mirror of
git://git.gnupg.org/gnupg.git
synced 2025-01-17 14:07:03 +01:00
915297705a
* common/util.h (UBID_LEN): New. Use it at all places. * kbx/keybox-blob.c (create_blob_finish): Do not write the UBID item. * kbx/keybox-dump.c (print_ubib): Remove. (_keybox_dump_blob): Do not print the now removed ubid flag. * kbx/keybox-search-desc.h (struct keydb_search_desc): Use constants for the size of the ubid and grip. * kbx/keybox-search.c (blob_cmp_ubid): New. (has_ubid): Make it a simple wrapper around blob_cmp_ubid. (keybox_get_data): Add arg 'r_ubid'. * kbx/frontend.h (enum kbxd_store_modes): New. * kbx/kbxserver.c (cmd_store): Add new option --insert. * kbx/backend-cache.c (be_cache_initialize): New. (be_cache_add_resource): Call it here. * kbx/backend-kbx.c (be_kbx_seek): Remove args 'fpr' and 'fprlen'. (be_kbx_search): Get the UBID from keybox_get_data. * kbx/backend-support.c (be_fingerprint_from_blob): Replace by ... (be_ubid_from_blob): new. Change all callers. * kbx/frontend.c (kbxd_add_resource): Temporary disable the cache but use the new cache init function. (kbxd_store): Replace arg 'only_update' by 'mode'. Seek using the ubid. Take care of the mode. -- It turned out that using the hash of the entire blob was not helpful. Thus we redefine the Unique-Blob-ID (UBID) as the primary fingerprint of the blob. In case this is a v5 OpenPGP key a left truncated version of the SHA-256 hash is used; in all other cases the full SHA-1 hash. Using a SHA-256 hash does not make sense because v4 keys are and will for some time be the majority of keys and thus padding them with zeroes won't make any difference. Even if fingerprint collisions can eventually be created we will assume that the keys are bogus and that it does not make sense to store its twin also in our key storage. We can also easily extend the update code to detect a collision and reject the update. Signed-off-by: Werner Koch <wk@gnupg.org>
98 lines
2.8 KiB
C
98 lines
2.8 KiB
C
/* keybox-search-desc.h - Keybox serch description
|
|
* Copyright (C) 2001 Free Software Foundation, Inc.
|
|
*
|
|
* This file is part of GnuPG.
|
|
*
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, see <https://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
/*
|
|
This file is a temporary kludge until we can come up with solution
|
|
to share this description between keybox and the application
|
|
specific keydb
|
|
*/
|
|
|
|
#ifndef KEYBOX_SEARCH_DESC_H
|
|
#define KEYBOX_SEARCH_DESC_H 1
|
|
|
|
typedef enum {
|
|
KEYDB_SEARCH_MODE_NONE,
|
|
KEYDB_SEARCH_MODE_EXACT,
|
|
KEYDB_SEARCH_MODE_SUBSTR,
|
|
KEYDB_SEARCH_MODE_MAIL,
|
|
KEYDB_SEARCH_MODE_MAILSUB,
|
|
KEYDB_SEARCH_MODE_MAILEND,
|
|
KEYDB_SEARCH_MODE_WORDS,
|
|
KEYDB_SEARCH_MODE_SHORT_KID,
|
|
KEYDB_SEARCH_MODE_LONG_KID,
|
|
KEYDB_SEARCH_MODE_FPR, /* (Length of fpr in .fprlen) */
|
|
KEYDB_SEARCH_MODE_ISSUER,
|
|
KEYDB_SEARCH_MODE_ISSUER_SN,
|
|
KEYDB_SEARCH_MODE_SN,
|
|
KEYDB_SEARCH_MODE_SUBJECT,
|
|
KEYDB_SEARCH_MODE_KEYGRIP,
|
|
KEYDB_SEARCH_MODE_UBID,
|
|
KEYDB_SEARCH_MODE_FIRST,
|
|
KEYDB_SEARCH_MODE_NEXT
|
|
} KeydbSearchMode;
|
|
|
|
|
|
/* Identifiers for the public key types we use in GnuPG. */
|
|
enum pubkey_types
|
|
{
|
|
PUBKEY_TYPE_UNKNOWN = 0,
|
|
PUBKEY_TYPE_OPGP = 1,
|
|
PUBKEY_TYPE_X509 = 2
|
|
};
|
|
|
|
|
|
/* Forward declaration. See g10/packet.h. */
|
|
struct gpg_pkt_user_id_s;
|
|
typedef struct gpg_pkt_user_id_s *gpg_pkt_user_id_t;
|
|
|
|
|
|
/* A search descriptor. */
|
|
struct keydb_search_desc
|
|
{
|
|
KeydbSearchMode mode;
|
|
/* Callback used to filter results. The first parameter is
|
|
SKIPFUNCVALUE. The second is the keyid. The third is the
|
|
1-based index of the UID packet that matched the search criteria
|
|
(or 0, if none).
|
|
|
|
Return non-zero if the result should be skipped. */
|
|
int (*skipfnc)(void *, u32 *, int);
|
|
void *skipfncvalue;
|
|
const unsigned char *sn;
|
|
int snlen; /* -1 := sn is a hex string */
|
|
union {
|
|
const char *name;
|
|
unsigned char fpr[32];
|
|
u32 kid[2]; /* Note that this is in native endianness. */
|
|
unsigned char grip[KEYGRIP_LEN];
|
|
unsigned char ubid[UBID_LEN];
|
|
} u;
|
|
byte fprlen; /* Only used with KEYDB_SEARCH_MODE_FPR. */
|
|
int exact; /* Use exactly this key ('!' suffix in gpg). */
|
|
};
|
|
|
|
|
|
struct keydb_search_desc;
|
|
typedef struct keydb_search_desc KEYDB_SEARCH_DESC;
|
|
typedef struct keydb_search_desc KEYBOX_SEARCH_DESC;
|
|
|
|
|
|
|
|
#endif /*KEYBOX_SEARCH_DESC_H*/
|