1 2009-10-16 Marcus Brinkmann <marcus@g10code.com>
3 * gpg_agent_CFLAGS, gpg_agent_LDADD: Use libassuan instead of
5 * gpg-agent.c: Invoke ASSUAN_SYSTEM_PTH_IMPL.
6 (main): Call assuan_set_system_hooks and assuan_sock_init.
7 Fix invocation of assuan_socket_connect.
9 2009-09-23 Werner Koch <wk@g10code.com>
11 * command.c (register_commands) [HAVE_ASSUAN_SET_IO_MONITOR]:
13 (start_command_handler) [HAVE_ASSUAN_SET_IO_MONITOR]: Ditto.
15 2009-09-23 Marcus Brinkmann <marcus@g10code.de>
17 * gpg-agent.c (parse_rereadable_options): Don't set global assuan
18 log file (there ain't one anymore).
19 (main): Update to new API.
20 (check_own_socket_pid_cb): Return gpg_error_t instead of int.
21 (check_own_socket_thread, check_for_running_agent): Create assuan
22 context before connecting to server.
23 * command.c: Include "scdaemon.h" before <assuan.h> because of
24 GPG_ERR_SOURCE_DEFAULT check.
25 (write_and_clear_outbuf): Use gpg_error_t instead of
27 (cmd_geteventcounter, cmd_istrusted, cmd_listtrusted)
28 (cmd_marktrusted, cmd_havekey, cmd_sigkey, cmd_setkeydesc)
29 (cmd_sethash, cmd_pksign, cmd_pkdecrypt, cmd_genkey, cmd_readkey)
30 (cmd_keyinfo, cmd_get_passphrase, cmd_clear_passphrase)
31 (cmd_get_confirmation, cmd_learn, cmd_passwd)
32 (cmd_preset_passphrase, cmd_scd, cmd_getval, cmd_putval)
33 (cmd_updatestartuptty, cmd_killagent, cmd_reloadagent)
34 (cmd_getinfo, option_handler): Return gpg_error_t instead of int.
35 (post_cmd_notify): Change type of ERR to gpg_error_t from int.
36 (io_monitor): Add hook argument. Use symbols for constants.
37 (register_commands): Change return type of HANDLER to gpg_error_t.
38 (start_command_handler): Allocate assuan context before starting
40 * call-pinentry.c: Include "scdaemon.h" before <assuan.h> because
41 of GPG_ERR_SOURCE_DEFAULT check.
42 (unlock_pinentry): Call assuan_release instead of
44 (getinfo_pid_cb, getpin_cb): Return gpg_error_t instead of int.
45 (start_pinentry): Allocate assuan context before connecting to
47 * call-scd.c (membuf_data_cb, learn_status_cb, get_serialno_cb)
48 (membuf_data_cb, inq_needpin, card_getattr_cb, pass_status_thru)
49 (pass_data_thru): Change return type to gpg_error_t.
50 (start_scd): Allocate assuan context before connecting to server.
52 2009-09-04 Marcus Brinkmann <marcus@g10code.com>
54 * command.c (start_command_handler): Add comment about gap in
55 implementation (in dead code), for future reference.
57 2009-08-11 Werner Koch <wk@g10code.com>
59 * divert-scd.c (ask_for_card): I18n a prompt string.
61 2009-07-06 Werner Koch <wk@g10code.com>
63 * agent.h: Include session-env.h.
64 (opt): Replace most of the startup_xxx fields by a session_env_t.
65 (struct server_control_s): Likewise.
66 * gpg-agent.c (main): Rewrite setting of the startup fields.
67 (handle_connections, main): Allocate SESSION_ENV.
68 (agent_init_default_ctrl, agent_deinit_default_ctrl): Change
70 * command.c (option_handler): Ditto.
71 (cmd_updatestartuptty): Change accordingly. Protect old values
72 from out of core failures.
73 * command-ssh.c (start_command_handler_ssh): Ditto.
74 (start_command_handler_ssh): Replace strdup by xtrystrdup.
75 * call-pinentry.c (atfork_cb): Pass new envrinmnet variables.
76 (start_pinentry): Use session_env stuff.
77 * protect-tool.c (main): Adjust call to gnupg_prepare_get_passphrase.
79 2009-06-24 Werner Koch <wk@g10code.com>
81 * genkey.c (agent_protect_and_store): Return RC and not 0.
82 * protect.c (do_encryption): Fix ignored error code from malloc.
83 Reported by Fabian Keil.
85 2009-06-17 Werner Koch <wk@g10code.com>
87 * call-pinentry.c (agent_get_confirmation): Add arg WITH_CANCEL.
89 * trustlist.c (agent_marktrusted): Use WITH_CANCEL
91 2009-06-09 Werner Koch <wk@g10code.com>
93 * learncard.c (send_cert_back): Ignore certain error codes.
95 2009-06-05 Werner Koch <wk@g10code.com>
97 * protect-tool.c (store_private_key): Fix last change by appending
100 2009-06-03 Werner Koch <wk@g10code.com>
102 * protect-tool.c: Include estream.h.
103 (store_private_key): Replace stdio streams by estream functions
104 for a portable use of the "x" mode.
105 * trustlist.c: Include estream.h.
106 (agent_marktrusted): Replace stdio stream by estream functions.
108 * protect-tool.c (store_private_key): Use bin2hex.
110 2009-06-02 Werner Koch <wk@g10code.com>
112 * gpg-agent.c (main): Run pth_kill after fork. Fixes bug#1066.
114 2009-05-19 Werner Koch <wk@g10code.com>
116 * gpg-agent.c (JNLIB_NEED_AFLOCAL): Define.
117 (create_server_socket): Use SUN_LEN macro.
119 2009-05-15 Werner Koch <wk@g10code.com>
123 * agent.h (lookup_ttl_t): New.
124 * findkey.c (unprotect): Add arg LOOKUP_TTL.
125 (agent_key_from_file): Ditto.
126 * pksign.c (agent_pksign_do): Ditto.
127 * command-ssh.c (ttl_from_sshcontrol): New.
128 (data_sign): Pass new function to agent_pksign_do.
129 (search_control_file): Add new arg R_TTL.
131 2009-05-14 Werner Koch <wk@g10code.com>
133 * command.c (cmd_get_passphrase): Add option --qualitybar.
134 * call-pinentry.c (agent_askpin): Factor some code out to ...
135 (setup_qualitybar): .. new.
136 (agent_get_passphrase): Add arg WITH_QUALITYBAR and implement it.
138 2009-04-14 Marcus Brinkmann <marcus@g10code.de>
140 * call-pinentry.c (agent_get_confirmation): Try SETNOTOK command
143 2009-04-01 Werner Koch <wk@g10code.com>
145 * protect-tool.c (pe_opt): New.
146 (opts): Add option --agent-program. Use ARGPARSE macros.
147 (get_new_passphrase): Remove.
148 (get_passphrase): Use gpg-agent directly. Remove arg OPT_CHECK and
150 * Makefile.am (gpg_protect_tool_LDADD): Replace pwquery_libs by
152 (gpg_protect_tool_CFLAGS): New.
154 * command.c (percent_plus_unescape): Remove.
155 (cmd_putval): Use percent_plus_unescape_inplace.
156 * call-scd.c (unescape_status_string): Remove.
157 (card_getattr_cb): Use percent_plus_unescape.
158 * protect-tool.c (main): Use percent_plus_unescape from common/.
159 (percent_plus_unescape, percent_plus_unescape_string): Remove.
161 2009-03-27 Werner Koch <wk@g10code.com>
163 * learncard.c (agent_handle_learn): Add new certtype 111.
165 2009-03-26 Werner Koch <wk@g10code.com>
167 * agent.h (MAX_DIGEST_LEN): Change to 64.
168 * command.c (cmd_sethash): Allow digest length of 48 and 64.
169 (cmd_sethash): Allow more hash algos.
171 * trustlist.c (reformat_name): New.
172 (agent_marktrusted): Use a reformatted name. Reload the table
173 before the update and always reload it at the end.
174 (agent_istrusted): Check early for the disabled flag.
176 2009-03-25 Werner Koch <wk@g10code.com>
178 * pkdecrypt.c (agent_pkdecrypt): Return a specific error message
179 if the key is not available.
181 * gpg-agent.c (main): Print a started message to show the real pid.
183 2009-03-20 Werner Koch <wk@g10code.com>
185 * learncard.c (struct kpinfo_cp_parm_s): Add field CTRL.
186 (struct certinfo_cb_parm_s): Ditto.
187 (agent_handle_learn): Set CTRL field.
188 (kpinfo_cb, certinfo_cb): Send progress status.
190 * agent.h (agent_write_status): Flag with GNUPG_GCC_A_SENTINEL.
192 2009-03-19 Werner Koch <wk@g10code.com>
194 * trustlist.c (struct trustitem_s): Add field DISABLED.
195 (read_one_trustfile): Parse the '!' flag.
196 (agent_istrusted, agent_listtrusted): Check flag.
197 (agent_istrusted): Add arg R_DISABLED. Change all callers.
198 (agent_marktrusted): Do not ask if flagged as disabled. Reverse
199 the order of the questions. Store the disabled flag.
201 * gpg-agent.c (main): Save signal mask and open fds. Restore mask
202 and close all fds prior to the exec. Fixes bug#1013.
204 2009-03-17 Werner Koch <wk@g10code.com>
206 * command.c (cmd_get_passphrase): Break repeat loop on error.
208 (cmd_getinfo): Add subcommand "cmd_has_option".
209 (command_has_option): New.
211 2009-03-17 Daiki Ueno <ueno@unixuser.org>
213 * command.c (option_value): New function.
214 (cmd_get_passphrase): Accept new option --repeat, which makes
215 gpg-agent to ask passphrase several times.
217 2009-03-06 Werner Koch <wk@g10code.com>
219 * command.c (cmd_keyinfo): New command.
220 (register_commands): Register it.
221 (agent_write_status): Make sure not to print LR or CR.
222 * divert-scd.c (ask_for_card): Factor shadow info parsing out to ...
223 * protect.c (parse_shadow_info): New.
224 * findkey.c (agent_key_from_file): Use make_canon_sexp.
225 (agent_write_private_key, unprotect, read_key_file)
226 (agent_key_available): Use bin2hex.
227 (agent_key_info_from_file): New.
228 (read_key_file): Log no error message for ENOENT.
230 2009-03-05 Werner Koch <wk@g10code.com>
232 * divert-scd.c (getpin_cb): Support flag 'P'. Change max_digits
233 from 8 to 16. Append a message about keypads.
234 * findkey.c (unprotect): Change max digits to 16.
236 2009-03-02 Werner Koch <wk@g10code.com>
238 * command.c (cmd_getinfo): Add subcommand "scd_running".
240 * call-scd.c (agent_scd_check_running): New.
242 * gpg-agent.c: Add missing option strings for "--batch" and
243 "--homedir". Reported by Petr Uzel.
245 * protect-tool.c (import_p12_file): Take care of canceled
246 passphrase entry. Fixes bug#1003.
247 (export_p12_file): Ditto.
249 2008-12-17 Werner Koch <wk@g10code.com>
251 * gpg-agent.c (handle_connections): Set action of all pth event
252 handled signals to SIG_IGN. Use a different pth_sigmask strategy.
254 2008-12-10 Werner Koch <wk@g10code.com>
256 * command.c (cmd_get_passphrase): Implement option --no-ask.
258 2008-12-09 Werner Koch <wk@g10code.com>
260 * gpg-agent.c (main): Call i18n_init before init_common_subsystems.
261 * preset-passphrase.c (main): Ditto.
262 * protect-tool.c (main): Ditto.
264 * command.c (cmd_preset_passphrase): Allow an arbitrary string for
267 2008-12-08 Werner Koch <wk@g10code.com>
269 * gpg-agent.c (handle_connections): Sync the ticker to the next
270 full second. This is bug#871.
272 2008-12-05 Werner Koch <wk@g10code.com>
274 * minip12.c (decrypt_block): Fix const modified of CHARSETS.
275 * learncard.c (sinfo_cb_parm_s): Remove superflous semicolon.
276 Reported by Stoyan Angelov.
278 2008-11-18 Werner Koch <wk@g10code.com>
280 * gpg-agent.c (make_libversion): New.
281 (my_strusage): Print libgcrypt version
283 2008-11-11 Werner Koch <wk@g10code.com>
285 * call-scd.c (membuf_data_cb): Change return type to
286 assuan_error_t to avoid warnings with newer libassuan versions.
288 2008-11-04 Werner Koch <wk@g10code.com>
290 * command.c (cmd_killagent): Stop the agent immediately.
