RPM Package Manager, CVS Repository http://rpm5.org/cvs/ ____________________________________________________________________________
Server: rpm5.org Name: Jeff Johnson Root: /v/rpm/cvs Email: [email protected] Module: rpm Date: 09-Jun-2010 04:29:07 Branch: HEAD Handle: 2010060902290402 Modified files: rpm CHANGES rpm/rpmio rpmgc.c rpmpgp.h rpmssl.c rpm/tests tecdsa.c tpgp.c trsa.c Log: - pgp: buff the chrome. Summary: Revision Changes Path 1.3384 +1 -0 rpm/CHANGES 2.32 +39 -33 rpm/rpmio/rpmgc.c 2.102 +9 -0 rpm/rpmio/rpmpgp.h 2.40 +42 -38 rpm/rpmio/rpmssl.c 1.21 +3 -5 rpm/tests/tecdsa.c 1.3 +38 -0 rpm/tests/tpgp.c 1.31 +26 -26 rpm/tests/trsa.c ____________________________________________________________________________ patch -p0 <<'@@ .' Index: rpm/CHANGES ============================================================================ $ cvs diff -u -r1.3383 -r1.3384 CHANGES --- rpm/CHANGES 8 Jun 2010 23:00:48 -0000 1.3383 +++ rpm/CHANGES 9 Jun 2010 02:29:04 -0000 1.3384 @@ -1,4 +1,5 @@ 5.3.0 -> 5.4a1: + - jbj: pgp: buff the chrome. - jbj: nss: add a strerror to decode errors to something meaningful. - jbj: nss: generate "real" PQG params for DSA. - jbj: nss: add RSA/DSA sign/generate methods. @@ . patch -p0 <<'@@ .' Index: rpm/rpmio/rpmgc.c ============================================================================ $ cvs diff -u -r2.31 -r2.32 rpmgc.c --- rpm/rpmio/rpmgc.c 6 Jun 2010 15:48:33 -0000 2.31 +++ rpm/rpmio/rpmgc.c 9 Jun 2010 02:29:05 -0000 2.32 @@ -26,12 +26,22 @@ extern int _pgp_print; /*...@=redecl@*/ -static const char * _pgpHashAlgo2Name(uint32_t algo) + +/*...@unchecked@*/ +static int _rpmgc_debug; + +#define SPEW(_t, _rc, _dig) \ + { if ((_t) || _rpmgc_debug || _pgp_debug < 0) \ + fprintf(stderr, "<-- %s(%p) %s\t%s\n", __FUNCTION__, (_dig), \ + ((_rc) ? "OK" : "BAD"), (_dig)->pubkey_algoN); \ + } + +static const char * rpmgcHashAlgo2Name(uint32_t algo) { return pgpValStr(pgpHashTbl, (rpmuint8_t)algo); } -static const char * _pgpPubkeyAlgo2Name(uint32_t algo) +static const char * rpmgcPubkeyAlgo2Name(uint32_t algo) { return pgpValStr(pgpPubkeyTbl, (rpmuint8_t)algo); } @@ -123,25 +133,21 @@ if (hash_algo_name == NULL) return 1; - xx = rpmDigestFinal(ctx, (void **)&dig->md5, &dig->md5len, 0); + xx = rpmDigestFinal(ctx, (void **)&gc->digest, &gc->digestlen, 0); /* Set RSA hash. */ err = rpmgcErr(gc, "RSA c", gcry_sexp_build(&gc->hash, NULL, - "(data (flags pkcs1) (hash %s %b))", hash_algo_name, dig->md5len, dig->md5) ); + "(data (flags pkcs1) (hash %s %b))", hash_algo_name, gc->digestlen, gc->digest) ); if (_pgp_debug < 0) rpmgcDump("gc->hash", gc->hash); /* Compare leading 16 bits of digest for quick check. */ - { const rpmuint8_t *s = dig->md5; + { const