Module Name:    src
Committed By:   agc
Date:           Sat Mar 13 23:30:41 UTC 2010

Modified Files:
        src/crypto/external/bsd/netpgp/dist: TODO configure configure.ac tst
        src/crypto/external/bsd/netpgp/dist/include: netpgp.h
        src/crypto/external/bsd/netpgp/dist/src/lib: create.c keyring.c
            keyring.h netpgp.c packet-print.c packet.h reader.c ssh2pgp.c
            version.h
        src/crypto/external/bsd/netpgp/dist/src/netpgp: Makefile
        src/crypto/external/bsd/netpgp/dist/src/netpgpkeys: netpgpkeys.1
            netpgpkeys.c
        src/crypto/external/bsd/netpgp/dist/src/netpgpverify: Makefile verify.c
        src/crypto/external/bsd/netpgp/lib: config.h shlib_version

Log Message:
Changes to 2.99.1/20100313

+ add functionality to parse basic signature subkeys
+ in doing so, add expiration of keys
+ at the same time, add revocation of keys
+ recognise the primary user id, and use it when displaying user ids
+ recognise self signed keys and subkeys
+ rework the indentation of output
+ add the --list-sigs [userid] option to netpgpkeys(1)
+ use memcmp(3) rather than strcmp(3) when checking binary user ids to
  be exported
+ add expiration display to subkey signature output
+ update libnetpgp library version major number to 3


To generate a diff of this commit:
cvs rdiff -u -r1.34 -r1.35 src/crypto/external/bsd/netpgp/dist/TODO
cvs rdiff -u -r1.26 -r1.27 src/crypto/external/bsd/netpgp/dist/configure
cvs rdiff -u -r1.27 -r1.28 src/crypto/external/bsd/netpgp/dist/configure.ac
cvs rdiff -u -r1.20 -r1.21 src/crypto/external/bsd/netpgp/dist/tst
cvs rdiff -u -r1.16 -r1.17 \
    src/crypto/external/bsd/netpgp/dist/include/netpgp.h
cvs rdiff -u -r1.23 -r1.24 \
    src/crypto/external/bsd/netpgp/dist/src/lib/create.c
cvs rdiff -u -r1.32 -r1.33 \
    src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c
cvs rdiff -u -r1.22 -r1.23 \
    src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h
cvs rdiff -u -r1.42 -r1.43 \
    src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c
cvs rdiff -u -r1.28 -r1.29 \
    src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c
cvs rdiff -u -r1.19 -r1.20 \
    src/crypto/external/bsd/netpgp/dist/src/lib/packet.h
cvs rdiff -u -r1.31 -r1.32 \
    src/crypto/external/bsd/netpgp/dist/src/lib/reader.c
cvs rdiff -u -r1.8 -r1.9 \
    src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c
cvs rdiff -u -r1.29 -r1.30 \
    src/crypto/external/bsd/netpgp/dist/src/lib/version.h
cvs rdiff -u -r1.11 -r1.12 \
    src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile
cvs rdiff -u -r1.5 -r1.6 \
    src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1
cvs rdiff -u -r1.8 -r1.9 \
    src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c
cvs rdiff -u -r1.10 -r1.11 \
    src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile
cvs rdiff -u -r1.6 -r1.7 \
    src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c
cvs rdiff -u -r1.3 -r1.4 src/crypto/external/bsd/netpgp/lib/config.h \
    src/crypto/external/bsd/netpgp/lib/shlib_version

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/crypto/external/bsd/netpgp/dist/TODO
diff -u src/crypto/external/bsd/netpgp/dist/TODO:1.34 src/crypto/external/bsd/netpgp/dist/TODO:1.35
--- src/crypto/external/bsd/netpgp/dist/TODO:1.34	Mon Mar  8 07:37:23 2010
+++ src/crypto/external/bsd/netpgp/dist/TODO	Sat Mar 13 23:30:40 2010
@@ -1,13 +1,10 @@
 To Do
 =====
-add revocation information to public key display
 agent
 agentctl
-trust subpackets
 make netpgpkeys work - add, import, commit, update, sign, passphrase
 convert to and from ascii armored sigs
 gpgme compat lib
---list-sigs - these come out in __ops_check_subkey_sig()
 return userids from successful verify, and then print id out if required
 is get_passphrase_cb needed?
 error logging
@@ -93,3 +90,6 @@
 hkpclient
 netbsd/pkgsrc pr 42922
 add expiry information to public key display
+trust subpackets
+add revocation information to public key display
+--list-sigs - these come out in __ops_check_subkey_sig()

Index: src/crypto/external/bsd/netpgp/dist/configure
diff -u src/crypto/external/bsd/netpgp/dist/configure:1.26 src/crypto/external/bsd/netpgp/dist/configure:1.27
--- src/crypto/external/bsd/netpgp/dist/configure:1.26	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/configure	Sat Mar 13 23:30:40 2010
@@ -1,7 +1,7 @@
 #! /bin/sh
-# From configure.ac Revision: 1.26 .
+# From configure.ac Revision: 1.27 .
 # Guess values for system-dependent variables and create Makefiles.
-# Generated by GNU Autoconf 2.63 for netpgp 20100307.
+# Generated by GNU Autoconf 2.63 for netpgp 20100313.
 #
 # Report bugs to <Alistair Crooks <[email protected]> c0596823>.
 #
@@ -751,8 +751,8 @@
 # Identity of this package.
 PACKAGE_NAME='netpgp'
 PACKAGE_TARNAME='netpgp'
-PACKAGE_VERSION='20100307'
-PACKAGE_STRING='netpgp 20100307'
+PACKAGE_VERSION='20100313'
+PACKAGE_STRING='netpgp 20100313'
 PACKAGE_BUGREPORT='Alistair Crooks <[email protected]> c0596823'
 
 ac_unique_file="src/netpgp/netpgp.c"
@@ -1483,7 +1483,7 @@
   # Omit some internal or obsolete options to make the list less imposing.
   # This message is too long to be a string in the A/UX 3.1 sh.
   cat <<_ACEOF
-\`configure' configures netpgp 20100307 to adapt to many kinds of systems.
+\`configure' configures netpgp 20100313 to adapt to many kinds of systems.
 
 Usage: $0 [OPTION]... [VAR=VALUE]...
 
