xref: /aosp_15_r20/external/webrtc/tools_webrtc/sslroots/generate_sslroots.py (revision d9f758449e529ab9291ac668be2861e7a55c2422)
1*d9f75844SAndroid Build Coastguard Worker#!/usr/bin/env vpython3
2*d9f75844SAndroid Build Coastguard Worker
3*d9f75844SAndroid Build Coastguard Worker# -*- coding:utf-8 -*-
4*d9f75844SAndroid Build Coastguard Worker# Copyright (c) 2015 The WebRTC project authors. All Rights Reserved.
5*d9f75844SAndroid Build Coastguard Worker#
6*d9f75844SAndroid Build Coastguard Worker# Use of this source code is governed by a BSD-style license
7*d9f75844SAndroid Build Coastguard Worker# that can be found in the LICENSE file in the root of the source
8*d9f75844SAndroid Build Coastguard Worker# tree. An additional intellectual property rights grant can be found
9*d9f75844SAndroid Build Coastguard Worker# in the file PATENTS.  All contributing project authors may
10*d9f75844SAndroid Build Coastguard Worker# be found in the AUTHORS file in the root of the source tree.
11*d9f75844SAndroid Build Coastguard Worker"""This is a tool to transform a crt file into a C/C++ header.
12*d9f75844SAndroid Build Coastguard Worker
13*d9f75844SAndroid Build Coastguard WorkerUsage:
14*d9f75844SAndroid Build Coastguard Workerpython3 generate_sslroots.py certfile.pem [--verbose | -v] [--full_cert | -f]
15*d9f75844SAndroid Build Coastguard Worker
16*d9f75844SAndroid Build Coastguard WorkerArguments:
17*d9f75844SAndroid Build Coastguard Worker  -v  Print output while running.
18*d9f75844SAndroid Build Coastguard Worker  -f  Add public key and certificate name.  Default is to skip and reduce
19*d9f75844SAndroid Build Coastguard Worker      generated file size.
20*d9f75844SAndroid Build Coastguard Worker
21*d9f75844SAndroid Build Coastguard WorkerThe supported cert files are:
22*d9f75844SAndroid Build Coastguard Worker  - Google: https://pki.goog/roots.pem
23*d9f75844SAndroid Build Coastguard Worker  - Mozilla: https://curl.se/docs/caextract.html
24*d9f75844SAndroid Build Coastguard Worker"""
25*d9f75844SAndroid Build Coastguard Worker
26*d9f75844SAndroid Build Coastguard Workerimport subprocess
27*d9f75844SAndroid Build Coastguard Workerfrom optparse import OptionParser
28*d9f75844SAndroid Build Coastguard Workerimport os
29*d9f75844SAndroid Build Coastguard Workerimport re
30*d9f75844SAndroid Build Coastguard Worker
31*d9f75844SAndroid Build Coastguard Worker_GENERATED_FILE = 'ssl_roots.h'
32*d9f75844SAndroid Build Coastguard Worker_PREFIX = '__generated__'
33*d9f75844SAndroid Build Coastguard Worker_EXTENSION = '.crt'
34*d9f75844SAndroid Build Coastguard Worker_SUBJECT_NAME_ARRAY = 'subject_name'
35*d9f75844SAndroid Build Coastguard Worker_SUBJECT_NAME_VARIABLE = 'SubjectName'
36*d9f75844SAndroid Build Coastguard Worker_PUBLIC_KEY_ARRAY = 'public_key'
37*d9f75844SAndroid Build Coastguard Worker_PUBLIC_KEY_VARIABLE = 'PublicKey'
38*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_ARRAY = 'certificate'
39*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_VARIABLE = 'Certificate'
40*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_SIZE_VARIABLE = 'CertificateSize'
41*d9f75844SAndroid Build Coastguard Worker_INT_TYPE = 'size_t'
42*d9f75844SAndroid Build Coastguard Worker_CHAR_TYPE = 'unsigned char* const'
43*d9f75844SAndroid Build Coastguard Worker_VERBOSE = 'verbose'
44*d9f75844SAndroid Build Coastguard Worker_MOZILLA_BUNDLE_CHECK = '## Certificate data from Mozilla as of:'
45*d9f75844SAndroid Build Coastguard Worker
46*d9f75844SAndroid Build Coastguard Worker
47*d9f75844SAndroid Build Coastguard Workerdef main():
48*d9f75844SAndroid Build Coastguard Worker  """The main entrypoint."""
