Robert Berry | bd086f1 | 2017-12-27 13:29:39 +0000 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2017 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 17 | package com.android.server.locksettings.recoverablekeystore.storage; |
| 18 | |
| 19 | import android.content.Context; |
| 20 | import android.database.sqlite.SQLiteDatabase; |
| 21 | import android.database.sqlite.SQLiteOpenHelper; |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 22 | import android.util.Log; |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 23 | |
| 24 | import com.android.server.locksettings.recoverablekeystore.storage.RecoverableKeyStoreDbContract.KeysEntry; |
Bo Zhu | 584b923f | 2017-12-22 16:05:15 -0800 | [diff] [blame] | 25 | import com.android.server.locksettings.recoverablekeystore.storage.RecoverableKeyStoreDbContract.RecoveryServiceMetadataEntry; |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 26 | import com.android.server.locksettings.recoverablekeystore.storage.RecoverableKeyStoreDbContract.RootOfTrustEntry; |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 27 | import com.android.server.locksettings.recoverablekeystore.storage.RecoverableKeyStoreDbContract.UserMetadataEntry; |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 28 | |
| 29 | /** |
| 30 | * Helper for creating the recoverable key database. |
| 31 | */ |
| 32 | class RecoverableKeyStoreDbHelper extends SQLiteOpenHelper { |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 33 | private static final String TAG = "RecoverableKeyStoreDbHp"; |
| 34 | |
Bo Zhu | 7ebcd66 | 2019-01-04 17:00:58 -0800 | [diff] [blame] | 35 | static final int DATABASE_VERSION = 5; |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 36 | private static final String DATABASE_NAME = "recoverablekeystore.db"; |
| 37 | |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 38 | private static final String SQL_CREATE_KEYS_ENTRY = |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 39 | "CREATE TABLE " + KeysEntry.TABLE_NAME + "( " |
| 40 | + KeysEntry._ID + " INTEGER PRIMARY KEY," |
Robert Berry | b7c06ea | 2017-12-21 13:37:23 +0000 | [diff] [blame] | 41 | + KeysEntry.COLUMN_NAME_USER_ID + " INTEGER," |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 42 | + KeysEntry.COLUMN_NAME_UID + " INTEGER," |
| 43 | + KeysEntry.COLUMN_NAME_ALIAS + " TEXT," |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 44 | + KeysEntry.COLUMN_NAME_NONCE + " BLOB," |
| 45 | + KeysEntry.COLUMN_NAME_WRAPPED_KEY + " BLOB," |
| 46 | + KeysEntry.COLUMN_NAME_GENERATION_ID + " INTEGER," |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 47 | + KeysEntry.COLUMN_NAME_LAST_SYNCED_AT + " INTEGER," |
Dmitry Dementyev | ad88471 | 2017-12-20 12:38:36 -0800 | [diff] [blame] | 48 | + KeysEntry.COLUMN_NAME_RECOVERY_STATUS + " INTEGER," |
Bo Zhu | 7ebcd66 | 2019-01-04 17:00:58 -0800 | [diff] [blame] | 49 | + KeysEntry.COLUMN_NAME_KEY_METADATA + " BLOB," |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 50 | + "UNIQUE(" + KeysEntry.COLUMN_NAME_UID + "," |
