1 ;;; epa.el --- the EasyPG Assistant -*- lexical-binding: t -*-
3 ;; Copyright (C) 2006-2013 Free Software Foundation, Inc.
5 ;; Author: Daiki Ueno <ueno@unixuser.org>
6 ;; Keywords: PGP, GnuPG
8 ;; This file is part of GNU Emacs.
10 ;; GNU Emacs is free software: you can redistribute it and/or modify
11 ;; it under the terms of the GNU General Public License as published by
12 ;; the Free Software Foundation, either version 3 of the License, or
13 ;; (at your option) any later version.
15 ;; GNU Emacs is distributed in the hope that it will be useful,
16 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
17 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 ;; GNU General Public License for more details.
20 ;; You should have received a copy of the GNU General Public License
21 ;; along with GNU Emacs. If not, see <http://www.gnu.org/licenses/>.
28 (eval-when-compile (require 'wid-edit
))
32 "The EasyPG Assistant"
36 (defcustom epa-popup-info-window t
37 "If non-nil, display status information from epa commands in another window."
41 (defcustom epa-info-window-height
5
42 "Number of lines used to display status information."
46 (defgroup epa-faces nil
51 (defface epa-validity-high
52 '((default :weight bold
)
53 (((class color
) (background dark
)) :foreground
"PaleTurquoise"))
54 "Face for high validity EPA information."
57 (defface epa-validity-medium
58 '((default :slant italic
)
59 (((class color
) (background dark
)) :foreground
"PaleTurquoise"))
60 "Face for medium validity EPA information."
63 (defface epa-validity-low
65 "Face used for displaying the low validity."
68 (defface epa-validity-disabled
69 '((t :slant italic
:inverse-video t
))
70 "Face used for displaying the disabled validity."
74 '((((class color
) (background dark
))
75 :foreground
"lightyellow")
76 (((class color
) (background light
))
78 "Face used for displaying the string."
82 '((default :weight bold
)
83 (((class color
) (background dark
)) :foreground
"orange")
84 (((class color
) (background light
)) :foreground
"red"))
85 "Face used for displaying the high validity."
88 (defface epa-field-name
89 '((default :weight bold
)
90 (((class color
) (background dark
)) :foreground
"PaleTurquoise"))
91 "Face for the name of the attribute field."
94 (defface epa-field-body
95 '((default :slant italic
)
96 (((class color
) (background dark
)) :foreground
"turquoise"))
97 "Face for the body of the attribute field."
100 (defcustom epa-validity-face-alist
101 '((unknown . epa-validity-disabled
)
102 (invalid . epa-validity-disabled
)
103 (disabled . epa-validity-disabled
)
104 (revoked . epa-validity-disabled
)
105 (expired . epa-validity-disabled
)
106 (none . epa-validity-low
)
107 (undefined . epa-validity-low
)
108 (never . epa-validity-low
)
109 (marginal . epa-validity-medium
)
110 (full . epa-validity-high
)
111 (ultimate . epa-validity-high
))
112 "An alist mapping validity values to faces."
113 :type
'(repeat (cons symbol face
))
116 (defvar epa-font-lock-keywords
119 ("^\t\\([^\t:]+:\\)[ \t]*\\(.*\\)$"
121 (2 'epa-field-body
)))
122 "Default expressions to addon in epa-mode.")
124 (defconst epa-pubkey-algorithm-letter-alist
132 (defvar epa-protocol
'OpenPGP
133 "The default protocol.
134 The value can be either OpenPGP or CMS.
136 You should bind this variable with `let', but do not set it globally.")
138 (defvar epa-armor nil
139 "If non-nil, epa commands create ASCII armored output.
141 You should bind this variable with `let', but do not set it globally.")
143 (defvar epa-textmode nil
144 "If non-nil, epa commands treat input files as text.
