2 * keydb_fs.c - Routines to store and fetch keys in a filesystem hierarchy.
4 * Copyright 2004 Daniel Silverstone <dsilvers@digital-scurf.org>
6 * This program is free software: you can redistribute it and/or modify it
7 * under the terms of the GNU General Public License as published by the Free
8 * Software Foundation; version 2 of the License.
10 * This program is distributed in the hope that it will be useful, but WITHOUT
11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
15 * You should have received a copy of the GNU General Public License along with
16 * this program; if not, write to the Free Software Foundation, Inc., 51
17 * Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
20 #include <sys/types.h>
32 #include "charfuncs.h"
33 #include "decodekey.h"
36 #include "keystructs.h"
39 #include "onak-conf.h"
44 /* Hack: We should really dynamically allocate our path buffers */
49 struct onak_fs_dbctx {
51 bool lockfile_readonly;
54 /*****************************************************************************/
56 /* Helper functions */
58 #define FNV_offset_basis 2166136261ul
59 #define FNV_mixing_prime 16777619ul
61 static uint32_t calchash(uint8_t * ptr)
63 register uint32_t h = FNV_offset_basis;
64 register uint32_t p = FNV_mixing_prime;
65 register uint32_t n = strlen((char *) ptr);
66 register uint8_t *c = ptr;
71 return h ? h : 1; /* prevent a hash of zero happening */
75 static void keypath(char *buffer, size_t length, uint64_t _keyid)
77 uint64_t keyid = _keyid << 32;
78 snprintf(buffer, length, "%s/key/%02X/%02X/%08X/%016" PRIX64,
79 config.db_dir, (uint8_t) ((keyid >> 56) & 0xFF),
80 (uint8_t) ((keyid >> 48) & 0xFF),
81 (uint32_t) (keyid >> 32), _keyid);
84 static void keydir(char *buffer, size_t length, uint64_t _keyid)
86 uint64_t keyid = _keyid << 32;
87 snprintf(buffer, length, "%s/key/%02X/%02X/%08X", config.db_dir,
88 (uint8_t) ((keyid >> 56) & 0xFF),
89 (uint8_t) ((keyid >> 48) & 0xFF),
90 (uint32_t) (keyid >> 32));
93 static void prove_path_to(uint64_t keyid, char *what)
95 static char buffer[PATH_MAX];
96 snprintf(buffer, sizeof(buffer), "%s/%s", config.db_dir, what);
99 snprintf(buffer, sizeof(buffer), "%s/%s/%02X", config.db_dir, what,
100 (uint8_t) ((keyid >> 24) & 0xFF));
103 snprintf(buffer, sizeof(buffer), "%s/%s/%02X/%02X", config.db_dir,
105 (uint8_t) ((keyid >> 24) & 0xFF),
106 (uint8_t) ((keyid >> 16) & 0xFF));
109 snprintf(buffer, sizeof(buffer), "%s/%s/%02X/%02X/%08X", config.db_dir,
111 (uint8_t) ((keyid >> 24) & 0xFF),
112 (uint8_t) ((keyid >> 16) & 0xFF), (uint32_t) (keyid));
116 static void wordpath(char *buffer, size_t length, char *word, uint32_t hash,
119 snprintf(buffer, length, "%s/words/%02X/%02X/%08X/%s/%016" PRIX64,
120 config.db_dir, (uint8_t) ((hash >> 24) & 0xFF),
121 (uint8_t) ((hash >> 16) & 0xFF), hash, word, keyid);
124 static void worddir(char *buffer, size_t length, char *word, uint32_t hash)
126 snprintf(buffer, length, "%s/words/%02X/%02X/%08X/%s", config.db_dir,
127 (uint8_t) ((hash >> 24) & 0xFF),
128 (uint8_t) ((hash >> 16) & 0xFF), hash, word);
131 static void subkeypath(char *buffer, size_t length, uint64_t subkey)
133 snprintf(buffer, length, "%s/subkeys/%02X/%02X/%08X/%016" PRIX64,
135 (uint8_t) ((subkey >> 24) & 0xFF),
136 (uint8_t) ((subkey >> 16) & 0xFF),
137 (uint32_t) (subkey & 0xFFFFFFFF),
141 static void subkeydir(char *buffer, size_t length, uint64_t subkey)
143 snprintf(buffer, length, "%s/subkeys/%02X/%02X/%08X",
145 (uint8_t) ((subkey >> 24) & 0xFF),
146 (uint8_t) ((subkey >> 16) & 0xFF),
147 (uint32_t) (subkey & 0xFFFFFFFF));
150 static void skshashpath(char *buffer, size_t length,
151 const struct skshash *hash)
153 snprintf(buffer, length, "%s/skshash/%02X/%02X/%02X%02X%02X%02X/"
154 "%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X%02X",
156 hash->hash[0], hash->hash[1],
157 hash->hash[0], hash->hash[1], hash->hash[2], hash->hash[3],
158 hash->hash[4], hash->hash[5], hash->hash[6], hash->hash[7],
159 hash->hash[8], hash->hash[9], hash->hash[10], hash->hash[11],
160 hash->hash[12], hash->hash[13], hash->hash[14],
164 /*****************************************************************************/
167 * starttrans - Start a transaction.
