seed.py 32 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051
  1. #!/usr/bin/env python
  2. # -*- coding: UTF-8 -*-
  3. #
  4. # mmgen = Multi-Mode GENerator, command-line Bitcoin cold storage solution
  5. # Copyright (C)2013-2018 The MMGen Project <mmgen@tuta.io>
  6. #
  7. # This program is free software: you can redistribute it and/or modify
  8. # it under the terms of the GNU General Public License as published by
  9. # the Free Software Foundation, either version 3 of the License, or
  10. # (at your option) any later version.
  11. #
  12. # This program is distributed in the hope that it will be useful,
  13. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. # GNU General Public License for more details.
  16. #
  17. # You should have received a copy of the GNU General Public License
  18. # along with this program. If not, see <http://www.gnu.org/licenses/>.
  19. """
  20. seed.py: Seed-related classes and methods for the MMGen suite
  21. """
  22. import os
  23. from binascii import hexlify,unhexlify
  24. from mmgen.common import *
  25. from mmgen.obj import *
  26. from mmgen.filename import *
  27. from mmgen.crypto import *
  28. pnm = g.proj_name
  29. def check_usr_seed_len(seed_len):
  30. if opt.seed_len != seed_len and 'seed_len' in opt.set_by_user:
  31. m = "ERROR: requested seed length ({}) doesn't match seed length of source ({})"
  32. die(1,m.format((opt.seed_len,seed_len)))
  33. class Seed(MMGenObject):
  34. def __init__(self,seed_bin=None):
  35. if not seed_bin:
  36. # Truncate random data for smaller seed lengths
  37. seed_bin = sha256(get_random(1033)).digest()[:opt.seed_len/8]
  38. elif len(seed_bin)*8 not in g.seed_lens:
  39. die(3,'{}: invalid seed length'.format(len(seed_bin)))
  40. self.data = seed_bin
  41. self.hexdata = hexlify(seed_bin)
  42. self.sid = SeedID(seed=self)
  43. self.length = len(seed_bin) * 8
  44. def get_data(self):
  45. return self.data
  46. class SeedSource(MMGenObject):
  47. desc = g.proj_name + ' seed source'
  48. file_mode = 'text'
  49. stdin_ok = False
  50. ask_tty = True
  51. no_tty = False
  52. op = None
  53. require_utf8_input = False
  54. _msg = {}
  55. class SeedSourceData(MMGenObject): pass
  56. def __new__(cls,fn=None,ss=None,seed=None,ignore_in_fmt=False,passchg=False):
  57. def die_on_opt_mismatch(opt,sstype):
  58. opt_sstype = cls.fmt_code_to_type(opt)
  59. compare_or_die(
  60. opt_sstype.__name__, 'input format requested on command line',
  61. sstype.__name__, 'input file format'
  62. )
  63. if ss:
  64. sstype = ss.__class__ if passchg else cls.fmt_code_to_type(opt.out_fmt)
  65. me = super(cls,cls).__new__(sstype or Wallet) # default: Wallet
  66. me.seed = ss.seed
  67. me.ss_in = ss
  68. me.op = ('conv','pwchg_new')[bool(passchg)]
  69. elif fn or opt.hidden_incog_input_params:
  70. if fn:
  71. f = Filename(fn)
  72. else:
  73. # permit comma in filename
  74. fn = ','.join(opt.hidden_incog_input_params.split(',')[:-1])
  75. f = Filename(fn,ftype=IncogWalletHidden)
  76. if opt.in_fmt and not ignore_in_fmt:
  77. die_on_opt_mismatch(opt.in_fmt,f.ftype)
  78. me = super(cls,cls).__new__(f.ftype)
  79. me.infile = f
  80. me.op = ('old','pwchg_old')[bool(passchg)]
  81. elif opt.in_fmt: # Input format
  82. sstype = cls.fmt_code_to_type(opt.in_fmt)
  83. me = super(cls,cls).__new__(sstype)
  84. me.op = ('old','pwchg_old')[bool(passchg)]
  85. else: # Called with no inputs - initialize with random seed
  86. sstype = cls.fmt_code_to_type(opt.out_fmt)
  87. me = super(cls,cls).__new__(sstype or Wallet) # default: Wallet
  88. me.seed = Seed(seed_bin=seed or None)
  89. me.op = 'new'
  90. # die(1,me.seed.sid.hl()) # DEBUG
  91. return me
  92. def __init__(self,fn=None,ss=None,seed=None,ignore_in_fmt=False,passchg=False):
  93. self.ssdata = self.SeedSourceData()
  94. self.msg = {}
  95. for c in reversed(self.__class__.__mro__):
  96. if hasattr(c,'_msg'):
  97. self.msg.update(c._msg)
  98. if hasattr(self,'seed'):
  99. self._encrypt()
  100. return
  101. elif hasattr(self,'infile') or not g.stdin_tty:
  102. self._deformat_once()
  103. self._decrypt_retry()
  104. else:
  105. if not self.stdin_ok:
  106. die(1,'Reading from standard input not supported for {} format'.format(self.desc))
  107. self._deformat_retry()
  108. self._decrypt_retry()
  109. m = ('',', seed length {}'.format(self.seed.length))[self.seed.length!=256]
  110. qmsg('Valid {} for Seed ID {}{}'.format(self.desc,self.seed.sid.hl(),m))
  111. def _get_data(self):
  112. if hasattr(self,'infile'):
  113. self.fmt_data = get_data_from_file(self.infile.name,self.desc,
  114. binary=self.file_mode=='binary',require_utf8=self.require_utf8_input)
  115. else:
  116. self.fmt_data = self._get_data_from_user(self.desc)
  117. def _get_data_from_user(self,desc):
  118. return get_data_from_user(desc)
  119. def _deformat_once(self):
  120. self._get_data()
  121. if not self._deformat():
  122. die(2,'Invalid format for input data')
  123. def _deformat_retry(self):
  124. while True:
  125. self._get_data()
  126. if self._deformat(): break
  127. msg('Trying again...')
