src/pEp_internal.h
author Edouard Tisserant <edouard@pep-project.org>
Wed, 03 May 2017 18:11:49 +0200
changeset 1746 498b0671ff4e
parent 1648 158e65c83311
child 1752 6991834e731a
child 1753 01faac16cec6
child 1816 dc9bc5fa3f18
permissions -rw-r--r--
Factorized and reworked fingerprint comparison code
vb@1517
     1
// This file is under GNU General Public License 3.0
vb@1517
     2
// see LICENSE.txt
vb@1517
     3
vb@928
     4
#define PEP_ENGINE_VERSION "0.8.0"
vb@908
     5
vb@908
     6
// maximum attachment size to import as key 1MB, maximum of 20 attachments
vb@908
     7
vb@908
     8
#define MAX_KEY_SIZE (1024 * 1024)
vb@908
     9
#define MAX_KEYS_TO_IMPORT  20
vb@24
    10
vb@233
    11
// this is 20 trustwords with 79 chars max
vb@251
    12
#define MAX_TRUSTWORDS_SPACE (20 * 80)
vb@24
    13
vb@24
    14
// XML parameters string
vb@24
    15
#define PARMS_MAX 32768
vb@24
    16
vb@24
    17
// maximum busy wait time in ms
vb@24
    18
#define BUSY_WAIT_TIME 5000
vb@24
    19
vb@24
    20
// maximum line length for reading gpg.conf
vb@24
    21
#define MAX_LINELENGTH 1024
vb@24
    22
vb@24
    23
// default keyserver
vb@450
    24
#ifndef DEFAULT_KEYSERVER
vb@24
    25
#define DEFAULT_KEYSERVER "hkp://keys.gnupg.net"
vb@450
    26
#endif
vb@450
    27
vb@450
    28
// crashdump constants
vb@450
    29
#ifndef CRASHDUMP_DEFAULT_LINES
vb@450
    30
#define CRASHDUMP_DEFAULT_LINES 100
vb@450
    31
#endif
vb@450
    32
#define CRASHDUMP_MAX_LINES 32767
vb@24
    33
vb@130
    34
#include "platform.h"
vb@130
    35
vb@24
    36
#ifdef WIN32
vb@24
    37
#define LOCAL_DB windoze_local_db()
vb@24
    38
#define SYSTEM_DB windoze_system_db()
vb@24
    39
#define LIBGPGME "libgpgme-11.dll"
vb@24
    40
#else // UNIX
vb@24
    41
#define _POSIX_C_SOURCE 200809L
vb@24
    42
#include <dlfcn.h>
vb@24
    43
#define LOCAL_DB unix_local_db()
vb@24
    44
#ifndef SYSTEM_DB
vb@24
    45
#define SYSTEM_DB "/usr/share/pEp/system.db"
vb@24
    46
#endif
vb@24
    47
#ifndef LIBGPGME
vb@24
    48
#define LIBGPGME "libgpgme-pthread.so"
vb@24
    49
#endif
vb@24
    50
#endif
vb@24
    51
vb@24
    52
#include <locale.h>
vb@24
    53
#include <stdlib.h>
vb@24
    54
#include <string.h>
vb@24
    55
#include <assert.h>
vb@24
    56
#include <stdio.h>
edouard@1521
    57
#include <ctype.h>
vb@24
    58
vb@24
    59
#include "sqlite3.h"
vb@24
    60
vb@24
    61
#define _EXPORT_PEP_ENGINE_DLL
vb@24
    62
#include "pEpEngine.h"
Edouard@168
    63
Edouard@168
    64
// If not specified, build for GPG
Edouard@168
    65
#ifndef USE_NETPGP
Edouard@168
    66
#ifndef USE_GPG
Edouard@168
    67
#define USE_GPG
Edouard@168
    68
#endif
Edouard@168
    69
#endif
Edouard@168
    70
Edouard@168
    71
#ifdef USE_GPG
vb@24
    72
#include "pgp_gpg_internal.h"
vb@229
    73
#elif defined(USE_NETPGP)
Edouard@168
    74
#include "pgp_netpgp_internal.h"
vb@24
    75
#endif
vb@24
    76
vb@292
    77
#include "keymanagement.h"
vb@28
    78
#include "cryptotech.h"
vb@28
    79
#include "transport.h"
vb@604
    80
#include "sync.h"
vb@28
    81
vb@125
    82
#define NOT_IMPLEMENTED assert(0); return PEP_UNKNOWN_ERROR;
vb@24
    83
edouard@1603
    84
struct _pEpSession;
edouard@1603
    85
