blob: c247501f6dc2882dc680fc89497561409491602c [file] [log] [blame]
Zhiyi Zhang91c846b2017-04-12 14:16:31 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesaventob48bbda2020-07-27 19:41:37 -04002/*
Davide Pesaventoe5b43692021-11-15 22:05:03 -05003 * Copyright (c) 2017-2021, Regents of the University of California.
Zhiyi Zhang91c846b2017-04-12 14:16:31 -07004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
Zhiyi Zhangb041d442020-10-22 21:57:11 -070021#include "detail/ca-sqlite.hpp"
Davide Pesaventob48bbda2020-07-27 19:41:37 -040022
Zhiyi Zhanga749f442020-09-29 17:19:51 -070023#include <sqlite3.h>
Davide Pesaventoe5b43692021-11-15 22:05:03 -050024
tylerliua7bea662020-10-08 18:51:02 -070025#include <ndn-cxx/security/validation-policy.hpp>
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070026#include <ndn-cxx/util/sqlite3-statement.hpp>
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070027
Davide Pesaventoe5b43692021-11-15 22:05:03 -050028#include <boost/filesystem.hpp>
29#include <boost/property_tree/json_parser.hpp>
30
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070031namespace ndn {
32namespace ndncert {
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -070033namespace ca {
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070034
Zhiyi Zhang59812232020-10-12 13:11:35 -070035using namespace ndn::util;
Davide Pesaventob48bbda2020-07-27 19:41:37 -040036const std::string CaSqlite::STORAGE_TYPE = "ca-storage-sqlite3";
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070037
38NDNCERT_REGISTER_CA_STORAGE(CaSqlite);
39
Zhiyi Zhang59812232020-10-12 13:11:35 -070040std::string
41convertJson2String(const JsonSection& json)
42{
43 std::stringstream ss;
44 boost::property_tree::write_json(ss, json);
45 return ss.str();
46}
47
48JsonSection
49convertString2Json(const std::string& jsonContent)
50{
51 std::istringstream ss(jsonContent);
52 JsonSection json;
53 boost::property_tree::json_parser::read_json(ss, json);
54 return json;
55}
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070056
57static const std::string INITIALIZATION = R"_DBTEXT_(
58CREATE TABLE IF NOT EXISTS
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -070059 RequestStates(
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070060 id INTEGER PRIMARY KEY,
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -070061 request_id BLOB NOT NULL,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070062 ca_name BLOB NOT NULL,
tylerliu182bc532020-09-25 01:54:45 -070063 request_type INTEGER NOT NULL,
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070064 status INTEGER NOT NULL,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070065 cert_request BLOB NOT NULL,
66 challenge_type TEXT,
Zhiyi Zhanga749f442020-09-29 17:19:51 -070067 challenge_status TEXT,
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070068 challenge_tp TEXT,
69 remaining_tries INTEGER,
Zhiyi Zhang5f749a22019-06-12 17:02:33 -070070 remaining_time INTEGER,
tylerliu8e170d62020-09-30 01:31:53 -070071 challenge_secrets TEXT,
Zhiyi Zhang222810b2020-10-16 21:50:35 -070072 encryption_key BLOB NOT NULL,
Zhiyi Zhangf9d94eb2020-12-21 15:39:38 -080073 encryption_iv BLOB,
74 decryption_iv BLOB
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070075 );
76CREATE UNIQUE INDEX IF NOT EXISTS
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -070077 RequestStateIdIndex ON RequestStates(request_id);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070078)_DBTEXT_";
79
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070080CaSqlite::CaSqlite(const Name& caName, const std::string& path)
Zhiyi Zhanga749f442020-09-29 17:19:51 -070081 : CaStorage()
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070082{
83 // Determine the path of sqlite db
84 boost::filesystem::path dbDir;
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070085 if (!path.empty()) {
86 dbDir = boost::filesystem::path(path);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070087 }
88 else {
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070089 std::string dbName = caName.toUri();
90 std::replace(dbName.begin(), dbName.end(), '/', '_');
91 dbName += ".db";
92 if (getenv("HOME") != nullptr) {
93 dbDir = boost::filesystem::path(getenv("HOME")) / ".ndncert";
94 }
95 else {
96 dbDir = boost::filesystem::current_path() / ".ndncert";
97 }
98 boost::filesystem::create_directories(dbDir);
99 dbDir /= dbName;
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700100 }
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700101
102 // open and initialize database
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700103 int result = sqlite3_open_v2(dbDir.c_str(), &m_database,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700104 SQLITE_OPEN_READWRITE | SQLITE_OPEN_CREATE,
