open-keychain/README.md

234 lines
11 KiB
Markdown
Raw Normal View History

2014-02-20 14:13:36 -05:00
# OpenKeychain (for Android)
2012-03-09 06:13:28 -05:00
OpenKeychain is an OpenPGP implementation for Android.
2014-03-03 07:31:21 -05:00
For a more detailed description and installation instructions go to http://www.openkeychain.org .
2012-03-09 06:13:28 -05:00
2014-03-03 07:36:11 -05:00
### Travis CI Build Status
2014-04-06 08:46:43 -04:00
[![Build Status](https://travis-ci.org/open-keychain/open-keychain.png?branch=master)](https://travis-ci.org/open-keychain/open-keychain)
2013-09-06 10:47:01 -04:00
2014-01-18 12:02:47 -05:00
## How to help the project?
### Translate the application
2013-10-25 15:59:20 -04:00
2014-04-06 07:06:12 -04:00
Translations are managed at Transifex, please contribute there at https://www.transifex.com/projects/p/open-keychain/
2013-10-25 15:59:20 -04:00
2014-01-18 12:02:47 -05:00
### Contribute Code
1. Join the development mailinglist at http://groups.google.com/d/forum/openpgp-keychain-dev
2014-04-06 07:06:12 -04:00
2. Lookout for interesting issues on our issue page at Github: https://github.com/open-keychain/open-keychain/issues
2014-01-18 12:02:47 -05:00
3. Tell us about your plans on the mailinglist
4. Read this README, especially the notes about coding style
2014-02-20 14:13:36 -05:00
5. Fork OpenKeychain and contribute code (the best part ;) )
2014-01-18 12:02:47 -05:00
6. Open a pull request on Github. I will help with occuring problems and merge your changes back into the main project.
2013-12-30 17:25:38 -05:00
2014-02-20 14:13:36 -05:00
I am happy about every code contribution and appreciate your effort to help us developing OpenKeychain!
2012-03-12 11:57:05 -04:00
2014-01-18 12:02:47 -05:00
## Development
Development mailinglist at http://groups.google.com/d/forum/openpgp-keychain-dev
### Build with Gradle
2013-05-25 16:52:44 -04:00
1. Get all external submodules with ``git submodule update --init --recursive``
2. Have Android SDK "tools", "platform-tools", and "build-tools" directories in your PATH (http://developer.android.com/sdk/index.html)
3. Open the Android SDK Manager (shell command: ``android``).
Expand the Tools directory and select "Android SDK Build-tools (Version 21.1.1)".
Expand the Extras directory and install "Android Support Repository"
Select everything for the newest SDK Platform (API-Level 21)
4. Export ANDROID_HOME pointing to your Android SDK
5. Execute ``./gradlew build``
6. You can install the app with ``adb install -r OpenKeychain/build/outputs/apk/OpenKeychain-debug-unaligned.apk``
2013-09-09 07:23:12 -04:00
2014-07-19 09:14:20 -04:00
### Run Tests
1. Use OpenJDK instead of Oracle JDK
3. Execute ``./gradlew test``
2013-09-09 07:23:12 -04:00
2014-01-27 08:47:23 -05:00
### Build API Demo with Gradle
2014-06-09 16:51:13 -04:00
1. Follow 1-4 from above
2. The example code is available at https://github.com/open-keychain/api-example
2014-01-27 08:47:23 -05:00
3. Execute ``./gradlew build``
### Development with Android Studio
2013-09-09 07:23:12 -04:00
2014-07-19 09:16:45 -04:00
We are using the newest [Android Studio](http://developer.android.com/sdk/installing/studio.html) for development. Development with Eclipse is currently not possible because we are using the new [project structure](http://developer.android.com/sdk/installing/studio-tips.html).
2014-07-19 09:16:45 -04:00
1. Clone the project from Github
2014-07-19 09:15:31 -04:00
2. From Android Studio: File -> Import Project -> Select the cloned top folder
2012-03-12 11:57:05 -04:00
2014-03-03 07:27:43 -05:00
## OpenKeychain's API
OpenKeychain provides two APIs, namely the Intent API and the Remote OpenPGP API.
The Intent API can be used without permissions to start OpenKeychain's activities for cryptographic operations, import of keys, etc.
However, it always requires user input, so that no malicious application can use this API without user intervention.
2014-03-03 07:27:43 -05:00
The Remote OpenPGP API is more sophisticated and allows to to operations without user interaction in the background.
When utilizing this API, OpenKeychain asks the user on first use to grant access for the calling client application.
More technical information and examples about these APIs can be found in the project's wiki:
2014-04-06 07:06:12 -04:00
* [Intent API](https://github.com/open-keychain/open-keychain/wiki/Intent-API)
* [Remote OpenPGP API](https://github.com/open-keychain/open-keychain/wiki/OpenPGP-API)
2013-09-10 06:48:29 -04:00
2013-09-15 09:20:15 -04:00
2014-01-18 12:02:47 -05:00
## Libraries
2012-03-12 11:57:05 -04:00
2014-01-18 12:02:47 -05:00
### ZXing Barcode Scanner Android Integration
2012-03-09 06:13:28 -05:00
2014-04-19 09:53:34 -04:00
Classes can be found under https://github.com/open-keychain/zxing-android-integration.
