mirror of
git://git.gnupg.org/gnupg.git
synced 2024-11-04 20:38:50 +01:00
203f54a634
* configure.ac (NEED_LIBASSUAN_API, NEED_LIBASSUAN_VERSION): Update to new API (2, 1.1.0). agent/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * gpg-agent.c (parse_rereadable_options): Don't set global assuan log file (there ain't one anymore). (main): Update to new API. (check_own_socket_pid_cb): Return gpg_error_t instead of int. (check_own_socket_thread, check_for_running_agent): Create assuan context before connecting to server. * command.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (write_and_clear_outbuf): Use gpg_error_t instead of assuan_error_t. (cmd_geteventcounter, cmd_istrusted, cmd_listtrusted) (cmd_marktrusted, cmd_havekey, cmd_sigkey, cmd_setkeydesc) (cmd_sethash, cmd_pksign, cmd_pkdecrypt, cmd_genkey, cmd_readkey) (cmd_keyinfo, cmd_get_passphrase, cmd_clear_passphrase) (cmd_get_confirmation, cmd_learn, cmd_passwd) (cmd_preset_passphrase, cmd_scd, cmd_getval, cmd_putval) (cmd_updatestartuptty, cmd_killagent, cmd_reloadagent) (cmd_getinfo, option_handler): Return gpg_error_t instead of int. (post_cmd_notify): Change type of ERR to gpg_error_t from int. (io_monitor): Add hook argument. Use symbols for constants. (register_commands): Change return type of HANDLER to gpg_error_t. (start_command_handler): Allocate assuan context before starting server. * call-pinentry.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (unlock_pinentry): Call assuan_release instead of assuan_disconnect. (getinfo_pid_cb, getpin_cb): Return gpg_error_t instead of int. (start_pinentry): Allocate assuan context before connecting to server. * call-scd.c (membuf_data_cb, learn_status_cb, get_serialno_cb) (membuf_data_cb, inq_needpin, card_getattr_cb, pass_status_thru) (pass_data_thru): Change return type to gpg_error_t. (start_scd): Allocate assuan context before connecting to server. common/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * asshelp.c (start_new_gpg_agent): Allocate assuan context before starting server. g10/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * call-agent.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (learn_status_cb, dummy_data_cb, get_serialno_cb, default_inq_cb) (learn_status_cb, inq_writecert_parms, inq_writekey_parms) (scd_genkey_cb, membuf_data_cb): Return gpg_error_t instead of int. * gpg.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (main): Update to new Assuan API. * server.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (option_handler, cmd_recipient, cmd_signer, cmd_encrypt) (cmd_decrypt, cmd_verify, cmd_sign, cmd_import, cmd_export) (cmd_delkeys, cmd_message, do_listkeys, cmd_listkeys) (cmd_listsecretkeys, cmd_genkey, cmd_getinfo): Return gpg_error_t instead of int. (register_commands): Allocate assuan context before starting server. (gpg_server): Allocate assuan_context before starting server. scd/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * command.c: Include "scdaemon.h" before <assuan.h> because of GPG_ERR_SOURCE_DEFAULT check. (option_handler, open_card, cmd_serialno, cmd_lean, cmd_readcert) (cmd_readkey, cmd_setdata, cmd_pksign, cmd_pkauth, cmd_pkdecrypt) (cmd_getattr, cmd_setattr, cmd_writecert, cmd_writekey) (cmd_genkey, cmd_random, cmd_passwd, cmd_checkpin, cmd_lock) (cmd_unlock, cmd_getinfo, cmd_restart, cmd_disconnect, cmd_apdu) (cmd_killscd): Return gpg_error_t instead of int. (scd_command_handler): Allocate assuan context before starting server. * scdaemon.c (main): Update to new Assuan API. sm/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * gpgsm.c (main): Update to new assuan API. * server.c: Include "gpgsm.h" before <assuan.h> due to check for GPG_ERR_SOURCE_DEFAULT and assuan.h now including gpg-error.h. (option_handler, cmd_recipient, cmd_signer, cmd_encrypt) (cmd_decrypt, cmd_verify, cmd_sign, cmd_import, cmd_export) (cmd_delkeys, cmd_message, cmd_listkeys, cmd_dumpkeys) (cmd_listsecretkeys, cmd_dumpsecretkeys, cmd_genkey) (cmd_getauditlog, cmd_getinfo): Return gpg_error_t instead of int. (register_commands): Same for member HANDLER in table. (gpgsm_server): Allocate assuan context before starting server. * sm/call-dirmngr.c: * call-dirmngr.c (prepare_dirmngr): Check for CTX and error before setting LDAPSERVER. (start_dirmngr_ext): Allocate assuan context before starting server. (inq_certificate, isvalid_status_cb, lookup_cb, lookup_status_cb) (run_command_cb, run_command_inq_cb, run_command_status_cb): Return gpg_error_t instead of int. tools/ 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * gpg-connect-agent.c (getinfo_pid_cb, read_and_print_response) (main): Update to new Assuan API. Conflicts: ChangeLog agent/ChangeLog agent/command.c common/ChangeLog g10/ChangeLog scd/ChangeLog sm/ChangeLog sm/gpgsm.c tools/ChangeLog Somehow this slipped through. Really commit this time. 2009-09-23 Marcus Brinkmann <marcus@g10code.de> * gpg-connect-agent.c (getinfo_pid_cb, read_and_print_response) (main): Update to new Assuan API. 2009-10-16 Marcus Brinkmann <marcus@g10code.com> * configure.ac: Check for libassuan instead of libassuan-pth. common/ 2009-10-16 Marcus Brinkmann <marcus@g10code.com> * Makefile.am (libcommon_a_CFLAGS): Use LIBASSUAN_CFLAGS instead of LIBASSUAN_PTH_CFLAGS. scd/ 2009-10-16 Marcus Brinkmann <marcus@g10code.com> * AM_CFLAGS, scdaemon_LDADD: Use libassuan instead of libassuan-pth. * scdaemon.c: Invoke ASSUAN_SYSTEM_PTH_IMPL. (main): Call assuan_set_system_hooks and assuan_sock_init. g13/ 2009-10-16 Marcus Brinkmann <marcus@g10code.com> * AM_CFLAGS, g13_LDADD: Use libassuan instead of libassuan-pth. * g13.c: Invoke ASSUAN_SYSTEM_PTH_IMPL. (main): Call assuan_set_system_hooks. agent/ 2009-10-16 Marcus Brinkmann <marcus@g10code.com> * gpg_agent_CFLAGS, gpg_agent_LDADD: Use libassuan instead of libassuan-pth. * gpg-agent.c: Invoke ASSUAN_SYSTEM_PTH_IMPL. (main): Call assuan_set_system_hooks and assuan_sock_init. Fix invocation of assuan_socket_connect. Conflicts: ChangeLog agent/ChangeLog common/ChangeLog configure.ac g13/ChangeLog g13/Makefile.am g13/g13.c scd/ChangeLog agent/ 2009-11-02 Marcus Brinkmann <marcus@g10code.de> * command.c (reset_notify): Take LINE arg and return error. (register_commands): Use assuan_handler_t type. common/ 2009-11-02 Marcus Brinkmann <marcus@g10code.de> * get-passphrase.c (default_inq_cb, membuf_data_cb): Change return type to gpg_error_t. g10/ 2009-11-02 Marcus Brinkmann <marcus@g10code.de> * server.c (reset_notify, input_notify, output_notify): Update to new assuan interface. (register_commands): Use assuan_handler_t. scd/ 2009-11-02 Marcus Brinkmann <marcus@g10code.de> * command.c (reset_notify): Take LINE arg and return error. (register_commands): Use assuan_handler_t type. sm/ 2009-11-02 Marcus Brinkmann <marcus@g10code.de> * server.c (reset_notify, input_notify, output_notify): Update to new assuan interface. (register_commands): Use assuan_handler_t. * call-agent.c (membuf_data_cb, default_inq_cb) (inq_ciphertext_cb, scd_serialno_status_cb) (scd_keypairinfo_status_cb, istrusted_status_cb) (learn_status_cb, learn_cb, keyinfo_status_cb): Return gpg_error_t. Conflicts: agent/ChangeLog common/ChangeLog g10/ChangeLog g10/server.c g13/ChangeLog g13/server.c scd/ChangeLog sm/ChangeLog Adjust for assuan_register_command change. Conflicts: agent/ChangeLog g10/ChangeLog g13/ChangeLog g13/server.c scd/ChangeLog sm/ChangeLog Add hack for the HELP command. Conflicts: tools/ChangeLog Add help strings for all commands. Conflicts: agent/ChangeLog agent/command.c Add help strings for all commands. Conflicts: scd/ChangeLog Add help strings for all commands Conflicts: sm/ChangeLog agent/ 2009-11-05 Marcus Brinkmann <marcus@g10code.de> * call-pinentry.c (start_pinentry): Call assuan_pipe_connect, not assuan_pipe_connect_ext. * command.c (start_command_handler): Change assuan_init_socket_server_ext into assuan_init_socket_server. * call-scd.c (start_scd): Update use of assuan_socket_connect and assuan_pipe_connect. * gpg-agent.c (check_own_socket_thread, check_for_running_agent): Update use of assuan_socket_connect. common/ 2009-11-05 Marcus Brinkmann <marcus@g10code.de> * asshelp.c (start_new_gpg_agent): Update use of assuan_socket_connect and assuan_pipe_connect. scd/ 2009-11-05 Marcus Brinkmann <marcus@g10code.de> * command.c (scd_command_handler): Call assuan_init_socket_server, not assuan_init_socket_server_ext. sm/ 2009-11-05 Marcus Brinkmann <marcus@g10code.de> * call-dirmngr.c (start_dirmngr_ext): Update use of assuan_pipe_connect and assuan_socket_connect. tools/ 2009-11-05 Marcus Brinkmann <marcus@g10code.de> * gpg-connect-agent.c (start_agent): Update use of assuan_socket_connect and assuan_pipe_connect. Conflicts: agent/ChangeLog common/ChangeLog g13/ChangeLog g13/call-gpg.c scd/ChangeLog sm/ChangeLog tools/ChangeLog agent/ 2009-11-25 Marcus Brinkmann <marcus@g10code.de> * command.c (start_command_handler): Use assuan_fd_t and assuan_fdopen on fds. scd/ 2009-11-25 Marcus Brinkmann <marcus@g10code.de> * command.c (scd_command_handler): Use assuan_fd_t and assuan_fdopen on fds. sm/ 2009-11-25 Marcus Brinkmann <marcus@g10code.de> * server.c (gpgsm_server): Use assuan_fd_t and assuan_fdopen on fds. g10/ 2009-11-25 Marcus Brinkmann <marcus@g10code.de> * server.c (gpg_server): Use assuan_fd_t and assuan_fdopen on fds. Conflicts: agent/ChangeLog g10/ChangeLog g13/server.c scd/ChangeLog sm/ChangeLog 2009-11-27 Marcus Brinkmann <marcus@g10code.de> * command.c (start_command_handler): Do not call assuan_set_log_stream anymore. * gpg-agent.c (main): But call assuan_set_assuan_log_stream here. Conflicts: agent/ChangeLog agent/command.c 2009-12-08 Marcus Brinkmann <marcus@g10code.de> * asshelp.c (start_new_gpg_agent) [HAVE_W32_SYSTEM]: Add missing argument in assuan_socket_connect invocation. * iobuf.c (iobuf_open_fd_or_name): Fix type of FD in function declaration. Conflicts: common/ChangeLog common/iobuf.c common/ 2009-12-08 Marcus Brinkmann <marcus@g10code.de> * asshelp.c (start_new_gpg_agent): Convert posix FD to assuan FD. agent/ 2009-12-08 Marcus Brinkmann <marcus@g10code.de> * call-pinentry.c (start_pinentry): Convert posix fd to assuan fd. * call-scd.c (start_scd): Likewise. sm/ 2009-12-08 Marcus Brinkmann <marcus@g10code.de> * call-dirmngr.c (start_dirmngr_ext): Convert posix fd to assuan fd. tools/ 2009-12-08 Marcus Brinkmann <marcus@g10code.de> * gpg-connect-agent.c (main): Convert posix fd to assuan fd. Conflicts: agent/ChangeLog common/ChangeLog g13/call-gpg.c sm/ChangeLog tools/ChangeLog
263 lines
7.8 KiB
C
263 lines
7.8 KiB
C
/* get-passphrase.c - Ask for a passphrase via the agent
|
|
* Copyright (C) 2009 Free Software Foundation, Inc.
|
|
*
|
|
* This file is part of GnuPG.