typedef struct _pEpSession pEpSession;
edouard@1603
    86
struct _pEpSession {
vb@24
    87
    const char *version;
Edouard@168
    88
#ifdef USE_GPG
vb@24
    89
    gpgme_ctx_t ctx;
vb@229
    90
#elif defined(USE_NETPGP)
Edouard@252
    91
    pEpNetPGPSession ctx;
vb@24
    92
#endif
vb@24
    93
vb@62
    94
    PEP_cryptotech_t *cryptotech;
vb@62
    95
    PEP_transport_t *transports;
vb@28
    96
vb@24
    97
    sqlite3 *db;
vb@24
    98
    sqlite3 *system_db;
vb@24
    99
vb@24
   100
    sqlite3_stmt *log;
vb@233
   101
    sqlite3_stmt *trustword;
vb@24
   102
    sqlite3_stmt *get_identity;
vb@24
   103
    sqlite3_stmt *set_person;
edouard@1234
   104
    sqlite3_stmt *set_device_group;
edouard@1235
   105
    sqlite3_stmt *get_device_group;
vb@24
   106
    sqlite3_stmt *set_pgp_keypair;
vb@24
   107
    sqlite3_stmt *set_identity;
vb@932
   108
    sqlite3_stmt *set_identity_flags;
edouard@1394
   109
    sqlite3_stmt *unset_identity_flags;
vb@24
   110
    sqlite3_stmt *set_trust;
vb@24
   111
    sqlite3_stmt *get_trust;
vb@251
   112
    sqlite3_stmt *least_trust;
vb@357
   113
    sqlite3_stmt *mark_compromized;
Edouard@409
   114
    sqlite3_stmt *reset_trust;
vb@450
   115
    sqlite3_stmt *crashdump;
vb@458
   116
    sqlite3_stmt *languagelist;
vb@458
   117
    sqlite3_stmt *i18n_token;
fdik@494
   118
fdik@494
   119
    // blacklist
fdik@494
   120
    sqlite3_stmt *blacklist_add;
fdik@494
   121
    sqlite3_stmt *blacklist_delete;
fdik@494
   122
    sqlite3_stmt *blacklist_is_listed;
fdik@494
   123
    sqlite3_stmt *blacklist_retrieve;
Edouard@584
   124
    
Edouard@584
   125
    // Own keys
Edouard@584
   126
    sqlite3_stmt *own_key_is_listed;
vb@955
   127
    sqlite3_stmt *own_identities_retrieve;
edouard@1394
   128
    sqlite3_stmt *own_keys_retrieve;
edouard@1394
   129
    sqlite3_stmt *set_own_key;
vb@292
   130
vb@632
   131
    // sequence value
vb@633
   132
    sqlite3_stmt *sequence_value1;
vb@633
   133
    sqlite3_stmt *sequence_value2;
vb@1085
   134
    sqlite3_stmt *sequence_value3;
vb@632
   135
edouard@1236
   136
    // revoked keys
Edouard@693
   137
    sqlite3_stmt *set_revoked;
Edouard@693
   138
    sqlite3_stmt *get_revoked;
Edouard@693
   139
Edouard@693
   140
    // callbacks
vb@292
   141
    examine_identity_t examine_identity;
vb@292
   142
    void *examine_management;
edouard@1462
   143
    void *sync_management;
vb@599
   144
    void *sync_obj;
vb@604
   145
    messageToSend_t messageToSend;
edouard@1459
   146
    notifyHandshake_t notifyHandshake;
vb@1043
   147
    inject_sync_msg_t inject_sync_msg;
vb@1043
   148
    retrieve_next_sync_msg_t retrieve_next_sync_msg;
vb@464
   149
edouard@1236
   150
    // key sync
edouard@1603
   151
    pEpSession* sync_session;
vb@690
   152
    DeviceState_state sync_state;
edouard@1460
   153
    void* sync_state_payload;
edouard@1236
   154
    char sync_uuid[37];
edouard@1316
   155
    time_t LastCannotDecrypt;
edouard@1316
   156
    time_t LastUpdateRequest;
vb@690
   157
vb@464
   158
    // runtime config
vb@464
   159
vb@464
   160
    bool passive_mode;
vb@464
   161
    bool unencrypted_subject;
Edouard@720
   162
    bool use_only_own_private_keys;
vb@1110
   163
