google / google/openhtf

Replacing `M2Crypto` dependency with `cryptography`

Open
#1,135 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
722
Forks
237
Avg merge
11h 31m
Merged PRs (30d)
4

Description

Hi! Would you be open to a PR to replace the `M2Crypto` dependency with [`cryptography`](https://pypi.org/project/cryptography/)?

- `cryptography` provides wheels for [most platforms](https://pypi.org/project/cryptography/#files), whereas `M2Crypto` only provides a [source tarball](https://pypi.org/project/M2Crypto/#files), meaning it has to be built from scratch every time.
- `M2Crypto` needs `swig` to be installed in order to be built, which means installing with `pip install openhtf[usb_plugs]` will fail unless `sudo apt install swig` (or equivalent) is [run before](https://github.com/google/openhtf/blob/696a3beb562bb4f72c8b1343651460b535395818/CONTRIBUTING.md?plain=1#L216).
- `cryptography` is actively maintained by the Python Cryptographic Authority

Since `M2Crypto` is only used to implement a `adb_protocol.AuthSigner` subclass ([`M2CryptoSigner`](https://github.com/google/openhtf/blob/c85fb069a1ce407e82bb47a8fb1b64220e974c5f/openhtf/plugs/usb/adb_device.py#L56-L70)), only needing to load RSA keys and sign with them, it could be easily replaced with something like:

```python
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives import hashes

def get_passphrase() -> Optional[str]:
from getpass import getpass
try:
return getpass('Enter passphrase:')
except KeyboardInterrupt:
return None

class CryptographySigner(adb_protocol.AuthSigner):
"""AuthSigner using cryptography."""
def __init__(self, rsa_key_path):
with open(rsa_key_path + '.pub') as rsa_pub_file:
self.public_key = rsa_pub_file.read()

with open(rsa_key_path, "rb") as rsa_file:
self.rsa_key = serialization.load_pem_private_key(rsa_file.read(),
password=get_passphrase())

def sign(self, data):
return self.rsa_key.sign(data, hashes.SHA1)

def get_public_key(self):
"""Return the public key."""
return self.public_key
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.