Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); iOS: Enable System.Net.Security.Native and parts of System.Security.Cryptography.Native.Apple by akoeplinger · Pull Request #33970 · dotnet/runtime · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/libraries/Native/Unix/CMakeLists.txt
Original file line numberDiff line numberDiff line change
Expand Up@@ -197,13 +197,13 @@ add_subdirectory(System.Native)

if (NOT CLR_CMAKE_TARGET_ARCH_WASM AND NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable for iOS
add_subdirectory(System.Globalization.Native)
add_subdirectory(System.Net.Security.Native)

# disable System.Security.Cryptography.Native build on iOS,
# only used for interacting with OpenSSL which isn't useful there
add_subdirectory(System.Security.Cryptography.Native)
endif()

if(CLR_CMAKE_TARGET_OSX OR CLR_CMAKE_TARGET_IOS)
add_subdirectory(System.Net.Security.Native)
add_subdirectory(System.Security.Cryptography.Native.Apple)
endif()
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,26 +5,24 @@ find_library(SECURITY_LIBRARY Security)

set(NATIVECRYPTO_SOURCES
pal_digest.c
pal_ecc.c
pal_hmac.c
pal_keyagree.c
pal_keychain.c
pal_random.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_symmetric.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)

if (NOT CLR_CMAKE_TARGET_IOS) # TODO: reenable more sources
set(NATIVECRYPTO_SOURCES
${NATIVECRYPTO_SOURCES}
pal_ecc.c
pal_keyagree.c
pal_keychain.c
pal_rsa.c
pal_sec.c
pal_seckey.c
pal_signverify.c
pal_ssl.c
pal_trust.c
pal_x509.c
pal_x509chain.c
)
if (CLR_CMAKE_TARGET_IOS)
add_definitions(-DTARGET_IOS)
endif()

add_library(System.Security.Cryptography.Native.Apple
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_ecc.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_EccGenerateKey(
int32_t keySizeBits, SecKeychainRef tempKeychain, SecKeyRef* pPublicKey, SecKeyRef* pPrivateKey, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -51,6 +52,7 @@ int32_t AppleCryptoNative_EccGenerateKey(
*pOSStatus = status;
return status == noErr;
}
#endif

uint64_t AppleCryptoNative_EccGetKeySizeInBits(SecKeyRef publicKey)
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate an ECC keypair of the specified size.

Expand All@@ -19,6 +20,7 @@ PALEXPORT int32_t AppleCryptoNative_EccGenerateKey(int32_t keySizeBits,
SecKeyRef* pPublicKey,
SecKeyRef* pPrivateKey,
int32_t* pOSStatus);
#endif

/*
Get the keysize, in bits, of an ECC key.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_keychain.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeychainItemCopyKeychain(SecKeychainItemRef item, SecKeychainRef* pKeychainOut)
{
if (pKeychainOut != NULL)
Expand DownExpand Up@@ -465,3 +466,4 @@ AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeycha
CFRelease(cert);
return *pOSStatus == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get a CFRetain()ed SecKeychainRef value for the keychain to which the keychain item belongs.

Expand DownExpand Up@@ -137,3 +138,4 @@ pOSStatus: Receives the last OSStatus value..
*/
PALEXPORT int32_t
AppleCryptoNative_X509StoreRemoveCertificate(CFTypeRef certOrIdentity, SecKeychainRef keychain, uint8_t isReadOnlyMode, int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_rsa.h"

#ifndef TARGET_IOS
static int32_t ExecuteCFDataTransform(
SecTransformRef xform, uint8_t* pbData, int32_t cbData, CFDataRef* pDataOut, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -267,6 +268,7 @@ static int32_t ExecuteCFDataTransform(

return ret;
}
#endif

static int32_t RsaPrimitive(SecKeyRef key,
uint8_t* pbData,
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a new RSA keypair with the specified key size, in bits.