49*d9f75844SAndroid Build Coastguard Worker  parser = OptionParser('usage %prog FILE')
50*d9f75844SAndroid Build Coastguard Worker  parser.add_option('-v', '--verbose', dest='verbose', action='store_true')
51*d9f75844SAndroid Build Coastguard Worker  parser.add_option('-f', '--full_cert', dest='full_cert', action='store_true')
52*d9f75844SAndroid Build Coastguard Worker  options, args = parser.parse_args()
53*d9f75844SAndroid Build Coastguard Worker  if len(args) < 1:
54*d9f75844SAndroid Build Coastguard Worker    parser.error('No crt file specified.')
55*d9f75844SAndroid Build Coastguard Worker    return
56*d9f75844SAndroid Build Coastguard Worker  root_dir, bundle_type = _SplitCrt(args[0], options)
57*d9f75844SAndroid Build Coastguard Worker  _GenCFiles(root_dir, options, bundle_type)
58*d9f75844SAndroid Build Coastguard Worker  _Cleanup(root_dir)
59*d9f75844SAndroid Build Coastguard Worker
60*d9f75844SAndroid Build Coastguard Worker
61*d9f75844SAndroid Build Coastguard Workerdef _SplitCrt(source_file, options):
62*d9f75844SAndroid Build Coastguard Worker  sub_file_blocks = []
63*d9f75844SAndroid Build Coastguard Worker  label_name = ''
64*d9f75844SAndroid Build Coastguard Worker  prev_line = None
65*d9f75844SAndroid Build Coastguard Worker  root_dir = os.path.dirname(os.path.abspath(source_file)) + '/'
66*d9f75844SAndroid Build Coastguard Worker  _PrintOutput(root_dir, options)
67*d9f75844SAndroid Build Coastguard Worker  lines = None
68*d9f75844SAndroid Build Coastguard Worker  with open(source_file) as f:
69*d9f75844SAndroid Build Coastguard Worker    lines = f.readlines()
70*d9f75844SAndroid Build Coastguard Worker  mozilla_bundle = any(l.startswith(_MOZILLA_BUNDLE_CHECK) for l in lines)
71*d9f75844SAndroid Build Coastguard Worker  for line in lines:
72*d9f75844SAndroid Build Coastguard Worker    if line.startswith('#'):
73*d9f75844SAndroid Build Coastguard Worker      if mozilla_bundle:
74*d9f75844SAndroid Build Coastguard Worker        continue
75*d9f75844SAndroid Build Coastguard Worker      if line.startswith('# Label: '):
76*d9f75844SAndroid Build Coastguard Worker        sub_file_blocks.append(line)
77*d9f75844SAndroid Build Coastguard Worker        label = re.search(r'\".*\"', line)
78*d9f75844SAndroid Build Coastguard Worker        temp_label = label.group(0)
79*d9f75844SAndroid Build Coastguard Worker        end = len(temp_label) - 1
80*d9f75844SAndroid Build Coastguard Worker        label_name = _SafeName(temp_label[1:end])
81*d9f75844SAndroid Build Coastguard Worker    if mozilla_bundle and line.startswith('==='):
82*d9f75844SAndroid Build Coastguard Worker      sub_file_blocks.append(line)
83*d9f75844SAndroid Build Coastguard Worker      label_name = _SafeName(prev_line)
84*d9f75844SAndroid Build Coastguard Worker    elif line.startswith('-----END CERTIFICATE-----'):
85*d9f75844SAndroid Build Coastguard Worker      sub_file_blocks.append(line)
86*d9f75844SAndroid Build Coastguard Worker      new_file_name = root_dir + _PREFIX + label_name + _EXTENSION
87*d9f75844SAndroid Build Coastguard Worker      _PrintOutput('Generating: ' + new_file_name, options)
88*d9f75844SAndroid Build Coastguard Worker      new_file = open(new_file_name, 'w')
89*d9f75844SAndroid Build Coastguard Worker      for out_line in sub_file_blocks:
90*d9f75844SAndroid Build Coastguard Worker        new_file.write(out_line)
91*d9f75844SAndroid Build Coastguard Worker      new_file.close()
92*d9f75844SAndroid Build Coastguard Worker      sub_file_blocks = []
93*d9f75844SAndroid Build Coastguard Worker    else:
94*d9f75844SAndroid Build Coastguard Worker      sub_file_blocks.append(line)
95*d9f75844SAndroid Build Coastguard Worker    prev_line = line