@@ -1553,7 +1553,7 @@
 
 if test -n "$ac_init_help"; then
   case $ac_init_help in
-     short | recursive ) echo "Configuration of netpgp 20100307:";;
+     short | recursive ) echo "Configuration of netpgp 20100313:";;
    esac
   cat <<\_ACEOF
 
@@ -1660,7 +1660,7 @@
 test -n "$ac_init_help" && exit $ac_status
 if $ac_init_version; then
   cat <<\_ACEOF
-netpgp configure 20100307
+netpgp configure 20100313
 generated by GNU Autoconf 2.63
 
 Copyright (C) 1992, 1993, 1994, 1995, 1996, 1998, 1999, 2000, 2001,
@@ -1674,7 +1674,7 @@
 This file contains any messages produced by compilers while
 running configure, to aid debugging if configure makes a mistake.
 
-It was created by netpgp $as_me 20100307, which was
+It was created by netpgp $as_me 20100313, which was
 generated by GNU Autoconf 2.63.  Invocation command line was
 
   $ $0 $@
@@ -2561,7 +2561,7 @@
 
 # Define the identity of the package.
  PACKAGE='netpgp'
- VERSION='20100307'
+ VERSION='20100313'
 
 
 cat >>confdefs.h <<_ACEOF
@@ -22306,7 +22306,7 @@
 # report actual input values of CONFIG_FILES etc. instead of their
 # values after options handling.
 ac_log="
-This file was extended by netpgp $as_me 20100307, which was
+This file was extended by netpgp $as_me 20100313, which was
 generated by GNU Autoconf 2.63.  Invocation command line was
 
   CONFIG_FILES    = $CONFIG_FILES
@@ -22369,7 +22369,7 @@
 _ACEOF
 cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
 ac_cs_version="\\
-netpgp config.status 20100307
+netpgp config.status 20100313
 configured by $0, generated by GNU Autoconf 2.63,
   with options \\"`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`\\"
 

Index: src/crypto/external/bsd/netpgp/dist/configure.ac
diff -u src/crypto/external/bsd/netpgp/dist/configure.ac:1.27 src/crypto/external/bsd/netpgp/dist/configure.ac:1.28
--- src/crypto/external/bsd/netpgp/dist/configure.ac:1.27	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/configure.ac	Sat Mar 13 23:30:40 2010
@@ -1,10 +1,10 @@
-# $NetBSD: configure.ac,v 1.27 2010/03/08 07:37:24 agc Exp $
+# $NetBSD: configure.ac,v 1.28 2010/03/13 23:30:40 agc Exp $
 #
 # Process this file with autoconf to produce a configure script.
 
-AC_INIT([netpgp],[20100307],[Alistair Crooks <[email protected]> c0596823])
+AC_INIT([netpgp],[20100313],[Alistair Crooks <[email protected]> c0596823])
 AC_PREREQ(2.63)
-AC_REVISION([$Revision: 1.27 $])
+AC_REVISION([$Revision: 1.28 $])
 
 AS_SHELL_SANITIZE
 

Index: src/crypto/external/bsd/netpgp/dist/tst
diff -u src/crypto/external/bsd/netpgp/dist/tst:1.20 src/crypto/external/bsd/netpgp/dist/tst:1.21
--- src/crypto/external/bsd/netpgp/dist/tst:1.20	Fri Mar  5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/tst	Sat Mar 13 23:30:40 2010
@@ -31,7 +31,7 @@
 	su root -c "make install"'
 
 passed=0
-total=26
+total=27
 echo "======> sign/verify 180938 file"
 cp configure a
 /usr/bin/netpgp --sign a
@@ -121,5 +121,7 @@
 /usr/bin/netpgp --sign --duration 2 --detached h
 sleep 3
 /usr/bin/netpgp --verify h.sig || passed=$(expr $passed + 1)
+echo "======> list signatures and subkey signatures"
+/usr/bin/netpgpkeys --list-sigs && passed=$(expr $passed + 1)
 rm -f a a.gpg b b.gpg c c.gpg d d.gpg e f f.sig g g.asc g2 a2 a3 a4 a5 h h.sig
 echo "Passed ${passed}/${total} tests"

Index: src/crypto/external/bsd/netpgp/dist/include/netpgp.h
diff -u src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.16 src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.17
--- src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.16	Fri Mar  5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/include/netpgp.h	Sat Mar 13 23:30:40 2010
@@ -72,7 +72,7 @@
 int netpgp_set_homedir(netpgp_t *, char *, const char *, const int);
 
 /* key management */
-int netpgp_list_keys(netpgp_t *);
+int netpgp_list_keys(netpgp_t *, const int);
 int netpgp_find_key(netpgp_t *, char *);
 char *netpgp_get_key(netpgp_t *, const char *, const char *);
 char *netpgp_export_key(netpgp_t *, char *);
@@ -92,7 +92,7 @@
 int netpgp_decrypt_memory(netpgp_t *, const void *, const size_t, char *, size_t, const int);
 
 /* match and hkp-related functions */
-int netpgp_match_keys(netpgp_t *, char *, const char *, void *);
+int netpgp_match_keys(netpgp_t *, char *, const char *, void *, const int);
 int netpgp_match_pubkeys(netpgp_t *, char *, void *);
 
 int netpgp_validate_sigs(netpgp_t *);

Index: src/crypto/external/bsd/netpgp/dist/src/lib/create.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.23 src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.24
--- src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.23	Fri Mar  5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/create.c	Sat Mar 13 23:30:41 2010
@@ -57,7 +57,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: create.c,v 1.23 2010/03/05 16:01:09 agc Exp $");
+__RCSID("$NetBSD: create.c,v 1.24 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #include <sys/types.h>
@@ -518,7 +518,7 @@
 
 unsigned 
 __ops_write_xfer_pubkey(__ops_output_t *output,
-			const __ops_key_t *keydata,
+			const __ops_key_t *key,
 			const unsigned armoured)
 {
 	unsigned    i, j;
@@ -527,30 +527,20 @@
 		__ops_writer_push_armoured(output, OPS_PGP_PUBLIC_KEY_BLOCK);
 	}
 	/* public key */
-	if (!write_struct_pubkey(output, &keydata->key.seckey.pubkey)) {
+	if (!write_struct_pubkey(output, &key->key.seckey.pubkey)) {
 		return 0;
 	}
 
