grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026a öxø_³òã@sddlmZmZmZddlZddlZddlZddlZddlm Z ddl m Z m Z ddlm Z ddlm Z ddlmZ[[[Gd d „d eƒZGd d „d eƒZGd d„deƒZdd„Zdd„Zdd„Zdd„Zdd„Zd%dd„Zeƒdd„Zdd„Zd&dd „Zd!d"„Zd#d$„ZdS)'é)Úabsolute_importÚprint_functionÚunicode_literalsNé)Úgpgme)Ú errorcheckÚ GPGMEError)Ú constants)Úerrors)ÚutilcsŽeZdZdZdd„Z‡fdd„Zdd„Zdd „Zd d „Ze d d „ƒZ e dd„ƒZ dd„Z e ƒZddd„Ze d¡Zdd„Z‡fdd„Z‡ZS)Ú GpgmeWrapperz>Base wrapper class Not to be instantiated directly. cCsd|_||_dS©N)Ú_callback_excinfoÚwrapped)Úselfr©rú./usr/lib64/python3.9/site-packages/gpg/core.pyÚ__init__3szGpgmeWrapper.__init__csd tt|ƒ ¡|j¡S)Nz <{}/{!r}>)ÚformatÚsuperr Ú__repr__r©r©Ú __class__rrr7sÿzGpgmeWrapper.__repr__csPd tˆjj¡g}‡fdd„ˆjDƒ}|r@| d d |¡¡¡d d |¡¡S)Nz{}.{}csg|]}tˆ|ƒr|‘qSr)Úgetattr©Ú.0ÚfrrrÚ =óz(GpgmeWrapper.__str__..z({})ú z<{}>)rÚ__name__rÚ_boolean_propertiesÚappendÚjoin)rZaccÚflagsrrrÚ__str__;s zGpgmeWrapper.__str__cCstt|jƒƒSr )ÚhashÚreprrrrrrÚ__hash__CszGpgmeWrapper.__hash__cCs$|dur dSt|jƒt|jƒkSdS)NF)r(r)rÚotherrrrÚ__eq__FszGpgmeWrapper.__eq__cCs tƒ‚dS)z]The name of the c type wrapped by this class Must be set by child classes. N©ÚNotImplementedErrorrrrrÚ_ctypeLszGpgmeWrapper._ctypecCs tƒ‚dS)zgThe common prefix of c functions wrapped by this class Must be set by child classes. Nr,rrrrÚ_cprefixUszGpgmeWrapper._cprefixcCs tƒ‚dS)z�Must be implemented by child classes. This function must return a trueish value for all c functions returning gpgme_error_t.Nr,©rÚnamerrrÚ _errorcheck^szGpgmeWrapper._errorcheckFNcs‚ttd |j|¡ƒ‰ttd |j|¡ƒ‰‡fdd„}‡fdd„}t||d |¡d�}t|j||ƒ|rv||t|ƒƒn||ƒSdS) Nz{}get_{}z{}set_{}cstˆ|jƒƒSr )Úboolr)Úslf)Úget_funcrrÚgetlsz1GpgmeWrapper.__wrap_boolean_property..getcsˆ|jt|ƒƒdSr )rr3)r4Úvalue)Úset_funcrrÚset_osz2GpgmeWrapper.__wrap_boolean_property..set_z{} flag)Údoc)rrrr/ÚpropertyÚsetattrrr3)rÚkeyZdo_setr7r6r9Úpr)r5r8rZ__wrap_boolean_propertyhs  z$GpgmeWrapper.__wrap_boolean_propertyz$gpgme_([^(]*)\(([^,]*), (.*\) -> .*)cs¶|ddksˆjdurdS|ˆjvr.ˆ |¡Sˆj|‰ttˆƒ‰ˆ ˆ¡r\‡‡fdd„‰n ‡fdd„‰tˆdƒ}|r†ˆj d|¡}nd}|ˆ_t ˆj |ˆƒ‡‡fd d „}||_|S) z7On-the-fly generation of wrapper methods and propertiesrÚ_Ncs,ˆ|jg|¢RŽ}|jr"t |¡t|ˆƒSr )rrrÚgpg_raise_callback_exceptionr©r4ÚargsÚresult)Úfuncr1rrÚ _funcwrap‰s z+GpgmeWrapper.__getattr__.._funcwrapcs&ˆ|jg|¢RŽ}|jr"t |¡|Sr )rrrr@rA)rDrrrE�s Ú__doc__z\2.\1(\3csˆˆg|¢RŽSr r)rB)rErrrÚwrapper¢sz)GpgmeWrapper.__getattr__..wrapper) r/r"Ú$_GpgmeWrapper__wrap_boolean_propertyrrr2Ú_munge_docstringÚsubrFr<r)rr=Zdoc_origr:rGr)rErDr1rrÚ __getattr__|s$       zGpgmeWrapper.__getattr__cs0||jvr| |d|¡ntt|ƒ ||¡dS)z#On-the-fly generation of propertiesTN)r"rHrr Ú __setattr__)rr=r7rrrrL©s zGpgmeWrapper.__setattr__)FN)r!Ú __module__Ú __qualname__rFrrr&r)r+r;r.r/r2Úsetr"rHÚreÚcompilerIrKrLÚ __classcell__rrrrr ,s      -r c s:eZdZdZdddgejejddf‡fdd„ Zdd„Zdd „Z gd ddddddd f d d „Z ded d„Z dej fdd„Z ddgfdd„Zdd„Zdfdd„Zdgdd„Zdhdd„Zddejjjdfdd„Zdidd„Zdjd d!„Zd"d#„Zd$d%„Zdkd&d'„Zd(d)„Zdld*d+„Zdmd,d-„Zed.d/„ƒZej d0d/„ƒZed1d2„ƒZ!e!j d3d2„ƒZ!ed4d5„ƒZ"e"j d6d5„ƒZ"ed7d8„ƒZ#e#j d9d8„ƒZ#d:Z$d;Z%d£Z'd?d@„Z(dAdB„Z)dCdD„Z*dEdF„Z+dGdH„Z,dndIdJ„Z-dKdL„Z.dMdN„Z/dodOdP„Z0dQdR„Z1dpdSdT„Z2dUdV„Z3dqdWdX„Z4dYdZ„Z5ed[d\„ƒZ6d]d^„Z7drd_d`„Z8dadb„Z9dcdd„Z:‡Z;S)sÚContextaContext for cryptographic operations All cryptographic operations in GPGME are performed within a context, which contains the internal state of the operation as well as configuration parameters. By using several contexts you can run several cryptographic operations in parallel, with different configuration. Access to a context must be synchronized. FNc sz|r d|_n0t ¡} tt | ¡ƒt | ¡}t | ¡d|_tt|ƒ  |¡||_ ||_ ||_ ||_ ||_||_||_dS)aConstruct a context object Keyword arguments: armor -- enable ASCII armoring (default False) textmode -- enable canonical text mode (default False) offline -- do not contact external key sources (default False) signers -- list of keys used for signing (default []) pinentry_mode -- pinentry mode (default PINENTRY_MODE_DEFAULT) protocol -- protocol to use (default PROTOCOL_OpenPGP) home_dir -- state directory (default is the engine default) FTN)ÚownrZnew_gpgme_ctx_t_prÚ gpgme_newZgpgme_ctx_t_p_valueZdelete_gpgme_ctx_t_prrSrÚarmorÚtextmodeÚofflineÚsignersÚ pinentry_modeÚprotocolÚhome_dir) rrVrWrXrYrZr[rr\Útmprrrr¾s  zContext.