832 lines
25 KiB
C
832 lines
25 KiB
C
#define _GNU_SOURCE
|
|
|
|
/* NSIGNER_HEADERLESS_DECLS_BEGIN */
|
|
#include <stddef.h>
|
|
#include <stdint.h>
|
|
#include <sys/types.h>
|
|
#include <cJSON.h>
|
|
|
|
/* from secure_mem.h */
|
|
|
|
|
|
/*
|
|
* Secure memory buffer — mlock'd, zeroized on free.
|
|
* Used for mnemonic phrases, private keys, and any sensitive material.
|
|
*/
|
|
typedef struct {
|
|
void *data; /* pointer to locked allocation */
|
|
size_t size; /* usable size in bytes */
|
|
int locked; /* 1 if mlock succeeded */
|
|
} secure_buf_t;
|
|
|
|
/* Allocate a secure buffer of `size` bytes. Returns 0 on success, -1 on failure. */
|
|
int secure_buf_alloc(secure_buf_t *buf, size_t size);
|
|
|
|
/* Zeroize and free a secure buffer. Always succeeds (idempotent). */
|
|
void secure_buf_free(secure_buf_t *buf);
|
|
|
|
/* Zeroize `len` bytes at `ptr` in a way the compiler cannot optimize away. */
|
|
void secure_memzero(void *ptr, size_t len);
|
|
|
|
|
|
/* from mnemonic.h */
|
|
|
|
|
|
/* Maximum mnemonic length: 24 words * 10 chars avg + spaces + null = 256 is safe */
|
|
#define MNEMONIC_MAX_LEN 256
|
|
|
|
/*
|
|
* Mnemonic state — holds the loaded mnemonic in secure memory.
|
|
* Only one mnemonic is active at a time per process.
|
|
*/
|
|
typedef struct {
|
|
secure_buf_t buf; /* secure storage for the mnemonic string */
|
|
int loaded; /* 1 if a mnemonic is currently loaded */
|
|
int word_count; /* 12, 15, 18, 21, or 24 */
|
|
} mnemonic_state_t;
|
|
|
|
/* Initialize mnemonic state (must be called before use). */
|
|
void mnemonic_init(mnemonic_state_t *state);
|
|
|
|
/* Load a mnemonic string into secure memory. Validates word count (12/15/18/21/24).
|
|
* Returns 0 on success, -1 on invalid input, -2 on memory error. */
|
|
int mnemonic_load(mnemonic_state_t *state, const char *phrase);
|
|
|
|
/* Zeroize and unload the mnemonic. Idempotent. */
|
|
void mnemonic_unload(mnemonic_state_t *state);
|
|
|
|
/* Check if a mnemonic is currently loaded. */
|
|
int mnemonic_is_loaded(const mnemonic_state_t *state);
|
|
|
|
/* Get the mnemonic string (only valid while loaded). Returns NULL if not loaded. */
|
|
const char *mnemonic_get_phrase(const mnemonic_state_t *state);
|
|
|
|
/* Generate a new BIP-39 mnemonic phrase (12/15/18/21/24 words) into out.
