| <!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="Source of the Rust file `attestation/src/service.rs`."><meta name="keywords" content="rust, rustlang, rust-lang"><title>service.rs - source</title><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceSerif4-Regular.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../FiraSans-Regular.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../FiraSans-Medium.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceCodePro-Regular.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceSerif4-Bold.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceCodePro-Semibold.ttf.woff2"><link rel="stylesheet" href="../../normalize.css"><link rel="stylesheet" href="../../rustdoc.css" id="mainThemeStyle"><link rel="stylesheet" href="../../ayu.css" disabled><link rel="stylesheet" href="../../dark.css" disabled><link rel="stylesheet" href="../../light.css" id="themeStyle"><script id="default-settings" ></script><script src="../../storage.js"></script><script defer src="../../source-script.js"></script><script defer src="../../source-files.js"></script><script defer src="../../main.js"></script><noscript><link rel="stylesheet" href="../../noscript.css"></noscript><link rel="alternate icon" type="image/png" href="../../favicon-16x16.png"><link rel="alternate icon" type="image/png" href="../../favicon-32x32.png"><link rel="icon" type="image/svg+xml" href="../../favicon.svg"></head><body class="rustdoc source"><!--[if lte IE 11]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><a class="sidebar-logo" href="../../teaclave_attestation/index.html"><div class="logo-container"><img class="rust-logo" src="../../rust-logo.svg" alt="logo"></div></a></nav><main><div class="width-limiter"><nav class="sub"><a class="sub-logo-container" href="../../teaclave_attestation/index.html"><img class="rust-logo" src="../../rust-logo.svg" alt="logo"></a><form class="search-form"><div class="search-container"><span></span><input class="search-input" name="search" autocomplete="off" spellcheck="false" placeholder="Click or press ‘S’ to search, ‘?’ for more options…" type="search"><div id="help-button" title="help" tabindex="-1"><a href="../../help.html">?</a></div><div id="settings-menu" tabindex="-1"><a href="../../settings.html" title="settings"><img width="22" height="22" alt="Change settings" src="../../wheel.svg"></a></div></div></form></nav><section id="main-content" class="content"><div class="example-wrap"><pre class="src-line-numbers"><span id="1">1</span> |
| <span id="2">2</span> |
| <span id="3">3</span> |
| <span id="4">4</span> |
| <span id="5">5</span> |
| <span id="6">6</span> |
| <span id="7">7</span> |
| <span id="8">8</span> |
| <span id="9">9</span> |
| <span id="10">10</span> |
| <span id="11">11</span> |
| <span id="12">12</span> |
| <span id="13">13</span> |
| <span id="14">14</span> |
| <span id="15">15</span> |
| <span id="16">16</span> |
| <span id="17">17</span> |
| <span id="18">18</span> |
| <span id="19">19</span> |
| <span id="20">20</span> |
| <span id="21">21</span> |
| <span id="22">22</span> |
| <span id="23">23</span> |
| <span id="24">24</span> |
| <span id="25">25</span> |
| <span id="26">26</span> |
| <span id="27">27</span> |
| <span id="28">28</span> |
| <span id="29">29</span> |
| <span id="30">30</span> |
| <span id="31">31</span> |
| <span id="32">32</span> |
| <span id="33">33</span> |
| <span id="34">34</span> |
| <span id="35">35</span> |
| <span id="36">36</span> |
| <span id="37">37</span> |
| <span id="38">38</span> |
| <span id="39">39</span> |
| <span id="40">40</span> |
| <span id="41">41</span> |
