src/pgp_gpg.c
author Edouard Tisserant
Fri, 13 May 2016 15:52:37 +0200
changeset 620 a6368004706a
parent 523 afaf34a57cc6
child 621 5ffe32a37fb4
permissions -rw-r--r--
When deleting personal keys, crash appeared in key_expired, dereferencing null pointer
vb@219
     1
#include "platform.h"
vb@130
     2
#include "pEp_internal.h"
vb@24
     3
#include "pgp_gpg.h"
vb@24
     4
vb@78
     5
#include <limits.h>
vb@78
     6
vb@62
     7
#include "wrappers.h"
vb@62
     8
vb@45
     9
#define _GPGERR(X) ((X) & 0xffffL)
vb@45
    10
vb@76
    11
static void *gpgme;
vb@76
    12
static struct gpg_s gpg;
vb@74
    13
vb@78
    14
static bool ensure_config_values(stringlist_t *keys, stringlist_t *values)
vb@24
    15
{
vb@24
    16
    static char buf[MAX_LINELENGTH];
vb@78
    17
    int r;
vb@62
    18
    FILE *f;
vb@78
    19
    stringlist_t *_k;
vb@78
    20
    stringlist_t *_v;
vb@79
    21
    unsigned int i;
vb@78
    22
    unsigned int found = 0;
vb@62
    23
vb@62
    24
    f = Fopen(gpg_conf(), "r");
vb@63
    25
    if (f == NULL && errno == ENOMEM)
vb@62
    26
        return false;
vb@24
    27
vb@24
    28
    if (f != NULL) {
vb@78
    29
        int length = stringlist_length(keys);
vb@79
    30
        unsigned int n = (1 << length) - 1;
vb@78
    31
vb@78
    32
        assert(length <= sizeof(unsigned int) * CHAR_BIT);
vb@78
    33
        assert(length == stringlist_length(values));
vb@78
    34
vb@62
    35
        do {
vb@62
    36
            char * s;
vb@62
    37
vb@63
    38
            s = Fgets(buf, MAX_LINELENGTH, f);
vb@78
    39
            if (!feof(f)) {
vb@78
    40
                assert(s);
vb@78
    41
                if (s == NULL)
vb@78
    42
                    return false;
vb@62
    43
vb@78
    44
                if (s && !feof(f)) {
vb@80
    45
                    char * rest;
vb@80
    46
                    char * t = strtok_r(s, " ", &rest);
vb@78
    47
                    for (i = 1, _k = keys, _v = values; _k != NULL;
vb@78
    48
                            _k = _k->next, _v = _v->next, i <<= 1) {
vb@80
    49
                        if (t && strncmp(t, _k->value, strlen(_k->value)) == 0)
vb@78
    50
                            found |= i;
vb@78
    51
vb@78
    52
                        if (i == n) {
vb@78
    53
                            r = Fclose(f);
vb@78
    54
                            return true;
vb@78
    55
                        }
vb@78
    56
                    }
vb@24
    57
                }
vb@24
    58
            }
vb@62
    59
        } while (!feof(f));
vb@63
    60
        f = Freopen(gpg_conf(), "a", f);
vb@24
    61
    }
vb@24
    62
    else {
vb@63
    63
        f = Fopen(gpg_conf(), "w");
vb@24
    64
    }
vb@24
    65
vb@24
    66
    assert(f);
vb@24
    67
    if (f == NULL)
vb@24
    68
        return false;
vb@24
    69
vb@78
    70
    for (i = 1, _k = keys, _v = values; _k != NULL; _k = _k->next,
vb@78
    71
            _v = _v->next, i <<= 1) {
vb@78
    72
        if ((found & i) == 0) {
vb@79
    73
            r = Fprintf(f, "%s %s\n", _k->value, _v->value);
vb@79
    74
            assert(r >= 0);
vb@78
    75
        }
vb@78
    76
    }
vb@62
    77
vb@63
    78
    r = Fclose(f);
vb@62
    79
    assert(r == 0);
vb@24
    80
vb@24
    81
    return true;
vb@24
    82
}
vb@24
    83
vb@62
    84
PEP_STATUS pgp_init(PEP_SESSION session, bool in_first)
vb@24
    85
{
vb@66
    86
    PEP_STATUS status = PEP_STATUS_OK;
vb@24
    87
    gpgme_error_t gpgme_error;
vb@62
    88
    bool bResult;
Edouard@348
    89
    char *cLocal;
vb@62
    90
    
vb@62
    91
    if (in_first) {
vb@78
    92
        stringlist_t *conf_keys   = new_stringlist("keyserver");
vb@78
    93
        stringlist_t *conf_values = new_stringlist("hkp://keys.gnupg.net");
vb@79
    94
vb@78
    95
        stringlist_add(conf_keys, "cert-digest-algo");
vb@78
    96
        stringlist_add(conf_values, "SHA256");
vb@78
    97
vb@80
    98
        stringlist_add(conf_keys, "no-emit-version");
vb@80
    99
        stringlist_add(conf_values, "");
vb@80
   100
vb@80
   101
        stringlist_add(conf_keys, "no-comments");
vb@80
   102
        stringlist_add(conf_values, "");
vb@80
   103
vb@80
   104
        stringlist_add(conf_keys, "personal-cipher-preferences");
vb@80
   105
        stringlist_add(conf_values, "AES AES256 AES192 CAST5");
vb@80
   106
vb@80
   107
        stringlist_add(conf_keys, "personal-digest-preferences");
vb@312
   108
        stringlist_add(conf_values, "SHA256 SHA512 SHA384 SHA224");
vb@80
   109
        
vb@78
   110
        bResult = ensure_config_values(conf_keys, conf_values);
vb@24
   111
vb@78
   112
        free_stringlist(conf_keys);
vb@78
   113
        free_stringlist(conf_values);
vb@78
   114
Edouard@175
   115
        assert(bResult);
Edouard@175
   116
        if(!bResult){
Edouard@175
   117
            status = PEP_INIT_NO_GPG_HOME;
Edouard@175
   118
            goto pep_error;
Edouard@175
   119
        }
Edouard@175
   120
Edouard@175
   121
vb@62
   122
        gpgme = dlopen(LIBGPGME, RTLD_LAZY);
vb@62
   123
        if (gpgme == NULL) {
vb@66
   124
            status = PEP_INIT_CANNOT_LOAD_GPGME;
vb@66
   125
            goto pep_error;
vb@62
   126
        }
vb@62
   127
vb@62
   128
        memset(&gpg, 0, sizeof(struct gpg_s));
vb@62
   129
vb@62
   130
        gpg.gpgme_set_locale
vb@62
   131
            = (gpgme_set_locale_t) (intptr_t) dlsym(gpgme,
vb@62
   132
            "gpgme_set_locale");
vb@62
   133
        assert(gpg.gpgme_set_locale);
vb@62
   134
vb@62
   135
        gpg.gpgme_check
vb@62
   136
            = (gpgme_check_version_t) (intptr_t) dlsym(gpgme,
vb@62
   137
            "gpgme_check_version");
vb@62
   138
        assert(gpg.gpgme_check);
vb@62
   139
vb@62
   140
        gpg.gpgme_new
vb@62
   141
            = (gpgme_new_t) (intptr_t) dlsym(gpgme, "gpgme_new");
vb@62
   142
        assert(gpg.gpgme_new);
vb@62
   143
vb@62
   144
        gpg.gpgme_release
vb@62
   145
            = (gpgme_release_t) (intptr_t) dlsym(gpgme, "gpgme_release");
vb@62
   146
        assert(gpg.gpgme_release);
vb@62
   147
vb@507
   148
        gpg.gpgme_get_engine_info
vb@507
   149
            = (gpgme_get_engine_info_t) (intptr_t) dlsym(gpgme,
vb@507
   150
            "gpgme_get_engine_info");
vb@507
   151
        assert(gpg.gpgme_get_engine_info);
vb@507
   152
vb@62
   153
        gpg.gpgme_set_protocol
vb@62
   154
            = (gpgme_set_protocol_t) (intptr_t) dlsym(gpgme,
vb@62
   155
            "gpgme_set_protocol");
vb@62
   156
        assert(gpg.gpgme_set_protocol);
vb@62
   157
vb@62
   158
        gpg.gpgme_set_armor
vb@62
   159
            = (gpgme_set_armor_t) (intptr_t) dlsym(gpgme,
vb@62
   160
            "gpgme_set_armor");
vb@62
   161
        assert(gpg.gpgme_set_armor);
vb@62
   162
vb@62
   163
        gpg.gpgme_data_new
vb@62
   164
            = (gpgme_data_new_t) (intptr_t) dlsym(gpgme,
vb@62
   165
            "gpgme_data_new");
vb@62
   166
        assert(gpg.gpgme_data_new);
vb@62
   167
vb@62
   168
        gpg.gpgme_data_new_from_mem
vb@62
   169
            = (gpgme_data_new_from_mem_t) (intptr_t) dlsym(gpgme,
vb@62
   170
            "gpgme_data_new_from_mem");
vb@62
   171
        assert(gpg.gpgme_data_new_from_mem);
vb@62
   172
vb@221
   173
        gpg.gpgme_data_new_from_cbs
vb@221
   174
            = (gpgme_data_new_from_cbs_t) (intptr_t) dlsym(gpgme,
vb@221
   175
            "gpgme_data_new_from_cbs");
vb@221
   176
        assert(gpg.gpgme_data_new_from_cbs);
vb@221
   177
vb@62
   178
        gpg.gpgme_data_release
vb@62
   179
            = (gpgme_data_release_t) (intptr_t) dlsym(gpgme,
vb@62
   180
            "gpgme_data_release");
vb@62
   181
        assert(gpg.gpgme_data_release);
vb@62
   182
vb@62
   183
        gpg.gpgme_data_identify
vb@62
   184
            = (gpgme_data_identify_t) (intptr_t) dlsym(gpgme,
vb@62
   185
            "gpgme_data_identify");
vb@62
   186
        assert(gpg.gpgme_data_identify);
vb@62
   187
vb@62
   188
        gpg.gpgme_data_seek
vb@62
   189
            = (gpgme_data_seek_t) (intptr_t) dlsym(gpgme,
vb@62
   190
            "gpgme_data_seek");
vb@62
   191
        assert(gpg.gpgme_data_seek);
vb@62
   192
vb@62
   193
        gpg.gpgme_data_read
vb@62
   194
            = (gpgme_data_read_t) (intptr_t) dlsym(gpgme,
vb@62
   195
            "gpgme_data_read");
vb@62
   196
        assert(gpg.gpgme_data_read);
vb@62
   197
vb@62
   198
        gpg.gpgme_op_decrypt
vb@62
   199
            = (gpgme_op_decrypt_t) (intptr_t) dlsym(gpgme,
vb@62
   200
            "gpgme_op_decrypt");
vb@62
   201
        assert(gpg.gpgme_op_decrypt);
vb@62
   202
vb@62
   203
        gpg.gpgme_op_verify
vb@62
   204
            = (gpgme_op_verify_t) (intptr_t) dlsym(gpgme,
vb@62
   205
            "gpgme_op_verify");
vb@62
   206
        assert(gpg.gpgme_op_verify);
vb@62
   207
vb@62
   208
        gpg.gpgme_op_decrypt_verify
vb@62
   209
            = (gpgme_op_decrypt_verify_t) (intptr_t) dlsym(gpgme,
vb@62
   210
            "gpgme_op_decrypt_verify");
vb@62
   211
        assert(gpg.gpgme_op_decrypt_verify);
vb@62
   212
vb@62
   213
        gpg.gpgme_op_decrypt_result
vb@62
   214
            = (gpgme_op_decrypt_result_t) (intptr_t) dlsym(gpgme,
vb@62
   215
            "gpgme_op_decrypt_result");
vb@62
   216
        assert(gpg.gpgme_op_decrypt_result);
vb@62
   217
vb@62
   218
        gpg.gpgme_op_encrypt_sign
vb@62
   219
            = (gpgme_op_encrypt_sign_t) (intptr_t) dlsym(gpgme,
vb@62
   220
            "gpgme_op_encrypt_sign");
vb@62
   221
        assert(gpg.gpgme_op_encrypt_sign);
vb@62
   222
vb@62
   223
        gpg.gpgme_op_verify_result
vb@62
   224
            = (gpgme_op_verify_result_t) (intptr_t) dlsym(gpgme,
vb@62
   225
            "gpgme_op_verify_result");
vb@62
   226
        assert(gpg.gpgme_op_verify_result);
vb@62
   227
vb@62
   228
        gpg.gpgme_signers_clear
vb@62
   229
            = (gpgme_signers_clear_t) (intptr_t) dlsym(gpgme,
vb@62
   230
