syntax = "proto2";

package android.os.statsd.conscrypt;

import "frameworks/proto_logging/stats/atoms.proto";
import "frameworks/proto_logging/stats/atom_field_options.proto";
import "frameworks/proto_logging/stats/enums/conscrypt/enums.proto";

option java_package = "com.android.os.conscrypt";

extend Atom {
    optional CertificateTransparencyLogListStateChanged certificate_transparency_log_list_state_changed = 934 [(module) = "conscrypt"];
    optional ConscryptServiceUsed conscrypt_service_used = 965 [(module) = "conscrypt"];
    optional CertificateTransparencyVerificationReported certificate_transparency_verification_reported = 989 [(module) = "conscrypt"];
    optional CertificateBlocklistBlockReported certificate_blocklist_block_reported = 1143 [(module) = "conscrypt"];
}

/*
 * Pushed atom on how successful was the loading of the log list.
 * Pushed from:
 *   external/conscrypt/common/src/main/java/org/conscrypt/metrics/StatsLogImpl.java
 */
message CertificateTransparencyLogListStateChanged {
    // The status of the log list.
    optional LogListStatus status = 1;

    // The compatibility version.
    optional LogListCompatibilityVersion loaded_compat_version = 2;

    // The minimum compatibility version available.
    optional LogListCompatibilityVersion min_compat_version = 3;

    // Log list version.
    optional int32 major_version = 4;
    optional int32 minor_version = 5;
}

/*
 * Pushed atom on certificate transparency verification outcome.
 * Pushed from:
 *   external/conscrypt/common/src/main/java/org/conscrypt/metrics/StatsLogImpl.java
 */
message CertificateTransparencyVerificationReported {
  // The outcome of the verification.
  optional VerificationResult result = 1;

  // Why was the verification triggered? Is it a default or opt-in by the app?
  optional VerificationReason reason = 2;

  // Log list version and the compatibility version.
  optional LogListCompatibilityVersion policy_compatibility_version = 3;
  optional int32 major_version = 4;
  optional int32 minor_version = 5;

  // The number of SCTs found for each origin.
  optional int32 num_cert_scts = 6;
  optional int32 num_ocsp_scts = 7;
  optional int32 num_tls_scts = 8;

  // The UID of the process doing the verification.
  optional int32 uid = 9 [(is_uid) = true];
}

/**
 * Pushed algorithm usage counters from Conscrypt.
 * Pushed from:
 *   external/conscrypt/common/src/main/java/org/conscrypt/metrics/StatsLogImpl.java
 */

enum Algorithm {
  UNKNOWN_ALGORITHM = 0;
  CIPHER = 1;
  SIGNATURE = 2;
}

enum Cipher {
  UNKNOWN_CIPHER = 0;
  AES = 1;
  DES = 2;
  DESEDE = 3;
  DSA = 4;
  BLOWFISH = 5;
  CHACHA20 = 6;
  RSA = 7;
  ARC4 = 8;
}

enum Mode {
  NO_MODE = 0;
  CBC = 1;
  CTR = 2;
  ECB = 3;
  CFB = 4;
  CTS = 5;
  GCM = 6;
  GCM_SIV = 7;
  OFB = 8;
  POLY1305 = 9;
}

enum Padding {
  NO_PADDING = 0;
  OAEP_SHA512 = 1;
  OAEP_SHA384 = 2;
  OAEP_SHA256 = 3;
  OAEP_SHA224 = 4;
  OAEP_SHA1 = 5;
  PKCS1 = 6;
  PKCS5 = 7;
  ISO10126 = 8;
}

message ConscryptServiceUsed {
  optional Algorithm algorithm = 1;
  optional Cipher cipher = 2;
  optional Mode mode = 3;
  optional Padding padding = 4;
}

/*
 * Pushed atom on a report that the blocklist was hit.
 */
message CertificateBlocklistBlockReported {
    // From where does this blocklist entry come from? Is that builtin Conscrypt or loaded at runtime?
    optional BlocklistSource source = 1;

    // The index that was hit (entry from the blocklist).
    optional int32 index = 2;

    // App UID that hit the blocklist.
    optional int32 uid = 3 [(is_uid) = true];
}
