2006-02-13 20:52:43 +01:00
|
|
|
#include "config.h"
|
|
|
|
|
2003-06-16 17:59:23 +02:00
|
|
|
#include <iostream>
|
|
|
|
|
2006-02-13 20:52:43 +01:00
|
|
|
#ifdef HAVE_OPENSSL
|
|
|
|
#include <openssl/md5.h>
|
|
|
|
#include <openssl/sha.h>
|
|
|
|
#else
|
2003-06-15 15:41:32 +02:00
|
|
|
extern "C" {
|
|
|
|
#include "md5.h"
|
2005-01-13 18:39:26 +01:00
|
|
|
#include "sha1.h"
|
2005-01-14 13:03:04 +01:00
|
|
|
#include "sha256.h"
|
2003-06-15 15:41:32 +02:00
|
|
|
}
|
2006-02-13 20:52:43 +01:00
|
|
|
#endif
|
2003-06-15 15:41:32 +02:00
|
|
|
|
|
|
|
#include "hash.hh"
|
2003-06-20 12:40:25 +02:00
|
|
|
#include "archive.hh"
|
2006-09-04 23:06:23 +02:00
|
|
|
#include "util.hh"
|
2003-06-15 15:41:32 +02:00
|
|
|
|
2005-01-13 18:39:26 +01:00
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include <fcntl.h>
|
|
|
|
|
|
|
|
|
2006-09-04 23:06:23 +02:00
|
|
|
namespace nix {
|
|
|
|
|
|
|
|
|
2005-01-14 17:04:03 +01:00
|
|
|
Hash::Hash()
|
|
|
|
{
|
|
|
|
type = htUnknown;
|
|
|
|
hashSize = 0;
|
|
|
|
memset(hash, 0, maxHashSize);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-01-13 16:44:44 +01:00
|
|
|
Hash::Hash(HashType type)
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
2005-01-13 16:44:44 +01:00
|
|
|
this->type = type;
|
|
|
|
if (type == htMD5) hashSize = md5HashSize;
|
|
|
|
else if (type == htSHA1) hashSize = sha1HashSize;
|
2005-01-14 13:03:04 +01:00
|
|
|
else if (type == htSHA256) hashSize = sha256HashSize;
|
2005-01-13 18:39:26 +01:00
|
|
|
else throw Error("unknown hash type");
|
2005-01-14 14:51:38 +01:00
|
|
|
assert(hashSize <= maxHashSize);
|
2005-01-14 17:04:03 +01:00
|
|
|
memset(hash, 0, maxHashSize);
|
2003-06-15 15:41:32 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2003-07-16 00:28:27 +02:00
|
|
|
bool Hash::operator == (const Hash & h2) const
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
2005-01-13 16:44:44 +01:00
|
|
|
if (hashSize != h2.hashSize) return false;
|
2003-06-15 15:41:32 +02:00
|
|
|
for (unsigned int i = 0; i < hashSize; i++)
|
|
|
|
if (hash[i] != h2.hash[i]) return false;
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2003-07-16 00:28:27 +02:00
|
|
|
bool Hash::operator != (const Hash & h2) const
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
|
|
|
return !(*this == h2);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2003-07-15 23:24:05 +02:00
|
|
|
bool Hash::operator < (const Hash & h) const
|
|
|
|
{
|
|
|
|
for (unsigned int i = 0; i < hashSize; i++) {
|
|
|
|
if (hash[i] < h.hash[i]) return true;
|
|
|
|
if (hash[i] > h.hash[i]) return false;
|
|
|
|
}
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2006-03-09 18:07:25 +01:00
|
|
|
const string base16Chars = "0123456789abcdef";
|
|
|
|
|
|
|
|
|
2005-01-14 17:04:03 +01:00
|
|
|
string printHash(const Hash & hash)
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
2006-03-09 18:07:25 +01:00
|
|
|
char buf[hash.hashSize * 2];
|
2005-01-14 17:04:03 +01:00
|
|
|
for (unsigned int i = 0; i < hash.hashSize; i++) {
|
2006-03-09 18:07:25 +01:00
|
|
|
buf[i * 2] = base16Chars[hash.hash[i] >> 4];
|
|
|
|
buf[i * 2 + 1] = base16Chars[hash.hash[i] & 0x0f];
|
2003-06-15 15:41:32 +02:00
|
|
|
}
|
2006-03-09 18:07:25 +01:00
|
|
|
return string(buf, hash.hashSize * 2);
|
2003-06-15 15:41:32 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-01-14 17:04:03 +01:00
|
|
|
Hash parseHash(HashType ht, const string & s)
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
2005-01-14 17:04:03 +01:00
|
|
|
Hash hash(ht);