96*d9f75844SAndroid Build Coastguard Worker  return root_dir, 'Mozilla' if mozilla_bundle else 'Google'
97*d9f75844SAndroid Build Coastguard Worker
98*d9f75844SAndroid Build Coastguard Worker
99*d9f75844SAndroid Build Coastguard Workerdef _GenCFiles(root_dir, options, bundle_type):
100*d9f75844SAndroid Build Coastguard Worker  output_header_file = open(root_dir + _GENERATED_FILE, 'w')
101*d9f75844SAndroid Build Coastguard Worker  output_header_file.write(_CreateOutputHeader(bundle_type))
102*d9f75844SAndroid Build Coastguard Worker  if options.full_cert:
103*d9f75844SAndroid Build Coastguard Worker    subject_name_list = _CreateArraySectionHeader(_SUBJECT_NAME_VARIABLE,
104*d9f75844SAndroid Build Coastguard Worker                                                  _CHAR_TYPE, options)
105*d9f75844SAndroid Build Coastguard Worker    public_key_list = _CreateArraySectionHeader(_PUBLIC_KEY_VARIABLE,
106*d9f75844SAndroid Build Coastguard Worker                                                _CHAR_TYPE, options)
107*d9f75844SAndroid Build Coastguard Worker  certificate_list = _CreateArraySectionHeader(_CERTIFICATE_VARIABLE,
108*d9f75844SAndroid Build Coastguard Worker                                               _CHAR_TYPE, options)
109*d9f75844SAndroid Build Coastguard Worker  certificate_size_list = _CreateArraySectionHeader(_CERTIFICATE_SIZE_VARIABLE,
110*d9f75844SAndroid Build Coastguard Worker                                                    _INT_TYPE, options)
111*d9f75844SAndroid Build Coastguard Worker
112*d9f75844SAndroid Build Coastguard Worker  for _, _, files in os.walk(root_dir):
113*d9f75844SAndroid Build Coastguard Worker    for current_file in files:
114*d9f75844SAndroid Build Coastguard Worker      if current_file.startswith(_PREFIX):
115*d9f75844SAndroid Build Coastguard Worker        prefix_length = len(_PREFIX)
116*d9f75844SAndroid Build Coastguard Worker        length = len(current_file) - len(_EXTENSION)
117*d9f75844SAndroid Build Coastguard Worker        label = current_file[prefix_length:length]
118*d9f75844SAndroid Build Coastguard Worker        filtered_output, cert_size = _CreateCertSection(root_dir, current_file,
119*d9f75844SAndroid Build Coastguard Worker                                                        label, options)
120*d9f75844SAndroid Build Coastguard Worker        output_header_file.write(filtered_output + '\n\n\n')
121*d9f75844SAndroid Build Coastguard Worker        if options.full_cert:
122*d9f75844SAndroid Build Coastguard Worker          subject_name_list += _AddLabelToArray(label, _SUBJECT_NAME_ARRAY)
123*d9f75844SAndroid Build Coastguard Worker          public_key_list += _AddLabelToArray(label, _PUBLIC_KEY_ARRAY)
124*d9f75844SAndroid Build Coastguard Worker        certificate_list += _AddLabelToArray(label, _CERTIFICATE_ARRAY)
125*d9f75844SAndroid Build Coastguard Worker        certificate_size_list += ('  %s,\n') % (cert_size)
126*d9f75844SAndroid Build Coastguard Worker
127*d9f75844SAndroid Build Coastguard Worker  if options.full_cert:
128*d9f75844SAndroid Build Coastguard Worker    subject_name_list += _CreateArraySectionFooter()
129*d9f75844SAndroid Build Coastguard Worker    output_header_file.write(subject_name_list)
130*d9f75844SAndroid Build Coastguard Worker    public_key_list += _CreateArraySectionFooter()
131*d9f75844SAndroid Build Coastguard Worker    output_header_file.write(public_key_list)
132*d9f75844SAndroid Build Coastguard Worker  certificate_list += _CreateArraySectionFooter()
133*d9f75844SAndroid Build Coastguard Worker  output_header_file.write(certificate_list)
134*d9f75844SAndroid Build Coastguard Worker  certificate_size_list += _CreateArraySectionFooter()