    bool keep_sync_msg;
Edouard@720
   164
    
edouard@1603
   165
};
vb@48
   166
vb@62
   167
PEP_STATUS init_transport_system(PEP_SESSION session, bool in_first);
vb@62
   168
void release_transport_system(PEP_SESSION session, bool out_last);
vb@48
   169
krista@1639
   170
/* NOT to be exposed to the outside!!! */
krista@1639
   171
PEP_STATUS encrypt_only(
krista@1639
   172
        PEP_SESSION session, const stringlist_t *keylist, const char *ptext,
krista@1639
   173
        size_t psize, char **ctext, size_t *csize
krista@1639
   174
);
krista@1639
   175
vb@216
   176
#ifdef NDEBUG
vb@216
   177
#define DEBUG_LOG(TITLE, ENTITY, DESC)
vb@216
   178
#else
huss@1571
   179
#ifdef ANDROID
huss@1571
   180
#include <android/log.h>
edouard@1630
   181
#define  LOG_MORE(...)  __android_log_print(ANDROID_LOG_DEBUG, "pEpEngine", " %s :: %s :: %s ", __VA_ARGS__);
edouard@1630
   182
#else
edouard@1630
   183
#include <stdio.h>
edouard@1630
   184
#define  LOG_MORE(...)  printf("pEpEngine DEBUG_LOG('%s','%s','%s')\n", __VA_ARGS__);
huss@1571
   185
#endif
edouard@1630
   186
#define DEBUG_LOG(TITLE, ENTITY, DESC) {\
edouard@1630
   187
    log_event(session, (TITLE), (ENTITY), (DESC), "debug");\
edouard@1630
   188
    LOG_MORE((TITLE), (ENTITY), (DESC))\
edouard@1630
   189
}
vb@216
   190
#endif
vb@216
   191
edouard@1746
   192
typedef enum _normalize_hex_rest_t {
edouard@1746
   193
    accept_hex,
edouard@1746
   194
    ignore_hex,
edouard@1746
   195
    reject_hex
edouard@1746
   196
} normalize_hex_res_t;
edouard@1746
   197
edouard@1746
   198
static inline normalize_hex_res_t _normalize_hex(char *hex) 
edouard@1746
   199
{
edouard@1746
   200
    if (*hex >= '0' && *hex <= '9')
edouard@1746
   201
        return accept_hex;
edouard@1746
   202
edouard@1746
   203
    if (*hex >= 'A' && *hex <= 'F') {
edouard@1746
   204
        *hex += 'a' - 'A';
edouard@1746
   205
        return accept_hex;
edouard@1746
   206
    }
edouard@1746
   207
edouard@1746
   208
    if (*hex >= 'a' && *hex <= 'f') 
edouard@1746
   209
        return accept_hex;
edouard@1746
   210
edouard@1746
   211
    if (*hex == ' ') 
edouard@1746
   212
        return ignore_hex;
edouard@1746
   213
edouard@1746
   214
    return reject_hex;
edouard@1746
   215
}
edouard@1746
   216
edouard@1521
   217
// Space tolerant and case insensitive fingerprint string compare
edouard@1746
   218
static inline PEP_STATUS _compare_fprs(
edouard@1746
   219
        const char* fpra,
edouard@1746
   220
        size_t fpras,
edouard@1746
   221
        const char* fprb,
edouard@1746
   222
        size_t fprbs,
edouard@1746
   223
        int* comparison)
edouard@1746
   224
{
edouard@1746
   225
edouard@1746
   226
    size_t ai = 0;
edouard@1746
   227
    size_t bi = 0;
edouard@1746
   228
    size_t significant = 0;
edouard@1746
   229
    int _comparison = 0;
edouard@1746
   230
    const int _FULL_FINGERPRINT_LENGTH = 40;
edouard@1746
   231
   
edouard@1746
   232
    // First compare every non-ignored chars until an end is reached
edouard@1746
   233
    while(ai < fpras && bi < fprbs)
edouard@1746
   234
    {
edouard@1746
   235
        char fprac = fpra[ai];
edouard@1746
   236
        char fprbc = fprb[bi];
