:group 'epg
:type 'string)
+(defconst epg-version-number "0.0.0")
+
(defvar epg-user-id nil
"GnuPG ID of your default identity.")
(defvar epg-key-id nil)
(defvar epg-context nil)
(defvar epg-debug nil)
+(defvar epg-debug-buffer nil)
;; from gnupg/include/cipher.h
(defconst epg-cipher-algorithm-alist
(9 . "Not a secret key")
(10 . "Key not trusted")))
+(defconst epg-delete-problem-alist
+ '((1 . "No such key")
+ (2 . "Must delete secret key first")
+ (3 . "Ambigious specification")))
+
(defvar epg-key-validity-alist
'((?o . unknown)
(?i . invalid)
(setcdr entry value)
(epg-context-set-result context (cons (cons name value) result)))))
+(defun epg-signature-to-string (signature)
+ (format "%s signature from %s %s%s"
+ (capitalize (symbol-name (epg-signature-status signature)))
+ (epg-signature-key-id signature)
+ (epg-signature-user-id signature)
+ (if (epg-signature-validity signature)
+ (format " (trust %s)"
+ (epg-signature-validity signature))
+ "")))
+
+(defun epg-verify-result-to-string (verify-result)
+ (mapconcat #'epg-signature-to-string verify-result "\n"))
+
(defun epg-start (context args)
"Start `epg-gpg-program' in a subprocess with given ARGS."
(let* ((args (append (list "--no-tty"
process)
(if epg-debug
(save-excursion
- (set-buffer (get-buffer-create " *epg-debug*"))
+ (unless epg-debug-buffer
+ (setq epg-debug-buffer (generate-new-buffer " *epg-debug*")))
+ (set-buffer epg-debug-buffer)
(goto-char (point-max))
(insert (format "%s %s\n" epg-gpg-program
(mapconcat #'identity args " ")))))
(defun epg-process-filter (process input)
(if epg-debug
(save-excursion
- (set-buffer (get-buffer-create " *epg-debug*"))
+ (unless epg-debug-buffer
+ (setq epg-debug-buffer (generate-new-buffer " *epg-debug*")))
+ (set-buffer epg-debug-buffer)
(goto-char (point-max))
(insert input)))
(if (buffer-live-p (process-buffer process))
(insert input)
(goto-char epg-read-point)
(beginning-of-line)
- (while (looking-at ".*\n") ;the input line is finished
+ (while (looking-at ".*\n") ;the input line finished
(save-excursion
(if (looking-at "\\[GNUPG:] \\([A-Z_]+\\) ?\\(.*\\)")
(let* ((status (match-string 1))
(accept-process-output (epg-context-process context) 1))))
(defun epg-wait-for-completion (context)
- (if (eq (process-status (epg-context-process context)) 'run)
- (process-send-eof (epg-context-process context)))
(while (eq (process-status (epg-context-process context)) 'run)
;; We can't use accept-process-output instead of sit-for here
;; because it may cause an interrupt during the sentinel execution.
