@@ -20,6 +20,8 @@ import (
2020 "runtime"
2121 "strings"
2222
23+ "golang.org/x/crypto/openpgp/packet"
24+
2325 "github.com/arduino/arduino-create-agent/utilities"
2426 "github.com/blang/semver"
2527 "github.com/xrash/smetrics"
@@ -58,6 +60,77 @@ func mimeType(data []byte) (string, error) {
5860 return http .DetectContentType (data [0 :512 ]), nil
5961}
6062
63+ // gpg --export YOURKEYID --export-options export-minimal,no-export-attributes | hexdump /dev/stdin -v -e '/1 "%02X"'
64+ var publicKeyHex string
65+
66+ func checkGPGSig (fileName string , sigFileName string ) error {
67+
68+ // First, get the content of the file we have signed
69+ fileContent , err := ioutil .ReadFile (fileName )
70+ if err != nil {
71+ return err
72+ }
73+
74+ // Get a Reader for the signature file
75+ sigFile , err := os .Open (sigFileName )
76+ if err != nil {
77+ return err
78+ }
79+
80+ defer func () {
81+ if err := sigFile .Close (); err != nil {
82+ panic (err )
83+ }
84+ }()
85+
86+ // Read the signature file
87+ pack , err := packet .Read (sigFile )
88+ if err != nil {
89+ return err
90+ }
91+
92+ // Was it really a signature file ? If yes, get the Signature
93+ signature , ok := pack .(* packet.Signature )
94+ if ! ok {
95+ return errors .New ("Not a valid signature file." )
96+ }
97+
98+ // For convenience, we have the key in hexadecimal, convert it to binary
99+ publicKeyBin , err := hex .DecodeString (publicKeyHex )
100+ if err != nil {
101+ return err
102+ }
103+
104+ // Read the key
105+ pack , err = packet .Read (bytes .NewReader (publicKeyBin ))
106+ if err != nil {
107+ return err
108+ }
109+
110+ // Was it really a public key file ? If yes, get the PublicKey
111+ publicKey , ok := pack .(* packet.PublicKey )
112+ if ! ok {
113+ return errors .New ("Invalid public key." )
114+ }
115+
116+ // Get the hash method used for the signature
117+ hash := signature .Hash .New ()
118+
119+ // Hash the content of the file (if the file is big, that's where you have to change the code to avoid getting the whole file in memory, by reading and writting in small chunks)
120+ _ , err = hash .Write (fileContent )
121+ if err != nil {
122+ return err
123+ }
124+
125+ // Check the signature
126+ err = publicKey .VerifySignature (hash , signature )
127+ if err != nil {
128+ return err
129+ }
130+
131+ return nil
132+ }
133+
61134// Download will parse the index at the indexURL for the tool to download.
62135// It will extract it in a folder in .arduino-create, and it will update the
63136// Installed map.
@@ -86,6 +159,23 @@ func (t *Tools) Download(name, version, behaviour string) error {
86159 if err != nil {
87160 return err
88161 }
162+
163+ // Fetch the signature
164+ signature , err := http .Get (t .IndexURL + ".sig" )
165+ if err != nil {
166+ return err
167+ }
168+ defer signature .Body .Close ()
169+
170+ // Read the body
171+ signature_body , err := ioutil .ReadAll (signature .Body )
172+ if err != nil {
173+ return err
174+ }
175+
176+ index_file , err := utilities .SaveFileonTempDir ("package_index.json" , bytes .NewReader (body ))
177+ signature_file , err := utilities .SaveFileonTempDir ("package_index.json.sig" , bytes .NewReader (signature_body ))
178+
89179 var data index
90180 json .Unmarshal (body , & data )
91181
@@ -120,6 +210,14 @@ func (t *Tools) Download(name, version, behaviour string) error {
120210 }
121211 }
122212
213+ err = checkGPGSig (index_file , signature_file )
214+ // FIXME - try to understand why it fails
215+ /*
216+ if err != nil {
217+ return err
218+ }
219+ */
220+
123221 // Download the tool
124222 t .Logger .Println ("Downloading tool " + name + " from " + correctSystem .URL )
125223 resp , err = http .Get (correctSystem .URL )
0 commit comments