 	/* TODO: revocation signatures go here */
 
 	/* user ids and corresponding signatures */
-	for (i = 0; i < keydata->uidc; i++) {
-		__ops_userid_t  *uid = &keydata->uids[i];
-
-		if (!__ops_write_struct_userid(output, uid)) {
+	for (i = 0; i < key->uidc; i++) {
+		if (!__ops_write_struct_userid(output, &key->uids[i])) {
 			return 0;
 		}
-
-		/* find signature for this packet if it exists */
-		for (j = 0; j < keydata->sigc; j++) {
-			sigpacket_t    *sig = &keydata->sigs[i];
-
-			if (strcmp((char *) sig->userid->userid,
-					(char *) uid->userid) == 0) {
-				if (!__ops_write(output, sig->packet->raw,
-						sig->packet->length)) {
-					return 0;
-				}
+		for (j = 0; j < key->packetc; j++) {
+			if (!__ops_write(output, key->packets[j].raw, key->packets[j].length)) {
+				return 0;
 			}
 		}
 	}
@@ -584,7 +574,7 @@
 
 unsigned 
 __ops_write_xfer_seckey(__ops_output_t *output,
-				const __ops_key_t *keydata,
+				const __ops_key_t *key,
 				const uint8_t *passphrase,
 				const size_t pplen,
 				unsigned armoured)
@@ -595,7 +585,7 @@
 		__ops_writer_push_armoured(output, OPS_PGP_PRIVATE_KEY_BLOCK);
 	}
 	/* public key */
-	if (!__ops_write_struct_seckey(&keydata->key.seckey, passphrase,
+	if (!__ops_write_struct_seckey(&key->key.seckey, passphrase,
 			pplen, output)) {
 		return 0;
 	}
@@ -603,23 +593,13 @@
 	/* TODO: revocation signatures go here */
 
 	/* user ids and corresponding signatures */
-	for (i = 0; i < keydata->uidc; i++) {
-		__ops_userid_t  *uid = &keydata->uids[i];
-
-		if (!__ops_write_struct_userid(output, uid)) {
+	for (i = 0; i < key->uidc; i++) {
+		if (!__ops_write_struct_userid(output, &key->uids[i])) {
 			return 0;
 		}
-
-		/* find signature for this packet if it exists */
-		for (j = 0; j < keydata->sigc; j++) {
-			sigpacket_t    *sig = &keydata->sigs[i];
-
-			if (strcmp((char *) sig->userid->userid,
-					(char *) uid->userid) == 0) {
-				if (!__ops_write(output, sig->packet->raw,
-						sig->packet->length)) {
-					return 0;
-				}
+		for (j = 0; j < key->packetc; j++) {
+			if (!__ops_write(output, key->packets[j].raw, key->packets[j].length)) {
+				return 0;
 			}
 		}
 	}

Index: src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.32 src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.33
--- src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.32	Fri Mar 12 01:22:01 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c	Sat Mar 13 23:30:41 2010
@@ -57,7 +57,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: keyring.c,v 1.32 2010/03/12 01:22:01 agc Exp $");
+__RCSID("$NetBSD: keyring.c,v 1.33 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #ifdef HAVE_FCNTL_H
@@ -480,36 +480,6 @@
 
 /**
 \ingroup Core_Keys
-\brief Add signed User ID to key
-\param keydata Key to which to add signed User ID
-\param userid User ID to add
-\param sigpacket Packet to add
-*/
-void 
-__ops_add_signed_userid(__ops_key_t *keydata,
-		const __ops_userid_t *userid,
-		const __ops_subpacket_t *sigpacket)
-{
-	__ops_subpacket_t	*pkt;
-	__ops_userid_t		*uid;
-
-	uid = __ops_add_userid(keydata, userid);
-	pkt = __ops_add_subpacket(keydata, sigpacket);
-
-	/*
-         * add entry in sigs array to link the userid and sigpacket
-	 * and add ptr to it from the sigs array */
-	EXPAND_ARRAY(keydata, sig);
-
-	/**setup new entry in array */
-	keydata->sigs[keydata->sigc].userid = uid;
-	keydata->sigs[keydata->sigc].packet = pkt;
-
-	keydata->sigc++;
-}
-
-/**
-\ingroup Core_Keys
 \brief Add selfsigned User ID to key
 \param keydata Key to which to add user ID
 \param userid Self-signed User ID to add
@@ -551,7 +521,8 @@
 	sigpacket.raw = __ops_mem_data(mem_sig);
 
 	/* add userid to keydata */
-	__ops_add_signed_userid(keydata, userid, &sigpacket);
+	(void) __ops_add_userid(keydata, userid);
+	(void) __ops_add_subpacket(keydata, &sigpacket);
 
 	/* cleanup */
 	__ops_create_sig_delete(sig);
@@ -583,7 +554,6 @@
 	}
 }
 
-
 /* used to point to data during keyring read */
 typedef struct keyringcb_t {
 	__ops_keyring_t		*keyring;	/* the keyring we're reading */
@@ -594,6 +564,8 @@
 cb_keyring_read(const __ops_packet_t *pkt, __ops_cbdata_t *cbinfo)
 {
 	__ops_keyring_t	*keyring;
+	__ops_revoke_t	*revocation;
+	__ops_key_t	*key;
 	keyringcb_t	*cb;
 