__init__cCs&|s |durdS| dtj¡| ¡S)zxRead helper Helper function to retrieve the results of an operation, or None if SINK is given. Nr)ÚseekÚosÚSEEK_SETÚread)rÚsinkÚdatarrrÚ__read__äs zContext.__read__cCs d |¡S)Nz¨Context(armor={0.armor}, textmode={0.textmode}, offline={0.offline}, signers={0.signers}, pinentry_mode={0.pinentry_mode}, protocol={0.protocol}, home_dir={0.home_dir}))rrrrrrïsüzContext.__repr__Tc  s"|r|ntƒ} d} | |tjO} | | tjO} | |tjO} | | tjO} | | tjO} ˆdur–|j} t|ddƒ}tj |_d‡fdd„ }|  |¡�zz*|r²|  || || ¡n|  || || ¡Wn¼t j�y€}z | ¡}|rì| ¡nd}| || ¡||f}| ¡t jk�r.|j�r.t j|j|j|d�‚| ¡t jk�rb| ¡}|j�rbt j|j|j|d�‚||_|‚WYd}~n d}~00Wˆdu�rØ| |_|�rØ|j |dd…Žn*ˆdu�rÖ| |_|�rÖ|j |dd…Ž0| ¡}|j�rìJ‚|�rú| ¡nd}|�r|j�rJ‚| || ¡||fS) a%Encrypt data Encrypt the given plaintext for the given recipients. If the list of recipients is empty, the data is encrypted symmetrically with a passphrase. The passphrase can be given as parameter, using a callback registered at the context, or out-of-band via pinentry. Keyword arguments: recipients -- list of keys to encrypt to sign -- sign plaintext (default True) sink -- write result to sink instead of returning it passphrase -- for symmetric encryption always_trust -- always trust the keys (default False) add_encrypt_to -- encrypt to configured additional keys (default False) prepare -- (ui) prepare for encryption (default False) expect_sign -- (ui) prepare for signing (default False) compress -- compress plaintext (default True) Returns: ciphertext -- the encrypted data (or None if sink is given) result -- additional information about the encryption sign_result -- additional information about the signature(s) Raises: InvalidRecipients -- if encryption using a particular key failed InvalidSigners -- if signing using a particular key failed GPGMEError -- as signaled by the underlying library rNÚ_passphrase_cbcsˆSr r©ÚhintZdescZprev_badÚhook©Ú passphraserrÚ passphrase_cb-sz&Context.encrypt..passphrase_cb©ÚerrorÚresultsr)N)ÚDatar ZENCRYPT_ALWAYS_TRUSTZENCRYPT_NO_ENCRYPT_TOZENCRYPT_PREPAREZENCRYPT_EXPECT_SIGNZENCRYPT_NO_COMPRESSrZrÚPINENTRY_MODE_LOOPBACKÚset_passphrase_cbZop_encrypt_signZ op_encryptr rZop_encrypt_resultÚop_sign_resultrdÚgetcodeZUNUSABLE_PUBKEYZinvalid_recipientsZInvalidRecipientsrmÚUNUSABLE_SECKEYÚinvalid_signersÚInvalidSignersrn)rÚ plaintextZ recipientsÚsignrbrjZ always_trustZadd_encrypt_toZprepareZ expect_signÚcompressÚ ciphertextr%Úold_pinentry_modeÚold_passphrase_cbrkÚerCZ sig_resultrnrrirÚencryptösf*  ýý ý  zContext.encryptc sbd}d}|r|ntƒ}ˆdurP|j}t|ddƒ} tj|_d‡fdd„ } | | ¡zÞzVt|tƒrd|}n$|dur€tj dt d�d}n|}d}|rš|  ||¡n |  ||¡WnZt j�y} z>| ¡} |rÒ| ¡} nd} | ||¡| | f| _| ‚WYd} ~ n d} ~ 00Wˆdu�rZ||_| �rZ|j| d d…Žn*ˆdu�rX||_| �rX|j| d d…Ž0| ¡} |�rr| ¡} nd} | ||¡| | f}| j�r t j| j|d �‚|�r^ttd d „| jƒƒ| _|du�r^g}|D]x}d}|jD]V}| jD]<}|jtj@d k�r�qæ|j�r|j|jk�rd}�q$�qæ|�rÜ�q4�qÜ|�sÎ| |¡�qÎ|�r^t j| ||d �‚|S)aëDecrypt data Decrypt the given ciphertext and verify any signatures. If VERIFY is an iterable of keys, the ciphertext must be signed by all those keys, otherwise a MissingSignatures error is raised. Note: if VERIFY is an empty iterable, that is treated the same as passing verify=True (that is, verify signatures and return data about any valid signatures found, but no signatures are required and no MissingSignatures error will be raised). If the ciphertext is symmetrically encrypted using a passphrase, that passphrase can be given as parameter, using a callback registered at the context, or out-of-band via pinentry. Keyword arguments: sink -- write result to sink instead of returning it passphrase -- for symmetric decryption verify -- check signatures (boolean or iterable of keys, see above) (default True) Returns: plaintext -- the decrypted data (or None if sink is given) result -- additional information about the decryption verify_result -- additional information about the valid signature(s) found Raises: UnsupportedAlgorithm -- if an unsupported algorithm was used MissingSignatures -- if expected signatures are missing or bad GPGMEError -- as signaled by the underlying library FNrecsˆSr rrfrirrrk…sz&Context.decrypt..passphrase_cbzTctx.decrypt called with verify=None, should be bool or iterable (treating as False).