|
|
* Returns 0 on success, -1 on invalid arguments or generation failure. */
|
|
int mnemonic_generate(int word_count, char *out, size_t out_len);
|
|
|
|
|
|
/* from role_table.h */
|
|
|
|
|
|
/* Maximum limits */
|
|
#define ROLE_NAME_MAX 64
|
|
#define ROLE_PATH_MAX 128
|
|
#define ROLE_PURPOSE_MAX 32
|
|
#define ROLE_CURVE_MAX 16
|
|
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
|
|
#define ROLE_TABLE_MAX_ENTRIES 256
|
|
|
|
/* Purpose enum for fast comparison (string form kept for config/display) */
|
|
typedef enum {
|
|
PURPOSE_NOSTR = 0,
|
|
PURPOSE_BITCOIN,
|
|
PURPOSE_SSH,
|
|
PURPOSE_AGE,
|
|
PURPOSE_FIPS,
|
|
PURPOSE_UNKNOWN
|
|
} role_purpose_t;
|
|
|
|
/* Curve enum */
|
|
typedef enum {
|
|
CURVE_SECP256K1 = 0,
|
|
CURVE_ED25519,
|
|
CURVE_X25519,
|
|
CURVE_UNKNOWN
|
|
} role_curve_t;
|
|
|
|
/* Selector type — how this role's key is addressed */
|
|
typedef enum {
|
|
SELECTOR_NOSTR_INDEX, /* uses nostr_index shorthand */
|
|
SELECTOR_ROLE_PATH /* uses explicit full path */
|
|
} role_selector_type_t;
|
|
|
|
/* A single role entry */
|
|
typedef struct {
|
|
char name[ROLE_NAME_MAX];
|
|
char purpose_str[ROLE_PURPOSE_MAX];
|
|
char curve_str[ROLE_CURVE_MAX];
|
|
role_purpose_t purpose;
|
|
role_curve_t curve;
|
|
role_selector_type_t selector_type;
|
|
int nostr_index; /* valid if selector_type == SELECTOR_NOSTR_INDEX */
|
|
char role_path[ROLE_PATH_MAX]; /* valid if selector_type == SELECTOR_ROLE_PATH */
|
|
char pubkey_hex[ROLE_PUBKEY_HEX_MAX]; /* filled after derivation, empty until then */
|
|
int derived; /* 1 if pubkey_hex has been populated */
|
|
} role_entry_t;
|
|
|
|
/* The role table */
|
|
typedef struct {
|
|
role_entry_t entries[ROLE_TABLE_MAX_ENTRIES];
|
|
int count;
|
|
} role_table_t;
|
|
|
|
/* Initialize an empty role table */
|
|
void role_table_init(role_table_t *table);
|
|
|
|
/* Add a role entry. Returns 0 on success, -1 if table full, -2 if name duplicate. */
|
|
int role_table_add(role_table_t *table, const role_entry_t *entry);
|
|
|
|
/* Find a role by name. Returns pointer to entry or NULL. */
|
|
role_entry_t *role_table_find_by_name(role_table_t *table, const char *name);
|
|
|
|
/* Find a role by nostr_index. Returns pointer or NULL. */
|
|
role_entry_t *role_table_find_by_nostr_index(role_table_t *table, int index);
|
|
|
|
/* Find a role by role_path. Returns pointer or NULL. */
|
|
role_entry_t *role_table_find_by_path(role_table_t *table, const char *path);
|
|
|
|
/* Get the default role (named "main"). Returns pointer or NULL if no "main" role. */
|
|
role_entry_t *role_table_get_default(role_table_t *table);
|
|
|
|
/* Parse purpose string to enum */
|
|
role_purpose_t role_purpose_from_str(const char *s);
|
|
|
|
/* Parse curve string to enum */
|
|
role_curve_t role_curve_from_str(const char *s);
|
|
|
|
/* Purpose enum to string */
|
|
const char *role_purpose_to_str(role_purpose_t p);
|
|
|
|
/* Curve enum to string */
|
|
const char *role_curve_to_str(role_curve_t c);
|
|
|
|
|
|
/* from selector.h */
|
|
|
|
|
|
/* Error codes for selector resolution */
|
|
#define SELECTOR_OK 0
|
|
#define SELECTOR_ERR_AMBIGUOUS -1 /* multiple selectors specified */
|
|
#define SELECTOR_ERR_NOT_FOUND -2 /* no matching role in table */
|
|
#define SELECTOR_ERR_NO_DEFAULT -3 /* no selector given and no "main" role exists */
|
|
|
|
/* Parsed selector from a request's options object */
|
|
typedef struct {
|
|
int has_role; /* 1 if "role" field was present */
|
|
char role_name[ROLE_NAME_MAX];
|
|
|
|
int has_nostr_index; /* 1 if "nostr_index" field was present */
|
|
int nostr_index;
|
|
|
|
int has_role_path; /* 1 if "role_path" field was present */
|
|
char role_path[ROLE_PATH_MAX];
|
|
} selector_request_t;
|
|
|
|
/* Initialize a selector request (all fields zeroed/unset) */
|
|
void selector_request_init(selector_request_t *req);
|
|
|
|
/*
|
|
* Resolve a selector request against the role table.
|
|
* On success (returns SELECTOR_OK), *out points to the matched role_entry_t.
|
|
* On failure, returns one of the SELECTOR_ERR_* codes and *out is NULL.
|
|
*/
|
|
int selector_resolve(const selector_request_t *req, role_table_t *table, role_entry_t **out);
|
|
|
|
/*
|
|
* Return a human-readable error string for a selector error code.
