2011-04-17 04:40:23 +00:00
|
|
|
{- common functions for encryptable remotes
|
2011-04-16 17:25:27 +00:00
|
|
|
-
|
|
|
|
- Copyright 2011 Joey Hess <joey@kitenet.net>
|
|
|
|
-
|
|
|
|
- Licensed under the GNU GPL version 3 or higher.
|
|
|
|
-}
|
|
|
|
|
2011-08-17 00:49:54 +00:00
|
|
|
module Remote.Helper.Encryptable where
|
2011-04-16 17:25:27 +00:00
|
|
|
|
|
|
|
import qualified Data.Map as M
|
|
|
|
|
2011-10-05 20:02:51 +00:00
|
|
|
import Common.Annex
|
2011-06-02 01:56:04 +00:00
|
|
|
import Types.Remote
|
2011-04-16 17:25:27 +00:00
|
|
|
import Crypto
|
2013-03-29 16:06:02 +00:00
|
|
|
import Types.Crypto
|
2011-04-16 22:22:52 +00:00
|
|
|
import qualified Annex
|
2013-03-13 20:16:01 +00:00
|
|
|
import Config.Cost
|
2012-04-29 18:31:34 +00:00
|
|
|
import Utility.Base64
|
2013-03-28 21:03:04 +00:00
|
|
|
import Utility.Metered
|
2011-04-16 17:25:27 +00:00
|
|
|
|
|
|
|
{- Encryption setup for a remote. The user must specify whether to use
|
|
|
|
- an encryption key, or not encrypt. An encrypted cipher is created, or is
|
2012-04-29 18:02:18 +00:00
|
|
|
- updated to be accessible to an additional encryption key. Or the user
|
|
|
|
- could opt to use a shared cipher, which is stored unencrypted. -}
|
2011-04-16 17:25:27 +00:00
|
|
|
encryptionSetup :: RemoteConfig -> Annex RemoteConfig
|
2013-08-28 02:24:14 +00:00
|
|
|
encryptionSetup c = maybe genCipher updateCipher $ extractCipher c
|
2012-11-11 04:51:07 +00:00
|
|
|
where
|
2013-08-28 02:24:14 +00:00
|
|
|
-- The type of encryption
|
|
|
|
encryption = M.lookup "encryption" c
|
|
|
|
-- Generate a new cipher, depending on the chosen encryption scheme
|
|
|
|
genCipher = case encryption of
|
2013-09-01 18:12:00 +00:00
|
|
|
_ | M.member "cipher" c || M.member "cipherkeys" c -> cannotchange
|
2013-08-28 02:24:14 +00:00
|
|
|
Just "none" -> return c
|
|
|
|
Just "shared" -> use "encryption setup" . genSharedCipher
|
|
|
|
=<< highRandomQuality
|
2013-09-04 23:09:56 +00:00
|
|
|
-- hybrid encryption is the default when a keyid is
|
|
|
|
-- specified but no encryption
|
|
|
|
_ | maybe (M.member "keyid" c) (== "hybrid") encryption ->
|
2013-09-05 15:12:01 +00:00
|
|
|
use "encryption setup" . genEncryptedCipher key Hybrid
|
2013-08-28 02:24:14 +00:00
|
|
|
=<< highRandomQuality
|
2013-09-05 15:12:01 +00:00
|
|
|
Just "pubkey" -> use "encryption setup" . genEncryptedCipher key PubKey
|
2013-09-01 18:12:00 +00:00
|
|
|
=<< highRandomQuality
|
|
|
|
_ -> error $ "Specify " ++ intercalate " or "
|
|
|
|
(map ("encryption=" ++)
|
2013-09-04 23:09:56 +00:00
|
|
|
["none","shared","hybrid","pubkey"])
|
2013-09-01 18:12:00 +00:00
|
|
|
++ "."
|
2013-08-28 02:24:14 +00:00
|
|
|
key = fromMaybe (error "Specifiy keyid=...") $ M.lookup "keyid" c
|
|
|
|
newkeys = maybe [] (\k -> [(True,k)]) (M.lookup "keyid+" c) ++
|
|
|
|
maybe [] (\k -> [(False,k)]) (M.lookup "keyid-" c)
|
2013-09-01 18:12:00 +00:00
|
|
|
cannotchange = error "Cannot set encryption type of existing remotes."
|
2013-08-28 02:24:14 +00:00
|
|
|
-- Update an existing cipher if possible.
