summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
author0x221E2026-05-10 22:39:57 +0200
committer0x221E2026-05-10 22:39:57 +0200
commit0bdf49ae045071a99674b4ac426c2c852f744443 (patch)
tree2eba04599d062be9ff1b3d2ed58a38bceda631a2
parent08d1240456383bc9554840a5255f7f87114ade92 (diff)
core: seperate integrity verification to the "crypto" subsystem.
Seperates cryptographic verification from pkgman_upstream_integrity_download to its own function for better code structure, and to create space for future cryptographic functions.
-rw-r--r--include/crypto.h6
-rw-r--r--include/lib/url.h17
-rw-r--r--src/crypto.c55
-rw-r--r--src/pkgman.c44
4 files changed, 80 insertions, 42 deletions
diff --git a/include/crypto.h b/include/crypto.h
new file mode 100644
index 0000000..c41c780
--- /dev/null
+++ b/include/crypto.h
@@ -0,0 +1,6 @@
+#ifndef CRYPTO_H
+#define CRYPTO_H
+
+int crypto_verify_integrity(const char *sig, const char *file);
+
+#endif
diff --git a/include/lib/url.h b/include/lib/url.h
new file mode 100644
index 0000000..6bb588a
--- /dev/null
+++ b/include/lib/url.h
@@ -0,0 +1,17 @@
+#ifndef URL_H
+#define URL_H
+
+#include <stddef.h>
+
+struct url {
+ char *buffer;
+ size_t len;
+};
+
+int url_init(struct url *url, char *base);
+void url_free(struct url *url);
+int url_copy(struct url *from, struct url *to);
+int url_append(struct url *url, const char *add);
+int url_append_path(struct url *url, const char *add);
+
+#endif
diff --git a/src/crypto.c b/src/crypto.c
new file mode 100644
index 0000000..281da36
--- /dev/null
+++ b/src/crypto.c
@@ -0,0 +1,55 @@
+#include <crypto.h>
+
+#include <gpgme.h>
+
+#include <err.h>
+
+#include <fcntl.h>
+
+int crypto_verify_integrity(const char *sig, const char *file)
+{
+ int ret = -ERR;
+
+ gpgme_check_version(NULL);
+
+ gpgme_ctx_t ctx;
+
+ gpgme_new(&ctx);
+ gpgme_set_protocol(ctx, GPGME_PROTOCOL_OPENPGP);
+
+ int fd = open(file, O_RDONLY);
+ int sigfd = open(sig, O_RDONLY);
+
+ gpgme_data_t gfile;
+ gpgme_data_t gsig;
+
+ gpgme_data_new_from_fd(&gfile, fd);
+ gpgme_data_new_from_fd(&gsig, sigfd);
+
+ if (gpgme_op_verify(ctx, gsig, gfile, NULL) == GPG_ERR_NO_ERROR) {
+ printf("Signature operation ran successfully.\n");
+ } else {
+ printf("Integrity verification failed!\n");
+ ret = -INTEGRITYERR;
+ goto cleanup;
+ }
+
+ gpgme_verify_result_t integ_res = gpgme_op_verify_result(ctx);
+
+ // Checking the first signature for now should be fine.
+ //TODO: Revisit this.
+ if ((integ_res->signatures->summary & GPGME_SIGSUM_VALID) &&
+ (integ_res->signatures->status == GPG_ERR_NO_ERROR)) {
+ printf("Integrity check successful, "
+ "package can be installed.\n");
+ ret = SUCCESS;
+ goto cleanup;
+ } else {
+ printf("Signature invalid!\n");
+ ret = -INTEGRITYERR;
+ goto cleanup;
+ }
+ cleanup:
+ gpgme_release(ctx);
+ return ret;
+}
diff --git a/src/pkgman.c b/src/pkgman.c
index c21d0c5..b5edc69 100644
--- a/src/pkgman.c
+++ b/src/pkgman.c
@@ -8,6 +8,7 @@
#include <lib/url.h>
#include <lib/archive.h>
#include <cookbook.h>
+#include <crypto.h>
#include <assert.h>
#include <string.h>
@@ -163,55 +164,14 @@ int pkgman_upstream_integrity_download(const char *pkg)
printf("Signature for '%s' downloaded.\n", url_sig.buffer);
- // Verify integrity
-
- gpgme_check_version(NULL);
-
- gpgme_ctx_t ctx;
-
- gpgme_new(&ctx);
- gpgme_set_protocol(ctx, GPGME_PROTOCOL_OPENPGP);
-
- int fd = open(path_pkg.buffer, O_RDONLY);
- int sigfd = open(path_sig.buffer, O_RDONLY);
-
- gpgme_data_t file;
- gpgme_data_t sig;
-
- gpgme_data_new_from_fd(&file, fd);
- gpgme_data_new_from_fd(&sig, sigfd);
-
- if (gpgme_op_verify(ctx, sig, file, NULL) == GPG_ERR_NO_ERROR) {
- printf("Signature operation ran successfully.\n");
- } else {
- printf("Integrity verification failed!\n");
+ if(crypto_verify_integrity(path_sig.buffer, path_pkg.buffer) != SUCCESS) {
ret = -INTEGRITYERR;
- gpgme_release(ctx);
goto cleanup;
}
-
- gpgme_verify_result_t integ_res = gpgme_op_verify_result(ctx);
-
- // Checking the first signature for now should be fine.
- //TODO: Revisit this.
- if ((integ_res->signatures->summary & GPGME_SIGSUM_VALID) &&
- (integ_res->signatures->status == GPG_ERR_NO_ERROR)) {
- printf("Integrity check successful, "
- "package can be installed.\n");
- } else {
- printf("Signature invalid!\n");
- ret = -INTEGRITYERR;
- gpgme_release(ctx);
- goto cleanup;
- }
-
ret = SUCCESS;
- gpgme_release(ctx);
-
cleanup:
-
url_free(&url_pkg);
url_free(&url_sig);