135*d9f75844SAndroid Build Coastguard Worker  output_header_file.write(certificate_size_list)
136*d9f75844SAndroid Build Coastguard Worker  output_header_file.write(_CreateOutputFooter())
137*d9f75844SAndroid Build Coastguard Worker  output_header_file.close()
138*d9f75844SAndroid Build Coastguard Worker
139*d9f75844SAndroid Build Coastguard Worker
140*d9f75844SAndroid Build Coastguard Workerdef _Cleanup(root_dir):
141*d9f75844SAndroid Build Coastguard Worker  for f in os.listdir(root_dir):
142*d9f75844SAndroid Build Coastguard Worker    if f.startswith(_PREFIX):
143*d9f75844SAndroid Build Coastguard Worker      os.remove(root_dir + f)
144*d9f75844SAndroid Build Coastguard Worker
145*d9f75844SAndroid Build Coastguard Worker
146*d9f75844SAndroid Build Coastguard Workerdef _CreateCertSection(root_dir, source_file, label, options):
147*d9f75844SAndroid Build Coastguard Worker  command = 'openssl x509 -in %s%s -noout -C' % (root_dir, source_file)
148*d9f75844SAndroid Build Coastguard Worker  _PrintOutput(command, options)
149*d9f75844SAndroid Build Coastguard Worker  output = subprocess.getstatusoutput(command)[1]
150*d9f75844SAndroid Build Coastguard Worker  decl_block = 'unsigned char .*_(%s|%s|%s)' %\
151*d9f75844SAndroid Build Coastguard Worker    (_SUBJECT_NAME_ARRAY, _PUBLIC_KEY_ARRAY, _CERTIFICATE_ARRAY)
152*d9f75844SAndroid Build Coastguard Worker  prog = re.compile(decl_block, re.IGNORECASE)
153*d9f75844SAndroid Build Coastguard Worker  renamed_output = prog.sub('const unsigned char ' + label + r'_\1', output)
154*d9f75844SAndroid Build Coastguard Worker
155*d9f75844SAndroid Build Coastguard Worker  filtered_output = ''
156*d9f75844SAndroid Build Coastguard Worker  cert_block = '^const unsigned char.*?};$'
157*d9f75844SAndroid Build Coastguard Worker  prog2 = re.compile(cert_block, re.IGNORECASE | re.MULTILINE | re.DOTALL)
158*d9f75844SAndroid Build Coastguard Worker  if not options.full_cert:
159*d9f75844SAndroid Build Coastguard Worker    filtered_output = prog2.sub('', renamed_output, count=2)
160*d9f75844SAndroid Build Coastguard Worker  else:
161*d9f75844SAndroid Build Coastguard Worker    filtered_output = renamed_output
162*d9f75844SAndroid Build Coastguard Worker
163*d9f75844SAndroid Build Coastguard Worker  cert_size_block = r'\d\d\d+'
164*d9f75844SAndroid Build Coastguard Worker  prog3 = re.compile(cert_size_block, re.MULTILINE | re.VERBOSE)
165*d9f75844SAndroid Build Coastguard Worker  result = prog3.findall(renamed_output)
166*d9f75844SAndroid Build Coastguard Worker  cert_size = result[len(result) - 1]
167*d9f75844SAndroid Build Coastguard Worker
168*d9f75844SAndroid Build Coastguard Worker  return filtered_output, cert_size
169*d9f75844SAndroid Build Coastguard Worker
170*d9f75844SAndroid Build Coastguard Worker
171*d9f75844SAndroid Build Coastguard Workerdef _CreateOutputHeader(bundle_type):
172*d9f75844SAndroid Build Coastguard Worker  output = ('/*\n'
173*d9f75844SAndroid Build Coastguard Worker            ' *  Copyright 2004 The WebRTC Project Authors. All rights '
174*d9f75844SAndroid Build Coastguard Worker            'reserved.\n'
175*d9f75844SAndroid Build Coastguard Worker            ' *\n'
176*d9f75844SAndroid Build Coastguard Worker            ' *  Use of this source code is governed by a BSD-style license\n'
177*d9f75844SAndroid Build Coastguard Worker            ' *  that can be found in the LICENSE file in the root of the '
178*d9f75844SAndroid Build Coastguard Worker            'source\n'
179*d9f75844SAndroid Build Coastguard Worker            ' *  tree. An additional intellectual property rights grant can be '
180*d9f75844SAndroid Build Coastguard Worker            'found\n'