  128. def _decrypt_retry(self):
  129. while True:
  130. if self._decrypt(): break
  131. if opt.passwd_file:
  132. die(2,'Passphrase from password file, so exiting')
  133. msg('Trying again...')
  134. @classmethod
  135. def get_subclasses_str(cls): # returns name of calling class too
  136. return cls.__name__ + ' ' + ''.join([c.get_subclasses_str() for c in cls.__subclasses__()])
  137. @classmethod
  138. def get_subclasses_easy(cls,acc=[]):
  139. return [globals()[c] for c in cls.get_subclasses_str().split()]
  140. @classmethod
  141. def get_subclasses(cls): # returns calling class too
  142. def GetSubclassesTree(cls,acc):
  143. acc += [cls]
  144. for c in cls.__subclasses__(): GetSubclassesTree(c,acc)
  145. acc = []
  146. GetSubclassesTree(cls,acc)
  147. return acc
  148. @classmethod
  149. def get_extensions(cls):
  150. return [s.ext for s in cls.get_subclasses() if hasattr(s,'ext')]
  151. @classmethod
  152. def fmt_code_to_type(cls,fmt_code):
  153. if not fmt_code: return None
  154. for c in cls.get_subclasses():
  155. if hasattr(c,'fmt_codes') and fmt_code in c.fmt_codes:
  156. return c
  157. return None
  158. @classmethod
  159. def ext_to_type(cls,ext):
  160. if not ext: return None
  161. for c in cls.get_subclasses():
  162. if hasattr(c,'ext') and ext == c.ext:
  163. return c
  164. return None
  165. @classmethod
  166. def format_fmt_codes(cls):
  167. d = [(c.__name__,('.'+c.ext if c.ext else c.ext),','.join(c.fmt_codes))
  168. for c in cls.get_subclasses()
  169. if hasattr(c,'fmt_codes')]
  170. w = max(len(i[0]) for i in d)
  171. ret = [u'{:<{w}} {:<9} {}'.format(a,b,c,w=w) for a,b,c in [
  172. ('Format','FileExt','Valid codes'),
  173. ('------','-------','-----------')
  174. ] + sorted(d)]
  175. return u'\n'.join(ret) + ('',u'-α')[g.debug_utf8] + '\n'
  176. def get_fmt_data(self):
  177. self._format()
  178. return self.fmt_data
  179. def write_to_file(self,outdir='',desc=''):
  180. self._format()
  181. kwargs = {
  182. 'desc': desc or self.desc,
  183. 'ask_tty': self.ask_tty,
  184. 'no_tty': self.no_tty,
  185. 'binary': self.file_mode == 'binary'
  186. }
  187. # write_data_to_file(): outfile with absolute path overrides opt.outdir
  188. if outdir:
  189. of = os.path.abspath(os.path.join(outdir,self._filename()))
  190. write_data_to_file(of if outdir else self._filename(),self.fmt_data,**kwargs)
  191. class SeedSourceUnenc(SeedSource):
  192. def _decrypt_retry(self): pass
  193. def _encrypt(self): pass
  194. def _filename(self):
  195. return u'{}[{}]{x}.{}'.format(self.seed.sid,self.seed.length,self.ext,x=u'-α' if g.debug_utf8 else '')
  196. class SeedSourceEnc(SeedSource):
  197. _msg = {
  198. 'choose_passphrase': """
  199. You must choose a passphrase to encrypt your new {} with.
  200. A key will be generated from your passphrase using a hash preset of '{}'.
  201. Please note that no strength checking of passphrases is performed. For
  202. an empty passphrase, just hit ENTER twice.
