+
+/**
+ * Gets the the Persistent Storage Database size
+ *
+ * @param ps - pointer of OCPersistentStorage for the Secure Virtual Resource(s)
+ *
+ * @return size_t - total size of the SVR database
+ */
+static size_t GetPSIDatabaseSize(const OCPersistentStorage *ps)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+
+ if (!ps)
+ {
+ return 0;
+ }
+
+ if (!g_svrDbFileSize)
+ {
+ size_t size = 0;
+ char buffer[DB_FILE_SIZE_BLOCK]; // can not initialize with declaration
+ // but maybe not needed to initialize
+ FILE *fp = ps->open(SVR_DB_DAT_FILE_NAME, "rb");
+ if (fp)
+ {
+ size_t bytesRead = 0;
+ do
+ {
+ bytesRead = ps->read(buffer, 1, DB_FILE_SIZE_BLOCK, fp);
+ size += bytesRead;
+ } while (bytesRead);
+ ps->close(fp);
+ }
+ else
+ {
+ OIC_LOG_V(ERROR, TAG, "%s: File open failed.", __func__);
+ }
+
+ UpdateSizePSI(size);
+ }
+ else
+ {
+ OIC_LOG_V(INFO, TAG, "%s get size from cache", __func__);
+ }
+
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+
+ return g_svrDbFileSize;
+}
+
+#ifdef __SECURE_PSI__
+static OCStackResult getPlaintextFromDB(const OCPersistentStorage *ps, uint8_t **pt,
+ size_t *pt_len)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+ OCStackResult ret = OC_STACK_ERROR;
+
+ uint8_t *plaintext = NULL;
+
+ FILE *fp = NULL;
+ fp = ps->open(SVR_DB_DAT_FILE_NAME, "rb");
+ if (NULL == fp)
+ {
+ OIC_LOG(ERROR, TAG, "ps->open() Failed");
+ return OC_STACK_ERROR;
+ }
+
+ // Get fileSize of plaintext
+ char buffer[DB_FILE_SIZE_BLOCK];
+ size_t bytesRead = 0;
+ size_t fileSize = 0;
+ do
+ {
+ bytesRead = ps->read(buffer, 1, DB_FILE_SIZE_BLOCK, fp);
+ fileSize += bytesRead;
+ } while (bytesRead);
+
+ // Get plaintext
+ ret = OC_STACK_NO_MEMORY;
+ plaintext = (uint8_t*)OICCalloc(1, fileSize);
+ VERIFY_NON_NULL(TAG, plaintext, ERROR);
+
+ ps->close(fp);
+ fp = ps->open(SVR_DB_DAT_FILE_NAME, "rb");
+ if (NULL == fp)
+ {
+ OIC_LOG(ERROR, TAG, "ps->open() Failed");
+ return OC_STACK_ERROR;
+ }
+
+ if (fileSize != ps->read(plaintext, 1, fileSize, fp))
+ {
+ OIC_LOG_V(ERROR, TAG, "ps->read() Failed");
+ ret = OC_STACK_ERROR;
+ goto exit;
+ }
+
+ *pt = plaintext;
+ *pt_len = fileSize;
+ ps->close(fp);
+
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+
+ return OC_STACK_OK;
+exit:
+ OICFree(plaintext);
+ if (fp)
+ {
+ ps->close(fp);
+ }
+ return ret;
+}
+
+static OCStackResult OTEncrypt(const OCPersistentStorage *psForPlain,
+ const OCPersistentStorage *psForEncrypted)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+
+ uint8_t *plaintext = NULL;
+ size_t pt_len = 0;
+ OCStackResult ret = getPlaintextFromDB(psForPlain, &plaintext, &pt_len);
+ if (OC_STACK_OK != ret)
+ {
+ OIC_LOG(ERROR, TAG, "getPlaintextFromDB() Failed");
+ return ret;
+ }
+
+ // Encrypt plaintext
+ uint8_t *ciphertext = NULL;
+ size_t ct_len = 0;
+ if (0 != psForEncrypted->encrypt(plaintext, pt_len, &ciphertext, &ct_len))
+ {
+ OIC_LOG(ERROR, TAG, "psForEncrypted->encrypt() Failed");
+ OICFree(plaintext);
+ return OC_STACK_ERROR;
+ }
+ OICFree(plaintext);
+
+ // Write Ciphertext
+ FILE *fp2 = psForEncrypted->open(SVR_DB_DAT_FILE_NAME, "wb");
+ if (NULL == fp2)
+ {
+ OIC_LOG(ERROR, TAG, "psForEncrypted->open() Failed");
+ OICFree(ciphertext);
+ return OC_STACK_ERROR;
+ }
+
+ if (ct_len != psForEncrypted->write(ciphertext, 1, ct_len, fp2))
+ {
+ OIC_LOG(ERROR, TAG, "psForEncrypted->write() Failed");
+ OICFree(ciphertext);
+ return OC_STACK_ERROR;
+ }