| 51 | + KeysEntry.COLUMN_NAME_ALIAS + "))"; |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 52 | |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 53 | private static final String SQL_CREATE_USER_METADATA_ENTRY = |
| 54 | "CREATE TABLE " + UserMetadataEntry.TABLE_NAME + "( " |
| 55 | + UserMetadataEntry._ID + " INTEGER PRIMARY KEY," |
| 56 | + UserMetadataEntry.COLUMN_NAME_USER_ID + " INTEGER UNIQUE," |
| 57 | + UserMetadataEntry.COLUMN_NAME_PLATFORM_KEY_GENERATION_ID + " INTEGER)"; |
| 58 | |
Dmitry Dementyev | 77183ef | 2018-01-05 15:46:00 -0800 | [diff] [blame] | 59 | private static final String SQL_CREATE_RECOVERY_SERVICE_METADATA_ENTRY = |
Bo Zhu | 584b923f | 2017-12-22 16:05:15 -0800 | [diff] [blame] | 60 | "CREATE TABLE " + RecoveryServiceMetadataEntry.TABLE_NAME + " (" |
| 61 | + RecoveryServiceMetadataEntry._ID + " INTEGER PRIMARY KEY," |
| 62 | + RecoveryServiceMetadataEntry.COLUMN_NAME_USER_ID + " INTEGER," |
| 63 | + RecoveryServiceMetadataEntry.COLUMN_NAME_UID + " INTEGER," |
Dmitry Dementyev | 77183ef | 2018-01-05 15:46:00 -0800 | [diff] [blame] | 64 | + RecoveryServiceMetadataEntry.COLUMN_NAME_SNAPSHOT_VERSION + " INTEGER," |
| 65 | + RecoveryServiceMetadataEntry.COLUMN_NAME_SHOULD_CREATE_SNAPSHOT + " INTEGER," |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 66 | + RecoveryServiceMetadataEntry.COLUMN_NAME_ACTIVE_ROOT_OF_TRUST + " TEXT," |
Bo Zhu | 584b923f | 2017-12-22 16:05:15 -0800 | [diff] [blame] | 67 | + RecoveryServiceMetadataEntry.COLUMN_NAME_PUBLIC_KEY + " BLOB," |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 68 | + RecoveryServiceMetadataEntry.COLUMN_NAME_CERT_PATH + " BLOB," |
| 69 | + RecoveryServiceMetadataEntry.COLUMN_NAME_CERT_SERIAL + " INTEGER," |
Dmitry Dementyev | bdfdf53 | 2017-12-27 11:58:45 -0800 | [diff] [blame] | 70 | + RecoveryServiceMetadataEntry.COLUMN_NAME_SECRET_TYPES + " TEXT," |
Dmitry Dementyev | 77183ef | 2018-01-05 15:46:00 -0800 | [diff] [blame] | 71 | + RecoveryServiceMetadataEntry.COLUMN_NAME_COUNTER_ID + " INTEGER," |
Dmitry Dementyev | 7d8c78a | 2018-01-12 19:14:07 -0800 | [diff] [blame] | 72 | + RecoveryServiceMetadataEntry.COLUMN_NAME_SERVER_PARAMS + " BLOB," |
Bo Zhu | 5b81fa6 | 2017-12-21 14:36:11 -0800 | [diff] [blame] | 73 | + "UNIQUE(" |
Bo Zhu | 584b923f | 2017-12-22 16:05:15 -0800 | [diff] [blame] | 74 | + RecoveryServiceMetadataEntry.COLUMN_NAME_USER_ID + "," |
| 75 | + RecoveryServiceMetadataEntry.COLUMN_NAME_UID + "))"; |
Bo Zhu | 5b81fa6 | 2017-12-21 14:36:11 -0800 | [diff] [blame] | 76 | |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 77 | private static final String SQL_CREATE_ROOT_OF_TRUST_ENTRY = |
| 78 | "CREATE TABLE " + RootOfTrustEntry.TABLE_NAME + " (" |
| 79 | + RootOfTrustEntry._ID + " INTEGER PRIMARY KEY," |
| 80 | + RootOfTrustEntry.COLUMN_NAME_USER_ID + " INTEGER," |
| 81 | + RootOfTrustEntry.COLUMN_NAME_UID + " INTEGER," |
| 82 | + RootOfTrustEntry.COLUMN_NAME_ROOT_ALIAS + " TEST," |
| 83 | + RootOfTrustEntry.COLUMN_NAME_CERT_PATH + " BLOB," |
| 84 | + RootOfTrustEntry.COLUMN_NAME_CERT_SERIAL + " INTEGER," |
| 85 | + "UNIQUE(" |
| 86 | + RootOfTrustEntry.COLUMN_NAME_USER_ID + "," |
