This library provides an implementation of the rpm's pgp interface using Sequoia.
This library's crypto policy can be customized. It finds the configuration file by checking the following in turn:
- the
RPM_SEQUOIA_CRYPTO_POLICYenvironment variable, /etc/crypto-policies/back-ends/rpm-sequoia.config,- the
SEQUOIA_CRYPTO_POLICYenvironment variable, and finally, /etc/crypto-policies/back-ends/sequoia.config.
Only the first configuration file that is present is used. If an environment is set to the empty string, then an empty configuration file is used. That is, the default policy is used.
Thus, if RPM_SEQUOIA_CRYPTO_POLICY is not set, and
/etc/crypto-policies/back-ends/rpm-sequoia.config, the latter will
be used. In this case, SEQUOIA_CRYPTO_POLICY and
/etc/crypto-policies/back-ends/sequoia.config will be completely
ignored.
Refer to the Fedora Crypto Policy project for information about the crypto policy.
To build, you need rustc (version 1.73 or later), cargo, and nettle-devel, which is the cryptographic library that Sequoia uses by default.
Here's how to build rpm-sequoia and a version of rpm that uses it (before 4.18):
$ sudo dnf install cargo rustc clang pkg-config nettle-devel
$ mkdir /tmp/rpm
$ cd /tmp/rpm
$ git clone git@github.com:rpm-software-management/rpm-sequoia.git
Cloning into 'rpm-sequoia'...
done.
$ cd rpm-sequoia
$ PREFIX=/usr LIBDIR="\${prefix}/lib64" \
cargo build --release && cargo test --release
Updating crates.io index
...
test result: ok. ...
$ cd /tmp/rpm
$ git clone git@github.com:rpm-software-management/rpm.git
Cloning into 'rpm'...
done.
$ cd rpm
$ git checkout rpm-4.18.1-release
Switched to a new branch 'rpm-4.18.1-release'
$ sudo dnf install automake autoconf gettext-devel libtool tar zlib-devel file-devel libarchive-devel popt-devel sqlite-devel lua-devel fakechroot
$ autoreconf -fis
...
$ mkdir b
$ cd b
$ export PKG_CONFIG_PATH=/tmp/rpm/rpm-sequoia/target/release
$ export LD_LIBRARY_PATH=/tmp/rpm/rpm-sequoia/target/release
$ ../configure --prefix=/ --with-crypto=sequoia
$ make
$ make check
Note: this builds version 4.18 of rpm, which is the current stable
release of rpm. The current development branch of rpm has
switched to using cmake instead of autoconf. Please refer to
rpm's INSTALL file for how to build master.
To use a different cryptographic backend, you need to disable the
default backend, and select your preferred backend. For instance, to
use Sequoia's OpenSSL backend, you would compile rpm-sequoia as
follows:
$ cargo build --release --no-default-features --features crypto-openssl
See sequoia-openpgp's README for the list of currently supported
cryptographic backends.
The rpm-sequoia artifacts (the .a, .so, and the .pc files) are placed
in the build directory, which, in this case, is
/tmp/rpm/rpm-sequoia/target/release.
We also set two environment variables when calling cargo build:
-
PREFIXis the prefix that will be used in the generatedrpm-sequoia.pcfile. It defaults to/usr/local. -
LIBDIRis the installed library path listed in the generated metadata. It can be an absolute path or one based on${prefix}, and defaults to${prefix}/lib.
The current rpm is using containers to run testsuite. To run just one or two tests, the simplest solution is to build a container with rpm testsuite, copy rpm-sequoia on top of that (for example in another container layer), run ldconfig and then run the tests:
$ cd /tmp/rpm/rpm/tests
$ podman build --target full -t rpm-tests -f Dockerfile
$ podman build -t rpm-tests-sequoia -f ../../tests/Dockerfile ../../
$ podman run --privileged -it --rm --read-only --tmpfs /tmp -v /tmp/rpm/rpm/:/srv:z --workdir /srv -e ROOTLESS=1 rpm-tests-sequoia rpmtests -k "openpgp v6 keys and signatures"
To get tracing output, set RPM_TRACE to 1. This needs to be passed
using --setenv optionto the specific command in the testsuite, for
example:
runroot --setenv RPM_TRACE 1 rpmkeys ...