mirror of
git://git.gnupg.org/gnupg.git
synced 2024-11-04 20:38:50 +01:00
ec332d58ef
* kbx/keybox-defs.h (struct keybox_handle): Add field for_openpgp. * kbx/keybox-file.c (_keybox_write_header_blob): Set openpgp header flag. * kbx/keybox-blob.c (_keybox_update_header_blob): Add arg for_openpgp and set header flag. * kbx/keybox-init.c (keybox_new): Rename to do_keybox_new, make static and add arg for_openpgp. (keybox_new_openpgp, keybox_new_x509): New. Use them instead of the former keybox_new. * kbx/keybox-update.c (blob_filecopy): Add arg for_openpgp and set the openpgp header flags. * g10/keydb.c (rt_from_file): New. Factored out and extended from keydb_add_resource. (keydb_add_resource): Switch to the kbx file if it has the openpgp flag set. * kbx/keybox-dump.c (dump_header_blob): Print header flags. -- The problem was reported by dkg on gnupg-devel (2014-10-07): I just discovered a new problem, though, which will affect people on systems that have gpg and gpg2 coinstalled: 0) create a new keyring with gpg2, and use it exclusively with gpg2 for a while. 1) somehow (accidentally?) use gpg (1.4.x) again -- this creates ~/.gnupg/pubring.gpg 2) future runs of gpg2 now only look at pubring.gpg and ignore pubring.kbx -- the keys you had accumulated in the keybox are no longer listed in the output of gpg2 --list-keys Note that gpgsm has always used pubring.kbx and thus this file might already be there but without gpg ever inserted a key. The new flag in the KBX header gives us an indication whether a KBX file has ever been written by gpg >= 2.1. If that is the case we will use it instead of the default pubring.gpg. Signed-off-by: Werner Koch <wk@gnupg.org>
270 lines
6.5 KiB
C
270 lines
6.5 KiB
C
/* keybox-init.c - Initalization of the library
|
|
* Copyright (C) 2001 Free Software Foundation, Inc.
|
|
*
|
|
* This file is part of GnuPG.
|
|
*
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, see <http://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
#include <config.h>
|
|
#include <stdlib.h>
|
|
#include <stdio.h>
|
|
#include <string.h>
|
|
#include <unistd.h>
|
|
#include <assert.h>
|
|
|
|
#include "../common/mischelp.h"
|
|
#include "keybox-defs.h"
|
|
|
|
static KB_NAME kb_names;
|
|
|
|
|
|
/* Register a filename for plain keybox files. Returns a pointer to
|
|
be used to create a handles and so on. Returns NULL to indicate
|
|
that FNAME has already been registered. */
|
|
void *
|
|
keybox_register_file (const char *fname, int secret)
|
|
{
|
|
KB_NAME kr;
|
|
|
|
for (kr=kb_names; kr; kr = kr->next)
|
|
{
|
|
if (same_file_p (kr->fname, fname) )
|
|
return NULL; /* Already registered. */
|
|
}
|
|
|
|
kr = xtrymalloc (sizeof *kr + strlen (fname));
|
|
if (!kr)
|
|
return NULL;
|
|
strcpy (kr->fname, fname);
|
|
kr->secret = !!secret;
|
|
|
|
kr->handle_table = NULL;
|
|
kr->handle_table_size = 0;
|
|
|
|
/* kr->lockhd = NULL;*/
|
|
kr->is_locked = 0;
|
|
kr->did_full_scan = 0;
|
|
/* keep a list of all issued pointers */
|
|
kr->next = kb_names;
|
|
kb_names = kr;
|
|
|
|
/* create the offset table the first time a function here is used */
|
|
/* if (!kb_offtbl) */
|
|
/* kb_offtbl = new_offset_hash_table (); */
|
|
|
|
return kr;
|
|
}
|
|
|
|
int
|
|
keybox_is_writable (void *token)
|
|
{
|
|
KB_NAME r = token;
|
|
|
|
return r? !access (r->fname, W_OK) : 0;
|
|
}
|
|
|
|
|
|
|
|
static KEYBOX_HANDLE
|
|
do_keybox_new (KB_NAME resource, int secret, int for_openpgp)
|
|
{
|
|
KEYBOX_HANDLE hd;
|
|
int idx;
|
|
|
|
assert (resource && !resource->secret == !secret);
|
|
hd = xtrycalloc (1, sizeof *hd);
|
|
if (hd)
|
|
{
|
|
hd->kb = resource;
|
|
hd->secret = !!secret;
|
|
hd->for_openpgp = for_openpgp;
|
|
if (!resource->handle_table)
|
|
{
|
|
resource->handle_table_size = 3;
|
|
resource->handle_table = xtrycalloc (resource->handle_table_size,
|
|
sizeof *resource->handle_table);
|
|
if (!resource->handle_table)
|
|
{
|
|
resource->handle_table_size = 0;
|
|
xfree (hd);
|
|
return NULL;
|
|