146 You should bind this variable with `let', but do not set it globally.")
148 (defvar epa-keys-buffer nil
)
149 (defvar epa-key-buffer-alist nil
)
151 (defvar epa-list-keys-arguments nil
)
152 (defvar epa-info-buffer nil
)
153 (defvar epa-last-coding-system-specified nil
)
155 (defvar epa-key-list-mode-map
156 (let ((keymap (make-sparse-keymap))
157 (menu-map (make-sparse-keymap)))
158 (define-key keymap
"m" 'epa-mark-key
)
159 (define-key keymap
"u" 'epa-unmark-key
)
160 (define-key keymap
"d" 'epa-decrypt-file
)
161 (define-key keymap
"v" 'epa-verify-file
)
162 (define-key keymap
"s" 'epa-sign-file
)
163 (define-key keymap
"e" 'epa-encrypt-file
)
164 (define-key keymap
"r" 'epa-delete-keys
)
165 (define-key keymap
"i" 'epa-import-keys
)
166 (define-key keymap
"o" 'epa-export-keys
)
167 (define-key keymap
"g" 'revert-buffer
)
168 (define-key keymap
"n" 'next-line
)
169 (define-key keymap
"p" 'previous-line
)
170 (define-key keymap
" " 'scroll-up-command
)
171 (define-key keymap
[?\S-\
] 'scroll-down-command
)
172 (define-key keymap
[delete] 'scroll-down-command)
173 (define-key keymap "q" 'epa-exit-buffer)
174 (define-key keymap [menu-bar epa-key-list-mode] (cons "Keys" menu-map))
175 (define-key menu-map [epa-key-list-unmark-key]
176 '(menu-item "Unmark Key" epa-unmark-key
177 :help "Unmark a key"))
178 (define-key menu-map [epa-key-list-mark-key]
179 '(menu-item "Mark Key" epa-mark-key
181 (define-key menu-map [separator-epa-file] '(menu-item "--"))
182 (define-key menu-map [epa-verify-file]
183 '(menu-item "Verify File..." epa-verify-file
184 :help "Verify FILE"))
185 (define-key menu-map [epa-sign-file]
186 '(menu-item "Sign File..." epa-sign-file
187 :help "Sign FILE by SIGNERS keys selected"))
188 (define-key menu-map [epa-decrypt-file]
189 '(menu-item "Decrypt File..." epa-decrypt-file
190 :help "Decrypt FILE"))
191 (define-key menu-map [epa-encrypt-file]
192 '(menu-item "Encrypt File..." epa-encrypt-file
193 :help "Encrypt FILE for RECIPIENTS"))
194 (define-key menu-map [separator-epa-key-list] '(menu-item "--"))
195 (define-key menu-map [epa-key-list-delete-keys]
196 '(menu-item "Delete Keys" epa-delete-keys
197 :help "Delete Marked Keys"))
198 (define-key menu-map [epa-key-list-import-keys]
199 '(menu-item "Import Keys" epa-import-keys
200 :help "Import keys from a file"))
201 (define-key menu-map [epa-key-list-export-keys]
202 '(menu-item "Export Keys" epa-export-keys
203 :help "Export marked keys to a file"))
206 (defvar epa-key-mode-map
207 (let ((keymap (make-sparse-keymap)))
208 (define-key keymap "q" 'epa-exit-buffer)
211 (defvar epa-info-mode-map
212 (let ((keymap (make-sparse-keymap)))
213 (define-key keymap "q" 'delete-window)
216 (defvar epa-exit-buffer-function #'bury-buffer)
218 (define-widget 'epa-key 'push-button
219 "Button for representing a epg-key object."
221 :button-face-get 'epa--key-widget-button-face-get
222 :value-create 'epa--key-widget-value-create
223 :action 'epa--key-widget-action
224 :help-echo 'epa--key-widget-help-echo)
226 (defun epa--key-widget-action (widget &optional _event)
227 (save-selected-window
228 (epa--show-key (widget-get widget :value))))
230 (defun epa--key-widget-value-create (widget)
231 (let* ((key (widget-get widget :value))
232 (primary-sub-key (car (epg-key-sub-key-list key)))
233 (primary-user-id (car (epg-key-user-id-list key))))
234 (insert (format "%c "
235 (if (epg-sub-key-validity primary-sub-key)
236 (car (rassq (epg-sub-key-validity primary-sub-key)
237 epg-key-validity-alist))
239 (epg-sub-key-id primary-sub-key)
242 (if (stringp (epg-user-id-string primary-user-id))
243 (epg-user-id-string primary-user-id)
244 (epg-decode-dn (epg-user-id-string primary-user-id)))
247 (defun epa--key-widget-button-face-get (widget)
248 (let ((validity (epg-sub-key-validity (car (epg-key-sub-key-list
249 (widget-get widget :value))))))
251 (cdr (assq validity epa-validity-face-alist))
254 (defun epa--key-widget-help-echo (widget)
256 (epg-sub-key-id (car (epg-key-sub-key-list
257 (widget-get widget :value))))))
260 (if (fboundp 'encode-coding-string)
261 (defalias 'epa--encode-coding-string 'encode-coding-string)
262 (defalias 'epa--encode-coding-string 'identity)))
265 (if (fboundp 'decode-coding-string)
266 (defalias 'epa--decode-coding-string 'decode-coding-string)
267 (defalias 'epa--decode-coding-string 'identity)))
269 (defun epa-key-list-mode ()
270 "Major mode for `epa-list-keys'."
271 (kill-all-local-variables)
272 (buffer-disable-undo)
273 (setq major-mode 'epa-key-list-mode
277 (use-local-map epa-key-list-mode-map)
278 (make-local-variable 'font-lock-defaults)
279 (setq font-lock-defaults '(epa-font-lock-keywords t))
280 ;; In XEmacs, auto-initialization of font-lock is not effective
281 ;; if buffer-file-name is not set.
282 (font-lock-set-defaults)
283 (make-local-variable 'epa-exit-buffer-function)
284 (make-local-variable 'revert-buffer-function)
285 (setq revert-buffer-function 'epa--key-list-revert-buffer)
286 (run-mode-hooks 'epa-key-list-mode-hook))
288 (defun epa-key-mode ()
289 "Major mode for a key description."