| <span id="42">42</span> |
| <span id="43">43</span> |
| <span id="44">44</span> |
| <span id="45">45</span> |
| <span id="46">46</span> |
| <span id="47">47</span> |
| <span id="48">48</span> |
| <span id="49">49</span> |
| <span id="50">50</span> |
| <span id="51">51</span> |
| <span id="52">52</span> |
| <span id="53">53</span> |
| <span id="54">54</span> |
| <span id="55">55</span> |
| <span id="56">56</span> |
| <span id="57">57</span> |
| <span id="58">58</span> |
| <span id="59">59</span> |
| <span id="60">60</span> |
| <span id="61">61</span> |
| <span id="62">62</span> |
| <span id="63">63</span> |
| <span id="64">64</span> |
| <span id="65">65</span> |
| <span id="66">66</span> |
| <span id="67">67</span> |
| <span id="68">68</span> |
| <span id="69">69</span> |
| <span id="70">70</span> |
| <span id="71">71</span> |
| <span id="72">72</span> |
| <span id="73">73</span> |
| <span id="74">74</span> |
| <span id="75">75</span> |
| <span id="76">76</span> |
| <span id="77">77</span> |
| <span id="78">78</span> |
| <span id="79">79</span> |
| <span id="80">80</span> |
| <span id="81">81</span> |
| <span id="82">82</span> |
| <span id="83">83</span> |
| <span id="84">84</span> |
| <span id="85">85</span> |
| <span id="86">86</span> |
| <span id="87">87</span> |
| <span id="88">88</span> |
| <span id="89">89</span> |
| <span id="90">90</span> |
| <span id="91">91</span> |
| <span id="92">92</span> |
| <span id="93">93</span> |
| <span id="94">94</span> |
| <span id="95">95</span> |
| <span id="96">96</span> |
| <span id="97">97</span> |
| <span id="98">98</span> |
| <span id="99">99</span> |
| <span id="100">100</span> |
| <span id="101">101</span> |
| <span id="102">102</span> |
| <span id="103">103</span> |
| <span id="104">104</span> |
| <span id="105">105</span> |
| <span id="106">106</span> |
| <span id="107">107</span> |
| <span id="108">108</span> |
| <span id="109">109</span> |
| <span id="110">110</span> |
| <span id="111">111</span> |
| <span id="112">112</span> |
| <span id="113">113</span> |
| <span id="114">114</span> |
| <span id="115">115</span> |
| <span id="116">116</span> |
| <span id="117">117</span> |
| <span id="118">118</span> |
| <span id="119">119</span> |
| <span id="120">120</span> |
| <span id="121">121</span> |
| <span id="122">122</span> |
| <span id="123">123</span> |
| <span id="124">124</span> |
| <span id="125">125</span> |
| <span id="126">126</span> |
| <span id="127">127</span> |
| <span id="128">128</span> |
| <span id="129">129</span> |
| <span id="130">130</span> |
| <span id="131">131</span> |
| <span id="132">132</span> |
| <span id="133">133</span> |
| <span id="134">134</span> |
| <span id="135">135</span> |
| <span id="136">136</span> |
| <span id="137">137</span> |
| <span id="138">138</span> |
| <span id="139">139</span> |
| <span id="140">140</span> |
| <span id="141">141</span> |
| <span id="142">142</span> |
| <span id="143">143</span> |
| <span id="144">144</span> |
| <span id="145">145</span> |
| <span id="146">146</span> |
| <span id="147">147</span> |
| <span id="148">148</span> |
| <span id="149">149</span> |
| <span id="150">150</span> |
| <span id="151">151</span> |
| <span id="152">152</span> |
| <span id="153">153</span> |
| <span id="154">154</span> |
| <span id="155">155</span> |
| <span id="156">156</span> |
| <span id="157">157</span> |
| <span id="158">158</span> |
| <span id="159">159</span> |
| <span id="160">160</span> |
| <span id="161">161</span> |
| <span id="162">162</span> |
| <span id="163">163</span> |
| <span id="164">164</span> |
| <span id="165">165</span> |
| <span id="166">166</span> |