105#ifdef NDN_CXX_DISABLE_SQLITE3_FS_LOCKING
106 "unix-dotfile"
107#else
108 nullptr
109#endif
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700110 );
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700111 if (result != SQLITE_OK)
tylerliu41c11532020-10-10 16:14:45 -0700112 NDN_THROW(std::runtime_error("CaSqlite DB cannot be opened/created: " + dbDir.string()));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700113
114 // initialize database specific tables
115 char* errorMessage = nullptr;
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400116 result = sqlite3_exec(m_database, INITIALIZATION.data(),
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700117 nullptr, nullptr, &errorMessage);
118 if (result != SQLITE_OK && errorMessage != nullptr) {
119 sqlite3_free(errorMessage);
tylerliu41c11532020-10-10 16:14:45 -0700120 NDN_THROW(std::runtime_error("CaSqlite DB cannot be initialized"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700121 }
122}
123
124CaSqlite::~CaSqlite()
125{
126 sqlite3_close(m_database);
127}
128
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700129RequestState
Zhiyi Zhangc9ada1b2020-10-29 19:13:15 -0700130CaSqlite::getRequest(const RequestId& requestId)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700131{
132 Sqlite3Statement statement(m_database,
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700133 R"_SQLTEXT_(SELECT id, ca_name, status,
134 challenge_status, cert_request,
135 challenge_type, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700136 challenge_tp, remaining_tries, remaining_time,
Zhiyi Zhangf9d94eb2020-12-21 15:39:38 -0800137 request_type, encryption_key, encryption_iv, decryption_iv
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700138 FROM RequestStates where request_id = ?)_SQLTEXT_");
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700139 statement.bind(1, requestId.data(), requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700140
141 if (statement.step() == SQLITE_ROW) {
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800142 RequestState state;
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800143 state.requestId = requestId;
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800144 state.caPrefix = Name(statement.getBlock(1));
145 state.status = static_cast<Status>(statement.getInt(2));
146 state.cert = security::Certificate(statement.getBlock(4));
147 state.challengeType = statement.getString(5);
148 state.requestType = static_cast<RequestType>(statement.getInt(10));
149 std::memcpy(state.encryptionKey.data(), statement.getBlob(11), statement.getSize(11));
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800150 state.encryptionIv = std::vector<uint8_t>(statement.getBlob(12), statement.getBlob(12) + statement.getSize(12));
151 state.decryptionIv = std::vector<uint8_t>(statement.getBlob(13), statement.getBlob(13) + statement.getSize(13));
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800152 if (state.challengeType != "") {
153 ChallengeState challengeState(statement.getString(3), time::fromIsoString(statement.getString(7)),
154 statement.getInt(8), time::seconds(statement.getInt(9)),
155 convertString2Json(statement.getString(6)));
156 state.challengeState = challengeState;
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700157 }
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800158 return state;
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700159 }
160 else {
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800161 NDN_THROW(std::runtime_error("Request " + toHex(requestId.data(), requestId.size()) +
162 " cannot be fetched from database"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700163 }
164}
165
166void
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700167CaSqlite::addRequest(const RequestState& request)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700168{
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700169 Sqlite3Statement statement(
170 m_database,
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700171 R"_SQLTEXT_(INSERT OR ABORT INTO RequestStates (request_id, ca_name, status, request_type,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700172 cert_request, challenge_type, challenge_status, challenge_secrets,
Zhiyi Zhangf9d94eb2020-12-21 15:39:38 -0800173 challenge_tp, remaining_tries, remaining_time, encryption_key, encryption_iv, decryption_iv)
Zhiyi Zhang4f1c0102020-12-21 15:08:09 -0800174 values (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?))_SQLTEXT_");