290 (kill-all-local-variables)
291 (buffer-disable-undo)
292 (setq major-mode 'epa-key-mode
296 (use-local-map epa-key-mode-map)
297 (make-local-variable 'font-lock-defaults)
298 (setq font-lock-defaults '(epa-font-lock-keywords t))
299 ;; In XEmacs, auto-initialization of font-lock is not effective
300 ;; if buffer-file-name is not set.
301 (font-lock-set-defaults)
302 (make-local-variable 'epa-exit-buffer-function)
303 (run-mode-hooks 'epa-key-mode-hook))
305 (defun epa-info-mode ()
306 "Major mode for `epa-info-buffer'."
307 (kill-all-local-variables)
308 (buffer-disable-undo)
309 (setq major-mode 'epa-info-mode
313 (use-local-map epa-info-mode-map)
314 (run-mode-hooks 'epa-info-mode-hook))
316 (defun epa-mark-key (&optional arg)
317 "Mark a key on the current line.
318 If ARG is non-nil, unmark the key."
320 (let ((inhibit-read-only t)
324 (unless (get-text-property (point) 'epa-key)
325 (error "No key on this line"))
326 (setq properties (text-properties-at (point)))
328 (insert (if arg " " "*"))
329 (set-text-properties (1- (point)) (point) properties)
332 (defun epa-unmark-key (&optional arg)
333 "Unmark a key on the current line.
334 If ARG is non-nil, mark the key."
336 (epa-mark-key (not arg)))
338 (defun epa-exit-buffer ()
339 "Exit the current buffer.
340 `epa-exit-buffer-function' is called if it is set."
342 (funcall epa-exit-buffer-function))
344 (defun epa--insert-keys (keys)
347 (narrow-to-region (point) (point))
352 (add-text-properties point (point)
353 (list 'epa-key (car keys)
358 (widget-create 'epa-key :value (car keys))
360 (setq keys (cdr keys))))
361 (add-text-properties (point-min) (point-max)
362 (list 'epa-list-keys t
368 (defun epa--list-keys (name secret)
369 (unless (and epa-keys-buffer
370 (buffer-live-p epa-keys-buffer))
371 (setq epa-keys-buffer (generate-new-buffer "*Keys*")))
372 (set-buffer epa-keys-buffer)
374 (let ((inhibit-read-only t)
377 (context (epg-make-context epa-protocol)))
378 (unless (get-text-property point 'epa-list-keys)
379 (setq point (next-single-property-change point 'epa-list-keys)))
382 (or (next-single-property-change point 'epa-list-keys)
385 (epa--insert-keys (epg-list-keys context name secret))
387 (set-keymap-parent (current-local-map) widget-keymap))
388 (make-local-variable 'epa-list-keys-arguments)
389 (setq epa-list-keys-arguments (list name secret))
390 (goto-char (point-min))
391 (pop-to-buffer (current-buffer)))
394 (defun epa-list-keys (&optional name)
395 "List all keys matched with NAME from the public keyring."
397 (if current-prefix-arg
398 (let ((name (read-string "Pattern: "
399 (if epa-list-keys-arguments
400 (car epa-list-keys-arguments)))))
401 (list (if (equal name "") nil name)))
403 (epa--list-keys name nil))
406 (defun epa-list-secret-keys (&optional name)
407 "List all keys matched with NAME from the private keyring."
409 (if current-prefix-arg
410 (let ((name (read-string "Pattern: "
411 (if epa-list-keys-arguments
412 (car epa-list-keys-arguments)))))
413 (list (if (equal name "") nil name)))
415 (epa--list-keys name t))
417 (defun epa--key-list-revert-buffer (&optional _ignore-auto _noconfirm)
418 (apply #'epa--list-keys epa-list-keys-arguments))
420 (defun epa--marked-keys ()
421 (or (with-current-buffer epa-keys-buffer
422 (goto-char (point-min))
424 (while (re-search-forward "^\\*" nil t)
425 (if (setq key (get-text-property (match-beginning 0)
427 (setq keys (cons key keys))))
429 (let ((key (get-text-property (point-at-bol) 'epa-key)))
433 (defun epa--select-keys (prompt keys)
434 (unless (and epa-keys-buffer
435 (buffer-live-p epa-keys-buffer))
436 (setq epa-keys-buffer (generate-new-buffer "*Keys*")))
437 (with-current-buffer epa-keys-buffer
439 ;; C-c C-c is the usual way to finish the selection (bug#11159).
440 (define-key (current-local-map) "\C-c\C-c" 'exit-recursive-edit)
441 (let ((inhibit-read-only t)
445 (substitute-command-keys "\
446 - `\\[epa-mark-key]' to mark a key on the line
447 - `\\[epa-unmark-key]' to unmark a key on the line\n"))
449 :notify (lambda (&rest _ignore) (abort-recursive-edit))
451 (substitute-command-keys
452 "Click here or \\[abort-recursive-edit] to cancel")
455 :notify (lambda (&rest _ignore) (exit-recursive-edit))
457 (substitute-command-keys
458 "Click here or \\[exit-recursive-edit] to finish")
461 (epa--insert-keys keys)
463 (set-keymap-parent (current-local-map) widget-keymap)
464 (setq epa-exit-buffer-function #'abort-recursive-edit)
465 (goto-char (point-min))
466 (let ((display-buffer-mark-dedicated 'soft))
467 (pop-to-buffer (current-buffer))))
472 (kill-buffer epa-keys-buffer))))
475 (defun epa-select-keys (context prompt &optional names secret)
476 "Display a user's keyring and ask him to select keys.
