Blame dnf/rpm/miscutils.py

Packit 6f3914
# This program is free software; you can redistribute it and/or modify
Packit 6f3914
# it under the terms of the GNU General Public License as published by
Packit 6f3914
# the Free Software Foundation; either version 2 of the License, or
Packit 6f3914
# (at your option) any later version.
Packit 6f3914
#
Packit 6f3914
# This program is distributed in the hope that it will be useful,
Packit 6f3914
# but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 6f3914
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit 6f3914
# GNU Library General Public License for more details.
Packit 6f3914
#
Packit 6f3914
# You should have received a copy of the GNU General Public License
Packit 6f3914
# along with this program; if not, write to the Free Software
Packit 6f3914
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
Packit 6f3914
# Copyright 2003 Duke University
Packit 6f3914
Packit 6f3914
from __future__ import print_function, absolute_import
Packit 6f3914
from __future__ import unicode_literals
Packit 6f3914
Packit 6f3914
import rpm
Packit 6f3914
import os
Packit 6f3914
Packit 6f3914
from dnf.i18n import ucd
Packit 6f3914
Packit 6f3914
Packit 6f3914
def checkSig(ts, package):
Packit 6f3914
    """Takes a transaction set and a package, check it's sigs,
Packit 6f3914
    return 0 if they are all fine
Packit 6f3914
    return 1 if the gpg key can't be found
Packit 6f3914
    return 2 if the header is in someway damaged
Packit 6f3914
    return 3 if the key is not trusted
Packit 6f3914
    return 4 if the pkg is not gpg or pgp signed"""
Packit 6f3914
Packit 6f3914
    value = 0
Packit 6f3914
    currentflags = ts.setVSFlags(0)
Packit 6f3914
    fdno = os.open(package, os.O_RDONLY)
Packit 6f3914
    try:
Packit 6f3914
        hdr = ts.hdrFromFdno(fdno)
Packit 6f3914
    except rpm.error as e:
Packit 6f3914
        if str(e) == "public key not available":
Packit 6f3914
            value = 1
Packit 6f3914
        if str(e) == "public key not trusted":
Packit 6f3914
            value = 3
Packit 6f3914
        if str(e) == "error reading package header":
Packit 6f3914
            value = 2
Packit 6f3914
    else:
Packit 6f3914
        # checks signature from an hdr
Packit 6f3914
        string = '%|DSAHEADER?{%{DSAHEADER:pgpsig}}:{%|RSAHEADER?{%{RSAHEADER:pgpsig}}:' \
Packit 6f3914
                 '{%|SIGGPG?{%{SIGGPG:pgpsig}}:{%|SIGPGP?{%{SIGPGP:pgpsig}}:{(none)}|}|}|}|'
Packit 6f3914
        try:
Packit 6f3914
            siginfo = hdr.sprintf(string)
Packit 6f3914
            siginfo = ucd(siginfo)
Packit 6f3914
            if siginfo == '(none)':
Packit 6f3914
                value = 4
Packit 6f3914
        except UnicodeDecodeError:
Packit 6f3914
            pass
Packit 6f3914
Packit 6f3914
        del hdr
Packit 6f3914
Packit 6f3914
    try:
Packit 6f3914
        os.close(fdno)
Packit 6f3914
    except OSError as e:  # if we're not opened, don't scream about it
Packit 6f3914
        pass
Packit 6f3914
Packit 6f3914
    ts.setVSFlags(currentflags)  # put things back like they were before
Packit 6f3914
    return value