|
2013-09-01 18:12:00 +00:00
|
|
|
updateCipher v = case v of
|
2013-09-05 02:39:25 +00:00
|
|
|
SharedCipher _ | maybe True (== "shared") encryption -> return c'
|
2013-09-05 02:18:33 +00:00
|
|
|
EncryptedCipher _ variant _
|
2013-09-05 15:12:01 +00:00
|
|
|
| maybe True (== if variant == Hybrid then "hybrid" else "pubkey") encryption ->
|
2013-09-05 02:18:33 +00:00
|
|
|
use "encryption update" $ updateEncryptedCipher newkeys v
|
2013-09-01 18:12:00 +00:00
|
|
|
_ -> cannotchange
|
2012-11-11 04:51:07 +00:00
|
|
|
use m a = do
|
2013-05-18 23:30:52 +00:00
|
|
|
showNote m
|
2012-11-11 04:51:07 +00:00
|
|
|
cipher <- liftIO a
|
2013-05-18 23:30:52 +00:00
|
|
|
showNote $ describeCipher cipher
|
2013-09-01 18:12:00 +00:00
|
|
|
return $ storeCipher c' cipher
|
2013-04-06 20:14:57 +00:00
|
|
|
highRandomQuality =
|
|
|
|
(&&) (maybe True ( /= "false") $ M.lookup "highRandomQuality" c)
|
|
|
|
<$> fmap not (Annex.getState Annex.fast)
|
2013-09-01 18:12:00 +00:00
|
|
|
c' = foldr M.delete c
|
|
|
|
-- git-annex used to remove 'encryption' as well, since
|
|
|
|
-- it was redundant; we now need to keep it for
|
2014-07-27 05:22:51 +00:00
|
|
|
-- public-key encryption, hence we leave it on newer
|
2013-09-01 18:12:00 +00:00
|
|
|
-- remotes (while being backward-compatible).
|
|
|
|
[ "keyid", "keyid+", "keyid-", "highRandomQuality" ]
|
2011-04-16 22:22:52 +00:00
|
|
|
|
2014-07-27 00:14:09 +00:00
|
|
|
{- Modifies a Remote to support encryption. -}
|
|
|
|
-- TODO: deprecated
|
2011-04-17 04:40:23 +00:00
|
|
|
encryptableRemote
|
2012-11-30 04:55:59 +00:00
|
|
|
:: RemoteConfig
|
2012-09-21 18:50:14 +00:00
|
|
|
-> ((Cipher, Key) -> Key -> MeterUpdate -> Annex Bool)
|
2013-04-11 21:15:45 +00:00
|
|
|
-> ((Cipher, Key) -> Key -> FilePath -> MeterUpdate -> Annex Bool)
|
2011-12-31 08:11:39 +00:00
|
|
|
-> Remote
|
|
|
|
-> Remote
|
2014-07-26 16:04:35 +00:00
|
|
|
encryptableRemote c storeKeyEncrypted retrieveKeyFileEncrypted r = r
|
|
|
|
{ storeKey = \k f p -> cip k >>= maybe
|
2012-11-11 04:51:07 +00:00
|
|
|
(storeKey r k f p)
|
2014-07-27 00:14:09 +00:00
|
|
|
(\v -> storeKeyEncrypted v k p)
|
2014-07-26 16:04:35 +00:00
|
|
|
, retrieveKeyFile = \k f d p -> cip k >>= maybe
|
2013-04-11 21:15:45 +00:00
|
|
|
(retrieveKeyFile r k f d p)
|
2014-07-27 00:14:09 +00:00
|
|
|
(\v -> retrieveKeyFileEncrypted v k d p)
|
2014-07-26 16:04:35 +00:00
|
|
|
, retrieveKeyFileCheap = \k d -> cip k >>= maybe
|
2012-11-11 04:51:07 +00:00
|
|
|
(retrieveKeyFileCheap r k d)
|
|
|
|
(\_ -> return False)
|
2014-07-27 00:14:09 +00:00
|
|
|
, removeKey = \k -> cip k >>= maybe
|
|
|
|
(removeKey r k)
|
|
|
|
(\(_, enckey) -> removeKey r enckey)
|
|
|
|
, hasKey = \k -> cip k >>= maybe
|
|
|
|
(hasKey r k)
|
|
|
|
(\(_, enckey) -> hasKey r enckey)
|
2014-07-26 16:04:35 +00:00
|
|
|
, cost = maybe
|
|
|
|
(cost r)
|
|
|
|
(const $ cost r + encryptedRemoteCostAdj)
|
|
|
|
(extractCipher c)
|
|
|
|
}
|
|
|
|
where
|
2014-07-27 00:14:09 +00:00
|
|
|
cip k = do
|
|
|
|
v <- cipherKey c
|
|
|
|
return $ case v of
|
|
|
|
Nothing -> Nothing
|
|
|
|
Just (cipher, enck) -> Just (cipher, enck k)
|
2011-04-16 22:22:52 +00:00
|
|
|
|
2011-12-08 20:01:46 +00:00
|
|
|
{- Gets encryption Cipher. The decrypted Ciphers are cached in the Annex
|
2011-05-01 18:05:10 +00:00
|
|
|
- state. -}
|
|
|
|
remoteCipher :: RemoteConfig -> Annex (Maybe Cipher)
|
2011-12-08 20:01:46 +00:00
|
|
|
remoteCipher c = go $ extractCipher c
|
2012-11-11 04:51:07 +00:00
|
|
|
where
|
|
|
|
go Nothing = return Nothing
|
|
|
|
go (Just encipher) = do
|
|
|
|
cache <- Annex.getState Annex.ciphers
|
|
|
|
case M.lookup encipher cache of
|
|
|
|
Just cipher -> return $ Just cipher
|
2012-11-18 19:27:44 +00:00
|
|
|
Nothing -> do
|
|
|
|
showNote "gpg"
|
|
|
|
cipher <- liftIO $ decryptCipher encipher
|
|
|
|
Annex.changeState (\s -> s { Annex.ciphers = M.insert encipher cipher cache })
|
|
|
|
return $ Just cipher
|
2011-05-01 18:05:10 +00:00
|
|
|
|
2012-11-19 21:32:58 +00:00
|
|
|
{- Checks if the remote's config allows storing creds in the remote's config.
