|
| 1 | +const std = @import("std"); |
| 2 | +const assert = std.debug.assert; |
| 3 | +const mem = std.mem; |
| 4 | +const fs = std.fs; |
| 5 | +const Allocator = std.mem.Allocator; |
| 6 | +const Bundle = @import("../Bundle.zig"); |
| 7 | + |
| 8 | +pub fn rescanMac(cb: *Bundle, gpa: Allocator) !void { |
| 9 | + const file = try fs.openFileAbsolute("/System/Library/Keychains/SystemRootCertificates.keychain", .{}); |
| 10 | + defer file.close(); |
| 11 | + |
| 12 | + const bytes = try file.readToEndAlloc(gpa, std.math.maxInt(u32)); |
| 13 | + defer gpa.free(bytes); |
| 14 | + |
| 15 | + var stream = std.io.fixedBufferStream(bytes); |
| 16 | + const reader = stream.reader(); |
| 17 | + |
| 18 | + const db_header = try reader.readStructBig(ApplDbHeader); |
| 19 | + assert(mem.eql(u8, "kych", &@bitCast([4]u8, db_header.signature))); |
| 20 | + |
| 21 | + try stream.seekTo(db_header.schema_offset); |
| 22 | + |
| 23 | + const db_schema = try reader.readStructBig(ApplDbSchema); |
| 24 | + |
| 25 | + var table_list = try gpa.alloc(u32, db_schema.table_count); |
| 26 | + defer gpa.free(table_list); |
| 27 | + |
| 28 | + var table_idx: u32 = 0; |
| 29 | + while (table_idx < table_list.len) : (table_idx += 1) { |
| 30 | + table_list[table_idx] = try reader.readIntBig(u32); |
| 31 | + } |
| 32 | + |
| 33 | + const now_sec = std.time.timestamp(); |
| 34 | + |
| 35 | + for (table_list) |table_offset| { |
| 36 | + try stream.seekTo(db_header.schema_offset + table_offset); |
| 37 | + |
| 38 | + const table_header = try reader.readStructBig(TableHeader); |
| 39 | + |
| 40 | + if (@intToEnum(TableId, table_header.table_id) != TableId.CSSM_DL_DB_RECORD_X509_CERTIFICATE) { |
| 41 | + continue; |
| 42 | + } |
| 43 | + |
| 44 | + var record_list = try gpa.alloc(u32, table_header.record_count); |
| 45 | + defer gpa.free(record_list); |
| 46 | + |
| 47 | + var record_idx: u32 = 0; |
| 48 | + while (record_idx < record_list.len) : (record_idx += 1) { |
| 49 | + record_list[record_idx] = try reader.readIntBig(u32); |
| 50 | + } |
| 51 | + |
| 52 | + for (record_list) |record_offset| { |
| 53 | + try stream.seekTo(db_header.schema_offset + table_offset + record_offset); |
| 54 | + |
| 55 | + const cert_header = try reader.readStructBig(X509CertHeader); |
| 56 | + |
| 57 | + try cb.bytes.ensureUnusedCapacity(gpa, cert_header.cert_size); |
| 58 | + |
| 59 | + const cert_start = @intCast(u32, cb.bytes.items.len); |
| 60 | + const dest_buf = cb.bytes.allocatedSlice()[cert_start..]; |
| 61 | + cb.bytes.items.len += try reader.readAtLeast(dest_buf, cert_header.cert_size); |
| 62 | + |
| 63 | + try cb.parseCert(gpa, cert_start, now_sec); |
| 64 | + } |
| 65 | + } |
| 66 | +} |
| 67 | + |
| 68 | +const ApplDbHeader = extern struct { |
| 69 | + signature: @Vector(4, u8), |
| 70 | + version: u32, |
| 71 | + header_size: u32, |
| 72 | + schema_offset: u32, |
| 73 | + auth_offset: u32, |
| 74 | +}; |
| 75 | + |
| 76 | +const ApplDbSchema = extern struct { |
| 77 | + schema_size: u32, |
| 78 | + table_count: u32, |
| 79 | +}; |
| 80 | + |
| 81 | +const TableHeader = extern struct { |
| 82 | + table_size: u32, |
| 83 | + table_id: u32, |
| 84 | + record_count: u32, |
| 85 | + records: u32, |
| 86 | + indexes_offset: u32, |
| 87 | + free_list_head: u32, |
| 88 | + record_numbers_count: u32, |
| 89 | +}; |
| 90 | + |
| 91 | +const TableId = enum(u32) { |
| 92 | + CSSM_DL_DB_SCHEMA_INFO = 0x00000000, |
| 93 | + CSSM_DL_DB_SCHEMA_INDEXES = 0x00000001, |
| 94 | + CSSM_DL_DB_SCHEMA_ATTRIBUTES = 0x00000002, |
| 95 | + CSSM_DL_DB_SCHEMA_PARSING_MODULE = 0x00000003, |
| 96 | + |
| 97 | + CSSM_DL_DB_RECORD_ANY = 0x0000000a, |
| 98 | + CSSM_DL_DB_RECORD_CERT = 0x0000000b, |
| 99 | + CSSM_DL_DB_RECORD_CRL = 0x0000000c, |
| 100 | + CSSM_DL_DB_RECORD_POLICY = 0x0000000d, |
| 101 | + CSSM_DL_DB_RECORD_GENERIC = 0x0000000e, |
| 102 | + CSSM_DL_DB_RECORD_PUBLIC_KEY = 0x0000000f, |
| 103 | + CSSM_DL_DB_RECORD_PRIVATE_KEY = 0x00000010, |
| 104 | + CSSM_DL_DB_RECORD_SYMMETRIC_KEY = 0x00000011, |
| 105 | + CSSM_DL_DB_RECORD_ALL_KEYS = 0x00000012, |
| 106 | + |
| 107 | + CSSM_DL_DB_RECORD_GENERIC_PASSWORD = 0x80000000, |
| 108 | + CSSM_DL_DB_RECORD_INTERNET_PASSWORD = 0x80000001, |
| 109 | + CSSM_DL_DB_RECORD_APPLESHARE_PASSWORD = 0x80000002, |
| 110 | + CSSM_DL_DB_RECORD_USER_TRUST = 0x80000003, |
| 111 | + CSSM_DL_DB_RECORD_X509_CRL = 0x80000004, |
| 112 | + CSSM_DL_DB_RECORD_UNLOCK_REFERRAL = 0x80000005, |
| 113 | + CSSM_DL_DB_RECORD_EXTENDED_ATTRIBUTE = 0x80000006, |
| 114 | + CSSM_DL_DB_RECORD_X509_CERTIFICATE = 0x80001000, |
| 115 | + CSSM_DL_DB_RECORD_METADATA = 0x80008000, |
| 116 | + |
| 117 | + _, |
| 118 | +}; |
| 119 | + |
| 120 | +const X509CertHeader = extern struct { |
| 121 | + record_size: u32, |
| 122 | + record_number: u32, |
| 123 | + unknown1: u32, |
| 124 | + unknown2: u32, |
| 125 | + cert_size: u32, |
| 126 | + unknown3: u32, |
| 127 | + cert_type: u32, |
| 128 | + cert_encoding: u32, |
| 129 | + print_name: u32, |
| 130 | + alias: u32, |
| 131 | + subject: u32, |
| 132 | + issuer: u32, |
| 133 | + serial_number: u32, |
| 134 | + subject_key_identifier: u32, |
| 135 | + public_key_hash: u32, |
| 136 | +}; |
0 commit comments