1 /* 2 * Copyright (c) 2021-2023 Huawei Device Co., Ltd. 3 * Licensed under the Apache License, Version 2.0 (the "License"); 4 * you may not use this file except in compliance with the License. 5 * You may obtain a copy of the License at 6 * 7 * http://www.apache.org/licenses/LICENSE-2.0 8 * 9 * Unless required by applicable law or agreed to in writing, software 10 * distributed under the License is distributed on an "AS IS" BASIS, 11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12 * See the License for the specific language governing permissions and 13 * limitations under the License. 14 */ 15 16 #ifndef PERMISSION_POLICY_SET_H 17 #define PERMISSION_POLICY_SET_H 18 19 #include <memory> 20 #include <string> 21 #include <vector> 22 23 #include "access_token.h" 24 #include "callback_manager.h" 25 #include "generic_values.h" 26 #include "permission_def.h" 27 #include "permission_state_full.h" 28 #include "rwlock.h" 29 30 namespace OHOS { 31 namespace Security { 32 namespace AccessToken { 33 struct PermissionPolicySet final { 34 public: PermissionPolicySetfinal35 PermissionPolicySet() : tokenId_(0) {} 36 virtual ~PermissionPolicySet(); 37 38 static std::shared_ptr<PermissionPolicySet> BuildPermissionPolicySet(AccessTokenID tokenId, 39 const std::vector<PermissionStateFull>& permStateList); 40 static std::shared_ptr<PermissionPolicySet> BuildPolicySetWithoutDefCheck(AccessTokenID tokenId, 41 const std::vector<PermissionStateFull>& permStateList); 42 static std::shared_ptr<PermissionPolicySet> RestorePermissionPolicy(AccessTokenID tokenId, 43 const std::vector<GenericValues>& permStateRes); 44 void StorePermissionPolicySet(std::vector<GenericValues>& permStateValueList); 45 void Update(const std::vector<PermissionStateFull>& permStateList); 46 47 PermUsedTypeEnum GetUserGrantedPermissionUsedType(const std::string& permissionName); 48 int VerifyPermissionStatus(const std::string& permissionName); 49 void GetDefPermissions(std::vector<PermissionDef>& permList); 50 void GetPermissionStateFulls(std::vector<PermissionStateFull>& permList); 51 bool IsPermissionGrantedWithSecComp(const std::string& permissionName); 52 int QueryPermissionFlag(const std::string& permissionName, int& flag); 53 int32_t UpdatePermissionStatus(const std::string& permissionName, bool isGranted, uint32_t flag); 54 void ToString(std::string& info); 55 bool IsPermissionReqValid(int32_t tokenApl, const std::string& permissionName, 56 const std::vector<std::string>& nativeAcls); 57 void PermStateToString(int32_t tokenApl, const std::vector<std::string>& nativeAcls, std::string& info); 58 void GetPermissionStateList(std::vector<PermissionStateFull>& stateList); 59 void ResetUserGrantPermissionStatus(void); 60 void ClearSecCompGrantedPerm(void); 61 static uint32_t GetFlagWithoutSpecifiedElement(uint32_t fullFlag, uint32_t removedFlag); 62 static uint32_t GetFlagWroteToDb(uint32_t grantFlag); 63 void GetDeletedPermissionListToNotify(std::vector<std::string>& permissionList); 64 void GetGrantedPermissionList(std::vector<std::string>& permissionList); 65 66 void GetPermissionStateList(std::vector<uint32_t>& opCodeList, std::vector<bool>& statusList); 67 uint32_t GetReqPermissionSize(); 68 private: 69 static void MergePermissionStateFull(std::vector<PermissionStateFull>& permStateList, 70 PermissionStateFull& state); 71 void UpdatePermStateFull(const PermissionStateFull& permOld, PermissionStateFull& permNew); 72 void StorePermissionDef(std::vector<GenericValues>& valueList) const; 73 void StorePermissionState(std::vector<GenericValues>& valueList) const; 74 void PermDefToString(const PermissionDef& def, std::string& info) const; 75 void PermStateFullToString(const PermissionStateFull& state, std::string& info) const; 76 int32_t UpdateSecCompGrantedPermList(const std::string& permissionName, bool isGranted); 77 int32_t UpdatePermStateList(const std::string& permissionName, bool isGranted, uint32_t flag); 78 void SetPermissionFlag(const std::string& permissionName, uint32_t flag, bool needToAdd); 79 void SecCompGrantedPermListUpdated(const std::string& permissionName, bool isToGrant); 80 OHOS::Utils::RWLock permPolicySetLock_; 81 std::vector<PermissionStateFull> permStateList_; 82 std::vector<std::string> secCompGrantedPermList_; 83 AccessTokenID tokenId_; 84 }; 85 } // namespace AccessToken 86 } // namespace Security 87 } // namespace OHOS 88 #endif // PERMISSION_POLICY_SET_H 89 90