|
|
*/
|
|
const char *selector_strerror(int err);
|
|
|
|
|
|
/* from enforcement.h */
|
|
|
|
|
|
/* Error codes */
|
|
#define ENFORCE_OK 0
|
|
#define ENFORCE_ERR_PURPOSE -1 /* purpose mismatch */
|
|
#define ENFORCE_ERR_CURVE -2 /* curve mismatch */
|
|
#define ENFORCE_ERR_UNKNOWN_VERB -3 /* verb not recognized */
|
|
|
|
/* Known verbs */
|
|
#define VERB_SIGN_EVENT "sign_event"
|
|
#define VERB_GET_PUBLIC_KEY "get_public_key"
|
|
#define VERB_NIP44_ENCRYPT "nip44_encrypt"
|
|
#define VERB_NIP44_DECRYPT "nip44_decrypt"
|
|
#define VERB_NIP04_ENCRYPT "nip04_encrypt"
|
|
#define VERB_NIP04_DECRYPT "nip04_decrypt"
|
|
|
|
/*
|
|
* Check whether `verb` is allowed to execute against `role`.
|
|
* Returns ENFORCE_OK if allowed, or an ENFORCE_ERR_* code.
|
|
*
|
|
* The enforcement rules are:
|
|
* - All nostr verbs (sign_event, get_public_key, nip44_*, nip04_*) require:
|
|
* purpose == PURPOSE_NOSTR and curve == CURVE_SECP256K1
|
|
* - Unknown verbs return ENFORCE_ERR_UNKNOWN_VERB (fail-closed).
|
|
*/
|
|
int enforce_verb_role(const char *verb, const role_entry_t *role);
|
|
|
|
/*
|
|
* Return a human-readable error string for an enforcement error code.
|
|
*/
|
|
const char *enforce_strerror(int err);
|
|
|
|
|
|
/* from policy.h */
|
|
|
|
|
|
#define POLICY_MAX_ENTRIES 32
|
|
#define POLICY_MAX_VERBS 16
|
|
#define POLICY_MAX_ROLES 16
|
|
#define POLICY_MAX_PURPOSES 8
|
|
#define POLICY_VERB_MAX_LEN 32
|
|
#define POLICY_CALLER_MAX_LEN 160
|
|
|
|
/* Prompt behavior */
|
|
typedef enum {
|
|
PROMPT_NEVER = 0,
|
|
PROMPT_FIRST_PER_BOOT,
|
|
PROMPT_EVERY_REQUEST,
|
|
PROMPT_DENY
|
|
} prompt_mode_t;
|
|
|
|
typedef enum {
|
|
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
|
|
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
|
|
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
|
|
} policy_source_t;
|
|
|
|
/* A single policy entry */
|
|
typedef struct {
|
|
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
|
|
char verbs[POLICY_MAX_VERBS][POLICY_VERB_MAX_LEN];
|
|
int verb_count;
|
|
char roles[POLICY_MAX_ROLES][ROLE_NAME_MAX];
|
|
int role_count;
|
|
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
|
|
int purpose_count;
|
|
prompt_mode_t prompt;
|
|
policy_source_t source;
|
|
} policy_entry_t;
|
|
|
|
/* Policy table */
|
|
typedef struct {
|
|
policy_entry_t entries[POLICY_MAX_ENTRIES];
|
|
int count;
|
|
} policy_table_t;
|
|
|
|
/* Policy check result */
|
|
#define POLICY_ALLOW 0
|
|
#define POLICY_DENY -1
|
|
#define POLICY_PROMPT -2 /* would need user confirmation */
|
|
#define POLICY_NO_MATCH -3 /* no policy entry matched (fail-closed = deny) */
|
|
|
|
/* Initialize policy table */
|
|
void policy_table_init(policy_table_t *table);
|
|
|
|
/* Initialize default policy: allow same-uid, deny others */
|
|
void policy_init_default(policy_table_t *table, uid_t owner_uid);
|
|
|
|
/* Add a policy entry. Returns 0 on success, -1 if full. */
|
|
int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
|
|
|
|
/*
|
|
* Check whether caller_id is allowed to invoke `verb` on `role_name` with given `purpose`.