|
|
|
|
-
|
|
|
|
- embedcreds=yes allows this, and embedcreds=no prevents it.
|
|
|
|
-
|
|
|
|
- If not set, the default is to only store creds when it's surely safe:
|
|
|
|
- When gpg encryption is used, in which case the creds will be encrypted
|
|
|
|
- using it. Not when a shared cipher is used.
|
|
|
|
-}
|
|
|
|
embedCreds :: RemoteConfig -> Bool
|
|
|
|
embedCreds c
|
|
|
|
| M.lookup "embedcreds" c == Just "yes" = True
|
|
|
|
| M.lookup "embedcreds" c == Just "no" = False
|
|
|
|
| isJust (M.lookup "cipherkeys" c) && isJust (M.lookup "cipher" c) = True
|
|
|
|
| otherwise = False
|
2012-09-26 16:06:44 +00:00
|
|
|
|
2014-07-27 00:14:09 +00:00
|
|
|
{- Gets encryption Cipher, and key encryptor. -}
|
|
|
|
cipherKey :: RemoteConfig -> Annex (Maybe (Cipher, EncKey))
|
|
|
|
cipherKey c = fmap make <$> remoteCipher c
|
2012-11-11 04:51:07 +00:00
|
|
|
where
|
2014-07-27 00:14:09 +00:00
|
|
|
make ciphertext = (ciphertext, encryptKey mac ciphertext)
|
2013-03-29 16:06:02 +00:00
|
|
|
mac = fromMaybe defaultMac $ M.lookup "mac" c >>= readMac
|
2012-04-29 18:31:34 +00:00
|
|
|
|
|
|
|
{- Stores an StorableCipher in a remote's configuration. -}
|
|
|
|
storeCipher :: RemoteConfig -> StorableCipher -> RemoteConfig
|
|
|
|
storeCipher c (SharedCipher t) = M.insert "cipher" (toB64 t) c
|
2013-09-01 18:12:00 +00:00
|
|
|
storeCipher c (EncryptedCipher t _ ks) =
|
2012-04-29 18:31:34 +00:00
|
|
|
M.insert "cipher" (toB64 t) $ M.insert "cipherkeys" (showkeys ks) c
|
2012-11-11 04:51:07 +00:00
|
|
|
where
|
2013-04-23 00:24:53 +00:00
|
|
|
showkeys (KeyIds l) = intercalate "," l
|
2012-04-29 18:31:34 +00:00
|
|
|
|
|
|
|
{- Extracts an StorableCipher from a remote's configuration. -}
|
|
|
|
extractCipher :: RemoteConfig -> Maybe StorableCipher
|
2013-09-01 18:12:00 +00:00
|
|
|
extractCipher c = case (M.lookup "cipher" c,
|
|
|
|
M.lookup "cipherkeys" c,
|
|
|
|
M.lookup "encryption" c) of
|
|
|
|
(Just t, Just ks, encryption) | maybe True (== "hybrid") encryption ->
|
2013-09-05 15:12:01 +00:00
|
|
|
Just $ EncryptedCipher (fromB64 t) Hybrid (readkeys ks)
|
2013-09-01 18:12:00 +00:00
|
|
|
(Just t, Just ks, Just "pubkey") ->
|
2013-09-05 15:12:01 +00:00
|
|
|
Just $ EncryptedCipher (fromB64 t) PubKey (readkeys ks)
|
2013-09-01 18:12:00 +00:00
|
|
|
(Just t, Nothing, encryption) | maybe True (== "shared") encryption ->
|
|
|
|
Just $ SharedCipher (fromB64 t)
|
|
|
|
_ -> Nothing
|
2012-11-11 04:51:07 +00:00
|
|
|
where
|
|
|
|
readkeys = KeyIds . split ","
|