(sit-for 0.1)))
+(defun epg-flush (context)
+ (if (eq (process-status (epg-context-process context)) 'run)
+ (process-send-eof (epg-context-process context))))
+
(defun epg-reset (context)
(if (and (epg-context-process context)
(buffer-live-p (process-buffer (epg-context-process context))))
(setq epg-key-id 'PIN))
(defun epg-status-GET_HIDDEN (process string)
- (let ((passphrase
- (funcall (if (consp (epg-context-passphrase-callback epg-context))
- (car (epg-context-passphrase-callback epg-context))
- (epg-context-passphrase-callback epg-context))
- epg-key-id
- (if (consp (epg-context-passphrase-callback epg-context))
- (cdr (epg-context-passphrase-callback epg-context)))))
- string)
- (if passphrase
- (unwind-protect
- (progn
- (setq string (concat passphrase "\n"))
- (fillarray passphrase 0)
- (setq passphrase nil)
- (process-send-string process string))
- (if string
- (fillarray string 0))))))
+ (if (and epg-key-id
+ (string-match "\\`passphrase\\." string))
+ (let ((passphrase
+ (funcall
+ (if (consp (epg-context-passphrase-callback epg-context))
+ (car (epg-context-passphrase-callback epg-context))
+ (epg-context-passphrase-callback epg-context))
+ epg-key-id
+ (if (consp (epg-context-passphrase-callback epg-context))
+ (cdr (epg-context-passphrase-callback epg-context)))))
+ string)
+ (if passphrase
+ (unwind-protect
+ (progn
+ (setq string (concat passphrase "\n"))
+ (fillarray passphrase 0)
+ (setq passphrase nil)
+ (process-send-string process string))
+ (if string
+ (fillarray string 0)))))))
(defun epg-status-GET_BOOL (process string)
(let ((entry (assoc string epg-prompt-alist)))
(cons 'no-recipients
(epg-context-result-for epg-context 'error))))
+(defun epg-status-DELETE_PROBLEM (process string)
+ (if (string-match "\\`\\([0-9]+\\)" string)
+ (epg-context-set-result-for
+ epg-context 'error
+ (cons (cons 'delete-problem (string-to-number (match-string 1 string)))
+ (epg-context-result-for epg-context 'error)))))
+
+(defun epg-status-SIG_CREATED (process string)
+ (if (string-match "\\`\\([DCS]\\) \\([0-9]+\\) \\([0-9]+\\) \
+\\([0-9A-Fa-F][0-9A-Fa-F]\\) \\(.*\\) " string)
+ (epg-context-set-result-for
+ epg-context 'sign
+ (cons (list (cons 'type (string-to-char (match-string 1 string)))
+ (cons 'pubkey-algorithm
+ (string-to-number (match-string 2 string)))
+ (cons 'digest-algorithm
+ (string-to-number (match-string 3 string)))
+ (cons 'class (string-to-number (match-string 4 string) 16))
+ (cons 'creation-time (match-string 5 string))
+ (cons 'fingerprint (substring string (match-end 0))))
+ (epg-context-result-for epg-context 'sign)))))
+
(defun epg-passphrase-callback-function (key-id handback)
(read-passwd
(if (eq key-id 'SYM)
(epg-context-set-output-file context
(epg-make-temp-file "epg-output"))
(epg-start-decrypt context (epg-make-data-from-file input-file))
+ (epg-flush context)
(epg-wait-for-completion context)
(if (epg-context-result-for context 'error)
(error "Decrypt failed: %S"
(epg-make-data-from-file input-file)
(epg-make-data-from-string signed-text)))
(epg-start-verify context (epg-make-data-from-string signature)))
+ (epg-flush context)
(epg-wait-for-completion context)
(epg-read-output context))
(epg-delete-output-file context)
"--detach-sign"
"--sign")))
(apply #'nconc
- (mapcar (lambda (signer)
- (list "-u" signer))
- (epg-context-signers context)))
+ (mapcar
+ (lambda (signer)
+ (list "-u"
+ (epg-sub-key-id
+ (car (epg-key-sub-key-list signer)))))
+ (epg-context-signers context)))
(if (epg-data-file plain)
(list (epg-data-file plain)))))
(epg-wait-for-status context '("BEGIN_SIGNING"))
(epg-context-set-output-file context
(epg-make-temp-file "epg-output"))
(epg-start-sign context (epg-make-data-from-string plain) mode)
+ (epg-flush context)
(epg-wait-for-completion context)
(if (epg-context-result-for context 'error)
(error "Sign failed: %S"
(list "-u" signer))
(epg-context-signers context)))))
(apply #'nconc
- (mapcar (lambda (recipient)
- (list "-r" recipient))
- recipients))
+ (mapcar
+ (lambda (recipient)
+ (list "-r"
+ (epg-sub-key-id
+ (car (epg-key-sub-key-list recipient)))))
+ recipients))
(if (epg-data-file plain)
(list (epg-data-file plain)))))
(if sign
(epg-make-temp-file "epg-output"))
(epg-start-encrypt context (epg-make-data-from-string plain)
recipients sign always-trust)
+ (epg-flush context)
(epg-wait-for-completion context)
(if (epg-context-result-for context 'error)
(error "Encrypt failed: %S"
(epg-reset context)))
;;;###autoload
-(defun epg-start-export-keys (context pattern)
+(defun epg-start-export-keys (context keys)
"Initiate an export keys operation.