|
2005-01-13 16:44:44 +01:00
|
|
|
if (s.length() != hash.hashSize * 2)
|
2003-10-08 17:06:59 +02:00
|
|
|
throw Error(format("invalid hash `%1%'") % s);
|
2005-01-13 16:44:44 +01:00
|
|
|
for (unsigned int i = 0; i < hash.hashSize; i++) {
|
2003-06-15 15:41:32 +02:00
|
|
|
string s2(s, i * 2, 2);
|
|
|
|
if (!isxdigit(s2[0]) || !isxdigit(s2[1]))
|
2003-10-08 17:06:59 +02:00
|
|
|
throw Error(format("invalid hash `%1%'") % s);
|
2006-09-04 23:06:23 +02:00
|
|
|
std::istringstream str(s2);
|
2003-06-15 15:41:32 +02:00
|
|
|
int n;
|
2006-09-04 23:06:23 +02:00
|
|
|
str >> std::hex >> n;
|
2003-06-15 15:41:32 +02:00
|
|
|
hash.hash[i] = n;
|
|
|
|
}
|
|
|
|
return hash;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-03-23 20:18:22 +01:00
|
|
|
static unsigned char divMod(unsigned char * bytes, unsigned char y)
|
2005-01-14 17:04:03 +01:00
|
|
|
{
|
|
|
|
unsigned int borrow = 0;
|
|
|
|
|
2005-03-23 20:18:22 +01:00
|
|
|
int pos = Hash::maxHashSize - 1;
|
|
|
|
while (pos >= 0 && !bytes[pos]) --pos;
|
2005-01-14 17:04:03 +01:00
|
|
|
|
|
|
|
for ( ; pos >= 0; --pos) {
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned int s = bytes[pos] + (borrow << 8);
|
2005-01-14 17:04:03 +01:00
|
|
|
unsigned int d = s / y;
|
|
|
|
borrow = s % y;
|
2005-03-23 20:18:22 +01:00
|
|
|
bytes[pos] = d;
|
2005-01-14 17:04:03 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
return borrow;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2006-09-20 18:15:32 +02:00
|
|
|
unsigned int hashLength32(const Hash & hash)
|
|
|
|
{
|
|
|
|
return (hash.hashSize * 8 - 1) / 5 + 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-01-14 17:04:03 +01:00
|
|
|
// omitted: E O U T
|
2005-11-16 09:27:06 +01:00
|
|
|
const string base32Chars = "0123456789abcdfghijklmnpqrsvwxyz";
|
2005-01-14 17:04:03 +01:00
|
|
|
|
|
|
|
|
|
|
|
string printHash32(const Hash & hash)
|
|
|
|
{
|
|
|
|
Hash hash2(hash);
|
2006-09-20 18:15:32 +02:00
|
|
|
unsigned int len = hashLength32(hash);
|
2005-11-16 09:27:06 +01:00
|
|
|
|
|
|
|
const char * chars = base32Chars.c_str();
|
2005-01-14 17:04:03 +01:00
|
|
|
|
|
|
|
string s(len, '0');
|
|
|
|
|
|
|
|
int pos = len - 1;
|
|
|
|
while (pos >= 0) {
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned char digit = divMod(hash2.hash, 32);
|
2005-01-14 17:04:03 +01:00
|
|
|
s[pos--] = chars[digit];
|
|
|
|
}
|
|
|
|
|
|
|
|
for (unsigned int i = 0; i < hash2.maxHashSize; ++i)
|
|
|
|
assert(hash2.hash[i] == 0);
|
|
|
|
|
|
|
|
return s;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-03-23 20:18:22 +01:00
|
|
|
static bool mul(unsigned char * bytes, unsigned char y, int maxSize)
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
{
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned char carry = 0;
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
|
|
|
|
for (int pos = 0; pos < maxSize; ++pos) {
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned int m = bytes[pos] * y + carry;
|
|
|
|
bytes[pos] = m & 0xff;
|
|
|
|
carry = m >> 8;
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
return carry;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2005-03-23 20:18:22 +01:00
|
|
|
static bool add(unsigned char * bytes, unsigned char y, int maxSize)
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
{
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned char carry = y;
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
|
|
|
|
for (int pos = 0; pos < maxSize; ++pos) {
|
2005-03-23 20:18:22 +01:00