 	cb = __ops_callback_arg(cbinfo);
@@ -602,11 +574,27 @@
 	case OPS_PARSER_PTAG:
 	case OPS_PTAG_CT_ENCRYPTED_SECRET_KEY:
 		/* we get these because we didn't prompt */
+		break;
 	case OPS_PTAG_CT_SIGNATURE_HEADER:
-	case OPS_PTAG_CT_SIGNATURE_FOOTER:
+		key = &keyring->keys[keyring->keyc - 1];
+		EXPAND_ARRAY(key, subsig);
+		key->subsigs[key->subsigc].uid = key->uidc - 1;
+		(void) memcpy(&key->subsigs[key->subsigc].sig, &pkt->u.sig,
+				sizeof(pkt->u.sig));
+		key->subsigc += 1;
+		break;
 	case OPS_PTAG_CT_SIGNATURE:
+		key = &keyring->keys[keyring->keyc - 1];
+		EXPAND_ARRAY(key, subsig);
+		key->subsigs[key->subsigc].uid = key->uidc - 1;
+		(void) memcpy(&key->subsigs[key->subsigc].sig, &pkt->u.sig,
+				sizeof(pkt->u.sig));
+		key->subsigc += 1;
+		break;
 	case OPS_PTAG_CT_TRUST:
-	case OPS_PARSER_ERRCODE:
+		key = &keyring->keys[keyring->keyc - 1];
+		key->subsigs[key->subsigc - 1].trustlevel = pkt->u.ss_trust.level;
+		key->subsigs[key->subsigc - 1].trustamount = pkt->u.ss_trust.amount;
 		break;
 	case OPS_PTAG_SS_KEY_EXPIRY:
 		EXPAND_ARRAY(keyring, key);
@@ -614,6 +602,47 @@
 			keyring->keys[keyring->keyc - 1].key.pubkey.duration = pkt->u.ss_time.time;
 		}
 		break;
+	case OPS_PTAG_SS_ISSUER_KEY_ID:
+		key = &keyring->keys[keyring->keyc - 1];
+		(void) memcpy(&key->subsigs[key->subsigc - 1].sig.info.signer_id,
+			      pkt->u.ss_issuer.key_id,
+			      sizeof(pkt->u.ss_issuer.key_id));
+		key->subsigs[key->subsigc - 1].sig.info.signer_id_set = 1;
+		break;
+	case OPS_PTAG_SS_CREATION_TIME:
+		key = &keyring->keys[keyring->keyc - 1];
+		key->subsigs[key->subsigc - 1].sig.info.birthtime = pkt->u.ss_time.time;
+		key->subsigs[key->subsigc - 1].sig.info.birthtime_set = 1;
+		break;
+	case OPS_PTAG_SS_EXPIRATION_TIME:
+		key = &keyring->keys[keyring->keyc - 1];
+		key->subsigs[key->subsigc - 1].sig.info.duration = pkt->u.ss_time.time;
+		key->subsigs[key->subsigc - 1].sig.info.duration_set = 1;
+		break;
+	case OPS_PTAG_SS_PRIMARY_USER_ID:
+		key = &keyring->keys[keyring->keyc - 1];
+		key->uid0 = key->uidc - 1;
+		break;
+	case OPS_PTAG_SS_REVOCATION_REASON:
+		key = &keyring->keys[keyring->keyc - 1];
+		if (key->uidc == 0) {
+			/* revoke whole key */
+			key->revoked = 1;
+			revocation = &key->revocation;
+		} else {
+			/* revoke the user id */
+			EXPAND_ARRAY(key, revoke);
+			revocation = &key->revokes[key->revokec];
+			key->revokes[key->revokec].uid = key->uidc - 1;
+			key->revokec += 1;
+		}
+		revocation->code = pkt->u.ss_revocation.code;
+		revocation->reason = netpgp_strdup(__ops_show_ss_rr_code(pkt->u.ss_revocation.code));
+		break;
+	case OPS_PTAG_CT_SIGNATURE_FOOTER:
+	case OPS_PARSER_ERRCODE:
+		break;
+
 	default:
 		break;
 	}
@@ -968,7 +997,7 @@
    \return none
 */
 int
-__ops_keyring_list(__ops_io_t *io, const __ops_keyring_t *keyring)
+__ops_keyring_list(__ops_io_t *io, const __ops_keyring_t *keyring, const int psigs)
 {
 	__ops_key_t		*key;
 	unsigned		 n;
@@ -977,16 +1006,17 @@
 		(keyring->keyc == 1) ? "" : "s");
 	for (n = 0, key = keyring->keys; n < keyring->keyc; ++n, ++key) {
 		if (__ops_is_key_secret(key)) {
-			__ops_print_keydata(io, key, "sec",
-				&key->key.seckey.pubkey);
+			__ops_print_keydata(io, keyring, key, "sec",
+				&key->key.seckey.pubkey, 0);
 		} else {
-			__ops_print_keydata(io, key, "pub", &key->key.pubkey);
+			__ops_print_keydata(io, keyring, key, "pub", &key->key.pubkey, psigs);
 		}
 		(void) fputc('\n', io->res);
 	}
 	return 1;
 }
 
+
 /* this interface isn't right - hook into callback for getting passphrase */
 char *
 __ops_export_key(__ops_io_t *io, const __ops_key_t *keydata, uint8_t *passphrase)

Index: src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.22 src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.23
--- src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.22	Fri Mar  5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h	Sat Mar 13 23:30:41 2010
@@ -93,7 +93,7 @@
 unsigned   __ops_keyring_fileread(__ops_keyring_t *, const unsigned,
 					const char *);
 
-int __ops_keyring_list(__ops_io_t *, const __ops_keyring_t *);
+int __ops_keyring_list(__ops_io_t *, const __ops_keyring_t *, const int);
 
 void __ops_set_seckey(__ops_contents_t *, const __ops_key_t *);
 void __ops_forget(void *, unsigned);
@@ -106,9 +106,6 @@
 __ops_userid_t *__ops_add_userid(__ops_key_t *, const __ops_userid_t *);
 __ops_subpacket_t *__ops_add_subpacket(__ops_key_t *,
 						const __ops_subpacket_t *);
-void __ops_add_signed_userid(__ops_key_t *,
-					const __ops_userid_t *,
-					const __ops_subpacket_t *);
 
 unsigned __ops_add_selfsigned_userid(__ops_key_t *, __ops_userid_t *);
 
@@ -119,12 +116,15 @@
 
 void __ops_pkeyid(FILE *, const uint8_t *, size_t);
 
-int __ops_sprint_keydata(const __ops_key_t *, char **, const char *,
-			const __ops_pubkey_t *);
+int __ops_sprint_keydata(__ops_io_t *, const __ops_keyring_t *,
+			const __ops_key_t *, char **, const char *,
+			const __ops_pubkey_t *, const int);
 int __ops_hkp_sprint_keydata(const __ops_key_t *, char **,
 			const __ops_pubkey_t *);
-void __ops_print_keydata(__ops_io_t *, const __ops_key_t *,
-			const char *, const __ops_pubkey_t *);
+void __ops_print_keydata(__ops_io_t *, const __ops_keyring_t *, const __ops_key_t *,
+			const char *, const __ops_pubkey_t *, const int);
+void __ops_print_sig(__ops_io_t *, const __ops_key_t *, const char *,
+			const __ops_pubkey_t *);
 void __ops_print_pubkey(const __ops_pubkey_t *);
 int __ops_sprint_pubkey(const __ops_key_t *, char *, size_t);
 

Index: src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.42 src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.43
--- src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.42	Fri Mar  5 16:30:05 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c	Sat Mar 13 23:30:41 2010
@@ -34,7 +34,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: netpgp.c,v 1.42 2010/03/05 16:30:05 agc Exp $");
+__RCSID("$NetBSD: netpgp.c,v 1.43 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #include <sys/types.h>
@@ -163,7 +163,7 @@
 		pubkey = __ops_getkeybyid(io, ring,
 			(const uint8_t *) res->valid_sigs[i].signer_id,
 			&from);
-		__ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+		__ops_print_keydata(io, ring, pubkey, "pub", &pubkey->key.pubkey, 0);
 	}
 }
 