169 static bool fs_starttrans(struct onak_dbctx *dbctx)
171 struct onak_fs_dbctx *privctx = (struct onak_fs_dbctx *) dbctx->priv;
172 struct flock lockstruct;
175 F_RDLCK | ((privctx->lockfile_readonly) ? 0 : F_WRLCK);
176 lockstruct.l_whence = SEEK_SET;
177 lockstruct.l_start = 0;
178 lockstruct.l_len = 1;
180 while (fcntl(privctx->lockfile_fd, F_SETLK, &lockstruct) == -1) {
181 if (remaining-- == 0)
182 return false; /* Hope to hell that noodles DTRT */
189 * endtrans - End a transaction.
191 static void fs_endtrans(struct onak_dbctx *dbctx)
193 struct onak_fs_dbctx *privctx = (struct onak_fs_dbctx *) dbctx->priv;
194 struct flock lockstruct;
196 lockstruct.l_type = F_UNLCK;
197 lockstruct.l_whence = SEEK_SET;
198 lockstruct.l_start = 0;
199 lockstruct.l_len = 1;
200 fcntl(privctx->lockfile_fd, F_SETLK, &lockstruct);
203 static uint64_t fs_getfullkeyid(struct onak_dbctx *dbctx, uint64_t keyid)
205 static char buffer[PATH_MAX];
207 struct dirent *de = NULL;
210 keydir(buffer, sizeof(buffer), keyid);
216 if (de && de->d_name[0] != '.') {
217 ret = strtoull(de->d_name, NULL, 16);
219 } while (de && de->d_name[0] == '.');
224 subkeydir(buffer, sizeof(buffer), keyid);
230 if (de && de->d_name[0] != '.') {
231 ret = strtoull(de->d_name, NULL, 16);
233 } while (de && de->d_name[0] == '.');
242 * fetch_key - Given a keyid fetch the key from storage.
243 * @keyid: The keyid to fetch.
244 * @publickey: A pointer to a structure to return the key in.
245 * @intrans: If we're already in a transaction.
247 static int fs_fetch_key_id(struct onak_dbctx *dbctx,
249 struct openpgp_publickey **publickey,
252 static char buffer[PATH_MAX];
254 struct openpgp_packet_list *packets = NULL;
257 fs_starttrans(dbctx);
259 if ((keyid >> 32) == 0)
260 keyid = fs_getfullkeyid(dbctx, keyid);
262 keypath(buffer, sizeof(buffer), keyid);
263 fd = open(buffer, O_RDONLY);
264 if (fd == -1 && errno == ENOENT) {
265 subkeypath(buffer, sizeof(buffer), keyid);
266 fd = open(buffer, O_RDONLY);
270 /* File is present, load it in... */
271 read_openpgp_stream(file_fetchchar, &fd, &packets, 0);
272 parse_keys(packets, publickey);
273 free_packet_list(packets);
285 * store_key - Takes a key and stores it.
286 * @publickey: A pointer to the public key to store.
287 * @intrans: If we're already in a transaction.
288 * @update: If true the key exists and should be updated.