291 (start_command_handler): Take care of GPG_ERR_EOF.
293 2008-10-29 Werner Koch <wk@g10code.com>
295 * gpg-agent.c (main): Move USE_STANDARD_SOCKET to the outer scope.
296 (create_socket_name): Remove arg USE_STANDARD_SOCKET. Change all
298 (create_server_socket): Remove IS_STANDARD_NAME and replace it by
299 USE_STANDARD_SOCKET. Change all callers.
300 (check_own_socket_running): New.
301 (check_own_socket, check_own_socket_thread): New.
302 (handle_tick): Check server socket once a minute.
303 (handle_connections): Remove the extra pth_wait in the shutdown
306 2008-10-20 Werner Koch <wk@g10code.com>
308 * command.c (cmd_geteventcounter): Mark unused arg.
309 (cmd_listtrusted, cmd_pksign, cmd_pkdecrypt, cmd_genkey): Ditto.
310 (cmd_updatestartuptty, post_cmd_notify): Ditto.
311 * command-ssh.c (add_control_entry)
312 (ssh_handler_request_identities, ssh_handler_remove_identity)
313 (ssh_handler_remove_all_identities, ssh_handler_lock)
314 (ssh_handler_unlock): Ditto.
315 * call-pinentry.c (pinentry_active_p, popup_message_thread)
316 (agent_popup_message_stop): Ditto.
317 * findkey.c (agent_public_key_from_file): Ditto.
318 * genkey.c (check_passphrase_pattern): Ditto.
319 * call-scd.c (atfork_cb): Ditto.
320 * protect-tool.c (import_p12_cert_cb): Ditto.
321 * t-protect.c (main): Ditto.
323 2008-10-17 Werner Koch <wk@g10code.com>
325 * call-scd.c (start_scd) [W32]: Use snprintf again because we now
326 always use the estream variant.
328 2008-10-15 Werner Koch <wk@g10code.com>
330 * call-scd.c (start_scd): Enable assuan loggging if requested.
331 (agent_scd_check_aliveness) [W32]: Fix use of GetExitCodeProcess.
333 2008-10-14 Werner Koch <wk@g10code.com>
335 * gpg-agent.c (get_agent_scd_notify_event): Need to use a manual
338 2008-09-29 Werner Koch <wk@g10code.com>
340 * agent.h (GCRY_MD_USER): Rename to GCRY_MODULE_ID_USER.
341 (GCRY_MD_USER_TLS_MD5SHA1): Rename to MD_USER_TLS_MD5SHA1 and
344 2008-09-25 Werner Koch <wk@g10code.com>
346 * divert-scd.c (getpin_cb): Support a Reset Code style PINs..
348 2008-09-03 Werner Koch <wk@g10code.com>
350 * command.c (parse_keygrip): Use hex2bin.
351 (cmd_preset_passphrase): Decode the passphrase. Reported by Kiss
352 Gabor. Fixes #679 again.
353 * preset-passphrase.c (make_hexstring): Remove.
354 (preset_passphrase): Use bin2hex.
356 2008-05-27 Werner Koch <wk@g10code.com>
358 * trustlist.c (insert_colons): Fix stupidly wrong allocation size
361 2008-05-26 Werner Koch <wk@g10code.com>
363 * gpg-agent.c (main): Re-initialize default assuan log stream if a
366 * trustlist.c (agent_marktrusted): Use xtryasprintf and xfree.
368 * gpg-agent.c (main, agent_deinit_default_ctrl): Always use xfree
369 because our asprintf is mapped to an xmalloc style function in
370 util.h. Replace xstrdup by xtrystrdup.
371 * w32main.c (build_argv): Ditto.
372 * preset-passphrase.c (preset_passphrase): Ditto.
373 * divert-scd.c (ask_for_card): Ditto.
374 * command.c (option_handler): Ditto.
375 * command-ssh.c (ssh_handler_request_identities): Ditto.
376 * call-pinentry.c (start_pinentry): Ditto.
378 * gpg-agent.c (start_connection_thread)
379 (start_connection_thread_ssh): Use pth_thread_id for useful output
381 (pth_thread_id) [!PTH_HAVE_PTH_THREAD_ID]: New.
383 2008-03-17 Werner Koch <wk@g10code.com>
385 * agent.h (agent_inq_pinentry_launched): New prototype.
387 * call-pinentry.c: Include sys/types.h and signal.h.
389 2008-02-14 Werner Koch <wk@g10code.com>
391 * command.c (agent_inq_pinentry_launched): New.
392 (option_handler): Add option allow-pinentry-notify.
393 * call-pinentry.c (getinfo_pid_cb): New.
394 (start_pinentry): Ask for the PID and notify the client.
396 2008-01-15 Marcus Brinkmann <marcus@g10code.de>
398 * call-pinentry.c (start_pinentry): Start pinentry in detached
401 2007-12-04 Werner Koch <wk@g10code.com>
403 * call-pinentry.c (agent_askpin): Use gnupg_get_help_string.
405 2007-12-03 Werner Koch <wk@g10code.com>
407 * gpg-agent.c (main): s/standard_socket/use_standard_socket/ for
409 (create_server_socket): New arg IS_SSH to avoid testing with
412 2007-11-20 Werner Koch <wk@g10code.com>
414 * gpg-agent.c (get_agent_scd_notify_event): New.
415 (handle_signal): Factor SIGUSR2 code out to:
416 (agent_sigusr2_action): .. New.
417 (agent_sighup_action): Print info message here and not in
419 (handle_connections) [PTH_EVENT_HANDLE]: Call agent_sigusr2_action.
421 * call-scd.c (agent_scd_check_aliveness) [W32]: Implemented.
422 (start_scd) [W32]: Send event-signal option.
424 2007-11-19 Werner Koch <wk@g10code.com>
426 * call-pinentry.c (agent_askpin): Set the tooltip for the quality
429 2007-11-15 Werner Koch <wk@g10code.com>
431 * agent.h (struct server_control_s): Add XAUTHORITY and
433 * gpg-agent.c: New option --xauthority.
434 (main, agent_init_default_ctrl)
435 (agent_deinit_default_ctrl): Implemented
436 * command.c (cmd_updatestartuptty): Ditto.
437 * command-ssh.c (start_command_handler_ssh): Ditto.
438 * call-pinentry.c (atfork_cb): Set the environment.
439 (start_pinentry): Pass CTRL as arg to atfork_cb.
441 2007-11-14 Werner Koch <wk@g10code.com>
443 * call-scd.c (start_scd) [W32]: Take care of fflush peculiarities.
445 2007-11-07 Werner Koch <wk@g10code.com>
447 * agent.h: Remove errors.h.
449 2007-10-24 Werner Koch <wk@g10code.com>
451 * genkey.c (check_passphrase_constraints): Changed the wording of
452 the warning messages.
454 2007-10-19 Werner Koch <wk@g10code.com>
456 * protect-tool.c (get_passphrase): Use new utf8 switch fucntions.
458 2007-10-15 Daiki Ueno <ueno@unixuser.org> (wk)
460 * command-ssh.c (reenter_compare_cb): New function; imported from
462 (ssh_identity_register): Ask initial passphrase twice.
464 2007-10-02 Werner Koch <wk@g10code.com>
466 * command.c (cmd_getinfo): Add "pid" subcommand.
468 2007-10-01 Werner Koch <wk@g10code.com>
470 * agent.h (struct server_control_s): Remove unused CONNECTION_FD.
472 * gpg-agent.c: Remove w32-afunix.h. Include mkdtemp.h.
473 (socket_nonce, socket_nonce_ssh): New.
474 (create_server_socket): Use assuan socket wrappers. Remove W32
475 specific stuff. Save the server nonce.
477 (start_connection_thread, start_connection_thread_ssh): Call it.
478 (handle_connections): Change args to gnupg_fd_t.
479 * command.c (start_command_handler): Change LISTEN_FD to gnupg_fd_t.
480 * command-ssh.c (start_command_handler_ssh): Ditto.
482 2007-09-18 Werner Koch <wk@g10code.com>
484 * agent.h (struct pin_entry_info_s): Add element WITH_QUALITYBAR.
485 * genkey.c (check_passphrase_constraints): New arg SILENT.
487 (agent_protect_and_store, agent_genkey): Enable qualitybar.
488 * call-pinentry.c (agent_askpin): Send that option.
489 (unescape_passphrase_string): New.
491 (estimate_passphrase_quality): New.
493 2007-09-14 Marcus Brinkmann <marcus@g10code.de>
495 * call-pinentry.c (agent_popup_message_stop): Implement kill for
498 2007-08-28 Werner Koch <wk@g10code.com>
500 * gpg-agent.c (main): Add option --faked-system-time.
502 * protect-tool.c (read_and_unprotect): Print the protected-at date.
504 * agent.h (struct server_control_s): Add member IN_PASSWD.
505 * command.c (cmd_passwd): Set it.
506 * findkey.c (try_unprotect_cb): Use it.
508 * protect.c (do_encryption): Replace asprintf by xtryasprint.
509 (agent_protect): Create the protected-at item.
510 (agent_unprotect): Add optional arg PROTECTED_AT.
511 (merge_lists): Add args CUTOFF and CUTLEN.
512 (agent_unprotect): Use them.
513 * findkey.c (try_unprotect_cb): Add code to test for expired keys.
514 (unprotect): Allow changing the passphrase.
516 2007-08-27 Werner Koch <wk@g10code.com>
518 * gpg-agent.c: Add options --min-passphrase-nonalpha,
519 --check-passphrase-pattern and --enforce-passphrase-constraints.
520 (MIN_PASSPHRASE_NONALPHA): Init nonalpha option to 1.
521 (main): Declare options for gpgconf.
522 * agent.h (struct): Add members MIN_PASSPHRASE_NONALPHA,
523 ENFORCE_PASSPHRASE_CONSTRAINTS and CHECK_PASSPHRASE_PATTERN.
524 * genkey.c (nonalpha_charcount): New.
525 (check_passphrase_pattern): New.
526 (check_passphrase_constraints): Implement. Factor some code out...
527 (take_this_one_anyway, take_this_one_anyway2): .. New.
529 * call-pinentry.c (agent_show_message): New.
530 (agent_askpin): We better reset the pin buffer before asking.
532 * trustlist.c (insert_colons): New.
533 (agent_marktrusted): Pretty print the fpr.
535 2007-08-22 Werner Koch <wk@g10code.com>
537 * findkey.c (O_BINARY): Make sure it is defined.
538 (agent_write_private_key): Use O_BINARY
540 * protect-tool.c (import_p12_file): Add hack to allow importing of
541 gnupg 2.0.4 generated files.
543 2007-08-06 Werner Koch <wk@g10code.com>
545 * trustlist.c (read_one_trustfile): Add flag "cm".
546 (agent_istrusted): Ditto.
548 2007-08-02 Werner Koch <wk@g10code.com>
550 * gpg-agent.c: Include gc-opt-flags.h and remove their definition
553 2007-07-13 Werner Koch <wk@g10code.com>
555 * genkey.c (check_passphrase_constraints): Require a confirmation
556 for an empty passphrase.
557 (agent_genkey, agent_protect_and_store): No need to repeat an
560 2007-07-05 Werner Koch <wk@g10code.com>
562 * call-scd.c (struct inq_needpin_s): New.
563 (inq_needpin): Pass unknown inquiries up.
565 2007-07-04 Werner Koch <wk@g10code.com>
567 * gpg-agent.c (TIMERTICK_INTERVAL): New.
568 (fixed_gcry_pth_init, main): Kludge to fix Pth initialization.
570 2007-07-03 Werner Koch <wk@g10code.com>
572 * gpg-agent.c (handle_connections): Do not use FD_SETSIZE for
573 select but compute the correct number.
575 2007-07-02 Werner Koch <wk@g10code.com>
577 * command.c (cmd_reloadagent) [W32]: New.
578 (register_commands) [W32]: New command RELOADAGENT.
580 * Makefile.am (gpg_agent_SOURCES): Remove w32main.c and w32main.h.
581 (gpg_agent_res_ldflags): Remove icon file as we don't have a
583 * gpg-agent.c (main): do not include w32main.h. Remove all calls
585 (agent_sighup_action): New.
586 (handle_signal): Use it.
588 2007-06-26 Werner Koch <wk@g10code.com>
590 * gpg-agent.c (create_directories) [W32]: Made it work.
592 2007-06-21 Werner Koch <wk@g10code.com>
594 * agent.h (ctrl_t): Remove. It is now declared in ../common/util.h.
596 * gpg-agent.c (check_for_running_agent): New arg SILENT. Changed
598 (create_server_socket): If the standard socket is in use check
599 whether a agent is running and avoid starting another one.