©ÚcategoryTr©rncSs |jtjkSr ©Ústatusr ZNO_ERROR)ÚsrrrÚ¹rz!Context.decrypt..r)N)rorZrr rprqÚ isinstancer3ÚwarningsÚwarnÚDeprecationWarningZop_decrypt_verifyZ op_decryptr rZop_decrypt_resultÚop_verify_resultrdrnZunsupported_algorithmZUnsupportedAlgorithmÚlistÚfilterÚ signaturesÚsubkeysÚsummaryÚ SIGSUM_VALIDÚcan_signÚfprr#ÚMissingSignatures)rrzrbrjÚverifyZdo_sig_verificationÚ required_keysrwr{r|rkr}rCZ verify_resultrnÚmissingr=ÚokÚsubkeyÚsigrrirÚdecryptYsŠ#   þ  ý  ÿ     ÿzContext.decryptc Cs¸|r|ntƒ}z| |||¡Wnttjy”}zZ| ||¡| ¡f}| ¡tjkrv|djrvtj |dj|j |d�‚||_ |‚WYd}~n d}~00| ¡}|jr¨J‚| ||¡|fS)aSign data Sign the given data with either the configured default local key, or the 'signers' keys of this context. Keyword arguments: mode -- signature mode (default: normal, see below) sink -- write result to sink instead of returning it Returns: either signed_data -- encoded data and signature (normal mode) signature -- only the signature data (detached mode) cleartext -- data and signature as text (cleartext mode) (or None if sink is given) result -- additional information about the signature(s) Raises: InvalidSigners -- if signing using a particular key failed GPGMEError -- as signaled by the underlying library rrlN) roZop_signr rrdrrrsrtrurvrmrn)rrcrbÚmodeZ signeddatar}rnrCrrrrxÏs" ý z Context.signc CsR|r d}n|r|ntƒ}z&|r.| ||d¡n| |d|¡Wn@tjy~}z&| ||¡| ¡f|_|‚WYd}~n d}~00| ||¡| ¡f}tdd„|djDƒƒr¾tj |d|d�‚t ƒ}|D]j} d} | j D]L} |djD]2} | j t j@dkrúqä| jrä| j| jkräd} �qqä| rÖ�q$qÖ| sÈ| | ¡qÈ|�rNtj|d||d�‚|S) aØVerify signatures Verify signatures over data. If VERIFY is an iterable of keys, the ciphertext must be signed by all those keys, otherwise an error is raised. Keyword arguments: signature -- detached signature data sink -- write result to sink instead of returning it Returns: data -- the plain data (or None if sink is given, or we verified a detached signature) result -- additional information about the signature(s) Raises: BadSignatures -- if a bad signature is encountered MissingSignatures -- if expected signatures are missing or bad GPGMEError -- as signaled by the underlying library Ncss|]}|jtjkVqdSr r‚)rr„rrrÚ !rz!Context.verify..rr�FrT)roZ op_verifyr rrdrŠrnÚanyr�Z BadSignaturesr‹rŽr�r r�r‘r’r#r“) rZ signed_dataZ signaturerbr”rcr}rnr–r=r—r˜r™rrrr”ús@   ÿzContext.verifyc CsÒz.| |¡| ¡}|jdkr&tj}ntj}WnŠty¸}zr|tjkrb|j dkrZtj }q¤tj }nB|t kr€t |dƒdur€tj}n$|t kržt |dƒduržtj }ntj}WYd}~n d}~00|tjkrÊ|}n|}|S)a»Import data Imports the given data into the Context. Returns: -- an object describing the results of imported or updated keys Raises: TypeError -- Very rarely. GPGMEError -- as signaled by the underlying library: Import status errors, when they occur, will usually be of NODATA. NO_PUBKEY indicates something managed to run the function without any arguments, while an argument of None triggers the first NODATA of errors.GPGME in the exception. rzNo dataÚdecodeTÚencodeN)Z op_importZop_import_resultZ consideredr ZSTATUS_IMPORT_PROBLEMZSTATUS_KEY_CONSIDEREDÚ Exceptionr rZcode_strZ STATUS_NODATAZSTATUS_FILE_ERRORÚ TypeErrorÚhasattrZSTATUS_NO_PUBKEYZ STATUS_ERROR)rrcrCrƒr}Z import_resultrrrÚ key_import8s(      zContext.key_importc Csvtƒ}d}z(| |||¡| dtj¡| ¡}Wn(tyZ}z|‚WYd}~n d}~00t|ƒdkrn|}nd}|S)aQExport keys. Exports public keys matching the pattern specified. If no pattern is specified then exports all available keys. Keyword arguments: pattern -- return keys matching pattern (default: all keys) Returns: -- A key block containing one or more OpenPGP keys in either ASCII armoured or binary format as determined by the Context(). If there are no matching keys it returns None. Raises: GPGMEError -- as signaled by the underlying library. rN)roÚ op_exportr^r_r`rarÚlen©rÚpatternrcr›Z pk_resultr}rCrrrÚ key_exportgs  zContext.key_exportc Csxtƒ}tj}z(| |||¡| dtj¡| ¡}Wn(ty\}z|‚WYd}~n d}~00t |ƒdkrp|}nd}|S)ayExport keys. Exports public keys matching the pattern specified in a minimised format. If no pattern is specified then exports all available keys. Keyword arguments: pattern -- return keys matching pattern (default: all keys) Returns: -- A key block containing one or more minimised OpenPGP keys in either ASCII armoured or binary format as determined by the Context(). If there are no matching keys it returns None. Raises: GPGMEError -- as signaled by the underlying library. rN) rorZGPGME_EXPORT_MODE_MINIMALr¤r^r_r`rarr¥r¦rrrÚkey_export_minimal‰s  zContext.key_export_minimalc Csxtƒ}tj}z(| |||¡| dtj¡| ¡}Wn(ty\}z|‚WYd}~n d}~00t |ƒdkrp|}nd}|S)aëExport secret keys. Exports secret keys matching the pattern