+ psForEncrypted->close(fp2);
+
+ // Remove plain DB
+ if (psForPlain->unlink)
+ {
+ psForPlain->unlink(SVR_DB_DAT_FILE_NAME);
+ }
+
+ OICFree(ciphertext);
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+
+ return OC_STACK_OK;
+}
+
+OCStackResult setSecurePSI(const unsigned char *key, const OCPersistentStorage *psPlain,
+ const OCPersistentStorage *psEnc, const OCPersistentStorage *psRescue)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+
+ if (!key || !psEnc)
+ {
+ OIC_LOG_V(ERROR, TAG, "%s: %s is NULL", __func__, !key ? "key" : "psEnc");
+ return OC_STACK_INVALID_PARAM;
+ }
+ if (!(psEnc->encrypt && psEnc->decrypt))
+ {
+ OIC_LOG(ERROR, TAG, "psEnc->encrypt && psEnc->decrypt should be set");
+ return OC_STACK_INVALID_PARAM;
+ }
+ if (psPlain && !(psPlain->open && psPlain->read && psPlain->close
+ && psPlain->unlink))
+ {
+ OIC_LOG(ERROR, TAG, "open/read/close/unlink funcion for plain should be set");
+ return OC_STACK_INVALID_PARAM;
+ }
+ if (psRescue && !(psRescue->open && psRescue->read && psRescue->close))
+ {
+ OIC_LOG(ERROR, TAG, "open/read/close funcion for rescue should be set");
+ return OC_STACK_INVALID_PARAM;
+ }
+
+ OCStackResult ret;
+ ret = psiSetKey(key);
+ if (OC_STACK_OK != ret)
+ {
+ OIC_LOG(ERROR, TAG, "psiSetKey() Failed");
+ return ret;
+ }
+ OIC_LOG(DEBUG, TAG, "key is set");
+
+ // if there is new plain db
+ FILE *fp = NULL;
+ if (psPlain && (fp = psPlain->open(SVR_DB_DAT_FILE_NAME, "rb")))
+ {
+ psPlain->close(fp);
+ fp = NULL;
+
+ ret = OTEncrypt(psPlain, psEnc);
+ if (OC_STACK_OK != ret)
+ {
+ OIC_LOG(ERROR, TAG, "OTEncrypt() Failed");
+ return ret;
+ }
+ }
+
+ // check ps & rescue
+ if (psRescue)
+ {
+ ret = CheckPersistentStorage((OCPersistentStorage*)psEnc);
+ if (OC_STACK_OK != ret)
+ {
+ fp = psRescue->open(SVR_DB_DAT_FILE_NAME, "rb");
+ if (NULL == fp)
+ {
+ OIC_LOG(ERROR, TAG, "psRescue->open() Failed");
+ return OC_STACK_ERROR;
+ }
+ psRescue->close(fp);
+ fp = NULL;
+
+ ret = OTEncrypt(psRescue, psEnc);
+ if (OC_STACK_OK != ret)
+ {
+ OIC_LOG_V(ERROR, TAG, "ps is currupted but NOT rescued(%d)", ret);
+ return ret;
+ }
+ OIC_LOG(INFO, TAG, "ps is currupted and rescued");
+ }
+ }
+
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+
+ return OC_STACK_OK;
+
+}
+#endif // __SECURE_PSI__
+
+/**
+ * Write the Persistent Storage
+ *
+ * @param payload - pointer of payload
+ * @param psize - size of payload
+ *
+ * @return OCStackResult - OC_STACK_OK sucsess, other - OC_STACK_ERROR
+ */
+OCStackResult WritePSIDatabase(const uint8_t *payload, size_t size)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+
+ if (!payload || !size || !g_mutexDb)
+ {
+ OIC_LOG_V(ERROR, TAG, "%s: %s is NULL",
+ __func__, !payload ? "payload" : !size ? "size" : "mutex");
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+ return OC_STACK_INVALID_PARAM;
+ }
+
+ OCPersistentStorage *ps = NULL;
+ FILE *fp = NULL;
+ OCStackResult ret = OC_STACK_SVR_DB_NOT_EXIST;
+
+ ps = SRMGetPersistentStorageHandler();
+ VERIFY_NON_NULL(TAG, ps, ERROR);
+
+#ifdef __SECURE_PSI__
+ if (psiIsKeySet() && ps->encrypt && ps->decrypt)
+ {
+ OIC_LOG(DEBUG, TAG, "ps->encrypt !");
+
+ uint8_t *ciphertext = NULL;
+ size_t ct_len = 0;
+
+ if (0 != ps->encrypt(payload, size, &ciphertext, &ct_len))
+ {
+ OIC_LOG(ERROR, TAG, "ps->encrypt() Failed");
+ ret = OC_STACK_ERROR;
+ goto exit;
+ }
+
+ payload = ciphertext;
+ size = ct_len;
+ }
+#endif // __SECURE_PSI__
+