edouard@1746
   237
        normalize_hex_res_t fprah = _normalize_hex(&fprac);
edouard@1746
   238
        normalize_hex_res_t fprbh = _normalize_hex(&fprbc);
edouard@1746
   239
edouard@1746
   240
        if(fprah == reject_hex || fprbh == reject_hex)
edouard@1746
   241
            return PEP_ILLEGAL_VALUE;
edouard@1746
   242
edouard@1746
   243
        if ( fprah == ignore_hex )
edouard@1746
   244
        {
edouard@1746
   245
            ai++;
edouard@1746
   246
        }
edouard@1746
   247
        else if ( fprbh == ignore_hex )
edouard@1746
   248
        {
edouard@1746
   249
            bi++;
edouard@1746
   250
        }
edouard@1746
   251
        else
edouard@1746
   252
        {
edouard@1746
   253
            if(fprac != fprbc && _comparison == 0 )
edouard@1746
   254
            {
edouard@1746
   255
                _comparison = fprac > fprbc ? 1 : -1;
edouard@1746
   256
            }
edouard@1746
   257
edouard@1746
   258
            significant++;
edouard@1746
   259
            ai++;
edouard@1746
   260
            bi++;
edouard@1746
   261
edouard@1746
   262
        } 
edouard@1746
   263
    }
edouard@1746
   264
edouard@1746
   265
    // Bail out if we didn't got enough significnt chars
edouard@1746
   266
    if (significant != _FULL_FINGERPRINT_LENGTH )
edouard@1746
   267
        return PEP_TRUSTWORDS_FPR_WRONG_LENGTH;
edouard@1746
   268
edouard@1746
   269
    // Then purge remaining chars, all must be ignored chars
edouard@1746
   270
    while ( ai < fpras )
edouard@1746
   271
    {
edouard@1746
   272
        char fprac = fpra[ai];
edouard@1746
   273
        normalize_hex_res_t fprah = _normalize_hex(&fprac);
edouard@1746
   274
        if( fprah == reject_hex )
edouard@1746
   275
            return PEP_ILLEGAL_VALUE;
edouard@1746
   276
        if ( fprah != ignore_hex )
edouard@1746
   277
            return PEP_TRUSTWORDS_FPR_WRONG_LENGTH;
edouard@1746
   278
        ai++;
edouard@1746
   279
    }
edouard@1746
   280
    while ( bi < fprbs )
edouard@1746
   281
    {
edouard@1746
   282
        char fprbc = fprb[bi];
edouard@1746
   283
        normalize_hex_res_t fprbh = _normalize_hex(&fprbc);
edouard@1746
   284
        if( fprbh == reject_hex )
edouard@1746
   285
            return PEP_ILLEGAL_VALUE;
edouard@1746
   286
        if ( fprbh != ignore_hex )
edouard@1746
   287
            return PEP_TRUSTWORDS_FPR_WRONG_LENGTH;
edouard@1746
   288
        bi++;
edouard@1746
   289
    }
edouard@1746
   290
edouard@1746
   291
    *comparison = _comparison;
edouard@1746
   292
    return PEP_STATUS_OK;
edouard@1746
   293
}
edouard@1746
   294
edouard@1521
   295
static inline int _same_fpr(
edouard@1521
   296
        const char* fpra,
edouard@1521
   297
        size_t fpras,
edouard@1521
   298
        const char* fprb,
edouard@1521
   299
        size_t fprbs
edouard@1521
   300
    )
edouard@1521
   301
{
edouard@1746
   302
    // illegal values are ignored, and considered not same.
edouard@1746
   303
    int comparison = 1;
edouard@1746
   304
edouard@1746
   305
    _compare_fprs(fpra, fpras, fprb, fprbs, &comparison);
edouard@1746
   306
edouard@1746
   307
    return comparison == 0;
edouard@1521
   308
}