            "gpgme_signers_clear");
vb@62
   231
        assert(gpg.gpgme_signers_clear);
vb@62
   232
vb@62
   233
        gpg.gpgme_signers_add
vb@62
   234
            = (gpgme_signers_add_t) (intptr_t) dlsym(gpgme,
vb@62
   235
            "gpgme_signers_add");
vb@62
   236
        assert(gpg.gpgme_signers_add);
vb@62
   237
vb@62
   238
        gpg.gpgme_get_key
vb@62
   239
            = (gpgme_get_key_t) (intptr_t) dlsym(gpgme, "gpgme_get_key");
vb@62
   240
        assert(gpg.gpgme_get_key);
vb@62
   241
vb@62
   242
        gpg.gpgme_op_genkey
vb@62
   243
            = (gpgme_op_genkey_t) (intptr_t) dlsym(gpgme,
vb@62
   244
            "gpgme_op_genkey");
vb@62
   245
        assert(gpg.gpgme_op_genkey);
vb@62
   246
vb@62
   247
        gpg.gpgme_op_genkey_result
vb@62
   248
            = (gpgme_op_genkey_result_t) (intptr_t) dlsym(gpgme,
vb@62
   249
            "gpgme_op_genkey_result");
vb@62
   250
        assert(gpg.gpgme_op_genkey_result);
vb@62
   251
vb@62
   252
        gpg.gpgme_op_delete = (gpgme_op_delete_t) (intptr_t)
vb@62
   253
            dlsym(gpgme, "gpgme_op_delete");
vb@62
   254
        assert(gpg.gpgme_op_delete);
vb@62
   255
vb@62
   256
        gpg.gpgme_op_import = (gpgme_op_import_t) (intptr_t)
vb@62
   257
            dlsym(gpgme, "gpgme_op_import");
vb@62
   258
        assert(gpg.gpgme_op_import);
vb@62
   259
vb@62
   260
        gpg.gpgme_op_export = (gpgme_op_export_t) (intptr_t)
vb@62
   261
            dlsym(gpgme, "gpgme_op_export");
vb@62
   262
        assert(gpg.gpgme_op_export);
vb@62
   263
vb@62
   264
        gpg.gpgme_set_keylist_mode = (gpgme_set_keylist_mode_t) (intptr_t)
vb@62
   265
            dlsym(gpgme, "gpgme_set_keylist_mode");
vb@62
   266
        assert(gpg.gpgme_set_keylist_mode);
vb@62
   267
vb@62
   268
        gpg.gpgme_get_keylist_mode = (gpgme_get_keylist_mode_t) (intptr_t)
vb@62
   269
            dlsym(gpgme, "gpgme_get_keylist_mode");
vb@62
   270
        assert(gpg.gpgme_get_keylist_mode);
vb@62
   271
vb@62
   272
        gpg.gpgme_op_keylist_start = (gpgme_op_keylist_start_t) (intptr_t)
vb@62
   273
            dlsym(gpgme, "gpgme_op_keylist_start");
vb@62
   274
        assert(gpg.gpgme_op_keylist_start);
vb@62
   275
vb@62
   276
        gpg.gpgme_op_keylist_next = (gpgme_op_keylist_next_t) (intptr_t)
vb@62
   277
            dlsym(gpgme, "gpgme_op_keylist_next");
vb@62
   278
        assert(gpg.gpgme_op_keylist_next);
vb@62
   279
vb@62
   280
        gpg.gpgme_op_keylist_end = (gpgme_op_keylist_end_t) (intptr_t)
vb@62
   281
            dlsym(gpgme, "gpgme_op_keylist_end");
vb@62
   282
        assert(gpg.gpgme_op_keylist_end);
vb@62
   283
vb@62
   284
        gpg.gpgme_op_import_keys = (gpgme_op_import_keys_t) (intptr_t)
vb@62
   285
            dlsym(gpgme, "gpgme_op_import_keys");
vb@62
   286
        assert(gpg.gpgme_op_import_keys);
vb@62
   287
vb@62
   288
        gpg.gpgme_key_ref = (gpgme_key_ref_t) (intptr_t)
vb@62
   289
            dlsym(gpgme, "gpgme_key_ref");
vb@62
   290
        assert(gpg.gpgme_key_ref);
vb@62
   291
vb@62
   292
        gpg.gpgme_key_unref = (gpgme_key_unref_t) (intptr_t)
vb@62
   293
            dlsym(gpgme, "gpgme_key_unref");
vb@62
   294
        assert(gpg.gpgme_key_unref);
vb@62
   295
vb@221
   296
        gpg.gpgme_op_edit = (gpgme_op_edit_t) (intptr_t)
vb@221
   297
            dlsym(gpgme, "gpgme_op_edit");
vb@221
   298
        assert(gpg.gpgme_op_edit);
vb@221
   299
vb@223
   300
        gpg.gpgme_io_write = (gpgme_io_write_t) (intptr_t)
vb@223
   301
            dlsym(gpgme, "gpgme_io_write");
vb@223
   302
        assert(gpg.gpgme_io_write);
vb@223
   303
vb@62
   304
        gpg.version = gpg.gpgme_check(NULL);
vb@62
   305
        
Edouard@348
   306
        cLocal = setlocale(LC_ALL, NULL);
Edouard@348
   307
        if (!cLocal || (strcmp(cLocal, "C") == 0))
vb@62
   308
            setlocale(LC_ALL, "");
vb@62
   309
vb@62
   310
        gpg.gpgme_set_locale(NULL, LC_CTYPE, setlocale(LC_CTYPE, NULL));
vb@62
   311
#ifdef LC_MESSAGES // Windoze
vb@62
   312
        gpg.gpgme_set_locale (NULL, LC_MESSAGES, setlocale(LC_MESSAGES, NULL));
vb@62
   313
#endif
vb@24
   314
    }
vb@24
   315
vb@62
   316
    gpgme_error = gpg.gpgme_new(&session->ctx);
vb@45
   317
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   318
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@66
   319
        status = PEP_INIT_GPGME_INIT_FAILED;
vb@66
   320
        goto pep_error;
vb@24
   321
    }
vb@46
   322
    assert(session->ctx);
vb@24
   323
vb@62
   324
    gpgme_error = gpg.gpgme_set_protocol(session->ctx, GPGME_PROTOCOL_OpenPGP);
vb@45
   325
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   326
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   327
vb@62
   328
    gpg.gpgme_set_armor(session->ctx, 1);
vb@24
   329
vb@24
   330
    return PEP_STATUS_OK;
vb@66
   331
vb@66
   332
pep_error:
vb@66
   333
    pgp_release(session, in_first);
vb@66
   334
    return status;
vb@24
   335
}
vb@24
   336
vb@62
   337
void pgp_release(PEP_SESSION session, bool out_last)
vb@24
   338
{
vb@62
   339
    if (session->ctx) {
vb@74
   340
        gpg.gpgme_release(session->ctx);
vb@62
   341
        session->ctx = NULL;
vb@62
   342
    }
vb@62
   343
vb@74
   344
    if (out_last)
vb@74
   345
        if (gpgme)
vb@74
   346
            dlclose(gpgme);
vb@24
   347
}
vb@24
   348
vb@24
   349
PEP_STATUS pgp_decrypt_and_verify(
vb@24
   350
    PEP_SESSION session, const char *ctext, size_t csize,
vb@24
   351
    char **ptext, size_t *psize, stringlist_t **keylist
vb@24
   352
    )
vb@24
   353
{
vb@24
   354
    PEP_STATUS result;
vb@24
   355
    gpgme_error_t gpgme_error;
vb@24
   356
    gpgme_data_t cipher, plain;
vb@24
   357
    gpgme_data_type_t dt;
vb@24
   358
vb@24
   359
    stringlist_t *_keylist = NULL;
vb@24
   360
    int i_key = 0;
vb@24
   361
vb@46
   362
    assert(session);
vb@24
   363
    assert(ctext);
vb@24
   364
    assert(csize);
vb@24
   365
    assert(ptext);
vb@24
   366
    assert(psize);
vb@24
   367
    assert(keylist);
vb@24
   368
vb@24
   369
    *ptext = NULL;
vb@24
   370
    *psize = 0;
vb@24
   371
    *keylist = NULL;
vb@24
   372
vb@74
   373
    gpgme_error = gpg.gpgme_data_new_from_mem(&cipher, ctext, csize, 0);
vb@45
   374
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   375
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   376
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@24
   377
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   378
            return PEP_OUT_OF_MEMORY;
vb@24
   379
        else
vb@24
   380
            return PEP_UNKNOWN_ERROR;
vb@24
   381
    }
vb@24
   382
vb@74
   383
    gpgme_error = gpg.gpgme_data_new(&plain);
vb@45
   384
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   385
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   386
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@74
   387
        gpg.gpgme_data_release(cipher);
vb@24
   388
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   389
            return PEP_OUT_OF_MEMORY;
vb@24
   390
        else
vb@24
   391
            return PEP_UNKNOWN_ERROR;
vb@24
   392
    }
vb@24
   393
vb@74
   394
    dt = gpg.gpgme_data_identify(cipher);
vb@24
   395
    switch (dt) {
vb@24
   396
    case GPGME_DATA_TYPE_PGP_SIGNED:
vb@24
   397
    case GPGME_DATA_TYPE_PGP_OTHER:
vb@74
   398
        gpgme_error = gpg.gpgme_op_decrypt_verify(session->ctx, cipher,
vb@24
   399
            plain);
vb@45
   400
        gpgme_error = _GPGERR(gpgme_error);
vb@24
   401
        assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
   402
        assert(gpgme_error != GPG_ERR_NO_DATA);
vb@24
   403
vb@24
   404
        switch (gpgme_error) {
vb@344
   405
            case GPG_ERR_NO_ERROR:
vb@344
   406
            {
vb@344
   407
                gpgme_verify_result_t gpgme_verify_result;
vb@344
   408
                char *_buffer = NULL;
vb@344
   409
                size_t reading;
vb@344
   410
                size_t length = gpg.gpgme_data_seek(plain, 0, SEEK_END);
vb@344
   411
                gpgme_signature_t gpgme_signature;
vb@24
   412
vb@344
   413
                assert(length != -1);
vb@344
   414
                gpg.gpgme_data_seek(plain, 0, SEEK_SET);
vb@24
   415
vb@344
   416
                // TODO: make things less memory consuming
vb@344
   417
                // the following algorithm allocates memory for the complete
vb@344
   418
                // text
vb@24
   419
vb@344
   420
                _buffer = malloc(length + 1);
vb@344
   421
                assert(_buffer);
vb@344
   422
                if (_buffer == NULL) {
vb@74
   423
                    gpg.gpgme_data_release(plain);
vb@74
   424
                    gpg.gpgme_data_release(cipher);
vb@24
   425
                    return PEP_OUT_OF_MEMORY;
vb@24
   426
                }
vb@24
   427
vb@344
   428
                reading = gpg.gpgme_data_read(plain, _buffer, length);
vb@344
   429
                assert(length == reading);
vb@24
   430
vb@344
   431
                gpgme_verify_result =
vb@344
   432
                    gpg.gpgme_op_verify_result(session->ctx);
vb@344
   433
                assert(gpgme_verify_result);
vb@344
   434
                gpgme_signature = gpgme_verify_result->signatures;
vb@24
   435
vb@344
   436
                if (gpgme_signature) {
vb@344
   437
                    stringlist_t *k;
vb@344
   438
                    _keylist = new_stringlist(NULL);
vb@24
   439
                    assert(_keylist);
vb@24
   440
                    if (_keylist == NULL) {
vb@344
   441
                        gpg.gpgme_data_release(plain);
vb@344
   442
                        gpg.gpgme_data_release(cipher);
vb@344
   443
                        free(_buffer);
vb@344
   444
                        return PEP_OUT_OF_MEMORY;
vb@344
   445
                    }
vb@344
   446
                    k = _keylist;
vb@344
   447
vb@344
   448
                    result = PEP_DECRYPTED_AND_VERIFIED;
vb@344
   449