@@ -534,9 +534,9 @@
 
 /* list the keys in a keyring */
 int
-netpgp_list_keys(netpgp_t *netpgp)
+netpgp_list_keys(netpgp_t *netpgp, const int psigs)
 {
-	return __ops_keyring_list(netpgp->io, netpgp->pubring);
+	return __ops_keyring_list(netpgp->io, netpgp->pubring, psigs);
 }
 
 DEFINE_ARRAY(strings_t, char *);
@@ -547,7 +547,7 @@
 
 /* find and list some keys in a keyring */
 int
-netpgp_match_keys(netpgp_t *netpgp, char *name, const char *fmt, void *vp)
+netpgp_match_keys(netpgp_t *netpgp, char *name, const char *fmt, void *vp, const int psigs)
 {
 	const __ops_key_t	*key;
 	unsigned		 k;
@@ -570,10 +570,10 @@
 						key, &pubs.v[pubs.c],
 						&key->key.pubkey);
 			} else {
-				__ops_sprint_keydata(
+				__ops_sprint_keydata(netpgp->io, netpgp->pubring,
 						key, &pubs.v[pubs.c],
 						"pub",
-						&key->key.pubkey);
+						&key->key.pubkey, psigs);
 			}
 			pubs.c += 1;
 			k += 1;
@@ -662,8 +662,9 @@
 		return (__ops_hkp_sprint_keydata(key, &newkey,
 				&key->key.pubkey) > 0) ? newkey : NULL;
 	}
-	return (__ops_sprint_keydata(key, &newkey, "pub",
-				&key->key.pubkey) > 0) ? newkey : NULL;
+	return (__ops_sprint_keydata(netpgp->io, netpgp->pubring,
+				key, &newkey, "pub",
+				&key->key.pubkey, 0) > 0) ? newkey : NULL;
 }
 
 /* export a given key */
@@ -706,7 +707,7 @@
 				f);
 		return 0;
 	}
-	return __ops_keyring_list(io, netpgp->pubring);
+	return __ops_keyring_list(io, netpgp->pubring, 0);
 }
 
 /* generate a new key */
@@ -876,10 +877,10 @@
 			if (pubkey == NULL) {
 				(void) fprintf(io->errs,
 					"netpgp: warning - using pubkey from secring\n");
-				__ops_print_keydata(io, keypair, "pub",
-					&keypair->key.seckey.pubkey);
+				__ops_print_keydata(io, netpgp->pubring, keypair, "pub",
+					&keypair->key.seckey.pubkey, 0);
 			} else {
-				__ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+				__ops_print_keydata(io, netpgp->pubring, pubkey, "pub", &pubkey->key.pubkey, 0);
 			}
 		}
 		if (netpgp_getvar(netpgp, "ssh keys") == NULL) {
@@ -989,10 +990,10 @@
 			if (pubkey == NULL) {
 				(void) fprintf(io->errs,
 					"netpgp: warning - using pubkey from secring\n");
-				__ops_print_keydata(io, keypair, "pub",
-					&keypair->key.seckey.pubkey);
+				__ops_print_keydata(io, netpgp->pubring, keypair, "pub",
+					&keypair->key.seckey.pubkey, 0);
 			} else {
-				__ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+				__ops_print_keydata(io, netpgp->pubring, pubkey, "pub", &pubkey->key.pubkey, 0);
 			}
 		}
 		/* now decrypt key */

Index: src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.28 src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.29
--- src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.28	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c	Sat Mar 13 23:30:41 2010
@@ -58,7 +58,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: packet-print.c,v 1.28 2010/03/08 07:37:24 agc Exp $");
+__RCSID("$NetBSD: packet-print.c,v 1.29 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #include <string.h>
@@ -382,28 +382,60 @@
 	return dest;
 }
 
+/* print the sub key binding signature info */
+static int
+psubkeybinding(char *buf, size_t size, __ops_subsig_t *subsig, const __ops_pubkey_t *pubkey, char *expired)
+{
+	char	keyid[512];
+	char	t[32];
+
+	return snprintf(buf, size, "sub %d/%s %s %s %s\n",
+		numkeybits(pubkey),
+		__ops_show_pka(subsig->sig.info.key_alg),
+		strhexdump(keyid, subsig->sig.info.signer_id, OPS_KEY_ID_SIZE, ""),
+		ptimestr(t, sizeof(t), subsig->sig.info.birthtime),
+		expired);
+}
+
+static int
+isrevoked(const __ops_key_t *key, unsigned uid)
+{
+	unsigned	r;
+
+	for (r = 0 ; r < key->revokec ; r++) {
+		if (key->revokes[r].uid == uid) {
+			return r;
+		}
+	}
+	return -1;
+}
+
 #ifndef KB
 #define KB(x)	((x) * 1024)
 #endif
 
 /* print into a string (malloc'ed) the pubkeydata */
 int
-__ops_sprint_keydata(const __ops_key_t *key, char **buf, const char *header,
-		const __ops_pubkey_t *pubkey)
-{
-	unsigned	 i;
-	time_t		 now;
-	char		 uidbuf[KB(128)];
-	char		 keyid[OPS_KEY_ID_SIZE * 3];
-	char		 fp[(OPS_FINGERPRINT_SIZE * 3) + 1];
-	char		 expired[128];
-	char		 t[32];
-	int		 cc;
-	int		 n;
+__ops_sprint_keydata(__ops_io_t *io, const __ops_keyring_t *keyring,
+		const __ops_key_t *key, char **buf, const char *header,
+		const __ops_pubkey_t *pubkey, const int psigs)
+{
+	const __ops_key_t	*trustkey;
+	unsigned	 	 from;
+	unsigned		 i;
+	unsigned		 j;
+	time_t			 now;
+	char			 uidbuf[KB(128)];
+	char			 keyid[OPS_KEY_ID_SIZE * 3];
+	char			 fp[(OPS_FINGERPRINT_SIZE * 3) + 1];
+	char			 expired[128];
+	char			 t[32];
+	int			 cc;
+	int			 n;
+	int			 r;
 