|
|
|
unsigned int m = bytes[pos] + carry;
|
|
|
|
bytes[pos] = m & 0xff;
|
|
|
|
carry = m >> 8;
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
if (carry == 0) break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return carry;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
Hash parseHash32(HashType ht, const string & s)
|
|
|
|
{
|
|
|
|
Hash hash(ht);
|
|
|
|
|
2005-11-16 09:27:06 +01:00
|
|
|
const char * chars = base32Chars.c_str();
|
|
|
|
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
for (unsigned int i = 0; i < s.length(); ++i) {
|
|
|
|
char c = s[i];
|
|
|
|
unsigned char digit;
|
2006-03-01 18:59:08 +01:00
|
|
|
for (digit = 0; digit < base32Chars.size(); ++digit) /* !!! slow */
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
if (chars[digit] == c) break;
|
|
|
|
if (digit >= 32)
|
|
|
|
throw Error(format("invalid base-32 hash `%1%'") % s);
|
2005-03-23 20:18:22 +01:00
|
|
|
if (mul(hash.hash, 32, hash.hashSize) ||
|
|
|
|
add(hash.hash, digit, hash.hashSize))
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
throw Error(format("base-32 hash `%1%' is too large") % s);
|
|
|
|
}
|
|
|
|
|
|
|
|
return hash;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2003-06-15 15:41:32 +02:00
|
|
|
bool isHash(const string & s)
|
|
|
|
{
|
|
|
|
if (s.length() != 32) return false;
|
|
|
|
for (int i = 0; i < 32; i++) {
|
|
|
|
char c = s[i];
|
|
|
|
if (!((c >= '0' && c <= '9') ||
|
|
|
|
(c >= 'a' && c <= 'f')))
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2006-02-13 19:00:08 +01:00
|
|
|
union Ctx
|
2003-06-16 15:33:38 +02:00
|
|
|
{
|
2006-02-13 20:52:43 +01:00
|
|
|
MD5_CTX md5;
|
|
|
|
SHA_CTX sha1;
|
2005-01-14 13:03:04 +01:00
|
|
|
SHA256_CTX sha256;
|
2005-01-13 18:39:26 +01:00
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
static void start(HashType ht, Ctx & ctx)
|
|
|
|
{
|
2006-02-13 20:52:43 +01:00
|
|
|
if (ht == htMD5) MD5_Init(&ctx.md5);
|
|
|
|
else if (ht == htSHA1) SHA1_Init(&ctx.sha1);
|
2005-01-14 13:03:04 +01:00
|
|
|
else if (ht == htSHA256) SHA256_Init(&ctx.sha256);
|
2005-01-13 18:39:26 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void update(HashType ht, Ctx & ctx,
|
|
|
|
const unsigned char * bytes, unsigned int len)
|
|
|
|
{
|
2006-02-13 20:52:43 +01:00
|
|
|
if (ht == htMD5) MD5_Update(&ctx.md5, bytes, len);
|
|
|
|
else if (ht == htSHA1) SHA1_Update(&ctx.sha1, bytes, len);
|
2005-01-14 13:03:04 +01:00
|
|
|
else if (ht == htSHA256) SHA256_Update(&ctx.sha256, bytes, len);
|
2005-01-13 18:39:26 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static void finish(HashType ht, Ctx & ctx, unsigned char * hash)
|
|
|
|
{
|
2006-02-13 20:52:43 +01:00
|
|
|
if (ht == htMD5) MD5_Final(hash, &ctx.md5);
|
|
|
|
else if (ht == htSHA1) SHA1_Final(hash, &ctx.sha1);
|
2005-01-14 13:03:04 +01:00
|
|
|
else if (ht == htSHA256) SHA256_Final(hash, &ctx.sha256);
|
2005-01-13 18:39:26 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
Hash hashString(HashType ht, const string & s)
|
2005-01-13 18:39:26 +01:00
|
|
|
{
|
|
|
|
Ctx ctx;
|
|
|
|
Hash hash(ht);
|
|
|
|
start(ht, ctx);
|
|
|
|
update(ht, ctx, (const unsigned char *) s.c_str(), s.length());
|
|
|
|
finish(ht, ctx, hash.hash);
|
2003-06-16 15:33:38 +02:00
|
|
|
return hash;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
Hash hashFile(HashType ht, const Path & path)
|
2003-06-15 15:41:32 +02:00
|
|
|
{
|
2005-01-13 18:39:26 +01:00
|
|
|
Ctx ctx;
|
|
|
|
Hash hash(ht);
|
|
|
|
start(ht, ctx);
|
|
|
|
|
|
|
|