                    do {
vb@344
   450
                        switch (_GPGERR(gpgme_signature->status)) {
vb@344
   451
                        case GPG_ERR_NO_ERROR:
Edouard@505
   452
                        {
Edouard@505
   453
                            gpgme_key_t key;
Edouard@505
   454
                            memset(&key,0,sizeof(key));
Edouard@505
   455
Edouard@505
   456
                            gpgme_error = gpg.gpgme_get_key(session->ctx,
Edouard@505
   457
                                gpgme_signature->fpr, &key, 0);
Edouard@505
   458
                            gpgme_error = _GPGERR(gpgme_error);
Edouard@505
   459
                            assert(gpgme_error != GPG_ERR_ENOMEM);
Edouard@505
   460
                            if (gpgme_error == GPG_ERR_ENOMEM) {
Edouard@505
   461
                                free_stringlist(_keylist);
Edouard@505
   462
                                gpg.gpgme_data_release(plain);
Edouard@505
   463
                                gpg.gpgme_data_release(cipher);
Edouard@505
   464
                                free(_buffer);
Edouard@505
   465
                                return PEP_OUT_OF_MEMORY;
Edouard@505
   466
                            }
Edouard@505
   467
                            // Primary key is given as the first subkey
Edouard@505
   468
                            if (key->subkeys && key->subkeys->fpr && key->subkeys->fpr[0]){
Edouard@505
   469
                                k = stringlist_add(k, key->subkeys->fpr);
Edouard@505
   470
                                if (k == NULL) {
Edouard@505
   471
                                    free_stringlist(_keylist);
Edouard@505
   472
                                    gpg.gpgme_data_release(plain);
Edouard@505
   473
                                    gpg.gpgme_data_release(cipher);
Edouard@505
   474
                                    free(_buffer);
Edouard@505
   475
                                    return PEP_OUT_OF_MEMORY;
Edouard@505
   476
                                }
Edouard@505
   477
                            }
Edouard@505
   478
                            else {
Edouard@505
   479
                                result = PEP_DECRYPT_SIGNATURE_DOES_NOT_MATCH;
Edouard@505
   480
                                break;
Edouard@505
   481
                            }
Edouard@505
   482
Edouard@505
   483
                            gpg.gpgme_key_unref(key);
vb@344
   484
                            break;
Edouard@505
   485
                        }
vb@344
   486
                        case GPG_ERR_CERT_REVOKED:
vb@344
   487
                        case GPG_ERR_BAD_SIGNATURE:
vb@344
   488
                            result = PEP_DECRYPT_SIGNATURE_DOES_NOT_MATCH;
vb@344
   489
                            break;
vb@344
   490
                        case GPG_ERR_SIG_EXPIRED:
vb@344
   491
                        case GPG_ERR_KEY_EXPIRED:
vb@344
   492
                        case GPG_ERR_NO_PUBKEY:
vb@344
   493
                            k = stringlist_add(k, gpgme_signature->fpr);
vb@344
   494
                            if (result == PEP_DECRYPTED_AND_VERIFIED)
vb@344
   495
                                result = PEP_DECRYPTED;
vb@344
   496
                            break;
vb@344
   497
                        case GPG_ERR_GENERAL:
vb@344
   498
                            break;
vb@344
   499
                        default:
vb@344
   500
                            if (result == PEP_DECRYPTED_AND_VERIFIED)
vb@344
   501
                                result = PEP_DECRYPTED;
vb@344
   502
                            break;
vb@344
   503
                        }
vb@344
   504
                    } while ((gpgme_signature = gpgme_signature->next));
vb@344
   505
                }
vb@344
   506
                else {
vb@344
   507
                    result = PEP_DECRYPTED;
vb@344
   508
                }
vb@344
   509
vb@344
   510
                if (result == PEP_DECRYPTED_AND_VERIFIED
vb@344
   511
                    || result == PEP_DECRYPTED) {
vb@344
   512
                    *ptext = _buffer;
vb@344
   513
                    *psize = reading;
vb@344
   514
                    (*ptext)[*psize] = 0; // safeguard for naive users
vb@344
   515
                    *keylist = _keylist;
vb@344
   516
                }
vb@344
   517
                else {
vb@344
   518
                    free_stringlist(_keylist);
vb@344
   519
                    free(_buffer);
vb@344
   520
                }
vb@344
   521
                break;
vb@344
   522
            }
vb@344
   523
            case GPG_ERR_BAD_PASSPHRASE:
vb@344
   524
                NOT_IMPLEMENTED;
vb@344
   525
            case GPG_ERR_DECRYPT_FAILED:
vb@344
   526
            default:
vb@344
   527
            {
vb@344
   528
                gpgme_decrypt_result_t gpgme_decrypt_result = gpg.gpgme_op_decrypt_result(session->ctx);
vb@344
   529
                result = PEP_DECRYPT_NO_KEY;
vb@344
   530
vb@344
   531
                if (gpgme_decrypt_result != NULL) {
vb@344
   532
                    if (gpgme_decrypt_result->unsupported_algorithm)
vb@344
   533
                        *keylist = new_stringlist(gpgme_decrypt_result->unsupported_algorithm);
vb@344
   534
                    else
vb@344
   535
                        *keylist = new_stringlist("");
vb@344
   536
                    assert(*keylist);
vb@344
   537
                    if (*keylist == NULL) {
vb@24
   538
                        result = PEP_OUT_OF_MEMORY;
vb@24
   539
                        break;
vb@24
   540
                    }
vb@344
   541
                    stringlist_t *_keylist = *keylist;
vb@344
   542
                    for (gpgme_recipient_t r = gpgme_decrypt_result->recipients; r != NULL; r = r->next) {
vb@344
   543
                        _keylist = stringlist_add(_keylist, r->keyid);
vb@344
   544
                        assert(_keylist);
vb@344
   545
                        if (_keylist == NULL) {
vb@344
   546
                            free_stringlist(*keylist);
vb@344
   547
                            *keylist = NULL;
vb@344
   548
                            result = PEP_OUT_OF_MEMORY;
vb@344
   549
                            break;
vb@344
   550
                        }
vb@344
   551
                    }
vb@344
   552
                    if (result == PEP_OUT_OF_MEMORY)
vb@344
   553
                        break;
vb@24
   554
                }
vb@24
   555
            }
vb@24
   556
        }
vb@24
   557
        break;
vb@24
   558
vb@24
   559
    default:
vb@24
   560
        result = PEP_DECRYPT_WRONG_FORMAT;
vb@24
   561
    }
vb@24
   562
vb@74
   563
    gpg.gpgme_data_release(plain);
vb@74
   564
    gpg.gpgme_data_release(cipher);
vb@24
   565
    return result;
vb@24
   566
}
vb@24
   567
vb@24
   568
PEP_STATUS pgp_verify_text(
vb@24
   569
    PEP_SESSION session, const char *text, size_t size,
vb@24
   570
    const char *signature, size_t sig_size, stringlist_t **keylist
vb@24
   571
    )
vb@24
   572
{
vb@24
   573
    PEP_STATUS result;
vb@24
   574
    gpgme_error_t gpgme_error;
vb@24
   575
    gpgme_data_t d_text, d_sig;
vb@24
   576
    stringlist_t *_keylist;
vb@24
   577
vb@24
   578
    assert(session);
vb@24
   579
    assert(text);
vb@24
   580
    assert(size);
vb@24
   581
    assert(signature);
vb@24
   582
    assert(sig_size);
vb@24
   583
    assert(keylist);
vb@24
   584
vb@24
   585
    *keylist = NULL;
vb@24
   586
vb@74
   587
    gpgme_error = gpg.gpgme_data_new_from_mem(&d_text, text, size, 0);
vb@45
   588
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   589
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   590
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@24
   591
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   592
            return PEP_OUT_OF_MEMORY;
vb@24
   593
        else
vb@24
   594
            return PEP_UNKNOWN_ERROR;
vb@24
   595
    }
vb@24
   596
vb@74
   597
    gpgme_error = gpg.gpgme_data_new_from_mem(&d_sig, signature, sig_size, 0);
vb@45
   598
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   599
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   600
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@74
   601
        gpg.gpgme_data_release(d_text);
vb@24
   602
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   603
            return PEP_OUT_OF_MEMORY;
vb@24
   604
        else
vb@24
   605
            return PEP_UNKNOWN_ERROR;
vb@24
   606
    }
vb@24
   607
vb@74
   608
    gpgme_error = gpg.gpgme_op_verify(session->ctx, d_sig, d_text, NULL);
vb@45
   609
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   610
    assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
   611
vb@24
   612
    switch (gpgme_error) {
vb@24
   613
    case GPG_ERR_NO_ERROR:
vb@24
   614
    {
vb@24
   615
        gpgme_verify_result_t gpgme_verify_result;
vb@24
   616
        gpgme_signature_t gpgme_signature;
vb@24
   617
vb@24
   618
        gpgme_verify_result =
vb@74
   619
            gpg.gpgme_op_verify_result(session->ctx);
vb@24
   620
        assert(gpgme_verify_result);
vb@24
   621
        gpgme_signature = gpgme_verify_result->signatures;
vb@24
   622
vb@24
   623
        if (gpgme_signature) {
vb@24
   624
            stringlist_t *k;
vb@24
   625
            _keylist = new_stringlist(NULL);
vb@24
   626
            assert(_keylist);
vb@24
   627
            if (_keylist == NULL) {
vb@74
   628
                gpg.gpgme_data_release(d_text);
vb@74
   629
                gpg.gpgme_data_release(d_sig);
vb@24
   630
                return PEP_OUT_OF_MEMORY;
vb@24
   631
            }
vb@24
   632
            k = _keylist;
vb@24
   633
vb@24
   634
            result = PEP_VERIFIED;
vb@24
   635
            do {
Edouard@502
   636
                gpgme_key_t key;
Edouard@502
   637
                memset(&key,0,sizeof(key));
Edouard@502
   638
Edouard@502
   639
                // GPGME may give subkey's fpr instead of primary key's fpr. 