477 CONTEXT is an epg-context.
478 PROMPT is a string to prompt with.
479 NAMES is a list of strings to be matched with keys. If it is nil, all
481 If SECRET is non-nil, list secret keys instead of public keys."
482 (let ((keys (epg-list-keys context names secret)))
483 (epa--select-keys prompt keys)))
485 (defun epa--show-key (key)
486 (let* ((primary-sub-key (car (epg-key-sub-key-list key)))
487 (entry (assoc (epg-sub-key-id primary-sub-key)
488 epa-key-buffer-alist))
489 (inhibit-read-only t)
493 (setq entry (cons (epg-sub-key-id primary-sub-key) nil)
494 epa-key-buffer-alist (cons entry epa-key-buffer-alist)))
495 (unless (and (cdr entry)
496 (buffer-live-p (cdr entry)))
497 (setcdr entry (generate-new-buffer
498 (format "*Key*%s" (epg-sub-key-id primary-sub-key)))))
499 (set-buffer (cdr entry))
501 (make-local-variable 'epa-key)
504 (setq pointer (epg-key-user-id-list key))
508 (if (epg-user-id-validity (car pointer))
510 (car (rassq (epg-user-id-validity (car pointer))
511 epg-key-validity-alist)))
514 (if (stringp (epg-user-id-string (car pointer)))
515 (epg-user-id-string (car pointer))
516 (epg-decode-dn (epg-user-id-string (car pointer))))
518 (setq pointer (cdr pointer)))
519 (setq pointer (epg-key-sub-key-list key))
522 (if (epg-sub-key-validity (car pointer))
524 (car (rassq (epg-sub-key-validity (car pointer))
525 epg-key-validity-alist)))
528 (epg-sub-key-id (car pointer))
531 (epg-sub-key-length (car pointer)))
533 (cdr (assq (epg-sub-key-algorithm (car pointer))
534 epg-pubkey-algorithm-alist))
537 (format-time-string "%Y-%m-%d"
538 (epg-sub-key-creation-time (car pointer)))
539 (error "????-??-??"))
540 (if (epg-sub-key-expiration-time (car pointer))
541 (format (if (time-less-p (current-time)
542 (epg-sub-key-expiration-time
547 (format-time-string "%Y-%m-%d"
548 (epg-sub-key-expiration-time
550 (error "????-??-??")))
553 (mapconcat #'symbol-name
554 (epg-sub-key-capability (car pointer))
557 (epg-sub-key-fingerprint (car pointer))
559 (setq pointer (cdr pointer)))
560 (goto-char (point-min))
561 (pop-to-buffer (current-buffer))))
563 (defun epa-display-info (info)
564 (if epa-popup-info-window
565 (save-selected-window
566 (unless (and epa-info-buffer (buffer-live-p epa-info-buffer))
567 (setq epa-info-buffer (generate-new-buffer "*Info*")))
568 (if (get-buffer-window epa-info-buffer)
569 (delete-window (get-buffer-window epa-info-buffer)))
570 (with-current-buffer epa-info-buffer
571 (let ((inhibit-read-only t)
576 (goto-char (point-min)))
577 (if (> (window-height)
578 epa-info-window-height)
579 (set-window-buffer (split-window nil (- (window-height)
580 epa-info-window-height))
582 (pop-to-buffer epa-info-buffer)
583 (if (> (window-height) epa-info-window-height)
584 (shrink-window (- (window-height) epa-info-window-height)))))
585 (message "%s" info)))
587 (defun epa-display-verify-result (verify-result)
588 (declare (obsolete epa-display-info "23.1"))
589 (epa-display-info (epg-verify-result-to-string verify-result)))
591 (defun epa-passphrase-callback-function (context key-id handback)
594 (format "Passphrase for symmetric encryption%s: "
595 ;; Add the file name to the prompt, if any.
596 (if (stringp handback)
597 (format " for %s" handback)
599 (eq (epg-context-operation context) 'encrypt))
602 "Passphrase for PIN: "
603 (let ((entry (assoc key-id epg-user-id-alist)))
605 (format "Passphrase for %s %s: " key-id (cdr entry))
606 (format "Passphrase for %s: " key-id)))))))
608 (defun epa-progress-callback-function (_context what _char current total
610 (let ((prompt (or handback
611 (format "Processing %s: " what))))
612 ;; According to gnupg/doc/DETAIL: a "total" of 0 indicates that
613 ;; the total amount is not known. The condition TOTAL && CUR ==
614 ;; TOTAL may be used to detect the end of an operation.