  203. """.strip()
  204. }
  205. def _get_hash_preset_from_user(self,hp,desc_suf=''):
  206. # hp=a,
  207. n = ('','old ')[self.op=='pwchg_old']
  208. m,n = (('to accept the default',n),('to reuse the old','new '))[
  209. int(self.op=='pwchg_new')]
  210. fs = "Enter {}hash preset for {}{}{},\n or hit ENTER {} value ('{}'): "
  211. p = fs.format(
  212. n,
  213. ('','new ')[self.op=='new'],
  214. self.desc,
  215. ('',' '+desc_suf)[bool(desc_suf)],
  216. m,
  217. hp
  218. )
  219. while True:
  220. ret = my_raw_input(p)
  221. if ret:
  222. if ret in g.hash_presets.keys():
  223. self.ssdata.hash_preset = ret
  224. return ret
  225. else:
  226. msg('Invalid input. Valid choices are {}'.format(', '.join(sorted(g.hash_presets.keys()))))
  227. else:
  228. self.ssdata.hash_preset = hp
  229. return hp
  230. def _get_hash_preset(self,desc_suf=''):
  231. if hasattr(self,'ss_in') and hasattr(self.ss_in.ssdata,'hash_preset'):
  232. old_hp = self.ss_in.ssdata.hash_preset
  233. if opt.keep_hash_preset:
  234. qmsg("Reusing hash preset '{}' at user request".format(old_hp))
  235. self.ssdata.hash_preset = old_hp
  236. elif 'hash_preset' in opt.set_by_user:
  237. hp = self.ssdata.hash_preset = opt.hash_preset
  238. qmsg("Using hash preset '{}' requested on command line".format(opt.hash_preset))
  239. else: # Prompt, using old value as default
  240. hp = self._get_hash_preset_from_user(old_hp,desc_suf)
  241. if (not opt.keep_hash_preset) and self.op == 'pwchg_new':
  242. m = ("changed to '{}'".format(hp),'unchanged')[hp==old_hp]
  243. qmsg('Hash preset {}'.format(m))
  244. elif 'hash_preset' in opt.set_by_user:
  245. self.ssdata.hash_preset = opt.hash_preset
  246. qmsg("Using hash preset '{}' requested on command line".format(opt.hash_preset))
  247. else:
  248. self._get_hash_preset_from_user(opt.hash_preset,desc_suf)
  249. def _get_new_passphrase(self):
  250. desc = '{}passphrase for {}{}'.format(
  251. ('','new ')[self.op=='pwchg_new'],
  252. ('','new ')[self.op in ('new','conv')],
  253. self.desc
  254. )
  255. if opt.passwd_file:
  256. w = pwfile_reuse_warning()
  257. pw = ' '.join(get_words_from_file(opt.passwd_file,desc,silent=w))
  258. elif opt.echo_passphrase:
  259. pw = ' '.join(get_words_from_user('Enter {}: '.format(desc)))
  260. else:
  261. for i in range(g.passwd_max_tries):
  262. pw = ' '.join(get_words_from_user('Enter {}: '.format(desc)))
  263. pw2 = ' '.join(get_words_from_user('Repeat passphrase: '))
  264. dmsg(u'Passphrases: [{}] [{}]'.format(pw,pw2))
  265. if pw == pw2:
  266. vmsg('Passphrases match'); break
  267. else: msg('Passphrases do not match. Try again.')
  268. else:
  269. die(2,'User failed to duplicate passphrase in {} attempts'.format(g.passwd_max_tries))
  270. if pw == '': qmsg('WARNING: Empty passphrase')
  271. self.ssdata.passwd = pw
  272. return pw
  273. def _get_passphrase(self,desc_suf=''):
  274. desc = u'{}passphrase for {}{}'.format(
  275. ('','old ')[self.op=='pwchg_old'],
  276. self.desc,
  277. ('',' '+desc_suf)[bool(desc_suf)]
  278. )
  279. if opt.passwd_file:
  280. w = pwfile_reuse_warning()
  281. ret = ' '.join(get_words_from_file(opt.passwd_file,desc,silent=w))
  282. else:
  283. ret = ' '.join(get_words_from_user(u'Enter {}: '.format(desc)))
  284. self.ssdata.passwd = ret
  285. def _get_first_pw_and_hp_and_encrypt_seed(self):
  286. d = self.ssdata
  287. self._get_hash_preset()
  288. if hasattr(self,'ss_in') and hasattr(self.ss_in.ssdata,'passwd'):
  289. old_pw = self.ss_in.ssdata.passwd
  290. if opt.keep_passphrase:
  291. d.passwd = old_pw
  292. qmsg('Reusing passphrase at user request')
  293. else:
  294. pw = self._get_new_passphrase()
  295. if self.op == 'pwchg_new':
  296. m = ('changed','unchanged')[pw==old_pw]
  297. qmsg('Passphrase {}'.format(m))
  298. else:
  299. qmsg(self.msg['choose_passphrase'].format(self.desc,d.hash_preset))
  300. self._get_new_passphrase()
  301. d.salt = sha256(get_random(128)).digest()[:g.salt_len]
  302. key = make_key(d.passwd, d.salt, d.hash_preset)
  303. d.key_id = make_chksum_8(key)
  304. d.enc_seed = encrypt_seed(self.seed.data,key)
  305. class Mnemonic (SeedSourceUnenc):
  306. stdin_ok = True
  307. fmt_codes = 'mmwords','words','mnemonic','mnem','mn','m'
  308. desc = 'mnemonic data'
  309. ext = 'mmwords'
  310. mn_lens = [i / 32 * 3 for i in g.seed_lens]
  311. wl_id = 'electrum' # or 'tirosh'
  312. def _get_data_from_user(self,desc):
  313. if not g.stdin_tty:
  314. return get_data_from_user(desc)
  315. from mmgen.term import get_char_raw,get_char
  316. def choose_mn_len():
  317. prompt = 'Choose a mnemonic length: 1) 12 words, 2) 18 words, 3) 24 words: '
  318. urange = [str(i+1) for i in range(len(self.mn_lens))]
  319. while True:
  320. r = get_char('\r'+prompt)
  321. if r in urange: break
  322. msg_r('\r' + ' '*len(prompt) + '\r')
  323. return self.mn_lens[int(r)-1]
  324. while True:
  325. mn_len = choose_mn_len()
  326. prompt = 'Mnemonic length of {} words chosen. OK?'.format(mn_len)
  327. if keypress_confirm(prompt,default_yes=True,no_nl=True): break
  328. wl = baseconv.digits[self.wl_id]
  329. longest_word = max(len(w) for w in wl)
  330. from string import ascii_lowercase
  331. m = u'Enter your {}-word mnemonic, hitting ENTER or SPACE after each word.\n'
  332. m += u"Optionally, you may use pad characters. Anything you type that's not a\n"
  333. m += u'lowercase letter will be treated as a “pad character”, i.e. it will simply\n'
  334. m += u'be discarded. Pad characters may be typed before, after, or in the middle\n'
  335. m += u"of words. For each word, once you've typed {} characters total (including\n"
  336. m += u'pad characters) a pad character will enter the word.'