specified. If no pattern is specified then exports or attempts to export all available secret keys. IMPORTANT: Each secret key to be exported will prompt for its passphrase via an invocation of pinentry and gpg-agent. If the passphrase is not entered or does not match then no data will be exported. This is the same result as when specifying a pattern that is not matched by the available keys. Keyword arguments: pattern -- return keys matching pattern (default: all keys) Returns: -- On success a key block containing one or more OpenPGP secret keys in either ASCII armoured or binary format as determined by the Context(). -- On failure while not raising an exception, returns None. Raises: GPGMEError -- as signaled by the underlying library. rN) rorZGPGME_EXPORT_MODE_SECRETr¤r^r_r`rarr¥)rr§rcr›Z sk_resultr}rCrrrÚkey_export_secret¬s  zContext.key_export_secretccsd|s| |¡| ||¡n t|tƒs0t|d�}| |d¡| ¡}|rX|V| ¡}qD| ¡dS)aList keys Keyword arguments: pattern -- return keys matching pattern (default: all keys) secret -- return only secret keys (default: False) mode -- keylist mode (default: list local keys) source -- read keys from source instead from the keyring (all other options are ignored in this case) Returns: -- an iterator returning key objects Raises: GPGMEError -- as signaled by the underlying library )ÚfilerN)Zset_keylist_modeÚop_keylist_startr†roZop_keylist_from_data_startÚop_keylist_nextÚop_keylist_end)rr§Úsecretr›Úsourcer=rrrÚkeylistÕs     zContext.keylistrc  s t ˆ¡r<|j} t|ddƒ} tj|_d‡fdd„ } | | ¡z®| ||d|d|rXtjj nd|rftjj ndB|rvtjj ndB|r†tjj ndBˆdurštjj ndB|r¦dntjjB| rºtjjndB¡Wt ˆ¡rê| |_| rê|j| dd…Žn,t ˆ¡�r| |_| �r|j| dd…Ž0| ¡S)a Create a primary key Create a primary key for the user id USERID. ALGORITHM may be used to specify the public key encryption algorithm for the new key. By default, a reasonable default is chosen. You may use "future-default" to select an algorithm that will be the default in a future implementation of the engine. ALGORITHM may be a string like "rsa", or "rsa2048" to explicitly request an algorithm and a key size. EXPIRES_IN specifies the expiration time of the key in number of seconds since the keys creation. By default, a reasonable expiration time is chosen. If you want to create a key that does not expire, use the keyword argument EXPIRES. SIGN, ENCRYPT, CERTIFY, and AUTHENTICATE can be used to request the capabilities of the new key. If you don't request any, a reasonable set of capabilities is selected, and in case of OpenPGP, a subkey with a reasonable set of capabilities is created. If PASSPHRASE is None (the default), then the key will not be protected with a passphrase. If PASSPHRASE is a string, it will be used to protect the key. If PASSPHRASE is True, the passphrase must be supplied using a passphrase callback or out-of-band with a pinentry. Keyword arguments: algorithm -- public key algorithm, see above (default: reasonable) expires_in -- expiration time in seconds (default: reasonable) expires -- whether or not the key should expire (default: True) sign -- request the signing capability (see above) encrypt -- request the encryption capability (see above) certify -- request the certification capability (see above) authenticate -- request the authentication capability (see above) passphrase -- protect the key with a passphrase (default: no passphrase) force -- force key creation even if a key with the same userid exists (default: False) Returns: -- an object describing the result of the key creation Raises: GPGMEError -- as signaled by the underlying library reNcsˆSr rrfrirrrk:sz)Context.create_key..passphrase_cbrr)N)r Ú is_a_stringrZrr rprqZ op_createkeyÚcreateÚSIGNÚENCRZCERTÚAUTHÚNOPASSWDÚNOEXPIREZFORCEÚop_genkey_result)rZuseridÚ algorithmÚ expires_inÚexpiresrxr~ZcertifyÚ authenticaterjÚforcer{r|rkrrirÚ create_keyúsH;   ÿþýüûúú ý zContext.create_keyc sút ˆ¡r<|j} t|ddƒ} tj|_d‡fdd„ } | | ¡zŒ| ||d||rVtjj nd|rdtjj ndB|rttjj ndBˆdurˆtjj ndB|r”dntjj B¡Wt ˆ¡rò| |_| rò|j| dd…Žn(t ˆ¡rð| |_| rð|j| dd…Ž0| ¡S)a@Create a subkey Create a subkey for the given KEY. As subkeys are a concept of OpenPGP, calling this is only valid for the OpenPGP protocol. ALGORITHM may be used to specify the public key encryption algorithm for the new subkey. By default, a reasonable default is chosen. You may use "future-default" to select an algorithm