| 87 | + RootOfTrustEntry.COLUMN_NAME_UID + "," |
| 88 | + RootOfTrustEntry.COLUMN_NAME_ROOT_ALIAS + "))"; |
| 89 | |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 90 | private static final String SQL_DELETE_KEYS_ENTRY = |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 91 | "DROP TABLE IF EXISTS " + KeysEntry.TABLE_NAME; |
| 92 | |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 93 | private static final String SQL_DELETE_USER_METADATA_ENTRY = |
| 94 | "DROP TABLE IF EXISTS " + UserMetadataEntry.TABLE_NAME; |
| 95 | |
Dmitry Dementyev | 77183ef | 2018-01-05 15:46:00 -0800 | [diff] [blame] | 96 | private static final String SQL_DELETE_RECOVERY_SERVICE_METADATA_ENTRY = |
Bo Zhu | 584b923f | 2017-12-22 16:05:15 -0800 | [diff] [blame] | 97 | "DROP TABLE IF EXISTS " + RecoveryServiceMetadataEntry.TABLE_NAME; |
Bo Zhu | 5b81fa6 | 2017-12-21 14:36:11 -0800 | [diff] [blame] | 98 | |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 99 | private static final String SQL_DELETE_ROOT_OF_TRUST_ENTRY = |
| 100 | "DROP TABLE IF EXISTS " + RootOfTrustEntry.TABLE_NAME; |
| 101 | |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 102 | RecoverableKeyStoreDbHelper(Context context) { |
| 103 | super(context, DATABASE_NAME, null, DATABASE_VERSION); |
| 104 | } |
| 105 | |
| 106 | @Override |
| 107 | public void onCreate(SQLiteDatabase db) { |
Robert Berry | bc08840 | 2017-12-18 13:10:41 +0000 | [diff] [blame] | 108 | db.execSQL(SQL_CREATE_KEYS_ENTRY); |
| 109 | db.execSQL(SQL_CREATE_USER_METADATA_ENTRY); |
Dmitry Dementyev | 77183ef | 2018-01-05 15:46:00 -0800 | [diff] [blame] | 110 | db.execSQL(SQL_CREATE_RECOVERY_SERVICE_METADATA_ENTRY); |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 111 | db.execSQL(SQL_CREATE_ROOT_OF_TRUST_ENTRY); |
| 112 | } |
| 113 | |
| 114 | @Override |
| 115 | public void onDowngrade(SQLiteDatabase db, int oldVersion, int newVersion) { |
| 116 | Log.e(TAG, "Recreating recoverablekeystore after unexpected version downgrade."); |
| 117 | dropAllKnownTables(db); // Wipe database. |
| 118 | onCreate(db); |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 119 | } |
| 120 | |
| 121 | @Override |
| 122 | public void onUpgrade(SQLiteDatabase db, int oldVersion, int newVersion) { |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 123 | if (oldVersion < 2) { |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 124 | dropAllKnownTables(db); // Wipe database. |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 125 | onCreate(db); |
| 126 | return; |
| 127 | } |
| 128 | |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 129 | if (oldVersion < 3 && newVersion >= 3) { |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 130 | upgradeDbForVersion3(db); |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 131 | oldVersion = 3; |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 132 | } |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 133 | |
| 134 | if (oldVersion < 4 && newVersion >= 4) { |
| 135 | upgradeDbForVersion4(db); |
| 136 | oldVersion = 4; |
| 137 | } |