Expand DownExpand Up@@ -60,6 +61,7 @@ Follows pal_seckey return conventions.
*/
PALEXPORT int32_t AppleCryptoNative_RsaEncryptPkcs(
SecKeyRef publicKey, uint8_t* pbData, int32_t cbData, CFDataRef* pEncryptedOut, CFErrorRef* pErrorOut);
#endif

/*
Apply an RSA private key to a signing operation on data which was already padded.
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,7 +4,9 @@

#include "pal_sec.h"

#ifndef TARGET_IOS
CFStringRef AppleCryptoNative_SecCopyErrorMessageString(int32_t osStatus)
{
return SecCopyErrorMessageString(osStatus, NULL);
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,9 +10,11 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Get an error message for an OSStatus error from the security library.

Returns NULL if no message is available for the code.
*/
PALEXPORT CFStringRef AppleCryptoNative_SecCopyErrorMessageString(OSStatus osStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_seckey.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
int32_t AppleCryptoNative_SecKeyExport(
SecKeyRef pKey, int32_t exportPrivate, CFStringRef cfExportPassphrase, CFDataRef* ppDataOut, int32_t* pOSStatus)
{
Expand DownExpand Up@@ -128,6 +129,7 @@ int32_t AppleCryptoNative_SecKeyImportEphemeral(
CFRelease(cfData);
return ret;
}
#endif

uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
{
Expand All@@ -139,6 +141,7 @@ uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey)
return SecKeyGetBlockSize(publicKey);
}

#ifndef TARGET_IOS
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)
{
SecExternalFormat dataFormat = kSecFormatOpenSSL;
Expand DownExpand Up@@ -197,3 +200,4 @@ OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type)

return status;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,6 +17,7 @@ static const int32_t kErrorSeeError = -2;
static const int32_t kErrorUnknownAlgorithm = -3;
static const int32_t kErrorUnknownState = -4;

#ifndef TARGET_IOS
/*
Export a key object.

Expand DownExpand Up@@ -48,6 +49,7 @@ state machine errors.
*/
PALEXPORT int32_t AppleCryptoNative_SecKeyImportEphemeral(
uint8_t* pbKeyBlob, int32_t cbKeyBlob, int32_t isPrivateKey, SecKeyRef* ppKeyOut, int32_t* pOSStatus);
#endif

/*
For RSA and DSA this function returns the number of bytes in "the key", which corresponds to
Expand All@@ -59,9 +61,11 @@ For ECC the value should not be used.
*/
PALEXPORT uint64_t AppleCryptoNative_SecKeyGetSimpleKeySizeInBytes(SecKeyRef publicKey);

#ifndef TARGET_IOS
/*
Export a key and re-import it to the NULL keychain.

Only internal callers are expected.
*/
OSStatus ExportImportKey(SecKeyRef* key, SecExternalItemType type);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -4,6 +4,7 @@

#include "pal_signverify.h"

#ifndef TARGET_IOS
static int32_t ExecuteSignTransform(SecTransformRef signer, CFDataRef* pSignatureOut, CFErrorRef* pErrorOut);
static int32_t ExecuteVerifyTransform(SecTransformRef verifier, CFErrorRef* pErrorOut);

Expand DownExpand Up@@ -285,3 +286,4 @@ static int32_t ConfigureSignVerifyTransform(SecTransformRef xform,

return 1;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,6 +10,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Generate a signature for algorithms which require only the data hash blob, like DSA and ECDSA.