  337. msg(m.format(mn_len,longest_word))
  338. def get_word():
  339. s,pad = '',0
  340. while True:
  341. ch = get_char_raw('')
  342. if ch in '\b\x7f':
  343. if s: s = s[:-1]
  344. elif ch in '\n ':
  345. if s: break
  346. elif ch not in ascii_lowercase:
  347. pad += 1
  348. if s and pad + len(s) > longest_word:
  349. break
  350. else:
  351. s += ch
  352. return s
  353. def in_list(w):
  354. from bisect import bisect_left
  355. idx = bisect_left(wl,w)
  356. return(True,False)[idx == len(wl) or w != wl[idx]]
  357. words,i,p = [],0,('Enter word #{}: ','Incorrect entry. Repeat word #{}: ')
  358. while len(words) < mn_len:
  359. msg_r('{r}{s}{r}'.format(r='\r',s=' '*40))
  360. if i == 1: time.sleep(0.1)
  361. msg_r(p[i].format(len(words)+1))
  362. s = get_word()
  363. if in_list(s):
  364. words.append(s); i = 0
  365. else:
  366. i = 1
  367. msg('')
  368. qmsg('Mnemonic successfully entered')
  369. return ' '.join(words)
  370. @staticmethod
  371. def _mn2hex_pad(mn): return len(mn) * 8 / 3
  372. @staticmethod
  373. def _hex2mn_pad(hexnum): return len(hexnum) * 3 / 8
  374. def _format(self):
  375. hexseed = self.seed.hexdata
  376. mn = baseconv.fromhex(hexseed,self.wl_id,self._hex2mn_pad(hexseed))
  377. ret = baseconv.tohex(mn,self.wl_id,self._mn2hex_pad(mn))
  378. # Internal error, so just die on fail
  379. compare_or_die(ret,'recomputed seed',hexseed,'original',e='Internal error')
  380. self.ssdata.mnemonic = mn
  381. self.fmt_data = ' '.join(mn) + '\n'
  382. def _deformat(self):
  383. mn = self.fmt_data.split()
  384. if len(mn) not in self.mn_lens:
  385. msg('Invalid mnemonic ({} words). Valid numbers of words: {}'.format(
  386. (len(mn),', '.join(map(str,self.mn_lens)))))
  387. return False
  388. for n,w in enumerate(mn,1):
  389. if w not in baseconv.digits[self.wl_id]:
  390. msg('Invalid mnemonic: word #{} is not in the wordlist'.format(n))
  391. return False
  392. hexseed = baseconv.tohex(mn,self.wl_id,self._mn2hex_pad(mn))
  393. ret = baseconv.fromhex(hexseed,self.wl_id,self._hex2mn_pad(hexseed))
  394. if len(hexseed) * 4 not in g.seed_lens:
  395. msg('Invalid mnemonic (produces too large a number)')
  396. return False
  397. # Internal error, so just die
  398. compare_or_die(' '.join(ret),'recomputed mnemonic',' '.join(mn),'original',e='Internal error')
  399. self.seed = Seed(unhexlify(hexseed))
  400. self.ssdata.mnemonic = mn
  401. check_usr_seed_len(self.seed.length)
  402. return True
  403. class SeedFile (SeedSourceUnenc):
  404. stdin_ok = True
  405. fmt_codes = 'mmseed','seed','s'
  406. desc = 'seed data'
  407. ext = 'mmseed'
  408. def _format(self):
  409. b58seed = baseconv.b58encode(self.seed.data,pad=True)
  410. self.ssdata.chksum = make_chksum_6(b58seed)
  411. self.ssdata.b58seed = b58seed
  412. self.fmt_data = '{} {}\n'.format(self.ssdata.chksum,split_into_cols(4,b58seed))
  413. def _deformat(self):
  414. desc = self.desc
  415. ld = self.fmt_data.split()
  416. if not (7 <= len(ld) <= 12): # 6 <= padded b58 data (ld[1:]) <= 11
  417. msg('Invalid data length ({}) in {}'.format(len(ld),desc))
  418. return False
  419. a,b = ld[0],''.join(ld[1:])
  420. if not is_chksum_6(a):
  421. msg("'{}': invalid checksum format in {}".format(a, desc))
  422. return False
  423. if not is_b58_str(b):
  424. msg("'{}': not a base 58 string, in {}".format(b, desc))
  425. return False
  426. vmsg_r('Validating {} checksum...'.format(desc))
  427. if not compare_chksums(a,'file',make_chksum_6(b),'computed',verbose=True):
  428. return False
  429. ret = baseconv.b58decode(b,pad=True)
  430. if ret == False:
  431. msg('Invalid base-58 encoded seed: {}'.format(val))
  432. return False
  433. self.seed = Seed(ret)
  434. self.ssdata.chksum = a
  435. self.ssdata.b58seed = b
  436. check_usr_seed_len(self.seed.length)
  437. return True
  438. class HexSeedFile (SeedSourceUnenc):
  439. stdin_ok = True
  440. fmt_codes = 'seedhex','hexseed','hex','mmhex'
  441. desc = 'hexadecimal seed data'
  442. ext = 'mmhex'
  443. def _format(self):
  444. h = self.seed.hexdata
  445. self.ssdata.chksum = make_chksum_6(h)
  446. self.ssdata.hexseed = h
  447. self.fmt_data = '{} {}\n'.format(self.ssdata.chksum, split_into_cols(4,h))
  448. def _deformat(self):
  449. desc = self.desc
  450. d = self.fmt_data.split()
  451. try:
  452. d[1]