that will be the default in a future implementation of the engine. ALGORITHM may be a string like "rsa", or "rsa2048" to explicitly request an algorithm and a key size. EXPIRES_IN specifies the expiration time of the subkey in number of seconds since the subkeys creation. By default, a reasonable expiration time is chosen. If you want to create a subkey that does not expire, use the keyword argument EXPIRES. SIGN, ENCRYPT, and AUTHENTICATE can be used to request the capabilities of the new subkey. If you don't request any, an encryption subkey is generated. If PASSPHRASE is None (the default), then the subkey will not be protected with a passphrase. If PASSPHRASE is a string, it will be used to protect the subkey. If PASSPHRASE is True, the passphrase must be supplied using a passphrase callback or out-of-band with a pinentry. Keyword arguments: algorithm -- public key algorithm, see above (default: reasonable) expires_in -- expiration time in seconds (default: reasonable) expires -- whether or not the subkey should expire (default: True) sign -- request the signing capability (see above) encrypt -- request the encryption capability (see above) authenticate -- request the authentication capability (see above) passphrase -- protect the subkey with a passphrase (default: no passphrase) Returns: -- an object describing the result of the subkey creation Raises: GPGMEError -- as signaled by the underlying library reNcsˆSr rrfrirrrk�sz,Context.create_subkey..passphrase_cbrr)N)r r²rZrr rprqZop_createsubkeyr³r´rµr¶r·r¸r¹) rr=rºr»r¼rxr~r½rjr{r|rkrrirÚ create_subkeyUs>6   ÿþýüû ý zContext.create_subkeycCs| ||d¡dS)zÔAdd a UID Add the uid UID to the given KEY. Calling this function is only valid for the OpenPGP protocol. Raises: GPGMEError -- as signaled by the underlying library rN)Z op_adduid©rr=ÚuidrrrÚ key_add_uid¨s zContext.key_add_uidcCs| ||d¡dS)zÜRevoke a UID Revoke the uid UID from the given KEY. Calling this function is only valid for the OpenPGP protocol. Raises: GPGMEError -- as signaled by the underlying library rN)Z op_revuidrÁrrrÚkey_revoke_uid´s zContext.key_revoke_uidcCsbd}|dus.t |¡rn|tjjO}d |¡}|s>|tjjO}|rN|tjjO}| ||||¡dS)aýSign a key Sign a key with the current set of signing keys. Calling this function is only valid for the OpenPGP protocol. If UIDS is None (the default), then all UIDs are signed. If it is a string, then only the matching UID is signed. If it is a list of strings, then all matching UIDs are signed. Note that a case-sensitive exact string comparison is done. EXPIRES_IN specifies the expiration time of the signature in seconds. If EXPIRES_IN is False, the signature does not expire. Keyword arguments: uids -- user ids to sign, see above (default: sign all) expires_in -- validity period of the signature in seconds (default: do not expire) local -- create a local, non-exportable signature (default: False) Raises: GPGMEError -- as signaled by the underlying library rNÚ ) r r²r ZkeysignZLFSEPr$r¸ÚLOCALZ op_keysign)rr=Zuidsr»Úlocalr%rrrÚkey_signÀs    zContext.key_signcCs| ||¡dS)zóSet a keys' TOFU policy Set the TOFU policy associated with KEY to POLICY. Calling this function is only valid for the OpenPGP protocol. Raises: GPGMEError -- as signaled by the underlying library N)Zop_tofu_policy)rr=ZpolicyrrrÚkey_tofu_policyés zContext.key_tofu_policyc CsÂt |¡st|tƒr|}nd dd„|Dƒ¡}t ¡}t |j||rRt   |¡|fnd|rft   |¡|fnd|rzt   |¡|fnd|¡}|j r’t  |¡t |ƒt |¡}t |¡|dkr¾t|ƒSdS)a“Issue a raw assuan command This function can be used to issue a raw assuan command to the engine. If command is a string or bytes, it will be used as-is. If it is an iterable of strings, it will be properly escaped and joined into an well-formed assuan command. Keyword arguments: data_cb -- a callback receiving data lines inquire_cb -- a callback providing more information status_cb -- a callback receiving status lines Returns: result -- the result of command as GPGMEError Raises: GPGMEError -- as signaled by the underlying library r css|]}t |¡VqdSr )r Zpercent_escaperrrrrœrz*Context.assuan_transact..Nr)r r²r†Úbytesr$rÚnew_gpgme_error_t_pZgpgme_op_assuan_transact_extrÚweakrefÚrefrr@rÚgpgme_error_t_p_valueÚdelete_gpgme_error_t_pr) rZcommandZdata_cbZ inquire_cbZ status_cbÚcmdZerrptrÚerrrƒrrrÚassuan_transactõs,ÿÿÿü   zContext.assuan_transactcCsr|durtdƒ‚|durtƒ}|r4t |¡||f}nt |¡|f}t |j||||¡}|jrft |¡t |ƒdS)aëInteract with the engine This method can be used to edit keys and cards interactively. KEY is the key to edit, FUNC is called repeatedly with two unicode arguments, 'keyword' and 'args'. See the GPGME manual for details. Keyword arguments: sink -- if given, additional output is written here flags -- use constants.INTERACT_CARD to edit a card Raises: GPGMEError -- as signaled by the underlying library NzFirst argument cannot be None) Ú ValueErrorrorÌrÍrZgpgme_op_interactrrr@r)rr=rDrbr%Ú fnc_valueZ opaquedatarCrrrÚinteract'sÿ zContext.interactcs‡fdd„tˆ ¡ƒDƒS)zKeys used for signingcsg|]}ˆ |¡‘qSr)Z signers_enum©rÚirrrrKrz#Context.signers..)ÚrangeZ signers_countrrrrrYHszContext.signerscCs@|j}| ¡z|D]}| |¡qWn||_‚Yn0dSr )rYZ signers_clearZ signers_add)rrYÚoldr=rrrrYMscCs| ¡S)z Pinentry mode)Zget_pinentry_moderrrrrZXszContext.pinentry_modecCs| |¡dSr )Zset_pinentry_mode©rr7rrrrZ]scCs| ¡S)zProtocol to use)Z get_protocolrrrrr[aszContext.protocolcCstt |¡ƒ| |¡dSr )rrÚgpgme_engine_check_versionZ set_protocolrÚrrrr[fscCs|jjS)zEngine's home directory)Ú engine_infor\rrrrr\kszContext.home_dircCs|j|j|d�dS)N)r\)Úset_engine_infor[rÚrrrr\psZ gpgme_ctx_tZgpgme_cCs| d¡r| d¡ p|dvS)ú?This function should list all functions returning gpgme_error_tZ gpgme_op_Z_result>Zgpgme_set_keylist_modeZgpgme_set_senderZgpgme_ctx_set_engine_infoZgpgme_set_sub_protocolZgpgme_get_sig_keyrUZgpgme_signers_addÚgpgme_set_localeÚ gpgme_get_keyZ gpgme_cancelZgpgme_set_pinentry_modeZgpgme_sig_notation_addZgpgme_set_protocolZgpgme_cancel_asyncZgpgme_set_ctx_flag)Ú startswithÚendswithr0rrrr2ws  ÿÿzContext._errorcheck>rVrXrWcCsHtsdS| ¡| ¡| ¡|jrD|jrDtjrDt |j¡d|_dSr )rÚ _free_passcbÚ_free_progresscbÚ_free_statuscbrTrZ gpgme_releaserrrrÚ__del__Šs zContext.__del__cCs|Sr rrrrrÚ __enter__—szContext.__enter__cCs | ¡dSr ©ræ©rÚtyper7ÚtbrrrÚ__exit__šszContext.__exit__cos8|j|i|¤Ž| ¡}|r,|V| ¡}q| ¡dSr )r¬r­r®)rrBÚkwargsr=rrrÚop_keylist_all�s  zContext.op_keylist_allc Cs†t ¡}z tt |j|¡ƒt |¡}Wn<tjyd}z"d}| ¡tj krP|‚WYd}~n d}~00t  |¡|r‚dd„|_ |SdS)z~Returns the next key in the list created by a call to op_keylist_start(). The object returned is of type Key.NcSs t |¡Sr ©rZgpgme_key_unrefrrrrr…³rz)Context.op_keylist_next..) rÚnew_gpgme_key_t_prZgpgme_op_keylist_nextrÚgpgme_key_t_p_valuer rrsÚEOFÚdelete_gpgme_key_t_præ)rÚptrr=Úexcprrrr­¥s  zContext.op_keylist_nextc Cs�t ¡}ztt |j|||¡ƒWnBtjyd}z(| ¡tjkrLt  |¡‚|‚WYd}~n d}~00t  |¡}t  |¡|s‚J‚dd„|_ |S)a&Get a key given a fingerprint Keyword arguments: secret -- to request a secret key Returns: -- the matching key Raises: KeyError -- if the key was not found GPGMEError -- as signaled by the underlying library NcSs t |¡Sr rïrrrrr…Ðrz!Context.get_key..) rrðrràrr rrsròZ KeyNotFoundrñróræ)rr’r¯rôr}r=rrrÚget_key¶s    zContext.get_keycos8|j|i|¤Ž| ¡}|r,|V| ¡}q| ¡dSr )Zop_trustlist_startÚop_trustlist_nextZop_trustlist_end)rrBríÚtrustrrrÚop_trustlist_allÓs  zContext.op_trustlist_allc Csrt ¡}z tt |j|¡ƒt |¡}Wn:tjyb}z d}| ¡tj krN‚WYd}~n d}~00t  |¡|S)z�Returns the next trust item in the list created by a call to op_trustlist_start(). The object returned is of type TrustItem.N) rZnew_gpgme_trust_item_t_prZgpgme_op_trustlist_nextrZgpgme_trust_item_t_p_valuer rrsròZdelete_gpgme_trust_item_t_p)rrôrørõrrrr÷Ûs zContext.op_trustlist_nextcCsF|durd}n(|dur&t |¡|f}nt |¡||f}t ||¡dS)a*Sets the passphrase callback to the function specified by func. When the system needs a passphrase, it will call func with three args: hint, a string describing the key it needs the passphrase for; desc, a string describing the passphrase it needs; prev_bad, a boolean equal True if this is a call made after unsuccessful previous attempt. If hook has a value other than None it will be passed into the func as a forth argument. Please see the GPGME manual for more information. N)rÌrÍrÚgpg_set_passphrase_cb©rrDrhÚhookdatarrrrqês zContext.set_passphrase_cbcCstjr| d¡dSr )rrúrqrrrrrãszContext._free_passcbcCsF|durd}n(|dur&t |¡|f}nt |¡||f}t ||¡dS)aÃSets the progress meter callback to the function specified by FUNC. If FUNC is None, the callback will be cleared. This function will be called to provide an interactive update of the system's progress. The function will be called with three arguments, type, total, and current. If HOOK is not None, it will be supplied as fourth argument. Please see the GPGME manual for more