616 (if (= current total)
617 (message "%s...done" prompt)
618 (message "%s...%d%%" prompt
619 (floor (* (/ current (float total)) 100))))
620 (message "%s..." prompt))))
622 (defun epa-read-file-name (input)
623 "Interactively read an output file name based on INPUT file name."
624 (setq input (file-name-sans-extension (expand-file-name input)))
627 (concat "To file (default " (file-name-nondirectory input) ") ")
628 (file-name-directory input)
632 (defun epa-decrypt-file (decrypt-file &optional plain-file)
633 "Decrypt DECRYPT-FILE into PLAIN-FILE.
634 If you do not specify PLAIN-FILE, this functions prompts for the value to use."
636 (let* ((file (read-file-name "File to decrypt: "))
637 (plain (epa-read-file-name file)))
639 (or plain-file (setq plain-file (epa-read-file-name decrypt-file)))
640 (setq decrypt-file (expand-file-name decrypt-file))
641 (let ((context (epg-make-context epa-protocol)))
642 (epg-context-set-passphrase-callback context
643 #'epa-passphrase-callback-function)
644 (epg-context-set-progress-callback context
646 #'epa-progress-callback-function
647 (format "Decrypting %s..."
648 (file-name-nondirectory decrypt-file))))
649 (message "Decrypting %s..." (file-name-nondirectory decrypt-file))
650 (epg-decrypt-file context decrypt-file plain-file)
651 (message "Decrypting %s...wrote %s" (file-name-nondirectory decrypt-file)
652 (file-name-nondirectory plain-file))
653 (if (epg-context-result-for context 'verify)
654 (epa-display-info (epg-verify-result-to-string
655 (epg-context-result-for context 'verify))))))
658 (defun epa-verify-file (file)
660 (interactive "fFile: ")
661 (setq file (expand-file-name file))
662 (let* ((context (epg-make-context epa-protocol))
663 (plain (if (equal (file-name-extension file) "sig")
664 (file-name-sans-extension file))))
665 (epg-context-set-progress-callback context
667 #'epa-progress-callback-function
668 (format "Verifying %s..."
669 (file-name-nondirectory file))))
670 (message "Verifying %s..." (file-name-nondirectory file))
671 (epg-verify-file context file plain)
672 (message "Verifying %s...done" (file-name-nondirectory file))
673 (if (epg-context-result-for context 'verify)
674 (epa-display-info (epg-verify-result-to-string
675 (epg-context-result-for context 'verify))))))
677 (defun epa--read-signature-type ()
680 (message "Signature type (n,c,d,?) ")
685 (setq type 'detached))
687 (with-output-to-temp-buffer "*Help*"
688 (with-current-buffer standard-output
690 n - Create a normal signature
691 c - Create a cleartext signature
692 d - Create a detached signature
696 (setq type 'normal))))
700 (defun epa-sign-file (file signers mode)
701 "Sign FILE by SIGNERS keys selected."
703 (let ((verbose current-prefix-arg))
704 (list (expand-file-name (read-file-name "File: "))
706 (epa-select-keys (epg-make-context epa-protocol)
707 "Select keys for signing.
708 If no one is selected, default secret key is used. "
711 (epa--read-signature-type)
713 (let ((signature (concat file
714 (if (eq epa-protocol 'OpenPGP)
717 '(nil t normal detached))))
719 (if (memq mode '(t detached))
722 (if (memq mode '(t detached))
725 (context (epg-make-context epa-protocol)))
726 (epg-context-set-armor context epa-armor)
727 (epg-context-set-textmode context epa-textmode)
728 (epg-context-set-signers context signers)
729 (epg-context-set-passphrase-callback context
730 #'epa-passphrase-callback-function)
731 (epg-context-set-progress-callback context
733 #'epa-progress-callback-function
734 (format "Signing %s..."
735 (file-name-nondirectory file))))
736 (message "Signing %s..." (file-name-nondirectory file))
737 (epg-sign-file context file signature mode)
738 (message "Signing %s...wrote %s" (file-name-nondirectory file)
739 (file-name-nondirectory signature))))
742 (defun epa-encrypt-file (file recipients)
743 "Encrypt FILE for RECIPIENTS."
745 (list (expand-file-name (read-file-name "File: "))
746 (epa-select-keys (epg-make-context epa-protocol)
747 "Select recipients for encryption.
748 If no one is selected, symmetric encryption will be performed. ")))
749 (let ((cipher (concat file (if (eq epa-protocol 'OpenPGP)
750 (if epa-armor ".asc" ".gpg")
752 (context (epg-make-context epa-protocol)))
753 (epg-context-set-armor context epa-armor)
754 (epg-context-set-textmode context epa-textmode)
755 (epg-context-set-passphrase-callback context
756 #'epa-passphrase-callback-function)
757 (epg-context-set-progress-callback context
759 #'epa-progress-callback-function
760 (format "Encrypting %s..."