2012-03-09 06:13:28 -05:00
2014-04-19 09:53:34 -04:00
1. Copy all classes from https://github.com/zxing/zxing/tree/master/android-integration folder to our git repository.
2012-03-09 06:13:28 -05:00
2014-04-19 09:53:34 -04:00
### ZXing QR-Code Classes
2014-04-19 09:53:34 -04:00
Classes can be found under https://github.com/open-keychain/zxing-qr-code.
All QR Code related classes were extracted from the ZXing library (https://github.com/zxing/zxing).
2012-03-09 06:13:28 -05:00
2014-01-18 12:02:47 -05:00
### Bouncy Castle
2013-09-16 04:30:31 -04:00
#### Spongy Castle
2014-02-20 14:13:36 -05:00
Spongy Castle is the stock Bouncy Castle libraries with a couple of small changes to make it work on Android. OpenKeychain uses a forked version with some small changes. These changes will been sent to Bouncy Castle, and Spongy Castle will be used again when they have filtered down.
see
2014-01-27 08:34:36 -05:00
* Fork: https://github.com/openpgp-keychain/spongycastle
* Spongy Castle: http://rtyley.github.com/spongycastle/
2013-09-16 04:30:31 -04:00
#### Bouncy Castle resources
* Repository: https://github.com/bcgit/bc-java
* Issue tracker: http://www.bouncycastle.org/jira/browse/BJA
#### Documentation
* Documentation project at http://www.cryptoworkshop.com/guide/
* Tests in https://github.com/bcgit/bc-java/tree/master/pg/src/test/java/org/bouncycastle/openpgp/test
2014-02-09 14:03:53 -05:00
* Examples in https://github.com/bcgit/bc-java/tree/master/pg/src/main/java/org/bouncycastle/openpgp/examples
2013-09-16 04:30:31 -04:00
* Mailinglist Archive at http://bouncy-castle.1462172.n4.nabble.com/Bouncy-Castle-Dev-f1462173.html
2014-08-19 08:53:25 -04:00
* Commit changelog of pg subpackage: https://github.com/bcgit/bc-java/commits/master/pg
2012-10-25 08:52:13 -04:00
2015-03-02 10:34:56 -05:00
## Build System
We try to make our builds as [reproducible/deterministic](https://blog.torproject.org/blog/deterministic-builds-part-one-cyberwar-and-global-compromise) as possible.
#### Update Gradle version
* Always use a fixed Android Gradle plugin version not a dynamic one, e.g. ``0.7.3`` instead of ``0.7.+`` (allows offline builds without lookups for new versions, also some minor Android plugin versions had serious issues, i.e. [0.7.2 and 0.8.1](http://tools.android.com/tech-docs/new-build-system))
* Update every build.gradle file with the new gradle version and/or gradle plugin version
2014-03-06 13:11:11 -05:00
* build.gradle
2014-04-06 07:06:12 -04:00
* OpenKeychain/build.gradle
* run ./gradlew wrapper twice to update gradle and download the new gradle jar file
* commit the corresponding [Gradle wrapper](http://www.gradle.org/docs/current/userguide/gradle_wrapper.html) to the repository (allows easy building for new contributors without the need to install the required Gradle version using a package manager)
#### Update SDK and Build Tools
* Open build.gradle and change:
```
ext {
compileSdkVersion = 21
buildToolsVersion = '21.1.2'
}
```
* Change SDK and Build Tools in git submodules "openkeychain-api-lib" and "openpgp-api-lib" manually. They should also build on their own without the ext variables.
#### Add new library
* You can add the library as a Maven dependency or as a git submodule (if patches are required) in the "extern" folder.
2015-03-02 11:23:06 -05:00
* If added as a Maven dependency, pin the library using [Gradle Witness](https://github.com/WhisperSystems/gradle-witness) (Do ``./gradlew -q calculateChecksums`` for Trust on First Use)
* If added as a git submodule, change the ``compileSdkVersion`` and ``buildToolsVersion`` in build.gradle to use the variables from the root project:
```
android {
compileSdkVersion rootProject.ext.compileSdkVersion
buildToolsVersion rootProject.ext.buildToolsVersion
}
```
2015-03-02 10:34:56 -05:00
* You can check for wrong ``compileSdkVersion`` by ``find -name build.gradle | xargs grep compileSdkVersion``
2015-03-02 10:34:56 -05:00
#### Slow Gradle?
* https://www.timroes.de/2013/09/12/speed-up-gradle/
* Disable Lint checking if it is enabled in build.gradle
2015-03-02 10:34:56 -05:00
#### Error:Configuration with name 'default' not found.
2014-08-04 03:59:11 -04:00
Gradle project dependencies are missing. Do a ``git submodule init && git submodule update``
2015-03-02 11:54:59 -05:00
#### Build on Mac OS X fails?
Try exporting JAVA_TOOL_OPTIONS="-Dfile.encoding=UTF8"
2015-03-02 10:34:56 -05:00
## Translations
2014-01-19 08:13:57 -05:00
Translations are hosted on Transifex, which is configured by ".tx/config".
