head.
74 */
Yi Jin42711a02017-10-11 18:20:24 -070075status_t
76PrivacyBuffer::stripField(const Privacy* parentPolicy, const PrivacySpec& spec)
Yi Jinc23fad22017-09-15 17:24:59 -070077{
Yi Jin42711a02017-10-11 18:20:24 -070078 if (!mData.hasNext() || parentPolicy == NULL) return BAD_VALUE;
79 uint32_t fieldTag = mData.readRawVarint();
80 const Privacy* policy = parentPolicy->lookup(read_field_id(fieldTag));
81
Yi Jinc23fad22017-09-15 17:24:59 -070082 if (policy == NULL || !policy->IsMessageType() || !policy->HasChildren()) {
83 bool skip = !spec.CheckPremission(policy);
Yi Jin42711a02017-10-11 18:20:24 -070084 // iterator will point to head of next field
85 writeFieldOrSkip(fieldTag, skip);
86 return NO_ERROR;
Yi Jinc23fad22017-09-15 17:24:59 -070087 }
88 // current field is message type and its sub-fields have extra privacy policies
Yi Jin42711a02017-10-11 18:20:24 -070089 uint32_t msgSize = mData.readRawVarint();
90 EncodedBuffer::Pointer start = mData.rp()->copy();
91 while (mData.rp()->pos() - start.pos() != msgSize) {
92 long long token = mProto.start(policy->EncodedFieldId());
93 status_t err = stripField(policy, spec);
Yi Jinc23fad22017-09-15 17:24:59 -070094 if (err != NO_ERROR) return err;
Yi Jin42711a02017-10-11 18:20:24 -070095 mProto.end(token);
Yi Jinc23fad22017-09-15 17:24:59 -070096 }
97 return NO_ERROR;
98}
99
100// ================================================================================
101PrivacyBuffer::PrivacyBuffer(const Privacy* policy, EncodedBuffer::iterator& data)
102 :mPolicy(policy),
103 mData(data),
Yi Jin42711a02017-10-11 18:20:24 -0700104 mProto(),
Yi Jinc23fad22017-09-15 17:24:59 -0700105 mSize(0)
106{
107}
108
109PrivacyBuffer::~PrivacyBuffer()
110{
111}
112
113status_t
114PrivacyBuffer::strip(const PrivacySpec& spec)
115{
116 // optimization when no strip happens
117 if (mPolicy == NULL || !mPolicy->HasChildren() || spec.RequireAll()) {
118 if (spec.CheckPremission(mPolicy)) mSize = mData.size();
119 return NO_ERROR;
120 }
121 while (mData.hasNext()) {
Yi Jin42711a02017-10-11 18:20:24 -0700122 status_t err = stripField(mPolicy, spec);
Yi Jinc23fad22017-09-15 17:24:59 -0700123 if (err != NO_ERROR) return err;
124 }
125 if (mData.bytesRead() != mData.size()) return BAD_VALUE;
Yi Jin42711a02017-10-11 18:20:24 -0700126 mSize = mProto.size();
Yi Jinc23fad22017-09-15 17:24:59 -0700127 mData.rp()->rewind(); // rewind the read pointer back to beginning after the strip.
128 return NO_ERROR;
129}
130
131void
132PrivacyBuffer::clear()
133{
134 mSize = 0;
Yi Jin42711a02017-10-11 18:20:24 -0700135 mProto = ProtoOutputStream();
Yi Jinc23fad22017-09-15 17:24:59 -0700136}
137
138size_t
139PrivacyBuffer::size() const { return mSize; }
140
141status_t
142PrivacyBuffer::flush(int fd)
143{
144 status_t err = NO_ERROR;
Yi Jin42711a02017-10-11 18:20:24 -0700145 EncodedBuffer::iterator iter = size() == mData.size() ? mData : mProto.data();
Yi Jinc23fad22017-09-15 17:24:59 -0700146 while (iter.readBuffer() != NULL) {
147 err = write_all(fd, iter.readBuffer(), iter.currentToRead());
148 iter.rp()->move(iter.currentToRead());
149 if (err != NO_ERROR) return err;
150 }
151 return NO_ERROR;
152}