tylerliu7b9185c2020-11-24 12:15:18 -0800175 statement.bind(1, request.requestId.data(), request.requestId.size(), SQLITE_TRANSIENT);
176 statement.bind(2, request.caPrefix.wireEncode(), SQLITE_TRANSIENT);
177 statement.bind(3, static_cast<int>(request.status));
178 statement.bind(4, static_cast<int>(request.requestType));
179 statement.bind(5, request.cert.wireEncode(), SQLITE_TRANSIENT);
180 statement.bind(12, request.encryptionKey.data(), request.encryptionKey.size(), SQLITE_TRANSIENT);
Zhiyi Zhang4f1c0102020-12-21 15:08:09 -0800181 statement.bind(13, request.encryptionIv.data(), request.encryptionIv.size(), SQLITE_TRANSIENT);
182 statement.bind(14, request.decryptionIv.data(), request.decryptionIv.size(), SQLITE_TRANSIENT);
tylerliu7b9185c2020-11-24 12:15:18 -0800183 if (request.challengeState) {
184 statement.bind(6, request.challengeType, SQLITE_TRANSIENT);
185 statement.bind(7, request.challengeState->challengeStatus, SQLITE_TRANSIENT);
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800186 statement.bind(8, convertJson2String(request.challengeState->secrets), SQLITE_TRANSIENT);
tylerliu7b9185c2020-11-24 12:15:18 -0800187 statement.bind(9, time::toIsoString(request.challengeState->timestamp), SQLITE_TRANSIENT);
188 statement.bind(10, request.challengeState->remainingTries);
189 statement.bind(11, request.challengeState->remainingTime.count());
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700190 }
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700191 if (statement.step() != SQLITE_DONE) {
Davide Pesaventoe5b43692021-11-15 22:05:03 -0500192 NDN_THROW(std::runtime_error("Request " + toHex(request.requestId.data(), request.requestId.size()) +
193 " cannot be added to database"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700194 }
195}
196
197void
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700198CaSqlite::updateRequest(const RequestState& request)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700199{
200 Sqlite3Statement statement(m_database,
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700201 R"_SQLTEXT_(UPDATE RequestStates
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700202 SET status = ?, challenge_type = ?, challenge_status = ?, challenge_secrets = ?,
Zhiyi Zhangf9d94eb2020-12-21 15:39:38 -0800203 challenge_tp = ?, remaining_tries = ?, remaining_time = ?, encryption_iv = ?, decryption_iv = ?
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700204 WHERE request_id = ?)_SQLTEXT_");
tylerliu7b9185c2020-11-24 12:15:18 -0800205 statement.bind(1, static_cast<int>(request.status));
206 statement.bind(2, request.challengeType, SQLITE_TRANSIENT);
207 if (request.challengeState) {
208 statement.bind(3, request.challengeState->challengeStatus, SQLITE_TRANSIENT);
209 statement.bind(4, convertJson2String(request.challengeState->secrets), SQLITE_TRANSIENT);
210 statement.bind(5, time::toIsoString(request.challengeState->timestamp), SQLITE_TRANSIENT);
211 statement.bind(6, request.challengeState->remainingTries);
212 statement.bind(7, request.challengeState->remainingTime.count());
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700213 }
214 else {
215 statement.bind(3, "", SQLITE_TRANSIENT);
216 statement.bind(4, "", SQLITE_TRANSIENT);
217 statement.bind(5, "", SQLITE_TRANSIENT);
218 statement.bind(6, 0);
219 statement.bind(7, 0);
220 }
Zhiyi Zhang4f1c0102020-12-21 15:08:09 -0800221 statement.bind(8, request.encryptionIv.data(), request.encryptionIv.size(), SQLITE_TRANSIENT);
222 statement.bind(9, request.decryptionIv.data(), request.decryptionIv.size(), SQLITE_TRANSIENT);
223 statement.bind(10, request.requestId.data(), request.requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700224
225 if (statement.step() != SQLITE_DONE) {
226 addRequest(request);
227 }
228}
229
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700230std::list<RequestState>
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700231CaSqlite::listAllRequests()
232{
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700233 std::list<RequestState> result;
tylerliu182bc532020-09-25 01:54:45 -0700234 Sqlite3Statement statement(m_database, R"_SQLTEXT_(SELECT id, request_id, ca_name, status,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700235 challenge_status, cert_request, challenge_type, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700236 challenge_tp, remaining_tries, remaining_time, request_type,
Zhiyi Zhangf9d94eb2020-12-21 15:39:38 -0800237 encryption_key, encryption_iv, decryption_iv
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700238 FROM RequestStates)_SQLTEXT_");
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400239 while (statement.step() == SQLITE_ROW) {