|
|
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
|
|
*/
|
|
int policy_check(const policy_table_t *table, const char *caller_id,
|
|
const char *verb, const char *role_name, const char *purpose,
|
|
policy_source_t *out_source);
|
|
|
|
/* Parse prompt mode from string */
|
|
prompt_mode_t prompt_mode_from_str(const char *s);
|
|
|
|
/* Prompt mode to string */
|
|
const char *prompt_mode_to_str(prompt_mode_t m);
|
|
|
|
|
|
/* from crypto.h */
|
|
|
|
|
|
/* Per-role derived key material (stored in secure memory) */
|
|
typedef struct {
|
|
secure_buf_t private_key; /* 32 bytes, mlock'd */
|
|
unsigned char public_key[32];
|
|
char pubkey_hex[65]; /* 64 hex chars + null */
|
|
char npub[128]; /* bech32 npub */
|
|
int valid;
|
|
} derived_key_t;
|
|
|
|
/* Key store — holds derived keys for all roles */
|
|
typedef struct {
|
|
derived_key_t keys[ROLE_TABLE_MAX_ENTRIES];
|
|
int count;
|
|
} key_store_t;
|
|
|
|
/* Derive keys for all roles in the table using the loaded mnemonic.
|
|
* Populates key_store and sets role->pubkey_hex and role->derived for each role.
|
|
* Only derives for roles with purpose=nostr and curve=secp256k1 (for now).
|
|
* Returns number of keys derived, or -1 on error. */
|
|
int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic);
|
|
|
|
/* Get the derived private key for a role (by table index). Returns NULL if not derived. */
|
|
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index);
|
|
|
|
/* Get the derived public key hex for a role. Returns NULL if not derived. */
|
|
const char *crypto_get_pubkey_hex(const key_store_t *store, int role_index);
|
|
|
|
/* Sign a Nostr event. event_json is the unsigned event JSON string.
|
|
* Returns a newly-allocated string containing the signed event JSON, or NULL on error.
|
|
* Caller must free() the returned string. */
|
|
char *crypto_sign_event(const key_store_t *store, int role_index, const char *event_json);
|
|
|
|
/* Zeroize all derived keys in the store. */
|
|
void crypto_wipe(key_store_t *store);
|
|
|
|
|
|
/* from dispatcher.h */
|
|
|
|
|
|
/* Dispatcher context — holds references to shared state */
|
|
typedef struct {
|
|
role_table_t *role_table;
|
|
mnemonic_state_t *mnemonic;
|
|
key_store_t *key_store;
|
|
} dispatcher_ctx_t;
|
|
|
|
/* Initialize dispatcher context */
|
|
void dispatcher_init(dispatcher_ctx_t *ctx, role_table_t *table, mnemonic_state_t *mnemonic, key_store_t *key_store);
|
|
|
|
/*
|
|
* Process a JSON-RPC request string and produce a JSON-RPC response string.
|
|
*
|
|
* The caller owns the returned string and must free() it.
|
|
* Returns NULL only on catastrophic allocation failure.
|
|
*
|
|
* Response format on success:
|
|
* { "id": "...", "result": "..." }
|
|
*
|
|
* Response format on error:
|
|
* { "id": "...", "error": { "code": <int>, "message": "..." } }
|
|
*
|
|
* Error codes:
|
|
* -32700 Parse error (invalid JSON)
|
|
* -32600 Invalid request (missing id/method/params)
|
|
* -32601 Method not found (unknown verb after enforcement)
|
|
* -32602 Invalid params
|
|
* 1001 ambiguous_role_selector
|
|
* 1002 role_not_found
|
|
* 1003 no_default_role
|
|
* 1004 purpose_mismatch
|
|
* 1005 curve_mismatch
|
|
* 1006 mnemonic_not_loaded
|
|
*/
|
|
char *dispatcher_handle_request(dispatcher_ctx_t *ctx, const char *json_request);
|
|
|
|
|
|
/* from server.h */
|
|
|
|
|
|
#define SERVER_SOCKET_NAME_MAX 108
|
|
#define SERVER_MAX_MSG_SIZE 65536
|
|
|
|
/* Caller identity */
|
|
typedef struct {
|
|
uid_t uid;
|
|
gid_t gid;
|
|
pid_t pid;
|
|
char caller_id[POLICY_CALLER_MAX_LEN]; /* "uid:<n>" */
|
|
} caller_identity_t;
|
|
|
|
/* Server context */
|
|
typedef struct {
|
|
char socket_name[SERVER_SOCKET_NAME_MAX]; /* abstract namespace name (without \0 prefix) */
|
|
char last_error[256];
|
|
int listen_fd;
|
|
int running;
|
|
dispatcher_ctx_t *dispatcher;
|
|
policy_table_t *policy;
|
|
int socket_name_explicit;
|
|
} server_ctx_t;
|
|
|
|
/* Initialize server context. socket_name is the abstract namespace name (e.g. "nsigner").