|
|
*
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, see <http://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
#include <config.h>
|
|
#include <stdio.h>
|
|
#include <stdlib.h>
|
|
#include <string.h>
|
|
#include <assert.h>
|
|
#include <assuan.h>
|
|
|
|
#include "util.h"
|
|
#include "i18n.h"
|
|
#include "asshelp.h"
|
|
#include "membuf.h"
|
|
#include "sysutils.h"
|
|
#include "get-passphrase.h"
|
|
|
|
/* The context used by this process to ask for the passphrase. */
|
|
static assuan_context_t agent_ctx;
|
|
static struct
|
|
{
|
|
gpg_err_source_t errsource;
|
|
int verbosity;
|
|
const char *homedir;
|
|
const char *agent_program;
|
|
const char *lc_ctype;
|
|
const char *lc_messages;
|
|
session_env_t session_env;
|
|
const char *pinentry_user_data;
|
|
} agentargs;
|
|
|
|
|
|
/* Set local variable to be used for a possible agent startup. Note
|
|
that the strings are just pointers and should not anymore be
|
|
modified by the caller. */
|
|
void
|
|
gnupg_prepare_get_passphrase (gpg_err_source_t errsource,
|
|
int verbosity,
|
|
const char *homedir,
|
|
const char *agent_program,
|
|
const char *opt_lc_ctype,
|
|
const char *opt_lc_messages,
|
|
session_env_t session_env)
|
|
{
|
|
agentargs.errsource = errsource;
|
|
agentargs.verbosity = verbosity;
|
|
agentargs.homedir = homedir;
|
|
agentargs.agent_program = agent_program;
|
|
agentargs.lc_ctype = opt_lc_ctype;
|
|
agentargs.lc_messages = opt_lc_messages;
|
|
agentargs.session_env = session_env;
|
|
}
|
|
|
|
|
|
/* Try to connect to the agent via socket or fork it off and work by
|
|
pipes. Handle the server's initial greeting. */
|
|
static gpg_error_t
|
|
start_agent (void)
|
|
{
|
|
gpg_error_t err;
|
|
|
|
/* Fixme: This code is not thread safe, thus we don't build it with
|
|
pth. We will need a context for each thread or serialize the
|
|
access to the agent. */
|
|
if (agent_ctx)
|
|
return 0;
|
|
|
|
err = start_new_gpg_agent (&agent_ctx,
|
|
agentargs.errsource,
|
|
agentargs.homedir,
|
|
agentargs.agent_program,
|
|
agentargs.lc_ctype,
|
|
agentargs.lc_messages,
|
|
agentargs.session_env,
|
|
agentargs.verbosity, 0, NULL, NULL);
|
|
if (!err)
|
|
{
|
|
/* Tell the agent that we support Pinentry notifications. No
|
|
error checking so that it will work with older agents. */
|
|
assuan_transact (agent_ctx, "OPTION allow-pinentry-notify",
|
|
NULL, NULL, NULL, NULL, NULL, NULL);
|
|
}
|
|
|
|
return err;
|
|
}
|
|
|
|
|
|
/* This is the default inquiry callback. It merely handles the
|
|
Pinentry notification. */
|
|
static gpg_error_t
|
|
default_inq_cb (void *opaque, const char *line)
|
|
{
|
|
(void)opaque;
|
|
|
|
if (!strncmp (line, "PINENTRY_LAUNCHED", 17) && (line[17]==' '||!line[17]))
|
|
{
|
|
gnupg_allow_set_foregound_window ((pid_t)strtoul (line+17, NULL, 10));
|
|
/* We do not return errors to avoid breaking other code. */
|
|
}
|
|
else
|
|
log_debug ("ignoring gpg-agent inquiry `%s'\n", line);
|
|
|
|
return 0;
|
|
}
|
|
|
|
|
|
static gpg_error_t
|
|
membuf_data_cb (void *opaque, const void *buffer, size_t length)
|
|
{
|
|
membuf_t *data = opaque;
|
|
|
|
if (buffer)
|
|
put_membuf (data, buffer, length);
|
|
return 0;
|
|
}
|
|
|
|
|
|
/* Ask for a passphrase via gpg-agent. On success the caller needs to
|
|
free the string stored at R_PASSPHRASE. On error NULL will be
|
|
stored at R_PASSPHRASE and an appropriate gpg error code is
|
|
returned. With REPEAT set to 1, gpg-agent will ask the user to
|
|
repeat the just entered passphrase. CACHE_ID is a gpg-agent style
|
|
passphrase cache id or NULL. ERR_MSG is a error message to be
|
|
presented to the user (e.g. "bad passphrase - try again") or NULL.
|
|
PROMPT is the prompt string to label the entry box, it may be NULL
|
|
for a default one. DESC_MSG is a longer description to be
|
|
displayed above the entry box, if may be NULL for a default one.