| <span id="167">167</span> |
| <span id="168">168</span> |
| <span id="169">169</span> |
| <span id="170">170</span> |
| <span id="171">171</span> |
| <span id="172">172</span> |
| <span id="173">173</span> |
| <span id="174">174</span> |
| <span id="175">175</span> |
| <span id="176">176</span> |
| <span id="177">177</span> |
| <span id="178">178</span> |
| <span id="179">179</span> |
| <span id="180">180</span> |
| <span id="181">181</span> |
| <span id="182">182</span> |
| <span id="183">183</span> |
| <span id="184">184</span> |
| <span id="185">185</span> |
| <span id="186">186</span> |
| <span id="187">187</span> |
| <span id="188">188</span> |
| <span id="189">189</span> |
| <span id="190">190</span> |
| <span id="191">191</span> |
| <span id="192">192</span> |
| <span id="193">193</span> |
| <span id="194">194</span> |
| <span id="195">195</span> |
| <span id="196">196</span> |
| <span id="197">197</span> |
| <span id="198">198</span> |
| <span id="199">199</span> |
| <span id="200">200</span> |
| <span id="201">201</span> |
| <span id="202">202</span> |
| <span id="203">203</span> |
| <span id="204">204</span> |
| <span id="205">205</span> |
| <span id="206">206</span> |
| <span id="207">207</span> |
| <span id="208">208</span> |
| <span id="209">209</span> |
| <span id="210">210</span> |
| <span id="211">211</span> |
| <span id="212">212</span> |
| <span id="213">213</span> |
| <span id="214">214</span> |
| <span id="215">215</span> |
| <span id="216">216</span> |
| <span id="217">217</span> |
| <span id="218">218</span> |
| <span id="219">219</span> |
| <span id="220">220</span> |
| <span id="221">221</span> |
| <span id="222">222</span> |
| <span id="223">223</span> |
| <span id="224">224</span> |
| <span id="225">225</span> |
| <span id="226">226</span> |
| <span id="227">227</span> |
| <span id="228">228</span> |
| <span id="229">229</span> |
| <span id="230">230</span> |
| <span id="231">231</span> |
| <span id="232">232</span> |
| <span id="233">233</span> |
| <span id="234">234</span> |
| <span id="235">235</span> |
| <span id="236">236</span> |
| <span id="237">237</span> |
| <span id="238">238</span> |
| <span id="239">239</span> |
| <span id="240">240</span> |
| <span id="241">241</span> |
| <span id="242">242</span> |
| <span id="243">243</span> |
| <span id="244">244</span> |
| <span id="245">245</span> |
| <span id="246">246</span> |
| <span id="247">247</span> |
| <span id="248">248</span> |
| <span id="249">249</span> |
| <span id="250">250</span> |
| <span id="251">251</span> |
| <span id="252">252</span> |
| <span id="253">253</span> |
| <span id="254">254</span> |
| <span id="255">255</span> |
| <span id="256">256</span> |
| <span id="257">257</span> |
| <span id="258">258</span> |
| <span id="259">259</span> |
| <span id="260">260</span> |
| <span id="261">261</span> |
| <span id="262">262</span> |
| <span id="263">263</span> |
| <span id="264">264</span> |
| <span id="265">265</span> |
| <span id="266">266</span> |
| <span id="267">267</span> |
| <span id="268">268</span> |
| <span id="269">269</span> |
| <span id="270">270</span> |
| <span id="271">271</span> |
| <span id="272">272</span> |
| <span id="273">273</span> |
| <span id="274">274</span> |
| <span id="275">275</span> |
| <span id="276">276</span> |
| <span id="277">277</span> |
| <span id="278">278</span> |
| <span id="279">279</span> |
| <span id="280">280</span> |
| <span id="281">281</span> |
| <span id="282">282</span> |
| <span id="283">283</span> |
| <span id="284">284</span> |
| <span id="285">285</span> |
| <span id="286">286</span> |
| <span id="287">287</span> |