Edouard@502
   640
                // Therefore we ask for the primary fingerprint instead
Edouard@502
   641
                // we assume that gpgme_get_key can find key by subkey's fpr
Edouard@502
   642
                gpgme_error = gpg.gpgme_get_key(session->ctx,
Edouard@502
   643
                    gpgme_signature->fpr, &key, 0);
Edouard@502
   644
                gpgme_error = _GPGERR(gpgme_error);
Edouard@502
   645
                assert(gpgme_error != GPG_ERR_ENOMEM);
Edouard@502
   646
                if (gpgme_error == GPG_ERR_ENOMEM) {
vb@24
   647
                    free_stringlist(_keylist);
Edouard@505
   648
                    gpg.gpgme_data_release(d_text);
Edouard@505
   649
                    gpg.gpgme_data_release(d_sig);
vb@24
   650
                    return PEP_OUT_OF_MEMORY;
vb@24
   651
                }
Edouard@502
   652
                // Primary key is given as the first subkey
Edouard@504
   653
                if (key->subkeys && key->subkeys->fpr && key->subkeys->fpr[0]){
Edouard@504
   654
                    k = stringlist_add(k, key->subkeys->fpr);
Edouard@502
   655
                    if (k == NULL) {
Edouard@502
   656
                        free_stringlist(_keylist);
Edouard@502
   657
                        gpg.gpgme_data_release(d_text);
Edouard@502
   658
                        gpg.gpgme_data_release(d_sig);
Edouard@502
   659
                        return PEP_OUT_OF_MEMORY;
Edouard@502
   660
                    }
Edouard@502
   661
                }
Edouard@502
   662
                else {
Edouard@502
   663
                    result = PEP_DECRYPT_SIGNATURE_DOES_NOT_MATCH;
Edouard@502
   664
                    break;
Edouard@502
   665
                }
Edouard@502
   666
Edouard@502
   667
                gpg.gpgme_key_unref(key);
Edouard@502
   668
vb@24
   669
                if (gpgme_signature->summary & GPGME_SIGSUM_RED) {
vb@24
   670
                    if (gpgme_signature->summary & GPGME_SIGSUM_KEY_EXPIRED
vb@24
   671
                        || gpgme_signature->summary & GPGME_SIGSUM_SIG_EXPIRED) {
vb@24
   672
                        if (result == PEP_VERIFIED
vb@24
   673
                            || result == PEP_VERIFIED_AND_TRUSTED)
vb@24
   674
                            result = PEP_UNENCRYPTED;
vb@24
   675
                    }
vb@24
   676
                    else {
vb@24
   677
                        result = PEP_DECRYPT_SIGNATURE_DOES_NOT_MATCH;
vb@24
   678
                        break;
vb@24
   679
                    }
vb@24
   680
                }
vb@24
   681
                else {
vb@24
   682
                    if (gpgme_signature->summary & GPGME_SIGSUM_VALID) {
vb@24
   683
                        if (result == PEP_VERIFIED)
vb@24
   684
                            result = PEP_VERIFIED_AND_TRUSTED;
vb@24
   685
                    }
vb@24
   686
                    if (gpgme_signature->summary & GPGME_SIGSUM_GREEN) {
vb@24
   687
                        // good
vb@24
   688
                    }
vb@24
   689
                    else if (gpgme_signature->summary & GPGME_SIGSUM_KEY_MISSING) {
vb@24
   690
                        result = PEP_VERIFY_NO_KEY;
vb@24
   691
                    }
vb@24
   692
                    else if (gpgme_signature->summary & GPGME_SIGSUM_SYS_ERROR) {
vb@24
   693
                        if (result == PEP_VERIFIED
vb@24
   694
                            || result == PEP_VERIFIED_AND_TRUSTED)
vb@24
   695
                            result = PEP_UNENCRYPTED;
vb@24
   696
                    }
vb@24
   697
                    else {
vb@24
   698
                        // do nothing
vb@24
   699
                    }
vb@24
   700
                }
vb@24
   701
            } while ((gpgme_signature = gpgme_signature->next));
vb@24
   702
            *keylist = _keylist;
vb@24
   703
        }
vb@24
   704
        else {
vb@24
   705
            result = PEP_UNENCRYPTED;
vb@24
   706
        }
vb@24
   707
        break;
vb@24
   708
    }
vb@24
   709
        break;
vb@24
   710
    case GPG_ERR_NO_DATA:
vb@24
   711
        result = PEP_DECRYPT_WRONG_FORMAT;
vb@24
   712
        break;
vb@24
   713
    case GPG_ERR_INV_VALUE:
vb@24
   714
    default:
vb@24
   715
        result = PEP_UNKNOWN_ERROR;
vb@24
   716
        break;
vb@24
   717
    }
vb@24
   718
vb@74
   719
    gpg.gpgme_data_release(d_text);
vb@74
   720
    gpg.gpgme_data_release(d_sig);
vb@24
   721
vb@24
   722
    return result;
vb@24
   723
}
vb@24
   724
vb@24
   725
PEP_STATUS pgp_encrypt_and_sign(
vb@24
   726
    PEP_SESSION session, const stringlist_t *keylist, const char *ptext,
vb@24
   727
    size_t psize, char **ctext, size_t *csize
vb@24
   728
    )
vb@24
   729
{
vb@24
   730
    PEP_STATUS result;
vb@24
   731
    gpgme_error_t gpgme_error;
vb@24
   732
    gpgme_data_t plain, cipher;
vb@24
   733
    gpgme_key_t *rcpt;
vb@24
   734
    gpgme_encrypt_flags_t flags;
vb@24
   735
    const stringlist_t *_keylist;
vb@24
   736
    int i, j;
vb@24
   737
vb@46
   738
    assert(session);
vb@24
   739
    assert(keylist);
vb@24
   740
    assert(ptext);
vb@24
   741
    assert(psize);
vb@24
   742
    assert(ctext);
vb@24
   743
    assert(csize);
vb@24
   744
vb@24
   745
    *ctext = NULL;
vb@24
   746
    *csize = 0;
vb@24
   747
vb@74
   748
    gpgme_error = gpg.gpgme_data_new_from_mem(&plain, ptext, psize, 0);
vb@45
   749
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   750
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   751
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@24
   752
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   753
            return PEP_OUT_OF_MEMORY;
vb@24
   754
        else
vb@24
   755
            return PEP_UNKNOWN_ERROR;
vb@24
   756
    }
vb@24
   757
vb@74
   758
    gpgme_error = gpg.gpgme_data_new(&cipher);
vb@45
   759
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   760
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   761
    if (gpgme_error != GPG_ERR_NO_ERROR) {
vb@74
   762
        gpg.gpgme_data_release(plain);
vb@24
   763
        if (gpgme_error == GPG_ERR_ENOMEM)
vb@24
   764
            return PEP_OUT_OF_MEMORY;
vb@24
   765
        else
vb@24
   766
            return PEP_UNKNOWN_ERROR;
vb@24
   767
    }
vb@24
   768
vb@109
   769
    rcpt = calloc(stringlist_length(keylist) + 1, sizeof(gpgme_key_t));
vb@24
   770
    assert(rcpt);
vb@24
   771
    if (rcpt == NULL) {
vb@74
   772
        gpg.gpgme_data_release(plain);
vb@74
   773
        gpg.gpgme_data_release(cipher);
vb@24
   774
        return PEP_OUT_OF_MEMORY;
vb@24
   775
    }
vb@24
   776
vb@74
   777
    gpg.gpgme_signers_clear(session->ctx);
vb@24
   778
vb@24
   779
    for (_keylist = keylist, i = 0; _keylist != NULL; _keylist = _keylist->next, i++) {
vb@24
   780
        assert(_keylist->value);
vb@74
   781
        gpgme_error = gpg.gpgme_get_key(session->ctx, _keylist->value,
vb@24
   782
            &rcpt[i], 0);
vb@45
   783
        gpgme_error = _GPGERR(gpgme_error);
vb@24
   784
        assert(gpgme_error != GPG_ERR_ENOMEM);
vb@24
   785
vb@24
   786
        switch (gpgme_error) {
vb@24
   787
        case GPG_ERR_ENOMEM:
vb@24
   788
            for (j = 0; j<i; j++)
vb@74
   789
                gpg.gpgme_key_unref(rcpt[j]);
vb@24
   790
            free(rcpt);
vb@74
   791
            gpg.gpgme_data_release(plain);
vb@74
   792
            gpg.gpgme_data_release(cipher);
vb@24
   793
            return PEP_OUT_OF_MEMORY;
vb@24
   794
        case GPG_ERR_NO_ERROR:
vb@24
   795
            if (i == 0) {
vb@74
   796
                gpgme_error_t _gpgme_error = gpg.gpgme_signers_add(session->ctx, rcpt[0]);
vb@45
   797
                _gpgme_error = _GPGERR(_gpgme_error);
vb@24
   798
                assert(_gpgme_error == GPG_ERR_NO_ERROR);
vb@24
   799
            }
vb@24
   800
            break;
vb@24
   801
        case GPG_ERR_EOF:
vb@24
   802
            for (j = 0; j<i; j++)
vb@74
   803
                gpg.gpgme_key_unref(rcpt[j]);
vb@24
   804
            free(rcpt);
vb@74
   805
            gpg.gpgme_data_release(plain);
vb@74
   806
            gpg.gpgme_data_release(cipher);
vb@24
   807
            return PEP_KEY_NOT_FOUND;
vb@24
   808
        case GPG_ERR_AMBIGUOUS_NAME:
vb@24
   809
            for (j = 0; j<i; j++)
vb@74
   810
                gpg.gpgme_key_unref(rcpt[j]);
vb@24
   811
            free(rcpt);
vb@74
   812
            gpg.gpgme_data_release(plain);
vb@74
   813
            gpg.gpgme_data_release(cipher);
vb@24
   814
            return PEP_KEY_HAS_AMBIG_NAME;
vb@24
   815
        default: // GPG_ERR_INV_VALUE if CTX or R_KEY is not a valid pointer or
vb@24
   816
            // FPR is not a fingerprint or key ID
vb@24
   817
            for (j = 0; j<i; j++)
vb@74
   818
                gpg.gpgme_key_unref(rcpt[j]);
vb@24
   819
            free(rcpt);
vb@74
   820
            gpg.gpgme_data_release(plain);
vb@74
   821
            gpg.gpgme_data_release(cipher);
vb@24
   822
            return PEP_GET_KEY_FAILED;
vb@24
   823
        }
vb@24
   824
    }
vb@24
   825
vb@24
   826
    // TODO: remove that and replace with proper key management
vb@24
   827
    flags = GPGME_ENCRYPT_ALWAYS_TRUST;
vb@24
   828
vb@74
   829
    gpgme_error = gpg.gpgme_op_encrypt_sign(session->ctx, rcpt, flags,
vb@24
   830
        plain, cipher);
vb@45
   831
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   832
    switch (gpgme_error) {
vb@24
   833
    case GPG_ERR_NO_ERROR:
vb@24
   834
    {
vb@24
   835
        char *_buffer = NULL;
vb@24
   836
        size_t reading;
vb@74
   837
        size_t length = gpg.gpgme_data_seek(cipher, 0, SEEK_END);
vb@24
   838
        assert(length != -1);
vb@74
   839
        gpg.gpgme_data_seek(cipher, 0, SEEK_SET);
vb@24
   840
vb@24
   841
        // TODO: make things less memory consuming
vb@24
   842