|
|
* socket_name_explicit should be non-zero when provided via --socket-name override. */
|
|
void server_init(server_ctx_t *ctx, const char *socket_name, int socket_name_explicit,
|
|
dispatcher_ctx_t *dispatcher, policy_table_t *policy);
|
|
|
|
/* Start listening. Returns 0 on success, -1 on error. */
|
|
int server_start(server_ctx_t *ctx);
|
|
|
|
/* Get human-readable description of last server error. */
|
|
const char *server_last_error(const server_ctx_t *ctx);
|
|
|
|
/* Handle one pending connection (non-blocking). Returns 1 if handled, 0 if nothing pending, -1 on error.
|
|
* activity_cb is called with a description string for the TUI activity log. */
|
|
typedef void (*server_activity_cb)(const char *message, void *user_data);
|
|
int server_handle_one(server_ctx_t *ctx, server_activity_cb cb, void *cb_data);
|
|
|
|
/* Stop server and close socket */
|
|
void server_stop(server_ctx_t *ctx);
|
|
|
|
/* Extract caller identity from connected fd */
|
|
int server_get_caller(int fd, caller_identity_t *out);
|
|
|
|
|
|
/* from socket_name.h */
|
|
|
|
|
|
/*
|
|
* Generate random socket name in format: nsigner_<word1>_<word2>
|
|
* Returns 0 on success, -1 on error.
|
|
*/
|
|
int socket_name_random(char *out, size_t out_len);
|
|
|
|
|
|
/* from main.h */
|
|
/*
|
|
* nsigner main header - version information
|
|
*
|
|
* Version macros are auto-updated by increment_and_push.sh.
|
|
*/
|
|
|
|
|
|
/* Version information (auto-updated by build/version tooling) */
|
|
#define NSIGNER_VERSION_MAJOR 0
|
|
#define NSIGNER_VERSION_MINOR 0
|
|
#define NSIGNER_VERSION_PATCH 2
|
|
#define NSIGNER_VERSION "v0.0.2"
|
|
|
|
|
|
/* NSIGNER_HEADERLESS_DECLS_END */
|
|
|
|
#include <arpa/inet.h>
|
|
#include <errno.h>
|
|
#include <signal.h>
|
|
#include <fcntl.h>
|
|
#include <stdio.h>
|
|
#include <stdlib.h>
|
|
#include <string.h>
|
|
#include <sys/socket.h>
|
|
#include <sys/types.h>
|
|
#include <sys/un.h>
|
|
#include <sys/wait.h>
|
|
#include <time.h>
|
|
#include <unistd.h>
|
|
|
|
#include "nsigner_client.h"
|
|
|
|
#define SOCKET_NAME_A "nsigner_test_run_a"
|
|
#define SOCKET_NAME_B "nsigner_test_run_b"
|
|
#define MAX_MSG_SIZE 65536
|
|
|
|
static int g_failures = 0;
|
|
|
|
static void check_condition(const char *name, int condition) {
|
|
if (condition) {
|
|
printf("PASS: %s\n", name);
|
|
} else {
|
|
printf("FAIL: %s\n", name);
|
|
g_failures++;
|
|
}
|
|
}
|
|
|
|
static int sleep_ms(int ms) {
|
|
struct timespec ts;
|
|
ts.tv_sec = ms / 1000;
|
|
ts.tv_nsec = (long)(ms % 1000) * 1000000L;
|
|
return nanosleep(&ts, NULL);
|
|
}
|
|
|
|
static int read_full(int fd, void *buf, size_t len) {
|
|
unsigned char *p = (unsigned char *)buf;
|
|
size_t off = 0;
|
|
|
|
while (off < len) {
|
|
ssize_t n = read(fd, p + off, len - off);
|
|
if (n == 0) {
|
|
return -1;
|
|
}
|
|
if (n < 0) {
|
|
if (errno == EINTR) {
|
|
continue;
|
|
}
|
|
return -1;
|
|
}
|
|