rpmuint8_t *s = gc->digest; const rpmuint8_t *t = sigp->signhash16; rc = memcmp(s, t, sizeof(sigp->signhash16)); -#ifdef DYING - if (rc != 0) - fprintf(stderr, "*** hash fails: digest(%02x%02x) != signhash(%02x%02x)\n", - s[0], s[1], t[0], t[1]); -#endif } +SPEW(0, !rc, dig); return rc; } @@ -151,17 +157,18 @@ { rpmgc gc = dig->impl; gcry_error_t err; + int rc; int xx; assert(sigp->hash_algo == rpmDigestAlgo(ctx)); - xx = rpmDigestFinal(ctx, (void **)&dig->sha1, &dig->sha1len, 0); + xx = rpmDigestFinal(ctx, (void **)&gc->digest, &gc->digestlen, 0); /* Set DSA hash. */ /*...@-moduncon -noeffectuncon @*/ { gcry_mpi_t c = NULL; /* XXX truncate to 160 bits */ err = rpmgcErr(gc, "DSA c", - gcry_mpi_scan(&c, GCRYMPI_FMT_USG, dig->sha1, 160/8, NULL)); + gcry_mpi_scan(&c, GCRYMPI_FMT_USG, gc->digest, 160/8, NULL)); err = rpmgcErr(gc, "DSA gc->hash", gcry_sexp_build(&gc->hash, NULL, "(data (flags raw) (value %m))", c) ); @@ -171,21 +178,25 @@ /*...@=moduncon =noeffectuncon @*/ /* Compare leading 16 bits of digest for quick check. */ - return memcmp(dig->sha1, sigp->signhash16, sizeof(sigp->signhash16)); + rc = memcmp(gc->digest, sigp->signhash16, sizeof(sigp->signhash16)); +SPEW(0, !rc, dig); + return rc; } static int rpmgcSetELG(/*...@only@*/ DIGEST_CTX ctx, /*...@unused@*/pgpDig dig, pgpDigParams sigp) /*...@*/ { + rpmgc gc = dig->impl; int rc = 1; /* XXX always fail. */ int xx; assert(sigp->hash_algo == rpmDigestAlgo(ctx)); - xx = rpmDigestFinal(ctx, (void **)NULL, NULL, 0); + xx = rpmDigestFinal(ctx, (void **)&gc->digest, &gc->digestlen, 0); /* Compare leading 16 bits of digest for quick check. */ +SPEW(0, !rc, dig); return rc; } @@ -193,8 +204,8 @@ int rpmgcSetECDSA(/*...@only@*/ DIGEST_CTX ctx, /*...@unused@*/pgpDig dig, pgpDigParams sigp) /*...@*/ { - int rc = 1; /* assume failure. */ rpmgc gc = dig->impl; + int rc = 1; /* assume failure. */ gpg_error_t err; int xx; @@ -218,9 +229,7 @@ /* Compare leading 16 bits of digest for quick check. */ -if (_pgp_debug < 0) -fprintf(stderr, "<-- %s(%p,%p) rc %d\n", __FUNCTION__, dig, sigp, rc); - +SPEW(0, !rc, dig); return rc; } @@ -278,8 +287,8 @@ int rc; pgpDigParams pubp = pgpGetPubkey(dig); pgpDigParams sigp = pgpGetSignature(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); -dig->hash_algoN = _pgpHashAlgo2Name(sigp->hash_algo); +dig->pubkey_algoN = rpmgcPubkeyAlgo2Name(pubp->pubkey_algo); +dig->hash_algoN = rpmgcHashAlgo2Name(sigp->hash_algo); if (gc->sig == NULL) { pgpDigParams pubp = pgpGetPubkey(dig); @@ -298,7 +307,7 @@ gcry_sexp_build(&gc->sig, NULL, "(sig-val (DSA (r %m) (s %m)))", gc->r, gc->s) ); break; - case PGPPUBKEYALGO_ECDSA: + case PGPPUBKEYALGO_ECDSA: /* XXX FIXME */ default: assert(0); break; @@ -351,9 +360,7 @@ rc = (gc->err == 0); -if (_pgp_debug < 0) -fprintf(stderr, "<-- %s(%p) rc %d\t%s-%s\n", __FUNCTION__, dig, rc, dig->pubkey_algoN, dig->hash_algoN); - +SPEW(0, rc, dig); return rc; /* XXX 1 on success */ } @@ -364,8 +371,8 @@ int rc; pgpDigParams pubp = pgpGetPubkey(dig); pgpDigParams sigp = pgpGetSignature(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); -dig->hash_algoN = _pgpHashAlgo2Name(sigp->hash_algo); +dig->pubkey_algoN = rpmgcPubkeyAlgo2Name(pubp->pubkey_algo); +dig->hash_algoN = rpmgcHashAlgo2Name(sigp->hash_algo); /* Sign the hash. */ gc->err = rpmgcErr(gc, "gcry_pk_sign", @@ -375,9 +382,7 @@ rc = (gc->err == 0); -if (_pgp_debug < 0) -fprintf(stderr, "<-- %s(%p) rc %d\t%s-%s\n", __FUNCTION__, dig, rc, dig->pubkey_algoN, dig->hash_algoN); - +SPEW(!rc, rc, dig); return rc; /* XXX 1 on success */ } @@ -388,7 +393,10 @@ rpmgc gc = dig->impl; int rc; pgpDigParams pubp = pgpGetPubkey(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); +dig->pubkey_algoN = rpmgcPubkeyAlgo2Name(pubp->pubkey_algo); + +if (gc->nbits == 0) gc->nbits = 1024; /* XXX FIXME */ +assert(gc->nbits); /* XXX FIXME: gc->{key_spec,key_pair} could be local. */ /* XXX FIXME: gc->qbits w DSA? curve w ECDSA? other params? */ @@ -476,9 +484,7 @@ } #endif -if (_pgp_debug < 0) -fprintf(stderr, "<-- %s(%p) rc %d\t%s\n", __FUNCTION__, dig, rc, dig->pubkey_algoN); - +SPEW(!rc, rc, dig); return rc; /* XXX 1 on success */ } @@ . patch -p0 <<'@@ .' Index: rpm/rpmio/rpmpgp.h ============================================================================ $ cvs diff -u -r2.101 -r2.102 rpmpgp.h --- rpm/rpmio/rpmpgp.h 4 Jun 2010 14:00:21 -0000 2.101 +++ rpm/rpmio/rpmpgp.h 9 Jun 2010 02:29:05 -0000 2.102 @@ -1753,6 +1753,15 @@ /** */ /*...@unused@*/ static inline +int pgpImplSetELG(/*...@only@*/ DIGEST_CTX ctx, pgpDig dig, pgpDigParams sigp) + /*...@modifies ctx, dig @*/ +{ + return (*pgpImplVecs->_pgpSetELG) (ctx, dig, sigp); +} + +/** + */ +/*...@unused@*/ static inline int pgpImplSetECDSA(/*...@only@*/ DIGEST_CTX ctx, pgpDig dig, pgpDigParams sigp) /*...@modifies ctx, dig @*/ { @@ . patch -p0 <<'@@ .' Index: rpm/rpmio/rpmssl.c ============================================================================ $ cvs diff -u -r2.39 -r2.40 rpmssl.c --- rpm/rpmio/rpmssl.c 8 Jun 2010 23:00:53 -0000 2.39 +++ rpm/rpmio/rpmssl.c 9 Jun 2010 02:29:05 -0000 2.40 @@ -43,12 +43,12 @@ ((_rc) ? "OK" : "BAD"), (_dig)->pubkey_algoN); \ } -static const char * _pgpHashAlgo2Name(uint32_t algo) +static const char * rpmsslHashAlgo2Name(uint32_t algo) { return pgpValStr(pgpHashTbl, (rpmuint8_t)algo); } -static const char * _pgpPubkeyAlgo2Name(uint32_t algo) +static const char * rpmsslPubkeyAlgo2Name(uint32_t algo) { return pgpValStr(pgpPubkeyTbl, (rpmuint8_t)algo); } @@ -71,6 +71,21 @@ return (unsigned char) '\0'; } +static unsigned char * rpmsslBN2bin(const char * msg, const BIGNUM * s, size_t maxn) +{ + unsigned char * t = xcalloc(1, maxn); +/*...