  453. chk,hstr = d[0],''.join(d[1:])
  454. except:
  455. msg("'{}': invalid {}".format(self.fmt_data.strip(),desc))
  456. return False
  457. if not len(hstr)*4 in g.seed_lens:
  458. msg('Invalid data length ({}) in {}'.format(len(hstr),desc))
  459. return False
  460. if not is_chksum_6(chk):
  461. msg("'{}': invalid checksum format in {}".format(chk, desc))
  462. return False
  463. if not is_hex_str(hstr):
  464. msg("'{}': not a hexadecimal string, in {}".format(hstr, desc))
  465. return False
  466. vmsg_r('Validating {} checksum...'.format(desc))
  467. if not compare_chksums(chk,'file',make_chksum_6(hstr),'computed',verbose=True):
  468. return False
  469. self.seed = Seed(unhexlify(hstr))
  470. self.ssdata.chksum = chk
  471. self.ssdata.hexseed = hstr
  472. check_usr_seed_len(self.seed.length)
  473. return True
  474. class Wallet (SeedSourceEnc):
  475. fmt_codes = 'wallet','w'
  476. desc = g.proj_name + ' wallet'
  477. ext = 'mmdat'
  478. require_utf8_input = True # label is UTF-8
  479. def _get_label_from_user(self,old_lbl=''):
  480. d = u"to reuse the label '{}'".format(old_lbl.hl()) if old_lbl else 'for no label'
  481. p = u'Enter a wallet label, or hit ENTER {}: '.format(d)
  482. while True:
  483. msg_r(p)
  484. ret = my_raw_input('')
  485. if ret:
  486. self.ssdata.label = MMGenWalletLabel(ret,on_fail='return')
  487. if self.ssdata.label:
  488. break
  489. else:
  490. msg('Invalid label. Trying again...')
  491. else:
  492. self.ssdata.label = old_lbl or MMGenWalletLabel('No Label')
  493. break
  494. return self.ssdata.label
  495. # nearly identical to _get_hash_preset() - factor?
  496. def _get_label(self):
  497. if hasattr(self,'ss_in') and hasattr(self.ss_in.ssdata,'label'):
  498. old_lbl = self.ss_in.ssdata.label
  499. if opt.keep_label:
  500. qmsg(u"Reusing label '{}' at user request".format(old_lbl.hl()))
  501. self.ssdata.label = old_lbl
  502. elif opt.label:
  503. qmsg(u"Using label '{}' requested on command line".format(opt.label.hl()))
  504. lbl = self.ssdata.label = opt.label
  505. else: # Prompt, using old value as default
  506. lbl = self._get_label_from_user(old_lbl)
  507. if (not opt.keep_label) and self.op == 'pwchg_new':
  508. m = (u"changed to '{}'".format(lbl),'unchanged')[lbl==old_lbl]
  509. qmsg(u'Label {}'.format(m))
  510. elif opt.label:
  511. qmsg(u"Using label '{}' requested on command line".format(opt.label.hl()))
  512. self.ssdata.label = opt.label
  513. else:
  514. self._get_label_from_user()
  515. def _encrypt(self):
  516. self._get_first_pw_and_hp_and_encrypt_seed()
  517. self._get_label()
  518. d = self.ssdata
  519. d.pw_status = ('NE','E')[len(d.passwd)==0]
  520. d.timestamp = make_timestamp()
  521. def _format(self):
  522. d = self.ssdata
  523. s = self.seed
  524. slt_fmt = baseconv.b58encode(d.salt,pad=True)
  525. es_fmt = baseconv.b58encode(d.enc_seed,pad=True)
  526. lines = (
  527. d.label,
  528. '{} {} {} {} {}'.format(s.sid.lower(), d.key_id.lower(),
  529. s.length, d.pw_status, d.timestamp),
  530. '{}: {} {} {}'.format(d.hash_preset,*get_hash_params(d.hash_preset)),
  531. '{} {}'.format(make_chksum_6(slt_fmt),split_into_cols(4,slt_fmt)),
  532. '{} {}'.format(make_chksum_6(es_fmt), split_into_cols(4,es_fmt))
  533. )
  534. chksum = make_chksum_6(' '.join(lines).encode('utf8'))
  535. self.fmt_data = '\n'.join((chksum,)+lines) + '\n'
  536. def _deformat(self):
  537. def check_master_chksum(lines,desc):
  538. if len(lines) != 6:
  539. msg('Invalid number of lines ({}) in {} data'.format(len(lines),desc))
  540. return False
  541. if not is_chksum_6(lines[0]):
  542. msg('Incorrect master checksum ({}) in {} data'.format(lines[0],desc))
  543. return False
  544. chk = make_chksum_6(' '.join(lines[1:]))
  545. if not compare_chksums(lines[0],'master',chk,'computed',
  546. hdr='For wallet master checksum',verbose=True):
  547. return False
  548. return True
  549. lines = self.fmt_data.splitlines()
  550. if not check_master_chksum(lines,self.desc): return False
  551. d = self.ssdata
  552. d.label = MMGenWalletLabel(lines[1])
  553. d1,d2,d3,d4,d5 = lines[2].split()
  554. d.seed_id = d1.upper()
  555. d.key_id = d2.upper()
  556. check_usr_seed_len(int(d3))
  557. d.pw_status,d.timestamp = d4,d5
  558. hpdata = lines[3].split()
  559. d.hash_preset = hp = hpdata[0][:-1] # a string!