601 2007-06-18 Marcus Brinkmann <marcus@g10code.de>
603 * gpg-agent.c (main): Percent escape pathname in --gpgconf-list
606 2007-06-18 Werner Koch <wk@g10code.com>
608 * w32main.c (build_argv): New.
611 * command.c (cmd_killagent) [W32]: New.
613 * gpg-agent.c (get_agent_ssh_socket_name): New.
614 (no_force_standard_socket) New.
615 (create_server_socket): Use it.
616 * Makefile.am (gpg_agent_res_ldflags): Pass windows option to ld.
618 2007-06-14 Werner Koch <wk@g10code.com>
620 * protect-tool.c (main): Setup default socket name for
622 (MAP_SPWQ_ERROR_IMPL): New. Use map_spwq_error for spqw related
624 * preset-passphrase.c (main): Setup default socket name for
626 (map_spwq_error): Remove.
627 (MAP_SPWQ_ERROR_IMPL): New.
629 * call-pinentry.c (start_pinentry): Use gnupg_module_name.
630 * call-scd.c (start_scd): Ditto.
632 2007-06-12 Werner Koch <wk@g10code.com>
636 * trustlist.c (read_one_trustfile): Replace GNUPG_SYSCONFDIR by a
638 (read_trustfiles): Ditto.
640 * gpg-agent.c (main): Replace some calls by init_common_subsystems.
641 * preset-passphrase.c (main): Ditto.
642 * protect-tool.c (main): Ditto.
644 2007-06-11 Werner Koch <wk@g10code.com>
646 * Makefile.am (common_libs): Use libcommonstd macro.
647 (commonpth_libs): Use libcommonpth macro.
649 * protect-tool.c (main) [W32]: Call pth_init.
651 * preset-passphrase.c (main) [W32]: Replace the explicit Winsocket
652 init by a call to pth_init.
654 * trustlist.c (initialize_module_trustlist): New.
655 * gpg-agent.c (main): Call it.
657 * call-pinentry.c (initialize_module_query): Rename to
658 initialize_module_call_pinentry.
660 * minip12.c: Remove iconv.h. Add utf8conf.h. Changed all iconv
661 calss to use these jnlib wrappers.
663 2007-06-06 Werner Koch <wk@g10code.com>
665 * minip12.c (enum): Rename CONTEXT to ASNCONTEXT as winnt.h
666 defines such a symbol to access the process context.
668 * call-pinentry.c (dump_mutex_state) [W32]: Handle the W32Pth case.
669 * call-scd.c (dump_mutex_state): Ditto.
671 * protect-tool.c (i18n_init): Remove.
672 * preset-passphrase.c (i18n_init): Remove.
673 * gpg-agent.c (i18n_init): Remove.
675 2007-05-19 Marcus Brinkmann <marcus@g10code.de>
677 * protect-tool.c (get_passphrase): Free ORIG_CODESET on error.
679 2007-05-14 Werner Koch <wk@g10code.com>
681 * protect.c (make_shadow_info): Replace sprintf by smklen.
683 2007-04-20 Werner Koch <wk@g10code.com>
685 * gpg-agent.c (my_gcry_logger, my_gcry_outofcore_handler): Removed.
686 (main): Call the setup_libgcrypt_logging helper.
687 * protect-tool.c (my_gcry_logger): Removed.
688 (main): Call the setup_libgcrypt_logging helper.
690 2007-04-03 Werner Koch <wk@g10code.com>
692 * trustlist.c (read_trustfiles): Take a missing trustlist as an
695 2007-03-20 Werner Koch <wk@g10code.com>
697 * protect-tool.c: New option --p12-charset.
698 * minip12.c (p12_build): Implement it.
700 2007-03-19 Werner Koch <wk@g10code.com>
702 * minip12.c: Include iconv.h.
703 (decrypt_block): New.
704 (parse_bag_encrypted_data, parse_bag_data): Use it here.
705 (bag_data_p, bag_decrypted_data_p): New helpers.
707 2007-03-06 Werner Koch <wk@g10code.com>
709 * gpg-agent.c (main) <gpgconf>: Add entries for all ttl options.
711 2007-02-20 Werner Koch <wk@g10code.com>
713 * call-pinentry.c (start_pinentry): Fix for OS X to allow loading
714 of the bundle. Tested by Benjamin Donnachie.
716 2007-02-14 Werner Koch <wk@g10code.com>
718 * gpg-agent.c: New option --pinentry-touch-file.
719 (get_agent_socket_name): New.
720 * agent.h (opt): Add pinentry_touch_file.
721 * call-pinentry.c (start_pinentry): Send new option to the
724 2007-01-31 Moritz Schulte <moritz@g10code.com> (wk)
726 * command-ssh.c (stream_read_string): Initialize LENGTH to zero.
727 (start_command_handler_ssh): Use es_fgetc/es_ungetc to check if
728 EOF has been reached before trying to process another request.
730 2007-01-31 Werner Koch <wk@g10code.com>
732 * command-ssh.c (start_command_handler_ssh):
734 * Makefile.am (t_common_ldadd): Add LIBICONV.
736 2007-01-25 Werner Koch <wk@g10code.com>
738 * genkey.c (check_passphrase_constraints): Get ngettext call right
739 and use UTF-8 aware strlen.
741 * protect-tool.c (get_passphrase): New arg OPT_CHECK.
742 (get_new_passphrase): Enable OPT_CHECK on the first call.
743 * command.c (cmd_get_passphrase): Implement option --check.
745 2007-01-24 Werner Koch <wk@g10code.com>
747 * gpg-agent.c (MIN_PASSPHRASE_LEN): New
748 (parse_rereadable_options): New option --min-passphrase-len.
749 * genkey.c (check_passphrase_constraints): New.
750 (agent_genkey, agent_protect_and_store): Call new function. Fix
753 * call-pinentry.c (agent_askpin): Allow translation of the displayed
755 (agent_popup_message_start): Remove arg CANCEL_BTN.
756 (popup_message_thread): Use --one-button option.
758 * command.c (cmd_passwd): Now that we don't distinguish between
759 assuan and regular error codes we can jump to the end on error.
761 2006-12-07 David Shaw <dshaw@jabberwocky.com>
763 * Makefile.am: Link to iconv for jnlib dependency.
765 2006-11-20 Werner Koch <wk@g10code.com>
767 * call-pinentry.c (agent_popup_message_stop): Use SIGKILL.
768 * call-scd.c (inq_needpin): Implement POPUPKEYPADPROMPT and
771 2006-11-15 Werner Koch <wk@g10code.com>
773 * protect.c (make_shadow_info): Cast printf arg to unsigned int.
774 * minip12.c (parse_bag_encrypted_data): Ditto.
775 (parse_bag_data, p12_parse): Ditto.
776 * command-ssh.c (ssh_identity_register): Changed buffer_n to
779 * agent.h (struct server_control_s): New field thread_startup.
780 * command.c (start_command_handler): Moved CTRL init code to ..
781 * gpg-agent.c (start_connection_thread): .. here.
782 (agent_deinit_default_ctrl): New.
783 (agent_init_default_ctrl): Made static.
784 (handle_connections): Allocate CTRL and pass it pth_spawn.
785 * command-ssh.c (start_command_handler_ssh): Moved CTRL init code
787 * gpg-agent.c (start_connection_thread_ssh): .. here.
789 2006-11-14 Werner Koch <wk@g10code.com>
791 * command.c (bump_key_eventcounter): New.
792 (bump_card_eventcounter): New.
793 (cmd_geteventcounter): New command.
794 * gpg-agent.c (handle_signal): Call bump_card_eventcounter.
795 * findkey.c (agent_write_private_key): Call bump_key_eventcounter.
796 * trustlist.c (agent_reload_trustlist): Ditto.
798 * command.c (post_cmd_notify, io_monitor): New.
799 (register_commands, start_command_handler): Register them.
801 2006-11-09 Werner Koch <wk@g10code.com>
803 * gpg-agent.c (main): In detached mode connect standard
804 descriptors to /dev/null.
806 * trustlist.c (read_trustfiles): Make sure not to pass a zero size
807 to realloc as the C standards says that this behaves like free.
809 2006-11-06 Werner Koch <wk@g10code.com>
811 * protect-tool.c (my_strusage): Fixed typo.
813 2006-10-23 Werner Koch <wk@g10code.com>
815 * gpg-agent.c (main): New command --gpgconf-test.
817 * minip12.c (parse_bag_encrypted_data, parse_bag_data): Allow for
820 2006-10-20 Werner Koch <wk@g10code.com>
822 * Makefile.am (t_common_ldadd): Use GPG_ERROR_LIBS instead -o just -l
824 2006-10-19 Werner Koch <wk@g10code.com>
826 * findkey.c (unprotect): Use it to avoid unnecessary calls to
828 * call-pinentry.c (pinentry_active_p): New.
830 2006-10-17 Werner Koch <wk@g10code.com>
832 * Makefile.am (gpg_agent_LDADD): Link to libcommonpth.
833 (gpg_agent_CFLAGS): New. This allows to only link this with Pth.
835 2006-10-16 Werner Koch <wk@g10code.com>
837 * call-pinentry.c (agent_get_confirmation): Map Cancel code here too.
838 * trustlist.c (agent_marktrusted): Return Cancel instead of
839 Not_Confirmed for the first question.
841 2006-10-12 Werner Koch <wk@g10code.com>
843 * protect-tool.c (get_passphrase): Fix if !HAVE_LANGINFO_CODESET.
845 2006-10-06 Werner Koch <wk@g10code.com>
847 * Makefile.am (AM_CFLAGS): Use PTH version of libassuan.
848 (gpg_agent_LDADD): Ditto.
850 * divert-scd.c (divert_pksign): Use PKAUTH for the TLS algo.
852 2006-10-05 Werner Koch <wk@g10code.com>
854 * command.c (has_option_name): New.
855 (cmd_sethash): New --hash option.
856 * pksign.c (do_encode_raw_pkcs1): New.
857 (agent_pksign_do): Use it here for the TLS algo.
858 * agent.h (GCRY_MD_USER_TLS_MD5SHA1): New.
859 * divert-scd.c (pksign): Add case for tls-md5sha1.
861 * divert-scd.c (encode_md_for_card): Check that the algo is valid.
863 2006-10-04 Werner Koch <wk@g10code.com>
865 * call-pinentry.c (agent_get_passphrase): Changed to return the
866 unencoded passphrase.
867 (agent_askpin, agent_get_passphrase, agent_get_confirmation): Need
868 to map the cancel error.
869 * command.c (send_back_passphrase): New.
870 (cmd_get_passphrase): Use it here. Also implement --data option.
873 2006-09-26 Werner Koch <wk@g10code.com>
875 * learncard.c (agent_handle_learn): Send back the keypair
878 2006-09-25 Werner Koch <wk@g10code.com>
880 * trustlist.c (read_one_trustfile): Allow extra flags.
881 (struct trustitem_s): Replaced KEYFLAGS by a FLAGS struct.
882 Changed all code to use this.
883 (agent_istrusted): New arg CTRL. Changed all callers. Send back
885 * command.c (agent_write_status): New.
887 2006-09-20 Werner Koch <wk@g10code.com>
889 * Makefile.am: Changes to allow parallel make runs.
891 2006-09-15 Werner Koch <wk@g10code.com>
893 * trustlist.c: Entirely rewritten.
894 (agent_trustlist_housekeeping): Removed and removed all calls.
896 2006-09-14 Werner Koch <wk@g10code.com>
898 Replaced all call gpg_error_from_errno(errno) by
899 gpg_error_from_syserror().
901 * call-pinentry.c (start_pinentry): Replaced pipe_connect2 by
903 * call-scd.c (start_scd): Ditto.
904 * command.c (start_command_handler): Replaced
905 init_connected_socket_server by init_socket_server_ext.
907 2006-09-13 Werner Koch <wk@g10code.com>
909 * preset-passphrase.c (main) [W32]: Check for WSAStartup error.
911 2006-09-08 Werner Koch <wk@g10code.com>
913 * call-scd.c: Add signal.h as we are referencing SIGUSR2.
915 2006-09-06 Marcus Brinkmann <marcus@g10code.de>
917 * Makefile.am (AM_CFLAGS): Add $(GPG_ERR_CFLAGS).
918 (gpg_agent_LDADD): Replace -lgpg-error with $(GPG_ERROR_LIBS).
920 2006-09-06 Werner Koch <wk@g10code.com>
922 * query.c: Renamed to ..
923 * call-pinentry.c: .. this.