| <span id="288">288</span> |
| <span id="289">289</span> |
| <span id="290">290</span> |
| <span id="291">291</span> |
| <span id="292">292</span> |
| <span id="293">293</span> |
| <span id="294">294</span> |
| <span id="295">295</span> |
| <span id="296">296</span> |
| <span id="297">297</span> |
| </pre><pre class="rust"><code><span class="comment">// Licensed to the Apache Software Foundation (ASF) under one |
| // or more contributor license agreements. See the NOTICE file |
| // distributed with this work for additional information |
| // regarding copyright ownership. The ASF licenses this file |
| // to you under the Apache License, Version 2.0 (the |
| // "License"); you may not use this file except in compliance |
| // with the License. You may obtain a copy of the License at |
| // |
| // http://www.apache.org/licenses/LICENSE-2.0 |
| // |
| // Unless required by applicable law or agreed to in writing, |
| // software distributed under the License is distributed on an |
| // "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
| // KIND, either express or implied. See the License for the |
| // specific language governing permissions and limitations |
| // under the License. |
| |
| </span><span class="doccomment">//! This module provide API to communicate with attestation service (AS) to get |
| //! attestation report endorsed by AS. |
| |
| </span><span class="kw">use </span><span class="kw">crate</span>::platform; |
| <span class="kw">use </span><span class="kw">crate</span>::AttestationAlgorithm; |
| <span class="kw">use </span><span class="kw">crate</span>::AttestationServiceConfig; |
| <span class="kw">use </span><span class="kw">crate</span>::EndorsedAttestationReport; |
| |
| <span class="kw">use </span>std::collections::HashMap; |
| <span class="kw">use </span>std::io::{ErrorKind, Read, Write}; |
| <span class="kw">use </span>std::net::TcpStream; |
| <span class="kw">use </span>std::sync::Arc; |
| |
| <span class="kw">use </span>anyhow::{anyhow, bail, <span class="prelude-ty">Result</span>}; |
| <span class="kw">use </span>log::{debug, trace, warn}; |
| <span class="kw">use </span>serde_json::json; |
| <span class="kw">use </span>sgx_crypto::ecc::EcPublicKey; |
| |
| <span class="doccomment">/// Root certification of the DCAP attestation service provider. |
| </span><span class="attribute">#[cfg(dcap)] |
| </span><span class="kw">const </span>DCAP_ROOT_CA_CERT: <span class="kw-2">&</span>str = <span class="macro">include_str!</span>(<span class="string">"../../config/keys/dcap_root_ca_cert.pem"</span>); |
| |
| <span class="doccomment">/// URL path to get the report from the attestation service. |
| </span><span class="kw">const </span>AS_REPORT_URL: <span class="kw-2">&</span>str = <span class="string">"/sgx/dev/attestation/v4/report"</span>; |
| |
| <span class="attribute">#[derive(thiserror::Error, Debug)] |
| </span><span class="kw">pub</span>(<span class="kw">crate</span>) <span class="kw">enum </span>AttestationServiceError { |
| <span class="attribute">#[error(<span class="string">"Invalid attestation service address."</span>)] |
| </span>InvalidAddress, |
| <span class="attribute">#[error(<span class="string">"Attestation service responds an malformed response."</span>)] |
| </span>InvalidResponse, |
| <span class="attribute">#[error(<span class="string">"{0} is missing in HTTP header."</span>)] |
| </span>MissingHeader(String), |
| <span class="attribute">#[error( |
| <span class="string">"Invalid Attestation Evidence Payload. The client should not repeat the |
| request without modifications." |
| </span>)] |
| </span>BadRequest, |