  560. qmsg("Hash preset of wallet: '{}'".format(hp))
  561. if 'hash_preset' in opt.set_by_user:
  562. uhp = opt.hash_preset
  563. if uhp != hp:
  564. qmsg("Warning: ignoring user-requested hash preset '{}'".format(uhp))
  565. hash_params = map(int,hpdata[1:])
  566. if hash_params != get_hash_params(d.hash_preset):
  567. msg("Hash parameters '{}' don't match hash preset '{}'".format(' '.join(hash_params),d.hash_preset))
  568. return False
  569. lmin,foo,lmax = [v for k,v in baseconv.b58pad_lens] # 22,33,44
  570. for i,key in (4,'salt'),(5,'enc_seed'):
  571. l = lines[i].split(' ')
  572. chk = l.pop(0)
  573. b58_val = ''.join(l)
  574. if len(b58_val) < lmin or len(b58_val) > lmax:
  575. msg('Invalid format for {} in {}: {}'.format(key,self.desc,l))
  576. return False
  577. if not compare_chksums(chk,key,
  578. make_chksum_6(b58_val),'computed checksum',verbose=True):
  579. return False
  580. val = baseconv.b58decode(b58_val,pad=True)
  581. if val == False:
  582. msg('Invalid base 58 number: {}'.format(b58_val))
  583. return False
  584. setattr(d,key,val)
  585. return True
  586. def _decrypt(self):
  587. d = self.ssdata
  588. # Needed for multiple transactions with {}-txsign
  589. suf = ('',os.path.basename(self.infile.name))[bool(opt.quiet)]
  590. self._get_passphrase(desc_suf=suf)
  591. key = make_key(d.passwd, d.salt, d.hash_preset)
  592. ret = decrypt_seed(d.enc_seed, key, d.seed_id, d.key_id)
  593. if ret:
  594. self.seed = Seed(ret)
  595. return True
  596. else:
  597. return False
  598. def _filename(self):
  599. return u'{}-{}[{},{}]{x}.{}'.format(
  600. self.seed.sid,
  601. self.ssdata.key_id,
  602. self.seed.length,
  603. self.ssdata.hash_preset,
  604. self.ext,
  605. x=u'-α' if g.debug_utf8 else '')
  606. class Brainwallet (SeedSourceEnc):
  607. stdin_ok = True
  608. fmt_codes = 'mmbrain','brainwallet','brain','bw','b'
  609. desc = 'brainwallet'
  610. ext = 'mmbrain'
  611. require_utf8_input = True # brainwallet is user input, so require UTF-8
  612. # brainwallet warning message? TODO
  613. def get_bw_params(self):
  614. # already checked
  615. a = opt.brain_params.split(',')
  616. return int(a[0]),a[1]
  617. def _deformat(self):
  618. self.brainpasswd = ' '.join(self.fmt_data.split())
  619. return True
  620. def _decrypt(self):
  621. d = self.ssdata
  622. # Don't set opt.seed_len! In txsign, BW seed len might differ from other seed srcs
  623. if opt.brain_params:
  624. seed_len,d.hash_preset = self.get_bw_params()
  625. else:
  626. if 'seed_len' not in opt.set_by_user:
  627. m1 = 'Using default seed length of {} bits\n'
  628. m2 = 'If this is not what you want, use the --seed-len option'
  629. qmsg((m1+m2).format(yellow(str(opt.seed_len))))
  630. self._get_hash_preset()
  631. seed_len = opt.seed_len
  632. qmsg_r('Hashing brainwallet data. Please wait...')
  633. # Use buflen arg of scrypt.hash() to get seed of desired length
  634. seed = scrypt_hash_passphrase(self.brainpasswd,'',d.hash_preset,buflen=seed_len/8)
  635. qmsg('Done')
  636. self.seed = Seed(seed)
  637. msg('Seed ID: {}'.format(self.seed.sid))
  638. qmsg('Check this value against your records')
  639. return True
  640. class IncogWallet (SeedSourceEnc):
  641. file_mode = 'binary'
  642. fmt_codes = 'mmincog','incog','icg','i'
  643. desc = 'incognito data'
  644. ext = 'mmincog'
  645. no_tty = True
  646. _msg = {
  647. 'check_incog_id': """
  648. Check the generated Incog ID above against your records. If it doesn't
  649. match, then your incognito data is incorrect or corrupted.
  650. """,
  651. 'record_incog_id': """
  652. Make a record of the Incog ID but keep it secret. You will use it to
  653. identify your incog wallet data in the future.
  654. """,
  655. 'incorrect_incog_passphrase_try_again': """
  656. Incorrect passphrase, hash preset, or maybe old-format incog wallet.
  657. Try again? (Y)es, (n)o, (m)ore information:
  658. """.strip(),
  659. 'confirm_seed_id': """
  660. If the Seed ID above is correct but you're seeing this message, then you need
  661. to exit and re-run the program with the '--old-incog-fmt' option.