761 (file-name-nondirectory file))))
762 (message "Encrypting %s..." (file-name-nondirectory file))
763 (epg-encrypt-file context file recipients cipher)
764 (message "Encrypting %s...wrote %s" (file-name-nondirectory file)
765 (file-name-nondirectory cipher))))
768 (defun epa-decrypt-region (start end &optional make-buffer-function)
769 "Decrypt the current region between START and END.
771 If MAKE-BUFFER-FUNCTION is non-nil, call it to prepare an output buffer.
772 It should return that buffer. If it copies the input, it should
773 delete the text now being decrypted. It should leave point at the
774 proper place to insert the plaintext.
776 Be careful about using this command in Lisp programs!
777 Since this function operates on regions, it does some tricks such
778 as coding-system detection and unibyte/multibyte conversion. If
779 you are sure how the data in the region should be treated, you
780 should consider using the string based counterpart
781 `epg-decrypt-string', or the file based counterpart
782 `epg-decrypt-file' instead.
786 \(let ((context (epg-make-context 'OpenPGP)))
787 (decode-coding-string
788 (epg-decrypt-string context (buffer-substring start end))
792 (let ((context (epg-make-context epa-protocol))
794 (epg-context-set-passphrase-callback context
795 #'epa-passphrase-callback-function)
796 (epg-context-set-progress-callback context
798 #'epa-progress-callback-function
800 (message "Decrypting...")
801 (setq plain (epg-decrypt-string context (buffer-substring start end)))
802 (message "Decrypting...done")
803 (setq plain (epa--decode-coding-string
805 (or coding-system-for-read
806 (get-text-property start 'epa-coding-system-used)
808 (if make-buffer-function
809 (with-current-buffer (funcall make-buffer-function)
810 (let ((inhibit-read-only t))
812 (if (y-or-n-p "Replace the original text? ")
813 (let ((inhibit-read-only t))
814 (delete-region start end)
817 (with-output-to-temp-buffer "*Temp*"
818 (set-buffer standard-output)
821 (if (epg-context-result-for context 'verify)
822 (epa-display-info (epg-verify-result-to-string
823 (epg-context-result-for context 'verify)))))))
825 (defun epa--find-coding-system-for-mime-charset (mime-charset)
826 (if (featurep 'xemacs)
827 (if (fboundp 'find-coding-system)
828 (find-coding-system mime-charset))
829 ;; Find the first coding system which corresponds to MIME-CHARSET.
830 (let ((pointer (coding-system-list)))
832 (not (eq (coding-system-get (car pointer) 'mime-charset)
834 (setq pointer (cdr pointer)))
838 (defun epa-decrypt-armor-in-region (start end)
839 "Decrypt OpenPGP armors in the current region between START and END.
841 Don't use this command in Lisp programs!
842 See the reason described in the `epa-decrypt-region' documentation."
846 (narrow-to-region start end)
848 (let (armor-start armor-end)
849 (while (re-search-forward "-----BEGIN PGP MESSAGE-----$" nil t)
850 (setq armor-start (match-beginning 0)
851 armor-end (re-search-forward "^-----END PGP MESSAGE-----$"
854 (error "Encryption armor beginning has no matching end"))
855 (goto-char armor-start)
856 (let ((coding-system-for-read
857 (or coding-system-for-read
858 (if (re-search-forward "^Charset: \\(.*\\)" armor-end t)
859 (epa--find-coding-system-for-mime-charset
860 (intern (downcase (match-string 1))))))))
861 (goto-char armor-end)
862 (epa-decrypt-region armor-start armor-end)))))))
865 (defun epa-verify-region (start end)
866 "Verify the current region between START and END.
868 Don't use this command in Lisp programs!
869 Since this function operates on regions, it does some tricks such
870 as coding-system detection and unibyte/multibyte conversion. If
871 you are sure how the data in the region should be treated, you
872 should consider using the string based counterpart
873 `epg-verify-string', or the file based counterpart
874 `epg-verify-file' instead.
878 \(let ((context (epg-make-context 'OpenPGP)))
879 (decode-coding-string
880 (epg-verify-string context (buffer-substring start end))
883 (let ((context (epg-make-context epa-protocol))
885 (epg-context-set-progress-callback context
887 #'epa-progress-callback-function
889 (message "Verifying...")
890 (setq plain (epg-verify-string
892 (epa--encode-coding-string
893 (buffer-substring start end)
894 (or coding-system-for-write
895 (get-text-property start 'epa-coding-system-used)))))
896 (message "Verifying...done")
897 (setq plain (epa--decode-coding-string
899 (or coding-system-for-read
900 (get-text-property start 'epa-coding-system-used)
902 (if (y-or-n-p "Replace the original text? ")
903 (let ((inhibit-read-only t)
905 (delete-region start end)
908 (with-output-to-temp-buffer "*Temp*"
909 (set-buffer standard-output)
912 (if (epg-context-result-for context 'verify)
913 (epa-display-info (epg-verify-result-to-string
914 (epg-context-result-for context 'verify))))))
917 (defun epa-verify-cleartext-in-region (start end)
918 "Verify OpenPGP cleartext signed messages in the current region
919 between START and END.