-	for (i = 0, n = 0; i < key->uidc; i++) {
-		n += snprintf(&uidbuf[n], sizeof(uidbuf) - n,
-			"uid              %s\n", key->uids[i].userid);
+	if (key->revoked) {
+		return -1;
 	}
 	now = time(NULL);
 	if (pubkey->duration > 0) {
@@ -417,6 +449,41 @@
 	} else {
 		expired[0] = 0x0;
 	}
+	for (i = 0, n = 0; i < key->uidc; i++) {
+		if ((r = isrevoked(key, i)) >= 0 &&
+		    key->revokes[r].code == OPS_REVOCATION_COMPROMISED) {
+			continue;
+		}
+		n += snprintf(&uidbuf[n], sizeof(uidbuf) - n, "uid%s%s%s\n",
+				(psigs) ? "    " : "              ",
+				key->uids[i].userid,
+				(isrevoked(key, i) >= 0) ? " [REVOKED]" : "");
+		for (j = 0 ; j < key->subsigc ; j++) {
+			if (psigs) {
+				if (key->subsigs[j].uid != i) {
+					continue;
+				}
+			} else {
+				if (!(key->subsigs[j].sig.info.version == 4 &&
+					key->subsigs[j].sig.info.type == OPS_SIG_SUBKEY &&
+					i == key->uidc - 1)) {
+						continue;
+				}
+			}
+			from = 0;
+			trustkey = __ops_getkeybyid(io, keyring, key->subsigs[j].sig.info.signer_id, &from);
+			if (key->subsigs[j].sig.info.version == 4 &&
+					key->subsigs[j].sig.info.type == OPS_SIG_SUBKEY) {
+				psubkeybinding(&uidbuf[n], sizeof(uidbuf) - n, &key->subsigs[j], pubkey, expired);
+			} else {
+				n += snprintf(&uidbuf[n], sizeof(uidbuf) - n,
+					"sig        %s  %s  %s\n",
+					strhexdump(keyid, key->subsigs[j].sig.info.signer_id, OPS_KEY_ID_SIZE, ""),
+					ptimestr(t, sizeof(t), key->subsigs[j].sig.info.birthtime),
+					(trustkey) ? (char *)trustkey->uids[trustkey->uid0].userid : "[unknown]");
+			}
+		}
+	}
 	return __ops_asprintf(buf, "%s %d/%s %s %s %s\nKey fingerprint: %s\n%s",
 		header,
 		numkeybits(pubkey),
@@ -455,12 +522,13 @@
 
 /* print the key data for a pub or sec key */
 void
-__ops_print_keydata(__ops_io_t *io, const __ops_key_t *key, const char *header,
-		const __ops_pubkey_t *pubkey)
+__ops_print_keydata(__ops_io_t *io, const __ops_keyring_t *keyring,
+		const __ops_key_t *key, const char *header,
+		const __ops_pubkey_t *pubkey, const int psigs)
 {
 	char	*cp;
 
-	if (__ops_sprint_keydata(key, &cp, header, pubkey)) {
+	if (__ops_sprint_keydata(io, keyring, key, &cp, header, pubkey, psigs) >= 0) {
 		(void) fprintf(io->res, "%s", cp);
 		free(cp);
 	}

Index: src/crypto/external/bsd/netpgp/dist/src/lib/packet.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.19 src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.20
--- src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.19	Fri Mar  5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/packet.h	Sat Mar 13 23:30:41 2010
@@ -296,6 +296,14 @@
 					 * with errcode returned */
 } __ops_content_tag_t;
 
+enum {
+	OPS_REVOCATION_NO_REASON	= 0,
+	OPS_REVOCATION_SUPERSEDED	= 1,
+	OPS_REVOCATION_COMPROMISED	= 2,
+	OPS_REVOCATION_RETIRED		= 3,
+	OPS_REVOCATION_NO_LONGER_VALID	= 0x20
+};
+
 typedef __ops_content_tag_t __ops_packet_tag_t;
 typedef __ops_content_tag_t __ops_ss_type_t;
 
@@ -757,7 +765,6 @@
 } __ops_ss_embedded_sig_t;
 
 /** __ops_subpacket_t */
-
 typedef struct __ops_subpacket_t {
 	size_t          length;
 	uint8_t		*raw;
@@ -1077,12 +1084,18 @@
 #define EXPAND_ARRAY(str, arr) do {					\
 	if (str->arr##c == str->arr##vsize) {				\
 		void	*__newarr;					\
-		str->arr##vsize = (str->arr##vsize * 2) + 10; 		\
-		if ((__newarr = realloc(str->arr##s,			\
-			str->arr##vsize * sizeof(*str->arr##s))) == NULL) { \
+		char	*__newarrc;					\
+		unsigned	__newsize;				\
+		__newsize = (str->arr##vsize * 2) + 10; 		\
+		if ((__newarrc = __newarr = realloc(str->arr##s,	\
+			__newsize * sizeof(*str->arr##s))) == NULL) {	\
 			(void) fprintf(stderr, "EXPAND_ARRAY - bad realloc\n"); \
+		} else {						\
+			(void) memset(&__newarrc[str->arr##vsize * sizeof(*str->arr##s)], \
+				0x0, (__newsize - str->arr##vsize) * sizeof(*str->arr##s)); \
+			str->arr##s = __newarr;				\
+			str->arr##vsize = __newsize;			\
 		}							\
-		str->arr##s = __newarr;					\
 	}								\
 } while(/*CONSTCOND*/0)
 
@@ -1094,24 +1107,40 @@
 } __ops_keydata_key_t;
 
 
-/** sigpacket_t */
+/* sigpacket_t */
 typedef struct {
 	__ops_userid_t		*userid;
 	__ops_subpacket_t	*packet;
 } sigpacket_t;
 
-/* XXX: gonna have to expand this to hold onto subkeys, too... */
-/** \struct __ops_keydata
- * \todo expand to hold onto subkeys
- */
+/* user revocation info */
+typedef struct __ops_revoke_t {
+	uint32_t		 uid;		/* index in uid array */
+	uint8_t			 code;		/* revocation code */
+	char			*reason;	/* c'mon, spill the beans */
+} __ops_revoke_t;
+
+/** signature subpackets */
+typedef struct __ops_subsig_t {
+	uint32_t		uid;		/* index in userid array in key */
+	__ops_sig_t		sig;		/* trust signature */
+	uint8_t			trustlevel;	/* level of trust */
+	uint8_t			trustamount;	/* amount of trust */
+} __ops_subsig_t;
+
+/* describes a user's key */
 struct __ops_key_t {
-	DYNARRAY(__ops_userid_t, uid);
-	DYNARRAY(__ops_subpacket_t, packet);
-	DYNARRAY(sigpacket_t, sig);
+	DYNARRAY(__ops_userid_t, uid);		/* array of user ids */
+	DYNARRAY(__ops_subpacket_t, packet);	/* array of raw subpackets */
+	DYNARRAY(__ops_subsig_t, subsig);	/* array of signature subkeys */
+	DYNARRAY(__ops_revoke_t, revoke);	/* array of signature revocations */
 	uint8_t			key_id[OPS_KEY_ID_SIZE];
-	__ops_fingerprint_t	fingerprint;
-	__ops_content_tag_t	type;
-	__ops_keydata_key_t	key;
+	__ops_fingerprint_t	fingerprint;	/* pgp fingerprint */
+	__ops_content_tag_t	type;		/* type of key */
+	__ops_keydata_key_t	key;		/* pubkey/seckey data */
+	uint32_t		uid0;		/* primary uid index in uids array */
+	uint8_t			revoked;
+	__ops_revoke_t		revocation;
 };
 
