2003-08-05 17:11:04 +00:00
|
|
|
/* scdaemon.h - Global definitions for the SCdaemon
|
|
|
|
* Copyright (C) 2001, 2002, 2003 Free Software Foundation, Inc.
|
|
|
|
*
|
|
|
|
* This file is part of GnuPG.
|
|
|
|
*
|
|
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
2007-07-04 19:49:40 +00:00
|
|
|
* the Free Software Foundation; either version 3 of the License, or
|
2003-08-05 17:11:04 +00:00
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
2016-11-05 12:02:19 +01:00
|
|
|
* along with this program; if not, see <https://www.gnu.org/licenses/>.
|
2003-08-05 17:11:04 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef SCDAEMON_H
|
|
|
|
#define SCDAEMON_H
|
|
|
|
|
|
|
|
#ifdef GPG_ERR_SOURCE_DEFAULT
|
|
|
|
#error GPG_ERR_SOURCE_DEFAULT already defined
|
|
|
|
#endif
|
|
|
|
#define GPG_ERR_SOURCE_DEFAULT GPG_ERR_SOURCE_SCD
|
|
|
|
#include <gpg-error.h>
|
|
|
|
|
|
|
|
#include <time.h>
|
|
|
|
#include <gcrypt.h>
|
|
|
|
#include "../common/util.h"
|
2007-10-01 14:48:39 +00:00
|
|
|
#include "../common/sysutils.h"
|
2019-06-21 10:23:35 +02:00
|
|
|
#include "app-common.h"
|
|
|
|
|
2003-08-05 17:11:04 +00:00
|
|
|
|
2006-10-24 14:45:34 +00:00
|
|
|
/* To convey some special hash algorithms we use algorithm numbers
|
|
|
|
reserved for application use. */
|
2008-09-29 15:02:55 +00:00
|
|
|
#ifndef GCRY_MODULE_ID_USER
|
|
|
|
#define GCRY_MODULE_ID_USER 1024
|
2006-10-24 14:45:34 +00:00
|
|
|
#endif
|
2008-09-29 15:02:55 +00:00
|
|
|
#define MD_USER_TLS_MD5SHA1 (GCRY_MODULE_ID_USER+1)
|
2006-10-24 14:45:34 +00:00
|
|
|
|
|
|
|
/* Maximum length of a digest. */
|
2009-03-26 19:27:04 +00:00
|
|
|
#define MAX_DIGEST_LEN 64
|
2006-10-24 14:45:34 +00:00
|
|
|
|
|
|
|
|
2003-08-05 17:11:04 +00:00
|
|
|
|
2005-11-28 11:52:25 +00:00
|
|
|
/* A large struct name "opt" to keep global flags. */
|
2020-02-10 16:37:34 +01:00
|
|
|
EXTERN_UNLESS_MAIN_MODULE
|
2006-09-06 16:35:52 +00:00
|
|
|
struct
|
|
|
|
{
|
2005-11-28 11:52:25 +00:00
|
|
|
unsigned int debug; /* Debug flags (DBG_foo_VALUE). */
|
|
|
|
int verbose; /* Verbosity level. */
|
|
|
|
int quiet; /* Be as quiet as possible. */
|
|
|
|
int dry_run; /* Don't change any persistent data. */
|
|
|
|
int batch; /* Batch mode. */
|
2003-08-05 17:11:04 +00:00
|
|
|
const char *ctapi_driver; /* Library to access the ctAPI. */
|
2003-08-19 09:36:48 +00:00
|
|
|
const char *pcsc_driver; /* Library to access the PC/SC system. */
|
2004-01-27 16:40:42 +00:00
|
|
|
const char *reader_port; /* NULL or reder port to use. */
|
2003-09-02 19:06:34 +00:00
|
|
|
int disable_ccid; /* Disable the use of the internal CCID driver. */
|
scd: Rename 'keypad' to 'pinpad'.
* NEWS: Mention scd changes.
* agent/divert-scd.c (getpin_cb): Change message.