921 Don't use this command in Lisp programs!
922 See the reason described in the `epa-verify-region' documentation."
926 (narrow-to-region start end)
928 (let (cleartext-start cleartext-end)
929 (while (re-search-forward "-----BEGIN PGP SIGNED MESSAGE-----$"
931 (setq cleartext-start (match-beginning 0))
932 (unless (re-search-forward "^-----BEGIN PGP SIGNATURE-----$"
934 (error "Invalid cleartext signed message"))
935 (setq cleartext-end (re-search-forward
936 "^-----END PGP SIGNATURE-----$"
938 (unless cleartext-end
939 (error "No cleartext tail"))
940 (epa-verify-region cleartext-start cleartext-end))))))
943 (if (fboundp 'select-safe-coding-system)
944 (defalias 'epa--select-safe-coding-system 'select-safe-coding-system)
945 (defun epa--select-safe-coding-system (_from _to)
946 buffer-file-coding-system)))
949 (defun epa-sign-region (start end signers mode)
950 "Sign the current region between START and END by SIGNERS keys selected.
952 Don't use this command in Lisp programs!
953 Since this function operates on regions, it does some tricks such
954 as coding-system detection and unibyte/multibyte conversion. If
955 you are sure how the data should be treated, you should consider
956 using the string based counterpart `epg-sign-string', or the file
957 based counterpart `epg-sign-file' instead.
961 \(let ((context (epg-make-context 'OpenPGP)))
964 (encode-coding-string (buffer-substring start end) 'utf-8)))"
966 (let ((verbose current-prefix-arg))
967 (setq epa-last-coding-system-specified
968 (or coding-system-for-write
969 (epa--select-safe-coding-system
970 (region-beginning) (region-end))))
971 (list (region-beginning) (region-end)
973 (epa-select-keys (epg-make-context epa-protocol)
974 "Select keys for signing.
975 If no one is selected, default secret key is used. "
978 (epa--read-signature-type)
981 (let ((context (epg-make-context epa-protocol))
983 ;;(epg-context-set-armor context epa-armor)
984 (epg-context-set-armor context t)
985 ;;(epg-context-set-textmode context epa-textmode)
986 (epg-context-set-textmode context t)
987 (epg-context-set-signers context signers)
988 (epg-context-set-passphrase-callback context
989 #'epa-passphrase-callback-function)
990 (epg-context-set-progress-callback context
992 #'epa-progress-callback-function
994 (message "Signing...")
995 (setq signature (epg-sign-string context
996 (epa--encode-coding-string
997 (buffer-substring start end)
998 epa-last-coding-system-specified)
1000 (message "Signing...done")
1001 (delete-region start end)
1003 (add-text-properties (point)
1005 (insert (epa--decode-coding-string
1007 (or coding-system-for-read
1008 epa-last-coding-system-specified)))
1010 (list 'epa-coding-system-used
1011 epa-last-coding-system-specified
1018 (if (fboundp 'derived-mode-p)
1019 (defalias 'epa--derived-mode-p 'derived-mode-p)
1020 (defun epa--derived-mode-p (&rest modes)
1021 "Non-nil if the current major mode is derived from one of MODES.
1022 Uses the `derived-mode-parent' property of the symbol to trace backwards."
1023 (let ((parent major-mode))
1024 (while (and (not (memq parent modes))
1025 (setq parent (get parent 'derived-mode-parent))))
1029 (defun epa-encrypt-region (start end recipients sign signers)
1030 "Encrypt the current region between START and END for RECIPIENTS.
1032 Don't use this command in Lisp programs!
1033 Since this function operates on regions, it does some tricks such
1034 as coding-system detection and unibyte/multibyte conversion. If
1035 you are sure how the data should be treated, you should consider
1036 using the string based counterpart `epg-encrypt-string', or the
1037 file based counterpart `epg-encrypt-file' instead.
1041 \(let ((context (epg-make-context 'OpenPGP)))
1044 (encode-coding-string (buffer-substring start end) 'utf-8)
1047 (let ((verbose current-prefix-arg)
1048 (context (epg-make-context epa-protocol))
1050 (setq epa-last-coding-system-specified
1051 (or coding-system-for-write
1052 (epa--select-safe-coding-system
1053 (region-beginning) (region-end))))
1054 (list (region-beginning) (region-end)
1055 (epa-select-keys context
1056 "Select recipients for encryption.
1057 If no one is selected, symmetric encryption will be performed. ")
1058 (setq sign (if verbose (y-or-n-p "Sign? ")))
1060 (epa-select-keys context
1061 "Select keys for signing. ")))))
1063 (let ((context (epg-make-context epa-protocol))
1065 ;;(epg-context-set-armor context epa-armor)
1066 (epg-context-set-armor context t)
1067 ;;(epg-context-set-textmode context epa-textmode)
1068 (epg-context-set-textmode context t)
1070 (epg-context-set-signers context signers))
1071 (epg-context-set-passphrase-callback context
1072 #'epa-passphrase-callback-function)
1073 (epg-context-set-progress-callback context
1075 #'epa-progress-callback-function
1077 (message "Encrypting...")