925 * agent.h (out_of_core): Removed.
926 (CTRL): Removed and changed everywhere to ctrl_t.
928 Replaced all Assuan error codes by libgpg-error codes. Removed
929 all map_to_assuan_status and map_assuan_err.
931 * gpg-agent.c (main): Call assuan_set_assuan_err_source to have Assuan
932 switch to gpg-error codes.
933 * command.c (set_error): Adjusted.
935 2006-09-04 Werner Koch <wk@g10code.com>
937 * command.c (percent_plus_unescape): New.
938 (cmd_get_val, cmd_putval): New.
940 2006-08-29 Werner Koch <wk@g10code.com>
942 * command-ssh.c (stream_read_mpi): Sanity check for early
943 detecting of too large keys.
944 * gpg-agent.c (my_gcry_outofcore_handler): New.
946 (main): No allocate 32k secure memory (was 16k).
948 2006-07-31 Werner Koch <wk@g10code.com>
950 * preset-passphrase.c (make_hexstring): For consistency use
951 xtrymalloc and changed caller to use xfree. Fixed function
954 2006-07-29 Marcus Brinkmann <marcus@g10code.de>
956 * preset-passphrase.c (preset_passphrase): Do not strip off last
957 character of passphrase.
958 (make_hexstring): New function.
959 * command.c (cmd_preset_passphrase): Use parse_hexstring to syntax
960 check passphrase argument. Truncate passphrase at delimiter.
962 2006-07-24 Werner Koch <wk@g10code.com>
964 * minip12.c (build_key_bag): New args SHA1HASH and
965 KEYIDSTR. Append bag Attributes if these args are given.
966 (build_cert_sequence): ditto.
967 (p12_build): Calculate certificate hash and pass to build
970 2006-07-21 Werner Koch <wk@g10code.com>
972 * minip12.c (oid_pkcs_12_keyBag): New.
973 (parse_bag_encrypted_data): New arg R_RESULT. Support keybags and
974 return the key object.
975 (p12_parse): Take new arg into account. Free RESULT on error.
977 2006-06-26 Werner Koch <wk@g10code.com>
979 * gpg-agent.c (handle_signal): Print info for SIGUSR2 only in
982 2006-06-22 Werner Koch <wk@g10code.com>
984 * command-ssh.c (make_cstring): Use memcpy instead of strncpy.
985 (ssh_receive_mpint_list, sexp_key_extract, data_sign): Use
986 xtrycalloc instead of xtrymalloc followed by memset.
988 2006-06-20 Werner Koch <wk@g10code.com>
990 * minip12.c (create_final): New arg PW. Add code to calculate the
993 2006-06-09 Marcus Brinkmann <marcus@g10code.de>
995 * Makefile.am (gpg_agent_LDADD): Add $(NETLIBS).
996 (gpg_protect_tool_LDADD): Likewise.
997 (gpg_preset_passphrase_LDADD): Likewise.
999 2006-04-09 Moritz Schulte <moritz@g10code.com>
1001 * command-ssh.c (ssh_request_process): Removed FIXME mentioning a
1002 possible DoS attack.
1004 2006-04-01 Moritz Schulte <moritz@g10code.com>
1006 * command-ssh.c (ssh_identity_register): Make KEY_GRIP_RAW be 20
1007 instead of 21 bytes long; do not fill KEY_GRIP_RAW[20] with NUL
1008 byte - KEY_GRIP_RAW is a raw binary string anyway.
1010 2006-02-09 Werner Koch <wk@g10code.com>
1012 * call-scd.c (struct scd_local_s): New field next_local.
1013 (scd_local_list): New.
1014 (start_scd): Put new local into list.
1015 (agent_reset_scd): Remove it from the list.
1016 (agent_scd_check_aliveness): Here is the actual reason why we need
1018 (agent_reset_scd): Send the new command RESTART instead of RESET.
1020 2005-12-16 Werner Koch <wk@g10code.com>
1022 * minip12.c (cram_octet_string): New
1023 (p12_parse): Use it for NDEFed bags.
1024 (parse_bag_data): Ditto.
1025 (string_to_key, set_key_iv, crypt_block): New arg SALTLEN.
1026 (p12_build): Use old value 8 for new arg.
1027 (parse_bag_encrypted_data, parse_bag_data): Allow for salts of 8
1028 to 16 bytes. Add new arg R_CONSUMED.
1030 2005-11-24 Werner Koch <wk@g10code.com>
1032 * minip12.c (p12_parse): Fixed for case that the key object comes
1033 prior to the certificate.
1035 2005-10-19 Werner Koch <wk@g10code.com>
1037 * divert-scd.c (getpin_cb): Hack to use it for a keypad message.
1039 * call-scd.c (inq_needpin): Reworked to support the new KEYPADINFO.
1041 * query.c (start_pinentry): Keep track of the owner.
1042 (popup_message_thread, agent_popup_message_start)
1043 (agent_popup_message_stop, agent_reset_query): New.
1044 * command.c (start_command_handler): Make sure a popup window gets
1047 2005-10-08 Marcus Brinkmann <marcus@g10code.de>
1049 * Makefile.am (gpg_protect_tool_LDADD): Add ../gl/libgnu.a.
1050 (gpg_preset_passphrase_LDADD, t_common_ldadd): Likewise.
1051 (gpg_agent_LDADD): Add ../gl/libgnu.a after ../common/libcommon.a.
1053 2005-09-16 Werner Koch <wk@g10code.com>
1055 * minip12.c (build_key_sequence, build_cert_sequence): Fixed
1058 2005-09-15 Moritz Schulte <moritz@g10code.com>
1060 * t-protect.c (test_agent_protect): Implemented.
1061 (main): Disable use of secure memory.
1063 2005-09-09 Werner Koch <wk@g10code.com>
1065 * minip12.c (p12_build): Oops, array needs to be larger for the
1067 (build_cert_bag): Fixed yesterdays change.
1069 * command-ssh.c (card_key_available): Let the card handler decide
1070 whether the card is supported here. Also get a short serial
1071 number to return from the card handler.
1073 2005-09-08 Werner Koch <wk@g10code.com>
1075 * minip12.c (build_cert_bag): Use a non constructed object.
1076 i.e. 0x80 and not 0xa0.
1078 2005-08-16 Werner Koch <wk@g10code.com>
1080 * gpg-agent.c (main): Use a default file name for --write-env-file.
1082 2005-07-25 Werner Koch <wk@g10code.com>
1084 * findkey.c (agent_public_key_from_file): Fixed array assignment.
1085 This was the cause for random segvs.
1087 2005-06-29 Werner Koch <wk@g10code.com>
1089 * command-ssh.c (data_sign): Removed empty statement.
1091 2005-06-21 Werner Koch <wk@g10code.com>
1093 * minip12.c (create_final): Cast size_t to ulong for printf.
1094 (build_key_bag, build_cert_bag, build_cert_sequence): Ditto.
1096 2005-06-16 Werner Koch <wk@g10code.com>
1098 * protect-tool.c (make_advanced): Makde RESULT a plain char.
1099 * call-scd.c (unescape_status_string): Need to cast unsigned char*
1101 (agent_card_pksign): Made arg R_BUF an unsigned char**.
1102 * divert-scd.c (divert_pksign): Made SIGVAL unsigned char*.
1103 (encode_md_for_card): Initialize R_VAL and R_LEN.
1104 * genkey.c (store_key): Made BUF unsigned.
1105 * protect.c (do_encryption): Ditto.
1106 (do_encryption): Made arg PROTBEGIN unsigned. Initialize RESULT
1107 and RESULTLEN even on error.
1108 (merge_lists): Need to cast unsigned char * for strcpy. Initialize
1109 RESULTand RESULTLEN even on error.
1110 (agent_unprotect): Likewise for strtoul.
1111 (make_shadow_info): Made P and INFO plain char.
1112 (agent_shadow_key): Made P plain char.
1114 2005-06-15 Werner Koch <wk@g10code.com>
1116 * query.c (agent_get_passphrase): Made HEXSTRING a char*.
1117 * command-ssh.c (ssh_key_grip): Made arg BUFFER unsigned.
1118 (ssh_key_grip): Simplified.
1119 (data_sign): Initialize variables with the definition.
1120 (ssh_convert_key_to_blob): Make sure that BLOB and BLOB_SIZE
1121 are set to NULL on error. Cool, gcc-4 detects uninitialized stuff
1122 beyond function boundaries; well it can't know that we do error
1123 proper error handling so that this was not a real error.
1124 (file_to_buffer): Likewise for BUFFER and BUFFER_N.
1125 (data_sign): Likewise for SIG and SIG_N.
1126 (stream_read_byte): Set B to a value even on error.
1127 * command.c (cmd_genkey): Changed VALUE to char.
1128 (cmd_readkey): Cast arg for gcry_sexp_sprint.
1129 * agent.h (struct server_control_s): Made KEYGRIP unsigned.
1131 2005-06-13 Werner Koch <wk@g10code.com>
1133 * command-ssh.c (start_command_handler_ssh): Reset the SCD.
1135 2005-06-09 Werner Koch <wk@g10code.com>
1137 * gpg-agent.c (create_socket_name): New option --max-cache-ttl-ssh.
1138 * cache.c (housekeeping): Use it.
1139 (agent_put_cache): Use a switch to get the default ttl so that it
1140 is easier to add more cases.
1142 2005-06-06 Werner Koch <wk@g10code.com>
1144 * gpg-agent.c: New option --default-cache-ttl-ssh.
1145 * agent.h (cache_mode_t): New.
1146 * pksign.c (agent_pksign_do): New arg CACHE_MODE to replace the
1147 ARG IGNORE_CACHE. Changed all callers.
1148 (agent_pksign): Ditto.
1149 * findkey.c (agent_key_from_file): Ditto. Canged all callers.
1151 * command-ssh.c (data_sign): Use CACHE_MODE_SSH.
1152 * cache.c (agent_get_cache): New arg CACHE_MODE.
1153 (agent_put_cache): Ditto. Store it in the cache.
1155 * query.c (agent_query_dump_state, dump_mutex_state): New.
1156 (unlock_pinentry): Reset the global context before releasing the
1158 * gpg-agent.c (handle_signal): Dump query.c info on SIGUSR1.
1160 * call-scd.c (agent_scd_check_aliveness): Always do a waitpid and
1161 add a timeout to the locking.
1163 2005-06-03 Werner Koch <wk@g10code.com>
1165 * command.c (cmd_updatestartuptty): New.
1167 * gpg-agent.c: New option --write-env-file.
1169 * gpg-agent.c (handle_connections): Make sure that the signals we
1170 are handling are not blocked.Block signals while creating new
1173 2005-06-02 Werner Koch <wk@g10code.com>
1175 * call-scd.c (agent_scd_dump_state, dump_mutex_state): New.
1176 * gpg-agent.c (handle_signal): Print it on SIGUSR1.
1177 (handle_connections): Include the file descriptor into the
1180 2005-06-01 Werner Koch <wk@g10code.com>
1182 * gpg-agent.c: Include setenv.h.
1184 2005-05-31 Werner Koch <wk@g10code.com>
1186 * agent.h (out_of_core): s/__inline__/inine. Noted by Ray Link.
1188 2005-05-25 Werner Koch <wk@g10code.com>
1190 * gpg-agent.c (main): Do not unset the DISPLAY when we are
1191 continuing as child.
1193 2005-05-24 Werner Koch <wk@g10code.com>
1195 * call-scd.c (inq_needpin): Skip leading spaces in of PIN
1197 * divert-scd.c (getpin_cb): Enhanced to cope with description
1199 * query.c (agent_askpin): Add arg PROMPT_TEXT. Changed all
1202 2005-05-21 Werner Koch <wk@g10code.com>
1204 * call-scd.c (start_scd): Don't test for an alive scdaemon here.
1205 (agent_scd_check_aliveness): New.
1206 * gpg-agent.c (handle_tick): Test for an alive scdaemon.
1207 (handle_signal): Print thread info on SIGUSR1.
1209 2005-05-20 Werner Koch <wk@g10code.com>
1211 * protect-tool.c: New option --canonical.
1212 (show_file): Implement it.
1214 * keyformat.txt: Define the created-at attribute for keys.
1216 2005-05-18 Werner Koch <wk@g10code.com>
1218 * divert-scd.c (ask_for_card): Removed the card reset kludge.
1220 2005-05-17 Werner Koch <wk@g10code.com>
1222 * call-scd.c (unlock_scd): Add new arg CTRL. Changed all callers.
1223 (start_scd): Reoworked to allow for additional connections.
1224 * agent.h (ctrl_t): Add local data for the SCdaemon.
