6ac1f2cded
* src/gpgme.h.in (GPGME_ENCRYPT_WRAP): New const. (gpgme_decrypt_flags_t): New enum. (GPGME_DECRYPT_VERIFY): New const (GPGME_DECRYPT_UNWRAP): New const (gpgme_op_decrypt_ext_start): New func. (gpgme_op_decrypt_ext): New func. * src/decrypt-verify.c (gpgme_op_decrypt_ext_start): New. (gpgme_op_decrypt_ext): New. (decrypt_verify_start): Add arg FLAGS. Replace call to engine_op_decrypt_verify by the plain decrypt with the flag set. (gpgme_op_decrypt_verify_start): Pass the flag. (gpgme_op_decrypt_verify): Pass the flag. * src/decrypt.c (decrypt_start): Rename to ... (_gpgme_decrypt_start): this. Add arg FLAGS. Pass FLAGS to engine_op_decrypt. (gpgme_op_decrypt_start): Adjust for chnage pass 0 for FLAG. (gpgme_op_decrypt_start): Ditto. * src/engine.c (_gpgme_engine_op_decrypt_verify): Remove. (_gpgme_engine_op_decrypt): Add arg FLAGS. * src/gpgme.def, src/libgpgme.vers: Add new functions. * src/engine-backend.h (struct engine_ops): Remove member 'decrypt_verify'. Add FLAGS to 'decrypt'. Adjust all initialization. * src/engine-uiserver.c (uiserver_decrypt): Remove. (uiserver_decrypt_verify): Remove. (_uiserver_decrypt): Rename to ... (uiserver_decrypt): this. Replace arg VERIFY by new arg FLAGS. * src/engine-gpg.c (gpg_decrypt): Support GPGME_DECRYPT_UNWRAP. (gpg_encrypt): Support GPGME_ENCRYPT_WRAP. * tests/run-decrypt.c (main): New option --unwrap. * tests/run-encrypt.c (main): New option --wrap. -- Manual testing of that wrap/unwrap feature can be done this way: ./run-encrypt --verbose --key Alice /etc/motd > x ./run-decrypt --verbose --unwrap x > y ./run-encrypt --verbose --key Bob --wrap y > z 1. The message was first encrypted to Alice. 2. Alice decrypts the message receiving a valid OpenPGP message. 3. Alice encrypt that message to Bob This will also work with encrypted and signed messages; the signature will be kept intact during re-encryption. Requires GnuPG 2.1.12. Signed-off-by: Werner Koch <wk@gnupg.org>
181 lines
4.9 KiB
C
181 lines
4.9 KiB
C
/* decrypt-verify.c - Decrypt and verify function.
|
||
Copyright (C) 2000 Werner Koch (dd9jn)
|
||
Copyright (C) 2001, 2002, 2003, 2004 g10 Code GmbH
|
||
|
||
This file is part of GPGME.
|
||
|
||
GPGME is free software; you can redistribute it and/or modify it
|
||
under the terms of the GNU Lesser General Public License as
|
||
published by the Free Software Foundation; either version 2.1 of
|
||
the License, or (at your option) any later version.
|
||
|
||
GPGME is distributed in the hope that it will be useful, but
|
||
WITHOUT ANY WARRANTY; without even the implied warranty of
|
||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||
Lesser General Public License for more details.