        // the following algorithm allocates a buffer for the complete text
vb@24
   843
vb@112
   844
        _buffer = malloc(length + 1);
vb@24
   845
        assert(_buffer);
vb@24
   846
        if (_buffer == NULL) {
vb@24
   847
            for (j = 0; j<stringlist_length(keylist); j++)
vb@74
   848
                gpg.gpgme_key_unref(rcpt[j]);
vb@24
   849
            free(rcpt);
vb@74
   850
            gpg.gpgme_data_release(plain);
vb@74
   851
            gpg.gpgme_data_release(cipher);
vb@24
   852
            return PEP_OUT_OF_MEMORY;
vb@24
   853
        }
vb@24
   854
vb@74
   855
        reading = gpg.gpgme_data_read(cipher, _buffer, length);
vb@24
   856
        assert(length == reading);
vb@24
   857
vb@24
   858
        *ctext = _buffer;
vb@24
   859
        *csize = reading;
vb@24
   860
        (*ctext)[*csize] = 0; // safeguard for naive users
vb@24
   861
        result = PEP_STATUS_OK;
vb@24
   862
        break;
vb@24
   863
    }
vb@24
   864
    default:
vb@24
   865
        result = PEP_UNKNOWN_ERROR;
vb@24
   866
    }
vb@24
   867
vb@24
   868
    for (j = 0; j<stringlist_length(keylist); j++)
vb@74
   869
        gpg.gpgme_key_unref(rcpt[j]);
vb@24
   870
    free(rcpt);
vb@74
   871
    gpg.gpgme_data_release(plain);
vb@74
   872
    gpg.gpgme_data_release(cipher);
vb@24
   873
    return result;
vb@24
   874
}
vb@24
   875
vb@24
   876
PEP_STATUS pgp_generate_keypair(
vb@24
   877
    PEP_SESSION session, pEp_identity *identity
vb@24
   878
    )
vb@24
   879
{
vb@24
   880
    gpgme_error_t gpgme_error;
vb@24
   881
    char *parms;
vb@24
   882
    const char *template =
vb@24
   883
        "<GnupgKeyParms format=\"internal\">\n"
vb@24
   884
        "Key-Type: RSA\n"
vb@24
   885
        "Key-Length: 4096\n"
vb@429
   886
        "Subkey-Type: RSA\n"
vb@429
   887
        "Subkey-Length: 4096\n"
vb@24
   888
        "Name-Real: %s\n"
vb@24
   889
        "Name-Email: %s\n"
vb@24
   890
        /* "Passphrase: %s\n" */
vb@24
   891
        "Expire-Date: 1y\n"
vb@24
   892
        "</GnupgKeyParms>\n";
vb@24
   893
    int result;
vb@24
   894
    gpgme_genkey_result_t gpgme_genkey_result;
vb@24
   895
vb@24
   896
    assert(session);
vb@24
   897
    assert(identity);
vb@24
   898
    assert(identity->address);
vb@298
   899
    assert(identity->fpr == NULL || identity->fpr[0] == 0);
vb@24
   900
    assert(identity->username);
vb@24
   901
vb@24
   902
    parms = calloc(1, PARMS_MAX);
vb@24
   903
    assert(parms);
vb@24
   904
    if (parms == NULL)
vb@24
   905
        return PEP_OUT_OF_MEMORY;
vb@24
   906
vb@24
   907
    result = snprintf(parms, PARMS_MAX, template, identity->username,
vb@46
   908
        identity->address); // , session->passphrase);
vb@24
   909
    assert(result < PARMS_MAX);
vb@24
   910
    if (result >= PARMS_MAX) {
vb@24
   911
        free(parms);
vb@24
   912
        return PEP_BUFFER_TOO_SMALL;
vb@24
   913
    }
vb@24
   914
vb@74
   915
    gpgme_error = gpg.gpgme_op_genkey(session->ctx, parms, NULL, NULL);
vb@45
   916
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   917
    free(parms);
vb@24
   918
vb@24
   919
    switch (gpgme_error) {
vb@24
   920
    case GPG_ERR_NO_ERROR:
vb@24
   921
        break;
vb@24
   922
    case GPG_ERR_INV_VALUE:
vb@24
   923
        return PEP_ILLEGAL_VALUE;
vb@24
   924
    case GPG_ERR_GENERAL:
vb@24
   925
        return PEP_CANNOT_CREATE_KEY;
vb@24
   926
    default:
vb@24
   927
        assert(0);
vb@24
   928
        return PEP_UNKNOWN_ERROR;
vb@24
   929
    }
vb@24
   930
vb@74
   931
    gpgme_genkey_result = gpg.gpgme_op_genkey_result(session->ctx);
vb@24
   932
    assert(gpgme_genkey_result);
vb@24
   933
    assert(gpgme_genkey_result->fpr);
vb@24
   934
vb@298
   935
    free(identity->fpr);
vb@24
   936
    identity->fpr = strdup(gpgme_genkey_result->fpr);
vb@298
   937
    if (identity->fpr == NULL)
vb@298
   938
        return PEP_OUT_OF_MEMORY;
vb@24
   939
vb@24
   940
    return PEP_STATUS_OK;
vb@24
   941
}
vb@24
   942
vb@24
   943
PEP_STATUS pgp_delete_keypair(PEP_SESSION session, const char *fpr)
vb@24
   944
{
vb@24
   945
    gpgme_error_t gpgme_error;
vb@24
   946
    gpgme_key_t key;
vb@24
   947
vb@24
   948
    assert(session);
vb@24
   949
    assert(fpr);
vb@24
   950
vb@74
   951
    gpgme_error = gpg.gpgme_get_key(session->ctx, fpr, &key, 0);
vb@45
   952
    gpgme_error = _GPGERR(gpgme_error);
vb@24
   953
    assert(gpgme_error != GPG_ERR_ENOMEM);
vb@24
   954
    switch (gpgme_error) {
vb@24
   955
    case GPG_ERR_NO_ERROR:
vb@24
   956
        break;
vb@24
   957
    case GPG_ERR_EOF:
vb@24
   958
        return PEP_KEY_NOT_FOUND;
vb@24
   959
    case GPG_ERR_INV_VALUE:
vb@24
   960
        return PEP_ILLEGAL_VALUE;
vb@24
   961
    case GPG_ERR_AMBIGUOUS_NAME:
vb@24
   962
        return PEP_KEY_HAS_AMBIG_NAME;
vb@24
   963
    case GPG_ERR_ENOMEM:
vb@24
   964
        return PEP_OUT_OF_MEMORY;
vb@24
   965
    default:
vb@24
   966
        assert(0);
vb@24
   967
        return PEP_UNKNOWN_ERROR;
vb@24
   968
    }
vb@24
   969
vb@74
   970
    gpgme_error = gpg.gpgme_op_delete(session->ctx, key, 1);
vb@45
   971
    gpgme_error = _GPGERR(gpgme_error);
vb@74
   972
    gpg.gpgme_key_unref(key);
vb@24
   973
    switch (gpgme_error) {
vb@24
   974
    case GPG_ERR_NO_ERROR:
vb@24
   975
        break;
vb@24
   976
    case GPG_ERR_INV_VALUE:
vb@24
   977
        assert(0);
vb@24
   978
        return PEP_UNKNOWN_ERROR;
vb@24
   979
    case GPG_ERR_NO_PUBKEY:
vb@24
   980
        assert(0);
vb@24
   981
        return PEP_KEY_NOT_FOUND;
vb@24
   982
    case GPG_ERR_AMBIGUOUS_NAME:
vb@24
   983
        assert(0);
vb@24
   984
        return PEP_KEY_HAS_AMBIG_NAME;
vb@24
   985
    default:
vb@24
   986
        assert(0);
vb@24
   987
        return PEP_UNKNOWN_ERROR;
vb@24
   988
    }
vb@24
   989
vb@24
   990
    return PEP_STATUS_OK;
vb@24
   991
}
vb@24
   992
Edouard@170
   993
PEP_STATUS pgp_import_keydata(PEP_SESSION session, const char *key_data, size_t size)
vb@24
   994
{
vb@24
   995
    gpgme_error_t gpgme_error;
vb@24
   996
    gpgme_data_t dh;
vb@24
   997
vb@24
   998
    assert(session);
vb@24
   999
    assert(key_data);
vb@24
  1000
vb@74
  1001
    gpgme_error = gpg.gpgme_data_new_from_mem(&dh, key_data, size, 0);
vb@45
  1002
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1003
    assert(gpgme_error != GPG_ERR_ENOMEM);
vb@24
  1004
    switch (gpgme_error) {
vb@24
  1005
    case GPG_ERR_NO_ERROR:
vb@24
  1006
        break;
vb@24
  1007
    case GPG_ERR_ENOMEM:
vb@24
  1008
        return PEP_OUT_OF_MEMORY;
vb@24
  1009
    case GPG_ERR_INV_VALUE:
vb@24
  1010
        assert(0);
vb@24
  1011
        return PEP_UNKNOWN_ERROR;
vb@24
  1012
    default:
vb@24
  1013
        assert(0);
vb@24
  1014
        return PEP_UNKNOWN_ERROR;
vb@24
  1015
    }
vb@24
  1016
vb@74
  1017
    gpgme_error = gpg.gpgme_op_import(session->ctx, dh);
vb@45
  1018
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1019
    switch (gpgme_error) {
vb@24
  1020
    case GPG_ERR_NO_ERROR:
vb@24
  1021
        break;
vb@24
  1022
    case GPG_ERR_INV_VALUE:
vb@24
  1023
        assert(0);
vb@74
  1024
        gpg.gpgme_data_release(dh);
vb@24
  1025
        return PEP_UNKNOWN_ERROR;
vb@24
  1026
    case GPG_ERR_NO_DATA:
vb@74
  1027
        gpg.gpgme_data_release(dh);
vb@24
  1028
        return PEP_ILLEGAL_VALUE;
vb@24
  1029
    default:
vb@24
  1030
        assert(0);
vb@74
  1031
        gpg.gpgme_data_release(dh);
vb@24
  1032
        return PEP_UNKNOWN_ERROR;
vb@24
  1033
    }
vb@24
  1034
vb@74
  1035
    gpg.gpgme_data_release(dh);
vb@24
  1036
    return PEP_STATUS_OK;
vb@24
  1037
}
vb@24
  1038
Edouard@170
  1039
PEP_STATUS pgp_export_keydata(
vb@24
  1040
    PEP_SESSION session, const char *fpr, char **key_data, size_t *size
vb@24
  1041
    )
vb@24
  1042
{
vb@24
  1043
    gpgme_error_t gpgme_error;
vb@24
  1044
    gpgme_data_t dh;
vb@24
  1045
    size_t _size;
vb@24
  1046
    char *buffer;
vb@24
  1047
    int reading;
vb@24
  1048
vb@24
  1049
    assert(session);
vb@24
  1050
    assert(fpr);
vb@24
  1051
    assert(key_data);
vb@24
  1052
    assert(size);
vb@24
  1053
vb@74
  1054
    gpgme_error = gpg.gpgme_data_new(&dh);
vb@45
  1055
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1056
    assert(gpgme_error != GPG_ERR_ENOMEM);
vb@24
  1057
    switch (gpgme_error) {
vb@24
  1058
    case GPG_ERR_NO_ERROR:
vb@24
  1059
        break;
vb@24
  1060
    case GPG_ERR_ENOMEM:
vb@24
  1061
        return PEP_OUT_OF_MEMORY;
vb@24
  1062
    case GPG_ERR_INV_VALUE:
vb@24
  1063
        assert(0);
vb@24
  1064
        return PEP_UNKNOWN_ERROR;
vb@24
  1065
    default:
vb@24
  1066
        assert(0);
vb@24
  1067
        return PEP_UNKNOWN_ERROR;
vb@24
  1068
    }
vb@24
  1069
vb@74
  1070
    gpgme_error = gpg.gpgme_op_export(session->ctx, fpr,
vb@24
  1071
        GPGME_EXPORT_MODE_MINIMAL, dh);
vb@45
  1072
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1073
    switch (gpgme_error) {
vb@24
  1074
    case GPG_ERR_NO_ERROR:
vb@24
  1075
        break;
vb@24
  1076
    case GPG_ERR_EOF:
vb@74
  1077
        gpg.gpgme_data_release(dh);
vb@24
  1078
        return PEP_KEY_NOT_FOUND;
vb@24
  1079
    case GPG_ERR_INV_VALUE:
vb@24
  1080
        assert(0);
vb@74
  1081
        gpg.gpgme_data_release(dh);
vb@24
  1082
        return PEP_UNKNOWN_ERROR;
vb@24
  1083
    default:
vb@24
  1084
        assert(0);
vb@74
  1085
        gpg.gpgme_data_release(dh);
vb@24
  1086
        return PEP_UNKNOWN_ERROR;
vb@24
  1087
    };
vb@24
  1088
vb@74
  1089
    _size = gpg.gpgme_data_seek(dh, 0, SEEK_END);
vb@24
  1090
    assert(_size != -1);
vb@74
  1091
    gpg.gpgme_data_seek(dh, 0, SEEK_SET);
vb@24
  1092
vb@24
  1093
    buffer = malloc(_size + 1);
vb@24
  1094
    assert(buffer);
vb@24
  1095
    if (buffer == NULL) {
vb@74
  1096
        gpg.gpgme_data_release(dh);