1225 * command.c (start_command_handler): Release SERVER_LOCAL.
1227 * gpg-agent.c (create_server_socket): Use xmalloc.
1228 (main): Removed option --disable-pth a dummy. Removed non-pth
1230 (cleanup_sh): Removed. Not needed anymore.
1232 2005-05-05 Moritz Schulte <moritz@g10code.com>
1234 * command-ssh.c (ssh_key_to_buffer): Rename to ...
1235 (ssh_key_to_protected_buffer): ... this; change callers.
1236 Improved documentation.
1237 Use ssh_key_grip(), where gcry_pk_get_keygrip() has been used
1239 (ssh_handler_sign_request): Removed unusued variable P.
1241 2005-04-20 Moritz Schulte <moritz@g10code.com>
1243 * command-ssh.c (ssh_handler_request_identities): Removed
1244 debugging code (sleep call), which was commited unintenionally.
1246 2005-04-20 Werner Koch <wk@g10code.com>
1248 * minip12.c (parse_bag_encrypted_data): Fix the unpadding hack.
1250 * gpg-agent.c: New option --disable-scdaemon.
1251 (handle_connections): Add time event to drive ...
1252 (handle_tick): New function.
1253 (main): Record the parent PID. Fixed segv when using ssh and a
1256 * call-scd.c (start_scd): Take care of this option.
1258 2005-04-03 Moritz Schulte <moritz@g10code.com>
1260 * command-ssh.c (ssh_request_spec): New member: secret_input.
1261 (REQUEST_SPEC_DEFINE): New argument: secret_input.
1262 (request_specs): Add secret_input flag.
1263 (request_spec_lookup): New function ...
1264 (ssh_request_process): ... use it here; depending on secret_input
1265 flag allocate secure or non-secure memory.
1267 2005-03-02 Moritz Schulte <moritz@g10code.com>
1269 * command-ssh.c (sexp_key_extract): Removed FIXME, since
1270 xtrymallos does set errno correctly by now.
1271 (sexp_extract_identifier): Remove const attribute from identifier.
1272 (ssh_handler_request_identities): Remove const attribute from
1273 key_type; removes ugly casts and FIXME.
1274 (sexp_key_extract): Remove const attribute from comment.
1275 (ssh_send_key_public): Remove const attribute from
1276 key_type/comment; removes ugly cast.
1277 (data_sign): Remove const attribute from identifier; removes ugly
1279 (key_secret_to_public): Remove const attribute from comment;
1281 (ssh_handler_sign_request): Remove const attribute from p.
1282 (sexp_key_extract): Use make_cstring().
1283 (ssh_key_extract_comment): Likewise.
1284 (ssh_key_to_buffer): Use secure memory for memory area to hold the
1286 Added more comments.
1288 2005-02-25 Werner Koch <wk@g10code.com>
1290 * findkey.c (modify_description): Keep invalid % escapes, so that
1291 %0A may pass through.
1293 * agent.h (server_control_s): New field USE_AUTH_CALL.
1294 * call-scd.c (agent_card_pksign): Make use of it.
1295 * command-ssh.c (data_sign): Set the flag.
1296 (ssh_send_key_public): New arg OVERRIDE_COMMENT.
1297 (card_key_available): Add new arg CARDSN.
1298 (ssh_handler_request_identities): Use the card s/n as comment.
1299 (sexp_key_extract): Use GCRYMPI_FMT_STD.
1302 * learncard.c (make_shadow_info): Moved to ..
1303 * protect.c (make_shadow_info): .. here. Return NULL on malloc
1304 failure. Made global.
1305 * agent.h: Add prototype.
1307 2005-02-24 Werner Koch <wk@g10code.com>
1309 * call-scd.c (unescape_status_string): New. Actual a copy of
1311 (card_getattr_cb, agent_card_getattr): New.
1313 * command-ssh.c (card_key_available): New.
1314 (ssh_handler_request_identities): First see whether a card key is
1317 * gpg-agent.c (handle_connections): Need to check for events if
1318 select returns with -1.
1320 2005-02-23 Werner Koch <wk@g10code.com>
1322 * command-ssh.c (get_passphrase): Removed.
1323 (ssh_identity_register): Partly rewritten.
1324 (open_control_file, search_control_file, add_control_entry): New.
1325 (ssh_handler_request_identities): Return only files listed in our
1328 * findkey.c (unprotect): Check for allocation error.
1330 * agent.h (opt): Add fields to record the startup terminal
1332 * gpg-agent.c (main): Record them and do not force keep display
1333 with --enable-ssh-support.
1334 * command-ssh.c (start_command_handler_ssh): Use them here.
1336 * gpg-agent.c: Renamed option --ssh-support to
1337 --enable-ssh-support.
1339 * command.c (cmd_readkey): New.
1340 (register_commands): Register new command "READKEY".
1342 * command-ssh.c (ssh_request_process): Improved logging.
1344 * findkey.c (agent_write_private_key): Always use plain open.
1345 Don't depend on an umask for permissions.
1346 (agent_key_from_file): Factored file reading code out to ..
1347 (read_key_file): .. new function.
1348 (agent_public_key_from_file): New.
1350 2005-02-22 Werner Koch <wk@g10code.com>
1352 * command-ssh.c (stream_read_string): Removed call to abort on
1353 memory error because the CVS version of libgcrypt makes sure
1354 that ERRNO gets always set on error even with a faulty user
1357 2005-02-19 Moritz Schulte <moritz@g10code.com>
1359 * command-ssh.c (ssh_receive_mpint_list): Slightly rewritten, do
1360 not use elems_secret member of key_spec.
1361 (ssh_key_type_spec): Removed member: elems_secret.
1362 (ssh_key_types): Removed elems_secret data.
1363 (ssh_sexp_construct): Renamed to ...
1364 (sexp_key_construct): ... this; changed callers.
1365 (ssh_sexp_extract): Renamed to ...
1366 (sexp_key_extract): ... this; changed callers.
1367 (ssh_sexp_extract_key_type): Renamed to ...
1368 (sexp_extract_identifier): ... this; changed callers; use
1370 Added more comments.
1372 2005-02-18 Moritz Schulte <moritz@g10code.com>
1374 * command-ssh.c (ssh_sexp_construct): Rewritten generation of sexp
1375 template, clarified.
1376 (ssh_sexp_extract): Support shadowed-private-key-sexp; treat
1377 protected-private key and shadowed-private-key as public keys.
1378 (key_secret_to_public): Rewritten: simply use ssh_sexp_extract()
1379 and ssh_sexp_construct().
1381 2005-02-15 Werner Koch <wk@g10code.com>
1383 * findkey.c (modify_description): Don't increment OUT_LEN during
1386 2005-02-14 Moritz Schulte <moritz@g10code.com>
1388 * command-ssh.c (es_read_byte): Renamed to ...
1389 (stream_es_read_byte): ... this; changed callers.
1390 (es_write_byte): Renamed to ...
1391 (stream_write_byte): ... this; changed callers.
1392 (es_read_uint32): Renamed to ...
1393 (stream_read_uint32): ... this; changed callers.
1394 (es_write_uint32): Renamed to ...
1395 (stream_write_uint32): ... this; changed callers.
1396 (es_read_data): Renamed to ...
1397 (stream_read_data): ... this; changed callers.
1398 (es_write_data): Renamed to ...
1399 (stream_write_data): ... this; changed callers.
1400 (es_read_string): Renamed to ...
1401 (stream_read_string): ... this; changed callers.
1402 (es_read_cstring): Renamed to ...
1403 (stream_read_cstring): ... this; changed callers.
1404 (es_write_string): Renamed to ...
1405 (stream_write_string): ... this; changed callers.
1406 (es_write_cstring): Renamed to ...
1407 (stream_write_cstring): ... this; changed callers.
1408 (es_read_mpi): Renamed to ...
1409 (stream_read_mpi): ... this; changed callers.
1410 (es_write_mpi): Renamed to ...
1411 (stream_write_mpi): ... this; changed callers.
1412 (es_copy): Renamed to ...
1413 (stream_copy): ... this; changed callers.
1414 (es_read_file): Renamed to ...
1415 (file_to_buffer): ... this; changed callers.
1416 (ssh_identity_register): Removed variable description_length;
1417 changed code to use asprintf for description.
1418 (stream_write_uint32): Do not filter out the last byte of shift
1420 (uint32_construct): New macro ...
1421 (stream_read_uint32): ... use it; removed unnecessary cast.
1423 2005-02-03 Werner Koch <wk@g10code.com>
1425 * agent.h (agent_exit): Add JNLIB_GCC_A_NR to indicate that this
1426 function won't return.
1428 * gpg-agent.c (check_for_running_agent): Initialize pid to a
1429 default value if not needed.
1431 * command-ssh.c: Removed stdint.h. s/byte_t/unsigned char/,
1432 s/uint32/u32/ becuase that is what we have always used in GnuPG.
1433 (ssh_request_specs): Moved to top of file.
1434 (ssh_key_types): Ditto.
1435 (make_cstring): Ditto.
1436 (data_sign): Don't use a variable for the passphrase prompt, make
1438 (ssh_request_process):
1441 * findkey.c (modify_description): Renamed arguments for clarity,
1442 polished documentation. Make comment a C-string. Fixed case of
1443 DESCRIPTION being just "%".
1444 (agent_key_from_file): Make sure comment string to a C-string.
1446 * gpg-agent.c (create_socket_name): Cleanup the implemntation, use
1447 DIMof, agent_exit, removed superflous args and return the
1448 allocated string as value. Documented. Changed callers.
1449 (create_server_socket): Cleanups similar to above. Changed callers.
1450 (cleanup_do): Renamed to ..
1451 (remove_socket): .. this. Changed caller.
1452 (handle_connections): The signals are to be handled in the select
1453 and not in the accept. Test all FDs after returning from a
1454 select. Remove the event tests from the accept calls. The select
1455 already assured that the accept won't block.
1457 2005-01-29 Moritz Schulte <moritz@g10code.com>
1459 * command-ssh.c (ssh_handler_request_identities)
1460 (ssh_handler_sign_request, ssh_handler_add_identity)
1461 (ssh_handler_remove_identity, ssh_handler_remove_all_identities)
1462 (ssh_handler_lock, ssh_handler_unlock): Changed to return an error
1463 code instead of a boolean.
1464 (ssh_request_process): Changed to return a boolean instead of an
1465 error; adjust caller.
1466 (ssh_request_handle_t): Adjusted type.
1467 (ssh_request_spec): New member: identifier.
1468 (REQUEST_SPEC_DEFINE): New macro; use it for initialization of
1470 (ssh_request_process): In debugging mode, log identifier of
1472 (start_command_handler_ssh): Moved most of the stream handling
1474 (ssh_request_process): ... here.
1476 2005-01-28 Moritz Schulte <moritz@g10code.com>
1478 * command-ssh.c (ssh_handler_add_identity): Pass ctrl to
1479 ssh_identity_register().
1480 (ssh_identity_register): New argument: ctrl; pass ctrl to
1482 (get_passphrase): Pass ctrl instead of NULL to agent_askpin().
1483 (start_command_handler_ssh): Use agent_init_default_ctrl();
1484 deallocate structure members, which might be dynamically
1486 (lifetime_default): Removed variable.
1487 (ssh_handler_add_identity): Fix ttl handling; renamed variable
1489 (ssh_identity_register): Fix key grip handling.
1491 2005-01-26 Moritz Schulte <moritz@g10code.com>
1493 * command-ssh.c (ssh_handler_sign_request): Confirm to agent
1494 protocol in case of failure.
1496 * command-ssh.c: New file.
1498 * Makefile.am (gpg_agent_SOURCES): New source file: command-ssh.c.
1500 * findkey.c (modify_description): New function.
1501 (agent_key_from_file): Support comment field in key s-expressions.
1503 * gpg-agent.c (enum cmd_and_opt_values): New item: oSSHSupport.
1504 (opts) New entry for oSSHSupport.
1505 New variable: socket_name_ssh.
1506 (cleanup_do): New function based on cleanup().
1507 (cleanup): Use cleanup_do() for socket_name and socket_name_ssh.
1508 (main): New switch case for oSSHSupport.
1509 (main): Move socket name creation code to ...
1510 (create_socket_name): ... this new function.
1511 (main): Use create_socket_name() for creating socket names for
1512 socket_name and for socket_name_ssh in case ssh support is
1514 Move socket creation code to ...
1515 (create_server_socket): ... this new function.
1516 (main): Use create_server_socket() for creating sockets.
1517 In case standard_socket is set, do not only store a socket name in
1518 socket_name, but also in socket_name_ssh.
