Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2017 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
Yi Jin | b592e3b | 2018-02-01 15:17:04 -0800 | [diff] [blame] | 16 | #pragma once |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 17 | |
| 18 | #ifndef PRIVACY_H |
| 19 | #define PRIVACY_H |
| 20 | |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 21 | #include <android/os/IncidentReportArgs.h> |
| 22 | |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 23 | #include <stdint.h> |
| 24 | |
Yi Jin | 6cacbcb | 2018-03-30 14:04:52 -0700 | [diff] [blame] | 25 | namespace android { |
| 26 | namespace os { |
| 27 | namespace incidentd { |
| 28 | |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 29 | using namespace android::os; |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 30 | |
| 31 | /* |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 32 | * In order to NOT auto-generate large chuck of code by proto compiler in incidentd, |
| 33 | * privacy options's data structure are explicitly redefined here and |
| 34 | * the values are populated by incident_section_gen tool. |
| 35 | * |
| 36 | * Each proto field will have a Privacy when it is different from its parent, otherwise |
| 37 | * it uses its parent's tag. A message type will have an array of Privacy. |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 38 | */ |
| 39 | struct Privacy { |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 40 | // The field number |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 41 | uint32_t field_id; |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 42 | |
| 43 | // The field type, see external/protobuf/src/google/protobuf/descriptor.h |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 44 | uint8_t type; |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 45 | |
| 46 | // If children is null, it is a primitive field, |
| 47 | // otherwise it is a message field which could have overridden privacy tags here. |
| 48 | // This array is NULL-terminated. |
Yi Jin | 7e0b4e5 | 2017-09-12 20:00:25 -0700 | [diff] [blame] | 49 | Privacy** children; |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 50 | |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 51 | // DESTINATION Enum in frameworks/base/core/proto/android/privacy.proto. |
| 52 | uint8_t policy; |
Joe Onorato | e547205 | 2019-04-24 16:27:33 -0700 | [diff] [blame^] | 53 | |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 54 | // A list of regexp rules for stripping string fields in proto. |
| 55 | const char** patterns; |
Joe Onorato | e547205 | 2019-04-24 16:27:33 -0700 | [diff] [blame^] | 56 | |
| 57 | string toString() const; |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 58 | }; |
| 59 | |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 60 | // Encode field id used by ProtoOutputStream. |
| 61 | uint64_t encode_field_id(const Privacy* p); |
| 62 | |
| 63 | // Look up the child with given fieldId, if not found, return NULL. |
| 64 | const Privacy* lookup(const Privacy* p, uint32_t fieldId); |
| 65 | |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 66 | /** |
| 67 | * PrivacySpec defines the request has what level of privacy authorization. |
| 68 | * For example, a device without user consent should only be able to upload AUTOMATIC fields. |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 69 | * PRIVACY_POLICY_UNSET are treated as PRIVACY_POLICY_EXPLICIT. |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 70 | */ |
| 71 | class PrivacySpec { |
| 72 | public: |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 73 | explicit PrivacySpec(uint8_t argPolicy); |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 74 | |
Yi Jin | 0f04716 | 2017-09-05 13:44:22 -0700 | [diff] [blame] | 75 | bool operator<(const PrivacySpec& other) const; |
| 76 | |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 77 | // check permission of a policy, if returns true, don't strip the data. |
Yi Jin | b592e3b | 2018-02-01 15:17:04 -0800 | [diff] [blame] | 78 | bool CheckPremission(const Privacy* privacy, |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 79 | const uint8_t defaultPrivacyPolicy = PRIVACY_POLICY_UNSET) const; |
Yi Jin | bdf5894 | 2017-11-14 17:58:19 -0800 | [diff] [blame] | 80 | |
| 81 | // if returns true, no data need to be stripped. |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 82 | bool RequireAll() const; |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 83 | |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 84 | uint8_t getPolicy() const; |
Yi Jin | b592e3b | 2018-02-01 15:17:04 -0800 | [diff] [blame] | 85 | |
Yi Jin | 3ec5cc7 | 2018-01-26 13:42:43 -0800 | [diff] [blame] | 86 | private: |
Joe Onorato | 99598ee | 2019-02-11 15:55:13 +0000 | [diff] [blame] | 87 | // unimplemented constructors |
| 88 | explicit PrivacySpec(); |
| 89 | |
| 90 | uint8_t mPolicy; |
Yi Jin | 3ec5cc7 | 2018-01-26 13:42:43 -0800 | [diff] [blame] | 91 | }; |
Yi Jin | 99c248f | 2017-08-25 18:11:58 -0700 | [diff] [blame] | 92 | |
Yao Chen | 43706b4 | 2019-04-21 14:34:30 -0700 | [diff] [blame] | 93 | // TODO: Add privacy flag in incident.proto and auto generate it inside Privacy. |
| 94 | bool sectionEncryption(int section_id); |
| 95 | |
Joe Onorato | e547205 | 2019-04-24 16:27:33 -0700 | [diff] [blame^] | 96 | /** |
| 97 | * If a privacy policy is other than the defined values, update it to a real one. |
| 98 | */ |
| 99 | uint8_t cleanup_privacy_policy(uint8_t policy); |
| 100 | |
Yi Jin | 6cacbcb | 2018-03-30 14:04:52 -0700 | [diff] [blame] | 101 | } // namespace incidentd |
| 102 | } // namespace os |
| 103 | } // namespace android |
| 104 | |
Yi Jin | b592e3b | 2018-02-01 15:17:04 -0800 | [diff] [blame] | 105 | #endif // PRIVACY_H |