vb@24
  1097
        return PEP_OUT_OF_MEMORY;
vb@24
  1098
    }
vb@24
  1099
vb@74
  1100
    reading = gpg.gpgme_data_read(dh, buffer, _size);
vb@24
  1101
    assert(_size == reading);
vb@24
  1102
vb@24
  1103
    // safeguard for the naive user
vb@24
  1104
    buffer[_size] = 0;
vb@24
  1105
vb@24
  1106
    *key_data = buffer;
vb@24
  1107
    *size = _size;
vb@24
  1108
vb@74
  1109
    gpg.gpgme_data_release(dh);
vb@24
  1110
    return PEP_STATUS_OK;
vb@24
  1111
}
vb@24
  1112
vb@46
  1113
static void _switch_mode(pEpSession *session, gpgme_keylist_mode_t remove_mode,
vb@24
  1114
    gpgme_keylist_mode_t add_mode)
vb@24
  1115
{
vb@24
  1116
    gpgme_error_t gpgme_error;
vb@24
  1117
    gpgme_keylist_mode_t mode;
vb@24
  1118
vb@74
  1119
    mode = gpg.gpgme_get_keylist_mode(session->ctx);
vb@24
  1120
vb@24
  1121
    mode &= ~remove_mode;
vb@24
  1122
    mode |= add_mode;
vb@24
  1123
vb@74
  1124
    gpgme_error = gpg.gpgme_set_keylist_mode(session->ctx, mode);
vb@45
  1125
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1126
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@24
  1127
}
vb@24
  1128
vb@24
  1129
PEP_STATUS pgp_recv_key(PEP_SESSION session, const char *pattern)
vb@24
  1130
{
vb@24
  1131
    gpgme_error_t gpgme_error;
vb@24
  1132
    gpgme_key_t key;
vb@24
  1133
vb@24
  1134
    assert(session);
vb@24
  1135
    assert(pattern);
vb@24
  1136
vb@46
  1137
    _switch_mode(session, GPGME_KEYLIST_MODE_LOCAL, GPGME_KEYLIST_MODE_EXTERN);
vb@24
  1138
vb@74
  1139
    gpgme_error = gpg.gpgme_op_keylist_start(session->ctx, pattern, 0);
vb@45
  1140
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1141
    switch (gpgme_error) {
vb@24
  1142
    case GPG_ERR_NO_ERROR:
vb@24
  1143
        break;
vb@24
  1144
    case GPG_ERR_INV_VALUE:
vb@24
  1145
        assert(0);
vb@47
  1146
        _switch_mode(session, GPGME_KEYLIST_MODE_EXTERN, GPGME_KEYLIST_MODE_LOCAL);
vb@24
  1147
        return PEP_UNKNOWN_ERROR;
vb@24
  1148
    default:
vb@47
  1149
        _switch_mode(session, GPGME_KEYLIST_MODE_EXTERN, GPGME_KEYLIST_MODE_LOCAL);
vb@24
  1150
        return PEP_GET_KEY_FAILED;
vb@24
  1151
    };
vb@24
  1152
vb@47
  1153
    gpgme_ctx_t import_ctx;
vb@74
  1154
    gpgme_error = gpg.gpgme_new(&import_ctx);
vb@47
  1155
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@47
  1156
vb@24
  1157
    do {
vb@74
  1158
        gpgme_error = gpg.gpgme_op_keylist_next(session->ctx, &key);
vb@45
  1159
        gpgme_error = _GPGERR(gpgme_error);
vb@24
  1160
        assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
  1161
        switch (gpgme_error) {
vb@24
  1162
        case GPG_ERR_EOF:
vb@24
  1163
            break;
vb@24
  1164
        case GPG_ERR_NO_ERROR:
vb@24
  1165
        {
vb@24
  1166
            gpgme_error_t gpgme_error;
vb@24
  1167
            gpgme_key_t keys[2];
vb@24
  1168
vb@24
  1169
            keys[0] = key;
vb@24
  1170
            keys[1] = NULL;
vb@24
  1171
vb@74
  1172
            gpgme_error = gpg.gpgme_op_import_keys(import_ctx, keys);
vb@45
  1173
            gpgme_error = _GPGERR(gpgme_error);
vb@74
  1174
            gpg.gpgme_key_unref(key);
vb@24
  1175
            assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
  1176
            assert(gpgme_error != GPG_ERR_CONFLICT);
vb@24
  1177
        }
vb@24
  1178
            break;
vb@24
  1179
        case GPG_ERR_ENOMEM:
vb@74
  1180
            gpg.gpgme_op_keylist_end(session->ctx);
vb@74
  1181
            gpg.gpgme_release(import_ctx);
vb@47
  1182
            _switch_mode(session, GPGME_KEYLIST_MODE_EXTERN, GPGME_KEYLIST_MODE_LOCAL);
vb@24
  1183
            return PEP_OUT_OF_MEMORY;
vb@24
  1184
        default:
vb@74
  1185
            gpg.gpgme_op_keylist_end(session->ctx);
vb@74
  1186
            gpg.gpgme_release(import_ctx);
vb@47
  1187
            _switch_mode(session, GPGME_KEYLIST_MODE_EXTERN, GPGME_KEYLIST_MODE_LOCAL);
vb@46
  1188
            return PEP_UNKNOWN_ERROR;
vb@24
  1189
        };
vb@24
  1190
    } while (gpgme_error != GPG_ERR_EOF);
vb@24
  1191
vb@74
  1192
    gpg.gpgme_op_keylist_end(session->ctx);
vb@74
  1193
    gpg.gpgme_release(import_ctx);
vb@47
  1194
    _switch_mode(session, GPGME_KEYLIST_MODE_EXTERN, GPGME_KEYLIST_MODE_LOCAL);
vb@24
  1195
    return PEP_STATUS_OK;
vb@24
  1196
}
vb@24
  1197
vb@24
  1198
PEP_STATUS pgp_find_keys(
vb@24
  1199
    PEP_SESSION session, const char *pattern, stringlist_t **keylist
vb@24
  1200
    )
vb@24
  1201
{
vb@24
  1202
    gpgme_error_t gpgme_error;
vb@24
  1203
    gpgme_key_t key;
vb@24
  1204
    stringlist_t *_keylist;
vb@24
  1205
    char *fpr;
vb@24
  1206
vb@24
  1207
    assert(session);
vb@24
  1208
    assert(pattern);
vb@24
  1209
    assert(keylist);
vb@24
  1210
vb@24
  1211
    *keylist = NULL;
vb@24
  1212
vb@74
  1213
    gpgme_error = gpg.gpgme_op_keylist_start(session->ctx, pattern, 0);
vb@45
  1214
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1215
    switch (gpgme_error) {
vb@24
  1216
    case GPG_ERR_NO_ERROR:
vb@24
  1217
        break;
vb@24
  1218
    case GPG_ERR_INV_VALUE:
vb@24
  1219
        assert(0);
vb@24
  1220
        return PEP_UNKNOWN_ERROR;
vb@24
  1221
    default:
vb@74
  1222
        gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1223
        return PEP_GET_KEY_FAILED;
vb@24
  1224
    };
vb@24
  1225
vb@24
  1226
    _keylist = new_stringlist(NULL);
vb@24
  1227
    stringlist_t *_k = _keylist;
vb@24
  1228
vb@24
  1229
    do {
vb@74
  1230
        gpgme_error = gpg.gpgme_op_keylist_next(session->ctx, &key);
vb@45
  1231
        gpgme_error = _GPGERR(gpgme_error);
vb@24
  1232
        assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
  1233
        switch (gpgme_error) {
vb@24
  1234
        case GPG_ERR_EOF:
vb@24
  1235
            break;
vb@24
  1236
        case GPG_ERR_NO_ERROR:
vb@24
  1237
            assert(key);
vb@24
  1238
            assert(key->subkeys);
vb@24
  1239
            fpr = key->subkeys->fpr;
vb@24
  1240
            assert(fpr);
vb@24
  1241
            _k = stringlist_add(_k, fpr);
vb@24
  1242
            assert(_k);
vb@24
  1243
            if (_k != NULL)
vb@24
  1244
                break;
vb@24
  1245
        case GPG_ERR_ENOMEM:
vb@24
  1246
            free_stringlist(_keylist);
vb@74
  1247
            gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1248
            return PEP_OUT_OF_MEMORY;
vb@24
  1249
        default:
vb@74
  1250
            gpg.gpgme_op_keylist_end(session->ctx);
vb@46
  1251
            return PEP_UNKNOWN_ERROR;
vb@24
  1252
        };
vb@24
  1253
    } while (gpgme_error != GPG_ERR_EOF);
vb@24
  1254
vb@74
  1255
    gpg.gpgme_op_keylist_end(session->ctx);
vb@523
  1256
    if (_keylist->value == NULL) {
vb@523
  1257
        free_stringlist(_keylist);
vb@523
  1258
        _keylist = NULL;
vb@523
  1259
    }
vb@24
  1260
    *keylist = _keylist;
vb@24
  1261
    return PEP_STATUS_OK;
vb@24
  1262
}
vb@24
  1263
vb@24
  1264
PEP_STATUS pgp_send_key(PEP_SESSION session, const char *pattern)
vb@24
  1265
{
vb@24
  1266
    gpgme_error_t gpgme_error;
vb@24
  1267
vb@24
  1268
    assert(session);
vb@24
  1269
    assert(pattern);
vb@24
  1270
vb@74
  1271
    gpgme_error = gpg.gpgme_op_export(session->ctx, pattern,
vb@24
  1272
        GPGME_EXPORT_MODE_EXTERN, NULL);
vb@45
  1273
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1274
    assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
  1275
    if (gpgme_error == GPG_ERR_NO_ERROR)
vb@24
  1276
        return PEP_STATUS_OK;
vb@24
  1277
    else
vb@24
  1278
        return PEP_CANNOT_SEND_KEY;
vb@24
  1279
}
vb@24
  1280
vb@24
  1281
PEP_STATUS pgp_get_key_rating(
vb@24
  1282
    PEP_SESSION session,
vb@24
  1283
    const char *fpr,
vb@24
  1284
    PEP_comm_type *comm_type
vb@24
  1285
    )
vb@24
  1286
{
vb@24
  1287
    PEP_STATUS status = PEP_STATUS_OK;
vb@24
  1288
    gpgme_error_t gpgme_error;
vb@24
  1289
    gpgme_key_t key;
vb@24
  1290
vb@24
  1291
    assert(session);
vb@24
  1292
    assert(fpr);
vb@24
  1293
    assert(comm_type);
vb@24
  1294
vb@24
  1295
    *comm_type = PEP_ct_unknown;
vb@24
  1296
vb@74
  1297
    gpgme_error = gpg.gpgme_op_keylist_start(session->ctx, fpr, 0);
vb@45
  1298
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1299
    switch (gpgme_error) {
vb@24
  1300
    case GPG_ERR_NO_ERROR:
vb@24
  1301
        break;
vb@24
  1302
    case GPG_ERR_INV_VALUE:
vb@24
  1303
        assert(0);
vb@24
  1304
        return PEP_UNKNOWN_ERROR;
vb@24
  1305
    default:
vb@24
  1306
        return PEP_GET_KEY_FAILED;
vb@24
  1307
    };
vb@24
  1308
vb@74
  1309
    gpgme_error = gpg.gpgme_op_keylist_next(session->ctx, &key);
vb@45
  1310
    gpgme_error = _GPGERR(gpgme_error);
vb@24
  1311
    assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@24
  1312
vb@24
  1313
    if (key == NULL) {
vb@74
  1314
        gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1315
        return PEP_KEY_NOT_FOUND;
vb@24
  1316
    }
vb@24
  1317
vb@24
  1318
    switch (key->protocol) {
vb@24
  1319
    case GPGME_PROTOCOL_OpenPGP:
vb@24
  1320
    case GPGME_PROTOCOL_DEFAULT:
vb@24
  1321
        *comm_type = PEP_ct_OpenPGP_unconfirmed;
vb@24
  1322
        break;
vb@24
  1323
    case GPGME_PROTOCOL_CMS:
vb@24
  1324
        *comm_type = PEP_ct_CMS_unconfirmed;
vb@24
  1325
        break;
vb@24
  1326
    default:
vb@24
  1327
        *comm_type = PEP_ct_unknown;
vb@74
  1328
        gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1329
        return PEP_STATUS_OK;
vb@24
  1330
    }
vb@24
  1331
vb@24
  1332
    switch (gpgme_error) {
vb@24
  1333
    case GPG_ERR_EOF:
vb@24
  1334
        break;
vb@24
  1335
    case GPG_ERR_NO_ERROR:
vb@24
  1336
        assert(key);
vb@24
  1337
        assert(key->subkeys);
vb@24
  1338
        for (gpgme_subkey_t sk = key->subkeys; sk != NULL; sk = sk->next) {