1519 Generate additional environment info strings for ssh support.
1520 Pass additional ssh socket argument to handle_connections.
1521 (start_connection_thread_ssh): New function.
1522 (handle_connections): Use select to multiplex between gpg-agent
1523 and ssh-agent protocol.
1525 * agent.h (struct opt): New member: ssh_support.
1526 (start_command_handler_ssh): Add prototype.
1528 2005-01-04 Werner Koch <wk@g10code.com>
1530 * trustlist.c (agent_marktrusted): Use "Cancel" for the first
1531 confirmation and made the strings translatable.
1533 * cache.c (agent_put_cache): Fix the test for using the default
1536 2004-12-21 Werner Koch <wk@g10code.com>
1538 * preset-passphrase.c (preset_passphrase): Handle --passphrase.
1540 * Makefile.am (gpg_preset_passphrase_LDADD): Reorder libs so that
1541 pwquery may use stuff from jnlib. Conditionally add -lwsock2
1542 (gpg_protect_tool_LDADD): Ditto.
1544 * preset-passphrase.c (main): Use default_homedir().
1545 (main) [W32]: Initialize sockets.
1547 2004-12-21 Marcus Brinkmann <marcus@g10code.de>
1549 * Makefile.am (libexec_PROGRAMS): Add gpg-preset-passphrase.
1550 (gpg_preset_passphrase_SOURCES, gpg_preset_passphrase_LDADD): New
1552 * agent.h (opt): New member allow_cache_passphrase.
1553 * cache.c (housekeeping): Check if R->ttl is not negative.
1554 (agent_put_cache): Allow ttl to be negative.
1555 * command.c (parse_hexstring): Allow something to follow the
1557 (cmd_cache_passphrase): New function.
1558 (register_commands): Add it.
1559 * gpg-agent.c: Handle --allow-preset-passphrase.
1560 * preset-passphrase.c: New file.
1562 2004-12-21 Werner Koch <wk@g10code.com>
1564 * gpg-agent.c (main): Use default_homedir().
1565 * protect-tool.c (main): Ditto.
1567 2004-12-20 Werner Koch <wk@g10code.com>
1569 * gpg-agent.c (main) [W32]: Now that Mutexes work we can remove
1570 the pth_init kludge.
1571 (main): Add new options --[no-]use-standard-socket.
1572 (check_for_running_agent): Check whether it is running on the
1575 * call-scd.c (init_membuf, put_membuf, get_membuf): Removed. We
1576 now use the identical implementation from ../common/membuf.c.
1578 * pksign.c (agent_pksign): Changed arg OUTFP to OUTBUF and use
1579 membuf functions to return the value.
1580 * pkdecrypt.c (agent_pkdecrypt): Ditto.
1581 * genkey.c (agent_genkey): Ditto.
1582 * command.c (cmd_pksign, cmd_pkdecrypt, cmd_genkey): Replaced
1583 assuan_get_data_fp() by a the membuf scheme.
1584 (clear_outbuf, write_and_clear_outbuf): New.
1586 2004-12-19 Werner Koch <wk@g10code.com>
1588 * query.c (initialize_module_query): New.
1589 * call-scd.c (initialize_module_call_scd): New.
1590 * gpg-agent.c (main): Call them.
1592 2004-12-18 Werner Koch <wk@g10code.com>
1594 * gpg-agent.c (main): Remove special Pth initialize.
1596 * agent.h (map_assuan_err): Define in terms of
1597 map_assuan_err_with_source.
1599 2004-12-17 Moritz Schulte <moritz@g10code.com>
1601 * query.c: Undo change from 2004-12-05.
1603 2004-12-15 Werner Koch <wk@g10code.com>
1605 * gpg-agent.c [W32]: Various hacks to make it work.
1607 * findkey.c (agent_write_private_key) [W32]: Adjust open call.
1609 * call-scd.c (start_scd) [W32]: Don't check whether the daemon
1610 didn't died. To hard to do under Windows.
1611 (start_scd) [W32]: Disable sending of the event signal option.
1613 * protect-tool.c (read_file, export_p12_file) [W32]: Use setmode
1614 to get stdout and stin into binary mode.
1616 2004-12-05 Moritz Schulte <moritz@g10code.com>
1618 * query.c (start_pinentry): Allow CTRL be NULL.
1620 2004-10-22 Werner Koch <wk@g10code.com>
1622 * gpg-agent.c (parse_rereadable_options): Return "not handled"
1623 when the log file has not beend hadled. This is will let the main
1624 option processing continue. Fixed a bug introduced on 2004-09-4
1625 resulting in logging to stderr until a HUP has been given.
1626 (main): Don't close the listen FD.
1628 2004-09-30 Werner Koch <wk@g10code.com>
1630 * Makefile.am: Adjusted from gettext 1.14.
1632 2004-09-29 Werner Koch <wk@g10code.com>
1634 * minip12.c (parse_bag_encrypted_data): Print error if a bad
1635 passphrase has been given.
1637 2004-09-28 Werner Koch <wk@g10code.com>
1639 * protect.c (agent_unprotect): Fixed wiping of CLEARTEXT. Thanks
1640 to Moritz for pointing this out.
1642 2004-09-25 Moritz Schulte <moritz@g10code.com>
1644 * agent.h: Declare: agent_pksign_do.
1645 (struct server_control_s): New member: raw_value.
1647 * pksign.c (do_encode_md): New argument: raw_value; support
1648 generation of raw (non-pkcs1) data objects; adjust callers.
1649 (agent_pksign_do): New function, based on code ripped
1650 out from agent_pksign.
1651 (agent_pksign): Use agent_pksign_do.
1653 * command.c (start_command_handler): Set ctrl.digest.raw_value.
1655 2004-09-09 Werner Koch <wk@g10code.de>
1657 * gpg-agent.c (check_for_running_agent): New.
1658 (main): The default action is now to check for an already running
1660 (parse_rereadable_options): Set logfile only on reread.
1661 (main): Do not print the "is development version" note.
1663 2004-08-20 Werner Koch <wk@g10code.de>
1665 * gpg-agent.c: New option --max-cache-ttl. Suggested by Alexander
1667 * cache.c (housekeeping): Use it here instead of the hardwired
1670 * query.c (start_pinentry): Use a timeout for the pinentry lock.
1672 2004-08-18 Werner Koch <wk@g10code.de>
1674 * protect-tool.c (get_passphrase): Make sure that the default
1675 prompts passed to gpg-agent are utf-8 encoded. Add new prompt values.
1676 (import_p12_file, import_p12_file, export_p12_file): Changed calls
1677 to get_passphrase so that better prompts are displayed.
1678 (get_new_passphrase): New.
1680 2004-07-22 Werner Koch <wk@g10code.de>
1682 * trustlist.c (read_list): Allow colons in the fingerprint.
1683 (headerblurb): Rephrased.
1685 * gpg-agent.c (handle_connections): Increase the stack size ot 256k.
1687 2004-06-20 Moritz Schulte <moritz@g10code.com>
1689 * gpg-agent.c: Include <sys/stat.h> (build fix for BSD).
1691 2004-05-11 Werner Koch <wk@gnupg.org>
1693 * gpg-agent.c (handle_signal): Reload the trustlist on SIGHUP.
1694 (start_connection_thread): Hack to simulate a ticker.
1695 * trustlist.c (agent_trustlist_housekeeping)
1696 (agent_reload_trustlist): New. Protected all global functions
1697 here with a simple counter which is sufficient for Pth.
1699 2004-05-03 Werner Koch <wk@gnupg.org>
1701 * gpg-agent.c: Remove help texts for options lile --lc-ctype.
1702 (main): New option --allow-mark-trusted.
1703 * trustlist.c (agent_marktrusted): Use it here.
1705 2004-04-30 Werner Koch <wk@gnupg.org>
1707 * protect-tool.c: New option --enable-status-msg.
1708 (store_private_key): Print status messages for imported keys.
1709 (read_and_unprotect): Ditto for bad passphrase.
1711 * gpg-agent.c (parse_rereadable_options): New arg REREAD. Allow
1713 (current_logfile): New.
1715 2004-04-26 Werner Koch <wk@gnupg.org>
1717 * call-scd.c (start_scd): Do not register an event signal if we
1718 are running as a pipe server.
1720 2004-04-21 Werner Koch <wk@gnupg.org>
1722 * call-scd.c (start_scd): Send event-signal option. Always check
1723 that the scdaemon is still running.
1725 * gpg-agent.c (handle_signal): Do not use SIGUSR{1,2} anymore for
1726 changing the verbosity.
1728 2004-04-16 Werner Koch <wk@gnupg.org>
1730 * gpg-agent.c (main): Tell the logging code that we are running
1733 2004-04-06 Werner Koch <wk@gnupg.org>
1735 * gpg-agent.c (main): Use new libgcrypt thread library register
1738 2004-03-23 Marcus Brinkmann <marcus@g10code.de>
1740 * gpg-agent.c (main): For now, always print the default config
1741 file name for --gpgconf-list.
1743 2004-03-17 Werner Koch <wk@gnupg.org>
1745 * gpg-agent.c (main) <gpgconf>: Fixed default value quoting.
1747 2004-03-16 Werner Koch <wk@gnupg.org>
1749 * gpg-agent.c (parse_rereadable_options): Use the new
1750 DEFAULT_CACHE_TTL macro.
1751 (main): Updated --gpgconf-list output.
1753 2004-02-21 Werner Koch <wk@gnupg.org>
1755 * command.c (cmd_passwd): Take acount of a key description.
1757 * genkey.c (reenter_compare_cb): Do not set the error text.
1758 (agent_protect_and_store, agent_genkey): Force a re-enter after a
1759 non-matching passphrase.
1760 * query.c (agent_askpin): Add new arg INITIAL_ERRTEXT; changed
1763 2004-02-19 Werner Koch <wk@gnupg.org>
1765 * protect-tool.c: New options --have-cert and --prompt.
1766 (export_p12_file): Read a certificate from STDIN and pass it to
1767 p12_build. Detect a keygrip and construct the filename in that
1768 case. Unprotcet a key if needed. Print error messages for key
1769 formats we can't handle.
1770 (release_passphrase): New.
1771 (get_passphrase): New arg PROMPTNO. Return the allocated
1772 string. Changed all callers.
1774 * minip12.c: Revamped the build part.
1775 (p12_build): New args CERT and CERTLEN.
1777 2004-02-18 Werner Koch <wk@gnupg.org>
1779 * protect-tool.c (main): Setup the used character set.
1780 * gpg-agent.c (main): Ditto.
1782 * gpg-agent.c (set_debug): New. New option --debug-level.
1783 (main): New option --gpgconf-list.
1785 2004-02-17 Werner Koch <wk@gnupg.org>
1787 * pksign.c (do_encode_md): Cleaned up by using gcry_sexp_build.
1789 * Makefile.am (gpg_protect_tool_SOURCES): Removed
1790 simple-pwquery.[ch], as we once moved it to ../common.
1792 2004-02-13 Werner Koch <wk@gnupg.org>
1794 * command.c (cmd_setkeydesc): New.
1795 (register_commands): Add command SETKEYDESC.
1796 (cmd_pksign, cmd_pkdecrypt): Use the key description.
1797 (reset_notify): Reset the description.
1798 * findkey.c (unprotect): Add arg DESC_TEXT.
1799 (agent_key_from_file): Ditto.
1800 * pksign.c (agent_pksign): Ditto.
1801 * pkdecrypt.c (agent_pkdecrypt): Ditto. Made CIPHERTEXT an
1804 * protect-tool.c (main): New options --no-fail-on-exist, --homedir.
1805 (store_private_key): Use them here.
1807 2004-02-12 Werner Koch <wk@gnupg.org>
1809 * protect-tool.c (read_file, main): Allow reading from stdin.
1811 * Makefile.am: Include cmacros.am for common flags.
1812 (libexec_PROGRAMS): Put gpg-protect-tool there.
1814 2004-02-10 Werner Koch <wk@gnupg.org>
1816 * minip12.c (parse_bag_encrypted_data): Finished implementation.
1817 (p12_parse): Add callback args.
1818 * protect-tool.c (import_p12_cert_cb): New.
1819 (import_p12_file): Use it.
1821 2004-02-06 Werner Koch <wk@gnupg.org>
1823 * minip12.c (crypt_block): Add arg CIPHER_ALGO; changed all callers.
1824 (set_key_iv): Add arg KEYBYTES; changed caller.
1826 2004-02-03 Werner Koch <wk@gnupg.org>
1828 * findkey.c (agent_key_from_file): Extra paranoid wipe.