AutoCloseFD fd = open(path.c_str(), O_RDONLY);
|
|
|
|
if (fd == -1) throw SysError(format("opening file `%1%'") % path);
|
|
|
|
|
|
|
|
unsigned char buf[8192];
|
|
|
|
ssize_t n;
|
|
|
|
while ((n = read(fd, buf, sizeof(buf)))) {
|
|
|
|
checkInterrupt();
|
|
|
|
if (n == -1) throw SysError(format("reading file `%1%'") % path);
|
|
|
|
update(ht, ctx, buf, n);
|
|
|
|
}
|
|
|
|
|
|
|
|
finish(ht, ctx, hash.hash);
|
2003-06-15 15:41:32 +02:00
|
|
|
return hash;
|
|
|
|
}
|
2003-06-16 17:59:23 +02:00
|
|
|
|
|
|
|
|
2006-11-30 20:19:59 +01:00
|
|
|
struct HashSink : Sink
|
2003-06-16 17:59:23 +02:00
|
|
|
{
|
2005-01-13 18:39:26 +01:00
|
|
|
HashType ht;
|
|
|
|
Ctx ctx;
|
2003-06-16 17:59:23 +02:00
|
|
|
virtual void operator ()
|
|
|
|
(const unsigned char * data, unsigned int len)
|
|
|
|
{
|
2005-01-13 18:39:26 +01:00
|
|
|
update(ht, ctx, data, len);
|
2003-06-16 17:59:23 +02:00
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
Hash hashPath(HashType ht, const Path & path)
|
2003-06-16 17:59:23 +02:00
|
|
|
{
|
|
|
|
HashSink sink;
|
2005-01-13 18:39:26 +01:00
|
|
|
sink.ht = ht;
|
|
|
|
Hash hash(ht);
|
|
|
|
start(ht, sink.ctx);
|
2003-06-16 17:59:23 +02:00
|
|
|
dumpPath(path, sink);
|
2005-01-13 18:39:26 +01:00
|
|
|
finish(ht, sink.ctx, hash.hash);
|
2003-06-16 17:59:23 +02:00
|
|
|
return hash;
|
|
|
|
}
|
2005-01-14 17:04:03 +01:00
|
|
|
|
|
|
|
|
|
|
|
Hash compressHash(const Hash & hash, unsigned int newSize)
|
|
|
|
{
|
|
|
|
Hash h;
|
|
|
|
h.hashSize = newSize;
|
|
|
|
for (unsigned int i = 0; i < hash.hashSize; ++i)
|
|
|
|
h.hash[i % newSize] ^= hash.hash[i];
|
|
|
|
return h;
|
|
|
|
}
|
* Removed the `id' attribute hack.
* Formalise the notion of fixed-output derivations, i.e., derivations
for which a cryptographic hash of the output is known in advance.
Changes to such derivations should not propagate upwards through the
dependency graph. Previously this was done by specifying the hash
component of the output path through the `id' attribute, but this is
insecure since you can lie about it (i.e., you can specify any hash
and then produce a completely different output). Now the
responsibility for checking the output is moved from the builder to
Nix itself.
A fixed-output derivation can be created by specifying the
`outputHash' and `outputHashAlgo' attributes, the latter taking
values `md5', `sha1', and `sha256', and the former specifying the
actual hash in hexadecimal or in base-32 (auto-detected by looking
at the length of the attribute value). MD5 is included for
compatibility but should be considered deprecated.
* Removed the `drvPath' pseudo-attribute in derivation results. It's
no longer necessary.
* Cleaned up the support for multiple output paths in derivation store
expressions. Each output now has a unique identifier (e.g., `out',
`devel', `docs'). Previously there was no way to tell output paths
apart at the store expression level.
* `nix-hash' now has a flag `--base32' to specify that the hash should
be printed in base-32 notation.
* `fetchurl' accepts parameters `sha256' and `sha1' in addition to
`md5'.
* `nix-prefetch-url' now prints out a SHA-1 hash in base-32. (TODO: a
flag to specify the hash.)
2005-01-17 17:55:19 +01:00
|
|
|
|
|
|
|
|
|
|
|
HashType parseHashType(const string & s)
|
|
|
|
{
|
|
|
|
if (s == "md5") return htMD5;
|
|
|
|
else if (s == "sha1") return htSHA1;
|
|
|
|
else if (s == "sha256") return htSHA256;
|
|
|
|
else return htUnknown;
|
|
|
|
}
|
2006-09-04 23:06:23 +02:00
|
|
|
|
|
|
|
|
|
|
|
}
|