@-modunconnomods@*/ + size_t nt = BN_bn2bin(s, t); +/*...@=modunconnomods@*/ + + if (nt < maxn) { + size_t pad = (maxn - nt); + memmove(t+pad, t, nt); + memset(t, 0, pad); + } + return t; +} + static int rpmsslSetRSA(/*...@only@*/ DIGEST_CTX ctx, pgpDig dig, pgpDigParams sigp) /*...@modifies dig @*/ @@ -85,8 +100,8 @@ int rc; int xx; pgpDigParams pubp = pgpGetPubkey(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); -dig->hash_algoN = _pgpHashAlgo2Name(sigp->hash_algo); +dig->pubkey_algoN = rpmsslPubkeyAlgo2Name(pubp->pubkey_algo); +dig->hash_algoN = rpmsslHashAlgo2Name(sigp->hash_algo); assert(sigp->hash_algo == rpmDigestAlgo(ctx)); if (prefix == NULL) @@ -124,25 +139,10 @@ signhash16[1] = (rpmuint8_t) (nibble(s[2]) << 4) | nibble(s[3]); /*...@=type@*/ rc = memcmp(signhash16, sigp->signhash16, sizeof(sigp->signhash16)); -SPEW(rc, !rc, dig); +SPEW(0, !rc, dig); return rc; } -static unsigned char * rpmsslBN2bin(const char * msg, const BIGNUM * s, size_t maxn) -{ - unsigned char * t = xcalloc(1, maxn); -/*...@-modunconnomods@*/ - size_t nt = BN_bn2bin(s, t); -/*...@=modunconnomods@*/ - - if (nt < maxn) { - size_t pad = (maxn - nt); - memmove(t+pad, t, nt); - memset(t, 0, pad); - } - return t; -} - static int rpmsslVerifyRSA(pgpDig dig) /*...@*/ @@ -201,7 +201,7 @@ } static -int rpmsslSignRSA(/*...@unused@*/pgpDig dig) +int rpmsslSignRSA(pgpDig dig) /*...@*/ { rpmssl ssl = dig->impl; @@ -209,7 +209,6 @@ unsigned char * c = NULL; unsigned char * hm = NULL; size_t maxn; - size_t nb; int xx; #ifdef DYING @@ -237,7 +236,7 @@ } static -int rpmsslGenerateRSA(/*...@unused@*/pgpDig dig) +int rpmsslGenerateRSA(pgpDig dig) /*...@*/ { rpmssl ssl = dig->impl; @@ -272,8 +271,8 @@ int rc; int xx; pgpDigParams pubp = pgpGetPubkey(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); -dig->hash_algoN = _pgpHashAlgo2Name(sigp->hash_algo); +dig->pubkey_algoN = rpmsslPubkeyAlgo2Name(pubp->pubkey_algo); +dig->hash_algoN = rpmsslHashAlgo2Name(sigp->hash_algo); assert(sigp->hash_algo == rpmDigestAlgo(ctx)); /* Set DSA hash. */ @@ -284,7 +283,7 @@ /* Compare leading 16 bits of digest for quick check. */ rc = memcmp(ssl->digest, sigp->signhash16, sizeof(sigp->signhash16)); -SPEW(rc, !rc, dig); +SPEW(0, !rc, dig); return rc; } @@ -305,7 +304,7 @@ } static -int rpmsslSignDSA(/*...@unused@*/pgpDig dig) +int rpmsslSignDSA(pgpDig dig) /*...@*/ { rpmssl ssl = dig->impl; @@ -326,7 +325,7 @@ } static -int rpmsslGenerateDSA(/*...@unused@*/pgpDig dig) +int rpmsslGenerateDSA(pgpDig dig) /*...