* agent/call-scd.c (inq_needpin): Change the protocol to
POPUPPINPADPROMPT and DISMISSPINPADPROMPT.
* scd/command.c (pin_cb): Likewise.
* scd/apdu.c (struct reader_table_s): Rename member functions.
(check_pcsc_pinpad, pcsc_pinpad_verify, pcsc_pinpad_modify,
check_ccid_pinpad, ccid_pinpad_operation, apdu_check_pinpad
apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/apdu.h (SW_HOST_NO_PINPAD, apdu_check_pinpad)
(apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/iso7816.h (iso7816_check_pinpad): Rename.
* scd/iso7816.c (map_sw): Use SW_HOST_NO_PINPAD.
(iso7816_check_pinpad): Rename.
(iso7816_verify_kp, iso7816_change_reference_data_kp): Follow
the change.
* scd/ccid-driver.h (CCID_DRIVER_ERR_NO_PINPAD): Rename.
* scd/ccid-driver.c (ccid_transceive_secure): Use it.
* scd/app-dinsig.c (verify_pin): Follow the change.
* scd/app-nks.c (verify_pin): Follow the change.
* scd/app-openpgp.c (check_pinpad_request): Rename.
(parse_login_data, verify_a_chv, verify_chv3, do_change_pin): Follow
the change.
* scd/scdaemon.c (oDisablePinpad, oEnablePinpadVarlen): Rename.
* scd/scdaemon.h (opt): Rename to disable_pinpad,
enable_pinpad_varlen.
* tools/gpgconf-comp.c (gc_options_scdaemon): Rename to
disable-pinpad.
2013-02-07 10:07:51 +09:00
|
|
|
int disable_pinpad; /* Do not use a pinpad. */
|
|
|
|
int enable_pinpad_varlen; /* Use variable length input for pinpad. */
|
2003-12-01 10:54:09 +00:00
|
|
|
int allow_admin; /* Allow the use of admin commands for certain
|
|
|
|
cards. */
|
2021-03-12 09:21:57 +01:00
|
|
|
int pcsc_shared; /* Use shared PC/SC access. */
|
2005-11-28 11:52:25 +00:00
|
|
|
strlist_t disabled_applications; /* Card applications we do not
|
2004-08-05 09:24:36 +00:00
|
|
|
want to use. */
|
2008-12-05 12:01:01 +00:00
|
|
|
unsigned long card_timeout; /* Disconnect after N seconds of inactivity. */
|
2003-08-05 17:11:04 +00:00
|
|
|
} opt;
|
|
|
|
|
|
|
|
|
2022-05-05 13:35:56 +02:00
|
|
|
#define DBG_APP_VALUE 1 /* Debug app specific stuff. */
|
2003-08-05 17:11:04 +00:00
|
|
|
#define DBG_MPI_VALUE 2 /* debug mpi details */
|
|
|
|
#define DBG_CRYPTO_VALUE 4 /* debug low level crypto */
|
2022-05-05 13:35:56 +02:00
|
|
|
#define DBG_CARD_VALUE 16 /* debug card info */
|
2003-08-05 17:11:04 +00:00
|
|
|
#define DBG_MEMORY_VALUE 32 /* debug memory allocation stuff */
|
|
|
|
#define DBG_CACHE_VALUE 64 /* debug the caching */
|
|
|
|
#define DBG_MEMSTAT_VALUE 128 /* show memory statistics */
|
|
|
|
#define DBG_HASHING_VALUE 512 /* debug hashing operations */
|
2015-04-06 13:42:17 +02:00
|
|
|
#define DBG_IPC_VALUE 1024
|
2022-05-05 13:35:56 +02:00
|
|
|
#define DBG_CARD_IO_VALUE 2048 /* debug card I/O (e.g. APDUs). */
|
2011-12-14 10:21:15 +01:00
|
|
|
#define DBG_READER_VALUE 4096 /* Trace reader related functions. */
|
2003-08-05 17:11:04 +00:00
|
|
|
|
2019-09-05 12:59:56 +02:00
|
|
|
#define DBG_APP (opt.debug & DBG_APP_VALUE)
|