vb@24
  1339
            if (sk->length < 1024)
vb@24
  1340
                *comm_type = PEP_ct_key_too_short;
vb@24
  1341
            else if (
vb@24
  1342
                (
vb@24
  1343
                (sk->pubkey_algo == GPGME_PK_RSA)
vb@24
  1344
                || (sk->pubkey_algo == GPGME_PK_RSA_E)
vb@24
  1345
                || (sk->pubkey_algo == GPGME_PK_RSA_S)
vb@24
  1346
                )
vb@24
  1347
                && sk->length == 1024
vb@24
  1348
                )
vb@122
  1349
                *comm_type = PEP_ct_OpenPGP_weak_unconfirmed;
vb@24
  1350
vb@24
  1351
            if (sk->invalid) {
vb@24
  1352
                *comm_type = PEP_ct_key_b0rken;
vb@24
  1353
                break;
vb@24
  1354
            }
vb@24
  1355
            if (sk->expired) {
vb@24
  1356
                *comm_type = PEP_ct_key_expired;
vb@24
  1357
                break;
vb@24
  1358
            }
vb@24
  1359
            if (sk->revoked) {
vb@24
  1360
                *comm_type = PEP_ct_key_revoked;
vb@24
  1361
                break;
vb@24
  1362
            }
vb@24
  1363
        }
vb@24
  1364
        break;
vb@24
  1365
    case GPG_ERR_ENOMEM:
vb@74
  1366
        gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1367
        *comm_type = PEP_ct_unknown;
vb@24
  1368
        return PEP_OUT_OF_MEMORY;
vb@24
  1369
    default:
vb@74
  1370
        gpg.gpgme_op_keylist_end(session->ctx);
vb@46
  1371
        return PEP_UNKNOWN_ERROR;
vb@24
  1372
    };
vb@24
  1373
vb@74
  1374
    gpg.gpgme_op_keylist_end(session->ctx);
vb@24
  1375
vb@24
  1376
    return status;
vb@24
  1377
}
vb@200
  1378
vb@200
  1379
static PEP_STATUS find_single_key(
vb@200
  1380
        PEP_SESSION session,
vb@200
  1381
        const char *fpr,
vb@200
  1382
        gpgme_key_t *key
vb@200
  1383
    )
vb@200
  1384
{
vb@200
  1385
    gpgme_error_t gpgme_error;
vb@200
  1386
vb@200
  1387
    *key = NULL;
vb@200
  1388
vb@200
  1389
    gpgme_error = gpg.gpgme_op_keylist_start(session->ctx, fpr, 0);
vb@200
  1390
    gpgme_error = _GPGERR(gpgme_error);
vb@200
  1391
    switch (gpgme_error) {
vb@200
  1392
    case GPG_ERR_NO_ERROR:
vb@200
  1393
        break;
vb@200
  1394
    case GPG_ERR_INV_VALUE:
vb@200
  1395
        assert(0);
vb@200
  1396
        return PEP_UNKNOWN_ERROR;
vb@200
  1397
    default:
vb@200
  1398
        return PEP_GET_KEY_FAILED;
vb@200
  1399
    };
vb@200
  1400
vb@200
  1401
    gpgme_error = gpg.gpgme_op_keylist_next(session->ctx, key);
vb@200
  1402
    gpgme_error = _GPGERR(gpgme_error);
vb@200
  1403
    assert(gpgme_error != GPG_ERR_INV_VALUE);
vb@200
  1404
vb@200
  1405
    gpg.gpgme_op_keylist_end(session->ctx);
vb@200
  1406
vb@200
  1407
    return PEP_STATUS_OK;
vb@200
  1408
}
vb@200
  1409
vb@201
  1410
typedef struct _renew_state {
vb@211
  1411
    enum {
vb@200
  1412
        renew_command = 0,
vb@200
  1413
        renew_date,
vb@200
  1414
        renew_secret_key,
vb@200
  1415
        renew_command2,
vb@200
  1416
        renew_date2,
vb@200
  1417
        renew_quit,
vb@200
  1418
        renew_save,
vb@200
  1419
        renew_exit,
vb@200
  1420
        renew_error = -1
vb@200
  1421
    } state;
vb@201
  1422
    const char *date_ref;
vb@201
  1423
} renew_state;
vb@200
  1424
vb@201
  1425
static gpgme_error_t renew_fsm(
vb@200
  1426
        void *_handle,
vb@200
  1427
        gpgme_status_code_t statuscode,
vb@200
  1428
        const char *args,
vb@200
  1429
        int fd
vb@200
  1430
    )
vb@200
  1431
{
vb@201
  1432
    renew_state *handle = _handle;
vb@200
  1433
vb@200
  1434
    switch (handle->state) {
vb@200
  1435
        case renew_command:
vb@200
  1436
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1437
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@201
  1438
                if (strcmp(args, "keyedit.prompt")) {
vb@201
  1439
                    handle->state = renew_error;
vb@201
  1440
                    return GPG_ERR_GENERAL;
vb@201
  1441
                }
vb@223
  1442
                gpg.gpgme_io_write(fd, "expire\n", 7);
vb@200
  1443
                handle->state = renew_date;
vb@200
  1444
            }
vb@200
  1445
            break;
vb@200
  1446
vb@200
  1447
        case renew_date:
vb@200
  1448
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1449
                assert(strcmp(args, "keygen.valid") == 0);
vb@201
  1450
                if (strcmp(args, "keygen.valid")) {
vb@201
  1451
                    handle->state = renew_error;
vb@201
  1452
                    return GPG_ERR_GENERAL;
vb@201
  1453
                }
vb@223
  1454
                gpg.gpgme_io_write(fd, handle->date_ref, 11);
vb@200
  1455
                handle->state = renew_secret_key;
vb@200
  1456
            }
vb@200
  1457
            break;
vb@200
  1458
vb@200
  1459
        case renew_secret_key:
vb@200
  1460
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1461
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@201
  1462
                if (strcmp(args, "keyedit.prompt")) {
vb@201
  1463
                    handle->state = renew_error;
vb@201
  1464
                    return GPG_ERR_GENERAL;
vb@201
  1465
                }
vb@223
  1466
                gpg.gpgme_io_write(fd, "key 1\n", 6);
vb@200
  1467
                handle->state = renew_command2;
vb@200
  1468
            }
vb@200
  1469
            break;
vb@200
  1470
vb@200
  1471
        case renew_command2:
vb@200
  1472
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1473
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@201
  1474
                if (strcmp(args, "keyedit.prompt")) {
vb@201
  1475
                    handle->state = renew_error;
vb@201
  1476
                    return GPG_ERR_GENERAL;
vb@201
  1477
                }
vb@223
  1478
                gpg.gpgme_io_write(fd, "expire\n", 7);
vb@200
  1479
                handle->state = renew_date2;
vb@200
  1480
            }
vb@200
  1481
            break;
vb@200
  1482
vb@200
  1483
        case renew_date2:
vb@200
  1484
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1485
                assert(strcmp(args, "keygen.valid") == 0);
vb@201
  1486
                if (strcmp(args, "keygen.valid")) {
vb@201
  1487
                    handle->state = renew_error;
vb@201
  1488
                    return GPG_ERR_GENERAL;
vb@201
  1489
                }
vb@223
  1490
                gpg.gpgme_io_write(fd, handle->date_ref, 11);
vb@200
  1491
                handle->state = renew_quit;
vb@200
  1492
            }
vb@200
  1493
            break;
vb@200
  1494
vb@200
  1495
        case renew_quit:
vb@200
  1496
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@201
  1497
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@201
  1498
                if (strcmp(args, "keyedit.prompt")) {
vb@201
  1499
                    handle->state = renew_error;
vb@201
  1500
                    return GPG_ERR_GENERAL;
vb@201
  1501
                }
vb@223
  1502
                gpg.gpgme_io_write(fd, "quit\n", 5);
vb@200
  1503
                handle->state = renew_save;
vb@200
  1504
            }
vb@200
  1505
            break;
vb@200
  1506
vb@200
  1507
        case renew_save:
vb@200
  1508
            if (statuscode == GPGME_STATUS_GET_BOOL) {
vb@201
  1509
                assert(strcmp(args, "keyedit.save.okay") == 0);
vb@201
  1510
                if (strcmp(args, "keyedit.save.okay")) {
vb@201
  1511
                    handle->state = renew_error;
vb@201
  1512
                    return GPG_ERR_GENERAL;
vb@201
  1513
                }
vb@223
  1514
                gpg.gpgme_io_write(fd, "Y\n", 2);
vb@200
  1515
                handle->state = renew_exit;
vb@200
  1516
            }
vb@200
  1517
            break;
vb@200
  1518
vb@200
  1519
        case renew_exit:
vb@200
  1520
            break;
vb@200
  1521
vb@200
  1522
        case renew_error:
vb@200
  1523
            return GPG_ERR_GENERAL;
vb@200
  1524
    }
vb@200
  1525
vb@200
  1526
    return GPG_ERR_NO_ERROR;
vb@200
  1527
}
vb@200
  1528
vb@200
  1529
static ssize_t _nullwriter(
vb@200
  1530
        void *_handle,
vb@200
  1531
        const void *buffer,
vb@200
  1532
        size_t size
vb@200
  1533
    )
vb@200
  1534
{
vb@200
  1535
    return size;
vb@200
  1536
}
vb@200
  1537
vb@201
  1538
PEP_STATUS pgp_renew_key(
vb@201
  1539
        PEP_SESSION session,
vb@201
  1540
        const char *fpr,
vb@201
  1541
        const timestamp *ts
vb@201
  1542
    )
vb@200
  1543
{
vb@200
  1544
    PEP_STATUS status = PEP_STATUS_OK;
vb@200
  1545
    gpgme_error_t gpgme_error;
vb@200
  1546
    gpgme_key_t key;
vb@200
  1547
    gpgme_data_t output;
vb@201
  1548
    renew_state handle;
vb@203
  1549
    char date_text[12];
vb@200
  1550
vb@200
  1551
    assert(session);
vb@200
  1552
    assert(fpr);
vb@200
  1553
vb@201
  1554
    memset(&handle, 0, sizeof(renew_state));
vb@203
  1555
    snprintf(date_text, 12, "%.4d-%.2d-%.2d\n", ts->tm_year + 1900,
vb@201
  1556
            ts->tm_mon + 1, ts->tm_mday);
vb@201
  1557
    handle.date_ref = date_text;
vb@200
  1558
vb@200
  1559
    status = find_single_key(session, fpr, &key);
vb@200
  1560
    if (status != PEP_STATUS_OK)
vb@200
  1561
        return status;
vb@200
  1562
vb@200
  1563
    struct gpgme_data_cbs data_cbs;
vb@200
  1564
    memset(&data_cbs, 0, sizeof(struct gpgme_data_cbs));
vb@200
  1565
    data_cbs.write = _nullwriter;
vb@220
  1566
    gpg.gpgme_data_new_from_cbs(&output, &data_cbs, &handle);
vb@200
  1567
vb@220
  1568
    gpgme_error = gpg.gpgme_op_edit(session->ctx, key, renew_fsm, &handle,
vb@200
  1569
            output);
vb@200
  1570
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@200
  1571
vb@200
  1572
    gpg.gpgme_data_release(output);
vb@200
  1573
    gpg.gpgme_key_unref(key);
vb@200
  1574
vb@200
  1575
    return PEP_STATUS_OK;
vb@200