181*d9f75844SAndroid Build Coastguard Worker            ' *  in the file PATENTS.  All contributing project authors may\n'
182*d9f75844SAndroid Build Coastguard Worker            ' *  be found in the AUTHORS file in the root of the source tree.\n'
183*d9f75844SAndroid Build Coastguard Worker            ' */\n\n'
184*d9f75844SAndroid Build Coastguard Worker            '#ifndef RTC_BASE_SSL_ROOTS_H_\n'
185*d9f75844SAndroid Build Coastguard Worker            '#define RTC_BASE_SSL_ROOTS_H_\n\n'
186*d9f75844SAndroid Build Coastguard Worker            '// This file is the root certificates in C form.\n\n'
187*d9f75844SAndroid Build Coastguard Worker            '// It was generated with the following script:\n'
188*d9f75844SAndroid Build Coastguard Worker            '// tools_webrtc/sslroots/generate_sslroots.py'
189*d9f75844SAndroid Build Coastguard Worker            ' %s_CA_bundle.pem\n\n'
190*d9f75844SAndroid Build Coastguard Worker            '// clang-format off\n'
191*d9f75844SAndroid Build Coastguard Worker            '// Don\'t bother formatting generated code,\n'
192*d9f75844SAndroid Build Coastguard Worker            '// also it would breaks subject/issuer lines.\n\n' % bundle_type)
193*d9f75844SAndroid Build Coastguard Worker  return output
194*d9f75844SAndroid Build Coastguard Worker
195*d9f75844SAndroid Build Coastguard Worker
196*d9f75844SAndroid Build Coastguard Workerdef _CreateOutputFooter():
197*d9f75844SAndroid Build Coastguard Worker  return '// clang-format on\n\n#endif  // RTC_BASE_SSL_ROOTS_H_\n'
198*d9f75844SAndroid Build Coastguard Worker
199*d9f75844SAndroid Build Coastguard Worker
200*d9f75844SAndroid Build Coastguard Workerdef _CreateArraySectionHeader(type_name, type_type, options):
201*d9f75844SAndroid Build Coastguard Worker  output = ('const %s kSSLCert%sList[] = {\n') % (type_type, type_name)
202*d9f75844SAndroid Build Coastguard Worker  _PrintOutput(output, options)
203*d9f75844SAndroid Build Coastguard Worker  return output
204*d9f75844SAndroid Build Coastguard Worker
205*d9f75844SAndroid Build Coastguard Worker
206*d9f75844SAndroid Build Coastguard Workerdef _AddLabelToArray(label, type_name):
207*d9f75844SAndroid Build Coastguard Worker  return ' %s_%s,\n' % (label, type_name)
208*d9f75844SAndroid Build Coastguard Worker
209*d9f75844SAndroid Build Coastguard Worker
210*d9f75844SAndroid Build Coastguard Workerdef _CreateArraySectionFooter():
211*d9f75844SAndroid Build Coastguard Worker  return '};\n\n'
212*d9f75844SAndroid Build Coastguard Worker
213*d9f75844SAndroid Build Coastguard Worker
214*d9f75844SAndroid Build Coastguard Workerdef _SafeName(original_file_name):
215*d9f75844SAndroid Build Coastguard Worker  bad_chars = ' -./\\()áéíőú\r\n'
216*d9f75844SAndroid Build Coastguard Worker  replacement_chars = ''
217*d9f75844SAndroid Build Coastguard Worker  for _ in bad_chars:
218*d9f75844SAndroid Build Coastguard Worker    replacement_chars += '_'
219*d9f75844SAndroid Build Coastguard Worker  translation_table = str.maketrans(bad_chars, replacement_chars)
220*d9f75844SAndroid Build Coastguard Worker  return original_file_name.translate(translation_table)
221*d9f75844SAndroid Build Coastguard Worker
222*d9f75844SAndroid Build Coastguard Worker
223*d9f75844SAndroid Build Coastguard Workerdef _PrintOutput(output, options):
224*d9f75844SAndroid Build Coastguard Worker  if options.verbose:
225*d9f75844SAndroid Build Coastguard Worker    print(output)
226*d9f75844SAndroid Build Coastguard Worker
227*d9f75844SAndroid Build Coastguard Worker
228*d9f75844SAndroid Build Coastguard Workerif __name__ == '__main__':
229*d9f75844SAndroid Build Coastguard Worker  main()
230