| <span class="attribute">#[error(<span class="string">"Failed to authenticate or authorize request."</span>)] |
| </span>Unauthorized, |
| <span class="attribute">#[error(<span class="string">"Internal error occurred."</span>)] |
| </span>InternalServerError, |
| <span class="attribute">#[error( |
| <span class="string">"Service is currently not able to process the request (due to a |
| temporary overloading or maintenance). This is a temporary state –the |
| same request can be repeated after some time." |
| </span>)] |
| </span>ServiceUnavailable, |
| <span class="attribute">#[error(<span class="string">"TLS connection error."</span>)] |
| </span>TlsError, |
| <span class="attribute">#[error(<span class="string">"Attestation service responds an unknown error."</span>)] |
| </span>Unknown, |
| } |
| |
| <span class="attribute">#[cfg(all(feature = <span class="string">"mesalock_sgx"</span>, not(feature = <span class="string">"libos"</span>)))] |
| </span><span class="kw">impl </span>EndorsedAttestationReport { |
| <span class="kw">pub fn </span>new( |
| att_service_cfg: <span class="kw-2">&</span>AttestationServiceConfig, |
| pub_k: EcPublicKey, |
| ) -> anyhow::Result<<span class="self">Self</span>> { |
| <span class="kw">let </span>(<span class="kw-2">mut </span>ak_id, qe_target_info) = platform::init_sgx_quote()<span class="question-mark">?</span>; |
| |
| <span class="comment">// For IAS-based attestation, we need to fill our SPID (obtained from Intel) |
| // into the attestation key id. For DCAP-based attestation, SPID should be 0 |
| </span><span class="kw">const </span>SPID_OFFSET: usize = std::mem::size_of::<sgx_types::types::QlAttKeyId>(); |
| ak_id.att_key_id[SPID_OFFSET..(SPID_OFFSET + att_service_cfg.spid.id.len())] |
| .clone_from_slice(<span class="kw-2">&</span>att_service_cfg.spid.id); |
| |
| <span class="kw">let </span>sgx_report = platform::create_sgx_isv_enclave_report(pub_k, qe_target_info)<span class="question-mark">?</span>; |
| <span class="kw">let </span>quote = platform::get_sgx_quote(<span class="kw-2">&</span>ak_id, sgx_report)<span class="question-mark">?</span>; |
| <span class="kw">let </span>as_report = get_report( |
| <span class="kw-2">&</span>att_service_cfg.algo, |
| <span class="kw-2">&</span>att_service_cfg.as_url, |
| <span class="kw-2">&</span>att_service_cfg.api_key, |
| <span class="kw-2">&</span>quote, |
| )<span class="question-mark">?</span>; |
| |
| <span class="prelude-val">Ok</span>(as_report) |
| } |
| } |
| |
| <span class="attribute">#[cfg(all(feature = <span class="string">"libos"</span>, not(feature = <span class="string">"mesalock_sgx"</span>)))] |
| </span><span class="kw">impl </span>EndorsedAttestationReport { |
| <span class="kw">pub fn </span>new(att_service_cfg: <span class="kw-2">&</span>AttestationServiceConfig, pub_k: EcPublicKey) -> <span class="prelude-ty">Result</span><<span class="self">Self</span>> { |
| <span class="kw">let </span>report_data = platform::create_sgx_report_data(pub_k); |
| <span class="kw">let </span>quote = <span class="kw">match </span><span class="kw-2">&</span>att_service_cfg.algo { |
| <span class="kw">crate</span>::AttestationAlgorithm::SgxEpid => { |
| platform::get_sgx_epid_quote(<span class="kw-2">&</span>att_service_cfg.spid, report_data)<span class="question-mark">? |
| </span>} |
| <span class="kw">crate</span>::AttestationAlgorithm::SgxEcdsa => { |
| platform::get_sgx_dcap_quote(<span class="kw-2">&</span>att_service_cfg.spid, report_data)<span class="question-mark">? |
| </span>} |
| }; |
| <span class="kw">crate</span>::service::get_report( |
| <span class="kw-2">&</span>att_service_cfg.algo, |
