openpgp: Store the issuer key id and fingerprint in <openpgp-signature>.

* guix/openpgp.scm (<openpgp-signature>)[issuer, issuer-fingerprint]:
New fields.
(openpgp-signature-issuer, openpgp-signature-issuer-fingerprint): Remove.
(verify-openpgp-signature): Use 'openpgp-signature-issuer-key-id'.
(get-signature): Initialize 'issuer' and 'issuer-fingerprint'.
* tests/openpgp.scm ("get-openpgp-detached-signature/ascii"): Adjust
accordingly.
This commit is contained in:
Ludovic Courtès 2020-04-26 16:03:46 +02:00
parent 4459c7859c
commit 7b2b3a13cc
No known key found for this signature in database
GPG key ID: 090B11993D9AEBB5
2 changed files with 11 additions and 19 deletions

View file

@ -32,7 +32,7 @@ (define-module (guix openpgp)
port-ascii-armored?
openpgp-signature?
openpgp-signature-issuer
openpgp-signature-issuer-key-id
openpgp-signature-issuer-fingerprint
openpgp-signature-public-key-algorithm
openpgp-signature-hash-algorithm
@ -469,7 +469,7 @@ (define-record-type <openpgp-public-key>
(define-record-type <openpgp-signature>
(make-openpgp-signature version type pk-algorithm hash-algorithm hashl16
append-data hashed-subpackets unhashed-subpackets
value)
value issuer issuer-fingerprint)
openpgp-signature?
(version openpgp-signature-version)
(type openpgp-signature-type)
@ -479,19 +479,9 @@ (define-record-type <openpgp-signature>
(append-data openpgp-signature-append-data) ;append to data when hashing
(hashed-subpackets openpgp-signature-hashed-subpackets)
(unhashed-subpackets openpgp-signature-unhashed-subpackets)
(value openpgp-signature-value))
(define (openpgp-signature-issuer sig)
(cond ((assq 'issuer (openpgp-signature-unhashed-subpackets sig)) => cdr)
;; XXX: is the issuer always in the unhashed subpackets?
(else #f)))
(define (openpgp-signature-issuer-fingerprint sig)
"When it's available, return the fingerprint, a bytevector, or the issuer of
SIG. Otherwise, return #f."
(or (assoc-ref (openpgp-signature-hashed-subpackets sig) 'issuer-fingerprint)
(assoc-ref (openpgp-signature-unhashed-subpackets sig)
'issuer-fingerprint)))
(value openpgp-signature-value)
(issuer openpgp-signature-issuer-key-id) ;integer | #f
(issuer-fingerprint openpgp-signature-issuer-fingerprint)) ;bytevector | #f
(define (openpgp-signature-creation-time sig)
(cond ((assq 'signature-ctime (openpgp-signature-hashed-subpackets sig))
@ -573,7 +563,7 @@ (define (check key sig)
;; TODO: Support SIGNATURE-TEXT.
(if (= (openpgp-signature-type sig) SIGNATURE-BINARY)
(let* ((issuer (openpgp-signature-issuer sig))
(let* ((issuer (openpgp-signature-issuer-key-id sig))
(key-data (lookup-key-by-id keyring issuer)))
;; Find the primary key or subkey that made the signature.
(let ((key (find (lambda (k)
@ -651,7 +641,8 @@ (define (bytevector->hex bv)
(list (cons 'signature-ctime ctime))
;; Unhashed subpackets
(list (cons 'issuer keyid))
value))))
value
keyid #f))))
((4)
(let*-values (((type pkalg halg) (get-integers p u8 u8 u8))
((hashed-subpackets)
@ -697,7 +688,8 @@ (define (bytevector->hex bv)
append-data
hashed-subpackets
unhashed-subpackets
value)))))
value
issuer-key-id issuer)))))
(else
(print "Unsupported signature version: " version)
'unsupported-signature-version))))

View file

@ -179,7 +179,7 @@ (define %hello-signature/ed25519/sha1 ;digest-algo: sha1
(map (lambda (str)
(let ((signature (get-openpgp-detached-signature/ascii
(open-input-string str))))
(list (openpgp-signature-issuer signature)
(list (openpgp-signature-issuer-key-id signature)
(openpgp-signature-issuer-fingerprint signature)
(openpgp-signature-public-key-algorithm signature)
(openpgp-signature-hash-algorithm signature))))