+ OIC_LOG_V(INFO, TAG, "Writing in the file: %zu", size);
+
+ fp = ps->open(SVR_DB_DAT_FILE_NAME, "wb");
+ VERIFY_NON_NULL(TAG, fp, ERROR);
+
+ oc_mutex_lock(g_mutexDb);
+ g_svrDbFileSize = ps->write(payload, 1, size, fp);
+ ps->close(fp);
+ oc_mutex_unlock(g_mutexDb);
+
+#ifdef __SECURE_PSI__
+ if (psiIsKeySet() && ps->encrypt && ps->decrypt)
+ {
+ OICFree((uint8_t*)payload);
+ }
+#endif // __SECURE_PSI__
+ if (size == g_svrDbFileSize)
+ {
+ OIC_LOG_V(INFO, TAG, "Written %zu bytes into SVR database file", size);
+ ret = OC_STACK_OK;
+ }
+ else
+ {
+ OIC_LOG_V(ERROR, TAG, "Failed writing %zu in the database", g_svrDbFileSize);
+ }
+
+exit:
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+ return ret;
+}
+
+/**
+ * Gets the Secure Virtual Database from the Persistent Storage
+ *
+ * @param ps - Persistent Storage handler
+ * @param rsrcName - pointer of character string for the SVR name (e.g. "acl")
+ * @param data - pointer of the returned Secure Virtual Resource(s)
+ * @param size - pointer of the returned size of Secure Virtual Resource(s)
+ *
+ * @return OCStackResult - result of getting Secure Virtual Resource(s)
+ */
+OCStackResult GetSecureVirtualDatabaseFromPS2(OCPersistentStorage* ps, const char *rsrcName, uint8_t **data, size_t *size)
+{
+ OIC_LOG_V(DEBUG, TAG, "In %s", __func__);
+
+ if (!data || *data || !size || !ps)
+ {
+ OIC_LOG_V(ERROR, TAG, "%s: %s is NULL",
+ __func__, !data || *data ? "data" : !size ? "size" : "ps");
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+ return OC_STACK_INVALID_PARAM;
+ }
+
+ FILE *fp = NULL;
+ uint8_t *fsData = NULL;
+ size_t fileSize = 0;
+ OCStackResult ret = OC_STACK_ERROR;
+
+ fileSize = GetPSIDatabaseSizeWithoutCaching(ps);
+ OIC_LOG_V(INFO, TAG, "File Read Size: %zu", fileSize);
+ if (fileSize)
+ {
+ fsData = (uint8_t *) OICCalloc(1, fileSize + 1);
+ VERIFY_NON_NULL(TAG, fsData, ERROR);
+
+ fp = ps->open(SVR_DB_DAT_FILE_NAME, "rb");
+ VERIFY_NON_NULL(TAG, fp, ERROR);
+ if (ps->read(fsData, 1, fileSize, fp) == fileSize)
+ {
+#ifdef __SECURE_PSI__
+ if (psiIsKeySet() && ps->encrypt && ps->decrypt)
+ {
+ OIC_LOG(DEBUG, TAG, "ps->decrypt !");
+
+ unsigned char *plainData = NULL;
+ size_t plainSize = 0;
+
+ if (0 != ps->decrypt(fsData, fileSize, &plainData, &plainSize))
+ {
+ OIC_LOG(ERROR, TAG, "ps->decrypt() Failed");
+ ret = OC_STACK_ERROR;
+ goto exit;
+ }
+ OICFree(fsData);
+ fsData = plainData;
+ fileSize = plainSize;
+ }
+#endif // __SECURE_PSI__
+ if (rsrcName)
+ {
+ CborParser parser; // will be initialized in |cbor_parser_init|
+ CborValue cbor; // will be initialized in |cbor_parser_init|
+ cbor_parser_init(fsData, fileSize, 0, &parser, &cbor);
+ CborValue cborValue = {0};
+ CborError cborFindResult = cbor_value_map_find_value(&cbor, rsrcName, &cborValue);
+ if (CborNoError == cborFindResult && cbor_value_is_byte_string(&cborValue))
+ {
+ cborFindResult = cbor_value_dup_byte_string(&cborValue, data, size, NULL);
+ VERIFY_SUCCESS(TAG, CborNoError==cborFindResult, ERROR);
+ ret = OC_STACK_OK;
+ }
+ // in case of |else (...)|, svr_data not found
+ }
+ // return everything in case rsrcName is NULL
+ else
+ {
+ *size = fileSize;
+ *data = (uint8_t *) OICCalloc(1, fileSize);
+ VERIFY_NON_NULL(TAG, *data, ERROR);
+ memcpy(*data, fsData, fileSize);
+ ret = OC_STACK_OK;
+ }
+ }
+ }
+ OIC_LOG_V(DEBUG, TAG, "Out %s", __func__);
+
+exit:
+ if (fp)
+ {
+ ps->close(fp);
+ }
+ OICFree(fsData);
+ return ret;
+}
+