  662. """.strip(),
  663. 'dec_chk': " {} hash preset"
  664. }
  665. def _make_iv_chksum(self,s): return sha256(s).hexdigest()[:8].upper()
  666. def _get_incog_data_len(self,seed_len):
  667. e = (g.hincog_chk_len,0)[bool(opt.old_incog_fmt)]
  668. return g.aesctr_iv_len + g.salt_len + e + seed_len/8
  669. def _incog_data_size_chk(self):
  670. # valid sizes: 56, 64, 72
  671. dlen = len(self.fmt_data)
  672. valid_dlen = self._get_incog_data_len(opt.seed_len)
  673. if dlen == valid_dlen:
  674. return True
  675. else:
  676. if opt.old_incog_fmt:
  677. msg('WARNING: old-style incognito format requested. Are you sure this is correct?')
  678. m = 'Invalid incognito data size ({} bytes) for this seed length ({} bits)'
  679. msg(m.format(dlen,opt.seed_len))
  680. msg('Valid data size for this seed length: {} bytes'.format(valid_dlen))
  681. for sl in g.seed_lens:
  682. if dlen == self._get_incog_data_len(sl):
  683. die(1,'Valid seed length for this data size: {} bits'.format(sl))
  684. msg('This data size ({} bytes) is invalid for all available seed lengths'.format(dlen))
  685. return False
  686. def _encrypt (self):
  687. self._get_first_pw_and_hp_and_encrypt_seed()
  688. if opt.old_incog_fmt:
  689. die(1,'Writing old-format incog wallets is unsupported')
  690. d = self.ssdata
  691. # IV is used BOTH to initialize counter and to salt password!
  692. d.iv = get_random(g.aesctr_iv_len)
  693. d.iv_id = self._make_iv_chksum(d.iv)
  694. msg('New Incog Wallet ID: {}'.format(d.iv_id))
  695. qmsg('Make a record of this value')
  696. vmsg(self.msg['record_incog_id'])
  697. d.salt = get_random(g.salt_len)
  698. key = make_key(d.passwd, d.salt, d.hash_preset, 'incog wallet key')
  699. chk = sha256(self.seed.data).digest()[:8]
  700. d.enc_seed = encrypt_data(chk + self.seed.data, key, 1, 'seed')
  701. d.wrapper_key = make_key(d.passwd, d.iv, d.hash_preset, 'incog wrapper key')
  702. d.key_id = make_chksum_8(d.wrapper_key)
  703. vmsg('Key ID: {}'.format(d.key_id))
  704. d.target_data_len = self._get_incog_data_len(self.seed.length)
  705. def _format(self):
  706. d = self.ssdata
  707. # print len(d.iv), len(d.salt), len(d.enc_seed), len(d.wrapper_key)
  708. self.fmt_data = d.iv + encrypt_data(
  709. d.salt + d.enc_seed,
  710. d.wrapper_key,
  711. int(hexlify(d.iv),16),
  712. self.desc)
  713. # print len(self.fmt_data)
  714. def _filename(self):
  715. s = self.seed
  716. d = self.ssdata
  717. return u'{}-{}-{}[{},{}]{x}.{}'.format(
  718. s.sid,
  719. d.key_id,
  720. d.iv_id,
  721. s.length,
  722. d.hash_preset,
  723. self.ext,
  724. x=u'-α' if g.debug_utf8 else '')
  725. def _deformat(self):
  726. if not self._incog_data_size_chk(): return False
  727. d = self.ssdata
  728. d.iv = self.fmt_data[0:g.aesctr_iv_len]
  729. d.incog_id = self._make_iv_chksum(d.iv)
  730. d.enc_incog_data = self.fmt_data[g.aesctr_iv_len:]
  731. msg('Incog Wallet ID: {}'.format(d.incog_id))
  732. qmsg('Check this value against your records')
  733. vmsg(self.msg['check_incog_id'])
  734. return True
  735. def _verify_seed_newfmt(self,data):
  736. chk,seed = data[:8],data[8:]
  737. if sha256(seed).digest()[:8] == chk:
  738. qmsg('Passphrase{} are correct'.format(self.msg['dec_chk'].format('and')))
  739. return seed
  740. else:
  741. msg('Incorrect passphrase{}'.format(self.msg['dec_chk'].format('or')))
  742. return False
  743. def _verify_seed_oldfmt(self,seed):
  744. m = 'Seed ID: {}. Is the Seed ID correct?'.format(make_chksum_8(seed))
  745. if keypress_confirm(m, True):
  746. return seed
  747. else:
  748. return False
  749. def _decrypt(self):
  750. d = self.ssdata
  751. self._get_hash_preset(desc_suf=d.incog_id)
  752. self._get_passphrase(desc_suf=d.incog_id)
  753. # IV is used BOTH to initialize counter and to salt password!