off += (size_t)n;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int write_full(int fd, const void *buf, size_t len) {
|
|
const unsigned char *p = (const unsigned char *)buf;
|
|
size_t off = 0;
|
|
|
|
while (off < len) {
|
|
ssize_t n = write(fd, p + off, len - off);
|
|
if (n < 0) {
|
|
if (errno == EINTR) {
|
|
continue;
|
|
}
|
|
return -1;
|
|
}
|
|
off += (size_t)n;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int connect_socket_retry(const char *name, int timeout_ms) {
|
|
int elapsed = 0;
|
|
|
|
while (elapsed < timeout_ms) {
|
|
int fd;
|
|
struct sockaddr_un addr;
|
|
socklen_t addr_len;
|
|
|
|
fd = socket(AF_UNIX, SOCK_STREAM, 0);
|
|
if (fd < 0) {
|
|
return -1;
|
|
}
|
|
|
|
memset(&addr, 0, sizeof(addr));
|
|
addr.sun_family = AF_UNIX;
|
|
addr.sun_path[0] = '\0';
|
|
strncpy(&addr.sun_path[1], name, sizeof(addr.sun_path) - 2);
|
|
addr.sun_path[sizeof(addr.sun_path) - 1] = '\0';
|
|
addr_len = (socklen_t)(sizeof(sa_family_t) + 1 + strlen(name));
|
|
|
|
if (connect(fd, (struct sockaddr *)&addr, addr_len) == 0) {
|
|
return fd;
|
|
}
|
|
|
|
close(fd);
|
|
sleep_ms(100);
|
|
elapsed += 100;
|
|
}
|
|
|
|
return -1;
|
|
}
|
|
|
|
static int send_framed(int fd, const char *payload) {
|
|
uint32_t len = (uint32_t)strlen(payload);
|
|
uint32_t be_len = htonl(len);
|
|
|
|
if (write_full(fd, &be_len, sizeof(be_len)) != 0) {
|
|
return -1;
|
|
}
|
|
if (write_full(fd, payload, len) != 0) {
|
|
return -1;
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
static int recv_framed(int fd, char **out_payload) {
|
|
uint32_t be_len;
|
|
uint32_t len;
|
|
char *payload;
|
|
|
|
if (out_payload == NULL) {
|
|
return -1;
|
|
}
|
|
|
|
*out_payload = NULL;
|
|
|
|
if (read_full(fd, &be_len, sizeof(be_len)) != 0) {
|
|
return -1;
|
|
}
|
|
|
|
len = ntohl(be_len);
|
|
if (len == 0 || len > MAX_MSG_SIZE) {
|
|
return -1;
|
|
}
|
|
|
|
payload = (char *)malloc((size_t)len + 1U);
|
|
if (payload == NULL) {
|
|
return -1;
|
|
}
|
|
|
|
if (read_full(fd, payload, len) != 0) {
|
|
free(payload);
|
|
return -1;
|
|
}
|
|
|
|
payload[len] = '\0';
|
|
*out_payload = payload;
|
|
return 0;
|
|
}
|
|
|
|
static int request_roundtrip_to(const char *socket_name, const char *req, char **resp) {
|
|
int fd = connect_socket_retry(socket_name, 5000);
|
|
int rc;
|
|
|
|
if (fd < 0) {
|
|
return -1;
|
|
}
|
|
|
|
rc = send_framed(fd, req);
|
|
if (rc == 0) {
|
|
rc = recv_framed(fd, resp);
|
|
}
|
|
|
|
close(fd);
|
|
return rc;
|
|
}
|
|
|
|
int main(void) {
|
|
int stdin_pipe[2];
|
|
pid_t child;
|
|
pid_t child2;
|
|
const char *mnemonic = "\nabandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon about\n";
|
|
char *resp = NULL;
|
|
int status;
|
|
|
|
(void)signal(SIGPIPE, SIG_IGN);
|
|
|
|
if (pipe(stdin_pipe) != 0) {
|
|
perror("pipe");
|
|
return 1;
|
|
}
|
|
|
|
child = fork();
|
|
if (child < 0) {
|
|
perror("fork");
|
|
close(stdin_pipe[0]);
|
|
close(stdin_pipe[1]);
|
|
return 1;
|
|