@*/ { rpmssl ssl = dig->impl; @@ -395,13 +394,13 @@ } static -int rpmsslVerifyECDSA(/*...@unused@*/pgpDig dig) +int rpmsslVerifyECDSA(pgpDig dig) /*...@*/ { + rpmssl ssl = dig->impl; int rc = 0; /* assume failure. */ #if !defined(OPENSSL_NO_ECDSA) - rpmssl ssl = dig->impl; rc = ECDSA_do_verify(ssl->digest, ssl->digestlen, ssl->ecdsasig, ssl->ecdsakey); #endif rc = (rc == 1); @@ -411,13 +410,13 @@ } static -int rpmsslSignECDSA(/*...@unused@*/pgpDig dig) +int rpmsslSignECDSA(pgpDig dig) /*...@*/ { + rpmssl ssl = dig->impl; int rc = 0; /* assume failure. */ #if !defined(OPENSSL_NO_ECDSA) - rpmssl ssl = dig->impl; ssl->ecdsasig = ECDSA_do_sign(ssl->digest, ssl->digestlen, ssl->ecdsakey); rc = (ssl->ecdsasig != NULL); #endif @@ -427,13 +426,18 @@ } static -int rpmsslGenerateECDSA(/*...@unused@*/pgpDig dig) +int rpmsslGenerateECDSA(pgpDig dig) /*...@*/ { + rpmssl ssl = dig->impl; int rc = 0; /* assume failure. */ #if !defined(OPENSSL_NO_ECDSA) - rpmssl ssl = dig->impl; + +if (ssl->nid == 0) { /* XXX FIXME */ +ssl->nid = NID_X9_62_prime256v1; +ssl->nbits = 256; +} if ((ssl->ecdsakey = EC_KEY_new_by_curve_name(ssl->nid)) != NULL && EC_KEY_generate_key(ssl->ecdsakey)) @@ -493,8 +497,8 @@ int rc = 0; /* assume failure */ pgpDigParams pubp = pgpGetPubkey(dig); pgpDigParams sigp = pgpGetSignature(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); -dig->hash_algoN = _pgpHashAlgo2Name(sigp->hash_algo); +dig->pubkey_algoN = rpmsslPubkeyAlgo2Name(pubp->pubkey_algo); +dig->hash_algoN = rpmsslHashAlgo2Name(sigp->hash_algo); switch (pubp->pubkey_algo) { default: @@ -522,7 +526,7 @@ { int rc = 0; /* assume failure */ pgpDigParams pubp = pgpGetPubkey(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); +dig->pubkey_algoN = rpmsslPubkeyAlgo2Name(pubp->pubkey_algo); switch (pubp->pubkey_algo) { default: @@ -550,7 +554,7 @@ { int rc = 0; /* assume failure */ pgpDigParams pubp = pgpGetPubkey(dig); -dig->pubkey_algoN = _pgpPubkeyAlgo2Name(pubp->pubkey_algo); +dig->pubkey_algoN = rpmsslPubkeyAlgo2Name(pubp->pubkey_algo); switch (pubp->pubkey_algo) { default: @@ . patch -p0 <<'@@ .' Index: rpm/tests/tecdsa.c ============================================================================ $ cvs diff -u -r1.20 -r1.21 tecdsa.c --- rpm/tests/tecdsa.c 8 Jun 2010 20:44:20 -0000 1.20 +++ rpm/tests/tecdsa.c 9 Jun 2010 02:29:06 -0000 1.21 @@ -77,17 +77,14 @@ #define _RPMPGP_INTERNAL #include <poptIO.h> +#define _RPMNSS_INTERNAL +#include <rpmnss.h> #ifdef NOTNOW #define _RPMBC_INTERNAL #include <rpmbc.h> #define _RPMGC_INTERNAL #include <rpmgc.h> -#define _RPMNSS_INTERNAL -#include <rpmnss.h> -#include <pk11pub.h> -#include <secerr.h> -#endif /* NOTNOW */ #define _RPMSSL_INTERNAL #include <rpmssl.h> @@ -98,6 +95,7 @@ #include <openssl/ecdsa.h> #include <openssl/err.h> #include <openssl/rand.h> +#endif /* NOTNOW */ #include "debug.h" @@ . patch -p0 <<'@@ .' Index: rpm/tests/tpgp.c ============================================================================ $ cvs diff -u -r1.2 -r1.3 tpgp.c --- rpm/tests/tpgp.c 7 Jun 2010 20:24:15 -0000 1.2 +++ rpm/tests/tpgp.c 9 Jun 2010 02:29:06 -0000 1.3 @@ -10,6 +10,11 @@ #define _RPMPGP_INTERNAL #include <rpmio.h> +#include <rpmbc.h> +#include <rpmgc.h> +#include <rpmnss.h> +#include <rpmssl.h> + #include <rpmns.h> #include <rpmcli.h> @@ -86,6 +91,26 @@ xx = pgpImplSetDSA(ctx, dig, sigp); xx = pgpImplVerify(dig); break; + case PGPPUBKEYALGO_ELGAMAL: + sigp->signhash16[0] = digest[0]; + sigp->signhash16[1] = digest[1]; + xx = pgpImplSetELG(rpmDigestDup(ctx), dig, sigp); + xx = pgpImplSign(dig); + sigp->signhash16[0] = digest[0]; + sigp->signhash16[1] = digest[1]; + xx = pgpImplSetELG(ctx, dig, sigp); + xx = pgpImplVerify(dig); + break; + case PGPPUBKEYALGO_ECDSA: + sigp->signhash16[0] = digest[0]; + sigp->signhash16[1] = digest[1]; + xx = pgpImplSetECDSA(rpmDigestDup(ctx), dig, sigp); + xx = pgpImplSign(dig); + sigp->signhash16[0] = digest[0]; + sigp->signhash16[1] = digest[1]; + xx = pgpImplSetECDSA(ctx, dig, sigp); + xx = pgpImplVerify(dig); + break; default: xx = rpmDigestFinal(ctx, NULL, NULL, 0); break; @@ -125,6 +150,19 @@ if (rc != RPMRC_OK) ec++; rc = generateTest(ts, "abc", PGPPUBKEYALGO_RSA, PGPHASHALGO_SHA1); if (rc != RPMRC_OK) ec++; + +#ifdef NOTYET /* XXX FIXME: pig slow. */ + if (pgpImplVecs == &rpmgcImplVecs) { +fprintf(stderr, " ELG"); + rc = generateTest(ts, "abc", PGPPUBKEYALGO_ELGAMAL, PGPHASHALGO_SHA1); + if (rc != RPMRC_OK) ec++; + } +#endif + if (pgpImplVecs == &rpmsslImplVecs) { +fprintf(stderr, " ECDSA"); + rc = generateTest(ts, "abc", PGPPUBKEYALGO_ECDSA, PGPHASHALGO_SHA1); + if (rc != RPMRC_OK) ec++; + } fprintf(stderr, "\n"); (void) rpmtsFree(ts); @@ . patch -p0 <<'@@ .' Index: rpm/tests/trsa.c ============================================================================ $ cvs diff -u -r1.30 -r1.31 trsa.c --- rpm/tests/trsa.c 8 Jun 2010 21:36:11 -0000 1.30 +++ rpm/tests/trsa.c 9 Jun 2010 02:29:06 -0000 1.31 @@ -78,14 +78,14 @@ #define _RPMPGP_INTERNAL #include <poptIO.h> -#define _RPMNSS_INTERNAL -#include <rpmnss.h> +#define _RPMGC_INTERNAL +#include <rpmgc.h> #ifdef NOTYET #define _RPMBC_INTERNAL #include <rpmbc.h> -#define _RPMGC_INTERNAL -#include <rpmgc.h> +#define _RPMNSS_INTERNAL +#include <rpmnss.h> #define _RPMSSL_INTERNAL #include <rpmssl.h> @@ -992,7 +992,6 @@ if (hash_algo_name == NULL) return 1; -/* XXX FIXME: gc->digest instead */ xx = rpmDigestFinal(ctx, (void **)&gc->digest, &gc->digestlen, 