| 138 | |
Bo Zhu | 7ebcd66 | 2019-01-04 17:00:58 -0800 | [diff] [blame] | 139 | if (oldVersion < 5 && newVersion >= 5) { |
| 140 | upgradeDbForVersion5(db); |
| 141 | oldVersion = 5; |
| 142 | } |
| 143 | |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 144 | if (oldVersion != newVersion) { |
| 145 | Log.e(TAG, "Failed to update recoverablekeystore database to the most recent version"); |
| 146 | } |
| 147 | } |
| 148 | |
| 149 | private void dropAllKnownTables(SQLiteDatabase db) { |
| 150 | db.execSQL(SQL_DELETE_KEYS_ENTRY); |
| 151 | db.execSQL(SQL_DELETE_USER_METADATA_ENTRY); |
| 152 | db.execSQL(SQL_DELETE_RECOVERY_SERVICE_METADATA_ENTRY); |
| 153 | db.execSQL(SQL_DELETE_ROOT_OF_TRUST_ENTRY); |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 154 | } |
| 155 | |
| 156 | private void upgradeDbForVersion3(SQLiteDatabase db) { |
| 157 | // Add the two columns for cert path and cert serial number |
| 158 | addColumnToTable(db, RecoveryServiceMetadataEntry.TABLE_NAME, |
| 159 | RecoveryServiceMetadataEntry.COLUMN_NAME_CERT_PATH, "BLOB", /*defaultStr=*/ null); |
| 160 | addColumnToTable(db, RecoveryServiceMetadataEntry.TABLE_NAME, |
| 161 | RecoveryServiceMetadataEntry.COLUMN_NAME_CERT_SERIAL, "INTEGER", /*defaultStr=*/ |
| 162 | null); |
| 163 | } |
| 164 | |
Dmitry Dementyev | f34fc7e | 2018-03-26 17:31:29 -0700 | [diff] [blame] | 165 | private void upgradeDbForVersion4(SQLiteDatabase db) { |
| 166 | Log.d(TAG, "Updating recoverable keystore database to version 4"); |
| 167 | // Add new table with two columns for cert path and cert serial number. |
| 168 | db.execSQL(SQL_CREATE_ROOT_OF_TRUST_ENTRY); |
| 169 | // adds column to store root of trust currently used by the recovery agent |
| 170 | addColumnToTable(db, RecoveryServiceMetadataEntry.TABLE_NAME, |
| 171 | RecoveryServiceMetadataEntry.COLUMN_NAME_ACTIVE_ROOT_OF_TRUST, "TEXT", |
| 172 | /*defaultStr=*/ null); |
| 173 | } |
| 174 | |
Bo Zhu | 7ebcd66 | 2019-01-04 17:00:58 -0800 | [diff] [blame] | 175 | private void upgradeDbForVersion5(SQLiteDatabase db) { |
| 176 | Log.d(TAG, "Updating recoverable keystore database to version 5"); |
| 177 | // adds a column to store the metadata for application keys |
| 178 | addColumnToTable(db, KeysEntry.TABLE_NAME, |
| 179 | KeysEntry.COLUMN_NAME_KEY_METADATA, "BLOB", /*defaultStr=*/ null); |
| 180 | } |
| 181 | |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 182 | private static void addColumnToTable( |
| 183 | SQLiteDatabase db, String tableName, String column, String columnType, |
| 184 | String defaultStr) { |
| 185 | Log.d(TAG, "Adding column " + column + " to " + tableName + "."); |
| 186 | |
| 187 | String alterStr = "ALTER TABLE " + tableName + " ADD COLUMN " + column + " " + columnType; |
| 188 | if (defaultStr != null && !defaultStr.isEmpty()) { |
| 189 | alterStr += " DEFAULT " + defaultStr; |
| 190 | } |
| 191 | |
| 192 | db.execSQL(alterStr + ";"); |
Robert Berry | 76cf083 | 2017-12-15 23:01:22 +0000 | [diff] [blame] | 193 | } |
| 194 | } |
Bo Zhu | 14d993d | 2018-02-03 21:38:48 -0800 | [diff] [blame] | 195 | |