|
||
|
||
You should have received a copy of the GNU Lesser General Public
|
||
License along with this program; if not, write to the Free Software
|
||
Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
|
||
02111-1307, USA. */
|
||
|
||
#if HAVE_CONFIG_H
|
||
#include <config.h>
|
||
#endif
|
||
|
||
#include <assert.h>
|
||
|
||
#include "debug.h"
|
||
#include "gpgme.h"
|
||
#include "ops.h"
|
||
|
||
|
||
static gpgme_error_t
|
||
decrypt_verify_status_handler (void *priv, gpgme_status_code_t code,
|
||
char *args)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
err = _gpgme_progress_status_handler (priv, code, args);
|
||
if (!err)
|
||
err = _gpgme_decrypt_status_handler (priv, code, args);
|
||
if (!err)
|
||
err = _gpgme_verify_status_handler (priv, code, args);
|
||
return err;
|
||
}
|
||
|
||
|
||
static gpgme_error_t
|
||
decrypt_verify_start (gpgme_ctx_t ctx, int synchronous,
|
||
gpgme_decrypt_flags_t flags,
|
||
gpgme_data_t cipher, gpgme_data_t plain)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
assert ((flags & GPGME_DECRYPT_VERIFY));
|
||
|
||
err = _gpgme_op_reset (ctx, synchronous);
|
||
if (err)
|
||
return err;
|
||
|
||
err = _gpgme_op_decrypt_init_result (ctx);
|
||
if (err)
|
||
return err;
|
||
|
||
err = _gpgme_op_verify_init_result (ctx);
|
||
if (err)
|
||
return err;
|
||
|
||
if (!cipher)
|
||
return gpg_error (GPG_ERR_NO_DATA);
|
||
if (!plain)
|
||
return gpg_error (GPG_ERR_INV_VALUE);
|
||
|
||
if (ctx->passphrase_cb)
|
||
{
|
||
err = _gpgme_engine_set_command_handler
|
||
(ctx->engine, _gpgme_passphrase_command_handler, ctx, NULL);
|
||
if (err)
|
||
return err;
|
||
}
|
||
|
||
_gpgme_engine_set_status_handler (ctx->engine,
|
||
decrypt_verify_status_handler, ctx);
|
||
|
||
return _gpgme_engine_op_decrypt (ctx->engine,
|
||
flags,
|
||
cipher, plain,
|
||
ctx->export_session_keys,
|
||
ctx->override_session_key);
|
||
}
|
||
|
||
|
||
/* Decrypt ciphertext CIPHER and make a signature verification within
|
||
CTX and store the resulting plaintext in PLAIN. */
|
||
gpgme_error_t
|
||
gpgme_op_decrypt_verify_start (gpgme_ctx_t ctx, gpgme_data_t cipher,
|
||
gpgme_data_t plain)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_verify_start", ctx,
|
||
"cipher=%p, plain=%p", cipher, plain);
|
||
|
||
if (!ctx)
|
||
return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE));
|
||
|
||
err = decrypt_verify_start (ctx, 0, GPGME_DECRYPT_VERIFY, cipher, plain);
|
||
return TRACE_ERR (err);
|
||
}
|
||
|
||
|
||
/* Decrypt ciphertext CIPHER and make a signature verification within
|
||
CTX and store the resulting plaintext in PLAIN. */
|
||
gpgme_error_t
|
||
gpgme_op_decrypt_verify (gpgme_ctx_t ctx, gpgme_data_t cipher,
|
||
gpgme_data_t plain)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_verify", ctx,
|
||
"cipher=%p, plain=%p", cipher, plain);
|
||
|
||
if (!ctx)
|
||
return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE));
|
||
|
||
err = decrypt_verify_start (ctx, 1, GPGME_DECRYPT_VERIFY, cipher, plain);
|
||
if (!err)
|
||
err = _gpgme_wait_one (ctx);
|
||
return TRACE_ERR (err);
|
||
}
|
||
|
||
|
||
/* Decrypt ciphertext CIPHER within CTX and store the resulting
|
||
plaintext in PLAIN. */
|
||
gpgme_error_t
|
||
gpgme_op_decrypt_ext_start (gpgme_ctx_t ctx,
|
||
gpgme_decrypt_flags_t flags,
|
||
gpgme_data_t cipher,
|
||
gpgme_data_t plain)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_ext_start", ctx,
|
||
"cipher=%p, plain=%p", cipher, plain);
|
||
|
||
if (!ctx)
|
||
return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE));
|
||
|
||
if ((flags & GPGME_DECRYPT_VERIFY))
|
||
err = decrypt_verify_start (ctx, 0, flags, cipher, plain);
|
||
else
|
||
err = _gpgme_decrypt_start (ctx, 0, flags, cipher, plain);
|
||
return TRACE_ERR (err);
|
||
}
|
||
|
||
|
||
/* Decrypt ciphertext CIPHER within CTX and store the resulting
|
||
plaintext in PLAIN. */
|
||
gpgme_error_t
|
||
gpgme_op_decrypt_ext (gpgme_ctx_t ctx,
|
||
gpgme_decrypt_flags_t flags,
|
||
gpgme_data_t cipher,
|
||
gpgme_data_t plain)
|
||
{
|
||
gpgme_error_t err;
|
||
|
||
TRACE_BEG2 (DEBUG_CTX, "gpgme_op_decrypt_ext", ctx,
|
||
"cipher=%p, plain=%p", cipher, plain);
|
||
|
||
if (!ctx)
|
||
return TRACE_ERR (gpg_error (GPG_ERR_INV_VALUE));
|
||
|
||
if ((flags & GPGME_DECRYPT_VERIFY))
|
||
err = decrypt_verify_start (ctx, 1, flags, cipher, plain);
|
||
else
|
||
err = _gpgme_decrypt_start (ctx, 1, flags, cipher, plain);
|
||
if (!err)
|
||
err = _gpgme_wait_one (ctx);
|
||
return TRACE_ERR (err);
|
||
}
|