1829 * protect.c (agent_unprotect): Ditto.
1830 (merge_lists): Ditto. Add arg RESULTLEN.
1831 * pkdecrypt.c (agent_pkdecrypt): Don't show the secret key even in
1834 * protect.c: Add DSA and Elgamal description.
1836 2004-01-29 Werner Koch <wk@gnupg.org>
1838 * agent.h (server_control_s): Add connection_fd field.
1839 * command.c (start_command_handler): Init it here.
1840 * gpg-agent.c (agent_init_default_ctrl): and here.
1841 * call-scd.c: Add the CTRL arg to all functions calling start_scd
1842 and pass it to start_scd. Changed all callers
1843 (start_scd): Keep track of the current active connection.
1844 (agent_reset_scd): New.
1845 * command.c (start_command_handler): Call it here.
1846 * learncard.c (agent_handle_learn): Add arg CTRL; changed caller.
1847 (send_cert_back): Ditto.
1849 2004-01-28 Werner Koch <wk@gnupg.org>
1851 * trustlist.c (agent_marktrusted): Check whether the trustlist is
1854 2004-01-27 Werner Koch <wk@gnupg.org>
1856 * sexp-parse.h: Moved to ../common.
1858 2004-01-24 Werner Koch <wk@gnupg.org>
1860 * call-scd.c (atfork_cb): New.
1861 (start_scd): Make sure secmem gets cleared.
1862 * query.c (atfork_cb): New.
1863 (start_pinentry): Make sure secmem gets cleared.
1865 2004-01-16 Werner Koch <wk@gnupg.org>
1867 * findkey.c (agent_key_from_file): Now return an error code so
1868 that we have more detailed error messages in the upper layers.
1869 This fixes the handling of pinentry's cancel button.
1870 * pksign.c (agent_pksign): Changed accordingly.
1871 * pkdecrypt.c (agent_pkdecrypt): Ditto.
1872 * command.c (cmd_passwd): Ditto.
1874 2003-12-16 Werner Koch <wk@gnupg.org>
1876 * gpg-agent.c (main): Set the prefixes for assuan logging.
1878 2003-12-15 Werner Koch <wk@gnupg.org>
1880 * protect.c (do_encryption): Use gcry_create_nonce instad of the
1881 obsolete WEAK_RANDOM.
1883 2003-11-20 Werner Koch <wk@gnupg.org>
1885 * sexp-parse.h (snext): Don't use atoi_1 and digitp macros, so
1886 that this file is useful by other applications too.
1888 2003-10-27 Werner Koch <wk@gnupg.org>
1890 * command.c (cmd_get_confirmation): New command.
1892 2003-08-20 Timo Schulz <twoaday@freakmail.de>
1894 * pksign.c (do_encode_md): Allocate enough space. Cast md
1895 byte to unsigned char to prevent sign extension.
1897 2003-08-14 Timo Schulz <twoaday@freakmail.de>
1899 * pksign.c (do_encode_md): Due to the fact pkcs#1 padding
1900 is now in Libgcrypt, use the new interface.
1902 2003-07-31 Werner Koch <wk@gnupg.org>
1904 * Makefile.am (gpg_agent_LDADD): Added INTLLIBS.
1905 (gpg_protect_tool_SOURCES): Added simple-pwquery.[ch]
1907 2003-07-27 Werner Koch <wk@gnupg.org>
1909 Adjusted for gcry_mpi_print and gcry_mpi_scan API change.
1911 2003-07-15 Werner Koch <wk@gnupg.org>
1913 * simple-pwquery.c, simple-pwquery.h: Moved to ../common.
1914 * Makefile.am (gpg_protect_tool_LDADD): Add simple-pwquery.o.
1915 Removed it from xx_SOURCES.
1917 2003-07-04 Werner Koch <wk@gnupg.org>
1919 * gpg-agent.c (handle_connections): Kludge to allow use of Pth 1
1922 2003-06-30 Werner Koch <wk@gnupg.org>
1924 * call-scd.c (learn_status_cb): Store the serialno in PARM.
1926 2003-06-26 Werner Koch <wk@gnupg.org>
1928 * call-scd.c (agent_card_serialno): Don't do a RESET anymore.
1930 2003-06-25 Werner Koch <wk@gnupg.org>
1932 * command.c (cmd_scd): New.
1933 * call-scd.c (agent_card_scd): New.
1934 * divert-scd.c (divert_generic_cmd): New
1936 * call-scd.c (agent_card_learn): New callback args SINFO.
1937 (learn_status_cb): Pass all other status lines to the sinfo
1939 * learncard.c (release_sinfo, sinfo_cb): New.
1940 (agent_handle_learn): Pass the new cb to the learn function and
1941 pass the collected information back to the client's assuan
1944 * gpg-agent.c (main): Moved pth_init before gcry_check_version.
1946 2003-06-24 Werner Koch <wk@gnupg.org>
1948 * gpg-agent.c (handle_connections): Adjusted for Pth 2.0
1950 Adjusted for changes in the libgcrypt API. Some more fixes for the
1953 2003-06-04 Werner Koch <wk@gnupg.org>
1955 Renamed error codes from INVALID to INV and removed _ERROR suffixes.
1957 2003-06-03 Werner Koch <wk@gnupg.org>
1959 Changed all error codes in all files to the new libgpg-error scheme.
1961 * agent.h: Include gpg-error.h and errno.h
1962 * Makefile.am: Link with libgpg-error
1964 * query.c: assuan.h is now a system header.
1965 * genkey.c (agent_genkey): Fixed silly use of xmalloc by
1968 2003-04-29 Werner Koch <wk@gnupg.org>
1970 * command.c (register_commands): Adjusted for new Assuan semantics.
1972 * Makefile.am: Don't override LDFLAGS.
1974 2002-12-04 Werner Koch <wk@gnupg.org>
1976 * gpg-agent.c: New variable config_filename.
1977 (parse_rereadable_options): New.
1978 (main): Use it here. Add setting of default values, set
1980 (reread_configuration): Filled with actual code.
1982 2002-12-03 Werner Koch <wk@gnupg.org>
1984 * protect-tool.c (read_key): Don't run make_canonical on a NULL
1987 * command.c (parse_hexstring): New.
1988 (cmd_sethash): Use it.
1989 (parse_keygrip): New.
1990 (cmd_havekey, cmd_sigkey): Use it.
1992 * genkey.c (agent_protect_and_store): New.
1993 (store_key): Add arg FORCE.
1994 (agent_genkey): Pass false to this force of store_key.
1996 2002-11-13 Werner Koch <wk@gnupg.org>
1998 * gpg-agent.c (main): Switch all messages to utf-8.
2000 * simple-pwquery.c (agent_send_all_options): Use $GPG_TTY and
2003 * cache.c (new_data): Uiih - /sizeof d/sizeof *d/.
2005 2002-11-10 Werner Koch <wk@gnupg.org>
2007 * command.c (option_handler): Fix keep_tty check.
2009 2002-11-06 Werner Koch <wk@gnupg.org>
2011 * gpg-agent.c (main): Make sure we have a default ttyname.
2012 * command.c (option_handler): Check opt.keep_tty here
2013 * query.c (start_pinentry): but not anymore here.
2015 2002-11-05 Werner Koch <wk@gnupg.org>
2017 * agent.h (opt,server_control_s): Move display and lc_ variables
2018 to the control struct so that they are per connection.
2019 * gpg-agent.c (agent_init_default_ctrl): New.
2020 (main): Assign those command line options to new default_* variables.
2021 Reset DISPLAY in server mode so that tehre is no implicit default.
2022 * command.c (start_command_handler): Initialize and deinitialize
2024 (option_handler): Work on the ctrl values and not on the opt.
2025 * query.c (start_pinentry): New argument CTRL to set the display
2026 connection specific. Changed all callers to pass this value.
2027 (agent_askpin,agent_get_passphrase,agent_get_confirmation): Add
2028 CTRL arg and pass it ot start_pinentry.
2029 * command.c (cmd_get_passphrase): Pass CTRL argument.
2030 * trustlist.c (agent_marktrusted): Add CTRL argument
2031 * command.c (cmd_marktrusted): Pass CTRL argument
2032 * divert-scd.c (ask_for_card): Add CTRL arg.
2033 (divert_pksign,divert_pkdecrypt): Ditto. Changed caller.
2034 (getpin_cb): Use OPAQUE to pass the CTRL variable. Changed both
2036 * findkey.c (unprotect): Add CTRL arg.
2037 (agent_key_from_file): Ditto.
2039 * query.c (unlock_pinentry): Disconnect the pinentry so that we
2040 start a new one for each request. This is required to support
2041 clients with different environments (e.g. X magic cookies).
2043 2002-09-05 Neal H. Walfield <neal@cs.uml.edu>
2045 * gpg-agent.c (main) [USE_GNU_PTH]: No need to call
2046 assuan_set_io_func as assuan is smart.
2048 2002-09-25 Werner Koch <wk@gnupg.org>
2050 * gpg-agent.c (handle_signal): Flush cache on SIGHUP.
2051 * cache.c (agent_flush_cache): New.
2053 * gpg-agent.c, agent.h: Add --keep-display and --keep-tty.
2054 * query.c (start_pinentry): Implement them. The option passing
2055 needs more thoughts.
2057 2002-09-09 Werner Koch <wk@gnupg.org>
2059 * gpg-agent.c (create_private_keys_directory)
2060 (create_directories): New.
2061 (main): Try to create a home directory.
2063 2002-09-04 Neal H. Walfield <neal@g10code.de>
2065 * gpg-agent.c (main): Use sigaction, not signal.
2067 2002-09-03 Neal H. Walfield <neal@g10code.de>
2069 * findkey.c: Include <fcntl.h>.
2070 (agent_write_private_key): Prefer POSIX compatibity, open and
2071 fdopen, over the simplicity of GNU extensions, fopen(file, "x").
2073 2002-08-22 Werner Koch <wk@gnupg.org>
2075 * query.c (agent_askpin): Provide the default desc text depending
2076 on the pininfo. Do the basic PIN verification only when
2079 2002-08-21 Werner Koch <wk@gnupg.org>
2081 * query.c (agent_askpin): Hack to show the right default prompt.
2082 (agent_get_passphrase): Ditto.
2084 * trans.c: Removed and replaced all usages with standard _()
2086 * divert-scd.c (getpin_cb): Pass a more descritive text to the
2089 * Makefile.am: Renamed the binary protect-tool to gpg-protect-tool.
2090 * protect-tool.c: Removed the note about internal use only.
2092 * gpg-agent.c (main): New option --daemon so that the program is
2093 not accidently started in the background.
2095 2002-08-16 Werner Koch <wk@gnupg.org>
2097 * call-scd.c (learn_status_cb): Handle CERTINFO status.
2098 (agent_card_learn): Add args for certinfo cb.
2099 * learncard.c (release_certinfo,certinfo_cb): New.
2100 (send_cert_back): New. With factored out code from ..
2101 (agent_handle_learn): here. Return certinfo stuff.
2103 2002-07-26 Werner Koch <wk@gnupg.org>
2105 * gpg-agent.c (main): New option --ignore-cache-for-signing.
2106 * command.c (option_handler): New server option
2107 use-cache-for-signing defaulting to true.
2108 (cmd_pksign): handle global and per session option.
2109 * findkey.c (agent_key_from_file, unprotect): New arg
2110 ignore_cache. Changed all callers.
2111 * pksign.c (agent_pksign): Likewise.
2113 2002-06-29 Werner Koch <wk@gnupg.org>
2115 * query.c (start_pinentry): Use GNUPG_DERAULT_PINENTRY.
2116 * call-scd.c (start_scd): Use GNUPG_DEFAULT_SCDAEMON.
2118 2002-06-28 Werner Koch <wk@gnupg.org>
2120 * protect-tool.c (export_p12_file): New.
2121 (main): New command --p12-export.
2122 * minip12.c (create_final,p12_build,compute_tag_length): New.
2123 (store_tag_length): New.
2125 2002-06-27 Werner Koch <wk@gnupg.org>
2127 * minip12.c (crypt_block): Renamed from decrypt_block, add arg to
2130 * Makefile.am (pkglib_PROGRAMS): Put protect-tool there.
2132 * findkey.c (agent_write_private_key,agent_key_from_file)
2133 (agent_key_available): Use GNUPG_PRIVATE_KEYS_DIR constant.
2134 * gpg-agent.c (main): Use GNUPG_DEFAULT_HOMEDIR constant.
2136 * protect-tool.c (store_private_key): New.
2137 (import_p12_file): Store the new file if requested.
2138 (main): New options --force and --store.