0); /* Set RSA hash. */ @@ -1001,7 +1000,6 @@ "(data (flags pkcs1) (hash %s %b))", hash_algo_name, gc->digestlen, gc->digest) ); if (_pgp_debug < 0) rpmgcDump("gc->hash", gc->hash); -/* XXX FIXME: gc->digest instead */ /* Compare leading 16 bits of digest for quick check. */ { const rpmuint8_t *s = gc->digest; const rpmuint8_t *t = sigp->signhash16; @@ -1038,6 +1036,22 @@ } static +int rpmgcSetELG(/*...@only@*/ DIGEST_CTX ctx, /*...@unused@*/pgpDig dig, pgpDigParams sigp) + /*...@*/ +{ + rpmgc gc = dig->impl; + int rc = 1; /* XXX always fail. */ + int xx; + +assert(sigp->hash_algo == rpmDigestAlgo(ctx)); + xx = rpmDigestFinal(ctx, (void **)&gc->digest, &gc->digestlen, 0); + + /* Compare leading 16 bits of digest for quick check. */ + + return rc; +} + +static int rpmgcSetECDSA(/*...@only@*/ DIGEST_CTX ctx, /*...@unused@*/pgpDig dig, pgpDigParams sigp) /*...@*/ { @@ -1074,8 +1088,6 @@ /*==============================================================*/ -/*==============================================================*/ - #if defined(_RPMGC_INTERNAL) static void check_cbc_mac_cipher(pgpDig dig) @@ -2985,8 +2997,6 @@ pgpCheckVerify(pgpDig dig, void * _badhash) { int rc = 0; /* assume success */ -pgpDigParams pubp = pgpGetPubkey(dig); -pgpDigParams sigp = pgpGetSignature(dig); const char * msg = rpmExpand(dig->pubkey_algoN, "-", dig->hash_algoN, " verify", NULL); int xx; @@ -2995,7 +3005,8 @@ DIGEST_CTX ctx = NULL; uint8_t * digest = NULL; size_t digestlen = 0; - +pgpDigParams pubp = pgpGetPubkey(dig); +pgpDigParams sigp = pgpGetSignature(dig); ctx = rpmDigestInit(sigp->hash_algo, 0); xx = rpmDigestUpdate(ctx, "abc", sizeof("abc")-1); @@ -5384,8 +5395,10 @@ if (n) BN_free(n); } - if (ssl->ecdsasig->r) _spewBN(" r", ssl->ecdsasig->r); - if (ssl->ecdsasig->s) _spewBN(" s", ssl->ecdsasig->s); + if (ssl->exdsasig) { + _spewBN(" r", ssl->ecdsasig->r); + _spewBN(" s", ssl->ecdsasig->s); + } } #undef _spewBN @@ -6220,22 +6233,9 @@ rpmgcImplVecs._pgpSetRSA = rpmgcSetRSA; rpmgcImplVecs._pgpSetDSA = rpmgcSetDSA; -#ifdef NOTYET rpmgcImplVecs._pgpSetELG = rpmgcSetELG; -#endif rpmgcImplVecs._pgpSetECDSA = rpmgcSetECDSA; -#ifdef DYING -rpmgcImplVecs._pgpErrChk = rpmgcErrChk; -rpmgcImplVecs._pgpAvailableCipher = rpmgcAvailableCipher; -rpmgcImplVecs._pgpAvailableDigest = rpmgcAvailableDigest; -rpmgcImplVecs._pgpAvailablePubkey = rpmgcAvailablePubkey; - -rpmgcImplVecs._pgpVerify = rpmgcVerify; -rpmgcImplVecs._pgpSign = rpmgcSign; -rpmgcImplVecs._pgpGenerate = rpmgcGenerate; -#endif - pgpImplVecs = &rpmgcImplVecs; dig = pgpDigNew(0); @@ . ______________________________________________________________________ RPM Package Manager http://rpm5.org CVS Sources Repository [email protected]