2003-08-05 17:11:04 +00:00
|
|
|
#define DBG_CRYPTO (opt.debug & DBG_CRYPTO_VALUE)
|
|
|
|
#define DBG_MEMORY (opt.debug & DBG_MEMORY_VALUE)
|
|
|
|
#define DBG_CACHE (opt.debug & DBG_CACHE_VALUE)
|
|
|
|
#define DBG_HASHING (opt.debug & DBG_HASHING_VALUE)
|
2015-04-06 13:42:17 +02:00
|
|
|
#define DBG_IPC (opt.debug & DBG_IPC_VALUE)
|
2022-05-05 13:35:56 +02:00
|
|
|
#define DBG_CARD (opt.debug & DBG_CARD_VALUE)
|
2003-08-05 17:11:04 +00:00
|
|
|
#define DBG_CARD_IO (opt.debug & DBG_CARD_IO_VALUE)
|
2011-12-14 10:21:15 +01:00
|
|
|
#define DBG_READER (opt.debug & DBG_READER_VALUE)
|
2003-08-05 17:11:04 +00:00
|
|
|
|
|
|
|
struct server_local_s;
|
2019-06-19 08:50:40 +02:00
|
|
|
struct card_ctx_s;
|
2003-08-05 17:11:04 +00:00
|
|
|
struct app_ctx_s;
|
|
|
|
|
2011-02-04 12:57:53 +01:00
|
|
|
struct server_control_s
|
2005-06-03 13:57:24 +00:00
|
|
|
{
|
2006-11-20 16:49:41 +00:00
|
|
|
/* Private data used to fire up the connection thread. We use this
|
|
|
|
structure do avoid an extra allocation for just a few bytes. */
|
|
|
|
struct {
|
2007-10-01 14:48:39 +00:00
|
|
|
gnupg_fd_t fd;
|
2006-11-20 16:49:41 +00:00
|
|
|
} thread_startup;
|
2011-02-04 12:57:53 +01:00
|
|
|
|
2005-06-03 13:57:24 +00:00
|
|
|
/* Local data of the server; used only in command.c. */
|
2003-08-05 17:11:04 +00:00
|
|
|
struct server_local_s *server_local;
|
2005-06-03 13:57:24 +00:00
|
|
|
|
|
|
|
/* The application context used with this connection or NULL if none
|
|
|
|
associated. Note that this is shared with the other connections:
|
|
|
|
All connections accessing the same reader are using the same
|
|
|
|
application context. */
|
2019-06-19 08:50:40 +02:00
|
|
|
struct card_ctx_s *card_ctx;
|
2005-06-03 13:57:24 +00:00
|
|
|
|
2019-06-21 10:47:45 +02:00
|
|
|
/* The currently active application for this context. We need to
|
scd: Add an re-select mechanism to switch apps.
* scd/app-common.h (struct app_ctx_s): Add func ptr 'reselect'.
* scd/app-piv.c (do_reselect): New.
(app_select_piv): Move AID constant to file scope.
* scd/app-openpgp.c (do_reselect): New.
(app_select_openpgp): Move AID constant to file scope.
* scd/app.c (apptype_from_name): New.
(check_application_conflict): Check against all apps of the card.
Always set current_apptype.
(select_additional_application): New.
(maybe_switch_app): New.
(app_write_learn_status, app_readcert, app_readkey, app_getattr)
(app_setattr, app_sign, app_auth, app_decipher, app_writecert)
(app_writekey, app_genkey, app_change_pin, app_check_pin): Use it here.
(app_do_with_keygrip): Force reselect on success.
(app_new_register): Move setting of CURRENT_APPTYPE to ...
(select_application): here so that it will be set to the requested
card.
* scd/command.c (open_card_with_request): Select additional
application if possible.
--
Noet that we will likely need to rework this even more so to get well
defined semantics for card access.
