diff options
| author | Werner Koch <[email protected]> | 2017-03-24 13:36:54 +0000 | 
|---|---|---|
| committer | Werner Koch <[email protected]> | 2017-03-24 14:17:23 +0000 | 
| commit | 6ac1f2cdedb085b4ac9372c1e591497e2e618de4 (patch) | |
| tree | e022c038fd965e40e4d7a9a4db6015a86d0e60a5 /src/decrypt-verify.c | |
| parent | qt: Add test for Data::toKeys (diff) | |
| download | gpgme-6ac1f2cdedb085b4ac9372c1e591497e2e618de4.tar.gz gpgme-6ac1f2cdedb085b4ac9372c1e591497e2e618de4.zip | |
core: New flags GPGME_DECRYPT_UNWRAP and GPGME_ENCRYPT_WRAP.
* src/gpgme.h.in (GPGME_ENCRYPT_WRAP): New const.
(gpgme_decrypt_flags_t): New enum.
(GPGME_DECRYPT_VERIFY): New const
(GPGME_DECRYPT_UNWRAP): New const
(gpgme_op_decrypt_ext_start): New func.
(gpgme_op_decrypt_ext): New func.
* src/decrypt-verify.c (gpgme_op_decrypt_ext_start): New.
(gpgme_op_decrypt_ext): New.
(decrypt_verify_start): Add arg FLAGS.  Replace call to
engine_op_decrypt_verify by the plain decrypt with the flag set.
(gpgme_op_decrypt_verify_start): Pass the flag.
(gpgme_op_decrypt_verify): Pass the flag.
* src/decrypt.c (decrypt_start): Rename to ...
(_gpgme_decrypt_start): this.  Add arg FLAGS.  Pass FLAGS to
engine_op_decrypt.
(gpgme_op_decrypt_start): Adjust for chnage pass 0 for FLAG.
(gpgme_op_decrypt_start): Ditto.
* src/engine.c (_gpgme_engine_op_decrypt_verify): Remove.
(_gpgme_engine_op_decrypt): Add arg FLAGS.
* src/gpgme.def, src/libgpgme.vers: Add new functions.
* src/engine-backend.h (struct engine_ops): Remove member
'decrypt_verify'.  Add FLAGS to 'decrypt'.  Adjust all initialization.
* src/engine-uiserver.c (uiserver_decrypt): Remove.
(uiserver_decrypt_verify): Remove.
(_uiserver_decrypt): Rename to ...
(uiserver_decrypt): this.  Replace arg VERIFY by new arg FLAGS.
* src/engine-gpg.c (gpg_decrypt): Support GPGME_DECRYPT_UNWRAP.
(gpg_encrypt): Support GPGME_ENCRYPT_WRAP.
* tests/run-decrypt.c (main): New option --unwrap.
* tests/run-encrypt.c (main): New option --wrap.
--
Manual testing of that wrap/unwrap feature can be done this way:
 ./run-encrypt --verbose --key Alice /etc/motd > x
 ./run-decrypt --verbose --unwrap x > y
 ./run-encrypt --verbose --key Bob --wrap y > z
1. The message was first encrypted to Alice.
2. Alice decrypts the message receiving a valid OpenPGP message.
3. Alice encrypt that message to Bob
This will also work with encrypted and signed messages; the signature
will be kept intact during re-encryption.  Requires GnuPG 2.1.12.
Signed-off-by: Werner Koch <[email protected]>
Diffstat (limited to 'src/decrypt-verify.c')
| -rw-r--r-- | src/decrypt-verify.c | 67 | 
1 files changed, 62 insertions, 5 deletions
| diff --git a/src/decrypt-verify.c b/src/decrypt-verify.c index e0aa8ea9..66cfe94f 100644 --- a/src/decrypt-verify.c +++ b/src/decrypt-verify.c @@ -23,6 +23,8 @@  #include <config.h>  #endif +#include <assert.h> +  #include "debug.h"  #include "gpgme.h"  #include "ops.h" @@ -45,10 +47,13 @@ decrypt_verify_status_handler (void *priv, gpgme_status_code_t code,  static gpgme_error_t  decrypt_verify_start (gpgme_ctx_t ctx, int synchronous, +                      gpgme_decrypt_flags_t flags,  		      gpgme_data_t cipher, gpgme_data_t plain)  {    gpgme_error_t err; +  assert ((flags & GPGME_DECRYPT_VERIFY)); +    err = _gpgme_op_reset (ctx, synchronous);    if (err)      return err; @@ -77,9 +82,11 @@ decrypt_verify_start (gpgme_ctx_t ctx, int synchronous,    _gpgme_engine_set_status_handler (ctx->engine,  				    decrypt_verify_status_handler, ctx); -  return _gpgme_engine_op_decrypt_verify (ctx->engine, cipher, plain, -                                          ctx->export_session_keys, -                                          ctx->override_session_key); +  return _gpgme_engine_op_decrypt (ctx->engine, +                                   flags, +                                   cipher, plain, +                                   ctx->export_session_keys, +                                   ctx->override_session_key);  } @@ -97,7 +104,7 @@ gpgme_op_decrypt_verify_start (gpgme_ctx_t ctx, gpgme_data_t cipher,    if (!ctx)      return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE)); -  err = decrypt_verify_start (ctx, 0, cipher, plain); +  err = decrypt_verify_start (ctx, 0, GPGME_DECRYPT_VERIFY, cipher, plain);    return TRACE_ERR (err);  } @@ -116,7 +123,57 @@ gpgme_op_decrypt_verify (gpgme_ctx_t ctx, gpgme_data_t cipher,    if (!ctx)      return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE)); -  err = decrypt_verify_start (ctx, 1, cipher, plain); +  err = decrypt_verify_start (ctx, 1, GPGME_DECRYPT_VERIFY, cipher, plain); +  if (!err) +    err = _gpgme_wait_one (ctx); +  return TRACE_ERR (err); +} + + +/* Decrypt ciphertext CIPHER within CTX and store the resulting +   plaintext in PLAIN.  */ +gpgme_error_t +gpgme_op_decrypt_ext_start (gpgme_ctx_t ctx, +                            gpgme_decrypt_flags_t flags, +                            gpgme_data_t cipher, +                            gpgme_data_t plain) +{ +  gpgme_error_t err; + +  TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_ext_start", ctx, +	      "cipher=%p, plain=%p", cipher, plain); + +  if (!ctx) +    return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE)); + +  if ((flags & GPGME_DECRYPT_VERIFY)) +    err = decrypt_verify_start (ctx, 0, flags, cipher, plain); +  else +    err = _gpgme_decrypt_start (ctx, 0, flags, cipher, plain); +  return TRACE_ERR (err); +} + + +/* Decrypt ciphertext CIPHER within CTX and store the resulting +   plaintext in PLAIN.  */ +gpgme_error_t +gpgme_op_decrypt_ext (gpgme_ctx_t ctx, +                      gpgme_decrypt_flags_t flags, +                      gpgme_data_t cipher, +                      gpgme_data_t plain) +{ +  gpgme_error_t err; + +  TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_ext", ctx, +	      "cipher=%p, plain=%p", cipher, plain); + +  if (!ctx) +    return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE)); + +  if ((flags & GPGME_DECRYPT_VERIFY)) +    err = decrypt_verify_start (ctx, 1, flags, cipher, plain); +  else +    err = _gpgme_decrypt_start (ctx, 1, flags, cipher, plain);    if (!err)      err = _gpgme_wait_one (ctx);    return TRACE_ERR (err); | 