2140 * gpg-agent.c (main): Set a global flag when running detached.
2141 * query.c (start_pinentry): Pass the list of FD to keep in the
2142 child when not running detached.
2143 * call-scd.c (start_scd): Ditto.
2145 2002-06-26 Werner Koch <wk@gnupg.org>
2147 * command.c (cmd_istrusted, cmd_listtrusted, cmd_marktrusted)
2148 (cmd_pksign, cmd_pkdecrypt, cmd_genkey, cmd_get_passphrase)
2149 (cmd_learn): Print an error message for a failed operation.
2151 * simple-pwquery.c, simple-pwquery.h: New.
2152 * protect-tool. (get_passphrase): New, used to get a passphrase
2153 from the agent if none was given on the command line.
2155 2002-06-25 Werner Koch <wk@gnupg.org>
2157 * protect-tool.c (rsa_key_check): New.
2158 (import_p12_file): New.
2159 (main): New command --p12-import.
2160 * minip12.c, minip12.h: New.
2162 2002-06-24 Werner Koch <wk@gnupg.org>
2164 * protect-tool.c (read_file): New.
2165 (read_key): Factored most code out to read_file.
2167 2002-06-17 Werner Koch <wk@gnupg.org>
2169 * agent.h: Add a callback function to the pin_entry_info structure.
2170 * query.c (agent_askpin): Use the callback to check for a correct
2171 PIN. Removed the start_err_text argument because it is not
2172 anymore needed; changed callers.
2173 * findkey.c (unprotect): Replace our own check loop by a callback.
2174 (try_unprotect_cb): New.
2175 * genkey.c (reenter_compare_cb): New.
2176 (agent_genkey): Use this callback here. Fixed setting of the pi2
2177 variable and a segv in case of an empty PIN.
2179 * divert-scd.c (getpin_cb): Removed some unused stuff and
2180 explained what we still have to change.
2182 2002-06-12 Werner Koch <wk@gnupg.org>
2184 * gpg-agent.c (main): New option --disable-pth.
2186 2002-06-11 Werner Koch <wk@gnupg.org>
2188 * protect-tool.c: Add command --show-keygrip
2189 (show_keygrip): New.
2191 2002-05-23 Werner Koch <wk@gnupg.org>
2193 * call-scd.c: Seirialized all scdaeom access when using Pth.
2195 * cache.c: Made the cache Pth-thread-safe.
2196 (agent_unlock_cache_entry): New.
2197 * findkey.c (unprotect): Unlock the returned cache value.
2198 * command.c (cmd_get_passphrase): Ditto.
2200 * gpg-agent.c (main): Register pth_read/write with Assuan.
2202 2002-05-22 Werner Koch <wk@gnupg.org>
2204 * query.c: Serialized all pinentry access when using Pth.
2206 * gpg-agent.c (handle_signal,start_connection_thread)
2207 (handle_connections): New
2208 (main): Use the new Pth stuff to allow concurrent connections.
2209 * command.c (start_command_handler): Add new arg FD so that the
2210 fucntion can also be used for an already connected socket.
2211 * Makefile.am: Link with Pth.
2213 2002-05-14 Werner Koch <wk@gnupg.org>
2215 * cache.c (housekeeping, agent_put_cache): Use our time() wrapper.
2217 2002-04-26 Werner Koch <wk@gnupg.org>
2219 * cache.c (agent_put_cache): Reinitialize the creation time and
2220 the ttl when reusing a slot.
2222 * call-scd.c (start_scd): Print debug messages only with debug
2224 * query.c (start_pinentry): Ditto.
2226 2002-04-25 Marcus Brinkmann <marcus@g10code.de>
2228 * agent.h (agent_get_confirmation): Replace paramter prompt with
2229 two parameters ok and cancel.
2230 * query.c (agent_get_confirmation): Likewise. Implement this.
2231 * trustlist.c (agent_marktrusted): Fix invocation of
2232 agent_get_confirmation.
2233 * divert-scd.c (ask_for_card): Likewise.
2235 2002-04-24 Marcus Brinkmann <marcus@g10code.de>
2237 * agent.h (struct opt): Add members display, ttyname, ttytype,
2238 lc_ctype, and lc_messages.
2239 * gpg-agent.c (enum cmd_and_opt_values): Add oDisplay, oTTYname,
2240 oTTYtype, oLCctype, and LCmessages.
2241 (main): Handle these options.
2242 * command.c (option_handler): New function.
2243 (register_commands): Register option handler.
2244 * query.c (start_pinentry): Pass the various display and tty
2245 options to the pinentry.
2247 2002-04-05 Werner Koch <wk@gnupg.org>
2249 * protect-tool.c (show_file): New. Used as default action.
2251 2002-03-28 Werner Koch <wk@gnupg.org>
2253 * divert-scd.c (encode_md_for_card): Don't do the pkcs-1 padding,
2254 the scdaemon should take care of it.
2255 (ask_for_card): Hack to not display the trailing zero.
2257 2002-03-11 Werner Koch <wk@gnupg.org>
2259 * learncard.c (kpinfo_cb): Remove the content restrictions from
2262 2002-03-06 Werner Koch <wk@gnupg.org>
2265 * divert-scd.c (ask_for_card): The serial number is binary so
2266 convert it to hex here.
2267 * findkey.c (agent_write_private_key): New.
2268 * genkey.c (store_key): And use it here.
2270 * pkdecrypt.c (agent_pkdecrypt): Changed the way the diversion is done.
2271 * divert-scd.c (divert_pkdecrypt): Changed interface and
2274 2002-03-05 Werner Koch <wk@gnupg.org>
2276 * call-scd.c (inq_needpin): New.
2277 (agent_card_pksign): Add getpin_cb args.
2278 (agent_card_pkdecrypt): New.
2280 2002-03-04 Werner Koch <wk@gnupg.org>
2282 * pksign.c (agent_pksign): Changed how the diversion is done.
2283 * divert-scd.c (divert_pksign): Changed interface and implemented it.
2284 (encode_md_for_card): New.
2285 * call-scd.c (agent_card_pksign): New.
2287 2002-02-28 Werner Koch <wk@gnupg.org>
2289 * pksign.c (agent_pksign): Detect whether a Smartcard is to be
2290 used and divert the operation in this case.
2291 * pkdecrypt.c (agent_pkdecrypt): Likewise
2292 * findkey.c (agent_key_from_file): Add optional arg shadow_info
2293 and have it return information about a shadowed key.
2294 * protect.c (agent_get_shadow_info): New.
2296 * protect.c (snext,sskip,smatch): Moved to
2297 * sexp-parse.h: New file.
2298 * divert-scd.c: New.
2300 2002-02-27 Werner Koch <wk@gnupg.org>
2302 * protect.c (agent_shadow_key): New.
2304 * command.c (cmd_learn): New command LEARN.
2305 * gpg-agent.c: New option --scdaemon-program.
2306 * call-scd.c (start_scd): New. Based on query.c
2307 * query.c: Add 2 more arguments to all uses of assuan_transact.
2309 2002-02-18 Werner Koch <wk@gnupg.org>
2311 * findkey.c (unprotect): Show an error message for a bad passphrase.
2313 * command.c (cmd_marktrusted): Implemented.
2314 * trustlist.c (agent_marktrusted): New.
2315 (open_list): Add APPEND arg.
2317 * query.c (agent_get_confirmation): New.
2319 2002-02-06 Werner Koch <wk@gnupg.org>
2321 * cache.c (housekeeping): Fixed linking in the remove case.
2323 2002-02-01 Werner Koch <wk@gnupg.org>
2325 * gpg-agent.c: New option --default-cache-ttl.
2326 * cache.c (agent_put_cache): Use it.
2328 * cache.c: Add a few debug outputs.
2330 * protect.c (agent_private_key_type): New.
2331 * agent.h: Add PRIVATE_KEY_ enums.
2332 * findkey.c (agent_key_from_file): Use it to decide whether we
2333 have to unprotect a key.
2334 (unprotect): Cache the passphrase.
2336 * findkey.c (agent_key_from_file,agent_key_available): The key
2337 files do now require a ".key" suffix to make a script's life
2339 * genkey.c (store_key): Ditto.
2341 2002-01-31 Werner Koch <wk@gnupg.org>
2343 * genkey.c (store_key): Protect the key.
2344 (agent_genkey): Ask for the passphrase.
2345 * findkey.c (unprotect): Actually unprotect the key.
2346 * query.c (agent_askpin): Add an optional start_err_text.
2348 2002-01-30 Werner Koch <wk@gnupg.org>
2351 (hash_passphrase): Based on the GnuPG 1.0.6 version.
2352 * protect-tool.c: New
2354 2002-01-29 Werner Koch <wk@gnupg.org>
2356 * findkey.c (agent_key_available): New.
2357 * command.c (cmd_havekey): New.
2358 (register_commands): And register new command.
2360 2002-01-20 Werner Koch <wk@gnupg.org>
2362 * command.c (cmd_get_passphrase): Remove the plus signs.
2364 * query.c (start_pinentry): Send no-grab option to pinentry
2365 * gpg-agent.c (main): Move variable grab as no_grab to agent.h.
2367 2002-01-19 Werner Koch <wk@gnupg.org>
2369 * gpg-agent.c (main): Disable core dumps.
2372 * command.c (cmd_get_passphrase): Use the cache.
2373 (cmd_clear_passphrase): Ditto.
2375 * gpg-agent.c: Removed unused cruft and implement the socket
2377 (my_strusage): Take bug report address from configure.ac.
2378 * command.c (start_command_handler): Add an argument to start as
2380 (start_command_handler): Enable Assuan logging.
2382 2002-01-15 Werner Koch <wk@gnupg.org>
2385 * command.c (cmd_istrusted, cmd_listtrusted, cmd_marktrusted): New.
2387 2002-01-07 Werner Koch <wk@gnupg.org>
2389 * genkey.c: Store the secret part and return the public part.
2391 2002-01-03 Werner Koch <wk@gnupg.org>
2393 * command.c (cmd_get_passphrase): New.
2394 (cmd_clear_passphrase): New.
2395 * query.c (agent_get_passphrase): New.
2397 2002-01-02 Werner Koch <wk@gnupg.org>
2400 * command.c (cmd_genkey): New.
2402 * command.c (rc_to_assuan_status): Removed and changed all callers
2403 to use map_to_assuan_status.
2405 2001-12-19 Werner Koch <wk@gnupg.org>
2407 * keyformat.txt: New.
2409 2001-12-19 Marcus Brinkmann <marcus@g10code.de>
2411 * query.c (start_pinentry): Add new argument to assuan_pipe_connect.
2413 2001-12-18 Werner Koch <wk@gnupg.org>
2415 * Makefile.am: Use LIBGCRYPT macros
2417 2001-12-14 Werner Koch <wk@gnupg.org>
2419 * gpg-agent.c (main): New option --batch. New option --debug-wait
2420 n, so that it is possible to attach gdb when used in server mode.
2421 * query.c (agent_askpin): Don't ask in batch mode.
2423 * command.c: Removed the conversion macros as they are now in
2426 2001-12-14 Marcus Brinkmann <marcus@g10code.de>
2428 * query.c (LINELENGTH): Removed.
2429 (agent_askpin): Use ASSUAN_LINELENGTH, not LINELENGTH.
2431 2001-11-19 Werner Koch <wk@gnupg.org>
2433 * gpg-agent.c: Removed all GUI code, removed code for old
2434 protocol. New code to use the Assuan protocol as a server and
2435 also to communicate with a new ask-passphrase utility.
2437 2000-11-22 Werner Koch <wk@gnupg.org>
2439 * gpg-agent.c (main): csh support by Dan Winship, new options --sh
2440 and --csh and set default by consulting $SHELL.
2442 Mon Aug 21 17:59:17 CEST 2000 Werner Koch <wk@openit.de>
2444 * gpg-agent.c (passphrase_dialog): Cleanup the window and added the
2445 user supplied text to the window.
2446 (main): Fixed segv in gtk_init when used without a command to start.
2448 * gpg-agent.c: --flush option.
2450 (req_clear_passphrase): Implemented.
2452 Fri Aug 18 14:27:14 CEST 2000 Werner Koch <wk@openit.de>
2458 Copyright 2001, 2002, 2003, 2004, 2005,
2459 2007, 2008, 2009 Free Software Foundation, Inc.
2461 This file is free software; as a special exception the author gives
2462 unlimited permission to copy and/or distribute it, with or without
2463 modifications, as long as this notice is preserved.
2465 This file is distributed in the hope that it will be useful, but
2466 WITHOUT ANY WARRANTY, to the extent permitted by law; without even the
2467 implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.