  754. key = make_key(d.passwd, d.iv, d.hash_preset, 'wrapper key')
  755. dd = decrypt_data(d.enc_incog_data, key,
  756. int(hexlify(d.iv),16), 'incog data')
  757. d.salt = dd[0:g.salt_len]
  758. d.enc_seed = dd[g.salt_len:]
  759. key = make_key(d.passwd, d.salt, d.hash_preset, 'main key')
  760. qmsg('Key ID: {}'.format(make_chksum_8(key)))
  761. verify_seed = getattr(self,'_verify_seed_'+
  762. ('newfmt','oldfmt')[bool(opt.old_incog_fmt)])
  763. seed = verify_seed(decrypt_seed(d.enc_seed, key, '', ''))
  764. if seed:
  765. self.seed = Seed(seed)
  766. msg('Seed ID: {}'.format(self.seed.sid))
  767. return True
  768. else:
  769. return False
  770. class IncogWalletHex (IncogWallet):
  771. file_mode = 'text'
  772. desc = 'hex incognito data'
  773. fmt_codes = 'mmincox','incox','incog_hex','xincog','ix','xi'
  774. ext = 'mmincox'
  775. no_tty = False
  776. def _deformat(self):
  777. ret = decode_pretty_hexdump(self.fmt_data)
  778. if ret:
  779. self.fmt_data = ret
  780. return IncogWallet._deformat(self)
  781. else:
  782. return False
  783. def _format(self):
  784. IncogWallet._format(self)
  785. self.fmt_data = pretty_hexdump(self.fmt_data)
  786. class IncogWalletHidden (IncogWallet):
  787. desc = 'hidden incognito data'
  788. fmt_codes = 'incog_hidden','hincog','ih','hi'
  789. ext = None
  790. _msg = {
  791. 'choose_file_size': """
  792. You must choose a size for your new hidden incog data. The minimum size is
  793. {} bytes, which puts the incog data right at the end of the file. Since you
  794. probably want to hide your data somewhere in the middle of the file where it's
  795. harder to find, you're advised to choose a much larger file size than this.
  796. """.strip(),
  797. 'check_incog_id': """
  798. Check generated Incog ID above against your records. If it doesn't
  799. match, then your incognito data is incorrect or corrupted, or you
  800. may have specified an incorrect offset.
  801. """,
  802. 'record_incog_id': """
  803. Make a record of the Incog ID but keep it secret. You will used it to
  804. identify the incog wallet data in the future and to locate the offset
  805. where the data is hidden in the event you forget it.
  806. """,
  807. 'dec_chk': ', hash preset, offset {} seed length'
  808. }
  809. def _get_hincog_params(self,wtype):
  810. a = getattr(opt,'hidden_incog_'+ wtype +'_params').split(',')
  811. return ','.join(a[:-1]),int(a[-1]) # permit comma in filename
  812. def _check_valid_offset(self,fn,action):
  813. d = self.ssdata
  814. m = ('Input','Destination')[action=='write']
  815. if fn.size < d.hincog_offset + d.target_data_len:
  816. fs = "{} file '{}' has length {}, too short to {} {} bytes of data at offset {}"
  817. die(1,fs.format(m,fn.name,fn.size,action,d.target_data_len,d.hincog_offset))
  818. def _get_data(self):
  819. d = self.ssdata
  820. d.hincog_offset = self._get_hincog_params('input')[1]
  821. qmsg(u"Getting hidden incog data from file '{}'".format(self.infile.name))
  822. # Already sanity-checked:
  823. d.target_data_len = self._get_incog_data_len(opt.seed_len)
  824. self._check_valid_offset(self.infile,'read')
  825. flgs = os.O_RDONLY|os.O_BINARY if g.platform == 'win' else os.O_RDONLY
  826. fh = os.open(self.infile.name,flgs)
  827. os.lseek(fh,int(d.hincog_offset),os.SEEK_SET)
  828. self.fmt_data = os.read(fh,d.target_data_len)
  829. os.close(fh)
  830. qmsg(u"Data read from file '{}' at offset {}".format(self.infile.name,d.hincog_offset))
  831. # overrides method in SeedSource
  832. def write_to_file(self):
  833. d = self.ssdata
  834. self._format()
  835. compare_or_die(d.target_data_len, 'target data length',
  836. len(self.fmt_data),'length of formatted ' + self.desc)
  837. k = ('output','input')[self.op=='pwchg_new']
  838. fn,d.hincog_offset = self._get_hincog_params(k)
  839. if opt.outdir and not os.path.dirname(fn):
  840. fn = os.path.join(opt.outdir,fn)
  841. check_offset = True
  842. try:
  843. os.stat(fn)
  844. except:
  845. if keypress_confirm(u"Requested file '{}' does not exist. Create?".format(fn),default_yes=True):
  846. min_fsize = d.target_data_len + d.hincog_offset
  847. msg(self.msg['choose_file_size'].format(min_fsize))
  848. while True:
  849. fsize = parse_nbytes(my_raw_input('Enter file size: '))
  850. if fsize >= min_fsize: break
  851. msg('File size must be an integer no less than {}'.format(min_fsize))
  852. from mmgen.tool import Rand2file # threaded routine
  853. Rand2file(fn,str(fsize))
  854. check_offset = False
  855. else:
  856. die(1,'Exiting at user request')
  857. f = Filename(fn,ftype=type(self),write=True)
  858. dmsg('{} data len {}, offset {}'.format(capfirst(self.desc),d.target_data_len,d.hincog_offset))
  859. if check_offset:
  860. self._check_valid_offset(f,'write')
  861. if not opt.quiet:
  862. confirm_or_exit('',"alter file '{}'".format(f.name))
  863. flgs = os.O_RDWR|os.O_BINARY if g.platform == 'win' else os.O_RDWR
  864. fh = os.open(f.name,flgs)
  865. os.lseek(fh, int(d.hincog_offset), os.SEEK_SET)
  866. os.write(fh, self.fmt_data)
  867. os.close(fh)
  868. msg(u"{} written to file '{}' at offset {}".format(capfirst(self.desc),f.name,d.hincog_offset))