Expand DownExpand Up@@ -56,3 +57,4 @@ PALEXPORT int32_t AppleCryptoNative_VerifySignature(SecKeyRef publicKey,
uint8_t* pbSignature,
int32_t cbSignature,
CFErrorRef* pErrorOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -585,6 +585,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
// Max numCipherSuites is 2^16 (all possible cipher suites)
assert(numCipherSuites < (1 << 16));

#ifndef TARGET_IOS
if (sizeof(SSLCipherSuite) == sizeof(uint32_t))
{
#pragma clang diagnostic push
Expand All@@ -594,6 +595,7 @@ int32_t AppleCryptoNative_SslSetEnabledCipherSuites(SSLContextRef sslContext, co
#pragma clang diagnostic pop
}
else
#endif
{
// iOS, tvOS, watchOS
SSLCipherSuite* cipherSuites16 = (SSLCipherSuite*)calloc((size_t)numCipherSuites, sizeof(SSLCipherSuite));
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,6 +6,7 @@

#include "pal_compiler.h"
#include <Security/Security.h>
#include <Security/SecureTransport.h>

enum
{
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@
#include "pal_trust.h"
#include "pal_utilities.h"

#ifndef TARGET_IOS
static bool CheckTrustMatch(SecCertificateRef cert,
SecTrustSettingsDomain domain,
SecTrustSettingsResult result,
Expand DownExpand Up@@ -245,3 +246,4 @@ int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut,

return ret;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -9,6 +9,7 @@

#include <Security/Security.h>

#ifndef TARGET_IOS
/*
Enumerate the certificates which are root trusted by the user.

Expand DownExpand Up@@ -62,3 +63,4 @@ pCertsOut: When the return value is not 1, NULL. Otherwise NULL on "no certs fou
pOSStatus: Receives the last OSStatus value.
*/
PALEXPORT int32_t AppleCryptoNative_StoreEnumerateMachineDisallowed(CFArrayRef* pCertsOut, int32_t* pOSStatusOut);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -108,6 +108,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}

#ifndef TARGET_IOS
SecExternalFormat dataFormat = kSecFormatPKCS7;
SecExternalFormat actualFormat = dataFormat;
SecExternalItemType itemType = kSecItemTypeAggregate;
Expand DownExpand Up@@ -175,6 +176,7 @@ PAL_X509ContentType AppleCryptoNative_X509GetContentType(uint8_t* pbData, int32_
return PAL_Certificate;
}
}
#endif

CFRelease(cfData);
return PAL_X509Unknown;
Expand DownExpand Up@@ -256,6 +258,7 @@ int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity
return SecIdentityCopyPrivateKey(identity, pPrivateKeyOut);
}

#ifndef TARGET_IOS
static int32_t ReadX509(uint8_t* pbData,
int32_t cbData,
PAL_X509ContentType contentType,
Expand DownExpand Up@@ -914,3 +917,4 @@ int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
*pOSStatus = status;
return status == noErr;
}
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,6 +74,7 @@ pPrivateKeyOut: Receives a SecKeyRef for the private key associated with the ide
*/
PALEXPORT int32_t AppleCryptoNative_X509CopyPrivateKeyFromIdentity(SecIdentityRef identity, SecKeyRef* pPrivateKeyOut);

#ifndef TARGET_IOS
/*
Read cbData bytes of data from pbData and interpret it to a collection of certificates (or identities).

Expand DownExpand Up@@ -191,3 +192,4 @@ PALEXPORT int32_t AppleCryptoNative_X509MoveToKeychain(SecCertificateRef cert,
SecKeyRef privateKey,
SecIdentityRef* pIdentityOut,
int32_t* pOSStatus);
#endif
Original file line numberDiff line numberDiff line change
Expand Up@@ -42,8 +42,8 @@ enum
typedef uint32_t PAL_X509ChainStatusFlags;

#define PAL_X509ChainErrorNone 0
#define PAL_X509ChainErrorUnknownValueType 0x0001L << 32
#define PAL_X509ChainErrorUnknownValue 0x0002L << 32
#define PAL_X509ChainErrorUnknownValueType (((uint64_t)0x0001L) << 32)
#define PAL_X509ChainErrorUnknownValue (((uint64_t)0x0002L) << 32)
typedef uint64_t PAL_X509ChainErrorFlags;

/*
Expand Down