1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
// Copyright (c) 2018-2026 [Ribose Inc](https://www.ribose.com).
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions
// are met:
// 1. Redistributions of source code must retain the above copyright
// notice, this list of conditions and the following disclaimer.
// 2. Redistributions in binary form must reproduce the above copyright
// notice, this list of conditions and the following disclaimer in the
// documentation and/or other materials provided with the distribution.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
// ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
//! OpenPGP signature support via `rnp-rs` (librnp FFI).
//!
//! rnp-rs is the idiomatic Rust binding to librnp — the OpenPGP C library
//! from Ribose (the same one Mozilla Thunderbird uses). Requires librnp
//! installed at build time: `brew install rnp` (macOS),
//! `apt install librnp-dev` (Debian), or build from source.
//!
//! ## Current surface
//!
//! Thin facade over rnp-rs's high-level API. The CLI layer wires
//! `enprot sign --alg openpgp` and `enprot verify-sig --alg openpgp`
//! through here.
//!
//! Key management (loading TPK/TSK from disk, keyring lookup) is handled
//! in the caller — pass a `&rnp::Key` in. For loading keys from files,
//! see `rnp::Context::load_keys`.
use crate;
/// Return the underlying librnp version string (e.g. `"RNP 0.17.1+...`").
/// Useful for `enprot --version` output and for confirming at startup
/// that librnp is reachable.
/// Initialize a fresh librnp [`rnp::Context`]. All rnp-rs operations
/// require one; enprot creates one per call (cheap — no I/O) to keep
/// the surface stateless.
/// Inline-sign `msg` with `signing_key`. Returns the OpenPGP-signed
/// message bytes (a "signed plaintext" block containing the message
/// and the signature).
/// Verify an inline-signed OpenPGP message. Returns `Ok(())` if at
/// least one signature is valid; `Err` otherwise.