}
|
|
|
|
if (child == 0) {
|
|
int null_fd = open("/dev/null", O_WRONLY);
|
|
if (null_fd >= 0) {
|
|
dup2(null_fd, STDOUT_FILENO);
|
|
dup2(null_fd, STDERR_FILENO);
|
|
close(null_fd);
|
|
}
|
|
|
|
(void)setenv("NSIGNER_TEST_FORCE_PROMPT", "1", 1);
|
|
(void)setenv("NSIGNER_TEST_NONINTERACTIVE_PROMPT", "allow", 1);
|
|
|
|
dup2(stdin_pipe[0], STDIN_FILENO);
|
|
close(stdin_pipe[0]);
|
|
close(stdin_pipe[1]);
|
|
|
|
execl("./build/nsigner", "./build/nsigner", "--socket-name", SOCKET_NAME_A, (char *)NULL);
|
|
_exit(127);
|
|
}
|
|
|
|
close(stdin_pipe[0]);
|
|
if (write_full(stdin_pipe[1], mnemonic, strlen(mnemonic)) == 0) {
|
|
|
|
check_condition("feed mnemonic to child stdin", 1);
|
|
} else {
|
|
check_condition("feed mnemonic to child stdin", 0);
|
|
}
|
|
close(stdin_pipe[1]);
|
|
|
|
{
|
|
int stdin_pipe2[2];
|
|
if (pipe(stdin_pipe2) != 0) {
|
|
perror("pipe2");
|
|
return 1;
|
|
}
|
|
child2 = fork();
|
|
if (child2 < 0) {
|
|
perror("fork2");
|
|
return 1;
|
|
}
|
|
if (child2 == 0) {
|
|
int null_fd = open("/dev/null", O_WRONLY);
|
|
if (null_fd >= 0) {
|
|
dup2(null_fd, STDOUT_FILENO);
|
|
dup2(null_fd, STDERR_FILENO);
|
|
close(null_fd);
|
|
}
|
|
(void)setenv("NSIGNER_TEST_FORCE_PROMPT", "1", 1);
|
|
(void)setenv("NSIGNER_TEST_HOTKEYS", "a", 1);
|
|
dup2(stdin_pipe2[0], STDIN_FILENO);
|
|
close(stdin_pipe2[0]);
|
|
close(stdin_pipe2[1]);
|
|
execl("./build/nsigner", "./build/nsigner", "--socket-name", SOCKET_NAME_B, (char *)NULL);
|
|
_exit(127);
|
|
}
|
|
close(stdin_pipe2[0]);
|
|
(void)write_full(stdin_pipe2[1], mnemonic, strlen(mnemonic));
|
|
close(stdin_pipe2[1]);
|
|
}
|
|
|
|
sleep_ms(1000);
|
|
|
|
{
|
|
nsigner_client_t client;
|
|
nsigner_client_init(&client);
|
|
if (nsigner_client_connect_unix(&client, SOCKET_NAME_A, 5000) == 0) {
|
|
if (nsigner_client_get_public_key(&client, "1", "", &resp) == 0) {
|
|
check_condition("get_public_key response id", strstr(resp, "\"id\":\"1\"") != NULL);
|
|
check_condition("get_public_key has result", strstr(resp, "\"result\":") != NULL);
|
|
} else {
|
|
check_condition("get_public_key request roundtrip", 0);
|
|
}
|
|
free(resp);
|
|
resp = NULL;
|
|
nsigner_client_close(&client);
|
|
} else {
|
|
check_condition("connect signer socket for client library", 0);
|
|
}
|
|
|
|
nsigner_client_init(&client);
|
|
if (nsigner_client_connect_unix(&client, SOCKET_NAME_A, 5000) == 0) {
|
|
if (nsigner_client_sign_event(&client,
|
|
"2",
|
|
"{\"kind\":1,\"content\":\"hello\",\"tags\":[],\"created_at\":1700000000}",
|
|
"main",
|
|
&resp) == 0) {
|
|
check_condition("sign_event response id", strstr(resp, "\"id\":\"2\"") != NULL);
|
|
check_condition("sign_event has result", strstr(resp, "\"result\":") != NULL);
|
|
} else {
|
|
check_condition("sign_event request roundtrip", 0);
|
|
}
|
|
free(resp);
|
|
resp = NULL;
|
|
} else {
|
|
check_condition("connect signer socket for sign_event", 0);
|
|
}
|
|
nsigner_client_close(&client);