1078 (setq cipher (epg-encrypt-string context
1079 (epa--encode-coding-string
1080 (buffer-substring start end)
1081 epa-last-coding-system-specified)
1084 (message "Encrypting...done")
1085 (delete-region start end)
1087 (add-text-properties (point)
1091 (list 'epa-coding-system-used
1092 epa-last-coding-system-specified
1099 (defun epa-delete-keys (keys &optional allow-secret)
1100 "Delete selected KEYS."
1102 (let ((keys (epa--marked-keys)))
1104 (error "No keys selected"))
1106 (eq (nth 1 epa-list-keys-arguments) t))))
1107 (let ((context (epg-make-context epa-protocol)))
1108 (message "Deleting...")
1109 (epg-delete-keys context keys allow-secret)
1110 (message "Deleting...done")
1111 (apply #'epa--list-keys epa-list-keys-arguments)))
1114 (defun epa-import-keys (file)
1115 "Import keys from FILE."
1116 (interactive "fFile: ")
1117 (setq file (expand-file-name file))
1118 (let ((context (epg-make-context epa-protocol)))
1119 (message "Importing %s..." (file-name-nondirectory file))
1122 (epg-import-keys-from-file context file)
1123 (message "Importing %s...done" (file-name-nondirectory file)))
1125 (message "Importing %s...failed" (file-name-nondirectory file))))
1126 (if (epg-context-result-for context 'import)
1127 (epa-display-info (epg-import-result-to-string
1128 (epg-context-result-for context 'import))))
1129 (if (eq major-mode 'epa-key-list-mode)
1130 (apply #'epa--list-keys epa-list-keys-arguments))))
1133 (defun epa-import-keys-region (start end)
1134 "Import keys from the region."
1136 (let ((context (epg-make-context epa-protocol)))
1137 (message "Importing...")
1140 (epg-import-keys-from-string context (buffer-substring start end))
1141 (message "Importing...done"))
1143 (message "Importing...failed")))
1144 (if (epg-context-result-for context 'import)
1145 (epa-display-info (epg-import-result-to-string
1146 (epg-context-result-for context 'import))))))
1149 (defun epa-import-armor-in-region (start end)
1150 "Import keys in the OpenPGP armor format in the current region
1151 between START and END."
1155 (narrow-to-region start end)
1157 (let (armor-start armor-end)
1158 (while (re-search-forward
1159 "-----BEGIN \\(PGP \\(PUBLIC\\|PRIVATE\\) KEY BLOCK\\)-----$"
1161 (setq armor-start (match-beginning 0)
1162 armor-end (re-search-forward
1163 (concat "^-----END " (match-string 1) "-----$")
1166 (error "No armor tail"))
1167 (epa-import-keys-region armor-start armor-end))))))
1170 (defun epa-export-keys (keys file)
1171 "Export selected KEYS to FILE."
1173 (let ((keys (epa--marked-keys))
1176 (error "No keys selected"))
1179 (concat (epg-sub-key-id (car (epg-key-sub-key-list (car keys))))
1180 (if epa-armor ".asc" ".gpg"))
1185 (concat "To file (default "
1186 (file-name-nondirectory default-name)
1188 (file-name-directory default-name)
1190 (let ((context (epg-make-context epa-protocol)))
1191 (epg-context-set-armor context epa-armor)
1192 (message "Exporting to %s..." (file-name-nondirectory file))
1193 (epg-export-keys-to-file context keys file)
1194 (message "Exporting to %s...done" (file-name-nondirectory file))))
1197 (defun epa-insert-keys (keys)
1198 "Insert selected KEYS after the point."
1200 (list (epa-select-keys (epg-make-context epa-protocol)
1201 "Select keys to export.
1202 If no one is selected, default public key is exported. ")))
1203 (let ((context (epg-make-context epa-protocol)))
1204 ;;(epg-context-set-armor context epa-armor)
1205 (epg-context-set-armor context t)
1206 (insert (epg-export-keys-to-string context keys))))
1208 ;; (defun epa-sign-keys (keys &optional local)
1209 ;; "Sign selected KEYS.
1210 ;; If a prefix-arg is specified, the signature is marked as non exportable.
1212 ;; Don't use this command in Lisp programs!"
1214 ;; (let ((keys (epa--marked-keys)))
1216 ;; (error "No keys selected"))
1217 ;; (list keys current-prefix-arg)))
1218 ;; (let ((context (epg-make-context epa-protocol)))
1219 ;; (epg-context-set-passphrase-callback context
1220 ;; #'epa-passphrase-callback-function)
1221 ;; (epg-context-set-progress-callback context
1223 ;; #'epa-progress-callback-function
1224 ;; "Signing keys..."))
1225 ;; (message "Signing keys...")
1226 ;; (epg-sign-keys context keys local)
1227 ;; (message "Signing keys...done")))
1228 ;; (make-obsolete 'epa-sign-keys "Do not use.")
1232 ;;; epa.el ends here