 #define MDC_PKT_TAG	0xd3

Index: src/crypto/external/bsd/netpgp/dist/src/lib/reader.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.31 src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.32
--- src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.31	Fri Mar  5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/reader.c	Sat Mar 13 23:30:41 2010
@@ -54,7 +54,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: reader.c,v 1.31 2010/03/05 16:01:10 agc Exp $");
+__RCSID("$NetBSD: reader.c,v 1.32 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #include <sys/types.h>
@@ -2243,7 +2243,7 @@
 		keypair = cbinfo->cryptinfo.keydata;
 		do {
 			/* print out the user id */
-			__ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+			__ops_print_keydata(io, cbinfo->cryptinfo.pubring,pubkey, "pub", &pubkey->key.pubkey, 0);
 			/* now decrypt key */
 			secret = __ops_decrypt_seckey(keypair, cbinfo->passfp);
 			if (secret == NULL) {
@@ -2279,8 +2279,8 @@
 	if (cbinfo->cryptinfo.keydata == NULL) {
 		(void) fprintf(io->errs, "get_passphrase_cb: NULL keydata\n");
 	} else {
-		__ops_print_keydata(io, cbinfo->cryptinfo.keydata, "pub",
-			&cbinfo->cryptinfo.keydata->key.pubkey);
+		__ops_print_keydata(io, cbinfo->cryptinfo.pubring, cbinfo->cryptinfo.keydata, "pub",
+			&cbinfo->cryptinfo.keydata->key.pubkey, 0);
 	}
 	switch (pkt->tag) {
 	case OPS_GET_PASSPHRASE:

Index: src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.8 src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.9
--- src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.8	Fri Mar  5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c	Sat Mar 13 23:30:41 2010
@@ -333,7 +333,8 @@
 		__ops_fingerprint(&key->fingerprint, pubkey);
 		free(userid.userid);
 		if (__ops_get_debug_level(__FILE__)) {
-			__ops_print_keydata(io, key, "pub", pubkey);
+			/*__ops_print_keydata(io, keyring, key, "pub", pubkey, 0);*/
+			__OPS_USED(io); /* XXX */
 		}
 	}
 	(void) free(bin);
@@ -358,7 +359,8 @@
 		return 0;
 	}
 	if (__ops_get_debug_level(__FILE__)) {
-		__ops_print_keydata(io, key, "sec", &key->key.seckey.pubkey);
+		/*__ops_print_keydata(io, key, "sec", &key->key.seckey.pubkey, 0);*/
+		/* XXX */
 	}
 	/* let's add some sane defaults */
 	(void) memcpy(&key->key.seckey.pubkey, pubkey, sizeof(*pubkey));

Index: src/crypto/external/bsd/netpgp/dist/src/lib/version.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.29 src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.30
--- src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.29	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/version.h	Sat Mar 13 23:30:41 2010
@@ -58,7 +58,7 @@
 #endif
 
 /* development versions have .99 suffix */
-#define NETPGP_BASE_VERSION	"1.99.22"
+#define NETPGP_BASE_VERSION	"2.99.1"
 
 #define NETPGP_VERSION_CAT(a, b)	"NetPGP portable " a "/[" b "]"
 #define NETPGP_VERSION_STRING \

Index: src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.11 src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.12
--- src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.11	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile	Sat Mar 13 23:30:41 2010
@@ -117,16 +117,16 @@
 PACKAGE = netpgp
 PACKAGE_BUGREPORT = Alistair Crooks <[email protected]> c0596823
 PACKAGE_NAME = netpgp
-PACKAGE_STRING = netpgp 20100307
+PACKAGE_STRING = netpgp 20100313
 PACKAGE_TARNAME = netpgp
-PACKAGE_VERSION = 20100307
+PACKAGE_VERSION = 20100313
 PATH_SEPARATOR = :
 RANLIB = ranlib
 SED = /usr/bin/sed
 SET_MAKE = 
 SHELL = /bin/ksh
 STRIP = strip
-VERSION = 20100307
+VERSION = 20100313
 WARNCFLAGS = -Werror -Wall -Wpointer-arith
 abs_builddir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgp
 abs_srcdir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgp

Index: src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.5 src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.6
--- src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.5	Sat Feb  6 02:24:34 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1	Sat Mar 13 23:30:41 2010
@@ -1,6 +1,6 @@
-.\" $NetBSD: netpgpkeys.1,v 1.5 2010/02/06 02:24:34 agc Exp $
+.\" $NetBSD: netpgpkeys.1,v 1.6 2010/03/13 23:30:41 agc Exp $
 .\"
-.\" Copyright (c) 2009 The NetBSD Foundation, Inc.
+.\" Copyright (c) 2009, 2010 The NetBSD Foundation, Inc.
 .\" All rights reserved.
 .\"
 .\" This manual page is derived from software contributed to
@@ -27,7 +27,7 @@
 .\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
 .\" POSSIBILITY OF SUCH DAMAGE.
 .\"
-.Dd December 4, 2009
+.Dd March 13, 2010
 .Dt NETPGPKEYS 1
 .Os
 .Sh NAME
@@ -55,6 +55,10 @@
 .Op options
 .Ar file ...
 .Nm
+.Fl Fl list-sigs
+.Op options
+.Ar file ...
+.Nm
 .Fl Fl version
 .Pp
 where the options for all commands are:
@@ -165,6 +169,10 @@
 .It Fl Fl list-keys
 List all the public keys in the current keyring.
 If no keyring is provided, the user's public keyring is used.
+.It Fl Fl list-sigs
+List all the public keys in the current keyring, along with
+the sub-key signatures which provide the key with trust.
+If no keyring is provided, the user's public keyring is used.
 .It Fl Fl version
 Print the version information from the
 .Xr libnetpgp 3

