1*5c2921b0SApple OSS Distributions #ifndef _CHUNKLIST_H 2*5c2921b0SApple OSS Distributions #define _CHUNKLIST_H 3*5c2921b0SApple OSS Distributions 4*5c2921b0SApple OSS Distributions #include <libkern/crypto/sha2.h> 5*5c2921b0SApple OSS Distributions 6*5c2921b0SApple OSS Distributions /* 7*5c2921b0SApple OSS Distributions * Chunklist file format 8*5c2921b0SApple OSS Distributions */ 9*5c2921b0SApple OSS Distributions #define CHUNKLIST_MAGIC 0x4C4B4E43 10*5c2921b0SApple OSS Distributions #define CHUNKLIST_FILE_VERSION_10 1 11*5c2921b0SApple OSS Distributions #define CHUNKLIST_CHUNK_METHOD_10 1 12*5c2921b0SApple OSS Distributions #define CHUNKLIST_SIGNATURE_METHOD_REV1 1 13*5c2921b0SApple OSS Distributions #define CHUNKLIST_REV1_SIG_LEN 256 14*5c2921b0SApple OSS Distributions #define CHUNKLIST_PUBKEY_LEN (2048/8) 15*5c2921b0SApple OSS Distributions #define CHUNKLIST_SIGNATURE_LEN (2048/8) 16*5c2921b0SApple OSS Distributions 17*5c2921b0SApple OSS Distributions struct chunklist_hdr { 18*5c2921b0SApple OSS Distributions uint32_t cl_magic; 19*5c2921b0SApple OSS Distributions uint32_t cl_header_size; 20*5c2921b0SApple OSS Distributions uint8_t cl_file_ver; 21*5c2921b0SApple OSS Distributions uint8_t cl_chunk_method; 22*5c2921b0SApple OSS Distributions uint8_t cl_sig_method; 23*5c2921b0SApple OSS Distributions uint8_t __unused1; 24*5c2921b0SApple OSS Distributions uint64_t cl_chunk_count; 25*5c2921b0SApple OSS Distributions uint64_t cl_chunk_offset; 26*5c2921b0SApple OSS Distributions uint64_t cl_sig_offset; 27*5c2921b0SApple OSS Distributions } __attribute__((packed)); 28*5c2921b0SApple OSS Distributions 29*5c2921b0SApple OSS Distributions struct chunklist_chunk { 30*5c2921b0SApple OSS Distributions uint32_t chunk_size; 31*5c2921b0SApple OSS Distributions uint8_t chunk_sha256[SHA256_DIGEST_LENGTH]; 32*5c2921b0SApple OSS Distributions } __attribute__((packed)); 33*5c2921b0SApple OSS Distributions 34*5c2921b0SApple OSS Distributions struct chunklist_pubkey { 35*5c2921b0SApple OSS Distributions const boolean_t is_production; 36*5c2921b0SApple OSS Distributions const uint8_t key[CHUNKLIST_PUBKEY_LEN]; 37*5c2921b0SApple OSS Distributions }; 38*5c2921b0SApple OSS Distributions 39*5c2921b0SApple OSS Distributions int authenticate_root_with_chunklist(const char *rootdmg_path, boolean_t *out_enforced); 40*5c2921b0SApple OSS Distributions int authenticate_root_version_check(void); 41*5c2921b0SApple OSS Distributions int authenticate_bootkc_uuid(void); 42*5c2921b0SApple OSS Distributions int authenticate_libkern_uuid(void); 43*5c2921b0SApple OSS Distributions #endif /* _CHUNKLIST_H */ 44