| <span class="kw-2">&</span>att_service_cfg.as_url, |
| <span class="kw-2">&</span>att_service_cfg.api_key, |
| <span class="kw-2">&</span>quote, |
| ) |
| } |
| } |
| |
| <span class="kw">fn </span>new_tls_stream(url: <span class="kw-2">&</span>url::Url) -> <span class="prelude-ty">Result</span><rustls::StreamOwned<rustls::ClientSession, TcpStream>> { |
| <span class="kw">let </span>host_str = url |
| .host_str() |
| .ok_or(AttestationServiceError::InvalidAddress)<span class="question-mark">?</span>; |
| <span class="kw">let </span>dns_name = webpki::DNSNameRef::try_from_ascii_str(host_str)<span class="question-mark">?</span>; |
| <span class="kw">let </span><span class="kw-2">mut </span>config = rustls::ClientConfig::new(); |
| <span class="attribute">#[cfg(dcap)] |
| </span>config |
| .root_store |
| .add_pem_file(<span class="kw-2">&mut </span>DCAP_ROOT_CA_CERT.to_string().as_bytes()) |
| .map_err(|<span class="kw">_</span>| AttestationServiceError::TlsError)<span class="question-mark">?</span>; |
| config |
| .root_store |
| .add_server_trust_anchors(<span class="kw-2">&</span>webpki_roots::TLS_SERVER_ROOTS); |
| <span class="kw">let </span>client = rustls::ClientSession::new(<span class="kw-2">&</span>Arc::new(config), dns_name); |
| <span class="kw">let </span>addrs = url.socket_addrs(|| <span class="kw">match </span>url.scheme() { |
| <span class="string">"https" </span>=> <span class="prelude-val">Some</span>(<span class="number">443</span>), |
| <span class="kw">_ </span>=> <span class="prelude-val">None</span>, |
| })<span class="question-mark">?</span>; |
| <span class="kw">let </span>socket = TcpStream::connect(<span class="kw-2">&*</span>addrs)<span class="question-mark">?</span>; |
| <span class="kw">let </span>stream = rustls::StreamOwned::new(client, socket); |
| |
| <span class="prelude-val">Ok</span>(stream) |
| } |
| |
| <span class="doccomment">/// Get attestation report form the attestation service (e.g., Intel Attestation |
| /// Service and customized DCAP attestation service). |
| </span><span class="kw">pub</span>(<span class="kw">crate</span>) <span class="kw">fn </span>get_report( |
| algo: <span class="kw-2">&</span>AttestationAlgorithm, |
| url: <span class="kw-2">&</span>url::Url, |
| api_key: <span class="kw-2">&</span>str, |
| quote: <span class="kw-2">&</span>[u8], |
| ) -> <span class="prelude-ty">Result</span><EndorsedAttestationReport> { |
| <span class="macro">debug!</span>(<span class="string">"get_report"</span>); |
| <span class="kw">let </span>encoded_quote = base64::encode(quote); |
| <span class="kw">let </span>encoded_json = <span class="macro">json!</span>({ <span class="string">"isvEnclaveQuote"</span>: encoded_quote }).to_string(); |
| <span class="kw">let </span>host_str = url |
| .host_str() |
| .ok_or(AttestationServiceError::InvalidAddress)<span class="question-mark">?</span>; |
| |
| <span class="kw">let </span>request = <span class="macro">format!</span>( |
| <span class="string">"POST {} HTTP/1.1\r\n\ |
| HOST: {}\r\n\ |
| Ocp-Apim-Subscription-Key: {}\r\n\ |
| Connection: Close\r\n\ |
| Content-Length: {}\r\n\ |
| Content-Type: application/json\r\n\r\n\ |
| {}"</span>, |
| AS_REPORT_URL, |
| host_str, |
| api_key, |
| encoded_json.len(), |
| encoded_json |
| ); |
| <span class="macro">trace!</span>(<span class="string">"{}"</span>, request); |
| |
| <span class="kw">let </span><span class="kw-2">mut </span>stream = new_tls_stream(url).map_err(|<span class="kw">_</span>| AttestationServiceError::TlsError)<span class="question-mark">?</span>; |
| stream.write_all(request.as_bytes())<span class="question-mark">?</span>; |