Index: src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.8 src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.9
--- src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.8	Fri Mar  5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c	Sat Mar 13 23:30:41 2010
@@ -53,6 +53,7 @@
 	"\t--generate-key [options] OR\n"
 	"\t--import-key [options] OR\n"
 	"\t--list-keys [options] OR\n"
+	"\t--list-sigs [options] OR\n"
 	"\t--get-key keyid [options] OR\n"
 	"\t--version\n"
 	"where options are:\n"
@@ -65,6 +66,7 @@
 enum optdefs {
 	/* commands */
 	LIST_KEYS = 1,
+	LIST_SIGS,
 	FIND_KEY,
 	EXPORT_KEY,
 	IMPORT_KEY,
@@ -95,6 +97,7 @@
 static struct option options[] = {
 	/* key-management commands */
 	{"list-keys",	no_argument,		NULL,	LIST_KEYS},
+	{"list-sigs",	no_argument,		NULL,	LIST_SIGS},
 	{"find-key",	no_argument,		NULL,	FIND_KEY},
 	{"export-key",	no_argument,		NULL,	EXPORT_KEY},
 	{"import-key",	no_argument,		NULL,	IMPORT_KEY},
@@ -148,7 +151,9 @@
 
 	switch (p->cmd) {
 	case LIST_KEYS:
-		return (f == NULL) ? netpgp_list_keys(netpgp) : netpgp_match_keys(netpgp, f, "human", stdout);
+		return (f == NULL) ? netpgp_list_keys(netpgp, 0) : netpgp_match_keys(netpgp, f, "human", stdout, 0);
+	case LIST_SIGS:
+		return (f == NULL) ? netpgp_list_keys(netpgp, 1) : netpgp_match_keys(netpgp, f, "human", stdout, 1);
 	case FIND_KEY:
 		return netpgp_find_key(netpgp, netpgp_getvar(netpgp, "userid"));
 	case EXPORT_KEY:
@@ -205,9 +210,6 @@
 	optindex = 0;
 	while ((ch = getopt_long(argc, argv, "", options, &optindex)) != -1) {
 		switch (options[optindex].val) {
-		case LIST_KEYS:
-			p.cmd = options[optindex].val;
-			break;
 		case COREDUMPS:
 			netpgp_setvar(&netpgp, "coredumps", "allowed");
 			p.cmd = options[optindex].val;
@@ -216,6 +218,8 @@
 			netpgp_setvar(&netpgp, "userid checks", "skip");
 			p.cmd = options[optindex].val;
 			break;
+		case LIST_KEYS:
+		case LIST_SIGS:
 		case FIND_KEY:
 		case EXPORT_KEY:
 		case IMPORT_KEY:

Index: src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.10 src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.11
--- src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.10	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile	Sat Mar 13 23:30:41 2010
@@ -117,16 +117,16 @@
 PACKAGE = netpgp
 PACKAGE_BUGREPORT = Alistair Crooks <[email protected]> c0596823
 PACKAGE_NAME = netpgp
-PACKAGE_STRING = netpgp 20100307
+PACKAGE_STRING = netpgp 20100313
 PACKAGE_TARNAME = netpgp
-PACKAGE_VERSION = 20100307
+PACKAGE_VERSION = 20100313
 PATH_SEPARATOR = :
 RANLIB = ranlib
 SED = /usr/bin/sed
 SET_MAKE = 
 SHELL = /bin/ksh
 STRIP = strip
-VERSION = 20100307
+VERSION = 20100313
 WARNCFLAGS = -Werror -Wall -Wpointer-arith
 abs_builddir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgpverify
 abs_srcdir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgpverify

Index: src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.6 src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.7
--- src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.6	Mon Mar  8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c	Sat Mar 13 23:30:41 2010
@@ -55,7 +55,7 @@
 
 #if defined(__NetBSD__)
 __COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: verify.c,v 1.6 2010/03/08 07:37:24 agc Exp $");
+__RCSID("$NetBSD: verify.c,v 1.7 2010/03/13 23:30:41 agc Exp $");
 #endif
 
 #include <sys/types.h>
@@ -161,7 +161,7 @@
 #undef USE_SHA384
 
 /* development versions have .99 suffix */
-#define NETPGP_BASE_VERSION	"1.99.22"
+#define NETPGP_BASE_VERSION	"2.99.1"
 
 #define NETPGP_VERSION_CAT(a, b)	"NetPGP portable " a "/[" b "]"
 #define NETPGP_VERSION_STRING \

Index: src/crypto/external/bsd/netpgp/lib/config.h
diff -u src/crypto/external/bsd/netpgp/lib/config.h:1.3 src/crypto/external/bsd/netpgp/lib/config.h:1.4
--- src/crypto/external/bsd/netpgp/lib/config.h:1.3	Tue Dec 22 06:03:25 2009
+++ src/crypto/external/bsd/netpgp/lib/config.h	Sat Mar 13 23:30:41 2010
@@ -125,19 +125,19 @@
 #define PACKAGE_NAME "netpgp"
 
 /* Define to the full name and version of this package. */
-#define PACKAGE_STRING "netpgp 20091221"
+#define PACKAGE_STRING "netpgp 20100313"
 
 /* Define to the one symbol short name of this package. */
 #define PACKAGE_TARNAME "netpgp"
 
 /* Define to the version of this package. */
-#define PACKAGE_VERSION "20091221"
+#define PACKAGE_VERSION "20100313"
 
 /* Define to 1 if you have the ANSI C header files. */
 #define STDC_HEADERS 1
 
 /* Version number of package */
-#define VERSION "20091221"
+#define VERSION "20100313"
 
 /* Define for Solaris 2.5.1 so the uint32_t typedef from <sys/synch.h>,
    <pthread.h>, or <semaphore.h> is not used. If the typedef were allowed, the
Index: src/crypto/external/bsd/netpgp/lib/shlib_version
diff -u src/crypto/external/bsd/netpgp/lib/shlib_version:1.3 src/crypto/external/bsd/netpgp/lib/shlib_version:1.4
--- src/crypto/external/bsd/netpgp/lib/shlib_version:1.3	Mon Jul 20 17:30:52 2009
+++ src/crypto/external/bsd/netpgp/lib/shlib_version	Sat Mar 13 23:30:41 2010
@@ -1,2 +1,2 @@
-major=2
+major=3
 minor=0

Reply via email to