If you use this function, you will need to wait for the completion of
`epg-gpg-program' by using `epg-wait-for-completion' and call
`epg-reset' to clear a temporaly output file.
If you are unsure, use synchronous version of this function
-`epg-export-keys' instead."
+`epg-export-keys-to-file' or `epg-export-keys-to-string' instead."
(epg-context-set-result context nil)
- (epg-context-set-output-file context (epg-make-temp-file "epg-output"))
- (epg-start context (list "--export" pattern)))
+ (epg-start context (cons "--export"
+ (mapcar
+ (lambda (key)
+ (epg-sub-key-id
+ (car (epg-key-sub-key-list key))))
+ keys))))
;;;###autoload
-(defun epg-export-keys (context pattern)
- "Extract public keys matched with PATTERN and return them."
+(defun epg-export-keys-to-file (context keys file)
+ "Extract public KEYS."
(unwind-protect
(progn
- (epg-start-export-keys context pattern)
+ (if keys
+ (epg-context-set-output-file context file)
+ (epg-context-set-output-file context
+ (epg-make-temp-file "epg-output")))
+ (epg-start-export-keys context keys)
(epg-wait-for-completion context)
(if (epg-context-result-for context 'error)
(error "Export keys failed"))
- (epg-read-output context))
+ (unless file
+ (epg-read-output context)))
+ (unless file
+ (epg-delete-output-file context))
(epg-reset context)))
;;;###autoload
+(defun epg-export-keys-to-string (context keys)
+ "Extract public KEYS and return them as a string."
+ (epg-export-keys-to-file context keys nil))
+
+;;;###autoload
(defun epg-start-import-keys (context keys)
"Initiate an import keys operation.
KEYS is a data object.
`epg-import-keys-from-file' or `epg-import-keys-from-string' instead."
(epg-context-set-result context nil)
(epg-context-set-output-file context (epg-make-temp-file "epg-output"))
- (epg-start context (append (list "--import") (epg-data-file keys)))
+ (epg-start context (list "--import" (epg-data-file keys)))
(if (and (epg-data-string keys)
(eq (process-status (epg-context-process context)) 'run))
(process-send-string (epg-context-process context)
(unwind-protect
(progn
(epg-start-import-keys context keys)
+ (if (epg-data-file keys)
+ (epg-flush context))
(epg-wait-for-completion context)
(if (epg-context-result-for context 'error)
(error "Import keys failed"))
"Add keys from a string KEYS."
(epg-import-keys-1 context (epg-make-data-from-string keys)))
+;;;###autoload
+(defun epg-start-delete-keys (context keys &optional allow-secret)
+ "Initiate an delete keys operation.
+
+If you use this function, you will need to wait for the completion of
+`epg-gpg-program' by using `epg-wait-for-completion' and call
+`epg-reset' to clear a temporaly output file.
+If you are unsure, use synchronous version of this function
+`epg-delete-keys' instead."
+ (epg-context-set-result context nil)
+ (epg-start context (cons (if allow-secret
+ "--delete-secret-key"
+ "--delete-key")
+ (mapcar
+ (lambda (key)
+ (epg-sub-key-id
+ (car (epg-key-sub-key-list key))))
+ keys))))
+
+;;;###autoload
+(defun epg-delete-keys (context keys &optional allow-secret)
+ "Delete KEYS from the key ring."
+ (unwind-protect
+ (progn
+ (epg-start-delete-keys context keys)
+ (epg-wait-for-completion context)
+ (if (epg-context-result-for context 'error)
+ (error "Delete key failed")))
+ (epg-reset context)))
+
(provide 'epg)
;;; epg.el ends here