Blame lang/python/tests/t-quick-key-manipulation.py

Packit d7e8d0
#!/usr/bin/env python
Packit d7e8d0
Packit d7e8d0
# Copyright (C) 2017 g10 Code GmbH
Packit d7e8d0
#
Packit d7e8d0
# This file is part of GPGME.
Packit d7e8d0
#
Packit d7e8d0
# GPGME is free software; you can redistribute it and/or modify it
Packit d7e8d0
# under the terms of the GNU General Public License as published by
Packit d7e8d0
# the Free Software Foundation; either version 2 of the License, or
Packit d7e8d0
# (at your option) any later version.
Packit d7e8d0
#
Packit d7e8d0
# GPGME is distributed in the hope that it will be useful, but WITHOUT
Packit d7e8d0
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
Packit d7e8d0
# or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General
Packit d7e8d0
# Public License for more details.
Packit d7e8d0
#
Packit d7e8d0
# You should have received a copy of the GNU Lesser General Public
Packit d7e8d0
# License along with this program; if not, see <http://www.gnu.org/licenses/>.
Packit d7e8d0
Packit d7e8d0
from __future__ import absolute_import, print_function, unicode_literals
Packit d7e8d0
del absolute_import, print_function, unicode_literals
Packit d7e8d0
Packit d7e8d0
import os
Packit d7e8d0
import gpg
Packit d7e8d0
import sys
Packit d7e8d0
Packit d7e8d0
import support
Packit d7e8d0
support.assert_gpg_version((2, 1, 14))
Packit d7e8d0
Packit d7e8d0
alpha = "Alpha <alpha@invalid.example.net>"
Packit d7e8d0
bravo = "Bravo <bravo@invalid.example.net>"
Packit d7e8d0
Packit d7e8d0
with support.EphemeralContext() as ctx:
Packit d7e8d0
    res = ctx.create_key(alpha, certify=True)
Packit d7e8d0
    key = ctx.get_key(res.fpr)
Packit d7e8d0
    assert len(key.subkeys) == 1, "Expected one primary key and no subkeys"
Packit d7e8d0
    assert len(key.uids) == 1, "Expected exactly one UID"
Packit d7e8d0
Packit d7e8d0
    def get_uid(uid):
Packit d7e8d0
        key = ctx.get_key(res.fpr)
Packit d7e8d0
        for u in key.uids:
Packit d7e8d0
            if u.uid == uid:
Packit d7e8d0
                return u
Packit d7e8d0
        return None
Packit d7e8d0
Packit d7e8d0
    # sanity check
Packit d7e8d0
    uid = get_uid(alpha)
Packit d7e8d0
    assert uid, "UID alpha not found"
Packit d7e8d0
    assert uid.revoked == 0
Packit d7e8d0
Packit d7e8d0
    # add bravo
Packit d7e8d0
    ctx.key_add_uid(key, bravo)
Packit d7e8d0
    uid = get_uid(bravo)
Packit d7e8d0
    assert uid, "UID bravo not found"
Packit d7e8d0
    assert uid.revoked == 0
Packit d7e8d0
Packit d7e8d0
    # revoke alpha
Packit d7e8d0
    ctx.key_revoke_uid(key, alpha)
Packit d7e8d0
    uid = get_uid(alpha)
Packit d7e8d0
    assert uid, "UID alpha not found"
Packit d7e8d0
    assert uid.revoked == 1
Packit d7e8d0
    uid = get_uid(bravo)
Packit d7e8d0
    assert uid, "UID bravo not found"
Packit d7e8d0
    assert uid.revoked == 0
Packit d7e8d0
Packit d7e8d0
    # try to revoke the last UID
Packit d7e8d0
    try:
Packit d7e8d0
        ctx.key_revoke_uid(key, alpha)
Packit d7e8d0
        # IMHO this should fail.  issue2961.
Packit d7e8d0
        # assert False, "Expected an error but got none"
Packit d7e8d0
    except gpg.errors.GpgError:
Packit d7e8d0
        pass
Packit d7e8d0
Packit d7e8d0
    # Everything should be the same
Packit d7e8d0
    uid = get_uid(alpha)
Packit d7e8d0
    assert uid, "UID alpha not found"
Packit d7e8d0
    assert uid.revoked == 1
Packit d7e8d0
    uid = get_uid(bravo)
Packit d7e8d0
    assert uid, "UID bravo not found"
Packit d7e8d0
    assert uid.revoked == 0
Packit d7e8d0
Packit d7e8d0
    # try to revoke a non-existent UID
Packit d7e8d0
    try:
Packit d7e8d0
        ctx.key_revoke_uid(key, "i dont exist")
Packit d7e8d0
        # IMHO this should fail.  issue2963.
Packit d7e8d0
        # assert False, "Expected an error but got none"
Packit d7e8d0
    except gpg.errors.GpgError:
Packit d7e8d0
        pass
Packit d7e8d0
Packit d7e8d0
    # try to add an pre-existent UID
Packit d7e8d0
    try:
Packit d7e8d0
        ctx.key_add_uid(key, bravo)
Packit d7e8d0
        assert False, "Expected an error but got none"
Packit d7e8d0
    except gpg.errors.GpgError:
Packit d7e8d0
        pass
Packit d7e8d0
Packit d7e8d0
    # Check setting the TOFU policy.
Packit d7e8d0
    with open(os.path.join(ctx.home_dir, "gpg.conf"), "a") as handle:
Packit d7e8d0
        handle.write("trust-model tofu+pgp\n")
Packit d7e8d0
Packit d7e8d0
    if not support.have_tofu_support(ctx, bravo):
Packit d7e8d0
        print("GnuPG does not support TOFU, skipping TOFU tests.")
Packit d7e8d0
        sys.exit()
Packit d7e8d0
Packit d7e8d0
    for name, policy in [(name, getattr(gpg.constants.tofu.policy, name))
Packit d7e8d0
                         for name in filter(lambda x: not x.startswith('__'),
Packit d7e8d0
                                            dir(gpg.constants.tofu.policy))]:
Packit d7e8d0
        if policy == gpg.constants.tofu.policy.NONE:
Packit d7e8d0
            # We must not set the policy to NONE.
Packit d7e8d0
            continue
Packit d7e8d0
Packit d7e8d0
        ctx.key_tofu_policy(key, policy)
Packit d7e8d0
Packit d7e8d0
        keys = list(ctx.keylist(key.uids[0].uid,
Packit d7e8d0
                                mode=(gpg.constants.keylist.mode.LOCAL
Packit d7e8d0
                                      |gpg.constants.keylist.mode.WITH_TOFU)))
Packit d7e8d0
        assert len(keys) == 1
Packit d7e8d0
Packit d7e8d0
        if policy == gpg.constants.tofu.policy.AUTO:
Packit d7e8d0
            # We cannot check that it is set to AUTO.
Packit d7e8d0
            continue
Packit d7e8d0
Packit d7e8d0
        for uid in keys[0].uids:
Packit d7e8d0
            if uid.uid == alpha:
Packit d7e8d0
                # TOFU information of revoked UIDs is not updated.
Packit d7e8d0
                # XXX: Is that expected?
Packit d7e8d0
                continue
Packit d7e8d0
            assert uid.tofu[0].policy == policy, \
Packit d7e8d0
                "Expected policy {0} ({1}), got {2}".format(policy, name,
Packit d7e8d0
                                                            uid.tofu[0].policy)