}
|
|
}
|
|
for (idx=0; idx < resource->handle_table_size; idx++)
|
|
if (!resource->handle_table[idx])
|
|
{
|
|
resource->handle_table[idx] = hd;
|
|
break;
|
|
}
|
|
if (!(idx < resource->handle_table_size))
|
|
{
|
|
KEYBOX_HANDLE *tmptbl;
|
|
size_t newsize;
|
|
|
|
newsize = resource->handle_table_size + 5;
|
|
tmptbl = xtryrealloc (resource->handle_table,
|
|
newsize * sizeof (*tmptbl));
|
|
if (!tmptbl)
|
|
{
|
|
xfree (hd);
|
|
return NULL;
|
|
}
|
|
resource->handle_table = tmptbl;
|
|
resource->handle_table_size = newsize;
|
|
resource->handle_table[idx] = hd;
|
|
for (idx++; idx < resource->handle_table_size; idx++)
|
|
resource->handle_table[idx] = NULL;
|
|
}
|
|
}
|
|
return hd;
|
|
}
|
|
|
|
|
|
/* Create a new handle for the resource associated with TOKEN. SECRET
|
|
is just a cross-check. This is the OpenPGP version. The returned
|
|
handle must be released using keybox_release. */
|
|
KEYBOX_HANDLE
|
|
keybox_new_openpgp (void *token, int secret)
|
|
{
|
|
KB_NAME resource = token;
|
|
|
|
return do_keybox_new (resource, secret, 1);
|
|
}
|
|
|
|
/* Create a new handle for the resource associated with TOKEN. SECRET
|
|
is just a cross-check. This is the X.509 version. The returned
|
|
handle must be released using keybox_release. */
|
|
KEYBOX_HANDLE
|
|
keybox_new_x509 (void *token, int secret)
|
|
{
|
|
KB_NAME resource = token;
|
|
|
|
return do_keybox_new (resource, secret, 0);
|
|
}
|
|
|
|
|
|
void
|
|
keybox_release (KEYBOX_HANDLE hd)
|
|
{
|
|
if (!hd)
|
|
return;
|
|
if (hd->kb->handle_table)
|
|
{
|
|
int idx;
|
|
for (idx=0; idx < hd->kb->handle_table_size; idx++)
|
|
if (hd->kb->handle_table[idx] == hd)
|
|
hd->kb->handle_table[idx] = NULL;
|
|
}
|
|
_keybox_release_blob (hd->found.blob);
|
|
_keybox_release_blob (hd->saved_found.blob);
|
|
if (hd->fp)
|
|
{
|
|
fclose (hd->fp);
|
|
hd->fp = NULL;
|
|
}
|
|
xfree (hd->word_match.name);
|
|
xfree (hd->word_match.pattern);
|
|
xfree (hd);
|
|
}
|
|
|
|
|
|
/* Save the current found state in HD for later retrieval by
|
|
keybox_restore_found_state. Only one state may be saved. */
|
|
void
|
|
keybox_push_found_state (KEYBOX_HANDLE hd)
|
|
{
|
|
if (hd->saved_found.blob)
|
|
{
|
|
_keybox_release_blob (hd->saved_found.blob);
|
|
hd->saved_found.blob = NULL;
|
|
}
|
|
hd->saved_found = hd->found;
|
|
hd->found.blob = NULL;
|
|
}
|
|
|
|
|
|
/* Restore the saved found state in HD. */
|
|
void
|
|
keybox_pop_found_state (KEYBOX_HANDLE hd)
|
|
{
|
|
if (hd->found.blob)
|
|
{
|
|
_keybox_release_blob (hd->found.blob);
|
|
hd->found.blob = NULL;
|
|
}
|
|
hd->found = hd->saved_found;
|
|
hd->saved_found.blob = NULL;
|
|
}
|
|
|
|
|
|
const char *
|
|
keybox_get_resource_name (KEYBOX_HANDLE hd)
|
|
{
|
|
if (!hd || !hd->kb)
|
|
return NULL;
|
|
return hd->kb->fname;
|
|
}
|
|
|
|
int
|
|
keybox_set_ephemeral (KEYBOX_HANDLE hd, int yes)
|
|
{
|
|
if (!hd)
|
|
return gpg_error (GPG_ERR_INV_HANDLE);
|
|
hd->ephemeral = yes;
|
|
return 0;
|
|
}
|
|
|
|
|
|
/* Close the file of the resource identified by HD. For consistent
|
|
results this fucntion closes the files of all handles pointing to
|
|
the resource identified by HD. */
|
|
void
|
|
_keybox_close_file (KEYBOX_HANDLE hd)
|
|
{
|
|
int idx;
|
|
KEYBOX_HANDLE roverhd;
|
|
|
|
if (!hd || !hd->kb || !hd->kb->handle_table)
|
|
return;
|
|
|
|
for (idx=0; idx < hd->kb->handle_table_size; idx++)
|
|
if ((roverhd = hd->kb->handle_table[idx]))
|
|
{
|
|
if (roverhd->fp)
|
|
{
|
|
fclose (roverhd->fp);
|
|
roverhd->fp = NULL;
|
|
}
|
|
}
|
|
assert (!hd->fp);
|
|
}
|
|
|
|
|
|
/*
|
|
* Lock the keybox at handle HD, or unlock if YES is false. Note that
|
|
* we currently ignore the handle and lock all registered keyboxes.
|
|
*/
|
|
int
|
|
keybox_lock (KEYBOX_HANDLE hd, int yes)
|
|
{
|
|
/* FIXME: We need to implement it before we can use it with gpg.
|
|
gpgsm does the locking in its local keydb.c driver; this should
|
|
be changed as well. */
|
|
|
|
(void)hd;
|
|
(void)yes;
|
|
return 0;
|
|
}
|