  1576
}
vb@200
  1577
vb@211
  1578
typedef struct _revoke_state {
vb@211
  1579
    enum {
vb@211
  1580
        revoke_command = 0,
vb@211
  1581
        revoke_approve,
vb@211
  1582
        revoke_reason_code,
vb@211
  1583
        revoke_reason_text,
vb@211
  1584
        revoke_reason_ok,
vb@211
  1585
        revoke_quit,
vb@211
  1586
        revoke_save,
vb@211
  1587
        revoke_exit,
vb@211
  1588
        revoke_error = -1
vb@211
  1589
    } state;
vb@211
  1590
    const char *reason_ref;
vb@211
  1591
} revoke_state;
vb@211
  1592
vb@211
  1593
static bool isemptystring(const char *str)
vb@211
  1594
{
vb@211
  1595
    if (str == NULL)
vb@211
  1596
        return true;
vb@211
  1597
vb@211
  1598
    for (; str; str++) {
vb@211
  1599
        if (*str != ' ' && *str != '\t' && *str != '\n')
vb@211
  1600
            return false;
vb@211
  1601
    }
vb@211
  1602
vb@211
  1603
    return true;
vb@211
  1604
}
vb@211
  1605
vb@211
  1606
static gpgme_error_t revoke_fsm(
vb@211
  1607
        void *_handle,
vb@211
  1608
        gpgme_status_code_t statuscode,
vb@211
  1609
        const char *args,
vb@211
  1610
        int fd
vb@211
  1611
    )
vb@211
  1612
{
vb@211
  1613
    revoke_state *handle = _handle;
vb@211
  1614
vb@211
  1615
    switch (handle->state) {
vb@211
  1616
        case revoke_command:
vb@211
  1617
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@211
  1618
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@211
  1619
                if (strcmp(args, "keyedit.prompt")) {
vb@211
  1620
                    handle->state = revoke_error;
vb@211
  1621
                    return GPG_ERR_GENERAL;
vb@211
  1622
                }
vb@223
  1623
                gpg.gpgme_io_write(fd, "revkey\n", 7);
vb@211
  1624
                handle->state = revoke_approve;
vb@211
  1625
            }
vb@211
  1626
            break;
vb@211
  1627
vb@211
  1628
        case revoke_approve:
vb@211
  1629
            if (statuscode == GPGME_STATUS_GET_BOOL) {
vb@211
  1630
                assert(strcmp(args, "keyedit.revoke.subkey.okay") == 0);
vb@211
  1631
                if (strcmp(args, "keyedit.revoke.subkey.okay")) {
vb@211
  1632
                    handle->state = revoke_error;
vb@211
  1633
                    return GPG_ERR_GENERAL;
vb@211
  1634
                }
vb@223
  1635
                gpg.gpgme_io_write(fd, "Y\n", 2);
vb@211
  1636
                handle->state = revoke_reason_code;
vb@211
  1637
            }
vb@211
  1638
            break;
vb@211
  1639
vb@211
  1640
        case revoke_reason_code:
vb@211
  1641
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@211
  1642
                assert(strcmp(args, "ask_revocation_reason.code") == 0);
vb@211
  1643
                if (strcmp(args, "ask_revocation_reason.code")) {
vb@211
  1644
                    handle->state = revoke_error;
vb@211
  1645
                    return GPG_ERR_GENERAL;
vb@211
  1646
                }
vb@223
  1647
                gpg.gpgme_io_write(fd, "1\n", 2);
vb@211
  1648
                handle->state = revoke_reason_text;
vb@211
  1649
            }
vb@211
  1650
            break;
vb@211
  1651
vb@211
  1652
        case revoke_reason_text:
vb@211
  1653
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@211
  1654
                assert(strcmp(args, "ask_revocation_reason.text") == 0);
vb@211
  1655
                if (strcmp(args, "ask_revocation_reason.text")) {
vb@211
  1656
                    handle->state = revoke_error;
vb@211
  1657
                    return GPG_ERR_GENERAL;
vb@211
  1658
                }
vb@213
  1659
                // BUG: issues when reason given
vb@213
  1660
                // Assertion failed: (gpg->cmd.code), function command_handler,
vb@213
  1661
                // file engine-gpg.c, line 662.
vb@213
  1662
                //
vb@213
  1663
                // if (isemptystring(handle->reason_ref)) {
vb@223
  1664
                    gpg.gpgme_io_write(fd, "\n", 1);
vb@213
  1665
                // }
vb@213
  1666
                // else {
vb@213
  1667
                //     size_t len = strlen(handle->reason_ref);
vb@223
  1668
                //     gpg.gpgme_io_write(fd, handle->reason_ref, len);
vb@213
  1669
                //     if (handle->reason_ref[len - 1] == '\n')
vb@223
  1670
                //         gpg.gpgme_io_write(fd, "\n", 1);
vb@213
  1671
                //     else
vb@223
  1672
                //         gpg.gpgme_io_write(fd, "\n\n", 2);
vb@213
  1673
                // }
vb@211
  1674
                handle->state = revoke_reason_ok;
vb@211
  1675
            }
vb@211
  1676
            break;
vb@211
  1677
vb@211
  1678
        case revoke_reason_ok:
vb@211
  1679
            if (statuscode == GPGME_STATUS_GET_BOOL) {
vb@211
  1680
                assert(strcmp(args, "ask_revocation_reason.okay") == 0);
vb@211
  1681
                if (strcmp(args, "ask_revocation_reason.okay")) {
vb@211
  1682
                    handle->state = revoke_error;
vb@211
  1683
                    return GPG_ERR_GENERAL;
vb@211
  1684
                }
vb@223
  1685
                gpg.gpgme_io_write(fd, "Y\n", 2);
vb@211
  1686
                handle->state = revoke_quit;
vb@211
  1687
            }
vb@211
  1688
            break;
vb@211
  1689
vb@211
  1690
        case revoke_quit:
vb@211
  1691
            if (statuscode == GPGME_STATUS_GET_LINE) {
vb@211
  1692
                assert(strcmp(args, "keyedit.prompt") == 0);
vb@211
  1693
                if (strcmp(args, "keyedit.prompt")) {
vb@211
  1694
                    handle->state = revoke_error;
vb@211
  1695
                    return GPG_ERR_GENERAL;
vb@211
  1696
                }
vb@223
  1697
                gpg.gpgme_io_write(fd, "quit\n", 5);
vb@211
  1698
                handle->state = revoke_save;
vb@211
  1699
            }
vb@211
  1700
            break;
vb@211
  1701
vb@211
  1702
        case revoke_save:
vb@211
  1703
            if (statuscode == GPGME_STATUS_GET_BOOL) {
vb@211
  1704
                assert(strcmp(args, "keyedit.save.okay") == 0);
vb@211
  1705
                if (strcmp(args, "keyedit.save.okay")) {
vb@211
  1706
                    handle->state = revoke_error;
vb@211
  1707
                    return GPG_ERR_GENERAL;
vb@211
  1708
                }
vb@223
  1709
                gpg.gpgme_io_write(fd, "Y\n", 2);
vb@211
  1710
                handle->state = revoke_exit;
vb@211
  1711
            }
vb@211
  1712
            break;
vb@211
  1713
vb@211
  1714
        case revoke_exit:
vb@211
  1715
            break;
vb@211
  1716
vb@211
  1717
        case revoke_error:
vb@211
  1718
            return GPG_ERR_GENERAL;
vb@211
  1719
    }
vb@211
  1720
vb@211
  1721
    return GPG_ERR_NO_ERROR;
vb@211
  1722
}
vb@211
  1723
vb@211
  1724
PEP_STATUS pgp_revoke_key(
vb@211
  1725
        PEP_SESSION session,
vb@211
  1726
        const char *fpr,
vb@211
  1727
        const char *reason
vb@211
  1728
    )
vb@200
  1729
{
vb@200
  1730
    PEP_STATUS status = PEP_STATUS_OK;
vb@211
  1731
    gpgme_error_t gpgme_error;
vb@200
  1732
    gpgme_key_t key;
vb@211
  1733
    gpgme_data_t output;
vb@211
  1734
    revoke_state handle;
vb@211
  1735
vb@200
  1736
    assert(session);
vb@200
  1737
    assert(fpr);
vb@200
  1738
vb@211
  1739
    memset(&handle, 0, sizeof(revoke_state));
vb@213
  1740
    handle.reason_ref = reason;
vb@211
  1741
vb@200
  1742
    status = find_single_key(session, fpr, &key);
vb@200
  1743
    if (status != PEP_STATUS_OK)
vb@200
  1744
        return status;
vb@200
  1745
vb@211
  1746
    struct gpgme_data_cbs data_cbs;
vb@211
  1747
    memset(&data_cbs, 0, sizeof(struct gpgme_data_cbs));
vb@211
  1748
    data_cbs.write = _nullwriter;
vb@220
  1749
    gpg.gpgme_data_new_from_cbs(&output, &data_cbs, &handle);
vb@211
  1750
vb@220
  1751
    gpgme_error = gpg.gpgme_op_edit(session->ctx, key, revoke_fsm, &handle,
vb@211
  1752
            output);
vb@211
  1753
    assert(gpgme_error == GPG_ERR_NO_ERROR);
vb@211
  1754
vb@211
  1755
    gpg.gpgme_data_release(output);
vb@211
  1756
    gpg.gpgme_key_unref(key);
vb@211
  1757
vb@200
  1758
    return PEP_STATUS_OK;
vb@200
  1759
}
vb@200
  1760
vb@214
  1761
PEP_STATUS pgp_key_expired(
vb@214
  1762
        PEP_SESSION session,
vb@214
  1763
        const char *fpr,
vb@214
  1764
        bool *expired
vb@214
  1765
    )
vb@214
  1766
{
vb@214
  1767
    PEP_STATUS status = PEP_STATUS_OK;
vb@214
  1768
    gpgme_key_t key;
vb@214
  1769
vb@214
  1770
    assert(session);
vb@214
  1771
    assert(fpr);
vb@214
  1772
    assert(expired);
vb@214
  1773
vb@214
  1774
    *expired = false;
vb@214
  1775
vb@214
  1776
    status = find_single_key(session, fpr, &key);
vb@214
  1777
    if (status != PEP_STATUS_OK)
vb@214
  1778
        return status;
vb@214
  1779
Edouard@620
  1780
    if (key->subkeys)
Edouard@620
  1781
    {
Edouard@620
  1782
        *expired = key->subkeys->expired;
Edouard@620
  1783
    }
Edouard@620
  1784
    else
Edouard@620
  1785
    {
Edouard@620
  1786
        status = PEP_KEY_NOT_FOUND;
Edouard@620
  1787
    }
Edouard@620
  1788
vb@214
  1789
    gpg.gpgme_key_unref(key);
Edouard@620
  1790
    return status;
vb@214
  1791
}
vb@214
  1792
vb@507
  1793
PEP_STATUS pgp_binary(const char **path)
vb@507
  1794
{
vb@507
  1795
    assert(path);
vb@507
  1796
    if (path == NULL)
vb@507
  1797
        return PEP_ILLEGAL_VALUE;
vb@507
  1798
vb@507
  1799
    *path = NULL;
vb@507
  1800
vb@507
  1801
    gpgme_engine_info_t info;
vb@507
  1802
    int err = gpg.gpgme_get_engine_info(&info);
vb@507
  1803
    assert(err == GPG_ERR_NO_ERROR);
vb@507
  1804
    if (err != GPG_ERR_NO_ERROR)
vb@507
  1805
        return PEP_OUT_OF_MEMORY;
vb@507
  1806
vb@507
  1807
    *path = info->file_name;
vb@507
  1808
vb@507
  1809
    return PEP_STATUS_OK;
vb@507
  1810
}
vb@507
  1811