290 static int fs_store_key(struct onak_dbctx *dbctx,
291 struct openpgp_publickey *publickey, bool intrans,
294 static char buffer[PATH_MAX];
295 static char wbuffer[PATH_MAX];
297 struct openpgp_packet_list *packets = NULL;
298 struct openpgp_packet_list *list_end = NULL;
299 struct openpgp_publickey *next = NULL;
301 struct ll *wordlist = NULL, *wl = NULL;
303 struct openpgp_fingerprint *subkeyids = NULL;
307 if (get_keyid(publickey, &keyid) != ONAK_E_OK) {
308 logthing(LOGTHING_ERROR, "Couldn't find key ID for key.");
313 fs_starttrans(dbctx);
315 prove_path_to(keyid, "key");
316 keypath(buffer, sizeof(buffer), keyid);
319 open(buffer, O_WRONLY | (update ? O_TRUNC : O_CREAT),
321 next = publickey->next;
322 publickey->next = NULL;
323 flatten_publickey(publickey, &packets, &list_end);
324 publickey->next = next;
326 write_openpgp_stream(file_putchar, &fd, packets);
328 free_packet_list(packets);
334 wl = wordlist = makewordlistfromkey(wordlist, publickey);
336 uint32_t hash = calchash((uint8_t *) (wl->object));
337 prove_path_to(hash, "words");
339 worddir(wbuffer, sizeof(wbuffer), wl->object, hash);
340 mkdir(wbuffer, 0777);
341 wordpath(wbuffer, sizeof(wbuffer), wl->object, hash,
343 link(buffer, wbuffer);
347 llfree(wordlist, free);
349 subkeyids = keysubkeys(publickey);
351 while (subkeyids != NULL && subkeyids[i].length != 0) {
352 keyid = fingerprint2keyid(&subkeyids[i]);
354 prove_path_to(keyid, "subkeys");
356 subkeydir(wbuffer, sizeof(wbuffer), keyid);
357 mkdir(wbuffer, 0777);
358 subkeypath(wbuffer, sizeof(wbuffer), keyid);
359 link(buffer, wbuffer);
363 if (subkeyids != NULL) {
368 get_skshash(publickey, &hash);
369 hashid = (hash.hash[0] << 24) + (hash.hash[1] << 16) +
370 (hash.hash[2] << 8) + hash.hash[3];
371 prove_path_to(hashid, "skshash");
372 skshashpath(wbuffer, sizeof(wbuffer), &hash);
373 link(buffer, wbuffer);
382 * delete_key - Given a keyid delete the key from storage.
383 * @keyid: The keyid to delete.
384 * @intrans: If we're already in a transaction.
386 static int fs_delete_key(struct onak_dbctx *dbctx, uint64_t keyid, bool intrans)
388 static char buffer[PATH_MAX];
390 struct openpgp_publickey *pk = NULL;
392 struct ll *wordlist = NULL, *wl = NULL;
393 struct openpgp_fingerprint *subkeyids = NULL;
397 if ((keyid >> 32) == 0)
398 keyid = fs_getfullkeyid(dbctx, keyid);
401 fs_starttrans(dbctx);
403 ret = fs_fetch_key_id(dbctx, keyid, &pk, true);
406 logthing(LOGTHING_DEBUG, "Wordlist for key %016" PRIX64,
408 wl = wordlist = makewordlistfromkey(wordlist, pk);
409 logthing(LOGTHING_DEBUG,
410 "Wordlist for key %016" PRIX64 " done", keyid);
412 uint32_t hash = calchash((uint8_t *) (wl->object));
413 prove_path_to(hash, "words");
415 wordpath(buffer, sizeof(buffer), wl->object, hash,
422 subkeyids = keysubkeys(pk);
424 while (subkeyids != NULL && subkeyids[i].length != 0) {
425 subkeyid = fingerprint2keyid(&subkeyids[i]);
426 prove_path_to(subkeyid, "subkeys");
428 subkeypath(buffer, sizeof(buffer), subkeyid);
433 if (subkeyids != NULL) {
438 get_skshash(pk, &hash);
439 skshashpath(buffer, sizeof(buffer), &hash);
443 keypath(buffer, sizeof(buffer), keyid);
451 static struct ll *internal_get_key_by_word(char *word, struct ll *mct)
453 struct ll *keys = NULL;
455 char buffer[PATH_MAX];
456 uint32_t hash = calchash((uint8_t *) (word));
459 worddir(buffer, sizeof(buffer), word, hash);
461 logthing(LOGTHING_DEBUG, "Scanning for word %s in dir %s", word,
466 if (de && de->d_name[0] != '.') {
468 || (llfind(mct, de->d_name,
469 (int (*)(const void *, const void *))
472 logthing(LOGTHING_DEBUG,
473 "Found %s // %s", word,
488 * fetch_key_text - Trys to find the keys that contain the supplied text.
489 * @search: The text to search for.
490 * @publickey: A pointer to a structure to return the key in.
492 static int fs_fetch_key_text(struct onak_dbctx *dbctx,
494 struct openpgp_publickey **publickey)
496 struct ll *wordlist = NULL, *wl = NULL;
497 struct ll *keylist = NULL;
498 char *searchtext = NULL;
501 logthing(LOGTHING_DEBUG, "Search was '%s'", search);
503 searchtext = strdup(search);
504 wl = wordlist = makewordlist(wordlist, searchtext);
506 keylist = internal_get_key_by_word(wordlist->object, NULL);
509 llfree(wordlist, NULL);
518 internal_get_key_by_word(wl->object, keylist);
520 llfree(wordlist, NULL);
521 llfree(keylist, free);
526 llfree(keylist, free);
531 llfree(wordlist, NULL);
533 /* Now add the keys... */
536 logthing(LOGTHING_DEBUG, "Adding key: %s", wl->object);
538 fs_fetch_key_id(dbctx,
539 strtoull(wl->object, NULL, 16), publickey,
541 if (addedkeys >= config.maxkeys)
546 llfree(keylist, free);
554 * fetch_key_skshash - Given an SKS hash fetch the key from storage.