| <span class="kw">let </span><span class="kw-2">mut </span>response = Vec::new(); |
| <span class="kw">if let </span><span class="prelude-val">Err</span>(e) = stream.read_to_end(<span class="kw-2">&mut </span>response) { |
| <span class="kw">match </span>e.kind() { |
| <span class="comment">// Server may send CloseNotify ConnectionAborted for Connection:Close request |
| </span>ErrorKind::ConnectionAborted => <span class="macro">warn!</span>(<span class="string">"connection aborted: {:?}"</span>, e), |
| <span class="kw">_ </span>=> <span class="macro">bail!</span>(<span class="string">"{:?} is not allowed"</span>, e), |
| } |
| }; |
| |
| <span class="macro">trace!</span>(<span class="string">"{}"</span>, String::from_utf8_lossy(<span class="kw-2">&</span>response)); |
| |
| <span class="kw">let </span><span class="kw-2">mut </span>headers = [httparse::EMPTY_HEADER; <span class="number">16</span>]; |
| <span class="kw">let </span><span class="kw-2">mut </span>http_response = httparse::Response::new(<span class="kw-2">&mut </span>headers); |
| |
| <span class="macro">debug!</span>(<span class="string">"http_response.parse"</span>); |
| <span class="kw">let </span>header_len = <span class="kw">match </span>http_response |
| .parse(<span class="kw-2">&</span>response) |
| .map_err(|<span class="kw">_</span>| AttestationServiceError::InvalidResponse)<span class="question-mark">? |
| </span>{ |
| httparse::Status::Complete(s) => s, |
| <span class="kw">_ </span>=> <span class="macro">bail!</span>(AttestationServiceError::InvalidResponse), |
| }; |
| |
| <span class="kw">match </span>http_response.code { |
| <span class="prelude-val">Some</span>(<span class="number">200</span>) => { |
| <span class="macro">debug!</span>(<span class="string">"Operation successful."</span>); |
| } |
| <span class="prelude-val">Some</span>(<span class="number">400</span>) => { |
| <span class="macro">debug!</span>( |
| <span class="string">"Invalid Attestation Evidence Payload. The client should not |
| repeat the request without modifications." |
| </span>); |
| <span class="macro">bail!</span>(AttestationServiceError::BadRequest); |
| } |
| <span class="prelude-val">Some</span>(<span class="number">401</span>) => { |
| <span class="macro">debug!</span>(<span class="string">"Failed to authenticate or authorize request."</span>); |
| <span class="macro">bail!</span>(AttestationServiceError::Unauthorized); |
| } |
| <span class="prelude-val">Some</span>(<span class="number">500</span>) => { |
| <span class="macro">debug!</span>(<span class="string">"Internal error occurred."</span>); |
| <span class="macro">bail!</span>(AttestationServiceError::InternalServerError); |
| } |
| <span class="prelude-val">Some</span>(<span class="number">503</span>) => { |
| <span class="macro">debug!</span>( |
| <span class="string">"Service is currently not able to process the request (due to a |
| temporary overloading or maintenance). This is a temporary |
| state, the same request can be repeated after some time." |
| </span>); |
| <span class="macro">bail!</span>(AttestationServiceError::ServiceUnavailable); |
| } |
| <span class="kw">_ </span>=> { |
| <span class="macro">debug!</span>(<span class="string">"Attestation service responds an unknown error"</span>); |
| <span class="macro">bail!</span>(AttestationServiceError::Unknown); |
| } |
| } |
| |
| <span class="kw">let </span>header_map = parse_headers(<span class="kw-2">&</span>http_response); |
| <span class="macro">debug!</span>(<span class="string">"ias header_map: {:?}"</span>, header_map); |
| |
| <span class="macro">debug!</span>(<span class="string">"get_content_length"</span>); |