|
|
If USE_SECMEM is true, the returned passphrase is retruned in
|
|
secure memory. The length of all these strings is limited; they
|
|
need to fit in their encoded form into a standard Assuan line (i.e
|
|
less then about 950 characters). All strings shall be UTF-8. */
|
|
gpg_error_t
|
|
gnupg_get_passphrase (const char *cache_id,
|
|
const char *err_msg,
|
|
const char *prompt,
|
|
const char *desc_msg,
|
|
int repeat,
|
|
int check_quality,
|
|
int use_secmem,
|
|
char **r_passphrase)
|
|
{
|
|
gpg_error_t err;
|
|
char line[ASSUAN_LINELENGTH];
|
|
const char *arg1 = NULL;
|
|
char *arg2 = NULL;
|
|
char *arg3 = NULL;
|
|
char *arg4 = NULL;
|
|
membuf_t data;
|
|
|
|
*r_passphrase = NULL;
|
|
|
|
err = start_agent ();
|
|
if (err)
|
|
return err;
|
|
|
|
/* Check that the gpg-agent understands the repeat option. */
|
|
if (assuan_transact (agent_ctx,
|
|
"GETINFO cmd_has_option GET_PASSPHRASE repeat",
|
|
NULL, NULL, NULL, NULL, NULL, NULL))
|
|
return gpg_error (GPG_ERR_NOT_SUPPORTED);
|
|
|
|
arg1 = cache_id && *cache_id? cache_id:NULL;
|
|
if (err_msg && *err_msg)
|
|
if (!(arg2 = percent_plus_escape (err_msg)))
|
|
goto no_mem;
|
|
if (prompt && *prompt)
|
|
if (!(arg3 = percent_plus_escape (prompt)))
|
|
goto no_mem;
|
|
if (desc_msg && *desc_msg)
|
|
if (!(arg4 = percent_plus_escape (desc_msg)))
|
|
goto no_mem;
|
|
|
|
snprintf (line, DIM(line)-1,
|
|
"GET_PASSPHRASE --data %s--repeat=%d -- %s %s %s %s",
|
|
check_quality? "--check ":"",
|
|
repeat,
|
|
arg1? arg1:"X",
|
|
arg2? arg2:"X",
|
|
arg3? arg3:"X",
|
|
arg4? arg4:"X");
|
|
line[DIM(line)-1] = 0;
|
|
xfree (arg2);
|
|
xfree (arg3);
|
|
xfree (arg4);
|
|
|
|
if (use_secmem)
|
|
init_membuf_secure (&data, 64);
|
|
else
|
|
init_membuf (&data, 64);
|
|
err = assuan_transact (agent_ctx, line,
|
|
membuf_data_cb, &data,
|
|
default_inq_cb, NULL, NULL, NULL);
|
|
|
|
/* Older Pinentries return the old assuan error code for canceled
|
|
which gets translated bt libassuan to GPG_ERR_ASS_CANCELED and
|
|
not to the code for a user cancel. Fix this here. */
|
|
if (err && gpg_err_source (err)
|
|
&& gpg_err_code (err) == GPG_ERR_ASS_CANCELED)
|
|
err = gpg_err_make (gpg_err_source (err), GPG_ERR_CANCELED);
|
|
|
|
if (err)
|
|
{
|
|
void *p;
|
|
size_t n;
|
|
|
|
p = get_membuf (&data, &n);
|
|
if (p)
|
|
wipememory (p, n);
|
|
xfree (p);
|
|
}
|
|
else
|
|
{
|
|
put_membuf (&data, "", 1);
|
|
*r_passphrase = get_membuf (&data, NULL);
|
|
if (!*r_passphrase)
|
|
err = gpg_error_from_syserror ();
|
|
}
|
|
return err;
|
|
no_mem:
|
|
err = gpg_error_from_syserror ();
|
|
xfree (arg2);
|
|
xfree (arg3);
|
|
xfree (arg4);
|
|
return err;
|
|
}
|
|
|
|
|
|
/* Flush the passphrase cache with Id CACHE_ID. */
|
|
gpg_error_t
|
|
gnupg_clear_passphrase (const char *cache_id)
|
|
{
|
|
gpg_error_t err;
|
|
char line[ASSUAN_LINELENGTH];
|
|
|
|
if (!cache_id || !*cache_id)
|
|
return 0;
|
|
|
|
err = start_agent ();
|
|
if (err)
|
|
return err;
|
|
|
|
snprintf (line, DIM(line)-1, "CLEAR_PASSPHRASE %s", cache_id);
|
|
line[DIM(line)-1] = 0;
|
|
return assuan_transact (agent_ctx, line, NULL, NULL,
|
|
default_inq_cb, NULL, NULL, NULL);
|
|
}
|