|
|
}
|
|
|
|
|
|
{
|
|
char *resp_a = NULL;
|
|
char pub_a[65] = {0};
|
|
char cipher[2048] = {0};
|
|
char req[4096];
|
|
const char *p;
|
|
|
|
if (request_roundtrip_to(SOCKET_NAME_A, "{\"id\":\"3\",\"method\":\"get_public_key\",\"params\":[\"\"]}", &resp_a) == 0) {
|
|
p = strstr(resp_a, "\"result\":\"");
|
|
if (p) { p += 10; strncpy(pub_a, p, 64); pub_a[64]='\0'; }
|
|
check_condition("single-instance public key request", pub_a[0] != '\0');
|
|
|
|
snprintf(req, sizeof(req), "{\"id\":\"5\",\"method\":\"nip04_encrypt\",\"params\":[\"%s\",\"hello_nip04\"]}", pub_a);
|
|
free(resp_a); resp_a = NULL;
|
|
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
|
|
p = strstr(resp_a, "\"result\":\"");
|
|
if (p) {
|
|
size_t i = 0;
|
|
p += 10;
|
|
while (p[i] && p[i] != '\"' && i < sizeof(cipher)-1) { cipher[i]=p[i]; i++; }
|
|
cipher[i]='\0';
|
|
}
|
|
snprintf(req, sizeof(req), "{\"id\":\"6\",\"method\":\"nip04_decrypt\",\"params\":[\"%s\",\"%s\"]}", pub_a, cipher);
|
|
free(resp_a); resp_a = NULL;
|
|
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
|
|
check_condition("nip04 round-trip plaintext recovered", strstr(resp_a, "hello_nip04") != NULL);
|
|
} else {
|
|
check_condition("nip04 decrypt request roundtrip", 0);
|
|
}
|
|
} else {
|
|
check_condition("nip04 encrypt request roundtrip", 0);
|
|
}
|
|
|
|
memset(cipher, 0, sizeof(cipher));
|
|
snprintf(req, sizeof(req), "{\"id\":\"7\",\"method\":\"nip44_encrypt\",\"params\":[\"%s\",\"hello_nip44\"]}", pub_a);
|
|
free(resp_a); resp_a = NULL;
|
|
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
|
|
p = strstr(resp_a, "\"result\":\"");
|
|
if (p) {
|
|
size_t i = 0;
|
|
p += 10;
|
|
while (p[i] && p[i] != '\"' && i < sizeof(cipher)-1) { cipher[i]=p[i]; i++; }
|
|
cipher[i]='\0';
|
|
}
|
|
snprintf(req, sizeof(req), "{\"id\":\"8\",\"method\":\"nip44_decrypt\",\"params\":[\"%s\",\"%s\"]}", pub_a, cipher);
|
|
free(resp_a); resp_a = NULL;
|
|
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
|
|
check_condition("nip44 round-trip plaintext recovered", strstr(resp_a, "hello_nip44") != NULL);
|
|
} else {
|
|
check_condition("nip44 decrypt request roundtrip", 0);
|
|
}
|
|
} else {
|
|
check_condition("nip44 encrypt request roundtrip", 0);
|
|
}
|
|
} else {
|
|
check_condition("single-instance public key request", 0);
|
|
}
|
|
free(resp_a);
|
|
}
|
|
|
|
if (kill(child, SIGTERM) == 0) {
|
|
check_condition("send SIGTERM to child", 1);
|
|
} else {
|
|
check_condition("send SIGTERM to child", 0);
|
|
}
|
|
|
|
if (waitpid(child, &status, 0) > 0) {
|
|
check_condition("child exited", WIFEXITED(status) || WIFSIGNALED(status));
|
|
} else {
|
|
check_condition("child exited", 0);
|
|
}
|
|
|
|
(void)kill(child2, SIGTERM);
|
|
(void)waitpid(child2, &status, 0);
|
|
|
|
if (g_failures == 0) {
|
|
printf("ALL TESTS PASSED\n");
|
|
return 0;
|
|
}
|
|
|
|
printf("TESTS FAILED: %d\n", g_failures);
|
|
return 1;
|
|
}
|