information. N)rÌrÍrÚgpg_set_progress_cbrûrrrÚset_progress_cbs zContext.set_progress_cbcCstjr| d¡dSr )rrýrþrrrrräszContext._free_progresscbcCsF|durd}n(|dur&t |¡|f}nt |¡||f}t ||¡dS)aPSets the status callback to the function specified by FUNC. If FUNC is None, the callback will be cleared. The function will be called with two arguments, keyword and args. If HOOK is not None, it will be supplied as third argument. Please see the GPGME manual for more information. N)rÌrÍrÚgpg_set_status_cbrûrrrÚ set_status_cbs zContext.set_status_cbcCstjr| d¡dSr )rrÿrrrrrrå2szContext._free_statuscbcs4|j‰‡fdd„| ¡Dƒ}t|ƒdks,J‚|dS)z,Configuration of the engine currently in usecsg|]}|jˆkr|‘qSr)r[rÖ©r>rrr:rz'Context.engine_info..rr)r[Úget_engine_infor¥)rZinfosrrrrÜ6szContext.engine_infocCs t |j¡S)z®Get engine configuration Returns information about all configured and installed engines. Returns: infos -- a list of engine infos )rZgpgme_ctx_get_engine_inforrrrrr>s zContext.get_engine_infocCs| |||¡dS)a6Change engine configuration Changes the configuration of the crypto engine implementing the protocol 'proto' for the context. Keyword arguments: file_name -- engine program file name (unchanged if None) home_dir -- configuration directory (unchanged if None) N)Zctx_set_engine_info)rÚprotoÚ file_namer\rrrrÝJs zContext.set_engine_infocCs8t ¡}t |j||¡t |¡}t |¡t|ƒdS)z°Wait for asynchronous call to finish. Wait forever if hang is True. Raises an exception on errors. Please read the GPGME manual for more information. N)rrËÚ gpgme_waitrrÎrÏr)rÚhangrôrƒrrrÚwaitWs   z Context.waitcCs tjdtd�|j||||d�S)a÷Start key editing using supplied callback function Note: This interface is deprecated and will be removed with GPGME 1.8. Please use .interact instead. Furthermore, we implement this using gpgme_op_interact, so callbacks will get called with string keywords instead of numeric status messages. Code that is using constants.STATUS_X or constants.status.X will continue to work, whereas code using magic numbers will break as a result. z"Call to deprecated method op_edit.r)rbrÔ)r‡rˆr‰rÕ)rr=rDrÔÚoutrrrÚop_editds ÿzContext.op_edit)NNT)N)N)N) NrTFFFFNF)NrTFFFN)NFF)NNN)NrN)F)N)N)N)NN)/ " # *ü 'ö ]ø S  )ü 2 !                rScsªeZdZdZdZdZdd„Zd'‡fdd „ Zd d „Zd d „Z dd„Z dd„Z dd„Z d(dd„Z d)dd„Zd*dd„Zdd„Zdd„Zdd„Zd d!„Zd"d#„Zd+d%d&„Z‡ZS),roaJData buffer A lot of data has to be exchanged between the user and the crypto engine, like plaintext messages, ciphertext, signatures and information about the keys. The technical details about exchanging the data information are completely abstracted by GPGME. The user provides and receives the data via `gpgme_data_t' objects, regardless of the communication protocol between GPGME and the crypto engine in use. This Data class is the implementation of the GpgmeData objects. Please see the information about __init__ for instantiation. Z gpgme_data_tZ gpgme_data_cCs|dvS)rÞ> Úgpgme_data_readZgpgme_data_release_and_get_memZgpgme_data_get_encodingÚgpgme_data_releaseÚgpgme_data_writeZgpgme_data_seekZgpgme_data_set_flagZgpgme_data_identifyZgpgme_data_get_file_namerr0rrrr2‰szData._errorcheckNTcs tt|ƒ d¡d|_|dur*|j|Žnr|dur@| ||¡n\|durh|durh|durh| |||¡n4|dur”t |¡rˆ|  ||¡qœ|  |¡n|  ¡dS)a�Initialize a new gpgme_data_t object. If no args are specified, make it an empty object. If string alone is specified, initialize it with the data contained there. If file, offset, and length are all specified, file must be either a filename or a file-like object, and the object will be initialized by reading the specified chunk from the file. If cbs is specified, it MUST be a tuple of the form: (read_cb, write_cb, seek_cb, release_cb[, hook]) where the first four items are functions implementing reading, writing, seeking the data, and releasing any resources once the data object is deallocated. The functions must match the following prototypes: def read(amount, hook=None): return def write(data, hook=None): return def seek(offset, whence, hook=None): return def release(hook=None): The functions may be bound methods. In that case, you can simply use the 'self' reference instead of using a hook. If file is specified without any other arguments, then it must be a filename, and the object will be initialized from that file. N) rrorZdata_cbsÚ new_from_cbsÚ new_from_memÚnew_from_filepartr r²Ú new_from_fileÚ new_from_fdÚnew)rÚstringr«ÚoffsetÚlengthZcbsÚcopyrrrrœs/   z Data.