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800240 RequestState state;
241 std::memcpy(state.requestId.data(), statement.getBlob(1), statement.getSize(1));
242 state.caPrefix = Name(statement.getBlock(2));
243 state.status = static_cast<Status>(statement.getInt(3));
244 state.challengeType = statement.getString(6);
245 state.cert = security::Certificate(statement.getBlock(5));
246 state.requestType = static_cast<RequestType>(statement.getInt(11));
247 std::memcpy(state.encryptionKey.data(), statement.getBlob(12), statement.getSize(12));
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800248 state.encryptionIv = std::vector<uint8_t>(statement.getBlob(13), statement.getBlob(13) + statement.getSize(13));
249 state.decryptionIv = std::vector<uint8_t>(statement.getBlob(14), statement.getBlob(14) + statement.getSize(14));
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800250 if (state.challengeType != "") {
251 ChallengeState challengeState(statement.getString(4), time::fromIsoString(statement.getString(8)),
252 statement.getInt(9), time::seconds(statement.getInt(10)),
253 convertString2Json(statement.getString(7)));
254 state.challengeState = challengeState;
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700255 }
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800256 result.push_back(state);
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700257 }
258 return result;
259}
260
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700261std::list<RequestState>
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700262CaSqlite::listAllRequests(const Name& caName)
263{
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700264 std::list<RequestState> result;
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700265 Sqlite3Statement statement(m_database,
tylerliu182bc532020-09-25 01:54:45 -0700266 R"_SQLTEXT_(SELECT id, request_id, ca_name, status,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700267 challenge_status, cert_request, challenge_type, challenge_secrets,
Zhiyi Zhang1f9551b2020-10-30 10:30:43 -0700268 challenge_tp, remaining_tries, remaining_time, request_type,
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800269 encryption_key, encryption_iv, decryption_iv
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700270 FROM RequestStates WHERE ca_name = ?)_SQLTEXT_");
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700271 statement.bind(1, caName.wireEncode(), SQLITE_TRANSIENT);
272
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400273 while (statement.step() == SQLITE_ROW) {
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800274 RequestState state;
275 std::memcpy(state.requestId.data(), statement.getBlob(1), statement.getSize(1));
276 state.caPrefix = Name(statement.getBlock(2));
277 state.status = static_cast<Status>(statement.getInt(3));
278 state.challengeType = statement.getString(6);
279 state.cert = security::Certificate(statement.getBlock(5));
280 state.requestType = static_cast<RequestType>(statement.getInt(11));
281 std::memcpy(state.encryptionKey.data(), statement.getBlob(12), statement.getSize(12));
Zhiyi Zhang48f546f2020-12-24 17:31:02 -0800282 state.encryptionIv = std::vector<uint8_t>(statement.getBlob(13), statement.getBlob(13) + statement.getSize(13));
283 state.decryptionIv = std::vector<uint8_t>(statement.getBlob(14), statement.getBlob(14) + statement.getSize(14));
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800284 if (state.challengeType != "") {
285 ChallengeState challengeState(statement.getString(4), time::fromIsoString(statement.getString(8)),
286 statement.getInt(9), time::seconds(statement.getInt(10)),
287 convertString2Json(statement.getString(7)));
288 state.challengeState = challengeState;
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700289 }
Zhiyi Zhang1f5e86e2020-12-04 15:07:57 -0800290 result.push_back(state);
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700291 }
292 return result;
293}
294
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700295void
Zhiyi Zhangc9ada1b2020-10-29 19:13:15 -0700296CaSqlite::deleteRequest(const RequestId& requestId)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700297{
298 Sqlite3Statement statement(m_database,
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700299 R"_SQLTEXT_(DELETE FROM RequestStates WHERE request_id = ?)_SQLTEXT_");
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700300 statement.bind(1, requestId.data(), requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700301 statement.step();
302}
303
Zhiyi Zhang32d4b4e2020-10-28 22:10:49 -0700304} // namespace ca
Zhiyi Zhange4891b72020-10-10 15:11:57 -0700305} // namespace ndncert
306} // namespace ndn