555 * @hash: The hash to fetch.
556 * @publickey: A pointer to a structure to return the key in.
557 * @intrans: If we're already in a transaction.
559 static int fs_fetch_key_skshash(struct onak_dbctx *dbctx,
560 const struct skshash *hash,
561 struct openpgp_publickey **publickey)
563 static char buffer[PATH_MAX];
565 struct openpgp_packet_list *packets = NULL;
567 skshashpath(buffer, sizeof(buffer), hash);
568 if ((fd = open(buffer, O_RDONLY)) != -1) {
569 read_openpgp_stream(file_fetchchar, &fd, &packets, 0);
570 parse_keys(packets, publickey);
571 free_packet_list(packets);
581 * iterate_keys - call a function once for each key in the db.
582 * @iterfunc: The function to call.
583 * @ctx: A context pointer
585 * Calls iterfunc once for each key in the database. ctx is passed
586 * unaltered to iterfunc. This function is intended to aid database dumps
587 * and statistic calculations.
589 * Returns the number of keys we iterated over.
591 static int fs_iterate_keys(struct onak_dbctx *dbctx,
592 void (*iterfunc)(void *ctx,
593 struct openpgp_publickey *key), void *ctx)
599 * Include the basic keydb routines.
601 #define NEED_KEYID2UID 1
602 #define NEED_GETKEYSIGS 1
603 #define NEED_UPDATEKEYS 1
604 #define NEED_GET_FP 1
608 * cleanupdb - De-initialize the key database.
610 static void fs_cleanupdb(struct onak_dbctx *dbctx)
612 struct onak_fs_dbctx *privctx = (struct onak_fs_dbctx *) dbctx->priv;
614 /* Mmmm nothing to do here? */
615 close(privctx->lockfile_fd);
619 * initdb - Initialize the key database.
621 struct onak_dbctx *keydb_fs_init(bool readonly)
623 char buffer[PATH_MAX];
624 struct onak_dbctx *dbctx;
625 struct onak_fs_dbctx *privctx;
627 dbctx = malloc(sizeof(struct onak_dbctx));
631 dbctx->priv = privctx = malloc(sizeof(*privctx));
632 if (privctx == NULL) {
637 privctx->lockfile_readonly = readonly;
639 snprintf(buffer, sizeof(buffer), "%s/.lock", config.db_dir);
641 if (access(config.db_dir, R_OK | W_OK | X_OK) == -1) {
642 if (errno != ENOENT) {
643 logthing(LOGTHING_CRITICAL,
644 "Unable to access keydb_fs root of '%s'. (%s)",
645 config.db_dir, strerror(errno));
646 exit(1); /* Lacking rwx on the key dir */
648 mkdir(config.db_dir, 0777);
649 privctx->lockfile_fd = open(buffer, O_RDWR | O_CREAT, 0600);
651 chdir(config.db_dir);
652 privctx->lockfile_fd = open(buffer,
653 (privctx->lockfile_readonly) ?
655 if (privctx->lockfile_fd == -1)
656 privctx->lockfile_fd = open(buffer, O_RDWR | O_CREAT, 0600);
657 if (privctx->lockfile_fd == -1) {
658 logthing(LOGTHING_CRITICAL,
659 "Unable to open lockfile '%s'. (%s)",
660 buffer, strerror(errno));
661 exit(1); /* Lacking rwx on the key dir */
664 dbctx->cleanupdb = fs_cleanupdb;
665 dbctx->starttrans = fs_starttrans;
666 dbctx->endtrans = fs_endtrans;
667 dbctx->fetch_key_id = fs_fetch_key_id;
668 dbctx->fetch_key_fp = generic_fetch_key_fp;
669 dbctx->fetch_key_text = fs_fetch_key_text;
670 dbctx->fetch_key_skshash = fs_fetch_key_skshash;
671 dbctx->store_key = fs_store_key;
672 dbctx->update_keys = generic_update_keys;
673 dbctx->delete_key = fs_delete_key;
674 dbctx->getkeysigs = generic_getkeysigs;
675 dbctx->cached_getkeysigs = generic_cached_getkeysigs;
676 dbctx->keyid2uid = generic_keyid2uid;
677 dbctx->getfullkeyid = fs_getfullkeyid;
678 dbctx->iterate_keys = fs_iterate_keys;