__init__cCsFtsdS|jdur:tjr:t |j¡|jr4t |¡d|_| ¡dSr )rrr rr@Ú _free_datacbsrrrrræÜs  z Data.__del__cCs|Sr rrrrrrçészData.__enter__cCs | ¡dSr rèrérrrrììsz Data.__exit__cCs d|_dSr )Z _data_cbsrrrrrïszData._free_datacbscCs0t ¡}tt |¡ƒt |¡|_t |¡dSr )rÚnew_gpgme_data_t_prZgpgme_data_newÚgpgme_data_t_p_valuerÚdelete_gpgme_data_t_p)rr]rrrròs zData.newcCs:t ¡}tt ||t|ƒ|¡ƒt |¡|_t |¡dSr )rrrZgpgme_data_new_from_memr¥rrr)rrrr]rrrrøs ÿ zData.new_from_memc Cs€t ¡}ztt |||¡ƒWnFtjyd}z,| ¡tjkrL|sLtdƒ‚n|‚WYd}~n d}~00t  |¡|_ t  |¡dS)Nz#delayed reads are not yet supported) rrrZgpgme_data_new_from_filer rrsZ INV_VALUErÓrrr)rÚfilenamerr]r}rrrrÿs  zData.new_from_filecCsdt ¡}|dur(t |¡|||||f}nt |¡||||f}t |||¡t |¡|_t |¡dSr )rrrÌrÍZgpg_data_new_from_cbsrrr)rZread_cbZwrite_cbZseek_cbZ release_cbrhr]rürrrr sÿÿ zData.new_from_cbscCs†t ¡}d}d}t |¡r |}n6t | ¡|j¡}|durVtdtt |ƒƒt|ƒfƒ‚t t  |||||¡ƒt  |¡|_ t |¡dS)zçThis wraps the GPGME gpgme_data_new_from_filepart() function. The argument "file" may be: * a string specifying a file name, or * a file-like object supporting the fileno() and the mode attribute. Nz"Failed to open file from %s arg %s)rrr r²ÚfdopenÚfilenor›rÓÚstrrêrZgpgme_data_new_from_filepartrrr)rr«rrr]rÚfprrrrs&  ÿÿ ÿÿ zData.new_from_filepartcCs6t ¡}tt || ¡¡ƒt |¡|_t |¡dS)z¢This wraps the GPGME gpgme_data_new_from_fd() function. The argument "file" must be a file-like object, supporting the fileno() method. N)rrrZgpgme_data_new_from_fdrrrr)rr«r]rrrr2s zData.new_from_fdcCs| |¡dS)z¯This wrap around gpgme_data_new_from_stream is an alias for new_from_fd() method since in python there's no difference between file stream and file descriptor.N)r©rr«rrrÚnew_from_stream=szData.new_from_streamcCs| |¡dS)zÄThis wrap around gpgme_data_new_from_estream is an alias for new_from_fd() method since in python there's no difference between file stream and file descriptor, but using fd broke.N)r"r!rrrÚnew_from_estreamCszData.new_from_estreamcCs4t |j|¡}|dkr0|jr(t |¡nt ¡‚|S)zkWrite buffer given as string or bytes. If a string is given, it is implicitly encoded using UTF-8.r)rr rrr@rZ fromSyserror)rÚbufferZwrittenrrrÚwriteIs  z Data.writeéÿÿÿÿcCs¬|dkr dS|dkrLzt |j|¡}Wn |jr@t |¡n‚Yn0|Sg}zt |jd¡}Wn |jr|t |¡n‚Yn0t|ƒdkr’qž| |¡qPd |¡SdS)zíRead at most size bytes, returned as bytes. If the size argument is negative or omitted, read until EOF is reached. Returns the data read, or the empty string if there was no data to read before EOF was reached.rÚirN)rr rrr@r¥r#r$)rÚsizerCÚchunksrrrraUs*    z Data.read)NNNNNT)T)T)N)r&)r!rMrNrFr.r/r2rrærçrìrrrrrrrr"r#r%rarRrrrrrous2ú@     rocCs t |¡S)z�Return short algorithm string Return a public key algorithm string (e.g. "rsa2048") for a given SUBKEY. Returns: algo - a string )rZgpgme_pubkey_algo_string)r˜rrrÚpubkey_algo_stringys r*cCs t |¡S)zºReturn name of public key algorithm Return the name of the public key algorithm for a given numeric algorithm id ALGO (cf. RFC4880). Returns: algo - a string )rZgpgme_pubkey_algo_name©ZalgorrrÚpubkey_algo_name†s r,cCs t |¡S)z®Return name of hash algorithm Return the name of the hash algorithm for a given numeric algorithm id ALGO (cf. RFC4880). Returns: algo - a string )rZgpgme_hash_algo_namer+rrrÚhash_algo_name“s r-cCs t |¡S)ztGet protocol description Get the string describing protocol PROTO. Returns: proto - a string )rZgpgme_get_protocol_name©rrrrÚget_protocol_name s r/cCs t |¡S)zŒReturn the address spec Return the addr-spec (cf. RFC2822 section 4.3) from a user id UID. Returns: addr_spec - a string )rZgpgme_addrspec_from_uid)rÂrrrÚaddrspec_from_uid¬s r0cCs t |¡Sr )rZgpgme_check_version)ÚversionrrrÚ check_version¸sr2cCs0ztt |¡ƒWdStjy*YdS0dS)NTF)rrrÛr rr.rrrÚengine_check_versionÃs r3cCsLt ¡}ztt |¡ƒt |¡}Wntjy<d}Yn0t |¡|Sr )rZnew_gpgme_engine_info_t_prZgpgme_get_engine_infoZgpgme_engine_info_t_p_valuer rZdelete_gpgme_engine_info_t_p)rôÚinforrrrËs  rcCstt |||¡ƒdS)a#Changes the default configuration of the crypto engine implementing the protocol 'proto'. 'file_name' is the file name of the executable program implementing this protocol. 'home_dir' is the directory name of the configuration directory (engine's default is used if omitted).N)rrZgpgme_set_engine_info)rrr\rrrrÝÖsrÝcCstt d||¡ƒdS)z(Sets the default locale used by contextsN)rrrß)r€r7rrrÚ set_localeßsr5cCsLt ¡}t d||¡}t |¡}t |¡|dursJ    M