| <span class="kw">if </span>!header_map.contains_key(<span class="string">"content-length"</span>) |
| || header_map |
| .get(<span class="string">"content-length"</span>) |
| .ok_or_else(|| AttestationServiceError::MissingHeader(<span class="string">"content-length"</span>.to_string()))<span class="question-mark">? |
| </span>.parse::<u32>() |
| .unwrap_or(<span class="number">0</span>) |
| == <span class="number">0 |
| </span>{ |
| <span class="macro">bail!</span>(AttestationServiceError::MissingHeader( |
| <span class="string">"content-length"</span>.to_string() |
| )); |
| } |
| |
| <span class="macro">debug!</span>(<span class="string">"get_signature"</span>); |
| <span class="kw">let </span>signature_header = <span class="kw">match </span>algo { |
| AttestationAlgorithm::SgxEpid => <span class="string">"x-iasreport-signature"</span>, |
| AttestationAlgorithm::SgxEcdsa => <span class="string">"x-dcapreport-signature"</span>, |
| }; |
| <span class="kw">let </span>signature = header_map |
| .get(signature_header) |
| .ok_or_else(|| AttestationServiceError::MissingHeader(signature_header.to_string()))<span class="question-mark">?</span>; |
| <span class="kw">let </span>signature = base64::decode(signature)<span class="question-mark">?</span>; |
| |
| <span class="macro">debug!</span>(<span class="string">"get_signing_cert"</span>); |
| <span class="kw">let </span>signing_cert_header = <span class="kw">match </span>algo { |
| AttestationAlgorithm::SgxEpid => <span class="string">"x-iasreport-signing-certificate"</span>, |
| AttestationAlgorithm::SgxEcdsa => <span class="string">"x-dcapreport-signing-certificate"</span>, |
| }; |
| <span class="kw">let </span>certs: Vec<Vec<u8>> = { |
| <span class="kw">let </span>cert_str = header_map.get(signing_cert_header).ok_or_else(|| { |
| AttestationServiceError::MissingHeader(signing_cert_header.to_string()) |
| })<span class="question-mark">?</span>; |
| <span class="kw">let </span>decoded_cert = percent_encoding::percent_decode_str(cert_str).decode_utf8()<span class="question-mark">?</span>; |
| <span class="kw">let </span>certs = rustls::internal::pemfile::certs(<span class="kw-2">&mut </span>decoded_cert.as_bytes()) |
| .map_err(|<span class="kw">_</span>| <span class="macro">anyhow!</span>(<span class="string">"pemfile error"</span>))<span class="question-mark">?</span>; |
| certs.iter().map(|c| c.<span class="number">0</span>.clone()).collect() |
| }; |
| |
| <span class="macro">debug!</span>(<span class="string">"return_report"</span>); |
| <span class="kw">let </span>report = response[header_len..].to_vec(); |
| <span class="prelude-val">Ok</span>(EndorsedAttestationReport { |
| report, |
| signature, |
| certs, |
| }) |
| } |
| |
| <span class="kw">fn </span>parse_headers(resp: <span class="kw-2">&</span>httparse::Response) -> HashMap<String, String> { |
| <span class="macro">debug!</span>(<span class="string">"parse_headers"</span>); |
| <span class="kw">let </span><span class="kw-2">mut </span>header_map = HashMap::new(); |
| <span class="kw">for </span>h <span class="kw">in </span>resp.headers.iter() { |
| header_map.insert( |
| <span class="comment">// HTTP header name is case insensitive |
| </span>h.name.to_lowercase(), |
| String::from_utf8_lossy(h.value).into_owned(), |
| ); |
| } |
| |
| header_map |
| } |
| </code></pre></div> |
| </section></div></main><div id="rustdoc-vars" data-root-path="../../" data-current-crate="teaclave_attestation" data-themes="ayu,dark,light" data-resource-suffix="" data-rustdoc-version="1.66.0-nightly (5c8bff74b 2022-10-21)" ></div></body></html> |