1. To pull newest translations install transifex client (e.g. ``apt-get install transifex-client``)
2. Config Transifex client with "~/.transifexrc"
3. Go into root folder of git repo
4. execute ``tx pull`` (``tx pull -a`` to get all languages)
see http://help.transifex.net/features/client/index.html#user-client
2014-01-18 12:02:47 -05:00
## Coding Style
2013-07-23 16:15:26 -04:00
2014-01-18 12:02:47 -05:00
### Code
2013-07-23 16:15:26 -04:00
* Indentation: 4 spaces, no tabs
* Maximum line width for code and comments: 100
* Opening braces don't go on their own line
* Field names: Non-public, non-static fields start with m.
* Acronyms are words: Treat acronyms as words in names, yielding !XmlHttpRequest, getUrl(), etc.
2014-03-26 08:42:16 -04:00
* Fully Qualify Imports: Do *not* use wildcard-imports such as ``import foo.*;``
2013-07-23 16:15:26 -04:00
2014-03-26 08:42:16 -04:00
The full coding style can be found at http://source.android.com/source/code-style.html
2013-07-23 16:15:26 -04:00
### Automated syntax check with CheckStyle
####Linux
1. Paste the `tools/checkstyle.xml` file to `~/.AndroidStudioPreview/config/codestyles/`
2. Go to Settings > Code Style > Java, select OpenPgpChecker, as well as Code Style > XML and select OpenPgpChecker again.
3. Start code inspection and see the results by selecting Analyze > Inspect Code from Android-Studio or you can directly run checkstyle via cli with `.tools/checkstyle`. Make sure it's executable first.
####Mac OSX
1. Paste the `tools/checkstyle.xml` file to `~/Library/Preferences/AndroidStudioPreview/codestyles`
2. Go to Preferences > Code Style > Java, select OpenPgpChecker, as well as Code Style > XML and select OpenPgpChecker again.
3. Start code inspection and see the results by selecting Analyze > Inspect Code from Android-Studio or you can directly run checkstyle via cli with `.tools/checkstyle`. Make sure it's executable first.
####Windows
1. Paste the `tools/checkstyle.xml` file to `C:\Users\<UserName>\.AndroidStudioPreview\config\codestyles`
2. Go to File > Settings > Code Style > Java, select OpenPgpChecker, as well as Code Style > XML and select OpenPgpChecker again.
3. Start code inspection and see the results by selecting Analyze > Inspect Code from Android-Studio.
2014-01-18 12:02:47 -05:00
## Licenses
2014-04-06 11:39:56 -04:00
OpenKechain is licensed under GPLv3+.
The full license text can be found in the [LICENSE file](https://github.com/open-keychain/open-keychain/blob/master/LICENSE).
Some parts and some libraries are Apache License v2, MIT X11 License (see below).
> This program is free software: you can redistribute it and/or modify
> it under the terms of the GNU General Public License as published by
> the Free Software Foundation, either version 3 of the License, or
> (at your option) any later version.
>
> This program is distributed in the hope that it will be useful,
> but WITHOUT ANY WARRANTY; without even the implied warranty of
> MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
> GNU General Public License for more details.
>
> You should have received a copy of the GNU General Public License
> along with this program. If not, see <http://www.gnu.org/licenses/>.
2012-12-19 08:05:08 -05:00
2014-01-18 12:02:47 -05:00
### Libraries
2012-12-19 08:05:08 -05:00
2015-03-04 09:52:06 -05:00
See https://github.com/open-keychain/open-keychain/blob/development/OpenKeychain/src/main/res/raw/help_about.html
2012-12-19 08:05:08 -05:00
2014-01-18 12:02:47 -05:00
### Images
* icon.svg
2012-12-19 08:05:08 -05:00
modified version of kgpg_key2_kopete.svgz
* Actionbar icons
2014-01-18 15:10:27 -05:00
http://developer.android.com/design/downloads/index.html#action-bar-icon-pack
* QR Code Actionbar icon
https://github.com/openintents/openintents/blob/master/extensions/qrcode_ext/icons/ic_menu_qr_code/ic_menu_qr_code_holo_light/ic_menu_qr_code.svg
2012-12-19 08:05:08 -05:00
2014-08-05 18:59:38 -04:00
* Key status icons by the ModernPGP working group
https://github.com/ModernPGP
2014-05-06 16:09:55 -04:00
* Purple color scheme
http://android-holo-colors.com/