Signed-off-by: Werner Koch <wk@gnupg.org>
2019-06-25 08:30:04 +02:00
|
|
|
* know this for cards which are able to switch on the fly between
|
2019-06-21 10:47:45 +02:00
|
|
|
* apps. */
|
|
|
|
apptype_t current_apptype;
|
|
|
|
|
2005-06-03 13:57:24 +00:00
|
|
|
/* Helper to store the value we are going to sign */
|
2011-02-04 12:57:53 +01:00
|
|
|
struct
|
2005-06-03 13:57:24 +00:00
|
|
|
{
|
2011-02-04 12:57:53 +01:00
|
|
|
unsigned char *value;
|
2003-08-05 17:11:04 +00:00
|
|
|
int valuelen;
|
2011-02-04 12:57:53 +01:00
|
|
|
} in_data;
|
2003-08-05 17:11:04 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
/*-- scdaemon.c --*/
|
|
|
|
void scd_exit (int rc);
|
2005-05-18 10:48:06 +00:00
|
|
|
const char *scd_get_socket_name (void);
|
2003-08-05 17:11:04 +00:00
|
|
|
|
|
|
|
/*-- command.c --*/
|
2016-12-29 10:07:43 +09:00
|
|
|
gpg_error_t initialize_module_command (void);
|
2022-03-31 21:03:13 +09:00
|
|
|
int scd_command_handler (ctrl_t, gnupg_fd_t);
|
2006-10-10 11:11:04 +00:00
|
|
|
void send_status_info (ctrl_t ctrl, const char *keyword, ...)
|
2015-07-26 12:50:16 +02:00
|
|
|
GPGRT_ATTR_SENTINEL(1);
|
2021-03-16 18:52:38 +01:00
|
|
|
gpg_error_t send_status_direct (ctrl_t ctrl,
|
|
|
|
const char *keyword, const char *args);
|
2019-01-21 14:06:51 +01:00
|
|
|
gpg_error_t send_status_printf (ctrl_t ctrl, const char *keyword,
|
|
|
|
const char *format, ...) GPGRT_ATTR_PRINTF(3,4);
|
2019-04-25 14:49:49 +09:00
|
|
|
void send_keyinfo (ctrl_t ctrl, int data, const char *keygrip_str,
|
|
|
|
const char *serialno, const char *idstr);
|
2019-01-21 14:06:51 +01:00
|
|
|
|
2020-01-07 18:45:33 +01:00
|
|
|
void pincache_put (ctrl_t ctrl, int slot, const char *appname,
|
2020-01-13 17:53:49 +01:00
|
|
|
const char *pinref, const char *pin, unsigned int pinlen);
|
2020-01-07 18:45:33 +01:00
|
|
|
gpg_error_t pincache_get (ctrl_t ctrl, int slot, const char *appname,
|
|
|
|
const char *pinref, char **r_pin);
|
|
|
|
|
2018-10-11 15:41:49 +09:00
|
|
|
void popup_prompt (void *opaque, int on);
|
2019-06-17 16:19:22 +02:00
|
|
|
|
2019-06-19 08:50:40 +02:00
|
|
|
/* Take care: this function assumes that CARD is locked. */
|
|
|
|
void send_client_notifications (card_t card, int removal);
|
2019-06-17 16:19:22 +02:00
|
|
|
|
2017-01-28 00:18:11 +09:00
|
|
|
void scd_kick_the_loop (void);
|
2017-02-01 08:58:01 +09:00
|
|
|
int get_active_connection_count (void);
|
2003-08-05 17:11:04 +00:00
|
|
|
|
2017-01-31 12:56:11 +09:00
|
|
|
/*-- app.c --*/
|
|
|
|
int scd_update_reader_status_file (void);
|
2021-10-29 10:48:01 +09:00
|
|
|
gpg_error_t app_send_devinfo (ctrl_t ctrl, int keep_looping);
|
2017-01-31 12:56:11 +09:00
|
|
|
|
2003-08-05 17:11:04 +00:00
|
|
|
#endif /*SCDAEMON_H*/
|